Microsoft Intune
Device security

Plan for Change: Intune migration for Windows Health Attestation to Microsoft Azure Attestation for Windows 11 devices

In brief

Intune will migrate Windows Health Attestation from Device Health Attestation to Microsoft Azure Attestation by early 2027. Organizations must ensure network access to Azure Attestation endpoints to maintain compliance evaluation for Windows 11 devices using health-based policies, or risk compliance failures.

Message Center announcement

What and why:

Microsoft Intune will migrate Windows Health Attestation compliance evaluation from the current Device Health Attestation (DHA) service to Microsoft Azure Attestation (MAA). This is an Intune service-side change that will happen automatically.

Rollout schedule:

This migration is expected at the end of the first quarter in calendar year 2027.

Impact on your organization:

This change affects evaluation of Windows compliance policies that rely on Health Attestation signals. Action is required to avoid interruption. Organizations that do not allow access to the required Azure Attestation endpoints will experience issues with Health Attestation-based compliance evaluation after the migration is completed.

Action required/recommendations:

Review your network, firewall, proxy, and endpoint access configurations. Specifically, verify that your environment allows devices to access the required Microsoft Azure Attestation endpoints. For detailed guidance, including the required endpoints and configuration recommendations, refer to: Configure endpoints for Azure Attestation migration.

Compliance considerations:

If unaddressed, Windows 11 devices with assigned compliance policies using any of the device health settings (BitLocker, Secure Boot, Code Integrity) will fall out of compliance.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…