Work app says your device is not compliant: how to fix access
For end users who are blocked from a work app by a "device not compliant" message. This runbook helps you identify the most common causes, check them in the least disruptive order, and apply the right fix using your device settings or your company's device-management portal.
TL;DR — If your work app says your device is not compliant, the most common causes are: your device has not checked in with your company’s device manager recently, your OS or security updates are behind, or required protections like disk encryption or a screen lock are off. Start by syncing the work account in your device settings or company portal app, then install pending updates and confirm encryption and a passcode are enabled. Reading time: ~6 min
The scenario
It is a normal Tuesday afternoon. You open your work email or VPN, then try to launch the company app you use every day, and instead of signing in you get a message saying your device is not compliant. You were using the same laptop or phone yesterday, nothing obvious changed, and now you cannot get to files, chat, or the customer system you need for a meeting in 20 minutes. The app may still open, but anything behind the company sign-in wall is blocked until the device passes a policy check.
Symptoms
- The app shows one of these messages:
- "Your device is not compliant"
- "Access blocked: device does not meet your organization’s security requirements"
- "You can’t get there from here"
- "This device is not trusted"
- "Your organization requires a compliant device to access this resource"
- You can sign in on the web with your password, but access stops after login.
- A company portal or device-management app shows:
- "Not compliant"
- "Pending evaluation"
- "Last check-in: days ago"
- "Action required"
- Your device settings show one or more of these:
- OS update available
- Antivirus/security protection off or outdated
- Disk encryption off
- No PIN/passcode/screen lock set
- Work account needs attention or re-authentication
- On mobile, the app may loop between sign-in and a compliance warning.
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| Device has not checked in with your company’s device manager | Very common | Open your company portal/device management app and look for "Last check-in" or tap/click "Sync" |
| Operating system updates are missing | Very common | Open device settings: Windows "Settings → Windows Update", macOS "System Settings → General → Software Update", iPhone/iPad "Settings → General → Software Update", Android "Settings → System → Software update" |
| Required protections are off: screen lock, disk encryption, firewall, antivirus | Common | Open device security settings and check for warnings in the main Security/Privacy screen |
| Work account or device registration is broken or expired | Common | Open device settings and inspect the connected work/school account for "Fix now", "Reconnect", or an error |
| Device date/time is wrong, so policy checks fail | Sometimes | Open date/time settings and confirm "Set automatically" is enabled |
| Your company changed the compliance policy and your device no longer qualifies | Less common | Check the company portal app for the exact failed rule, or contact IT and ask for the policy name shown in the block message |
Step-by-step diagnosis
-
Open the company portal or device-management app and force a sync.
- Path: open the app your company uses for device access, then look for a button named "Sync", "Check status", "Refresh", or "Check access".
- If you do not have a portal app, use device settings:
- Windows: "Settings → Accounts → Access work or school → select your work account → Info → Sync"
- iPhone/iPad: "Settings → General → VPN & Device Management" and open the management profile if present
- Android: "Settings → Passwords & accounts" or "Settings → Security & privacy → Device admin apps" depending on device maker
- macOS: "System Settings → Privacy & Security → Profiles" or your company portal app
- This is your problem if the status changes from "Not compliant" to "Pending" and then to "Compliant", or if it says the last check-in was many days ago.
- If sync fixes it, stop here. If sync reports a specific failed rule, jump to the matching fix below.
-
Check for operating system updates and install them.
- Windows: "Settings → Windows Update → Check for updates"
- macOS: "System Settings → General → Software Update"
- iPhone/iPad: "Settings → General → Software Update"
- Android: "Settings → System → Software update"
- This is your problem if you see one or more pending security or feature updates and the compliance message mentions minimum OS version, security patch level, or unsupported version.
- Install updates, restart if prompted, then jump to "### Missing operating system updates".
-
Check the basic security requirements on the device.
- Windows: "Settings → Privacy & security → Windows Security → Open Windows Security"
- macOS: "System Settings → Privacy & Security"
- iPhone/iPad: "Settings → Face ID & Passcode" or "Touch ID & Passcode"
- Android: "Settings → Security & privacy"
- This is your problem if you see any of these: no PIN/passcode, encryption off, firewall off, antivirus off, or device protection marked with a warning.
- Jump to "### Required protections are off".
-
Reconnect the work account if it shows an error.
- Windows: "Settings → Accounts → Access work or school"
- macOS: your company portal app or "System Settings → Internet Accounts" if your org uses account-based enrollment
- Mobile: open the company portal app or the work profile settings
- This is your problem if the account shows "Needs attention", "Fix now", repeated password prompts, certificate/profile errors, or registration failed.
- Jump to "### Broken or expired work account registration".
-
Confirm date and time are automatic.
- Windows: "Settings → Time & language → Date & time → Set time automatically"
- macOS: "System Settings → General → Date & Time → Set time and date automatically"
- iPhone/iPad: "Settings → General → Date & Time → Set Automatically"
- Android: "Settings → System → Date & time → Set time automatically"
- This is your problem if the time zone or clock is wrong by more than a few minutes.
- Correct it, then sync again and jump to "### Incorrect device date or time".
-
If none of the above explains it, check whether the company changed the policy.
- Open the block message and look for a "More details" link, or open the company portal app and find the failed compliance rule.
- This is your problem if the failure names a new requirement such as minimum OS version, approved antivirus, encryption required, or unsupported device type.
- Jump to "### Company policy changed or your device no longer qualifies".
Fixes
Device has not checked in with your company’s device manager
- Connect to the internet without a captive portal (the kind that asks you to open a browser and accept terms).
- Force a sync:
- Windows: "Settings → Accounts → Access work or school → your work account → Info → Sync"
- In your company portal app: tap/click "Sync" or "Check status"
- Restart the device after sync if the status stays stuck on "Pending" for more than 10 minutes.
- Open the app again and retry sign-in.
If you have shell access and your IT team told you to use it, Windows can also trigger device management refresh from an elevated Command Prompt:
start ms-settings:workplace
Verify it worked: the portal app or account page shows "Compliant" or a recent "Last check-in" time from today.
Missing operating system updates
- Install all pending updates from your device’s update screen.
- Restart when prompted. Compliance checks often do not pass until after reboot.
- After restart, open the company portal app and run another sync.
If your device is company-managed and updates are paused by policy, do not try to bypass that. Contact IT and tell them the exact OS version shown on your update screen.
Verify it worked: the update screen says the device is up to date, and the portal app no longer lists OS version or security patch level as a failure.
Required protections are off
Turn on the failed protection named in the portal app or warning.
Common fixes:
- Screen lock/passcode
- Windows: "Settings → Accounts → Sign-in options → PIN (Windows Hello) → Set up"
- macOS: "System Settings → Touch ID & Password" or "Lock Screen"
- iPhone/iPad: "Settings → Face ID & Passcode" or "Touch ID & Passcode"
- Android: "Settings → Security & privacy → Device unlock"
- Disk encryption (encrypts data at rest so a lost device is harder to read)
- Windows: search for "Manage BitLocker" and turn it on if available
- macOS: "System Settings → Privacy & Security → FileVault → Turn On"
- Mobile devices are usually encrypted automatically once a passcode is set on current versions
- Antivirus/firewall
- Windows: "Settings → Privacy & security → Windows Security"
- macOS: many orgs require an approved security app; check the portal app for the exact product requirement
⚠️ Turning on disk encryption can take time and may require a restart. Keep the device plugged in until it finishes.
Verify it worked: the failed item disappears from the portal app after the next sync.
Broken or expired work account registration
- Open the work account page and click the repair option if offered:
- Windows: "Settings → Accounts → Access work or school → your account → Fix" or "Info"
- If repair fails, remove and re-add the work account.
⚠️ Removing a work account can sign you out of work apps and may remove company-managed email, Wi‑Fi, VPN, or app access until re-enrollment completes. Save your work first.
- Remove the account/profile:
- Windows: "Settings → Accounts → Access work or school → your account → Disconnect"
- iPhone/iPad: "Settings → General → VPN & Device Management" and remove only the work profile if your IT instructions allow it
- Android: remove the work profile from the company portal app or work profile settings
- Re-add it using your company’s enrollment instructions or portal app.
- Complete any multi-factor authentication prompts and allow device management when asked.
- Sync again.
Verify it worked: the work account shows connected with no warning, and the app sign-in completes without the compliance block.
Incorrect device date or time
- Turn on automatic date/time and automatic time zone in device settings.
- If already enabled, toggle it off, wait 10 seconds, then toggle it back on.
- Restart the company app and sync the portal app.
Verify it worked: the displayed time matches your local time, and sign-in no longer loops or fails immediately after authentication.
Company policy changed or your device no longer qualifies
- Open the detailed compliance message and note the exact failed rule.
- Compare it to your device:
- OS version too old: update if supported
- Unsupported device type: for example, rooted/jailbroken devices are commonly blocked
- Required app missing: install the named company portal or security app from your official app store
- If the device cannot meet the new rule, contact your IT/help desk with these details:
- Device type and model
- OS version
- Exact compliance error text
- Screenshot of the failed rule in the company portal app
- Last successful access time
Verify it worked: the failed rule is marked passed in the portal app, or IT confirms your device was granted a compliant state after remediation.
Prevention
- Keep automatic OS updates on.
- Windows: "Settings → Windows Update → Get the latest updates as soon as they’re available"
- macOS/iPhone/iPad: "Software Update → Automatic Updates → On"
- Android: enable automatic system updates if your device offers the option
- Open the company portal/device-management app once a week and confirm it has checked in recently.
- A healthy device usually shows a recent sync time and no pending actions.
- Turn on a screen lock and encryption before you need access.
- This avoids the common "suddenly non-compliant" problem after a policy change.
- Do not ignore "work account needs attention" banners.
- Re-authenticate as soon as you see them in "Access work or school", your portal app, or your mail app.
- If you travel, leave automatic date/time enabled.
- Manual time zones are a common reason for sign-in and compliance loops.
- Ask your IT team to publish the exact compliance rules in a self-service page.
- Useful items to list: minimum OS versions, whether encryption is required, whether personal devices are allowed, and which portal/security app must be installed.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI