Looking for a way to present legal disclaimers and compliance requirements to users before they enroll devices or access protected resources?

As organizations adopt modern device management and Zero Trust approaches, one question frequently arises: how can we maintain legal and compliance requirements during the enrollment process? This is where terms and conditions policies come into play.

In this post, I will explore how Microsoft Intune terms and conditions policies work, compare them with Microsoft Entra Conditional Access terms of use, and discuss when and why you should consider using both as part of your device enrollment strategy.

What are Microsoft Intune Terms and Conditions?

Microsoft Intune terms and conditions policies provide a way to present relevant disclaimers for legal or compliance requirements to device users. A terms and conditions policy requires targeted users to accept your terms in the Company Portal before they can enroll devices or access protected resources.

A futuristic ‘Terms and Conditions’ blueprint floating above the laptop with glowing checkmarks and signature lines.

This feature is particularly valuable for organizations that need to:

  • Communicate acceptable use policies: Inform users about what is and is not acceptable behavior when using corporate devices and resources.
  • Establish legal agreements: Create a documented agreement between the organization and the user.
  • Meet regulatory requirements: Satisfy industry or regional compliance requirements that mandate user acknowledgment.
  • Set expectations: Clarify the organization’s right to manage, monitor, and secure enrolled devices.

Creating Terms and Conditions in Microsoft Intune

Setting up a terms and conditions policy in Microsoft Intune is straightforward:

  1. Sign in to the Microsoft Intune admin center .
  2. Navigate to Tenant administration > End user experiences > Terms and conditions.
  3. Select Create to start a new policy.
  4. On the Basics page, enter:
    • Name: A descriptive name for the policy (not visible to end users).
    • Description: Optional description of the purpose or intended use.
  5. On the Terms page, enter:
    • Title: The display name users will see in Company Portal.
    • Terms and conditions: The full text that users must accept or reject.
    • Summary of terms: A brief, high-level explanation of what the user is agreeing to.
  6. On the Assignments page, target the policy to:
    • All users: Apply to everyone in your organization.
    • Select groups: Target specific user groups.
  7. Review and Create the policy.

Formatting guidelines

Before crafting your terms and conditions, keep these limitations and best practices in mind:

  • Plain text only: Microsoft Intune terms and conditions do not support markdown, HTML, or rich text formatting. Bold, italics, bullet points, and hyperlinks will not render - they will display as raw characters.
  • Keep it concise: Aim for 500-1000 characters for the summary of terms and 2000-4000 characters for the full terms. Users are more likely to read and understand shorter, focused content.
  • Use simple structure: Use line breaks, CAPS, dashes, or numbered sections (1., 2., 3.) for visual separation since formatting is not available.
  • Mobile-friendly: Many users will view terms on mobile devices. Short paragraphs and clear language improve readability.
  • Focus on essentials: Cover the key points - device management rights, monitoring, data handling, and remote wipe capabilities. You can reference external policies for additional details.

Terms and Conditions example

To help you get started, here are example texts for the Title, Terms and conditions, and Summary of terms fields. These examples are designed to cover common scenarios in enterprise device management.

FieldExample
TitleDevice Management Terms and Conditions
Terms and conditionsDEVICE MANAGEMENT TERMS AND CONDITIONS
Effective: [Month Year].

By enrolling this device, you acknowledge and agree to the following:
1. DEVICE MANAGEMENT - Your organization will manage this device remotely, including deploying software, enforcing security policies, and performing remote actions such as lock or wipe.
2. DATA COLLECTION - Your organization may collect device information including device name, serial number, OS version, installed apps, and compliance status to ensure security.
3. ACCEPTABLE USE - Use this device in accordance with organization policies. Do not install unauthorized software or use the device for illegal activities.
4. REMOTE WIPE - Your organization may remotely wipe this device if lost, stolen, compromised, or upon your departure from the organization. Personal data may be lost.
5. POLICY UPDATES - These terms may be updated. You will be notified of significant changes and may need to accept updated terms. By accepting, you confirm you have read and agree to these conditions.
Summary of termsBy enrolling your device, you agree to allow your organization to manage, monitor, and secure this device. Your organization may collect device information, enforce security policies, and remotely wipe the device if necessary.

Please review the complete Terms before accepting.
Example terms and conditions content

Feel free to adapt these examples to match your organization’s specific policies and legal requirements. Consider referencing your existing acceptable use policy or employee handbook rather than duplicating all content in the terms.

How users experience terms and conditions

Once you deploy a terms and conditions policy, targeted users encounter it during device enrollment and in the Company Portal app. The experience is designed to be clear and unambiguous:

  1. Users see the title and summary of terms prominently displayed.
  2. Tapping Read Terms expands the full terms and conditions text.
  3. Users must explicitly Decline or Accept the terms.
  4. Declining prevents enrollment or access to protected resources.
  5. Once accepted, users do not see the terms again unless you update them and require re-acceptance.

This user experience ensures that acceptance is an active, conscious decision - not something that can be accidentally bypassed.

Managing Terms and Conditions

Once your terms and conditions are deployed, Microsoft Intune provides tools to manage versions and track user acceptance over time.

Version Control and Updates

Microsoft Intune provides built-in version control for terms and conditions:

  • Version tracking: Every time you make a significant change, you can increment the version number.
  • Re-acceptance requirement: When you update terms and check the “Require users to re-accept” option, all assigned users must accept the new version before continuing.
  • Acceptance reporting: Track which users have accepted which versions.

Monitoring acceptance

Microsoft Intune provides acceptance reporting to help you track compliance with your terms and conditions:

Report FieldDescription
User nameThe name of the user who accepted the terms
Accepted versionThe version number that was accepted
Accepted timeDate and time of acceptance
Accepted latestWhether the user has accepted the most current version
UPNThe user principal name
Available fields in the acceptance report

To access these reports:

  1. Navigate to Tenant administration > Terms and conditions.
  2. Select your policy from the table.
  3. Select Acceptance Reporting to view and export the data.

Microsoft Entra Conditional Access Terms of Use

Now, here is where things get interesting. Microsoft Entra ID also offers a terms of use feature as part of Conditional Access. While both features serve similar purposes, they have distinct characteristics and use cases.

Microsoft Entra terms of use provides several capabilities beyond what Microsoft Intune offers:

CapabilityMicrosoft Intune T&CMicrosoft Entra ToU
Document formatPlain textPDF (with branding, images, hyperlinks)
Multi-language supportCreate separate policiesAttach multiple PDFs to one policy
Per-device consentNoYes (can require consent on every device)
Consent expirationManual version updatesAutomatic expiration schedules
Re-acceptance periodManualConfigurable (e.g., every 30 days)
Conditional Access integrationNoYes (enforce based on user, app, location, risk)
Triggered duringEnrollment / Company PortalSign-in to targeted applications
Audit logsIntune reportingMicrosoft Entra audit logs
License requirementMicrosoft Intune licenseMicrosoft Entra ID P1 or P2
Comparison of Microsoft Intune Terms and Conditions vs Microsoft Entra Terms of Use

Key Differences Explained

Trigger point: The most significant difference is when users encounter the terms. Microsoft Intune terms and conditions are presented during device enrollment or when accessing the Company Portal. Microsoft Entra terms of use are presented during sign-in to applications protected by Conditional Access policies.

Rich content: Microsoft Entra terms of use supports PDF documents, allowing for sophisticated formatting, corporate branding, images, and hyperlinks. This is particularly valuable for legal documents that require specific formatting.

Granular targeting: With Conditional Access, you can target terms of use based on specific applications, user groups, locations, device platforms, and risk signals. This enables scenarios like “show terms only when accessing HR applications from unmanaged devices.”

Expiration and re-acceptance: Microsoft Entra terms of use supports automatic consent expiration, allowing you to require periodic re-acceptance without manually updating the terms content.

Should you use both?

The short answer: it depends on your requirements. The longer answer: many organizations benefit from using both in complementary ways.

When to use Microsoft Intune Terms and Conditions

  • Device enrollment context: When you specifically need users to acknowledge terms before enrolling their device.
  • Simpler requirements: When you need a straightforward text-based acknowledgment without complex formatting.
  • Company Portal access: When terms should be visible and accepted within the Company Portal experience.
  • Enrollment-focused compliance: When your legal requirement is specifically tied to the act of enrolling a device.

When to use Microsoft Entra Terms of Use

  • Application access context: When terms should be presented before accessing specific cloud applications.
  • Rich document requirements: When you need PDFs with branding, images, or hyperlinks.
  • Periodic re-acceptance: When regulations require users to re-accept terms on a schedule.
  • Per-device consent: When users must accept terms on each device they use.
  • Risk-based presentation: When terms should only appear under certain conditions (high-risk sign-in, new location, etc.).

Using both together

If you configure both Microsoft Intune terms and conditions and Microsoft Entra terms of use, users will be required to accept both - they are completely independent. This is by design and can be valuable when you have:

  • Device-specific terms: Enrollment-related policies in Microsoft Intune (e.g., “By enrolling this device, you agree to allow remote management…”).
  • Application-specific terms: Access-related policies in Entra (e.g., “By accessing the HR system, you agree to maintain confidentiality…”).

Terms and Conditions with Windows Autopilot Device Preparation

Windows Autopilot device preparation is changing the way we think about device onboarding. Let us explore how terms and conditions fit into this modern provisioning workflow.

The modern enrollment journey

With Windows Autopilot device preparation, the enrollment experience is streamlined:

  1. User receives a new device (or resets an existing one).
  2. Device connects to the internet and detects Windows Autopilot configuration.
  3. User signs in with their organizational credentials.
  4. Device joins Microsoft Entra ID and enrolls in Microsoft Intune.
  5. Policies, applications, and configurations are applied.
  6. User reaches the desktop and begins working.

Where do Terms and Conditions fit?

If you have Microsoft Intune terms and conditions assigned to the user, the timing of when they encounter the terms depends on the enrollment scenario:

  • During enrollment: If the user has not previously accepted the terms, they are presented during the Windows enrollment process and must accept before enrollment completes.
  • After enrollment: If the device is already enrolled and new terms are assigned (or existing terms are updated), the user must open the Company Portal app to accept the terms.

This distinction is important: terms and conditions do appear during Windows Autopilot provisioning if the user has not yet accepted them.

For scenarios where you need additional control over terms acceptance, consider:

  • Microsoft Entra terms of use with Conditional Access: Configure a Conditional Access policy targeting the Microsoft Intune Enrollment app. However, be aware of limitations - per-device terms of use do not support the Microsoft Intune Enrollment app.
  • Enrollment Status Page (ESP) requiring Company Portal: Configure the ESP to require Company Portal as a required app, where users will encounter the terms.

For organizations with strict compliance requirements, the timing of terms acceptance matters:

ScenarioRecommendation
Terms must be accepted before any enrollmentUse Microsoft Entra terms of use with Conditional Access targeting the Microsoft Intune Enrollment app
Terms must be accepted before accessing corporate resourcesUse Microsoft Entra terms of use with Conditional Access targeting specific apps
Terms acknowledgment for device managementUse Microsoft Intune terms and conditions for Company Portal acceptance
Both enrollment and ongoing complianceUse both solutions together
Recommendations based on compliance scenarios

Implementing terms and conditions is not just a technical exercise - it provides real legal and organizational value.

A well-crafted terms and conditions policy strengthens your organization’s legal position in several ways:

  • Documented consent: Creates a record that users explicitly agreed to organizational policies.
  • Liability limitation: Terms can include disclaimers about monitoring, data collection, and the organization’s rights.
  • Policy enforcement basis: Provides a foundation for disciplinary actions related to policy violations.

Compliance requirements

Many industries and regulations require organizations to obtain user acknowledgment:

  • GDPR: Transparency requirements about data processing.
  • HIPAA: Acknowledgment of policies regarding protected health information.
  • Financial regulations: Terms related to handling sensitive financial data.
  • Government requirements: Compliance with specific agency mandates.

User awareness

Beyond legal protection, terms and conditions serve an educational purpose:

  • Set clear expectations: Users understand what is expected of them.
  • Explain device management: Users know the organization can manage, monitor, and remotely wipe their device.
  • Reduce support requests: Clear policies reduce confusion and related support tickets.

Best practices

Based on my experience implementing terms and conditions across various organizations, here are my recommendations:

  1. Keep terms concise and readable: Legal language is necessary, but aim for clarity. Users who understand the terms are more likely to comply.
  2. Use both solutions strategically: Do not implement both Microsoft Intune and Microsoft Entra terms just because you can. Have a clear purpose for each.
  3. Plan for localization: If you have a global workforce, plan for translated terms from the start.
  4. Review and update regularly: Terms should evolve with your policies and regulations. Schedule annual reviews.
  5. Document your rationale: Keep records of why you implemented specific terms and the legal/compliance requirements they address.
  6. Test the user experience: Go through the enrollment and sign-in process yourself to ensure the terms appear when and how you expect.
  7. Communicate with users: Before rolling out new terms, inform users about what to expect and why.

Final thoughts

Terms and conditions policies - whether in Microsoft Intune or Microsoft Entra Conditional Access - are essential tools for organizations that need to establish clear agreements with their users before granting access to devices and resources.

While Microsoft Intune terms and conditions provide a straightforward way to present terms during enrollment and Company Portal access, Microsoft Entra terms of use offers richer capabilities for complex compliance scenarios with Conditional Access integration.

In the context of Windows Autopilot device preparation and modern device management, understanding how these features work together enables you to design an enrollment experience that is both user-friendly and legally compliant.

The future of device management is not about blocking at the door - it is about smart policies, identity-centric security, and clear agreements that protect both the organization and its users.

What is your experience with terms and conditions in your organization? Do you use both solutions, or have you found one to be sufficient? I would love to hear your thoughts - reach out on Bluesky  or get in touch.

–Jesper


Header image attribution: Image created with help from Adobe Firefly