Device compliance is a snapshot, not permanent health

A compliance check tells you the state at the moment it ran.

Between checks, software gets uninstalled, updates get deferred and configurations change. Access decisions based on a compliance flag are therefore based on history rather than on current state, and the gap can be days. Continuous evaluation narrows it, and nothing closes it entirely.

More on Endpoint security