Application & Browser Endpoint Security policy not applicable when assigned to Windows 10 Endpoint (Application Guard not deploying)

Jennifer Parsons 21 Reputation points
2021-08-10T10:01:52.183+00:00

Hi,

I've created a new Endpoint Security - App & Browser Isolation policy which enabled Application Guard for Edge and includes our SharePoint site in the Network Isolation profile. However, the assigned Windows 10 endpoints (Surface laptops) are showing as "not applicable", application guard is not being enabled on the endpoints and the policy list against the work account on the device does not show AppHVSI or NetworkIsolation being applied.

I can't figure out why it is considered not applicable to the device! Any suggestions or solutions, please?

Many thanks
Jen

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,708 questions
0 comments No comments
{count} votes

8 answers

Sort by: Most helpful
  1. Lu Dai-MSFT 28,341 Reputation points
    2021-08-11T01:30:53.657+00:00

    @Jennifer Parsons Thanks for posting in our Q&A. From your description, I know that the App and browser isolation policy is not applicable to the device.

    Generally, "Not applicable" means that the policy is not supported on the device. To clarify this issue, we appreciate your help to collect some informmation:

    1. Make sure that the device is the supported system. Please refer to the following article to check.
      https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-application-guard/reqs-md-app-guard
    2. Make sure that Microsoft Defender Application Guard is installed.
      122050-image.png

    If there is anything update, feel free to let us know.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Jack Hsieh 1 Reputation point
    2022-04-13T06:12:36.493+00:00

    Hi,

    I tried to turn on Application Guard through Intune, however the message shows as "Not Applicable" .

    I have checked / also make sure I have the right OS version and Windows features turned on.

    0 comments No comments

  3. Jack Hsieh 1 Reputation point
    2022-04-13T06:14:56.827+00:00

    I was able to turn on manually on the device, but not through Intune, the result returned "Not Applicable"

    Do you know how to solve this ? @Lu Dai-MSFT

    0 comments No comments

  4. Denis Dal Molin 51 Reputation points
    2022-04-25T20:13:29.433+00:00

    I have the same error

    0 comments No comments

  5. Lacy Neugebauer 1 Reputation point
    2022-07-12T18:38:44.367+00:00

    Hello all, have there been any solutions found for this issue? I have 11 out of my 55 PCs in my network that all have the same error in InTune and I have manually tuned it on and its running on one of my users pc's to test and InTune still shows this not on and "not applicable". These pcs are all windows 10, and brand new 2022 dells with MDM installed...

    please help!

    0 comments No comments