In several cases like this I have solved by applying the default reset of the firewall one and several times.
From Control Panel Network Settings - Windows Firewall - Restore default firewall settings
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
We have had this recurring issue for a long time now, and despite searching the error all over the place, there seem to be a lot of other IT professionals in the same boat, but no obvious answers.
The error is on the Anti-Virus setting on the default compliance policy.
2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)
The compliance policy in question is assigned to all users.
This is a very annoying issue as it stops users from being able to access any MSFT apps as it marks the device as non compliant.
we are forced to add users to the exclusion list of the policy until the error clears on it's own days/weeks later.
If anyone has any ideas on what could be the cause or any possible fixes, it would be greatly appreciated
We have been dealing with this issue since March and it isn't getting any better.
We have the same issue, no third party AV, laptops updated re-synched multiple times.
It happens to Win11 laptops only!
I can confirm we are a Defender shop and seeing this as well, specifically for the Firewall setting within Device Compliance. It seems to resolve itself after a few hours, but OP mentions, it locks users out.
I also wanted to note that we started seeing OneDrive not silently login or preform known folder redirection on a few of our accounts. While troubleshooting the problem further I noticed that we are also seeing: 2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request) on specifically my account and a co-workers with reguards to the antivirus and firewall categories. This appears to be happening on freshly enrolled PCs through autopilot and existing PCs in my fleet. We use Microsoft 365 Defender for our Antivirus and firewall solution that are UpToDate. I have not seen the problem occur on others within our school district but that doesn't mean that it isn't happening which is scary because it could give users a false sense that they are signed into Onedrive when they are not. Problems started occurring around mid-July 2023 for us.
*Accidental double post
Looks like there are multiple people in this thread having the same problem.
Please open support cases so we can get more traction on this issue, and they can start to get it resolved.
Facing the same issue here.
This comment has been deleted due to a violation of our Code of Conduct. The comment was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.
Hello all,
unfortunately, we have the same issue and all our computer names are up to 10 characters long. So this (renaming) will not be the solution for everybody.
I am getting this error on Firewall and not Antivirus...
We are seeing this error as well. And our machine names are only 10 characters, so Less than 15 is not going to fix the issue.
We have been having the same issue since we started using Intune. It hits different computers on different days, and it clears after hours/days/resyncs.
Our device names are 15 characters or less. We have removed and redeployed machines, removed and recreated the compliance policy. The issue may resolve for a while, but it always comes back.
The exact same issue and error will randomly affect our machines. No third-party AV, OneDrive first starts complaining about device compliance, InTune reports AV is out of compliance due to this error. Computer names are less than 15 characters.
Hi,
For our environment we resolve this by letting the user click "Fix now" under the Work or school account settings menu.
After that they can click on "Check access" under the device menu in Company portal.
We dont have any hybrid devices, only AAD.
We've just seen this appear in our environment. The Senior VP got an email that she forwarded onto my team for action. Not a good look MS.
Anti-Virus is ESET Protect.
We need this addressed PDQ!
Same problem here, on brand new machines. No long computer names.
We are experiencing the same issue. Our devices are AzureAD Joined, we do several app installations when the devices is joined. The issue only happens with Windows 11. The machine becomes very slow and AV stops working after reboot. It appears the Microsoft Defender AV (Endpoint security) is trying to restart. EDR show as if it is updating.
Same issue with our devices.
We have this on Win10 laptops.
We see this persisting for firewall and antivirus even on new build recently joined laptops (win10).
Same problem here! Any solution Microsoft? resetting the PCs is not a popular one
Keep having this issue intermittently affecting random users using random AAD hybrid joined Windows 10 endpoints.
Machine names are less then 15characters.
Fixed the issue once by running sync from Endpoint and InTune.
All other times need to wait days to weeks for the issue to resolve itself, else delete the endpoint from InTune and AzureAD then do a fresh Azure AD hybrid + InTune join.
Myself and colleagues gave raised tickets with MSFT 365 support who aren't much help, leaving poor 1st line guys struggling when a senior team needs to get involved and gather debug logs to determine the actual cause.
Same issue here for Antivirus and Firewall on multiple Win 11 devices
Same here, only a few devices. Firewall is active (Via Intune Policy), AV = Defender (Managed).
We have a culprit, not sure.... will see if it helps:
Resetting firewall defaults didn't help.
Checking compliance via Companyportal (last checkin 40 minutes ago) takes forever, reboot doesn't help.
How are you "resetting firewall defaults"? Is it through the Defender menu or some other way?
Same here, we have few devices whit that error message, but the Antivirus is up to date and no issues
We also have a few users affected by this issue (until now all hybrid joined):
2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)
It's always the Windows Firewall. Never AV (we use windows defender):
Same issue here: It occurs randomly after users restart their machines. Sometimes, a sync is enough to fix the issue, but other times we have to reboot the machine, sync, check for compliance, and repeat the process multiple times.
We use Windows Defender AV, and our machines’ names are only 11 characters. Last year, this issue was happening very often, but Microsoft fixed it. However, we now observe the same issue occurring since the beginning of March 2024.
One machine had this issue, the devicename in autopilot was blank, the devicename in intune was below 15 chars. the machine was also inactive.
I have reinstalled the Company Portal its working fine
I am having this issue on Win 10 laptops as well
Hi Guys, i have had this issue for several users. fix is to turn off the windows firewall and turn it back again. then go to company portal click once on check access and wait 2-3mins until it completes. do not click again and again as it will then take more time. if its taking way too long turn off the conditional access policy that check for compliance. then once company portal check is ok you can turn on the conditional access.
To verify further you can check azure ad portal devices and select the device you are checking on. check if its compliant. Then you can go to intune portal check if it shows compliant. it may be compliant on azure ad and not in intune. give it some time and then it will show compliant on intune as well.
So I have this on multiple instances of both Win11 and Win10 machines for various clients (different intune configs, different methods of setup), I've poked and asked around, mostly from what I can see it's a sync issue. Again cloud loves to take its time with these, and its v. intermittent.
With Stricter compliance policies it appears more frequently than less relaxed policies but I will try and investigate further into this, I don't really have a concrete answer to this other than sync-ing devices.
Usually (on device) i'll run intunemanagementextension://synccompliance in the run diag
This usually clears up after about 10-30ish minutes
We continue to have this issue several times a week. We either wait several days for it to clear on its own or have the user initiate a sync, reboot, etc.
We have opened issues with MS Support only to be passed around to different agents/techs with no solutions offered.
Our compliance platform was integrated to Intune to pull device status,. This became unworkable with this issue occurring so often, so we had to go a different route for that.
It is unfortunate that an issue that is this widespread gets no attention from Microsoft, and support is not helpful.
@Chad Coker Changes are supposed to be coming but they missed the 2404 deployment. Waiting to see when they might be implemented and if they do in fact fix these issues. Update from Microsoft below. You can reference our case so you might be in the loop better on the rollout.
2310040040013084
this has happened to a few windows 10 distros
Microsoft, get it together. This seems to be a recurring issue. This is now happening to us
Why is this still a problem over a year later? Is the Intune Team at Microsoft staffed at all?
@Philipp Durrer
Yes.. I got this update this week, but still no details around what the fix is so I can say it actually will fix the issue.
I have see other orgs will move to custom compliance policies to do the checks for these items which is more accurate. They write a custom script and json responses to validate the fw/av settings are correct. I haven't done that myself, but I heard it is helping them.
"There are several CSS Engineers that are monitoring this request / issue with our Engineering team. We have a received an update on a corrective action, however, we do not have a date just yet for the completion. We are attempting to ascertain a definitive date from Engineering and then I will advise. As this has slipped before, we do not want to publish a speculative date, so once Engineering provides a definitive date, I will share it with you."
Been hassling with this issue for several years, ever since started using InTune.
I really don't get how big business corporations and governments see this as a viable product with the amount of hassle it is to use.
But as to the syncml(500) issue, once confirmed Windows Security on the endpoint reports no issues I've been able to clear the bug twice now by:
0. Run sync from device endpoint in InTune MDM admin centre
@Nick Eckermann Thank you for your updates on this - We're seeing a similar issue and have referred our Microsoft Support contact to your ticket number. Unfortunately I've not managed to have them get in touch with the engineering team yet... I'm still just getting documentation quoted back at me.
I was wondering if you had any updates from MS recently? It sounds like the fix just keeps getting delayed over and over again.
*Edit - I see you posted a week ago that you'd had another noncommittal response from them. No surprises there! Fingers crossed they finally get it sorted soon.
Thanks again,
Joe
same error message
Been fighting with this since Semptember 23.
It's a shame that an small indie studio like Microsoft can't fix a recurring issue like this.
We recently onboarded our devices to Intune. We had no previous MDM so all these devices were never managed by anything before. After using the default the Firewall Windows default policy as our base policy, we started to get this error in our compliance report. I took the provided policy, duplicated it and renamed the duplicate. This fixed our issue.
This is broken for years now.
The issue seems to be not resolved yet, i think microsoft intune team need to release a bug fix update. So many companies are relied on intune.
Yup, I've got one windows laptop having the antivirus "2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)" error now for a week. I'm going to either reapply the policy today, or try one of the other things listed here. What I don't want to do is reset the computer or rejoin it to intune. I shouldn't have to do that, for crying out loud.
We have a lot of devices with this problem
We have the same problem, Intune support unhelpful and will not recognize it as Intune problem. Windows team blames Intune. Intune support refers to this thread as it would be official answer... They told to do windows 10 updates and our devices are Windows 11 and the character limit which is not documented to my understanding and is happening to devices less than the recommended character limit. Same error for Firewall and Antivirus. Would be great to get actual technical help.
We have the same problem, 600 machines under Intune. Cant live with Microsofts neclect.
I thought we could rely part of our security on Conditional Access requiring compliance.
but with 5-10 false positives each month its not reliable
FIRST i thought it only happend on Hybid joined computers or computers from acquired companies "joined EntraID as is" but we see it frequetly on "pure" Autopilot reshly picked up computers
Great with the workaround - thanks!
Cheers from Denmark
PS: Can we upvote this or is there an article where Microsoft accept the fact that so many of us see this ?
Another report of this for multiple devices. Device Names under 15 characters, Defender as standard AV and fully patched and up to date with Fresh Synch completed locally from device.
Nick Eckermann may be onto something as we have seen this occurring more on pre-provisioned devices where they have been built but the use reenrollment step may be completed several days later or used sporadically after deployment.
Either way MS needs to acknowledge and patch this there so many people reporting this you think there own firewall product and AV could talk to their own systems correctly!
Has there been any recent feedback from Microsoft regarding this issue and a potential solution in a future release?
also a strange thing is that I have one device compliant and the other not.
Both the same error code as mentiont here.
Microsoft was having issues this week attempting to deploy a fix for the issue that has been around. It accidentally caused issues with devices that should have fallen the error state grace period to be marked non-compliant immediately depending on if a user was on the device or not when it ran a compliance scan. It was supposed to be mitigated late yesterday after to resolve the new issue. Time will tell if it solved the overall problem with the syncml500 errors.
I managed to get it compliant again somehow, any known problems for the sync not working correctly ?
I'm running into this too specifically with the Firewall.
101 devices but 5 of them aren't happy with 2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)
Hybrid Joined with Auto Enrolment.
Confirmed the device name is under 15 characters.
Confirmed the firewall is on
Tried resetting the firewall to defaults.
Triggered syncs from Intune and from the client-side (Accounts->Work or School->Info->Sync)
Used the Company Portal 'Check Compliance'
Triggered syncs via
Trigger a compliance check via local process on PC (use remote shell or execute locally)
Start-Process -FilePath "C:\Program Files (x86)\Microsoft Intune Management Extension\Microsoft.Management.Services.IntuneWindowsAgent.exe" -ArgumentList "intunemanagementextension://synccompliance"
Trigger a sync via local scheduled task on PC (use remote shell or execute locally)
Get-ScheduledTask -TaskName “Schedule #3 created by enrollment client” | Start-ScheduledTask
Nothing is helping - to the extent I had to simply exclude them from the policy which is ridiculous... does anyone have any other bright ideas?
do you use windows hello? Did you try it switch off it?
You can reset the Windows Hello with the following command:
certutil /deletehellocontainer
After running the PowerShell script locally and then clicking sync from Intune the computer needs to be rebooted, after reboot its compliant again, without reboot it does not take affect.
Hello, Check if your user has at least one Intune license and that he can sync successfully.
In my case, I had users who do not have a license, neither intune nor Office, nor anything.
And I was able to go through users who have Co-manag SCCM licenses (flag). then my workstations became compliant.
Thanks for the suggestions folks, I've tried/ruled out everything suggested so far except deleting the Windows Hello container. I'm averse to doing that (really shouldn't be necessary!!) but will give it a whirl on one of the affected users to at least rule it out. Appreciate the suggestions so far.
Pretty sad that this is still an issue years later.
Sadly, MS devs seem at times to conveniently ignore these ongoing issues without offering much support.
Started to seeing this again since last week, created a copy of our existing compliance policy, changed the assignment from devices to users and it fixed the problem, temporarily.
Next day the device appears to randomly complain about compliance with syncml 500 error again, sometimes AV, firewall or defender updates or all of them.
However, with the new policy, a manual check-in from the device does remediate it again, whereas devices with the original policy, stubbornly never went back to green, no matter what we've tried.
Definitely a reporting bug in Intune, thinking of creating a custom compliance policy and ditching the template generated one.
Hello, I have deposited the following remediation script in Intune. The commands can also be easily executed in Powershell.
Get-ScheduledTask | ? {$_.TaskName -eq 'Schedule #3 created by enrollment client'} | Start-ScheduledTask
Start-Process -FilePath "C:\Program Files (x86)\Microsoft Intune Management Extension\Microsoft.Management.Services.IntuneWindowsAgent.exe" -ArgumentList "intunemanagementextension://syncapp"
Start-Process -FilePath "C:\Program Files (x86)\Microsoft Intune Management Extension\Microsoft.Management.Services.IntuneWindowsAgent.exe" -ArgumentList "intunemanagementextension://synccompliance"
In several cases like this I have solved by applying the default reset of the firewall one and several times.
From Control Panel Network Settings - Windows Firewall - Restore default firewall settings
We are having the same problem, but its not making the device non-compliant? it just brings up an error under the policy and when you click on the actual policy and it says Compliant, non-compliant and other, the said device appears under other?
We also had an issue with 2 devices. But since we use 3rd-party AV we deleted that and reinstalled it and it was back to a compliant state. Sync device side didnt do anything other then confirm the error.
We also have started to have this problem. Multiple restarts and checking status from Company Portal app does not help. Security app confirms all services are running with green checkmarks.
Seems like a problem between Intune system and company portal app. I finally got this to work after 2 1/2 hours with a user. Had to do many restarts and status checking, but eventually the laptop became compliant.
Happens again for few devices, no pattern.
It's mostly hybrid joined devices, name is below 15 characters.
It always complains about the firewall.
Firewall & AV is Windows Defender.
Same issue here: It occurs randomly after users restart their machines. Sometimes, a sync is enough to fix the issue, but other times we have to reboot the machine, sync, check for compliance, and repeat the process multiple times.
We use Windows Defender AV, and our machines’ names are only 11 characters. Last year, this issue was happening very often, but Microsoft fixed it. However, we now observe the same issue occurring since the beginning of March 2024.
We just sign up for Intune with in the last month and we were seeing this error as well. I fixed it by duplicating the default firewall policy and renaming the new one.