Intune CSP deployment constant errors

Jason P 186 Reputation points
2024-02-05T16:10:10.0533333+00:00

Hi All,

I have an issue with Custom CSP Profiles I am creating.

I created on with 4 different OAM-URI settings in a one policy. Two use Integer values and the other two need string (xml Format). These are needed to remediate security vulnerabilities flagged up by Defender for Endpoint. I got the xml ones to work.

The integer valued one that is failing is this : ./Device/Vendor/MSFT/Policy/Config/LocalPoliciesSecurityOptions/NetworkAccess_DoNotAllowStorageOfPasswordsAndCredentialsForNetworkAuthentication Value = 1 But when configuring this one: ./Device/Vendor/MSFT/Policy/Config/LocalSecurityAuthority/ConfigureLsaProtectedProcess Value = 1 It shows up as succeeded, but if I look in the registry it has not changed the value that is already there. Currently value is 2. One of them works (one of the ones that need an integer value) and the other fails with remediation errors (-2016281112 / 0x87d1fde8). All of OAM-URI's where taken from the MS site. If someone knows how to get these working that would be greatly appreciated. Thanks

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Answer accepted by question author
  1. Crystal-MSFT 54,201 Reputation points Microsoft External Staff
    2024-02-06T02:16:04.73+00:00

    @Jason P, Thanks for posting in Q&A。 For the custom policy with OMA_URI with error, you can go to event viewer Applications and Services Logs > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostic-Provider > Admin to see if any error with it.

    For the setting which applied successfully but not working, I would like to confirm if there's any GPO set the same setting, Based as I know, if the same setting deployed via GPO, GPO will win over Intune policy.

    Please check the above information and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 13,426 Reputation points MVP
    2024-02-05T21:53:15.2033333+00:00

    Have you cheched Settings Catalog or Admin Tamples if they contain same setting? OMA-URI is the last method you want to use.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.