Scripts are running on our devices that have been unassigned. How to track them down?

Batman, John 1 Reputation point
2020-11-18T22:11:33.353+00:00

We have checked thoroughly that our test devices are not part of any other groups. We waited time between unassigning the script. We have a few scripts it seems that always show up in our intunepowershell.log that should not be running. It has become important now for us to resolve this nagging issue. Thanks for any suggestions!

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,768 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,282 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 44,851 Reputation points Microsoft Vendor
    2020-11-19T03:05:09.313+00:00

    @Batman, John , From your description, it seems that our issue is the script is still running on the device after we remove the devices from the assigned group. If there's any misunderstanding, feel free to let us know.

    For our issue, we suggest to choose one affected device, Go to Settings->Accounts->Access work or school, and sync policy on our account. Afterwards, restart the affected device and see if the script is still running. Meanwhile, check the device status for this affected device in Intune portal to see if the device record will disappear.

    Please try the above steps and if there's any update, feel free to let us know.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Batman, John 1 Reputation point
    2020-11-19T14:21:23.38+00:00

    Thank you for the suggestions. I have sync'd the computer, fresh started, reimaged a clean 2004 Windows, removed it from Intune and Autopilot by deleting account and hash. It happens on multiple computers as well. Somewhere in our system this script which disables ipv6 in a way we would like to change is still being called to run during enrollment. I was wondering if there was some script I could run to check for all instances of the script in our MEM console. Thanks again, working on this today.


  3. Aravinth Mathan 321 Reputation points
    2020-11-20T19:14:29.237+00:00

    Hi @Batman, John

    By any chance is there any powershell script that is assigned to a dynamic group. That's the only possible way a device could get it even after fresh re-enrollment.

    0 comments No comments