I am currently in the process of trying to migrate my GPO settings to Intune and running into a few issues when I am using Device Configuration Profiles.
My test scenario is as follows:
Two Computers - PC1 and PC2 both with the same setup
- Windows 10.0.19044.1348
- Co-Managed with SCCM and Intune
- Intune Workload - Compliance Policies, Device Configuration, Client Apps
- Both are checking-in successfully
Multiple Users
- User1,User2 and User3 are setup as a Mail User in On-Prem Exchange
- User4, User5 and User6 are setup as Office 365 in On-Prem Exchange
- All six users have an Enterprise Mobility Security E3 license applied
Intune Configuration Profile Settings
- Setting 1 - Remove Change Password, Lock Computer, Task Manager from ctrl-alt-delete
- Setting 2 - Disable Control Panel, Registry, CMD, MMC
No GPO settings being applied except for Domain Password Policy (which is Enforced)
Here are the details when each user logs on to each computer
To help understand the table for example if User1 logs into PC1 he will get Setting 1 and Setting 2 applied, however if User 1 logs into PC2 he will only get Setting 1 applied.
I have already checked View Report and it shows it applied Successfully except for a blank logged in user. I also went to Troubleshooting and Support and got no info from there.
I been working on this for days trying to figure it out, and I thought it had to do with being a Mail User vs an Office 365 mailbox, but that didn't seem to make a difference. I am open to any suggestions on how to troubleshoot this.