Intune Device Configuration Profiles Not Working

Prescimone, Chris 121 Reputation points
2021-11-18T20:04:31.59+00:00

I am currently in the process of trying to migrate my GPO settings to Intune and running into a few issues when I am using Device Configuration Profiles.

My test scenario is as follows:

Two Computers - PC1 and PC2 both with the same setup

  • Windows 10.0.19044.1348
  • Co-Managed with SCCM and Intune
  • Intune Workload - Compliance Policies, Device Configuration, Client Apps
  • Both are checking-in successfully

Multiple Users

  • User1,User2 and User3 are setup as a Mail User in On-Prem Exchange
  • User4, User5 and User6 are setup as Office 365 in On-Prem Exchange
  • All six users have an Enterprise Mobility Security E3 license applied

Intune Configuration Profile Settings

  • Setting 1 - Remove Change Password, Lock Computer, Task Manager from ctrl-alt-delete
  • Setting 2 - Disable Control Panel, Registry, CMD, MMC

No GPO settings being applied except for Domain Password Policy (which is Enforced)

Here are the details when each user logs on to each computer

150783-image.png

To help understand the table for example if User1 logs into PC1 he will get Setting 1 and Setting 2 applied, however if User 1 logs into PC2 he will only get Setting 1 applied.

I have already checked View Report and it shows it applied Successfully except for a blank logged in user. I also went to Troubleshooting and Support and got no info from there.

I been working on this for days trying to figure it out, and I thought it had to do with being a Mail User vs an Office 365 mailbox, but that didn't seem to make a difference. I am open to any suggestions on how to troubleshoot this.

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments

Answer accepted by question author
Rahul Jindal 11,721 Reputation points
2021-11-19T13:04:10.703+00:00

"For both Setting 1 and Setting 2, the Intune Configuration Profiles are all being to Device Groups." - I will suggest to deploy against user based groups.

"They are Hybrid devices, however I blocked Inheritance for test purposes to ensure there are no GPO conflicts." - Check in the MDM diagnostics report if the settings from Intune are applying. I will still suggest to use MDMwinoverGPO CSP to ensure that MDM policies take precedence.

"I can confirm that the Configuration Profiles are showing "Succeeded" for all users." - Doesn't always mean that the settings are applying as intended.

Was this answer helpful?

0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Prescimone, Chris 121 Reputation points
    2021-11-19T13:50:32.367+00:00

    @Rahul Jindal thanks for the info. I will work on this with User Groups and use Filters. Hopefully I have more success.

    Was this answer helpful?

    0 comments No comments

  2. Prescimone, Chris 121 Reputation points
    2021-11-19T12:57:52.56+00:00

    @Rahul Jindal and @Lu Dai-MSFT to answer your questions:

    1. For both Setting 1 and Setting 2, the Intune Configuration Profiles are all being to Device Groups.
    2. They are Hybrid devices, however I blocked Inheritance for test purposes to ensure there are no GPO conflicts.
    3. I can confirm that the Configuration Profiles are showing "Succeeded" for all users.

    I am trying to avoid using Filters and work with Device Groups, but not sure that will be an option.

    Was this answer helpful?

    0 comments No comments

  3. Lu Dai-MSFT 28,536 Reputation points
    2021-11-19T06:38:46.797+00:00

    @Prescimone, Chris Thanks for posting in our Q&A.

    To clarify this issue, we appreciate your help to collect some information:

    1. Which group did you assign these two configuration profiles? User group or device group?
    2. If it is a user group, please make sure that you use the user included in the target user group to login in the device.
    3. From your description, did you mean that these configuration profiles are successfully deployed to all the target users? For User1's situation, please check if the User1's deployment status shows "succeeded" in its setting 2 configuration profile.

    If there is anything update, feel free to let us know.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?

    0 comments No comments

  4. Rahul Jindal 11,721 Reputation points
    2021-11-18T21:55:41.597+00:00

    Are the Device Config policies assigned to device based group or users? Also, if the devices are Hybrid joined then you may want to throw in the CSP of MDM win over GPO policy just to make sure that MDM policies you deploy takes precedence over GPO.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.