Application Guard status is error, even it is enabled

Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
2021-12-05T11:12:50.107+00:00

From a machine, I locally see that Application Guard mode is enabled to Edge browser, but the Intune configuration policy has errors. Has anyone succeed in this? I see few other similar posts about same issue. I enabled Application Guard via ASR.

Microsoft Security Intune Configuration
Microsoft Security Intune Other
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Simon Ren-MSFT 40,341 Reputation points Microsoft External Staff
    2021-12-06T08:56:10.13+00:00

    Hi,

    Thanks for posting in Microsoft Q&A forum.

    It's a little strange now. Please help check below event logs under Applications and Services Logs to see if we can find any useful information:
    Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provide
    Microsoft-Windows-WDAG-PolicyEvaluator-CSP
    Microsoft-Windows-Windows Defender-Operational

    Thanks for your time.

    Best regards,
    Simon


    If the response is helpful, please click "Accept Answer" and upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
    2021-12-08T07:53:35.9+00:00

    There are some or a lot errors in different Event Viewer nodes you mentioned, but nothing specific I can grap on. Some of errors are very cryptic so I don't understand what they are about. This event viewer "chaos" is a problem releated to MDM, which makes them partly unreadable without specific experience. Troubleshoting Group Polcies with Event Viewer was a lot easier.

    0 comments No comments

  3. Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
    2021-12-08T18:40:52.89+00:00

    Both, from new Security node and from old Configuration Profile \ Endpoint Protection, the App Guard deployment status goes read, even if all machines are actually using it. The feature is installed and Edge browser has new feature.

    0 comments No comments

  4. Pavel yannara Mirochnitchenko 13,331 Reputation points MVP
    2021-12-09T05:55:48.133+00:00

    @Simon Ren-MSFT I discovered few things.

    1. In event viewer I see this all the time:

    156119-image.png

    1. All these settings are really off, even they are set to on in Intune.

    156183-image.png


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.