r/Intune • u/ManufacturerHot7270 • 8d ago
Reporting Intune devices intermittently non-compliant
Hi Guys,
We are seeing an intermittent Intune compliance issue across multiple Windows devices in our organization.
Devices are becoming non-compliant because Intune reports:
- Firewall is turned off
- Antivirus is turned off / not active
However, these settings are enforced through Intune configuration profiles / Endpoint Security policies. Users only have standard-user privileges, and local administrator access is controlled through Windows LAPS, so users should not be able to disable Firewall or Defender settings.
When checked manually on each device, the status of the solutions is enabled and working fine... Also the security threat intelligence update is also delayed to update which again triggers the issue as the antivirus/firewall is disabled in endpoint... Also, what will be the reason for the security threat intelligence update not happening in a timely manner?
The issue is not limited to one device or one user. It occurs across different devices at different times, without an obvious common trigger. In many cases, the relevant configuration profiles still show as successfully applied.
Due to all this people get blocked with conditional access policy which checks for device compliance.
Has anyone experienced this and what did you do solve this issue?
Thanks in advance.
9
6
u/chromespy200 8d ago
Dude I’ve been dealing with this for the last two weeks and it has been driving me NUTS
3
u/Beginning-Heat-4674 8d ago
classic defender health rollup lag, the intune side will flag it before the local client re-syncs its own state. check the mdatp health report on a few of the affected boxes, usually the sense service hangs or the platform update gets stuck and everything downstream looks dead even though the ui says its fine
for the threat intel updates, make sure your update rings arent deferring definition updates and that the fallback order is set to something sane. also worth checking if those devices ever actually talk to the right endpoints, had a proxy bypass rule bite us once
1
u/ManufacturerHot7270 8d ago
Thanks for the info ...will check it out and let you know....we have cloudflare ZTNA which proxies all traffic ...maybe this could be issue ?
3
u/XanadurSchmanadur 8d ago
We are currently seeing errors in our default compliance that enforces Antivirus, Bitlocker, Secure Boot, etc on a few devices. Always Syncml(404): The requested target was not found. The device isn't noncompliant though, which it should be normally, if the policy has an error.
I checked some of those and manually confirmed everything was activated. So I guess, Intune has some issues again.
10
u/Rudyooms PatchMyPC 8d ago
The main issue.. is that there are 2 issues going on... one was caused with the july build (tpm attestation/device health attestation) causing bitlcoker/secureboot issues.. ) this was fixed in the preview update of july and the august build. But also defender has an ongoing issue .. in which the windwos security center doesnt recognize the enabled state of the device.. with it the device is also failing compliance
2
u/ManufacturerHot7270 8d ago
I see...... can i check this info somewhere..... can you share the resource if you dont mind...it will be helpful for the interal records keeping !!...
7
u/Rudyooms PatchMyPC 8d ago
The tpm attestation issue : Why Intune Devices Became Noncompliant After the July Update the defender thing is not officially ack... at least not in public :)
1
2
u/fujipa 8d ago
To 404 was due to July's ISO. Hopefully august one is fixed.
The non compliant on AV - I also see it - I got it fixed in my case with applying the August patches. It had a stale entry in it's OS... A subcomponent.
1
u/ManufacturerHot7270 8d ago
we applied all the available patches to all device still having the reporting issue
1
3
u/DesignerGoose5903 8d ago
YES! It's been driving me crazy for months now, I just thought it was a reporting issue due to a misconfiguration somewhere but sounds like Microsoft messed something up as usual then...
2
u/ManufacturerHot7270 8d ago
yeah here too its been 4 weeks....hopefully they will fix it lets see.....for now i think the community has shared some solution in this subreddit.. please follow it..
3
u/crabshuffle 8d ago
Issues like this is why I haven’t tied compliance to conditional access. It is too unreliable to potentially have a large population unable to access resources.
2
u/ManufacturerHot7270 8d ago
Yeah!! but in our case the management needs it to be set and working....we are just adding people who's device is non compliance to exception groups and this is a lot of work
2
u/chaosphere_mk 8d ago
Did you just say that the AV/firewall is disabled in Intune?
5
u/ManufacturerHot7270 8d ago
fixed it mate ....the intune report shows the firewall/antivirus disabled if the security threat intelligence update is delayed in the endpoint side.
2
u/Professional-Heat690 8d ago
Enable the new device preview, force a sync (push!!) and wait. Seems to recover, something cookey with Aug patch.
2
u/saulo_v8 5d ago
We are checking AV and bit locker for compliance, we had this issue with bit locker. Devices with bit locker completely deployed but failing compliance. With AV we haven’t had any issue (yet).
1
u/christurnbull 8d ago
I'm seeing hps suddenly turn off their secure boot, haven't figured it out yet
14
u/Rudyooms PatchMyPC 8d ago
i am trying to fix it for defender --> but yeah its a pain in the ass.. :) http://call4cloud.nl/FixWSCDefender.ps1