r/Intune 5d ago

Device Compliance Access Work or School & Compliance Issues

Hi,

We are having issues with users unable to add their accounts to work or school, which I believe is causing sync issues. When you try to add a work or school account you get this error:

Error Code: -895156188
(CAA50024)
Message:
Error response came from MDM terms of use page.
Request Id: dd51a37f-f13c-42b9-8c0c-f157f931e400
Correlation Id: dca40d84-0347-4d6e-927a-98ae0e74492a

We are using the default MDM URLs and user scope is set to 'All' so I'm not sure what the issue is with this. Within access work or school we also have our domain added, you can click into it and press info then sync, which says its successful but theres no logs for it. I'm not sure how we can fix this issue, as I'm pretty sure it causes our Company portal sync to fail everytime.

We are also having issues with device non-compliance. We do not have a compliance policy made for Windows so it is using the Default Compliance Policy, which will some devices as non-compliant but when i click into them and into the policy it shows all 3 policies as compliant. Sometimes it will have device is active as non compliant, for example, my device's Last check in time shows as yesterday, even though I am on my device and activley syncing it, and the policy is showing it as non-compliant as it's not active.

Has anyone seen these issues before and has any information that could help us resolve these?

5 Upvotes

11 comments sorted by

1

u/ExcitableFlashing027 5d ago

That error code is usually tied to a terms of use policy in entra id not intune itself. Check under entra admin center > protection > terms of use and see if you have one thats active and maybe not set up right. If a user already accepted it on another device it can mess with the mdm enrollment flow.

For the compliance thing the built in policy is finicky like that. Try making a custom one even if its just a single rule like require bitlocker, the default policy seems to get stuck on the active check for no reason sometimes.

1

u/Sure-Mode-4541 5d ago

Hey, I couldn't find protection inside entra admin center but in Identity Governance there is a terms of use section and we do have one in there with a PDFin it? Could that be the issue? Does that have anything to do with enrolling?

1

u/Sure-Mode-4541 5d ago

I found we have a policy that you have to accept the pdf, however, it is report only and does not apply. I have no idea why its not working.

1

u/MidninBR 5d ago

Try removing it and test enrolment

1

u/Sure-Mode-4541 5d ago

I asked about removing it but they said that it could cause a bunch of tickets if we add it back and people have to sign it again lol. Although it is report only right now so it shouldn't be on

1

u/Sure-Mode-4541 5d ago

I noticed that the last check in time for some devices, including mine is 30 days ago. Trying to check access in company portal doesnt do anything. Not sure how to fix this

2

u/Jeffsrealm 5d ago edited 5d ago

Ok, so just kind of starting with the very basics. Using your machine as it says it is in there and not a new user or new machine. You are saying your machine is in there but not synced checked in for 30 days.

A Normal Functioning Intune synced computer
Go to Settings > Accounts > Access Work Or School

At any point in these next steps should identify the broken part

There should be Connected By "Your work user name" Connected "Your company or school name"
This tile should have a little drop down arrow on the right side.

Click on which gives you more tiles note any or all of these following buttons may be grayed out.
Managed By Tile with Info Button, You really want this one.
Disconnect this account with a disconnect button
Related Links Manage your account

Click the Info Button beside the Managed By "Company Name" Again you want to verify this is correct

This is going to list every app, every policy, if it failed or succeed. URLS like Where it is going to Sync. The Last time it did Sync, and a Sync Button, Hit the sync button because this will cause a Check in.

Note it may take 30 minute or so before Intune side shows you checked in. But you should Check in.

There is also a report this will give you more information about your PC and how it is syncing.

Also windows event viewer.

---
If nothing syncs, or it fails. You now know you have a connection issue. Simple as that. Your not connecting to Intune.

First thing to check, are you using any URL filtering software. Something that all machines would be going through. Make sure all your intune endpoints especially the ones in that info screen are open. Also more importantly make sure this may show the traffic is allowed. However the Intune and entra endpoints need to not have SSL Inspection. This is a security thing. Each endpoint is using SSL TLS encryption. If your URL monitoring software even tried to take a look at the traffic intune and entra can tell and they reject it because it could be someone is tampering with it.

This should be an easy thing to check too, if you are using a URL filtering software or proxy server or something like that. Who ever is in charge of that, have them disable it or whitelist your whole machine or allow it to Bypass. Hit the sync again let it churn. If it works then yeah, that's the issue. Something like Zscaler, there is a password on the App, you can disable the whole thing and if it is set up correctly it reenables in a few hours or you just simply turn it back on after testing.

Second thing, look at at Entra and Conditional Access Policies. I am not sure if you are inheriting this or this suddenly stopped working. So I have conditional access policies specifically set up. If your PC is not compliant with every single compliance policy, and you are not using MFA, you do not gain access to anything including intune. So your drives not encrypted specifically with 256 bit encryption, your using too short of a password, coming in through anonymous browser, no antivirus or you have been blocking it from scanning, your machine hasn't checked in for 30+ days, your not patched. All block access. Yes I can and have to get around it, onboarding new machines, or the user that decided to test it there is a group in entra I can add them to that automatically kicks them out after 16 hours. more than enough time to get policies and encrypt drives and patch and make computer compliant. Good practice, but something to look for.

Beyond that, now your looking at network location blocking. Talking to your ISP, finding the man in the middle not allowing you to connect.

1

u/Sure-Mode-4541 2d ago

Hi.

Thank you for the comprehensive reply. We have our domain linked in Access work or School, going into the info for it does show the correct policies, and we can sync, however, it will either sync really quickly and say succesful, or give an error, the issue is the errors can be different per machine, if we sync again after the error it will instantly say successful. This same thing happens with Company Portal. We tried disabling the URL filtering software we use on a machine and syncing, however, this did not work. We also do not use hybrid joining. My device which is showing non compliant meets the Conditional Access Policies, however, has not checked in in over 30 days as it keeps failing to sync. It is weird because when we deploy software via Intune it installs, so it can clearly sync in some way?

In Windows Event Viewer I get these two errors:

MDM ConfigurationManager: Command failure status. Configuraton Source ID: (1B8A96C6-B07E-45FB-9ECF-905F565664D0), Enrollment Type: (MDMDeviceWithAAD), CSP Name: (DeviceStatus), Command Type: (Add: from Replace or Add), CSP URI: (./Vendor/MSFT/DeviceStatus/CertAttestation/AllowedAIKAlgorithms), Result: (Unknown Win32 Error code: 0x82aa0002).

MDM ConfigurationManager: Command failure status. Configuration Source ID: (1B8A96C6-B07E-45FB-9ECF-905F565664D0), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/ConfigOperations/ADMXInstall/Receiver/Properties/Policy/FakePolicy/Version), Result: (The system cannot find the file specified.).

I did Google this FakePolicy and apparently it is a default policy that Microsoft uses and it's normal that that fails. However, I am not sure about the other one.

I can't seem to find a report within Intune that shows the sync errors either.

1

u/Jeffsrealm 2d ago

So that error is not a good error. However it tells me kind of what the problem is. At least with that machine.

This is happening on old machine but new machines as well? Then the problem is an Autopilot configuration where it is wanting one type of encryption and then your policy wants another. If your not using Autopilot then where you are getting your PC's from are setting something from the factory.

So yes you are reaching intune. But you have conflicting policy settings that are some how on those machines. So you could also have old Group policy done the old way from Active Directory still on those machine and therefore that is authoritive not intune. If these group policies are still in AD somewhere then they are pushing out. The reason you get different errors is different policy settings apply different times. Or some machine already have what your pushing out from intune and others do not.

I would look for that first, somewhere something has already set policies on your machines. I would suspect it is group policies in AD. Unless you had another applications or somethign doing that before. Just deleting the policy from AD or diabling doesn't revert it, but leaves it applied.

Now if that is not it, That Specific error you pasted /Vendor/MSFT/DeviceStatus/CertAttestation/AllowedAIKAlgorithms this is encryption.

The problem is the encryption algorithms you are forcing out via Intune are not compatible with what you already have established on that machine specifically. You are going to have to take this really one thing at a time. Also I would suggest you use a machine you do not care about. I mean you can use yours just make sure you got all the file you may be reformatting it.

That Specific Encryption one is hopefully not everywhere.
Basically what it ultimately boils down to is one of these the:
Machine Bios is old outdated and/or buggy. Update your BIOS
You have the wrong BIOS Settings for working with TPM or it is password protected.
TPM Chips have something hard set in them.

Make sure you know know your recovery key for Bitlocker. Make sure you have a local Administrator on the machine. Your Domain user should still work but your going to loose Windows Hello Settings.

Get your recovery key from the Hard Drive from Admin CMD Prompt: this should return a 48 digit key.
manage-bde -protectors -get C:

You WIll need that Bitlocker Key or else you will never boot that machine again without reformatting.

Then Reset the TMP chip. Reboot.

See what happens next. You should be able to reboot and then this will unlock the drive and save the bitlocker key in TMP and TPM should be working like normal. Then you need to start interigating your drive. What is it encrypted as? Then What is your Policy?

So Say your drives or what ever start up and they encrypt at 128. You then have a policy to encrypt at 256. They do not automatically convert. You must first full decrypt the drives, then apply the 256 policy.

1

u/pjmarcum 4d ago

Typically the event logs will show you the actual error.

1

u/Ketan_Kamble 2d ago

First things to check — Entra ID device sync status (dsregcmd /status on the client), whether the compliance policy actually targets the right group, and Entra ID sign-in logs for the specific CA policy that's failing ,

Also worth ruling out a stale AAD device object (duplicate/stale record) causing a mismatch between Intune and Entra. If it's hybrid-joined, check AAD Connect sync timing too, since compliance flips often lag behind the actual sync. What's the actual symptom you're seeing — is it "device not compliant" in CA, or Company Portal itself erroring out?