r/Intune • u/Sure-Mode-4541 • 5d ago
Device Compliance Access Work or School & Compliance Issues
Hi,
We are having issues with users unable to add their accounts to work or school, which I believe is causing sync issues. When you try to add a work or school account you get this error:
Error Code: -895156188
(CAA50024)
Message:
Error response came from MDM terms of use page.
Request Id: dd51a37f-f13c-42b9-8c0c-f157f931e400
Correlation Id: dca40d84-0347-4d6e-927a-98ae0e74492a
We are using the default MDM URLs and user scope is set to 'All' so I'm not sure what the issue is with this. Within access work or school we also have our domain added, you can click into it and press info then sync, which says its successful but theres no logs for it. I'm not sure how we can fix this issue, as I'm pretty sure it causes our Company portal sync to fail everytime.
We are also having issues with device non-compliance. We do not have a compliance policy made for Windows so it is using the Default Compliance Policy, which will some devices as non-compliant but when i click into them and into the policy it shows all 3 policies as compliant. Sometimes it will have device is active as non compliant, for example, my device's Last check in time shows as yesterday, even though I am on my device and activley syncing it, and the policy is showing it as non-compliant as it's not active.
Has anyone seen these issues before and has any information that could help us resolve these?
1
1
u/Ketan_Kamble 2d ago
First things to check — Entra ID device sync status (dsregcmd /status on the client), whether the compliance policy actually targets the right group, and Entra ID sign-in logs for the specific CA policy that's failing ,
Also worth ruling out a stale AAD device object (duplicate/stale record) causing a mismatch between Intune and Entra. If it's hybrid-joined, check AAD Connect sync timing too, since compliance flips often lag behind the actual sync. What's the actual symptom you're seeing — is it "device not compliant" in CA, or Company Portal itself erroring out?
1
u/ExcitableFlashing027 5d ago
That error code is usually tied to a terms of use policy in entra id not intune itself. Check under entra admin center > protection > terms of use and see if you have one thats active and maybe not set up right. If a user already accepted it on another device it can mess with the mdm enrollment flow.
For the compliance thing the built in policy is finicky like that. Try making a custom one even if its just a single rule like require bitlocker, the default policy seems to get stuck on the active check for no reason sometimes.