T The Triage ManualTechnical Guides for IT Emergencies
P2 · Endpoint & Device Management

Intune MDM/Configuration Policy Not Applying to Enrolled Devices

Configuration profiles or compliance policies enrolled via Microsoft Intune fail to apply to Windows/iOS/Android devices despite successful enrollment. Commonly caused by assignment scope gaps, CSP conflicts between profiles, or devices failing to check in.

Indicators

Likely causes

Diagnostic steps

  1. Intune portal > Devices > select device > Configuration profiles — review per-profile status and error codes
  2. Verify group membership: confirm device or user is in the AAD group assigned to the policy
  3. Force sync from portal: Devices > select device > Sync; or on device run: Start-Process 'C:\Windows\System32\deviceenroller.exe' -ArgumentList '/o'
  4. Check MDM logs: Event Viewer > Apps and Services > Microsoft > Windows > DeviceManagement-Enterprise-Diagnostics-Provider > Admin
  5. Collect full MDM diagnostics: MdmDiagnosticsTool.exe -out C:\MDMLogs — zip and review CAB
  6. If multiple profiles conflict: identify which CSPs overlap, consolidate into a single profile or use Settings Catalog to detect conflicts

Resolution path

Prevention

Tools

intunemdmconfiguration-profileendpoint-managementmicrosoft-intunecsp