How to Troubleshoot Windows 11 10 Intune MDM Issues 1

How to Troubleshoot Windows 11 10 Intune MDM Issues

This blog post teaches you how to Troubleshoot Windows 11 10 Intune MDM Issues. There are several options to troubleshoot, and some of them are explained here.

Windows 11 or 10 MDM issues and troubleshooting are pretty new for SCCM admins like me! So what is the importance of Windows 10 MDM? When you use Intune or SCCM + Intune hybrid to manage Windows 10 machines, all the management policies are deployed through the MDM channel. This post is Windows 10 MDM Troubleshooting Guide.

There could be many ways to troubleshoot Windows 10 MDM issues while using Microsoft Intune to deploy policies to those devices. In this post, I will share the 3 easy ways to start MDM troubleshooting. Yes, it’s different from the SCCM/ConfigMgr client’s way of troubleshooting, as there are no log files for the MDM client.

MDM client is in build with the Windows 10 operating system, and events logs are the best place to troubleshoot Windows 10 MDM issues. The 3rd way mentioned in this post is very easy for me and IT Pros to understand and start Windows 10 MDM troubleshooting. I have created a video to explain the troubleshooting tips, as you can see above.

[Related Posts – How to Start Troubleshooting Intune Issues]

Related Posts

Understand Windows 10 MDM Architecture

For example, if an Intune policy is deployed to a Windows 10 machine but is not getting applied, how do we start troubleshooting? First, we need to understand Windows 10 management architecture.

The following is the high-level architecture diagram for Windows 10 management. If we know this high-level architecture, troubleshooting Windows 10 MDM issues will be easy. This post will help us as a Windows 10 MDM Troubleshooting Guide.

How to Troubleshoot Windows 11 10 Intune MDM Issues - Fig.1
How to Troubleshoot Windows 11 10 Intune MDM Issues – Fig.1

Video Tutorial – Windows 10 MDM Troubleshooting Guide

Windows 10 MDM Troubleshooting Guide video tutorial to help IT Pros! This video teaches you how to fix problems with Windows 10 MDM (Mobile Device Management) using the registry, WMI (Windows Management Instrumentation), and Event Logs.

It breaks down troubleshooting into simple steps, showing you how to identify and solve issues with your device management. You can learn to resolve common problems efficiently by following along with the video.

How to Troubleshoot Windows 11 10 Intune MDM Issues – Video 1

Troubleshoot with Windows 10 Event Logs

Event Logs  :- Microsoft->Windows->DeviceManagement-> Enterprise-Diagnostics-Provider/Admin

Event logs in Windows 10 machines are the best to start troubleshooting MDM-related issues. As you can see in the below screen capture, you could be able to see where to go in events logs (Microsoft->Windows->DeviceManagement->Enterprise-Diagnostics-Provider/Admin) to see the details of the MDM and Device Management related issues. When the machine is Workplace Joined or AAD joined, all the events related to Intune/SCCM policies are recorded in “this” event log section.

AAD event logs are also very useful in this Windows 10 MDM issue, and you can check out the following location for AAD-related event logs: “Microsoft-Windows-AAD/ Operational”. Event logs are an integral part of the Windows 10 MDM Troubleshooting Guide.

The event logs are the best way to troubleshoot Windows 10 MDM issues. You will get the detailed status of Intune or SCCM hybrid policies from event logs. Each entry in those event logs will tell you whether or not the deployed policies are reached and applied on that machine. There is also a way to export the MDM log files to the folder “C:\Users\Public\Documents\MDMDiagnostics” from Windows 10 settings – connect to the work or school page.

[Related Posts – How to Start Troubleshooting Intune Issues]

How to Troubleshoot Windows 11 10 Intune MDM Issues - Fig.2
How to Troubleshoot Windows 11 10 Intune MDM Issues – Fig.2

Troubleshoot Windows 10 with WMI Explorer

WMI Explorer way of Checking whether the Policy Settings are Applied or Not:-

WMI Explorer is the best tool to check the MDM policies to confirm whether those settings are applied on the windows 10 system or not. As you can see in the following screen capture, this is how to check whether MDM policies are correctly applied to a Windows 10 machine.

I have deployed the Windows Defender policy from Intune to this Windows 10 machine, and you can use WMI explorer to find out whether these policies are applied on the machine or not. Again, when you start troubleshooting, the best place to begin with is event logs.

We can also check this via WBEMTEST, but we may need to start WBEMTEST from the system context to see the policy details. WMI Explorer is the best place to check and confirm whether the MDM policies (from Intune or SCCM) have been applied to a machine.

[Related Posts – How to Start Troubleshooting Intune Issues]

Registry way of Checking Windows 10 MDM Policy Settings

Troubleshoot Windows 10 with Registry Entries

The 3rd and easiest way to check whether the MDM policies are applied to a Windows 10 machine is the registry key. Following is the registry location where you can find MDM policy settings. You want to check for MDM policy settings on Windows 10 machine is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers

In this below screen capture, you can see the Windows Defender settings I applied to Windows 10 machines through Intune policies. The only caveat of this method is we need to find out a way to decode each provider GUID (CLSID Key?) related to MDM policies. Following are some of the extracts from my Windows 10 machine:-

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\18dcffd4-37d6-4bc6-87e0-4266fdbb8e49 - Power Policy Settings Buttons

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\1e05dd5d-a022-46c5-963c-b20de341170f - Power Policy Controls Energy

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\23cb517f-5073-4e96-a202-7fe6122a2271 - Power Policy Settings Disaplay

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\2648BF76-DA4B-409A-BFFA-6AF111C298A5 - ?

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\268c43e1-aa2b-4036-86ef-8cda98a0c2fe - ? Power Policy Settings PCI Express

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\2AB668F3-6D58-4030-9967-0E5358B1B78B - Microsoft Intune MDM Policy Settings - Account, Bitlocker, Connectivity, Data Protection, Defender, Device Lock, Experience, Network Isolation, Security, System, update and WiFi

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\Providers\C8DC8AF6-2A7D-4195-BA77-0A4DAC2C05A4 - Microsoft Intune/SCCM MDM policy settings - Browser, Camera, Connectivity, Device Lock, Security, Systems and Wifi
  • System > Power Management > Button Settings
  • Select the Start menu Power button action (on battery)
  • Select the Start menu Power button action (plugged in)
  • Select the Start menu Power button action (plugged in)
  • Enabled – Select the Start menu Power button action (on battery).
Steps
System > Power Management > Button Settings
Select the Start menu Power button action (on battery)
Select the Start menu Power button action (plugged in)
Select the Start menu Power button action (plugged in)
Enabled – Select the Start menu Power button action (on battery).
How to Troubleshoot Windows 11 10 Intune MDM Issues – Table 1
How to Troubleshoot Windows 11 10 Intune MDM Issues - Fig.3
How to Troubleshoot Windows 11 10 Intune MDM Issues – Fig.3

Troubleshoot Windows 10 with MDMDiagReport

These GUID IDs can be found in the MDMDiagReport.xml file, and this XML can be decoded into HTML file MDMDiagReport.html using the tool.

How to Troubleshoot Windows 11 10 Intune MDM Issues - Fig.4
How to Troubleshoot Windows 11 10 Intune MDM Issues – Fig.4

[Related Posts – How to Start Troubleshooting Intune Issues]

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

SCCM ConfigMgr Current Branch Backup Recovery Options 3

SCCM ConfigMgr Current Branch Backup Recovery Options

Let’s discuss the SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager. This post contains a collection of video tutorials that I created last year to help you better understand the backup and recovery process of the SCCM ConfigMgr Current Branch (CB).

As part of the website revamp, I checked whether the posts were okay, and this series of SCCM/ConfigMgr CB backup and recovery posts came to my attention. SCCM ConfigMgr Current Branch Backup Recovery Options?

These videos should give you an overview of the entire backup and recovery process, with different scenarios, such as restoring with a full native SCCM ConfigMgr CB backup.

Also, backup and restore only using SQL backup, etc..CD.LATEST folder is another big change in the backup and recovery process if you compare SCCM 2012 and SCCM CB. I wish that none of us (SCCM Admins) should be in a situation where we must restore our site from backup! But be ready for the worst case.

How to Recover or Restore the SCCM CB Primary Server using SQL Database Backup

In this video, I’ll show you how to restore your SCCM CB 1606 primary server, especially if you’re using Intune Hybrid, using an SQL database backup. The key is that you don’t need a full backup of SCCM CB to get your primary server back up and running.

SCCM ConfigMgr Current Branch Backup Recovery Options – Video 1

Introduction – SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager

The following are the posts you can refer to for each scenario. I’m still planning to create the last couple of videos in this series, which will cover the backup and restore of the SCCM/ConfigMgr CB CAS server either from native SCCM backup or from SQL backup.

How to Plan Backup and Recovery for SCCM ConfigMgr CB

SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager? This post contains a collection of video tutorials that I created last year to help you better understand the backup and recovery process of the SCCM ConfigMgr Current Branch (CB).

As part of the website revamp, I checked whether the posts were okay, and this series of SCCM/ConfigMgr CB backup and recovery posts came to my attention.

CD.LATEST?

These videos should give you an overview of the entire backup and recovery process, with different scenarios, like restoring with a full native SCCM ConfigMgr CB backup, backup and restore only using SQL backup, etc. The CD.LATEST folder is another big change in the backup and recovery process if you compare SCCM 2012 and SCCM CB.

I wish we (SCCM Admins) would never be in a situation where we must restore our site from backup, but be ready for the worst case.

SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager - Fig.1
SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager – Fig.1

The following are the posts you can refer to for each scenario. I’m still planning to create the last couple of videos in this series, which will cover the backup and restore of the SCCM/ConfigMgr CB CAS server either from native SCCM backup or from SQL backup.

How to Plan Backup and Recovery for SCCM ConfigMgr CB

SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager? More details in the following link https://www.anoopcnair.com/what-are-the-options-for-sccm-cb-1606-backup-and-recovery/

How to Restore or Recover SCCM ConfigMgr CB Standalone Primary Server

This video tutorial explains restoring or recovering an SCCM/ConfigMgr CB standalone primary server. Some prerequisites are needed to ensure a smooth and successful recovery of your SCCM/ConfigMgr CB standalone primary server. It helps maintain consistency and compatibility with your existing setup.

How to Recover SCCM CB Primary Server Using SQL Database Backup 

SCCM ConfigMgr Current Branch Backup Recovery Options | Configuration Manager | Endpoint Manager? The following Link will have more details – https://www.anoopcnair.com/how-to-recover-sccm-cb-primary-server-using-sql-database-backup/

More details in the following link https://www.anoopcnair.com/what-are-the-options-for-sccm-cb-1606-backup-and-recovery/

How to Recover SCCM CB Primary Server Using SQL Database Backup 

The following Link will have more details – https://www.anoopcnair.com/how-to-recover-sccm-cb-primary-server-using-sql-database-backup/
https://www.youtube.com/embed/4aZFSPI3x1I

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

SCCM Online Service Connection Point Details - 2 Options 5

SCCM Online Service Connection Point Details – 2 Options

Let’s discuss the SCCM Online Service Connection Point Details – 2 Options. Microsoft released a new SCCM Current Branch version, SCCM CB 1610. If you are running SCCM CB 1511, 1602, or 1606, you can directly upgrade to SCCM CB 1610. This post and video provide more details about SCCM ConfigMgr CB Updates in Console and Upgrade.

SCCM Upgrade Process The ConfigMgr CB upgrade process via updates and servicing channel is very straightforward if you have an ONLINE service connection point mode.

If you are running an offline service connection point mode, you must perform manual ways to get the latest SCCM CB 1610 updates available in your SCCM CB console.

This post provides all the details about the SCCM Online Service Connection Point Details—2 Options. For SCCM CB infra with an online service connection point, the SCCM CB 1610 update will automatically appear in the console once Microsoft has released this for “slow ring“.

SCCM Online Service Connection Point

Now (18th Nov 2016), Microsoft released SCCM CB 1610 updates only for the “fast ring,” which can be enabled only by running a PowerShell script provided in the following link.

Download_SCCM_ConfigMgr_1610_Updates
SCCM Online Service Connection Point Details – 2 Options – Fig.1

SCCM Servicing Flowchart 

Let’s discuss the SCCM Servicing Flowchart. The screenshot helps you show the updates and servicing download process. The flow chart documentation is here.

Updates and Servicing Download Process
Service Connection Point
Hierarchy Manager
The hierarchy Manager checks the applicability of the package
Is the package applicable?
DMP Downloader downloads the payload and redist files
The hierarchy Manager checks the applicability of the package
SCCM Online Service Connection Point Details – 2 Options – Table 1
SCCM Online Service Connection Point Details - 2 Options - Fig.2
SCCM Online Service Connection Point Details – 2 Options – Fig.2

How Did I Upgrade ConfigMgr SCCM CB 1602 to 1606

This is a 1-minute video that tells you how to start the SCCM CB 1610 upgrade process once the updates are available in the CM CB console. I have already covered the end-to-end SCCM CB upgrade process in a video here (even though that is about the CM 1606 upgrade, the process is similar).

SCCM Online Service Connection Point Details – 2 Options – Video 1

Start the Upgrade Process from the Console

I’m sharing the video tutorial about upgrading the SCCM ConfigMgr CB 1610 console. Before initiating the SCCM ConfigMgr CB console upgrade process, you must complete all the reset activities for site system roles (sitecomp.log gives you more ideas). Otherwise, there could be more chances of failures during the SCCM CB console upgrade.

SCCM Console Upgrade

Let’s discuss the SCCM Console Upgrade. The below section shows the SCCM Console Upgrade details.

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch 6

Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch

Let’s discuss the Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch. SCCM ConfigMgr’s current branch (CB) XXXX was released last Friday (18th Nov 2016).

SCCM CB YYYY has many features, and the upgrade process via updates and servicing channels is straightforward. You are done with the SCCM CB 1610 upgrade with just a couple of clicks.

You can directly upgrade your SCCM CB 1511 server to 1610. You do not need to go through all the other upgrades (1602 /1606) available in your SCCM CB console. The blog post with more details is available here.

This post will share a comparison video of SCCM CB 1606 and 1610 features. The features discussed in the video below are essential for upcoming changes to SCCM ConfigMgr CB.

How Did I Upgrade ConfigMgr SCCM CB 1602 to 1606

The video tutorial below explains how I Upgraded ConfigMgr SCCM CB 1602 to 1606.

Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch – Video 1

Feature Comparison Between SCCM ConfigMgr CB Versions

The configuration and compliance policy updates are critical if you use a hybrid SCCM CB version to manage mobile devices and domain-joined machines. I think the SCCM team invested loads of time in improving the features of their product.

Feature Comparison Between SCCM ConfigMgr CB Versions
SCCM ConfigMgr 1606 and 1610
Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch – Table 1
Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch - Fig.1
Feature Comparison Between SCCM ConfigMgr CB Versions | Configuration Manager Current Branch – Fig.1

Feature Comparison Between SCCM ConfigMgr CB Versions

SCCM CB is moving away from old-fashioned boundary-setting, such as fast and slow boundaries. Rather, investing more in current and neighbor boundary groups. This will help to evolve the product further in upcoming versions.

A version of SCCM 1610 feature comparison includes Boundary groups

  • current and neighbor boundary groups, Improvements on Windows Store for business,
  • Cloud Management Gateway (internet client management),
  • Immediate Policy sync for Intune-enrolled devices,
  • Changes in Configuration and compliance policies,
  • Lookout integration with SCCM CB 1610,
  • Client Peer cache settings – client peer cache dashboard,
  • enforcement of grace period,
  • Content size filter in Software update ADR and monitoring of loads of components have been updated,
  • And new dashboards have been included.

List of Feature Comparison Between SCCM ConfigMgr CB Versions

New Features as part of SCCM CB 1610 updates and servicing. Boundary Changes – Improvements for boundary groups – current boundary group vs neighbor boundary groups.

  1. Improvements Windows Store for Business  – Modify the client secret key and delete a subscription to the store from the SCCM Console.
  2. Cloud management gateway for managing Internet-based clients – Cloud management gateway provides a simple way to manage Configuration Manager clients on the Internet.
  3. Immediate Policy sync for MDM channel Intune-enrolled devices.
  4. Configuration policies – New policies included in SCCM CB 1610 – Android (23), iOS (4), Mac (4), Windows 10 desktop and mobile (37), Windows 10 Team (7), Windows 8.1 (11), and Windows Phone 8.1 (3).
  5. Compliance Policies settings improvements -Lookout integration compliance Policies
  6. The Windows 10 Edition Upgrade Policy can be applied for SCCM CB 1610. It is now available for Intune and SCCM clients.
  7. Client Agent—Client Peer Cache helps you manage content deployment to clients in remote locations. Peer Cache is a built-in SCCM solution that allows clients to share content directly from their local cache. To share content, enable the Configuration Manager client in full OS. Yes.
  8. Customizable Branding is also included in the SCCM CB 1610.
  9. The enforcement grace period is an excellent feature of SCCM CB 1610.
  10. Another nice feature included in SCCM CB 1610 Software Update ADR is Content Size.
  11. Monitoring – Compliance policies Dashboard and Client Data Source Dashboard.

Resources

SCCM Dynamic Collection – Part 2 | WQL Query | ConfigMgr | Create HTMD Blog (anoopcnair.com)

Validate Azure AD Dynamic Group Rules | Intune

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.