mattfarnell Posted June 9, 2025 Posted June 9, 2025 We have been using intune for a while now but only for MDM stuff, not really main stream computers. As we are looking to expand i've been testing new policies and restrictions and the such. When i started looking at Intune, i was told under no circumstances do i log on with this account. (call it accountx for reference). The account is well known for stripping Intune policies of the device and leaves it in a state where it can only be fixed by autopilot reset. By accident last week, i logged on to a device as accountx and sure enough i've had to autopilot it just to make it work again. Is this something that someone may have set up or broken somewhere in Intune? It's the only account known on our network to do this. A sensible person would disable or not use that account however it's one of our "special" accounts so can't really do that. Any help would be much appreciated
bicky Posted June 9, 2025 Posted June 9, 2025 Please check under Devices >> Manage devices >> Scripts and remediations >> there may be script targeted to this particular user?
mattfarnell Posted June 9, 2025 Author Posted June 9, 2025 Just checked and there's nothing pointing to that user directly. As a bit of a test, i built a clean environment no policies or scripts assigned to the device. I gave it a wallpaper and it worked as a normal user. I logged on as accountx and it removed it. almost like it's a user setting somewhere that says "Will not use policies". It's very odd.
Smokebomb Posted June 9, 2025 Posted June 9, 2025 We've had something similar going on, but discovered the accounts in question did not have the "Intune plan 1" license assigned to them in the MS365 admin centre. Once we assigned that license to them the issue was resolved. Maybe something similar with this account?
mattfarnell Posted June 9, 2025 Author Posted June 9, 2025 i've just assigned it a license. it did have one however it wasn't a full one. Lots of components were unticked. I'll report back if it cures it. Thanks
mjhardisty Posted June 9, 2025 Posted June 9, 2025 Interested to what the device state is after a user has logged in that it can't be used? Have you tried something like the Intune Assignment Checker to see exactly what configurations that user has: https://intuneassignmentchecker.ugurkoc.de/
mattfarnell Posted June 9, 2025 Author Posted June 9, 2025 i can only describe the state as loss of all policies and not actually useable. It does break windows when t does it. It broke the logon screen last time i did it. The laptop started up and gave me the standard wallpaper but nothing on it, so it removed all the settings but didn't restore defaults. Just had a look at the above, we block powershell and cmd so i'll have to have a play about with the computer policy to allow it through. It's a nice idea though. Basically like a GP result
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now