Forum Discussion

MaxMorsia's avatar
MaxMorsia
Brass Contributor
Mar 30, 2023

Endpoint privilege management, deployment unsuccessful with "device health monitoring" error

Hello all, I'm testing Endpoint privilege management on a few machines in a test environment. The elevation settings policy isn't deploying when "send data to microsoft" is selected, the error received mentions an "Allow Device Health Monitoring" error, but that settings is correctly deployed via configuration profiles. Also can't find any info about that in the logs.

If I deselect "send data to microsoft" then the policy is deployed successfully, but in reality the app is not installed on the target devices (so no right click options about EPM). Anyone facing the same issue, and what steps could we try to fix it?

    • dye_lucky's avatar
      dye_lucky
      Copper Contributor
      It's sad, but yeah, I think we will need to wait. So far, I've seen this work or not work with no rhyme or reason....I've AutoPiloted 2 PC's recently and was enabled, but the other one didn't...
  • MaxMorsia I also do not seem to get this working on any of my ARM64 based devices like the Surface Pro X or Surface Pro 9 LTE.

    On Intel devices it seems to work.

  • dye_lucky's avatar
    dye_lucky
    Copper Contributor

    MaxMorsia same things are happening on my tenant:


     

    Please note that I'm testing with a Surface Pro X (2nd gen).

    • dye_lucky's avatar
      dye_lucky
      Copper Contributor

      *UPDATE* seemed to work perfectly on my Intel device [Dell].  🫤

  • Ztdid's avatar
    Ztdid
    Copper Contributor
    The exact same issue is occuring on my Dell 3310 laptops.
    • Ztdid's avatar
      Ztdid
      Copper Contributor
      I even went into the settings catalog and there is a setting called Device Health, I pushed that to my device with the same reults.
  • I assume you arent blocking telemetry? AllowTelemetry
    SOFTWARE\Policies\Microsoft\Windows\DataCollection

    And this service isnt disabled?
    Connected User Experience and Telemetry.

    What does this reg key tells you?
    HKEY_LOCAL_MACHINE\software\microsoft\policymanager\current\device\DeviceHealthMonitoring
    • Ztdid's avatar
      Ztdid
      Copper Contributor
      Connected User Experience and Telemetry is running

      SOFTWARE\Policies\Microsoft\Windows\DataCollection I see this key Allow Telementary Policy Manager value 3

      HKEY_LOCAL_MACHINE\software\microsoft\policymanager\current\device\DeviceHealthMonitoring I see 12 keys , do you have keys to refernce to see if the values are correct?
    • MaxMorsia's avatar
      MaxMorsia
      Brass Contributor

      Hi,
      regarding the first nest, AllowTelemetry_PolicyManager is = 1
      same goes for AllowDeviceHealthMonitoring (=1) under HKEY_LOCAL_MACHINE\software\microsoft\policymanager\current\device\DeviceHealthMonitoring. Service "Connected User Experience and Telemetry" is running.

  • What happpens when kickstarting the enrollment by using the csp that initializes the enrollment?
    • MaxMorsia's avatar
      MaxMorsia
      Brass Contributor

      Sorry, I'm not following you. Isn't the CSP already the policy deploying the settings?

  • MaxMorsia's avatar
    MaxMorsia
    Brass Contributor
    Something changed this morning. Now the impacted devices are "not applicable". No more failure...
    • MaxMorsia's avatar
      MaxMorsia
      Brass Contributor
      After installing manually KB5023773 on Win 10 21H2, deployment was finally successful! Now testing after updating Win11 client to 22h2.
      • MaxMorsia's avatar
        MaxMorsia
        Brass Contributor
        also successful on win11 after update to 22h2!
  • Ashok1996's avatar
    Ashok1996
    Copper Contributor
    I am also getting same issue what will be exact solution to resolve this issue
  • sammyvvv's avatar
    sammyvvv
    Copper Contributor

    has anyone had any joy with this ?also having the same issue..

    • MaxMorsia's avatar
      MaxMorsia
      Brass Contributor
      Have you installed KB5023773 on Win 10 or is Win 11 on 22h2? After that my deployment was successful, though there are still some glitches (same error on "device health" for some devices, but the whole contraption seems to work)
      • iainfm's avatar
        iainfm
        Copper Contributor

        I'm having the same issue. EPM deploys and works on some machines, but not others even though they're the same version (22H2 22621.1555) and have the latest updates.

        If I try to install KB5023774 I get an error saying "The update is not applicable for your computer".

Resources