Home
%3CLINGO-SUB%20id%3D%22lingo-sub-377803%22%20slang%3D%22en-US%22%3EChanges%20to%20CSP%20path%20for%20Windows%2010%20email%20profiles%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-377803%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3E4%2F19%2F19%20Update%3A%20This%20fix%20has%20now%20been%20rolled%20out%20with%201904%20or%20the%20April%20update%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EThere%20is%20currently%20an%20issue%20in%20Intune%20where%20selective%20wipe%20does%20not%20work%20as%20expected%20on%20Windows%2010%20email%20profiles.%20To%20fix%20this%2C%20we%E2%80%99re%20updating%20the%20CSP%20path%20for%20Windows%2010%20email%20profiles%20in%20the%20April%20(1904)%20update%20of%20the%20Intune%20service.%20This%20will%20ensure%20your%20email%20profiles%20continue%20to%20work%20in%20future%20versions%20of%20Windows%2010%2C%20which%20will%20already%20have%20this%20updated%20CSP%20path.%3C%2FP%3E%0A%3CP%3EThis%20impacts%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EThe%20native%20Mail%20client%20on%20Windows%2010%20desktops%3C%2FLI%3E%0A%3CLI%3EThe%20Outlook%20email%20client%20on%20Windows%2010%20Mobile%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EDesktop%20or%20online%20versions%20of%20Outlook%20will%20not%20be%20affected%20by%20this%20change.%3C%2FP%3E%0A%3CP%3EBoth%20Intune%20standalone%20and%20hybrid%20MDM%20are%20impacted%20by%20this.%20If%20you%E2%80%99re%20using%20hybrid%20MDM%2C%20remember%20that%20hybrid%20MDM%20is%20deprecated%2C%20and%20you%20should%20migrate%20to%20Intune%20standalone%20as%20soon%20as%20possible.%3C%2FP%3E%0A%3CP%3EAfter%201904%20rolls%20out%2C%20if%20you%20do%20not%20re-create%20these%20Windows%2010%20email%20profiles%2C%20you%E2%80%99ll%20see%20the%20issues%20listed%20below%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EExisting%20email%20profiles%20will%20show%20up%20in%20error%20state%3C%2FLI%3E%0A%3CLI%3EIn%20the%20Intune%20console%2C%20this%20error%20is%20shown%20as%20-%3CSTRONG%3E2016281112%20(Remediation%20failed)%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EFor%20hybrid%20MDM%2C%20this%20error%20shows%20up%20in%20the%20monitoring%20section%20of%20the%20Configuration%20Manager%20admin%20console%3A%3CUL%3E%0A%3CLI%3EError%20ID%3A%20%3CSTRONG%3E0X87D1FDE8%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3CLI%3EDescription%3A%20%3CSTRONG%3ERemediation%20failed%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EHowever%2C%20despite%20the%20reported%20error%2C%20devices%20targeted%20with%20these%20profiles%20will%20still%20have%20access%20to%20email.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EIn%20a%20subsequent%20release%20of%20Windows%2010%20where%20the%20old%20CSP%20path%20is%20removed%2C%20email%20profiles%20created%20before%20the%20April%20update%20for%20Intune%20will%20not%20work%20at%20all.%20End%20users%20will%20lose%20access%20to%20email%20through%20the%20clients%20specified%20above.%3C%2FLI%3E%0A%3CLI%3EEdits%20made%20to%20these%20profiles%20will%20not%20be%20reflected%20in%20targeted%20devices.%3C%2FLI%3E%0A%3CLI%3EThese%20profiles%20will%20not%20be%20removed%20on%20selective%20wipe.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EIn%20order%20to%20prevent%20these%20issues%2C%20we%20recommend%20that%20if%20you%20use%20Windows%2010%20email%20profiles%20today%2C%20take%20the%20following%20action%20to%20re-create%20your%20email%20profiles%20after%20the%20April%20update%20rolls%20out.%20We%E2%80%99ll%20notify%20you%20through%20the%20Message%20Center%20when%20this%20fix%20is%20rolled%20out%20to%20your%20account%20with%20the%20April%20update%20so%20you%20can%20take%20action.%20Note%20that%20taking%20action%20before%20that%20will%20not%20fix%20the%20issue.%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECapture%20your%20existing%20Windows%2010%20email%20profile%20settings.%3C%2FLI%3E%0A%3CLI%3EUnassign%20your%20existing%20Windows%2010%20email%20profiles%20(and%2For%20delete%20them).%20Note%20that%20all%20existing%20Windows%2010%20email%20profiles%20should%20be%20unassigned.%20If%20multiple%20Windows%2010%20email%20profiles%20are%20targeted%20to%20the%20same%20device%2C%20removing%20one%20will%20immediately%20replace%20it%20with%20another%20unless%20all%20are%20unassigned.%3C%2FLI%3E%0A%3CLI%3ECreate%20new%20Windows%2010%20email%20profiles%20using%20the%20same%20settings%20as%20in%20the%20existing%20ones.%3C%2FLI%3E%0A%3CLI%3EAssign%20the%20new%20Windows%2010%20email%20profiles%20to%20the%20same%20groups.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3EEnd%20users%20will%20have%20the%20same%20experience%20as%20when%20installing%20an%20email%20profile%20for%20the%20first%20time%2C%20so%20on%20first%20check-in%20after%20the%20profile%20change%2C%20end%20users%20will%20get%20a%20system%20notification%20telling%20them%20their%20email%20profile%20settings%20are%20out%20of%20date.%20They%20will%20need%20to%20follow%20all%20prompts%20and%20accept%20the%20update%20(a%20few%20taps%20or%20clicks)%20for%20the%20new%20profile%20to%20be%20applied%20and%20for%20email%20syncing%20to%20resume.%20Email%20syncing%20will%20be%20blocked%20until%20they%20accept%20the%20update.%3C%2FP%3E%0A%3CP%3ELet%20us%20know%20if%20you%20have%20any%20questions!%20We%E2%80%99ll%20update%20the%20post%20when%20the%20fix%20starts%20to%20roll%20out.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-377803%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20style%3D%22display%3A%20inline%20!important%3B%20float%3A%20none%3B%20background-color%3A%20%23ffffff%3B%20color%3A%20%23333333%3B%20font-family%3A%20'SegoeUI'%2C'Lato'%2C'Helvetica%20Neue'%2CHelvetica%2CArial%2Csans-serif%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant%3A%20normal%3B%20font-weight%3A%20300%3B%20letter-spacing%3A%20normal%3B%20orphans%3A%202%3B%20text-align%3A%20left%3B%20text-decoration%3A%20none%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20-webkit-text-stroke-width%3A%200px%3B%20white-space%3A%20normal%3B%20word-spacing%3A%200px%3B%22%3EThere%20is%20currently%20an%20issue%20in%20Intune%20where%20selective%20wipe%20does%20not%20work%20as%20expected%20on%20Windows%2010%20email%20profiles.%20To%20fix%20this%2C%20we%E2%80%99re%20updating%20the%20CSP%20path%20for%20Windows%2010%20email%20profiles%20in%20the%20April%20(1904)%20update%20of%20the%20Intune%20service.%20%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-377803%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eknown%20issue%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E

 

4/19/19 Update: This fix has now been rolled out with 1904 or the April update

There is currently an issue in Intune where selective wipe does not work as expected on Windows 10 email profiles. To fix this, we’re updating the CSP path for Windows 10 email profiles in the April (1904) update of the Intune service. This will ensure your email profiles continue to work in future versions of Windows 10, which will already have this updated CSP path.

This impacts:

  • The native Mail client on Windows 10 desktops
  • The Outlook email client on Windows 10 Mobile

Desktop or online versions of Outlook will not be affected by this change.

Both Intune standalone and hybrid MDM are impacted by this. If you’re using hybrid MDM, remember that hybrid MDM is deprecated, and you should migrate to Intune standalone as soon as possible.

After 1904 rolls out, if you do not re-create these Windows 10 email profiles, you’ll see the issues listed below:

  • Existing email profiles will show up in error state
  • In the Intune console, this error is shown as -2016281112 (Remediation failed)
  • For hybrid MDM, this error shows up in the monitoring section of the Configuration Manager admin console:
    • Error ID: 0X87D1FDE8
    • Description: Remediation failed

However, despite the reported error, devices targeted with these profiles will still have access to email.

  • In a subsequent release of Windows 10 where the old CSP path is removed, email profiles created before the April update for Intune will not work at all. End users will lose access to email through the clients specified above.
  • Edits made to these profiles will not be reflected in targeted devices.
  • These profiles will not be removed on selective wipe.

In order to prevent these issues, we recommend that if you use Windows 10 email profiles today, take the following action to re-create your email profiles after the April update rolls out. We’ll notify you through the Message Center when this fix is rolled out to your account with the April update so you can take action. Note that taking action before that will not fix the issue.

  • Capture your existing Windows 10 email profile settings.
  • Unassign your existing Windows 10 email profiles (and/or delete them). Note that all existing Windows 10 email profiles should be unassigned. If multiple Windows 10 email profiles are targeted to the same device, removing one will immediately replace it with another unless all are unassigned.
  • Create new Windows 10 email profiles using the same settings as in the existing ones.
  • Assign the new Windows 10 email profiles to the same groups.

End users will have the same experience as when installing an email profile for the first time, so on first check-in after the profile change, end users will get a system notification telling them their email profile settings are out of date. They will need to follow all prompts and accept the update (a few taps or clicks) for the new profile to be applied and for email syncing to resume. Email syncing will be blocked until they accept the update.

Let us know if you have any questions! We’ll update the post when the fix starts to roll out.