Support Tip: Known Issues with Intune policy reports

Published Aug 23 2021 12:00 PM 4,553 Views

The Intune team is aware of several policy reporting scenarios that require additional consideration in the Microsoft Endpoint Manager admin center. In this post, we will address some of these issues and highlight some upcoming improvements to Intune policy reports.

 

Common issues with Intune policy reports

 

A policy report shows two records for the same device: one with a ‘user’ account and one with a ‘system’ account.

 

Policy reporting records are based on the configured assignment and the enrollment of the devices checking in. Intune will surface a unique record for the user checking in to the device to receive the policy. When check-ins happen on a device with varying user presence, this can result in multiple reporting records for the same policy. This typically happens when the device (system) automatically checks in if the user hasn’t checked in for 8 hours, or during Windows Autopilot scenarios.


How we plan to enhance this: We plan to add more reporting options so you can clearly understand when and which user check-ins happened on the device with a policy status. With this, we plan to provide views to surface an additional view that does not have duplicate entries per device.

 

A policy report shows devices stuck in pending status.

 

When a device has a "pending” status, it means the device has not checked in to receive the policy. There is a known scenario where sometimes the device status can still show as “pending” in a report even after the policy has been delivered to the device. To remediate this, try syncing the device or confirming the policy has been applied to the device to ensure that report data gets updated to accurately reflect device status.

 

How we plan to enhance this: We are working to ensure our policy reports show the latest set of accurate data for targeted devices. For devices in pending state, we are verifying our calculation of this data is correct and consistent throughout the console.

 

The data in report lists and summary charts isn’t consistent.

 

The policy report lists and summary pages update on a different cadence, which can lead to inconsistencies in the reported data. In addition, the summary doughnut charts aggregate based on the worst case of a targeted device for a policy. This can result in the summary numbers showing different totals than the number of entries in the full detailed list.

 

How we plan to enhance this: We are working on improvements to ensure the summary and list reports are always consistent. In addition, we are looking to change the way we aggregate the summarized charts to reflect the same number of entries as in the list view.

 

Common issues with Intune policy reports

 

We are working towards having consistent, accurate information across all the policy reports in the console. This includes device configuration profiles (including settings catalog), security baseline profiles and endpoint security profiles. The new reports will have better performance and capabilities for search, sort, filtering, improved paging, and export. We are looking to incorporate better drill-down capabilities and navigational flows with user experience.

 

To learn about new reports we released earlier this year, see Introducing new policy reports & more in Microsoft Endpoint Manager reporting. To stay up to date with these and other updates, see What's new in Microsoft Intune and Features in development.

 

We will continue to update this post as new information becomes available. If you have questions or comments for the Intune team, reply to this post or reach out to @IntuneSuppTeam on Twitter.

3 Comments
Senior Member

Please extend these changes to application install reports as well!

Please fix for app deployments too.  I get so much duplicate data (e.g. Chrome has deployed to "Machine01 No user" and to "Machine01 FBloggs@myorg.org") that the data reported is utterly useless.  An app is on a device or it is not, the user affinity is not relevant.  That's pretty basic, no?  I have to hand craft my own reports and it doesn't have to be this way.  Also, please extend the filtering capability, because so many fields are not available for filtering.

 

Occasional Visitor

The "Device Install Status" for application needs to be accurate to effectively manage devices and confirm deployments of apps and to assist with identifying application and device issues.

%3CLINGO-SUB%20id%3D%22lingo-sub-2676483%22%20slang%3D%22en-US%22%3ESupport%20Tip%3A%20Known%20Issues%20with%20Intune%20policy%20reports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2676483%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20Intune%20team%20is%20aware%20of%20several%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmem%2Fintune%2Ffundamentals%2Freports%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Epolicy%20reporting%20scenarios%3C%2FA%3E%20that%20require%20additional%20consideration%20in%20the%20Microsoft%20Endpoint%20Manager%20admin%20center.%20In%20this%20post%2C%20we%20will%20address%20some%20of%20these%20issues%20and%20highlight%20some%20upcoming%20improvements%20to%20Intune%20policy%20reports.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3ECommon%20issues%20with%20Intune%20policy%20reports%3CP%3E%26nbsp%3B%3C%2FP%3EA%20policy%20report%20shows%20two%20records%20for%20the%20same%20device%3A%20one%20with%20a%20%E2%80%98user%E2%80%99%20account%20and%20one%20with%20a%20%E2%80%98system%E2%80%99%20account.%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPolicy%20reporting%20records%20are%20based%20on%20the%20configured%20assignment%20and%20the%20enrollment%20of%20the%20devices%20checking%20in.%20Intune%20will%20surface%20a%20unique%20record%20for%20the%20user%20checking%20in%20to%20the%20device%20to%20receive%20the%20policy.%20When%20check-ins%20happen%20on%20a%20device%20with%20varying%20user%20presence%2C%20this%20can%20result%20in%20multiple%20reporting%20records%20for%20the%20same%20policy.%20This%20typically%20happens%20when%20the%20device%20(system)%20automatically%20checks%20in%20if%20the%20user%20hasn%E2%80%99t%20checked%20in%20for%208%20hours%2C%20or%20during%20Windows%20Autopilot%20scenarios.%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EHow%20we%20plan%20to%20enhance%20this%3A%20We%20plan%20to%20add%20more%20reporting%20options%20so%20you%20can%20clearly%20understand%20when%20and%20which%20user%20check-ins%20happened%20on%20the%20device%20with%20a%20policy%20status.%20With%20this%2C%20we%20plan%20to%20provide%20views%20to%20surface%20an%20additional%20view%20that%20does%20not%20have%20duplicate%20entries%20per%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EA%20policy%20report%20shows%20devices%20stuck%20in%20pending%20status.%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20a%20device%20is%20%22pending%E2%80%9D%20status%2C%20it%20means%20the%20device%20has%20not%20checked%20in%20to%20receive%20the%20policy.%20There%20is%20a%20known%20scenario%20where%20sometimes%20the%20device%20status%20can%20still%20show%20as%20%E2%80%9Cpending%E2%80%9D%20in%20a%20report%20even%20after%20the%20policy%20has%20been%20delivered%20to%20the%20device.%20To%20remediate%20this%2C%20try%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmem%2Fintune%2Fremote-actions%2Fdevice-sync%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3Esyncing%20the%20device%3C%2FA%3E%20or%20confirming%20the%20policy%20has%20been%20applied%20to%20the%20device.%20to%20ensure%20that%20report%20data%20gets%20updated%20to%20accurately%20reflect%20device%20status.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20we%20plan%20to%20enhance%20this%3A%20We%20are%20working%20to%20ensure%20our%20policy%20reports%20show%20the%20latest%20set%20of%20accurate%20data%20for%20targeted%20devices.%20For%20devices%20in%20pending%20state%2C%20we%20are%20verifying%20our%20calculation%20of%20this%20data%20is%20correct%20and%20consistent%20throughout%20the%20console.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3EThe%20data%20in%20report%20lists%20and%20summary%20charts%20isn%E2%80%99t%20consistent.%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20policy%20report%20lists%20and%20summary%20pages%20update%20on%20a%20different%20cadence%2C%20which%20can%20lead%20to%20inconsistencies%20in%20the%20reported%20data.%20In%20addition%2C%20the%20summary%20doughnut%20charts%20aggregate%20based%20on%20the%20worst%20case%20of%20a%20targeted%20device%20for%20a%20policy.%20This%20can%20result%20in%20the%20summary%20numbers%20showing%20different%20totals%20than%20the%20number%20of%20entries%20in%20the%20full%20detailed%20list.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20we%20plan%20to%20enhance%20this%3A%20We%20are%20working%20on%20improvements%20to%20ensure%20the%20summary%20and%20list%20reports%20are%20always%20consistent.%20In%20addition%2C%20we%20are%20looking%20to%20change%20the%20way%20we%20aggregate%20the%20summarized%20charts%20to%20reflect%20the%20same%20number%20of%20entries%20as%20in%20the%20list%20view.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3ECommon%20issues%20with%20Intune%20policy%20reports%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20working%20towards%20having%20consistent%2C%20accurate%20information%20across%20all%20the%20policy%20reports%20in%20the%20console.%20This%20includes%20device%20configuration%20profiles%20(including%20settings%20catalog)%2C%20security%20baseline%20profiles%20and%20endpoint%20security%20profiles.%20The%20new%20reports%20will%20have%20better%20performance%20and%20capabilities%20for%20search%2C%20sort%2C%20filtering%2C%20improved%20paging%2C%20and%20export.%20We%20are%20looking%20to%20incorporate%20better%20drill-down%20capabilities%20and%20navigational%20flows%20with%20user%20experience.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20learn%20about%20new%20reports%20we%20released%20earlier%20this%20year%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FMEMReportingBlog2011%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3EIntroducing%20new%20policy%20reports%20%26amp%3B%20more%20in%20Microsoft%20Endpoint%20Manager%20reporting%3C%2FA%3E.%20To%20stay%20up%20to%20date%20with%20these%20and%20other%20updates%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FMEMWN%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3EWhat's%20new%20in%20Microsoft%20Intune%3C%2FA%3E%20and%20%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FMEMID%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3EFeatures%20in%20development%3C%2FA%3E.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20will%20continue%20to%20update%20this%20post%20as%20new%20information%20becomes%20available.%26nbsp%3BIf%26nbsp%3Byou%20have%26nbsp%3Bquestions%20or%20comments%20for%20the%20Intune%20team%2C%20reply%20to%20this%20post%26nbsp%3Bor%20reach%20out%26nbsp%3Bto%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FIntuneSuppTeam%22%20rel%3D%22noopener%20noreferrer%22%20target%3D%22_blank%22%3E%40IntuneSuppTeam%3C%2FA%3E%26nbsp%3Bon%20Twitter.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2676483%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20Intune%20team%20is%20aware%20of%20several%20policy%20reporting%20scenarios%20that%20require%20additional%20consideration%20in%20the%20Microsoft%20Endpoint%20Manager%20admin%20center.%20In%20this%20post%2C%20we%20will%20address%20some%20of%20these%20issues%20and%20highlight%20some%20upcoming%20improvements%20to%20Intune%20policy%20reports.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2676483%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Endpoint%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESupport%20Tip%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2678691%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Known%20Issues%20with%20Intune%20policy%20reports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2678691%22%20slang%3D%22en-US%22%3E%3CP%3EPlease%20fix%20for%20app%20deployments%20too.%26nbsp%3B%20I%20get%20so%20much%20duplicate%20data%20(e.g.%20Chrome%20has%20deployed%20to%20%22Machine01%20No%20user%22%20and%20to%20%22Machine01%20%3CA%20href%3D%22mailto%3AFBloggs%40myorg.org%26quot%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EFBloggs%40myorg.org%22%3C%2FA%3E)%20that%20the%20data%20reported%20is%20utterly%20useless.%26nbsp%3B%20An%20app%20is%20on%20a%20device%20or%20it%20is%20not%2C%20the%20user%20affinity%20is%20not%20relevant.%26nbsp%3B%20That's%20pretty%20basic%2C%20no%3F%26nbsp%3B%20I%20have%20to%20hand%20craft%20my%20own%20reports%20and%20it%20doesn't%20have%20to%20be%20this%20way.%26nbsp%3B%20Also%2C%20please%20extend%20the%20filtering%20capability%2C%20because%20so%20many%20fields%20are%20not%20available%20for%20filtering.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2678352%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Known%20Issues%20with%20Intune%20policy%20reports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2678352%22%20slang%3D%22en-US%22%3E%3CP%3EPlease%20extend%20these%20changes%20to%20application%20install%20reports%20as%20well!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2782498%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Known%20Issues%20with%20Intune%20policy%20reports%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2782498%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20%22Device%20Install%20Status%22%20for%20application%20needs%20to%20be%20accurate%20to%20effectively%20manage%20devices%20and%20confirm%20deployments%20of%20apps%20and%20to%20assist%20with%20identifying%20application%20and%20device%20issues.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Version history
Last update:
‎Aug 23 2021 06:08 PM
Updated by: