Microsoft, get it together. This seems to be a recurring issue. This is now happening to us
2016345612(Syncml(500) - Intune Compliance Policy Error
We have had this recurring issue for a long time now, and despite searching the error all over the place, there seem to be a lot of other IT professionals in the same boat, but no obvious answers.
The error is on the Anti-Virus setting on the default compliance policy.
2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)
The compliance policy in question is assigned to all users.
This is a very annoying issue as it stops users from being able to access any MSFT apps as it marks the device as non compliant.
we are forced to add users to the exclusion list of the policy until the error clears on it's own days/weeks later.
If anyone has any ideas on what could be the cause or any possible fixes, it would be greatly appreciated
Microsoft Intune Compliance
Microsoft Intune
-
Nick Eckermann 466 Reputation points
2023-10-04T16:12:45.83+00:00 We have been dealing with this issue since March and it isn't getting any better.
-
Nick Eckermann 466 Reputation points
2023-10-12T13:40:20.92+00:00 Looks like there are multiple people in this thread having the same problem.
Please open support cases so we can get more traction on this issue, and they can start to get it resolved. -
ShadabK OA 0 Reputation points
2023-10-13T09:42:37.9+00:00 Rename the device up to 15 characters only, it will resolve the issue.
-
Davio, Peter [HCL] 90 Reputation points
2023-10-16T17:29:59.4533333+00:00 I am getting this error on Firewall and not Antivirus...
-
Jerry Peacock 100 Reputation points
2023-10-16T20:30:33.23+00:00 We are seeing this error as well. And our machine names are only 10 characters, so Less than 15 is not going to fix the issue.
-
Chad Coker 5 Reputation points
2023-10-19T12:21:52.9433333+00:00 We have been having the same issue since we started using Intune. It hits different computers on different days, and it clears after hours/days/resyncs.
Our device names are 15 characters or less. We have removed and redeployed machines, removed and recreated the compliance policy. The issue may resolve for a while, but it always comes back. -
Albin Fransson 0 Reputation points
2023-10-25T09:08:25.17+00:00 Hi,
For our environment we resolve this by letting the user click "Fix now" under the Work or school account settings menu.
After that they can click on "Check access" under the device menu in Company portal.
We dont have any hybrid devices, only AAD.
-
Robert Young 16 Reputation points
2023-11-02T16:20:39.5133333+00:00 We've just seen this appear in our environment. The Senior VP got an email that she forwarded onto my team for action. Not a good look MS.
Anti-Virus is ESET Protect.
We need this addressed PDQ!
-
jason@4streamline.com 6 Reputation points
2023-11-10T20:56:09.1566667+00:00 We are experiencing the same issue. Our devices are AzureAD Joined, we do several app installations when the devices is joined. The issue only happens with Windows 11. The machine becomes very slow and AV stops working after reboot. It appears the Microsoft Defender AV (Endpoint security) is trying to restart. EDR show as if it is updating.
-
Denis Payne 166 Reputation points
2024-01-04T13:54:58.73+00:00 Keep having this issue intermittently affecting random users using random AAD hybrid joined Windows 10 endpoints.
Machine names are less then 15characters.
Fixed the issue once by running sync from Endpoint and InTune.
All other times need to wait days to weeks for the issue to resolve itself, else delete the endpoint from InTune and AzureAD then do a fresh Azure AD hybrid + InTune join.Myself and colleagues gave raised tickets with MSFT 365 support who aren't much help, leaving poor 1st line guys struggling when a senior team needs to get involved and gather debug logs to determine the actual cause.
-
Florian Obradovic 11 Reputation points
2024-03-20T11:15:59.6933333+00:00 We also have a few users affected by this issue (until now all hybrid joined):
2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)It's always the Windows Firewall. Never AV (we use windows defender):
-
Felipe M Ferreira 6 Reputation points
2024-04-01T13:44:43.2266667+00:00 Same issue here: It occurs randomly after users restart their machines. Sometimes, a sync is enough to fix the issue, but other times we have to reboot the machine, sync, check for compliance, and repeat the process multiple times.
We use Windows Defender AV, and our machines’ names are only 11 characters. Last year, this issue was happening very often, but Microsoft fixed it. However, we now observe the same issue occurring since the beginning of March 2024.
-
Rune Pettersen 0 Reputation points
2024-04-08T07:41:46.42+00:00 One machine had this issue, the devicename in autopilot was blank, the devicename in intune was below 15 chars. the machine was also inactive.
-
Seshagiri Rao Padaki 0 Reputation points
2024-04-17T06:43:08.71+00:00 I have reinstalled the Company Portal its working fine
-
Anthony Yeshan Isuru De Silva 0 Reputation points
2024-04-23T01:13:21.6133333+00:00 Hi Guys, i have had this issue for several users. fix is to turn off the windows firewall and turn it back again. then go to company portal click once on check access and wait 2-3mins until it completes. do not click again and again as it will then take more time. if its taking way too long turn off the conditional access policy that check for compliance. then once company portal check is ok you can turn on the conditional access.
To verify further you can check azure ad portal devices and select the device you are checking on. check if its compliant. Then you can go to intune portal check if it shows compliant. it may be compliant on azure ad and not in intune. give it some time and then it will show compliant on intune as well.
-
Rob Plumridge 0 Reputation points
2024-05-22T10:36:34.27+00:00 So I have this on multiple instances of both Win11 and Win10 machines for various clients (different intune configs, different methods of setup), I've poked and asked around, mostly from what I can see it's a sync issue. Again cloud loves to take its time with these, and its v. intermittent.
With Stricter compliance policies it appears more frequently than less relaxed policies but I will try and investigate further into this, I don't really have a concrete answer to this other than sync-ing devices.
Usually (on device) i'll run intunemanagementextension://synccompliance in the run diag
This usually clears up after about 10-30ish minutes
-
Chad Coker 5 Reputation points
2024-05-22T12:20:13.9833333+00:00 We continue to have this issue several times a week. We either wait several days for it to clear on its own or have the user initiate a sync, reboot, etc.
We have opened issues with MS Support only to be passed around to different agents/techs with no solutions offered.
Our compliance platform was integrated to Intune to pull device status,. This became unworkable with this issue occurring so often, so we had to go a different route for that.It is unfortunate that an issue that is this widespread gets no attention from Microsoft, and support is not helpful.
-
Nick Eckermann 466 Reputation points
2024-05-22T18:32:28.79+00:00 @Chad Coker Changes are supposed to be coming but they missed the 2404 deployment. Waiting to see when they might be implemented and if they do in fact fix these issues. Update from Microsoft below. You can reference our case so you might be in the loop better on the rollout.
2310040040013084
Sign in to comment
26 answers
Sort by: Most helpful
-
Kodi Rozanski 0 Reputation points
2024-06-27T12:33:41.33+00:00