Share via

2016345612(Syncml(500) - Intune Compliance Policy Error

Craig Pennington 325 Reputation points
2023-09-05T13:23:04.57+00:00

We have had this recurring issue for a long time now, and despite searching the error all over the place, there seem to be a lot of other IT professionals in the same boat, but no obvious answers.

The error is on the Anti-Virus setting on the default compliance policy.

2016345612(Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request)User's image

The compliance policy in question is assigned to all users.

This is a very annoying issue as it stops users from being able to access any MSFT apps as it marks the device as non compliant.

we are forced to add users to the exclusion list of the policy until the error clears on it's own days/weeks later.

If anyone has any ideas on what could be the cause or any possible fixes, it would be greatly appreciated

Microsoft Security | Intune | Compliance
Microsoft Security | Intune | Other

23 answers

Sort by: Most helpful
  1. Smith, Lachlan 0 Reputation points
    2026-05-01T01:06:14.4366667+00:00

    A bit late to the conversation sorry. I had this issue on one of our compliance policies. We have ours setup into an immediate and a 24hr delay.
    Immediate
    User's image

    and 24hrs User's image

    At first the firewall had this syncml issue however we also had bitlocker failed to encypt. Once the bitlocker was encrypted for silent encryption (i missed some components for it) (https://learn.microsoft.com/en-us/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows#configure-silent-bitlocker-encryption), it then encrypted, did a Check Access in CP, rebooted, did another sync and the Immediate was working. The FW was then resolved by doing another sync in CP, restarting. To help I was using the event logs in Apps and services > MS > windows > deviceMGMT-Ent and looking there for the warning 2750 for (WSC_security_provider_firewall). After the last sync locally, the event logs no longer showed the 2750, i redid a check access in CP and it then synced back to Intune.

    TLDR: I suspect FW was being prevented from working due to bitlocker not encypting.... No idea why though.

    0 comments No comments

  2. Tyler Huggins 0 Reputation points
    2025-05-29T16:59:14.2566667+00:00

    I discovered another potential cause of this error.

    In my case, the affected device had received the compliance policy via dynamic device group, but had later been removed from that group. Once it was added back to the group and synced, the error disappeared and the device was compliant again.

    If your affected device is no longer in a group needed for the initial compliance policy assignment, make sure to add the group back (or if dynamic, update the dynamic membership rules to include the device).

    0 comments No comments

  3. Igor Trenk 0 Reputation points
    2024-09-25T18:21:15.0266667+00:00

    we have same issue, if i have only virtual windows 365 machines, if i start to sync over company portal after issue was repaired. when it happened in laptop, after i tried more stuff but it didnt help. what solve that issue was switch off windows hello, after 1 day it works like before.


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.