Setting up and managing device configurations using Intune
The available information only documents how BIOS configuration policies work in Intune and how they are reported at a high level. It does not describe internal data flows, password field behavior, or remediation methods for the specific mismatch scenario described.
From the context, only the following supported and documented actions apply:
- BIOS configuration policy behavior and reporting
- Intune delivers the OEM BIOS configuration file to the device when the BIOS configuration and other settings policy is assigned. The OEM Win32 agent on the device applies the configuration.
- Intune reporting for these policies is limited to whether the configuration file applied successfully. The documented report is the Device status report under Devices > Manage devices > Configuration > Policies. It shows the status of the policy and any error details for troubleshooting.
- There is no documented mechanism in the provided material to reconcile or override a mismatch between what the Intune Management Extension (IME) records locally and what Intune reports in the portal.
- Prerequisites and password handling constraints
- The feature requires that devices do not already have an existing BIOS password configured unless Intune has that password. If Intune does not have the BIOS password, it cannot update the BIOS configuration.
- The documentation does not describe any supported method to manually set or restore a BIOS password value (such as
currentPassword) in Intune or on the agent side, nor any registry-based or local method to repopulate such a field. - The documentation also does not describe any supported way to manipulate or resynchronize the BIOS password state between IME, Intune, and the OEM tooling beyond normal policy assignment and application.
- Supported remediation and monitoring options in scope of the documentation
- The only documented operational steps are:
- Ensure prerequisites are met (organization-owned, MDM-enrolled devices, no unknown BIOS password configured).
- Create and assign the BIOS configuration and other settings policy with the OEM configuration file.
- Monitor the policy using the built-in Device status report under Devices > Manage devices > Configuration > Policies.
- Use Intune’s general device configuration monitoring and reporting capabilities for further troubleshooting.
- There is no documented way in the provided material to:
- Force a special synchronization between IME and Intune beyond standard device check-in/sync.
- Directly edit or restore BIOS password fields such as
currentPasswordorpreviousPasswordvia a supported local/agent/registry/Dell-tooling method. - Change the data flow or telemetry behavior between IME and any backend service.
Because of these limits, the specific questions about:
- Root cause of the mismatch between IME status and Intune reporting,
- Why
currentPasswordis not populated whilepreviousPasswordis, - Any special/manual synchronization mechanism beyond normal sync actions,
- Whether the data flow between IME and DCECMI is managed through telemetry,
- Any supported method to manually repopulate
currentPasswordwithout removing the BIOS password,
are not answered or described in the provided documentation.
The only supported guidance available here is to:
- Ensure the documented prerequisites are satisfied (especially that Intune has the BIOS password when needed),
- Use the standard Intune policy creation and assignment flow for BIOS configuration and other settings, and
- Monitor and troubleshoot using the built-in Device status report and general Intune reporting.
References: