‎Intune Dell BIOS Configuration – Status Mismatch and Password Sync Issue‎

Kyuzo88 106 Reputation points
2026-05-14T12:49:41.3133333+00:00

Hello,
I am using the “BIOS configurations and other settings” configuration profile in Microsoft Intune to manage BIOS settings and passwords. I am currently experiencing an issue on a laptop where there is a mismatch between the status reported in Intune and the status recorded by the Intune Management Extension (IME).

Specifically, the registry key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\IntuneManagementExtension\HardwareConfig\1c1f71b7-069c-4b2c-87dc-27b165263b21 shows the value “success”, while in Intune the status is still reported as Pending, and this has been the case for about a month.

As recommended by Dell and Microsoft, the configuration profile should not be modified while there are pending statuses. This situation is effectively blocking further progress.

On the same device, I have also noticed that the currentPassword retrieved via Microsoft Graph is empty, while the previousPassword field is populated (and matches the actual BIOS password currently in use).

If I reassign the policy to the device, the deployment will most likely fail.

This happens because the currentPassword field is empty, while the BIOS password is actually still configured on the device and matches the value stored in previousPassword.

This means that, when the device is reassigned to the policy, the system will attempt to configure the BIOS using the .CCTK configuration file but WITHOUT providing the existing BIOS password, since currentPassword is blank.

Therefore, before reassigning the policy, I would first need to manually remove the BIOS password from the affected device.

This is not feasible on a fleet of 7,000 devices. At the moment, the issue rate in my pilot phase is 14.5% (2 devices out of 14). Extrapolated to 7,000 devices, this would potentially impact around 980 devices, which is clearly unrealistic to handle manually.

My questions are:

  1. What could cause this mismatch between IME status and Intune reporting?
  2. Why is the currentPassword field not being populated?
  3. Is there a way to manually trigger a synchronization? (Sync actions from Intune and the Company Portal do not resolve the issue.)
  4. Is the data flow between IME and DCECMI managed through telemetry?

Additionally, I would like to understand whether there is any supported method to manually set or restore the currentPassword value on affected devices. Using Microsoft Graph for this operation is not feasible. Could you please confirm whether there is an alternative supported approach (local, agent-side, registry-based, or via Dell tooling) to manually repopulate the currentPassword field without having to remove the BIOS password directly on each device?

Thank you in advance for your support.

Microsoft Security | Intune | Configuration

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-14T12:50:14.94+00:00

    The available information only documents how BIOS configuration policies work in Intune and how they are reported at a high level. It does not describe internal data flows, password field behavior, or remediation methods for the specific mismatch scenario described.

    From the context, only the following supported and documented actions apply:

    1. BIOS configuration policy behavior and reporting
    • Intune delivers the OEM BIOS configuration file to the device when the BIOS configuration and other settings policy is assigned. The OEM Win32 agent on the device applies the configuration.
    • Intune reporting for these policies is limited to whether the configuration file applied successfully. The documented report is the Device status report under Devices > Manage devices > Configuration > Policies. It shows the status of the policy and any error details for troubleshooting.
    • There is no documented mechanism in the provided material to reconcile or override a mismatch between what the Intune Management Extension (IME) records locally and what Intune reports in the portal.
    1. Prerequisites and password handling constraints
    • The feature requires that devices do not already have an existing BIOS password configured unless Intune has that password. If Intune does not have the BIOS password, it cannot update the BIOS configuration.
    • The documentation does not describe any supported method to manually set or restore a BIOS password value (such as currentPassword) in Intune or on the agent side, nor any registry-based or local method to repopulate such a field.
    • The documentation also does not describe any supported way to manipulate or resynchronize the BIOS password state between IME, Intune, and the OEM tooling beyond normal policy assignment and application.
    1. Supported remediation and monitoring options in scope of the documentation
    • The only documented operational steps are:
      • Ensure prerequisites are met (organization-owned, MDM-enrolled devices, no unknown BIOS password configured).
      • Create and assign the BIOS configuration and other settings policy with the OEM configuration file.
      • Monitor the policy using the built-in Device status report under Devices > Manage devices > Configuration > Policies.
      • Use Intune’s general device configuration monitoring and reporting capabilities for further troubleshooting.
    • There is no documented way in the provided material to:
      • Force a special synchronization between IME and Intune beyond standard device check-in/sync.
      • Directly edit or restore BIOS password fields such as currentPassword or previousPassword via a supported local/agent/registry/Dell-tooling method.
      • Change the data flow or telemetry behavior between IME and any backend service.

    Because of these limits, the specific questions about:

    1. Root cause of the mismatch between IME status and Intune reporting,
    2. Why currentPassword is not populated while previousPassword is,
    3. Any special/manual synchronization mechanism beyond normal sync actions,
    4. Whether the data flow between IME and DCECMI is managed through telemetry,
    5. Any supported method to manually repopulate currentPassword without removing the BIOS password,

    are not answered or described in the provided documentation.

    The only supported guidance available here is to:

    • Ensure the documented prerequisites are satisfied (especially that Intune has the BIOS password when needed),
    • Use the standard Intune policy creation and assignment flow for BIOS configuration and other settings, and
    • Monitor and troubleshoot using the built-in Device status report and general Intune reporting.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.