Compliance failing because Firewall not detected

Pavel yannara Mirochnitchenko 12,576 Reputation points MVP
2020-08-18T08:59:43.66+00:00

Win10 cloud-only Intune managed, 1909 and 2004 devices. I get:

"Firewall Error -2016345612"
ERROR CODE
0x87d101f4
ERROR DETAILS
Syncml(500): The recipient encountered an unexpected condition which prevented it from fulfilling the request

I noticed that first when I create the compliance policy, it is green but after some usage, it turns to error. Seems like a bug. I use only Win10 protection, no 3rd party and Firewall is own and Security Center is green in Win10.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,893 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,048 questions
{count} vote

21 answers

Sort by: Most helpful
  1. AndyLiu-MSFT 586 Reputation points
    2020-08-19T02:32:32.313+00:00

    It sounds like that this is a known issue, which has been discussed a lot on the Intune uservoice site.

    Please click the following link for more details.

    https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/36815068-intune-device-compliance-evaluation-not-stable-fa

    To take a further investigation for this issue, I would recommend to create an online support ticket.

    0 comments No comments

  2. Pavel yannara Mirochnitchenko 12,576 Reputation points MVP
    2020-09-17T16:43:50.947+00:00

    Any chance that the Compliance should be applied to Users instead of Devices? Just for test, I removed the most problematic compliance from Devices, applied it to Users and I see slowly devices being green up.

    0 comments No comments

  3. Pavel yannara Mirochnitchenko 12,576 Reputation points MVP
    2020-09-25T17:36:59.713+00:00

    With Firewall and AV I am not sure, but I had bigger problem because I had on Compliance top level the deadline time set to 1 day, which means that if device is offline more than 1 day, it becomes non-compliant.

    I did;

    • Removed FW and AV
    • Applied compliance policy back to devices instead of users
    • CHanged from 1 day to 90 day on top level.

    I will follow how this will go during the week, but so far so good.


  4. Swati Arora 1 Reputation point
    2021-06-08T07:42:14.153+00:00

    Hi Yannara,

    We are facing similar issues, devices coming as not compliant or not evaluated. In compliance policy we are checking below:

    1. Anti spyware
    2. Anti Virus
    3. Microsoft defender anti malware
    4. Microsoft defender anti malware security intelligence up to date
    5. real time protection.

    Turned off firewall checking but still the same issue.

    Any advise please.

    0 comments No comments

  5. Stephen Kerkmann 1 Reputation point
    2021-08-19T12:03:22.52+00:00

    Hi There. We have a similar problem. Was this issue resolved. Please share.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.