Knowledge base
The build knowledge base
Every article here is a real problem admins hit doing device builds — found in the wild, root-caused, and answered properly. The fix works whether or not you ever use Decolla. That is rather the point.
Windows (14)
- Autopilot ESP stuck at Account Setup: causes and fixes — Why Autopilot's Enrollment Status Page hangs at Account Setup, how the Intune Management Extension tracks ESP state, and how to diagnose and unstick it.
- Intune registry detection rule not working: 32/64-bit fix — Intune marks a Win32 app failed though it installed fine? Two silent detection-rule killers — WOW6432Node redirection and HKCU:\ syntax — and the fix.
- ESP stuck on apps? Don't mix Win32 and MSI LOB in Intune — Win32 and MSI LOB apps contend for msiexec during ESP, stalling Autopilot builds invisibly. Why it happens and how standardising on Win32 fixes it.
- Intune 'Available' apps not showing in Company Portal — Intune 'Available' app assignments to device groups are silently ignored for almost every app type. The full intent-by-target support table and the fix.
- Force Intune to retry a failed Win32 app (GRS 24-hour lock) — Intune's Global Retry Schedule locks a failed Win32 app for 24 hours with no retry button. How GRS works, and how to reset it safely via the registry.
- Autopilot dynamic group lag: apps missing during ESP — Autopilot devices join dynamic groups minutes to hours late, so the ESP runs before apps are assigned. Why the ZTDId rule lags and how to fix it.
- Autopilot device removed from group: reset loop fix — Why Autopilot devices removed from their deployment group mid-enrolment fall into a reset loop or hang at 'Please wait', and how to prevent it.
- Intune policies taking 8 hours? Check WNS first — Intune delivers policy changes in minutes via WNS; the 8-hour sync is only a safety net. If WNS is blocked at the firewall, here's how to fix it.
- Intune device shows as personal despite corporate identifier — Windows corporate identifiers only apply at enrolment — devices can still show as personal in Intune. Why it happens, and how to fix ownership properly.
- Intune Win32 install fails: SYSTEM vs user context — Why a Win32 app installs manually but fails from Intune: SYSTEM vs user context, HKCU and %APPDATA% traps, and how to pre-test with PsExec -s.
- Intune: removing app assignment doesn't uninstall the app — Removing a Required assignment in Intune does not uninstall the app. Why it's by design, plus the Uninstall-intent pattern to decommission apps safely.
- Intune Remediations: the hidden detect-and-fix engine — What Intune Remediations do, why they only fire on detection exit code 1, licensing prerequisites, and five ready-made detect-and-fix examples.
- Autopilot ESP: only fail selected blocking apps — Stop the Enrollment Status Page waiting for every app: selected blocking apps, the technician-phase toggle, and the timeout maths for large apps.
- Intune Win32 app runs 32-bit PowerShell? The SysWOW64 fix — Intune Win32 PowerShell installers can run 32-bit even with the 64-bit toggle on. How SysWOW64 redirection breaks scripts, and the sysnative guard fix.
Apple — Business Manager, tokens & certificates (8)
- Renew or recreate the Apple MDM push certificate in Intune? — Renew — never recreate — your Intune APNs certificate. Why device trust follows the push topic, what the Apple ID actually controls, and the safe path.
- APNs certificate expired in Intune: recovery options — What happens when your Intune APNs certificate expires, the documented 30-day renewal grace period, and when non-removable profiles force a full wipe.
- Apple tokens in Intune: APNs, ADE and VPP renewal explained — The APNs certificate, ADE enrolment token and VPP token all expire yearly and each breaks something different. A one-page matrix and the renewal rules.
- Duplicate apps in Intune after VPP token renewal — Renewing an Apple VPP token as a new entry duplicates every app in Intune. How to renew in place, recover from duplicates, and catch early expiry.
- Intune T_C_NOT_Signed error: accept Apple's new ABM terms — Intune stopped syncing with Apple after an iOS release? T_C_NOT_Signed means new ABM terms need accepting. Who can sign, how to fix it, how to prevent it.
- Apple Business Manager stuck on D-U-N-S verification — ABM enrolment can stall for a week on D-U-N-S checks and Apple's verification call. The exact fixes: record matching, contact briefing, lead time.
- Retail-bought devices don't appear in Apple Business Manager — Retail purchases can't satisfy ABM chain of custody. Register reseller DEP IDs, add devices with Apple Configurator, and mind the 30-day release window.
- ABM federation Apple ID conflicts: the 60-day rename — ABM federation gives personal Apple IDs on your domain 60 days, then a forced rename. The conflict lifecycle, plus a staff comms email template.
iOS / iPadOS (3)
- Intune iOS restrictions not applying? Check supervision — Half of Intune's iOS restrictions only apply to supervised devices. See the supervised-only capability split, how to check, and why the fix needs a wipe.
- Activation Lock: save the bypass code before you wipe — Activation Lock survives a wipe and Intune's bypass code dies with the device record. The offboarding order that stops a returned iPhone being a brick.
- Return to Service: wipe and auto re-enrol iPhones (iOS 17+) — iOS 17's Return to Service wipes and auto re-enrols iPhones — a Wi-Fi profile survives the erase and Setup Assistant is skipped. Requirements and gotchas.
macOS (3)
- FileVault key not in Intune after MDM migration: the fix — Intune shows a migrated Mac encrypted but holds no FileVault key. Fix: rotate the personal recovery key so the new one escrows — no re-encryption needed.
- macOS bootstrap token missing after zero-touch enrolment — Skipping account creation in Setup Assistant delays macOS bootstrap token escrow — verify it with profiles status before FileVault and kext jobs fail.
- Mac stuck at 'Awaiting final configuration' in Intune — Why Intune's Await Final Configuration locks the Mac after Setup Assistant, how long is normal, how to trim the enrolment payload, and triage when stuck.
Android (14)
- Zero-touch Intune enrolment fails after Microsoft sign-in — Android zero-touch enrolment fails after Microsoft sign-in with 'Page not found'? Zero-touch did its job — the fault is Intune-side. How to fix it.
- Android devices not in the zero-touch portal — what now — Only authorised resellers can register Android devices for zero-touch. What to demand at purchase, the dual-SIM IMEI trap, and fallback enrolment paths.
- Android Enterprise apps stuck at 'Pending' in Intune — Why Intune Android apps stick at 'Pending' — Google Play's install queue, not Intune — and the triage ladder that unsticks them.
- Approved managed Google Play app not showing on devices — Approved an app in managed Google Play but users can't see it? One old collections edit flips the tenant into Custom mode. Here's the fix.
- Android Enterprise: work profile vs fully managed vs COPE — A decision tree for the four Android Enterprise modes — work profile, COPE, fully managed, dedicated — and why switching later means a factory reset.
- Samsung KME stuck at 'Please click here to continue' — Samsung S23s hang at 'Please click here to continue' during Knox Mobile Enrolment into Intune. It's a One UI 6.0 firmware bug — here's how to triage it.
- Knox Mobile Enrollment: pending uploads and one-way deletes — Samsung devices ignoring KME? Reseller uploads wait unapproved on the UPLOADS tab — and Knox portal deletes can be one-way. How to fix and prevent both.
- OEMConfig shows success in Intune but setting not applied — Intune reports a Knox Service Plugin OEMConfig profile as succeeded, yet the device ignores it. Why "applied" only means delivered, and how to verify.
- Intune OEMConfig: one profile per app per device limit — Multiple OEMConfig profiles on one Android device make settings flap. Why the managed-configuration model allows only one, and how to consolidate safely.
- Android stuck at 'Your work checklist': afw#setup + COPE — Android 11+ devices enrolled with afw#setup and a corporate-owned work profile token loop at 'Your work checklist'. Why it happens and the supported paths.
- Managed Home Screen kiosk: calls, dialer and notifications — Per-OEM dialer package IDs, the Intune settings that govern notification trays and screen-wake, and a repeatable recipe for Managed Home Screen kiosks.
- Factory Reset Protection and Intune: why reset path matters — Android FRP locks returned devices after some resets but not others. How Intune wipe vs on-device reset differ, FRP admin emails, and captive-portal traps.
- Managed Google Play app updates taking 24 hours to install? — Managed Google Play app updates can take 24 hours to queue and never land on busy kiosks. The per-app high-priority update mode most admins miss.
- Knox Service Plugin: free KPE Premium settings in Intune — KPE Premium is free. Deploy Knox Service Plugin via OEMConfig in Intune to control screen timeout, hidden settings menus, power and language on Samsung.
See it on a real device.
Decolla is in private build — early-access members see a build defined, deployed and rolled back first.
Get early access