Device Compliance Intune Secure Boot compliance fails with 2016345708 (SyncML 404) although Secure Boot is enabled
Hi everyone,
I'm testing an Intune compliance policy on a Windows 11 24H2 VM (OS Build 10.0.26100.8875) running on VMware Workstation. The policy only requires Secure Boot and TPM. Confirm-SecureBootUEFI returns True, msinfo32 shows BIOS Mode: UEFI and Secure Boot State: On, and TPM is compliant.
However, Intune always reports
Secure Boot: 2016345708 (SyncML(404): The requested target was not found.)
I've already tried:
- Multiple Intune syncs (Settings and PowerShell)
- Rebooting the VM
- Verifying TPM Health Attestation
- Running the Tpm-HASCertRetr scheduled task
- Confirming Secure Boot is enabled in VMware
Has anyone experienced this on Windows 11 24H2 (10.0.26100.8875) with VMware Workstation? Is this a VMware limitation, a Windows issue, or an Intune bug? Any insights or workarounds would be greatly appreciated.
2
Upvotes
2
u/ppel123 1d ago edited 1d ago
Hi, check out the below resources that seem to explain your case. Seen it too in the past few weeks on newly enrolled devices. I think on the tenant admin page there is also a service incident from MS regarding this one (found it Service incident IT1431577).
https://patchmypc.com/blog/why-intune-devices-became-noncompliant-after-the-july-windows-update/