Runbook 06 · 25 scenarios
Configuration and security
Policy conflicts, BitLocker, Defender, LAPS, certificates, Wi-Fi and VPN.
Encrypted traffic · first-line boundary
HTTPS protects transit. It does not prove trust.
Malicious files, stolen sessions and unsafe services can all use encrypted connections. Collect the alert, device, account, destination and time; do not improvise traffic interception or certificate changes.
What may authorised security systems still see?
Depending on design and policy, systems may record destination, timing, volume, DNS activity and some server-name information. Inspection can reveal more, but it requires privacy review, written authority, testing and change control.
What belongs with the security owner?
TLS policy, encrypted-traffic inspection, certificate deployment, web application firewalls, zero-trust access and denial-of-service mitigation. A first-line technician packages the evidence and preserves the recovery route.
The “start here” text identifies the first control plane and evidence to inspect. It does not replace change approval, safeguarding requirements, backup or a tested rollback route.
Configuration profile reports Error
Start hereInspect per-setting status and device diagnostics.
Intune configurationConfiguration profile reports Conflict
Start hereFind every policy surface configuring the same setting.
Intune configurationConfiguration remains Pending
Start hereCheck device contact, assignment and user or device context.
Intune configurationSetting reports Not applicable
Start hereCheck Windows edition, version and CSP support.
Intune configurationLegacy Group Policy conflicts with Intune
Start hereUse Group Policy Analytics and choose the intended authority.
Intune configurationSecurity baseline conflicts with endpoint-security policy
Start hereConfigure each setting from one chosen source.
Intune configurationFirewall policy does not apply correctly
Start hereCheck active profile, third-party firewall and GPO conflict.
Intune configurationBitLocker does not enable silently
Start hereCheck TPM readiness, policy conflict and user requirements.
Intune configurationBitLocker recovery key is not escrowed
Start hereVerify join state, protector and backup status before repair.
Intune configurationMicrosoft Defender is in passive mode
Start hereIdentify competing antivirus or workload authority.
Defender / IntuneDefender onboarding fails
Start hereCheck licence, connector, onboarding state and service endpoints.
Defender for EndpointTamper protection prevents a local change
Start hereChange the centrally managed policy instead of bypassing protection.
Defender / IntuneLAPS password is not backed up
Start hereCheck policy, local account, directory target and permissions.
Intune configurationTechnician cannot retrieve the LAPS password
Start hereCheck the authorised directory role and audit access.
Entra / LAPSLocal Administrators group contains unwanted users
Start hereUse account-protection policy with controlled membership.
Intune configurationWindows Hello provisioning fails
Start hereCheck policy, TPM, authentication methods and trust model.
Intune configurationShared-device or kiosk configuration fails
Start hereCheck assigned-access account, app identity and restrictions.
Intune configurationOneDrive Known Folder Move does not start
Start hereCheck licence, sign-in, folder state and policy conflict.
OneDrive / IntuneWi-Fi profile deploys but cannot connect
Start hereCheck SSID, EAP method, certificate chain and RADIUS.
Network / PKIVPN profile deploys but authentication fails
Start hereCheck plug-in, certificate, server and authentication method.
Network / PKISCEP or PKCS certificate is not issued
Start hereCheck root trust, connector or NDES, template and assignment.
PKI / IntuneTrusted-root certificate is missing
Start hereDeploy the correct root to the intended population before SCEP.
PKI / IntuneUniversal Print printer is unavailable
Start hereCheck licence, printer sharing, group access and connector.
Universal PrintRemote wipe or reset remains pending
Start hereConfirm the device is online and review action status.
Intune configurationRisk of wiping a device instead of retiring it
Start hereUse clear runbooks, least privilege and multi-admin approval.
Intune configuration