You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?
Trap 1: Reissue the user's Microsoft 365 license from the admin center.
Licensing governs service access, not policy assignment; a licensed user with a correctly targeted device still receives policy. Reissuing is tempting when a user cannot sign in or Intune reports an unlicensed state, but the device is enrolled and reporting compliance, so licensing is not the failing dependency.
Trap 2: Reset the device's enrollment state via the Company Portal.
Resetting enrollment state removes the device's Intune and Microsoft Entra ID registration, forcing re-enrolment and wiping work data; it does not deliver the missing policy. It tempts when a device is stale or duplicated, where re-enrolment genuinely fixes sync. Here the device already reports compliance status, so the management channel is intact.
Trap 3: Run Invoke-Command to remotely execute gpupdate /force.
gpupdate /force refreshes Group Policy from on-premises domain controllers; it has no effect on Intune MDM policy, which arrives via the MDM channel and the Intune Management Extension. It tempts on hybrid-joined devices where Group Policy and Intune coexist, but the stem concerns Intune policy delivery specifically.
- A
Ensure the device is in the correct Microsoft Entra ID group targeted by the policy.
Policy assignment flows through Microsoft Entra ID group membership, so a device outside the targeted group never receives the configuration. Confirming correct group membership restores delivery of the security policy and clears the noncompliant state.
- B
Reissue the user's Microsoft 365 license from the admin center.
Why it fails: Licensing governs service access, not policy assignment; a licensed user with a correctly targeted device still receives policy. Reissuing is tempting when a user cannot sign in or Intune reports an unlicensed state, but the device is enrolled and reporting compliance, so licensing is not the failing dependency.
- C
Reset the device's enrollment state via the Company Portal.
Why it fails: Resetting enrollment state removes the device's Intune and Microsoft Entra ID registration, forcing re-enrolment and wiping work data; it does not deliver the missing policy. It tempts when a device is stale or duplicated, where re-enrolment genuinely fixes sync. Here the device already reports compliance status, so the management channel is intact.
- D
Verify that the device has an active internet connection and can reach Intune services.
Intune policies reach devices through the Microsoft Intune service over the internet; without an active connection the device cannot check in, receive configuration, or update compliance status. Verifying connectivity to Intune services restores policy delivery and compliance evaluation.
- E
Run Invoke-Command to remotely execute gpupdate /force.
Why it fails: gpupdate /force refreshes Group Policy from on-premises domain controllers; it has no effect on Intune MDM policy, which arrives via the MDM channel and the Intune Management Extension. It tempts on hybrid-joined devices where Group Policy and Intune coexist, but the stem concerns Intune policy delivery specifically.