Management agent Not Available

hieunm2411 25 Reputation points
2025-01-08T03:46:01.77+00:00

I have some company devices that are marked as non-compliant. The report shows some are not secure boot enabled, some are not Bitlocker encrypted. But when I check on these computers, all conditions are compliant. And when I look at the report in Devices -> Monitor -> Noncompliant devices, I see that the Management agent column of those computers is in Not Available status. I checked the Microsoft Intune Management Extension services and all the log files in C:\ProgramData\Microsoft\IntuneManagementExtension\Logs but found nothing unusual. I'm looking forward to your support in resolving this issue. Thank you.

User's image

Microsoft Intune Compliance
Microsoft Intune Compliance
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Compliance: Adhering to rules, standards, policies, and laws.
177 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,423 questions
{count} votes

Accepted answer
  1. Xenia-MSFT 3,600 Reputation points Microsoft Vendor
    2025-01-09T02:50:14.1033333+00:00

    @hieunm2411 Thanks for your update.

    Based on my research, Secure Boot is supported on some TPM 1.2 and 2.0 devices. For devices that don't support TPM 2.0 or later, the policy status in Intune shows as Not Compliant. TPM 2.0 requires UEFI firmware. A computer with legacy BIOS and TPM 2.0 won't work as expected.

    Please follow these steps to confirm:

    1.Check the TPM version.

    Type tpm.msc in the Run box, and then check the value in Specification Version.

    2.Open an elevated command prompt, and run the msinfo32 command.

    3.In System Summary, verify that BIOS Mode is UEFI, and PCR7 Configuration is Bound.

    For "Encryption of data storage on a device", please try to reboot the devices and then check if the compliance status will be changed.

    Hope it will help


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Xenia-MSFT 3,600 Reputation points Microsoft Vendor
    2025-01-08T07:03:04.3566667+00:00

    @hieunm2411 Thanks for posting in our Q&A.

    Based on checking in my environment, the compliant device's management agent also shows "Not Available". So, it seems not related to this reason.

    User's image

    For this issue, could you please show us the screen shot of detailed error under Devices > the target device > Device compliance > the compliance policy shows not compliant in intune portal.

    Then we will continue to discuss this issue.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.