UEFI Settings with DFCI don't process, deployment status staying on Pending

Christian Kruesi 216 Reputation points
2020-10-14T13:47:59.757+00:00

We have some Surface Pro 7 and I want to try to secure the UEFI Settings with DFCI as described in this [Microsoft Learn article][1]. The devices are registered by our CSP, autopilot works, the profiles for autopilot deployment, Enrollment State Page and DFCI are assigned. But the Deployment Status of my test devices is hanging on Pending. Are there any logfiles for DFCI available? Any Idea to my problem? Any help highly appreciated, thanks. [1]: https://learn.microsoft.com/en-us/mem/intune/configuration/device-firmware-configuration-interface-windows

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,720 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,248 questions
0 comments No comments
{count} votes

Accepted answer
  1. Christian Kruesi 216 Reputation points
    2020-11-13T15:07:07.717+00:00

    It was the mistake of the CSP as suspected on this tweet: https://twitter.com/ncbrady/status/1324269514259943424. So the CSP did something wrong (although autopilot deployment still worked). I hope he can fix it for the already delivered devices.

    On the one hand I'm happy that it finally works and that I didn't make a mistake and on the other hand I'm frustrated because I lost dozens of hours.

    Thanks to everyone who answered and helped here...


7 additional answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,146 Reputation points MVP
    2020-10-14T17:51:11.44+00:00

    Have you verified on the device itself whether the policy is applying or not? In my experience the status on Intune can take a while to update sometimes.

    0 comments No comments

  2. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2020-10-15T02:02:43.847+00:00

    anonymous user, Agree with RahulJindal, we can wait some more time to let the status update to Intune. Meanwhile, to check if the policy is applied, we can also check the Advanced Diagnostic report under Accounts->Access Work or school->Azure AD account->info->Advanced Diagnostic Report to see if the setting is there..
    https://learn.microsoft.com/en-us/windows/client-management/mdm/diagnose-mdm-failures-in-windows-10#download-the-mdm-diagnostic-information-log-from-windows-10-pcs

    In addition, we can also verify UEFI settings on DFCI-managed devices
    https://learn.microsoft.com/en-us/surface/surface-manage-dfci-guide#verifying-uefi-settings-on-dfci-managed-devices

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  3. Christian Kruesi 216 Reputation points
    2020-10-15T07:37:42.523+00:00

    Thanks for your answers, @Rahul Jindal [MVP] and @Crystal-MSFT .

    I tried to verify the UEFI settings directly in the UEFI but the settings in the devices menu aren't greyed out and in the management menu is still written: "Zero-touch UEFI Management: Ready".

    Didn't looked at the Advanced Diagnostic Report, thanks for this advice. But I can't find there something that looks like beeing in relation to DFCI.


  4. Christian Kruesi 216 Reputation points
    2020-10-17T07:42:54.933+00:00

    Is there a way to check if my Cloud Solution Provider CSP partner did a mistake when registering the devices? Are there any logfiles to get a hint where to look further? Thanks in advance.

    0 comments No comments