Apply Policy CSP Error for "RequirePrivateStoreOnly" , "TurnOnPowerShellScriptBlockLogging" and "ConfigureWindowsSpotlightOnLockScreen" when apply in intune portal to my devices.

Toh 81 Reputation points
2021-03-18T14:45:54.617+00:00

Hi All, I have apply this 3 CSP in my Intune following "CIS Microsoft Intune for Windows 10 (Release 2004) Benchmark" to my window 10 devices and I got Error. Anyone encounter the same problem? you can try on your devices, I suspect it will not work on windows 10 20H2. do let me know if you encounter the same Error ( -2016281112 (Remediation failed) ERROR CODE 0x87d1fde8)

18.9.72.2 RequirePrivateStoreOnly (Page 852)

./Device/Vendor/MSFT/Policy/Config/ApplicationManagement/RequirePrivateStoreOnly
Integer "1"

18.9.95.1 TurnOnPowerShellscriptBlockLogging (Page 892)

./Device/Vendor/MSFT/Policy/Config/WindowsPowerShell/TurnOnPowerShellScriptBlockLogging
Integer "0"

19.7.8.1 ConfigureWindowsSpotlightOnLockScreen (Page 954)

./User/Vendor/MSFT/Policy/Config/Experience/ConfigureWindowsSpotlightOnLockScreen
Integer "2"

One more question which is not related , will my posted question be deleted after few days if i never read? i remember I posted one question 1 weeks back and now is gone. how can i find all the question i posted before?

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,715 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,320 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,341 Reputation points
    2021-03-19T08:28:34.593+00:00

    @Toh Thanks for posting in our Q&A. For this issue, I have done the test in my lab(Windows 10 version 20H2). The settings are same as you provided.

    For "RequirePrivateStoreOnly" custom profile, I delploy it to my device group and I find it is successful.
    79563-image.png
    For "TurnOnPowerShellScriptBlockLogging", there is the same build-in setting under Administrative Templates, so it is suggested to configure in Administrative Templates and it will succeed.
    79583-image.png
    For "ConfigureWindowsSpotlightOnLockScreen" custom profile, I deploy it to my user group and I find it is successful.
    79554-image.png

    If you want to find the case you posted, you can click on the "Q&A" in the upper left corner and enter the question title to find. Another way is click on the "Activity" under your own name.

    If there is anything unclear, feel free to let us know.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


1 additional answer

Sort by: Most helpful
  1. Toh 81 Reputation points
    2021-03-22T07:05:59.093+00:00

    Hi,

    @Lu Dai-MSFT

    I have realise my issue as well, previously I have tested it on window 10 pro and I encounter the error for "RequirePrivateOnly" and "ConfigureWindowsSPotlightONLOckScreen".
    Now I have setup window 10 enterprise and both the error is gone except for "TurnonPOwershellScriptBlockLogging", it will not work on both WIndow 10 Pro and Enterprise. Thus I will just follow the GUI step you have provided above.

    Thanks a lot for your time to help me to test it out. Really appreciate for your kindness and God Bless.