UEFI Settings with DFCI don't process, deployment status staying on Pending

Christian Kruesi 216 Reputation points
2020-10-14T13:47:59.757+00:00

We have some Surface Pro 7 and I want to try to secure the UEFI Settings with DFCI as described in this [Microsoft Learn article][1]. The devices are registered by our CSP, autopilot works, the profiles for autopilot deployment, Enrollment State Page and DFCI are assigned. But the Deployment Status of my test devices is hanging on Pending. Are there any logfiles for DFCI available? Any Idea to my problem? Any help highly appreciated, thanks. [1]: https://learn.microsoft.com/en-us/mem/intune/configuration/device-firmware-configuration-interface-windows

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,730 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
0 comments No comments
{count} votes

Accepted answer
  1. Christian Kruesi 216 Reputation points
    2020-11-13T15:07:07.717+00:00

    It was the mistake of the CSP as suspected on this tweet: https://twitter.com/ncbrady/status/1324269514259943424. So the CSP did something wrong (although autopilot deployment still worked). I hope he can fix it for the already delivered devices.

    On the one hand I'm happy that it finally works and that I didn't make a mistake and on the other hand I'm frustrated because I lost dozens of hours.

    Thanks to everyone who answered and helped here...


7 additional answers

Sort by: Most helpful
  1. Christian Kruesi 216 Reputation points
    2020-10-19T09:49:32.577+00:00

    Thanks @Crystal-MSFT for your help. One error under DeviceManagement-EnterpriseDiagnostics-Provider is something about a fake policy: ![33240-error01.png][1] [1]: /api/attachments/33240-error01.png?platform=QnA No idea, if this is important. I opened a case and hope to get some more help there. Thank you anyway.


  2. Christian Kruesi 216 Reputation points
    2020-10-27T09:52:30.707+00:00

    Some news for the moment.

    According to this answer on twitter (https://twitter.com/IntuneSuppTeam/status/1320843122058928129) the reporting of DFCI settings back to Intune is broken and will be fixed soon.

    But that is only one part of my problem. More serious is that the settings aren’t applied and the UEFI isn’t secured by the moment.
    So still hoping for new insights and any help still highly appreciated.


  3. Christian Kruesi 216 Reputation points
    2020-11-03T15:40:26.71+00:00

    Today DFCI is general available: https://techcommunity.microsoft.com/t5/microsoft-endpoint-manager-blog/microsoft-endpoint-manager-support-for-dfci-firmware-management/ba-p/1829869. But still it doesn’t work here. So every help is still highly appreciated.

    0 comments No comments