- Article
- 9 minutes to read
In Intune, you can create device configuration profiles that contain connectivity settings for your WiFi network. Use this setting to connect users' Android, iOS/iPadOS, and Windows devices to your organization's network.
This article shows what a Wi-Fi profile looks like when successfully applied to devices. It also includes registry information, general issues, and more. Use this article to troubleshoot your WiFi profiles.
For more information about Wi-Fi profiles in Intune, seeAdd and use WiFi settings on your devices.
Use
The examples in this article use SCEP certificate authentication for Intune profiles. It also assumes that the Trusted Root and SCEP profiles are working properly on the device.
Troubleshooting Android WiFi profiles
In this section, we review the user experience when installing configuration profiles on an Android device. This scenario uses a Nokia 6.1 device. Before installing the Wi-Fi profile on the device, install the Trusted Root and SCEP profiles.
Users receive a notification about installing the Trusted Root Certificate Profile:
The following notification prompts installation of the SCEP certificate profile:
Advice
If you're using a device administrator-managed Android device, the list might contain multiple certificates. If a certificate profile is revoked or deleted, the certificate remains on the device. In this scenario, select the latest certificate. This is usually the last certificate shown in the list.
(Video) Microsoft Endpoint Manager Intune Configuration Profiles Part XII Wi Fi ProfilesThis situation does not occur on Android Enterprise and Samsung Knox devices. For more information, seeManage Android devices with work profilejRemove SCEP and PKCS certificates.
Users will then receive a notification to install the Wi-Fi profile:
Once complete, the Wi-Fi connection will appear as a saved network:
Check the Company Portal app logs
On Android is theOmadmlog.logThe file describes the activities of the Wi-Fi profile when installed on the device. You can have up to five omadmlog log files. Make sure you get the last sync timestamp as it will help you find the related registry entries.
Use in the example belowCMTraceTo read the logs and search for wifimgr:
The following log shows the results of your search and shows the successfully created Wi-Fi profile:
Verb com.microsoft.omadm.platforms.android.wifimgr.OneX 15118 04142 Start parsing OneX from Wifi XML.2019-08-01T19:22:46.8100000 VERB com.microsoft.omadm.platforms.android.wifimgr.OneX 15118 04142 Parsing completed Wifi OneX XML.2019-08-01T19:22:46.8209999 VERB com.microsoft.omadm.platforms.android.wifimgr.WifiProfile 15118 04142 Completed parsing wifi profile xml named "<profile id>" .2019-08-01T19 : 22:46.8240000 INFO com.microsoft.omadm.utils.CertificateSelector 15118 04142 Selected CA certificate with alias: "user:205xxxxx.0" and thumbprint "<thumbprint>".2019-08-01T19 : 22:47.0990000 VERB com.microsoft . omadm.platforms.android.certmgr.CertificateChainBuilder 15118 04142 Complete certificate chain built with Complete certs.2019-08-01T19:22:47.1010000 VERB com.microsoft.omadm.utils.CertUt ils 15118 04142 1 certificate(s) with criteria: User < ID>[i:<ID>,17CECEA1D337FAA7D167AD83A8CC7A8FCBF9xxxx;eku:1.3.6.1.5.5.7.3.1,1.3.6.1.5.5.7.3.2]2019-08-01T19:22:47.1090000 VERB com.microsoft.omadm . utils.CertUtils 15118 04142 0 Certificate(s) excluded by criteria:2019-08-01T19:22:47.1110000 INFO com.microsoft.omadm.utils.CertificateSelector 15118 04142 Selected client certificate with alias "User<ID>" and RequestId "ModelName =<ModelName>%2FLogicalName_<LogicalName>;Hash=-912418295'.2019-08-01T19:22:47.4120000 VERB com.microsoft.omadm.Services 15118 04142 Applied successfully, WiFi profile enabled and '<Profile- ID>'2019 saved -08-01T19:22:47.4240000 VERB com.microsoft.omadm.platforms.android.wifimgr.OneX 15118 04142 Start parsing OneX from Wifi XML.2019-08-01T 19:22:47.4910000 VERB com.microsoft.omadm.platforms.android.wifimgr.OneX 15118 04142 OneX full scan of wifi XML.2019-08-01T19:22:47.4970000 VERB com.microsoft.omadm.platforms.android.wifimgr. WifiProfile 15118 04142 Starts parsing wifi-i profile xml named <profile id>. XML.2019-08-01T19:22:47.5820000 VERB com.microsoft.omadm.platforms.android.wifimgr.OneX 15118 04142 Full OneX scan of Wifi XML.2019-08-01T19:22:47.5900000 VERB com.microsoft.omadm .platforms.android.wifimgr.WifiProfile 15118 04142 XML parsing of wifi profile named '<profile id>' completed.2019-08-01T19:22:47.5910000 INFO com.microsoft.omadm.platforms.android Applied profile <Profile ID>
Troubleshooting iOS/iPadOS WiFi profiles
After the Wi-Fi profile is installed on the device, it will appear on theManagementprofil:
Check the iOS/iPadOS console and device logs
On iOS/iPadOS devices, the Company Portal app log does not contain information about Wi-Fi profiles. To view the installation details of your Wi-Fi profiles, use the console/device logs:
Connect iOS/iPadOS device to Macapplications>Utilitiesand open the console app.
Lowaction, chooseInclude informational messagesjInclude debugging messages:
(Video) Create and Deploy Wifi profile in Microsoft IntunePlay the scenario and save the logs to a text file:
- Select all messages on the current screen:Edit>Choose All.
- Copy messages:Edit>Copy.
- Paste the log data into a text editor and save the file.
Browse the saved log file to view detailed information. If the profile installs successfully, the output looks like the following log:
Line 390870: Debug 11:19:58.994815 -0400 Profiled dependent www.windowsintune.com.wifi.Contoso add Microsoft.Profiles.MDM principal in domain ManagingProfileToManagedProfile for system\Line 390872: Debug 11:19:58.995210 -0400 Profiled dependent Microsoft .Profiles.MDM to www.windowsintune.com.wifi.Contoso parent in domain ManagedProfileToManagingProfile to system\Line 392346: Default 11:19:59.360460 -0400 Profiled profile \'93www.windowsintune.com.wifi.Contoso\' 94 installed .\
Troubleshooting Windows Wi-Fi profiles
After installing the Wi-Fi profile on the device, go toIdeas>Content>access to work or school> Select your account >Information:
InMicrosoft Managed Spaces,W-lanit shows:
To view the Wi-Fi connection, go toIdeas>Red e-Internet>W-lan:
Check the Event Viewer logs
On Windows devices, details about Wi-Fi profiles are logged in Event Viewer:
- open thatEvent ViewerApplication
- About himVistaselect menuView analysis and debug logs.
- ExpandApplication and Service Logs>Microsoft>Window>DeviceManagement-Enterprise-Diagnostic-Provider>Administration
Its output resembles the following logs:
Log Name: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/AdminSource: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-ProviderDate: 7/8/2019 8:01:41 PMEvent ID: 1506 Task Category: (1 ) Level : InformationKeywords: (2)User: SYSTEMComputer: <computer name>Description:WiFi Configuration Service Provider: Node Set Value, Type: (0x4), Result: (The operation completed successfully.)
General problems
This section provides troubleshooting guidance for the following scenarios:
- The Wi-Fi profile is not implemented on the device
- The Wi-Fi profile is implemented on the device, but the device cannot connect to the network
- Users do not get a new profile after changing the password on the existing profile
- All Wi-Fi profiles report an error
- A Wi-Fi profile reports an error but appears to be working
The Wi-Fi profile is not implemented on the device
Confirm that the WiFi profile is assigned to the correct group:
- insideMicrosoft Endpoint Manager Admin Center, chooseDevices>configuration profiles.
- Select your profile >Tasks. Confirm that the selected groups are correct.
- Select in Endpoint ManagerTroubleshooting + Support. Check theTasksInformation.
Select in Endpoint ManagerTroubleshooting + Support. Confirm that the device can sync with Intune by checking the boxLast postTime.
If the Wi-Fi profile is associated with the Trusted Root and SCEP profiles, confirm that both profiles are deployed on the device. The Wi-Fi profile depends on these profiles.
On Windows 10 and newer devices, check the MDM diagnostic information log:
BecomesIdeas>Content>access to work or school.
(Video) Microsoft Endpoint Manager Intune Configuration Profiles Part VII Delivery OptimizationSelect your work or school account >Information.
At the bottom of theIdeaspage, selectCreate a report.
A window opens with the path to the log files. ChooseExport.
Ve a la
\Users\Public\Documents\MDMDiagnostics
Route and view the report:
Advice
For more information, seeDiagnose MDM errors in Windows 10.
On Android devices, if the Trusted Root and SCEP profiles are not installed on the device, you will see the following entry in the Company Portal app omadmlog file:
2019-08-01T19:18:13.5120000 INFO com.microsoft.omadm.platforms.android.wifimgr.WifiProfileManager 15118 04105 Skipping wifi profile <profile id> because it has pending certificates.
If Trusted Root and SCEP profiles are present and supported on the Android device, the Wi-Fi profile may not be on the device. This problem occurs when theCertificate SelectionThe Company Portal app provider cannot find a certificate that matches the specified criteria. The specific criteria can be included in the certificate template or in the SCEP profile.
If the matching certificate is not found, the certificates will not be installed on the device. The Wi-Fi profile is not applied because it does not have the correct certificate. In this scenario, you see the following entry in the omadmlog file for the Company Portal app:
Skipping WiFi profile <profile ID> because it has pending certificates.
The following example log shows the exclusion of certificates because theany purposeExtended Key Usage (EKU) criteria were specified. However, the certificates assigned to the device do not have this EKU:
2018-11-27T21:10:37.6390000 VERB com.microsoft.omadm.utils.CertUtils 14210 00948 Exclude the certificate with alias User<ID1> and RequestId <requestID1> because it has no purpose EKU.2018-11-27T21 :10 :37.6400000 VERB com.microsoft.omadm.utils.CertUtils 14210 00948 Exclude the certificate with alias User<ID2> and RequestId <requestID2> because it has no purpose EKU.2018-11-27T21:10:37.6400000 VERB com.microsoft. omadm.utils.CertUtils 14210 00948 0 Certificate(s) with criteria:2018-11-27T21:10:37.6400000 VERB com.microsoft.omadm.utils.CertUtils 14210 00948 2 Certificate(s) excluded by criteria:2018-11-27T21 :10:37.6400000 INFO com.microsoft.omadm.platforms.android.wifimgr.WifiProfileManager 14210 00948 Skipping wifi profile <profile id> because it has pending certificates.
The following example shows the SCEP profile entered in theany purposeECU. However, it is not entered in the certificate template of the certification authority (CA). To fix the problem, add theany purposeCertificate template option. Or delete themany purposeSCEP-Profiloption.
(Video) Microsoft Endpoint Manager Intune Configuration Profiles Part I The Basics and BeyondConfirm that all required certificates are in the full certificate chain on the Android device. Otherwise, the Wi-Fi profile cannot be installed on the device. For more information, seeMissing intermediate CA(opens the Android website).
Filter the omadmlog with keywords to find information e.g. B. which certificate is used in the WLAN profile and whether the profile was successfully applied.
Use for exampleCMTraceto read the registers. Use the search string to filter for "wifimgr":
The output resembles the following log:
If you see an error in the log, copy the timestamp of the error and remove the filter from the log. Then use the "Find" option with the timestamp to see what happened just before the error.
The Wi-Fi profile is implemented on the device, but the device cannot connect to the network
Typically, this issue is caused by something outside of Intune. The following tasks can help you understand and troubleshoot connectivity issues:
Connect to the network manually using a certificate with the same criteria as the Wi-Fi profile.
If you can connect, look at the certificate properties in the manual connection. Then update the Intune WiFi profile with the same certificate properties.
Connection errors are usually logged in the Radius server log. For example, it should show if the device tried to connect using the Wi-Fi profile.
Users do not get a new profile after changing the password on the existing profile
You create a corporate Wi-Fi profile, deploy the profile to a group, change the password, and save the profile. If the profile changes, some users may not receive the new profile.
To resolve this issue, set up guest WiFi. If the corporate WiFi goes down, users can connect to the guest WiFi. Be sure to enable all automatic connection settings. Deploy the guest WiFi profile to all users.
Some additional recommendations:
- If the Wi-Fi network you are connecting to uses a password or passphrase, make sure you can connect directly to the Wi-Fi router. You can test with an iOS/iPadOS device.
- After successfully connecting to the wireless endpoint (wireless router), note the SSID and the credentials used (this value is the password or passphrase).
- Enter the SSID and credentials (password or passphrase) in the Pre-Shared Key field.
- Deploy to a test group with a limited number of users, preferably just the IT team.
- Sync your iOS/iPadOS device with Intune. Sign up if you haven't already.
- Try connecting to the same Wi-Fi endpoint (as mentioned in the first step) again.
- Deploy to larger groups and eventually to all expected users in your organization.
All Wi-Fi profiles report an error
For corporate-owned, dedicated, and fully-managed Android Enterprise work profile devices, you may receive a report that all profiles failed. This can happen when you implement more than one Wi-Fi profile. In this case, if one fails, all profiles you provided will be reported as failed (even if they still work).
A Wi-Fi profile reports an error but appears to be working
If a Wi-Fi profile works fine on an Android device but reports an error, it may be a reporting error. To fix this, update the Intune app to version 2021.05.02 or later.
FAQs
How do you troubleshoot Intune issues? ›
- Sign in to Microsoft Endpoint Manager admin center.
- Select Troubleshooting + support > Troubleshoot.
- Find and select a User by entering a display name or email.
- If the user has multiple devices, filter by Device.
- Review the provided information to help troubleshoot end-user issues.
Device profiles allow you to add and configure settings, and then push these settings to devices in your organization. You have some options when creating policies: Administrative templates: On Windows 10/11 devices, these templates are ADMX settings that you configure.
How do I add a WIFI profile to Intune? ›...
Create the profile
- Android device administrator.
- Android (AOSP)
- Android Enterprise.
- iOS/iPadOS.
- macOS.
- Windows 10 and later.
- Windows 8.1 and later.
Intune Policy Sync Interval
Do you know how long does it take for devices to get a Intune policy, profile, or app after they are assigned? The answer is 8 hours. The default Intune policy refresh intervals for different device types are already specified by Microsoft.
Common issues with Intune policy reports
We are aware of some common issue with Intune policy reports, including multiple records for a single device, inaccurate "pending" status, and inconsistencies between data in report lists and in summary charts.
- Open the Company Portal app for Android on your device.
- Tap Devices and then select your device.
- Under Device Settings Status, tap Check device settings. ...
- After the check, your device settings status will either read, In Compliance or Not in Compliance.
Configuration profiles are intended for managing the settings or configurations of different device features in a remote and centralized way. Each configuration profile defines a range of settings concerning a specific feature.
What is a configuration profile used for? ›A profile allows you to manage configurations and settings centrally and then deploy those configurations to as many locations as necessary. Use profiles to update or modify multiple servers or devices instead of manually changing settings for each one.
What is a device profile? ›A device profile comprises the set of attributes (services and/or features) that associate with a particular device.
How do I setup a Wi-Fi profile? ›- Network name: Provide the name that devices will display as the network name. ...
- SSID: Specify the case-sensitive ID of the wireless network.
- Connect automatically when this network is in range.
- Look for other wireless network while connected to this network.
How do I create a custom configuration profile in Intune? ›
...
Create the profile
- Android device administrator.
- Android Enterprise.
- iOS/iPadOS.
- macOS.
- Windows 10 and later.
- Open your phone's Settings app.
- Tap Network & internet. Internet. If you can't find it, search for the setting you want to change. ...
- At the bottom, tap Network preferences.
- Tap an option. These vary by phone and Android version. Turn on Wi-Fi automatically: Have Wi-Fi automatically turn on near saved networks.
Sign in to the Microsoft Endpoint Manager admin center. Select Devices > All devices. In the list of devices you manage, select a device to open its Overview pane, and then select Sync. To confirm, select Yes.
How often do Intune configuration profiles run? ›The notification times vary, including immediately up to a few hours. These notification times also vary between platforms. If a device doesn't check in to get the policy or profile after the first notification, Intune makes three more attempts.
How do I check my Intune enrollment failure? ›In the admin center, go to Troubleshooting + support > Select user. Choose a user > Select. Under Enrollment failures, select a row to view more details about the failure and recommended remediation steps.
What happens if a device is not compliant in Intune? ›The result of this default is when Intune detects a device isn't compliant, Intune immediately marks the device as noncompliant. After a device is marked as noncompliance, Azure Active Directory (AD) Conditional Access can block the device.
How do I check my Intune device compliance? ›- Sign in to the Microsoft Endpoint Manager admin center.
- Select Devices > Monitor, and then from below Compliance select the report you want to view. Some of the available compliance reports include: Device compliance. Noncompliant devices. Devices without compliance policy. Setting compliance.
Device will show “Not Evaluated” if the User Account Control (UAC) not enabled. Though the device is registered with Azure AD and Azure Intune your device will show Not Evaluated in Azure portal if UAC is not enabled in your system. It is mandatory to enable UAC to enroll your system in Azure Intune.
How often do devices check into Intune? ›By default, Intune devices check in every 8 hours. If Last check in is more than 24 hours, there may be an issue with the device. A device that can't check in can't receive your policies from Intune.
How do I update device settings in Intune company portal? ›- Your device begins enrolling. ...
- On the Company Access Setup screen, check that your device is enrolled. ...
- Your organization might require you to update your device settings. ...
- When setup is complete, tap DONE.
How do I make my device compliant in Intune? ›
To manage the compliance policy settings, sign in to Microsoft Endpoint Manager admin center and go to Endpoint security > Device compliance > Compliance policy settings. This setting determines how Intune treats devices that haven't been assigned a device compliance policy.
What are the 3 types of profiles? ›Profile Type Comparisons: Mandatory, Local, & Roaming.
Which are the three 3 main types of user profiles? ›- Local User Profiles. A local user profile is created the first time that a user logs on to a computer. ...
- Roaming User Profiles. A roaming user profile is a copy of the local profile that is copied to, and stored on, a server share. ...
- Mandatory User Profiles. ...
- Temporary User Profiles.
A provisioning profile is a collection of information that links an App ID with signing certificates and authorized devices. It is used to control and authorize the devices on which the app can run and the Apple services it can access (such as iCloud or In-App Payment).
What are the types of profiles? ›A profile-type defines a set of properties, also referred to as a schema, that are inherent to all profiles of that type. This set of properties is used internally to group objects and enforce overall system constraints. Examples of common profile-types are customer , employee , and contractor .
What document type does a configuration profile use? ›Configuration Profile(s means an XML file that allows You to distribute configuration information (e.g., VPN or Wi-Fi settings) and restrictions on device features (e.g., disabling the camera) to compatible Apple-branded products through Apple Configurator or other similar Apple- branded software tools, email, a ...
Why configuration files are used? ›Configuration files ("config files" for short) are important to modern computing. They allow you to customize how you interact with an application or how an application interacts with the rest of your system.
How do I create a device profile? ›Navigate to Device Profiles & Policies > Device Profiles and click CREATE NEW PROFILE button. In the create profile dialog select Windows tab. Enter a name for your profile and click on SUBMIT. The Profile Creator wizard will be launched.
What is device configuration? ›The Android Device Configuration Service periodically sends data from Android devices to Google. This data helps Google ensure that your device remains up-to-date and is working as well as possible.
What is configuration policy in Intune? ›App configuration policies can help you eliminate app setup problems by letting you assign configuration settings to a policy that is assigned to end-users before they run the app. The settings are then supplied automatically when the app is configured on the end-users device, and end-users don't need to take action.
How do I find my Wi-Fi profile? ›
- Type and search [Command Prompt] in the Windows search bar①, then click [Open]②.
- In the Command Prompt window, type the command [Netsh wlan show profile name=”Wi-F name” key=clear]③, and then press Enter key. ...
- You can find the Wi-Fi password in the [Key Content] field of Security settings④.
The easiest way to view your network profiles is through the Settings app. On both Windows 10 or 11, go to Settings > Network & Internet > Wi-Fi. Click Manage known networks to see a list of all available network profiles. You can also view a list of wireless network profiles in Command Prompt.
What does a Wi-Fi profile do? ›Wi-Fi profiles provide Android, iOS, MAC OS X, and Windows devices with secure access to wireless networks. One or more Wi-Fi profiles can be assigned to specific user roles or to all roles. Up to 10 profiles can be defined.
How do I create and manage profiles? ›- Start the Profile Management Tool to create a new runtime environment. ...
- Click Create on the Profiles tab to create a new profile. ...
- Select Management and click Next. ...
- Select Deployment manager and click Next. ...
- Select either Typical profile creation or Advanced profile creation, and click Next.
Both solutions are parts of Microsoft Endpoint Manager – a single, integrated platform for managing all the endpoints in the organization. Intune is a cloud-based solution that allows you to manage company-owned and personal devices, while SCCM is a more traditional on-premises solution.
Can you copy a configuration profile in Intune? ›You can duplicate the settings catalog profile or settings catalog policy in Intune with the following steps. Sign-in to Microsoft Endpoint Admin Center. Go to Devices > Configuration profiles. Right-click the settings catalog profile and select Duplicate.
How do I remove all Wi-Fi profiles? ›- Click the Start button. in the bottom left corner of the screen.
- Type "network and" and select Network and Sharing Center from the search result.
- Select Manage wireless networks.
- Select the Wi-Fi profile you want to delete then select the Remove button. Note. ...
- Select Yes to confirm.
- Click Start > Control Panel > System and Security > Device Manager.
- Click the Plus Sign (+) next to Network Adapters.
- Right-click the wireless adapters and, if disabled, click Enable.
- Click the wireless icon in the notification area.
- Select one one of the wireless networks listed.
- Check the box for Connect automatically and the click Connect. This automatically moves the network up the priority list.
- Sign in to the Microsoft Endpoint Manager admin center.
- Navigate to Devices > Windows > select a supported device.
- On the device's Overview page, select … > ...
- To see the status of the action, select Device diagnostics monitor.
How do I check my Intune health? ›
The Service health and message center page are where you can view details about the Intune Service health, Issues in your environment that require action, and Message center posts that can provide information about updates and planned changes.
How do you test for Intune compliance? ›- Sign in to the Microsoft Endpoint Manager admin center.
- Select Devices > Monitor, and then from below Compliance select the report you want to view. Some of the available compliance reports include: Device compliance. Noncompliant devices. Devices without compliance policy. Setting compliance.
By default, Intune devices check in every 8 hours. If Last check in is more than 24 hours, there may be an issue with the device. A device that can't check in can't receive your policies from Intune.
Can Intune detect whether a device is jailbroken? ›Intune can't guarantee that each significant location change results in a jailbreak detection check, as the check depends on a device's network connection at the time.
How do I force a device to sync with Intune? ›- Sign in to the Microsoft Endpoint Manager admin center.
- Select Devices > All devices.
- In the list of devices you manage, select a device to open its Overview pane, and then select Sync.
- To confirm, select Yes.
- Click Start on your Windows device.
- Click on Settings.
- Click Accounts.
- Click Access work or school.
- Click Connected to MESA AD domain then click Info. Note: If the Info button does not appear on your device, your device has not been successfully enrolled.
- Go to Start.
- Open the Settings app. ...
- Select Accounts > Access work or school > Connect. ...
- To get to your organization's Intune sign-in page, enter your work or school email address. ...
- Sign in to Intune with your work or school account.
- In the search box on the taskbar, type Windows Security, and then select it from the results.
- Select Device performance & health to view the Health report.
Intune doesn't collect nor allow an Admin to see the following data: An end users' calling or web browsing history. Personal email. Text messages.
Can Intune track devices? ›When you use the Locate device action for an Android Enterprise dedicated device that is off-line and unable to respond with its current location, Intune attempts to display its last known location. This capability uses data submitted by the device when it checks in with Intune.
Does Intune require device compliance? ›
Device compliance policies are a key feature when using Intune to protect your organization's resources. In Intune, you can create rules and settings that devices must meet to be considered compliant, such as a minimum OS version.
How does Intune know if a device is personal or corporate? ›For Microsoft Intune, devices are considered personal by default. Here are some ways for a device to become identified as corporate: The device serial number is stored in Intune prior to enrollment. When the device is enrolled, Intune will find the match and automatically categorize the device as a corporate device.