Some tickets eat an afternoon because the symptom looks like a configuration mistake when it is actually a documented Intune known issue. Microsoft keeps a public list of them, but it's easy to forget it exists while you're re-checking an assignment for the third time. In this post I'll go through the items on that list that touch Company Portal, Microsoft Store apps and compliance messaging, with what you see, what Microsoft says about it, what to tell users and how to work around it.
Status (October 2026): every item below is marked Active on Microsoft Learn's "Known issues with Microsoft Intune" page, last updated by Microsoft on 30 March 2026 and checked on 3 October 2026. Microsoft updates the page when an issue is resolved and typically links a Customer Success blog post with details. Re-check it before you quote any of this to a user.
How to use this list#
Before you troubleshoot, match the symptom against the page. If it's there, your job changes from "find the misconfiguration" to "confirm it's this issue, apply the workaround, and set expectations". The items below use Microsoft's wording for the issue itself; the advice around it is mine.
Regional selection for Microsoft Store apps is unavailable#
- What you see: when adding a Microsoft Store app, you can't pick a region, and some apps you expect to find don't appear in search.
- Why (as documented): regional selection is temporarily unavailable while Microsoft addresses an issue affecting app creation. In the meantime Intune uses the default United States Store catalog when searching for and adding apps. Existing Store apps aren't affected.
- What to tell requesters: apps already deployed keep working; a new app that exists only in a non-US catalog can't be added through the Store type until Microsoft restores region selection.
- Workaround: search by the exact app name in case it is in the US catalog, and for urgent needs package the vendor's installer as a Win32 app instead.
Configuration Manager apps load slowly in Company Portal#
- What you see: on co-managed devices, the Windows apps page in Company Portal sits empty or spinning before Configuration Manager apps appear.
- Why (as documented): Windows apps deployed with Configuration Manager might take multiple seconds, up to a few minutes, to load on the Windows apps page. Microsoft is investigating.
- What to tell users: wait on the page; the apps do arrive. It isn't a sign the app was removed.
- Workaround: none documented. If a Configuration Manager app is urgent, Software Center still lists it immediately.
Azure enterprise applications don't show in Company Portal#
- What you see: Microsoft Entra enterprise applications you published for users aren't listed in Company Portal for Windows or on the Company Portal website.
- Why (as documented): Microsoft is investigating and will update the page when more information is available. No cause has been published, so don't attribute one.
- What to tell users: the app itself is fine; the shortcut is missing.
- Workaround: point users to the My Apps portal or the application's own URL until the listing returns.
Remediation message lists only the first OS build range#
- What you see: a Windows device is noncompliant for its OS build. Company Portal tells the user the OS needs updating and shows one acceptable version range, even though your policy allows several.
- Why (as documented): when multiple ranges are configured with the Valid operating system builds compliance setting, the Company Portal message displays only the first range rather than all acceptable ranges. The compliance policy itself is enforced correctly; only the message is incomplete.
- What to tell users: the device really is outside the allowed builds; the message just doesn't show every option.
- Workaround: update the device to a build inside any of the configured ranges. Put the full list of acceptable builds in your own helpdesk article, and order the ranges in the policy so the first one is the version most devices should move to.
Android 12 clipboard toast notification#
- What you see: on Android 12 or later, users of Company Portal 5.0.5450.0 or later see a toast such as "Outlook pasted from your clipboard" while using apps like Outlook.
- Why (as documented): Android 12 introduced a system notification whenever an app reads the clipboard, regardless of MDM enrolment or app protection policies. Microsoft notes that clipboard data is never stored locally or sent to Microsoft.
- What to tell users: it's an Android privacy feature, not a sign of data leaving the device.
- Workaround: none needed; include the explanation in your Android onboarding notes to cut down the tickets.
Other active items worth knowing#
The same page lists more Active items that regularly masquerade as admin mistakes:
- Fully managed Samsung devices on Android 11 and later can show as noncompliant after a managed update, which can affect Conditional Access.
- Intune policy reports can show multiple records for one device, inaccurate "pending" states, and summary charts that disagree with report lists.
- Several Office settings in the settings catalog don't automatically enable their required parent setting; Microsoft marks the affected ones as deprecated in the catalog.
- When a user deletes the management profile on an iOS/iPadOS or macOS device, Intune may not reflect the unenrolment for up to 30 days.
- Exported Android Enterprise reports don't filter by corporate-owned management mode; filter the exported file instead.
Stay ahead: track the page and escalate properly#
The known issues page didn't advertise a feed of its own when I checked, but Microsoft Learn exposes RSS through its search API; Microsoft prints the same pattern on its Entra "What's new" page. Build one for this page with a search for its title, for example https://learn.microsoft.com/api/search/rss?search=%22Known+issues+with+Microsoft+Intune%22&locale=en-us, and pair it with the Intune Customer Success blog, which the page links to for the backlog of past issues, and Service health in the Microsoft 365 admin center for incidents.
When a symptom isn't on the page, open a case from the admin center under Troubleshooting + support › Help and support (or the question mark near your profile picture). Your account needs an Entra role that includes the support-ticket permission. Include from the start: the tenant ID, the Intune device name and ID, the user principal name, exact timestamps with time zone, screenshots of the user-facing message, the policy or app name, and diagnostics. For Windows, run the Collect diagnostics device action and download the package; for mobile devices, ask the user to send logs from the Company Portal app. A case that opens with that data skips a full round trip.
Key takeaways#
- Check the known issues page before you redo an assignment; Microsoft's own wording is the quickest way to close a ticket with confidence.
- For the remediation-message issue, the policy is right and the text is wrong; document the full build list yourself.
- Follow the page through a Learn RSS search, the Customer Success blog and Service health, and open support cases with device, user and timing data attached.