IntuneHow-to

Intune Remediations: detect and fix common Windows issues at scale

Set up Intune Remediations end to end: licensing and tenant attestation, the exit-code contract, run context, schedules, on-demand runs and reading the results.

Remediations pair a detection script with a fix script, run them on a schedule across your Windows devices, and report per-device results in the Microsoft Intune admin center. In this how-to I'll cover the prerequisites that catch people out, the script contract, a small and safe example you can adapt, and how to read the results.

How this guide is organised: Prerequisites → How it works → Step-by-step → Verify the results → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. How it works. 3. Step-by-step (4 steps: Write and test the scripts; Create the script package; Assign and schedule; Run it on demand). 4. Verify the results. 5. Tips and gotchas. Toolbox: HealthScripts.log, AgentExecutor.log, psexec.exe, Devices › All devices, Devices › Windows.1Prerequisites2How it works3Step-by-step4Verify theresults5Tips andgotchas1Write and test the scripts2Create the scriptpackage3Assign and schedule4Run it on demandTOOLBOXHealthScripts.logAgentExecutor.logpsexec.exeDevices › All devicesDevices › WindowsHow this guide is organised: Prerequisites → How it works → Step-by-step → Verify the results → Tips and gotchasFlow diagram of the article's sections in reading order: 1. Prerequisites. 2. How it works. 3. Step-by-step (4 steps: Write and test the scripts; Create the script package; Assign and schedule; Run it on demand). 4. Verify the results. 5. Tips and gotchas. Toolbox: HealthScripts.log, AgentExecutor.log, psexec.exe, Devices › All devices, Devices › Windows.1Prerequisites2How it works3Step-by-step1Write and test the scripts2Create the script package3Assign and schedule4Run it on demand4Verify the results5Tips and gotchasTOOLBOXHealthScripts.logAgentExecutor.logpsexec.exeDevices › All devicesDevices › Windows
At a glance: how this guide is organised · 4 steps · 5 key settings and tools

Prerequisites#

  • Licensing. Users of the devices need Windows Enterprise E3 or E5 (included in Microsoft 365 F3, E3 and E5), Windows Education A3 or A5 (included in Microsoft 365 A3 and A5), or Windows Virtual Desktop Access per user. Microsoft 365 Business Premium on its own isn't on that list.
  • Tenant attestation. Before first use, an Intune Service Administrator has to confirm the licensing. Go to Tenant administration › Connectors and tokens › Windows data and turn on I confirm that my tenant owns one of these licenses, which is off by default.
  • Devices. Microsoft Entra joined or Microsoft Entra hybrid joined, and either enrolled in Intune running Windows Enterprise, Pro or Education, or co-managed. The Intune Management Extension (IME) installs automatically once a remediation is assigned.
  • Permissions. Managing script packages uses permissions in the Device configurations category; on-demand runs need Remote tasks › Run remediation.

How it works#

A script package holds a detection script and, optionally, a remediation script, with up to 200 packages per tenant. The IME runs them, and the detection script's exit code drives everything:

Detection scriptMeaningWhat happens next
exit 0No issue foundNothing; the result is reported
exit 1Issue foundThe remediation script runs, then detection runs again to confirm the fix
Any other exit codeNot treated as "issue found"The remediation script doesn't run

Three settings shape how the scripts run:

  • Run this script using the logged-on credentials: No runs as SYSTEM; Yes runs as the signed-in user.
  • Run script in 64-bit PowerShell: the default, No, uses a 32-bit host, where HKLM:\SOFTWARE is redirected to WOW6432Node and $env:ProgramFiles points at Program Files (x86).
  • Enforce script signature check: when on, the device's execution policy applies and scripts must be UTF-8 without a byte order mark; when off, scripts run with the Bypass policy.

Whatever your scripts write to STDOUT, up to 2,048 characters, appears in the reports. The IME fetches remediation policy every 8 hours, after the device or the IME service restarts, and when a user signs in.

Step-by-step#

1. Write and test the scripts#

This example turns off Windows Fast Startup, a common helpdesk annoyance because "Shut down" then isn't a full restart. The detection script:

PowerShell
# Detect_FastStartup.ps1 - exit 1 means Fast Startup is on
$path = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power'
$value = (Get-ItemProperty -Path $path -Name HiberbootEnabled -ErrorAction SilentlyContinue).HiberbootEnabled
if ($value -eq 0) {
    Write-Output 'OK: Fast Startup is disabled'
    exit 0
}
Write-Output "Issue: HiberbootEnabled is '$value'"
exit 1

The remediation script:

PowerShell
# Remediate_FastStartup.ps1
$path = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power'
try {
    Set-ItemProperty -Path $path -Name HiberbootEnabled -Value 0 -Type DWord -ErrorAction Stop
    Write-Output 'Fixed: HiberbootEnabled set to 0'
    exit 0
}
catch {
    Write-Output "Failed: $($_.Exception.Message)"
    exit 1
}

Test both on a test device as SYSTEM, for example from a PowerShell window opened with Sysinternals psexec.exe -s -i, and check $LASTEXITCODE after each run. Save the files as UTF-8.

2. Create the script package#

  1. Go to Devices › Manage devices › Scripts and remediations, stay on the Remediations tab and select Create script package.
  2. On Basics, give it a clear name and describe what it fixes.
  3. On Settings, upload both .ps1 files rather than editing them in the browser, which helps keep the encoding correct. For this example, set logged-on credentials, signature check and 64-bit PowerShell all to No. A 32-bit host is fine here because HKLM\SYSTEM isn't redirected; choose Yes for 64-bit PowerShell when a script touches HKLM\SOFTWARE or 64-bit paths.
  4. Add scope tags if you use them, then continue to assignments.

3. Assign and schedule#

Assign the package to device groups (filters work too), and don't mix user and device groups across include and exclude. Each assignment gets a schedule:

  • Once: a single run at a set date and time, ideal for one-off cleanups.
  • Hourly: every n hours, with an interval below 24.
  • Daily: once a day at a set time, which suits this example.

Schedules follow the device's local time unless you select Use UTC, and a missed run happens as soon as the device is back online.

4. Run it on demand#

To fix one device right now, open it from Devices › All devices, select Run remediation, pick the script package and run it. The package must exist but doesn't need to be assigned. The device has to be online and reachable through Intune and Windows Push Notification Services (WNS), with the IME installed. Send one Run remediation action at a time per device, because several in quick succession can overwrite each other.

Verify the results#

  • In Devices › Manage devices › Scripts and remediations, select the package for the detection and remediation overview, then Device status for per-device results. Add the pre- and post-remediation detection output columns to see what your scripts wrote, and use Export for a CSV.
  • For a single device, open it under Devices › Windows and select Remediations in the Monitor section.
  • Good looks like this: the first run finds the issue and fixes it, the post-remediation detection agrees, and later runs find nothing to fix.
  • Expect some lag on recurring schedules. Devices report only changes during the first six days of each cycle and send a full report every seven days. On the device, HealthScripts.log and AgentExecutor.log in the IME Logs folder record the runs.

Tips and gotchas#

  • Keep reboot commands, passwords and personal data out of your scripts.
  • Make detection output stable; values that change on every run, such as timestamps, make the results noisy.
  • If a setting exists in the settings catalog, manage it with a configuration policy. Remediations are best for drift, cleanup and the gaps policies can't cover.
  • Scripts that run with the logged-on credentials need someone signed in.
  • Start with a detection-only package to measure how widespread a problem is before you fix it.
  • Assign only what each device needs, and give heavy scripts a less frequent schedule; every run costs CPU and battery.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)