Remediations pair a detection script with a fix script, run them on a schedule across your Windows devices, and report per-device results in the Microsoft Intune admin center. In this how-to I'll cover the prerequisites that catch people out, the script contract, a small and safe example you can adapt, and how to read the results.
Prerequisites#
- Licensing. Users of the devices need Windows Enterprise E3 or E5 (included in Microsoft 365 F3, E3 and E5), Windows Education A3 or A5 (included in Microsoft 365 A3 and A5), or Windows Virtual Desktop Access per user. Microsoft 365 Business Premium on its own isn't on that list.
- Tenant attestation. Before first use, an Intune Service Administrator has to confirm the licensing. Go to Tenant administration › Connectors and tokens › Windows data and turn on I confirm that my tenant owns one of these licenses, which is off by default.
- Devices. Microsoft Entra joined or Microsoft Entra hybrid joined, and either enrolled in Intune running Windows Enterprise, Pro or Education, or co-managed. The Intune Management Extension (IME) installs automatically once a remediation is assigned.
- Permissions. Managing script packages uses permissions in the Device configurations category; on-demand runs need Remote tasks › Run remediation.
How it works#
A script package holds a detection script and, optionally, a remediation script, with up to 200 packages per tenant. The IME runs them, and the detection script's exit code drives everything:
| Detection script | Meaning | What happens next |
|---|---|---|
exit 0 | No issue found | Nothing; the result is reported |
exit 1 | Issue found | The remediation script runs, then detection runs again to confirm the fix |
| Any other exit code | Not treated as "issue found" | The remediation script doesn't run |
Three settings shape how the scripts run:
- Run this script using the logged-on credentials: No runs as SYSTEM; Yes runs as the signed-in user.
- Run script in 64-bit PowerShell: the default, No, uses a 32-bit host, where
HKLM:\SOFTWAREis redirected toWOW6432Nodeand$env:ProgramFilespoints atProgram Files (x86). - Enforce script signature check: when on, the device's execution policy applies and scripts must be UTF-8 without a byte order mark; when off, scripts run with the Bypass policy.
Whatever your scripts write to STDOUT, up to 2,048 characters, appears in the reports. The IME fetches remediation policy every 8 hours, after the device or the IME service restarts, and when a user signs in.
Step-by-step#
1. Write and test the scripts#
This example turns off Windows Fast Startup, a common helpdesk annoyance because "Shut down" then isn't a full restart. The detection script:
# Detect_FastStartup.ps1 - exit 1 means Fast Startup is on
$path = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power'
$value = (Get-ItemProperty -Path $path -Name HiberbootEnabled -ErrorAction SilentlyContinue).HiberbootEnabled
if ($value -eq 0) {
Write-Output 'OK: Fast Startup is disabled'
exit 0
}
Write-Output "Issue: HiberbootEnabled is '$value'"
exit 1The remediation script:
# Remediate_FastStartup.ps1
$path = 'HKLM:\SYSTEM\CurrentControlSet\Control\Session Manager\Power'
try {
Set-ItemProperty -Path $path -Name HiberbootEnabled -Value 0 -Type DWord -ErrorAction Stop
Write-Output 'Fixed: HiberbootEnabled set to 0'
exit 0
}
catch {
Write-Output "Failed: $($_.Exception.Message)"
exit 1
}Test both on a test device as SYSTEM, for example from a PowerShell window opened with Sysinternals psexec.exe -s -i, and check $LASTEXITCODE after each run. Save the files as UTF-8.
2. Create the script package#
- Go to Devices › Manage devices › Scripts and remediations, stay on the Remediations tab and select Create script package.
- On Basics, give it a clear name and describe what it fixes.
- On Settings, upload both
.ps1files rather than editing them in the browser, which helps keep the encoding correct. For this example, set logged-on credentials, signature check and 64-bit PowerShell all to No. A 32-bit host is fine here becauseHKLM\SYSTEMisn't redirected; choose Yes for 64-bit PowerShell when a script touchesHKLM\SOFTWAREor 64-bit paths. - Add scope tags if you use them, then continue to assignments.
3. Assign and schedule#
Assign the package to device groups (filters work too), and don't mix user and device groups across include and exclude. Each assignment gets a schedule:
- Once: a single run at a set date and time, ideal for one-off cleanups.
- Hourly: every n hours, with an interval below 24.
- Daily: once a day at a set time, which suits this example.
Schedules follow the device's local time unless you select Use UTC, and a missed run happens as soon as the device is back online.
4. Run it on demand#
To fix one device right now, open it from Devices › All devices, select Run remediation, pick the script package and run it. The package must exist but doesn't need to be assigned. The device has to be online and reachable through Intune and Windows Push Notification Services (WNS), with the IME installed. Send one Run remediation action at a time per device, because several in quick succession can overwrite each other.
Verify the results#
- In Devices › Manage devices › Scripts and remediations, select the package for the detection and remediation overview, then Device status for per-device results. Add the pre- and post-remediation detection output columns to see what your scripts wrote, and use Export for a CSV.
- For a single device, open it under Devices › Windows and select Remediations in the Monitor section.
- Good looks like this: the first run finds the issue and fixes it, the post-remediation detection agrees, and later runs find nothing to fix.
- Expect some lag on recurring schedules. Devices report only changes during the first six days of each cycle and send a full report every seven days. On the device,
HealthScripts.logandAgentExecutor.login the IME Logs folder record the runs.
Tips and gotchas#
- Keep reboot commands, passwords and personal data out of your scripts.
- Make detection output stable; values that change on every run, such as timestamps, make the results noisy.
- If a setting exists in the settings catalog, manage it with a configuration policy. Remediations are best for drift, cleanup and the gaps policies can't cover.
- Scripts that run with the logged-on credentials need someone signed in.
- Start with a detection-only package to measure how widespread a problem is before you fix it.
- Assign only what each device needs, and give heavy scripts a less frequent schedule; every run costs CPU and battery.