azureblog.co.uk
← cd ~/posts

Intune Remediations: find and fix problems before users notice

Remediations pair a detection script with a fix script and run them on a schedule. It's one of the most useful and underused features in Intune.

2 min read✓ checked 15 Apr 2026Intune · Windows · PowerShell
On this page
  1. How the scripts talk to Intune
  2. Example: clear a full temp folder
  3. Good uses
  4. Things to know
  5. Writing scripts that behave
  6. Reading the results
  7. Troubleshooting

(once called Proactive Remediations) run a pair of PowerShell scripts on Windows devices on a schedule. The detection script checks for a problem. If it finds one, the remediation script fixes it. Intune reports on both, so you can see how many devices had the problem and how many were fixed.

  1. 01Detection script runs
  2. 02Exit 1: problem found
  3. 03Remediation script fixes it
  4. 04Results reported in Intune

How the scripts talk to Intune

  • Exit 0 from detection means "all good". Nothing else runs.
  • Exit 1 from detection means "problem found". The remediation script runs.
  • Whatever the script writes to output appears in the Intune report, so write something useful.
Detection script exit code?
Exit 0No issue detected. Remediation doesn't run.
Exit 1Issue detected. Remediation script runs, then detection runs again to confirm.
Error or timeoutReported as failed in Intune. Check the output.
What happens on each run.

Example: clear a full temp folder

Detection:

powershell
$sizeGB = (Get-ChildItem "$env:SystemRoot\Temp" -Recurse -Force -ErrorAction SilentlyContinue |
  Measure-Object Length -Sum).Sum / 1GB
if ($sizeGB -gt 5) { Write-Output "Temp is $([math]::Round($sizeGB,1)) GB"; exit 1 }
Write-Output "Temp OK"; exit 0

Remediation:

powershell
Get-ChildItem "$env:SystemRoot\Temp" -Recurse -Force -ErrorAction SilentlyContinue |
  Where-Object { $_.LastWriteTime -lt (Get-Date).AddDays(-7) } |
  Remove-Item -Recurse -Force -ErrorAction SilentlyContinue
Write-Output "Cleaned temp folder"; exit 0

Good uses

  • Restarting a service that keeps stopping
  • Fixing a registry value that users or apps keep changing
  • Detection-only reports, such as finding devices with a specific app version or a certificate about to expire

Things to know

  • Licensing: Remediations needs Windows Enterprise E3/E5 or equivalent (included in Microsoft 365 E3/E5).
  • Context: scripts run as SYSTEM by default. Choose "run as logged-on user" for user-level fixes.
  • Use Run remediation on a single device for on-demand fixes from the device page.

Writing scripts that behave

  • Make detection read-only: it should only check, never change anything
  • Make remediation safe to run twice (idempotent)
  • Write one clear line of output: it appears in the Intune report columns
  • Keep scripts short and fast: they run on every device in scope
  • Sign scripts if your devices enforce signed PowerShell, or allow unsigned in the remediation settings

Reading the results

In Intune, open Devices → Scripts and remediations → Remediations and select the package. The overview shows how many devices had the issue, how many were fixed and how many failed. The device status view adds the detection and remediation output for each device, so useful output lines pay off here.

Troubleshooting

  • Logs are on the device under C:\ProgramData\Microsoft\IntuneManagementExtension\Logs, mainly AgentExecutor.log and IntuneManagementExtension.log.
  • A script that works in your console but fails in Intune is usually running as SYSTEM, where user paths and mapped drives don't exist.
  • 64-bit versus 32-bit PowerShell changes which registry view you see. Choose 64-bit in the package settings if you read HKLM\SOFTWARE.
Next in Intune for Windows, start to finish · part 3 of 6Windows LAPS with Intune: unique local admin passwords in minutes →