Intune Remediations: find and fix problems before users notice
Remediations pair a detection script with a fix script and run them on a schedule. It's one of the most useful and underused features in Intune.
On this page
Remediations (once called Proactive Remediations) run a pair of PowerShell scripts on Windows devices on a schedule. The detection script checks for a problem. If it finds one, the remediation script fixes it. Intune reports on both, so you can see how many devices had the problem and how many were fixed.
- 01Detection script runs
- 02Exit 1: problem found
- 03Remediation script fixes it
- 04Results reported in Intune
How the scripts talk to Intune
- Exit 0 from detection means "all good". Nothing else runs.
- Exit 1 from detection means "problem found". The remediation script runs.
- Whatever the script writes to output appears in the Intune report, so write something useful.
Example: clear a full temp folder
Detection:
$sizeGB = (Get-ChildItem "$env:SystemRoot\Temp" -Recurse -Force -ErrorAction SilentlyContinue |
Measure-Object Length -Sum).Sum / 1GB
if ($sizeGB -gt 5) { Write-Output "Temp is $([math]::Round($sizeGB,1)) GB"; exit 1 }
Write-Output "Temp OK"; exit 0Remediation:
Get-ChildItem "$env:SystemRoot\Temp" -Recurse -Force -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -lt (Get-Date).AddDays(-7) } |
Remove-Item -Recurse -Force -ErrorAction SilentlyContinue
Write-Output "Cleaned temp folder"; exit 0Good uses
- Restarting a service that keeps stopping
- Fixing a registry value that users or apps keep changing
- Detection-only reports, such as finding devices with a specific app version or a certificate about to expire
Things to know
- Licensing: Remediations needs Windows Enterprise E3/E5 or equivalent (included in Microsoft 365 E3/E5).
- Context: scripts run as SYSTEM by default. Choose "run as logged-on user" for user-level fixes.
- Use Run remediation on a single device for on-demand fixes from the device page.
Writing scripts that behave
- Make detection read-only: it should only check, never change anything
- Make remediation safe to run twice (idempotent)
- Write one clear line of output: it appears in the Intune report columns
- Keep scripts short and fast: they run on every device in scope
- Sign scripts if your devices enforce signed PowerShell, or allow unsigned in the remediation settings
Reading the results
In Intune, open Devices → Scripts and remediations → Remediations and select the package. The overview shows how many devices had the issue, how many were fixed and how many failed. The device status view adds the detection and remediation output for each device, so useful output lines pay off here.
Troubleshooting
- Logs are on the device under
C:\ProgramData\Microsoft\IntuneManagementExtension\Logs, mainlyAgentExecutor.logandIntuneManagementExtension.log. - A script that works in your console but fails in Intune is usually running as SYSTEM, where user paths and mapped drives don't exist.
- 64-bit versus 32-bit PowerShell changes which registry view you see. Choose 64-bit in the package settings if you read
HKLM\SOFTWARE.