Unknown compliance generally ties to scan agent status. Are the devices in question receiving the update deployment assignments and installing updates or is that not working either?
Configuration Manager | Compliance state unknown
Hello Team,
there are devices under compliance state unknown for specific collection and for a software update deployment.
Checked that there are no scan errors in the scan report.
Please let me know is there any report or query available based on the specific software update group and collection to check the status message in database.
Need to know whether devices return below state message or not.
Alos guide me how to troubleshoot from SCCM infrastructure end to check the issue.
Microsoft Security | Intune | Configuration Manager | Updates
2 answers
Sort by: Most helpful
-
-
Kalyan Sundar 571 Reputation points
2025-08-08T19:39:11.41+00:00 Please verify the scan status of Scan 3 - Last Scan Status by Collection under Scan Deport, and determine whether all unknown devices have completed their scan and are reported as "Scan Completed"
- Scan Status Verification:
- Review the status of Scan 3 - Last Scan Status by Collection in the console.
- Check if all devices categorized as "Unknown" have transitioned to a completed scan state.
- Log Validation on Sample Clients:
- Select a few client devices from the affected group.
- Review the following logs for errors or scan-related issues:
- ScanAgent.log
- WUAHandler.log
- Confirm whether the scan has been successfully completed or if any errors persist.
- Force Update Compliance State (if scan is complete):
- If the scan has been completed without errors, execute the following PowerShell commands on the client to manually trigger a compliance state update to the database:
- Scan Status Verification: