- If your AVD VMs were previously domain-joined or synced via Entra Connect, legacy on-prem GPOs can still apply and override Intune/PEM settings.
- Even after enabling MDM Wins Over GP, this only works for CSP-backed settings, not all PEM actions.
- PEM policies require correct Entra ID group targeting and device management type validation.
- If the device is tagged incorrectly or not in the right group, the policy won’t deploy
- PEM “allow” actions (e.g., run CMD as admin) are supported on personal host pools, but require:
For further troubleshooting refer to : https://v4.hkg1.meaqua.org/en-us/windows/client-management/mdm-diagnose-enrollment