Passbeam

I changed something and nothing happened.

Check which side of the exchange caches. Passbeam applies most changes on the very next authentication — a group removed from a permitted list, a suspension, a VLAN rule — so if the device has not tried to join since, nothing has had the chance to change.

Intune is the slower half. A device sync does not pull platform scripts; the Intune Management Extension checks in on its own cycle. Restarting that service on the machine forces it, which is the difference between testing something in a minute and waiting an hour.

And Apple devices cache the enrolment URL from the profile they were given. If an enrolment address has changed, the profile has to be re-pushed — the device will otherwise keep using the old one indefinitely.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.