Tag Archives: Nerdio Manager for Enterprise

EUC with Nerdio Manager and Intune – Part 2: The Configuration Issues Dashboard

EUC with Nerdio Manager and Intune: Part 1 – Powerful Device Filters | Part 2 – The Configuration Issues Dashboard (you are here)

In Part 1 of this series, we looked at how Nerdio Manager takes Intune’s device data and makes it genuinely usable through fast, practical filtering. In this second post, we move from finding devices to fixing them. Intune policy conflicts anyone? Sure enough, we land on one of my favorite capabilities in the entire product.

That capability is the Configuration Issues dashboard.

Here is the short version: Nerdio Manager tells you which of your devices are suffering from Intune policy conflicts, then walks you back to the exact policies, settings, values, and assignments causing the trouble. As far as I can tell, there is no single equivalent view anywhere in the native Intune admin center. Not one.

Intune Policy Conflicts Are One of the Quietest Problem in Endpoint Management

Policy conflicts rarely announce themselves. Nobody gets an alert that says, “two of your configuration profiles are fighting over the camera.” What you get instead is much more annoying; a setting that simply doesn’t apply; a compliance state that looks wrong; a Cloud PC that behaves differently than its identical twin; and a help desk ticket that reads “my camera stopped working and I didn’t change anything.”

The cause is usually structural rather than careless. Over time, an Intune tenant accumulates layers, including:

  • Configuration profiles built for one project and never retired
  • Security baselines applied broadly, then partially overridden by a targeted profile
  • Settings Catalog profiles that overlap with older templates covering the same setting
  • Group assignments that were clean at design time and messy after a year of reorgs
  • Inherited configuration from a merger, an acquisition, or simply a previous administrator

Each layer is reasonable on its own. Stacked, they collide. And when two profiles assigned to the same device set the same setting to different values, Intune does the only thing it can do, it flags a conflict and applies neither value.

NOTE: A conflict is not a failure. Nothing crashed and nothing is broken in the classic sense. That is precisely why conflicts survive so long in production; they stay invisible until someone goes looking for them.

What Native Intune Gives You, and Where It Runs Out

To be fair to Microsoft, Intune does surface conflicts. You can open a configuration profile, check Device status or Per setting status, and see a Conflict count. You can open a single device, look at its device configuration, and see a profile sitting in a Conflict state. Drill far enough and Intune will even show you which setting is in dispute.

The trouble is not that the information is missing. The trouble is that the information is scattered.

Every path in native Intune starts from something you already suspect. You have to pick a profile, or pick a device, and then go digging. There is no view that opens with the answer to the question every endpoint team actually asks first:

Across my whole estate, which devices have configuration problems right now?

Without that view, conflict hunting becomes a manual audit. And manual audits in a tenant with thousands of endpoints and dozens of profiles are the kind of task that gets scheduled, postponed, and then quietly abandoned.

The Config. Issues Dashboard – Intune Policy Conflicts Be Gone

Now let’s flip it around.

In Nerdio Manager, navigate to Endpoints > Intune > Configuration Issues. What loads is the list of devices in your environment that currently have policy configuration issues, presented under a Configuration Policy Conflicts tab with an Alerts count right at the top of the page.

Nerdio Manager for Enterprise Configuration Issues dashboard under Endpoints > Intune, showing a Windows 365 Cloud PC with four conflicting policies
Endpoints > Intune > Configuration Issues opens with the answer – every device currently affected, its device type, and how many policies are in play.

Notice what each device card gives you before you have clicked a single thing:

  • The device name — in our lab, a Cloud PC named CPC-Monic-QWTS7
  • The Device type — Windows 365 Cloud PCs, which matters when you support a mixed estate of physical endpoints, session hosts, and Cloud PCs
  • The Policies count — four policies in play on this device
  • Two actions: Show policies and Details

No profile to guess at first. No device to guess at first. The dashboard leads with the affected devices, which is exactly where a troubleshooting session naturally begins. That single design decision changes the character of the work. Instead of asking “is this profile causing a problem somewhere?” you get to ask “which of my devices need attention today?” One question is a search. The other is a work queue.

Trace the Conflict Back to Its Source

Finding the affected devices is only half the job. Nerdio Manager takes you the rest of the way.

The workflow is short, and it follows the same sequence every time:

  1. Open Endpoints > Intune > Configuration Issues and review the devices listed under Configuration Policy Conflicts.
  2. Select Show policies to see the policies involved on that device.
  3. Select Details to open the full conflict map for the device.
  4. Review the policy details in Table or Flowchart format, depending on whether you want precision or perspective.

That fourth step is where this feature earns its keep.

Nerdio Manager conflict map for a Cloud PC showing two policies setting Allow Camera to different values, with settings, values, assignments, and context
Policy, Setting, Value, Assignments, Context – read left to right. Support-Team allows the camera, Camera Config blocks it, and both land on the same user.

Reading the Details

Look at what the flowchart lays out for CPC-Monic-QWTS7. Every row reads left to right as a complete chain: Policy → Setting → Value → Assignments → Context. And the very first two rows tell the whole story.

  • The Support-Team policy sets Allow Camera to a value of 1, assigned to the Support Team user scope.
  • The Camera Config policy sets that same Allow Camera setting to a value of 0, assigned to All devices and All users.
  • Both chains converge on the same Context — the user signed in to that Cloud PC.

That is the conflict, drawn as a picture. One policy turns the camera on for the support team. Another turns it off for everybody. They meet on one device, and the camera setting ends up in limbo. The remaining rows in the view do the same for the update policies — Standard Update Settings driving Automatic Update Mode, and Windows Update for Business Starter Policy driving Allow Auto Update — so you can see the full configuration picture for the device, not just the single setting you happened to be chasing.

Think of it the way a network engineer thinks about a topology diagram. You can absolutely read a routing table and work out the path. But the diagram is what makes the loop obvious.

The real payoff is the Assignments column. Knowing that two policies disagree is useful. Knowing that one of them landed on this device because of a broad All devices, All users assignment tells you how to fix it — and that is the difference between identifying a problem and closing a ticket.

Native Intune and Nerdio Manager, Side by Side

What you need Native Intune Nerdio Manager
Starting point for conflict investigation A specific profile, or a specific device A list of all affected devices
Estate-wide view of configuration issues Not available as a single view The Configuration Issues dashboard
Path from device to offending policy Manual drill-down across blades Show policies, then Details
Conflicting settings and values together Assembled by hand Shown side by side in one view
Assignment that caused the conflict A separate investigation The Assignments column
Visual map of policy relationships Not available Flowchart view
Time to first useful answer Minutes to hours, depending on tenant size Seconds

The last row is the one that matters most to a busy team. The value here is not that Nerdio Manager knows something Intune doesn’t — the data is Intune’s data. The value is that Nerdio Manager asks the right question first and hands you the answer already assembled.

Making It Part of the Routine

A dashboard only pays off if someone looks at it. A few ways teams put this one to work:

  • Add it to the weekly operational review. A short standing look at Configuration Issues catches drift before it becomes a ticket trend.
  • Check it before you blame the image. When a device misbehaves after provisioning, a policy conflict is a far more common culprit than a bad image, and it takes far less time to rule out.
  • Use it during profile cleanup. If you are consolidating years of accumulated profiles, this dashboard is how you confirm the cleanup actually helped.
  • Use it after any broad assignment change. New baseline, new group, new project profile — check the dashboard the next day and see what you disturbed.

None of that requires a new process. It requires a bookmark and about five minutes.

What’s Next in the Nerdio Manager + Intune Series

We are two posts in and we have only scratched the surface of what Nerdio Manager brings to Intune-based EUC management. In upcoming articles, we will keep working through the features that save real time for real teams — policy reports, performance reports, policy backup and version comparison, and more.

Thank you for reading Part 2. Conflicting policies have been costing endpoint teams quiet hours for years, and honestly, it is a wonderful thing to finally have a place to go and simply see them. Bring your coffee, open the dashboard, and enjoy the very satisfying work of fixing something before anyone has to report it.

Nerdio help article: Configuration Issues Dashboard
Nerdio on-demand webinar: Simplify Intune policy conflicts before they impact you: