Password complexity Error 2016281112 (Remediation failed) -2016281112

Darren Heath 0 Reputation points
2024-09-18T12:16:52.2366667+00:00

We are using Endpoint Manager to enroll and install Windows O/S and company polices. All Windows devices are getting Non-Compliant status. I get the following two errors in Event Viewer:

MDM PolicyManager: Set policy int, Policy: (MinDevicePasswordComplexCharacters), Area: (DeviceLock), EnrollmentID requesting set: (0DA44E47-6CFF-4BD0-A8BA-5FB790475719), Current User: (Device), Int: (0x4), Enrollment Type: (0x6), Scope: (0x0), Result:(0x86000011) Unknown Win32 Error code: 0x86000011.

MDM ConfigurationManager: Command failure status. Configuraton Source ID: (0DA44E47-6CFF-4BD0-A8BA-5FB790475719), Enrollment Type: (MDMDeviceWithAAD), CSP Name: (Policy), Command Type: (SetValue: from Replace), CSP URI: (./Vendor/MSFT/Policy/Config/DeviceLock/MinDevicePasswordComplexCharacters), Result: (Unknown Win32 Error code: 0x86000011).

Password policy is set to use Device Default password complexity. User's image

We do have a script that adds a local admin account that sets the password never to expire. Built in admin account is disabled. Plan on moving to LAPS in the near future.

Is the error being caused by having the additional local admin account, because we have password policy set to Device Default and not Alphanumeric, or something else?

Any insight would be greatly appreciated.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,885 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,992 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 48,081 Reputation points Microsoft Vendor
    2024-09-19T02:18:16.08+00:00

    @Darren Heath, Thanks for posting in Q&A. For the error message, i know it is affected to MinDevicePasswordComplexCharacters

    https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#mindevicepasswordcomplexcharacters

    For the Password Type: Device default (default), it means require a password, numeric PIN, or alphanumeric PIN. Please change the local user account password to meet the requirement to see if the issue can be fixed.

    https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-protection/error-deploying-password-policy

    Meanwhile, based on my researching, I find the password policy applies to current local account and all administrator accounts.

    https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/dn282287(v=ws.11)#password-length-and-complexity-supported-by-account-types

    I notice the Built in admin account is disabled. Please enable the built-in admin on one device and change its password to meet the requirement to see if it is the issue.

    Please try the above suggestion and if there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.