Hello resecurity,
Before making any manual modifications (not recommended), here are a few things to verify:
- Check device exclusion logic • If you’ve excluded the device using a group (i.e., added the device to a group and set that group under Exclusions in policy assignments), consider using filters instead. • When using dynamic groups, membership updates can take time to propagate. This delay may cause temporary policy conflicts, especially when multiple USB control policies are involved.
- Verify configuration in the Intune portal • Go to Devices → macOS → [Select the device] → Device configuration. • Ideally, only the allow policy should appear here. • If you see both allow and block policies, the device is experiencing a policy conflict, and Intune will apply the most restrictive action — in this case, block.
Double-check the assigned groups, exclusions, and filters to ensure they’re configured correctly and that the device is properly targeted or excluded as intended.
Hope this helps!
If you found the information above helpful, please Click Yes. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.