Modern WorkplaceHelp

Intune, Azure, Cloud Computing and more…


When Intune App Assignments Do Not Change

Troubleshooting and lessons learnt

A guide to understanding assignment reconciliation, choosing user or device groups, and diagnosing the gap between a publishing tool configuration and the actual state of an Intune Win32 app.

A common Intune deployment problem is changing an assignment in a management tool, running a sync, and then finding that Intune still shows the old deployment. This can look like an Intune problem, but often the issue is earlier in the chain: the management tool did not save, reconcile, or publish the new assignment to the existing Intune app.

In this case, App XYZ t was already published in Intune and still had two Available for enrolled devices assignments. The intended change was to remove those Available assignments and deploy the app as Uninstall to a device group. The app remained installed because Intune never received the requested assignment change.

The logs showed that Patch My PC found App XYZ and processed it as already published, but there was no App XYZspecific assignment add, delete, or update operation. Intune therefore retained the existing assignments, which is expected: Intune does not infer that an Available assignment should become an Uninstall assignment.

Understand the Two States

  1. Configured state in the publishing tool: what you select in Patch My PC or another management console.
  2. Actual state in Intune: the assignments currently attached to the existing Intune Win32 app.

Changing the first state does not help unless the tool successfully pushes and reconciles that change with the second state.

App XYZ... is already published as an application.

That message confirms the app already exists in Intune. It does not prove that assignment changes were applied.

User Groups vs Device Groups

For Intune Win32 apps, assignments can generally target either user groups or device groups. The right choice depends on the intended outcome.

Assignment typeRecommended targetWhy
RequiredDevice group for device-wide software; user group for user-specific softwareUse devices when every targeted endpoint should install the app, independent of sign-in.
AvailableUser group in most self-service scenariosThe app appears in Company Portal for those users.
Available for enrolled devicesDevice groupAllows the app to appear on managed devices targeted by the group.
UninstallDevice group in most casesRemoval follows the device and remains reliable on shared or multi-user endpoints.
UninstallUser group only when removal must follow a particular userLess predictable on shared devices or where several users sign in.

Important: using a device group for Available for enrolled devices is valid. It is not inherently wrong. For normal self-service in Company Portal, however, a user-group Available assignment is usually clearer and easier to reason about.

Recommended Approach

  • Use Required + device groups for baseline or device-wide applications.
  • Use Available + user groups for optional software users can install from Company Portal.
  • Use Available for enrolled devices + device groups only when availability should be based on device membership.
  • Use Uninstall + device groups for software removal campaigns.
  • Avoid assigning the same app as both Available and Uninstall to the same device or overlapping target populations.

Uninstall Campaign Checklist

  1. Remove the old Available assignment from the relevant target group.
  2. Add the target device group under Uninstall.
  3. Save the publishing-tool configuration.
  4. Run a targeted publish or sync operation.
  5. Check both the Intune portal and publisher logs for an assignment update.
  6. Force a device sync or wait for the normal Intune Management Extension check-in.
  7. Review IntuneManagementExtension.log on a test device if the uninstall still does not start.

What to Check in Logs

A successful assignment reconciliation should show evidence of the relevant app being updated, such as:

Updating Intune application metadata
assignments to add
assignments to delete
Assignment added
Assignment deleted

If the logs only say the app is already published, and Intune still shows the old assignments, do not troubleshoot the device yet. The deployment state in Intune has not changed, so there is no uninstall policy for the device to process.

Key lesson: installation status does not prevent assignment changes. If the old assignment remains visible in Intune, the problem is assignment reconciliation or publishing, not the endpoint.



Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.