Windows MDM event

DMEDP Event 404

MDM ConfigurationManager command failed

Event ID
404
Log
DeviceManagement-Enterprise-Diagnostics-Provider/Admin

What it means

Windows recorded a failed ConfigurationManager command. The provider name, command type, CSP URI, and result in the event identify what actually failed.

Authoritative context: Microsoft Windows MDM documentation

Resolution playbook

From symptom to verified fix

Start with evidence, change one variable at a time, and confirm the result before closing the incident.

1

Likely causes

  • Windows recorded a failed ConfigurationManager command. The provider name, command type, CSP URI, and result in the event identify what actually failed.
  • The decisive details are usually in the event payload and adjacent DMEDP events, not the event ID by itself.
  • Assignment, enrollment, scope, CSP applicability, and service response must be correlated at the same UTC timestamp.
2

Recommended fix

  1. Copy the full provider name, command type, CSP URI, and result.
  2. Correlate with adjacent DMEDP events and the MDM diagnostic report.
  3. If Admin data is insufficient, reproduce with the DMEDP Debug log enabled.
3

Verify

  1. Trigger a manual sync or repeat the original enrollment/policy operation.
  2. Confirm a new event shows success or a different actionable result.
  3. Verify the device state in Intune or the target MDM service after the client reports success.
4

Escalate when

  • The same event repeats after the configuration and prerequisites are corrected.
  • The server reports success but the Windows event stream shows a persistent failure, or vice versa.
  • You have exported the event payload, adjacent events, MDM diagnostic report, device build, and UTC timeline.
Read recent Event 404 records
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin'; Id=404} -MaxEvents 10 | Format-List TimeCreated,Id,LevelDisplayName,Message

Read-only. Run in PowerShell on the affected device.

← Search another event or code