Windows MDM event

DMEDP Event 814

MDM string policy value recorded

Event ID
814
Log
DeviceManagement-Enterprise-Diagnostics-Provider/Admin

What it means

Windows recorded an MDM PolicyManager operation for a string setting. Interpret the string value, policy area, scope, and result together rather than using the event ID alone.

Authoritative context: Microsoft Windows MDM documentation

Resolution playbook

From symptom to verified fix

Start with evidence, change one variable at a time, and confirm the result before closing the incident.

1

Likely causes

  • Windows recorded an MDM PolicyManager operation for a string setting. Interpret the string value, policy area, scope, and result together rather than using the event ID alone.
  • The decisive details are usually in the event payload and adjacent DMEDP events, not the event ID by itself.
  • Assignment, enrollment, scope, CSP applicability, and service response must be correlated at the same UTC timestamp.
2

Recommended fix

  1. Read the policy name, area, string value, scope, and result in Event Details.
  2. Review nearby 813/814 events for settings from the same profile.
  3. Consult the CSP reference for supported operations and value formats.
3

Verify

  1. Trigger a manual sync or repeat the original enrollment/policy operation.
  2. Confirm a new event shows success or a different actionable result.
  3. Verify the device state in Intune or the target MDM service after the client reports success.
4

Escalate when

  • The same event repeats after the configuration and prerequisites are corrected.
  • The server reports success but the Windows event stream shows a persistent failure, or vice versa.
  • You have exported the event payload, adjacent events, MDM diagnostic report, device build, and UTC timeline.
Read recent Event 814 records
Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin'; Id=814} -MaxEvents 10 | Format-List TimeCreated,Id,LevelDisplayName,Message

Read-only. Run in PowerShell on the affected device.

← Search another event or code