Hello,
Since implementing the Jamf/Intune Integration that machines will randomly fall out of compliance. Users lose access to their Office 365 suite and they are unable to log into Cisco AnyConnect. The usually get prompted to re-enroll their device in Jamf. For Office 365 apps, they get a "You can't get there from here" notification.
When I check the device status in Intune/Azure AD they are properly enrolled and compliant.
The only way that I can usually fix this is with the solution that Microsoft provided. I first need to remove the device from Intune/Azure AD. Then I completely remove every instance of the company portal with a script. The final step is re-enrolling the device into Intune/Azure AD.
You can read more about this here.
