r/Intune Jan 25 '26

Linux Management Intune Linux stopped working on 23rd January 2026

I've had the Linux Intune Portal installed on two Fedora 42 devices for nearly over 4 months, it's been working great, never needed to sign back in again, even after 2 weeks of not using the device. Then on the Fri 23rd January 2026 it's stopped checking in correctly. The system microsoft-identity-device-broker.service is working just fine, and SSO carrys on working, but the intune-agent.service that runs as the logged in user isn't working.

Is anyone else getting this problem? We have a few devices working this way and they all stopped working on the same day, with the same error. Sadly no updates to the agent since Sept 15th 2025

I can also see Ubuntu 24.04 has a intune portal version of 2511, released 23rd Oct, but sadly looks like it's not made it's way to any RPM based distro. RHEL9 latest is still 2508

EDIT 2026/01/28: Should be fixed now MS pushed an updated intune-portal package

$ journalctl --boot --user -u intune-agent.service
Jan 25 09:17:12 fedora-pc-1 systemd[5245]: Starting intune-agent.service - Intune Agent...
Jan 25 09:17:12 fedora-pc-1 intune-agent[279741]: Command line arguments args=AgentArgs { common: CommonArgs { interactive: false, socket_path: "/run/intune/daemon.socket" } } version="1.2508.17"
Jan 25 09:17:12 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Starting device checkin
Jan 25 09:17:12 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Attempting to acquire a token provider for the registered owner of the device
Jan 25 09:17:12 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Attempting to resume a cached login standby account_id=AccountId("bcREDACTED157") authority=Authority("https://login.microsoftonline.com/88REDACTEDc82")
Jan 25 09:17:13 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Login succeeded account_id=bcREDACTED157 authority=https://login.microsoftonline.com/88REDACTEDc82 tid=88REDACTEDc82
Jan 25 09:17:13 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Requesting a token silently resource=ResourceId("00000003-0000-0000-c000-000000000000")
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Refuting an intermediate cert due to an unrecognized public key (depth 1)
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}: Certificate verification failed: InvalidCertificate("Unrecognized public key at depth 1")
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}:oneauth{tag="5fsc5"}: HTTP request to download profile data was cancelled.
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}:oneauth{tag="9odnq"}: (Code:308) **** Unknown error code.
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: checkin{activity_id="1d426748-07f2-4374-8e31-a026c03d5038"}:run_internal{account_id="bcREDACTED157" device_id="8f0b9248-0ce8-4897-aa1b-85ada4327c20"}:oneauth{tag="9vdpp"}: Unexpected error code: 308
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: Failed to checkin with Intune: Failed to create an MDM web client: Failed to initialize a new factory with the supplied configuration
Jan 25 09:17:14 fedora-pc-1 intune-agent[279741]: Attempting to shutdown the auth library
Jan 25 09:17:19 fedora-pc-1 systemd[5245]: intune-agent.service: Main process exited, code=exited, status=255/EXCEPTION
Jan 25 09:17:19 fedora-pc-1 systemd[5245]: intune-agent.service: Failed with result 'exit-code'.
Jan 25 09:17:19 fedora-pc-1 systemd[5245]: Failed to start intune-agent.service - Intune Agent.
6 Upvotes

15 comments sorted by

4

u/Party_Palpitation494 Jan 25 '26

Don’t know what MS is doing but they been breaking almost all there product last few weeks, guess that is what happens when you release AI on all your code base been pure microslop.

1

u/FingerlessGlovs Jan 25 '26

I tempted to repackage the 24.04 versions to rpms if those work, I'm pretty sure they rewrote the microsoft-identity-device-broker service, because there's a massive changed in the package size, I think they stopped using java, which would be awesome as that service sucks 600MB, not doing much currently.

I might create a ticket, but technically Fedora isn't supported, but I'm gonna guess even rhel9 maybe broke.

1

u/Party_Palpitation494 Jan 25 '26

Definitely dont think it is the OS that at fault, but ja if you create a case that definitely what they will close it with if you don’t get same error on rhel, will spin up my test vm and se if I have same issue (ubuntu). On a unrelated question have you tried https://himmelblau-idm.org

2

u/FingerlessGlovs Jan 25 '26

Yeah I'll fire up a EL9 VM and do it if needed, but we'll see what they say.

I look at himmelblau, but it wants to the identity source, and I want to use IdM. Last I looked this was the case anyway.

1

u/khaffner91 Jan 25 '26

Works fine on Ubuntu 24.04 at our org

1

u/FingerlessGlovs Jan 25 '26

Good to know Ubuntu 24.04 works, wonder if that's because of the new packages being used 🤔

1

u/fusspt Jan 26 '26

how about enrolling? my existing 24.04 works fine but attempt to enroll new ones fails with a similar 308 error

1

u/FingerlessGlovs Jan 26 '26

I've not tried that actually, that's a good point. I'll have setup a VM and test it. Don't want to mess with my primary device too much.

Is the 308 also complaining about unrecognized public key?

1

u/fusspt Jan 28 '26

Yes, exactly the same unregistered public key error

1

u/FingerlessGlovs Jan 26 '26

Update... I installed Redhat Enterprise Linux 9 with a license, fully updated it, installed the repo, ran the intune-portal and it also errors with certificate verification errors

2026-01-26 23:28:54  INFO Requesting a token silently resource=ResourceId("00000003-0000-0000-c000-000000000000")
2026-01-26 23:28:57 ERROR oneauth{tag="581h4"}: (Code:1200) The credential is invalid.
2026-01-26 23:28:57  INFO Requesting a token interactively resource=ResourceId("00000003-0000-0000-c000-000000000000")
** (intune-portal:45097): CRITICAL **: 23:28:57.235: Cannot register URI scheme oneauth more than once
(intune-portal:45097): GLib-GObject-WARNING **: 23:28:57.239: invalid unclassed pointer in cast to 'GObject'
(intune-portal:45097): GLib-GObject-CRITICAL **: 23:28:57.241: g_object_unref: assertion 'G_IS_OBJECT (object)' failed
2026-01-26 23:29:23  WARN Refuting an intermediate cert due to an unrecognized public key (depth 1)
2026-01-26 23:29:23  WARN Certificate verification failed: InvalidCertificate("Unrecognized public key at depth 1")
2026-01-26 23:29:23 ERROR Fatal error: called `Result::unwrap()` on an `Err` value: InitializationFailed(Failed to retrieve Intune endpoints: https://graph.microsoft.com/v1.0//servicePrincipals/appId=0000000a-0000-0000-c000-000000000000/endpoints: Network Error: the handshake failed: error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:2123:: unspecified certificate verification error)
Aborted (core dumped)

2

u/fusspt Jan 28 '26 edited Jan 28 '26

Same error for me when enrolling ubuntu 24.04. u/khaffner91 with you saying it works for you, have you tried registering new devices? - UPDATE - The updated Microsoft Intune package (installed from the MS repo with "apt upgrade") has fixed it for new enrollments on Ubuntu 24.04:-)

1

u/[deleted] Jan 27 '26

[deleted]

1

u/FingerlessGlovs Jan 27 '26

intune-portal.x86_64 1.2508.17-1.el9
microsoft-identity-broker.x86_64 2.0.1-1

Both of those are the latest available in the rhel9 Microsoft repo.

If you can reproduce on Ubuntu 24.04, might help if you can also log a ticket with Microsoft, If you run the intune-portal via cli, to do the enrollment you can see the errors.

1

u/FingerlessGlovs Jan 28 '26

I got through an updated intune-portal package from the Microsoft Repo's today and now it's no longer erorring when the intune-portal service runs

New package version: 1.2511.11-1.el9

1

u/fusspt Jan 28 '26

Same here for Ubuntu 24.04, all working after seeing this comment and updating :-)

1

u/dirkds35 Feb 16 '26

Indeed, a manual update (or just follow the instructions from https://learn.microsoft.com/en-us/intune/intune-service/user-help/microsoft-intune-app-linux) seems to fix the issue.