We've had this issue ever since we put up this policy. We have a Group for restricted device access with the "Device control scanning" enabled, however for some of the computers in that group it shows up as "Differs from policy" and "Device control scanning" Inactive. We can go in there and manually comply with "Group Device control policy" and it will be fine but the next morning the same issue happens. This has been an ongoing issue not sure if anyone else have had this issue. We've tried recreating th policy, using the default policy as enabled, etc, but nothing seems to work.
This thread was automatically locked due to age.