How to Fix Intune Custom Compliance Policy Error 65009
Question details
The user needs to resolve error 65009 in Microsoft Intune, which occurs during custom compliance policy checks.

- Product
- Microsoft Intune
- Device & OS
- not provided
- Scenario
- Running a custom compliance discovery script via PowerShell that fails to validate correctly in Intune.
- Observed behavior
- The compliance script returns error 65009 indicating a JSON schema mismatch, even when the JSON output appears structurally valid in standard validators.
Ensure you have administrator access to the Microsoft Intune admin center and can edit the PowerShell discovery script locally for testing.
Verify and Correct the PowerShell Script JSON Schema
Adjust your PowerShell script to ensure the returned JSON matches Microsoft Intune's strict schema requirements.
Intune error 65009 typically means the discovery script's JSON output does not perfectly align with the required compliance schema. Standard JSON validators only check for basic syntax, but Intune requires exact data types, setting names, and specific formatting.
Open your custom compliance discovery script in PowerShell ISE, VS Code, or your preferred text editor.
Verify that the setting names, data types, and Boolean compliance values exactly match the Intune custom compliance documentation. Ensure numbers are not wrapped in quotes if they should be integers.
Check for correct capitalization and ensure complex strings like registry paths are properly escaped (e.g., using double backslashes where required).
Execute the script locally on a test machine to generate the JSON output. Compare this output character-by-character with Intune's expected JSON structure to identify missing or incorrectly formatted fields.

Document Your IT Policies with WPS Office
While troubleshooting Intune compliance policies and scripts, use WPS Office as a free, lightweight, and highly compatible alternative to Microsoft Office to draft your IT documentation and standard operating procedures.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Create IT Documentation: Launch WPS Writer to draft detailed standard operating procedures (SOPs) for resolving Intune compliance errors.
- 3. Save and Share: Save your documentation in .docx format to easily share it with your IT team and administrators.

Frequently Asked Questions
Why does my JSON pass syntax validators but fail in Intune with Error 65009?
Standard JSON validators only confirm that the code is structurally sound. Intune requires a specific schema format, meaning your setting names, data types (like Booleans vs. strings), and values must exactly mirror its compliance policy expectations.
Can case sensitivity cause Intune custom compliance script errors?
Yes. Microsoft Intune is highly sensitive to capitalization. Incorrect casing in setting names, properties, or Boolean values within the returned JSON will trigger Error 65009.
Where can I get advanced help for Intune PowerShell scripts?
If adjusting the JSON schema does not resolve the issue, you can seek specialist help in the Microsoft Intune Community Hub or the Microsoft PowerShell Community forums.




