## TL;DR
The Duo trusted-endpoint check fails when the Duo device certificate is missing from the device, the management profile is gone, or the device fell out of compliance. Verify the device is compliant in the MDM first, then confirm the Duo certificate is present, then check Duo's trusted-endpoints report.

## The query
```text
duo trusted endpoint check failing on compliant devices
```

## Use this when
- Duo blocks access saying the endpoint is not trusted
- device shows compliant in Intune or Jamf but Duo disagrees
- check starts failing after an OS update

## Not for
- Duo push notifications not arriving (different symptom)
- unenrolled or unknown devices (enroll them first)
- Duo policy misconfiguration blocking everyone

## Steps
1. In the MDM, confirm the device is compliant and the management profile is installed. Expected output: compliant status with the profile present
2. On the device, confirm the Duo device certificate exists in the certificate store and is valid. Expected output: the certificate is present and valid
3. If it is missing, push the certificate or profile again from the MDM, or re-enroll the device. Expected output: the certificate installs successfully
4. Check the Duo admin panel trusted-endpoints report for the device. Expected output: the device is listed as trusted
5. If compliance recently flipped, have the device check in with the MDM and retry. Expected output: fresh compliance state and the check passes

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_BpJM-1qpNqqLHiJp4Apchw
