We experience the passcode reset token issue that is described by Microsoft here: https://techcommunity.microsoft.com/blog/intunecustomersuccess/support-tip-powershell-script-now-available-for-ios-passcode-reset-token-known-i/1250875
We've run the PowerShell script created by Dave Falkus that's described in the link above.
When we evaluate the report from the script, it doesn't align with what we're seeing in our environment. In the report, devices that are shown to have an unlock token, don't work with a passcode reset. Devices that are shown to NOT have an unlock token are able to successfully get their passcodes reset. The correlation between what's expected from the report and what happens in our environment is very, very low. I would say the report correlates to what we see about 1 in 10 times.
I opened a Microsoft ticket and it was suggested that I submit an issue for this here.
To summarize, trying to find a way to validate what mobile devices in our environment will actually fail to reset their passcodes.
Thanks