In modern hybrid corporate workspaces, few helpdesk complaints are as pervasive and frustrating as Wi-Fi disconnects during laptop mobility. A user starts an active Microsoft Teams video call at their desk, walks down the hallway into a conference room or cafeteria, and immediately experiences severe audio stutters, frozen video, and a 15-second network reconnection freeze.
On modern enterprise laptops equipped with Intel Wi-Fi 6E AX211 / AX210 / AX201 (160MHz) chipsets, the root cause is almost never an Access Point (AP) failure or poor signal coverage. Instead, it is caused by the adapter's conservative factory default roaming threshold—a condition known in wireless engineering as Sticky Client Syndrome. This guide explains the underlying 802.11k/v/r roaming mechanics and provides a production-tested Intune Proactive Remediation pipeline to optimize roaming aggressiveness and hardware parameters across thousands of endpoints without manual desk-side intervention.
Understanding Sticky Client Syndrome & Roaming Aggressiveness
In Wi-Fi network architecture, the decision to roam from one Access Point to another is controlled exclusively by the client network interface card (NIC), not by the wireless controller or the AP. The wireless infrastructure can broadcast 802.11k neighbor reports and send 802.11v BSS transition management suggestions, but the laptop's Wi-Fi driver decides when to initiate a scan and trigger a re-association request.
Intel wireless chipsets evaluate the Received Signal Strength Indicator (RSSI) of the connected AP. The RoamAggressiveness registry parameter dictates the RSSI degradation threshold required before the driver begins scanning for a stronger AP:
| Level | Setting Name | Scan Threshold (RSSI) | Enterprise Behavior & Recommendation |
|---|---|---|---|
| 1 | Lowest | -85 dBm | Will not roam until connection is virtually dropped. Extreme sticky client behavior. |
| 2 | Medium-Low | -80 dBm | Conservative. Only recommended for home environments with single APs. |
| 3 | Medium (Default) | -75 dBm | Factory default. Laptops stubbornly hold onto distant desk APs even inside conference rooms. |
| 4 | Medium-High (Recommended) | -70 dBm | Optimal Enterprise Standard. Actively scans and roams smoothly when walking into meeting rooms. |
| 5 | Highest | -65 dBm | Aggressive. Can cause ping-pong roaming loops in high-density office layouts with overlapping 5GHz cells. |
The 4 Critical Intel AX211 Adapter Optimizations
Beyond roaming aggressiveness, four additional driver parameters must be standardized to prevent sleep disconnects, packet drops, and channel negotiation bottlenecks:
- Roaming Aggressiveness (
RoamAggressiveness = "4"): Forces background probing when the current RSSI drops below -70 dBm, ensuring fast handover before Teams call buffer exhaustion. - Preferred Band (
PreferredBand = "2"): Configures the driver to prioritize 5 GHz and 6 GHz bands over congested 2.4 GHz channels. - ARP and NS Offload for WoWLAN (
PMARPOffload = "1"&PMNSOffload = "1"): Enables the network card to respond to ARP and IPv6 Neighbor Solicitation requests autonomously while in Modern Standby, preventing DHCP lease dropouts and sudden IP de-authentication. - MIMO Power Save Mode (
MIMOPowerSaveMode = "0"): Disables dynamic spatial multiplexing power saving (sets to No SMPS), maintaining full 2x2 multi-stream throughput even on battery power.
Production Intune Proactive Remediation Pipeline
Deploying registry changes via Intune Proactive Remediations ensures that every managed laptop in your fleet is evaluated continuously, auto-healed if a driver update resets settings, and reported back with compliance telemetry.
Detection Script: Detect-IntelWiFiSettings.ps1
# ==============================================================================
# Detection Script: Intel AX211 / AX210 Wi-Fi Roaming & Hardware Optimizations
# ==============================================================================
try {
$classKey = "HKLM:\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}"
# Locate all active Intel Wi-Fi Adapters
$intelAdapters = Get-ChildItem -Path $classKey -ErrorAction SilentlyContinue | Where-Object {
$desc = (Get-ItemProperty -Path $_.PSPath -Name "DriverDesc" -ErrorAction SilentlyContinue).DriverDesc
$desc -match "Intel.*(Wi-Fi|Wireless|AX211|AX210|AX201|AX200|BE200)"
}
if (-not $intelAdapters) {
Write-Host "Non-Intel Wi-Fi hardware detected or no wireless NIC installed. Compliant."
exit 0
}
$nonCompliantCount = 0
foreach ($adapter in $intelAdapters) {
$props = Get-ItemProperty -Path $adapter.PSPath
$roam = $props.RoamAggressiveness
$band = $props.PreferredBand
$arp = $props.PMARPOffload
$ns = $props.PMNSOffload
# Required Standard: RoamAggressiveness = 4, PreferredBand = 2 (5GHz/6GHz), ARP = 1, NS = 1
if ($roam -ne "4" -or $band -ne "2" -or $arp -ne "1" -or $ns -ne "1") {
Write-Warning "Adapter [$($props.DriverDesc)] is non-compliant: Roam=$roam, Band=$band, ARP=$arp, NS=$ns"
$nonCompliantCount++
}
}
if ($nonCompliantCount -gt 0) {
Write-Host "Found $nonCompliantCount non-compliant Intel wireless adapter(s). Remediation required."
exit 1 # Triggers Remediation Script
}
Write-Host "All Intel Wi-Fi adapters are fully compliant with Enterprise Roaming Standards."
exit 0
}
catch {
Write-Error "Detection error: $($_.Exception.Message)"
exit 1
}
Remediation Script: Remediate-IntelWiFiSettings.ps1
# ==============================================================================
# Remediation Script: Apply Enterprise Roaming & Hardware Tweaks to Intel NICs
# ==============================================================================
try {
$classKey = "HKLM:\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}"
$intelAdapters = Get-ChildItem -Path $classKey -ErrorAction SilentlyContinue | Where-Object {
$desc = (Get-ItemProperty -Path $_.PSPath -Name "DriverDesc" -ErrorAction SilentlyContinue).DriverDesc
$desc -match "Intel.*(Wi-Fi|Wireless|AX211|AX210|AX201|AX200|BE200)"
}
if (-not $intelAdapters) {
Write-Host "No Intel adapters found to remediate."
exit 0
}
foreach ($adapter in $intelAdapters) {
$path = $adapter.PSPath
$name = (Get-ItemProperty -Path $path -Name "DriverDesc").DriverDesc
Write-Host "Applying Enterprise Roaming Optimization to: $name..."
# 1. Roaming Aggressiveness -> 4 (Medium-High)
Set-ItemProperty -Path $path -Name "RoamAggressiveness" -Value "4" -Type String -Force
# 2. Preferred Band -> 2 (Prefer 5GHz / 6GHz)
Set-ItemProperty -Path $path -Name "PreferredBand" -Value "2" -Type String -Force
# 3. ARP Offload for WoWLAN -> 1 (Enabled)
Set-ItemProperty -Path $path -Name "PMARPOffload" -Value "1" -Type String -Force
# 4. NS Offload for WoWLAN -> 1 (Enabled)
Set-ItemProperty -Path $path -Name "PMNSOffload" -Value "1" -Type String -Force
# 5. Disable MIMO Power Save -> 0 (No SMPS / Max Performance)
Set-ItemProperty -Path $path -Name "MIMOPowerSaveMode" -Value "0" -Type String -Force
}
# Restart WLAN AutoConfig adapter binding cleanly without dropping active connection abruptly
Write-Host "Hardware registry keys successfully updated."
exit 0
}
catch {
Write-Error "Remediation error: $($_.Exception.Message)"
exit 1
}
Step-by-Step Intune Deployment Configuration
- Sign in to the Microsoft Intune Admin Center (intune.microsoft.com).
- Navigate to Devices > Remediations > Create script package.
- Basics: Name the package
Hardware - Intel Wi-Fi Roaming & AX211 Optimizations. - Settings:
- Detection script file: Upload
Detect-IntelWiFiSettings.ps1. - Remediation script file: Upload
Remediate-IntelWiFiSettings.ps1. - Run this script using the logged-on credentials:
No(Must run in 64-bit SYSTEM context to modify HKLM Class registry keys). - Enforce script signature check:
No(Unless you sign enterprise scripts with a corporate PKI code signing certificate). - Run script in 64-bit PowerShell:
Yes.
- Detection script file: Upload
- Assignments: Assign to your Entra ID Dynamic Device Group containing all corporate Windows 11/10 laptops (e.g.,
All-Corporate-Laptops). - Schedule: Configure the remediation to run Daily to maintain baseline compliance against OEM driver update regressions.
Field Diagnostic Commands for On-Site Wi-Fi Troubleshooting
When investigating a localized connectivity complaint on an end-user laptop, execute these diagnostic commands in PowerShell to inspect real-time BSSID roaming transitions:
# 1. View Current Connected AP Details (Signal %, BSSID, Channel, Radio Type)
netsh wlan show interfaces
# 2. View all visible BSSIDs and their respective signal strengths
netsh wlan show networks mode=bssid
# 3. Query the last 5 Roaming & Deauthentication events from Event Viewer
Get-WinEvent -LogName "Microsoft-Windows-WLAN-AutoConfig/Operational" -MaxEvents 15 | Where-Object {
$_.Id -in 8001, 8002, 8003, 11001, 11004
} | Select-Object TimeCreated, Id, Message | Format-Table -Wrap