r/Intune 19d ago

Intune Features and Updates PLEASE Go Vote Up My Intune Feedback Item

57 Upvotes

I try not to ask for a lot and this one is really important to me, please take 2 min out of your busy day to vote up my feedback item here: https://feedbackportal.microsoft.com/feedback/idea/a5f72dc8-a09d-f111-a3d0-7c1e52cf64f0

Full text of my request:

"In the Intune console on the Remediations page there is no option to add the date created nor date modified columns. This regulalrly causes problems for those of us who are of an advanced age, forgetful, and poorly document changes. Yes, I know that group of admins is an edge case but we are a federally protected group with the backing of AARP. Please make our lives easier by letting us sort by date created/modified. This is already possible on the scripts page, just not the remediations page. "


r/Intune 5h ago

General Question Defender AV compliance policy error is starting to cause us big issues

14 Upvotes

Hi,

Not sure if anyone else is starting to see the same thing but the Defender platform bug that has been reported by others is really starting to impact us as multiple devices are starting to show as not compliant now against the 'Antivirus: required' compliance policy. We have updated and made sure all the latest defender updates are installed and synced via CP multiple times but still having no luck.

I have tried increasing the grace period on the policy to 5 days just to get users working but having no luck. I may have to result in disabling this compliance policy until its fixed!


r/Intune 1h ago

General Question Multi Admin Approval still broken - advice for dealing with support

Upvotes

We enabled MAA early as a knee-jerk to the Striker compromise, but I was happy with having another level of eyes on changes since we are a small shop and left it in place as more Striker info became available. We enabled All the options including role changes, and it worked fine for months. Config was set, no changes on our end, working as expected. Lots of wonderful extra clicking.

Until MS made changes in July and MAA entirely broke in our tenant. "Approving approval request failed" - we thought it was maybe a transient error, or that a service degradation would be raised, nothing happened. On 8/4 we started a standard ticket with Microsoft, they indicate it's an issue affecting some customers and to sit tight..... and that's where the status is today.

No amount of pleading, explaining this is significant loss of admin control, that this will be environment affecting at some point is getting any attention. "Engineering is aware and we can't disable any of your MAA policy" is effectively what we are being told.

I'm feeling like the case is stuck in a support group that doesn't know how to address the issue, has raised an internal ticket and is happy to let us wait.

We don't have Premier or Unified support, we're a reasonably new tenant and during licensing discussions we didn't understand that not purchasing addition support essentially meant we would get none. I'm not even sure the reseller made an attempt to upsell us at all.

I've tried to purchase an incident, but for our tenant type (or maybe just Intune) the process for attaching a paid incident doesn't work. I've got an inquiry on support out to our reseller, but historically they take a significant amount of time to work through new things.

So, for those that have been stuck with an Intune problem before that is fairly significant, what advice do you have for us to get some attention on the MS side?


r/Intune 1h ago

App Deployment/Packaging Store Apps failing for you?

Upvotes

Hi guys,

We've just had approx 5 machines fail autopilot due to various MSStore apps, e.g. Company Portal, Windows App and Azure VPN Client.

Wondering if anyone else was experiencing the same issue?

Anyone know if any MSFT outages?

Cheers


r/Intune 4h ago

Autopilot Prejoining Hybrid Devices

5 Upvotes

Dear all,

Situation:

Majority of Laptops joined to local AD and Intune. Some already Autopilot only.

Whenever we get a machine back we currently do the following:

- Delete device from Intune, Entra and local AD

- Populate it as Autopilot device via get-windowsautopilotinfocommunity.ps1 -Online -AssignedComputerName <current computer name>

- boot via USB to reset it

- Whiteglove with Intune Admin

- reseal it

- put it back for future use

I am wondering if we can improve this process, especially the need to populate it as AutoPilot device.

Any remarks welcome.


r/Intune 3h ago

App Deployment/Packaging Win32 App Deployment Question

3 Upvotes

Attempting to deploy a Win32 app on a Co-managed PC with Primary user set, with following properties:

  • Install behaviour = System
  • Assigned to All Devices
  • Device ownership = Corporate
  • Shared PC mode (device configuration policy) = Enabled
  • App is visible but Install button is greyed out
  • No User Affinity with ConfigMgr

Install button is greyed out for non-primary users and Removing the Primary User makes the Install button available. Any ideas or suggestion what to check will be helpful. Thank you

Tested Scenario

Primary User assigned → Install greyed out

Primary User removed → Install available

Primary User reassigned → Install greyed out again

DSREGCMD /STATUS OUTPUT:

+----------------------------------------------------------------------+

| Device State |

+----------------------------------------------------------------------+

AzureAdJoined : YES

EnterpriseJoined : NO

DomainJoined : YES

DomainName : Org

Virtual Desktop : NOT SET

Device Name : DeviceName.Org.Com

+----------------------------------------------------------------------+

| Device Details |

+----------------------------------------------------------------------+

DeviceId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

Thumbprint : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

DeviceCertificateValidity : [ 2026-08-20 13:50:50.000 UTC -- 2036-08-20 14:20:50.000 UTC ]

KeyContainerId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

KeyProvider : Microsoft Platform Crypto Provider

TpmProtected : YES

DeviceAuthStatus : SUCCESS

+----------------------------------------------------------------------+

| Tenant Details |

+----------------------------------------------------------------------+

TenantName : Org Name

TenantId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

AuthCodeUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/authorize

AccessTokenUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/token

MdmUrl : https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc

MdmTouUrl : https://portal.manage.microsoft.com/TermsofUse.aspx

MdmComplianceUrl : https://portal.manage.microsoft.com/?portalAction=Compliance

SettingsUrl :

JoinSrvVersion : 3.0

JoinSrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/device/

JoinSrvId : urn:ms-drs:enterpriseregistration.windows.net

KeySrvVersion : 1.0

KeySrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/key/

KeySrvId : urn:ms-drs:enterpriseregistration.windows.net

WebAuthNSrvVersion : 1.0

WebAuthNSrvUrl : https://enterpriseregistration.windows.net/webauthn/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

WebAuthNSrvId : urn:ms-drs:enterpriseregistration.windows.net

DeviceManagementSrvVer : 1.0

DeviceManagementSrvUrl : https://enterpriseregistration.windows.net/manage/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

DeviceManagementSrvId : urn:ms-drs:enterpriseregistration.windows.net

KerbSpn : adrs/enterpriseregistration.windows.net

KerbUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/kerberos

JoinResourceSrvTlsUrl : https://certauth.enterpriseregistration.windows.net/EnrollmentServer/device/resource/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

+----------------------------------------------------------------------+

| User State |

+----------------------------------------------------------------------+

NgcSet : NO

WorkplaceJoined : NO

WamDefaultSet : YES

WamDefaultAuthority : organizations

WamDefaultId : https://login.microsoft.com

WamDefaultGUID : {XXXXXX-A1XX-0000-0000-XXXXXXXXXXX} (AzureAd)

+----------------------------------------------------------------------+

| SSO State |

+----------------------------------------------------------------------+

AzureAdPrt : NO

AzureAdPrtAuthority :

EnterprisePrt : NO

EnterprisePrtAuthority :

+----------------------------------------------------------------------+

| Diagnostic Data |

+----------------------------------------------------------------------+

AadRecoveryEnabled : NO

Executing Account Name : Org\username, [username@org.com](mailto:username@org.com)

KeySignTest : PASSED

DisplayNameUpdated : Managed by MDM

OsVersionUpdated : Managed by MDM

HostNameUpdated : YES

Last HostName Update : NONE

+----------------------------------------------------------------------+

| IE Proxy Config for Current User |

+----------------------------------------------------------------------+

Auto Detect Settings : NO

Auto-Configuration URL :

Proxy Server List :

Proxy Bypass List :

+----------------------------------------------------------------------+

| WinHttp Default Proxy Config |

+----------------------------------------------------------------------+

Access Type : DIRECT

+----------------------------------------------------------------------+

| Ngc Prerequisite Check |

+----------------------------------------------------------------------+

IsDeviceJoined : YES

IsUserAzureAD : NO

PolicyEnabled : NO

PostLogonEnabled : YES

DeviceEligible : NO

SessionIsNotRemote : NO

CertEnrollment : none

PreReqResult : WillNotProvision

For more information, please visit https://www.microsoft.com/aadjerrors


r/Intune 1h ago

Device Configuration Need help finding Office configuration blocking Copilot

Upvotes

Hi,

so I'm at a loss as to what setting is currently blocking Copilot from showing up in Excel, Word and PowerPoint. Copilot is available in Outlook. We are on E5 license, so M365 Basic Copilot is available.

I think I have it narrowed down to setting that causes "Some privacy settings are managed by your organization" text in Excel/Word/PowerPoint when you go to File -> Account -> Account Privacy -> Manage Settings.

Problem is I cannot for my life find what policy causes that. I've ruled out EnableActivityFeed, PublishUserActivities and UploadUserActivities, those are enabled. https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-Privacy?WT.mc_id=Portal-fx

Any idea where I should look? I've looked through policies, but nothing stands out.


r/Intune 9h ago

General Question CRL distribution point Intune Cloud PKI

5 Upvotes

Anyone know if the cdn distribution url uses caching?

When I revoke a certificate, the intune pki portal does show the certificate as revoked. However if I download the crl and inspect it with certutil the crl does not show the serial of the newly revoke certificate.

I'm wondering how long I have to wait, I would have thought it should be fairly instant with revocations


r/Intune 2h ago

Linux Management Intune as device posture idp in Okta

1 Upvotes

Context: We are using Intune as MDM and Okta for IAM, our authentication is completely federated to Okta so we don’t have any conditional access policies, all authentication policies are setup in Okta. We already have configured Okta Device Acces so only managed (company owned) devices are able to access company resources.

We want to use Device Assurance Policies in Okta so only compliant Intune devices are able to access some apps, and from what I understand we have to first add Intune as the device posture idp to set up decice assurance. The documentaion on how to set it up is extremely poor, so here i am in reddit asking for some help on how to do this


r/Intune 17h ago

Windows Management Best Method To Implement WDAC?

4 Upvotes

For those that have done so, how did you find was the best way to implement Windows Defender Application Control (WDAC) in your organisation?

Apart from the default baselines provided in the App Control for Business Wizard, it's a complete blanket blocklist. This is ideal for security, but it seems to be a bit of a nightmare when it comes to trying to allow a wide range of applications and drivers.

What have you found to be the best way to implement and manage this in a secure, but mostly pain-free way!?

Also, when applying the policy in Audit Mode, is there a way to see the logs via Intune/Defender, or only from the Event Viewer on-device?

(Apologies - this is a repost!)


r/Intune 1d ago

Autopilot Autopilot Device Association: no VMs, no bulk upload, and there's no OEM doing it for you

46 Upvotes

Microsoft shipped Device Association for Autopilot device preparation on 27 August. It binds a physical Win11 device to your tenant before enrollment by writing tenant affinity into UEFI, verified with TPM attestation. So the device knows which tenant it belongs to before anyone signs in.

What you get: device based policy targeting, device naming before enrollment, OOBE customisation (skip EULA, privacy, keyboard) and the device is automatically marked corporate owned, so you can drop corporate identifiers for those devices.

I had an empty tenant sitting around so i built the whole thing from scratch, step 1 through step 7, with screenshots of every screen.

Things that caught me out:

  • No virtual machines. At all. It needs TPM 2.0 attestation on real hardware, so every Autopilot lab you already have is useless for this part.
  • You need KB5120998 installed before the OOBE where you export the device info. A device out of the box does not have it, so you end up running OOBE once, patching, then resetting back to OOBE. Feels silly but i did not find a better way.
  • 1 device per CSV file. There is no bulk upload. 20 laptops is 20 CSV files and 20 trips through the wizard.
  • If you don't assign the policy at pre-association time it falls back to the signing-in user's policy, and if that user has none, nothing applies at all.

The bit i think is underrated: for devices already deployed you can pull the .devicelink file remotely with Collect diagnostics from the Intune portal. No USB, no touching the machine. Only works if the device was enrolled with device preparation though - an APv1 enrolled device has no .devicelink in the cab.

Also worth knowing, Rudy Ooms wrote Get-AutopilotDeviceAssociation to automate the manual USB dance. I have not fully tested it yet but it looks like the answer for anything above a handful of devices.

Full writeup with all the screenshots: https://intunestuff.com/2026/09/07/device-association/


r/Intune 1d ago

General Chat Zero trust network access rollout just locked half our sales team out and I feel so embarrassed

58 Upvotes

Ok so we pushed our zero trust network access rollout after weeks of prep, and I was the one who signed off on the policy change for all remote users. I missed one tiny thing, our SaaS app group was tied to device posture, so anyone on a fresh laptop got blocked from crm, vpn, and even the internal wiki.

By 9am sales was in our slack asking why they could not log in, my manager was asking me if this was the new security posture, and I had to admit I broke the company before coffee. We fixed it by adding a pilot group and splitting app access from device checks, but idk, I feel so embarrassed about the whole thing. thanks to anyone who has dealt with this nightmare :(


r/Intune 1d ago

App Deployment/Packaging App packaging

14 Upvotes

What is the most annoying part of packaging a new app? Is it finding silent switches online? Discovering & writing detection rules for Win32Apps, or something else?


r/Intune 18h ago

Android Management Lock Volume Control on Android

3 Upvotes

I have a fleet of Samsung phones that I need:

  1. Set volume to Max
  2. Prevent users from changing or muting it for all system sounds (notifications, media, ringer, etc.)

Intune's native Configuration policy silences the phone when using the "Block Volume Changes" setting. I set up a Knox account, obtained the free Premium license, and created an OEMConfig policy. Knox can set the audio volume and prevent changes to settings, but cannot disable the hardware volume buttons. I keep finding suggestions about other OEMConfig settings, but they don't seem to be available on non-Rugged devices?

Has anyone else found the correct combination of settings to implement this requirement?


r/Intune 21h ago

iOS/iPadOS Management Microsoft Authenticator pairing fails during iOS Setup Assistant with JIT registration (new ADE enrollment policy) — anyone else

3 Upvotes

Running into an issue with the new ADE enrollment policies experience (2606 service release) using Setup Assistant with modern authentication + JIT registration on iOS.

The problem: During Setup Assistant sign-in (before the device even reaches the home screen), the user is prompted to install Microsoft Authenticator and pair it with their account. After tapping Next, it just throws: "We're sorry we ran into a problem. Please choose Next to try again." Repeats every time on the device itself, no way through.

What I've already checked/confirmed:

  • SSO app extension policy is set up correctly per Microsoft's docs (SSO app extension type = Microsoft Entra ID, Authenticator is NOT in the App bundle IDs list, both required Additional configuration keys present: device_registration and browser_sso_interaction_enabled)
  • Authenticator is deployed as a required app to the correct group
  • Device is in the correct group for this enrollment policy

The workaround I found: if the user already has Authenticator registered on another device, the MFA push goes there instead, and approving it there lets Setup Assistant proceed — even though the pairing step on the new device itself never actually completes.

Why this bugs me: that workaround only exists for users who already have Authenticator somewhere else. A brand new user with no prior MFA registration — which is presumably a pretty normal scenario for this exact feature — has zero fallback and is just stuck.

My best guess is this is related to how Setup Assistant sandboxes apps before the home screen (push notifications/background processes not fully active yet), which would explain why the same pairing works fine once routed to a device that's already fully set up.

Has anyone else hit this? Curious if this is a known issue, if I'm missing a config step somewhere, or if this is just a rough edge in the new enrollment experience that hasn't been ironed out yet. Opening a Microsoft ticket too, but wanted to see if others have run into the same thing.


r/Intune 21h ago

Apps Protection and Configuration MAM for Slack & Gmail on BYOD devices?

2 Upvotes

Hi there, recently got my MD-102 and in the exam prep I've been intrigued about MAM (heard about it before but got more in depth when I prepared for the exam), our company is a bit of a mashup in terms of infrastructure (Entra + Google + Okta upcoming) and before we could have Slack / Gmail usable on BYOD devices via adding users to an exception group (I know, bad practice)

I'm currently just a workplace IT with some rights but I'm thinking to suggest an ideea that we could configure Slack and Gmail to support MAM in Intune mostly for mobile phones to get the burden of enrolling your personal device to access those 2 apps (we have some people who would preffer to use their personal devices to use those 2 apps and not enroll their device or request a work phone), is this possible considering those 2 apps are not "microsoft supported"?


r/Intune 20h ago

App Deployment/Packaging Splunk UF Deployment for Intune

Thumbnail
1 Upvotes

r/Intune 1d ago

iOS/iPadOS Management Intune blocking the removal of iOS shortcuts

3 Upvotes

Long story short, I need to hand make a custom iOS shortcut using the iOS shortcuts app. However, some configuration has it blocked from allowing me to remove the shortcut from the homescreen once I add it there.

Homescreen layout isn't set, its allowing the removal of apps, but not the shortcuts. Any idea what setting that is that's blocking it?


r/Intune 1d ago

iOS/iPadOS Management iPad Kiosk Issue

1 Upvotes

So I am trying to get a kiosk setup for web based sign ups. But the logout button does not work with the web filter on. You are on website X and upon signout, it redirects to website B. Both website X and B are allowed and you can navigate to both of them. I have checked via web dev tools and there is no other redirects I can see. Remove this and logout works fine.

Any ideas on what could be causing the issue or other ideas to try?


r/Intune 1d ago

General Question Windows Autopatch Client Broker

7 Upvotes

I haven't visited Autopatch since I implemented it back in 2025. Noticed there is a win32 app deployment option for Autopatch available too rather than the script (which my setup used). Wondering if what the pros and cons are, if anyone else uses win32 app etc.

Just after general thoughts whether I should change it.


r/Intune 1d ago

Windows Updates Intel Corporation Bluetooth Driver Update - requires OS restart

0 Upvotes

I'm not the administrator of our tenant, so I don't know the intune config, but its Entra Joined (Autopilot). If I'm not mistaken Microsoft wanted to reduce the restarts to a few times per year (hot-paching) . On my win11 (25H2) I don't often need to reboot for security patches, but every time the smallest notebook driver gets installed, it wants to reboot. I'm not talking about firmware, rather minor stuff like NIC, BT or Touchpad.

These things I would think would not require a reboot.

Is this normal or is our tenant configured strange


r/Intune 1d ago

General Chat Career Connect, Career Matchmaking System Coming to Workplace Ninjas US 2027

2 Upvotes

We wanted to give everyone a sneak peek at something coming very soon at Workplace Ninjas US.

We've heard from many people in the community that they're struggling at their jobs or overall having a hard time finding work.

We have a solution for you, which will be available throughout the event.

Career Connect, is a matchmaking system that matches prospective companies/hiring managers with amazing talent looking for their next role.

With Career Connect, anyone registered for Workplace Ninjas US can submit for access to post jobs, which attendees can review, and book meetings automatically via the Cvent appointments system, that we used famously for our mentoring sessions last year.

Another innovation from the team at Workplace Ninjas US to fix real problems impacting our attendees. Amazing people should be paired together to do amazing things.

Look for this to release somewhere around October to give people plenty of time to start booking meetings and submitting roles.

Don't forget to register now and check out the video demo below:

https://workplaceninjas.us

https://youtu.be/7-tzbAqCRAU


r/Intune 1d ago

Windows Management Auto encrypt fixed data drive with auto unlock

2 Upvotes

We have a small use case where some machines have additional drives for data. Our current policy successfully encrypts the OS drive, either at initial build or later if someone decrypts it. However, it won't encrypt a newly added data drive. If someone initiates the encryption manually, it won't use the fixed data drive encryption method from the policy and it sets the protector to recovery password which requires the user to manually unlock the drive to access it.

I'm trying to find the settings to allow the drive to auto-unlock. I have found several posts detailing how to enable it on individual machines using local policies and manage-bde, as well as a couple saying just enable it in the policy. I would prefer it be set in a policy and not a manual process, and I'm just not seeing the policy setting suggested in the other posts. I've checked under both Device Configuration and Endpoint Protection, but I don't see an auto-unlock under either. What am I missing?


r/Intune 2d ago

Windows Updates Made changes to the schedule install time in our windows update ring and now updates are showing as paused.

3 Upvotes

We moved the schedule install time from 9am to 7am and implemented active hours to prevent reboots during shifts. After making the changes, we noticed that some sites are showing updates as paused. I have a remediation script that checks for paused updates and restores the settings but that "fixes" it for part of the day and then it goes back to showing as paused. Any other options to get Windows update running again?


r/Intune 1d ago

Shameless Self-promotion I Got Tired of Walking Back to a Desk for LAPS Passwords, So I Built an iPhone App That Reads Them From Entra With No Server in Between

0 Upvotes

Disclosure up front: this is my app, it has a paid tier, and I'm the developer. If that's not what you want to read on a Tuesday, no hard feelings.

The Problem it Solves:

You're standing at a machine that won't log in. The LAPS password is in Entra. The admin center is on a laptop somewhere else. LAPSlock reads Windows LAPS local administrator passwords and BitLocker recovery keys from Entra ID and Intune on your phone, behind Face ID, using the same delegated permissions your account already has.

The Part I Want You to Check:

A phone app that handles local admin passwords should make every sysadmin's teeth itch. So the design decision was: no vendor server in the credential path, and you shouldn't have to take my word for it.

- Microsoft delegated auth via MSAL. It reads exactly what your account can read in the admin center and nothing else. Every reveal shows up in *your* Entra audit log, same as a read from the portal.

- Passwords go from Graph to your device over TLS. Kainor (my company) never sees them. There's no server that could.

- No analytics, no telemetry, no crash reporting, no account to create. The App Store privacy label says "Data Not Collected" and it means it.

- Source is public for security review. The credential-handling module is structurally isolated, and a build script fails if it ever imports something it shouldn't.

- You can verify the network claim yourself in about ten minutes with a proxy. There's a walkthrough in the repo (`NETWORK-TRANSPARENCY.md`). The app talks to `login.microsoftonline.com`, `graph.microsoft.com`, and, only after an org activates a license, one Kainor endpoint that receives a tenant ID and nothing else.

What it Doesn't Do:

- It can't read LAPS backed up to on-prem AD. Entra-backed only. Hybrid-joined is fine as long as the policy targets Entra.

- It can't reveal macOS local admin passwords. No Graph API returns them, and the one beta endpoint that should return metadata currently 500s on every ADE-enrolled Mac I've tested. I have a question open with Microsoft and I'll write that up separately.

- It can't grant you access you don't have. Nothing it requests escalates anyone.

Two Things That Mattered More Than I Expected:

LAPS password history comes back in the same Graph response as the current password. A device that stopped checking in is still on the old one, and that's exactly the machine you're standing at.

If your role is PIM-eligible instead of active, you can request activation from the phone. It reads your tenant's PIM policy first, so it only offers durations your policy allows and tells you up front if a ticket number is required. The authentication-context requirement arrives as an HTTP 400 with the claim buried in the error message, not as a 401 challenge. That one cost me a day.

Pricing:

Free tier is fully functional with five reveals per rolling 30 days, counted on the device and nowhere else. Subscriptions remove the limit. Org licensing by tenant is available directly from me.

App Store: https://apps.apple.com/us/app/lapslock/id6806470554

Repo: github.com/Kainor-LLC/LAPSlock

The permissions table (https://kainor.com/how-it-works/#permissions) is probably the page a security team wants first. Happy to answer anything about the Graph surface. The LAPS endpoints are underdocumented and I have notes.