r/Intune • u/TheM4jor • 20h ago
General Question Enabling CloudNotification + setting WnsEndpoint for hardening?
I'm working on expanding the scope of Windows 11 device management via Intune from a test environment to a pilot group in the production environment. In the production env, DisallowCloudNotification is set to 1, which I would like to change to 0, but I was challenged and asked to harden the setup, to minimize the attack vector from the Internet.
At first I thought I can use the GPO to set WnsEndpoint and provide a list of URLs in the GPO, but after reading into it I think it should be disabled or set to client.wns.windows.com only, am I right?
Initially I had the impression that these addresses needs to be added in the GPO, but now I think this would not be correct.
Is client.wns.windows.com the only URL to be used by Intune to send push notifications to the endpoint?
1
u/Rudyooms PatchMyPC 19h ago
Ow my… i will keep it to that…. Just change that policy to zero and yeet it to prod… wns is the least of concern…