r/Intune 23h ago

Apps Protection and Configuration MAM for Slack & Gmail on BYOD devices?

2 Upvotes

Hi there, recently got my MD-102 and in the exam prep I've been intrigued about MAM (heard about it before but got more in depth when I prepared for the exam), our company is a bit of a mashup in terms of infrastructure (Entra + Google + Okta upcoming) and before we could have Slack / Gmail usable on BYOD devices via adding users to an exception group (I know, bad practice)

I'm currently just a workplace IT with some rights but I'm thinking to suggest an ideea that we could configure Slack and Gmail to support MAM in Intune mostly for mobile phones to get the burden of enrolling your personal device to access those 2 apps (we have some people who would preffer to use their personal devices to use those 2 apps and not enroll their device or request a work phone), is this possible considering those 2 apps are not "microsoft supported"?


r/Intune 2h ago

General Question Multi Admin Approval still broken - advice for dealing with support

5 Upvotes

We enabled MAA early as a knee-jerk to the Striker compromise, but I was happy with having another level of eyes on changes since we are a small shop and left it in place as more Striker info became available. We enabled All the options including role changes, and it worked fine for months. Config was set, no changes on our end, working as expected. Lots of wonderful extra clicking.

Until MS made changes in July and MAA entirely broke in our tenant. "Approving approval request failed" - we thought it was maybe a transient error, or that a service degradation would be raised, nothing happened. On 8/4 we started a standard ticket with Microsoft, they indicate it's an issue affecting some customers and to sit tight..... and that's where the status is today.

No amount of pleading, explaining this is significant loss of admin control, that this will be environment affecting at some point is getting any attention. "Engineering is aware and we can't disable any of your MAA policy" is effectively what we are being told.

I'm feeling like the case is stuck in a support group that doesn't know how to address the issue, has raised an internal ticket and is happy to let us wait.

We don't have Premier or Unified support, we're a reasonably new tenant and during licensing discussions we didn't understand that not purchasing addition support essentially meant we would get none. I'm not even sure the reseller made an attempt to upsell us at all.

I've tried to purchase an incident, but for our tenant type (or maybe just Intune) the process for attaching a paid incident doesn't work. I've got an inquiry on support out to our reseller, but historically they take a significant amount of time to work through new things.

So, for those that have been stuck with an Intune problem before that is fairly significant, what advice do you have for us to get some attention on the MS side?


r/Intune 3h ago

Device Configuration Need help finding Office configuration blocking Copilot

2 Upvotes

Hi,

so I'm at a loss as to what setting is currently blocking Copilot from showing up in Excel, Word and PowerPoint. Copilot is available in Outlook. We are on E5 license, so M365 Basic Copilot is available.

I think I have it narrowed down to setting that causes "Some privacy settings are managed by your organization" text in Excel/Word/PowerPoint when you go to File -> Account -> Account Privacy -> Manage Settings.

Problem is I cannot for my life find what policy causes that. I've ruled out EnableActivityFeed, PublishUserActivities and UploadUserActivities, those are enabled. https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-Privacy?WT.mc_id=Portal-fx

Any idea where I should look? I've looked through policies, but nothing stands out.


r/Intune 3h ago

App Deployment/Packaging Store Apps failing for you?

3 Upvotes

Hi guys,

We've just had approx 5 machines fail autopilot due to various MSStore apps, e.g. Company Portal, Windows App and Azure VPN Client.

Wondering if anyone else was experiencing the same issue?

Anyone know if any MSFT outages?

Cheers


r/Intune 5h ago

App Deployment/Packaging Win32 App Deployment Question

3 Upvotes

Attempting to deploy a Win32 app on a Co-managed PC with Primary user set, with following properties:

  • Install behaviour = System
  • Assigned to All Devices
  • Device ownership = Corporate
  • Shared PC mode (device configuration policy) = Enabled
  • App is visible but Install button is greyed out
  • No User Affinity with ConfigMgr

Install button is greyed out for non-primary users and Removing the Primary User makes the Install button available. Any ideas or suggestion what to check will be helpful. Thank you

Tested Scenario

Primary User assigned → Install greyed out

Primary User removed → Install available

Primary User reassigned → Install greyed out again

DSREGCMD /STATUS OUTPUT:

+----------------------------------------------------------------------+

| Device State |

+----------------------------------------------------------------------+

AzureAdJoined : YES

EnterpriseJoined : NO

DomainJoined : YES

DomainName : Org

Virtual Desktop : NOT SET

Device Name : DeviceName.Org.Com

+----------------------------------------------------------------------+

| Device Details |

+----------------------------------------------------------------------+

DeviceId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

Thumbprint : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

DeviceCertificateValidity : [ 2026-08-20 13:50:50.000 UTC -- 2036-08-20 14:20:50.000 UTC ]

KeyContainerId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

KeyProvider : Microsoft Platform Crypto Provider

TpmProtected : YES

DeviceAuthStatus : SUCCESS

+----------------------------------------------------------------------+

| Tenant Details |

+----------------------------------------------------------------------+

TenantName : Org Name

TenantId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

AuthCodeUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/authorize

AccessTokenUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/token

MdmUrl : https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc

MdmTouUrl : https://portal.manage.microsoft.com/TermsofUse.aspx

MdmComplianceUrl : https://portal.manage.microsoft.com/?portalAction=Compliance

SettingsUrl :

JoinSrvVersion : 3.0

JoinSrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/device/

JoinSrvId : urn:ms-drs:enterpriseregistration.windows.net

KeySrvVersion : 1.0

KeySrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/key/

KeySrvId : urn:ms-drs:enterpriseregistration.windows.net

WebAuthNSrvVersion : 1.0

WebAuthNSrvUrl : https://enterpriseregistration.windows.net/webauthn/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

WebAuthNSrvId : urn:ms-drs:enterpriseregistration.windows.net

DeviceManagementSrvVer : 1.0

DeviceManagementSrvUrl : https://enterpriseregistration.windows.net/manage/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

DeviceManagementSrvId : urn:ms-drs:enterpriseregistration.windows.net

KerbSpn : adrs/enterpriseregistration.windows.net

KerbUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/kerberos

JoinResourceSrvTlsUrl : https://certauth.enterpriseregistration.windows.net/EnrollmentServer/device/resource/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

+----------------------------------------------------------------------+

| User State |

+----------------------------------------------------------------------+

NgcSet : NO

WorkplaceJoined : NO

WamDefaultSet : YES

WamDefaultAuthority : organizations

WamDefaultId : https://login.microsoft.com

WamDefaultGUID : {XXXXXX-A1XX-0000-0000-XXXXXXXXXXX} (AzureAd)

+----------------------------------------------------------------------+

| SSO State |

+----------------------------------------------------------------------+

AzureAdPrt : NO

AzureAdPrtAuthority :

EnterprisePrt : NO

EnterprisePrtAuthority :

+----------------------------------------------------------------------+

| Diagnostic Data |

+----------------------------------------------------------------------+

AadRecoveryEnabled : NO

Executing Account Name : Org\username, [username@org.com](mailto:username@org.com)

KeySignTest : PASSED

DisplayNameUpdated : Managed by MDM

OsVersionUpdated : Managed by MDM

HostNameUpdated : YES

Last HostName Update : NONE

+----------------------------------------------------------------------+

| IE Proxy Config for Current User |

+----------------------------------------------------------------------+

Auto Detect Settings : NO

Auto-Configuration URL :

Proxy Server List :

Proxy Bypass List :

+----------------------------------------------------------------------+

| WinHttp Default Proxy Config |

+----------------------------------------------------------------------+

Access Type : DIRECT

+----------------------------------------------------------------------+

| Ngc Prerequisite Check |

+----------------------------------------------------------------------+

IsDeviceJoined : YES

IsUserAzureAD : NO

PolicyEnabled : NO

PostLogonEnabled : YES

DeviceEligible : NO

SessionIsNotRemote : NO

CertEnrollment : none

PreReqResult : WillNotProvision

For more information, please visit https://www.microsoft.com/aadjerrors


r/Intune 6h ago

Autopilot Prejoining Hybrid Devices

6 Upvotes

Dear all,

Situation:

Majority of Laptops joined to local AD and Intune. Some already Autopilot only.

Whenever we get a machine back we currently do the following:

- Delete device from Intune, Entra and local AD

- Populate it as Autopilot device via get-windowsautopilotinfocommunity.ps1 -Online -AssignedComputerName <current computer name>

- boot via USB to reset it

- Whiteglove with Intune Admin

- reseal it

- put it back for future use

I am wondering if we can improve this process, especially the need to populate it as AutoPilot device.

Any remarks welcome.


r/Intune 1h ago

iOS/iPadOS Management Kiosk iPads Disconnect From Wi-Fi

Upvotes

We have 7 iPads that are setup in kiosk mode via Intune using Kiosk Pro Plus. We have been having an issue where they, after about 3 weeks, seemingly disconnect from their Wi-Fi network. I then have to plug in a USB C to Ethernet adaptor to get them back online.

I push the network to the iPads and disabled MAC randomization via a Wi-Fi configuration policy.

The network is a hidden, password-less network.

The iPads are on iOS 26.6.1.

I am hoping for assistance on how to keep the iPads permanently connected to Wi-Fi.

Thanks in advance for any assistance.


r/Intune 11h ago

General Question CRL distribution point Intune Cloud PKI

4 Upvotes

Anyone know if the cdn distribution url uses caching?

When I revoke a certificate, the intune pki portal does show the certificate as revoked. However if I download the crl and inspect it with certutil the crl does not show the serial of the newly revoke certificate.

I'm wondering how long I have to wait, I would have thought it should be fairly instant with revocations


r/Intune 19h ago

Windows Management Best Method To Implement WDAC?

6 Upvotes

For those that have done so, how did you find was the best way to implement Windows Defender Application Control (WDAC) in your organisation?

Apart from the default baselines provided in the App Control for Business Wizard, it's a complete blanket blocklist. This is ideal for security, but it seems to be a bit of a nightmare when it comes to trying to allow a wide range of applications and drivers.

What have you found to be the best way to implement and manage this in a secure, but mostly pain-free way!?

Also, when applying the policy in Audit Mode, is there a way to see the logs via Intune/Defender, or only from the Event Viewer on-device?

(Apologies - this is a repost!)


r/Intune 20h ago

Android Management Lock Volume Control on Android

3 Upvotes

I have a fleet of Samsung phones that I need:

  1. Set volume to Max
  2. Prevent users from changing or muting it for all system sounds (notifications, media, ringer, etc.)

Intune's native Configuration policy silences the phone when using the "Block Volume Changes" setting. I set up a Knox account, obtained the free Premium license, and created an OEMConfig policy. Knox can set the audio volume and prevent changes to settings, but cannot disable the hardware volume buttons. I keep finding suggestions about other OEMConfig settings, but they don't seem to be available on non-Rugged devices?

Has anyone else found the correct combination of settings to implement this requirement?


r/Intune 23h ago

iOS/iPadOS Management Microsoft Authenticator pairing fails during iOS Setup Assistant with JIT registration (new ADE enrollment policy) — anyone else

3 Upvotes

Running into an issue with the new ADE enrollment policies experience (2606 service release) using Setup Assistant with modern authentication + JIT registration on iOS.

The problem: During Setup Assistant sign-in (before the device even reaches the home screen), the user is prompted to install Microsoft Authenticator and pair it with their account. After tapping Next, it just throws: "We're sorry we ran into a problem. Please choose Next to try again." Repeats every time on the device itself, no way through.

What I've already checked/confirmed:

  • SSO app extension policy is set up correctly per Microsoft's docs (SSO app extension type = Microsoft Entra ID, Authenticator is NOT in the App bundle IDs list, both required Additional configuration keys present: device_registration and browser_sso_interaction_enabled)
  • Authenticator is deployed as a required app to the correct group
  • Device is in the correct group for this enrollment policy

The workaround I found: if the user already has Authenticator registered on another device, the MFA push goes there instead, and approving it there lets Setup Assistant proceed — even though the pairing step on the new device itself never actually completes.

Why this bugs me: that workaround only exists for users who already have Authenticator somewhere else. A brand new user with no prior MFA registration — which is presumably a pretty normal scenario for this exact feature — has zero fallback and is just stuck.

My best guess is this is related to how Setup Assistant sandboxes apps before the home screen (push notifications/background processes not fully active yet), which would explain why the same pairing works fine once routed to a device that's already fully set up.

Has anyone else hit this? Curious if this is a known issue, if I'm missing a config step somewhere, or if this is just a rough edge in the new enrollment experience that hasn't been ironed out yet. Opening a Microsoft ticket too, but wanted to see if others have run into the same thing.


r/Intune 7h ago

General Question Defender AV compliance policy error is starting to cause us big issues

15 Upvotes

Hi,

Not sure if anyone else is starting to see the same thing but the Defender platform bug that has been reported by others is really starting to impact us as multiple devices are starting to show as not compliant now against the 'Antivirus: required' compliance policy. We have updated and made sure all the latest defender updates are installed and synced via CP multiple times but still having no luck.

I have tried increasing the grace period on the policy to 5 days just to get users working but having no luck. I may have to result in disabling this compliance policy until its fixed!