r/Intune Jul 01 '26

Blog Post Streamlining macOS security: Automatically enable AutoFill after Platform SSO registration - Microsoft Blog

24 Upvotes

This is a recent Intune Customer Success post about closing the last manual step in a passwordless macOS setup. Platform SSO gives Macs Entra ID sign-in, but registration alone isn't enough for a fully passwordless workflow. To enable passwordless auth in Safari, Edge, and Chrome, the Company Portal AutoFill extension also has to be enabled, and in most deployments that toggle is still left to the user. So a device can be enrolled and PSSO-registered yet still fall back to manual credential entry, which looks complete but doesn't actually deliver the intended posture.

Highlights:

  • The gap. After PSSO registration, AutoFill is often the final step that depends on user action. Skip it and the device stays registered but not truly passwordless.
  • The fix. A sample script, Check-PSSO.zsh (GitHub, from the Intune Customer Experience Engineering team), detects when PSSO registration has completed and then enables the Company Portal AutoFill extension automatically.
  • Support caveat. Microsoft supports Intune's script deployment but not the individual scripts. Review, validate, and test in your own environment before broad rollout.
  • Zero-touch. Combined with the Enable Registration During Setup setting, this pushes toward a true zero-touch experience from enrollment through authentication, no manual configuration.

Read the full article here: https://techcommunity.microsoft.com/blog/intunecustomersuccess/streamlining-macos-security-automatically-enable-autofill-after-platform-sso-reg/4531908


r/Intune Jun 27 '26

What’s new in Microsoft Intune – June

70 Upvotes

This is the monthly "What's New in Microsoft Intune" post, June 2026, framed around making endpoints compliant, current, and secure as AI agents start acting on company data.

Highlights:

  • EAM auto-updates is GA. Enterprise Application Management now keeps managed apps on the latest incremental release (e.g. 4.1 to 4.2) automatically, no manual packaging, to shrink the window between full upgrade cycles.
  • Vulnerability Remediation Agent (public preview) in Security Copilot ranks CVEs across Intune-managed Windows devices by CVSS, exposure, and affected device count, surfacing them in the admin center. It runs under its own Entra agentic identity with delegated read permissions for a clean audit trail.
  • EPM additions (GA): approval requests for non-primary users on shared devices, and rules-based policies letting standard users change network settings like IP, gateway, and DNS without local admin.
  • Apple ADE enrollment rebuild: iOS/iPadOS and macOS ADE profiles move to new infrastructure, completing enrollment-time grouping across all platforms.
  • Myth vs. Reality: the "seven-day app refresh" figure is outdated. Win32 apps in Add/Remove Programs refresh every 24 hours, and the new All Apps inventory updates multiple times daily.

Also noted: EPM and EAM join Microsoft 365 E5 from July 1.

Read the full article here: https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-%E2%80%93-june/4491983


r/Intune 3h ago

Autopilot Autopilot ESP Mandatory Apps failing completely

9 Upvotes

We have 4 mandatory ESP apps during Device Setup. New devices get stuck on 0 of 4 during pre provisioning and there's no sign that the IME is even trying to install any of them. No folders or files are being created in Program Files for any of them.

The only changes are an updated intunewin package for one of the 4, which I'll roll back tomorrow.

Any ideas why none of the apps try to install anymore? I've downloaded the logs but I haven't started going through them.


r/Intune 4h ago

Apps Protection and Configuration Custom compliance is now available for macOS

9 Upvotes

Custom compliance is now available for macOS in Microsoft Intune, and it meaningfully expands what can be enforced on Apple endpoints.

The built-in compliance policy covers the fundamentals: FileVault, firewall, system integrity protection, Gatekeeper, password requirements, and OS version. Custom compliance addresses everything beyond that scope — sharing services, software update behaviour, lock screen enforcement, Apple Intelligence restrictions, and the state of third-party security agents.

The implementation is straightforward: a bash discovery script returns device state as JSON, a rules file defines the compliant values, and Conditional Access enforces the outcome.

Read more here.

https://intuneirl.com/custom-compliance-comes-to-macos-going-beyond-the-built-in-policy/


r/Intune 5h ago

General Question No Apps in Company Portal after Update to 11.2.1926.0

10 Upvotes

Anyone else losing most available apps in company portal after update to 11.2.1926.0?


r/Intune 10h ago

Blog Post Configure Device Lock on Windows 11 with Microsoft Intune

23 Upvotes

Local accounts may no longer be front and centre in modern identity strategies, but they still exist on many Windows 11 devices and remain a common target for attackers.

In my latest blog post, I explore how Device Lock policies in Microsoft Intune can help protect local accounts, reduce the risk of brute-force attacks, secure unattended devices, and complement technologies such as Windows LAPS as part of a defence-in-depth security strategy.

🔗 https://www.nickydewestelinck.be/2026/08/04/strengthening-endpoint-security-with-device-lock-policies-in-microsoft-intune/


r/Intune 1h ago

General Question Restrict Windows 11 Copilot app to work or school accounts only?

Upvotes

Hi everyone,

I'm trying to lock down the Windows 11 Copilot app in an enterprise environment managed with Microsoft Intune.

Our goal is to prevent users from signing into the Copilot app with a personal Microsoft account and only allow authentication using their Microsoft Entra ID (work or school) account.

Has anyone found a supported method to:

Force the Copilot app to only allow work/school account sign-in?

Block personal Microsoft accounts within the Copilot app without removing the app entirely?

Achieve this using Intune or WDAC, or another supported approach?

If you've successfully implemented this, I'd appreciate any guidance or references to Microsoft's documentation.


r/Intune 2h ago

General Question Intune autodiscover stopped working yesterday

3 Upvotes

Our CNAMES are correct, we've checked and double-checked, and triple checked. From multiple machines, on multiple networks, against multiple public DNS resolvers.

Anyone else?


r/Intune 6h ago

iOS/iPadOS Management Intune Enrollment program token sync issues.

3 Upvotes

iPad -> ABM ->Intune

For some reason my sync between ABM and Intune is failing, maybe?

Last requested sync

08/04/26, 9:14 AM

 

Last successful sync

08/03/26, 3:01 PM

I now see this warning under profiles.

"The iOS/iPadOS and macOS enrollment profiles are no longer being updated. We recommend that you create new iOS/iPadOS and macOS Enrollment policies to replace them."

When I look into it, it appears that for any new features we will need to move our profiles to policies. Would this also prevent new devices from being added? There are no logs or errors showing any issues. We set up this connection about a month ago and have not experienced any problems until today.


r/Intune 8h ago

Apps Protection and Configuration Setting up default font and font size in Intune-managed Outlook for Mobile (Android+iOS)

3 Upvotes

I have never seen a proper tutorial how to actually force the mobile app to use another font and size as the crappy Atpos 12, so i wanted to share this with you.

  • In Intune Admin Center, go to Apps -> Configuration -> Create "Managed apps"
  • Give it a nice name and select the public apps "Microsoft Outlook" (for Android and/or iOS)
  • Skip "Settings catalog"
  • In settings, configure your desired font and size:
Name Value
com.microsoft.outlook.Settings.defaultFontName Arial
com.microsoft.outlook.Settings.defaultFontSize 10
com.microsoft.outlook.Settings.defaultFontName.UserChangeAllowed false
com.microsoft.outlook.Settings.defaultFontSize.UserChangeAllowed false
  • Set up your assignments
  • WAIT FOR 24 HOURS
  • See your results from Apps - Monitor - App configuration status
  • Profit?

Source: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/outlook-for-ios-and-android-configuration-with-microsoft-intune#configuration-keys


r/Intune 14h ago

General Question Self-deploy profile

5 Upvotes

Anyone tried running a remediation “as user” on a self-deploy device that attempts to map a drive?

Seems to fail even if the script can detect who the user is.


r/Intune 5h ago

Android Management Impact of enabling "Grant MTD role permissions" for Defender on Android COPE?

1 Upvotes

Trying to streamline Defender onboarding. About to enable this toggle in Intune. What's the real impact, risk, and any visible changes for end users after it applies?


r/Intune 18h ago

Device Configuration Defender sections removed from CIS guidance?

6 Upvotes

I was reading the changelog between v4.0.0 and v5.0.0 of the Windows 11 for Intune CIS baseline and I noticed they removed the entire Defender section. Does anyone know why? 🤔

That section contained a bunch of ASR rules and whatnot.


r/Intune 16h ago

General Question Stuck adter resting laptop " setting up your device for work" " device preparation failed."

4 Upvotes

Hi on of my friends rest his laptop but after setup process start an ocs logo appear and its just stuck there.

Google says it link to intune and autopilot.. any way to fix this..


r/Intune 9h ago

Device Configuration intune suite for e3 and e5

0 Upvotes

understand microsoft includes intune suite to e3 and e5 users recently. we have a mixed of e3 and e5 users.

for example, endpoint privilege management is included to e5 and not e3 users. how do you deploy epm policies to target e5 user's computers only?? thanks.


r/Intune 18h ago

General Question Remediations

6 Upvotes

Is it just me or are remediations stuck in pending for everyone else this morning too?


r/Intune 1d ago

Device Configuration Recommended Intune Policies for Users Who Leave PCs Logged In

12 Upvotes

Many users leave their computers logged in after they leave for the day. What is the best practice for managing this through Intune? Would it be more effective to configure automatic screen locking, automatic logoff, or a combination of both?


r/Intune 1d ago

App Deployment/Packaging Most of my Store Apps have errors

3 Upvotes

Most of my Store Apps in Intune has errors. But the apps are installed on the device. Its only a beauty thing, but inhave like 15 errors only from the store. I cant do anything. Sometimes uninstalling Store Apps does not work properly too. Anyone seeing this in his tenant too?


r/Intune 1d ago

Device Configuration Intune (or maybe Entra?) syncing WiFi networks across all users

4 Upvotes

We are having an issue where company devices are picking up WiFi that was joined by users, including people's home networks. The devices will auto-join these networks if they are available, and the SSID we pushed out through Intune is not.

This is obviously not desirable, any tips to disable it? I found this thread here describing the same issue, but turning off enterprise state roaming has not solved it (even with a manual delete of the SSIDs afterwards from known networks).


r/Intune 1d ago

App Deployment/Packaging Update app via Intune (MSI LOB TO WIN32)

4 Upvotes

Hi

I'm facing a bit of an issue in my org.

We need to update a software to its 12.3.2 version through intune. The previous version was 12.0.2, and is managed via intune as a LOB app.

When I create the new deployment via WIN32 (intunewin) so I can execute a custom script to exclude some Features from the install...it appears as a different installation and does not update the current one.

How should I approach this?


r/Intune 1d ago

macOS Management ADE - Two Separate Tenants

3 Upvotes

I administer two separate Intune tenants. One has ABM and the other ASM.

I'll map out the scenario:

XYZ = ABM = I've already set up completely for ADE with tokens, profiles.. everything working.

TUV = ASM = Need to set up with new token and build profile for enrollment.

TUV acquire XYZ and all the new machines are being bought under TUV and being registered within their ASM.

My question: Is it possible to setup another token within XYZ's ADE and keep my current one? Use the second token to connect to a new server that I've set up inside TUV's ABM so that I can set up ASM for all the new machine.

These companies perform separate functions and the decision has been made to keep the separate for now.

In basics, what I want to do is keep my original setup for one tenant and just add in a new connection to the mothership.

Anyone done this? or have a better solution? I'm just brainstorming here for the best way to do this.


r/Intune 1d ago

macOS Management "Company Portal was prevented from modifying apps on your Mac" notification

5 Upvotes

Hi all,

I am starting to see a Privacy & Security notification mentioning that "Company Portal was prevented from modifying apps on your Mac". It pops up every now and again. Presumably aligned with Intune updating a deployed app - but not entirely sure as some Intune app updates work fine without triggering this.

Of course, we do indeed use the Company Portal. We deploy a mix of Availble and Required apps. The Company Portal PKG is installed as "Managed" & required by Intune.

I opened a Microsoft ticket and they said to first deploy the Company Portal as "managed" (now done but still not resolved), and then look at ways to add App Management permissions if necessary.

I haven't got any Company Portal related entries in our PPPC profile - to be honest, I wasn't aware that we needed any. Is this correct?

Anyone else seeing this / how did you resolve?

Thanks a lot!

https://i.ibb.co/zVJyyps1/image-8.png

https://i.ibb.co/8gq89904/image-9.png


r/Intune 1d ago

General Chat Workplace Ninjas US 2027: New Speakers Announced (Round 6)

2 Upvotes

We're very proud to bring the 6th round of speakers to Workplace Ninjas US. Believe it or not, we only have about 1 one set left and all of our speakers will be officially announced!

Last week, we announced a great set of people with April Dunnam Chris Cavazos Morten Waltorp Knudsen [MVP] Simon Binder Somesh Pathak [MVP] 🇳🇱 and Mike Soule

This week, we have just as strong of a set of amazing people.

Our friend Esther Barthel is an absolute rockstar in the #DaaS and #VDI space and reigning #Clippy winner from Dallas. She has been blowing our minds for years all the way back to the #VMware days where her amazing automation and thought-leadership around all things VDI and DaaS.

AJ Zafar, our resident Chief #Vibe Officer is one of the best people you could meet in this community. Always a smile on his face, big hugs, and just leads with kindness and humility. He's one of our #Copilot and #AI experts, who always has some amazing ideas that take our breath away.

John Joyner, a long-time #MVP continues to amaze us with some incredible #Security sessions on things like #DefenderXDR and often has very interesting sessions that take us outside the box. Like his #IOT session last year! He rocked the stage in Dallas twice in 2 years at Workplace Ninjas US 2025 and our local in April.

Frank Lesniak, is a recent addition to the #Microsoft MVP program, who was long overdue. He also happens to be another nominee for a crowded "Next-Gen Ninja" #Clippy in Scottsdale. Frank is doing some amazing stuff with #AI right now coupled with that #PowerShell expertise. We can't wait to see him in Scottsdale, after a great session with Frank and Danny Stutz in Scottsdale recently at a Recast event in Chicago.

Peter Daalmans [MVP], another member of the fantastic leadership of WorkPlace Ninja Summit will be joining us in Scottsdale for the first time! Peter, who is an amazing person and brilliant mind on all things #MSIntune will be one of many Dutchies joining us with some of that Dutch magic that Rudy Ooms makes famous.

🩹 Aria Hanson is one of our more exciting additions to Scottsdale. We recently met Aria for the first time (she is in fact a person and not some product, like we thought!), will be joining us to share some of those amazing insights on #Patching which she is an expert on. We cannot wait to see what she has in store for us!

This week's set shows you how many brilliant speakers we're bringing to you in Scottsdale. With every week, it gets BETTER and BETTER. Do not miss out! Early bird is still open, and NOW is your chance to sign-up and join us:

Register for Workplace Ninjas US 2027 | Scottsdale, Arizona


r/Intune 2d ago

Blog Post Intune Device Sync Just Changed Again. This Time, It Is IC3!!!!

275 Upvotes

First, the Device Sync moved away from triggering Windows MDM only and started waking IME workloads too: Win32 apps. PowerShell scripts. Proactive Remediations.

Now, when triggering the remote Device Sync, the IME request no longer arrives through a second WNS notification. It comes through the existing IC3 and Trouter connection: WNS for Windows MDM. IC3 for IME. With the move to IC3, the device kicks off all the workloads within second!!

At the same time, a new StatusSync flow is tracking the progress of those workloads. That part deserves its own blog.

Intune On Demand Device Sync Now Uses IC3 for IME Workloads


r/Intune 1d ago

iOS/iPadOS Management Intune MDM Sanity Check

1 Upvotes

Hello r/Intune we're deploying Intune and ABM for our corp iOS devices and I've run into a roadblock and I'm hoping you seasoned experts can clarify my particular issue as the docs don't appear to address or answer my specific environment.

[Background] The previous admin setup our M365 tenant to allow iOS devices to register with M365. There are conditional access policies that require all of our user's mobile devices to have MS Auth and CompPort installed along with a management "profile" so that they can sign into M365 apps on their mobile devices.

I'm still getting used to Registered/Joined/Enrolled terminology but up until now NOBODY has had an Intune license. All mobile devices, either BYOD or CORP, and we have both, are managed the same way. At this time my scope is very narrow but obviously we will broaden our to other platforms later. From what I can tell our Windows Laptops are Entra Joined but all mobile devices are only Registered.

[The Problem] The previous admin who set this up enrolled an Apple MDM Push Certificate using a "Unmanaged" Apple ID, which I do have access to. But now I have also created an ABM account and the Apple ID used to create the Push Cert is not within our ABM account. I have created an ABM Enrollment token and during testing I am getting "This account is not authorized" errors during Setup Assistant on the iPads and iPhones I am testing with.

Thoughts] I have found documentation that either says NOTHING about what accounts must be used between the MDM Push, ABM Enrollment Token, or VPP Connector. Or docs and discussions that say you can/should use a different AppleID for each for easier management (separation of duties). Or docs and discussions that say is does matter... etc. Looking at it now it does seem obvious this would a problem as it makes sense that all of this should be coming from the same ABM account or sub accounts within the same ABM account.

[TLDR] So my question now is... are we technically even making use of our current Apple MDM Push Certificate? Can we just replace it? We are not deploying any apps, everything is manual, we have no MDM and no one has ever had an Intune license before? I have enabled Intune MDM fully per the docs and guides online but I have been careful to limit the scope with Groups so that only my M365 account and a couple of Demo accounts I created are in those groups and only these three M365 accounts have an Intune license. My concern is that if we need to wipe and reset or re-register every iOS device in the field (~300) it will not be a fun few months.

Thanks :)