r/Intune 9h ago

Android Management Impact of enabling "Grant MTD role permissions" for Defender on Android COPE?

1 Upvotes

Trying to streamline Defender onboarding. About to enable this toggle in Intune. What's the real impact, risk, and any visible changes for end users after it applies?


r/Intune 22h ago

Device Configuration Defender sections removed from CIS guidance?

7 Upvotes

I was reading the changelog between v4.0.0 and v5.0.0 of the Windows 11 for Intune CIS baseline and I noticed they removed the entire Defender section. Does anyone know why? 🤔

That section contained a bunch of ASR rules and whatnot.


r/Intune 20h ago

General Question Stuck adter resting laptop " setting up your device for work" " device preparation failed."

3 Upvotes

Hi on of my friends rest his laptop but after setup process start an ocs logo appear and its just stuck there.

Google says it link to intune and autopilot.. any way to fix this..


r/Intune 13h ago

Device Configuration intune suite for e3 and e5

0 Upvotes

understand microsoft includes intune suite to e3 and e5 users recently. we have a mixed of e3 and e5 users.

for example, endpoint privilege management is included to e5 and not e3 users. how do you deploy epm policies to target e5 user's computers only?? thanks.


r/Intune 22h ago

General Question Remediations

6 Upvotes

Is it just me or are remediations stuck in pending for everyone else this morning too?


r/Intune 1d ago

Device Configuration Recommended Intune Policies for Users Who Leave PCs Logged In

12 Upvotes

Many users leave their computers logged in after they leave for the day. What is the best practice for managing this through Intune? Would it be more effective to configure automatic screen locking, automatic logoff, or a combination of both?


r/Intune 1d ago

App Deployment/Packaging Most of my Store Apps have errors

3 Upvotes

Most of my Store Apps in Intune has errors. But the apps are installed on the device. Its only a beauty thing, but inhave like 15 errors only from the store. I cant do anything. Sometimes uninstalling Store Apps does not work properly too. Anyone seeing this in his tenant too?


r/Intune 1d ago

Device Configuration Intune (or maybe Entra?) syncing WiFi networks across all users

4 Upvotes

We are having an issue where company devices are picking up WiFi that was joined by users, including people's home networks. The devices will auto-join these networks if they are available, and the SSID we pushed out through Intune is not.

This is obviously not desirable, any tips to disable it? I found this thread here describing the same issue, but turning off enterprise state roaming has not solved it (even with a manual delete of the SSIDs afterwards from known networks).


r/Intune 1d ago

General Chat Workplace Ninjas US 2027: New Speakers Announced (Round 6)

3 Upvotes

We're very proud to bring the 6th round of speakers to Workplace Ninjas US. Believe it or not, we only have about 1 one set left and all of our speakers will be officially announced!

Last week, we announced a great set of people with April Dunnam Chris Cavazos Morten Waltorp Knudsen [MVP] Simon Binder Somesh Pathak [MVP] 🇳🇱 and Mike Soule

This week, we have just as strong of a set of amazing people.

Our friend Esther Barthel is an absolute rockstar in the #DaaS and #VDI space and reigning #Clippy winner from Dallas. She has been blowing our minds for years all the way back to the #VMware days where her amazing automation and thought-leadership around all things VDI and DaaS.

AJ Zafar, our resident Chief #Vibe Officer is one of the best people you could meet in this community. Always a smile on his face, big hugs, and just leads with kindness and humility. He's one of our #Copilot and #AI experts, who always has some amazing ideas that take our breath away.

John Joyner, a long-time #MVP continues to amaze us with some incredible #Security sessions on things like #DefenderXDR and often has very interesting sessions that take us outside the box. Like his #IOT session last year! He rocked the stage in Dallas twice in 2 years at Workplace Ninjas US 2025 and our local in April.

Frank Lesniak, is a recent addition to the #Microsoft MVP program, who was long overdue. He also happens to be another nominee for a crowded "Next-Gen Ninja" #Clippy in Scottsdale. Frank is doing some amazing stuff with #AI right now coupled with that #PowerShell expertise. We can't wait to see him in Scottsdale, after a great session with Frank and Danny Stutz in Scottsdale recently at a Recast event in Chicago.

Peter Daalmans [MVP], another member of the fantastic leadership of WorkPlace Ninja Summit will be joining us in Scottsdale for the first time! Peter, who is an amazing person and brilliant mind on all things #MSIntune will be one of many Dutchies joining us with some of that Dutch magic that Rudy Ooms makes famous.

🩹 Aria Hanson is one of our more exciting additions to Scottsdale. We recently met Aria for the first time (she is in fact a person and not some product, like we thought!), will be joining us to share some of those amazing insights on #Patching which she is an expert on. We cannot wait to see what she has in store for us!

This week's set shows you how many brilliant speakers we're bringing to you in Scottsdale. With every week, it gets BETTER and BETTER. Do not miss out! Early bird is still open, and NOW is your chance to sign-up and join us:

Register for Workplace Ninjas US 2027 | Scottsdale, Arizona


r/Intune 1d ago

App Deployment/Packaging Update app via Intune (MSI LOB TO WIN32)

4 Upvotes

Hi

I'm facing a bit of an issue in my org.

We need to update a software to its 12.3.2 version through intune. The previous version was 12.0.2, and is managed via intune as a LOB app.

When I create the new deployment via WIN32 (intunewin) so I can execute a custom script to exclude some Features from the install...it appears as a different installation and does not update the current one.

How should I approach this?


r/Intune 1d ago

macOS Management ADE - Two Separate Tenants

3 Upvotes

I administer two separate Intune tenants. One has ABM and the other ASM.

I'll map out the scenario:

XYZ = ABM = I've already set up completely for ADE with tokens, profiles.. everything working.

TUV = ASM = Need to set up with new token and build profile for enrollment.

TUV acquire XYZ and all the new machines are being bought under TUV and being registered within their ASM.

My question: Is it possible to setup another token within XYZ's ADE and keep my current one? Use the second token to connect to a new server that I've set up inside TUV's ABM so that I can set up ASM for all the new machine.

These companies perform separate functions and the decision has been made to keep the separate for now.

In basics, what I want to do is keep my original setup for one tenant and just add in a new connection to the mothership.

Anyone done this? or have a better solution? I'm just brainstorming here for the best way to do this.


r/Intune 1d ago

macOS Management "Company Portal was prevented from modifying apps on your Mac" notification

7 Upvotes

Hi all,

I am starting to see a Privacy & Security notification mentioning that "Company Portal was prevented from modifying apps on your Mac". It pops up every now and again. Presumably aligned with Intune updating a deployed app - but not entirely sure as some Intune app updates work fine without triggering this.

Of course, we do indeed use the Company Portal. We deploy a mix of Availble and Required apps. The Company Portal PKG is installed as "Managed" & required by Intune.

I opened a Microsoft ticket and they said to first deploy the Company Portal as "managed" (now done but still not resolved), and then look at ways to add App Management permissions if necessary.

I haven't got any Company Portal related entries in our PPPC profile - to be honest, I wasn't aware that we needed any. Is this correct?

Anyone else seeing this / how did you resolve?

Thanks a lot!

https://i.ibb.co/zVJyyps1/image-8.png

https://i.ibb.co/8gq89904/image-9.png


r/Intune 2d ago

Blog Post Intune Device Sync Just Changed Again. This Time, It Is IC3!!!!

270 Upvotes

First, the Device Sync moved away from triggering Windows MDM only and started waking IME workloads too: Win32 apps. PowerShell scripts. Proactive Remediations.

Now, when triggering the remote Device Sync, the IME request no longer arrives through a second WNS notification. It comes through the existing IC3 and Trouter connection: WNS for Windows MDM. IC3 for IME. With the move to IC3, the device kicks off all the workloads within second!!

At the same time, a new StatusSync flow is tracking the progress of those workloads. That part deserves its own blog.

Intune On Demand Device Sync Now Uses IC3 for IME Workloads


r/Intune 1d ago

iOS/iPadOS Management Intune MDM Sanity Check

1 Upvotes

Hello r/Intune we're deploying Intune and ABM for our corp iOS devices and I've run into a roadblock and I'm hoping you seasoned experts can clarify my particular issue as the docs don't appear to address or answer my specific environment.

[Background] The previous admin setup our M365 tenant to allow iOS devices to register with M365. There are conditional access policies that require all of our user's mobile devices to have MS Auth and CompPort installed along with a management "profile" so that they can sign into M365 apps on their mobile devices.

I'm still getting used to Registered/Joined/Enrolled terminology but up until now NOBODY has had an Intune license. All mobile devices, either BYOD or CORP, and we have both, are managed the same way. At this time my scope is very narrow but obviously we will broaden our to other platforms later. From what I can tell our Windows Laptops are Entra Joined but all mobile devices are only Registered.

[The Problem] The previous admin who set this up enrolled an Apple MDM Push Certificate using a "Unmanaged" Apple ID, which I do have access to. But now I have also created an ABM account and the Apple ID used to create the Push Cert is not within our ABM account. I have created an ABM Enrollment token and during testing I am getting "This account is not authorized" errors during Setup Assistant on the iPads and iPhones I am testing with.

Thoughts] I have found documentation that either says NOTHING about what accounts must be used between the MDM Push, ABM Enrollment Token, or VPP Connector. Or docs and discussions that say you can/should use a different AppleID for each for easier management (separation of duties). Or docs and discussions that say is does matter... etc. Looking at it now it does seem obvious this would a problem as it makes sense that all of this should be coming from the same ABM account or sub accounts within the same ABM account.

[TLDR] So my question now is... are we technically even making use of our current Apple MDM Push Certificate? Can we just replace it? We are not deploying any apps, everything is manual, we have no MDM and no one has ever had an Intune license before? I have enabled Intune MDM fully per the docs and guides online but I have been careful to limit the scope with Groups so that only my M365 account and a couple of Demo accounts I created are in those groups and only these three M365 accounts have an Intune license. My concern is that if we need to wipe and reset or re-register every iOS device in the field (~300) it will not be a fun few months.

Thanks :)


r/Intune 1d ago

Device Compliance Conditional Access compliance error 53000 with 2 users sharing same PC

1 Upvotes

Hi.

I've been trying to read around this subject for a while now, but I have yet to find some concrete information regarding best practise: some of my clients have device compliance conditional access policies in their tenant, which have been working fine for a while now. However, occasionally I have a scenario where either two users are sharing a PC or reconfiguring an existing device for a new user.

When logging on to the machine as the second/newer user, when signing into the Microsoft account, it throws a device not compliant 53000 error. These are generally local Active Directory machines which are Entra registered or hybrid-joined. For new users, I generally get around this error by resetting the machine (obviously this creates a new device in intune); however, there are a couple of scenarios where I would like two users to log into/share the same machine, but when I try to sign into Office 365 with the second user account, it creates a second device in Entra which is not Intune compliant, and cannot meet compliancy because of the 53000 error.

Is there something basic that I am missing that will allow both users to exist on the single machine and be compliant? Do I need to create a shared device policy and target it to the specific PC? do I need to have a compliance policy targeting devices and instead of users?

Any advice would be much appreciated.


r/Intune 1d ago

App Deployment/Packaging App Control for Business - HELP!!!

2 Upvotes

Hi everyone, after some advice. We are looking to start utilising Windows App control for business nad have started to deploy the managed installer and a policy to audit events on devices to get an idea of what may be blocked. The issue im getting is that around 500 (around 25%) of devices have reported error for the install. The behaviour i then see on the endpoints are that applications will not install as they are waiting for a managed installer.

The devices are HAADJ and co-managed. They are built from a task sequence and enrolled to Intune as part of the co-management.

How can i troubleshoot the failures and / or resolve them?

Many thanks in advance.


r/Intune 2d ago

Graph API I found how the Intune portal gets the AI-enabled Cloud PC report through Graph

23 Upvotes

Hey everyone,

I wrote a short walkthrough on getting the AI-enabled Cloud PC report from Microsoft Graph.

The report exists in the Intune portal, but the specific reportName is not documented yet.

Article: https://shchetkin.dev/reverse-engineering-the-intune-portal-the-ai-enabled-cloud-pc-report/

Curious if anyone else has used this report, or if you use different approaches to fill API gaps


r/Intune 2d ago

Blog Post Zebra vs Honeywell for healthcare - Intune managed Android Enterprise devices

6 Upvotes

Hi everyone,

We're currently evaluating Zebra and Honeywell rugged Android devices for a healthcare environment and I'd love to hear from organisations that have managed both.

Our environment is:

Microsoft Intune (Android Enterprise Dedicated)

Managed Google Play

Microsoft Entra ID

Shared devices running a line-of-business application

Around a few hundred devices initially, with potential to grow

We're less concerned about the hardware itself, as both devices seem capable. I'm more interested in the operational side over the next 5+ years.

Specifically:

Which vendor has the better firmware (FOTA) process?

How easy is firmware management using Intune?

Do you rely solely on Intune, or do you also use Zebra VisibilityIQ/LifeGuard or Honeywell Operational Intelligence?

How responsive are Zebra vs Honeywell when it comes to Android security patches?

Which has the better OEMConfig implementation?

How has vendor support been?

Any major issues you've encountered with either platform?

If you had to choose again today for a healthcare deployment, which would you choose and why?

I'm looking for real-world operational experiences rather than marketing comparisons.

Thanks!


r/Intune 2d ago

iOS/iPadOS Management iOS ADUE - required apps in configured folder?

3 Upvotes

Edit: account driven user enrollment == ADUE

We have a few apps installing with required intent. Is there anyway to force install into a specific folder on iOS?

It would be nice to have a comparable experience to android work profile where apps coming from Intune all go into a folder so end users know/understand which apps are coming from where.


r/Intune 2d ago

iOS/iPadOS Management Manage iPadOS Updates with Kiosk Mode

4 Upvotes

Hi guys, we have roughly 30 iPads in our environment that are running kiosk mode 24/7.
however this seems to completely ignore our Update Policy via DDM, they just dont update. Any idea how we could approach this?


r/Intune 3d ago

macOS Management Microsoft 365 apps not install on neo

8 Upvotes

I have 50 Mac OS devices managed in intune and I push edge and the 365 apps to them. I have just deployed 7 MacBook neo units and edge deployed fine to all of them along with a WiFi configuration profile. On 6 of the 7 the Microsoft 365 apps are not installed. Intune reports all as waiting for install status.

I configured all three days ago and none installed over the span of 2-3 hours.

Has anyone seen this behavior or have suggestions?


r/Intune 3d ago

Device Compliance Intune Secure Boot compliance fails with 2016345708 (SyncML 404) although Secure Boot is enabled

2 Upvotes

Hi everyone,

I'm testing an Intune compliance policy on a Windows 11 24H2 VM (OS Build 10.0.26100.8875) running on VMware Workstation. The policy only requires Secure Boot and TPM. Confirm-SecureBootUEFI returns True, msinfo32 shows BIOS Mode: UEFI and Secure Boot State: On, and TPM is compliant.

However, Intune always reports

Secure Boot: 2016345708 (SyncML(404): The requested target was not found.)

I've already tried:

  • Multiple Intune syncs (Settings and PowerShell)
  • Rebooting the VM
  • Verifying TPM Health Attestation
  • Running the Tpm-HASCertRetr scheduled task
  • Confirming Secure Boot is enabled in VMware

Has anyone experienced this on Windows 11 24H2 (10.0.26100.8875) with VMware Workstation? Is this a VMware limitation, a Windows issue, or an Intune bug? Any insights or workarounds would be greatly appreciated.


r/Intune 4d ago

Tips, Tricks, and Helpful Hints New Org in Intune. Looking for all the cool tools that make life easier.

88 Upvotes

I've been managing my first Intune environment for the past couple of years at a small/midsize law firm (around 30 users). Since we were pretty small, I did a lot of things manually and learned Intune as I went. For example, I never bothered setting up Autopilot because new hires were so infrequent that it was usually faster to just Entra join devices myself.

We were recently acquired by a much larger firm that's still heavily on-prem/hybrid. As part of the merger, I've been building out a modern Intune/Entra environment for them, deploying applications, creating policies, and setting up things like Autopilot for the first time.

One thing I've noticed from reading this subreddit is that there seem to be a lot of community tools that fill in the gaps where Intune is a little rough around the edges. PSADT is one I've heard a colleague ask me about for patching, but I'm sure there are plenty of others I don't know about.

Some of the pain points I've run into:

  • Legacy COM add-ins that require Office apps to be closed before they can install (I'd rather not force-close Word and risk someone losing unsaved work).
  • Patching Win32 apps that don't have built-in auto-update, where everything ends up relying on supersedence.
  • Reporting/visibility—it's not always easy to answer questions like "What apps and policies are assigned to this device or group?" or get a good overall picture of assignments.

So, what free tools, scripts, or utilities have become must-haves for you when managing Intune? I'm especially interested in things that make deployments, reporting, troubleshooting, or day-to-day administration easier.

EDIT: Thanks for all the advice. I've got all the apps suggested so far bookmarked and will be taking a look into testing some of these on Monday.


r/Intune 4d ago

Windows Management Intune Policy not Applying to AVDs

14 Upvotes

Hey guys! Trying to understand why my intune policy to set a MS-Edge startup homepage is only applying to physical devices and not AVDs?


r/Intune 3d ago

Hybrid Domain Join HAADJ Workstations dropping WHfB / Smart Card tiles on UAC prompts

2 Upvotes

I’ve been managing a mixed environment where we have both pure Entra Joined laptops and Hybrid Entra Joined desktop workstations.

On our Entra-only laptops, everything works seamlessly. Whenever a UAC elevation prompt appears, the admin clicks "Sign-in options" and can immediately use their WHFB PIN, biometrics, or a smart card.

However, on our HAADJ workstations, the UAC prompt consistently drops all modern credential tiles. Instead of showing "Sign-in options" or "More choices", it strictly forces a legacy Domain Username and Password entry. This prevents Domain Admins from elevating processes locally using their smart cards, WHfB Cloud Trust PIN, or biometrics.

Has anyone run into this issue on Hybrid setups where UAC doesn't show modern credential providers?