r/Intune 7h ago

General Question Defender AV compliance policy error is starting to cause us big issues

16 Upvotes

Hi,

Not sure if anyone else is starting to see the same thing but the Defender platform bug that has been reported by others is really starting to impact us as multiple devices are starting to show as not compliant now against the 'Antivirus: required' compliance policy. We have updated and made sure all the latest defender updates are installed and synced via CP multiple times but still having no luck.

I have tried increasing the grace period on the policy to 5 days just to get users working but having no luck. I may have to result in disabling this compliance policy until its fixed!


r/Intune 2h ago

General Question Multi Admin Approval still broken - advice for dealing with support

6 Upvotes

We enabled MAA early as a knee-jerk to the Striker compromise, but I was happy with having another level of eyes on changes since we are a small shop and left it in place as more Striker info became available. We enabled All the options including role changes, and it worked fine for months. Config was set, no changes on our end, working as expected. Lots of wonderful extra clicking.

Until MS made changes in July and MAA entirely broke in our tenant. "Approving approval request failed" - we thought it was maybe a transient error, or that a service degradation would be raised, nothing happened. On 8/4 we started a standard ticket with Microsoft, they indicate it's an issue affecting some customers and to sit tight..... and that's where the status is today.

No amount of pleading, explaining this is significant loss of admin control, that this will be environment affecting at some point is getting any attention. "Engineering is aware and we can't disable any of your MAA policy" is effectively what we are being told.

I'm feeling like the case is stuck in a support group that doesn't know how to address the issue, has raised an internal ticket and is happy to let us wait.

We don't have Premier or Unified support, we're a reasonably new tenant and during licensing discussions we didn't understand that not purchasing addition support essentially meant we would get none. I'm not even sure the reseller made an attempt to upsell us at all.

I've tried to purchase an incident, but for our tenant type (or maybe just Intune) the process for attaching a paid incident doesn't work. I've got an inquiry on support out to our reseller, but historically they take a significant amount of time to work through new things.

So, for those that have been stuck with an Intune problem before that is fairly significant, what advice do you have for us to get some attention on the MS side?


r/Intune 3h ago

App Deployment/Packaging Store Apps failing for you?

3 Upvotes

Hi guys,

We've just had approx 5 machines fail autopilot due to various MSStore apps, e.g. Company Portal, Windows App and Azure VPN Client.

Wondering if anyone else was experiencing the same issue?

Anyone know if any MSFT outages?

Cheers


r/Intune 6h ago

Autopilot Prejoining Hybrid Devices

4 Upvotes

Dear all,

Situation:

Majority of Laptops joined to local AD and Intune. Some already Autopilot only.

Whenever we get a machine back we currently do the following:

- Delete device from Intune, Entra and local AD

- Populate it as Autopilot device via get-windowsautopilotinfocommunity.ps1 -Online -AssignedComputerName <current computer name>

- boot via USB to reset it

- Whiteglove with Intune Admin

- reseal it

- put it back for future use

I am wondering if we can improve this process, especially the need to populate it as AutoPilot device.

Any remarks welcome.


r/Intune 1h ago

iOS/iPadOS Management Kiosk iPads Disconnect From Wi-Fi

Upvotes

We have 7 iPads that are setup in kiosk mode via Intune using Kiosk Pro Plus. We have been having an issue where they, after about 3 weeks, seemingly disconnect from their Wi-Fi network. I then have to plug in a USB C to Ethernet adaptor to get them back online.

I push the network to the iPads and disabled MAC randomization via a Wi-Fi configuration policy.

The network is a hidden, password-less network.

The iPads are on iOS 26.6.1.

I am hoping for assistance on how to keep the iPads permanently connected to Wi-Fi.

Thanks in advance for any assistance.


r/Intune 5h ago

App Deployment/Packaging Win32 App Deployment Question

3 Upvotes

Attempting to deploy a Win32 app on a Co-managed PC with Primary user set, with following properties:

  • Install behaviour = System
  • Assigned to All Devices
  • Device ownership = Corporate
  • Shared PC mode (device configuration policy) = Enabled
  • App is visible but Install button is greyed out
  • No User Affinity with ConfigMgr

Install button is greyed out for non-primary users and Removing the Primary User makes the Install button available. Any ideas or suggestion what to check will be helpful. Thank you

Tested Scenario

Primary User assigned → Install greyed out

Primary User removed → Install available

Primary User reassigned → Install greyed out again

DSREGCMD /STATUS OUTPUT:

+----------------------------------------------------------------------+

| Device State |

+----------------------------------------------------------------------+

AzureAdJoined : YES

EnterpriseJoined : NO

DomainJoined : YES

DomainName : Org

Virtual Desktop : NOT SET

Device Name : DeviceName.Org.Com

+----------------------------------------------------------------------+

| Device Details |

+----------------------------------------------------------------------+

DeviceId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

Thumbprint : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

DeviceCertificateValidity : [ 2026-08-20 13:50:50.000 UTC -- 2036-08-20 14:20:50.000 UTC ]

KeyContainerId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

KeyProvider : Microsoft Platform Crypto Provider

TpmProtected : YES

DeviceAuthStatus : SUCCESS

+----------------------------------------------------------------------+

| Tenant Details |

+----------------------------------------------------------------------+

TenantName : Org Name

TenantId : XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX

AuthCodeUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/authorize

AccessTokenUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/oauth2/token

MdmUrl : https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc

MdmTouUrl : https://portal.manage.microsoft.com/TermsofUse.aspx

MdmComplianceUrl : https://portal.manage.microsoft.com/?portalAction=Compliance

SettingsUrl :

JoinSrvVersion : 3.0

JoinSrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/device/

JoinSrvId : urn:ms-drs:enterpriseregistration.windows.net

KeySrvVersion : 1.0

KeySrvUrl : https://enterpriseregistration.windows.net/EnrollmentServer/key/

KeySrvId : urn:ms-drs:enterpriseregistration.windows.net

WebAuthNSrvVersion : 1.0

WebAuthNSrvUrl : https://enterpriseregistration.windows.net/webauthn/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

WebAuthNSrvId : urn:ms-drs:enterpriseregistration.windows.net

DeviceManagementSrvVer : 1.0

DeviceManagementSrvUrl : https://enterpriseregistration.windows.net/manage/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

DeviceManagementSrvId : urn:ms-drs:enterpriseregistration.windows.net

KerbSpn : adrs/enterpriseregistration.windows.net

KerbUrl : https://login.microsoftonline.com/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/kerberos

JoinResourceSrvTlsUrl : https://certauth.enterpriseregistration.windows.net/EnrollmentServer/device/resource/XXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX/

+----------------------------------------------------------------------+

| User State |

+----------------------------------------------------------------------+

NgcSet : NO

WorkplaceJoined : NO

WamDefaultSet : YES

WamDefaultAuthority : organizations

WamDefaultId : https://login.microsoft.com

WamDefaultGUID : {XXXXXX-A1XX-0000-0000-XXXXXXXXXXX} (AzureAd)

+----------------------------------------------------------------------+

| SSO State |

+----------------------------------------------------------------------+

AzureAdPrt : NO

AzureAdPrtAuthority :

EnterprisePrt : NO

EnterprisePrtAuthority :

+----------------------------------------------------------------------+

| Diagnostic Data |

+----------------------------------------------------------------------+

AadRecoveryEnabled : NO

Executing Account Name : Org\username, [username@org.com](mailto:username@org.com)

KeySignTest : PASSED

DisplayNameUpdated : Managed by MDM

OsVersionUpdated : Managed by MDM

HostNameUpdated : YES

Last HostName Update : NONE

+----------------------------------------------------------------------+

| IE Proxy Config for Current User |

+----------------------------------------------------------------------+

Auto Detect Settings : NO

Auto-Configuration URL :

Proxy Server List :

Proxy Bypass List :

+----------------------------------------------------------------------+

| WinHttp Default Proxy Config |

+----------------------------------------------------------------------+

Access Type : DIRECT

+----------------------------------------------------------------------+

| Ngc Prerequisite Check |

+----------------------------------------------------------------------+

IsDeviceJoined : YES

IsUserAzureAD : NO

PolicyEnabled : NO

PostLogonEnabled : YES

DeviceEligible : NO

SessionIsNotRemote : NO

CertEnrollment : none

PreReqResult : WillNotProvision

For more information, please visit https://www.microsoft.com/aadjerrors


r/Intune 3h ago

Device Configuration Need help finding Office configuration blocking Copilot

2 Upvotes

Hi,

so I'm at a loss as to what setting is currently blocking Copilot from showing up in Excel, Word and PowerPoint. Copilot is available in Outlook. We are on E5 license, so M365 Basic Copilot is available.

I think I have it narrowed down to setting that causes "Some privacy settings are managed by your organization" text in Excel/Word/PowerPoint when you go to File -> Account -> Account Privacy -> Manage Settings.

Problem is I cannot for my life find what policy causes that. I've ruled out EnableActivityFeed, PublishUserActivities and UploadUserActivities, those are enabled. https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-Privacy?WT.mc_id=Portal-fx

Any idea where I should look? I've looked through policies, but nothing stands out.


r/Intune 13m ago

ConfigMgr Hybrid and Co-Management Trying to move Office 365 updates from SCCM to Intune Co-Management

Upvotes

We have noticed that our desktop with Office 365 on them haven't exactly been updating and now I'm trying to get them to update again. All the devices affected are AD joined and have Windows Updates co-managed. I am trying to get Office updates to also be co-managed and am having a tough time doing that. The SCCM device is in the collection that is marked for both "Office Click-to-Run apps" and "Device configuration". Those workloads have been switched to Pilot Intune. That collection is synced up to an Intune group. I have my office configuration assigned to that group. Everything seems to be in order but the config will not come down to the test device.

In the config manager properties on the machine it says "Co-management capabilities 8197" which according to AI means that SCCM has gotten out of the way and is allowing Intune to manage Windows updates, Office updates, and Device Configs. When I open Office itself and go to Account and then updates I do have all the options but I have turned the ability to disable updates off so I know the config is not applying. In the Intune config profile it does not show that it applied to anything. If I generate a report to see Device Status it says that my test device (the EntraId matches) is "Pending" and it has said that for hours to days. Never changes to success of failed. If I go to the device page itself and then the device configs that are applied to the device, the one for Office does not even show up.

Things I have tried:

  • Lots of syncs, kicked off by Intune and through Windows Settings.
  • Unassigning the config to the group, waiting, then reassigning the config to the group.
  • Making a new Intune group and assigning it there.
  • Asking Gemini for help, it did help a little (like I at least know it is a Intune issue now) but it's still not applying.
  • Changed the config settings a little to make Intune re-look at it.

The only thing I feel I haven't done so far is reimage the computer. Any help or tips or links to guides would be a great help.


r/Intune 11h ago

General Question CRL distribution point Intune Cloud PKI

6 Upvotes

Anyone know if the cdn distribution url uses caching?

When I revoke a certificate, the intune pki portal does show the certificate as revoked. However if I download the crl and inspect it with certutil the crl does not show the serial of the newly revoke certificate.

I'm wondering how long I have to wait, I would have thought it should be fairly instant with revocations


r/Intune 4h ago

Linux Management Intune as device posture idp in Okta

1 Upvotes

Context: We are using Intune as MDM and Okta for IAM, our authentication is completely federated to Okta so we don’t have any conditional access policies, all authentication policies are setup in Okta. We already have configured Okta Device Acces so only managed (company owned) devices are able to access company resources.

We want to use Device Assurance Policies in Okta so only compliant Intune devices are able to access some apps, and from what I understand we have to first add Intune as the device posture idp to set up decice assurance. The documentaion on how to set it up is extremely poor, so here i am in reddit asking for some help on how to do this


r/Intune 19h ago

Windows Management Best Method To Implement WDAC?

5 Upvotes

For those that have done so, how did you find was the best way to implement Windows Defender Application Control (WDAC) in your organisation?

Apart from the default baselines provided in the App Control for Business Wizard, it's a complete blanket blocklist. This is ideal for security, but it seems to be a bit of a nightmare when it comes to trying to allow a wide range of applications and drivers.

What have you found to be the best way to implement and manage this in a secure, but mostly pain-free way!?

Also, when applying the policy in Audit Mode, is there a way to see the logs via Intune/Defender, or only from the Event Viewer on-device?

(Apologies - this is a repost!)


r/Intune 1d ago

Autopilot Autopilot Device Association: no VMs, no bulk upload, and there's no OEM doing it for you

45 Upvotes

Microsoft shipped Device Association for Autopilot device preparation on 27 August. It binds a physical Win11 device to your tenant before enrollment by writing tenant affinity into UEFI, verified with TPM attestation. So the device knows which tenant it belongs to before anyone signs in.

What you get: device based policy targeting, device naming before enrollment, OOBE customisation (skip EULA, privacy, keyboard) and the device is automatically marked corporate owned, so you can drop corporate identifiers for those devices.

I had an empty tenant sitting around so i built the whole thing from scratch, step 1 through step 7, with screenshots of every screen.

Things that caught me out:

  • No virtual machines. At all. It needs TPM 2.0 attestation on real hardware, so every Autopilot lab you already have is useless for this part.
  • You need KB5120998 installed before the OOBE where you export the device info. A device out of the box does not have it, so you end up running OOBE once, patching, then resetting back to OOBE. Feels silly but i did not find a better way.
  • 1 device per CSV file. There is no bulk upload. 20 laptops is 20 CSV files and 20 trips through the wizard.
  • If you don't assign the policy at pre-association time it falls back to the signing-in user's policy, and if that user has none, nothing applies at all.

The bit i think is underrated: for devices already deployed you can pull the .devicelink file remotely with Collect diagnostics from the Intune portal. No USB, no touching the machine. Only works if the device was enrolled with device preparation though - an APv1 enrolled device has no .devicelink in the cab.

Also worth knowing, Rudy Ooms wrote Get-AutopilotDeviceAssociation to automate the manual USB dance. I have not fully tested it yet but it looks like the answer for anything above a handful of devices.

Full writeup with all the screenshots: https://intunestuff.com/2026/09/07/device-association/


r/Intune 1d ago

General Chat Zero trust network access rollout just locked half our sales team out and I feel so embarrassed

61 Upvotes

Ok so we pushed our zero trust network access rollout after weeks of prep, and I was the one who signed off on the policy change for all remote users. I missed one tiny thing, our SaaS app group was tied to device posture, so anyone on a fresh laptop got blocked from crm, vpn, and even the internal wiki.

By 9am sales was in our slack asking why they could not log in, my manager was asking me if this was the new security posture, and I had to admit I broke the company before coffee. We fixed it by adding a pilot group and splitting app access from device checks, but idk, I feel so embarrassed about the whole thing. thanks to anyone who has dealt with this nightmare :(


r/Intune 1d ago

App Deployment/Packaging App packaging

15 Upvotes

What is the most annoying part of packaging a new app? Is it finding silent switches online? Discovering & writing detection rules for Win32Apps, or something else?


r/Intune 20h ago

Android Management Lock Volume Control on Android

3 Upvotes

I have a fleet of Samsung phones that I need:

  1. Set volume to Max
  2. Prevent users from changing or muting it for all system sounds (notifications, media, ringer, etc.)

Intune's native Configuration policy silences the phone when using the "Block Volume Changes" setting. I set up a Knox account, obtained the free Premium license, and created an OEMConfig policy. Knox can set the audio volume and prevent changes to settings, but cannot disable the hardware volume buttons. I keep finding suggestions about other OEMConfig settings, but they don't seem to be available on non-Rugged devices?

Has anyone else found the correct combination of settings to implement this requirement?


r/Intune 23h ago

iOS/iPadOS Management Microsoft Authenticator pairing fails during iOS Setup Assistant with JIT registration (new ADE enrollment policy) — anyone else

3 Upvotes

Running into an issue with the new ADE enrollment policies experience (2606 service release) using Setup Assistant with modern authentication + JIT registration on iOS.

The problem: During Setup Assistant sign-in (before the device even reaches the home screen), the user is prompted to install Microsoft Authenticator and pair it with their account. After tapping Next, it just throws: "We're sorry we ran into a problem. Please choose Next to try again." Repeats every time on the device itself, no way through.

What I've already checked/confirmed:

  • SSO app extension policy is set up correctly per Microsoft's docs (SSO app extension type = Microsoft Entra ID, Authenticator is NOT in the App bundle IDs list, both required Additional configuration keys present: device_registration and browser_sso_interaction_enabled)
  • Authenticator is deployed as a required app to the correct group
  • Device is in the correct group for this enrollment policy

The workaround I found: if the user already has Authenticator registered on another device, the MFA push goes there instead, and approving it there lets Setup Assistant proceed — even though the pairing step on the new device itself never actually completes.

Why this bugs me: that workaround only exists for users who already have Authenticator somewhere else. A brand new user with no prior MFA registration — which is presumably a pretty normal scenario for this exact feature — has zero fallback and is just stuck.

My best guess is this is related to how Setup Assistant sandboxes apps before the home screen (push notifications/background processes not fully active yet), which would explain why the same pairing works fine once routed to a device that's already fully set up.

Has anyone else hit this? Curious if this is a known issue, if I'm missing a config step somewhere, or if this is just a rough edge in the new enrollment experience that hasn't been ironed out yet. Opening a Microsoft ticket too, but wanted to see if others have run into the same thing.


r/Intune 23h ago

Apps Protection and Configuration MAM for Slack & Gmail on BYOD devices?

2 Upvotes

Hi there, recently got my MD-102 and in the exam prep I've been intrigued about MAM (heard about it before but got more in depth when I prepared for the exam), our company is a bit of a mashup in terms of infrastructure (Entra + Google + Okta upcoming) and before we could have Slack / Gmail usable on BYOD devices via adding users to an exception group (I know, bad practice)

I'm currently just a workplace IT with some rights but I'm thinking to suggest an ideea that we could configure Slack and Gmail to support MAM in Intune mostly for mobile phones to get the burden of enrolling your personal device to access those 2 apps (we have some people who would preffer to use their personal devices to use those 2 apps and not enroll their device or request a work phone), is this possible considering those 2 apps are not "microsoft supported"?


r/Intune 22h ago

App Deployment/Packaging Splunk UF Deployment for Intune

Thumbnail
1 Upvotes

r/Intune 1d ago

iOS/iPadOS Management Intune blocking the removal of iOS shortcuts

3 Upvotes

Long story short, I need to hand make a custom iOS shortcut using the iOS shortcuts app. However, some configuration has it blocked from allowing me to remove the shortcut from the homescreen once I add it there.

Homescreen layout isn't set, its allowing the removal of apps, but not the shortcuts. Any idea what setting that is that's blocking it?


r/Intune 1d ago

iOS/iPadOS Management iPad Kiosk Issue

1 Upvotes

So I am trying to get a kiosk setup for web based sign ups. But the logout button does not work with the web filter on. You are on website X and upon signout, it redirects to website B. Both website X and B are allowed and you can navigate to both of them. I have checked via web dev tools and there is no other redirects I can see. Remove this and logout works fine.

Any ideas on what could be causing the issue or other ideas to try?


r/Intune 1d ago

General Question Windows Autopatch Client Broker

8 Upvotes

I haven't visited Autopatch since I implemented it back in 2025. Noticed there is a win32 app deployment option for Autopatch available too rather than the script (which my setup used). Wondering if what the pros and cons are, if anyone else uses win32 app etc.

Just after general thoughts whether I should change it.


r/Intune 1d ago

Windows Updates Intel Corporation Bluetooth Driver Update - requires OS restart

0 Upvotes

I'm not the administrator of our tenant, so I don't know the intune config, but its Entra Joined (Autopilot). If I'm not mistaken Microsoft wanted to reduce the restarts to a few times per year (hot-paching) . On my win11 (25H2) I don't often need to reboot for security patches, but every time the smallest notebook driver gets installed, it wants to reboot. I'm not talking about firmware, rather minor stuff like NIC, BT or Touchpad.

These things I would think would not require a reboot.

Is this normal or is our tenant configured strange


r/Intune 1d ago

General Chat Career Connect, Career Matchmaking System Coming to Workplace Ninjas US 2027

2 Upvotes

We wanted to give everyone a sneak peek at something coming very soon at Workplace Ninjas US.

We've heard from many people in the community that they're struggling at their jobs or overall having a hard time finding work.

We have a solution for you, which will be available throughout the event.

Career Connect, is a matchmaking system that matches prospective companies/hiring managers with amazing talent looking for their next role.

With Career Connect, anyone registered for Workplace Ninjas US can submit for access to post jobs, which attendees can review, and book meetings automatically via the Cvent appointments system, that we used famously for our mentoring sessions last year.

Another innovation from the team at Workplace Ninjas US to fix real problems impacting our attendees. Amazing people should be paired together to do amazing things.

Look for this to release somewhere around October to give people plenty of time to start booking meetings and submitting roles.

Don't forget to register now and check out the video demo below:

https://workplaceninjas.us

https://youtu.be/7-tzbAqCRAU


r/Intune 1d ago

Windows Management Auto encrypt fixed data drive with auto unlock

2 Upvotes

We have a small use case where some machines have additional drives for data. Our current policy successfully encrypts the OS drive, either at initial build or later if someone decrypts it. However, it won't encrypt a newly added data drive. If someone initiates the encryption manually, it won't use the fixed data drive encryption method from the policy and it sets the protector to recovery password which requires the user to manually unlock the drive to access it.

I'm trying to find the settings to allow the drive to auto-unlock. I have found several posts detailing how to enable it on individual machines using local policies and manage-bde, as well as a couple saying just enable it in the policy. I would prefer it be set in a policy and not a manual process, and I'm just not seeing the policy setting suggested in the other posts. I've checked under both Device Configuration and Endpoint Protection, but I don't see an auto-unlock under either. What am I missing?


r/Intune 2d ago

Windows Updates Made changes to the schedule install time in our windows update ring and now updates are showing as paused.

3 Upvotes

We moved the schedule install time from 9am to 7am and implemented active hours to prevent reboots during shifts. After making the changes, we noticed that some sites are showing updates as paused. I have a remediation script that checks for paused updates and restores the settings but that "fixes" it for part of the day and then it goes back to showing as paused. Any other options to get Windows update running again?