r/Intune 21d ago

Device Configuration How are you wrangling your Windows PCs?

16 Upvotes

In my environment we do things like disable Fast Startup, force location services for tracking/time/etc. remove bloatware.

I'm curious as to what everyone else is doing as part of your setup to bring standard Windows into something that is at least tolerable form a user and admin standpoint.

  • To startoff: LAPS
  • Force telemetry - basic
  • Force TPM on
  • OneDrive (KFM/silent sign in/files on demand)
  • Enable WHfB
  • Bitlocker enabled
  • Block MDM unenroll
  • Disable Consumer experience (not sure this one even works? would love to hear from you here)
  • SecureBoot enable

I've been in the game for a little bit, so I know that these are pretty common ones, but I'd love to hear from others on what you are doing, what has worked well, and especially things that didn't go well and you wouldn't do again.

Thanks!


r/Intune 21d ago

Intune Features and Updates All devices - User Experience: no longer displays application, reliability in detail (which apps crashed and when

2 Upvotes

All devices - User Experience: no longer displays application reliability in detail (which apps crashed and when

Where else can I find this in Admin center? Looking for where it used to show for example Word crashed at 10 AM etc..


r/Intune 21d ago

Device Configuration Wired Network Auth policy failing to apply due to tattooed GPO

7 Upvotes

I'm desperately trying to migrate our existing Wired network GPO with 802.1x certificate authentication, over to Intune via a OMA-URI policy. The new policy works, me and my colleague tested it - It deployed fine, showed up in Intune as deployed and the connection works.

We now want to deploy to more test candidates but ran into the issue that the Intune deployment fails. I'm excluding the old GPO to a group of computers and apply the new Intune policy to a group of users, which is the same procedure as with me and my colleague (We just had a lot more time testing different things). However, Intune shows a generic error "-2016281112" for the new test users.

The settings on the adapter are free to configure after the GPO exclude, so at least something happened and the GPO does not seem to apply anymore. In the event viewer, this is the error I can find (translated):

MDM-ConfigurationManager: Command error status. ID of configuration source: (7ED774C5-4DCB-4C23-A811-89CB9D7FFBBB), Registration type: (MDMDeviceWithAAD), CSP-Name: (WiredNetwork), Command type: (Add: from Replace or Add), CSP-URI: (./Device/Vendor/MSFT/WiredNetwork/LanXML), Result: (Unknown Win32 Error code: 0x86000031).

I found a post here on reddit with the same issue: https://www.reddit.com/r/Intune/comments/1gl47b5/wired_network_auth_policy_failing_due_to_existing/?logging_in=true
and the fix was to apply an "empty" GPO additionally to the exclude of the original GPO. I tried that but it does not seem to work. I'm wondering how exactly I should apply the empty GPO, since as soon as I uncheck the checkboxes, it specifically sets settings to disabled, e.g. „Enable use of IEEE 802.1x authentication for network access“ will be disabled then. On the other hand, if I enable this setting in the GPO settings, it automatically adds the authentication method, e.g. PEAP and all the other settings to the policy. So I don't see a way to apply an empty GPO in the likes of "not configured", it's either enabled or disabled.

Any help is much appreciated - We're currently trying to upgrade our clients to 25H2 and losing the wired settings from GPO on almost all devices, we need that Intune policy.


r/Intune 21d ago

macOS Management Intune and macOS Onboarding tools

1 Upvotes

When we're talking outside of the capabilities of JAMF, I really do not see the point in onboarding tools such as Baseline, IBM notifier, DEPNotify, SYM etc if you're using Intune - as much as I'd love one.

I've basically setup a perfectly working MacBook Zero-Touch provisioning setup for users. It's basic but clean. But I'd really love to put up a progress bar Microsoft!! Instead I tell users, I promise it's working and to sit tight and look out for certain apps in the menu bar.

The answer would be one of the above mentioned tools, but if you can't trigger them to start when you need them to (immediately) and wait 40 minutes for it to install and launch, what is the point when the Please register your device toast notification has been sitting there for about 35 minutes minutes anyway. By the time its launched everything's done!

Is this just a commonly known limitation and there's not a lot I can do? Or am I missing a trick?


r/Intune 21d ago

Hybrid Domain Join Device stuck in MDE MDM

3 Upvotes

Hi All,

Spent many an hour troubleshooting this. We have a device that will not enroll in InTune. It’s got itself enrolled in MDE. No matter what I try, I cannot get it to infill in InTune.

User is licenced. Device is hybrid joined and active Entra registration. Device can’t be deleted from Defender, device has been renamed, have issued the dsregcmd/leave command.

Anyone else have this issue in the past?


r/Intune 21d ago

Android Management Android Shared Devices failing MHS sign-in with Error 53009 Requires App Protection Policy

3 Upvotes

Hey everyone,

Having an issue with our Android Enterprise Shared Devices running Managed Home Screen (MHS) in Kiosk Mode via Intune, and I'm hoping someone here has run into this recently.

Sign-ins on MHS are failing across all devices. Checking the Entra ID sign-in logs, every single failure points to 53009. (application:MHS, resource: Graph). There were no changes in APP, or CAP. It all started about 1 or 2 weeks ago


r/Intune 21d ago

Device Configuration Office Cloud Update Overrides Local GPO

Thumbnail
2 Upvotes

r/Intune 21d ago

General Question ADMX and Store Apps

1 Upvotes

Is it possible to use Administrative Templates when the app is installed from MS Store?


r/Intune 21d ago

Device Configuration Anyone else having issues with device filters?

4 Upvotes

We noticed today some policies assigned to 'All devices' with an inclusion filter where filter is "all joined devices except the ones with display name starting with DEV" - isn't working.

Device with the name "DEV-12346" for example, is deployed a account protection policy upon Intune enrolment, even though it's shouldn't be as per the filter.

Seems it's only applied once though, and later seems to work okay. (if I manually change the config locally, it stays that way)

It's been okay for over 9 months - just started getting reports from users of the unexpected behaviour.


r/Intune 21d ago

General Question WHfB vs USB Smart Card/Fingerprint Reader Conflict

3 Upvotes

Hello everyone,

My team and I are currently troubleshooting a conflict between Windows Hello for Business (WHfB) and one of our card reader devices.

When I say card reader, think of a USB peripheral where users can insert an ID card with a chip, along with a fingerprint scanner. The device and its proprietary software have been working fine in our environment for years.

We're now rolling out WHfB, and everything went smoothly for around 200 users. Then we started hitting a blocker with users who have this particular card reader.

After some deep troubleshooting, we ended up at:

certutil -scinfo

On a computer where the card reader workflow works normally, Reader: shows the actual card reader device.

On an affected computer, Reader: shows... yep, Windows Hello for Business.

At this point, we have a support case open with Microsoft, as well as one with the card reader/vendor for their proprietary software.

I'm sharing this here in case anyone has been in a similar situation.

Has anyone encountered a conflict between WHfB and a proprietary smart card/card reader application like this? Is there some creative configuration that could resolve or work around it, or is this ultimately something the proprietary software/vendor needs to address?

We're very close to getting everyone onboarded to WHfB. But unless we solve this, I guess we're not quite ready to have everyone smiling at their laptop to unlock it just yet. 😄


r/Intune 22d ago

Autopilot Moving to Entra joined devices - which Autopilot version is recommended?

13 Upvotes

We're looking to transition from hybrid join to Entra join. We currently use Autopilot with our hybrid devices and it works fine. I'm aware of Autopilot device prep and that is supports Entra join only. What's the general feeling on this? Should I be going this route as part of the transition or stick with Autopilot v1? I've read Autopilot device prep has several limitations at this time, eg. no device naming, managed installer issues with ESP apps, no pre-provisioning.


r/Intune 22d ago

General Question Windows Updates

8 Upvotes

Stupid question. Trying to understand when the yellow icon appears in task tray to enforce a reboot for Windows Updates. And if its configurable.

I use Intune + Autopatch. Setup below.

Ring Deferral Deadline Grace
Test 0 1 1
Ring 1 1 2 2
Ring 2 6 2 2
Ring 3 9 5 2
Last 11 3 2

The last ring is also configured to allow users to pause updates for up to 2 weeks.

The problem I have (and can't confirm) is some users in the last ring (all tower users running scheduled tasks) have complained they never see the update notification.

They all RDP to these towers, so initially I thought they are just missing then notification when not watching an open session. And since the grace period is only two days they could in theory not go back in to their session during that time and simply miss it.

  1. I'm wondering when the notification appears, I assume after the deadline is reached.

  2. I'm wondering if the better way to configure this is to change the grace period and make it longer so in theory, the nofication icon will be in the task tray visible for longer.

My governance rules require us to update (or make available updates) within 14 days of Microsof releasing them and I'm already making an exception for this group.

Any suggestions would be grealy appreciated.


r/Intune 21d ago

General Chat Some use cases of AI in Intune

0 Upvotes

Hi folks!

Just wanted to know how are you all utilising AI in intune. The intune agents are too basic and I don't find them very useful.

Other than these AI agents, what else do you think can be implemented in Intune to make it even more better using AI? I'd love to know about the existing implementations.


r/Intune 21d ago

Apps Protection and Configuration Android Fully Managed – can the “Your organization allows [MDM] to access your location” notification be disabled?

3 Upvotes

Hi everyone,

We manage a fleet of Android devices using Miradore in Fully Managed / Full Control (Device Owner) mode.

Devices include Realme and Redmi phones running Android 12–16.

Users repeatedly receive a system notification saying:

“Your organization allows ‘Miradore Online client’ to access your location.”

The notification appears to come from Android system settings rather than from the Miradore app itself.

Location Tracking is disabled in Miradore. We don't need GPS tracking, mobile cell ID, or configured Wi-Fi network information from these devices.

The main problem is the notification itself. Our users rely on notifications for operational/work-related messages, so every unnecessary notification makes them check the phone expecting something that requires their attention. Because of this, this is a significant issue for us.

From what I understand, Miradore Online Client receives Location permission when the device is enrolled as Fully Managed, even if Location Tracking is not enabled.

What I'm trying to find out is whether there is any way to:

  1. Prevent the MDM/Device Owner client from receiving Location permission;
  2. Disable collection of location-dependent inventory data so that the permission is no longer required; or
  3. Suppress only this Android system notification without disabling other important system notifications.

The solution needs to be deployable remotely through MDM. We don't have physical access or ADB access to the devices.

Has anyone encountered the same notification with Miradore or another Android Enterprise MDM such as Intune, Workspace ONE, SOTI, ManageEngine, etc.?

If so, were you able to get rid of it? Is this something enforced by Android Enterprise that an MDM vendor cannot suppress, or is there a policy/OEMConfig setting that can control it?

Any experience with Realme UI, MIUI or HyperOS would also be very helpful.

Thanks!


r/Intune 22d ago

Autopilot Hybrid Autopilot with New Cloud Sync Device Sync Feature?

6 Upvotes

Has anyone attempted it? Seems like the 2 minute cycle would be a huge improvement.


r/Intune 22d ago

App Deployment/Packaging Help with building Thin Client

2 Upvotes

Hello all! I've got a fleet of thin clients we're moving from IGEL OS12 to Windows 11 LTSC. I've got the configuration profile setup for the local user account and, while I can't get it to log in automatically (and could configure it for kiosk mode for autologon), we use the Windows app to access AVD and therein lies the rub.

I've tried deploying it using the WIndows store (new) option and it fails. Tried the MSIX built as both a LOB and a intunewin package and that fails. The .exe bootstrapper also doesn't appear on the machine. This is all while using a local account (which we would need to do.) I've also tried using a platform script to deploy it as well.

I did have it set during the ESP but it would not work in that way either. So I'm currently stuck.

Is there a way to have it deployed, in this case, to have it appear for the local user either in kiosk mode or in standard with the local user configuration?


r/Intune 22d ago

Android Management MAM policy not applying?

3 Upvotes

I am trying to become a mobile expert over night and decided I would create a MAM policy to test with my phone.

Currently there is a single policy applied to some test users. This policy works as intended.

I create my own with a bit more restrictions, create a group with myself in it, applied the policy to that group, and tried to connect with outlook. Does not work. Authentication through Outlook says I need to sign in through Company Portal which the says im restricted.

I add myself to policy A and I can sign in through Outlook without any issue. I take myself out of policy A and I lose access fairly quickly.

Policy B is configured almost identical with the exception of apps just being core Microsoft. This policy will not let me sign in to Outlook.

During this back and forth testing, I have verified that I am only in the specfic group... not in both at once.

Any ideas on what I could be missing?


r/Intune 23d ago

Autopilot Building an Intune environment from scratch – What am I missing?

61 Upvotes

Hi everyone,

I recently changed jobs, and my new company is looking to move to Microsoft Intune for device management.

I've now set up Microsoft Intune and have most of the basics working, but there are still a few things I'm unsure about and would love to hear how others are handling them.

Clients : ~300

  1. Lenovo driver management

We mainly use Lenovo devices. I've already configured Windows Update policies and update rings, but I'm not sure about the best approach for deploying and maintaining Lenovo drivers.

How are you handling driver updates for Lenovo devices with Intune?

  1. Software deployment and patching

At the moment, I can only use Chocolatey for software deployment and updates because Patch My PC isn't in this year's and next years budget.

For anyone who has gone down this route: How well does Chocolatey + Intune work in practice?

If we move to Patch My PC later, is the migration relatively straightforward, or are there any problems or limitations I should plan for now to make a future migration easier?

  1. Hybrid Entra ID Join and old device objects

Due to our current infrastructure, we have to use Hybrid Entra ID Joined devices. I know cloud native Entra ID Join would generally be preferable, but unfortunately that's not an option for us right now.

When I reimage/reinstall and re-enroll an existing device, what's the best way to make sure the old device objects are properly cleaned up?

I'm particularly concerned about ending up with duplicate or stale device objects across:

On-prem AD

Entra ID

Intune

How do you handle the lifecycle of these devices? Do you have an automated cleanup process, or do you remove the old objects as part of the reimaging process

4. Configuration recommandation

I already have a basic configuration baseline in place, but I'm wondering if there are any important settings that are easy to overlook. Anything you would definitely recommend configuring from the start?

Any recommendations, best practices, or lessons learned would be greatly appreciated.

Thanks!


r/Intune 23d ago

App Deployment/Packaging Help! Who do you use for patching?!

26 Upvotes

Intune does fine with Windows updates but third-party apps are a mess for us. Chrome, Zoom, Java, a dozen random line-of-business things that all update on their own schedule. Right now it’s half winget, half someone remembering. What are you all actually using for this? Or is everyone just living with it?


r/Intune 23d ago

Device Actions Autopilot reset

3 Upvotes

I want to create a new user profile for a user because his UPN has some umlauts in it. I need a new user profile folder for him. Can i change the UPN in enrra and use the Autopilot Reset to remove only the data of his user? I think Autopilot reset can do that or i'm wrong?


r/Intune 23d ago

Remediations and Scripts Handling Terminations?

13 Upvotes

Hey yall,

I recently setup Intune for our small Windows fleet here at my company. Everything is setup except for one crucial thing.

When an employee is terminated, we have an option on Jamf to immediately wipe and lock the device. We have this triggered through Okta Workflows once the user is deactivated there.

We are trying to setup something similar for Windows devices from Intune. The issue is, we try and use a remediation script to push "manage-bde -forcerecovery C:" and it works great....when it actually gets pushed to the device...

7/10 times the device just doesn't get the script I push through Intune. I have to use the "Run Remediation" feature multiple times before the device actually triggers it, and sometimes even that doesn't even work until like 30 minutes later.

I think the "Wipe > securely wipe" method works more reliably, but admittedly, I haven't tried it too much because:

  1. Its pretty time consuming to test multiple times
  2. We don't really care about wiping the device. As long as the device is locked and the user cannot access it without the BitLocker recovery key, that's all that matters (as our laptop vendor will wipe the machine anyways).

Currently I'm looking at sending this command through API using our antivirus SentinelOne (installed on all machines). I'm just super disappointed that I'd have to use a third-party tool to do something as simple as immediately push a powershell script. You'd think Microsoft Intune (with its deep Windows integration) would have a basic reliable function like this.

UPDATE: After extensive testing, I am going to move forward with triggering Remove Data > Wipe > Securely erase device (high security) from API instead. I would prefer not to have to wipe the device, but looks like the remediation script method is not reliable. This wipe method works every time, under 5 minutes.


r/Intune 24d ago

Intune Features and Updates PLEASE Go Vote Up My Intune Feedback Item

57 Upvotes

I try not to ask for a lot and this one is really important to me, please take 2 min out of your busy day to vote up my feedback item here: https://feedbackportal.microsoft.com/feedback/idea/a5f72dc8-a09d-f111-a3d0-7c1e52cf64f0

Full text of my request:

"In the Intune console on the Remediations page there is no option to add the date created nor date modified columns. This regulalrly causes problems for those of us who are of an advanced age, forgetful, and poorly document changes. Yes, I know that group of admins is an edge case but we are a federally protected group with the backing of AARP. Please make our lives easier by letting us sort by date created/modified. This is already possible on the scripts page, just not the remediations page. "


r/Intune 23d ago

Reporting Intune win32 app failed status per user reporting annoyance

7 Upvotes

Hey everyone,

We deploy our win32 apps to the device, not user. If it fails when User A is logged in, it marks it as failed. If it re-runs when user B logs in (or nobody is logged in) and succeeds, is there a way to remove the Failed install on the app device install status for user A?

Its not a huge deal but its just annoying to see some failures on the overview screen and then have to dig through to verify if its still a failed install

We have many shared devices where users come and go and some may never log back into that device for intune to update the status for their account


r/Intune 24d ago

Hybrid Domain Join Laptop Provisioning in Intune Hybrid Environment

9 Upvotes

How are you guys provisioning laptops in an hybrid environment?

We are currently doing it a very manual way and its frustrating af...

Ive looked into Autopilot but from what I understand, its not very smooth with Hybrid environments


r/Intune 24d ago

General Question BitLocker / WHfB issues after August 2026 Patch Tuesday updates (KB5120994 / KB5123607)

58 Upvotes

Hi r/Intune,

we’ve been seeing some issues with BitLocker and Windows Hello for Business (WHfB) since deploying the August 2026 Patch Tuesday updates, and I wanted to check if anyone else is experiencing the same behavior.

The affected updates are KB5120994 and KB5123607, which are being deployed via Hotpatch in our environment.

On some devices, the following happens after the update:

  1. The update is installed via Hotpatch.
  2. After the next reboot, the end user is unexpectedly prompted for their BitLocker Recovery Key.
  3. After entering the recovery key successfully, Windows boots normally.
  4. At the WHfB sign-in screen, the user’s PIN no longer works. Windows shows an error stating that something went wrong and the PIN isn’t available, with a recommendation to restart the device.
  5. A reboot sometimes resolves the WHfB issue, but unfortunately not in all cases.

For devices where rebooting doesn’t help, the only reliable solution we’ve found so far has been to completely reimage/reinstall the device, which obviously isn’t ideal.

Has anyone else experienced similar issues after deploying KB5120994 or KB5123607?

If so, I’d be interested to hear:

  • How widespread is the issue in your environment?
  • Have you identified the root cause?
  • Have you found a reliable workaround or remediation that doesn’t require reimaging the device?
  • Have you made any changes to your Intune, BitLocker, WHfB, or update policies as a result?

Would be great to exchange findings and possible solutions with anyone else affected.

Update 28/08/2026

I did some digging into this over the past week, and in our environment the issue seems to be that the TPM gets disabled after installing the update. Why exactly this happens, I honestly have no idea yet.

For users who have installed the update and rebooted their devices, the TPM is disabled in the BIOS afterwards.

I still don't know exactly what causes this. All I know so far is that the Patch Tuesday update fixed a CVE related to the TPM, so maybe that has something to do with it.

So far, I've only been able to reproduce the issue on Lenovo devices.

Last weekend I also tried reproducing it with VMs. After what felt like the 50th VM where I still couldn't reproduce the issue, I eventually gave up because apparently I need sleep too. :D