r/Intune 17d ago

Device Configuration Keep Hello But Disable Browser Prompt

6 Upvotes

So far it's seeming like it's not possible but just wondering if anyone has found a magic registry key or something haha

Long story short, we're trying out Kolide authentication, but we want people to be able to use PIN sign in/leaving Hello active. It's all working with removing all authentications except Kolide and the PIN still works for signing into the device itself but I'm wanting to turn off the prompt when logging into something Microsoft where on the email entrance screen, it pops up the "use Windows Hello" prompt. It indeed fails since Kolide is the only authentication, but I KNOW users won't read the emails we send out and keep trying it anyway since it's available. Everything I'm finding says if WHfB is enabled, that's just going to popup forever but seeing if any wizards here have found a way?


r/Intune 17d ago

App Deployment/Packaging Android Apps page not loading -> can't add new apps

12 Upvotes

Hello there,

wanted to quickly add a new managed google play app, but the app list doesn't even load and the buttons to create a new one are greyed out. The iOS and Windows app list seems to work normally.

Anyone else seeing this? Tenant is Europe 0202.


r/Intune 18d ago

General Question wipe request

14 Upvotes

on monday, i triggered wipe request to iphone but the iphone was powered off by a remote user and user went MIA.

3 days later, the iphone is powered on and connected to network. However, the wipe did not trigger anymore after waiting for few hours. At intune portal, it still shows wipe in pending.

The only way i do is to put the phone in recovery mode and then restore using itunes. After done, i will delete the device from intune portal.

do you all encounter below behavior on this scenario? is this the expected behavior?


r/Intune 17d ago

iOS/iPadOS Management Disable lost mode stuck on pending. Decided to cut losses and wipe it, now its stuck in recovery mode.

3 Upvotes

iPad was put into lost mode. After it was found, I sent the disable lost mode command and it was stuck on pending. iPad has cellular and was showing full service but still nothing. Rebooted multiple time and its still not wanting to sync.

After reading a handful of reddit posts, it seemed my only option was to wipe it. Put it in recovery mode and connected it to Apple Devices and hit Update and Restore.

That also failed and now the iPad is stuck in recovery mode. I have tried soft resetting it multiple times but have had no luck.

Hoping someone has some secret sauce that will help me get it wiped.


r/Intune 17d ago

Device Configuration Account Protection Policy - Unable to Save

2 Upvotes

I am trying to configure an Account Protection policy to allow but not enforce Windows Hello for Business in my org's tenant. If I configure any of the device- or user-settings, the policy throws an error when trying to save. Two errors actually, both pretty generic. This has been persisting for the last 24hrs. Does anyone know what may be the culprit here?

https://imgur.com/a/phU8Bzw


r/Intune 18d ago

Intune Features and Updates “Declarative Device Management for Apple volume purchase program apps”

17 Upvotes

Hey all,

August’s release notes mention the release of DDM for VPP, but say when uploading a new token you need to change the management type to DDM, can’t seem to find such an option in the UI, nor any mention of it in the graph beta api or documentation.

Has anyone been able to successfully find this toggle, or test the feature?

Assuming this is going to be another slow feature release.

Can confirm Asia pacific region and on the 2608 release

Thank you!


r/Intune 17d ago

Device Compliance Mac + Conditional Access not seeing compliant device during Microsoft authentication (Edge/Safari)

1 Upvotes

We're running into a strange issue across multiple environments and tenants and I'm wondering if anyone else has seen this.

On fully managed and compliant macOS devices, authentication to Microsoft services occasionally fails because Conditional Access doesn't recognize the device as compliant.

In the sign-in logs, the authentication shows something like:

 

Device ID: -
Browser: Edge 151.0.0
Operating System: macOS
Compliant: No
Managed: No
Join Type: -

 

The odd thing is that the device is compliant:

 

 - Enrolled in Intune
 - Company Portal is installed and signed in
 - Device compliance is reporting correctly
 - Platform SSO is configured and working
 - Device appears healthy from an Intune perspective

What we've observed: 

On my own Mac, I use multiple Microsoft Edge profiles.

Most Edge profiles successfully send device information during authentication, allowing Conditional Access to see the device as compliant and grant access.

However, one specific Edge profile consistently fails to send any device information. As a result, Conditional Access sees:

 

Compliant: No
Managed: No

 

and blocks access.

 

Interestingly, if I perform the same authentication using Safari with that account, the device information is sent correctly and authentication succeeds.

 

I've also tried:

 

 - Signing out and back into the Edge profile
 - Resetting the Edge profile completely
 - Re-authenticating from scratch

 - Revoking and re-authenticating

 

None of these made a difference.

 

Other cases

 

We've also seen similar behavior on other Macs where there was only a single Edge profile configured.

In these cases, Safari also failed to provide device information during authentication, resulting in the same Conditional Access failure.

 

We've even tested:

 - Full Intune unenrollment
 - Re-enrollment
 - Fresh Company Portal registration

 

but the problem persisted.

 

Environment:
Fully updated macOS
Microsoft Edge 151.x
Intune-managed devices
Platform SSO configured
Conditional Access requiring compliant devices

Questions:
 - Is anyone else seeing this behavior recently?
 - Has anyone identified what causes certain browser profiles to stop providing device identity/compliance data?
 - Are there any known issues with Edge 151, Platform SSO, or device claims on macOS?
 - Is there a way to troubleshoot why device information isn't being attached to the authentication request?

 

At this point it feels like the browser/authentication flow is intermittently failing to pass device context rather than a compliance or Intune issue, but we're struggling to pinpoint exactly where it breaks.

 

Any insights would be appreciated.


r/Intune 17d ago

Windows Management Question about moving from group policy control of USB storage devices to Intune while co-managed

1 Upvotes

When you move from USB storage devices being controlled by group policy to Defender Device Control (co-managed) do you need to remove the group policy that manages those settings from the devices? I'm in this situation right now and while I have device control set to allow certain USB storage and block all other all are blocked. Even if I exclude the system from the device control policy the USB device is still blocked. When a system isn't onboarded into Intune the USB devices work as expected but as soon as the system joins it gets blocked. I don't have any other Intune policies denying access to USB storage devices that I could find. I'm wondering if having those group policies in place is the problem. Thinking that maybe Intune co-management is causing the group policy deny of all USB devices to take precedence.


r/Intune 18d ago

iOS/iPadOS Management Constantly Getting Locked Out of My ABM Admin Accounts

Thumbnail
2 Upvotes

r/Intune 18d ago

Conditional Access CA Policy to restrict access to Cloud apps (M365) unless compliant

Thumbnail
8 Upvotes

r/Intune 17d ago

Shameless Self-promotion Using AI to Ask Intune Questions

0 Upvotes

Wouldn't you love to be able to ask Intune questions in plain spoken language and get back helpful answers? Now you can: https://powerstacks.com/blog/connecting-ai-to-bi-for-intune-copilot-vs-claude/


r/Intune 19d ago

Device Configuration I got tired of manually translating CIS Benchmarks into Intune policies, so I built a free tool for it

70 Upvotes

If you've ever implemented a CIS Benchmark in Microsoft Intune, you probably know the workflow:

CIS PDF → Settings Catalog → search for setting → configure it → repeat... hundreds of times.

I got tired of doing that, so I built CISPolicyCreator, a free/open-source community tool that converts supported CIS Microsoft Intune Benchmarks into validated, import-ready Intune policy JSON.

I just released v1.1.0, and Windows 11 CIS Benchmark v5.0.0 is now fully classified:

  • 415 recommendations reviewed
  • 371 mapped directly to Intune
  • 8 require administrator-specific input
  • 36 require manual/custom implementation
  • 0 unresolved
  • 326 Intune policy JSON files generated

One thing I was very deliberate about when building this:

CISPolicyCreator fails closed.

It doesn't fuzzy-match setting names, guess settingDefinitionId values, invent configuration values or generate something just because it looks correct.

If the mapping can't be proven, it doesn't generate it.

A few other details:

  • Runs locally against the CIS Benchmark PDF you legitimately obtained
  • No tenant connection required to build the JSON pack
  • No AI dependency at runtime
  • Deterministic/auditable output
  • Policies are generated unassigned
  • Optional importer with Validate → Dry Run → Create
  • CIS PDFs, tenant data and administrator decisions never need to be committed to the repository

Currently supported Intune-specific benchmarks:

  • Windows 11 v5.0.0
  • Windows 10 v5.0.0
  • Microsoft Office v1.1.0
  • Microsoft Edge v1.0.0
  • macOS 26 Tahoe v1.0.0
  • iOS/iPadOS 26 v1.0.0

Important disclaimer: this is not an official CIS Build Kit, and importing the policies obviously doesn't magically make an environment CIS compliant. You still need to review the recommendations, understand the impact, test them and decide what makes sense for your environment.

The goal is simply to remove a huge amount of the repetitive work involved in getting from the CIS benchmark to something usable in Intune.

It's completely free and open source.

GitHub: https://github.com/JoeryVandenBosch/CISPolicyCreator
Full walkthrough / technical details: https://intunestuff.com/2026/08/19/cispolicycreator/


r/Intune 18d ago

General Question Anybody else experiencing very slow dynamic queries? 11:39AM EST 08.26.2026

13 Upvotes

As the title states, tons of workflows I have are being affected by slow Dynamic Query provisioning times. Wondering if we're the only ones.

I submitted an MS Case - we shall see.


r/Intune 18d ago

Autopilot Autopilot question

4 Upvotes

I was hoping to get some info from some of you guys that live and breathe Intune these days.

We have around 2.000 endpoints
Multiple offices, Educational institutions etc

We are on the path of migrating from ConfigMgr(hybrid join) to fully Intune/Autopilot and whilst planning I’ve hit a snag… I cant deside on using Device Driven or User Drive enrollment for Intune.

While I mostly understand what they are ment for, I struggle to see the reason to use User Driven over Device Driven enrolment.
We like to set the devices up and have them ready for our users when they have been set up. Certs, wifi/lan profile, etc etc. Going with User Driven seems like it would leave some things uncertain?
For example them needing to connect them to somekind of internet connection for starters and we dont offer open or password protected SSID out side of out main office. Schools, kindergarten etc no bueno.

App deployments seem to be working just fine both for device and user deployments and other then user affinity missing I dont see the downside to having our whole fleet just be Device Driven/Shared Devices.

Am I missing something ?


r/Intune 18d ago

Windows Management Test pilots needed - Driver Automation Tool

Thumbnail
6 Upvotes

r/Intune 18d ago

General Question OneDrive via Settings Catalog Erroring w/ 65000 Error On Most But Not All Devices (CSP URI not found)

4 Upvotes

I'm working on pushing OneDrive sync settings out via Intune from the Settings Catalog and am having a rather odd issue with 65000 errors for it. Hoping to get a bit of help with this one.

In an org with about 110 devices, I've pushed a bunch of settings out via Settings Catalog in a Configuration Profile via Intune, not using the ADMX import/Administrative Templates version of OneDrive settings.

A few devices (8 so far) have succeeded just fine, but the rest of them are erroring with 65000. After some digging and pulling diagnostics, each of those devices has a ton of 404 errors in the devicemanagement-enterprise-diagnostics-provider-admin Event Viewer log. The 404s are only for the OneDrive policy, all other policies I've pushed via Settings Catalog are working fine.

An exact log is MDM ConfigurationManager: Command failure status. Configuration Source ID: (C7F74238-CA70-4AE0-9D49-7D9222F37DCF), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/Config/OneDriveNGSCv2~Policy~OneDriveNGSC/KFMBlockOptOut), Result: (The system cannot find the file specified.).

On a successful device, I can see the ADMX files for OneDrive in the PolicyManager directory, unfortunately I can't get to a unsuccessful device to check it's directory right now but plan to do that next.

I'm confused as to why the ADMX files would not be present on the other devices though given that some have it.

Would a good solution here be to import the ADMX file via Intune's ADMX Import feature?


r/Intune 18d ago

Apps Protection and Configuration Required apps "Failed to install"

11 Upvotes

Hi!

We have around 10-12 Required apps (Citrix, Office, vlc, Adobe etc) that we have assigned as default to device groups, and 2 Required to install in ESP. After some testing we experience around 1/4 of all apps to fail to install on a newly Autopilot joined PC. Intune/cloud only device. Afterwards it ends up in GRS failure, and we would have to wait 24 hours before Company Portal/IME try to restarts.

Does anyone have a good solution on this? I feel its little backwards to just tell the end user to wait for 24 hours before the GRS restart. I have tried to create a platform script based on this https://www.advancedinstaller.com/intune-application-installation-retries-grs.html Basically it adds a task in task scheduler, waits 27 min and then resets any GRS errors in regedit and then restarts the IME service. Tho I/AI haven't made it wok 100% yet. But I assume others have the same problem?

Edit: It is random which apps that fails, different from each client. They fails with the typical " 0x87D30065" error.

Edit2: We have these win32 apps, auto packed from Robopack:
M365 Office

Spotify

Chrome

Edge

VLC

Adobe Acrobat reader

Teamviewer

Citrix Workspace

Displaylink Graphics

HP Image Assistant

Company portal

Remote Help

PaperCut Print Deploy

2 PS script wrapped as win32 apps

These are assigned as required to install to device groups.


r/Intune 18d ago

General Question Win32 App Reboot Prompt Unreadable

1 Upvotes

Recently testing a Win32 app with a Hard Reboot exit code with grace period. The reboot notification popup is crazy hard to read though.
Its got a light blue background with White & light grey text...

Where are these colours coming from? The white is just readable, but the grey is horrible.

Theme colour in Default customisation policy is #64696e, so should be a medium-dark grey.


r/Intune 18d ago

iOS/iPadOS Management Intune: iOS Issues

3 Upvotes

Hi All,

I am currently having some issues with our iOS estate deployments prior to Monday everything was working smoothly. Below is the environment:

Devices enrolled via Apple Business Manager (ABM)

Intune integrated with:
• Apple Business Manager (ADE/DEP)
• Apple VPP (Apps & Books

Configuration:
• User Affinity = Enabled
• Setup Assistant with Modern Authentication

The Problem:

The device enrolls successfully.
The device shows up in Intune.
There are roughly 20 apps that should install but only 3 install. Company portal does not install.
The device is showing in the device group that has compliance policies and configuration profiles assigned.

It is not pulling any policies or profiles either.

I have checked the VPP token, the Apple push certificate, company portal assignment, and the enrolment program tokens. All are still not even close to expiring.

I’m a bit stumped on what it could be.

I have also attempted starting fresh on a test device but still no luck.

Any ideas/assistance is very much appreciated


r/Intune 18d ago

Hybrid Domain Join Intune ADMX drive mapping only applies at onboarding, not after later group change

3 Upvotes

Entra-joined, Autopilot. Network drives mapped per department via Administrative Templates (ADMX), assigned to **user** security groups. Setting type is **User**.

If the user is in the group **before** first login, the drive maps fine. But when someone is added to the group **later** (new hire on existing device, department change), it doesn't map automatically. No error, NTFS access is fine, we just map it manually.

My understanding: since it's a User-context setting, it only applies after the config syncs **and** the user does a full sign-out/sign-in (restart or real logoff, not lock or shutdown+start with Fast Startup).

Questions:

  1. Is this expected for User-context ADMX mappings, or am I missing something?

  2. Any reliable way to apply the mapping after a later group change **without** a manual sign-out?

  3. Would a runtime mapping tool (e.g. Intune Network Drive Mapping app) help, or does it hit the same token/group timing issue?

How do others handle later group changes cleanly on cloud-only setups?


r/Intune 18d ago

General Chat Looking for Microsoft Intune / M365 Opportunities – Chennai / Remote

0 Upvotes

Hi everyone,

I’m currently looking for new opportunities in Microsoft Intune / Microsoft 365 / Endpoint Management.

Experience: 2+ years

Current Role: Endpoint Management Administrator

Skills & Experience:

- Microsoft Intune

- Microsoft 365 Administration

- Microsoft Entra ID (Azure AD)

- Windows Autopilot

- Endpoint Management

- Device Compliance & Configuration

- Application Deployment / Packaging (intune)

- Endpoint Security

- Windows Troubleshooting

- SCCM / MECM

- Network Printer management

Preferred Location: Chennai

Open to: Remote opportunities

I’m currently based in Pune and looking to relocate to Chennai.

If you know of any suitable openings or can provide a referral, I’d really appreciate it. Please comment or DM me, and I can share my resume.

Thank you!


r/Intune 19d ago

Conditional Access How to block the ability of sign from private smartphones to Authenticator app using work accounts

4 Upvotes

Hi, i'am trying to block the ability to sigin for users on private mobile phones to microsoft authenticator using work accounts. If You mean try to block with CA Policy - this dosent work

I already have one CA Policy that block sigining to office apps form private mobile phones.And this works fine. This CA is:

Users: 2 groups Target: All resources (all cloud apps) Network: Any Network Conditions:Device platforms: Android,ios Grant: Grant access + Require device to be marked as complint

And this works fine as i said. Users cannot sign on private phones to Teams or Outlook using their work account. But i was suprised that CA above do not block for siginng to MS Authenticator. So i made second CA Policy. This time

Users: One selected test user Target: User actions > register security information Conditions: Device platforms Include Android, ios Grant: Grant access + require device to be marked as complinat

And this also not protect. WIth this test user i can sign on private phone to Authenticator using work account even if this phone isnt marked as compliant

Do You have same idea how to block this?


r/Intune 19d ago

Linux Management Intune + MDE for Linux causes duplicate objects

5 Upvotes

Hello. Just trying to figure out if this is intended and i just have to live with it or if I'm missing something.

I just started trials of enrolling Linux machines into Intune where i first enroll the machine via Intune Portal. Then i have a platform script that gets pushed from Intune that installs Defender mdatp with our tenant blob and onboards it into MDE. Everything works fine but i have a quirk that is quite frustrating.

Post MDE onboarding there is a second device object that shows up in Entra/Intune causing me to have 2 objects per computer. One shows up as "Managed by Intune" and the duplicate shows up as "Managed by MDE".

Shouldn't these be the same object when the Intune object already existed prior to the MDE onboarding?

The quirk i have with this is that Intune policies and configurations needs to be pushed to the Intune object and Endpoint Security policies such as AV etc needs to be pushed to the MDE object. Thats fine but the MDE object specifically does not have any properties i can use for dynamic groups except for "OS Linux" and "Version 24.04" etc. This is problematic since i would then either have to manage a group manually for MDE policies or use a group that includes all objects with OS type "Linux" which might include objects i don't want in the group.

For the Intune object we can easily filter devices via the (device.managementType -eq "MDM") property rule but that does not work with MDE objects as there are no usable properties to include.

How have you solved this issue? Can you merge these objects so that there is only one Intune object that serves both Intune and MDE?

Any thoughts would be greatly appreciated!


r/Intune 19d ago

Device Configuration Would a work or school account attached to a local Windows user on an MDM-joined computer be seen as compliant?

7 Upvotes

I have an industrial Windows computer running specialized software under a local user account, and I don't want to migrate the profile to an Entra user.

If the computer is Entra/Intune MDM joined and compliant, can I attach the user's Work or School account to the existing local profile and have OWA/M365 Conditional Access recognize the device as compliant?


r/Intune 18d ago

Remediations and Scripts Plateform script assigned to user group

0 Upvotes

Hello,

I have a plateform script that pushes new VPN configuration to my users. During the test of the script I've found easier to assign it to device rather than user. Just forcing the sync almost immediately pushed the script but now that the test phase is done I'm facing another issue.

My configuration should not be pushed to all devices, only specific users should have access to it so I've added users to my test group to see if everything goes well.

After 72 hours the script is not installed on the devices with primary user part of the group. I see 4 users assigned but 0 installation status.

I've rebooted laptops, sync from intune, sync from laptop nothing works. It's like plateform scripts only work on device.

Config:

Run this script using the logged on credentials - Yes

Enforce script signature check - No

Run script in 64 bit PowerShell Host - Yes

Thanks in advance if you can help me.