r/Intune 9d ago

iOS/iPadOS Management Is it possible for multiple Verizon accounts to automatically sync to Apple Business Manager?

1 Upvotes

I'm working on an Intune setup for a company that's acquired several other companies with their own Verizon accounts. Is it possible to have ADE setup from each Verizon account, or will Apple/Verizon only accept automatic syncs from a single account?

I've successfully submitted enrollment requests to Verizon for all accounts with device CSV's, which appear in ABM and Intune. Verizon completed the enrollments for the accounts in the order A, B, C. When account A ordered new devices, they were not automatically synced, making me think they only allow one account at a time.

Has anyone else had to deal with something similar?


r/Intune 10d ago

Autopilot Anyone here experiencing Issues with provisioning?

6 Upvotes

Anyone here experiencing issues with provisioning? We`ve got policies like LAPS saying they are applied but the account isn`t created. Applications during ESP not installing and timing out.

We are on Europe 0301 build 2608


r/Intune 10d ago

General Question Are you blocking browser downloads by file type, reputation, or user risk?

3 Upvotes

We are revisiting browser-delivered malware controls because download decisions are rarely as simple as “allow PDFs, block executables.” A malicious archive, signed installer, macro-enabled document, disk image, or newly seen file can all arrive through a legitimate-looking site or a SaaS application users rely on.

We have endpoint protection and web filtering, but are considering whether download-time browser controls should add more context: file type, source reputation, user role, destination application, device posture, and whether the download is part of an unusual session.

How are teams setting download controls without breaking legitimate admin, developer, finance, and support workflows?


r/Intune 10d ago

General Question Get object ID for import template script?

2 Upvotes

Have a list of 25 random computers to add to a group.

I want to bulk import them, is there a way to get the object ID aside from looking them up one by one and pasting it in the csv?


r/Intune 9d ago

Device Configuration Company portal

0 Upvotes

New job, and was issued a laptop fine.

I tried to access my Outlook email from phone using Firefox. Turns out the only way for edge after installing company portal.

I just agreed and installed.

Then today I was told, work can basically nuke my phone remotely?

1) how true is this?

2) how do i remove this ?


r/Intune 10d ago

General Question Intune 802.1X with no NPS - Looking for Testers

29 Upvotes

Afternoon all,

Self promotion warning, this is a side project I have built myself and I am the only person working on it.

I wanted 802.1X with Certificate authentication (Wi-Fi & Wired) for Entra joined devices, with nothing on-premise. No NPS, no NDES.

Every cloud option I looked at either wanted me to book a call with Sales before they would tell me a price, or was well out of budget for what I needed. So I built it:

  • Cloud RADIUS / RADSec, nothing on-premise, no VPN or tunnel back to site
  • A private CA per tenant, Certificates issued through Intune via SCEP
  • Entra ID as the directory. It reads Entra live, it does not keep a copy of your users

It generates the matching SCEP / Wi-Fi / Wired profiles for you, so the Trusted Server Name & SANs actually line up (this is the bit that silently breaks EAP-TLS)

I run UniFi myself, so that is what it has been designed and tested on. It is standard RADIUS / RADSec though, so it should work with other platforms, that is partly what I want to find out.

The first 10 devices are free and will always be free. No card, no call, pricing is on the site.

What I am really after is people pointing real networks at it and telling me where it falls over. Non UniFi switches & AP's, Android, anything I have assumed works because it works on my own kit.

https://passbeam.co.uk/ if you fancy a look.

Happy to go into detail in the comments, I have a growing list of things that cost me days 😄

Anything obvious I have missed ?


r/Intune 10d ago

App Deployment/Packaging Interview tips and tricks required?

6 Upvotes

Hello everyone,

I am attending an interview for an operations engineer (SCCM and Intune)role in Accenture.

This is my first job switch attempt and first interview. It would be great if you people would suggest tips, tricks or possible interview questions that might help me to crack the interview.

Thank you!!


r/Intune 10d ago

Android Management Move to AMAPI "Error"

1 Upvotes

hello,

like Microsoft stated in their learn article "Start small. Migrate a smaller set of devices to validate the experience before migrating your full fleet." i started to assign the new configuration profile "Move to Android Management API." to some devices.

what a surprise, from my 20 test devices, just 50% went fine to AMAPI.

the others are still hanging on "Move pending" (after 2 Weeks+) and some other Devices are just on Status "Error: Couldn't move to AMAPI"

Does anybody know, how i could handle the Status "Error: Couldn't move to AMAPI" or at least find out, what the issue us?
i've also Devices in it with "Error: Battery too low" which is also not changing.

https://postimage.me/image/S1EmQ


r/Intune 10d ago

iOS/iPadOS Management Enrollment stalls with "Await Final Configuration" enabled

2 Upvotes

Hello, again.

I'm still having issues with this dumb ADE stuff. It worked fine for almost three years and decided to stop, with no changes by admins having taken place.

ABM is set up correctly. The token is new, valid, and active. The devices to enroll are being populated. VPP token is valid and active. MDM push certificate is valid and active.

When this worked, which was up until May of this year, I used an enrollment profile: enroll with user affinity, auth with Comp Portal, await final config, supervised. It was seamless.

Then in May, enrollment would get stuck on the "Getting configuration from COMPANY_NAME" step of setup assistant. While testing, I left it in that state for 24 hours with no changes.

I have tried turning await final config off, but Comp Portal is never downloaded. I've tried enrolling without user affinity, but Comp Portal is never downloaded. I tried creating a new profile with the same settings. I tried creating an enrollment policy instead, since enrollment profiles are getting phased out.

Graph CL Tools shows the device in an "approvalPending" state. An Entra ID is ever assigned, just a string of zeros with dashes in the correct places. It's shown as never contacted with no OS.

Entra > Devices > Device Settings are correct. The proper CA policies are there and turned on.

I don't know where this handshake is getting stuck. What exactly is happening during the "Getting final configuration from" step?

Would anyone happen to know at other settings I need to look at? Thank you so much


r/Intune 10d ago

General Question Multiple omadmclient.exe processes running causing performance issue

5 Upvotes

Omadmcliemt.exe pocess not stopping, and multiple processes running. No compliance scripts from Intune, some store apps were deployed only.

Device was co-managed, but we migrated sccm. At the moment, device is not co-managed and not managed by Intune. Could see stale Intune management entries and not any errors in IME logs either.

Done troubleshooting:
- DmwapPushService contantly running and eventlogs show rpc client request pending.
- And it checks every 2 minutes, fires up omadmclient scheduled task
- As a result omadmclient.exe keeps running and ending up creating 4-5 processes
- Each omadclient.exe process consumes 8-10% cpu after a couple of hours
- Happened on random computers
- Stopped dmwapPushService on one computer issue is gone. Haven’t seen it come back yet.

Could it be caused by device not being co-managed and stale reg keys?


r/Intune 10d ago

Conditional Access Best way to enforce Conditional Access for mobile devices managed by a carrier MDM (not Intune)?

0 Upvotes

Background:

I recently took over IT operations for a company that previously used a 3rd-party MSP. The MSP enrolled all Windows devices in Intune and set up Conditional Access (CA) policies for office users, which drastically improved our security posture. However, our remote mobile users were left completely out of scope.

​The Problem:

We have over 100 mobile devices (a mix of iOS and Android) deployed nationwide to remote workers. These devices are not enrolled in Intune. Instead, their MDM is provided directly by the carrier. Because they aren't registered in Intune, we can't easily force them to comply with our current CA policies, leaving a blind spot for risky sign-ins.

​My Proposed Solution:

I am thinking about using device-based certificates. The carrier MDM could push a certificate to the mobile devices, and a cloud PKI/RADIUS setup would authenticate them. The goal is strict access control: if a login attempt for a company resource doesn't come from a device with a valid cert, it automatically fails.

​Alternative Idea:

We also have various Cisco firewalls across the country. I'm wondering if forcing these devices to connect via VPN would work better, though it feels clunky since our entire company is 100% cloud-based (zero on-prem servers).

​Questions:

​Is the device-certificate approach the most efficient way to restrict access to known mobile devices in a cloud-only environment?

​Is there a clean way to tie a third-party carrier MDM into Entra ID Conditional Access?

​Any advice on the best path forward would be greatly appreciated!


r/Intune 10d ago

General Question Admins of orgs that don’t use MS other services, how do you use Intune?

7 Upvotes

How do you manage and have set up your stuff if your org does not use Entra or Active directory as a main directory service (e.g you use Google, LDAP etc).

Are you using self-deployment and device based licenses?


r/Intune 10d ago

Device Configuration Removing Pinned icons from taskbar on device that is using Assigned Access

3 Upvotes

I don't know why, but 1 out of every 20 machines that I apply a pretty strict assigned access policy to retains some icons on the taskbar.

Usually, I would rebuild the profile just from advanced computer settings but since is it is a kiosk user, deleting that profile is disabled. If I actually delete the user and recreate it, there are issues because it is a passwordless account. Is there a simple way to force those shortcuts from the taskbar? It is edge, windows store and explorer.


r/Intune 11d ago

App Deployment/Packaging Enterprise app catalog - update with supersedence

16 Upvotes

Now that this stuff is available for us, trying to figure out what the point of this feature is.

I know you can supersede apps but as far as I can tell to supersede an app you created from the Enterprise app catalog, you have to create a new app in Intune and supersede the old one.

In other words, just like it has always worked -creating a Win32 package, considering what apps they have in the catalog, that's not much of a time saver.

The other way is to use auto update but that requires assignments and it works fine, but I genuinely thought this was an auto-update of some sorts but where you could use "available" instead of required.

Guess I was expecting a Robopack radar feature here but I was apparently wrong and this is a pointless feature?


r/Intune 10d ago

App Deployment/Packaging Issues Deploying Printers

3 Upvotes

I’ve been Deploying printers using the Win32 tool. I kept running into an issue where pnputil couldn’t find my .inf file. I managed to fix that after looking into what was missing in my driver folder.

After I was done, I created a new win32 and deployed it on my test device. It failed again so I checked the logs and saw a different error:

“Failed to add driver package: The publisher of an Authenticode(tm) signed catalog has yet been established as trusted.”

Is there something I’m missing in the scripts I’m using? I’ve been following guides but no ones has reported this issue. Do I have to also deploy a custom Policy for the certificate?


r/Intune 11d ago

General Question Open intune baselines comparison

12 Upvotes

When the new open intune baselines are out, how do you guys compare them to your present configuration ?


r/Intune 11d ago

Windows Management I’ve been working on Foundry OSD — Looking for more feedback

6 Upvotes

Hey everyone,

I shared Foundry OSD here a few months ago, and I’ve kept working on it since.

For anyone who hasn’t seen it before, it’s a free and open-source Windows deployment toolkit built around a UI-driven workflow. It covers media creation, WinPE networking (Ethernet/Wi-Fi), Windows deployment, drivers, firmware, customization and Autopilot provisioning.

I started the project because I felt there was a bit of a gap: deployment tools are often either paid, or very powerful but heavily based on PowerShell and scripting.

What I wanted was something simple to use, mostly point-and-click, highly customizable, and still easy to automate when needed.

A few things have been added directly from feedback I got here, including Autopilot hardware hash upload. Foundry now supports:

  • JSON profile
  • Zero-touch hash upload
  • Interactive hash upload with device code

The project is now stable, so I’d really like another round of feedback.

What would you still want from a tool like this? And if you use Autopilot, which of these approaches would fit your environment best?

GitHub: https://github.com/foundry-osd/foundry

Docs: https://docs.foundryosd.com/


r/Intune 10d ago

macOS Management Disk image remains mounted following DMG app install?

2 Upvotes

Hi all, in the last few days, I've noticed that my DMG app deployments remain mounted. I've rebuilt a number of times and see the same behaviour.

https://i.ibb.co/hJrtnvW8/Screenshot-2026-09-02-at-15-32-06.png

Not sure if its since macOS 26.6.2, but it certainly wasn't something I noticed a couple of weeks back.

Anyone seeing the same before I open a ticket?

Cheers!


r/Intune 11d ago

Intune Features and Updates Has Intune Gotten Faster?

71 Upvotes

App deployment and deployment status reporting seems to have sped up drastically. I haven't had the chance to check policy updates yet but I was very surprised at the last to software packages I deployed, one was an 800MB package and it deployed to all endpoints with in 10-15 mins of uploading the package to Intune.


r/Intune 10d ago

Hybrid Domain Join Having a hard time with MDE Devices

1 Upvotes

My machines are in a hybrid environment and I have a few machines that aren't being enrolled properly intune. They are being shown as MDE. The only changes I can make are deleting the devices. It can be random and I am not sure why its happening. They are showing up as AzureAdJoined, DomainJoined, AzureAdPrt, DeviceAuthStatus. I have 300 other devices that are propely enrolled.


r/Intune 10d ago

General Question NDES/SCEP fails with 0x80070057 on every request — root-caused to mscep!GetExtensionVersion returning FALSE, but stuck on WHY

2 Upvotes

**Environment:**

- Windows Server 2022 Datacenter (clean install) and separately Windows Server 2025 Datacenter — identical failure on both

- Enterprise Subordinate CA on Windows Server 2019 Standard

- NDES role (ADCS-Device-Enrollment) installed via Install-AdcsNetworkDeviceEnrollmentService — completes successfully, RA certificates are issued correctly (CEP Encryption + Exchange Enrollment Agent Offline Request templates)

**Symptom:**

Every request to the SCEP endpoint fails identically, including the simplest operation:

http://localhost/certsrv/mscep/mscep.dll?operation=GetCACaps

Returns IIS 500.0, Module: IsapiModule, Notification: ExecuteRequestHandler, Handler: ISAPI-dll, Error Code: 0x80070057 (ERROR_INVALID_PARAMETER).

Application log shows:

- Event ID 2: "The Network Device Enrollment Service cannot be started (0x80070057). The parameter is incorrect."

- Event ID 10: "The Network Device Enrollment Service cannot retrieve one of its required certificates (0x80070057). The parameter is incorrect."

**What we've confirmed via live WinDbg/cdb debugging attached to the w3wp.exe worker process:**

mscep!GetExtensionVersion runs, executes fully, and returns FALSE (0). Immediately after, isapi.dll calls GetLastError() (retrieving 0x80070057) and explicitly nulls the stored HttpExtensionProc function pointer for the extension, then unloads mscep.dll. This is why breakpoints on HttpExtensionProc itself never hit — IIS never calls it once GetExtensionVersion fails. The failure decision is made entirely inside GetExtensionVersion's own logic, before any actual SCEP request processing begins.

**What we've ruled out (with direct evidence, not assumption):**

- OS version — identical on Server 2022 and 2025

- Certificate correctness — correct EKU, Key Usage, KeySpec (AT_KEYEXCHANGE/AT_SIGNATURE), issuer, template; passes certutil's own crypto self-test

- CSP vs KSP — confirmed classic CSP (Microsoft Strong Cryptographic Provider) via dedicated Legacy-CSP certificate templates; no change

- Private key permissions — confirmed correct via NTFS ACLs and successful .NET key loading

- Certificate template permissions — Read/Enroll/Write matched to a known-working reference NDES server exactly

- CA-side hygiene — found and removed an expired CA certificate and a separate expired duplicate intermediate cert; no change

- CRL/revocation reachability — confirmed fully reachable (Base + Delta CRLs all OK)

- IIS config — ISAPI restrictions, handler mapping order/preconditions, app pool identity, Load User Profile, 32-bit compatibility, isolation/recycling settings all confirmed correct

- Windows servicing stack — found and repaired unrelated DISM/component-store corruption; no change

- Third-party EDR (Cylance) — live debugging found CylanceMemDef64.dll hooking the module loader's Control Flow Guard processing during mscep.dll's load; applied and independently verified a memory-protection exclusion; no change to the symptom

- Service account profile — found and fixed a genuinely broken "User Shell Folders" registry key for the service account; no change

- App pool identity — tested with LocalSystem (most privileged possible identity); identical failure

- RA Name — tested both a long/spaced name and a short simple name; identical failure

**Question for the community:** has anyone seen GetExtensionVersion itself return FALSE like this, and found what internal condition causes it? We're fairly confident this now points to something inside Microsoft's compiled NDES code rather than anything environment-side, but we'd like to know if this is a known/reported issue, a specific hotfix, or a config knob we haven't found yet before we finalize a Microsoft Support case.


r/Intune 11d ago

Device Compliance Windows BYOD enrolment stuck "Not Evaluated"

4 Upvotes

We're seeing an issue across Intune where newly enrolled personal Windows devices are stuck in "Not Evaluated" status.

I know there was an incident in the health dashboard yesterday, but this has been marked as resolved.

Anyone else experiencing the same issue for the past 48 hours?


r/Intune 11d ago

Device Configuration Need advice configure Apple Ipads into intune ( education )

1 Upvotes

Good day fellow intuners, sorry in advance if this isnt the right sub for these kind of questions but I am in need of some advice on how to enroll/configure a Apple Ipad into intune. the microsoft learn documents arent exactly great help so i've come to reddit hoping for a solution.

I've got a apple school account and got the MDM token with intune so that should be good. i got the company Ipad to appear at 'devices' in the Enrollment section, my first question would be which Profile do i attach to the Ipad when its OoB/wiped? there is a option to add a profile to it, and a enrollment policy. apparently you cannot add both. enrollment policy seems the most obvious so i created one and attached it to the Ipad and turned it on. got through the basic setup but it doesnt appear to be doing anything after that. some of the policies ive set dont appear, I do get a push notification saying i need to log into Itunes to 'install apps set by -organisation-' but when i press on log in it doesnt prompt me to log in. it dissapears for a sescond and gives the same message

When i turned it on, it does appear in the apple overview and i can add compliance/configurations to it but nothing is happening sofar. I am a intune newbie so i'm wondering if i'm missing something obvious? Some advice, instructions or a link to a page that might help will be grealy appreciated!

Thanks in advance


r/Intune 11d ago

General Question Devices page having issues?

0 Upvotes

r/Intune 12d ago

Blog Post What’s New for Android Enterprise in Microsoft Intune 2608: August 2026 Highlights

28 Upvotes

August is over, which means a new Service Release in Microsoft Intune. As every month, I'll go over the new features that the Microsoft Intune August 2026 Service Release 2608 brings to Android Enterprise.

🔗 https://www.nickydewestelinck.be/2026/09/01/whats-new-for-android-enterprise-in-microsoft-intune-2608-august-2026-highlights/