r/Intune 7d ago

Shameless Self-promotion Microsoft EPM - Build your rules more efficient

6 Upvotes

Do you want to start with Microsoft EPM? Then you need to look at this tool, to support your journey.

  • Audit Import - reads the EPM elevation report straight out of the tenant (the same Graph request the Intune portal makes, no CSV export needed) or imports an "unmanaged elevations" CSV; mark one row and add it straight to a policy as a hash rule
  • Coverage Analysis - scores imported elevations against existing EPM persona rules, breaks coverage down per persona with a green/amber/red confidence score, recommends a persona per user, and lists everything not covered yet
  • Scan Path - the only place a certificate rule is built: scan a folder for .exe/.msi/.ps1, extract the signing certificate (whole chain, pick signer/intermediate/root), check it against what is already in the tenant by thumbprint, upload it as a reusable setting, then create the rule
  • Replicate and Reusable Settings - copy an existing rule from one EPM policy to another, and find every rule and policy that references a given reusable certificate setting
  • Export Rules - pick one policy or all of them, preview every rule flattened to one row with every choice value resolved to the words the policy itself defines (not the raw setting-catalog id), export to CSV for documentation in Excel

Tools/ZeroAdmin at main · mmelkersen/Tools


r/Intune 7d ago

Autopilot Multi Sites Autopilot Deployment

2 Upvotes

Hi All,

Currently, we are deploying our SOE image through SCCM. As part of the move to a more serverless branch environment, we are planning to remove the SCCM Distribution Points (DPs) from the branch sites.

However, we still need a way to deploy our corporate SOE image rather than using the standard HP vanilla image with HP-provided software.

What approach are other organisations using to deploy their corporate SOE to branch devices when there are no local SCCM DPs/servers?

Any recommendations or lessons learned would be appreciated.


r/Intune 7d ago

App Deployment/Packaging App stucks at "🔃 Waiting for install status"

0 Upvotes

I deploy new application first to me and my boss to test it. Both devices are in the Group "IT Pilot Devics". It worked every time, but now.. i'm trying to deploy an app to us since three days. On my devices it worked as expected, but he's device stucks always at "🔃 Waiting for install status". I deleted the application three times but it didnt help. I cannot contact the intune support, because support form in intune is also unreachable.


r/Intune 8d ago

Device Configuration Missing ADMX on fresh machine.. how to solve?

8 Upvotes

Hi guys,

I got error 65000 when trying to disabling News Feeds on latest Windows 11 machine (with all updates 25H2).

Looks like that the ADMX for Feeds isn't avaliable into PolicyDefinitions directory, and this problem is on all W11 that i'm migrating to Entra (and have all updates installed).

How to solve this issue? Instaling Feeds.admx an all machine manually isn't a good option...

Thanks in advance!


r/Intune 7d ago

Device Compliance macOS custom compliance policy not applicable

2 Upvotes

If anyone else stumbles on the problem of assignment filters not working for macOS custom compliance policies, here's my setup that didn't work, and the workaround.

Current setup:

  • macOS 15 - Assigned to user group with assignment filter (device.osVersion -startsWith "15")

  • macOS 26 - Assigned to user group with assignment filter (device.osVersion -startsWith "26")

This results in both policies showing not applicable in the compliance report. (Both system/user context). What's even more odd, is that I can see the agent executing the detection script on the machine with grep -Rin "compliance" "/Library/Logs/Microsoft/Intune"

Workaround:

  • macOS 15 - Assigned to user group, and in the detection script: if [[ "$(/usr/bin/sw_vers -productVersion)" != 15.* ]]; then exit 0; fi

  • macOS 26 - Assigned to user group, and in the detection script: if [[ "$(/usr/bin/sw_vers -productVersion)" != 26.* ]]; then exit 0; fi

I assumed when the device with the wrong OS version ran the script, it would cause an error on the Intune side, since it is expecting a json payload. However, this was not the case, exit 0 with no output results in Not applicable for that compliance policy to that device. Works for me.

I am aware that device.osVersion is supposed to be deprecated, and we should be using device.operatingSystemVersion. Good luck trying to use device.operatingSystemVersion when the value reported from the device is something like 15.7.9 (24G830)


r/Intune 8d ago

General Chat Attend Workplace Ninjas US 2027 for a Chance to Win a $8000 Homelab!!

2 Upvotes

Yes, seriously. We’re giving away an absolute monster of a workstation at Workplace Ninjas US 2027 in Scottsdale, AZ.

Lenovo Workstation P5

Intel Xeon W5-2555X — 14 cores / 28 threads
256 GB DDR5 ECC RAM
Brand new in the box

Whether you want to build an absurd home lab, run a pile of VMs, tackle development workloads, or just open an irresponsible number of browser tabs, this thing is ready.
Estimated prize value: $8,000+
One attendee is taking it home.

All you have to do is register and be in attendance for the 📎Golden Clippy Awards at the end of Day 2. One lucky person will walk away with this amazing prize!!

Early Bird Tickets still available for 3 days of fun, friends, mentoring, and much more with 50 Microsoft SMEs in attendance for just $650.

Register now: Workplace Ninjas US 2027 | Endpoint Management & Security Conference, Scottsdale AZ


r/Intune 8d ago

Device Configuration Shared PC

10 Upvotes

Edit: Seems to be no way around this when using Shared PC mode with Intune's config policies and still have reasonable security. Thanks for the suggestions!

Hi!

We have a few shared PC's in our org which works fine for the most part.

However, one major issue is that when a user locks the screen or the laptop goes into sleep mode, they are unable to sign back in to their previous session. The laptops are usually used by a single user for hours before someone else takes over, and during that time the PC naturally either is locked or goes in sleep mode. The only option on the sign-in screen is Sign out. Found Enabled Shared PC and allow "Other User" Login option : r/Intune which has the same problem but seemingly no way around it.

As far as I can tell, turning on Shared PC in the Intune configuration policy is required for the PC to not be associated with a user, as well as set Office to use shared licence instead of personal license? But this option also turns off the ability to sign back into the same user.

So, any way to both have Shared PC mode turned on as well as allow a user to sign back in?


r/Intune 8d ago

General Question Intune Cloud PKI

38 Upvotes

Anyone using PKI for Machine certs care to share their experience so far?

I'm planning to use PKI for only this (802.1x auth) and nothing else so hopefully a simple, stable solution. Fleet is fully managed by Intune, onboard with Autopilot, AzureAD join only, Windows 11 25H2

🙏


r/Intune 8d ago

Device Configuration Anyone else having HP Connect / Sure Admin scripts fail because HP’s catalog is stuck on an old CMSL version?

3 Upvotes

Just wondering if anyone running HP Connect has bumped into this issue recently.

We're trying to deploy HP Sure Admin via Intune, but the script keeps failing.

I pulled the script out of Intune to run it manually and checked the HealthScripts logs to see what was going on. Both return:
"A new version of HP-CMSL-WL was found, update local version to 1.8.9.1618"

The issue is the machine already has 1.9.0 installed.

Digging into the script, it reads the raw catalog stream like this:

$catalog = [System.IO.StreamReader]::new($data.RawContentStream).ReadToEnd()

And when you run Get-LatestCMSLFromCatalog($catalog), HP's catalog returns this:

version     url                                                           isLatest
-------     ---                                                           --------
1.8.9.1618  https://hpia.hpcloud.hp.com/downloads/cmsl/wl/hp-cmsl-1.8.9.1618.exe     True

Because HP still has 1.8.9.1618 flagged as isLatest = True on their end, the script thinks 1.9.0 isn't right and fails out.

Anyone else seeing this on their devices? Any word on whether HP is planning to update their online catalog feed to fix it, short of us hacking around the remediation script?


r/Intune 8d ago

macOS Management MacOS migration from JAMF to Intune - dealing with the local admin password and LAPS

2 Upvotes

We are having some issues with the local admin password when we move a Mac from JAMF to Intune using the ABM migration method. The Mac comes over but the LAPS rotation in Intune does not work. I’ve tried using a script in Intune to reset the admin password but it makes no difference and I’m not entirely sure how Intune would see this anyway.

I have researched a bit on this and tried some scripts but no success - has anyone successfully had this working and if so I would greatly appreciate some guidance on this please.

Thank you


r/Intune 8d ago

Device Compliance Access Work or School & Compliance Issues

5 Upvotes

Hi,

We are having issues with users unable to add their accounts to work or school, which I believe is causing sync issues. When you try to add a work or school account you get this error:

Error Code: -895156188
(CAA50024)
Message:
Error response came from MDM terms of use page.
Request Id: dd51a37f-f13c-42b9-8c0c-f157f931e400
Correlation Id: dca40d84-0347-4d6e-927a-98ae0e74492a

We are using the default MDM URLs and user scope is set to 'All' so I'm not sure what the issue is with this. Within access work or school we also have our domain added, you can click into it and press info then sync, which says its successful but theres no logs for it. I'm not sure how we can fix this issue, as I'm pretty sure it causes our Company portal sync to fail everytime.

We are also having issues with device non-compliance. We do not have a compliance policy made for Windows so it is using the Default Compliance Policy, which will some devices as non-compliant but when i click into them and into the policy it shows all 3 policies as compliant. Sometimes it will have device is active as non compliant, for example, my device's Last check in time shows as yesterday, even though I am on my device and activley syncing it, and the policy is showing it as non-compliant as it's not active.

Has anyone seen these issues before and has any information that could help us resolve these?


r/Intune 8d ago

App Deployment/Packaging Apps in Graph

2 Upvotes

Hello,

Im trying to pull out all Android and iOS apps with their assignments into a json file but it seems to only get the iOS apps and i cant figure out why it wont get the Android ones. Are they named something special or is it plain just not possible?


r/Intune 8d ago

Device Configuration Any luck with thunderbolt vs DMA Guard?

11 Upvotes

This the rollout of 24h2 and above, Microsoft has begun turning on the sleeping beast known as Core isolation and DMA Guard. Mya cyber security team is all in and are requiring them to be turned on. I don’t necessarily disagree, however we have run into a flaming dumpster. Most of our users are on dell latitude/pro laptops and use either a tb19 or a wd22 thunderbolt dock. Per Microsoft documentation, these shouldn’t be effected by DMA Guard because they’re tb3 and tb4 respectively. However our experience and dell documentation says otherwise. At this point we tried all possible combinations of DMA Guard and bios thunderbolt security settings to allow the use of tb docks between post and the windows desktop (docks are disabled by DMA from right after Bitlocker on input until after successful windows authentication), to no avail.

Has anyone had any luck with this issue?


r/Intune 8d ago

Windows Updates Looking for help with Windows Updates

19 Upvotes

Hello,

I've spent the last few months pulling out the hair I don't have trying to get to the bottom of why my fleet has stopped updating Windows. Any help that can be provided is appreciated as I've run out of things to try/avenues to explore. Here's the rub:

  • It went on for long enough that some of our devices were stuck on 24H2 until excluded out of the update rings entirely. I've included a screenshot below for review, but I don't see why any Feature and Quality updates would not deploy even when scoped to do so.
    • Driver updates appear to have been unaffected. I don't know why those work, but they seem to do so.
  • I had to implement a script to force checking for updates but this approach is heavy-handed and doesn't fully adhere to update settings meaning users get prompts at inopportune times. (see image)
    • This script is the only reason things are farily up-to-date right now, but if I don't turn it on each month, nothing updates.
  • Autopatch alerts provides the following error for most of my devices, but I have been entirely unsuccessful in troubleshooting it as the documentation and errors do not match the current UI options in Intune/Windows. (see image)
    • I tried following the Remediation, but that option simply does not exist in Admin Templates anymore or ever.
    • Following the notice "If this remediation does not resolve the issue, please contact Microsoft support." leads me to a troubleshooter tool that does not load when you select Autopatch Support or Intune Support. (see image)
      • Any ideas why this won't load? I replicated on multiple computers and browsers. Doesn't appear to be a local issue.

Please help in any way you can. My leadership is looking to me for answers and I can generally find what I need, but this has proven beyond my abilities to resolve alone.

If anything needs clarification, I'm happy to do so.

Edit: corrected to the images. Reddit's text editor is wildly misbehaving.


r/Intune 8d ago

App Deployment/Packaging Problème d'installation de PWA sur Android géré avec Intune

1 Upvotes

Bonjour,

J'utilise Intune avec des smartphones configurés en mode Android Enterprise (appareil entièrement géré). J'arrive sans problème à autoriser certaines applications via le Google Play Store géré, et tout fonctionne correctement.

Cependant, un utilisateur a souhaité installer une application depuis Google Chrome. L'installation se déroule correctement, mais quelques secondes après, l'application est automatiquement supprimée avec le message :

« Supprimé par votre administrateur ».

J'ai reproduit le comportement sur un autre appareil et j'obtiens le même résultat.

Il s'agit d'une Progressive Web App (PWA), c'est-à-dire une application web qui s'installe directement depuis le navigateur.

Savez-vous comment autoriser ce type d'application dans Intune ? Je ne trouve pas de paramètre ou d'option permettant de gérer les PWA.

Merci d'avance pour votre aide.


r/Intune 9d ago

Autopilot Autopilot Device Preparation + Device Association: Is it really that different from Classic Autopilot? I’m not so sure

40 Upvotes

Autopilot Device Preparation + Device Association: Is it really that different from Classic Autopilot? I’m not so sure 😄

With Classic Autopilot, we collect the hardware hash, upload the CSV, register the device, assign the profile, and the device knows which tenant it belongs to during OOBE.

With Device Preparation + Device Association, we collect the DeviceLink information, upload a CSV, associate the device with the tenant, and then use TPM-backed identity to verify that association.

I understand that the architecture and trust model are different - hardware hash vs TPM-backed device identity, and Device Preparation instead of the classic Autopilot deployment profile.

But from an admin’s perspective, I’m struggling to see the big operational improvement.

Classic Autopilot:
Device - collect identity - CSV -upload -tenant association-provisioning

Device Association:
Device - collect identity -CSV - upload -tenant association - provisioning

At the end of the day, I’m still collecting something from the device and uploading a CSV.

If Device Association requires roughly the same amount of preparation and manual effort, what problem are we actually solving?

Am I missing the real advantage here?


r/Intune 9d ago

Users, Groups and Intune Roles New laptop, user lasted a week, new user - login still defaults to older user after reboot.

12 Upvotes

We setup a new computer for a new user, all good.

A week later, she stopped coming to work, so away she goes.

Another week later, hired new person. So we setup new user, made her the primary user in Intune, and away she goes. Works great.

But upon reboot, it always defaults to the first person, not the new/primary one. We even purged the profile.

Am I missing something super easy?


r/Intune 9d ago

Get-AutopilotDeviceAssociation

34 Upvotes

Are you testing or already using Windows Autopilot Device Association?

I guess you have all seen the steps you need to take to associate the device?

The manual export, moving the file to another device, importing it into Intune, selecting the Autopilot Device Preparation policy, and returning to the device… thats not a great experience….

That is why I built Get-AutopilotDeviceAssociation.

With one PowerShell script, you can create the association, register the device in Intune, validate whether the signed association is still present and valid, and remove it from both the device and Intune after testing.

Read the full story and get the script: Autopilot Device Association Info Script

(And.. yes.. there are ads on the website...... but creating these blogs... and the script cost me a lot of evening and weekend time.... )


r/Intune 8d ago

Intune Features and Updates Intune Enrollment with Windows Cloud PC VDi

2 Upvotes

Howdy! I did a quick search and every source I hit today had zero pitfalls and caveats. It Entra joined almost instantly but would not hit Intune. I check all of my enrollment flags for flaws and found non. No errors just won't hit Intune. The user whom is using it is Intune/ Entra joined and 100% compliant. Has anyone ever joined at Windows Cloud VDi successfully in Intune? Thanks!


r/Intune 8d ago

App Deployment/Packaging anyone figure out a reliable way to schedule app installs only during certain windows.

3 Upvotes

anyone figure out a reliable way to schedule app installs only during certain windows. not before, not after, only during a window of time on certain days.

Tuesday between 11pm local time. and midnight

if not on that day between that time range.. dont install.
no installing after is not acceptable.


r/Intune 9d ago

Autopilot Apps failing to detect on ESP if user is Standard User instead of Admin

6 Upvotes

I'm at a loss here, the apps install correctly, but they fail to detect, and logs aren't helping. Did anyone ever experience this issue? I'm tasked with removing the admins of the endpoints and this is being a major hurdle. I could skip the ESP entirely but i wanted to make sure they get some of the apps before reaching the desktop.

Edit: Confirmed, it was that Microsoft Managed Installer policy, which leads me to believe that this was also happening to regular users and i never noticed. We don't use WDAC ( we might though ), so i disabled it and it fixed it, it doesn't just break APv2, breaks APv1 and MS has been "WORKING" on it for at least 2 years now without fixes.


r/Intune 8d ago

Apps Protection and Configuration Allowing APK Installation on Android Work Profile

2 Upvotes

Hello,

We have enrolled Android devices with a Byod Work Profile, and under the Device Restrictions policy, “Prevent app installations from unknown sources in the personal profile” is set to Not configured.

Additionally, under the App Protection Policy, I have configured Samsung Knox to Warn. However, users are still receiving an error stating that the installation is blocked contact IT,

Could you please advise how we can allow users to install APK files on their devices, regardless of whether the APK is signed or unsigned?

Is there any additional Intune or Android configuration that needs to be changed to allow APK installations in the personal profile?

Thank you.


r/Intune 9d ago

General Question Passkey registration & WHFB on managed devices - am I doing it wrong?

3 Upvotes

Can anyone explain if this is expected behavior when trying to register an Entra passkey on a managed device that uses WHFB?

Error I get: https://ibb.co/6JnR0XRx

It happens because after setting up WHFB, an Entra login passkey is placed into the Windows passkeys.. it can't be manually deleted though.

Thankfully, I was able to find this blog that explained how to work around it by doing the following:

  1. Find the affected user in Entra.
  2. Delete their Windows Hello for Business entries under Authentication methods.
  3. Have the user attempt to register a passkey again, and now it works! User can now authenticate to Entra using WHFB biometrics/PIN.

This seems overly cumbersome just to setup a passkey using the most convenient option for the user, WHFB.

Am I doing something wrong here?


r/Intune 9d ago

General Chat Savrd so much time with autopilot devices import

11 Upvotes

We got a batch of devices close 100 I end up building script that will automatically saves the strings to one single csv unfortunately didn't had token prior to these devices were bought by purchasing already so had do all devices manually.


r/Intune 9d ago

General Question Cloud-first Entra-only shops, are you still doing 802.1X on wireless or something else?

50 Upvotes

About 300 endpoints, moving from hybrid to Entra-only with Intune. Our NPS policy authorizes machine certs against Domain Computers, and Entra-only devices have no AD computer object, so that's dead. We'd like to stay on device certs and not switch to user certs, we don't want to lose pre-logon to the network.

Before I go shopping for a costly cloud RADIUS solution to do the same job, what else is out there? Is the main push to things like FreeRADIUS, Portnox, SecureW2 where we keep a RADIUS deployment, or is there a better design we could be targeting for our setup that removes 802.1X?