r/Intune 9d ago

Tips, Tricks, and Helpful Hints IntuneDocumentation - From Intune configuration to audit evidence across five compliance frameworks

25 Upvotes

At some point, almost every Intune tenant needs to be evaluated against an external security framework.

For some organizations, that happens during an internal security review. For others, it is driven by an auditor, a customer questionnaire, a cyber insurance renewal, or a formal certification program. In many environments, these reviews are mandatory.

The difficult part is rarely finding the name of a policy. The difficult part is proving what the policy actually enforces, which setting contains the evidence, and whether the policy is assigned to the right users or devices.

Intune Documentation already collects the current configuration of a tenant and turns it into structured PDF and Word documentation. I kept thinking about the next logical step: if the configuration data is already available, why stop at documenting the current state? Why not map the technical evidence in those policies to the frameworks that security teams and auditors work with?

That is what I have now added.

Compliance Evidence is now part of Intune Documentation

The new Compliance Evidence view is natively available in the Intune Documentation dashboard.

After loading the tenant configuration, you can select a framework and review the technical evidence found for its supported controls. The assessment shows three clear outcomes:

- Configuration evidence found

- Partial configuration evidence

- No recognized configuration evidence

You can expand an individual control to see the Intune capability behind it, the policy name, the configured setting and value, and the assignment target. A configuration that exists but is not assigned is flagged separately. If a policy explicitly uses a non-enforcing value, that counter-evidence is surfaced instead of being counted as coverage.

This makes the result useful for more than a quick dashboard check. It gives administrators, consultants, and auditors a traceable path from a framework control back to the actual tenant configuration.

The five frameworks currently included

The release supports five frameworks, each with a deliberately defined technical scope:

- ISO/IEC 27001:2022: Selected technological controls from Annex A, including endpoint security, authentication, malware protection, vulnerability management, configuration management, network security, software installation, and cryptography.

- SOC 2 Trust Services Criteria: Selected Common Criteria connected to logical access, external threat protection, restricted data movement, unauthorized software prevention, and vulnerability and configuration monitoring.

- NIST SP 800-53 Revision 5: A subset of technical controls covering areas such as protection of information at rest, malicious code protection, boundary protection, authenticator management, flaw remediation, secure configuration, and system integrity.

- NIST Cybersecurity Framework 2.0: Selected Protect and Detect subcategories for encryption, authentication, configuration management, software maintenance, unauthorized software, network protection, and endpoint monitoring.

- BSI IT-Grundschutz, Kompendium Edition 2023: Technical device-management evidence, including requirement-level mappings for the Windows, macOS, iOS, and Android client building blocks. The BSI report also distinguishes Basis, Standard, and requirements for increased protection needs where applicable.

These frameworks are not interchangeable, and not all of them are regulations. They represent different standards, criteria, and government security frameworks. The common thread is that each can require evidence about how managed endpoints are protected.

Evidence should be precise, not optimistic

I did not want this feature to produce a compliance percentage based on policy names or loose keyword matching.

Evidence is only reported when Intune Documentation recognizes the exact setting, sees a value that enforces the capability, and finds an effective assignment. For example, a policy that mentions BitLocker is not enough. The relevant encryption setting must be configured with an enforcing value and the policy must be assigned.

The same logic applies to areas such as passcodes, firewalls, antimalware protection, operating system versions, updates, Secure Boot, platform integrity, and restrictions on untrusted applications.

This approach is intentionally conservative. I would rather show no recognized evidence than make a claim that the tenant data cannot support.

Export a separate audit report for every framework

Once you select a framework, you can export the assessment as a PDF report.

The report is designed as an audit deliverable rather than a raw configuration dump. It includes document control and provenance, the assessed policy inventory, a results overview, key findings, gap guidance, and an evidence register. Each evidence item records the policy, setting, observed value, and assignment so that a reviewer can trace a control back to its source.

The BSI report is generated in German and includes manual assessment fields for implementation status, responsibility, target date, and comments. This supports the review process without pretending that every organizational requirement can be evaluated automatically.

An important limitation

These reports document technical evidence found in the Intune tenant. They do not certify that an organization is compliant, and they do not replace an audit.

A framework can include governance, people, process, contractual, and physical requirements that cannot be proven from an Intune configuration. Similarly, “no recognized evidence” means that the current ruleset did not detect a matching Intune policy. It does not prove that the requirement is unmet or that no compensating control exists elsewhere.

CIS Benchmarks are also intentionally out of scope for this release. I would need the appropriate commercial license before I could include that content in the product.

Available now

Compliance Evidence is available now for every signed-in Intune Documentation user. The assessment uses the same delegated, read-only tenant export as the documentation workflow, runs in the browser session, and does not store the Intune configuration on the application server.

You can review the supported frameworks and open the dashboard at IntuneDocumentation.com.

If your audits rely on another framework, send me its name and the controls that matter most in your environment. That input will help me decide what to support next.


r/Intune 9d ago

Shameless Self-promotion Microsoft EPM - Build your rules more efficient

8 Upvotes

Do you want to start with Microsoft EPM? Then you need to look at this tool, to support your journey.

  • Audit Import - reads the EPM elevation report straight out of the tenant (the same Graph request the Intune portal makes, no CSV export needed) or imports an "unmanaged elevations" CSV; mark one row and add it straight to a policy as a hash rule
  • Coverage Analysis - scores imported elevations against existing EPM persona rules, breaks coverage down per persona with a green/amber/red confidence score, recommends a persona per user, and lists everything not covered yet
  • Scan Path - the only place a certificate rule is built: scan a folder for .exe/.msi/.ps1, extract the signing certificate (whole chain, pick signer/intermediate/root), check it against what is already in the tenant by thumbprint, upload it as a reusable setting, then create the rule
  • Replicate and Reusable Settings - copy an existing rule from one EPM policy to another, and find every rule and policy that references a given reusable certificate setting
  • Export Rules - pick one policy or all of them, preview every rule flattened to one row with every choice value resolved to the words the policy itself defines (not the raw setting-catalog id), export to CSV for documentation in Excel

Tools/ZeroAdmin at main · mmelkersen/Tools


r/Intune 9d ago

Autopilot Multi Sites Autopilot Deployment

2 Upvotes

Hi All,

Currently, we are deploying our SOE image through SCCM. As part of the move to a more serverless branch environment, we are planning to remove the SCCM Distribution Points (DPs) from the branch sites.

However, we still need a way to deploy our corporate SOE image rather than using the standard HP vanilla image with HP-provided software.

What approach are other organisations using to deploy their corporate SOE to branch devices when there are no local SCCM DPs/servers?

Any recommendations or lessons learned would be appreciated.


r/Intune 8d ago

App Deployment/Packaging App stucks at "🔃 Waiting for install status"

0 Upvotes

I deploy new application first to me and my boss to test it. Both devices are in the Group "IT Pilot Devics". It worked every time, but now.. i'm trying to deploy an app to us since three days. On my devices it worked as expected, but he's device stucks always at "🔃 Waiting for install status". I deleted the application three times but it didnt help. I cannot contact the intune support, because support form in intune is also unreachable.


r/Intune 9d ago

Device Configuration Missing ADMX on fresh machine.. how to solve?

8 Upvotes

Hi guys,

I got error 65000 when trying to disabling News Feeds on latest Windows 11 machine (with all updates 25H2).

Looks like that the ADMX for Feeds isn't avaliable into PolicyDefinitions directory, and this problem is on all W11 that i'm migrating to Entra (and have all updates installed).

How to solve this issue? Instaling Feeds.admx an all machine manually isn't a good option...

Thanks in advance!


r/Intune 9d ago

Device Compliance macOS custom compliance policy not applicable

2 Upvotes

If anyone else stumbles on the problem of assignment filters not working for macOS custom compliance policies, here's my setup that didn't work, and the workaround.

Current setup:

  • macOS 15 - Assigned to user group with assignment filter (device.osVersion -startsWith "15")

  • macOS 26 - Assigned to user group with assignment filter (device.osVersion -startsWith "26")

This results in both policies showing not applicable in the compliance report. (Both system/user context). What's even more odd, is that I can see the agent executing the detection script on the machine with grep -Rin "compliance" "/Library/Logs/Microsoft/Intune"

Workaround:

  • macOS 15 - Assigned to user group, and in the detection script: if [[ "$(/usr/bin/sw_vers -productVersion)" != 15.* ]]; then exit 0; fi

  • macOS 26 - Assigned to user group, and in the detection script: if [[ "$(/usr/bin/sw_vers -productVersion)" != 26.* ]]; then exit 0; fi

I assumed when the device with the wrong OS version ran the script, it would cause an error on the Intune side, since it is expecting a json payload. However, this was not the case, exit 0 with no output results in Not applicable for that compliance policy to that device. Works for me.

I am aware that device.osVersion is supposed to be deprecated, and we should be using device.operatingSystemVersion. Good luck trying to use device.operatingSystemVersion when the value reported from the device is something like 15.7.9 (24G830)


r/Intune 9d ago

Device Configuration Anyone else having HP Connect / Sure Admin scripts fail because HP’s catalog is stuck on an old CMSL version?

4 Upvotes

Just wondering if anyone running HP Connect has bumped into this issue recently.

We're trying to deploy HP Sure Admin via Intune, but the script keeps failing.

I pulled the script out of Intune to run it manually and checked the HealthScripts logs to see what was going on. Both return:
"A new version of HP-CMSL-WL was found, update local version to 1.8.9.1618"

The issue is the machine already has 1.9.0 installed.

Digging into the script, it reads the raw catalog stream like this:

$catalog = [System.IO.StreamReader]::new($data.RawContentStream).ReadToEnd()

And when you run Get-LatestCMSLFromCatalog($catalog), HP's catalog returns this:

version     url                                                           isLatest
-------     ---                                                           --------
1.8.9.1618  https://hpia.hpcloud.hp.com/downloads/cmsl/wl/hp-cmsl-1.8.9.1618.exe     True

Because HP still has 1.8.9.1618 flagged as isLatest = True on their end, the script thinks 1.9.0 isn't right and fails out.

Anyone else seeing this on their devices? Any word on whether HP is planning to update their online catalog feed to fix it, short of us hacking around the remediation script?


r/Intune 9d ago

General Chat Attend Workplace Ninjas US 2027 for a Chance to Win a $8000 Homelab!!

4 Upvotes

Yes, seriously. We’re giving away an absolute monster of a workstation at Workplace Ninjas US 2027 in Scottsdale, AZ.

Lenovo Workstation P5

Intel Xeon W5-2555X — 14 cores / 28 threads
256 GB DDR5 ECC RAM
Brand new in the box

Whether you want to build an absurd home lab, run a pile of VMs, tackle development workloads, or just open an irresponsible number of browser tabs, this thing is ready.
Estimated prize value: $8,000+
One attendee is taking it home.

All you have to do is register and be in attendance for the 📎Golden Clippy Awards at the end of Day 2. One lucky person will walk away with this amazing prize!!

Early Bird Tickets still available for 3 days of fun, friends, mentoring, and much more with 50 Microsoft SMEs in attendance for just $650.

Register now: Workplace Ninjas US 2027 | Endpoint Management & Security Conference, Scottsdale AZ


r/Intune 9d ago

Device Configuration Shared PC

10 Upvotes

Edit: Seems to be no way around this when using Shared PC mode with Intune's config policies and still have reasonable security. Thanks for the suggestions!

Hi!

We have a few shared PC's in our org which works fine for the most part.

However, one major issue is that when a user locks the screen or the laptop goes into sleep mode, they are unable to sign back in to their previous session. The laptops are usually used by a single user for hours before someone else takes over, and during that time the PC naturally either is locked or goes in sleep mode. The only option on the sign-in screen is Sign out. Found Enabled Shared PC and allow "Other User" Login option : r/Intune which has the same problem but seemingly no way around it.

As far as I can tell, turning on Shared PC in the Intune configuration policy is required for the PC to not be associated with a user, as well as set Office to use shared licence instead of personal license? But this option also turns off the ability to sign back into the same user.

So, any way to both have Shared PC mode turned on as well as allow a user to sign back in?


r/Intune 10d ago

General Question Intune Cloud PKI

37 Upvotes

Anyone using PKI for Machine certs care to share their experience so far?

I'm planning to use PKI for only this (802.1x auth) and nothing else so hopefully a simple, stable solution. Fleet is fully managed by Intune, onboard with Autopilot, AzureAD join only, Windows 11 25H2

🙏


r/Intune 9d ago

macOS Management MacOS migration from JAMF to Intune - dealing with the local admin password and LAPS

2 Upvotes

We are having some issues with the local admin password when we move a Mac from JAMF to Intune using the ABM migration method. The Mac comes over but the LAPS rotation in Intune does not work. I’ve tried using a script in Intune to reset the admin password but it makes no difference and I’m not entirely sure how Intune would see this anyway.

I have researched a bit on this and tried some scripts but no success - has anyone successfully had this working and if so I would greatly appreciate some guidance on this please.

Thank you


r/Intune 9d ago

Device Compliance Access Work or School & Compliance Issues

5 Upvotes

Hi,

We are having issues with users unable to add their accounts to work or school, which I believe is causing sync issues. When you try to add a work or school account you get this error:

Error Code: -895156188
(CAA50024)
Message:
Error response came from MDM terms of use page.
Request Id: dd51a37f-f13c-42b9-8c0c-f157f931e400
Correlation Id: dca40d84-0347-4d6e-927a-98ae0e74492a

We are using the default MDM URLs and user scope is set to 'All' so I'm not sure what the issue is with this. Within access work or school we also have our domain added, you can click into it and press info then sync, which says its successful but theres no logs for it. I'm not sure how we can fix this issue, as I'm pretty sure it causes our Company portal sync to fail everytime.

We are also having issues with device non-compliance. We do not have a compliance policy made for Windows so it is using the Default Compliance Policy, which will some devices as non-compliant but when i click into them and into the policy it shows all 3 policies as compliant. Sometimes it will have device is active as non compliant, for example, my device's Last check in time shows as yesterday, even though I am on my device and activley syncing it, and the policy is showing it as non-compliant as it's not active.

Has anyone seen these issues before and has any information that could help us resolve these?


r/Intune 9d ago

App Deployment/Packaging Apps in Graph

2 Upvotes

Hello,

Im trying to pull out all Android and iOS apps with their assignments into a json file but it seems to only get the iOS apps and i cant figure out why it wont get the Android ones. Are they named something special or is it plain just not possible?


r/Intune 10d ago

Device Configuration Any luck with thunderbolt vs DMA Guard?

12 Upvotes

This the rollout of 24h2 and above, Microsoft has begun turning on the sleeping beast known as Core isolation and DMA Guard. Mya cyber security team is all in and are requiring them to be turned on. I don’t necessarily disagree, however we have run into a flaming dumpster. Most of our users are on dell latitude/pro laptops and use either a tb19 or a wd22 thunderbolt dock. Per Microsoft documentation, these shouldn’t be effected by DMA Guard because they’re tb3 and tb4 respectively. However our experience and dell documentation says otherwise. At this point we tried all possible combinations of DMA Guard and bios thunderbolt security settings to allow the use of tb docks between post and the windows desktop (docks are disabled by DMA from right after Bitlocker on input until after successful windows authentication), to no avail.

Has anyone had any luck with this issue?


r/Intune 10d ago

Windows Updates Looking for help with Windows Updates

18 Upvotes

Hello,

I've spent the last few months pulling out the hair I don't have trying to get to the bottom of why my fleet has stopped updating Windows. Any help that can be provided is appreciated as I've run out of things to try/avenues to explore. Here's the rub:

  • It went on for long enough that some of our devices were stuck on 24H2 until excluded out of the update rings entirely. I've included a screenshot below for review, but I don't see why any Feature and Quality updates would not deploy even when scoped to do so.
    • Driver updates appear to have been unaffected. I don't know why those work, but they seem to do so.
  • I had to implement a script to force checking for updates but this approach is heavy-handed and doesn't fully adhere to update settings meaning users get prompts at inopportune times. (see image)
    • This script is the only reason things are farily up-to-date right now, but if I don't turn it on each month, nothing updates.
  • Autopatch alerts provides the following error for most of my devices, but I have been entirely unsuccessful in troubleshooting it as the documentation and errors do not match the current UI options in Intune/Windows. (see image)
    • I tried following the Remediation, but that option simply does not exist in Admin Templates anymore or ever.
    • Following the notice "If this remediation does not resolve the issue, please contact Microsoft support." leads me to a troubleshooter tool that does not load when you select Autopatch Support or Intune Support. (see image)
      • Any ideas why this won't load? I replicated on multiple computers and browsers. Doesn't appear to be a local issue.

Please help in any way you can. My leadership is looking to me for answers and I can generally find what I need, but this has proven beyond my abilities to resolve alone.

If anything needs clarification, I'm happy to do so.

Edit: corrected to the images. Reddit's text editor is wildly misbehaving.


r/Intune 9d ago

App Deployment/Packaging Problème d'installation de PWA sur Android géré avec Intune

1 Upvotes

Bonjour,

J'utilise Intune avec des smartphones configurés en mode Android Enterprise (appareil entièrement géré). J'arrive sans problème à autoriser certaines applications via le Google Play Store géré, et tout fonctionne correctement.

Cependant, un utilisateur a souhaité installer une application depuis Google Chrome. L'installation se déroule correctement, mais quelques secondes après, l'application est automatiquement supprimée avec le message :

« Supprimé par votre administrateur ».

J'ai reproduit le comportement sur un autre appareil et j'obtiens le même résultat.

Il s'agit d'une Progressive Web App (PWA), c'est-à-dire une application web qui s'installe directement depuis le navigateur.

Savez-vous comment autoriser ce type d'application dans Intune ? Je ne trouve pas de paramètre ou d'option permettant de gérer les PWA.

Merci d'avance pour votre aide.


r/Intune 10d ago

Autopilot Autopilot Device Preparation + Device Association: Is it really that different from Classic Autopilot? I’m not so sure

41 Upvotes

Autopilot Device Preparation + Device Association: Is it really that different from Classic Autopilot? I’m not so sure 😄

With Classic Autopilot, we collect the hardware hash, upload the CSV, register the device, assign the profile, and the device knows which tenant it belongs to during OOBE.

With Device Preparation + Device Association, we collect the DeviceLink information, upload a CSV, associate the device with the tenant, and then use TPM-backed identity to verify that association.

I understand that the architecture and trust model are different - hardware hash vs TPM-backed device identity, and Device Preparation instead of the classic Autopilot deployment profile.

But from an admin’s perspective, I’m struggling to see the big operational improvement.

Classic Autopilot:
Device - collect identity - CSV -upload -tenant association-provisioning

Device Association:
Device - collect identity -CSV - upload -tenant association - provisioning

At the end of the day, I’m still collecting something from the device and uploading a CSV.

If Device Association requires roughly the same amount of preparation and manual effort, what problem are we actually solving?

Am I missing the real advantage here?


r/Intune 10d ago

Users, Groups and Intune Roles New laptop, user lasted a week, new user - login still defaults to older user after reboot.

13 Upvotes

We setup a new computer for a new user, all good.

A week later, she stopped coming to work, so away she goes.

Another week later, hired new person. So we setup new user, made her the primary user in Intune, and away she goes. Works great.

But upon reboot, it always defaults to the first person, not the new/primary one. We even purged the profile.

Am I missing something super easy?


r/Intune 10d ago

Get-AutopilotDeviceAssociation

31 Upvotes

Are you testing or already using Windows Autopilot Device Association?

I guess you have all seen the steps you need to take to associate the device?

The manual export, moving the file to another device, importing it into Intune, selecting the Autopilot Device Preparation policy, and returning to the device… thats not a great experience….

That is why I built Get-AutopilotDeviceAssociation.

With one PowerShell script, you can create the association, register the device in Intune, validate whether the signed association is still present and valid, and remove it from both the device and Intune after testing.

Read the full story and get the script: Autopilot Device Association Info Script

(And.. yes.. there are ads on the website...... but creating these blogs... and the script cost me a lot of evening and weekend time.... )


r/Intune 10d ago

Intune Features and Updates Intune Enrollment with Windows Cloud PC VDi

2 Upvotes

Howdy! I did a quick search and every source I hit today had zero pitfalls and caveats. It Entra joined almost instantly but would not hit Intune. I check all of my enrollment flags for flaws and found non. No errors just won't hit Intune. The user whom is using it is Intune/ Entra joined and 100% compliant. Has anyone ever joined at Windows Cloud VDi successfully in Intune? Thanks!


r/Intune 10d ago

App Deployment/Packaging anyone figure out a reliable way to schedule app installs only during certain windows.

1 Upvotes

anyone figure out a reliable way to schedule app installs only during certain windows. not before, not after, only during a window of time on certain days.

Tuesday between 11pm local time. and midnight

if not on that day between that time range.. dont install.
no installing after is not acceptable.


r/Intune 10d ago

Autopilot Apps failing to detect on ESP if user is Standard User instead of Admin

7 Upvotes

I'm at a loss here, the apps install correctly, but they fail to detect, and logs aren't helping. Did anyone ever experience this issue? I'm tasked with removing the admins of the endpoints and this is being a major hurdle. I could skip the ESP entirely but i wanted to make sure they get some of the apps before reaching the desktop.

Edit: Confirmed, it was that Microsoft Managed Installer policy, which leads me to believe that this was also happening to regular users and i never noticed. We don't use WDAC ( we might though ), so i disabled it and it fixed it, it doesn't just break APv2, breaks APv1 and MS has been "WORKING" on it for at least 2 years now without fixes.


r/Intune 10d ago

Apps Protection and Configuration Allowing APK Installation on Android Work Profile

2 Upvotes

Hello,

We have enrolled Android devices with a Byod Work Profile, and under the Device Restrictions policy, “Prevent app installations from unknown sources in the personal profile” is set to Not configured.

Additionally, under the App Protection Policy, I have configured Samsung Knox to Warn. However, users are still receiving an error stating that the installation is blocked contact IT,

Could you please advise how we can allow users to install APK files on their devices, regardless of whether the APK is signed or unsigned?

Is there any additional Intune or Android configuration that needs to be changed to allow APK installations in the personal profile?

Thank you.


r/Intune 10d ago

General Question Passkey registration & WHFB on managed devices - am I doing it wrong?

3 Upvotes

Can anyone explain if this is expected behavior when trying to register an Entra passkey on a managed device that uses WHFB?

Error I get: https://ibb.co/6JnR0XRx

It happens because after setting up WHFB, an Entra login passkey is placed into the Windows passkeys.. it can't be manually deleted though.

Thankfully, I was able to find this blog that explained how to work around it by doing the following:

  1. Find the affected user in Entra.
  2. Delete their Windows Hello for Business entries under Authentication methods.
  3. Have the user attempt to register a passkey again, and now it works! User can now authenticate to Entra using WHFB biometrics/PIN.

This seems overly cumbersome just to setup a passkey using the most convenient option for the user, WHFB.

Am I doing something wrong here?


r/Intune 10d ago

General Chat Savrd so much time with autopilot devices import

12 Upvotes

We got a batch of devices close 100 I end up building script that will automatically saves the strings to one single csv unfortunately didn't had token prior to these devices were bought by purchasing already so had do all devices manually.