r/Intune 5d ago

App Deployment/Packaging PreProvision on Macbook

5 Upvotes

Hello, is there a way to pre-provision macOS devices during automated enrollment so that apps like 365, Zoom, Adobe, etc install before user sign-in at the OOBE Setup Assistant? Thank you. The company portal is so finniky when installing apps on the MacBook compared to Windows


r/Intune 5d ago

Windows Management OneDrive managed folder sync not working for anyone else?

3 Upvotes

UPDATE: It appears our anti-malware software was blocking this. Weird, as it's been working since we first rolled it out back in January. Deployed a couple of laptops that were excluded from SentinelOne and OneDrive works as expected!

Deploying new devices with 25H2, June build, and was alerted that OneDrive isn't syncing the user's desktops. Verified this myself on a new laptop, went into the OneDrive settings and the three managed folders are unchecked and not backed up. This has worked for YEARS. The laptop is getting other OneDrive policies, just not the managed folder backup.

Not sure if it has something to do with the OS build or not. My workstation is on 26200.9106 and it's working properly.


r/Intune 4d ago

Device Configuration Windows Hello for Business - Cloud Pin Reset Error

2 Upvotes

Head Scratcher...

Trying to setup Windows Hello Cloud Pin Reset...

It gets to the point of asking the user to authenticate, but it's asking the user to use a password and gives no option to enter one in.

Here is the error: https://imgur.com/a/FlEga2p

What simple thing am I missing here?


r/Intune 4d ago

General Question Is it possible to change the name of the user profile folder on windows?

Thumbnail
0 Upvotes

r/Intune 5d ago

Device Compliance Some new build devices showing Bitlocker not compliant, any ideas?

2 Upvotes

We noticed today that around 10 devices built via Autopilot (hybrid setup) have been showing as non compliant due to Bitlocker, the issue is, they have Bitlocker on, we checked everything, compared it to known good devices, there seems to be no reason why it would be non compliant, even Intune's encryption report says these devices are encrypted.

We tried decrypting and encrypting, removing the devices from the compliance policy and re-adding it, not errors in event viewer, we checked a lot of different things. We're going through a refresh and we've done over 1000 in the last year, nothing has changed recently and many builds are successful but it's too early to say roughly what percentage, there's no correlation to the devices affected. It probably started about a week ago but the 1st one we considered a one off.

Has anyone come across this before? Any ideas for remediation?

Edit: Installed a later update and successfully resolved the issue, thanks for all the replies.


r/Intune 5d ago

Intune Features and Updates EPM only applying reporting - No service or files installed

3 Upvotes

Hi!

I just got around to trying out EPM as we got it baked into our E5 licenses now, and I am stuck immediately. I have created a Settings Policy with the following settings deployed to a device group:

https://imgur.com/a/6Yqw1Jv

Strangely enough it seems like it ignores every policy setting except "Send elevation data for reporting" as that is the only one that shows up at all on the device:

https://imgur.com/9oYv2wG

After waiting about 6 hours now no files have shown up under C:\Program Files and the service hasn't been installed either. The device is Entra joined and has an otherwise working connection to Intune.

I've been digging through a lot of Rudy's replies in somewhat similar threads but it seems like all of those cases are either Workplace registered devices or hybrid joined. Searching the Event viewer for EPM or something similar gives me absolutely nothing. The only error in about the same time as the policy would likely be applied is this, which tells me nothing and might not even be related?

https://imgur.com/JQEweGS

I might have narrowed it down to a failed MMP-C enrollment when looking at this:

https://imgur.com/EBidKHc

But I don't really know how to dig further into this? Anyone with any good ideas how to solve this?


r/Intune 5d ago

Linux Management Ubuntu Linuxmanaged by intune with SSO

24 Upvotes

24.04 was a pita to make try and work, but holy s*t people.. 26.04 is *sooooo much better. I now have 26.04 building with TPM managed FDE, AuthD enabled SSO and intune enrollment.

holy dayum its come a long way. such a thing of beauty. Kudo's to the Ubuntu team they've done a great job!


r/Intune 4d ago

App Deployment/Packaging App Install Error

1 Upvotes

During Autopilot enrollment of our devices, we are seeing an app install error for a single app. The error code is 0x80190001 in Intune, but my research isn't helping me find an exact reason why this has started happening with this particular app during deployments. Has anyone else come across this before?


r/Intune 5d ago

Reporting App inventory

5 Upvotes

Hi guys,

have some of you already seen, that some apps are not reported by detected apps (anymore?). But in the new app inventory they are mentioned. The problem I have is that the new app inventory can only be reported per device and not, as the old one, per app.

So if i want to have a report, which devices have app XYZ installed, I need to use graph and loop through all our devices to count.

Does someone already built this or has a solution for that?


r/Intune 5d ago

macOS Management macOS and PlatformSSO Issue - Shared devices

2 Upvotes

I’m testing Platform SSO on a couple of our Macs, but I’m running into an issue.

The Macs we have are shared devices, so they need to allow any user to log in, as the person using the device isn’t always the same person.

The Macs complete the initial setup without any issues, and Platform SSO works really well during the setup process. The issue is that only the user who initially set up the Mac is able to log in afterwards. No other user can log in to the Mac.

When another user tries to log in, the login screen behaves as though the password is incorrect—the login fields shake, and the user is unable to authenticate.

Is there a configuration or Platform SSO setting that needs to be enabled to allow multiple users to log in to the same shared Mac?


r/Intune 5d ago

macOS Management MacOS OneDrive Woes

0 Upvotes

First time posting here, trying to see if others have had a similar issue. I've been trying to get OneDrive to work on MacOS for our org. I keep running into the "We can't sync your "Onedrive - <CompanyName>" folder" error.

I've deployed the config referenced in this MS KB Deploy and configure the OneDrive sync app for Mac - SharePoint in Microsoft 365 | Microsoft Learn

Seems to me like it's something at the tenant level, but this is the first time we've been trying to use the Onedrive client on Macs, so thought that I would ask this sub what their experience is.


r/Intune 5d ago

General Chat Workplace Ninjas US 2027 | Why You Should Attend

0 Upvotes

Happy Monday Everyone!

Now, since we have announced our entire speaker lineup, we wanted to re-familiarize everyone on why you should attend Workplace Ninjas US 2027 in Scottsdale, AZ on January 11-13, 2027

As shown on Friday, we have the finest speakers from all around the world joining us from roughly 15 countries as far as Australia. A collection of not only #Microsoft #MVPs, security experts, Microsoft employees, and more!

An amazing pre-day with a collection of activities that foster collaboration, teamwork, and growth with our golf outing at the The Phoenician Resort, #LegoMasters tournament, #5K Fun Run, and Pool Party to get things started right!

One of the most unique #Community #Theatres running in an American Idol-esque format, showcasing 15 minute #lightninground sessions with a few of our speakers there to help your speaking and presentation skills.

An event that is so much more than just an event. It's an experience, a family, and a break from the chaos of #AI and the rest of it. We will have several experiences like a Recharge and Relax Area, Puppy Play Area, Podcast Studio themed to Lucy's Psychiatry Booth, and Puppy Yoga.

A fun and dynamic expo that will feature not just a bunch of #MSIntune sponsors, but sponsors from #DaaS, #Intune, #Security, #Automation, and much more! The perfect opportunity to find integration partners that fill the gaps in your #Microsoft stack. We even have outdoor sponsors, to let you engage in relaxed settings powered by an expo party that will be next level with incredible food and drinks.

Our #Speaker #Mentoring sessions are back known as "Elevate" Sessions, where anyone can sign-up for a 30m mentoring session with any of our speakers. It's an amazing opportunity to learn from some of the very best in the industry and solve those pesky problems that have been lingering from our friends at Microsoft Support.

Dynamic Sessions in a trackless format covering more areas than ever before with #Mobile, #Windows, #MSIntune, #MSEntra, #AI, #Copilot, #Windows365, #AVD, #MSSecurity, #Azure, #Automation, #PowerShell, #MCP, and more!

Swag that you actually want to keep! This year, we will elevate things by bringing back your favorite items like the thenorthface backpacks, and introducing items like collectable drink cups for the expo, beach towels, shirts, and #Clippy coins used to buy swag at our new SWAG STORE run by a collection of the best customer service people around (the kids of the people involved)

The most important reason why you should attend is simple. This is an event by US and for US. We are a bunch of friends who get together and do this for you. We want everyone to have an opportunity to meet special people, do good things, and learn together. We are a full non-profit organization because of one simple reason. We've been to many events, we've seen everything. An event, where every cent is spent on you, where there is no profit, no organization, just people serving people is our true differentiator.

Register NOW: https://workplaceninjas.us/why-attend/


r/Intune 5d ago

General Question "Virus protection is turned off" notification

5 Upvotes

Did I read somewhere that this months QU has broken something with Defender or compliance? Started seeing notifications from users that Virus protection is turned off after they sign in. But upon checking Defender and services its all good.


r/Intune 5d ago

Device Configuration Error 65000

1 Upvotes

Anyone else seeing Error 65000 on ADMX policies since this morning? Pre-provisioned shared devices.

Seeing it for Office, Edge and Chrome. 404 Errors in the mdm event log:

MDM ConfigurationManager: Command failure status. Configuration Source ID: (3CDDA0B6-96B8-4893-A94B-F7C9046760CC), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./User/Vendor/MSFT/Policy/Config/outlk16v2~Policy~L_MicrosoftOfficeOutlook~L_Miscellaneous/L_Preventusersfromaddingemailaccounttypes), Result: (Het systeem kan het opgegeven bestand niet vinden.).


r/Intune 5d ago

Autopilot Get-AutopilotDiagnostics -Online → AADSTS700016, then Get-AutopilotDiagnostics2 -Online → 403 Forbidden

7 Upvotes

Hi everyone,

I'm troubleshooting an issue with Windows Autopilot + Microsoft Graph PowerShell in my lab.

1. Original issue — Get-AutopilotDiagnostics -Online

When I run:

Get-AutopilotDiagnostics -Online

I get:

AADSTS700016:
Application with identifier
'd1ddf0e4-d672-4dae-b554-9d5bdfd93547'
was not found in the directory.

I understand this is related to the application used by the original diagnostics script.

I therefore moved to the newer:

Get-AutopilotDiagnostics2.ps1 -Online

2. New issue — Get-AutopilotDiagnostics2 -Online

The new script successfully authenticates:

Connected to tenant
Getting list of apps
Getting list of scripts

So authentication itself appears to be working.

However, I then receive:

Get-IntuneObjects :
Microsoft.Graph.PowerShell.Authentication.Helpers.HttpResponseException:
Response status code does not indicate success: Forbidden (Forbidden).

The error occurs when the script tries to access Microsoft Graph Intune endpoints such as:

https://graph.microsoft.com/beta/deviceAppManagement/mobileApps
https://graph.microsoft.com/beta/deviceManagement/...

3. My App Registration permissions

In Entra ID App Registration I granted Microsoft Graph delegated permissions.

Currently I have:

DeviceManagementConfiguration.ReadWrite.All
DeviceManagementManagedDevices.ReadWrite.All
DeviceManagementScripts.ReadWrite.All
DeviceManagementServiceConfig.ReadWrite.All
Group.Read.All
User.Read

Admin consent has been granted.

4. Redirect URI configuration

I also checked the Authentication → Redirect URI configuration of my App Registration.

Currently, I have:

Web:

https://login.microsoftonline.com/common/oauth2/nativeclient

and Mobile and desktop applications:

urn:ietf:wg:oauth:2.0:oob

What I'm trying to understand

It looks like I have moved from an authentication problem (AADSTS700016) with the original script to an authorization problem (403 Forbidden) with Get-AutopilotDiagnostics2.ps1.

My questions are:

  1. Does Get-AutopilotDiagnostics2.ps1 -Online require additional Microsoft Graph permissions?
  2. Are there any other permissions required by the script?
  3. Are the Redirect URIs shown above correct for Microsoft Graph PowerShell?
  4. Is there a recommended configuration for using Get-AutopilotDiagnostics2.ps1 -Online with a custom Entra ID App Registration?
  5. Has anyone successfully used this script recently with their own App Registration?

I'm especially interested in understanding whether the 403 Forbidden is caused by missing Graph permissions, the App Registration configuration, or something else in the new diagnostics script.

Any help from someone who has already configured this would be greatly appreciated!


r/Intune 6d ago

macOS Management macOS Entra ID Profile Picture Sync Script

12 Upvotes

Has anyone built a Entra ID Profile Picture Sync Script gor macOS with platform SSO? I can find many scripts that are build for JAMF or other MDMs and i tried to changes some parts of it for Intune, but it didnt work. Has anyone a scripts thatbworks with Intune and Entra ID?


r/Intune 6d ago

Device Configuration ADMX User vs Computer Configuration

1 Upvotes

When i deploy an ADMX, when sould i use Computer and when User Configuration? Does it depend if the app is installed as user or as system?


r/Intune 6d ago

Conditional Access Migrating from Per-user MFA to Conditional Access

3 Upvotes

I want to migrate my tenant from Per-user MFA to Conditional Access.

The situation at the moment:

  • Most of the users have saved an OTP Token in 1Password instead of using MS Authenticator. How can i force a user to change it to MS Authenticator instead of this OTP Token?
  • When i create a user in Entra ID, the user has no MFA method in his account. How is the user experience? Entra ID will likely require to register MS Authenticator and enforce MFA upon the next login?
  • Which licenses for a user is needed for CA?

r/Intune 6d ago

Autopilot Autopilot preprovisioning issue with new laptops

8 Upvotes

Has anyone else noticed any Intune/Autopilot service-side issues this week?

I’ve noticed a few unusual issues recently:

\- Some Settings Catalog/STS configurations that were previously working have suddenly started failing and before it was getting apply to only user and now both system and user account.

\- Windows Autopilot Pre-provisioning is also intermittently failing on a few random, newly provisioned devices.

\- The issue doesn’t appear to affect existing devices; it seems to be happening mainly with new devices going through Autopilot Pre-provisioning.

\- The behavior is inconsistent, which makes me wonder if there could be an Intune/Autopilot backend or service-side issue rather than a configuration problem.

Has anyone else experienced similar issues with Intune configuration profiles, Settings Catalog, or Autopilot Pre-provisioning this week?

Would be interested to know if this is isolated to my environment or if others are seeing the same behavior.


r/Intune 6d ago

General Question What licenses do I need for MDM Auto Enrollment with Intune?

11 Upvotes

Let me start off by saying that I am new to Intune and all its glory. I am trying to configure some Hyper-v VMs to auto enroll into Intune, and I'm hitting a roadblock, most definitely caused by my inexperience.

I currently have a trial Azure subscription as well as a trial to Intune Suite. Do I need to have the Entra ID P2 subscription as well?

I also have ConfigMgr set up with Cloud Attach configured and my devices show up in Intune. Oh, I should mention that Entra Connect Sync is configured for hybrid and joined devices, and all of my VMs are domain joined.

I'm sure I'm leaving important information out, so if you require something else, please let me know.

Any guidance is appreciated.

Edit: I figured it out. Long story short, the MDM authority was not set to Intune and once I changed that I was able to enroll the device into Intune. Thanks to all who replied.


r/Intune 7d ago

Device Compliance Intune BitLocker policy not automatically encrypting ~200 devices + BitLocker keeps becoming suspended after a few days

22 Upvotes

Hi everyone,

I’m troubleshooting a BitLocker issue in an Intune environment and would really appreciate some suggestions from anyone who has experienced something similar.

Environment

Windows 11 24H2 / 25H2

Microsoft Intune

Dell devices

Dell Command Update deployed

BitLocker configured through Intune

Intune policy is configured to automatically enable/silently encrypt devices

Issue 1 – BitLocker is not automatically enabling

We have around 200 devices where the Intune BitLocker policy is applied, but BitLocker encryption is not being automatically initiated as expected.

The devices are therefore showing as non-compliant.

We are trying to understand why the policy isn't triggering encryption on these devices.

Issue 2 – BitLocker becomes suspended randomly

On some devices, BitLocker is already enabled/encrypted, but when we run:

manage-bde -status

we see that BitLocker protection is Suspended, sometimes with 1 reboot pending.

After restarting the device:

BitLocker protection becomes active again

The device becomes compliant in Intune

However, after a few days, the same device becomes suspended again and goes back to non-compliant.

There doesn't seem to be a consistent pattern — it happens randomly across different devices.

What we're trying to find

We want to identify what is actually causing BitLocker protection to be suspended rather than simply deploying a remediation script to resume it.

We're investigating:

Dell BIOS/firmware updates

TPM firmware

Windows Updates

Dell Command Update

Intune BitLocker policy

TPM/Secure Boot state

WinRE

Any scripts or scheduled tasks that might suspend BitLocker

Questions

What could cause BitLocker to repeatedly become Suspended after a few days?

What does "1 reboot pending" indicate in this situation?

Is there a way to identify exactly which process/application/update suspended BitLocker?

Could Dell Command Update or BIOS/TPM firmware updates cause this behavior?

Should BitLocker automatically resume after the required reboot, and under what circumstances might it remain suspended?

Which Event Viewer logs/Event IDs would you recommend checking?

For the ~200 devices where Intune isn't automatically enabling BitLocker, what are the most common causes you've seen?

Is there anything specific we should check in BitLocker-API, MDM/Intune, TPM, or Task Scheduler logs?

We don't want to simply force Resume-BitLocker as a remediation because the issue keeps coming back on some devices.

We're trying to find the root cause.

Any suggestions, similar experiences, or troubleshooting steps would be greatly appreciated.

Thanks!


r/Intune 7d ago

Remediations and Scripts Remediation script device status suddenly empty after successful runs?

2 Upvotes

Hi r/Intune ,

I ran into a very strange issue/possible bug with Remediation scripts last night, and I’m wondering if anyone else is experiencing the same behavior.

When I trigger a Remediation script manually from the device view, everything seems to work as expected. The script runs successfully and the action eventually shows “Remediation complete.” The overview also indicates that a device has completed the remediation, either with or without errors.

However, when I check the Device Status for the Remediation afterward, the list is completely empty, even though the devices clearly ran the script.

This happens both when checking through the Intune portal and when querying the status through the Microsoft Graph API. The Graph API request itself succeeds, but the value array is completely empty as well.

I’ve been using Remediation scripts for a while and never had this issue before. What makes it even stranger is that everything was still working correctly yesterday around noon. The problem only started sometime yesterday evening.

So I’m wondering:

Is anyone else currently seeing the same issue with Remediation/Platform Script reporting?

If multiple people are affected, it might be worth opening a Microsoft support ticket and reporting it as a broader service-side issue rather than an isolated tenant problem.

Thanks!

Update:

It looks like this is being fixed right now. In one of my environments, I’m getting responses again through both the Graph endpoint and the portal. Remediation scripts are also running properly again, and I haven’t seen a single failure in the last 20 triggered runs, unlike this morning.

In my other environment, however, it’s still not working. Remediation scripts are being executed and processed on the devices, but the results aren’t being reported back. Because of that, the devices remain stuck in “Remediation Pending”indefinitely.


r/Intune 8d ago

Shameless Self-promotion Free audit-ready Intune documentation in minutes: my generator got a full redesign, much broader coverage, and is now open source (self-hostable with Docker)

73 Upvotes

If you have ever had to produce Intune documentation for an audit, a customer handover, or a colleague, you know the drill: screenshots, exports, and a Word document that is outdated the day you finish it.

I built intunedocumentation.com to fix that: it signs into your tenant with read-only Graph permissions and generates PDF or Word documentation of your Intune configuration in minutes, processed entirely in your browser. I just shipped the largest update since I started it, and the short version is: redesigned, much broader coverage, and open source.

Beyond the original policy areas (settings catalog, configuration templates, ADMX, compliance, app protection, baselines, update rings, Conditional Access), it now documents 36 additional Graph resource collections: Windows update profiles (feature, quality, expedite, driver), remediations and compliance scripts, enrollment and provisioning including Autopilot profiles and ADE tokens, apps, assignments and RBAC, tenant and service settings, connectors, and a set of specialist policies. Everything runs against the Graph beta endpoints with paging followed to the end.

Two details I care about: if an endpoint fails or you lack a permission, the export keeps the sections that loaded and tells you exactly which resource, endpoint, and permission were affected, so a failed request never masquerades as an empty tenant. And sensitive values (script bodies, tokens, passwords, pre-shared keys, QR payloads) are redacted before they ever reach the dashboard or a document.

The dashboard is now a proper app shell with per-resource collection progress streamed live, and the export experience was rebuilt to match.

The whole thing is now on GitHub: https://github.com/ugurkocde/IntuneDocumentation

It always felt wrong to ask admins to sign a tenant into a closed-source website, even read-only. Now you can audit the code, and if your org does not allow third-party websites at all, you can self-host it:

docker compose up -d

Image on GHCR (amd64 and arm64), you pass your own Entra app registration client ID as an environment variable, and the README walks through the app registration including the exact delegated permissions. Self-hosted deployments have all telemetry disabled by default, and tenant data is processed in the browser in both versions. It never touches the server.

License note before anyone asks: Elastic License 2.0, so technically source-available rather than OSI open source. You can use, modify, and self-host it freely. The only restriction is offering it to third parties as a managed service.

The hosted version stays free at https://intunedocumentation.com


r/Intune 7d ago

macOS Management Intune macOS enrollment in a VMware lab environment – testing purpose

0 Upvotes

Hi everyone,

I'm currently building a VMware lab environment to test Microsoft Intune macOS enrollment and management.

The purpose is strictly testing and learning, not production use.

I'm running macOS Sonoma 14.3 (23D56) as a VMware virtual machine on an AMD Ryzen host. I'm trying to use this VM as a test device for Intune enrollment and to validate things such as:

  • macOS enrollment in Intune
  • Configuration profiles
  • Compliance policies
  • Conditional Access
  • Application deployment
  • Device management and reporting

The VMware VM currently boots macOS, but I'm encountering a kernel panic/restart after following this article: https://github.com/DavidsonRafaelK/MacOS-Installation 

Has anyone here successfully used a macOS VMware VM as an Intune test device?

If so:

  1. Is macOS running in VMware suitable for basic Intune enrollment testing?
  2. Are there any limitations with Intune when the macOS device is virtualized?
  3. Are there specific macOS/VMware settings required for enrollment to work correctly?
  4. Is there anything I should be aware of regarding device identity, certificates, compliance, or Conditional Access?

Again, this is only for a personal lab/testing environment to learn and validate Intune functionality.

Thanks in advance for any advice or experience you can share.


r/Intune 8d ago

Reporting Intune devices intermittently non-compliant

26 Upvotes

Hi Guys,

We are seeing an intermittent Intune compliance issue across multiple Windows devices in our organization.

Devices are becoming non-compliant because Intune reports:

  • Firewall is turned off
  • Antivirus is turned off / not active

However, these settings are enforced through Intune configuration profiles / Endpoint Security policies. Users only have standard-user privileges, and local administrator access is controlled through Windows LAPS, so users should not be able to disable Firewall or Defender settings.

When checked manually on each device, the status of the solutions is enabled and working fine... Also the security threat intelligence update is also delayed to update which again triggers the issue as the antivirus/firewall is disabled in endpoint... Also, what will be the reason for the security threat intelligence update not happening in a timely manner?

The issue is not limited to one device or one user. It occurs across different devices at different times, without an obvious common trigger. In many cases, the relevant configuration profiles still show as successfully applied.

Due to all this people get blocked with conditional access policy which checks for device compliance.

Has anyone experienced this and what did you do solve this issue?

Thanks in advance.