Forum Widgets
Latest Discussions
Create dynamic device group based off of which user enrolled the device
Is there a way to create a dynamic device group based off of which user enrolled the device? For example, I have an admin account that enrolled a bunch of kiosk machines, and I want the group to consist of all the devices that were enrolled by that account. (It might just be me being dense, but I can't for the life of me figure out how to do this based off Microsoft's documentation.)SolvedskythrockFeb 06, 2025Copper Contributor24KViews0likes15CommentsBlocking Installation of Software via Intune
Hi We are trying to block users installing software and browser apps once a device is set up. Can we do this via a configuration policy in Intune or do we need a third party app or do we need to increase our licensing.AaronDurberFeb 06, 2025Occasional Reader12Views0likes0CommentsIntune Autopilot Reset
For devices that have had their partitions deleted and Windows 11 23h2 reinstalled and manually joined to autopilot at OOBE, any autopilot reset command fails. We ran reagentc /info and the device reports Winre as enabled. We would like assistance in figuring out what Is missing or what we need to do to get these devices that get manually rejoined to autopilot to reset as expected through autopilot reset.RG1218Feb 06, 2025Copper Contributor17Views0likes1CommentMake Required applications visible in Intune Company Portal on iOS
Hi everyone, I'm new to Intune and have a question. Is it possible to make required applications visible in the Intune Company Portal on iOS (supervised devices)? Currently, only "available" apps are shown. This would be really helpful because if a user deletes a required app, the automatic re-installation can sometimes take a long time. Thanks!indigobluesFeb 06, 2025Copper Contributor27Views0likes2CommentsMissing local users menu in Devices [admin]
Hello! Expected: Under device > (specific device) > Manage, I expect to see a whole menu like "local administrator password recovery". Like this picture Current: However, I only see "Properties" under manage, missing all the rest. Using https://intune.microsoft.com/ I'm a superadmin of this Intune. Anyone knows where I can find those? Thank you!wsvFeb 06, 2025Occasional Reader5Views0likes1CommentHow do we set PurchaseOrderId using Get-WindowsAutoPilotInfo.ps1
We would like to use intune to manage all our existing and new Windows computers. We have several offices and today we use different computer configuration policies for different locations. Today, we do this by assigning a standard prefix to the computer name (e.g. OSL for Oslo, PAR for Paris). We are unable to figure out how to achieve this using intune. We are aware that in intune we can create a Dynamic security group with rule = device.devicePhysicalIDs -any _ -contains “[ZTDId]” and assign an Autopilot profile to that group, but this doesn't allow us to group devices located in different offices (we can use the computer naming template, but then the same prefix is applied on all the computers). We are now thinking if we can set a specific PurchaseOrderId when we collect device information using Get-WindowsAutoPilotInfo.ps1 (different for each office), so that we can create dynamic groups and have separate autopilot profiles for each office. How to set a PurchaseOrderId when csv file is created?Rajesh KhanikarFeb 06, 2025Copper Contributor19KViews0likes8CommentsWindows 11 Autopilot and language packages
Hi everyone, I work for a Company with about 10.000 employees. We have a working SCCM envoirenment and an Autopilot PoC which should go live in the near future. The whole project was in cooperation with DELL. The problem here is that DELL scammed us a little bit, because they always ensured us, that we will get the DELL ready image for the region where Notebook is deployed (DELL ready Image contains the LPs for all countries in the Region e.g. central Europe, Asia pecific etc.). At the End Dell told us, that it us technically not possible to provide us this image and the only thing they can do is to provide us the basic US image That's where our problem started... We need some languages for our subsidaries in some countries. Thus we tried to create a package for the Language install. 1. First idea was to use the Powershell cmdlet install-language (Install-Language (LanguagePackManagement) | Microsoft Learn). The problem here is that this package runs pretty unstable. During Autopilot the command needs about 30 Minutes to finish. Sometimes the command throws an error: "Language Pack or feature could only be partially installed. Error Code: -2147023436“ (I guess it is a timeout but I didn't find anything on Google). The strange thing here is that this cmdlet runs pretty good and stable in private envoirenment. I tested it on my PC at home with Windows 10 22H2 and on a company device with the Microsoft en-US base Image (Win 11 23H2). With Autopilot it worked 70-80% of the time and the rest failed. It was very strange that in the logs the cmdlet faild with error Code: -2147023436, but after Autopilot finished, the Language was available if I called get-language. I also monitored it in the OOBE with the powershell. Result: cmdlet sometimes failed, Language was av Does anyone know how install-language works in the Background? Which URLs are called or what this error code means? Thank you for every kind of help Best regards SvenSven00952410Feb 06, 2025Copper Contributor2.6KViews0likes7CommentsIntune - Shared iPad and deleting a user
hello all we have recently started configuring 'shared ipads' via intune and have run in to a tricky issue. We want to be able to remove a users 'profile' off the ipad but cant find a way of doing it. While researching on Google we saw that in Education you have the ability to find the device then see which users have signed in and then delete one if you wish however in Business that doesnt seem to exist. we would be really grateful if anyone can shine some light on this pleasemeravensdownFeb 05, 2025Copper Contributor7KViews0likes5CommentsCompany portal says rooted device but it's not - Android
Hi everyone, We came across a situation where one of our Android user is not able to access Outlook and Teams due to rooted device. We configured only App protection (MAM) policy in Intune and blocked access from Jailbroken/rooted devices. Only the MAM policy as been applied on the device and the device is not enrolled with Intune. So far, we have followed below troubleshooting, Rejoined the device again, however after sometime, the error will be appeared again. Check whether the device is rooted or not (Go to Settings > About phone > Status Information > Phone Status). Phone status says official. I believe this means not a rooted device. Below is the error message from the company portal Device Status in Azure AD (Not enroll with Intune) I would appreciate if anyone can help me whether I have anything else try out before I create a support case with Microsoft. Thanks, DilanSolveddilanmicFeb 05, 2025Iron Contributor16KViews0likes8CommentsConfiguration profile to set File and browser preferences in Outlook Options > Advanced
Hello, Wondering if anyone has found a way to set these settings in Outlook (classic) via Intune. We do not want hyperlinks from Outlook opening with Edge and likewise we do not want email attachments for office files opening in the browser, we want them to open with the office apps.527Views0likes4Comments
Resources
Tags
- Intune3,978 Topics
- Mobile Device Management (MDM)2,156 Topics
- Mobile Application Management (MAM)791 Topics
- Conditional Access435 Topics
- Software Management417 Topics
- Graph API232 Topics
- Azure Friday157 Topics
- Autopilot105 Topics
- android64 Topics
- iOS55 Topics