Recent Discussions
Advanced Microsoft Intune capabilities - Coming to Education A5?
The Advanced Microsoft Intune capabilities (what was the Intune Suite has now arrived for E5 customers (and some of the features to E3 customers. Can anyone give any clarity as to if/when these features will be coming to A5 customers? I can see we seem to have some of the features (Remote Help, Endpoint Privilege Management) but could really do with knowing if the rest of the features are coming. Can't seem to find any information online about it.40Views0likes2Commentsproblem with Auto-Enrollment for windows devices in Hybrid enviroument
Hi everyone, I am in the process of setting up Intune for automatic enrollment on Windows devices within our hybrid environment. Here are the steps I have taken so far: 1. Configured Entra ID sync to synchronize a selected OU with Entra ID. 2. In the Intune Portal, set the Automatic enrollment MDM user scope to "All." 3. Created a GPO linked to that OU, which includes the settings to "register domain-joined computers as devices" and "Enabled automatic MDM enrollment using default Azure credentials" based on User Credential. 4. Prepared a clean computer, free of any software, and joined it to the Domain (on-prem server). 5. Moved the computer to the appropriate OU for syncing with Entra ID. 6. At this point, I can see the computer listed in the Entra ID portal under devices as Entra Hybrid joined 7. A regular domain user with a Business Premium license logged into the computer.( Only sign-in to windows, we don't have office app or add this account to windows.) 8. I ran GPupdate /force and rebooted the computer several times, but it still does not appear in the Intune portal. 9.Windows client is windows 11 Pro version 25H2 OS build 26200.8893 Dsregcmd output shows: ✅ Device is domain joined ✅ Device is synced to Entra ID ✅ Device authentication is working ✅ User has a valid PRT (Primary Refresh Token) ✅ Hybrid Join is successful On second test computer2, I installed office desktop app, then sign-in with test user to activate it. After few minutes the computer appeared on Intune portal. but on test computer 1 without user's interaction, it doesn't show up. would you be able to help me with this? Does it really need user to attach his/her account manually to "work or school account" or sing-in to any office desktop apps?77Views0likes5CommentsCompliance Policies - Device Health Attestation failing (Syncml 404 / 0x87d10194)
Windows 11 devices are non compliant in Intune against BitLocker, Secure Boot and Code Integrity, all three returning the Syncml 404 error. The settings are genuinely enabled. The real cause is the device can't retrieve a Device Health Attestation certificate, so the health cert status sits at 65535 and the retrieval task fails. What I've found: the TPM is healthy (present, ready, attestation capable, firmware not vulnerable), and the endorsement key cert is valid, chaining to Nuvoton TPM Root CA 2111. But the EK chain check comes back invalid with zero intermediate certificates, because the Nuvoton key is signed straight off the root with no intermediate for the chain walk. A Hyper-V VM on the same build and tenant works fine, but only because it has no manufacturer EK cert, so it skips that chain check entirely. What I've tried: patching TPM firmware (ruled out the older ADV190024 issue), refreshing the local trusted TPM certificate store, and rerunning the retrieval task. None fixed it. This matches Rudy Ooms' well known call4cloud writeup, where he concluded it's a service side trust problem that can't be fixed from the device. It's now appearing on brand new Dell hardware too, so I can't just exclude the old kit and move on. Is this a known issue with the Nuvoton root chain, and is there a supported fix or position from Microsoft? Screenshots below showing the compliance errors and the failure.187Views0likes3CommentsIOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP
IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP I am trying to test the newer iOS Enrollment Policies using User Affinity with Modern Authentication instead of the older Enrollment Profiles. One thing I've noticed is that the "Install Company Portal with VPP" setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies. My test Policy configuration is using: User Affinity with Modern Authentication Company Portal deployed as a VPP app I tested deploying Company Portal as a required VPP app, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to set up company access and download a management profile. This doesn't seem correct because the device was already enrolled through ADE. If I select Postpone, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed. this has to be a bug or something right? the microsoft docs on this are very confusing or missing details. I also noticed that the device initially appears in Intune/entra as "iPad". After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing two devices: "iPad" (This is the Ipad that you're currently using) "ipad123-testing" ( this is the proper name and matches intune / entra) Under Settings > General > VPN & Device Management, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully. It appears that Company Portal is not associating itself with the existing ADE enrollment record. Instead, it seems to be attempting a user-driven enrollment workflow on a device that is already enrolled and managed through ADE. Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state. i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.I am trying to test the newer iOS Enrollment Policies using User Affinity with Modern Authentication instead of the older Enrollment Profiles. One thing I've noticed is that the "Install Company Portal with VPP" setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies. My test Policy configuration is using: User Affinity with Modern Authentication Company Portal deployed as a VPP app I tested deploying Company Portal as a required VPP app, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to set up company access and download a management profile. This doesn't seem correct because the device was already enrolled through ADE. If I select Postpone, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed. this has to be a bug or something right? the microsoft docs on this are very confusing or missing details. I also noticed that the device initially appears in Intune/entra as "iPad". After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing two devices: "iPad" (This is the Ipad that you're currently using) "ipad123-testing" ( this is the proper name and matches intune / entra) Under Settings > General > VPN & Device Management, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully. It appears that Company Portal is not associating itself with the existing ADE enrollment record. Instead, it seems to be attempting a user-driven enrollment workflow on a device that is already enrolled and managed through ADE. Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state. i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.37Views0likes2CommentsiOS Enrollment and Conditional Access
Hello everyone, I need some help! We are configuring Intune to allow BYOD on iOS devices using the Account Driven User Enrollment method. In this scenario, the user enrolls the device by following the path: Settings > General > VPN & Device Management > Sign in to your Work or School Account The enrollment process was working correctly until we configured a Conditional Access policy to ensure that only BYOD-managed devices can access company resources. In other words, only devices that have successfully completed enrollment and are marked as Compliant in Intune should be allowed to use corporate applications. However, after applying the policy, we are no longer able to complete the enrollment process. During one of the enrollment steps, the device displays the following message: Translate English "Setting Up iPhone iPhone setup may take a few minutes. Sign-In Failed Enrollment failed. Please try again. OK" 1. Target resources (Include) 2. Target resources (Exclude) 3. Device Platform: iOS 4. Filter for devices: device.mdmAppId -notIn ["0000000a-0000-0000-c000-000000000000"] 5. Grant: Require device to be marked as compliant This is our current Conditional Access policy configuration. Has anyone encountered this behavior before, or can identify whether there is any setting that might be blocking the enrollment process during the compliance validation stage?29Views0likes1CommentDell Firmware Very Slow to Appear in Intune Driver Updates
Have an instance where the Dell 5520 latest firmware release (1.51.0 released 09/06/26) has still not appeared in the Intune Driver Updates which means we have vulnerable laptops in the field. We do not utilise Dell Command update on the laptop to reduce the attack surface so do rely on Intune to deliver these updates in a timely manner. I'm aware that it can take a little while for Dell releases to appear on the Microsoft side, but this is over 6 weeks now. We have spoken to Dell Support, but they have deemed this a Microsoft problem. We then spoke to Microsoft Support, and it was deemed that we would have to pay for support on this given it fell outside of the scope of our service level. So essentially no-one wanted to take responsibility or assist with this! Does the forum have any insights into what may be going on here and how we can move this forward?121Views0likes2CommentsBitlocker key requested on the boot, but I don’t have any key
My laptop (Windows 10, version 22H2, build 19045), that I have been using more than 6 years already, suddenly started asking for the BitLocker recovery key at startup, which is blocking access to the system entirely. What I've already checked/tried: - Checked account.microsoft.com/devices/recoverykey while signed in with my Microsoft account, no key appears for this device. - Contacted Microsoft Support directly, they said they can no longer assist with Windows 10 issues and suggested posting here instead. Is there any way to recover access to this drive?89Views0likes3CommentsMicrosoft EPM – Random CMD / PowerShell / OpenConsole popups
Hello everyone, we are currently testing Microsoft Endpoint Privilege Management (EPM) and are seeing some unexpected behavior on several devices. Symptoms Users occasionally see random: CMD windows PowerShell windows OpenConsole windows The windows usually appear shortly after logon and disappear automatically after a short time. Some developers also reported issues related to: VS Code terminal integration Copilot terminal actions Windows Terminal WSL / Debian Additional observations However, we have also seen PowerShell popups on a user who is not currently part of the EPM pilot group Some affected devices still have Admin By Request installed Current EPM Configuration At the moment we only have an Elevation Settings Policy assigned with User Confirmed enabled. We currently do not have any custom elevation rules, file hash rules, publisher rules or automatic elevations configured. The issue appears in a configuration that is essentially limited to: EPM client installed Elevation Settings Policy assigned User Confirmed elevation workflow enabled This is one of the reasons why we are unsure whether the behavior is directly related to an EPM policy configuration or to an interaction between: EPM agent Windows Terminal / OpenConsole VS Code WSL Admin By Request Questions Has anyone experienced random CMD / PowerShell / OpenConsole windows after introducing EPM? Has anyone seen issues between EPM and: Windows Terminal OpenConsole.exe VS Code terminal WSL Has anyone run Admin By Request and Microsoft EPM on the same device and observed unexpected console windows? Are there any EPM-specific logs that provide detailed parent/child process relationships for these launches? Any ideas or similar experiences would be greatly appreciated. Thanks!130Views0likes3CommentsIs it possible to automate Minimum Windows OS version compliance policy?
Is it possible to set a Windows compliance policy for Minimum OS Version that automatically updates each month and marks the device noncompliant after 14 days? This would work if we normally allow users 2 weeks after Patch Tuesday to get their device updated. We would like to avoid having to have someone remember to manually edit the compliance policy every month to update the minimum build number in the policy.128Views0likes2CommentsAndroid Fully Managed devices treated as personal after AD password change
Hello! We have a huge problem... We have recently observed an issue in our organization affecting Android Fully Managed devices. After users change their domain password, within 1–3 days Conditional Access starts blocking access to Outlook and Teams. The system appears to treat the device as non-corporate, even though in Intune the device is still present, marked as corporate, and fully functional. It synchronizes both manually and automatically, and remote actions can be executed without any issues. However, when users open Outlook or Teams, they receive messages such as “We need to secure your device” and “Install the Intune app from Google Play,” which does not make sense because Intune is already installed on the device. When opening the Intune app, users see a “Update your password” prompt. After selecting it, they are redirected to a device registration screen. Previously, it was sometimes possible to complete this process (although we did not understand why it was required), but recently re-registration consistently fails. The user clicks “Register,” and the process spins indefinitely without completing. This issue is very difficult to troubleshoot. Device logs are not particularly helpful, and all users have Microsoft Authenticator configured. The problem appears randomly across users with no clear pattern—some devices were enrolled over a year ago, others just a month ago. The only clue we have found so far points to a potential issue with the broker authentication token, but we do not know how to verify or resolve this, nor why it is happening in the first place. We have been experiencing this issue since around January this year, but we noticed a significant increase in cases this month. In addition, there are more and more devices that can no longer be re‑registered from within the Intune app. Has anyone encountered a similar issue or can provide guidance on how to investigate or fix this?181Views0likes2CommentsConfiguration Manager manifest synchronization failing since 8 July 2026
Has anyone else experienced Configuration Manager Updates and Servicing synchronization failures since 8 July 2026? We have three independent Microsoft Configuration Manager hierarchies: Test environment Production T0 environment Production T1 environment All three started showing the same SMS_DMP_DOWNLOADER error during the last three days. The affected request is sent to: https://sccm.manage.microsoft.com/SCCMConnectedService.svc/Manifest Configuration Manager builds a hierarchy-specific request containing the Tenant, Version, Ring, and Branch parameters. However, the endpoint now returns only: OK The resulting file is: ConfigMgr.Update.Manifest.cab Size: 2 bytes Hex: 4F 4B Content: OK Because this is not a valid signed CAB file, dmpdownloader.log records: manifest.cab (http response) size is 2 Error in verifying the trust of file ConfigMgr.Update.Manifest.cab' WARNING: Failed to call IsFileTrusted WARNING: Failed to download and verify the manifest.cab. We cant get info in Updates and Servicing mode.128Views0likes2CommentsAutopatch for quality updates and WUFB for feature updates
We have switched to Autopatch for quality updates in our environment, but now is the time for feature update deployments. In the past we had used Windows Updates for Business for feature update without any problem. We would like to deploy the feature updates and retain the control of the target groups through the process, which are different ones from the quality updates. As the content is much bigger, we would like to test to specific users, after communicating to them for the procedure, and also be sure that the availability and the bandwidth will be adequate specially now during summer holidays. Could we still use WUfB only for the feature deployment along with Autopatch, without intervening to the normal monthly update cycle?Solved99Views0likes4CommentsCannot delete a website shortcut by Intune managed iphone
Hi We manually created a shortcut to a website from Safari browser and the shortcut is on the Intune managed iPhone. We don't need the shortcut now. However we cannot delete it. Press and hold apps on this phone does not start wiggle mode and we cannot drag the shortcut onto a new home screen. We also cannot see it in the Apps list in Intune to delete either because it was manually added on that specific iPhone. Can you tell me if there is a away to delete the shortcuts please? Kind regards Rob55Views0likes3CommentsAutomatically Sync SharePoint Document Libraries on macOS
Hi everyone, We manage macOS devices with Microsoft Intune and need to automatically sync one or more SharePoint document libraries to users' OneDrive, similar to how it's done on Windows using the Intune auto-sync policy. Has anyone successfully implemented this on macOS using Intune, Jamf Pro, configuration profiles, or a supported script? We're looking for a Microsoft-supported solution that minimizes or eliminates user interaction. Any guidance or recommendations would be greatly appreciated. Thanks!77Views0likes2CommentsAllow Teams desktop on unmanaged Windows, but block Outlook desktop using Entra conditional access
I need to allow Teams to run on non Intuned devices but not allow Outlook desktop to be available I am looking for a solution for Windows and Mac and ideally linux as well The issue is Ig I have Office 365 Exchange Online as my resource, it blocks Microsoft Team Services as well How can I fix this149Views1like2CommentsIntune Platform Scripts never target devices (0 targeted devices) despite healthy Intune environment
Hi everyone, I'm hoping someone has seen this before because I've exhausted most of the obvious troubleshooting. Environment Microsoft 365 Business Premium Windows 11 Pro Microsoft Intune Microsoft Entra ID Joined devices Intune Management Extension (IME) installed and healthy The Issue Platform Scripts never target any devices. Regardless of the script, assignment or device, the script always remains at: 0 Devices 0 Succeeded 0 Errors The device never appears under Device Status. What works The Intune environment is otherwise functioning normally. Configuration Profiles deploy successfully. Settings Catalog policies apply successfully. BitLocker policies apply. Windows Firewall policies apply. Windows LAPS is working. Win32 applications deploy successfully Devices are Entra Joined and managed by Intune. What I've tested To eliminate variables I created: Created a brand new PowerShell script that simply creates a text file. Created a brand new assigned Security Group containing a single Windows 11 device. Assigned only that Security Group to the Platform Script. The result is still: 0 Devices 0 Succeeded 0 Errors Device checks completed On the client: dsregcmd /status shows AzureAdJoined = YES. Intune Management Extension service is running. Win32 apps are deploying correctly. Intune Management Extension logs appear healthy. AgentExecutor.log contains WinGet application activity but no evidence of any Platform Script ever being downloaded or executed. The IntuneManagementExtension registry contains SideCarPolicies but there is no evidence of any PowerShell script policy being received. Additional observations I reproduced the issue on two separate Windows 11 devices. I reproduced the issue using both dynamic and assigned device groups. I reproduced the issue using different PowerShell scripts. This makes me believe the issue is not device specific. Question Has anyone seen Platform Scripts remain permanently at 0 targeted devices despite Intune otherwise functioning normally? Is there a known tenant-side issue, prerequisite or licensing requirement that would prevent Platform Scripts from ever targeting devices while Win32 apps and Configuration Profiles continue to work? Any suggestions would be appreciated.Solved191Views0likes5CommentsSecure Score does not reflect settings in ASR rule
Hi, Our secure score ist pretty low, so I followed recommendations from M365 Security Center. The setting reside in one ASR rule, but Secure Score still does not reflect my settings still stating 0% achievement. I waited nearly a week. Defender is not the primary AV, but on other tenants the same setting led to success. Any ideas?72Views0likes5CommentsIntune Autopatch Reports - Expected Behavior
I utilize the Intune Autopatch Reports for Quality Updates to monitor the deployment of updates across our environment. We currently have a group of devices which have a 30-day deferral period due to the compliance/testing policy we have to follow. My Understanding is that the "Quality Update Status" Report will determine if the device is Up-to-Date based on if the device has the update that has been released to it but I am finding that all devices are marked as Not Up-to-Date even with the 2026.05 QU installed as the 2026.06 QU is not available for the devices. I am wondering if this is expected behavior or if this changed because before the changes to the reports in May (2026.05) it was showing correctly Thanks!138Views0likes4Commentsenrolling in Intune MacBook Pro with an M5 Pro
Hi everyone We have tested the Wi-Fi and ethernet profile without success with Apple businesses manager. The Wi-Fi and the ethernet connection itself works, but the enrollment process into Intune does not complete successfully. At this stage, we cannot sign in, and neither the Wi-Fi nor the Ethernet connection appears to be working. The device is a 14-inch MacBook Pro with an M5 Pro chip, running macOS 26.5.1 the device connects to the server, the settings begin to apply, but the process suddenly stops, and we are then unable to log in. These are steps followed : Synchronize the device from Apple Business Manager to Intune. Assign the enrollment profile to the device. Perform a device wipe/reset. Start Automated Device Enrollment (ADE). Complete the device setup and user sign-in. The device successfully enrolls into Intune. Intune begins deploying configuration profiles, compliance policies, security policies, and applications. During the policy application process, Wi-Fi connectivity stops responding. The device loses network connectivity and cannot continue synchronizing policies. We are unable to sign in because the enrolment process has not been finalized. As a result, we have to wipe the Mac and start the process again each time. We have disabled some policies, but we are still experiencing the same issue. Have anyone experienced any issues like that ? Regards,127Views1like1CommentCanReset value flipping on cloud only devices
Hello, I have a problem with cloud only Windows 11 devices configured with passwordless policy. I have noticed that when you run dsregcmd /status command, CanReset value under User State is flipping between "No" and "DestructiveAndNonDestructive". When it's latter, everything works fine, users can start wizard for facial recognition or make PIN changes under Sign In options in Windows. But when it flips to No, everything is blocked. It seems to happen randomly, you can leave device untouched for few hours and just check dcregcmd and the value will change. CanReset is the only value that changes in the dsregcmd report. It happens for different devices located on different networks. Also, I have disabled web gateway completely for one device just for testing but no change. Any suggestions would be welcome.60Views1like1Comment
Events
Recent Blogs
- By: Madison Cooks, Product Manager | Microsoft Intune IT admins need a reliable way to confirm how Windows devices are configured, especially when troubleshooting, validating compliance, or investi...Jul 28, 202610KViews2likes8Comments
- 4 MIN READSee what's new in Intune, including agent security baselines, custom macOS compliance, and Samsung firmware controls.Jul 28, 202613KViews3likes1Comment