Event details
Join this Ask Microsoft Anything (AMA) to dive into the real-world deployment scenarios organizations are navigating every day.
A successful Intune deployment is about more than getting devices enrolled. You want a reliable, secure, and frustration-free experience from day one yet even experienced IT teams can run into unexpected challenges during rollout and ongoing management. Small missteps can quickly impact productivity and user trust.
Have questions about Windows Autopilot configuration, dynamic groups, enrollment strategies, app packaging and delivery, troubleshooting failed deployments, deployment rings, and avoiding policy conflicts that can lock users out or disrupt workflows? Whether you’re just getting started or refining a mature deployment strategy, this AMA is your opportunity to connect directly with Microsoft experts, share challenges, and learn practical approaches for building a smoother, more resilient deployment experience with Intune.
I'm in. How do I participate?
Sign in to the Tech Community, select Add to Calendar and Attend to receive event reminders. Post your questions (early and often!) in the Comments below.
|
This session is part of the Tech Community Live: Intune Edition. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event. |
35 Comments
- AMishra_SYDOccasional Reader
What best practices should be followed when transitioning from an SCCM-based legacy setup to Windows Autopilot with Hybrid Azure AD Join
- Veeresh697Occasional Reader
During Windows Autopilot provisioning, users sometimes receive the message "You can't get there from here" due to Conditional Access or authentication requirements. Are there any planned improvements to simplify authentication during Autopilot while maintaining security?
- Veeresh697Occasional Reader
Will Microsoft introduce more flexible device naming options in Windows Autopilot, such as using custom attributes like location, department, or serial number?
- egellertOccasional Reader
Many of us pre-stage devices in inventory before shipping to users — with Autopilot v1 we'd white-glove them so apps like Office were already installed. Device Preparation (v2) dropped that. Is pre-provisioning coming back to Device Prep, or is there a recommended way to stage warehoused devices before they reach the user?
- C00kieMonsterBrass Contributor
Is there a list of all URLs required for AutoPilot to work?
Trying to get this working from an on-prem secured network has been pretty painful - still haven't gotten it working yet. It would be great if there was a comprehensive list of all required URLs/IPs/ports, including calling out exactly what URLs don't permit TLS inspection. Also, do you think at some point there could be a troubleshooting tool similar to what O365 has that automatically determines your tenant, tests all the required URLs, etc. and gives you a report of what's working, what's not, and what configuration changes need to be made?- LightNiNCopper Contributor
Here is the Microsoft Learn page with the requirements:
https://learn.microsoft.com/en-us/autopilot/requirements?tabs=networking
- Hung_Dang
Microsoft
Check this out: Windows Autopilot requirements | Microsoft Learn
- kxOccasional Reader
thx
- Arden_White
Microsoft
No. Secure Boot updates are BitLocker-aware. Before applying the update, Windows performs a predictive reseal of BitLocker to help ensure the device does not enter BitLocker recovery.
While a system could encounter a blue screen for unrelated reasons, Secure Boot updates are not expected to cause a BSOD or reboot loop.
- SCawedCopper Contributor
On mobile, we have been purely iOS for the past years, but will soon be absorbing a company that is purely Android. Assume all upcoming android device as company owned.
- Which is better enrollment "Corporate-owned, fully managed user devices" or "Corporate-owned devices with work profile"
- Wil it be better to factory reset the mobile devices prior to enroll, or just enroll. Note we are strict on DLP.
- How do we ensure that once android device is enrolled that it is on our tenant "forever".
Thank you
- Morgan-JansenCopper Contributor
Sometimes when we send a device for repair, they replace the motherboard with one that is already registered to a different Tenant. I assume it was not removed from its last tenant when it was offboarded and the OEM reused the motherboard. Is there any solution for this?
I'd like to proactively catch it but it usually shows up when the user tries to enroll in autopilot. At that point, the new hardware hash needs to be exported. A ticket needs to be opened with Microsoft to have the device removed from it's old tenant, and then the new hardware hash can be imported.
Any way to make this less painful?- Hung_Dang
Microsoft
OEMs are told to clear the Autopilot data from motherboards after they rip them out. One way to catch this before it goes to the end user is for you to boot up the device with connectivity, and check if there's an AP profile.
Or use Autopilot Device Preparation + the upcoming Autopilot Device Association feature. :)
- Bran_Occasional Reader
what are the most common reasons a newly enrolled device remains stuck as not evaluated or pending for compliance. Whats the best route to determine next steps?
- VaishnavK1993Brass Contributor
Autopilot Device provisioning is not completing successfully, and we are encountering an error stating “Something went wrong” (Error Code: 0x80004005). However, the issue resolves automatically after some time. What could be the reason behind this?
- Veeresh697Occasional Reader
Yes even I have faced this issue may 3rd week to June 2nd week..but it seems resolved automatically.i have raised ms ticket still not get proper response
- Hung_Dang
Microsoft
It depends on which subcategory you see this error code next to.
- Morgan-JansenCopper Contributor
We have seen this when ZTNA was conflicting a bit