Event details
The series that brings you real discussions and proven tips and tricks is back—and live at Microsoft Technical Takeoff! Let's face it. Some configurations, policies, and approaches work better than others. That's why Danny and Rachelle, and their fellow colleagues in the Microsoft Intune, Security, and Customer Experience engineering and product teams are reigniting the series with conversations the things that make a successful endpoint management strategy. Tune in for tips to help you optimize and simplify the way you do things today, and in the future.
This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, click Attend for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.
33 Comments
- MarkT76Copper Contributor
Hi. Are there any plans to improved the functionality of the Multi Admin Approval (MAA) polices in Intune. Given some recent high profile wiper attacks MAA is more important than ever to configure. At the moment there are no prompts when an Intune admin requests to wipe a device. They literally have to manually contact the approvers and say 'hey, can you approve that wipe request'. Also an MAA policy that would require MAA approval for an Autopilot reset currently does not exist. An bulk Autopilot reset can do as much damage as a bulk device wipe request. Thanks.
- Per-Larsen
Microsoft
Thanks for the feedback for autopilot reset.
We did release admin task in Intune, we are investigation a way on giving notifications to the IT admin - we do not have more the share right now.
Admin tasks in Microsoft Intune: Centralized control today, AI-ready for tomorrow
- Th3n3xtL3v3lCopper Contributor
Where can we find the Autopatch report endpoints in Graph?
- Pearl-Angeles
Community Manager
Thanks for your question! Your question was addressed at 18:02 during the live AMA. For more info, go to this MS Learn article: adminWindowsUpdate resource type.
- JoeLovelessCopper Contributor
It looks like W365 has priority to resolve conflicts? Intune admins have been asking for that for years (since migrating from Group Policy). Will that be coming to workstations?
- Per-Larsen
Microsoft
It is a limitation in the MDM stack.
We do have it for EPM policies today , where we do the conflict handling in the backend, and have the most restrictive policy wins.- JoeLovelessCopper Contributor
Im asking specifically about priority, setting it to 1 is the highest priority and wins out. The W365 event said they support it, Defender supports it, Office portal supports it...why not Intune?
- RobkohliCopper Contributor
Good to see you all again. I used to see during the bi-monthly engineering meetings.
- Ali11CHIron Contributor
Currently there is a nice preview feature to run remediation scripts manually on individual devices.
Is there a way to run a remediation script manually to a number of devices, like a bulk action.
Just in case there isn't currently :)
https://feedbackportal.microsoft.com/feedback/idea/22a47388-cf26-f111-9730-0022485314bc
p.s. Thanks for the sessions, they are great.- Pearl-Angeles
Community Manager
Thanks for your participation and feedback! Your question was addressed at 10:18 during the live AMA.
- Heather_Poulsen
Community Manager
Welcome to “Unpacking Endpoint Management: Live from Tech Takeoff 2026” at Microsoft Technical Takeoff. Q&A is open now and throughout the week. Please post any questions or feedback here in the Comments. [Note: If your organization’s policies prevent you from seeing the video on this page, you can also tune in on LinkedIn.]
- Ali11CHIron Contributor
If a user who enrolled a device is deleted (eg, could be user from stale enrolment package) for whatever reason, the device then becomes eternally non-compliant because "User exists" will always be False. (thinking mostly about shared devices in a classroom)
What is the most efficient way to deal with this without having to reimage the device.- Per-Larsen
Microsoft
Devices that are shared should be device enrolled and not user enrolled.
Windows device enrollment guide for Microsoft Intune - Microsoft Intune | Microsoft Learn - jxsh42Brass Contributor
DEM account or change your compliance policy
- RobkohliCopper Contributor
Reassign the device, it should really be re-imaged as per best practices.
- Th3n3xtL3v3lCopper Contributor
We’re actively transitioning from on‑prem Group Policy to Intune configuration profiles as our primary configuration model.
In Group Policy, we relied heavily on hierarchy, inheritance, and layered targeting to manage complex and evolving scenarios at scale.From a product and engineering perspective, what are the best practices for designing Intune configuration profiles upfront—around scoping, modularity, and ownership—to minimize long‑term technical debt when new or unexpected scenarios emerge after hundreds of profiles are already in production?
- Pearl-Angeles
Community Manager
Panelists covered your question at 6:17 during the live AMA.
- Per-Larsen
Microsoft
Can you elabore more on your scenario's.
You should try and simplify policy configuration with MDM, first security policies, the configuration policies that helps your end user, and last settings that for you apps.
Configure for all devices/all users when posible, otherwise use specific device/user groups.