Event banner

Windows + Intune Office Hours LIVE at Technical Takeoff

Event Ended
Thursday, Nov 30, 2023, 10:30 AM PST
Online

Event details

Need help with Windows updates and upgrades in your organization? For targeted questions or things you missed during Technical Takeoff, come connect with the engineers working on Windows and Intune. We're here to help and listen to your feedback!

We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, security, public sector, FastTrack, and more. And, for your continued questions, join us every third Thursday for Windows Office Hours here on the Tech Community.

Familiar face Joe Lurie will host the full one-hour event. For the first half hour, we'll focus on Intune questions with Deepika Wadhwa, Peter Richards, Venkata Raghuram Pampana, Ciaran Murphy, and Alemeshet Alemu. For the second hour, we'll switch out our on-camera experts to focus on Windows with Jason Sandys, Sean McLaren, Aria Carley, Jason Leznek, and Adam Nichols.

This session is part of the Microsoft Technical Takeoff: Windows + Intune. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event.

Char_Cheesman
Updated Dec 27, 2024

104 Comments

  • AaronSharp's avatar
    AaronSharp
    Copper Contributor
    My new ARM powered Surface 9's need a special A/V built for ARM and cannot use the standard x64 application. Will I be able to create a dynamic group in Entra ID to target the ARM processor type already in GRAPH to be able to target the ARM specific application and conversely exempt them from x64 application that do not work for them?
    • SigurdWerner's avatar
      SigurdWerner
      Iron Contributor
      Filter doesn't help here since the Intel and the ARM based device both show-up as 'Surface Pro 9'. So, the general demand is to be able to create dynamic groups and/or filters based on all inventoried data of a client. Natively in Intune. As we have w/ collections in MCM
    • ericschreiber's avatar
      ericschreiber
      Icon for Microsoft rankMicrosoft

      From the live event, Peter Richards suggested using Assignment Filters, which doesn't currently support processor architecture but does support manufacturer and device model, which should provide the functionality you need.

      • PeterRichards's avatar
        PeterRichards
        Icon for Microsoft rankMicrosoft
        Unfortunately, as Sigurd points out in the other reply the ARM and Intel based Surface Pro 9 devices both show up as 'Surface Pro 9' so the assignment filters approach I suggested in the video won't work. One alternative approach that may apply depending on how you are deploying your A/V would be to set the Operating System Architecture requirement on the app in Intune to ARM that way the ARM version of your A/V will be marked as Not Applicable on any Intel devices. I would also encourage you to add a request at https://aka.ms/intunefeedback for processor architecture support in assignment filters
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's Windows + Intune Office Hours LIVE at Technical Takeoff! For reference, the panel covered this topic at around 17:05.

  • lalanc01's avatar
    lalanc01
    Iron Contributor
    Will Endpoint security ever support setting up a pin via the policies like with GPO. We require to have a pin set, so for now we rely on custom solutions to enforce it, because our understanding is that Endpoint security doesn't allow that. Thks
    • Jason_Sandys's avatar
      Jason_Sandys
      Icon for Microsoft rankMicrosoft
      Ultimately, the challenge here is that setting a single PIN across the board is not very valuable and thus there's very little to no benefit to implementing something like this within Intune. Settings a pre-boot auth for BitLocker in Windows has many possible shortcomings and is one of the reasons we've introduced Personal Data Encryption (PDE) in Win 11 22H2 and in general, this is the path we are beginning to recommend to customers instead of using pre-boot auth with BitLocker.
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's Windows + Intune Office Hours LIVE at Technical Takeoff! For reference, the panel covered this topic at around 01:30.

  • I am just here to hear venkata talk about whats top of mind … and everything Intune related 🙂 . Love to hear him and everyone talk about how ddm (windc) for windows devices is one of the best things that arrived this year…

    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's Windows + Intune Office Hours LIVE at Technical Takeoff! For reference, the panel covered this topic at around 06:00.

  • lalanc01's avatar
    lalanc01
    Iron Contributor
    Hi, when using Universal print, if we have different locations across the world, does that we that we have to use separate Universal print subscription because of where the data is stored? Thks
  • lalanc01's avatar
    lalanc01
    Iron Contributor
    Hi, will we ever have a way to use/set servicing profile and more importantly the reporting part of it so we don't have to use a separate portal to manage this? We use WUFB part of Autopatch, so we can't fully use Autopatch to manage all updates. thks
    • Char_Cheesman's avatar
      Char_Cheesman
      Bronze Contributor

      Thanks for participating in today's Windows + Intune Office Hours LIVE at Technical Takeoff! For reference, the panel covered this topic at around 36:00.

  • lalanc01's avatar
    lalanc01
    Iron Contributor
    Hi, will we ever see in settings catalog a way to control the service state (manual/automatic) so we don't need to rely on GPO or proactive remediation scripts to set those. Thks
    • Jason_Sandys's avatar
      Jason_Sandys
      Icon for Microsoft rankMicrosoft
      There is an infinite set of possible configurations, settings, and policies we could implement within Intune for Windows management, and we just can't do them all. This is the reality of Windows and not specific to Intune. Thus, we prioritize based on ROI and impact to customers if they don't have this. Given that there are very good paths to address this; i.e., proactive remediations and very simple scripts, I don't anticipate that this is something that will get prioritized any time soon. We've certainly discussed this item specifically, but there are many others we've discussed as well. If you feel strongly about this, please submit the feedback via the console.
    • Jason_Sandys's avatar
      Jason_Sandys
      Icon for Microsoft rankMicrosoft
      There's not a specific limitation here other than it wasn't designed to account for scope tags and RBAC and thus requires time, effort and investment once we decide to prioritize this work. At this time, I don't anticipate that we'll ever prioritize this work though as the recommendation is to implement co-management which will get you this functionality or to move to full Intune (which should be everyone's goal anyway).
    • reastman1966's avatar
      reastman1966
      Brass Contributor

      I was just introduced to your blog https://call4cloud.nl/2022/06/enrollmenterrorsintune/#part5. This is a fantastic resource. On the famous 0x8018002b error if all the steps including the PowerShell script at the end does not work if there anything new I can try?  thanks.

      • Rudy_Ooms_MVP's avatar
        Rudy_Ooms_MVP
        MVP
        Hehe thanks… doing my best… sometimes abit to much but :)… nice to hear you like it
Date and Time
Nov 30, 202310:30 AM - 11:30 AM PST