Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
59 Comments
- CaseyBIron Contributor
Is there any work being done to make the Company Portal app more responsive to the app state of an application? Sometimes we see Company Portal not recognize that an app is no longer installed. Is there a way to immediately trigger a re-run of the detection rule?
- Jason_Sandys
Microsoft
Hi CaseyB , There is a list of improvements that we are investigating to improve many aspects of the Company Portal including what you've characterized above. At this time, these have not yet been prioritized though and thus there's nothing additional to share on this. Please submit feedback on this item directly in the Intune console or using the Microsoft Feedback portal at Microsoft Intune · Community.
- timi1990Copper Contributor
We've noticed our devices are not able to update to the latest version on Intune. We configured ring update feature using Microsoft documentation , but this seem not to work . Can you help with any work around ?
- EricMoe
Microsoft
If you are using Intune for Feature Updates, our Autopatch documentation will guide you through creating Feature Update phased rollouts, Windows feature updates overview | Microsoft Learn In terms of what's not working, it will be difficult for us to diagnose through this forum. But some things you can check - if the devices are in scope of the policy but do not report any status back, it's possible the devices current have a safeguard hold in place that prevents the feature update from being offered to them. If the feature update should encounter an error while processing, that should show up in reporting in Intune in the Feature Update Policies with Alerts.
- AriaUpdated
Microsoft
Hi there, so if you are trying to update to the latest feature update version via Intune there are a few reasons this may not be working:
- Policy conflict (make sure you have no leftover policies from Configuration Manager, Group Policy, etc. that could be causing conflict)
- Safeguard holds Safeguard holds for Windows | Microsoft Learn which should go away automatically
- If moving from Windows 10 to Windows11, in addition to the deferrals, you will need to select target product version = 11, you can do this via the "Windows 11" toggle on the rings page or via Settings Catalog.
Hope this helps, let me know if you have any additional questions! :)
- Pearl-Angeles
Community Manager
Welcome to April's session of Windows Office Hours! We'll be here for the next hour reviewing and responding to your questions here in the Comments section. Let's get started!
- GomesCopper Contributor
what is the advantage of using Device preparation policies to autopilot?
can i apply a name template?
- Jason_Sandys
Microsoft
Windows Autopilot device preparation is not a set of policies, it is a whole new profile type that changes the nature of Autopilot. It is separate and distinct from the original Windows Autopilot profiles (user driven, pre-provisioning, and self-provisioning). It is not a full replacement for the original Windows Autopilot profiles (today at least) but can be useful for certain scenarios including GCCH/US Government and assigning Autopilot to users instead of devices without pre-registering the devices. Windows Autopilot device preparation is a work in progress though and we plan on adding a lot of new capabilities to it in the near future. Check out Skilling snack: Windows Autopilot device preparation | Windows IT Pro Blog for a lot more info.
Note that today, you cannot use a custom name for devices with Windows Autopilot device preparation but this is something we've investigated adding.
- shin0933Brass Contributor
You should be able to apply a template: https://learn.microsoft.com/en-us/autopilot/profiles
(requires Microsoft Entra join type): Select Yes to create a template to use when naming a device during enrollment. Names must be 15 characters or less, and can have letters, numbers, and hyphens. Names can't be all numbers. Use the %SERIAL% macro to add a hardware-specific serial number. Or, use the %RAND:x% macro to add a random string of numbers, where x equals the number of digits to add. Only a prefix can be provided for hybrid devices in a domain join profile.
The advantage is essentially saving time and automating deployment processes.- GomesCopper Contributor
I already use the normal autopilot deployment With name template trough a deployment profile, but just trying to understand the use of Device preparation policies, that is similar to the normal autopilot.
- BenYasikaCopper Contributor
In Intune we are able to create a kiosk configuration with a local user “kiosk user” that auto logs on. This is ideal for users with no AD/Azure AD account that need to access single use-case non ms365 resources. For these types of scenarios where there is no user association to the device and therefore no license technically assigned, what is Microsoft’s guidance on licensing for these types of devices?
- Dan_Ramacciotti
Microsoft
BenYasika You should work with your Microsoft account team, the device may need a device license. Here is the guide Overview for Windows Autopilot self-deploying mode in Intune | Microsoft Learn
- shin0933Brass Contributor
For devices managed by intune that will be used by K-12 students, are there any best practices or recommendations that Microsoft suggests to follow to provide students a safe device learning environment?
- Jason_Sandys
Microsoft
The additional resources section at the bottom of the Learn docs at Get started with Intune for Education - M365 Education | Microsoft Learn offer a lot of great guidance that should get you going.
- shin0933Brass Contributor
I understand for MFA deployment there are two components: the MFA setup itself and the conditional access rule. Is there a guide on setting up the conditional access side of MFA?
- Jason_Sandys
Microsoft
The guide at Require MFA for all users with Conditional Access - Microsoft Entra ID | Microsoft Learn should get you going. Additional, make sure that you leverage the templates that we created and detailed at Simplify Conditional Access policy deployment with templates - Microsoft Entra ID | Microsoft Learn.
- HeyHey16KIron Contributor
When our third-party recycle company try to reset the UEFI/DFCI management on our decommissioned Surface Laptops using the same procedure (documented here https://learn.microsoft.com/en-us/surface/surface-manage-dfci-guide#removing-dfci-management) we have been using for years, they are now seeing the below. Affected devices confirmed removed from Intune/Autopilot etc.
ps - why on Microsoft hardware is the UEFI so limited in what you can see? With other vendors you can see/configure all the hardware...- Dan_Ramacciotti
Microsoft
HeyHey16K If you can confirm you are not seeing the request in Intune it would best to contact Microsoft support.
- HeyHey16KIron Contributor
If the device has been removed from Intune, where would we look for the request please Dan?
Or where would it be if the device hadn't been removed (just for future reference)?
- CaseyBIron Contributor
When using Edge Kiosk mode, this can be configured with Intune -- once the Kiosk mode is operational, it's a local Kiosk user logging into the device or VM. How does Intune licensing work with Kiosk mode. Is there an Intune device license that is needed per device when using Kiosk mode? How does Intune licensing work with devices in Kiosk mode?
- Phil_Urban
Microsoft
There is device-based licensing available for both Intune and Windows. Also, if needed, there are several ways to license Entra ID P1 (for the auto logged in account). It's best to work with your Microsoft or partner account team to validate the appropriate combination of licenses for your specific scenario.
- CaseyBIron Contributor
Regarding the new Intune connector that uses the MSA account, in a multiple on-prem domain environment one would need to set up one connector per domain. This increases the connector footprint unfortunately. Is it the case that builds in a specific domain will find the right connector for that domain -- there is no configuration needed for that?
- Jason_Sandys
Microsoft
For the Intune Connector for Active Directory, round robin is always used to attempt to "proxy" the ODJ blob properly to the proper domain. Whether a specific instance of the connector can successfully do this or not depends on the permissions of the MSA account. This is effectively no different than the behavior of the old connector.
Ultimately, our recommendation and guidance here remains the same though: Entra join should be used with Autopilot to provision new devices and hybrid join with Autopilot is best avoided.