Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
40 Comments
- Pearl-Angeles
Community Manager
Thanks for joining December’s Office Hours. We appreciate your questions and engagement and look forward to seeing you at the next session on January 15, 2026.
- JerrinMCopper Contributor
Here's something "simple" and definitely not a major impact on our environment, nonetheless a bit annoying. When we shadow users through Teams, and gain control it would be great if we are able to see their sharing control bar so that we do not accidentally click the cancel control button! Or at least make it inoperable from our side. 👏
thanks!
- EricMoe
Microsoft
Great suggestion, please post this over in the Teams community - Category: Microsoft Teams | Microsoft Community Hub as this would need to be something they would address.
- TroyG_1206Copper Contributor
Would it be possible to get an export to csv function built into the Intune>Devices>Monitor>Windows Autopilot deployments report? And potentially add additional data columns for Group Tags, etc? We do a pretty healthy amount of Autopilot deployments daily, and having some better canned reporting available in the portal would be very beneficial for some admins who either are Graph challenged😂 or not authorized to pull data with Graph.
- EricMoe
Microsoft
TroyG_1206 Sorry the export function isn't there. The team is focused on furthering Autopilot Device Preparation features (and you can see the Windows Autopilot device preparation deployment status report has an Export function). Unfortunately, you are looking using Graph - you could always have Github Copilot help write the script :).
- TroyG_1206Copper Contributor
Thanks EricMoe - that export feature in the Device Prep report is what triggered my question :) We are doing some Copilot agent development for a few other admin functions related to Autopilot, maybe we can add this Graph data pull into our agent.
Looking forward to the advancements in Device Prep, planning our transition to Entra Join and Device Prep Autopilot for 2026.
- andrew_munroCopper Contributor
We've got around 100 Windows 11 laptops on 23H2, running Pro, with M365 Business Premium licencing for all the users of these laptops.
In Intune (Windows Updates) the EOL date given for the 23H2 feature update is November 2026, however none of our Windows Devices (running Windows 11 Pro) have been offered the December 2025 quality update.
None of the update channels is paused. All devices on 24H2 and 25H2 with the same M365 Business Premium licences have updated.
What's going wrong here? Is it that we're not on Enterprise licencing? If so, why does Intune not recognise this?
- Joe_Lurie
Microsoft
Hi andrew_munro. When a Windows 11 OS reaches EOL, it stops receiving Security Updates. In this case, as you correctly state, the EOL date of Windows 11, version 23H2 Pro was Nov. 11, 2025. Therefore, the last security updates expected on this version/edition of Windows 11 would have been on November 11, 2025. See Windows 11, version 23H2 reaching end of updates (Home, Pro) - Microsoft Lifecycle | Microsoft Learn for more info.
Did you have a different question or am I misreading your question?- andrew_munroCopper Contributor
My question relates to how information about this is presented to us in Intune:
I understand that Windows 11 23H2 went EOL for Home and Pro in November 2025, however Intune reports to us that our support End Date for this feature update is November 2026.
- Amarjeet5Iron Contributor
Wish we could rescind/revoke wipes for devices that are offline & was accidental wipe command.
Yes workflow needs to be improved to prevent this however, we should have granular ability to have wipe commands timeout for specific devices/groups. Some devices should never be wiped and not being able to revoke the command is annoying as we scale up on deployments.
- Joe_Lurie
Microsoft
Amarjeet5 That's a great request. Please post it to our Feedback portal at https://aka.ms/IntuneFeedback or with the Send a Smiley within the Intune admin center.
I do want to point out that we added Wipe to our Multi Admin Approval workflow, ensuring that no device is wiped accidentally without another admin approving that. Check out Multi Admin Approval here: Use Multi Admin Approval in Intune - Microsoft Intune | Microsoft Learn
- Petr_FalcCopper Contributor
If I start an Intune remediation from the device tab for a specific device while it is offline, will it still run on that device once it comes back online, or will it not execute at all?
- Joe_Lurie
Microsoft
Petr_Falc Check the big note on this Learn page: Use Remediations to Detect and Fix Support Issues - Microsoft Intune | Microsoft Learn. Problem with running an on-demand Remediation script is that the device may not receive the policy if Intune cannot communicate with the device or the Windows Notification Service (WNS) on the device.
- Petr_FalcCopper Contributor
Thank, Joe_Lurie, that makes sense. I just wanted to confirm whether the device will receive the on-demand remediation once it comes back online, similar to how a message sent to someone while they are offline is delivered when they come online.
- Vinod7Brass Contributor
In Outlook we have the option to save settings in the cloud that stores the settings but we do not have anything for other office applications. We are more interested to know if there are future plans to save these on Cloud (Settings), Like what UEV does
- EricMoe
Microsoft
Vinod7 You may want to try this question in the M365 Community. Their community is at Category: Microsoft 365 | Microsoft Community Hub
- Heather_Poulsen
Community Manager
Thanks for joining us for Windows Office Hours. Post your questions in the Comments and we'll do our best to help.
- HeyHey16KIron Contributor
Two queries relating to the Secure Boot certificate change
- In the AMA (https://techcommunity.microsoft.com/event/WindowsEvents/ama-secure-boot/4472784) the team said they would come back regarding the question about the Registry Key status being "Not Started" as this was unexpected. How will this be fed back please, as we are seeing this in our environment
- Where can we find the Microsoft high-confidence device list, so we know which computer makes/models are marked as high confidence please? - nlmitchellIron Contributor
Good news recently about the additional features coming to E3/E5 licensing next year.
We are particularly interested in Enterprise App Management, amongst others, and wondered if you had any recommended resources available that we can review in the meantime.
We currently use a 3rd party product and want ideally like to use EAM as a direct replacement of that product.Regarding functionality, does it archive off apps after X number of versions for example? How does it cope with automating deployments out to existing AD/Entra groups? How do you opt in/out of apps and updates?
Lodas of questions in my head, way too many to mention here😀
- Joe_Lurie
Microsoft
nlmitchell It's great news about the inclusion of Suite into ME3 and ME5 (some in ME3 and some in ME5 - see our blog here).
To answer your questions:- For resources on using EAM, start here: https://aka.ms/EAMDocs. At the bottom of the page are a lot of additional resources.
- This is something we're toying with, but right now we are not planning on offering N-1 or N-2 in the catalog. As long as the ISV submits the app into the Catalog and it passes our requirements, we'll leave it there until they remove it. If you'd like us to remove after x number of iterations, make sure you leave that feedback: https://aka.ms/IntuneFeedback.
- Today, when you search the Enterprise App Catalog for an app, you still target the app to your Entra groups, like you do with Win32 apps. This process will be very familiar to you.
- Auto updates of EAM apps is not yet available, though it should be available soon. Once available, we'll have docs on that process.
Hope this helps!