Event details
Have a question about Windows 11, device management, security, updates, or modern endpoint operations? This hour is dedicated entirely to your questions. Bring what's top of mind—from Windows 11 adoption and application compatibility to update management, cloud-native administration, Zero Trust, Intune, Windows 365, and hybrid environments.
Drop your questions in the comments and hear directly from Microsoft experts. Whether you're planning your next rollout, troubleshooting a management challenge, evaluating new capabilities, or looking for best practices, this is your opportunity to get answers and learn from the questions other IT admins are asking right now.
This is part of our continuing series of live Q&A for IT professionals here on Tech Community. Follow the Windows Office Hours to add future dates to your calendar.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
49 Comments
- HeyHey16KSteel Contributor
Hey guys 👋, have you had any reports of LAPS password issues on macOS Tahoe 26.5.2? Since we upgraded, after a scheduled LAPS password rotation, macOS local admin account stops accepting the Intune stored password and goes straight into account lockdown. Manual password rotation doesn't make any difference. Issue doesn't affect our (new version of) PSSO managed standard user account on the same computer. If we rebuild the computer, no problems with the LAPS password until the scheduled rotation then problem re-appears 😭. Both the local admin and standard user local accounts are created by ADE Profile during the build.
- Heather_Poulsen
Community Manager
Thanks for joining Office Hours. We'll be back next month: Windows Office Hours: August 20, 2026 - Windows Tech Community
- Dom_CoteIron Contributor
Did Modern Standby behavior change in the last few years? PCs in ModS used to stay network connected and would receive MDM commands. Especially awesome were wipes, which would happen even at night, as long as the deivce was in ModS and network connected.
In fact, modern apps could periodically connect and sync as well, such as the old Windows Mail app.
These days, it seems devices always, invariably completely disconnect from the network while sleeping.
- Dom_CoteIron Contributor
Is there an MDM CSP by now that lets us enable Windows Hello Face Login Anti Spoof?
For the longest time, we needed to deploy a script to set a reg key.- Joe_Lurie
Microsoft
Dom_Cote Yes, I believe you can manage this through the PassportForWork CSP rather than a custom reg-key script. The anti-spoofing control lives under:
.../Biometrics/FacialFeaturesUseEnhancedAntiSpoofing
...which you can push via a Settings Catalog profile (search "enhanced anti-spoofing") or an OMA-URI custom policy.
CSP reference: https://learn.microsoft.com/windows/client-management/mdm/passportforwork-csp
- Dom_CoteIron Contributor
It is still REALLY hard to get new Windows Devices to encrypt Bitlocker with 256bit AES from OoBE.
Normally, the Entra join happens before Intune enrollment and Bitlocker policy deployment.
That causes Windows to do the stone-age 128bit AES encryption.
Currently, we cludge that by scheduling a decryption task and then letting Intune remediate it with the intended 256AES encryption. While it works, it is not elegant.
Can we get Windows do just encrypt with 256bit AES by default please? That'll fix so much - Mahesh_STWCopper Contributor
We are looking for a customised name in company portal for the apps . So we can organisation standard on the Intune and user understandable name on the company portal. We have this feature in MECM console which is missing in Intune.
- Dom_CoteIron Contributor
Does the option to apply branding to company portal in Intune not work for you?
- Mahesh_STWCopper Contributor
Not the branding, we can apply branding successfully.
On Intune Apps blade, For any app under the App information the Name should be Organisation custom name and in Company portal the same App should reflect is User understandable name.
Example: Here the name was with Organisation standard name, is there any possible for users in compnay portal can have only Notepad ++.
- EnterUsernameHereOccasional Reader
Is there a reason why Windows Catalog Apps and the Auto Updates are only available for required apps? They would be far more useful for us, if we could use it with available apps too.
- Joe_Lurie
Microsoft
EnterUsernameHere Great question. Today the Enterprise App Catalog ties automatic updates to the Required assignment because Intune owns the full install-and-update lifecycle for those apps. With Available (user-initiated) installs there's no guaranteed baseline version to update from. It's a reasonable ask though, and is on our backlog. The best way to get it prioritized is to log/upvote it at https://aka.ms/IntuneFeedback .
- Dom_CoteIron Contributor
Are there any plans to add additional repositories to Intune Windows App deployment?
For example, Winget? Or Nuget? Choco? Sometimes there are frameworks or dependencies that really only can be installed from there.
I know we can script that, but we all know the shortest joke in IT: Let script that real quick... - pc-88Brass Contributor
We’re in a hybrid environment but currently don’t manually delete our old devices from Entra or Intune. (For some reason, deleting devices from our on-prem AD will not always remove them from Entra.) I’ve read that deleting them in the wrong order (i.e. deleting from Entra before Intune) can cause certain issues, but as far as I can tell those issues are all related to Autopilot. If we currently don’t use Autopilot at all, are we able to freely delete old devices from Entra and Intune in any order without causing issues down the line?
- Jason_Sandys
Microsoft
Hi pc-88, To the best of my knowledge and experience, without Autopilot involved, there is no implication to the order of deletes of these objects.
- pc-88Brass Contributor
Thanks. And just to confirm, if you are using Autopilot, is this the correct order?
- delete device in Intune
- delete device in Autopilot (if present)
- delete device in Entra
- EnterUsernameHereOccasional Reader
Another question, regarding the OOBE Updates. Is this more or less finished, or could it be, that we would be able to install updates during the Device Setup in a future release?
- AriaUpdated
Microsoft
Quality updates are available today to deploy during OOBE today. As for other updates, are you looking for some specific updates / capability?
- EnterUsernameHereOccasional Reader
They are and it is working fine. But we can only deploy them after the Device Setup, during the account setup, so after a user logs in. That means f.e. that the users have to restart the devices, because of many of the quality updates and drivers, but also have to wait about 30-60 minutes.
With my question I was more looking at the possibility to use the OOBE Updates, before the users log in. During the technician phase or PPD.