Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
35 Comments
- LeeMitchellRPCopper Contributor
The new Intune device all apps > App inventory view is great and a very welcome feature. Are there any plans to surface any of this additional information globally in Discovered Apps? The "Installed for" [User/Device] in this view would be extremely useful.
- ebpoulinCopper Contributor
Hi,
I’m using Windows Autopilot Device Preparation with personal device enrollment set to block. Is there a feature in development that would eliminate the need to use a corporate identifier?
Having to manually add serial numbers or upload a CSV file is quite tedious and time-consuming. With Autopilot (v1), it’s possible to register devices through an OEM or by using the Get-WindowsAutopilotInfo script.
- Maggie_Dakeva
Microsoft
Hi ebpoulin , yes, we have a feature in progress to address this which will be available in the future.
- Heather_Poulsen
Community Manager
ebpoulin - We're checking with the Autopilot team and will get back to you as soon as we can.
- HeyHey16KSteel Contributor
In Apple's WWDAC conference they announced several new features exposed on macOS27, expected in autumn, so they can be controlled by MDM systems like Intune. We are very keen for the new application binaries management (to block/allow applications) feature and was wondering when that will be manageable in Intune please?
- Joe_Lurie
Microsoft
HeyHey16K Good question. Some of the features announced at WWDC will start rolling out in Q3 2026 (Jul-Aug-Sep) and Q4 (Oct-Nov-Dec) and some will be later. Best is to keep an eye on our roadmap page for the specific features you're interested in: Microsoft 365 Roadmap | Microsoft 365
- HeyHey16KSteel Contributor
Thank you Joe_Lurie 🙏
- EthanM1Copper Contributor
What's the best modern and future-proof way to map drives on Entra joined devices (with AD users)? There are community scripts, but does Microsoft offer any tools to make this migration simple and easy to manage in the cloud going forward?
- Joe_Lurie
Microsoft
EthanM1 When you say Entra Joined devices, I assume that these are Intune managed, and will answer based on this assumption. Cloud-native scenarios have no built-in solution for drive mapping, and since you mention "future-proof" I also want to say that drive mapping isn't in the future. Take a look at our Cloud-native endpoints guide, specifically the Mapping Drives and Printers section: Tutorial - Set up cloud-native Windows endpoints with Microsoft Intune - Microsoft Intune | Microsoft Learn.
This will show you where we are investing in the future.
--Joe.
- BallITGuy1Copper Contributor
Azure Monitor | Metrics. I've been upvoting the ability to select multiple network interfaces and disks for 3 years already, but this still isn't available. This seems like such an easy win to have this ability, what's holding this back?
- Joe_Lurie
Microsoft
BallITGuy1 We don't have any Azure Monitor SMEs in this group. Best to ask your question in the Azure Observability space: Azure Observability | Microsoft Community Hub
- RejinaCopper Contributor
In a Microsoft 365 environment, where security controls are distributed across services such as Defender, Intune, and Entra, what governance approaches or integrated reporting methods does Microsoft recommend to consistently map and demonstrate these controls against frameworks like NIST or SOC 2 in an audit context?
- EricMoe
Microsoft
Rejina Similar to your question around Audit compliance, you should start with the Service Trust Portal, Service Trust Portal Home Page, and check out the link for "Resources for Your Organization." Individual controls like NIST and SOC 2 should also be available through this portal.
- fuhr8g93ur8923u0tfe4tgBrass Contributor
hello I have a doubt how Windows is going to organize the feature update of this year and the improvements planned for it
- Heather_Poulsen
Community Manager
fuhr8g93ur8923u0tfe4tg - Feature updates are released in the second half of the calendar year. The best way to preview the improvements planned is to join the Windows Insider Program.
- RejinaCopper Contributor
When relying on Microsoft Defender as a SaaS-based security control, what artifacts or assurance mechanisms should customers use to support shared responsibility and third-party reliance in an audit context?
- EricMoe
Microsoft
Rejina Start here, Service Trust Portal Home Page, and based on what your auditor needs you should be able to pull the correct reports. For instance, SOC 1 Type 2 Reports, SOC 2 Type 2 Reports, ISO certs, etc. The SOC 2 Type 2 explicitly lists several Defender services as in scope, including Microsoft Defender XDR, Microsoft Defender for Endpoint, etc.
- RejinaCopper Contributor
Thank you. In addition to SOC 2 reports covering Microsoft-managed controls, what specific customer-side artifacts or reports (e.g., from Defender or Intune) would you recommend to demonstrate implementation and ongoing effectiveness of those controls in an audit?
- bigmanjohnCopper Contributor
Good morning. My question is how I can ban any user profile level installation of browsers eg Chrome Firefox Brave etc via Intune. I've asked Copilot about this and have been given many versions of solutions, but none would work. Thank you.
- Joe_Lurie
Microsoft
bigmanjohn This is a common question since browsers like Chrome and Firefox can install into the user's AppData folder without requiring admin rights. There are a couple of possible workarounds you can take with Intune:
- App Control for Business: This is the modern application control solution in Windows. You can create policies in Intune under Endpoint Security > App Control for Business that only allow approved applications to run, blocking everything else including user-profile-installed browsers. You can use publisher rules, file path rules, or file hash rules. Here's the guide: Manage approved apps for Windows devices with App Control for Business policy and Managed Installers in Microsoft Intune - Microsoft Intune | Microsoft Learn.
- Device Restriction settings: In a device configuration profile, you can set "Apps from Store only" to block │ installations from outside the Microsoft Store, which covers most user-profile browser installs. See: Device restriction settings for Windows devices in Microsoft Intune - Microsoft Intune | Microsoft Learn.
Hope this helps!
--Joe.
- MEB2004Brass Contributor
I have been having trouble downloading Azure Sign-In logs. Either it says No Sign-ins found or the download fails or I get "The server is receiving too many requests". This happens in both the old and preview versions. I just need to get 30 days of logs with two filters applied and cannot. I got lucky once and got 7 day's worth.
- Heather_Poulsen
Community Manager
MEB2004 - While we don't have any Azure folks "in the office" today, I've seen similar posts in the Azure discussion boards. Browser downloads can time out on large sign-in datasets so the general recommendation is to use the reporting API instead or export logs through diagnostic settings.
- BallITGuy1Copper Contributor
This happens to me regularly also. I ended up using a log analytics workspace to capture all the events, then I query that.