Event banner
Windows Office Hours: June 19, 2025
Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
48 Comments
- Heather_Poulsen
Community Manager
Thanks for joining Office Hours today. We'll be back next month. Visit https://aka.ms/Windows/OfficeHours for upcoming dates.
- shend141Copper Contributor
We need to migrate our Intune Connector for AD v6.18 to v6.25 before the end of June deadline, but when we sign in as the Intune Admin we get a blank page, followed by this error:-
- Joe_Lurie
Microsoft
shend141 Make sure you have the latest Connector, version 6.2504.2001.8. Also, follow these steps documented here. Make sure you are using an account that is not only an Intune Global Admin (or Service Admin) but also has the appropriate domain rights to create the Managed Service Account in each domain where you need to connect Intune to AD.
Also, and I know you know this but it's worth mentioning, the Intune Connector for Active Directory has one purpose: to allow Hybrid-joined Autopilot to create the domain object. If you are using Autopilot in the recommended scenario of Entra-joined only, you do not need the connector as it isn't utilized anywhere else in Intune or for any other scenarios.
- MarioMCopper Contributor
Hi, what is the recommended way to install a new os-Image on a Surface device in Intune only env. We used the Surface Deployment Accelerator (SDA) but it it was updated 4 years ago.
- EricMoe
Microsoft
Have you seen Recovery Tool (IT Toolkit) - Surface | Microsoft Learn ? This article was updated recently and should provide you with the steps to build a Surface image to deploy via USB.
- jdaultonSICopper Contributor
Greetings,
We are working with our OEM partner on a "enterprise-ready" Windows 11 image for the Windows 11 PCs we purchase through them. They have provided a POC for us to test. During the testing we determined that remote wipes and resets via Intune do not work. The process fails around 3-4% for each. Per our OEM partner, there is an issue with Windows 11 Enterprise that is causing the issue.
In testing, the only way we can reset the device is to perform a push-button reset from within Windows and use the "download" option. I believe this option may be downloading the fix as it falls in-line with the information in the release note below.
Per the Windows 11 release notes, this may have been resolved with the April 25, 2025, KB5055627 preview update and officially in the May 13, 2025, KB5058411 update. Per the notes:
"Windows Setup Fixed: If you install Windows 11, version 24H2 with Windows Setup and run System Preparation (Sysprep) afterwards, the boot file configuration is not properly updated, resulting in push-button reset options not working."
Can we confirm that the push-button reset fixes are related to remote wipe/resets performed in Intune? Will this fix be added to the Enterprise build of the Windows 11 OS? If so, do we know what build this will be? If not, how can OEM partners ensure the Enterprise build they send to customers includes this fix?
Thank you,
Jeremy- EricMoe
Microsoft
Hi Jeremy - since this fix shipped in May's update, and would be included in June's update as well, your best bet would be to first test reset through Intune on an up-to-date device and confirm you no longer see the issue. If you do, then the issue must not be related to the fix in 5B, and a new support case should be opened to investigate. Your OEM would need to make sure they are shipping an up-to-date enterprise build based on their image creation processes.
- jdaultonSICopper Contributor
Hello Eric,
Thank you for the prompt reply. I can confirm that a reset through Intune was successful on the machine after performing the push-button reset. During the push-button reset/reinstall of Windows it checks for updates, and I believe the machine received the update at that time. Once that was finished, I performed a reset via Intune which was successful. No other changes were made. I then found the release notes referenced in my initial comment but couldn't specifically find any information that those fixes would apply to remote resets via Intune.
Thank you,
Jeremy
- ahammondOccasional Reader
Hi, I am wondering how I get started with utilizing my nonprofit credits for services( Azure,...etc)? Also, can they be used for Office 365 applications? I have a few licenses that I am paying for directly outside of my nonprofit subscription.
- Phil_Urban
Microsoft
If you're already an approved nonprofit, you can view and activate your grants at https://nonprofit.microsoft.com/ . If you are aren't already approved, you can apply there as well.
- EricMoe
Microsoft
Start here: How to activate your non-profit organization’s Azure credits | Microsoft Community Hub and then check out the FAQ here: Nonprofit FAQ | Microsoft Nonprofits I don't believe we have any experts in nonprofit credits here today, but hopefully these articles help get you in the right direction.
- ahammondOccasional Reader
Ok, it has been activated since January, just not sure how it applies credits for usage, as it is still sitting at the initial grant amount. I'll review your FAQ's. Is there a contact person I can connect with later?
- ReeceOccasional Reader
Is there a way we can prevent our corporate users from signing into the Edge browser with their work accounts on personal devices, but still allow them to log into apps and things such as Office.com on these personal devices? The personal devices are not registered anywhere in Entra/InTune. With the aim being to allow Edge password manager but prevent them from accessing the saved/synced credentials on non-corporate devices.
- Joe_Lurie
Microsoft
Reece I'm not sure I follow. If these devices are not managed, we can't control policy on the devices. However, you can use Entra Conditional Access to control what users can do on unmanaged devices. See Set up device-based Conditional Access policies with Intune - Microsoft Intune | Microsoft Learn for more information.
- ReeceOccasional Reader
Thanks for the response. Yes, so in the way you can use CA to determine what users can access on unmanaged devices, such as preventing the use of SharePoint on them, I'm trying to specifically block the work account from being signed into the Edge browser. However Edge does not appear to be a cloud app option with CA policies.
- Heather_Poulsen
Community Manager
Welcome to Windows Office Hours! In the office today, we have EricMoe, Joe_Lurie, Danny_Guillory, Phil_Urban, AriaUpdated, and others. Let's get started. Post your questions here in the Comments.
- HeyHey16KIron Contributor
Is there a way to download PS scripts once they are uploaded to Intune please? I know you can monitor the local computer ISE folder, deploy the script then quickly copy it but sometimes they disappear too fast. There's just one script we need to get as the person who uploaded it didn't keep an offline copy 🙃. Thank you!
- Joe_Lurie
Microsoft
HeyHey16K Thanks for the feedback. Please like (👍) this post on aka.ms/IntuneFeedback https://feedbackportal.microsoft.com/feedback/idea/6f1a23c9-a819-ef11-989b-000d3a05ece8?q=download+script and add feedback directly from the Scripts blade in the Intune admin center (intune.microsoft.com).
- HeyHey16KIron Contributor
Thank you Joe 😊
- HeyHey16KIron Contributor
Is there a way to export computer HW Hashes from Intune (like we can with SCCM) please?
- Jason_Sandys
Microsoft
Hi HeyHey16K,
No, Intune has no built in method of enabling admins to directly gather Autopilot hardware hashes for direct use or access by admins. However, Intune can automatically register devices with Autopilot without needing this type of functionality or any admin intervention (except a single checkbox on the Autopilot profile). See Automatic registration of existing devices | Microsoft Learn for details. Not sure of your exact use case, but this typically is sufficient for customers.
- HeyHey16KIron Contributor
Thank you Jason 😊
- HeyHey16KIron Contributor
Is there a way to for Autopilot to auto-sync timezone/region before it starts please? e.g. if the computers are shipped from one country and Autopiloted in another? Currently we are running a quick PS command/script first to do this as historically it caused issues with Autopilot if the timezone changed halfway through the build.
Or, even better, tell me this is no longer an issue please 🙏- Joe_Lurie
Microsoft
HI HeyHey16K There are a couple ways to set the timezone in Intune - either from a script or from Settings Catalog. Because Autopilot skips the Privacy page in OOBE, there's no opt-in for Location services, so it's not something we can detect. Please see this post on aka.ms/IntuneFeedback and follow the suggestion https://feedbackportal.microsoft.com/feedback/idea/40e7ba5a-d159-ef11-b4ad-0022484d3ecc
- HeyHey16KIron Contributor
Thank you Joe, am a bit confused though... when the computer is in OOBE before Autopilot starts, Intune isn't managing it at that stage?