Event banner
Windows Office Hours: May 15, 2025
Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
Please note corrected date.
36 Comments
- Heather_Poulsen
Community Manager
Thanks for joining us for Office Hours today. We'll be back next month on June 19th! https://techcommunity.microsoft.com/event/windowsevents/windows-office-hours-june-19-2025/4391593
- pc-88Brass Contributor
I was recently testing installing Windows 11 24H2 using SCCM task sequences in our Entra hybrid joined environment. Sometimes after imaging I would get a toast notification: 'work or school account problem - to fix this, select this notification to sign in again.' Clicking through to fix it in Windows 11 settings > Accounts > access work or school > "sign in again to fix your work or school account" would just immediately fail with the message "sign in failed. please try again to repair your account". The machines appear to be correctly registered in Entra and Intune, and they do successfully get Intune policies, app deployments, etc. Any idea why this message keeps coming up and how to fix the supposed problem?
I did a little reading and some people recommended exempting Intune device enrollment from MFA Conditional Access requirements, but my understanding is that this shouldn't be necessary since our devices are Entra hybrid joined (and therefore are being registered in Intune by SCCM, and not logged-in user).
- Jason_Sandys
Microsoft
Hi pc-88, have you validated the user has retrieved their PRT and that the hybrid join is truly complete? See for Troubleshoot Microsoft Entra hybrid joined devices - Microsoft Entra ID | Microsoft Learn for guidance on this.
If the device is receiving policy from Intune, then enrollment is complete and so exempting from MFA should be moot.
- CaseyBIron Contributor
We're piloting hotpatch -- this month we got an additional patch on some devices that got the hotpatch CU. It's a powershell security update, KB5061096, -- and Windows calls for a restart after applying it. The KB indicates that this applies to hotpatched devices and may call for a restart, so it seems expected. Any comments on that? Hopefully we don't expect that to be the norm.
- EricMoe
Microsoft
Hi CaseyB, Hotpatching gets you secure faster without requiring the user to restart the device. The KB5061096 article does state if a PowerShell session is active, then a computer restart might be required. Other types of updates may require restarts too. Hotpatching's goal is to get you secure faster, but other update types could require a restart.
- CaseyBIron Contributor
We see issues from time to time where a user needs to set their time zone on Win11. Or they say that the time zone is incorrect for where they are. We typically have devices set to autoupdate the time zone. This relies on location awareness I think. The user sometimes goes to the old control panel and updates the time zone there. But it reverts back. The options to resolve are to turn off location awareness, and then use the older control panel. Or, to turn off autoupdate of the time zone in Settings -- this exposes the time zone dropdown in Settings, Date & time. I saw something in the release notes from the January 28 CU --
- [Settings] New! You can change time zones in Settings > Time & Language > Date & Time. You don’t have to be an admin to make this change.
I find that when I click on Date & time on my Win11 hybrid joined device, I get prompted by UAC -- is this expected? Just trying to get some clarify on how date and time is expected to work for admins and non-admins.
- reastman1966Copper Contributor
We are seeing this now and in some cases the Windows OS has the correct time but Teams will be wrong. I would have to check to see if we have other apps that behave this way so I am just hoping to follow this along to get some insight on what the issue maybe.
- MarttiBrass Contributor
Are there any resources you'd recommend for learning best practices on how to apply Microsoft Purview solutions effectively?
I understand there are many options for configuring DLP, but honestly, I often struggle to even envision how some of them would make sense in a real-world setup.- Dan_Ramacciotti
Microsoft
Martti Check out this guide and links of Microsoft Purview Explore practical best practices to secure your data with Microsoft Purview | Microsoft Security Blog
- nlmitchellBrass Contributor
Slight grumble from me around the Win11 24H2 upgrade. We are in the process of deploying it across our estate, however are having to exclude any devices that have less than 30Gb free diskspace, approx. 1000 devices currently. Most devices only have a 120Gb HDD :-(
I don't recall previous upgrades needing this amount of freespace to be able to apply an OS upgrade.
We are looking at potential solutions and have had calls in with MS about it. Implementing a Storage Sense policy has reduced the number slightly, but still a long way to go
- Heather_Poulsen
Community Manager
Welcome to Office Hours! If you need help with planning for migration, deployment, configuration, management, updates, and [fill in the blank], we're here to help.
- mjsrcCopper Contributor
We are attempting to configure organizational messaging for sending out emergency alerts and other service messages. In our testing we've found it very inconsistent in sending messages out to the test group of users that we selected. Some users get the messages, and others do not. We have completely validated that the users are getting the same policies applied. I have followed the Microsoft documentation on configuring the correct policy (see Organizational messages in the Microsoft 365 admin center - Microsoft 365 admin | Microsoft Learn) and all users are licensed with Microsoft 365 E5 licenses which meet the licensing requirements. We have submitted a ticket to Microsoft Support on this issue, but they have not provided a resolution. I did find that if a user has the "Suggested" notification option turned off, this negatively affects a user being able to see the toast notification. Are there any other settings or configurations that could affect a user being able to receive an org message toast or taskbar notification?
- UserVoiceCopper Contributor
- There is an ongoing MAPI problem within the Graph service preventing 3rd party software from accessing some end-users’ mailboxes. Do you have any info about the case and fixing progress on MS end?
- EOP servers in the UKSouth Azure region seems inefficient because they return much more temporary exceptions than several other Azure regions. Is there anything wrong happening there? Any maintenances?
- There are much more network related exceptions (“A transport-level error has occurred when receiving results from the server”) within the function apps in the WestEurope Azure region. Is there anything wrong happening there? Any maintenances?
- According to CA/Browser Forum decision about reducing SSL certificates lifetime up to 47 days in 2029 - what incoming features or integrations should we expect for services like Azure Key Vault? More 3rd party vendors to automatically buy and renew certs?
- haris7777Occasional Reader
We are totally based on cloud with nothing on prem. We all work remote and a bunch of our users are windows 10. Please if you can advise me the exact steps of migrating win10 users to win 11. also would it have any impact on users system like data loss or BSOD during migration. Secondly, I have the global admin rights and I am unable to join devices to cloud our per user device limit restriction is 6 and I have 5 devices with 1 left for my own use. Please advice how can I increase my limit to enroll more devices
- nlmitchellBrass Contributor
We are upgrading ours using an Intune Feature Update Policy. This alongside an Update Ring policy allows the user some flexibility around when it gets forced/deadlined on them. We kicked off the 24H2 upgrade on the 6th May and have upgraded over 2,000 in just over a week, no loss of data or BSOD's reported so far....famous last words :-)
- Rob_WillisCopper Contributor
We used the windows 11 installation media from here Download Windows 11. I created a bootable USB, put the files on a mapped drive and sent this to all users. They then installed at a time that was convenient to them. It took around an hour for each machine and we completed 176 in a week. There was no loss of data and profiles stayed intact. With regards to your limits when enrolling this should help: Understand Intune and Microsoft Entra device limit restrictions - Microsoft Intune | Microsoft Learn
- Dan_Ramacciotti
Microsoft
haris7777 The Windows 10 device can be updated using Intune Feature Update Policy or even just using Windows Update. Using a cloud service like One Drive is a great way to make sure user data has a backup before the upgrade. With Intune you could use DEM Account or adjust your device limit in Entra.
- Jason_Sandys
Microsoft
Tacking on to Dan's answer a bit, keep in mind that DEM accounts should not accounts used by actual users. Instead, they should be generic accounts. For clarity though, haris7777, you asking about "enrolling", enrolling to what though? Are you talking about enrolling the devices into Intune for management? Or are you instead referring to "joining" the devices to Entra? Can you provide more details about the full scenario including current device state and where you are going besides wanting to upgrade the devices to Win11?