Event banner
Windows Office Hours: November 16, 2023
Event details
Get answers to your questions about adopting Windows 11 and managing the Windows devices used by remote, onsite, and hybrid workers across your organization. Get tips on keeping devices up to date effectively! Learn how to cloud attach your on-premises workloads!
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below. |
65 Comments
- marycortezCopper ContributorHi, I have some users who work out of the office so they sometimes require administrator access to complete something on their computer. What would be a great way to allow them access for a one time event? I currently have Device Administrators set up in Azure AD.
- David_Guyer
Microsoft
Hi Maryann, Consider using the new Endpoint Privilege Management feature in Intune, which is designed to first configure devices for Standard User access, a much more secure way to use Windows... and then to have the "exceptions" to that defined, so that customers can install and run specific software, and more. It might just be a great fit. https://learn.microsoft.com/en-us/mem/intune/protect/epm-overview HTH, -David
- Levin_SchalkOccasional ReaderWe want to configure Autopilot through Intune. We have a Hybrid Azure AD with local AD without an AD FS. We want that the Autopilot devices also join the local AD. I have set up an OU with the required permissions and set up a Gateway between Intune and local AD. The gateway shows online and Active, but no matter what we tried so far, we can't get the Autopilot device to join the local AD. It fails and we have only the Option to start over. Are there any special requirements if we don't have an AD FS or what do I need to configure so we can use Autopilot in our Hybrid tenant?
- Jason_Sandys
Microsoft
Hi Levin. Can you expand what you mean by "Gateway"? Are you referring to Azure AD Connect? Have you also set up the Intune Connector for AD? Are you also deploying a VPN client during Autopilot so that the device can connect to your on-prem AD (assuming the device is no on-prem)? Finally, can you also expand on what you mean by "Option to start over"? Also, just to call it out here, we strongly recommend avoiding this approach. Autopilot works best with Entra Joined (aka Azure AD joined) and we strongly recommend not using hybrid join with Autopilot for a variety of reasons. Cloud value is best realized with Entra joined and this aligns with all of our engineering investment and direction while also avoiding the many shortfalls of hybrid join with Autopilot. This recommendation is detailed at https://learn.microsoft.com/en-us/mem/solutions/cloud-native-endpoints/azure-ad-joined-hybrid-azure-ad-joined#which-option-is-right-for-your-organization- Levin_SchalkOccasional ReaderWe have set up Azure AD Connect and the Intune Connector for AD on the same Windows Server. The synchronisation between AD and Azure AD works and the Intune Connector shows up in the Intune Endpoint Management Console. It shows as Aktive and working. We have successfully testet an Autopilot profile wit AAD only. But we can't get the Hybrid join working. When the enrolment gets to the point to join the local AD it fails and the only Option it lets us choose is to reset the Device again. As of right now we are highly dependent on local AD management. That`s why we need our devices as hybrid. Also we would like to use Autopilot to simplify the process of resetting old devices and setting up new ones.
- ColreynoCopper ContributorWith Intune enrolled Windows devices they are scanned for Malware threats and that is reported up through the MDO home page. Is there an alert/report that is triggered somewhere that would let me know via email that devices are being found with active threats?
- David_Guyer
Microsoft
Vulnerability reports are going to be found in the Microsoft Defender for Endpoints portal. The integration with Intune enables you to create a security task from a security issue, and that security task will show up and be tracked in both Intune and MDE. HTH, -David - Rich_OlsonCopper ContributorWe ran into this same issue and was told no there is no way for the this alert to email someone that malware was found.
- Eli_RamirezCopper ContributorIf the registry key for Office 365 enterprise cloud update (below) is deleted, is there a way to force it to sync again? HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\cloud\office\16.0\Common\officesvcmanager\officeupdate
- Sean_McLaren
Microsoft
Hi Eli, Are you looking for a way as an IT Admin to set automatic updating for remote machines or are you looking for steps on the physical device? Is this M365 apps on Windows or Mac and is it fairly current already?- Eli_RamirezCopper ContributorYes, it's on M365 apps for enterprise on Windows and it's on the latest current channel version. I'm more so looking for steps on the physical device, but either would help.
- Laser235Copper ContributorWhat is the recommended ADMX group policies if running a blend of Windows 10, 11, with the majority Windows 10 clients?.
- Sean_McLaren
Microsoft
Hi Gary, The latest ADMX templates have been updated and are backwards compatible with Windows 10, so as long as you are running a mix of Windows 11 and Windows 10 22H2, you should be fine with the latest templates.- Laser235Copper Contributor
So long as we use the latest Windows 11 ADMX templates should be compatible, correct?
- IndiaYankeeBrass ContributorWindows Autopilot: I am looking for a way to make the handling of the motherboard change issue more efficient. We have more than 7000 laptops in our tenant. All the devices are from the same production batch. That means that with time, we get more refurbish motherboards as replacement parts. With laptops, changing of the motherboard is the most common type of repair. In our organization, now that the devices are about 3 years old, changing of motherboards is something that happens every week. Changing of a motherboard calls for the re-registering of the device in Autopilot as the HW identifier for the motherboard is unique. This is a school organization where we host IT services for about 70 schools and other institutions in the district. The only way I have, to handle those issues is by getting the devices here to head office after repair where I can re-register them in Autopilot. This is a tedious process which is taking a lot of resources from clients and me. With refurbished boards the issue of boards that are still registered in other tenants and thus cannot be imported to Autopilot (error 806) is getting more and more common. Right now, it looks like we are having this issue with every 3rd board. Every time it means opening a case at Microsoft, uploading different materials, proof of ownership etc. I have been working in this business for about 20 years now and I have never had the need to open so many support cases. With every case handling taking between 1 to 4 weeks to resolve, this is not a good way to run a service. I am looking for a way for making the re-registration of the boards more effective where I would no need to get the machines over here, and where I won’t need to run all those cases with Microsoft support. I guess, that if I wont find a better way, I will have to conclude that Microsoft Autopilot is simply not suitable for organizations like ours and drop the use of it in the near future.
- Jason_Sandys
Microsoft
Hi Ido. I'm sorry for your frustration on this scenario and the additional work it's causing you. What version of Windows are you running and is there a single hardware vendor for all of these devices? Also, who is performing the motherboard replacement? A tech from the vendor?- IndiaYankeeBrass ContributorHej Jason, thank you for your reply. We are running Windows 10 22H2 and the devices are all Dell Latitude 13" and 15" with following serial numbers(!). This is a school evironment. It's a public sector organization. A large land district. All our purchase is bound to public procurement rules. That means that we have a 4 years hardware support contract with at big firm here in Denmark. Our contractor is working with Dell support. We are replacing our HW every 4 years bound to those public procurement rules and it is always one of the big producents that wins. We worked with Lenovo products for many years for example. Nevertheles, it is common that we need to change many motherboards. it is very common procedure i am afraid...
- Rich_OlsonCopper ContributorWhat is the difference between Windows CoPilot that is showing up on the Taskbar in Preview Mode and Windows CoPilot in Edge?
- Jason_Leznek
Microsoft
Copilot in Windows includes access to Bing Chat/Bing Chat Enterprise (what you see in the Copilot tab in Edge) as well as Windows Skills. The tab in Edge only gives you access to Bing Chat/Bing Chat Enterprise.
- Rich_OlsonCopper ContributorI have read that there is a Microsoft 365 CoPilot - I do not see it anywhere in any of our Office Applications - how do we get it and where it is found?
- ThomasTrombleyFormer EmployeeGood morning/afternoon/evening Rich, we're still catching up on yesterday's Ignite keynotes and announcements ourselves, ha! However, this page provides a boatload of additional details from yesterday's Ignite efforts: https://www.microsoft.com/en-us/bing/chat/enterprise/?form=MA13FV.
- Rich_OlsonCopper ContributorI see nothing on this link about Microsoft 365 CoPilot
- Heather_Poulsen
Community Manager
Welcome to Windows Office Hours! We've got a group spanning Windows, Intune, and Windows 365 in the virtual office today and ready to help with your questions. Update management, Windows LAPS, Windows 11 adoption, and device management -- what's top of mind for you? Let's get started!
- yılmazozkanOccasional Readeriyi günler kolay gelsin benim bilgisayarıma sürekli windows hesabınızı etkinleştirin diye bilirim geliyor ve eski ürün anahtarımı bilmiyorum bu konuda bana yardımcı olabilirmisiniz
- ChrisSutcliffeCopper ContributorHere's a couple of good questions that a lot of people have been asking for a while, with little to no response. 1. Why hasn't the Microsoft store been working for 2-3 weeks now? 2-3 weeks. The Whatsapp app has become completely useless as it needs an update but the Microsoft Store will not open the page to update it. As a matter of fact, it wont open any app page. This is obvious when you look at the "Feedback" hub, where everyone is equally as confused with no real solution. Just the fact that some users buy items and then have no access to them... well that's what most people would call a scam. (Code: 0x80070424 CV: 2JLqlsqWyEufFxpASv0pQg) 2. For a vast number of Windows users, and people that are having the same Microsoft Store problem, the ability to update Windows in general is simply non existent. Again, in the Feedback Hub its all there, with 0 answers. No amount of troubleshooting helps because the device barely even recognizes that its a feature. This has already happened before and I somehow managed to forcefully update Windows but the problem persists. So the question is; why hasn't this been fixed at all? My laptop isn't even a year old but the amount of problems Windows has given is unbelievable. And its a Victus so the hardware shouldn't be a problem. Please, help.
- ChrisSutcliffeCopper ContributorI dont know if this actually has anything to do with it or if its just pure luck, but everything I listed yesterday which has been causing problems for months is all fixed now. I really appreciate it. Thank you.
- OrhanMehmedCopper Contributor
Hi there,
So, we've tried to deploy storage device management in the company that was supposed to block all storage devices (USB, ext HDD etc.) and allow specific approved devices using this document https://learn.microsoft.com/en-us/mem/intune/configuration/administrative-templates-restrict-usb but MS Support person told us the Intune controls in the doc are for preventing installation of all system devices (and drivers, surprise!), not just USBs. Even with all the GUIDs in the doc added as 'allowed' in Intune, we had a pretty crappy month of WiFi, graphics, BT, sound, printers and even monitors blocked by this policy.
I've tried using this doc (Intune /> Scenario 1) https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/deploy-manage-removable-storage-intune?view=o365-worldwide#scenario-1-prevent-write-and-execute-access-to-all-but-allow-specific-approved-usbs-1 but it doesn't work. The reusable settings are in the registry, but the 'allowed' devices are still been blocked on Windows 10. Also, the policy is entirely non functional on Windows 11 - it doesn't even block the storage devices even with the registry keys present.
I've raised 2 tickets about this and after 4 weeks now, there isn't even an agent assigned to the cases. Can someone please advice? We are on 300+ licenses E3 + E5 Security which is tons of money and we can't even get a simple 1st line support.
Thanks.