Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
64 Comments
- HeyHey16KIron Contributor
In light of Configuration Manager switching to an annual release cadence, to focus on Intune, will more CM only features be added to Intune? For example, recording current user, advanced device inventory alike what CM records, software monitoring etc. please?
- Danny_Guillory
Microsoft
Our goal with Intune is to continue expanding capabilities that help organizations manage devices and apps in a cloud-first way. While some Configuration Manager (CM)-specific features may not map directly to Intune, we are actively investing new scenarios that will help you in your journey to cloud.
- HeyHey16KIron Contributor
Thank you Danny 🙏
- Samsquanch90Copper Contributor
Is version 1 Autopilot still available for Hybrid Joined Devices? We are having issues on the AD join and have been told that we cannot use deployment profiles for hybrid join scenario. We are using the Zscaler Machine tunnel as a required app as part of the ESP.
- Joe_Lurie
Microsoft
Samsquanch90 You can still use Autopilot for Hybrid-joined devices. Are you using the latest ODJ Connector?
And as you know, we highly recommend using Autopilot for Entra joined devices, not for Hybrid-joined.- Samsquanch90Copper Contributor
Thanks Joe_Lurie Yes we are using the lates Intune Connector for AD. We're getting a failure after "Starting wait for ODJ blob" that states "Timed out waiting for ODJ blob for connectivity.
- HeyHey16KIron Contributor
We asked (via OH I think) in July if there was a way to be able to pause individual Windows Updates via Intune instead of just pausing everything or nothing. Someone replied to say it's coming in a few months. Do you know when that may be please?
- HeyHey16KIron Contributor
Thank you both 🙏
- Jason_Sandys
Microsoft
Hi HeyHey16K ,
There is no ability for that today although in general, there's no value in doing this as there are no "individual" updates to pause. For quality updates, in general, there are simply the monthly cumulative Windows updates. .NET Framework updates do fall into this category as well and cannot be separately paused. There is in-flight work to provide granular control for these different update types, but there's nothing to share on when this will be completed.
- JaminAlmond
Microsoft
Good day Heyhey25 ,
I’m not aware of any capabilities on the roadmap to pause individual updates. At this time, you can only pause updates at the Quality Update or Feature Update level, aligned with your organizational process and policies.
- Heather_Poulsen
Community Manager
Welcome to November's Office Hours. We're looking through the questions you've already posted, but feel free to keep them coming. We're here to help!
- HeyHey16KIron Contributor
Hi Guys👋, just wondering if there is a way yet to see on the local computer what OCPS settings are applied please?
- DavidGutierrezOccasional Reader
Are there any initiatives to make Autopilot more... automatic? In a world with systems that are racing to outthink me and anticipate my needs, I would love a 100% unattended experience for device setup in my environment. At this point, once I am entering inventory data into a group I am already giving enough attention to a task to give it all my attention, and I'll just take the five minutes to manage it and never see any value from devoting time to configuring Autopilot anything.
- Jason_Sandys
Microsoft
Hi DavidGutierrez,
Can you be a little more specific on what your expectations and requirements are? Autopilot, other than the initial login which should be performed by the end-user, is unattended for core provisioning tasks. Autopilot does represent a shift though to a user-driven and user-centric process that may require some adjustments in your process to fully embrace. For userless devices like kiosks, self-deploying mode can be used.
- lalanc01Iron Contributor
Hi, is there a way to control or mitigate the reboots for extension drivers that are auto installed when using WUFB drivers and firmware since they don't respect deadline settings?
Asking to avoid uncontrolled restart of devices due to those drivers which is preventing us from using the feature.
thks in advance and don't hesitate if you have any questions- RyanSteele-CoVIron Contributor
I'm not from Microsoft, but my guess is that your OEM has packaged the drivers in such a way that the installation is initiating its own reboot. This would be up to your OEM to address. (I can share that we use WUfB to deploy drivers to Microsoft Surface and Dell machines and we haven't had any reports of unexpected reboots.)
- JaminAlmond
Microsoft
Good day,
If you’re on cloud-native devices, we recently announced maintenance windows, which you can use to manage install timing and reboot control.
What's new in Microsoft Intune at Ignite - Microsoft Intune Blog- lalanc01Iron Contributor
Will driver extension respect maintenance Windows?
- estefonm23Occasional Reader
Within a co-management environment, there are some machines that are starting to drop from Intune even though co-management is enabled. Within SCCM we have co-management enabled on ALL devices. But I am noticing some of these machines that are dropping from intune are still updating or getting Intune policies when I sign in and verify if the Info button is in the Access work or school account. When I select Sync it asks for me to sign in (I use an admin account as I troubleshoot). My question is that, does a licensed intune account have to sign into the machine every so often to prevent it from dropping from Intune?
- Joe_Lurie
Microsoft
estefonm23 You should not need to login occasionally to keep the device enrolled in Intune, when it's enrolled via Co-management. Devices that are enrolled as part of co-management have that enrollment tied to the device and its Entra ID join state, not the user. You can do a dsregsmd /status to check the join state and verify MDM URL, or check the CoManagementHandler.log for any errors. But if devices are falling out of Co-management and you cannot determine why, you may need to open a ticket for further troubleshooting.
- estefonm23Occasional Reader
I thought the same thing, however, I when I looked at the logs it would mention that the Azure AD creds are not recognized until I signed into the machine then everything was fine. Any ideas, for that?
- RyanSteele-CoVIron Contributor
Back in August I asked about the possibility of performing an in-place reinstall of Windows without having to remove the device from Intune update management and have someone manually press the "Reinstall now" button in the Settings app under "System > Recovery". At that time I was told it was not possible.
I have since learned from this blog post that there is in fact a way to do this. Apparently Microsoft Support is telling customers that they can simply create the following registry value to initiate the in-place reinstall:
Key: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion
Value name: AllowInplaceUpgrade
Value data: 4
Value type: REG_DWORDI can confirm that on a machine where the in-place reinstall has been manually initiated, the value is present, except the value data is 1 instead of 4.
Unfortunately, there doesn't appear to be any official documentation about this function, aside from an off-hand reference to the value name on this support page: Windows Update Troubleshooter for devices experiencing recurring issues installing monthly security updates - Microsoft Support
Can someone please provide the technical details? What is the significance of the value data? Does it change the behavior in some way? And why isn't this documented anywhere?
- Joe_Lurie
Microsoft
RyanSteele-CoV Thanks for the question. This is not a key/value that we publicly document, so we don't have anything to share here. I can tell you, though, that this reg key is used by some Windows Update components as a flag to direct the client to offer or perform an in‑place upgrade (IPU) under certain remediation or admin‑initiated scenarios. Sorry we can't get deeper into the nitty gritty here.
- RyanSteele-CoVIron Contributor
Thanks for responding. If you are able to share feedback with whoever is responsible for this: as long as Windows is prone to getting into a state where updates can no longer be installed, administrators need a way to remotely initiate an in-place reinstall. This is a security issue.
- Deleted
Seeking confirmation. The Outlook mobile client is not processing workspace booking requests. Allows for the workspace to be selected, yet no invitation is received to the workspace resource calendar. I've been working with 365 support (case number 2510230040003387) and would like to know if this issue is isolated to my specific environment or if others are currently experiencing the issue. The process works without any issues from the Outlook desktop (classic and new) and OWA clients. It even works when using OWA on the same mobile device in which it does not work from the Outlook mobile client. Tested on Apple and Android and while using version 4.2539.2 and 5.2543.0 versions of the Outlook mobile app.
- RyanSteele-CoVIron Contributor
I've been working with 365 support
You have my sympathies.
I just tested and I can confirm that I was able to successfully book a workspace using Outlook version 5.2545.0 on my iPhone 13 running iOS 18.7.2.