Event details
Get answers to your questions about adopting Windows 11 and managing Windows devices across your organization. Find out how to proactively implement and monitor Zero Trust practices. Get tips on keeping devices up to date. Learn how to move forward with cloud-native workloads, even if you have on-premises or hybrid needs.
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
50 Comments
- RVLCopper ContributorFollowing the installation of the June 2025 Windows security update (https://support.microsoft.com/help/5060842) or later updates, we encounter issues with Windows Hello PIN setup on Microsoft Entra joined devices. 
 Tried applying a new Intune policy to devices instead of users, but still got the error.
 What is the fix and for which Windows versions does it work ?- Jason_SandysMicrosoft Hi RVL, This issue is fixed with the October Cumulative update (released two days ago). https://support.microsoft.com/help/5065789. 
 
- derhoeppiOccasional ReaderHi, one question to the application management in Windows 11 and Intune. We have many applications that works alone. But some user groups (e.g. developers) use multiple of that applications. Our problem is that we provide the most of that applications as available. If there is a new version we use the "Auto-Update" feature to update our clients. To checkins and the application starts updating. Thats fine but our developers are note amused if we kill them different applications without any warning multiple times in a week. So my question is - is it possible that the Intune team implement a deathline for the "Auto Update" feature so that the there is no static (hard) limit with two checkins? Our users would be happy if the could define an installation time. And we would be happy if we can force that update due an update deathline. 
- HeyHey16KIron ContributorSeveral key firewall settings currently available in Group Policy do not seem to be available in the Intune firewall settings? e.g. Windows Defender Firewall: Allow authenticated IPsec bypass Windows Defender Firewall: Allow inbound Remote Desktop exceptions from certain IP addresses Windows Defender Firewall: Allow inbound UPnP framework exceptions Windows Defender Firewall: Allow local port exceptions Windows Defender Firewall: Allow local program exceptions Windows Defender Firewall: Do not allow exceptions Windows Defender Firewall: Prohibit notifications 
 When will these be added please?- Jason_SandysMicrosoft Hi HeyHey16K, Since the release of 25H2, we're going to now focus on closing gaps in policy for notable missing policies (there aren't all that many left). Thank you for bringing this up and I will add it to my list of items we need to ensure get addressed. I can't give you a timeline of when these will be added but can ensure you that we will be reviewing and adding to the backlog of policies that need to be added. - HeyHey16KIron ContributorThank you Jason 🙏. We're trying to get as much out of Group Policy into Intune as possible, so that will really help 😁 
 
 
- HeyHey16KIron ContributorWhen will it be possible to download scripts that have been uploaded to Intune please? - Danny_GuilloryMicrosoft Interesting ask. Not the 1st time we have gotten that request. Something we will evaluate at some point in the future. - HeyHey16KIron ContributorThank you Danny 🙏 
 
 
- HeyHey16KIron ContributorIs it possible to export HW Hashes from Intune yet please (like we can do with Configuration Manager)? If so, how please? 🙂 - Maggie_DakevaMicrosoft Hi, do you mean export the list of HH for all Autopilot registered devices you have? If so, that's available in the Autopilot devices list - HeyHey16KIron ContributorHi Maggie - yes please. I'm looking at that screen now but cannot see where the hardware hashes are? They're not in the export on this page either? 
 
 
- HeyHey16KIron ContributorHi guys 👋, 
 Just wondering if there is still an issue with Autopilot and timezones please. Currently we run a PS script in OOBE to check/set region/timezone etc. to ensure the computer has the correct region/timezone (e.g. if it's been shipped from abroad) before Autopilot runs (because if it's not right, then corrects itself halfway through Autopilot, Autopilot has a tantrum). Is this step still necessary or can Autopilot handle this now, perhaps include an automatic region/timezone check/set itself before it starts please? It would be amazing if we could ditch the OOBE PS script 🙏- Maggie_DakevaMicrosoft Hi! Unfortunately, the script would still be needed - HeyHey16KIron ContributorOK thank you Maggie, appreciate the response 👍 
 
 
- Piyush1Copper ContributorHello, I have a question regarding the Secure Boot certificates that are set to expire in July 2026, as outlined in this Act now: Secure Boot certificates expire in June 2026 - Windows IT Pro Blog We’ve already taken the recommended steps to obtain the updated certificates. Could you please clarify when the new certificates will be deployed to our devices, and how we can verify that they’ve been successfully installed? Thanks. - Jason_SandysMicrosoft Hi Piyush1, Depending on a variety of factors including hardware compatibility, cert updates will be gradually rolling out to device over the next 8-9 months. Thus, there is no explicit or predictable timeframe. Make sure that you check with your hardware vendors for updated firmware if necessary. Additionally, there is a fair amount of documentation that we have not published yet that will admins validate the process and state of the cert update process. I think most of this additional documentation is set to be published in the next few weeks. 
 
- MatthewWagsterCopper ContributorMC1160180 and MC1152323 say that the M365 Companion Apps and Copilot app will be "automatically installed" on devices with Windows 11 and M365 Desktop client apps on them. How will these apps be automatically installed? Is it being pushed through Windows store? M365 Apps for Enterprise update? Windows update? Something else? - EricMoeMicrosoft MatthewWagster - both the M365 Companion Apps and the M365 Copilot App deployment settings are in the Microsoft 365 Apps admin center (config.office.com), under Customization | Device Configuration, then select the Modern Apps Settings tab. You will see default deployment configurations for Microsoft 365 Companion apps and the Microsoft 365 Copilot app. Both of these have tenant-wide settings to enable automatic installation. If you have a separate team managing your M365 admin centers, you will need to work with them to ensure these policies are configured the way you need for your organization. - MatthewWagsterCopper ContributorThank you. I have disabled the automatic install in our production environment already until we can better understand the deployment method, but what we're trying to understand is HOW these apps are being deployed? We tightly control our environment and have Windows Store blocked on client devices, so we're trying to understand how these apps are "automatically installed" so we can figure out if it's blocked or not by something else we have in place. 
 
 
- MikeChapmanCopper ContributorOut of several hundred devices, most have migrated from Windows 10 to Windows 11 but about 40 laptops still haven't been offered the upgrade. All our devices are subject to the same Windows Update for Business policies in Intune / AD / Configuration Manager and as far as I can tell, the devices stuck on Windows 10 are hardware compatible with Windows 11 and don't have any high risks that are blocking upgrades. The installation assistant works fine, but it's a massive inconvenience when users are working remotely and there's no maintenance window. Is this a common scenario and do I need to repair the Windows Update mechanism on these machines or is there something else I need to do? - Joe_LurieMicrosoft MichaelChapman Without more info, it's hard to say if this is a common scenario. What we see a lot is low disk space issues causing the upgrade to fail. Or a Safeguard Hold that causes it to not be offered. In this case, there also may be a conflict between policies being offered via Intune / AD / ConfigMgr. I don't want to say that you have to repair the Windows Update agent, but if you haven't tried that on one of the devices, it couldn't hurt to try. You also may want to open a ticket, so they can gather logs. - MikeChapmanCopper ContributorThanks Joe. We do have some safeguard holds on drivers and some low disk space issues, but there are a lot that don't have even a medium risk reported. I've followed official guides and community posts for fixing Windows Update on some but these haven't helped. I've done my best to retire any legacy GP objects and ConfigMgr policies for updates, but I'm worried there are tattooed settings in their registries. Are there any keys in particular that I should check? 
 
 
- nlmitchellIron ContributorWe have began rolling out Windows 11 25H2 to our ICT department. Other test phases are planned before rollout to all devices on our estate. My query is around Hotpatching. We utilise Hotpatching and have done since the beginning of this year. From what I've read, if you upgrade to 25H2 during a non-baseline release month (Feb/Mar/May/Jun/Aug/Sep/Nov/Dec) then it will break hotpatching until the next baseline release. To retain consistent Hotpatching functionality you need to upgrade during a baseline release month (Jan/Apr/Jul/Oct). Does it matter if you upgrade before or after that months cumulative OS updates on Patch Tuesday (B Release) get applied to devices? Basically, the ICT devices that have been upgraded this week, pre Patch Tuesday, will Hotpatching continue to function? Ones that are upgraded post Patch Tuesday (planned for the 22nd Oct), will Hotpatching continue to function? Our global rollout is planned at the end of November (assuming no major issues are reported in testing phases), from what I'm reading that means that they won't receive Hotpatching in December, they'll revert back to the 'normal' process where users will have to reboot to finalise the monthly updates. They'll then start Hotpatching again in February next year once they've received the baseline release in January?? By the time this event happens on the 16th Oct I guess we'll have our answer about the IT devices, just wondered if you had any further guidance? Thanks - EricMoeMicrosoft Hi nlmitchell, this is a great question. For a device to be eligible for a hotpatch it needs to have installed the most current baseline update. So for November and December, devices need to be on the October baseline update in order to be eligible for a hotpatch. So let's look at your example here: You have a device on Windows 11 24H2 and you update to 25H2 sometime after October 14, 2025 but before November patch Tuesday. And then the 25H2 device takes delivery of the October baseline for Windows 11 25H2. This keeps it on the hotpatch "train" for November and December. But suppose you upgrade to 25H2 after the November update is released, your device would scan and see that it needs the November non-hotpatch and then it's off the hotpatch train until after the January baseline. Hotpatching absolutely will keep working, but the requirement for having the baseline update installed prior to the hotpatch release for that quarter does not change. I hope this helps.