Event details
Have a question about Windows 11, device management, security, updates, or modern endpoint operations? This hour is dedicated entirely to your questions. Bring what's top of mind—from Windows 11 adoption and application compatibility to update management, cloud-native administration, Zero Trust, Intune, Windows 365, and hybrid environments.
Drop your questions in the comments and hear directly from Microsoft experts. Whether you're planning your next rollout, troubleshooting a management challenge, evaluating new capabilities, or looking for best practices, this is your opportunity to get answers and learn from the questions other IT admins are asking right now.
This is part of our continuing series of live Q&A for IT professionals here on Tech Community. Follow the Windows Office Hours to add future dates to your calendar.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
40 Comments
- Heather_Poulsen
Community Manager
Thanks for joining today's Office Hours session. We'll work on finishing up with your questions below. In the meantime, save the date for our next session on October 15:
https://techcommunity.microsoft.com/event/windowsevents/windows-office-hours-october-15-2026/4529260
- Dom_CoteIron Contributor
Did Modern Standby change its behavior sometime in the past?
It seems devices in standby won't reliably download and install updates anymore.
Also, almost all apps get quiesced during standby, which means we miss Teams notifications etc. when devices are in standby (but open)
Lastly, they drop their network connections, which makes them effectively unreachable for MDM. For example, when a device is lost and you need to wipe it remotely.
In the (more or less distant) past, devices would wipe even under (modern) standby. These days, it can take hours before anything happens.- Joe_Lurie
Microsoft
Dom_Cote If I recall, yes, there have been power-management changes, including additional Modern Standby power-saving behavior in Windows 11, version 24H2.
Windows can pause desktop apps and network activity during standby; Windows Update can wake the system but download and installation behavior night depend on the power state. A remote Intune action may remain pending until the device resumes and checks in. Finally, make sure the OEM firmware and network drivers are current.
--Joe.
- Dom_CoteIron Contributor
Do you have an ETA on the Windows Defender notification issue which causes Intune to consider Windows PCs as non-compliant, due to missing Antivirus?
We got a fix from support, but deploying that to dozens of tenants is hard work.
Be nice if WUfB shipped the fix automatically.- Heather_Poulsen
Community Manager
Hi Dom_Cote - This issue has been confirmed and documented on the Windows release health hub so please keep an eye on that site for updates on mitigations and fixes.
- Dom_CoteIron Contributor
This is not just a local issue. Intune device compliance also considers these devices as having no antivirus, which makes them non-compliant. Entra conditional access blocks them subsequently.
While it doesn't impact all devices, it does block enough people from getting work done.
No ETA at all? 😉
- Rajith88Copper Contributor
Is there a roadmap to enhance the reporting capabilities for Windows Autopatch Driver Updates? The current reporting experience is quite limited, making it challenging to effectively track, manage, and troubleshoot driver deployment status across devices.
- AriaUpdated
Microsoft
While we don't have a public roadmap, that is certainly something we are looking at creating and we are certainly working on improving these reports. Can you share more about what specifically you'd like to see in the driver reports to help make it easier for you to manage such? And what features you'd like to see prioritized?
- Rajith88Copper Contributor
Thanks for the response. I would like to see
1. A filter option based on driver status while we try to do bulk approval, currently it is showing only "Name"
2. Driver Failed report is showing number of failed, it would be good to show number of success as well. for ex: few machines the same driver may get installed successfully
3. Autopatch ring wise report including success and failure
- HeyHey16KSteel Contributor
We are now managing Apple computers via Intune. Unfortunately, we've already hit on two showstopper technical issues (one with the local admin account permanently locking out and now the PSSO v Golden Gate issue).
Why do Microsoft and Apple not have a joint team that work together? We logged a support ticket to Microsoft, who said it was Apple, so logged a support ticket to Apple, who said it was Microsoft.
Doesn't seem fair (not to mention very costly in terms of time and effort) that us customers have to play piggy in the middle going back and forth between you both, and having to play referee... 🙃- Joe_Lurie
Microsoft
HeyHey16K Ugh. I’m sorry you’ve been caught between support organizations, obviously that isn’t the experience we want. Ownership can be difficult to isolate when macOS, Platform SSO, FileVault, and MDM behavior intersect. We are sharing your question with the PM owner of Apple in the Intune prodict group. If you can share both case numbers with him privately, he can ask Support to coordinate the escalation and ensure both teams have the combined diagnostic information. Good luck.
--Joe.
- HeyHey16KSteel Contributor
Hi Joe, thank you for your response. Who do I need to share the ticket number with please?
- Heather_Poulsen
Community Manager
Welcome to September's edition of Windows Office Hours! Our engineering and product team members are here to help. Keep your questions coming in the comments. Thanks for being here!
- HeyHey16KSteel Contributor
Is Intune slow and full of regular errors (examples below) for anyone else last couple of weeks?
- Joe_Lurie
Microsoft
HeyHey16K Sorry you're having these issues. I'm not aware of any known issues with the admin center. Have you checked with your CSAM or with support?
- HeyHey16KSteel Contributor
Thank you for your response Joe. We avoid logging tickets with MS support unless it's critical as they take on average 6+ months to investigate our tickets and even then it's only 50/50 if the problem gets resolved. Our company doesn't have time/capacity/etc. to endure that for every issue we see in our environment.
- SergioTin Contributor
We have recently begun deploying machines using Autopilot, and these machines are 100% cloud-based; the devices are only registered in Entra.
As they are purely cloud-based, they are not registered on our internal DNS, and this is causing us certain problems as their names cannot be resolved.
We haven’t found a document explaining the best way to get Entra devices to register with DNS so that their names can be resolved.
Could you please help us sort this out ?
- Jason_Sandys
Microsoft
Hi Sergio, DaveD-MS-CETS covered the answer here pretty well but I'm curious which tasks specifically that require client name resolution are causing you challenges?
- SergioTin Contributor
Hi Jason_Sandys , DaveD-MS-CETS ,
Examples of the problems that have been reported to us are by our on-site teams:
- We can't ping those machines.
- It is not possible to connect to those machines via Remote Desktop.
- As the firewalls cannot resolve the names of those machines, they block access to OT environment.
- DaveD-MS-CETS
Microsoft
Hi Sergio, being cloud based, these devices won't be associated with internal DNS servers. If it's management tasks, such as sync, reset, remote control - Intune can provide those for Entra devices without needing internal DNS registration Device Actions - Wipe, Lock, Locate, and More - Microsoft Intune | Microsoft Learn Networks under your control, such as on-premises, could use DHCP server settings to set a specific DNS server. For public networks, DNS is typically via the network provider.
- lalanc01Iron Contributor
When will out of band updates support in Autopatch outside of expedite?
Would be nice not to have to pause updates and install fixes with Intune apps which degrades the user patching experience.
Perfect example is the RDS know issue with the september update.
thks- AriaUpdated
Microsoft
Great question! While I cannot publicly share exact dates at this time, I can tell you that you will likely not have to wait much longer for this capability. We fully understand the criticality of this control and are working to get it to you ASAP.
p.s. if you would like to test out these new features earlier or get the longest roadmap view, please consider joining our NDA community of IT Admins so that you can become part of our private previews! :) Innovate with the Microsoft Management Advisors Community
- lalanc01Iron Contributor
Thks for the info. Already part of this great community. Always willing to participate in WU private previews
- lalanc01Iron Contributor
Why is there no support for Bitlocker Pin in Intune, when it's recommended to have one to prevent most hacks regarding Bitlocker?
Most resort to creating custom scripts to enable it and it would be great to have it in Intune and/or to understand to reasons why it's not there (maybe a technical limitation)
thks- DaveD-MS-CETS
Microsoft
Hi, as far as I can see, Intune does support TPM startup PIN policies. In Settings Picker -> Bitlocker Drive Encryption -> Operating System Drives you can require a TPM startup PIN and configure the minimum PIN length as needed. TPM+PIN requires user interaction, so it isn’t compatible with silent BitLocker enablement during Windows Autopilot; these settings also primarily apply when BitLocker is first enabled.
When requiring a startup PIN, the experience becomes:-
Power on -> Bitlocker pre-boot screen -> enter Bitlocker PIN -> Windows boots -> Windows sign in.
- Jason_Sandys
Microsoft
Hi lalanc01. There is no official recommendation on whether orgs should use or not use a preboot authenticator (PBA) -- aka PIN -- for BitLocker. This is a complicated and touchy subject as there are pros and cons both ways and the choice should be based on your org's security posture and should not necessarily be a blanket choice for all devices either. There's also a lot of FUD out there on what and how BitLocker can be compromised and the ease of doing so which is another reason that your org should assess the risks (based on factual information) and make an informed choice based on this.
Moving on to your question, similar to many people's social media status, the short answer is "it's complicated". The basic challenge is that there isn't an adequate control in Windows itself to accommodate setting a PIN by a non-admin user when no PIN currently exists. There are workarounds for this including using a script/tool that is run elevated (this is what MBAM did) and there are solutions available in/from the community that do just this.
The good news is that there has been a possible strategy update around this. Nothing to share at this time other than we know this is a challenge and this is currently being revisited with the outcome hopefully being a direct control to allow for this. No guarantees or commitments though.