Event details
Have a question about Windows 11, device management, security, updates, or modern endpoint operations? This hour is dedicated entirely to your questions. Bring what's top of mind—from Windows 11 adoption and application compatibility to update management, cloud-native administration, Zero Trust, Intune, Windows 365, and hybrid environments.
Drop your questions in the comments and hear directly from Microsoft experts. Whether you're planning your next rollout, troubleshooting a management challenge, evaluating new capabilities, or looking for best practices, this is your opportunity to get answers and learn from the questions other IT admins are asking right now.
This is part of our continuing series of live Q&A for IT professionals here on Tech Community. Follow the Windows Office Hours to add future dates to your calendar.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.
40 Comments
- nlmitchellIron Contributor
I wonder if anyone can offer any advice/guidance around Intune Unattended Remote, specifically on ARM devices. I posted this in the Intune Feedback Community -
https://feedbackportal.microsoft.com/feedback/idea/c1070699-85a7-f111-85ce-7c1e529382f4
We just need to know if it's supported on ARM (Snapdragon) devices.
We have Intune Remote Help up and running, but we need to have the Unattended option/functionality available to us to support devices in certain scenarios.
- Joe_Lurie
Microsoft
nlmitchell As of today, Unattended Remote Help requires an x64 OS. Keep an eye on this page for any changes to that requisite: Plan for Remote Help with Microsoft Intune - Microsoft Intune | Microsoft Learn.
--Joe.
- nlmitchellIron Contributor
Thanks Joe, so x64 OS is a requirement. Does that include both ARM (SnapDragon) and Intel/AMD architectures? We seem to be having issues with Unattended on ARM x64 devices and wanted confirmation before we spend considerable time troubleshooting
- stdcsbBrass Contributor
We are seeing an increasing number of vulnerability findings in Microsoft applications where the application itself appears current, but a bundled third-party security library remains vulnerable.
As a specific example, Microsoft Defender Vulnerability Management is reporting that Microsoft OneDrive version 26.153.0809.0004 contains OpenSSL 3.4.5. At the time of assessment, OpenSSL 3.4.6 had been available since 9 June 2026 and OpenSSL 3.4.7 since 25 August 2026, meaning OneDrive appears to have missed at least one complete OpenSSL security release cycle and remained on a vulnerable OpenSSL version for more than three months after a fixed upstream release became available.
From an enterprise vulnerability management perspective, this raises several questions:
- What is Microsoft's expected servicing timeframe for critical third-party components embedded within Microsoft applications such as OneDrive?
- When a current Microsoft application is flagged by Microsoft Defender Vulnerability Management due to a vulnerable bundled library, should customers treat that vulnerability as a remediation requirement, or as a risk that must be accepted until Microsoft republishes the application?
- Is there a documented service level objective, target timeframe, or best-practice guidance for how quickly Microsoft applications should incorporate upstream security fixes for bundled libraries such as OpenSSL?
- What is Microsoft's recommended course of action when no newer Microsoft-published version is available but vulnerability scanners continue to report critical or high-severity findings within Microsoft-managed software?
We are looking for guidance on how enterprise security teams should assess, report, and respond to these findings, particularly when the vulnerable component is embedded within a Microsoft application and remediation is wholly dependent on Microsoft's release process.
- shin0933Brass Contributor
Back in 23H2 and prior, systemreset in an administrative cmd would trigger the Windows Reset process when a user was signed in. Now, in 24H2 and beyond, the command is no longer recognized. The only way we can do a reset now is to boot into the recovery mode then navigate to the advanced settings to reset the PC. Would it be possible to bring back systemreset or some other form of command to quickly reset Windows PCs ?
- Joe_Lurie
Microsoft
systemreset.exe isn’t a documented, supported reset interface in current Windows releases, and there isn’t a direct replacement command that launches the same type of experience. The supported local paths to reset a PC are:
Settings > System > Recovery > Reset PC; orWindows Recovery Environment > Troubleshoot > Reset this PC.
For managed devices, Intune Wipe, Fresh Start, or Autopilot Reset may be better options depending on whether enrollment and user data should be preserved.
Check this out for more info: techcommunity.microsoft.com/blog/windows-itpro-blog/windows-device-recovery-in-2026-a-guide-for-it-pros/4541207
--Joe.
- shin0933Brass Contributor
Thank you for your response, Mr. Lurie. What you offered will not help our technicians when they need to reset a device that is in the Out-of-box-experience state. We need to be able to launch a system reset when in command prompt.
- garlinTin Contributor
Heather,
Does the Windows team know the "Repair My PC" feature from the Windows ISO has been broken since May? MS replaced the WinPE version of RecEnv.exe with the Cloud rebuild version from WinRE. Except they forgot to include two required DLL's, wlanapi.dll & mobilenetworking.dll
When you boot the ISO and select Repair My PC, it currently fails. Copying the missing DLL's into boot.wim fixes the problem. This condition impacts all current Windows ISO's from May 2026 and onward, including MCT and all of the Insider ISO's.