Event banner
Windows Office Hours: September 19, 2024
Event Ended
Thursday, Sep 19, 2024, 08:00 AM PDTEvent details
Get answers to your questions about adopting Windows 11 and managing the Windows devices used by remote, onsite, and hybrid workers across your organization. Get tips on keeping devices up to date effectively! Learn how to cloud attach your on-premises workloads!
Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.
How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.
Post your questions in the Comments early and throughout the one-hour event.
Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below. |
Heather_Poulsen
Updated Nov 19, 2024
- Heather_Poulsen
Community Manager
Thanks to everyone who joined us for Office Hours today. We'll be back next month (October 17) and the third Thursday of every month. Visit https://aka.ms/Windows/OfficeHours to add future dates to your calendar.
- Paul_WoodwardIron ContributorThanks all for taking the time.
- MatthewK280Occasional ReaderAre there any plans to expand the capabilities of the User Templates feature in the admin center? User templates can set a new user's password, license, job title information. What I really need is a section to automatically add Teams and email distributions when a user is assigned the template. I'm currently manually adding up to 20 Teams and distributions for every new user.
- MattLavineAllurionOccasional ReaderHi! I've got a few questions. (1) I'm seeing issues when deploying certain machines where Classic Teams is installed alongside New Teams. I'm not sure if this is being done by the Office Deployment tool or via a Teams Classic installer being included as part of the OEM image. If the issue is because of the OEM image (the PC I've been seeing this behavior on is a Surface Laptop 3), is there a way to remove it from the image so it doesn't reappear when the device is Reset? (2) Are there plans for Policy Sets to support including other policies such as a Disk Encryption policy from the Endpoint Security section of Intune?
- Paul_WoodwardIron ContributorYou can create a remediate script to remove Teams classic. You can use the Teams admin portal to make New Teams the default. I guess you could use Applocker to block it too? Get Rubix has some videos on removal of Teams and Applocker : https://www.youtube.com/watch?v=HzhT-4xwVhQ&t=20s
- MikeGCopper ContributorI have a Config Manager site installed on a physical server that is beginning to report hardware issues so I am working on migrating to a new Config Manager site in a VM. The old site is tenant attached, co-managed, and has a CMG. It has been suggested in various forums to deploy a script that will simply change the site code to the new site. I've done some preliminary testing and this seems to work, though various client logs such as policyagent show warnings concerning policies from the old site which I'd expect. My question is, is this a recommended method? Are there any "gotchas" in doing this? The new site isn't configured for the cloud yet (no tenant attach, co-mgmt, or CMG) and so I don't know if simply changing the site code on an endpoint will cause issues with it communicating with those components or other things that I haven't thought of.
- Jason_Sandys
Microsoft
Additional comment here, after you get over this initially hump, I do strongly encourage you to begin your path to Windows Cloud Native and move away from ConfigMgr and on-prem AD joining devices completely. Check out https://aka.ms/cloudnativeendpoints for a lot more info and details. - Jason_Sandys
Microsoft
Hi Michael, The best path here is to do a "site" backup and restore. This will allow you to restore the site, as is, including all configuration to a new "server" (virtual or physical is irrelevant). This is completely transparent to the clients and thus requires no client-side changes (including site code) whatsoever. Here's a nice post that will help you understand what's involved (as this is essentially a disaster recovery scenario): https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/change-configuration-manager-site-server-os-disaster-recovery/ba-p/3765562 - Jason_Sandys
Microsoft
Hi Michael, The best path here is to do a "site" backup and restore. This will allow you to restore the site, as is, including all configuration to a new "server" (virtual or physical is irrelevant). This is completely transparent to the clients and thus requires no client-side changes (including site code) whatsoever. Here's a nice post that will help you understand what's involved (as this is essentially a disaster recovery scenario): https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/change-configuration-manager-site-server-os-disaster-recovery/ba-p/3765562- MikeGCopper ContributorI looked into this and found it worrisome since the hostname of the primary site server must not change which means completely taking down the old server. So if something goes wrong, there probably won't be an easy way to fall back. I have a question about doing this though. Do the sizes of the volumes of the new server need to match the sizes of the old? The old server has a volume several TB in size and I don't have the capacity to match that in the new VM environment. A number of forums that I read about this process have stated the volumes need to be the same size.
- EricDavisTechBronze Contributor
Is Windows Copilot going to be able to assist users to search, find, and change Windows settings, (e.g. helping a user find the dark mode setting and easily change it), or is that feature going to be completely deprecated with upcoming Windows releases? So far is seems the feature is being neutered as Copilot in Windows appears to becoming a simple web app that can't tie into Windows very deeply at all. I'll be disappointed if this feature is going away.
- Natalie_Palmisano
Microsoft
EricDavisTech thanks for the question!
As the Copilot in Windows experience continues to evolve, I would highly encourage you to take a look at the information we released on Monday in support of our Microsoft 365 Copilot: Wave 2 initiative.
Enhanced data protection with Windows and Microsoft Copilot - Windows IT Pro Blog
Microsoft 365 Copilot: Wave 2 AMA - Microsoft Community Hub
- EMarrero1720Occasional ReaderThis question will be for Intune - I have hybrid devices in Intune for co-management. I have setup Endpoint Analytics, but I am seeing issues where there are no results in the "Top 10 Impacting Processes" for some of the endpoints. Is there any way I can troubleshoot this issue to resolve?
- SoupAtMSFT
Microsoft
Hi Estefon, If you've not already looked here - have a read. https://learn.microsoft.com/en-us/mem/analytics/troubleshoot- EMarrero1720Occasional ReaderHi Steve, thank you for your reply. I should have listed what I did, my apologies. But I did follow the documentation you have mentioned. Everything seems to be looking good in the logs and communication is going back and forth from client to intune and vice versa.
- MikeGCopper ContributorRegarding the Windows enrollment will include quality updates during OOBE change, the bulletin states this will affect devices enrolled in an MDM. Am I correct that this will not affect devices that are imaged with Config Manager?
- Paul_WoodwardIron ContributorReading between the lines, this seems to be a Windows 11 OOBE behaviour change, and it's been observed in the wild on devices both in management and outside. I don't believe it matters if it's in CM or Intune or anything else - although time will tell. As Eric says, if you skip OOBE, then you'll also skip the updates. Hey, did Aria change her name?
- AriaUpdated
Microsoft
If you have set scan source for QU to WSUS then you will not receive Quality updates from WU. More info coming soon. 🙂 - EricMoe
Microsoft
If your task sequence installs the OS end-to-end without having the user go through an Out of Box Experience, then they would not be affected by this new capability.
- matthlock25Copper ContributorSome of our admin role assignment have over 100 scope tags which causes issues when they are automatically added to policies and apps due to the limit. Is there a way to increase this limit? Or any plans to add controls to remove all scope tags in bulk when creating the policy?
- SoupAtMSFT
Microsoft
Hi matthlock25, You are correct, the documented limit is 100 per object. https://learn.microsoft.com/en-us/mem/intune/fundamentals/scope-tags#assign-scope-tags-to-other-objects Please use the Give Feedback to Microsoft to provide your requirements to the team. Find it at the top right corner of the MEM console.- matthlock25Copper ContributorThanks. I already have, about a year ago. This is a real inconvenience for the affected admins, especially when using Intune for Education as they don't have the screen of the wizard to remove scope tags to reduce them below the limit. We're working around it for now.
- Luke_DavidsonCopper ContributorWhat are ways for our technicians to reinstall win32 applications from Company Portal when the app is deployed as required? Occassionally, a technician will want to reinstall an app because it is misbehaving. The current processes we are using is to remove the app from Windows Settings, clear the GRS key and app compliance keys for that app from the registry, restart the IME service, and sync the device. This seems to take hours for the app to actually reinstall. Is there a better way to do it?
- EricMoe
Microsoft
You should be able to target a win32 as required to a group and target it as available to a group. This should put it into Company Portal and install it on the system. Your technician could uninstall the app (locally) and then the user can open Company Portal and install it again. Is this not working for you?- Luke_DavidsonCopper ContributorHi Eric, I gave that a go in the past and it seemed like the required deployment was overriding the available deployment, it didn't show up as available. I'll give it a go again, could be I just didn't give it long enough or goofed something up. Thanks!
- VNJoeIron ContributorAre there plans to improve the times for Intune? 24 hour cycles aren't nearly enough for business standards, and recently, there have been more issues with extended install times. Will you be bolstering the infrastructure to support more efficient endpoint processing?
- Paul_WoodwardIron Contributoroofhours.com has an article about triggering some Intune tasks - IIRC it was 'device sync' - they are actually just tasks in the task scheduler. After the initial hour after boot, the Intune client gets a lot less chatty with the backend service, so some changes to policy etc might take longer to be picked up. You might find out a way to get whatever it is done a bit faster, take a look.
- EricMoe
Microsoft
The policy refresh intervals are defined here, https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot, all of which are shorter than 24 hours. Is there a particular 24-hour cycle that you are experiencing that you want to call out?- VNJoeIron ContributorI'd say that if there were a mechanism that resets the check-in cycling, that'd help. 8 hours generally means one change per operator shift, and they're hard pressed to modify it if it's not a correct policy. It's mostly in regards to troubleshooting where it becomes cumbersome. Additionally, Autopilot installs have become extremely slow and/or drawn out where it's starting to take days to install the same software that usually was deployed within hours. Just some recent observations