mobile device management (mdm)
2326 TopicsPlatform SSO + Secure Enclave: True Passwordless macOS Sign-in with Entra ID?
Hi all, I'm testing macOS DEP/ADE + Intune + Platform SSO with Microsoft Entra ID. I have the Mac successfully enrolling through ADE, becoming Entra joined, and users can authenticate against Entra ID. With Platform SSO configured for Password authentication, users can sign in using their Entra password and everything works as expected. What I'm trying to achieve is a passwordless experience using Secure Enclave, similar to Windows Hello for Business: User enrolls the Mac via ADE Device joins Entra ID Platform SSO is registered Authentication uses Secure Enclave / biometrics (Touch ID) User is no longer prompted for their Entra password during normal sign-in/unlock scenarios Has anyone successfully implemented this with Intune and Platform SSO? Specifically: Is a true Windows Hello-like passwordless experience currently supported on macOS with Entra ID + Platform SSO? If yes, what authentication method and Platform SSO configuration are required? Are there any known limitations where Entra authentication still requires the cloud password even when Secure Enclave is configured? I'm interested in real-world deployments and lessons learned. Thanks!4Views0likes0CommentsWindows 11 + Intune: restrict devices to MDM-managed Wi-Fi profiles only
I was trying to solve a problem for our school exam laptops potentially accessing student phones as hotspots and thought I'd share the results in case it helps someone else. Environment Windows 11 Education 25H2 Microsoft Entra Joined (cloud only) Microsoft Intune Standard users (no local admin) Intune Wi-Fi profiles deployed normally Goal Prevent students from using personal hotspots or home Wi-Fi while still allowing normal Windows logon and access to approved school wireless networks. Most discussions I found concluded that the old "Allow only these SSIDs" WLAN Group Policy isn't available for Entra-only devices. Configuration Custom Intune profile using the Wi-Fi Policy CSP: ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowWiFi = 1 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowManualWiFiConfiguration = 0 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowWiFiDirect = 0 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowAutoConnectToWiFiSenseHotspots = 0 The important setting appears to be: AllowManualWiFiConfiguration = 0 Microsoft describes this as: No Wi-Fi connection outside of MDM provisioned network is allowed. What I observed Before policy: Student Wi-Fi visible Staff Wi-Fi visible Home Wi-Fi visible Phone hotspot visible Neighbour Wi-Fi visible After policy: ✔ Student Wi-Fi (deployed by Intune) visible ✔ Test hotspot profile (also deployed by Intune) visible ❌ Phone hotspot not deployed by Intune hidden ❌ Home Wi-Fi hidden ❌ Neighbour Wi-Fi hidden The device automatically connected to managed Wi-Fi profiles and failed back correctly when one disappeared. Students only saw Wi-Fi profiles that had been deployed through Intune. I have now rolled it out to one of our laptop carts and it has worked flawwlessly for the last week. Unexpected result I originally thought this setting simply prevented users creating new Wi-Fi profiles. Instead it appears (at least in our environment) to hide every unmanaged SSID and only expose MDM-managed Wi-Fi profiles. That effectively solved the hotspot problem without kiosk mode or AppLocker, meaning I can apply it to all school managed student devices now too. Has anyone else seen the same behaviour? I'd be interested to know if this is consistent across: Windows 11 Pro Enterprise Hybrid Entra Join Different Wi-Fi adapters 24H2 vs 25H222Views0likes0CommentsIntune partner compliance onboarding
Hello, We develop a MDM solution and we would like to become device compliance partner to offer our customers conditionnal access functionality. After filling twice (the first time almost two month ago) the form "Intune partner compliance onboarding request" whose link is available on this page https://learn.microsoft.com/en-us/intune/device-security/compliance/third-party-partners, we didn't get any reply to our request. Would you know if there is any other way to integrate this partnership ? Any contact or anything to get some news about our request ? Thank you for your help. Best regards,13Views0likes0CommentsDisallow O365 access from 'outside' of the Android for Work work profile?
Is there a way to block Android for Work users to connect to Office 365 with apps that are installed outside of the work profile? For example on my Android for Work capable device I have a work profile with eg. Outlook, which I can use to read my mail. However, i'm also able to use the Outlook app in my personal space to connect to Office 365, I was kinda expecting to only be able to connect to Office 365 from my work profile (?)13KViews0likes24CommentsAdvanced Microsoft Intune capabilities - Coming to Education A5?
The Advanced Microsoft Intune capabilities (what was the Intune Suite has now arrived for E5 customers (and some of the features to E3 customers. Can anyone give any clarity as to if/when these features will be coming to A5 customers? I can see we seem to have some of the features (Remote Help, Endpoint Privilege Management) but could really do with knowing if the rest of the features are coming. Can't seem to find any information online about it.53Views0likes2CommentsAndroid Multi-App Kiosk. (Required apps not installing)
Hi I have an issue on my devices, I set Microsoft Teams as a required app for all devices (filter for corporate android devices) But It get's stuck, Saying installing for hours, nothing happens, this is for all apps I set as required except applications as Managed Home Screen , Authenticator, etc. But extra apps all have this issue. If I manually press Cancel in Google Play store and the press install again, it installs instantly. But without me manually doing that the apps are stick at Installing. Device install status in Intune. The application failed to install, possibly because of insufficient storage or an unreliable network connection. The installation will be retried automatically. (0xC7D24FBA). In Google Play you just see the app saying Installing. Now this is for all apps I add. Running Android 11 Samsung tablet, managed dedicated multi app kiosk.2.9KViews0likes2CommentsAD Naming Conventions vs Intune/AutoPilot Conventions
In Active Directory we use a 20 or so character naming convention of all of our PC's, basically it is the location, cart, and serial number, and this works well for us as we are a school district, and it allows us to locate the pc's quickly. However, we are moving to Intune and eventually AutoPilot. Currently AutoPilot has a 15-character limitation. And to the best of my knowledge that cannot be changed or extended, correct? But here is my question, as we want to move to Autopilot for deploying our new machines, can a Group Tag or other automated device be used to allow me to use a longer name, or at least a way of filtering and finding a name more efficiently in Intune? And also, from a reporting standpoint to create reports of School 3's computer inventory vs schools 2's inventory? As I don't believe this is possible, we will continue to build pc's using Kace or SCCM and then import them into Intune and manage them as a hybrid machine, rather than as a Joined machine. Our ultimate goal is to have them all be Joined, and eliminate AD, but we have not figured out a way of doing this yet. Would switching from standard Intune to Intune for Education benefit us in any way for this situation?2.9KViews0likes2CommentsiOS Enrollment and Conditional Access
Hello everyone, I need some help! We are configuring Intune to allow BYOD on iOS devices using the Account Driven User Enrollment method. In this scenario, the user enrolls the device by following the path: Settings > General > VPN & Device Management > Sign in to your Work or School Account The enrollment process was working correctly until we configured a Conditional Access policy to ensure that only BYOD-managed devices can access company resources. In other words, only devices that have successfully completed enrollment and are marked as Compliant in Intune should be allowed to use corporate applications. However, after applying the policy, we are no longer able to complete the enrollment process. During one of the enrollment steps, the device displays the following message: Translate English "Setting Up iPhone iPhone setup may take a few minutes. Sign-In Failed Enrollment failed. Please try again. OK" 1. Target resources (Include) 2. Target resources (Exclude) 3. Device Platform: iOS 4. Filter for devices: device.mdmAppId -notIn ["0000000a-0000-0000-c000-000000000000"] 5. Grant: Require device to be marked as compliant This is our current Conditional Access policy configuration. Has anyone encountered this behavior before, or can identify whether there is any setting that might be blocking the enrollment process during the compliance validation stage?36Views0likes1CommentWindows App Application Protection Policy
I have been testing out an Intune MAM policy to restrict copy/paste and drive redirection to AVD session hosts based on the link here: https://learn.microsoft.com/en-us/windows-app/require-device-security-compliance-intune?tabs=web#related-contentHowever, I've run into problems (in two separate tenants) that have halted me from being able to test. Setup Intune App Protection Policy targeting Windows Devices & Microsoft Edge\ Conditional Access Policy enforcing App Protection Policy when users access 'Azure Virtual Desktop' target resource via https://windows.cloud.microsoft.com Results First When signing into a user account targeted by the policy, they are prompted to Switch Edge Profile which signs in the user to a new Edge profile for 'Work or School Account'. The account has to sign in again. The account can access Windows App resources When launching a desktop session, this authentication page pops up for an account "local@debugonly" Second When signing into a user account targeted by the policy, they are prompted to Switch Edge Profile which signs in the user to a new Edge profile for 'Work or School Account'. The account has to sign in again. After sign in, the account loops with 'Switch Edge Profile' and gets stuck here I'm curious if anyone has gotten this to work and what was your setup? Or if Microsoft or provide some assistance or if this is in the wrong forum, any help would be appreciated.234Views0likes2CommentsHave OneDrive or SharePoint files/folders on home screen of iPad without internet connection?
This. I'm on a big iOS project. We have several users who need files on an ipad when traveling, and be able to open them when there is no internet connectivity. These files aren't intended to be edited, just 'read only.' These files do not contain any sensitive corporate data. The content lives in SharePoint online and I'm using OneDrive as a bridge to their sharepoint site. BUT the files can only be viewed on the ipad within the OneDrive app without internet access. These are devices using user affinity enrollment. Initially, the solution for users was to use the 'Mark Offline' feature within the OneDrive iOS app. I used Power Automate to have it fetch new files found in OneDrive and move them to the teams SharePoint site. These shared devices are locked down (an understatement). These will be used by the least computer savy/literate people and so having them dive through OneDrive folder after folder, even offline, is a tall order to ask. I totally get it and don't want them doing that either. So now I have to move onto plan B. How can we put the files that live within OneDrive/Sharepoint onto the home screen without an internet connection when the ipad is 'out in the field.?' This would make it infinitely easier for them. The key here is to not have end users manually moving files around. We don't want them to even have to go into OneDrive and mark folders/files offline, if possible. We don't have the SharePoint app on them. I tried the SP app a while back, and it is a hot mess of garbage. I could revisit it. Whatever I can get to work of course we'll have to modify our Intune polices. Thoughts?149Views0likes1Comment