Forum Widgets
Latest Discussions
Intune and PSADT v4.x
I have a reboot package PSADT and the first dialog give the user the choice to defer the install, and a Scheduled Task is created to run an hour later. I am returning a 1618 (retry) and inside the PSADT, If Intune runs the app again, it will check my reg key for the defer and check that the task is active and hasn't run, and will exit without any interaction to the user and exit with another 1618. I am not an Intune admin and wondered if there are some downsides to trying this type of package in Intune. The defer time is the unknown for me and I am not sure how many times Intune will try to reinstall the reboot package within the deferred hour, and what Intune will do after the 3rd try...which I think is the max retries it might attempt in an hour? Any suggestions for a change in the exit codes or script interaction with Intune? Thanks.digiman57Aug 13, 2026Copper Contributor25Views0likes1CommentIntune App inventory Graph
Hi All, I've enabled the configuration profile to receive app inventory data in Intune. In the GUI the data I can view the data just fine, but I would like to use Graph to automate this data and create custom reports. When I use the following https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties') I get an error: "Forbidden - 403 - 199 ms Either the signed-in user does not have sufficient privileges, or you need to consent to one of the permissions on the Modify permissions tab" even though the docs I can find about permissions are OK.357Views1like3CommentsCompliance Policies - Device Health Attestation failing (Syncml 404 / 0x87d10194)
Windows 11 devices are non compliant in Intune against BitLocker, Secure Boot and Code Integrity, all three returning the Syncml 404 error. The settings are genuinely enabled. The real cause is the device can't retrieve a Device Health Attestation certificate, so the health cert status sits at 65535 and the retrieval task fails. What I've found: the TPM is healthy (present, ready, attestation capable, firmware not vulnerable), and the endorsement key cert is valid, chaining to Nuvoton TPM Root CA 2111. But the EK chain check comes back invalid with zero intermediate certificates, because the Nuvoton key is signed straight off the root with no intermediate for the chain walk. A Hyper-V VM on the same build and tenant works fine, but only because it has no manufacturer EK cert, so it skips that chain check entirely. What I've tried: patching TPM firmware (ruled out the older ADV190024 issue), refreshing the local trusted TPM certificate store, and rerunning the retrieval task. None fixed it. This matches Rudy Ooms' well known call4cloud writeup, where he concluded it's a service side trust problem that can't be fixed from the device. It's now appearing on brand new Dell hardware too, so I can't just exclude the old kit and move on. Is this a known issue with the Nuvoton root chain, and is there a supported fix or position from Microsoft? Screenshots below showing the compliance errors and the failure.DurranteAug 12, 2026Brass Contributor500Views1like5CommentsAD Minimization: How ready are organizations for the journey?
Microsoft's direction around Active Directory minimization is an interesting and important part of the broader cloud transformation journey. Moving more identity and device management toward Microsoft Entra ID can help organizations gradually reduce their dependency on traditional on-premises Active Directory and move towards a more cloud-first environment. What I particularly like about Microsoft's approach is that this is positioned as a journey rather than something that needs to happen overnight. For many organizations, Active Directory has been part of the environment for 20+ years. Over that time, a lot of dependencies may have been built around it, such as: Legacy applications, Group Policies, Domain-joined Windows devices, LDAP, Kerberos or NTLM dependencies, File servers and other infrastructure, Scripts and operational processes linked to AD. Moving new users, applications and devices towards a cloud-first approach is one part of the journey. The more interesting challenge is how organizations modernize the existing environment while minimizing disruption to users and day-to-day operations. This is where I think Microsoft's phased approach makes a lot of sense. Organizations can gradually identify and reduce AD dependencies while continuing to modernize identity, endpoint management and applications at a pace that works for their environment. I would be interested to hear from others who are already working towards AD minimization. Where is your organization in this journey today? Are you already actively reducing your dependency on on-premises AD? And what has been the biggest area to address so far, legacy applications, Group Policy, existing Windows devices, authentication dependencies, or something else? It would also be interesting to hear which Microsoft technologies or approaches have helped you most during this transition.VincentSKYAug 11, 2026Copper Contributor11Views0likes0CommentsIntune partner compliance onboarding
Hello, We develop a MDM solution and we would like to become device compliance partner to offer our customers conditionnal access functionality. After filling twice (the first time almost two month ago) the form "Intune partner compliance onboarding request" whose link is available on this page https://learn.microsoft.com/en-us/intune/device-security/compliance/third-party-partners, we didn't get any reply to our request. Would you know if there is any other way to integrate this partnership ? Any contact or anything to get some news about our request ? Thank you for your help. Best regards,46Views0likes1CommentEntra Shared Mode - Force App Stop
Hi All I hope you are well. Anyway, I was asked this yesterday and think I already might know the answer, but here goes. We had an instance of Microsoft Excel stuck in "getting things ready" on an Android Entra Shared Mode Device. Technical Support wondered if there was a way to Force Stop Excel or clear the app data. We had a look in Exit Kiosk Mode, Android Settings, and the Force Stop of Excel said "Action not allowed" and the clear the app data said "Unable to delete data for app" So, my question(s) would be, is going into Exit Kiosk Mode and even trying to force stop / clear data on apps even a valid option, or is this by design? Would adding Excel to this setting help? Any help or confirmation would be greatly appreciated. StuartStuartK73Aug 11, 2026Steel Contributor283Views0likes3CommentsBest approach for migrating AD joined devices to Entra ID without wiping user profiles?
We’ve seen many organizations struggle with device migration when moving from traditional Active Directory (AD) or hybrid environments to Microsoft Entra ID. The biggest challenge is avoiding user disruption especially when wiping devices causes profile loss, app reconfiguration, and downtime. In large environments, wipe-and-reload becomes difficult to scale and impacts productivity significantly. Curious to know how others are handling this: Are you still using wipe/reimage methods, or are you using alternative approaches that preserve user profiles, applications, and settings? Would love to hear practical experiences from the community.Pranavsethuraman10Aug 11, 2026Tin Contributor890Views2likes8CommentsINTUNE: Problems with the Google address (Managed Google Play)
Hello everyone, Ever since we added our email address under “Managed Google Play” (in the Intune Admin Center), we can no longer use that address to sign in to Google, Google Docs, Google Drive, or similar services... Is this normal? - If not, what settings do I need to adjust, and where, to get it working again? The error message looks something like this: "Error message: We’re sorry, but you don’t have access to Google Docs. Please log in to your Admin Console to enable it" Thanks and best regards ChrisChristianEdwardsen365Aug 11, 2026Copper Contributor47Views0likes2CommentsPlatform SSO + Secure Enclave: True Passwordless macOS Sign-in with Entra ID?
Hi all, I'm testing macOS DEP/ADE + Intune + Platform SSO with Microsoft Entra ID. I have the Mac successfully enrolling through ADE, becoming Entra joined, and users can authenticate against Entra ID. With Platform SSO configured for Password authentication, users can sign in using their Entra password and everything works as expected. What I'm trying to achieve is a passwordless experience using Secure Enclave, similar to Windows Hello for Business: User enrolls the Mac via ADE Device joins Entra ID Platform SSO is registered Authentication uses Secure Enclave / biometrics (Touch ID) User is no longer prompted for their Entra password during normal sign-in/unlock scenarios Has anyone successfully implemented this with Intune and Platform SSO? Specifically: Is a true Windows Hello-like passwordless experience currently supported on macOS with Entra ID + Platform SSO? If yes, what authentication method and Platform SSO configuration are required? Are there any known limitations where Entra authentication still requires the cloud password even when Secure Enclave is configured? I'm interested in real-world deployments and lessons learned. Thanks!King_RustamusAug 10, 2026Copper Contributor110Views0likes3CommentsWindows 11 + Intune: restrict devices to MDM-managed Wi-Fi profiles only
I was trying to solve a problem for our school exam laptops potentially accessing student phones as hotspots and thought I'd share the results in case it helps someone else. Environment Windows 11 Education 25H2 Microsoft Entra Joined (cloud only) Microsoft Intune Standard users (no local admin) Intune Wi-Fi profiles deployed normally Goal Prevent students from using personal hotspots or home Wi-Fi while still allowing normal Windows logon and access to approved school wireless networks. Most discussions I found concluded that the old "Allow only these SSIDs" WLAN Group Policy isn't available for Entra-only devices. Configuration Custom Intune profile using the Wi-Fi Policy CSP: ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowWiFi = 1 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowManualWiFiConfiguration = 0 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowWiFiDirect = 0 ./Device/Vendor/MSFT/Policy/Config/Wifi/AllowAutoConnectToWiFiSenseHotspots = 0 The important setting appears to be: AllowManualWiFiConfiguration = 0 Microsoft describes this as: No Wi-Fi connection outside of MDM provisioned network is allowed. What I observed Before policy: Student Wi-Fi visible Staff Wi-Fi visible Home Wi-Fi visible Phone hotspot visible Neighbour Wi-Fi visible After policy: ✔ Student Wi-Fi (deployed by Intune) visible ✔ Test hotspot profile (also deployed by Intune) visible ❌ Phone hotspot not deployed by Intune hidden ❌ Home Wi-Fi hidden ❌ Neighbour Wi-Fi hidden The device automatically connected to managed Wi-Fi profiles and failed back correctly when one disappeared. Students only saw Wi-Fi profiles that had been deployed through Intune. I have now rolled it out to one of our laptop carts and it has worked flawwlessly for the last week. Unexpected result I originally thought this setting simply prevented users creating new Wi-Fi profiles. Instead it appears (at least in our environment) to hide every unmanaged SSID and only expose MDM-managed Wi-Fi profiles. That effectively solved the hotspot problem without kiosk mode or AppLocker, meaning I can apply it to all school managed student devices now too. Has anyone else seen the same behaviour? I'd be interested to know if this is consistent across: Windows 11 Pro Enterprise Hybrid Entra Join Different Wi-Fi adapters 24H2 vs 25H2NeilMVAug 09, 2026Occasional Reader68Views0likes1Comment
Tags
- intune4,369 Topics
- mobile device management (mdm)2,326 Topics
- Mobile Application Management (MAM)851 Topics
- Software Management477 Topics
- Conditional Access464 Topics
- Graph API255 Topics
- Azure Friday166 Topics
- Autopilot118 Topics
- android75 Topics
- ios62 Topics