<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ct-p/microsoftintune</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Mon, 03 Aug 2026 13:11:24 GMT</pubDate>
    <dc:creator>microsoftintune</dc:creator>
    <dc:date>2026-08-03T13:11:24Z</dc:date>
    <item>
      <title>Advanced Microsoft Intune capabilities - Coming to Education A5?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/advanced-microsoft-intune-capabilities-coming-to-education-a5/m-p/4542707#M23649</link>
      <description>&lt;P&gt;The Advanced Microsoft Intune capabilities (what was the Intune Suite has now arrived for E5 customers (and some of the features to E3 customers. Can anyone give any clarity as to if/when these features will be coming to A5 customers?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see we seem to have some of the features (Remote Help, Endpoint Privilege Management) but could really do with knowing if the rest of the features are coming. Can't seem to find any information online about it.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 08:06:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/advanced-microsoft-intune-capabilities-coming-to-education-a5/m-p/4542707#M23649</guid>
      <dc:creator>MarkBerry</dc:creator>
      <dc:date>2026-07-31T08:06:51Z</dc:date>
    </item>
    <item>
      <title>problem with Auto-Enrollment for windows devices in Hybrid enviroument</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/problem-with-auto-enrollment-for-windows-devices-in-hybrid/m-p/4542003#M23639</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I am in the process of setting up Intune for automatic enrollment on Windows devices within our hybrid environment. Here are the steps I have taken so far:&lt;/P&gt;&lt;P&gt;1. Configured Entra ID sync to synchronize a selected OU with Entra ID.&lt;/P&gt;&lt;P&gt;2. In the Intune Portal, set the Automatic enrollment MDM user scope to "All."&lt;/P&gt;&lt;P&gt;3. Created a GPO linked to that OU, which includes the settings to "register domain-joined computers as devices" and "Enabled automatic MDM enrollment using default Azure credentials" based on User Credential.&lt;/P&gt;&lt;P&gt;4. Prepared a clean computer, free of any software, and joined it to the Domain (on-prem server).&lt;/P&gt;&lt;P&gt;5. Moved the computer to the appropriate OU for syncing with Entra ID.&lt;/P&gt;&lt;P&gt;6. At this point, I can see the computer listed in the Entra ID portal under devices as Entra Hybrid joined&lt;/P&gt;&lt;P&gt;7. A regular domain user with a Business Premium license logged into the computer.( Only sign-in to windows, we don't have office app or add this account to windows.)&lt;/P&gt;&lt;P&gt;8. I ran GPupdate /force and rebooted the computer several times, but it still does not appear in the Intune portal.&lt;/P&gt;&lt;P&gt;9.Windows client is windows 11 Pro version 25H2 OS build 26200.8893&lt;/P&gt;&lt;P&gt;Dsregcmd output shows:&lt;/P&gt;&lt;P&gt;✅ Device is domain joined&lt;BR /&gt;✅ Device is synced to Entra ID&lt;BR /&gt;✅ Device authentication is working&lt;BR /&gt;✅ User has a valid PRT (Primary Refresh Token)&lt;BR /&gt;✅ Hybrid Join is successful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On second test computer2, I installed office desktop app, then sign-in with test user to activate it. After few minutes the computer appeared on Intune portal. but on test computer 1 without user's interaction, it doesn't show up.&lt;/P&gt;&lt;P&gt;would you be able to help me with this?&amp;nbsp; Does it really need user to attach his/her account manually to "work or school account" or sing-in to any office desktop apps?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 12:06:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/problem-with-auto-enrollment-for-windows-devices-in-hybrid/m-p/4542003#M23639</guid>
      <dc:creator>Amir Gh</dc:creator>
      <dc:date>2026-07-29T12:06:51Z</dc:date>
    </item>
    <item>
      <title>Registry Inventory in Microsoft Intune: Verifying What’s on Your Devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/registry-inventory-in-microsoft-intune-verifying-what-s-on-your/ba-p/4541312</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Madison Cooks, Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IT admins need a reliable way to confirm how Windows devices are configured, especially when troubleshooting, validating compliance, or investigating security posture. Policy assignment alone doesn’t always show what’s present on the device and getting registry visibility at scale has often required custom discovery or remediation scripts that take time to build, test, and maintain.&lt;/P&gt;
&lt;P&gt;With Microsoft Intune’s July (2607) release, device inventory will include Windows registry data, helping IT admins verify a device’s actual configuration, not just the policy assigned. With a new Device inventory property for registry keys, you define the keys you care about in the properties catalog, and Intune collects them for you. There’s no collection logic to build or keep running.&lt;/P&gt;
&lt;P&gt;This makes registry-based configuration checks easier to operationalize across managed Windows devices, so teams can spend less time maintaining scripts and more time acting on the data.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Microsoft Intune device inventory profile creation screen showing the Properties picker with the Registry category selected for inventory data collection.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;What registry data you collect&lt;/H2&gt;
&lt;P&gt;Registry data collection is configured through the existing properties catalog. For each entry, provide a registry key path and, when needed, a value name. For every targeted device, the device agent attempts collection and reports:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Registry key path&lt;/LI&gt;
&lt;LI&gt;Value name&lt;/LI&gt;
&lt;LI&gt;Value type&lt;/LI&gt;
&lt;LI&gt;Value data&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;&lt;EM&gt;Figure 2: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune device inventory profile configuration page showing registry key collection settings, including registry path, collection pattern options, and value name fields.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;The initial release supports the following collection patterns designed for common admin scenarios that use HKEY_LOCAL_MACHINE (HKLM) paths.&lt;/P&gt;
&lt;H3&gt;Single value&lt;/H3&gt;
&lt;P&gt;Specify a registry path and value name to collect one value from that path. For example, collect Secure Boot certificate servicing status from HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot by using values such as UEFICA2023Status, UEFICA2023Error, or UEFICA2023ErrorEvent.&lt;/P&gt;
&lt;H3&gt;All values under a path, non-recursive&lt;/H3&gt;
&lt;P&gt;Specify a registry path to collect all values directly under that path. This pattern doesn't include subkeys. For example, collect values directly under a Windows Update configuration path to help validate expected settings.&lt;/P&gt;
&lt;H3&gt;Same value across subkeys&lt;/H3&gt;
&lt;P&gt;Specify a base registry key path and a value name to collect that value from each immediate subkey. For example, collect DHCP status across network interface subkeys under HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.&lt;/P&gt;
&lt;H2&gt;Where registry inventory data appears&lt;/H2&gt;
&lt;P&gt;After collection, registry inventory data will be available in &lt;STRONG&gt;Device inventory&lt;/STRONG&gt; at initial release. We’ll expand access to registry data in the coming months, including support in additional reporting and exploration experiences.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 3: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune Device Inventory page displaying collected Windows registry data for a device, including registry key paths, values, collection status, and timestamps.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This makes registry data available alongside other inventory signals, so admins can use familiar tools to investigate configuration, validate device state, and support troubleshooting without building separate collection scripts.&lt;/P&gt;
&lt;H2&gt;How admins use this&lt;/H2&gt;
&lt;P&gt;You can collect registry data and view it per device in Device inventory - a verified record of each endpoint’s actual configuration and a key source of settings data on each endpoint. This helps answer questions like: Is a setting actually enabled on the device? Which app, version, or configuration is installed? Did a policy apply correctly? Why is this device behaving differently from the rest?&lt;/P&gt;
&lt;P&gt;Registry data collection in Device inventory is included with Microsoft Intune Plan 1.&lt;/P&gt;
&lt;H2&gt;Collection results and limits&lt;/H2&gt;
&lt;P&gt;If a registry value exists but doesn’t contain data, collection succeeds and the value appears as empty. If the registry path or value name doesn’t exist on a device, that device reports &lt;STRONG&gt;Not found&lt;/STRONG&gt; for the collection result. Collection continues for all other devices, so one missing value won’t block results from devices where the value exists.&lt;/P&gt;
&lt;P&gt;Registry inventory includes safeguards to keep collection focused and manageable. Each collected registry value is capped at &lt;STRONG&gt;6 KB&lt;/STRONG&gt;, and each device can collect up to &lt;STRONG&gt;100 registry keys&lt;/STRONG&gt;. If a value or device exceeds these limits, collection skips the excess data and reports the applicable result for that device. These limits help manage data volume, maintain service performance, and reduce the risk of over-collection.&lt;/P&gt;
&lt;P&gt;Registry inventory is designed for configuration visibility and troubleshooting, not for collecting sensitive or confidential data. Built-in heuristic detection helps identify and prevent ingestion of values that may contain secrets, credentials, authentication tokens, certificates, private keys, connection strings, or other data that could grant access if exposed. If a value is flagged as potentially sensitive, it&lt;STRONG&gt; isn’t &lt;/STRONG&gt;collected.&lt;/P&gt;
&lt;P&gt;Collection is limited to HKEY_LOCAL_MACHINE (HKLM) paths. This keeps inventory focused on device-level configuration and avoids user-specific registry contexts.&lt;/P&gt;
&lt;H1&gt;Summary&lt;/H1&gt;
&lt;P&gt;Registry inventory in Microsoft Intune helps admins collect Windows registry data in a native, declarative way. Instead of maintaining custom scripts for common inventory scenarios, admins can configure registry collection in the properties catalog and query the results through familiar Intune reporting experiences.&lt;/P&gt;
&lt;P&gt;Use registry inventory for configuration visibility and troubleshooting across managed Windows devices. As you plan your collection strategy, focus on device-level HKLM data, avoid sensitive values, and remember collection limits to keep inventory targeted and manageable.&lt;/P&gt;
&lt;P&gt;If you have any feedback or questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 20:59:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/registry-inventory-in-microsoft-intune-verifying-what-s-on-your/ba-p/4541312</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-28T20:59:27Z</dc:date>
    </item>
    <item>
      <title>Compliance Policies - Device Health Attestation failing (Syncml 404 / 0x87d10194)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/compliance-policies-device-health-attestation-failing-syncml-404/m-p/4541626#M23633</link>
      <description>&lt;P&gt;Windows 11 devices are non compliant in Intune against BitLocker, Secure Boot and Code Integrity, all three returning the Syncml 404 error. The settings are genuinely enabled. The real cause is the device can't retrieve a Device Health Attestation certificate, so the health cert status sits at 65535 and the retrieval task fails.&lt;/P&gt;&lt;P&gt;What I've found: the TPM is healthy (present, ready, attestation capable, firmware not vulnerable), and the endorsement key cert is valid, chaining to Nuvoton TPM Root CA 2111. But the EK chain check comes back invalid with zero intermediate certificates, because the Nuvoton key is signed straight off the root with no intermediate for the chain walk. A Hyper-V VM on the same build and tenant works fine, but only because it has no manufacturer EK cert, so it skips that chain check entirely.&lt;/P&gt;&lt;P&gt;What I've tried: patching TPM firmware (ruled out the older ADV190024 issue), refreshing the local trusted TPM certificate store, and rerunning the retrieval task. None fixed it. This matches Rudy Ooms' well known call4cloud writeup, where he concluded it's a service side trust problem that can't be fixed from the device.&lt;/P&gt;&lt;P&gt;It's now appearing on brand new Dell hardware too, so I can't just exclude the old kit and move on.&lt;/P&gt;&lt;P&gt;Is this a known issue with the Nuvoton root chain, and is there a supported fix or position from Microsoft? Screenshots below showing the compliance errors and the failure.&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 16:31:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/compliance-policies-device-health-attestation-failing-syncml-404/m-p/4541626#M23633</guid>
      <dc:creator>Durrante</dc:creator>
      <dc:date>2026-07-28T16:31:49Z</dc:date>
    </item>
    <item>
      <title>What’s new in Microsoft Intune – July</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-july/ba-p/4537392</link>
      <description>&lt;P&gt;Ask an IT admin what a good day looks like, and it usually comes down to one word: control. Control means you push a change and know it landed. It means you have a clear view into your device fleet, from compliance status to sync health. That certainty is what helps IT stay ahead and deliver.&lt;/P&gt;
&lt;P&gt;Still, endpoint management gets harder as fleets grow across locations and device types. More devices and policies rarely mean fewer admin hours. This month's updates focus on giving IT clearer visibility and more confident action.&lt;/P&gt;
&lt;H4&gt;Demystify Windows device sync status&lt;/H4&gt;
&lt;P&gt;&lt;SPAN data-teams="true"&gt;When admins troubleshoot a device, they need visibility into what’s happening. The updated per-device sync experience in the Intune admin center now shows progress, making it easier for admins to confirm actions are running and understand where they are in the process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The updated sync action also triggers both the mobile device management check-in and the Intune Management Extension (Windows only) check-in. One sync can now pull-down policy, app, and script changes in a single pass. For admins working through a single-device issue, this makes sync more transparent, more complete, and easier to trust as a troubleshooting step. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/actions/sync?pivots=windows" target="_blank" rel="noopener"&gt;Learn more about sync actions for Windows&lt;/A&gt; and how to use them to troubleshoot and validate device state.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;SPAN data-contrast="auto"&gt;Figure 1: The Sync status pane tracks each step live, from notifying the device to calculating compliance.&lt;/SPAN&gt;&lt;/img&gt;
&lt;P&gt;Want a deeper story about how we delivered this change? Read the&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize-time-sensitive-a/4515942" target="_blank" rel="noopener" data-lia-auto-title="blog" data-lia-auto-title-active="0"&gt;blog&lt;/A&gt; about how Intune helps IT prioritize time-sensitive actions or catch the recent &lt;A class="lia-external-url" href="https://www.youtube.com/live/dUN6cAI6nhA?is=3kHcspq7ZUYMxU6v" target="_blank" rel="noopener"&gt;Microsoft Technical Takeoff video&lt;/A&gt; on Intune timing demystified.&lt;/P&gt;
&lt;H4&gt;Help ensure compliance for macOS&lt;/H4&gt;
&lt;P&gt;This month, custom compliance settings for macOS became generally available. Admins can use these settings to apply organization-specific requirements that built-in compliance settings don’t cover. This extended coverage helps reduce risk and unblock macOS deployments by aligning compliance and Conditional Access requirements with the Intune security policies organizations need to manage them. To learn more about compliance policies and what they do, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/overview" target="_blank" rel="noopener"&gt;"Use compliance policies to set rules for devices you manage with Intune."&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Additionally, using discovery scripts and JSON rules, admins can inspect many macOS device attributes and conditions. Think about installed software, running processes, app versions, or security posture that no Apple built-in setting captures. Now macOS devices report compliance the same way Windows and Linux devices do, giving you one consistent view instead of three different ones. Read more about how to set up the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/custom-settings" target="_blank" rel="noopener"&gt;custom compliance settings documentation for Microsoft Intune&lt;/A&gt;.&lt;/P&gt;
&lt;H4&gt;More control over Samsung firmware updates&lt;/H4&gt;
&lt;P&gt;Keeping firmware current becomes harder as your mobile device fleet grows. For example, a new version may need testing against line-of-business apps before reaching production devices. In a Zero Trust environment, every unpatched device can become a compliance gap waiting to happen.&lt;/P&gt;
&lt;P&gt;The &lt;A class="lia-external-url" href="https://www.samsungknox.com/en/solutions/it-solutions/samsung_e-fota" target="_blank" rel="noopener"&gt;Samsung Knox Enterprise Firmware-Over-The-Air (E-FOTA)&lt;/A&gt; integration brings precise control over firmware and OS updates across their Galaxy devices into the Microsoft Intune console. Existing Intune device groups determine which devices receive each version. If group membership changes, the firmware assignment follows.&lt;/P&gt;
&lt;P&gt;Admins can keep production devices on their current version while testing an update. After validation, they can roll it out gradually during planned maintenance windows. Battery requirements and postponement limits provide more control over installation timing. This helps maintain consistent firmware and compliance across the fleet.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;H4&gt;Intune: Myth vs. reality&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Myth: &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/overview" target="_blank" rel="noopener"&gt;Windows Autopilot&lt;/A&gt; requires device registration for new PCs.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Reality: &lt;/STRONG&gt;Device registration is not required in all Windows Autopilot scenarios. Many IT admins associate Windows Autopilot with device registration because the original Windows Autopilot solution uses registration to identify devices. Today, organizations can choose from multiple Autopilot approaches depending on their deployment needs.&lt;/P&gt;
&lt;P&gt;Windows Autopilot helps IT remotely provision devices at scale across a range of deployment scenarios, including existing devices, pre-provisioning, self-deploying deployments, and remote users.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/overview" target="_blank" rel="noopener"&gt;Windows Autopilot device preparation&lt;/A&gt; helps streamline Windows 11 provisioning without requiring Windows Autopilot registration. It uses enrollment-time grouping to deliver selected apps and scripts during setup, with near real-time deployment reporting.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How to choose the right Autopilot approach:&lt;/STRONG&gt; If you need registration-based deployment scenarios, such as pre-provisioning, self-deploying deployments, or existing device provisioning, use the original Windows Autopilot solution. Use Windows Autopilot device preparation when you want to streamline Windows 11 onboarding without Windows Autopilot registration and deliver selected apps and scripts during setup before users reach the desktop.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows Autopilot in action:&lt;/STRONG&gt; &lt;A class="lia-external-url" href="https://aka.ms/Onboarding-AutopilotVideo" target="_blank" rel="noopener"&gt;Watch Microsoft MVP Jonathan Edwards walk through remote, at-scale onboarding with Intune&lt;/A&gt;. You will get a step-by-step look at both Windows Autopilot and Autopilot device preparation in action, along with guidance on choosing the right approach for your environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H4&gt;Keep the conversation going&lt;/H4&gt;
&lt;P&gt;Control rarely arrives as one big feature or capability. It shows up in the smaller updates admins lean on daily. A sync they can watch, a compliance rule they can shape, or a firmware update they can run with confidence. Together, these capabilities add more certainty and give time back. That is how modern endpoint management should work.&lt;/P&gt;
&lt;P&gt;In that same spirit, staying in control means staying current as threat response speeds up. &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/build-a-patch-strategy-for-today%E2%80%99s-threat-pace-with-microsoft/4535115" target="_blank" rel="noopener" data-lia-auto-title="Read our recent post by Jason Roszak" data-lia-auto-title-active="0"&gt;Read our recent post by Jason Roszak&lt;/A&gt; for practical guidance on building a patch strategy with Microsoft. Let us know in the comments what you think of these new capabilities and stay tuned for more next month.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 22:03:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-july/ba-p/4537392</guid>
      <dc:creator>ScottSawyer</dc:creator>
      <dc:date>2026-07-28T22:03:17Z</dc:date>
    </item>
    <item>
      <title>IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-policys-user-affinity-with-modern-auth-does-not/m-p/4541329#M23629</link>
      <description>&lt;P&gt;IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP&lt;/P&gt;&lt;P&gt;I am trying to test the newer&amp;nbsp;&lt;STRONG&gt;iOS Enrollment Policies&lt;/STRONG&gt;&amp;nbsp;using&amp;nbsp;&lt;STRONG&gt;User Affinity with Modern Authentication&lt;/STRONG&gt;&amp;nbsp;instead of the older&amp;nbsp;&lt;STRONG&gt;Enrollment Profiles&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One thing I've noticed is that the&amp;nbsp;&lt;STRONG&gt;"Install Company Portal with VPP"&lt;/STRONG&gt;&amp;nbsp;setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies.&lt;/P&gt;&lt;P&gt;My test Policy configuration is using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User Affinity with Modern Authentication&lt;/LI&gt;&lt;LI&gt;Company Portal deployed as a VPP app&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tested deploying Company Portal as a&amp;nbsp;&lt;STRONG&gt;required VPP app&lt;/STRONG&gt;, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to&amp;nbsp;&lt;STRONG&gt;set up company access&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;download a management profile&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;This doesn't seem correct because the device was already enrolled through&amp;nbsp;&lt;STRONG&gt;ADE&lt;/STRONG&gt;. If I select&amp;nbsp;&lt;STRONG&gt;Postpone&lt;/STRONG&gt;, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed.&lt;/P&gt;&lt;P&gt;this has to be a bug or something right? the microsoft docs on this are very confusing or missing details.&lt;/P&gt;&lt;P&gt;I also noticed that the device initially appears in Intune/entra as&amp;nbsp;&lt;STRONG&gt;"iPad"&lt;/STRONG&gt;. After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing&amp;nbsp;&lt;STRONG&gt;two devices&lt;/STRONG&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"iPad" (This is the Ipad that you're currently using)&lt;/LI&gt;&lt;LI&gt;"ipad123-testing" ( this is the proper name and matches intune / entra)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Under&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management&lt;/STRONG&gt;, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully.&lt;/P&gt;&lt;P&gt;It appears that Company Portal is&amp;nbsp;&lt;STRONG&gt;not associating itself with the existing ADE enrollment record&lt;/STRONG&gt;. Instead, it seems to be attempting a&amp;nbsp;&lt;STRONG&gt;user-driven enrollment workflow&lt;/STRONG&gt;&amp;nbsp;on a device that is already enrolled and managed through ADE.&lt;/P&gt;&lt;P&gt;Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state.&lt;/P&gt;&lt;P&gt;i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.I am trying to test the newer&amp;nbsp;&lt;STRONG&gt;iOS Enrollment Policies&lt;/STRONG&gt;&amp;nbsp;using&amp;nbsp;&lt;STRONG&gt;User Affinity with Modern Authentication&lt;/STRONG&gt;&amp;nbsp;instead of the older&amp;nbsp;&lt;STRONG&gt;Enrollment Profiles&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One thing I've noticed is that the&amp;nbsp;&lt;STRONG&gt;"Install Company Portal with VPP"&lt;/STRONG&gt;&amp;nbsp;setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies.&lt;/P&gt;&lt;P&gt;My test Policy configuration is using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User Affinity with Modern Authentication&lt;/LI&gt;&lt;LI&gt;Company Portal deployed as a VPP app&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tested deploying Company Portal as a&amp;nbsp;&lt;STRONG&gt;required VPP app&lt;/STRONG&gt;, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to&amp;nbsp;&lt;STRONG&gt;set up company access&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;download a management profile&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;This doesn't seem correct because the device was already enrolled through&amp;nbsp;&lt;STRONG&gt;ADE&lt;/STRONG&gt;. If I select&amp;nbsp;&lt;STRONG&gt;Postpone&lt;/STRONG&gt;, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed.&lt;/P&gt;&lt;P&gt;this has to be a bug or something right? the microsoft docs on this are very confusing or missing details.&lt;/P&gt;&lt;P&gt;I also noticed that the device initially appears in Intune/entra as&amp;nbsp;&lt;STRONG&gt;"iPad"&lt;/STRONG&gt;. After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing&amp;nbsp;&lt;STRONG&gt;two devices&lt;/STRONG&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"iPad" (This is the Ipad that you're currently using)&lt;/LI&gt;&lt;LI&gt;"ipad123-testing" ( this is the proper name and matches intune / entra)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Under&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management&lt;/STRONG&gt;, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully.&lt;/P&gt;&lt;P&gt;It appears that Company Portal is&amp;nbsp;&lt;STRONG&gt;not associating itself with the existing ADE enrollment record&lt;/STRONG&gt;. Instead, it seems to be attempting a&amp;nbsp;&lt;STRONG&gt;user-driven enrollment workflow&lt;/STRONG&gt;&amp;nbsp;on a device that is already enrolled and managed through ADE.&lt;/P&gt;&lt;P&gt;Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state.&lt;/P&gt;&lt;P&gt;i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 02:55:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-policys-user-affinity-with-modern-auth-does-not/m-p/4541329#M23629</guid>
      <dc:creator>GT3</dc:creator>
      <dc:date>2026-07-28T02:55:58Z</dc:date>
    </item>
    <item>
      <title>iOS Enrollment and Conditional Access</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-and-conditional-access/m-p/4541284#M23628</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need some help!&lt;/P&gt;&lt;P&gt;We are configuring Intune to allow &lt;STRONG&gt;BYOD on iOS devices&lt;/STRONG&gt; using the &lt;STRONG&gt;Account Driven User Enrollment&lt;/STRONG&gt; method. In this scenario, the user enrolls the device by following the path:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management &amp;gt; Sign in to your Work or School Account&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The enrollment process was working correctly until we configured a &lt;STRONG&gt;Conditional Access&lt;/STRONG&gt; policy to ensure that only BYOD-managed devices can access company resources. In other words, only devices that have successfully completed enrollment and are marked as &lt;STRONG&gt;Compliant&lt;/STRONG&gt; in Intune should be allowed to use corporate applications.&lt;/P&gt;&lt;P&gt;However, after applying the policy, we are no longer able to complete the enrollment process. During one of the enrollment steps, the device displays the following message:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translate English&lt;/STRONG&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;"Setting Up iPhone&lt;/STRONG&gt;&lt;BR /&gt;iPhone setup may take a few minutes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sign-In Failed&lt;/STRONG&gt;&lt;BR /&gt;Enrollment failed. Please try again.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;OK"&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;1.&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Target resources (Include)&lt;/STRONG&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;2.&amp;nbsp;Target resources (Exclude)&lt;/STRONG&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;3. &lt;/STRONG&gt;&lt;STRONG&gt;Device Platform:&lt;/STRONG&gt; iOS&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;4.&lt;/STRONG&gt; &lt;STRONG&gt;Filter for devices:&lt;/STRONG&gt; device.mdmAppId -notIn ["0000000a-0000-0000-c000-000000000000"]&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;5.&lt;/STRONG&gt; &lt;STRONG&gt;Grant:&lt;/STRONG&gt; Require device to be marked as compliant&lt;/P&gt;&lt;img /&gt;&lt;P&gt;This is our current Conditional Access policy configuration. Has anyone encountered this behavior before, or can identify whether there is any setting that might be blocking the enrollment process during the compliance validation stage?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 19:37:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-and-conditional-access/m-p/4541284#M23628</guid>
      <dc:creator>GuilhermeSoares</dc:creator>
      <dc:date>2026-07-27T19:37:50Z</dc:date>
    </item>
    <item>
      <title>From hours to minutes: Rethinking Microsoft Intune compliance reporting with the Export API</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/from-hours-to-minutes-rethinking-microsoft-intune-compliance/ba-p/4540554</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Daniel Gerrity – Principal Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you manage a large device fleet with Microsoft Intune, you’ve almost certainly needed to get reporting data out of the service at scale — compliance state, device inventory, app status, endpoint analytics, or one of the many other reports admins rely on for operations and audit evidence. Intune supports this pattern through the &lt;STRONG&gt;export API&lt;/STRONG&gt;, which generates supported reports as asynchronous export jobs instead of requiring you to retrieve the same data through thousands of operational Graph calls.&lt;/P&gt;
&lt;P&gt;You can see the full list of reports available through the export API in &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/reports/ref-graph-available-reports" target="_blank" rel="noopener"&gt;Intune reports and properties available using Graph API&lt;/A&gt; documentation. In the illustrative scenario below, moving one nightly job from operational Graph reporting endpoints to the &lt;STRONG&gt;Intune export API (exportJobs)&lt;/STRONG&gt; cuts the work from roughly &lt;STRONG&gt;100,000 API calls to about 15&lt;/STRONG&gt; while producing the same report data. The runtime drops from &lt;STRONG&gt;~2.5 hours to ~15 minutes&lt;/STRONG&gt;. Here’s how, and why the pattern holds up as your fleet grows.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; padding: 18px 20px; border-left: 5px solid #FFB900; background-color: #fff8e5; border-radius: 6px; color: #1f1f1f; font-family: Arial, Helvetica, sans-serif; font-size: 14px;"&gt;
&lt;DIV style="display: flex; align-items: center; gap: 8px; margin-bottom: 8px;"&gt;&lt;SPAN style="font-size: 18px; line-height: 1;"&gt;&lt;STRONG style="font-size: 16px; color: #8a5a00;"&gt;Note on the numbers&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P style="margin: 0; line-height: 1.5;"&gt;The figures below are a representative example for a hypothetical 50,000-device enterprise, “Contoso,” and are rounded for clarity. Your results may vary based on fleet size, policy count, and how many compliance settings you evaluate.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H2&gt;The scenario&lt;/H2&gt;
&lt;P&gt;Contoso runs a nightly job that answers a deceptively simple question:&lt;/P&gt;
&lt;DIV style="margin: 24px 0; padding: 20px 24px; background-color: #f5f9ff; border-left: 4px solid #0078d4; border-radius: 4px;"&gt;
&lt;P style="margin: 0; font-size: 16px; line-height: 1.6; color: #323130;"&gt;For each device, across every compliance policy assigned to it, what is the state of each individual setting?&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;This is a classic &lt;STRONG&gt;per-device, per-compliance-policy, per-setting&lt;/STRONG&gt; state export. It’s the raw material behind compliance dashboards, audit evidence, remediation targeting, and “why is this device noncompliant” investigations. In Intune’s reporting catalog, this is the DeviceStatusSummaryByCompliancePolicySettingsReportV3 report.&lt;/P&gt;
&lt;P&gt;Contoso has &lt;STRONG&gt;~50,000 managed devices&lt;/STRONG&gt;, and the job runs once a day.&lt;/P&gt;
&lt;H2&gt;The old way: Operational Graph APIs&lt;/H2&gt;
&lt;P&gt;The intuitive approach treats compliance data as something you &lt;EM&gt;fetch, per device, right now&lt;/EM&gt;. The script:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Enumerates the fleet (managedDevices).&lt;/LI&gt;
&lt;LI&gt;Loops over every device, and for each one calls the operational reporting or setting-state endpoints (such as managedDevices detail and settingStates) to pull that device’s per-policy, per-setting results.&lt;/LI&gt;
&lt;LI&gt;Pages through the results in small JSON pages (often 50 rows at a time), reassembling everything client-side.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It works. It just doesn’t scale because the &lt;STRONG&gt;number of calls is a function of the number of devices&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;At roughly two operational calls per device, 50,000 devices is on the order of &lt;STRONG&gt;~100,000 Graph calls per run&lt;/STRONG&gt;. That volume brings its own tax:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Throttling. &lt;/STRONG&gt;You hit service protection limits and have to implement retry/back-off logic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Threading. &lt;/STRONG&gt;To finish inside the window at all, you parallelize which means concurrency bugs, partial failures, and harder debugging.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fragility. &lt;/STRONG&gt;A run that makes 100,000 calls has 100,000 chances to fail, and a mid-run failure often means starting over.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Time. &lt;/STRONG&gt;End&lt;STRONG&gt;=&lt;/STRONG&gt;to&lt;STRONG&gt;-&lt;/STRONG&gt;end, the job lands around ~2.5 hours.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Every time Contoso onboards more devices, this job gets &lt;EM&gt;slower and more expensive&lt;/EM&gt; - the worst possible scaling direction for something that runs every night.&lt;/P&gt;
&lt;H2&gt;The new way: Export API (exportJobs)&lt;/H2&gt;
&lt;P&gt;The export API flips the model. Instead of asking Graph to compute results device-by-device in real time, you ask Intune to &lt;STRONG&gt;generate the entire report once, server-side&lt;/STRONG&gt;, and hand you back a single file.&lt;/P&gt;
&lt;P&gt;The flow is a short, asynchronous handshake:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;1. POST  /deviceManagement/reports/exportJobs
         { "reportName": "DeviceStatusSummaryByCompliancePolicySettingsReportV3",
           "format": "csv", ...optional filter/select... }
         → returns a jobId, status: "notStarted"

2. GET   /deviceManagement/reports/exportJobs('{jobId}')
         → poll until status: "completed"     (a handful of polls while it builds)
         → response includes a short-lived download URL

3. GET   {download URL}
         → one zipped CSV containing every device × policy × setting row&lt;/LI-CODE&gt;
&lt;P&gt;That’s the whole pattern: &lt;STRONG&gt;request → poll → download → unzip → load&lt;/STRONG&gt;. One report, one file, the entire fleet inside it.&lt;/P&gt;
&lt;P&gt;Count the calls: &lt;STRONG&gt;one&lt;/STRONG&gt; POST to start the job, &lt;STRONG&gt;a handful&lt;/STRONG&gt; of GET polls while Intune builds the file, and &lt;STRONG&gt;one&lt;/STRONG&gt; GET to download it - call it&amp;nbsp;&lt;STRONG&gt;~15 calls total&lt;/STRONG&gt;. Not ~15 per device. ~15 for the whole 50,000-device run. And that number barely moves whether Contoso has 50,000 devices or 150,000.&lt;/P&gt;
&lt;P&gt;Runtime drops to about &lt;STRONG&gt;~15 minutes&lt;/STRONG&gt;, most of which is simply &lt;EM&gt;waiting&lt;/EM&gt; for the export to finish - cheap poll calls, not active compute.&lt;/P&gt;
&lt;P&gt;Most importantly, &lt;STRONG&gt;the output schema is identical&lt;/STRONG&gt;. The CSV columns match what the old per-device loop assembled, so nothing downstream; dashboards, warehouse tables, alerting, has to change. You swap the &lt;EM&gt;acquisition&lt;/EM&gt; layer and leave everything else alone.&lt;/P&gt;
&lt;H2&gt;Side by side&lt;/H2&gt;
&lt;DIV style="max-width: 900px; margin: 24px auto; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-custom-d1d1d1 lia-border-style-solid" border="1" style="width: 100%; border-width: 1px; border-spacing: 0;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-f5f5f5" scope="col" style="padding: 16px;"&gt;Comparison&lt;/th&gt;&lt;th class="lia-background-color-custom-0f6cbd" scope="col" style="padding: 16px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Operational Graph APIs&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-background-color-custom-fff4ce" scope="col" style="padding: 16px;"&gt;&lt;SPAN style="display: inline-block; margin-bottom: 6px; padding: 2px 8px; font-size: 12px; font-weight: 600; color: #5c4400; background-color: #ffdf75; border: 1px solid #e0b000; border-radius: 12px;"&gt; Recommended &lt;/SPAN&gt; &lt;BR /&gt;Export API (&lt;CODE style="font-size: 13px;"&gt;exportJobs&lt;/CODE&gt;)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Pattern&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Per-device loop plus paging&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Async export → download one file&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;API calls per run&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~100,000&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~15&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Calls scale with&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Number of devices&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Nothing. The handshake remains fixed.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Runtime&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~2.5 hours&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~15 minutes&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Concurrency&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Threading required&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;None needed&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Output schema&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;—&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Unchanged and drop-in compatible&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-f0f6ff" scope="row" style="padding: 16px;"&gt;Net result&lt;/th&gt;&lt;td class="lia-background-color-custom-f7f9fc" style="padding: 16px;"&gt;—&lt;/td&gt;&lt;td class="lia-background-color-custom-dff6dd" style="padding: 16px;"&gt;~6,000× fewer API calls&lt;BR /&gt;~10× faster runtime&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;Why it scales: Roundtrips, not bytes&lt;/H2&gt;
&lt;P&gt;Here’s the subtlety worth internalizing, because it’s easy to get wrong. There are &lt;STRONG&gt;two different costs&lt;/STRONG&gt; in this job, and they scale on &lt;STRONG&gt;different axes&lt;/STRONG&gt;:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;The number of API calls&lt;/STRONG&gt; - round-trips across the wire.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The volume of data&lt;/STRONG&gt; - the actual compliance rows you move.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;The data volume is the same either way. &lt;/STRONG&gt;50,000 devices × N settings is 50,000 × N rows, whether you assemble them from 100,000 little paged responses or receive them in one CSV. The export doesn’t move &lt;EM&gt;less&lt;/EM&gt; data - it moves the&amp;nbsp;&lt;EM&gt;same&lt;/EM&gt; data. And yes, that file grows with &lt;STRONG&gt;both&lt;/STRONG&gt; device count and setting count. More devices, bigger file; more settings, bigger file.&lt;/P&gt;
&lt;P&gt;So the win isn’t fewer bytes. &lt;STRONG&gt;The win is fewer round-trips.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Every one of those 100,000 operational calls relies on authentication, TLS setup, network latency, and service-protection (throttling) accounting regardless of how much data it returns. Multiply that fixed overhead by 100,000 and it dominates everything. The export only pays that tax &lt;STRONG&gt;twice&lt;/STRONG&gt;: once to start the job, once to download the file. Intune does the assembly server-side and streams you the result in a single bulk transfer.&lt;/P&gt;
&lt;P&gt;That reframes the scaling story:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Call count&lt;/STRONG&gt; is essentially constant - it doesn’t grow with devices or settings. It’s one job and one download.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data volume&lt;/STRONG&gt; grows with devices and settings but a bigger CSV is a bigger &lt;EM&gt;single download&lt;/EM&gt;, not more calls. Bulk transfer is exactly what HTTP is good at.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Runtime&lt;/STRONG&gt; has a mild data dependency: a larger fleet takes Intune a little longer to build the file. But you absorb that as a few extra seconds of poll-waiting, not as thousands of extra calls you have to orchestrate, retry, and throttle-manage.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;What the IT admin actually gets&lt;/H2&gt;
&lt;P&gt;Beyond the raw speed, here’s the value that shows up in day-to-day operations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Your maintenance window comes back. &lt;/STRONG&gt;A 15-minute job leaves room for everything else.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fewer moving parts to maintain. &lt;/STRONG&gt;No custom throttling handler, no thread pool, no resumability logic. Less code is less to break at 2 a.m.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reliability by design. &lt;/STRONG&gt;Two roundtrips means two failure points, and the server does the heavy lifting of assembling a consistent snapshot.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Lower cost and lower service impact. &lt;/STRONG&gt;Eliminating ~100,000 calls is easier on your tenant’s throttling limits and a better citizen for the Intune service overall.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Room to grow. &lt;/STRONG&gt;Because call count is decoupled from device count, doubling the fleet doesn’t double the job, you just download a somewhat larger file.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No downstream disruption. &lt;/STRONG&gt;Same schema for the output means the migration is contained to the ingestion step which is a low-risk swap, not a re-platforming.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;When to use which&lt;/H2&gt;
&lt;P&gt;The export API isn’t a universal replacement, it’s best used for &lt;STRONG&gt;bulk, point-in-time snapshots&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Reach for exportJobs&lt;/STRONG&gt; when you need the whole fleet’s state (or a large, filtered slice) on a schedule such as nightly compliance loads, audit exports, warehouse hydration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Stick with the operational endpoints&lt;/STRONG&gt; when you need a single device &lt;EM&gt;right now&lt;/EM&gt;, an interactive “check this one device” lookup, or a real-time remediation trigger where waiting on an async job doesn’t make sense.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The two are complementary. The mistake isn’t using the operational APIs, it’s using them &lt;EM&gt;in a loop&lt;/EM&gt; to reconstruct something the export API will hand you in one file.&lt;/P&gt;
&lt;H2&gt;The takeaway&lt;/H2&gt;
&lt;P&gt;The per-device loop feels natural because it mirrors how we think about devices, one at a time. But at fleet scale, the question isn’t “what’s the state of this device?” a hundred thousand times over. It’s “give me the state of everything,” once. The export API is built for exactly that question, and answering it the right way turned a multi-hour nightly grind into a coffee break - &lt;STRONG&gt;from ~100,000 calls to about 15, ~10× faster, with zero downstream changes.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment below or reach out to us on X: &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 19:07:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/from-hours-to-minutes-rethinking-microsoft-intune-compliance/ba-p/4540554</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-24T19:07:28Z</dc:date>
    </item>
    <item>
      <title>Designing Intune enrollment for frontline workers: Choosing the right path for real-world devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Shawn Catlin – Senior Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Practitioner perspective from Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune), with deep experience in secure frontline mobility, including regulated healthcare environments.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Enrollment &lt;U&gt;methodology&lt;/U&gt;&amp;nbsp;is one of the most consequential design decisions teams make for frontline environments. It shapes how devices are used, how identity is handled, how failures are recovered from, and how much friction workers experience before they can do their jobs.&lt;/P&gt;
&lt;P&gt;Frontline use cases aren’t limited to shared devices. They can span nearly every enrollment type available in Microsoft Intune, including user-assigned, shared, dedicated, kiosk, corporate-owned, BYOD, and zero-touch deployment models. The right choice is often influenced by business need, operational workflow, budget, support model, and security requirements. But it must also account for platform and operating system design. Android, iOS, and iPadOS may offer similar enrollment concepts, but they don’t always behave the same way or support the same management patterns.&lt;/P&gt;
&lt;P&gt;That distinction matters. A kiosk or dedicated-device model, for example, is intentionally designed for a locked-down, task-focused experience. It manages the device around a specific function, not around a personalized user workspace. In that model, broad app availability, persistent personalization, and user-driven app installation are not the primary management paradigm. Similarly, a shared-device model should not be selected simply because an organization cannot provide a dedicated device to every worker. If identity, app access, compliance, or user context are required, those needs must be part of the enrollment decision from the beginning.&lt;/P&gt;
&lt;P&gt;There is no copy-and-paste frontline enrollment strategy that works across every industry, business unit, or device scenario. Some frontline devices are shared across shifts and must remain reliable where connectivity, identity, and support are not guaranteed. Others are assigned to supervisors, clinicians, field workers, or shift leads who need persistent access to apps, settings, and data. When enrollment choices are made without accounting for these realities, especially platform differences and OS-level limitations, friction surfaces quickly during pilots and scales painfully during rollout.&lt;/P&gt;
&lt;P&gt;This article explains how to approach Intune enrollment for frontline devices through a practical, reality-first lens: start with how the device is used, align the management model to the workflow, and then plan how the device will be enrolled, replaced, and reprovisioned at scale.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;In a hospital environment, frontline does not mean one type of device or one type of worker. A shared clinical workstation, a nurse’s mobile device, a patient check-in kiosk, a barcode scanner, and a supervisor’s assigned device may all be considered frontline, but they each have very different identity, security, app, and recovery requirements. That is why enrollment decisions have to start with the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment Is a Design Decision, not a Checkbox&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Enrollment does more than bring a device under management. It defines how the device is expected to work, where the security boundary sits, how identity is applied, and what recovery looks like when something fails in the field.&lt;/P&gt;
&lt;P&gt;There is no single “best” enrollment model for frontline. There is only the model that best fits how the device is actually used. The right choice depends on whether the device follows a person, a shift, a task, or a business process. It also depends on how much identity matters to the experience, whether apps need to be personalized, whether Conditional Access or compliance is required, and how quickly the device must be replaced or recovered.&lt;/P&gt;
&lt;P&gt;This is why many problems that look like policy, app, or configuration failures are actually enrollment design problems in disguise. A device can be successfully enrolled and still be poorly designed for the job it needs to do.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;A device can be successfully enrolled and still fail the workflow. If a shift worker cannot access the right app quickly, if a shared device retains the wrong user context, or if a replacement device cannot be brought online during a shift, the issue may look like an app or support problem. In reality, it often traces back to an enrollment model that did not match the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Separate Two Decisions: Management Model and Provisioning Method&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment planning becomes easier when teams separate two related but different decisions.&lt;/P&gt;
&lt;P&gt;The first decision is the &lt;STRONG&gt;management model&lt;/STRONG&gt;. This is the architectural choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does the device need to represent a specific person?&lt;/LI&gt;
&lt;LI&gt;Is the device shared across multiple workers?&lt;/LI&gt;
&lt;LI&gt;Is it dedicated to a narrow task or workflow?&lt;/LI&gt;
&lt;LI&gt;Does the device require personal apps, persistent settings, or user-specific data?&lt;/LI&gt;
&lt;LI&gt;Does the workflow require Conditional Access, compliance, auditability, or individual identity?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This decision determines whether the device should be user-associated, shared, dedicated, kiosk-style, personally owned, or corporate-owned with a work profile.&lt;/P&gt;
&lt;P&gt;The second decision is the &lt;STRONG&gt;provisioning and reprovisioning method&lt;/STRONG&gt;. This is the lifecycle choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How will the device get into management the first time?&lt;/LI&gt;
&lt;LI&gt;Will it be staged by IT, a depot, a partner, or the site?&lt;/LI&gt;
&lt;LI&gt;What happens after a wipe, repair, refresh, or reassignment?&lt;/LI&gt;
&lt;LI&gt;Can the device recover without a specific user’s credentials?&lt;/LI&gt;
&lt;LI&gt;Will Wi-Fi, certificates, tokens, apps, and policies be available at first boot?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Zero-touch, pre-staging, depot workflows, and reprovisioning plans support the selected management model. They should not replace the decision about which model is right for the scenario.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Start With How the Device Is Used&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;In the previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/A&gt;, we discussed why successful frontline migrations begin with understanding how devices are actually used in the field. That discovery work should now feed directly into enrollment design.&lt;/P&gt;
&lt;P&gt;The most reliable starting point is not the department, license, or ownership model. It is the device’s behavior in the field.&lt;/P&gt;
&lt;P&gt;Ask:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does this device follow a person?&lt;/LI&gt;
&lt;LI&gt;Does it follow a shift?&lt;/LI&gt;
&lt;LI&gt;Does it follow a task?&lt;/LI&gt;
&lt;LI&gt;Does it need to know who the user is?&lt;/LI&gt;
&lt;LI&gt;Does it need persistent user context?&lt;/LI&gt;
&lt;LI&gt;Does it need to be quickly replaced with minimal IT involvement?&lt;/LI&gt;
&lt;LI&gt;Does the platform support the experience you expect?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The answers help map real-world requirements to the right Intune enrollment approach. Before selecting an enrollment model, organizations should also understand how identity is expected to function on the device. If you have not yet reviewed assigned versus shared identity patterns, see our previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-Identity" target="_blank" rel="noopener"&gt;Migrating frontline mobile devices: Identity considerations for assigned and shared devices&lt;/A&gt;, which explores how user identity, authentication, auditability, and device ownership assumptions can influence frontline management decisions.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Decision indicator&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Usually points toward&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Validate before choosing&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs persistent apps, settings, approvals, or data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-driven or user-associated enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether identity and personalization are truly required for the workflow&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers use the same device across shifts and need individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared or device-first enrollment with identity support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;How sign-in, sign-out, session cleanup, and auditability will work&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device performs a narrow, repeatable task&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or kiosk-style enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can operate with a locked-down app set and minimal user choice&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device needs corporate control but may allow limited personal use&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned work profile where supported&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the OS supports the expected separation between work and personal data&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device is personally owned and only work data needs to be protected&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD / personally owned work profile / user enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can tolerate limited organizational control&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device must be replaced quickly with minimal IT involvement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Pre-staged, zero-touch, or easily reprovisioned device-first model&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Reset behavior, network readiness, certificate delivery, and replacement speed&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The environment has inconsistent connectivity or limited support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Simpler enrollment paths with fewer live dependencies&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;What the device needs at first boot, during sign-in, and after wipe or reset&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Map Frontline Scenarios to Enrollment Models&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;A practical Intune strategy starts by accepting that frontline is not one scenario. It is a collection of scenarios. Standardization is important, but standardizing on one enrollment method for every frontline use case is rarely the right goal. Mature organizations standardize the decision framework, not necessarily the deployment model.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Device usage pattern&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Typical characteristics&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;iOS/iPadOS enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Android enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-assigned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs personalized apps, settings, and data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with user affinity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Fully Managed or Corporate-Owned Work Profile if personal use is permitted&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared device with individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers share the device and sign in with their own identities&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with Microsoft Entra Shared Device Mode; Shared iPad when multi-user iPad support is required&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or task-based device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Device performs a specific function and does not require a personalized user experience&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment without user affinity, with supervised device and app restrictions&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android device without Google Mobile Services&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned specialty device, often shared or task-focused&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Not applicable&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android AOSP userless or AOSP user-associated enrollment&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Personally owned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Employee-owned device used for work&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD User Enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Personally Owned Work Profile&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Zero-touch or pre-staged deployment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned device that needs scalable provisioning or replacement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment through Apple Business Manager or Apple School Manager&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Zero-touch Enrollment, Samsung Knox Mobile Enrollment, or equivalent supported provisioning path&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If the device follows a person, choose a model optimized for identity and personalized access. If the device follows a shift, workflow, or task, choose a model optimized for simplicity, consistency, and easy replacement.&lt;/P&gt;
&lt;P&gt;If you’re looking for more platform-specific guidance please see frontline enrollment resources for both Android and iOS/iPadOS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/android?tabs=ae" target="_blank" rel="noopener"&gt;Get started with Android frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/ios-ipados?tabs=sharedipad" target="_blank" rel="noopener"&gt;Get started with iOS/iPadOS frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These resources provide detailed implementation guidance, recommended enrollment approaches, and platform-specific considerations for frontline deployments.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Platform and OS Differences Matter&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Teams often assume that similar enrollment concepts behave the same way across platforms. They do not.&lt;/P&gt;
&lt;P&gt;On Android, a shared frontline device that needs a locked-down experience and individual worker sign-in often maps to Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode. Android Enterprise Dedicated Device provides the task-focused management model. Entra Shared Device Mode adds the identity layer so workers can sign in as themselves. Intune Managed Home Screen then helps present a consistent launcher experience and enforce the sign-in flow between shifts.&lt;/P&gt;
&lt;P&gt;On iPadOS, a shared device with individual sign-in may be designed using Shared iPad for Business or Automated Device Enrollment with Microsoft Entra Shared Device Mode. The distinction becomes important when security requirements are involved. Shared iPad can support multi-user scenarios, but organizations should review its limitations carefully, especially if Conditional Access or device compliance enforcement is required. Where Conditional Access, compliance, and security-driven access controls are mandatory, ADE with Entra Shared Device Mode may be the better fit, although it introduces additional configuration considerations and dependency on compatible apps. See &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/apple/shared-device-solutions-ios" target="_blank" rel="noopener"&gt;Shared iOS and iPadOS devices&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;Platform differences also matter for corporate-owned devices that allow personal use. Android Corporate-Owned Work Profile provides a native work profile boundary between corporate and personal data. iOS and iPadOS do not provide that same OS-level separation for corporate-owned personally enabled devices, so organizations often rely more heavily on app-level controls and MAM policies.&lt;/P&gt;
&lt;P&gt;The practical point is simple: choose the enrollment model that fits the workflow, but confirm that the platform supports the management pattern you expect.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;When User-Driven Enrollment Makes Sense&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;User-driven enrollment still has a place in frontline, but the use cases are narrower than many teams expect. It makes sense when the device needs to reflect a specific person, not just a task.&lt;/P&gt;
&lt;P&gt;This can work well for shift managers, supervisors, clinicians, field workers, or frontline leads who need persistent access to apps, approvals, notifications, data, and settings. In these cases, user-driven or user-associated enrollment can provide cleaner app targeting, stronger identity context, and a more familiar experience for the person carrying the device.&lt;/P&gt;
&lt;P&gt;Common indicators include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The worker keeps the device for most of its working life.&lt;/LI&gt;
&lt;LI&gt;The user needs email, Teams, approvals, or real-time app badges.&lt;/LI&gt;
&lt;LI&gt;The workflow depends on user-specific apps, settings, or data.&lt;/LI&gt;
&lt;LI&gt;The device may support some personal enablement where the platform supports separation.&lt;/LI&gt;
&lt;LI&gt;The worker is responsible for keeping the device available, charged, and ready for use.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But personalization comes with operational cost. User-driven enrollment increases dependency on credentials, adds friction when sign-in steps fail, and makes recovery more complex when a device must be replaced quickly. It is usually a poor fit for shared workflows, high-turnover roles, or task-based devices where speed and predictability matter more than personalization.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Designing for Shared and Shift-Based Devices&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Shared and shift-based devices are passed from one worker to the next. They are expected to stay productive across handoffs and often operate in environments where there is little time for sign-in friction or troubleshooting.&lt;/P&gt;
&lt;P&gt;For these scenarios, device-first enrollment usually aligns better with reality because the device is treated as a managed tool for a shared workflow, not as a personal endpoint tied to one individual. The goal is consistency: the next worker should be able to pick up the device, authenticate if required, and get to work without recovering from leftover state or complex setup steps.&lt;/P&gt;
&lt;P&gt;If shared devices require individual sign-in, identity must be designed into the enrollment model. Microsoft Entra Shared Device Mode and QR code authentication can help preserve individual identity without forcing workers through a full username and password flow at every handoff. This is especially relevant in environments such as retail, healthcare, warehousing, and field operations where shared devices still need auditability, Conditional Access, app access, or user-specific sessions.&lt;/P&gt;
&lt;P&gt;Shared-device success does not come from default settings alone. Teams should define:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How sign-in and sign-out should work.&lt;/LI&gt;
&lt;LI&gt;What user context should persist.&lt;/LI&gt;
&lt;LI&gt;What should be cleared between sessions.&lt;/LI&gt;
&lt;LI&gt;Which apps need to support shared-device behavior.&lt;/LI&gt;
&lt;LI&gt;How quickly a device can be swapped or reprovisioned.&lt;/LI&gt;
&lt;LI&gt;Whether access depends on the user, the device, the app session, or a combination.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;Especially in healthcare and clinical settings, shared devices have to be absolutely ready for the next worker, the next patient, and the next task. There is rarely time for complex recovery steps, unclear ownership, or leftover user state from the previous shift. A good shared-device design should support quick handoff, clean session behavior, and predictable recovery under pressure.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Dedicated and Kiosk Devices: Avoid Personalization Drift&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Dedicated and kiosk-style enrollment is ideal when the device performs a narrow, repeatable function and individual identity is secondary or unnecessary. Examples include scanners, point-of-sale systems, check-in kiosks, digital signage, inventory devices, and task-specific handhelds.&lt;/P&gt;
&lt;P&gt;The strength of kiosk-style design is that it limits choice. That is also the boundary teams must respect. A kiosk is not intended to behave like a general-purpose device where users browse a catalog of available apps, personalize settings, or install what their business unit needs on demand.&lt;/P&gt;
&lt;P&gt;A common friction point occurs when organizations try to simplify IT support with one shared kiosk configuration for multiple businesses or personas, and then expect users to install the apps they need. That creates a mismatch. User-installed available apps are not the kiosk paradigm. If each business unit needs a different set of apps, the better design is usually to do the work upfront: segment the device scenarios, define the required app sets, and deploy the right configuration to the right devices.&lt;/P&gt;
&lt;P&gt;This is also important for identity and certificates. User certificates, persistent user sessions, and shared secrets can conflict with the assumptions of a device-first or kiosk model. If the workflow requires user identity, auditability, or user-specific access, that requirement should be addressed through the right shared-device identity pattern, not bolted onto a kiosk design after the fact.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment at Scale: Plan for Provisioning and Replacement&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Once the right management model is selected, teams should plan how devices will be enrolled and reprovisioned at scale.&lt;/P&gt;
&lt;P&gt;At scale, enrollment becomes a lifecycle capability. The question is not only how a device gets into management the first time. Instead, it is how quickly that same device can be staged, replaced, wiped, repaired, reassigned, or reintroduced into service.&lt;/P&gt;
&lt;P&gt;Some organizations ship devices directly to frontline locations and complete setup during out-of-box experience. Others rely on depot, partner, or white-glove processes to front-load setup before the device reaches the site. Neither model is automatically better. The right choice depends on network readiness, site support, variability at first boot, app dependencies, certificate delivery, and replacement expectations.&lt;/P&gt;
&lt;P&gt;Replacement velocity is a real design constraint. In many frontline settings, a broken device cannot wait for a full troubleshooting cycle. A worker may need to drop one device at a charging bay and pick up another with minimal disruption. The more the enrollment and reprovisioning model supports a known-good state, the less productivity depends on one specific device surviving the shift.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Common Friction Points in Frontline Enrollment&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment problems are rarely caused by one dramatic failure. More often, they come from reasonable decisions made in the wrong order or optimized for the wrong thing.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Friction point&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Why it happens&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Better design approach&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating frontline as only shared&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The organization assumes all frontline workers use devices the same way&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Segment by workflow: person, shift, task, or business process&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Choosing shared because dedicated devices are too expensive&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Budget drives the model before identity and workflow are understood&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate identity, app, compliance, and recovery needs before choosing shared&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using kiosk for personalized workflows&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Kiosk seems simple and locked down&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use kiosk only when the workflow is task-focused and does not require broad personalization&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Wanting available apps on kiosk devices&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One configuration is used for too many personas&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Build scenario-specific app sets and configurations instead of relying on user installation&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using shared credentials&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Enrollment was not designed for individual identity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use Entra Shared Device Mode, QR code authentication, or another supported identity pattern&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Requiring user certificates on device-first or kiosk scenarios&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Security assumptions are copied from knowledge-worker designs&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate whether access can be controlled through device, app, or session design&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Over-securing setup at the expense of recovery&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Controls are designed for ideal conditions, not shift pressure&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design security that holds up during replacement, poor connectivity, and limited support&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating enrollment as a one-time event&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Success is measured by initial provisioning only&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design for wipe, repair, reassignment, refresh, and reprovisioning&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A deployment path that saves time on day one can create years of friction if it does not match how the device is used. In frontline scenarios, the best enrollment model is not always the fastest one to provision. It is the one that is easiest to sustain.&lt;/P&gt;
&lt;/DIV&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Closing&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Successful frontline deployments are rarely defined by the sophistication of their policies alone. They are defined by how well design choices hold up under real-world pressure. Enrollment is one of the earliest and most visible signals to frontline teams about whether the technology is there to support their work or get in the way.&lt;/P&gt;
&lt;P&gt;By treating enrollment as a deliberate design decision and grounding it in how devices are actually used, organizations can reduce friction, improve resilience, and create a foundation that scales as frontline operations evolve. Getting enrollment right does not guarantee success, but getting it wrong sets a ceiling that no amount of policy refinement can overcome.&lt;/P&gt;
&lt;P&gt;For more frontline examples and implementation guidance, see related Microsoft frontline worker management resources, including the blog, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-the-frontlines-frontline-worker-management-with-microsoft-intune/4387449" target="_blank" rel="noopener" data-lia-auto-title="From the frontlines: Frontline worker management with Microsoft Intune" data-lia-auto-title-active="0"&gt;&lt;EM&gt;From the frontlines: Frontline worker management with Microsoft Intune&lt;/EM&gt;&lt;/A&gt;, and the earlier article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;&lt;EM&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;When enrollment, identity, security, and recovery are designed well, frontline teams can stay focused on the people they serve - customers, patients, guests, employees, students, and communities - instead of the device in their hands. That is the standard a frontline enrollment strategy should be measured against.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As always, we welcome your feedback and experience. If you’ve navigated identity decisions for shared or frontline devices, share your advice and lessons learned in the comments, or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 16:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-23T16:59:40Z</dc:date>
    </item>
    <item>
      <title>Dell Firmware Very Slow to Appear in Intune Driver Updates</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/dell-firmware-very-slow-to-appear-in-intune-driver-updates/m-p/4539663#M23622</link>
      <description>&lt;P&gt;Have an instance where the Dell 5520 latest firmware release (1.51.0 released 09/06/26) has still not appeared in the Intune Driver Updates which means we have vulnerable laptops in the field.&lt;/P&gt;&lt;P&gt;We do not utilise Dell Command update on the laptop to reduce the attack surface so do rely on Intune to deliver these updates in a timely manner.&lt;/P&gt;&lt;P&gt;I'm aware that it can take a little while for Dell releases to appear on the Microsoft side, but this is over 6 weeks now.&lt;/P&gt;&lt;P&gt;We have spoken to Dell Support, but they have deemed this a Microsoft problem. We then spoke to Microsoft Support, and it was deemed that we would have to pay for support on this given it fell outside of the scope of our service level. So essentially no-one wanted to take responsibility or assist with this!&lt;/P&gt;&lt;P&gt;Does the forum have any insights into what may be going on here and how we can move this forward?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 08:56:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/dell-firmware-very-slow-to-appear-in-intune-driver-updates/m-p/4539663#M23622</guid>
      <dc:creator>SenõrEngineer</dc:creator>
      <dc:date>2026-07-22T08:56:43Z</dc:date>
    </item>
    <item>
      <title>Bitlocker key requested on the boot, but I don’t have any key</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager/bitlocker-key-requested-on-the-boot-but-i-don-t-have-any-key/m-p/4538890#M392</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My laptop (Windows 10, version 22H2, build 19045), that I have been using more than 6 years already, suddenly started asking for the BitLocker recovery key at startup, which is blocking access to the system entirely.&lt;/P&gt;&lt;P&gt;What I've already checked/tried:&lt;/P&gt;&lt;P&gt;- Checked account.microsoft.com/devices/recoverykey while signed in with my Microsoft account, no key appears for this device.&lt;/P&gt;&lt;P&gt;- Contacted Microsoft Support directly, they said they can no longer assist with Windows 10 issues and suggested posting here instead.&lt;/P&gt;&lt;P&gt;Is there any way to recover access to this drive?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 10:22:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager/bitlocker-key-requested-on-the-boot-but-i-don-t-have-any-key/m-p/4538890#M392</guid>
      <dc:creator>Yann1</dc:creator>
      <dc:date>2026-07-20T10:22:27Z</dc:date>
    </item>
    <item>
      <title>Microsoft EPM – Random CMD / PowerShell / OpenConsole popups</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/microsoft-epm-random-cmd-powershell-openconsole-popups/m-p/4538823#M23617</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;we are currently testing &lt;STRONG&gt;Microsoft Endpoint Privilege Management (EPM)&lt;/STRONG&gt; and are seeing some unexpected behavior on several devices.&lt;/P&gt;&lt;H3&gt;Symptoms&lt;/H3&gt;&lt;P&gt;Users occasionally see random:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CMD windows&lt;/LI&gt;&lt;LI&gt;PowerShell windows&lt;/LI&gt;&lt;LI&gt;OpenConsole windows&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The windows usually appear shortly after logon and disappear automatically after a short time.&lt;/P&gt;&lt;P&gt;Some developers also reported issues related to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;VS Code terminal integration&lt;/LI&gt;&lt;LI&gt;Copilot terminal actions&lt;/LI&gt;&lt;LI&gt;Windows Terminal&lt;/LI&gt;&lt;LI&gt;WSL / Debian&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Additional observations&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;However, we have also seen PowerShell popups on a user who is not currently part of the EPM pilot group&lt;/LI&gt;&lt;LI&gt;Some affected devices still have &lt;STRONG&gt;Admin By Request&lt;/STRONG&gt; installed&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Current EPM Configuration&lt;/H3&gt;&lt;P&gt;At the moment we only have an &lt;STRONG&gt;Elevation Settings Policy&lt;/STRONG&gt; assigned with &lt;STRONG&gt;User Confirmed&lt;/STRONG&gt; enabled.&lt;/P&gt;&lt;P&gt;We currently do &lt;STRONG&gt;not&lt;/STRONG&gt; have any custom elevation rules, file hash rules, publisher rules or automatic elevations configured.&lt;/P&gt;&lt;P&gt;The issue appears in a configuration that is essentially limited to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EPM client installed&lt;/LI&gt;&lt;LI&gt;Elevation Settings Policy assigned&lt;/LI&gt;&lt;LI&gt;User Confirmed elevation workflow enabled&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is one of the reasons why we are unsure whether the behavior is directly related to an EPM policy configuration or to an interaction between:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EPM agent&lt;/LI&gt;&lt;LI&gt;Windows Terminal / OpenConsole&lt;/LI&gt;&lt;LI&gt;VS Code&lt;/LI&gt;&lt;LI&gt;WSL&lt;/LI&gt;&lt;LI&gt;Admin By Request&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Questions&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Has anyone experienced random CMD / PowerShell / OpenConsole windows after introducing EPM?&lt;/LI&gt;&lt;LI&gt;Has anyone seen issues between EPM and:&lt;UL&gt;&lt;LI&gt;Windows Terminal&lt;/LI&gt;&lt;LI&gt;OpenConsole.exe&lt;/LI&gt;&lt;LI&gt;VS Code terminal&lt;/LI&gt;&lt;LI&gt;WSL&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Has anyone run &lt;STRONG&gt;Admin By Request&lt;/STRONG&gt; and &lt;STRONG&gt;Microsoft EPM&lt;/STRONG&gt; on the same device and observed unexpected console windows?&lt;/LI&gt;&lt;LI&gt;Are there any EPM-specific logs that provide detailed parent/child process relationships for these launches?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any ideas or similar experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 08:35:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/microsoft-epm-random-cmd-powershell-openconsole-popups/m-p/4538823#M23617</guid>
      <dc:creator>silasst</dc:creator>
      <dc:date>2026-07-20T08:35:45Z</dc:date>
    </item>
    <item>
      <title>Is it possible to automate Minimum Windows OS version compliance policy?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/is-it-possible-to-automate-minimum-windows-os-version-compliance/m-p/4538058#M23602</link>
      <description>&lt;P&gt;Is it possible to set a Windows compliance policy for Minimum OS Version that automatically updates each month and marks the device noncompliant after 14 days?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This would work if we normally allow users 2 weeks after Patch Tuesday to get their device updated. We would like to avoid having to have someone remember to manually edit the compliance policy every month to update the minimum build number in the policy.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 06:17:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/is-it-possible-to-automate-minimum-windows-os-version-compliance/m-p/4538058#M23602</guid>
      <dc:creator>Modechristo_13</dc:creator>
      <dc:date>2026-07-17T06:17:56Z</dc:date>
    </item>
    <item>
      <title>Android Fully Managed devices treated as personal after AD password change</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/android-fully-managed-devices-treated-as-personal-after-ad/m-p/4536270#M23591</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We have a huge problem...&lt;/P&gt;&lt;P&gt;We have recently observed an issue in our organization affecting Android Fully Managed devices.&lt;/P&gt;&lt;P&gt;After users change their domain password, within 1–3 days Conditional Access starts blocking access to Outlook and Teams. The system appears to treat the device as non-corporate, even though in Intune the device is still present, marked as corporate, and fully functional. It synchronizes both manually and automatically, and remote actions can be executed without any issues.&lt;/P&gt;&lt;P&gt;However, when users open Outlook or Teams, they receive messages such as “We need to secure your device” and “Install the Intune app from Google Play,” which does not make sense because Intune is already installed on the device.&lt;/P&gt;&lt;P&gt;When opening the Intune app, users see a “Update your password” prompt. After selecting it, they are redirected to a device registration screen.&lt;/P&gt;&lt;P&gt;Previously, it was sometimes possible to complete this process (although we did not understand why it was required), but recently re-registration consistently fails. The user clicks “Register,” and the process spins indefinitely without completing.&lt;/P&gt;&lt;P&gt;This issue is very difficult to troubleshoot. Device logs are not particularly helpful, and all users have Microsoft Authenticator configured. The problem appears randomly across users with no clear pattern—some devices were enrolled over a year ago, others just a month ago.&lt;/P&gt;&lt;P&gt;The only clue we have found so far points to a potential issue with the broker authentication token, but we do not know how to verify or resolve this, nor why it is happening in the first place.&lt;/P&gt;&lt;P&gt;We have been experiencing this issue since around January this year, but we noticed a significant increase in cases this month. In addition, there are more and more devices that can no longer be re‑registered from within the Intune app.&lt;/P&gt;&lt;P&gt;Has anyone encountered a similar issue or can provide guidance on how to investigate or fix this?&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2026 17:39:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/android-fully-managed-devices-treated-as-personal-after-ad/m-p/4536270#M23591</guid>
      <dc:creator>dammas</dc:creator>
      <dc:date>2026-07-12T17:39:36Z</dc:date>
    </item>
    <item>
      <title>Configuration Manager manifest synchronization failing since 8 July 2026</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager/configuration-manager-manifest-synchronization-failing-since-8/m-p/4535722#M389</link>
      <description>&lt;P&gt;Has anyone else experienced Configuration Manager Updates and Servicing synchronization failures since 8 July 2026?&lt;/P&gt;&lt;P&gt;We have three independent Microsoft Configuration Manager hierarchies:&lt;/P&gt;&lt;P&gt;Test environment&lt;/P&gt;&lt;P&gt;Production T0 environment&lt;/P&gt;&lt;P&gt;Production T1 environment&lt;/P&gt;&lt;P&gt;All three started showing the same SMS_DMP_DOWNLOADER error during the last three days.&lt;/P&gt;&lt;P&gt;The affected request is sent to:&lt;/P&gt;&lt;P&gt;https://sccm.manage.microsoft.com/SCCMConnectedService.svc/Manifest&lt;/P&gt;&lt;P&gt;Configuration Manager builds a hierarchy-specific request containing the Tenant, Version, Ring, and Branch parameters. However, the endpoint now returns only:&lt;/P&gt;&lt;P&gt;OK&lt;/P&gt;&lt;P&gt;The resulting file is:&lt;/P&gt;&lt;P&gt;ConfigMgr.Update.Manifest.cab Size: 2 bytes Hex: 4F 4B Content: OK&lt;/P&gt;&lt;P&gt;Because this is not a valid signed CAB file, dmpdownloader.log records:&lt;/P&gt;&lt;P&gt;manifest.cab (http response) size is 2 Error in verifying the trust of file ConfigMgr.Update.Manifest.cab' WARNING: Failed to call IsFileTrusted WARNING: Failed to download and verify the manifest.cab. We cant get info in Updates and Servicing mode.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 12:28:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager/configuration-manager-manifest-synchronization-failing-since-8/m-p/4535722#M389</guid>
      <dc:creator>rajha1750</dc:creator>
      <dc:date>2026-07-10T12:28:01Z</dc:date>
    </item>
    <item>
      <title>Build a patch strategy for today’s threat pace with Microsoft</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/build-a-patch-strategy-for-today-s-threat-pace-with-microsoft/ba-p/4535115</link>
      <description>&lt;P&gt;AI-accelerated vulnerability discovery and remediation are changing how organizations manage risk. As discussed in Pavan Davuluri’s recent &lt;A class="lia-external-url" href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery" target="_blank" rel="noopener"&gt;blog&lt;/A&gt;,&lt;STRONG&gt; &lt;/STRONG&gt;Microsoft is investing across the vulnerability lifecycle to help organizations identify, validate, and respond faster.&lt;/P&gt;
&lt;P&gt;For IT and security teams, one challenge lies downstream: deploying fixes quickly across endpoints to reduce exposure. Each update needs to be evaluated, piloted, monitored, and enforced across a mixed fleet of devices and apps. Some parts of the estate can move quickly; others cannot because of compliance requirements, approved change windows, and business-critical dependencies.&lt;/P&gt;
&lt;P&gt;As organizations adopt AI tools and agents across their environment, maintaining a current and hardened endpoint estate becomes increasingly important. In this context, patching becomes an ongoing operational discipline that combines OS, app, and driver updates with compliance enforcement, access control, and security baseline hardening.&lt;/P&gt;
&lt;P&gt;To keep pace, organizations need a patch strategy that helps in 3 stages:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Mitigate&lt;/STRONG&gt;: automate updates that can move quickly&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess&lt;/STRONG&gt;: prioritize risk based on exposure and severity&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Contain&lt;/STRONG&gt;: enforce compliance and limit exposure&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Operationalizing a patch strategy requires coordinated capabilities across endpoint management and security tools. Microsoft Intune brings these capabilities together in a single admin center, alongside the broader Microsoft security ecosystem, and is available with qualifying Microsoft 365 subscriptions&lt;SUP&gt;1&lt;/SUP&gt;.&lt;/P&gt;
&lt;P&gt;In this post, we show how organizations can use these capabilities to build a patch strategy that helps reduce the time between update release and deployment across their endpoint estate.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;1. &lt;/STRONG&gt;&lt;STRONG&gt;Mitigate:&lt;/STRONG&gt; automate updates that can move quickly&lt;/H3&gt;
&lt;P&gt;A patch strategy is not about pushing every update everywhere at once. It’s about identifying the parts of your estate that can move quickly, then using automation, rings, monitoring, and enforcement to help those updates move with confidence. Regulations, approved change windows, validation needs, and business dependencies will shape what’s possible, but the strategy starts by separating repeatable update work from the exceptions that need deeper review.&lt;/P&gt;
&lt;P&gt;For OS, app, and driver updates that can move quickly, modern tools can help shorten the time between update release and deployment; without manual rollouts, ticket-driven packaging, or reboot disruption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-groups-policies" target="_blank" rel="noopener"&gt;Windows Autopatch&lt;/A&gt; orchestrates ring-based update rollouts to reduce manual effort and keep Windows devices current. To help monitor risk, the Autopatch report visualizes how quickly devices apply updates based on the configured deployment cadence. In this report, devices are categorized as current within three days of update release, at risk between three and seven days, and at critical risk beyond seven days, based on the reporting model used by Windows Autopatch. Learn more about &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-groups-policies" target="_blank" rel="noopener"&gt;ring-based rollout updates&lt;/A&gt; or how to &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/protect-your-estate-reassess-your-windows-update-policies/4515228" target="_blank" rel="noopener" data-lia-auto-title="reassess Windows OS updates" data-lia-auto-title-active="0"&gt;reassess Windows OS updates&lt;/A&gt; using this report.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank" rel="noopener"&gt;Hotpatch&lt;/A&gt; (enabled by default for 24H2+ in Intune) applies critical updates without requiring a reboot, helping reduce security gaps while keeping users productive.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=QdjSkbKXoJw/1783549162389" data-video-remote-vid="https://www.youtube.com/watch?v=QdjSkbKXoJw/1783549162389" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FQdjSkbKXoJw%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DQdjSkbKXoJw&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FQdjSkbKXoJw%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Watch the latest Microsoft Mechanics episode to see how Windows Autopatch and Hotpatch help organizations accelerate update deployment, reduce operational overhead, and keep devices secure.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Intune Enterprise App Management&lt;/A&gt; (EAM) supports keeping Windows apps current through auto-updates, including the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/update-enterprise-supersedence" target="_blank" rel="noopener"&gt;guided upgrade supersedence&lt;/A&gt; reporting, which surfaces outdated versions or version changes. EAM auto-updates are now generally available; details are included in the &lt;A class="lia-external-url" href="http://aka.ms/IntuneWN2606" target="_blank" rel="noopener"&gt;June Intune What’s new blog&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=iI-sJ6kz_vg/1783549052628" data-video-remote-vid="https://www.youtube.com/watch?v=iI-sJ6kz_vg/1783549052628" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FiI-sJ6kz_vg%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DiI-sJ6kz_vg&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FiI-sJ6kz_vg%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 2: Watch how Intune helps you move from update release to deployment to accelerate responses to vulnerabilities with Windows app management.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enhanced-app-inventory" target="_blank" rel="noopener"&gt;The enhanced application inventory&lt;/A&gt; in the All apps page shows the app version installed on each managed Windows device, refreshed multiple times per day on most active devices, helping teams target app-specific vulnerabilities and confirming when fixes have been applied.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;The Vulnerability Remediation Agent&lt;/A&gt; in Security Copilot uses data from Defender Vulnerability Management to prioritize Common Vulnerabilities and Exposures (CVEs) across Intune-managed Windows devices and apps, and provides recommended remediation actions within Intune. The Vulnerability Remediation Agent is&lt;STRONG&gt; &lt;/STRONG&gt;currently in public preview, &lt;A class="lia-external-url" href="http://aka.ms/Intune/VRA-blog" target="_blank" rel="noopener"&gt;read the blog to learn more&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=-xhy3yXGVGM/1783549191510" data-video-remote-vid="https://www.youtube.com/watch?v=-xhy3yXGVGM/1783549191510" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-xhy3yXGVGM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-xhy3yXGVGM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-xhy3yXGVGM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 3: Watch this video to see how the Vulnerability Remediation Agent in Security Copilot, within Microsoft Intune, helps make agentic security easier to adopt and use.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Apple devices&lt;/STRONG&gt; can be configured for &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/apple/planning-guide-macos" target="_blank" rel="noopener"&gt;automatic OS updates on managed devices&lt;/A&gt;, including enforcing updates to the latest version and deploying Background Security Improvement patches through the settings catalog. App updates can be managed by configuring &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/manage-vpp-apple" target="_blank" rel="noopener"&gt;volume-purchased App Store apps&lt;/A&gt; to update automatically and &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-dmg-macos" target="_blank" rel="noopener"&gt;deploy updated app packages&lt;/A&gt; to keep apps current across macOS, iPhone, and iPad devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Android devices&lt;/STRONG&gt; can be managed using &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/planning-guide" target="_blank" rel="noopener"&gt;built-in update policies in Intune&lt;/A&gt;, including configuring install windows and freeze periods. For corporate Android fleets, Intune also integrates with OEM firmware management solutions - including&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/setup-zebra-lifeguard" target="_blank" rel="noopener"&gt;Zebra LifeGuard Over-the-Air&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/manage-fota" target="_blank" rel="noopener"&gt;Samsung E-FOTA&lt;/A&gt; - to enable more granular update control. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-managed-google-play" target="_blank" rel="noopener"&gt;Managed Google Play also supports configurable app auto-update modes&lt;/A&gt;, allowing admins to define whether updates install automatically, on Wi-Fi only, or manually.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;2. &lt;/STRONG&gt;&lt;STRONG&gt;Assess: &lt;/STRONG&gt;prioritize risk based on exposure and severity&lt;/H3&gt;
&lt;P&gt;The first step is reducing exposure across the parts of your estate that can move quickly. But not every system, application, or vulnerability can be addressed through broad update deployment. Teams also need a way to determine which risks require immediate action and which ones can be addressed over time.&lt;/P&gt;
&lt;P class=""&gt;A calendar-based approach can treat every CVE equally. However, it doesn’t account for severity, exposure, or business impact. As AI accelerates vulnerability discovery, this can lead to effort being spent on lower-risk updates while higher-risk updates remain unaddressed.&lt;/P&gt;
&lt;P&gt;Risk-based service level objectives (SLOs) help bring prioritization to address this challenge. Instead of patching on a fixed schedule, IT and security teams can align response timeframes by severity, moving quickly on actively exploited or critical vulnerabilities, and applying a more measured approach where risk or impact is lower.&lt;/P&gt;
&lt;P&gt;This stage creates a clearer prioritization of remediation and helps bridge the view between the security teams that identify threats and the IT teams that act on them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune and Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;A class="lia-external-url" href="https://aka.ms/Intune" target="_blank" rel="noopener"&gt;security update status dashboard in Intune&lt;/A&gt; provides an aggregated view of update compliance across Windows clients, Windows servers, and Microsoft 365 Apps. It shows overall counts of devices in different states across Intune-endpoints and helps teams identify where remediation should be focused. These status categories reflect how quickly devices apply updates based on a configured deployment cadence and internal SLOs.&lt;BR /&gt;&lt;BR /&gt;&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 4: Security update dashboard showing patch status for Windows clients, servers, and Microsoft 365 apps.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-vulnerability-management/defender-vulnerability-management" target="_blank" rel="noopener"&gt;Microsoft Defender Vulnerability Management&lt;/A&gt; surfaces CVEs, affected devices, vulnerable software, and recommended remediation actions, offering a shared view of risk and progress across IT and security teams.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Translate Defender recommendations into targeted Intune actions described in the mitigate section, such as updating software or moving devices through expedited remediation workflows so teams can focus on vulnerabilities that are actively exploited or most likely to affect an organization.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;For Apple devices&lt;/STRONG&gt;, use the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/apple/monitor-reports" target="_blank" rel="noopener"&gt;Apple software update report&lt;/A&gt; in Intune to monitor update status across macOS, iOS, and iPadOS.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;For Android, &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/monitor-policy" target="_blank" rel="noopener"&gt;compliance reporting&lt;/A&gt; surfaces devices that fall behind on OS version or security patch level.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;3. &lt;/STRONG&gt;&lt;STRONG&gt;Contain&lt;/STRONG&gt;: enforce patch compliance and limit exposure&lt;/H3&gt;
&lt;P&gt;Even with automated deployments and prioritized triage, gaps can remain. Some devices are unsupported, fall behind, operate on slower deployment rings, and others can’t be patched quickly. A patch strategy needs to focus on including containment for those surfaces.&lt;/P&gt;
&lt;P&gt;Compliance controls, conditional access, and device hardening act as an always-on safety net that limits risks that can fall through gaps. Compliance policies and Conditional Access can use a patch state as a signal for resource access, preventing non-compliant devices from accessing corporate resources. Security baselines reduce the attack surface by limiting risky defaults and common attack patterns. Together, these controls shift enforcement from a periodic activity to a continuous condition across a fleet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune and Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/overview" target="_blank" rel="noopener"&gt;compliance policies&lt;/A&gt; in Intune to define what "current" means, including minimum OS build, required update levels, risk status, and encryption state.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/conditional-access-integration/overview" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; (managed in Microsoft Entra, accessible from the Intune admin center) to control access to company resources based on user and device health. Combined with threat signals from Microsoft Defender, these policies help prevent non-compliant devices from accessing corporate resources.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use Microsoft Defender Vulnerability Management and &lt;A class="lia-external-url" href="https://learn.microsoft.com/security-exposure-management/microsoft-security-exposure-management" target="_blank" rel="noopener"&gt;Microsoft Security Exposure Management&lt;/A&gt; insights to identify exposed assets, prioritize remediation, and apply recommended protections where patching must move more slowly.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Apply Intune &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/security-baselines/overview" target="_blank" rel="noopener"&gt;security baselines&lt;/A&gt; to establish Microsoft-recommended configurations on Windows devices, such as disabling risky defaults, blocking common attack techniques, and reducing configuration drift. Watch this &lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=V-QBO2cJn4E" target="_blank" rel="noopener"&gt;demo on security baselines&lt;/A&gt; being applied in the &lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;Zero Trust workshop&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/attack-surface-reduction" target="_blank" rel="noopener"&gt;attack surface reduction policies in Intune&lt;/A&gt; to deploy Microsoft Defender for Endpoint protections, such as ASR rules and network protection, that help block common attack techniques on devices that can't be patched right away.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=9TFhIRHma1E&amp;amp;t/1783554817508" data-video-remote-vid="https://www.youtube.com/watch?v=9TFhIRHma1E&amp;amp;t/1783554817508" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F9TFhIRHma1E%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D9TFhIRHma1E&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F9TFhIRHma1E%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 5: Watch this Demo on how you can manage devices and implement Conditional Access with Intune.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Compliance policies and Conditional Access controls apply across Windows, macOS, iOS/iPadOS, and Android.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Intune &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/protection/overview" target="_blank" rel="noopener"&gt;app protection policies&lt;/A&gt; extend compliance requirements and data protections to managed apps used for work on personal devices and add an additional layer of data protection on corporate devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog" target="_blank" rel="noopener"&gt;settings catalog&lt;/A&gt; and configuration profiles to apply the same hardening intent on macOS, iOS/iPadOS, and Android, reducing configuration drift across platforms.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Stay ahead with a patch strategy&lt;/H3&gt;
&lt;P&gt;As vulnerability discovery and response continue to accelerate, organizations need an operational strategy that balances speed, risk, and resilience. By automating updates where possible, prioritizing remediation based on exposure, and limiting exposure through compliance and security controls, teams can reduce risk across their endpoint estate.&lt;/P&gt;
&lt;P&gt;Intune helps simplify this approach by bringing these capabilities together alongside the rest of your Microsoft security tools and ecosystem.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://security.microsoft.com/securenow" target="_blank" rel="noopener"&gt;Get started with Microsoft Secure Now&lt;/A&gt; to assess risk across your digital estate.&lt;/LI&gt;
&lt;LI&gt;Explore the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is-foundational-to-/4513766" target="_blank" rel="noopener" data-lia-auto-title="new security update status dashboard" data-lia-auto-title-active="0"&gt;new security update status dashboard&lt;/A&gt; in Intune.&lt;/LI&gt;
&lt;LI&gt;Harden the admin plane and review the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noopener" data-lia-auto-title="best practices for securing Microsoft Intune" data-lia-auto-title-active="0"&gt;best practices for securing Microsoft Intune&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR style="border: 0; border-top: 1px solid #e5e5e5; margin: 32px 0 20px 0;" /&gt;
&lt;DIV style="font-size: 13px; line-height: 1.6; color: #666666;"&gt;
&lt;P&gt;&lt;SUP&gt;1&lt;/SUP&gt; &lt;STRONG&gt;Licensing and requirements&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Feature availability and included capabilities vary by Microsoft 365 subscription plan and feature. Some Microsoft capabilities referenced in this post may require specific licenses or additional enablement.&lt;/P&gt;
&lt;P&gt;Advanced Microsoft Intune capabilities are now included &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5/4529335" target="_blank" rel="noopener" data-lia-auto-title="in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3" data-lia-auto-title-active="0"&gt;in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3&lt;/A&gt; as part of updates effective July 1, 2026. Existing customers will receive a 30-day notice in the Microsoft Admin Center prior to availability, with access beginning by August 2026.&lt;/P&gt;
&lt;P&gt;Microsoft Security Copilot and related AI capabilities may require separate licensing, &lt;A class="lia-external-url" href="https://aka.ms/SecurityCopilotPricing" target="_blank" rel="noopener"&gt;learn more here&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;/EM&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt;&lt;EM&gt; and follow us on LinkedIn or&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 17:18:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/build-a-patch-strategy-for-today-s-threat-pace-with-microsoft/ba-p/4535115</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-10T17:18:27Z</dc:date>
    </item>
    <item>
      <title>Autopatch for quality updates and WUFB for feature updates</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-for-quality-updates-and-wufb-for-feature-updates/m-p/4535259#M23586</link>
      <description>&lt;P&gt;We have switched to Autopatch for quality updates in our environment, but now is the time for feature update deployments. In the past we had used Windows Updates for Business for feature update without any problem. We would like to deploy the feature updates and retain the control of the target groups through the process, which are different ones from the quality updates. As the content is much bigger, we would like to test to specific users, after communicating to them for the procedure, and also be sure that the availability and the bandwidth will be adequate specially now during summer holidays. Could we still use WUfB only for the feature deployment along with Autopatch, without intervening to the normal monthly update cycle?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 09:00:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-for-quality-updates-and-wufb-for-feature-updates/m-p/4535259#M23586</guid>
      <dc:creator>demion</dc:creator>
      <dc:date>2026-07-09T09:00:56Z</dc:date>
    </item>
    <item>
      <title>Cannot delete a website shortcut by Intune managed iphone</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-delete-a-website-shortcut-by-intune-managed-iphone/m-p/4534924#M23581</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;We manually created a shortcut to a website from Safari browser and the shortcut is on the Intune managed iPhone. We don't need the shortcut now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However we cannot delete it. Press and hold apps on this phone does not start wiggle mode and we cannot drag the shortcut onto a new home screen. We also cannot see it in the Apps list in Intune to delete either because it was manually added on that specific iPhone. Can you tell me if there is a away to delete the shortcuts please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 12:16:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-delete-a-website-shortcut-by-intune-managed-iphone/m-p/4534924#M23581</guid>
      <dc:creator>rredford</dc:creator>
      <dc:date>2026-07-08T12:16:14Z</dc:date>
    </item>
    <item>
      <title>Automatically Sync SharePoint Document Libraries on macOS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/automatically-sync-sharepoint-document-libraries-on-macos/m-p/4534130#M23569</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We manage macOS devices with Microsoft Intune and need to automatically sync one or more SharePoint document libraries to users' OneDrive, similar to how it's done on Windows using the Intune auto-sync policy.&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented this on macOS using Intune, Jamf Pro, configuration profiles, or a supported script?&lt;/P&gt;&lt;P&gt;We're looking for a Microsoft-supported solution that minimizes or eliminates user interaction.&lt;/P&gt;&lt;P&gt;Any guidance or recommendations would be greatly appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 13:01:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/automatically-sync-sharepoint-document-libraries-on-macos/m-p/4534130#M23569</guid>
      <dc:creator>ynarvil</dc:creator>
      <dc:date>2026-07-06T13:01:11Z</dc:date>
    </item>
    <item>
      <title>Migrating frontline mobile devices: Identity considerations for assigned and shared devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/migrating-frontline-mobile-devices-identity-considerations-for/ba-p/4532671</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Carol Burns - Principal Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Practitioner perspective from Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune), with deep experience in secure frontline mobility, including regulated healthcare environments.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In previous articles in this series, we focused on &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/migrating-frontline-mobile-devices-understanding-the-reality-of-your-estate/4511683" target="_blank" rel="noopener" data-lia-auto-title="understanding the reality of your frontline device estate" data-lia-auto-title-active="0"&gt;understanding the reality of your frontline device estate&lt;/A&gt; and preparing for real-world testing through &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/migrating-frontline-mobile-devices-aligning-stakeholders-before-real-world-testi/4516511" target="_blank" rel="noopener" data-lia-auto-title="stakeholder alignment" data-lia-auto-title-active="0"&gt;stakeholder alignment&lt;/A&gt;. One of the most critical areas to get right during the testing phase is identity and security, particularly given the often fast-paced, shift-based nature of frontline work, where organizations must account for the distinct requirements and challenges of devices assigned to a single individual versus devices shared across multiple users or shifts.&lt;/P&gt;
&lt;P&gt;Identity decisions directly affect security posture, sign‑in experience, operational support overhead, and worker productivity. Getting them wrong is one of the most common reasons pilots stall or fail.&lt;/P&gt;
&lt;P&gt;This article explores how to think about identity on frontline devices by distinguishing between assigned and shared usage models, clarifying when individual sign-in is required, and highlighting patterns to avoid such as shared accounts and passwords.&lt;/P&gt;
&lt;H2&gt;Start by distinguishing device usage models&lt;/H2&gt;
&lt;P&gt;Frontline mobile devices generally fall into one of two broad categories.&lt;/P&gt;
&lt;H3&gt;Assigned devices&lt;/H3&gt;
&lt;P&gt;Assigned devices are issued to a specific individual, often for the duration of their role. These devices:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Typically require persistent access to user‑specific data&lt;/LI&gt;
&lt;LI&gt;Align with user‑based identity, Microsoft Entra ID Conditional Access, and audit controls.&lt;/LI&gt;
&lt;LI&gt;Enable greater accountability and traceability by associating activity with an individual user rather than a shared credential.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Common examples include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A doctor using an individually assigned clinical tablet, where uninterrupted access to patient data and clinical systems is essential and actions must always be attributable to a named identity&lt;/LI&gt;
&lt;LI&gt;A field engineer assigned a single device that retains configuration, credentials, and offline content across jobs and locations&lt;/LI&gt;
&lt;LI&gt;An inspector or supervisor using an assigned device for approvals, reporting, and decision‑making that requires traceability&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Shared devices&lt;/H3&gt;
&lt;P&gt;Shared devices are used by multiple people across shifts or tasks. These scenarios introduce additional identity complexity and generally fall into two distinct models.&lt;/P&gt;
&lt;H3&gt;Shared devices without user sign-in (task or kiosk-based)&lt;/H3&gt;
&lt;P&gt;Some frontline devices exist to perform a narrow, often repetitive task and don’t require sign in with a user account.&lt;/P&gt;
&lt;P&gt;Typical examples include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Retail price-check devices used on the shop floor to scan an item and display its current price or stock availability, with no need for access to personal or user-specific information&lt;/LI&gt;
&lt;LI&gt;Environmental monitoring devices used to read and record temperature or humidity in a storage area, ward, or vehicle, where the task is simple, repetitive, and not tied to an individual user identity&lt;/LI&gt;
&lt;LI&gt;Warehouse or facility scanning devices used for a narrow operational task such as scanning an asset, bin, or location code to confirm status, location, or completion of a step in a process&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In these cases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices are locked down to a specific task&lt;/LI&gt;
&lt;LI&gt;No user-specific data is stored, and access is limited to the minimum required for the task&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;“When a device is truly task-only, removing sign-in friction is a huge win, but only if we’re aware what data the device can access. When things like patient context or personalized tasks enter the picture, identity becomes required” - &lt;EM&gt;Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Shared devices with individual user sign-in&lt;/H3&gt;
&lt;P&gt;Organizations are increasingly digitizing and modernizing frontline workflows end-to-end. Paper processes and simple apps give way to connected systems, manual handovers are replaced with digital task lists, and workers begin to rely on mobile devices as their primary interface from completing tasks.&lt;/P&gt;
&lt;P&gt;As roles evolve, workers are expected to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Receive tasks, schedules, and updates digitally&lt;/LI&gt;
&lt;LI&gt;Communicate with supervisors and peers using collaboration tools such as Microsoft Teams&lt;/LI&gt;
&lt;LI&gt;Capture information at the point of work rather than transcribing later&lt;/LI&gt;
&lt;LI&gt;Interact with workflows that are increasingly automated or assisted by AI, such as guided steps, data validation, or suggested actions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This shift delivers clear productivity and quality benefits, but it also means access must now be tied to individual identity to protect sensitive data, support auditability, and prevent information from being carried over between users.&lt;/P&gt;
&lt;P&gt;Common scenarios include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Retail store associates rotating across shifts, moving from paper schedules and verbal handovers to digital task lists, real-time communications, and collaboration tools such as Microsoft Teams&lt;/LI&gt;
&lt;LI&gt;Nurses sharing mobile devices in a hospital ward, where paper notes and whiteboards are replaced with secure access to patient-linked applications, care coordination tools, and role-based alerts&lt;/LI&gt;
&lt;LI&gt;Logistics workers signing in to shared devices to complete role-based tasks, capture data at the point of work, and interact with AI-assisted workflows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Don’t use shared credentials, always prefer individual sign-in&lt;/H3&gt;
&lt;P&gt;Shared credentials may seem like a shortcut in frontline environments, but they undermine accountability and make policy enforcement and incident response significantly harder.&lt;/P&gt;
&lt;P&gt;“Shared credentials feel ‘efficient’ until your first incident. You lose auditability, Conditional Access becomes meaningless, and investigations turn into guesswork. Individual identity is the only scalable model.” &lt;EM&gt;-Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;If access involves corporate systems or sensitive data, each worker should use their individual credentials to sign in, even on a shared device.&lt;/P&gt;
&lt;H2&gt;Identity decision checklist for frontline devices&lt;/H2&gt;
&lt;P&gt;Use the checklist to validate identity choices and confirm that the overall security posture matches the way the device is used.&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Decision area&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Indicators&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Users access personal or role-specific data.&lt;/LI&gt;
&lt;LI&gt;Auditability or compliance is required.&lt;/LI&gt;
&lt;LI&gt;Conditional Access or multifactor authentication (MFA) must be enforced.&lt;/LI&gt;
&lt;LI&gt;Applications rely on user identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use kiosk-style or device-only identity&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Devices perform a single task.&lt;/LI&gt;
&lt;LI&gt;No user-specific or sensitive organizational data is accessed.&lt;/LI&gt;
&lt;LI&gt;Workflows are entirely device-centric.&lt;/LI&gt;
&lt;LI&gt;Speed and simplicity outweigh personalization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Avoid entirely&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Shared usernames or passwords.&lt;/LI&gt;
&lt;LI&gt;Reused local accounts across shifts.&lt;/LI&gt;
&lt;LI&gt;MFA exclusions that weaken security without compensating controls.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 35.00%" /&gt;&lt;col style="width: 65.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;Choosing the right sign‑in experience&lt;/H2&gt;
&lt;P&gt;The challenge in frontline environments is balancing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Security requirements&lt;/LI&gt;
&lt;LI&gt;Speed of access&lt;/LI&gt;
&lt;LI&gt;Ease of use across shifts&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;“Frontline setups may fail because the sign-in flow doesn’t match reality. If authentication takes 60 seconds and the worker has to do it 30 times a shift, they’ll find a workaround.”&lt;STRONG&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;-Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Typing complex usernames and passwords repeatedly during a shift is often impractical on mobile devices. QR code authentication is one effective option for shared frontline devices, but it’s not the only supported approach. For other supported methods, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/overview-authentication" target="_blank" rel="noopener"&gt;Microsoft Entra authentication methods overview.&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;QR code authentication&lt;/H3&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-qr-code" target="_blank" rel="noopener"&gt;Microsoft Entra QR code authentication&lt;/A&gt; is designed for frontline workers to sign-in efficiently on shared Android and iOS/iPadOS devices without repeatedly entering usernames and passwords.&lt;/P&gt;
&lt;DIV style="margin: 16px 0; padding: 14px 16px; border-left: 4px solid #0078d4; background: #f3f9fd; border-radius: 4px; color: #242424;"&gt;&lt;STRONG style="color: #005a9e;"&gt;Note:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN class="tooltip" tabindex="0"&gt;For individually assigned devices, phishing-resistant, passwordless authentication methods are the recommended approach, such as &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2" target="_blank" rel="noopener"&gt;Passkeys&lt;/A&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;QR code authentication enables workers to sign in using a unique QR code and a personal numeric PIN.&lt;/P&gt;
&lt;P&gt;This approach:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Eliminates typed usernames and passwords&lt;/LI&gt;
&lt;LI&gt;Preserves individual identity&lt;/LI&gt;
&lt;LI&gt;Works well for shared devices with frequent user turnover&lt;/LI&gt;
&lt;LI&gt;Integration with Microsoft Intune, Managed Home Screen and Conditional Access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;QR code authentication should always be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scoped to specific users and devices&lt;/LI&gt;
&lt;LI&gt;Combined with Conditional Access policies&lt;/LI&gt;
&lt;LI&gt;Evaluated during real‑world testing to ensure the right balance of usability and security&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Security posture and Conditional Access for frontline devices&lt;/H2&gt;
&lt;P&gt;Individual identity is a critical foundation for stronger security posture, but it’s not enough on its own. Frontline device security also depends on management, data and app protection, session handling, and access policies that reflect the actual usage model.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/conditional-access/overview" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; is an important part of securing frontline environments, but its effectiveness depends on aligning policies to the actual device and identity model in use.&lt;/P&gt;
&lt;P&gt;To ensure that the &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/concept-authentication-qr-code" target="_blank" rel="noopener"&gt;QR code authentication method&lt;/A&gt; can only be used by the frontline workers it’s intended for, &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/concept-authentication-strength-advanced-options" target="_blank" rel="noopener"&gt;create a custom authentication methods policy&lt;/A&gt;, which you can use in a dedicated Conditional Access policy. That Conditional Access policy should then be scoped to the group of users (frontline workers) who should log on using the QR code authentication method, and have the &lt;STRONG&gt;Require authentication strength&lt;/STRONG&gt; control configured, which targets the custom authentication strength for "QR Code" which was previously created.&lt;/P&gt;
&lt;P&gt;During real‑world testing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validate that design and controls support the intended usage model&lt;/LI&gt;
&lt;LI&gt;Ensure policies don’t block legitimate workflows&lt;/LI&gt;
&lt;LI&gt;Confirm sessions, access, and user targeting behave as expected&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These decisions should also be validated in practice: can users sign in and out reliably across shifts, is personal data cleared between sessions, and does the chosen experience match the pace of frontline work?&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;This article walks through how identity choices shape security, usability, and day-to-day success for frontline mobile devices. It explains the difference between assigned and shared devices, when individual sign-in is needed, and why shared credentials can create risk. It also highlights QR code authentication and Conditional Access as practical ways to keep each worker’s identity protected while making sign-in simple enough for fast-paced frontline workflows.&lt;/P&gt;
&lt;H2&gt;What’s next in the series&lt;/H2&gt;
&lt;P&gt;In the next article, we’ll focus on Microsoft Intune enrollment models, exploring how different enrollment approaches support—or constrain—the identity and usage patterns discussed here, including their role in protecting session identity, enforcing the intended sign-in model, and preventing one user’s access or data from carrying over to the next.&lt;/P&gt;
&lt;P&gt;As always, we welcome your feedback and experience. If you’ve navigated identity decisions for shared or frontline devices, share your advice and lessons learned in the comments, &amp;nbsp;or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For more guidance across frontline scenarios, explore our broader &lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-the-frontlines-frontline-worker-management-with-microsoft-intune/4387449" target="_blank" rel="noopener"&gt;&lt;EM&gt;From the Frontlines&lt;/EM&gt;&lt;/A&gt; series on frontline worker management with Microsoft Intune.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 18:00:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/migrating-frontline-mobile-devices-identity-considerations-for/ba-p/4532671</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-01T18:00:50Z</dc:date>
    </item>
  </channel>
</rss>

