<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ct-p/microsoftintune</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Fri, 19 Jun 2026 01:35:28 GMT</pubDate>
    <dc:creator>microsoftintune</dc:creator>
    <dc:date>2026-06-19T01:35:28Z</dc:date>
    <item>
      <title>Our MacOS Platform SSO deployment</title>
      <link>https://techcommunity.microsoft.com/t5/device-management-in-microsoft/our-macos-platform-sso-deployment/ba-p/4529316</link>
      <description>&lt;P&gt;Naveen Kumar Akkugari wrote up a blog post on how we deployed an early version of the Platform SSO for MacOS devices.&amp;nbsp; We decided to try something a little different in the blog-o-sphere so it was posted up at &lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/deploying-platform-sso-for-pre-macos-26-with-microsoft-intune-lessons-learned/4521368" target="_blank"&gt;Deploying Platform SSO for pre macOS 26 with Microsoft Intune: Lessons Learned | Microsoft Community Hub&lt;/A&gt; instead of here.&amp;nbsp; Go take a read and see if it is interesting to you.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 19:23:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/device-management-in-microsoft/our-macos-platform-sso-deployment/ba-p/4529316</guid>
      <dc:creator>MikeGriz</dc:creator>
      <dc:date>2026-06-18T19:23:08Z</dc:date>
    </item>
    <item>
      <title>Deploying Platform SSO for pre macOS 26 with Microsoft Intune: Lessons Learned</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/deploying-platform-sso-for-pre-macos-26-with-microsoft-intune/ba-p/4521368</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Naveen Akkugari, Sr. Service Engineer and Michael Griswold, Principal Service Engineering Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Who we are&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Our internal Intune administration team at Microsoft is responsible for running Intune and Configuration Manager for the devices used by employees. We &lt;STRONG&gt;receive&lt;/STRONG&gt; early access to features for evaluation and feedback using real world usage scenarios. As such, some features may be changed before the public release and be slightly different. The experience should be similar and&lt;STRONG&gt; &lt;/STRONG&gt;we wanted to share our learnings when deploying platform single sign-on (PSSO). It is worth noting that since the time of this experience a new method for newer OS versions is available and you can read more about it at:&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-platform-sso-with-registration-during-automated-device-enrollment-on-macos/4519846" target="_blank" rel="noopener" data-lia-auto-title="New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Why we implemented Platform single sign-on (PSSO) and what we learned&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;As IT admins managing a growing Mac fleet, we kept running into the same gap. Our Windows devices had hardware-backed authentication, token protection, and seamless SSO through Windows Hello for Business, but our Macs were still relying on browser-based prompts with no easy way to enforce the same level of security and identity protection. Platform SSO finally closed that gap for us. It’s worth noting that new macOS allows new capabilities in this space and we are evaluating them as well. The new flow can be read about at &lt;A class="lia-external-url" href="https://aka.ms/Intune/MacPSSO-Setup" target="_blank" rel="noopener"&gt;https://aka.ms/Intune/MacPSSO-Setup&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;While there were fewer pip-ups, we found the changes in the security layer to be the real value to our operations. Platform SSO binds authentication tokens (Primary Refresh Tokens) to the device’s Secure Enclave hardware. Even if a PRT is intercepted, it’s &lt;STRONG&gt;designed to not be replayed from another device&lt;/STRONG&gt;. For our team, this unlocked two things we couldn’t do on macOS before:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Token protection policies:&lt;/STRONG&gt; Conditional Access can now verify that tokens are device-bound, the same enforcement we had been relying on with Windows Hello for Business&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Phishing-resistant MFA:&lt;/STRONG&gt; Secure Enclave keys act as FIDO2 passkeys, so users authenticate with Touch ID instead of passwords or SMS codes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Getting from documentation to production took real effort for us. A password policy issue that silently blocked registration for half our pilot group, users who swiped away the registration banner without knowing what it was, and macOS updates that broke SSO overnight. This blog post is what we wish someone had written before we started.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it works under the hood: &lt;/STRONG&gt;Intune delivers the SSO extension profile → macOS prompts the user to register → the device registers with Microsoft Entra ID and gets a hardware-bound workplace (WPJ) certificate → a PRT is issued and bound to device hardware (not designed to be exported) → SSO works across Microsoft 365 apps, browsers, and Kerberos resources, all with token protection enforced.&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Available authentication methods when we implemented&lt;/STRONG&gt;&lt;/H1&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Capability&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Secure Enclave&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Smart Card&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Password Sync&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Passwordless and phishing-resistant&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Touch ID / passkey (WebAuthn)&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌ &lt;SPAN style="color: #666;"&gt;Touch ID only&lt;/SPAN&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Local password synced with Microsoft Entra&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Minimum macOS&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;13.0&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;14.0&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;13.0&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Recommendation: Start with Secure Enclave. &lt;/STRONG&gt;Keys are hardware-bound, phishing-resistant, and double as FIDO2 passkeys via WebAuthn, enabling browser-based passwordless login (Touch ID instead of passwords) and meeting Conditional Access multi-factor authentication (MFA) requirements. Unlike iCloud-synced passkeys, these are &lt;STRONG&gt;device-bound&lt;/STRONG&gt;, aligning with Zero Trust.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;Quick setup using the Intune settings catalog&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Prerequisites: &lt;/STRONG&gt;macOS 13+, Intune with Microsoft Entra ID, Intune Company Portal v5.2404.0+&lt;/P&gt;
&lt;P&gt;In the Intune admin center, navigate to &lt;STRONG&gt;Devices &amp;gt; Configuration &amp;gt; Create &amp;gt; macOS &amp;gt; Settings Catalog &amp;gt; Authentication &amp;gt; Extensible SSO&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Setting&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Value&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Extension Identifier&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;com.microsoft.CompanyPortalMac.ssoextension&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Team Identifier&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;UBF8T346G9&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Type&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Redirect&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Registration Token&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;{{DEVICEREGISTRATION}}&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use Shared Device Keys&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Enabled&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Screen Locked Behavior&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;DoNotHandle&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;URLs&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;https://login.microsoftonline.com&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://login.microsoft.com&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://sts.windows.net&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://login-us.microsoftonline.com&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Users see a “Registration required” notification → sign in → complete MFA → SSO works everywhere.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;What the user experience looks like&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Knowing what users see on their screen helps you write better rollout communications and cuts down help desk tickets.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;First-time registration flow:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Profile arrives silently: &lt;/STRONG&gt;After enrollment, Intune pushes the SSO extension profile to the Mac. Nothing visible to the user yet.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Registration banner appears: &lt;/STRONG&gt;macOS displays a notification: “Registration required: Your organization requires you to register your device.” The user must click this to proceed. (This is our #1 learning point, users swipe it away, and there’s no simple way to retrigger it.)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Sign-in window: &lt;/STRONG&gt;The user enters their Microsoft Entra ID email and password.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; MFA challenge: &lt;/STRONG&gt;Authenticator app push, phone call, or other configured method.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Secure Enclave key creation: &lt;/STRONG&gt;macOS generates a hardware-bound key pair. The user may see a Touch ID or local password prompt to authorize this.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Registration completes: &lt;/STRONG&gt;Device registers with Microsoft Entra ID, a WPJ certificate and PRT are issued. User sees a success confirmation.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; SSO is active: &lt;/STRONG&gt;From here, Microsoft 365 apps, Edge (natively), Chrome (with SSO extension), and Kerberos resources authenticate without prompts. Touch ID replaces password entry.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Missed the registration notification? Here is how to manually register:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This was our most common help desk ticket during rollout. If a user dismissed or missed the banner, they can still register manually through the following options:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; (Recommended) System Settings → Users &amp;amp; Groups → Network Account Server: &lt;/STRONG&gt;This is the easiest method. Go to System Settings → Users &amp;amp; Groups, scroll down to “Network Account Server” and click “Edit.” This opens a panel showing two sections: Network Servers and Platform single sign-on. If the Platform SSO policy is deployed, “Mac SSO Extension” will be listed under Platform single sign-on. If the device isn’t registered, there will be a “Register” button that can be selected to start the Platform SSO device registration flow.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Lock / Sign out and back in:&lt;/STRONG&gt; Performing a lock or signing out of macOS followed by signing back in can retrigger the registration notification upon the next login attempt.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Wait for the notification to reappear: &lt;/STRONG&gt;macOS retries the notification periodically around every 15 mins.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Last resort, reprofile: &lt;/STRONG&gt;If none of the above work, an IT admin can remove and reassign the SSO extension profile in Intune. Before doing so, ensure any stale device objects are cleared from Microsoft Entra ID to avoid conflicts. Once the new profile lands on the device, the registration notification reappears.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;How to verify Platform SSO registration&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;One of the first questions we got after rollout was “how do I know it’s actually working?” Here’s how both users and IT admins can confirm.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For IT admins (Microsoft Entra ID &amp;amp; Intune admin centers):&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;What to check&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Platform SSO registered device&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Non-registered device&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Microsoft Entra ID → Devices&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Join Type shows &lt;STRONG&gt;Microsoft Entra joined&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Join Type shows &lt;STRONG&gt;Microsoft Entra registered&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune → Device configuration&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;SSO extension profile shows &lt;STRONG&gt;Succeeded&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Profile may show &lt;STRONG&gt;Pending&lt;/STRONG&gt;, &lt;STRONG&gt;Error&lt;/STRONG&gt;, or not assigned&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For users (on the Mac):&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; System Settings → Users &amp;amp; Groups → Network Account Server: &lt;/STRONG&gt;Scroll down in Users &amp;amp; Groups to “Network Account Server” and click “Edit.” If the Platform SSO policy is deployed, they will see “Mac SSO Extension” listed under Platform Single Sign-on. A registered device shows a green dot with “Registered” status and a “Repair” button (useful if registration gets into a bad state). If not registered, they will see a “Register” button instead. This is the quickest at-a-glance check for users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; System Settings → Users &amp;amp; Groups:&lt;/STRONG&gt; Click on the user account name in Users &amp;amp; Groups (on macOS 14+, click the info button “i” next to the user name). When Platform SSO registration is complete, a “Platform Single Sign-on” section will be listed under the account. If Platform SSO is active, the user account shows the Microsoft Entra ID identity linked to the local account.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Company Portal app → Devices: &lt;/STRONG&gt;The device should show as “Compliant” and “Microsoft Entra ID registered.” If registration failed, it shows “Registration required.”&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Terminal command: &lt;/STRONG&gt;Run app-sso platform -s to check Platform SSO status.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;Troubleshooting Platform SSO errors&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;If you run into issues during deployment, here’s how you can diagnose and fix issues.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Check the Platform SSO profile in Intune device management&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Before troubleshooting on the Mac itself, confirm the profile reached the device:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Intune: &lt;/STRONG&gt;Go to Devices → select the device → Device configuration. The SSO extension profile should show “Succeeded.” If it shows “Pending” or “Error,” the device hasn’t received the policy. Check assignment groups, sync status, and whether the device is enrolled.&lt;/P&gt;
&lt;P&gt;Then&amp;nbsp;&lt;STRONG&gt;on the Mac: &lt;/STRONG&gt;Go to System Settings → General → Device Management (or Profiles on older macOS). Look for the SSO extension profile (com.apple.extensiblesso). It should show as “Installed” with no errors. If the profile isn’t listed, it hasn’t been delivered yet. Check Intune assignment and device sync.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Check registration status on the Mac &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Refer to the &lt;STRONG&gt;previous section&lt;/STRONG&gt; &lt;STRONG&gt;“&lt;/STRONG&gt;How to &lt;STRONG&gt;verify &lt;/STRONG&gt;P&lt;STRONG&gt;latform &lt;/STRONG&gt;SSO &lt;STRONG&gt;registration” for steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Check SSO extension logs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Run in Terminal for real-time logs:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;log stream --predicate 'subsystem == "com.apple.AppSSO"' --level debug&lt;/LI-CODE&gt;
&lt;P&gt;Then prompt a sign-in (open Edge or Outlook). Look for:&lt;BR /&gt;&lt;STRONG&gt;Error 10002:&lt;/STRONG&gt; Duplicate SSO profiles. Remove the extra one from Intune.&lt;BR /&gt;&lt;STRONG&gt;Error 10003:&lt;/STRONG&gt; Registration failed. Usually a network issue or TLS inspection blocking auth URLs.&lt;BR /&gt;&lt;STRONG&gt;User cancelled:&lt;/STRONG&gt; User dismissed the registration banner.&lt;BR /&gt;&lt;STRONG&gt;Token refresh failed:&lt;/STRONG&gt; PRT could not refresh. Check network and whether the Microsoft Entra ID password was recently changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 4: Verify from the admin side&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Check&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;How&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;What It Tells You&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Profile delivery&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune &amp;gt; Devices &amp;gt; select device &amp;gt; Device configuration&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether the SSO profile reached the device and its install status&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Registration state&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Devices &amp;gt; search device &amp;gt; Properties&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether the device has PSSO registration and NGC credential&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Sign-in failures&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Sign-in logs &amp;gt; filter by user&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Error codes like &lt;CODE&gt;AADSTS50076&lt;/CODE&gt; MFA required, &lt;CODE&gt;AADSTS700024&lt;/CODE&gt; token issue, or &lt;CODE&gt;AADSTS7000218&lt;/CODE&gt; client assertion&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Token protection&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Sign-in logs &amp;gt; Conditional Access tab&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether token protection policy was applied or skipped&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Company Portal version&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune &amp;gt; Apps &amp;gt; macOS &amp;gt; Company Portal&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Must be &lt;STRONG&gt;v5.2404.0+&lt;/STRONG&gt; for PSSO; older versions silently fail&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Common error codes and fixes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 285px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7" style="height: 47.5px;"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Error&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Cause&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Fix&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;10002&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Multiple SSO extension profiles assigned&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Remove duplicate profiles; keep only the Settings Catalog policy&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;10003&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Registration failed network/TLS&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Allowlist Apple and Microsoft auth URLs from TLS inspection&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS50076&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;MFA required but not completed&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;User needs to complete MFA during registration&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS700024&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Client assertion invalid&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Password likely needs reset; have user reset Entra ID password and retry&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS7000218&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Request body must contain &lt;CODE&gt;client_assertion&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Company Portal version too old; update to &lt;STRONG&gt;v5.2404.0+&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Best practices&lt;/STRONG&gt;&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Have newer OS devices and use the new flow: &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-platform-sso-with-registration-during-automated-device-enrollment-on-macos/4519846" target="_blank" rel="noopener" data-lia-auto-title="New Platform SSO with registration during Automated Device Enrollment on macOS" data-lia-auto-title-active="0"&gt;New Platform SSO with registration during Automated Device Enrollment on macOS&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Have users reset their password before Platform SSO registration. &lt;/STRONG&gt;During initial enrollment, if password configuration or compliance policies are applied, users are required to reset their password after device enrollment and prior to initiating Platform SSO registration. Skipping this step can result in silent registration failures that are difficult to diagnose. Ensure this is communicated as the first step in your rollout guidance.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Assign the SSO profile during enrollment, not after. &lt;/STRONG&gt;Deploying during enrollment means the registration prompt shows up at first login, a natural part of setup. Retrofitting existing devices forces users to notice and click a notification banner. Many will not. macOS Tahoe (26) Simplified Setup will auto-register, removing this friction.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; One SSO profile per device, no exceptions. &lt;/STRONG&gt;Duplicate profiles cause Error 10002. If you are migrating from a Device Features template to Settings Catalog, remove the old one first.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Pilot with realistic scenarios. &lt;/STRONG&gt;Don’t just test “can I open Outlook.” Test registration, SSO to Microsoft 365, on-prem file shares, password change mid-session, reboot behavior, and what happens when a user dismisses the registration banner. We found issues in every one of these.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Align password policies end-to-end. &lt;/STRONG&gt;For Password Sync, Intune compliance and Microsoft Entra ID password policies must match: length, complexity, expiration.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Integrate legacy Kerberos properly. &lt;/STRONG&gt;If you run a standalone Kerberos SSO extension, set usePlatformSSOTGT = true in its ExtensionData to reuse Platform SSO TGT instead of running duplicate flows. Requires macOS 14.6+ and Company Portal 5.2408.0+.&lt;BR /&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/devices/device-join-macos-platform-single-sign-on-kerberos-configuration" target="_blank" rel="noopener"&gt;Enable Kerberos SSO to on-premises Active Directory and Microsoft Entra ID Kerberos Resources in Platform SSO&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Allowlist auth URLs from TLS inspection. &lt;/STRONG&gt;Apple and Microsoft authentication endpoints must be excluded from proxy/TLS inspection. If they are not, registration fails silently with no error.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;Challenges we faced&lt;/STRONG&gt;&lt;/H1&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 420px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7" style="height: 47.5px;"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Challenge&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;What we experienced&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Solution&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 92.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Password must be reset before registration during the new enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Half our pilot group could not register after the new enrollment as their Entra ID password had not been reset.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Require a password reset before rollout; make this step 1 in user communications&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Users dismiss the registration banner&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;The notification is easy to swipe away. Once dismissed, there is no simple way to retrigger it.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Send screenshots and instructions before rollout; macOS Tahoe auto-registers via Simplified Setup&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;SSO breaks after macOS updates&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;After point updates, SSO stopped working until re-registration.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Restart &lt;CODE&gt;swcd&lt;/CODE&gt; process; some cases required full re-registration; check release notes&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Password policy mismatch&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Users changed Microsoft Entra password, but local Mac password did not sync, causing lockouts.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Match Intune compliance and Microsoft Entra ID password policies exactly; test end-to-end&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Browser SSO inconsistency&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Edge worked natively, Chrome needed extension, Safari varied by OS.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Deploy Chrome SSO extension via Intune; test Safari on each target OS version&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Platform SSO delivers phishing-resistant passwordless authentication, seamless cross-platform SSO, and Conditional Access compliance with hardware-backed identity. &lt;STRONG&gt;Start&lt;/STRONG&gt; your implementation&lt;STRONG&gt; with Secure Enclave, deploy via Intune Settings Catalog, pilot small, then scale.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have questions on implementing Platform SSO, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Faka.ms%2FJoinIntuneCommunity.&amp;amp;data=05%7C02%7CMax.Stein%40microsoft.com%7C559e75711c2d49a5c96f08dec0c964db%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639160168381447093%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=Q6H3j1xPZv2JTqAQMiHnpbPEo2Fw0%2B51VIS2YlNbflE%3D&amp;amp;reserved=0" target="_blank" rel="noopener" data-outlook-id="1500cb02-a991-4798-bffb-dc0f1bde5fd5"&gt;https://aka.ms/JoinIntuneCommunity.&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 17:30:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/deploying-platform-sso-for-pre-macos-26-with-microsoft-intune/ba-p/4521368</guid>
      <dc:creator>MikeGriz</dc:creator>
      <dc:date>2026-06-18T17:30:00Z</dc:date>
    </item>
    <item>
      <title>IT experts weigh in: Advanced Intune capabilities coming to Microsoft 365 E3 and E5</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/it-experts-weigh-in-advanced-intune-capabilities-coming-to/ba-p/4516898</link>
      <description>&lt;P&gt;Back on December 4th, we shared that &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="advanced capabilities from the Microsoft Intune Suite were coming to Microsoft 365 E3 and Microsoft 365 E5" data-lia-auto-title-active="0"&gt;advanced capabilities from the Microsoft Intune Suite were coming to Microsoft 365 E3 and Microsoft 365 E5&lt;/A&gt;. These packaging changes become effective on July 1st, with existing eligible customers expected to receive the capabilities in their tenants by August&lt;SUP&gt;1&lt;/SUP&gt;. So you can understand how these capabilities will help your organization, we’ve pulled together a select set of guides and reviews from IT experts who have earned Microsoft “Most Valuable Professionals” (MVP) status. These MVPs from across segments and industries have real-world experience and lots of hands-on time with Intune.&lt;/P&gt;
&lt;P&gt;So, whether you're a security admin sizing up Endpoint Privilege Management, an IT pro curious what Advanced Analytics reveals about your fleet, a help desk lead rethinking Remote Help, or someone just getting started with Intune, there's something here for you. This roundup is packed with practical, honest, in-practice perspectives from the people who know these capabilities best.&lt;SUP&gt;2&lt;/SUP&gt;&lt;/P&gt;
&lt;P&gt;The focus now is on the practical details: what each capability does, where it fits, and what to consider before deployment. The MVP resources below help answer those questions with implementation guidance, technical context, and comparisons that can help teams evaluate the right approach for their environment.&lt;/P&gt;
&lt;P&gt;Here’s a quick refresher on the Microsoft 365 plan changes related to Microsoft Intune:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;colgroup&gt;&lt;col style="width: 49.9518%" /&gt;&lt;col style="width: 49.9518%" /&gt;&lt;/colgroup&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 plan&lt;SUP&gt;2&lt;/SUP&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Newly included Intune capabilities &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;EMS E3  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;(&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Included&lt;/SPAN&gt; &lt;SPAN data-ccp-parastyle="heading 2"&gt;in Microsoft 365 E3) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Remote Help  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Advanced Analytics  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Plan 2 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft 365 E5 &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;All the above &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;plus&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Endpoint&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Privilege&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; Management  &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft Cloud PKI   &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Intune Enterprise App Management &lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Microsoft Security Copilot &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;201341983&amp;quot;:0,&amp;quot;335559738&amp;quot;:240,&amp;quot;335559739&amp;quot;:240,&amp;quot;335559740&amp;quot;:240}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H4&gt;One place to manage it all&lt;/H4&gt;
&lt;P&gt;Customers have been clear that they want to make full use of the capabilities already included in their licenses and manage them from a more centralized platform. They also want to understand the tradeoffs: how consolidation changes day-to-day operations, how these capabilities work with Cloud PCs, and what it means to reduce reliance on multiple vendors, contracts, and support models.&lt;/P&gt;
&lt;P&gt;The Microsoft MVP resources below tackle those questions directly such as what's included in your license and how integrated endpoint management plays out in practice.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=oD-st6f2YvA" target="_blank" rel="noopener"&gt;Microsoft Intune Suite in E3 vs E5: What's Included from July 2026&lt;/A&gt; – &lt;EM&gt;Dean Ellerby&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.xplorethecloud.nl/l/intune-suite-not-an-add-on-but-a-part-of-your-microsoft-suite/" target="_blank" rel="noopener"&gt;Intune Suite: Not an Add-on but a part of your Microsoft 365 Suite&lt;/A&gt; – &lt;EM&gt;Johan Adreaan (Arno) van Dijk&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/pulse/one-console-every-endpoint-why-2026s-microsoft-365-update-jon-jarvis-vw1le" target="_blank" rel="noopener"&gt;One Console, Every Endpoint: Why 2026’s Microsoft 365 Update Actually Matters for Your Cloud PCs&lt;/A&gt; – &lt;EM&gt;Jon Jarvis&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.burgerhout.org%2Fp%2F7f5e1a0a-5c12-47e0-b1b2-a93911cd3315%2F%3Fmember_status%3Dfree&amp;amp;data=05%7C02%7Cv-olverjon%40microsoft.com%7C9ea6233a5d3749c0b89b08dec6c1d674%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639166733013660742%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=xniAE5MNVRGHG6QMw%2Bf3JbHQeA7ZdD74wc9asW7RdH0%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Windows 365 x Intune Suite: Looking Beyond the Feature List&lt;/A&gt; – &lt;EM&gt;Jeroen Burgerhout&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Our MVPs have also taken deep dives into the individual capabilities that are coming to E3 and E5 (and are still available to other license holders as an add-on).&lt;/P&gt;
&lt;H4&gt;Advanced Analytics&lt;/H4&gt;
&lt;P&gt;Advanced Analytics gives IT teams a clearer view of endpoint health and performance, with capabilities like device query, anomaly detection, and battery health reporting that build on endpoint analytics. For Microsoft 365 E3 and E5 customers, troubleshooting and fleet-wide visibility are now part of the plan. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/advanced-analytics/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fmsnugget.com%2Fget-ready-for-advanced-analytics-in-m365-e3-and-e5%2F&amp;amp;data=05%7C02%7Cv-olverjon%40microsoft.com%7C84a8dbcaeda74710ae5e08decbca4842%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C639172266816406456%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=bvgn83JaCmtpm2ezxuu%2F%2BiEs%2B%2BjbzBhsMDX7SneV1KY%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;Get Ready for Advanced Analytics in M365 E3 and E5&lt;/A&gt; – &lt;EM&gt;Florian Salzmann &amp;amp; Jannik Reinhard&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://rozemuller.com/microsoft-intune-advance-analytics-more-than-endpoint-analytics/" target="_blank" rel="noopener"&gt;Microsoft Intune Advanced Analytics more than Endpoint Analytics&lt;/A&gt; – &lt;EM&gt;Sander Rozemuller&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.linkedin.com/pulse/using-intune-suite-advanced-analytics-solve-issues-faster-panu-saukko-0qcsf/" target="_blank" rel="noopener"&gt;Using Intune Suite Advanced Analytics to Solve Issues Faster&lt;/A&gt; – &lt;EM&gt;Panu Saukko&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://jannikreinhard.com/2026/06/13/intune-advanced-analytics-market-comparison/" target="_blank" rel="noopener"&gt;Intune Advanced Analytics: How It Compares to Other Tools&lt;/A&gt; – &lt;EM&gt;Jannik Reinhard&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Remote Help&lt;/H4&gt;
&lt;P&gt;Remote Help is a cloud-based solution that enables secure, role-based help desk connections to managed devices, with support for unattended scenarios and compliance with Intune's RBAC model. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/remote-help/" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://cracky96.blogspot.com/2026/06/how-to-implement-intune-remote-help.html" target="_blank" rel="noopener"&gt;How to Implement Intune Remote Help&lt;/A&gt; – &lt;EM&gt;Thant Zin Phyo&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://gerryhampsoncm.blogspot.com/2026/06/you-have-intune-remote-help-already-you.html" target="_blank" rel="noopener"&gt;You have Intune Remote Help already, you might as well use it&lt;/A&gt; – &lt;EM&gt;Gerry Hampson&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.rockenroll.tech/2026/06/14/microsoft-intune-remote-help-my-overview/" target="_blank" rel="noopener"&gt;Microsoft Intune Remote Help: My Overview&lt;/A&gt; – &lt;EM&gt;Nicklas Ahlberg&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Endpoint Privilege Management&lt;/H4&gt;
&lt;P&gt;Endpoint Privilege Management (EPM) lets organizations elevate permissions for specific, IT-approved tasks on a just-in-time basis, avoiding the need to create users with ‘admin’ privileges for routine activities, directly supporting a Zero Trust, least-privilege posture. See the official documentation &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/epm/overview" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://ccmexec.com/2026/06/microsoft-intune-endpoint-privilege-management-overview/" target="_blank" rel="noopener"&gt;Microsoft Intune Endpoint Privilege Management Overview&lt;/A&gt; – &lt;EM&gt;Jorgen Nilsson&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://msendpointmgr.com/2026/06/15/epm-part-1-the-end-of-local-admin-how-intune-endpoint-privilege-management-solves-a-problem-it-has-lived-with-for-decades/" target="_blank" rel="noopener"&gt;The end of local admin - How Intune Endpoint Privilege Management solves a problem IT has lived with for decades&lt;/A&gt; – &lt;EM&gt;Mattias Melkersen Kalvåg &amp;amp; Simon Skotheimsvik&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://scloud.work/intune-endpoint-privilege-management-vs-the-alternatives/" target="_blank" rel="noopener"&gt;When Intune Endpoint Privilege Management Wins, and When It Does Not&lt;/A&gt; – &lt;EM&gt;Florian Salzman&lt;/EM&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H4&gt;Just getting started with Intune?&lt;/H4&gt;
&lt;P&gt;If all this is new to you, you don’t need to absorb every advanced capability at once. A great place to begin is &lt;A class="lia-external-url" href="https://www.indefent.com/advanced-microsoft-intune-capabilities-whats-changing-and-where-it-pros-should-start/" target="_blank" rel="noopener"&gt;Albin Klinaku's guide&lt;/A&gt;, which walks through what these E3 and E5 changes mean for someone getting started and breaks down the fundamentals in an approachable way. From there, the official &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/intune/" target="_blank" rel="noopener"&gt;Microsoft Intune overview&lt;/A&gt; on Microsoft Learn provides tutorials. Start there, explore at your own pace, and you'll be ready to make the most of everything coming to your tenant.&lt;/P&gt;
&lt;H4&gt;A special thanks to our contributors&lt;/H4&gt;
&lt;P&gt;None of this guidance would exist without the community behind it, which brings me to the people who made this roundup possible. A big thank you to the MVPs who took the time to share their perspectives on this important news:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Nicklas Ahlberg | Thant Zin Phyo | Gerry Hampson | Dean Ellerby | Jorgen Nilsson | Mattias Melkersen Kalvåg | Florian Salzmann | Sander Rozemuller | Panu Saukko | Jannik Reinhard | Jon Jarvis | Jeroen Burgerhout | Simon Skotheimsvik | Arno van Dijk | Albin Klinaku&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Your expertise, generosity, and willingness to share continue to elevate the entire Intune community. Thank you for everything you do. Stay secure, stay innovative, and be well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on &lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank" rel="noopener"&gt;LinkedIn &lt;/A&gt;or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune &lt;/A&gt;&lt;/EM&gt;&lt;EM&gt;and &lt;A href="https://x.com/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 16:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-blog/it-experts-weigh-in-advanced-intune-capabilities-coming-to/ba-p/4516898</guid>
      <dc:creator>Lior_Bela</dc:creator>
      <dc:date>2026-06-18T16:00:00Z</dc:date>
    </item>
    <item>
      <title>Triage vulnerabilities with the Vulnerability Remediation Agent, now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/triage-vulnerabilities-with-the-vulnerability-remediation-agent/ba-p/4528646</link>
      <description>&lt;P&gt;As automation and AI accelerate the pace of vulnerability discovery, the window between disclosure and exploitation continues to shrink. For IT and security teams, the challenge is no longer just &lt;EM&gt;finding&lt;/EM&gt; vulnerabilities - it's prioritizing the ones that matter and acting on them before they can be exploited. To help organizations close that gap, we're pleased to announce that the&amp;nbsp;&lt;STRONG&gt;Vulnerability Remediation Agent for Security Copilot &lt;/STRONG&gt;in Microsoft Intune is now in public preview and rolling out to all customers.&lt;/P&gt;
&lt;P&gt;Following a successful limited preview, the agent is now broadly available. This release brings agentic vulnerability remediation out of an early-access cohort and into the hands of every eligible organization - an important step in our continued investment in helping admins reduce exposure faster and with greater confidence. View eligibility prerequisites&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#prerequisites" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How the agent helps you identify and triage vulnerabilities&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The Vulnerability Remediation Agent uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) across your Intune-managed Windows devices and apps, then prioritizes them for remediation. Rather than leaving admins to sift through lengthy &amp;nbsp;CVE lists with little context, the agent surfaces a prioritized set of recommendations directly in the Intune admin center - accessible from both the Agents and Endpoint security pages.&lt;/P&gt;
&lt;P&gt;When the agent runs, it evaluates vulnerability data and ranks threats based on factors such as CVSS scores, exposure impact, and affected device count, so the most critical issues rise to the top. Drilling into any suggestion provides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The count of associated CVEs&lt;/LI&gt;
&lt;LI&gt;A Copilot-assisted summarized impact analysis&lt;/LI&gt;
&lt;LI&gt;Suggested actions and affected systems&lt;/LI&gt;
&lt;LI&gt;Exposed devices and potential impact&lt;/LI&gt;
&lt;LI&gt;Step-by-step guidance for remediating the threat using Intune&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After acting on a recommendation, admins can mark it as applied, allowing the agent to retain a record for tracking remediation actions over time. The result is a meaningful reduction in the time it takes to investigate, prioritize, and remediate - strengthening overall security posture.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Introducing agentic identity for the Vulnerability Remediation Agent&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;With this release, the agent now operates under Microsoft&lt;STRONG&gt; &lt;/STRONG&gt;Entra agentic identity - a meaningful advancement in how autonomous agents are governed and secured.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What it is.&lt;/STRONG&gt; Agentic identity is a specialized identity in Microsoft Entra ID that allows the agent to operate securely and independently. During setup, the agent provisions a dedicated agentic identity and a corresponding agentic user in your tenant's Microsoft Entra directory. The agent then runs under the permissions delegated to that agentic user rather than under a human user account.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why it matters.&lt;/STRONG&gt; Agentic identity decouples the agent from any one person, ensuring its behavior is strictly bound to the permissions and scope you delegate to it. This delivers clearer accountability, a cleaner audit trail, and enterprise-grade governance for autonomous operations.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it helps.&lt;/STRONG&gt; Admins remain firmly in control. After setup, delegate the required read permissions to the agentic user in the &amp;nbsp;Microsoft Intune and Microsoft Defender admin centers, then use the built-in Readiness Check to confirm everything is configured correctly before the agent runs.&lt;/P&gt;
&lt;P&gt;Learn more in &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#agent-identity" target="_blank" rel="noopener"&gt;Agent identity&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Getting started: Connect → Enable → Run → Remediate → Track&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;One of the design goals behind the Vulnerability Remediation Agent is to make agentic security approachable, not complex. Rather than stitching together signals across multiple tools and admin centers, the agent guides admins through a clear, repeatable flow - from connecting your data to tracking measurable improvement over time.&lt;/P&gt;
&lt;div contenteditable="false" class="lia-embeded-content"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-xhy3yXGVGM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-xhy3yXGVGM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-xhy3yXGVGM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" title="YouTube embed" scrolling="no" allowfullscreen="allowfullscreen" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture" class="lia-iframe-embeded" sandbox="allow-scripts allow-same-origin"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Connect — bring Defender and Intune data together.&lt;/STRONG&gt; The agent draws on Microsoft Defender Vulnerability Management for CVE intelligence and Microsoft Intune for device and configuration context. With the required Microsoft Defender and Microsoft Intune plugins in place, your vulnerability and management signals work as one. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#prerequisites" target="_blank" rel="noopener"&gt;Learn more on what is needed to connect the experience.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enable — turn on the agent. &lt;/STRONG&gt;From the &lt;STRONG&gt;Agents&lt;/STRONG&gt; node in the Microsoft Intune admin center, set up the agent in a few guided steps. During setup, the agent provisions its Microsoft Entra agentic identity and surfaces the permissions and plugins it needs, so you know exactly what to delegate before the first run.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Run — let automated prioritization do the heavy lifting.&lt;/STRONG&gt; Once permissions are delegated and the Run Readiness Check passes, you can configure the agent to run on demand or schedule it to run automatically in the background on a cadence you define; scheduling is a unique capability that helps teams stay ahead of emerging risks without requiring constant manual intervention. Each run analyzes your environment and produces a prioritized list of recommendations ranked by CVSS score, exposure impact, and affected device count so the most critical risks rise to the top automatically.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remediate — act with guided, Intune-ready actions.&lt;/STRONG&gt; Each recommendation includes a Copilot-assisted impact summary, &amp;nbsp;exposed devices, and step-by-step guidance for remediating the threat using Intune. Admins move directly from insight to action, without leaving the admin center.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Track — measure improvement over time.&lt;/STRONG&gt; Recommendations can be marked as applied, and the agent retains a record of your remediation actions.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The outcome is a streamlined operating model: connect once, enable with confidence, and let the agent drive a continuous cycle of prioritization, remediation, and view progress. For full prerequisites, licensing, plugin, and role requirements, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent overview and set up&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The Vulnerability Remediation Agent represents a meaningful step toward a more proactive, AI-assisted security posture, one where admins spend less time sifting through CVE lists and more time acting on what matters most. We invite you to try the public preview today, connect your Defender and Intune data, and experience how agentic remediation can help your team stay ahead of emerging threats. As always, we'd love to hear your feedback as we continue investing in making security in Intune faster, smarter, and more accessible. Share your tips and lessons learned in the comments below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 21:27:48 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/triage-vulnerabilities-with-the-vulnerability-remediation-agent/ba-p/4528646</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-16T21:27:48Z</dc:date>
    </item>
    <item>
      <title>enrolling in Intune MacBook Pro with an M5 Pro</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/enrolling-in-intune-macbook-pro-with-an-m5-pro/m-p/4528566#M23543</link>
      <description>&lt;P&gt;Hi everyone&lt;/P&gt;&lt;P&gt;We have tested the Wi-Fi and ethernet profile without success with Apple businesses manager.&lt;/P&gt;&lt;P&gt;The Wi-Fi and the ethernet connection itself works, but the enrollment process into Intune does not complete successfully.&lt;/P&gt;&lt;P&gt;At this stage, we cannot sign in, and neither the Wi-Fi nor the Ethernet connection appears to be working.&lt;/P&gt;&lt;P&gt;The device is a 14-inch MacBook Pro with an M5 Pro chip, running macOS 26.5.1 the device connects to the server, the settings begin to apply, but the process suddenly stops, and we are then unable to log in.&lt;/P&gt;&lt;P&gt;These are steps followed :&lt;BR /&gt;Synchronize the device from Apple Business Manager to Intune.&lt;/P&gt;&lt;P&gt;Assign the enrollment profile to the device.&lt;/P&gt;&lt;P&gt;Perform a device wipe/reset.&lt;/P&gt;&lt;P&gt;Start Automated Device Enrollment (ADE).&lt;/P&gt;&lt;P&gt;Complete the device setup and user sign-in.&lt;/P&gt;&lt;P&gt;The device successfully enrolls into Intune.&lt;/P&gt;&lt;P&gt;Intune begins deploying configuration profiles, compliance policies, security policies, and applications.&lt;/P&gt;&lt;P&gt;During the policy application process, Wi-Fi connectivity stops responding.&lt;/P&gt;&lt;P&gt;The device loses network connectivity and cannot continue synchronizing policies. We are unable to sign in because the enrolment process has not been finalized. As a result, we have to wipe the Mac and start the process again each time.&lt;/P&gt;&lt;P&gt;We have disabled some policies, but we are still experiencing the same issue.&lt;/P&gt;&lt;P&gt;Have anyone experienced any issues like that ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 15:17:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/enrolling-in-intune-macbook-pro-with-an-m5-pro/m-p/4528566#M23543</guid>
      <dc:creator>miguMac</dc:creator>
      <dc:date>2026-06-16T15:17:50Z</dc:date>
    </item>
    <item>
      <title>How Enterprise App Management secures your App Catalog from ingestion to device</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/how-enterprise-app-management-secures-your-app-catalog-from/ba-p/4528361</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Joe Lurie, Sr. Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;One of the most common questions I get from customers when I talk about Enterprise App Management is some version of: &lt;EM&gt;"Okay, but how do I know these apps are safe?"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;It's a fair question. You're trusting a catalog of pre-packaged Win32 apps to land on thousands of managed devices across your organization. If you're responsible for endpoint security, you should be asking that question. This post explains how Enterprise App Management works behind the scenes, how apps get into the catalog, what happens before they're visible to your tenant, and why the architecture matters for your security posture.&lt;/P&gt;
&lt;H1&gt;The architecture: Not a new system, but an extension of what you already trust&lt;/H1&gt;
&lt;P&gt;An important design decision with Enterprise App Management is that it's not a separate app delivery system. It's an extension of the existing &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/app-management-win32" target="_blank" rel="noopener"&gt;Intune Win32 app architecture&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;From the admin perspective, everything starts in the Intune admin center. But behind the scenes, there's a clean separation between the control plane and the data plane:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Control plane&lt;/STRONG&gt;: For each app being added to the Enterprise App Management catalog, Intune curates app metadata, including app version, install commands, uninstall commands, detection logic, requirements, and supported configurations. This metadata is validated and normalized before it shows up in your tenant. That's why catalog apps behave consistently whether you're deploying to 50 devices or 50,000.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data plane&lt;/STRONG&gt;: Once an app is assigned by an admin, it flows through the same Win32 app delivery and enforcement pipeline you already rely on. Your devices don't know they're installing an "Enterprise App Management app" - they're enforcing a Win32 app with well-defined intent. Same Enrollment Status Page support, same reporting, same retry logic, same Intune Management Extension. No new agent. No new runtime. And finally, Enterprise App Management apps have the same support for&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/security/application-security/application-control/app-control-for-business/design/configure-authorized-apps-deployed-with-a-managed-installer" target="_blank" rel="noopener"&gt;App Control for Business with Managed Installer&lt;/A&gt; which can automatically tag the apps as safe.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is important because it means Enterprise App Management inherits all the trust and operational maturity of Win32 app management in Intune. Curated content is delivered through established, reliable infrastructure.&lt;/P&gt;
&lt;H1&gt;How Enterprise App Management apps are delivered: The ingestion pipeline&lt;/H1&gt;
&lt;P&gt;This section walks through what happens from the moment an app is sourced to the moment it appears in your catalog.&lt;/P&gt;
&lt;H2&gt;Content ingestion&lt;/H2&gt;
&lt;P&gt;It starts with the catalog. Microsoft receives app metadata, including install and uninstall commands, version info, and download URLs. The data is then ingested, flattened, transformed, and Microsoft's own identifiers are applied. After the data lands in the database, eligibility and filtering gates are applied through allow and deny lists. Apps on the allow list are permitted to download content from controlled internet locations. This process handles both net-new apps and version updates to apps already in the catalog.&lt;/P&gt;
&lt;H2&gt;Security and functional validation&lt;/H2&gt;
&lt;P&gt;This is the part that answers the "how do I know it's safe?" question. Once content ingestion is complete, every app is submitted for security and functional validation. This is a queue-driven service that runs two parallel tracks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Static malware detection&lt;/STRONG&gt; scans the installer and related artifacts for malicious content, assigning a VirusTotal score. If an app receives a non-zero score, it's blocked from proceeding, full stop. Static scanning is about establishing baseline trust before deployment. It validates that binaries are intact, that they originate from trusted sources, and they don't carry known indicators of malware or tampering. This process catches embedded malicious payloads, corrupted binaries, and known bad signatures before they can impact any device.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamic analysis (detonation)&lt;/STRONG&gt; runs in parallel. The app is installed and uninstalled inside a VM detonation chamber, producing install results, logs, and artifacts. This is about validating behavior, not just files. Modern threats don't always look malicious at rest; some issues only surface when an installer or application runs or interacts with the system. Dynamic evaluation catches unexpected system changes, unsafe persistence mechanisms, and activity inconsistent with enterprise deployment expectations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If an app fails automatic validation, it goes through manual validation by Intune engineering.&lt;/P&gt;
&lt;P&gt;Both layers are required. Static scanning provides speed and broad coverage, while dynamic scanning provides depth and behavioral assurance.&lt;/P&gt;
&lt;H2&gt;After publication: Ongoing scanning&lt;/H2&gt;
&lt;P&gt;The security story doesn't end at publication. Apps already in the catalog are periodically re-scanned. If a version that previously passed validation is later found to fail a malware scan, it's flagged and removed from the catalog. This is a critical detail - the catalog isn't a snapshot-in-time trust decision. It's a continuously validated inventory.&lt;/P&gt;
&lt;H2&gt;Update velocity&lt;/H2&gt;
&lt;P&gt;Once a new app version is received, the target is to have it available in the catalog within 24 hours. Around 80–90% of apps hit that timeline. The remainder are apps that don't pass automatic validation and require manual review, which takes longer. But the pipeline processes updates through the exact same ingestion and validation flow as new apps - no shortcuts.&lt;/P&gt;
&lt;H2&gt;Where Zero Trust fits in&lt;/H2&gt;
&lt;P&gt;If you've been following Microsoft's &lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust model&lt;/A&gt;, this pipeline should feel familiar. Zero Trust is built on three principles: &lt;STRONG&gt;verify explicitly&lt;/STRONG&gt;, &lt;STRONG&gt;use least-privilege access&lt;/STRONG&gt;, and &lt;STRONG&gt;assume breach&lt;/STRONG&gt;. EAM's validation pipeline maps directly to these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Verify explicitly&lt;/STRONG&gt;: Every app is verified through multiple independent signals, including source integrity, static malware scanning, and dynamic behavioral analysis, before it's ever exposed to a tenant. No app gets a pass based on reputation or publisher name alone. Trust is earned through evidence, every time.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Use least-privilege access&lt;/STRONG&gt;: Enterprise App Management catalog apps ship with prefilled, scoped install and uninstall commands, detection rules, and requirements. You're not handing an installer broad system access and hoping for the best. The deployment surface is defined and constrained by design.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assume breach&lt;/STRONG&gt;: This is why the pipeline doesn't stop at initial validation. Ongoing re-scanning means that even apps that previously cleared every check are continuously re-evaluated. If an app that was clean six months ago is later found to carry a risk, it's flagged and pulled from the catalog. The system assumes that trust is perishable, exactly the way Zero Trust says it should be.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In practice, this means Enterprise App Management gives you an app lifecycle that's not just convenient - it follows the same security framework your organization is likely already adopting for identity, network, and device access. The app layer is often the last piece to catch up, and Enterprise App Management closes that gap.&lt;/P&gt;
&lt;P&gt;Here's the ingestion flow that shows how all of this fits together:&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1: &lt;/EM&gt;&lt;EM&gt;The Enterprise App Management ingestion pipeline: from source metadata through content ingestion, static and dynamic security validation, manual review for failures, periodic re-scanning, and finally publication to the catalog.&lt;/EM&gt;&lt;/img&gt;
&lt;H1&gt;Takeaways&lt;/H1&gt;
&lt;P&gt;If you're evaluating Enterprise App Management or explaining it to your security team, here's what I'd suggest that you land on:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enterprise App Management reduces the packaging tax.&lt;/STRONG&gt; Pre-packaged apps with prefilled install details, detection rules, requirements, and restart behavior mean you spend less time building the same scaffolding repeatedly and more time on policy and rollout strategy.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Patching becomes more predictable.&lt;/STRONG&gt; Guided update flows using supersedence and a documented expectation of 24-hour update availability give you a cadence you can plan around, not react to.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The security model is layered and continuous.&lt;/STRONG&gt; Static scanning, dynamic detonation, manual review fallback, and ongoing re-scanning mean the catalog maintains a high trust bar - not just at ingestion, but over time. And it's all built on the same Win32 delivery infrastructure that you and your devices already trust.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The bottom line: Enterprise App Management isn’t just about convenience. It shifts the app lifecycle from a manual, error-prone process to one with built-in security validation, operational consistency, and governance you can defend to your security team. Rather than manually sourcing installers and creating detection rules, use this approach to streamline the process.&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Want to go deeper? Check out the &lt;/EM&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise App Management documentation&lt;/A&gt;&lt;EM&gt; and keep an eye out for upcoming changes to &lt;/EM&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/add-ons" target="_blank" rel="noopener"&gt;Intune Suite licensing&lt;/A&gt;&lt;EM&gt; that will make Enterprise App Management available in the Microsoft 365 plans you may already own. And as always, drop feedback at &lt;/EM&gt;&lt;A class="lia-external-url" href="https://aka.ms/IntuneFeedback" target="_blank" rel="noopener"&gt;aka.ms/IntuneFeedback&lt;/A&gt;&lt;EM&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 17:10:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/how-enterprise-app-management-secures-your-app-catalog-from/ba-p/4528361</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-15T17:10:22Z</dc:date>
    </item>
    <item>
      <title>CanReset value flipping on cloud only devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/canreset-value-flipping-on-cloud-only-devices/m-p/4527692#M23539</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with cloud only Windows 11 devices configured with passwordless policy. I have noticed that when you run dsregcmd /status command, CanReset value under User State is flipping between "No" and "DestructiveAndNonDestructive". When it's latter, everything works fine, users can start wizard for facial recognition or make PIN changes under Sign In options in Windows. But when it flips to No, everything is blocked. It seems to happen randomly, you can leave device untouched for few hours and just check dcregcmd and the value will change. CanReset is the only value that changes in the dsregcmd report.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It happens for different devices located on different networks. Also, I have disabled web gateway completely for one device just for testing but no change. Any suggestions would be welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 07:06:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/canreset-value-flipping-on-cloud-only-devices/m-p/4527692#M23539</guid>
      <dc:creator>Mariusz_80</dc:creator>
      <dc:date>2026-06-12T07:06:37Z</dc:date>
    </item>
    <item>
      <title>Windows App Update Notification</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have deployed the Windows App for a client. Currently, when an update is available, users are seeing an in app banner that says: "Click here to update the app. Meanwhile you can use the app."&lt;/P&gt;&lt;P&gt;If the user clicks it, the update finishes successfully. However, our organization requires a completely hands off, automated update process. We do not want end-users to have to interact with a notification or manually click a button to keep the app up to date.&lt;/P&gt;&lt;P&gt;Is there a specific Group Policy, registry key or Intune configuration that completely suppresses this in app notification and forces the MSIX package to install silently in the background when the app or machine is idle?&lt;/P&gt;&lt;P&gt;Any advice on how to bypass this "Notification" behavior and enforce touchless updates enterprise wide would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 00:08:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</guid>
      <dc:creator>malithamadushan</dc:creator>
      <dc:date>2026-06-10T00:08:45Z</dc:date>
    </item>
    <item>
      <title>Intune Install Printer Driver</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</link>
      <description>&lt;P&gt;I am trying to install a Printer driver via a Win32app using System to install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have set configuration as below:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a simple powershell script which runs perfectly when installing on a device as an administrator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$printdriver = "PCL6 V4 Driver for Universal Print"&lt;/P&gt;&lt;P&gt;C:\Windows\system32\pnputil.exe /add-driver "r4600.inf" /install&lt;/P&gt;&lt;P&gt;Add-PrinterDriver -name $printdriver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However installing it via Intune I get an event id 215 with failed error code 0x0 HRESULT 0x80070705 on the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 10:12:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</guid>
      <dc:creator>tonybap1</dc:creator>
      <dc:date>2026-06-09T10:12:13Z</dc:date>
    </item>
    <item>
      <title>MDOP is out of support: What to do next with Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Joe Lurie – Sr. Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;On April 14, 2026, the &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-desktop-optimization-pack/" target="_blank" rel="noopener"&gt;Microsoft Desktop Optimization Pack (MDOP)&lt;/A&gt; reached the end of extended support. Microsoft no longer provides security updates, bug fixes, or technical support for MDOP components. For more information, refer to: &lt;A class="lia-external-url" href="https://learn.microsoft.com/lifecycle/announcements/mdop-extended" target="_blank" rel="noopener"&gt;Microsoft Desktop Optimization Pack (MDOP) support extended&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If your organization still relies on parts of MDOP, it’s time to move to supported options. In most cases, including Windows desktop management, app virtualization, BitLocker administration, and Group Policy change control, you can handle the same workloads with capabilities in Microsoft Entra ID, Intune, Windows 11, and Configuration Manager.&lt;/P&gt;
&lt;P&gt;Moving these workloads to the cloud does more than keep you supported. It removes on-premises server infrastructure you have to stand up and patch, brings management of cross-platform devices into a unified console, and connects capabilities like encryption and recovery into a Zero Trust framework with Conditional Access.&lt;/P&gt;
&lt;H2&gt;Quick start checklist&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Inventory what you actually use.&lt;/STRONG&gt; Confirm whether Application Virtualization (App-V) server components, Microsoft BitLocker Administration and Monitoring (MBAM), Diagnostics and Recovery Toolset (DaRT), User Experience Virtualization (UE-V), or Advanced Group Policy Management (AGPM) are still in production.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prioritize BitLocker Management first.&lt;/STRONG&gt; If you still rely on MBAM, plan your move to &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows" target="_blank" rel="noopener"&gt;BitLocker management in Intune&lt;/A&gt; and confirm recovery key escrow is working as expected.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Plan your App-V exit.&lt;/STRONG&gt; Keep existing App-V packages running where needed but shift net-new packaging work to &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/overview" target="_blank" rel="noopener"&gt;MSIX&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate your PC recovery story.&lt;/STRONG&gt; Document how you’ll handle common break/fix scenarios using &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/quick-machine-recovery/" target="_blank" rel="noopener"&gt;Quick Machine Recovery&lt;/A&gt;, WinRE, bootable media, and Intune remote actions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Decide how you want to handle policy change management.&lt;/STRONG&gt; For cloud policy, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/role-based-access-control/multi-admin-approval" target="_blank" rel="noopener"&gt;Multi Admin Approval&lt;/A&gt; for sensitive actions and policy-as-code practices for versioning and review.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;App-V&lt;/H2&gt;
&lt;P&gt;App-V let you virtualize applications so they could run in isolated environments without a traditional install, which helped avoid app conflicts. It was especially useful for legacy line-of-business apps that were hard to install or update cleanly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;BR /&gt;&lt;/STRONG&gt;The App-V server components (Management Server, Publishing Server, Reporting Server) reached end of extended support in April 2026. The App-V client and sequencer are still included with Windows Enterprise and Education editions. They will continue to receive security fixes for the support lifecycle of the Windows versions they ship with. If you are distributing App-V packages today via Configuration Manager, that can still work. The key change is that you should not plan on using the standalone App-V server infrastructure going forward. For more details refer to: &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-desktop-optimization-pack/app-v/appv-support-policy" target="_blank" rel="noopener"&gt;App-V in Windows support policy&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; For new packaging work, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/overview" target="_blank" rel="noopener"&gt;moving to MSIX&lt;/A&gt;. MSIX is a modern packaging format that supports clean install and uninstall and more predictable updating. The &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/packaging-tool/tool-overview" target="_blank" rel="noopener"&gt;MSIX Packaging Tool&lt;/A&gt; can help you convert existing installers. In Azure Virtual Desktop, &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/virtual-desktop/app-attach-overview" target="_blank" rel="noopener"&gt;MSIX App Attach&lt;/A&gt; can deliver apps without baking them into the base image. A good starting point is to inventory your App-V packages, identify the ones you still need, and prioritize candidates to &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/packaging-tool/create-app-package" target="_blank" rel="noopener"&gt;convert&lt;/A&gt; to MSIX.&lt;/P&gt;
&lt;H2&gt;MBAM&lt;/H2&gt;
&lt;P&gt;MBAM gave IT admins centralized control over BitLocker, including policy enforcement, compliance reporting, and a self-service recovery portal. Many organizations used MBAM as their standard management solution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; We recommend replacing MBAM with Microsoft Intune’s BitLocker policy management through an &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows#endpoint-security-policy-recommended" target="_blank" rel="noopener"&gt;Endpoint security policy&lt;/A&gt;. Intune management provides backup of recovery keys to Microsoft Entra ID, reporting, and &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/protect/conditional-access" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; integration so you can require encryption for access to company resources. If you already manage devices with Intune, you may only need to create a disk encryption policy and confirm recovery keys are being escrowed. For detailed guidance, review &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows" target="_blank" rel="noopener"&gt;Encrypt Windows devices with BitLocker using Intune&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;DaRT&lt;/H2&gt;
&lt;P&gt;DaRT provided a bootable recovery environment with advanced tools like file recovery, registry editing, and offline troubleshooting. You typically used DaRT when a machine wouldn’t boot and you needed to repair it or recover data without reimaging.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; Windows includes the &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-hardware/manufacture/desktop/windows-recovery-environment--windows-re--technical-reference" target="_blank" rel="noopener"&gt;Windows Recovery Environment (WinRE)&lt;/A&gt; with tools like Startup Repair, System Restore, command prompt, and reset options. For many scenarios DaRT covered, WinRE is enough. You can also boot from a Windows installation USB, select "Repair your computer," and use the recovery tools for tasks like offline troubleshooting.&lt;/P&gt;
&lt;P&gt;For managed devices, you can pair recovery options with Intune remote actions, such as restart, wipe, or collect diagnostics, or use &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noopener"&gt;Quick Machine Recovery&lt;/A&gt;. Additionally, Quick Machine Recovery can automatically detect and fix boot failures using cloud-based remediation delivered through Windows Update, with no hands-on IT intervention required for managed devices running Windows 11 version 24H2 or later. You can enable and configure it through the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/" target="_blank" rel="noopener"&gt;settings catalog&lt;/A&gt; in Intune, and &lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/windows-autopilot" target="_blank" rel="noopener"&gt;Windows Autopilot&lt;/A&gt; scenarios for redeployment. These don’t replace every DaRT capability, but they cover many common use cases and work without shipping a separate recovery toolkit.&lt;/P&gt;
&lt;H2&gt;UE-V&lt;/H2&gt;
&lt;P&gt;UE-V roamed (synchronized) some user application and OS settings to persist across devices so users could sign in to a different Windows PC and keep a familiar experience. This was often used in shared workstation scenarios.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; For Windows settings roaming, &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/windows-backup/?tabs=intune" target="_blank" rel="noopener"&gt;Windows Backup for Organizations&lt;/A&gt; syncs certain Windows settings across Microsoft Entra ID joined devices. Review the latest guidance to confirm which settings are covered and how to enable it in your environment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Windows Backup for Organizations syncs Windows settings (theme, password, language) but doesn’t roam per-application settings for Win32 apps. Some apps may provide their own cloud-based sync. Windows Backup for Organizations is not a direct replacement for UE-V.&lt;/P&gt;
&lt;P&gt;For user files, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/sharepoint/redirect-known-folders" target="_blank" rel="noopener"&gt;OneDrive Known Folder Move&lt;/A&gt; to back up Desktop, Documents, and Pictures so content follows the user. Many Microsoft applications also sync their own settings through the cloud, which reduces the need for an OS-level roaming solution.&lt;/P&gt;
&lt;P&gt;Another option is to use a virtualized solution, like &lt;A class="lia-external-url" href="https://azure.microsoft.com/products/virtual-desktop/" target="_blank" rel="noopener"&gt;Azure Virtual Desktop&lt;/A&gt; or &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/overview" target="_blank" rel="noopener"&gt;Windows 365&lt;/A&gt;. With a Cloud PC, users connect to the same environment from any device, so settings and apps are already there when they sign in. For scenarios where UE-V mattered most, like shared workstation environments, Windows 365 can be a practical alternative. And for Azure Virtual Desktop, &lt;A class="lia-external-url" href="https://learn.microsoft.com/fslogix/overview-what-is-fslogix" target="_blank" rel="noopener"&gt;FSLogix&lt;/A&gt; is a viable option.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Enterprise State Roaming does not roam per-application settings for traditional Win32 desktop apps the way UE-V did. So, Windows 365 may not be the right fit if you need settings roaming across multiple physical devices.&lt;/P&gt;
&lt;H2&gt;AGPM&lt;/H2&gt;
&lt;P&gt;AGPM brought version control, change tracking, and approval workflows to Group Policy management. Instead of an admin changing Group Policy Objects (GPOs) directly in production, AGPM enforced a check-out and check-in model with full audit history. This mattered most in environments with strict change management requirements.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; Move to cloud-managed endpoints and replace Group Policy settings with Intune configuration profiles and security baselines. The settings catalog in Intune includes thousands of settings, including many ADMX-backed policies. If you use custom ADMX files for third-party or internal applications, you can &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/import-custom-admx-templates" target="_blank" rel="noopener"&gt;import them into Intune&lt;/A&gt;. For settings that aren’t available in the catalog, custom OMA-URI profiles can sometimes be used, depending on the CSP support for that setting.&lt;/P&gt;
&lt;P&gt;For change management, Intune offers&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/role-based-access-control/multi-admin-approval" target="_blank" rel="noopener"&gt;Multi Admin Approval&lt;/A&gt; for certain policy changes, which can add a second-admin approval step. If you want deeper versioning and review workflows, we often see teams using Configuration as Code. Teams practicing Configuration as Code define Intune policies as code or structured data, such as in a JSON file stored outside the Intune admin center. This can be stored in version control like Azure DevOps or GitHub, and use &lt;A class="lia-external-url" href="https://learn.microsoft.com/graph/api/resources/intune-graph-overview?view=graph-rest-1.0" target="_blank" rel="noopener"&gt;Microsoft Graph&lt;/A&gt; – directly or via tooling – to deploy and reconcile the service. This enables deep versioning, peer review, and repeatable, auditable changes. And with Intune, you can use Graph API to get &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/governance/monitor-audit-logs#use-graph-api-to-retrieve-audit-events" target="_blank" rel="noopener"&gt;two years&lt;/A&gt; of audit events.&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-indent-margin-left-60px lia-border-style-solid" border="1" style="width: 85.1852%; height: 523.657px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 57.1875px;"&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;MDOP tool&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;What it did&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud-native replacement&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 91.75px;"&gt;&lt;td class="lia-align-center" style="height: 91.75px;"&gt;
&lt;P&gt;App-V (Server)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 91.75px;"&gt;
&lt;P&gt;Application virtualization and streaming&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 91.75px;"&gt;
&lt;P&gt;MSIX packaging and Intune deployment (client still supported in Windows)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 81px;"&gt;&lt;td class="lia-align-center" style="height: 81px;"&gt;
&lt;P&gt;MBAM&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 81px;"&gt;
&lt;P&gt;BitLocker management and recovery&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 81px;"&gt;
&lt;P&gt;Intune management of BitLocker and Microsoft Entra ID key escrow&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 84.1875px;"&gt;&lt;td class="lia-align-center" style="height: 84.1875px;"&gt;
&lt;P&gt;DaRT&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 84.1875px;"&gt;
&lt;P&gt;Bootable diagnostics and recovery&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 84.1875px;"&gt;
&lt;P&gt;Windows Recovery Environment (WinRE), bootable USB, and Intune remote actions&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 102.766px;"&gt;&lt;td class="lia-align-center" style="height: 102.766px;"&gt;
&lt;P&gt;UE-V&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 102.766px;"&gt;
&lt;P&gt;User settings roaming&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 102.766px;"&gt;
&lt;P&gt;Windows 365 Cloud PC, Windows Backup for Organizations, OneDrive Known Folder Move, app-native sync&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 106.766px;"&gt;&lt;td class="lia-align-center" style="height: 106.766px;"&gt;
&lt;P&gt;AGPM&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 106.766px;"&gt;
&lt;P&gt;GPO version control and approval workflows&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 106.766px;"&gt;
&lt;P&gt;Intune settings catalog, Multi Admin Approval, policy-as-code in source control&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.4003%" /&gt;&lt;col style="width: 33.4003%" /&gt;&lt;col style="width: 33.3006%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Moving forward&lt;/H2&gt;
&lt;P&gt;By moving to cloud endpoint management, most MDOP scenarios are covered through Microsoft Intune and Microsoft Entra ID supported capabilities with less infrastructure to maintain, making it easier for you to manage.&lt;/P&gt;
&lt;P&gt;If you haven’t started planning yet, we suggest starting with MBAM since Intune is the most direct replacement. Then, you can work through App-V, DaRT, UE-V, and AGPM based on what’s still in use.&lt;/P&gt;
&lt;P&gt;If you’re in the middle of an MDOP exit and need help leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;. Tell us which components you still have and how you manage endpoints today (Intune, Configuration Manager, hybrid, or other). We can help you sanity-check dependencies, choose an order of operations, and avoid common migration pitfalls.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2026 16:58:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-08T16:58:58Z</dc:date>
    </item>
    <item>
      <title>Moving from Windows Server 2022 to 2025</title>
      <link>https://techcommunity.microsoft.com/t5/configuration-manager/moving-from-windows-server-2022-to-2025/m-p/4526041#M387</link>
      <description>&lt;P&gt;And by moving I mean stand up a completely fresh Windows Server 2025 as the old server was patched for one too many times. (painfully slow and stuffy)&lt;/P&gt;&lt;P&gt;What I figured out so far, is to&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;install Windows Server 2025, and the exact same SQL Server 1:1 to the build #&lt;/LI&gt;&lt;LI&gt;install ODBC v18&lt;/LI&gt;&lt;LI&gt;update current MECM to the latest and its OS (update other Microsoft products with windows update)&lt;/LI&gt;&lt;LI&gt;go to sites / maintenance tasks and do an export&lt;/LI&gt;&lt;LI&gt;robocopy the "software" folder as is&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Now next would be to shut down old MECM server, rename new to the old's hostname, and start the "recover site"&lt;/P&gt;&lt;P&gt;What my concern is as always "What if" can I at this point or once I set up the new MECM up and running go back by shutting down this new server, and powering on the old (leave and rejoin domain for trust) and go back to business as usual?&lt;BR /&gt;That if anything goes sideways, or things won't get better. By that i mean speeding up things which is the main reason of the 'move' which now I do not wish to troubleshoot. Our environment, database size is 7.9 Gb, which is far from being big. The reason must be the update over upgrade over update over 15 years or more no and never brand new OS.&lt;/P&gt;&lt;P&gt;I can take care of the "how to" I know exactly how to recover a site 'on paper'. I just want to know there's no such thing as point of no return. (when not making a single change in the Db/console)&lt;/P&gt;&lt;P&gt;I also understand I should not make any changes in the Db (console) while testing, which is no problem at all. All we use MECM for is staging computers. Nothing else really. Like nothing else at all. PXE. The end.&lt;/P&gt;&lt;P&gt;Thanks for the inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(I hope I picked the right tags)&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2026 03:50:02 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/configuration-manager/moving-from-windows-server-2022-to-2025/m-p/4526041#M387</guid>
      <dc:creator>GabeCz</dc:creator>
      <dc:date>2026-06-06T03:50:02Z</dc:date>
    </item>
    <item>
      <title>Intune macOS ADE: support for minimum macOS version enforcement before Platform SSO registration</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like to ask whether Microsoft Intune has any supported method, roadmap, or recommended workaround for enforcing a minimum or target macOS version during Automated Device Enrollment before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;The scenario is macOS zero-touch deployment with Intune, Automated Device Enrollment, Setup Assistant with modern authentication, Await final configuration, and Platform SSO registration during ADE.&lt;/P&gt;&lt;P&gt;Platform SSO registration during Setup Assistant depends on newer macOS capabilities. In addition, some macOS deployment scenarios, such as Platform SSO password sync and macOS LAPS, may require or strongly benefit from a specific macOS version being installed before the user completes enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, Intune can manage macOS software updates after enrollment using Declarative Device Management software update policies. However, that does not fully solve the issue where the Mac starts ADE on an older macOS version. In that case, the device may begin Setup Assistant and Platform SSO registration before the required macOS version is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am looking for is an Intune-native equivalent of enforcing a minimum or target macOS version during ADE, before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally, the macOS ADE enrollment profile in Intune would support options such as:&lt;/P&gt;&lt;P&gt;- Minimum required macOS version&lt;/P&gt;&lt;P&gt;- Target specific macOS version&lt;/P&gt;&lt;P&gt;- Target specific build, if supported&lt;/P&gt;&lt;P&gt;- Latest eligible macOS version for the device&lt;/P&gt;&lt;P&gt;- Apply the OS update before Platform SSO registration and final configuration&lt;/P&gt;&lt;P&gt;- Reporting in Intune showing whether the ADE OS update was required, started, completed, skipped, or failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without this capability, organizations using Intune-only macOS deployment may still need manual IT staging or macOS restore/update before handing devices to users. This weakens the zero-touch deployment model, especially when adopting Platform SSO registration during Automated Device Enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is there currently any supported way in Intune to enforce a minimum or target macOS version during ADE before Setup Assistant continues?&lt;/P&gt;&lt;P&gt;2. Is this capability on the Intune roadmap?&lt;/P&gt;&lt;P&gt;3. Are there any recommended workarounds for organizations deploying Platform SSO registration during ADE where a specific macOS version is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance from the Intune team or the community.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 20:56:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</guid>
      <dc:creator>KacperM</dc:creator>
      <dc:date>2026-06-04T20:56:14Z</dc:date>
    </item>
    <item>
      <title>8 hour wait time for Intune when "Configuring team site libraries to sync automatically"</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/8-hour-wait-time-for-intune-when-quot-configuring-team-site/m-p/4524954#M23527</link>
      <description>&lt;P&gt;I hate this, we dont want to wait for this long to find out it doesnt work because we forgot a curly bracket!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fix this or give us a solution to manually push this config policy out so we can see it working immediately!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More exclamation marks!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 21:54:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/8-hour-wait-time-for-intune-when-quot-configuring-team-site/m-p/4524954#M23527</guid>
      <dc:creator>bdenison</dc:creator>
      <dc:date>2026-06-02T21:54:41Z</dc:date>
    </item>
    <item>
      <title>AMA: Visibility and control across devices with Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-visibility-and-control-across-devices-with-intune/ec-p/4524903#M5987</link>
      <description>&lt;P&gt;This AMA is designed for IT teams looking to cut through the noise and gain clearer insight into what’s really happening across their device estate.&lt;BR /&gt;&lt;BR /&gt;You can’t secure or manage what you can’t fully see. As organizations support more users, more device types, and more ways of working, endpoint management has become increasingly complex. Windows, macOS, iOS, Android, personally-owned devices, frontline workers, remote teams: every layer adds new challenges when it comes to visibility, monitoring, compliance, and troubleshooting.&lt;BR /&gt;&lt;BR /&gt;Come ready to talk through the sometimes messy realities of endpoint management in today's world. Let's talk about inconsistent reporting, missing signals, compliance blind spots, alert fatigue, cross-platform management, and the challenge of turning raw data into meaningful action. Want to know if your reporting is giving you the full picture? Curious where organizations typically lose visibility or struggle with enforcement at scale? Wondering how others are approaching analytics, monitoring, and troubleshooting across multiple platforms? Bring your toughest questions and compare notes directly with Microsoft experts and peers navigating the same challenges in Intune every day.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;I'm in. How do I participate?&lt;/H2&gt;
&lt;P&gt;Sign in to the Tech Community, select &lt;STRONG&gt;Add to Calendar&lt;/STRONG&gt; and &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders. Post your questions (early and often!) in the Comments below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-color-custom-0078d4 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-0066cc lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;" data-unlink="true"&gt;This session is part of the &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/tech-community-live-microsoft-intune-edition/4524892" target="_blank" rel="noopener" data-lia-auto-title="Tech Community Live: Intune Edition" data-lia-auto-title-active="0"&gt;&lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;&lt;/A&gt;. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:31:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-visibility-and-control-across-devices-with-intune/ec-p/4524903#M5987</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-02T18:31:07Z</dc:date>
    </item>
    <item>
      <title>AMA: Keeping up with security, compliance, and the pace of change</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-keeping-up-with-security-compliance-and-the-pace-of-change/ec-p/4524902#M5986</link>
      <description>&lt;P&gt;Security and compliance aren’t standing still—and neither is Intune. With new features, enforcement changes, SDK requirements, and evolving security expectations arriving at a rapid pace, IT teams are under constant pressure to stay current without disrupting productivity or overwhelming administrators. Join this Ask Microsoft Anything (AMA) session to discuss the challenges of managing security, compliance, and updates at scale in a fast-moving cloud environment.&lt;BR /&gt;&lt;BR /&gt;This is an interactive event so you guide the discussion. From patching strategies, compliance policies, and app protection to reducing operational overhead while maintaining a strong security posture, we'll be here to answer your questions. Whether you’re navigating changing compliance requirements, trying to simplify policy management, or working to balance security with a seamless user experience, come explore practical approaches for staying secure, compliant, and ready for what’s next with Intune.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;I'm in. How do I participate?&lt;/H2&gt;
&lt;P&gt;Sign in to the Tech Community, select &lt;STRONG&gt;Add to Calendar&lt;/STRONG&gt; and &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders. Post your questions (early and often!) in the Comments below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-color-custom-0078d4 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-0066cc lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;" data-unlink="true"&gt;This session is part of the &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/tech-community-live-microsoft-intune-edition/4524892" target="_blank" rel="noopener" data-lia-auto-title="Tech Community Live: Intune Edition" data-lia-auto-title-active="0"&gt;&lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;&lt;/A&gt;. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:29:22 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-keeping-up-with-security-compliance-and-the-pace-of-change/ec-p/4524902#M5986</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-02T18:29:22Z</dc:date>
    </item>
    <item>
      <title>AMA: Deployment made easy with Intune and Windows Autopilot</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-deployment-made-easy-with-intune-and-windows-autopilot/ec-p/4524899#M5985</link>
      <description>&lt;P&gt;Join this Ask Microsoft Anything (AMA) to dive into the real-world deployment scenarios organizations are navigating every day.&lt;BR /&gt;&lt;BR /&gt;A successful Intune deployment is about more than getting devices enrolled. You want a reliable, secure, and frustration-free experience from day one yet even experienced IT teams can run into unexpected challenges during rollout and ongoing management. Small missteps can quickly impact productivity and user trust.&lt;BR /&gt;&lt;BR /&gt;Have questions about Windows Autopilot configuration, dynamic groups, enrollment strategies, app packaging and delivery, troubleshooting failed deployments, deployment rings, and avoiding policy conflicts that can lock users out or disrupt workflows? Whether you’re just getting started or refining a mature deployment strategy, this AMA is your opportunity to connect directly with Microsoft experts, share challenges, and learn practical approaches for building a smoother, more resilient deployment experience with Intune.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;I'm in. How do I participate?&lt;/H2&gt;
&lt;P&gt;Sign in to the Tech Community, select &lt;STRONG&gt;Add to Calendar&lt;/STRONG&gt; and &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders. Post your questions (early and often!) in the Comments below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-color-custom-0078d4 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-0066cc lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;" data-unlink="true"&gt;This session is part of the &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/tech-community-live-microsoft-intune-edition/4524892" target="_blank" rel="noopener" data-lia-auto-title="Tech Community Live: Intune Edition" data-lia-auto-title-active="0"&gt;&lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;&lt;/A&gt;. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:27:34 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/ama-deployment-made-easy-with-intune-and-windows-autopilot/ec-p/4524899#M5985</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-02T18:27:34Z</dc:date>
    </item>
    <item>
      <title>On premises to cloud native: Your Intune setup AMA</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/on-premises-to-cloud-native-your-intune-setup-ama/ec-p/4524895#M5984</link>
      <description>&lt;P&gt;Moving to Intune isn’t just about replacing legacy management tools; it’s about rethinking how devices are deployed, secured, and managed in a cloud-first world. But where should you start? How do you avoid recreating old processes that add complexity, slow down users, or limit the value of cloud-native management? Join our Ask Microsoft Anything (AMA) session to explore the strategies, lessons learned, and real-world considerations that can help you build a simpler, more scalable endpoint management approach with Intune.&lt;BR /&gt;&lt;BR /&gt;Bring your questions about device strategy, co-management vs. cloud-only management, policy design, security baselines, user experience tradeoffs, and more. Whether you’re planning a new deployment, modernizing existing processes, or trying to reduce administrative overhead, this AMA is an opportunity to talk directly with Microsoft experts about the decisions, challenges, and best practices shaping modern endpoint management today.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;I'm in. How do I participate?&lt;/H2&gt;
&lt;P&gt;Sign in to the Tech Community, select &lt;STRONG&gt;Add to Calendar&lt;/STRONG&gt; and &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders. Post your questions (early and often!) in the Comments below.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-background-color-22 lia-border-color-custom-0078d4 lia-border-style-dotted" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-0066cc lia-border-style-dotted"&gt;
&lt;P style="margin: 10px; line-height: 140%; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px;" data-unlink="true"&gt;This session is part of the &lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/tech-community-live-microsoft-intune-edition/4524892" target="_blank" rel="noopener" data-lia-auto-title="Tech Community Live: Intune Edition" data-lia-auto-title-active="0"&gt;&lt;STRONG&gt;Tech Community Live: Intune Edition&lt;/STRONG&gt;&lt;/A&gt;. View the full agenda for more AMAs! This session will also be recorded and available on demand shortly after conclusion of the live event.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:27:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/on-premises-to-cloud-native-your-intune-setup-ama/ec-p/4524895#M5984</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-02T18:27:53Z</dc:date>
    </item>
    <item>
      <title>Tech Community Live: Microsoft Intune edition</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune-events/tech-community-live-microsoft-intune-edition/ec-p/4524892#M5983</link>
      <description>&lt;P&gt;Save your spot and tune in for a brand-new Intune edition of Tech Community Live! Whether you need help with your cloud-native management strategy, tackling Windows Autopilot and enrollment challenges, strengthening security and compliance, or trying to gain better visibility across your device fleet, this event is your chance to get real-world guidance and ask the questions top of mind for your organization.&lt;/P&gt;
&lt;P&gt;Bring your toughest deployment scenarios, policy debates, troubleshooting pain points, and “how are other IT teams handling this?” questions for a lively, practical conversation designed to help you optimize endpoint management with more confidence—and maybe learn a few new tricks along the way.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;I'm in. How do I participate?&lt;/H2&gt;
&lt;P&gt;Excited for three hours of interactive Ask Microsoft Anything (AMA) sessions with the engineers, product experts, and teams behind Microsoft Intune? Great! &lt;BR /&gt;&lt;BR /&gt;Sign in to the Tech Community, select&amp;nbsp;&lt;STRONG&gt;Add to Calendar&lt;/STRONG&gt; and &lt;STRONG&gt;Attend&lt;/STRONG&gt; to receive event reminders. Visit each AMA page and do the same. Post your questions (early and often!) in the Comments section on each AMA page.&lt;/P&gt;
&lt;H2 style="margin-top: 36px; margin-bottom: 20px; font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 600; font-size: 20px; color: #333333;"&gt;Agenda: June 23, 2026&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 99.9344%; height: 319.334px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-custom-0078d4" style="height: 44.6667px;"&gt;&lt;td class="lia-align-left lia-vertical-align-middle" style="height: 44.6667px;"&gt;
&lt;P style="margin-left: 8px; margin-bottom: 0px;"&gt;&lt;SPAN style="color: #ffffff;"&gt;TIME&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left lia-vertical-align-middle" style="height: 44.6667px;"&gt;
&lt;P style="margin-left: 8px; margin-bottom: 0px;"&gt;&lt;SPAN style="color: #ffffff;"&gt;TOPIC&lt;/SPAN&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 20px;"&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;8:00 AM PDT&lt;BR /&gt;3:00 PM UTC&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/on-premises-to-cloud-native-your-intune-setup-ama/4524895" target="_blank" rel="noopener" data-lia-auto-title="On premises to cloud native: Your Intune setup AMA" data-lia-auto-title-active="0"&gt;On premises to cloud native: Your Intune setup AMA&lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 20px;"&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;9:00 AM PDT&lt;BR /&gt;4:00 PM UTC&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-deployment-made-easy-with-intune-and-windows-autopilot/4524899" target="_blank" rel="noopener" data-lia-auto-title="AMA: Deployment made easy with Intune and Windows Autopilot" data-lia-auto-title-active="0"&gt;AMA: Deployment made easy with Intune and Windows Autopilot&lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 20px;"&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;10:00 AM PDT&lt;BR /&gt;5:00 PM UTC&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-keeping-up-with-security-compliance-and-the-pace-of-change/4524902" target="_blank" rel="noopener" data-lia-auto-title="AMA: Keeping up with security, compliance, and the pace of change" data-lia-auto-title-active="0"&gt;AMA: Keeping up with security, compliance, and the pace of change&lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 20px;"&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;10:30 AM PDT&lt;BR /&gt;5:30 PM UTC&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-left lia-vertical-align-center" style="height: 20px;"&gt;
&lt;P style="font-family: 'Segoe UI', Segoe, Tahoma, Geneva, sans-serif; font-weight: 400; font-size: 16px; margin-left: 8px; margin-bottom: 0px;"&gt;&lt;A href="https://techcommunity.microsoft.com/event/microsoftintuneevents/ama-visibility-and-control-across-devices-with-intune/4524903" target="_blank" rel="noopener" data-lia-auto-title="AMA: Visibility and control across devices with Intune" data-lia-auto-title-active="0"&gt;AMA: Visibility and control across devices with Intune&lt;/A&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 21.0446%" /&gt;&lt;col style="width: 78.9053%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 02 Jun 2026 18:42:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune-events/tech-community-live-microsoft-intune-edition/ec-p/4524892#M5983</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-02T18:42:42Z</dc:date>
    </item>
    <item>
      <title>Intune App inventory Graph</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-app-inventory-graph/m-p/4524828#M23524</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've enabled the configuration profile to receive app inventory data in Intune.&lt;/P&gt;&lt;P&gt;In the GUI the data I can view the data just fine, but I would like to use Graph to automate this data and create custom reports.&lt;/P&gt;&lt;P&gt;When I use the following &lt;A class="lia-external-url" href="https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties')" target="_blank"&gt;https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties')&lt;/A&gt; I get an error: &lt;EM&gt;"Forbidden - 403 - 199 ms Either the signed-in user does not have sufficient privileges, or you need to consent to one of the permissions on the Modify permissions tab"&lt;/EM&gt; even though the docs I can find about permissions are OK.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 12:46:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-app-inventory-graph/m-p/4524828#M23524</guid>
      <dc:creator>RobV</dc:creator>
      <dc:date>2026-06-02T12:46:44Z</dc:date>
    </item>
    <item>
      <title>Add Security Key Support to Microsoft Authenticator and Managed Home Screen</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/add-security-key-support-to-microsoft-authenticator-and-managed/m-p/4524037#M23511</link>
      <description>undefined</description>
      <pubDate>Fri, 29 May 2026 13:57:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/add-security-key-support-to-microsoft-authenticator-and-managed/m-p/4524037#M23511</guid>
      <dc:creator>AbeSummers</dc:creator>
      <dc:date>2026-05-29T13:57:01Z</dc:date>
    </item>
  </channel>
</rss>

