<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Intune Customer Success articles</title>
    <link>https://techcommunity.microsoft.com/t5/intune-customer-success/bg-p/IntuneCustomerSuccess</link>
    <description>Intune Customer Success articles</description>
    <pubDate>Tue, 29 Sep 2026 12:51:24 GMT</pubDate>
    <dc:creator>IntuneCustomerSuccess</dc:creator>
    <dc:date>2026-09-29T12:51:24Z</dc:date>
    <item>
      <title>Microsoft Intune and Apple OS 27: New settings, support, and platform changes</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-and-apple-os-27-new-settings-support-and/ba-p/4559764</link>
      <description>&lt;P&gt;With Apple's release of OS 27, we’ve been working hard to ensure that Microsoft Intune provides support for Apple’s latest operating systems (OS) so that existing features work as expected, and adding support for new features that were introduced at WWDC.&lt;/P&gt;
&lt;P&gt;We’ll continue to upgrade our service and release new capabilities that integrate elements of the new OS versions.&lt;/P&gt;
&lt;H2&gt;New DDM configurations and settings&lt;/H2&gt;
&lt;P&gt;With continued investments in the Intune data-driven infrastructure that powers the settings catalog, we’re able to provide day zero support for new OS settings as they’re released by Apple. We’ve updated the settings catalog to support newly released iOS/iPadOS and macOS settings for both declarative device management (DDM) and mobile device management (MDM) to empower your IT teams to have devices ready for the latest OS release. Configurations that have been updated include:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;App settings (DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Control which apps can launch on supervised iPhone, iPad, Apple TV, and Apple Vision Pro devices and which binaries can run on supervised Macs using allow and deny rules. Define organization-suggested privacy permission defaults for apps - including camera, microphone, Bluetooth, location, local network, dictation, and accessibility - to present users with a single consolidated consent prompt.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Intelligence settings (DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Control Apple Intelligence capabilities, including Visual Intelligence, Writing Tools, Genmoji, Image Playground, app-specific features in Mail, Notes, and Safari, and requirements for on-device dictation and translation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Accessibility settings &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Configure organization-defined accessibility preferences - such as display, text, motion, audio, and interaction options - so supported settings can be applied consistently on managed devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Safari settings &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Manage Safari behavior and privacy, including cookies, fraud warnings, history clearing, JavaScript, pop-ups, private browsing, summaries, new-tab start pages, and website camera or microphone permission defaults.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Siri settings &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Control Siri availability and behavior, including Siri AI features, user-generated content, access while the device is locked, profanity filtering, and reduction of sensitive content.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Content caching &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Configure the macOS Content Caching service to store Apple-distributed software and iCloud content locally, define the clients and networks it serves, and optimize parent, peer, storage, and network behavior to reduce internet bandwidth use.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;DNS Proxy &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Configure a DNS proxy network extension to handle device DNS traffic, including the provider app and its vendor-defined settings, so name-resolution requests can be routed through an organization-approved service.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Web content filter &lt;/STRONG&gt;&lt;STRONG&gt;(DDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Configure a plug-in-based web content filter to inspect and control network traffic using an approved filtering app, with provider, authentication, and filtering settings appropriate to the organization.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Login window (MDM)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Customize the macOS login window and sign-in experience, including the information shown to users and the login options and controls available on managed Macs. Located under the &lt;STRONG&gt;Login Window&lt;/STRONG&gt; category.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information on configuring these new settings using the settings catalog is available at &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/configuration/settings-catalog?tabs=sc-search-filter%2Csc-reporting" target="_blank" rel="noopener"&gt;create a policy using settings catalog in Microsoft Intune&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;New keys to skip Setup Assistant panes&lt;/H2&gt;
&lt;P&gt;We recently added our new enrollment policies experience based on data-driven infrastructure that powers the settings catalog. This enables Intune to quickly and easily add new Skip Keys such as Liquid Glass and Accessibility Appearance. A list of Setup Assistant panes that can be managed is available in our &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/apple/setup-automated-ios#setup-assistant-screen-reference" target="_blank" rel="noopener"&gt;Setup Assistant screen reference&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Streamline AppleCare cases with enhanced logging support&lt;/H2&gt;
&lt;P&gt;Microsoft Intune now supports Apple's Enhanced Logging device action on supported supervised devices running a compatible OS release. Administrators can start an AppleCare diagnostic-log collection session using an AppleCare-provided token and monitor device-reported status through DDM, reducing the need to coordinate manual log collection with the device user. More information is available in our device actions documentation for &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/actions/apple-enhanced-logging" target="_blank" rel="noopener"&gt;Enhanced logging&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Support updates for legacy MDM workloads&lt;/H2&gt;
&lt;P&gt;As more workloads are shifting to DDM, Apple is ending support for the following legacy MDM commands and payloads, which means they’ll no longer be updated or supported. You should instead manage these workloads using DDM through the settings catalog, which contains the latest settings.&lt;/P&gt;
&lt;P&gt;MDM payloads that are now deprecated with OS 27 include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Content caching service&lt;/LI&gt;
&lt;LI&gt;DNS settings&lt;/LI&gt;
&lt;LI&gt;DNS proxy&lt;/LI&gt;
&lt;LI&gt;Parental controls application restrictions&lt;/LI&gt;
&lt;LI&gt;Privacy preferences policy control&lt;/LI&gt;
&lt;LI&gt;Passcode&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Multiple settings have been deprecated in the MDM Restrictions payload, and we recommend using the equivalent DDM configuration to manage these features. The table below provides the new DDM location for these deprecated settings.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;DDM Configuration&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Deprecated MDM Settings&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;App Settings&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL style="margin: 0; padding-left: 20px;"&gt;
&lt;LI&gt;Allow Listed App Bundle IDs&lt;/LI&gt;
&lt;LI&gt;Blocked App Bundle IDs&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;External Intelligence Settings&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL style="margin: 0; padding-left: 20px;"&gt;
&lt;LI&gt;Allowed External Intelligence Workspace IDs&lt;/LI&gt;
&lt;LI&gt;Allow External Intelligence Integrations&lt;/LI&gt;
&lt;LI&gt;Allow External Intelligence Integrations Sign In&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Intelligence Settings&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL style="margin: 0; padding-left: 20px;"&gt;
&lt;LI&gt;Allow Apple Intelligence Report&lt;/LI&gt;
&lt;LI&gt;Allow Genmoji&lt;/LI&gt;
&lt;LI&gt;Allow Image Playground&lt;/LI&gt;
&lt;LI&gt;Allow Image Wand&lt;/LI&gt;
&lt;LI&gt;Allow Personalized Handwriting Results&lt;/LI&gt;
&lt;LI&gt;Allow Visual Intelligence Summary&lt;/LI&gt;
&lt;LI&gt;Allow Writing Tools&lt;/LI&gt;
&lt;LI&gt;Force On Device Only Dictation&lt;/LI&gt;
&lt;LI&gt;Force On Device Only Translation&lt;/LI&gt;
&lt;LI&gt;Allow Mail Smart Replies&lt;/LI&gt;
&lt;LI&gt;Allow Mail Summary&lt;/LI&gt;
&lt;LI&gt;Allow Notes Transcription&lt;/LI&gt;
&lt;LI&gt;Allow Notes Transcription Summary&lt;/LI&gt;
&lt;LI&gt;Allow Safari Summary&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Keyboard Settings&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL style="margin: 0; padding-left: 20px;"&gt;
&lt;LI&gt;Allow Auto Correction&lt;/LI&gt;
&lt;LI&gt;Allow Continuous Path Keyboard&lt;/LI&gt;
&lt;LI&gt;Allow Definition Lookup&lt;/LI&gt;
&lt;LI&gt;Allow Dictation&lt;/LI&gt;
&lt;LI&gt;Allow Keyboard Shortcuts&lt;/LI&gt;
&lt;LI&gt;Allow Predictive Keyboard&lt;/LI&gt;
&lt;LI&gt;Allow Spell Check&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Siri Settings&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL style="margin: 0; padding-left: 20px;"&gt;
&lt;LI&gt;Allow Assistant&lt;/LI&gt;
&lt;LI&gt;Allow Assistant User Generated Content&lt;/LI&gt;
&lt;LI&gt;Allow Assistant While Lock&lt;/LI&gt;
&lt;LI&gt;Force Assistant Profanity Filter&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Apple previously ended support for MDM device configuration templates, and software update commands and settings. These have been removed from OS 27, and you should use DDM for these instead. To align with this change, starting with the October (2610) release, Intune will remove the following legacy workloads from the Microsoft Intune admin center:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;iOS/iPadOS update policies&lt;/LI&gt;
&lt;LI&gt;macOS update policies&lt;/LI&gt;
&lt;LI&gt;macOS software updates report (per-device)&lt;/LI&gt;
&lt;LI&gt;iOS update installation failures&lt;/LI&gt;
&lt;LI&gt;macOS update installation failures&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;More information on this change is available in the support tip: &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/support-tip-move-to-declarative-device-management-for-apple-software-updates/4432177" target="_blank" rel="noopener" data-lia-auto-title="Move to declarative device management for Apple software updates" data-lia-auto-title-active="0"&gt;Move to declarative device management for Apple software updates&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Support statement for “supported” versus “allowed” versions for user-less Apple devices&lt;/H2&gt;
&lt;P&gt;As new operating system updates are released throughout the year by Apple, Intune plans to support critical functionality that comes with each new OS version. With the release of iOS/iPadOS and macOS 26, we’ll continue with our existing model for enrolling user-less devices for supported and allowed OS versions to keep enrolled devices secure and efficient.&lt;/P&gt;
&lt;P&gt;This includes devices enrolling without user affinity (user-less devices), such as shared iPads and devices enrolling through Automated Device Enrollment (ADE) without user affinity. We highly recommend updating your organization’s devices to the most recent Apple OS version publicly available to keep your devices secure and up to date.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Supported&lt;/STRONG&gt; OS versions means that user-less devices running the three most recent iOS/iPadOS versions are fully supported by Intune. Devices running iOS/iPadOS 26.x, 18.x, and 17.x can enroll and take advantage of all Intune MDM functionality that is applicable to user-less devices, and all new eligible features will work on these devices. Allowed OS versions let you enroll user-less devices running an unsupported iOS/iPadOS version within the three versions of the supported range. These devices can use eligible Intune features supported by the MDM protocol, but OS changes, bugs, or other issues might affect functionality. Devices enrolled with user affinity or apps that rely on user sign-in will continue to not be supported.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;User-less enrollment and feature support&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Capability&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Supported&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Allowed&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Applicable Versions&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Three most recent versions (N-2):
&lt;UL style="margin: 8px 0 0 0; padding-left: 20px;"&gt;
&lt;LI&gt;iOS/iPadOS 18.x and later&lt;/LI&gt;
&lt;LI&gt;macOS 15.x and later&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Up to three versions below the supported version (N-5):
&lt;UL style="margin: 8px 0 0 0; padding-left: 20px;"&gt;
&lt;LI&gt;iOS/iPadOS 16.x and later&lt;/LI&gt;
&lt;LI&gt;macOS 13.x and later&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Can Enroll&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;User-less Eligible Intune MDM Features&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes. May be impacted by breaking OS features, bugs, or issues.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;User Affinity Enrollment&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Apps That Require User Sign-In&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Yes&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;No&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;For more details, review our blog &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/support-statement-for-supported-versus-allowed-versions-for-user-less-apple-devi/3484657" target="_blank" rel="noopener" data-lia-auto-title="Support statement for supported versus allowed versions for user-less Apple devices" data-lia-auto-title-active="0"&gt;Support statement for supported versus allowed versions for user-less Apple devices&lt;/A&gt; to learn more.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Intune MAM controls and updates&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;As you plan for the new features and changes with the latest OS release, we wanted to highlight additions with the latest Intune App SDK. With Intune App SDK for iOS v21.8.0 or later, organizations can take advantage of the following Intune MAM updates. Apps must be integrated with SDK v21.8.0 or later to support the experiences described below. As always, we recommend keeping apps updated with the latest SDK.&lt;/P&gt;
&lt;H3&gt;Refreshed app protection user experience&lt;/H3&gt;
&lt;P&gt;We’ve modernized the Intune app protection experience on iOS to make policy interactions clearer and more intuitive. The refreshed experience includes updated prompts and full-screen messaging, clearer account context on conditional launch screens such as the MAM PIN screen, and a &lt;STRONG&gt;Remove Account&lt;/STRONG&gt; option that lets users remove a blocked managed account and its organizational data from the app. This is a user experience update only, with no changes to app functionality or app protection policies.&lt;/P&gt;
&lt;H3&gt;Control Siri onscreen awareness for organizational data&lt;/H3&gt;
&lt;P&gt;The &lt;STRONG&gt;Screen capture&lt;/STRONG&gt; &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/protection/ref-settings-ios#functionality" target="_blank" rel="noopener"&gt;app protection policy setting&lt;/A&gt; now controls whether Siri onscreen awareness can access work or school data.&lt;/P&gt;
&lt;P&gt;Set &lt;STRONG&gt;Screen capture&lt;/STRONG&gt; to &lt;STRONG&gt;Block&lt;/STRONG&gt; to prevent the &lt;STRONG&gt;Ask Siri&lt;/STRONG&gt; option from appearing in the context menu for organizational data. If the setting remains &lt;STRONG&gt;Allow&lt;/STRONG&gt;, which is the default value, users can share organizational data through Siri onscreen awareness.&lt;/P&gt;
&lt;P&gt;The updates require apps to use the Intune App SDK for iOS version &lt;STRONG&gt;21.8.0 or later&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Bookmark the &lt;A href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0" target="_blank"&gt;Microsoft Intune Blog&lt;/A&gt; and follow us on&amp;nbsp;&lt;A href="https://www.linkedin.com/company/microsoft-intune-product" target="_blank"&gt;LinkedIn &lt;/A&gt; or&amp;nbsp;&lt;A href="https://twitter.com/MSIntune" target="_blank"&gt;@MSIntune &lt;/A&gt;and&amp;nbsp;&lt;A href="https://x.com/IntuneSuppTeam" target="_blank"&gt;@IntuneSuppTeam &lt;/A&gt;on X to continue the conversation. &lt;/EM&gt;Stay tuned to &lt;A class="lia-external-url" href="https://aka.ms/IntuneWN" target="_blank"&gt;What’s new in Intune&lt;/A&gt; for additional settings and capabilities that will soon be available.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Sep 2026 22:48:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-and-apple-os-27-new-settings-support-and/ba-p/4559764</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-09-24T22:48:40Z</dc:date>
    </item>
    <item>
      <title>Moving from Windows Autopilot to Windows Autopilot device preparation</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/moving-from-windows-autopilot-to-windows-autopilot-device/ba-p/4557269</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Maggie Dakeva, Senior Product Manager - Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Organizations have spent years refining Windows Autopilot deployments. Profiles, Enrollment Status Page settings, group tags, dynamic groups, application assignments, and support processes all work together to deliver a familiar provisioning experience.&lt;/P&gt;
&lt;P&gt;Windows Autopilot device preparation is a re-architecture of Windows Autopilot designed around the customer asks we hear most often: simpler configuration, faster and more reliable setup, clearer progress for users, and near real-time deployment reporting for administrators. A single &lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/tutorial/user-driven/entra-join-autopilot-policy" target="_blank"&gt;device preparation policy&lt;/A&gt; brings deployment and the out-of-box experience (OOBE) settings together, &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/setup-time-grouping" target="_blank"&gt;enrollment time grouping (ETG)&lt;/A&gt; places devices into the right security group during enrollment, and granular application and PowerShell script status makes troubleshooting easier.&lt;/P&gt;
&lt;P&gt;Autopilot device preparation is now the recommended solution for user-driven scenarios. Future engineering investments will focus on Windows Autopilot device preparation, enabling organizations to benefit from ongoing improvements to provisioning, reliability, reporting, and support. Moving eligible deployments positions your organization to benefit from those ongoing improvements while reducing the complexity of provisioning and support.&lt;/P&gt;
&lt;P&gt;So how do you move without disrupting devices that are already working - or forcing every deployment scenario to transition at once?&lt;/P&gt;
&lt;P&gt;The answer is a phased approach.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/compare" target="_blank"&gt;Windows Autopilot and Windows Autopilot device preparation&lt;/A&gt; can coexist in the same organization. You can move eligible user-driven Microsoft Entra join populations in controlled waves, validate the full experience, and keep scenarios that still require Windows Autopilot on their existing path.&lt;/P&gt;
&lt;P&gt;The result is a practical way to adopt a simpler provisioning model while protecting the investments and workflows your organization still depends on.&lt;/P&gt;
&lt;H2&gt;Start with the outcome, not a one-for-one migration&lt;/H2&gt;
&lt;P&gt;Windows Autopilot device preparation brings enrollment settings, OOBE, device naming, required applications, PowerShell scripts, and enrollment-time targeting into a more coherent policy flow. The device preparation page, which replaces the Enrollment status page, gives users clearer progress and gives administrators more detailed deployment status for troubleshooting.&lt;/P&gt;
&lt;P&gt;Windows Autopilot device preparation includes two complementary capabilities:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Device preparation policy&lt;/STRONG&gt; defines the deployment experience, including OOBE settings, applications, scripts, naming, and ETG.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/device-association/overview" target="_blank"&gt;Device association&lt;/A&gt; optionally binds a physical device to your organization before enrollment. It can establish corporate ownership and tenant affinity, enable associated-device OOBE settings, and support direct per-device policy assignment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Based on organizational needs, customers can choose to use device preparation policy, device association, or both. Device preparation policy provides the deployment configuration and experience, while device association adds pre-enrollment device affinity and device-based capabilities. Organizations can adopt each capability where it adds value to their provisioning model.&lt;/P&gt;
&lt;P&gt;But moving to that model shouldn't mean recreating every Windows Autopilot object exactly as it exists today.&lt;/P&gt;
&lt;P&gt;Instead, begin with the outcome each device population needs. Identify the required OOBE behavior, applications, scripts, naming, assignments, and support experience. Then design the device preparation policy and ETG model that delivers that outcome.&lt;/P&gt;
&lt;P&gt;This approach reduces inherited complexity and helps ensure that the new deployment is designed for Windows Autopilot device preparation and not constrained by the architecture it replaces.&lt;/P&gt;
&lt;H2&gt;Choose what moves - and what stays&lt;/H2&gt;
&lt;P&gt;Windows Autopilot device preparation is the recommended path for eligible user-driven provisioning scenarios, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Corporate-owned Windows 11 devices&lt;/LI&gt;
&lt;LI&gt;User-driven Microsoft Entra join&lt;/LI&gt;
&lt;LI&gt;Windows 365&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Continue using Windows Autopilot for scenarios that aren't supported or recommended for transition, including:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/pre-provision" target="_blank"&gt;Pre-provisioning&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/self-deploying" target="_blank"&gt;Self-deploying mode&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/windows-autopilot-hybrid" target="_blank"&gt;Hybrid Microsoft Entra join&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/configmgr/comanage/autopilot-enrollment" target="_blank"&gt;Autopilot into co-management&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This isn't an all-or-nothing decision. The right transition plan deliberately separates eligible populations from valid exceptions.&lt;/P&gt;
&lt;H2&gt;Translate the provisioning model&lt;/H2&gt;
&lt;P&gt;Several familiar Windows Autopilot concepts have a corresponding role in Windows Autopilot device preparation:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Windows Autopilot Concept&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Windows Autopilot Device Preparation Model&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Deployment profile&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Device preparation policy&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Enrollment Status Page profile&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Device preparation policy&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Enrollment Status Page in OOBE&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Device preparation page in OOBE&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;P&gt;Windows Autopilot registration&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Optional device association&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Profile and dynamic group-based targeting based on group tags&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Granular device preparation policy assignment with enrollment time grouping (ETG) using Microsoft Entra static security groups&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Device name template defined in the Autopilot deployment profile&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Device name template defined in the device preparation policy&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Windows Autopilot deployments report&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Windows Autopilot device preparation deployments report&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;The goal is to preserve the required customer and administrator experience - not every historical configuration object.&lt;/P&gt;
&lt;H2&gt;How the transition flow works&lt;/H2&gt;
&lt;P&gt;A controlled transition can follow eight steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Define the eligible population:&lt;/STRONG&gt; Start with corporate-owned Windows 11 devices using user-driven Microsoft Entra join. Exclude scenarios that should remain on Windows Autopilot.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Design enrollment time grouping (ETG):&lt;/STRONG&gt; Create assigned, static Microsoft Entra security groups for populations that genuinely differ by location, role, device type, or required configuration. Don't build the new design around a group tag or a device object that must exist before enrollment.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Create device preparation policy equivalents:&lt;/STRONG&gt; Inventory each deployment profile and Enrollment Status Page pairing. Map the required OOBE settings, naming, applications, PowerShell scripts, blocking requirements, and dependencies into the new device preparation policy.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Evaluate whether device association is required for all scenarios.&lt;/STRONG&gt; For user-targeted deployments that don't need pre-enrollment tenant affinity or per-device policy selection, the organization can use the device preparation policy without device association and simplify the setup and management of device onboarding. For devices that need automatic corporate ownership, OOBE customization settings, or stronger pre-enrollment trust, continue with step 5.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pre-associate eligible devices.&lt;/STRONG&gt; For existing registered or enrolled devices, collect the pre-association information by &lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/tutorial/user-driven/entra-join-device-association#export-device-information-from-oobe" target="_blank"&gt;collecting the diagnostics logs&lt;/A&gt;, then exporting the DeviceLink CSV file found in the logs. Upload the CSV in the Associated devices blade in Intune and assign a device preparation policy to the device. Assignment can be done during the CSV upload process or after. Confirm that the device reaches the &lt;STRONG&gt;Pre-associated&lt;/STRONG&gt; state before its planned reset or refresh.&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV style="border-left: 4px solid #0078D4; background-color: #f3f9fd; padding: 16px; margin: 16px 0; border-radius: 4px;"&gt;
&lt;P style="margin: 0;"&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; Device pre-association is only available for devices that meet the &lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/requirements" target="_blank" rel="noopener noreferrer"&gt; minimum OS and hardware requirements &lt;/A&gt;, including &lt;STRONG&gt;TPM 2.0&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;OL start="6"&gt;
&lt;LI&gt;&lt;STRONG&gt;Pilot the complete OOBE experience.&lt;/STRONG&gt; Start with new devices or reset a small, representative set of devices. Validate policy selection, ETG placement, applications, scripts, naming, progress reporting.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Expand and pre-associate remaining devices.&lt;/STRONG&gt; Pre-associate additional populations in controlled waves. You do not need to force resets to all existing enrolled devices but simply pre-associate to prepare them so they enroll via the Windows Autopilot device preparation flow whenever each device next undergoes a natural or required reset.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Retire registered flows. &lt;/STRONG&gt;Retire deployment profiles, Enrollment Status Page profiles, groups, registrations, and processes only after reporting confirms that no active or planned population still depends on them.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Pre-association doesn’t reset the device or disrupt its current use. The device remains enrolled and productive until its next natural or required reset, when Windows Autopilot device preparation takes effect.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Don't remove the Windows Autopilot registration early.&lt;/STRONG&gt; Doing so can remove Autopilot properties and affect dynamic-group membership that supports the device's current configuration.&lt;/P&gt;
&lt;P&gt;The next time the device enters OOBE, Windows recognizes the association and follows the Windows Autopilot device preparation path. If a device is both registered and associated, association takes precedence. Plan the pilot around this behavior rather than expecting an automatic fallback to Windows Autopilot.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;OEM and partner note:&lt;/STRONG&gt; Device association uploads are currently only supported through Intune. OEM and partner pre-association scenarios aren't supported yet, but they’re on the roadmap.&lt;/P&gt;
&lt;H2&gt;What this means for your organization&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;You can prepare existing devices for transition while they remain enrolled and in use.&lt;/LI&gt;
&lt;LI&gt;You can move one eligible population at a time instead of committing to an organization-wide cutover.&lt;/LI&gt;
&lt;LI&gt;You can preserve Windows Autopilot for scenarios that still require it.&lt;/LI&gt;
&lt;LI&gt;You can use the transition to simplify assignment and provisioning logic rather than carry every legacy object forward.&lt;/LI&gt;
&lt;LI&gt;You can retire the old configuration gradually - after validation and dependency checks confirm that nothing still relies on it.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;A sample customer pilot setup scenario&lt;/H2&gt;
&lt;P&gt;Consider a multinational organization, Contoso, that uses group tags to distinguish devices in the United Kingdom and Germany and to identify different device use cases. Dynamic groups use those tags to determine which deployment profile, Enrollment Status Page configuration, applications, policies, scope tags, and naming rules apply. The organization wants to move its eligible user-driven Windows 11 populations to Windows Autopilot device preparation without reproducing the same pre-created record and dynamic-group dependencies.&lt;/P&gt;
&lt;P&gt;The Contoso deployment team transitions to Autopilot device preparation with the following steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Create static security groups for each required configuration.&lt;/STRONG&gt; The team creates assigned Microsoft Entra security groups such as &lt;STRONG&gt;User Devices UK&lt;/STRONG&gt; and &lt;STRONG&gt;User Devices Germany&lt;/STRONG&gt;. It creates separate groups only when location, role, device type, scope, or required configuration differs.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Create a device preparation policy for each population.&lt;/STRONG&gt; The team creates a policy such as &lt;STRONG&gt;User Devices UK DPP&lt;/STRONG&gt; and &lt;STRONG&gt;User Devices Germany DPP&lt;/STRONG&gt;. Each policy contains the required OOBE settings, applications, PowerShell scripts, blocking behavior, and device name template, and identifies the corresponding enrollment time grouping (ETG) security group.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assign the device preparation policies to each population.&lt;/STRONG&gt; The team assigns each device preparation policy to the respective sets of devices at time of pre-association or later. During enrollment, the device joins the group selected by the device preparation policy. For example, devices assigned the &lt;STRONG&gt;User Devices UK DPP&lt;/STRONG&gt; join the &lt;STRONG&gt;User Devices UK&lt;/STRONG&gt; group and receive the apps and policies assigned to that group.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Configure scope through the static groups.&lt;/STRONG&gt; The team assigns the appropriate regional scope tag to each ETG security group. The device receives the associated scope tag when it joins the group during enrollment.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Set a naming template for each device preparation policy.&lt;/STRONG&gt; The organization uses a naming convention where devices start with a prefix indicating their location. The team sets &lt;CODE&gt;UK-%SERIAL%&lt;/CODE&gt; in &lt;STRONG&gt;User Devices UK DPP&lt;/STRONG&gt; and &lt;CODE&gt;DE-%SERIAL%&lt;/CODE&gt; in &lt;STRONG&gt;User Devices Germany DPP&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pre-associate pilot devices without disruption.&lt;/STRONG&gt; Selected devices can be pre-associated while they remain enrolled and in use. The team collects diagnostics logs via script, extracts the DeviceLink CSV files, imports them in Intune, confirms the devices reach the &lt;STRONG&gt;Pre-associated&lt;/STRONG&gt; state, and keeps the Windows Autopilot registration in place until the approved reset or refresh window.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate the end-to-end experience with representative devices.&lt;/STRONG&gt; The admin team uses test devices representing each target population to verify policy assignment, static group membership, scope tags, naming, applications, scripts, reporting, and successful completion of the device preparation flow. Existing devices can remain in service until their next natural or required reset.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;img&gt;&lt;EM&gt;Figure 1: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Seven-step regional Windows Autopilot device preparation rollout workflow, from creating security groups and device preparation policies through regional configuration, pilot association, and device validation.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This scenario is illustrative, not a completed deployment or a measured customer outcome. It shows the transition pattern: define the supported scope, replace group-tag dependencies with ETG, move Enrollment Status Page and deployment profile settings to the device preparation policy, decide where device association adds value, validate end to end, and expand in controlled waves.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Begin with one eligible user-driven Microsoft Entra join population. Map its current Windows Autopilot outcomes to enrollment time grouping (ETG) and a device preparation policy. Pre-associate a representative pilot, validate the complete reset-to-desktop experience, and expand only when the results meet your deployment and support criteria.&lt;/P&gt;
&lt;P&gt;Moving to Windows Autopilot device preparation doesn't require a forced cutover. It requires a clear boundary, a deliberately redesigned assignment model, and evidence from each wave.&lt;/P&gt;
&lt;P&gt;That gives IT a controlled path toward simpler provisioning while keeping every device population on the experience that supports it best.&lt;/P&gt;
&lt;H2&gt;Learn more&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/overview" target="_blank"&gt;Windows Autopilot device preparation overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/compare" target="_blank"&gt;Compare Windows Autopilot device preparation and Windows Autopilot&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/tutorial/user-driven/entra-join-workflow" target="_blank"&gt;Windows Autopilot device preparation user-driven Microsoft Entra join workflow&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/requirements" target="_blank"&gt;Windows Autopilot device preparation requirements&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;We’d love to hear your feedback! Share your thoughts in the comments below, follow us on&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/IntuneLinked" target="_blank"&gt;LinkedIn&lt;/A&gt;&amp;nbsp;or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank"&gt;@IntuneSuppTeam&lt;/A&gt; or &lt;A class="lia-external-url" href="https://aka.ms/MSIntune" target="_blank"&gt;@MSIntune&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2026 23:03:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/moving-from-windows-autopilot-to-windows-autopilot-device/ba-p/4557269</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-09-16T23:03:15Z</dc:date>
    </item>
    <item>
      <title>From GPO to Microsoft Intune: A practical guide to cloud-first policy management</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/from-gpo-to-microsoft-intune-a-practical-guide-to-cloud-first/ba-p/4551946</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Per Larsen - Senior Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;For many organizations, Group Policy Objects (GPOs) remain an important part of Windows configuration. As device strategies expand to include cloud-native management, Microsoft Intune provides the policy platform for devices that are Microsoft Entra joined and managed from the cloud. The goal isn’t to force every organization through the same migration, it’s to choose the right management path for each device population and each setting.&lt;/P&gt;
&lt;P&gt;This guide explains three common paths: starting fresh for new cloud-native devices, selectively transitioning required settings to Intune, and coordinating GPO with Intune for hybrid Microsoft Entra joined or co-managed devices. Across all three paths, the recommended principle is the same: assess and rationalize existing policy before deciding what to retain, re-create, redesign, or retire.&lt;/P&gt;
&lt;H1&gt;1. Choose the right path for each device population&lt;/H1&gt;
&lt;P&gt;GPO was designed primarily for domain-joined, on-premises devices. Intune, in contrast, is designed for cloud-based management of devices whether they are on or off prem. The right path will depend on the scenario in which the devices are joined and managed.&lt;/P&gt;
&lt;H3&gt;Scenario 1: Start fresh for new cloud-native devices&lt;/H3&gt;
&lt;P&gt;This is the recommended approach for new Microsoft Entra joined devices. Invest in the cloud-first configuration you need today rather than reproducing every historical GPO. Begin with mandatory security requirements, Microsoft-recommended security baselines, and essential settings for services such as OneDrive and Microsoft Edge. Add other settings only when there’s business, security, or operational requirement.&lt;/P&gt;
&lt;H3&gt;Scenario 2: Selectively transition required settings&lt;/H3&gt;
&lt;P&gt;Organizations that need to preserve specific behavior can assess and rationalize existing GPOs, then re-create only the settings that are supported and necessary in Intune. Treat this as a deliberate replatforming effort, not a one-to-one copy. Test each new profile with a pilot group before broad deployment.&lt;/P&gt;
&lt;H3&gt;Scenario 3: Coordinate GPO and Intune for hybrid devices&lt;/H3&gt;
&lt;P&gt;Hybrid Microsoft Entra joined devices may receive settings from both GPO and Intune, including common scenarios where Intune-managed workloads or Windows Autopatch are used for existing hybrid domain-joined devices. Use of both group policy and Intune policy enforcement can continue for an extended period, but you should plan carefully to avoid conflicting settings. Organizations can either leave existing GPOs in place until devices are rebuilt as cloud-native, or actively shift selected policy areas to Intune while the devices remain hybrid joined.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1. A cloud-first policy workflow begins with assessment and rationalization, then applies the appropriate path for each device population.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;2. Assess and rationalize before you transition&lt;/H2&gt;
&lt;P&gt;Before changing policy source, understand what’s actually in use. Many environments contain GPOs that are old, undocumented, duplicated, or applied more broadly than intended. A direct lift-and-shift carries that technical debt into Intune.&lt;/P&gt;
&lt;H3&gt;Key assessment actions&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Export all GPOs from &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-server/identity/ad-ds/manage/group-policy/group-policy-management-console" target="_blank"&gt;Group Policy Management Console (GPMC).&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc733160(v=ws.11)" target="_blank"&gt;Gpresult&lt;/A&gt; and operational knowledge to identify which GPOs are still applied and functional.&lt;/LI&gt;
&lt;LI&gt;Remove or archive unused, legacy, or duplicated policies instead of transitioning them.&lt;/LI&gt;
&lt;LI&gt;Categorize required settings by security, update management, device restrictions, application control, and legacy or unsupported scenarios.&lt;/LI&gt;
&lt;LI&gt;Record the device populations and business requirements associated with each policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;3. Use Group Policy Analytics as an assessment input&lt;/H2&gt;
&lt;P&gt;Microsoft Intune includes &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/intune-service/configuration/group-policy-analytics" target="_blank"&gt;Group Policy Analytics&lt;/A&gt;, a built-in tool that imports on-premises GPOs and reports their mapped support in mobile device management. It can help identify settings with Intune equivalents, deprecated settings, and configurations that may require another implementation approach.&lt;/P&gt;
&lt;P&gt;Use the report as one source of evidence rather than as a complete transition engine. Its mappings may not reflect every setting currently available in the Settings Catalog, especially settings added after the analytics mapping was last updated. Validate important settings directly in Intune and against current Microsoft documentation.&lt;/P&gt;
&lt;H3&gt;Useful outcomes&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Highlights settings with documented Intune mappings.&lt;/LI&gt;
&lt;LI&gt;Surfaces GPO settings that no longer make sense for cloud-native devices.&lt;/LI&gt;
&lt;LI&gt;Helps identify GPOs that should be retired rather than re-created.&lt;/LI&gt;
&lt;LI&gt;Supports, but does not replace, business validation and pilot testing.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;4. Don't lift and shift: Re-design for cloud-first management&lt;/H2&gt;
&lt;P&gt;A direct copy of GPOs into Intune can reproduce policy sprawl and create new conflicts. Instead, use the assessment to determine the intended outcome of each setting. Some settings will be unnecessary, some will have a direct Intune settings catalog equivalent, and others will need a cloud-appropriate redesign.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Retire settings that are no longer required.&lt;/LI&gt;
&lt;LI&gt;Re-create settings that are supported and necessary.&lt;/LI&gt;
&lt;LI&gt;Rethink and redesign legacy dependencies such as drive mappings, printers, or vendor-specific prioritizing or considering cloud-first solutions and configurations.&lt;/LI&gt;
&lt;LI&gt;Document the owner, target population, and validation method for each resulting Intune profile.&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 2. Decide whether to retain, re-create, redesign, or retire each GPO based on device type and current business need.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;5. Start with security baselines&lt;/H2&gt;
&lt;P&gt;Security baselines in Intune are curated collections of Microsoft-recommended settings for Windows, Microsoft Edge, and Microsoft Defender. They provide a controlled foundation that can reduce policy sprawl and align devices with current security guidance.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Review baseline settings with security stakeholders rather than applying them without evaluation.&lt;/LI&gt;
&lt;LI&gt;Identify overlaps with existing policies before deployment.&lt;/LI&gt;
&lt;LI&gt;Pilot the baseline with representative devices and users.&lt;/LI&gt;
&lt;LI&gt;Layer additional configuration policies only for documented requirements.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;6. Create equivalent Intune configuration profiles where needed&lt;/H2&gt;
&lt;P&gt;After assessment and baseline planning:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure supported and necessary settings in the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalogs%2Csc-search-filter%2Csc-reporting" target="_blank"&gt;settings catalog&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;Use Administrative Templates or imported ADMX policies for applicable settings.&lt;/LI&gt;
&lt;LI&gt;Use custom configuration, scripts, or remediations only when a built-in option doesn’t meet the requirement.&lt;/LI&gt;
&lt;LI&gt;Use standard or organizational safe rollout practices to assign policies before broad rollout, and monitor deployment and conflict reports.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;7. Coordinate GPO and Intune during a hybrid period&lt;/H2&gt;
&lt;P&gt;Customers often expect GPOWinsOverMDM to act as a universal precedence switch: whenever Group Policy and Intune configure the same setting, GPO should win. In reality, conflict control applies only to the subset of settings exposed through the Windows Policy CSP with corresponding Group Policy mappings.&lt;/P&gt;
&lt;P&gt;Additionally, it doesn’t govern settings delivered through other CSPs, such as Defender or Windows Update. Those policy areas can have different precedence, merging, or conflict behavior. Consequently, using GPOWinsOverMDM as a coexistence strategy can produce inconsistent and difficult-to-predict results.&lt;/P&gt;
&lt;P&gt;The safer approach is to avoid configuring the same setting through both management planes. Use targeted groups, assignment filters, GPO security filtering, and Organizational Units (OU) scoping to establish one authoritative source for each setting and device population.&lt;/P&gt;
&lt;H3&gt;Use selective targeting to move policy areas in controlled stages:&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;In Group Policy, use appropriate OU link placement, security group filtering, and carefully validated Windows Management Instrumentation (WMI) filters to stop selected GPOs from applying to devices that will receive the Intune equivalent.&lt;/LI&gt;
&lt;LI&gt;In Intune, use Microsoft Entra groups, dynamic membership rules, assignment filters, and exclusions to target the intended device population.&lt;/LI&gt;
&lt;LI&gt;For each policy area, document the authoritative management plane and the date or condition for changing ownership.&lt;/LI&gt;
&lt;LI&gt;Validate effective configuration with Gpresult, Intune reports, Event Viewer, and representative pilot devices.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For example, an organization might leave most existing GPOs in place for hybrid joined devices while excluding a pilot group from the Windows Update GPO. The same group can then receive the corresponding Intune update policy. After validation, you can expand the targeting changes in stages in alignment with your organizational safe-rollout standards.&lt;/P&gt;
&lt;H2&gt;8. Common Pitfalls&lt;/H2&gt;
&lt;H3&gt;Enforcing GPO and Intune side by side without coordinated targeting&lt;/H3&gt;
&lt;P&gt;Uncoordinated configuration can create conflicts, inconsistent results, and difficult troubleshooting. Define an authoritative management plane for each setting and device population.&lt;/P&gt;
&lt;H3&gt;Transitioning everything as is&lt;/H3&gt;
&lt;P&gt;You should rationalize old, unused, or duplicated settings rather than reproducing or recreating them in Intune. Supporting legacy or non-cloud-first settings. Some requirements don’t have a direct built-in Intune equivalent. Evaluate whether the requirement is still necessary, then use a supported alternative, redesign the process, or retain the setting in GPO for the applicable hybrid devices.&lt;/P&gt;
&lt;H3&gt;Skipping the pilot phase&lt;/H3&gt;
&lt;P&gt;Pilot groups reveal assignment, compatibility, and user-impact issues before a broad deployment.&lt;/P&gt;
&lt;H2&gt;10. Retire old GPOs gradually&lt;/H2&gt;
&lt;P&gt;Retire a GPO only after its replacement or removal has been validated for the affected device population.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exclude a pilot population from the original GPO and assign the intended Intune configuration.&lt;/LI&gt;
&lt;LI&gt;Validate effective settings, Intune deployment status, device events, and user impact.&lt;/LI&gt;
&lt;LI&gt;Expand the targeting change in controlled stages.&lt;/LI&gt;
&lt;LI&gt;Disable and archive the GPO after dependencies are removed and rollback is no longer required.&lt;/LI&gt;
&lt;LI&gt;Keep GPOs that remain necessary for hybrid joined devices, with clear ownership and targeting.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Conclusion&lt;/H2&gt;
&lt;P&gt;Moving to Intune policy management isn’t a one-size-fits-all migration or a copy-and-paste exercise. For new cloud-native devices, start with a clean, cloud-first configuration. When existing behavior must be preserved, assess and rationalize the requirement before re-creating it in Intune. During a period of parallel Group Policy and Intune management, coordinate targeting so GPO and Intune do not compete for the same settings.&lt;/P&gt;
&lt;P&gt;The key principles are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Choose the management path by device population.&lt;/LI&gt;
&lt;LI&gt;Assess and rationalize before making changes.&lt;/LI&gt;
&lt;LI&gt;Start with security requirements and validated baselines.&lt;/LI&gt;
&lt;LI&gt;Use Group Policy Analytics as an input, not as the sole source of truth.&lt;/LI&gt;
&lt;LI&gt;Transition only supported and necessary settings.&lt;/LI&gt;
&lt;LI&gt;Coordinate GPO and Intune targeting throughout any transition period.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 31 Aug 2026 16:44:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/from-gpo-to-microsoft-intune-a-practical-guide-to-cloud-first/ba-p/4551946</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-08-31T16:44:53Z</dc:date>
    </item>
    <item>
      <title>Introducing device association for Windows Autopilot device preparation</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/introducing-device-association-for-windows-autopilot-device/ba-p/4550603</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Maggie Dakeva, Senior Product Manager - Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;We’ve heard organizations want Windows deployment to be simple for employees and predictable for IT admins. But before a device enrolls, how does the organization know that the device is really one of its own - and how can IT make sure the right experience and policy reach that device regardless of who signs in?&lt;/P&gt;
&lt;P&gt;Today, we're announcing &lt;STRONG&gt;device association for Windows Autopilot device preparation&lt;/STRONG&gt;, a new way to bind a physical Windows 11 device to your organization before enrollment begins.&lt;/P&gt;
&lt;P&gt;Device association uses hardware-backed attestation to create a trusted relationship between the device and your tenant at the start of the provisioning journey. That relationship helps Windows Autopilot device preparation recognize the device during the out-of-box experience (OOBE), automatically treat it as corporate-owned, and apply the experience and policy intended for that specific device.&lt;/P&gt;
&lt;P&gt;The result is a more secure, more consistent, and more device-centric onboarding flow.&lt;/P&gt;
&lt;H2&gt;Start with the device, not just the user&lt;/H2&gt;
&lt;P&gt;Windows Autopilot device preparation already gives IT teams a straightforward way to configure new Windows devices with the apps, scripts, and policies employees need. Device association extends that experience by allowing IT to target a device preparation policy directly to a device before it enrolls.&lt;/P&gt;
&lt;P&gt;This is especially valuable when the deployment experience needs to follow the hardware rather than the person signing in. For example, one employee can enroll multiple devices that serve different purposes, and each device can receive its own device preparation policy. When both device-based and user-based assignments are available, the device-based assignment takes precedence.&lt;/P&gt;
&lt;P&gt;That gives administrators greater confidence that the correct configuration reaches the correct device from the beginning of its lifecycle.&lt;/P&gt;
&lt;H2&gt;Create a simpler out-of-box experience&lt;/H2&gt;
&lt;P&gt;Because an associated device is recognized before enrollment, IT can configure more of the Windows setup experience in advance.&lt;/P&gt;
&lt;P&gt;Device association enables organizations to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Configure Language and region.&lt;/LI&gt;
&lt;LI&gt;Automatically configure the keyboard and skip the keyboard selection page. When the device uses a Wi-Fi network connection during OOBE, the language and keyboard selection screens aren't hidden.&lt;/LI&gt;
&lt;LI&gt;Hide the Microsoft Software License Terms page.&lt;/LI&gt;
&lt;LI&gt;Hide privacy settings during OOBE.&lt;/LI&gt;
&lt;LI&gt;Apply a device name template that uses the serial number or a randomized value.&lt;/LI&gt;
&lt;LI&gt;Hide account-change options on company sign-in and domain error pages.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These controls reduce the number of decisions an employee must make while setting up a device and help create a consistent, organization-ready experience from the first screen.&lt;/P&gt;
&lt;H2&gt;Strengthen trust before enrollment&lt;/H2&gt;
&lt;P&gt;Device association isn't only an experience improvement. It establishes device trust earlier in the deployment process.&lt;/P&gt;
&lt;P&gt;The association uses hardware-based attestation and TPM-backed cryptographic validation to verify the device's identity. Tenant affinity is stored in the device's UEFI firmware, where it persists across a Windows reset, operating system reinstallation, or removal of enrollment.&lt;/P&gt;
&lt;P&gt;This durable, hardware-backed relationship helps ensure that the device presenting itself for preparation is the device the organization intended to onboard.&lt;/P&gt;
&lt;P&gt;Associated devices are also automatically marked as corporate-owned. If your organization blocks personally owned Windows devices with Intune enrollment restrictions, device association can be used instead of uploading a separate corporate identifier. You can continue to use corporate identifiers where they fit your process, but an associated device doesn't need both.&lt;/P&gt;
&lt;H2&gt;How the device association flow works&lt;/H2&gt;
&lt;P&gt;Device association is designed as a clear workflow that starts with IT and finishes automatically during OOBE:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Create the device preparation policy.&lt;/STRONG&gt; Configure the apps, scripts, deployment settings, OOBE experience, and optional device name template that should apply.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Export the device information.&lt;/STRONG&gt; During OOBE, a technician opens the Autopilot menu and exports the DeviceLink CSV with the device information required for pre-association to a USB. For an existing device, the same information can be collected from Autopilot diagnostic logs.&lt;/LI&gt;
&lt;/OL&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1. The Windows Autopilot menu with Assign device association selected.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;&lt;img&gt;&lt;EM&gt;Figure 2. The Assign device association screen confirms that device link information was exported to a removable drive.&lt;/EM&gt;&lt;/img&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;Pre-associate the device in Intune.&lt;/STRONG&gt; In the Microsoft Intune admin center, go to &lt;STRONG&gt;Devices&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Enrollment&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Device association&lt;/STRONG&gt; &amp;gt; &lt;STRONG&gt;Devices&lt;/STRONG&gt;, upload the CSV, and optionally assign a device preparation policy directly to the device.&lt;BR /&gt;&lt;img&gt;&lt;EM&gt;Figure 3. The Associated devices page in the Microsoft Intune admin center shows a successfully uploaded pre-associated device.&lt;/EM&gt;&lt;/img&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Complete association.&lt;/STRONG&gt; When the device connects to a network in OOBE, it finds the pre-association record and completes association automatically. A technician can also trigger this step manually from the Autopilot menu.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enroll and prepare the device.&lt;/STRONG&gt; The device receives the applicable device-targeted policy, is marked as corporate-owned, and presents the configured OOBE experience.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Monitor the deployment.&lt;/STRONG&gt; Administrators can review association state and assigned policy in the Device association blade and filter devices by state, policy, manufacturer, or model.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The device association lifecycle consists of the following states:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Pre-associated:&lt;/STRONG&gt; The device was added on the service side and is waiting to complete association in OOBE.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Associated:&lt;/STRONG&gt; The device completed association by writing the tenant affinity to UEFI and is ready for enrollment. This happens automatically when a pre-associated device syncs with an MDM provider.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Pending removal:&lt;/STRONG&gt; A request to remove the pre-association is being processed.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A device's association can be removed by an administrator or partner with physical access to the device who manually runs a local script that clears the tenant affinity information stored in the device's UEFI. This action should be performed only when the device should no longer be associated with the organization, such as when it is sold, recycled, or transferred.&lt;/P&gt;
&lt;H2&gt;Manage the full device lifecycle&lt;/H2&gt;
&lt;P&gt;The association remains with the device through reset and reinstallation, helping preserve the organization's intended provisioning path when a device is redeployed internally.&lt;/P&gt;
&lt;P&gt;When a device permanently leaves the organization - for example, when it's sold, recycled, or transferred—the association should be removed as part of decommissioning. Because the tenant affinity is stored on the device, clearing a completed association can be performed via script locally on the physical device, without access to the service.&lt;/P&gt;
&lt;P&gt;This lifecycle model is intentional: association is durable during normal reuse inside the organization, while permanent removal can be completed by an admin or partner who has control of the physical device.&lt;/P&gt;
&lt;H2&gt;Designed to work alongside your existing Windows Autopilot strategy&lt;/H2&gt;
&lt;P&gt;Device association is part of Windows Autopilot device preparation and can coexist with traditional Windows Autopilot deployments in the same organization.&lt;/P&gt;
&lt;P&gt;For a device already registered with Windows Autopilot, the association state determines which deployment runs. If the device isn't associated, its Windows Autopilot registration takes precedence. If it is associated, the Windows Autopilot device preparation deployment takes precedence.&lt;/P&gt;
&lt;P&gt;This gives organizations a practical path to introduce device association while continuing to support existing Windows Autopilot investments.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;To use device association, you'll need a supported physical Windows 11 device with TPM 2.0 enabled and in a healthy state. Virtual machines aren't supported because device association relies on hardware-backed identity verification.&lt;/P&gt;
&lt;P&gt;Start by reviewing the Windows Autopilot device association requirements, then create or update your Windows Autopilot device preparation policy. From there, export the device information, pre-associate the device in Intune, and let Windows complete the trusted association during OOBE.&lt;/P&gt;
&lt;P&gt;With device association, Windows Autopilot device preparation moves device trust, targeting, and customization earlier in the deployment journey - before enrollment and before the employee reaches the desktop.&lt;/P&gt;
&lt;P&gt;That means fewer setup decisions for users, more predictable deployments for IT, and stronger confidence that the right device is joining the right organization with the right configuration.&lt;/P&gt;
&lt;H2&gt;Learn more&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/device-association/overview" target="_blank" rel="noopener"&gt;Overview of Windows Autopilot device association&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/device-association/requirements" target="_blank" rel="noopener"&gt;Requirements for Windows Autopilot device association&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/device-preparation/tutorial/user-driven/entra-join-device-association" target="_blank" rel="noopener"&gt;Set up Windows Autopilot device preparation with device association&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 27 Aug 2026 15:00:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/introducing-device-association-for-windows-autopilot-device/ba-p/4550603</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-08-27T15:00:00Z</dc:date>
    </item>
    <item>
      <title>Remote Help on Windows: Unattended Support with Remote Sign-In Is Here</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/remote-help-on-windows-unattended-support-with-remote-sign-in-is/ba-p/4549772</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Rodolfo Bermudez | Sr. Product Manager &amp;amp; Kara Wang | Product Manager 2 - Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Helpdesk teams have long asked for a way to remotely troubleshoot Windows devices without needing the user to be present. Whether it’s after-hours maintenance on a shared device in a call center, or a device sitting idle at a remote office, waiting for a user to be available shouldn’t be the blocker to getting work done.&lt;/P&gt;
&lt;P&gt;With Intune’s August release, we’re excited to announce &lt;STRONG&gt;Remote Help Windows Unattended Support with Remote Sign-In&lt;/STRONG&gt; a new capability that lets helpdesk staff remotely access physical Windows devices by signing in with credentials they have access to, without requiring the user to grant access or even be logged in.&lt;/P&gt;
&lt;H2&gt;Why this matters&lt;/H2&gt;
&lt;P&gt;Previously, every Remote Help session on Windows required the user to be present at the device to accept the connection. Now Remote Help Windows Unattended Support enables:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;After-hours support - &lt;/STRONG&gt;Devices that need maintenance outside business hours can be serviced without scheduling time with users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Improved Helpdesk efficiency - &lt;/STRONG&gt;Tier 2 support staff don't spend extra time coordinating schedules that often take only minutes to fix.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remote locations get the help they need - &lt;/STRONG&gt;Branch offices without on-site IT have path to immediate remediation.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;With unattended capabilities your helpdesk connects directly to the Windows login screen, authenticates with their own credentials, and works in a separate Windows session, all while the user’s session remains safely locked and preserved.&lt;/P&gt;
&lt;H2&gt;What the feature enables&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Capability&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Details&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Remote Access Without User Presence&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Helpers can sign in with their own credentials and establish a new Windows session on the target device, even when no user is actively connected.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Session Isolation&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The user's existing session remains locked and preserved, preventing disruption while support activities are performed in a separate session.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Security-First Design&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Uses least-privilege access, a dedicated RBAC permission, and a complete audit trail to help maintain security and compliance requirements.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;User Awareness&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;If a user is currently signed in, they receive a notification and can choose to accept or reject the remote access request.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Rich Session Features&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Supports file transfer, clipboard passthrough, Remote Desktop Virtual Printer, multi-monitor support, and other productivity-enhancing capabilities.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Prerequisites&lt;/H2&gt;
&lt;H3&gt;Licensing&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;Remote Help is included with Microsoft Intune Suite, Remote Help standalone add-on, or Microsoft 365 E3/E5.&lt;/LI&gt;
&lt;LI&gt;Remote Help must be enabled in the tenant. You can find step-by-step instructions in the following article: &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/remote-help/deploy?tabs=macos#configure-remote-help-for-your-tenant" target="_blank" rel="noopener"&gt;Deploy Remote Help with Microsoft Intune&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Device requirements&lt;/H3&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Requirement&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Details&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Ownership&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Supports corporate-owned enrolled devices that are &lt;STRONG&gt;Microsoft Entra joined&lt;/STRONG&gt; or &lt;STRONG&gt;Hybrid Microsoft Entra joined&lt;/STRONG&gt;. Personal and BYOD devices aren't supported.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Platform&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Requires physical Windows devices running &lt;STRONG&gt;x64-based operating systems&lt;/STRONG&gt;. Virtual machines aren't currently supported.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Device State&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The device must be powered on, connected to the internet, able to reach the required Microsoft service endpoints, and have the &lt;STRONG&gt;Intune Management Extension&lt;/STRONG&gt; installed.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H3&gt;Role-based access control (RBAC) permission&lt;/H3&gt;
&lt;P&gt;This feature uses a dedicated permission: &lt;STRONG&gt;Remote Help app &amp;gt; Windows unattended control remote sign-in&lt;/STRONG&gt;. It must be explicitly assigned to helpdesk roles targeting specific device groups. To maintain a higher security boundary, this permission isn’t included in any Intune built-in role, including existing roles such as Help Desk Operator or School Administrator, and must be granted through a custom role assignment.&lt;/P&gt;
&lt;DIV style="border-left: 4px solid #0078D4; background-color: #f3f9fd; padding: 16px; margin: 16px 0; border-radius: 4px;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Tip: Limit Access to Unattended Support&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Consider creating a dedicated custom role for &lt;STRONG&gt;unattended support&lt;/STRONG&gt; rather than including it in your standard Remote Help roles. Because unattended access enables support sessions without an end user present, it's a best practice to restrict this capability to &lt;STRONG&gt;Tier 2 and Tier 3 support staff&lt;/STRONG&gt; or senior administrators, and scope access only to the devices they are responsible for managing.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P style="margin-bottom: 0;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Remote Help app settings in the Microsoft Intune admin center showing enabled and disabled permissions, including elevation, screen viewing, full control, and Windows unattended control at remote sign-in.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H3&gt;How to set it up&lt;/H3&gt;
&lt;H4&gt;Step 1: Configure RBAC&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;In the Intune admin center, go to Tenant administration &amp;gt; Roles&lt;/LI&gt;
&lt;LI&gt;Create or edit a custom role&lt;/LI&gt;
&lt;LI&gt;Under Permissions &amp;gt; Remote Help app, enable Windows unattended control remote sign-in&lt;/LI&gt;
&lt;LI&gt;Assign to your helpdesk groups, scoping to the device groups that should receive unattended support&lt;/LI&gt;
&lt;/OL&gt;
&lt;H4&gt;Step 2: Deploy Azure Virtual Desktop agents&lt;/H4&gt;
&lt;P&gt;&lt;STRONG&gt;Required agents&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2310011" target="_blank" rel="noopener"&gt;Azure Virtual Desktop Agent&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://go.microsoft.com/fwlink/?linkid=2311028" target="_blank" rel="noopener"&gt;Azure Virtual Desktop Agent Bootloader&lt;/A&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Package both the AVD Agent MSI and AVD Agent Bootloader MSI as Win32 apps in Intune. Deploy to the same target device groups that are intended to receive unattended support from Step 1. No ongoing maintenance is required - the components auto-update.&lt;/P&gt;
&lt;H4&gt;Step 3: Enable Remote Desktop&lt;/H4&gt;
&lt;OL&gt;
&lt;LI&gt;Go to Devices &amp;gt; Windows &amp;gt; Configuration profiles &amp;gt; Create profile&lt;/LI&gt;
&lt;LI&gt;Platform: Windows 10 and later | Profile type: Settings catalog&lt;/LI&gt;
&lt;LI&gt;Add setting: Search for Remote Desktop &amp;gt; Enable "Allow users to connect remotely using Remote Desktop"&lt;/LI&gt;
&lt;LI&gt;Assign to your target device groups&lt;/LI&gt;
&lt;LI&gt;Verify: Devices &amp;gt; Configuration profiles &amp;gt; Device status&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;The helper experience: A walkthrough&lt;/H2&gt;
&lt;H3&gt;Starting the session&lt;/H3&gt;
&lt;P&gt;From the Intune admin center, navigate to the target device and select "..." &amp;gt; New remote assistance session. A side panel appears with two options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Initiate attended control: sessions in which a signed-in end user is present and grants access to the helper&lt;/LI&gt;
&lt;LI&gt;Initiate unattended control: sessions in which an authorized helper can access and control an Intune managed device without a signed in end user present&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Select Initiate unattended control and click Select.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 2: Microsoft Intune admin center device overview with the Remote Help panel open, showing the option to initiate an unattended control session on a corporate Windows device.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H3&gt;Built-in safety checks&lt;/H3&gt;
&lt;P&gt;Before connecting, the Intune portal validates several conditions:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Condition&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;What You'll See&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Missing RBAC Permission&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The unattended control option is disabled and displays the message: &lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"You can only select session types for which you have permission."&lt;/EM&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Personal Device&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The unattended control option is disabled and displays: &lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"Unattended control is not available on personal devices."&lt;/EM&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Device Noncompliant&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;A warning appears indicating the device doesn't meet your organization's security or compliance requirements.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Device Offline&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The connection attempt fails and displays: &lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;"Make sure the user's device is on and connected to the internet."&lt;/EM&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Missing Prerequisites&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;P&gt;The Remote Help pane in the Intune admin center indicates that required agents, policies, permissions, or device settings haven't been configured.&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 3: &lt;/EM&gt;&lt;EM style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune Remote Help panel displaying a notice that unattended control is unavailable for a personally owned device, with session options disabled.&lt;/EM&gt;&lt;/img&gt;
&lt;H3&gt;Connection progress and success&lt;/H3&gt;
&lt;P&gt;A progress panel shows real-time status: "Starting unattended session on user’s device" followed by green checkmarks when successful, with an "Open Remote Help" link.&lt;/P&gt;
&lt;P&gt;If the connection fails, for example because the device is offline or there is a network connectivity related issue, you’ll see a clear error with a Retry option.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 4: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune Remote Help panel confirming that an unattended remote session has started on a managed Windows device, with a link to open Remote Help.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This will launch a new browser tab opening the Windows App (web client). The helper may need to authenticate again using the same username and credentials used to authenticate to Intune Admin portal.&lt;/P&gt;
&lt;H3&gt;Signing in to the remote device&lt;/H3&gt;
&lt;P&gt;Once connected, the helper then needs to authenticate to the device within the remote session. You can sign in using a local Windows account (ComputerName\UserName), an Active Directory domain account (Domain\UserName or UPN), or a Microsoft Entra ID account (UPN), whichever is appropriate based on the join state of the device and the scenario. Least privilege is enforced - a standard user account does not gain Administrator permissions.&lt;/P&gt;
&lt;H3&gt;When a user is currently signed in&lt;/H3&gt;
&lt;P&gt;If someone is actively using the device, the helper sees: "Another user is signed in. If you continue, they’ll be disconnected. Do you want to sign in anyway?"&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 5: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Windows sign-in screen displaying a prompt warning that another user is signed in and asking whether to continue with a remote sign-in session.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;Choosing "Yes" locks the user’s session (preserving their work) and connects the helper to a separate Windows session.&lt;/P&gt;
&lt;H2&gt;The device-side experience&lt;/H2&gt;
&lt;H3&gt;User notification (when someone is present)&lt;/H3&gt;
&lt;P&gt;If a user is signed in, they see a notification: "Do you want to allow the helper to connect to this machine? Click OK to disconnect your session immediately or click Cancel to stay connected. No action will disconnect your session in 30 seconds."&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 6: &lt;/EM&gt;&lt;EM style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Windows 11 desktop showing a Remote Desktop Connection dialog requesting approval for a remote user to connect, with options to allow or cancel the session.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;If they don’t respond in 30 seconds, the unattended session starts automatically.&lt;/P&gt;
&lt;H3&gt;During the session&lt;/H3&gt;
&lt;P&gt;The end user’s console shows their lock screen. They cannot see what the helper is doing. The helper works in a separate Windows session.&lt;/P&gt;
&lt;H3&gt;Taking back control&lt;/H3&gt;
&lt;P&gt;The end user can regain control at any time by signing back into their session from the lock screen. The helper is notified and can choose to disconnect.&lt;/P&gt;
&lt;H3&gt;Monitoring and audit&lt;/H3&gt;
&lt;P&gt;Unattended sessions are fully auditable using the same reporting infrastructure as existing Remote Help:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Session monitoring: Tenant administration &amp;gt; Remote Help &amp;gt; Monitor tab (active sessions, average time, total sessions)&lt;/LI&gt;
&lt;LI&gt;Session history: Remote Help sessions tab with Provider, Recipient, Device, OS, session type (Unattended/Attended), and export capability&lt;/LI&gt;
&lt;LI&gt;Audit logs: Tenant administration &amp;gt; Audit logs - filter by category "RemoteHelp" for complete session lifecycle events&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For detailed step-by-step instructions on monitoring, reporting, and auditing Remote Help sessions, see: &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/remote-help/troubleshoot?tabs=macos" target="_blank" rel="noopener"&gt;Troubleshoot and monitor Remote Help for Microsoft Intune.&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;Security at a glance&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Control&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;How It Works&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Corporate-Only Access&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Only Intune-enrolled, corporate-owned physical devices that are Microsoft Entra joined or Hybrid Microsoft Entra joined are eligible for unattended support.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Explicit RBAC Permission&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Uses a dedicated permission separate from traditional Remote Help scenarios that require user presence. This permission is included in the built-in Intune Help Desk Operator role.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Least Privilege&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;The helper's actions are limited to the permissions associated with the Windows account used to sign in to the target device.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;User Awareness&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;If a user is actively signed in, they receive a notification and a 30-second window to accept or reject the unattended access request.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Session Isolation&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Support occurs in a separate Windows session, keeping the user's active session locked and preventing access to in-use applications or data.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Full Audit Trail&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;All unattended support sessions are logged to support auditing, compliance reviews, and operational accountability.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;12-Hour Maximum Session Duration&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Unattended sessions automatically terminate after 12 hours to help reduce security risk and prevent abandoned connections.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Key things to remember&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Things to Keep in Mind&lt;/H2&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; margin-bottom: 10px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;Three setup steps:&lt;/STRONG&gt; RBAC role + AVD agents + Remote Desktop config profile, all targeting the same device groups.&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; margin-bottom: 10px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;Corporate-owned physical devices only:&lt;/STRONG&gt; Personal and virtual devices are not supported at GA.&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; margin-bottom: 10px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;Dedicated RBAC permission:&lt;/STRONG&gt; Use &lt;EM&gt;Windows unattended control remote sign-in&lt;/EM&gt;.&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; margin-bottom: 10px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;Devices must be online:&lt;/STRONG&gt; Sleep, hibernate, and powered-off devices cannot receive unattended sessions.&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; margin-bottom: 10px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;User sessions are preserved:&lt;/STRONG&gt; If a user is signed in, their session is locked, not terminated.&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e1e1e1; padding: 12px 16px; border-radius: 4px;"&gt;✅ &lt;STRONG&gt;Auto-updating agents:&lt;/STRONG&gt; The AVD agent updates automatically, so no ongoing deployment maintenance is required.&lt;/DIV&gt;
&lt;H2&gt;Frequently asked questions&lt;/H2&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Can I start an unattended session from the Remote Help app?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;No. Unattended sessions can only be initiated from the device page in the Intune admin center.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;What if a user rejects the connection?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;If they click Cancel, nothing happens and the session doesn't start.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;What happens if no one responds to the notification?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;After 30 seconds with no response, the unattended session starts automatically.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Does this work on Windows 365 or AVD?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;We are working towards providing support for Windows 365 and Azure Virtual Desktop in the future.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;What's the maximum session length?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Sessions can last up to 12 hours. After 12 hours, the session automatically disconnects. This limit isn't configurable.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="background: #f7f7f7; border: 1px solid #e5e5e5; border-radius: 8px; padding: 20px; margin: 16px 0;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;What credentials can I use to sign in?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Users can sign in using a local Windows account (ComputerName\UserName), an Active Directory domain account (Domain\UserName or UPN), or a Microsoft Entra ID account (UPN), whichever is appropriate based on the join state of the device and the scenario.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H2&gt;Resources to learn more&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/fundamentals/remote-help-windows" target="_blank" rel="noopener"&gt;Remote Help overview&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://www.microsoft.com/microsoft-365/roadmap" target="_blank" rel="noopener"&gt;Microsoft 365 Roadmap&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/fundamentals/role-based-access-control" target="_blank" rel="noopener"&gt;Role-based access control (RBAC) with Microsoft Intune&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Remote Help Documentation: &lt;A class="lia-external-url" href="https://aka.ms/remotehelpdocs" target="_blank" rel="noopener"&gt;aka.ms/remotehelpdocs&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;EM&gt;We’d love to hear your feedback! Share your thoughts in the comments below, follow us on&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/IntuneLinked" target="_blank" rel="noopener"&gt;LinkedIn&lt;/A&gt;&amp;nbsp;or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; or &lt;A class="lia-external-url" href="https://aka.ms/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2026 16:39:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/remote-help-on-windows-unattended-support-with-remote-sign-in-is/ba-p/4549772</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-08-25T16:39:03Z</dc:date>
    </item>
    <item>
      <title>Support tip: Restore the Managed Home Screen Exit PIN</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-restore-the-managed-home-screen-exit-pin/ba-p/4549102</link>
      <description>&lt;P&gt;We identified and resolved a recent issue (IT1450132) that could cause the configured Managed Home Screen exit PIN to be removed from some existing Android Enterprise when updating older device configuration policies. &amp;nbsp;While a fix has been deployed to address this, if a policy was already affected, you will need update the affected policy or policies and ensure the Exit Kiosk Mode PIN is set before saving.&lt;/P&gt;
&lt;H2&gt;What you might see&lt;/H2&gt;
&lt;P&gt;On an affected device, selecting &lt;STRONG&gt;Exit kiosk&lt;/STRONG&gt; can display a message that a PIN to exit kiosk mode has not been set by the IT administrator, even though the policy was previously configured with one. See an example screenshot below. Note that this screen will also show on devices where you’ve intentionally disabled the Exit kiosk feature.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Android device in kiosk mode displaying a message that no PIN has been configured to exit kiosk mode and advising the user to contact an administrator.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;Update the affected policy&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;In the Microsoft Intune admin center, open the device restrictions policy assigned to the affected Android Enterprise dedicated devices.&lt;/LI&gt;
&lt;LI&gt;Under &lt;STRONG&gt;Device experience&lt;/STRONG&gt;, confirm that &lt;STRONG&gt;Leave kiosk mode&lt;/STRONG&gt; is set to &lt;STRONG&gt;Enable&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Enter a new 4-6 digit value for &lt;STRONG&gt;Leave kiosk mode code&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Save the policy and allow it to deploy to the affected devices.&lt;/LI&gt;
&lt;LI&gt;Verify that the new PIN can be used to exit kiosk mode.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The previous PIN cannot be recovered after it has been removed, so a new PIN is required. For more information, see &lt;A href="https://learn.microsoft.com/intune/device-configuration/templates/ref-device-restrictions-android-enterprise" target="_blank" rel="noopener"&gt;Android template device settings list to restrict features using Intune&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If you need temporary access before the updated policy reaches a device, use the &lt;A href="https://learn.microsoft.com/intune/device-management/actions/suspend-managed-home-screen" target="_blank" rel="noopener"&gt;Suspend Managed Home Screen device action&lt;/A&gt;, provided the documented prerequisites are met.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 2: Microsoft Intune admin center showing Android Enterprise device restriction settings, with the “Leave kiosk mode” option enabled and a kiosk exit code configured.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;The service-side issue has been resolved. Administrators with previously affected policies should configure and deploy a new Managed Home Screen exit PIN, then verify the behavior on their devices.&lt;/P&gt;
&lt;P&gt;We’ll continue to update this post as new information becomes available. If you have questions or comments for the Intune team, reply to this post or reach out to &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; on X.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2026 21:53:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-restore-the-managed-home-screen-exit-pin/ba-p/4549102</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-08-21T21:53:41Z</dc:date>
    </item>
    <item>
      <title>Configure Delivery Optimization for Windows to save bandwidth and speed up deployments</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/configure-delivery-optimization-for-windows-to-save-bandwidth/ba-p/4547592</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Carlos Diaz - Sr. Product Manager and Jason Sandys - Principal Product Manager | Microsoft Intune&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/do/waas-delivery-optimization" target="_blank" rel="noopener"&gt;Delivery Optimization&lt;/A&gt; is built into Windows and can help reduce bandwidth usage during app and update deployments. Instead of downloading content from the internet every time, devices can download it from nearby devices or a local cache when available.&lt;/P&gt;
&lt;P&gt;Many organizations leave Delivery Optimization at its default settings or disable it entirely. As a result, they may miss opportunities to reduce network traffic, improve deployment performance, and make better use of existing network resources.&lt;/P&gt;
&lt;P&gt;This article focuses on the Delivery Optimization scenarios and the common configurations that Intune admins use most often: large-scale patching, Windows Autopilot provisioning, branch office bandwidth management, and Microsoft Connected Cache for scenarios where peer-to-peer sharing alone isn't enough.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How Delivery Optimization works&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Delivery Optimization is an HTTP downloader with built-in peer-to-peer capabilities available in supported versions of &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/do/waas-delivery-optimization#requirements" target="_blank" rel="noopener"&gt;Windows&lt;/A&gt;. It helps distribute Windows updates, Microsoft 365 Apps updates, Microsoft Defender definition updates, Microsoft Store apps, Intune Win32 apps package and other supported &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/do/waas-delivery-optimization#types-of-download-content-supported-by-delivery-optimization" target="_blank" rel="noopener"&gt;content&lt;/A&gt;. Delivery Optimization checks local sources before falling back to internet content caches.&lt;/P&gt;
&lt;P&gt;The most important Delivery Optimization policy setting is &lt;STRONG&gt;Download Mode&lt;/STRONG&gt;, which determines how devices discover peers.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-custom-d1d1d1 lia-border-style-solid" border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Mode&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Description&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Mode 1 (LAN)&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Devices share content with peers behind the same IP/NAT boundary.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Mode 2 (Group)&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Devices share content within a defined group, such as an Active Directory site, domain, or custom group ID. &lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Recommended&lt;/STRONG&gt; for environments with multiple VLANs or segmented networks.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Mode 3 (Internet)&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Devices can share content with internet peers outside the organization. &lt;BR /&gt;&lt;BR /&gt;This mode is &lt;STRONG&gt;rarely used&lt;/STRONG&gt; in enterprise environments.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Delivery Optimization checks sources in this order:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;LAN or group peers and, if configured, Microsoft Connected Cache in&lt;STRONG&gt; &lt;/STRONG&gt;parallel.&lt;/LI&gt;
&lt;LI&gt;Internet peers, if allowed in the Download Mode setting&lt;/LI&gt;
&lt;LI&gt;Internet content caches, which are always available as the final fallback&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Regardless of the mode you choose, the goal is to keep content download traffic local whenever possible.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Common misconceptions&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Before configuring Delivery Optimization, it's worth addressing a few common misunderstandings we’ve heard from customers.&lt;/P&gt;
&lt;DIV style="border: 1px solid #e5e5e5; border-radius: 8px; padding: 16px; margin: 16px 0; background-color: #fafafa;"&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;&lt;STRONG&gt;"Does Delivery Optimization use my bandwidth to upload content to the internet?"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;In&amp;nbsp;&lt;STRONG&gt;Mode 1 (LAN)&lt;/STRONG&gt;, peer sharing is restricted to your local subnet. Content is only shared with other devices on the same network segment, and no content leaves your LAN. Additionally, you have full control over upload usage through the &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/do/waas-delivery-optimization-reference#monthly-upload-data-cap" target="_blank" rel="noopener noreferrer"&gt;&amp;nbsp;Monthly upload data cap setting&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e5e5e5; border-radius: 8px; padding: 16px; margin: 16px 0; background-color: #fafafa;"&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;&lt;STRONG&gt;"Is Delivery Optimization the same as BranchCache?"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;While both technologies help reduce bandwidth usage, they are built on different architectures and support different scenarios.&amp;nbsp;&lt;STRONG&gt;BranchCache&lt;/STRONG&gt; relies on BranchCache-enabled content servers to cache and distribute content, whereas &lt;STRONG&gt;Delivery Optimization&lt;/STRONG&gt; is built directly into Windows and is designed to work natively with cloud-delivered content, including Windows updates, Microsoft Store apps, and Microsoft 365 Apps.&lt;/P&gt;
&lt;/DIV&gt;
&lt;DIV style="border: 1px solid #e5e5e5; border-radius: 8px; padding: 16px; margin: 16px 0; background-color: #fafafa;"&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;&lt;STRONG&gt;"We disabled Delivery Optimization years ago. Is there any reason to revisit it?"&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0 0 12px 0;"&gt;Yes. Delivery Optimization has evolved significantly and now offers extensive management capabilities through the Intune Settings Catalog. Administrators can configure download modes, define group boundaries, control bandwidth usage, set cache sizes, and limit uploads. If Delivery Optimization was disabled in the past, it may be worth reevaluating your configuration. When properly configured, it can help reduce bandwidth consumption, improve content distribution efficiency, and accelerate update and application deployments.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Essential policies&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The following settings, available in the settings catalog under Delivery Optimization, provide you a strong starting point:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Setting&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Default Value*&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Recommended Value&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;What It Does&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DODownloadMode&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;1 (LAN)&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;1 (LAN)&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Keeps peer-to-peer sharing within your subnet or Delivery Optimization group.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DORestrictPeerSelectionBy&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;1&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Devices discover and peer with others on the same subnet.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DOMaxCacheSize&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;20%&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;20% to 30%&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Amount of local disk space allocated to the Delivery Optimization cache.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DOMinFileSizeToCache&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;50 MB&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;5 MB&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Minimum file size eligible for caching and peer-to-peer distribution.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DOMaxCacheAge&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;259,200 seconds (3 days)&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;1,209,600 seconds (14 days)&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Determines how long cached content remains available before cleanup.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DOMonthlyUploadDataCap&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;20 GB&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;20 GB&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Limits the total amount of data a device can upload to peers each month.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;*The default values in this table are for Windows 11.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;The table above lists common Delivery Optimization settings, their default values, and recommended starting values. However, the best configuration depends on your network topology, device count, update cadence, and whether you’re using Microsoft Connected Cache. Use the scenario guidance below to tune from the baseline. for the full policy reference review:&amp;nbsp; &lt;A class="lia-external-url" href="https://aka.ms/ConfigureDO" target="_blank" rel="noopener"&gt;Configure Delivery Optimization (DO) for Windows&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The defaults provide some immediate value, but organizations often achieve better results by:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Defining peer groups&lt;/LI&gt;
&lt;LI&gt;Increasing cache size&lt;/LI&gt;
&lt;LI&gt;Increasing retention periods&lt;/LI&gt;
&lt;LI&gt;Lowering the minimum file-size threshold when appropriate&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When configuring Delivery Optimization, avoid managing the same setting from multiple locations, such as settings catalog and custom policy. Using the settings catalog as your primary management location can help reduce conflicts and simplify troubleshooting.&lt;/P&gt;
&lt;P&gt;Windows quality updates, feature updates, and Office updates are typically the largest bandwidth consuming events most organizations face. A 1 GB cumulative update pushed to 10,000 devices means 10 TB of traffic from the internet unless Delivery Optimization lets devices share locally. This is where properly configured Delivery Optimization pays for itself immediately.&lt;/P&gt;
&lt;P&gt;Coordinate Delivery Optimization with deployment rings. Start with a small seeder ring, typically 5 to 10 percent of devices, so those devices populate peer caches before broader rings begin hours or days later. If Microsoft Connected Cache is deployed, the same seeder ring also populates the cache node, creating a persistent local source for later rings.&lt;/P&gt;
&lt;H3&gt;Scenario 1. Large-scale update deployments&lt;/H3&gt;
&lt;P&gt;Large scale deployments vary greatly in complexity and challenges. Device count isn’t the only factor to consider. Network infrastructure and configuration can also play a role in your configuration and deployment of Delivery Optimization. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;How you tune Delivery Optimization for large-scale updates depends heavily on your WAN topology. The two most common designs call for different approaches:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Star (hub-and-spoke) topology&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Branches connect to a central hub; internet traffic may be backhauled. Every update byte a branch device pulls from the internet crosses the internal link between the hub and spoke.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Group boundaries:&lt;/STRONG&gt; Identify local LAN configurations at branch locations. If all devices at a branch location are on a single subnet, use DODownloadMode = 1 with DORestrictPeerSelectionBy=1 to restrict peers to that subnet. If a branch site has multiple subnets, DODownloadMode = 2 with a branch-specific DOGroupID is more effective because devices can discover peers throughout the branch instead of being limited to their local subnet.&lt;BR /&gt;
&lt;DIV style="border-left: 4px solid #0078D4; background-color: #f3f9fd; padding: 16px; margin: 16px 0; border-radius: 4px;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Tip: Delivery Optimization Has Evolved&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Many organizations disabled Delivery Optimization during early Windows 10 deployments after experiencing unexpected WAN traffic. At that time, peer sharing controls were far less granular, making it difficult to limit content sharing to devices within the same network or site.&lt;/P&gt;
&lt;P&gt;As a result, some organizations chose to disable Delivery Optimization entirely and missed potential bandwidth savings from peer-to-peer content distribution.&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Today, modern Delivery Optimization policies provide significantly more control through features such as &lt;STRONG&gt;Group mode&lt;/STRONG&gt;, &lt;STRONG&gt;Group IDs&lt;/STRONG&gt;, &lt;STRONG&gt;subnet-based peer restrictions&lt;/STRONG&gt;, bandwidth management settings, and integration with &lt;STRONG&gt;Microsoft Connected Cache&lt;/STRONG&gt;. These capabilities help organizations realize the benefits of peer caching while maintaining tighter control over network traffic.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Bandwidth throttling:&lt;/STRONG&gt; Spoke links are often the bottleneck. Use DOPercentageMaxBackgroundBandwidth to limit Delivery Optimization background downloads to 10% to 25% of available bandwidth during business hours. Configure DOSetHoursToLimitBackgroundDownloadBandwidth to define the hours when those limits apply, then relax or remove the limits outside business hours.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cache retention:&lt;/STRONG&gt; Set DOMaxCacheSize to 40% to 50% and DOMaxCacheAge to match your final deployment ring so cached content survives all ring phase days at branches. Branch peers are the only local sources. They need to hold content long enough for the full ring cycle.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Hub site:&lt;/STRONG&gt; Devices at the hub have direct internet access and also typically have more bandwidth available. Standard cache settings (20% to 30%, 3 days) are usually sufficient.&lt;BR /&gt;
&lt;DIV style="border-left: 4px solid #0078D4; background-color: #f3f9fd; padding: 16px; margin: 16px 0; border-radius: 4px;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Tip: Combine Peer Caching and Microsoft Connected Cache&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;In star (hub-and-spoke) network topologies, &lt;STRONG&gt;Microsoft Connected Cache (MCC)&lt;/STRONG&gt; can deliver the greatest bandwidth savings at central hubs and larger branch offices. By caching frequently requested updates and applications locally, MCC helps reduce the amount of content that must traverse upstream WAN links.&lt;/P&gt;
&lt;P&gt;You can configure an MCC server directly in your Delivery Optimization policy by specifying: &lt;STRONG&gt;DOCacheHost=&amp;lt;MCC FQDN&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;When configured, Delivery Optimization continues to prioritize content from nearby peers. If the requested content isn't available from peers, devices will attempt to download it from Microsoft Connected Cache. If the content isn't present in the cache, devices automatically fall back to Microsoft's internet content source.&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Think of the content retrieval process as a layered approach: &lt;STRONG&gt;Peers → Microsoft Connected Cache → Internet&lt;/STRONG&gt;. This hierarchy helps optimize bandwidth usage while maintaining reliable access to updates and applications.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Distributed topology&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;With a distributed topology, all locations have their own local internet access. Each site reaches the internet directly, so the WAN penalty for a cache miss is lower.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Group&lt;/STRONG&gt;&lt;STRONG&gt; boundaries:&lt;/STRONG&gt; Set DODownloadMode=2 and set a DOGroupID. The key is that each physical site is its own peer group. DORestrictPeerSelectionBy = 1 (Subnet) is still recommended but less critical because cross-site peer-to-peer traffic is less likely.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Bandwidth&lt;/STRONG&gt;&lt;STRONG&gt; limits:&lt;/STRONG&gt; More relaxed than star. 25% to 50% during business hours is typical since each site has its own internet cache path.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Tip: With local internet connectivity and Delivery Optimization Group mode, many locations achieve excellent bandwidth savings with no additional infrastructure. Microsoft Connected Cache adds value primarily at the largest locations (more than 100 devices).&lt;/P&gt;
&lt;H3&gt;Scenario 2. Branch offices with limited WAN&lt;/H3&gt;
&lt;P&gt;Branch offices often see the biggest Delivery Optimization savings. Instead of every device pulling the same update over the WAN, one device can download from the internet and share locally with peers on the subnet.&lt;/P&gt;
&lt;P&gt;Use DODownloadMode = 2 and assign a unique DOGroupID per branch location to keep peer-to-peer traffic within the branch. Set aggressive background limits (15% to 25% of link speed) to protect line-of-business applications. For very small branches with fewer than 10 devices, or locations where devices are frequently reimaged, consider adding a Microsoft Connected Cache node. A small cache server with a 100 GB drive provides a persistent local source that doesn't depend on any single peer being online.&lt;/P&gt;
&lt;H3&gt;Scenario 3. Mass provisioning and Windows Autopilot&lt;/H3&gt;
&lt;P&gt;During Windows Autopilot bulk provisioning or mass reimaging, many devices request identical content at the same time. Without Delivery Optimization, every device downloads independently from the internet cache, often saturating internet links and extending provisioning times.&lt;/P&gt;
&lt;P&gt;For environments with repeated content consumption, such as shared devices, labs, and kiosks that get reimaged frequently, peer-to-peer distribution has a structural limitation. After a mass reimage, no device has cached content available to share. This is where Microsoft Connected Cache provides the greatest value. Because the cache node retains content on-premises independent of device state, the first device after a wipe can download from the local cache rather than the internet cache. If you're using peer-to-peer alone, consider staggering reimage schedules so that some devices always have content available to share.&lt;/P&gt;
&lt;P&gt;Intune already uses Delivery Optimization to distribute Win32 and Microsoft Store apps, so no extra setup is needed beyond the core Delivery Optimization policies. The main tuning is around thresholds and retention. Lower DOMinFileSizeToCache from 10 MB to 5 MB so snaller app installers qualify for peer-to-peer sharing and extend DOMaxCacheAge to 7 days (604800 seconds) to accommodate app deployments that often span a full week.&lt;/P&gt;
&lt;P&gt;During large provisioning events, be generous with cache resources. Increase DOMaxCacheSize to 50 percent or higher to ensure early devices have room to cache and share content. Set DOMonthlyUploadDataCap to 0 (unlimited) so the first-wave of devices can serve a larger number of peers. Finally, provision devices in stages whenever possible. Even a 15-minute delay between groups gives Delivery Optimization time to build peer availability before the next wave starts.&lt;/P&gt;
&lt;H3&gt;Scenario 4. Devices that move between locations&lt;/H3&gt;
&lt;P&gt;In environments where employees frequently move between locations, isolating peer traffic can be challenging. For example, a device assigned to the Group ID for Branch A may be physically connected at Branch B, causing it to search for peers across the WAN. In this scenario, use DHCP to provide the appropriate DOGroupID and, when applicable, DOCacheHost source for the device’s current location.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;DOCacheHostSource=1 and set the DHCP Option 235 at the site to the FQDN of the Microsoft Connected Cache.&lt;/LI&gt;
&lt;LI&gt;DOGroupIdSource=3 and set the DHCP Option 234 to the GUID for the GroupID.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Go further with Microsoft Connected Cache&lt;/H2&gt;
&lt;P&gt;Microsoft Connected Cache is an optional on-premises content cache. It complements Delivery Optimization by providing a persistent local source when peers are unavailable.&lt;/P&gt;
&lt;DIV style="border-left: 4px solid #0078D4; background-color: #f3f9fd; padding: 16px; margin: 16px 0; border-radius: 4px;"&gt;
&lt;P style="margin-top: 0;"&gt;&lt;STRONG&gt;Tip: Start with Peer-to-Peer Caching First&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Before deploying &lt;STRONG&gt;Microsoft Connected Cache (MCC)&lt;/STRONG&gt;, consider optimizing &lt;STRONG&gt;Delivery Optimization peer-to-peer caching&lt;/STRONG&gt;. Many organizations achieve substantial bandwidth savings through properly configured download modes, peer groups, cache settings, and deployment rings without introducing additional infrastructure.&lt;/P&gt;
&lt;P&gt;Peer-to-peer caching is often the simplest and most cost-effective first step because devices can share content directly with one another, reducing internet downloads and WAN utilization across the organization.&lt;/P&gt;
&lt;P style="margin-bottom: 0;"&gt;Microsoft Connected Cache becomes particularly valuable when peer sharing alone cannot fully meet business requirements, such as locations with few devices, frequent device reimaging, limited peer availability, or a need for a persistent on-premises content source. In these scenarios, MCC can complement Delivery Optimization to further reduce bandwidth consumption and improve content availability.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;Microsoft Connected Cache is most valuable at small locations with few peers, in environments with frequent device resets, or anywhere large content volumes need a guaranteed local source. Devices can find the cache node in two ways:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Static (Intune policy): &lt;/STRONG&gt;Set DOCacheHost to the FQDN of your Microsoft Connected Cache server in the Intune Settings catalog. Simple, static, works well for single-site deployments.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamic (DHCP Option 235): &lt;/STRONG&gt;Set DOCacheHostSource = 1 and configure DHCP Option 235 with the MCC server FQDN. Devices discover the correct cache node automatically based on network location. This is the preferred approach for multi-site deployments.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When using Microsoft Connected Cache, configure DODelayForegroundDownloadFromHttp to 30 seconds and DODelayBackgroundDownloadFromHttp to 60 seconds. These timeouts control how long Delivery Optimization waits for a local source before falling back to the internet cache; they don’t control download speed.&lt;/P&gt;
&lt;P&gt;For setup details and hardware requirements, refer to: &lt;A class="lia-external-url" href="https://aka.ms/MCC-ENT-release-notes" target="_blank" rel="noopener"&gt;Release Notes for Microsoft Connected Cache for Enterprise and Education&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Troubleshooting tips&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Slow downloads: &lt;/STRONG&gt;The fallback timeout is the most misunderstood Delivery Optimization setting. It controls how long a device waits for a local source before requesting from the internet cache, not download speed. If downloads are slow, check network routing, DNS, and firewall rules.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Cache misses: &lt;/STRONG&gt;Internet cache Vary headers can prevent content from being cached on the first request. Microsoft Connected Cache respects these headers, which can cause initial cache misses. The product team is actively working on a fix.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Diagnostics: &lt;/STRONG&gt;Run the Delivery Optimization troubleshooter at &lt;A class="lia-external-url" href="https://aka.ms/DO-Fix" target="_blank" rel="noopener"&gt;aka.ms/DO-Fix&lt;/A&gt; for automated diagnostics.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;PowerShell: &lt;/STRONG&gt;Use Get-DeliveryOptimizationStatus in PowerShell to see real-time download source, peer count, and bytes per source for each active download.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Delivery Optimization reporting:&lt;/STRONG&gt; Centralized reporting is available in the Windows Update for Business Delivery Optimization report or through PowerShell cmdlets. &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/do/waas-delivery-optimization-monitor" target="_blank" rel="noopener"&gt;Monitor Delivery Optimization&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;Delivery Optimization is already available on supported Windows devices you manage. The configurations in this post take minutes to deploy through the Intune settings catalog and can save significant bandwidth with every update cycle and application deployment. Start with the essential policies table, pilot the profile with a small device group, and review Windows Update for Business reports after a couple of patch cycles to measure the impact.&lt;/P&gt;
&lt;P&gt;Many organizations achieve their goals using Delivery Optimization peer-to-peer caching alone. For scenarios where peer caching is insufficient or a persistent local cache is required, Microsoft Connected Cache is available as an additional option. The product team is active in the Connected Cache Community at &lt;A class="lia-external-url" href="https://aka.ms/ConnectedCacheCommunity" target="_blank" rel="noopener"&gt;aka.ms/ConnectedCacheCommunity&lt;/A&gt;, and feature ideas can be submitted through the Intune feedback portal at &lt;A class="lia-external-url" href="https://aka.ms/IntuneFeedback" target="_blank" rel="noopener"&gt;aka.ms/IntuneFeedback&lt;/A&gt;.&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Resource&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;SPAN class="lia-text-color-22"&gt;Link&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Configure Delivery Optimization&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/ConfigureDO" target="_blank" rel="noopener noreferrer"&gt; Configure Delivery Optimization &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Delivery Optimization Troubleshooter&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/DO-Fix" target="_blank" rel="noopener noreferrer"&gt; Run the Delivery Optimization Troubleshooter &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Microsoft Connected Cache Release Notes&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/MCC-ENT-release-notes" target="_blank" rel="noopener noreferrer"&gt; View MCC Release Notes &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Connected Cache Community&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/ConnectedCacheCommunity" target="_blank" rel="noopener noreferrer"&gt; Join the Community &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;DO + MCC AMA Recording&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/ama/ConnectedCache" target="_blank" rel="noopener noreferrer"&gt; Watch the AMA Recording &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f8f9fa"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;STRONG&gt;Intune Feedback&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;A href="https://aka.ms/IntuneFeedback" target="_blank" rel="noopener noreferrer"&gt; Submit Product Feedback &lt;/A&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have any feedback or questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2026 22:01:39 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/configure-delivery-optimization-for-windows-to-save-bandwidth/ba-p/4547592</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-08-18T22:01:39Z</dc:date>
    </item>
    <item>
      <title>Registry Inventory in Microsoft Intune: Verifying What’s on Your Devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/registry-inventory-in-microsoft-intune-verifying-what-s-on-your/ba-p/4541312</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Madison Cooks, Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;IT admins need a reliable way to confirm how Windows devices are configured, especially when troubleshooting, validating compliance, or investigating security posture. Policy assignment alone doesn’t always show what’s present on the device and getting registry visibility at scale has often required custom discovery or remediation scripts that take time to build, test, and maintain.&lt;/P&gt;
&lt;P&gt;With Microsoft Intune’s July (2607) release, device inventory will include Windows registry data, helping IT admins verify a device’s actual configuration, not just the policy assigned. With a new Device inventory property for registry keys, you define the keys you care about in the properties catalog, and Intune collects them for you. There’s no collection logic to build or keep running.&lt;/P&gt;
&lt;P&gt;This makes registry-based configuration checks easier to operationalize across managed Windows devices, so teams can spend less time maintaining scripts and more time acting on the data.&lt;/P&gt;
&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Microsoft Intune device inventory profile creation screen showing the Properties picker with the Registry category selected for inventory data collection.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;
&lt;H2&gt;What registry data you collect&lt;/H2&gt;
&lt;P&gt;Registry data collection is configured through the existing properties catalog. For each entry, provide a registry key path and, when needed, a value name. For every targeted device, the device agent attempts collection and reports:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Registry key path&lt;/LI&gt;
&lt;LI&gt;Value name&lt;/LI&gt;
&lt;LI&gt;Value type&lt;/LI&gt;
&lt;LI&gt;Value data&lt;/LI&gt;
&lt;/UL&gt;
&lt;img&gt;&lt;EM&gt;Figure 2: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune device inventory profile configuration page showing registry key collection settings, including registry path, collection pattern options, and value name fields.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;The initial release supports the following collection patterns designed for common admin scenarios that use HKEY_LOCAL_MACHINE (HKLM) paths.&lt;/P&gt;
&lt;H3&gt;Single value&lt;/H3&gt;
&lt;P&gt;Specify a registry path and value name to collect one value from that path. For example, collect Secure Boot certificate servicing status from HKLM\SYSTEM\CurrentControlSet\Control\SecureBoot by using values such as UEFICA2023Status, UEFICA2023Error, or UEFICA2023ErrorEvent.&lt;/P&gt;
&lt;H3&gt;All values under a path, non-recursive&lt;/H3&gt;
&lt;P&gt;Specify a registry path to collect all values directly under that path. This pattern doesn't include subkeys. For example, collect values directly under a Windows Update configuration path to help validate expected settings.&lt;/P&gt;
&lt;H3&gt;Same value across subkeys&lt;/H3&gt;
&lt;P&gt;Specify a base registry key path and a value name to collect that value from each immediate subkey. For example, collect DHCP status across network interface subkeys under HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces.&lt;/P&gt;
&lt;H2&gt;Where registry inventory data appears&lt;/H2&gt;
&lt;P&gt;After collection, registry inventory data will be available in &lt;STRONG&gt;Device inventory&lt;/STRONG&gt; at initial release. We’ll expand access to registry data in the coming months, including support in additional reporting and exploration experiences.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 3: &lt;SPAN style="color: rgb(112, 112, 112);" data-mce-style="color: rgb(112, 112, 112);"&gt;Microsoft Intune Device Inventory page displaying collected Windows registry data for a device, including registry key paths, values, collection status, and timestamps.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;This makes registry data available alongside other inventory signals, so admins can use familiar tools to investigate configuration, validate device state, and support troubleshooting without building separate collection scripts.&lt;/P&gt;
&lt;H2&gt;How admins use this&lt;/H2&gt;
&lt;P&gt;You can collect registry data and view it per device in Device inventory - a verified record of each endpoint’s actual configuration and a key source of settings data on each endpoint. This helps answer questions like: Is a setting actually enabled on the device? Which app, version, or configuration is installed? Did a policy apply correctly? Why is this device behaving differently from the rest?&lt;/P&gt;
&lt;P&gt;Registry data collection in Device inventory is included with Microsoft Intune Plan 1.&lt;/P&gt;
&lt;H2&gt;Collection results and limits&lt;/H2&gt;
&lt;P&gt;If a registry value exists but doesn’t contain data, collection succeeds and the value appears as empty. If the registry path or value name doesn’t exist on a device, that device reports &lt;STRONG&gt;Not found&lt;/STRONG&gt; for the collection result. Collection continues for all other devices, so one missing value won’t block results from devices where the value exists.&lt;/P&gt;
&lt;P&gt;Registry inventory includes safeguards to keep collection focused and manageable. Each collected registry value is capped at &lt;STRONG&gt;6 KB&lt;/STRONG&gt;, and each device can collect up to &lt;STRONG&gt;100 registry keys&lt;/STRONG&gt;. If a value or device exceeds these limits, collection skips the excess data and reports the applicable result for that device. These limits help manage data volume, maintain service performance, and reduce the risk of over-collection.&lt;/P&gt;
&lt;P&gt;Registry inventory is designed for configuration visibility and troubleshooting, not for collecting sensitive or confidential data. Built-in heuristic detection helps identify and prevent ingestion of values that may contain secrets, credentials, authentication tokens, certificates, private keys, connection strings, or other data that could grant access if exposed. If a value is flagged as potentially sensitive, it&lt;STRONG&gt; isn’t &lt;/STRONG&gt;collected.&lt;/P&gt;
&lt;P&gt;Collection is limited to HKEY_LOCAL_MACHINE (HKLM) paths. This keeps inventory focused on device-level configuration and avoids user-specific registry contexts.&lt;/P&gt;
&lt;H1&gt;Summary&lt;/H1&gt;
&lt;P&gt;Registry inventory in Microsoft Intune helps admins collect Windows registry data in a native, declarative way. Instead of maintaining custom scripts for common inventory scenarios, admins can configure registry collection in the properties catalog and query the results through familiar Intune reporting experiences.&lt;/P&gt;
&lt;P&gt;Use registry inventory for configuration visibility and troubleshooting across managed Windows devices. As you plan your collection strategy, focus on device-level HKLM data, avoid sensitive values, and remember collection limits to keep inventory targeted and manageable.&lt;/P&gt;
&lt;P&gt;If you have any feedback or questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 20:59:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/registry-inventory-in-microsoft-intune-verifying-what-s-on-your/ba-p/4541312</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-28T20:59:27Z</dc:date>
    </item>
    <item>
      <title>From hours to minutes: Rethinking Microsoft Intune compliance reporting with the Export API</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/from-hours-to-minutes-rethinking-microsoft-intune-compliance/ba-p/4540554</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Daniel Gerrity – Principal Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you manage a large device fleet with Microsoft Intune, you’ve almost certainly needed to get reporting data out of the service at scale — compliance state, device inventory, app status, endpoint analytics, or one of the many other reports admins rely on for operations and audit evidence. Intune supports this pattern through the &lt;STRONG&gt;export API&lt;/STRONG&gt;, which generates supported reports as asynchronous export jobs instead of requiring you to retrieve the same data through thousands of operational Graph calls.&lt;/P&gt;
&lt;P&gt;You can see the full list of reports available through the export API in &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-management/reports/ref-graph-available-reports" target="_blank" rel="noopener"&gt;Intune reports and properties available using Graph API&lt;/A&gt; documentation. In the illustrative scenario below, moving one nightly job from operational Graph reporting endpoints to the &lt;STRONG&gt;Intune export API (exportJobs)&lt;/STRONG&gt; cuts the work from roughly &lt;STRONG&gt;100,000 API calls to about 15&lt;/STRONG&gt; while producing the same report data. The runtime drops from &lt;STRONG&gt;~2.5 hours to ~15 minutes&lt;/STRONG&gt;. Here’s how, and why the pattern holds up as your fleet grows.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; padding: 18px 20px; border-left: 5px solid #FFB900; background-color: #fff8e5; border-radius: 6px; color: #1f1f1f; font-family: Arial, Helvetica, sans-serif; font-size: 14px;"&gt;
&lt;DIV style="display: flex; align-items: center; gap: 8px; margin-bottom: 8px;"&gt;&lt;SPAN style="font-size: 18px; line-height: 1;"&gt;&lt;STRONG style="font-size: 16px; color: #8a5a00;"&gt;Note on the numbers&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P style="margin: 0; line-height: 1.5;"&gt;The figures below are a representative example for a hypothetical 50,000-device enterprise, “Contoso,” and are rounded for clarity. Your results may vary based on fleet size, policy count, and how many compliance settings you evaluate.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H2&gt;The scenario&lt;/H2&gt;
&lt;P&gt;Contoso runs a nightly job that answers a deceptively simple question:&lt;/P&gt;
&lt;DIV style="margin: 24px 0; padding: 20px 24px; background-color: #f5f9ff; border-left: 4px solid #0078d4; border-radius: 4px;"&gt;
&lt;P style="margin: 0; font-size: 16px; line-height: 1.6; color: #323130;"&gt;For each device, across every compliance policy assigned to it, what is the state of each individual setting?&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;This is a classic &lt;STRONG&gt;per-device, per-compliance-policy, per-setting&lt;/STRONG&gt; state export. It’s the raw material behind compliance dashboards, audit evidence, remediation targeting, and “why is this device noncompliant” investigations. In Intune’s reporting catalog, this is the DeviceStatusSummaryByCompliancePolicySettingsReportV3 report.&lt;/P&gt;
&lt;P&gt;Contoso has &lt;STRONG&gt;~50,000 managed devices&lt;/STRONG&gt;, and the job runs once a day.&lt;/P&gt;
&lt;H2&gt;The old way: Operational Graph APIs&lt;/H2&gt;
&lt;P&gt;The intuitive approach treats compliance data as something you &lt;EM&gt;fetch, per device, right now&lt;/EM&gt;. The script:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Enumerates the fleet (managedDevices).&lt;/LI&gt;
&lt;LI&gt;Loops over every device, and for each one calls the operational reporting or setting-state endpoints (such as managedDevices detail and settingStates) to pull that device’s per-policy, per-setting results.&lt;/LI&gt;
&lt;LI&gt;Pages through the results in small JSON pages (often 50 rows at a time), reassembling everything client-side.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It works. It just doesn’t scale because the &lt;STRONG&gt;number of calls is a function of the number of devices&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;At roughly two operational calls per device, 50,000 devices is on the order of &lt;STRONG&gt;~100,000 Graph calls per run&lt;/STRONG&gt;. That volume brings its own tax:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Throttling. &lt;/STRONG&gt;You hit service protection limits and have to implement retry/back-off logic.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Threading. &lt;/STRONG&gt;To finish inside the window at all, you parallelize which means concurrency bugs, partial failures, and harder debugging.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fragility. &lt;/STRONG&gt;A run that makes 100,000 calls has 100,000 chances to fail, and a mid-run failure often means starting over.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Time. &lt;/STRONG&gt;End&lt;STRONG&gt;=&lt;/STRONG&gt;to&lt;STRONG&gt;-&lt;/STRONG&gt;end, the job lands around ~2.5 hours.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Every time Contoso onboards more devices, this job gets &lt;EM&gt;slower and more expensive&lt;/EM&gt; - the worst possible scaling direction for something that runs every night.&lt;/P&gt;
&lt;H2&gt;The new way: Export API (exportJobs)&lt;/H2&gt;
&lt;P&gt;The export API flips the model. Instead of asking Graph to compute results device-by-device in real time, you ask Intune to &lt;STRONG&gt;generate the entire report once, server-side&lt;/STRONG&gt;, and hand you back a single file.&lt;/P&gt;
&lt;P&gt;The flow is a short, asynchronous handshake:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;1. POST  /deviceManagement/reports/exportJobs
         { "reportName": "DeviceStatusSummaryByCompliancePolicySettingsReportV3",
           "format": "csv", ...optional filter/select... }
         → returns a jobId, status: "notStarted"

2. GET   /deviceManagement/reports/exportJobs('{jobId}')
         → poll until status: "completed"     (a handful of polls while it builds)
         → response includes a short-lived download URL

3. GET   {download URL}
         → one zipped CSV containing every device × policy × setting row&lt;/LI-CODE&gt;
&lt;P&gt;That’s the whole pattern: &lt;STRONG&gt;request → poll → download → unzip → load&lt;/STRONG&gt;. One report, one file, the entire fleet inside it.&lt;/P&gt;
&lt;P&gt;Count the calls: &lt;STRONG&gt;one&lt;/STRONG&gt; POST to start the job, &lt;STRONG&gt;a handful&lt;/STRONG&gt; of GET polls while Intune builds the file, and &lt;STRONG&gt;one&lt;/STRONG&gt; GET to download it - call it&amp;nbsp;&lt;STRONG&gt;~15 calls total&lt;/STRONG&gt;. Not ~15 per device. ~15 for the whole 50,000-device run. And that number barely moves whether Contoso has 50,000 devices or 150,000.&lt;/P&gt;
&lt;P&gt;Runtime drops to about &lt;STRONG&gt;~15 minutes&lt;/STRONG&gt;, most of which is simply &lt;EM&gt;waiting&lt;/EM&gt; for the export to finish - cheap poll calls, not active compute.&lt;/P&gt;
&lt;P&gt;Most importantly, &lt;STRONG&gt;the output schema is identical&lt;/STRONG&gt;. The CSV columns match what the old per-device loop assembled, so nothing downstream; dashboards, warehouse tables, alerting, has to change. You swap the &lt;EM&gt;acquisition&lt;/EM&gt; layer and leave everything else alone.&lt;/P&gt;
&lt;H2&gt;Side by side&lt;/H2&gt;
&lt;DIV style="max-width: 900px; margin: 24px auto; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-border-color-custom-d1d1d1 lia-border-style-solid" border="1" style="width: 100%; border-width: 1px; border-spacing: 0;"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-f5f5f5" scope="col" style="padding: 16px;"&gt;Comparison&lt;/th&gt;&lt;th class="lia-background-color-custom-0f6cbd" scope="col" style="padding: 16px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Operational Graph APIs&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-background-color-custom-fff4ce" scope="col" style="padding: 16px;"&gt;&lt;SPAN style="display: inline-block; margin-bottom: 6px; padding: 2px 8px; font-size: 12px; font-weight: 600; color: #5c4400; background-color: #ffdf75; border: 1px solid #e0b000; border-radius: 12px;"&gt; Recommended &lt;/SPAN&gt; &lt;BR /&gt;Export API (&lt;CODE style="font-size: 13px;"&gt;exportJobs&lt;/CODE&gt;)&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Pattern&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Per-device loop plus paging&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Async export → download one file&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;API calls per run&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~100,000&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~15&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Calls scale with&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Number of devices&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Nothing. The handshake remains fixed.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Runtime&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~2.5 hours&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;&lt;STRONG&gt;~15 minutes&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Concurrency&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;Threading required&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;None needed&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-fafafa" scope="row" style="padding: 14px 16px;"&gt;Output schema&lt;/th&gt;&lt;td style="padding: 14px 16px;"&gt;—&lt;/td&gt;&lt;td class="lia-background-color-custom-fffaf0" style="padding: 14px 16px;"&gt;Unchanged and drop-in compatible&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;th class="lia-background-color-custom-f0f6ff" scope="row" style="padding: 16px;"&gt;Net result&lt;/th&gt;&lt;td class="lia-background-color-custom-f7f9fc" style="padding: 16px;"&gt;—&lt;/td&gt;&lt;td class="lia-background-color-custom-dff6dd" style="padding: 16px;"&gt;~6,000× fewer API calls&lt;BR /&gt;~10× faster runtime&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;Why it scales: Roundtrips, not bytes&lt;/H2&gt;
&lt;P&gt;Here’s the subtlety worth internalizing, because it’s easy to get wrong. There are &lt;STRONG&gt;two different costs&lt;/STRONG&gt; in this job, and they scale on &lt;STRONG&gt;different axes&lt;/STRONG&gt;:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;The number of API calls&lt;/STRONG&gt; - round-trips across the wire.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The volume of data&lt;/STRONG&gt; - the actual compliance rows you move.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;The data volume is the same either way. &lt;/STRONG&gt;50,000 devices × N settings is 50,000 × N rows, whether you assemble them from 100,000 little paged responses or receive them in one CSV. The export doesn’t move &lt;EM&gt;less&lt;/EM&gt; data - it moves the&amp;nbsp;&lt;EM&gt;same&lt;/EM&gt; data. And yes, that file grows with &lt;STRONG&gt;both&lt;/STRONG&gt; device count and setting count. More devices, bigger file; more settings, bigger file.&lt;/P&gt;
&lt;P&gt;So the win isn’t fewer bytes. &lt;STRONG&gt;The win is fewer round-trips.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Every one of those 100,000 operational calls relies on authentication, TLS setup, network latency, and service-protection (throttling) accounting regardless of how much data it returns. Multiply that fixed overhead by 100,000 and it dominates everything. The export only pays that tax &lt;STRONG&gt;twice&lt;/STRONG&gt;: once to start the job, once to download the file. Intune does the assembly server-side and streams you the result in a single bulk transfer.&lt;/P&gt;
&lt;P&gt;That reframes the scaling story:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Call count&lt;/STRONG&gt; is essentially constant - it doesn’t grow with devices or settings. It’s one job and one download.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data volume&lt;/STRONG&gt; grows with devices and settings but a bigger CSV is a bigger &lt;EM&gt;single download&lt;/EM&gt;, not more calls. Bulk transfer is exactly what HTTP is good at.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Runtime&lt;/STRONG&gt; has a mild data dependency: a larger fleet takes Intune a little longer to build the file. But you absorb that as a few extra seconds of poll-waiting, not as thousands of extra calls you have to orchestrate, retry, and throttle-manage.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;What the IT admin actually gets&lt;/H2&gt;
&lt;P&gt;Beyond the raw speed, here’s the value that shows up in day-to-day operations:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Your maintenance window comes back. &lt;/STRONG&gt;A 15-minute job leaves room for everything else.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Fewer moving parts to maintain. &lt;/STRONG&gt;No custom throttling handler, no thread pool, no resumability logic. Less code is less to break at 2 a.m.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Reliability by design. &lt;/STRONG&gt;Two roundtrips means two failure points, and the server does the heavy lifting of assembling a consistent snapshot.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Lower cost and lower service impact. &lt;/STRONG&gt;Eliminating ~100,000 calls is easier on your tenant’s throttling limits and a better citizen for the Intune service overall.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Room to grow. &lt;/STRONG&gt;Because call count is decoupled from device count, doubling the fleet doesn’t double the job, you just download a somewhat larger file.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;No downstream disruption. &lt;/STRONG&gt;Same schema for the output means the migration is contained to the ingestion step which is a low-risk swap, not a re-platforming.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;When to use which&lt;/H2&gt;
&lt;P&gt;The export API isn’t a universal replacement, it’s best used for &lt;STRONG&gt;bulk, point-in-time snapshots&lt;/STRONG&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Reach for exportJobs&lt;/STRONG&gt; when you need the whole fleet’s state (or a large, filtered slice) on a schedule such as nightly compliance loads, audit exports, warehouse hydration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Stick with the operational endpoints&lt;/STRONG&gt; when you need a single device &lt;EM&gt;right now&lt;/EM&gt;, an interactive “check this one device” lookup, or a real-time remediation trigger where waiting on an async job doesn’t make sense.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The two are complementary. The mistake isn’t using the operational APIs, it’s using them &lt;EM&gt;in a loop&lt;/EM&gt; to reconstruct something the export API will hand you in one file.&lt;/P&gt;
&lt;H2&gt;The takeaway&lt;/H2&gt;
&lt;P&gt;The per-device loop feels natural because it mirrors how we think about devices, one at a time. But at fleet scale, the question isn’t “what’s the state of this device?” a hundred thousand times over. It’s “give me the state of everything,” once. The export API is built for exactly that question, and answering it the right way turned a multi-hour nightly grind into a coffee break - &lt;STRONG&gt;from ~100,000 calls to about 15, ~10× faster, with zero downstream changes.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment below or reach out to us on X: &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 19:07:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/from-hours-to-minutes-rethinking-microsoft-intune-compliance/ba-p/4540554</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-24T19:07:28Z</dc:date>
    </item>
    <item>
      <title>Designing Intune enrollment for frontline workers: Choosing the right path for real-world devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Shawn Catlin – Senior Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Practitioner perspective from Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune), with deep experience in secure frontline mobility, including regulated healthcare environments.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Enrollment &lt;U&gt;methodology&lt;/U&gt;&amp;nbsp;is one of the most consequential design decisions teams make for frontline environments. It shapes how devices are used, how identity is handled, how failures are recovered from, and how much friction workers experience before they can do their jobs.&lt;/P&gt;
&lt;P&gt;Frontline use cases aren’t limited to shared devices. They can span nearly every enrollment type available in Microsoft Intune, including user-assigned, shared, dedicated, kiosk, corporate-owned, BYOD, and zero-touch deployment models. The right choice is often influenced by business need, operational workflow, budget, support model, and security requirements. But it must also account for platform and operating system design. Android, iOS, and iPadOS may offer similar enrollment concepts, but they don’t always behave the same way or support the same management patterns.&lt;/P&gt;
&lt;P&gt;That distinction matters. A kiosk or dedicated-device model, for example, is intentionally designed for a locked-down, task-focused experience. It manages the device around a specific function, not around a personalized user workspace. In that model, broad app availability, persistent personalization, and user-driven app installation are not the primary management paradigm. Similarly, a shared-device model should not be selected simply because an organization cannot provide a dedicated device to every worker. If identity, app access, compliance, or user context are required, those needs must be part of the enrollment decision from the beginning.&lt;/P&gt;
&lt;P&gt;There is no copy-and-paste frontline enrollment strategy that works across every industry, business unit, or device scenario. Some frontline devices are shared across shifts and must remain reliable where connectivity, identity, and support are not guaranteed. Others are assigned to supervisors, clinicians, field workers, or shift leads who need persistent access to apps, settings, and data. When enrollment choices are made without accounting for these realities, especially platform differences and OS-level limitations, friction surfaces quickly during pilots and scales painfully during rollout.&lt;/P&gt;
&lt;P&gt;This article explains how to approach Intune enrollment for frontline devices through a practical, reality-first lens: start with how the device is used, align the management model to the workflow, and then plan how the device will be enrolled, replaced, and reprovisioned at scale.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;In a hospital environment, frontline does not mean one type of device or one type of worker. A shared clinical workstation, a nurse’s mobile device, a patient check-in kiosk, a barcode scanner, and a supervisor’s assigned device may all be considered frontline, but they each have very different identity, security, app, and recovery requirements. That is why enrollment decisions have to start with the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment Is a Design Decision, not a Checkbox&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Enrollment does more than bring a device under management. It defines how the device is expected to work, where the security boundary sits, how identity is applied, and what recovery looks like when something fails in the field.&lt;/P&gt;
&lt;P&gt;There is no single “best” enrollment model for frontline. There is only the model that best fits how the device is actually used. The right choice depends on whether the device follows a person, a shift, a task, or a business process. It also depends on how much identity matters to the experience, whether apps need to be personalized, whether Conditional Access or compliance is required, and how quickly the device must be replaced or recovered.&lt;/P&gt;
&lt;P&gt;This is why many problems that look like policy, app, or configuration failures are actually enrollment design problems in disguise. A device can be successfully enrolled and still be poorly designed for the job it needs to do.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;A device can be successfully enrolled and still fail the workflow. If a shift worker cannot access the right app quickly, if a shared device retains the wrong user context, or if a replacement device cannot be brought online during a shift, the issue may look like an app or support problem. In reality, it often traces back to an enrollment model that did not match the workflow.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Separate Two Decisions: Management Model and Provisioning Method&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment planning becomes easier when teams separate two related but different decisions.&lt;/P&gt;
&lt;P&gt;The first decision is the &lt;STRONG&gt;management model&lt;/STRONG&gt;. This is the architectural choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does the device need to represent a specific person?&lt;/LI&gt;
&lt;LI&gt;Is the device shared across multiple workers?&lt;/LI&gt;
&lt;LI&gt;Is it dedicated to a narrow task or workflow?&lt;/LI&gt;
&lt;LI&gt;Does the device require personal apps, persistent settings, or user-specific data?&lt;/LI&gt;
&lt;LI&gt;Does the workflow require Conditional Access, compliance, auditability, or individual identity?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This decision determines whether the device should be user-associated, shared, dedicated, kiosk-style, personally owned, or corporate-owned with a work profile.&lt;/P&gt;
&lt;P&gt;The second decision is the &lt;STRONG&gt;provisioning and reprovisioning method&lt;/STRONG&gt;. This is the lifecycle choice. It answers questions such as:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How will the device get into management the first time?&lt;/LI&gt;
&lt;LI&gt;Will it be staged by IT, a depot, a partner, or the site?&lt;/LI&gt;
&lt;LI&gt;What happens after a wipe, repair, refresh, or reassignment?&lt;/LI&gt;
&lt;LI&gt;Can the device recover without a specific user’s credentials?&lt;/LI&gt;
&lt;LI&gt;Will Wi-Fi, certificates, tokens, apps, and policies be available at first boot?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Zero-touch, pre-staging, depot workflows, and reprovisioning plans support the selected management model. They should not replace the decision about which model is right for the scenario.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Start With How the Device Is Used&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;In the previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/A&gt;, we discussed why successful frontline migrations begin with understanding how devices are actually used in the field. That discovery work should now feed directly into enrollment design.&lt;/P&gt;
&lt;P&gt;The most reliable starting point is not the department, license, or ownership model. It is the device’s behavior in the field.&lt;/P&gt;
&lt;P&gt;Ask:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Does this device follow a person?&lt;/LI&gt;
&lt;LI&gt;Does it follow a shift?&lt;/LI&gt;
&lt;LI&gt;Does it follow a task?&lt;/LI&gt;
&lt;LI&gt;Does it need to know who the user is?&lt;/LI&gt;
&lt;LI&gt;Does it need persistent user context?&lt;/LI&gt;
&lt;LI&gt;Does it need to be quickly replaced with minimal IT involvement?&lt;/LI&gt;
&lt;LI&gt;Does the platform support the experience you expect?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The answers help map real-world requirements to the right Intune enrollment approach. Before selecting an enrollment model, organizations should also understand how identity is expected to function on the device. If you have not yet reviewed assigned versus shared identity patterns, see our previous article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-Identity" target="_blank" rel="noopener"&gt;Migrating frontline mobile devices: Identity considerations for assigned and shared devices&lt;/A&gt;, which explores how user identity, authentication, auditability, and device ownership assumptions can influence frontline management decisions.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Decision indicator&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Usually points toward&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Validate before choosing&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs persistent apps, settings, approvals, or data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-driven or user-associated enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether identity and personalization are truly required for the workflow&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers use the same device across shifts and need individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared or device-first enrollment with identity support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;How sign-in, sign-out, session cleanup, and auditability will work&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device performs a narrow, repeatable task&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or kiosk-style enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can operate with a locked-down app set and minimal user choice&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device needs corporate control but may allow limited personal use&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned work profile where supported&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the OS supports the expected separation between work and personal data&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device is personally owned and only work data needs to be protected&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD / personally owned work profile / user enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Whether the workflow can tolerate limited organizational control&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The device must be replaced quickly with minimal IT involvement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Pre-staged, zero-touch, or easily reprovisioned device-first model&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Reset behavior, network readiness, certificate delivery, and replacement speed&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The environment has inconsistent connectivity or limited support&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Simpler enrollment paths with fewer live dependencies&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;What the device needs at first boot, during sign-in, and after wipe or reset&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;&lt;STRONG&gt;Map Frontline Scenarios to Enrollment Models&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;A practical Intune strategy starts by accepting that frontline is not one scenario. It is a collection of scenarios. Standardization is important, but standardizing on one enrollment method for every frontline use case is rarely the right goal. Mature organizations standardize the decision framework, not necessarily the deployment model.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Device usage pattern&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Typical characteristics&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;iOS/iPadOS enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Android enrollment&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;User-assigned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One person regularly uses the device and needs personalized apps, settings, and data&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with user affinity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Fully Managed or Corporate-Owned Work Profile if personal use is permitted&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Shared device with individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Multiple workers share the device and sign in with their own identities&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment with Microsoft Entra Shared Device Mode; Shared iPad when multi-user iPad support is required&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Dedicated or task-based device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Device performs a specific function and does not require a personalized user experience&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment without user affinity, with supervised device and app restrictions&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Dedicated Device&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android device without Google Mobile Services&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned specialty device, often shared or task-focused&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Not applicable&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android AOSP userless or AOSP user-associated enrollment&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Personally owned device&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Employee-owned device used for work&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;BYOD User Enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Enterprise Personally Owned Work Profile&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Zero-touch or pre-staged deployment&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Corporate-owned device that needs scalable provisioning or replacement&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Automated Device Enrollment through Apple Business Manager or Apple School Manager&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Android Zero-touch Enrollment, Samsung Knox Mobile Enrollment, or equivalent supported provisioning path&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;If the device follows a person, choose a model optimized for identity and personalized access. If the device follows a shift, workflow, or task, choose a model optimized for simplicity, consistency, and easy replacement.&lt;/P&gt;
&lt;P&gt;If you’re looking for more platform-specific guidance please see frontline enrollment resources for both Android and iOS/iPadOS:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/android?tabs=ae" target="_blank" rel="noopener"&gt;Get started with Android frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/solutions/frontline-worker/ios-ipados?tabs=sharedipad" target="_blank" rel="noopener"&gt;Get started with iOS/iPadOS frontline worker devices&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These resources provide detailed implementation guidance, recommended enrollment approaches, and platform-specific considerations for frontline deployments.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Platform and OS Differences Matter&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Teams often assume that similar enrollment concepts behave the same way across platforms. They do not.&lt;/P&gt;
&lt;P&gt;On Android, a shared frontline device that needs a locked-down experience and individual worker sign-in often maps to Android Enterprise Dedicated Device with Microsoft Entra Shared Device Mode. Android Enterprise Dedicated Device provides the task-focused management model. Entra Shared Device Mode adds the identity layer so workers can sign in as themselves. Intune Managed Home Screen then helps present a consistent launcher experience and enforce the sign-in flow between shifts.&lt;/P&gt;
&lt;P&gt;On iPadOS, a shared device with individual sign-in may be designed using Shared iPad for Business or Automated Device Enrollment with Microsoft Entra Shared Device Mode. The distinction becomes important when security requirements are involved. Shared iPad can support multi-user scenarios, but organizations should review its limitations carefully, especially if Conditional Access or device compliance enforcement is required. Where Conditional Access, compliance, and security-driven access controls are mandatory, ADE with Entra Shared Device Mode may be the better fit, although it introduces additional configuration considerations and dependency on compatible apps. See &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/apple/shared-device-solutions-ios" target="_blank" rel="noopener"&gt;Shared iOS and iPadOS devices&lt;/A&gt; for more information.&lt;/P&gt;
&lt;P&gt;Platform differences also matter for corporate-owned devices that allow personal use. Android Corporate-Owned Work Profile provides a native work profile boundary between corporate and personal data. iOS and iPadOS do not provide that same OS-level separation for corporate-owned personally enabled devices, so organizations often rely more heavily on app-level controls and MAM policies.&lt;/P&gt;
&lt;P&gt;The practical point is simple: choose the enrollment model that fits the workflow, but confirm that the platform supports the management pattern you expect.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;When User-Driven Enrollment Makes Sense&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;User-driven enrollment still has a place in frontline, but the use cases are narrower than many teams expect. It makes sense when the device needs to reflect a specific person, not just a task.&lt;/P&gt;
&lt;P&gt;This can work well for shift managers, supervisors, clinicians, field workers, or frontline leads who need persistent access to apps, approvals, notifications, data, and settings. In these cases, user-driven or user-associated enrollment can provide cleaner app targeting, stronger identity context, and a more familiar experience for the person carrying the device.&lt;/P&gt;
&lt;P&gt;Common indicators include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The worker keeps the device for most of its working life.&lt;/LI&gt;
&lt;LI&gt;The user needs email, Teams, approvals, or real-time app badges.&lt;/LI&gt;
&lt;LI&gt;The workflow depends on user-specific apps, settings, or data.&lt;/LI&gt;
&lt;LI&gt;The device may support some personal enablement where the platform supports separation.&lt;/LI&gt;
&lt;LI&gt;The worker is responsible for keeping the device available, charged, and ready for use.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But personalization comes with operational cost. User-driven enrollment increases dependency on credentials, adds friction when sign-in steps fail, and makes recovery more complex when a device must be replaced quickly. It is usually a poor fit for shared workflows, high-turnover roles, or task-based devices where speed and predictability matter more than personalization.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Designing for Shared and Shift-Based Devices&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Shared and shift-based devices are passed from one worker to the next. They are expected to stay productive across handoffs and often operate in environments where there is little time for sign-in friction or troubleshooting.&lt;/P&gt;
&lt;P&gt;For these scenarios, device-first enrollment usually aligns better with reality because the device is treated as a managed tool for a shared workflow, not as a personal endpoint tied to one individual. The goal is consistency: the next worker should be able to pick up the device, authenticate if required, and get to work without recovering from leftover state or complex setup steps.&lt;/P&gt;
&lt;P&gt;If shared devices require individual sign-in, identity must be designed into the enrollment model. Microsoft Entra Shared Device Mode and QR code authentication can help preserve individual identity without forcing workers through a full username and password flow at every handoff. This is especially relevant in environments such as retail, healthcare, warehousing, and field operations where shared devices still need auditability, Conditional Access, app access, or user-specific sessions.&lt;/P&gt;
&lt;P&gt;Shared-device success does not come from default settings alone. Teams should define:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;How sign-in and sign-out should work.&lt;/LI&gt;
&lt;LI&gt;What user context should persist.&lt;/LI&gt;
&lt;LI&gt;What should be cleared between sessions.&lt;/LI&gt;
&lt;LI&gt;Which apps need to support shared-device behavior.&lt;/LI&gt;
&lt;LI&gt;How quickly a device can be swapped or reprovisioned.&lt;/LI&gt;
&lt;LI&gt;Whether access depends on the user, the device, the app session, or a combination.&lt;/LI&gt;
&lt;/UL&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;Especially in healthcare and clinical settings, shared devices have to be absolutely ready for the next worker, the next patient, and the next task. There is rarely time for complex recovery steps, unclear ownership, or leftover user state from the previous shift. A good shared-device design should support quick handoff, clean session behavior, and predictable recovery under pressure.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Dedicated and Kiosk Devices: Avoid Personalization Drift&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Dedicated and kiosk-style enrollment is ideal when the device performs a narrow, repeatable function and individual identity is secondary or unnecessary. Examples include scanners, point-of-sale systems, check-in kiosks, digital signage, inventory devices, and task-specific handhelds.&lt;/P&gt;
&lt;P&gt;The strength of kiosk-style design is that it limits choice. That is also the boundary teams must respect. A kiosk is not intended to behave like a general-purpose device where users browse a catalog of available apps, personalize settings, or install what their business unit needs on demand.&lt;/P&gt;
&lt;P&gt;A common friction point occurs when organizations try to simplify IT support with one shared kiosk configuration for multiple businesses or personas, and then expect users to install the apps they need. That creates a mismatch. User-installed available apps are not the kiosk paradigm. If each business unit needs a different set of apps, the better design is usually to do the work upfront: segment the device scenarios, define the required app sets, and deploy the right configuration to the right devices.&lt;/P&gt;
&lt;P&gt;This is also important for identity and certificates. User certificates, persistent user sessions, and shared secrets can conflict with the assumptions of a device-first or kiosk model. If the workflow requires user identity, auditability, or user-specific access, that requirement should be addressed through the right shared-device identity pattern, not bolted onto a kiosk design after the fact.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Enrollment at Scale: Plan for Provisioning and Replacement&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Once the right management model is selected, teams should plan how devices will be enrolled and reprovisioned at scale.&lt;/P&gt;
&lt;P&gt;At scale, enrollment becomes a lifecycle capability. The question is not only how a device gets into management the first time. Instead, it is how quickly that same device can be staged, replaced, wiped, repaired, reassigned, or reintroduced into service.&lt;/P&gt;
&lt;P&gt;Some organizations ship devices directly to frontline locations and complete setup during out-of-box experience. Others rely on depot, partner, or white-glove processes to front-load setup before the device reaches the site. Neither model is automatically better. The right choice depends on network readiness, site support, variability at first boot, app dependencies, certificate delivery, and replacement expectations.&lt;/P&gt;
&lt;P&gt;Replacement velocity is a real design constraint. In many frontline settings, a broken device cannot wait for a full troubleshooting cycle. A worker may need to drop one device at a charging bay and pick up another with minimal disruption. The more the enrollment and reprovisioning model supports a known-good state, the less productivity depends on one specific device surviving the shift.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Common Friction Points in Frontline Enrollment&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Frontline enrollment problems are rarely caused by one dramatic failure. More often, they come from reasonable decisions made in the wrong order or optimized for the wrong thing.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; overflow-x: auto;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-0078d4"&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Friction point&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Why it happens&lt;/SPAN&gt;&lt;/th&gt;&lt;th class="lia-border-color-custom-d1d1d1 lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;&lt;SPAN class="lia-text-color-16"&gt;Better design approach&lt;/SPAN&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating frontline as only shared&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;The organization assumes all frontline workers use devices the same way&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Segment by workflow: person, shift, task, or business process&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Choosing shared because dedicated devices are too expensive&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Budget drives the model before identity and workflow are understood&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate identity, app, compliance, and recovery needs before choosing shared&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using kiosk for personalized workflows&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Kiosk seems simple and locked down&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use kiosk only when the workflow is task-focused and does not require broad personalization&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Wanting available apps on kiosk devices&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;One configuration is used for too many personas&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Build scenario-specific app sets and configurations instead of relying on user installation&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Using shared credentials&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Enrollment was not designed for individual identity&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Use Entra Shared Device Mode, QR code authentication, or another supported identity pattern&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Requiring user certificates on device-first or kiosk scenarios&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Security assumptions are copied from knowledge-worker designs&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Validate whether access can be controlled through device, app, or session design&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-22"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Over-securing setup at the expense of recovery&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Controls are designed for ideal conditions, not shift pressure&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design security that holds up during replacement, poor connectivity, and limited support&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-f7f7f7"&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Treating enrollment as a one-time event&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Success is measured by initial provisioning only&lt;/td&gt;&lt;td class="lia-border-color-custom-d1d1d1 lia-vertical-align-top lia-border-style-solid" style="border-width: 1px; padding: 12px 14px;"&gt;Design for wipe, repair, reassignment, refresh, and reprovisioning&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A deployment path that saves time on day one can create years of friction if it does not match how the device is used. In frontline scenarios, the best enrollment model is not always the fastest one to provision. It is the one that is easiest to sustain.&lt;/P&gt;
&lt;/DIV&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;One of the most common mistakes I have seen is designing for the cleanest administrative model instead of the messiest operational reality. In FLW cases, the real test is not whether the device enrolls successfully on day one. It is whether the device can keep supporting the workflow after shift changes, network changes, app issues, wipes, repairs, and urgent replacements.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H2&gt;&lt;STRONG&gt;Closing&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Successful frontline deployments are rarely defined by the sophistication of their policies alone. They are defined by how well design choices hold up under real-world pressure. Enrollment is one of the earliest and most visible signals to frontline teams about whether the technology is there to support their work or get in the way.&lt;/P&gt;
&lt;P&gt;By treating enrollment as a deliberate design decision and grounding it in how devices are actually used, organizations can reduce friction, improve resilience, and create a foundation that scales as frontline operations evolve. Getting enrollment right does not guarantee success, but getting it wrong sets a ceiling that no amount of policy refinement can overcome.&lt;/P&gt;
&lt;P&gt;For more frontline examples and implementation guidance, see related Microsoft frontline worker management resources, including the blog, &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-the-frontlines-frontline-worker-management-with-microsoft-intune/4387449" target="_blank" rel="noopener" data-lia-auto-title="From the frontlines: Frontline worker management with Microsoft Intune" data-lia-auto-title-active="0"&gt;&lt;EM&gt;From the frontlines: Frontline worker management with Microsoft Intune&lt;/EM&gt;&lt;/A&gt;, and the earlier article, &lt;A class="lia-external-url" href="https://aka.ms/Intune/FLM-mobile-estate" target="_blank" rel="noopener"&gt;&lt;EM&gt;Migrating Frontline Mobile Devices: Understanding the Reality of Your Estate&lt;/EM&gt;&lt;/A&gt;.&lt;/P&gt;
&lt;BLOCKQUOTE style="margin: 28px 0; padding: 24px 28px; border-left: 5px solid #5b5fc7; border-radius: 0 8px 8px 0; background-color: #f5f6fa; color: #242424;"&gt;
&lt;P style="margin: 0 0 16px; font-size: 18px; line-height: 1.65;"&gt;&lt;SPAN style="font-size: 32px; line-height: 0; vertical-align: -6px;" aria-hidden="true"&gt;“&lt;/SPAN&gt;When enrollment, identity, security, and recovery are designed well, frontline teams can stay focused on the people they serve - customers, patients, guests, employees, students, and communities - instead of the device in their hands. That is the standard a frontline enrollment strategy should be measured against.&lt;/P&gt;
&lt;P style="margin: 0; font-size: 14px; line-height: 1.5; color: #555555;"&gt;&lt;STRONG style="color: #242424;"&gt;Sucheta Gawade&lt;/STRONG&gt;&lt;BR /&gt;Practitioner&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;As always, we welcome your feedback and experience. If you’ve navigated identity decisions for shared or frontline devices, share your advice and lessons learned in the comments, or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 16:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/designing-intune-enrollment-for-frontline-workers-choosing-the/ba-p/4540144</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-23T16:59:40Z</dc:date>
    </item>
    <item>
      <title>Build a patch strategy for today’s threat pace with Microsoft</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/build-a-patch-strategy-for-today-s-threat-pace-with-microsoft/ba-p/4535115</link>
      <description>&lt;P&gt;AI-accelerated vulnerability discovery and remediation are changing how organizations manage risk. As discussed in Pavan Davuluri’s recent &lt;A class="lia-external-url" href="https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery" target="_blank" rel="noopener"&gt;blog&lt;/A&gt;,&lt;STRONG&gt; &lt;/STRONG&gt;Microsoft is investing across the vulnerability lifecycle to help organizations identify, validate, and respond faster.&lt;/P&gt;
&lt;P&gt;For IT and security teams, one challenge lies downstream: deploying fixes quickly across endpoints to reduce exposure. Each update needs to be evaluated, piloted, monitored, and enforced across a mixed fleet of devices and apps. Some parts of the estate can move quickly; others cannot because of compliance requirements, approved change windows, and business-critical dependencies.&lt;/P&gt;
&lt;P&gt;As organizations adopt AI tools and agents across their environment, maintaining a current and hardened endpoint estate becomes increasingly important. In this context, patching becomes an ongoing operational discipline that combines OS, app, and driver updates with compliance enforcement, access control, and security baseline hardening.&lt;/P&gt;
&lt;P&gt;To keep pace, organizations need a patch strategy that helps in 3 stages:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Mitigate&lt;/STRONG&gt;: automate updates that can move quickly&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assess&lt;/STRONG&gt;: prioritize risk based on exposure and severity&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Contain&lt;/STRONG&gt;: enforce compliance and limit exposure&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Operationalizing a patch strategy requires coordinated capabilities across endpoint management and security tools. Microsoft Intune brings these capabilities together in a single admin center, alongside the broader Microsoft security ecosystem, and is available with qualifying Microsoft 365 subscriptions&lt;SUP&gt;1&lt;/SUP&gt;.&lt;/P&gt;
&lt;P&gt;In this post, we show how organizations can use these capabilities to build a patch strategy that helps reduce the time between update release and deployment across their endpoint estate.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;1. &lt;/STRONG&gt;&lt;STRONG&gt;Mitigate:&lt;/STRONG&gt; automate updates that can move quickly&lt;/H3&gt;
&lt;P&gt;A patch strategy is not about pushing every update everywhere at once. It’s about identifying the parts of your estate that can move quickly, then using automation, rings, monitoring, and enforcement to help those updates move with confidence. Regulations, approved change windows, validation needs, and business dependencies will shape what’s possible, but the strategy starts by separating repeatable update work from the exceptions that need deeper review.&lt;/P&gt;
&lt;P&gt;For OS, app, and driver updates that can move quickly, modern tools can help shorten the time between update release and deployment; without manual rollouts, ticket-driven packaging, or reboot disruption.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-groups-policies" target="_blank" rel="noopener"&gt;Windows Autopatch&lt;/A&gt; orchestrates ring-based update rollouts to reduce manual effort and keep Windows devices current. To help monitor risk, the Autopatch report visualizes how quickly devices apply updates based on the configured deployment cadence. In this report, devices are categorized as current within three days of update release, at risk between three and seven days, and at critical risk beyond seven days, based on the reporting model used by Windows Autopatch. Learn more about &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-groups-policies" target="_blank" rel="noopener"&gt;ring-based rollout updates&lt;/A&gt; or how to &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/protect-your-estate-reassess-your-windows-update-policies/4515228" target="_blank" rel="noopener" data-lia-auto-title="reassess Windows OS updates" data-lia-auto-title-active="0"&gt;reassess Windows OS updates&lt;/A&gt; using this report.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates" target="_blank" rel="noopener"&gt;Hotpatch&lt;/A&gt; (enabled by default for 24H2+ in Intune) applies critical updates without requiring a reboot, helping reduce security gaps while keeping users productive.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=QdjSkbKXoJw/1783549162389" data-video-remote-vid="https://www.youtube.com/watch?v=QdjSkbKXoJw/1783549162389" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FQdjSkbKXoJw%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DQdjSkbKXoJw&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FQdjSkbKXoJw%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 1: Watch the latest Microsoft Mechanics episode to see how Windows Autopatch and Hotpatch help organizations accelerate update deployment, reduce operational overhead, and keep devices secure.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Intune Enterprise App Management&lt;/A&gt; (EAM) supports keeping Windows apps current through auto-updates, including the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/update-enterprise-supersedence" target="_blank" rel="noopener"&gt;guided upgrade supersedence&lt;/A&gt; reporting, which surfaces outdated versions or version changes. EAM auto-updates are now generally available; details are included in the &lt;A class="lia-external-url" href="http://aka.ms/IntuneWN2606" target="_blank" rel="noopener"&gt;June Intune What’s new blog&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=iI-sJ6kz_vg/1783549052628" data-video-remote-vid="https://www.youtube.com/watch?v=iI-sJ6kz_vg/1783549052628" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FiI-sJ6kz_vg%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DiI-sJ6kz_vg&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FiI-sJ6kz_vg%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 2: Watch how Intune helps you move from update release to deployment to accelerate responses to vulnerabilities with Windows app management.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enhanced-app-inventory" target="_blank" rel="noopener"&gt;The enhanced application inventory&lt;/A&gt; in the All apps page shows the app version installed on each managed Windows device, refreshed multiple times per day on most active devices, helping teams target app-specific vulnerabilities and confirming when fixes have been applied.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;The Vulnerability Remediation Agent&lt;/A&gt; in Security Copilot uses data from Defender Vulnerability Management to prioritize Common Vulnerabilities and Exposures (CVEs) across Intune-managed Windows devices and apps, and provides recommended remediation actions within Intune. The Vulnerability Remediation Agent is&lt;STRONG&gt; &lt;/STRONG&gt;currently in public preview, &lt;A class="lia-external-url" href="http://aka.ms/Intune/VRA-blog" target="_blank" rel="noopener"&gt;read the blog to learn more&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=-xhy3yXGVGM/1783549191510" data-video-remote-vid="https://www.youtube.com/watch?v=-xhy3yXGVGM/1783549191510" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-xhy3yXGVGM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-xhy3yXGVGM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-xhy3yXGVGM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 3: Watch this video to see how the Vulnerability Remediation Agent in Security Copilot, within Microsoft Intune, helps make agentic security easier to adopt and use.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;
&lt;P class="lia-clear-both"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Apple devices&lt;/STRONG&gt; can be configured for &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/apple/planning-guide-macos" target="_blank" rel="noopener"&gt;automatic OS updates on managed devices&lt;/A&gt;, including enforcing updates to the latest version and deploying Background Security Improvement patches through the settings catalog. App updates can be managed by configuring &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/manage-vpp-apple" target="_blank" rel="noopener"&gt;volume-purchased App Store apps&lt;/A&gt; to update automatically and &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-dmg-macos" target="_blank" rel="noopener"&gt;deploy updated app packages&lt;/A&gt; to keep apps current across macOS, iPhone, and iPad devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Android devices&lt;/STRONG&gt; can be managed using &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/planning-guide" target="_blank" rel="noopener"&gt;built-in update policies in Intune&lt;/A&gt;, including configuring install windows and freeze periods. For corporate Android fleets, Intune also integrates with OEM firmware management solutions - including&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/setup-zebra-lifeguard" target="_blank" rel="noopener"&gt;Zebra LifeGuard Over-the-Air&lt;/A&gt; and &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/android/manage-fota" target="_blank" rel="noopener"&gt;Samsung E-FOTA&lt;/A&gt; - to enable more granular update control. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-managed-google-play" target="_blank" rel="noopener"&gt;Managed Google Play also supports configurable app auto-update modes&lt;/A&gt;, allowing admins to define whether updates install automatically, on Wi-Fi only, or manually.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;2. &lt;/STRONG&gt;&lt;STRONG&gt;Assess: &lt;/STRONG&gt;prioritize risk based on exposure and severity&lt;/H3&gt;
&lt;P&gt;The first step is reducing exposure across the parts of your estate that can move quickly. But not every system, application, or vulnerability can be addressed through broad update deployment. Teams also need a way to determine which risks require immediate action and which ones can be addressed over time.&lt;/P&gt;
&lt;P class=""&gt;A calendar-based approach can treat every CVE equally. However, it doesn’t account for severity, exposure, or business impact. As AI accelerates vulnerability discovery, this can lead to effort being spent on lower-risk updates while higher-risk updates remain unaddressed.&lt;/P&gt;
&lt;P&gt;Risk-based service level objectives (SLOs) help bring prioritization to address this challenge. Instead of patching on a fixed schedule, IT and security teams can align response timeframes by severity, moving quickly on actively exploited or critical vulnerabilities, and applying a more measured approach where risk or impact is lower.&lt;/P&gt;
&lt;P&gt;This stage creates a clearer prioritization of remediation and helps bridge the view between the security teams that identify threats and the IT teams that act on them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune and Microsoft Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;A class="lia-external-url" href="https://aka.ms/Intune" target="_blank" rel="noopener"&gt;security update status dashboard in Intune&lt;/A&gt; provides an aggregated view of update compliance across Windows clients, Windows servers, and Microsoft 365 Apps. It shows overall counts of devices in different states across Intune-endpoints and helps teams identify where remediation should be focused. These status categories reflect how quickly devices apply updates based on a configured deployment cadence and internal SLOs.&lt;BR /&gt;&lt;BR /&gt;&lt;img&gt;
&lt;P&gt;&lt;EM&gt;Figure 4: Security update dashboard showing patch status for Windows clients, servers, and Microsoft 365 apps.&lt;/EM&gt;&lt;/P&gt;
&lt;/img&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/defender-vulnerability-management/defender-vulnerability-management" target="_blank" rel="noopener"&gt;Microsoft Defender Vulnerability Management&lt;/A&gt; surfaces CVEs, affected devices, vulnerable software, and recommended remediation actions, offering a shared view of risk and progress across IT and security teams.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Translate Defender recommendations into targeted Intune actions described in the mitigate section, such as updating software or moving devices through expedited remediation workflows so teams can focus on vulnerabilities that are actively exploited or most likely to affect an organization.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;For Apple devices&lt;/STRONG&gt;, use the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/apple/monitor-reports" target="_blank" rel="noopener"&gt;Apple software update report&lt;/A&gt; in Intune to monitor update status across macOS, iOS, and iPadOS.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;For Android, &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/monitor-policy" target="_blank" rel="noopener"&gt;compliance reporting&lt;/A&gt; surfaces devices that fall behind on OS version or security patch level.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;&lt;STRONG&gt;3. &lt;/STRONG&gt;&lt;STRONG&gt;Contain&lt;/STRONG&gt;: enforce patch compliance and limit exposure&lt;/H3&gt;
&lt;P&gt;Even with automated deployments and prioritized triage, gaps can remain. Some devices are unsupported, fall behind, operate on slower deployment rings, and others can’t be patched quickly. A patch strategy needs to focus on including containment for those surfaces.&lt;/P&gt;
&lt;P&gt;Compliance controls, conditional access, and device hardening act as an always-on safety net that limits risks that can fall through gaps. Compliance policies and Conditional Access can use a patch state as a signal for resource access, preventing non-compliant devices from accessing corporate resources. Security baselines reduce the attack surface by limiting risky defaults and common attack patterns. Together, these controls shift enforcement from a periodic activity to a continuous condition across a fleet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Operationalize in Intune and Defender&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/compliance/overview" target="_blank" rel="noopener"&gt;compliance policies&lt;/A&gt; in Intune to define what "current" means, including minimum OS build, required update levels, risk status, and encryption state.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/conditional-access-integration/overview" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; (managed in Microsoft Entra, accessible from the Intune admin center) to control access to company resources based on user and device health. Combined with threat signals from Microsoft Defender, these policies help prevent non-compliant devices from accessing corporate resources.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use Microsoft Defender Vulnerability Management and &lt;A class="lia-external-url" href="https://learn.microsoft.com/security-exposure-management/microsoft-security-exposure-management" target="_blank" rel="noopener"&gt;Microsoft Security Exposure Management&lt;/A&gt; insights to identify exposed assets, prioritize remediation, and apply recommended protections where patching must move more slowly.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Apply Intune &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-security/security-baselines/overview" target="_blank" rel="noopener"&gt;security baselines&lt;/A&gt; to establish Microsoft-recommended configurations on Windows devices, such as disabling risky defaults, blocking common attack techniques, and reducing configuration drift. Watch this &lt;A class="lia-external-url" href="https://www.youtube.com/watch?v=V-QBO2cJn4E" target="_blank" rel="noopener"&gt;demo on security baselines&lt;/A&gt; being applied in the &lt;A class="lia-external-url" href="https://zerotrust.microsoft.com/" target="_blank" rel="noopener"&gt;Zero Trust workshop&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/attack-surface-reduction" target="_blank" rel="noopener"&gt;attack surface reduction policies in Intune&lt;/A&gt; to deploy Microsoft Defender for Endpoint protections, such as ASR rules and network protection, that help block common attack techniques on devices that can't be patched right away.&lt;BR /&gt;&lt;BR /&gt;&lt;div data-video-id="https://www.youtube.com/watch?v=9TFhIRHma1E&amp;amp;t/1783554817508" data-video-remote-vid="https://www.youtube.com/watch?v=9TFhIRHma1E&amp;amp;t/1783554817508" class="lia-video-container lia-media-is-center lia-media-size-medium"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F9TFhIRHma1E%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D9TFhIRHma1E&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F9TFhIRHma1E%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;span class="lia-media-caption-text"&gt;
&lt;P&gt;&lt;EM&gt;Figure 5: Watch this Demo on how you can manage devices and implement Conditional Access with Intune.&lt;/EM&gt;&lt;/P&gt;
&lt;/div&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Extend across your endpoint estate&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Compliance policies and Conditional Access controls apply across Windows, macOS, iOS/iPadOS, and Android.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Intune &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/protection/overview" target="_blank" rel="noopener"&gt;app protection policies&lt;/A&gt; extend compliance requirements and data protections to managed apps used for work on personal devices and add an additional layer of data protection on corporate devices.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog" target="_blank" rel="noopener"&gt;settings catalog&lt;/A&gt; and configuration profiles to apply the same hardening intent on macOS, iOS/iPadOS, and Android, reducing configuration drift across platforms.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Stay ahead with a patch strategy&lt;/H3&gt;
&lt;P&gt;As vulnerability discovery and response continue to accelerate, organizations need an operational strategy that balances speed, risk, and resilience. By automating updates where possible, prioritizing remediation based on exposure, and limiting exposure through compliance and security controls, teams can reduce risk across their endpoint estate.&lt;/P&gt;
&lt;P&gt;Intune helps simplify this approach by bringing these capabilities together alongside the rest of your Microsoft security tools and ecosystem.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://security.microsoft.com/securenow" target="_blank" rel="noopener"&gt;Get started with Microsoft Secure Now&lt;/A&gt; to assess risk across your digital estate.&lt;/LI&gt;
&lt;LI&gt;Explore the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is-foundational-to-/4513766" target="_blank" rel="noopener" data-lia-auto-title="new security update status dashboard" data-lia-auto-title-active="0"&gt;new security update status dashboard&lt;/A&gt; in Intune.&lt;/LI&gt;
&lt;LI&gt;Harden the admin plane and review the &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/best-practices-for-securing-microsoft-intune/4502117" target="_blank" rel="noopener" data-lia-auto-title="best practices for securing Microsoft Intune" data-lia-auto-title-active="0"&gt;best practices for securing Microsoft Intune&lt;/A&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR style="border: 0; border-top: 1px solid #e5e5e5; margin: 32px 0 20px 0;" /&gt;
&lt;DIV style="font-size: 13px; line-height: 1.6; color: #666666;"&gt;
&lt;P&gt;&lt;SUP&gt;1&lt;/SUP&gt; &lt;STRONG&gt;Licensing and requirements&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Feature availability and included capabilities vary by Microsoft 365 subscription plan and feature. Some Microsoft capabilities referenced in this post may require specific licenses or additional enablement.&lt;/P&gt;
&lt;P&gt;Advanced Microsoft Intune capabilities are now included &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/advanced-microsoft-intune-capabilities-now-available-in-microsoft-365-e3-and-e5/4529335" target="_blank" rel="noopener" data-lia-auto-title="in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3" data-lia-auto-title-active="0"&gt;in Microsoft 365 E5, with select capabilities available in Microsoft 365 E3&lt;/A&gt; as part of updates effective July 1, 2026. Existing customers will receive a 30-day notice in the Microsoft Admin Center prior to availability, with access beginning by August 2026.&lt;/P&gt;
&lt;P&gt;Microsoft Security Copilot and related AI capabilities may require separate licensing, &lt;A class="lia-external-url" href="https://aka.ms/SecurityCopilotPricing" target="_blank" rel="noopener"&gt;learn more here&lt;/A&gt;.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Stay up to date! Bookmark the &lt;/EM&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/category/microsoftintune/blog/microsoftintuneblog" target="_blank" rel="noopener" data-lia-auto-title="Microsoft Intune Blog" data-lia-auto-title-active="0"&gt;Microsoft Intune Blog&lt;/A&gt;&lt;EM&gt; and follow us on LinkedIn or&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/MSIntune" target="_blank" rel="noopener"&gt;@MSIntune&lt;/A&gt; and &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt; on X to continue the conversation.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 17:18:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/build-a-patch-strategy-for-today-s-threat-pace-with-microsoft/ba-p/4535115</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-10T17:18:27Z</dc:date>
    </item>
    <item>
      <title>Migrating frontline mobile devices: Identity considerations for assigned and shared devices</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/migrating-frontline-mobile-devices-identity-considerations-for/ba-p/4532671</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Carol Burns - Principal Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Practitioner perspective from Sucheta Gawade, Microsoft MVP (Azure &amp;amp; Security / Intune), with deep experience in secure frontline mobility, including regulated healthcare environments.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In previous articles in this series, we focused on &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/migrating-frontline-mobile-devices-understanding-the-reality-of-your-estate/4511683" target="_blank" rel="noopener" data-lia-auto-title="understanding the reality of your frontline device estate" data-lia-auto-title-active="0"&gt;understanding the reality of your frontline device estate&lt;/A&gt; and preparing for real-world testing through &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/migrating-frontline-mobile-devices-aligning-stakeholders-before-real-world-testi/4516511" target="_blank" rel="noopener" data-lia-auto-title="stakeholder alignment" data-lia-auto-title-active="0"&gt;stakeholder alignment&lt;/A&gt;. One of the most critical areas to get right during the testing phase is identity and security, particularly given the often fast-paced, shift-based nature of frontline work, where organizations must account for the distinct requirements and challenges of devices assigned to a single individual versus devices shared across multiple users or shifts.&lt;/P&gt;
&lt;P&gt;Identity decisions directly affect security posture, sign‑in experience, operational support overhead, and worker productivity. Getting them wrong is one of the most common reasons pilots stall or fail.&lt;/P&gt;
&lt;P&gt;This article explores how to think about identity on frontline devices by distinguishing between assigned and shared usage models, clarifying when individual sign-in is required, and highlighting patterns to avoid such as shared accounts and passwords.&lt;/P&gt;
&lt;H2&gt;Start by distinguishing device usage models&lt;/H2&gt;
&lt;P&gt;Frontline mobile devices generally fall into one of two broad categories.&lt;/P&gt;
&lt;H3&gt;Assigned devices&lt;/H3&gt;
&lt;P&gt;Assigned devices are issued to a specific individual, often for the duration of their role. These devices:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Typically require persistent access to user‑specific data&lt;/LI&gt;
&lt;LI&gt;Align with user‑based identity, Microsoft Entra ID Conditional Access, and audit controls.&lt;/LI&gt;
&lt;LI&gt;Enable greater accountability and traceability by associating activity with an individual user rather than a shared credential.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Common examples include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A doctor using an individually assigned clinical tablet, where uninterrupted access to patient data and clinical systems is essential and actions must always be attributable to a named identity&lt;/LI&gt;
&lt;LI&gt;A field engineer assigned a single device that retains configuration, credentials, and offline content across jobs and locations&lt;/LI&gt;
&lt;LI&gt;An inspector or supervisor using an assigned device for approvals, reporting, and decision‑making that requires traceability&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Shared devices&lt;/H3&gt;
&lt;P&gt;Shared devices are used by multiple people across shifts or tasks. These scenarios introduce additional identity complexity and generally fall into two distinct models.&lt;/P&gt;
&lt;H3&gt;Shared devices without user sign-in (task or kiosk-based)&lt;/H3&gt;
&lt;P&gt;Some frontline devices exist to perform a narrow, often repetitive task and don’t require sign in with a user account.&lt;/P&gt;
&lt;P&gt;Typical examples include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Retail price-check devices used on the shop floor to scan an item and display its current price or stock availability, with no need for access to personal or user-specific information&lt;/LI&gt;
&lt;LI&gt;Environmental monitoring devices used to read and record temperature or humidity in a storage area, ward, or vehicle, where the task is simple, repetitive, and not tied to an individual user identity&lt;/LI&gt;
&lt;LI&gt;Warehouse or facility scanning devices used for a narrow operational task such as scanning an asset, bin, or location code to confirm status, location, or completion of a step in a process&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In these cases:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Devices are locked down to a specific task&lt;/LI&gt;
&lt;LI&gt;No user-specific data is stored, and access is limited to the minimum required for the task&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;“When a device is truly task-only, removing sign-in friction is a huge win, but only if we’re aware what data the device can access. When things like patient context or personalized tasks enter the picture, identity becomes required” - &lt;EM&gt;Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;H3&gt;Shared devices with individual user sign-in&lt;/H3&gt;
&lt;P&gt;Organizations are increasingly digitizing and modernizing frontline workflows end-to-end. Paper processes and simple apps give way to connected systems, manual handovers are replaced with digital task lists, and workers begin to rely on mobile devices as their primary interface from completing tasks.&lt;/P&gt;
&lt;P&gt;As roles evolve, workers are expected to:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Receive tasks, schedules, and updates digitally&lt;/LI&gt;
&lt;LI&gt;Communicate with supervisors and peers using collaboration tools such as Microsoft Teams&lt;/LI&gt;
&lt;LI&gt;Capture information at the point of work rather than transcribing later&lt;/LI&gt;
&lt;LI&gt;Interact with workflows that are increasingly automated or assisted by AI, such as guided steps, data validation, or suggested actions&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This shift delivers clear productivity and quality benefits, but it also means access must now be tied to individual identity to protect sensitive data, support auditability, and prevent information from being carried over between users.&lt;/P&gt;
&lt;P&gt;Common scenarios include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Retail store associates rotating across shifts, moving from paper schedules and verbal handovers to digital task lists, real-time communications, and collaboration tools such as Microsoft Teams&lt;/LI&gt;
&lt;LI&gt;Nurses sharing mobile devices in a hospital ward, where paper notes and whiteboards are replaced with secure access to patient-linked applications, care coordination tools, and role-based alerts&lt;/LI&gt;
&lt;LI&gt;Logistics workers signing in to shared devices to complete role-based tasks, capture data at the point of work, and interact with AI-assisted workflows.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Don’t use shared credentials, always prefer individual sign-in&lt;/H3&gt;
&lt;P&gt;Shared credentials may seem like a shortcut in frontline environments, but they undermine accountability and make policy enforcement and incident response significantly harder.&lt;/P&gt;
&lt;P&gt;“Shared credentials feel ‘efficient’ until your first incident. You lose auditability, Conditional Access becomes meaningless, and investigations turn into guesswork. Individual identity is the only scalable model.” &lt;EM&gt;-Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;If access involves corporate systems or sensitive data, each worker should use their individual credentials to sign in, even on a shared device.&lt;/P&gt;
&lt;H2&gt;Identity decision checklist for frontline devices&lt;/H2&gt;
&lt;P&gt;Use the checklist to validate identity choices and confirm that the overall security posture matches the way the device is used.&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Decision area&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Indicators&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use individual sign-in&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Users access personal or role-specific data.&lt;/LI&gt;
&lt;LI&gt;Auditability or compliance is required.&lt;/LI&gt;
&lt;LI&gt;Conditional Access or multifactor authentication (MFA) must be enforced.&lt;/LI&gt;
&lt;LI&gt;Applications rely on user identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use kiosk-style or device-only identity&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Devices perform a single task.&lt;/LI&gt;
&lt;LI&gt;No user-specific or sensitive organizational data is accessed.&lt;/LI&gt;
&lt;LI&gt;Workflows are entirely device-centric.&lt;/LI&gt;
&lt;LI&gt;Speed and simplicity outweigh personalization.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Avoid entirely&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;
&lt;UL&gt;
&lt;LI&gt;Shared usernames or passwords.&lt;/LI&gt;
&lt;LI&gt;Reused local accounts across shifts.&lt;/LI&gt;
&lt;LI&gt;MFA exclusions that weaken security without compensating controls.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 35.00%" /&gt;&lt;col style="width: 65.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H2&gt;Choosing the right sign‑in experience&lt;/H2&gt;
&lt;P&gt;The challenge in frontline environments is balancing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Security requirements&lt;/LI&gt;
&lt;LI&gt;Speed of access&lt;/LI&gt;
&lt;LI&gt;Ease of use across shifts&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;“Frontline setups may fail because the sign-in flow doesn’t match reality. If authentication takes 60 seconds and the worker has to do it 30 times a shift, they’ll find a workaround.”&lt;STRONG&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;-Sucheta Gawade, Microsoft MVP&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Typing complex usernames and passwords repeatedly during a shift is often impractical on mobile devices. QR code authentication is one effective option for shared frontline devices, but it’s not the only supported approach. For other supported methods, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/overview-authentication" target="_blank" rel="noopener"&gt;Microsoft Entra authentication methods overview.&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;QR code authentication&lt;/H3&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/how-to-authentication-qr-code" target="_blank" rel="noopener"&gt;Microsoft Entra QR code authentication&lt;/A&gt; is designed for frontline workers to sign-in efficiently on shared Android and iOS/iPadOS devices without repeatedly entering usernames and passwords.&lt;/P&gt;
&lt;DIV style="margin: 16px 0; padding: 14px 16px; border-left: 4px solid #0078d4; background: #f3f9fd; border-radius: 4px; color: #242424;"&gt;&lt;STRONG style="color: #005a9e;"&gt;Note:&lt;/STRONG&gt;&amp;nbsp;&lt;SPAN class="tooltip" tabindex="0"&gt;For individually assigned devices, phishing-resistant, passwordless authentication methods are the recommended approach, such as &lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-passkeys-fido2" target="_blank" rel="noopener"&gt;Passkeys&lt;/A&gt;.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;QR code authentication enables workers to sign in using a unique QR code and a personal numeric PIN.&lt;/P&gt;
&lt;P&gt;This approach:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Eliminates typed usernames and passwords&lt;/LI&gt;
&lt;LI&gt;Preserves individual identity&lt;/LI&gt;
&lt;LI&gt;Works well for shared devices with frequent user turnover&lt;/LI&gt;
&lt;LI&gt;Integration with Microsoft Intune, Managed Home Screen and Conditional Access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;QR code authentication should always be:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Scoped to specific users and devices&lt;/LI&gt;
&lt;LI&gt;Combined with Conditional Access policies&lt;/LI&gt;
&lt;LI&gt;Evaluated during real‑world testing to ensure the right balance of usability and security&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Security posture and Conditional Access for frontline devices&lt;/H2&gt;
&lt;P&gt;Individual identity is a critical foundation for stronger security posture, but it’s not enough on its own. Frontline device security also depends on management, data and app protection, session handling, and access policies that reflect the actual usage model.&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/conditional-access/overview" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; is an important part of securing frontline environments, but its effectiveness depends on aligning policies to the actual device and identity model in use.&lt;/P&gt;
&lt;P&gt;To ensure that the &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/concept-authentication-qr-code" target="_blank" rel="noopener"&gt;QR code authentication method&lt;/A&gt; can only be used by the frontline workers it’s intended for, &lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/authentication/concept-authentication-strength-advanced-options" target="_blank" rel="noopener"&gt;create a custom authentication methods policy&lt;/A&gt;, which you can use in a dedicated Conditional Access policy. That Conditional Access policy should then be scoped to the group of users (frontline workers) who should log on using the QR code authentication method, and have the &lt;STRONG&gt;Require authentication strength&lt;/STRONG&gt; control configured, which targets the custom authentication strength for "QR Code" which was previously created.&lt;/P&gt;
&lt;P&gt;During real‑world testing:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Validate that design and controls support the intended usage model&lt;/LI&gt;
&lt;LI&gt;Ensure policies don’t block legitimate workflows&lt;/LI&gt;
&lt;LI&gt;Confirm sessions, access, and user targeting behave as expected&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;These decisions should also be validated in practice: can users sign in and out reliably across shifts, is personal data cleared between sessions, and does the chosen experience match the pace of frontline work?&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;P&gt;This article walks through how identity choices shape security, usability, and day-to-day success for frontline mobile devices. It explains the difference between assigned and shared devices, when individual sign-in is needed, and why shared credentials can create risk. It also highlights QR code authentication and Conditional Access as practical ways to keep each worker’s identity protected while making sign-in simple enough for fast-paced frontline workflows.&lt;/P&gt;
&lt;H2&gt;What’s next in the series&lt;/H2&gt;
&lt;P&gt;In the next article, we’ll focus on Microsoft Intune enrollment models, exploring how different enrollment approaches support—or constrain—the identity and usage patterns discussed here, including their role in protecting session identity, enforcing the intended sign-in model, and preventing one user’s access or data from carrying over to the next.&lt;/P&gt;
&lt;P&gt;As always, we welcome your feedback and experience. If you’ve navigated identity decisions for shared or frontline devices, share your advice and lessons learned in the comments, &amp;nbsp;or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;For more guidance across frontline scenarios, explore our broader &lt;A href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/from-the-frontlines-frontline-worker-management-with-microsoft-intune/4387449" target="_blank" rel="noopener"&gt;&lt;EM&gt;From the Frontlines&lt;/EM&gt;&lt;/A&gt; series on frontline worker management with Microsoft Intune.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2026 18:00:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/migrating-frontline-mobile-devices-identity-considerations-for/ba-p/4532671</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-07-01T18:00:50Z</dc:date>
    </item>
    <item>
      <title>Streamlining macOS security: Automatically enable AutoFill after Platform SSO registration</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/streamlining-macos-security-automatically-enable-autofill-after/ba-p/4531908</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Chris Kunze - Principal Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Platform single sign-on (SSO) improves how macOS devices establish identity with Microsoft Entra ID, enabling a more secure and streamlined authentication experience. However, completing Platform SSO registration isn’t enough to deliver a fully passwordless workflow. To enable passwordless authentication in Safari, Microsoft Edge, and Google Chrome, the Company Portal AutoFill extension must also be enabled. In many deployments, this step still depends on the user.&lt;/P&gt;
&lt;P&gt;Devices may be fully enrolled, and Platform SSO may be successfully registered, yet users can still fall back to entering credentials manually if Company Portal AutoFill is not enabled. At scale, even small manual configuration steps can lead to inconsistent results. The goal of this post is to remove that dependency by automatically enabling AutoFill after Platform SSO registration, so users receive a complete passwordless experience without any additional steps.&lt;/P&gt;
&lt;H2&gt;The challenge&lt;/H2&gt;
&lt;P&gt;After Platform SSO is deployed to a macOS device, two conditions must be met before users receive the intended passwordless experience:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Platform SSO registration must be completed&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;The device must complete Platform SSO registration with Microsoft Entra ID.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Company Portal AutoFill must be enabled&lt;/STRONG&gt;&lt;BR /&gt;The Company Portal AutoFill extension must be enabled for supported browsers so credentials can be supplied automatically.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When Platform &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-platform-sso-with-registration-during-automated-device-enrollment-on-macos/4519846" target="_blank" rel="noopener" data-lia-auto-title="SSO registration happens after Setup Assistant" data-lia-auto-title-active="0"&gt;SSO registration happens after Setup Assistant&lt;/A&gt;, the user is prompted through the registration flow and receives a reminder to enable Company Portal AutoFill. However, enabling AutoFill is still a separate manual step that the user must complete. If the user skips or overlooks that step, the device can be successfully registered for Platform SSO while still requiring credentials to be entered manually. The result is a deployment that appears complete but does not consistently deliver the intended passwordless experience or security posture. Authentication should not depend on user action after enrollment.&lt;/P&gt;
&lt;H2&gt;Especially valuable with the “Enable Registration During Setup” setting&lt;/H2&gt;
&lt;P&gt;This approach becomes especially impactful when combined with the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/configure-platform-sso-during-enrollment" target="_blank" rel="noopener"&gt;Enable Registration During Setup&lt;/A&gt; setting for Platform SSO. When used with &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-enrollment/apple/overview-automated-enrollment-macos" target="_blank" rel="noopener"&gt;Automated Device Enrollment (ADE)&lt;/A&gt;, Platform SSO registration can be completed automatically during Setup Assistant before the user reaches the desktop. This helps ensure identity registration completes as part of the provisioning experience rather than requiring additional post-enrollment actions.&lt;/P&gt;
&lt;H2&gt;Automating AutoFill after Platform SSO registration&lt;/H2&gt;
&lt;P&gt;After registration has completed, AutoFill often becomes the final remaining step that still depends on user action. To close this gap, you can use a custom script to enable the Company Portal AutoFill extension after Platform SSO registration is complete.&lt;/P&gt;
&lt;P&gt;The sample script, Check-PSSO.zsh, available in the &lt;A class="lia-external-url" href="https://github.com/microsoft/shell-intune-samples/tree/master/macOS/Config/Set%20Autofill%20Automatically%20after%20PSSO%20Registration" target="_blank" rel="noopener"&gt;GitHub repository&lt;/A&gt;, was written by the Intune Customer Experience Engineering team. The script detects when Platform SSO registration has completed on a device and then enables AutoFill automatically.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV style="margin: 16px 0; padding: 14px 16px; border-left: 4px solid #c50f1f; background: #fdf3f4; border-radius: 4px; color: #242424;"&gt;&lt;STRONG style="color: #a80000;"&gt;Important:&lt;/STRONG&gt; &lt;SPAN class="tooltip" tabindex="0"&gt; Microsoft supports Intune’s ability to deploy scripts, but not the scripts themselves. &lt;SPAN class="tooltip-text" role="tooltip"&gt;&amp;nbsp;Microsoft fully supports Intune and its script deployment capabilities. However, Microsoft does not provide support for individual scripts, including scripts published in Microsoft GitHub repositories. These scripts are provided as examples only. You are responsible for reviewing, validating, and testing their behavior in your environment before deploying them broadly.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;P&gt;&lt;BR /&gt;The script essentially performs four key actions:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Wait for a user session&lt;/STRONG&gt; - The script detects when a user session is active to ensure the device is ready for configuration.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Verify Platform SSO registration - &lt;/STRONG&gt;It confirms that Platform SSO registration has completed successfully before proceeding.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Detect the AutoFill extension - &lt;/STRONG&gt;The script waits until the Company Portal AutoFill extension becomes available on the device.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enable AutoFill automatically - &lt;/STRONG&gt;Once detected, the script enables AutoFill programmatically, eliminating the need for users to manually configure the setting in System Settings.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;All activities are logged locally, providing visibility for auditing and troubleshooting.&lt;/P&gt;
&lt;H2&gt;Supported browsers&lt;/H2&gt;
&lt;P&gt;The Company Portal AutoFill extension works with:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Safari (native support)&lt;/LI&gt;
&lt;LI&gt;Microsoft Edge (native support)&lt;/LI&gt;
&lt;LI&gt;Google Chrome (requires &lt;A class="lia-external-url" href="https://chromewebstore.google.com/detail/windows-accounts/ppnbnpeolgkicgegkbkbjmhlideopiji" target="_blank" rel="noopener"&gt;Microsoft Single Sign On extension&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Once AutoFill is enabled, users can authenticate across all supported browsers on their macOS device without manually entering passwords.&lt;/P&gt;
&lt;H2&gt;System requirements&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;macOS 15 or later&lt;/LI&gt;
&lt;LI&gt;Company Portal version 5.2604.0 or later installed on the device&lt;/LI&gt;
&lt;LI&gt;Platform SSO configured via an &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/configuration/use-enterprise-sso-plug-in-macos-with-intune" target="_blank" rel="noopener"&gt;Intune SSO extension profile&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Deployment via Intune&lt;/H2&gt;
&lt;P&gt;The Check-PSSO script is deployed using a lightweight, scalable approach aligned with modern macOS management practices.&lt;/P&gt;
&lt;P&gt;The recommended method is to package the script as a &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/exploring-the-use-cases-of-payloadless-packages-in-microsoft-intune-for-macos/4382728" target="_blank" rel="noopener" data-lia-auto-title="payloadless PKG" data-lia-auto-title-active="0"&gt;payloadless PKG&lt;/A&gt; with a pre-install script.&lt;/P&gt;
&lt;P&gt;High-level steps:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Build an empty PKG&lt;/LI&gt;
&lt;LI&gt;Attach the Check-PSSO script as a pre-install script&lt;/LI&gt;
&lt;LI&gt;Upload the package to Intune&lt;/LI&gt;
&lt;LI&gt;Assign it as &lt;STRONG&gt;Required&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Verify successful deployment through script logs&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Detailed instructions are available in the &lt;A class="lia-external-url" href="https://github.com/microsoft/shell-intune-samples/tree/master/macOS/Config/Set%20Autofill%20Automatically%20after%20PSSO%20Registration" target="_blank" rel="noopener"&gt;GitHub repository&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;Key Features&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;Polling with timeouts&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The script waits for the required conditions to be met before continuing, including an active user session and completed Platform SSO registration. To avoid indefinite loops in edge-case scenarios, it uses timeouts while polling for those conditions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Diagnostic logging and auditing&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Optional verbose logging provides detailed troubleshooting information and an audit trail confirming AutoFill was enabled. Each run is logged locally under:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;/Library/Logs/Microsoft/IntuneScripts/checkPSSO&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Clear exit codes&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Exit 0: Success&lt;/LI&gt;
&lt;LI&gt;Exit 1: Failure&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;div data-video-id="https://youtu.be/b9nMSNOnQEo/1782756754391" data-video-remote-vid="https://youtu.be/b9nMSNOnQEo/1782756754391" class="lia-video-container lia-media-is-center lia-media-size-large"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2Fb9nMSNOnQEo%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Db9nMSNOnQEo&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2Fb9nMSNOnQEo%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" allowfullscreen="" style="max-width: 100%"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;H2&gt;Benefits of automating AutoFill&lt;/H2&gt;
&lt;P&gt;Automating AutoFill helps ensure users can take advantage of passwordless authentication without additional configuration steps. It reduces reliance on user action, improves deployment consistency, improves security posture, and supports zero-touch provisioning. It also provides admins with verification through centralized logging and reporting.&lt;/P&gt;
&lt;H2&gt;Get started&lt;/H2&gt;
&lt;P&gt;If you’ve already deployed Platform SSO, automating AutoFill is a natural next step toward delivering a complete passwordless experience. By removing a manual configuration step that often depends on user action, you can improve consistency and user experience across devices. When combined with the Enable Registration During Setup setting, this helps create a true zero-touch experience from enrollment through authentication.&lt;/P&gt;
&lt;H2&gt;Learn more&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/devices/macos-psso" target="_blank" rel="noopener"&gt;Platform SSO for macOS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/user-help/what-happens-if-you-install-the-company-portal-app-and-enroll-your-mac-in-intune" target="_blank" rel="noopener"&gt;Company Portal for macOS&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/exploring-the-use-cases-of-payloadless-packages-in-microsoft-intune-for-macos/4382728" target="_blank" rel="noopener" data-lia-auto-title="Payloadless Packages in Intune (Tech Community)" data-lia-auto-title-active="0"&gt;Payloadless Packages in Intune (Tech Community)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A class="lia-external-url" href="https://github.com/microsoft/shell-intune-samples" target="_blank" rel="noopener"&gt;Microsoft shell-intune-samples Repository&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;BR /&gt;Let us know if you have questions by leaving a comment below or reaching out on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppteam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at&amp;nbsp;&lt;A href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 18:31:55 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/streamlining-macos-security-automatically-enable-autofill-after/ba-p/4531908</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-29T18:31:55Z</dc:date>
    </item>
    <item>
      <title>Microsoft Intune and Apple platform updates: What to expect after WWDC 2026</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-and-apple-platform-updates-what-to-expect-after/ba-p/4531058</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By Benjamin Flamm | Product Manager, Iris Yuning Ye | Product Manager - Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Apple’s Worldwide Developers Conference (WWDC) is the annual starting point for the next wave of Apple platform changes. For Microsoft Intune customers, WWDC is also the moment when IT teams begin planning how new operating system capabilities will affect Apple device management, security, app deployment, and user readiness ahead of the fall OS releases. We’ve spent time watching and re-watching the sessions, sifting through new documentation with a magnifying glass, and philosophizing over the impact of what’s new this year. Just like every year, we’ll still have our day zero blog officially announcing what Intune supports for the new OS versions; however, this year we’ve heard your feedback that you’d like to know where Intune is prioritizing investments ahead of time so that you can prepare with confidence.&lt;/P&gt;
&lt;H2&gt;What’s new in managing Apple devices&lt;/H2&gt;
&lt;P&gt;Our team is absolutely thrilled&lt;STRONG&gt; &lt;/STRONG&gt;by the latest WWDC announcements and what they mean for organizations using Intune to manage Apple devices at scale. Apple is executing their promise of a declarative future, and we’re excited to enable our customers to leverage the benefits of declarative device management (DDM) like efficient configurations and real time status reporting. Most importantly, Apple continues to provide new customer-delighting functionality that previously didn’t exist in the legacy protocol.&lt;/P&gt;
&lt;H3&gt;Data-driven settings&lt;/H3&gt;
&lt;P&gt;The Intune settings catalog is our data-driven experience that automatically generates UI based on a schema. Basically, Intune adds new settings very quickly. Our goal is to always provide new settings like restrictions and intelligence controls as fast as possible, but in a way that’s enterprise ready. Having to manually create policies in third party tools just to upload them into the Intune admin center is a thing of the past. That said, these are the configurations and settings announced at WWDC 2026 that will be available very soon in the settings catalog for testing on the OS 27 betas.&lt;/P&gt;
&lt;H4&gt;Allow and deny binaries on macOS&lt;/H4&gt;
&lt;P&gt;One of the biggest announcements for device management this year is the new App settings configuration which includes declarative binary management for Mac. Until now, admins have relied on third party tooling and scripting for controlling unwanted apps on macOS, which is a clunky and time-consuming process. This new configuration also brings privacy permission management to DDM, reducing the number of prompts that users see while ensuring that apps have the permissions they need.&lt;/P&gt;
&lt;H4&gt;Content caching&lt;/H4&gt;
&lt;P&gt;Content caching has been supported in mobile device management (MDM) and our settings catalog for years, but it’s becoming much more powerful as it moves to DDM in macOS 27. New status items provide richer information about the &lt;A class="lia-external-url" href="https://developer.apple.com/documentation/devicemanagement/statuscontentcacheservicecontentcachestatusobject" target="_blank"&gt;health, disk space, and usage&lt;/A&gt; of content cache services without requiring a separate monitoring agent. This will be especially useful for everyone who wants to significantly reduce network traffic due to large deployments such as multi-gigabyte app installations and OS updates.&lt;/P&gt;
&lt;H4&gt;Platform Single Sign-on&lt;/H4&gt;
&lt;P&gt;Platform Single Sign-on (Platform SSO) picked up a major set of upgrades this year as part of its transition to DDM: the option to require Touch ID as a built-in second factor for logging in and unlocking FileVault. Additionally, new web-based authentication that opens the door to customizable push notifications, one-time codes, and QR-code sign-in for shared-device environments.&lt;/P&gt;
&lt;H4&gt;New skip keys for Automated Device Enrollment&lt;/H4&gt;
&lt;P&gt;Our settings story wouldn’t be complete without mentioning skip keys, and we have so much to mention this year! You may have seen the news that we recently updated our Apple enrollment policies, but what you may have missed is that these use the same infrastructure as our settings catalog. Starting this year, you should now expect to see skip keys release as fast as the Apple settings catalog.&lt;/P&gt;
&lt;H4&gt;Settings, settings, and more settings&lt;/H4&gt;
&lt;P&gt;Everything we’ve talked about so far is only the tip of the iceberg for settings and what’s coming, so here’s the complete list of what you should expect to see in Intune this summer:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;App Settings
&lt;UL&gt;
&lt;LI&gt;Allow/deny macOS binaries&lt;/LI&gt;
&lt;LI&gt;App privacy&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Content caching&lt;/LI&gt;
&lt;LI&gt;DNS Settings&lt;/LI&gt;
&lt;LI&gt;DNS Proxy&lt;/LI&gt;
&lt;LI&gt;Extensible SSO&lt;/LI&gt;
&lt;LI&gt;Safari privacy&lt;/LI&gt;
&lt;LI&gt;Web Content Filter&lt;/LI&gt;
&lt;LI&gt;Apple Intelligence (Calendar)&lt;/LI&gt;
&lt;LI&gt;Device restrictions&lt;/LI&gt;
&lt;LI&gt;Skip keys&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Network configurations are now in DDM&lt;/H3&gt;
&lt;P&gt;This is the announcement that we’ve been waiting for ever since Apple first showed us the power of DDM! While there isn’t Wi-Fi support yet, we’re thrilled to see this first step into DDM-based network configurations. The on-device user experience and admin configuration experience will see significant improvements in comparison to today’s profile model, especially when managing policies that depend on certificates for authentication. Our team is evaluating the new network configurations for our roadmap as we build support for these critical workloads in a declarative world.&lt;/P&gt;
&lt;H3&gt;Fleet monitoring and MDM status&lt;/H3&gt;
&lt;P&gt;The more device information that Apple moves to DDM, the faster Intune will become. The 15-minute check-in will soon be obsolete as MDM can solely rely on the device to detect drift or issues. This year, Apple has continued to add more device information to the DDM status channel, allowing admins to get a richer picture of the health of their device fleet. &lt;A class="lia-external-url" href="https://developer.apple.com/documentation/devicemanagement/statusdevicesystemhealthdevicesystemhealthobject" target="_blank"&gt;Device health reports &lt;/A&gt;that highlight whether a specific hardware component is operating normally, or experiencing an issue, will provide useful insights to organizations when planning their next device refresh cycle or monitoring for device issues before they affect productivity. Apple also added new status reports that show MDM-specific information for devices, such as if they’re enabled for return to service or shared iPad, and APNS-related information for MDMs to better stay in sync with devices.&lt;/P&gt;
&lt;H3&gt;macOS package uninstall and the Managed App framework&lt;/H3&gt;
&lt;P&gt;Over the past few years, Apple has been adding new features that are shifting traditional agent-based management to the DDM stack. The declarative package (.pkg) configuration introduced last year lets MDM send complex macOS packages and configurations without the constraints of the legacy install command. This year, they rounded out the story by adding package uninstall to remove data and files that were installed by a declarative package configuration as well as extending the &lt;A class="lia-external-url" href="https://developer.apple.com/documentation/ManagedApp" target="_blank"&gt;Managed App framework&lt;/A&gt; to macOS. Just like with the new network configurations, our team is investigating what this means for Intune Mac management and re-evaluating our macOS roadmap.&lt;/P&gt;
&lt;H3&gt;Streamlined log collection with AppleCare&lt;/H3&gt;
&lt;P&gt;Apple introduced a new command to remotely trigger enhanced log collection which seems simple, but it has a lot packed into it. The old way involved lots of downloading and waiting and uploading and more waiting. With this latest announcement, Apple has streamlined this whole process by allowing MDMs to send a command to enable the device for logging with the correct logging state configured. The cherry on top is this new process will tell the device to directly upload its sysdiagnose to AppleCare without requiring physical access to the device or manual interaction from the device owner. It also wouldn’t be a new feature without DDM status, and devices will report their enhanced logging status every step of the way. This will reduce a lot of the friction, idle time, and “what’s actually happening?” that’s associated with getting a sysdiagnose file needed for engineering investigations. This new feature benefits IT teams, AppleCare, MDMs, and everyone in between, and our team is prioritizing this new workflow for the fall.&lt;/P&gt;
&lt;H3&gt;Return to service (RTS) gets better and better&lt;/H3&gt;
&lt;P&gt;Apple has continued to iterate on the &lt;A class="lia-external-url" href="https://support.apple.com/guide/deployment/use-return-to-service-for-apple-devices-dep17cb455a0/web" target="_blank"&gt;return to service workflow&lt;/A&gt; since its introduction in 2023. Its first iterations showed how RTS can be useful for troubleshooting, quickly returning devices back to a fresh service state while also preserving apps across resets. This year, Apple announced 2 major improvements: the ability to trigger RTS directly from the device and the ability to configure an inactivity timeout. This makes RTS a must-have for shared device scenarios where you need to securely and quickly minimize downtime between user sessions.&lt;/P&gt;
&lt;H3&gt;MDM software updates are no more&lt;/H3&gt;
&lt;P&gt;DDM is now the only way to manage software updates, with the legacy MDM workload being fully removed from support in OS 27. We will be removing the legacy software update policies and settings from our UI in the coming months. Intune has supported DDM updates since they were first released in 2023, and we also have &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-updates/apple/monitor-reports?tabs=summary" target="_blank"&gt;gold standard software update reports&lt;/A&gt; where you can see rich and fast OS update status every step of the way. More information is available on our &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/support-tip-move-to-declarative-device-management-for-apple-software-updates/4432177" data-lia-auto-title="Tech Community blog." data-lia-auto-title-active="0" target="_blank"&gt;Tech Community blog.&lt;/A&gt;&lt;/P&gt;
&lt;H2&gt;How IT teams can prepare now&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Identify the Apple device populations that are most business-critical, including supervised iOS and iPadOS devices, shared devices, and managed Macs.&lt;/LI&gt;
&lt;LI&gt;Review enrollment, compliance, app deployment, and software update workflows that may be affected by major OS upgrades.&lt;/LI&gt;
&lt;LI&gt;Plan a beta validation ring with representative users, devices, apps, and different network conditions.&lt;/LI&gt;
&lt;LI&gt;Document known business-critical apps and confirm vendor readiness timelines for the fall OS releases.&lt;/LI&gt;
&lt;LI&gt;Test the available beta settings in the settings catalog and share your feedback with our team and Apple via Feedback Assistant.&lt;/LI&gt;
&lt;LI&gt;Watch for Intune documentation, Message center posts, and release notes as support details become available.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Looking ahead&lt;/H2&gt;
&lt;P&gt;Apple’s fall OS releases are an important planning milestone for every organization managing Apple devices, and Intune’s priority is to help our customers confidently adopt new capabilities securely and at scale. Keep an eye out for our yearly day zero blog to learn more about Intune updates and new feature support as we get closer to the OS 27 release this fall – happy beta testing!&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment below or reach out to us on X&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Join our community!&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2026 18:33:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-and-apple-platform-updates-what-to-expect-after/ba-p/4531058</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-25T18:33:03Z</dc:date>
    </item>
    <item>
      <title>How to Configure macOS Privacy Preferences Policy Control (PPPC) Using the Intune Settings Catalog</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/how-to-configure-macos-privacy-preferences-policy-control-pppc/ba-p/4530406</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Chris Kunze - Principal Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.apple.com/guide/deployment/privacy-preferences-policy-control-payload-dep38df53c2a/web" target="_blank" rel="noopener"&gt;Privacy Preferences Policy Control (PPPC)&lt;/A&gt; settings on macOS are used to pre-approve privacy permissions for apps so users aren't repeatedly prompted by macOS for access requests. Common examples include Full Disk Access, Screen Recording, Camera, Microphone, Accessibility, Files and Folders, and Apple Events permissions.&lt;/P&gt;
&lt;P&gt;Organizations commonly deploy PPPC profiles to improve the user experience, reduce support calls, and ensure management and security tools have the permissions they require to function correctly. This is especially important for tools such as Microsoft Defender, remote support applications, compliance agents, and inventory tools. PPPC profiles also help standardize privacy settings across managed Macs and support zero-touch onboarding scenarios where users can begin working without manually approving a series of permission prompts.&lt;/P&gt;
&lt;P&gt;Intune’s settings catalog provides a straightforward way to deploy PPPC settings, but because macOS uses strict matching criteria, a few configuration details are important to get right. If these settings aren’t configured correctly, apps can either break - or worse, fail quietly. This article walks through the key configuration details that help ensure those settings are applied correctly.&lt;/P&gt;
&lt;H2&gt;How macOS evaluates PPPC entries&lt;/H2&gt;
&lt;P&gt;macOS evaluates PPPC entries using a combination of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;App identifier (Bundle ID or Path)&lt;/LI&gt;
&lt;LI&gt;Code requirement (from the app’s signature)&lt;/LI&gt;
&lt;LI&gt;The specific permission being granted or denied.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://developer.apple.com/documentation/devicemanagement/privacypreferencespolicycontrol/services-data.dictionary/identity" target="_blank" rel="noopener"&gt;Apple&lt;/A&gt; requires each PPPC payload to use either Authorization or Allowed, but not both. If any of these values don’t align correctly, the policy won’t apply.&lt;/P&gt;
&lt;H2&gt;Configure PPPC in Intune settings catalog&lt;/H2&gt;
&lt;OL&gt;
&lt;LI&gt;Create a settings catalog profile.&lt;BR /&gt;In the&amp;nbsp;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://intune.microsoft.com" target="_blank" rel="noopener"&gt;Intune admin center&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;, create a macOS configuration profile using &lt;/SPAN&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/mem/intune/configuration/settings-catalog" target="_blank" rel="noopener"&gt;Settings Catalog&lt;/A&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;. Search for: &lt;/SPAN&gt;&lt;A class="lia-external-url" style="font-style: normal; font-weight: 400; background-color: rgb(255, 255, 255);" href="https://learn.microsoft.com/mem/intune/configuration/privacy-preferences-policy-control-macos" target="_blank" rel="noopener"&gt;Privacy Preferences Policy Control&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;img&gt;&lt;EM&gt;Figure 1 - Settings picker showing Privacy Preferences Policy Control.&lt;/EM&gt;&lt;/img&gt;This is where you'll configure the PPPC permissions required by your application.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Use the Authorization field &lt;BR /&gt;When configuring, select the &lt;STRONG&gt;Authorization&lt;/STRONG&gt; setting instead of the legacy &lt;STRONG&gt;Allowed&lt;/STRONG&gt; setting whenever supported, but never both.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;Get the correct code requirement&lt;BR /&gt;
&lt;P&gt;On a Mac where the application is installed, open &lt;STRONG&gt;Terminal&lt;/STRONG&gt; and run:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;codesign -dr - /Applications/YourApp.app&lt;/LI-CODE&gt;
&lt;P&gt;Replace /Applications/YourApp.app with the path to the application you're configuring.&lt;BR /&gt;&lt;BR /&gt;The output will contain a string similar to:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;designated =&amp;gt; identifier "com.example.app" and ...&lt;/LI-CODE&gt;
&lt;P&gt;Copy everything that appears after “designated =&amp;gt;” exactly as displayed. You'll use this value when configuring the PPPC entry in Intune.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;: Some applications return a multi-line code requirement. If that happens, paste the value into Intune as a single continuous string without line breaks. The content for the Identifier field can also be extracted from this command.&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 2 - Screenshot of a terminal window showing Chrome/ChromeDriver startup errors, including “DevToolsActivePort file doesn’t exist” and certificate-related error messages.&lt;/EM&gt;&lt;/img&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;Configure the PPPC entry&lt;BR /&gt;
&lt;P&gt;After gathering the required information, configure the application entry.&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Field&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Value&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Identifier type&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Bundle ID or Path&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Identifier&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Application Bundle ID&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Code requirement&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Full output from the &lt;CODE&gt;codesign&lt;/CODE&gt; command in Step 3.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Authorization&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Allow&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 35.00%" /&gt;&lt;col style="width: 65.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;BR /&gt;&lt;img&gt;&lt;EM&gt;Figure 3 - Screenshot of the Microsoft Intune admin center editing a OneDrive configuration profile. The main pane shows privacy and synchronization settings, while a right-side “Configure instance” panel displays Privacy Preferences Policy Control options, including an enabled setting for “Use System SSL.”&lt;/EM&gt;&lt;/img&gt;
&lt;DIV style="margin: 16px 0; padding: 14px 16px; border-left: 4px solid #0078d4; background: #f3f9fd; border-radius: 4px; color: #242424;"&gt;&lt;STRONG style="color: #005a9e;"&gt;Tip:&lt;/STRONG&gt; &lt;SPAN class="tooltip"&gt; Use Bundle ID for apps whenever possible. &lt;SPAN class="tooltip-text" role="tooltip"&gt; Bundle IDs are more reliable than file paths because they typically remain consistent when an app is updated or moved. &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H2&gt;Why PPPC settings may not apply&lt;/H2&gt;
&lt;P&gt;If these settings fail, they fail silently. Intune may report the policy as successfully applied, but macOS evaluates PPPC entries when the app requests access to the protected resource. Upon app launch, macOS skips any entry where the code requirement doesn’t match the app’s current binary signature without any indication that the setting is skipped. The three most common causes are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Incorrect code requirement&lt;BR /&gt;The code requirement must match the application's current signing information exactly. Even a small mismatch can prevent the PPPC setting from being applied.&lt;/LI&gt;
&lt;LI&gt;Mixing Authorization and Allowed&lt;BR /&gt;Apple’s documentation states PPPC entries should use either Authorization or Allowed, not both.&lt;/LI&gt;
&lt;LI&gt;Wrong identifier type&lt;BR /&gt;If the PPPC entry is configured with the wrong identifier type, macOS won't match the application correctly.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Try it in your environment&lt;/H2&gt;
&lt;P&gt;If you’ve been avoiding the settings catalog for PPPC, try this approach. Pull the identifier and code requirement directly from the app using codesign, use Authorization when available, and validate the configuration with a pilot group before broader deployment. &lt;BR /&gt;&lt;BR /&gt;Most PPPC issues come down to matching. Once you understand how macOS evaluates these settings it becomes much more predictable. &lt;BR /&gt;&lt;BR /&gt;If you have any questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 18:14:31 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/how-to-configure-macos-privacy-preferences-policy-control-pppc/ba-p/4530406</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-24T18:14:31Z</dc:date>
    </item>
    <item>
      <title>Exporting all Microsoft Intune Enterprise App Management catalog apps to CSV using Microsoft Graph</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/exporting-all-microsoft-intune-enterprise-app-management-catalog/ba-p/4529579</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Joe Lurie, Sr. Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Managing applications at scale is one of the biggest time-consuming tasks for IT admins. Between packaging installers, writing detection rules, and keeping everything up to date - it adds up fast. That's exactly the problem &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise App Management&lt;/A&gt; in Microsoft Intune is designed to address.&lt;/P&gt;
&lt;P&gt;Enterprise App Management gives you access to a curated &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/add-enterprise-catalog-app" target="_blank" rel="noopener"&gt;Enterprise App Catalog&lt;/A&gt; with hundreds of popular Win32 apps that are pre-packaged, pre-tested, and ready to deploy. Microsoft handles the install commands, detection logic, and update-ready packaging. Automatic updates for catalog apps are expected to roll out in mid-2026, making the experience even more hands-off. You just pick the app, assign it, and move on.&lt;/P&gt;
&lt;P&gt;But what if you want a full inventory of what's available in the catalog? Maybe you're evaluating which apps your organization can migrate from manual packaging, or you want to share the list with your app owners for review. In this post, I'll show you how to pull the complete catalog using Microsoft Graph PowerShell and export it to a CSV file.&lt;/P&gt;
&lt;H1&gt;Prerequisites&lt;/H1&gt;
&lt;P&gt;Before you start, make sure you have:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Intune admin permissions&lt;/STRONG&gt;: An account with Intune permissions to read app and catalog data (such as Intune Administrator or a custom role with app read access).
&lt;UL&gt;
&lt;LI&gt;You will also need &lt;STRONG&gt;Microsoft Graph delegated scope&lt;/STRONG&gt;: &lt;EM&gt;DeviceManagementApps.Read.All&lt;/EM&gt; (you'll consent to this when connecting).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;An &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/add-ons" target="_blank" rel="noopener"&gt;Intune Suite&lt;/A&gt;&lt;STRONG&gt; or Enterprise App Management add-on license:&lt;/STRONG&gt; Enterprise App Management is part of the Intune Suite or available as a standalone add-on. &lt;EM&gt;Note: Microsoft has &lt;/EM&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank" rel="noopener" data-lia-auto-title="announced" data-lia-auto-title-active="0"&gt;announced&lt;/A&gt;&lt;EM&gt; that Enterprise App Management will also be included in Microsoft 365 E5 licensing starting July 1, 2026 - check current licensing guidance to confirm availability for your tenant.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Microsoft &lt;/STRONG&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/powershell/microsoftgraph/installation" target="_blank" rel="noopener"&gt;Graph PowerShell SDK&lt;/A&gt;&lt;STRONG&gt; (Beta module)&lt;/STRONG&gt; &lt;STRONG&gt;installed&lt;/STRONG&gt;: Note that the catalog API is currently in the beta endpoint which means cmdlet names and properties may change before reaching v1.0.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you don't have the beta module installed yet, run:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Install-Module Microsoft.Graph.Beta.Devices.CorporateManagement -Scope CurrentUser -Force&lt;/LI-CODE&gt;
&lt;H3&gt;&lt;STRONG&gt;Step 1: Connect to Microsoft Graph&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;First, authenticate to Microsoft Graph with the required scope:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Connect-MgGraph -Scopes "DeviceManagementApps.Read.All"&lt;/LI-CODE&gt;
&lt;P&gt;You'll get a browser prompt to sign in and consent. Once connected, you're ready to query the catalog.&lt;/P&gt;
&lt;H3&gt;&lt;STRONG&gt;Step 2: Retrieve all Catalog apps&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Microsoft Graph exposes the Enterprise App Catalog through the /beta/deviceAppManagement/mobileAppCatalogPackages collection. The PowerShell cmdlet for it is:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$catalogApps = Get-MgBetaDeviceAppManagementMobileAppCatalogPackage -All&lt;/LI-CODE&gt;
&lt;P&gt;The -All parameter is important as it handles pagination automatically so you get every catalog package, not just the first page of results.&lt;/P&gt;
&lt;DIV style="margin: 24px 0; padding: 18px 20px; border-left: 5px solid #0078D4; background-color: #f3f9fd; border-radius: 6px; color: #1f1f1f;"&gt;
&lt;DIV style="display: flex; align-items: center; gap: 8px; margin-bottom: 10px;"&gt;&lt;SPAN style="font-size: 20px; line-height: 1;"&gt;💡&lt;/SPAN&gt; &lt;STRONG style="font-size: 16px; color: #005a9e;"&gt;Tip&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;P style="margin: 0 0 12px; line-height: 1.5;"&gt;To see every property available on a catalog package object, pipe the first result to &lt;CODE style="padding: 2px 5px; background-color: #e7f3fa; border-radius: 3px; font-family: Consolas, Monaco, monospace;"&gt;Format-List&lt;/CODE&gt;.&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$catalogApps | Select-Object -First 1 | Format-List *&lt;/LI-CODE&gt;&lt;/DIV&gt;
&lt;H3&gt;&lt;STRONG&gt;Step 3: Export to CSV&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Next, let's select the most useful fields and write them to a CSV file:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;$csvPath = "C:\Temp\IntuneCatalogApps.csv"
New-Item -ItemType Directory -Path (Split-Path $csvPath) -Force | Out-Null&lt;/LI-CODE&gt;&lt;LI-CODE lang="powershell"&gt;$catalogApps | Select-Object ProductDisplayName, VersionDisplayName, PublisherDisplayName | Export-Csv -Path $csvPath -NoTypeInformation&lt;/LI-CODE&gt;
&lt;P&gt;Open the CSV in Excel and you've got a clean, sortable list of every catalog package in the Intune Enterprise App Catalog.&lt;/P&gt;
&lt;H1&gt;Putting it all together&lt;/H1&gt;
&lt;P&gt;Here's the complete script you can save and run:&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;# Connect to Microsoft Graph
Connect-MgGraph -Scopes "DeviceManagementApps.Read.All"

# Pull all Enterprise App Catalog packages
$catalogApps = Get-MgBetaDeviceAppManagementMobileAppCatalogPackage -All

# Export to CSV
$csvPath = "C:\Temp\IntuneCatalogApps.csv"
New-Item -ItemType Directory -Path (Split-Path $csvPath) -Force | Out-Null

$catalogApps | Select-Object ProductDisplayName, VersionDisplayName, PublisherDisplayName | Export-Csv -Path $csvPath -NoTypeInformation

Write-Host "Exported $($catalogApps.Count) catalog apps to $csvPath" -ForegroundColor Green

# Disconnect when done
Disconnect-MgGraph&lt;/LI-CODE&gt;
&lt;H1&gt;Sample output&lt;/H1&gt;
&lt;P&gt;Your CSV will look something like this:&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Product&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Version&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Publisher&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Mozilla Firefox&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;137.0.1&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Mozilla Corporation&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Google Chrome&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;135.0.6998.89&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Google LLC&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Zoom Workplace&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;6.4.6&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Zoom Video Communications, Inc.&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Adobe Acrobat Reader DC&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;25.001.20467&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Adobe Inc.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;7-Zip&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;24.09&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Igor Pavlov&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 40.00%" /&gt;&lt;col style="width: 22.00%" /&gt;&lt;col style="width: 38.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H1&gt;Why this matters&lt;/H1&gt;
&lt;P&gt;Having a complete list of what's in the catalog is useful for a few scenarios:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;App rationalization&lt;/STRONG&gt; - Share the list with app owners and identify which apps you can stop manually packaging and switch to the catalog instead.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Gap analysis&lt;/STRONG&gt; - Compare the catalog against your current app portfolio to see what's missing.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Change management&lt;/STRONG&gt; - Track what's available over time as Microsoft continues to add new apps.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Compliance and auditing&lt;/STRONG&gt; - Document which catalog apps are available for your tenant.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Wrapping up&lt;/H2&gt;
&lt;P&gt;Enterprise App Management is one of the most impactful features in the Intune Suite. It takes the most tedious parts of endpoint management - app packaging and updates - and just handles it for you. And with a short Graph script, you can get full visibility into what's available. And to see how Enterprise App Management secures your app catalog, check out the companion post here:&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/Intune/EAM-Security" target="_blank" rel="noopener"&gt;aka.ms/Intune/EAM-Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Give the script a try and let us know what you think along with other Enterprise App Management topics you’d like to see by leaving a comment below or reaching out on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Want to learn more about Enterprise App Management? Check out the &lt;/EM&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;official documentation&lt;/A&gt;&lt;EM&gt; for the full details.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c"&gt;https://aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2026 17:59:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/exporting-all-microsoft-intune-enterprise-app-management-catalog/ba-p/4529579</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-22T17:59:40Z</dc:date>
    </item>
    <item>
      <title>Deploying Platform SSO for pre macOS 26 with Microsoft Intune: Lessons Learned</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/deploying-platform-sso-for-pre-macos-26-with-microsoft-intune/ba-p/4521368</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Naveen Akkugari, Sr. Service Engineer and Michael Griswold, Principal Service Engineering Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Who we are&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Our internal Intune administration team at Microsoft is responsible for running Intune and Configuration Manager for the devices used by employees. We &lt;STRONG&gt;receive&lt;/STRONG&gt; early access to features for evaluation and feedback using real world usage scenarios. As such, some features may be changed before the public release and be slightly different. The experience should be similar and&lt;STRONG&gt; &lt;/STRONG&gt;we wanted to share our learnings when deploying platform single sign-on (PSSO). It is worth noting that since the time of this experience a new method for newer OS versions is available and you can read more about it at:&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-platform-sso-with-registration-during-automated-device-enrollment-on-macos/4519846" target="_blank" rel="noopener" data-lia-auto-title="New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub" data-lia-auto-title-active="0"&gt;New Platform SSO with registration during Automated Device Enrollment on macOS | Microsoft Community Hub&lt;/A&gt;.&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Why we implemented Platform single sign-on (PSSO) and what we learned&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;As IT admins managing a growing Mac fleet, we kept running into the same gap. Our Windows devices had hardware-backed authentication, token protection, and seamless SSO through Windows Hello for Business, but our Macs were still relying on browser-based prompts with no easy way to enforce the same level of security and identity protection. Platform SSO finally closed that gap for us. It’s worth noting that new macOS allows new capabilities in this space and we are evaluating them as well. The new flow can be read about at &lt;A class="lia-external-url" href="https://aka.ms/Intune/MacPSSO-Setup" target="_blank" rel="noopener"&gt;https://aka.ms/Intune/MacPSSO-Setup&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;While there were fewer pip-ups, we found the changes in the security layer to be the real value to our operations. Platform SSO binds authentication tokens (Primary Refresh Tokens) to the device’s Secure Enclave hardware. Even if a PRT is intercepted, it’s &lt;STRONG&gt;designed to not be replayed from another device&lt;/STRONG&gt;. For our team, this unlocked two things we couldn’t do on macOS before:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Token protection policies:&lt;/STRONG&gt; Conditional Access can now verify that tokens are device-bound, the same enforcement we had been relying on with Windows Hello for Business&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Phishing-resistant MFA:&lt;/STRONG&gt; Secure Enclave keys act as FIDO2 passkeys, so users authenticate with Touch ID instead of passwords or SMS codes&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Getting from documentation to production took real effort for us. A password policy issue that silently blocked registration for half our pilot group, users who swiped away the registration banner without knowing what it was, and macOS updates that broke SSO overnight. This blog post is what we wish someone had written before we started.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it works under the hood: &lt;/STRONG&gt;Intune delivers the SSO extension profile → macOS prompts the user to register → the device registers with Microsoft Entra ID and gets a hardware-bound workplace (WPJ) certificate → a PRT is issued and bound to device hardware (not designed to be exported) → SSO works across Microsoft 365 apps, browsers, and Kerberos resources, all with token protection enforced.&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Available authentication methods when we implemented&lt;/STRONG&gt;&lt;/H1&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Capability&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Secure Enclave&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Smart Card&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Password Sync&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Passwordless and phishing-resistant&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Touch ID / passkey (WebAuthn)&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌ &lt;SPAN style="color: #666;"&gt;Touch ID only&lt;/SPAN&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Local password synced with Microsoft Entra&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;❌&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;✅&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Minimum macOS&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;13.0&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;14.0&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;13.0&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;col style="width: 25.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Recommendation: Start with Secure Enclave. &lt;/STRONG&gt;Keys are hardware-bound, phishing-resistant, and double as FIDO2 passkeys via WebAuthn, enabling browser-based passwordless login (Touch ID instead of passwords) and meeting Conditional Access multi-factor authentication (MFA) requirements. Unlike iCloud-synced passkeys, these are &lt;STRONG&gt;device-bound&lt;/STRONG&gt;, aligning with Zero Trust.&lt;/P&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;Quick setup using the Intune settings catalog&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;&lt;STRONG&gt;Prerequisites: &lt;/STRONG&gt;macOS 13+, Intune with Microsoft Entra ID, Intune Company Portal v5.2404.0+&lt;/P&gt;
&lt;P&gt;In the Intune admin center, navigate to &lt;STRONG&gt;Devices &amp;gt; Configuration &amp;gt; Create &amp;gt; macOS &amp;gt; Settings Catalog &amp;gt; Authentication &amp;gt; Extensible SSO&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Setting&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Value&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Extension Identifier&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;com.microsoft.CompanyPortalMac.ssoextension&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Team Identifier&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;UBF8T346G9&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Type&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Redirect&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Registration Token&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;{{DEVICEREGISTRATION}}&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Use Shared Device Keys&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Enabled&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Screen Locked Behavior&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;DoNotHandle&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;URLs&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;https://login.microsoftonline.com&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://login.microsoft.com&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://sts.windows.net&lt;/CODE&gt;&lt;BR /&gt;&lt;CODE&gt;https://login-us.microsoftonline.com&lt;/CODE&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 50.00%" /&gt;&lt;col style="width: 50.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;
&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Users see a “Registration required” notification → sign in → complete MFA → SSO works everywhere.&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;What the user experience looks like&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Knowing what users see on their screen helps you write better rollout communications and cuts down help desk tickets.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;First-time registration flow:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Profile arrives silently: &lt;/STRONG&gt;After enrollment, Intune pushes the SSO extension profile to the Mac. Nothing visible to the user yet.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Registration banner appears: &lt;/STRONG&gt;macOS displays a notification: “Registration required: Your organization requires you to register your device.” The user must click this to proceed. (This is our #1 learning point, users swipe it away, and there’s no simple way to retrigger it.)&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Sign-in window: &lt;/STRONG&gt;The user enters their Microsoft Entra ID email and password.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; MFA challenge: &lt;/STRONG&gt;Authenticator app push, phone call, or other configured method.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Secure Enclave key creation: &lt;/STRONG&gt;macOS generates a hardware-bound key pair. The user may see a Touch ID or local password prompt to authorize this.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Registration completes: &lt;/STRONG&gt;Device registers with Microsoft Entra ID, a WPJ certificate and PRT are issued. User sees a success confirmation.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; SSO is active: &lt;/STRONG&gt;From here, Microsoft 365 apps, Edge (natively), Chrome (with SSO extension), and Kerberos resources authenticate without prompts. Touch ID replaces password entry.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;Missed the registration notification? Here is how to manually register:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This was our most common help desk ticket during rollout. If a user dismissed or missed the banner, they can still register manually through the following options:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; (Recommended) System Settings → Users &amp;amp; Groups → Network Account Server: &lt;/STRONG&gt;This is the easiest method. Go to System Settings → Users &amp;amp; Groups, scroll down to “Network Account Server” and click “Edit.” This opens a panel showing two sections: Network Servers and Platform single sign-on. If the Platform SSO policy is deployed, “Mac SSO Extension” will be listed under Platform single sign-on. If the device isn’t registered, there will be a “Register” button that can be selected to start the Platform SSO device registration flow.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Lock / Sign out and back in:&lt;/STRONG&gt; Performing a lock or signing out of macOS followed by signing back in can retrigger the registration notification upon the next login attempt.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Wait for the notification to reappear: &lt;/STRONG&gt;macOS retries the notification periodically around every 15 mins.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Last resort, reprofile: &lt;/STRONG&gt;If none of the above work, an IT admin can remove and reassign the SSO extension profile in Intune. Before doing so, ensure any stale device objects are cleared from Microsoft Entra ID to avoid conflicts. Once the new profile lands on the device, the registration notification reappears.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;How to verify Platform SSO registration&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;One of the first questions we got after rollout was “how do I know it’s actually working?” Here’s how both users and IT admins can confirm.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For IT admins (Microsoft Entra ID &amp;amp; Intune admin centers):&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;What to check&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Platform SSO registered device&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Non-registered device&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Microsoft Entra ID → Devices&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Join Type shows &lt;STRONG&gt;Microsoft Entra joined&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Join Type shows &lt;STRONG&gt;Microsoft Entra registered&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune → Device configuration&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;SSO extension profile shows &lt;STRONG&gt;Succeeded&lt;/STRONG&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Profile may show &lt;STRONG&gt;Pending&lt;/STRONG&gt;, &lt;STRONG&gt;Error&lt;/STRONG&gt;, or not assigned&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;For users (on the Mac):&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; System Settings → Users &amp;amp; Groups → Network Account Server: &lt;/STRONG&gt;Scroll down in Users &amp;amp; Groups to “Network Account Server” and click “Edit.” If the Platform SSO policy is deployed, they will see “Mac SSO Extension” listed under Platform Single Sign-on. A registered device shows a green dot with “Registered” status and a “Repair” button (useful if registration gets into a bad state). If not registered, they will see a “Register” button instead. This is the quickest at-a-glance check for users.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; System Settings → Users &amp;amp; Groups:&lt;/STRONG&gt; Click on the user account name in Users &amp;amp; Groups (on macOS 14+, click the info button “i” next to the user name). When Platform SSO registration is complete, a “Platform Single Sign-on” section will be listed under the account. If Platform SSO is active, the user account shows the Microsoft Entra ID identity linked to the local account.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Company Portal app → Devices: &lt;/STRONG&gt;The device should show as “Compliant” and “Microsoft Entra ID registered.” If registration failed, it shows “Registration required.”&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Terminal command: &lt;/STRONG&gt;Run app-sso platform -s to check Platform SSO status.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;Troubleshooting Platform SSO errors&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;If you run into issues during deployment, here’s how you can diagnose and fix issues.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 1: Check the Platform SSO profile in Intune device management&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Before troubleshooting on the Mac itself, confirm the profile reached the device:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;In Intune: &lt;/STRONG&gt;Go to Devices → select the device → Device configuration. The SSO extension profile should show “Succeeded.” If it shows “Pending” or “Error,” the device hasn’t received the policy. Check assignment groups, sync status, and whether the device is enrolled.&lt;/P&gt;
&lt;P&gt;Then&amp;nbsp;&lt;STRONG&gt;on the Mac: &lt;/STRONG&gt;Go to System Settings → General → Device Management (or Profiles on older macOS). Look for the SSO extension profile (com.apple.extensiblesso). It should show as “Installed” with no errors. If the profile isn’t listed, it hasn’t been delivered yet. Check Intune assignment and device sync.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 2: Check registration status on the Mac &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Refer to the &lt;STRONG&gt;previous section&lt;/STRONG&gt; &lt;STRONG&gt;“&lt;/STRONG&gt;How to &lt;STRONG&gt;verify &lt;/STRONG&gt;P&lt;STRONG&gt;latform &lt;/STRONG&gt;SSO &lt;STRONG&gt;registration” for steps.&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 3: Check SSO extension logs&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Run in Terminal for real-time logs:&lt;/P&gt;
&lt;LI-CODE lang="bash"&gt;log stream --predicate 'subsystem == "com.apple.AppSSO"' --level debug&lt;/LI-CODE&gt;
&lt;P&gt;Then prompt a sign-in (open Edge or Outlook). Look for:&lt;BR /&gt;&lt;STRONG&gt;Error 10002:&lt;/STRONG&gt; Duplicate SSO profiles. Remove the extra one from Intune.&lt;BR /&gt;&lt;STRONG&gt;Error 10003:&lt;/STRONG&gt; Registration failed. Usually a network issue or TLS inspection blocking auth URLs.&lt;BR /&gt;&lt;STRONG&gt;User cancelled:&lt;/STRONG&gt; User dismissed the registration banner.&lt;BR /&gt;&lt;STRONG&gt;Token refresh failed:&lt;/STRONG&gt; PRT could not refresh. Check network and whether the Microsoft Entra ID password was recently changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Step 4: Verify from the admin side&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Check&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;How&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;What It Tells You&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Profile delivery&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune &amp;gt; Devices &amp;gt; select device &amp;gt; Device configuration&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether the SSO profile reached the device and its install status&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Registration state&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Devices &amp;gt; search device &amp;gt; Properties&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether the device has PSSO registration and NGC credential&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Sign-in failures&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Sign-in logs &amp;gt; filter by user&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Error codes like &lt;CODE&gt;AADSTS50076&lt;/CODE&gt; MFA required, &lt;CODE&gt;AADSTS700024&lt;/CODE&gt; token issue, or &lt;CODE&gt;AADSTS7000218&lt;/CODE&gt; client assertion&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Token protection&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Entra ID &amp;gt; Sign-in logs &amp;gt; Conditional Access tab&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Whether token protection policy was applied or skipped&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Company Portal version&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Intune &amp;gt; Apps &amp;gt; macOS &amp;gt; Company Portal&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="border-width: 1px; padding: 12px;"&gt;Must be &lt;STRONG&gt;v5.2404.0+&lt;/STRONG&gt; for PSSO; older versions silently fail&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Common error codes and fixes:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 285px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7" style="height: 47.5px;"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Error&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Cause&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Fix&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;10002&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Multiple SSO extension profiles assigned&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Remove duplicate profiles; keep only the Settings Catalog policy&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;10003&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Registration failed network/TLS&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Allowlist Apple and Microsoft auth URLs from TLS inspection&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS50076&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;MFA required but not completed&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;User needs to complete MFA during registration&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS700024&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Client assertion invalid&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Password likely needs reset; have user reset Entra ID password and retry&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 47.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;&lt;CODE&gt;AADSTS7000218&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Request body must contain &lt;CODE&gt;client_assertion&lt;/CODE&gt;&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Company Portal version too old; update to &lt;STRONG&gt;v5.2404.0+&lt;/STRONG&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;&lt;STRONG&gt;Best practices&lt;/STRONG&gt;&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Have newer OS devices and use the new flow: &lt;/STRONG&gt;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-platform-sso-with-registration-during-automated-device-enrollment-on-macos/4519846" target="_blank" rel="noopener" data-lia-auto-title="New Platform SSO with registration during Automated Device Enrollment on macOS" data-lia-auto-title-active="0"&gt;New Platform SSO with registration during Automated Device Enrollment on macOS&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Have users reset their password before Platform SSO registration. &lt;/STRONG&gt;During initial enrollment, if password configuration or compliance policies are applied, users are required to reset their password after device enrollment and prior to initiating Platform SSO registration. Skipping this step can result in silent registration failures that are difficult to diagnose. Ensure this is communicated as the first step in your rollout guidance.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Assign the SSO profile during enrollment, not after. &lt;/STRONG&gt;Deploying during enrollment means the registration prompt shows up at first login, a natural part of setup. Retrofitting existing devices forces users to notice and click a notification banner. Many will not. macOS Tahoe (26) Simplified Setup will auto-register, removing this friction.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; One SSO profile per device, no exceptions. &lt;/STRONG&gt;Duplicate profiles cause Error 10002. If you are migrating from a Device Features template to Settings Catalog, remove the old one first.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Pilot with realistic scenarios. &lt;/STRONG&gt;Don’t just test “can I open Outlook.” Test registration, SSO to Microsoft 365, on-prem file shares, password change mid-session, reboot behavior, and what happens when a user dismisses the registration banner. We found issues in every one of these.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Align password policies end-to-end. &lt;/STRONG&gt;For Password Sync, Intune compliance and Microsoft Entra ID password policies must match: length, complexity, expiration.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Integrate legacy Kerberos properly. &lt;/STRONG&gt;If you run a standalone Kerberos SSO extension, set usePlatformSSOTGT = true in its ExtensionData to reuse Platform SSO TGT instead of running duplicate flows. Requires macOS 14.6+ and Company Portal 5.2408.0+.&lt;BR /&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/entra/identity/devices/device-join-macos-platform-single-sign-on-kerberos-configuration" target="_blank" rel="noopener"&gt;Enable Kerberos SSO to on-premises Active Directory and Microsoft Entra ID Kerberos Resources in Platform SSO&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt; Allowlist auth URLs from TLS inspection. &lt;/STRONG&gt;Apple and Microsoft authentication endpoints must be excluded from proxy/TLS inspection. If they are not, registration fails silently with no error.&lt;/LI&gt;
&lt;/OL&gt;
&lt;H1&gt;&lt;STRONG&gt;Challenges we faced&lt;/STRONG&gt;&lt;/H1&gt;
&lt;DIV style="overflow-x: auto; max-width: 100%;"&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="width: 100%; height: 420px; border-width: 1px;"&gt;&lt;thead&gt;&lt;tr class="lia-background-color-custom-f2f4f7" style="height: 47.5px;"&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Challenge&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;What we experienced&lt;/th&gt;&lt;th class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 47.5px; border-width: 1px; padding: 12px;"&gt;Solution&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr style="height: 92.5px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Password must be reset before registration during the new enrollment&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Half our pilot group could not register after the new enrollment as their Entra ID password had not been reset.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 92.5px; border-width: 1px; padding: 12px;"&gt;Require a password reset before rollout; make this step 1 in user communications&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Users dismiss the registration banner&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;The notification is easy to swipe away. Once dismissed, there is no simple way to retrigger it.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Send screenshots and instructions before rollout; macOS Tahoe auto-registers via Simplified Setup&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;SSO breaks after macOS updates&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;After point updates, SSO stopped working until re-registration.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Restart &lt;CODE&gt;swcd&lt;/CODE&gt; process; some cases required full re-registration; check release notes&lt;/td&gt;&lt;/tr&gt;&lt;tr class="lia-background-color-custom-fafafa" style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Password policy mismatch&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Users changed Microsoft Entra password, but local Mac password did not sync, causing lockouts.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Match Intune compliance and Microsoft Entra ID password policies exactly; test end-to-end&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 70px;"&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Browser SSO inconsistency&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Edge worked natively, Chrome needed extension, Safari varied by OS.&lt;/td&gt;&lt;td class="lia-border-color-custom-dddddd lia-border-style-solid" style="height: 70px; border-width: 1px; padding: 12px;"&gt;Deploy Chrome SSO extension via Intune; test Safari on each target OS version&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H1&gt;&lt;STRONG&gt;Conclusion&lt;/STRONG&gt;&lt;/H1&gt;
&lt;P&gt;Platform SSO delivers phishing-resistant passwordless authentication, seamless cross-platform SSO, and Conditional Access compliance with hardware-backed identity. &lt;STRONG&gt;Start&lt;/STRONG&gt; your implementation&lt;STRONG&gt; with Secure Enclave, deploy via Intune Settings Catalog, pilot small, then scale.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;If you have questions on implementing Platform SSO, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="1500cb02-a991-4798-bffb-dc0f1bde5fd5"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 23:33:29 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/deploying-platform-sso-for-pre-macos-26-with-microsoft-intune/ba-p/4521368</guid>
      <dc:creator>MikeGriz</dc:creator>
      <dc:date>2026-06-19T23:33:29Z</dc:date>
    </item>
    <item>
      <title>Triage vulnerabilities with the Vulnerability Remediation Agent, now in public preview</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/triage-vulnerabilities-with-the-vulnerability-remediation-agent/ba-p/4528646</link>
      <description>&lt;P&gt;As automation and AI accelerate the pace of vulnerability discovery, the window between disclosure and exploitation continues to shrink. For IT and security teams, the challenge is no longer just &lt;EM&gt;finding&lt;/EM&gt; vulnerabilities - it's prioritizing the ones that matter and acting on them before they can be exploited. To help organizations close that gap, we're pleased to announce that the&amp;nbsp;&lt;STRONG&gt;Vulnerability Remediation Agent for Security Copilot &lt;/STRONG&gt;in Microsoft Intune is now in public preview and rolling out to all customers.&lt;/P&gt;
&lt;P&gt;Following a successful limited preview, the agent is now broadly available. This release brings agentic vulnerability remediation out of an early-access cohort and into the hands of every eligible organization - an important step in our continued investment in helping admins reduce exposure faster and with greater confidence. View eligibility prerequisites&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#prerequisites" target="_blank" rel="noopener"&gt;here&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How the agent helps you identify and triage vulnerabilities&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;The Vulnerability Remediation Agent uses data from Microsoft Defender Vulnerability Management to identify Common Vulnerabilities and Exposures (CVEs) across your Intune-managed Windows devices and apps, then prioritizes them for remediation. Rather than leaving admins to sift through lengthy &amp;nbsp;CVE lists with little context, the agent surfaces a prioritized set of recommendations directly in the Intune admin center - accessible from both the Agents and Endpoint security pages.&lt;/P&gt;
&lt;P&gt;When the agent runs, it evaluates vulnerability data and ranks threats based on factors such as CVSS scores, exposure impact, and affected device count, so the most critical issues rise to the top. Drilling into any suggestion provides:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The count of associated CVEs&lt;/LI&gt;
&lt;LI&gt;A Copilot-assisted summarized impact analysis&lt;/LI&gt;
&lt;LI&gt;Suggested actions and affected systems&lt;/LI&gt;
&lt;LI&gt;Exposed devices and potential impact&lt;/LI&gt;
&lt;LI&gt;Step-by-step guidance for remediating the threat using Intune&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After acting on a recommendation, admins can mark it as applied, allowing the agent to retain a record for tracking remediation actions over time. The result is a meaningful reduction in the time it takes to investigate, prioritize, and remediate - strengthening overall security posture.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Introducing agentic identity for the Vulnerability Remediation Agent&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;With this release, the agent now operates under Microsoft&lt;STRONG&gt; &lt;/STRONG&gt;Entra agentic identity - a meaningful advancement in how autonomous agents are governed and secured.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What it is.&lt;/STRONG&gt; Agentic identity is a specialized identity in Microsoft Entra ID that allows the agent to operate securely and independently. During setup, the agent provisions a dedicated agentic identity and a corresponding agentic user in your tenant's Microsoft Entra directory. The agent then runs under the permissions delegated to that agentic user rather than under a human user account.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why it matters.&lt;/STRONG&gt; Agentic identity decouples the agent from any one person, ensuring its behavior is strictly bound to the permissions and scope you delegate to it. This delivers clearer accountability, a cleaner audit trail, and enterprise-grade governance for autonomous operations.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;How it helps.&lt;/STRONG&gt; Admins remain firmly in control. After setup, delegate the required read permissions to the agentic user in the &amp;nbsp;Microsoft Intune and Microsoft Defender admin centers, then use the built-in Readiness Check to confirm everything is configured correctly before the agent runs.&lt;/P&gt;
&lt;P&gt;Learn more in &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#agent-identity" target="_blank" rel="noopener"&gt;Agent identity&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Getting started: Connect → Enable → Run → Remediate → Track&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;One of the design goals behind the Vulnerability Remediation Agent is to make agentic security approachable, not complex. Rather than stitching together signals across multiple tools and admin centers, the agent guides admins through a clear, repeatable flow - from connecting your data to tracking measurable improvement over time.&lt;/P&gt;
&lt;div contenteditable="false" class="lia-embeded-content"&gt;&lt;iframe src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-xhy3yXGVGM%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-xhy3yXGVGM&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-xhy3yXGVGM%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" title="YouTube embed" scrolling="no" allowfullscreen="allowfullscreen" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture" class="lia-iframe-embeded" sandbox="allow-scripts allow-same-origin"&gt;&lt;/iframe&gt;&lt;/div&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt; Connect — bring Defender and Intune data together.&lt;/STRONG&gt; The agent draws on Microsoft Defender Vulnerability Management for CVE intelligence and Microsoft Intune for device and configuration context. With the required Microsoft Defender and Microsoft Intune plugins in place, your vulnerability and management signals work as one. &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent#prerequisites" target="_blank" rel="noopener"&gt;Learn more on what is needed to connect the experience.&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Enable — turn on the agent. &lt;/STRONG&gt;From the &lt;STRONG&gt;Agents&lt;/STRONG&gt; node in the Microsoft Intune admin center, set up the agent in a few guided steps. During setup, the agent provisions its Microsoft Entra agentic identity and surfaces the permissions and plugins it needs, so you know exactly what to delegate before the first run.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Run — let automated prioritization do the heavy lifting.&lt;/STRONG&gt; Once permissions are delegated and the Run Readiness Check passes, you can configure the agent to run on demand or schedule it to run automatically in the background on a cadence you define; scheduling is a unique capability that helps teams stay ahead of emerging risks without requiring constant manual intervention. Each run analyzes your environment and produces a prioritized list of recommendations ranked by CVSS score, exposure impact, and affected device count so the most critical risks rise to the top automatically.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Remediate — act with guided, Intune-ready actions.&lt;/STRONG&gt; Each recommendation includes a Copilot-assisted impact summary, &amp;nbsp;exposed devices, and step-by-step guidance for remediating the threat using Intune. Admins move directly from insight to action, without leaving the admin center.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Track — measure improvement over time.&lt;/STRONG&gt; Recommendations can be marked as applied, and the agent retains a record of your remediation actions.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The outcome is a streamlined operating model: connect once, enable with confidence, and let the agent drive a continuous cycle of prioritization, remediation, and view progress. For full prerequisites, licensing, plugin, and role requirements, see &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/copilot/agents/vulnerability-remediation-agent" target="_blank" rel="noopener"&gt;Vulnerability Remediation Agent overview and set up&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;The Vulnerability Remediation Agent represents a meaningful step toward a more proactive, AI-assisted security posture, one where admins spend less time sifting through CVE lists and more time acting on what matters most. We invite you to try the public preview today, connect your Defender and Intune data, and experience how agentic remediation can help your team stay ahead of emerging threats.&lt;/P&gt;
&lt;P&gt;As always, we'd love to hear your feedback as we continue investing in making security in Intune faster, smarter, and more accessible. Share your tips and lessons learned in the comments below or reach out to us on X&amp;nbsp;&lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" target="_blank" rel="noopener" data-outlook-id="1500cb02-a991-4798-bffb-dc0f1bde5fd5"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 23:34:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/triage-vulnerabilities-with-the-vulnerability-remediation-agent/ba-p/4528646</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-19T23:34:41Z</dc:date>
    </item>
    <item>
      <title>How Enterprise App Management secures your App Catalog from ingestion to device</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/how-enterprise-app-management-secures-your-app-catalog-from/ba-p/4528361</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Joe Lurie, Sr. Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;One of the most common questions I get from customers when I talk about Enterprise App Management is some version of: &lt;EM&gt;"Okay, but how do I know these apps are safe?"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;It's a fair question. You're trusting a catalog of pre-packaged Win32 apps to land on thousands of managed devices across your organization. If you're responsible for endpoint security, you should be asking that question. This post explains how Enterprise App Management works behind the scenes, how apps get into the catalog, what happens before they're visible to your tenant, and why the architecture matters for your security posture.&lt;/P&gt;
&lt;H1&gt;The architecture: Not a new system, but an extension of what you already trust&lt;/H1&gt;
&lt;P&gt;An important design decision with Enterprise App Management is that it's not a separate app delivery system. It's an extension of the existing &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/app-management-win32" target="_blank" rel="noopener"&gt;Intune Win32 app architecture&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;From the admin perspective, everything starts in the Intune admin center. But behind the scenes, there's a clean separation between the control plane and the data plane:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Control plane&lt;/STRONG&gt;: For each app being added to the Enterprise App Management catalog, Intune curates app metadata, including app version, install commands, uninstall commands, detection logic, requirements, and supported configurations. This metadata is validated and normalized before it shows up in your tenant. That's why catalog apps behave consistently whether you're deploying to 50 devices or 50,000.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Data plane&lt;/STRONG&gt;: Once an app is assigned by an admin, it flows through the same Win32 app delivery and enforcement pipeline you already rely on. Your devices don't know they're installing an "Enterprise App Management app" - they're enforcing a Win32 app with well-defined intent. Same Enrollment Status Page support, same reporting, same retry logic, same Intune Management Extension. No new agent. No new runtime. And finally, Enterprise App Management apps have the same support for&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/security/application-security/application-control/app-control-for-business/design/configure-authorized-apps-deployed-with-a-managed-installer" target="_blank" rel="noopener"&gt;App Control for Business with Managed Installer&lt;/A&gt; which can automatically tag the apps as safe.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;This is important because it means Enterprise App Management inherits all the trust and operational maturity of Win32 app management in Intune. Curated content is delivered through established, reliable infrastructure.&lt;/P&gt;
&lt;H1&gt;How Enterprise App Management apps are delivered: The ingestion pipeline&lt;/H1&gt;
&lt;P&gt;This section walks through what happens from the moment an app is sourced to the moment it appears in your catalog.&lt;/P&gt;
&lt;H2&gt;Content ingestion&lt;/H2&gt;
&lt;P&gt;It starts with the catalog. Microsoft receives app metadata, including install and uninstall commands, version info, and download URLs. The data is then ingested, flattened, transformed, and Microsoft's own identifiers are applied. After the data lands in the database, eligibility and filtering gates are applied through allow and deny lists. Apps on the allow list are permitted to download content from controlled internet locations. This process handles both net-new apps and version updates to apps already in the catalog.&lt;/P&gt;
&lt;H2&gt;Security and functional validation&lt;/H2&gt;
&lt;P&gt;This is the part that answers the "how do I know it's safe?" question. Once content ingestion is complete, every app is submitted for security and functional validation. This is a queue-driven service that runs two parallel tracks:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Static malware detection&lt;/STRONG&gt; scans the installer and related artifacts for malicious content, assigning a VirusTotal score. If an app receives a non-zero score, it's blocked from proceeding, full stop. Static scanning is about establishing baseline trust before deployment. It validates that binaries are intact, that they originate from trusted sources, and they don't carry known indicators of malware or tampering. This process catches embedded malicious payloads, corrupted binaries, and known bad signatures before they can impact any device.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Dynamic analysis (detonation)&lt;/STRONG&gt; runs in parallel. The app is installed and uninstalled inside a VM detonation chamber, producing install results, logs, and artifacts. This is about validating behavior, not just files. Modern threats don't always look malicious at rest; some issues only surface when an installer or application runs or interacts with the system. Dynamic evaluation catches unexpected system changes, unsafe persistence mechanisms, and activity inconsistent with enterprise deployment expectations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If an app fails automatic validation, it goes through manual validation by Intune engineering.&lt;/P&gt;
&lt;P&gt;Both layers are required. Static scanning provides speed and broad coverage, while dynamic scanning provides depth and behavioral assurance.&lt;/P&gt;
&lt;H2&gt;After publication: Ongoing scanning&lt;/H2&gt;
&lt;P&gt;The security story doesn't end at publication. Apps already in the catalog are periodically re-scanned. If a version that previously passed validation is later found to fail a malware scan, it's flagged and removed from the catalog. This is a critical detail - the catalog isn't a snapshot-in-time trust decision. It's a continuously validated inventory.&lt;/P&gt;
&lt;H2&gt;Update velocity&lt;/H2&gt;
&lt;P&gt;Once a new app version is received, the target is to have it available in the catalog within 24 hours. Around 80–90% of apps hit that timeline. The remainder are apps that don't pass automatic validation and require manual review, which takes longer. But the pipeline processes updates through the exact same ingestion and validation flow as new apps - no shortcuts.&lt;/P&gt;
&lt;H2&gt;Where Zero Trust fits in&lt;/H2&gt;
&lt;P&gt;If you've been following Microsoft's &lt;A class="lia-external-url" href="https://learn.microsoft.com/security/zero-trust/zero-trust-overview" target="_blank" rel="noopener"&gt;Zero Trust model&lt;/A&gt;, this pipeline should feel familiar. Zero Trust is built on three principles: &lt;STRONG&gt;verify explicitly&lt;/STRONG&gt;, &lt;STRONG&gt;use least-privilege access&lt;/STRONG&gt;, and &lt;STRONG&gt;assume breach&lt;/STRONG&gt;. EAM's validation pipeline maps directly to these:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Verify explicitly&lt;/STRONG&gt;: Every app is verified through multiple independent signals, including source integrity, static malware scanning, and dynamic behavioral analysis, before it's ever exposed to a tenant. No app gets a pass based on reputation or publisher name alone. Trust is earned through evidence, every time.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Use least-privilege access&lt;/STRONG&gt;: Enterprise App Management catalog apps ship with prefilled, scoped install and uninstall commands, detection rules, and requirements. You're not handing an installer broad system access and hoping for the best. The deployment surface is defined and constrained by design.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Assume breach&lt;/STRONG&gt;: This is why the pipeline doesn't stop at initial validation. Ongoing re-scanning means that even apps that previously cleared every check are continuously re-evaluated. If an app that was clean six months ago is later found to carry a risk, it's flagged and pulled from the catalog. The system assumes that trust is perishable, exactly the way Zero Trust says it should be.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In practice, this means Enterprise App Management gives you an app lifecycle that's not just convenient - it follows the same security framework your organization is likely already adopting for identity, network, and device access. The app layer is often the last piece to catch up, and Enterprise App Management closes that gap.&lt;/P&gt;
&lt;P&gt;Here's the ingestion flow that shows how all of this fits together:&lt;/P&gt;
&lt;img&gt;&lt;EM&gt;Figure 1: &lt;/EM&gt;&lt;EM&gt;The Enterprise App Management ingestion pipeline: from source metadata through content ingestion, static and dynamic security validation, manual review for failures, periodic re-scanning, and finally publication to the catalog.&lt;/EM&gt;&lt;/img&gt;
&lt;H1&gt;Takeaways&lt;/H1&gt;
&lt;P&gt;If you're evaluating Enterprise App Management or explaining it to your security team, here's what I'd suggest that you land on:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Enterprise App Management reduces the packaging tax.&lt;/STRONG&gt; Pre-packaged apps with prefilled install details, detection rules, requirements, and restart behavior mean you spend less time building the same scaffolding repeatedly and more time on policy and rollout strategy.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Patching becomes more predictable.&lt;/STRONG&gt; Guided update flows using supersedence and a documented expectation of 24-hour update availability give you a cadence you can plan around, not react to.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The security model is layered and continuous.&lt;/STRONG&gt; Static scanning, dynamic detonation, manual review fallback, and ongoing re-scanning mean the catalog maintains a high trust bar - not just at ingestion, but over time. And it's all built on the same Win32 delivery infrastructure that you and your devices already trust.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The bottom line: Enterprise App Management isn’t just about convenience. It shifts the app lifecycle from a manual, error-prone process to one with built-in security validation, operational consistency, and governance you can defend to your security team. Rather than manually sourcing installers and creating detection rules, use this approach to streamline the process.&lt;/P&gt;
&lt;P&gt;If you have any questions, leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Want to go deeper? Check out the &lt;/EM&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/app-management/deployment/enterprise-app-management" target="_blank" rel="noopener"&gt;Enterprise App Management documentation&lt;/A&gt;&lt;EM&gt; and keep an eye out for upcoming changes to &lt;/EM&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/add-ons" target="_blank" rel="noopener"&gt;Intune Suite licensing&lt;/A&gt;&lt;EM&gt; that will make Enterprise App Management available in the Microsoft 365 plans you may already own. And as always, drop feedback at &lt;/EM&gt;&lt;A class="lia-external-url" href="https://aka.ms/IntuneFeedback" target="_blank" rel="noopener"&gt;aka.ms/IntuneFeedback&lt;/A&gt;&lt;EM&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A class="lia-external-url" href="https://aka.ms/JoinIntuneCommunity" data-outlook-id="b28472ac-e9ef-4c22-803d-2eabb395ee0c" target="_blank"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt; .&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 23:32:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/how-enterprise-app-management-secures-your-app-catalog-from/ba-p/4528361</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-19T23:32:01Z</dc:date>
    </item>
    <item>
      <title>MDOP is out of support: What to do next with Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024</link>
      <description>&lt;P&gt;&lt;STRONG&gt;By: Joe Lurie – Sr. Product Manager | Microsoft Intune&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;On April 14, 2026, the &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-desktop-optimization-pack/" target="_blank" rel="noopener"&gt;Microsoft Desktop Optimization Pack (MDOP)&lt;/A&gt; reached the end of extended support. Microsoft no longer provides security updates, bug fixes, or technical support for MDOP components. For more information, refer to: &lt;A class="lia-external-url" href="https://learn.microsoft.com/lifecycle/announcements/mdop-extended" target="_blank" rel="noopener"&gt;Microsoft Desktop Optimization Pack (MDOP) support extended&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If your organization still relies on parts of MDOP, it’s time to move to supported options. In most cases, including Windows desktop management, app virtualization, BitLocker administration, and Group Policy change control, you can handle the same workloads with capabilities in Microsoft Entra ID, Intune, Windows 11, and Configuration Manager.&lt;/P&gt;
&lt;P&gt;Moving these workloads to the cloud does more than keep you supported. It removes on-premises server infrastructure you have to stand up and patch, brings management of cross-platform devices into a unified console, and connects capabilities like encryption and recovery into a Zero Trust framework with Conditional Access.&lt;/P&gt;
&lt;H2&gt;Quick start checklist&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Inventory what you actually use.&lt;/STRONG&gt; Confirm whether Application Virtualization (App-V) server components, Microsoft BitLocker Administration and Monitoring (MBAM), Diagnostics and Recovery Toolset (DaRT), User Experience Virtualization (UE-V), or Advanced Group Policy Management (AGPM) are still in production.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Prioritize BitLocker Management first.&lt;/STRONG&gt; If you still rely on MBAM, plan your move to &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows" target="_blank" rel="noopener"&gt;BitLocker management in Intune&lt;/A&gt; and confirm recovery key escrow is working as expected.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Plan your App-V exit.&lt;/STRONG&gt; Keep existing App-V packages running where needed but shift net-new packaging work to &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/overview" target="_blank" rel="noopener"&gt;MSIX&lt;/A&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Validate your PC recovery story.&lt;/STRONG&gt; Document how you’ll handle common break/fix scenarios using &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/quick-machine-recovery/" target="_blank" rel="noopener"&gt;Quick Machine Recovery&lt;/A&gt;, WinRE, bootable media, and Intune remote actions.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Decide how you want to handle policy change management.&lt;/STRONG&gt; For cloud policy, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/role-based-access-control/multi-admin-approval" target="_blank" rel="noopener"&gt;Multi Admin Approval&lt;/A&gt; for sensitive actions and policy-as-code practices for versioning and review.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;App-V&lt;/H2&gt;
&lt;P&gt;App-V let you virtualize applications so they could run in isolated environments without a traditional install, which helped avoid app conflicts. It was especially useful for legacy line-of-business apps that were hard to install or update cleanly.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important&lt;BR /&gt;&lt;/STRONG&gt;The App-V server components (Management Server, Publishing Server, Reporting Server) reached end of extended support in April 2026. The App-V client and sequencer are still included with Windows Enterprise and Education editions. They will continue to receive security fixes for the support lifecycle of the Windows versions they ship with. If you are distributing App-V packages today via Configuration Manager, that can still work. The key change is that you should not plan on using the standalone App-V server infrastructure going forward. For more details refer to: &lt;A class="lia-external-url" href="https://learn.microsoft.com/microsoft-desktop-optimization-pack/app-v/appv-support-policy" target="_blank" rel="noopener"&gt;App-V in Windows support policy&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; For new packaging work, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/overview" target="_blank" rel="noopener"&gt;moving to MSIX&lt;/A&gt;. MSIX is a modern packaging format that supports clean install and uninstall and more predictable updating. The &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/packaging-tool/tool-overview" target="_blank" rel="noopener"&gt;MSIX Packaging Tool&lt;/A&gt; can help you convert existing installers. In Azure Virtual Desktop, &lt;A class="lia-external-url" href="https://learn.microsoft.com/azure/virtual-desktop/app-attach-overview" target="_blank" rel="noopener"&gt;MSIX App Attach&lt;/A&gt; can deliver apps without baking them into the base image. A good starting point is to inventory your App-V packages, identify the ones you still need, and prioritize candidates to &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/msix/packaging-tool/create-app-package" target="_blank" rel="noopener"&gt;convert&lt;/A&gt; to MSIX.&lt;/P&gt;
&lt;H2&gt;MBAM&lt;/H2&gt;
&lt;P&gt;MBAM gave IT admins centralized control over BitLocker, including policy enforcement, compliance reporting, and a self-service recovery portal. Many organizations used MBAM as their standard management solution.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; We recommend replacing MBAM with Microsoft Intune’s BitLocker policy management through an &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows#endpoint-security-policy-recommended" target="_blank" rel="noopener"&gt;Endpoint security policy&lt;/A&gt;. Intune management provides backup of recovery keys to Microsoft Entra ID, reporting, and &lt;A class="lia-external-url" href="https://learn.microsoft.com/mem/intune/protect/conditional-access" target="_blank" rel="noopener"&gt;Conditional Access&lt;/A&gt; integration so you can require encryption for access to company resources. If you already manage devices with Intune, you may only need to create a disk encryption policy and confirm recovery keys are being escrowed. For detailed guidance, review &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/endpoint-security/encrypt-bitlocker-windows" target="_blank" rel="noopener"&gt;Encrypt Windows devices with BitLocker using Intune&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;DaRT&lt;/H2&gt;
&lt;P&gt;DaRT provided a bootable recovery environment with advanced tools like file recovery, registry editing, and offline troubleshooting. You typically used DaRT when a machine wouldn’t boot and you needed to repair it or recover data without reimaging.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; Windows includes the &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-hardware/manufacture/desktop/windows-recovery-environment--windows-re--technical-reference" target="_blank" rel="noopener"&gt;Windows Recovery Environment (WinRE)&lt;/A&gt; with tools like Startup Repair, System Restore, command prompt, and reset options. For many scenarios DaRT covered, WinRE is enough. You can also boot from a Windows installation USB, select "Repair your computer," and use the recovery tools for tasks like offline troubleshooting.&lt;/P&gt;
&lt;P&gt;For managed devices, you can pair recovery options with Intune remote actions, such as restart, wipe, or collect diagnostics, or use &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noopener"&gt;Quick Machine Recovery&lt;/A&gt;. Additionally, Quick Machine Recovery can automatically detect and fix boot failures using cloud-based remediation delivered through Windows Update, with no hands-on IT intervention required for managed devices running Windows 11 version 24H2 or later. You can enable and configure it through the &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/" target="_blank" rel="noopener"&gt;settings catalog&lt;/A&gt; in Intune, and &lt;A class="lia-external-url" href="https://learn.microsoft.com/autopilot/windows-autopilot" target="_blank" rel="noopener"&gt;Windows Autopilot&lt;/A&gt; scenarios for redeployment. These don’t replace every DaRT capability, but they cover many common use cases and work without shipping a separate recovery toolkit.&lt;/P&gt;
&lt;H2&gt;UE-V&lt;/H2&gt;
&lt;P&gt;UE-V roamed (synchronized) some user application and OS settings to persist across devices so users could sign in to a different Windows PC and keep a familiar experience. This was often used in shared workstation scenarios.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; For Windows settings roaming, &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows/configuration/windows-backup/?tabs=intune" target="_blank" rel="noopener"&gt;Windows Backup for Organizations&lt;/A&gt; syncs certain Windows settings across Microsoft Entra ID joined devices. Review the latest guidance to confirm which settings are covered and how to enable it in your environment.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Windows Backup for Organizations syncs Windows settings (theme, password, language) but doesn’t roam per-application settings for Win32 apps. Some apps may provide their own cloud-based sync. Windows Backup for Organizations is not a direct replacement for UE-V.&lt;/P&gt;
&lt;P&gt;For user files, we recommend &lt;A class="lia-external-url" href="https://learn.microsoft.com/sharepoint/redirect-known-folders" target="_blank" rel="noopener"&gt;OneDrive Known Folder Move&lt;/A&gt; to back up Desktop, Documents, and Pictures so content follows the user. Many Microsoft applications also sync their own settings through the cloud, which reduces the need for an OS-level roaming solution.&lt;/P&gt;
&lt;P&gt;Another option is to use a virtualized solution, like &lt;A class="lia-external-url" href="https://azure.microsoft.com/products/virtual-desktop/" target="_blank" rel="noopener"&gt;Azure Virtual Desktop&lt;/A&gt; or &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-365/overview" target="_blank" rel="noopener"&gt;Windows 365&lt;/A&gt;. With a Cloud PC, users connect to the same environment from any device, so settings and apps are already there when they sign in. For scenarios where UE-V mattered most, like shared workstation environments, Windows 365 can be a practical alternative. And for Azure Virtual Desktop, &lt;A class="lia-external-url" href="https://learn.microsoft.com/fslogix/overview-what-is-fslogix" target="_blank" rel="noopener"&gt;FSLogix&lt;/A&gt; is a viable option.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Important:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Enterprise State Roaming does not roam per-application settings for traditional Win32 desktop apps the way UE-V did. So, Windows 365 may not be the right fit if you need settings roaming across multiple physical devices.&lt;/P&gt;
&lt;H2&gt;AGPM&lt;/H2&gt;
&lt;P&gt;AGPM brought version control, change tracking, and approval workflows to Group Policy management. Instead of an admin changing Group Policy Objects (GPOs) directly in production, AGPM enforced a check-out and check-in model with full audit history. This mattered most in environments with strict change management requirements.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What to do instead:&lt;/STRONG&gt; Move to cloud-managed endpoints and replace Group Policy settings with Intune configuration profiles and security baselines. The settings catalog in Intune includes thousands of settings, including many ADMX-backed policies. If you use custom ADMX files for third-party or internal applications, you can &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/device-configuration/settings-catalog/import-custom-admx-templates" target="_blank" rel="noopener"&gt;import them into Intune&lt;/A&gt;. For settings that aren’t available in the catalog, custom OMA-URI profiles can sometimes be used, depending on the CSP support for that setting.&lt;/P&gt;
&lt;P&gt;For change management, Intune offers&amp;nbsp;&lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/fundamentals/role-based-access-control/multi-admin-approval" target="_blank" rel="noopener"&gt;Multi Admin Approval&lt;/A&gt; for certain policy changes, which can add a second-admin approval step. If you want deeper versioning and review workflows, we often see teams using Configuration as Code. Teams practicing Configuration as Code define Intune policies as code or structured data, such as in a JSON file stored outside the Intune admin center. This can be stored in version control like Azure DevOps or GitHub, and use &lt;A class="lia-external-url" href="https://learn.microsoft.com/graph/api/resources/intune-graph-overview?view=graph-rest-1.0" target="_blank" rel="noopener"&gt;Microsoft Graph&lt;/A&gt; – directly or via tooling – to deploy and reconcile the service. This enables deep versioning, peer review, and repeatable, auditable changes. And with Intune, you can use Graph API to get &lt;A class="lia-external-url" href="https://learn.microsoft.com/intune/governance/monitor-audit-logs#use-graph-api-to-retrieve-audit-events" target="_blank" rel="noopener"&gt;two years&lt;/A&gt; of audit events.&lt;/P&gt;
&lt;H2&gt;Summary&lt;/H2&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table class="lia-indent-margin-left-60px lia-border-style-solid" border="1" style="width: 85.1852%; height: 523.657px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr style="height: 57.1875px;"&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;MDOP tool&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;What it did&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 57.1875px;"&gt;
&lt;P&gt;&lt;STRONG&gt;Cloud-native replacement&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 91.75px;"&gt;&lt;td class="lia-align-center" style="height: 91.75px;"&gt;
&lt;P&gt;App-V (Server)&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 91.75px;"&gt;
&lt;P&gt;Application virtualization and streaming&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 91.75px;"&gt;
&lt;P&gt;MSIX packaging and Intune deployment (client still supported in Windows)&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 81px;"&gt;&lt;td class="lia-align-center" style="height: 81px;"&gt;
&lt;P&gt;MBAM&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 81px;"&gt;
&lt;P&gt;BitLocker management and recovery&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 81px;"&gt;
&lt;P&gt;Intune management of BitLocker and Microsoft Entra ID key escrow&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 84.1875px;"&gt;&lt;td class="lia-align-center" style="height: 84.1875px;"&gt;
&lt;P&gt;DaRT&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 84.1875px;"&gt;
&lt;P&gt;Bootable diagnostics and recovery&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 84.1875px;"&gt;
&lt;P&gt;Windows Recovery Environment (WinRE), bootable USB, and Intune remote actions&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 102.766px;"&gt;&lt;td class="lia-align-center" style="height: 102.766px;"&gt;
&lt;P&gt;UE-V&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 102.766px;"&gt;
&lt;P&gt;User settings roaming&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 102.766px;"&gt;
&lt;P&gt;Windows 365 Cloud PC, Windows Backup for Organizations, OneDrive Known Folder Move, app-native sync&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr style="height: 106.766px;"&gt;&lt;td class="lia-align-center" style="height: 106.766px;"&gt;
&lt;P&gt;AGPM&lt;/P&gt;
&lt;/td&gt;&lt;td class="lia-align-center" style="height: 106.766px;"&gt;
&lt;P&gt;GPO version control and approval workflows&lt;/P&gt;
&lt;/td&gt;&lt;td style="height: 106.766px;"&gt;
&lt;P&gt;Intune settings catalog, Multi Admin Approval, policy-as-code in source control&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.4003%" /&gt;&lt;col style="width: 33.4003%" /&gt;&lt;col style="width: 33.3006%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;H2&gt;Moving forward&lt;/H2&gt;
&lt;P&gt;By moving to cloud endpoint management, most MDOP scenarios are covered through Microsoft Intune and Microsoft Entra ID supported capabilities with less infrastructure to maintain, making it easier for you to manage.&lt;/P&gt;
&lt;P&gt;If you haven’t started planning yet, we suggest starting with MBAM since Intune is the most direct replacement. Then, you can work through App-V, DaRT, UE-V, and AGPM based on what’s still in use.&lt;/P&gt;
&lt;P&gt;If you’re in the middle of an MDOP exit and need help leave a comment below or reach out to us on X &lt;A class="lia-external-url" href="https://aka.ms/IntuneSuppTeam" target="_blank" rel="noopener"&gt;@IntuneSuppTeam&lt;/A&gt;. Tell us which components you still have and how you manage endpoints today (Intune, Configuration Manager, hybrid, or other). We can help you sanity-check dependencies, choose an order of operations, and avoid common migration pitfalls.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Join our community!&lt;/STRONG&gt;&amp;nbsp;Discuss real-world scenarios, get expert guidance, connect with peers, and influence the future of Microsoft Security products. Learn more at &lt;A href="https://aka.ms/JoinIntuneCommunity" data-outlook-id="1500cb02-a991-4798-bffb-dc0f1bde5fd5" target="_blank"&gt;aka.ms/JoinIntuneCommunity&lt;/A&gt;.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 23:35:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024</guid>
      <dc:creator>Intune_Support_Team</dc:creator>
      <dc:date>2026-06-19T23:35:18Z</dc:date>
    </item>
  </channel>
</rss>

