<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Intune topics</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune</link>
    <description>Microsoft Intune topics</description>
    <pubDate>Tue, 04 Aug 2026 03:17:24 GMT</pubDate>
    <dc:creator>Microsoft-Intune</dc:creator>
    <dc:date>2026-08-04T03:17:24Z</dc:date>
    <item>
      <title>INTUNE: Problems with the Google address (Managed Google Play)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-problems-with-the-google-address-managed-google-play/m-p/4543486#M23661</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ever since we added our email address under “&lt;STRONG&gt;Managed Google Play&lt;/STRONG&gt;” (in the Intune Admin Center), we can no longer use that address to sign in to Google, Google Docs, Google Drive, or similar services...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this normal? - If not, what settings do I need to adjust, and where, to get it working again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The error message looks something like this:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Error message:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;We’re sorry, but you don’t have access to Google Docs. Please log in to your Admin Console to enable it"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 11:43:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-problems-with-the-google-address-managed-google-play/m-p/4543486#M23661</guid>
      <dc:creator>ChristianEdwardsen365</dc:creator>
      <dc:date>2026-08-03T11:43:53Z</dc:date>
    </item>
    <item>
      <title>Advanced Microsoft Intune capabilities - Coming to Education A5?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/advanced-microsoft-intune-capabilities-coming-to-education-a5/m-p/4542707#M23649</link>
      <description>&lt;P&gt;The Advanced Microsoft Intune capabilities (what was the Intune Suite has now arrived for E5 customers (and some of the features to E3 customers. Can anyone give any clarity as to if/when these features will be coming to A5 customers?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see we seem to have some of the features (Remote Help, Endpoint Privilege Management) but could really do with knowing if the rest of the features are coming. Can't seem to find any information online about it.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Jul 2026 08:06:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/advanced-microsoft-intune-capabilities-coming-to-education-a5/m-p/4542707#M23649</guid>
      <dc:creator>MarkBerry</dc:creator>
      <dc:date>2026-07-31T08:06:51Z</dc:date>
    </item>
    <item>
      <title>problem with Auto-Enrollment for windows devices in Hybrid enviroument</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/problem-with-auto-enrollment-for-windows-devices-in-hybrid/m-p/4542003#M23639</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I am in the process of setting up Intune for automatic enrollment on Windows devices within our hybrid environment. Here are the steps I have taken so far:&lt;/P&gt;&lt;P&gt;1. Configured Entra ID sync to synchronize a selected OU with Entra ID.&lt;/P&gt;&lt;P&gt;2. In the Intune Portal, set the Automatic enrollment MDM user scope to "All."&lt;/P&gt;&lt;P&gt;3. Created a GPO linked to that OU, which includes the settings to "register domain-joined computers as devices" and "Enabled automatic MDM enrollment using default Azure credentials" based on User Credential.&lt;/P&gt;&lt;P&gt;4. Prepared a clean computer, free of any software, and joined it to the Domain (on-prem server).&lt;/P&gt;&lt;P&gt;5. Moved the computer to the appropriate OU for syncing with Entra ID.&lt;/P&gt;&lt;P&gt;6. At this point, I can see the computer listed in the Entra ID portal under devices as Entra Hybrid joined&lt;/P&gt;&lt;P&gt;7. A regular domain user with a Business Premium license logged into the computer.( Only sign-in to windows, we don't have office app or add this account to windows.)&lt;/P&gt;&lt;P&gt;8. I ran GPupdate /force and rebooted the computer several times, but it still does not appear in the Intune portal.&lt;/P&gt;&lt;P&gt;9.Windows client is windows 11 Pro version 25H2 OS build 26200.8893&lt;/P&gt;&lt;P&gt;Dsregcmd output shows:&lt;/P&gt;&lt;P&gt;✅ Device is domain joined&lt;BR /&gt;✅ Device is synced to Entra ID&lt;BR /&gt;✅ Device authentication is working&lt;BR /&gt;✅ User has a valid PRT (Primary Refresh Token)&lt;BR /&gt;✅ Hybrid Join is successful&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On second test computer2, I installed office desktop app, then sign-in with test user to activate it. After few minutes the computer appeared on Intune portal. but on test computer 1 without user's interaction, it doesn't show up.&lt;/P&gt;&lt;P&gt;would you be able to help me with this?&amp;nbsp; Does it really need user to attach his/her account manually to "work or school account" or sing-in to any office desktop apps?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 12:06:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/problem-with-auto-enrollment-for-windows-devices-in-hybrid/m-p/4542003#M23639</guid>
      <dc:creator>Amir Gh</dc:creator>
      <dc:date>2026-07-29T12:06:51Z</dc:date>
    </item>
    <item>
      <title>Compliance Policies - Device Health Attestation failing (Syncml 404 / 0x87d10194)</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/compliance-policies-device-health-attestation-failing-syncml-404/m-p/4541626#M23633</link>
      <description>&lt;P&gt;Windows 11 devices are non compliant in Intune against BitLocker, Secure Boot and Code Integrity, all three returning the Syncml 404 error. The settings are genuinely enabled. The real cause is the device can't retrieve a Device Health Attestation certificate, so the health cert status sits at 65535 and the retrieval task fails.&lt;/P&gt;&lt;P&gt;What I've found: the TPM is healthy (present, ready, attestation capable, firmware not vulnerable), and the endorsement key cert is valid, chaining to Nuvoton TPM Root CA 2111. But the EK chain check comes back invalid with zero intermediate certificates, because the Nuvoton key is signed straight off the root with no intermediate for the chain walk. A Hyper-V VM on the same build and tenant works fine, but only because it has no manufacturer EK cert, so it skips that chain check entirely.&lt;/P&gt;&lt;P&gt;What I've tried: patching TPM firmware (ruled out the older ADV190024 issue), refreshing the local trusted TPM certificate store, and rerunning the retrieval task. None fixed it. This matches Rudy Ooms' well known call4cloud writeup, where he concluded it's a service side trust problem that can't be fixed from the device.&lt;/P&gt;&lt;P&gt;It's now appearing on brand new Dell hardware too, so I can't just exclude the old kit and move on.&lt;/P&gt;&lt;P&gt;Is this a known issue with the Nuvoton root chain, and is there a supported fix or position from Microsoft? Screenshots below showing the compliance errors and the failure.&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 16:31:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/compliance-policies-device-health-attestation-failing-syncml-404/m-p/4541626#M23633</guid>
      <dc:creator>Durrante</dc:creator>
      <dc:date>2026-07-28T16:31:49Z</dc:date>
    </item>
    <item>
      <title>IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-policys-user-affinity-with-modern-auth-does-not/m-p/4541329#M23629</link>
      <description>&lt;P&gt;IOS Enrollment Policys - User affinity with modern auth, does not work with Company Portal VPP&lt;/P&gt;&lt;P&gt;I am trying to test the newer&amp;nbsp;&lt;STRONG&gt;iOS Enrollment Policies&lt;/STRONG&gt;&amp;nbsp;using&amp;nbsp;&lt;STRONG&gt;User Affinity with Modern Authentication&lt;/STRONG&gt;&amp;nbsp;instead of the older&amp;nbsp;&lt;STRONG&gt;Enrollment Profiles&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One thing I've noticed is that the&amp;nbsp;&lt;STRONG&gt;"Install Company Portal with VPP"&lt;/STRONG&gt;&amp;nbsp;setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies.&lt;/P&gt;&lt;P&gt;My test Policy configuration is using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User Affinity with Modern Authentication&lt;/LI&gt;&lt;LI&gt;Company Portal deployed as a VPP app&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tested deploying Company Portal as a&amp;nbsp;&lt;STRONG&gt;required VPP app&lt;/STRONG&gt;, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to&amp;nbsp;&lt;STRONG&gt;set up company access&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;download a management profile&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;This doesn't seem correct because the device was already enrolled through&amp;nbsp;&lt;STRONG&gt;ADE&lt;/STRONG&gt;. If I select&amp;nbsp;&lt;STRONG&gt;Postpone&lt;/STRONG&gt;, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed.&lt;/P&gt;&lt;P&gt;this has to be a bug or something right? the microsoft docs on this are very confusing or missing details.&lt;/P&gt;&lt;P&gt;I also noticed that the device initially appears in Intune/entra as&amp;nbsp;&lt;STRONG&gt;"iPad"&lt;/STRONG&gt;. After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing&amp;nbsp;&lt;STRONG&gt;two devices&lt;/STRONG&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"iPad" (This is the Ipad that you're currently using)&lt;/LI&gt;&lt;LI&gt;"ipad123-testing" ( this is the proper name and matches intune / entra)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Under&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management&lt;/STRONG&gt;, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully.&lt;/P&gt;&lt;P&gt;It appears that Company Portal is&amp;nbsp;&lt;STRONG&gt;not associating itself with the existing ADE enrollment record&lt;/STRONG&gt;. Instead, it seems to be attempting a&amp;nbsp;&lt;STRONG&gt;user-driven enrollment workflow&lt;/STRONG&gt;&amp;nbsp;on a device that is already enrolled and managed through ADE.&lt;/P&gt;&lt;P&gt;Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state.&lt;/P&gt;&lt;P&gt;i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.I am trying to test the newer&amp;nbsp;&lt;STRONG&gt;iOS Enrollment Policies&lt;/STRONG&gt;&amp;nbsp;using&amp;nbsp;&lt;STRONG&gt;User Affinity with Modern Authentication&lt;/STRONG&gt;&amp;nbsp;instead of the older&amp;nbsp;&lt;STRONG&gt;Enrollment Profiles&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;One thing I've noticed is that the&amp;nbsp;&lt;STRONG&gt;"Install Company Portal with VPP"&lt;/STRONG&gt;&amp;nbsp;setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies.&lt;/P&gt;&lt;P&gt;My test Policy configuration is using:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User Affinity with Modern Authentication&lt;/LI&gt;&lt;LI&gt;Company Portal deployed as a VPP app&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I tested deploying Company Portal as a&amp;nbsp;&lt;STRONG&gt;required VPP app&lt;/STRONG&gt;, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to&amp;nbsp;&lt;STRONG&gt;set up company access&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;download a management profile&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;This doesn't seem correct because the device was already enrolled through&amp;nbsp;&lt;STRONG&gt;ADE&lt;/STRONG&gt;. If I select&amp;nbsp;&lt;STRONG&gt;Postpone&lt;/STRONG&gt;, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed.&lt;/P&gt;&lt;P&gt;this has to be a bug or something right? the microsoft docs on this are very confusing or missing details.&lt;/P&gt;&lt;P&gt;I also noticed that the device initially appears in Intune/entra as&amp;nbsp;&lt;STRONG&gt;"iPad"&lt;/STRONG&gt;. After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing&amp;nbsp;&lt;STRONG&gt;two devices&lt;/STRONG&gt;:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;"iPad" (This is the Ipad that you're currently using)&lt;/LI&gt;&lt;LI&gt;"ipad123-testing" ( this is the proper name and matches intune / entra)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Under&amp;nbsp;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management&lt;/STRONG&gt;, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully.&lt;/P&gt;&lt;P&gt;It appears that Company Portal is&amp;nbsp;&lt;STRONG&gt;not associating itself with the existing ADE enrollment record&lt;/STRONG&gt;. Instead, it seems to be attempting a&amp;nbsp;&lt;STRONG&gt;user-driven enrollment workflow&lt;/STRONG&gt;&amp;nbsp;on a device that is already enrolled and managed through ADE.&lt;/P&gt;&lt;P&gt;Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state.&lt;/P&gt;&lt;P&gt;i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2026 02:55:58 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-policys-user-affinity-with-modern-auth-does-not/m-p/4541329#M23629</guid>
      <dc:creator>GT3</dc:creator>
      <dc:date>2026-07-28T02:55:58Z</dc:date>
    </item>
    <item>
      <title>iOS Enrollment and Conditional Access</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-and-conditional-access/m-p/4541284#M23628</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I need some help!&lt;/P&gt;&lt;P&gt;We are configuring Intune to allow &lt;STRONG&gt;BYOD on iOS devices&lt;/STRONG&gt; using the &lt;STRONG&gt;Account Driven User Enrollment&lt;/STRONG&gt; method. In this scenario, the user enrolls the device by following the path:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Settings &amp;gt; General &amp;gt; VPN &amp;amp; Device Management &amp;gt; Sign in to your Work or School Account&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The enrollment process was working correctly until we configured a &lt;STRONG&gt;Conditional Access&lt;/STRONG&gt; policy to ensure that only BYOD-managed devices can access company resources. In other words, only devices that have successfully completed enrollment and are marked as &lt;STRONG&gt;Compliant&lt;/STRONG&gt; in Intune should be allowed to use corporate applications.&lt;/P&gt;&lt;P&gt;However, after applying the policy, we are no longer able to complete the enrollment process. During one of the enrollment steps, the device displays the following message:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Translate English&lt;/STRONG&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;"Setting Up iPhone&lt;/STRONG&gt;&lt;BR /&gt;iPhone setup may take a few minutes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sign-In Failed&lt;/STRONG&gt;&lt;BR /&gt;Enrollment failed. Please try again.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;OK"&lt;/STRONG&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;1.&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;Target resources (Include)&lt;/STRONG&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;2.&amp;nbsp;Target resources (Exclude)&lt;/STRONG&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;3. &lt;/STRONG&gt;&lt;STRONG&gt;Device Platform:&lt;/STRONG&gt; iOS&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;4.&lt;/STRONG&gt; &lt;STRONG&gt;Filter for devices:&lt;/STRONG&gt; device.mdmAppId -notIn ["0000000a-0000-0000-c000-000000000000"]&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&lt;STRONG&gt;5.&lt;/STRONG&gt; &lt;STRONG&gt;Grant:&lt;/STRONG&gt; Require device to be marked as compliant&lt;/P&gt;&lt;img /&gt;&lt;P&gt;This is our current Conditional Access policy configuration. Has anyone encountered this behavior before, or can identify whether there is any setting that might be blocking the enrollment process during the compliance validation stage?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2026 19:37:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/ios-enrollment-and-conditional-access/m-p/4541284#M23628</guid>
      <dc:creator>GuilhermeSoares</dc:creator>
      <dc:date>2026-07-27T19:37:50Z</dc:date>
    </item>
    <item>
      <title>Dell Firmware Very Slow to Appear in Intune Driver Updates</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/dell-firmware-very-slow-to-appear-in-intune-driver-updates/m-p/4539663#M23622</link>
      <description>&lt;P&gt;Have an instance where the Dell 5520 latest firmware release (1.51.0 released 09/06/26) has still not appeared in the Intune Driver Updates which means we have vulnerable laptops in the field.&lt;/P&gt;&lt;P&gt;We do not utilise Dell Command update on the laptop to reduce the attack surface so do rely on Intune to deliver these updates in a timely manner.&lt;/P&gt;&lt;P&gt;I'm aware that it can take a little while for Dell releases to appear on the Microsoft side, but this is over 6 weeks now.&lt;/P&gt;&lt;P&gt;We have spoken to Dell Support, but they have deemed this a Microsoft problem. We then spoke to Microsoft Support, and it was deemed that we would have to pay for support on this given it fell outside of the scope of our service level. So essentially no-one wanted to take responsibility or assist with this!&lt;/P&gt;&lt;P&gt;Does the forum have any insights into what may be going on here and how we can move this forward?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 08:56:43 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/dell-firmware-very-slow-to-appear-in-intune-driver-updates/m-p/4539663#M23622</guid>
      <dc:creator>SenõrEngineer</dc:creator>
      <dc:date>2026-07-22T08:56:43Z</dc:date>
    </item>
    <item>
      <title>Microsoft EPM – Random CMD / PowerShell / OpenConsole popups</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/microsoft-epm-random-cmd-powershell-openconsole-popups/m-p/4538823#M23617</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;we are currently testing &lt;STRONG&gt;Microsoft Endpoint Privilege Management (EPM)&lt;/STRONG&gt; and are seeing some unexpected behavior on several devices.&lt;/P&gt;&lt;H3&gt;Symptoms&lt;/H3&gt;&lt;P&gt;Users occasionally see random:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;CMD windows&lt;/LI&gt;&lt;LI&gt;PowerShell windows&lt;/LI&gt;&lt;LI&gt;OpenConsole windows&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The windows usually appear shortly after logon and disappear automatically after a short time.&lt;/P&gt;&lt;P&gt;Some developers also reported issues related to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;VS Code terminal integration&lt;/LI&gt;&lt;LI&gt;Copilot terminal actions&lt;/LI&gt;&lt;LI&gt;Windows Terminal&lt;/LI&gt;&lt;LI&gt;WSL / Debian&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Additional observations&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;However, we have also seen PowerShell popups on a user who is not currently part of the EPM pilot group&lt;/LI&gt;&lt;LI&gt;Some affected devices still have &lt;STRONG&gt;Admin By Request&lt;/STRONG&gt; installed&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Current EPM Configuration&lt;/H3&gt;&lt;P&gt;At the moment we only have an &lt;STRONG&gt;Elevation Settings Policy&lt;/STRONG&gt; assigned with &lt;STRONG&gt;User Confirmed&lt;/STRONG&gt; enabled.&lt;/P&gt;&lt;P&gt;We currently do &lt;STRONG&gt;not&lt;/STRONG&gt; have any custom elevation rules, file hash rules, publisher rules or automatic elevations configured.&lt;/P&gt;&lt;P&gt;The issue appears in a configuration that is essentially limited to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EPM client installed&lt;/LI&gt;&lt;LI&gt;Elevation Settings Policy assigned&lt;/LI&gt;&lt;LI&gt;User Confirmed elevation workflow enabled&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This is one of the reasons why we are unsure whether the behavior is directly related to an EPM policy configuration or to an interaction between:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;EPM agent&lt;/LI&gt;&lt;LI&gt;Windows Terminal / OpenConsole&lt;/LI&gt;&lt;LI&gt;VS Code&lt;/LI&gt;&lt;LI&gt;WSL&lt;/LI&gt;&lt;LI&gt;Admin By Request&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Questions&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;Has anyone experienced random CMD / PowerShell / OpenConsole windows after introducing EPM?&lt;/LI&gt;&lt;LI&gt;Has anyone seen issues between EPM and:&lt;UL&gt;&lt;LI&gt;Windows Terminal&lt;/LI&gt;&lt;LI&gt;OpenConsole.exe&lt;/LI&gt;&lt;LI&gt;VS Code terminal&lt;/LI&gt;&lt;LI&gt;WSL&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Has anyone run &lt;STRONG&gt;Admin By Request&lt;/STRONG&gt; and &lt;STRONG&gt;Microsoft EPM&lt;/STRONG&gt; on the same device and observed unexpected console windows?&lt;/LI&gt;&lt;LI&gt;Are there any EPM-specific logs that provide detailed parent/child process relationships for these launches?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Any ideas or similar experiences would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2026 08:35:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/microsoft-epm-random-cmd-powershell-openconsole-popups/m-p/4538823#M23617</guid>
      <dc:creator>silasst</dc:creator>
      <dc:date>2026-07-20T08:35:45Z</dc:date>
    </item>
    <item>
      <title>Is it possible to automate Minimum Windows OS version compliance policy?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/is-it-possible-to-automate-minimum-windows-os-version-compliance/m-p/4538058#M23602</link>
      <description>&lt;P&gt;Is it possible to set a Windows compliance policy for Minimum OS Version that automatically updates each month and marks the device noncompliant after 14 days?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;This would work if we normally allow users 2 weeks after Patch Tuesday to get their device updated. We would like to avoid having to have someone remember to manually edit the compliance policy every month to update the minimum build number in the policy.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2026 06:17:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/is-it-possible-to-automate-minimum-windows-os-version-compliance/m-p/4538058#M23602</guid>
      <dc:creator>Modechristo_13</dc:creator>
      <dc:date>2026-07-17T06:17:56Z</dc:date>
    </item>
    <item>
      <title>Android Fully Managed devices treated as personal after AD password change</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/android-fully-managed-devices-treated-as-personal-after-ad/m-p/4536270#M23591</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;We have a huge problem...&lt;/P&gt;&lt;P&gt;We have recently observed an issue in our organization affecting Android Fully Managed devices.&lt;/P&gt;&lt;P&gt;After users change their domain password, within 1–3 days Conditional Access starts blocking access to Outlook and Teams. The system appears to treat the device as non-corporate, even though in Intune the device is still present, marked as corporate, and fully functional. It synchronizes both manually and automatically, and remote actions can be executed without any issues.&lt;/P&gt;&lt;P&gt;However, when users open Outlook or Teams, they receive messages such as “We need to secure your device” and “Install the Intune app from Google Play,” which does not make sense because Intune is already installed on the device.&lt;/P&gt;&lt;P&gt;When opening the Intune app, users see a “Update your password” prompt. After selecting it, they are redirected to a device registration screen.&lt;/P&gt;&lt;P&gt;Previously, it was sometimes possible to complete this process (although we did not understand why it was required), but recently re-registration consistently fails. The user clicks “Register,” and the process spins indefinitely without completing.&lt;/P&gt;&lt;P&gt;This issue is very difficult to troubleshoot. Device logs are not particularly helpful, and all users have Microsoft Authenticator configured. The problem appears randomly across users with no clear pattern—some devices were enrolled over a year ago, others just a month ago.&lt;/P&gt;&lt;P&gt;The only clue we have found so far points to a potential issue with the broker authentication token, but we do not know how to verify or resolve this, nor why it is happening in the first place.&lt;/P&gt;&lt;P&gt;We have been experiencing this issue since around January this year, but we noticed a significant increase in cases this month. In addition, there are more and more devices that can no longer be re‑registered from within the Intune app.&lt;/P&gt;&lt;P&gt;Has anyone encountered a similar issue or can provide guidance on how to investigate or fix this?&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jul 2026 17:39:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/android-fully-managed-devices-treated-as-personal-after-ad/m-p/4536270#M23591</guid>
      <dc:creator>dammas</dc:creator>
      <dc:date>2026-07-12T17:39:36Z</dc:date>
    </item>
    <item>
      <title>Autopatch for quality updates and WUFB for feature updates</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-for-quality-updates-and-wufb-for-feature-updates/m-p/4535259#M23586</link>
      <description>&lt;P&gt;We have switched to Autopatch for quality updates in our environment, but now is the time for feature update deployments. In the past we had used Windows Updates for Business for feature update without any problem. We would like to deploy the feature updates and retain the control of the target groups through the process, which are different ones from the quality updates. As the content is much bigger, we would like to test to specific users, after communicating to them for the procedure, and also be sure that the availability and the bandwidth will be adequate specially now during summer holidays. Could we still use WUfB only for the feature deployment along with Autopatch, without intervening to the normal monthly update cycle?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 09:00:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-for-quality-updates-and-wufb-for-feature-updates/m-p/4535259#M23586</guid>
      <dc:creator>demion</dc:creator>
      <dc:date>2026-07-09T09:00:56Z</dc:date>
    </item>
    <item>
      <title>Cannot delete a website shortcut by Intune managed iphone</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-delete-a-website-shortcut-by-intune-managed-iphone/m-p/4534924#M23581</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;We manually created a shortcut to a website from Safari browser and the shortcut is on the Intune managed iPhone. We don't need the shortcut now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However we cannot delete it. Press and hold apps on this phone does not start wiggle mode and we cannot drag the shortcut onto a new home screen. We also cannot see it in the Apps list in Intune to delete either because it was manually added on that specific iPhone. Can you tell me if there is a away to delete the shortcuts please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 12:16:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-delete-a-website-shortcut-by-intune-managed-iphone/m-p/4534924#M23581</guid>
      <dc:creator>rredford</dc:creator>
      <dc:date>2026-07-08T12:16:14Z</dc:date>
    </item>
    <item>
      <title>Automatically Sync SharePoint Document Libraries on macOS</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/automatically-sync-sharepoint-document-libraries-on-macos/m-p/4534130#M23569</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We manage macOS devices with Microsoft Intune and need to automatically sync one or more SharePoint document libraries to users' OneDrive, similar to how it's done on Windows using the Intune auto-sync policy.&lt;/P&gt;&lt;P&gt;Has anyone successfully implemented this on macOS using Intune, Jamf Pro, configuration profiles, or a supported script?&lt;/P&gt;&lt;P&gt;We're looking for a Microsoft-supported solution that minimizes or eliminates user interaction.&lt;/P&gt;&lt;P&gt;Any guidance or recommendations would be greatly appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 13:01:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/automatically-sync-sharepoint-document-libraries-on-macos/m-p/4534130#M23569</guid>
      <dc:creator>ynarvil</dc:creator>
      <dc:date>2026-07-06T13:01:11Z</dc:date>
    </item>
    <item>
      <title>Intune Platform Scripts never target devices (0 targeted devices) despite healthy Intune environment</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-platform-scripts-never-target-devices-0-targeted-devices/m-p/4531649#M23557</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm hoping someone has seen this before because I've exhausted most of the obvious troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Microsoft 365 Business Premium&lt;/LI&gt;&lt;LI&gt;Windows 11 Pro&lt;/LI&gt;&lt;LI&gt;Microsoft Intune&lt;/LI&gt;&lt;LI&gt;Microsoft Entra ID Joined devices&lt;/LI&gt;&lt;LI&gt;Intune Management Extension (IME) installed and healthy&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;The Issue&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Platform Scripts never target any devices.&lt;/P&gt;&lt;P&gt;Regardless of the script, assignment or device, the script always remains at:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;0 Devices&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;0 Succeeded&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;0 Errors&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The device never appears under &lt;STRONG&gt;Device Status&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What works&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The Intune environment is otherwise functioning normally.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Configuration Profiles deploy successfully.&lt;/LI&gt;&lt;LI&gt;Settings Catalog policies apply successfully.&lt;/LI&gt;&lt;LI&gt;BitLocker policies apply.&lt;/LI&gt;&lt;LI&gt;Windows Firewall policies apply.&lt;/LI&gt;&lt;LI&gt;Windows LAPS is working.&lt;/LI&gt;&lt;LI&gt;Win32 applications deploy successfully&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Devices are Entra Joined and managed by Intune.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;What I've tested&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;To eliminate variables I created:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Created a brand new PowerShell script that simply creates a text file.&lt;/LI&gt;&lt;LI&gt;Created a brand new &lt;STRONG&gt;assigned Security Group&lt;/STRONG&gt; containing a single Windows 11 device.&lt;/LI&gt;&lt;LI&gt;Assigned &lt;STRONG&gt;only that Security Group&lt;/STRONG&gt; to the Platform Script.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The result is still:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;0 Devices&lt;/LI&gt;&lt;LI&gt;0 Succeeded&lt;/LI&gt;&lt;LI&gt;0 Errors&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Device checks completed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;On the client:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;dsregcmd /status shows AzureAdJoined = YES.&lt;/LI&gt;&lt;LI&gt;Intune Management Extension service is running.&lt;/LI&gt;&lt;LI&gt;Win32 apps are deploying correctly.&lt;/LI&gt;&lt;LI&gt;Intune Management Extension logs appear healthy.&lt;/LI&gt;&lt;LI&gt;AgentExecutor.log contains WinGet application activity but no evidence of any Platform Script ever being downloaded or executed.&lt;/LI&gt;&lt;LI&gt;The IntuneManagementExtension registry contains SideCarPolicies but there is no evidence of any PowerShell script policy being received.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Additional observations&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I reproduced the issue on two separate Windows 11 devices.&lt;/LI&gt;&lt;LI&gt;I reproduced the issue using both dynamic and assigned device groups.&lt;/LI&gt;&lt;LI&gt;I reproduced the issue using different PowerShell scripts.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This makes me believe the issue is not device specific.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen Platform Scripts remain permanently at &lt;STRONG&gt;0 targeted devices&lt;/STRONG&gt; despite Intune otherwise functioning normally?&lt;/P&gt;&lt;P&gt;Is there a known tenant-side issue, prerequisite or licensing requirement that would prevent Platform Scripts from ever targeting devices while Win32 apps and Configuration Profiles continue to work?&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 05:42:08 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-platform-scripts-never-target-devices-0-targeted-devices/m-p/4531649#M23557</guid>
      <dc:creator>HRZook</dc:creator>
      <dc:date>2026-06-29T05:42:08Z</dc:date>
    </item>
    <item>
      <title>Secure Score does not reflect settings in ASR rule</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/secure-score-does-not-reflect-settings-in-asr-rule/m-p/4530110#M23548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Our secure score ist pretty low, so I followed recommendations from M365 Security Center. The setting reside in one ASR rule, but Secure Score still does not reflect my&amp;nbsp; settings still stating 0% achievement. I waited nearly a week. Defender is not the primary AV, but on other tenants the same setting led to success.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 09:59:39 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/secure-score-does-not-reflect-settings-in-asr-rule/m-p/4530110#M23548</guid>
      <dc:creator>heinzelrumpel</dc:creator>
      <dc:date>2026-06-23T09:59:39Z</dc:date>
    </item>
    <item>
      <title>Intune Autopatch Reports - Expected Behavior</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-autopatch-reports-expected-behavior/m-p/4529521#M23547</link>
      <description>&lt;P&gt;I utilize the Intune Autopatch Reports for Quality Updates to monitor the deployment of updates across our environment. We currently have a group of devices which have a 30-day deferral period due to the compliance/testing policy we have to follow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Understanding is that the "Quality Update Status" Report will determine if the device is Up-to-Date based on if the device has the update that has been released to it but I am finding that all devices are marked as Not Up-to-Date even with the 2026.05 QU installed as the 2026.06 QU is not available for the devices. I am wondering if this is expected behavior or if this changed because before the changes to the reports in May (2026.05) it was showing correctly&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2026 14:47:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-autopatch-reports-expected-behavior/m-p/4529521#M23547</guid>
      <dc:creator>jokelly</dc:creator>
      <dc:date>2026-06-19T14:47:13Z</dc:date>
    </item>
    <item>
      <title>enrolling in Intune MacBook Pro with an M5 Pro</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/enrolling-in-intune-macbook-pro-with-an-m5-pro/m-p/4528566#M23543</link>
      <description>&lt;P&gt;Hi everyone&lt;/P&gt;&lt;P&gt;We have tested the Wi-Fi and ethernet profile without success with Apple businesses manager.&lt;/P&gt;&lt;P&gt;The Wi-Fi and the ethernet connection itself works, but the enrollment process into Intune does not complete successfully.&lt;/P&gt;&lt;P&gt;At this stage, we cannot sign in, and neither the Wi-Fi nor the Ethernet connection appears to be working.&lt;/P&gt;&lt;P&gt;The device is a 14-inch MacBook Pro with an M5 Pro chip, running macOS 26.5.1 the device connects to the server, the settings begin to apply, but the process suddenly stops, and we are then unable to log in.&lt;/P&gt;&lt;P&gt;These are steps followed :&lt;BR /&gt;Synchronize the device from Apple Business Manager to Intune.&lt;/P&gt;&lt;P&gt;Assign the enrollment profile to the device.&lt;/P&gt;&lt;P&gt;Perform a device wipe/reset.&lt;/P&gt;&lt;P&gt;Start Automated Device Enrollment (ADE).&lt;/P&gt;&lt;P&gt;Complete the device setup and user sign-in.&lt;/P&gt;&lt;P&gt;The device successfully enrolls into Intune.&lt;/P&gt;&lt;P&gt;Intune begins deploying configuration profiles, compliance policies, security policies, and applications.&lt;/P&gt;&lt;P&gt;During the policy application process, Wi-Fi connectivity stops responding.&lt;/P&gt;&lt;P&gt;The device loses network connectivity and cannot continue synchronizing policies. We are unable to sign in because the enrolment process has not been finalized. As a result, we have to wipe the Mac and start the process again each time.&lt;/P&gt;&lt;P&gt;We have disabled some policies, but we are still experiencing the same issue.&lt;/P&gt;&lt;P&gt;Have anyone experienced any issues like that ?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 15:17:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/enrolling-in-intune-macbook-pro-with-an-m5-pro/m-p/4528566#M23543</guid>
      <dc:creator>miguMac</dc:creator>
      <dc:date>2026-06-16T15:17:50Z</dc:date>
    </item>
    <item>
      <title>Windows App Update Notification</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have deployed the Windows App for a client. Currently, when an update is available, users are seeing an in app banner that says: "Click here to update the app. Meanwhile you can use the app."&lt;/P&gt;&lt;P&gt;If the user clicks it, the update finishes successfully. However, our organization requires a completely hands off, automated update process. We do not want end-users to have to interact with a notification or manually click a button to keep the app up to date.&lt;/P&gt;&lt;P&gt;Is there a specific Group Policy, registry key or Intune configuration that completely suppresses this in app notification and forces the MSIX package to install silently in the background when the app or machine is idle?&lt;/P&gt;&lt;P&gt;Any advice on how to bypass this "Notification" behavior and enforce touchless updates enterprise wide would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 00:08:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</guid>
      <dc:creator>malithamadushan</dc:creator>
      <dc:date>2026-06-10T00:08:45Z</dc:date>
    </item>
    <item>
      <title>Intune Install Printer Driver</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</link>
      <description>&lt;P&gt;I am trying to install a Printer driver via a Win32app using System to install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have set configuration as below:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a simple powershell script which runs perfectly when installing on a device as an administrator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$printdriver = "PCL6 V4 Driver for Universal Print"&lt;/P&gt;&lt;P&gt;C:\Windows\system32\pnputil.exe /add-driver "r4600.inf" /install&lt;/P&gt;&lt;P&gt;Add-PrinterDriver -name $printdriver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However installing it via Intune I get an event id 215 with failed error code 0x0 HRESULT 0x80070705 on the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 10:12:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</guid>
      <dc:creator>tonybap1</dc:creator>
      <dc:date>2026-06-09T10:12:13Z</dc:date>
    </item>
    <item>
      <title>Intune macOS ADE: support for minimum macOS version enforcement before Platform SSO registration</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like to ask whether Microsoft Intune has any supported method, roadmap, or recommended workaround for enforcing a minimum or target macOS version during Automated Device Enrollment before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;The scenario is macOS zero-touch deployment with Intune, Automated Device Enrollment, Setup Assistant with modern authentication, Await final configuration, and Platform SSO registration during ADE.&lt;/P&gt;&lt;P&gt;Platform SSO registration during Setup Assistant depends on newer macOS capabilities. In addition, some macOS deployment scenarios, such as Platform SSO password sync and macOS LAPS, may require or strongly benefit from a specific macOS version being installed before the user completes enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, Intune can manage macOS software updates after enrollment using Declarative Device Management software update policies. However, that does not fully solve the issue where the Mac starts ADE on an older macOS version. In that case, the device may begin Setup Assistant and Platform SSO registration before the required macOS version is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am looking for is an Intune-native equivalent of enforcing a minimum or target macOS version during ADE, before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally, the macOS ADE enrollment profile in Intune would support options such as:&lt;/P&gt;&lt;P&gt;- Minimum required macOS version&lt;/P&gt;&lt;P&gt;- Target specific macOS version&lt;/P&gt;&lt;P&gt;- Target specific build, if supported&lt;/P&gt;&lt;P&gt;- Latest eligible macOS version for the device&lt;/P&gt;&lt;P&gt;- Apply the OS update before Platform SSO registration and final configuration&lt;/P&gt;&lt;P&gt;- Reporting in Intune showing whether the ADE OS update was required, started, completed, skipped, or failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without this capability, organizations using Intune-only macOS deployment may still need manual IT staging or macOS restore/update before handing devices to users. This weakens the zero-touch deployment model, especially when adopting Platform SSO registration during Automated Device Enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is there currently any supported way in Intune to enforce a minimum or target macOS version during ADE before Setup Assistant continues?&lt;/P&gt;&lt;P&gt;2. Is this capability on the Intune roadmap?&lt;/P&gt;&lt;P&gt;3. Are there any recommended workarounds for organizations deploying Platform SSO registration during ADE where a specific macOS version is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance from the Intune team or the community.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 20:56:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</guid>
      <dc:creator>KacperM</dc:creator>
      <dc:date>2026-06-04T20:56:14Z</dc:date>
    </item>
  </channel>
</rss>

