<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Intune topics</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune</link>
    <description>Microsoft Intune topics</description>
    <pubDate>Sat, 13 Jun 2026 02:14:11 GMT</pubDate>
    <dc:creator>Microsoft-Intune</dc:creator>
    <dc:date>2026-06-13T02:14:11Z</dc:date>
    <item>
      <title>CanReset value flipping on cloud only devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/canreset-value-flipping-on-cloud-only-devices/m-p/4527692#M23539</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with cloud only Windows 11 devices configured with passwordless policy. I have noticed that when you run dsregcmd /status command, CanReset value under User State is flipping between "No" and "DestructiveAndNonDestructive". When it's latter, everything works fine, users can start wizard for facial recognition or make PIN changes under Sign In options in Windows. But when it flips to No, everything is blocked. It seems to happen randomly, you can leave device untouched for few hours and just check dcregcmd and the value will change. CanReset is the only value that changes in the dsregcmd report.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It happens for different devices located on different networks. Also, I have disabled web gateway completely for one device just for testing but no change. Any suggestions would be welcome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jun 2026 07:06:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/canreset-value-flipping-on-cloud-only-devices/m-p/4527692#M23539</guid>
      <dc:creator>Mariusz_80</dc:creator>
      <dc:date>2026-06-12T07:06:37Z</dc:date>
    </item>
    <item>
      <title>Windows App Update Notification</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We have deployed the Windows App for a client. Currently, when an update is available, users are seeing an in app banner that says: "Click here to update the app. Meanwhile you can use the app."&lt;/P&gt;&lt;P&gt;If the user clicks it, the update finishes successfully. However, our organization requires a completely hands off, automated update process. We do not want end-users to have to interact with a notification or manually click a button to keep the app up to date.&lt;/P&gt;&lt;P&gt;Is there a specific Group Policy, registry key or Intune configuration that completely suppresses this in app notification and forces the MSIX package to install silently in the background when the app or machine is idle?&lt;/P&gt;&lt;P&gt;Any advice on how to bypass this "Notification" behavior and enforce touchless updates enterprise wide would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2026 00:08:45 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536</guid>
      <dc:creator>malithamadushan</dc:creator>
      <dc:date>2026-06-10T00:08:45Z</dc:date>
    </item>
    <item>
      <title>Intune Install Printer Driver</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</link>
      <description>&lt;P&gt;I am trying to install a Printer driver via a Win32app using System to install.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have set configuration as below:&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its a simple powershell script which runs perfectly when installing on a device as an administrator.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$printdriver = "PCL6 V4 Driver for Universal Print"&lt;/P&gt;&lt;P&gt;C:\Windows\system32\pnputil.exe /add-driver "r4600.inf" /install&lt;/P&gt;&lt;P&gt;Add-PrinterDriver -name $printdriver&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However installing it via Intune I get an event id 215 with failed error code 0x0 HRESULT 0x80070705 on the device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2026 10:12:13 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-install-printer-driver/m-p/4526738#M23534</guid>
      <dc:creator>tonybap1</dc:creator>
      <dc:date>2026-06-09T10:12:13Z</dc:date>
    </item>
    <item>
      <title>Intune macOS ADE: support for minimum macOS version enforcement before Platform SSO registration</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I would like to ask whether Microsoft Intune has any supported method, roadmap, or recommended workaround for enforcing a minimum or target macOS version during Automated Device Enrollment before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;The scenario is macOS zero-touch deployment with Intune, Automated Device Enrollment, Setup Assistant with modern authentication, Await final configuration, and Platform SSO registration during ADE.&lt;/P&gt;&lt;P&gt;Platform SSO registration during Setup Assistant depends on newer macOS capabilities. In addition, some macOS deployment scenarios, such as Platform SSO password sync and macOS LAPS, may require or strongly benefit from a specific macOS version being installed before the user completes enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today, Intune can manage macOS software updates after enrollment using Declarative Device Management software update policies. However, that does not fully solve the issue where the Mac starts ADE on an older macOS version. In that case, the device may begin Setup Assistant and Platform SSO registration before the required macOS version is installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I am looking for is an Intune-native equivalent of enforcing a minimum or target macOS version during ADE, before Setup Assistant continues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ideally, the macOS ADE enrollment profile in Intune would support options such as:&lt;/P&gt;&lt;P&gt;- Minimum required macOS version&lt;/P&gt;&lt;P&gt;- Target specific macOS version&lt;/P&gt;&lt;P&gt;- Target specific build, if supported&lt;/P&gt;&lt;P&gt;- Latest eligible macOS version for the device&lt;/P&gt;&lt;P&gt;- Apply the OS update before Platform SSO registration and final configuration&lt;/P&gt;&lt;P&gt;- Reporting in Intune showing whether the ADE OS update was required, started, completed, skipped, or failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Without this capability, organizations using Intune-only macOS deployment may still need manual IT staging or macOS restore/update before handing devices to users. This weakens the zero-touch deployment model, especially when adopting Platform SSO registration during Automated Device Enrollment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Is there currently any supported way in Intune to enforce a minimum or target macOS version during ADE before Setup Assistant continues?&lt;/P&gt;&lt;P&gt;2. Is this capability on the Intune roadmap?&lt;/P&gt;&lt;P&gt;3. Are there any recommended workarounds for organizations deploying Platform SSO registration during ADE where a specific macOS version is required?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any guidance from the Intune team or the community.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2026 20:56:14 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530</guid>
      <dc:creator>KacperM</dc:creator>
      <dc:date>2026-06-04T20:56:14Z</dc:date>
    </item>
    <item>
      <title>8 hour wait time for Intune when "Configuring team site libraries to sync automatically"</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/8-hour-wait-time-for-intune-when-quot-configuring-team-site/m-p/4524954#M23527</link>
      <description>&lt;P&gt;I hate this, we dont want to wait for this long to find out it doesnt work because we forgot a curly bracket!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fix this or give us a solution to manually push this config policy out so we can see it working immediately!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;More exclamation marks!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 21:54:41 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/8-hour-wait-time-for-intune-when-quot-configuring-team-site/m-p/4524954#M23527</guid>
      <dc:creator>bdenison</dc:creator>
      <dc:date>2026-06-02T21:54:41Z</dc:date>
    </item>
    <item>
      <title>Intune App inventory Graph</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-app-inventory-graph/m-p/4524828#M23524</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've enabled the configuration profile to receive app inventory data in Intune.&lt;/P&gt;&lt;P&gt;In the GUI the data I can view the data just fine, but I would like to use Graph to automate this data and create custom reports.&lt;/P&gt;&lt;P&gt;When I use the following &lt;A class="lia-external-url" href="https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties')" target="_blank"&gt;https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties')&lt;/A&gt; I get an error: &lt;EM&gt;"Forbidden - 403 - 199 ms Either the signed-in user does not have sufficient privileges, or you need to consent to one of the permissions on the Modify permissions tab"&lt;/EM&gt; even though the docs I can find about permissions are OK.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2026 12:46:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-app-inventory-graph/m-p/4524828#M23524</guid>
      <dc:creator>RobV</dc:creator>
      <dc:date>2026-06-02T12:46:44Z</dc:date>
    </item>
    <item>
      <title>Add Security Key Support to Microsoft Authenticator and Managed Home Screen</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/add-security-key-support-to-microsoft-authenticator-and-managed/m-p/4524037#M23511</link>
      <description>undefined</description>
      <pubDate>Fri, 29 May 2026 13:57:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/add-security-key-support-to-microsoft-authenticator-and-managed/m-p/4524037#M23511</guid>
      <dc:creator>AbeSummers</dc:creator>
      <dc:date>2026-05-29T13:57:01Z</dc:date>
    </item>
    <item>
      <title>Edge displays a splash screen saying ‘Sign in to sync your data’</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-displays-a-splash-screen-saying-sign-in-to-sync-your-data/m-p/4523908#M23510</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;When the user logs in to a device for the first time and launches Edge, the following splash screen appears, even though we have created the Intune configuration below, which is intended to prevent this.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have following Intune configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;Why does the splash screen still appear?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2026 08:59:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-displays-a-splash-screen-saying-sign-in-to-sync-your-data/m-p/4523908#M23510</guid>
      <dc:creator>staeheli</dc:creator>
      <dc:date>2026-05-29T08:59:51Z</dc:date>
    </item>
    <item>
      <title>Broken functionality of macOSWiFiConfiguration policies</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/broken-functionality-of-macoswificonfiguration-policies/m-p/4523591#M23507</link>
      <description>&lt;P&gt;I'm having trouble accessing macOSWiFiConfiguration policies. They are completely inaccessible via the Intune admin portal (no actual data is displayed) and the Microsoft Graph API. When using Graph (/beta/deviceManagement/deviceConfigurations or with policyId) an InternalServerError is returned mid-response, resulting in a truncated and malformed body. This error indicates that the 'wifiRequirePhysicalMacAddressEnabled' property (type Edm.Boolean, Nullable = False) has a null value stored in the back end. The policy also fails to load in the Intune which I suspect is caused by the same underlying issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR DETAILS:&lt;/P&gt;&lt;P&gt;Endpoint: GET https://graph.microsoft.com/beta/deviceManagement/deviceConfigurations/{policy-id}&lt;/P&gt;&lt;P&gt;Error code: InternalServerError&lt;/P&gt;&lt;P&gt;Error message: "The property 'wifiRequirePhysicalMacAddressEnabled[Nullable=False]' of type 'Edm.Boolean' has a null value, which is not allowed."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;STEPS TO REPRODUCE:&lt;/P&gt;&lt;P&gt;1. Create a macOSWiFiConfiguration policy in the Intune admin portal. Additional note: front end will attempt to create the policy multiple times (around 20), even though the back end responds with a 201 HTTP code.&lt;/P&gt;&lt;P&gt;2. Try to GET the policy via Graph API (returns InternalServerError with malformed JSON body) or retrieve it using the WebUI (no data is shown).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EXPECTED BEHAVIOR:&lt;/P&gt;&lt;P&gt;The policy should be retrievable via Graph API and visible in the Intune admin portal. The property wifiRequirePhysicalMacAddressEnabled should hold a valid boolean value (true or false).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ACTUAL BEHAVIOR:&lt;/P&gt;&lt;P&gt;Failed to retrieve policy through Graph API and Intune WebUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else encountered this issue? Does anyone know how can I report this directly to Microsoft? All the options I have found lead me to AI chatbots which unfortunately are not helpful at all.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2026 11:07:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/broken-functionality-of-macoswificonfiguration-policies/m-p/4523591#M23507</guid>
      <dc:creator>MikolajKornas</dc:creator>
      <dc:date>2026-05-28T11:07:01Z</dc:date>
    </item>
    <item>
      <title>Is monthly BIOS updates via Intune overkill for enterprise Windows 11</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/is-monthly-bios-updates-via-intune-overkill-for-enterprise/m-p/4521736#M23477</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;Looking for some opinions from others managing BIOS and Drivers on enterprise environments.&lt;/P&gt;&lt;P&gt;We’re considering pushing BIOS/firmware updates monthly across our Windows 11 fleet using Intune, but it feels a bit too aggressive.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is anyone actually doing BIOS updates this frequently?&lt;/LI&gt;&lt;LI&gt;Do you see real risk in not updating BIOS regularly?&lt;/LI&gt;&lt;LI&gt;Or do you treat BIOS updates more as “only when needed” (security issue / vendor recommendation)?&lt;/LI&gt;&lt;LI&gt;Any issues you’ve run into pushing BIOS updates at scale via Intune?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;My concern is stability risk vs actual security benefit — feels like monthly might be overkill unless there’s a critical vulnerability.&lt;/P&gt;&lt;P&gt;Keen to hear how others are handling this in production environments.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2026 04:28:42 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/is-monthly-bios-updates-via-intune-overkill-for-enterprise/m-p/4521736#M23477</guid>
      <dc:creator>ER2025</dc:creator>
      <dc:date>2026-05-21T04:28:42Z</dc:date>
    </item>
    <item>
      <title>MS InTune - packaging Amazon DCV client</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/ms-intune-packaging-amazon-dcv-client/m-p/4519339#M23446</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I used the InTune prep tool to bundle the Amazon DCV client.&amp;nbsp; Everything seems to work correctly, bundle created and it uploads well.&amp;nbsp; When I use the company portal to install, it looks like it pushes\installs properly but the DCV client does not run on the laptop after install.&amp;nbsp; This is a .msi package so all the settings are in place when i create the InTune APP in the portal.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone succesfully bundled DCV in InTune?&lt;/P&gt;&lt;P&gt;Am I missing anything?&amp;nbsp; or anything to try?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2026 14:01:55 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/ms-intune-packaging-amazon-dcv-client/m-p/4519339#M23446</guid>
      <dc:creator>learnazure_ad</dc:creator>
      <dc:date>2026-05-13T14:01:55Z</dc:date>
    </item>
    <item>
      <title>Retrieving the “Device inventory” of iOS devices via the Graph API</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/retrieving-the-device-inventory-of-ios-devices-via-the-graph-api/m-p/4519225#M23445</link>
      <description>&lt;P&gt;We use Microsoft Intune to manage our iOS mobile devices.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;To achieve the highest possible level of efficiency, we use PowerShell as a supplementary tool for administration.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since our devices may contain two SIM cards, it is important for us to be able to read this information in order to perform relevant processes (e.g., adding phone numbers to address books).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In general, it would be desirable to be able to read the information from the “Device Inventory” of iOS devices.&lt;BR /&gt;For the reasons mentioned above, we would like this information to be made available via the Graph API. Alternatively, there should be a way to provide this information for all devices in a single report.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2026 08:46:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/retrieving-the-device-inventory-of-ios-devices-via-the-graph-api/m-p/4519225#M23445</guid>
      <dc:creator>ATroester</dc:creator>
      <dc:date>2026-05-13T08:46:36Z</dc:date>
    </item>
    <item>
      <title>BYOD devices can't launch Windows 365 PC because of device compliance check during CA policy check.</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/byod-devices-can-t-launch-windows-365-pc-because-of-device/m-p/4518584#M23436</link>
      <description>&lt;P&gt;We have a device compliance policy for all cloud apps. We would like to allow personal (BYOD) devices to be able to connect to Windows 365 Cloud PC. In the sign in logs we see the failures for application "Windows 365 Client" app id 4fb5cc57-dbbc-4cdc-9595-748adff5f414. We can't exclude that application in the conditional access policy as it's not available. We already added exclusions for&amp;nbsp;Azure Virtual Desktop, Windows 365 and Windows Cloud Login.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we allow BYOD devices to connect to cloud PCs?&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 19:33:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/byod-devices-can-t-launch-windows-365-pc-because-of-device/m-p/4518584#M23436</guid>
      <dc:creator>wcaetano</dc:creator>
      <dc:date>2026-05-11T19:33:33Z</dc:date>
    </item>
    <item>
      <title>Policy applied allthough it shouldn't</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/policy-applied-allthough-it-shouldn-t/m-p/4516937#M23417</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;all of a sudden Intune chaanges its behavior. I have a policy in place that sets persistent browser session. On the device filter tab I excluded devices with this syntax:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang=""&gt;device.trustType -eq "ServerAD" -or device.deviceOwnership -eq "Company"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting last week I have to re-authenticate on a remote Desktop running Windows Server 2025 every 8 hours. Thats what the policy requires. In Entra I see in the logs for my user that this conditional access policy applied. I then extended the filter to this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang=""&gt;device.trustType -eq "ServerAD" -or device.deviceOwnership -eq "Company" -or device.operatingSystem -contains "Server"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it did not make a difference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what is going? This is not specific to my tenant. On a different tenant it behaves the same way.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2026 05:52:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/policy-applied-allthough-it-shouldn-t/m-p/4516937#M23417</guid>
      <dc:creator>heinzelrumpel</dc:creator>
      <dc:date>2026-05-05T05:52:11Z</dc:date>
    </item>
    <item>
      <title>App Enforced Restrictions not working on Chrome</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/app-enforced-restrictions-not-working-on-chrome/m-p/4516309#M23409</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;Anyway, a strange one here.&lt;/P&gt;&lt;P&gt;We have implemented App Enforced Restrictions on unmanaged / BYOD macOS devices.&lt;/P&gt;&lt;P&gt;This seems to have taken effect on Edge and Safari browsers but not Chrome.&lt;/P&gt;&lt;P&gt;Is there anything we can do to resolve this or force BYOD macOS to use Edge?&lt;/P&gt;&lt;P&gt;Info appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 18:14:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/app-enforced-restrictions-not-working-on-chrome/m-p/4516309#M23409</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-04-30T18:14:53Z</dc:date>
    </item>
    <item>
      <title>Reporting on Device CPU and Memory</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/reporting-on-device-cpu-and-memory/m-p/4515752#M23402</link>
      <description>&lt;P&gt;I have a requirement to produce a monthly report on all our Intune managed Windows devices and the applications they have installed.&amp;nbsp; I have written a script that is able to report on UPN, Device Name, Manufacturer, Model, Serial Number, OS, Total HHD and Free space along with all the applications installed.&amp;nbsp; I am however unable to output the devices CPU and Memory details.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried using the Get-MgBetaDeviceManagementManagedDevices with the ProcessorArchitecture and PhysicalMemoryInBytes parameters but these just report 0 or NULL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the best way to report on the CPU and Memory from Intune?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 07:31:50 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/reporting-on-device-cpu-and-memory/m-p/4515752#M23402</guid>
      <dc:creator>StuartW</dc:creator>
      <dc:date>2026-04-29T07:31:50Z</dc:date>
    </item>
    <item>
      <title>Protect org data on BYOD Windows / macOS devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/protect-org-data-on-byod-windows-macos-devices/m-p/4514964#M23387</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;Anyway, I have a need to protect org data on:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Window personal / BYOD devices&lt;/LI&gt;&lt;LI&gt;MacOS personal&amp;nbsp; / BYOD devices&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What's the best way to achieve this?&lt;/P&gt;&lt;P&gt;My thinking is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;1 X Conditional Access policy that blocks&lt;/LI&gt;&lt;LI&gt;1 X Conditional Access policy that allows via Edge, no persistent session, no downloads etc&lt;/LI&gt;&lt;LI&gt;Device filter on both policies that target unmanaged devices&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2026 07:38:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/protect-org-data-on-byod-windows-macos-devices/m-p/4514964#M23387</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-04-27T07:38:28Z</dc:date>
    </item>
    <item>
      <title>Best approach for migrating AD joined devices to Entra ID without wiping user profiles?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/best-approach-for-migrating-ad-joined-devices-to-entra-id/m-p/4514425#M23382</link>
      <description>&lt;P&gt;We’ve seen many organizations struggle with device migration when moving from traditional Active Directory (AD) or hybrid environments to Microsoft Entra ID.&lt;/P&gt;&lt;P&gt;The biggest challenge is avoiding user disruption especially when wiping devices causes profile loss, app reconfiguration, and downtime.&lt;/P&gt;&lt;P&gt;In large environments, wipe-and-reload becomes difficult to scale and impacts productivity significantly.&lt;/P&gt;&lt;P&gt;Curious to know how others are handling this:&lt;/P&gt;&lt;P&gt;Are you still using wipe/reimage methods, or are you using alternative approaches that preserve user profiles, applications, and settings?&lt;/P&gt;&lt;P&gt;Would love to hear practical experiences from the community.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 08:12:47 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/best-approach-for-migrating-ad-joined-devices-to-entra-id/m-p/4514425#M23382</guid>
      <dc:creator>Pranavsethuraman10</dc:creator>
      <dc:date>2026-04-24T08:12:47Z</dc:date>
    </item>
    <item>
      <title>Autopilot V1 vs “Device Preparation” (V2): Great direction — but is it enterprise-ready yet?</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-v1-vs-device-preparation-v2-great-direction-but-is-it/m-p/4514362#M23381</link>
      <description>&lt;P&gt;We evaluated &lt;STRONG&gt;Autopilot v2&lt;/STRONG&gt; but decided to stay on &lt;STRONG&gt;Autopilot v1&lt;/STRONG&gt; for large‑enterprise scale.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Group Tags + dynamic groups&lt;/STRONG&gt; are still essential for our device naming, segmentation, and governance model.&lt;/P&gt;&lt;P&gt;We intentionally limit apps in EAS to speed up provisioning, so EAS‑based app deployment in v2 isn’t a compelling advantage for us.&lt;/P&gt;&lt;P&gt;v2 looks promising, but until there’s stronger parity for &lt;STRONG&gt;enterprise‑scale targeting and naming&lt;/STRONG&gt;, v1 remains the better fit.&lt;/P&gt;&lt;P&gt;Curious how others at scale are balancing provisioning speed vs. segmentation without Group Tags.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2026 06:39:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-v1-vs-device-preparation-v2-great-direction-but-is-it/m-p/4514362#M23381</guid>
      <dc:creator>christiandominguezjp</dc:creator>
      <dc:date>2026-04-24T06:39:18Z</dc:date>
    </item>
    <item>
      <title>Autopatch - Microsoft 365 Apps Update Rings</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-microsoft-365-apps-update-rings/m-p/4513986#M23376</link>
      <description>&lt;P&gt;I’m trying to understand how the&amp;nbsp;UpdateDeferredVersions&amp;nbsp;registry value is updated in an Intune Autopatch scenario, specifically the&amp;nbsp;&lt;STRONG&gt;version and FileTime values&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Registry path:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;HKLM\SOFTWARE\Microsoft\Office\ClickToRun\Updates&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Example value:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;UpdateDeferredVersions = 16.0.19725.20170:13420719560293 | 16.0.19822.20180:13421142577563&lt;/P&gt;&lt;P&gt;I’ve observed the following and would appreciate any clarification:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When I modify&amp;nbsp;&lt;STRONG&gt;deadline or deferral settings&lt;/STRONG&gt;&amp;nbsp;via Autopatch (policy changes), the&amp;nbsp;&lt;STRONG&gt;FileTime value does not update&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;Is there a&amp;nbsp;&lt;STRONG&gt;delay or specific trigger&lt;/STRONG&gt;&amp;nbsp;(e.g., policy refresh, scheduled task, CDN sync) that updates this FileTime?&lt;/LI&gt;&lt;LI&gt;How exactly is this&amp;nbsp;&lt;STRONG&gt;FileTime calculated&lt;/STRONG&gt;? Is it tied to when the build was released, assigned, or when the policy was applied?&lt;/LI&gt;&lt;LI&gt;Is there any&amp;nbsp;&lt;STRONG&gt;supported way to force or influence&lt;/STRONG&gt;&amp;nbsp;this FileTime update?&lt;/LI&gt;&lt;LI&gt;Or is this value simply tracking when the&amp;nbsp;&lt;STRONG&gt;build cap was issued&lt;/STRONG&gt;, with deferral logic calculated relative to that timestamp?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Additionally, I’ve noticed that updates only seem to apply when the FileTime is approximately&amp;nbsp;&lt;STRONG&gt;4 days behind the current date,&lt;/STRONG&gt; is this expected behavior with Autopatch deferral logic? I was able to successfully test this updating FileTime 4 days behind ((Get-Date).AddDays(-4)).ToFileTime().&lt;/P&gt;&lt;P&gt;Any insights into how this mechanism works under the hood (especially with Click-to-Run + Autopatch interaction) would be really helpful.&lt;/P&gt;&lt;P&gt;Below is Autopatch group settings for Microsoft 365 update rings that we set in our environment:&lt;/P&gt;&lt;P&gt;Test - Deferral 0 - Deadline 0&lt;/P&gt;&lt;P&gt;Ring 1 - Deferral 1 - Deadline 0&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ring 2 - Deferral 2 - Deadline 0&lt;/P&gt;&lt;P&gt;Last - Deferral 4 - Deadline 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2026 10:49:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-microsoft-365-apps-update-rings/m-p/4513986#M23376</guid>
      <dc:creator>PaulJebastin</dc:creator>
      <dc:date>2026-04-23T10:49:32Z</dc:date>
    </item>
  </channel>
</rss>

