<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>Microsoft Intune topics</title>
    <link>https://techcommunity.microsoft.com/t5/microsoft-intune/bd-p/Microsoft-Intune</link>
    <description>Microsoft Intune topics</description>
    <pubDate>Fri, 06 Mar 2026 07:21:24 GMT</pubDate>
    <dc:creator>Microsoft-Intune</dc:creator>
    <dc:date>2026-03-06T07:21:24Z</dc:date>
    <item>
      <title>Erweiterungsmanagement im Browser</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/erweiterungsmanagement-im-browser/m-p/4499632#M23257</link>
      <description>&lt;P&gt;We would like to distribute browser extensions in Edge via Intune in a granular manner.&lt;/P&gt;&lt;P&gt;The problem is that assigning two profiles with different extensions leads to a conflict. We would like to be able to assign extensions individually and assign multiple different profiles with different browser extensions to a user.&lt;/P&gt;&lt;P&gt;With the current options, it becomes very complex and error-prone when there are multiple extensions with different user groups.&lt;/P&gt;&lt;P&gt;Or have I overlooked a possibility?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 07:13:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/erweiterungsmanagement-im-browser/m-p/4499632#M23257</guid>
      <dc:creator>Regine147</dc:creator>
      <dc:date>2026-03-05T07:13:49Z</dc:date>
    </item>
    <item>
      <title>How to create a dependency using Graph API in PowerShell</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-create-a-dependency-using-graph-api-in-powershell/m-p/4498988#M23253</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I used following documentations to create a dependency via Graph API in Powershell:&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/graph/api/intune-apps-mobileappdependency-list?view=graph-rest-beta" target="_blank"&gt;https://learn.microsoft.com/en-us/graph/api/intune-apps-mobileappdependency-list?view=graph-rest-beta&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.beta.devices.corporatemanagement/new-mgbetadeviceappmanagementmobileapprelationship?view=graph-powershell-beta" target="_blank"&gt;https://learn.microsoft.com/en-us/powershell/module/microsoft.graph.beta.devices.corporatemanagement/new-mgbetadeviceappmanagementmobileapprelationship?view=graph-powershell-beta&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Both ways give me the same error:&lt;/P&gt;&lt;P&gt;New-MgBetaDeviceAppMgtMobileAppRelationship : No OData route exists that match template ~/singleton/navigation with http verb POST for request /AppLifecycle_2602/StatelessAppMetadataFEService/deviceAppManagement/mobileAppRelationships.&lt;BR /&gt;Status: 400 (BadRequest)&lt;BR /&gt;ErrorCode: No method match route template&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems like these Endpoints do not support POST/PATCH requests at all. Is there any other way to create a dependency using Graph API in PowerShell?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 09:10:51 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-create-a-dependency-using-graph-api-in-powershell/m-p/4498988#M23253</guid>
      <dc:creator>DamianIntune</dc:creator>
      <dc:date>2026-03-03T09:10:51Z</dc:date>
    </item>
    <item>
      <title>Block Local Logon to enrolling user of an Intune Managed Device</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/block-local-logon-to-enrolling-user-of-an-intune-managed-device/m-p/4498480#M23250</link>
      <description>&lt;P&gt;Has anyone successfully managed to deploy a security baseline template or Configuration profile or proactive remediation script that can successfully block any AAD user from being able to logon to an Intune managed device, other than the user who enrolled the device?&lt;/P&gt;&lt;P&gt;I have a use case of an industutrial type device where we use a secure shared logon credential who is also the enrolling user, and i want to prevent anyone with an account loggin goff the primary&amp;nbsp; user account and loggingin with their own personal account.&lt;/P&gt;&lt;P&gt;The issue i seems to face now is the policy is not able to evaluate the AAD group where i assign the user account/accounts allowed to logon, and i subsequently end up blocking all local logons.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2026 13:41:56 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/block-local-logon-to-enrolling-user-of-an-intune-managed-device/m-p/4498480#M23250</guid>
      <dc:creator>Chris Snell</dc:creator>
      <dc:date>2026-03-02T13:41:56Z</dc:date>
    </item>
    <item>
      <title>Will Intune device-only subscription get additional value in FY27</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/will-intune-device-only-subscription-get-additional-value-in/m-p/4495898#M23240</link>
      <description>&lt;P&gt;Will the Intune device-only subscription (&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-intune-announces-device-only-subscription-for-shared-resources/280817" target="_blank"&gt;Microsoft Intune announces device-only subscription for shared resources | Microsoft Community Hub&lt;/A&gt;) get the additional features which Intune P1 will get in FY27 (&lt;A href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272" target="_blank"&gt;Microsoft 365 adds advanced Microsoft Intune solutions at scale - Microsoft Intune Blog&lt;/A&gt;), Intune Remote Help, Intune Advanced Analytics and Intune P2?&lt;/P&gt;&lt;P&gt;This would have a huge impact of our planning how to manage special purpose devices in production environments without any user affinity. Deploying security and configuration settings, Windows Autopilot for Windows IoT Enterprise LTSC kiosk deployment, Windows Autopatch (servicing), Remote Help and FOTA for Zebra devices would be drivers to add these production devices to Intune.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2026 15:07:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/will-intune-device-only-subscription-get-additional-value-in/m-p/4495898#M23240</guid>
      <dc:creator>ATEdeBer</dc:creator>
      <dc:date>2026-02-19T15:07:11Z</dc:date>
    </item>
    <item>
      <title>How to Disable Self-Service Passcode Reset for Standard Users in Microsoft Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-disable-self-service-passcode-reset-for-standard-users-in/m-p/4495577#M23238</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using Microsoft Intune to manage Android corporate-owned devices. Currently, standard users can reset their own device passcode remotely. The problem is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Users reset the passcode themselves&lt;/LI&gt;&lt;LI&gt;Then they get confused&lt;/LI&gt;&lt;LI&gt;They call IT saying they cannot open their phone&lt;/LI&gt;&lt;/UL&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want to prevent users from doing self-service passcode reset. Only admin should be able to reset the device passcode. I already checked configuration profiles and compliance policies in Intune, but I cannot find any setting to disable this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone successfully disabled this feature?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 07:17:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/how-to-disable-self-service-passcode-reset-for-standard-users-in/m-p/4495577#M23238</guid>
      <dc:creator>tarunograa29</dc:creator>
      <dc:date>2026-02-18T07:17:18Z</dc:date>
    </item>
    <item>
      <title>Edge for Android Smartscreen</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-for-android-smartscreen/m-p/4495038#M23227</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, is it possible to configure Edge for Android Smartscreen to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Prevent end user bypass&lt;/LI&gt;&lt;LI&gt;Block potential risky downloads&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I can see various methods and guides pointing to Edge App Configuration policies but just cannot seem to get the this to work on Android Enterprise Fully Managed devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SK&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2026 05:50:03 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/edge-for-android-smartscreen/m-p/4495038#M23227</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-02-15T05:50:03Z</dc:date>
    </item>
    <item>
      <title>Intune - ASR Rules - exclusion</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-asr-rules-exclusion/m-p/4494800#M23221</link>
      <description>&lt;P&gt;Hello, please can anybody give me an advice about Intune exception? We are using N-Able client for computer management and Intune ASR is blocking it. I tried to add exception in rule setting but it has not helped so far.&lt;/P&gt;&lt;P&gt;I am getting defender popup with info that&amp;nbsp;&lt;/P&gt;&lt;P&gt;risky action blocked&lt;/P&gt;&lt;P&gt;Your admin blocker this action.&lt;/P&gt;&lt;P&gt;Blocked app or process - winagent.exe&lt;/P&gt;&lt;P&gt;Blocked by - surface attack reduction&lt;/P&gt;&lt;P&gt;Rule - Block using of copied or personified system tools.&lt;/P&gt;&lt;img /&gt;&lt;P&gt;There is my exception but it did not helped.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 13:16:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-asr-rules-exclusion/m-p/4494800#M23221</guid>
      <dc:creator>Jendislav</dc:creator>
      <dc:date>2026-02-13T13:16:01Z</dc:date>
    </item>
    <item>
      <title>Help creating Device groups</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/help-creating-device-groups/m-p/4494774#M23220</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm new to using Intune on a day to day basis, after adding our devices to Intune via our On-prem Active Directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the best practice for organizing our Devices, such as Staff devices and Student devices?&lt;/P&gt;&lt;P&gt;I want to create a group for all staff devices and another for student devices.&lt;/P&gt;&lt;P&gt;Also, is there any way to auto enroll these pcs in to the correct groups once they're new ones added via our on Prem AD and Entra?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 10:25:44 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/help-creating-device-groups/m-p/4494774#M23220</guid>
      <dc:creator>MaxRebo</dc:creator>
      <dc:date>2026-02-13T10:25:44Z</dc:date>
    </item>
    <item>
      <title>Replacing Complex GPO Item-Level Targeting with Intune</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/replacing-complex-gpo-item-level-targeting-with-intune/m-p/4494722#M23219</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I’m looking for some advice on the best way to handle this scenario.&lt;/P&gt;&lt;P&gt;We’re running a hybrid environment and currently have a GPO that creates 1,000+ registry entries across 150+ user groups using item-level targeting with security groups.&lt;/P&gt;&lt;P&gt;Now we need to move this over to Intune, and that’s where things get tricky. Intune doesn’t really offer the same item-level targeting flexibility as GPO. So far, the only workable option seems to be creating 150+ platform scripts or Proactive Remediation scripts, which obviously isn’t ideal from a management perspective.&lt;/P&gt;&lt;P&gt;I’m thinking it might be much easier long-term to create one large PowerShell script that checks the logged-in user’s group membership and then applies the appropriate registry settings dynamically.&lt;/P&gt;&lt;P&gt;Has anyone dealt with something similar? Is there a cleaner or more scalable approach in Intune?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Dilan&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 02:58:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/replacing-complex-gpo-item-level-targeting-with-intune/m-p/4494722#M23219</guid>
      <dc:creator>dilanmic</dc:creator>
      <dc:date>2026-02-13T02:58:17Z</dc:date>
    </item>
    <item>
      <title>Controlling Excel Add-ins and Microsoft Store App Installations</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/controlling-excel-add-ins-and-microsoft-store-app-installations/m-p/4494654#M23218</link>
      <description>&lt;P&gt;We have a requirement to block users from adding add-ins to Excel and Installing certain application directly which utilize Microsoft Store apps. Below are the two scenarios we need to address. I would appreciate any guidance or recommendations on how to implement these controls.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) Blocking Excel Add-ins from Microsoft Store&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Users are currently able to add add-ins such as “Claude by Anthropic in Excel” directly from the Microsoft Store apps. For example, if a user accesses the URL: https://marketplace.microsoft.com/en-us/product/saas/wa200009404?tab=overview they can proceed to add the add-in to Excel.&lt;/P&gt;&lt;P&gt;So, We need a method to prevent users from adding Office add-ins from the Microsoft Marketplace or external sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) Blocking Installation of Microsoft Store Apps (e.g., WhatsApp)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We are currently blocking Microsoft Store apps on OS level. However, users can still download and install applications such as WhatsApp directly from the vendor website, which utilize Microsoft store apps in backend: https://www.whatsapp.com/download&lt;/P&gt;&lt;P&gt;We are considering configuring the Intune policy “Only Private Store is enabled.” However, we noticed that enabling this setting prevents users from accessing certain built-in applications (e.g., Notepad). Is there any other way to block access Microsoft Store apps directly?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your assistance.&lt;/P&gt;&lt;P&gt;Dilan&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 19:25:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/controlling-excel-add-ins-and-microsoft-store-app-installations/m-p/4494654#M23218</guid>
      <dc:creator>dilanmic</dc:creator>
      <dc:date>2026-02-12T19:25:40Z</dc:date>
    </item>
    <item>
      <title>Creating a successful intune deployment using an installer exe combine with XML configuration file.</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/creating-a-successful-intune-deployment-using-an-installer-exe/m-p/4494601#M23217</link>
      <description>&lt;P&gt;I am having issue creating a successful intune deployment package involving MathCad Prime 11 and XML file, this might be cause my powershell scripting is very weak.&lt;BR /&gt;&lt;BR /&gt;This is the current script I am trying to used, but it does not seem to deploy successfully, the errors I am seeing from intune is "The unmonitored process is in progress, however it may timeout. (0x87D300C9)."&lt;BR /&gt;&lt;BR /&gt;Perhaps someone has come across this and point me in the right direction on how to handle installer with exe and using XML for configuration.&lt;BR /&gt;&lt;BR /&gt;"&lt;/P&gt;&lt;P&gt;# Get the current script directory to locate setup.xml&lt;/P&gt;&lt;P&gt;$CurrentDir = $PSScriptRoot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Define the installer path and the XML argument file&lt;/P&gt;&lt;P&gt;$ExePath = Join-Path -Path $CurrentDir -ChildPath "setup.exe"&lt;/P&gt;&lt;P&gt;$XmlPath = Join-Path -Path $CurrentDir -ChildPath "mathcad.p.xml"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Adobe command-line parameters for silent installation with a deployment file&lt;/P&gt;&lt;P&gt;$Arguments = "--mode=silent --deploymentFile=`"$XmlPath`""&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Start the installation process and wait for completion&lt;/P&gt;&lt;P&gt;$Process = Start-Process -FilePath $ExePath -ArgumentList $Arguments -Wait -PassThru&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Return the exit code to Intune (0 is success)&lt;/P&gt;&lt;P&gt;Exit $Process.ExitCode&lt;BR /&gt;&lt;BR /&gt;"&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2026 15:25:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/creating-a-successful-intune-deployment-using-an-installer-exe/m-p/4494601#M23217</guid>
      <dc:creator>XSupramanX</dc:creator>
      <dc:date>2026-02-12T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Autopilot enrollment through serial number</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-enrollment-through-serial-number/m-p/4494450#M23214</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;PRE&gt;I’m working for a reseller, and one of my customers has asked us to enroll their device&amp;nbsp;&lt;STRONG&gt;serial numbers&lt;/STRONG&gt; into their Intune/Autopilot tenant.&lt;BR /&gt;We &lt;STRONG&gt;only have permission to upload devices&lt;/STRONG&gt; because we are &lt;EM&gt;not&lt;/EM&gt; their CSP partner.&lt;BR /&gt;&lt;BR /&gt;Now the customer wants us to enroll the devices, &lt;STRONG&gt;including their Purchase Order (PO) number,&lt;/STRONG&gt; in the &lt;STRONG&gt;Purchase Order&lt;/STRONG&gt; field in Intune.&lt;BR /&gt;&lt;BR /&gt;The issue is:&lt;BR /&gt;Because we are &lt;EM&gt;not&lt;/EM&gt; their CSP, the tenant does &lt;STRONG&gt;not allow us to enter or modify the Purchase Order field&lt;/STRONG&gt; when we upload devices.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;My question:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Is it possible for a non‑CSP reseller or partner to add a Purchase Order number during Autopilot device enrollment?&lt;/STRONG&gt;&lt;BR /&gt;If not, what options exist for a reseller to ensure that the Purchase Order field is populated?&lt;/PRE&gt;</description>
      <pubDate>Wed, 11 Feb 2026 21:21:57 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-enrollment-through-serial-number/m-p/4494450#M23214</guid>
      <dc:creator>HarisNadeem1</dc:creator>
      <dc:date>2026-02-11T21:21:57Z</dc:date>
    </item>
    <item>
      <title>Unmanaged Microsoft 365 Applications in Intune-Managed Windows 11 Devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/unmanaged-microsoft-365-applications-in-intune-managed-windows/m-p/4494358#M23208</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;We have identified in our Intune environment that several users have installed Microsoft 365 applications outside of Intune on their managed Windows 11 devices (Corporate).&lt;/P&gt;&lt;P&gt;Could you please confirm whether these users receive configuration profiles (for Microosft 365 app update enforcement for example)?&lt;/P&gt;&lt;P&gt;Additionally, we would appreciate guidance on the best practices for addressing unmanaged application replacements.&lt;/P&gt;&lt;P&gt;Thank you for your assistance. :)&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 15:14:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/unmanaged-microsoft-365-applications-in-intune-managed-windows/m-p/4494358#M23208</guid>
      <dc:creator>Ibteea</dc:creator>
      <dc:date>2026-02-11T15:14:23Z</dc:date>
    </item>
    <item>
      <title>Configure the Device with Microsoft Entra Hybrid Joined</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/configure-the-device-with-microsoft-entra-hybrid-joined/m-p/4494263#M23207</link>
      <description>&lt;P&gt;Hi, Can you share the best practices to configure the device with Microsoft Entra Hybrid Joined. Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Feb 2026 05:01:36 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/configure-the-device-with-microsoft-entra-hybrid-joined/m-p/4494263#M23207</guid>
      <dc:creator>harpreet-singh-him</dc:creator>
      <dc:date>2026-02-11T05:01:36Z</dc:date>
    </item>
    <item>
      <title>Entra Shared Mode - Force App Stop</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/entra-shared-mode-force-app-stop/m-p/4493979#M23206</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I hope you are well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway, I was asked this yesterday and think I already might know the answer, but here goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had an instance of Microsoft Excel stuck in "getting things ready" on an Android Entra Shared Mode Device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Technical Support wondered if there was a way to Force Stop Excel or clear the app data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had a look in Exit Kiosk Mode, Android Settings, and the Force Stop of Excel said "Action not allowed" and the clear the app data said "Unable to delete data for app"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, my question(s) would be, is going into Exit Kiosk Mode and even trying to force stop&amp;nbsp; / clear data on apps even a valid option, or is this by design?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would adding Excel to this setting help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or confirmation would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stuart&lt;/P&gt;</description>
      <pubDate>Mon, 09 Feb 2026 23:27:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/entra-shared-mode-force-app-stop/m-p/4493979#M23206</guid>
      <dc:creator>StuartK73</dc:creator>
      <dc:date>2026-02-09T23:27:15Z</dc:date>
    </item>
    <item>
      <title>Intune MAM BYOD: Remove Account message for iOS devices</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-mam-byod-remove-account-message-for-ios-devices/m-p/4493004#M23202</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing an issue for Intune MAM BYOD(iOS) users. After a user account password reset, it causes Intune to remove the account configured from mobile applications like MS Outlook, Work, OneDrive, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current Intune Configuration:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Done - App Protection Policy&amp;nbsp;&lt;/P&gt;&lt;P&gt;Done - Conditional access policy --&amp;gt; Grant --&amp;gt; Requires app protection policy (checked)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users had to re-enrol to access his/her data.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the screenshot,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P class="lia-clear-both"&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 07:35:18 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-mam-byod-remove-account-message-for-ios-devices/m-p/4493004#M23202</guid>
      <dc:creator>rahulc9222</dc:creator>
      <dc:date>2026-02-06T07:35:18Z</dc:date>
    </item>
    <item>
      <title>Windows Autopilot API</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-autopilot-api/m-p/4492943#M23200</link>
      <description>&lt;P&gt;Hello Members,&lt;/P&gt;&lt;P&gt;Is it possible to configure the Windows Autopilot API to generate the "skiptoken" based on a different attribute (such as a unique ID or a field guaranteed to be whitespace-free)?&lt;/P&gt;&lt;P&gt;Any info or pointers would be great.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Feb 2026 06:10:17 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/windows-autopilot-api/m-p/4492943#M23200</guid>
      <dc:creator>DarshilBhatt24</dc:creator>
      <dc:date>2026-02-06T06:10:17Z</dc:date>
    </item>
    <item>
      <title>Cannot enroll azure vm(windows 24H2) in Microsoft company portal</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-enroll-azure-vm-windows-24h2-in-microsoft-company-portal/m-p/4492046#M23188</link>
      <description>&lt;P&gt;I created a windows VM in Azure. To access company resources on this machine, I attempted to enroll the device through the Company Portal. However, the enrollment failed while setting up the work or school account, with the error message&amp;nbsp;&lt;STRONG&gt;“This connection isn’t secure.”&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;How should I fix this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Feb 2026 05:57:07 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/cannot-enroll-azure-vm-windows-24h2-in-microsoft-company-portal/m-p/4492046#M23188</guid>
      <dc:creator>yanxxu</dc:creator>
      <dc:date>2026-02-04T05:57:07Z</dc:date>
    </item>
    <item>
      <title>intune constantly tries to re-install Chrome everyday when it is already installed</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-constantly-tries-to-re-install-chrome-everyday-when-it-is/m-p/4491959#M23186</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have set Intune to install few applications including Google Chrome for users but Intune constantly tries to re-install Google Chrome everyday. What could be wrong with detection rule setting for Google Chrome and how to fix it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your assistance will be greatly appreciated!&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Sasan&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 21:25:00 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/intune-constantly-tries-to-re-install-chrome-everyday-when-it-is/m-p/4491959#M23186</guid>
      <dc:creator>Sasan29</dc:creator>
      <dc:date>2026-02-03T21:25:00Z</dc:date>
    </item>
    <item>
      <title>LAPS Intune policies</title>
      <link>https://techcommunity.microsoft.com/t5/microsoft-intune/laps-intune-policies/m-p/4491859#M23184</link>
      <description>&lt;P&gt;So it seems that there are legacy LAPS policies (via&amp;nbsp; Configuration/Policies/New/Windows 10/Settings catalog Search for LAPS = Administrative templates/LAPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, I did configure them &amp;amp; added my device group.&lt;/P&gt;&lt;P&gt;Then I realize that it is NOT this LAPS I need (by then quite few devices got the policy)&lt;/P&gt;&lt;P&gt;I unlinked the group, deleted this policy &amp;amp; created NEW LAPS policy via Endpoint Security/Account Protection/Create policy/Windows/Windows LAPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here I can setup new settings (especially Password Complexity = Passphrase)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While lots of my devices get the local admin password reset to correct Passphrase, there are quite a few that have complex password (leftover from previous attempt?)&amp;nbsp;&lt;/P&gt;&lt;P&gt;No matter what I do, I cannot get this local admin password changed to Passphrase&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how to get ALL the local admin passwords to be in same format?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Seb&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 13:19:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/microsoft-intune/laps-intune-policies/m-p/4491859#M23184</guid>
      <dc:creator>SebCerazy</dc:creator>
      <dc:date>2026-02-03T13:19:53Z</dc:date>
    </item>
  </channel>
</rss>

