intune
4466 TopicsAndroid Fully Managed devices treated as personal after AD password change
Hello! We have a huge problem... We have recently observed an issue in our organization affecting Android Fully Managed devices. After users change their domain password, within 1–3 days Conditional Access starts blocking access to Outlook and Teams. The system appears to treat the device as non-corporate, even though in Intune the device is still present, marked as corporate, and fully functional. It synchronizes both manually and automatically, and remote actions can be executed without any issues. However, when users open Outlook or Teams, they receive messages such as “We need to secure your device” and “Install the Intune app from Google Play,” which does not make sense because Intune is already installed on the device. When opening the Intune app, users see a “Update your password” prompt. After selecting it, they are redirected to a device registration screen. Previously, it was sometimes possible to complete this process (although we did not understand why it was required), but recently re-registration consistently fails. The user clicks “Register,” and the process spins indefinitely without completing. This issue is very difficult to troubleshoot. Device logs are not particularly helpful, and all users have Microsoft Authenticator configured. The problem appears randomly across users with no clear pattern—some devices were enrolled over a year ago, others just a month ago. The only clue we have found so far points to a potential issue with the broker authentication token, but we do not know how to verify or resolve this, nor why it is happening in the first place. We have been experiencing this issue since around January this year, but we noticed a significant increase in cases this month. In addition, there are more and more devices that can no longer be re‑registered from within the Intune app. Has anyone encountered a similar issue or can provide guidance on how to investigate or fix this?66Views0likes2CommentsAllow Teams desktop on unmanaged Windows, but block Outlook desktop using Entra conditional access
I need to allow Teams to run on non Intuned devices but not allow Outlook desktop to be available I am looking for a solution for Windows and Mac and ideally linux as well The issue is Ig I have Office 365 Exchange Online as my resource, it blocks Microsoft Team Services as well How can I fix this88Views1like2CommentsIntune Platform Scripts never target devices (0 targeted devices) despite healthy Intune environment
Hi everyone, I'm hoping someone has seen this before because I've exhausted most of the obvious troubleshooting. Environment Microsoft 365 Business Premium Windows 11 Pro Microsoft Intune Microsoft Entra ID Joined devices Intune Management Extension (IME) installed and healthy The Issue Platform Scripts never target any devices. Regardless of the script, assignment or device, the script always remains at: 0 Devices 0 Succeeded 0 Errors The device never appears under Device Status. What works The Intune environment is otherwise functioning normally. Configuration Profiles deploy successfully. Settings Catalog policies apply successfully. BitLocker policies apply. Windows Firewall policies apply. Windows LAPS is working. Win32 applications deploy successfully Devices are Entra Joined and managed by Intune. What I've tested To eliminate variables I created: Created a brand new PowerShell script that simply creates a text file. Created a brand new assigned Security Group containing a single Windows 11 device. Assigned only that Security Group to the Platform Script. The result is still: 0 Devices 0 Succeeded 0 Errors Device checks completed On the client: dsregcmd /status shows AzureAdJoined = YES. Intune Management Extension service is running. Win32 apps are deploying correctly. Intune Management Extension logs appear healthy. AgentExecutor.log contains WinGet application activity but no evidence of any Platform Script ever being downloaded or executed. The IntuneManagementExtension registry contains SideCarPolicies but there is no evidence of any PowerShell script policy being received. Additional observations I reproduced the issue on two separate Windows 11 devices. I reproduced the issue using both dynamic and assigned device groups. I reproduced the issue using different PowerShell scripts. This makes me believe the issue is not device specific. Question Has anyone seen Platform Scripts remain permanently at 0 targeted devices despite Intune otherwise functioning normally? Is there a known tenant-side issue, prerequisite or licensing requirement that would prevent Platform Scripts from ever targeting devices while Win32 apps and Configuration Profiles continue to work? Any suggestions would be appreciated.Solved129Views0likes5CommentsOutlook for iOS (MAM only Call Identification)
In order of the implementation of O365/M365 and with it Microsoft Intune, Outlook for iOS has become the standard mail client on iOS devices for many customers today. This is due to the excellent user experience and the constant stream of new features implemented by Microsoft. From a security perspective, in addition to the provision on managed devices (managed by Intune), the secure use on unmanaged devices with MAM or App Protection Policies (APP) is a big argument for using Outlook for iOS. Currently, many ouf our customers are working on a BYOD setup for blue collar worker, who typically have a maximum of one email inbox. A big pain point for many users who use Outlook for iOS in an MAM-only setup (and for MDM setup with Intune) is the missing caller identification of Exchange Online (EXO) contacts. Outlook for iOS supports a one-way contact export process whereby contacts from within Outlook for iOS can be exported into the personal (unmanaged) part of the native iOS Contacts app. This means a contact must first be imported into the users personal contacts directory of EXO and then exported from Outlook for iOS to the native (unmanaged) iOS Contact app in order to see who is calling. This functionality enables Caller-ID, iMessage, and FaceTime integration for users’ Outlook contacts. The exported Outlook contacts are considered unmanaged and are accessible by unmanaged, personal apps. Especially for European customers who are subject to GDPR compliance, this is a no go, as personal data and company data must not be mixed. The unintentional outflow of contact data worthy of protection to commercial platforms, such as WhatsApp or Google, and the unintentional synchronization of address books with social media apps, represents a significant GDPR risk. Although the user's personal EXO contacts can be synchronized, there is currently no option to synchronize the GAL. Furthermore, there is currently no provision in Outlook for iOS to synchronize the GAL cyclically. The user has to add a GAL contact to his personal contacts as described above and then within the Outlook for iOS app export the contact to his native iOS contacts app to be able to see who is calling. To meet the GDPR compliance, we need to prevent the contact export. So this is not a solution. The question to ask is: Why does a user need to export a GAL/personal contact to their native iOS Contact app? There are already several paid app solutions that close exactly this gap (ebf Contacts, Secure Contacts, etc.) which offer more or less the same range of functions. The app builds a container and downloads the managed address books (GAL, personal) of the user and then enables the resolution of the CallerID or identification of the caller via the so-called Apple CallKit integration. Apple has been offering the so-called CallKit integration for years. With CallKit you can integrate your calling services with other call-related apps on the system. CallKit provides the calling interface, and you handle the back-end communication with your VoIP service. For incoming and outgoing calls, CallKit displays the same interfaces as the Phone app, giving your app a more native look and feel. CallKit also responds appropriately to system-level behaviors such as Do Not Disturb. In addition to handling calls, you can provide a Call Directory app extension to provide caller ID information and a list of blocked numbers associated with your service. When a phone receives an incoming call, the system first consults the user’s contacts to find a matching phone number. If no match is found, the system then consults your app’s Call Directory extension to find a matching entry to identify the phone number. This is useful for applications that maintain a contact list for a user that’s separate from the system contacts, such as a Outlook for iOS. For example, consider a user who is a colleague to Jane, but doesn’t have her phone number in their contacts. If the Outlook for iOS app has a Call Directory app extension, which downloads and adds the phone numbers of all of the user´s colleagues. When the user gets an incoming call from Jane, the system displays something like “(App Name, e.g. Outlook) Caller ID: Jane Appleseed” rather than “Unknown Caller”. The effort to integrate the Call Directory Extension is minimal and would solve many pain points from both a security and user experience perspective. Apple has documented CallKit excellently on the developer site: https://developer.apple.com/documentation/callkit With the possibility of using Apple CallKit in combination with Outlook for iOS and the contact synchronization (personal/GAL) of a managed EXO mailbox, the use of M365 in a BYOD scenario for customers Blue Collar workers will massively increase. Furthermore, the use of contact synchronization is then also possible for devices managed by Intune. This creates an outstanding user experience while increasing user adoption! This article was also published as feedback in the Outlook Forum for iOS: https://feedbackportal.microsoft.com/feedback/idea/a80414f4-9598-ed11-a81b-000d3ae32cd0 There are already other requests within the Microsoft community that I would like to link here: PatrickF11 : Outlook for iOS + Caller Identification - Microsoft Community Hub Daniel Huttenlocher: https://feedbackportal.microsoft.com/feedback/idea/bbfc8763-da97-ed11-a81b-000d3ae32cd06KViews6likes8CommentsCompany Portal No Longer Installing During Autopilot Enrollment
Up until today, Autopilot enrollment which included Company Portal from the Microsoft Store (NEW) was successful. Starting today, the same enrollment workflow with similar hardware is failing to install Company Portal, reporting an error code of 0x87D1041C ("The application was not detected after installation completed successfully"). The only difference between yesterday and today? Today's enrollment including updating Windows to10.0.26200.8457 (today's Patch Tuesday update). I did find information that there was a similar issue nearly a year ago, where the latest Windows Update resulted in the same errors, and Company Portal requiring an update to fix. Are we looking at the same issue again?4.8KViews2likes28CommentsOneDrive for macOS documentation issue. DefaultFolder plist example is missing array wrapper
Hi everyone, The Microsoft Learn documentation for configuring the OneDrive sync app on macOS currently contains an incorrect plist example for the DefaultFolderLocation setting. Documentation page: https://learn.microsoft.com/en-us/sharepoint/deploy-and-configure-on-macos#defaultfolderlocation In the “DefaultFolderLocation” section, the current plist example shows the DefaultFolder key as a dictionary: <key>DefaultFolder</key> <dict> <key>Path</key> <string>(DefaultFolderPath)</string> <key>TenantId</key> <string>(TenantID)</string> </dict> This format does not work correctly when deployed as a managed preference/configuration profile. The setting starts working when the DefaultFolder dictionary is wrapped in an array, like this: <key>DefaultFolder</key> <array> <dict> <key>Path</key> <string>(DefaultFolderPath)</string> <key>TenantId</key> <string>(TenantID)</string> </dict> </array> Please update the Microsoft Learn documentation to include the array wrapper in the DefaultFolder plist example. The current Microsoft Learn example is confusing because administrators may deploy the documented plist exactly as shown, but the setting does not appear to work correctly until the array wrapper is added.78Views0likes2CommentsAutopatch for quality updates and WUFB for feature updates
We have switched to Autopatch for quality updates in our environment, but now is the time for feature update deployments. In the past we had used Windows Updates for Business for feature update without any problem. We would like to deploy the feature updates and retain the control of the target groups through the process, which are different ones from the quality updates. As the content is much bigger, we would like to test to specific users, after communicating to them for the procedure, and also be sure that the availability and the bandwidth will be adequate specially now during summer holidays. Could we still use WUfB only for the feature deployment along with Autopatch, without intervening to the normal monthly update cycle?Solved57Views0likes4CommentsCannot delete a website shortcut by Intune managed iphone
Hi We manually created a shortcut to a website from Safari browser and the shortcut is on the Intune managed iPhone. We don't need the shortcut now. However we cannot delete it. Press and hold apps on this phone does not start wiggle mode and we cannot drag the shortcut onto a new home screen. We also cannot see it in the Apps list in Intune to delete either because it was manually added on that specific iPhone. Can you tell me if there is a away to delete the shortcuts please? Kind regards Rob36Views0likes3CommentsApp Protection: Custom app vs Partner app
Is there any functional difference in using an app protection policy to manage a public partner app versus a custom application? We have an app vendor that says they wrapped their app with the SDK but it is not on the partner list so we cannot pick it from the public app list. Which leaves us with the custom app option. Is the functionality the same? Will it show up on the app protection report, work with conditional access policies, other Microsoft solutions, etc.? Thank you - Jessie54Views0likes1CommentOutlook for iOS + Caller Identification
Hey folks, i'm struggling at this for years, as you can see in my previus post from 2020. Let me shorten this: Scenario We have iOS Devices with Outlook for iOS installed. The users have many contacts in their EXO Mailboxes When a user gets a call from one of his contacts, the phone number is presented instead of the name (no Caller identification) Approaches I already know this MS articles belonging to Contact Sync. So i've learned that this leads to a running contact sync without the need of an icloud Account. The contacts could be written directly between Outlook for iOS and the native contacts app. (Better than nothing ) The Problem is, that if contact sync is in use ANY App could see these contacts. (Including Whatsapp, etc...) Because of GDPR this is a no-brainer. Many other solutions are using Apple Call-Kit, so that the incoming call is identified (name is shown) just without any need of contacts to be present in the native contact app. I didn't found anything belonging Call-Kit or any other possible solution for this issue, yet. There MUST be any better solutions except syncronizing all the contacts, isn't it? ANY Answer is highly appreciated. (At least the positive ones ) Regards, Patrick!7KViews2likes10Comments