intune
4374 TopicsKeyboard reverting on reboot
I'm having an issue with the keyboard reverting after OOBE. I'm using an English (UK) Windows 11 25H2 base image (deliberately — I want English display language, with Swedish keyboard/regional settings applied without needing to install a Swedish language pack). Deployment is native Windows Autopilot, no third-party tooling involved. Autopilot deployment profile: Language (Region) = Swedish (Sweden), Automatically configure keyboard = No. During OOBE, I manually select Swedish keyboard, and it's correctly applied — it's still Swedish through the first user logon. But after rebooting the keyboard silently reverts to English (UK). This is regardless of if I run pre-provisioning or user-driven. Is this a known/new behaviour, and how can I fix it?12Views0likes0CommentsINTUNE: Problems with the Google address (Managed Google Play)
Hello everyone, Ever since we added our email address under “Managed Google Play” (in the Intune Admin Center), we can no longer use that address to sign in to Google, Google Docs, Google Drive, or similar services... Is this normal? - If not, what settings do I need to adjust, and where, to get it working again? The error message looks something like this: "Error message: We’re sorry, but you don’t have access to Google Docs. Please log in to your Admin Console to enable it" Thanks and best regards Chris243Views0likes3CommentsRemoteHelp.exe reports FileVersion 10.4.10008.1000 while the product version is 5.2.1037.0
Problem 1 - File Version Because RemoteHelp.exe reports FileVersion 10.4.10008.1000 while the product version is 5.2.1037.0, this makes Intune detection, packaging, inventory reporting, and supersedence unnecessarily difficult. Remote Help publishes release versions such as 5.2.1037.0, but the primary executable reports a different FileVersion (10.4.10008.1000). This prevents administrators from using standard file-version detection methods in Intune, Configuration Manager, and software inventory solutions. Administrators must instead enumerate uninstall registry entries and distinguish between the Burn bundle and MSI entries. Aligning the executable FileVersion/ProductVersion with the published release version would significantly simplify enterprise application management. Remote Help combines both common enterprise packaging mistakes: The executable version doesn't match the advertised product version. The installer creates two uninstall entries with the same DisplayName. Neither issue is fatal, but together they make what should be a trivial Intune detection rule far more complicated than it needs to be. From an enterprise management perspective, this causes several problems: Application detection scripts become more complicated. Supersedence rules are harder to create. Administrators waste time investigating apparent version mismatches. Software inventory reports show different versions depending on which source is queried. Automated packaging systems cannot simply use file versioning. Documentation has to explicitly state "do not use the EXE version". Problem 2 - Duplicate Uninstall entries The Burn bootstrapper situation makes it even more confusing because there are two uninstall entries, both called Remote Help, both reporting version 5.2.1037.0, but representing two different installer components. This isn't unique to Remote Help unfortunately. Microsoft has a history of doing similar things with: Company Portal Teams (various generations) Edge WebView2 Visual Studio bootstrapper installers Azure VPN Client Some Defender components where the executable version represents the underlying codebase rather than the product release version that administrators actually deploy. The file version should be treated as an API contract with administrators. Once an application is broadly managed by enterprises, changing versioning schemes or exposing an internal build number instead of the published product version makes lifecycle management considerably harder than it needs to be. Problem 3 - Unversioned download URL The URL to download the latest version https://aka.ms/downloadremotehelp is only a redirect link, not a versioned artefact. The download URL itself does not expose any metadata about: The current Remote Help version The release date When the installer was last updated Previous versions A changelog Microsoft's documentation simply points administrators to the download link for installation. When you download the 'latest version' you always receive whatever Microsoft currently considers the latest installer, but the URL itself provides no version information. For enterprise deployment scenarios, the ideal solution would be one of: A "What's New" page with version history. A release notes page containing: Version Release date Changes Versioned download URLs, for example: RemoteHelp-5.2.1037.0.exe RemoteHelp-5.2.1037.0.msi Solution? Please can these three problems be resolved to ease some of the unnecessary burden placed on Intune Administrators?244Views0likes1CommentAccount Protection Policy Unable to Save
I am trying to configure an Account Protection policy to allow but not enforce Windows Hello for Business in my org's tenant. If I configure any of the device- or user-settings, the policy throws an error when trying to save. Two errors actually, both pretty generic. This has been persisting for the last 24hrs. Does anyone know what may be the culprit here?216Views0likes5CommentsAndroid 12 Sign-In Issue with HP Corporate Accounts via Intune Company Portal
Since yesterday, HP employees using older mobile operating systems (Ex. Android 12) have been unable to access Microsoft Outlook and Microsoft Teams on their smart devices. When launching Outlook or Teams, users are prompted to install the Microsoft Intune Company Portal app for authentication and device compliance. However, the latest version of this app appears to require a newer operating system version and is not supported on older devices. As a result, users with devices running Android 12 or earlier cannot complete the authentication process and are unable to use Outlook or Teams. ■ Please provide additional details 1) The issue started yesterday and affects employees using older Android and iOS versions. 2) On iOS devices, users can typically resolve the issue by upgrading to a newer iOS version. 3) However, some Android devices cannot be upgraded further due to manufacturer limitations. 4) For example, Samsung Galaxy Note 10 officially supports Android 12 as its final OS version and cannot be upgraded to Android 13 or later. 5) Because of this limitation, affected Android users are unable to install or use the required Microsoft Intune Company Portal app, which prevents access to Microsoft Outlook and Microsoft Teams. 6) This issue may impact multiple HP employees who are using Android devices that do not support Android 13 or later. Example affected device: Samsung Galaxy Note 10 (Android 12) Affected applications: Microsoft Outlook, Microsoft Teams, and Microsoft Intune Company Portal Business impact: Users cannot access corporate email, messaging, and collaboration services from their mobile devices. I have already posted this issue on the Microsoft Feedback Portal: https://feedbackportal.microsoft.com/feedback/idea/7bba2697-a2a2-f111-85ce-7c1e529382f4 However, this issue cannot be reproduced when using a personal Microsoft account. It only occurs when using an HP corporate email account because HP requires the use of the Microsoft Intune Company Portal app for authentication and device compliance. Since the problem appears to be related to the Intune Company Portal rather than Outlook or Teams themselves, I would like to post this issue here and seek guidance on resolving the Intune Company Portal authentication and compatibility issue affecting Android 12 devices.165Views0likes2CommentsBlocking/Disabling SMS, RCS and iMessage services on a device
Hi all, I'm trying to gather more information on Intune capabilities around blocking or disabling various text messaging services on mobile devices. I have done some research and here are my current understandings: SMS Android: This can be disabled on Samsung Knox Only devices. Not 100% if this means devices that are enrolled via Samsung's Knox enrollment, but that's what it sounds like. iOS: Did not find any capabilities here. iMessage: Android: N/A iOS: This can be disabled on iOS ADE enrollment device, no other types of enrollment support this for iOS. RCS: Android: Need to utilize OEMConfig profiles, which means it's vendor specific. Don't have any details here so not sure which OEMs support this for Android. iOS: N/A Any further information on this would be very appreciated. Thanks, Durango2k134.3KViews0likes3CommentsIntune Settings Catalog Updates
I am trying to create a Windows Device Configuration Policy for Microsoft Edge. The setting I need is: Force foreground priority for specific URLs (ForceForegroundPriorityForUrls) This setting should have been included in the https://learn.microsoft.com/en-us/intune/whats-new/#week-of-july-27-2026-service-release-2607 and our tenant is on 2608. However, whenever I look for the setting in the catalog, I cannot find it. I can see other older throttling policies, and I can see other polices that were added in the 2607 release. I have checked on two different tenants, both on 2607 or higher and it doesn't show up on either.Solved171Views0likes2CommentsIntune partner compliance onboarding
Hello, We develop a MDM solution and we would like to become device compliance partner to offer our customers conditionnal access functionality. After filling twice (the first time almost two month ago) the form "Intune partner compliance onboarding request" whose link is available on this page https://learn.microsoft.com/en-us/intune/device-security/compliance/third-party-partners, we didn't get any reply to our request. Would you know if there is any other way to integrate this partnership ? Any contact or anything to get some news about our request ? Thank you for your help. Best regards,254Views0likes2CommentsIntune client vs MDM
Dear all, We have been checking out trying to manage our Windows 10 workstations using Intune. We know we can enroll our devices either via MDM or deploying the Intune client. I understand that MS recommends using MDM. But I found that when looking at the workstations with the Intune Admin (Silverlight version), I am getting a lot more information, like software inventory, hardware details. They seem to be more comprehensive. Just wondering if this is how people found? Any idea if MS gonna drop the client, please? Or is there something I have missed? Thanks, Edmond.Solved2.6KViews1like3CommentsManaged Google Play > Multiple MDM's
Hi All Just a quick question. If a customer is using Managed Google Play / Android Enterprise for another MDM, say SOTI, and they want to move to Intune, can the same Managed Google Play / Android Enterprise account be used or must they create another / new / separate one? TIASolved1.6KViews1like2Comments