intune
4381 TopicsIntune App inventory Graph
Hi All, I've enabled the configuration profile to receive app inventory data in Intune. In the GUI the data I can view the data just fine, but I would like to use Graph to automate this data and create custom reports. When I use the following https://graph.microsoft.com/beta/deviceManagement/managedDevices/[device-id]/deviceInventories('ApplicationProperties') I get an error: "Forbidden - 403 - 199 ms Either the signed-in user does not have sufficient privileges, or you need to consent to one of the permissions on the Modify permissions tab" even though the docs I can find about permissions are OK.805Views2likes6CommentsIntune Update Ring not applying to co-managed Windows 11 device
Hello. I am troubleshooting a co-managed Windows 11 Enterprise 23H2 device that is not receiving an assigned Intune Update Ring. The Windows Update policies workload is assigned to Intune, and CoManagementHandler.log confirms that the device is MDM-enrolled, provisioned, and reporting the expected co-management workload flags. The Update Ring settings do not appear under Configured update policies, in the managed policy section of the MDM diagnostics report, or under: "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\Update" The device also cannot check directly with Microsoft Update and reports that it cannot connect to the update service. I have already checked: Intune assignment, exclusions, and filters Co-management workload ownership MDM enrollment and synchronization WSUS, BigFix, GPO, and scan-source conflicts WinHTTP and user proxy settings DNS and outbound TCP 80/443 connectivity Windows Update Client and MDM event logs Local Update CSP and Windows Update registry settings Other Intune MDM policies apply successfully, and no firewall or network issue has been identified. CoManagementHandler.log repeatedly shows: Could not find one of the mandatory rules Failed to merge/resolve rules. Error 0x8000ffff Failed to process GET for assignment Could these rule-processing errors prevent the Update Ring from reaching the device even though Intune appears to own the Windows Update workload? Which event IDs, registry values, WMI classes, or Configuration Manager policy evaluations would best confirm where the process is failing? Also, the Update Ring is not reporting as failed or in error in the Intune admin center, but its settings are not appearing or taking effect on the endpoint. What additional steps can be used to determine why Intune considers the policy healthy, and how can the policy be forced or corrected so it applies successfully to the device?277Views1like11CommentsMicrosoft Edge default browser with Intune
Hello everyone, I am looking for the best way to configure Microsoft Edge as the default browser for Windows devices managed through Microsoft Intune. I have reviewed the available Microsoft Edge settings in the Settings Catalog but have not been able to identify a specific setting that configures Edge as the default browser. Is there a supported and recommended way to enforce Microsoft Edge as the default browser for managed Windows 10/11 devices? If there are multiple approaches available, I would appreciate recommendations on the preferred method for enterprise environments. Thank you.79Views0likes1CommentMicrosoft Teams not working when Company Intune Portal is installed
Hello can someone help me why MS Teams force to closed the app when the company intune portal is installed. I need the company portal to sign in on teams because of policy in our company. But when I installed it crashed the MS team app Using android 13.12KViews0likes3CommentsKeyboard reverting on reboot
I'm having an issue with the keyboard reverting after OOBE. I'm using an English (UK) Windows 11 25H2 base image (deliberately — I want English display language, with Swedish keyboard/regional settings applied without needing to install a Swedish language pack). Deployment is native Windows Autopilot, no third-party tooling involved. Autopilot deployment profile: Language (Region) = Swedish (Sweden), Automatically configure keyboard = No. During OOBE, I manually select Swedish keyboard, and it's correctly applied — it's still Swedish through the first user logon. But after rebooting the keyboard silently reverts to English (UK). This is regardless of if I run pre-provisioning or user-driven. Is this a known/new behaviour, and how can I fix it?117Views0likes2CommentsINTUNE: Problems with the Google address (Managed Google Play)
Hello everyone, Ever since we added our email address under “Managed Google Play” (in the Intune Admin Center), we can no longer use that address to sign in to Google, Google Docs, Google Drive, or similar services... Is this normal? - If not, what settings do I need to adjust, and where, to get it working again? The error message looks something like this: "Error message: We’re sorry, but you don’t have access to Google Docs. Please log in to your Admin Console to enable it" Thanks and best regards Chris330Views0likes3CommentsRemoteHelp.exe reports FileVersion 10.4.10008.1000 while the product version is 5.2.1037.0
Problem 1 - File Version Because RemoteHelp.exe reports FileVersion 10.4.10008.1000 while the product version is 5.2.1037.0, this makes Intune detection, packaging, inventory reporting, and supersedence unnecessarily difficult. Remote Help publishes release versions such as 5.2.1037.0, but the primary executable reports a different FileVersion (10.4.10008.1000). This prevents administrators from using standard file-version detection methods in Intune, Configuration Manager, and software inventory solutions. Administrators must instead enumerate uninstall registry entries and distinguish between the Burn bundle and MSI entries. Aligning the executable FileVersion/ProductVersion with the published release version would significantly simplify enterprise application management. Remote Help combines both common enterprise packaging mistakes: The executable version doesn't match the advertised product version. The installer creates two uninstall entries with the same DisplayName. Neither issue is fatal, but together they make what should be a trivial Intune detection rule far more complicated than it needs to be. From an enterprise management perspective, this causes several problems: Application detection scripts become more complicated. Supersedence rules are harder to create. Administrators waste time investigating apparent version mismatches. Software inventory reports show different versions depending on which source is queried. Automated packaging systems cannot simply use file versioning. Documentation has to explicitly state "do not use the EXE version". Problem 2 - Duplicate Uninstall entries The Burn bootstrapper situation makes it even more confusing because there are two uninstall entries, both called Remote Help, both reporting version 5.2.1037.0, but representing two different installer components. This isn't unique to Remote Help unfortunately. Microsoft has a history of doing similar things with: Company Portal Teams (various generations) Edge WebView2 Visual Studio bootstrapper installers Azure VPN Client Some Defender components where the executable version represents the underlying codebase rather than the product release version that administrators actually deploy. The file version should be treated as an API contract with administrators. Once an application is broadly managed by enterprises, changing versioning schemes or exposing an internal build number instead of the published product version makes lifecycle management considerably harder than it needs to be. Problem 3 - Unversioned download URL The URL to download the latest version https://aka.ms/downloadremotehelp is only a redirect link, not a versioned artefact. The download URL itself does not expose any metadata about: The current Remote Help version The release date When the installer was last updated Previous versions A changelog Microsoft's documentation simply points administrators to the download link for installation. When you download the 'latest version' you always receive whatever Microsoft currently considers the latest installer, but the URL itself provides no version information. For enterprise deployment scenarios, the ideal solution would be one of: A "What's New" page with version history. A release notes page containing: Version Release date Changes Versioned download URLs, for example: RemoteHelp-5.2.1037.0.exe RemoteHelp-5.2.1037.0.msi Solution? Please can these three problems be resolved to ease some of the unnecessary burden placed on Intune Administrators?322Views0likes1CommentAccount Protection Policy Unable to Save
I am trying to configure an Account Protection policy to allow but not enforce Windows Hello for Business in my org's tenant. If I configure any of the device- or user-settings, the policy throws an error when trying to save. Two errors actually, both pretty generic. This has been persisting for the last 24hrs. Does anyone know what may be the culprit here?332Views0likes5CommentsAndroid 12 Sign-In Issue with HP Corporate Accounts via Intune Company Portal
Since yesterday, HP employees using older mobile operating systems (Ex. Android 12) have been unable to access Microsoft Outlook and Microsoft Teams on their smart devices. When launching Outlook or Teams, users are prompted to install the Microsoft Intune Company Portal app for authentication and device compliance. However, the latest version of this app appears to require a newer operating system version and is not supported on older devices. As a result, users with devices running Android 12 or earlier cannot complete the authentication process and are unable to use Outlook or Teams. ■ Please provide additional details 1) The issue started yesterday and affects employees using older Android and iOS versions. 2) On iOS devices, users can typically resolve the issue by upgrading to a newer iOS version. 3) However, some Android devices cannot be upgraded further due to manufacturer limitations. 4) For example, Samsung Galaxy Note 10 officially supports Android 12 as its final OS version and cannot be upgraded to Android 13 or later. 5) Because of this limitation, affected Android users are unable to install or use the required Microsoft Intune Company Portal app, which prevents access to Microsoft Outlook and Microsoft Teams. 6) This issue may impact multiple HP employees who are using Android devices that do not support Android 13 or later. Example affected device: Samsung Galaxy Note 10 (Android 12) Affected applications: Microsoft Outlook, Microsoft Teams, and Microsoft Intune Company Portal Business impact: Users cannot access corporate email, messaging, and collaboration services from their mobile devices. I have already posted this issue on the Microsoft Feedback Portal: https://feedbackportal.microsoft.com/feedback/idea/7bba2697-a2a2-f111-85ce-7c1e529382f4 However, this issue cannot be reproduced when using a personal Microsoft account. It only occurs when using an HP corporate email account because HP requires the use of the Microsoft Intune Company Portal app for authentication and device compliance. Since the problem appears to be related to the Intune Company Portal rather than Outlook or Teams themselves, I would like to post this issue here and seek guidance on resolving the Intune Company Portal authentication and compatibility issue affecting Android 12 devices.267Views0likes2CommentsBlocking/Disabling SMS, RCS and iMessage services on a device
Hi all, I'm trying to gather more information on Intune capabilities around blocking or disabling various text messaging services on mobile devices. I have done some research and here are my current understandings: SMS Android: This can be disabled on Samsung Knox Only devices. Not 100% if this means devices that are enrolled via Samsung's Knox enrollment, but that's what it sounds like. iOS: Did not find any capabilities here. iMessage: Android: N/A iOS: This can be disabled on iOS ADE enrollment device, no other types of enrollment support this for iOS. RCS: Android: Need to utilize OEMConfig profiles, which means it's vendor specific. Don't have any details here so not sure which OEMs support this for Android. iOS: N/A Any further information on this would be very appreciated. Thanks, Durango2k134.4KViews0likes3Comments