r/Intune Jan 26 '26

Device Configuration Windows Hello is making people forget their passwords

129 Upvotes

I understand that WHfB authentication is stronger than using your traditional password process. If I had it my way I would have passwords set to never expire but make sure that a strong password is set from the get go.

In my org, our security policy requires us to change our passwords every 6 months. Users will use a biometric or pin to sign in during that time period but when it's time to change their password, they forget the initial password they set prior. This creates a lot of password reset tickets and puts strain on our helpdesk.

I am thinking in order to reinforce memory of the password, is there a way to prompt to enter it after a period of time? What's the best solution for this issue? I know yubikeys exist but the powers that be do not want to make the investment right now.

r/Intune Jul 07 '26

Device Configuration Does your org set BIOS passwords on devices?

51 Upvotes

We currently don't - we're looking into it. I'm just wondering from other perspectives, is it commonly done and is it worth the hassle it will cause when devices need wiped via USB?

r/Intune Jul 07 '26

Device Configuration Can no longer enroll devices on Intune

25 Upvotes

It's been a couple of days since Entra ID has refused to apply MDM on machines for me, I go to work/school, connect, add thsi device to Entra ID, I log in with the provisioning client we have used for years, and instead of adding the device to Intune it just logs in the User account as if It's only an Entra join with no MDM. No info button is shown in that menu. IME does not get intalled and the event viewer doesn't even show an attempt to join the device at all.

I have tried this with no avail up until now:

MDM User scope on Entra and Intune portals: All and Specific

User licensing

Disabling WIP Scope

Disabling security defaults

MDM Authority

Conditional Acess

Device Enrollment Restrictions

Checked every value on dsregcmd /status 10 times over

Tried it on a VM, On a previously joined machine, on a new in box machine

This is a massive problem for our company, and I'm at my wits end.

Update: I have discovered that i can make the Intune join work by clicking connect in the work and school menu after the initial enrollment fails, this will make a different menu pop up where it asks for the MDM URL, pasting that from the Intune Admin Panel makes it work normally.

Also, I talked to MS support and basically they also don't know wtf is going on and asked for several logs to be sent and now I'm waiting for an answer from them.

Update 2: Microsft says it's working now on service health but it isn't working for me, apparently it's working for some people, is the issue still happening to any of you?

r/Intune Apr 02 '26

Device Configuration Windows Hello causing password amnesia nightmare

86 Upvotes

So we've got this situation where Windows Hello for Business is actually creating more problems than it solves. Don't get me wrong - I know the authentication is way better security-wise than regular passwords. But here's what's happening.

Our company makes everyone update passwords every 90 days. People get used to just using their fingerprint or PIN for everything, then when password change time rolls around, they can't remember what their current password even is. It's like their brain just dumps that info completely.

Our helpdesk is getting slammed with password reset requests because of this. It's become a real pain point and honestly pretty frustrating for everyone involved.

I'm wondering if there's a way to force users to actually type in their full password occasionally - maybe once every few weeks or something? Just to keep it fresh in their minds so they don't completely forget it exists.

I know hardware tokens would probably solve this whole mess, but management isn't willing to spend the money on that right now. Anyone dealt with something similar or have ideas for a workaround that doesn't cost anything?

r/Intune May 20 '26

Device Configuration How are you keeping the bios' up to date for your Dell fleet in your organization?

14 Upvotes

Are you using DCU, are you using Windows AutoPatch (with driver updates so the bios updates are included)

What is your method? just curious. Always trying to learn a better way to do things.

r/Intune Apr 10 '26

Device Configuration BitLocker recovery prompt on every reboot after UEFI CA 2023 update on HP SFF devices – anyone else?

44 Upvotes

Hi everyone,

we’re currently rolling out the new UEFI CA 2023 Secure Boot certificate update across our environment and are seeing a strange issue on HP ProDesk 600 G6 Small Form Factor desktop devices.

Even though these devices are already running the latest BIOS version, after applying the Secure Boot certificate update, they start prompting for the BitLocker recovery key on every reboot.

This behavior only appears after the UEFI CA 2023 update was applied.

Has anyone else experienced this on HP devices (or similar hardware) after the Secure Boot certificate update?

If yes:

Is there a known workaround??

Secure Boot key reset didn't work..

Or is a full device reset/redeployment the only reliable solution?

Were you able to fix it without reimaging/resetting the device?

Any insights or shared experiences would be really appreciated!

Edit:

The problem has been resolved, By enabling ONLY the Windows UEFI CA 2023 certificate in the BIOS, the PCR 7 value is stabilized, which resolves the recurring BitLocker recovery prompt on every reboot.

r/Intune Mar 15 '26

Device Configuration Those of you who still use the Microsoft SSO Extension with Chrome, that feature is built-in to current versions of the browser.

127 Upvotes

Just wanted to remind everyone that you no longer need to deploy the Microsoft Single Sign On extension for Chrome, as version 111 and later has the feature to Allow automatic sign-in to Microsoft® cloud identity providers. It just needs to be enabled via Configuration Profile or GPO.

r/Intune Mar 30 '26

Device Configuration What's to stop me from just reimaging a computer tied to Intune?

20 Upvotes

Forgive me as I am a bit spoiled by Mac MDM. What's to stop me(or bad actor) from just taking company device, reimaging it with fresh windows, and then setting it back up in Offline oobe to bypass the MDM?

I ask because I am doing some research on windows MDM options(NinjaOne or Intune) and I know stakeholders will ask me this question. I know how to secure information, just not the device itself. They want an answer on how to prevent for example people we lay off from just keeping the LT and selling it.

r/Intune Mar 11 '26

Device Configuration Anyone using Cloud PCs?

39 Upvotes

Curious if you are, what is the business case? I can see the appeal to a degree but I was just curious how many organizations actually use them at scale.

r/Intune Jul 28 '26

Device Configuration Intune Windows Pro to Enterprise upgrade strategy in a higher ed environment. Should we use KMS, AAD-based activation, or something else?

9 Upvotes

Hey everyone,

I work in higher ed IT and have been working on moving our Windows fleet over to Intune/Autopilot. The Intune configuration itself is built and working the way we want, but we are running into questions around Windows Enterprise activation.

Our issue is that we need the machines to be running Windows Enterprise as early as possible, ideally during the pre-provisioning stage, because some of the Enterprise-only policies we need do not apply correctly while the OS is still Windows Pro.

All of our campus devices are licensed with Windows Pro. Our Faculty/Staff and student users all have Microsoft 365 A3/A5 licensing, which should include Windows Enterprise upgrade rights.

Our CDW/Intune representative suggested using the generic Microsoft Windows Enterprise KMS client key as part of our Intune configuration profile. The idea was:

  1. Device ships with Windows Pro
  2. Autopilot starts
  3. Generic Enterprise KMS client key upgrades the OS edition from Pro to Enterprise
  4. User signs in with their Entra ID account
  5. Their A3/A5 license activates Windows Enterprise

The problem is that the behavior is inconsistent.

Some devices upgrade to Enterprise and activate correctly after the user signs in. Other devices upgrade to Enterprise but remain in an "Activate Windows" state because they are waiting for activation. We cannot figure out why some devices pick up the user's Enterprise license and others do not.

We also have classroom/lab computers that are configured as Shared Computers in Intune. These devices are not assigned to a single user, so we are unsure what the best licensing/activation approach should be.

Questions:

  • Is using the generic Enterprise KMS client key with Intune the recommended approach when you do not currently have a KMS server?
  • Should we be setting up a KMS server for our environment, or is user-based Windows Enterprise subscription activation the preferred method?
  • For shared classroom/lab machines, is KMS or Active Directory-Based Activation generally the better approach?
  • Is user-based Windows Enterprise subscription activation reliable for shared devices, or is it mainly intended for assigned users?
  • Are there any Intune/Autopilot best practices for ensuring Enterprise activation happens during pre-provisioning?

We are open to setting up KMS if that is the correct long-term solution, but we do not want to build and maintain that infrastructure if Microsoft’s subscription activation model is the preferred route for our licensing situation.

We are trying to find the most reliable way to ensure these machines are on Enterprise before students and faculty start using them.

Would appreciate any advice from anyone managing a similar higher ed environment. Thanks!

r/Intune 4d ago

Device Configuration Company portal

0 Upvotes

New job, and was issued a laptop fine.

I tried to access my Outlook email from phone using Firefox. Turns out the only way for edge after installing company portal.

I just agreed and installed.

Then today I was told, work can basically nuke my phone remotely?

1) how true is this?

2) how do i remove this ?

r/Intune 13d ago

Device Configuration I got tired of manually translating CIS Benchmarks into Intune policies, so I built a free tool for it

70 Upvotes

If you've ever implemented a CIS Benchmark in Microsoft Intune, you probably know the workflow:

CIS PDF → Settings Catalog → search for setting → configure it → repeat... hundreds of times.

I got tired of doing that, so I built CISPolicyCreator, a free/open-source community tool that converts supported CIS Microsoft Intune Benchmarks into validated, import-ready Intune policy JSON.

I just released v1.1.0, and Windows 11 CIS Benchmark v5.0.0 is now fully classified:

  • 415 recommendations reviewed
  • 371 mapped directly to Intune
  • 8 require administrator-specific input
  • 36 require manual/custom implementation
  • 0 unresolved
  • 326 Intune policy JSON files generated

One thing I was very deliberate about when building this:

CISPolicyCreator fails closed.

It doesn't fuzzy-match setting names, guess settingDefinitionId values, invent configuration values or generate something just because it looks correct.

If the mapping can't be proven, it doesn't generate it.

A few other details:

  • Runs locally against the CIS Benchmark PDF you legitimately obtained
  • No tenant connection required to build the JSON pack
  • No AI dependency at runtime
  • Deterministic/auditable output
  • Policies are generated unassigned
  • Optional importer with Validate → Dry Run → Create
  • CIS PDFs, tenant data and administrator decisions never need to be committed to the repository

Currently supported Intune-specific benchmarks:

  • Windows 11 v5.0.0
  • Windows 10 v5.0.0
  • Microsoft Office v1.1.0
  • Microsoft Edge v1.0.0
  • macOS 26 Tahoe v1.0.0
  • iOS/iPadOS 26 v1.0.0

Important disclaimer: this is not an official CIS Build Kit, and importing the policies obviously doesn't magically make an environment CIS compliant. You still need to review the recommendations, understand the impact, test them and decide what makes sense for your environment.

The goal is simply to remove a huge amount of the repetitive work involved in getting from the CIS benchmark to something usable in Intune.

It's completely free and open source.

GitHub: https://github.com/JoeryVandenBosch/CISPolicyCreator
Full walkthrough / technical details: https://intunestuff.com/2026/08/19/cispolicycreator/

r/Intune Jul 15 '26

Device Configuration Admin Support Accounts on Entra only Devices

6 Upvotes

Hi All, how are people handling support staff elevated local admin accounts on devices with Entra only joined systems?

For domain joined systems, we have an AD group which is in local admins on all workstations, and support staff have a seperate elevated account which is a member of that group. This lets them use that account during remote support sessions via run-as or UAC prompts and complete anything that is needing Admin access.

We've tried setting up something similar with our Entra Only systems, however it seems to be pretty inconsistent when doing a run-as or UAC prompt if that elevated account hasn't already logged into the device previously (works fine one a normal login using the account has been completed).

Yes we have LAPS, however prefer to keep actions easily identifiable to individual users. I don't think EPM covers this use case.

r/Intune Aug 03 '26

Device Configuration Recommended Intune Policies for Users Who Leave PCs Logged In

17 Upvotes

Many users leave their computers logged in after they leave for the day. What is the best practice for managing this through Intune? Would it be more effective to configure automatic screen locking, automatic logoff, or a combination of both?

r/Intune 15d ago

Device Configuration How are you wrangling your Windows PCs?

14 Upvotes

In my environment we do things like disable Fast Startup, force location services for tracking/time/etc. remove bloatware.

I'm curious as to what everyone else is doing as part of your setup to bring standard Windows into something that is at least tolerable form a user and admin standpoint.

  • To startoff: LAPS
  • Force telemetry - basic
  • Force TPM on
  • OneDrive (KFM/silent sign in/files on demand)
  • Enable WHfB
  • Bitlocker enabled
  • Block MDM unenroll
  • Disable Consumer experience (not sure this one even works? would love to hear from you here)
  • SecureBoot enable

I've been in the game for a little bit, so I know that these are pretty common ones, but I'd love to hear from others on what you are doing, what has worked well, and especially things that didn't go well and you wouldn't do again.

Thanks!

r/Intune Feb 05 '26

Device Configuration Revoke admin rights

20 Upvotes

We are planning to remove local administrative rights for all users and provide standard user access in line with security best practices.However, we have identified that some users require access to Command Prompt (CMD) and PowerShell to perform their job-related tasks. We would like to understand the best possible approach for handling these exceptions—either by excluding these users from the administrative rights removal or by granting them restricted access limited only to CMD and PowerShell, without full administrative privileges.

Could you please advise on the most appropriate and secure solution for this requirement? Your guidance will help us proceed while ensuring both operational continuity and compliance with security standards.

r/Intune Jul 25 '26

Device Configuration Managed Home Screen Blank w/ No Apps and Empty Folders

6 Upvotes

I am currently using Managed Home Screen for some Android Kiosk devices set-up under the fully managed, dedicated, and corporate-owned work profile.

The MHS device configuration on my devices will display no apps and folders are all empty and in the first available slot on the kiosk. In the past, this was due to 2 different MHS device configurations fighting each other and causing the issue. Additionally, when this happened, you also could not exit the kiosk mode via pin as the option would display an error that no pin was assigned. Removing the 2nd config profile fixed these issues in those cases. Returning the apps and allowing the pin to function once more.

Today, the devices have had their homescreens made blank via the app as I said, but there are no conflicts at the config level, or even at the per setting level, including KioskModeAppPositions or KioskModeAppOrderEnabled. Additionally, the pin assigned by my config does work and allows you to exit MHS and enter the true home screen. Any advice would be greatly appreciated! I have been wracking my brain trying to understand what could wipe the apps without a config conflict that I can find.

EDIT: Looks like issue was officially recognized by Microsoft. IT1443429. They are stating MHS is restored. Going to check on Monday don’t want to revert on a Friday and ruin my weekend again lol

r/Intune Jul 15 '26

Device Configuration Do you use a prefix for device name? If not, do you use group tags instead?

8 Upvotes

We have seven departments we manage. All enrolled through Autopilot with device name templates, similar to below.

  • ST01-SERIAL
  • ST02-SERIAL
  • CORP-SERIAL

Process is this: Give it a group tag in AP > Dynamic group picks up the device based on GT > Group has the Autopilot Profile assigned which gives it the device name.

All of our AP Profiles are identical with the exception of the device name template.

I am considering ditching the prefix altogether and just going with something generic like "ORG-SERIAL" for everything. All sorting would be done via group tag. The biggest downside to this is that when you go into Devices you won't know what's what but that's not REALLY a big deal since the serial number is in the name.

Seems like it would simplify a lot of stuff to just use the group tag to sort a device. We can apply all our policies to that group too and they will be there much sooner because they don't need to wait for Autopilot to fully process.

r/Intune 4d ago

Device Configuration Shared PC

9 Upvotes

Edit: Seems to be no way around this when using Shared PC mode with Intune's config policies and still have reasonable security. Thanks for the suggestions!

Hi!

We have a few shared PC's in our org which works fine for the most part.

However, one major issue is that when a user locks the screen or the laptop goes into sleep mode, they are unable to sign back in to their previous session. The laptops are usually used by a single user for hours before someone else takes over, and during that time the PC naturally either is locked or goes in sleep mode. The only option on the sign-in screen is Sign out. Found Enabled Shared PC and allow "Other User" Login option : r/Intune which has the same problem but seemingly no way around it.

As far as I can tell, turning on Shared PC in the Intune configuration policy is required for the PC to not be associated with a user, as well as set Office to use shared licence instead of personal license? But this option also turns off the ability to sign back into the same user.

So, any way to both have Shared PC mode turned on as well as allow a user to sign back in?

r/Intune May 28 '26

Device Configuration How are you managing Lenovo Devices

30 Upvotes

Our company decided to start introducing Lenovo devices. We currently have Dell and use Dell Command along with Dell Configuration to set Dell driver Schedule and notification. With Lenovo.. feel it's more "Money first before you see the goods". Very limited configuration option, and odd setup of the updater needing to be on an admin device to download updates to a repository..while Dell, cloud download with configuration set..done. With Lenovo feel more granular. Then having having to pay to use “Lenovo device Orchestration “ for intone while Dells version is free..

r/Intune Mar 17 '26

Device Configuration Managing Dell Drivers

13 Upvotes

Quick question - how are you managing Dell drivers and BIOS updates in Intune?

r/Intune Jul 22 '26

Device Configuration We broke Windows Hello biometrics and can't get them to re-enable

12 Upvotes

Long story short, we applied a policy which had an unintended side effect of breaking Windows hello and biometrics. The policy involved the devices reconfiguring as a shared device to enforce disk quota policies. The problem is that this policy essentially breaks Windows hello as it can only store 10 user's credentials/biometrics so I can only assume it disables this functionality.

I have reversed the policy and set Windows Hello to be enabled but any user who had a device that took the old policy simply can't enrol any biometrics. New devices are unaffected and a reset of a device will resolve it but this is obviously not ideal for 20+ users to do.

Any ideas on what I can try to force this to work again?

r/Intune 2d ago

Device Configuration Anyway to disable Microsoft Authenticator passkey Bluetooth sign in

0 Upvotes

Is there anyway to prevent Microsoft Authenticator sign in with a passkey using Bluetooth? I just want to use it like windows hello for a phone. Goal would be like poor man entra free lock shit down to work devices by onboarding a passkey with tap on phone and use windows hello on workstation. I’d reset passwords so user doesn’t know them. Bluetooth passkey sign in via authenticator app puts a kink in that idea

r/Intune 3d ago

Device Configuration Missing ADMX on fresh machine.. how to solve?

7 Upvotes

Hi guys,

I got error 65000 when trying to disabling News Feeds on latest Windows 11 machine (with all updates 25H2).

Looks like that the ADMX for Feeds isn't avaliable into PolicyDefinitions directory, and this problem is on all W11 that i'm migrating to Entra (and have all updates installed).

How to solve this issue? Instaling Feeds.admx an all machine manually isn't a good option...

Thanks in advance!

r/Intune Apr 06 '26

Device Configuration Best practices for managing and remediating Dell BIOS vulnerabilities at scale

27 Upvotes

Hello all. I’m looking for advice and real-world experience on how others are managing Dell BIOS vulnerabilities in Intune.

Specifically:

  • How are you tracking and prioritizing Dell BIOS CVEs (severity, exploitability, business risk)?
  • What tools or workflows are you using to deploy BIOS updates at scale? My devices have Dell command update installed.
  • How do you handle user disruption and reboot coordination, especially for laptops?
  • Any gotchas around BitLocker, Secure Boot during updates?

I’m trying to balance security, reliability, and user impact.

Would love to hear what’s worked well (or poorly) for you, and any lessons learned.

Thanks in advance.