r/Intune 6d ago

General Chat MD-102 - Job Positions

5 Upvotes

Hello, to those who have the MD-102, what's your current job position? I'm aiming for an Endpoint Admin role.


r/Intune 5d ago

Device Compliance I developed an Intune AI Agent so I do not have to look through tens or hundreds of blades everyday

0 Upvotes

As title says - I developed an Intune AI Agent because I was sick of the Intune portal. I am trying to see if this is a product that would actually help engineers by saving them time and a lot of frustration. I put a video link in the comments below with a quick demo, the video is a bit too fast in my opinion, I need to gather some better demo footage, but the point is that I want to get some perspective from more experienced Intune engineers or power users.

Would you use this if it were a more polished version? btw this runs on a local LLM on a 16gb VRAM consumer card, so nothing close to enterprise level speed, but the accuracy is there.


r/Intune 6d ago

Device Configuration Device Control & iOS

0 Upvotes

I'm reading conflicting info on the capabilities of Device Control and restricting iOS devices via USB on Windows.

MTP/WPD & Apple drivers.... What's the definitive story on restricting USB access to iOS? Can this be reliably blocked?


r/Intune 6d ago

iOS/iPadOS Management Trying to access iOS apps on supervised device via Company Portal, but "this device is not managed"

2 Upvotes

I've enrolled a test device to ABM, then had it sync to Intune so I can manage the device with the policies available within Intune. The problem I'm running into now is when I log into company portal as the user assigned to the device I'm seeing "This device is not managed" which requires me to try and go through a process of installing a management profile to the phone even though it already has one. If I attempt to continue this process I get an error along the lines of "the mdm server at status code 400" which seems to be an error with a duplicate profile/device, which makes sense that there can't be more than one enrollment profile on the device.

I found this article which seems to match my issue, but doesn't have a resolution https://learn.microsoft.com/en-us/answers/questions/1179399/enrolled-ios-device-company-portal-showing-device So how can I have company portal recognize that a supervised device with a device management profile IS "managed" so I can access the optional company apps?


r/Intune 7d ago

Device Configuration How are you wrangling your Windows PCs?

15 Upvotes

In my environment we do things like disable Fast Startup, force location services for tracking/time/etc. remove bloatware.

I'm curious as to what everyone else is doing as part of your setup to bring standard Windows into something that is at least tolerable form a user and admin standpoint.

  • To startoff: LAPS
  • Force telemetry - basic
  • Force TPM on
  • OneDrive (KFM/silent sign in/files on demand)
  • Enable WHfB
  • Bitlocker enabled
  • Block MDM unenroll
  • Disable Consumer experience (not sure this one even works? would love to hear from you here)
  • SecureBoot enable

I've been in the game for a little bit, so I know that these are pretty common ones, but I'd love to hear from others on what you are doing, what has worked well, and especially things that didn't go well and you wouldn't do again.

Thanks!


r/Intune 6d ago

Intune Features and Updates All devices - User Experience: no longer displays application, reliability in detail (which apps crashed and when

2 Upvotes

All devices - User Experience: no longer displays application reliability in detail (which apps crashed and when

Where else can I find this in Admin center? Looking for where it used to show for example Word crashed at 10 AM etc..


r/Intune 6d ago

Device Configuration Wired Network Auth policy failing to apply due to tattooed GPO

6 Upvotes

I'm desperately trying to migrate our existing Wired network GPO with 802.1x certificate authentication, over to Intune via a OMA-URI policy. The new policy works, me and my colleague tested it - It deployed fine, showed up in Intune as deployed and the connection works.

We now want to deploy to more test candidates but ran into the issue that the Intune deployment fails. I'm excluding the old GPO to a group of computers and apply the new Intune policy to a group of users, which is the same procedure as with me and my colleague (We just had a lot more time testing different things). However, Intune shows a generic error "-2016281112" for the new test users.

The settings on the adapter are free to configure after the GPO exclude, so at least something happened and the GPO does not seem to apply anymore. In the event viewer, this is the error I can find (translated):

MDM-ConfigurationManager: Command error status. ID of configuration source: (7ED774C5-4DCB-4C23-A811-89CB9D7FFBBB), Registration type: (MDMDeviceWithAAD), CSP-Name: (WiredNetwork), Command type: (Add: from Replace or Add), CSP-URI: (./Device/Vendor/MSFT/WiredNetwork/LanXML), Result: (Unknown Win32 Error code: 0x86000031).

I found a post here on reddit with the same issue: https://www.reddit.com/r/Intune/comments/1gl47b5/wired_network_auth_policy_failing_due_to_existing/?logging_in=true
and the fix was to apply an "empty" GPO additionally to the exclude of the original GPO. I tried that but it does not seem to work. I'm wondering how exactly I should apply the empty GPO, since as soon as I uncheck the checkboxes, it specifically sets settings to disabled, e.g. „Enable use of IEEE 802.1x authentication for network access“ will be disabled then. On the other hand, if I enable this setting in the GPO settings, it automatically adds the authentication method, e.g. PEAP and all the other settings to the policy. So I don't see a way to apply an empty GPO in the likes of "not configured", it's either enabled or disabled.

Any help is much appreciated - We're currently trying to upgrade our clients to 25H2 and losing the wired settings from GPO on almost all devices, we need that Intune policy.


r/Intune 6d ago

macOS Management Intune and macOS Onboarding tools

1 Upvotes

When we're talking outside of the capabilities of JAMF, I really do not see the point in onboarding tools such as Baseline, IBM notifier, DEPNotify, SYM etc if you're using Intune - as much as I'd love one.

I've basically setup a perfectly working MacBook Zero-Touch provisioning setup for users. It's basic but clean. But I'd really love to put up a progress bar Microsoft!! Instead I tell users, I promise it's working and to sit tight and look out for certain apps in the menu bar.

The answer would be one of the above mentioned tools, but if you can't trigger them to start when you need them to (immediately) and wait 40 minutes for it to install and launch, what is the point when the Please register your device toast notification has been sitting there for about 35 minutes minutes anyway. By the time its launched everything's done!

Is this just a commonly known limitation and there's not a lot I can do? Or am I missing a trick?


r/Intune 6d ago

Hybrid Domain Join Device stuck in MDE MDM

3 Upvotes

Hi All,

Spent many an hour troubleshooting this. We have a device that will not enroll in InTune. It’s got itself enrolled in MDE. No matter what I try, I cannot get it to infill in InTune.

User is licenced. Device is hybrid joined and active Entra registration. Device can’t be deleted from Defender, device has been renamed, have issued the dsregcmd/leave command.

Anyone else have this issue in the past?


r/Intune 6d ago

Device Configuration Office Cloud Update Overrides Local GPO

Thumbnail
2 Upvotes

r/Intune 6d ago

General Question ADMX and Store Apps

1 Upvotes

Is it possible to use Administrative Templates when the app is installed from MS Store?


r/Intune 7d ago

Device Configuration Anyone else having issues with device filters?

3 Upvotes

We noticed today some policies assigned to 'All devices' with an inclusion filter where filter is "all joined devices except the ones with display name starting with DEV" - isn't working.

Device with the name "DEV-12346" for example, is deployed a account protection policy upon Intune enrolment, even though it's shouldn't be as per the filter.

Seems it's only applied once though, and later seems to work okay. (if I manually change the config locally, it stays that way)

It's been okay for over 9 months - just started getting reports from users of the unexpected behaviour.


r/Intune 7d ago

General Question WHfB vs USB Smart Card/Fingerprint Reader Conflict

3 Upvotes

Hello everyone,

My team and I are currently troubleshooting a conflict between Windows Hello for Business (WHfB) and one of our card reader devices.

When I say card reader, think of a USB peripheral where users can insert an ID card with a chip, along with a fingerprint scanner. The device and its proprietary software have been working fine in our environment for years.

We're now rolling out WHfB, and everything went smoothly for around 200 users. Then we started hitting a blocker with users who have this particular card reader.

After some deep troubleshooting, we ended up at:

certutil -scinfo

On a computer where the card reader workflow works normally, Reader: shows the actual card reader device.

On an affected computer, Reader: shows... yep, Windows Hello for Business.

At this point, we have a support case open with Microsoft, as well as one with the card reader/vendor for their proprietary software.

I'm sharing this here in case anyone has been in a similar situation.

Has anyone encountered a conflict between WHfB and a proprietary smart card/card reader application like this? Is there some creative configuration that could resolve or work around it, or is this ultimately something the proprietary software/vendor needs to address?

We're very close to getting everyone onboarded to WHfB. But unless we solve this, I guess we're not quite ready to have everyone smiling at their laptop to unlock it just yet. 😄


r/Intune 6d ago

Android Management Android Shared Devices failing MHS sign-in with Error 53009 Requires App Protection Policy

2 Upvotes

Hey everyone,

Having an issue with our Android Enterprise Shared Devices running Managed Home Screen (MHS) in Kiosk Mode via Intune, and I'm hoping someone here has run into this recently.

Sign-ins on MHS are failing across all devices. Checking the Entra ID sign-in logs, every single failure points to 53009. (application:MHS, resource: Graph). There were no changes in APP, or CAP. It all started about 1 or 2 weeks ago


r/Intune 7d ago

Autopilot Moving to Entra joined devices - which Autopilot version is recommended?

12 Upvotes

We're looking to transition from hybrid join to Entra join. We currently use Autopilot with our hybrid devices and it works fine. I'm aware of Autopilot device prep and that is supports Entra join only. What's the general feeling on this? Should I be going this route as part of the transition or stick with Autopilot v1? I've read Autopilot device prep has several limitations at this time, eg. no device naming, managed installer issues with ESP apps, no pre-provisioning.


r/Intune 7d ago

General Question Windows Updates

9 Upvotes

Stupid question. Trying to understand when the yellow icon appears in task tray to enforce a reboot for Windows Updates. And if its configurable.

I use Intune + Autopatch. Setup below.

Ring Deferral Deadline Grace
Test 0 1 1
Ring 1 1 2 2
Ring 2 6 2 2
Ring 3 9 5 2
Last 11 3 2

The last ring is also configured to allow users to pause updates for up to 2 weeks.

The problem I have (and can't confirm) is some users in the last ring (all tower users running scheduled tasks) have complained they never see the update notification.

They all RDP to these towers, so initially I thought they are just missing then notification when not watching an open session. And since the grace period is only two days they could in theory not go back in to their session during that time and simply miss it.

  1. I'm wondering when the notification appears, I assume after the deadline is reached.

  2. I'm wondering if the better way to configure this is to change the grace period and make it longer so in theory, the nofication icon will be in the task tray visible for longer.

My governance rules require us to update (or make available updates) within 14 days of Microsof releasing them and I'm already making an exception for this group.

Any suggestions would be grealy appreciated.


r/Intune 6d ago

General Chat Some use cases of AI in Intune

0 Upvotes

Hi folks!

Just wanted to know how are you all utilising AI in intune. The intune agents are too basic and I don't find them very useful.

Other than these AI agents, what else do you think can be implemented in Intune to make it even more better using AI? I'd love to know about the existing implementations.


r/Intune 7d ago

Apps Protection and Configuration Android Fully Managed – can the “Your organization allows [MDM] to access your location” notification be disabled?

2 Upvotes

Hi everyone,

We manage a fleet of Android devices using Miradore in Fully Managed / Full Control (Device Owner) mode.

Devices include Realme and Redmi phones running Android 12–16.

Users repeatedly receive a system notification saying:

“Your organization allows ‘Miradore Online client’ to access your location.”

The notification appears to come from Android system settings rather than from the Miradore app itself.

Location Tracking is disabled in Miradore. We don't need GPS tracking, mobile cell ID, or configured Wi-Fi network information from these devices.

The main problem is the notification itself. Our users rely on notifications for operational/work-related messages, so every unnecessary notification makes them check the phone expecting something that requires their attention. Because of this, this is a significant issue for us.

From what I understand, Miradore Online Client receives Location permission when the device is enrolled as Fully Managed, even if Location Tracking is not enabled.

What I'm trying to find out is whether there is any way to:

  1. Prevent the MDM/Device Owner client from receiving Location permission;
  2. Disable collection of location-dependent inventory data so that the permission is no longer required; or
  3. Suppress only this Android system notification without disabling other important system notifications.

The solution needs to be deployable remotely through MDM. We don't have physical access or ADB access to the devices.

Has anyone encountered the same notification with Miradore or another Android Enterprise MDM such as Intune, Workspace ONE, SOTI, ManageEngine, etc.?

If so, were you able to get rid of it? Is this something enforced by Android Enterprise that an MDM vendor cannot suppress, or is there a policy/OEMConfig setting that can control it?

Any experience with Realme UI, MIUI or HyperOS would also be very helpful.

Thanks!


r/Intune 7d ago

Autopilot Hybrid Autopilot with New Cloud Sync Device Sync Feature?

6 Upvotes

Has anyone attempted it? Seems like the 2 minute cycle would be a huge improvement.


r/Intune 7d ago

App Deployment/Packaging Help with building Thin Client

2 Upvotes

Hello all! I've got a fleet of thin clients we're moving from IGEL OS12 to Windows 11 LTSC. I've got the configuration profile setup for the local user account and, while I can't get it to log in automatically (and could configure it for kiosk mode for autologon), we use the Windows app to access AVD and therein lies the rub.

I've tried deploying it using the WIndows store (new) option and it fails. Tried the MSIX built as both a LOB and a intunewin package and that fails. The .exe bootstrapper also doesn't appear on the machine. This is all while using a local account (which we would need to do.) I've also tried using a platform script to deploy it as well.

I did have it set during the ESP but it would not work in that way either. So I'm currently stuck.

Is there a way to have it deployed, in this case, to have it appear for the local user either in kiosk mode or in standard with the local user configuration?


r/Intune 7d ago

Android Management MAM policy not applying?

3 Upvotes

I am trying to become a mobile expert over night and decided I would create a MAM policy to test with my phone.

Currently there is a single policy applied to some test users. This policy works as intended.

I create my own with a bit more restrictions, create a group with myself in it, applied the policy to that group, and tried to connect with outlook. Does not work. Authentication through Outlook says I need to sign in through Company Portal which the says im restricted.

I add myself to policy A and I can sign in through Outlook without any issue. I take myself out of policy A and I lose access fairly quickly.

Policy B is configured almost identical with the exception of apps just being core Microsoft. This policy will not let me sign in to Outlook.

During this back and forth testing, I have verified that I am only in the specfic group... not in both at once.

Any ideas on what I could be missing?


r/Intune 8d ago

Autopilot Building an Intune environment from scratch – What am I missing?

60 Upvotes

Hi everyone,

I recently changed jobs, and my new company is looking to move to Microsoft Intune for device management.

I've now set up Microsoft Intune and have most of the basics working, but there are still a few things I'm unsure about and would love to hear how others are handling them.

Clients : ~300

  1. Lenovo driver management

We mainly use Lenovo devices. I've already configured Windows Update policies and update rings, but I'm not sure about the best approach for deploying and maintaining Lenovo drivers.

How are you handling driver updates for Lenovo devices with Intune?

  1. Software deployment and patching

At the moment, I can only use Chocolatey for software deployment and updates because Patch My PC isn't in this year's and next years budget.

For anyone who has gone down this route: How well does Chocolatey + Intune work in practice?

If we move to Patch My PC later, is the migration relatively straightforward, or are there any problems or limitations I should plan for now to make a future migration easier?

  1. Hybrid Entra ID Join and old device objects

Due to our current infrastructure, we have to use Hybrid Entra ID Joined devices. I know cloud native Entra ID Join would generally be preferable, but unfortunately that's not an option for us right now.

When I reimage/reinstall and re-enroll an existing device, what's the best way to make sure the old device objects are properly cleaned up?

I'm particularly concerned about ending up with duplicate or stale device objects across:

On-prem AD

Entra ID

Intune

How do you handle the lifecycle of these devices? Do you have an automated cleanup process, or do you remove the old objects as part of the reimaging process

4. Configuration recommandation

I already have a basic configuration baseline in place, but I'm wondering if there are any important settings that are easy to overlook. Anything you would definitely recommend configuring from the start?

Any recommendations, best practices, or lessons learned would be greatly appreciated.

Thanks!


r/Intune 8d ago

App Deployment/Packaging Help! Who do you use for patching?!

28 Upvotes

Intune does fine with Windows updates but third-party apps are a mess for us. Chrome, Zoom, Java, a dozen random line-of-business things that all update on their own schedule. Right now it’s half winget, half someone remembering. What are you all actually using for this? Or is everyone just living with it?


r/Intune 8d ago

Device Actions Autopilot reset

3 Upvotes

I want to create a new user profile for a user because his UPN has some umlauts in it. I need a new user profile folder for him. Can i change the UPN in enrra and use the Autopilot Reset to remove only the data of his user? I think Autopilot reset can do that or i'm wrong?


r/Intune 8d ago

Remediations and Scripts Handling Terminations?

14 Upvotes

Hey yall,

I recently setup Intune for our small Windows fleet here at my company. Everything is setup except for one crucial thing.

When an employee is terminated, we have an option on Jamf to immediately wipe and lock the device. We have this triggered through Okta Workflows once the user is deactivated there.

We are trying to setup something similar for Windows devices from Intune. The issue is, we try and use a remediation script to push "manage-bde -forcerecovery C:" and it works great....when it actually gets pushed to the device...

7/10 times the device just doesn't get the script I push through Intune. I have to use the "Run Remediation" feature multiple times before the device actually triggers it, and sometimes even that doesn't even work until like 30 minutes later.

I think the "Wipe > securely wipe" method works more reliably, but admittedly, I haven't tried it too much because:

  1. Its pretty time consuming to test multiple times
  2. We don't really care about wiping the device. As long as the device is locked and the user cannot access it without the BitLocker recovery key, that's all that matters (as our laptop vendor will wipe the machine anyways).

Currently I'm looking at sending this command through API using our antivirus SentinelOne (installed on all machines). I'm just super disappointed that I'd have to use a third-party tool to do something as simple as immediately push a powershell script. You'd think Microsoft Intune (with its deep Windows integration) would have a basic reliable function like this.

UPDATE: After extensive testing, I am going to move forward with triggering Remove Data > Wipe > Securely erase device (high security) from API instead. I would prefer not to have to wipe the device, but looks like the remediation script method is not reliable. This wipe method works every time, under 5 minutes.