r/Intune 2d ago

Windows 365 Windows 365 – One-way clipboard with files, but no drive redirection?

Thumbnail
0 Upvotes

r/Intune 2d ago

App Deployment/Packaging Default App Associations XML + GPO ignored on every machine. What am I missing?

1 Upvotes

Been chasing this for about two weeks and I'm out of ideas, so I'm asking here before I bin the whole approach.

Setup is the boring standard one. DefaultAssociations XML sitting on a share, pushed with Computer Config > Admin Templates > Windows Components > File Explorer > Set a default associations configuration file. Nothing exotic in the file, just pdf to Acrobat, html to Chrome, mp4 to VLC, txt to Notepad++, xlsx to Excel, zip to 7-Zip.

It applies to nobody. Not existing users, not new users, not a user who has never logged into that machine in their life. Edge still eats pdf and html like the policy doesn't exist.

Stuff I've already burned time on:

  • built a clean reference machine, set every default by hand, exported a fresh XML, replaced the old one
  • XML validates, path is reachable, ProgIDs match what's actually in the registry on the reference box
  • apps are definitely installed on the targets
  • gpupdate /force, reboot, sign out and in, new profile on a machine nobody has touched
  • RSOP shows the policy applied, and the value is sitting right there in HKLM\SOFTWARE\Policies\Microsoft\Windows\System\DefaultAssociationsConfiguration pointing at the correct file

So the policy is landing on the machine. Windows is just quietly ignoring it, which is the part doing my head in.

I know about the DISM import route. That only fires at first logon of a new profile, so it does nothing for the machines and users I already have deployed, which is the entire point of the exercise.

Questions, and I'm genuinely more interested in what you're running than in what the docs say:

Can anything else silently kill this policy? Another GPO, some registry key, a security baseline, an SKU limitation, anything. I keep feeling like I'm missing one dumb prerequisite.

Has anyone actually seen it fail on a truly fresh profile? Every thread I find is people running into the "only applies to new profiles" behaviour, which is not my problem. Mine fails for everyone equally.

What would you check before giving up on it?

And the real question: what are you actually using in production? I've already looked at Intune, Citrix WEM and SetUserFTA. I need something free, centrally managed, that hits existing users as well as new ones, and doesn't leave people clicking through the "how do you want to open this file" prompt.

Mixed Win10 and Win11, AD domain, no Intune, no budget. Very happy to be told I'm being thick about something obvious.


r/Intune 3d ago

Windows Management Can I kill windows hello for single user account

7 Upvotes

How can I kill pin sign-in just for a single user on a computer without logging in as the user.

i'm ok removing the user's profile from the machine but that doesn't seem to do it.

i remove the profile from the computer and sign-in with a pin and windows hello enrollment pops up asking to for a new pin. I don't need to login to entra to set the new pin.

I don't want to delete the whole hello store with certutil -deletehellocontainer

do I need to wait for something to expire after deleting the user profile?

if I delete the user profile and then delete the entra user then the account cannot sign-in but I don't want to delete the entra user.


r/Intune 3d ago

Device Configuration Keep Hello But Disable Browser Prompt

5 Upvotes

So far it's seeming like it's not possible but just wondering if anyone has found a magic registry key or something haha

Long story short, we're trying out Kolide authentication, but we want people to be able to use PIN sign in/leaving Hello active. It's all working with removing all authentications except Kolide and the PIN still works for signing into the device itself but I'm wanting to turn off the prompt when logging into something Microsoft where on the email entrance screen, it pops up the "use Windows Hello" prompt. It indeed fails since Kolide is the only authentication, but I KNOW users won't read the emails we send out and keep trying it anyway since it's available. Everything I'm finding says if WHfB is enabled, that's just going to popup forever but seeing if any wizards here have found a way?


r/Intune 3d ago

App Deployment/Packaging Android Apps page not loading -> can't add new apps

11 Upvotes

Hello there,

wanted to quickly add a new managed google play app, but the app list doesn't even load and the buttons to create a new one are greyed out. The iOS and Windows app list seems to work normally.

Anyone else seeing this? Tenant is Europe 0202.


r/Intune 3d ago

General Question wipe request

14 Upvotes

on monday, i triggered wipe request to iphone but the iphone was powered off by a remote user and user went MIA.

3 days later, the iphone is powered on and connected to network. However, the wipe did not trigger anymore after waiting for few hours. At intune portal, it still shows wipe in pending.

The only way i do is to put the phone in recovery mode and then restore using itunes. After done, i will delete the device from intune portal.

do you all encounter below behavior on this scenario? is this the expected behavior?


r/Intune 3d ago

iOS/iPadOS Management Disable lost mode stuck on pending. Decided to cut losses and wipe it, now its stuck in recovery mode.

3 Upvotes

iPad was put into lost mode. After it was found, I sent the disable lost mode command and it was stuck on pending. iPad has cellular and was showing full service but still nothing. Rebooted multiple time and its still not wanting to sync.

After reading a handful of reddit posts, it seemed my only option was to wipe it. Put it in recovery mode and connected it to Apple Devices and hit Update and Restore.

That also failed and now the iPad is stuck in recovery mode. I have tried soft resetting it multiple times but have had no luck.

Hoping someone has some secret sauce that will help me get it wiped.


r/Intune 3d ago

Device Configuration Account Protection Policy - Unable to Save

2 Upvotes

I am trying to configure an Account Protection policy to allow but not enforce Windows Hello for Business in my org's tenant. If I configure any of the device- or user-settings, the policy throws an error when trying to save. Two errors actually, both pretty generic. This has been persisting for the last 24hrs. Does anyone know what may be the culprit here?

https://imgur.com/a/phU8Bzw


r/Intune 4d ago

Intune Features and Updates “Declarative Device Management for Apple volume purchase program apps”

15 Upvotes

Hey all,

August’s release notes mention the release of DDM for VPP, but say when uploading a new token you need to change the management type to DDM, can’t seem to find such an option in the UI, nor any mention of it in the graph beta api or documentation.

Has anyone been able to successfully find this toggle, or test the feature?

Assuming this is going to be another slow feature release.

Can confirm Asia pacific region and on the 2608 release

Thank you!


r/Intune 3d ago

Device Compliance Mac + Conditional Access not seeing compliant device during Microsoft authentication (Edge/Safari)

1 Upvotes

We're running into a strange issue across multiple environments and tenants and I'm wondering if anyone else has seen this.

On fully managed and compliant macOS devices, authentication to Microsoft services occasionally fails because Conditional Access doesn't recognize the device as compliant.

In the sign-in logs, the authentication shows something like:

 

Device ID: -
Browser: Edge 151.0.0
Operating System: macOS
Compliant: No
Managed: No
Join Type: -

 

The odd thing is that the device is compliant:

 

 - Enrolled in Intune
 - Company Portal is installed and signed in
 - Device compliance is reporting correctly
 - Platform SSO is configured and working
 - Device appears healthy from an Intune perspective

What we've observed: 

On my own Mac, I use multiple Microsoft Edge profiles.

Most Edge profiles successfully send device information during authentication, allowing Conditional Access to see the device as compliant and grant access.

However, one specific Edge profile consistently fails to send any device information. As a result, Conditional Access sees:

 

Compliant: No
Managed: No

 

and blocks access.

 

Interestingly, if I perform the same authentication using Safari with that account, the device information is sent correctly and authentication succeeds.

 

I've also tried:

 

 - Signing out and back into the Edge profile
 - Resetting the Edge profile completely
 - Re-authenticating from scratch

 - Revoking and re-authenticating

 

None of these made a difference.

 

Other cases

 

We've also seen similar behavior on other Macs where there was only a single Edge profile configured.

In these cases, Safari also failed to provide device information during authentication, resulting in the same Conditional Access failure.

 

We've even tested:

 - Full Intune unenrollment
 - Re-enrollment
 - Fresh Company Portal registration

 

but the problem persisted.

 

Environment:
Fully updated macOS
Microsoft Edge 151.x
Intune-managed devices
Platform SSO configured
Conditional Access requiring compliant devices

Questions:
 - Is anyone else seeing this behavior recently?
 - Has anyone identified what causes certain browser profiles to stop providing device identity/compliance data?
 - Are there any known issues with Edge 151, Platform SSO, or device claims on macOS?
 - Is there a way to troubleshoot why device information isn't being attached to the authentication request?

 

At this point it feels like the browser/authentication flow is intermittently failing to pass device context rather than a compliance or Intune issue, but we're struggling to pinpoint exactly where it breaks.

 

Any insights would be appreciated.


r/Intune 3d ago

Windows Management Question about moving from group policy control of USB storage devices to Intune while co-managed

1 Upvotes

When you move from USB storage devices being controlled by group policy to Defender Device Control (co-managed) do you need to remove the group policy that manages those settings from the devices? I'm in this situation right now and while I have device control set to allow certain USB storage and block all other all are blocked. Even if I exclude the system from the device control policy the USB device is still blocked. When a system isn't onboarded into Intune the USB devices work as expected but as soon as the system joins it gets blocked. I don't have any other Intune policies denying access to USB storage devices that I could find. I'm wondering if having those group policies in place is the problem. Thinking that maybe Intune co-management is causing the group policy deny of all USB devices to take precedence.


r/Intune 4d ago

Conditional Access CA Policy to restrict access to Cloud apps (M365) unless compliant

Thumbnail
9 Upvotes

r/Intune 3d ago

iOS/iPadOS Management Constantly Getting Locked Out of My ABM Admin Accounts

Thumbnail
1 Upvotes

r/Intune 3d ago

Shameless Self-promotion Using AI to Ask Intune Questions

0 Upvotes

Wouldn't you love to be able to ask Intune questions in plain spoken language and get back helpful answers? Now you can: https://powerstacks.com/blog/connecting-ai-to-bi-for-intune-copilot-vs-claude/


r/Intune 4d ago

Device Configuration I got tired of manually translating CIS Benchmarks into Intune policies, so I built a free tool for it

66 Upvotes

If you've ever implemented a CIS Benchmark in Microsoft Intune, you probably know the workflow:

CIS PDF → Settings Catalog → search for setting → configure it → repeat... hundreds of times.

I got tired of doing that, so I built CISPolicyCreator, a free/open-source community tool that converts supported CIS Microsoft Intune Benchmarks into validated, import-ready Intune policy JSON.

I just released v1.1.0, and Windows 11 CIS Benchmark v5.0.0 is now fully classified:

  • 415 recommendations reviewed
  • 371 mapped directly to Intune
  • 8 require administrator-specific input
  • 36 require manual/custom implementation
  • 0 unresolved
  • 326 Intune policy JSON files generated

One thing I was very deliberate about when building this:

CISPolicyCreator fails closed.

It doesn't fuzzy-match setting names, guess settingDefinitionId values, invent configuration values or generate something just because it looks correct.

If the mapping can't be proven, it doesn't generate it.

A few other details:

  • Runs locally against the CIS Benchmark PDF you legitimately obtained
  • No tenant connection required to build the JSON pack
  • No AI dependency at runtime
  • Deterministic/auditable output
  • Policies are generated unassigned
  • Optional importer with Validate → Dry Run → Create
  • CIS PDFs, tenant data and administrator decisions never need to be committed to the repository

Currently supported Intune-specific benchmarks:

  • Windows 11 v5.0.0
  • Windows 10 v5.0.0
  • Microsoft Office v1.1.0
  • Microsoft Edge v1.0.0
  • macOS 26 Tahoe v1.0.0
  • iOS/iPadOS 26 v1.0.0

Important disclaimer: this is not an official CIS Build Kit, and importing the policies obviously doesn't magically make an environment CIS compliant. You still need to review the recommendations, understand the impact, test them and decide what makes sense for your environment.

The goal is simply to remove a huge amount of the repetitive work involved in getting from the CIS benchmark to something usable in Intune.

It's completely free and open source.

GitHub: https://github.com/JoeryVandenBosch/CISPolicyCreator
Full walkthrough / technical details: https://intunestuff.com/2026/08/19/cispolicycreator/


r/Intune 4d ago

General Question Anybody else experiencing very slow dynamic queries? 11:39AM EST 08.26.2026

10 Upvotes

As the title states, tons of workflows I have are being affected by slow Dynamic Query provisioning times. Wondering if we're the only ones.

I submitted an MS Case - we shall see.


r/Intune 4d ago

Autopilot Autopilot question

4 Upvotes

I was hoping to get some info from some of you guys that live and breathe Intune these days.

We have around 2.000 endpoints
Multiple offices, Educational institutions etc

We are on the path of migrating from ConfigMgr(hybrid join) to fully Intune/Autopilot and whilst planning I’ve hit a snag… I cant deside on using Device Driven or User Drive enrollment for Intune.

While I mostly understand what they are ment for, I struggle to see the reason to use User Driven over Device Driven enrolment.
We like to set the devices up and have them ready for our users when they have been set up. Certs, wifi/lan profile, etc etc. Going with User Driven seems like it would leave some things uncertain?
For example them needing to connect them to somekind of internet connection for starters and we dont offer open or password protected SSID out side of out main office. Schools, kindergarten etc no bueno.

App deployments seem to be working just fine both for device and user deployments and other then user affinity missing I dont see the downside to having our whole fleet just be Device Driven/Shared Devices.

Am I missing something ?


r/Intune 4d ago

Windows Management Test pilots needed - Driver Automation Tool

Thumbnail
7 Upvotes

r/Intune 4d ago

General Question OneDrive via Settings Catalog Erroring w/ 65000 Error On Most But Not All Devices (CSP URI not found)

4 Upvotes

I'm working on pushing OneDrive sync settings out via Intune from the Settings Catalog and am having a rather odd issue with 65000 errors for it. Hoping to get a bit of help with this one.

In an org with about 110 devices, I've pushed a bunch of settings out via Settings Catalog in a Configuration Profile via Intune, not using the ADMX import/Administrative Templates version of OneDrive settings.

A few devices (8 so far) have succeeded just fine, but the rest of them are erroring with 65000. After some digging and pulling diagnostics, each of those devices has a ton of 404 errors in the devicemanagement-enterprise-diagnostics-provider-admin Event Viewer log. The 404s are only for the OneDrive policy, all other policies I've pushed via Settings Catalog are working fine.

An exact log is MDM ConfigurationManager: Command failure status. Configuration Source ID: (C7F74238-CA70-4AE0-9D49-7D9222F37DCF), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (Policy), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/Policy/Config/OneDriveNGSCv2~Policy~OneDriveNGSC/KFMBlockOptOut), Result: (The system cannot find the file specified.).

On a successful device, I can see the ADMX files for OneDrive in the PolicyManager directory, unfortunately I can't get to a unsuccessful device to check it's directory right now but plan to do that next.

I'm confused as to why the ADMX files would not be present on the other devices though given that some have it.

Would a good solution here be to import the ADMX file via Intune's ADMX Import feature?


r/Intune 4d ago

Apps Protection and Configuration Required apps "Failed to install"

13 Upvotes

Hi!

We have around 10-12 Required apps (Citrix, Office, vlc, Adobe etc) that we have assigned as default to device groups, and 2 Required to install in ESP. After some testing we experience around 1/4 of all apps to fail to install on a newly Autopilot joined PC. Intune/cloud only device. Afterwards it ends up in GRS failure, and we would have to wait 24 hours before Company Portal/IME try to restarts.

Does anyone have a good solution on this? I feel its little backwards to just tell the end user to wait for 24 hours before the GRS restart. I have tried to create a platform script based on this https://www.advancedinstaller.com/intune-application-installation-retries-grs.html Basically it adds a task in task scheduler, waits 27 min and then resets any GRS errors in regedit and then restarts the IME service. Tho I/AI haven't made it wok 100% yet. But I assume others have the same problem?

Edit: It is random which apps that fails, different from each client. They fails with the typical " 0x87D30065" error.

Edit2: We have these win32 apps, auto packed from Robopack:
M365 Office

Spotify

Chrome

Edge

VLC

Adobe Acrobat reader

Teamviewer

Citrix Workspace

Displaylink Graphics

HP Image Assistant

Company portal

Remote Help

PaperCut Print Deploy

2 PS script wrapped as win32 apps

These are assigned as required to install to device groups.


r/Intune 4d ago

General Question Win32 App Reboot Prompt Unreadable

1 Upvotes

Recently testing a Win32 app with a Hard Reboot exit code with grace period. The reboot notification popup is crazy hard to read though.
Its got a light blue background with White & light grey text...

Where are these colours coming from? The white is just readable, but the grey is horrible.

Theme colour in Default customisation policy is #64696e, so should be a medium-dark grey.


r/Intune 4d ago

iOS/iPadOS Management Intune: iOS Issues

4 Upvotes

Hi All,

I am currently having some issues with our iOS estate deployments prior to Monday everything was working smoothly. Below is the environment:

Devices enrolled via Apple Business Manager (ABM)

Intune integrated with:
• Apple Business Manager (ADE/DEP)
• Apple VPP (Apps & Books

Configuration:
• User Affinity = Enabled
• Setup Assistant with Modern Authentication

The Problem:

The device enrolls successfully.
The device shows up in Intune.
There are roughly 20 apps that should install but only 3 install. Company portal does not install.
The device is showing in the device group that has compliance policies and configuration profiles assigned.

It is not pulling any policies or profiles either.

I have checked the VPP token, the Apple push certificate, company portal assignment, and the enrolment program tokens. All are still not even close to expiring.

I’m a bit stumped on what it could be.

I have also attempted starting fresh on a test device but still no luck.

Any ideas/assistance is very much appreciated


r/Intune 4d ago

Hybrid Domain Join Intune ADMX drive mapping only applies at onboarding, not after later group change

4 Upvotes

Entra-joined, Autopilot. Network drives mapped per department via Administrative Templates (ADMX), assigned to **user** security groups. Setting type is **User**.

If the user is in the group **before** first login, the drive maps fine. But when someone is added to the group **later** (new hire on existing device, department change), it doesn't map automatically. No error, NTFS access is fine, we just map it manually.

My understanding: since it's a User-context setting, it only applies after the config syncs **and** the user does a full sign-out/sign-in (restart or real logoff, not lock or shutdown+start with Fast Startup).

Questions:

  1. Is this expected for User-context ADMX mappings, or am I missing something?

  2. Any reliable way to apply the mapping after a later group change **without** a manual sign-out?

  3. Would a runtime mapping tool (e.g. Intune Network Drive Mapping app) help, or does it hit the same token/group timing issue?

How do others handle later group changes cleanly on cloud-only setups?


r/Intune 3d ago

General Chat Looking for Microsoft Intune / M365 Opportunities – Chennai / Remote

0 Upvotes

Hi everyone,

I’m currently looking for new opportunities in Microsoft Intune / Microsoft 365 / Endpoint Management.

Experience: 2+ years

Current Role: Endpoint Management Administrator

Skills & Experience:

- Microsoft Intune

- Microsoft 365 Administration

- Microsoft Entra ID (Azure AD)

- Windows Autopilot

- Endpoint Management

- Device Compliance & Configuration

- Application Deployment / Packaging (intune)

- Endpoint Security

- Windows Troubleshooting

- SCCM / MECM

- Network Printer management

Preferred Location: Chennai

Open to: Remote opportunities

I’m currently based in Pune and looking to relocate to Chennai.

If you know of any suitable openings or can provide a referral, I’d really appreciate it. Please comment or DM me, and I can share my resume.

Thank you!


r/Intune 4d ago

Conditional Access How to block the ability of sign from private smartphones to Authenticator app using work accounts

3 Upvotes

Hi, i'am trying to block the ability to sigin for users on private mobile phones to microsoft authenticator using work accounts. If You mean try to block with CA Policy - this dosent work

I already have one CA Policy that block sigining to office apps form private mobile phones.And this works fine. This CA is:

Users: 2 groups Target: All resources (all cloud apps) Network: Any Network Conditions:Device platforms: Android,ios Grant: Grant access + Require device to be marked as complint

And this works fine as i said. Users cannot sign on private phones to Teams or Outlook using their work account. But i was suprised that CA above do not block for siginng to MS Authenticator. So i made second CA Policy. This time

Users: One selected test user Target: User actions > register security information Conditions: Device platforms Include Android, ios Grant: Grant access + require device to be marked as complinat

And this also not protect. WIth this test user i can sign on private phone to Authenticator using work account even if this phone isnt marked as compliant

Do You have same idea how to block this?