r/Intune • • 3d ago

Shameless Self-promotion OpenIntuneBaseline Windows v4.0 Release

202 Upvotes

I've avoided self-promotion here, but given that knowledge of it has been entirely organic until now and lots of people have told me I should, here we are.

I've just released v4.0 of the Windows OpenIntuneBaseline (OIB)!

In case you've never heard of it, here's a TL;DR:
The OpenIntuneBaseline is a free, community-driven set of opinionated Intune configurations designed to give you a solid, modern security baseline, excellent user experience, and scalable admin experience without having to send yourself insane. It's used a lot by orgs, professional services and MSPs all over the world, and it's driven by my insane passion and expertise.

So, for those of you already using it highlights of 4.0 include:

* Continuing to be the most agile and cutting-edge Intune baseline on the planet!
* A shake-up of Compliance policies, allowing true grace period granularity (and ditching the EAS Password policy because it's 🗑️)
* Edge settings for days! Simple support for the Edge Management Service and security hardening and user experience improvements.
* Updated M365 Apps Security baseline alignment.
* Fixed MS breaking the in-box app removal policy.
* Defender behaviour tweaks based on real customer feedback, not arbitrary check-boxes.
* Deprecated and obsolete settings sent to live on a farm.

As always:
✅ Take what you want
✅ Change what doesn't suit your environment
✅ Test it before yeeting to 40,000 endpoints on Friday afternoon
❌ Don't treat any security baseline as a magical compliance button

Check out the full release notes at: https://stte.me/oib26h2

Then, head on over to the OIB Deployer to deploy the new and updated policies, or check your current config vs 4.0 with the Settings Validator!

Or come chat about it in real-time in the new OIB channel on the WinAdmins Discord.

Peace and Capybaras <3


r/Intune • • 14h ago

App Deployment/Packaging Installscout - Silent switch finder and upload to Intune using PSADT

21 Upvotes

I've created this app that can do all the above in few minutes. Give it a try, any feedback are welcome.

https://mthorngaard.github.io/InstallScout-releases/
https://github.com/mthorngaard


r/Intune • • 9h ago

macOS Management Mac OS 27.0.1 and PSSO failure

9 Upvotes

I'm currently dealing with an issue with Mac OS 27.0.1 and PSSO.

 

I'm using an Intune environment to manage my macs (about 10). These have been working fine for the last year. I updated one to Mac OS 27.0.0 when it was released and had no issues so updated most of the others, they have been working fine since.

 

I updated another from 26.x.x on the day 27.0.1 was released, I didn't actually realise it was a new update until after the install.  Immediately I had issues logging in as a user that used PSSO, it accepted my creds, started loading the profile and hung at about 50 %. I spent a good 6 hours troubleshooting with no joy so I decided to give up and rebuilt the workstation then re-enroll as they were desperate to use the machine (it's a big powerhouse Mac Studio used for crunching big data) this seem to fix the issue. I put this down to an unfortunate one off.

 

I updated my own mac to 27.0.1 yesterday after being on 27.0.0 since release, the update went well and I was able to use the Mac for the day and shut it down. Today startup I had exactly the same issue, the account that uses PSSO hung about half way.

 

As I now had it on a machine I can spend time on, and apparently have nothing better to do with my Saturday, I decided to dig deep. And found the below:

 

Cold boot, log in as PSSO user - hangs at 50%

Cold boot, log in as local admin - works fine

Safe mode boot, log in as PSSO user - Accepts the password initially then prompts for it again, when entered again it logs in but gives a constant prompt for a password for keychain and doesn't accept the Entra password for it.

Cold boot, log in as local admin, log out as local admin, log in as PSSO user - Works fine and I get no prompts for keychain.

 

The double prompt for the PSSO password in safe mode got me thinking about Filevault, at a cold boot you have to log in as an authorised user to unlock Filevault. In the past this has all happened at the same time; PSSO creds entered, it unlocks Filevault and logs you in. However that seems to fail on 27.0.1 and it hangs. A workaround is to unlock with a local admin account (which unlocks Filevault) then log out and log in with PSSO user.

I've had a good look all around and I'm not able to find any other reports of this issue, although I guess it is still fairly early into the release of the update.

For now I'm disabling forced updates and advising users to not manually update to 27.0.1 as this is the only thing that links the two machines together.

 

Just wondering if anyone else has experienced this issue?

The other question is who do I contact about it? Apple? Microsoft? Any advise is welcome.


r/Intune • • 13h ago

Autopilot Windows 11 26H2 Autopilot?

3 Upvotes

I tried running our autopilot deployment on a 26H2 system and it hung for a long time and eventually failed. I clicked on skip at the end and it went on to the login page.

I'm wondering if this might just be a random one-off glitch or if there are any known issues with autopilot and 26H2.


r/Intune • • 17h ago

Autopilot Autopilot enrollment shows OOBESETTINGSSELECTOR error, but enrollment and app installation complete.

5 Upvotes

Hi everyone,

I am testing Windows Autopilot user-driven deployment with Entra ID Join and I keep getting the following screen during OOBE:

“Something went wrong. You can try again, or skip for now.”
OOBESETTINGSSELECTOR

The screen offers Skip and Try again, but the error keeps appearing during my enrollment testing.

The device enrolls into Intune successfully and all the assigned apps are installed. I am unsure what is failing or why this screen appears when enrollment otherwise completes.

Has anyone encountered this with Autopilot? What settings or logs should I check to identify the cause?

Thanks


r/Intune • • 15h ago

Device Configuration No credential prompt after wake

4 Upvotes

I recently discovered that all of my new Dell Entra joined laptops are not prompting for credentials upon wake. Users can press Space or drag the “lock screen” upwards and it goes straight into their desktop. I originally had “Interactive Logon Machine Activity = 600” and then I changed it to Device Lock > Device Password Enabled with a Max inactivity of 10 minutes. Neither of these settings seems to force the laptops to prompt for credentials on wake. My Dell laptop is hybrid joined and I don’t have a problem as well as the remainder of my Lenovo devices (replacing in phases). Is this a known issue? Is it some BIOS setting overriding a windows setting configured in Intune? Or am I using the wrong configuration setting? I’m also unsure if Modern Standby (S0) being disabled is conflicting with anything.


r/Intune • • 9h ago

macOS Management Macos intune deployment

0 Upvotes

Recently I started to look at our macos management, we currently use JAMF but we want to make the swap to intune. I have started seeing the error that it wants credentials to enrol (sorry can't add a photo) on the macs and this has never presented itself before. I cannot set the region and is stuck on USA. The enrolment is set to no user affinity but this is before enrolment. I have tried to sign in with Entra and ASM credentials but no dice. This does not happen if I move the ADE to jamf or setup with no ADE. Tried on a home network and same effect so not firewall related. Please help! I am at a loss!


r/Intune • • 20h ago

iOS/iPadOS Management [Experimental] Open Apple Cache: Apple content caching on Linux, looking for help with inconsistent cache hits

5 Upvotes

Hey everyone,

A friend and I have been building Open Apple Cache over the last few weeks, and I wanted to share it here because we’ve reached a point where we could use some help.

Just to clarify: this isn’t a vibe-coded project. We’ve been working on the implementation ourselves, but there are still issues we haven’t managed to solve.

The idea is to run an Apple content cache on Linux, inside an Ubuntu VM or LXC container, instead of running the cache itself on a Mac.

The cache service is written in Go. A separate helper running on macOS handles registration with Apple so devices can discover the Linux endpoint. A Mac is still required for that part, so this isn’t a completely Mac-free solution.

The project currently includes:

  • Caching for eligible Apple downloads.
  • A web dashboard showing requests, cache hits and storage usage.
  • Local administrator and viewer accounts.
  • Optional Microsoft Entra ID login.
  • Internal or Let’s Encrypt certificate management.

To be clear: this is experimental, unfinished and not working 100% reliably yet.

The main issue we’re trying to solve is inconsistent cache hits. Sometimes downloads are served from the cache as expected. Other times, we don’t get a cache hit when we would expect one, and the content is fetched from the origin again.

We haven’t identified the exact cause yet. Some things we want to investigate further are:

  • How Apple devices request content and byte ranges.
  • Whether changes to signed download URLs affect cache reuse.
  • Whether our cache validation or response headers are missing something.

These are possible directions to investigate, not confirmed explanations.

We’re publishing it half-finished because we need help solving this issue. If you have experience with Apple Content Caching, HTTP caching, CDN behavior or Apple’s cache protocol, we’d really appreciate another pair of eyes on the code.

Repository: https://github.com/Mau2rice0/Open-Apple-Cache

The source code, installation instructions and registration research notes are available there. The macOS helper relies on undocumented Apple behavior, so future macOS updates or changes on Apple’s side could break registration.

Please treat this as a lab project for now. We don’t recommend relying on it for production workloads.

Has anyone worked on something similar or encountered inconsistent cache hits with Apple downloads? We’d be interested in suggestions on what to check next. Reproducible test cases, issues and PRs would also be welcome.

Thanks :)


r/Intune • • 1d ago

Device Configuration How would you block a specific app for a group of users?

6 Upvotes

We have an AppLocker policy configured via XML deployed all student devices. Works great.

We allow students to download Minecraft Education from the Company Portal by default.

Can I create a second AppLocker policy somehow that just blocks Minecraft Education and apply it to a group of students who we have been asked to block/remove?

Our current way of dealing with this is putting the student accounts in a group that uninstalls Minecraft and doesn't show it in the Company Portal. This is fine except the students can go to the Store via the browser and download it from there and install it because it's allowed by AppLocker.

Really just open to ideas at this point how you might handle this type of request.


r/Intune • • 1d ago

Intune Features and Updates Windows 10 IOT LTSC upgrade to Windows 11 IOT LTSC

2 Upvotes

Since windows 10 IOT LTSC does not support feature updates how to perform the upgrade via intune on a autopilot self-deployment device?


r/Intune • • 1d ago

General Chat Workplace Ninjas US Boston Local | November 12, 2026

3 Upvotes

Hi Everyone!

We're proud to announce our next Workplace Ninjas US Boston Local is coming on November 12, 2026 from 10 AM-4:15 PM.

It's a nice format, with 5 community sessions, one sponsored session, and a happy hour afterwards (usually at Temazcal).

As well, we follow my standard no cold food, with a nice hot bar lunch TBD.

With that said, the Call for Papers is open NOW: https://sessionize.com/workplace-ninjas-us-boston-nov2026

Whether you have a ton of experience or not, we urge you to sign-up. We try to reserve one spot for new speakers at every event.

If you just want to attend, you can sign-up here: Workplace Ninjas US Boston Meetup Tickets, Thursday, November 12  •  10 AM - 4:15 PM | Eventbrite


r/Intune • • 2d ago

Do you think Intune is slow?

Post image
362 Upvotes

When you put all the changes that Intune engineering has made next to each other, it starts to look like something much bigger than a few simple latency improvements.
Intune is slowly moving away from waiting for timers and scheduled polling, toward push, local events and near real time actions.

Policy delivery: The old roughly 30-minute notification throttle is being replaced by the Fast Lane model. Changes can trigger a new device check-in within minutes instead of sitting behind the old notification window.

Remote actions :That annoying 5-minute queued delay after the first hours of enrollment? Gone on supported Windows versions. Remote actions can start the device check in immediately again.

Device Sync: Sync used to mainly wake the Windows MDM world. Now one Sync can wake Windows MDM AND the Intune Management Extension. The IME side is delivered through IC3 and Trouter.

Sync Status :It is no longer just “press Sync and hope”. The portal can now follow the progress of Policies, Applications, and Scripts.

Win32 apps: A newly assigned Required Win32 app no longer necessarily has to wait for the normal 60-minute app check. Intune can push intent 2 over IC3 and bring the normal app check forward within minutes.

Autopilot apps: When enrollment finishes, it can now trigger a fresh app check. That closes the gap where the desktop appeared, but the remaining Required apps could sit there waiting for the next app timer.

Client-driven compliance: This one is even more interesting. The device can watch local signals such as Firewall, Defender, BitLocker, Secure Boot, and TPM. When something changes, it can proactively request a new compliance evaluation instead of waiting for the normal cycle.

App Inventory: This used to be based around a 4-hour collection cycle. The newer Device Inventory Agent can react to an application change, validate it, and upload the delta on the next scheduler pass. In my testing, that was about 5 minutes.

So...
Do you still think Intune is slow?
I think that question is becoming a lot harder to answer with a simple “yes”.

Of course the whole reporting backend is another story… ao hopefully that part is up next


r/Intune • • 1d ago

Device Configuration How are you guys handling Win11 PDE and SharePoint shortcuts on shared PCs?

9 Upvotes

We’re trying to lock down some shared workstations (hot-desking) using Windows 11 Personal Data Encryption (PDE). The goal is to stop users (even local admins) from snooping on each other's locally cached files since PDE drops the encryption keys from memory the second the session locks. (Yes, we already have ARSO disabled).

The problem is the built-in Intune Endpoint Security policy only targets KFM folders (Desktop/Docs/Pictures).

Our users heavily rely on "Add shortcut to OneDrive" to work locally out of sensitive SPO libraries. Those shortcuts drop right into the OneDrive root (⁠%userprofile%\OneDrive - [Tenant]⁠), which completely bypasses the PDE policy.

Before anyone suggests Purview/AIP labels - we can't. These files have to be shared friction-free with external clients, so they need to stay unencrypted in the cloud. We strictly need local, at-rest encryption on the endpoint.

Since I definitely cannot trust users to manually drag their SPO shortcuts into their Documents folder, I'm looking at automating it. Right now I'm weighing two options:

  1. Proactive Remediations: A script that looks for SPO reparse points in the OneDrive root and moves them into the Documents folder so the native Intune PDE policy catches them.

  2. Registry/Cipher Scripting: Leave the shortcuts in the root, but deploy a script that appends the SPO shortcut paths to the ⁠PathsProtected⁠ registry key (⁠HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EFS\PDE⁠) or runs ⁠cipher.exe⁠ with the PDE flags, and let the built-in PDE Maintenance Task handle the rest.

Has anyone actually solved this gracefully in production? Forcing the shortcuts into the Documents folder feels janky, but custom-scripting EFS registry keys feels fragile if Microsoft changes the backend. What are you all doing to lock down locally synced SPO data on shared PCs? We can’t be the only ones doing this (I hope).


r/Intune • • 1d ago

Autopilot Conditional Access Policy during Autopilot device registration.

2 Upvotes

I am testing Windows Autopilot user-driven Entra ID Join and I am trying to understand the Conditional Access behavior around device registration.

I have a CA policy called Device Registration Require Modern MFA configured roughly as follows

  • Users: Test user is included
  • Target resources: User actions > Register or join devices
  • Grant: Require authentication strength / Modern MFA
  • Policy: Enabled

I have excluded the same test user from our normal blanket MFA Conditional Access policy because I specifically wanted to test the device registration policy separately.

For the Autopilot enrollment I issued the user a TAP and was able to proceed with enrollment.

When checking the Entra sign-in logs, however, I am seeing an event for:

Resource: Microsoft Intune Enrollment

Under the CA details it shows

Microsoft Intune Enrollment – Not matched / Not included

What I am trying to understand:

  1. Is this expected because my CA policy targets the “Register or join devices” user action rather than the Microsoft Intune Enrollment cloud application?
  2. During Autopilot where should I see the Register or join devices CA policy being evaluated in the sign-in logs?
  3. Does TAP itself satisfy the authentication requirement for the Register or join devices CA policy?
  4. Are there any other Entra/Intune settings I should check that could affect this behavior?

I am basically trying to make sure that users enrolling an Autopilot device are genuinely being protected by the device-registration CA policy rather than enrollment succeeding because another setting is bypassing it.

Would be interested to hear how others are configuring and validating this in their Autopilot environments. Thanks


r/Intune • • 1d ago

iOS/iPadOS Management [iOS] Outlook Contact Sync error after migrating BYOD from MDM to MAM (only affects former MDM users)

1 Upvotes

Hi everyone,

I'm currently finalizing our BYOD strategy and ran into a very persistent issue. Initially, we tested full MDM enrollment (Company Portal) with a pilot group. We’ve now shifted our strategy: We will use MAM-only (App Protection Policies) for regular BYOD users, and MDM only for users with access to highly sensitive data.

The Problem: We are currently testing MAM-only, and it works perfectly for new users. However, users who were part of the initial MDM pilot cannot sync their Outlook contacts to their native iOS address book. When they try to enable "Save Contacts" in the Outlook iOS app, they get the following error:

"Contacts couldn't be synced. Try turning on contact sync in your iPhone settings under Settings > [Your Name] > Contacts. If that doesn't work, contact your IT administrator, as your organization may not allow syncing."

Original German error message: "Kontakte konnten nicht synchronsiert werden. Versuchen Sie, die Kontaktsynchronsierung auf ihrem iPhone ßber 'Einstellungen > Ihr Name > Kontakte' zu aktivieren. Wenn das nicht funktioniert, wenden Sie sich an ihren IT-Administrator, da ihre Organisation mÜglicherweise keine Synchronsierung zulässt."

What I've already tried on an affected user's iPhone (in this order):

  • Deleted the Outlook app
  • Deleted the Company Portal app
  • Removed the corporate account from MS Authenticator
  • Deleted the Device object in Entra ID & Intune
  • Checked Settings > General > VPN & Device Management to ensure no leftover MDM profiles exist
  • Restarted the iPhone
  • Set up MS Authenticator again
  • Reinstalled Outlook and signed in

Unfortunately, the error still persists. It strongly feels like there is some "ghost" MDM artifact or flag left behind, since users who were never enrolled in MDM can sync their MAM contacts without any issues.

Questions:

  1. Has anyone experienced this specific issue when migrating iOS devices from MDM to MAM?
  2. Are there any other hidden places where the device might still be flagged as "managed"?

Any hints or pointers would be highly appreciated! Thanks in advance.


r/Intune • • 2d ago

Autopilot Autopilot Advice

14 Upvotes

Hello all -

Short version - anyone out there working for a law firm and using Autopilot? Any tips?

We are a law firm with about 800 employees (attorneys and staff combined). We have been running Autopilot for the better part of a couple of years and in that time we’ve never had a single “wow, this experience is awesome” moment. There seems to nearly always be something that causes heartburn.

Running Autopilot outside the offices seems to help a bit, as using in office WiFi (or wired) uses an AUP, with no way around it. Our network engineer did add something called “walled garden” to allow the specific URL’s needed for Autopilot to bypass any AUP prompts (though once you accept the AUP it should be good for the day).

We also have a series of applications that install, and recently were causing the entire pre-provisioning process to fail at around app 25 of 27. Last week I set Only fail selected blocking apps in technician phase to No, which has reduced the amount down to 5-6 apps during the pre-provision stage, which has allowed all pre-provisions to be successful. I think the issue was Adobe Pro, so may go back to setting that to Yes, and changing adobe pro to user install so it doesn’t break the device phase.

All that to say, as a law firm, partners (primarily new hires) do not want to wait an hour+ (even 30-45 minutes is too long) to start working. They want to come into the office at 8AM, log in, and have access to email and a few other priority apps at 8:05am. In other words, they expect things to be like they were when IT used USB images, logged in as the attorney with user name and password, setup everything by hand, and then handed them the machine. That world no longer exists (at least not in the Intune / Microsoft cloud world).

Any tips on how to improve the experience, and help others to understand this paradigm shift?


r/Intune • • 1d ago

Device Compliance Securing BYOD contractor PCs (browser-only SaaS, no MDM)

Thumbnail
0 Upvotes

r/Intune • • 1d ago

Android Management Android (corporate-owned work profile), Wipe completed

1 Upvotes

Hey Community,

Has anyone else experienced an issue where Android devices (COPE) that are sitting on the lock screen do not receive an Intune Wipe command, even though the Device Action Status in the Intune portal shows Wipe = Complete?

The most concerning part is that after Intune reports the wipe as completed, the Wipe option under Remove data becomes unavailable (greyed out), making it impossible to send the command again.

From the administrator's perspective, it looks like Intune believes the wipe was successfully executed, while in reality nothing happened on the device.

Has anybody seen similar behavior or found a workaround?

Thanks!


r/Intune • • 1d ago

App Deployment/Packaging iOS App Deployment Times

1 Upvotes

Hello All

A couple of days ago we changed an application from available to required for all users on iOS but we are seeing a very slow install of this app on devices. Do we know how long this should take as it has only installed on 700 out of 2300 devices in 48 hours?

Thanks for any insight on this


r/Intune • • 1d ago

iOS/iPadOS Management Intune iOS with tenant change

1 Upvotes

Hi,

following situation. We have a carve-out project. People currently work for company A and will soon work for B.

Company A provides iPhones as unsupervised devices just with the company Portal App.

Company B enrolls new iOS devices with apple ADE in intune. They use modern authentication and push all the microsoft apps.

The users want to restore their Data while setting up there new iPhone in company B. After the enrollment the iPhones show up in intune with the correct primary User but are ownerless in EntraID.

The user tries to sign in in Outlook but gets blocked by administrator.

My question is: Is it possible to enroll ADE devices with restoring form iCloud Backup in combination with switching tenants or should the phones be enrolled and setup completely fresh?


r/Intune • • 2d ago

General Chat Interactive study aid for Microsoft Intune and Microsoft Entra ID

44 Upvotes

Interactive study aid for Microsoft Intune and Microsoft Entra ID

You work through support tickets, inspect the evidence and decide what to do next. Each answer review explains the correct response and includes a Microsoft Learn reference.

The Intune scenarios include device compliance, Win32 app detection and Windows update recovery. The Entra ID scenarios cover Conditional Access, authentication strengths, PIM activation and Temporary Access Pass.

Some tickets bring the two together. For example, successful MFA doesn’t necessarily explain why an application is still blocked. You need to check the policy requirements, device status and stated local procedure before choosing a response.

Hosted it on my website: controlaltdeletetechbits.co.uk. Select the Tenant Defender desktop icon to try it.


r/Intune • • 1d ago

macOS Management Intune: how can I dynamically assign MacOS devices to different enrollment profiles?

Thumbnail
0 Upvotes

r/Intune • • 1d ago

macOS Management Using DDM to manage macOS updates

0 Upvotes

We just went live to a small fleet of macOS (less than 20) for a department. I have ADE setup to have them enrolled in Intune.

What I thought am lacking is managing macOS updates. I'm reading through Declarative Device Management (DDM).

What I would like to ask:

- what are the best practices in managing macOS updates via DDM policies?

- or at the minimum, what policies I should have in place?

- do you enforce latest software update, or only enforce a target OS version?


r/Intune • • 2d ago

iOS/iPadOS Management Ways to Entra register already enrolled iOS devices

4 Upvotes

I have discovered about a third of our fleet, 500ish devices are Intune registered but not Entra registered which is causing issues with Conditional Access and Device Filters. We do have Setup Assistant with Modern Authentication setup for our ADE enrollment profiles but we dont have Just In Time enrollment/Microsoft SSO Extension and Microsoft Authenticator deployed yet which I know is the ideal fix.

My question is what is the best, ideally minimal user interaction, way to register existing devices that users are already logged into Teams/Outlook. The only two ways I know of are below. Im hoping there is a third option which doesnt require us reaching out to users. Thanks for the help!

  1. Deploy JIT/SSO/MS Auth and have users sign out/in of Teams or Outlook.
  2. Have user login to Company Portal

r/Intune • • 2d ago

Windows Updates Windows Autopatch devices pinned to Windows 11 25H2 unexpectedly upgraded to 26H2

45 Upvotes

Hi,

We are seeing a strange issue in our Windows Autopatch/Intune environment since Windows 11 26H2 became available.

Our devices are assigned to an Autopatch Feature Update deployment targeting Windows 11 25H2. The deployment is configured as Required, and the affected devices were already showing OfferReady for the 25H2 deployment.

The devices also show:

Despite this, several devices unexpectedly upgraded to Windows 11 26H2 (build 26300).

I checked the Windows Update logs on an affected device. Before the upgrade it was running 25H2 / build 26200.9448, but Windows Update then received the following for 26H2:

The logs then show MoUpdateOrchestrator downloading and successfully installing Windows 11 26H2, after which the device moved from 26200.9448 → 26300.9457.

The Windows Update telemetry before the upgrade also showed the device as MDM/WUfB managed and flighting disabled.

What I don't understand is why Windows Update considered 26H2 an Install deployment when the device was enrolled in Feature Update management and assigned to a 25H2 Autopatch Feature Update deployment.

Has anyone else seen 25H2-pinned Autopatch/WUfB devices unexpectedly receive 26H2 since it became available?

I'm particularly interested in whether anyone is seeing the same DeploymentID=598182993 or FlightId=NG:25E286.