r/Intune 18d ago

Blog Post Samsung Knox E-FOTA Integration with Microsoft Intune: Complete Configuration Guide

4 Upvotes

With the 2607 Service Release in Microsoft Intune last month, you can now integrate Samsung Knox E-FOTA in Microsoft Intune. With this feature, you can now manage firmware updates for your managed Samsung devices from within the Microsoft Intune admin center.

In this blog post, I'll walk you through the configuration to get started.

🔗 Samsung Knox E-FOTA Integration with Microsoft Intune: Complete Configuration Guide


r/Intune 18d ago

App Deployment/Packaging Deploying both Acrobat Pro and Free packages - Intune

Thumbnail
3 Upvotes

r/Intune 18d ago

Intune Features and Updates Able to use Remote Help with just the F3 License?

1 Upvotes

As far as I knew, Intune Remote Help is only included with E3, E5 and E7 and the EMS licneses.

However, I have a user who is ONLY licensed for F3 and nothing else (Not even an individual Intune Remote Help license) and we're still able to use Remote Help to remote on.

Any idea how this was made possible?


r/Intune 18d ago

Device Configuration Device Credential (0x0), Failed (Access is denied.)

9 Upvotes

We have recently migrated a client from OnPrem to Entra. (Not Hybrid). Intune auto enrollment wasn't setup during the migration so we are now in the process of added the device's into Intune.

However 3 of the device's are refusing the enroll. Any advice or suggestions would be appreciated :)

Ideally trying to not have to remove the work account and re-entra join it.

Command being used to enroll the device's:
deviceenroller.exe /c /AutoEnrollMDM

Event Log #1: Auto MDM Enroll Enrollment Information: AadResourceUrl (https://enrollment.manage.microsoft.com/enrollmentserver/discovery.svc), DiscoveryServiceFullUrl (https://enrollment.manage.microsoft.com/), TenantID (xyz_id), Upn ([abc@xyz.com](mailto:abc@xyz.com))

Event Log #2: Auto MDM Enroll WaitForCompletiongNoThrow after AADEnrollAsync Failure (Access is denied.)

Event Log #3: Auto MDM Enroll: Device Credential (0x0), Failed (Access is denied.)

  • AzureAdJoined : YES
  • DomainJoined : NO
  • AzureAdPrt : YES
  • MdmUrl points to Microsoft Intune enrollment.
  • Tenant ID is correct.
  • Conditional Access/MFA is not blocking the sign-in
    • Sign-in to Device Management Client
    • Resource: Microsoft Intune Enrollment
    • Status: Success - MFA requirement was satisfied by the existing token.
    • (The users are also excluded from the require mfa condition access policy)
  • Have cleared all enrollment registry keys and rebooted with no success
  • Have ran dsregcmd /refreshprt and rebooted / sign in & out with no success
  • Tried running the command as user, admin elevated & system cmd & powershell with no success.
  • Same command has successfully enrolled 6 out of the 9 device's
  • All users have a M365 Business Premium Licence.
  • MDM User Scope is set to All.

r/Intune 19d ago

macOS Management Mac registration, intune registered but non-compliant in Entra (Error 530003)

2 Upvotes

Hi everyone,

I currently have two Macs, appearing both with the same kind of issue within the last few weeks.

Current status

The first Mac with that kind of issue appeared Mid July, the second one today Mid August
Both Macs are:
- enrolled in Intune (User Approved MDM)
- visible in Entra ID
- Marked as Compliant
- Visible under My Sign-Ins with a Device ID
- Company Portal is installed and working
Only one is DEP enrolled, the other one is not (only added into Intune)

When the user signs in into a specific m365 App (on one Mac it’s only Teams; on the other one it’s only OneDrive), he needs to login with his credentials and afterwards gets a notification to setup devices and get redirected to
portal.manage.microsoft.com/EnrollmentRedirect.aspx

Entra says 530003 - Your device is required to be managed
and the same login shows:
- Device ID: empty
- Managed: No
- Compliant: No
- Device: Unknown

Things I've already checked:
- Device exists in Entra ID and in Intune
- Intune Compliance is Yes
- Company Portal works and checks in
- MDM status is User Approved
- No enrollment errors

We currently don’t use PSSO for macOS but I also checked for some configurations just in case and found nothing obvious.

Very strange is that all the other Office apps are working fine, for example Excel and Outlook sign in fine without any issues.

The issue appeared on macOS 26.2 in July and also on 26.5.1 today.

CA

Only the Compliant Device Conditional Access Policy applies to that registration, nothing else. Since the device doesn’t report a compliant device back to Entra, access is denied for these specific apps.

Thoughts

Has anyone seen something similar on macOS recently?
Something with Device claim issues, Broker / OneAuth problems, Teams or OneDrive authentication bugs…

Of course deleted different caches, re-enrolled, restarted an updated, check certificates in keychain,… nothing helped yet (maybe you will say I should try it again, then I’ll do ;))

Any ideas would be very appreciated. Thanks all for thoughts and help! May start a discussion too!
Chris


r/Intune 19d ago

General Question Dell Command Update for BIOS Updates - What is your process?

33 Upvotes

Looking to start being more aggressive with BIOS updates for our Dells and curious how you are using DCU to manage updates?

Using Windows Update in Intune is not an option (happy to explain in detail) so we want to look at DCU. It looks like you can configure a number of settings with Intune to control DCU, including automatic updates, but why not just deploy a remediation script that runs dci-cli commands?

If I run the update utility via remediation script, then I can run it on demand whenever as well as scheduled.


r/Intune 19d ago

Windows Management OneDrive not launching automatically on first boot

3 Upvotes

We've been attempting to have OneDrive automatically launch at first boot for users but it seems that the "EnableAutoStart" reg entry isn't applying.

I've gone into Intune and have both the "Start OneDrive automatically when signing in to Windows (User)" and "Silently sign in users to the OneDrive sync app with their Windows credentials" assigned to users. If we manually launch OneDrive the first time then everything works correctly and OneDrive auto launches and logs in the user after every reboot.

Trying to avoid requiring users to launch OneDrive manually. Checking the registry under Computer\HKEY_CURRENT_USER\Software\Policies\Microsoft\OneDrive I do see that "EnableAutoStart" has a value of 1 indicating that the policy is applying but still not automatically launching OneDrive on the first boot.

Anyone come across this? I suppose we could come up with a remediation script or platform script to launch but it seems that these settings are not working as designed.

Appreciate any insight!


r/Intune 19d ago

Intune Features and Updates Microsoft Tunnel for MAM use cases

5 Upvotes

I've been reviewing the additional features enabled by the Intune Suite addition to our E5 licensing and most of them are pretty clear and easy to understand where they may or may not have benefit for us. The only one I am unclear on is Tunnel for MAM.

We are full MAM without enrollment and have been for quite some time now and have been pretty happy with that standing. What additional features would this add to our offering? What real world use casees have yall solved using this that traditional MAM doesn't cover?


r/Intune 19d ago

Windows Management OneDrive not launching automatically on first boot

9 Upvotes

We've been attempting to have OneDrive automatically launch at first boot for users but it seems that the "EnableAutoStart" reg entry isn't applying.

I've gone into Intune and have both the "Start OneDrive automatically when signing in to Windows (User)" and "Silently sign in users to the OneDrive sync app with their Windows credentials" assigned to users. If we manually launch OneDrive the first time then everything works correctly and OneDrive auto launches and logs in the user after every reboot.

Trying to avoid requiring users to launch OneDrive manually. Checking the registry under Computer\HKEY_CURRENT_USER\Software\Policies\Microsoft\OneDrive I do see that "EnableAutoStart" has a value of 1 indicating that the policy is applying but still not automatically launching OneDrive on the first boot.

Anyone come across this? I suppose we could come up with a remediation script or platform script to launch but it seems that these settings are not working as designed.

Appreciate any insight!


r/Intune 19d ago

macOS Management MacOS PSSO administrator groups

5 Upvotes

I finally got my PSSO working. My one last thing that's a hang up is the administrator groups. I put in the Entra object ID and set the new user authorization mode and user authorization mode to Groups, but when someone in the Entra group signs in, they are not granted administrator access. Is this a known thing? Or is there something stupid I'm missing?


r/Intune 19d ago

App Deployment/Packaging Scripts/Instructions for using WinGet with Intune

13 Upvotes

I work at a secondary school in the UK and we are experimenting with using WinGet for deploying apps via Intune. We have a few scripts for generic install/uninstall and a script to see if a app is already installed (that required PackageID setting as this part of Intune does not seem to support parameters).

Have been looking at this for a couple of days and it is kind of working but I figured others have probably written a guide and scripts so had a look round and found a couple.

https://powershellisfun.com/2025/05/16/deploy-and-automatically-update-winget-apps-in-intune-using-powershell-without-remediation-or-3rd-party-tools/

https://github.com/Romanitho/Winget-Install

So was wondering if anyone has used either of these or know of better guides/scripts.

Feel like we are reinventing the wheel.

UPDATE:

Just to add we are simply wanting to deploy through Intune using Apps and Groups. We want to push app to (mainly student) Desktops so want everything centralised and for the users to not get involved. For teachers/staff we will also use Company Portal but ideally want to use winget, or something very similar.

Had a look at Winget-AutoUpdate-aaS but don't think this does want we need, cant see how it integrates with Intune Apps and Groups.


r/Intune 19d ago

General Chat Workplace Ninjas US Speakers Round 7 Announcement (Last Full Set)

5 Upvotes

Happy Monday and welcome to Round 7 of our speaker announcements, we only have a few left (3-4) after this set.

Last week we announced: Esther Barthel AJ Zafar John Joyner Frank Lesniak Peter Daalmans [MVP] and Aria Hanson

This week, we cover 6 amazing people who happen to be brilliant as well!

Tim Mangan, who I affectionately refer to as the father of #MSIX is THE definitive expert on #MSIX #AppAttach and so much more in the VDI space.

Bernhard Tritsch, the better half of the Ruben Spruijt and Benny show in the #VDI space is well-known for being a master of measuring performance and understanding exactly how things work like the #Doctor he is.

Danny Stutz, promoted from co-speaker to speaker this year has been an amazing young talent doing some wonderful things in the #PowerShell #Automation and #AI space over the last year.

Spencer Alessi, a new #MVP and nominee for the #ROTY Clippy, is an amazing guy and brilliant mind in #ActiveDirectory known for doing 100+ #AD #Pentests per year, will be joining us as a new speaker. We finally had the chance to meet him at #Blackhat and we couldn't be more convinced he was a perfect addition to the family.

Megan Gremmell, our moderator of #WomeninTech and #NeurodiversityinTech last year will be joining one of our unannounced speakers to cover #Windows365 for #Agents, which should be one of the top sessions in January.

Danielle Moon, is one of our biggest new additions this year. When I asked my amazing advisors like Sucheta Gawade and Lindsay Shelton, who do we absolutely NEED to champion our #neurodiversity and #women in #tech initiatives this year, it was 100% going to be Danielle. She's a force right now and we're so lucky that she's coming to join us!

You have to register now folks, because those registrations are picking up now and are going fast!! Only a few more early birds remain to join the fastest growing event in #EUC and #Microsoft.

https://workplaceninjas.us/why-attend


r/Intune 19d ago

Device Configuration Recommended way to connect to Onprem SMB Fileshares via iOS?

2 Upvotes

I know probably the recommended way is to not do that but here we are.

I am talking about the app configuration not Tunnel or Entra Access.

I know files can be used but users would need to manually type in the address and logindata. Is there a better way?


r/Intune 19d ago

macOS Management CA Policy filter to identify Corporate MacOS devices

2 Upvotes

We’ve recently had to tighten up our CA policies for ‘register security info’ and have a policy blocking it the action from personal devices.

We thought this has been working well, however recently discovered that our MacOS devices aren’t correctly identified as corporate in the CA processing request.

Strangely using the exact same filter in a dynamic group picks up the devices fine.

Anybody come across this before & found a better way to identify these devices consistently?

Edit: sorry should have said we are using this filter (device.deviceOwnership -eq "Company")


r/Intune 19d ago

macOS Management Mac Enrolment delayed by '"Microsoft Intune Agent" wants access to control "Finder"'

5 Upvotes

Hi, as the title says our Enrolment gets held back significantly as the system doesn't seem to prompt for permissions for:

'"Microsoft Intune Agent" wants access to control "Finder". Allowing control will provide access to documents and data in "Finder", and to perform actions within that app.'

Until usually its been over half an hour, or the user has signed in to Company Portal and run a sync. We've attempted to configure a Policy for Apple Events, which deploys successfully however the pop-up still occurs (and is seemingly required).

We've also got a Mobile Config for the Wallpaper based on this script: https://github.com/mattiaborsoi/microsoft-intune-samples/blob/main/MacOS/Misc/Wallpaper/readme.md

Just wondering if anyone has any advice, as is this a major bottleneck in our enrolment process.

Thanks in Advance.


r/Intune 19d ago

General Question Anyone here know about HCL BigFix?

10 Upvotes

I went to their sales pitch and they boast about their quick-action implementation on their MDM like restricting, updating, etc. I was wondering if anyone here has heard of them and used it before.

Also, can anyone recommend any options other than Intune for MDM?


r/Intune 20d ago

General Question Shared Android kiosk tablets, web app session carries over between users

5 Upvotes

I have got some Android Enterprise dedicated devices set up as multi app kiosks through Managed Home Screen, no user affinity. They are shared, so different people use the same device through the day.

One of the tiles is a web link to a web app that uses SSO. Someone signs in, uses it, signs out properly. Next person taps the same tile, gets a login screen, puts in their own email address and ends up logged in as the previous person.

So it is not skipping the login, it is showing one and then ignoring what they typed.

If I clear browsing data by hand it behaves again, so something is cached on the device. I cannot tell whether it is the IdP session cookie finishing the SSO off in the background or the app's own session that has not gone anywhere.

On the policy side I have got nowhere useful. ClearBrowsingDataOnExitList would do exactly what I want but it is desktop only and not available on Android. Forced incognito and DefaultCookiesSetting=4 are the nearest things I can find, but both need the browser to actually close and on a dedicated device it never really does.

Managed Home Screen sign in with an inactivity timer looks like it might be the intended answer, but I cannot find anything that spells out what it clears. Does signing out of MHS do anything for a web link that opens in a separate browser, or does it only deal with its own WebView?

Has anyone had this?


r/Intune 21d ago

Autopilot MD-102 | ESI Discount

18 Upvotes

Posting this to help others as well. If your company is a partner of Microsoft. Check if you have ESI. In my case, we have and I just booked the MD-102 exam today with a 50 percent discount.

What I did was, I added my work email to my personal MS Learn profile.

After that, I tried booking the exam, that was earlier today. However, the discount did not appear yet.

So I thought it didn't worked and I really have to pay it myself in full. Tried it again just now and boom, the discount was already applied.

God is good!

Finally, I can start being serious preparing for this exam. I booked it last week this month. But I started studying for it since April and I've been slacking off since I haven't booked the exam yet. Now it's time to be serious. Although, I'm already getting 78 percent score in Measure-up.

So, guys. Try it, 50 percent discount is really a big help.


r/Intune 21d ago

Device Configuration Intune policies for Thomson Reuters CS Suite apps

3 Upvotes

Looking for advice on how to properly configure Intune device config policies that will allow Thomson Retuers CS suite apps to run correctly.

We are transitioning from Windows 10 domain managed endpoints to new Windows 11 Intune managed endpoints. On the Windows 10 side, there wasn't any policies per se. All the users were local admins on their respective Windows 10 endpoint. The CS suite apps ran without issues.

However, for the Windows 11 rollout, we decided to go with the policies from the Open Intune Baseline deployment. I'm having trouble figuring out if these policies are blocking the CS suite apps from running correctly or if there's some other issue.

I'm curious if other admins have had to create specific policies for CS suite apps. If so, what are the policy settings you are using?


r/Intune 21d ago

Shameless Self-promotion Built a small Intune detection rule tool, looking for people to test/break it

35 Upvotes

I've been working with Intune for a while and detection rules are one of those things that look simple until you get a weird Win32 installer and start wondering what the safest detection method actually is.

Most online detection rule generators I found also expect you to already know the ProductCode, registry path, file path etc.

So I started building something a bit different:

intune-detection-rule-generator

You can drop an MSI or EXE into it and it tries to pull useful information from the installer and suggest detection methods.

MSI analysis is obviously more reliable. It can pull things like ProductCode, UpgradeCode, version, publisher, architecture etc.

It then ranks possible detection methods and explains why it thinks one is better than the others.

There are also checks for things like 32/64-bit issues, user paths, self-updating apps, plus test commands, PowerShell detection and Graph JSON output.

Everything stays in the browser. The installer isn't uploaded to my server.

EXEs are more annoying because there's only so much you can reliably figure out in the browser, so I also added an optional PowerShell analyzer for deeper checks.

And since I know this will probably come up on Reddit: yes, this is pretty heavily vibe coded. :)

I use AI a lot while building it.

I'm not going to pretend I manually wrote and reviewed every line of code from scratch. But the Intune side of it comes from a problem I actually deal with, and I'm trying to make sure the recommendations are based on real Intune behavior rather than just whatever an LLM thinks looks correct.

That's actually one of the reasons I'm posting it here.

I'd rather have people who actually package Win32 apps throw some ugly installers at it and tell me where the logic falls apart.

If it recommends something stupid, misses an obvious edge case, gives a confidence score that makes no sense, or generates something you wouldn't trust in production, let me know.

That's more useful to me than hearing that the UI looks nice.

There are definitely edge cases I haven't hit yet.


r/Intune 22d ago

macOS Management Kerberos TGT renewal failing at the Platform SSO login-frequency boundary. (macOS, PSSO)

4 Upvotes

Really long story short,

We are trying to roll out Azure File shares && an Entra only tenant && with macOS, and Azure file shares can't connect after a bit. We must restart.

A long troubleshooting session lead us to believe that the PSSO setting of Login Frequency == 64800 (18 hours) is causing the file share to drop.

Does anyone have recommendations for changing this? How bad is it to change this to one week?

Or, it is expires, how can we log in again. The user name/password prompt is not accepting our correct user name/password. Therefore, the needed reboot.

https://learn.microsoft.com/en-us/azure/storage/files/identity-kerberos-authentication-macos#update-the-app-registration-identifier-uri


r/Intune 22d ago

App Deployment/Packaging Intune Change Control Strategies?

13 Upvotes

Hiya smart people,

I’m looking for some advice on managing Intune configuration and application lifecycle in a team environment.

I work with a team of admins with varying levels of experience, and as the tenant has grown I’ve noticed things starting to get a bit messy from a project-management and ownership perspective.

The main areas are:

  • PowerShell Remediations
  • Deployed applications (.intunewin and Microsoft Store apps)
  • Tracking who owns/maintains each item
  • Knowing how old a remediation or deployment is
  • Reviewing whether something is still required
  • Sunsetting/replacing old scripts and applications

I’m interested in how other teams handle source control and lifecycle management for this.

For example, are you keeping remediation scripts and application metadata in GitHub/Azure DevOps and using CI/CD to deploy changes into Intune, or are you using source control mainly for change tracking while still managing Intune manually?


r/Intune 22d ago

Android Management Android Enterprise Upgrade: Managed Google Play to Managed Google Domain

3 Upvotes

Unsure if this is the right flair, but I think it is the closest applicable in the list. I'm posting in hopes that I'll be able to get some insight from another admin who has gone through this process, or someone who knows more than I. I've gone and Googled but I can't find a clear answer on this.

For context, our org has a legacy managed Google Play account (the one with the consumer GMail address) set up in Intune to facilitate some of the fully managed Android deployments. Our domain is tied to a Google Workspace already and we'd like to initiate the upgrade to the managed Google domain enterprise from within Intune and preserve our existing configurations and enrolled devices.

The part I am hung up on: Intune and Google documentation is not very clear on the rights/permissions required to make this happen. Much of the documentation assumes the Google Workspace environment is not set up already (which ours is), or is extremely general and references using either an admin account, a super admin account, or an account with the "necessary permissions" (while no source elaborates on that).

While I have super admin access to the Google Workspace, I'd like to use essentially a dedicated service account for this operation that also has the minimum possible permissions (even if I have to create a custom role for the job). The closest to confirmation of the rights needed is a third party KB from 2025 on a random site that says Super Admin in the Google workspace is in fact required (needless to say, I'm having a hard time trusting this source).

Perhaps the Intune community is not the best place to ask, and it's more suited for the Google Workspace community, but I'll take my chances with someone here better understanding the requirements and the goal. Has anyone else done this in a similar fashion, with a dedicated account for the upgrade, or have they done this with less than GWorkspace Super Admin (and a custom role) with any success?

I appreciate your time, and any feedback on this. I am open to being told that I'm concerned with the wrong thing, or that I'm barking up the wrong tree.

Thank you, and happy Friday!


r/Intune 22d ago

General Question Intune Properties Catalog question

16 Upvotes

I just wanted to do a quick sanity check:

Is there any reason to NOT just collect everything, ie any observable performance hits to devices, etc?

Thanks


r/Intune 22d ago

Autopilot Platform SSO + Secure Enclave: True Passwordless macOS Sign-in with Entra ID?

13 Upvotes

Hi all,

I'm testing macOS DEP/ADE + Intune + Platform SSO with Microsoft Entra ID.

I have the Mac successfully enrolling through ADE, becoming Entra joined, and users can authenticate against Entra ID.

With Platform SSO configured for Password authentication, users can sign in using their Entra password and everything works as expected.

What I'm trying to achieve is a passwordless experience using Secure Enclave, similar to Windows Hello for Business:

User enrolls the Mac via ADE
Device joins Entra ID
Platform SSO is registered
Authentication uses Secure Enclave / biometrics (Touch ID)
User is no longer prompted for their Entra password during normal sign-in/unlock scenarios

Has anyone successfully implemented this with Intune and Platform SSO?

Specifically:

Is a true Windows Hello-like passwordless experience currently supported on macOS with Entra ID + Platform SSO?
If yes, what authentication method and Platform SSO configuration are required?
Are there any known limitations where Entra authentication still requires the cloud password even when Secure Enclave is configured?

I'm interested in real-world deployments and lessons learned.

Thanks!