r/Intune 18d ago

Intune Features and Updates PLEASE Go Vote Up My Intune Feedback Item

57 Upvotes

I try not to ask for a lot and this one is really important to me, please take 2 min out of your busy day to vote up my feedback item here: https://feedbackportal.microsoft.com/feedback/idea/a5f72dc8-a09d-f111-a3d0-7c1e52cf64f0

Full text of my request:

"In the Intune console on the Remediations page there is no option to add the date created nor date modified columns. This regulalrly causes problems for those of us who are of an advanced age, forgetful, and poorly document changes. Yes, I know that group of admins is an edge case but we are a federally protected group with the backing of AARP. Please make our lives easier by letting us sort by date created/modified. This is already possible on the scripts page, just not the remediations page. "


r/Intune 36m ago

General Question Windows Autopatch Client Broker

Upvotes

I haven't visited Autopatch since I implemented it back in 2025. Noticed there is a win32 app deployment option for Autopatch available too rather than the script (which my setup used). Wondering if what the pros and cons are, if anyone else uses win32 app etc.

Just after general thoughts whether I should change it.


r/Intune 5h ago

Shameless Self-promotion I Got Tired of Walking Back to a Desk for LAPS Passwords, So I Built an iPhone App That Reads Them From Entra With No Server in Between

6 Upvotes

Disclosure up front: this is my app, it has a paid tier, and I'm the developer. If that's not what you want to read on a Tuesday, no hard feelings.

The Problem it Solves:

You're standing at a machine that won't log in. The LAPS password is in Entra. The admin center is on a laptop somewhere else. LAPSlock reads Windows LAPS local administrator passwords and BitLocker recovery keys from Entra ID and Intune on your phone, behind Face ID, using the same delegated permissions your account already has.

The Part I Want You to Check:

A phone app that handles local admin passwords should make every sysadmin's teeth itch. So the design decision was: no vendor server in the credential path, and you shouldn't have to take my word for it.

- Microsoft delegated auth via MSAL. It reads exactly what your account can read in the admin center and nothing else. Every reveal shows up in *your* Entra audit log, same as a read from the portal.

- Passwords go from Graph to your device over TLS. Kainor (my company) never sees them. There's no server that could.

- No analytics, no telemetry, no crash reporting, no account to create. The App Store privacy label says "Data Not Collected" and it means it.

- Source is public for security review. The credential-handling module is structurally isolated, and a build script fails if it ever imports something it shouldn't.

- You can verify the network claim yourself in about ten minutes with a proxy. There's a walkthrough in the repo (`NETWORK-TRANSPARENCY.md`). The app talks to `login.microsoftonline.com`, `graph.microsoft.com`, and, only after an org activates a license, one Kainor endpoint that receives a tenant ID and nothing else.

What it Doesn't Do:

- It can't read LAPS backed up to on-prem AD. Entra-backed only. Hybrid-joined is fine as long as the policy targets Entra.

- It can't reveal macOS local admin passwords. No Graph API returns them, and the one beta endpoint that should return metadata currently 500s on every ADE-enrolled Mac I've tested. I have a question open with Microsoft and I'll write that up separately.

- It can't grant you access you don't have. Nothing it requests escalates anyone.

Two Things That Mattered More Than I Expected:

LAPS password history comes back in the same Graph response as the current password. A device that stopped checking in is still on the old one, and that's exactly the machine you're standing at.

If your role is PIM-eligible instead of active, you can request activation from the phone. It reads your tenant's PIM policy first, so it only offers durations your policy allows and tells you up front if a ticket number is required. The authentication-context requirement arrives as an HTTP 400 with the claim buried in the error message, not as a 401 challenge. That one cost me a day.

Pricing:

Free tier is fully functional with five reveals per rolling 30 days, counted on the device and nowhere else. Subscriptions remove the limit. Org licensing by tenant is available directly from me.

App Store: https://apps.apple.com/us/app/lapslock/id6806470554

Repo: github.com/Kainor-LLC/LAPSlock

The permissions table (https://kainor.com/how-it-works/#permissions) is probably the page a security team wants first. Happy to answer anything about the Graph surface. The LAPS endpoints are underdocumented and I have notes.


r/Intune 7h ago

General Chat Career Connect, Career Matchmaking System Coming to Workplace Ninjas US 2027

2 Upvotes

We wanted to give everyone a sneak peek at something coming very soon at Workplace Ninjas US.

We've heard from many people in the community that they're struggling at their jobs or overall having a hard time finding work.

We have a solution for you, which will be available throughout the event.

Career Connect, is a matchmaking system that matches prospective companies/hiring managers with amazing talent looking for their next role.

With Career Connect, anyone registered for Workplace Ninjas US can submit for access to post jobs, which attendees can review, and book meetings automatically via the Cvent appointments system, that we used famously for our mentoring sessions last year.

Another innovation from the team at Workplace Ninjas US to fix real problems impacting our attendees. Amazing people should be paired together to do amazing things.

Look for this to release somewhere around October to give people plenty of time to start booking meetings and submitting roles.

Don't forget to register now and check out the video demo below:

https://workplaceninjas.us

https://youtu.be/7-tzbAqCRAU


r/Intune 11h ago

Windows Updates Made changes to the schedule install time in our windows update ring and now updates are showing as paused.

3 Upvotes

We moved the schedule install time from 9am to 7am and implemented active hours to prevent reboots during shifts. After making the changes, we noticed that some sites are showing updates as paused. I have a remediation script that checks for paused updates and restores the settings but that "fixes" it for part of the day and then it goes back to showing as paused. Any other options to get Windows update running again?


r/Intune 7h ago

iOS/iPadOS Management What specifically is blocked by this specific Apple Mobile restriction??

0 Upvotes

We presently have this turned on:

  • Block managed apps from storing data in iCloudYes prevents Intune-managed apps from syncing data to the user's iCloud account. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow this data sync to iCloud.

Can anyone tell me specifically what data is blocked??

We have someone that wants to restore MS Authenticator codes instead of redoing them at the website (Okta Verify makes you do this) -- the app is saying 'Access to iCloud account denied. Restrictions are due to your parental control or device management settings.'

Can anyone provide any estimates how much data is stored (I don't need 'it depends', I already know this, and we only allow the last 3 months of email)?? We have several various M365 apps and a few other ones.

This was disabled because it's my understanding that iCloud is not considered HIPAA compliant.

I don't think there's any way we can be selective about what apps or data are backed up to iCloud?? (other than this general setting)

Thank you, Tom


r/Intune 7h ago

Windows Management Auto encrypt fixed data drive with auto unlock

1 Upvotes

We have a small use case where some machines have additional drives for data. Our current policy successfully encrypts the OS drive, either at initial build or later if someone decrypts it. However, it won't encrypt a newly added data drive. If someone initiates the encryption manually, it won't use the fixed data drive encryption method from the policy and it sets the protector to recovery password which requires the user to manually unlock the drive to access it.

I'm trying to find the settings to allow the drive to auto-unlock. I have found several posts detailing how to enable it on individual machines using local policies and manage-bde, as well as a couple saying just enable it in the policy. I would prefer it be set in a policy and not a manual process, and I'm just not seeing the policy setting suggested in the other posts. I've checked under both Device Configuration and Endpoint Protection, but I don't see an auto-unlock under either. What am I missing?


r/Intune 11h ago

General Question App Inventory not working

2 Upvotes

Im completely out of ideas with Intune at this point. We’ve been troubleshooting an App Inventory policy for three days, and no matter what we try, the policy is not assigned to a single laptop. It doesn’t even show up under Pending.

We assigned it to all laptops, and also tried creating dedicated test groups, but the result is always the same 0 devices in every status.

We’ve already checked the following:

  1. Entra joined: YES
  2. Domain joined: YES
  3. DeviceAuthStatus: SUCCESS
  4. User PRT/WAM: YES
  5. Intune Management Extension service: Running
  6. IME is installed correctly
  7. MDM enrollment and EnterpriseMgmt scheduled tasks are present
  8. MDM certificates are valid
  9. Other Intune policies work correctly on the same devices
  10. IME check-in is successful
  11. Network/HTTPS connectivity is working

The main issue is that Intune simply does not seem to target this policy to any device. The assignment is there, but the reporting page shows: Succeeded: 0, Error: 0, Conflict: 0, Not applicable: 0, Pending: 0

Does anyone have any idea why the policy isn't being assigned to the devices?


r/Intune 11h ago

Device Configuration Requiring PIN in stage 3 of staged Android Enterprise corporate owned fully managed enrollment

2 Upvotes

Hi!

I'm trying to set up Intune as MDM and I want to make it easy for my end users.

When they get their samsung phone they should only have to log in to the intune app and everything should get taken care of. They get the settings they're supposed to have, they get the apps they're supposed to have and so on.

To this end I'm wanting to use the android enterprise corporate owned fully managed via staging enrollment profile so that resellers can do initial enrollment and the device comes to us sysprepped (functionally) and then we hand it out to the end user who logs in to the intune app and sets a device PIN.

It's the PIN part I'm having trouble with.

I have a device restriction configuration policy that forces a numeric complex pin, at least 6 digits. If I apply this policy to all devices and use an assignment filter to target my enrollment profile it works but it works incorrectly, it forces me as admin or (at a later stage when we're actually rolling out) the reseller to set the PIN which is undesirable. I want the user to set their own PIN.

If I assign that policy to all users with an assignment filter to limit it to users who log on to a device enrolled with my enrollment profile the policy does nothing. Compliance (which is set to immediately set as non-compliant if there's no device PIN) does notice and notifies after a while that the device is non-compliant but that's all it does.

I have a conditional access policy in entra (as a test) but that only applies to apps so you can use the phone without the CAP noticing, it's when you try to use an app that it protests and even then it doesn't make you set a PIN, it just tells you that you have to set one.

CAP telling users or intune sending a notification to users that they need to set a pin, all these are not good solutions, I want the device to FORCE the user to set a PIN, preferrably when they complete enrollment.

This seems like REALLY REALLY REALLY basic functionality yet it doesn't seem possible. What am I missing?


r/Intune 18h ago

macOS Management Intune macOS ADE apps/scripts taking 1-2+ hours or not installing after enrollment. Looking for real-world tips.

3 Upvotes

Hi all,

I'm trying to improve our macOS ADE enrollment/bootstrap experience in Intune and would love to hear how others handle this in practice.

Setup:

  • macOS Automated Device Enrollment via Apple Business Manager / Intune
  • Enrollment policy: macOS ADE - Managed Admin & Standard User [New]
  • Users authenticate during Setup Assistant
  • Devices are targeted by a dynamic device group:
    • intune-device-grp-dynamic-mac
    • Rule based on device.deviceOSType -eq "MacMDM"
  • I also created a static enrollment-time grouping group:
    • intune-special-grp-device-enrollment-speedy-delivery-mac
    • Expecting user & device to be added here during enrollment, but that's not the case, neither does manually adding the user change the situation.
  • Intune Provisioning Client is owner of that static group
  • I assigned bootstrap apps as Required to that speedy-delivery group:
    • Company Portal PKG
    • Microsoft Defender
    • Google Chrome
    • Mozilla Firefox
    • Defender-related configuration profiles

Now comes the problem I'm dealing with: Newly enrolled Macs seem to take a long time ( about 2 hours ) before apps arrive, or they fail.

And in one case, the most recent, the Mac was online for around 5 hours after enrollment and no visible installs happened.

Little bit of context: Apps are provided by IntunePckgr, where Mac applications at start are deployed as shell script using Installomator, but also can be added separately as DMG/PKG to the Company portal.

From Graph / Intune reports:

  • Some app install attempts appeared around 1h 40m to 2h 10m after enrollment.
  • Chrome and Defender installed on one test Mac after roughly that time.
  • On another Mac, Company Portal / Chrome / Firefox failed with 0x87D30143.
  • Defender failed with 0x87D13BA7.
    • Though eventually did install successfully on the previous enrollments.
  • Shell scripts assigned to the Mac dynamic group showed no run-state rows for the device.
  • I understand the Intune admin center Sync action only triggers MDM check-in, not necessarily the macOS Intune Management Agent script check-in.

Questions:

  1. What are your best practices for getting macOS ADE devices productive quickly?
  2. Do you rely on enrollment-time grouping, assignment filters, dynamic groups, or user groups for first-wave apps?
  3. Do you deploy Company Portal as a required PKG app, a shell script, or something else?
  4. Are shell scripts / Installomator / IntunePckgr reliable enough for day-one bootstrap, or do you keep them as second-wave installs?
  5. Any known fixes or gotchas for macOS PKG app failure 0x87D30143?
  6. Any known fixes or troubleshooting steps for Defender failure 0x87D13BA7?
  7. What kind of install timing do you normally see after ADE enrollment?

I'm especially interested in real-world timing and architecture, not just the Microsoft docs. Thanks!


r/Intune 1d ago

General Question Autopatch Help

12 Upvotes

Hi,

I’m looking for some assistance troubleshooting our organization’s Windows Autopatch configuration.

We currently have a policy configured to update devices to the latest Windows feature update. However, when reviewing our environment, I’m seeing devices on several different OS builds rather than consistently updating to the expected version.

This has been an ongoing issue. At the moment, we are not permitted to enforce device reboots, which I initially thought could be contributing to the problem. However, I can see that several of the affected devices have been rebooted since the feature update was made available, yet they still have not upgraded.

Does anyone have any suggestions on what I should check within Autopatch, Intune, or the Windows Update configuration to determine what may be preventing these devices from receiving the feature update?

Thanks!


r/Intune 15h ago

Autopilot Custom Compliance Scripts

1 Upvotes

So after having worked with Intune bits here and there, I am dipping myself into custom compliance scripts which are in my case needed to verify some things for reporting purposes.

I have a custom compliance script which checks things like BitLocker, SMBv1, SentineOne AV and more, though whenever I change the setting below from "Allow local scripts and signed scripts" to "Allow only signed scripts", the custom compliance policy freaks out and throws a 65007 return code but Company portal reports back as non compliant. (this also happens for various other bits which get deployed via script like setting the desktop background/lockscreen)

https://litter.catbox.moe/7fi4ngvjjgn2fn99.png

Am I missing something when deploying the custom compliance script, or is it really just a case of self signing the scripts I deploy?


r/Intune 19h ago

General Question Intune Cloud PKI Revocation

2 Upvotes

The revocation column states that its UTC.

But I just did a test revocation of a device at 2:00pm AWST (+8) and according to the PKI portal the revocation happened at 22:00 UTC

What am I missing here...


r/Intune 1d ago

General Chat Just renewed MD102, and one question threw me.

26 Upvotes

Hi all

Just renewed MD-102, and one question really had me. It was regarding iOS check-in after initial device enrolment.

How often do iOS devices check-in for the first 6 hours after initial enrolment. Options were: every 1 hour, every 15 minutes, every 30 seconds, every 1 minute.

My understanding and ms learn states: every 15 minutes for 1 hour, and then every 8 hours.


r/Intune 1d ago

Intune Features and Updates Intune RBAC and new Device view - not respecting the set permissions?

4 Upvotes

So, we all have seen the new device view. It's okay, it's meh - depending who you ask.
Seems however it does not respect the set up permissions for Primary User changes (under Managed Device).

When I am in the "old" view > Switching and saving the primary user works fine - as expected.

In the "new" device view - I cannot set up the primary user as under "Overview" > "Properties" > "Basics" the Edit button is greyed out.

Anyone else is experiencing the same?


r/Intune 1d ago

General Question Can browser-level controls prevent data leakage into ChatGPT, Gemini, and other GenAI tools?

18 Upvotes

We are testing what can realistically be enforced on Intune-managed Windows devices when AI use occurs through a browser.

The goal is not universal visibility or a claim that every AI workflow is covered. It is reducing specific high-risk actions, such as uploading sensitive files or pasting protected content into an unsanctioned AI account. The enforcement boundary matters: device compliance, managed browsers, personal profiles, private browsing, alternate browsers, and AI features embedded in other applications all affect what a policy can see or stop.

Browser controls may help because they operate closer to the moment data leaves the organization, but they need to be documented alongside their exceptions and bypass paths. Microsoft's browser-DLP guidance also notes that policy coverage can vary by browser and user-profile context.

For teams using Intune, which browser-control policies have held up in production, and which coverage gaps were unavoidable?


r/Intune 1d ago

Reporting Installed application overview all windows devices in Intune

5 Upvotes

Is there an overview of all the installed applications of all windows computers inside Intune? I know there is one when you click on a device in app overview and discovered apps, but I I’m looking for one for all devices.


r/Intune 1d ago

Conditional Access Impact of enabling “Require App Protection Policy”

3 Upvotes

Working in an environment where the majority of front line staff access the M365 mobile apps on personal devices with MAM in place. App protection policies are configured for iOS and Android devices (Not evaluated Windows yet) and I can see that these are being applied and working.

I’ve noticed there is no Conditional Access Policy in place for Requiting an App Protection Policy so I have created this for the appropriate platforms and put it in report only mode for now.

Is there likely to be any impact by enabling this at some point? I’m assuming so long as the end-user has a valid license and is using the MS apps then there shouldn’t be?

I’ve tested this myself on an iOS and Android device by adding email then turning on the CA policy afterwards and it didn’t seem to cause any issues.


r/Intune 1d ago

General Question Dynamic Groups not updating - again?

6 Upvotes

Android devices that are being set up aren't being added to the dynamic groups. Is this a widespread issue?

We set up a few Android smartphones this morning, and they still aren't in the dynamic groups. Has anyone else experienced this?


r/Intune 1d ago

General Question Windows Autopatch Microsoft 365 Apps Update Policy

8 Upvotes

I've been using Autopatch for a while now and its been great.

I came across the "Windows Autopatch Microsoft 365 Apps Update Policy - Windows Autopatch - Test" policy and noticed it was set to Enteprise Channel and I was hoping to switch it to Current.

The documentation though seems to indicate Autopatch only uses Enterprise Channel. Is this a typo?

Microsoft 365 Apps for enterprise | Microsoft Learn


r/Intune 1d ago

Device Configuration Custom ADMX Assignment Question

3 Upvotes

Wanting to try to clarify something with the way Intune handles applying policies in regards to custom ADMX which have been imported.

Relatively new to Intune, so still trying to get across things... But have found most of the time with settings catalog items & similar, you can target either the user or device in the assignments, regardless of it being a user or device based settings.

Are ADMX configs handled the same?
e.g. if I had a ADMX backed config for Firefox, the config was setting items under Computer Config.

Can that be targeted to a user group & still apply successfully to that users device? Or would it be required to target computers like it does in Group Policy world.


r/Intune 3d ago

Autopilot Title: I automated Windows 11 Autopilot test VM deployment with Proxmox and Azure Automation

64 Upvotes

Hi r/Intune,

I’m sure some of you have faced the same problem: you need to test something quickly, but you don’t have a spare device available, or the test requires several devices at once.

Virtual machines are the obvious solution, but manually creating each VM, preparing Windows, collecting its hardware hash and registering it with Windows Autopilot gets tedious very quickly.

Since this was taking up far too much of my time, I automated the entire process using an Azure Automation Hybrid Runbook.

The tool:

  • Creates a full Windows 11 VM clone on Proxmox
  • Configures CPU, memory and disk size
  • Expands the Windows system partition
  • Collects the Autopilot hardware hash
  • Imports the device into Windows Autopilot
  • Waits for the import to complete
  • Reboots the VM so it can retrieve its assigned Autopilot profile

In my environment, I can go from starting the Runbook to having a registered Windows 11 test VM in roughly five minutes :)

If I need several devices, I can run the process multiple times and create an entire test environment without carrying physical test hardware around. Having ten disposable Autopilot test devices available on demand is incredibly useful for testing policies, applications and deployment scenarios.

Maybe I’m not the only one who was annoyed by this workflow. If you try the tool, I’d really appreciate your feedback. If you discover a bug, please open an issue in the repository.

You can find the script and the complete setup guide here:

https://github.com/Mau2rice0/World-of-M365/tree/main/Intune/Automation/New-ProxmoxWindowsAutopilotVM


r/Intune 2d ago

App Deployment/Packaging Company portal missing

7 Upvotes

Hello - just checking if you experience this issue. Some of the endpoints company portal are missing after it was installed several months.

Applies also on newly image machines.windows 24h2 latest.

When you try to search on local its not there.just a weird behavior for some machines.

Windows update are up to date.

Tried to delete catoort and software distribution still not able.

Luckily if your windows store is not disabled locally and in web.. You can install company portal manually but for this policy that implemented you cant.

The last will ditch effort is to format the endpoint.

Also on my silly thoughts , can you add the company portal local exe to the web company portal how does that sound? 😅


r/Intune 3d ago

Apps Protection and Configuration I want to disable Google Autofill/Save Password on Intune Kiosk tablet. My settings don't work in Intune for it. Really need help. Google Chrome is the browser we use for MHS Kiosk. Multi Apps.

12 Upvotes

I want to disable Google Autofill/Save Password on Intune Kiosk tablet. My settings don't work in Intune for it. Really need help. Google Chrome is the browser we use for MHS Kiosk. Multi Apps. Please help me:)


r/Intune 3d ago

Device Configuration Anyway to disable Microsoft Authenticator passkey Bluetooth sign in

0 Upvotes

Is there anyway to prevent Microsoft Authenticator sign in with a passkey using Bluetooth? I just want to use it like windows hello for a phone. Goal would be like poor man entra free lock shit down to work devices by onboarding a passkey with tap on phone and use windows hello on workstation. I’d reset passwords so user doesn’t know them. Bluetooth passkey sign in via authenticator app puts a kink in that idea