Questions tagged [microsoft-intune]

Microsoft Intune is Microsoft's Mobile Device Management (MDM) platform.

Filter by
Sorted by
Tagged with
4 votes
2 answers
5k views

How does one map a drive on a Windows 10 device managed by Intune?

I'm trying to setup some basic group policy settings with Microsoft Intune. We have Windows 10 Enterprise installed on all our devices and they are Azure AD joined. To start I wanted to map a network ...
Mrtn92's user avatar
  • 61
3 votes
2 answers
7k views

Is it possible to set the Windows 10 time zone through Intune and if so, should we?

Using AutoPilot to provision Windows 10 v1803 devices, it only asks for the user's language and the user's credentials. After a few minutes waiting at the AutoPilot status page, the user is logged on ...
Nathan Hartley's user avatar
3 votes
1 answer
32k views

Microsoft Intune - How to modify Windows 10 registry settings?

Win32 app uses bat file to install software and edit registry keys. Registry keys are modified if I run bat file locally but not when run through via Intune because Intune runs installation as System. ...
JPX's user avatar
  • 151
3 votes
2 answers
5k views

Is it possible to rename a Windows 10 device when using Autopilot to join it to the domain and Intune management?

Realizing that naming a PC is old school, I would still like to know if it is possible to rename a Windows 10 device either as part of the AutoPilot process or later through Intune. Another ...
Nathan Hartley's user avatar
3 votes
2 answers
4k views

How do you create an Azure AD Dynamic Device Group based on the Intune Device Enrollment Manager which enrolled the device via AutoPilot?

I am trying to create an Azure AD dynamic device group which contains all devices enrolled by X user 'Associated User'? This user is the Device Enrollment Manager user DEM which allowed me to enroll ...
Helmy Mohamed's user avatar
2 votes
2 answers
7k views

Is it possible to uninstall default Windows 10 apps with Intune? If so, how?

Through Intune, is it possible to uninstall default Windows 10 apps; like Pandora, X-box and Candy Crush? If so, how?
Nathan Hartley's user avatar
2 votes
2 answers
2k views

Specifying machine certificate issuer with Windows VPN

I am trying to create a Windows Always On VPN connection between an AD and AAD joined Windows 10 client and a StrongSwan VPN server. The Windows client has multiple "Client Authentication" ...
Cameron's user avatar
  • 287
2 votes
1 answer
240 views

Hybrid Azure AD Join - Not joining correctly

Another day, another Hybrid Azure AD Join issue. Having set up Hybrid Join, it looked like it was working.  The device I onboarded via autopilot was created in "on-prem" AD, was in Azure AD, ...
AngryDog's user avatar
2 votes
1 answer
87 views

To use MDM or Intune?

I'm seeing conflicting suggestions from MS about whether to use MDM or Intune. One says to use MDM when possible despite Intune having more features. https://docs.microsoft.com/en-us/intune/pc-...
Simon's user avatar
  • 21
2 votes
2 answers
658 views

How does one deploy through Intune the Microsoft.Office.Desktop Appx Package?

Knowing that there is the Office 365 ProPlus Click-to-run installer template within Intune, I wonder if there may be a way to deploy Office through the Store for Business. We are finding Office to be ...
Nathan Hartley's user avatar
2 votes
0 answers
265 views

autopilot not installing apps after autopilot reset

Whenever I putt a computer into autopilot and let the user login it installs all the applications. But whenever I do an autopilot reset and then let je user login in wont install any of the ...
thebest07111's user avatar
2 votes
1 answer
4k views

Updating Microsoft Intune devices via Powershell

Looking for a bit of help with the Intune Powershell/graph interface. I'm trying to manipulate Intune Device Categories via Powershell, so that I can firstly correct devices that were placed into the ...
Rob Moir's user avatar
  • 32k
2 votes
1 answer
51 views

Recommendations for future-facing (fully cloud-based) Identity and EMM/UEM Solutions

I have recently started consulting for a tech startup of about 60 users that has grown, and is looking to expand, quickly. Due to the fast growth, and lack of formal IT advice up until now, they are ...
Campbell's user avatar
1 vote
1 answer
801 views

Microsoft Endpoint Manager Firewall rule not working

I am trying to use Microsoft Endpoint Manager to block all traffic to Microsoft Edge for a group. I have done the following: Created a group called Students and added user "Zephyr Prospect" ...
jimboweb's user avatar
  • 129
1 vote
1 answer
2k views

Disable the Windows 10 Password login option when FIDO in use

Hello Collective intelligence, I have a question that is bugging me, I have a Yubikey 5C setup in Azure AD with passwordless auth and registered to my account, I can log into the PC using the FIDO key ...
Sparky BearBomb's user avatar
1 vote
1 answer
3k views

Could Intune be the cause of unwanted restarts?

I have an Intune environment that I am currently working on pushing out an endpoint protection profile. There was an older endpoint protection profile that only pushed app control as "audit-only&...
Wesley Blackwell's user avatar
1 vote
1 answer
128 views

Installing Microsoft Store for Business apps on Intune Managed Self-Deploying Devices

We are having trouble with Microsoft Store for Business apps not installing, when assigned as Required to their Device group, on our Endpoint Manager (Intune) managed, Autopilot Self-Deploying, Shared ...
Nathan Hartley's user avatar
1 vote
1 answer
2k views

Microsoft Intune mdm cant remove outlook profile data in desktops and mac

We have configured MDM and assigned E3 license and intune license. We have azure AD and intune MDM and also outlook with exchange. It seems that microsoft intune in Desktops cant remove outlook ...
user879's user avatar
  • 267
1 vote
1 answer
2k views

How does one build an Intune AutoPilot ready device, using SCCM, without it becoming Co-Managed?

I would like to build devices using SCCM, much like they arrive new, for Intune AutoPilot deployments. It seemed simple enough. I created a generic Task Sequence, Then wrote a script which uninstalls ...
Nathan Hartley's user avatar
1 vote
1 answer
6k views

Don't allow to deactivate Company Portal Intune App as a Device Administrator in Android

Is there any way that I could block the user of deactivating the Company Portal app from the Device Administrator in a Android Device. What I'm trying to accomplish is that the user can't uninstall ...
Andres's user avatar
  • 121
1 vote
1 answer
61 views

Intune issues after UPN change for user

I have a bit of a weird situation, already contacted Microsoft support, but hoping sages here know something. We are planning a change of UPN for our 700+ users. We are in the process of testing what ...
AnalyticaL's user avatar
1 vote
1 answer
604 views

Restrict other Azure AD users from logging into Intune devices

I want to make sure that a user in our domain [email protected] does not login to a device that has been assigned to [email protected]. I have created a configuration profile but not sure what the ...
user3511199's user avatar
1 vote
0 answers
39 views

How to set alerts for an installed application not in exception list?

We are often getting incidents from Microsoft Defender about malicious activity detected on user devices, For example, lately we had an incident that said there was a defense evasion, however, at the ...
Cataster's user avatar
  • 117
1 vote
0 answers
174 views

Why isnt the remediation improving the exposure score in Microsoft defender?

I am trying to improve our exposure score on Microsoft Defender and noted that "Block persistence through WMI event subscription" has a remediation which Ive already applied since almost a ...
Cataster's user avatar
  • 117
1 vote
0 answers
618 views

How to force users to change their Windows Hello Pin

We changed our password policy in the Microsoft Endpoint Manager and now require a longer PIN. The issue is, in testing we noticed you're only asked to change the Windows Hello PIN, when logging in ...
Leopepe's user avatar
  • 13
1 vote
1 answer
216 views

How to deploy Microsoft Endpoint / InTune to computers that are in use already and not tied to Azure AD Accounts (Password Policy Failure)

We recently rolled out Microsoft Endpoint / InTune to our company computers. Everything works great if the first time a user logs in it is with their Azure AD credentials. We have computers that are ...
nweg's user avatar
  • 111
1 vote
0 answers
1k views

Configuration Profiles applying as System Account instead of user

I'm pulling my hair out over an issue I'm having with Intune. I've deployed a VPN profile using a custom configuration profile to my users and most users have received the VPN profile on their laptops ...
OPG1987's user avatar
  • 13
1 vote
1 answer
342 views

Block unapproved Remote Assistance solutions

We have a cloud-only setup using Azure AD + Intune to manage our organisation's windows devices, since all are remote workers/work from home. I'm looking to remove the possibility for users to ...
TMann's user avatar
  • 13
1 vote
1 answer
893 views

Intune new office installation on already installed office

Currently users have office 365 installed via een msi that was inserted into Intune. We now want to use the new method because than we can easily add and remove applications. Is it possible to do so? ...
sgouman's user avatar
  • 21
1 vote
0 answers
201 views

Enrol Chrome Browser via InTune

I'm having difficulty enrolling Chrome Browsers for management via Gsuite Admin on machines managed by InTune MDM. I've tried following this guide, to set the CloudManagementEnrollmentToken via the ...
Peter Coghill's user avatar
1 vote
0 answers
60 views

Can you target app deployments to local users in InTune?

Is there any way to target app deployments to local users (not devices) such as the local user that kiosks create, kioskUser0?
Tim's user avatar
  • 111
1 vote
0 answers
40 views

No mobile devices in Intune - Testing a few users from Hybrid SCCM to Intune Standalone

I'm testing at the moment with a few users to migratie from Hybrid SCCM to Intune Standalone. I followed this steps: https://docs.microsoft.com/en-us/sccm/mdm/deploy-use/migrate-hybridmdm-to-intunesa ...
William's user avatar
  • 11
1 vote
1 answer
40 views

Apple Configurator config files in Intune

I’m looking at moving a MDM config from SCCM hybrid to Intune Standalone. I know I can migrate but right now I’m running down options for a fresh setup. If all I have is an xml dump of an Apple ...
Rob Moir's user avatar
  • 32k
1 vote
2 answers
1k views

Azure AD, InTune, TeamViewer

So I had come across This Article explaining it is better to manage Windows 10 devices as mobile devices rather than using the InTune console, which I have already done. Most of our machine are ...
nathank1989's user avatar
1 vote
1 answer
7k views

Configuring Wi-Fi on Android via Intune. Missing Wi-Fi certificate issue

I am having an issue when Android phones are unable to get correct WiFi configuration policy from Intune. Intune is in 'cloud mode' (non-hybrid) I have the following polices configured in Intune: ...
J-M's user avatar
  • 1,960
1 vote
0 answers
41 views

Deploy Modern UI App

I have enrolled my devices with Windows Intune and Install Corporate Portal to them. I have added to InTune some Windows Store App, MS Corporate Portal appx and my own application appx. When I am ...
ceth's user avatar
  • 536
0 votes
1 answer
2k views

How do I disable Bitlocker Encryption settings using Intune?

We've activated Intune Bitlocker encryption and configured it needs a password to unlock. Since we don't want our users to change the Bitlocker pin, we want to disable the Settings below. Bitlocker ...
Leopepe's user avatar
  • 13
0 votes
1 answer
2k views

Intune device not in Endpoint Manager

One of our devices is visible in MS Azure AD > Devices with Jointype = Azure AD joined and MDM = Microsoft Intune, but not visible in MS Endpoint Manager. Any experiences/suggestions?
Soliman's user avatar
  • 103
0 votes
1 answer
407 views

can windows intune do a self service software distribution portal?

I want to give users a self-service software portal like sccm can do but sccm is huge and I have less than 100 users and many are mobile From what I understand intune is for oob/mobile users. Does ...
red888's user avatar
  • 4,213
0 votes
1 answer
10k views

Microsoft Intune conflict resolution

I have a number of devices enrolled in Microsoft Intune. Currently, they all share a single set of Intune configuration profiles and compliance policies; our "all employees" group has the profiles/...
Alexander Martin's user avatar
0 votes
1 answer
2k views

Change Windows PIN requirements in Intune for an Azure AD-joined PC

I am the part-time admin of a small nonprofit, with a Microsoft 365 Business Premium subscription. I have been searching through admin.microsoft.com and portal.azure.com, but can't seem to find the ...
Conrad's user avatar
  • 314
0 votes
1 answer
77 views

Can Autopilot PCs be required to be Intune managed?

After recently having the Intune Wipe action fail to Wipe PCs though it removes the PC from Intune, I worry we could have more unmanaged yet fully functional PCs in the field. Is there a way to ...
Nathan Hartley's user avatar
0 votes
2 answers
574 views

Using InTune for BitLocker enabling TPM+PIN+USB

I am tasked with enabling BitLocker via InTune and I am struggling to understand why the following settings are not taking effect on the endpoint. In the OS drive settings Compatible TPM Startup - ...
The_Honkler's user avatar
0 votes
1 answer
1k views

Intune Autopilot replace WDS or Sccm

I have been doing some research on Intune autopilot - I see that once hardware hash is registered it can go on autopilot mode wherein- users just need to sign in and all configurations are taken care ...
Jon drew's user avatar
0 votes
2 answers
9k views

This Apple ID can't be used to make purchases - InTune/Apple Business Manager

We have just integrated InTune with Apple Business Manager and turned on the domain Federation which now allows our Azure AD users to log into Apple Devices with their work email address. We have hit ...
Nathan Dries's user avatar
0 votes
1 answer
6k views

Block Users from Installing programs with Azure AD joined Devices

I am looking for a way to block users from installing programs without an on prem AD domain (so no GPOs etc.). We have Office365 and the included Azure AD. The devices have not yet been joined to ...
Chaim Ginsberg's user avatar
0 votes
0 answers
96 views

Azure AD - Intune device mismatch, not joined properly

I have something of a mess on my hands. When these devices were joined, or "registered" with Azure AD, they had already been through OOBE and had local accounts created on them. I realize ...
boog's user avatar
  • 230
0 votes
0 answers
26 views

Since private MS store no longer working, what is the best practice to set policy on MS store?

Since private MS Store no longer work in the policy What is the best practice to set policy on MS Store. Atm, our company is blocking access to MS store, however this cause a lot of issue with ...
user3755790's user avatar
0 votes
1 answer
36 views

Hybrid AD Joined and Autopilot

I've been working on setting up our Autopilot onboarding with our Hybrid AD. I have managed to join a device to the domain successfully, but I have noticed some differences against when we do this ...
AngryDog's user avatar
0 votes
1 answer
86 views

hybrid azure ad join devices

We have a hybrid active directory set up between our servers held in a DC and our Azure AD.I am currently working on the configuration of our Autopilot and Intune deployment. At the moment we deploy ...
AngryDog's user avatar