r/Intune 21d ago

Blog Post Streamlining macOS security: Automatically enable AutoFill after Platform SSO registration - Microsoft Blog

24 Upvotes

This is a recent Intune Customer Success post about closing the last manual step in a passwordless macOS setup. Platform SSO gives Macs Entra ID sign-in, but registration alone isn't enough for a fully passwordless workflow. To enable passwordless auth in Safari, Edge, and Chrome, the Company Portal AutoFill extension also has to be enabled, and in most deployments that toggle is still left to the user. So a device can be enrolled and PSSO-registered yet still fall back to manual credential entry, which looks complete but doesn't actually deliver the intended posture.

Highlights:

  • The gap. After PSSO registration, AutoFill is often the final step that depends on user action. Skip it and the device stays registered but not truly passwordless.
  • The fix. A sample script, Check-PSSO.zsh (GitHub, from the Intune Customer Experience Engineering team), detects when PSSO registration has completed and then enables the Company Portal AutoFill extension automatically.
  • Support caveat. Microsoft supports Intune's script deployment but not the individual scripts. Review, validate, and test in your own environment before broad rollout.
  • Zero-touch. Combined with the Enable Registration During Setup setting, this pushes toward a true zero-touch experience from enrollment through authentication, no manual configuration.

Read the full article here: https://techcommunity.microsoft.com/blog/intunecustomersuccess/streamlining-macos-security-automatically-enable-autofill-after-platform-sso-reg/4531908


r/Intune 25d ago

What’s new in Microsoft Intune – June

69 Upvotes

This is the monthly "What's New in Microsoft Intune" post, June 2026, framed around making endpoints compliant, current, and secure as AI agents start acting on company data.

Highlights:

  • EAM auto-updates is GA. Enterprise Application Management now keeps managed apps on the latest incremental release (e.g. 4.1 to 4.2) automatically, no manual packaging, to shrink the window between full upgrade cycles.
  • Vulnerability Remediation Agent (public preview) in Security Copilot ranks CVEs across Intune-managed Windows devices by CVSS, exposure, and affected device count, surfacing them in the admin center. It runs under its own Entra agentic identity with delegated read permissions for a clean audit trail.
  • EPM additions (GA): approval requests for non-primary users on shared devices, and rules-based policies letting standard users change network settings like IP, gateway, and DNS without local admin.
  • Apple ADE enrollment rebuild: iOS/iPadOS and macOS ADE profiles move to new infrastructure, completing enrollment-time grouping across all platforms.
  • Myth vs. Reality: the "seven-day app refresh" figure is outdated. Win32 apps in Add/Remove Programs refresh every 24 hours, and the new All Apps inventory updates multiple times daily.

Also noted: EPM and EAM join Microsoft 365 E5 from July 1.

Read the full article here: https://techcommunity.microsoft.com/blog/microsoftintuneblog/what%E2%80%99s-new-in-microsoft-intune-%E2%80%93-june/4491983


r/Intune 3h ago

Windows Management Windows 11 Pro to Enterprise on Autopilot devices with Microsoft E5 - Edition upgrade failing

4 Upvotes

We’re trying to work out the best way to convert a small number of Windows 11 Pro devices to Enterprise without rebuilding them.

Current situation:

Around 35 out of 1,000 devices are still on Windows Pro.
Devices are Microsoft Entra (Azure AD) joined (dsregcmd /status is healthy).
All devices are Windows Autopilot enrolled and managed by Intune.
Users are assigned a Microsoft 365 E5 licence.
Devices have a valid Windows Pro licence.
We’ve excluded the Windows Store for Business cloud app from our MFA Conditional Access policy.

We’ve tried:
Using an Edition Upgrade policy in Intune with the Windows Enterprise GVLK key.
The device attempts the upgrade but throws an error in the activation whilst showing enterprise .

My understanding was that with an E5 licence, the device should step up from Pro to Enterprise automatically once licensing requirements are met, but that doesn’t seem to be happening for these devices.

Has anyone come across this before?
Is there a supported way to convert Pro to Enterprise without wiping or re-enrolling the device?
Is the GVLK approach still the recommended method, or should this happen automatically?
Are there any common prerequisites or licensing checks I’m missing?


r/Intune 11h ago

Remediations and Scripts Force Intune Check Ins

11 Upvotes

Just wondering what all tips, tricks, or scripts you all use to help devices force a check in to Intune. We have quite the number that while they are definitely online and checking in to AD and our antivirus, they're not checking in to Intune.


r/Intune 7h ago

Device Configuration We broke Windows Hello biometrics and can't get them to re-enable

6 Upvotes

Long story short, we applied a policy which had an unintended side effect of breaking Windows hello and biometrics. The policy involved the devices reconfiguring as a shared device to enforce disk quota policies. The problem is that this policy essentially breaks Windows hello as it can only store 10 user's credentials/biometrics so I can only assume it disables this functionality.

I have reversed the policy and set Windows Hello to be enabled but any user who had a device that took the old policy simply can't enrol any biometrics. New devices are unaffected and a reset of a device will resolve it but this is obviously not ideal for 20+ users to do.

Any ideas on what I can try to force this to work again?


r/Intune 4h ago

Apps Protection and Configuration iOS App Protection Policy

3 Upvotes

Weird issue ongoing. We've got users who are unable to take screenshots on personal email accounts in Outlook while the restriction is only supposed to be the organizational account.

Anybody come across this before? Any potential solutions?

This is only on iPhones


r/Intune 11h ago

Autopilot Green screen is back in 26H2 Insider Preview?

9 Upvotes

r/Intune 15h ago

General Question how do you roll out extension whitelisting without disrupting the whole org's workflows.

19 Upvotes

my leadership wants to move from "block known bad extensions" to "allow known good extensions only" and i already know this is going to generate a wave of tickets if we flip the switch overnight.

im posting inthis community to understand what's worked for other people doing this migration? actually our current plan is to log what's installed and used across the org for a few weeks before writing any policy, then build the allowlist from that real usage data instead of guessing what people need. once the allowlist ships, blocked extensions show a self service request flow instead of a hard block, so people aren't just stuck waiting on a ticket. imo my biggest worry is the sales and marketing teams who live in browser based tools all day and have picked up a dozen niche extensions nobody in IT signed off on. don't want to be the reason someone can't close a deal because their crm plugin got blocked without warning.


r/Intune 7h ago

App Deployment/Packaging Teams not auto-updating: Bootstrapper vs Add-AppProvisionedPackage

4 Upvotes

When deploying Teams, is there a difference between downloading the latest MSIX package and running Add-AppProvisionedPackage versus using the bootstrapper exe? Long story but some of our clients are getting banner messages saying Teams is out-of-date and prompting them to download the latest version. We don't want that. If they go into Teams and check for updates it does find and apply the latest update but it's a manual proces.

We are using the MSIX package method and the documentation seems to state that if Teams is not installed via the Bootstrapper then it won't update automatically. The documentation also says the bootstrapper simply downloads the latest msix file and provisions it for all users.


r/Intune 15h ago

General Question PDQ Connect or PMPC for third party patching for intune devices?

6 Upvotes

Good morning,

I'm looking for a third party patch management solution and i cant quite decide between PDQ Connect or PMPC. I understand PDQ Connect is more than just patching but just looking for some advice from admins that use either of them and how they find it.

I am trialling both and i like them i just need some help deciding. Supporting 250 endpoints

Appreciate any advice


r/Intune 9h ago

App Deployment/Packaging Need help regarding app deployment

1 Upvotes

Hi guys, I have a question regarding app deployment. I need to deploy a few applications which should be assigned to a group of users. The application installation should happen only on those devices where the assigned user is the primary user. If the user logs in on a device where he is not the primary user, the application should not get installed.

Any idea how to achieve this?


r/Intune 9h ago

Apps Protection and Configuration MAM Conditional Launch Question

1 Upvotes

All - I'm testing a basic MAM policy and everything is working as expected, with one exception. Under conditional launch, there's a setting called "disabled account" with the option to select either block access or wipe data. However, in my testing I am finding that neither of those options are triggering inside the Outlook mobile app upon user block/password reset.

Am I understanding the criteria for "disabled account" the wrong way? I assumed that when an account is reset/blocked, conditional launch would trigger that setting automatically.

Thanks all!


r/Intune 15h ago

General Question RBAC Rights - Remote Support

3 Upvotes

Hi,

anyone knows which rights in RBAC are required so that the limited admin in intune can click on a device and select New remote assistance session?

So far I tried these and also waited some days for the change:

RemoteTasks - RequestRemoteAssistance

RemoteAssistanceApp - Elevation

RemoteAssistanceApp - TakeFullControl

Also the other posts did not help me:

https://www.reddit.com/r/Intune/comments/16hlha4/android_mdm_start_new_remote_session_greyed_out/

https://www.reddit.com/r/Intune/comments/1h15tzq/rbac_settings_for_help_desk/

Any idea?

Btw. my intune full admin can use it, when I enable the administrator role in Azure


r/Intune 20h ago

General Question Question about kiosk mode setups

6 Upvotes

Recently I got handed a project to put several workstations (tablet PCs running Windows 11) into kiosk mode so they would all point to one webpage, and users would not be able to traverse to the internet and would be locked down on that webpage. The way I had it set up was through the single-app InPrivate kiosk mode, but management wants cookies to be saved so users are able to log in faster on the webpage they are using (this is a priority for them). From what I see in Intune, you cannot configure a single-app kiosk mode without using InPrivate mode. I've been trying to set it up through an OMA-URI, but I've been hitting some roadblocks. I've only recently started using Intune to deploy workstations, so building up policies is still relatively new to me.

I guess my question is this: is there a way to configure a workstation so it's running in single-app, full-screen kiosk mode, and the local kiosk account doesnt clear the cookies on edge?

Any help is appreciated. I've been hitting my head against a wall for the past three days trying to figure this out while juggling other tickets, lol.


r/Intune 10h ago

General Question How do you map a drive on a group of workstations?

1 Upvotes

We have a customer that is Entra Joined/Intune only. I have built a win32 app with powershell scripts that map a drive, but it seems to have a high-failure rate. I've tried a couple different approaches including add-smbshare and net use.

It seems like there should be a better way to have a drive mapping for users. I was really hoping for a Settings Configuration or similar but I don't see anything. What does everyone do for this?

M365 Business Premium.


r/Intune 17h ago

Device Actions Multi admin approval + wipe

3 Upvotes

Anyone had issues with this just not doing anything? The flow within the UI all looks good, the device just never wipes.


r/Intune 11h ago

General Question Intune Autopilot Shared Lab PC Enviroment

0 Upvotes

Morning all,

I want to mention that our current setup is Hybrid. I know—we're trying to move away from it.

With that said, does anyone have a shared PC lab environment that's using Autopilot? Because we're Hybrid, our deployment profile has to be User-Driven.

I have a DEM account that has enrolled well over 100 PCs. For about the last month, I've had an open ticket with Microsoft regarding an issue we're still experiencing. To their credit, Microsoft has been great to work with.

When I factory reset a PC and manually enroll it into Autopilot using PowerShell scripts, the PC reboots back to the login screen. I sign in with my account, and the PC sits on the "Please wait while we set up your PC" screen for about 26 minutes. It then fails and gives me the option to "Reset this device," which I do.

After the reset completes, the PC returns to the login screen. This time, however, it proceeds to the ESP page and, after a short while, completes successfully.

Microsoft's current explanation is that this happens because I'm using a DEM account, and DEM accounts are only allowed to enroll up to 15 devices. I understand that limitation, but I exceeded the 15-device limit well over a year ago without any issues. The only explanation they've been able to provide for why it works on the second attempt is that there may be an actual bug.

This issue started for us in late March or early April.

Is anyone else running a Hybrid Autopilot shared PC lab environment? If so, have you found a better way to handle shared lab PCs?

I can continue this method I just waste time with the multiple PC resets.....


r/Intune 1d ago

Tips, Tricks, and Helpful Hints Please halp. My org wants no Tiktok on any phones. We have a mix of web-enrolled and fully ADE supervised.

12 Upvotes

So for web-enrolled (BYOD) as far as I understand it, if I go in the hardware info and the Supervised state is "no" then I can't apply an app restriction configuration to it and simply have the phone disappear the app. The best you can do is set a compliance policy to immediately make the phone go non-compliant if the restricted app is on there.

For fully supervised ADE enrolled phones, you can go to device configuration and create an app restriction policy which has made the app vanish on the testing I've done. However, the app still seems to be on the phone in some capacity and the App Store thinks it's installed, and it's still marked as non-compliant. I have read that the app restriction basically just hides it. To actually remove it from the phone you add the app you don't want to your App library in Intune, and then assign your users under the "uninstall" section. Also on that subject, I added the app to my Intune app library as a VPP app, and another duplicate entry as an iOS store app - any issue there?

Do I have all this correct? I also read for the non fully supervised phones that you can have it removed by intentionally setting the app as "required" and then it will pop up on users phones and ask them if they want to let Intune manage the app. Then you can set it to uninstall. Is that true and works?

This is all for iPhones by the way. Thanks folks.

edit: just to clarify for everyone, they are corporate phones but they were web-enrolled after being released from the previous MDM so that everyone wouldnt have to wipe their phone. So they're managed with the profile downloaded and installed, but not ADE fully supervised.


r/Intune 1d ago

Device Actions Is anyone else unable to approve Multi-admin approval requests?

12 Upvotes

A wipe request was submitted for a device, but when trying to approve it we're all getting the message:

Failure - Approving approval request failed.

Intune roles are active, browser has been relaunched, request resubmitted.. This seems to have just started recently as well.


r/Intune 1d ago

Intune Features and Updates MD-102 Exam

3 Upvotes

Hello, can someone help me where I can study to pass the MD-102 certification exam? Thank you!


r/Intune 1d ago

App Deployment/Packaging Datto RMM deployment to MacOS: Anyone had sucess

5 Upvotes

So I attempted to deploy Datto RMM through Intune to some of the few Mac's we use, and despite following the instructions on their deployment guide to the letter, have had zero success so far. Script says it ran successfully but the agent is not installed. A little reading suggested it may be due to FileVault being active and the general recommendation seems to be just to install it directly, but I thought I would check here first before I drag a handful of mostly remote people in to install and configure.


r/Intune 23h ago

Autopilot Migrating partially enrolled Windows 10 Home devices into Intune/Autopilot - is this the right approach?

0 Upvotes

I’m fairly new to Intune and looking for advice on migrating our existing laptop estate.

A lot of our devices are currently set up with local/personal Windows accounts, then connected to Microsoft 365 using Access work or school. Some are Windows 10/11 Home, so they are only Entra registered rather than fully Entra joined and managed.

My proposed process is:

- Remote onto the laptop using Splashtop SOS.

- Run a PowerShell assessment to check Windows edition, activation, drivers and current join state.

- Upgrade Windows Home to Pro using a genuine licence where required.

- Capture the Autopilot hardware hash and export it to CSV.

- Upload the CSV into Intune with a migration Group Tag.

- Confirm the device receives our user-driven Entra join Autopilot profile.

- Back up the user’s data and agree a suitable reset time.

- Reset Windows using Remove everything.

- Have the user complete the Autopilot OOBE using their work account.

- Confirm the device is Entra joined, Intune enrolled and compliant.

The preparation and hardware-hash capture can mostly be completed silently while the user is still working. The only disruptive parts should be the windows edition upgrade restart, where required, and the final reset.

Does this sound like the correct and safest approach for moving these devices from local accounts/workplace registration into full Intune management? Are there any common pitfalls, licensing issues or better migration methods I should consider?

Any advice would be appreciated


r/Intune 1d ago

General Question Microsoft Tunnel vs Global Secure Access (GSA) for a 21k iOS Intune migration

8 Upvotes

Hi everyone,

I'm looking for advice from people who have actually deployed and operated either Microsoft Tunnel, Global Secure Access (GSA) / Entra Private Access, or ideally both.

We're currently managing around 20 000 company-owned iOS devices with Ivanti Neurons MDM, and roughly 75% of them are in Supervised mode.

We're now running a Proof of Concept for Microsoft Intune MDM and the currently approved design is based on Microsoft Tunnel. The Tunnel Gateway infrastructure has already been deployed and configured, and we've invested considerable time in the design, security reviews, networking discussions, firewall rules, certificates, VPN topology, etc.

Our use cases include:

  • Access to on-premises resources from mobile devices
  • Per-app VPN
  • Certificate-based authentication
  • Conditional Access integration
  • Internal web applications
  • Exchange/OWA access
  • Future SSO testing scenarios
  • Potential Kerberos/KCD-based use cases

However, the integration partner we're working with is strongly pushing us toward Global Secure Access (GSA) and keeps telling us that:

I understand Microsoft's long-term Zero Trust vision and I can see the benefits of identity-centric access and ZTNA. What concerns me is that moving away from Microsoft Tunnel at this stage would effectively mean a redesign of an already approved architecture and would significantly extend the timeline of the PoC.

So I'd love to hear from people who have real production experience:

  • If you were starting an Intune migration today for a large iOS fleet, would you choose Microsoft Tunnel or Global Secure Access (GSA) and why?
  • What are the biggest challenges you've experienced with either solution in production?
  • Have you regretted choosing one over the other?
  • Are there any mobile, SSO, certificate-based authentication, or on-prem access scenarios where one solution clearly performs better?
  • If you had an approved Microsoft Tunnel design already deployed for a PoC, would you redesign for GSA or continue with Tunnel and revisit GSA later?

Any real-world experience and comment will be appreciated.

Thank you in advance.


r/Intune 1d ago

General Question Why are so many of our phones now appearing as Supervised even though they were web-enrolled after being retired from a previous MDM?

1 Upvotes

I retired the iphones from our previous MDM, then did the QR code method to add the profile to the phone for most of our fleet so they didnt need to be recalled and wiped. So at first most of them were not showing as supervised. However, over time it seems like more and more of them are even though the phones weren't wiped and set up from scratch (ADE). Is this because the phones were always in ABM, and the supervised state they were under with our previous MDM never really left the phone? That's what I'm reading it could be.


r/Intune 1d ago

Hybrid Domain Join Shared manufacturing devices

4 Upvotes

Hey everyone sorry if this has been asked. I’m currently setting up intune for my company. I have all end user pcs enrolled no issue. I’m having issues with our manufacturing plant. I’m trying to enroll them as shared device using device creds gpo. I don’t want these ties to an individual user as the enrolled by since there’s a lot of turn over and if it’s enrolled by a user that leaves, it’ll become non compliant. Is there a way I can enroll these devices? Without wiping and not being tied to one user?