How to exclude all company devices from an Intune Application Protection Policy (APP)
Our company environment is in a hybrid setup. We have an on-prem Entra Connect server synchronizing our on-prem AD with Entra ID in the cloud. We also use Intune to manage our devices including Windows, iOS, and Android. The new project I am working on…
How to remove or disable OneDrive personal on Windows devices via Intune? Is there any policy or settings which we can deploy on devices?
How to remove or disable OneDrive personal on Windows devices via Intune? Is there any policy or settings which we can deploy on devices? I am seeing this on Windows device and hence we want to stop or not to show on device for users. See below snapshot
Autopilot - Why some taking so long time
I have a few devices there it taking one hour to making Autopilot process, what is depend on ? I know it take about 15-20 minutes with a normal autopilot process. How I will troubleshooting that ? // Sokoban

MDM and GPO co-existance
Hello there, I have to move one policy to Intune which is currently configured in GPO. If I enable MDM Wins over GP, I believe other settings configured in GPO will be still be applied on the systems. Is it mandatory to remove the configuration from GPO…
Problem with "The user's password must be changed before signing in" Intune
Hi We have applied Security Baseline for Windows with the Device Lock setting enabled. So this provoke that when we want to log with our local admin user it show a prompt saying "The user's password must be changed before signing in". We have…
TPM Attestation Failed. Error: 0x80280009
TPM Attestation Failed. Error: 0x80280009 We are getting an error during autopilot preparation. I am sure folks have seen this error - Securing your hardware (0x80280009). We're using Windows 11 Enterprise with the most updated BIOS and TMP version 2,49…
Conditional Policy not matching Platform and blocking access
We are implementing a conditional access policy to limit BYOD iPhones to use the Outlook App. We have followed the recommendations…
Intune Update Rings and Feature Update - how to keep them separate
Hey folks, Got a couple of wee questions around Update Rings and separating out Windows 10 to 11 upgrades being provided to our user base. We have four ring profiles configured; three for standard patch Tuesday Updates, one for Windows 10 to 11 Upgrades.…
Addressing 'Disable JavaScript on Adobe Reader DC
Hello All, Can somebody please assist. How do I Address Defender Security Recommendation 'Disable JavaScript on Adobe DC. I have 100 devices that needs remediation, is there a PS script I can run or another option?
Intune script fails "Powershell execution has exceeded defined timeout."
Hi All, The script only takes backup of Outlook signatures and removes them. Applied the script through Intune. The device is marked as compliant. What might be the reason of the script failing with the result "Powershell execution has exceeded…
How to deploy printers with Intune using device groups
I'm trying to deploy a printer that I have setup in Universal Print to some workstations (so that anyone who logs in gets the printer) with an Intune policy. I have been able to make it work using a group containing user accounts. But, it will not work…
Azure/Intune Remote tools?
What is the Intune Remote software tool to remote to other systems?
Users Unable to View Saved Passwords After Switching to Web Sign-In
After changing device configurations in Intune to enable web sign-in, users are unable to view their saved passwords in Edge and Chrome. When trying to access saved passwords, it prompts for a "device password," but no field is available to…
Disabling Personal Email Access on Corporate Devices via Intune
Is it possible to restrict access to personal email accounts on corporate Windows devices using Intune? Many users in the organization are signing in to apps like Copilot and Adobe with their personal email IDs.
How to setup Intune MacOS Device Configuration policy for Google Chrome
Hi, We have setup a device configuration policy for Google Chrome on our Windows devices but, we need to do the same for MacOS. What would be the best advised way to do this? Thanks, Jack

How to grant permission to manage apps in Intune
I have created a custom role within Intune and granted the permission of managed apps - read, however, the users that are assigned this role are not able to view anything under Devices\Windows\Device Name\Managed Apps. Is there a specific permission…
Configure devices from multiple Microsoft 365 tenants in different OUs with Intune
Hello, Is it possible to use multiple tenants for Intune if the devices belong to the same domain? More precisely: Can a hybrid join be configured via the Intune Connector so that it does not refer to the entire domain, but to the specific OU of the…
Can not access the link from edge ,working fine in chrome
We have 2 categories for devices. Azure ad connected and hybrid. For azure ad device , we are unable to browse to specific https url. It’s shows Your Connection isn’t Private and if click on advanced option we are not able to see the link to proceed.but…

Which License is required to manage Bitlocker through Intune, is it Windows 10 pro or enterprise
License Confusion for Managing BitLocker via Intune License Confusion for Managing BitLocker via Intune Scenario: We are managing BitLocker through Intune, with recovery keys backed up to Entra ID for both Hybrid and Entra ID-joined devices. Our devices…
Guest account logging is not working
Microsoft Intune managed devices, some computers, guest logging is working, other computers, when you click on guest login, nothing happens