Endpoint protection/MTD for user-less devices enrolled in intune
Hi, I am looking to have some MTD solution for user-less devices that are enrolled in intune. If I understand correctly its is not possible with defender as it requires a user account. Does anyone have any tips on if there are any other endpoint…
Implement App Control For Business
Good afternoon, To protect our organisation from possible improper installations, we implemented Microsoft's new App Control for Business tool. We've had some challenges, but we've managed to overcome them all by applying supplementary policies with a…


EDR Policy Success but Devices Show 'Can Be Onboarded' Status in MDE
In an environment where an EDR Policy is configured to onboard devices, the policy reports success in Intune for all scoped devices. However, some devices have been successfully onboarded to MDE, while others continue to show an onboarding status of 'can…
How do I to Find the Location of Quarantined Malware found in an Intune Microsoft Defender Antivirus Report?
Hi all, I’m currently using Intune and have configured Antivirus policies. When I check the report in Microsoft Defender Antivirus, I can see malware such as HackTool:Win32/AutoKMS!MSR that have been detected and moved to quarantine on a couple of…
Solidwork PDM View set up issue with intune
We currently have a large number of users running solidworks pdm viewer installed at the C: level. When trying to run the installer on a newer machine with intune it prevents installing at the C: level and requires an additional folder layer to be…
Best practices for defender p1 plan for hybrid devices
We use on-prem Active Directory which syncs to Azure Entra ID in our M365/Azure tenancy All users are licensed for M365-E3 so all devices step-up from Windows 10/11 Pro to Enterprise We have used a deploy script provided by Microsoft as part of the…
Intune y MDefender
Hello, I have an Azure Tenant configured with computer synchronisation with EntraID On the other hand, I have the Microsoft Defender console configured The thing is, I have computers that are not registered in Intune and have Microsoft Defender…
Run processes with elevated privileges using the Entra account.
Hello, Windows devices are managed by Intune. All users have standard user privileges. For IT department employees, the "Microsoft Entra Joined Device Local Administrator" role is assigned However, to perform any administrative actions, you…
Why cannot the MDM be removed completely from a BYOD and why is the phone still under the control of the MDM?
My personal iPhone that was used to access work email via Outlook app had experienced extreme drain of battery and usage since last August when the work account security issue was reported. Is it normal to ask for the unlocking code to a personal cell…
how to get 6 digit verification code from microsoft authenticator app
I was trying to login in one of my company website using my Microsoft Account. After i gave credential and password it is asking for authentication code which is showing in my authentication app in my phone. I am seeing 8 digits code Microsoft…
How can I force an Intune-enrolled machine to log in with an Office 365 password?
After configuring Intune, I enrolled a client machine into Intune. I want to unset the Windows PIN password and enforce the use of the Office 365 password as the PIN. This is because an unset machine prompts to set a PIN at first boot.
Credential Guard - Windows 11 pro/business with O365 Business Premium license
Hi, We have Windows 11 pro machines with o365 Business Premium license. I try to enable Credential Guard for the computers but it is not being activated. VBS service is running. On some websites i read that Windows 11 pro is not supporting Credential…
Can't Recieve SMS Code! Why can't i have the code?
Alright, here the problems -How can i verify my identity if i can't even get the SMS Code? -How can i add alternative email if you guys didn't even send the SMS Code? -How can i add another protection meanwhile this whole system telling me to verify my…

What does the Defender Anti-Spam (Inbound) policy overrule?
The Defender Anti-Spam, Anti-Malware and Anti-Phish policies all sit together in the Email Policy and Rules section, but I am trying to understand what an exception to these policies would over rule? Mainly looking at the Anti-Spam Policy, as that is…
Issue with Web Content Filtering – Indicators Not Working
Hello, I'm trying to set up site blocking using Web Content Filtering. After enabling all the necessary components in Advanced Features in security center: Web Content Filtering And configuring the following components in the system (via…
MS Defender web protection / SmartScreen for Google Chrome and Firefox
Hi. We have our CE+ assessment in a few weeks. In our CE basic, we provided information about our browsers Edge, Google Chrome and Firefox they have MS Defender / SmartScreen options enabled for malicious sites and downloads. Unfortunately, MS Defender…
ADMINISTRATION PROBLEM
So my mother originally set up an account on my computer which gives her administration. There are some applications I can't download or delete without permission, but the problem is: She forgot the password to it, and she said she can't reset it. I…
Windows Hello for Business- Intune
We have Windows 10/11 devices enrolled in Intune. How can we enable users to use WHfB for computer logons without requiring it to be used? The option for standard users to set up WHfB in the device settings are grayed out.
Conditional Access Policy Frustration
I do what I am asked. I was asked to build a policy that would prevent using Office 365 apps or access to Online apps unless the device was either Entra Registered or Entra Joined. I have this working 99%. The issue is that I cannot enroll new devices…

BitLocker Recovery Prompt After Update - Assistance Needed
Hi everyone, I’m experiencing an issue where BitLocker recovery is being required on a device, and I’m trying to understand why. The device recently received update KB5048652, and the recovery prompt started appearing after that. Is there a way to…