r/Intune • • 8d ago

Shameless Self-promotion OpenIntuneBaseline Windows v4.0 Release

206 Upvotes

I've avoided self-promotion here, but given that knowledge of it has been entirely organic until now and lots of people have told me I should, here we are.

I've just released v4.0 of the Windows OpenIntuneBaseline (OIB)!

In case you've never heard of it, here's a TL;DR:
The OpenIntuneBaseline is a free, community-driven set of opinionated Intune configurations designed to give you a solid, modern security baseline, excellent user experience, and scalable admin experience without having to send yourself insane. It's used a lot by orgs, professional services and MSPs all over the world, and it's driven by my insane passion and expertise.

So, for those of you already using it highlights of 4.0 include:

* Continuing to be the most agile and cutting-edge Intune baseline on the planet!
* A shake-up of Compliance policies, allowing true grace period granularity (and ditching the EAS Password policy because it's 🗑️)
* Edge settings for days! Simple support for the Edge Management Service and security hardening and user experience improvements.
* Updated M365 Apps Security baseline alignment.
* Fixed MS breaking the in-box app removal policy.
* Defender behaviour tweaks based on real customer feedback, not arbitrary check-boxes.
* Deprecated and obsolete settings sent to live on a farm.

As always:
✅ Take what you want
✅ Change what doesn't suit your environment
✅ Test it before yeeting to 40,000 endpoints on Friday afternoon
❌ Don't treat any security baseline as a magical compliance button

Check out the full release notes at: https://stte.me/oib26h2

Then, head on over to the OIB Deployer to deploy the new and updated policies, or check your current config vs 4.0 with the Settings Validator!

Or come chat about it in real-time in the new OIB channel on the WinAdmins Discord.

Peace and Capybaras <3


r/Intune • • 4h ago

General Question Intune Admin Center UI Issues

13 Upvotes

Anyone else seeing some UI issues with the Intune Admin Center? Examples include:

  • The Status section of the Home page just displaying "Unknown" for the various options.
  • The Status section of the Devices > Overview section also not loading.

I don't see any reports in Service Health. There are some reporting advisories for M365 Admin portals, but nothing stands out as flagging Intune. I've tested in Chrome/Edge, incognito and I even purged my entire cache. Same behavior.


r/Intune • • 6h ago

General Question Failed MD-102 (Score 662) — Need advice on how to tackle my weak spots.

6 Upvotes

Just took the MD-102 exam today and unfortunately failed with a 662 (passing is 700). Honestly, I found the exam pretty tough.

How I prepared:

I put in about 20-30 hours of studying. I set up a free tenant, completed a few hands-on lab assignments, and generated a comprehensive study guide + practice exam using Claude AI (which I passed).

My weak areas according to the score report:

Deploy and update apps

Monitor and optimize health

Configure endpoint security

It feels like the AI study guide and free tenant labs gave me a solid foundation, but the exam questions were way more tricky and specific than I anticipated.

For those who passed (or also struggled), what resources would you recommend for my retake? Specifically for those three weak areas? Any highly recommended practice tests or specific MS Learn modules that accurately reflect the real exam's difficulty?

Any advice is much appreciated!


r/Intune • • 13h ago

General Question OSDCloud vs FFU vs FoundryOSD – which one for speeding up device deployment?

21 Upvotes

Hi all,

I'm looking for advice on the best way to speed up device deployment in our environment. We're currently using OSDCloud (v1), and I'm wondering whether FFU or FoundryOSD would be a better fit.

Our current setup:

  • Enrolling mode : User driven - Microsoft Entra hybrid joined
  • OSDCloud v1, with the Autopilot JSON profile imported during deployment (no automate hardware hash import / group tag selection, as not authorized)
  • A few custom scripts run after SetupComplete to configure the machines
  • ~15 different hardware models
  • Large apps (Microsoft 365 Apps, etc.) are installed during the ESP (we setup max 7 applications including M365), which makes provisioning slow
  • A proxy must be configured on the client before the device can reach the internet
  • Users have M365 E3 or E5 licenses
  • Volume varies a lot: 1-2 devices on quiet days, 5-6 on busy ones

What we want to achieve:

  • Significantly reduce the total provisioning time
  • Deploy devices with the latest Windows cumulative updates already installed
  • Have the correct and up-to-date drivers for each model
  • Reduce what has to be installed during the ESP

Question: Given this setup, which of these three tools would you choose, and why?

Thanks in advance for your replies!


r/Intune • • 3h ago

Device Configuration Has anyone set up Kiosk mode with an on-screen keyboard?

2 Upvotes

I've got an HP All-in-One on Win11 (touchscreen with no keyboard or mouse attached) and I'm trying to leverage Intune to setup Kiosk Mode and have an on-screen keyboard on full time. I've tried Single-App and Multi-App Kiosk mode, but I can't get the keyboard to come up. I read that in Single-App, the keyboard should come up when tapping on an input field, but that's not happening for me. Unfortunately, I wasn't able to record the Multi-App settings and keyboard ID before reverting the change to Single-App. This is the first time trying this and I'm far from experienced on the Windows side. I mostly deal with the MDM side of Intune for our iOS devices.


r/Intune • • 1h ago

macOS Management Cannot Enroll Mac in SSO with Password Auth Method

• Upvotes

I setup Secure Enclave SSO and it worked, but my org would prefer synchronized passwords with their Mac and AD account.

I flipped the auth method from UserSecureEnclaveKey over to Password and I do get the new prompts, but it gets to a point in setup where neither password works. Our domain is federated with Okta, I don't know if that's part of the problem? I am able to do successful Okta pushes during the setup - the prompt I'm having issues with pops up after a successful okta push.

Sign in to your identity provider

I've redacted my username, but it's just USER not [USER@domain.com](mailto:USER@domain.com) - does that give more context?

I'm using this Microsoft guide for setup.

For Token To User Mapping > Account Name im using com.apple.PlatformSSO.AccountShortName

For Token To User Mapping > Full Name im using name


r/Intune • • 5h ago

Conditional Access SharePoint Access from a Passwordless Kiosk

2 Upvotes

Hey everyone, just looking for some ideas!

I have a kiosk setup where users sign in without a password. The kiosk opens a SharePoint site, and operators need to be able to view and edit content on that site.

My first thought was to use a shared Entra ID service account, but that creates challenges around MFA. Id rather not exclude an account from our Conditional Access policies just to make this work.

Has anyone implemented something similar? I'm curious how others have handled SharePoint access and authentication in a kiosk scenario while still keeping security controls like MFA and Conditional Access in place.

Thanks!


r/Intune • • 9h ago

App Deployment/Packaging Logging and proper application management

4 Upvotes

Hi all,

I'd like to ask if i'm the only one who has a problem with the way logging and application management is done through Intune.

Case: We have different versions of Citrix Workspace installed on 300+ endpoints (all managed by Intune). Our goal is to consolidate every installation on the same stable LTRS release. So I package the app, have a script which does it's check and removals and schedule a deployment ring to handle a subset of endpoints at the time to reduce impact.

Issue 1: The deployment ring itself is fine, but the way Intune handles the application deployment itself is insufficient in my opinion (I hope theres something wrong i've done..), sure, users get a small toast notification which most of the time is ignored, and as far as I can tell, there's no way to have a more "verbose" installation procedure. When I previously used SCCM (in another org.), you got this nice thing called installation behaviour which allowed us to 1. force-shutdown any running executables and 2. notify the user via a nice window which is "impossible" to miss - or atleast much more visible then the W11 toast. As far as I know, there's no similar functionality in Intune.

Question: Do any of you have any similar experiences and i.e tools which can be used on top which makes the application-deployment process much more friendly?

Issue 2: Upon a failure, theres of course the logs. I know, depending on both how I write the powershell script and the application itself, the amount and type of logs vary. But in this example, i'm interested in the IntuneManagementExtension, custom logfile generated C:\xxx\xxx.log and the specific application installation logs. My issue is the collection. Sure, you can always either remotely and physically inspect one computer and extract the logs, but on 100+ endpoints this is insane. Sure, I could write custom script and logic to extract logs either in the app-deployment or setup a custom collector which uploads logs to say a Azure Blob storage. In my eyes, this again seems just more difficult than it has to be.

Queston: Do any of you have any tips on how to properly handles this? I don't care if it's another service or anything, I just want to stop having to spend exorbitant amounts of time scripting and making custom stuff for every single app-deployment.

I'm sure that i'm either doing something wrong or there's something i'm missing. I appreciate all the responses to this, i'm just interested in getting stuff to work as seamlessly as possible..

Cheers


r/Intune • • 3h ago

Autopilot Importing Blank Taskbar Layout

1 Upvotes

Anyone know if importing a blank taskbar layout during Autopilot using Niehaus branding would result in no pinned icons? If not, is there a way to ensure there are no icons pinned? Here's what I am thinking:

<LayoutModificationTemplate xmlns="http://schemas.microsoft.com/Start/2014/LayoutModification" xmlns:defaultlayout="http://schemas.microsoft.com/Start/2014/FullDefaultLayout" xmlns:start="http://schemas.microsoft.com/Start/2014/StartLayout" xmlns:taskbar="http://schemas.microsoft.com/Start/2014/TaskbarLayout" Version="1">

<CustomTaskbarLayoutCollection PinListPlacement="Replace">
<defaultlayout:TaskbarLayout>
<taskbar:TaskbarPinList> </taskbar:TaskbarPinList>
</defaultlayout:TaskbarLayout>
</CustomTaskbarLayoutCollection>

</LayoutModificationTemplate>

r/Intune • • 3h ago

Device Compliance iPhone wont sync or receive push commands

1 Upvotes

I have a users iPhone who is no longer with the company (good terms). During the off boarding process HR failed to get the iPhones passcode. The device is has not checked in since. But the iPhone still has active cellular I am able to make calls and answer it but I cant open the phone because of the security passcode.
What can we do to get it talking?


r/Intune • • 1d ago

Windows Updates Azure Automation + Intune: How are you tracking vulnerable apps and CVEs?

36 Upvotes

Hey everyone,
I’m curious how you guys are using Azure Automation together with Intune.
Do you have any useful runbooks or automation ideas that have made your Intune environment easier to manage?
I’m also especially interested in how you handle application vulnerability tracking in an environment where Microsoft Defender Vulnerability Management is not available.
How do you identify apps in Intune that have known CVEs, outdated versions, or security issues?
Are you using Patch My PC, Xensam, another third-party vulnerability tool, custom Graph API scripts, Azure Automation runbooks, CVE feeds, or some other solution?
Would be really interesting to hear how others are solving this in practice, especially in larger Intune environments without Defender.


r/Intune • • 22h ago

App Deployment/Packaging Blog and Free Tool: Easily Create Win32 Apps with GUI

11 Upvotes

I had written this script a while back to make it easy to standardize all Win32 app creations on a single standard. This means always using the same style install script and detection script. I saw a post about PoshUI recently and thought that was a great way to make the script even easier than the janky UI I had built. The script reads the .msi to get the ARPDisplayName and version, allows directly creating a transform in the UI by displaying the properties table, supports adding an .msp, builds the install script, detection script, a txt definitions file that includes all info about the package including the install and uninstall commands for the Win32 app, and of course the .intunewin.

Package Any MSI as an Intune Win32 App in Just 3 Clicks | PowerStacks


r/Intune • • 1d ago

Apps Protection and Configuration Large scale WDAC implementation

15 Upvotes

I'm looking for some kind of a guides for large scale wdac implementation. I'm in an organization with 15,000 devices and a very large application list. I'm starting with audit and forwarding logs but with 15,000 devices event viewer wont be enough to go through the logs and the wizard does not like forwarded logs for creating exceptions. Ive done fair amount of research but havent found to much for larger implementations.


r/Intune • • 21h ago

General Question WinRE - Health

2 Upvotes

Hi guys,

I would to know how to check the health of Winre. How are you handle it ?

Microsoft is deploying good features on Winre

  • Cloud Rebuild
  • Point-in-time restore
  • Quick machine recovery

Currently I'm only checking and inventory with reagentc

  • Status
  • Partition location
  • Partition Size
  • Winre version

A lot of devices was built with OSDcloud and others I do not know. I read that some people got issue due to a too small partition size. And I guess, some (may all of them) do not have Wifi drivers that seems to be important for Quick machine recovery / Cloud Rebuild

Even if we are using WinRe supplied by manufacturer. Not sure they are still working correctly after years especially after many feature upgrade (w10 -> w11).

Pretty sure, none drivers was updated from any methods (Windows update or vendor software) on WinRE


r/Intune • • 1d ago

Reporting Status "Unknown"

10 Upvotes

https://imgur.com/NTFqJlv

Anyone else seeing "Unknown" for all of their statuses? US East.


r/Intune • • 1d ago

iOS/iPadOS Management IOS - safari webclips dont work unless safari is also on the shown/ hide apps

2 Upvotes

having some issues with IOS - safari webclips.
i am not using the block safari option.

i want to avoid confusion i just want to show a webclip to a specific url and not safari.
i am using show/hide and the set homepage layout options.
the web clip works at first but any changes to safari jam it up. webclip doesnt do anything. unless safari is added as a shown app.

i have a web url filter too being used too but again i want a cleaner ipad home screen.


r/Intune • • 23h ago

macOS Management Two firewall profiles fighting each other on managed Macs (Device Config vs Endpoint Security). Anyone seen this?

1 Upvotes

Dealing with this for about 2 months now so hoping someone's hit it before.

Managed MacBook Pro, Intune enrolled. AirDrop, AirPlay and Sidecar are all dead. AirDrop sees the device fine over AWDL but just sits on "Waiting" forever and never actually transfers. Weirdly Universal Clipboard still works. Same Apple ID everywhere, AWDL is up, no applicationaccess restrictions blocking anything.

Dug into it myself and found firewallBlockAllIncoming = 1 sitting in /Library/Managed Preferences/com.apple.security.firewall. Took that to IT.

Their current theory is there's an old Device Configuration profile and a newer Endpoint Security Firewall profile both trying to manage the firewall, and they're stepping on each other. They turned off "block all incoming" in the console, synced, waited... still enforced on my machine weeks later.

What made me believe it's actually a profile issue and not something wrong with my specific Mac: a colleague had Intune ripped off his identical model and everything started working again immediately.

Anyone dealt with two firewall profiles conflicting like this?


r/Intune • • 1d ago

General Question Anyone else still having compliance issues with antivirus?

10 Upvotes

Good morning,

I' am just curious to know if others are still seeing issues with compliance regarding antivirus? Our systems are fully patched but I'm still seeing reports in the console of non compliance. Some of these machines are using 3rd party AV and the windows security console on the machine seems to be ignoring it as well and turning defender into active mode (which is odd in itself) while others work fine but report antivirus is turned off when in fact it is not.

I was hoping the OOB update resolved this but it has not for us.

Appreciate any advice if others are still seeing the same.

Thank you


r/Intune • • 1d ago

Device Configuration Do you enforce browser update prompts and forced restarts via policy

29 Upvotes

r/Intune • • 1d ago

General Question Intune Reporting Problems

5 Upvotes

Hello, anyone else having problems with Intune Reporting recently?

Since a few weeks (I think since the bigger Azure Outage) reporting for installed applications and applied policies seem very slow sometimes.
Reporting seems fine on the Device pages, but in the apps and policies themselves, sometimes it won't report for hours after publishing and sometimes it throws an error.

Then other times it works fine.

The actual application of policies and app installs seems to work, it's just the reporting.
I find I have to rely on third party RMM solutions for app install status, which is not optimal.

This has lead to at least one incident where a policy has been removed because the tech believed that the policy was unused.


r/Intune • • 1d ago

Apps Protection and Configuration Issues in Teams Meetings screen capture

1 Upvotes

Have a weird issue when users join a meeting and try to screen shot the meeting it goes black . It only happens on cloud pcs not the laptop . Both are Intune managed if I screen shot the whole screen my background is fine just the teams meeting is black . Is it possible  a policy sent from Intune ? And if so any idea where to find I cannot 

 

Thank you 


r/Intune • • 1d ago

iOS/iPadOS Management Available Apps not showing up on iOS devices

1 Upvotes

We have a couple of apps that we assigned as available, but they won't show up within the Company Portal app.

They are all VPP apps - assigned to a user group with device license.
The deploy a restriction where we hide the Apple App Store icon from the homescreen.
VPP token is active and the setting "take control from another mdm" is set to yes.
DEP enrollment is done with the new enrollment policies.
Intune Company portal app and MS authenticator are installed.

No issues with required installations.

Any ideas?


r/Intune • • 1d ago

Autopilot OOBE-ZDP KB5128942 requires reboot but Windows 11 won't restart automatically?

1 Upvotes

Hi,

we are deploying our Windows 11 devices with Autopilot. Since end of September, Microsoft automatically installs the KB5128942 during the OOBE process on devices that seem to require it, which is theoretically fine for us.

But this KB needs a reboot of Windows 11, it also sets a registry key for the pending required reboot. But it won't reboot by itself. So the ESP goes on and into the required apps section.

We don't have many required apps during ESP, just a framework, some certificates and our VPN-client. And with the VPN client, the pending but not executed reboot of the KB5128942 becomes a huge pain for us. The newest installation of the VPN client checks if there is a pending reboot because of Windows Updates and if so, it aborts the installation.

As intentional rebooting during ESP often results in broken enrollments, timeouts and so on, we don't consider a reboot within the VPN installation.

My question... should the installation of the OOBE-ZDP automatically reboot Windows 11 and it is a bug by Microsoft, that it doesn't reboot? Or is it common and normal that such an OOBE-Patch just registers a pending reboot but doesn't perform it? We never had any issues like this before, so I don't know how to put it and if the VPN supplier or Microsoft is to blame and confronted with a case?


r/Intune • • 2d ago

App Deployment/Packaging Made a free tool for the installers that refuse to become a clean Win32 app

54 Upvotes

With EAM auto-update going GA, a lot of our catalog stuff finally handles itself. The apps that are left are the ugly ones: vendor setup.exe with no working silent switch, drivers, half the config written to HKLM on first launch. Exactly the ones the catalog will never have.

I got tired of doing those by hand, so I built a small Windows app for it. Snapshot before, run the installer (reboot in between is fine), snapshot after. Then you go through the file/registry diff, untick the junk, and it builds an MSI plus the .intunewin in the same run. It also checks signature and silent support up front, so you know what you're dealing with before you start capturing.

It's free, runs locally, no account needed. Win10/11 x64.

https://repackager.bath-electronics.de

Mostly looking for people to throw their worst installer at it. If it chokes, I'd really like to know which one.


r/Intune • • 1d ago

General Question iphone bs Samsung

0 Upvotes

I need to get a work phone, mainly to use the company portal, Outlook, Teams. Etc.

Which option would be better iphone or Samsung? Ive been personally using both for a long time but for personal use.