News
How to setup Windows 11 kiosk Multi-App mode with Edge and the Windows App – The XML Struggle
Hi Community, Some time ago a customer asked me if I could help them with the setup of a Windows 11 multi-app kiosk with Edge and the Windows app. I told them straight away that thas is something I really had very little to no experience with. I knew it was going to...
How to Set Up Intune Multi-Admin Approval with Ease – and a quirk
HI Community, Another day another blog, this time on Multi-Admin approval in Intune. This is not a new feature but Microsoft recently added some more functionality to it and for the better! In this blog i will give you some information on what it is and does, show you...
How to setup Windows Autopatch and enable Hotpatch – The Complete Step by Step guide
Hi Community, We are almost at the ending of a great year filled with new and cool features all across the Microsoft cloud ecosystem. After Microsoft Ignite this year a lot of new Intune features where announced. Windows Autopatch is not new however the Hotpatch...
Device Query for Multiple Devices – Security Copilot KQL generation
Hi Community, Guess what? Device Query for Multiple Devices is now live, however not on all tenants so it seems. This long awaited feature is an huge step forward and addition to the single device query that has been around for some time now. Check out the Microsoft...
Security Copilot with Entra and Intune: The Ultimate Trio for Cybersecurity (and Maybe World Domination) – Part 2
Hi Community, Welcome to part 2 of my blog series on Security Copilot. If you missed part 1 you can find it here. [visual-link-preview...
Security Copilot with Entra and Intune: The Ultimate Trio for Cybersecurity (and Maybe World Domination) – Part 1
Hi Community, This time some stuff on Security Copilot. I thought it was about time to write up something on Security Copilot. World domination is not about to happen i guess but you never know. In this blog i hope to show you how powerfull the product is already,...
HyperPilot – Next gen HyperV VM Creation for Autopilot Device Preparation in 3 steps
Hi Community, Are you also creating a bunch of HyperV machines to test out Intune configs, Autopilot enrollments? If the answer is yes to this question i have something cool for you. It is called HyperPilot. This tool is created by Steven Weiner, he is also an Intune...
How to setup Enhanced device hardware inventory in Intune
Hi Community, At Ignite, Microsoft anounced an improved device hardware inventory feature for Windows devices in Intune, giving IT teams more detailed and useful information about their devices. This new feature lets organizations gather and analyze a wider variety of...
How to get the Bundle ID of an iOS app? It’s easy and effortless.
Hi Community, This time a short, but in my humble opinion something nice, about retrieving the bundle id of an iOS app. Let's say you want to use an iOS app protection policy for a custom app in Intune. In this case, you will need the identifier of the app you want to...
Enable Filevault during setup assistant on macOS not working? – It works great, seriously!
Hi Community, Starting from July 2024 there was an issue regarding the enablement of Keyvault during the setup assitant on macOS. You can read the full article here. ...
How To Setup MAM (Mobile Application Management) In Intune – The Series Part 3: Windows
Hi Community, This will be the 3th of 3 guides on how to setup MAM (Mobile Application Management) in Intune. In this 3th part i will cover Windows. We’ll explore how to protect company data on unmanaged Windows devices using Microsoft Intune. For simplicity, We’ll...
Kerberos SSO to Active Directory and Microsoft Entra ID Kerberos resources in Platform SSO for macOS
Hi Community, This time a post about Kerberos with macOS. Mac users can now easily connect their new devices to Microsoft Entra ID during the initial out-of-box experience (OOBE). The macOS Platform Single Sign-on (PSSO) feature, powered by the Microsoft Enterprise...
Easy Identify failed apps during an Autopilot installation (Error 0x81036502 & 0x87D1041C)
Easy Identify failed apps during an Autopilot installation (Error 0x81036502 & 0x87D1041C) When you start an autopilot installation for a device the ESP (Enrollment Status Page) just shows you how many apps are being installed. When an app fails to install...
How to setup MAM (Mobile Application Management) In Intune – The Series – Part 1: iOS
Hi Community, This will be the 1st of 3 guides on how to setup MAM (Mobile Application Management) in Intune. I will be starting with MAM for iOS. We'll explore how to protect company data on unmanaged iOS and iPadOS devices using Microsoft Intune. For simplicity,...
How to get the hardware hash imported into intune without going through the full OOBE for Autopilot
Hi community and welcome to my first post of 2024! With AutoPilot you need to import a machines AutoPilot hash, or hardware ID, to register the device with the Windows AutoPilot deployment service in Azure. Ideally, the process of getting the Auto Pilot hash would be...
Intune Android Enrollment in a loop at “Your Work Checklist” for Corporate-Owned Devices with Work Profile when using afw#setup.
Hey there! I wanted to share a quick piece about a frustrating issue I encountered while doing Intune Android Enrollment, specifically the Corporate Owned with work profile ones. It took me some time to figure out, so I'm hoping this helps anyone else facing a similar...
Intune Assignments User Groups vs Device Groups – A Short Blog
Intune Assignments User Groups vs Device Groups
How to enable insights & Reporting for Conditional Access Policies in report only mode
Many individuals depend on Azure AD Sign-in logs, yet there are valuable additional features to consider for implementation within your tenant. One such feature is the Insights and reporting feature for Conditional Access. This feature allows administrators to analyze...
Configure Local Administrator Password Solution (LAPS) on Entra ID in minutes. (Without OMA-URI & local user group membership policy)
In the dynamic field of IT security and management, safeguarding sensitive information stands as a top priority. Central to this effort is the secure handling of administrator passwords, an area where Windows Local Administrator Password Solution (LAPS) plays a...
How to add extension attributes for AAD-Entra ID Devices
Hi, as you might know it is possible for some time now to add extension attributes to you Entra ID joined devices. A few reasons for doing this would be: Using a device filter on a conditional access policy - see this Microsoft article For instance, you might include...
How to set the Home page (and new tab) & Managed Bookmarks in Edge, Chrome and Firefox with intune
Hi guys, here are some guidelines to get your company defined home page, and other tabs in Edge, Chrome and Firefox with Microsoft Intune, also i will describe how to set some managed bookmarks for these browsers. Additionally, utilizing Managed Bookmarks can enhance...
How to download the intunewin file from Intune
In this article, I aim to provide tips on how to download the intunewin file from Intune when the source files are no longer available or have been lost. The MEM portal doesn't include a download button for this file type. Instead, I'll guide you through a simple...
How to get the ID of your Intune Policies
Sometimes you need to lookup the ID of your Intune policies. Let's say you have an issue with a specific policy and you have requested a service request to Microsoft for assistance. The Microsoft technician can ask you for the ID of the failing policy. In this article...
Manage Microsoft Defender Policies with Intune on Servers or Non-Managed Devices
From the standpoint of endpoint security management architecture, this situation addresses the challenge of overseeing security features on devices that are not under direct management. In the case of Intune-managed devices, whether operating solely in the cloud or...
Intune Attack Surface Reduction Rules for Windows Server OS
Your organization's attack surface includes all the places where an attacker could compromise your organization's devices or networks. Reducing your attack surface means protecting your organization's devices and network, which leaves attackers with fewer ways to...
How To Setup Break Glass Account (BGA Account) Notifications on Azure with SMS and email
It is important that you prevent being accidentally locked out of your Microsoft Entra organization because you can't sign in or activate another user's account as an administrator. You can mitigate the impact of accidental lack of administrative access by creating...
How to renew the MDM Push Certificate on Intune for Apple devices
An Apple MDM Push certificate is required to manage iOS/iPadOS and macOS devices in Microsoft Intune, and enables devices to enroll via: Apple bulk enrollment methods, such as the Device Enrollment Program, Apple School Manager, and Apple Configurator. The Intune...



























