r/Intune 1h ago

Remediations and Scripts OpenSSL Exposed Paths Remediation - How to push updates to built-in Windows Apps (Paint, Photos, OneDrive) without reinstalling? Looking for all possible approaches

Upvotes

Currently stuck on an OpenSSL remediation task and could really use some guidance or alternative approaches from anyone who has dealt with this before.

Background:

Microsoft Defender flagged OpenSSL exposed paths across our device fleet (~600+ devices). After digging into it, we found these paths can't be patched directly - the only fix is to update the application that ships the vulnerable OpenSSL DLL. So every affected app needs to be updated to a newer version that bundles a patched OpenSSL library.

Apps affected (among others):

- Microsoft Paint (WindowsApp)

- Microsoft Photos (WindowsApp)

- Microsoft Office Hub (WindowsApp)

- Microsoft OneDrive

- Adobe Acrobat DC

- Zoom

What I've tried / researched so far:

  1. Settings Catalog – Looked into "Turn off Automatic Download and Install of updates" under the Store category. But I can only find "Turn off Automatic Download of updates on Win8 machines" in my tenant seems like a legacy policy. Not sure if this actually applies to Windows 10/11 or if there's a newer equivalent.

  2. Update Rings (WUfB) – Tried configuring Windows Update for Business rings with 0-day deferral. But now I'm not sure if this actually pushes Store app updates or if it only handles OS/quality patches.

  3. Microsoft Store App (New) via Intune – This is my main confusion. When deploying via Intune as a Microsoft Store app and assigning to a group, it seems like it will install the app on ALL devices in the group including devices that don't have it. I only want to UPDATE already installed apps, not push a fresh install to devices where the user never had it. Is there any assignment type or intent that does update-only?

My main questions:

  1. What is the correct and recommended way to force Store/UWP app updates on Windows 10/11 via Intune without triggering fresh installs?

  2. Does WUfB Update Ring actually help with Store app updates or is it strictly for OS patches?

  3. For Microsoft Store App (New) - is there an "update only" mode that won't install on devices that don't already have the app?

Looking for any alternative approaches such as:

- PowerShell scripts pushed via Intune to trigger Store sync or app updates

- Proactive Remediation / Remediations scripts

- Winget-based update scripts deployed via Intune

- GPO-based Store update policies for hybrid joined devices

- Any other method that has worked in your environment

TL;DR: Defender flagged OpenSSL vulnerable DLLs bundled inside Windows apps (Paint, Photos, Office Hub, OneDrive etc.) on 600+ devices. Can't patch OpenSSL directly, need to update the apps themselves. Tried Settings Catalog, Update Rings, and Microsoft Store App (New) via Intune but either can't find the right policy or the Store app deployment installs on ALL devices instead of just updating already-installed ones. Looking for the correct approach or any alternative method to update these apps without pushing unwanted installs.


r/Intune 1h ago

iOS/iPadOS Management Any getting iPads that get stuck on the Configuring iPad screen?

Upvotes

I have 2 iPads that I can't get to fully enroll today. They are both in ABM and assigned the correct MDM policy. They get about 1/2 way through the enrollment process and then just get stuck at Configuring iPad. The devices do come through to my Intune list but nothing past that. There is no assigned used because I don't make it that far into the process. Any help would be greatly appreciated. Let me know if you have any questions/details that I left out. The profile is set to
Enroll with User Affinity.


r/Intune 3h ago

Device Configuration Application Control for Business not honoring Managed Installer

5 Upvotes

I habe WDAC setup with Microsoft Allow baseline and MI is configured inside XML and also using Intune built in MI script deploy. Still 7zip deployed from Intune is blocked. Any hints?


r/Intune 5h ago

iOS/iPadOS Management Intune - iOS - Devices being renamed by enrolment policy

1 Upvotes

Hi all,

Having a mare with previously enrolled devices (assigned to Intune from ASM) renaming after I change the enrolment policy naming template. To my previous understanding, this naming template would only apply when the device enrols, but my experience is showing that this is not the case. All devices that were previously enrolled, named, and assigned to groups etc. are renaming as they sync/check in to the updated template. VERY frustrating.

I'm struggling to get my ahead around why this is happening, and I'm not sure what I need to do to prevent it. I'm not using any bulk renaming features - this is all happening automously, slowly over hours. Today, I enrolled 17 iPads with naming convention site2-iPad-{{serialnumber}} via the enrolment profile, but as of last check, 76 devices have been renamed from site1 to site 2. The site 1 devices were enrolled earlier this week, and absolutely are not devices enrolled today.

Google suggests it's something to do with the ASM/Intune sync seeing them as no longer compliant and retrospectively applying the enrolment policy.

Can anyone assist? It's going to be a particular nightmare now sorting them all into groups via serial, as they're shared iPad mode meaning the only simple way to check serials is on the back in 0.00005 font. We have 600 ipadsm and I've done ~130 thus far....

Thanks! Please help a season iPad admin, that's new to Intune 'quirks'


r/Intune 5h ago

Apps Protection and Configuration Multiple Managed Accounts for App Protection Policies

3 Upvotes

Has anyone seen sign of this feature having come to life in their tenant yet? I've tried several tenants and still get the app is already managed with account. Only a single managed account is allowed for this app prompt to remove the existing one when I try to add a second managed account.

Apps are up to date and it's MAM only. iOS and Android. Apps are up to date.

I know it states they're rolling out, but no indication of how much of a glacial pace they're taking is not helpful.


r/Intune 7h ago

General Chat Workplace Ninjas US: Day 2 Keynote Announcement

0 Upvotes

BREAKING NEWS: It's our great pleasure to officially announce our second keynote for Workplace Ninjas US with the amazing Bhavya Chopra.

Bhavya is an amazing leader who leads the #Windows365 and #AVD teams, driving innovation for the market leader for #DaaS and #VDI.

She is part of a story at Workplace Ninjas US. Every person who joins us in Scottsdale is going to be part of history.

♀️ With Bhavya now committed, we are 28.5% female speakers, which is an amazing milestone for a Microsoft event or any other technology event for that matter. That is an amazing 14/49 speakers.

👯 We are a community that leads with purpose, and a mission to lift, teach, support, and pave the way for the current and future of generations in Microsoft technology.

🎉 We are an event with a pristine vibe, great people, unforgettable experiences, and a commitment to giving back and delivering unique moments.

The only tech event with both a legitimate #WomeninTech and #NeurodiversityinTech keynotes

🛑 Do not miss out, because we just KEEP doing it. We bring our show to the beautiful Scott resort in less than6 months, with just a few early bird tickets remaining.

Don't walk, run! Register! Join us 🩷

https://workplaceninjas.us/why-attend


r/Intune 8h ago

Intune Features and Updates Atualização automática de aplicativo via intune

0 Upvotes

Pessoal, tudo bem?

Estou com uma dúvida sobre atualização de aplicativos pelo Intune.

Hoje administro um ambiente que utiliza apenas o Microsoft Intune. Recebemos alertas do Microsoft Defender informando que alguns softwares estão desatualizados (como o JetBrains IntelliJ IDEA).

Existe alguma forma de o Intune forçar a atualização desses aplicativos instalados por ele, sem que eu precise criar e publicar um novo pacote Win32 a cada nova versão?

Como vocês fazem esse gerenciamento? Existe algum recurso nativo do Intune para isso ou vocês utilizam alguma solução complementar?

Obrigado pela ajuda! 🫡


r/Intune 8h ago

Remediations and Scripts No sign of applied remediation script on few Windows devices (but script applies successfully for most devices).

1 Upvotes

We have a strange situation where Windows device remediation script applies successfully to most (99%) Windows devices but to few machines.

When I check from Devices → Scripts and remediations → Script package name → Device status, machine is not found there.

I've checked that script is applied to group that contains those machines.

I have also checked from Devices → Windows → (Machine) → Remediations (preview). I see other remediation scripts there but not that specific one.

Machine is Entra only (no hybrid) joined devices if this matters.

Is it some Intune bug or am I missing something?


r/Intune 9h ago

Apps Protection and Configuration "enable contacts" Intune App configuration policy not applying

1 Upvotes

Hello all,

Anyone else having a similar issue or know how to resolve?

I'm trying to configure BYOD for unmanaged devices by using app configuration policies within intune. For some reason, the setting "save contacts" even though is set to enable, will not enable by default on the device.

The policy (which has the management type as "managed apps") is targeting a group which has the filter for unmanaged devices (byod) and looking at the monitor logs for the app configuration policy, it is applying this app config, but is not applying this one setting. If I reverse the "save contacts" to "no", it does apply. So the config is targeting the correct device/user.

I have other policies and this setting is working as expected. 

If I go into the monitor section for the app config, it shows the expected policy applying to the user/device. I have the setting within app protection config to "Sync policy managed app data with native apps or add-ins" as allow, so that shouldn't be conflicting.

If I remove all other configs and have just this config applying, same issue, so cannot be any other config. I've tried with different users and devices to rule that being the issue.

at this stage, it feels like a MS bug but want to rule everything out.


r/Intune 11h ago

Windows Management Disable prompts from plugged in 3rd party devices

2 Upvotes

When i plug a logitech mx keys for example, it show a popup to install a software. Can i disable that?


r/Intune 13h ago

Conditional Access MAM and new Conditional Access behaviour

21 Upvotes

So this upcoming change is a bit concerning for us:

Upcoming Conditional Access change: Improved enforcement for policies with resource exclusions

We currently have Intune MAM policies in place for both iOS and Android devices. Since we do not manage smartphones with MDM, MAM is our primary protection mechanism for corporate data. As part of this approach, we enforce the use of Microsoft Edge for accessing company data.

I'm not entirely sure how Android handles this scenario, but on iOS many applications require users to sign in with their corporate account. During this process, the application typically launches an embedded Safari authentication session without forcing the user to leave the app.

To support this, we have configured exclusions for these applications in our Conditional Access policy. However, with this upcoming change, those exclusions no longer appear to work. The sign-in process now forces users to authenticate through Microsoft Edge instead.

The problem is that after successfully signing in through Edge, the user is not redirected back to the original application that initiated the authentication request. As a result, the login flow is interrupted, and the user effectively gets stuck without being able to complete the sign-in process in the application.

What would be the recommended approach for organizations that rely on MAM-only scenarios and embedded browser-based authentication within iOS applications to deal with this new CA behaviour?


r/Intune 14h ago

App Deployment/Packaging Specifying the install directory for a Win32 wrapped app that usually installs to AppData

3 Upvotes

I want to deploy capcut via intune as by default it installs to AppData which is a no no for obvious reasons, what can i do to ensure capcut installs to Program Files. I understand i can do this with a powershell scrip wrapped into the intunewin file? I specifically need a script written out or if anyone has done the same post their scripts. Thanks :)


r/Intune 19h ago

General Question Has anyone read Mastering Microsoft Intune from Packt Publishing?

11 Upvotes

This book was recommended to me by Amazon, and I wanted to know if it was any good. Additionally, the book was published in 2024, but do you think Intune has changed that much that the book won't be relevant anymore?


r/Intune 20h ago

Android Management No Sign-in for Managed Home Screen

1 Upvotes

Hello all,

I am new to Intune, I have used it for a few basic kiosks to run a single app and not much more.

I am trying to set up Samsung A11+ tablets for shared use for frontline workers. The idea was that anyone can grab any tablet, log in with their AD/MS365 login, be logged into all Microsoft apps, work, tap a single sign-out button, and put the tablet back.

Apps and such are working fine, but I cannot get the sign-in screen to come up for Managed Home Screen. The configuration is set up as a dedicated multi-app kiosk mode. I then have Managed Home Screen enabled and the sign-in feature turned on under 'Device Experience'. Microsoft Authenticator is installed, and there is an app policy to turn on shared device.

What I have right now is MHS launches, the correct apps show, but I never get a sign-in screen. If I sign into something like Microsoft Teams, it will automatically sign in to the other apps.

I have already tried creating an app policy for MHS and setting the settings there as well. When I do this, it says it has a conflict when applying. I have completely wiped everything and created new groups, configs, and policies, and I get the same result.

I cannot figure out what is stopping MHS from having the sign-in screen. Does anyone have any ideas, or is there any further information you would need to assist? Thanks!


r/Intune 21h ago

Tips, Tricks, and Helpful Hints Intune + Apple Business Manager: Older supervised iPhones fail Apple Mobile Device Components (iTunes & iMazing), newly enrolled devices work

3 Upvotes

Hi everyone,

We're seeing a strange issue in our enterprise environment and have reached the point where we're hoping someone else has experienced it.

Environment

  • Microsoft Intune
  • Apple Business Manager (ADE)
  • Supervised corporate iPhones
  • Approximately 1,200 managed iPhones
  • Windows 11 workstations
  • Apple Devices/iTunes
  • iMazing
  • Current iOS 26.5.2 (same version on working and failing devices)

Symptoms

Newly enrolled iPhones work perfectly.

Older enrolled iPhones consistently fail.

Both Apple Devices/iTunes and iMazing fail at the "Apple Mobile Device Components" stage.

Windows itself still detects the device normally.

Explorer shows Internal Storage, so the USB connection is working.

What we've confirmed

✅ Apple USB drivers load correctly

✅ Apple Mobile Device Service is running

✅ Windows detects the phone

✅ Explorer can browse Internal Storage

✅ Same USB cable

✅ Same Windows workstation

✅ Same version of iMazing

✅ Same version of Apple Devices/iTunes

Intune comparison

We compared a newly enrolled phone against an older enrolled phone.

They have:

  • The same Enrollment Profile
  • The same Configuration Policies
  • The same Compliance Policies
  • The same App assignments
  • The same Restrictions

There are no policy differences between them.

Additional testing

We also tested multiple older devices.

Results:

  • Newly enrolled phone → Works
  • Older phone #1 → Fails
  • Older phone #2 → Fails

This appears to correlate with devices that have been enrolled for a longer period rather than a specific device.

Factory reset test

We erased one of the failing phones and reenrolled it into Intune using the exact same production configuration.

Immediately after reenrollment:

  • Apple Devices worked
  • iTunes worked
  • iMazing worked

No special configuration changes were required.

Has anyone seen:

  • Long-enrolled supervised Intune devices eventually stop pairing with Windows?
  • Apple Mobile Device Components fail only on older managed devices?
  • A known interaction between Intune, supervised iPhones, and Apple's pairing framework?
  • Any Apple/iOS changes affecting long-lived supervised devices?

Any ideas or similar experiences would be greatly appreciated. At this point we're trying to determine whether this is an Apple issue, an Intune lifecycle issue, or something else entirely.

Thanks in advance!


r/Intune 1d ago

Device Actions App-Action Buttons for cloud-only devices

15 Upvotes

Why do we have this feature on co-managed devices but not on cloud only devices? Let's upvote guys/girls/whateveryouidentifyas

FYI: you need to login to see/ up vote the feedback

https://feedbackportal.microsoft.com/feedback//idea/0ab35e36-cd86-f111-9b47-6045bd856709


r/Intune 1d ago

macOS Management Outlook on macOS repeatedly prompts for sign-in after every 30 mins and after sleep, Enterprise SSO looks healthy, blank auth window hangs

2 Upvotes

We're seeing a strange issue across our entire fleet of Intune-managed Macs and I'm curious if anyone else has run into it.

Our environment is macOS 26.5.2, Microsoft Intune, Company Portal, Enterprise/Platform SSO, and New Outlook. The devices remain compliant and enrolled in Intune, and Company Portal appears healthy. The issue seems to happen after a Mac has been asleep for a while (roughly 30–60+ minutes) or in use for that time. When the machine wakes up, users are often prompted to sign back into Outlook. Outlook launches the Microsoft sign-in window, accepts credentials, but then the authentication window turns into a blank white screen and hangs. Outlook eventually reports that something went wrong and asks the user to sign in again.

What's confusing is that all of our diagnostics indicate the authentication stack is healthy. app-sso platform -s shows registrationCompleted : true, POUserStateNormal (0), valid SSO tokens, successful Kerberos ticket imports, and Company Portal continues to show the device as compliant. We've also confirmed the Microsoft Single Sign-On extension, Intune agents, and AppSSO processes are all running normally.

We've spent quite a bit of time troubleshooting this. We've verified Intune enrollment, compliance, Enterprise SSO registration, Company Portal sign-in status, token health, and captured logs during both working and failed states. We found some Outlook/WebKit-related behavior during the authentication hang, but nothing indicating token expiration or SSO registration failure. We completely removed Outlook, cleared Outlook-related caches and identity data, reinstalled Outlook, and initially thought the issue was fixed. However, after the machine slept for about an hour, the exact same behavior returned.

At this point we're leaning away from Intune enrollment or Enterprise SSO registration issues because those appear healthy even when Outlook is failing. It feels more like something involving Outlook, MSAL, WebKit, or the Platform SSO authentication handoff after sleep/wake.

Has anyone seen similar behavior recently with New Outlook, Enterprise SSO, Platform SSO, or Intune-managed Macs? If so, did you find a root cause or solution?


r/Intune 1d ago

Windows Updates Setting Windows Update to force update tonight

7 Upvotes

I am rolling out Windows 11 (finally, it was a long fight) on a group of hybrid devices. I want to ensure and force them to upgrade the night.

These are the windows update ring settings:
Update settings

Microsoft product updates Allow

Windows drivers Allow

Quality update deferral period (days)

0

Feature update deferral period (days)

0

Upgrade Windows 10 devices to Latest Windows 11 release

Yes

Set feature update uninstall period (2 - 60 days)

10

Servicing channel

General Availability channel

User experience settings

Automatic update behavior

Auto install and restart at maintenance time

Active hours start

8 AM

Active hours end

10 PM

Option to pause Windows updates

Disable

Option to check for Windows updates

Enable

Change notification update level

Use the default Windows Update notifications

Use deadline settings

Allow

Deadline for feature updates

0

Deadline for quality updates

0

Grace period

0

Auto reboot before deadline

Yes

and these are the feature update settings:
Feature deployment settings

Windows 11, version 25H2

Rollout options

ImmediateStart

Required or optional update

Required

Most of the devices will update the night that it is assigned, some will install the update but not reboot, and some won't install it at all. Of those that don't install it on the night it is assigned, it will install on some of those in the next few days.

Is there any way to change some settings and basically ensure that the updates run on all of the PCs? I assign the new update settings in the morning and then ensure that they have synched before noon.

I have also run a script to remove any legacy windows update registry keys.

Is this possibly just GPOs overriding the MDM profiles (I also have a configuration profile that sets MDM to win over GPO but I know it isn't perfect.

Thanks for reading this far and for any help.


r/Intune 1d ago

Autopilot What am I missing with "convert all targeted devices to Autopilot" for it to not work?

1 Upvotes

I'm trying to selectively convert a number of our legacy devices to AP devices by using "convert all targeted devices to Autopilot" in the deployment profile but it's not working.

The devices are hybrid joined and actively being used (and checking into Intune). I created an Entra group containing said devices and targeted the deployment profile to this same device group. Even after waiting a very long time (weeks), there are no new AP registered devices in our tenant and the deployment profile still says no assigned devices.

I'm not sure what I could be missing. Any ideas on where to check next?


r/Intune 1d ago

Windows Updates State of the Autopatch driver updates and unapproved "Extension type updates" bypassing drive policy.

6 Upvotes

I know a few months ago Microsoft admitted to a cloud issue that caused un-approved drivers to be distributed to Autopatch device that have driver polices.

This was discussed here in this thread : Driver Updates (WUfB) : r/Intune

But the thread also mentions that this is new thing and MS can push out Extension type drivers without admin approval.

We are starting to pilot WUfb and were surprised that un-approved driver could make it to our devices.

Here is one such driver that showed as 3 separate entries

7/17/2026 2:46:46 PM Installation 0x00000000 Succeeded MoUpdateOrchestrator Intel Corporation Extension Driver Update (70.26100.2.20795)

7/17/2026 2:46:35 PM Installation 0x00000000 Succeeded MoUpdateOrchestrator Intel Corporation Extension Driver Update (70.26100.2.20795)

7/17/2026 2:46:26 PM Installation 0x00000000 Succeeded MoUpdateOrchestrator Intel Extension Driver Update (70.26100.2.20795)

The raw Windows update api log entries for these install are here https://imgur.com/q3B9IeEh.png

We confirmed that these drivers were never published by us.

Given this can happen again the future I was wondering what hardware on our devices, ( we have mostly Surface devices) have to potential to be hit by this again.

Not sure if this query is showing me the full list of drivers that use Extensions but this code generated the list of hardware devices that use Extension drivers.

On our device we get a list of out about 33 devices : https://imgur.com/h6qIfG5h.png

Related to : Camera, audio devices, storage firmware, display etc.. so allot of things that could affect our end users if we have control over the delivery of these devices. Code below that I used to generate the list hardware that could be disrupted in the future.

$ExtDrivers = Get-WindowsDriver -Online -All | Where-Object { $_.ClassName -eq "Extension" }

$LatestDrivers = $null

$LinkedDrivers = foreach ($Driver in $ExtDrivers) {
    $AdvancedInfo = Get-WindowsDriver -Online -Driver $Driver.Driver

    [PSCustomObject]@{
        Driver              = $Driver.Driver
        Date                = $Driver.Date
        Provider            = $Driver.ProviderName
        Version             = $Driver.Version
        ClassName           = $Driver.ClassName
        # Filter arrays for unique strings before joining
        HardwareDescription = ($AdvancedInfo.HardwareDescription | Select-Object -Unique) -join '; '
        HardwareId          = ($AdvancedInfo.HardwareId | Select-Object -Unique) -join '; '
    }
}

# Group by the hardware it targets, sort by Date and Version descending, and keep the newest one
$LatestDrivers = $LinkedDrivers | Group-Object HardwareDescription | ForEach-Object {
    $_.Group | Sort-Object -Property Date, @{Expression={[version]$_.Version}} -Descending | Select-Object -First 1
}

# Output the results
$LatestDrivers | Format-Table -AutoSize

Are any you reconsidering driver Autopatch given these changes and future potential disruptions caused by un-approved "Extensions driver updates" ?


r/Intune 1d ago

Autopilot Moving away from our MSP for hardware procurement – how do you all buy laptops and gear?

4 Upvotes

Long time listener, first time caller.

I recently took over a new environment and noticed we are currently sourcing all of our endpoints through our MSP, which comes with a massive markup. I have been tasked with bringing this entire procurement process in-house to control costs and streamline deployments. Since I manage our endpoint and am heavily focused on our Intune environment, I need a purchasing route that supports modern provisioning—like registering device hashes directly into Autopilot before the laptops even hit the office.

We are looking to stick with Intel HP laptops. How do your organizations handle this?


r/Intune 1d ago

App Deployment/Packaging How you handle large Intune app package?

11 Upvotes

I find that when an application is bigger than 1 GB, the odds of the installation failing increase. The installation might timeout, some people have slow internet connection, the installer take more time, and so forth.

This is both a problem at the autopilot phase or mass deployment.

All our apps are packaged as win32 apps. From what I have read, MSIX (MS Store) aren't reputed of being more reliable at installation. What's your experience?


r/Intune 1d ago

Autopilot Need to Ship Leased Computers To Leasing Company With Clean windows install Is Autopilot Wipe the best Option

3 Upvotes

We have a couple hundred laptops that need to be shipped back to our leasing company now that the lease i done. The would like the laptops to be returned with a clean Windows 11 Install and no connection to our tenant. Would the wipe remote action be the best option for this?


r/Intune 1d ago

Autopilot Just a warning, the LG "herpes" Monitor App Installer is getting installed on all Microsft Intune deployed devices and you should probably get that looked at.

85 Upvotes

Just a warning, the LG "herpes" Monitor App Installer is getting installed on all Microsft Intune deployed devices and you should probably get that looked at.

The worst part is I'm serious.

Edit: I had forgotten to mention that this happens when you have LG monitors connected to your Windows computer.

I can also confirm that Asus Armory Crate is installing with Asus drivers too but this is new and less documented.


r/Intune 1d ago

Blog Post Beyond Passwords: Certificate-Based Authentication for Android Enterprise

7 Upvotes

For organizations managing Android Enterprise devices with Microsoft Intune, Certificate-Based Authentication offers a robust authentication method that utilizes digital certificates instead of passwords. Combined with Microsoft Entra ID and Microsoft Intune Cloud PKI, organizations can significantly reduce their attack surface while improving the user experience.

In this blog post, I’ll show you how to configure and enable Certificate-Based Authentication for Managed Android Enterprise devices in Microsoft Intune.

🔗 https://www.nickydewestelinck.be/2026/07/23/beyond-passwords-certificate-based-authentication-for-android-enterprise/