USB Block - Attack Surface Reduction
Hi All, I am trying to block all removable storage connection from all users and allow only specific Instance ID to be allowed using Attack surface reduction policy as below. I waited almost 6 hours still its allowing all the removable disks. Is the…
Need a Script or Policy to Automatically Set Installed Adobe (Reader or Acrobat) as Default App for .PDF Files Based on Available ProgID
Hi, Hi, We have a mixed environment where both Adobe Reader and Adobe Acrobat are deployed across different user machines. The requirement is to implement a solution (via PowerShell script or policy) that automatically detects the installed Adobe…

How do I fix the error this error, "Oops! We're having trouble verifying your phone number. Follow these steps to troubleshoot the issue."?
I am creating a new account for Microsoft Intune, and I have entered all the relevant information, but I get an error when I get to the Security Check section. I have followed all the steps recommended by the link in the error. I have tried with…
AVD support for EPM
Does a personal AVD host support EPM? I have read personal hosts are supported for EPM but not multi-user hosts.
how to switch of bitlocker for entra registered devices
How do you switch of bitlocker for microsoft entra registered devices? Every devices that gets registered to microsoft entra gets a bitlocker encryption key but we want to switch this off as we do not want to control this, is there an option to turn this…
How to remove all files for MDE (Microsoft Defender for Endpoint) using Intune after offboarding script is run.
Hi, we have Windows and Mac Clients with Microsoft Defender for Endpoint. Intune deploys it to the Windows and Jamf to the Macs. If we download the offboarding scripts and run them, all the program files are left behind. Is there an easy way using…

How to Activate Microsoft Defender for Business Licenses on Linux Servers?
I work for an organization and we are using Microsoft. I have access to admin panels. We have purchased a number of licenses for "Microsoft Defender for Business" with the idea of using them on some of our Linux-based servers. We have set up a…
How to assign Defender for endpoint server licenses on Windows server 2025
Hi~ 我們已經有為公司的Windows server 2025購買Defender for endpoint server授權了,但是使用MDE onboarding腳本上線後,在Microsoft Defender 入口網站或Intune上都沒有看到這幾台servers,只有在Azure的適用於雲端的Microsoft defender上有看到這幾台servers,但是卻顯示目前正在試用授權中,我們該如何使用我們所購買的Defender for endpoint server授權呢?
Block mobile phones when connected to a device as Removable Storage
Hi all, I'm trying to block all USB removable media connected to my company's laptops to about security breaches. I'm able to block USB pendrives and external hard drives, but If a connect a mobile phone (Android) to a laptop and set the connection to…
How to disable threat actions in Windows Defender managed by Defender for Endpoint?
I have Defender for Endpoint set up on Windows 10 devices. The enrollment was done in Defender (without enrolling them directly in Microsoft Intune). However, MDE has been allowed to apply security settings in Intune. A highlight of the policies is that…
How to Enable Malware Scanning for Files in Azure Blob Storage via Intune?
We need to confirm if Microsoft Defender scans files uploaded to the Azure Blob Storage used by our operators. Specifically, we are uploading files through Intune to its designated workspace (which uses Blob Storage). If not, is it possible to enable…
Regarding Endpoint security | Firewall rules configuration and limitations
Hi, I am exploring the configuration and limitations of Windows Server Firewall using Intune. While configuring policies for firewall rules, I was wondering how would you implement outbound HTTP and HTTPS connections rules regarding public internet…
Autopilot issue on device set up "Identifying"
Hello everyone, I'm currently using autopilot to enroll devices into Intune. Up until now, everything has been going smoothly without any changes. However, the last three devices, which are the same models as the ones that previously worked, are…
Azure Arc-Enabled Windows Servers managed by MDE - AV Policies Stuck "Pending" for 5 days
We have about 45 Windows servers ranging from Server 2012 to Server 2025 added into Azure Arc. These servers are enrolled in MDE management, which is confirmed working. Our initial test deployment of 6 Windows VMs received all AV policies…
Device Bitlock encrypted after the un-enrollment from Intune
Hello, I have this issue currently facing which one of my company device bitlock encrypted after unjoining to intune and unable to find the recovery even on the user company account ID on MS. Is there's a way that we can see the history on…
Intune how to allow second user to access company portal apps
Is there any way to give a user access to company portal apps on all devices when the primary user has been set? We want an IT account to be able to log into staff computers and access company portal apps but the staff computers are all set with primary…
How to get the device last reboot details like date & time via PowerShell or any other way for this?
How to get the device last reboot details like date & time via PowerShell or any other way for this?
Windows Hello for Business does not work if set with Settings Catalog
I tried to set WHFB with Settings Catalog, using same options as I did with Identity Protection, but it seems with SC, it works very unreliably. It only enforces WHFB on part devices, not all. Some devices receive it fast, some very late and some not at…

What does the Defender Anti-Spam (Inbound) policy overrule?
The Defender Anti-Spam, Anti-Malware and Anti-Phish policies all sit together in the Email Policy and Rules section, but I am trying to understand what an exception to these policies would over rule? Mainly looking at the Anti-Spam Policy, as that is…
How do I to Find the Location of Quarantined Malware found in an Intune Microsoft Defender Antivirus Report?
Hi all, I’m currently using Intune and have configured Antivirus policies. When I check the report in Microsoft Defender Antivirus, I can see malware such as HackTool:Win32/AutoKMS!MSR that have been detected and moved to quarantine on a couple of…