2,214 questions with Microsoft Security | Intune | Configuration tags

Sort by: Updated
1 answer

802.1x wired profile

Previously i push 802.1x user authentication wired profile from intune by export the xml file from working machine and deploy to all users. Now we will change from user authentication to computer authentication and want to know how to deploy this…

Microsoft Security | Intune | Configuration
asked 2026-07-29T01:07:59.9066667+00:00
Handian Sudianto 7,361 Reputation points
answered 2026-07-29T01:08:21.38+00:00

AI answer

1 answer

Push PKCS Intune

If we add one entry to the Subject Alternative Name then are qwe need to removethe existing certificate from the host and from the CA Authrotity? Or after adding the entry then intune will repush the new cert?

Microsoft Security | Intune | Configuration
asked 2026-07-28T06:37:43.36+00:00
Handian Sudianto 7,361 Reputation points
answered 2026-07-28T06:38:03.2633333+00:00

AI answer

1 answer

Microsoft 365 Apps Cloud Policy - Can a User Scoped Policy (Not Configured) Override a Tenant Policy?

Hello, I am looking for guidance regarding Microsoft 365 Apps Cloud Policy Service behavior and policy precedence. Current Configuration In Microsoft 365 Apps Admin Center → Policy Management (config.office.com), we have the following policies: …

Microsoft Security | Intune | Configuration
asked 2026-07-24T11:12:57.9633333+00:00
Ragaven007 0 Reputation points
answered 2026-07-24T11:13:41.24+00:00

AI answer

1 answer

bitlocker key not found in view bitlocker keys

bitlocker key not found in view bitlocker keys. There are two devices linked to my account I could see one but the other one not found

Microsoft Security | Intune | Configuration
asked 2026-07-20T17:44:45.54+00:00
Jeenath Nawabjan 0 Reputation points
answered 2026-07-20T17:45:07.6033333+00:00

AI answer

1 answer

Why doesn’t Intune support forcing BitLocker PIN after deployment like MBAM did?

Hello, We used MBAM for years because it had a unique feature: it could enforce TPM+PIN after a certain time or immediately after deployment. This was critical for our security policy. Now that MBAM is deprecated and we are moving to Intune/ConfigMgr…

Microsoft Security | Intune | Configuration
asked 2025-12-03T08:02:53.9733333+00:00
Belan Marek 56 Reputation points
commented 2026-07-17T08:19:08.9766667+00:00
LeeW 6 Reputation points
1 answer

How to make Power Options configurable for users via Intune?

Hi All, How do I make Power Options configurable for users via Intune? Right no these settings are greyed out i.e. not available for users to customize. I do not want to create some specific configuration but instead want allow users to configure…

Microsoft Security | Intune | Configuration
asked 2026-07-13T23:30:27.6233333+00:00
DT_2026 40 Reputation points
answered 2026-07-13T23:31:37.9+00:00

AI answer

1 answer

To Enable Kernel-mode Hardware-enforced Stack Protection in the Intune configuration policy

Hi Team, I am trying to enable both Memory Integrity (HVCI) and Kernel-mode Hardware-enforced Stack Protection on Windows 11 devices using Intune. Currently, I have configured the following Intune policy: Devices > Configuration Profiles > Settings…

Microsoft Security | Intune | Configuration
asked 2026-06-25T06:48:37.6933333+00:00
Vinayak Kanavimath 20 Reputation points
answered 2026-07-10T08:43:56.5633333+00:00
Roy E. Ingvaldsen 0 Reputation points
0 answers

Intune Custom OMA-URI Policy for AppLocker Shows "Not Applicable" on Windows Multi-Session AVD

I'm trying to deploy an AppLocker policy to Windows Enterprise Multi-Session AVD hosts using an Intune Custom OMA-URI policy, but the deployment status shows "Not Applicable." Could someone confirm whether: My OMA-URI path is incorrect, or …

Microsoft Security | Intune | Configuration
asked 2026-07-09T06:26:56.4433333+00:00
Siu476 0 Reputation points
0 answers

Need help with Intune Custom VPN (VPNv2 CSP) - Windows unable to parse XML data (EAP-TLS)

Hi, I am trying to deploy a native Windows IKEv2 Split-Tunnel VPN profile via Microsoft Intune using a Custom OMA-URI policy. The goal is to enforce strict EAP-TLS authentication using device/user certificates. Target OMA-URI:…

Microsoft Security | Intune | Configuration
asked 2026-07-08T12:54:47.68+00:00
Brenden Dorler 0 Reputation points
0 answers

Duplicate entry in AAD

We have a hybrid environment. If we import the hash file of a Windows device after that, in Azure AD, 2 entry created, one entry joins type = "Microsoft Entra joined", MDM = blank and 2nd entry joins showing blank but MDM = "Microsoft…

Microsoft Security | Intune | Configuration
asked 2026-07-01T12:17:23.7133333+00:00
Sharad Patil 0 Reputation points
edited a comment 2026-07-03T22:15:17.5266667+00:00
Rahul Jindal 11,641 Reputation points
1 answer

Bitlocker Encryption Error Code Add-TpmProtectorInternal : Die Daten sind unzulässig. (Ausnahme von HRESULT: 0x8007000D)

Hello Everybody, For weeks now, I have been trying to solve a problem regarding an error code that appears when trying to enable BitLocker. The error code is 0x8007000D – The data is invalid. I have not found any articles that address this exact…

Microsoft Security | Intune | Configuration
asked 2026-07-02T09:43:30.93+00:00
Roots, Robert 0 Reputation points
answered 2026-07-02T09:44:02.4433333+00:00

AI answer

7 answers

Windows 11 - Autopilot - remove Consumer Shortcuts

Is there a configuration setting in Intune that would remove the shortcuts for Spotify,TikTok, WhatsApp, Disney+, etc that seem to appear on a fresh install of Windows 11? I have successfully used Proactive Remediation to get rid of the Consumer version…

Microsoft Security | Windows Autopilot
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
asked 2023-01-19T20:37:35.0733333+00:00
Matt Dillon 437 Reputation points
commented 2026-06-30T14:21:56.8566667+00:00
Sebastian Cerazy 351 Reputation points
2 answers

Intune configuration not pushed to devices

i have deployed a wifi profile to both adroid and IOS devices but months later the assignment status is still showing 0 with not success or fail or not applicable even when devices are constantly syncing.

Microsoft Security | Intune | Configuration
asked 2026-06-29T10:26:28.66+00:00
MKHULEKO THABISO NHLAMBO 45 Reputation points
commented 2026-06-30T13:34:47.5233333+00:00
MKHULEKO THABISO NHLAMBO 45 Reputation points
1 answer

Unathorisation for Intune Apps | Configuration

Hello, Support. I am a Global Administrator, but when I log in to Intune Apps | Configuration error (Fetch scope tags You don't have authorization to retrieve any scope tag. Contact your Global or Intune administrator.), it shows me that I am not…

Microsoft Security | Intune | Configuration
asked 2026-06-29T14:20:09.3566667+00:00
IT 0 Reputation points
answered 2026-06-30T09:33:39.52+00:00
JimmySalian-2011 45,871 Reputation points Volunteer Moderator
1 answer

Intune policy

When we remove the policy from intune then the configuration on the device will be removed or still there? Example i create policy to deploy PCKS certificate and all devices will have this certificate , then if i remove the policy from intune then the…

Microsoft Security | Intune | Configuration
asked 2026-06-26T01:55:20.02+00:00
Handian Sudianto 7,361 Reputation points
edited a comment 2026-06-26T11:11:47.9166667+00:00
Marcin Policht 99,785 Reputation points MVP Volunteer Moderator
1 answer

how to fix Microsoft Intune Restricted Kiosk experiance

We encountered recently and issue with enrolling devices into a restricted kiosk experience. we've stetted the approved apps and star pins in the xml with the proper format but nothing seems to get this right. the devices don't get the right setup no…

Microsoft Security | Intune | Configuration
asked 2026-06-24T08:00:41.72+00:00
Daniel Cohen 5 Reputation points
answered 2026-06-24T08:01:17.5733333+00:00

AI answer

1 answer One of the answers was accepted by the question author.

802.1x certificate deploy from intune

I was success setup and push certificate configuration for each user for 802.1x authentication from intune. The deployment time when user logon to the endpoint until certificate installed up to 20 minutes. Now i want to know can we improve the time so…

Microsoft Security | Intune | Configuration
asked 2026-06-22T08:18:38.6633333+00:00
Handian Sudianto 7,361 Reputation points
accepted 2026-06-24T01:07:06.5566667+00:00
Handian Sudianto 7,361 Reputation points
1 answer

After wiping by intune, windwos enter winre instead os OOBE.

Hi MS, I am trying Intune's wipe. When I click wipe in intune, there are two options for me to choose from, as mentioned in the document. https://learn.microsoft.com/en-us/intune/device-management/actions/wipe?pivots=windows I have 2 Machines(Same…

Microsoft Security | Intune | Configuration
asked 2026-05-26T00:51:59.1633333+00:00
Li, Jiawei 0 Reputation points
answered 2026-06-23T13:17:51.77+00:00
Pavel yannara Mirochnitchenko 13,456 Reputation points MVP
1 answer

802.1x wired configuration intune

When we configure 802.1x for wired then we must assign the policy to users or to devices? I assign to users but almost one day the policy not yet applied.

Microsoft Security | Intune | Configuration
asked 2026-05-26T08:16:19.16+00:00
Handian Sudianto 7,361 Reputation points
commented 2026-06-23T11:44:57.3166667+00:00
Handian Sudianto 7,361 Reputation points
1 answer

Do not Lock out screen after inactivity. Windows 10 and Later

Hi everybody I've established the no screen saver after a certain amount of idle time policy in Intune for one of the PCs from the client side. However, despite the fact that the policy was correctly applied on client devices, it is still not…

Microsoft Security | Intune | Configuration
Windows for business | Windows Client for IT Pros | User experience | Other
asked 2023-06-20T11:15:23.26+00:00
Shah Muhammad 66 Reputation points
answered 2026-06-22T15:25:31.78+00:00
Zeeshan Nasir Bajwa 1,116 Reputation points