<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Intune Weekly</title>
    <link>https://ugurkocde.github.io/IntuneWeekly/</link>
    <atom:link href="https://ugurkocde.github.io/IntuneWeekly/rss.xml" rel="self" type="application/rss+xml" />
    <description>A weekly briefing for Microsoft Intune admins. What is landing in your tenant soon, what is on the horizon, what shipped, and what the community is hitting in the field.</description>
    <language>en</language>
    <lastBuildDate>Tue, 16 Jun 2026 14:17:36 +0000</lastBuildDate>
    <item>
      <title>Edition 8 - June 9 - 15, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-16/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-16/</guid>
      <pubDate>Tue, 16 Jun 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[Kerberos RC4 deadline looms, KB5094126 breaks HP devices, and Intune Devices blade goes dark.]]></description>
      <content:encoded><![CDATA[<p>Kerberos RC4 deadline looms, KB5094126 breaks HP devices, and Intune Devices blade goes dark.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-16/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong>Florian Salzmann &amp; Jannik Reinhard</strong> - <em>CMTrace.dev - log viewer in your browser</em>
A free, zero-install log viewer for ConfigMgr, SCCM, and Intune. Open massive client logs, color-code severity, and chase down error codes - all in the browser, with files processed 100% locally so nothing leaves your machine. <a href="https://cmtrace.dev/">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://support.microsoft.com/topic/1ebcda33-720a-4da8-93c1-b0496e1910dc">Kerberos RC4 Enforcement: 30-Day Remediation Deadline</a></strong> <em>(Microsoft - Release Health)</em> - July 2026 Windows security updates permanently remove Audit mode - any remaining RC4 dependencies will cause authentication failures the moment the update applies.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1u5er12/updatenightmare/">KB5094126 Causing BSODs and Boot Failures on HP Devices</a></strong> <em>(Reddit)</em> - The June 2026 cumulative update is actively breaking HP ProBook/EliteBook fleets with boot failures, BitLocker recovery prompts, and EFI partition issues - admins should pause update rings for HP devices now.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1u7anmf/intune_devices_blade_down_uk/">Intune Devices Blade Outage Across Multiple Regions</a></strong> <em>(Reddit)</em> - The Devices blade was confirmed unavailable on 16 June across UK, Austria, Netherlands, and Brazil - admins should monitor Service Health for an incident ID and verify console access is restored.</li>
<li><strong><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/known-issue-upgrading-microsoft-tunnel-version-20260129-1/ba-p/4517935">Microsoft Tunnel v20260129.1 Stuck - Remediation Script Out</a></strong> <em>(Blog - Customer Success)</em> - Servers on this version are stalling mid-upgrade and need Microsoft's mstunnel-patch-2602 script or a full reinstall to restore tunnel functionality.</li>
<li><strong><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Controlled Configuration for Defender Antivirus (Preview)</a></strong> <em>(Microsoft - In Development)</em> - This upcoming feature will override Group Policy, ConfigMgr, and local changes to Defender settings - co-managed environments need to review governance implications before it lands.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong></p>
<ul>
<li><a href="https://support.microsoft.com/topic/1ebcda33-720a-4da8-93c1-b0496e1910dc">Kerberos RC4 Enforcement Mode Arrives with July 2026 Windows Security Update</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Enrollment Time Grouping for Apple ADE Policies Goes GA</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse (Beta) Power BI Connector Retirement Begins</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Scope Tags Now Respected in EPM Reports</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Device Control Policy Support Extends to MDE Security Settings Management</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u38h9w/maintenance_window_is_now_ga_for_windows_update/">Maintenance Window for Windows Update for Business Now GA</a></li>
</ul>
<p><strong>On the horizon</strong></p>
<ul>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Android Personally Owned Work Profile Devices Migrate to Android Management API (AMAPI)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Controlled Configuration for Defender Antivirus Settings (Public Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Strict Tunnel Mode for Microsoft Tunnel on Android Enterprise</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Multiple Managed Accounts for App Protection Policies (iOS and Android)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Client-Driven Compliance Evaluation for Windows Devices (Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">In-Place Renewal for Cloud PKI Issuing Certification Authorities</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Agentic Identity for the Policy Configuration Agent (Public Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Custom Compliance Settings Coming to macOS</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Grant Enhanced MTD Security Permissions on Android Enterprise</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Silence Apps on Managed Home Screen During Authentication Prompts (Android)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Block Bluetooth Sharing Setting Added to Android Enterprise Settings Catalog</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Disable MAC Address Randomization on macOS Wi-Fi Profiles</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">802.1x Wired Networks Profile Coming to iOS/iPadOS</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">STIG Audit Security Baseline for GCC High Tenants</a></li>
</ul>
<p><strong>Action required</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/known-issue-upgrading-microsoft-tunnel-version-20260129-1/ba-p/4517935">Microsoft Tunnel Servers on Version 20260129.1 Are Stuck - Remediation Script Available</a></li>
<li><a href="https://support.microsoft.com/topic/1ebcda33-720a-4da8-93c1-b0496e1910dc">Kerberos RC4 Enforcement Deadline: Remediate RC4 Dependencies Before July 2026 Update</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u7anmf/intune_devices_blade_down_uk/">Intune Devices Blade Outage Reported Across Multiple Regions</a></li>
</ul>
<p><strong>What shipped</strong></p>
<ul>
<li><a href="https://support.microsoft.com/help/5094126">June 2026 Windows Security Update (KB5094126) Now Available</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/how-enterprise-app-management-secures-your-app-catalog-from/ba-p/4528361">Enterprise App Management: Security Architecture Deep-Dive Published</a></li>
</ul>
<p><strong>From the field</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1u5er12/updatenightmare/">KB5094126 Causing Boot Failures, BSODs, BitLocker Recovery, and HP EFI Partition Issues</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u5esc9/increase_size_of_efi_with_a_script/">HP EFI Partition (100 MB) Causing Recurring Windows Update Failures</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/canreset-value-flipping-on-cloud-only-devices/m-p/4527692#M23539">CanReset Value Randomly Flipping on Passwordless Cloud-Only Windows 11 Devices</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u185pl/are_we_good_with_the_new_secure_boot_certificate/">Secure Boot CA 2023 Rollout: Confidence Level Confusion and What "Under Observation" Actually Means</a></li>
<li><a href="https://www.reddit.com/r/sysadmin/comments/1u69v44/secure_boot_ca_2023_update_deadline_approaching/">Secure Boot CA 2023 Expiry Behaviour for Offline and Non-SB Devices Clarified by Community</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u25c20/we_built_a_browserbased_cmtrace_because_we_needed/">Browser-Based CMTrace Log Viewer (cmtrace.dev) Built for Autopilot ESP Troubleshooting</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u1tdhs/easily_modify_registry_keys_with_intune/">Browser-Based Registry-to-Remediation Script Generator</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u298dr/built_a_simple_edge_extension_inventory_script/">Edge Extension Inventory Script Sending Data to Azure Log Analytics</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/windows-app-update-notification/m-p/4526926#M23536">Windows App (Remote Desktop) Update Notification Requiring User Interaction - No Silent Update Option Found</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u39nsk/acrobat_and_wdachow/">WDAC and Adobe Acrobat Update Compatibility Causing Consistent Failures</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u6sp5f/just_spinning_up_our_intune_pilot_any_gotchas_or/">SCCM-to-Intune Migration: Real-World Gotchas from Admins Making the Switch</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1u2dj25/free_powershell_webinar_series_with_microsoft/">Free Two-Part PowerShell Webinar Series for Intune/ConfigMgr Admins (June 23 and 30)</a></li>
</ul>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-16/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 7 - June 2 - 8, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-09/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-09/</guid>
      <pubDate>Tue, 09 Jun 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[WUfB driver bypass, ASR silent disables, and Scripts reliability meltdown dominate a turbulent week.]]></description>
      <content:encoded><![CDATA[<p>WUfB driver bypass, ASR silent disables, and Scripts reliability meltdown dominate a turbulent week.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-09/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong>Simon Hartmann Eriksen &amp; Roy Klooster</strong> - <em>PPPC Builder for macOS</em>
A lightweight web-based tool that generates macOS PPPC (.mobileconfig) profiles tailored for Microsoft Intune. Select an app (or upload its Info.plist), choose the required privacy permissions (Screen Recording, Full Disk Access, Camera, Microphone, Accessibility), and download a ready-to-deploy .mobileconfig for Intune. No Jamf dependency; simple, fast, Intune-focused. <a href="https://github.com/Simsen/PPPC-Builder">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tus7af/driver_updates_wufb/">WUfB Driver Policies Bypassed: 32 Drivers Force-Installed</a></strong> <em>(Reddit)</em> - A Microsoft-acknowledged service incident (MO1332784) caused declined driver policies to be ignored across multiple tenants, so admins should audit driver inventory and declined states immediately.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1txnfox/bug_found_in_attack_surface_reduction_through_intune/">ASR Rules Silently Disabled by Baseline + Policy Conflict</a></strong> <em>(Reddit)</em> - Conflicting ASR assignments between a Security Baseline and an Endpoint Security profile silently disable rules with no conflict alert, leaving endpoints potentially unprotected without any visible warning.</li>
<li><strong><a href="https://www.reddit.com/r/sysadmin/comments/1tvks8e/intune_is_not_fit_for_purpose/">Scripts &amp; Remediations: Silent Failures and 8-Day Execution Gaps</a></strong> <em>(Reddit)</em> - A 900-upvote community thread documents widespread silent failures, missing logs, and multi-day execution delays in Scripts and Remediations, making any automation relying on these features unreliable right now.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tuqj8r/secure_boot_certificate_update_status_change/">Secure Boot CA 2023: Manual Task Trigger Required for Update</a></strong> <em>(Reddit)</em> - BIOS updates alone do not trigger the Secure Boot CA 2023 certificate update, and the scheduled task must be manually invoked, so admins relying on passive rollout may miss the update entirely before compliance deadlines.</li>
<li><strong><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024">MDOP End of Support: Migrate MBAM and App-V to Intune</a></strong> <em>(Blog - Customer Success)</em> - MDOP passed end of extended support on April 14, 2026, meaning any remaining MBAM or App-V workloads are now unpatched security risks and migration to Intune equivalents should be treated as urgent.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong></p>
<ul>
<li><a href="https://mc.merill.net/message/MC1381122">MDE iOS In-App OS Update Notifications Retiring Mid-July 2026</a></li>
</ul>
<p><strong>On the horizon</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/mdop-is-out-of-support-what-to-do-next-with-microsoft-intune/ba-p/4526024">MDOP End of Support: Migration Path to Intune</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/made-for-developers-and-agents-windows-365-at-build-2026/ba-p/4519041">Windows 365 Developer-Focused Enhancements Announced at Build 2026</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/intune-macos-ade-support-for-minimum-macos-version-enforcement/m-p/4525688#M23530">macOS ADE: No Supported Method to Enforce Minimum OS Version Before Platform SSO Registration</a></li>
</ul>
<p><strong>Action required</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1tuqj8r/secure_boot_certificate_update_status_change/">Secure Boot CA 2023 Certificate Update: Widespread Admin Confusion, Manual Trigger Available</a></li>
</ul>
<p><strong>From the field</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1tus7af/driver_updates_wufb/">WUfB Driver Update Policies Bypassed: 32 Drivers Installed Across Multiple Tenants Simultaneously</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1txnfox/bug_found_in_attack_surface_reduction_through_intune/">ASR Rules Silently Disabled When Security Baseline and Endpoint Security Profile Conflict</a></li>
<li><a href="https://www.reddit.com/r/sysadmin/comments/1txls2t/intune_assistance_application_not_syncing_to_devices/">Newly Created Entra Groups and App Deployments Not Reporting or Applying This Week</a></li>
<li><a href="https://www.reddit.com/r/sysadmin/comments/1txp89w/motherboard_replaced_on_an_entraintune_joined/">Motherboard Replacement Breaks Entra/Intune Authentication Due to TPM/Hardware Hash Change</a></li>
<li><a href="https://www.reddit.com/r/sysadmin/comments/1tvks8e/intune_is_not_fit_for_purpose/">Scripts and Remediations: Inconsistent Execution, No Logs, and 8-Day Gaps Draw Community Fury</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/intune-app-inventory-graph/m-p/4524828#M23524">Intune App Inventory Graph API Returns 403 Despite GUI Access</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tvjzpv/autopilot_v2_device_rename_and_reboot_and_oobe/">Autopilot v2 Device Rename Causes Unexpected OOBE Reboot Behaviour</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1txo76c/deploying_intune_remote_help_for_modern_endpoint/">Remote Help Rollout: Edge Cases in Mixed Build Environments, SKU Confusion Persists</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1twmj89/robopack_900_a_year_patch_my_pc_3500_no_brainer/">Third-Party App Patching Tool Comparison: Robopack vs. Patch My PC vs. WAU</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tydpgd/what_are_your_rookiemistakes_on_intune/">Intune Naming Schemes: Community Tool nametune.vercel.app Gaining Traction</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tyd3i7/intune_or_gpo_for_hybrid_joined_endpoints/">Hybrid Joined Devices: Community Advises Against Managing via Both GPO and Intune Simultaneously</a></li>
</ul>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-09/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 6 - May 26 - June 1, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-02/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-02/</guid>
      <pubDate>Tue, 02 Jun 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[Service outages hit Autopatch & Proactive Remediation; critical defaults let users wipe corporate devices.]]></description>
      <content:encoded><![CDATA[<p>Service outages hit Autopatch &amp; Proactive Remediation; critical defaults let users wipe corporate devices.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-02/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tr2pg3/any_user_can_unenroll_their_device/">Default Intune Settings Allow Users to Wipe Corporate Devices</a></strong> <em>(Reddit)</em> - Any enrolled user can unenroll and wipe their own corporate device via Company Portal by default - admins should hide remove/reset options in Tenant &gt; Customization immediately.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tr2ol2/autopatch_group_errors/">Autopatch Groups &amp; Reporting Inaccessible - Multi-Region Outage</a></strong> <em>(Reddit)</em> - Admins in UK, Europe, and US lost access to Autopatch groups and update reports; validate configurations are intact now that access appears restored.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tr3724/i_knew_it_service_degredation_reported_for/">Proactive Remediation Reporting Delayed Up to 7 Days</a></strong> <em>(Reddit)</em> - A confirmed service degradation means absence of remediation data should not be treated as success - do not make compliance or patching decisions based on reporting until resolved.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1ttlmmk/mysigninsmicrosoftcom/">mysignins.microsoft.com Down - New User MFA Registration Blocked</a></strong> <em>(Reddit)</em> - New users cannot register Microsoft Authenticator via the self-service portal; workaround is to manually add authentication methods in the Entra admin center.</li>
<li><strong><a href="https://mc.merill.net/message/MC1330892">M365 Apps Policy Blade Leaving Intune Admin Center in June 2026</a></strong> <em>(Microsoft - Message Center)</em> - Admins must migrate policy creation and editing workflows to the Microsoft 365 Apps admin center before the June 2026 service release removes the current blade.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong></p>
<ul>
<li><a href="https://mc.merill.net/message/MC1330892">M365 Apps Policy Configuration Moves Out of Intune Admin Center</a></li>
</ul>
<p><strong>On the horizon</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/entra/comments/1tt73bo/the_wait_is_finally_over_for_accidental_device/">Entra Device Soft Delete Now in Preview - BitLocker Keys and LAPS Preserved for 30 Days</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-news-you-can-use-may-2026/ba-p/4516353">Secure Boot Certificate Expiry Hits in June - AMA Scheduled June 4</a></li>
</ul>
<p><strong>Action required</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1tr2ol2/autopatch_group_errors/">Windows Autopatch Reporting and Groups Inaccessible Across Multiple Regions</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tr3724/i_knew_it_service_degredation_reported_for/">Proactive Remediation Reporting Delayed Up to 7 Days - Service Degradation Confirmed</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1ttlmmk/mysigninsmicrosoftcom/">mysignins.microsoft.com Security Info Page Not Loading - New User MFA Setup Blocked</a></li>
</ul>
<p><strong>What shipped</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-may/ba-p/4491984">What's New in Microsoft Intune - May 2026</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new">Intune RBAC Roles Now Automatically Inherit Copilot in Intune Access</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new">Remote Help for Windows 5.2.1037.0 Released with Performance Improvements</a></li>
<li><a href="https://aka.ms/WindowsNewsYouCanUse/May2026">Windows Autopatch Hotpatch Now Default for Intune-Managed Devices; GCC Support Added</a></li>
<li><a href="https://support.microsoft.com/help/5089573">May 2026 Windows 11 Non-Security Preview Update Now Available</a></li>
<li><a href="https://www.reddit.com/r/SCCM/comments/1tr8t3j/cm_2603_update_available_no_new_adk/">ConfigMgr 2603 Update Now Available</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/unpacking-endpoint-management-is-back-and-we-ve-got-a-lot-to/ba-p/4514599">Unpacking Endpoint Management Video Series Returns</a></li>
</ul>
<p><strong>From the field</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/broken-functionality-of-macoswificonfiguration-policies/m-p/4523591#M23507">macOS WiFi Configuration Policies Returning InternalServerError via Graph - Inaccessible in Portal</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tpfjb7/company_portal_failing/">Company Portal (UWP) Showing Widespread Failure Rates Across Multiple Tenants</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tt0dd3/new_release_alert_getintuneassignments_v1015_is/">Community Tool: Get-IntuneAssignments v1.0.15 Adds 7 New Policy Types</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tox16s/intune_management_extension_the_changelog/">Community Tool: IME Changelog Automation - What Changed Inside the Intune Management Extension</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tp3wke/zerotouch_autopilot_hardware_hash_upload_now/">Community Tool: Foundry OSD Now Supports Zero-Touch Autopilot Hardware Hash Upload</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tr2pg3/any_user_can_unenroll_their_device/">Default Intune Settings Allow End Users to Self-Unenroll and Wipe Their Own Corporate Devices</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/edge-displays-a-splash-screen-saying-sign-in-to-sync-your-data/m-p/4523908#M23510">Edge "Sign in to sync your data" Splash Screen Persists Despite Intune Configuration Profile</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tnqa5o/intune_microsoft_store_app_deployment_fails/">Microsoft Store App (New) Deployment Fails Reporting When Store Is Blocked by Policy</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tqz9zf/whats_new_in_microsoft_intune_may/">macOS Platform SSO During ADE Failing 30–50% of the Time</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1ts9g5s/what_if_secureboot_is_disabled_can_certificates/">Secure Boot Enablement May Break Windows Hello When BitLocker Is Active</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1ts6udr/intune_alternative_for_the_sccm_script_feature/">On-Demand Script Execution in Intune: Remediation Scripts as the SCCM "Scripts" Replacement</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tsta6w/can_i_upload_windows_device_into_autopilot/">Autopilot v2 Supports Manufacturer + Model + Serial Registration Without Hardware Hash</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tq3r9o/do_you_rely_on_winget_for_deploying_apps/">WinGet Auto-Update vs. Enterprise App Management vs. Patch My PC - Community Verdict</a></li>
</ul>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-06-02/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 5 - May 19 - 25, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-26/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-26/</guid>
      <pubDate>Tue, 26 May 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[BitLocker loops return, passkeys bypassed by AiTM, and scripts reporting still broken.]]></description>
      <content:encoded><![CDATA[<p>BitLocker loops return, passkeys bypassed by AiTM, and scripts reporting still broken.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-26/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong><a href="https://www.linkedin.com/in/sandy-tsang">Sandy Zeng</a></strong> - <em>IntuneDiff</em>
A diff/compare tool for Intune configurations that lets admins spot drift between policies, profiles, and tenants at a glance. Available as a website and now also as a PowerShell module on the PowerShell Gallery, so the same comparison logic can be scripted into reviews, audits, and CI checks. <a href="https://www.awesomeintune.com/tools/intune-diff">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tik9fl/bitlocker_issues_with_kb5089549/">BitLocker Recovery Loop After May KB5089549</a></strong> <em>(Reddit)</em> - Windows 11 devices are looping on the BitLocker recovery screen after every reboot post-patch - HP has a firmware workaround but admins need to act before wider deployment.</li>
<li><strong><a href="https://www.reddit.com/r/sysadmin/comments/1tklvyg/intuneazure_passkeys_now_compromised_in_addition/">Passkeys Not Blocking AiTM Session Token Theft</a></strong> <em>(Reddit)</em> - Confirmed compromises show phishing-resistant MFA alone doesn't stop session hijacking - admins should add token protection and Continuous Access Evaluation policies now.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tkm0t4/monitoring_and_remediation_script_results_not/">Remediation Script Reporting Still Stale Post-Outage</a></strong> <em>(Reddit)</em> - Console results are still showing May 16–17 timestamps days after recovery, so any compliance or operational decisions based on console data are unreliable until Microsoft closes the investigation.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tk9hg2/switched_telemetry_to_full_for_secure_boot_cert/">Low Telemetry Hides Devices from Secure Boot Report</a></strong> <em>(Reddit)</em> - Devices on 'Security' telemetry level are completely invisible to the Secure Boot certificate report, meaning admins may be miscounting compliance exposure ahead of the certificate rollout deadline.</li>
<li><strong><a href="https://mc.merill.net/message/MC1304290">Remote Help &amp; Advanced Analytics Rolling Into M365 Suites</a></strong> <em>(Microsoft - Message Center)</em> - Starting mid-June, these premium add-on features begin landing automatically in M365/EMS SKUs - admins should review licensing now to avoid surprise capacity or configuration gaps.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong></p>
<ul>
<li><a href="https://mc.merill.net/message/MC1304290">Remote Help and Intune Advanced Analytics Coming to M365 / EMS Suites in Mid-June</a></li>
</ul>
<p><strong>On the horizon</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570">Admin Insights for Windows 365 Now in Public Preview</a></li>
</ul>
<p><strong>Action required</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1timxi3/platform_scripts_all_returning_404not_found_errors/">Remediation and Platform Scripts Reporting Broken - Multi-Tenant Outage Now Resolved</a></li>
</ul>
<p><strong>What shipped</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920">Updated Secure Boot Status Report Now Live in Windows Autopatch</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Batch of In-Development Features Removed - Likely Shipped or Cancelled</a></li>
</ul>
<p><strong>From the field</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1tik9fl/bitlocker_issues_with_kb5089549/">BitLocker Recovery Loop Returns After May KB5089549 - Worse Than April's KB5083769</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tk9hg2/switched_telemetry_to_full_for_secure_boot_cert/">Telemetry Level Affects Secure Boot Certificate Report Visibility</a></li>
<li><a href="https://www.reddit.com/r/sysadmin/comments/1tklvyg/intuneazure_passkeys_now_compromised_in_addition/">Passkeys Not Stopping Session Token Theft via AiTM Attacks</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tkm0t4/monitoring_and_remediation_script_results_not/">Remediation Script Console Reporting Still Delayed Days After Outage Recovery</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tnqa5o/intune_microsoft_store_app_deployment_fails/">Microsoft Store App Deployment Fails Reporting When Store Access Is Blocked by Policy</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1thurqe/built_a_framework_for_sccmtointune_migration_that/">SCCM-to-Intune Migration Framework Automates Autopilot Import - 6.5 Hours to 30 Minutes</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tld2as/driver_automation_tool_feedback/">Driver Automation Tool v10 Seeking Community Feedback</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1thjuwk/we_have_a_byod_policy_that_says_personal_devices/">94 Personal Devices Enrolled Despite BYOD Policy - Enforcement Gap Pattern</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tis2jb/windows_hello_for_business/">Windows Hello for Business Cloud Kerberos Trust Fails on Hybrid-Joined Devices</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tklsr9/intune_admin_center_supported_dark_mode_all_this/">Dark Mode QR Code Bug: Enrollment Token QR Codes Won't Scan in Dark Mode</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tn4mc7/laps_for_macos_not_working/">LAPS for macOS Intermittently Failing - Username Case Sensitivity Is a Factor</a></li>
<li><a href="https://www.reddit.com/r/Intune/comments/1tio4ma/how_are_you_keeping_the_bios_up_to_date_for_your/">Dell BIOS/Firmware Management via Intune: DCU + Autopatch Approaches Compared</a></li>
</ul>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-26/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 4 - May 12 - 18, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-19/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-19/</guid>
      <pubDate>Tue, 19 May 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[YellowKey BitLocker bypass, Hotpatch silently enabled, and Secure Boot certs expiring June 2026.]]></description>
      <content:encoded><![CDATA[<p>YellowKey BitLocker bypass, Hotpatch silently enabled, and Secure Boot certs expiring June 2026.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-19/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong><a href="https://www.linkedin.com/in/simonskotheimsvik/">Simon Skotheimsvik</a></strong> - <em>1PhoneMirror</em>
A Windows-based screen-mirroring receiver built for Intune admins who need consistent, framed mobile screens for documentation and training. Supports iOS/macOS AirPlay (with optional PIN), Android wireless debugging via bundled adb/scrcpy, and experimental Miracast, with one-click screenshots or MP4/GIF recordings inside a device frame. Multiple devices stay paired and can be switched from a bottom bezel, with no app installs on the phones. <a href="https://www.awesomeintune.com/tools/1phonemirror">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/sysadmin/comments/1tgr205/yellowkey_mitigation/">YellowKey BitLocker Bypass - No Official Patch Yet</a></strong> <em>(Microsoft - Learn)</em> - Admins managing standalone Windows devices must evaluate disabling WinRE immediately as the only confirmed mitigation until Microsoft issues a fix; Entra-joined devices appear protected but should be verified.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tc2v5b/hot_patch_on_by_default_now/">Hotpatch Silently Enabled Tenant-Wide from May 12</a></strong> <em>(Reddit)</em> - Admins may be unaware devices are running hotpatch builds instead of the standard May CU, and those rolling out Secure Boot cert updates should expect additional unexpected reboots until the quarterly baseline CU applies.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1tgr0kv/anyone_else_getting_access_denied_in_intune/">Intune Admin Center 'Access Denied' Outage on May 18</a></strong> <em>(Reddit)</em> - Multiple admins lost access to the Intune admin center despite holding valid admin roles, and the Azure status page incorrectly showed all healthy - admins should know to open a support ticket rather than rely on the status page during future incidents.</li>
<li><strong><a href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524">Secure Boot Certificates Expiring June 2026 - Rollout Planning Urgent</a></strong> <em>(Microsoft - Release Health)</em> - With expiry less than 13 months away and hotpatch now delaying certificate delivery to quarterly CU cycles, admins should use the updated Autopatch Secure Boot Status report now to identify unready devices and sequence rollouts.</li>
<li><strong><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse Beta Power BI Connector Retiring</a></strong> <em>(Microsoft - In Development)</em> - The gradual retirement began in late April 2026 and any Power BI reports built before November 2025 will lose data access if not migrated to connector v2 or the OData Feed connector immediately.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong>
- <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/new-platform-sso-with-registration-during-automated-device/ba-p/4519846">Platform SSO with Registration During Automated Device Enrollment Now GA for macOS</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse Beta Connector in Power BI Retiring - Transition Now</a>
- <a href="https://www.reddit.com/r/sysadmin/comments/1tdy52o/fyi_enabling_windows_hotpatch_while_update_secure/">Hotpatch Now On by Default - Conflict with Secure Boot Cert Rollout</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Enrollment Time Grouping for Apple ADE Policies Going GA</a>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/updated-secure-boot-status-report-in-windows-autopatch/ba-p/4517920">Updated Secure Boot Status Report in Windows Autopatch Now Available</a></p>
<p><strong>On the horizon</strong>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Android Personally Owned Work Profile Devices Moving to Android Management API (AMAPI)</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Controlled Configuration for Microsoft Defender Antivirus Settings Coming to Public Preview</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Strict Tunnel Mode for Microsoft Tunnel on Android (AMAPI Devices)</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Multiple Managed Accounts for App Protection Policies Coming to iOS and Android</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Device Control Policy Support Extended to Defender for Endpoint Security Settings Management</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Scope Tags to be Enforced on EPM Reports</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">In-Place Renewal for Cloud PKI Issuing Certificate Authorities</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Custom Compliance Settings Coming to macOS</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Client-Driven Compliance Evaluation for Windows Devices Coming to Preview</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">New STIG Audit Security Baseline for GCC High Tenants</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">New 802.1x Wired Networks Profile for iOS/iPadOS</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Disable MAC Address Randomization Setting for macOS Wi-Fi Profiles</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Block Bluetooth Sharing Setting Added to Android Enterprise Settings Catalog</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Grant Enhanced Security Permissions to MTD App on Android Enterprise</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Silence Apps on Managed Home Screen During Authentication Prompts</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Agentic Identity for the Policy Configuration Agent Coming to Public Preview</a>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/admin-insights-for-windows-365-stay-on-top-of-what-needs/ba-p/4517570">Admin Insights for Windows 365 Now in Public Preview</a></p>
<p><strong>Action required</strong>
- <a href="https://techcommunity.microsoft.com/event/windowsevents/ask-microsoft-anything-secure-boot---may-2026/4513524">Secure Boot Certificates Begin Expiring June 2026 - Plan Your Rollout Now</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse Beta Power BI Connector Retiring - Migrate Before Data Access Ends</a>
- <a href="https://www.reddit.com/r/sysadmin/comments/1tgr205/yellowkey_mitigation/">YellowKey BitLocker Bypass - No Official Patch Yet, Evaluate Mitigations</a></p>
<p><strong>What shipped</strong>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Multiple In-Development Features Removed from the List - Likely Shipped</a></p>
<p><strong>From the field</strong>
- <a href="https://www.reddit.com/r/Intune/comments/1tgr0kv/anyone_else_getting_access_denied_in_intune/">Widespread "Access Denied" Errors Hit Intune Admin Center - Unacknowledged on Status Page</a>
- <a href="https://www.reddit.com/r/Intune/comments/1tc2v5b/hot_patch_on_by_default_now/">Hotpatch Silently Enabled by Default - Many Admins Unaware</a>
- <a href="https://www.reddit.com/r/sysadmin/comments/1td6g1n/yellowkey_working_irl/">YellowKey BitLocker Bypass: Field Testing Shows Entra-Joined Devices Appear Protected</a>
- <a href="https://www.reddit.com/r/Intune/comments/1td7ebq/autopatch_hit_users_with_a_40min_update_from_24h2/">Autopatch Upgrading Devices from 23H2 to 25H2 Takes 40+ Minutes - Not a Bug</a></p>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-19/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 3 - May 5 - 11, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-12/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-12/</guid>
      <pubDate>Tue, 12 May 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[Tunnel servers stuck, BYOD blocked from Cloud PC, and Power BI connector retiring now.]]></description>
      <content:encoded><![CDATA[<p>Tunnel servers stuck, BYOD blocked from Cloud PC, and Power BI connector retiring now.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-12/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong><a href="https://www.linkedin.com/in/mauricedaly/">Maurice Daly</a></strong> - <em>Driver Automation Tool</em>
A PowerShell WPF desktop app that automates the full lifecycle of OEM driver and BIOS package management for ConfigMgr and Intune. It discovers vendor catalogs, downloads with resume-enabled curl, extracts, builds WIMs, and wraps packages as .intunewin for Win32 deployment. Multi-OEM support, BIOS update handling, hash verification, and configurable packaging (DISM/wimlib/7-Zip) collapse hours of manual driver work into a single signed workflow. <a href="https://github.com/maurice-daly/DriverAutomationTool">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/known-issue-upgrading-microsoft-tunnel-version-20260129-1/ba-p/4517935">Tunnel servers on v20260129.1 stuck - reinstall required</a></strong> <em>(Blog - Customer Success)</em> - Servers on the early-March Tunnel release are not functioning correctly and Microsoft has published a remediation script; admins must act now or deploy version 20260330.1 or later.</li>
<li><strong><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Power BI Intune beta connector retiring - no grace period</a></strong> <em>(Microsoft - In Development)</em> - The two-week retirement window is already rolling out and once complete all data access stops, so any reports built before November 2025 must be migrated to connector v2 or OData Feed immediately.</li>
<li><strong><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/byod-devices-can-t-launch-windows-365-pc-because-of-device/m-p/4518584#M23436">BYOD devices blocked from Windows 365 Cloud PC via CA</a></strong> <em>(Microsoft - Message Center)</em> - The Windows 365 Client app cannot be individually excluded in Conditional Access compliance policies, causing BYOD devices to be blocked from Cloud PC with no clean workaround yet from Microsoft.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1t63m0q/intune_enhanced_app_inventory/">Enhanced App Inventory Graph API returning forbidden errors</a></strong> <em>(Reddit)</em> - Multiple admins confirm the /deviceInventories endpoint is inaccessible via Graph Explorer and PowerShell with no official workaround, blocking automation built around the newly shipped feature.</li>
<li><strong><a href="https://mc.merill.net/message/MC1304290">M365 suites gaining Intune Plan 2 and Remote Help mid-June</a></strong> <em>(Microsoft - Message Center)</em> - Intune Remote Help, Advanced Analytics, and Plan 2 capabilities begin rolling into Microsoft 365, Office 365, and EMS suites from mid-June, requiring licensing and budget review before rollout completes August 1.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong></p>
<ul>
<li><a href="https://mc.merill.net/message/MC1303717">Outlook for iOS/Android: Admins Can Allow Users to Override Default Compose Font</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse Beta Connector Retiring in Power BI</a></li>
<li><a href="https://mc.merill.net/message/MC1304290">M365 2026 Packaging Update Brings Intune Remote Help, Advanced Analytics, and Plan 2 Features to More Suites</a></li>
</ul>
<p><strong>On the horizon</strong></p>
<ul>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Android Enterprise Personally Owned Work Profile Migrating to Android Management API (AMAPI)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Controlled Configuration for Microsoft Defender Antivirus Settings (Public Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Strict Tunnel Mode for Microsoft Tunnel on Android Enterprise (AMAPI)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Device Control Policy Support Extended to Defender for Endpoint Security Settings Management</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Multiple Managed Accounts for App Protection Policies (iOS/Android)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Enrollment Time Grouping for Apple ADE Policies Going GA</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Platform SSO Registration During macOS Automated Device Enrollment</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Custom Compliance Settings Coming to macOS</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Client-Driven Compliance Evaluation for Windows (Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">In-Place Renewal for Cloud PKI Issuing CAs</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">STIG Audit Security Baseline for GCC High Tenants</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Scope Tags Support for Endpoint Privilege Management Reports</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Agentic Identity for the Intune Policy Configuration Agent (Public Preview)</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Grant Enhanced MTD Security Permissions on Android Enterprise</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Silence Apps on Managed Home Screen During Authentication Prompts</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">New Wired Networks (802.1x) Profile for iOS/iPadOS</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Disable MAC Address Randomization on macOS Wi-Fi Profiles</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Block Bluetooth Sharing Setting Added to Android Enterprise Settings Catalog</a></li>
</ul>
<p><strong>Action required</strong></p>
<ul>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/known-issue-upgrading-microsoft-tunnel-version-20260129-1/ba-p/4517935">Microsoft Tunnel Servers on Version 20260129.1 Are Stuck - Reinstall or Run Patch Script</a></li>
<li><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Intune Data Warehouse Beta Connector in Power BI: Migrate Before Retirement Completes</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/byod-devices-can-t-launch-windows-365-pc-because-of-device/m-p/4518584#M23436">BYOD Devices Blocked from Windows 365 Cloud PC by Conditional Access - No Clean Exclusion Path</a></li>
</ul>
<p><strong>What shipped</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1t99b0c/check_out_the_new_intune_device_view/">New Intune Device Page Now in Public Preview</a></li>
<li><a href="https://zerotruststories.com/how-to-use-microsoft-intune-enhanced-app-inventory-for-advanced-insights/">Enhanced App Inventory with Faster Data Updates Now Available</a></li>
<li><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-resolve-device-noncompliance-with-mobile-threat/ba-p/4491669">Support Tip Published: Resolving Device Noncompliance with MTD Partner Apps</a></li>
<li><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/configuring-firewall-and-proxies-for-smooth-windows-updates/4517913">Firewall and Proxy Configuration Guide for Windows Update Published</a></li>
<li><a href="https://github.com/SkipToTheEndpoint/OpenIntuneBaseline/releases/tag/windows-v3.8">Open Intune Baseline 3.8 Released</a></li>
</ul>
<p><strong>From the field</strong></p>
<ul>
<li><a href="https://www.reddit.com/r/Intune/comments/1t63m0q/intune_enhanced_app_inventory/">Enhanced App Inventory Graph API Endpoint Returning Access Errors</a></li>
</ul>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-12/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 2 - April 28 - May 4, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-05/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-05/</guid>
      <pubDate>Tue, 05 May 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[Hotpatch on by default, Secure Boot deadline looms, and Autopilot stalls hit production.]]></description>
      <content:encoded><![CDATA[<p>Hotpatch on by default, Secure Boot deadline looms, and Autopilot stalls hit production.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-05/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong><a href="https://www.linkedin.com/in/lewis-barry/">Lewis Barry</a></strong> - <em>Intune Settings Catalog Viewer</em>
Built intunesettings.app, a faster way to browse the Intune Settings Catalog with a dedicated page that tracks changes Microsoft makes to the catalog over time. Cuts the friction of digging through the admin center and surfaces silent additions or removals that would otherwise go unnoticed. <a href="https://intunesettings.app/">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1syunmi/secureboot_certificate_updates_realitycheck/">Secure Boot Certs Expire June 2026 - Remediate Now</a></strong> <em>(Reddit)</em> - Unremediated devices will silently stop receiving boot manager updates and may trigger BitLocker recovery prompts - the June deadline leaves little runway for large inventories.</li>
<li><strong><a href="https://techcommunity.microsoft.com/blog/Windows-ITPro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066/replies/4516455">Hotpatch Flipped On Tenant-Wide - May Is First Affected Month</a></strong> <em>(Microsoft - Message Center)</em> - Microsoft silently enabled Hotpatch for all tenants in April, meaning newly enrolled devices will receive hotpatch instead of a full CU starting in May - admins must configure exclusion groups now for any devices that should not receive hotpatches.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1t3saxx/autopilot_pre_provisioning_stuck_at_app_installs/">Autopilot Pre-Provisioning Stalling at App Install Phase</a></strong> <em>(Reddit)</em> - Multiple admins are hitting this in production today with no config changes on their end, and the only unblock requires a force-reboot - active issue to watch before scheduling any provisioning runs this week.</li>
<li><strong><a href="https://techcommunity.microsoft.com/t5/microsoft-intune/policy-applied-allthough-it-shouldn-t/m-p/4516937#M23417">Conditional Access Filter Now Hitting Windows Server RDP Sessions</a></strong> <em>(Blog - Discussions)</em> - A backend CA evaluation change is causing policies that should exclude company-owned devices to incorrectly apply to Windows Server 2025 RDP sessions, forcing unexpected 8-hour reauthentication - admins with device-filter CA policies should audit scope immediately.</li>
<li><strong><a href="https://support.microsoft.com/help/5083631">April 2026 Non-Security Preview: Dynamic App Removal + Secure Boot Side-Effect</a></strong> <em>(Microsoft - Release Health)</em> - This update delivers the new dynamic MSIX/APPX removal capability but also carries the KB5082052 Secure Boot cert prompt side-effect - admins should read the known issue before pushing to pilot rings.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong>
- <a href="https://techcommunity.microsoft.com/blog/Windows-ITPro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066/replies/4516455">Hotpatch Enabled Tenant-Wide by Default - May Updates Are First Affected</a>
- <a href="https://support.microsoft.com/help/5083631">April 2026 Windows Non-Security Preview Update Now Available</a></p>
<p><strong>On the horizon</strong>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/dynamically-remove-apps-from-managed-windows-11-devices/ba-p/4516291">Dynamic App Removal for Managed Windows 11 Devices</a>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/windows-365-for-agents-now-in-public-preview-run-ai-agents/ba-p/4513479">Windows 365 for Agents Now in Public Preview</a>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/public-preview-user-initiated-provisioning-for-windows-365/ba-p/4512474">User-Initiated Provisioning for Windows 365 Reserve Now in Public Preview</a></p>
<p><strong>Action required</strong>
- <a href="https://www.reddit.com/r/Intune/comments/1syunmi/secureboot_certificate_updates_realitycheck/">Secure Boot Certificates Expire June 2026 - Intune-Managed Device Remediation Underway</a></p>
<p><strong>What shipped</strong>
- <a href="https://techcommunity.microsoft.com/t5/microsoft-intune-blog/what-s-new-in-microsoft-intune-april/ba-p/4493135">April 2026 Intune Service Update - Higher-Frequency App Inventory, Linux SSO, Apple Enrollment Expansion</a>
- <a href="https://techcommunity.microsoft.com/t5/windows-it-pro-blog/protect-your-estate-reassess-your-windows-update-policies/ba-p/4515228">New Windows Autopatch Overview Report Now Available for All Tenants</a>
- <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/in-development">Multiple Features Drop Off In-Development List - Likely Shipped in April Service Update</a>
- <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/speed-where-it-matters-how-microsoft-intune-helps-it-prioritize/ba-p/4515942">Microsoft Confirms Intune Policy Sync Is Far Faster Than the "8-Hour" Myth</a>
- <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/migrating-frontline-mobile-devices-aligning-stakeholders-before/ba-p/4516511">Frontline Device Migration Guidance: Stakeholder Alignment Before Testing</a></p>
<p><strong>From the field</strong>
- <a href="https://techcommunity.microsoft.com/t5/microsoft-intune/policy-applied-allthough-it-shouldn-t/m-p/4516937#M23417">Conditional Access Filter Behavior Changing - Server Devices Now Getting Sign-In Policies They Shouldn't</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t3saxx/autopilot_pre_provisioning_stuck_at_app_installs/">Autopilot Pre-Provisioning Intermittently Stalling at App Install Phase</a>
- <a href="https://techcommunity.microsoft.com/t5/microsoft-intune/app-enforced-restrictions-not-working-on-chrome/m-p/4516309#M23409">App Enforced Restrictions Not Enforcing on Chrome for BYOD macOS</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t2f8mq/autopilot_profile_assignment_issues_after_moving/">Autopilot Profile Assignment Breaks When Moving from "All Devices" to Dynamic Group</a>
- <a href="https://www.reddit.com/r/Intune/comments/1szupgk/hybrid_join_and_intune_double_entity_problem/">Hybrid Join Producing Double Entra Entries After Device Reset</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t4asyd/does_anyone_have_a_system_using_winget_to_install/">WinGet App Deployment via Intune Consistently Failing for Many Admins</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t0eins/pim_multirole_activation/">Community Tool: PIM Multi-Role Activation GUI for Intune Admins</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t0cqyx/interest_in_dashboard_for_intune/">Community Tool: Central Intune Reporting Dashboard in Development - Feature Requests Wanted</a>
- <a href="https://www.reddit.com/r/sysadmin/comments/1t0157x/hp_laptop_pricing_is_so_out_of_control_management/">Organisations Eyeing Mac Fleets as HP Laptop Prices Double - Intune Mac Management Considerations</a>
- <a href="https://www.reddit.com/r/Intune/comments/1t13jim/is_there_a_way_to_connect_existing_domain_join/">Domain-to-Entra Migration Without Reformat - Community Shares Scalable Approaches</a></p>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-05-05/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
    <item>
      <title>Edition 1 - April 21 - 27, 2026</title>
      <link>https://ugurkocde.github.io/IntuneWeekly/editions/2026-04-28/</link>
      <guid isPermaLink="true">https://ugurkocde.github.io/IntuneWeekly/editions/2026-04-28/</guid>
      <pubDate>Tue, 28 Apr 2026 12:00:00 +0000</pubDate>
      <description><![CDATA[Samsung Knox wipe-block locks devices permanently; Autopatch report shows zero devices for weeks.]]></description>
      <content:encoded><![CDATA[<p>Samsung Knox wipe-block locks devices permanently; Autopatch report shows zero devices for weeks.</p>
<p><strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-04-28/intune-weekly.pdf">Download the full PDF →</a></strong></p>
<p><strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">Subscribe on LinkedIn →</a></strong> to get the next edition every Tuesday</p>
<hr />
<h2>Community shoutout</h2>
<p><strong><a href="https://www.linkedin.com/in/janic-verboon-04b11b114/">Janic Verboon</a></strong> - <em>EAM-AutoUpdater</em>
Built EAM-AutoUpdater, a free PowerShell automation that watches the Intune Enterprise App Catalog for new app versions, deploys them, and migrates assignments, scope tags, and Enrollment Status Page references from the previous version. Turns a recurring manual chore into an Azure Automation runbook. <a href="https://github.com/JanicVerboon/EAM-AutoUpdater">Read more</a></p>
<h2>On the radar this week</h2>
<ul>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1svibhk/warning_with_fully_managed_samsung_devices_and/">Samsung Knox OEMConfig wipe-block bricks devices permanently</a></strong> <em>(Reddit)</em> - Deploying a KSP profile that blocks device reset enforces at firmware level with no recovery path - do not push to production without a validated recovery procedure.</li>
<li><strong><a href="https://www.reddit.com/r/Intune/comments/1sso3r4/is_the_autopatch_management_status_report_just/">Autopatch 'Managed for quality updates' report showing zero devices</a></strong> <em>(Reddit)</em> - The report has been broken for weeks across multiple tenants, silently undermining compliance reporting - raise a support case now if affected.</li>
<li><strong><a href="https://aka.ms/secureboot-mde">Microsoft Defender now assesses Secure Boot 2023 certificate readiness fleet-wide</a></strong> <em>(Microsoft - Release Health)</em> - New Defender capability auto-categorizes devices as exposed, compliant, or not applicable with remediation guidance attached - useful directly against the 'Under observation' pain admins are reporting.</li>
<li><strong><a href="https://techcommunity.microsoft.com/t5/intune-customer-success/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is/ba-p/4513766">AI-speed CVE exploitation raises the bar for patch currency</a></strong> <em>(Blog - Customer Success)</em> - Microsoft's customer success team warns that AI-assisted exploit discovery collapses the safe response window, making proactive Autopatch ring configuration a baseline requirement now.</li>
</ul>
<hr />
<h2>In this edition</h2>
<p><strong>Landing in your tenant soon</strong>
- <a href="https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai?source=docs#removemicrosoftcopilotapp">New IT admin policy: Remove Microsoft Copilot app</a></p>
<p><strong>On the horizon</strong>
- <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/as-vulnerability-discovery-moves-at-ai-speed-keeping-current-is/ba-p/4513766">Keeping current is the new patching strategy as AI accelerates vulnerability discovery</a>
- <a href="https://techcommunity.microsoft.com/t5/microsoft-intune/autopilot-v1-vs-device-preparation-v2-great-direction-but-is-it/m-p/4514362#M23381">Autopilot Device Preparation (v2) enterprise readiness still in question for large-scale deployments</a>
- <a href="https://www.reddit.com/r/Intune/comments/1stzhf9/epm_for_network_adapter_change/">EPM network adapter elevation support reportedly in development</a>
- <a href="https://techcommunity.microsoft.com/t5/intune-customer-success/unpacking-endpoint-management-is-back-and-we-ve-got-a-lot-to/ba-p/4514599">"Unpacking Endpoint Management" series returns with engineering and product team involvement</a>
- <a href="https://aka.ms/AMA/SecureBoot">Ask Microsoft Anything: Secure Boot certificate updates (April 23 and May 18)</a></p>
<p><strong>Action required</strong>
- <a href="https://www.reddit.com/r/sysadmin/comments/1sucuh6/half_our_company_is_local_admin_security_team/">Samsung Knox OEMConfig wipe-block policy renders devices unrecoverable - test before broad deployment</a></p>
<p><strong>What shipped</strong>
- <a href="https://aka.ms/secureboot-mde">Microsoft Defender now provides centralized Secure Boot 2023 certificate readiness assessment</a></p>
<p><strong>From the field</strong>
- <a href="https://www.reddit.com/r/sysadmin/comments/1sucuh6/half_our_company_is_local_admin_security_team/">Local admin removal project: EPM audit-first approach and change management are the consensus best practice</a>
- <a href="https://www.reddit.com/r/sysadmin/comments/1srp86f/im_incredibly_confused_by_microsofts_remediation/">Secure Boot certificate update: "Under observation" status and UEFICA2023Status "Not started" on majority of fleet</a>
- <a href="https://www.reddit.com/r/Intune/comments/1sso3r4/is_the_autopatch_management_status_report_just/">Autopatch "Managed for quality updates" report showing zero devices for weeks</a>
- <a href="https://www.reddit.com/r/Intune/comments/1st15h8/windows_updates_during_oobe_autopilot/">Windows Updates not applying at Device ESP phase during Autopilot pre-provisioning</a>
- <a href="https://www.reddit.com/r/Intune/comments/1ss4gs9/opinions_of_hot_patch/">Hotpatch on 24H2: ARM64 devices silently excluded without an additional config profile</a>
- <a href="https://www.reddit.com/r/Intune/comments/1ssgr95/something_went_wrong_viewing_device_list_anyone/">Intune device list throwing "Unable to fetch any device" errors - transient but recurring</a>
- <a href="https://www.reddit.com/r/Intune/comments/1su9fdn/i_built_an_open_source_visual_map_for_microsoft/">EntraMap: open-source visual relationship mapper for users, groups, apps, and Conditional Access</a>
- <a href="https://www.reddit.com/r/Intune/comments/1srypqx/logic_app_to_monitor_expiring_apple_certificates/">Logic App for proactive Apple certificate and token expiry alerting in Intune</a>
- <a href="https://www.reddit.com/r/Intune/comments/1sruk61/enroll_existing_macs_into_intune_enable_entra_id/">Platform SSO on macOS requires ADE/ABM enrollment - user-driven Company Portal enrollment is not sufficient</a>
- <a href="https://www.reddit.com/r/microsoft365/comments/1svggs3/anyone_else_frustrated_that_corporate_contacts/">GAL contacts not surfacing in iOS native dialer - no clean Intune-native solution exists</a>
- <a href="https://techcommunity.microsoft.com/t5/microsoft-intune/autopatch-microsoft-365-apps-update-rings/m-p/4513986#M23376">Autopatch UpdateDeferredVersions registry value behaviour under active investigation by community</a>
- <a href="https://www.reddit.com/r/Intune/comments/1ssnbb2/i_want_to_install_an_intune_app_only_during/">Autopilot-only app deployment: defaultuser0 requirements script is the cleanest gate</a></p>
<hr />
<p>For the full story on every item, <strong><a href="https://ugurkocde.github.io/IntuneWeekly/editions/2026-04-28/intune-weekly.pdf">download the PDF</a></strong>. The PDF includes the radar, the upcoming-changes timeline, and the full body of each section.</p>
<p>Never miss an edition - <strong><a href="https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7454605096895746048">subscribe to Intune Weekly on LinkedIn</a></strong>.</p>]]></content:encoded>
    </item>
  </channel>
</rss>
