Windows At Work
Windows 365 Flex: Frequently asked questions
updated
Look back at five years of Windows 365 innovation and explore what’s next for Cloud PCs in the era of AI and agents. Read the Windows Experience Blog: https://aka.ms/Windows365Turns5
Learn how Windows settings backup and restore helps IT administrators preserve user settings and Microsoft Store app lists, then restore them during setup or first sign-in. See how administrator-controlled backup and restore can reduce migration risk, minimize support tickets, and help users get back to work faster.
Whether you're planning hardware refreshes, device resets, or Windows 11 migrations, Windows settings backup and restore can help create a smoother experience for both users and IT teams.
To learn more, visit https://aka.ms/NewResilienceBaseline.
Not sure where to start? Visit https://aka.ms/SecureBootForServer
Join Microsoft MVP Ugur Koc at our next #IntuneforMSPs Meetup as he walks through the continually evolving journey of macOS device management in Intune—from Apple Business Manager integration and enrollment to policy configuration, security controls, and the latest additions shaping what comes next.
Whether you’re expanding your macOS offering or refining existing workflows, this session will highlight practical guidance, real-world demos, and new opportunities to strengthen your management approach.
📍 Secure your spot and level up your macOS management strategy: techcommunity.microsoft.com/event/microsoftintuneevents/intuneformsps-meetup---june-2026/4508553
0:00 – Welcome and introductions
1:41 – Intune for MSPs Meetup mission
5:37 – macOS Management with Intune – Ugur Koc
7:24 – macOS Management with Intune – What Apple just announced
9:08 – macOS Management with Intune – The big picture in 4 parts
10:08 – macOS Management with Intune – Step 1 – Onboard
14:00 – macOS Management with Intune – Step 2 – Enroll
21:36 – macOS Management with Intune – Step 3 – Configure
32:57 – macOS Management with Intune – Step 4 – What’s New
40:29 – macOS Management with Intune – Takeaways – Your action checklist for this quarter
45:45 – Q&A
45:54 – Question – There are a lot of preinstalled apps, macOS, basic apps, etc., How do we keep these from running in a professional environment when you’re managing these with Intune?
48:03 – Question – One aspect of Platform Single Sign-on (SSO) that is not equivalent on the Mac side is authorization groups. What would you tell an admin who misses or is looking for the same kind of functionality as authorization groups?
49:20 – Question – Does macOS has a BitLocker To Go equivalent that we can manage through Intune?
50:12 – Question – Can you use the Setup Assistant panes in the Setup Assistant screen for enrolling a shared device without user affinity?
51:42 – Question – AirDrop could create some data leak possibilities – have you any experience with controlling or limiting access to AirDrop?
52:12 – Question – Intune My Mac has a Company Portal install via script. Will this work for automatic device enrollment with Platform SSO, or does it need to be a line-of-business apps?
53:44 – Question – What are the main differences in enrollment for a corporate-owned versus a BYOD mac?
54:54 – Question – When should an admin use user affinity versus device affinity?
Bring your questions on rollout plans, challenges, reporting, and best practices. We’ll cover real-world scenarios, common challenges, and the steps you can take to confidently navigate the process.
microsoft.com/en-us/windows-365/reserve?msockid=0021ad7896ec68c6314fba79975669af
learn.microsoft.com/en-us/windows-365/enterprise/introduction-windows-365-reserve
This month's #IntuneForMSPs Community Meetup features guest speaker Joery Van den Bosch, a long-time Microsoft Intune practitioner and MVP, who will share field-tested insights and lessons learned from real customer deployments.
Bookmark https://aka.ms/IntuneforMSPs for additional resources and future meetup dates.
Still need clarification? Join the next AMA live, May 18, 2026 at 8:00 a.m. PDT. Visit https://aka.ms/AMA/SecureBoot to save the date.
First, we'll show you how to create and collaborate on documents with confidence: Improvements in Narrator that make reading, navigating, and collaborating on documents smoother and more predictable on Microsoft Word.
Then, take a look at how to get through your inbox and meetings with ease. Reduce friction when triaging email, reading messages, and staying connected with your team using Outlook and Microsoft Teams.
Finally, we'll show you how to do more with Narrator itself: Image descriptions, new natural voices, ability to personalize announcements, speech recap to review or copy anything Narrator has said, screen curtain for privacy in public spaces, and braille viewer for educators and trainers -- all designed to make your everyday experience smoother and more flexible.
If you are a screen reader user, assistive technology trainer, and/or an accessibility advocate, watch and learn, then sign up to stay connected for future webinars and co-creation opportunities by visiting https://aka.ms/ContactWindowsAccessibility.
0:00 – Welcome in introductions
6:48 – With End of Life coming this week for MS Remote Desktop Client, what resources are available for admins who need to move their users to Windows App?
12:45 – Question – Will you be adding support for AI-Cloud PCs to the Canada datacenter? Currently our USA team benefits from this feature, but Canada team cannot as it's not available here.
14:44 – Question – Can we add more regions for Windows365 Enterprise in general? It seems the only Canada datacenter allowed is at Canada Central, and we'd like the other regions.
16:05 – Question – What is the exact support stance on Windows Hello for Business, passwordless sign-in, and Cloud PC access across the different clients? Where do admins most commonly misunderstand the difference between service auth, remote session auth, and in-session auth?
24:36 – Question – Is it possible to enforce strict MFA policies (example: force MFA every logon) for the Windows App on devices not managed by Intune for access Cloud PCs?
28:53 – Question – RDP Multipath is GA, what admin-facing telemetry will tell us whether it’s actually helping users in our environment?
34:58 – Question – How do I deploy Windows App to Mac, iOS, and Android at scale?
40:36 – Question – What exactly is an "agent" in the context of Windows 365 for Agents, and how is it different from a Copilot Studio bot?
49:47 – Question – For customers like ourselves using Microsoft Global Secure Access, what is the supported network design pattern for Windows 365 so we do not break Shortpath or degrade the experience?
techcommunity.microsoft.com/event/windowsevents/transitioning-to-post-quantum-cryptography/4490542
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:39 – What is post-quantum cryptography – And why do we care?
6:30 – Standard post-quantum cryptography algorithms – And when to use them
13:46 – Using post-quantum cryptography digital signatures - Using Windows APIs and tools to sign and verify with an ML-DSA certificate
16:09 – Post-quantum cryptography for encryption in transit – Preview TLS hybrid key exchange
20:16 – What comes next? – Begin your post-quantum cryptography journey now
techcommunity.microsoft.com/event/windowsevents/ama-ai-and-agentic-features-for-windows-365/4490518
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
1:17 – Question – Currently, AI-enabled Windows 365 Cloud PCs require a Windows 365 Enterprise SKU with at least 8 vCPU, 32 GB RAM, and 256 GB storage. Is there any possibility that this capability will be extended to other SKUs as well? It would be very useful if users could test this new AI experience on lower configurations.
3:42 – Question – What are the minimum specs to enable AI features on Cloud PCs?
4:28 – Question – How does Windows 365 for Agents differ from a standard Cloud PC?
7:24 – Question – How do agents use W365 to perform real work on Windows—what actually happens when an agent “checks out” a Cloud PC?
14:20 – Question – What reports are available to track Cloud PC performance and agent activity?
17:19 – Question – How do I right-size Cloud PCs for AI workloads?
21:04 – Question – What are the minimum requirements for using Windows 365 Agents? Additionally, can we automate the entire Windows 365 workflow, such as Cloud PC/Cloud Apps provisioning, configuration, and user assignment, by using Windows 365 Agents?
23:36 – Question – I get the value of W365 for Agents, but in one sentence: what problem do AI-enabled Cloud PCs solve for IT versus traditional Cloud PCs?
techcommunity.microsoft.com/event/windowsevents/protect-users-stop-attacks-passkeys-on-windows/4490547
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:58 – Passwordless on Windows – Overview, Windows Hello, Securitykey experience, plugin credential managers
5:52 – High assurance authorization – VBS Enclave SDK
10:54 – Learn more
techcommunity.microsoft.com/event/windowsevents/azure-virtual-desktop-for-hybrid-environments/4490512
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:55 – The power of Windows cloud solutions
2:33 – The case for hybrid VDI
4:18 – What is Azure Virtual Desktop for hybrid environments?
9:44 – Partners
12:23 – Resources
techcommunity.microsoft.com/event/microsoftIntuneevents/unpacking-endpoint-management-live-from-tech-takeoff-2026/4490583
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome, introductions, and discussion
6:17 – Question – From a product and engineering perspective, what are the best practices for designing Intune configuration profiles upfront—around scoping, modularity, and ownership—to minimize long term technical debt when new or unexpected scenarios emerge after hundreds of profiles are already in production?
10:18 – Question – Currently there is a nice preview feature to run remediation scripts manually on individual devices. Is there a way to run a remediation script manually to a number of devices, like a bulk action.
11:22 – Question – What are you most excited about that’s coming soon or has landed recently?
13:48 – Aria mentioned new Autopatch reports. Where is Autopatch alert and management status data sourced from, and how often is it refreshed?
15:51 – Question – What are best practices for avoiding policy conflicts and sync delays?
18:02 – Question – Where can we find the Autopatch report endpoints in Graph?
• For more info, go to learn.microsoft.com/en-us/graph/api/resources/adminwindowsupdates?view=graph-rest-beta&preserve-view=true
18:37 – Question – What is the best way to manage Win32, Store, and LOB apps together? – answered at 18:37.
• Read Pavan blog recently published: blogs.windows.com/windows-insider/2026/03/20/our-commitment-to-windows-quality
techcommunity.microsoft.com/event/windowsevents/deploy-and-manage-windows-365-with-microsoft-Intune/4490510
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:09 – Microsoft Intune and Windows 365
3:08 – Windows Autopilot device preparation support
11:55 – Microsoft Intune Suite value for Windows 365
13:20 – Microsoft Hosted Network (MHN) resiliency improvements
16:02 – Windows 365 settings
20:37 – New AI value for Windows 365
techcommunity.microsoft.com/event/windowsevents/secure-and-manage-ai-and-agentic-capabilities-in-windows/4490541
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introductions
1:49 – Question – Are agentic capacities opt-in, preview-only, or turned on by default?
3:32 – Question – Can we enable AI features for some users or devices but not others?
5:13 – Question – Do agents run as the user, as a service, or as a separate identity?
7:45 – Question – With the recent news on how Microsoft is pulling back certain AI integrations (Notepad, etc.), what changes will there be with managing AI on Windows?
10:58 – Question – What’s the recommended approach to managing agentic features across a mixed fleet (managed, unmanaged, and different device types)?
13:59 – Question – How should admins think about permissions for agent connectors/workspaces—what’s the “least privilege” strategy?
17:23 – Question – Are AI and agent actions logged separately from user actions?
19:27 – Question – Do you have any updates on how MCP on Windows is evolving? (MCP = Model Context Protocol)
21:13 – Question – What’s the best way to monitor or block risky AI‑initiated behaviors?
24:17 – Question – How do you roll this out safely—pilot design, rings, and criteria for broad enablement?
techcommunity.microsoft.com/event/windowsevents/zero-trust-dns-securing-windows-one-connection-at-a-time/4490555
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:01 – Evolution of DNS security
3:14 – Zero Trust DNS
4:36 – Demo
11:17 – Deployment guidance
17:19 – Resources
17:40 – Survey
techcommunity.microsoft.com/event/windowsevents/ama-the-latest-in-windows-hardware-security/4490546
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome & introductions
1:22 – Question – How do I tell—at scale—which devices can support VBS, HVCI, and newer kernel protections?
2:23 – Question – What does VBS actually do at a hardware level?
4:05 – Question – Do all TPMs behave the same, or are there differences between firmware TPM, discrete TPM, and Pluton?
6:22 – Question – How do we verify—remotely—that hardware-based protections are actually running?
8:09 – Question – What exactly does Secure Boot protect against—and what does it/doesn’t it stop?
10:20 – Question – What happens if our devices don't get updated with the new Secure Boot certs in time?
• For more info go to https://aka.ms/GetSecureBoot
12:56 – Question – Can VBS or memory integrity break drivers, VPNs, or virtualization tools?
15:30 – Question – Why are features like Credential Guard and HVCI enabled by default on some devices but not others?
17:51 – Question – Will enabling Secure Boot break imaging, recovery media, or dual‑boot scenarios?
19:48 – Question – What’s the real‑world performance impact of VBS on modern CPUs?
20:52 – Question – What happens on older hardware that technically runs Windows 11 but can’t enable all hardware-backed protections?
22:21 – Question – What is kernel mode hardware enforced stack protection, and do we need new CPUs for it?
23:15 – Question – How do we explain the value of hardware-backed security to leadership in plain language?
techcommunity.microsoft.com/event/windowsevents/resilience-for-the-modern-era-windows-quick-machine-recovery/4490551
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:28 – Getting started – Windows Autopatch, Windows Resiliency initiative, Quick machine recovery
9:30 – Quick machine recovery in Windows Autopatch – IT admin controls, reporting, alerts
15:56 – Learn more
Have questions? Join the discussion on the Microsoft Tech Community: techcommunity.microsoft.com/event/microsoftintuneevents/advanced-automation-and-powershell-for-intune---intuneformsps-meetup/4497183
Bookmark the Microsoft Intune for MSPs resource guide, your home for all things #IntuneForMSPs, for future session dates and resources to help you on your journey: https://aka.ms/IntuneforMSPs
0:00 – Welcome and introductions
3:13 – Presentation – Intune API introduction with Microsoft’s Dave Randall
14:36 – Presentation – Hear from a peer: MVP Erik Loef “My MSP Journey”
30:35 – Presentation – Hear from a peer: MVP Andrew Taylor Intune Automation
47:00 – Q&A starts
47:28 – Question – Are there endpoints that cannot be accessed by API?
48:41 – Question – You mentioned config as code-- what’s the best strategy for pipeline management? What are the best tools to manage that most effectively?
50:36 – Question – From your experience running an MSP, what was the biggest game-changer for you? Where did you see a real difference in your operations?
52:41 – Question – If you’re doing automation across multiple tenants of repeatable tasks, what’s the safest way to run scheduled jobs and what tools and parameter recommendations do you have?
54:04 – How do you make sure your automation doesn’t accidentally break something? Or if it does break, what’s your testing/roll-back strategy? How to build these systems to avoid upsetting clients?
56:45 – Presentation – What’s next & closing
techcommunity.microsoft.com/event/windowsevents/migrating-from-vdi-to-windows-365/4490516
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:22 – Windows 365 overview
5:38 – Migrating to Windows 365
9:58 – Technical overview
13:22 – Demo: Migrating to Windows 365
16:35 – Resources
techcommunity.microsoft.com/event/windowsevents/app-control-for-business-same-roots-new-playbook/4490549
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:00 – Introduction – Brief refresher on ACfB
3:29 – Deep dive – Script Enforcement
12:13 – Deep dive – Azure Arc
17:36 – Deep dive – Session Locked Policy
23:39 – Wizard + documentation additions
techcommunity.microsoft.com/event/microsoftIntuneevents/click-less-manage-more-simplify-app-deployment-with-Intune/4490573
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:02 – Enterprise App Management overview
6:07 – Architecture
12:30 – How to keep apps up to date
15:40 – Learn more
techcommunity.microsoft.com/event/microsoftIntuneevents/manage-apple-devices-at-scale-Intune-security-best-practices/4490571
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:09 – Intune macOS capabilities – recent updates, roadmap
10:08 – Enrollment – LAPS, PSSO during device enrollment
21:00 – Custom compliance
23:50 – macOS Recovery Lock
27:24 – Join the Microsoft Mac Admins Community!
techcommunity.microsoft.com/event/microsoftIntuneevents/ama-getting-the-most-from-security-copilot-in-Intune/4490590
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introductions
1:29 – Question – What exactly does Security Copilot do inside of Intune?
2:16 – Question – How do I know if Copilot is enabled in my tenant?
• For more information, go to https://aka.ms/IntuneCopilotOverview
3:38 – Question – How does Security Copilot pull data from Intune? What permissions does it use?
4:41 – Question – Are there any plans to increase the file size limit in the Policy Configuration Agent?
5:12 – Question – Can Security Copilot help me write or troubleshoot Intune Policies?
7:19 – Question – Can you provide a few examples of how I should use this inside existing workflows?
8:55 – Question – How accurate and reliable are the recommendations these agents offer? Are they customized to my tenant?
11:22 – Question – Which Entra ID role and License required to use the features of Security Copilot?
• Learn about Security Copilot for Microsoft 365 E5 included customers here: https://aka.ms/SecurityCopilotM365.
13:48 – Question – Do Intune agents need secure compute units (SCUs)?
15:28 – Question – Can Security Copilot explain why a device is non compliant or blocked by Conditional Access and recommend remediation steps?
16:57 – Question – Will Intune agents be able to update the applications in my environment automatically based on vulnerabilities and new releases from the vendor?
20:50 – Question – Does not Purview and Sentinel provide that information in the device reports?
22:18 – Question – What kind of reporting do we provide, where you don’t have to go to Purview and Sentinel?
24:26 – Question – If I’m new to this, where do I start using Security Copilot for Intune? How can I get started?
techcommunity.microsoft.com/event/microsoftIntuneevents/ai-roundup-Intune-agents-for-outcome-oriented-innovation/4490578
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:22 – What are AI agents?
3:30 – Change review agent
6:50 – Policy configuration agent
10:18 – Vulnerability remediation agent
13:08 – Learn more
techcommunity.microsoft.com/event/windowsevents/user-experience-updates-windows-365-boot-and-more/4490509
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:30 – Windows 365 Boot: What’s new
5:28 – Windows 365: Choose your connection method
9:32 – Surface Mouse support on iOS
14:22 – Microsoft Teams optimizations
techcommunity.microsoft.com/event/microsoftIntuneevents/Intune-timing-demystified-what-really-happens-behind-the-scenes/4490580
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:00 – Intune architecture – Device check-in types, Intune payload delivery journey, the ‘Fast-lane’
5:32 – Deep dive – Optimizing load, improving performance
7:19 – Deep dive – Check-in prioritization
10:28 – Deep dive – Consistent notifications
12:57 – Deep dive – Notification resiliency
15:03 – Deep dive – Timely maintenance notifications
3:29 – What we’ve been working on
16:39 – Other investments
17:09 – Summary
techcommunity.microsoft.com/event/windowsevents/reporting-at-scale-with-windows-autopatch-update-readiness/4490526
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:43 – What’s in Windows Autopatch today?
2:10 – Windows Autopatch update readiness
19:44 – What next?
techcommunity.microsoft.com/event/microsoftIntuneevents/why-smarter-windows-management-starts-with-Intune/4490586
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
4:48 – Windows Autopilot
8:36 – Windows Autopilot device prep
19:44 – Application Management
0:00 – Welcome & introductions
0:46 – Question – What happens if you set the registry settings on a device that is still using Legacy BIOS? Is the update process smart enough to ignore those devices?
1:59 – Question – Our company does not allow us to use Intune. Are there any helpful tools or scripts to Inventory?
3:24 – Question – During the February AMA, you en-phased that enterprises should leverage Intune and build their own dashboard to monitor secure boot states. The guide requires Enterprises licenses. As an MSP that manages thousands of devices with Business Premium Plan...
6:03 – Question – Could you confirm that the Secure-Boot-Update scheduled task expects Microsoft's Owner GUID on Microsoft's signatures in Secure Boot? We customize the Secure Boot content ....
9:20 – Question – "The KEK update (needs to be signed by the OEM because they own the PK) is required before June 2026." I remember Scott in the December AMA saying that the various (existing) key/cert updates continued to work past 2026...
10:38 – Question – If I ignore this and do nothing, will devices with (or without) secure boot enabled continue to boot?
12:05 – Question – What is the timeline of assisted Controlled Feature Update? Are you planning to roll out the Secure Boot Cert. Update to 100% of devices before June 2026? Or should we already prepare the alternative ways to update the devices (registry, GPO or Intune policy)?
14:29 – Question – Seeing some devices running on Hyper V with the March 2026 updates applied, some Server 2019 servers show updated...
16:02 – Question – What would be the impact of blanketly applying this policy setting? Enable Secureboot Certificate Updates
17:12 – Question – Are these updates Bitlocker aware? Do we need to suspend bitlocker for 2-3 reboots during this process?
18:25 – Question – We've successfully updated some of our devices with the 2023 cert, and tested how PXE boot in SCCM would work....
22:35 – Question – How can we get a compliance report if we do not use AutoPatch?
Question – What is the timeframe for the cert to upgrade if we leave the LCU to do the job based on a high confidence level compared to enabling the CFR settings?
26:48 – Question – How important is it that the system already boots trusting the 2023 cert instead of the 2011 cert? Is it okay for the system to continue booting using the 2011 cert as long as the 2023 KEK and DB certificates install?
29:37 – Question – I have deployed the secure boot remediation through Intune and I see event ID 1801 that says the certificates are available but not applied and the BucketConfidenceLevel shows Need more data. Do i need to take any action on that ?
33:02 – Question – Looks like there have been reports online of users receiving driver updates that are requiring bitlocker keys to be entered after reboot...
35:24 – Question – I noticed that some of my clients (around 5% so far) updated only two of three Secure Boot Certificates. Intune Remediation script shows the following output: Microsoft UEFI CA 2023 = False, Microsoft Corporation UEFI CA 2011 = True...
38:23 – Question – Will Microsoft release an OS upgrade that requires the EFI partition to be signed with the 2023 certificate? If so, is this expected in Windows 11 26H2, and has Microsoft announced anything about this?
42:14 – Question – Can Secure Boot certificates be updated when Secure Boot is disabled?
Question – Does Server 2025 automagically comply? Both fresh install & Server 2022 update? – answered at 47:15.
49:00 – Question – Will devices that have 2023 cert already require a boot.wim that has 2023 cert once June 2026 has passed?
50:47 – Question – How long will the 2023 certs last? Will this process need to be repeated when that happens?
52:59 – Question – I manually updated the registry on a device, set it to 22852, and forced the Scheduled Task to start, waited 30 seconds and forced a reboot, and the server (server 2019 VM in hyperv with the latest march patches)...
55:27 – Question – In the March 2026 release notes it says this: “With this update, Windows quality updates include additional high confidence device targeting data, increasing coverage of devices eligible to automatically receive new Secure Boot...
57:36 – Question – How will Windows Update behavior change post-expiration on devices that haven't trusted the 2023 keys....
techcommunity.microsoft.com/event/microsoftintuneevents/the-intune-playbook-for-ios-management-at-scale/4490574
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:00 – Enrollment
4:35 – AxM (Apple Business/School Manager)
6:40 – DDM (Declarative device management)
10:48 – Apple mobile roadmap
techcommunity.microsoft.com/event/windowsevents/from-panic-to-productive-point-in-time-restore-in-windows/4490554
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:28 – What is point-in-time restore? Feature overview and how it works
4:30 – Limitations & Configuration – learn more about constraints and features management
9:50 – End user experience – Demo of how an end-user can recover theirdevice with point-in-time restore
12:46 – IT Admin experience – Get a preview into how IT Admins will be able toperform a restore remotely
15:44 – Best practices and call to action
techcommunity.microsoft.com/event/windowsevents/windows-365-frontline-expands-with-cloud-apps-and-more/4490517
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:10 – Windows 365 Frontline deep dive
2:52 – How to persist application data and settings with User Experience Sync
4:05 – Delivering targeted experiences with Cloud Apps
6:08 – Delivering Frontline Shared: An End to End Cloud PC and App Experience
techcommunity.microsoft.com/event/microsoftintuneevents/least-privilege-on-windows-with-endpoint-privilege-management/4490591
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:00 – EPM Basic
4:00 – EPM Policy and setup
9:01 – Administering EPM
13:30 – Support approved for elevations
20:28 – Path to least privilege – adopting EPM
techcommunity.microsoft.com/event/windowsevents/windows-365-reporting-and-monitoring-updates/4490515
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:07 – Reporting evolution
7:22 – Demo: Monitoring & reporting
techcommunity.microsoft.com/event/microsoftIntuneevents/making-the-most-of-your-Intune-data/4490577
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:28 – Overview
3:07 – Copilot chat – overview and demo
10:47 – Explorer experience – overview and demo
18:10 – Advanced Analytics – overview and demo
26:20 – Learn more
techcommunity.microsoft.com/event/windowsevents/ready-day-one-how-to-get-windows-users-up-and-running-fast/4490534
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:43 – Windows backup for organizations
5:32 – Windows Update in OOBE
10:48 – Demo – tie everything together
13:35 – Get started today
techcommunity.microsoft.com/event/microsoftIntuneevents/feedback-wanted-app-management-in-the-enterprise/4490584
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome & introductions
3:06 – Feedback/question – Is there a plan to provide more visibility to the supersedence portion of app deployment? For example, I have an app that I deployed an update to that supersedes an existing deployment. If I deploy an app that supersedes both the update an the original deployment, then weeks later go back and delete the original deployment, I have to find the app that is preventing the deletion because of the supersedence relationship. In SCCM, I can at least see the offending app. In Intune, I'm not able to other than that there's a supersedence rule applied.
5:07 – Feedback/question – Also, what about dependencies? You can see down the chain but not up. As I'm modifying an app, it'd be good to know which other apps depend on it.
5:22 – Feedback/question –What about adding the running process check like in ConfigMgr, before upgrading or superseding an application. If the native app is running, alert user first.
8:18 – Feedback/question – Will there ever be a way to create a dynamic group of devices that have a particular program installed in Intune? I have this set up in Config Manager and this helps with program deployment.
11:05 – Feedback/question – Most of our applications are migrated to Intune from ConfigMgr. However, we have some rather large packages, like AutoDesk applications (some take up to 25-30GB), that we prefer to push via ConfigMgr, since it is typically much faster than going from the internet. --- Similar feedback from Sinan -- We deploy big CAD software (100+ GB) via SCCM. How to do that with Intune?
17:27 – Feedback/question – The inclusion of a bespoke "Microsoft 365 Apps" app type is useful and simplifies the deployment of the M365 apps to endpoints. However, the process of adding an individual app to a pre-existing install is not smooth; for example, where the company base profile excludes Microsoft Access but some users later require Access, it's tricky to add it when the suite is already installed, largely because most users have at least one of the M365 apps open at all times, which blocks config changes. It's also infeasible to have users self-service via Company Portal since the apps are all delivered as a single bundle. This adds to the request for adding support for running process handling natively in Intune.
22:02 – Feedback/question – Can you work on integrating app discovery with App Control for Business. My concern is that our endpoints already have a large number of apps installed through previous deployment processes, and so even with "managed installer" allowed, that does not cover previously deployed apps which then get blocked. The whole app control for business side of Intune would be much easier to deploy if that team was totally looped in with the teams building app deployment, app inventory, and app updates for Intune.
techcommunity.microsoft.com/event/windowsevents/secure-boot-certificate-updates-explained/4490529
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:49 – Secure Boot overview – introduction to Secure Boot cert expiration and its impact
3:28 – New devices
3:56 – Preparing your environment
8:56 – Solution pathways – deployment pathways for in-market devices 1. Windows-drive rollout 2. Admin managed alternatives
11:28 – Solution pathways – 2. Admin managed alternatives
22:12 – Additional info
techcommunity.microsoft.com/event/windowsevents/the-latest-in-security-for-windows-365-and-azure-virtual-desktop/4490503
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:35 – Windows 365 strengthens security from client to cloud
9:59 – Demos: Better protect the OS, data, and access in your organization
26:10 – Windows 365 Reserve provides secured, as-needed access
techcommunity.microsoft.com/event/windowsevents/resiliency-with-windows-365-and-azure-virtual-desktop/4490507
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
3:29 – Connectivity platform
8:17 – Management platform
10:43 – Workload resiliency
11:00 – Azure Virtual Desktop resiliency
15:15 – Windows 365 resiliency
techcommunity.microsoft.com/event/microsoftintuneevents/one-platform-many-industries-smart-android-management-with-intune/4490570
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:04 – Android overview
3:54 – Key features for Android – organized by industries
15:28 – What’s coming
techcommunity.microsoft.com/event/windowsevents/the-latest-in-windows-11-security/4490530
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
0:50 – A deep-dive on NTLM – what is NTLM? And what are the associated security risks?
3:33 – NTLM auditing – Auditing NTLM usage and legacy dependencies
5:01 – More Kerberos, better security – introducing upcoming Kerberos enhancements
16:53 – Disabling NTLM by default – roadmap to disabling NTLM in Windows
18:31 – Learn more
techcommunity.microsoft.com/event/microsoftintuneevents/the-ai%E2%80%91powered-admin-emerging-trends-in-endpoint-management/4490567
This session is part of the Microsoft Technical Takeoff: Windows + Intune: https://aka.ms/TechTakeoff
0:00 – Welcome and introduction
1:15 – Why AI now?
5:16 – 5 Trends & expectations
13:13 – Intune developments
21:43 – Summary


