Uploaded October 2025 | Updated September 2026, 17 hours ago
Curious how to stay agile and ready for growth with a secure Zero Trust approach? From baselines and policies to device actions and compliance, our engineering teams will be ready to answer your questions and help you find the right solutions for your ecosystem. Whether you are looking at those first steps of going cloud-native, or are already cloud-based, this is Ask Microsoft Anything (AMA) so get the advice you need to simplify, optimize, and secure.
The live stream is over, but we're taking your questions on the Tech Community until Friday, October 10 so visit https://aka.ms/AMA/IntuneManagement to keep posting your questions.
This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition.
📃 For the full agenda, see: https://aka.ms/TCL/Intune
❓To see the full Q&A: https://aka.ms/AMA/IntuneManagement
0:00 – Welcome & introductions
2:28 – Can you share some of the history/thought behind where endpoint security came from within Intune, and how it lives in Intune, and what some of those early thoughts and ideas—and where the inspiration came from for endpoint security?
7:15 – Do we have a road map to bring Windows Server to Intune? Where we are on the Linux Endpoints in support with Intune Endpoint Security?
12:32 – What are some tips, or ways you’ve seen common misconfigurations, and general learning you have to share?
15:43 – The age old question: native multi-tenancy management, from a managed services provider's perspective. I think this pertains to security and zero trust due to the fact many providers solution for this is a guest admin account in the clients org with global privileges. What are some best practices around multi-tenancy—using guest accounts, how you should audit that, how you should keep track of it, etc.?
18:18 – Are there audit logs for Intune management?
21:24 – AVDs (IaaS VMs) + Windows 11 combinations, we are missing the patching directly from Intune in terms of Auto patch. Any plan for that? If so, it will give some sort of relaxation on the vulnerability management in terms of quality updates for a better security.
22:56 – What are some of the biggest challenges you’ve seen for customers, where they’ve solved it in the past couple years? And then what are some of the biggest challenges you see coming up in the next few years, specifically pertaining to endpoint security?
27:32 – Is there any plans to expand on the functionality of Endpoint Privilege Management? And is there any changes that can be done that can speed up the reply from an elevation requests?
30:31 – Since you work so closely with the Defender team-- what is one of the highlights that came out this past year and what’s one of the new things that’s been announced that coming out in the next few months, with regards to integrations with Microsoft Defender?
37:48 – Intune integrates with Defender and conditional access for risked based compliance, but how does integration handle real time enforcement across non-Windows devices?
43:18 – Would it be possible to introduce dynamic Intune policies based on things such as device risk levels, locations, known application vulnerabilities etc..?
45:05– Using MAM-WE (without enrollment) with App Protection policies, is there a way to require Microsoft Defender to be not just installed but also have "Check for harmful links" enabled?
46:44 – Finals thoughts - round robin
51:07 – I've sent a wipe request to a device which a user took away when they left, on Intune it still hasn’t done the wipe and I think it’s because it’s not connected to a network yet? Also does Intune continue to send the wipe request until its done?
55:04 – Closing remarks
Curious how to stay agile and ready for growth with a secure Zero Trust approach? From baselines and policies to device actions and compliance, our engineering teams will be ready to answer your questions and help you find the right solutions for your ecosystem. Whether you are looking at those first steps of going cloud-native, or are already cloud-based, this is Ask Microsoft Anything (AMA) so get the advice you need to simplify, optimize, and secure.
The live stream is over, but we're taking your questions on the Tech Community until Friday, October 10 so visit https://aka.ms/AMA/IntuneManagement to keep posting your questions.
This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition.
📃 For the full agenda, see: https://aka.ms/TCL/Intune
❓To see the full Q&A: https://aka.ms/AMA/IntuneManagement
0:00 – Welcome & introductions
2:28 – Can you share some of the history/thought behind where endpoint security came from within Intune, and how it lives in Intune, and what some of those early thoughts and ideas—and where the inspiration came from for endpoint security?
7:15 – Do we have a road map to bring Windows Server to Intune? Where we are on the Linux Endpoints in support with Intune Endpoint Security?
12:32 – What are some tips, or ways you’ve seen common misconfigurations, and general learning you have to share?
15:43 – The age old question: native multi-tenancy management, from a managed services provider's perspective. I think this pertains to security and zero trust due to the fact many providers solution for this is a guest admin account in the clients org with global privileges. What are some best practices around multi-tenancy—using guest accounts, how you should audit that, how you should keep track of it, etc.?
18:18 – Are there audit logs for Intune management?
21:24 – AVDs (IaaS VMs) + Windows 11 combinations, we are missing the patching directly from Intune in terms of Auto patch. Any plan for that? If so, it will give some sort of relaxation on the vulnerability management in terms of quality updates for a better security.
22:56 – What are some of the biggest challenges you’ve seen for customers, where they’ve solved it in the past couple years? And then what are some of the biggest challenges you see coming up in the next few years, specifically pertaining to endpoint security?
27:32 – Is there any plans to expand on the functionality of Endpoint Privilege Management? And is there any changes that can be done that can speed up the reply from an elevation requests?
30:31 – Since you work so closely with the Defender team-- what is one of the highlights that came out this past year and what’s one of the new things that’s been announced that coming out in the next few months, with regards to integrations with Microsoft Defender?
37:48 – Intune integrates with Defender and conditional access for risked based compliance, but how does integration handle real time enforcement across non-Windows devices?
43:18 – Would it be possible to introduce dynamic Intune policies based on things such as device risk levels, locations, known application vulnerabilities etc..?
45:05– Using MAM-WE (without enrollment) with App Protection policies, is there a way to require Microsoft Defender to be not just installed but also have "Check for harmful links" enabled?
46:44 – Finals thoughts - round robin
51:07 – I've sent a wipe request to a device which a user took away when they left, on Intune it still hasn’t done the wipe and I think it’s because it’s not connected to a network yet? Also does Intune continue to send the wipe request until its done?
55:04 – Closing remarks










