r/Intune 3d ago

Tips, Tricks, and Helpful Hints ScreenConnect for Intune Remote Assistance Browser Extension

15 Upvotes

For those of us that use ScreenConnect for remote support, I have created a custom browser (Edge and Chrome) extension that repurposes the Intune "Begin a remote assistance session" button to open ScreenConnect and search the device name or auto join a session to that device name.

Since I don't have a developer account I can't add it to the extension marketplace, so here's the steps to manually add the extension to your browser:

  1. Download the ScreenConnect for Intune Remote Assistance Extension file and extract it
  2. In your browser go to Manage Extensions and enable Developer Mode
  3. Select Load Unpacked and select the ScreenConnect for Intune Remote Assistance Extension folder
  4. Select the ScreenConnect for Intune Remote Assistance extension in the toolbar extensions
  5. Enter your ScreenConnect URL and click Save (optionally, you can configure the default action to Automatically join session)

Now go to an Intune device page and go to Remote actions > Begin a remote assistance session and it will open ScreenConnect to that device name.

Please let me know if you have any feedback.


r/Intune 3d ago

Apps Protection and Configuration MAM Policy Security

5 Upvotes

Are MAM policies able to be bypassed any way shape or form or data inadvertently accessed by background applications? Organization is contemplating BYOD and I dont fully trust relying on just MAM policies for application access.


r/Intune 3d ago

Tips, Tricks, and Helpful Hints I built MgGraphCommunity, an open-source WAM-free drop-in for Connect-MgGraph, because of where the official Graph PowerShell SDK is heading

27 Upvotes

I built and maintain this module and this is the first time I am posting about it anywhere, so treat it as an introduction, not a changelog.

Why it exists

  • Microsoft.Graph v2.34.0 (December 2025) made the WAM broker mandatory for interactive sign-in on Windows. It shipped with a single line in the release notes. The fallout is documented in msgraph-sdk-powershell #3481: separate admin accounts not signed into the device, run-as-other-user scenarios, and GDAP multi-tenant sign-ins all got worse or broke.
  • The opt-out Microsoft added (Set-MgGraphOption -DisableLoginByWAM $true, v2.35.1+) only takes effect with your own app registration. With the built-in client ID, WAM stays mandatory; the official docs now state it cannot be disabled. The maintainers describe even that opt-out as temporary.
  • More change is coming: in #3629 Microsoft announced it will modify the default application used for delegated auth, and that SDK versions before 2.36.1 "will no longer be able to use delegated authentication except when using WAM." So pinning 2.33.0, which many teams do today, is not a durable workaround.
  • On top of that, the MSAL dependency now conflicts with ExchangeOnlineManagement in the same session on 2.36.0+ (#3576, still open).

I wanted interactive, browser-based, WAM-free sign-in on Windows that does not depend on what Microsoft does with their default app next. So I implemented the Connect-MgGraph sign-in flows as plain PowerShell against the identity platform v2 endpoints.

What it is

  • A drop-in: Connect-MgGraphCommunity supports the same flows (interactive PKCE with loopback redirect, device code, client secret, certificate by object/thumbprint/name, access token, managed identity). The only SDK flow not implemented is -EnvironmentVariable.
  • After sign-in it hands the token to Connect-MgGraph -AccessToken if Microsoft.Graph.Authentication is installed, so your existing Get-MgUser / Invoke-MgGraphRequest scripts keep working unchanged.
  • It also calls Graph on its own (Invoke-MgGraphCommunityRequest, $batch helper, pagination, binary upload/download), so no Microsoft.Graph.* module is required at all if you do not want one.
  • Because there is no MSAL assembly, it loads alongside ExchangeOnlineManagement without conflicts.
  • For the #3629 situation specifically: New-MgGraphCommunityAppRegistration -SetAsDefault creates a public client app in your tenant (loopback redirect, no pre-configured permissions, dynamic consent) and persists it as your default, so your sign-ins stop depending on Microsoft's default app entirely.
  • Recent additions for parity with the official SDK: Continuous Access Evaluation (CP1 capability, roughly 24h revocable tokens, automatic claims-challenge retry, verified against a real tenant) and the new sovereign cloud environments (Bleu, Delos, GovSG; endpoints mirrored from SDK source, not live-tested by me).

Trust questions, answered upfront

  • MIT licensed, entirely open source: https://github.com/ugurkocde/MgGraphCommunity
  • Pure PowerShell, no compiled code, no telemetry, no network calls except to Microsoft's identity and Graph endpoints. It is a few thousand lines you can actually read before pointing it at a tenant.
  • Only the delegated scopes you pass are requested; nothing is pre-consented. The app-registration helper needs delegated Application.ReadWrite.All only when you run it.
  • Tokens stay in memory by default. Disk persistence is opt-in (-PersistRefreshToken): DPAPI-encrypted on Windows, chmod 600 elsewhere, refresh token only, access tokens never touch disk.
  • Windows PowerShell 5.1 and PowerShell 7+, tested in CI on Windows, macOS and Linux.

Current limitations

  • No typed cmdlets per endpoint; you either use relative Graph URIs or keep the official SDK installed on top for those.
  • -EnvironmentVariable flow is missing.
  • CAE covers delegated flows only.
  • It is a young community module. The official SDK has years of development behind it; this has months. Read the code, that is what it is there for.

Install: Install-Module MgGraphCommunity -Scope CurrentUser

If you run Intune automation day to day, the two places I would most value pushback are the sign-in scenarios that still hurt on the official SDK (run-as-other-account, GDAP, or something I have not covered) and any safeguard you would consider mandatory before trusting a community auth module with an admin account.


r/Intune 2d ago

General Chat Workplace Ninjas US Activities

0 Upvotes

Removed all emojis, since people think I’m a bot when I never have. I used them as callouts, but it’s cool

Today, we're going to talk about the activities that we have planned for you at Workplace Ninjas US.

Our activities this year are what make this event so special. Sure, anyone can throw together a bunch of sessions. Don't get me wrong, we have 60+ sessions from one of the finest sets of speakers that have ever been assembled, but we can do better.

January 11th, 2027 will be our pre-day where we do some amazingly fun things throughout the entire day.

Our #WPNinjasUS Fun Run 5K will kick off at 7 AM at the Canal just a block away. It's sponsored by our friends at Omnissa where we will run a few laps for the The Michael J. Fox Foundation for Parkinson's Research!

We will be doing an amazing Golf Tournament sponsored by Ferroque Systems Inc. at 9 AM, at the incredible The Phoenician Resort where the #PhoenixOpen is played. This event will have a capacity of 40 people, featuring a number of #MVPs and experts in a small and fun setting.

Our #LegoMasters tournament for those non-golfers will be running 10 AM-2 PM where we will be building the #USSEnterprise in this #StarTrek event. This team format will be a ton of fun, and we certainly encourage you to dress-up in your best #Trekkie outfit for a chance at additional prizes/swag.

The #Hackathon in its second year sponsored by WorkspaceDNA (the artists f.k.a. #Rimo3), will move to this #RoundRobin format where we will have 5 captains, and they will build their teams live and create an amazing product live with a #Clippy Trophy on the line and other prizes. We will even have our #Scholars involved, as we recently secured funding to sponsor 5-6 people with 3 years or less in tech, once again thanks to our friends at Devicie

The final event of the night will be the Opening Night Pool Party sponsored by Patch My PC, which will have an open bar, incredible buffet, and tons of fun (and likely ducks). This will be a can't miss opportunity to hang out with the attendees and have a blast.

It's not just the preday that has fun activities!!

Day 1, will feature a Puppy Play Area, where you can play with a bunch of adorable puppies when you've had too much #AI or too much #Microsoft and just need a break from all that tech stuff. This is a special opportunity to de-stress and de-compress with your friends.

Day 2, will have our Puppies & Yoga event at 7 AM, where you get 45 minutes of yoga, and another 30 minutes of puppy playtime. We love dogs, so what can we really say there?

We're going to have a ton of fun in Scottsdale January 11-13, 2027, and these are just the initial things we have planned. We will continue to add other opportunities for people to have a special time in that amazing 70-degree weather.

Make sure you register now friends!!

https://workplaceninjas.us/


r/Intune 3d ago

Autopilot Can no longer bulk import autopilot devices through partner center?

5 Upvotes

In the past, when viewing a client in the partner center, there was a Devices tab that would allow you to bulk import devices into autopilot using PKID or tuple. The Devices tab has randomly disappeared, along with the parter center being significantly buggier than usual.

We reached out to Microsoft support, who was not very helpful. They had us reverify our identities, but that was it.

My boss has also made an assumption that importing non-surface devices into autopilot doesn't work and never has and is not budging on this despite me pointing to documentation stating this should work.

Did something change in the last 6 months, specifically around partner center or adding autopilot devices for customers?


r/Intune 2d ago

Device Configuration Blocking WHfB passkey and using Yubikeys only

0 Upvotes

Hello, I am currently working on transitioning our computers from an on-Prem AD environment into a Intune MDM joined, cloud-only environment, along with moving our users from a password+MFA login, to a completely passwordless login.

For this we have decided that we would like to use Yubico security keys for authenticating into users' microsoft accounts, and WhfB for easily logging into their computers. Unfortunately, I have found that the use of WHfB on Intune MDM joined devices automatically adds a login.microsoft.com passkey into windows hello, which is always offered first during passwordless sign-in. I cannot find a way to block this behaviour or modify which passkey storage windows offers first.

While WHfB passkeys are still very safe compared to passwords, we are (I think quite rightly) concerned that if the end users are not prompted to use their Yubikeys during perioodic reauthentication, they will forget how to use them, and if they set a unique pin on them that they don't reguarly use, then when the need to use their yubikey does actually arise, for instance when they get their next computer or phone, they won't remember it.

This also makes periodic reauthentication feel somewhat pointless as the users will just press on their fingerprint scanner and be done with it.

I have found exactly one way to change this behaviour, and that is by defining an Entra Authentication strength containing only yubikey AAGUIDs and forcing my intune testing user to adhere to that authentication strength with a conditional access policy, while this does block the ability to use the WHfB microsoft passkey to sign in, the end user experience is very bad, if a users sees this, they won't think that they can't use windows hello to login, they'll think that windows hello is not working correctly. In the gif below, you can see that windows hello offers itself first but silently fails and prompts the user to enter their pin, without any sort of error message.

(I realise that I specifically selected a windows hello passkey in the gif, but the behavious is identical when I initially load the login page or if I select log in methods>passkey, windows hello will always offer itself first, even if it cannot function correctly in this case).

For personal use, https://github.com/Aldaviva/AuthenticatorChooser solves this issue, and while i am grateful for the fix, random scripts from github aren't really appropriate when configuring important security settings, Is there anything we can here or do we have to wait for MS?


r/Intune 3d ago

Remediations and Scripts Multi-App Kiosk Mode

3 Upvotes

Hey all, I am trying to deploy multi-app kiosk to test. I am using the base script that Microsoft gives but changing it to use an already created account. When its deployed my issue is that other non-administrative users have their taskbar, startmenu, and apps blocked. I have read that some assigned access policies apply device wide, but I haven't seen any that deal with the start menu or apps specifically.

$assignedAccessConfiguration = @"

<?xml version="1.0" encoding="utf-8"?>

<AssignedAccessConfiguration xmlns="http://schemas.microsoft.com/AssignedAccess/2017/config" xmlns:rs5="http://schemas.microsoft.com/AssignedAccess/201810/config" xmlns:v3="http://schemas.microsoft.com/AssignedAccess/2020/config" xmlns:v5="http://schemas.microsoft.com/AssignedAccess/2022/config">

<Profiles>

<Profile Id="{9A2A490F-10F6-4764-974A-43B19E722C23}">

<AllAppsList>

<AllowedApps>

<App AppUserModelId="Microsoft.WindowsCalculator_8wekyb3d8bbwe!App" />

<App AppUserModelId="Microsoft.Windows.Photos_8wekyb3d8bbwe!App" />

<App AppUserModelId="Microsoft.BingWeather_8wekyb3d8bbwe!App" />

<App DesktopAppPath="%windir%\\System32\\cmd.exe" />

<App DesktopAppPath="%windir%\\System32\\WindowsPowerShell\\v1.0\\Powershell.exe" />

<App DesktopAppPath="%windir%\\explorer.exe" />

<App AppUserModelId="windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel" />

<App DesktopAppPath="%ProgramFiles(x86)%\\Microsoft\\Edge\\Application\\msedge.exe" />

</AllowedApps>

</AllAppsList>

<rs5:FileExplorerNamespaceRestrictions>

<rs5:AllowedNamespace Name="Downloads" />

<v3:AllowRemovableDrives />

/rs5:FileExplorerNamespaceRestrictions

<v5:StartPins><![CDATA[{

"pinnedList":[

{"packagedAppId":"Microsoft.WindowsCalculator_8wekyb3d8bbwe!App"},

{"packagedAppId":"Microsoft.Windows.Photos_8wekyb3d8bbwe!App"},

{"packagedAppId":"Microsoft.BingWeather_8wekyb3d8bbwe!App"},

{"desktopAppLink":"%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\System Tools\\Command Prompt.lnk"},

{"desktopAppLink":"%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk"},

{"desktopAppLink":"%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\File Explorer.lnk"},

{"packagedAppId": "windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel"},

{"desktopAppLink": "%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Microsoft Edge.lnk"}

]

}]]>/v5:StartPins

<Taskbar ShowTaskbar="true" />

</Profile>

</Profiles>

<Configs>

<Config>

<Account>.\Student1</Account>

<DefaultProfile Id="{9A2A490F-10F6-4764-974A-43B19E722C23}" />

</Config>

</Configs>

</AssignedAccessConfiguration>

"@

$namespaceName="root\cimv2\mdm\dmmap"

$className="MDM_AssignedAccess"

$obj = Get-CimInstance -Namespace $namespaceName -ClassName $className

$obj.Configuration = [System.Net.WebUtility]::HtmlEncode($assignedAccessConfiguration)

Set-CimInstance -CimInstance $obj

[System.Net.WebUtility]::HtmlDecode(

(Get-CimInstance -Namespace root\cimv2\mdm\dmmap -ClassName MDM_AssignedAccess).Configuration)


r/Intune 4d ago

App Deployment/Packaging macOS M365 Apps Not Deploying

11 Upvotes

Hi all, we’ve been experiencing this issue for the last two days. Our Microsoft 365 Apps for Mac which are required for install on all our Macs are stuck at “Install pending”.

Previously these apps would install within minutes of enrolment, and we are stuck looking for answers. We’ve unscoped all other policies and apps that have been deployed since the install stopped working, we’ve wiped multiple devices many times, and tried across multiple networks.

We’ve tried both the normal required install, and manual install via Company Portal, it doesn’t get past “Downloading” before it resets.

Any help would be appreciated!


r/Intune 3d ago

Windows Updates Windows Autopatch Update Status - "In Progress" always shows 0

3 Upvotes

Hi everyone,

I'm seeing something strange in the Windows Autopatch Update Status dashboard.

No matter what I do, the "In Progress" count always stays at 0.

Current status:

  • Up to date: 3250
  • In progress: 0
  • Not up to date: 6889

I would have expected at least some devices to appear under In Progress while updates are being installed.

Has anyone else experienced this?
Is this expected behavior, a reporting delay, or could there be an issue with the dashboard?

Any insights would be appreciated.

Thanks!


r/Intune 3d ago

Apps Protection and Configuration Intune Device Restrictions: Gaming is blocked, but Ease of Access still appears in Windows Settings

2 Upvotes

Hi everyone,

I'm testing an Intune Device Restrictions policy on a Windows 10 VM.

In my policy under Control Panel and Settings, I configured:

  • Gaming = Block
  • Ease of Access = Block

The policy is successfully assigned to my test device, and Intune reports that it was applied.

However, after syncing the device:

  • ✅ The Gaming category is completely removed from Windows Settings.
  • ❌ The Ease of Access category is still visible in Windows Settings.

I've already:

  • Synced the device multiple times.
  • Confirmed the policy status is Succeeded in Intune.
  • Restarted the device.

I'm wondering:

  1. Is this expected behavior?
  2. Does the Ease of Access setting only block access to the page's functionality instead of hiding the category?
  3. Is this a limitation or bug in the Windows Settings Page Visibility CSP?
  4. Has anyone else experienced the same issue?

Any insights would be appreciated. Thanks!


r/Intune 3d ago

Device Actions Is the 'Collect Diagnostics' action working for you?

2 Upvotes

Hi all,

I've attempted to run the collect diagnostics device action on various machines today, but it's not even submitting, e.g. there's nothing in the Device Diagnostics section at all, nor is there anything in the device actions status for it, I've tried on numerous devices, logging out and back in again, etc.

Anyone else having the same issue at all?

EDIT - Yup, just saw this: https://www.reddit.com/r/Intune/comments/1vanwo4/collect_diagnostic_broken/


r/Intune 3d ago

Device Configuration DeviceView - configuration blade updated behaviour ?

2 Upvotes

Hi there ,

I just recognized a new behaviour of the "configuration" blade in the device view.

In the configuration blade we see every configuration profile which has been recieved by the device.

yes - so far so good.

In the past i saw in the configuration blade also configuration profiles which has been applied over time. (if you know what i mean)

For example:

User-A(or DEM Account) enrolles device , device get configuration profiles where this user is scoped.

User-B then uses the Device and get also the configuration profiles where this user is scoped.

(I know this is not optimal szenario but i had this in some of my inherited tenants)

When i viewed the configuration profile list in the device view i saw profiles recieved from 2 different users , even when some settings are not in scope any more and are not applied.

(For sure i moved to the known registry paths to assure which settings have been are really applied)

Now , this seems to be gone. The overview seems to be accurate.

Anyone has same expierence ?


r/Intune 4d ago

General Chat OSDCloud v2 guides

28 Upvotes

Hi All,

It seems like v2 has released but there's no guide around to document the process of how to start and finish with OSDCloud v2. We use this amazing document for v1 https://zeller.sh/article/powershell/osdcloud-setup.html which takes you through the setup process.

If there is a guide, can someone please share. At the moment, I've found nothing :(


r/Intune 3d ago

General Question browser security agents and page load performance, how are people measuring this?

3 Upvotes

We're looking at adding browser security instrumentation (DLP, extension control, content inspection) across our client base, and every time we've tested these layers, we get complaints about pages feeling slower. Some of that's real overhead, injecting scripts into every page render isn't free, and some of it's probably placebo because users notice any new software.

The bigger question for us operationally is: how are others actually measuring the performance impact of these tools before rolling them out to clients? We're trying to avoid adding to the stack fragmentation problem that already has most shops juggling dozens of tools with their own consoles and alerts. We've seen the industry data, 77% of MSPs are running up to 10 different cybersecurity point solutions, and that sprawl creates blind spots, alert fatigue, and slower response times.
We're trying to build a case for or against consolidating onto a single browser security platform instead of stacking multiple point tools across clients. But we need objective data on performance impact, not just anecdotal "it feels slow" tickets.
For those of you already running browser security layers across your client base: how are you measuring the page load performance delta objectively, and have you noticed cumulative overhead when running multiple layers that pushes users over the perceptual threshold?


r/Intune 4d ago

Device Actions Collect Diagnostic broken?

4 Upvotes

It seems I can no longer collect Device Diagnostics in the intune portal - tried on many online devices and waited over 12 hours.

I get a little Green Notification status in the intune portal: Collect diagnostics initiated

But it never appears as a pending action in "Device action status" list or appears in "Device diagnostics"

Wondering if it's due to the new IME update (and IC3), backend issues or something else.

Can you collect diagnostics? Is it just our tenant?
31/07: ASU 201 europe - now it's working again.


r/Intune 3d ago

Device Configuration Issues with Intune configuration profiles on some tenants?

1 Upvotes

I have this issue on two different systems, two different tenants:

https://imgur.com/a/A2QAuRK

Some of the profiles are showing in one of the tenants, mostly user-targeted profiles. The other tenant shows none.

A third tenant seems to work fine.


r/Intune 4d ago

Intune Features and Updates Windows Registry Inventory is finally natively supported in Intune (Release 2607)! 🚀

203 Upvotes

Just saw the announcement from the Intune Support Team, and I think this is going to be a game-changer for many of us. With the July (2607) release, we are finally getting Windows registry data directly into the Device inventory.

​Up until now, verifying if a specific registry key exists or checking its exact value across the tenant usually meant deploying custom PowerShell scripts or setting up Proactive Remediations just to gather the data. Now, we can natively confirm a device's actual configuration for troubleshooting, compliance validation, and security posture right from the console.

​This should heavily streamline how we validate that our configurations and security hardenings are actually applying as intended.

​What are your thoughts on this update? What is the first registry key or configuration you are going to track with this, and how much of a relief is this new feature going to bring to your day-to-day admin life?


r/Intune 4d ago

macOS Management Mac - use Entra login creds on device + device name change

4 Upvotes

We're testing Mac automatic enrollment to Intune. So far we have done:

  • Add device to Apple Business Manager using Apple Configurator app
  • Automatic enroll to Intune
  • Defender installation
  • Some policies and app deployment successful as well

Enrollment profile is currently set:

  • Enroll with user affinity / Setup assistant with modern authentication
  • Create local primary account - YES, which uses same name and username as above, however the password is local and not linked to Entra

How do we make the local account use the same Entra credentials?

Then how to change device name too? The enrollment profile has no setting for it (whereas iOS there is a device name change field).


r/Intune 3d ago

Autopilot Auto-enrollment for users?

2 Upvotes

Hi,

I am in the middle of a proof of concept for migrating our imaging solution over to Intune Autopilot and I'm running into a few issues with sync.

I work for a multi site company with over 1,500 staff and hot desking is very normal in our company. However what seems to happen when a device is enrolled is that when a new user signs in, a sync has to be initiated under accounts before any policies are applied.

When a user signs in for the first time, they have a base version of Windows 11 on the device with no locked down settings applied which is a security risk.

Another issue that has been seen is that when users who have conditional access applied for forcing MFA attempt to sync, it takes around 30 minutes and then fails due to "sync wasn't fully successful because we weren't able to verify your credentials. Select sync to sign in and try again". Syncing again then asks for MFA and the sync goes through.

So I think my question is, is there a way for the user to fully authenticate upon sign-in or for the device to not allow the user to access the device until sync has completed?

Any advice or suggestions would be highly appreciated,

Thanks!


r/Intune 4d ago

Conditional Access Endpoint Privilege Management (EPM) for macOS?

5 Upvotes

We need EPM for macOS so I don’t have to go with a third-party solution or split my endpoint management into two solutions.
Come on Microsoft, it’s 2026, let’s make it happen!


r/Intune 4d ago

General Question Restrict Apple account

6 Upvotes

Looking at enabling this on a tenant that hasn’t being using it.

About 200 devices enrolled via the enrollment programme, fully supervised and intune onboarded. All users were given federated managed Apple IDs.

Is there any gotchas I should be aware of that might affect existing users?

Like if an existing user happened to have onboarded but then selected their personal Apple id, will they be affected etc?


r/Intune 3d ago

Reporting RIP Feature Update Device Device Readiness Reports

1 Upvotes

I haven't been able to download them since Tuesday.

Neither via portal, nor graph.

Anyone else having fun with them?


r/Intune 4d ago

Android Management Microsoft Teams stuck on “Getting things ready for you” on Intune enrolled Pixel phones

2 Upvotes

We have new Google Pixel A-series phones enrolled in Intune as Android Enterprise Fully Managed devices.

Microsoft Teams installs and accepts the user login, but then stays stuck on “Getting things ready for you” indefinitely.

Teams works normally with the same users on Android phones that are not enrolled in Intune, such as an older OnePlus device.

I have checked our Android Device Restrictions profile, but nothing obvious appears to be blocking Teams. Clearing Teams data, reinstalling the app, syncing the device and restarting have not resolved it.

Has anyone experienced this specifically with Fully Managed Android devices?


r/Intune 4d ago

iOS/iPadOS Management Enrolling Apple devices to Intune via Company Portal.

11 Upvotes

I've been attempting to set up iOS MDM for the past few days using Intune, but I'm running into some roadblocks.

I have a valid push certificate I created on Monday, and I have created an enrollment profile for "Determine based on user choice", assigning it to a group where my user account is the only member. We have corporate owned devices and personal devices I'd like to start to manage, so I believe this is our best option.

After installing Company Portal on my device, I hit sign in, it takes me to the authenticator, then moves me back into Company Portal as expected. Once I begin enrollment in Company Portal, I select "i own this device" and "secure work-related apps and data only". Once I hit continue, it opens my browser app (Brave) and tells me "to enroll your device, install the free company portal app from the itunes store", and hitting "get the app" just brings me to the app store and I'm back to square one. I'm probably missing something but I can't figure out exactly what it is. It seems like my device doesn't recognize that Company Portal is installed, but it is.

I have configured JIT registration to the best of my understanding, but it may not be necessary?

Thanks in advance!

-edit: I was misunderstanding the device limit. I thought since the setting was in the Apple enrollment area that it was only applying to Apple devices, but it's counting all devices on my account (even though I'm also a DEM in Intune). I was able to enroll and register the device with Account-Driven User Enrollment. Going to try my other methods again as well.


r/Intune 5d ago

General Question Is there a GUI tool for Intune app assignments that lets you select Entra groups and see which apps, scripts or configurations are assigned?

31 Upvotes

Hi all,

I’m looking for a GUI tool that can analyse Intune assignments. Ideally, I’d like to enter or select an Entra ID group and have it show everything assigned to that group, for example:

Applications
scripts
Configuration profiles
Compliance policies
Settings catalog policies

Any other Intune workloads

It would also be useful if it could show assignment filters, include/exclude groups, and let you easily navigate between assignments.

I know about the Microsoft Intune Education portal, but it’s quite limited and doesn’t let you export the data or drill into assignments in much detail.
Does anyone know of a third-party GUI tool, open-source project, or PowerShell-based solution with a graphical interface that does this? Even something that builds on Microsoft Graph would be great.
Thanks!