<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[ITSpecialist.News | Riccardo Corna: ITSpecialist.News - Same Content, in English]]></title><description><![CDATA[A curated selection of my work, in English. Practical guides and strategies for adopting Microsoft Intune, Windows 365, Azure Virtual Desktop, and Microsoft Entra in a secure, modern, and effective way.
]]></description><link>https://www.itspecialist.news/s/english</link><image><url>https://substackcdn.com/image/fetch/$s_!i9bM!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e18c6e5-52e0-4daf-a28b-58913c923ffc_1280x1280.png</url><title>ITSpecialist.News | Riccardo Corna: ITSpecialist.News - Same Content, in English</title><link>https://www.itspecialist.news/s/english</link></image><generator>Substack</generator><lastBuildDate>Tue, 14 Apr 2026 20:16:38 GMT</lastBuildDate><atom:link href="https://www.itspecialist.news/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Riccardo Corna]]></copyright><language><![CDATA[it]]></language><webMaster><![CDATA[itspecialistnews@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[itspecialistnews@substack.com]]></itunes:email><itunes:name><![CDATA[Riccardo Corna]]></itunes:name></itunes:owner><itunes:author><![CDATA[Riccardo Corna]]></itunes:author><googleplay:owner><![CDATA[itspecialistnews@substack.com]]></googleplay:owner><googleplay:email><![CDATA[itspecialistnews@substack.com]]></googleplay:email><googleplay:author><![CDATA[Riccardo Corna]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Have you tried restarting? #11]]></title><description><![CDATA[Intune in a mystic crisis, Microsoft radar, community gems, a wave of events, nerd-friendly books and music, existential van life crisis.]]></description><link>https://www.itspecialist.news/p/have-you-tried-restarting-11</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-restarting-11</guid><pubDate>Thu, 09 Apr 2026 15:03:27 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b2f50e17-3e37-4e8f-9691-924ec4161ae0_1200x896.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>And here we are in April! Spring has arrived, bringing plenty of sunshine and vitamin D (my blood tests are grateful). The events season kicks off again in full force: for all the details on &#8220;where-I&#8217;ll-be-when&#8221;, refer to the dedicated section later in this email.</p><p>On another note, Italian-language articles from members of the Italian community are finally coming in more often (I was starting to get tired of always having to hunt down content from the usual foreign names).</p><p>Happy reading!</p><div><hr></div><h2 style="text-align: center;">&#9888;&#65039; Important!</h2><p style="text-align: center;">The ITSpecialist.News editorial offering has just expanded with a new English section, featuring a curated selection of my main articles.</p><p style="text-align: center;">Since most of these are the same contents available in both languages, you might prefer not to receive them twice.</p><p>If you&#8217;d like to receive updates only in your preferred language:<br>&#8594; Go to <a href="https://itspecialistnews.substack.com/account">itspecialistnews.substack.com/account</a><br>&#8594; Open the &#8220;Notifications&#8221; section<br>&#8594; If you&#8217;re an English reader, keep only <em>&#8220;ITSpecialist.News &#8211; Same Content, in English&#8221;</em> enabled and disable the others.<br>&#8594; If you&#8217;re an Italian reader, keep only <em>&#8220;ITSpecialist.News | Riccardo Corna&#8221;</em> enabled.</p><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LD18!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LD18!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LD18!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LD18!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LD18!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LD18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg" width="950" height="410" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:410,&quot;width&quot;:950,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/193084667?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LD18!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 424w, https://substackcdn.com/image/fetch/$s_!LD18!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 848w, https://substackcdn.com/image/fetch/$s_!LD18!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!LD18!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9b82dff0-971b-467a-a444-3a4f8a7b666c_950x410.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"></p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ITSpecialist.News &#10084;&#65039;&#128591;&#127995;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><ul><li><p><strong>FAQ&#8230; with style</strong>: <em>&#8220;Intune error event codes can be a bit cryptic at times. Where can I find a quick and easy reference list of Intune configuration profile error codes?&#8221;</em></p></li><li><p><strong>Microsoft News Radar</strong>: the latest straight from Microsoft sources.</p></li><li><p><strong>Community Picks</strong>: the most interesting community-created content this month.</p></li><li><p><strong>Events</strong>: Global Azure everywhere, plus the usual appointments and, even if we&#8217;re getting ahead of ourselves, AperiTeams Conference 2026.</p></li><li><p><strong>On a personal note</strong>: that&#8217;s it, I&#8217;ve made up my mind!</p></li></ul><div><hr></div><h2>&#10067; FAQ&#8230; with style</h2><h3>Question</h3><p><em>&#8221;Intune error event codes can be a bit cryptic at times. Where can I find a quick and easy reference list of Intune configuration profile error codes?&#8221;</em></p><h3>Answer</h3><p>Microsoft maintains official documentation dedicated to exactly this:</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/troubleshoot/mem/intune/general/troubleshoot-company-resource-access-problems">Error and status codes in Microsoft Intune</a>.</p><p>Here you&#8217;ll find a complete table of MDM error codes (iOS/iPadOS, Android, Windows) with descriptions and common causes &#8212; very handy when you&#8217;re staring at cryptic hex codes in device reports.</p><p>For errors specific to app installation (VPP, LOB), there&#8217;s also a dedicated page:</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/troubleshoot/mem/intune/app-management/app-install-error-codes">App installation error codes for Microsoft Intune</a>.</p><p>Bookmark both pages: they&#8217;re the first ones to check whenever a profile or app fails without a clear message!</p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>A curated selection of content straight from Microsoft sources.</p><ul><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/windows-365--intune-advanced-endpoint-management-capabilities-better-together/4503802">Windows 365 + Intune Advanced Endpoint Management Capabilities: Better Together</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/what&#8217;s-new-in-microsoft-intune-&#8211;-march/4493136">What&#8217;s new in Microsoft Intune &#8211; March</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/secure-apps-where-people-data-and-ai-intersect/4493201">Secure apps: Where people, data, and AI intersect</a></p></li></ul></li><li><p><strong>Surface IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/surfaceitpro/vibe-coding-for-the-npu/4497674">Vibe Coding for the NPU</a></p></li></ul></li><li><p><strong>Microsoft Defender for Endpoint</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/introducing-effective-settings-see-security-configurations-enforced-on-your-devi/4499551">Introducing effective settings: See security configurations enforced on your device</a></p></li></ul></li><li><p>Microsoft Entra</p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/evolving-identity-security-how-the-conditional-access-optimization-agent-helps-y/4488927">Evolving identity security: How the Conditional Access Optimization Agent helps you adapt</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/strengthen-identity-resilience-recover-with-confidence-using-microsoft-entra-bac/4462426">Strengthen identity resilience: Recover with confidence using Microsoft Entra Backup and Recovery</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/external-mfa-in-microsoft-entra-id-is-now-generally-available/4488926">External MFA in Microsoft Entra ID is now generally available</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>The most useful community content I've come across these past few weeks.</p><ul><li><p>&#128279; <strong><a href="https://www.ictpower.it/microsoft-365/winget-creare-app-win32-evergreen-con-microsoft-intune.htm">WinGet: building evergreen Win32 apps with Microsoft Intune</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/simonetermine/">Simone Termine</a><br><em>In the Intune world, WinGet and PowerShell come together to turn classic Win32 apps into evergreen objects that install, update, and uninstall based on the actual software state on the client. A concrete pattern, with scripts and logging included, to cut repetitive work without giving up enterprise-grade governance.</em></p></li><li><p>&#128279; <strong><a href="https://www.cloudcommunity.it/2026/03/windows-autopatch-guida-pratica-alla-reportistica-per-monitorare-aggiornamenti-readiness-e-anomalie/">Windows Autopatch: a practical guide to reporting for monitoring updates, readiness, and anomalies</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/davidesalsi/">Davide Salsi</a><br><em>A structured map of all Windows Autopatch reports in Intune: how to read dashboards, trends, and alerts to truly understand what&#8217;s happening with Quality and Feature Updates, measure readiness, spot anomalies, and turn patching from a technical task into a risk management tool.</em></p></li><li><p>&#128279; <strong><a href="https://www.ictpower.it/microsoft-365/windows-autopatch-quick-start-gli-aggiornamenti-si-fanno-da-soli-compreso-laddio-a-windows-10.htm">Windows Autopatch Quick Start: updates take care of themselves (including saying goodbye to Windows 10)</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/francescofacco/">Francesco Facco</a><br><em>A practical guide to turning update chaos into an automated flow managed by Intune and Windows Autopatch, from assessing eligibility for Windows 11 all the way to test, pilot, and production rings, with real-world advice on risk, timelines, monitoring, and user management.</em></p></li></ul><div><hr></div><h2>&#127917; Eventi e Call for Speaker</h2><p>Community and Microsoft events, plus the main open Calls for Speakers.</p><ul><li><p>&#127760; <strong><a href="https://globalazure.net/">Global Azure 2026</a></strong><br>&#128197; 13, 16&#8211;18 April 2026 &#8211; &#128187; Online and/or &#127757; In person<br><em>Global Azure 2026 is back: special days in April 2026 to share our passion for Microsoft Azure through technical sessions, inspiration, and networking. Here&#8217;s the list of Italian editions with links to their websites so you can find all the details you need.</em></p><ul><li><p><strong><a href="https://globalazuretorino.welol.it/">Global Azure Torino 2026</a></strong> (I&#8217;ll be there, as an attendee)</p></li><li><p><strong><a href="https://veneto.globalazure.it/">Global Azure Veneto 2026</a></strong> (I&#8217;ll be there, as an attendee)</p></li><li><p><strong><a href="https://globalazure2026pn.1nn0va.it/">Global Azure Pordenone 2026</a></strong></p></li><li><p><strong><a href="https://azure-meetup-puglia.github.io/">Global Azure Puglia 2026</a></strong></p></li><li><p><strong><a href="https://overnet.zohobackstage.eu/GlobalAzure2026Ticino#/">Global Azure Ticino 2026 (Switzerland)</a></strong> (I&#8217;ll be there, as a speaker)!</p></li><li><p><strong><a href="https://www.azuremeetupmilano.it/e/3814/Global-Azure-Milano-2026">Global Azure Milano 2026</a></strong></p></li></ul></li></ul><p>Details of my session at Global Azure Ticino 2026:</p><p>&#128187; <strong><a href="https://www.eventi.overnet.education/GlobalAzure2026Ticino#/agenda?day=1&amp;lang=it">SCEP It Easy With Intune Cloud PKI</a></strong><br>In this session, we&#8217;ll explore best practices for implementing the Simple Certificate Enrollment Protocol (SCEP) and integrating it with Intune to ensure secure, automated certificate deployment, comparing the pros and cons of an on-premises SCEP infrastructure versus an Intune Cloud PKI solution.</p><ul><li><p>&#8986; <strong><a href="https://www.youtube.com/watch?v=33P9dfT2nv0">BeConnected Hour</a></strong><br>&#128197; 30 April 2026 &#8211; &#128187; Online<br><em>Monthly update on what&#8217;s new in Microsoft 365, Teams, MTR, Purview, MDO, and Copilot, together with Luca Vitali, Fabrizio Volpe, and Raffaele Colavecchi.</em></p></li><li><p><strong><a href="https://www.aperiteams.it/AC2026/#agenda">AperiTeams Conference 2026</a></strong><br>&#128197; 24 June 2026 &#8211; &#128187; Online and &#127757; In person<br><em>A free one-day conference at the Microsoft House in Milan for IT professionals, focused on infrastructure, hybrid cloud, modern workplace, cybersecurity, and artificial intelligence, with technical sessions, demos, and networking, organized by Inside Technologies.</em></p></li></ul><h3>Call for Speaker</h3><p>Here are a few interesting Calls for Speakers.</p><ul><li><p><a href="https://my.runevents.net/auth/login?returnUrl=https:%2F%2Fe.runevents.net%2Fbeconnected-day-14%2Fspeakers">BeConnected Day 14</a></p></li></ul><h4>Disclaimer</h4><blockquote><p>The events I highlight in &#8220;Have you tried turning it off and on again?&#8221; are not meant to be a complete list: I only share those I personally come across and consider useful for the community. If an event is missing, it simply slipped past me or I wasn&#8217;t aware of it. If you&#8217;d like to flag yours, feel free to reach out. Publication is for informational purposes only and does not imply endorsement, approval, sponsorship, or partnership, unless explicitly stated otherwise.</p></blockquote><div><hr></div><h2>&#127911; On a personal note</h2><p>Outside the IT world, here&#8217;s what&#8217;s been inspiring me lately.</p><h3>&#128214; What I&#8217;m reading (books, newsletters, and more)</h3><ul><li><p><a href="https://open.substack.com/pub/orabuca/p/non-aprite-quella-parentesi?utm_campaign=post-expanded-share&amp;utm_medium=web">Non aprite quella parentesi</a></p></li><li><p><a href="https://substack.com/home/post/p-192705948">Il mercato del tradimento</a></p></li><li><p><a href="https://frankmerenda.substack.com/p/stamattina-8-miliardi-di-persone">Stamattina 8 miliardi di persone si sono svegliate volendo essere te. Tu ti sei svegliato vergognandoti</a></p></li></ul><h3>&#127925; What I&#8217;m listening to (this month&#8217;s musical obsessions) </h3><ul><li><p><a href="https://music.apple.com/it/album/ephemeral/970887924?i=970887927">Ephemeral / What We All Come to Need / Pelican</a></p></li><li><p><a href="https://music.apple.com/it/album/luminance-2025-remaster/1820238383?i=1820238384">Luminance / Creative Eclipses / Cave-In</a></p></li><li><p><a href="https://music.apple.com/it/album/wasting-time/1355665592?i=1355665596">Wasting Time / Vhs / Castlebeat</a></p></li></ul><h3>&#9997;&#65039; Random thoughts</h3><p><em>Folks, after years of fascination and binge-watching vanlife videos, I&#8217;ve decided: I&#8217;m renting a van for a weekend to see what it&#8217;s really like. I still need to pick the dates but, I swear, this time I&#8217;m actually doing it.</em></p><p>See you soon!</p><p>Riccardo</p><div><hr></div><blockquote><p><em>Some of the links on this site point to products or books sold by third parties. If you choose to make a purchase through these links, I may earn a commission as an affiliate, at no additional cost to you. This helps support the work I do and allows me to keep providing quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[A question that’s been stuck in my head for a while]]></title><description><![CDATA[I&#8217;ve got this idea stuck in my head: turning ITSpecialist.News into a global project in English. But what would that mean for you? I really want to hear your opinion.]]></description><link>https://www.itspecialist.news/p/a-question-thats-been-stuck-in-my</link><guid isPermaLink="false">https://www.itspecialist.news/p/a-question-thats-been-stuck-in-my</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Sat, 21 Mar 2026 10:46:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!i31W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A Saturday email from me? &#128558; Let&#8217;s get straight to the point, no beating around the bush. I&#8217;ve got something stuck in my head that keeps circling around. It&#8217;s the idea of completely transforming <strong><a href="http://itspecialist.news/">itspecialist.news</a></strong> into a more &#8220;global&#8221; project in English, with a view to a possible &#8220;FutureInWhichWhoKnowsWhereI&#8217;llBeWhatI&#8217;llDo&#8221; (even though, to be honest, that part for now feels quite far away).&#8203;</p><p>Short story.&#8203;</p><p>Regarding the Italian language, I&#8217;ve always chosen to use it as the main (and essentially only) language for my publications because I believe that, when you share knowledge, it&#8217;s right to do it &#8220;here and now&#8221; for the local community. There isn&#8217;t much more to add: I&#8217;ve been doing it since 2011 (the year of my very first blog) and I still do it today.&#8203;</p><p>Now let&#8217;s talk about English. I started publishing in English too in 2023, after my first MVP Summit. The idea was to connect somehow with the community outside of Italy as well. It didn&#8217;t work out because my main effort was still focused on Italian content: social posts, talks, events, and so on. English was just something extra that I had added in a rush of enthusiasm, but without any solid foundation behind it. After some time, I realized it was a pointless effort that only ate up time and energy. Today on Substack there is an English section with a few selected pieces of content and, above all, AI gives me a big hand with translations, saving me a lot of time. Has anything changed? No, pretty much nothing, apart from the effort I put into translating, which is definitely lower thanks to AI.&#8203;</p><p>So what? Maybe it&#8217;s a bit of a simple and &#8220;naively enthusiastic&#8221; thought, but every time I come back from an event like the recent Tech Connect 2026 in Seattle, where there are literally people from all over the world... I remember that there is a whole world out there. &#128515;&#8203;</p><p>You might think: &#8220;Well, no kidding!&#8221;. And you&#8217;d be right, but sometimes you need to have things right in front of your eyes to really become aware of them.&#8203;</p><p>So? All of this to say that I have this idea stuck in my head. The problem is that, in terms of effort, focus, time, and so on, I definitely wouldn&#8217;t be able to produce content in two languages with the same quality and intensity. Besides my job at Microsoft and the &#8220;IT Specialist&#8221; project (driven purely by passion and from which I don&#8217;t make a single euro), let&#8217;s just say I also like to have a life. &#128517;&#8203;</p><p><strong>What would a new project in English mean, according to what this idea is suggesting to me? It would definitely mean choosing just one of the two languages, not both.</strong>&#8203;</p><p>And this is where things become extremely difficult.&#8203;</p><p>I&#8217;ll think about it; in the meantime, I wanted to share this doubt that&#8217;s been nagging at me.&#8203;</p><p>Maybe this idea is just the beginning of something new&#8230; or maybe it will just go away on its own, like many other late&#8209;night ideas. &#128516;&#8203;</p><div class="pullquote"><p>As Ted Mosby would say: &#8220;Nothing good happens after 2 a.m.&#8221;&#8203;</p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i31W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i31W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i31W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i31W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i31W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i31W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg" width="736" height="370" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:370,&quot;width&quot;:736,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:157799,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/191662108?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!i31W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i31W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i31W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i31W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81580a4e-991d-4e28-a381-6f228b0cb422_736x370.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And probably even these kinds of ideas are born around that time.&#8203;</p><blockquote><p><strong>But there&#8217;s one question that really matters to me: if one day ITSpecialist.News used another language, would that change the way you follow it?&#8203;</strong></p></blockquote><p>Having some points of view on this would be important.&#8203;</p><div class="poll-embed" data-attrs="{&quot;id&quot;:481075}" data-component-name="PollToDOM"></div><p>Vote in the poll, and feel free to write to me here or in private to talk about it!&#8203;</p><p>See you soon,&#8203;</p><p>Rick</p>]]></content:encoded></item><item><title><![CDATA[Have you tried restarting? #10]]></title><description><![CDATA[Back from Seattle, Intune, and iOS: a March issue to reboot your brain after the jet lag.]]></description><link>https://www.itspecialist.news/p/have-you-tried-restarting-10</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-restarting-10</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 11 Mar 2026 06:59:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!T3_-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15022861-3a85-4e62-b7ac-6d16028d766c.heic" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi! Back from Seattle, wrecked by jet lag but happy. Tech Connect is one of those events where you really see the global scale of a company like Microsoft. It's one thing to know you have thousands of colleagues scattered around the world, but seeing them in person is a whole different story! I&#8217;m bringing home plenty of interesting insights on technical content, lots of little techniques to 'steal' as a speaker, and above all, the experience of sharing something with colleagues that goes beyond calls and the office. Honestly, we could use a week like this every year!</p><p></p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/heic&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15022861-3a85-4e62-b7ac-6d16028d766c.heic&quot;},{&quot;type&quot;:&quot;image/heic&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4ca080d7-17d1-40ff-84a9-728be7f91188.heic&quot;},{&quot;type&quot;:&quot;image/heic&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71df9dd0-010d-4ed4-b6ec-33cb499aa79a.heic&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/png&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/548aef42-0c4a-4dfd-83c0-b330b658fa22_1456x474.png&quot;}},&quot;isEditorNode&quot;:true}"></div><p>Anyway, moving on: the next big event is Global Azure, you'll find all the details below. As for the rest, you'll find the usual tasty FAQs and plenty of useful official Microsoft resources.</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ITSpecialist.News &#10084;&#65039;&#128591;&#127995;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><ul><li><p><strong>FAQ&#8230; but with style</strong>: &#8220;<em>How can I find the Bundle ID of an iOS app available on the App Store?</em>&#8221;</p></li><li><p><strong>Microsoft News Radar</strong>: updates directly from Microsoft sources.</p></li><li><p><strong>Community Picks</strong>: the most interesting content created by the community this month.</p></li><li><p><strong>Events</strong>: Global Azure everywhere, plus the other usual appointments.</p></li><li><p><strong>On a personal note</strong>: winter restlessness as soon as the days get nicer and warmer.</p></li></ul><div><hr></div><h2>&#10067; FAQ&#8230; but with style</h2><h3>Question</h3><p><em>&#8220;How can I find the Bundle ID of an iOS app available on the App Store?&#8221;</em></p><h3>Answer</h3><p>It&#8217;s not possible to search directly for Bundle IDs within the Apple App Store. However, you can find it by accessing a specific file associated with your app or by using an online method.</p><p>If the app is already published on the App Store, proceed as follows:</p><ol><li><p>Find the app&#8217;s web page on the App Store (for example, by searching for the corresponding link).</p><ol><li><p>Example: <strong>Apple Pages</strong>, whose URL is <a href="https://apps.apple.com/us/app/pages-crea-documenti/id**361309726">https://apps.apple.com/us/app/pages-crea-documenti/id</a><strong><a href="https://apps.apple.com/us/app/pages-crea-documenti/id**361309726">361309726</a></strong></p></li></ol></li><li><p>Copy the number following the letters id in the URL. In the example given, the number is <strong>361309726</strong>.</p></li><li><p>Open the address <strong><a href="https://itunes.apple.com/lookup?id=361309726">https://itunes.apple.com/lookup?id=361309726</a></strong> in your browser, replacing the number with the one for your app.</p></li><li><p>In the displayed output, look for the bundleId field. In the example, it appears like this: <em>&#8220;bundleId&#8221;:&#8221;com.apple.Pages&#8221;</em>. Therefore, the app&#8217;s Bundle ID is <strong>com.apple.Pages</strong>.</p></li></ol><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/apps/get-app-bundle-id-intune-admin-center">Get App Bundle ID - Microsoft Intune</a></p><p>&#128206; <a href="https://support.apple.com/guide/deployment/bundle-ids-for-iphone-and-ipad-apple-apps-depece748c41/web">Bundle IDs for iPhone and iPad Apple apps</a></p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>A selection of content directly from Microsoft sources.</p><ul><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-%e2%80%93-february/4488307">What&#8217;s New in Microsoft Intune &#8211; February</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/protect-browser-based-work-on-agency-managed-windows-pcs/4496538">Protect browser-based work on agency-managed Windows PCs</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/admin-tasks-in-microsoft-intune-centralized-control-today-ai-ready-for-tomorrow/4489448">Admin tasks in Microsoft Intune: Centralized control today, AI-ready for tomorrow</a></p></li></ul></li><li><p><strong>Windows IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/what-to-know-about-windows-11-version-26h1/4491941">What to know about Windows 11, version 26H1</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/plan-for-windows-server-2016-and-windows-10-2016-ltsb-end-of-support/4496136">Plan for Windows Server 2016 and Windows 10 2016 LTSB end of support</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-first-sign-in-restore-experience-now-available/4495551">Windows first sign-in restore experience now available</a></p></li></ul></li><li><p><strong>Microsoft Defender for Endpoint</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/introducing-library-management-in-microsoft-defender/4494434">Introducing library management in Microsoft Defender</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>The most useful community content I stumbled upon in recent weeks.</p><ul><li><p>&#128279; <strong><a href="https://www.ictpower.it/cloud/microsoft-intune-dynamic-groups-con-microsoft-graph-e-powershell.htm">Microsoft Intune: dynamic groups with Microsoft Graph and PowerShell</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/simonetermine/">Simone Termine</a><br><em>The article explains how to use PowerShell and Microsoft Graph to create custom Dynamic Groups using extensionAttributes. It also includes a demo showing step-by-step how to intervene on Entra, Intune, and PowerShell, as well as how to rollback custom attributes and troubleshooting procedures.</em></p><p></p></li><li><p>&#128279; <strong><a href="https://www.tbone.se/2026/02/20/the-unexpected-enrollment-how-personal-windows-home-devices-slipped-into-intune-and-how-you-can-finally-block-them/?utm_source=substack&amp;utm_medium=email">The Unexpected Enrollment: How Personal Windows Home Devices Slipped into Intune and How You Can Finally Block Them</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/mrtbone/overlay/about-this-profile/">T-Bone Granheden</a><br><em>In this piece, T-Bone shows how personal Windows Home PCs still manage to end up in Intune via the &#8220;Allow my organization to manage my device&#8221; flow when the user adds their work account in apps like Outlook/Teams. He also explains how to plug the hole using the new &#8220;Disable MDM enrollment when adding work or school account on Windows&#8221; setting, with practical details on the portal, Graph, limits, and impact on BYOD and SSO. It&#8217;s very useful if you need to tidy up personal and corporate devices without breaking the user experience.</em></p><p></p></li><li><p>&#128279; <strong><a href="https://skiptotheendpoint.co.uk/intune-administrator-is-the-new-domain-admin/?utm_source=substack&amp;utm_medium=email">Intune Administrator Is the New Domain Admin</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/skiptotheendpoint/?utm_source=substack&amp;utm_medium=email">James Robinson</a><br><em>An Intune Administrator can cause damage comparable to a Domain Admin. The article addresses real risks (mass code execution, insecure configurations, loss of segregation of duties) and how to mitigate them with RBAC, scope tags, and MAA.</em></p></li></ul><div><hr></div><h2>&#127917; Events and Call for Speakers</h2><p>Community and Microsoft events, plus the main open Call 4 Speakers.</p><ul><li><p>&#8986; <strong><a href="https://www.youtube.com/@BeConnectedday/">BeConnected Hour</a></strong><br>&#128197; March 25, 2026 - &#128187; Online<br><em>Monthly update on news from the world of Microsoft 365, Teams, MTR, Purview, MDO, and Copilot, together with Luca Vitali, Fabrizio Volpe, and Raffaele Colavecchi.</em></p><p></p></li><li><p>&#127760; <strong><a href="https://globalazure.net/">Global Azure 2026</a></strong><br>&#128197; April 13, 16-18, 2026 - &#128187; Online and/or &#127757; In-person<br><em>Global Azure 2026 returns: special days in April 2026 to experience together the passion for Microsoft Azure through technical sessions, inspiration, and networking. Here is the list of the Italian instances with the relative link to each website, so you can get all the necessary information. The list is partial and I will update it as the websites become available.</em></p><ul><li><p><strong><a href="https://globalazuretorino.welol.it/">Global Azure Torino 2026</a></strong></p></li><li><p><strong><a href="https://veneto.globalazure.it/">Global Azure Veneto 2026</a></strong></p></li><li><p><strong><a href="https://globalazure2026pn.1nn0va.it/">Global Azure Pordenone 2026</a></strong></p></li><li><p><strong><a href="https://azure-meetup-puglia.github.io/">Global Azure Puglia 2026</a></strong></p></li><li><p><strong><a href="https://overnet.zohobackstage.eu/GlobalAzure2026Ticino#/">Global Azure Ticino 2026 (Switzerland)</a></strong></p></li><li><p><strong><a href="https://www.azuremeetupmilano.it/e/3814/Global-Azure-Milano-2026">Global Azure Milano 2026</a></strong></p></li></ul></li></ul><blockquote><p><strong>Disclaimer</strong><br>The events I point out in &#8220;Have you tried restarting?&#8221; are not an exhaustive list: I share the ones I personally intercept and find useful for the community. If an event is missing, it simply slipped by me or I wasn&#8217;t aware of it: if you want to point yours out to me, write me. The publication is for informational purposes and does not imply endorsement, approval, sponsorship, or partnership, unless explicitly stated otherwise.</p></blockquote><div><hr></div><h2>&#127911; On a personal note</h2><p>Outside the IT world, here is what&#8217;s been inspiring me lately.</p><h3>&#128214; What I&#8217;m reading (books, newsletters, and various things)</h3><ul><li><p><a href="https://maranga9000.substack.com/p/il-patetico-spezzone-delle-papere?utm_source=%2Finbox&amp;utm_medium=reader2">Il patetico spezzone delle papere AI di Sanremo</a></p></li><li><p><a href="https://fabiosabatini.substack.com/p/il-lento-suicidio-della-russia-in?utm_source=%2Finbox&amp;utm_medium=reader2">Il lento suicidio della Russia in Ucraina</a></p></li><li><p><a href="https://scrollinginfinito.substack.com/p/sui-social-non-devi-essere-te-stesso?utm_source=%2Finbox&amp;utm_medium=reader2">Sui social non devi essere te stesso</a></p></li></ul><h3>&#127925; What I&#8217;m listening to (musical fixations of the month)</h3><ul><li><p><a href="https://music.apple.com/it/album/dumb/1413920644?i=1413921581">Dumb / Nirvana / Nirvana</a></p></li><li><p><a href="https://music.apple.com/it/album/descending/1475686696?i=1475687061">Descending / Fear Inoculum / Tool</a></p></li><li><p><a href="https://music.apple.com/it/album/helitrope/1440917565?i=1440917820">Heliotrope / Vaya / At The Drive-In</a></p></li></ul><h3>&#9997;&#65039; Random thoughts</h3><p><em>Craving the sun, spring, the sea, craving to be outside the walls of my home and office, craving to travel.</em></p><p>See you soon!</p><p>Riccardo</p><div><hr></div><blockquote><p><em>Some of the links on this site point to products or books sold by third parties. If you decide to purchase through these links, I may receive an affiliate commission at no extra cost to you. This supports the work I do and allows me to continue offering quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[How to Hide Apps on iOS/iPadOS with Microsoft Intune]]></title><description><![CDATA[Watch now | Eliminate distractions from corporate iOS devices. Use Bundle IDs and Microsoft Intune to hide native and third&#8209;party apps on supervised devices.]]></description><link>https://www.itspecialist.news/p/how-to-hide-apps-on-iosipados-with-microsoft-intune</link><guid isPermaLink="false">https://www.itspecialist.news/p/how-to-hide-apps-on-iosipados-with-microsoft-intune</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 25 Feb 2026 06:59:21 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/186425502/2e8ffd845532af7b88e424e14891a734.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hi IT specialists! Today we&#8217;re looking at a configuration that&#8217;s highly requested in both enterprise and education environments: how to hide specific apps on managed iPhones and iPads. The goal is often twofold: blocking access to non-essential features and removing potential distractions for end users.</p><div><hr></div><h2>&#128240; What do you prefer? Video or article?</h2><p>A few notes to help you get the most out of this content.</p><p><strong>If you prefer to watch the full video, easy</strong>: you&#8217;ll find it right above in the header.</p><p><strong>If you prefer reading, that&#8217;s just as easy</strong>: keep scrolling here. For each step I&#8217;ve embedded the specific video segment, so you&#8217;ll only see the screens you care about, without my talking head in the way.</p><p>Either way, subscribe to the newsletter to make sure you never miss a new tutorial.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>OK, let&#8217;s go!</p><div><hr></div><h2>Disclaimer</h2><p>Before we dive into the actual configuration, a key disclaimer: this policy only works on <strong>Supervised</strong> devices.<br>This means devices must be enrolled in Intune via <strong>Apple Business Manager (ABM)</strong> using an <strong>Automatic Device Enrollment (ADE)</strong> profile. If you are managing manually enrolled devices or a BYOD scenario, this procedure will have no effect.</p><p>With that out of the way, let&#8217;s jump into the Intune portal and start &#8220;operating&#8221;! &#128518;</p><h2>Retrieving Bundle IDs for System Apps</h2><p>To hide an app, Intune needs its <strong>Bundle ID</strong>, a unique string that identifies the application within the operating system. In this article we&#8217;ll focus on two native apps that IT admins often want to remove from users&#8217; view: <strong>Freeform</strong> and <strong>Games</strong>.</p><p>Fortunately, Apple gives us an official resource. There is an Apple Support page that&#8217;s a real gold mine for us admins: it lists all the Bundle IDs of the native apps preinstalled on iOS and iPadOS, ready to be copied.</p><p>Here&#8217;s the link to the support page:</p><ul><li><p><a href="https://support.apple.com/it-it/guide/deployment/depece748c41/web">ID pacchetto per app Apple per iPhone e iPad</a></p></li></ul><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;abd415c6-a11a-4638-92b2-09c7ad904bc2&quot;,&quot;duration&quot;:null}"></div><h2>Creating the Policy in Intune</h2><p>Once you have collected the required IDs, move over to the Microsoft Intune portal to create the actual configuration. To achieve the result, we&#8217;ll use an iOS/iPadOS-specific <strong>Device Restrictions</strong> profile (or alternatively the <strong>Settings Catalog</strong>).</p><p>One small but important technical detail: even though the Intune portal lets you hide apps by simply entering the App Store URL, I personally always prefer to use the <strong>Bundle ID</strong>.</p><p>So let&#8217;s go ahead and paste in the strings we gathered in the previous step.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;6e75c697-e4ad-4d6e-ab7c-450fa0fe32c0&quot;,&quot;duration&quot;:null}"></div><h2>The trick for third&#8209;party app Bundle IDs</h2><p>We&#8217;ve seen how to handle Apple&#8217;s native apps, but what if you want to hide a third&#8209;party app (for example a social network or a messaging app)?<br>In this case Apple does not provide a handy list like it does for system apps. However, there is a very quick &#8220;trick&#8221; to get the Bundle ID starting from the App Store web page.</p><p>The method is to search for the desired app on the web version of the App Store, identify the numeric ID in the page URL, and use it (via a specific query or free online tools) to obtain the exact Bundle ID to add to your policy.</p><p>Here is the link where you &#8220;append&#8221; the app&#8217;s numeric code so you can retrieve the text file and extract the Bundle ID (you can see the exact procedure in the video below).</p><ul><li><p><strong>https://itunes.apple.com/lookup?id=</strong><em><strong>&lt;qui il codice&gt;</strong></em></p></li></ul><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;905693fa-09a0-4264-9d0c-71b05f7f2a7d&quot;,&quot;duration&quot;:null}"></div><h2>Final Result on the Device</h2><p>After applying the policy and waiting for the device to sync, it&#8217;s time to verify the result.<br>As you can see in the video below, when scrolling through the App Library and the Home Screen on our test iPhone, the Freeform and Games icons have disappeared. It&#8217;s important to note that the apps are still technically installed on the system, but they&#8217;ve been made completely inaccessible and invisible to the user.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;93ed59a5-5f67-4624-88dc-f2c934b7f12f&quot;,&quot;duration&quot;:null}"></div><h2>Documentation</h2><p>For anyone who wants to dig into every single technical detail, below you&#8217;ll find what I&#8217;d call an <strong>absurd</strong> amount of documentation (yes, mandatory quote &#128518;).</p><ul><li><p><a href="https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-ios">iOS/iPadOS device restrictions in Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/mem/intune/configuration/bundle-ids-built-in-ios-apps">iOS/iPadOS Bundle IDs for built-in apps</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/mem/intune/enrollment/device-supervised-mode">iOS/iPadOS supervised mode with Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/mem/intune/configuration/ios-device-features-settings">iOS/iPadOS device feature settings in Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/mem/intune/apps/get-app-bundle-id-intune-admin-center">Get App Bundle ID from Intune admin center</a></p></li></ul><p>Make sure you <strong>study it</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n4qp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n4qp!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 424w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 848w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 1272w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n4qp!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif" width="480" height="344" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:344,&quot;width&quot;:480,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!n4qp!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 424w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 848w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 1272w, https://substackcdn.com/image/fetch/$s_!n4qp!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1406c016-f82e-42d4-af0f-f0e9c8f36bf5_480x344.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">STUDYYYY</figcaption></figure></div><h2>Conclusions</h2><p>We&#8217;ve seen how to clean up the interface of our corporate devices by hiding everything that isn&#8217;t strictly necessary for day&#8209;to&#8209;day work.</p><p>If you found this article useful, subscribe to the <strong>ITSpecialist.News</strong> newsletter so you don&#8217;t miss upcoming deep dives into the Microsoft Enterprise world.</p><p>See you next time!</p><p>Rick</p>]]></content:encoded></item><item><title><![CDATA[Have you tried restarting? #9]]></title><description><![CDATA[February with Intune, tech events and dreams of ubiquity: tough FAQs, in love with Seattle, Global Azure and me trying to clone myself to be everywhere.]]></description><link>https://www.itspecialist.news/p/have-you-tried-restarting-9</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-restarting-9</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 11 Feb 2026 06:59:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e7cb7924-7984-4bf7-a3e5-2be5eff75161_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi and welcome back! February is usually the month to plan which events to attend in the &#8220;spring&#8221; season. The same thing is happening to me this year: I started out firmly intending to attend fewer events but now that I see them all on my calendar, I&#8217;m seriously wavering. &#128518; It&#8217;s always painful to skip some of them but, unfortunately, not even AI can make me ubiquitous.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rA2n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rA2n!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 424w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 848w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 1272w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rA2n!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif" width="444" height="250" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:250,&quot;width&quot;:444,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rA2n!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 424w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 848w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 1272w, https://substackcdn.com/image/fetch/$s_!rA2n!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5572ea7d-ceb8-4a30-ac5c-539d8e472133_444x250.gif 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Me, unable to wrap my head around how many events there are to attend.</figcaption></figure></div><p>As soon as I&#8217;ve decided how to plan this &#8220;spring season&#8221; of events, you&#8217;ll of course hear about it here. I hope to see you there and, as always, happy reading!</p><p>Rick</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ITSpecialist.News &#10084;&#65039;&#128591;&#127995;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><ul><li><p><strong>FAQ&#8230; with style</strong>: <em>&#8220;When an Intune admin is limited by a specific scope tag and reviews Endpoint Privilege Management elevation requests, what do they see? Only requests within their scope tag or all tenant requests?&#8221;</em></p></li><li><p><strong>Microsoft News Radar</strong>: updates straight from official Microsoft sources.</p></li><li><p><strong>Community Picks</strong>: the most interesting community content from this month.</p></li><li><p><strong>Events</strong>: things are starting to move again for the upcoming event season.</p></li><li><p><strong>On a personal note</strong>: I&#8217;m a Seattleite.</p></li></ul><div><hr></div><h2>&#10067; FAQ&#8230; with style</h2><h3>Question</h3><p><em>&#8220;When an Intune admin is limited by a specific scope tag and reviews Endpoint Privilege Management elevation requests, what do they see? Only requests within their scope tag or all tenant requests?&#8221;</em></p><h3>Answer</h3><p>With the update released in the week of November 10, 2025 (Service Release 2511), Microsoft implemented scope tag enforcement for Endpoint Privilege Management elevation requests.</p><h4>Before this update</h4><p>Admins with permissions to manage elevation requests could see all tenant requests, regardless of the scope tags assigned.</p><h4>After the update</h4><p>Scope tag enforcement is now active: admins can view and manage only the requests related to devices and users that fall within the scope of their assigned scope tag. This change helps maintain administrative boundaries and strengthens security by aligning Endpoint Privilege Management with Zero Trust principles and reducing unnecessary visibility into devices and users outside their area of responsibility.</p><p>In short: if an admin is assigned the &#8220;Italy&#8221; scope tag, they will only see elevation requests coming from devices and users tagged with &#8220;Italy&#8221;, ensuring more granular and secure permission management.</p><p>As always, I&#8217;ll leave you with the comfort of the official documentation for further reading.</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new#scope-tag-enforcement-for-endpoint-privilege-management-elevation-requests">Scope tag enforcement for Endpoint Privilege Management elevation requests</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/protect/epm-support-approved#about-support-approved-elevations">About support approved elevations</a></p><p>&#128206; <a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-december-2025/4476486">What&#8217;s new in Microsoft Intune: December 2025</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/scope-tags">Use role-based access control (RBAC) and scope tags for distributed IT</a></p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>A selection of content directly from official Microsoft sources: tons of new features were announced at Ignite.</p><ul><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new">What's new in Microsoft Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new#notices">Microsoft Intune - Important Notices</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/intune-service-servicing-information">Microsoft Intune servicing information and details</a></p></li></ul></li><li><p><strong>Windows IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/announcing-hardware-accelerated-bitlocker/4474609">Announcing hardware-accelerated BitLocker</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-news-you-can-use-december-2025/4473277">Windows news you can use: December 2025</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-skilling-snacks-bite-sized-technical-learning/4478464">Windows skilling snacks: bite-sized learning for IT pros</a></p></li></ul></li><li><p><strong>Microsoft Entra</strong></p><ul><li><p><a href="https://learn.microsoft.com/en-us/entra/architecture/road-to-the-cloud-ad-minimization">Road to the cloud - Case studies to reduce your dependency on traditional on-premises Active Directory services - Microsoft Entra</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>The most useful community content I&#8217;ve come across over the past few weeks.</p><ul><li><p><strong>&#128279; <a href="https://www.windowserver.it/2026/01/active-directory-le-best-practice-da-seguire/">Active Directory: le best practice da seguire</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/silviodibenedetto/?locale=it_IT">Silvio Di Benedetto</a><br><em>A practical guide to making Active Directory resilient: least&#8209;privilege access, clear role separation, a well&#8209;disciplined Tier Model, local passwords managed with LAPS, and thoughtful KRBTGT key rotation. It&#8217;s well worth reading because it provides concrete criteria to prevent compromise and strengthen your entire infrastructure.<br></em></p></li><li><p><strong>&#128279; <a href="https://www.ictpower.it/cloud/come-utilizzare-uno-script-powershell-come-installer-type-per-le-app-win32-in-microsoft-intune.htm">Come utilizzare uno script PowerShell come installer type per le app Win32 in Microsoft Intune</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/simonetermine/">Simone Termine</a><br><em>The article explains a new feature from January 2026: how to use PowerShell as an &#8220;installer type&#8221; to handle prerequisites, logging and post-config, without repackaging .intunewin every time. It includes examples and practical tips on detection, return codes and troubleshooting.<br></em></p></li><li><p><strong>&#128279; <a href="https://www.linkedin.com/pulse/automated-windows-autopilot-weekly-reporting-azure-logic-colella-ur8cf/?trackingId=2eo8Vz3yTcuTovlRmvFdmg%3D%3D">Automated Windows Autopilot Weekly Reporting with Azure Logic Apps &#128202;</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/simone-colella-96953a211/">Simone Colella</a><br><em>How to automate a weekly Windows Autopilot report with Azure Logic Apps and Microsoft Graph, sending the Service Desk emails with KPIs and detailed CSVs. It&#8217;s interesting because it turns raw logs into ready-to-use metrics, enabling proactive monitoring, failure analysis and optimization of Autopilot deployments.</em><br></p></li></ul><div><hr></div><h2>&#127917; Events and Call for Speaker</h2><p>Community and Microsoft events, plus the main open Calls for Speakers.</p><ul><li><p>&#127760; <strong><a href="https://globalazure.net/">Global Azure 2026</a><br></strong>&#128197; 13, 16-18 April 2026 - &#128187; Online e/o &#127757; In presence<br><em>Global Azure 2026 is back: special days in April 2026 to share a passion for Microsoft Azure through technical sessions, inspiration and networking. Here&#8217;s a list of the Italian events with links to their websites so you can find all the details you need. <strong>The list is partial and I&#8217;ll update it as new sites go live.</strong></em></p><ul><li><p><strong><a href="https://globalazuretorino.welol.it/">Global Azure Torino 2026</a></strong></p></li><li><p><strong><a href="https://veneto.globalazure.it/">Global Azure Veneto 2026</a></strong></p></li><li><p><strong><a href="https://azure-meetup-puglia.github.io/">Global Azure Puglia 2026</a></strong></p></li></ul></li></ul><p>Even though there&#8217;s still some time to go (the event will take place in April), most of the Calls for Speakers are already closed. Below are the ones still open as of today (11 February 2026).</p><ul><li><p>&#127760; <strong><a href="https://sessionize.com/globalazure2026pn/">Call for Speaker: Global Azure Pordenone 2026</a></strong></p></li></ul><h4>Disclaimer</h4><blockquote><p>The events I feature in &#8220;Have you tried restarting?&#8221; are not meant to be a complete list: I share the ones I personally come across and consider useful for the community. If an event is missing, it simply slipped past me or I wasn&#8217;t aware of it; <strong>if you&#8217;d like to highlight yours, just reach out</strong>. Publication is for informational purposes only and does not imply endorsement, approval, sponsorship or partnership, unless explicitly stated otherwise.</p></blockquote><div><hr></div><h2>&#127911; On a personal note</h2><p>Outside the IT world, here&#8217;s what&#8217;s been inspiring me lately.</p><h3>&#128214; What I&#8217;m reading (books, newsletters)</h3><h4>Books</h4><ul><li><p>This month, no books on my list yet, but I&#8217;m on the hunt for inspiration&#8212;if you have any recommendations, I&#8217;m all ears!</p></li></ul><h4>Newsletter</h4><ul><li><p><a href="https://danielaamenta.substack.com/p/crans-montana-e-il-gioco-dei-26-cantoni">Crans Montana e il gioco dei 26 Cantoni / Daniela Amenta</a></p></li><li><p><a href="https://frankmerenda.substack.com/p/fatturi-fai-utili-e-fallisci-lo-stesso">Fatturi, fai utili e fallisci lo stesso / Frank Merenda</a></p></li><li><p><a href="https://day1one.substack.com/p/french-touch">French -Touch! / Mattia Ravanelli</a></p></li></ul><h3>&#127925; What I&#8217;m listening to (this month&#8217;s earworms).</h3><ul><li><p>&#8206;<a href="https://music.apple.com/it/album/ex-lion-tamer-2006-remastered-version/1328682500?i=1328682916">Ex Lion Tamer / Pink Flag / Wire</a></p></li><li><p><a href="https://music.apple.com/it/album/stay/1789586115?i=1789586118">Stay / Diving For A Prize / Sea Lemon</a></p></li><li><p><a href="https://music.apple.com/it/album/crystals-feat-benjamin-gibbard/1789586115?i=1789586402">Crystals (feat. Benjamin Gibbard) / Diving For A prize / Sea Lemon</a></p></li></ul><h3>&#9997;&#65039; Scattered thoughts.</h3><p><em>Seattle here we go! This month I&#8217;ll be visiting Seattle, a city I&#8217;m returning to for the fourth time: at this point I can almost call myself a &#8220;Seattleite&#8221; and I&#8217;m really starting to grow fond of the place. A little trip to break up the routine (which has been exactly the same for the past few months) was just what I needed.</em></p><p>See you soon!</p><p>Riccardo</p><div><hr></div><blockquote><p><em>Some of the links on this site point to products or books sold by third parties. If you decide to purchase through these links, I may earn a commission as an affiliate, at no additional cost to you. This supports the work I do and allows me to keep offering quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[Remove Preinstalled Windows 11 Apps with Intune (No Scripts)]]></title><description><![CDATA[Watch now | Step-by-step guide: remove Windows 11 default apps (Xbox, Solitaire, etc.) via Intune with RemoveDefaultMicrosoftStorePackages.]]></description><link>https://www.itspecialist.news/p/remove-preinstalled-windows-11-apps-with-microsoft-intune-and-no-scripts</link><guid isPermaLink="false">https://www.itspecialist.news/p/remove-preinstalled-windows-11-apps-with-microsoft-intune-and-no-scripts</guid><pubDate>Wed, 28 Jan 2026 07:00:26 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/182782700/ea513f28c94d8f7f8856fb6181d36cec.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Welcome back to ITSpecialist.News! Today we&#8217;re talking about a very &#8220;IT admin-friendly&#8221; feature to clean up Windows 11 25H2 machines managed with Intune, removing preinstalled apps (Xbox, Solitaire, etc.) in a supported and native way using the RemoveDefaultMicrosoftStorePackages setting.</p><div><hr></div><h2>&#128240; Video or article? What do you prefer?</h2><p>Some notes to make the most of this content.</p><p><strong>If you prefer watching the full video</strong>, easy: find it above in the header.</p><p><strong>If you prefer reading, also easy</strong>: keep reading here. For each step, I&#8217;ve inserted the specific video clip, so you&#8217;ll only see the screens that interest you, without my face talking.</p><p>Either way, subscribe to the newsletter to make sure you don&#8217;t miss any new tutorial releases.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>Perfect, let&#8217;s get started!</p><div><hr></div><h2>What are preinstalled apps?</h2><p>When talking about &#8220;preinstalled apps,&#8221; we mean the Microsoft Store in-box apps that Windows 11 provides by default (those you already find ready in Start and the Installed apps list).</p><p>They&#8217;re convenient in consumer scenarios, but in enterprise environments they&#8217;re often just noise: they increase user confusion, generate avoidable tickets, and complicate base image standardization.</p><h2>Approach</h2><p>The approach is: create a configuration profile in Intune&#8217;s Settings Catalog, enable &#8220;<strong>Remove default Microsoft Store packages from the system</strong>,&#8221; and set to <strong>True</strong> the apps you want to remove.</p><p>Enforcement happens during specific events like OOBE/provisioning or user sign-in after upgrade/policy update, so it&#8217;s normal not to see &#8220;instant&#8221; results.</p><h2>Requirements</h2><p>To use the RemoveDefaultMicrosoftStorePackages setting, you need precise OS/edition prerequisites:</p><ul><li><p>The feature is designed for Windows 11 Enterprise/Education</p></li><li><p>Requires Windows 11 version 25H2 (or later)</p></li><li><p>The PC must be managed by Microsoft Intune</p></li><li><p>Does not support multi-session environments</p></li></ul><h2>Important note 1: not a &#8220;universal&#8221; anti-bloatware</h2><p>With this configuration, you remove only the Microsoft &#8220;in-box&#8221; default apps listed in the policy, not any third-party bloatware (OEM, trials, &#8220;exotic&#8221; stuff).</p><p>For those, continue using custom scripts (PowerShell) or Remediations/Proactive Remediations via Intune, as per tradition.</p><h2>Important note 2: policy application timing and scenarios</h2><p>The policy activates in specific situations, so if you expect apps to disappear instantly on an existing machine with an already-created user profile, listen carefully to what I&#8217;m about to say.</p><p>Here are the situations where the policy activates:</p><ul><li><p>Out-of-box experience (OOBE)</p></li><li><p>User login after an OS upgrade</p></li><li><p>User login after a policy change</p></li></ul><p>This means removal is guaranteed on new user profiles created on the machine after policy application, while for existing ones, you need at least logoff-logon a few hours after policy creation.</p><p>Perfect, now we&#8217;re ready to start!</p><h2>Initial situation verification</h2><p>Before touching Intune, it&#8217;s best to check the &#8220;out of the box&#8221; situation: standard Windows 11 PC with default apps present, so you have a clean and measurable before/after. </p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;86e1e2e9-6e8a-4c8c-b47d-7c82f98ee957&quot;,&quot;duration&quot;:null}"></div><p>You can do this verification from Settings &#8594; Apps &#8594; Installed apps (or searching &#8220;Xbox,&#8221; &#8220;Camera,&#8221; etc. in Start).</p><h2>Removal configuration</h2><p>In Microsoft Intune admin center, create a Configuration profile for &#8220;Windows 10 and later&#8221; using &#8220;Settings catalog,&#8221; then search for the setting Remove default Microsoft Store packages from the system.</p><p>If you want to navigate the tree manually, find everything under the node:</p><p><strong>Administrative Templates</strong> &#8594; <strong>Windows Components</strong> &#8594; <strong>App Package Deployment</strong></p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;7c7603ba-3813-477b-91b0-53c1bce26a97&quot;,&quot;duration&quot;:null}"></div><h2>Policy application verification</h2><p>Now log into a machine targeted by our policy and verify that the selected apps are no longer installed.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;a01316a1-7b2a-4809-89b7-2d2a7161f02b&quot;,&quot;duration&quot;:null}"></div><p>Microsoft describes policy application in scenarios like OOBE/provisioning and sign-in after upgrade or policy update, so correct verification timing is crucial.</p><p>For an &#8220;admin&#8221; verification, you can also check that the policy has written the registry keys in HKLM\SOFTWARE\Policies\Microsoft\Windows\Appx\RemoveDefaultMicrosoftStorePackages. </p><h2>Deep dives (generous like extra pounds)</h2><p>Here&#8217;s the usual dump of official Microsoft documentation (yes: it needs to be STUDIED). </p><ul><li><p><a href="https://learn.microsoft.com/en-us/windows/configuration/policy-based-inbox-app-removal/policy-based-inbox-app-removal">Policy-based in-box app removal (Microsoft Learn)</a> </p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/policy-based-removal-of-pre-installed-microsoft-store-apps/4463835">Windows IT Pro official blog</a></p></li></ul><h2>Conclusions</h2><p>Finally, a supported and &#8220;clean&#8221; method to manage default apps on Windows 11 Enterprise/Education without relying solely on scripts that eventually bill you during Autopilot or after an upgrade!</p><p>If you liked the article, leave a like, reshare everywhere on your favorite socials, and subscribe to the ITSpecialist.News newsletter: it&#8217;s the best way not to miss practical guides on Intune, Windows, and security.</p><p>See you in the next video! Talk soon&#8230; LEGENDARY!</p><p>Rick</p>]]></content:encoded></item><item><title><![CDATA[Have you tried restarting? #8 (Happy new year!)]]></title><description><![CDATA[AVD multi-session and Intune pains, Microsoft news, calls for speakers everywhere, music and (somewhat) lazy thoughts to kick off 2026 with a bang.]]></description><link>https://www.itspecialist.news/p/have-you-tried-restarting-8-happy-new-year</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-restarting-8-happy-new-year</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 14 Jan 2026 07:00:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6bec32ff-0ce8-4673-aea0-94aa684999f0_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Happy New Year! Here we are again after the holiday break. It&#8217;s common to say that accumulated extra kilos can be dispensed with and the desire to restart is lacking. But let&#8217;s talk about us: we&#8217;re at issue #8 of &#8220;Have you tried restarting?&#8221; but you&#8217;ve never told me if you like it, what you think about it, whether you find it useful. How about sharing your thoughts in this first issue of 2026? There&#8217;s no better moment, right?</p><p>If you&#8217;d like to chat about it, just reply to this email with your feedback on the newsletter: I read and respond to everyone!</p><p>Perfect, let&#8217;s begin!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ITSpecialist.News! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><p>&#8226; <strong>FAQ... but with style</strong>: <em>&#8220;In my environment I have Azure Virtual Desktop machines in multi-session mode, managed with Intune. Some policies I created on these machines don&#8217;t work. Why? Are there any limitations on the types of policies and settings applicable to AVD multi-session session hosts?&#8221;</em></p><p>&#8226; <strong>Microsoft News Radar</strong>: news directly from Microsoft sources.</p><p>&#8226; <strong>Community Picks</strong>: community creators never stop, not even during the holiday season: fortunately they&#8217;re there.</p><p>&#8226; <strong>Events</strong>: new year, new events, new calls for speakers!</p><p>&#8226; <strong>On a personal note</strong>: the keyword is...</p><div><hr></div><h2>&#10067; FAQ... but with style</h2><h3>Question</h3><p><em>&#8220;In my environment I have Azure Virtual Desktop machines in multi-session mode, managed with Intune. Some policies I created on these machines don&#8217;t work. Why? Are there any limitations on the types of policies and settings applicable to AVD multi-session session hosts?&#8221;</em></p><h3>Answer</h3><p>Yes, and what you&#8217;re experiencing is completely normal. Intune has limitations when it comes to managing multi-session AVD hosts. Not all settings and policies that work perfectly on traditional desktop endpoints are supported on Windows Enterprise multi-session.</p><h4>The specific limitations</h4><p>Microsoft officially supports multi-session in Intune, but only a few configuration templates are truly supported: trusted certificates (Trusted, SCEP, PKCS) and VPN (Device Tunnel only). All other traditional templates are not supported and will appear as &#8220;Not applicable&#8221; in your compliance reports.</p><h4>The device vs. user constraint</h4><p>There&#8217;s a critical aspect that many don&#8217;t know: while on a classic endpoint this wouldn&#8217;t be a problem, on AVD multi-session device-level configurations cannot be assigned to users, and vice versa. In a multi-session environment, where dozens of users access the same physical host, most policies must be assigned at the device level through device groups. If you assign a policy to a user thinking it will work, you&#8217;ll get errors.</p><h4>Okay, so how do you know which settings will work?</h4><p>Few people know this simple trick: start filtering the Settings Catalog using &#8220;<strong>OS edition = Enterprise multi-session</strong>&#8221; to display only the configurations actually supported.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qfXl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qfXl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 424w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 848w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 1272w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qfXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png" width="1456" height="1054" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1054,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:167362,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/183370614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qfXl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 424w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 848w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 1272w, https://substackcdn.com/image/fetch/$s_!qfXl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1fa2ff0-806f-4659-8042-c8acf1eb188f_1696x1228.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><blockquote><p><strong>After applying the filter, the available settings will be those truly compatible with AVD multi-session.</strong></p></blockquote><p>Then assign all policies at the device level, not to users. And most importantly, always test your configurations by checking compliance reports: if a policy shows &#8220;Not applicable&#8221;, it&#8217;s because it&#8217;s not supported on multi-session.</p><p>As always, I&#8217;ll leave you with the comfort of official documentation for further insights.</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/mem/intune/fundamentals/azure-virtual-desktop-multi-session">Using Azure Virtual Desktop multi-session with Microsoft Intune</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-assign)">Assign device profiles in Microsoft Intune</a></p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>A selection of content directly from Microsoft sources: lots of news announced at Ignite.</p><ul><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-december-2025/4476486">What&#8217;s new in Microsoft Intune: December 2025</a></p></li></ul></li><li><p>Microsoft Defender for Endpoint</p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftdefenderatpblog/sensor-disconnection-notifications-with-microsoft-defender-for-iot-and-microsoft/4375517">Sensor Disconnection Notifications with Microsoft Defender for IoT and Microsoft Sentinel</a></p></li></ul></li><li><p><strong>Surface IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/surfaceitpro/improved-address-management-in-service-orders-on-surface-portals/4471487">Improved address management in service orders on Surface Portals</a></p></li></ul></li><li><p><strong>Microsoft Entra</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/securing-the-ai-era-starts-with-identity/4478952">Securing the AI era starts with identity</a></p></li></ul></li><li><p><strong>Microsoft 365 copilot</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft365copilotblog/new-capabilities-for-ai-admins-from-ignite-2025/4478906">New capabilities for AI admins from Ignite 2025</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>The most useful community content I&#8217;ve come across in these weeks.</p><ul><li><p>&#128279; <strong><a href="https://www.windowserver.it/2025/12/surface-management-portal-analisi-tecnica-completa-per-it-administrator/">Surface Management Portal: complete technical analysis for IT Administrator</a></strong><br>&#128100; <a href="https://www.linkedin.com/in/francesco-cantoni-85b24255/">Francesco Cantoni</a><br><em>An article that explores the Surface Management Portal in depth in Intune, illustrating its functions, advantages, limitations and ideal scenarios for enterprise Surface management.<br></em></p></li><li><p>&#128279; <strong><a href="https://www.windowserver.it/2025/12/windows-admin-center-v2511">Windows Admin Center v2511</a></strong></p><p>&#128100; <a href="https://www.linkedin.com/in/silviodibenedetto/">Silvio Di Benedetto</a><br><em>The article presents the news in Windows Admin Center v2511, including high availability, advanced security for Windows Server 2025 and migration tools from VMware to Hyper-V, offering practical insights for modernizing infrastructure management, auditing and automation.</em></p><p></p></li><li><p>&#128279; <strong><a href="https://www.tbone.se/2025/12/12/updated-my-script-to-cleanup-entra-id-devices-faster-and-better-logging/">Updated My Script To &#8220;Cleanup Entra ID Devices&#8221;, Faster and better logging</a></strong>&#128100; <a href="https://www.linkedin.com/in/mrtbone/?originalSubdomain=se">Mr T-Bone</a><br><em>The updated version of a very useful PowerShell script for cleaning up obsolete devices on Entra: faster, more robust, with advanced logging/reporting. Useful for security, accurate inventory and automation.</em></p></li></ul><div><hr></div><h2>&#127917; Events and Call for Speakers</h2><p>Community and Microsoft events, plus the main open Call 4 Speakers. Here&#8217;s my selection.</p><ul><li><p>&#128267; <strong><a href="https://www.ictpower.it/events/powercon2026-lit-tra-innovazione-sicurezza-e-controllo-evento-online-gratuito.htm">#POWERCON2026</a></strong></p><p>&#128197; January 23, 2026 - &#128187; Online</p><p><em>POWERCON2026 is a free online event that brings together innovation, security and modern IT governance, with concrete technical sessions on cloud, AI, Microsoft 365 and hybrid infrastructures, led by top experts and MVPs, with full recordings available.<br></em></p></li><li><p>&#8986; <strong><a href="https://www.linkedin.com/events/7408416541525839873/">Be Connected Hour</a></strong></p><p>&#128197; January 30, 2026 - &#128187; Online</p><p><em>Monthly update on news from the Microsoft 365, Teams, MTR, Purview, MDO, Copilot world, together with Luca Vitali, Fabrizio Volpe, Raffaele Colavecchi.<br></em></p></li><li><p>&#127760; <strong><a href="https://globalazure.net/">Global Azure 2026</a></strong></p><p>&#128197; April 13, 16-18, 2026 - &#128187; Online and/or &#127757; In person</p><p><em>Global Azure 2026 returns: special days in April 2026 to share the passion for Microsoft Azure together through technical sessions, inspiration and networking.</em></p></li></ul><p>Since Global Azure will be in April (there&#8217;s still time) and there are several Italian instances, more than the event itself I&#8217;d like to highlight the calls for speakers. Here they are.</p><ul><li><p>&#127760; <strong><a href="https://sessionize.com/global-azure-torino-2026/">Call for Speaker: Global Azure Torino 2026</a></strong></p></li><li><p>&#127760; <strong><a href="https://sessionize.com/globalazure2026pn/">Call for Speaker: Global Azure Pordenone 2026</a></strong></p></li><li><p>&#127760; <strong><a href="https://sessionize.com/global-azure-veneto-2026/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio">Call for Speaker: Global Azure Veneto 2026</a></strong></p></li><li><p>&#127760; <strong><a href="https://sessionize.com/global-azure-milano-2026">Call for Speaker: Global Azure Milano 2026</a></strong></p></li></ul><p>I&#8217;m certain that there will also be an instance in Italian at <strong>Lugano (Switzerland)</strong> but, at the time I&#8217;m writing this newsletter issue, the C4S is not yet available. You&#8217;ll definitely find it in the next February issue!</p><h4>Disclaimer</h4><blockquote><p>The events I highlight in &#8220;Have you tried restarting?&#8221; do not constitute a complete list: I share the ones I personally pick up and that I think are useful to the community. If an event is missing, I simply missed it or didn&#8217;t become aware of it: <strong>if you want to let me know about yours, write to me</strong>. Publication is for informational purposes only and does not imply endorsement, approval, sponsorship or partnership unless explicitly stated otherwise.</p></blockquote><div><hr></div><h2>&#127911; On a personal note</h2><p>Outside the IT world, here&#8217;s what&#8217;s been inspiring me lately.</p><h3>&#128214; What I&#8217;m reading (books, newsletters and more)</h3><h4>Books</h4><ul><li><p><a href="https://amzn.to/44QIk19">The Scortese Method: A contrarian guide to making it in everyday life (Ilaria Albano / Solferino Publisher)</a></p></li></ul><h4>Newsletters</h4><ul><li><p><a href="https://www.dividendology.com/p/barrons-top-10-stocks-for-2026">Barron&#8217;s Top 10 Stocks for 2026</a></p></li><li><p><a href="https://maranga9000.substack.com/p/il-2026-sara-lanno-dei-porno?utm_source=post-email-title&amp;publication_id=1747273&amp;post_id=183173440&amp;utm_campaign=email-post-title&amp;isFreemail=true&amp;r=2sx2g3&amp;triedRedirect=true&amp;utm_medium=email">Il 2026 sar&#224; l&#8217;anno dei porno</a></p></li><li><p><a href="https://orabuca.substack.com/p/cosa-rimane-se-nessuno-ti-guarda">What remains if no one is watching you</a></p></li></ul><h3>&#127925; What I&#8217;m listening to (monthly musical monkeys)</h3><ul><li><p><a href="https://music.apple.com/it/album/plimsoll-punks/1243615779?i=1243616348">Plimsoll Punks / Artist: Alvvays / Album: Antisocialities</a></p></li><li><p><a href="https://music.apple.com/it/album/believe/288794071?i=288794075">Believe / Artist: Staind / Album The Illusion of Progress</a></p></li><li><p><a href="https://music.apple.com/it/album/zelda/1806721142?i=1806721145">Zelda / Artist: TOLEDO / EP: Inertia</a></p></li></ul><h3>&#9997;&#65039; Random thoughts</h3><p><em>I expected different holiday vacations: more active, less &#8220;lazy&#8221; and during which I could re-knot some things left hanging, resume habits frozen after a decidedly strange and exceptional period. Instead, they were decidedly &#8220;lazy&#8221;, perhaps too much. The keyword now is &#8220;shock&#8221;.</em></p><p>See you soon!</p><p>Riccardo</p><blockquote><p><em>Some of the links on this site redirect to products or books sold by third parties. If you decide to purchase through these links, I may receive a commission as an affiliate, at no additional cost to you. This supports the work I do and allows me to continue to provide quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[Active Directory minimization case studies]]></title><description><![CDATA[Reduce Your Dependence on Active Directory with Real-World Examples: Cloud-First Strategies, Case Studies, and Practical Tips to Modernize Identities and Devices.]]></description><link>https://www.itspecialist.news/p/active-directory-minimization-case-studies</link><guid isPermaLink="false">https://www.itspecialist.news/p/active-directory-minimization-case-studies</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Tue, 13 Jan 2026 10:07:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!K5WJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Reducing Dependence on On-Prem Active Directory doesn&#8217;t have to mean &#8220;Full Cloud or Nothing&#8221;. It&#8217;s more useful to think in terms of <strong>AD minimization</strong>: gradually moving identities and device management to cloud platforms (Microsoft Entra + Intune) where it makes sense, while keeping on-prem only where it&#8217;s truly needed.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!K5WJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!K5WJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!K5WJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/acf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:137342,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/184529175?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!K5WJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 424w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 848w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!K5WJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Facf008b1-666e-4e2e-a2d7-76ce5e860c25_1536x1024.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>What Does &#8220;Reducing AD&#8221; Mean?</h3><p>In the Microsoft document (you&#8217;ll find the link at the end of the article), the concept refers to reducing reliance on traditional AD services (domain join, GPO, infrastructure, and operational overhead) by shifting identity and device management toward the cloud.<br>The stated benefits are clear: lower infrastructure costs, modern security (e.g., Conditional Access), improved user experience, and simpler, centralized management.</p><h3>Do You Have to Go Full Cloud?</h3><p>No: case studies show different paths, and that&#8217;s the interesting part.<br>Practical example: you can start with devices (provisioning and management) without &#8220;turning off AD tomorrow morning,&#8221; and even that significantly reduces domain dependency.</p><h3>3 Practical Insights from Case Studies</h3><ol><li><p><strong>Chugai Pharmaceutical</strong>: transition from domain-joined devices to cloud-managed endpoints, using Windows Autopilot for &#8220;cloud-first&#8221; provisioning.</p></li><li><p><strong>NTT Communications</strong>: evolution from hybrid to &#8220;100% cloud&#8221; device management with Microsoft Intune, reducing AD dependencies and simplifying operations.</p></li><li><p><strong>We Are Era</strong>: on-prem AD decommissioning with a focus on modern authentication and Zero Trust principles, including integration between cloud identities and on-prem resources where necessary.</p></li></ol><h3>Want to Learn More?</h3><p>Here&#8217;s the full article &#128073;&#127995; <strong><a href="https://learn.microsoft.com/en-us/entra/architecture/road-to-the-cloud-ad-minimization">Active Directory Minimization Case Studies</a></strong></p>]]></content:encoded></item><item><title><![CDATA[Have you tried restarting? #7 (Merry XMas!)]]></title><description><![CDATA[Microsoft Ignite 2025 news, Intune Suite included in M365 E3/E5, various simplifications, and Christmas greetings from the IT world]]></description><link>https://www.itspecialist.news/p/have-you-tried-restarting-7-merry</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-restarting-7-merry</guid><pubDate>Sat, 20 Dec 2025 15:25:31 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/efc9abeb-59a0-4aed-80ea-e2542ed5266e_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>&#8220;Merry Christmas,&#8221; &#8220;Happy New Year,&#8221; &#8220;to you and your family&#8221;, everywhere! By now we&#8217;re right in the middle of the Christmas countdown (everyone) and some simple but well-earned time off (me, the Grinch &#128518;). That WPC post completely wiped me out, and I can&#8217;t wait to recharge.</p><p>I&#8217;m heading into 2026 knowing I&#8217;ll definitely simplify my online presence even more, and I&#8217;ll also cut back on events (without disappearing altogether). In the meantime, there&#8217;s still plenty to read over the holidays this month, especially after Microsoft Ignite 2025!</p><p>But you know what? Put this issue aside. Just send me a quick Christmas hello by replying to this email (if you feel like it), and then go do something else entirely. You can always catch up later, the holiday break is meant to be enjoyed.</p><p>No long speech: whatever your take is on the holidays (and everything that comes with them), I simply hope they&#8217;re a good one and that you get to enjoy them at your best. See you in 2026! Byyyyyye!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading ITSpecialist.News &#10084;&#65039;&#128591;&#127995;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><ul><li><p><strong>FAQ&#8230; but make it stylish</strong>: &#8220;<em>What&#8217;s this about Intune Suite now being included with Microsoft 365 licenses?</em> &#128561;&#8221;</p></li><li><p><strong>Microsoft News Radar</strong>: post-Ignite 2025 updates straight from Microsoft sources.</p></li><li><p><strong>Community Picks</strong>: I haven&#8217;t been very active on LinkedIn lately, but the hunt for great community content never stopped. Here&#8217;s a selection of the most interesting finds this month.</p></li><li><p><strong>Events</strong>: yep, after WPC we&#8217;re not slowing down, and the events keep coming, with a techy Christmas twist!</p></li><li><p><strong>On a personal note</strong>: a year that&#8230; honestly, I don&#8217;t even know.</p></li></ul><div><hr></div><h2>&#10067; FAQ&#8230; with style</h2><h3>Question</h3><p>&#8220;<em>What&#8217;s this about Intune Suite now being included with Microsoft 365 licenses?</em> &#128561;&#8221;</p><h3>Answer</h3><p>In early December, <a href="https://www.linkedin.com/in/liorbela/">Lior Bela</a> (Director @ Microsoft Intune) dropped a bomb on LinkedIn one evening.</p><blockquote><p><strong>All Microsoft Intune Suite capabilities will be included and redistributed within EMS E3, Microsoft 365 E3, and E5.</strong></p></blockquote><p>All hell broke loose.</p><p><em>&#8220;What do you mean? When? Which features go into E3 and which into E5? TELL ME RIGHT NOW&#8230; AAAARGHHHH&#8221;</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!A49Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!A49Y!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 424w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 848w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 1272w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!A49Y!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif" width="480" height="270" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:270,&quot;width&quot;:480,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!A49Y!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 424w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 848w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 1272w, https://substackcdn.com/image/fetch/$s_!A49Y!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73d8492f-ce94-4e63-88e7-3b8f0d4ffedd_480x270.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">A line of community members asking for &#8221;simple information&#8221;&#8230;</figcaption></figure></div><p>Let&#8217;s bring some order with a Q&amp;A on the key points.</p><h4>Which Intune features are included in the different Microsoft 365 plans?</h4><p>The answer is in the table in the image.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4PLE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4PLE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4PLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg" width="1456" height="794" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:794,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Nessuna descrizione alternativa per questa immagine&quot;,&quot;title&quot;:&quot;Nessuna descrizione alternativa per questa immagine&quot;,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Nessuna descrizione alternativa per questa immagine" title="Nessuna descrizione alternativa per questa immagine" srcset="https://substackcdn.com/image/fetch/$s_!4PLE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 424w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 848w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!4PLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcbbca804-12d0-41f6-be1f-f05aa202f68a_2048x1117.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>What does Intune Plan 2 include?</h4><p>The Intune Plan 2 features, included in EMS E3, include:</p><ul><li><p><strong>Microsoft Tunnel for Mobile Application Management (MAM)</strong>: provides secure VPN connectivity for individual apps, enabling access to corporate resources without requiring full device enrollment.</p></li><li><p><strong>Specialty device management</strong>: helps secure specialized devices such as AR/VR headsets, smart displays, and meeting room systems.</p></li><li><p><strong>Firmware over-the-air (FOTA) updates</strong>: firmware updates for supported Zebra devices.</p></li></ul><h4>When will these changes take effect?</h4><p>A common question is, of course, about timing. The changes will take effect in 2026, and the process will be largely automatic:</p><ul><li><p>All eligible tenants with Enterprise Mobility and Security E3 and Microsoft 365 E5 will automatically receive provisioning of Intune Suite capabilities.</p></li><li><p>Microsoft will notify administrators of eligible organizations 30 days before the change is applied via the Microsoft 365 admin center.</p></li><li><p>There&#8217;s no need to change plans to take advantage of these new capabilities.</p></li></ul><p>As always, here are some verifiable sources where you can dive deeper into your licensing considerations.</p><p>&#128206; <a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/microsoft-365-adds-advanced-microsoft-intune-solutions-at-scale/4474272">Microsoft 365 adds advanced Microsoft Intune solutions at scale</a></p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>A selection of content straight from Microsoft sources: a ton of new announcements from Ignite.</p><ul><li><p><strong><a href="https://news.microsoft.com/ignite-2025-book-of-news/">Microsoft Ignite 2025 Book of News</a></strong></p></li><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/whats-new-in-microsoft-intune-at-ignite/4471043">What&#8217;s new in Microsoft Intune at Ignite</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new#week-of-december-1-2025">What&#8217;s new in Microsoft Intune</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/debunking-the-myth-cloud-native-windows-devices-and-access-to-on-premises-resour/4470056">Debunking the myth: Cloud-native Windows devices and access to on-premises resources</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoftintuneblog/essential-intune-reading-list-mvp-community-content-for-2025/4471897">Essential Intune reading list: MVP community content for 2025</a></p></li></ul></li><li><p><strong>Windows IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/experience-next-gen-productivity-with-windows-365-ai-enabled-cloud-pcs/4467875">Experience next-gen productivity with Windows 365 AI-enabled Cloud PCs</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-365-and-azure-virtual-desktop-support-external-identities-now-generally-/4468103">Windows 365 and Azure Virtual Desktop support external identities, now generally available</a></p></li></ul></li><li><p><strong>Microsoft Entra</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/icymi-watch-replays-of-microsoft-entra-sessions-at-microsoft-ignite-2025/4427989">ICYMI: Watch replays of Microsoft Entra sessions at Microsoft Ignite 2025</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>he most useful community content I came across over the past few weeks. </p><ul><li><p><strong>&#128279; <a href="https://scloud.work/intune-secure-boot-certificate-updates/?utm_source=substack&amp;utm_medium=email">Intune and Secure Boot Certificate Updates: What You Must Fix Before the 2026 Expiry</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/fsalzmann/">Florian Salzmann</a><br><em>How to manage Secure Boot certificate updates on devices managed with Microsoft Intune, with practical guidance to keep Windows systems secure. A hands-on approach to avoid issues in June 2026.</em></p></li><li><p><strong>&#128279; Windows Backup for Organizations: a modern approach with Microsoft Intune</strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/nickydewestelinck/">Nicky De Westelinck</a><br><em>This article explains how to use Windows Backup for Organizations with Microsoft Intune to protect and easily restore settings and Microsoft Store apps on Windows 11 devices, simplifying IT management and improving the user experience in case of a reset or device replacement.<br></em></p></li><li><p><strong>&#128279; <a href="https://jeffreyappel.nl/troubleshoot-configured-defender-av-settings-with-effective-settings-in-defender/#google_vignette">Troubleshoot configured Defender AV settings with effective settings in Defender</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/jeffrey-appel-nl/">Jeffrey Appel</a><br><em>This article explains how to use the Effective Settings feature in Microsoft Defender to analyze which Defender AV antivirus configurations are actually applied on devices when policies come from multiple sources (Intune, GPO, MECM, scripts, etc.), helping identify conflicts that can disable or weaken protection.</em> </p></li></ul><div><hr></div><h2>&#127917; Events and Call for Speaker</h2><p>Eventi di community e Microsoft, oltre alle principali Call 4 Speaker aperte.</p><ul><li><p>&#8986; <strong><a href="https://www.youtube.com/@BeConnectedday/">Be Connected Hour</a></strong><br>&#128197; 19 December 2025 - &#128187; Online<br><em>Monthly update on what&#8217;s new across Microsoft 365, Teams, MTR, Purview, MDO, and Copilot, together with Luca Vitali, Fabrizio Volpe, and Raffaele Colavecchi.<br></em></p></li><li><p>&#127877;&#127995; <strong><a href="https://globalai.community/chapters/lecce/events/santa-cloud-day-christmas-edition/">Santa Cloud Day</a></strong><br>&#128197; 20 December 2025 - &#127757; Meetup (Lecce)<br><em>A day dedicated to Generative AI, Cloud, and Security, organized together with Global AI Lecce, plus talks, hands-on demos, and plenty of networking among enthusiasts and industry professionals.</em></p></li></ul><div><hr></div><h2>&#127911; On a personal note</h2><p>Outside the IT world, here&#8217;s what&#8217;s been inspiring me lately.</p><h3>&#128214; What I&#8217;m reading (books, newsletters)</h3><ul><li><p><strong>Books</strong></p><ul><li><p><em><a href="https://amzn.to/48LoCoH">Sommersi: Resistere nell&#700;era delle notifiche e dell&#700;infodemia social / Mattia Marangon / Apogeo</a></em></p></li></ul></li></ul><h3>&#127925; What I&#8217;m Listening To (my musical obsessions) </h3><ul><li><p><a href="https://music.apple.com/it/station/stazione-di-riccardo-corna/ra.u-0708c3089a73ab7e1abb70ff757aa95f">&#8206;</a><a href="https://music.apple.com/it/album/smash-remastered/1485043082">Smash (Remastered) / The Offspring</a></p></li><li><p><a href="https://music.apple.com/it/album/gimme-single/1851139225">Gimme / Artist: Hazel English / Singolo: Gimme</a></p></li><li><p><a href="https://music.apple.com/it/album/stop-at-nothing-ep/1699059159">Breakdown / Artist: Sea Lemon / Album: Stop at Nothing - EP</a> <em><br>(this one in particular has been obsessing me)</em></p></li></ul><h3>&#9997;&#65039; Random Thoughts</h3><p><em>I&#8217;m not usually one to have thoughts like this, but 2025 is a year I&#8217;m more than happy to file away and move on from. Even so, I&#8217;ve got a feeling that 2026 will mean rolling up our sleeves to tackle a few things.</em></p><p>See you soon!</p><p>Riccardo</p><div><hr></div><blockquote><p><em>Some links on this site point to products or books sold by third parties. If you choose to purchase through these links, I may earn an affiliate commission at no additional cost to you. This supports the work I do and helps me continue to provide high-quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[Microsoft Intune Device Cleanup Rules]]></title><description><![CDATA[Watch now | Clean management of Intune devices: cleanup rules and lifecycle flow tips for Intune, Entra, and Active Directory.]]></description><link>https://www.itspecialist.news/p/microsoft-intune-device-cleanup-rules</link><guid isPermaLink="false">https://www.itspecialist.news/p/microsoft-intune-device-cleanup-rules</guid><pubDate>Wed, 17 Dec 2025 07:00:39 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/177075629/12e748302d3d0dc7dfb6bef75fc3e591.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Welcome to ITSpecialist.News! Today we&#8217;re diving into a feature every IT Specialist working with Intune should know and use: Device Cleanup Rules. If your tenant is full of inactive devices that look like zombies &#129503;, this article is your first step toward restoring cosmic order in your Intune portal.</p><div><hr></div><h2>&#128240; What&#8217;s your preference? Video or article?</h2><p>A few notes to help you get the most out of this content:</p><ul><li><p><strong>If you prefer watching the full video</strong>, easy: you&#8217;ll find it right above in the header.</p></li><li><p><strong>If you prefer reading</strong>, also easy: just keep scrolling. For each section, I&#8217;ve included the relevant video snippet so you&#8217;ll only see the screens that matter &#8212; no talking head in the way.</p></li></ul><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>Either way, make sure to subscribe to the newsletter so you won&#8217;t miss any future tutorials.</p><p>Let&#8217;s get started!</p><div><hr></div><h2>What are Device Cleanup Rules?</h2><p>Device Cleanup Rules let you hide devices from the Intune console if they haven&#8217;t checked in for a certain number of days.<br>They&#8217;re not deleted, just removed from view, helping you avoid an endless list of zombie devices.</p><p>This feature is essential for:</p><ul><li><p>Keeping the console tidy</p></li><li><p>Improving readability and manageability</p></li><li><p>Reducing noise in reports and policies</p></li></ul><div><hr></div><h2>Two things to know before using them</h2><h3>1. Devices can reappear</h3><p>If a device was hidden due to inactivity but is turned back on and still has a valid Intune management certificate, it will reappear in the console.<br>So this isn&#8217;t permanent cleanup, it&#8217;s more like temporary archiving.</p><h3>2. Cleanup applies only to Intune, not Entra</h3><p>Device Cleanup Rules only affect Intune. If you want to keep <strong>Entra ID</strong> clean as well, you&#8217;ll need to implement a separate cleanup flow.</p><p>Here&#8217;s what to do:</p><ul><li><p>For <strong>Entra Joined</strong> devices: check the <code>ApproximateLastSignInDateTime</code> attribute</p></li><li><p>For <strong>Hybrid Joined</strong> devices: clean up in <strong>Active Directory</strong> by deleting stale computer objects or moving them to an OU that&#8217;s not synced with Entra Connect</p></li></ul><div><hr></div><h2>How to configure Device Cleanup Rules</h2><p>You can set up these rules from the Intune portal and even differentiate them by platform (Windows, iOS, Android, macOS).<br>This is handy if you have different policies for mobile and desktop devices.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;e51bb53f-b23e-4a5a-9cfc-353b1ff545e5&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>How to check the Intune management certificate expiration</h2><p>There are two ways to verify if a device still has a valid certificate:</p><h3>1. On the client</h3><p>You can check the certificate directly on the device.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;2e3eaeb6-51a4-4fc3-91ee-0b7869bc05cd&quot;,&quot;duration&quot;:null}"></div><p></p><h3>2. In the Intune portal</h3><p>In the device&#8217;s section of the Intune portal, you&#8217;ll find the certificate expiration date.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;02b82df7-0570-4ba1-829b-3f530b5a19f1&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>Useful documentation</h2><p>For those who want to dig deeper, here&#8217;s a selection of official resources and helpful scripts:</p><ul><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/device-cleanup-rules">Automatically Hide Devices With Cleanup Rules</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/entra/identity/devices/manage-stale-devices">How to manage stale devices in Microsoft Entra ID</a></p></li></ul><div><hr></div><h2>Conclusion</h2><p>Cleaning up your tenant isn&#8217;t just about aesthetics, it&#8217;s a solid governance practice.<br>Intune&#8217;s Device Cleanup Rules are a great starting point, but remember: <strong>Entra and AD need separate management</strong>.</p><p>Thanks for reading all the way through!<br>If you found this helpful, share the article and subscribe to the ITSpecialist.News newsletter so you won&#8217;t miss future updates.</p><p>Until next time, and keep those tenants clean &#128170;</p><p>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Microsoft Intune Remote Help for macOS]]></title><description><![CDATA[Set Up Remote Help on Intune for macOS: A Complete Guide with Video, Permissions, Requirements, and Policies for Smooth and Secure Remote Support.]]></description><link>https://www.itspecialist.news/p/microsoft-intune-remote-help-for</link><guid isPermaLink="false">https://www.itspecialist.news/p/microsoft-intune-remote-help-for</guid><pubDate>Wed, 19 Nov 2025 07:00:43 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/176867990/b7f54b06b989c42de2286c4d01a32335.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><strong>IT Specialists! Hello everyone! Especially you, reading yet another tutorial. &#128521;</strong><br>Today we&#8217;ll look at how to configure Remote Help on Intune for macOS, a super useful feature for providing remote support in a secure and controlled way.<br>Preconfiguring app deployment, support staff permissions, and macOS permissions is essential: it simplifies the user experience and makes support much smoother, avoiding interruptions and manual prompts during the session.</p><div><hr></div><h2>&#128736;&#65039; Enabling Remote Help on the Tenant</h2><p>Let&#8217;s start with the first step: enabling Remote Help in the Intune tenant. This is necessary to make the feature available globally.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;86e6a856-363b-41d9-a1e4-66bb66a02037&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128230; Deploying the Remote Help App</h2><p>Download the Remote Help PKG app from the following URL:</p><pre><code><a href="https://aka.ms/downloadremotehelpmacos">https://aka.ms/downloadremotehelpmacos</a></code></pre><p>Then upload it to Intune to deploy it to macOS devices.<br>This is a <strong>Managed PKG</strong>! If you&#8217;re not sure what the difference is between Managed and Unmanaged PKGs, no worries, I&#8217;ve included the usual bucketload of documentation at the end of the article or in the description. &#128522;</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;d37cfbfd-b430-4893-a30a-f0b64298d012&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128101; Required Permissions for Help Desk Operators</h2><p>Anyone providing support must have the correct permissions.<br>The <strong>Help Desk Operators</strong> role in Intune is sufficient to use Remote Help.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;ec79f77c-00d0-42c0-93b0-db9ba9e5256f&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#9989; Requirements for a Smooth macOS Experience</h2><p>To avoid issues during support sessions, the Mac must have:</p><ul><li><p><strong>Enterprise SSO configured</strong> (even better if using Platform SSO).<br>If you want to see how to configure PSSO, check out my video linked in this article.</p></li><li><p><strong>Company Portal open and user signed in</strong></p></li></ul><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;fe634551-a587-4f2e-88f4-3898ac7eefd5&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128272; Configuring Accessibility and Screen Capture Permissions</h2><p>Create an Intune policy to configure <strong>Accessibility</strong> and <strong>Screen Capture</strong> permissions.</p><blockquote><p><em>&#9888;&#65039; <strong>Important</strong>: Screen Capture still needs to be manually authorized by the user, as macOS doesn&#8217;t allow MDM to force the &#8220;Allow&#8221; setting.<br>With Intune, the best we can do is allow even standard users to change this permission, no admin rights required.</em></p></blockquote><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;7ef16061-560f-4320-84d0-7cea4f4acae1&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128187; Verifying Permissions on macOS</h2><p>Launch the Remote Help app on macOS and check that permissions are correctly set.<br>The user will only see the manual prompt for screen capture.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;18763ad9-d57b-4775-ba09-62222ecab4ee&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128105;&#127995;&#8205;&#128187; User Experience (IT Specialist and End User)</h2><p>With some incredible special effects (I definitely need to improve my video editing skills) &#128522; we&#8217;ll explore the user experience from both perspectives: the support provider and the end user.</p><p>In full screen, I&#8217;ve shown your experience as the <strong>IT Specialist</strong> providing support.<br>In a small overlay at the bottom right, I&#8217;ve also recorded what&#8217;s happening simultaneously on the <strong>end user&#8217;s side</strong>, so you can fully understand the experience from both points of view.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;acaa1d74-5315-40c6-affd-b3fd252c200b&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128196; Attached Documentation</h2><p>Here are some useful links to dive deeper into Remote Help and macOS permissions management.<br>As always, freshly baked and delightfully crisp documentation:</p><ul><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help?tabs=macos">Use Remote Help to Assist Users Authenticated by your Organization</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-plan?tabs=macos">Plan for Remote Help with Microsoft Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-deploy?tabs=macos">Deploy Remote Help with Microsoft Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-use?tabs=macos%2Cwindowsnative">Using Remote Help on Windows to Assist Authenticated Users</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remote-help-troubleshoot-monitor?tabs=macos">Troubleshoot and monitor Remote Help for Microsoft Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/apps/lob-apps-macos">How to Add macOS Line-of-Business Apps to Microsoft Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/apps/macos-unmanaged-pkg">Add an Unmanaged macOS PKG App to Microsoft Intune</a></p></li></ul><div><hr></div><h2>&#128233; Conclusion</h2><p>Awesome! Remote Help is now correctly configured on macOS via Intune.<br>Thanks for sticking with me this far!<br>If you found this video helpful, subscribe to my newsletter at <strong>ITSpecialist.News</strong> to stay up to date on all things Microsoft Intune, Entra, and Security.</p><p>To you and all IT Specialists, see you soon&#8230; you legends!</p><p>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Have you tried restarting? #6]]></title><description><![CDATA[Events, events, events, Intune remediations that don&#8217;t behave as you expect, Windows 11 25H2, inspiring new reads, Jedi cats.]]></description><link>https://www.itspecialist.news/p/have-you-tried-turning-it-off-and</link><guid isPermaLink="false">https://www.itspecialist.news/p/have-you-tried-turning-it-off-and</guid><pubDate>Wed, 05 Nov 2025 07:00:48 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4baedbf8-f60f-489c-8fa6-19ede6513241_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Hi there! Let&#8217;s get straight to the point: this issue is all about events, especially two of them: AperiTeams Conference and WPC 2025.</p><p>Let&#8217;s start with AperiTeams Conference: it took place on October 8, 2025, and I was there as a speaker. It&#8217;s always fun to attend and a great opportunity to chat with other speakers and, most importantly, to connect with the people who actually use the technologies we talk about: our customers.</p><p>I owe a double thank-you to Silvio Di Benedetto and Irene Bugatti: the first &#8220;thank you&#8221; is for inviting me and trusting me, the second because, unintentionally, I&#8230; &#8220;stole&#8221; something. Yes, really&#8230; let me explain. &#128518;</p><p>When I started this newsletter, I already had in mind that, editorially, there would be two sections: a technical video tutorial and a more &#8220;chatty&#8221; column, the one you&#8217;re reading now: <em>&#8220;Have you tried restarting?&#8221;</em> Back then, though, I hadn&#8217;t decided on the title yet, so I posted a poll on LinkedIn with several options.</p><p>One of those options was exactly <em>&#8220;Have you tried restarting?&#8221;</em> The rest is history. Too bad that&#8230; deep in the dark corners of Silvio and Irene&#8217;s data centers, without us talking to each other, they were also planning a column with the same title. &#128517;</p><p>How did it end? With a few (joking) curses from Silvio and Irene and an awesome T-shirt! &#128071;&#127995; </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UwDC!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UwDC!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UwDC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg" width="498" height="663.885989010989" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:498,&quot;bytes&quot;:2319242,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/176434775?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UwDC!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!UwDC!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4bb5c6e5-c224-4c24-b8a9-9f3c956ed457_3471x4628.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Thanks again and see you at the next AperiTeams! I owe you the title of a column. &#128540;</strong></p><p>Now let&#8217;s talk about WPC 2025! This year, besides being a speaker, I&#8217;ll also be the agenda lead for the <strong>Security &amp; Compliance</strong> and <strong>Infrastructure &amp; Devices</strong> tracks. What does that mean? It means I helped Overnet select the sessions and speakers for WPC. I still can&#8217;t believe it: a few years ago I almost &#8220;envied&#8221; (constructively, of course &#128517;) those who stepped on that stage and thought I&#8217;d never make it there. Today, in 2025, I&#8217;ve been speaking at WPC for some time, and this year I even contributed a little during the planning phase. I&#8217;m thrilled and super happy. This WPC will be special! Thanks to <a href="https://www.overnet.education">Overnet</a> and Michele Sensalari for the trust and the opportunity. &#128591;&#127995; <br>You&#8217;ll find all the WPC details later in this email, including the full agenda and my session.</p><p>Thanks and talk soon!</p><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti&quot;,&quot;language&quot;:&quot;it&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Do you like this newsletter? Subscribe!  &#10084;&#65039;&#128591;&#127995;</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digita la tua email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Iscriviti"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>&#128204; In this issue</h2><ul><li><p><strong>FAQ&#8230; with style:</strong> <em>&#8220;I&#8217;ve set up an Intune remediation to run every day at 2:00 PM. Today is November 5, and when I created and assigned the remediation it was 5:00 PM. When will the first execution happen? Today, November 5, right after the client receives the policy, or tomorrow, November 6 at 2:00 PM?&#8221;</em></p></li><li><p><strong>Microsoft News Radar:</strong> updates straight from Microsoft sources.</p></li><li><p><strong>Community Picks:</strong> the best content from the IT Specialist community in Italy and beyond. This month, a special mention for the AperiTeams Conference held on October 8, 2025.</p></li><li><p><strong>Events:</strong> I&#8217;ll just say&#8230; WPC 2025! <em>The</em> Italian event dedicated to Microsoft technologies. Less than a month to go&#8230;</p></li><li><p><strong>On a personal note:</strong> cats named after Star Wars princesses.</p></li></ul><div><hr></div><h2>&#10067; FAQ&#8230; with style</h2><h3>Question</h3><p><em>&#8220;I&#8217;ve set up an Intune remediation to run every day at 2:00 PM. Today is November 5, and when I created and assigned the remediation it was 5:00 PM. When will the first execution happen? Today, November 5, right after the client receives the policy, or tomorrow, November 6 at 2:00 PM?&#8221;</em></p><h3>Answer</h3><p>This is one of those real-world cases where I thought I knew how a feature behaved. Turns out&#8230; I didn&#8217;t.</p><p>Logic suggests that if I create and assign a remediation at 5:00 PM on November 5 to run daily at 2:00 PM, the first execution should happen on November 6 at 2:00 PM. But no.</p><p>Here&#8217;s the actual behavior:</p><ul><li><p>Once created and assigned, the remediation policy &#8220;lands&#8221; on the client as soon as it checks in with Intune.</p></li><li><p>As soon as the policy is received, the detection runs immediately for the first time, regardless of the scheduled time.</p></li><li><p>The usual mechanism doesn&#8217;t change: if <code>exit = 1</code>, remediation is triggered; otherwise, nothing happens.</p></li><li><p>Future executions will follow the schedule set in the portal. So, in our case, the second run will actually happen on November 6 at 2:00 PM.</p></li></ul><div class="pullquote"><p><strong>Is this documented? No. But I&#8217;ve tested it in the field.</strong></p></div><p>Here&#8217;s an example: a remediation created and assigned in my lab on October 16 in the late afternoon (around 5:45 PM), definitely after 2:00 PM. The policy is clear: I want it to run daily at 2:00 PM.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LctB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LctB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 424w, https://substackcdn.com/image/fetch/$s_!LctB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 848w, https://substackcdn.com/image/fetch/$s_!LctB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 1272w, https://substackcdn.com/image/fetch/$s_!LctB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LctB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png" width="349" height="397.68403361344537" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:678,&quot;width&quot;:595,&quot;resizeWidth&quot;:349,&quot;bytes&quot;:32752,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/176434775?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LctB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 424w, https://substackcdn.com/image/fetch/$s_!LctB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 848w, https://substackcdn.com/image/fetch/$s_!LctB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 1272w, https://substackcdn.com/image/fetch/$s_!LctB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28044b21-34eb-4cbc-9051-0814c4bdcc8b_595x678.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The test detection I wrote was designed to trigger the remediation. The remediation was supposed to write a text file to <code>C:\</code>.</p><p>My expectation was that <strong>no file would be written</strong> <strong>until October 17 at 2:00 PM</strong>.</p><p>And yet&#8230; the image speaks for itself: <strong>the remediation ran on October 16, 2025, at 6:25 PM.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1o3N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1o3N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 424w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 848w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 1272w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1o3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png" width="1456" height="1113" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1113,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:892949,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/176434775?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1o3N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 424w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 848w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 1272w, https://substackcdn.com/image/fetch/$s_!1o3N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc760716c-4be4-4c55-b455-58c693f2e641_1823x1393.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>So, detection and remediation were executed immediately upon policy receipt, regardless of the fact that I had set 2:00 PM.</strong></p><p><strong>The moral of the story? If you plan remediations, remember that the first execution will always happen as soon as the policy is received. Subsequent runs will follow the schedule you set, whether that&#8217;s &#8220;once every hour&#8221; or at a specific time.</strong></p></blockquote><p>As I mentioned, this behavior isn&#8217;t documented, but if you want to dive deeper into Intune remediations, here are the usual links that survived Halloween night, plus a few examples! &#127875;</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/remediations">Use Remediations to Detect and Fix Support Issues - Microsoft Intune</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/powershell-scripts-remediation">PowerShell Scripts for Remediations - Microsoft Intune</a></p><div><hr></div><h2>&#128752;&#65039; Microsoft Radar</h2><p>Top picks from official Microsoft sources.</p><ul><li><p><strong>Microsoft Intune</strong></p><ul><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/whats-new">What&#8217;s new in Microsoft Intune - Microsoft Intune | Microsoft Learn</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/microsoft-intune-advanced-analytics-in-action-real-world-scenarios-for-it-teams/4459812">Microsoft Intune Advanced Analytics in action: Real-world scenarios for IT teams</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/intunecustomersuccess/deep-dive-into-windows-autopilot-device-preparation-how-to-deploy-and-when-to-us/4455341">Deep dive into Windows Autopilot device preparation: How to deploy and when to use it</a></p></li></ul></li><li><p><strong>Windows IT Pro</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/an-it-pro%e2%80%99s-guide-to-windows-11-version-25h2/4457409">An IT pro&#8217;s guide to Windows 11, version 25H2</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/windows-10-extended-security-updates-for-windows-365/4459693">Windows 10 Extended Security Updates for Windows 365</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/hotpatch-efficiency-unlocked-smaller-update-size/4460681">Hotpatch efficiency unlocked: Smaller update size</a></p></li></ul></li><li><p><strong>Microsoft Entra</strong></p><ul><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/what%e2%80%99s-new-in-microsoft-entra-%e2%80%93-september-2025/4352576">Learn about the latest features and change announcements across Microsoft Entra</a></p></li><li><p><a href="https://techcommunity.microsoft.com/blog/microsoft-entra-blog/the-conditional-access-optimization-agent-keeps-getting-better%e2%80%94and-making-your-l/4460535">The Conditional Access Optimization Agent keeps getting better&#8212;and making your life easier</a></p></li></ul></li></ul><div><hr></div><h2>&#127760; Community Picks</h2><p>The most useful community content I&#8217;ve come across in recent weeks. This month, a special mention goes to the resources from <a href="https://www.aperiteams.it">AperiTeams Conference</a>, the event organized by Inside Technologies for CIOs, IT Managers, and decision makers, where key IT topics are explored: Cloud, Security, Modern Work, and Infrastructure.<br></p><ul><li><p><strong>&#128279; <a href="https://www.youtube.com/playlist?list=PLL1BLRV7EMENg41yrJdbquQxQ3pFcNdL-">AperiTeams Conference - Security Day 2025</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/silviodibenedetto/">Silvio Di Benedetto</a>, <a href="https://www.linkedin.com/in/vitofrancavilla/">Vito Francavilla</a>, <a href="https://www.linkedin.com/in/michele-sensalari/">Michele Sensalari</a>, <a href="https://www.linkedin.com/in/frigerio-simone/">Simone Frigerio</a>, <a href="https://www.linkedin.com/in/mario-serra-85829828/">Mario Serra</a>, <a href="https://www.linkedin.com/in/ninocrudele/">Nino Crudele</a>, <a href="https://www.linkedin.com/in/francesco-castano-8400a28/">Francesco Castano</a><br><em>The full playlist of all conference sessions: the main theme of the day was Identity and its security. Tons of must-watch content and, best of all, it&#8217;s free.<br></em></p></li><li><p><strong>&#128279; <a href="https://andrewstaylor.com/2025/10/20/getting-windows-kiosks-to-work-in-intune-whilst-avoiding-inprivate-browsing/">Getting Windows Kiosks to work in Intune whilst avoiding InPrivate browsing</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/andrew-taylor-41707916/">Andrew Taylor</a><br><em>A practical guide to configuring Windows Kiosks in Intune while avoiding InPrivate mode, which causes issues with conditional access policies.<br></em></p></li><li><p><strong>&#128279; <a href="https://www.vansurksum.com/2025/10/20/balancing-control-and-convenience-preventing-edge-password-sync-on-unmanaged-devices/">Balancing Control and Convenience: Preventing Edge Password Sync on Unmanaged Devices</a></strong><br><strong>&#128100; </strong><a href="https://www.linkedin.com/in/kennethvansurksum/">Kenneth van Surksum</a><br><em>This guide explains how to block password sync in Microsoft Edge on unmanaged devices, protecting corporate data. Perfect for those looking to balance security and convenience in browser management.</em></p></li></ul><div><hr></div><h2>&#127917; Events and Call for Speaker</h2><p>Eventi di community e Microsoft, oltre alle principali Call 4 Speaker aperte.</p><ul><li><p>&#8986; <strong><a href="https://www.linkedin.com/company/beconnectedday/posts/?feedView=all">Be Connected Hour</a></strong><br>&#128197; 28 November 2025 - &#128187; Online<br><em>Monthly update on what&#8217;s new in Microsoft 365, Teams, MTR, Purview, MDO, and Copilot, together with Luca Vitali, Fabrizio Volpe, and Raffaele Colavecchi.</em><br></p></li><li><p><strong>&#128308; <a href="https://www.wpc.education/">WPC 2025 - 30a edizione</a></strong><br>&#128197; 2, 3, 4 December 2025 - &#127757; On site<br><em>WPC is Italy&#8217;s #1 ICT conference dedicated to Microsoft technologies, featuring over 100 brand-new technical sessions. It brings together MVPs, experts, and decision makers for three days of training, networking, and innovation. A must-attend event to stay up to date, exchange ideas, and bring new solutions to your team. Spoiler: I&#8217;ll be there with my own session!</em></p></li></ul><p><strong>All the details about my session: what, where, when.</strong></p><p>&#129489;&#127995;&#8205;&#128187; <strong>Windows Autopilot Device Preparation: provisioning cloud&#8209;ready&#8230; in every sense</strong><br><em>With Windows Autopilot Device Preparation, provisioning becomes truly cloud-ready. After covering prerequisites and comparing it with Autopilot v1, we&#8217;ll dive into practice: configuring Device Preparation, optimizing Microsoft 365 app deployment, various script-based automations, creating Intune profiles for physical PCs and (plot twist!) Windows 365 Frontline Cloud PCs. As promised&#8230; cloud in every sense!</em></p><p>&#128197; Tuesday December 2 at 12:00 PM<br>&#128205; NH Milano Congress Centre - Assago (MI)<br>&#9899; Black Room</p><p>&#128209; <a href="https://www.wpc.education/agenda-wpc">Here&#8217;s the full WPC agenda with all sessions and speakers.</a></p><div><hr></div><h2>&#127911; On a personal note</h2><p>Beyond Tech: what&#8217;s inspiring me right now.</p><h3>&#128214; What I&#8217;m Reading (Books, Newsletters &amp; More)</h3><p>I&#8217;ve realized that a good part of the time I dedicate to reading is spent on newsletters as well as books. So, why not share some interesting newsletters too?</p><ul><li><p><strong>Newsletter</strong></p><ul><li><p><a href="https://orabuca.substack.com/p/non-siate-coerenti">Non siate coerenti - by Carmela Giglio - OraBuca</a></p></li><li><p><a href="https://frankmerenda.substack.com/p/come-schiantare-130-milioni-vendendo">Come Schiantare 130 Milioni Vendendo Occhiali di Velluto: Il Capolavoro Involontario di Lapo Elkann</a></p></li><li><p><a href="https://mizionewsletter.substack.com/p/studia-tutto-tranne-lai">Studia tutto, tranne l&#8217;AI. - by Mizio Ratti</a></p></li></ul></li><li><p><strong>Books</strong></p><ul><li><p><em>No books this month, even though I already have a few in my sights. If you have any suggestions, reply to this email with your recommendation! </em>&#128521;</p></li></ul></li></ul><h3>&#127925; What I&#8217;m Listening To (a.k.a. This Month&#8217;s Musical Obsessions)</h3><ul><li><p><a href="https://music.apple.com/it/station/stazione-di-riccardo-corna/ra.u-0708c3089a73ab7e1abb70ff757aa95f">&#8206;</a><a href="https://music.apple.com/it/album/hearts-and-flowers/1836562633?i=1836562634">Tennis / Artist: CASTLEBEAT / Album: Vhs</a></p></li><li><p><a href="https://music.apple.com/it/album/calgary/1839082662?i=1839082663">Calgary / Artist: Hazel English / Singolo: Calgary</a></p></li><li><p><a href="https://music.apple.com/it/album/tenderness/1463547005?i=1463547016">Tenderness / Artist: Jay Som / Album: Anak Ko</a></p></li></ul><h3>&#9997;&#65039; Random Thoughts</h3><p><em>Soft and purring news: a little furry princess named Padm&#233; has joined our home. The Force is strong with her, and we&#8217;re already head over heels in love. </em>&#129321;<em> Plus, she seems to have a certain IT Specialist vibe&#8230; </em>&#128516;</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h-Hl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h-Hl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h-Hl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg" width="1456" height="1941" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1941,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1374988,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/176434775?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h-Hl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 424w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 848w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!h-Hl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F66c94746-5f67-4cb4-bc00-4d4d75aaea6b_2481x3308.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Talk to tou soon!</p><p>Riccardo</p><div><hr></div><blockquote><p><em>Some of the links on this site point to products or books sold by third parties. If you decide to purchase through these links, I may earn a commission as an affiliate, at no additional cost to you. This helps support the work I do and allows me to keep providing quality content.</em></p></blockquote>]]></content:encoded></item><item><title><![CDATA[BitLocker Key Readers Custom Role in Microsoft Entra]]></title><description><![CDATA[Watch Now | Viewing BitLocker keys from Intune requires a specific permission in Microsoft Entra: a practical guide to creating it]]></description><link>https://www.itspecialist.news/p/bitlocker-key-readers-custom-role-in-microsoft-entra</link><guid isPermaLink="false">https://www.itspecialist.news/p/bitlocker-key-readers-custom-role-in-microsoft-entra</guid><pubDate>Wed, 22 Oct 2025 06:00:35 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/175900182/ec243860a4f166dd2c17981deea7fbdf.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hello and welcome to a new tutorial from ITSpecialist.news! Today we&#8217;ll address a concrete need that many of you may have already encountered: allowing a help desk operator to <strong>view the BitLocker recovery keys</strong> of Windows devices managed by <strong>Microsoft Intune</strong>.</p><div><hr></div><h2>&#128240; What do you prefer? Video or article?</h2><p>Some notes to make the most of this content.</p><p><strong>If you prefer to watch the full video</strong>, easy: you&#8217;ll find it right above in the header.</p><p><strong>If you prefer reading, that&#8217;s easy too</strong>: just keep going here. For each step I&#8217;ve included the specific video snippet, so you&#8217;ll only see the screens that matter, without my face talking.</p><p>In any case, subscribe to the newsletter to make sure you don&#8217;t miss any new tutorials.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>Perfect, let&#8217;s get started!</p><div><hr></div><h2>Will being a Help Desk Operator through Intune RBAC be enough?</h2><p>Our main character is <strong>Hazel</strong>, a help desk operator, who already has the <strong>Help Desk Operator</strong> role assigned via Intune RBAC. But&#8230; will that be sufficient?</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;d109cd39-144a-49bf-b226-447ff39faa0a&quot;,&quot;duration&quot;:null}"></div><p>Even though Hazel has the correct role in Intune, <strong>she won&#8217;t be able to view the BitLocker keys</strong>. Why? Because this permission is not managed by Intune, but by <strong>Microsoft Entra</strong>.</p><p>With a Zero Trust Security approach, let&#8217;s see how to grant the minimum permissions needed to allow Hazel to read the BitLocker recovery keys of devices managed by Intune.</p><h2>&#128736;&#65039; Create a group assignable to Entra roles</h2><p>First, we need to create a security group that can be assigned to Entra roles.</p><blockquote><p>&#9888;&#65039; <strong>Attention</strong>: this option can only be <strong>enabled at the moment of group creation and cannot be modified later</strong>.</p></blockquote><p>Once the group is created, we add Hazel as a member.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;642fd08f-295c-4386-baf7-872dedb21272&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#129513; Create the custom role in Entra</h2><p>Now let&#8217;s create a <strong>custom role</strong> in Entra. The permissions we need are:</p><pre><code><code>microsoft.directory/deviceBitLockerKeys/read
microsoft.directory/bitlockerKeys/metadata/read</code></code></pre><p>This allows reading the BitLocker recovery keys associated with devices registered in Entra.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;0d365360-fa2b-4b52-9f4b-3c5621128711&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128279; Assign the role to the group</h2><p>With the role ready and the group created, we can proceed with assigning the custom role to the group that contains Hazel. This is the step that effectively enables the visualization of the keys.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;79bb138f-5a83-49f9-adaf-dd7977c5dc3b&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#9989; Verification: can Hazel see the keys now?</h2><p>Let&#8217;s go back to Intune and log in with Hazel&#8217;s account. This time, thanks to the Entra role, she will be able to correctly view the BitLocker keys of the devices.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c7d37a76-7bde-4ba4-90e3-cc423feca57b&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128218; Attached documentation and useful links</h2><p>To explore the topic further, here are some official documents with a hint <a href="https://sallysbakingaddiction.com/best-pumpkin-cake/">pumpkin cake</a>:</p><ul><li><p>&#128206; <a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-create?tabs=admin-center">Create a custom role in Microsoft Entra ID</a> </p></li><li><p>&#128206; <a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/custom-overview">Overview of role-based access control in Microsoft Entra ID</a> </p></li><li><p>&#128206; <a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/manage-roles-portal?tabs=admin-center">Assign Microsoft Entra roles </a></p></li></ul><div><hr></div><h2>&#128236; Conclusions</h2><p>We&#8217;ve seen how a simple Intune role is not enough to access BitLocker keys, and how to solve the problem with a custom role in Entra.</p><p>If you found this useful, subscribe to the ITSpecialist.News newsletter to receive more practical content, guides, and updates from the Microsoft 365 world.</p><p>As always, thank you for following me this far!</p><p>See you soon&#8230; LEGENDS!</p><p>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Disable synchronization between Active Directory and Entra using Graph Explorer]]></title><description><![CDATA[Disable synchronization between Active Directory and Entra ID: a practical step-by-step guide using Graph Explorer and PowerShell.]]></description><link>https://www.itspecialist.news/p/disable-synchronization-between-active-directory-and-entra-id</link><guid isPermaLink="false">https://www.itspecialist.news/p/disable-synchronization-between-active-directory-and-entra-id</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Thu, 02 Oct 2025 09:25:44 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/d6008d95-6952-4189-9d09-c68e35e34a41_1579x805.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>An era ends in my Lab. I&#8217;ve decided to decommission all on-premises components: domain controller, certification authority, and the Entra Connect server, rolling back my tenant to be cloud-only. Here are two methods to do it, one using Microsoft Graph Explorer and the other with PowerShell.</p><h2>&#129517; Objective</h2><p>Disable synchronization with Active Directory and remove on-premises attributes from synchronized users, making everything cloud-only.</p><h2>&#9888;&#65039; Disclaimer</h2><blockquote><p><strong>You should not use this method for any kind of troubleshooting. Disabling synchronization between AD and Entra is an action to be taken only if you intend to permanently convert your users to cloud-only.</strong></p><p><strong>If you&#8217;re doing this in a production environment, make sure you&#8217;ve completed all the necessary preparatory steps to do it safely.</strong></p><p><strong>The information and procedures described in this document are provided for informational purposes only and must be executed with the utmost caution. I take no responsibility for any damage, service interruptions, or data loss resulting from the application of the instructions provided, especially if implemented in production environments.<br>It is strongly recommended to always test these procedures in a development or staging environment before applying them in production, and to perform full backups of all involved systems.</strong></p></blockquote><p>Furthermore:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rYnM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rYnM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 424w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 848w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 1272w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rYnM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png" width="1456" height="374" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baa0854f-ac7c-411b-b149-00317c111024_1738x446.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:374,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86770,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/175090695?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!rYnM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 424w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 848w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 1272w, https://substackcdn.com/image/fetch/$s_!rYnM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa0854f-ac7c-411b-b149-00317c111024_1738x446.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>&#128206; Source</strong>: <a href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/turn-off-directory-synchronization?view=o365-worldwide">Turn off directory synchronization for Microsoft 365 - Microsoft 365 Enterprise | Microsoft Learn</a></p><h2>&#128736;&#65039; Method 1: Microsoft Graph Explorer</h2><ol><li><p><strong>Sign in to Microsoft Graph Explorer</strong><br>Go to Microsoft Graph Explorer and sign in with a <strong>Global Administrator</strong> account.</p></li><li><p><strong>Modify permissions</strong><br>In the <strong>Modify Permissions</strong> section, grant the <strong>Organization.ReadWrite.All</strong> permission.</p></li><li><p><strong>Run the PATCH request</strong><br>Enter the following request, replacing <strong>{organization-id}</strong> with your <strong>Tenant ID</strong>:</p></li></ol><pre><code><code>PATCH https://graph.microsoft.com/beta/organization/{organization-id}</code></code></pre><ol start="4"><li><p><strong>Request body (JSON)</strong></p></li></ol><pre><code>{
  "onPremisesSyncEnabled": false
}</code></pre><ol start="5"><li><p><strong>Execute the query</strong><br>Click <strong>Run Query</strong>. Changes may take anywhere from <strong>4&#8211;5 minutes up to 72 hours</strong> to reflect in the Azure portal, depending on the size of the objects.</p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-mzm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-mzm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 424w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 848w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 1272w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-mzm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png" width="1456" height="742" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:742,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:59773,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/175090695?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-mzm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 424w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 848w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 1272w, https://substackcdn.com/image/fetch/$s_!-mzm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f2260bd-d916-4872-8b7c-21d879128499_1579x805.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>&#128736;&#65039; Method 2: Microsoft Graph PowerShell</h2><ol><li><p><strong>Install the PowerShell modules</strong></p></li></ol><pre><code><code>Install-Module Microsoft.Graph -Force
Install-Module Microsoft.Graph.Beta -AllowClobber -Force</code></code></pre><ol start="2"><li><p><strong>Connect with the administrator account</strong></p></li></ol><pre><code><code>Connect-MgGraph -Scopes &#8220;Organization.ReadWrite.All,Directory.ReadWrite.All&#8221;</code></code></pre><ol start="3"><li><p><strong>Check the current synchronization status</strong></p></li></ol><pre><code><code>Get-MgOrganization | Select OnPremisesSyncEnabled</code></code></pre><ol start="4"><li><p><strong>Store the Tenant ID and parameters</strong></p></li></ol><pre><code><code>$organizationId = (Get-MgOrganization).Id
$params = @{ onPremisesSyncEnabled = $false }
</code></code></pre><ol start="5"><li><p><strong>Update the configuration</strong></p></li></ol><pre><code><code>Update-MgOrganization -OrganizationId $organizationId -BodyParameter $params</code></code></pre><ol start="6"><li><p><strong>Verify the change</strong></p></li></ol><pre><code><code>Get-MgOrganization | Select OnPremisesSyncEnabled</code></code></pre><p>Below is the full script:</p><pre><code># Install v1.0 and beta Microsoft Graph PowerShell modules 
  Install-Module Microsoft.Graph -Force
  Install-Module Microsoft.Graph.Beta -AllowClobber -Force 
  
  # Connect With Hybrid Identity Administrator Account
  Connect-MgGraph -scopes &#8220;Organization.ReadWrite.All,Directory.ReadWrite.All&#8221; 
  
  # Verify the current status of the DirSync Type
  Get-MgOrganization | Select OnPremisesSyncEnabled 
  
  # Store the Tenant ID in a variable named organizationId
  $organizationId = (Get-MgOrganization).Id 
  
  # Store the False value for the DirSyncEnabled Attribute
  $params = @{
  &#9;onPremisesSyncEnabled = $false
  }
  
  # Perform the update
  Update-MgOrganization -OrganizationId $organizationId -BodyParameter $params 
  
  # Check that the command worked
  Get-MgOrganization | Select OnPremisesSyncEnabled</code></pre><p><strong>&#128206; Source</strong>: <a href="https://learn.microsoft.com/en-us/microsoft-365/enterprise/turn-off-directory-synchronization?view=o365-worldwide#turn-off-directory-synchronization">Turn off directory synchronization for Microsoft 365 - Microsoft 365 Enterprise | Microsoft Learn</a></p><h2>&#9989; <strong>Final Result and Conclusions</strong></h2><p>Once the procedure is completed, previously synchronized users will be converted into cloud-only users.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sfo5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sfo5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 424w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 848w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 1272w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sfo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png" width="1456" height="781" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:781,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:681743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/175090695?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sfo5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 424w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 848w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 1272w, https://substackcdn.com/image/fetch/$s_!sfo5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F890b44d7-a2fe-48ba-8ba6-38aa8442e920_2219x1190.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Enjoy!</p><p>Riccardo</p><p></p>]]></content:encoded></item><item><title><![CDATA[LAPS for macOS with Microsoft Intune]]></title><description><![CDATA[Watch now | Learn how to configure LAPS for macOS with Microsoft Intune. A complete guide to strengthening your IT infrastructure security with automated, unique passwords for every device.]]></description><link>https://www.itspecialist.news/p/macos-laps-with-microsoft-intune</link><guid isPermaLink="false">https://www.itspecialist.news/p/macos-laps-with-microsoft-intune</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 24 Sep 2025 18:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/174758999/63388e4a781ec8de3f0090691a34380e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>If you work with Microsoft Intune and Apple devices, this is the news you&#8217;ve been waiting for: LAPS for macOS is finally available! It&#8217;s a feature long requested by many IT Specialists, and today I&#8217;ll walk you through how it works and what&#8217;s different compared to the Windows version.</p><div><hr></div><h2>&#128240; What do you prefer? Video or article?</h2><p>Here are a few notes to help you get the most out of this content.</p><ul><li><p>If you&#8217;d rather watch the full video, easy: you&#8217;ll find it right above in the header.</p></li><li><p>If you prefer reading, that&#8217;s just as easy: keep scrolling here. For each step, I&#8217;ve included the exact video snippet, so you&#8217;ll only see the screens that matter&#8212;without my face talking in between.</p></li></ul><p>Either way, make sure to subscribe to the newsletter so you won&#8217;t miss any of my upcoming tutorials.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>Perfect, let&#8217;s get started!</p><div><hr></div><h2>What is LAPS</h2><p>LAPS, short for <em>Local Administrator Password Solution</em>, is a technology that allows you to securely and automatically manage the local administrator account password on a device.</p><p>What is it for? Its purpose is to prevent the same password from being reused across multiple devices, reducing the risk of lateral movement and improving the overall security of your infrastructure.</p><h2>Things to consider before implementing LAPS for macOS</h2><p>Before you start configuring LAPS for macOS, here are three key points to keep in mind:</p><ul><li><p>You cannot choose the length or complexity of the password: it is defined by Microsoft and will always be 15 characters long, including uppercase and lowercase letters, numbers, and special characters.</p></li><li><p>Password rotation is fixed: it occurs every 6 months, with no customization options.</p></li><li><p>Configuration takes place in the enrollment profile associated with the Enrollment Token Program: therefore, the Mac must be supervised, enrolled via ADE, and registered in Apple Business Manager.</p></li></ul><p><em><strong>Note:</strong> Points 1 and 2 represent a major difference compared to the configuration options available with LAPS for Windows. At the time of writing this article (September 2025), this is the current state of the technology. It may change in the future, but for now, this is how it works.</em></p><h2>Configurazione del LAPS nel profilo di enrollment</h2><p>Now let&#8217;s go into Intune to see how to configure LAPS for macOS. In the following example, I used a mix of static text and variables for the local administrator username, choosing the format <code>admin-</code>. I also chose to hide the administrative account in the <em>Users &amp; Groups</em> panel as an additional measure to obscure the presence of the admin account.</p><blockquote><p><strong>These configurations are just an example to illustrate the customization possibilities: it&#8217;s important to select the most appropriate settings for your own infrastructure. Remember that this option is only available if the Mac has been properly enrolled via ADE and is supervised.</strong></p></blockquote><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;cc7ce6a5-daea-4fc6-93ce-2b47d724e9e8&quot;,&quot;duration&quot;:null}"></div><h2>Final Result</h2><p>Once everything is configured, here&#8217;s what happens on the Mac at the time of enrollment: the local administrator account password is generated automatically, it is unique for each device, and you can view it directly in Intune whenever you need it for technical interventions.</p><blockquote><p>Configuring LAPS by modifying an existing enrollment profile has no effect on Macs that are already associated with that profile and enrolled. The configuration will only take effect once the Mac is reset and re-enrolled.</p></blockquote><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;f93923f8-6baf-470d-aa14-1a124f82ffa4&quot;,&quot;duration&quot;:null}"></div><h2>Role Based Access Control for the new macOS LAPS</h2><p>With the release of the new feature, the corresponding RBAC controls have also been introduced, allowing you to grant permissions to rotate the local Mac admin password without necessarily being an Intune Administrator.</p><p>The settings can be found under the <strong>Enrollment programs</strong> category:</p><ul><li><p><strong>Rotate macOS admin password</strong></p></li><li><p><strong>View macOS admin password</strong></p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!viPV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!viPV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 424w, https://substackcdn.com/image/fetch/$s_!viPV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 848w, https://substackcdn.com/image/fetch/$s_!viPV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 1272w, https://substackcdn.com/image/fetch/$s_!viPV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!viPV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png" width="1456" height="481" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:481,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:66812,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/170545830?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!viPV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 424w, https://substackcdn.com/image/fetch/$s_!viPV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 848w, https://substackcdn.com/image/fetch/$s_!viPV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 1272w, https://substackcdn.com/image/fetch/$s_!viPV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F91b35d7f-d66d-487f-a213-5fdeefec60f9_1604x530.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Attached Documentation</h2><p>To explore further, here are some links to Microsoft&#8217;s official documentation:</p><ul><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/macos-laps">Set up local admin account creation and password management for macOS devices</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/create-custom-role">Create a custom role in Intune</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos">Set up automated device enrollment (ADE) for macOS</a></p></li><li><p><a href="https://learn.microsoft.com/en-us/intune/intune-service/enrollment/device-enrollment-program-enroll-macos#create-an-apple-enrollment-profile">Create an Apple enrollment profile</a></p></li></ul><h2>Takeaways</h2><p>Thank you for reading this article! I hope it helped you understand how LAPS for macOS works and how you can start using it right away in your infrastructure.</p><p>If you&#8217;d like to support my work and stay up to date with the latest IT news, subscribe to ITSpecialist.News, your support is essential to keep creating content like this.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>See you soon&#8230; LEGENDARY!</p><p>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Windows Autopilot Device Preparation (Autopilot v2)]]></title><description><![CDATA[Watch Now | Simplify PC Provisioning with Windows Autopilot Device Preparation: A Step-by-Step Practical Guide for IT Administrators]]></description><link>https://www.itspecialist.news/p/windows-autopilot-device-preparation-eng</link><guid isPermaLink="false">https://www.itspecialist.news/p/windows-autopilot-device-preparation-eng</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 06 Aug 2025 06:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/174763432/416d6371f7a764a6d3964a4fdbc5f270.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hi there! For a year now, everyone&#8217;s been asking me about this, and finally here we are: today we&#8217;re talking about <strong>Windows Autopilot Device Preparation</strong> or, as friends call it, <strong>Autopilot v2</strong>. This is the new version of Windows Autopilot, designed to simplify and speed up the setup of corporate devices.</p><p>This video is a bit longer than usual, but it&#8217;s absolutely worth it. So sit back, spritz in hand, and let&#8217;s get started!</p><div><hr></div><h2>&#128240; What do you prefer? Video or article?</h2><p>Some notes to help you get the most out of this content.</p><ul><li><p>If you&#8217;d rather watch the full video, easy: you&#8217;ll find it right above in the header.</p></li><li><p>If you&#8217;d rather read, that&#8217;s just as easy: simply keep scrolling here. For each step, I&#8217;ve included the specific video clip, so you&#8217;ll only see the screens that matter&#8212;without my face talking at you.</p></li></ul><p>Either way, make sure to subscribe to the newsletter so you don&#8217;t miss any of my upcoming tutorials.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>Ok, let&#8217;s get started!</p><div><hr></div><h2>What is Windows Autopilot Device Preparation?</h2><p>Windows Autopilot Device Preparation is a Microsoft solution that automates and standardizes the process of configuring corporate PCs. Each device is prepared quickly, securely, and in compliance with company policies&#8212;without any manual intervention from IT administrators.</p><p>In short? A magic wand for anyone who wants to simplify deployment.</p><h2>Key Differences Compared to Autopilot v1</h2><ul><li><p><strong>No more hardware hash</strong>: the PC&#8217;s serial number is enough.</p></li><li><p><strong>Entra Join only</strong>: no hybrid mode (with Active Directory domain join). For those who still need it, the classic version of Autopilot remains available.</p></li><li><p><strong>No PC name templates</strong>: but this can be worked around with a script.</p></li></ul><p>A more detailed comparison table between Autopilot v1 and v2 follows below.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6feq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6feq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 424w, https://substackcdn.com/image/fetch/$s_!6feq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 848w, https://substackcdn.com/image/fetch/$s_!6feq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!6feq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6feq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png" width="1240" height="1028" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1028,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:186410,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/174763432?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6feq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 424w, https://substackcdn.com/image/fetch/$s_!6feq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 848w, https://substackcdn.com/image/fetch/$s_!6feq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 1272w, https://substackcdn.com/image/fetch/$s_!6feq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F59c48ecd-1788-403a-9e64-dba40d69bc4e_1240x1028.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><h2>&#128296; Requirements</h2><p>Make sure you have all the necessary requirements in place.<br>As per my usual style, here&#8217;s some summer-flavored documentation, with just a hint of sunscreen. &#128522;</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/requirements?tabs=software">Windows Autopilot device preparation requirements | Microsoft Learn</a></p><div><hr></div><h2>&#129706; Verify Autoenrollment and Entra Join Permissions</h2><p>To make Autopilot Device Preparation work, make sure that:</p><ul><li><p>Users have the necessary permissions for autoenrollment in Intune.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;26aef132-b644-4bd7-a5da-405d29e10860&quot;,&quot;duration&quot;:null}"></div><p></p></li><li><p>Users must be able to perform <strong>Entra Join</strong>.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;9faab436-3108-4587-8ceb-5eea8f02f771&quot;,&quot;duration&quot;:null}"></div></li></ul><div><hr></div><h2>&#128421;&#65039; Create a Static Device Group</h2><p>Create a static group in Intune and set as owner a specific Service Principal called <strong>Intune Provisioning Client</strong>, which has the following AppId: </p><pre><code>f1346770-5b25-470b-88bd-d5744ab7952c</code></pre><p>This service principal has an AppId that is the same across all tenants.</p><p><strong>If you don&#8217;t find any service principal corresponding to this Id in your tenant, you&#8217;ll need to create it</strong>. No worries, it only takes a few PowerShell commands.</p><pre><code><code>Install-Module Microsoft.Graph.Authentication
Install-Module Microsoft.Graph.Applications
Connect-MgGraph -Scopes "Application.ReadWrite.All"
New-MgServicePrincipal -AppID f1346770-5b25-470b-88bd-d5744ab7952c</code></code></pre><p>This group will be automatically populated with the devices registered in the Corporate Identifiers (we&#8217;ll get to that shortly). That&#8217;s right, you won&#8217;t need to populate it yourself, it will be filled automatically!</p><p>In the meantime, create the group and remember to set the service principal as the Owner: this step is essential!</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;c7fa7f49-c582-4749-9106-bb46d5ccbc82&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128111; Create a Static User Group</h2><p>Create a static user group and add the people you want to include in the Autopilot scope.<br>In this case, unlike the device group, you&#8217;ll be the one populating it manually.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;0ed10e9e-d697-44fe-9a8d-8cc5919cccff&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128290; Serial Number Registration in Corporate Device Identifiers</h2><p>Enter the serial numbers of your PCs into the Corporate Device Identifiers.<br>This allows the device to immediately recognize that it&#8217;s managed by Autopilot.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;54bd0b59-e6d0-4a57-b5e1-3d9a58d13076&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#129668; Creating the Autopilot Policy</h2><p>We&#8217;ve finally reached the heart of the process: the <strong>Autopilot Device Preparation policy</strong>. This is where you&#8217;ll configure:</p><ul><li><p>Deployment settings</p></li><li><p>Security configurations</p></li><li><p>Apps or scripts to install during the initial phase</p></li></ul><p>Let&#8217;s just say that with this policy, we&#8217;re tying together all the configurations we&#8217;ve made so far.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;4eaf8f65-3af4-4114-a69e-3b68ccbd6b48&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128187; Hands-On Test on a PC (Shortened OOBE Phase)</h2><p>Let&#8217;s power on a PC and walk through the OOBE (Out-Of-Box Experience) phase.<br>The video is sped up to show you the entire process from A to Z.</p><div class="native-video-embed" data-component-name="VideoPlaceholder" data-attrs="{&quot;mediaUploadId&quot;:&quot;d82887f0-73ff-4d04-b2ac-1aea6013229a&quot;,&quot;duration&quot;:null}"></div><div><hr></div><h2>&#128195; Attached Documentation</h2><p>You wouldn&#8217;t want to miss this truckload of documentation while lounging under your beach umbrella, would you? &#128516;</p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/whats-new">What's new in Windows Autopilot device preparation | Microsoft Learn</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/overview">Overview of Windows Autopilot device preparation | Microsoft Learn</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/tutorial/scenarios">Windows Autopilot device preparation scenarios | Microsoft Learn</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/faq">Windows Autopilot device preparation FAQ | Microsoft Learn</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/troubleshooting-faq">Windows Autopilot troubleshooting FAQ | Microsoft Learn</a></p><p>&#128206; <a href="https://learn.microsoft.com/en-us/autopilot/device-preparation/known-issues">Windows Autopilot device preparation known issues | Microsoft Learn</a></p><h2>&#128235; Wrap-Up</h2><p>In short:</p><ul><li><p>Automation</p></li><li><p>Speed</p></li><li><p>Fewer errors</p></li><li><p>Less manual work</p></li><li><p>More focus on the user</p></li></ul><p>Windows Autopilot Device Preparation makes device onboarding easier&#8212;for both IT and end users. And finally&#8230; no more hash calculations! &#129395;</p><p>I hope you enjoyed this video, even if it was a bit longer and more intense than usual&#8212;thank you!</p><p>Subscribe to the ITSpecialist.News newsletter to stay up to date with all the latest from the Microsoft world. It means a lot to me and really shows your support.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.itspecialist.news/subscribe?&quot;,&quot;text&quot;:&quot;Iscriviti ora&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.itspecialist.news/subscribe?"><span>Iscriviti ora</span></a></p><p>See you soon&#8230; LEGENDARY!</p>]]></content:encoded></item><item><title><![CDATA[Microsoft 365 Copilot in the macOS dock]]></title><description><![CDATA[Watch now | How to deploy a Microsoft 365 Copilot webclip on the macOS dock via Microsoft Intune]]></description><link>https://www.itspecialist.news/p/microsoft-365-copilot-in-the-macos-dock</link><guid isPermaLink="false">https://www.itspecialist.news/p/microsoft-365-copilot-in-the-macos-dock</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 28 May 2025 06:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/192101812/bc2bca8f1bd30c66ef6ffc9cd10ee18f.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<h2>Small small intro, I promise!</h2><p>Hi! A quick intro before we start the article: I'm publishing here on the newsletter the first technical content, starting with a video/article that I had actually already published. I'm doing this for two reasons:</p><ol><li><p>To get familiar with the Substack platform</p></li><li><p>Because on LinkedIn, thanks to the magic of the algorithm, nobody (and when I say nobody, this is very close to the literal meaning of the word) had seen this content.</p></li></ol><p>I&#8217;ve almost decided that I&#8217;ll follow an &#8220;alternating&#8221; editorial plan: when there&#8217;s new and specific technical content (like today&#8217;s, for example), the newsletter will be a kind of &#8220;text&#8221; version of the video.<br>In other newsletter issues, I&#8217;ll collect some useful info, highlighting interesting community articles, events, official Microsoft news, and so on.</p><p>What do you think?</p><h2>Ok, let's really get started&#8230;</h2><p>In this article, we'll explore how to simplify the daily experience of using Microsoft 365 Copilot on macOS, through a wepclip. </p><h2>What is a web clip in macOS?</h2><p>A webclip is a quick way to reach our favorite websites, by pinning an icon on the macOS dock. Through Intune we can natively manage webclips, simplifying access to Microsoft 365 Copilot. I used a web clip because, at the time I'm publishing this article, there is no official app yet on the Mac App Store for Microsoft 365 Copilot.</p><p>This is the URL the web clip will point to:</p><pre><code>https://m365.cloud.microsoft/chat</code></pre><p>Let's see right away how to create the policy and deploy the web clip."</p><div id="youtube2-fcVwhJPKtYk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;fcVwhJPKtYk&quot;,&quot;startTime&quot;:&quot;142&quot;,&quot;endTime&quot;:&quot;194&quot;}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/fcVwhJPKtYk?start=142&amp;end=194&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Verifying the webclip on the Mac</h2><p>After deploying the webclip, let's verify that it has been correctly placed on our Mac's dock. The webclip should appear at the bottom right, in a specific area of the dock.</p><div id="youtube2-fcVwhJPKtYk" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;fcVwhJPKtYk&quot;,&quot;startTime&quot;:&quot;211&quot;,&quot;endTime&quot;:&quot;218&quot;}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/fcVwhJPKtYk?start=211&amp;end=218&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h2>Attached documentation</h2><p>As always, here is some useful documentation:</p><p>&#128206; <a href="https://substack.com/redirect/5e07c5b3-b71e-4843-8f3a-20f0b9915079?j=eyJ1IjoiMjVoZTQzIn0.sz5YLxjZNyL5d_2VY3RVvRfcvKcmU_c84ms-nXlWF-0">Add web apps to Microsoft Intune</a></p><h2>Conclusions</h2><p>We've seen how to use Intune to create and deploy a webclip that points to Microsoft 365 Copilot, simplifying access to Copilot on macOS. This workaround allows us to replicate a behavior similar to pinning on the Windows taskbar, improving the Microsoft 365 Copilot user experience. Thank you for following this article all the way to the end.</p><p>See you soon, you legend!<br>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Launching Microsoft 365 Copilot with a single key mapped via Microsoft Intune]]></title><description><![CDATA[Watch now | Streamline the Microsoft 365 Copilot user experience by using Microsoft Intune policies to map the physical Copilot key on newer PCs]]></description><link>https://www.itspecialist.news/p/launching-microsoft-365-copilot-with-copilot-key-mapped-via-microsoft-intune</link><guid isPermaLink="false">https://www.itspecialist.news/p/launching-microsoft-365-copilot-with-copilot-key-mapped-via-microsoft-intune</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Wed, 30 Apr 2025 06:00:00 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/192827507/86d83b09242bd51e8091a3488dc4e4f0.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>Hi everyone, IT specialists! In this article, we continue our mini-series on how to simplify the Microsoft 365 Copilot and Microsoft 365 Copilot Chat user experience by using Microsoft Intune policies. Today, we will see how to map the physical Copilot key on newer PCs to launch the app with a single key press.</p><blockquote><p><strong>Please note: the video is narrated in Italian. English subtitles are available for non-Italian speakers.</strong></p></blockquote><h2>Mapping the physical Copilot key</h2><p>Today we focus on mapping the physical Copilot key, available on newer PCs. This key lets you launch the Microsoft 365 Copilot app with a single tap, further simplifying the user experience. To achieve this, we use a custom Microsoft Intune OMA-URI.</p><p>Let&#8217;s see right away how to create the policy and deploy this setting.</p><h2>Creating a custom OMA-URI</h2><p>Creating a custom OMA-URI is a quick and simple process: the specific details of the OMA-URI used are available below, right after the video snippet.</p><div id="youtube2-afa98hkVrn4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;afa98hkVrn4&quot;,&quot;startTime&quot;:&quot;78&quot;,&quot;endTime&quot;:&quot;133&quot;}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/afa98hkVrn4?start=78&amp;end=133&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><pre><code><code>&#10145;&#65039; Name: SetCopilotHardwareKey
&#10145;&#65039; OMA-URI: ./User/Vendor/MSFT/Policy/Config/WindowsAI/SetCopilotHardwareKey
&#10145;&#65039; Data type: String
&#10145;&#65039; Value: Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe!Microsoft.MicrosoftOfficeHub</code></code></pre><h2>Verification of policy application</h2><p>Let&#8217;s see what happens on the Windows client in the personalization panel.</p><div id="youtube2-afa98hkVrn4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;afa98hkVrn4&quot;,&quot;startTime&quot;:&quot;143&quot;,&quot;endTime&quot;:&quot;157&quot;}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/afa98hkVrn4?start=143&amp;end=157&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><h3>Test with the Copilot key</h3><p>It&#8217;s time to press the key and see if everything works!</p><div id="youtube2-afa98hkVrn4" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;afa98hkVrn4&quot;,&quot;startTime&quot;:&quot;166&quot;,&quot;endTime&quot;:&quot;172&quot;}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/afa98hkVrn4?start=166&amp;end=172&amp;rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Perfect, everything works! &#128522;</p><h2>Attached documentation</h2><p>As always, here is some useful documentation:</p><p>&#128204; <a href="https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-windowsai#setcopilothardwarekey">SetCopilotHardwareKey</a><br>&#128204; <a href="https://learn.microsoft.com/en-us/windows/configuration/store/find-aumid?tabs=ps%2Cexplorer&amp;pivots=windows-11">How to find the AUMID</a></p><h2>Conclusions</h2><p>Thank you for following this article all the way to the end! Implementing these policies is an effective way to streamline the Microsoft 365 Copilot user experience. If you already have PCs with the physical Copilot key in your device fleet, this policy is simple to implement and offers great benefits.</p><p>Let me know what you think in the comments of the video or on my social profiles!</p><p>See you soon, legends!</p><p>Your IT Specialist,<br>Riccardo</p>]]></content:encoded></item><item><title><![CDATA[Microsoft Entra ID Protection: what is Risk in Entra ID?]]></title><description><![CDATA[How Microsoft Entra ID Protection works and what the concept of risk means when applied to a user and a sign-in.]]></description><link>https://www.itspecialist.news/p/microsoft-entra-id-protection-what</link><guid isPermaLink="false">https://www.itspecialist.news/p/microsoft-entra-id-protection-what</guid><dc:creator><![CDATA[Riccardo Corna]]></dc:creator><pubDate>Fri, 06 Oct 2023 06:00:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sS4u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In a Zero Trust Security approach, where identity is a fundamental element, the security of authentications can be measured to some extent based on the so-called &#8220;signals&#8221;. Analyzing these signals provides a level of &#8220;risk&#8221; for a particular user when authenticating to Microsoft 365 services. Today, I&#8217;ll tell you about Mirosoft Entra Identity Protection and what the concept of &#8220;risk&#8221; means.</p><p>As always, before diving headfirst into this &#8220;risky&#8221; journey (pun intended &#129315;), we need to introduce another concept: you need to understand what <strong>signals</strong> are.</p><h2>What is a signal?</h2><p>In Entra ID, a signal is defined as a property or a particular condition that a user and an authentication have. Here are some examples:</p><ul><li><p>User&#8217;s IP address</p></li><li><p>IP and user geolocation</p></li><li><p>Application they are trying to access.</p></li><li><p>The operating system of the device they are using (Windows, Linux, macOS, iOS, Android?)</p></li><li><p>What type of client the user is using to access M365 services? An app that supports Modern Authentication, a browser, or an app that only supports legacy authentication?</p></li><li><p>If it&#8217;s a browser, which browser?</p></li><li><p>Which Azure AD groups does their account belong to?</p></li><li><p>And so on&#8230;</p></li></ul><p>These are all <strong>signals</strong>, and as you can see, Entra ID is capable of detecting many of them.</p><p>You might be wondering: <em>&#8221;Rick, why are you bothering me with this signal stuff?&#8221;</em></p><p>I&#8217;ll answer that without too much beating around the bush: <strong>because &#8220;risk&#8221; is a signal</strong>!</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sS4u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sS4u!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 424w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 848w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 1272w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sS4u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png" width="886" height="360" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:360,&quot;width&quot;:886,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:86838,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/174761520?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sS4u!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 424w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 848w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 1272w, https://substackcdn.com/image/fetch/$s_!sS4u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92c51df3-c243-42af-8420-0bcbcb559e2f_886x360.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And so, how does risk fit in among the signals, and what is it?</p><h2>What is risk in Entra ID Protection?</h2><p>In Entra ID Protection, risk is an assessment of user actions, authentications, and their properties. <strong>Cross-analysis of user properties and actions provides an assessment of how clean or suspicious the authentication is and how secure or insecure the user is</strong>.</p><p>Risk can be:</p><ul><li><p>Calculated in real-time (evaluations available in 5/10 minutes)</p></li><li><p>Calculated by Microsoft cloud intelligence based on an analysis of authentication events in your tenant, which happens in the background (evaluations available in a few hours)</p></li></ul><p>It is further divided into two types:</p><ul><li><p>User Risk</p></li><li><p>Sign-in Risk</p></li></ul><h2>User Risk</h2><p>Here are the risk signals associated with a user.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AKFT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AKFT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 424w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 848w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 1272w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AKFT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png" width="1240" height="1966" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1966,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385823,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/174761520?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fddc34ecb-4ff8-49d7-a9a5-3891be14c061_1240x2046.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AKFT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 424w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 848w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 1272w, https://substackcdn.com/image/fetch/$s_!AKFT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6bd40cc3-715b-4011-adf0-8b6014519744_1240x1966.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These signals are constantly updated and improved. The ones listed above are those available at the time of writing this article. If you want to ensure you are always up to date, I recommend referring to the official documentation:</p><ul><li><p><a href="https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks">What are risk detections? | Microsoft Docs</a></p></li></ul><h2>Sign-in Risk</h2><p>Here are the risk signals associated with a single authentication.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e0n4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e0n4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 424w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 848w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 1272w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e0n4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png" width="1240" height="7134" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:7134,&quot;width&quot;:1240,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1200357,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.itspecialist.news/i/174761520?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e0n4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 424w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 848w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 1272w, https://substackcdn.com/image/fetch/$s_!e0n4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F29ed62bb-41c6-47e7-8528-94c0981e9e53_1240x7134.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>These signals are constantly updated and improved. The ones listed above are those available at the time of writing this article. If you want to ensure you are always up to date, I recommend referring to the official documentation:</p><ul><li><p><a href="https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/concept-identity-protection-risks">What are risk detections? | Microsoft Docs</a></p></li></ul><h2>How can risk in Entra ID Protection be useful?</h2><p>The concept of risk is <strong>extremely useful</strong> when used in combination with <strong>Conditional Access </strong>and <strong>Multi-Factor Authentication</strong>! Even more so if you have access to Azure Sentinel and want to automate automatic responses.</p><p>Concrete examples? Here they are:</p><ul><li><p>If two authentications from Italy and Spain are detected within 5 minutes (impossible travel), I request Multi-Factor Authentication for access (Conditional Access + MFA).</p></li><li><p>If it&#8217;s detected that the user&#8217;s password matches one found in public lists of compromised credentials (risk), I block the authentication (Conditional Access), raise an incident, and lock the user account (Azure Sentinel).</p></li></ul><h2>Where can you find risk assessments and events?</h2><p>You can simply navigate to the Entra ID portal under</p><p><strong>Microsoft Entra ID</strong> -&gt; <strong>Security </strong>-&gt; <strong>Identity Protection</strong>.</p><h2>License requirements for Entra ID Protection</h2><p>Here&#8217;s an official Microsoft document that will clarify which licenses are required to take advantage of these features:</p><ul><li><p><a href="https://docs.microsoft.com/en-us/azure/active-directory/identity-protection/overview-identity-protection#license-requirements">License Requirements | Microsoft Docs</a></p></li></ul><h2>Conclusions on risk and Entra ID Protection</h2><p>As you can see, the limit to securing your identities in a simple and automated way is only your imagination and, of course, a careful analysis of your needs and environment.</p><p>Are you already using Entra ID Protection? Have you automated reactions in case of high risk? Let&#8217;s discuss it in the comments or on my social media channels; I&#8217;m here!</p><p>Your IT Specialist,</p><p>Riccardo</p>]]></content:encoded></item></channel></rss>