HomeNewsletterCommunityMVP FeedToolsArchiveBlogToday's NewsAboutServicesQuick Links Subscribe free
Imran Awan — EndpointWeekly

Blog

Thoughts on Microsoft endpoint management, IT leadership and building a newsletter in public.

Live · Updated daily at 07:00 UTC
What's New Today — Official Vendor News
Today's announcements direct from Microsoft, OpenAI and Google. No community blogs — vendor sources only.
View today's news →
Security 13 August 2026
BlackLotus Isn't Fixed When the Certificate Updates: Tracking All Four Secure Boot Mitigations
Your Secure Boot report shows the 2023 certificate installed - but CVE-2023-24932 (BlackLotus) needs four sequential mitigations to actually close, and a cert-only check misses the other three. What each mitigation does, the registry bitmask that tracks them, and a ConfigMgr hardware inventory technique for fleet-wide tracking that Intune's own report doesn't cover.
IA
Imran Awan
👁 Read post →
Windows Update 12 August 2026
KB5121003 and KB5120240: What's Actually New in August 2026's Patch Tuesday
KB5121003 (24H2/25H2, builds 26200.9168 / 26100.9168) and KB5120240 (23H2, build 22631.7517) landed 11 August 2026 with no known issues - but File Explorer, Search and Windows Hello ESS changes roll out gradually via Controlled Feature Rollout. What's actually in it, why some devices won't show it yet, and a script to confirm your fleet landed on the right build.
IA
Imran Awan
👁 Read post →
Microsoft Entra ID 11 August 2026
SMS and Voice MFA Are Being Retired in Entra ID: A Scenario-Based Guide to What Replaces Them
Passkeys become the Entra ID default on 1 September 2026 and SMS/voice MFA retires on 1 February 2027 - but one blanket replacement for everyone is the wrong call. A scenario-based framework for office users, admins, frontline shared devices, and onboarding/recovery, with a read-only readiness audit script.
IA
Imran Awan
👁 Read post →
Security 9 August 2026
Microsoft Edge Now Lets Users Sign In With Google — Here's What Enterprise Admins Need to Do
Edge now shows a Google sign-in option for browser profiles. On managed endpoints, that means corporate passwords and history can sync to a personal Google account.
IA
Imran Awan
👁 Read post →
Security 9 August 2026
Device Code Phishing: How Attackers Steal Microsoft 365 Sessions Without a Password
A user visits the real microsoft.com/devicelogin page, enters a real code, and hands an attacker a valid OAuth token - no password stolen, no MFA bypassed. How the flow is abused, how to spot it in Entra sign-in logs, and how to block it with Conditional Access.
IA
Imran Awan
👁 Read post →
Autopilot 7 August 2026
Windows Autopilot MDM Log Collection: Complete Troubleshooting Reference
Every command, registry key, event ID, and error code for diagnosing Windows Autopilot enrollment failures. Covers MdmDiagnosticsTool.exe, Get-AutopilotDiagnostics, ESP registry analysis, ODJ Connector logs, and hardware hash collection.
IA
Imran Awan
👁 Read post →
Security 7 August 2026
Windows August 2026 Patch Tuesday: SharePoint Unauthenticated RCE, Kernel Privesc, and What’s Actually Good in KB5101684
A no-auth SharePoint RCE chain, a Windows kernel privesc, and 200-300+ CVEs land on 12 August. Here is what to patch first and what to enable in KB5101684.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 4 August 2026
Windows Hello for Business Not Working on a Hybrid-Joined Device — Step-by-Step Diagnostic Walkthrough
WHfB signs in with a PIN but Event 360 keeps firing? This walkthrough traces the real command sequence — dsregcmd, AAD event logs, VPN PRT refresh — and finds the root cause: a domain controller you cannot reach.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
dsregcmd /status Decoded: The Complete Field Reference for WHfB and PRT
One command answers more WHfB questions than any portal - and its forty-plus fields come with almost no explanation. This is the field-by-field reference: every dsregcmd /status section, what each line means, and which values are good, so you read the whole picture instead of the three lines you recognise.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
The Complete Windows Hello for Business Event ID Catalog (Across All Three Logs)
WHfB logs to three different places with cryptic IDs and no index. This catalog maps which log holds what - User Device Registration (358/360/362/363), HelloForBusiness Device Unlock (3520-8520), and AAD - and what each event is telling you, so you stop guessing which log to open.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Force Phishing-Resistant Sign-In: Requiring WHfB With Conditional Access Authentication Strength
Enabling WHfB makes it available - it does not make it mandatory. A Conditional Access authentication strength does. WHfB is one of three methods that satisfy the built-in Phishing-resistant MFA strength; here is how to require it on sensitive resources, and the primary-auth trap that generates lockout tickets.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows as a Passkey Provider: Where WHfB Ends and Passkeys Begin (24H2)
Windows Hello is already a passkey provider - it can create, store and unlock passkeys for the whole web with the same PIN or biometric your users have for WHfB. This closing post in the series maps where WHfB ends and passkeys begin, and the 24H2 privacy-consent controls enterprises need to govern them.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Signs In Fine but File Shares Prompt: Fixing On-Premises SSO
The user signs in with their PIN and cloud apps work, but a file share throws a credential prompt. Hello is fine - the hand-off to an on-premises Kerberos ticket broke. This walks the PRT to partial-TGT to full-TGT chain and shows how to find the exact broken link with dsregcmd, klist and nltest.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Survives a Password Change - Your Saved Credentials Might Not (DPAPI)
Changing a password does not break WHfB sign-in - it uses a key, not the password. But a password RESET can orphan the DPAPI master key, and suddenly saved Wi-Fi drops and Credential Manager throws 0x80090345. Here is why the two are independent, and how to stop the DPAPI casualties.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Deploying FIDO2 Security Keys Alongside Windows Hello - and Locking Them Down by AAGUID
A FIDO2 key is the portable companion to a device-bound WHfB credential - but enabling FIDO2 without restrictions lets users register any key from a drawer. This covers passkey profiles, enforcing attestation, and restricting registration to the exact key models you trust by their AAGUID.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
TPM and Windows Hello for Business: Require It, Diagnose It, and the Firmware-TPM Traps
The TPM is what makes a WHfB key unexportable - but without RequireSecurityDevice, some of your fleet may be running Hello on software keys with no hardware guarantee. This covers requiring the TPM properly, diagnosing lockout with Get-Tpm, and the fTPM/PTT firmware traps that wipe credentials.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
How to Cleanly Disable or Remove Windows Hello for Business (Without Leaving Orphaned Keys)
WHfB is enabled by default on every Entra joined device - Autopilot turned it on, not you. Disabling it cleanly is a three-part job across the tenant policy, device policy and the credential cleanup. Here is how to do it at the right layer without scattering orphaned keys across your directory.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business During Autopilot: Why It Provisions When You Did Not Expect It
A new Autopilot device pops a 'set up a PIN' prompt nobody configured - or fails provisioning on a hybrid device at first boot. WHfB is enabled by default on Entra joined devices and the tenant policy fires at enrolment. Here is how to control exactly when, and whether, Hello provisions.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business PIN Complexity: Every Setting, CSP and GPO (and the 24H2 Trap)
The WHfB PIN complexity Group Policy is not where you would look, and PIN expiration silently stopped working on Windows 11 24H2 with VBS. This documents every PIN setting in CSP and GPO, and the two traps that make admins think their policy is broken when it is working as designed.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello for Business Dual Enrollment: A Privileged PIN for Admins (Cert-Trust Only)
Dual enrollment lets an admin enrol both their standard and privileged accounts for Hello on one device and elevate with a PIN instead of a password. It is powerful and narrow - certificate trust only, GPO only, and not a PAW replacement. Here is the full setup including the AdminSDHolder step.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Shadow Credentials: Detecting the msDS-KeyCredentialLink Attack Hiding in Your WHfB Deployment
The same attribute that stores WHfB keys - msDS-KeyCredentialLink - is one of Active Directory's most abused escalation primitives. This defender's guide covers how the Shadow Credentials attack works, how to catch it with Event 5136 auditing, and how to cut the write paths that enable it.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Inside the NGC Container: Why 'Just Delete the Ngc Folder' Is Terrible Windows Hello Advice
The NGC container is where your WHfB private key lives - and 'just delete the Ngc folder' is the internet's most destructive fix for it. Here are the real PassportForWork registry keys, the Event ID catalog, the supported certutil reset, and a Proactive Remediation pair - not another folder-delete guide.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello PIN Reset Done Right: Destructive vs Non-Destructive (and the Free Service Nobody Enables)
The default WHfB PIN reset throws away the credential and re-enrols - which can lock out hybrid key-trust users above the lock screen. Non-destructive PIN reset fixes that, is free, and almost nobody turns it on. Here is how to deploy it and prove it is live with dsregcmd CanReset.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Windows Hello Multifactor Device Unlock: Require a Trusted Signal, Not Just a PIN
Trusted signal unlock makes a device open only when the user proves themselves AND the machine sees a trusted signal - a known Wi-Fi network or a paired phone. This guide covers the exact credential-provider GUIDs, the signal-rule XML, and the Device Unlock event IDs to verify it.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 31 July 2026
Where Windows Hello for Business Keys Really Live: The msDS-KeyCredentialLink Deep Dive
The WHfB public key lives in one AD attribute - msDS-KeyCredentialLink - and almost nobody looks inside it. This deep dive decodes the key credential structure, shows how to enumerate and audit it with PowerShell, and explains how to find and clean up orphaned keys safely.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Zero Reviewers Responded, So Entra Auto-Approved a Departed Admin
An Entra access review whose deadline passes with no responses can auto-apply a default decision of Approve, so a stale or departed user silently keeps a privileged role. Here's the exact setting combination, how to check it, and a read-only PowerShell audit.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Your Classic Entra Connect Sync Server Stopped Exporting — and Cloud Sync Monitoring Won't Catch It
You monitor modern Entra Cloud Sync, but a second domain still syncs through classic Entra Connect Sync on an ageing server. Its scheduler drifted or it slipped into staging mode, exports stopped, and objects silently went stale. Here's how to audit Connect Sync health with the ADSync module and a read-only PowerShell script.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Entra Says "No Risky Users" — But a Real Detection Just Auto-Dismissed Itself
A risky sign-in fires a real detection, the user passes MFA under a risk-based policy, the riskState flips to remediated, and they vanish from the risky users report. Here's how to resurface every dismissed and auto-remediated detection with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Intune 31 July 2026
Your Intune Filter Matches Zero Devices and the Portal Won't Tell You
An include assignment filter with a subtly wrong rule can match zero devices, so a policy assigned to All Devices silently lands on nobody - with no error. Here's why it happens and a read-only PowerShell script that flags the traps.
IA
Imran Awan
👁 Read post →
Entra ID 31 July 2026
Group-Based Licensing Fails Silently for Some Users — Here's How to Find Them
Assign Microsoft 365 licences to a security group and for some members the assignment silently fails - a service-plan conflict, too few licences, or a missing usage location. The group looks fine; the error only lives in each user's licenseAssignmentStates. Here's how to audit it with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Windows LAPS vs Legacy LAPS: The Migration Drift Where Two Managers Fight Over One Password
You migrated from legacy Microsoft LAPS to Windows LAPS and the portal looks clean. But if the old client and GPO are still applying, two managers fight over the local admin password and only one actually rotates. Here's a device-side drift audit.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
A Revoked Certificate That Still Signs In: The Entra CBA Revocation Gap
You enable phishing-resistant certificate-based auth, issue smart-card certs, then revoke one when someone leaves. But if the CA's CRL distribution point is missing from your Entra CBA trust store, Entra never checks revocation and the revoked cert keeps signing in. Here's why, and a read-only PowerShell audit that catches it.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
Global Secure Access Is On, But Your Internet Traffic Never Entered the Tunnel
You rolled out Global Secure Access and assumed traffic was now tunnelled and inspected. By default only the Microsoft 365 profile is enabled - Internet and Private access ship disabled. Here's how to audit GSA traffic forwarding profile coverage with Microsoft Graph before a Conditional Access assumption breaks.
IA
Imran Awan
👁 Read post →
Intune 31 July 2026
You Scoped That Admin to One Scope Tag. They Can Still See Every Untagged Object.
Intune scope tags are an allow-list of what a scoped admin CAN see, not a wall around what they can't. Any policy, profile or app you forget to tag silently gets the Default scope tag and stays visible. Here's the mechanism and a read-only PowerShell script to find every leaky object.
IA
Imran Awan
👁 Read post →
Security 31 July 2026
A Partner Tenant Can Satisfy Your MFA Requirement For You
Your Conditional Access requires MFA, yet a guest from a partner tenant signs in without ever being challenged. An inbound trust setting is accepting MFA already satisfied in their tenant. Here's how to audit every cross-tenant inbound trust with Microsoft Graph.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 30 July 2026
Key Trust vs Certificate Trust vs Cloud Kerberos Trust: Which One Is Your Device Actually Using?
Three trust models, and most admins cannot say for certain which one a given device is running. This guide decodes the difference, then shows the exact commands and registry values that prove - not guess - whether a device is on key trust, certificate trust or cloud Kerberos trust.
IA
Imran Awan
👁 Read post →
Windows 30 July 2026
Windows Hello for Business Doesn't Work Over RDP — Here's What Actually Does
A user signs into their laptop with a fingerprint, then RDPs to a server and gets thrown back to a password prompt. WHfB credentials are TPM-bound to the local device and can't be used on a remote session. Here are the two real supported fixes, and a script that checks which one your device is ready for.
IA
Imran Awan
👁 Read post →
Entra ID 30 July 2026
Temporary Access Pass: The Passwordless Bootstrap Nobody Talks About
A new hire needs Windows Hello for Business set up on day one with no password yet. A user loses their only passwordless method and support has no way back in. A Temporary Access Pass solves both - here's exactly how the lifetime settings work, the two-TAP gotcha, and an audit script.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 29 July 2026
Migrating Windows Hello for Business From Certificate Trust to Cloud Kerberos Trust (and Retiring NDES)
There is no in-place migration from certificate trust to cloud Kerberos trust - the Windows Hello container must be deleted first. Here is the safe phased cut-over, the certutil -deletehellocontainer step, and how to decommission NDES without breaking your Wi-Fi and VPN certificates.
IA
Imran Awan
👁 Read post →
Intune 29 July 2026
Your Intune Portal Shows What Was Assigned. This Script Shows What Actually Landed.
The Intune admin center reports what a policy was assigned to. It doesn't tell you what actually landed in the registry on that device. Here's a script that reads all six real local sources of truth and builds one readable report - no Graph, no internet required.
IA
Imran Awan
👁 Read post →
Windows Hello for Business 28 July 2026
Windows Hello for Business Cloud Kerberos Trust: The Complete Deployment Guide
Cloud Kerberos trust deploys Windows Hello for Business with no PKI and no AD FS. This end-to-end guide covers the partial-TGT mechanism, Entra Kerberos setup with Set-AzureADKerberosServer, the exact Intune, CSP and GPO settings, and how to prove it works.
IA
Imran Awan
👁 Read post →
Entra ID 28 July 2026
A Lapsed Entra ID P2 License Doesn't Pause PIM — It Deletes Every Eligible Assignment
When your Entra ID P2 or Governance license lapses, Conditional Access policies freeze in place - but PIM eligible role assignments are deleted outright, while standing admin access survives untouched. Here's the exact behaviour, and a script to check your exposure first.
IA
Imran Awan
👁 Read post →
Security 23 July 2026
Your BitLocker Escrow Report Says 100%. When Did Anyone Last Prove One of Those Keys Still Matches the Drive?
A recovery key escrowed to Entra ID or AD is tied to a specific KeyProtectorId - one protector, one point in time. Re-image a drive or rotate a protector, and the escrowed record can quietly go stale while your audit still reports GREEN.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Windows Autopilot Deployment Modes Explained: User-Driven, Self-Deploying, and White Glove
User-driven, self-deploying, and pre-provisioning look interchangeable in the Intune dropdown. They aren't — pick the wrong one or leave a stale device record behind, and the device drops straight to standard, unbranded OOBE.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Autopilot-Capable Isn’t Autopilot-Registered: The Hardware Gap That Breaks Deployment
A laptop can meet every Windows Autopilot hardware requirement on paper and still fail hardware hash capture or profile assignment. Here's the exact SMBIOS and hash-capture gap that causes it, and how to check for it before deployment day.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
The Enrollment Status Page Isn't Blocking What You Think It's Blocking
ESP shows progress for a lot more than it actually blocks on, and the gap between 'tracked' and 'blocking' is exactly why an app can show failed while it's sitting there installed and working. Here's what ESP really enforces and how to configure a timeout policy that doesn't trap users forever.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Flip a Co-Management Workload to Intune Too Early and the Policy Gap Is Invisible
Co-management splits management authority per workload between ConfigMgr and Intune — but switch a workload before the equivalent Intune policy exists, and devices lose settings silently, with no error anywhere.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Cloud Management Gateway: Why "Not Connected to CMG" Almost Always Means a Certificate, Not a Server
A device shows healthy CMG deployment on the console, yet the client says it can't reach it. Here's what CMG actually does and why cert trust or CRL/OCSP reachability — not the gateway itself — is usually the real cause.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Intune Management Extension: Why Your Win32 App Is Stuck at "Processing"
A required Win32 app stuck at 'Processing' for days isn't an Intune problem — it's the Intune Management Extension agent on the device. Here's what it does, how it installs, and the real fix.
IA
Imran Awan
👁 Read post →
Entra ID 23 July 2026
An Entra Registered Device Isn’t a Security Gap — It’s a Different Job Entirely
An admin sees 'Microsoft Entra registered' and assumes it's the weak, unmanaged category — then tries to force BYOD devices into full join and breaks access for a whole team. Here's what actually separates joined, hybrid joined, and registered.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Switching Co-Management Workloads to Intune: Pilot Collection First, Never All Seven at Once
Switching all seven co-management workloads to Intune at once for your whole estate is how organisations silently lose GPO and baseline settings enforcement overnight. Here's the staged, pilot-first rollout Microsoft actually documents.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Windows Autopilot Fails During OOBE: The Errors, Event IDs, and Fixes That Actually Matter
Devices stuck on 'Just a moment', ESP timeouts, and Something went wrong pages during Autopilot deployment — here are the real Event IDs, error codes, and root causes behind them, plus a read-only script.
IA
Imran Awan
👁 Read post →
Intune 23 July 2026
Deregister an Autopilot Device Out of Order and You Can Orphan It Permanently
Windows Autopilot registration is a two-part process, and deregistering a device the wrong way — or deleting the Entra device object manually — can leave it permanently stuck. Here's the exact correct order across Intune, Autopilot, and Entra ID, plus a read-only PowerShell script to check status before and after.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many People Are Still in Your Local Administrators Group From a Request Six Months Ago?
LAPS proves your local admin password rotates. It doesn't prove nobody's quietly accumulated permanent access. Here's a device-side detection script for Intune Proactive Remediations that catches local admin group drift.
IA
Imran Awan
👁 Read post →
Entra ID 22 July 2026
Your Entra Cloud Sync Job Has Been Failing Quietly for Three Weeks — Here's How to Catch It
Hybrid sync errors pile up silently until a helpdesk ticket arrives weeks later. Here's how Entra Cloud Sync job health actually works via Microsoft Graph, the gotcha with CountSuccessiveCompleteFailures, and a PowerShell script that catches it early.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many of Your BitLocker Devices Actually Have a Recovery Key Escrowed Anywhere?
If it's not 100%, some of your encrypted devices are one recovery prompt away from permanent data loss. Here's why Entra-escrowed and AD-escrowed keys need two different audits, and a PowerShell script for the one Graph can actually see.
IA
Imran Awan
👁 Read post →
Security 22 July 2026
How Many of Your App Registrations Have a Secret Expiring This Week?
App registration client secrets and certificates expire silently, and nobody tracks the date until an integration breaks with AADSTS7000215. Here's a PowerShell audit that flags every expiring credential in your tenant before it does.
IA
Imran Awan
👁 Read post →
Windows 21 July 2026
Windows 11 LTSC 2024: The 5-Year vs 10-Year Lifecycle Trap
Windows 11 Enterprise LTSC 2024 has a 5-year lifecycle. Windows 11 IoT Enterprise LTSC 2024 has a 10-year lifecycle. Same feature set, same version — buying the wrong SKU for a long-life device is an expensive mistake.
IA
Imran Awan
👁 Read post →
Entra ID 21 July 2026
Find Every Privileged Role, Permission & Assignment in Entra ID
Microsoft's new PRIVILEGED label (preview) finally flags every Entra role, permission, and assignment that can lead to elevation of privilege. Here's how to find them all with PowerShell and Graph, read the escalation chains, and cut your privileged assignments down to size.
IA
Imran Awan
👁 Read post →
Security 16 July 2026
That AI Tool You Just Gave 'Read/Write All' to Entra and Intune — Would You Even Notice?
A newly adopted AI ITSM platform just asked for Directory.ReadWrite.All. Most tenants never revisit an OAuth consent grant once it's approved. Here's a PowerShell audit that flags every risky enterprise app permission in your tenant.
IA
Imran Awan
👁 Read post →
Security 16 July 2026
Is Your LAPS Password Actually Rotating — Or Just Configured? Here's How to Tell the Difference
Windows LAPS can look compliant in Intune and still have a local admin password that hasn't rotated in months. Here's why the CSP and GPO paths conflict, and a PowerShell script that tells you which devices are actually stale.
IA
Imran Awan
👁 Read post →
Entra ID 16 July 2026
How Many of Your Global Admins Are PERMANENTLY Global Admins? Here's How to Find Out
Standing privileged access is the top finding in every security review — and turning on PIM doesn't retroactively convert old active assignments to eligible. Here's a script that finds every permanent admin role in your tenant.
IA
Imran Awan
👁 Read post →
Entra ID 16 July 2026
Do You Know Which Users Have ZERO Conditional Access Policy Applied? Here's How to Check
Conditional Access targets groups and apps, not "all users" by default. Gaps open silently as your tenant grows. Here's a PowerShell script that computes real effective coverage per user and workload identity — and finds every hole.
IA
Imran Awan
👁 Read post →
Microsoft 365 15 July 2026
Building Agents for Microsoft Teams: SDK, MCP, and What IT Admins Need to Know
Microsoft's Teams SDK now lets you build native AI agents in TypeScript, C#, and Python. Here's how authentication, MCP, and governance work — and what IT admins must audit before agents go live.
IA
Imran Awan
👁 Read post →
Entra ID 14 July 2026
Passkeys Are Now the Default in Entra ID: What You Need to Do Before February 2027
Microsoft is ending SMS and voice MFA by 1 February 2027 and making passkeys the default in Entra ID. Here's the full timeline, how to find at-risk users with PowerShell, and how to run a registration campaign before the deadline.
IA
Imran Awan
👁 Read post →
Windows 11 14 July 2026
Windows June 2026: Kerberos RC4 Enforcement, Windows Ready Print, and What IT Admins Need to Do Now
June 2026 brought one of the most urgent Windows security changes in years: Kerberos RC4 Audit mode is gone. Plus Intune Compliance policy deep-dive, Defender for Endpoint via Intune, security baselines update, and Intune Suite now free in M365 E3/E5.
IA
Imran Awan
👁 Read post →
Entra ID 12 July 2026
How to Enable Passkeys with Microsoft Authenticator in Microsoft 365
Passkeys in Microsoft Authenticator give your users phishing-resistant authentication without hardware keys. Here is how to enable them in Entra ID, deploy via Intune, and verify adoption with PowerShell.
IA
Imran Awan
👁 Read post →
Windows 11 12 July 2026
Windows Monthly Updates Explained: LCU, SSU, Patch Tuesday and What Actually Gets Installed
Every month Windows ships updates and most admins do not know the difference between an LCU and a preview release. Here is the complete guide to the Windows update cadence, update types, and how to control them in Intune.
IA
Imran Awan
👁 Read post →
Microsoft 365 12 July 2026
Copilot in Excel for Finance: Skills, Data Connectors, and Plan with Copilot Explained
Microsoft has rebuilt Copilot in Excel around how finance teams actually work — with custom Skills, six new financial data connectors, and a Plan with Copilot feature that shows every step before executing.
IA
Imran Awan
👁 Read post →
Guides 12 July 2026
Active Directory Domain Controller Hardening for Hybrid Environments
Domain Controllers are the highest-value target in your environment. This post covers DCSync audit, Protected Users, Credential Guard via Intune, Kerberoasting detection, and Entra Connect hardening for hybrid AD deployments.
IA
Imran Awan
👁 Read post →
Guides 12 July 2026
Windows 365 for Agents: A Secured Cloud PC Execution Environment for AI
AI agents running on user workstations create unacceptable blast radius and auditability problems. Windows 365 for Agents gives each agent its own isolated, Intune-managed Cloud PC with network isolation and full audit logs.
IA
Imran Awan
👁 Read post →
Intune 12 July 2026
How to Look Up a Windows Autopilot Device by Serial Number Using PowerShell
The exact Graph PowerShell filter syntax to look up any Autopilot device by serial number — single device, bulk CSV, Group Tag updates, and what to do when the filter returns nothing.
IA
Imran Awan
👁 Read post →
Active Directory 12 July 2026
10 Essential PowerShell Commands Every Active Directory Administrator Should Know
The 10 PowerShell commands every AD administrator needs: DC enumeration, replication status, FSMO roles, stale account cleanup, lockout detection, password policy review, and DC port connectivity testing.
IA
Imran Awan
👁 Read post →
Guides 11 July 2026
MD-102 Exam Guide: How to Pass the Microsoft Endpoint Administrator Certification
The complete guide to passing MD-102: Endpoint Administrator. Covers all five exam domains with official skill percentages, real Intune scenarios, PowerShell examples, and exam-day tips — built entirely from Microsoft Learn.
IA
Imran Awan
👁 Read post →
Intune 11 July 2026
Windows 11 Start Menu Policy Settings: The Complete Intune & CSP Reference
Every Windows 11 Start menu policy setting explained — CSP paths, GPO equivalents, and exactly how to deploy them via Intune custom OMA-URI profiles. Pin layouts, power buttons, account options, and pinned folders all covered.
IA
Imran Awan
👁 Read post →
Windows 11 10 July 2026
Microsoft's AI Is Hunting Windows Vulnerabilities Before Attackers Do — What MDASH Means for Your Fleet
Microsoft's MDASH — a multi-model AI scanning harness — is now hunting Windows vulnerabilities before attackers find them. Expect more patches, faster. Here is what MDASH actually does, why you should expect higher patch volume, and how to configure Windows Autopatch and hotpatch to absorb it without breaking your fleet.
IA
Imran Awan
👁 Read post →
Azure 9 July 2026
Azure Files Kerberos Auth With Hybrid Identities — No More Storage Account Keys for Domain Users
Storage account keys give everyone root-level access with no per-user permissions and no SSO. Microsoft Entra Kerberos authentication fixes this — hybrid domain users access Azure Files with their Windows credentials, proper NTFS ACLs, and silent SSO at logon. Here is the complete Intune setup from storage account through to client policy and proof it is working.
IA
Imran Awan
👁 Read post →
Windows 11 9 July 2026
Windows Settings Backup Is On by Default From 26H2 — What You Need to Do Before It Hits Your Fleet
Starting with Windows 11 26H2, eligible devices will have settings backup on by default. If your backup policy is Not Configured right now, backup will start running automatically when 26H2 lands. Here is what changes, what does not, and the three decisions every admin needs to make before it reaches their fleet.
IA
Imran Awan
👁 Read post →
Intune 8 July 2026
Get a PRT Fleet Health Report in 5 Minutes Using Graph Explorer
You have deployed the PRT detection script to Intune. Now how do you see the results across your whole fleet? Two Graph Explorer queries, one JSON export, and 30 seconds in Excel gives you a complete PRT health snapshot with hostnames, UPNs, and which devices need manual intervention.
IA
Imran Awan
👁 Read post →
Entra ID 7 July 2026
The Primary Refresh Token (PRT): How Entra ID SSO Actually Works Under the Hood
The PRT is the token that powers silent SSO across every Microsoft 365 app on your Windows devices. Most admins treat it as a black box. Here is what is actually inside it, how the TPM protects it, and what breaks when it goes wrong.
IA
Imran Awan
👁 Read post →
Scripts & Tools 6 July 2026
Deploy Free WHfB Health Scripts to Intune: Six Checks, Five Auto-Repairs, Zero Helpdesk Calls
WHfB breaks silently — PRT expires, NGC keys corrupt, services stop. Here is a Proactive Remediation pair that detects all six failure modes and repairs them automatically, including the trick for running dsregcmd /refreshprt from SYSTEM context.
IA
Imran Awan
👁 Read post →
Guides 1 July 2026
Microsoft Intune Complete Roadmap: Beginner to Advanced (All 12 Chapters)
A structured 12-chapter roadmap covering everything in Microsoft Intune — from architecture and enrolment to Autopilot, compliance, Win32 apps, Defender, and troubleshooting. The learning path for MD-102 and real-world endpoint engineering.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Intune Certificate Profiles: SCEP, PKCS, NDES and the Full Architecture
Certificate-based authentication in Intune — the full architecture from Root CA through NDES and the Certificate Connector to device and user profiles. Covers SCEP vs PKCS, lifecycle management, troubleshooting connector errors, and best practices.
IA
Imran Awan
👁 Read post →
Entra ID 1 July 2026
Microsoft Entra ID Complete Overview: Identity, SSO, Conditional Access and Licensing (Part 1)
The complete foundational guide to Microsoft Entra ID — what it is, how authentication works, core components (users, groups, devices, apps), identity types, SSO protocols, Conditional Access, licensing tiers, and Azure AD Connect hybrid identity.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Windows Autopilot Complete Overview: Deployment Types, Components and Registration (Part 1)
The complete Windows Autopilot fundamentals guide: what it is, how it works, User-Driven vs Self-Deploying vs Hybrid deployment, required components, Autopilot profiles, device registration methods, prerequisites, and the firewall URLs you must allow.
IA
Imran Awan
👁 Read post →
Intune 1 July 2026
Intune Win32 App Deployment: Complete Guide from Packaging to Monitoring
The complete Win32 app deployment guide: packaging with IntuneWinAppUtil, install and uninstall commands, detection rules (file, registry, MSI, script), assignment types, the IME installation pipeline, monitoring, common error codes, and best practices.
IA
Imran Awan
👁 Read post →
Guides 1 July 2026
Top 20 PowerShell Commands Every Intune & Azure Engineer Needs
PowerShell is not optional for Intune and Azure engineers. Here are the 20 commands you need daily — with real-world examples from device management, identity, and automation workflows.
IA
Imran Awan
👁 Read post →
Intune 30 June 2026
Microsoft Store Apps in Intune — Deployment & Troubleshooting, End to End
Store for Business is gone — modern Intune Store apps are winget-backed. The full deployment flow, what the IME leaves on the device (registry, logs, services), the PFN vs Package ID, the error codes everyone hits, and a free read-only status script.
IA
Imran Awan
👁 Read post →
Intune 30 June 2026
Windows Autopatch — What It Actually Is, and What It Changes on Your Devices
Microsoft-managed updates sound great — but what does Autopatch actually do? The cloud back end, the registration flow, the deployment rings, and the exact registry keys, agents, tasks, services and events it leaves on a device — verified live.
IA
Imran Awan
👁 Read post →
Security 29 June 2026
Secure Boot Certificate Update 2026: Fix Non-Compliant Devices with Intune
3,052 devices showing 'Not Up to Date' in your Secure Boot Status Report? Here is the complete guide — what Secure Boot is, why the 2026 deadline matters, and how to fix both failure states with Intune Proactive Remediations and PowerShell scripts.
IA
Imran Awan
👁 Read post →
Security 29 June 2026
Which Windows Hello Gesture Did They Actually Use? Face, Fingerprint, PIN or Password
Entra only ever says "Windows Hello for Business" — never whether someone used face, fingerprint, PIN or password. Here is how I reverse-engineered the Windows event logs to build the report Microsoft does not ship.
IA
Imran Awan
👁 Read post →
Intune 28 June 2026
Microsoft Intune: Win32 vs. Store App Deployment — Complete Guide
Win32 or Store? Complete breakdown of both Intune app deployment methods — packaging, IME internals, detection rules, Autopilot ingestion order, and PowerShell scripts for every scenario.
IA
Imran Awan
👁 Read post →
Autopilot 28 June 2026
Windows Autopilot: Complete Device Lifecycle Management Guide
Zero-touch provisioning from factory to fully managed desktop. Complete guide to Autopilot deployment modes, ESP configuration, hardware hash harvesting, profile assignment, and troubleshooting the 5 most common failures.
IA
Imran Awan
👁 Read post →
Microsoft 365 27 June 2026
Agent 365 Now Requires M365 E5 — Licensing Impact and Your Options
From June 1 2026, new Agent 365 purchases require M365 E5. Existing customers are grandfathered, but E3 organisations wanting new deployments must upgrade. Full breakdown of what E5 adds, the cost comparison, and your three options.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Security Copilot for Intune — 4 AI Agents Deep Dive (Policy, Change, Offboarding, Vuln)
Microsoft Security Copilot now has four dedicated Intune agents: Policy Configuration, Change Review, Device Offboarding, and Vulnerability Remediation. E5 tenants get free SCU capacity through June 30. Complete technical guide with PowerShell scripts.
IA
Imran Awan
👁 Read post →
Copilot 27 June 2026
Copilot Cowork Is Now GA — Metered Billing, Spending Limits & IT Governance
Copilot Cowork went GA on June 16 2026 with usage-based billing — enterprises now pay per task on top of M365 Copilot licences. Off by default. This guide covers spending limits, compliance controls, and how to enable it safely for your organisation.
IA
Imran Awan
👁 Read post →
Copilot 27 June 2026
Microsoft Scout — The Always-On Autopilot Agent for M365 (Build 2026)
Announced at Build 2026, Microsoft Scout is Microsoft's first always-on Autopilot agent — it runs in the background under its own Entra identity, monitoring Teams, Outlook, and SharePoint and taking action without prompting. IT governance guide for endpoint admins.
IA
Imran Awan
👁 Read post →
Microsoft 365 27 June 2026
Microsoft 365 Copilot Auto-Install Block Guide — IT Admin Opt-Out (June–July 2026)
Microsoft is pushing the M365 Copilot app to all enterprise Windows devices June 15–July 20, even without a Copilot licence. Act before your channel window closes — here are the three methods to block it and the PowerShell to remove it if it already installed.
IA
Imran Awan
👁 Read post →
Windows 27 June 2026
Windows Hello for Business Provisioning Failure — Complete Fix
WHfB provisioning prompt never appears, or disappears silently? Event IDs 360, 362, and 363 in User Device Registration log tell you exactly why. This guide covers every cause — TPM lockout, missing PRT, policy conflicts — and the fix for each.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
PRT Not Working + Local Admin Missing on Entra Joined Device
Primary Refresh Token broken means no SSO to Microsoft 365. Local admin not applying means the Entra role claim hasn't refreshed. Both fixed with dsregcmd /refreshprt and a full sign-out — here's the complete guide.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
Entra Hybrid Join Stuck in Pending State — Complete Fix Guide
Devices stuck in Pending in the Entra portal won't receive Intune policies. This guide covers every root cause — stale certs, OU moves, AD sync gaps — with dsregcmd commands and a bulk GPO fix script.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Intune Enrollment Error Codes: Complete Troubleshooting Guide
Intune enrollment failing with a hex error code? This complete reference covers every common enrollment error — 0x80180026, 0x80070774, 80180018, 801c0003, 0x80090016 — with the exact cause and fix for each.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Intune and Apple WWDC 2026 — What IT Admins Need to Know
Apple WWDC 2026 brought major changes to MDM management — new declarative device management APIs, iOS 26 supervised mode changes, and macOS 26 privacy controls that affect Intune enrollment. Full breakdown for IT admins.
IA
Imran Awan
👁 Read post →
Windows 27 June 2026
KB5094126 Sign-in Failure Fix — Windows 11 24H2
KB5094126 is causing sign-in failures on some Windows 11 24H2 devices after installation. This post covers the symptoms, affected configurations, and both the official Microsoft workaround and the permanent fix.
IA
Imran Awan
👁 Read post →
Entra ID 27 June 2026
Entra Conditional Access: WHfB Enforcement Deadline July 2026
Microsoft's July 2026 deadline for phishing-resistant MFA enforcement is approaching. Here's what Conditional Access changes you need to make now to avoid access disruptions when the WHfB enforcement goes live.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
What's New in Microsoft Intune — June 2026
Microsoft Intune June 2026 release — new Autopilot device preparation updates, Copilot integration in Intune admin centre, and the latest policy improvements for Windows, iOS, and Android.
IA
Imran Awan
👁 Read post →
Intune 27 June 2026
Top 10 Intune PowerShell Commands Every Admin Should Know
These 10 Microsoft Graph PowerShell commands are the foundation every IT admin and EUC engineer needs before moving to advanced Intune automation — covering device inventory, compliance reporting, remote actions, and bulk cleanup.
IA
Imran Awan
👁 Read post →
Scripts 27 June 2026
Export and Filter Group Policy Objects to CSV with PowerShell
A simple PowerShell script that lets you search your entire GPO estate by keyword and export the results to CSV — no manual browsing in GPMC required.
IA
Imran Awan
👁 Read post →
Autopilot 27 June 2026
Windows Autopilot Enrollment Failures: A Structured Troubleshooting Guide
A step-by-step guide for troubleshooting Windows Autopilot enrollment failures — covering hardware hash, profile assignment, network requirements, logs, and common error codes.
IA
Imran Awan
👁 Read post →
Windows 26 June 2026
Windows Update Stuck? The Complete Fix Guide (Every Verified Method)
Windows Update stuck at 0%, failing with an error code, or frozen at boot? This complete guide covers every verified fix — from the built-in troubleshooter and DISM/SFC repairs to the full component reset script — with real command outputs and community-validated methods used by thousands of IT professionals.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Autopatch Is Alerting on Expiring Secure Boot Certificates — Here's What to Do
Windows Autopatch has added a new alert: 'Secure Boot — certificate update required'. Devices using the older Microsoft Secure Boot certificates are flagged because those certificates expire in 2026. Here is what the alert means, which devices are affected, and how to get them onto the 2023 UEFI certificates.
IA
Imran Awan
👁 Read post →
Technical Guide 26 June 2026
Hotpatch for Windows 11 — June and July Are Baseline Months. Here's the Full 2026 Schedule
If your Windows 11 devices didn't hotpatch in June — that's expected. June 2026 is a baseline month, which means a full cumulative update and a restart. So is July. Hotpatch doesn't resume until August. Here is the complete 2026 schedule, what prerequisites you need, and what to check if your devices aren't hotpatching when they should be.
IA
Imran Awan
👁 Read post →
Intune 26 June 2026
Windows Autopilot Device Preparation Roadmap: What Is Coming and When to Migrate
Pre-provisioning and self-deploying modes are planned for Autopilot Device Preparation but not yet available. Both classic Autopilot and Device Preparation run in parallel — no forced migration.
IA
EndpointWeekly Team
👁 Read post →
Intune 26 June 2026
Autopilot Device Preparation: App Limit Now 25, Managed Installer Fixed, Enterprise App Catalog Added
Three key improvements: app limit raised to 25, managed installer fix (April 2026), Enterprise App Catalog support from Intune 2506.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Windows Autopilot Now Installs Monthly Security Updates During OOBE — What IT Admins Must Check
From January 2026, devices going through Windows Autopilot automatically receive the latest monthly security update during OOBE. Adds 20-40 min to provisioning.
IA
EndpointWeekly Team
👁 Read post →
Intune 26 June 2026
Windows Autopilot Device Preparation + Windows 365: Now Generally Available
From May 11 2026, Autopilot Device Preparation GA for Windows 365 Enterprise, Flex Dedicated, Flex Shared, and Cloud Apps.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Copilot Notebooks Now Available to Copilot Chat Users: What Is New in June 2026
Microsoft is expanding Copilot Notebooks to Copilot Chat users for the first time, rolling out in June 2026. Chat users get access via OneNote on web with standard sources and mind maps. At the same time, M365 Copilot users gain Teams meetings as a knowledge source, an Excel agent that generates spreadsheets from notebook content, auto-generated infographics, and a redesigned UI.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Microsoft Agent 365: The IT Admin Guide to Governing AI Agents Across Your Organisation
Microsoft Agent 365 is generally available as of May 1, 2026 — a purpose-built control plane for observing, governing, and securing every AI agent in your organisation. GA brings the Agent Registry backed by Entra Agent IDs, Registry Sync with AWS, Google Cloud, Salesforce and Databricks, a Shadow AI page for local endpoint agents, and deployment controls for approved agents. Here's what IT admins need to know.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Windows 365 Developer Image: A Pre-Configured Cloud PC for Dev Teams (Build 2026)
Microsoft announced a Windows 11 developer configuration image for Windows 365 at Build 2026, now in public preview. It comes pre-installed with VS Code, Git, GitHub CLI, Python, Node.js, and WSL with Ubuntu. Here's what IT admins need to know about availability, requirements, and preview limitations.
IA
EndpointWeekly Team
👁 Read post →
AI 26 June 2026
Claude Opus 4.8 Is Now Inside Microsoft 365 Copilot: What IT Admins Need to Know
Anthropic Claude Opus 4.8 is now available directly inside Microsoft 365 Copilot alongside OpenAI GPT models. Users can choose their model, run side-by-side comparisons with Model Council, or let Auto mode pick the best option. Here is what IT admins need to know about EU Data Boundary restrictions, government cloud limitations, and how to brief your users.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Microsoft Purview DLP Now Scans Copilot Prompts in Real Time: How to Turn It On
Microsoft Purview DLP can now block Copilot from processing prompts that contain sensitive data — credit card numbers, national IDs, or custom sensitive information types your organisation defines. A default policy already exists in your tenant, but it is in simulation mode and not blocking anything yet.
IA
EndpointWeekly Team
👁 Read post →
Licensing 26 June 2026
Microsoft 365 Copilot SMB Pricing Changes July 1, 2026: What You Need to Know Before the Deadline
From July 1, Microsoft 365 Business Standard with Copilot and Business Premium with Copilot become permanent SKUs with updated list prices. If you manage licensing for a business under 300 seats, here is exactly what changes, what promos are still running, and whether to buy before June 30.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Entra ID SSPR Change: Unregistered Phone Numbers Stop Working September 7, 2026
From September 7 2026, Microsoft Entra self-service password reset will only accept methods users have explicitly registered. Directory-sourced phone numbers and emails that were never formally registered will stop working. Here is what to audit and fix before the deadline.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Microsoft Entra Custom Controls Are Being Retired: How to Migrate to External MFA Before September 2026
Custom Controls in Microsoft Entra Conditional Access stop accepting changes in September 2026 and reach end of life in May 2027. If you use Duo, Okta, or any third-party MFA provider through Custom Controls, here is your step-by-step migration guide to External MFA before the deadline.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
Windows 11 June 2026 Security Alert: Secure Boot Certificate Update and BitLocker Bypass Fix
KB5094126 delivers two urgent security items: automatic migration from expiring 2011 Secure Boot certificates to 2023 certs, and a patch for CVE-2026-45585 — a BitLocker bypass that allows physical attackers to decrypt protected drives via the Windows Recovery Environment.
IA
EndpointWeekly Team
👁 Read post →
Windows 26 June 2026
Get Ready for Windows 11 26H2: What IT Teams Need to Do Now
Windows 11 version 26H2 is confirmed for Fall 2026 and is already in the Experimental Insider channel. Here is everything enterprise IT teams need to know to start testing and plan their rollout — including the critical 26H1 device upgrade dead-end.
IA
EndpointWeekly Team
👁 Read post →
Security 26 June 2026
The Windows 11 25H2 Security Baseline Is in Intune — Here Is What Changed and How to Migrate
The Windows 11 25H2 security baseline is now in Intune. Your existing profiles will not auto-update. Here is what changed, how to handle the IE11 COM known issue, and how to migrate cleanly.
IA
Imran Awan
👁 Read post →
Windows Update 26 June 2026
Windows Autopatch Just Turned Hotpatch On By Default — Act Before It Hits Your Estate
From May 2026, hotpatch updates are enabled by default for all eligible devices in Windows Autopatch. No restart required for most months — but if your estate is not ready, you need to opt out now.
IA
Imran Awan
👁 Read post →
Licensing 26 June 2026
Intune Suite Is Now Included in M365 E3 and E5 — What Changes on July 1
From July 1 2026, Endpoint Privilege Management, Enterprise App Management, and Cloud PKI land in M365 E5 at no extra cost. M365 E3 gets Advanced Analytics, Remote Help, and Tunnel for MAM. No action needed — tenants are auto-provisioned.
IA
Imran Awan
👁 Read post →
AI 26 June 2026
ChatGPT Is Now Inside Microsoft Teams — What Every IT Admin Needs to Know
OpenAI has shipped admin-managed Teams sync for ChatGPT Enterprise. One Entra admin consent and ChatGPT can index your entire organisation Teams content. Here is what IT admins need to know before enabling it.
IA
Imran Awan
👁 Read post →
Scripts 26 June 2026
Get the Primary User and Last Sync Time for Any Intune Device — Bulk via PowerShell
You export a list of devices and all you get is hostnames. This script feeds that CSV into Microsoft Graph and gives you back the primary user, last sync time, and device status for every device in one run.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Microsoft Defender EDR Updates Now Ship via Microsoft Update — What Changes for Endpoint Admins
Microsoft now distributes Defender for Endpoint EDR component updates through Microsoft Update independently of the monthly Windows OS rollup. If you rely on manual deployment packages, you need to add the new Defender update package to your update process now.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Microsoft Defender Can Now Automatically Isolate Compromised Endpoints — Here's How It Works
Microsoft Defender for Endpoint now has a preview capability that automatically severs a compromised device from your corporate network the moment suspicious activity is detected — while keeping a secure channel open so your security team can still investigate remotely.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
Defender Now Discovers and Protects Local AI Agents on Windows Endpoints
A new preview capability in Microsoft Defender for Endpoint automatically discovers local AI agents running on onboarded Windows devices — coding agents, IDE extensions like GitHub Copilot, desktop AI assistants — and provides runtime protection that can block prompt injection before it executes.
IA
Imran Awan
👁 Read post →
Security 26 June 2026
CVE-2026-41091: Microsoft Defender Elevation of Privilege Vulnerability Exploited in the Wild — Patch Now
CVE-2026-41091 is a CVSS 7.8 elevation of privilege vulnerability in Microsoft Defender that has already been exploited in the wild. Fixed in June 2026 Patch Tuesday alongside two additional Defender CVEs. Check your Defender engine version now — it should be 1.1.26050.11 or later.
IA
Imran Awan
👁 Read post →
Technical Guide 25 June 2026
Silently Fix a Missing Primary Refresh Token with Intune Proactive Remediations
No PRT means no passwordless. The device looks healthy in Intune, compliance shows green, but WHfB provisioning silently fails. Here is the 6-step automated remediation that detects and fixes it without touching a healthy device.
IA
Imran Awan
👁 Read post →
AI Engineering 25 June 2026
AI Loops: What the Best Engineers Are Actually Building Right Now
Most people still use AI the slowest way — one prompt, one answer, repeat by hand. The engineers pulling ahead are building loops. Here is what a loop actually is, how it works, when to build one, and two copy-paste templates you can run in Claude or ChatGPT right now.
IA
Imran Awan
👁 Read post →
Technical Guide 25 June 2026
Silently Fix Broken Windows Hello for Business with Intune Proactive Remediations
NgcSet = NO on a device that looks perfectly healthy is one of the most common WHfB failure patterns. Here is the two-script Intune Proactive Remediation that detects and silently fixes it — without touching a healthy device.
IA
Imran Awan
👁 Read post →
Community Recap 24 June 2026
10 Key Takeaways from Microsoft's Windows Autopilot AMA
Microsoft's product team hosted a live AMA on Windows Autopilot deployment — Maggie D'Acuba (Product Manager, Windows Autopilot) and Perla Morales answered real questions from IT admins. Here are the 10 things that stood out.
IA
Imran Awan
👁 Read post →
Story 20 June 2026
Why I Started EndpointWeekly
Every Friday I found myself manually searching through dozens of blogs, social feeds and Microsoft docs just to stay current. I built EndpointWeekly to fix that — for myself, and for every engineer who feels the same.
IA
Imran Awan
👁 Read post →
Tips 10 June 2026
5 Intune Tips Every Admin Should Know in 2026
After years of managing Intune environments, these are the five settings, workflows and techniques that consistently save time and prevent headaches.
IA
Imran Awan
👁 Read post →
Technical Guide 11 May 2026
Automating Windows Hello for Business Enrollment with PowerShell and Intune
Devices can be Azure AD joined with a valid PRT and still have Windows Hello completely unprovisioned. Here's how I built a three-script solution to detect, remediate and automate the entire enrollment flow — silently, in user context, via Intune.
IA
Imran Awan
👁 Read post →
🔍
No posts found
Try a different search term or filter