A lab-validated approach for deploying PowerPoint templates via Intune, from SharePoint setup and certificate-based Graph API authentication to Proactive Remediations, self-healing and the security tradeoffs worth knowing about.
Posts for: #MSIntune
Setting Adobe Acrobat Reader as the Default PDF Viewer via Intune
A complete Intune deployment that enforces Adobe Acrobat Reader as the default PDF handler, covering the DefaultAssociationsConfiguration CSP, Edge PDF takeover suppression, ADMX-based handler locking, ownership popup remediation and the kernel driver that silently blocks the CSP on most enrolled devices.
Part 2: Autopilot Automated Device Naming: From SharePoint Queue to Sequential Device Names
Builds the naming engine: a SharePoint list as the work queue, an Entra app registration with certificate authentication, and a scheduled PowerShell script that reads pending devices and assigns sequential names via Graph API.
Part 1: Autopilot Automated Device Naming: From Hash Capture to SharePoint Queue
Builds a custom Windows 11 ISO with embedded WinPE scripts that capture the hardware hash, detect the device type and department, upload the device to Autopilot via Graph API and automatically queue it for naming in SharePoint.
OneDrive SilentAccountConfig: How a Conditional Access Policy Silently Blocks the WAM Broker
A forensic walkthrough of an OneDrive SilentAccountConfig failure on a freshly enrolled Autopilot device, tracing errors across the WAM broker, AAD event log and OneDrive diagnostic logs to a Conditional Access Terms of Use policy creating a complete PRT authentication deadlock.
Pinning a Custom URL to the Windows Taskbar via Intune
A step-by-step Intune deployment of a custom URL shortcut to the Windows Taskbar, unpacking the SYSTEM context limitation, the Win32 app and XML Layout policy dependency chain and the silent failure that occurs when the shortcut isn’t on disk before the policy fires.
OneDrive SilentAccountConfig: When There Are No Sign-In Logs and Where to Look Next
A structured diagnostic walkthrough of an OneDrive SilentAccountConfig failure on an Entra ID joined device from registry validation and PRT health checks to Entra sign-in logs, where the complete absence of authentication attempts reveals the real root cause.
Autopilot ESP Failure: Tracing the Error from Screen to Root Cause
A deep technical walkthrough of an ESP failure encountered during Windows Autopilot provisioning. This guide traces the error path across enrollment phases, log artifacts and application processing to reveal where and why the deployment breaks.
Windows Autopilot Deployment with Intune: Configuration, Enrollment and Real-World Troubleshooting
An end-to-end walkthrough of Windows Autopilot deployment with Intune, highlighting real world configuration decisions, troubleshooting insights and field-tested best practices.
Intune Foundation for Windows Autopilot: Enrollment, ESP, Compliance and Device Configuration
Practical Intune configuration covering tenant readiness, device targeting, Windows Hello, compliance policies and the groundwork that makes Autopilot deployments consistent.