Intune deployment plans arrive in preview: the payload is still yours
Posted in

Intune deployment plans arrive in preview: the payload is still yours

Intune deployment plans are in public preview: a reusable set of rings, then a deployment that walks one app or policy through them. Worth piloting.

The part admins will trip over is that the deployment does not own the payload. Direct payload edits take precedence, include assignments accumulate as rings activate, and pausing or canceling a rollout leaves the assignments the earlier rings already added. Pause and cancel stop future rings, they do not take back what already landed.

Before your first pilot: pull the payload assignments next to your rings and remove any overlap, check that whoever launches the deployment has Read and Assign on the payload category (plan permissions are separate), and remember Multi Admin Approval now gates create, resume, cancel and delete.

Windows only for now, four payload types, Required install intent only for Win32 and catalog apps.

This is the way: Windows Autopilot device preparation
Posted in

This is the way: Windows Autopilot device preparation

Microsoft has not retired classic Windows Autopilot, and nothing in the documentation behind this post carries an end-of-life date for it. What the September Intune Customer Success post did say is that device preparation is now the recommended path for user-driven Entra join and that future engineering investment goes there. That is a direction, not a deadline, and it matters because the transition costs money before any deadline appears: every new Windows 11 device provisioned the old way is another one to migrate later, Windows 10 and hybrid-joined fleets have no device preparation path at all, and pre-association only converts devices at their next natural reset. Start with the population that qualifies rather than the whole estate.

I’d Run Omarchy Everywhere if Intune Would Manage It
Posted in

I’d Run Omarchy Everywhere if Intune Would Manage It

I have been running Omarchy on my own laptop and it is the most fun I have had with a computer in years. Arch, Hyprland, agents wired in. Then I held it up against the Intune Linux support matrix: Ubuntu 24.04 or 26.04 LTS, RHEL 9 or 10, GNOME documented as required, x86/64, Edge plus the Intune app. My machine is LUKS-encrypted with Secure Boot and a TPM, and Intune still rejects it at the platform and package layer. Here is what Intune actually does on Linux, and what I evaluated as a way around it.

Intune Suite Capabilities Now Included in M365 E3/E5 — What MSPs Should Enable First
Posted in

Intune Suite Capabilities Now Included in M365 E3/E5 — What MSPs Should Enable First

As of July 1, Microsoft folded EPM, Cloud PKI, and Advanced Analytics into M365 E5 (select pieces into E3). If you manage E5/E3 clients, they now own tooling they were paying extra for — here’s the enable-first order and a per-tenant checklist.

Intune Field Notes: MDOP Migration Deadlines and macOS Platform SSO Gotchas
Posted in

Intune Field Notes: MDOP Migration Deadlines and macOS Platform SSO Gotchas

Two Intune signals deserve client action this quarter: MDOP is now out of extended support, and Microsoft’s Platform SSO field notes show where Mac rollouts can break. MSPs should inventory legacy MDOP dependencies, prioritize MBAM replacement, and pilot Platform SSO before pushing it broadly.