top of page


(199) Microsoft Intune - Rename devices with PowerShell
Previous posts I have covered with setting a hostname or prompt for computer name . Manually renaming a single device is simple, but managing a large fleet requires automation for efficiency. While the standard CSP method exists, it can be inconsistent—especially regarding console reporting. To solve this, I’m sharing a PowerShell script that integrates with Microsoft Intune to streamline and automate your device renaming process. This script detects the type of device used f
Jan 202 min read


(198) Microsoft Intune - Set USB selective suspend settings from Enabled to Disabled
Customer has kiosk builds as one part of their personas that I did for them, they had this request where "USB selective suspend settings" is showing as "Enabled", but the customer wants it set to 'Disabled' as the USB scanners use it for power. Before it was like this: I attempted using powercfg command, which unfortunately didn't do anything. powercfg /SETACVALUEINDEX SCHEME_CURRENT 2a737441-1930-4402-8d77-b2bebba308a3 48e6b7a6-50f5-4782-a5d4-53bb8f07e226 0 Next I was thinki
Jan 167 min read


(197) Microsoft Intune - Uninstall/Reinstall App with removing Root CA certs
Applications like GlobalProtect when installed will deploy Root CA certificates (when setup properly), what if a customer wants to remove the Root CA certificates along with an uninstall of GlobalProtect then re-install with another version of GlobalProtect, this is what can be done to achieve this. What the application will do overall: Kills GlobalProtect process Run fast reference package to uninstall Remove certs based on thumbprints Sleeps for 30 seconds Then installs Glo
Jan 85 min read


(196) Microsoft Intune - Set HP BIOS Password as a Win32 App
Download and run the installer on an HP machine: HP BIOS Configuration Utility | HP Client Management Solutions Then run HpqPsw64.exe. Then to create a BIOS password - enter twice for the password to be encrypted and save the location. You can save it to whatever you like, in this case I have saved as HPBIOSPassword.bin Prepare the scripts: Install.ps1 Uninstall.ps1 BiosConfigUtility64.exe HPBIOSPassword.bin Detect.ps1 Prepare the Install.ps1 script: # Script sets the BIO
Jan 82 min read


(195) Microsoft Intune - Set Lockscreen and Desktop Wallpaper for Shared Devices
Standard wallpaper and lock screen customization via Intune is technically restricted to Windows Enterprise editions. If you’re on Microsoft 365 Business Premium, the Settings Catalog won't work for this. However, you can bypass this limitation by deploying a Win32 package . Not only does this solve the licensing hurdle, but it also simplifies deployment since the image file is bundled right into the package rather than hosted online. Prepare the following: wallpaper.jpg is t
Jan 83 min read


(194) Microsoft Intune - Autopilot ESP shows Certificates (0 out of 1 applied)
This recently happened late last year in December to one of our customers, as well it happened earlier yesterday for another customer. Gathering the logs, my initial thoughts it was an application matter as you know most customers don't give enough detail and simply say "Autopilot is not working since 6/01/206" which honestly doesn't give me much transparency on what is happening. From the logs I gathered from only showed: "[StatusService] Downloading app (id = 5bd17f11-2c60-
Jan 72 min read


(193) Microsoft Intune - Multi-App Kiosk - Start local .html on C drive on Microsoft Edge Kiosk Mode
Been working on this persona for this customer which is a multi-app kiosk build, the .html is not hosted anywhere on any websites but installed locally as part of the build process. Using assigned access, similar to my previous post: https://soeintunedevice.wixsite.com/home/post/155-microsoft-intune-kiosk-assigned-access In the XML below, you may have noticed that I have added <App DesktopAppPath="C:\Windows\SystemApps\MicrosoftWindows.Client.CBS\_cw5n1h2txyewy\CrossDeviceRes
Jan 51 min read


(192) Microsoft Intune - Multi-App Kiosk - This operation has been cancelled due to restrictions in effect on this computer.
This issue has been bugging me for awhile, at first I thought it was the 'Phone Link', which was wrong, till I grabbed the logs and eventually found it what was the cause of it. As I was viewing the logs for (52) Events Microsoft-Windows-AppLocker_Packaged_app-Execution Events.evtx, I found the issue. I updated the XML for the Kiosk Assigned Access profile, which I allowed <App DesktopAppPath="C:\Windows\SystemApps\MicrosoftWindows.Client.CBS\_cw5n1h2txyewy\CrossDeviceResume.
Dec 11, 20251 min read


(191) Microsoft Intune - Multi-App Kiosk to Allow Store Apps to Run
My colleague had some issues around this persona build for a customer, my colleauge reached out to me to have a look. I enrolled a physical device and all checked out, when clicking on 'Photos' and 'Paint' on the start menu - it would try to load but never worked. My colleague confirmed that he had whitelisted the XML to: <App AppUserModelId="Microsoft.Paint_8wekyb3d8bbwe!App" /> <App AppUserModelId="Microsoft.Windows.Photos_8wekyb3d8bbwe!App" /> Which didn't work, till I did
Dec 11, 20251 min read


(190) Microsoft Intune - Set Inital Start Menu for Windows 11 23H2
A customer reached out with wanting to set an initial start menu layout for their Windows 11 23H2 fleet, unfortunately for them if they were on Windows 11 24H2, we could use the .json and simply use the settings catalog option. In this case, I attempted with start2.bi n option as a win32 app which didn't give me the best success till I attempted using a remediation script. What you will need to do first is: Customise your start menu what you like to show up Run PowerShell ISE
Dec 3, 20252 min read


(189) Microsoft Intune - Install WordPad
Microsoft deprecated Wordpad as of 1st Sept 2023 https://learn.microsoft.com/en-us/windows/whats-new/deprecated-features#:~:text=WordPad,deprecated%20features which applies to Windows 11 24H2 and above. An education customer who requires Wordpad to be reinstated reach out to me to get it reinstalled as they were on Windows 11 25H2. What I needed to do is setup a VM with Windows 11 23H2, navigated to C:\Program Files\Windows NT\Accessories\ - copied the files over where the p
Dec 3, 20251 min read


(188) Microsoft Intune - Remove Shortcuts (*.lnk) on Public Desktop
A customer reached out to me as they wanted to prevent shortcuts (*.lnk) from appearing on their student devices. Easiest I could think of is a detect and remediation script. Detect.ps 1 $Shortcuts2Remove = "Google Chrome.lnk", "VLC media player.lnk", "Audacity.lnk", "Firefox.lnk", "Google Chrome.lnk", "Microsoft Edge.lnk", "Vivi.lnk" $DesktopPath = "C:\Users\Public\Desktop" # Public and User Desktop: "C:\Users\*\Desktop\*", for Public Desktop shortcuts only: "C:\Users\Public
Nov 19, 20251 min read


(187) Microsoft Intune - Update to Custom Power Plan (Win32)
Late last year I posted about a 'Custom Power Plan (Win32 app)' , I decided to revisit this again. Create a Power Plan: Call whatever name you like, in this I have called it 'Devicie Power Plan' Then customize your power plan as you need. Start Command Prompt as Administrator, and run the following: This will list out your current plans: powercfg /L Then in the same command prompt, run: powercfg -export "C:\Temp\DeviciePowerPlan.pow" 9044f02c-182b-4a85-955c-567522ab795b wher
Nov 19, 20251 min read


(186) Microsoft Intune - Update to User Locale (en-AU)
Last year I posted about using 'User Locale' with remediation scripts , and not too long ago I posted about setting English (Australia) as the default language . Of late I have noticed in Windows 11 25H2 when you have English (Australia) as the default language in place, it somehow sets English (United Kingdom) showing up. What I did was re-look at my 'User Locale' with remediation scripts , which I know works. It will check to see if "en-GB" is there, if it does then it
Nov 19, 20251 min read


(185) Microsoft Intune - Mozilla Firefox blocking all extensions except for Lastpass
I have been helping this customer who want to block all extensions on Firefox to be installed, except allowing 'Lastpass' to be installed. You can view the relevant settings that Mozilla Firefox has https://mozilla.github.io/policy-templates/#extensions , mainly what you are looking for is: https://mozilla.github.io/policy-templates/#extensionsettings . Generally you can use the ADMX/ADML templates to import into Intune, this customer already has an existing policy that ties
Nov 19, 20251 min read


(184) Microsoft Intune - Removing Dell Bloatware and Dell Apps
One of our customers listed me a detail list of Dell vulernable apps within their tenant. I tried to re-invent the wheel by using my HP Bloatware removal remediation script which did partial removing these bloatware apps. I ended up using Andrew Taylor's script with some modifications in place by removing all the unwanted bloatware lines he has added, and only focusing on Dell bloatware and Dell installed apps. Install.ps 1 #################################################
Nov 7, 202511 min read


(183) Microsoft Intune - Deploying Winget UWP Apps
I have this customer where strangly enough Company Portal and Notepad fail to install properly on their Windows 11 devices, even from the logs I was seeing these: [Win32App][WinGetApp][WinGetAppDetectionExecutor] Starting detection of app with id: 0a74d8d1-42e1-414a-ade0-5cfec8545c94 and context: SystemContext. [Win32App][WinGetApp][WinGetOperation] Starting Detection for app with id: 0a74d8d1-42e1-414a-ade0-5cfec8545c94 and package id: 9WZDNCRFJ3PZ. [Win32App][ReportingManag
Oct 31, 20253 min read


(182) Microsoft Intune - Set Hostname to periodically go up to a new number
As I prepping this yesterday for a customer, which does work https://soeintunedevice.wixsite.com/home/post/181-microsoft-intune-prompt-for-hostname-change if you want to have a read. Install.ps 1 is as follows, to explain what it does is the "Prefix" is generally what you see in Since there is no way to do this via Intune, the only way would be via PowerShell. It will start off with applying WIN11-3D-001 as the hostname $Prefix = 'WIN11-3D-' $regPath = "HKLM:\SOFTWARE\MrBSOE
Oct 24, 20252 min read


(181) Microsoft Intune - Prompt for Hostname Change
A customer who wanted a way for end users to get prompted to change hostname for their devices, and I remember I did something like this a few years ago (simple but easy to do). You need to prep for the following: RenameComputer.ps 1 Install.ps 1 Detect.ps 1 ServiceUI.exe (which you can grab easily from any MDT installer) RenameComputer.ps 1 - is a form that will appear to prompt the end user to change their hostname. Add-Type -AssemblyName System.Windows.Forms # Create the
Oct 24, 20252 min read


(180) Microsoft Intune - Company Portal Shortcut
A few months ago before I went on annual leave, a customer wanted to deploy Company Portal as a shortctut on the desktop for end users. The easiest way I could figure out looks like this: Install.ps 1 will do the following: [CmdletBinding()] Param ( [Parameter(Mandatory=$false)] [String]$ShortcutTargetPath, [Parameter(Mandatory=$false)] [String]$ShortcutDisplayName, [Parameter(Mandatory=$false)] [Switch]$PinToStart=$false, [Parameter(Mandatory=$false)] [String]$IconFile=$n
Oct 16, 20251 min read


(179) Microsoft Intune - Fingerprint recognition - Windows Hello for Business
A customer only wanted to setup 'Fingerprint recongition' to be applied to their HP devices only, just required prerequisites must be...
Sep 5, 20251 min read


(178) Microsoft Intune - User Profile Backup & Restore and Windows Easy Transfer
From 3 years ago, I did a blog around https://soeintunedevice.wixsite.com/home/post/34-backup-restore-win32-app using batch files from a...
Sep 3, 20253 min read


(177) Microsoft Intune - Remove previous versions ASP.NetCore
Had this issue with a customer who reported having issues with ASP.Net Core 8.0.11 showing up in Tenable, where the current installed is...
Aug 29, 20251 min read


(176) Microsoft Intune - Set Start Menu to not startup on logon
I have this customer who I have been helping over a period of time with setting up their 'Shared PCs' with some customisations, one of...
Aug 27, 20252 min read
bottom of page