▲ 20 r/Intune

company portal Error loading apps and downloads / updates - North America tenant

**update: service degredation: IT1456599 **

devices are failing to load the apps, downloands and updates page on company portal apps. seeing this behavior different devices, on different networks. ( vpn, no vpn, home, corp, mobile hotspots)

C:\Users\<profile>\AppData\Local\Packages\Microsoft.CompanyPortal_8wekyb3d8bbwe\LocalState
log_2.log

shows 509 errors

WARN Event

Request failed with status: 509

ERROR Event

Exception of type ServiceTooBusyException has been thrown.

Detailed message:

Failed to get app data from Intune.

Inner Exception:

Microsoft.Management.Services.SelfServicePortal.Common.Portable.DataAccess.Exceptions.ServiceTooBusyException

Message:

HTTP request failed: 509

Error response by downstream service:

{

"odata.error": {

"code": "HttpSysQueueTimeout",

"message": {

"lang": "en-us",

"value": {

"Message": "An error has occurred while retrieving the Intune application catalog.",

"CustomApiErrorPhrase": "",

"RetryAfter": null,

"ErrorSourceService": "StatelessApplicationService",

"HttpHeaders": {

"unhealthyEndpoints": "True"

}

}

}

}

}

reddit.com
u/gurban2013 — 3 days ago
▲ 24 r/ammo

veteran ammo is still indeed garbage and they are scummy

veteran ammo is still indeed garbage and they are scummy. do not buy it it will destroy your firearm or possibly result in injury.

reddit.com
u/gurban2013 — 5 days ago
▲ 3 r/Intune

North America tenant outage for Windows apps?

anyone else getting error 5003 on windows > apps > app app
tried the usual browser cache. different SSID. mobile hotspot.

  • Resource ID Not available
  • Extension Microsoft_Intune_Apps
  • Content AppWizardBlade
  • Error code 503
reddit.com
u/gurban2013 — 8 days ago

Top panel of door rubs slightly on the center rail / carrier arm

i just noticed that the center of my door is slightly rubbing the center overhead carrier rail for the motor arm or whatever its called.
panel of door rubs slightly on the center rail / carrier arm when at the apex both open and close. this is when the doors top panel is at a 45 degree.

i check all the bolts, hinges, hook arm etc. everything was secure. (overly tight TBH)
so i went through and serviced and lubed everything per manual.

checked the clearance gap around the sides of door to jam and the top of door to top plate. left and right sides are about 1/4inch and the top 3/16 or so on the side and 1/2 in the middle.

no bend or damage to the top rail horizontal support brace.

i set the chain tension per manual spec. (it was only slightly loose, nothing wild)

i reset the limits at the door (was slightly pushing down to much. only needed one button press adjusting on down limit to resolve)

pulled the release handle and validated it still rubs slightly under man power vs motor.

any ideas? the motor is about 1.5 inch above the wall mount for center rail.

do i just need to raise the wall mount 2 inches and adjust the hook arm and limits?

u/gurban2013 — 15 days ago
▲ 2 r/Intune

IOS Enrollment Policy - issues or bug with company portal and management profiles?

I am trying to test the newer iOS Enrollment Policies using User Affinity with Modern Authentication instead of the older Enrollment Profiles.

One thing I've noticed is that the "Install Company Portal with VPP" setting exists in Enrollment Profiles, but I don't see an equivalent setting in the new Enrollment Policies.

My test Policy configuration is using:

  • User Affinity with Modern Authentication
  • Company Portal deployed as a VPP app

I tested deploying Company Portal as a required VPP app, and it installs successfully. However, when I launch Company Portal and sign in with my Entra ID credentials, it immediately prompts me to set up company access and download a management profile.

This doesn't seem correct because the device was already enrolled through ADE. If I select Postpone, Company Portal reports that I can't access company resources, and when I check further, it states that the device must be managed before apps can be installed.

this has to be a bug or something right? the microsoft docs on this are very confusing or missing details.

I also noticed that the device initially appears in Intune/entra as "iPad". After some time, the name eventually updates in entra and intune, However, within the Company Portal app, I end up seeing two devices:

  1. "iPad" (This is the Ipad that you're currently using)
  2. "ipad123-testing" ( this is the proper name and matches intune / entra)

Under Settings > General > VPN & Device Management, I can see the correct Intune management profile installed. Sync and restart actions from Company Portal also work successfully.

It appears that Company Portal is not associating itself with the existing ADE enrollment record. Instead, it seems to be attempting a user-driven enrollment workflow on a device that is already enrolled and managed through ADE.

Has anyone else seen this behavior when using the new iOS Enrollment Policies with User Affinity and Modern Authentication? its unusable in this state.

i saw a random blog about using an app config to set xml for the company portal app but that cant be right for such a vanilla use case? didnt need to do that with the old profiles.

reddit.com
u/gurban2013 — 23 days ago

Auto download images for trusted domains and recipients

Hello all,

trying to have images from a domain auto download for all users. testing right now with 1 account and i tried the Set-MailboxJunkEmailConfiguration and added the domain. it didnt work. the images are on a subdomain of the parent if that matters. photos.domain.com instead of the allowed domain.com

toggling the dont download pictures automatically resulted in them automatically appearing but the wording makes me thinks its for all emails not the trusted domains. which is insecure.

i do not have the domain added to any ATP rules at this time.

what am i missing here?

https://preview.redd.it/stksrgb5u6fh1.png?width=821&format=png&auto=webp&s=e073155b8aafe7676614dace4d8ad8f1b10f4cb2

reddit.com
u/gurban2013 — 27 days ago
▲ 3 r/Intune

mac DDM -target date and version

Have had some issues with % of devices, that do not update when DDM target date and version was used.

Tested across 30 devices. 3 separate times.
7 days, 5 days, 2 days in the future, all for 15.7.7 version.

in each test i validated that each device has the update with install status as prepared. had plenty of disc space over 50gb+, battery over 50%, and i let the device sit a few days 3+ after the target date too just to make sure it wasnt somehow a temporary issue or a user somehow was getting around it.

Some devices would update day of, some would update the next day, some would update 2/3 days later. if it didnt update within 3 days the device wouldnt update in that group.

those that did not update in group one, i added to group 2 and again mixed results, and same experience for remaining in group 3.

These were all on different version of macOS 14 Sonoma and i had the appropriate update settings applied as well not that it should matter per apple and Microsoft documentation enforce latest and target version override everything.

anyone else experience this on Sonoma? have not tried DDM for anything on Sequoia 15 or Tahoe 26.

when it worked it worked great. but always seems like there is a small % that just does not work initially for no obvious reason.

everything is ADE, supervised, checks in daily all that is fine.

apple
https://support.apple.com/en-ca/guide/deployment/depc30268577/web

https://learn.microsoft.com/en-us/intune/device-updates/apple/?tabs=automatic-updates

reddit.com
u/gurban2013 — 2 months ago
▲ 9 r/AZURE

Azure Conditional Access policys for privileged accounts

Curious what others are doing in Azure CAPs to secure their privilege accounts. both in M365 Azure roles and the subscriptions. i am not looking hear about what microsoft docs say or this is best practice or basic common sense things like geo blocks and require mfa. curious what people are actually implementing.

Topics PIM, Phishing resistant, sign in frequency, Authentication Contexts. combine with federation with a 3rd party.

have been messing with this in great detail for multiple use cases and some of the behavior is that azure just kind of ignored things.

for example my experience is that Microsoft Entra ID may reuse an existing authenticated session if the current authentication already satisfies the required Authentication Strength and Conditional Access policy requirements. As a result, a fresh MFA challenge is not always triggered during PIM activation. this makes requiring mfa at every PIM activation useless when trying to use least standing privilege and a user may need to active 2 or more roles.

reddit.com
u/gurban2013 — 2 months ago
▲ 1 r/Intune

Intune windows 365 - Device prep policy broken. (tenant location NA0201)

Hey yall working in device prep policys in my tenant for some windows 365 enterprise and frontline /flex when i edit the apps /scripts section its broken.

issues
if i add an app and save it saves under scripts. and sometimes removes the apps that got added to scripts.
if i remove from scripts and saves, nothing saves.

its completely hosed. had a friend in a separate tenant test and same issue different tenant region.

this is a big issue cloud PCs are not getting the apps installed during device prep prior to provisioning.

Edit*
this is policy is type "automatic"

reddit.com
u/gurban2013 — 3 months ago
▲ 1 r/Intune

Mac DDM Os updates - not applicable

looks like a handful of straggler devices on macOS 14 are showing as not applicable for the intune DDM OS updates policy.

is this a MacOS 14 thing? anyone else see that? i can have Techs reach out to users and run the updates or whatever just curious wanted to ask the community.

Allow Standard User OS Updates
Allowed
Automatic Actions
Download
AlwaysOn
Install OS Updates
Always On
Install Security Update
AlwaysOn
Deferrals
Major Period In Days
90
Minor Period In Days
7
System Period In Days
2
Notifications
Enabled
reddit.com
u/gurban2013 — 3 months ago

ADA or easier to reset GFCI outlet?

hello genuine question.

i did some light searching but didnt see anything obvious and wanted to ask the community who do this daily.

i have a family member with some limitation in their fine motor skills and occasionally a GFCI outlet trips in their house. normal stuff like to many appliance on 1 outlet or spike when window unit kicks on, things that occasionally happen and are rare but i cant always be there to help, and they have trouble resetting the tiny buttons.

i thought about swap it to a non-gfci receptacle and put a gfci breaker in. but i would rather them not go into the panel as its not the most accessible for someone in their state.

is there any other good solutions? i was hoping there was something that either had no outlets and was just the two buttons or maybe a single outlet and the bottom was two larger buttons instead of duplex.

thank you all

reddit.com
u/gurban2013 — 3 months ago
▲ 5 r/Intune

thoughts i would post this to explain the recent experience when cutting over to cloud update.

Last week, went through a migration of moving away from GPO, and Intune and m365 admin center to migrate to config.offfice.com cloud update to manage the office update channel. align to monthly channel.

The Good.

Overall very happy. once i figured out where do click in the portal to actually cut the devices over.
there is a clear and simply Pop up alert to end user when o365 apps are running, allows postpone and the process takes less than 1 minutes to update the binaries. it reopened the apps after. it does NOT reinstall office unless you change from x86 to x64.

ref doc.

https://learn.microsoft.com/en-us/microsoft-365-apps/best-practices/adopting-cloud-update

  • Easy onboarding: Devices in scope of cloud update automatically bypass other Microsoft 365 Apps update configurations, with no need for detachment. If out-of-scope, previous controls are restored. Cloud update applies solely to Microsoft 365 Apps, leaving other app configurations unchanged. Thus, a device can be simultaneously managed by two solutions without conflict.

i did make an intune policy for all windows devices and set enforce updates settings with no channel just to catch any device that may not get picked up by cloudupdate. and there is no risk because of this. good move here.

The Bad.
The web UI is a bit confusing on where to go to actually do this.
needs to clarity.
There is no option to cut over all devices.
You basically have to keep coming in here and forcing devices to change channels. if there is something that installs office in a different channel. ( m365 admin center >settings m365 install settings, or other installers with different xml config) the biggest miss from Microsoft docs is that it didn't mention the pop up window for the update process. but it was minimal and testing before pilot groups caught this immediately so a quick play book for help desk handled it if any users were confused.

doesnt manage macs. thats disappointing. and another "gotchya" when microsoft says oh we can manage macs easily.

reddit.com
u/gurban2013 — 3 months ago
▲ 1 r/Intune

trying to push a new version of global protect VPN pkg to my macs and getting "The app is running and could not be updated. The update will be tried the next time the device syncs. (0x87D30145)"

is there a way to kill the process prior? just use a preinstall script or what?

reddit.com
u/gurban2013 — 4 months ago