Martin Himken | MVP @intune.best · 24/09/2026The preview update contains some interesting information about WinRE👀. What do you mean by 'remote management plug-in for extending WinRE management capabilities for MDM providers'? It's now ~828 MB, by the way. support.microsoft.com/en-us/servic... 000
Martin Himken | MVP @intune.best · 09/09/2026📢 PSA #Windows Update September 2026 warning: Following MS latest recommendation for the WinRE partition size is about 750MB. If your WinRE partition is smaller, Windows Update will attempt to resize the partition, which may result in failure. Be aware :) 010
Martin Himken | MVP @intune.best · 31/08/2026#FringeKnowledge #TheMoreYouKnow Me: ** Puts on dark shades and long coat ** Hey you... You: Me? Me: SHHHHH.... yes you... did you know Amazon is shutting down MTurk? You: MTURK? Me: SHSHSHSSSHHHH yeeess... en.wikipedia.org/wiki/Amazon_...en.wikipedia.orgAmazon Mechanical Turk - Wikipedia 000
Martin Himken | MVP @intune.best · 27/08/2026#Intune has finally gotten the #Autopilot Device Preparation update it needed! Device Association, Device Name templates and configurable OOBE! techcommunity.microsoft.com/blog/intunec... 041
Martin Himken | MVP @intune.best · 19/08/2026📢 Do not disable VBS! I've seen this configuration before and, unfortunately, expect to see it again. If your environment can't support VBS, you're missing out on some of Windows 11's most important built-in security features. Fix whatever is holding you back now! 120
Martin Himken | MVP @intune.best · 04/08/2026Wow! Thank you, Center for Internet Security! For those who don't know me or haven't seen my name on the Windows 11 (Intune) Benchmark, I now also have a fancy badge for it! 🤘 www.credly.com/badges/27fb1...credly.com2026 CIS Benchmarks™ Contributor was issued by The Center for Internet Security to Martin Himken.A CIS Benchmarks Contributor is a subject matter expert within specific technology(ies) who attends most Community meetings and creates or comments on tickets, proposed changes, and discussions. They ... 000
Martin Himken | MVP @intune.best · 30/07/2026#Entra Cloud Sync has just introduced Hybrid Join capability. Attributes cannot be configured yet, but it works! Enable the checkbox for your cloud sync AD > Entra ID configuration and it's done! Run it in parallel with Entra Connect if need be #RTFM #Yeet learn.microsoft.com/en-us/entra/... 000
Martin Himken | MVP @intune.best · 23/07/2026Stern reminder: If you are migrating to cloud-native devices, ensure that your hybrid identities are not in a protected group and that they don't have access to the AdminSDHolder object. This will safe you a lot of time when doing WHfB and Cloud Trust! learn.microsoft.com/en-us/window...learn.microsoft.comAppendix C - Protected Accounts and Groups in Active DirectoryLearn more about: Appendix C: Protected Accounts and Groups in Active Directory 010
Martin Himken | MVP @intune.best · 17/07/2026This is probably the most detailed explanation I’ve ever seen how #WHfB aka Windows Hello works. Many of the #ITSecurity folks might have picked up this document from @bsi.bund.de already, but thus far this 170 page behemoth is a good read! www.bsi.bund.de/SharedDocs/D...bsi.bund.de 000
Martin Himken | MVP @intune.best · 15/07/2026My first #MVPBuzz as a dual MVP! I can now say that I am an Intune and Windows MVP. I'm one of many today - but I couldn't wait to post this! Thank you so much for having me, and thank you to everyone who has supported me. W/ you I wouldn’t have be here. mvp.microsoft.com/en-us/mvp/pr...mvp.microsoft.comMicrosoft Most Valuable ProfessionalsThe Microsoft MVP Program connects technical community leaders with Microsoft to promote engagement, advocacy, and knowledge sharing on Microsoft Products & Services. 180
Martin Himken | MVP @intune.best · 24/03/2026#Windows team is cooking * movable taskbar * more update related reboot control * enhanced search * file explorer speed improvements * WHfB reliability improvements * … This blog covers a lot of the concerns I keep hearing from the community. Nice! blogs.windows.com/windows-insi...blogs.windows.comOur commitment to Windows qualityHello Windows Insiders, I want to speak to you directly, as an engineer who has spent his career building technology that people depend on every day. Windows touches more people's lives than almost a... 000
Martin Himken | MVP @intune.best · 24/02/2026#Windows Backup for Organizations now has First Sign-In Restore! This means you can now have people sign in and select a backup even if the device wasn't enrolled. aka.ms/FirstSignInR...aka.msWindows first sign-in restore experience now available - Windows IT Pro BlogWith Windows Backup for Organizations, you can now restore Windows on even more devices. 000
Martin Himken | MVP @intune.best · 24/01/2026People will be so mad if they already packaged the #OOB KB5077744 or KB5077797 to be deployed in #Intune manually... 040
Martin Himken | MVP @intune.best · 21/01/2026What do #Certificates, #SecureBoot, and #BlackLotus have in common? Read my new blog post for more context on what's actually happening and why you need to do more than just flip a few settings in the long run. Enjoy reading! manima.de/2026/01/secu...manima.deSecure Boot, Certificates and BlackLotus – mAnimA.deMicrosoft wants you to update your Secure Boot certificates as soon as possible. Join me as I explain the situation and take action now! 021
Martin Himken | MVP @intune.best · 22/12/2025Using #PowerShell Graph modules for #Intune or #EntraID administration? Well, the interactive sign in for Connect-MGGraph has finally been fixed! All you need is to update your module(s)! Happy Holidays! github.com/microsoftgra... 030
Martin Himken | MVP @intune.best · 12/12/2025📰 New blog post dropped! In this long due blog post, we explore the "split device" issue in your #Entra tenant a bit more. Don't think you have this? Run the script and find out! manima.de/2025/12/the-...manima.deThe disconnected Entra double computer object problem - Part 1 – mAnimA.deAre there Entra devices in your tenant that you cannot delete? Is your Autopilot device pointing to the wrong Entra device? Read more here! 000
Reposted by Martin Himken | MVPSteve Syfuhs @syfuhs.net · 03/12/2025Oh hey, we're [finally] killing RC4 everywhere officially. www.microsoft.com/en-us/window...microsoft.comBeyond RC4 for Windows authenticationAs organizations face an evolving threat landscape, strengthening Windows authentication is more critical than ever. 1176
Martin Himken | MVP @intune.best · 04/12/2025📰🤯 #Microsoft just announced the biggest #Intune license update since 2023 (release of the first Intune Suite Feature "Remote help"). aka.ms/M365-PIBlog aka.ms/M365Governme... aka.ms/IntuneM365Blog 000
Martin Himken | MVP @intune.best · 26/11/2025📰 Reminder that TLS inspection is unsupported for many of the endpoints required for #Intune services. In this case its the Store endpoints, that are required for things like license validation. github.com/MicrosoftDoc...github.comUpdate intune-endpoints.md by FadiJo · Pull Request #4841 · MicrosoftDocs/memdocsAs per ICM (675845676) SSL inspection is not supported for Microsoft store API and may cause reporting issues so we need to add the note that SSL inspection not supported for Microsoft Store API si... 000
Martin Himken | MVP @intune.best · 19/11/2025#MSIgnite listening to BRK1700 right now. So the „cloud restore“ will use WinRE to download and reinstall Windows. 👌🏻 This is exactly what I wanted for years! Early Christmas if you ask me ❤️ 110
Martin Himken | MVP @intune.best · 18/11/2025"Microsoft Ignite 2025 Book of News" is out and _man_ there is a lot to unpack. Go read about it! Keywords to look for: * Security Copilot * Windows Resiliency Initiative * Maintenance Window and many more! news.microsoft.com/ignite-2025-... 010
Martin Himken | MVP @intune.best · 16/11/2025#PowerShell #Windows I just found one of the weirdest thing. Remember reagentc? If you /disable while using a x86 PowerShell the WinRE.wim will be put into a different folder than when you do it from x64. This is wild. github.com/MHimken/WinR... 100
Martin Himken | MVP @intune.best · 13/11/2025#Intune network requirements page got a huge update! There is now a consolidated list for the network endpoints. Rejoice! However, it's still not fully complete 😭 But updating _that_ list should be much easier than the JSON 😊. learn.microsoft.com/intune/intun...learn.microsoft.comNetwork endpoints for Microsoft Intune - Microsoft IntuneReview endpoints for Intune. This page lists IP addresses and port settings needed for proxy settings in your Intune deployments. 021
Martin Himken | MVP @intune.best · 06/11/2025#Entra will have "soft delete" for _cloud_ security groups. I wonder if this would also restore access to things like Teams private channels and SharePoint. deltapulse.app/message/MC11... I wish I had this feature a couple moons ago...💀deltapulse.appMicrosoft Entra: Soft deletion and restoration for cloud security groupsMicrosoft Entra introduces soft deletion and restoration for cloud security groups, allowing recovery within 30 days while preserving settings, ownership, and m 120
Martin Himken | MVP @intune.best · 03/11/2025📰🆕: The #INR script v1.4 to test #Intune and related network services just got its first big update in a bit. Here's what changed in the latest version. - ID-to-Service list is now available. - Test MCC - Test NuGet - ... Go grab the new version here: github.com/MHimken/Intu...github.comRelease Version 1.4 (Community-Is-Key) released · MHimken/IntuneNetworkRequirementsA handful of updates (full changelog here) are finally implemented: ID-to-Service-List list is now available. This will show you which custom ID is related to which service. Test MCC endpoints Tes... 062
Martin Himken | MVP @intune.best · 24/10/2025PSA: If you're running WSUS you will want to look at MC1178653 in your Message Center. The only workaround to CVE-2025-59287 is denying access to the service. If you haven't patched your Server 2025 yet (and as that update apparently was pulled) this is the replacement fix. 110
Reposted by Martin Himken | MVPWinAdmins Community @winadmins.io · 15/10/2025Hey #Intune peeps, @skiptotheendpoint.co.uk released a new version of his awesome #OpenIntuneBaseline #OIB today for 25H2! stte.me/oib25h2stte.meRelease windows-v3.7 · SkipToTheEndpoint/OpenIntuneBaselineWindows v3.7 - 2025-10-15 - 25H2 Edition Added 🆕 Settings Catalog 🆕Win - OIB - SC - Device Security - D - Administrator Protection - v3.7 Added configuration to enable the new Administrator Protec... 031
Martin Himken | MVP @intune.best · 14/10/2025💡New docs on #Intune "remote device actions". Apparently it was updated this month and while it looks much cleaner now, I think its missing crucial information (like what each action actually does?) I liked the old table more 🙈. learn.microsoft.com/intune/intun... web.archive.org/web/20250328...learn.microsoft.comRemote Device Actions – Wipe, Lock, Locate, and More - Microsoft IntuneDiscover how to use Microsoft Intune to remotely manage, wipe, lock, restart, and secure Android, iOS/iPadOS, macOS, Windows, and ChromeOS devices. Learn about available remote actions, prerequisites,... 000
Martin Himken | MVP @intune.best · 10/10/2025Using #WindowsAutopatch in #Intune? You should go here and Migrate to the Win32 App. This will create an application for you "Windows Autopatch Client Broker" that you can use to deploy the AP service instead of the script. intune.microsoft.com#view/Microso... learn.microsoft.com/en-us/window... 030
Martin Himken | MVP @intune.best · 30/09/2025TIL: Is it #Office ADMX x86 or x64 right for me? They're identical except for a minor version number string in the Lync16.adml files. Just use whichever download you prefer. 000
Martin Himken | MVP @intune.best · 10/09/2025Ok, Citrix really? First of all, Intune has been able to do this for years. So, you've figured that out, and you've even got a working template? Oh, wait a minute - your new ADMX doesn't work too, because you forgot to include EXPLAIN strings in 2 spots. github.com/MHimken/FixM... 000
Reposted by Martin Himken | MVPAnthony J. Fontanez @ajf8729.com · 08/09/2025Reminder! - "The option to move back to Compatibility mode will remain until September 2025. After this date, the StrongCertificateBindingEnforcement registry key will no longer be supported" - support.microsoft.com/en-us/topic/... #ADCS #InfoSecsupport.microsoft.comKB5014754: Certificate-based authentication changes on Windows domain controllers - Microsoft Support 022
Martin Himken | MVP @intune.best · 01/09/2025🖨️💡Have you switched your #Windows printer drivers to v4 or IPP with PSAs yet? Don't know I'm talking about? It's time to read up on this apparently forgotten topic. Out of the five customers I had today, none of them knew about the change. To busy w/ W11. learn.microsoft.com/en-us/window...learn.microsoft.comEnd of Servicing Plan for Third-Party Printer Drivers on Windows - Windows driversThis article provides information on the end of servicing plan for third-party printer drivers on Windows. 122
Martin Himken | MVP @intune.best · 29/08/2025#INR aka #Intune Network Requirements script just got an update and a new home. Update your bookmarks! Also, new ASAs added: * Microsoft Defender for Endpoint * Visual Studio github.com/MHimken/Intu... #MVPBuzzgithub.comGitHub - MHimken/IntuneNetworkRequirements: This tool provides a way to verify Intune network requirements automaticallyThis tool provides a way to verify Intune network requirements automatically - MHimken/IntuneNetworkRequirements 053
Martin Himken | MVP @intune.best · 29/08/2025#Intune "Windows Quality Update management policies" just dropped on the roadmap. This will allow you to control non-security and OOB updates more granular. www.microsoft.com/en-us/micros...microsoft.comMicrosoft 365 Roadmap | Microsoft 365 020
Martin Himken | MVP @intune.best · 01/08/2025You can now specify whether an #ADDS group is an #EntraID group or on-premises. This is called a 'change of SOA'. However, be aware that, since @ajf8729.com and I have only just tried this out, the documentation is incomplete for now. Let me explain...🧵 learn.microsoft.com/en-us/entra/...learn.microsoft.comEmbrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud (Preview) - Microsoft Entra IDLearn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators. 120
Martin Himken | MVP @intune.best · 31/07/2025#WindowsUpdate: Thinking of moving to #Intune and/or #Autopatch? Used GPOs or any RMM tool (yes CM too) to adjust the update settings? This cleanup script is for you. I recently received some requests for this again, so I'll share it once more. github.com/MHimken/tool... #MVPBuzzgithub.comtoolbox/Intune/Platform Scripts/Reset-WindowsUpdateSettings.ps1 at main · MHimken/toolboxThis is my toolbox. Watch where you step. Contribute to MHimken/toolbox development by creating an account on GitHub. 010
Martin Himken | MVP @intune.best · 29/07/2025'Windows 11 cloud-native migration with Microsoft Intune'. There's a great article from @onpremcloudguy.com with lots of useful information in the links. Afterwards, you can read my blog to find out about other relevant technologies 😉 techcommunity.microsoft.com/blog/windows...techcommunity.microsoft.comWindows 11 cloud-native migration with Microsoft Intune - Windows IT Pro BlogLearn how to migrate domain-joined, co-managed Windows 10 devices to Microsoft Intune managed Windows 11. 010
Martin Himken | MVP @intune.best · 29/07/2025Unattended access with Remote Help is on its way! Bear in mind that this is the GA date, so there may be a (private) preview available to join. I still highly recommend checking out the MMCCP to participate in early previews. techcommunity.microsoft.com/blog/windows... #MVPBuzztechcommunity.microsoft.comInnovate with the Microsoft Management Customer Connection Program | Microsoft Community HubMicrosoft engineers and IT pros come together to develop solutions that better meet customer needs. 010
Reposted by Martin Himken | MVPAnthony J. Fontanez @ajf8729.com · 27/07/2025Internet-facing file servers, using SMB over QUIC, and secured using Entra authentication! This turned out to be really easy to get up and running. ajf.one/entrafs #Entra #EntraIDajf.oneInternet-facing File Servers, with a dash of Entra Authentication!Now that the the “Azure AD based Windows Login” extension is available (docs here), a Windows server running in Azure or that is Arc-enabled can now be signed into via Entra ID. When I … 041
Martin Himken | MVP @intune.best · 25/07/2025Since I don't do a lot of macOS administration I completely missed this (thanks Andreas!). LAPS for macOS is here :) learn.microsoft.com/en-us/intune... #MVPBuzzlearn.microsoft.comSet up local admin account creation and password management for macOS devices - Microsoft IntuneSet up macOS account configuration with LAPS through automatic device enrollment for macOS devices in Intune. 000
Martin Himken | MVP @intune.best · 23/07/2025⚠️⚠️The preview update for #Windows 24H2 allows you to pin apps to the start menu ONCE (aka boolean). No mention of how yet though 🙈Finally, no more playing around with start2.bin Also: Quick Machine Recovery and many more things - go read now! support.microsoft.com/en-us/topic/... #MVPbuzzsupport.microsoft.comJuly 22, 2025—KB5062660 (OS Build 26100.4770) Preview - Microsoft Support 021
Martin Himken | MVP @intune.best · 22/07/2025This post does not have enough attention yet. 2.29.1 seems to finally solve the authentication issues that existed in Microsoft.Graph.Authentication for a good while now. Run your Update-Module now! 110
Martin Himken | MVP @intune.best · 21/07/2025In case you're using a Windows 11 IoT version and it isn't a Microsoft Teams Room device, here's a reminder that (since may actually) Autopilot is _not_ supported. learn.microsoft.com/en-us/autopi... I can only assume that's because it - by default - skips the OOBE.learn.microsoft.comWindows Autopilot requirementsSoftware, Networking, Licensing, and Configuration requirements for Windows Autopilot. 010
Reposted by Martin Himken | MVPSteve Syfuhs @syfuhs.net · 13/07/2025Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing. support.microsoft.com/en-us/topic/...support.microsoft.comOverview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft SupportSummary of new auditing features and deployment details 34612
Martin Himken | MVP @intune.best · 08/07/2025TIL: Using #Windows #24H2 with activated VBS (which is enabled by default on Windows 11) #WHfB PIN expiration and history are _not supported_. Time to change change some policies... learn.microsoft.com/en-us/window...learn.microsoft.comWindows Hello for Business policy settingsLearn about the policy settings to configure Configure Windows Hello for Business. 000
Martin Himken | MVP @intune.best · 27/06/2025See? Not called Windows12 ¯\_(ツ)_/¯ techcommunity.microsoft.com/blog/Windows...techcommunity.microsoft.comGet ready for Windows 11, version 25H2 - Windows IT Pro BlogReady for the next feature update? Windows 11, version 25H2 is coming as an enablement package (eKB) later this year! 021
Martin Himken | MVP @intune.best · 27/06/2025Oh wow, I just set up another PoC for GSA and checked the recommended ports for domain controllers. That list was extended by a _lot_. This will be hard to argue with some security folks. Mind you the 4 ports before were enough to get a TGT. learn.microsoft.com/en-us/entra/... 010
Martin Himken | MVP @intune.best · 31/05/2025@jgkps and I will be speaking at not just one, but two sessions at #WPNinjasUK25! I'm looking forward to seeing Scotland and meeting more people to discuss passwordless and cloud-native devices with! wpninjas.uk Bring your questions if you've signed up! 010
Martin Himken | MVP @intune.best · 30/05/2025Almost all customers requested this when we did the PoC. „We can’t protect the client otherwise!“. Right, but you should worry about the identity first and you don’t even enforce MFA let alone phishing resistant auth… 110