Sign in

Sascha Stumpler 💻

@sastu-insights.com
203 followers 235 following 1.4K posts

IT Professional working with #Intune #CM #ConfigMgr #M365 #Windows #OSD #PowerShell #Azure #EPM #LeastPrivilege #EPM

PostsRepliesMedia
Sascha Stumpler 💻 @sastu-insights.com · 2h
dlvr.it
Microsoft Intune Settings Catalog updated to support Windows 11, version 26H2
Windows 11, version 26H2 is now available, and Microsoft Intune provides day zero support for valida...
000
Sascha Stumpler 💻 @sastu-insights.com · 26/09/2026
dlvr.it
Aligning Intune Policies with Your Windows Rollout Using OS Version Filters
Microsoft deprecated the osVersion filter property. That sent me through every assignment filter in my tenant, and it turned out the ones doing real work were all doing the same single thing.
000
Sascha Stumpler 💻 @sastu-insights.com · 23/09/2026
dlvr.it
Aligning Intune Policies with Your Windows Rollout Using OS Version Filters
Microsoft deprecated the osVersion filter property. That sent me through every assignment filter in my tenant, and it turned out the ones doing real work were all doing the same single thing.
000
Sascha Stumpler 💻 @sastu-insights.com · 23/09/2026
dlvr.it
What's new for MSPs: September 2026
Welcome to a new series for a new era of MSPs! I'm Bryan Irwin and in this new blog series, I'll sha...
000
Sascha Stumpler 💻 @sastu-insights.com · 22/09/2026
dlvr.it
Workplace Ninja Summit 2026: What I Took Home from Baden
Four days, six tracks, and a venue that still looks like the transformer factory it used to be, right down to the main room being called the Trafohall. The Workplace Ninja Summit in Baden has grown into the place where the European endpoint management community actually talks to each other, and 2026 was no exception.
000
Sascha Stumpler 💻 @sastu-insights.com · 19/09/2026
dlvr.it
Workplace Ninja Summit 2026: What I Took Home from Baden
Four days, six tracks, and a venue that still looks like the transformer factory it used to be, right down to the main room being called the Trafohall. The Workplace Ninja Summit in Baden has grown into the place where the European endpoint management community actually talks to each other, and 2026 was no exception.
000
Sascha Stumpler 💻 @sastu-insights.com · 18/09/2026
dlvr.it
Keep Windows activation automation working with PowerShell
If your organization uses slmgr.vbs to automate Windows activation, now is the time to identify depe...
000
Sascha Stumpler 💻 @sastu-insights.com · 18/09/2026
dlvr.it
Retiring NTLM: Frequently asked questions
NTLM has been a loyal companion to Windows since 1993. It helped us log in and share files, but it a...
000
Sascha Stumpler 💻 @sastu-insights.com · 18/09/2026
dlvr.it
Moving from Windows Autopilot to Windows Autopilot device preparation
By: Maggie Dakeva, Senior Product Manager - Microsoft Intune Organizations have spent years refining...
000
Sascha Stumpler 💻 @sastu-insights.com · 17/09/2026
dlvr.it
Announcing Microsoft Desired State Configuration v3.3.0
This post announces the General Availability of Microsoft Desired State Configuration (DSC) v3.3.0, with new Windows resources, a registry adapter, server mode improvements, expression function updates, expanded what-if support, and experimental export filtering. The post Announcing Microsoft Desired State Configuration v3.3.0 appeared first on PowerShell Team.
000
Sascha Stumpler 💻 @sastu-insights.com · 12/09/2026
dlvr.it
Deploying the Global Secure Access Client with Microsoft 365 Business Premium
The Microsoft 365 traffic profile in Global Secure Access is included in Microsoft 365 Business Premium. No add-on, no Entra Suite, nothing extra to buy. That is easy to miss, because most of what is written about Global Secure Access is written about Private Access and Internet Access, which are not included.
000
Sascha Stumpler 💻 @sastu-insights.com · 09/09/2026
dlvr.it
Deploying the Global Secure Access Client with Microsoft 365 Business Premium
The Microsoft 365 traffic profile in Global Secure Access is included in Microsoft 365 Business Premium. No add-on, no Entra Suite, nothing extra to buy. That is easy to miss, because most of what is written about Global Secure Access is written about Private Access and Internet Access, which are not included.
000
Sascha Stumpler 💻 @sastu-insights.com · 07/09/2026
dlvr.it
Securing Your Certification Authorities (Practical PKI Part 4)
My name is Ron Arestia, and I am a Security Researcher with Microsoft’s Detection and Response Team ...
000
Sascha Stumpler 💻 @sastu-insights.com · 06/09/2026
dlvr.it
The Poor Man’s Remediation: Win32 Apps for Tenants Without Remediation Licenses
Remediations are the single most useful thing in Intune that most small businesses are not allowed to use. Detect a condition, fix it, repeat on a schedule - that pattern solves half of the day-to-day tickets in a managed fleet. And it is licensed out of reach of exactly the tenants that need it most.
000
Sascha Stumpler 💻 @sastu-insights.com · 04/09/2026
dlvr.it
Windows news you can use: August 2026
From device recovery and unattended remote support to post-quantum cryptography readiness and Window...
000
Sascha Stumpler 💻 @sastu-insights.com · 03/09/2026
dlvr.it
The Poor Man’s Remediation: Win32 Apps for Tenants Without Remediation Licenses
Remediations are the single most useful thing in Intune that most small businesses are not allowed to use. Detect a condition, fix it, repeat on a schedule - that pattern solves half of the day-to-day tickets in a managed fleet. And it is licensed out of reach of exactly the tenants that need it most.
110
Sascha Stumpler 💻 @sastu-insights.com · 30/08/2026
dlvr.it
Part 3: Packaging a Drive and Printer Mapping Script with PSAppDeployToolkit and Deploying It with Intune
Part 3 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 - reading AD group data from a cloud-only device and acting on it. Part 2 - running the job only when on-prem AD is actually reachable. Part 3 (this article) - packaging and deploying it with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 29/08/2026
dlvr.it
What’s new in Microsoft Intune – August
At scale, endpoint management becomes a different job. A two-minute task on one device can become mo...
000
Sascha Stumpler 💻 @sastu-insights.com · 28/08/2026
dlvr.it
Introducing device association for Windows Autopilot device preparation
By: Maggie Dakeva, Senior Product Manager - Microsoft Intune We’ve heard organizations want Windows ...
000
Sascha Stumpler 💻 @sastu-insights.com · 27/08/2026
dlvr.it
Part 3: Packaging a Drive and Printer Mapping Script with PSAppDeployToolkit and Deploying It with Intune
Part 3 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 - reading AD group data from a cloud-only device and acting on it. Part 2 - running the job only when on-prem AD is actually reachable. Part 3 (this article) - packaging and deploying it with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 26/08/2026
dlvr.it
Security baseline for Microsoft Edge version 151
We are pleased to announce the enterprise-ready release of the security baseline for Microsoft Edge ...
000
Sascha Stumpler 💻 @sastu-insights.com · 26/08/2026
dlvr.it
Remote Help on Windows: Unattended Support with Remote Sign-In Is Here
By: Rodolfo Bermudez | Sr. Product Manager & Kara Wang | Product Manager 2 - Microsoft Intune He...
000
Sascha Stumpler 💻 @sastu-insights.com · 24/08/2026
dlvr.it
Support tip: Restore the Managed Home Screen Exit PIN
We identified and resolved a recent issue (IT1450132) that could cause the configured Managed Home S...
000
Sascha Stumpler 💻 @sastu-insights.com · 23/08/2026
dlvr.it
Part 2: Running a Scheduled Task Only When Active Directory Is Actually Reachable
Part 2 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 - reading AD group data from a cloud-only device and acting on it. Part 2 (this article) - running the job only when on-prem AD is actually reachable. Part 3 - packaging and deploying the whole thing with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 20/08/2026
dlvr.it
Part 2: Running a Scheduled Task Only When Active Directory Is Actually Reachable
Part 2 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 - reading AD group data from a cloud-only device and acting on it. Part 2 (this article) - running the job only when on-prem AD is actually reachable. Part 3 - packaging and deploying the whole thing with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 20/08/2026
dlvr.it
Configure Delivery Optimization for Windows to save bandwidth and speed up deployments
By: Carlos Diaz - Sr. Product Manager and Jason Sandys - Principal Product Manager | Microsoft Intun...
000
Sascha Stumpler 💻 @sastu-insights.com · 20/08/2026
dlvr.it
Collecting Delivery Optimization logs the easy way
You've deployed Delivery Optimization settings and perhaps even a Microsoft Connected Cache node to ...
000
Sascha Stumpler 💻 @sastu-insights.com · 17/08/2026
dlvr.it
Part 1: Using Active Directory Information on Cloud-Only Devices to Map Printers and Shares
Part 1 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 (this article) - reading AD group data from a cloud-only device and acting on it. Part 2 - running the job only when on-prem AD is actually reachable. Part 3 - packaging and deploying the whole thing with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 15/08/2026
dlvr.it
Windows device recovery in 2026: A guide for IT pros
Windows device recovery is fundamentally stronger today than it was a year ago. Thanks to your feedb...
000
Sascha Stumpler 💻 @sastu-insights.com · 14/08/2026
dlvr.it
Part 1: Using Active Directory Information on Cloud-Only Devices to Map Printers and Shares
Part 1 of 3 in the Drive and printer mappings for Entra-joined devices series. Part 1 (this article) - reading AD group data from a cloud-only device and acting on it. Part 2 - running the job only when on-prem AD is actually reachable. Part 3 - packaging and deploying the whole thing with PSAppDeployToolkit and Intune.
000
Sascha Stumpler 💻 @sastu-insights.com · 09/08/2026
dlvr.it
Microsoft Removes memberOf for Dynamic Groups - Now What?
Microsoft published MC1448379: the memberOf rule operator in Microsoft Entra ID is being retired on November 3, 2026. If you’ve used memberOf to build dynamic groups whose membership depends on nested group membership - user.memberOf -any (group.objectId -eq '...') - those rules stop being evaluated once the deadline hits. Membership freezes at its last known state instead of erroring out, which is the annoying part: nothing breaks loudly, access and licensing just quietly go stale.
000
Sascha Stumpler 💻 @sastu-insights.com · 06/08/2026
dlvr.it
Microsoft Removes memberOf for Dynamic Groups - Now What?
Microsoft published MC1448379: the memberOf rule operator in Microsoft Entra ID is being retired on November 3, 2026. If you’ve used memberOf to build dynamic groups whose membership depends on nested group membership - user.memberOf -any (group.objectId -eq '...') - those rules stop being evaluated once the deadline hits. Membership freezes at its last known state instead of erroring out, which is the annoying part: nothing breaks loudly, access and licensing just quietly go stale.
011
Sascha Stumpler 💻 @sastu-insights.com · 04/08/2026
dlvr.it
Windows news you can use: July 2026
July delivered a wide range of Windows updates for IT admins, with new capabilities across security,...
000
Sascha Stumpler 💻 @sastu-insights.com · 03/08/2026
dlvr.it
From hours to minutes: Rethinking Microsoft Intune compliance reporting with the Export API
By: Daniel Gerrity – Principal Product Manager | Microsoft Intune If you manage a large device fleet...
000
Sascha Stumpler 💻 @sastu-insights.com · 03/08/2026
dlvr.it
What’s new in Microsoft Intune – July
Ask an IT admin what a good day looks like, and it usually comes down to one word: control. Control ...
010
Sascha Stumpler 💻 @sastu-insights.com · 19/07/2026
dlvr.it
Auto-Accepting the “Continue to sign in” SSO Prompt with Intune
If you manage Windows devices in the European Economic Area, you have met this dialog: a user signs in, opens Word, and Windows asks whether it may share the signed-in work account with Microsoft apps - “Continue to sign in”. Microsoft added the prompt to comply with the Digital Markets Act, and on paper it gives users control over their credentials. In a managed environment it mostly gives them a new way to break single sign-on.
000
Sascha Stumpler 💻 @sastu-insights.com · 17/07/2026
dlvr.it
Automatically Migrate Apple Enrollment Profiles as Enrollment Policy
After I wrote about migrating Apple ADE enrollment profiles to the new enrollment policies, someone asked me on LinkedIn whether the recreation step could be scripted. The article covers that part manually: open the wizard, tick through every Setup Assistant screen, one profile at a time. That’s fine for a single token with two or three profiles. It stops being fine once you’re doing it across several enrollment program tokens with iOS and macOS profiles on each.
000
Sascha Stumpler 💻 @sastu-insights.com · 16/07/2026
dlvr.it
Auto-Accepting the “Continue to sign in” SSO Prompt with Intune
If you manage Windows devices in the European Economic Area, you have met this dialog: a user signs in, opens Word, and Windows asks whether it may share the signed-in work account with Microsoft apps - “Continue to sign in”. Microsoft added the prompt to comply with the Digital Markets Act, and on paper it gives users control over their credentials. In a managed environment it mostly gives them a new way to break single sign-on.
000
Sascha Stumpler 💻 @sastu-insights.com · 16/07/2026
dlvr.it
Now available: Admin control for SSO prompts in Windows
IT administrators can now automatically accept SSO permissions on managed Windows devices using a su...
000
Sascha Stumpler 💻 @sastu-insights.com · 14/07/2026
dlvr.it
Automatically Migrate Apple Enrollment Profiles as Enrollment Policy
After I wrote about migrating Apple ADE enrollment profiles to the new enrollment policies, someone asked me on LinkedIn whether the recreation step could be scripted. The article covers that part manually: open the wizard, tick through every Setup Assistant screen, one profile at a time. That’s fine for a single token with two or three profiles. It stops being fine once you’re doing it across several enrollment program tokens with iOS and macOS profiles on each.
000
Sascha Stumpler 💻 @sastu-insights.com · 14/07/2026
dlvr.it
Migrating from Apple Enrollment Profiles to the Enrollment Policies
I recently stumbled upon a warning message in the iOS enrollment profiles saying that new features will only be added to the new Enrollment policies, not to the classic enrollment profiles anymore. Interestingly, this change was only mentioned in passing in the What’s new section, in the announcement of enrollment-time grouping for new Apple ADE enrollment policies. There was no dedicated migration announcement, so if you missed that entry, the warning banner in the portal is probably the first time you hear about it.
000
Sascha Stumpler 💻 @sastu-insights.com · 11/07/2026
dlvr.it
Migrating from Apple Enrollment Profiles to the Enrollment Policies
I recently stumbled upon a warning message in the iOS enrollment profiles saying that new features will only be added to the new Enrollment policies, not to the classic enrollment profiles anymore. Interestingly, this change was only mentioned in passing in the What’s new section, in the announcement of enrollment-time grouping for new Apple ADE enrollment policies. There was no dedicated migration announcement, so if you missed that entry, the warning banner in the portal is probably the first time you hear about it.
000
Sascha Stumpler 💻 @sastu-insights.com · 10/07/2026
dlvr.it
Understanding Windows monthly updates: Servicing explained
Windows updates help keep devices secure, reliable, and productive. Whether you're an IT admin or a ...
000
Sascha Stumpler 💻 @sastu-insights.com · 08/07/2026
dlvr.it
Windows settings backup becoming a new resilience baseline
Resilience is about to get easier for the Windows devices you manage! Eligible devices will now have...
000
Sascha Stumpler 💻 @sastu-insights.com · 06/07/2026
dlvr.it
Resetting Forced Edge PWAs: Quick Guide for IT Admins
Every now and then a ticket lands in our queue that reads something like: “The app won’t start anymore.” A quick look shows it is one of the web apps we push out through Edge, force-installed so that everyone has it ready to go. Normally that is convenient - but when the app breaks, the user is stuck. Because it is force-installed, there is no obvious way to remove and reinstall it: the usual “uninstall and try again” simply is not available to them, and the app keeps failing to launch.
000
Sascha Stumpler 💻 @sastu-insights.com · 03/07/2026
dlvr.it
Resetting Forced Edge PWAs: Quick Guide for IT Admins
Every now and then a ticket lands in our queue that reads something like: “The app won’t start anymore.” A quick look shows it is one of the web apps we push out through Edge, force-installed so that everyone has it ready to go. Normally that is convenient - but when the app breaks, the user is stuck. Because it is force-installed, there is no obvious way to remove and reinstall it: the usual “uninstall and try again” simply is not available to them, and the app keeps failing to launch.
000
Sascha Stumpler 💻 @sastu-insights.com · 02/07/2026
dlvr.it
Windows news you can use: June 2026
Earlier this month, we announced that Windows 11, version 26H2—the next annual feature update for Wi...
011
Sascha Stumpler 💻 @sastu-insights.com · 02/07/2026
dlvr.it
Migrating frontline mobile devices: Identity considerations for assigned and shared devices
By: Carol Burns - Principal Product Manager | Microsoft Intune and Sucheta Gawade, Microsoft MVP (Az...
000
Sascha Stumpler 💻 @sastu-insights.com · 30/06/2026
dlvr.it
Streamlining macOS security: Automatically enable AutoFill after Platform SSO registration
By: Chris Kunze - Principal Product Manager | Microsoft Intune Platform single sign-on (SSO) improve...
000
Sascha Stumpler 💻 @sastu-insights.com · 29/06/2026
dlvr.it
Non-Exportable Certificate Authentication for Azure App Registrations
A few years back I started digging into Microsoft365DSC to manage tenant configuration as code. It needs an App Registration to reach all those workloads, and right from the start I decided I did not want a client secret sitting in a config file for it - I wanted certificate authentication instead. What I assumed would be a five-minute New-SelfSignedCertificate one-liner quickly turned into a small side project: every time I thought I was done, I caught myself asking what “secure” actually meant for that private key. Could someone just export it again? Did it have to touch the disk at all? Should it be bound to the hardware? The script grew with each answer, and what you see below is where it eventually landed.
000