Microsoft

Microsoft Endpoint Manager Intune Feedback

Suggestion box powered by UserVoice

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Manager Intune, though we can’t promise to reply to all posts.

Standard Disclaimer – our lawyers made us put this here ;-) We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Intune feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Intune. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.


  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Policy conflict handling mechanism

    Currently if a user is part of two user-groups and a policy setting conflicts, the setting is not applied.

    For example:- A user is a part of group 'All Company' which allows camera and is also a part of group 'project ABC' which restricts use of camera.
    The more restrictive setting should be applied irrespective whether these two groups have parent-child relationship or not.

    19 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  2. Android Enterprise Device Wipe

    In a company owned device scenario we would like to manage the devices with the wipe function (they are company owned) and not require a user to log in to their google account to install applications that we deploy. Sadly as you know the Android for Work Enrollment option does not provide the option to wipe devices and the Android enrolment for personal use requires a google account to deploy software and while we could use a generic google account for this we do not want people to have access on the device to that account. Android in Kiosk Enrolment…

    19 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  3. Set a device as corporate/personal from the console or AD using AD Writeback.

    Currently a device needs to be pre-enrolled by IMEI/Serial or enrolled by a Device Enrollment Manager to be a corporate device. As this is just a flag in Intune, we should be able to toggle Corporate/Personal after enrollment. Preferably via some sort of API, but possibly through AADConnect/AD.

    19 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  4. "Device cap reached" error message - No devices enrolled

    User gets error device cap reached, but Intune admin consol and Azure AD shows 0 devices.

    Error is caused by the device trying to enroll 5 times without succeeding. The user is then capped until MS Intune server que is purged.

    This must be a design flaw.

    18 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  5. Enable full management of the Windows Firewall

    Enable full management if outgoing as well as incoming firewall rules in Intune Device Configuration Profiles.
    Enabling the management of outgoing firewall rules, and providing the ability add individual exceptions would help prevent data leakage in corporate environments.

    17 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  6. PowerShell with Parameters

    Would be awesome if you could add the ability to pass parameters down to PowerShell scripts.

    Why?
    We have multiple customers running the exact same script, where ONE variable has to be changed according to the customer. Currently we have to create and maintain one script per unique customer. If we could pass parameters through Intune it would make this a whole lot easier and dynamic.

    17 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  7. Better integration with Cisco ISE

    When using NDES to request certificates on behalf of the user of a mobile device this certificate needs to be published in the AD account of the user. At the moment it is stored in the AD service account of the NDES. This way Cisco ISE cannot do the binary comparison needed for certificate authentication.
    If there is a way of integrating Intune/NDES better into Cisco ISE this could be solved or have an option in the CA to tell it to publish the certificate in the correct user account.

    17 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  8. allow device pairing with iTunes

    There is no option to allow device pairing with iTunes. This is a problem whe you have more that 500 iphone managed with apple DEP program and some of these device need to use Itunes...

    16 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    5 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  9. ability to hide Device Categories

    I would like the ability to hide Device Categories. I use them with dynamic groups in order to provision devices. I have a standard group to 'build' a Kiosk device because Apple permissions force me install apps then give them permissions (such as camera). I then switch the category to something that has a KIOSK policy applied.

    The issue is I really do not want the users seeing 30 categories when they enroll their devices.

    Please add a check box that 'hides' the category during enrollment, but allows an admin to change to that category to get policies.

    Yes, you…

    16 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  10. Import the devices according to the deployment profile we create

    I think It would be great if we could import the devices according to the deployment profile we create.

    Ex: we provide Machine S/n, Win product ID and Hardware hash while importing the device and create a dynamic group in Azure AD with query ZTDID, which includes all the machines imported.

    Here we cannot segregate according to the department.

    If we could add Deployment group while importing the devices and that fit in to the deployment profile and then we add the Azure AD Group (Dynamic query enrollment profile) to the deployment profile, so whatever devices are there in dep…

    15 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    1 comment  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  11. Search devices by ICCID

    It would be really helpful if we could search devices by the ICCID of the currently inserted SIM card. Sometimes our users switch the SIM cards between devices and we would like to be able to check which SIM is in which device.

    15 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  12. Adding users to Mobile Device Management Issue - Enrollment Problems

    Hi

    We are in the process of setting up Office 365 Mobile Device Management. We've created a MDM policy, created a security group and associated this group with the newly created MDM policy. We have added about 10 users to run as a pilot test.

    There has been a number of scenarios which have occurred whilst setting end user devices up.


    1. Add the user to the security group associated against MDM policy. The user receives the enrollment email, and email stos syncing with Office 365 mailbox on device until they successfully complete the enrollment process

    This is what you expect…

    15 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    4 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  13. Add Location field to Devices

    In the device management it would be great if a location field / column could be added which we could use to add in the office / location of the Smartphone Device.
    This will make it easier to find out how many devices are enrolled into Intune for a specific location.

    15 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  14. taskbar layout not sync

    Update the taskbar layout with the sync with intune.
    Actually, when the policy is applied, the start layout and taskbar are applied. But at first launch, not all the apps are provisoned to the device, meaning that only apps that are present on the device are shown in the start menu and the taskbar.
    Then, as the policy was applied, the part with the xml file for the start menu and taskbar are not sync again, meaning new apps are not shown in the taskbar.
    You have to modify your xml file, and upload a new one, to make it…

    14 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  15. Intune - Device Non-Compliance Notificaiton -End User must get the Non-Complaince alert with(Username, Device ID, Reason of non-Compliance)

    End User & IT Admin must get the Non-Compliance alert & email notification with (Username, Device ID, Reason of non-compliance) and so on.

    In the message option string option should be introduce for customize the notification template and end user will get the required Machine and device details in alert and email notification.

    14 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  16. Setup a notification message for intune to inform system admins about the expiry date of Apple APN certificate.

    Allowing the Apple iOS APN certificate to expire causes a lot of headache to system Admins, the users will have to enroll devices again. so there should be a notification option to remind admins to renew. and the notification (email, SMS, popup notice,...) should occur at least a month in advance.

    14 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  17. Add the possibility of assigning to corporate or personal devices

    It now is possible, by using groups to automaticaly fill that group with devices that have a certain ownership (corporate/personal). It would be great if that step could be eliminated and that it will be possible to just have a pull down menu per app/configuration profile/update policy/etc. where we have the possibility to assign those settings to personal or corporate devices.

    So as an addition to the possibility of adding group memberships or all users or devices.

    For example:
    Say that we have corporate and byo devices. We create 2 device configuration profiles. One for the corporate devices and one…

    14 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  18. The status after applying the StartLayout configuration policy by Windows10 is displayed as "Not applicable".

    Currently, the content of XML set by StartLayout configuration policy ( 1) is reflected immediately in Windows10 device. However, we would inform you the inappropriate behavior that the status ( 2) after applying the policy does not become "Succeeded" instead of continues to be displayed as "Not applicable" when you check from the management screen.


    • 1 Microsoft Intune> Device configuration> Profiles> Create profile> Device restrictions> Start

    • 2 Microsoft Intune> Device configuration> Profiles> Created StartLayout policy> monitor> Device status> [Deployment Status] in the item list

    In addition, we confirmed that the event is reproduced as well by applying sample XML according…

    14 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    2 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  19. Hardware Inventory for Mobile Devices Enrolled by Microsoft Intune and Configuration Manager

    At the moment the inventory we get from our more than 900 WP8 Phones is very limited.
    See also; https://technet.microsoft.com/en-us/library/dn469411.aspx

    Please implement a feature that we can see the following:

    Wi-Fi MAC
    Subscriber Carrier
    Phone Number (for company phones not only the last 4 digits. we need the complete number)

    Phone Number2 (for DUAL SIM phones)
    International Mobile Equipment Identity or IMEI (IMEI)
    Free Storage Space
    Total Storage Space
    Serial Number
    Model (f.e. Lumia 925)
    Manufacturer (f.e. NOKIA)
    Current Operator Name
    Data Roaming Enabled

    13 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  20. Ping feature

    Insert a feature which allows you to "ping" devices from the Intune console, so you can verify if a device is reachable (e.g. for a sync).

    13 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google Microsoft Intune
    Signed in as (Sign out)
    You have left! (?) (thinking…)
    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base