Microsoft

Microsoft Intune Feedback

Suggestion box powered by UserVoice

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Intune, though we can’t promise to reply to all posts.

Standard Disclaimer – our lawyers made us put this here ;-) We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Microsoft Intune feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Microsoft Intune. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.

How can we improve Microsoft Intune

You've used all your votes and won't be able to post a new idea, but you can still search and comment on existing ideas.

There are two ways to get more votes:

  • When an admin closes an idea you've voted on, you'll get your votes back from that idea.
  • You can remove your votes from an open idea you support.
  • To see ideas you have already voted on, select the "My feedback" filter and select "My open ideas".
(thinking…)

Enter your idea and we'll search to see if someone has already suggested it.

If a similar idea already exists, you can support and comment on it.

If it doesn't exist, you can post your idea so others can support it.

Enter your idea and we'll search to see if someone has already suggested it.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Add a policy to prevent device unenrollment from Company portal

    Companies provide devices to their employees and generally wants to make sure that these devices will always remain managed through Intune. It could be interesting to have a policy that prevent users to unenroll a device identified as a company device from the Intune company portal.

    487 votes
    Vote
    Sign in
    Check!
    (thinking…)
    Reset
    or sign in with
    • facebook
    • google
      Password icon
      Signed in as (Sign out)
      You have left! (?) (thinking…)
      56 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →

      The PMs involved have been talking about how best to give you a way to disable the “remove device” action. They think rather than focusing on platform enrollment types (iOS, Android, Windows), they could allow you to disable based on corporate vs personal ownership. I said I’d ask if that would work for you. :-)

      Would that get you want you need?

    • Folder redirection to Onedrive for Business

      I would like to have a Intune Policy to redirect, for example, the Documents folder of an Azure AD Joined device to Onedrive for Business of the user.

      393 votes
      Vote
      Sign in
      Check!
      (thinking…)
      Reset
      or sign in with
      • facebook
      • google
        Password icon
        Signed in as (Sign out)
        You have left! (?) (thinking…)
        20 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
      • Allow blocking of iOS update

        I want the ability to block updating to the newest iOS version. I have users who don't listen when I send out an email blast to not update their devices but I still get users who either don't read or just ignore the email. I want the ability to set the highest version that I want available and to disable updating to the newest version until I release it. Same type of deal as when I have to approve Windows updates.

        183 votes
        Vote
        Sign in
        Check!
        (thinking…)
        Reset
        or sign in with
        • facebook
        • google
          Password icon
          Signed in as (Sign out)
          You have left! (?) (thinking…)
          14 comments  ·  iOS-specific  ·  Flag idea as inappropriate…  ·  Admin →

          I know it’s not a total, perpetual block, but as of the week of August 27 you can configure the days and times when you don’t want devices to install any updates. In a future update, you’ll be able to delay when a software update is visibly shown on the device, from one to 90 days.

          When we deliver the 90-day delay, is that good enough to call this complete? As @Daniil points out, that’s what’s Apple is offering now. And it’s not great to get yourself too out of date with updates.

        • Extend the SCEP enrollment profile with additional Active Directory attributes

          At the moment only two user attributes (CN and UPN) are available to use in SCEP profiles. With our current MDM solution it is possible to use every AD attribute to request a certificate with this unique attribute. Both Intune and the other MDM solution are using the same SCEP server so it is possible. This seems like extending a table in Intune or using a text box with variables. We have the need to use ExtensionAttributes as the unique identifier for a certificate.

          132 votes
          Vote
          Sign in
          Check!
          (thinking…)
          Reset
          or sign in with
          • facebook
          • google
            Password icon
            Signed in as (Sign out)
            You have left! (?) (thinking…)
            5 comments  ·  Certs, Email , VPN, Wi-Fi  ·  Flag idea as inappropriate…  ·  Admin →

            AS of the week of April 23, 2018, you can use the OnPremisesSamAccountName the common name in a custom subject on an SCEP certificate profile. For example, you can use CN={OnPremisesSamAccountName}).

            As of Dec 11, when you create a SCEP certificate profile in Intune, you can now use the AAD_DEVICE_ID variable when you build the custom subject name. When the certificate is requested using this SCEP profile, the variable is replaced with the AAD device ID of the device making the certificate request.
            https://docs.microsoft.com/en-us/intune/whats-new

            I don’t think it gives you everything you want, but how close are we?

          • Static computernames in Windows autopilot before Intune autoenrollment.

            Maybe posting this to the wrong component-team but a suggestion would be to give the ability to set a static computername to the imported device when registering the csv file containing hardware information in "Autopilot deployment". The current functionality randomizes the computername after each factory reset or reinstallation. Seems pointless to perform a namechange after Intune autoenrollment. This would solve alot of of administrative issues within larger organizations.

            128 votes
            Vote
            Sign in
            Check!
            (thinking…)
            Reset
            or sign in with
            • facebook
            • google
              Password icon
              Signed in as (Sign out)
              You have left! (?) (thinking…)
              12 comments  ·  Windows-specific  ·  Flag idea as inappropriate…  ·  Admin →

              As of the week of August 27, you can use a template to control how the machine will be automatically named. So not exactly static, but gets you away from total random.

              When you create an autopilot deployment profile, you can designate a name, which must be 15 characters or less, and can contain letters, numbers, and hyphens. Names can’t be all numbers. Use the SERIAL macro to add a hardware-specific serial number. Alternatively, use the RAND:x macro to add a random string of numbers, where x equals the number of digits to add.
              https://docs.microsoft.com/en-us/intune/enrollment-autopilot#create-an-autopilot-deployment-profile

              It’s only available with the Windows Insider build for now.

              Do you really need static? Or is “not random” close enough?

            • Apply filters for Apps expiration in Azure as same as Classic Portal

              For a Large enterprise its Difficult to keep a track of App expiry date and notify the vendors or relevant dev teams. In Classic portal earlier we could apply the filters and get a consolidated report of app about to expire in next 40 days.

              Same feature does not imply in Azure Admin console , We have to manually check the App expiry for iOS provisioning profiles.

              48 votes
              Vote
              Sign in
              Check!
              (thinking…)
              Reset
              or sign in with
              • facebook
              • google
                Password icon
                Signed in as (Sign out)
                You have left! (?) (thinking…)
                4 comments  ·  Azure Admin Console  ·  Flag idea as inappropriate…  ·  Admin →
              • Option to force users to accept terms and conditions each time they enroll a new device.

                Currently, once a user accepts the deployed Terms and Conditions across one of their enrolled devices, they will not be required to accept the Terms and Conditions again on any of their other devices.

                From https://docs.microsoft.com/en-us/intune/terms-and-conditions-create:
                "Users only have to accept updated terms and conditions once. Users with multiple devices don't have to accept terms and conditions on each device."

                This is a request to create the option to force users to accept deployed terms and conditions each time they enroll a new device, even if they have already accepted them on the first device they have enrolled.

                37 votes
                Vote
                Sign in
                Check!
                (thinking…)
                Reset
                or sign in with
                • facebook
                • google
                  Password icon
                  Signed in as (Sign out)
                  You have left! (?) (thinking…)
                  2 comments  ·  Company Portal (all platforms)  ·  Flag idea as inappropriate…  ·  Admin →
                • Windows 10 IoT enterprise support in InTune.

                  It would be great to have the ability to manage windows 10 IoT builds with InTune as an MDM solution

                  25 votes
                  Vote
                  Sign in
                  Check!
                  (thinking…)
                  Reset
                  or sign in with
                  • facebook
                  • google
                    Password icon
                    Signed in as (Sign out)
                    You have left! (?) (thinking…)
                    1 comment  ·  Windows-specific  ·  Flag idea as inappropriate…  ·  Admin →
                  • Prevent apps to be uninstalled

                    Some mobile apps could be required by the company as mandatory on the device (antivirus for instance). Having a feature that could prevent user to uninstall some application could help on a better user support.

                    19 votes
                    Vote
                    Sign in
                    Check!
                    (thinking…)
                    Reset
                    or sign in with
                    • facebook
                    • google
                      Password icon
                      Signed in as (Sign out)
                      You have left! (?) (thinking…)
                      2 comments  ·  Apps (all platforms)  ·  Flag idea as inappropriate…  ·  Admin →
                    • Implement MDM-approved kernel extension loading for macOS

                      Please implement kernel extension whitelisting for macOS. A change in macOS High Sierra has made it so that kernel extensions have to be user-approved or whitelisted by profiles deployed by MDM. Kernel extensions include critical applications like hardware drivers, and anti-virus utilities.

                      More information in the links below:

                      https://support.apple.com/en-us/HT208019
                      https://developer.apple.com/library/content/technotes/tn2459/_index.html
                      http://www.richard-purves.com/2017/11/09/mdm-and-the-kextpocalypse-2/

                      19 votes
                      Vote
                      Sign in
                      Check!
                      (thinking…)
                      Reset
                      or sign in with
                      • facebook
                      • google
                        Password icon
                        Signed in as (Sign out)
                        You have left! (?) (thinking…)
                        2 comments  ·  MacOS-specific  ·  Flag idea as inappropriate…  ·  Admin →

                        I’ll change the status back to “needs more info” and talk to the PM who owns this feature

                        previously posted: As of the week of April 23, 2018, Intune supports User Approved MDM enrollment. Devices enrolled using the macOS Company Portal are considered “Not User Approved” unless the end user opens System Preferences and manually provides approval. To this end, the macOS Company Portal now directs users on macOS 10.13.2 and above to go and manually approve their enrollment at the end of the enrollment process. The Intune admin console will report on if an enrolled device is user approved.
                        https://docs.microsoft.com/en-us/intune/whats-new
                        Thanks for your feedback! Please go vote on other things you’d like to see.

                      • Setup a notification message for intune to inform system admins about the expiry date of Apple APN certificate.

                        Allowing the Apple iOS APN certificate to expire causes a lot of headache to system Admins, the users will have to enroll devices again. so there should be a notification option to remind admins to renew. and the notification (email, SMS, popup notice,...) should occur at least a month in advance.

                        13 votes
                        Vote
                        Sign in
                        Check!
                        (thinking…)
                        Reset
                        or sign in with
                        • facebook
                        • google
                          Password icon
                          Signed in as (Sign out)
                          You have left! (?) (thinking…)
                          0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
                        • Allow organizations to remove the full wipe option from non-company owned devices

                          Allow an organization to define user-owned devices and remove the ability to perform full wipes on those devices.

                          12 votes
                          Vote
                          Sign in
                          Check!
                          (thinking…)
                          Reset
                          or sign in with
                          • facebook
                          • google
                            Password icon
                            Signed in as (Sign out)
                            You have left! (?) (thinking…)
                            5 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
                          • Software Publisher tool for Mac OS

                            Currently it is not possible to publish apps using a Mac OS device because the Software Publishing tool is not compatible with Mac OS (Intune standalone obviously). This is a major blocker in a Mac only environment.

                            10 votes
                            Vote
                            Sign in
                            Check!
                            (thinking…)
                            Reset
                            or sign in with
                            • facebook
                            • google
                              Password icon
                              Signed in as (Sign out)
                              You have left! (?) (thinking…)
                              1 comment  ·  Apps (all platforms)  ·  Flag idea as inappropriate…  ·  Admin →
                            • Windows (built-in) VPN Provider for Windows 10 / Mobile

                              According to documentation (see link below) Intune only supports creating VPN profiles for a set list of connection types; Cisco AnyConnect, Pulse Secure, F5 Edge Client, Dell SonicWALL Mobile Connect and CheckPoint Mobile VPN

                              https://docs.microsoft.com/en-us/intune/deploy-use/vpn-connections-in-microsoft-intune#vpn-connection-types

                              The Windows (built-in) VPN Provider for Windows 10 / Mobile should also be supported.

                              7 votes
                              Vote
                              Sign in
                              Check!
                              (thinking…)
                              Reset
                              or sign in with
                              • facebook
                              • google
                                Password icon
                                Signed in as (Sign out)
                                You have left! (?) (thinking…)
                                1 comment  ·  Windows-specific  ·  Flag idea as inappropriate…  ·  Admin →
                              • Outlook as a managed email profile

                                My organisation is looking to replace our windows phones in the near future, most likely with Android devices. We have been looking into Android for work as the option to use.

                                Currently the managed email profiles in intune are for only gmail and 9work. Are there any plans to use Outlook as a a managed email profile? Our users are familiar with outlook and we are a company that uses MS as our preferred option.

                                Currently we have a separate MAM policy to allow/enable outlook on an Android phone, so we have control of things through this means. This policy…

                                3 votes
                                Vote
                                Sign in
                                Check!
                                (thinking…)
                                Reset
                                or sign in with
                                • facebook
                                • google
                                  Password icon
                                  Signed in as (Sign out)
                                  You have left! (?) (thinking…)
                                  0 comments  ·  Android-specfiic  ·  Flag idea as inappropriate…  ·  Admin →
                                • Add ability to see a policies apllied to a device or something similar.

                                  Being able to see the policies applied to a device and not just the last synch time would be very helpful from a testing standpoint and allow one to not spend time wondering whether or not the newly created policy was actually synched.

                                  3 votes
                                  Vote
                                  Sign in
                                  Check!
                                  (thinking…)
                                  Reset
                                  or sign in with
                                  • facebook
                                  • google
                                    Password icon
                                    Signed in as (Sign out)
                                    You have left! (?) (thinking…)
                                    0 comments  ·  Mobile Device Management (general)  ·  Flag idea as inappropriate…  ·  Admin →
                                  • Assign all devices in a dynamic group to a device category

                                    It would be great if we could assign devices to a category based on their dynamic group assignment. We have a naming convention for all of our Windows PCs that we can create a Dynamic Device group to query that name and since we know that devices that follow that convention are always going to be company-owned Windows 10 devices, we would like to be able to assign every device in that group to our "Corporate Windows 10" Device Category.

                                    3 votes
                                    Vote
                                    Sign in
                                    Check!
                                    (thinking…)
                                    Reset
                                    or sign in with
                                    • facebook
                                    • google
                                      Password icon
                                      Signed in as (Sign out)
                                      You have left! (?) (thinking…)
                                      0 comments  ·  Azure Admin Console  ·  Flag idea as inappropriate…  ·  Admin →
                                    • Better Customer Service

                                      Customer service that is actually useful, that would be great!

                                      3 votes
                                      Vote
                                      Sign in
                                      Check!
                                      (thinking…)
                                      Reset
                                      or sign in with
                                      • facebook
                                      • google
                                        Password icon
                                        Signed in as (Sign out)
                                        You have left! (?) (thinking…)
                                        1 comment  ·  Flag idea as inappropriate…  ·  Admin →
                                      • How to disable the Windows 10 Express File totally

                                        PROBLEM STATEMENT:
                                        ============================
                                        How to disable the Windows 10 Express File
                                        WORKAROUND ANALYSIS:
                                        ============================
                                        What we did here is to disable the Windows 10 express file settings. But the previous downloaded updates when the settings still enabled still the download the express because as per MS Premiere it was already save in DB and could not clear it.

                                        I have to download the latest one where the express is not enable, then the files being downloaded is back to normal without the express files.

                                        IMPACT TO BUSINESS:
                                        ============================
                                        The affected here are the Storage and network bandwidth because the files…

                                        1 vote
                                        Vote
                                        Sign in
                                        Check!
                                        (thinking…)
                                        Reset
                                        or sign in with
                                        • facebook
                                        • google
                                          Password icon
                                          Signed in as (Sign out)
                                          You have left! (?) (thinking…)
                                          0 comments  ·  Flag idea as inappropriate…  ·  Admin →
                                        • Regarding the updating of public information for the behavior of assigning apps to the device group

                                          We recognized that there is a divergence in behavior between actual environment and public information is describing.

                                          Title: Assign apps to groups with Microsoft Intune
                                          URL: https://docs.microsoft.com/en-us/intune/apps-deploy

                                          This document mentioned as below
                                          ------------------------------------------------
                                          After you've added an app to Microsoft Intune, you can assign the app to users and devices.

                                          You can assign an app to a device whether or not the device is managed by Intune.

                                          The following table lists the various options for assigning apps to users and devices:
                                          ------------------------------------------------

                                          When apps are assigned as “required” to devices, apps are installed successfully, but if apps are assigned as…

                                          1 vote
                                          Vote
                                          Sign in
                                          Check!
                                          (thinking…)
                                          Reset
                                          or sign in with
                                          • facebook
                                          • google
                                            Password icon
                                            Signed in as (Sign out)
                                            You have left! (?) (thinking…)
                                            0 comments  ·  Intune PC client  ·  Flag idea as inappropriate…  ·  Admin →

                                            Hi,
                                            You posted this under the PC Client category, so I’m not sure if you’re really talking about deploying apps to the full PC client, or deploying apps to PCs managed using the MDM client. If you’re really asking about the PC client, that might be the disconnect with the documentation.

                                          ← Previous 1
                                          • Don't see your idea?

                                          Feedback and Knowledge Base