Ability to Set / Deploy HKLM & HKCU Registry keys
Similar to how it's done in GPP, Having the ability to deploy / set HKCU & HKLM registry keys against Win10 devices would be extremely helpful.
Currently to do this we need to use a custom powershell script for anything not ADMX based which in my example is setting a application licensing server for the user based on a dynamic group (location).
It would be nice if we can do this. Also would be good if this is a specific policy, but also something you can deploy with a win32 application deployment. So you can update/change/create the HKCU or HKLM keys easily with app deployment.
Joerg Aulenbach commented
Security Recommendations dahbourd tells us to Enable 'Local Security Authority (LSA) protection' by setting a regkey. Actually there is no way to configure it in a profile. The ability to set or Deploy HKLM & HKCU Registry keys within Intune would be a great benefit
See also https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/19764631-make-it-possible-to-push-user-based-registry-setti
I think for these two you can count the votes together :-)
Clunky i know - how we are currently doing this is packaging a win32 app that is a bat file for setting the value, and then making the detection script check the registry location. not the cleanest, but it will rerun if needed.
Powershell scripts are also run once which if it ever fails never runs again.