<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Intune on JanBakker.tech</title><link>https://janbakker.tech/categories/intune/</link><description>Recent content in Intune on JanBakker.tech</description><generator>Hugo</generator><language>en-US</language><copyright>Jan Bakker</copyright><lastBuildDate>Tue, 21 Jul 2026 13:53:20 +0000</lastBuildDate><atom:link href="https://janbakker.tech/categories/intune/index.xml" rel="self" type="application/rss+xml"/><item><title>Lock or sign-out when Yubikey is removed from the device</title><link>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</link><pubDate>Tue, 21 Jul 2026 13:53:20 +0000</pubDate><guid>https://janbakker.tech/lock-or-sign-out-when-yubikey-is-removed-from-the-device/</guid><description>&lt;p&gt;I didn&amp;rsquo;t know there was already a solution for this, and maybe you are looking for it too. I learned about this from the &#10;&lt;a href="https://youtu.be/eXqW3FAY_hE?t=1632" rel="noopener"&gt;Blue Security Podcast&lt;/a&gt;.&lt;/p&gt;&#10;&lt;p&gt;Meet: &#10;&lt;a href="https://www.yubico.com/works-with-yubikey/catalog/sciber/#overview" rel="noopener"&gt;YubiKey Locker | Yubico&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;With YubiKey Locker, implement a protocol-agnostic security key removal policy that seamlessly integrates across various operating systems. This is important in meeting existing smart card customer security requirements (e.g. policies for smart card removal behavior), but also enables the forward-looking customer to bridge to modern protocols like FIDO2 passkeys, while staying compliant with their existing security policies. Moreover, the capability developed by Sciber enhances overall security posture for all organizations by locking the workstation or logging off the user when a YubiKey is not present, so it&amp;rsquo;s a great capability not only for those sunsetting legacy methods or form factors.&lt;/p&gt;</description></item><item><title>Admin control for SSO prompts in Windows; finally, an off switch!</title><link>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</link><pubDate>Thu, 16 Jul 2026 07:15:29 +0000</pubDate><guid>https://janbakker.tech/admin-control-for-sso-prompts-in-windows-finally-an-off-switch/</guid><description>&lt;p&gt;If you&amp;rsquo;ve been paying attention to the EEA sign-in changes over the past while, you&amp;rsquo;ll know Microsoft started prompting users before reusing their Windows credentials to sign in to other Microsoft apps and services. Good for user choice, less great if you&amp;rsquo;re an admin who just spent years getting SSO &lt;em&gt;working&lt;/em&gt; and now watches it ask permission every time.&lt;/p&gt;</description></item><item><title>Block users from viewing their BitLocker keys</title><link>https://janbakker.tech/block-users-from-viewing-their-bitlocker-keys/</link><pubDate>Tue, 16 Aug 2022 10:29:09 +0000</pubDate><guid>https://janbakker.tech/block-users-from-viewing-their-bitlocker-keys/</guid><description>&lt;p&gt;This post is mainly focused on a new tenant setting, where you can prevent your end-users from viewing their Bitlocker keys. By design, your users can see Bitlocker keys from devices they own from the MyAccount portal. &#10;&lt;a href="https://myaccount.microsoft.com/device-list" rel="noopener"&gt;My Account (microsoft.com)&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;For some (large) enterprise organizations, this is an unwanted feature.&lt;/p&gt;</description></item><item><title>Download Intune PowerShell scripts with Graph Explorer</title><link>https://janbakker.tech/download-intune-powershell-scripts-with-graph-explorer/</link><pubDate>Tue, 05 Apr 2022 14:14:46 +0000</pubDate><guid>https://janbakker.tech/download-intune-powershell-scripts-with-graph-explorer/</guid><description>&lt;p&gt;This quick post will show an easy method to fetch your PowerShell scripts after you have uploaded them using the Intune management portal. Unfortunately, the portal does not provide a UI to download the script content as soon as you hit that save button.&lt;/p&gt;</description></item><item><title>Microsoft 365 self-service using Power Apps</title><link>https://janbakker.tech/microsoft-365-self-service-using-power-apps/</link><pubDate>Wed, 12 Jan 2022 15:12:05 +0000</pubDate><guid>https://janbakker.tech/microsoft-365-self-service-using-power-apps/</guid><description>&lt;p&gt;This &#10;&lt;a href="https://techcommunity.microsoft.com/t5/microsoft-365-pnp-blog/microsoft-365-self-service-using-power-apps/ba-p/3056109" rel="noopener"&gt;article&lt;/a&gt; was originally posted on the &#10;&lt;a href="https://techcommunity.microsoft.com/t5/microsoft-365-pnp-blog/bg-p/Microsoft365PnPBlog" rel="noopener"&gt;Microsoft 365 PnP Blog&lt;/a&gt;.&lt;/p&gt;&#10;&lt;p&gt;I was inspired by &#10;&lt;a href="https://www.loryanstrant.com/2021/10/13/automate-your-windows-11-upgrade-with-forms-power-automate-and-intune/" rel="noopener"&gt;this post&lt;/a&gt; from Loryan Strant, that used Microsoft Forms to add users to an Azure AD group so that they were upgraded to Windows 11. With that in mind, I created a mock-up and &#10;&lt;a href="https://twitter.com/janbakker_/status/1470673405183770625" rel="noopener"&gt;posted&lt;/a&gt; it on Twitter.&lt;/p&gt;</description></item><item><title>Food for thought - Bring Your Own Disaster.</title><link>https://janbakker.tech/food-for-thought-bring-your-own-disaster/</link><pubDate>Mon, 28 Sep 2020 14:41:49 +0000</pubDate><guid>https://janbakker.tech/food-for-thought-bring-your-own-disaster/</guid><description>&lt;p&gt;Today a slightly different blog post. It&amp;rsquo;s a common discussion that I face almost daily. Clients that embrace the &amp;ldquo;&lt;em&gt;anywhere, anytime, any device&lt;/em&gt;&amp;rdquo; approach, and want to take control over their data. And that&amp;rsquo;s not as easy as it sounds.&lt;/p&gt;</description></item><item><title>Set additional clocks to Windows 10 using Intune</title><link>https://janbakker.tech/set-additional-clocks-to-windows-10-using-intune/</link><pubDate>Mon, 01 Jun 2020 06:38:14 +0000</pubDate><guid>https://janbakker.tech/set-additional-clocks-to-windows-10-using-intune/</guid><description>&lt;p&gt;When you work for an international company, or you have to deliver support in other timezones, you might find yourself Googling for time in different timezones from time to time. At least I did.&lt;/p&gt;&#10;&lt;p&gt;Then I start looking for a way to make this easier and I was thinking to use BGInfo do reflect the time on my background. When struggling with this for 2 hours, I accidentally stumbled upon this setting, where you can display 2 additional clocks:&lt;/p&gt;</description></item><item><title>Install Windows Package Manager (winget) using Intune</title><link>https://janbakker.tech/install-windows-package-manager-winget-using-intune/</link><pubDate>Sat, 23 May 2020 10:47:27 +0000</pubDate><guid>https://janbakker.tech/install-windows-package-manager-winget-using-intune/</guid><description>&lt;p&gt;Microsoft released a preview of the Windows Package Manager. I&amp;rsquo;m not going into detail about the product itself, because there are a lot of (better) alternatives for this already in the market. Today, we focus on how to get this tool installed on your endpoints, so you can use it for your software distribution. In this approach I use the APPX package. Normally I would use the Business Store for this, that version does not (yet) contain the winget feature.&lt;/p&gt;</description></item><item><title>Manage Teams custom backgrounds using Intune</title><link>https://janbakker.tech/manage-teams-custom-backgrounds-using-intune/</link><pubDate>Thu, 16 Apr 2020 20:10:44 +0000</pubDate><guid>https://janbakker.tech/manage-teams-custom-backgrounds-using-intune/</guid><description>&lt;blockquote&gt;&#10;&lt;p&gt;&lt;strong&gt;Update!&lt;/strong&gt; I got some feedback on this blog. Seems that if your users are not members of the local administrator group, install will faill with error: &lt;strong&gt;0x80070001&lt;/strong&gt;. I&amp;rsquo;ve updated the article to solve this problem. I replaced the cmd files for Powershell scripts and did some minor changes to the detection and uninstall scripts. This should now work for users without admin permissions.&lt;/p&gt;&#10;&lt;/blockquote&gt;</description></item></channel></rss>