How time flies, can you believe it’s the end of July already! I had a lovely few days at the beginning of the week at Loch Lomond to fully recharge the batteries.
A slightly quieter week this week for content, hopefully everyone is enjoying the weather and the holidays (or busy trying to entertain bored children). We do have an exciting Microsoft announcement at the bottom though.
Community Content
We start this week with a look at the new Web Based enrollment for Android Work Profile devices here from Rahul Jindal
https://rahuljindalmyit.blogspot.com/2026/07/demystifying-android-web-based.html
We now have three posts from Joey Verlinden who has had a very busy week! The first post covers an always tricky one to manage, removable devices. Learn how to use Device Control to properly manage what people can and can’t do with them
Block access to removable storage while allowing exceptions? Device Control to the rescue!
The second post is an update to the excellent Conditional Access Framework which is a great way to get your tenant secured quickly and easily
Joey also has a new tool to visualise your existing CA policies and also deploy a secure baseline rapidly.
If you’re running E5, you now have access to the Security Copilot Agents (especially with your free SCUs). In this post, Michael Frank looks at the Change Review agent
https://michaelsendpoint.com/intune/SecurityCopilot/ChangeReviewAgent.html
If you’re doing anything in Graph, this is one you definitely need to be aware of. Multi-Admin approval now also hits your Graph calls. Learn what it means for you in this post from Jannik Reinhard
For those of you running Global Secure Access, this post from Dustin Gullett is a must-read. It shows how you can drop your logs, review, monitor and make sure everything is running as expected
https://zerototrust.tech/global-secure-access-sentinel-workbook/
Microsoft are shortly going to retire SMS and Voice calls for MFA. Find out what this means to you, who is effected and your options in this post from Thomas Marcussen
Following on from the initial look at Windows 365 Reserve, Niall Brady continues testing after the initial 10 day window has passed
If you have noticed a new OneDrive Photos app appearing on your devices which only works with a personal OneDrive account (well done Microsoft), here is a remediation script from Nicky De Westelinck to remove it (I’ve also added it to my debloat script, thank you Nicky!)
https://github.com/nickydewestelinck/MicrosoftIntune/tree/main/Scripts/Remove-OneDrivePhotos
Video Content
Now onto the video content, starting with a look at why you should be using Autopilot and how to do so properly in this video from Jonathan Edwards
Jonathan also covers one I mention a lot, why trusting your Office IP to exclude from MFA is a bad idea
Learn how to configure and deploy Remote Help using the Enterprise App Catalog in this video and post (below) from Mark Oldham
Set Up Microsoft Intune Remote Help with the Enterprise App Catalog
We also have the first two episodes of a full Defender for Endpoint course from Chander Mani Pandey starting with an overview of what it is
Followed by an onboarding guide for the different platforms
Learn how Intune Device Intentory works in this video from Steve Weiner
Microsoft Content
Onto this weeks Microsoft content, starting with a look at the new Export API for bulk jobs from Daniel Gerrity
A very exciting announcement, Registry Inventory is coming to Properties Catalog to quickly check reg keys on your devices. Learn more here from Madison Cooks
That’s all for this week, have an amazing weekend!