For Intune Engineers

What Intune doesn't tell you —
but you'll hit in production.

Real patterns from real environments. Compliance gaps, enforcement blind spots, and the fixes that actually hold up at scale.

Sep 16, 2026

The Ghost Tenant Invoice: Billed for What Microsoft Deleted

Microsoft deleted a CDX (Customer Digital Experiences) partner tenant at scheduled end-of-life. Two subscriptions tied to it kept billing for 27 more months. | $6,980.48 across 65 charges, April 2023 → July 2026 — because a deleted tenant leaves no subscription in the admin center to select or ca...

Read
Jun 29, 2026

Cleaning Up a Dual RealVNC Server Install After Winget Deployment

Winget deploys the new RealVNC Server (7.x) but leaves the legacy MSI install (6.x) behind — two "VNC Server" entries in Add/Remove Programs | Intune Proactive Remediation cleans this up automatically: detects when 2+ server installs coexist, removes the older one via msiexec, keeps the highest v...

Read
May 31, 2026

Passwordless Works — Then M365 Dies a Few Days Later

After a clean passwordless/FIDO2 rollout, users start losing M365 access days or weeks later — long after go-live | A password reset "fixes" it instantly… then it comes back for the next user. Everyone blames the security key

Read
May 18, 2026

FIDO2 Coexistence: RDP, Legacy VPNs, and Recovery Flows

FIDO2 hardware keys cannot satisfy RDP Network Level Authentication — a scoped auth strength or Windows Hello for Business is required for Windows logon scenarios | RADIUS-backed VPNs do not support FIDO2 natively; every generic MFA grant in your CA policies needs an audit after hardware key depl...

Read
May 18, 2026

FortiGate VPN Broken by FIDO2: Diagnosing the CAP Conflict

After deploying FIDO2 hardware keys, FortiGate VPN users were prompted for their YubiKey instead of Authenticator — even though VPN was never scoped for FIDO2 | Root cause: a generic "Require MFA" grant in a CA policy selects the **strongest registered method** when multiple methods exist; once u...

Read
May 18, 2026

Zero-Lockout FIDO2 Rollout: Our Production Wave Plan

The most common FIDO2 rollout mistake is flipping CA enforcement before users are enrolled — causing immediate lockouts | A staged wave approach (Wave 0 prerequisites → Wave 1 pilot → Wave 2 high-risk → Wave 3 general) eliminates that risk

Read

Working on something harder? Talk to Hal → — 20 minutes, no pitch.