<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>Omer Eltayeb — Microsoft 365 Blog</title>
  <link>https://www.oeltayeb.com/</link>
  <description>Practical troubleshooting guides and how-tos for Microsoft Intune, Entra ID, Defender and Exchange Online.</description>
  <language>en</language>
  <atom:link href="https://www.oeltayeb.com/feed.xml" rel="self" type="application/rss+xml"/>
  <item>
    <title>Enrollment Status Page timing out during Autopilot: a step-by-step troubleshooting guide</title>
    <link>https://www.oeltayeb.com/articles/enrollment-status-page-timeout-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/enrollment-status-page-timeout-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>Find the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.</description>
  </item>
  <item>
    <title>Win32 app error 0x87D1041C: the app installed but Intune can't detect it</title>
    <link>https://www.oeltayeb.com/articles/win32-app-0x87d1041c-not-detected.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/win32-app-0x87d1041c-not-detected.html</guid>
    <category>Microsoft Intune</category>
    <description>0x87D1041C means the installer finished but the detection rule found nothing. The usual causes (bitness, install context, version drift) and how to test detection on the device.</description>
  </item>
  <item>
    <title>Windows Autopilot error 0x80180014 when redeploying a device: cause and fix</title>
    <link>https://www.oeltayeb.com/articles/autopilot-error-0x80180014-reenrollment.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/autopilot-error-0x80180014-reenrollment.html</guid>
    <category>Microsoft Intune</category>
    <description>A reused Autopilot device fails MDM enrollment with 0x80180014. Why it happens, and the documented fixes: unblock or remove the stale Intune record and check enrollment restrictions.</description>
  </item>
  <item>
    <title>Reading Intune Management Extension logs: IME, AppWorkload and AgentExecutor explained</title>
    <link>https://www.oeltayeb.com/articles/intune-management-extension-logs-guide.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-management-extension-logs-guide.html</guid>
    <category>Microsoft Intune</category>
    <description>What each Intune Management Extension log records, how to read them with CMTrace, what to search for, how to force a check-in, and how to collect the logs remotely.</description>
  </item>
  <item>
    <title>Noncompliant on the Default Device Compliance Policy? The three built-in checks explained</title>
    <link>https://www.oeltayeb.com/articles/default-device-compliance-policy-noncompliant.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/default-device-compliance-policy-noncompliant.html</guid>
    <category>Microsoft Intune</category>
    <description>Why devices fail the built-in Is active, Enrolled user exists and Has a compliance policy assigned checks in Intune, and how to clear each one before Conditional Access blocks users.</description>
  </item>
  <item>
    <title>BitLocker silent encryption not starting on Intune-managed devices: causes and fixes</title>
    <link>https://www.oeltayeb.com/articles/bitlocker-silent-encryption-not-starting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/bitlocker-silent-encryption-not-starting.html</guid>
    <category>Microsoft Intune</category>
    <description>Silent BitLocker not starting? Check TPM, UEFI, Secure Boot and WinRE, the required policy settings, startup authentication conflicts and recovery key backup to Microsoft Entra ID.</description>
  </item>
  <item>
    <title>Deploying Windows LAPS with Intune and backing up passwords to Microsoft Entra ID</title>
    <link>https://www.oeltayeb.com/articles/windows-laps-intune-entra-backup.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-laps-intune-entra-backup.html</guid>
    <category>Microsoft Intune</category>
    <description>Set up Windows LAPS end to end: enable it in Microsoft Entra ID, build the Intune account protection profile, retrieve and rotate passwords, and check the LAPS event log.</description>
  </item>
  <item>
    <title>Intune Remediations: detect and fix common Windows issues at scale</title>
    <link>https://www.oeltayeb.com/articles/intune-remediations-fix-issues-at-scale.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-remediations-fix-issues-at-scale.html</guid>
    <category>Microsoft Intune</category>
    <description>Set up Intune Remediations end to end: licensing and tenant attestation, the exit-code contract, run context, schedules, on-demand runs and reading the results.</description>
  </item>
  <item>
    <title>Finding and fixing Intune policy conflicts with the MDM diagnostic report</title>
    <link>https://www.oeltayeb.com/articles/intune-policy-conflicts-mdm-diagnostics.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-policy-conflicts-mdm-diagnostics.html</guid>
    <category>Microsoft Intune</category>
    <description>Settings stuck on Conflict in Intune? Find the competing policies, confirm what the device received with the MDM diagnostic report and event log, and rule out Group Policy.</description>
  </item>
  <item>
    <title>Windows 11 feature update not offered by Intune? A troubleshooting checklist</title>
    <link>https://www.oeltayeb.com/articles/windows-11-feature-update-not-offered-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-11-feature-update-not-offered-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Feature update policy assigned but nothing offered? Check licensing, join type, telemetry, update ring deferrals, WSUS and Group Policy, hardware readiness and safeguard holds.</description>
  </item>
  <item>
    <title>App protection policies not applying to Outlook mobile: a troubleshooting checklist</title>
    <link>https://www.oeltayeb.com/articles/app-protection-policy-not-applying-outlook-mobile.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/app-protection-policy-not-applying-outlook-mobile.html</guid>
    <category>Microsoft Intune</category>
    <description>Outlook on iOS or Android ignoring your Intune app protection policy? Check targeting, licensing, the signed-in account, broker apps, check-in timing, reports and Edge diagnostics.</description>
  </item>
  <item>
    <title>Apple ADE devices missing in Intune or stuck without an enrollment policy</title>
    <link>https://www.oeltayeb.com/articles/apple-ade-devices-not-syncing-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/apple-ade-devices-not-syncing-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Why Apple ADE devices don't appear in Intune or enroll without the right policy: device assignment, token sync limits and renewal, default policies, and why a reset is needed.</description>
  </item>
  <item>
    <title>Android Enterprise work profile enrollment failures: what to check</title>
    <link>https://www.oeltayeb.com/articles/android-work-profile-enrollment-failures.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/android-work-profile-enrollment-failures.html</guid>
    <category>Microsoft Intune</category>
    <description>A practical checklist for failed Android personally owned work profile enrollments: Managed Google Play, restrictions, licences, device requirements, existing profiles and logs.</description>
  </item>
  <item>
    <title>Moving co-management workloads from Configuration Manager to Intune without surprises</title>
    <link>https://www.oeltayeb.com/articles/co-management-workloads-switch-to-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/co-management-workloads-switch-to-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>A staged way to switch co-management workloads to Intune: what each slider really controls, pilot collections, the client logs to watch, rollback caveats and a sensible order.</description>
  </item>
  <item>
    <title>Automating Intune device reports with Microsoft Graph PowerShell</title>
    <link>https://www.oeltayeb.com/articles/export-intune-device-inventory-graph-powershell.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/export-intune-device-inventory-graph-powershell.html</guid>
    <category>Microsoft Intune</category>
    <description>Export your Intune device inventory to CSV with the Microsoft Graph PowerShell SDK, spot stale and noncompliant devices, and run it unattended with certificate-based app-only sign-in.</description>
  </item>
  <item>
    <title>Keeping Intune tidy: device cleanup rules and stale device hygiene</title>
    <link>https://www.oeltayeb.com/articles/intune-device-cleanup-rules.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-device-cleanup-rules.html</guid>
    <category>Microsoft Intune</category>
    <description>How Intune device cleanup rules work per platform, what they hide and what they leave behind, and how to pair them with a safe Entra ID stale-device routine that spares Autopilot.</description>
  </item>
  <item>
    <title>Windows enrollment error 0x80180018 and its neighbours: what to check, and where</title>
    <link>https://www.oeltayeb.com/articles/windows-enrollment-error-0x80180018-not-authorized.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-enrollment-error-0x80180018-not-authorized.html</guid>
    <category>Microsoft Intune</category>
    <description>Windows MDM enrollment fails with 0x80180018 or a nearby 0x8018 code. What Microsoft documents for each code, which tenant setting is behind it, and how to confirm the fix in the enrollment event log.</description>
  </item>
  <item>
    <title>Intune device not checking in: diagnosing a Windows device that stopped syncing</title>
    <link>https://www.oeltayeb.com/articles/intune-device-not-checking-in-sync-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-device-not-checking-in-sync-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>A Windows device shows a stale last check-in in Intune and policies stop arriving. How check-in works, what to inspect on the device (service, tasks, certificate, network) and when to re-enroll.</description>
  </item>
  <item>
    <title>Intune PowerShell scripts not running: execution context, 64-bit, signing and where to look</title>
    <link>https://www.oeltayeb.com/articles/intune-powershell-scripts-not-running.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-powershell-scripts-not-running.html</guid>
    <category>Microsoft Intune</category>
    <description>An Intune platform script reports Failed or never runs. How the Intune Management Extension executes scripts, what the three script settings change, how retries and re-runs work, and where to look.</description>
  </item>
  <item>
    <title>iOS/iPadOS apps not installing from Intune: VPP tokens, licences and installs stuck pending</title>
    <link>https://www.oeltayeb.com/articles/ios-apps-not-installing-vpp-tokens-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/ios-apps-not-installing-vpp-tokens-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Apple Business Manager apps assigned in Intune stay pending or fail on iPhones and iPads. How location (VPP) tokens and licences work, what the 0x87D13B error codes mean, and what to check in order.</description>
  </item>
  <item>
    <title>Packaging a Win32 app for Intune: .intunewin, install commands, detection and requirement rules</title>
    <link>https://www.oeltayeb.com/articles/package-win32-app-intunewin-content-prep-tool.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/package-win32-app-intunewin-content-prep-tool.html</guid>
    <category>Microsoft Intune</category>
    <description>How to wrap an installer with the Win32 Content Prep Tool, choose silent install and uninstall commands, set install behaviour, return codes, requirement and detection rules, and pilot the app.</description>
  </item>
  <item>
    <title>Windows Autopilot from scratch: register devices, build a user-driven profile and assign it</title>
    <link>https://www.oeltayeb.com/articles/windows-autopilot-setup-hardware-hash-deployment-profile.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-autopilot-setup-hardware-hash-deployment-profile.html</guid>
    <category>Microsoft Intune</category>
    <description>Set up Windows Autopilot end to end: tenant prerequisites, collecting and importing hardware hashes, group tags and dynamic groups, a user-driven Entra join profile, an Enrollment Status Page and the first test device.</description>
  </item>
  <item>
    <title>Windows Update for Business in Intune: update rings, expedited updates and reports</title>
    <link>https://www.oeltayeb.com/articles/windows-update-rings-expedite-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-update-rings-expedite-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Prerequisites, the update ring settings and their ranges, a pilot/broad ring design, expedite and driver update policies, the Intune and Windows Update for Business reports, and how to check a device locally.</description>
  </item>
  <item>
    <title>Settings catalog, templates, baselines or endpoint security? Choosing the right Intune policy type</title>
    <link>https://www.oeltayeb.com/articles/settings-catalog-vs-templates-vs-baselines.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/settings-catalog-vs-templates-vs-baselines.html</guid>
    <category>Microsoft Intune</category>
    <description>What each Intune policy type is for, how conflicts between them are resolved and reported, a recommended layering for a new tenant, and naming and assignment hygiene with filters.</description>
  </item>
  <item>
    <title>Training path: becoming a Microsoft Intune administrator (MD-102 study plan)</title>
    <link>https://www.oeltayeb.com/articles/training-path-md-102-intune-endpoint-administrator.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/training-path-md-102-intune-endpoint-administrator.html</guid>
    <category>Microsoft Intune</category>
    <description>A five-stage plan for Exam MD-102 and the Endpoint Administrator Associate certification: the current skills-measured domains, the Microsoft Learn paths to follow, lab exercises and exam-day tips.</description>
  </item>
  <item>
    <title>Noncompliant on the Defender "machine risk score" setting: the end-to-end checklist</title>
    <link>https://www.oeltayeb.com/articles/intune-noncompliant-machine-risk-score-defender-for-endpoint.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-noncompliant-machine-risk-score-defender-for-endpoint.html</guid>
    <category>Microsoft Intune</category>
    <description>Why a Windows device fails "Require the device to be at or under the machine risk score", and how to check the connector, onboarding, device identity and active alerts in the right order.</description>
  </item>
  <item>
    <title>Windows 11 24H2 won't onboard to Defender for Endpoint: the missing Sense client (KB5043950)</title>
    <link>https://www.oeltayeb.com/articles/windows-11-24h2-defender-for-endpoint-sense-client-missing-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-11-24h2-defender-for-endpoint-sense-client-missing-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Some Windows 11 24H2 devices ship without the Sense client, so Intune's EDR policy errors and the device never reaches Defender. How to detect it at scale with Remediations and add the capability.</description>
  </item>
  <item>
    <title>Intune health attestation is moving to Azure Attestation: prepare before compliance breaks</title>
    <link>https://www.oeltayeb.com/articles/intune-health-attestation-azure-attestation-migration-compliance.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-health-attestation-azure-attestation-migration-compliance.html</guid>
    <category>Microsoft Intune</category>
    <description>Intune will evaluate BitLocker, Secure Boot and code integrity compliance through Microsoft Azure Attestation. Which endpoints to allow, how to test from a device, and how to find affected policies.</description>
  </item>
  <item>
    <title>Domain trust failures after KB5124008: Machine Identity Isolation explained for Intune admins</title>
    <link>https://www.oeltayeb.com/articles/machine-identity-isolation-domain-trust-sign-in-failures-september-2026.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/machine-identity-isolation-domain-trust-sign-in-failures-september-2026.html</guid>
    <category>Microsoft Intune</category>
    <description>After the September 2026 Windows 11 updates some domain-joined devices lose their secure channel because Machine Identity Isolation is now honoured. How to find the policy, roll it back and verify.</description>
  </item>
  <item>
    <title>Hybrid join Autopilot deployments time out with 0x80004005: the 2026 known issue and the fix</title>
    <link>https://www.oeltayeb.com/articles/autopilot-hybrid-join-timeout-0x80004005-2026.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/autopilot-hybrid-join-timeout-0x80004005-2026.html</guid>
    <category>Microsoft Intune</category>
    <description>Microsoft Entra hybrid join Autopilot deployments can time out with 0x80004005 on older Windows 11 builds. How to confirm the known issue, which KBs fix it and how to get devices onto a fixed build.</description>
  </item>
  <item>
    <title>Pre-provisioning hybrid join fails when a policy needs a domain controller (0x800706FD)</title>
    <link>https://www.oeltayeb.com/articles/autopilot-pre-provisioning-hybrid-join-policy-conflict-domain-controller.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/autopilot-pre-provisioning-hybrid-join-policy-conflict-domain-controller.html</guid>
    <category>Microsoft Intune</category>
    <description>Autopilot pre-provisioning for hybrid join fails in the technician flow when a policy such as a User Rights setting needs a domain controller. How to read the 0x800706FD event and fix the scoping.</description>
  </item>
  <item>
    <title>Intune Connector for AD fails with SeLogonAsServicePrivilege when you bring your own gMSA</title>
    <link>https://www.oeltayeb.com/articles/intune-connector-active-directory-gmsa-selogonasservice-error.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-connector-active-directory-gmsa-selogonasservice-error.html</guid>
    <category>Microsoft Intune</category>
    <description>Configuring the Intune Connector for AD with your own gMSA can fail on the SeLogonAsServicePrivilege pre-check. The June 2026 known issue, the SkipByoMsaPrivilegeCheck fix and how to verify it.</description>
  </item>
  <item>
    <title>Windows Autopilot known issues in 2026: what's open, what's fixed and how to stay informed</title>
    <link>https://www.oeltayeb.com/articles/windows-autopilot-known-issues-2026-roundup.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-autopilot-known-issues-2026-roundup.html</guid>
    <category>Microsoft Intune</category>
    <description>A walkthrough of the Windows Autopilot known issues page as of October 2026: open and fixed items, deeper guidance on the January 2026 entries, and how to subscribe so new issues reach you first.</description>
  </item>
  <item>
    <title>Windows Autopilot device preparation: known issues and how to troubleshoot a failed run</title>
    <link>https://www.oeltayeb.com/articles/windows-autopilot-device-preparation-known-issues-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-autopilot-device-preparation-known-issues-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>What trips admins up in Autopilot device preparation, the known issues and their status as of October 2026, how to read the deployment status report, and the documented steps for a failed deployment.</description>
  </item>
  <item>
    <title>Rolling out the 2023 Secure Boot certificates with Intune before the last 2011 CA expires</title>
    <link>https://www.oeltayeb.com/articles/secure-boot-certificate-expiration-intune-rollout.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/secure-boot-certificate-expiration-intune-rollout.html</guid>
    <category>Microsoft Intune</category>
    <description>Which 2011 Secure Boot certificates expire and when, the Settings catalog Secure Boot settings, model-based filters for a staged rollout, and the Intune report and remediation that track progress.</description>
  </item>
  <item>
    <title>Secure Boot certificate update not applying: registry values, event IDs and the Intune report</title>
    <link>https://www.oeltayeb.com/articles/secure-boot-certificate-update-not-applying-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/secure-boot-certificate-update-not-applying-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>Read UEFICA2023Status, the AvailableUpdates bitmask and TPM-WMI events 1795 to 1808 to see where a Secure Boot certificate update is stuck, interpret the Intune report, and clear the common blockers.</description>
  </item>
  <item>
    <title>Rolling out Windows 11 26H2 with Intune: feature update policy, known issues, safeguard holds</title>
    <link>https://www.oeltayeb.com/articles/windows-11-26h2-rollout-with-intune-feature-update-policy.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-11-26h2-rollout-with-intune-feature-update-policy.html</guid>
    <category>Microsoft Intune</category>
    <description>How 26H2 installs as an enablement package, the Intune feature update policy and rollout options to deploy it, the known issues listed at launch, how safeguard holds show up, and how to verify a device.</description>
  </item>
  <item>
    <title>Current Intune known issues that aren't your fault: Company Portal, Store apps, compliance messages</title>
    <link>https://www.oeltayeb.com/articles/intune-known-issues-company-portal-apps-remediation-message-2026.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-known-issues-company-portal-apps-remediation-message-2026.html</guid>
    <category>Microsoft Intune</category>
    <description>Five items Microsoft currently lists as Active on the Intune known issues page, what each looks like, what to tell users, how to work around it, and how to track the page and escalate properly.</description>
  </item>
  <item>
    <title>Macs unexpectedly unenrolled from Intune: the MDM certificate renewal issue and how to recover</title>
    <link>https://www.oeltayeb.com/articles/macos-devices-unenrolled-mdm-certificate-renewal-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/macos-devices-unenrolled-mdm-certificate-renewal-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Why some Macs dropped out of Intune during MDM identity certificate renewal, Apple's fix in macOS 26.4, how to find and re-enroll affected devices, and how this differs from an expired Apple MDM push certificate.</description>
  </item>
  <item>
    <title>Is it me or is it Intune? Check service health, known issues and release notes first</title>
    <link>https://www.oeltayeb.com/articles/when-intune-is-the-problem-service-health-known-issues-checklist.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/when-intune-is-the-problem-service-health-known-issues-checklist.html</guid>
    <category>Microsoft Intune</category>
    <description>A 10-minute checklist to rule out a service incident, a documented known issue or a gradual service release before you troubleshoot your tenant, plus what to collect for a support case and how to subscribe.</description>
  </item>
  <item>
    <title>Intune deployments (preview): stage Win32 apps and policies across deployment rings</title>
    <link>https://www.oeltayeb.com/articles/intune-phased-deployments-preview-rings.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-phased-deployments-preview-rings.html</guid>
    <category>Microsoft Intune</category>
    <description>Intune's new Deployments experience (preview): staging Win32 and Enterprise App Catalog apps, settings catalog and endpoint security policies across rings, permissions, how rings advance, and a ring design.</description>
  </item>
  <item>
    <title>Windows Autopilot device association: TPM-backed tenant affinity before enrollment</title>
    <link>https://www.oeltayeb.com/articles/windows-autopilot-device-association-tpm-tenant-affinity.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-autopilot-device-association-tpm-tenant-affinity.html</guid>
    <category>Microsoft Intune</category>
    <description>What device association writes to UEFI, the Windows 11 and TPM 2.0 requirements, exporting the DeviceLink CSV and pre-associating in Intune, lifecycle and removal, and how it coexists with classic Autopilot.</description>
  </item>
  <item>
    <title>Windows Autopatch: approvals, deferrals, pausing and quick machine recovery updates</title>
    <link>https://www.oeltayeb.com/articles/windows-autopatch-approvals-pausing-recovery-updates-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-autopatch-approvals-pausing-recovery-updates-intune.html</guid>
    <category>Microsoft Intune</category>
    <description>Autopatch groups and quality update policies, the per-update-type automatic or manual approvals, deferrals and pausing rolling out in autumn 2026, quick machine recovery approvals, the reports, and migration tips.</description>
  </item>
  <item>
    <title>Enterprise App Catalog in Intune: deploying third-party apps and keeping them updated</title>
    <link>https://www.oeltayeb.com/articles/intune-enterprise-app-catalog-deploy-update-apps.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-enterprise-app-catalog-deploy-update-apps.html</guid>
    <category>Microsoft Intune</category>
    <description>Add a prepackaged Win32 app from the Enterprise App Catalog, understand the prefilled install and detection settings, choose between auto-update and guided supersedence, and troubleshoot failed installs.</description>
  </item>
  <item>
    <title>Microsoft Cloud PKI: issuing device certificates for Wi-Fi and VPN without NDES</title>
    <link>https://www.oeltayeb.com/articles/microsoft-cloud-pki-intune-certificates-wifi-vpn.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/microsoft-cloud-pki-intune-certificates-wifi-vpn.html</guid>
    <category>Microsoft Intune</category>
    <description>Build a two-tier Microsoft Cloud PKI hierarchy in Intune, deploy the trusted certificate and SCEP profiles, bind the certificate to Wi-Fi or VPN profiles, monitor and revoke, and fix the common SCEP errors.</description>
  </item>
  <item>
    <title>Endpoint Privilege Management in Intune: elevation settings, rules and user experience</title>
    <link>https://www.oeltayeb.com/articles/intune-endpoint-privilege-management-elevation-rules.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-endpoint-privilege-management-elevation-rules.html</guid>
    <category>Microsoft Intune</category>
    <description>Deploy Intune Endpoint Privilege Management: the elevation settings policy, elevation rules by hash or certificate, the user experience, the elevation reports, and how to troubleshoot rules that don't match.</description>
  </item>
  <item>
    <title>Remote Help in Intune: licensing, setup, helper roles, deployment and troubleshooting</title>
    <link>https://www.oeltayeb.com/articles/remote-help-intune-setup-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/remote-help-intune-setup-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>Set up Remote Help end to end: check licensing, enable the tenant settings, grant least-privilege helper roles, deploy the Windows app, handle Conditional Access, and fix sessions that won't connect.</description>
  </item>
  <item>
    <title>Custom compliance in Intune: writing the discovery script and JSON rules</title>
    <link>https://www.oeltayeb.com/articles/intune-custom-compliance-policy-json-script.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-custom-compliance-policy-json-script.html</guid>
    <category>Microsoft Intune</category>
    <description>Extend Intune compliance with your own checks: write a discovery script that returns compressed JSON, define rules in the JSON schema, upload both, and troubleshoot error codes 65007 to 65010.</description>
  </item>
  <item>
    <title>Intune RBAC and scope tags: delegate administration without Intune Administrator</title>
    <link>https://www.oeltayeb.com/articles/intune-rbac-scope-tags-delegated-administration.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-rbac-scope-tags-delegated-administration.html</guid>
    <category>Microsoft Intune</category>
    <description>How Intune roles, role assignments and scope tags fit together, three delegation designs that work, the pitfalls that leak visibility, and how to audit and test what an admin can really do.</description>
  </item>
  <item>
    <title>Windows 365 Cloud PC provisioning failed: finding the cause, fixing the ANC and retrying</title>
    <link>https://www.oeltayeb.com/articles/windows-365-cloud-pc-provisioning-failed-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-365-cloud-pc-provisioning-failed-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>A Cloud PC shows Provisioning failed in the Intune admin center. How provisioning works, what the Azure network connection health checks test, the documented failure reasons, and when to retry or reprovision.</description>
  </item>
  <item>
    <title>Windows kiosk and Shared PC with Intune: single-app, multi-app and shared devices</title>
    <link>https://www.oeltayeb.com/articles/windows-kiosk-shared-pc-intune-configuration.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-kiosk-shared-pc-intune-configuration.html</guid>
    <category>Microsoft Intune</category>
    <description>Configure single-app and multi-app kiosks with the Intune Kiosk template or Assigned Access XML, set up Shared PC mode, pair with Autopilot self-deploying mode, and fix kiosks that won't launch.</description>
  </item>
  <item>
    <title>Company Portal for Windows: Sync fails, device not enrolled or assigned to someone else</title>
    <link>https://www.oeltayeb.com/articles/company-portal-sync-errors-device-not-enrolled-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/company-portal-sync-errors-device-not-enrolled-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>What the Company Portal Sync button really does, why the app says a device isn't set up or belongs to another user, how the primary user drives it, and where the logs are.</description>
  </item>
  <item>
    <title>Wi-Fi or VPN profile not applying? Troubleshoot the SCEP/PKCS certificate chain in Intune</title>
    <link>https://www.oeltayeb.com/articles/intune-wifi-vpn-profile-not-applying-scep-pkcs-certificates.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/intune-wifi-vpn-profile-not-applying-scep-pkcs-certificates.html</guid>
    <category>Microsoft Intune</category>
    <description>Trace a stuck Wi-Fi or VPN profile back through the certificate chain: trusted root, SCEP/PKCS profile, Certificate Connector and NDES, using the logs and event IDs Microsoft documents.</description>
  </item>
  <item>
    <title>OneDrive Known Folder Move with Intune: silent sign-in, silent move and stuck folders</title>
    <link>https://www.oeltayeb.com/articles/onedrive-known-folder-move-intune-deployment-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/onedrive-known-folder-move-intune-deployment-troubleshooting.html</guid>
    <category>Microsoft Intune</category>
    <description>Deploy OneDrive Known Folder Move through the Intune settings catalog, roll it out at a safe pace, read the sync health dashboard, and fix the documented reasons a folder refuses to move.</description>
  </item>
  <item>
    <title>Android Enterprise dedicated devices: Managed Home Screen kiosks and shared device sign-in</title>
    <link>https://www.oeltayeb.com/articles/android-enterprise-dedicated-devices-managed-home-screen.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/android-enterprise-dedicated-devices-managed-home-screen.html</guid>
    <category>Microsoft Intune</category>
    <description>Build a locked-down Android kiosk with Intune: dedicated device enrollment tokens, multi-app kiosk mode with Managed Home Screen, Entra shared device mode sign-in, and fixes for missing apps.</description>
  </item>
  <item>
    <title>AADSTS53000 vs AADSTS53003: troubleshooting Conditional Access sign-in blocks</title>
    <link>https://www.oeltayeb.com/articles/aadsts53000-aadsts53003-conditional-access-blocks.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/aadsts53000-aadsts53003-conditional-access-blocks.html</guid>
    <category>Microsoft Entra ID</category>
    <description>What AADSTS53000, 53001 and 53003 actually mean, how to find the blocking policy in the sign-in logs, and how to fix compliance and browser device-identity gaps.</description>
  </item>
  <item>
    <title>Troubleshooting Microsoft Entra hybrid join with dsregcmd /status</title>
    <link>https://www.oeltayeb.com/articles/hybrid-join-troubleshooting-dsregcmd.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/hybrid-join-troubleshooting-dsregcmd.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Read dsregcmd /status for hybrid join failures, check the SCP and Entra Connect sync, use the User Device Registration log and clear devices stuck in Pending.</description>
  </item>
  <item>
    <title>Primary Refresh Token (PRT) explained: fixing SSO and repeated sign-in prompts</title>
    <link>https://www.oeltayeb.com/articles/primary-refresh-token-sso-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/primary-refresh-token-sso-troubleshooting.html</guid>
    <category>Microsoft Entra ID</category>
    <description>How the Primary Refresh Token powers single sign-on on Windows, how to check it with dsregcmd and the AAD event logs, and how to fix a missing or stale PRT.</description>
  </item>
  <item>
    <title>Test before you enforce: Conditional Access What If and report-only mode</title>
    <link>https://www.oeltayeb.com/articles/conditional-access-what-if-report-only.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/conditional-access-what-if-report-only.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Use report-only mode, the sign-in logs, the insights workbook and the What If tool to prove a Conditional Access policy behaves as expected before you turn it on.</description>
  </item>
  <item>
    <title>Temporary Access Pass: onboarding users to passwordless and Windows Hello for Business</title>
    <link>https://www.oeltayeb.com/articles/temporary-access-pass-passwordless-onboarding.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/temporary-access-pass-passwordless-onboarding.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Enable the Temporary Access Pass policy, issue passes in the portal or with Graph PowerShell, and use them to register passkeys, Authenticator and Windows Hello for Business.</description>
  </item>
  <item>
    <title>Dynamic device groups for Intune: membership rules that actually work</title>
    <link>https://www.oeltayeb.com/articles/dynamic-device-groups-intune-rules.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/dynamic-device-groups-intune-rules.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Working dynamic device rules for Autopilot, group tags, OS version, ownership and enrollment profiles, plus licensing, processing time, rule validation and when filters fit better.</description>
  </item>
  <item>
    <title>AADSTS50076, AADSTS50079 and AADSTS50158: fixing MFA and authentication-strength sign-in errors</title>
    <link>https://www.oeltayeb.com/articles/aadsts50076-aadsts50079-aadsts50158-mfa-errors.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/aadsts50076-aadsts50079-aadsts50158-mfa-errors.html</guid>
    <category>Microsoft Entra ID</category>
    <description>What the MFA-related AADSTS codes mean, how to read the Authentication details and Conditional Access tabs of a sign-in, and how to fix legacy clients, unregistered users and authentication strength mismatches.</description>
  </item>
  <item>
    <title>Entra Connect sync errors: duplicates, InvalidSoftMatch and objects that never sync</title>
    <link>https://www.oeltayeb.com/articles/entra-connect-sync-errors-duplicate-attribute-invalidsoftmatch.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-connect-sync-errors-duplicate-attribute-invalidsoftmatch.html</guid>
    <category>Microsoft Entra ID</category>
    <description>How to read Entra Connect export errors such as AttributeValueMustBeUnique, InvalidSoftMatch and LargeObject, fix matching problems with ms-DS-ConsistencyGuid, and find objects that filtering keeps out of Entra ID.</description>
  </item>
  <item>
    <title>A Conditional Access baseline: the first policies every tenant should deploy</title>
    <link>https://www.oeltayeb.com/articles/conditional-access-baseline-policies-every-tenant.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/conditional-access-baseline-policies-every-tenant.html</guid>
    <category>Microsoft Entra ID</category>
    <description>The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.</description>
  </item>
  <item>
    <title>Deploying Windows Hello for Business with cloud Kerberos trust using Intune</title>
    <link>https://www.oeltayeb.com/articles/windows-hello-for-business-cloud-kerberos-trust-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/windows-hello-for-business-cloud-kerberos-trust-intune.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Why cloud Kerberos trust is the recommended Windows Hello for Business model for hybrid tenants, how to create the Entra Kerberos server object, configure the Intune policy, and verify with dsregcmd and klist.</description>
  </item>
  <item>
    <title>Training path: Microsoft Entra ID for administrators (SC-300 study plan)</title>
    <link>https://www.oeltayeb.com/articles/training-path-sc-300-identity-access-administrator.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/training-path-sc-300-identity-access-administrator.html</guid>
    <category>Microsoft Entra ID</category>
    <description>A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.</description>
  </item>
  <item>
    <title>Conditional Access now evaluates OIDC-only sign-ins: the 2026 baseline scopes change</title>
    <link>https://www.oeltayeb.com/articles/conditional-access-oidc-scope-enforcement-change-2026.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/conditional-access-oidc-scope-enforcement-change-2026.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Sign-ins requesting only openid, profile, email or User.Read are now subject to All resources policies with exclusions: who is affected, how to find the apps in sign-in logs, how to fix them, and the timeline.</description>
  </item>
  <item>
    <title>Mandatory MFA for Azure and admin portals: fix scripts, service accounts and break-glass accounts</title>
    <link>https://www.oeltayeb.com/articles/mandatory-mfa-admin-portals-automation-service-accounts.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/mandatory-mfa-admin-portals-automation-service-accounts.html</guid>
    <category>Microsoft Entra ID</category>
    <description>What mandatory MFA enforcement covers, the failures it causes for user-based automation and admin sign-ins, how to verify who is ready, moving scripts to workload identities, and MFA-capable break-glass accounts.</description>
  </item>
  <item>
    <title>Dual state, Pending and duplicate device objects in Microsoft Entra ID: a clean-up guide</title>
    <link>https://www.oeltayeb.com/articles/entra-device-registration-dual-state-pending-devices-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-device-registration-dual-state-pending-devices-troubleshooting.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Why a hybrid joined PC also shows as Entra registered, what Pending really means, and how to clean up duplicates with dsregcmd, BlockAADWorkplaceJoin and Graph PowerShell.</description>
  </item>
  <item>
    <title>Rolling out passkeys in Microsoft Authenticator: policy, registration and the errors users hit</title>
    <link>https://www.oeltayeb.com/articles/passkeys-microsoft-authenticator-rollout-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/passkeys-microsoft-authenticator-rollout-troubleshooting.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Configure the Passkey (FIDO2) policy and a passkey profile for Authenticator, pick the right registration flow, roll out in rings and fix the registration and sign-in failures users report.</description>
  </item>
  <item>
    <title>Privileged Identity Management: just-in-time Microsoft Entra roles done properly</title>
    <link>https://www.oeltayeb.com/articles/entra-privileged-identity-management-just-in-time-roles.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-privileged-identity-management-just-in-time-roles.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Set up PIM for Microsoft Entra roles: role settings, eligible assignments, activation and approvals, PIM for Groups, alerts, access reviews, and the activation problems you'll hit.</description>
  </item>
  <item>
    <title>Access reviews and entitlement management basics: a starter plan for Entra ID Governance</title>
    <link>https://www.oeltayeb.com/articles/entra-access-reviews-entitlement-management-basics.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-access-reviews-entitlement-management-basics.html</guid>
    <category>Microsoft Entra ID</category>
    <description>How access reviews and entitlement management fit together in Microsoft Entra ID Governance: licensing, creating reviews, catalogs and access packages, and a starter plan you can run this quarter.</description>
  </item>
  <item>
    <title>Microsoft Entra ID Protection: risk policies, self-remediation and false positives</title>
    <link>https://www.oeltayeb.com/articles/entra-id-protection-risk-policies-false-positives.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-id-protection-risk-policies-false-positives.html</guid>
    <category>Microsoft Entra ID</category>
    <description>User risk vs sign-in risk, the detections behind them, risk-based Conditional Access that lets users fix their own risk, and how to investigate, dismiss or confirm the false positives.</description>
  </item>
  <item>
    <title>Self-service password reset and password writeback: fixing the usual failures</title>
    <link>https://www.oeltayeb.com/articles/self-service-password-reset-password-writeback-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/self-service-password-reset-password-writeback-troubleshooting.html</guid>
    <category>Microsoft Entra ID</category>
    <description>SSPR prerequisites, password writeback through Connect Sync or Cloud Sync, the documented SSPR_00xx portal errors, the Windows sign-in screen Reset password link, and the event IDs behind writeback failures.</description>
  </item>
  <item>
    <title>Reading Microsoft Entra sign-in logs like an engineer</title>
    <link>https://www.oeltayeb.com/articles/entra-sign-in-logs-reading-like-an-engineer.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-sign-in-logs-reading-like-an-engineer.html</guid>
    <category>Microsoft Entra ID</category>
    <description>The four sign-in log types, the fields that matter, how to trace one failed sign-in end to end, KQL against the SigninLogs table, export and retention by licence, and the misreads that waste hours.</description>
  </item>
  <item>
    <title>Microsoft Entra Cloud Sync vs Connect Sync: choosing the right tool and migrating safely</title>
    <link>https://www.oeltayeb.com/articles/entra-cloud-sync-vs-connect-sync-choosing-migrating.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/entra-cloud-sync-vs-connect-sync-choosing-migrating.html</guid>
    <category>Microsoft Entra ID</category>
    <description>Architecture differences, the Learn feature comparison, when each sync tool fits, and the documented pilot-OU migration from Connect Sync to Cloud Sync with cloudNoFlow and JoinNoFlow rules.</description>
  </item>
  <item>
    <title>Onboarding Windows devices to Defender for Endpoint with Intune (and proving it worked)</title>
    <link>https://www.oeltayeb.com/articles/onboard-defender-for-endpoint-with-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/onboard-defender-for-endpoint-with-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>Connect Intune to Microsoft Defender for Endpoint, onboard Windows devices with an EDR policy, then prove it worked on the device, in the Defender portal and with a detection test.</description>
  </item>
  <item>
    <title>Rolling out ASR rules safely: audit mode, exclusions and advanced hunting</title>
    <link>https://www.oeltayeb.com/articles/attack-surface-reduction-rules-audit-mode.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/attack-surface-reduction-rules-audit-mode.html</guid>
    <category>Microsoft Defender</category>
    <description>A phased plan for attack surface reduction rules in Intune: standard rules straight to Block, the rest in Audit, measured with advanced hunting, narrow exclusions, then enforce.</description>
  </item>
  <item>
    <title>Defender Antivirus settings not applying from Intune: a troubleshooting checklist</title>
    <link>https://www.oeltayeb.com/articles/defender-antivirus-policy-not-applying.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-antivirus-policy-not-applying.html</guid>
    <category>Microsoft Defender</category>
    <description>Intune says the antivirus policy succeeded but the device disagrees. Check the management channel, conflicts, passive mode, tamper protection and exclusion behaviour to find out why.</description>
  </item>
  <item>
    <title>Device shows "Inactive" or "No sensor data" in Microsoft Defender: how to troubleshoot</title>
    <link>https://www.oeltayeb.com/articles/defender-device-inactive-no-sensor-data.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-device-inactive-no-sensor-data.html</guid>
    <category>Microsoft Defender</category>
    <description>What Inactive, Impaired communications and No sensor data mean in the Defender device inventory, and how to check the sensor, onboarding state, proxy and duplicate device records.</description>
  </item>
  <item>
    <title>Handling false-positive quarantined email in Defender for Office 365 the right way</title>
    <link>https://www.oeltayeb.com/articles/release-quarantined-email-defender-office-365.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/release-quarantined-email-defender-office-365.html</guid>
    <category>Microsoft Defender</category>
    <description>Find the message, read why it was quarantined, release it, and report it through Submissions so a scoped, expiring allow entry replaces risky mail flow rule bypasses.</description>
  </item>
  <item>
    <title>Defender for Endpoint onboarding failures: SENSE event IDs, script errors and what they mean</title>
    <link>https://www.oeltayeb.com/articles/defender-for-endpoint-onboarding-errors-sense-event-ids.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-for-endpoint-onboarding-errors-sense-event-ids.html</guid>
    <category>Microsoft Defender</category>
    <description>A field guide to Defender for Endpoint onboarding failures: onboarding script error codes, SENSE Operational event IDs, Intune error codes, and the registry and service checks that show where it broke.</description>
  </item>
  <item>
    <title>Managing Defender settings on devices not enrolled in Intune: security settings management explained</title>
    <link>https://www.oeltayeb.com/articles/defender-security-settings-management-non-intune-devices.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-security-settings-management-non-intune-devices.html</guid>
    <category>Microsoft Defender</category>
    <description>How Defender for Endpoint security settings management pushes Intune endpoint security policies to devices not enrolled in Intune: prerequisites, enforcement scope, synthetic registration and pitfalls.</description>
  </item>
  <item>
    <title>Advanced hunting for Intune admins: KQL queries that answer everyday device questions</title>
    <link>https://www.oeltayeb.com/articles/advanced-hunting-kql-queries-for-intune-admins.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/advanced-hunting-kql-queries-for-intune-admins.html</guid>
    <category>Microsoft Defender</category>
    <description>Eight short KQL queries for the Defender portal using documented tables: OS builds, sensor health, app versions, CVE exposure, antivirus posture, who ran a tool, ASR audit hits and network destinations.</description>
  </item>
  <item>
    <title>Defender for Office 365 presets: Standard vs Strict, and why custom policies seem ignored</title>
    <link>https://www.oeltayeb.com/articles/preset-security-policies-standard-strict-defender-office-365.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/preset-security-policies-standard-strict-defender-office-365.html</guid>
    <category>Microsoft Defender</category>
    <description>What Built-in protection, Standard and Strict presets enforce, how they outrank custom threat policies, what you still have to configure for impersonation protection, and how to verify which policy handled a message.</description>
  </item>
  <item>
    <title>Training path: SC-200 Security Operations Analyst study plan (Defender XDR and Sentinel)</title>
    <link>https://www.oeltayeb.com/articles/training-path-sc-200-security-operations-analyst.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/training-path-sc-200-security-operations-analyst.html</guid>
    <category>Microsoft Defender</category>
    <description>A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.</description>
  </item>
  <item>
    <title>Security settings management enrollment errors: decoding SenseCM EnrollmentStatus codes</title>
    <link>https://www.oeltayeb.com/articles/defender-security-settings-management-sensecm-enrollment-errors.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-security-settings-management-sensecm-enrollment-errors.html</guid>
    <category>Microsoft Defender</category>
    <description>A device is onboarded to Defender but never shows up as MDE-managed in Intune. Read HKLM\SOFTWARE\Microsoft\SenseCM\EnrollmentStatus, map the code to its cause and fix it.</description>
  </item>
  <item>
    <title>Moving Defender for Endpoint to streamlined connectivity: URLs, proxies and validation</title>
    <link>https://www.oeltayeb.com/articles/defender-for-endpoint-streamlined-connectivity-migration-proxy.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-for-endpoint-streamlined-connectivity-migration-proxy.html</guid>
    <category>Microsoft Defender</category>
    <description>What *.endpoint.security.microsoft.com replaces and what it doesn't, the sensor prerequisites, how to migrate onboarded devices, EDR and antivirus proxy settings, and how to prove it worked.</description>
  </item>
  <item>
    <title>Defender Antivirus platform and engine updates: channels, gradual rollout and rollback</title>
    <link>https://www.oeltayeb.com/articles/defender-antivirus-platform-engine-updates-gradual-rollout-rollback.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-antivirus-platform-engine-updates-gradual-rollout-rollback.html</guid>
    <category>Microsoft Defender</category>
    <description>What the monthly KB4052623 platform and engine updates are, how to assign Intune update channels in rings, how to read versions with Get-MpComputerStatus, and how to roll back with MpCmdRun.</description>
  </item>
  <item>
    <title>Defender for Endpoint AIR: device groups, automation levels and undoing remediation</title>
    <link>https://www.oeltayeb.com/articles/defender-xdr-automated-investigation-remediation-levels-device-groups.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-xdr-automated-investigation-remediation-levels-device-groups.html</guid>
    <category>Microsoft Defender</category>
    <description>How automated investigation and response decides what to remediate, how device groups and automation levels control it, and how to approve, reject or undo an action in the Action center.</description>
  </item>
  <item>
    <title>Defender Vulnerability Management: from security recommendation to Intune security task</title>
    <link>https://www.oeltayeb.com/articles/defender-vulnerability-management-remediate-with-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-vulnerability-management-remediate-with-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>How exposure score, recommendations, software inventory and weaknesses fit together, and how a Request remediation in the Defender portal becomes a security task an Intune admin can close.</description>
  </item>
  <item>
    <title>Controlling USB and removable storage with Defender device control and Intune</title>
    <link>https://www.oeltayeb.com/articles/defender-device-control-usb-removable-storage-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-device-control-usb-removable-storage-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>Device control concepts (groups, rules, entries, access masks), the Intune Device Control profile with reusable settings, audit before block, printers, hunting queries and fixes when a USB stick stays writable.</description>
  </item>
  <item>
    <title>Tamper protection and Intune: why a Defender setting won't change, and how to fix it</title>
    <link>https://www.oeltayeb.com/articles/defender-tamper-protection-troubleshooting-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-tamper-protection-troubleshooting-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>What tamper protection locks, the four places it can be managed and their precedence, how to see which one controls a device, and how to fix settings that won't apply or exclusions that aren't protected.</description>
  </item>
  <item>
    <title>Safe Links and Safe Attachments: troubleshooting blocked links, missing rewrites and delays</title>
    <link>https://www.oeltayeb.com/articles/safe-links-safe-attachments-blocked-link-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/safe-links-safe-attachments-blocked-link-troubleshooting.html</guid>
    <category>Microsoft Defender</category>
    <description>How Safe Links rewriting and time-of-click checks work, what the Safe Attachments actions do, how to find out why a click was blocked, and how to allow a legitimate URL without weakening protection.</description>
  </item>
  <item>
    <title>Onboarding macOS to Defender for Endpoint with Intune: profiles, app and onboarding package</title>
    <link>https://www.oeltayeb.com/articles/defender-for-endpoint-macos-onboarding-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/defender-for-endpoint-macos-onboarding-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>The Intune deployment for Defender for Endpoint on Mac in the documented order: system extensions, Full Disk Access, network filter, background services, the app, the onboarding package, mdatp checks and fixes.</description>
  </item>
  <item>
    <title>Web content filtering in Defender for Endpoint: network protection, categories and indicators</title>
    <link>https://www.oeltayeb.com/articles/web-content-filtering-network-protection-defender-intune.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/web-content-filtering-network-protection-defender-intune.html</guid>
    <category>Microsoft Defender</category>
    <description>Enable network protection from Intune, turn on web content filtering, build category policies scoped to device groups, add allow indicators, and read blocks in reports, Event Viewer and advanced hunting.</description>
  </item>
  <item>
    <title>Email never arrived? Using message trace in Exchange Online to find out why</title>
    <link>https://www.oeltayeb.com/articles/exchange-online-message-trace-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-online-message-trace-troubleshooting.html</guid>
    <category>Exchange Online</category>
    <description>Run a message trace in the Exchange admin center or with Get-MessageTraceV2, read the delivery status and events, and pull older data from downloadable reports.</description>
  </item>
  <item>
    <title>SPF, DKIM and DMARC for your Microsoft 365 custom domain: a practical setup guide</title>
    <link>https://www.oeltayeb.com/articles/spf-dkim-dmarc-microsoft-365-custom-domain.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/spf-dkim-dmarc-microsoft-365-custom-domain.html</guid>
    <category>Exchange Online</category>
    <description>Publish one correct SPF record, turn on DKIM signing in the Defender portal, then move DMARC from p=none to p=reject without blocking your own legitimate mail.</description>
  </item>
  <item>
    <title>NDR 550 5.7.520: fixing “Your organization does not allow external forwarding”</title>
    <link>https://www.oeltayeb.com/articles/ndr-550-5-7-520-external-forwarding-blocked.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/ndr-550-5-7-520-external-forwarding-blocked.html</guid>
    <category>Exchange Online</category>
    <description>Why Exchange Online blocks automatic forwarding to external addresses with 5.7.520, and how to allow it only for the mailboxes that need it instead of for everyone.</description>
  </item>
  <item>
    <title>Shared mailbox automapping in Outlook: why it appears (or doesn't) and how to control it</title>
    <link>https://www.oeltayeb.com/articles/shared-mailbox-automapping-outlook.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/shared-mailbox-automapping-outlook.html</guid>
    <category>Exchange Online</category>
    <description>How automapping really works, why group-based Full Access never automaps, how to switch it off per user, and how to keep sent items in the shared mailbox.</description>
  </item>
  <item>
    <title>Enabling and troubleshooting auto-expanding archiving in Exchange Online</title>
    <link>https://www.oeltayeb.com/articles/auto-expanding-archiving-exchange-online.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/auto-expanding-archiving-exchange-online.html</guid>
    <category>Exchange Online</category>
    <description>Check licensing and the one-way switch, enable auto-expanding archiving org-wide or per user, make sure items actually move, and confirm extra storage was provisioned.</description>
  </item>
  <item>
    <title>NDR 550 5.4.1 “Recipient address rejected: Access denied”: Directory-Based Edge Blocking</title>
    <link>https://www.oeltayeb.com/articles/ndr-550-5-4-1-recipient-address-rejected-access-denied.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/ndr-550-5-4-1-recipient-address-rejected-access-denied.html</guid>
    <category>Exchange Online</category>
    <description>Why Exchange Online rejects mail with 550 5.4.1 at the perimeter, how Directory-Based Edge Blocking and the accepted domain type cause it, and how to fix each common cause.</description>
  </item>
  <item>
    <title>Printers and apps can't send via Microsoft 365: SMTP AUTH, relay connectors and 5.7.57</title>
    <link>https://www.oeltayeb.com/articles/smtp-auth-relay-printers-apps-error-5-7-57.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/smtp-auth-relay-printers-apps-error-5-7-57.html</guid>
    <category>Exchange Online</category>
    <description>What error 5.7.57 means, how SMTP AUTH client submission, SMTP relay and Direct Send differ, how to fix each cause, and where Basic authentication for SMTP AUTH stands.</description>
  </item>
  <item>
    <title>Exchange Online PowerShell V3: connect, automate with certificates, run everyday reports</title>
    <link>https://www.oeltayeb.com/articles/exchange-online-powershell-v3-connect-automate-reports.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-online-powershell-v3-connect-automate-reports.html</guid>
    <category>Exchange Online</category>
    <description>Install the ExchangeOnlineManagement module, connect interactively or with app-only certificate authentication, and run five quick reports with the fast Get-EXO cmdlets.</description>
  </item>
  <item>
    <title>Mail flow rules that don't backfire: external sender tagging, priorities and exceptions</title>
    <link>https://www.oeltayeb.com/articles/mail-flow-rules-best-practices-external-tag-exceptions.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/mail-flow-rules-best-practices-external-tag-exceptions.html</guid>
    <category>Exchange Online</category>
    <description>How Exchange Online evaluates mail flow rules, why the native External tag beats a subject-prefix rule, and how to test, order and audit rules without punching holes in EOP.</description>
  </item>
  <item>
    <title>Training path: MS-102 Microsoft 365 Administrator study plan with Exchange Online depth</title>
    <link>https://www.oeltayeb.com/articles/training-path-ms-102-microsoft-365-administrator-exchange.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/training-path-ms-102-microsoft-365-administrator-exchange.html</guid>
    <category>Exchange Online</category>
    <description>A six-stage MS-102 study plan built on the official Microsoft Learn paths, with extra Exchange Online practice, lab ideas and what the November 2026 retirement of the exam means for you.</description>
  </item>
  <item>
    <title>EWS switch-off in Exchange Online: EwsEnabled, the app allow list and finding EWS usage</title>
    <link>https://www.oeltayeb.com/articles/exchange-online-ews-retirement-ewsenabled-allowlist-october-2026.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-online-ews-retirement-ewsenabled-allowlist-october-2026.html</guid>
    <category>Exchange Online</category>
    <description>Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.</description>
  </item>
  <item>
    <title>“Mailbox full” in Exchange Online: quotas, Recoverable Items and the 554 5.2.2 NDR</title>
    <link>https://www.oeltayeb.com/articles/exchange-online-mailbox-full-quota-recoverable-items-ndr-5-2-2.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-online-mailbox-full-quota-recoverable-items-ndr-5-2-2.html</guid>
    <category>Exchange Online</category>
    <description>Why senders get 554 5.2.2 mailbox full, how to measure a mailbox and its hidden Recoverable Items folder, and the fix for each cause: user data, holds, calendar logging or the wrong licence.</description>
  </item>
  <item>
    <title>Hybrid free/busy not working: OAuth, the dedicated hybrid app and Test-OAuthConnectivity</title>
    <link>https://www.oeltayeb.com/articles/exchange-hybrid-free-busy-calendar-sharing-not-working.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-hybrid-free-busy-calendar-sharing-not-working.html</guid>
    <category>Exchange Online</category>
    <description>A methodical way to troubleshoot hybrid free/busy and calendar sharing: direction, Autodiscover, the OAuth trust and dedicated hybrid app, connectors and relationships, with cmdlets for each hop.</description>
  </item>
  <item>
    <title>Investigating a compromised Exchange Online mailbox: rules, forwarding, sign-ins and audit</title>
    <link>https://www.oeltayeb.com/articles/investigate-compromised-mailbox-exchange-online-inbox-rules-audit.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/investigate-compromised-mailbox-exchange-online-inbox-rules-audit.html</guid>
    <category>Exchange Online</category>
    <description>Microsoft's response order for a compromised mailbox, cmdlets that find malicious inbox rules and forwarding across every mailbox, what to read in sign-in and audit logs, and how to harden afterwards.</description>
  </item>
  <item>
    <title>Retention policies, labels, MRM and litigation hold in Exchange Online: which one does what</title>
    <link>https://www.oeltayeb.com/articles/retention-policies-litigation-hold-exchange-online-purview.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/retention-policies-litigation-hold-exchange-online-purview.html</guid>
    <category>Exchange Online</category>
    <description>Purview retention policies vs retention labels vs Exchange MRM tags vs litigation hold: what each does, what wins in a conflict, licensing, how to set them up and how to prove a mailbox is really on hold.</description>
  </item>
  <item>
    <title>Hybrid mailbox migration batches: reading statuses, fixing common errors and completing the move</title>
    <link>https://www.oeltayeb.com/articles/exchange-hybrid-mailbox-migration-batches-errors.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/exchange-hybrid-mailbox-migration-batches-errors.html</guid>
    <category>Exchange Online</category>
    <description>How a remote move batch works, what Syncing, Synced and Completing really mean, the documented errors (SMTP proxy, MRS Proxy 401, skipped items) and how to finish the cutover cleanly.</description>
  </item>
  <item>
    <title>Outlook can't connect or set up the account: Autodiscover troubleshooting for Exchange Online</title>
    <link>https://www.oeltayeb.com/articles/outlook-autodiscover-connectivity-exchange-online-troubleshooting.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/outlook-autodiscover-connectivity-exchange-online-troubleshooting.html</guid>
    <category>Exchange Online</category>
    <description>How classic Outlook finds Exchange Online, how to read Test E-mail AutoConfiguration and the Remote Connectivity Analyzer, and the usual culprits: DNS, stale on-premises Autodiscover, old clients and broken profiles.</description>
  </item>
  <item>
    <title>Distribution groups vs Microsoft 365 Groups vs shared mailboxes: which one to use and how to convert</title>
    <link>https://www.oeltayeb.com/articles/distribution-groups-vs-microsoft-365-groups-vs-shared-mailboxes.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/distribution-groups-vs-microsoft-365-groups-vs-shared-mailboxes.html</guid>
    <category>Exchange Online</category>
    <description>A capability-by-capability comparison of distribution groups, dynamic groups, Microsoft 365 Groups and shared mailboxes, when to choose each, how to upgrade a DL and the PowerShell to answer the usual questions.</description>
  </item>
  <item>
    <title>Legitimate email landing in Junk: how EOP decides and the right way to fix it</title>
    <link>https://www.oeltayeb.com/articles/legitimate-email-going-to-junk-tuning-anti-spam-exchange-online.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/legitimate-email-going-to-junk-tuning-anti-spam-exchange-online.html</guid>
    <category>Exchange Online</category>
    <description>Read the X-Forefront-Antispam-Report header (CAT, SFV, BCL, compauth) to see why a good message was junked, then fix it the supported way: submissions, Tenant Allow/Block List, sender authentication, not bypass rules.</description>
  </item>
  <item>
    <title>Room and equipment mailboxes in Exchange Online: creation, booking policies and Room Finder</title>
    <link>https://www.oeltayeb.com/articles/room-resource-mailboxes-booking-policies-exchange-online.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/room-resource-mailboxes-booking-policies-exchange-online.html</guid>
    <category>Exchange Online</category>
    <description>Create room and equipment mailboxes, tune Set-CalendarProcessing (auto-accept, conflicts, booking window, delegates), build room lists and Set-Place metadata for Room Finder, and fix the usual booking complaints.</description>
  </item>
  <item>
    <title>The Microsoft MVP Award explained: contributions, nominations and keeping your record</title>
    <link>https://www.oeltayeb.com/articles/microsoft-mvp-award-contributions-explained.html</link>
    <guid isPermaLink="true">https://www.oeltayeb.com/articles/microsoft-mvp-award-contributions-explained.html</guid>
    <category>Community &amp; career</category>
    <description>What the Microsoft MVP Award recognises, how nominations and reviews work, which contributions count (and which don't), and a simple log template to track your community work.</description>
  </item>
</channel>
</rss>
