Get-IntuneStaleDevices.ps1
Reports Intune managed devices that have not synced for a given number of days and can optionally retire or delete them.
Hi, I'm Omer Eltayeb — an independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert. I share what I learn with the Microsoft technical community: step-by-step guides, open-source scripts, downloadable toolkits and free training — every one written so you can go from the error message to the root cause to a result you can verify.
I share practical Microsoft Intune, Entra ID, Defender and Microsoft 365 knowledge through technical articles, open-source scripts, downloadable toolkits, community training and volunteer leadership — and I keep a public, evidence-based record of it.
Troubleshooting guides, how-tos and deep dives for Intune, Entra ID, Defender and Exchange Online — free, each with verification steps.
Open 28 Open-source PowerShell scriptsDocumented, read-only-by-default scripts for Microsoft 365 admins, published on GitHub under the MIT licence.
Open 37 Downloadable toolkitsChecklists, log references and decision trees for recurring troubleshooting scenarios.
Open 4 Training pathsFree stage-by-stage study plans for MD-102, SC-300, SC-200 and MS-102.
Open Intune · AZ-900 · AZ-104 · MS-102 Community trainingCourses and lectures for SIPAQ and Microsoft Community Sudan.
Open IEEE Sudan co-lead · SIPAQ trainer Community leadershipVolunteer co-lead of the IEEE Sudan Subsection and Microsoft trainer for Sudanese ICT communities in Qatar and Sudan.
Open MIEE 2024–25 · MIEE 2025–26 · Elevate 2026–27 Microsoft educator recognitionThree consecutive terms of Microsoft educator recognition.
Open 6.5K+ followers LinkedInMicrosoft 365, Intune and security posts for a growing audience across Africa and the Arab region.
OpenProfessional client and employer work is listed separately under Experience — it is not counted as community contribution.
Issues Microsoft has documented in 2026 for Intune, Autopilot, Windows 11 and the services around them, written up with the symptoms, the confirmation steps and the fix.
Every device problem touches identity, security or mail at some point. Pick a technology to see all of its guides.
Windows Autopilot, app deployment, compliance, BitLocker, Windows LAPS, updates, and Apple and Android enrollment — the heart of this blog.
Conditional Access, device identity, hybrid join, PRT and passwordless — the identity layer every Intune fix depends on.
21 articlesExploreDefender for Endpoint onboarding, antivirus policy, attack surface reduction and email threat protection.
20 articlesExploreMail flow, message trace, SPF/DKIM/DMARC, shared mailboxes, forwarding and archiving.
20 articlesExploreRelated guides grouped into reading paths — from first setup to the errors you'll meet along the way.
Least privilege with PIM, access reviews that people actually complete, risk policies without the false positives, SSPR that works — and how to read the sign-in logs when it doesn't.
Start the series 6 partsThe recipient and retention decisions every Microsoft 365 admin makes — groups vs shared mailboxes, rooms, archives, holds — plus the Outlook connectivity issues behind most mailbox tickets.
Start the series 5 partsSet Autopilot up from nothing, then work through the errors that stop a deployment: the Enrollment Status Page, redeployments and enrollment blocks.
Start the series 5 partsDeploy a safe baseline, test it in report-only mode, then decode the sign-in errors users hit when a policy blocks them.
Start the series28 documented, read-only-by-default scripts for Intune, Entra ID, Defender, Exchange Online, Purview and Teams — built on Microsoft Graph and Exchange Online PowerShell V3, published on GitHub under the MIT licence.
Get-IntuneStaleDevices.ps1Reports Intune managed devices that have not synced for a given number of days and can optionally retire or delete them.
Get-AutopilotDeviceReport.ps1Windows Autopilot registration health report: profile assignment status, enrollment state and last contact per device.
Export-EntraConditionalAccessPolicies.ps1Backs up every Conditional Access policy to JSON and builds a human-readable CSV summary.
Get-EXOExternalForwardingReport.ps1Finds mail leaving the tenant through mailbox forwarding or inbox rules, and optionally removes it.
Get-IntunePolicyAssignments.ps1Builds a "who gets what" assignment matrix for Intune policies and (optionally) apps.
Get-EntraMFARegistrationReport.ps1Reports the MFA, passwordless and SSPR registration posture of users in Microsoft Entra ID.
A hand-picked mix across Intune, Entra ID, Defender and Exchange Online.
Why a Windows device fails "Require the device to be at or under the machine risk score", and how to check the connector, onboarding, device identity and active alerts in the right order.
Read the guideFind the app or policy holding up the Enrollment Status Page, collect the right logs from OOBE, and fix the profile settings behind most Autopilot ESP timeouts.
The core Conditional Access policies to deploy first, how they map to Microsoft's templates and Microsoft-managed policies, and how to roll them out in report-only mode without locking anyone out.
A device is onboarded to Defender but never shows up as MDE-managed in Intune. Read HKLM\SOFTWARE\Microsoft\SenseCM\EnrollmentStatus, map the code to its cause and fix it.
Exchange Web Services is being disabled in Exchange Online from October 2026. What changes, how EwsEnabled and EwsAllowedAppIDs work, how to find what still uses EWS and how to buy time safely.
As a Microsoft Certified Trainer I've coached IT teams and community groups through these certifications. Each path maps the official exam objectives to a stage-by-stage plan with hands-on labs.
A five-stage plan for Exam MD-102 and the Endpoint Administrator Associate certification: the current skills-measured domains, the Microsoft Learn paths to follow, lab exercises and exam-day tips.
A six-stage study plan for exam SC-300, mapped to the official Microsoft Learn learning paths, with hands-on labs for Conditional Access, authentication methods, PIM, access reviews, apps and Entra Connect.
A stage-by-stage study plan for exam SC-200 (Security Operations Analyst Associate): the current skills-measured domains, the Microsoft Learn paths to follow, hands-on labs and exam-day tips.
A six-stage MS-102 study plan built on the official Microsoft Learn paths, with extra Exchange Online practice, lab ideas and what the November 2026 retirement of the exam means for you.
I'm an independent Microsoft Intune consultant based in Cairo, Egypt, and a former Microsoft Cloud Solutions Architect. Since 2018 I've worked in security operations, consulting and cloud architecture across the Middle East and EMEA — and every one of those roles kept leading me back to the same place: the endpoint, and the identity, security and mail services around it.
Today I work independently with organisations that run Microsoft Intune — designing rollouts, training IT teams and getting them past the problems that stop devices — and the people using them — from getting work done: Windows Autopilot deployments that stall at the Enrollment Status Page, Win32 apps that install but never report success, compliance policies that lock the wrong people out, and Conditional Access rules that block the wrong sign-ins. Every one of those problems has a root cause, and finding it quickly is the part of the job I enjoy most.
Before that I spent two years at Microsoft as a Cloud Solutions Architect for enterprise customers across EMEA, where I was the industry lead for telecommunications, designed Intune and Configuration Manager co-management rollouts, moved organisations off legacy MDM platforms, delivered Active Directory and Exchange projects, and ran workshops for customer IT teams. Earlier roles — Principal Security Consultant at Dell Technologies, cloud and security consultant at NourNet, and information security specialist in a SOC — gave me the identity, Exchange, Defender and SIEM background that Intune troubleshooting draws on every day.
I hold a Master of Science in Cybersecurity and a Bachelor of Science in ICT, both from the University of Science & Technology, along with 28 professional certifications including CISSP, CCSP, CISM, CISA and PMP — all of them, together with my Microsoft programme badges, verifiable on my Credly profile. As a Microsoft Certified Trainer and Microsoft Innovative Educator Expert I deliver Intune, Azure and Microsoft 365 training to customer teams and to IT communities in Qatar and Sudan. This blog is the written version of that work: what you'll see, why it happens, how to fix it, and how to prove the fix worked.
Each fix starts with why it broke, so you can recognise the pattern next time.
Portal paths, commands, logs and settings — spelled out, in order.
Every guide ends with how to verify the fix, not just how to apply it.
Eight years across security operations, consulting and cloud architecture — with Intune, identity, Exchange and Defender running through all of it.
Professional experience — employer and client work. Kept separate from community contribution on purpose.
Helping organisations design, deploy and troubleshoot Microsoft Intune: enrollment and Autopilot, app deployment, compliance and Conditional Access, security policy and update management — plus training for IT teams.
Cloud governance and security for enterprise customers: Microsoft 365 and Enterprise Mobility + Security deployments, Intune-based endpoint management, Configuration Manager co-management, SIEM, SOAR and SASE.
Designed and deployed Intune and co-management for large enterprise customers, led migrations from legacy MDM platforms, ran Active Directory and Exchange projects and customer workshops, and served as industry lead for telecommunications.
Planned and delivered cloud and security projects: Intune rollouts (enrollment, compliance baselines, app packaging), hybrid Configuration Manager + Intune designs and training for customer IT teams.
SOC monitoring and incident response with SIEM and SOAR, vulnerability assessments, security audits and policies, plus Intune compliance, Conditional Access and Configuration Manager patching.
Microsoft programmes first, then security, Microsoft cloud, networking and project management — the credentials behind the advice on this blog. Every badge links to my public Credly wallet, where each credential can be verified.
Three consecutive terms of Microsoft educator recognition (MIEE 2024–25, MIEE 2025–26, Elevate 2026–27) alongside the Microsoft Certified Trainer programme — continuity, not a one-off. Evidence and details
Questions about an article, a topic you'd like me to cover, or an idea to collaborate on? I'd love to hear from you.