<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Intune Tips on PaulyCloud</title><link>https://paulycloud.com/categories/intune-tips/</link><description>Recent content in Intune Tips on PaulyCloud</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Simon Pauly Kofoed Mose</copyright><lastBuildDate>Mon, 18 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://paulycloud.com/categories/intune-tips/index.xml" rel="self" type="application/rss+xml"/><item><title>Confirm Escrow of FileVault Recovery Keys in Microsoft Entra</title><link>https://paulycloud.com/posts/confirm-escrow-of-filevault-recovery-keys/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/confirm-escrow-of-filevault-recovery-keys/</guid><description>&lt;p&gt;A couple of weeks ago I wrote about &lt;a href="https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/" &gt;confirming the escrow of BitLocker recovery keys&lt;/a&gt; in Microsoft Entra — driven by the urgency of the Secure Boot certificate changes. On the macOS side, there is no equivalent certificate crisis forcing our hand right now, but that does not make FileVault key escrow any less important.&lt;/p&gt;
&lt;p&gt;macOS continues to grow as a platform in the enterprise. More and more organizations are offering Macs as a choice — or even a default — for their workforce, and with Apple Silicon delivering strong performance across developer, creative, and general productivity workloads, that trend is only accelerating. As your Mac fleet grows, so does the importance of managing it with the same rigour you apply to Windows.&lt;/p&gt;</description></item><item><title>IntuneTip: Reset Windows Hello for Business Using On-Demand Remediation</title><link>https://paulycloud.com/posts/intune-tip-reset-windows-hello-container/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/intune-tip-reset-windows-hello-container/</guid><description>&lt;p&gt;Sometimes users need to have their Windows Hello for Business container reset. This can happen for a myriad of reasons:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Biometrics stopped working&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Something went wrong&amp;rdquo; errors during sign-in that won&amp;rsquo;t resolve&lt;/li&gt;
&lt;li&gt;Trust relationship between the credential and Microsoft Entra ID broke&lt;/li&gt;
&lt;li&gt;User suspects their PIN was observed or compromised&lt;/li&gt;
&lt;li&gt;Device was lost briefly and recovered — user wants to re-key&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For this support request, you can easily push a small script using Intune&amp;rsquo;s on-demand remediation feature (preview). All it does is use &lt;code&gt;certutil&lt;/code&gt; to delete the Windows Hello container and return the exit code.&lt;/p&gt;</description></item><item><title>Secure Boot Certificates – Confirm Escrow of BitLocker Recovery Keys in Microsoft Entra</title><link>https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/</guid><description>&lt;p&gt;With the change of the Secure Boot certificates coming in fast and furious as summer approaches, it is paramount to ensure that your estate is ready to deploy the changes swiftly and securely.&lt;/p&gt;
&lt;p&gt;The change and deployment has been documented thoroughly by several great community articles and contributions in recent months, along with the expansion of Microsoft&amp;rsquo;s own documentation on the subject.&lt;/p&gt;
&lt;p&gt;I will not delve further into that here other than to provide links for further reading, but if you&amp;rsquo;re looking at a deployment guide, I would highly suggest taking a look at Mindcore&amp;rsquo;s blog linked below:&lt;/p&gt;</description></item></channel></rss>