<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PaulyCloud — Intune &amp; Endpoint Management Blog on PaulyCloud</title><link>https://paulycloud.com/</link><description>Recent content in PaulyCloud — Intune &amp; Endpoint Management Blog on PaulyCloud</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 Simon Pauly Kofoed Mose</copyright><lastBuildDate>Mon, 18 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://paulycloud.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Confirm Escrow of FileVault Recovery Keys in Microsoft Entra</title><link>https://paulycloud.com/posts/confirm-escrow-of-filevault-recovery-keys/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/confirm-escrow-of-filevault-recovery-keys/</guid><description>&lt;p&gt;A couple of weeks ago I wrote about &lt;a href="https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/" &gt;confirming the escrow of BitLocker recovery keys&lt;/a&gt; in Microsoft Entra — driven by the urgency of the Secure Boot certificate changes. On the macOS side, there is no equivalent certificate crisis forcing our hand right now, but that does not make FileVault key escrow any less important.&lt;/p&gt;
&lt;p&gt;macOS continues to grow as a platform in the enterprise. More and more organizations are offering Macs as a choice — or even a default — for their workforce, and with Apple Silicon delivering strong performance across developer, creative, and general productivity workloads, that trend is only accelerating. As your Mac fleet grows, so does the importance of managing it with the same rigour you apply to Windows.&lt;/p&gt;</description></item><item><title>IntuneTip: Reset Windows Hello for Business Using On-Demand Remediation</title><link>https://paulycloud.com/posts/intune-tip-reset-windows-hello-container/</link><pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/intune-tip-reset-windows-hello-container/</guid><description>&lt;p&gt;Sometimes users need to have their Windows Hello for Business container reset. This can happen for a myriad of reasons:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Biometrics stopped working&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Something went wrong&amp;rdquo; errors during sign-in that won&amp;rsquo;t resolve&lt;/li&gt;
&lt;li&gt;Trust relationship between the credential and Microsoft Entra ID broke&lt;/li&gt;
&lt;li&gt;User suspects their PIN was observed or compromised&lt;/li&gt;
&lt;li&gt;Device was lost briefly and recovered — user wants to re-key&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For this support request, you can easily push a small script using Intune&amp;rsquo;s on-demand remediation feature (preview). All it does is use &lt;code&gt;certutil&lt;/code&gt; to delete the Windows Hello container and return the exit code.&lt;/p&gt;</description></item><item><title>Secure Boot Certificates – Confirm Escrow of BitLocker Recovery Keys in Microsoft Entra</title><link>https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/</link><pubDate>Mon, 27 Apr 2026 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/confirm-escrow-of-bitlocker-recovery-keys/</guid><description>&lt;p&gt;With the change of the Secure Boot certificates coming in fast and furious as summer approaches, it is paramount to ensure that your estate is ready to deploy the changes swiftly and securely.&lt;/p&gt;
&lt;p&gt;The change and deployment has been documented thoroughly by several great community articles and contributions in recent months, along with the expansion of Microsoft&amp;rsquo;s own documentation on the subject.&lt;/p&gt;
&lt;p&gt;I will not delve further into that here other than to provide links for further reading, but if you&amp;rsquo;re looking at a deployment guide, I would highly suggest taking a look at Mindcore&amp;rsquo;s blog linked below:&lt;/p&gt;</description></item><item><title>Passkey (iOS/Android) Registration Issue</title><link>https://paulycloud.com/posts/passkey-ios-android-registration-issue/</link><pubDate>Tue, 20 May 2025 00:00:00 +0000</pubDate><guid>https://paulycloud.com/posts/passkey-ios-android-registration-issue/</guid><description>&lt;p&gt;It is essential for some organizations to support BYOD for the iOS and Android platforms.&lt;/p&gt;
&lt;p&gt;This is most easily done while protecting data by utilizing &lt;strong&gt;Mobile Application Management (MAM)&lt;/strong&gt;, &lt;strong&gt;App Protection Policies (APP)&lt;/strong&gt;, and &lt;strong&gt;Conditional Access policies&lt;/strong&gt; to enforce it.&lt;/p&gt;
&lt;p&gt;Along with this, we are all in the eternal search for features that provide more security and a better user experience. Such unicorn features are few and far between, as more security usually means impacting the end-user experience in some way.&lt;/p&gt;</description></item><item><title>About</title><link>https://paulycloud.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://paulycloud.com/about/</guid><description>&lt;h2 class="relative group"&gt;Welcome to PaulyCloud
 &lt;div id="welcome-to-paulycloud" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#welcome-to-paulycloud" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;PaulyCloud is a blog dedicated to &lt;strong&gt;Microsoft Intune&lt;/strong&gt; and &lt;strong&gt;endpoint management&lt;/strong&gt;. Here you&amp;rsquo;ll find practical guides, deep dives, and real-world tips for managing devices at scale in the modern workplace.&lt;/p&gt;

&lt;h3 class="relative group"&gt;What You&amp;rsquo;ll Find Here
 &lt;div id="what-youll-find-here" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-youll-find-here" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Configuration Profiles&lt;/strong&gt; — Settings catalog, templates, and custom OMA-URI to manage endpoints the right way&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Scripting &amp;amp; Automation&lt;/strong&gt; — PowerShell scripts, remediation scripts, and Graph API to take the manual work out of endpoint management&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Windows Autopilot &amp;amp; Device Preparation&lt;/strong&gt; — Zero-touch deployment, provisioning profiles, and modern device onboarding at scale&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security Baselines&lt;/strong&gt; — Hardening endpoints with Microsoft&amp;rsquo;s recommended settings and beyond&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Conditional Access&lt;/strong&gt; — Integrating Intune with Entra ID to enforce the right access controls at the right time&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Device Compliance&lt;/strong&gt; — Configuring and troubleshooting compliance policies that feed into your security posture&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;App Deployment&lt;/strong&gt; — Win32 apps, LOB apps, Microsoft Store apps, and everything in between&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Troubleshooting&lt;/strong&gt; — Diagnosing and resolving the Intune issues you&amp;rsquo;ll inevitably run into&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;Connect
 &lt;div id="connect" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#connect" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;Feel free to reach out or follow along on &lt;a href="https://www.linkedin.com/in/simon-pauly-kofoed-mose-258485158/" target="_blank" rel="noreferrer"&gt;LinkedIn&lt;/a&gt; and &lt;a href="https://github.com/spkm95" target="_blank" rel="noreferrer"&gt;GitHub&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Contact</title><link>https://paulycloud.com/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://paulycloud.com/contact/</guid><description>&lt;h2 class="relative group"&gt;Get in Touch
 &lt;div id="get-in-touch" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#get-in-touch" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Have a question, feedback, or just want to connect? Feel free to reach out.&lt;/p&gt;

&lt;h3 class="relative group"&gt;Email
 &lt;div id="email" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#email" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;📧 &lt;a href="mailto:simon.pauly@paulycloud.com" &gt;simon.pauly@paulycloud.com&lt;/a&gt;&lt;/p&gt;

&lt;h3 class="relative group"&gt;LinkedIn
 &lt;div id="linkedin" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#linkedin" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;🔗 &lt;a href="https://www.linkedin.com/in/simon-pauly-kofoed-mose-258485158/" target="_blank" rel="noreferrer"&gt;Simon Pauly Kofoed Mose&lt;/a&gt;&lt;/p&gt;

&lt;h3 class="relative group"&gt;GitHub
 &lt;div id="github" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#github" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;🐙 &lt;a href="https://github.com/spkm95" target="_blank" rel="noreferrer"&gt;spkm95&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Privacy Policy</title><link>https://paulycloud.com/privacy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://paulycloud.com/privacy/</guid><description>&lt;h2 class="relative group"&gt;We Do Not Collect Your Data
 &lt;div id="we-do-not-collect-your-data" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#we-do-not-collect-your-data" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;PaulyCloud is a personal blog. Your privacy matters, and this site is designed to respect it fully.&lt;/p&gt;

&lt;h3 class="relative group"&gt;No Tracking
 &lt;div id="no-tracking" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#no-tracking" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;No cookies&lt;/strong&gt; — This site does not set any cookies&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No analytics&lt;/strong&gt; — No Google Analytics, no tracking pixels, no telemetry&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No fingerprinting&lt;/strong&gt; — No browser or device fingerprinting of any kind&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;No Data Collection
 &lt;div id="no-data-collection" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#no-data-collection" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;No personal data&lt;/strong&gt; is collected, stored, or processed&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No email addresses&lt;/strong&gt; are harvested or stored&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No user accounts&lt;/strong&gt; are required&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No forms&lt;/strong&gt; collect or transmit data from this site&lt;/li&gt;
&lt;/ul&gt;

&lt;h3 class="relative group"&gt;No Third-Party Trackers
 &lt;div id="no-third-party-trackers" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#no-third-party-trackers" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;This site does not embed any third-party tracking scripts, ad networks, or social media trackers.&lt;/p&gt;</description></item><item><title>Search</title><link>https://paulycloud.com/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://paulycloud.com/search/</guid><description/></item></channel></rss>