<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows</id>
    <title>UEM Information Hub Blog</title>
    <updated>2026-01-26T00:00:00.000Z</updated>
    <generator>https://github.com/jpmonette/feed</generator>
    <link rel="alternate" href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows"/>
    <subtitle>UEM Information Hub Blog</subtitle>
    <icon>https://tamu-edu.github.io/UEM-Information-Hub/img/favicon.ico</icon>
    <entry>
        <title type="html"><![CDATA[Admin By Request 8.6 Release Notes]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/admin-by-request-8.6-release-notes</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/admin-by-request-8.6-release-notes"/>
        <updated>2026-01-26T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Browser download elevation: Seamless browser download handling across Chrome, Edge, and Firefox. When a user downloads and launches an executable from the browser, the new Admin By Request Browser Extension detects the action and routes it through the proper elevation flow.]]></summary>
        <content type="html"><![CDATA[<p>Browser download elevation: Seamless browser download handling across Chrome, Edge, and Firefox. When a user downloads and launches an executable from the browser, the new Admin By Request Browser Extension detects the action and routes it through the proper elevation flow.</p>
<p>Refer to <a href="https://docs.adminbyrequest.com/endpoints/Windows/install.htm#Installing" target="_blank" rel="noopener noreferrer">Installing Admin By Request</a> for more information.</p>
<p>System tray improvements: The system tray icon has been optimized for speed and reliability - it now appears immediately when Explorer starts.
Additionally:
The tray icon automatically restarts if the ABR process is unexpectedly closed.
Logged-in users who are Azure global and device administrators now see the correct red tray icon when the Entra connector is not configured.
In tray tools, the Network Adapters tray tool now correctly displays all Wi-Fi adapters, resolving previous visibility issues.</p>
<p>Refer to <a href="https://docs.adminbyrequest.com/endpoints/Windows/ui.htm#Using_Tray_Tools" target="_blank" rel="noopener noreferrer">Using Tray Tools</a> for more information.</p>
<p>A significant number of bug fixes and minor improvements, benefiting the broader ABR community across the Windows product range.</p>]]></content>
        <author>
            <name>Jon Griffey</name>
        </author>
        <category label="Release Notes" term="Release Notes"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Implement New Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu]]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/433317</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/433317"/>
        <updated>2025-11-18T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 433317 Implement New Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu].]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=433317" target="_blank" rel="noopener noreferrer">433317</a> Implement New Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu].</p>
<p>Description: Details of maintenance:
This change consists of the implementation of a new Recast Management Server [MECM-1P-RCST-W1.auth.tamu.edu] and upgrade of existing Recast Console Extension agents on MECM Jump Servers and Recast Agents on workstations.</p>
<p>Degraded Recast Management Servers:
mecm-1p-rcst-c1.auth.tamu.edu
cm2-recast.as.tamu.edu</p>
<p>MECM Jump Servers:
mgmt-3p-cst.auth.tamu.edu
batcave.it.tamu.edu
mgmt-2p-cst.ads.tamu.edu
cm2.as.tamu.edu</p>
<p>Benefit of change:
This change addresses issues with both former Recast Management Servers that were both in different states of degradation and could not be reverted to a functional state since no backup snapshot existed.</p>
<p>By implementing a new sever, its database is now on the primary sql.it.tamu.edu SQL server&nbsp;and the old servers may now be decommissioned.&nbsp; The new server is on the latest Recast version 5.11.2511.1804, and agents and Recast Console Extensions will be upgraded on each MECM Jump Server. This brings&nbsp;alignment of each application version in accordance with the vendors specification for a properly configured environment.</p>
<p>The latest version includes several bug fixes and Right-Click Tools features outlined in the following release notes: <a href="https://docs.recastsoftware.com/help/recast-software-version-5-11-releases#recast-version-51125111804" target="_blank" rel="noopener noreferrer">https://docs.recastsoftware.com/help/recast-software-version-5-11-releases#recast-version-51125111804</a>.</p>
<p>Impact to customers:
There is no impact on campus faculty, staff, or students as it is a tool used by MECM admins. Recast Agents for OAL workstations will be upgraded and Unit Admins may deploy the new Recast Agent at their earliest convenience.</p>]]></content>
        <author>
            <name>Jon Griffey</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Scope Intune Company Portal as Required for 'All Devices']]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/392644</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/392644"/>
        <updated>2025-10-13T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 392644 Scope Intune Company Portal as Required for 'All Devices'.]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=392644" target="_blank" rel="noopener noreferrer">392644</a> Scope Intune Company Portal as Required for 'All Devices'.</p>
<p>Description: Details of maintenance:
This change will consist of modifying the 'Assignments' for the Microsoft Company Portal application in Intune. Currently following an opt-in model, to install Company Portal on Intune-managed devices, units must 'Include' a 'scope group' associated with target devices. With this change, the built-in virtual group 'All Devices' will be assigned, enforcing the install of the application upon device enrollment into Intune, removing the need for individual units to manage and assign their own 'scope groups'.</p>
<p>For special use-cases where Company Portal may not be appropriate to deploy, units may still prevent the deployment by using scope-groups to 'exclude' devices from receiving the application.</p>
<p>Benefit of change:
The Microsoft Company Portal app enables customers to install managed applications and access of other self-service resources from their Intune-managed workstation. A primary benefit of this change is to simplify the management and promote a consistent user experience.</p>
<p>Impact to customers:
There is no expected impact to campus members and will result in a shift from the current opt-in deployment model to a more manageable opt-out model for Intune Administrators.</p>]]></content>
        <author>
            <name>Neil Feagan</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Move Intune 'Drive Mapping' Policies to Production State]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/392747</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/392747"/>
        <updated>2025-10-13T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 392747 Move Intune 'Drive Mapping' Policies to Production State.]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=392747" target="_blank" rel="noopener noreferrer">392747</a> Move Intune 'Drive Mapping' Policies to Production State.</p>
<p>Description: Details of maintenance:
This change moves the following production-ready Intune enterprise 'template' policies to a production state, making them available to IT Units managing devices in Intune. Once in production, these Enterprise policies are intended to be used as templates by all Units to address their unique drive mapping needs. Note: The ADMX template may be copied and renamed directly in Intune, while the OMA-URI (single-drive configuration) policy must be manually recreated.</p>
<p>Enterprise Policy Templates Moving to Production:
02-TMPL-USER-Single-DriveMapping-v1 (Custom OMA-URI Configuration)
02-TMPL-USER-Multi-DriveMapping-v1 (ADMX Configuration)</p>
<p>Note: Both policy templates work in conjunction with the following Enterprise Platform Required (EPR) policy that must first be applied to enable drive mapping functionality.</p>
<p>02-EPR-MGMT-EnableDriveMapping-v1</p>
<p>Benefit of change:
The primary benefit of this change is to simplify and streamline configuration management for departmental network drives mapped to Intune-managed workstations.</p>
<p>Impact to customers:
There will be no customer impact due to the nature of this change.</p>]]></content>
        <author>
            <name>Neil Feagan</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Publish Forensit Migration Scripts v24.8 (Standard and SkipUser) to SCCM Following Validation by Mays]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/267881</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/267881"/>
        <updated>2025-07-09T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 267881 Publish Forensit Migration Scripts v24.8 (Standard and SkipUser) to SCCM Following Validation by Mays.]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=267881" target="_blank" rel="noopener noreferrer">267881</a> Publish Forensit Migration Scripts v24.8 (Standard and SkipUser) to SCCM Following Validation by Mays.</p>
<p>Description: This change is in response to TDX#267783, submitted by Mays, reporting that users experienced desktop icon flashing during Forensit-based migrations. Vendor documentation confirmed this behavior as a bug fixed in Forensit version 24.8.</p>
<p>Platform Engineering built the following updated applications and made them available in SCCM:</p>
<p>Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-CLBA</p>
<p>Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-TAMUCS</p>
<p>Forensit Migrate-TAMUMigrationAuthUserEXP010426 v14-TAMUCS-SkipUser</p>
<p>Mays conducted testing across multiple devices—each version was tested independently. Additionally, they verified that version 24.8 resolved the flashing desktop icons on a device that had already been migrated using a previous version of the Forensit script.</p>
<p>These packages are now published and available in SCCM. This change does not include production assignment. Each distributed unit is responsible for testing and deployment in their respective environments.</p>
<p>• Impact to Customers:
None as part of this change. No automatic deployments are being made.</p>
<p>• Impact to Other Services/Websites:
None.</p>]]></content>
        <author>
            <name>Nicholas Swanzy</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Enable “Allow Available Uninstall” in PatchMyPC Publisher for Win32 Apps in Intune]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/264345</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/264345"/>
        <updated>2025-07-07T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 264345 Enable “Allow Available Uninstall” in PatchMyPC Publisher for Win32 Apps in Intune.]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=264345" target="_blank" rel="noopener noreferrer">264345</a> Enable “Allow Available Uninstall” in PatchMyPC Publisher for Win32 Apps in Intune.</p>
<p>Description: Details of Maintenance:</p>
<p>A configuration update will be applied to PatchMyPC Publisher to enable the “Allow available uninstall for Win32 apps in Intune” setting. This change will allow all Available applications published via PatchMyPC to be uninstalled by end users through the Company Portal.</p>
<p>In addition, a Microsoft Graph API script will update all existing PatchMyPC-published Win32 apps in Intune to ensure the uninstall option is enabled for apps already marked as Available.</p>
<p>Benefit of Change:</p>
<p>Enables end-user self-service for uninstalling optional software.</p>
<p>Reduces IT support burden for basic uninstall requests.</p>
<p>Aligns PatchMyPC deployments with modern application lifecycle practices.</p>
<p>Retains strict control for Required applications, which are not affected.</p>
<p>Impact to Customers</p>
<p>Users will gain the ability to uninstall Available applications directly via the Company Portal.</p>
<p>No impact to users with Required apps or apps installed by other methods.</p>
<p>Users will not be prompted or forced to take any action.</p>
<p>Impact to Other Services/Websites</p>
<p>No impact expected to external services or websites.</p>
<p>Intune service will be used via Microsoft Graph API but within approved API usage guidelines.</p>]]></content>
        <author>
            <name>Nicholas Swanzy</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Intune/SCCM Co-Management settings no longer assigned]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/265098</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/265098"/>
        <updated>2025-07-07T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 265098 Intune/SCCM Co-Management settings no longer assigned.]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=265098" target="_blank" rel="noopener noreferrer">265098</a> Intune/SCCM Co-Management settings no longer assigned.</p>
<p>Description: Change Description:
An emergency change was implemented to reassign the Intune Enrollment Co-management settings after it was discovered that they were no longer assigned to any device group. This reassignment was necessary to resolve an issue reported by Jon, where SCCM agents were failing to install on OAL Self-Driven Autopilot enrolled devices.</p>
<p>Root Cause and Initial Fix</p>
<p>Root Cause:
The Intune Co-management settings had lost their assignments, which prevented proper SCCM agent deployment during Autopilot.</p>
<p>Initial Emergency Action:
The Co-management settings were assigned to the device scope group for all Autopilot enrolled devices.</p>
<p>Immediate Outcome:
This resolved the issue for OAL Self-Driven devices, as confirmed by Jon.</p>]]></content>
        <author>
            <name>Jon Griffey</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Disable SCCM application visibility in Company Portal to enforce an Intune-only application experience.]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/218049</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/218049"/>
        <updated>2025-05-22T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 218049 Disable SCCM application visibility in Company Portal to enforce an Intune-only application experience..]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=218049" target="_blank" rel="noopener noreferrer">218049</a> Disable SCCM application visibility in Company Portal to enforce an Intune-only application experience..</p>
<p>Description: Details of Maintenance:
This change will disable the setting that allows Configuration Manager (SCCM)-deployed applications to appear in the Intune Company Portal. Going forward, only applications deployed via Intune will be visible to end users. This action supports the proposed Company Portal redesign, which improves performance and simplifies the user experience by removing hybrid app listings.
Benefit of Change:</p>
<p>Reduces Company Portal load and UI latency</p>
<p>Eliminates user confusion caused by duplicate SCCM and Intune app listings</p>
<p>Establishes Company Portal as the single, authoritative interface for Intune application access</p>
<p>Aligns with onboarding practices under the Unified Device Management (UDM) project</p>
<p>Reinforces the use of PSG and ESG targeting standards</p>
<p>Impact to Customers:</p>
<p>No interruption of service</p>
<p>End users will no longer see SCCM applications in the Company Portal.</p>
<p>End users will now need to look at Software Center for SCCM applications.</p>
<p>Required apps from SCCM will continue deploying silently without user interaction</p>
<p>Impact to Other Services/Websites:</p>
<p>No impact to external services or websites</p>
<p>SCCM and Intune infrastructure continue to operate normally</p>
<p>Change is limited to the frontend presentation in the Company Portal</p>]]></content>
        <author>
            <name>Nicholas Swanzy</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
    <entry>
        <title type="html"><![CDATA[Implementation of the “All Shared Devices” filter in Intune to support scoped application and policy assignments for Self-Driven (Shared) devices.]]></title>
        <id>https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/218076</id>
        <link href="https://tamu-edu.github.io/UEM-Information-Hub/blog-windows/218076"/>
        <updated>2025-05-22T00:00:00.000Z</updated>
        <summary type="html"><![CDATA[Change Request 218076 Implementation of the “All Shared Devices” filter in Intune to support scoped application and policy assignments for Self-Driven (Shared) devices..]]></summary>
        <content type="html"><![CDATA[<p>Change Request <a href="https://service.tamu.edu/SBTDNext/Apps/34/Tickets/TicketDet?TicketID=218076" target="_blank" rel="noopener noreferrer">218076</a> Implementation of the “All Shared Devices” filter in Intune to support scoped application and policy assignments for Self-Driven (Shared) devices..</p>
<p>Description: Details of Maintenance:
This change introduces and standardizes the use of a device filter in Intune named “All Shared Devices.” The filter is used to identify devices that are enrolled without user affinity (Self-Driven), typically used as Shared Devices in labs, kiosks, and classrooms.
The filter uses the following syntax to exclude User-Driven devices enrolled using pre-provisioning:
(device.enrollmentProfileName -ne "_TAMU User Driven with Pre Provision")
This filter will be applied as Include or Exclude in assignments depending on the target audience. It will now serve as the standard method for distinguishing between Shared and User-Managed devices in policy and application assignments.
Benefit of Change:</p>
<p>Enables consistent targeting logic across device management scenarios</p>
<p>Supports clean separation between Shared and User-Managed devices</p>
<p>Reduces risk of misapplication of user-focused policies to Shared Devices</p>
<p>Aligns with Experience Scope Group (ESG) and Policy Scope Group (PSG) design standards</p>
<p>Supports structured onboarding under the Unified Device Management (UDM) project</p>
<p>Impact to Customers:</p>
<p>No user disruption</p>
<p>Improved accuracy and consistency of application and policy targeting</p>
<p>Easier troubleshooting and policy validation for distributed IT admins</p>
<p>Impact to Other Services/Websites:</p>
<p>No impact to external services or platforms</p>
<p>Change is limited to device targeting logic in Intune</p>]]></content>
        <author>
            <name>Nicholas Swanzy</name>
        </author>
        <category label="Change Request" term="Change Request"/>
    </entry>
</feed>