Skip to content

Blogs

Registry Inventory in Intune: What It Kills, What It Can’t Touch

A side-by-side against Proactive Remediations with the limits Microsoft buried in a bullet point. Intune 2607 added native Windows registry collection to the properties catalog. It retires a specific class of detection script, the ones… 

Your April RDP Fix Is Already Legacy

Microsoft renamed the .rdp trusted-publisher policy and added SHA-2 support in the July 2026 update and Intune still shows the old SHA-1 label. Here is the complete deployment, signing, and audit playbook. Timeline: what changed,… 

Real-Time Driver & Firmware Update Reporting for Intune

Because “Windows Update Says We’re Fine” Isn’t a Report If you manage a Windows fleet through Microsoft Intune, you’ve probably had a version of this conversation with a client or a security team: “Are all… 

The July Update That Quietly Kills Your VPN

Hunting unregistered TDI transports with Intune before they reach your broad ring. Microsoft shipped a record 570 CVE fixes on 14 July 2026. Every blog on earth is busy counting them. The change that will… 

Extensions Monitoring in Edge: The Visibility Gap Just Closed

Browser extensions have quietly become one of the least-governed attack surfaces in the modern enterprise stack. They run with broad permissions, update outside your normal patch cycle, and until now, most admins running Microsoft Edge… 

Automating Stale Device Cleanup in Microsoft Entra ID

A practical, production-ready approach to keeping your device inventory clean. If you’ve administered a Microsoft Entra ID (formerly Azure AD) tenant for any length of time, you’ve seen it, hundreds and sometimes thousands of stale…