Rudy Ooms | MVP

@call4cloud.nl

{"Title":"Microsoft MVP","Talks About":"Intune, Autopilot, MMP-C ","Function":"Master Chief Content creator PMPC","Blog":"https://Call4cloud.nl"}

Sometimes the best investigations start with a Reddit post. After Windows devices began showing Intune compliance error 2016345708, @call4cloud.nl traced the issue through TPM changes, AIK v2, Device Health Attestation, and Microsoft's eventual fix. 🔗 https://bit.ly/4yNTjWi #MSIntune #SysAdmin

Why Intune Devices Became Noncompliant After the July Windows Update

Why July 2026 Windows builds caused 2016345708 compliance issues, how feature 62861611 enabled the new AIKv2 path, and how KB5101684 fixed it

bit.ly

We all thought the Sync button in #MSIntune forced everything to check in. It didn't. Microsoft's improved on-demand Sync now wakes both the MDM client and the Intune Management Extension. @call4cloud.nl breaks down exactly how it all works behind the scenes ➡️ https://bit.ly/4vuKOgd #SysAdmin

Inside the Improved on-demand sync for Windows devices

The improved Intune on demand Sync now triggers the regular policy check in plus Win32 apps, PowerShell scripts, and Remediations.

bit.ly

Something interesting is brewing with Microsoft Endpoint Privilege Management. @call4cloud.nl took a closer look at new #EPM components that suggest support for Network Settings and Time Sync may be on the way. Here's what he uncovered ➡️ https://bit.ly/4v3cKr6 #MSIntune #WindowsIT #PatchMyPC

Intune EPM System Settings: Network and Time Sync Elevation

Intune Endpoint Privilege Management appears to be adding a System Settings experience for Network Settings and Time Sync.

bit.ly

Not every #Autopilot timeout is actually an Autopilot problem. 👀 @call4cloud.nl traced a 0x800705b4 enrollment failure to an App Control for Business (#WDAC) trust issue in the #Intune Management Extension. Microsoft has now fixed it in the latest #IME release. ➡️ https://bit.ly/4vJh547 #MSIntune

Autopilot 0x800705b4: App Control Blocks the IME Installation

Autopilot failed with 0x800705b4 while preparing the device for mobile management. App Control for Business breaks the IME install (3033)

bit.ly

@call4cloud.nl is at it again 🕵️‍♂️ Within the #ITCommunity, a strange #Autopilot pre-provisioning issue was reported, so Rudy started investigating. The culprit? A failing MSI, a missing registry key, and a timing issue hiding in plain sight. Another mystery solved ✅ https://bit.ly/4ece9qn #Intune

Autopatch Client Broker Fails During Autopilot Pre-Provisioning

Autopatch Client Broker breaks Autopilot Pre Provisioning because one MSI custom action looks for TenantInfo after Windows already removed it

bit.ly

"Everything looks healthy." Sometimes that's the most frustrating thing an #ITPro can hear. #Intune says the action was sent. IME looks fine. No errors. But nothing happens. After reports from the #ITCommunity, @call4cloud.nl dug in to find out why. 👉 https://bit.ly/4ecZ1sR #MSIntune

When Intune Remediations Fail: Troubleshooting Push Notifications

Troubleshooting Intune remediations when push notifications never reach the device, including how to verify and repair the IME push channel.

bit.ly

Last check-in: 5 minutes ago. #Intune says the device is active. ...Is it, though? @call4cloud.nl recently uncovered why devices with expired MDM certificates can still show fresh check-in timestamps and what that really means for device health. 👉 https://bit.ly/4e4gwKh #MSIntune #ITCommunity

The Illusion of Intune “Last Check-in”: When Devices Appear Active but Cannot Sync

Devices with an expired Intune MDM certificate can still update their Last check in timestamp and appear healthy in the portal.

bit.ly

Certificates are scary, But be sure to join the webinar tomorrow where @byteben.bsky.social and @call4cloud.nl and myself talk about the Intune MDM device certificate and what the Intermediate cert expiring could mean for you. Maybe a little bit of talk about 🧀 too 😋🍴

Patch My PC@patchmypc.com · 3mo ago

Everything can look healthy until things get weird. ❌ Scripts failing ❌ Apps not installing ❌ Policies acting inconsistently Some devices never properly renew their #Intune certificate expiry updates, and you may not know which ones yet. We’ll show you how to find them 👉 https://bit.ly/42futzM

HP’s latest OneAgent update (v1.2.50.9581) quietly deleted the MS-Organization-Access certificate, breaking Entra ID joins across devices. Users? Locked out. Devices? No longer #Entra joined. Cause? A cleanup script gone rogue. Full breakdown and fixes from @call4cloud.nl ➡️ bit.ly/42Pk9iI

HP OneAgent Update Broke Entra Trust on HP AI Devices

A faulty cleanup script in HP OneAgent 1.2.50.9581 deleted the MS-Organization-Access certificate, disconnecting devices from Entra ID.

bit.ly

“#Intune only syncs every eight hours.” You sure about that? 🤔 In this week’s #PatchMeIfYouCan, @call4cloud.nl busts one of the biggest #Intune myths, diving into syncs, push notifications, and Microsoft’s new Fast Lane. Watch here ➡️ bit.ly/3IW5D1X #MSIntune #PatchNRant #PatchMyPC

The 8-Hour Intune Sync Myth… Busted! How Push Notifications Really Work in 2025 | Patch & Rant Ep.14

Think Intune only syncs every eight hours? Think again. In this Patch-N-Rant episode, we dive deep into one of Microsoft Intune’s biggest myths and uncover what really happens under the hood. From enrollment check-ins to push notifications, throttling, and Microsoft’s new Fast Lane delivery model. You’ll learn: • Why Windows devices don’t actually “wait eight hours” • How push notifications trigger instant policy syncs • What’s inside the mysterious Windows Notification Service payload • How Microsoft’s “Fast Lane” could change policy delivery forever If you love deep dives into what Microsoft doesn’t tell you, hit that and subscribe, or see how Patch My PC brings the same reliability and speed to third-party app patching. Book a demo: https://pmpc.link/j3xL 0:00 – Intro Breaking down the biggest Intune sync myth 0:39 – Understanding Enrollment How Intune devices really check in during setup 1:53 – Rapid Enrollment Schedule Why devices sync every few minutes at first 2:58 – After Enrollment Behavior From pull-based to push-based policy updates 4:14 – Push Notification Mechanics How Intune triggers device actions instantly 5:19 – What’s Inside the Push The hidden JSON payload and what it means 7:18 – The 30-Minute Throttle Rule Why not every policy change triggers a push 9:30 – Enter the Fast Lane Microsoft’s new model for faster policy delivery 10:31 – Myth Busted Recap Debunking the 8-hour sync and key takeaways 11:31 – Outro & Demo Invite Faster patching, smarter automation with Patch My PC #Intune #MicrosoftIntune #EndpointManager #IntuneAdmin #PatchMyPC #WindowsITPro #DeviceManagement #CloudIT #SysAdminLife #TechDeepDive #PatchNRant #RudyOoms #FastLane #ITHumor #Automation

bit.ly

📢It’s time. We’re officially launching MEM Summit 2026! Our 5th edition and by far the most ambitious. Early Bird tickets are now open. 👉 30% off for individual full passes 👉 35% off for group registrations #MEMSummit

New blog 🚨 Windows backup for orgs in #Windows11 isn’t what it seems. It’s more ESR with a facelift than a full backup. @call4cloud.nl covers: 💠 What’s new (and not) 💠 ESR vs Backup 💠 How to build a full restore w/ OneDrive + #PatchMyPC Learn more 👉 https://bit.ly/4mbZ8pe #SysAdminLife

BitLocker Policies Not Getting Applied in Intune (65000)

BitLocker policies pushed with Intune failed during Autopilot with error 65000. We explain why the BitLocker policies were never applied.

bit.ly