For Intune Engineers

What Intune doesn't tell you —
but you'll hit in production.

Real patterns from real environments. Compliance gaps, enforcement blind spots, and the fixes that actually hold up at scale.

May 31, 2026

Passwordless Works — Then M365 Dies a Few Days Later

After a clean passwordless/FIDO2 rollout, users start losing M365 access days or weeks later — long after go-live | A password reset "fixes" it instantly… then it comes back for the next user. Everyone blames the security key

Read
May 18, 2026

FIDO2 Coexistence: RDP, Legacy VPNs, and Recovery Flows

FIDO2 hardware keys cannot satisfy RDP Network Level Authentication — a scoped auth strength or Windows Hello for Business is required for Windows logon scenarios | RADIUS-backed VPNs do not support FIDO2 natively; every generic MFA grant in your CA policies needs an audit after hardware key depl...

Read
May 18, 2026

FortiGate VPN Broken by FIDO2: Diagnosing the CAP Conflict

After deploying FIDO2 hardware keys, FortiGate VPN users were prompted for their YubiKey instead of Authenticator — even though VPN was never scoped for FIDO2 | Root cause: a generic "Require MFA" grant in a CA policy selects the **strongest registered method** when multiple methods exist; once u...

Read
May 18, 2026

Zero-Lockout FIDO2 Rollout: Our Production Wave Plan

The most common FIDO2 rollout mistake is flipping CA enforcement before users are enrolled — causing immediate lockouts | A staged wave approach (Wave 0 prerequisites → Wave 1 pilot → Wave 2 high-risk → Wave 3 general) eliminates that risk

Read

Working on something harder? Talk to Hal → — 20 minutes, no pitch.