Generated by All in One SEO v5.0.1.1, this is an llms.txt file, used by LLMs to index the site. # Lucas Hadberg Microsoft 365, Intune & Modern Workplace Knowledge Base ## Sitemaps - [XML Sitemap](https://hadberg.eu/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Silently Enforce Bitlocker Using Endpoint Manager (Intune)](https://hadberg.eu/silently-enforce-bitlocker-using-endpoint-manager-intune/) - Bitlocker is one of the most essential security features to deploy to your windows devices. BitLocker Drive Encryption is a security feature that protects against data theft or exposure on lost, stolen, or improperly decommissioned computers. It integrates with the operating system to provide enhanced protection for files and systems, making it difficult for unauthorized - [How To Create Filters In Endpoint Manager](https://hadberg.eu/how-to-create-filters-in-endpoint-manager/) - Filters provide a convenient and efficient way to target specific devices, unlike the traditional method of using "dynamic groups", which can take time to update when new or updated devices are added. With filters, we can quickly and easily target devices without having to wait for membership lists to be updated. This makes filters a - [Bulk Convert CSV Files to Excel Files Using Powershell](https://hadberg.eu/bulk-convert-csv-files-to-excel-files-using-powershell/) - If you work with data, chances are you've encountered CSV files. While they're great for storing and exchanging data, they can be a bit time consuming to work with in certain situations. If you've ever needed to analyze or present CSV data in a more user-friendly way, you might have found yourself wishing for an - [How To Export Named Locations In AzureAD Using PowerShell](https://hadberg.eu/how-to-export-named-locations-in-azuread-using-powershell/) - In this blog post, I will guide you through how to export named locations in AzureAD using PowerShell, as well as how to configure the required API permissions using app registrations in AzureAD. If your organization has many office locations and branches, you might have numerous IP addresses added to your named locations in Azure - [Intune Update Rings Not Delivering Windows Feature Updates? How to Fix](https://hadberg.eu/intune-update-rings-not-delivering-windows-feature-updates-how-to-fix/) - I ran into an issue where several Windows devices stopped receiving feature updates, even though they looked completely healthy and continued to install security and quality updates without any problems. The tenant was managed using Intune update rings only. No feature update policies were assigned, and the deferral settings should have allowed the devices to - [How to Disable the "Allow my organization to manage my device" Prompt in Intune](https://hadberg.eu/how-to-disable-the-allow-my-organization-to-manage-my-device-prompt-in-intune/) - If you manage a modern workplace using Microsoft Intune, you are likely intimately familiar with the headache of BYOD (Bring Your Own Device) scenarios. One of the most common helpdesk triggers happens when a user signs into a Microsoft 365 app like Teams or Outlook on their personal Windows computer. They are presented with the - [Guide to Configuring Windows Backup for Organizations via Intune](https://hadberg.eu/guide-to-configuring-windows-backup-for-organizations-via-intune/) - If your organization is planning a massive PC hardware refresh or migrating users to newer builds of Windows 11, you know that preserving user settings and app configurations can be a significant headache. Microsoft recently introduced Windows Backup for Organizations, an enterprise-grade feature designed to streamline device transitions. By preserving user settings, preferences, and Microsoft - [Devices Showing “Office 365 Mobile” Instead of Intune? Fix the MDM Authority](https://hadberg.eu/devices-showing-office-365-mobile-instead-of-intune-fix-the-mdm-authority/) - This is one of those Intune issues that doesn’t make much sense when you first see it. A customer recently had devices enrolling into Entra ID, but the MDM field showed Office 365 Mobile instead of Microsoft Intune. Everything suggested Intune was in use, licenses were assigned, and yet enrollment clearly wasn’t happening correctly. The - [Intune Settings Catalog vs Administrative Templates](https://hadberg.eu/intune-settings-catalog-vs-administrative-templates/) - What actually matters in 2026 If you are still treating Administrative Templates and Settings Catalog as two equal options in Intune, you are already behind. In 2026, the decision is mostly made for you. Settings Catalog is the default for a reason. The real question is not which one is better in theory, but when - [When to Use Device vs User Targeting in Microsoft Intune](https://hadberg.eu/when-to-use-device-vs-user-targeting-in-microsoft-intune/) - User vs device targeting is one of those choices that looks simple but quietly shapes everything from troubleshooting to policy reliability. My general rule is simple: in most enterprise environments, device targeting should be the default unless you have a clear reason not to use it. That said, there are still cases where user targeting - [How To Configure Update rings for Windows using Intune](https://hadberg.eu/configure-update-rings-for-windows-using-endoint-manager/) - In today's blog I will quickly guide you through how to configure update rings for windows using intune. It is important to keep your organization's Windows version up to date in order to reduce the risks and vulnerabilities that are constantly being discovered. By running the latest version of Windows, you can decrease the chances - [How To Clear msExchMailboxGUID String From Exchange Online.](https://hadberg.eu/how-to-clear-msexchmailboxguid-string-from-exchange-online/) - If you have been running a hybrid environment with your office licenses running in the cloud but you still have your Exchange server on-premise, you might be looking to migrate your mailboxes to Microsoft 365 Exchange Online. Note: This guide should not be followed if you're using Hybrid Exchange to migrate mailboxes. There are plenty - [Get VMware Disk Usage Report for all VMs using PowerCLI.](https://hadberg.eu/get-used-storage-disk-space-for-all-vms-in-vmware-vcenter/) - Use this script to generate a comprehensive report of the disk space used and allocated to your virtual machines in VMware Vcenter using PowerCLI. Be sure to customize the variables to match your environment and always adjust the script to fit your specific needs. The script will also work for multiple Vcenter connections at once, - [Find External Email Forwarding rules in Microsoft365 Exchange Online](https://hadberg.eu/find-external-forward-mail-rules-in-microsoft365/) - NOTE: This has been added as a GUI view in the new Modern Exchange Admin Center. https://admin.exchange.microsoft.com/#/reports/autoforwardedmessages I have encountered instances where mailbox rules were used to silently steal important data from users by forwarding their important emails to an external address. This is a common method of data theft, and it is important to - [Problems With Webcam / Microphone](https://hadberg.eu/problems-with-webcam-microphone/) - Since the start of the pandemic and the shift to remote work, I have received more cases involving broken webcams or microphones than ever before. I always begin by performing basic troubleshooting steps, such as checking drivers, settings, and the F1-12 keys, but nothing seemed to work. After spending hours updating drivers, BIOS, and Windows, - [How To Change Office Update Targeting Channel.](https://hadberg.eu/how-to-change-office-update-targeting-channel/) - When working with Office, there are various targeting channels for program updates. Depending on your needs, you may require a newer or older version of a program. Understanding the different targeting channels can help you manage your Office programs and ensure that you have the right versions installed. As of writing this post there is - [SharePoint / OneDrive Sync Error On Windows 10 - Files On Demand](https://hadberg.eu/sharepoint-onedrive-sync-error-on-windows-10-files-on-demand/) - Some users may encounter an error when using synced SharePoint libraries, which is a common problem if you have migrated your data to SharePoint using the SharePoint Migration Tool. This error occurs when a user attempts to open a file from the SharePoint library using the OneDrive Sync function for that library. In my testing, - [SharePoint Online - Restore All files Deleted by Specific User.](https://hadberg.eu/restore-all-files-deleted-by-specific-user/) - OneDrive Sync users may accidentally delete an entire SharePoint library because they do not understand how it works or accidentally click "Delete" thinking it's only the data stored on their computer. It is strongly recommended to have a third-party backup solution for your Microsoft 365 services, including OneDrive, SharePoint, and Exchange. If a user has - [Manage Calendar Permissions in Exchange Online via PowerShell.](https://hadberg.eu/manage-calendar-permissions-in-exchange-online-via-powershell/) - PowerShell is often a more efficient and convenient way to perform tasks, especially when making multiple or frequent changes. This guide provides a quick example of how to manage user permissions in Microsoft 365 Exchange Online using PowerShell. Whenever the - User "Default" is selected it means that everyone has that permission unless anything else - [Configuration of Subdomain And Manage Who Can Create Teams.](https://hadberg.eu/microsoft-teams-configuration-of-subdomain-and-limit-creation-of-teams/) - When working with Teams in Microsoft 365, it is easy for users to create teams, which can lead to an excessive number of unnecessary or inappropriate teams for your organization. Another issue with Teams is that when a new team is created, its name is used as the username and email address, potentially preventing the - [Go Passwordless With Microsoft Authenticator.](https://hadberg.eu/go-passwordless-with-microsoft-authenticator-passwordless-sign-in/) - Microsoft Authenticator passwordless sign-in (PREVIEW) is a free tool that allows you or your users to go passwordless without much effort. By using this feature, you can improve security and reduce the burden of managing passwords, making it easier and more convenient for users to access their accounts. Here is a quick guide on how - [Configure Manged Favorites For Microsoft Edge Chromium](https://hadberg.eu/configure-manged-favorites-for-microsoft-edge-chromium/) - If your organization has many internal web services or frequently used websites that your users need quick and easy access to, the managed favorites feature could be a useful way to make these websites easily available to end-users. By setting up managed favorites, you can ensure that your users have quick and convenient access to - [RemoteApps on Windows Server lagging performance.](https://hadberg.eu/remoteapps-on-windows-server-lagging-performance/) - I recently encountered an issue with one of our clients regarding slow performance when using RemoteApps on their home computer. Initially, I thought it was a problem with their internet connection or the computer itself, but after trying to connect via their laptop, the performance was fine on their home network. After extensive troubleshooting and - [Block external forwarding in Exchange Online](https://hadberg.eu/block-external-forwarding-in-exchange-online/) - External forwarding should always be disabled by default in any tenant, as it is commonly used by intruders to extract confidential emails from key individuals within the organization. Disabling this feature can help prevent unauthorized access to sensitive information and protect your business from potential security threats. One example of these malicious inbox rules could - [Active Directory - Send email alerts based on events.](https://hadberg.eu/active-directory-send-email-alerts-based-on-events/) - You may want to proactively respond to events generated by your domain controller or other servers in order to quickly address potential issues or security threats. By monitoring events and taking appropriate action. You can modify the script below to your needs. In my example below i use the incidentID of a user account lockout. - [Protect SharePoint Data From Unmanaged Devices.](https://hadberg.eu/protect-sharepoint-data-from-unmanaged-devices/) - When working with confidential files in any company size it's very important to protect data from leaving the company to unwanted people or competitors. Microsoft has a lot of different technologies to help this from happening, but today we are taking a look at securing SharePoint data from unmanaged devices. There is two settings we - [MDM User Self-Enrollment Using Deep Links On Windows 10](https://hadberg.eu/mdm-user-self-enrollment-using-deep-links-on-windows10/) - This will be a very short, but yet useful blog post about making the self-enrollment end-user experience better for your users.Keep in mind that this way of enrollment is not intended for large scale enterprises. Today we will take a look at how you can use "Deep links" to help guide your users to self-enroll - [Retention and Archiving not working in Exchange Online.](https://hadberg.eu/exchange-online-retention-and-archiving-not-working/) - There are a lot of reasons why your new retention policy might not run for some users, i have listed a bunch of reasons why the mailbox might be on some sort of hold or different retention that might cause the MRM not to run. Hold will prevent the retention and archive polices to run. - [How To Configure "Dynamic Device" Group For MacBooks In AzureAD.](https://hadberg.eu/how-to-configure-dynamic-device-group-for-macbooks/) - When creating configuration or compliance policies in Microsoft 365, its important to make sure you're only targeting the devices or users you want to target. To do this you can use the Microsoft365 "Dynamic device/user" feature when creating groups in "Azure Active Directory" Start by going to the "https://aad.portal.azure.com/" and open the groups section in - [How to Configure Daily End-User Spam Report For Exchange Online](https://hadberg.eu/how-to-enable-configure-end-user-spam-notifications/) - The following is a quick and simple guide to show you how you can set up daily spam reports for your users. The first step is to access the Exchange administrator panel, it can be accessed via the following link: https://outlook.office365.com/ecp Go to "Spam Filter" under the section "Protection". Select the default spam filter policy - [How To Check Password Expire Status In Active Directory.](https://hadberg.eu/how-to-check-password-expire-status/) - It's quite simple to check if your users password has expired or is about to expire. Just run the following command from the Domain controller in CMD as administrator. net user "username" /domain If you have any questions / feedback or would like to correct me on any of the stuff above.Please use the comment - [Activation / Login Issues With Office, Login Loop Or Activation Error](https://hadberg.eu/activation-login-issues-with-office-login-loop-or-activation-error/) - It's often af problem with shared machines or if the user has taken over someones PC after they left the company. Sometimes it can happen if the users password was changed or the license was Upgraded/Downgraded. There is two things you need to do to solve this problem 90% of the time. Remove the registred ## Pages - [About Me](https://hadberg.eu/about-me/) - Hello, my name is Lucas Hadberg, I am heavily invested in Microsoft 365 Cloud Solutions and have spent the past years working with a wide range of different organizations to help them leverage and migrate their on-premise resources to Microsoft 365. I enjoy working in this rapidly growing field and like to further my knowledge - [Contact me](https://hadberg.eu/contact-me/) - If you would like to get in contact with me, please use the form below.[contact-form-7 id="47" title="Contact form 1"] ## Categories - [SharePoint / OneDrive](https://hadberg.eu/category/sharepointonedrive/) - [Active Directory](https://hadberg.eu/category/activedirectory/) - [Exchange Online](https://hadberg.eu/category/exchangeonline/) - [Windows 10](https://hadberg.eu/category/win10/) - [Azure](https://hadberg.eu/category/azure/) - [VMware](https://hadberg.eu/category/vmware/) - [Microsoft Teams](https://hadberg.eu/category/microsoft-teams/) - [PowerShell](https://hadberg.eu/category/powershell/) - [Group Policy](https://hadberg.eu/category/group-policy/) - [Intune](https://hadberg.eu/category/intune/) - [Windows 11](https://hadberg.eu/category/windows-11/) ## Tags - [external mail](https://hadberg.eu/tag/external-mail/) - [forwarding](https://hadberg.eu/tag/forwarding/) - [exchange online](https://hadberg.eu/tag/exchange-online/) - [microsoft365](https://hadberg.eu/tag/microsoft365/) - [powershell](https://hadberg.eu/tag/powershell/) - [webcam issue](https://hadberg.eu/tag/webcam-issue/) - [microphone](https://hadberg.eu/tag/microphone/) - [lenovo](https://hadberg.eu/tag/lenovo/) - [hp](https://hadberg.eu/tag/hp/) - [dell](https://hadberg.eu/tag/dell/) - [troubleshotting](https://hadberg.eu/tag/troubleshotting/) - [activation](https://hadberg.eu/tag/activation/) - [loop](https://hadberg.eu/tag/loop/) - [login](https://hadberg.eu/tag/login/) - [issues](https://hadberg.eu/tag/issues/) - [office](https://hadberg.eu/tag/office/) - [office365](https://hadberg.eu/tag/office365/) - [stuck](https://hadberg.eu/tag/stuck/) - [reactivation](https://hadberg.eu/tag/reactivation/) - [target](https://hadberg.eu/tag/target/) - [channel](https://hadberg.eu/tag/channel/) - [script](https://hadberg.eu/tag/script/) - [update](https://hadberg.eu/tag/update/) - [dynamic groups](https://hadberg.eu/tag/dynamic-groups/) - [macbook](https://hadberg.eu/tag/macbook/) - [intune](https://hadberg.eu/tag/intune/) - [list](https://hadberg.eu/tag/list/) - [devices](https://hadberg.eu/tag/devices/) - [MDM](https://hadberg.eu/tag/mdm/) - [mangement](https://hadberg.eu/tag/mangement/) - [password](https://hadberg.eu/tag/password/) - [expire](https://hadberg.eu/tag/expire/) - [command](https://hadberg.eu/tag/command/) - [activedirectory](https://hadberg.eu/tag/activedirectory/) - [msExchMailboxGUID](https://hadberg.eu/tag/msexchmailboxguid/) - [adsync](https://hadberg.eu/tag/adsync/) - [exchange](https://hadberg.eu/tag/exchange/) - [migration](https://hadberg.eu/tag/migration/) - [hybrid](https://hadberg.eu/tag/hybrid/) - [AD connect](https://hadberg.eu/tag/ad-connect/) - [sync](https://hadberg.eu/tag/sync/) - [null](https://hadberg.eu/tag/null/) - [clear](https://hadberg.eu/tag/clear/) - [spam](https://hadberg.eu/tag/spam/) - [rapport](https://hadberg.eu/tag/rapport/) - [report](https://hadberg.eu/tag/report/) - [quarantine](https://hadberg.eu/tag/quarantine/) - [spam filter](https://hadberg.eu/tag/spam-filter/) - [filter](https://hadberg.eu/tag/filter/) - [enduser](https://hadberg.eu/tag/enduser/) - [notifications](https://hadberg.eu/tag/notifications/) - [administrator](https://hadberg.eu/tag/administrator/) - [phish](https://hadberg.eu/tag/phish/) - [leak](https://hadberg.eu/tag/leak/) - [0x80070184](https://hadberg.eu/tag/0x80070184/) - [0x80070185](https://hadberg.eu/tag/0x80070185/) - [0x8007017F](https://hadberg.eu/tag/0x8007017f/) - [The Cloud sync engine failed](https://hadberg.eu/tag/the-cloud-sync-engine-failed-2/) - [The cloud operation was unsuccessful](https://hadberg.eu/tag/the-cloud-operation-was-unsuccessful/) - [Onedrive](https://hadberg.eu/tag/onedrive/) - [sharepoint](https://hadberg.eu/tag/sharepoint/) - [libary](https://hadberg.eu/tag/libary/) - [cloud](https://hadberg.eu/tag/cloud/) - [windows 10](https://hadberg.eu/tag/windows-10/) - [files on demand](https://hadberg.eu/tag/files-on-demand/) - [demand](https://hadberg.eu/tag/demand/) - [data](https://hadberg.eu/tag/data/) - [deleted](https://hadberg.eu/tag/deleted/) - [restore](https://hadberg.eu/tag/restore/) - [files](https://hadberg.eu/tag/files/) - [accident](https://hadberg.eu/tag/accident/) - [user](https://hadberg.eu/tag/user/) - [mail](https://hadberg.eu/tag/mail/) - [calendar](https://hadberg.eu/tag/calendar/) - [admin](https://hadberg.eu/tag/admin/) - [Vmware](https://hadberg.eu/tag/vmware/) - [disk](https://hadberg.eu/tag/disk/) - [cli](https://hadberg.eu/tag/cli/) - [storage](https://hadberg.eu/tag/storage/) - [vcenter](https://hadberg.eu/tag/vcenter/) - [vm](https://hadberg.eu/tag/vm/) - [virtual machines](https://hadberg.eu/tag/virtual-machines/) - [powercli](https://hadberg.eu/tag/powercli/) - [usage](https://hadberg.eu/tag/usage/) - [export](https://hadberg.eu/tag/export/) - [excel](https://hadberg.eu/tag/excel/) - [csv](https://hadberg.eu/tag/csv/) - [multiple connections](https://hadberg.eu/tag/multiple-connections/) - [VMware.PowerCLI](https://hadberg.eu/tag/vmware-powercli/) - [microsoft](https://hadberg.eu/tag/microsoft/) - [teams](https://hadberg.eu/tag/teams/) - [dns](https://hadberg.eu/tag/dns/) - [microsoft teams](https://hadberg.eu/tag/microsoft-teams/) - [subdomain](https://hadberg.eu/tag/subdomain/) - [group](https://hadberg.eu/tag/group/) - [groups](https://hadberg.eu/tag/groups/) - [passwordless](https://hadberg.eu/tag/passwordless/) - [authenticator](https://hadberg.eu/tag/authenticator/) - [mfa](https://hadberg.eu/tag/mfa/) - [azure](https://hadberg.eu/tag/azure/) - [azuread](https://hadberg.eu/tag/azuread/) - [phone](https://hadberg.eu/tag/phone/) - [ios](https://hadberg.eu/tag/ios/) - [android](https://hadberg.eu/tag/android/) - [edge](https://hadberg.eu/tag/edge/) - [chrome](https://hadberg.eu/tag/chrome/) - [chromium](https://hadberg.eu/tag/chromium/) - [group policy](https://hadberg.eu/tag/group-policy/) - [ADMX](https://hadberg.eu/tag/admx/) - [configure](https://hadberg.eu/tag/configure/) - [security](https://hadberg.eu/tag/security/) - [unmanged](https://hadberg.eu/tag/unmanged/) - [device](https://hadberg.eu/tag/device/) - [byod](https://hadberg.eu/tag/byod/) - [limit](https://hadberg.eu/tag/limit/) - [access](https://hadberg.eu/tag/access/) - [protect](https://hadberg.eu/tag/protect/) - [enrollment](https://hadberg.eu/tag/enrollment/) - [enroll](https://hadberg.eu/tag/enroll/) - [deep links](https://hadberg.eu/tag/deep-links/) - [self-enroll](https://hadberg.eu/tag/self-enroll/) - [self-enrollment](https://hadberg.eu/tag/self-enrollment/) - [windows](https://hadberg.eu/tag/windows/) - [end-user](https://hadberg.eu/tag/end-user/) - [experince](https://hadberg.eu/tag/experince/) - [remoteapp](https://hadberg.eu/tag/remoteapp/) - [remotedesktop](https://hadberg.eu/tag/remotedesktop/) - [slow](https://hadberg.eu/tag/slow/) - [laggy](https://hadberg.eu/tag/laggy/) - [lag](https://hadberg.eu/tag/lag/) - [mouse](https://hadberg.eu/tag/mouse/) - [gaming](https://hadberg.eu/tag/gaming/) - [retention](https://hadberg.eu/tag/retention/) - [archive](https://hadberg.eu/tag/archive/) - [policy](https://hadberg.eu/tag/policy/) - [mrm](https://hadberg.eu/tag/mrm/) - [troubleshooting](https://hadberg.eu/tag/troubleshooting/) - [external](https://hadberg.eu/tag/external/) - [blocking](https://hadberg.eu/tag/blocking/) - [best practice](https://hadberg.eu/tag/best-practice/) - [Active directory](https://hadberg.eu/tag/active-directory/) - [email](https://hadberg.eu/tag/email/) - [alerts](https://hadberg.eu/tag/alerts/) - [eventlog](https://hadberg.eu/tag/eventlog/) - [event](https://hadberg.eu/tag/event/) - [instanceid](https://hadberg.eu/tag/instanceid/) - [endpoint](https://hadberg.eu/tag/endpoint/) - [endpointmanager](https://hadberg.eu/tag/endpointmanager/) - [ring](https://hadberg.eu/tag/ring/) - [patch](https://hadberg.eu/tag/patch/) - [windows 11](https://hadberg.eu/tag/windows-11/) - [bitlocker](https://hadberg.eu/tag/bitlocker/) - [encryption](https://hadberg.eu/tag/encryption/) - [recovery key](https://hadberg.eu/tag/recovery-key/) - [decryption](https://hadberg.eu/tag/decryption/) - [silently](https://hadberg.eu/tag/silently/) - [filters](https://hadberg.eu/tag/filters/) - [dynamic](https://hadberg.eu/tag/dynamic/) - [assignments](https://hadberg.eu/tag/assignments/) - [automation](https://hadberg.eu/tag/automation/) - [ise](https://hadberg.eu/tag/ise/) - [graph](https://hadberg.eu/tag/graph/) - [api](https://hadberg.eu/tag/api/) - [named locations](https://hadberg.eu/tag/named-locations/)