All Intune, AI and Azure Blog Posts
Guides, code and lessons from working with Intune, AI agents and Azure. Find your topic with search or the filters below.
Supported byAdvertisement
Agent 365 registration: Python and Entra walkthrough
Your agent runs outside Microsoft. Your administrators still need to know that it exists, who owns it and which identity it uses. That is the starting point for this Agent 365 registration walkthrough. In this episode, I register a small Python-based ticket-triage demo in Microsoft Agent 365, connect its Entra identity and inspect the resulting objects in the portals. The useful part is not another agent demo. It is seeing how the registry entry, identity and activity fit together—and where they remain separate.
Read article: Agent 365 registration: Python and Entra walkthrough
Read Copilot Studio Memory: Off Does Not Mean DeletedCopilot Studio Memory: Off Does Not Mean Deleted
I opened the Build page of my Copilot Studio demo agent and looked at the Memory switch. It was off. That is a useful observation, but it does not answer every data-handling question. Microsoft documents that turning Memory off prevents the agent from using stored memories. It does not delete those memories. If your change record says “memory disabled and all stored information removed,” one toggle is not enough evidence. Copilot Studio Memory documentation. That distinction is worth understanding before adding memory to a production agent. Here is how I would review the feature, using an existing policy-assistant draft in my ModernDevMgmt tenant.
Read article: Copilot Studio Memory: Off Does Not Mean Deleted
Read Copilot Studio Costs Start Before You PublishCopilot Studio Costs Start Before You Publish
The new Copilot Studio home page makes it easy to start an agent. There is another label on the same page that deserves just as much attention: Uses Copilot Credits. If your mental model is “we pay once the agent is published,” it is time to check which harness you are using. With the GitHub Copilot harness, the work before publication matters too. That changes how I would plan a demo, a development environment and a production pilot. I opened my ModernDevMgmt tenant to look at the current experience. The screenshots below are fresh portal captures from 28 September 2026, not Microsoft documentation images. I inspected existing demo agents without changing their configuration, running prompts or publishing them. Cost-control guidance is linked to Microsoft's documentation; this was not a billing or enforcement benchmark.
Read article: Copilot Studio Costs Start Before You Publish
Read Microsoft Agent 365: A Live Portal OverviewMicrosoft Agent 365: A Live Portal Overview
Microsoft Agent 365 gives administrators a place to inspect the agents around their organization: which agents exist, who owns them and where their identities and management settings can be found. In this episode, I explore that experience in my demo tenant. This is a portal overview with a few administrative actions, not a claim that the tenant has a complete, production-tested governance setup. Some agents are still drafts, activity is limited, and one policy-template flow does not accept the license state as expected. Those details are part of the walkthrough. Video language: German · Duration: 15:38 · Released 30 September 2026. The recording reflects the portal and demo-tenant state at the time it was made; availability depends on licensing and rollout.
Read article: Microsoft Agent 365: A Live Portal Overview
Read Copilot Budgets: Which Settings Actually Stop Usage?Copilot Budgets: Which Settings Actually Stop Usage?
You give a Copilot pilot a budget. Someone enters a number in an admin portal. Finance expects the service to stop at that number. That expectation is worth checking before the pilot starts. Some Copilot budgets send alerts. Other controls restrict access or turn an agent off. They are not interchangeable. The answer depends on the service, the billing experience and the setting you configure. I would start with the control, not the credit price: what exactly should happen when the team reaches its allowance? This guide separates the main control types and gives you a practical review plan. Product information was checked on 28 September 2026. The screenshot comes from my ModernDevMgmt demo tenant. Billing and enforcement behavior below is Microsoft-documented; I did not enable paid billing or run a limit-exhaustion test for this article.
Read article: Copilot Budgets: Which Settings Actually Stop Usage?
Read Copilot Chat vs Cowork vs Autopilot: What to Use WhenCopilot Chat vs Cowork vs Autopilot: What to Use When
You need to prepare Friday's service review. Do you want help understanding the numbers, a finished review pack, or someone to keep following up during the week? That is how I would approach Copilot Chat vs Cowork vs Autopilot. Start with the responsibility you want to hand over. The product name comes second. In this guide, I compare the three options using the same practical example. I also cover licenses, consumption costs and the controls to check before a rollout. Status checked: 27 September 2026. This article covers commercial Microsoft 365. Autopilot is the new name for Scout and remains in private preview. Its section is based on Microsoft's announcement, not a claim that I have tested it in my tenant. Microsoft's announcement This comparison is about three ways of working inside Microsoft 365 Copilot: asking, delegating a task and ongoing follow-up. If your question is whether to use a ready-made experience or build a reusable business agent, start with my Copilot, Copilot Studio and custom agents guide.
Read article: Copilot Chat vs Cowork vs Autopilot: What to Use When
Read The Enterprise Agent Control Plane I WantThe Enterprise Agent Control Plane I Want
I do not want another dashboard for enterprise AI agents. I want an enterprise agent control plane that can answer who owns an agent, what it can call, how it behaves and how to stop it. In this blog post I explain the five layers I would connect: identity, catalog, policy, telemetry and lifecycle. Microsoft Foundry now has a Control Plane experience for visibility and lifecycle operations across agents. That is an important platform building block. My broader point is that an enterprise control plane is also an operating model. It has to connect the AI platform with Microsoft Entra ID, Azure API Management, monitoring, data governance and the teams that own the affected systems.
Read article: The Enterprise Agent Control Plane I Want
Read Microsoft Foundry Python Agents: Build a Policy AssistantMicrosoft Foundry Python Agents: Build a Policy Assistant
Microsoft Foundry Python agents become easier to understand when you separate three steps: call a model, create an agent, and run that agent against a real question. In this episode, I walk through those steps in VS Code using an IT policy assistant as the example. The useful part is not getting another chatbot to answer “What is MFA?” It is moving from that simple connectivity check to an agent that can look up company policy and return sources. Watch the complete walkthrough below; the written notes explain the boundaries between the scripts and the checks I would make before using the same pattern in an application. Related Python examples: You can find model calls, agents and Azure AI Search examples in my Microsoft Foundry examples repository on GitHub. This is a broader collection, not an exact copy of the three scripts in this video. Some agent examples use the classic Agent Service API, so follow the repository README for the matching SDK and setup. Video language: German · Duration: 10:05 · Released 22 September 2026.
Read article: Microsoft Foundry Python Agents: Build a Policy Assistant
Read Five Gates Before an MCP Tool Reaches ProductionFive Gates Before an MCP Tool Reaches Production
Connecting a Model Context Protocol server to an agent is easy. The difficult part starts when that connection can reach a real business system. For MCP tool production, I want five gates to pass before the first user can rely on it: identity, scope, limits, approval and evidence. In this blog post I explain what I check at each gate and where Azure API Management can help. This is not a generic zero-trust checklist. It is the practical review I would use for an MCP tool that reads or changes enterprise data. The goal is simple: every call should have an accountable caller, a narrow permission, a controlled impact and enough evidence to explain what happened.
Read article: Five Gates Before an MCP Tool Reaches Production
Read Copilot vs Cowork vs Agents: Licenses, Costs and GovernanceCopilot vs Cowork vs Agents: Licenses, Costs and Governance
You want AI to prepare a rollout meeting. Should you ask Copilot, delegate the work to Cowork, or build an agent? All three might help. But you would be buying, operating and governing three different things. One approach may need only a prompt. Another needs a consumption budget. A third becomes a service that somebody has to maintain. In this Copilot vs Cowork vs agents guide, I explain how I would make that decision. We will look at each option, its licenses and charges, and the governance boundaries. I also walk through the new Copilot Studio interface with real product screenshots. Scope and date: commercial Microsoft 365, checked on 16 September 2026. This is not a comparison with consumer Copilot, Claude Cowork or the GitHub coding subscription. Prices below are US public list prices, excluding tax, base subscriptions and contractual discounts. Availability varies by region, cloud, license and rollout. This guide focuses on the platform decision: use Microsoft 365 Copilot, configure a Copilot Studio agent or build with Microsoft Foundry. For the narrower question of interactive help, delegated work and ongoing follow-up, see my Copilot Chat vs Cowork vs Autopilot comparison.
Read article: Copilot vs Cowork vs Agents: Licenses, Costs and Governance
Read Azure API Management MCP: The Control Plane for Agent ToolsAzure API Management MCP: The Control Plane for Agent Tools
MCP makes it easy to connect an AI agent to tools. That is useful for a demo, but an enterprise needs more than a connection string. It needs identity, a controlled tool surface, rate limits, monitoring and a clear owner. In this blog post I show how I would use Azure API Management MCP as the control plane between agents and enterprise tools.
Read article: Azure API Management MCP: The Control Plane for Agent Tools
Read Detect and Block Shadow AI with Intune: OpenClaw in PracticeDetect and Block Shadow AI with Intune: OpenClaw in Practice
Local AI agents are moving from developer experiments to normal Windows endpoints. They can read files, call tools and act with the permissions of the signed-in user. That makes them useful, but it also creates a new blind spot for endpoint teams. In this blog post I show how the new Intune Shadow AI controls can discover local agents such as OpenClaw, give you useful inventory data and help you decide what to control.
Read article: Detect and Block Shadow AI with Intune: OpenClaw in PracticeComplete archiveAll articles by year
All articles by year
2026
- Agent 365 registration: Python and Entra walkthrough
- Copilot Studio Memory: Off Does Not Mean Deleted
- Copilot Studio Costs Start Before You Publish
- Microsoft Agent 365: A Live Portal Overview
- Copilot Budgets: Which Settings Actually Stop Usage?
- Copilot Chat vs Cowork vs Autopilot: What to Use When
- The Enterprise Agent Control Plane I Want
- Microsoft Foundry Python Agents: Build a Policy Assistant
- Five Gates Before an MCP Tool Reaches Production
- Copilot vs Cowork vs Agents: Licenses, Costs and Governance
- Azure API Management MCP: The Control Plane for Agent Tools
- Detect and Block Shadow AI with Intune: OpenClaw in Practice
- Work IQ API: Query Microsoft 365 Data With AI
- Microsoft Foundry Tracing and Evaluation: Debug an Agent
- Desk Setup 2026: Every Product I Use and What I Would Skip
- Fabric Data Agents: Chat With Your Data in OneLake
- Microsoft Foundry Landing Zone: Governance in the Portal
- Agent Skills vs MCP: When to Use Which for AI Agents
- Claude Code GitHub Actions: Setup, YAML and Permissions
- Microsoft Foundry Guardrails: Portal Walkthrough and Tests
- Multi-Agent Orchestration in Microsoft Foundry: A Deep Dive
- My Agentic OS: How I Run Notion, Outlook, Codex and OneDrive
- Security Copilot Agents in Intune: What You Get in 2026
- Microsoft Foundry Model Deployment: A Practical Guide
- Foundry IQ Deep Dive: Knowledge Bases for AI Agents
- Microsoft Foundry Setup: Project, Model and Deployment
- Microsoft Foundry Playground: Build and Test Your First Agent
- Intune Multi Admin Approval Now Enforced on Graph API Calls
- Microsoft Foundry Observability: Trace AI Agents in Production
- Microsoft Foundry Realtime Voice Agent: Talk to Your Screen
- Enterprise App Management Auto-Update: Now Generally Available
- Azure AI Inference SDK Migration: OpenAI v1 Guide
- Microsoft Foundry Model Router and Catalog: A Deep Dive
- Microsoft Foundry June 2026: Build More Than a Demo
- Secure Microsoft Foundry: Network, Identity and Guardrails
- Microsoft Foundry vs Copilot Studio: Which Agent Platform?
- Admin By Request Unboxed: My Full EPM Walkthrough
- How to Evaluate AI Agents in Microsoft Foundry Step by Step
- Agent Skills Explained: How to Build Your First Skill
- Build Your First AI Agent in Microsoft Foundry Step by Step
- Protect AI Agents with Microsoft Defender for Endpoint
- Azure Private Networking, End to End: Service Endpoints, Private Endpoints, VNet Integrat...
- The Ultimate Intune Troubleshooting Guide: How It Works and How I Fix It
- AI Models 2026: Prices, Task Costs and EU Hosting
- Foundry Local: Run AI Models Offline on Your Mac
- Intune Advanced Analytics: How It Compares to Other Tools
- Microsoft Build 2026: A Field Guide to the Agentic Stack
- My New Setup: Why the Oakywood Standing Desk Pro Has Actually Made Me More Productive
- Skills vs MCP vs CLI: AI Agent Tools Compared
- Microsoft Agent 365 vs. Microsoft 365 Agents: A Field Guide for IT and Architects
- AI-Powered Intune Policy Documentation and Conflict Analysis
- CLI Tools vs MCP: Better AI Agents With Less Context
- Azure AI Content Safety Guide: Filters and Best Practices
- 8 Productivity Tools I Use Daily for AI, Coding, and Planning
- Azure OCR Comparison: Mistral, GPT & Document Intelligence
- Build a Microsoft Intune AI Agent with Foundry
2025
- How to Create an AI Selfie Tour Video with Tech Icons
- Microsoft IQ Explained: Making Enterprise AI Agents Work
- AI Document Manager with Azure OpenAI for Paperless Offices
- Right Click Tools for SCCM & Intune: Patch, Report, Elevate
- AI-Driven Endpoint Management: The Future with Intune
- Right Click Tools for Intune: Free Community Edition
- Simplify App Management and Patching with Recast
2024
- Become a Prompt Engineering Pro: Mastering the Art of Talking to AI in 2025
- Patch My PC Home Updater 5.0: What’s New and How It Works
- Convert Intune Device Groups to User Groups via Graph API
- Robopack A bis Z: Alles, was du wissen musst (Sponsor)
- Graph Batch Endpoint
- Set Up a Windows Autopilot Lab on macOS
- Azure AI Search: Build a Powerful AI Search Engine
- Microsoft Intune Mac Management: A Complete Guide
- IME Log Summarizer for Microsoft Intune
- How to create a custom SSO Teams bot
- How to build your custom GPT apps
- Cloud-Native Endpoint Deployment with Microsoft Intune
- Microsoft Copilot for Security: Getting Started Guide
- Automate Local Admin Rights Removal with Privilege Manager
- Build an Intune Copilot with Microsoft Copilot Studio
- Build a No-Code Intune Copilot in Azure OpenAI Studio
- Re-enroll Intune Devices Without a Wipe
- GPT Remediation creator
2023
- Easy and Effective App Management in Intune
- How Copilots Work: LLM Architecture, Grounding, and Intune
- Microsoft Defender for Endpoint: Setup and Best Practices
- Data Science with Microsoft Intune — Quick Start
- Detect new Intune Management Extension Updates
- How to Onboard Devices to Microsoft Defender for Endpoint
- GPT Intune Device Troubleshooter: AI-Powered Admin Help
- Intune Group Assignment Script: Find Policy and App Targets
- How to activate the uninstallation feature in the Company Portal
- Azure Monitor Agent to monitor Windows devices (1/2) – Setup
- Intune Driver Update Management — Quick Start
- Export Intune Data to OneLake for Power BI with Fabric
- Management of external devices (peripherals) with Intune
- V2 – Get a Daily Device Report via Email or Teams with Logic Apps (Step by Step)
- Mastering Intune Reporting and Analytics
- Tracking Windows 11 Upgrades with Azure Automation and Intune
- Building an Intune AI Voice Bot with Azure OpenAI
- Creating and Configuring Bash Scripts for Ubuntu Devices in Intune
- Automate Intune Tasks with Azure Automation Runbooks
- Intune Suite Part 3: Advanced Endpoint Analytics
- Intune Endpoint Privilege Management: Setup Guide
- How to Get a Report of All New Enrolled Devices
- Endpoint analytics remediation script community repository
- Intune Suite Part 1: Easy start with Remote Help
- How to use Custom Compliance Script + Example script
- Intune Wave Deployment: Create Smart Device Groups
- Automate Intune Tasks with PowerShell and Microsoft Graph
- How to Export Intune Assignment Errors with PowerShell
- Get Assignments of a Device via PowerShell
- Intune Scope Tags: Delegate Administration and Limit Visibility
- Easy way to analyse MDM Diagnostic data on the client
- Intune Quick Start Guide
- System Information and Self Service Tool
2022
- The new multiple administrative approvals (MAAs)
- Deploy Windows Store Apps via Intune
- Intune mass export with the Graph Report API
- How to setup Organizational messages
- Intune Device Inventory UI
- How to Enroll an Ubuntu Device in Intune
- Microsoft Intune Analytics: Reports, Endpoint Analytics & BI
- What is New in Microsoft Intune 2210
- Intune DevOps Pipeline: Move Objects from Dev to Prod Tenant
- Recap Ignite 2022 – New Intune related announcements
- Deep Dive into delivery optimization
- How to skip the ESP for a single app installation
- What is New in Microsoft Intune 2209
- Deep dive into the IME Health check
- Detect Connected Hardware with Intune Endpoint Analytics
- Show user dialog with Endpoint Analytics (Smartphone Replacement Tool)
- Enable Passwordless Authentication with Microsoft Authenticator
- How to Start Blogging about Microsoft Intune (MEM)
- Create and Fill an Entra ID Group based on Local Attributes
- Check Autopilot enrollment prerequisite
- Send Teams Alerts for Top 5 Intune App Install Errors
- Import Custom ADMX and ADML Templates into Intune
- Activate Mac FileVault using Intune
- Detect anomalies in your Intune environment with Azure Cognitive Services – Part 3 Bluesc...
- Change Windows 11 Context Menu with Intune
- Intune App Creator: Package Chocolatey Apps for Deployment
- Intune Device Troubleshooter: Inspect and Troubleshoot Devices
- Intune Management Extension Deep Dive: How IME Works
- Company Portal System Tray Icon: New Intune Features
- Detect Intune App Installation Anomalies with Azure AI
- macOS Custom Attributes in Intune: Collect Device Inventory
- Automate Intune App Assignment Groups with Azure Runbooks
- Use Endpoint Analytics to clean up the disk
- Set a Default Assignment Filter in Microsoft Intune
- Detect anomalies in your Intune environment with Azure Cognitive Services – Part 1...
- Build a Power BI Dashboard with the Intune Data Warehouse
- Sync Microsoft Entra ID Group with Kiosk Config Profile
- Intune Tool Box – Rebuild of Intune in PowerShell
- Applicability Rule: Gone but still there
- Convert Microsoft Entra ID User and Device Groups with PowerShell
- Copy Intune Discovered Apps in Log Analytics Workspace
- Daily Intune Device Reports via Logic Apps, Email & Teams
- Configuration of Windows Update reboot notifications
- Manage and Enroll macOS Devices with Microsoft Intune
- Update Quick Assist with Microsoft Intune
- List All Intune Assignments of an Entra ID Group
- Detect Slow Internet Breakouts with Endpoint Analytics
- Get Microsoft Intune Status Reports with PowerShell
- Clean up Windows 11: Hide task view, widgets and search with Intune
- Dive deeper into the IME log with a simple change of the log level
- Company Portal System Tray Icon
- Decode a Windows Autopilot Hardware Hash
- Create a Windows 11 Hyper-V VM: Step-by-Step Guide
- Add Trusted Publisher Certificates in Intune with PowerShell
- Delay Windows Update pending reboot with toast notification
- Log Toast Notification Responses in Azure Log Analytics
- Back Up and Restore Windows Registry Keys Safely
- Manage Local Windows Groups with Intune: Account Protection
2021
- Remove Windows 11 Built-in Teams App with Intune
- Install Windows 11 without TPM
- Microsoft Intune Users and Groups Management Guide
- Remove the Primary User from Intune Devices with PowerShell (Shared Device)
- Ultimate MEM Tour Part 4: Microsoft Intune Reporting
- Ultimate MEM Tour Part 3: Endpoint Security in Intune
- Add Microsoft Entra ID Users and Groups to Local Groups with Intune
- How to Restrict the Login to Dedicated Users with Intune – Part 1
- Group Windows 11 Devices with Intune
- Microsoft Intune App Management: Ultimate MEM Tour Part 2
- Ultimate MEM Tour Part 1: Microsoft Intune Devices
- Deploy the Web Company Portal with Microsoft Intune
- Map a Network Drive with Intune
- Create a Desktop Website Shortcut with Microsoft Intune
- How to Align the Windows 11 Taskbar Left with Intune
- Use assignment filter for the update ring assignment
- Enable Tab groups in MS Edge Chromium
- Microsoft Intune Policy Sets: Group and Assign Policies
- Set the Windows 10 background picture
- Deploy a Win32 App with Intune (Cmtrace)
- Set Up a Modern Windows Kiosk PC with Intune
- Get the Application User Model ID (AUMID)
- Duplicate Device Configuration Profiles
- Configure Device Categories in Microsoft Intune
- Set Up a Windows Autopilot Test Lab
- Microsoft Intune and AI Blog by Jannik Reinhard



