Showing posts with label Intune. Show all posts
Showing posts with label Intune. Show all posts

Monday, August 3, 2026

Bug or ?? : Intune EAM update silently drops supersedence

Update: 05/August/2026 - This issue is limited to our Tenant only and doesn't affect others.

I ran into a strange issue today and wanted to write it down. Partly to save someone else the trouble, and partly because I’m now pretty sure this is a bug and not just me clicking the wrong thing.

A bit of background first. The Enterprise App Management (EAM) side of Intune lets you deploy apps straight from Microsoft’s catalog. No more packaging or manual works. When a newer version comes out, Intune shows it in a report under Apps > Monitor > Enterprise App Catalog apps with updates. The idea is simple. You click the app, hit Update, and Intune creates the latest version as a new app that supersedes the old one. The old installs then move up to the new version.

That’s how it’s meant to work. Here’s what actually happened.

Following the normal steps:

I was testing this with Docker Desktop (x64). I had deployed it as an EAM catalog app, and a newer version (4.78.0.229452) showed up in the report, just like it should.


I clicked on the app. On the overview page there’s an Update button at the top. One thing I noticed here: Intune shows a small warning that says “This app can update itself. App updates will come directly from the publisher…” Docker is one of those apps that can update on its own. Its Update Method was even listed as Auto-update. Keep that in mind, because it’s why I doubted myself at first.


Clicking Update opens the Supersede with latest app wizard. This part looks completely fine while you’re going through it:

1. You go through App information, Program, Requirements, Detection rules, and Scope tags. All good.

2. You reach the Supersedence step. Intune has already added the old Docker Desktop app under “Apps that this app will supersede.”

3. The Uninstall previous version toggle is set to No by default. That means update in place instead of replacing. Which is what you want for a version update.

4. You click Next, reach the review screen, and the supersedence is right there in the summary before you save.





Every screen tells you the same thing. This new app will supersede the old one. So you save it.

And then it’s gone.


This is where it breaks. After the new app is created, I opened its Supersedence tab, expecting to see the old Docker Desktop app listed.

It wasn’t there. The list was empty. The relationship the wizard showed me twice, once on the supersedence step and once on the review page, just didn’t save.

I thought maybe it was a display glitch, so I opened the Relationship viewer on both apps to check. Nothing there either. The new app shows no link to the old one, and the old app shows no link to the new one. After saving, Intune treats them as two completely separate apps.

So the supersedence you set up during the update is accepted, shown to you, and then dropped on save. No warning, no error.

Why this matters?

If you don’t catch it, this is a real problem. The whole point of the Update button is to build an update chain so devices with the old version move to the new one. No supersedence link means no chain. Your existing installs never learn there’s a newer version, and you end up with two separate apps instead of a proper update path. The report says the update is done, but nothing is actually superseding anything on the devices.

The tricky part is that it looks like it worked. You only find out by going back into the new app and checking the Supersedence tab yourself, which most people won’t do after the wizard just told them everything was set.

At first I blamed the self-updating app.

With Docker, I wasn’t sure. Its Update Method was set to Auto-update, and there was that warning saying the app updates itself. So my first thought was that Intune drops the supersedence on purpose because a self-updating app doesn’t “need” it. That would have been annoying but at least it would make some sense.

So I tested a second app to rule that out.

I picked Notepad++ (x64), version 8.6.9. This one is different in every way that matters here. Its Update Method is set to Supersedence, not Auto-update. It doesn’t self-update. The warning on its page is just the plain “A newer version of this app is available in the Enterprise App Catalog.” No self-update note at all.

I ran the exact same Update flow. Same result. The wizard added the old version, showed it on the review screen, let me save, and then the new app came out with an empty Supersedence tab. The Relationship viewer showed no link between the two, same as Docker.

That settles it for me. This isn’t about self-updating apps. A normal catalog app, set to supersede, still loses its supersedence on save. It’s a bug in the update flow itself.

What I’m doing about it:

For now the workaround is boring but it works. After you run the Update flow, go back into the new app, open the Supersedence tab, and add the old version by hand if it’s missing. Then check the Relationship viewer to make sure it stuck before you assign anything. Don’t trust the wizard’s word for it.

I’ve already raised a bug post in the Microsoft Management Advisors Teams channel program and also a support ticket, and I’m waiting on confirmation of the bug and the next steps. I’ll update this post once I hear back. If you’ve seen the same thing on your own EAM catalog apps, I’d love to know. Two apps that were completely different, one auto-updating and one set to supersede, both dropped the relationship the same way. So I doubt it’s just me.

Until then, check your Supersedence tab after every EAM update.

Thursday, October 3, 2024

50th Blog Post and Windows 11 24H2 images available in Windows 365 CPC in Intune

Hola! Celebrating My 50th Blog of the Year πŸ’₯πŸŽ‰πŸ₯‚

Hola, everyone! I’m thrilled to announce that this is my 50th blog post of the year, and it’s been an amazing journey contributing to the Windows 365 community. Your support and engagement have made this milestone possible, and I’m excited to keep delivering insights and updates to help you navigate the world of Windows 365 and Microsoft Intune. This year, I have achieved the below awards for my contributions towards the community and the Microsoft Management Customer Connection Program MCCPπŸ₯‡πŸ₯ˆπŸ₯‰ 

So, without further ado, let’s dive into today’s topic!

The Latest Windows 11 24H2 version that has been announced recently are available in the Windows 365 offerings in the Windows 365 Intune blade.

Optimized images missing?

Microsoft has recently retired the optimized images that we had delved in our earlier post. If you don't require M365 apps as pre-installed, then you can make use of the available Windows 11 Enterprise images that are shown in above picture.

Saturday, August 17, 2024

Intune & macOS: .app .pkg .dmg file is blocked by Gatekeeper

Understanding Gatekeeper in macOS and How to Bypass Its Prompts

Gatekeeper is a security feature in macOS designed to protect your system from untrusted software by verifying the source of apps, PKG, and DMG files. When you try to open a file from an unverified source, macOS may show a Gatekeeper prompt, even if the file is legitimate.

What is Gatekeeper?

Gatekeeper controls what software can be installed on your Mac, ensuring that apps are from the App Store or identified developers. It checks for a digital signature to verify that the app hasn’t been tampered with and is safe to run.




How to Resolve Gatekeeper Prompts:

If you encounter a Gatekeeper prompt despite the file being genuine, you can bypass it by checking and removing the quarantine attribute, which Gatekeeper uses to track downloaded files.

1. Check for Quarantine Attribute:
   Run the following command in Terminal to see if the file is quarantined:

xattr /path/to/App.dmg

2. Remove the Quarantine Attribute:
   If the quarantine attribute (`com.apple.quarantine`) is present, remove it by running:

xattr -dr com.apple.quarantine /path/to/App.dmg
   
   
This command removes the quarantine attribute from the file, allowing it to open without Gatekeeper blocking it.

Applying This Solution to .app, .pkg, and .dmg Files

The same process can be applied to any app, PKG, or DMG file. Simply replace the file path in the commands with the appropriate file's path on your system. This method helps bypass Gatekeeper's restrictions when you know the file is safe but still encounter warnings.

Wednesday, August 14, 2024

Intune & macOS - Comparison between macOS Line Of Business LOB PKG vs Non-managed PKG

Here's a comprehensive comparison between the requirements for deploying PKG as Line of Business LOB apps or Unmanaged macOS PKG apps.

Feature/Requirement Unmanaged macOS PKG Line of Business PKG Apps 
Non-flat Packages Supported: Hierarchical structure, typically a directory with package components inside Supported
Component Packages Supported: Allows multiple independent components to be installed separately Supported: Component package or package containing multiple packages
Unsigned Packages Supported Not Supported (must be signed with "Developer ID Installer" certificate)
Packages Without a Payload Supported Not Supported (must contain a payload). without payload, re-install will happen in loop till the app is unassigned from the group
Packages Installing Outside `/Applications/` Supported Not Supported
Custom Packages with Scripts Supported Supported
Contain Bundles, Disk Images, or `.app` Files Supported Not Supported
Signing Requirement None Must be signed with a "Developer ID Installer" certificate

Saturday, July 6, 2024

Intune & macOS management - Couldn't add your device. Your IT support doesn't allow OSX devices to be added to management

After creating Apple MDM push certificate in Intune portal and while testing in the macOS device, after you install the company portal and login and try to enrol, the app shows error as 

"Couldn't add your device.

Your IT support doesn't allow OSX devices to be added to management." 


First step is to check in Intune portal - devices - enrollment - monitor - enrollment failure for any entry for the affected user.


In this scenario, the issue was due to the device type restrictions that was blocking the macOS devices.

Solution:

Open intune portal -  Devices - Enrollment - click Apple.

Select device platform restrictions and switch to MacOS restrictions tab.

Your administrator would have created a device restriction to block the enrollment of MacOS earlier. If there are multiple restrictions created for devices open one by one and make sure the macOS platform is allowed for enrollment. 

When you edit the restrictions and go to the properties and under platform settings, you can find out whether the macOS devices are allowed to enroll or if they are blocked.

Tuesday, June 11, 2024

Intune - Linux Intune app shows Something went wrong [1001] while registering

 login in Intune app in Ubuntu 22.04 and click Register shows an error after a while "Something went wrong. [1001]"

Image
Run below command in terminal and reproduce the issue on the device again.

journalctl --user -f -u microsoft-identity-broker. service

Found the below error in the logs -

Jul 02 12:39:37 microsoft-identity-broker[2719976]: Caused by: com.microsoft.identity.broker4j.workplacejoin.exception.DrsErrorResponseException: {"code":"invalid_request","subcode":"error_directory_quota_exceeded","message":"User 'aef5db22-07a6-40ee-9f7e-20' is not eligible to enroll a device of type 'Linux'. Reason 'DeviceCapReached'.","operation":"DeviceJoin","requestid":"08e0c4a1-e0d4-4a1f-bad9-101f3549aba6"}

From the logs, we can see that this user is not eligible to enrol his device because the maximum limit to register devices has already reached.

Remove any stale devices for the end user in Intune portal and retry registration again.