Endpoint Management, Intune-Managed Windows, Standard Configuration

Summary

This article describes the standard configuration for Windows devices managed with Microsoft Intune, including the baseline application set and how to verify that a deployed computer matches the expected state.

Body

Search Criteria

Use or adapt these terms in the KB’s search/keyword settings:

  • Intune standard build
  • Intune baseline configuration
  • Windows device configuration
  • managed apps
  • required applications
  • available applications
  • required uninstall

Symptoms / Problem Statement

Use this article when:

  • You need to verify whether a Windows computer deployed through Intune is in its expected “standard” state.
  • You are troubleshooting a device that is missing required software or still has unsupported software installed.
  • You are documenting or reviewing the configuration of managed Windows endpoints.

Environment

  • Platform: Windows 11
  • Management: Microsoft Intune / Endpoint Manager
  • Scope: University-owned devices assigned to Intune device groups for standard faculty/staff (and/or student) deployments
  • Audience: IT staff and support personnel who can view devices in the Intune admin center or assist users with Company Portal

Prerequisites

Before you start:

  • The device is enrolled in Intune and shows in the Windows devices list.
  • You have sufficient permissions in the Intune admin center to view device properties and managed apps (for IT staff), or you can sign into Company Portal on the device.
  • The device has a network connection so it can check in with Intune.
  • You know which user or device name you are working with.

Configuration

Note: To review a specific device from the user’s perspective, use the Company Portal app on that device. This section describes what should appear there.

1. Standard configuration items

The tables below describe the standard application configuration for Intune-managed Windows devices.

1.1 Required applications (installed automatically)

These apps are required and should normally show as Installed.

Required applications
Application Resolved intent Expected purpose / notes
M365 Apps for Enterprise x64 Required install Microsoft 365 desktop apps (Word, Excel, PowerPoint, etc.).
Remote Help Required install Remote assistance tool used by IT support.
Chrome x64 Required install Supported web browser alongside Microsoft Edge.
Company Portal Required install Self-service app catalog and device management portal.
Secure Client AnyConnect VPN Required install VPN client for secure remote access to campus resources.
Firefox x64 Required install Additional browser for compatibility and testing.
Box Drive Required install Desktop client for Box cloud storage.
Falcon – Community Required install Endpoint security / EDR client.
Zoom Workplace Required install Standard video conferencing and collaboration client.

1.2 Available applications (optional via Company Portal)

These apps are offered as Available. They are not installed automatically, but users can install them from the Company Portal.

Available applications
Application Resolved intent Expected purpose / notes
7-Zip Available File compression and archiving utility.
Acrobat DC Unified Available Adobe Acrobat DC for advanced PDF editing.
Bitwarden Available Password manager for secure credentials.

1.3 Applications marked for removal

These apps must not remain on managed devices. Intune is configured to uninstall them when present.

Applications marked for removal
Application Resolved intent Rationale / notes
Microsoft Copilot (Personal) Required uninstall Consumer/personal version not supported on managed PCs.
Microsoft Teams (Personal) Required uninstall Personal Teams client not supported; avoids confusion with work/school Teams.

2. Verify a device against the standard

Use the Company Portal app on the Windows 11 device:

  1. Open the Start menu, search for Company Portal, and launch it.
  2. Sign in with your University credentials if prompted.
  3. In Company Portal, select Downloads & updates.
  4. In the list of apps, confirm that all required applications listed in section 1.1 appear and show as Installed (or a similar status indicating they are installed).
  5. Optionally, confirm that apps listed as Available in section 1.2 are visible as install options.
  6. If a required application is missing or does not show as installed, contact your IT support team or follow local instructions to request assistance.

Troubleshooting

Use the steps below when a device does not match the standard configuration.

A required app is not installed

  • Instruct the user to open Company Portal, go to Downloads & updates, and check for pending installs or updates for that app.
  • If the app is not listed, IT staff can verify assignments in the Intune admin center to confirm the device or user is in the correct target group.
  • IT staff may also review the app’s installation status and error details in Intune and take action as needed (for example, repair or reinstall).

An app marked for required uninstall is still present

  • Have the user restart the device and confirm that all pending updates in Company Portal have completed.
  • IT staff can confirm in Intune that the app has a Resolved intent of Required uninstall and that the assignment applies to this device.
  • If the app remains installed, IT staff may need to uninstall it manually and then re-check the device in Intune.

The device does not appear in Intune or shows as not compliant

  • Confirm that the device is Azure AD / Entra ID joined and enrolled in Intune.
  • Check that the device is assigned to the correct group for this standard configuration.
  • If enrollment failed or compliance remains in error, follow your local Intune enrollment troubleshooting guide or contact your IT support team.

Keywords

Intune Windows 11 device standard configuration baseline managed apps required install available apps uninstall VPN Box Drive Zoom Falcon Bitwarden Acrobat 7-Zip Chrome Firefox Microsoft 365

Details

Details

Article ID: 3019
Created
Fri 12/5/25 3:25 PM
Modified
Fri 12/5/25 3:27 PM