Microsoft

Microsoft Endpoint Configuration Manager Feedback

Suggestion box powered by UserVoice - Update: Microsoft will be moving away from UserVoice sites on a product-by-product basis throughout the 2021 calendar year. We will leverage 1st party solutions for customer feedback. Learn more

Ideas

What features would you like to see?

All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Configuration Manager, though we canā€™t promise to reply to all posts.

Please do not use UserVoice to report product bugs or for assisted support.
If you believe you have found a product bug, please send us a bug report through the Configuration Manager Console (1806 and newer). To do this, press the šŸ™‚ button in the top right corner and choose ā€œSend a Frownā€. For more details, see https://docs.microsoft.com/en-us/sccm/core/understand/find-help.

If you require assisted support, please see https://aka.ms/cmcbsupport for more details.

Standard Disclaimer ā€“ our lawyers made us put this here ;-)
We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Microsoft Endpoint Configuration Manager feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Configuration Manager. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.


  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Allow Compliance Settings to to disabled

    Unlike Applications you cannot disable a compliance setting. Currently I have to change there name and add "Disabled" in the front so when they show on the baseline list people know that they are currently not in production.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  2. Add the hability to deploy 'Data and User Profiles' to Computers Collections

    Hello,

    Data and Users Profiles are good to get rid of the equivalent GPO settings. However, they lack the possibility to be deployed to Computers Collections.

    Offline Folders for instance can be set as 'Computer setting' with GPO and you can't do the equivalent with SCCM as you can only deploy to 'Users Collections'.

    Best regards,
    Michael De Bona

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  3. Configuration Baselines only create QWORDs

    Right now if you use HKCU and try to create a DWORD value that does NOT exist, even though you set remediation up properly and select the box that says to create the value as a REG_DWORD, it still does not create the entry at all and the baseline reads as compliant. The creation of DWORD values using baselines has been a common post on forums for many years.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  4. Deploy Application via Baseline Compliance

    Right now you can deploy a base line to see if system have all the require local apps. Would be nice if you allow the system to have remediation for the missing application, that is specify by the company. As of now the only thing you can have baseline auto fix is Registry value & Script (by running remediation script) & WQL Query. If it could auto and manually fix application that would be outstanding. I would allow it in these two ways, if the system detects it missing an app it auto deploys that package ID to itself (Checkā€¦

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  5. Certificate Profiles for Servers

    We have some workgroup servers which are unable to access the enterprise CA so we want to deploy some root CA certificates to them per sccm.
    Currently it is only possible to select client OSE's on the supported plattform page. Please allow server OSE's as well.
    Thanks

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  6. Allow all Compliance Settings to work on Co-Managed Devices

    Right now Configuration Baselines have the option "Always apply this baseline even for co-managed clients". This is great as our journey to Modern Management and Intune will likely take several years and our investment in on-prem ConfigMgr is significant.

    It would be very useful if this option could apply to other Compliance Settings which cannot be added to a baseline. One example is Company Resource Access -> Wi-Fi Profiles. Right now, co-managed devices will ignore Wi-Fi profiles deployed to them. This is limiting for those of us still getting started with Intune and Modern Management.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  7. transcript

    I would like to turn off powershell transcripting in configuration item. If I run PS script in user mode (means "Run scripts by using the logged on user credentials" is enabled.) then it creates a folder under user's mydocuments folder. It is very annoying.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  8. Run program from a package as a remediation step.

    Today you have to ability to run JScript, Windows PowerShell or VBscript scripts to remediate condition on Clients in ConfigMgr. But sometimes runing a program from a package would also be a very useful. Example, run a reboot program like the Cortech Shutdown tool if computer/server is non-compliant.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  9. L2TP VPN - Allow psk to be added

    Currently there is no option to add a psk to an L2TP VPN when deploying a VPN Profile from Config Manager VPN Profile Wizard. This would be good to have so that it is a one-stop solution, rather than having to continue using CMAK or (as our client wants to do) forcing a powershell script to work. This missing option is the only thing stopping us using the built in tools.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  10. Import/use ADMX to create Compliance Settings

    Import or use ADMX Files to create compliance settings/items and us SCCM to deploy these Settings instead of active directory gpo

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  11. Custom Client settings for Compliance Scheduling

    There is no option currently to create a custom client settings for Compliance Scheduling for specific Compliance Baseline deployment.

    It would be great if we get an option.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  12. Enable reboot messages for configration baseline remediations

    Some configuration items require a reboot (such as disabling a windows optional feature) before they fully take affect. Currently, there is no way to prompt the end user to reboot their computer or notify them that a reboot is necessary. Furthermore, there is no way to manage the reboot in any way through Endpoint Manager Configuration Console.

    The only way to ensure a reboot happens as a configuration remediation script runs is to include a "restart-computer" powershell cmdlet or a "shudown.exe /r /t" command.

    There should be a way to leverage Configuration Manager's built in reboot handling and messaging. Iā€¦

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  13. Populate OS versions for "Valid operating system builds" in compliance policies

    In the new condition "Valid operating system build" added to Windows 10 (w/o CM) compliance policies it would be very useful to have a drop down with build version numbers translated to meaningful names. Otherwise we have to go external and find a version list. Even better if it could be pulled from the CM DB for existing versions in the same way you can with collection queries.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    1 comment  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  14. Support Enabling Credential Guard via Compliance Settings

    Need to be able to enable/configure Credential Guard via Compliance Settings with per-collection deployments. Need to get compliance data reported back.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  15. Expose Windows Defender Configuration (Specifically Exploit Guard) as a CI Baseline

    I believe the Windows Defender Configurations and specifically the Exploit Guard configuration settings are evaluated very similarly to a configuration baseline. It would be awesome if we could see this under the Configurations Tab in the Config Manager client so we can see revision information + force re-evaluation.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  16. Use Configuration Item Results in SCCM

    I would like to be able to use the results of a configuration item to create collections.

    An example would be I have a CI that collects the value of a registry key on computers. I am returning the value of that reg key. I would like to be able to create collections based on the value of the reg key result I had returned.

    If I have it return the string ā€œ1234ā€. I want create a collection based off of computers that return 1234.

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  17. Non Compliance - Get Actual Value

    Hello,

    Can you add on the "Non-Compliant" tab the column "Actual Value"
    Because actually we need to click on each device to know this actual value ...

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    3 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  18. Add Applications to compliance baselines

    I'd like to be able to report on compliance for Tier 1 apps using the same mechanism I use for other compliance settings. It would be a nice convenient way of showing Tier 1 apps coverage in a single report

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  19. Apply CI/Baseline as an action on a failed compliance policy

    In tech-preview 1606 an awesome feature has been added that let's you take an action on a compliance policy if it is not met.

    What would be awesome would be the ability to apply a configuration item/baseline on the non compliant device.

    E.g. If an intune device such as iOS has a malicious threat installed (combined with the compliance setting maximum threat level an action to remediate the threat by applying a configuration item that completely locks down that device)

    See Suzanne Grant (Intune MSFT) for full scenario. Great work guys!

    3 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  20. List all CIs in a category regardless of folder

    We use folders to organize Configuration Items (Applications, Task Sequences, etc.) however there is no place to view all the CIs in a category. You have to click on each individual folder to view those CIs. For example, it would be nice to select Applications and see all of your Apps listed there instead of having to select each folder to view Status or check for duplicates. Each folder should do the same for its sub-folders. Having a column that shows which folder/sub-folder the CI is in would be helpful as well.

    2 votes
    Vote

    We're glad you're here

    Please sign in to leave feedback

    Signed in as (Sign out)
    You have left! (?) (thinkingā€¦)
    Noted  ·  0 comments  ·  Compliance and settings  ·  Flag idea as inappropriateā€¦  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base