FR EN
portal
One Place for IT Services, Knowledge and Support
IT Wiki · Intune / M365
Welcome to Ainos

Get started

Secure your account
Install Microsoft Authenticator and register your sign-in methods (MFA). This is what protects your account. → Security info · MFA
Set up your phone
Choose the option that suits you: BYOD (apps only, simplest) or full enrollment via Company Portal. → BYOD (MAM) · Company Portal
Set up your PC (laptop)
Your work PC is provisioned via Windows Autopilot and managed by Intune: sign in with your Ainos account and everything sets up automatically. → New PC
Access your email and files
Install Outlook for your email and discover OneDrive and Teams for collaboration. → Outlook mobile · OneDrive · Teams

Browse by topic

My phone

Connect your personal or work device securely.

My email

Outlook, shared mailbox and best practices.

Collaborate

Files, meetings and teamwork.

Security

Passwords, MFA and spotting scams.

🔎
TipUse the search bar at the top left to find an answer in seconds — try typing "PIN", "travel", "reset password"…
🔗 Quick access
Ainos IT Wiki · Intune & Microsoft 365Got a question? Contact IT support.
🖥️Understanding how my PC is managed

From the moment it's provisioned, your Ainos PC is registered in Windows Autopilot and then continuously managed by Microsoft Intune: security, updates, apps and compliance are all driven remotely by IT for the device's entire lifecycle. First-time setup is covered on I have a new device; the details of updates and compliance are on Updates & compliance.

⚙️ Managed by IT, silently

Encryption, antivirus, firewall, security updates, compliance: it all applies itself, with no action needed from you. → Details

🙋 What's still on you

Reasonable everyday use, restarting when an update asks for it, and taking care of the physical hardware (see below).

Every Ainos PC has a local administrator account whose password is generated and rotated automatically by Windows LAPS (Local Admin Password Solution), then stored securely in Intune. Nobody needs to remember it: if a technical intervention requires it, only IT can retrieve it, in a fully traceable way.

ℹ️
No need for admin rights day-to-dayWork applications install through Company Portal. If a specific install genuinely requires elevated rights, contact IT rather than looking for the local password.
🏪Company Portal on PC

The Company Portal app (already installed) isn't just for phones: on PC, it acts as a dashboard for your device.

✅

Compliance status

The Devices tab shows whether your PC is marked Compliant or Not compliant, and why.

🧩

Self-service apps

The Apps tab lists work software you can install without admin rights.

🎧

Support tied to your device

Contacting IT from the app automatically links your request to this specific PC.

⚠️
PC marked "Not compliant"Contact IT quickly: beyond a certain grace period, access to some work resources can be reduced via Conditional access.
🛡️Damage, loss or theft
Never try to repair it yourself
Opening the device or attempting a repair yourself can make things worse and voids any support coverage.
Stop using it if there's a hazard
A swollen battery, a cracked screen that's leaking, a burning smell, or abnormal overheating: power it off and report it immediately.
Report the damage to IT
Via the "Other request" form on the Self-Service Portal, or Contact IT support, describing precisely what happened.
🚨
Notify IT without delayEvery minute counts: the sooner IT knows, the sooner access tied to this device can be revoked (active sessions, sign-in tokens) via Intune and Entra ID.
Contact IT immediately
Contact IT support — specify that it's a loss or theft, with the circumstances.
Change your Ainos password
From another device, as soon as possible, even if the stolen PC was protected by a lock screen.
A report may be requested
For internal procedures or a theft report, depending on the circumstances.

🔒 Your data stays protected

The drive is encrypted with BitLocker: without your credentials, its contents are unreadable to whoever finds or steals the device. Reporting it quickly is still essential to cut off online access.

🎒 Transport

Use a padded sleeve or bag, even for a short trip. Never in an unprotected hold or stacked under other objects.

🌡️ Environment

Avoid direct heat, humidity, and placing a glass or bottle near the keyboard.

🔋 Power

Use the original or a certified charger. Avoid repeated full battery discharges.

🧽 Cleaning

Power off the device before cleaning it, using a dry or microfiber cloth — never spray any product directly onto it.

Laptop · Ainos IT WikiNot sure about your device? Contact IT support.
Full MDM enrollment: an isolated corporate container (Office apps, Wi-Fi/VPN, email) kept separate from personal data, synced with the company's Intune cloud
Full enrollment (MDM) creates a managed work space on the device, walled off from your personal data.
🚀Getting started
📶

Wi-Fi connection

Stable network required throughout the procedure.

🔋

Battery > 50%

Avoids interruption during MDM installation.

🔑

Microsoft 365 account

@domain.lu address + MFA configured.

🚫

No jailbreak

Modified devices are blocked by Intune policy.

ℹ️
Intune license requiredIncluded in Microsoft 365 Business Premium, EMS E3/E5. Without an active license, enrollment fails with error 401.

⚠️ A prior request to Ainos IT is required before any enrollment. Once the request is approved, the device will be managed by Ainos IT (security policies, updates, access to organizational resources).

The enrollment method depends on the device type. This page (Company Portal) mainly covers mobile devices; work Windows PCs are pre-configured via Windows Autopilot.

DeviceMethodWhat you do
Work Windows PCAutopilot + Intune (auto)You sign in with your Ainos account: everything configures itself. → New PC
iPhone / iPadCompany Portal (MDM/BYOD)Install Company Portal and follow the wizard (below).
AndroidCompany Portal (MDM/BYOD)Install Company Portal and follow the wizard (below).
Personal phone (work apps)BYOD (MAM)Just the protected apps, without managing the phone. → BYOD
🪟
Windows PC: nothing to installNo need for Company Portal to enroll a work Windows PC: it's pre-registered in Autopilot and managed by Intune from the first sign-in. The procedure below covers mobile devices.

📱Enrollment by platform

The procedure is nearly identical on both systems. Select the tab matching your phone to display only the steps relevant to you.

Enrolling an iPhone or iPad in Microsoft Intune via the Company Portal app. First: install Intune Company Portal from the App Store, open the app, sign in with your prenom.nom@ainos.lu account, and approve MFA. Then follow the wizard.

📥
Prerequisite — install the appDownload Intune Company Portal (publisher Microsoft Corporation) from the App Store, then open the app.
iPhone / iPad
Open the App Store ↗
Intune Company Portal Microsoft Corporation ★ 4,0   ·   4+   ·   N°7 Business
"Intune Company Portal" (Microsoft Corporation) listing on the App Store.
Open the app and tap "Sign in"
Launch Company Portal then tap Sign in to start signing in.
Company Portal Get access to company resources and keep them secure. Sign in
Home screen: tap "Sign in".
Sign in with your work account
Enter your work address prenom.nom@ainos.lu, tap Next, then enter your password and approve MFA (approval in Microsoft Authenticator).
Microsoft Intune Microsoft Sign in prenom.nom@ainos.lu Can't access your account? Next Sign-in options
Enter the work address, then "Next".
Allow notifications
The app requests permission to send notifications (compliance-related alerts). Tap Allow, then Ok.
Get notified so you don'tlose accessWe'll send important notifications to yourdevice when action is needed so you cankeep accessing work resources.You can turn this off later in app settings.Ok
Allow notifications, then tap “Ok”.
Start setup
Work access setup screen: tap Begin.
Set up Ainos accessSet up your device to access your email, devices, Wi-Fi, and apps.Review privacy informationDownload management profileInstall management profileChecking device settingsBegin
"Set up access" screen: tap "Begin".
Read the privacy information
Overview of what the organization can and can't see on the device. The Can't tab lists what stays private (browsing history, personal emails and documents, passwords, photos, location of a personal device). Tap Continue.
Device management andyour privacyHere is what Ainos can and cannot see onyour device.Can'tCanView browsing history on this deviceSee your personal emails, documents,contacts, or calendarAccess your passwordsView, edit or delete your photosSee the location of a personal deviceContinue
Privacy: the "Can't" tab details what IT can't see → "Continue".
Start preparation
The "Review privacy information" step is complete. Tap Continue to download the profile.
Set up Ainos accessSet up your device to access your email, devices, Wi-Fi, and apps.Review privacy informationDownload management profileInstall management profileChecking device settingsContinue
Privacy step complete — "Continue".
Download the management profile
At the browser prompt, tap Allow to authorize the profile download.
Downloading the management profile — tap
Allow downloading the management profile.
Profile downloaded
The profile is downloaded. Tap Close: it will need to be installed manually from Settings.
Profile downloaded — tap
“Profile Downloaded” → tap “Close”.
Open the Settings app
Company Portal shows the procedure to follow: open the iPhone's Settings app.
9:41Comp PortalSettings
Home screen: tap the "Settings" icon.
Tap "Profile Downloaded"
At the top of Settings, tap the search field for "Profile Downloaded".
iOS Settings — tap
Settings → "Profile Downloaded".
Install the profile
On the "Install Profile" screen, tap Install (top right).
Settings → "Install Profile" → "Install".
Enter the device passcode
Enter the device's unlock code, then tap Done.
Enter passcode123456789
Enter the device passcode, then tap “Done”.
Confirm installation
Confirm by tapping Install again.
\
Confirmer l'installation du profil.
Trust remote management
A warning lists the root certificate and remote management (MDM). Tap Install, then Trust.
Warning: root certificate + remote management —
Trust remote management —
Root certificate + remote management: "Install" then "Trust".
Profile installed
The "Profile Installed" screen confirms installation. Tap Done.
Profile installed — tap
“Profile Installed”: tap “Done”.
Finish in Company Portal
Go back to Company Portal and tap Continue: the app checks the device's compliance ("Checking device settings"). Enrollment is complete.
Back in Company Portal — tap “Continue”
Back in Company Portal → "Continue" → compliance check.
Setup complete
The "You're all set!" screen confirms the device has access to work resources. Tap Done.
“You're all set!” → tap “Done”.
Set a lock code
To stay compliant, the device may require an unlock code. Tap Change Now and set a code (at least 6 digits).
9:41 Comp Portal Outlook Settings Passcode Requirement You must set an iPhone unlock passcode within 59 minutes. Later Change Now
"Passcode Requirement" → "Change Now".
Install work apps
The organization can automatically deploy apps (Outlook, Teams…). At the "App Installation" prompt, tap Install.
9:41 Comp Portal Settings App Installation Ainos is about to install and manage "Microsoft Outlook" from the App Store. Cancel Install
"App Installation" → "Install" (apps deployed by IT).
Open Microsoft Defender to finalize compliance
Once the apps are deployed, open the Microsoft Defender app (automatically installed by IT) and let it finish initializing. It's this first launch that reports the device's security status to Intune: as long as Defender has never been opened, the device may appear non-compliant. When the screen shows "Device Secure", compliance is OK.
Microsoft Defender 10:28 Device Secure 0 threats found Update Status: Automatic Security Status App Security 48 Apps scanned in the last 24 hours No threats found Dashboard App Security Web Protection Tunnel
Microsoft Defender → "Device Secure": the device is compliant.

Enrolling an Android device in Microsoft Intune via Company Portal (Android Enterprise — work profile). Compatible with Android 8.0+. Sign in with your prenom.nom@ainos.lu account.

📥
Prerequisite — install the appDownload Intune Company Portal (publisher Microsoft Corporation) from the Google Play Store, then open the app.
Install Company Portal
On the Google Play Store, search for Intune Company Portal (publisher Microsoft Corporation) and tap Install.
13:35Google PlayIntune CompanyPortalMicrosoft Corporation3,5 ★86 k avis10 M+DownloadsPEGI 3AgeInstall
Google Play → "Install".
Start setup
On the "Set up your device to get access" screen, tap Continue.
Set up your device to getaccessAinos requires you to secure thisdevice before you can access Ainosemail, files and data.More detailsContinueIf you have forgotten your password orusername, contact helpdesk@ainos.luTerms of use Privacy & cookies …
« Set up your device to get access » → Continue.
Get the app
If prompted, tap Go to Google Play to install the Company Portal app.
To enroll your device, install the free MicrosoftIntune Company Portal app.Go to Google PlayOpen withGoogle Play servicesChrome
Prompt: “Go to Google Play”.
Page de l'application
Fiche Google Play d'Intune Company Portal (Microsoft Corporation).
Google PlayIntune CompanyPortalMicrosoft Corporation3,5★86 k avis10 M+DownloadsPEGI 3ⓘInstallAbout this appGet access to your organization’s resources andkeep them secure.# 6 top apps in business
Fiche Google Play de l'application.
Open the app and tap “Sign in”
Launch Company Portal and tap Sign in.
Company PortalGet access to company resourcesand keep them secure.SIGN IN
Home screen → "Sign in".
Enter your work address
Enter your address prenom.nom@ainos.lu, then Next.
Company PortalMicrosoft IntuneMicrosoftSign inEmail or phoneCan’t access your account?NextSign-in options
Enter the address, then “Next”.
Enter your password
Enter your password, then Sign in.
Enter passwordPasswordForgot my passwordSign in
Password → “Sign in”.
Approve the MFA prompt
Approve the sign-in request in Microsoft Authenticator.
Approve sign in requestOpen your Microsoft Authenticator app andapprove the request to sign in.I can’t use my Microsoft Authenticator app right nowIf you have forgotten your password orusername, contact helpdesk@ainos.lu
Approve the sign-in in Authenticator.
Start access setup
The wizard lists the steps: create the work profile, activate it, adjust settings.
Ainos Access SetupLet’s set up your device to access your email,Wi-Fi, and apps for work. You’ll also be able tomanage your devices.1Create work profile2Activate work profile3Update device settings
"Access Setup": profile, activation, settings.
Privacy
Overview of what the organization can and can't see. Tap Continue.
While setting up your device, you will see some Androidsystem screens requesting permissions to help yourcompany secure your device.Ainos can never see:· Call and Web history· Location· Email and text messages· Contacts· Passwords· Calendar· Camera roll· Personal appsAinos may see:· Model· Serial number· Operating system· Work apps· Owner· Device name· Manufacturer· Phone number for corporate devicesMore about privacyCONTINUE
Ce que l'organisation peut / ne peut pas voir → Continue.
Create the work profile
The "Set up a work profile" screen creates a separate, managed space. Tap Agree.
Set up a work profileYour work profile will be managedand monitored by your organization.Check our Ainos Mobile Device PrivacyPolicy to see how we manage your data.Agree
« Set up a work profile » → Agree.
Creating the profile
The work profile is being created — please wait a moment.
14:18CreatingWork profile…Work app icons are marked witha badge so you can tell themapart from your personal apps.
« Creating work profile… ».
Activate the work profile
The wizard activates the work profile (“Activate work profile”).
Ainos Access SetupLet’s set up your device to access your email,Wi-Fi, and apps for work. You’ll also be able tomanage your devices.Create work profile2Activate work profile3Update device settings
Activation du profil professionnel.
Adding the device
The device is added to Company Portal and synced.
Adding your device to Company Portal…
Adding the device to Company Portal.
Update required settings
If settings are requested (e.g. unlock code), tap Resolve and fix them.
Update device settingsAinos needs you to adjust thesesettings to finish setting up your device. TapCONTINUE to recheck these settings.Set a longer device passwordA device password must be at least 6 characterslong.RESOLVECheck device settings againYou need to change some settings to maintainaccess to company resources.
“Update device settings”: fix the required items.
Steps complete
All three steps (profile created, activated, settings) are complete.
Ainos Access SetupLet’s set up your device to access your email,Wi-Fi, and apps for work. You’ll also be able tomanage your devices.Create work profileActivate work profile3Update device settings
Setup steps complete.
Setup complete
"You're all set": the device has access to work resources.
You’re all set!You should have access to your email, Wi-Fi, andapps for work within a couple of minutes.Create work profileActivate work profileUpdate device settings
« You're all set ».
Your new workspace
Overview of the work space: managed apps and the briefcase badge.
Your new work setupSeparate apps for workTo ensure privacy, your work andpersonal apps have been separated.Look for the briefcaseWhen you need to use an app for work,use the version with a work badge.Get more apps for workFind available work apps in the workversion of the Google Play Store.Learn more about your new work setupGOT IT
« Your new work setup ».
Install work apps
The organization can deploy apps (Outlook, Teams…). Accept the installation.
DEVICESSUPPORTAinos_AndroidForWork_2025…Open the badged version of GooglePlay to get apps suggested by Ainos.DISMISSOPEN
Deploying work apps.
Work apps
Work apps (Company Portal, Outlook…) appear with a briefcase badge on the home screen.
13:42SearchCompanyPortalContactsMy FilesPlay StorePersonalSAMSUNG Knox
Work apps badged on the home screen.
Open Microsoft Defender to finalize compliance
Once the apps are deployed, open the Microsoft Defender app (automatically installed by IT) and let it finish initializing. It's this first launch that reports the device's security status to Intune: as long as Defender has never been opened, the device may appear non-compliant. When the screen shows "Device Secure", compliance is OK.
10:28 Microsoft Defender for Endpoint Device Secure 0 threats found Update Status: Automatic Security Status App Security 48 Apps scanned in the last 24 hours No threats found Web Protection Dashboard App Security Web Protection Tunnel
Microsoft Defender → "Device Secure": the device is compliant.

🔒After enrollment

Precise limits depending on the platform — a common question from BYOD users.

Data / ActioniOS (BYOD)Android Work Profile
Deployed work appsVisibleVisible
Personal phone numberNot visibleNot visible
Personal photos / filesNot visibleNot visible
Installed personal appsNot visibleNot visible
Force PIN rotationPossiblePossible
Selective wipe (work data)PossiblePossible
Full wipe (factory reset)BYOD: NoBYOD: No
GPS locationNoNo (BYOD)

📵 Missing profile (iOS)

Wait 2 min then go to Settings → General → VPN & Device Management. If nothing appears, close and reopen Company Portal, then resume from step 5.

⚠️ "Device not compliant" (Android)

Check: Android ≥ 8.0, encryption enabled, lock code active. Fix these, then tap Check compliance again.

🔁 MFA authentication loop

Clear the cache (Android: Settings → Apps → Company Portal → Clear cache) or reinstall on iOS. Also check your license with IT.

♻️ "Device already enrolled"

The old registration blocks the new one. Contact IT to remove the old entry, then try again.

📚 Official Microsoft documentation
Last updated: June 2025 · Intune 2405+ IT Ops — Internal Wiki
✅
In shortYou install Outlook like any other app, sign in, create a PIN — and that's it. No "Company Portal", no management profile to install. Setup takes ~5 minutes.

How the protection works (MAM)

MAM (Mobile Application Management) protects work applications and their data, without managing the whole device. Intune applies app protection policies: company data flows freely between managed apps (Outlook, Word, Excel, PowerPoint, OneDrive…) but stays walled off from your personal apps and storage.

MAM diagram: Intune MAM Service, corporate and personal data walled off
🔒
In practiceYour work apps share their data with each other, but copy-paste, saving or opening a work file in a personal app is blocked. Your personal data, meanwhile, is never visible to IT.
✅
Active on the Ainos tenantThese app protection policies are deployed and active in Intune, for both Android and iOS/iPadOS, across all Microsoft 365 work applications.

Protected apps

The protection applies to Microsoft 365 applications: Outlook, Teams, OneDrive, Word, Excel, PowerPoint and other mobile Office apps. Your other applications are not affected.

Installing on iPhone / iPad

Download the app (Outlook & other Microsoft apps)
Open the App Store, search for Microsoft Outlook and install it (like any other app). The same procedure applies to all "core" Microsoft apps — install the ones you need, they'll automatically get the same protection:
Outlook Teams Edge OneDrive SharePoint
📲 Outlook on the App StoreScan this QR code with the camera to open the official Microsoft Outlook listing directly.
Sign in with your work email
Launch Outlook and enter your firstname.lastname@ainos.lu address then your password (and MFA verification if requested).
Create the work PIN
Outlook asks you to create a 6-digit PIN to protect the work apps. Avoid obvious codes (111111, 123456).
Enable Face ID / Touch ID
Accept using Face ID or Touch ID to unlock the apps faster day to day.
Done
Outlook is up and running. Other Microsoft apps (Teams, OneDrive…) will automatically get the same protection once installed and signed in.

Day to day — what you'll notice

🔓

Quick unlock

Open a Microsoft app → Face ID / fingerprint → immediate access. The PIN is asked again after 30 minutes of inactivity.

📋

Copy/paste between Microsoft apps

Copy text from Outlook to Teams: allowed. Paste into a personal app (WhatsApp, personal Gmail): blocked.

🔒

Privacy preserved

Your photos, contacts and personal apps are never visible to or touched by IT. The company sees nothing of your personal use.

Restrictions to know

ActionBehavior
Backing up work filesForced to OneDrive (no local backup or personal iCloud/Google)
Printing work documentsBlocked
Screenshots in work appsBlocked (iOS and Android)
Copy/paste to personal appsBlocked

Security — access rules

SituationConsequence
5 consecutive wrong PIN attemptsWork data wiped only (personal photos/contacts untouched)
Jailbroken / rooted deviceAccess blocked
iOS older than version 18.0 iOSAccess blocked
Samsung device — Knox attestation failure AndroidAccess blocked (on compatible devices)
Device offline for 24 hAccess temporarily blocked (restored on reconnection)
Device offline for 90 daysWork data wiped
Account disabled / departureWork data wiped
🧹
If you leave AinosIT only wipes Outlook, Teams, OneDrive and work data. Your photos, contacts, WhatsApp and personal apps stay intact — the device remains yours.

BYOD (MAM) vs full enrollment (MDM)

Ainos chose MAM mode (app protection) for BYOD, rather than full device enrollment (MDM). Here's why, from a user perspective:

AspectBYOD / MAM (Ainos's choice)MDM enrollment
SetupDownload Outlook → email → PIN (~5 min)Company Portal → sign-in → enrollment → profile (~15-20 min)
Message shown"PIN required for this app""This device is managed by Ainos S.A."
What IT controlsWork apps onlyThe whole device
What IT seesNothing personalInstalled apps, GPS location, model, phone number
In case of wipeSelective: work apps removed, personal intactFull: entire device wiped
PrivacyFully preservedDevice fully visible to IT
🎯
In one sentenceMAM: "IT protects the work apps, your phone stays private". MDM: "IT manages the phone and can see / wipe everything". For a personal device, MAM offers equivalent data protection without intruding on your privacy.

Special case: Windows

⚠️
BYOD not allowed on WindowsBYOD is limited to iOS, iPadOS and Android. On Windows, access from a personal PC is blocked (no MAM containerization available). To work on a PC, use a corporate device provided by Ainos.
⚠️
Don't bypass the restrictionsDon't try to bypass MAM protections (blocked copy/paste, backup outside managed apps, personal apps for work data). → These rules protect company data and are a condition of your access.
ℹ️
🔒 Your personal data stays privateOn a registered personal device, IT only manages the work context (company apps and data): it can't see your photos, SMS, browsing history or personal passwords. The exact details of what the organization can/can't see are listed in the Intune documentation below.
📚 Official Microsoft documentation
Intune — App Protection Policies (MAM)IT Ops — Internal Wiki
🚀Setup
📲
Quick downloadScan the QR code matching your phone with the camera to open the official Microsoft Outlook listing directly.
iPhone / iPad
App Store
Android
Google Play
Download Microsoft Outlook
Install Microsoft Outlook from the App Store (iOS) or the Google Play Store (Android).
Open the app and add the account
Open the app → Get Started / Add Account. Enter the work address username@ainos.lu then Add Account.
Welcome to Outlook Bring all your emails, contacts, files and calendars together. Add Account Create New Account
Open the app → "Add Account".
‹ Add Account Enter your work or personal email Email Address Add Account Create New Account Sign in using the QR code on your computer Privacy & Cookies
Enter the address username@ainos.lu → "Add Account".
Password + MFA
Enter the password, then approve the multi-factor authentication request (approval in Microsoft Authenticator). See the Password - MFA page.
Device registration
If asked, tap Register: this verifies your identity and lets the organization validate access to work resources.
Finish
If prompted to add another account, choose Maybe Later. Browse through the intro. At the "Enable Notifications" prompt, tap Turn On (recommended). Mail, calendar and contacts appear.
Saturday New Email Enable Notifications Outlook uses notifications as a way to make sure your inbox is always up-to-date. Disabling them might delay email delivery. No Thanks Turn On
Enable notifications: tap "Turn On" (recommended).

On a personal smartphone, Outlook is a Microsoft app protected by app protection policies (MAM), without full device enrollment. The flow differs slightly:

🔐
"Your organization now protects its data"After signing in, a message states the app needs to restart to apply the protection. Tap OK, relaunch Outlook, then set a PIN when prompted.
Managed by your organization To access work or school data with this app, set your PIN. PIN length of 6 digits required. PIN must contain numeric characters only. PIN
Set a PIN (6 digits) to protect work data.
✅ Allowed🚫 Blocked
Reading/sending work emails, calendar, contactsCopy/paste to a personal app
Copy/paste between Microsoft apps (Outlook ↔ Teams)Saving attachments locally (forced to OneDrive)
Face ID / fingerprint unlockForwarding to a personal mail account
Opening attachments in Microsoft appsAccess if device is jailbroken / rooted
⚠️
PIN & wipeThe PIN is asked again after a period of inactivity. After 5 wrong attempts, Outlook's work data is wiped from the device; personal data stays intact. Full details: BYOD (MAM).

🔔Daily use

Outlook automatically sorts mail into two tabs: Focused (important messages) and Other. To move a message, open it → menu (•••) → Move to Other / Move to Focused, and choose "Always" for that sender.

🔔
Adjusting notificationsIn the app: Settings → Notifications. You can be notified for the Focused inbox only, turn calendar alerts on/off, and set quiet hours. On iOS/Android, also check notifications at the system level.

Outlook mobile supports multiple accounts (usually only one Ainos work account is needed). To add one: Settings → Add Account → Add Email Account. Switch between accounts via the avatar in the top left. On a personal device, the work account stays protected by MAM policies, independently of your personal accounts.

🛠️Troubleshooting
SymptomLikely causeSolution
Account won't sign inPassword changed, MFA not approved, or conditional accessDouble-check the password, approve the request in Authenticator; see Conditional access
"Your organization protects its data" keeps loopingApp protection (MAM) not finalizedTap OK, relaunch Outlook, set the requested PIN. Details: BYOD (MAM)
Slow sync or missing emailsWeak network, app needs updatingCheck the connection, update Outlook, pull to refresh; if needed remove and re-add the account
No email notificationsNotifications off (app or system)Enable notifications in Outlook and in the phone's settings
📘
SourceMicrosoft documentation: "Set up the Outlook app for iOS / Android" (support.microsoft.com) + Ainos IT's MAM policy.
📚 Official Microsoft documentation
Microsoft 365 — Outlook mobileIT Ops — Internal Wiki
✉️Best practices

Rather than attaching a copy of the file, share a link to the document stored in OneDrive or SharePoint (a "cloud attachment").

📎 Attachment (copy)

Everyone gets their own version → multiple versions, heavy email, scattered edits. Reserve this for external recipients.

🔗 OneDrive link (recommended)

Everyone works on the same file, always up to date, lighter email, access rights under control.

📎 Classic attachment🔗 OneDrive / SharePoint link
VersionFrozen: everyone gets a copy that drifts apartSingle and up to date for everyone
Co-authoringNot possible (manual merge)Several people at once
Email sizeWeighs down the mailbox (quota)Light (just a link)
Access controlNone once sentEdit/Read rights, revocable
🎯
Habit to buildIn Outlook, attaching a file already on OneDrive automatically inserts a link. For a large local file, Outlook offers to upload it to OneDrive and share the link. Keep the classic attachment for external recipients who can't access the link — or go through the Self-Service Portal for controlled external sharing.

✍️
A clear subject = a faster replySummarize the expected action in the subject: "For approval — Q3 budget by Friday" rather than "Info". A precise subject also helps find the message later.
FieldFor whomWhen to use it
ToRecipients who need to act or replyPeople directly concerned
CcFor information, no action expectedKeep people posted without asking anything
BccRecipients hidden from othersSending to a large list (protects addresses); never to "spy" on a conversation

📦 Attachment size

Beyond ~20–25 MB, sending may be refused. Prefer a OneDrive/SharePoint link (see above) for large files.

🖋️ Signature

A professional signature (name, role, Ainos) is set up in Outlook → Options → Signatures. Keep it simple: no heavy images.

🗂️ Sorting & rules

Create rules (Outlook → Rules) to sort automatically, and use Sweep for newsletters. A tidy inbox is faster to search.

🎣 Attachment caution

Never open an unexpected attachment. If in doubt: Security & phishing.


🔒Confidentiality

Classifying an email based on the confidentiality of its content helps protect it (encryption, restrictions) and prevent leaks.

Label (example)UseProtection
PublicNon-sensitive information, shareableNone
InternalInternal Ainos useMarking, limited distribution
ConfidentialSensitive business dataEncryption, transfer restrictions
Highly confidentialCritical / regulated dataStrong encryption, very restricted access
🏷️
Sensitivity labelsIf enabled by IT, choose the label via the Sensitivity button in Outlook. The label can automatically apply encryption and a visual marking.
⚠️
Before sending sensitive dataDouble-check the recipients (watch out for autocomplete), avoid sending confidential data to external addresses, and prefer a restricted-access link over an attachment for sensitive documents.
📘
SourceMicrosoft 365 best practices: cloud attachments (OneDrive/SharePoint) and Microsoft Purview Information Protection sensitivity labels.
📚 Official Microsoft documentation
Microsoft 365 — EmailIT Ops — Internal Wiki
🧭Understanding it

1️⃣ You share

Right-click your calendar → Sharing Permissions…, add the colleague.

2️⃣ You set the permission level

From "busy / free" to full editing — you stay in control of the access level.

3️⃣ They accept

The recipient gets an invitation email; the calendar is added to their My Calendars list.

The level you choose determines exactly what the recipient sees of your agenda:

LevelWhat the recipient sees (or can do)
NoneNothing — the calendar stays invisible.
Can view when I'm busyYour availability only (busy / free), with no details. Recommended by default
Can view titles and locationsAvailability plus the subject and location of each appointment.
Can view all detailsThe full content: subject, attendees, appointment body, notes.
Can editSee everything and edit: create, move, delete events.
Delegate new OutlookCan edit and send / respond to invitations on your behalf — reserve this for assistants.
🔒
Private itemsAppointments marked "Private" only expose the time slot, never their content — regardless of the level granted (except for the specific delegate option).

📅Sharing & viewing
Open sharing permissions
In the left pane of the Calendar, right-click the calendar to share (Calendar — YourName) → Sharing Permissions…
Open in New Window New Calendar… Hide This Calendar Overlay Colour Rename Calendar Copy Calendar Delete Calendar Move Up Move Down Sharing Permissions…
Right-click the calendar → "Sharing Permissions…" (reproduction of the Classic Outlook menu).
Add the recipient
In Calendar Properties → the Permissions tab, click Add… The Add Users window opens: search for the colleague by name, select them, click Add then OK.
Calendar Properties GeneralPermissionsSynchronisation NamePermission LevelMy OrganizationCan view when I'm busyLuc ValentinCan view all details Add… Remove None Can view when I'm busy Can view titles and locations Can view all details Can edit Add Users Search: luc 👤 Luc Valentin👤 Lucas Meyer👤 Lucie Anders Add OK
Permissions tab: "Add…" opens the user search; the levels outlined in green apply to the selected colleague.
Set the permission level
Back in Permissions, select the added person from the list, then check the desired access level (see the table above).
Confirm
Click OK: the recipient immediately receives a sharing invitation email.

Accept the invitation
Open the received email ("X has shared a calendar with you") and click Accept / Add calendar.
Check the display
The calendar appears automatically in the My Calendars list (or under a group named after the owner), with a checkbox to show or hide it.
Overlay or view side by side
Check several calendars to see them side by side, or use Overlay mode to stack them in a single view.
🛠️Troubleshooting

⏳ The calendar doesn't appear

Wait a few minutes, then refresh (F9 in Classic Outlook). Check that the invitation was accepted.

✏️ Change or remove access

Reopen Sharing Permissions…, select the person, change the level or click Remove.

🌐 External sharing

Calendar sharing outside the organization is restricted by default: submit an IT support request.

📚 Official Microsoft documentation
Last updated: July 2026IT Ops — Internal Wiki

What is set up at Ainos Official Ainos rules — Oct 2026

RuleWhat it means for you
"Anyone" links (no sign-in) don't existEvery link asks the person to sign in.
The suggested link is "People you choose", with the "Can view" permissionYour members switch to "Can edit" only when the person must write.
No password on a linkYou can set an expiration date instead, and sometimes block downloads.
OneDrive can't be shared outsideAnything an external person must see lives in a team space.
SharePoint and Teams: sharing only with guests already created by ITAn unknown address is refused.
Only IT creates guests, and only for approved partner companiesThe request goes through "Invite an external guest"; you are the one who approves it.
A guest cannot reshareThey can't give access to what they don't own.
Access given on the site, on a file or through a link (since 1 October 2026) expires after 180 daysYou get an e-mail before it expires so you can extend it. A guest who is a member of the team doesn't expire: they stay as long as you confirm them in the quarterly review, or until you remove them.
Only IT creates teams, sites, private and shared channelsYour members can create standard channels, unless you turn this off.
"Everyone except external users" is no longer offeredIf it still shows up in an old share (Manage access), check that it's intended, otherwise remove it.
At least two owners per teamThe space stays managed when someone is away or leaves.
Confidential content: a dedicated space, with no external sharingSee Confidential content below.
🔑Your role as owner
RoleSharePoint levelWhat they can do
OwnersFull controlManage the team, its members and its settings
MembersEditCreate, edit and share files
Visitors (SharePoint site)ReadRead only
  • Lasting access goes through the team: in Teams, ⋯ next to the team → Manage team → Members. Not folder by folder.
  • One-off sharing goes through the file: for an occasional reader, share the file rather than adding them to the team.
  • Someone only needs to read the site: add them as a visitor (site ⚙ → Site permissions).
  • Standard channels: your members can create them. To prevent it: Manage team → Settings → Member permissions.
  • A library with different permissions from the rest: ask IT for it.
⚠️
Private channel: two trapsIts SharePoint site doesn't appear in the team's Site contents: you reach it through the channel's Shared tab (formerly "Files"), then Open in SharePoint. And deleting the channel also deletes its files; an owner can restore it within 30 days.
📨
Guests: an e-mail from MicrosoftIf your team has guests, every quarter you get an e-mail from Microsoft (sender MSSecurity-noreply@microsoft.com) asking you to review them. Open the Start review link, or go to myaccess.microsoft.com, then approve or deny each one within 14 days. Keep only those who still work with the team: a denied guest is removed from the team. If you don't answer, nothing changes at the first review; after that, the guest is removed. Guests who only received a file aren't included: their access expires after 180 days. The details: Guest review, step by step.

While you're at it, check the rest:

Team members
Teams → ⋯ next to the team → Manage team → Members: remove anyone who no longer needs access.
Site permissions
On the SharePoint site: ⚙ → Site permissions: owners, members and visitors.
Sensitive files and folders
⋯ next to the file or folder → Manage access: remove links and access that are no longer needed.
Two owners still in place
Check that the team has at least two owners (Manage team → Members, Role column). An owner is leaving? Tell IT before they leave, so the team isn't left without anyone to manage it.
The ⋯ menu of a folder in an Ainos SharePoint library: Share, Copy link, Copilot, Manage access, Delete and other actions.
A folder's ⋯ menu: Manage access shows who has access, and through which links.
A colleague makes the request
The Invite an external guest form on the Self-Service Portal: the person, their company, the dates, the need.
You approve
IT asks for your approval, by e-mail or in Teams, before creating the guest. Without your approval, nothing is created.
IT creates the guest
Only for an approved partner company, then IT adds them to the team.
You check what they can see
A guest who is a team member has the same rights as a member: they see and can edit the files of all standard channels and the site's other libraries, as well as those of the private channels they're added to. Keep elsewhere what they must not see.
During the project
Access given on the site, on a file or through a link expires after 180 days: you get a weekly e-mail in the 2 to 3 weeks before, and a banner shows on the site. To extend it: site ⚙ → Site permissions → Guest expiration. A guest who is a member of the team doesn't expire: they stay as long as you confirm them in the quarterly review, or until you remove them.
At the end of the project
Remove the guest from the team and delete the links you had sent them.

The whole journey in one picture: Share with someone outside Ainos.

My guest can't sign in

  • They haven't accepted the invitation, or opened it with a different address from the one invited: ask them to look for the "Microsoft Invitations on behalf of Ainos" e-mail, including in their junk folder, and select Accept invitation with the right address. Can't find it? IT can resend the invitation.
  • They're asked for two-step verification when they sign in: that's normal, they must complete it.
  • Sign-in can be refused from some countries.
  • They can sign in but no longer open a file: the access may have expired (180 days without extension). Share the file with them again: their guest account still exists.
🔒
The principleWhat must not leave Ainos (contracts, HR, finance, legal) lives in a dedicated site, created by IT, with no external sharing, and open only to a named list of people. Not in an open space where people "are careful".
  • Confidential work with a partner: a separate project space, where IT adds only the guests named for this project. Put in it only what concerns that partner.
  • To ask for one: a Other request on the Self-Service Portal, saying the content is sensitive and who must have access.
  • Sharing based on sensitivity level (labels) is planned for 2027.
ActionEmployee or managerOwnerIT
Create a team, a site, a private or shared channelrequests—does it
Add a colleague to the teamrequestsdoes it—
Share a file within Ainosdoes it——
Give access to someone outside Ainosrequestsapprovesdoes it
Extend a guest's access (link or file)—does it—
Quarterly guest review—does itstarts the review
An owner leaves Ainosthe manager or another owner reports the departure in advance—appoints a new owner
Project finished, or space unused for 6 months—asks for archivingdoes it
🆘
Need help?An access, a guest, a space to create or archive: submit an Other request on the Self-Service Portal, or message IT in Teams. → Support

In short

WhatFor each guest in your team, you confirm whether they should keep their access.
WhenEvery quarter. First review: 2 October 2026.
WhoThe team's owners. A team without an owner is reviewed by IT.
How long14 days to answer. A reminder arrives by e-mail halfway through.
Who is on the listOnly the team's guests (people outside Ainos). Not your Ainos colleagues.
If you denyThe guest is removed from the team at the end of the review, not straight away.
If you don't answerFirst review: nothing changes. From the January 2027 review: guests without an answer are removed.
Diagram of the access review cycle: request sent to owners, review of current members, confirmation of those to keep, removal of stale access, report to the admin.
Every quarter: the request is sent to you, you review the guests and confirm those to keep, the others are removed, then IT gets the summary. Diagram: Microsoft Learn, CC BY 4.0.
📨Answering the review
  • Sender: Microsoft, MSSecurity-noreply@microsoft.com. Depending on the language of your account, the e-mail and the review page are in English or French.
  • Content: the name of the review, your team's name, the due date, and a button to start the review (Start review or Review access, depending on the version).
  • A short message from IT comes with it: keep only the guests who still work with your team.
🛡️
A real e-mail, not phishingIt can arrive up to 24 hours after the review starts. If in doubt, don't click: go straight to myaccess.microsoft.com, Access reviews menu. You'll find the same reviews there.
Example of a Microsoft access review e-mail: “Please review Review access”, the due date, the group name and the Review access button.
Example e-mail (screenshot: Microsoft Learn, CC BY 4.0, demo tenant). At Ainos, it shows your team's name.
Open the review
The Start review button in the e-mail, or myaccess.microsoft.com → Access reviews → the row for your team (Resource column). Sign in with your Ainos account. Another way: the left menu of the My Account portal (myaccount.microsoft.com) → My Access → Access Reviews.
Left menu of the My Account portal on the Ainos tenant: My Access is expanded and Access Reviews is highlighted.
My Access → Access Reviews
List of access reviews in My Access: Groups and Apps tab, one row with the review name, the due date, the resource reviewed and the progress.
One row per team: the due date (Due), the team (Resource) and your progress. Click the review's name to open it. Screenshot: Microsoft Learn, CC BY 4.0.
Go through the list of guests
For each one: their name, their address, and a Microsoft recommendation. Deny is recommended when the guest hasn't signed in for 30 days.
Decide
Tick the circle next to one or more names, then Approve (they keep their access) or Deny (they will be removed). Don't know: the guest keeps their access until the next review.
Give the reason
One sentence in Reason is enough: “project X ongoing”, “assignment ended in June”. It is required, and the other owners can see it.
Submit
Submit. You can change your mind until the review ends: select the row and change the decision.
⚡
Going fastWith nothing ticked, Accept recommendations applies Microsoft's recommendations to every guest not yet reviewed, then Submit. Check the list first: a useful guest who rarely signs in would be denied.
SituationDecision
The guest still works with the team (ongoing project, active contract)Approve
The project or assignment is overDeny
You don't know this personDeny, or first ask the colleague who works with them
The guest only comes for an occasional meeting or fileDeny: you can invite them to a meeting or share a file with them without making them a member
You're unsureDon't know, with a reason: another owner can decide
👥
Several owners: the last decision countsEvery owner receives the review. If one approves and another denies afterwards, the denial applies. Agree among yourselves, and leave a clear reason.
🔄After the review
  • At the end of the 14 days, the decisions apply automatically: a denied guest is removed from the team. They no longer see the team's channels or files.
  • Their account is not deleted: a file or folder shared with them directly stays accessible. Access given since 1 October 2026 expires after 180 days; older access stays until someone removes it. If they should no longer have it, remove it: ⋯ → Manage access.
  • Removed by mistake? Make a new Invite an external guest request on the Self-Service Portal: IT adds them back to the team.
  • The next review comes the following quarter, for every team that has guests at that time.
AccessHow it ends
A guest who only received a file or a linkAccess given since 1 October 2026 expires after 180 days; the team's owners get an e-mail before then to extend it. Older access doesn't expire: check it during your quarterly review (⋯ → Manage access).
Your Ainos colleagues who are team membersThat's your quarterly check: Reviewing access every quarter.
Links and access given on a file or folder⋯ → Manage access, during the same check.
  • I didn't receive anything. Your team may have no guests. Check myaccess.microsoft.com → Access reviews, and your junk e-mail.
  • I'm no longer an owner of this team. Tell IT. The current review stays yours: answer for the guests you know, and choose Don't know with a reason for the others. The new owner will get the next review.
  • I'll be away during the review. If there is another owner, tell them: they receive the same review. If you are the only owner, answer before you leave: from January 2027, guests without an answer are removed. An owner added during the review only gets it the following quarter.
  • Will the guest know I denied them? They get no e-mail from the review; they just find they no longer have access to the team. Let them know if the collaboration continues another way.
🆘
Need help?A question about a guest or the review: submit an Other request on the Self-Service Portal, or message IT in Teams.

Which file goes where?

What you haveWhere it goesWho can see it
A draft, a personal working fileOneDrive, "My files"Only you, until you share it
A file your team works onThe Shared tab (formerly "Files") of the Teams channel — the files are stored in SharePointThe members of the team
A department's reference documentThe department's SharePoint site or the intranetEveryone, read-only
A file sent in a Teams chatIt is stored automatically in your OneDrive, in the Microsoft Teams Chat Files folderThe people in that chat
A formal messageOutlook, with a link rather than an attachment for a colleague. Outside Ainos: Share with someone outside AinosThe recipients
🏢
Your OneDrive belongs to AinosWhen you leave, your manager can recover what is useful for a limited time, then your OneDrive is deleted. Anything that must stay after you leave belongs in a team space, not in your OneDrive.

🔗 I want to share a file

Share a file: with whom, how, and what is blocked.

🛟 I deleted or overwrote a file

Get a file back, personal or team.

🗂️ I want team files in File Explorer

Add a shortcut in three clicks.

🔄 My sync is stuck

Read the icon and act, in the right order.

💻On your PC

Your Ainos PC comes configured. Nothing below needs switching on: these are enforced settings, worth knowing so you don't mistake them for faults.

SettingWhat it means for you
Automatic sign-inOneDrive is already signed in to your Ainos account the first time you start the PC. No password to type.
Desktop, Documents and Pictures backed upThese three folders are already in OneDrive: backed up, versioned and available on your other devices. This backup cannot be turned off. To see it: OneDrive settings → Sync and backup → Manage backup.
Files On-DemandAll your files show in File Explorer, but almost nothing takes up disk space until you open it.
1 TB of spaceThat is the size of your OneDrive.
Internal sharing onlyYour OneDrive can only be shared with people at Ainos. For someone outside: Share with someone outside Ainos.
OneDrive My files — English labelsReproduction of the My files view showing the Desktop, Documents and Pictures folders redirected from the device, with the Sharing column. Name Modified Modified By File size Sharing Attachments 24 April Vincent Maon 2 items Private Desktop 24 April Vincent Maon 3 items Private Documents 24 April Vincent Maon 9 items Private Recordings 1 April Vincent Maon 0 items Shared Microsoft Copilot Chat Files 28 May Vincent Maon 0 items Private Microsoft Teams Chat Files 1 June Vincent Maon 5 items Private Pictures 24 April Vincent Maon 4 items Private Meetings 1 April Vincent Maon 0 items Shared Ainos · Wiki IT
In My files, the Desktop, Documents and Pictures folders are the ones from your PC. The Sharing column shows what stayed private.
💡
The habit that followsSave your work in Desktop, Documents or Pictures, or straight into OneDrive. A file dropped anywhere else (the root of C:\, a temporary folder, a USB stick) is not backed up, not versioned and cannot be recovered.

Microsoft 365 puts some files in your OneDrive without asking. Here is what these folders are for. Their names may appear in English or French, depending on the language of your account.

FolderWhat it holds
Desktop, Documents, PicturesYour PC's Desktop, Documents and Pictures, backed up automatically.
Microsoft Teams Chat FilesThe files you sent in a Teams chat. The people in the chat can open them: if you move or delete the file, their link stops working.
Recordings (FR: Enregistrements)Recordings of the Teams meetings you organize, even if someone else started the recording (a channel meeting is recorded in the channel). They are deleted automatically after 120 days, unless you change the expiration date.
Meetings (FR: Réunions)Shared meeting notes for the meetings you organize.
AttachmentsAttachments you shared from Outlook as a OneDrive link.
Scans (FR: Numérisations)Documents you scanned, for example with the OneDrive mobile app.
Microsoft Copilot Chat Files (FR: Fichiers Microsoft Copilot Chat)The files you gave to Copilot Chat.
⚠️
Don't rename or delete these foldersTeams, Outlook and Copilot use them. Renaming or emptying them breaks the links you have already sent.

In File Explorer, each OneDrive file carries a small icon that tells you where it really is: online only, already on the disk, or kept on the PC for good.

The three states of a OneDrive fileComparison of online-only, available on this device and always keep on this device, with disk usage and the transitions between them. The three states of a file Files On-Demand — what the icon in File Explorer is telling you Online-only file state Visible in File Explorer, storedin the cloud only. Disk space 0 MB on disk Downloads when opened · needs aconnection Available on this device file state Downloaded once opened, readableoffline. Disk space Takes up its full size Reversible with "Free up space" Always keep on this device file state Pinned offline permanently, neverpurged. Disk space Takes up its full size Best before travelling · keep toactive folders open the file "Free up space" "Always keep on this device" clear the option Reversible at any time Nothing is lost: the file stays in the cloud Ainos · Wiki IT
Right-click a file or folder: Free up space sends it back online, Always keep on this device keeps it on the PC. All three states can be reversed.
Status column in Windows File Explorer on an Ainos PC: green ticks, blue clouds and sync arrows.
On an Ainos PC, the Status column: green tick = on the PC, blue cloud = online only, arrows = syncing.

🗑️ Deleting means deleting everywhere

Deleting a file in File Explorer deletes it from your OneDrive and all your devices. To free the disk without losing anything, use Free up space.

🔎 Windows search has a limit

It finds an "online-only" file by its name, not by its content. To search inside the text, use OneDrive search on the web.

📌 Pin before you travel

Before a trip without network: right-click the folders you need → Always keep on this device, then wait for the download to finish.

Your team's files in File Explorer

To work on a team's files from File Explorer, add a shortcut: it shows up in your OneDrive folder, on all your PCs.

Open the team's library
In Teams: the channel → Shared tab → In library view → Open in SharePoint.
Add the shortcut
For the folder on screen: Add shortcut in the command bar (or ⋯ → Add shortcut to OneDrive). For a single subfolder: ⋯ next to its name → Add shortcut to OneDrive → My files.
Find the shortcut
It appears in your OneDrive folder in File Explorer and in OneDrive on the web, on all your devices.
An Ainos team library: the ⋯ menu is open, Add shortcut to OneDrive is highlighted, with its two choices Shortcuts and My files.
⋯ → Add shortcut to OneDrive → My files.
⚠️
A shortcut or a sync, not bothFor the same team folder, don't add a shortcut and a sync: you would get a duplicate folder ("… (1)") or the message "A folder already exists on this PC". The shortcut is enough.
The ⋯ menu of an Ainos SharePoint library: the Sync entry is highlighted.
If IT asks you to sync a library: ⋯ → Sync. Otherwise, prefer the shortcut.
🛟When something goes wrong

Almost everything can be recovered, as long as you pick the right tool. This section covers your personal files and your team's files.

SituationWhereUntil when
I deleted one of my filesonedrive.com → Recycle bin → select the file → Restore93 days after deletion
I deleted a team fileTeams → the channel → Shared tab → In library → Open in SharePoint → Recycle bin (left menu, or Site contents) → Restore. You usually see what you deleted; if the file isn't there (a colleague deleted it, or the bin was emptied), ask the team owner: they can see everything, including the second-stage recycle bin.
I saved a wrong versionOn onedrive.com or in the library, right-click the file (or ⋯) → Version history → Restore. Restoring creates a new version: nothing is lost.Previous versions of the file; past a certain number, the oldest are deleted automatically
Major damage: ransomware, mass deletion, runaway syncOn onedrive.com: ⚙ Settings → Restore OneDrive. Call IT first. For a team space, only IT steps in.Up to 30 days back
An Ainos team library: the file is ticked, its ⋯ menu is open and the Version history entry is highlighted at the bottom of the list.
Tick the file, then ⋯ → Version history. Right-clicking the file opens the same menu.
Version history window of a document: three versions numbered 3.0, 2.0 and 1.0, with modification date, author and size; the arrow next to the date of version 3.0 is highlighted.
Each version has its date, author and size. The arrow next to the date opens View and Restore: no need to keep "v2" or "v3 final" copies.
Menu of a version in the history: View and Restore.
Restore puts this version back.
⚠️
Two recycle bins, not to be confusedThe Windows Recycle Bin and the online OneDrive recycle bin are different. Emptying the online recycle bin moves the files to the second-stage recycle bin (link at the bottom of the Recycle bin page): they can still be recovered there, within the same period.

Always start by reading the icon: hover over the OneDrive icon near the clock, the tooltip shows the real status and the name of the file at fault. Only these icons call for action.

In File Explorer

IconMeaningWhat you do
White cross on a red circle — can't syncClick the OneDrive icon near the clock: the error details are there.
Grey circle with a bar — blocked file typeThis file type can't be uploaded to OneDrive: move it out of the OneDrive folder.

On the OneDrive icon, near the clock

IconMeaningWhat you do
Pause — sync pausedClick the icon → Resume syncing. Often caused by battery saver or a metered network.
Yellow triangle — the account needs your attentionOpen the activity center: the message tells you what to do.
Red "no entry" circle — account blockedAccount blocked: contact IT.
Grey cloud with a line through it — not signed inWindows key → "OneDrive" → open the app and sign in again.
Troubleshooting OneDrive syncA four-step diagnostic path, from the mildest action to the most intrusive. Sync is stuck — the order to work through From the mildest action to the most intrusive. Do not skip a step. 1 Read the icon Taskbar, and the Statuscolumn in File Explorer. Pause → resume syncing Triangle → message in the activity centre Red cross → a file in error to fix 2 Check the ordinary causes Most stalls come fromhere. Quota close to the limit File open in another application Path too long or illegal character A .pst file in a synced folder 3 Restart cleanly Without unlinking anythingyet. Quit OneDrive and start it again Restart the machine Check the connection and the VPN 4 Unlink and relink Last resort — tell ITfirst. Settings → Account → Unlink this PC Sign back in with the Ainos account Files in the cloud are not lost Before anything destructive Check the quota and the network first: most stalls have nothing to do with the sync client itself. Ainos · Wiki IT
Four levels, from the simplest to the heaviest. Don't skip a step, and never start with level 4.
SymptomMost common causeWhat to do
"Processing changes" that never endsA file open elsewhere, a very large file uploadingClose Office apps, wait, then restart OneDrive if nothing moves
A file stays in red errorA forbidden character in the name, a path that is too long, a locked fileRename it, shorten the folder tree, close the app holding it
Nothing syncs any moreOneDrive full, or no networkCheck your space (see below) and your connection
The OneDrive icon has disappearedThe app is no longer runningWindows key → "OneDrive" → open the app
🧯
Don't unlink your account without ITUnlinking the PC loses no file that is already online, but it restarts a full sync; because the backup is enforced, your Desktop and Documents may look empty until OneDrive is signed in again. And in the advanced settings, avoid Download all files: your whole OneDrive would be copied to the disk.

Keeping space free

💽 The PC's disk is full

Right-click large folders you no longer use → Free up space. The files stay in OneDrive and download again when you open them. Start with archives and the Downloads folder.

☁️ Your OneDrive (1 TB) is full

Delete duplicates (a .zip archive and its unzipped content, successive exports) and move team folders to their Teams space. Deleted files still count while they sit in the recycle bin.

⏱️
The figure takes time to changeAfter a big clean-up, the space used can take up to 24 hours to update.
🧭Working well day to day
🗂️
Five habits that save searching
  1. Name your files Subject-Type-Date, for example Budget-Training-2026-10.
  2. No "v2" or "v3 final" copies: version history keeps the old ones.
  3. Few folders, not too deep: three levels are almost always enough.
  4. "Move to" gives a file the permissions of its new location: moved into a team, it becomes visible to its members.
  5. No .pst file (Outlook data) in OneDrive: kept open by Outlook all the time, it syncs badly.

In a team library, + Create or upload makes a new document right where it belongs, and a simple drag and drop uploads your files.

  • On the web: onedrive.com or microsoft365.com, with your Ainos account.
  • In Teams: the OneDrive icon in the left bar (if it isn't there: … → OneDrive).
  • What others sent you: the Shared view in OneDrive (not to be confused with a Teams channel's Shared tab) gathers everything shared with you, and what you shared.

On your phone: scan the code for your phone to install the OneDrive app, then sign in with your Ainos account.

QR code — OneDrive on the App Store Download on the App Store
QR code — OneDrive on Google Play Get it on Google Play
🆘
Need help?File missing, sync blocked, restore: submit an Other request on the Self-Service Portal, or message IT in Teams. → Support

How a team is organised

Teams is for conversations and meetings. The team's files are stored in SharePoint, behind the Shared tab (formerly "Files") of each channel. SharePoint also hosts the intranet and the department sites.

Channel typeWho sees itWhere its files areHow to open them
StandardAll the members of the teamA folder in the team's SharePoint libraryThe channel's Shared tab; for the whole library: In library view → Open in SharePoint
Private 🔒Only the people added to the channelA separate SharePoint site, hidden from the rest of the team

Shared channel (with another team, or another organisation if IT can set it up): only on request to IT.

  • The intranet and department sites are read-only for most of us. To publish there, contact the site owner.
  • "Access denied"? The Request access button sends your request to the owner of the file, team or site.
  • Roles: owners run the team, members edit and share its files, visitors of a SharePoint site can only read.
SharePoint You need access page: a message for the site owner and the Request access button.
"You need access": write why you need it, then Request access.

🔗 I want to share a file

Share a file: with whom, how, and what is blocked.

🛟 I deleted a team file

Get a file back, personal or team.

🗂️ I want team files in File Explorer

Add a shortcut in three clicks.

What you do yourself, what goes through IT

✅ Yourself

  • Post in channels and chats
  • Schedule meetings, including with people outside Ainos
  • Upload files and share them within Ainos
  • Create a standard channel in a team you belong to (unless its owner has turned this off)

🛠️ Through IT

  • A new team or a new site
  • A private or shared channel
  • A confidential space
  • Giving someone outside Ainos access to a team or site (guest account)

Other request ↗ Invite an external guest ↗

🤝The team and its files

Before asking for a new team, check whether a channel in an existing team would do: for a small topic, it usually does. Otherwise, submit an Other request on the Self-Service Portal, or message IT in Teams. Say:

  • what the space is for (one sentence is enough);
  • two named owners, so it stays managed when someone is away or leaves;
  • the members;
  • whether people outside Ainos will join, and whether the content is sensitive (HR, finance, legal, contracts).

IT creates the space and names it. A team also has a group mailbox (calendar and conversations): it is not a shared mailbox.

A chat is a conversation between two people or a small group. A channel is a team topic, visible to all its members.

#️⃣ A team question? In the channel

Everyone benefits from the answer, and it can be found again.

🧵 Reply in the thread

Under the message it answers, not as a new message: the context stays together.

@ A targeted @mention

Mention the right person; keep @channel for announcements.

🔗 A link, not a copy

Paste the file's link rather than an attachment: one version, always up to date.

🗳️ Decide in the channel

Not in a private chat: the whole team can follow.

Sharing a team file in a conversation: in the library, tick the file → Copy link, then paste the link into the channel or chat. Team members already have access to the file: the link is all they need.

An Ainos team SharePoint library: a file ticked and the Copy link button highlighted in the command bar.
File ticked → Copy link: a link to the up-to-date version, instead of a copy as an attachment.
📎
A file sent in a chatIt is stored in the sender's OneDrive (Microsoft Teams Chat Files folder), and only the people in the chat can open it. For a team file, put it in the channel's Shared tab instead.
  • Open the file from the channel's Shared tab: in Teams, in the browser or in the app. Several people can edit at the same time, and everyone sees the others' cursors.
  • Comment: an @mention in a comment notifies the person by e-mail (and usually in Teams Activity too). Click Resolve once it's settled.
  • For a formal review, turn on Track Changes in Word.
  • Planner (tasks) and OneNote (notes) can be added as tabs at the top of the channel, with +.
  • Create a document or upload files in the team library: + Create or upload, or a simple drag and drop.
An Ainos team SharePoint library: the Create or upload menu with Folder, Files upload, Folder upload, Word, Excel, PowerPoint and more.
Create or upload: a folder, files, or a new Word, Excel or PowerPoint document… right where it belongs.

Choose where files open

In Teams: ⋯ (Settings and more) → Settings → Files and links → "Always open Word, PowerPoint, and Excel files in": Teams, Desktop (the installed app, with all its features) or Browser.

Teams settings, Files and links page: download location, opening Word, PowerPoint and Excel files in Teams, Desktop or Browser, browser for links and file previews.
Files and links: where Office documents open, and which browser opens links.

Saved a wrong version? I deleted or overwrote a file.

📅Meetings

The Teams calendar is your Outlook calendar: a meeting created in one shows up in the other.

Schedule
Calendar → + New meeting (or New, depending on the version): a title, the attendees, the date → Send.
Start right away
Calendar → Meet now, then invite the attendees.
Join
The invitation's Join link, or Calendar → arrow next to Meet now → Join with an ID (the ID and passcode are in the invitation).
Check your sound before joining
On the pre-join screen, check which microphone and speaker are selected, then Test mic and speaker. That's where most "we can't hear you" moments are avoided.
Teams pre-join screen: camera, microphone and speaker selection, Test mic and speaker link, and audio options.
Before joining: camera, microphone and speaker. The Test mic and speaker link starts a three-screen test.
Teams audio test in three screens: hear the test sound, hear yourself speak, then confirmation that the audio is ready.
The test: the speaker plays a sound, you speak and hear yourself back, then Teams confirms your audio is ready.
🤖
Note-taking botsWhen Teams recognises a note-taking assistant from another company, it holds it in the lobby, flagged as a bot: someone has to admit it. Only admit the ones you expect.

🌫️ Blur your background

Before joining: Effects and avatars → arrow next to Blur → Portrait blur. During the meeting: More actions (⋯) → Video effects.

🖥️ Share your screen

Share → pick the screen or window; turn on Include sound for a video.

🚪 Leave

The arrow next to Leave offers Leave on all my devices and, for the organizer, End meeting.

Teams Effects and avatars panel with the Portrait blur background selected.
Effects and avatars → Portrait blur.
⏺️
Before recording, tell the participantsTeams shows a banner when recording starts, but doesn't ask for their consent. The recording is stored in the organizer's OneDrive, even if someone else started it (in the channel for a channel meeting). It is deleted automatically after 120 days, unless the organizer (or someone who can edit the file) changes the date. Copilot in meetings only works once transcription is started: see Copilot.
AllowedBlocked
Chats, calls and meetings with people from other organisations (if their organisation allows it too)Chats and calls with personal Teams accounts (not managed by an organisation). These people can still join a meeting with the link, without signing in: they go through the lobby.
Inviting anyone to a meeting by e-mail: they join with the link, even without a Microsoft accountAn external participant cannot take control of your screen
  • The lobby: people who received the invitation (directly, through a distribution list or forwarded) and who sign in with their account get straight in. People who join without signing in, or with just the link and no invitation, wait until the organizer, a co-organizer or a presenter admits them.
  • Who can present: everyone, by default. So every participant can also share their screen and admit people from the lobby. When external people attend, restrict it in Meeting options.
  • No files in the chat of a meeting or conversation with outsiders: they would be stored in your OneDrive, which can't be shared outside Ainos. Share your screen instead.
  • Bringing someone into a team: that requires a guest created by IT. See Share with someone outside Ainos.
🧭Day to day

Choose your notifications

Open the channel settings
⋯ next to the channel name → Channel notifications.
Pick the level
Everything for important channels; less, or nothing, for the others.
Protect your focus when needed
Your picture → status Do not disturb.

Turn on an out-of-office message

⋯ → Settings → General → Out of office: turn on automatic replies, write the message (and its version for outside senders), tick the time period, then Save. It is the same message as in Outlook.

Teams settings, General then Out of office: automatic replies on, internal and external message, period from 24 December to 1 January.
General → Out of office: message, replies to outside senders and time period. Synced with Outlook.

You won't miss anything: your @mentions always reach Activity. The search bar at the top finds messages, people and files, with filters. For the AI assistant: Copilot.

🆘
Need help?A question about Teams, an access, a team to create: submit an Other request on the Self-Service Portal, or message IT in Teams. → Support

The 4 rules Official Ainos rules — Oct. 2026

1Send a link, not an attachment

Everyone works on the same version, and you can remove access at any time.

2The permission offered is “Can view”

Only switch to “Can edit” if the person needs to write in the document.

3Someone outside Ainos: IT creates the access

Submit the “Invite an external guest” request on the Self-Service Portal, then share from the space IT names.

Invite an external guest →

4HR, finance, legal, contracts

In a dedicated confidential space, requested from IT. Never with a “People in Ainos S.A.” link.

Everything at a glance

Infographic “What you can and can't do” (Microsoft 365 at Ainos, October 2026): you can share with named colleagues or with everyone at Ainos, where new links propose “People you choose” with “Can view” and you can set an expiry date, share from a team space with a guest IT has created, and chat, call, meet or share your screen in Teams with people from other organizations. Blocked, each with what to do instead: “Anyone” and “Everyone except external users” links, inviting someone outside Ainos yourself (use the “Invite an external guest” form), sharing from OneDrive with someone outside Ainos, a company not on the approved list, personal Teams accounts, sending files in a chat with another organization, creating a team, a site, or a private or shared channel yourself, and connecting a third-party app to your account (ask IT).
What you can and can't do. Click to enlarge · October 2026

Find the right way to share

Two or three questions: the card that appears tells you where to share from, which settings to pick, what the Ainos configuration blocks and what is best avoided.

1. With whom?
2. Is it sensitive (HR, finance, legal, contracts)?
Answer the questions: the card that matches your case will appear here.
📘How-to

The same window opens from OneDrive, Teams, SharePoint, Word, Excel or PowerPoint. Screenshots taken on the Ainos tenant; when one shows the French interface, the English labels are given underneath.

Click “Share”
On the file: the Share button, or right-click the file → Share.
An Ainos team library: the file is ticked and the Share button is highlighted in the toolbar.
Tick the file, then Share in the toolbar.
Add the names
In To: Name, group or email, type each person's name and pick them from the list. The message is optional.
The Share window on the Ainos tenant: a recipient added in the To field, an optional message, the Copy link button, the link settings gear and the Send button.
The Share window: the recipients at the top, then an optional message. The gear ⚙, next to Copy link, opens the link settings.
Open ⚙ Link settings
Under The link works for, keep People you choose.
Bottom of the Share window: the Link settings gear, highlighted, between Copy link and Send.
The ⚙ Link settings gear, between Copy link and Send.
Link settings on the Ainos tenant: People in Ainos S.A., Only people with existing access, People you choose (selected); under More settings, the permission list open: Can edit, Can review, Can view, Can't download.
Three choices only: “Anyone” does not exist at Ainos. Under More settings, the four permissions; here Can edit was chosen, keep it for people who need to write.
Choose the permission
Under More settings: Can view is offered. Switch to Can edit only if the person needs to write. Add an expiration date if needed, then Apply.
More settings of a link: the Can edit permission, then the Expires field set to Saturday, Oct 31, 2026, and the Apply button.
Expires: pick the day access stops, then Apply.
Send, or copy the link
Send: each person receives an email with the link. Copy link: paste it into a Teams conversation or an email.

From Outlook: dragging a file into an email

When you drag a file from your PC into a new message, Outlook offers two zones. For a colleague, drop it on Upload to OneDrive and share link: the message carries a link, not a copy. Attach files sends a copy: avoid it.

A file from the OneDrive folder dragged into a new Outlook message and dropped on the Upload to OneDrive and share link zone.
✅ For a colleague: Upload to OneDrive and share link: the message carries a link.
The same file dropped on the Attach files zone of the Outlook message.
🚫 Attach files: a copy of the file goes into the e-mail.
ℹ️
A copy, stored in your OneDriveOutlook puts a copy of the file in the Attachments folder of your OneDrive: that copy is what your colleagues open. For a file you are already working on, in OneDrive or in a team, share the original instead (Share or Copy link, above). The link only opens within Ainos: for someone outside, see Sharing with someone outside Ainos.

What you'll see on screen

On screenWhat it means
The link works for
People you choose
offered — keep it
Only the people you name can open the link. Forwarded to anyone else, it doesn't open.
People in Ainos S.A.
non-sensitive only
Anyone at Ainos who receives the link, even forwarded, can open the file. It may then show up in their search and in Copilot.
Only people with existing accessTo send the link again to someone who already has access. It grants no new rights.
More settings
Can editChange the document, with several people at the same time. Only if the person needs to write.
Can reviewSuggest changes (in Word), without applying them.
Can viewRead, without changing anything. This is the permission offered.
Can't downloadRead online only, without downloading a copy: this is how downloads are blocked. Offered only for some links, mostly in OneDrive.
Set expiration dateAccess stops by itself on that date.

“Anyone” (a link that would open for anybody) does not exist at Ainos. Besides the permission, there are only two options: an expiration date and, depending on the link, blocking downloads.

What if your link is forwarded?With a People you choose link, only the person you named opens the file; forwarded to a colleague or to someone outside Ainos, the link does not open. With a People in Ainos S.A. link, the colleague who receives the forwarded link opens the file too, and can then find it in their search and in Copilot; outside Ainos, the link does not open. What if your link is forwarded? You share a file with Léa. Léa forwards the link to other people. the link is forwarded LINK TYPE Léa named by you Marc, Ainos colleague gets the link from Léa Someone outside Ainos gets the forwarded link People you choose offered by default Opens the file with the permission set Doesn't open he must request access Doesn't open no access outside Ainos People in Ainos S.A. non-sensitive only Opens the file with the permission set Opens the file too then finds it in his search and in Copilot Doesn't open no access outside Ainos “Anyone” (a link that opens for anybody) does not exist at Ainos. Ainos · Wiki IT
With “People you choose”, a forwarded link gives no access. With “People in Ainos S.A.”, it opens the file for any colleague who receives it.

🤖 When you add people, Copilot may offer a summary of the file in the message: read it before sending, and don't add it to a sensitive document.

You can adjust a share at any time, always in the same place:

Right-click the file › Manage access › Links tab › ⚙

The People tab of the same panel shows who has access, name by name.

🔁 Change the permission

In ⚙, switch for example from “Can edit” to “Can view”. The change applies to everyone who uses this link.

📅 Set or move the end date

“Set expiration date”: access stops by itself on that day. To extend it, pick a later date: nothing to send again.

✂️ Remove access

Bin icon next to the link: it stops working for everyone, straight away. For one person only: People tab.

Manage access panel: the sharing link with the Copy button and the bin icon, then the Settings menu of permissions: Can edit, Can review, Can view, Can't download.
Manage access: the link, its permission under Settings, and the bin icon to delete it.
🧹
The right habitReview done, project over: remove the access nobody needs any more. A forgotten link stays open.

Sharing with someone outside Ainos — permitted / forbidden

One single rule for everything that leaves Ainos, large files included: IT creates the access, never you.

Infographic “Working with people outside Ainos” (October 2026), in four steps: you request access with the “Invite an external guest” form on the Self-Service Portal, the owner of the team or space approves, IT creates the guest (approved partner companies only) and adds them to the space, then you share from the space IT names, preferably with “Can view”. A guest added to a team stays until the owner removes them, access given by a link or directly on a file or site ends after 180 days (extendable, email 2–3 weeks before), no external sharing is possible from OneDrive, and with other organizations you share your screen rather than files.
You request, the owner approves, IT creates the guest, then you share from the space IT names. Click to enlarge · October 2026
🌐 Submit the “Invite an external guest” request →

Permitted

  • Requesting guest access with the “Invite an external guest” form: the person, their company, the dates, what they need.
  • Once IT has created the guest, sharing with them from the space IT tells you, preferably with “Can view”.
  • Chatting, calling and holding Teams meetings with people from other organizations, and showing them a document by sharing your screen. See Teams & SharePoint.

Forbidden or blocked

  • Sharing yourself with someone outside Ainos without an approved request, or from a space other than the one IT names, even if the screen accepts it: they may already have guest access for another project.
  • Sharing a file yourself with an outside address that has no guest access: it is blocked.
  • Sharing from OneDrive to the outside: blocked, even with a guest.
  • Forwarding an internal link to someone outside: it won't open for them.
  • Sending a file in a Teams chat or meeting with another organization: it would come from your OneDrive, which can't be shared outside. Share your screen instead.
  • Chatting in Teams with a personal Teams account (one that belongs to no organization): blocked.
ℹ️
Good to know
  • Only partner companies approved by IT can receive guest access. The list is not published: IT will tell you when you make the request.
  • A guest added to a team stays a member until the owner removes them. Access given to a guest by a link, or directly on a file or a site, lasts 180 days: the site admins (usually the team owners) are notified 2 to 3 weeks before the end and can extend it.
  • A guest cannot reshare your files.
  • In a meeting, an outside participant cannot take control of your screen.
🧭
Do you manage a team?Member permissions, access reviews, guests in your space: it's all in Manage a team space.
📚 Official Microsoft documentation
Last updated: October 2026IT Ops — Internal Wiki
🔎Discover
Open myaccount.microsoft.com
From any browser, go to https://myaccount.microsoft.com and sign in with your firstname.lastname@ainos.lu account.
Open the My Account section
In the left-hand menu, under the My Account section, select Security info.
My Account side menu: My Account section open, Security info entry highlighted
In the left menu, open "Security info" to see the list of your sign-in methods.
💡
Direct-access tipYou can go straight to the page by typing https://aka.ms/mysecurityinfo in the address bar: this shortcut opens the "Security info" screen without going through the menus.

This screen lists all the active methods on your account. For each method, depending on the case, you have a Change and/or Delete button. The + Add sign-in method button at the top of the list lets you register a new method.

Security info page listing phone, password, Microsoft Authenticator and passkey methods
Overview: phone, password, Microsoft Authenticator (MFA) and passkey are all configured on this account.

Available methods

Several types of methods can coexist on your account. Here are the main ones found at Ainos:

📱 Phone

A mobile number where you receive an SMS or call with a verification code. It's a handy backup method, but less secure than an authenticator app. Use Change to update the number and Delete to remove it.

🔑 Password

Your account password. The row shows the last change date (Last updated). The Change button takes you to the password change wizard. The password can't be deleted: it remains the base of your identity.

🛡️ Microsoft Authenticator (MFA)

The Microsoft Authenticator app installed on your smartphone gets an approval notification (push) or generates a one-time code at every sign-in. It's the strong authentication method recommended by Ainos. The registered phone model name appears next to it (e.g. SM-S938B).

🔓 Passkey (security key)

A passkey lets you sign in without a password, using biometrics (fingerprint, face recognition), a PIN, or a physical security key. On this account, a passkey linked to a Yubikey-type device is registered. It's the method most resistant to phishing.

💡
Most secure method by defaultThe portal shows at the top of the page the most recommended sign-in method currently in use. Keep at least two active methods (e.g. Authenticator + passkey) so you never lose access to your account if one becomes unavailable.
✏️Manage your methods

Click + Add sign-in method at the top of the list. A window then lets you choose the type of method to register, and guides you step by step through the setup.

Add a sign-in method window with the list of available types
The "Add a sign-in method" window: choose the type of method to add (passkey, Authenticator, hardware token, office phone, email…).

The options offered may include:

  • Passkey in Microsoft Authenticator — a passkey stored in the Authenticator app (face, fingerprint, PIN).
  • Passkey — a passkey via biometrics, PIN, or a physical security key.
  • Microsoft Authenticator — sign-in approval via notification or one-time codes.
  • Hardware token — a hardware token generating a code.
  • Office phone — a call received on your professional landline.
  • Email — receiving a code to reset your password (reset only, not for sign-in).

Select the desired method and follow the on-screen instructions (scanning a QR code, entering a number, registering the key, etc.). Once verification succeeds, the new method appears immediately in the list.

💡
Ainos recommendationPrefer adding a passkey or Microsoft Authenticator rather than SMS. These methods are significantly more resistant to phishing and interception attempts.

For each listed method:

  • Change — click Change to the right of the relevant row (for example to change a phone number or password), then follow the wizard.
  • Remove — click Delete to the right of the row, then confirm. The method is removed from your account immediately.
💡
Before deletingMake sure you keep at least one other valid strong authentication method before removing an existing one. Without a backup method, you risk being locked out of your account. If you run into trouble, contact Ainos IT support.
Choose a topic — click to switch guides

💡 Your security methods are registered once and serve all three uses: MFA sign-in, passkey, and password reset.

ℹ️Why MFA

Microsoft Entra ID conditional access analyzes several signals in real time (user, device, application, risk) and decides to allow, require MFA, or block access.

📲 Authenticator recommended

The safest and fastest method: a notification to approve on your phone.

🔢 Number matching

Enter the number shown on screen into the app — this prevents accidental approvals.

🛟 Keep a backup method

Register at least two methods (e.g. Authenticator + phone) so you're never locked out.

Conditional access diagram
Conditional access architecture — Signals → Verify → Apps and data

On first sign-in, or when the conditional access policy requires it, the "More information required" screen appears. Click Next to register an MFA method.

Microsoftprenom.nom@ainos.luMore information requiredYour organization needs more information to keepyour account secureUse a different accountLearn moreNext
MFA registration trigger — the organization requires additional verification
📲Set it up

On first sign-in, the guided "Keep your account secure" wizard walks you step by step through registering Microsoft Authenticator.

Download Microsoft Authenticator
Install the Microsoft Authenticator app on your smartphone (available on the App Store and Google Play).
App Store QR code — Microsoft Authenticator on the App Store
iOS / iPadOS
Scan to open the app listing
Google Play QR code — Microsoft Authenticator on Google Play
Android
Scan to open the app listing
MicrosoftKeep your account secureYour organization requires you to set up the following methods of proving who you are.Microsoft AuthenticatorStart by getting the appOn your phone, install the Microsoft Authenticator app. Download nowAfter you install the app on your device, choose “Next”.I want to use a different authenticator appNextI want to set up a different method
“Keep your account secure” wizard → “Start by getting the app”.
Go to security info
Go to myaccount.microsoft.com → Security info → + Add method and select Microsoft Authenticator.
Scan the QR code
In the Authenticator app, tap + → Work or school account → Scan QR code. Scan the code shown on screen.
Microsoft AuthenticatorSet up your accountIf prompted, allow notifications. Then add an account, andselect “Work or school”.BackNext
“Set up your account”: allow notifications, then add the account.
Approve the test notification
The portal sends a test push notification. Approve it from the Authenticator app. Registration is confirmed.
Microsoft AuthenticatorLet’s try it outApprove the notification we’re sending to your app byentering the number shown below.11BackNextMicrosoft AuthenticatorNotification approvedBackNext
"Let's try it out": enter the number shown, then "Notification approved".
ℹ️
Default methodThe organization's policy uses Microsoft Authenticator (push notification) as the default method. SMS/call is configured as a backup if Authenticator isn't available.
MethodTypePhishing resistanceRecommended
Microsoft Authenticator (push)Mobile appPartialYes
Passkey (FIDO2)Biometrics / hardware keyFullYes ★
TOTP code (Authenticator)One-time codePartialBackup
SMSTextLowLast resort
ℹ️
🔢 Number matching mandatoryNumber matching is now enabled by default for all Microsoft Authenticator users. When approving, you must enter the number shown on screen into the app: this protects against "MFA fatigue" (accidental approvals). Never approve a request you didn't trigger yourself (source: Microsoft Learn).
📚 Official Microsoft documentation
Last updated: July 2026IT Ops — Internal Wiki
✅
In shortConditional access looks at who is signing in, from which device, and from where, then decides: let it through, ask for confirmation (MFA), or block it if something looks risky. The goal: protect your data and Ainos's, without getting in your way day to day.
🧭Understanding it

At every sign-in, several signals are analyzed (who you are, your device, your location, the risk detected). Depending on the result, access is allowed, subject to additional verification (MFA), or blocked — before it even reaches your apps and data.

Diagram: the principle of conditional access — signals analyzed (device, location, user risk, application), policy engine, then decision: access granted, MFA required, or access blocked, before reaching apps and data.
The policy engine evaluates signals at every sign-in and decides: access granted, additional verification (MFA), or access blocked.
🛡️
Why these rules?They're not here to monitor you: they stop a stranger from using your account, even if they stole your password. Most are invisible day to day and only show up in an unusual situation.

2-step verification (MFA) for everyone

At sign-in, a confirmation via Microsoft Authenticator (or a passkey) proves it's really you. It's the most effective protection against password theft.

Extra verification outside the office

From an unusual network or location (outside the office or VPN), an additional MFA check may be requested. This also applies to external guests collaborating with Ainos.

Sign-ins from certain countries blocked

Sign-in attempts from countries where Ainos doesn't operate are automatically blocked. Before a business trip, notify IT to avoid getting blocked.

Only modern apps are allowed

Legacy protocols (legacy authentication, ActiveSync) are blocked : they can't handle MFA. Use up-to-date Microsoft apps such as Outlook and Teams.

Automatic response to suspicious activity

If a sign-in looks risky (password found in a breach, unusual behavior), the system requires a new verification, or even a password change (SSPR). It's a protection, not a punishment.

Verification when adding a device

Registering a new device in the company directory requires an MFA check. That way, no one else can attach their own device to your account (enrollment).

🔑
Privileged accounts (administrators)Admin accounts are subject to even stricter rules : passwordless sign-in (Windows Hello, FIDO2 key), phishing-resistant MFA, more frequent re-authentication, and restricted admin access. This changes nothing for a standard user account.
❓In practice

Here are the most common situations and what to do in each case.

A prompt in Microsoft Authenticator

You're asked to approve a notification or enter a code. This is MFA : it confirms it's really you. Only approve if you just signed in. Details: Password — MFA.

🔢

A PIN in Outlook or Teams

On a personal phone, Microsoft apps ask for a PIN (or your fingerprint / Face ID). It only protects your work data, never your personal data. See BYOD (MAM).

Your mail app won't connect anymore

Only modern apps (Outlook, Teams…) are allowed. Old mail clients (IMAP/POP, a misconfigured "Mail" app) are blocked for security reasons. Fix: use Outlook mobile.

Access blocked abroad

Sign-ins from certain countries are restricted. If you're going on a business trip, notify IT in advance to avoid getting blocked.

📱

"Non-compliant device"

The device must meet a few rules (lock code, up-to-date system, not "jailbroken"). Fix the reported item then try again, or enroll the device: Company Portal.

🔒
An unexpected sign-in request?If you get an MFA notification when you're not signing in, deny it and notify IT: someone may be trying to use your account.
Legacy mail protocols can't handle MFA and offer no data protection. On a personal device, only managed Microsoft apps (Outlook, Teams…) encrypt work content and enforce the PIN. A personal app can't guarantee that. See Set up Outlook mobile.
Sign-ins from unusual countries are monitored and sometimes blocked, and an additional MFA check may be required. Before a trip, tell IT so a temporary authorization can be set up.
The PIN protects the app's work "container". It's requested again after a period of inactivity. Even if your phone is lost or stolen, your company emails and files stay inaccessible. See BYOD (MAM).
No, normally it only appears occasionally (new device, new situation). If it comes back too often, check that the Authenticator app is set up correctly (Security info) or contact IT.
📚 Learn more
Microsoft Entra ID — Conditional accessAinos IT Wiki · for users
✅
In shortNTLM dates from the 1990s. An attacker who gets into a PC can reuse what it leaves in memory to pose as you to other servers (pass-the-hash and NTLM relay attacks). Kerberos doesn't allow this. For you, nothing changes day to day: Outlook, Teams, OneDrive and SharePoint are not affected.
Banner “Kerberos vs NTLM”: on the left NTLM, legacy protocol blocked in Intune (challenge-response based on password hashes, vulnerable to relay and pass-the-hash attacks, no mutual authentication); on the right Kerberos, recommended and used at Ainos (TGT then service ticket issued by the KDC, mutual authentication, SSO); key takeaways: use Kerberos whenever possible, an NTLM-only server needs an alternative or a controlled exception.
NTLM and Kerberos at a glance (click to enlarge).

What is set on your PC

ConnectionWhat happens
Your PC connects to a server (file share, internal application)NTLM is blocked: the connection goes through Kerberos. Only servers that IT has placed in the exceptions still accept NTLM.
Another device connects to your PCNTLM is blocked.
The oldest versions (LM, NTLMv1)Refused everywhere, including for servers in the exceptions.
🛠️If a server stops responding
  • A network share or an old business application keeps asking for your username and password, or shows Access denied.
  • A share opened by its IP address (for example \\10.0.0.5\share) no longer opens, while it opens by its name.
  • An old printer, scanner or NAS refuses the connection.
Use the server's name
Open the share by its full name (\\server-name.domain\share), not by its IP address: Kerberos needs the name.
Still blocked? Ask for an exception
Submit an Other request on the Self-Service Portal. Give the name of the server or device, the application concerned and what you can no longer do.
IT checks
IT first tries to move the server to Kerberos. If it can't, it adds the server to the exceptions.

An exception allows NTLM to one specific server, only when it can't work any other way. It isn't permanent: the aim remains to move that server to Kerberos.

  • Every exception is automatically documented: the server, the date it entered the exceptions and the person who requested it.
  • After 6 months, IT asks you to confirm it is still needed.
  • The list of servers in the exceptions is not published.
🆘
Need help?Submit an Other request on the Self-Service Portal, or message IT in Teams.
✅
In shortThese blocks are intentional: they stop the typical moves of viruses and ransomware before they do damage. Don't try to get around them: no exception is granted for a personal tool or a suspicious file. To test it, use a Hyper-V virtual machine, at your own responsibility. Only a validated business application can be allowed by IT.
Banner “Attack Surface Reduction with Microsoft Intune”: six areas — reduce unnecessary features, control application execution, limit browser attack vectors, harden devices, protect identities and access, continuously monitor and improve.
Overview of attack surface reduction with Intune (click to enlarge). At Ainos, App Control for Business (WDAC) is not in place: what is actually active is detailed below.

The messages you may see

On screenWhat happenedWhat to do
A Windows Security message saying your IT administrator blocked the actionA protection rule stopped a dangerous behavior: a macro launching a program, an executable attachment, a program on a USB stick…See A program is blocked: what to do?
“Unauthorized changes blocked”, or a Controlled folder access messageAn unknown program tried to change a file in your protected folders (Documents, Pictures…).Office, OneDrive and most well-known programs are recognized automatically. Another program blocked? See what to do.
A Windows Security message reporting threats, or a file quarantinedDefender isolated a dangerous file.Don't try to recover it. Not sure (a file you expected from a client, for example)? Tell IT.
No message: an application receives no connectionThe firewall refuses connections coming in to your PC.See The firewall.
“Your account is temporarily locked…” or “The referenced account is currently locked out…”Too many wrong passwords in a row.See Account locked.
🛡️What is protected
What is blockedExample of what you might see
Office: an Office application launching another program, creating an executable file, injecting code into another program, or a macro calling Windows directly (unless IT has approved an exception)A macro in a document you received stops with the Windows Security message.
Attachments: a program or script received by e-mail (Outlook or webmail) won't runAn .exe or .js attachment won't open.
Scripts: a JavaScript or VBScript script can't launch a downloaded programA .js or .vbs file (often inside a .zip you received) can't launch the program it downloaded.
USB stick: an unsigned or unknown program run from a USB stick is blockedAn unknown tool copied to a stick may not run. Your documents on the stick stay readable.
Adobe Reader: it can't launch other programsA malicious PDF can't start anything.
Ransomware: a program behaving like ransomware, or a disguised copy of a Windows tool, is blockedRare: a recent or little-known program may be blocked as a precaution.
Protections invisible day to day: vulnerable drivers, password theft from memory, forced restart in safe mode, remote program launchNothing, except for a very specific technical tool.

Controlled folder access protects Documents, Pictures, Videos, Music and Favorites, including when they are backed up to OneDrive. Only trusted programs can save, change or delete files there: ransomware that tries to encrypt them is blocked.

  • Most well-known programs (Office, OneDrive, Teams…) are recognized automatically.
  • An unknown program (a recent tool, a rare business application) may be blocked: you see “Unauthorized changes blocked”. Save to another OneDrive folder instead (not Documents or Pictures).
  • The history of blocks is in Windows Security → Virus & threat protection → Protection history.

After 10 wrong passwords, your account is temporarily blocked: this is what stops an attacker trying to guess your password.

  • Wait a few minutes: the block lifts on its own, but it lasts longer after each new mistake. Before trying again, check Caps Lock and the keyboard language.
  • Forgot your password? Reset it yourself: MFA · Passkey · SSPR. This also lifts the block straight away.
  • Locked without typing anything? A device (phone, tablet) may still hold your old password, or someone may be trying your account: tell IT.

With Windows Hello (PIN or face), this counter doesn't apply: the PIN has its own protection. See Windows Hello (PC).

The Windows firewall is on for every network (office, home, public Wi-Fi) and refuses connections that come in to your PC (except those IT has allowed), without showing a message. Internet, Teams, Outlook and OneDrive are not affected: those connections go out from your PC.

An application that needs to receive connections (a copier dropping a scan into a folder on your PC, a tool running locally) may therefore fail without explanation. If it is a business application, IT can allow it.

A program is blocked: what to do?

What is blockedWhat to do
A personal tool, software found on the Internet, a suspicious file to examineNo exception. Test it in a Hyper-V virtual machine: an isolated PC inside your PC, which you manage and are responsible for.
A business application you need for your work (a client's tool, a company application)Ask IT to allow it, below.

Getting a business application allowed

Note what was blocked
The name of the application, the exact message (a screenshot is enough), the date and time, and what you use it for.
Make the request
Other request on the Self-Service Portal, or a Teams chat with IT.
IT checks and allows
IT finds the block in Microsoft Defender and allows that specific application if it is safe. A protection is never turned off for the whole PC.
⚠️
A block you didn't expect?If you didn't launch anything special (a document that just arrived by e-mail, a link you clicked), it may be a real attack stopped in time. Don't reopen the file and tell IT straight away. See also Security & phishing.
⚠️
You are responsible for itThe virtual machine is outside Ainos protections: neither Intune, nor the Defender rules, nor the OneDrive backup apply to it. What you install, open or download there is your responsibility. Follow the rules below: they stop a virus tested in the VM from reaching your data or the Ainos network.

The rules to follow

RuleWhy
No Ainos data in the VM: don't sign in with your Ainos account, no Outlook, Teams or OneDrive, no client filesNothing in the VM is protected or backed up.
Don't enroll the VM in Intune or join it to Entra IDIt would become a non-compliant Ainos device with access to company resources.
Two uses, two VMs: a VM-API connected to the Default Switch to test a tool or an API, and a VM-Quarantine with the network Not connected to open a suspicious file. Never an external switchWhen connected, the VM goes out through your PC's connection and can reach the Ainos network: a malicious file opened in a connected VM would take advantage of it.
In the VM-API, test access only: test API keys, accounts and data sets, never a production secret or real client dataWhat goes into the VM is neither protected nor backed up, and the tool under test may compromise the VM.
Basic session for a suspicious file: turn off enhanced session modeIt shares your PC's clipboard (including files) and printers with the VM, and can give access to your drives.
A “clean” checkpoint before each test, and go back to it afterwardsYou start from a healthy VM every time: nothing you tested remains.
VM files in C:\VMs, never in Documents or on the DesktopThose folders sync with OneDrive: a virtual disk of tens of GB would be uploaded.
Delete the VM as soon as you no longer need itA forgotten VM no longer gets updates.
🛠️Setting up the VM

Hyper-V is built into Windows: nothing to download. Open PowerShell as administrator (right-click → Run as administrator), then:

Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All

Answer Y to restart. After the restart, Hyper-V Manager appears in the Start menu.

Without PowerShell: type features in the taskbar search → Turn Windows features on or off → tick Hyper-V → OK, then restart.

Windows search: the word features typed, and the Turn Windows features on or off (Control panel) result highlighted.
Search → Turn Windows features on or off.
Turn Windows features on or off window: the Hyper-V box is ticked and highlighted.
Tick Hyper-V, then OK.

If the command fails, note the full error message and contact IT.

Use the Windows 11 Enterprise evaluation, free and legal for testing, valid for 90 days, with no product key: Microsoft Evaluation Center → Windows 11 Enterprise (not LTSC) → fill in the registration form → 64-bit (x64) ISO (Arm64 only if your PC has a Snapdragon processor), any language.

  • First create the folder, in an administrator PowerShell: New-Item -ItemType Directory -Path "C:\VMs\ISO" -Force, then save the ISO there.
  • Never download Windows from anywhere other than a Microsoft site.
  • After 90 days, delete the VM and create a new one: an expired evaluation shuts down every hour.

If you have your own Windows 11 product key, you can also take the standard ISO from the Windows 11 download page → Download Windows 11 Disk Image (ISO) for x64 devices. Without a key, Windows stays unactivated: use the evaluation instead.

Microsoft Windows 11 download page (in French): Download Windows 11 Disk Image (ISO) for x64 devices section, Windows 11 (multi-edition ISO for x64 devices) choice and the Download button highlighted.
The standard Windows 11 ISO, which needs a product key (page shown in French).

In an administrator PowerShell, adjust the ISO path, then paste:

$vm  = "VM-Quarantine"
$iso = "C:\VMs\ISO\Windows11-Evaluation.iso"
New-Item -ItemType Directory -Path "C:\VMs" -Force | Out-Null
New-VM -Name $vm -Generation 2 -MemoryStartupBytes 4GB -Path "C:\VMs" -NewVHDPath "C:\VMs\$vm\$vm.vhdx" -NewVHDSizeBytes 64GB
Set-VMProcessor -VMName $vm -Count 2
Set-VMKeyProtector -VMName $vm -NewLocalKeyProtector
Enable-VMTPM -VMName $vm
Add-VMDvdDrive -VMName $vm -Path $iso
Set-VMFirmware -VMName $vm -FirstBootDevice (Get-VMDvdDrive -VMName $vm)
Set-VMHost -EnableEnhancedSessionMode $false
vmconnect.exe localhost $vm
Start-VM -Name $vm

What these lines do: a generation 2 VM with 4 GB of memory, 2 processors and a 64 GB disk in C:\VMs, secure boot and a virtual TPM (required by Windows 11), no network, and enhanced session mode turned off (for all VMs on the PC). The VM window opens, then the VM starts: press a key right away to boot from the ISO. If you miss it, use Action → Reset, then press a key. Install Windows with a local account, never your Ainos account or a personal Microsoft account.

Create both VMs: run the script once as is (VM-Quarantine, no network), then a second time with $vm = "VM-API", and connect the latter:

Connect-VMNetworkAdapter -VMName "VM-API" -SwitchName "Default Switch"

Without PowerShell: Hyper-V Manager → New → Virtual Machine: tick Store the virtual machine in a different location and enter C:\VMs; generation 2, 4096 MB, network Not connected, 64 GB disk in C:\VMs, the ISO. Then Settings → Processor: 2 virtual processors; Security: tick Enable Secure Boot and Enable Trusted Platform Module.

Hyper-V Manager: Action menu open, New then Virtual Machine.
1. Action → New → Virtual Machine.
New Virtual Machine Wizard, Specify Name and Location page: VM name and the Store the virtual machine in a different location box, unticked by default.
2. Name the VM (VM-Quarantine or VM-API), tick Store the virtual machine in a different location and enter C:\VMs.
Specify Generation page: Generation 2 selected.
3. Generation 2. Then, Assign Memory page: 4096 MB.
Configure Networking page: Connection list set to Default Switch.
4. Connection: Not Connected for the VM-Quarantine. Default Switch, as here, only for the VM-API.
Connect Virtual Hard Disk page: Create a virtual hard disk, default location C:\ProgramData\Microsoft\Windows\Virtual Hard Disks and size 127 GB.
5. Replace the suggested location with C:\VMs\ + the VM name, and the size with 64 GB.
Open dialog to pick the ISO: a 7.94 GB Windows 11 disc image file in the Downloads folder.
6. Installation Options: Install an operating system from a bootable image file, then pick the ISO, ideally stored in C:\VMs\ISO.

Before starting the VM, set what the wizard doesn't:

Hyper-V Manager: right-click on the turned-off VM, menu with Settings highlighted.
7. Right-click the VM → Settings.
VM settings, Processor page: Number of virtual processors set to 4.
8. Processor: at least 2 virtual processors (4 here).
VM settings, Security page: Enable Secure Boot with the Microsoft Windows template, and Enable Trusted Platform Module, ticked and highlighted.
9. Security: Enable Secure Boot (Microsoft Windows template) and Enable Trusted Platform Module, then OK.

All the commands below run in an administrator PowerShell.

Once Windows is installed, activate and update it
The VM is still clean: connect it for activation (otherwise it shuts down every hour) and Windows updates, check Settings → System → Activation, then disconnect the VM-Quarantine:
Connect-VMNetworkAdapter -VMName "VM-Quarantine" -SwitchName "Default Switch"
# … activation and updates inside the VM, then:
Disconnect-VMNetworkAdapter -VMName "VM-Quarantine"
Save a clean state
Checkpoint-VM -Name "VM-Quarantine" -SnapshotName "Clean", and the same for the VM-API.
Bring the tool or the file in
A tool or an API to test: in the VM-API, download it directly from inside the VM.
A suspicious file already on your PC (an attachment, for example): in the VM-Quarantine, use a small transfer disk:
Stop-VM -Name "VM-Quarantine"
New-VHD -Path "C:\VMs\transfer.vhdx" -SizeBytes 2GB -Dynamic
Mount-VHD "C:\VMs\transfer.vhdx" -Passthru | Initialize-Disk -Passthru | New-Partition -AssignDriveLetter -UseMaximumSize | Format-Volume -FileSystem NTFS -Confirm:$false
# if File Explorer offers to format the disk: Cancel.
# copy the file to the new drive that appears, then:
Dismount-VHD "C:\VMs\transfer.vhdx"
Add-VMHardDiskDrive -VMName "VM-Quarantine" -Path "C:\VMs\transfer.vhdx"
Start-VM -Name "VM-Quarantine"
Test
As long as the VM has no network and uses a basic session, what happens in it stays isolated from your PC.
Go back to the clean state
Restore-VMSnapshot -VMName "VM-Quarantine" -Name "Clean" -Confirm:$false. The VM is then turned off and the transfer disk detached.

After the test, delete the transfer disk (C:\VMs\transfer.vhdx) without reopening it on your PC: it may have been changed inside the VM.

Delete a VM when you no longer need it: Stop-VM -Name "VM-Quarantine" -TurnOff, then Remove-VM -Name "VM-Quarantine" -Force, then delete the C:\VMs\VM-Quarantine folder (if a file is "in use", wait a few minutes).

💼
A business application doesn't go in the VMIf the blocked tool is for your work (a client's application, company software), your work data would end up outside Ainos protection. Ask for it to be allowed instead: Getting a business application allowed.
ℹ️
PrerequisiteThe IT administrator must have granted you access rights to the shared mailbox. In most cases it appears automatically in Outlook after a restart. The steps below cover adding it manually if it does not appear.
📨
Request access to a shared mailbox If the mailbox does not appear in your Outlook yet, submit an access request via the Self-Service Portal (“Shared mailbox access” form).
💻On computer

If the shared mailbox does not appear automatically after a restart, add it manually via the Exchange settings.

File → Account Settings
Click the File tab in the top left, then Account Settings → Account Settings…
Inbox - Vincent.MAON@ainos.lu - OutlookInfoOpen & ExportSave AsSave AttachmentsPrintAccount InformationVincent.MAON@ainos.luMicrosoft Exchange+Add AccountAccountSettings ▾Change settings for this account or set up moreconnections.Access this account on the web.https://outlook.office.com/owa/ainos.lu/Android.ChangeAccount Settings…Add and remove accounts or changeexisting connection settings.Account Name and Sync SettingsUpdate basic account settings such asaccount name and folder sync settings.
Select the Exchange account → Change
On the Email tab, select your Exchange account (user@ainos.lu) and click Change…
Email AccountsYou can add or remove an account. You can select an account and change its settings.EmailData FilesRSS FeedsSharePoint ListsInternet CalendarsPublished CalendarsAddress BooksNew...Repair...Change...Set as Default×RemoveNameTypeVincent.MAON@ainos.luMicrosoft Exchange (send from this account by default)vincent.maon@ainos.luMicrosoft ExchangeSelected account delivers new messages to the following location:Vincent.MAON@ainos.lu\Inboxin data file C:\Users\...\Microsoft\Outlook\Vincent.MAON@ainos.lu.ostClose
More Settings…
In the Exchange Account Settings window, click More Settings…
Exchange Account SettingsVincent.MAON@ainos.luOffline SettingsUse Cached Exchange Mode to download email to an Outlook data fileDownload email for the past:1 yearMore SettingsNext
Advanced tab → Add
In the Microsoft Exchange dialog, go to the Advanced tab and click Add…
GeneralAdvancedSecurityMailboxesOpen these additional mailboxes:Add…RemoveCached Exchange Mode SettingsUse Cached Exchange ModeDownload shared foldersDownload Public Folder FavouritesOutlook Data File Settings…Microsoft 365 FeaturesTurn on shared calendar improvementsMailbox ModeOutlook is running in Unicode mode against MicrosoftExchange.
Enter the shared mailbox address
Type the shared mailbox email address (e.g. shared@ainos.lu) and click OK.
Microsoft ExchangeGeneralAdvancedSecurityMailboxesOpen these additional mailboxes:Add…RemoveCached Exchange Mode SettingsUse Cached Exchange ModeAdd MailboxAdd mailbox:sharedmailbox@ainos.luOKCancel
Confirm — mailbox listed on the Advanced tab
The shared mailbox appears under "Open these additional mailboxes". Click OK → Apply → OK → Next → Finish → Close.
Microsoft ExchangeGeneralAdvancedSecurityMailboxesOpen these additional mailboxes:sharedmailbox@ainos.luAdd…RemoveCached Exchange Mode Settings
Result — mailbox available in the folder pane
After restarting Outlook, the shared mailbox appears in the left pane below your main mailbox. Click its name to expand the folders.
Search File Home Send / Receive Folder View Help Try the new Outlook New Email New Items New Delete Archive Delete Reply Reply All Forward Respond Share to Teams Teams Quick Steps Quic... Move Tags Find Find A Rea... Alo... Spee... P Drag Your Favorite Folders Here @offi... Sharedmailbox@ainos.lu Inbox Drafts Sent Items Deleted Items Archive Conversation History Junk Email Outbox All Unread By Categories We didn't find anything to show here.
Optional — Add to Favorites
For quick access, right-click the shared mailbox in the pane and select Add to Favorites.
SearchFileHomeSend / ReceiveFolderViewHelpTry the new Out…New EmailFavoritesInboxSharedmailbox@ainos.luInboxDraftsSent ItemsDeleted ItemsArchiveConversation HistoryJunk EmailOutboxAllUnreadBy Categori…We didn't find anything to show here.Open in New WindowOpen File LocationClose "Sharedmailbox"New Folder…Add to FavoritesAZSort Subfolders A to ZFolder PermissionsData File Properties…

Send from the shared mailbox (Classic Outlook)

In a new message, click the From: field and select shared@ainos.lu from the drop-down list.

In the new Outlook, shared mailboxes usually appear automatically under “Shared with me” once rights are granted. To add one manually, follow these steps:

Open File → Settings
Click File in the menu bar, then Settings to open the account settings panel.
Outlook☰FileHomeView✎ New⌄ Fav…☉➤➤› Vir…Account infoSave as›PrintOpen and exportSettingsAbout OutlookExit
Accounts → Shared with me → + Add
In settings, go to Accounts → Shared with me, then click + Add.
SettingsSearch settingsAccountsFilesGeneralYour accountsShared with meAutomatic repliesSignaturesCategoriesShared with meView and manage all shared emailaccounts you have access to.AddAinos - Helpdesk ITExchange permissions granted to Vincent.MAON@...
Enter the shared mailbox address
In the “Add a shared email account” dialog, enter sharedmailbox@ainos.lu and click Add.
Add a shared email accountAdd a shared mailbox or mailbox folders fromthe email account of the person who has givenyou permission to access their mailbox, foldersor calendars with you.sharedmailbox@ainos.lu
Result — mailbox under “Shared with me”
The shared mailbox appears in the left pane and can be expanded with all its folders (Inbox, Drafts, Sent Items…). You're done.

Send from the shared mailbox (New Outlook)

In a new message, click the From: field, start typing the address and pick sharedmailbox@ainos.lu from the suggestions.

📱On mobile

On mobile, the shared mailbox is added as an extra account. The procedure is identical on iOS and Android.

Open Outlook and tap the profile picture
Open the Outlook app, then tap the profile picture (or the ☰ menu) in the top left.
9:41 Inbox Focused Other Filter Daisy PhillipsSurprise Birthday Planning Lydia BauerMeet & Greet Celeste BurtonTeam Bonding Pictures
Tap the profile icon (top left).
Open Settings (⚙️)
At the bottom left of the pane, tap the ⚙️ Settings icon.
Accounts → Add account → Shared mailbox
Scroll to Accounts → Add account, then choose Add Shared Mailbox.
SignaturePer Account › Swipe OptionsArchive/Schedule › Add AccountOutlook, Gmail, Exchange, iCloud… Add Shared MailboxShared and delegate mailboxes Add Storage AccountConnect to OneDrive, Dropbox etc… Cancel
Choose “Add Shared Mailbox” (shared and delegate mailboxes).
Enter the shared mailbox address
Enter the mailbox address (e.g. shared@ainos.lu) and tap Continue. Outlook checks your permissions and adds the mailbox to your account automatically.
Switch between your mailboxes
Once added, you can switch between your own mailbox and the shared one from the account menu (profile icon, top left).
ℹ️
Send from the shared mailbox on mobileIn the compose window, tap From: and select shared@ainos.lu. If the address does not appear, switch to the shared mailbox first via the profile icon.

The procedure on Android is identical to iOS. The Outlook app interface is the same on both platforms.

Profile / ☰ → ⚙️ Settings
Tap the profile picture or ☰ → the ⚙️ Settings icon at the bottom left.
9:41 Inbox Focused Other Filter Daisy PhillipsSurprise Birthday Planning Lydia BauerMeet & Greet Celeste BurtonTeam Bonding Pictures
Tap the profile icon (top left).
Accounts → Add account → Shared mailbox
Accounts → Add account → Add Shared Mailbox. Enter shared@ainos.lu → Continue.
SignaturePer Account › Swipe OptionsArchive/Schedule › Add AccountOutlook, Gmail, Exchange, iCloud… Add Shared MailboxShared and delegate mailboxes Add Storage AccountConnect to OneDrive, Dropbox etc… Cancel
Choose “Add Shared Mailbox” (shared and delegate mailboxes).
Mailbox added
The shared mailbox is available via the profile icon in the top left, like a separate account.

🛠️Troubleshooting
ProblemCauseSolution
Mailbox missing after restarting OutlookAuto-mapping not enabled or rights not propagated yetWait 5-10 min and restart; if it persists, add it manually
Cannot send from the mailboxMissing "Send As" permissionContact IT to have the rights granted
Mobile — mailbox not found when typingRights not propagated in Exchange yetWait 15 min after rights are granted, then try again
Classic Outlook — mailbox cannot be removedAdded via Exchange auto-mappingIT must remove the rights in the Microsoft 365 Admin Center
📚 Official Microsoft documentation
Shared mailbox · Ainos IT WikiIT Ops — Internal Wiki

Sign-in & password

You can reset it yourself, without calling IT, using SSPR. On the sign-in screen, click "Forgot my password". Details: Reset my password (SSPR).
MFA (multi-factor authentication) adds a 2nd proof of identity on top of your password — usually an approval in Microsoft Authenticator. Even if someone knows your password, they can't get in. See Password — MFA.
Yes! With a passkey or a FIDO2 security key, you sign in with your fingerprint or face. It's faster and safer. See Passkey & FIDO.
Reinstall the Microsoft Authenticator app on the new device, then add your account again from your Security info. Remember to remove the old device from the list.

📱 Phone & devices

BYOD (MAM) only protects work apps — IT never sees your personal data and doesn't control the phone. It's the simplest option. Full enrollment (MDM) via Company Portal manages the device more thoroughly (often for company-owned phones). See BYOD and Company Portal.
No. In BYOD as in an Android Work Profile, your photos, texts, personal apps and phone number stay private. The organization only sees the work apps it deployed. The details are in the table on the Company Portal page.
Notify IT immediately. Only work data can be wiped remotely (selective wipe); your personal data is not touched. The PIN and encryption prevent access to your work email in the meantime.

Email

Microsoft Outlook. It's the only approved and protected app for work email. See Set up Outlook mobile.
A shared mailbox (e.g. contact@, support@) is added to Outlook automatically. To write "on behalf of" the mailbox, choose it as the sender. See Shared mailbox.
Prefer a OneDrive link: everyone works on the same version, and it's lighter. See Email best practices.

Collaboration

OneDrive = your personal work files. SharePoint / Teams = files shared with your team. See My files (OneDrive) and Teams & SharePoint.
The OneDrive app shows all your files in Windows Explorer without downloading everything (files on demand). For a shared SharePoint/Teams library, use "Add shortcut to OneDrive" instead. See OneDrive.
Never with a OneDrive link: sharing outside Ainos from OneDrive is blocked. Submit the “Invite an external guest” request on the Self-Service Portal: once IT has created the guest access, you share from the space IT tells you. Full details: Share a file.
From Outlook, share your calendar with a chosen level of detail (availability only, or full details). See Calendar sharing.

Security & access

Don't click any link and don't open any attachment. Use Outlook's Report button (Report > Phishing). See Security & phishing.
It's Conditional Access checking your sign-in (device, location, risk). The causes and fixes are explained here: Conditional access.
No, MFA is mandatory for all Ainos accounts — it's the most effective protection against account takeover. That said, a passkey or FIDO2 key makes signing in as fast as a fingerprint. See Passkey & FIDO.
Windows and security updates are deployed automatically by IT; a non-compliant device can lose access to some resources. See Updates & compliance.
FAQ · Ainos IT WikiUpdated 2026
🎣
What is phishing?An email (or SMS) that looks legitimate but tries to steal your credentials or money, or to install malware. It often plays on urgency or fear.
🎣Understanding phishing

Modern attacks are not always just a fake link: some hijack legitimate Microsoft mechanisms. Here is a common example, device code phishing, from the first email to the theft of the tokens.

6-step diagram of a device code phishing attack: baited email, click on the link, redirect to the attacker's server, device code generation, entry on microsoft.com/devicelogin, theft of the access and refresh tokens
A real technique known as “device code phishing”. Never enter a code received by email on microsoft.com/devicelogin if you did not start a sign-in on a device yourself.
⏰

A sense of urgency

“Your account will be closed in 24h”, “Action required immediately”. Urgency is there to make you act without thinking.

🔗

Suspicious links or senders

Hover over the link without clicking: the real address does not match. The sender imitates a known name with an odd domain.

📎

An unexpected attachment

An invoice, CV or delivery note you were not expecting. Never open an attachment from a stranger.

🔑

You are asked for your credentials

Microsoft, your bank or IT will never ask for your password by email.

Scam typeWarning signThe right response
Credential phishing“Microsoft” sign-in page received via a link, URL that does not end in an official Microsoft domainDo not enter your password; open the service from a known favorite, not the link
CEO / invoice fraudUrgent request for a transfer or an IBAN change, “confidential”, pressure from aboveVerify via a 2nd channel (phone, in person) before any financial action
Malicious attachmentUnexpected file (invoice, CV, .zip, .html) asking you to “enable macros”Do not open; report the message; ask the sender to confirm via another channel
Fake support / IT“Your account is compromised”, you are asked for your credentials or an MFA codeIT never asks for your password or an MFA code; refuse and alert support
Smishing (SMS) / Quishing (QR code)Delivery/bank SMS with a short link, QR code received by emailDo not click/scan; check directly on the organization's official website
🛡️The right reflexes
✅
When in doubt, don't click.If unsure, don't click any link, don't open any attachment, and don't reply. Report the message (see below) or ask IT.
  • Verify the sender through a trusted channel (directory, phone) rather than the contact details in the email.
  • Never reuse your work password anywhere else.
  • Keep MFA on: it's your best safety net (MFA).
  • An MFA prompt you did not trigger? Deny it and tell IT.
🚨If it happens
Select the message
In Outlook, open or select the suspicious email (without clicking its links).
Click “Report”
Use the built-in Report button in the ribbon (Outlook desktop, web and mobile).
Choose “Phishing”
Select Report phishing. The message is sent for analysis and leaves your mailbox. You just helped protect the whole company.
Ruban Outlook : le bouton Signaler ouvre un menu avec Report phishing et Report junk
In the Outlook ribbon, click Report and choose Report phishing. Report junk is for spam, not for a real scam attempt.
⚙️
What happens next?Reported as phishing: the message is removed and sent for analysis. Reported as junk: it is moved to the Junk Email folder and the sender is automatically blocked. The Report button is available in all recent versions of Outlook (desktop, web, mobile, Mac) — source: Microsoft Learn.
🚨
Don't panic, but act fast.1) Alert IT support immediately. 2) Change your password (SSPR). 3) If you entered banking details, contact your bank. Better to report a false alarm than to stay silent.
❓FAQ
❓
I reported a legitimate email by mistake — is that a problem?No. A false positive is better than real phishing going unreported. The email goes for analysis; if it was legitimate you can recover it, and IT won't mind at all.
❓
How can I check a link without clicking?Hover over it (on PC) or long-press it (on mobile) to reveal the real URL: if the domain does not match the claimed sender, that's a red flag. When in doubt, see the FAQ.
Security · Ainos IT WikiIf in doubt: contact IT.
Endpoint Management Platform (Intune): update sources (Microsoft Cloud, CVE, CIS Benchmarks, Intune) assessed to produce compliant devices and apps.
⏳
A known, unpatched flaw is an open door.Every update closes vulnerabilities that attackers actively exploit, sometimes as soon as they're published. Postponing a restart indefinitely leaves the door ajar.
🔄Understanding updates

Every month — the famous "Patch Tuesday" (2nd Tuesday of the month) — Microsoft releases fixes for Windows, Office, Edge and its other products. Every fixed flaw is publicly listed in the Security Update Guide (MSRC), with its severity and affected systems.

MSRC Security Update Guide — All updates view
The "All" view: each row is a fixed flaw on a Microsoft product, with its severity.
MSRC Security Update Guide — Deployments view
The "Deployments" view: build numbers and release notes, month by month.
MSRC Security Update Guide — Vulnerabilities (CVE) view
The "Vulnerabilities" view: each flaw has a CVE identifier and a severity level (Critical, Important…).
💡
No need to track this yourselfThis catalog is meant for IT teams. At Ainos, Intune deploys these fixes to your managed devices — your only job: restart when asked.
🔄

Automatic updates

Windows Update is managed by Intune: fixes download and install on their own, no action needed from you.

🔁

Restart when asked

A fix is only active after a restart. Save your work and restart your PC as soon as possible.

⏱️

Don't postpone indefinitely

Past a grace period, a restart can be forced to protect the whole company.

🏬 Install via official channels

Company Portal or Microsoft Store only. An installer found elsewhere can be booby-trapped.

🧩 Office & Edge auto-update

They update themselves in the background: no need to look for a new version.

🛡️ Trusted apps only

Smart App Control blocks unrecognized or unsigned applications before they're even installed.

🛡️Security & compliance

Your Ainos PC combines several layers of protection, always active in the background.

Identity: passwordless sign-in and advanced credential protection

🪪 Identity

Passwordless sign-in (Windows Hello, Passkey) and advanced credential protection.

Application: app and driver control, application isolation

📋 Applications

Smart App Control and isolation (Sandbox, containers) limit what an app can do, even if compromised.

Operating system: encryption, network, antivirus, device management

💻 System

BitLocker (disk encryption), Microsoft Defender (antivirus) and firewall protect the device and your data, even if stolen.

Intune continuously checks that a device follows company rules: active encryption, a lock code set, an up-to-date Windows version, an unmodified device (no jailbreak/root). A compliant device gets access to work resources; a device that no longer is can have its access reduced, via conditional access.

🔐
The link between the twoUpdates + compliance go hand in hand: an up-to-date device meets the compliance criteria, and a compliant device can access Outlook, Teams, SharePoint… A device that falls too far behind on updates can be flagged non-compliant and lose that access.
✅Best practices

🔁 Restart without delay

As soon as an update requires it, restart at the first convenient opportunity.

🚫 Don't disable anything

Defender, BitLocker and the firewall must stay active: never disable them, even "temporarily".

🏬 Official sources only

Company Portal or Store for any new application.

⚠️ Device flagged "non-compliant"?

Contact IT quickly to avoid losing access.

Security · Ainos IT WikiIf in doubt: contact IT.

What Copilot can do for you

✍️

Draft

An email draft, meeting minutes, a document outline.

📝

Summarize

A long email thread, a document, a Teams meeting.

🔎

Find

Information across your files and messages, in plain language.

💡

Brainstorm

Ideas, an action list, a presentation outline.

Microsoft 365 Copilot app: “New chat” pane and “Message Copilot” box.
The Microsoft 365 Copilot app: side pane (Search, Library, Agents) and the “Message Copilot” box in the “New chat” view.
🔎Discover
ApplicationExample use
Outlook“Summarize this thread” · “Draft a polite reply to decline”
TeamsDuring/after a meeting: “What was decided and who’s doing what?”
Word“Draft a memo about…” then adjust the tone
Excel“Highlight the rows that concern me” · spotting trends
Copilot ChatOn m365.cloud.microsoft: ask a question about your documents

At Ainos, you’ll come across two experiences: both sign in with your work account firstname.lastname@ainos.lu and both benefit from Enterprise Data Protection (EDP).

Microsoft 365 Copilot ChatMicrosoft 365 Copilot
AvailabilityIncluded with the Microsoft 365 subscriptionDedicated license (assigned by IT)
SourcesGrounded on the web (Bing search)Web + your work data (emails, files, chats via Microsoft Graph)
Internal dataOnly if you provide it (attached file, “/”, Outlook, agent)Semantic index access to everything you already have rights to
ProtectionEDPEDP
🛡️
The green shieldA green shield shown next to “New chat” confirms that Enterprise Data Protection is active: your prompts and responses stay within the Microsoft 365 boundary and are not used to train the models.
⚠️
Don’t confuse the twoMicrosoft Copilot (personal Microsoft account) is meant for personal use and does not offer EDP. For work, always sign in with your @ainos.lu account.
📎

Attach a file

The “+” button or drag & drop (Word, Excel, PDF…) to summarize or analyze it. The file is stored in your OneDrive.

🖼️

Images

Generate an image from a description, or upload a photo to discuss it.

📄

Copilot Pages

Turn a response into an editable canvas you can share with others.

🕑

History

Find and pick up your previous conversations.

🐍

Data analysis

The code interpreter (Python) for calculations, charts, and visualizations.

🎤

Voice

Dictate your prompts and have responses read aloud.

🔒Use & privacy

A good prompt generally has 4 ingredients: a goal, some context, a source, and the expected format.

✅
Example“Write an email (goal) announcing that the Project Alpha meeting is postponed to Friday (context), based on Marie’s last message (source), cordial tone and max 5 lines (format).”

A few useful prompts

  • “Summarize the key points and action items in this document.”
  • “Which unread emails need a reply today?”
  • “Prepare an agenda for a 30-minute meeting about…”
  • “Rephrase this message to be more concise and professional.”

In the Microsoft Edge business browser, Copilot Chat is available in a side pane, handy for working on the page you’re viewing.

  • Open it: the Copilot icon in the top-right of the browser (shortcut Ctrl+Shift+.), after signing in with your @ainos.lu account.
  • Summarize a page: ask for a summary of the open web page or a displayed PDF.
  • Context: page content is only shared with your consent (“Allow access to this page”), for more relevant answers.
🔐
Data Loss Prevention (DLP)Edge for Business automatically applies company policies: internal content carrying a sensitive confidentiality label cannot be summarized by Copilot. The green shield at the top of the pane confirms EDP.
🔒
Good to knowCopilot only accesses content you already have access to (your emails, your files). Your work data is not used to train public models and stays within the company boundary.
Microsoft 365 Copilot Chat ArchitectureYour usersand devicesApplicationson your devicesWXPNMicrosoft 365 Service BoundaryMicrosoft 365 CopilotAzure OpenAI Servicefor Microsoft 365Large Language Model (LLM)Logging + audit/eDiscoveryYour tenantMicrosoft 365Bing searchservice34215
Path of a Copilot Chat prompt: everything is processed within the Microsoft 365 service boundary (the Bing web search stays anonymized).

How it works, in 5 steps

  1. Prompt — your request goes to the Copilot orchestrator, which coordinates Responsible AI controls and logs the exchange.
  2. Web grounding — if web search is enabled, only a few keywords are sent to Bing over a secure connection.
  3. Model (LLM) — the grounded prompt is sent to the large language model to draft the response.
  4. Logging — the prompt and response are recorded in your tenant (Exchange) for audit / eDiscovery.
  5. Response — after a final security check, the response is returned to you.
🚫
What is NEVER sent to BingNo user or tenant identifier, never your entire prompt (unless it’s two words long), no uploaded files, and no summarized pages / PDFs. Web queries are not shared with advertisers.

Your prompts and responses are not used to train foundation models and are not shared with OpenAI. Copilot supports GDPR; for the European Union, traffic stays within the EU Data Boundary (EUDB) — except for search queries sent to Bing.

🔗 See also
Copilot · Ainos IT WikiUpdated 2026
✅
Why it's safer than a passwordYour face, fingerprint, and PIN never leave the device and are never sent over the network. Your PIN only works on your PC: useless to a remote attacker. It's phishing-resistant.
Windows Hello sign-in options: PIN, facial recognition, fingerprint
PIN, facial recognition, or fingerprint — three ways to unlock your PC without a password.
🚀Setup
Open sign-in settings
Go to Settings → Accounts → Sign-in options. You'll see the available methods: facial recognition, fingerprint, and PIN (Windows Hello).
Accounts›Sign-in options Ways to sign in Facial recognition (Windows Hello) Sign in with your camera (Recommended) Fingerprint recognition (Windows Hello) Sign in with your fingerprint scanner (Recommended) PIN (Windows Hello) Sign in with a PIN (Recommended) Security key Sign in with a physical security key Password Sign in with your account's password
Settings → Accounts → Sign-in options (Windows Hello: face, fingerprint, PIN).
Create your PIN
Choose PIN (Windows Hello) then follow the wizard. An MFA check may be required (approve in Authenticator).
Add face or fingerprint
If your PC supports it, set up facial recognition or fingerprint for instant unlocking. Your PIN remains your fallback.

📌 Your PIN stays on the device

Unlike a password, the PIN is tied to this PC: it never travels over the network, so it's useless to a remote attacker.

😊 Biometrics are optional

Face and fingerprint speed up sign-in, but the PIN remains your fallback if recognition fails.

🔁 Independent from your password

Windows Hello keeps working even after a password change on the account.

🔒 Built-in protection

After several incorrect PIN attempts, the device locks (protection against repeated attempts).

💡Day to day

At startup, look at the camera or place your finger on the scanner — you're signed in. No password to remember. Even if you change your password, Windows Hello keeps working.

🛠️Troubleshooting

On the sign-in screen, click “I forgot my PIN”: after an MFA check, you'll be able to create a new one, with no reinstall needed. For the account password, see SSPR.

SymptomLikely causeSolution
“Windows Hello unavailable” / greyed-out optionPolicy still being applied, or PC not yet registered in Entra IDRestart, wait for setup to finish, then try again in Sign-in options. If it persists, contact IT
The fingerprint reader doesn't respondMissing driver or unregistered fingerRe-register your fingerprint (Settings → Sign-in options → Fingerprint), clean the sensor, update Windows
Facial recognition failsInsufficient lighting, IR camera obstructedImprove lighting, clear the camera, use “Improve recognition”; the PIN remains your fallback
PIN rejected after several attemptsProtective lockout after incorrect attemptsWait out the displayed delay, then use “I forgot my PIN” to reset it (MFA check)
The PIN stops working after an incidentSecurity component (TPM) resetRecreate the PIN via “I forgot my PIN”; no reinstall needed
📚 Learn more
Windows Hello · Ainos IT WikiUpdated 2026
💻New PC

Ainos work PCs are provisioned with Windows Autopilot and managed by Microsoft Intune. In practice: you unbox the device, sign in with your Ainos account, and everything configures itself — no manual installation.

New Ainos device: laptop and phone, then the Windows Autopilot flow — Ainos IT registers the device, it ships directly to the employee, who signs in for automatic deployment.
A new Ainos computer or phone comes pre-configured: IT registers the device in Windows Autopilot, it ships directly to the employee, who just signs in with their Ainos account — everything sets itself up automatically.
🧭
Step orderOn first start-up, everything runs automatically, in this order:
1Language & Wi-FiFirst screen at start-up
2Sign-in + MFAAccount surname.name@ainos.lu
3Automatic setupAutopilot + Intune — nothing to doAutomatic
4Windows HelloSet up your PIN / biometrics
5OneDriveCheck your files are backed up
Unbox, power on, pick language & Wi-Fi
On first start-up, select your language/region and connect to a stable Wi-Fi network.
Sign in with your Ainos account
Enter surname.name@ainos.lu and approve the MFA prompt. The device is then recognized by Windows Autopilot.
Let the automatic setup run
The “Setting up for work or school” screen prepares the device (securing hardware, joining the organization's network, Intune registration) then applies policies, certificates and apps. Nothing to install manually.
Setting up for work or school This will take a few minutes. Your device might restart. ⚙ Device preparation ● Completed Securing your hardware (Completed) Joining your organisation's network (Completed) Registering your device for mobile management (Completed) 🖥 Device setup Working on it… Security policies (1 of 2 applied) Certificates (No setup needed) Apps (Identifying…)
The “Setting up for work or school” screen: Autopilot prepares the device, then Intune applies policies, certificates and apps.
Set up Windows Hello
Create a PIN and enable face/fingerprint. → Windows Hello
Check OneDrive, Outlook & Teams
Check that OneDrive is signed in: your Desktop, Documents and Pictures folders are backed up there automatically (→ My files (OneDrive)). Outlook and Teams sync automatically.
🔑
What about a passkey?Once MFA is set up, also consider registering a passkey for faster, passwordless sign-in afterwards. → Passkey & FIDO — how to register it
📱New phone
Check your sign-in methods (MFA)
First, review your Security info so you keep access even if the old phone is no longer available.
Reinstall Microsoft Authenticator
Then re-add your account from your Security info, and remove the old phone from the list.
Choose BYOD or enrollment
Simplest option: install Outlook (BYOD). → BYOD · Company Portal
Install your apps
Outlook, Teams, OneDrive — sign in and create the work PIN.
♻️
Old deviceBefore returning or recycling a work device, tell IT so it can be removed cleanly (unenrollment / wipe). On a personal device, remove the work accounts.
New device · Ainos IT WikiUpdated 2026

Before you contact us

  • Check the FAQ.
  • Forgot your password? Use self-service (SSPR).
  • Note down the exact error message and roughly when it happened.

How to reach us

Outlook
Special request via Self-Service For any specific request (access, configuration, a case not covered below), use the "Special request" form on the Self-Service Portal.
Microsoft Teams

Chat with internal IT

A quick question, something to clarify, or a small nudge in the right direction? Message us directly on Teams — it’s often sorted in a few minutes, no form needed. For anything bigger, please use the form above instead.

Describe your issue clearly

🧭
For a faster reply, include:
  1. What you're trying to do
  2. What happens (error message, screenshot)
  3. Since when
  4. The device involved (PC / phone, personal / work)
🔐
SecuritySuspect phishing or a compromised account? This is priority: report it immediately. → Security & phishing
Support · Ainos IT WikiContact details to be confirmed with IT

Accounts & sign-in

MFAMulti-factor authentication: a 2nd proof of identity in addition to the password (e.g. approving in Authenticator). → MFA
SSPRSelf-Service Password Reset: resetting your own password without IT. → SSPR
Passkey / FIDO2Passwordless sign-in via fingerprint, face or a security key. → Passkey
AuthenticatorThe Microsoft app that validates your sign-ins (notifications, codes).
Conditional AccessRules that check every sign-in (device, location, risk). → Learn more
Entra IDMicrosoft's identity directory (formerly "Azure AD") that manages your Ainos accounts and sign-ins.
SSOSingle Sign-On: one authentication grants access to all your work applications, without re-entering your password.
Zero TrustPrinciple of "never trust by default": every access is verified (identity, device, context). → Conditional access

Devices Microsoft Intune

BYODBring Your Own Device: using your personal device for work. → BYOD
MDMDevice management (full enrollment via Company Portal). → Company Portal
IntuneThe Microsoft service that manages the organization's devices and apps (security policies, deployment, compliance). → Company Portal
MAMManaging only the work apps (BYOD mode), without controlling the phone.
ConteneurAn isolated work space on your device: your personal and work data never mix.
Compliance"In good standing" state for a device (lock code, system up to date…) required to access resources.
Company PortalThe app used to enroll and manage a device, and to install work apps.
Windows AutopilotThe service that automatically pre-configures a new PC the first time it signs in, with no manual setup. → New device
BitLockerHard drive encryption: without your credentials, its contents are unreadable, even if the device is lost or stolen. → Laptop
Windows HelloSigning in to a PC with a PIN, face, or fingerprint, without typing a password. → Windows Hello
LAPSLocal Admin Password Solution: a PC's local administrator password, generated and rotated automatically by Intune. → Laptop

Services

OneDriveYour personal work files in the cloud. → OneDrive
SharePointTeam sites and shared files. → Teams & SharePoint
TenantAinos's "Microsoft 365 space" (your accounts, data and policies).
CopilotThe AI assistant built into the Microsoft 365 apps. → Copilot
PhishingA fraudulent email that tries to steal your information. → Security
Microsoft 365Ainos's cloud suite: Outlook, Teams, OneDrive, SharePoint, Office and their services.
TeamsMeetings, calls and team chat. → Teams
🔗 See also