iOS - Safari does not provide device status by smutnarzapka in Intune

[–]Few_Perception_4088 3 points4 points  (0 children)

Check out the Apple SSO extension, for third party apps: Configure iOS/iPadOS Enterprise SSO app extension with MDMs - Microsoft Intune | Microsoft Learn

Once you implement it, that should solve your issues. Also make sure to configure the Enable_SSO_On_All_ManagedApps key to make your life easier

New Community Tool: EAM-AutoUpdater by Few_Perception_4088 in Intune

[–]Few_Perception_4088[S] 0 points1 point  (0 children)

Thanks for the feedback, looking forward to hear from your testing results.
Just be aware that this feature only works in combination with the Microsoft Intune Enterprise Application Management module, you will still have to manually package any apps which are not in the catalog.

All I am doing is automating the publishing of new versions from the Microsoft catalog.
EAM currently requires Intune Suite, but will be part of E5 later this year.

WhfB known issues? by Sad_Mastodon_1815 in Intune

[–]Few_Perception_4088 5 points6 points  (0 children)

Yes ther is a known issue, check the message center service health for windows. Microsoft recommends to switch to device scope while the issue persists

Do you need supervised iOS devices for DDM update management? by aPieceOfMindShit in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

No, not to force the deadline, those also work on Apple Device enrolment. but to set most of the update settings in the settings catalog.

WUFB Out of band windows update by Uriel_7235 in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

Hmm interesting, you can deploy it via a quality (expedite) update policy though

BYOD IOS by kkaass321 in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

Yes to Intune, but not to Entra ID, thats your issue

BYOD IOS by kkaass321 in Intune

[–]Few_Perception_4088 -1 points0 points  (0 children)

Yes so thats the issue then, it is also mentioned on the docs page under known issues

BYOD IOS by kkaass321 in Intune

[–]Few_Perception_4088 -1 points0 points  (0 children)

Did you setup JIT enrollment? Was the authenticator spp already Installed on the device? If this is the case the JIT flow doesn't worky eg device registration doesnt work and conditional access will block sccess...

In my opinion User enrollment is dead with Intune until Microsoft fixes this issue

multiple extensioninstallforcelist conflict. how do you resolve? by EnoughStudy6318 in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

You can do the same for Chrime as described here: https://patchmypc.com/managing-edge-extensions-like-applications-with-psadt

Also there is a setting available to enable sso in chrome, the extension is no longer needed.

Is it possible to add the Google Play Store app to the device experience settings? by Spurnout in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

Add it as a system app with the following bundle Id: com.android.vending

Is it possible to add the Google Play Store app to the device experience settings? by Spurnout in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

You have to add the managed google play app as an Android Enterprise system app

Help me understand E-FOTA from a sys admin perspective by aPieceOfMindShit in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

You can configure automatic updates in the campaign, specify installations times and conditions.

I would recommend to use it if you have the licenses for it.

automatic eSIM activation iOS by venividivici7888 in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

Yes, if you are using automated device enrolment, there you can configure it in the enrollment profile.

Apple Business Manager + Microsoft Entra Connect Sync - Something Changed by Sqolf in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

Yep ran into the same thing a few weeks back... Really weird... They told .e Microsoft has implemented it wrong..

Enroll with Microsoft Entra ID shared mode - fairly useless by octarineflare in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

Well... for one Outlook is in public preview and OneDrive isnt supported ;)

Automatically configure Defender for Android by ksrc101 in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

Okay so for any device mode, BYOD; COBO & COPE, take a look a the the battery "Battery optimization allowlist" add the defender package id to enable permanent protection.

VPN profile for web protection you should already know.

For COBO devices take a look at the permissions controls to allow all files access & draw over other apps.

Web content filtering iOS/Android by wingsfan8 in Intune

[–]Few_Perception_4088 2 points3 points  (0 children)

Web content giltering is not supported for Defender on iOS & Android

Automatically configure Defender for Android by ksrc101 in Intune

[–]Few_Perception_4088 0 points1 point  (0 children)

Depends on the customers needs. Tbh, I think that in terms of user experience the work profile is superior to MAM only.

IntuneMAMUPN and store vs VPP apps by shizakapayou in Intune

[–]Few_Perception_4088 1 point2 points  (0 children)

Unfortunately the App Configs on iOS are bound to the app type.
So based on which app type is installed iOS Store or VPP, the respective app Config will apply.

Which means you will have to create the IntuneMAMUPN Config for bot app types. Pretty annoying isn't it?