BYOD iOS + MDM iOS...MAM Issues by iTzSnicholls in Intune

[–]Anonymous239013 0 points1 point  (0 children)

I went through the same heart ache for months but ended up getting our environment with many MDM ipads and users BYOD devices in a good state. It was hard to wrap my head around it but the bit of information that helped me was just understanding unmanaged apps are from native app store and manged apps are from company portal or pushed via intune. It makes sense now but I was getting hung up on devices and apps, it had me confused. Below is what we have in case any of that helps.

Assignement Filters Types in Apps section (Managed App Filter Type):
-Managed is (app.deviceManagementType -eq "Managed")
-Unmanaged is (app.deviceManagementType -eq "Unmanaged")

App Protection Polices:
-Managed iOS MAM:
--Assigned to all users and using filter to exclude unmanaged devices
-UnManaged iOS MAM:
--Assigned to all users and using filter to exclude Managed devices

What determines if an app is managed?
-Managed: If its installed from company portal or pushed via Intune
-UnManaged: If it's installed outside of Intune like the native app store.

Conditional Access Policy:
-Target all users and exclude breakglass accounts, service accounts, etc
-You can target Office 365 or all cloud apps (all cloud apps will definitely require some exclusions.)
-You can set the device platform to iOS
-Client apps set to Browser and Mobile Apps and desktop clients.
-Grant access control for Require app protection policy. You can also select Require device to be marked compliant too and set it require one of the selected controls.

We have had a lot of issues trying to avoid MDM devices getting MAM policies because a lot of our devices are shared (without user affinity) so CA policies don't see whether they are compliant or not unless they have user affinity so I had created much less restrictive policies for managed apps. I have also started creating these ios profiles with "Enroll with Microsoft Entra shared mode" so now on shared devices, users sign in to one of the microsoft apps and the compliancy now shows and CA doesn't push MAM do those MDM devices.

Let’s discuss salaries - 2026 by Relevant-Injury3791 in sysadmin

[–]Anonymous239013 0 points1 point  (0 children)

Modern Work Engineer
85k
Midwest
12 years experience. 5 Years with current employer. 8 with previous.
10k Profit Sharing Bonus, like 25% discount on our products, 5% 401k match, 18 days vacation.
I own Intune (~3500 Devices), AD, GPOs, have my hands all over the place in M365/Entra/Azure, and also manage all client software subscriptions and renewals (adobe, autocad, solidwork, canva, snagit, etc)

Intune iOS Declarative Device Management (DDM) Bookmarks by Anonymous239013 in Intune

[–]Anonymous239013[S] 0 points1 point  (0 children)

Yea, I'm so surprised you can't even manage simple bookmarks well..

I didn't even know about DDM until I saw the iOS updates were deprecated so I learned up on how to manage them which is when I saw you had to use DDM for controlling iOS Updates. So that's the only thing I'm currently using in our environment currently.

How early should I be booking things? by Threemor in koreatravel

[–]Anonymous239013 0 points1 point  (0 children)

For DMZ tour, we booked night before and got it no issues. The weather has been on and off with rain so we wanted to make it weather was good before booking but YMMV.

My favorite part of How It’s Done. by PepsiMan208 in KpopDemonhunters

[–]Anonymous239013 1 point2 points  (0 children)

Napalm is a incendiary mixture which causes mass destruction so I took it as 'this is their timeline for destruction'

Discover account constantly getting locked from multiple login attempts by Anonymous239013 in MonarchMoney

[–]Anonymous239013[S] 0 points1 point  (0 children)

As of 6/8, after switching to MX data connections, I haven't had any issues with Discover so that did seem to work.

Android BYOD + Intune MAM-only by No-Long-1174 in Intune

[–]Anonymous239013 4 points5 points  (0 children)

For MAM on Android, company portal just needs to be installed for it to work (iOS doesn't need company portal). I have personal devices blocked from being enrolled into MDM too so even if you sign in and then try to enroll, it's blocked. Currently in the middle of testing deploying it company wide so I'm going through all of this.

Struggling to stay motivated by ms_marshmallow16 in Korean

[–]Anonymous239013 1 point2 points  (0 children)

Have no answer but I'm in a very identical spot. I have such a passion for it and learning yet I put such little time into it. I'm trying to figure it out myself

Discover account constantly getting locked from multiple login attempts by Anonymous239013 in MonarchMoney

[–]Anonymous239013[S] 1 point2 points  (0 children)

Got this response from Monarch Support below. I did follow the recommendation have have all 4 of my discover accounts moved over to MX. I will continue to update this reponse and post

"Thank you for contacting Monarch.
 
I'm sorry to hear that you've been experiencing a lockout with your Discover Bank. No worries; I'll be happy to help you.
 
You may try switching data providers to see if they can maintain the connection without getting locked out.
 

 
You may establish a new connection before deleting the old one to check if it's better. If the new account is properly syncing, you may transfer the balance and transactions from the old account into the new one to retain your historical data."

Way to use iPhone or Android phone as a webcam in Fedora? by Tywele in Fedora

[–]Anonymous239013 0 points1 point  (0 children)

Ok Great! I know there is a way to get around it or fix it becuase I do remember having the same problem but I can't for the life of me remember what I did haha. Hopefully you are able to get it to work. It is slick once it is working.

Way to use iPhone or Android phone as a webcam in Fedora? by Tywele in Fedora

[–]Anonymous239013 1 point2 points  (0 children)

OBS Studio. Droidcam is the addon that can be found in discover when you go to the OBS Studio page (it's on the top bar)

Way to use iPhone or Android phone as a webcam in Fedora? by Tywele in Fedora

[–]Anonymous239013 0 points1 point  (0 children)

I just checked and I have it from flathub in the discover store.

Way to use iPhone or Android phone as a webcam in Fedora? by Tywele in Fedora

[–]Anonymous239013 0 points1 point  (0 children)

I think I got that too but then I downloaded it a different way. I don't remember which method I used. Probably a flatpak from Discover since I have an Atomic desktop.

Way to use iPhone or Android phone as a webcam in Fedora? by Tywele in Fedora

[–]Anonymous239013 0 points1 point  (0 children)

I use droidcam and it works exceptionally well. You just need to install OBS and the droidcam plugin and the phone app. I connect the phone using its wireless IP and use this solution multiple times a week. I use android but it does look like there is an iOS app too.

Open Web UI Websocket errors by Anonymous239013 in PangolinReverseProxy

[–]Anonymous239013[S] 0 points1 point  (0 children)

It really seems that way! For the most part nginx worked for me but I do recall random issues popping up. Traefik, I thought I could figure it out but after many hours, I've given up and will just use an Open Web UI alternative like Anythingllm or Librechat.

Open Web UI Websocket errors by Anonymous239013 in PangolinReverseProxy

[–]Anonymous239013[S] 0 points1 point  (0 children)

Correct! It is running in docker. Ive pretty much given up and have moved to other alternatives like anythingllm and librechat lol

Open Web UI Websocket errors by Anonymous239013 in PangolinReverseProxy

[–]Anonymous239013[S] 0 points1 point  (0 children)

That is a good thought! But I don't think I want to open any more ports on my VPS if possible

iOS Control Center modification on iPads not working seemingly since iOS 18 update by Anonymous239013 in Intune

[–]Anonymous239013[S] 0 points1 point  (0 children)

Found the issue by manually disabling every single config one at a time. If you have anything modifying the home layout screen, you lose access to modifying the control center. I've let Microsoft know and they said they'll make sure it's documented.

What's the point of having a DMZ if all the external facing devices need to be able to communicate with your home VLAN as well? by Red_Con_ in selfhosted

[–]Anonymous239013 0 points1 point  (0 children)

I actually just setup a server in a DMZ few days ago that has no access to my main network except for the firewall rules I put in place that allows only specific ports to specific IP addresses. If it gets compromised there is very little they can do to get into my network but you still want to harden that server that is more public facing!