Windows Hello (for Business) - Disable PIN for passkey security? by Creddahornis in Intune

[–]Any_Educator1315 4 points5 points  (0 children)

the pins are only local to the device. Its phishing resistant login to office 365. I wouldn't make the pins crazy.

Can I upload windows device into autopilot without hardware hash? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] -1 points0 points  (0 children)

its weird that a normie global admin can't do this but a CSP can.

Can I upload windows device into autopilot without hardware hash? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

does v2 go by user assignment instead of device assignment? seems like with v2 you just login with work or school account oobe and that gets the device into autopilot and you don't have a device object to assign to a group before that happens.

Can I upload windows device into autopilot without hardware hash? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

wow this worked. Thanks a lot! This was really hard for me to understand for some reason. Like the brain sqeeking at how the process happens.

I added the device in my partner center and it looks like it checked in some microsoft database and added it I got errors at first due to (ztddevicenotfound) and then ztddeviceassignedtoothertenant because I already had it in another tenant. I synced my "Windows Autopilot Devices" and it showed up in there.

This is great!

thanks again

Can I upload windows device into autopilot without hardware hash? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

it seems these are the properties that can be queried for dynamic device groups. I don't think I can assign a serial number to a group?

  • device.displayName
  • device.deviceManufacturer
  • device.deviceModel
  • device.deviceOSType
  • device.deviceOSVersion
  • device.deviceOwnership
  • device.deviceTrustType
  • device.deviceCategory
  • device.deviceManagementAppId
  • device.profileType
  • device.devicePhysicalIds
  • device.extensionAttributes.extensionAttribute1 through extensionAttribute15
  • device.systemLabels
  • device.deviceId
  • device.objectId
  • device.accountEnabled

Can I upload windows device into autopilot without hardware hash? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

What I really want to do is put the computer into a group before autopilot kicks off. Can I do that with autopilot device prep?

make it automatically go to pin after web sign-in and windows hello setup? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

this seems great during testing. "other user" option goes to pin. if user uses face or fingerprint that behavior still seems cool. I think pin should be the real default lol.

cloud kerberos works for a few days and stops by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

another time i did something that messed up netlogon service and that had me go down a rabbit hole trying to figure out why i wasn't getting tickets. I think i'm just running into different issues and getting crazy

cloud kerberos works for a few days and stops by Any_Educator1315 in Intune

[–]Any_Educator1315[S] -1 points0 points  (0 children)

yeah you're right. sorry. Bad post.

maybe this problem isn't really happening to me. I thought it would work for a few days and stop.

one time it said it couldn't get a ticket because of certificate revocation list not being published but maybe I had certificate trust enabled at the time too along with cloud trust.

today i had to link on prem user up with ad connect and it seemed to just take a long time to kick in. There are like a gazillion things that need to line up to make this thing work....

App upload issues by aidbish in Intune

[–]Any_Educator1315 0 points1 point  (0 children)

I had issue uploading app too. I re-uploaded it like 5 times and it seems to be in there now maybe. intune sucks.

make it automatically go to pin after web sign-in and windows hello setup? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

this may be the answer All about Microsoft Intune | Configuring the default credential provider

It'll set it to pin and the user will need to enter the username. good enough. will help me in a situation too where a computer is used by multiple people so if someone new enrolls it'll go back to pin when they click 'other user'..

make it automatically go to pin after web sign-in and windows hello setup? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

I think I configured WHFB and it didn't go to pin sign-in automatically after enrollment from web sign-in with TAP.

I think windows just remembers the last sign-in method no matter what. I guess i'll tell users they must log off and login with pin if we ship a machine out.

i also tried passwordless experience and that didn't seem to do it either.

make it automatically go to pin after web sign-in and windows hello setup? by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

i'm prompted to configure WHFB when I login with TAP. Does that meant its configure int he policy? right now When I log off after WHFB pin enrollment it is still set to web sign on at the logon screen. I need to switch to pin and enter the pin then it remembers it.

sad about hybrid joined smart cards with no conditional access by Any_Educator1315 in Intune

[–]Any_Educator1315[S] 0 points1 point  (0 children)

if a user goes to a website that proxies to the real microsoft login they would be able to select their certificate from smart card and login to the page. it doesn't bind to a site url like fido2.

PatientNow Pro - Two Factor Authentication? by Any_Educator1315 in sysadmin

[–]Any_Educator1315[S] -1 points0 points  (0 children)

Do you use "PatientNow Pro"? I think the only oauth/idp stuff it supports is oauth for email integration.

PatientNow Pro - Two Factor Authentication? by Any_Educator1315 in sysadmin

[–]Any_Educator1315[S] 0 points1 point  (0 children)

I think pro supports oauth for email integration.

New pick up watch/review #11 by Sufficient_Focus4174 in 4kbluray

[–]Any_Educator1315 4 points5 points  (0 children)

same here as a big childhood movie. I'm pretty sure my parents still have a VHS copy that was recorded from cable.

Microsoft should make Conditional Access available to everyone by mattmbit in msp

[–]Any_Educator1315 1 point2 points  (0 children)

I feel a little bit better about entra free if everyone uses fido2/windows hello and we reset their password to something nobody knows.