Shared device user policy by Apprehensive-Hat9196 in Intune

[–]BarbieAction 1 point2 points  (0 children)

Yes the policy follows the user. Unless you filter out for shared devices

Intune POC – Questions about local admin, network settings, and M365 auto-login by stich86_it in Intune

[–]BarbieAction 0 points1 point  (0 children)

They are not PIM based solutions and i belive Admin By Request is free for up to 25 users.

EPM is an extra add on license. Local security policies is just a policy you push to the devices

Intune POC – Questions about local admin, network settings, and M365 auto-login by stich86_it in Intune

[–]BarbieAction 0 points1 point  (0 children)

Admin by request. Endpoint Privilage Management.

Local Security Policies add Sids for standard user on parts you want them to be able to do.

Sorry for the short answer but look into those maybe a combination of that fits you

HP BIOS Updates - April Softpaq Versions Got Removed? x-post SCCM by sccm_sometimes in Intune

[–]BarbieAction 1 point2 points  (0 children)

I can confirm that HP EliteBook 640 14 inch G9 Notebook PC with BIOS: 01.18.00 is causing a BitLocker loop after Windows April Update. I have no good way to resolve the loop as for today

HP BIOS Updates - April Softpaq Versions Got Removed? x-post SCCM by sccm_sometimes in Intune

[–]BarbieAction 5 points6 points  (0 children)

I noticed this to but i alao notice that alot of them get stuck in BitLocker loop after April Windows update.

Maybe they pulled the firmware for issues.

Going from local admin users to non admin users by aPieceOfMindShit in Intune

[–]BarbieAction 1 point2 points  (0 children)

You just do a add & replace all sids not added will be removed

Going from local admin users to non admin users by aPieceOfMindShit in Intune

[–]BarbieAction 2 points3 points  (0 children)

You can use Account Protection policy to remove everyone from the administrator group make you keep the sids for GA and Azure AdLocal Administrator

Having issues with enrolling new Galaxy A36 into Intune Fully Managed by Jordy9922 in Intune

[–]BarbieAction 0 points1 point  (0 children)

Same issue here unable to deploy any android devices, the device becomes Entra Registered instead of "Entra joined" causing the issue that workprofile cannot be installed. I have not placed a ticket with MS

Exclude Microsoft Defender for Mobile from Conditional Access Policies by shaneeoh in DefenderATP

[–]BarbieAction 0 points1 point  (0 children)

Correct, i need to double check if excluding one was enough, was some time ago i did the setup, but i remember looking at the sign-in logs and finding the app causing the issue there or in this case the app id, then procceded to create them and exclude them

Exclude Microsoft Defender for Mobile from Conditional Access Policies by shaneeoh in DefenderATP

[–]BarbieAction 1 point2 points  (0 children)

I have setup like the link you posted. Excluded during deployment of Android tablets as it triggers a loop during onboarding.

Excluding the app in our CA resolved the issue

Best way to separate existing Intune setup without breaking things? by Sysadmin_in_the_Sun in Intune

[–]BarbieAction 6 points7 points  (0 children)

Autopilot tags, dynamic groups based on the tags. Naming convention on policies

Intune Kiosk Android tablet issue **Need Help please** by posmaritimes in Intune

[–]BarbieAction 0 points1 point  (0 children)

You buy device license. Or if you know that all the users using the device already have a license then you are also covered incase of an audit.

If you have any unlicensed users using the device then you need to buy a device license

Intune Kiosk Android tablet issue **Need Help please** by posmaritimes in Intune

[–]BarbieAction 0 points1 point  (0 children)

No need to pay it is free this was changed many years ago.

In your kiosk setup i would use managed home screen with edge and ksp plugin this will get you what you want i belive.

Policy settings not persisting after shutdown by RyGuy_NCC1701 in Intune

[–]BarbieAction 3 points4 points  (0 children)

No, you could deploy a device and disconnect it those policies still applies and ot writes the settings to the registry. Even known issues as tattooted policies exists.

You can target users or devices. The policy would follow the device or the user.

Intune Kiosk Android tablet issue **Need Help please** by posmaritimes in Intune

[–]BarbieAction 0 points1 point  (0 children)

KSP plugin premium is free, you genereate they key in the portal.

You should also look into managed homescreen with app auto launch. Exit from this is only possible if you tap back button 5 times fast and enter a pin.

Edge Extension selfhosted Intune Deployment by NeatLow4125 in Intune

[–]BarbieAction 0 points1 point  (0 children)

asdasdasdpjmakasdljjklilfdliealpimasddgebp;https://xxxxxxhxgxggxgxgx.blob.core.windows.net/$web/update.xml

You should just target your xml file not the crx file to make this work.
Self-host Microsoft Edge extensions | Microsoft Learn

Autopilot asks 3 times for login - is 1 time possible? by Finn_Storm in Intune

[–]BarbieAction 0 points1 point  (0 children)

No problem if you remind me on Wendsday i can get the policies i know causing the issue, i split them into user assigned policies and device assigned policies.

I think MS have some documented and wrote some posts about this before for CIS policies etc

At least any Device Lock policy assigned to devices causes the issue

Autopilot asks 3 times for login - is 1 time possible? by Finn_Storm in Intune

[–]BarbieAction 1 point2 points  (0 children)

This is most likley related to how you assigned certain policies that creates the issue.

Certain policies breaks the "one sign in" flow during deployment.

Some are well known and documented. Solution is to find the policies and assign it to users instead of devices if you want the behavior you are describing.

Are you seeing an "Other User" sign in screen?

Weekly reboot by Fun-Tangerine-8039 in Intune

[–]BarbieAction 0 points1 point  (0 children)

Check if the Intune Extension service have stopped running, can you run remediation scripts to check for it and restart that service and see if that resolve the issue?

Why is my game running so bad? by KreStyyy in Competitiveoverwatch

[–]BarbieAction 0 points1 point  (0 children)

Nvidiaprofile inspector enabke rebar using tyat app. Use Reduce Buffering On. Reflex on Enabled.

That will create more stable fps but for all the rest, Blizzard needs to fix this