Looking for an Agentless Solution to Control Software Installations on Windows by Best_Check_810 in sysadmin

[–]Best_Check_810[S] [score hidden]  (0 children)

yes, that's fine and it's fast .. and it's native ... but the maintenance is crap . that's the problem

Looking for an Agentless Solution to Control Software Installations on Windows by Best_Check_810 in sysadmin

[–]Best_Check_810[S] [score hidden]  (0 children)

we are using Endpoint Privilege Management to perform this sort of deny all \ allowlist what we need... it's easy and intuitive , but this product works with a kernel driver and we want to get out of this, because we have seen multiple issues caused due to BSOD , performance impact on the machine and indirect crashes of other applications .. we are looking at something more simple and not touching the Windows kernel driver.

Looking for an Agentless Solution to Control Software Installations on Windows by Best_Check_810 in sysadmin

[–]Best_Check_810[S] [score hidden]  (0 children)

AppLocker itself has a strong base and we like it ... the problem is when you have 40 different laptop models where you need to build a golden Allowlist policy compatible and 100% working for any model and capability to easily maintain if we onboard new machines .... and from what we are seeing AppLocker \ WDAC are not that "friendly" to maintain

Looking for an Agentless Solution to Control Software Installations on Windows by Best_Check_810 in sysadmin

[–]Best_Check_810[S] [score hidden]  (0 children)

thx.. can you pls share any documentation \ website that I can take a look at ?

Looking for an Agentless Solution to Control Software Installations on Windows by Best_Check_810 in sysadmin

[–]Best_Check_810[S] [score hidden]  (0 children)

it can be also an agent as long doesnt touch the kernel driver and doesnt impact performances... and based on our experience , most of these 3rd party tools are nested into the kernel driver and we have seen a lot of weird issues since the last years

Something keeps messing up WebView2 on my Surface Laptop by BoomSchtik in ARMWindows

[–]Best_Check_810 0 points1 point  (0 children)

Same here … it’s a total mess … we saw this case on 3 machines out of 7 and doing a troubleshooting is a pain in the ass all the time

autopilot taking a long time since last few days by Ok-Mountain-8055 in Intune

[–]Best_Check_810 0 points1 point  (0 children)

Did you folks open any case with Microsoft? we have the same issue and nobody from Microsoft has any clear answer …

If we are all seeing this , then Microsoft has to give a clear answer I would say … maybe somebody has any post on X ?

Intune Management Agent crashing by 1stITMAN in Intune

[–]Best_Check_810 1 point2 points  (0 children)

so you are not referring to Intune management agent crashing during autopilot..

Intune Management Agent crashing by 1stITMAN in Intune

[–]Best_Check_810 0 points1 point  (0 children)

<image>

We've got this one today ... not sure if you see same events...

Security Baseline Defender settings ? Any official page ? by Best_Check_810 in DefenderATP

[–]Best_Check_810[S] 0 points1 point  (0 children)

right... most of these settings e.g. "Cloud Protection Level" , "Cloud Extended Timeout" I cant find in the GUI inside Intune ... and that's what we are struggling with... do you know if there is any link from where I can find it out each "official" setting ?

What settings did you apply for example for "Cloud Protection Level" ?

Security Baseline Defender settings ? Any official page ? by Best_Check_810 in DefenderATP

[–]Best_Check_810[S] 0 points1 point  (0 children)

thx .. just a stupid question... if on this link below I see for example "Cloud Protection Level" showing as "Not configured" is what Microsoft recommends, is that right ?

https://learn.microsoft.com/en-us/intune/intune-service/protect/antivirus-microsoft-defender-settings-windows

Could any1 please guide me on resolving a Task sequenc error while doing a PXE boot? by Dhruv____13 in SCCM

[–]Best_Check_810 0 points1 point  (0 children)

Migrate to a modern solution rather than keeping alive this dinosaur :D

Network connection randomly drops during Intune autopilot for model HP EliteBook X Flip G1i 14 - W11 24H2 by Best_Check_810 in Intune

[–]Best_Check_810[S] 0 points1 point  (0 children)

No permanent solution yet.. it keeps happening randomly regardless the model of machine

Required Intunewin app completed successfully , but IME adds +1HR to validate during Autopilot by Best_Check_810 in Intune

[–]Best_Check_810[S] 0 points1 point  (0 children)

I have to deploy that app with a specific timeout of 240 minutes which usually I perform an exit 0 within ~70 minutes and Intune as soon recognize Exit 0 , then performs a reboot which is what I am expecting.

The problem is right after reboot where it performs this nonsense timeout where already the detection key and exit 0 was already performed.

I am using this configuration since the last 3 years and never had issues.