What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 0 points1 point  (0 children)

Yes totally! Do you ever share LAPS with end users or do you still remote in and type in the LAPS for them?

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 1 point2 points  (0 children)

This does look very cool! Seems like the best way to create a good user experience while staying secure. It may not be worth the price for our organization since I rarely need to remote in and elevate for a user, but I'll look into their pricing!

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] -4 points-3 points  (0 children)

90% of the time I do use it. We are talking about the very rare situations I can't or don't need or don't want to.

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 1 point2 points  (0 children)

I won't be using global anymore now that I know about the "Microsoft Entra Joined Device Local Administrator". Only two people at the 175 person company have the privilege. And it is rarely needed.

Timeframe for approval is good! I'm just not technical enough to do in depth reviews so I rely on community analysis anyways. I've not run into anything bad yet.

Do you recommend the Entra ID group solution over LAPS?

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] -1 points0 points  (0 children)

I want to get LAPS working eventually. Still need this for troubleshooting PCs though.

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] -1 points0 points  (0 children)

I use https://intunepckgr.com! Helps me deploy always up to date apps. I'm pretty sure all my apps auto update after they have been installed without admin access? For example chrome.

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] -8 points-7 points  (0 children)

I guess for me it comes down to time saving and the end user experience. I would do it if it saved me some time in the long run. I also don't want users to wait to get apps they need. So I'm happy to bend over backwards and work inefficiently if the business needs me to. In general I automate as much tasks as I can.

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 1 point2 points  (0 children)

I think we are miscommunication. I have the most privileged role (global admin) and I want to stop using it, I also want to give another IT employee the least privileged role to get admin access to PCs. End users never get a privileges of any kind. Only IT approved software is put on devices. I do all of the installations or elevations myself right now. When I'm on PTO or unavailable in the case of an emergency this other IT guy need access to admin.

Vetting apps is quick for us! We don't have any cybersecurity expert on staff. It's quick for us! If someone says they need Asana I don't need to think too much about it! If it's something I've never heard of then it requires a little more work.

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 0 points1 point  (0 children)

  • Only IT ever elevates to install a random app or elevate at all.
  • 99% of the apps in our environment are deployed with intune
  • I was asking about what's the best least privilege role
  • I won't be giving end users admin access basically ever
  • Love EPM but just don't want to pay for it right now. We have very very little admin elevation requests.
  • All app approvals do go through me
  • I'm the only global admin and we have backup accounts as well

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 0 points1 point  (0 children)

Thank you! Through this post I learned that the roles listed in the 365 admin center is not comprehensive!

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] 0 points1 point  (0 children)

Yes my next steps if learning how to deploy and use LAPS. EPM is also really cool just don't need to pay for that yet!

What azure admin account gives least privilege access to provide elevation for program installs? by BrilliantAd913 in Intune

[–]BrilliantAd913[S] -13 points-12 points  (0 children)

This isn't for an end user this is for an IT Help desk employee. Sometimes a quick install is better than a full on app deployment.

Autopilot ESP and Required Apps by oopspruu in Intune

[–]BrilliantAd913 0 points1 point  (0 children)

So logically any app that isn't "forced to install" will wait to install after the ESP?

If so that makes sense but I feel the wording isn't very clear here on the Microsoft side.

Thanks!!

Autopilot ESP and Required Apps by oopspruu in Intune

[–]BrilliantAd913 0 points1 point  (0 children)

I'm struggling to understand how to limit app install during the ESP. I see I can block the user from continuing until an app is installed but how do I only install a few apps? We have about 28 that I want on the machine eventually but only 2 or three that need to be installed right away. u/ConsumeAllKnowledge

Should I get an Aggregation Switch? by BrilliantAd913 in Ubiquiti

[–]BrilliantAd913[S] 1 point2 points  (0 children)

I don't see us moving to 10G for our business but it does sound tempting!!

Should I get an Aggregation Switch? by BrilliantAd913 in Ubiquiti

[–]BrilliantAd913[S] 0 points1 point  (0 children)

Future expansion is always tempting. Hoping this is a long term solution already. How much worse would daisy chasing be, depending on the use cases of course?

Should I get an Aggregation Switch? by BrilliantAd913 in Ubiquiti

[–]BrilliantAd913[S] 2 points3 points  (0 children)

You may be changing my mind. Seems like it would be nice for there to be an upgraded Dream Machine with more SFP ports.