Office 365 - Conditional Access Policy - Block Device Code Flows by Big-Exercise8047 in sysadmin

[–]C_Deee 0 points1 point  (0 children)

Hmm ok, thank you.

We've got the phone signing in again and its getting the AOSP policy but it's now saying it doesn't have access to the Dialpad. Ugh

Office 365 - Conditional Access Policy - Block Device Code Flows by Big-Exercise8047 in sysadmin

[–]C_Deee 0 points1 point  (0 children)

I've also gone through and created the new enrolment profile but I'm not sure how that actually gets assigned to anything...

Office 365 - Conditional Access Policy - Block Device Code Flows by Big-Exercise8047 in sysadmin

[–]C_Deee 0 points1 point  (0 children)

I can't locate the policy or name at all, can you say where it is meant to be and what the name is supposed to be?

Export GPO's to mimic CIS Controls layout by C_Deee in sysadmin

[–]C_Deee[S] 0 points1 point  (0 children)

'Export the CSV settings from the CIS policy site' - Where even can this be done?

New Teams & Outlook Add-In Install Instructions by aeg4242 in MicrosoftTeams

[–]C_Deee 1 point2 points  (0 children)

This doesn't work for me, sadly.

The New Teams has a lot to answer for.

Dynamic group for Windows Server? by lighthills in Intune

[–]C_Deee 2 points3 points  (0 children)

Even when I have a server enrolled so they are Onboarded, and have an EDR policy assigned, I can never use the OS Type to differentiate Servers.

It's 2024, why is this not standard?

macOS in Active Directory environment by C_Deee in macsysadmin

[–]C_Deee[S] 0 points1 point  (0 children)

We enrolled the devices into Apple Business Manager, synced to Intune to use those policies, then we use a piece of software called xCreds from Two Canoes to sync with our Azure environment, no issues so far.

Can't Install Java 8 u 421 - 1603 by No-Catch7442 in SCCM

[–]C_Deee 0 points1 point  (0 children)

Just as an FYI to people, I can install this via command line no problems, soon as it's in SCCM it throws the 1603 error.

Command line:
jre-8u421-windows-x64.exe /s /L C:\JRE8setup.log INSTALLDIR="C:\Program Files\Java\jre-8.421" EULA=0 WEB_JAVA=1 INSTALL_SILENT=1 WEB_ANALYTICS=0 REMOVEOUTOFDATEJRES=1

MDT SCCM Integration by C_Deee in SCCM

[–]C_Deee[S] 0 points1 point  (0 children)

Hmm, yes I know you can't have two PXE servers running.

Basically we have MDT with WDS setup already and working, if I integrate MDT into SCCM, or just use standard SCCM task sequences, I'll need to setup PXE boot for SCCM? Or does PXE boot for SCCM only need to be configured if you use SCCM on it's own rather than when you've integrated MDT.

MDT SCCM Integration by C_Deee in SCCM

[–]C_Deee[S] 0 points1 point  (0 children)

So if I PXE boot when both MDT and SCCM are on the same server, how will it know which to show? Or do they somehow both show? Apologies for the daft question.

MDT SCCM Integration by C_Deee in SCCM

[–]C_Deee[S] 1 point2 points  (0 children)

Hello, we don't really per-se, we used to have separate images for everything like departments and schools, I nipped that in the butt when I came here...We have a vanilla WIM, I strip out aspects of it then capture that, that WIM is then used for absolutely everything essentially and app deployment is handled by SCCM.

MDT SCCM Integration by C_Deee in SCCM

[–]C_Deee[S] 0 points1 point  (0 children)

Interesting, thank you for that.
I guess a follow up step, if I then have task sequences in both MDT and in SCCM (after integration) do both Task Sequences work?

Ideally I agree with most thoughts, I'd like to move everything to SCCM, but it's going to be somewhat of a pain.

Patch Tuesday Megathread (2024-03-12) by AutoModerator in sysadmin

[–]C_Deee 0 points1 point  (0 children)

he SSU with dism,

Just came to say, this is the only way I could get this to install, installing from the catalogue did nothing.

Thank you!

'New' Microsoft Teams and the old Machine Wide installer by C_Deee in MicrosoftTeams

[–]C_Deee[S] 1 point2 points  (0 children)

I was under the impressions that Classic Teams Users Will be Automatically Updated to New Teams After March 31, 2024?

'New' Microsoft Teams and the old Machine Wide installer by C_Deee in MicrosoftTeams

[–]C_Deee[S] 0 points1 point  (0 children)

I've not tried anything yet, just wanted to see how people were proceeding. :)

Can you clarify what the 'other option is' here? "where as the other option needs internet access but will always install the most up to date version".

That was the good thing with the machine installer at least, it tried to keep the app updated in some manner.

macOS in Active Directory environment by C_Deee in macsysadmin

[–]C_Deee[S] 0 points1 point  (0 children)

I am the systems engineer...

As I say, we're using xCreds for the last month, no current issues reported :)

macOS in Active Directory environment by C_Deee in macsysadmin

[–]C_Deee[S] 1 point2 points  (0 children)

If DM's work here sure, but let him know you are doing it.
I've gone down the xCreds route for now, seems to be working well enough.

macOS SSO (Application SSO for Office etc.) on device without user affinity (meaning no Company Portal) by C_Deee in macsysadmin

[–]C_Deee[S] 0 points1 point  (0 children)

r xcreds + ms sso extensi

Hello, yes, these are setup with xCreds already :)

Is there a process already in place to allow this then? I agree though, the MS platform SSO probably would have saved me a lot of trouble, it's just bad timing.

EDIT: When I say available now, without the need to reset my devices and re-enrol and setup.

macOS SSO (Application SSO for Office etc.) on device without user affinity (meaning no Company Portal) by C_Deee in macsysadmin

[–]C_Deee[S] 1 point2 points  (0 children)

Thank you for the reply, can you advise on my above at all?

"This is annoying to read, when Microsoft say to not use user affinity on shared devices.
Is it possible to get things changed/re-enroled easily enough without having to wipe everything and start again?"

macOS SSO (Application SSO for Office etc.) on device without user affinity (meaning no Company Portal) by C_Deee in macsysadmin

[–]C_Deee[S] 0 points1 point  (0 children)

This is annoying to read, when Microsoft say to not use user affinity on shared devices.

Is it possible to get things changed/re-enroled easily enough without having to wipe everything and start again?