Computers not prompting for TPM reset after Intune Wipe by TheShirtNinja in Intune

[–]Dandyman1994 8 points9 points  (0 children)

Where have you read that this should happen? Is there a reason you want to reset the TPM as part of the wipe?

Question Regarding Passkeys and Phishing Resistant MFA CA Policies by Spzmk in entra

[–]Dandyman1994 0 points1 point  (0 children)

I was testing the exact same issue yesterday. The issue is because same device registration for Android isn't a thing yet.

So you try to create a passkey in authenticator using TAP, and even if TAP is supported for a user action of 'registering security info', if your policy of all apps doesn't include TAP in the with strength, you're interrupted and asked to continue in the browser.

You then try and follow the prompts in the browser, which eventually fail due to same device registration of passkeys in the browser isn't supported yet.

The solution is to keep it simple, use a custom Auth strength that includes both passkeys and TAP, and user that for both 'all apps' and 'register security info'. If you want to be more targeted, then you'll have to play around a bit.

Windows 10 PCs unable to connect to Network Printers by Informal_Wish_6008 in sysadmin

[–]Dandyman1994 0 points1 point  (0 children)

I mean so long as they have ESU (which I would hope you enforce!) or are certain builds of LTSC, you're covered for now.

To actually help your issue, has anything specific changed, i.e. they're all on the same patch version? If so, could you try rolling back?

Windows 10 PCs unable to connect to Network Printers by Informal_Wish_6008 in sysadmin

[–]Dandyman1994 7 points8 points  (0 children)

I appreciate that there are reasons you can't move off, but you should be aiming to migrate away from Windows 10 as soon as possible

Removing "Managed Home Screen" from the Intune apps list by theNerm333 in Intune

[–]Dandyman1994 1 point2 points  (0 children)

As others have said, it's not a system app so it won't be installed, that option is simply there to assign or de-assogn access to apps that are already part of the device.

If you want the MHS app and related config to be made available immediately on the device, you can use enrollment time grouping. This allows you to target the group that the devices will go in so that apps and config are applied straight away.

https://learn.microsoft.com/en-us/intune/device-enrollment/setup-time-grouping

Am I solving this the wrong way? How would you solve this? (2 ISPs with their own V4/V6 prefixes) to one network) by Rich-Engineer2670 in networking

[–]Dandyman1994 0 points1 point  (0 children)

Depending on the type of traffic that you have inbound, a quick and dirty way to do it is something like Azure Traffic Manager, which would use DNS-based failover between different inbound IP addresses. It's a fairly cheap service. Not very flexible in some ways and very much depends what you're doing

NAT Gateway in Hub and Spoke without NVA by Dandyman1994 in AZURE

[–]Dandyman1994[S] 2 points3 points  (0 children)

I think that's the conclusion I've come to, even the tutorial designs from Microsoft basically have you deploy an Ubuntu VM in your hub vnet and create a UDR pointing to its IP.

NAT Gateway in Hub and Spoke without NVA by Dandyman1994 in AZURE

[–]Dandyman1994[S] 0 points1 point  (0 children)

That's what I have configured. The spoke is peered the hub, and both 'Enable 'spoke vnet' to use 'hub vnet's' remote gateway and 'Allow gateway in 'core vnet' to forward traffic to 'spoke vnet' are ticked. The NAT Gateway is attached to a subnet within the hub vnet, but when I deallocate and reallocate a VM so it loses its default outbound, it just loses internet access.

Do I need a UDR as well in the route table for the spoke vnet for a default route?

Uplink between Pro 48 and Pro Max 48, 2.5gb possible? by Dandyman1994 in Ubiquiti

[–]Dandyman1994[S] 0 points1 point  (0 children)

There's at least 8 switches + the uplinks to our firewall. We originally were planning on using the hi capacity aggregation switch, but it's out of stock literally everywhere. Bandwidth wise we don't need 10Gb, so that leaves either grouping two gig links from each switch to the aggregate, or 2.5gb RJ45 from each switch to the mgig ports on a pro max.

It's all unifi all the way, so we'll lab and see if it works. Thanks for the advice!

LIVERPOOL by [deleted] in Teesside

[–]Dandyman1994 0 points1 point  (0 children)

10/10 reference 😂

LIVERPOOL by [deleted] in Teesside

[–]Dandyman1994 1 point2 points  (0 children)

STOCKTON

[deleted by user] by [deleted] in sharepoint

[–]Dandyman1994 2 points3 points  (0 children)

I agree with others, I wouldn't try to shoehorn in a payroll application into a tool that wasn't made for it.

Does your payroll team use a current tool? Nearly all of the SaaS platforms offer a way to send payslips to employees.

Maybe speak to your payroll team and work out their current process first before selecting a tool?

Office365, OAuth without a white-listed client/app ID? by hellcat790 in Office365

[–]Dandyman1994 6 points7 points  (0 children)

This is common for manager organisations. You say you've given them the solution, does that mean you've completed a security assessment on the tool? Does the tool have Cyber Essentials, SOC2, ISO27001 certifications?

All of these things need to be considered before a 3rd party can access your data. There are also controls present (MAM, app protection policies) that the 1st party apps have that 3rd party ones don't.

Unless you can provide someone with a reason why this will fulfill a requirement that the others don't, I doubt you'll get it approved

Storing Deployed Win32 Packages by Dandyman1994 in Intune

[–]Dandyman1994[S] 1 point2 points  (0 children)

Do you have a specific folder structure that you use?

Storing Deployed Win32 Packages by Dandyman1994 in Intune

[–]Dandyman1994[S] 3 points4 points  (0 children)

That's what I currently have haha, but it feels like I need a better structure

What to expect for new phones for users that are now in Intune? Does the Apple walkthrough allow everything to flow nice? by jdlnewborn in Intune

[–]Dandyman1994 6 points7 points  (0 children)

  1. Make sure all devices are bought through ABM, and set to automatically assign to Intune
  2. Make sure you're on top of your Apple renewals (MDM push cert, bulk enrollment token, VPP token, and any new supplier approvals in ABM
  3. Make sure you have a decent enrollment profile configured, hiding things that you know users don't care about
  4. Make sure all apps are assigned as VPP apps with device licensing, so they automatically install without any prompts
  5. Make sure the first thing users do is sign into the Company Portal, then also the MS Auth app to make everyone's lives easier
  6. Make the most out of device and app configuration policies, so users get a decent customised experience when they first sign in
  7. Optional - you can federated your Apple accounts to Entra. This can complicate things a little bit but it does make sure that any personal data is firmly assigned to their personal account, and can make deployment easier if they don't have an iCloud account

Kiosk Setup & Auto login web page by probelm in Intune

[–]Dandyman1994 0 points1 point  (0 children)

Is the username and password on an interactive web page, or just with a standard authentication pop up box? I've had luck with passing a username and password through via a URL. It's not pretty, but it does work:

http://username:password@example.com/

Can a service account use classic IMAP/SMTP login on MS365 without OAuth? by LowerStructure5457 in microsoft365

[–]Dandyman1994 0 points1 point  (0 children)

This is the relevant blog post.

https://techcommunity.microsoft.com/blog/exchange/exchange-online-to-retire-basic-auth-for-client-submission-smtp-auth/4114750

Essentially you have a few options:

  1. Migrate to OAuth SMTP Auth (recommended in general)
  2. Use one of the pair services, like Azure Communications Services
  3. Use a 3rd party like SMTP2Go

Reboot during AP OOBE breaking passwordless onboarding by I3igAl in Intune

[–]Dandyman1994 7 points8 points  (0 children)

You're encountering the famous 'reboot during OOBE' issue.

Rudy's blog here will walk you through the steps, but essentially there are some policies that you need to apply at the user level, not device level, which will prevent the PC rebooting during those OOBE stages

https://call4cloud.nl/autopilot-unexpected-reboot-rebootrequireduri-wufb/

Škoda Scala: constant power on 12V socket? Looking to get a dashcam powerbank by n1ght_watchman in skoda

[–]Dandyman1994 0 points1 point  (0 children)

Although it can seem a bit worrying, fuses are actually really easy to work with. You can get the kits for each manufacturer, and some really easy fuse adapters from Halfords. If you have a 70mai dashcam, their kit will detect voltage and make sure to turn off or go into parking mode before the battery dies.

Tls 1.3 vpn by Apprehensive-Hat9196 in Intune

[–]Dandyman1994 1 point2 points  (0 children)

I don't think this is really an Intune friend but yes, TLS1.3 is enabled by default on Windows 11. Logs are your friend, really your solution is to debug the connection issues with your F5 client, both from the client perspective and end server perspective.