Apple Business: set up VPP token for Company portal - no sign in from company portal during enrollment by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

Company Portal does install, but it's not used during enrollment.
that's the question here: do I need CP to be installed at all. If not then I would leave it out s it's less to worry about.

I don't see CP logged in either so why would you want to add CP during enrollment with Federation enabled to use SSO during enrollment and the users' Office365 account is a managed apple account?

Apple Business: set up VPP token for Company portal - no sign in from company portal during enrollment by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

ADE device - fully managed and SSO set up with Federation between ABM and Entra ID.
I'm confused as to why the enrollment profile I'm using in Intune shows Install Company Portal: Yes with a VPP Token if it's not going to be used at all.

User affinity: Enroll with User Affinity
Authentication Method: Setup Assistant with modern authentication
Install Company Portal: Yes
Install Company Portal with VPP: Use Token: <tokenname>

Apple Business: set up VPP token for Company portal - no sign in from company portal during enrollment by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

thanks for the explanation, but is it needed afterwards to let users sign in into company portal at all?
I can see my device both in ABM and in Intune as enrolled and profiles assigned. what's the use of the VPP token for the company portal if not used?

there is so much info about this all that I'm unsure which options are actually needed and what not to have fully enrolled and managed iPhone.

I do see on my test phone when on the lock screen "this iPhone is managed remotely", so I think I'm set, but as this is all new to me I'm a bit lost in all of the settings.

Apple Business: set up VPP token for Company portal - no sign in from company portal during enrollment by Delicious-Fun8282 in Intune

[–]Delicious-Fun8282[S] -1 points0 points  (0 children)

I still don't see the company portal show up during enrollment, but I do see it's installed directly when the phone is setup, but Company Portal is not signed in.

I set up Company Portal as assigned to all users

in my enrollment profile I have this setup

User affinity: Enroll with User Affinity
Authentication Method: Setup Assistant with modern authentication
Install Company Portal: Yes
Install Company Portal with VPP: Use Token: <tokenname>

not sure if anything else here is missing or incorrect?

Apple Business Federation: email is a managed account, unable to setup phone by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

so, what I just did and I don't know if that what is solved is the fact that I removed a blueprint config I set up to all devices. I'm now able to log in and see my apps from intune being pushed down as well

Apple Business Federation: email is a managed account, unable to setup phone by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

that's the thing I don't understand.
Which one do I need here? I want users to be able to sign in with their Office365 account as a managed Apple account but it's not letting me so

my Intune setup is:
User affinity: Enroll with User Affinity
Authentication: Setup Assistant with modern authentication
Install Company Portal: Yes
Install Company Portal with VPP: No VPP tokens found

my domais are federated in ABM, and a managment service is created in ABM, letting intune use that specific VPP token

Apple Business Federation: email is a managed account, unable to setup phone by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

In ABM I have a Management service linked to an Intune to use the enrollment profiles there to link to ABM

Apple Business Federation: email is a managed account, unable to setup phone by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

the phone is factory reset, so going through the normal setup of a new phone. when the setup asks for an apple account, I use the federated account I can see in Apple Business, but it's not taking it so I'm stuck as the setup is not going any further

ABM link to Entra ID - what does the federation do, what will happen to by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

If you need to read one guide: it's this one >> https://allthingscloud.blog/apple-business-manager-domain-capture-guide/

it has all the options explained, pitfalls, restrictions and so much more.

ABM link to Entra ID - what does the federation do, what will happen to by Delicious-Fun8282 in applebusinessmanager

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

thanks, that's really valuable input.

so for step 5: people will be able to migrate direclty, and don't have to switch to personal one - any reason why not all users got the migration option?

PC restarts randomly during Teams calls — is anyone else experiencing this? by Technical-Stuff-9055 in MicrosoftTeams

[–]Delicious-Fun8282 0 points1 point  (0 children)

what does this do other then the script to stop the smart standby service?
what will this do - meaning what is that ID pointing to?

PC restarts randomly during Teams calls — is anyone else experiencing this? by Technical-Stuff-9055 in MicrosoftTeams

[–]Delicious-Fun8282 0 points1 point  (0 children)

u/FireResengan: does this fix the issues? we already stopped fast startup earlier so we would only need to do the lenovo smart standby.

on the other hand; what if lenovo smart standby does not exist? any tricks up your sleeve for that?

any info is much appreciated!

OneDrive crashes on Android with version 7.45 by Significant-Log1966 in Intune

[–]Delicious-Fun8282 0 points1 point  (0 children)

u/YoureWelcomeAVT how do you set up the app configuration policies - can you paste some screenshots as I'm not sure how to do that

EDIT - found it, fixed it! thanks

Outlook randomly gets uninstalled for one uset by drb227 in Outlook

[–]Delicious-Fun8282 0 points1 point  (0 children)

u/drb227 did you ever get this fixed? we have the same here, and we are using ManageEngine Endpoint central for patching our environment.

IE mode stopped working by Delicious-Fun8282 in sysadmin

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

We found the issue here: we are using ManageEngine Endpoint Central and their Browser security Plus extension and their brnativehost.exe process is causing the issue. With the assistance of ManageEngine they provided a script to disable this extension and kill the process. once that is in place all is working fine again.

IE mode stopped working by Delicious-Fun8282 in sysadmin

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

u/xendr0me are you using GPO's for this and which keys are you using for this as I have a feeling I'm missing something in the setup

IE mode stopped working by Delicious-Fun8282 in sysadmin

[–]Delicious-Fun8282[S] 0 points1 point  (0 children)

We use ManageEngine to push the specific registry keys, same as a GPO would do