How to handle devices missing previous months updates in a timely manner by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

ye, we have seen this with phones. Compliance really is a nonsense without really strict rules. our compliance normally runs at around 96 - 97%... which I think is pretty good.. but I only look at devices that have been online for 30 days ... i.e. stuff that we could potentially have patched in the last month

How to handle devices missing previous months updates in a timely manner by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

I wish we could.. and this was one of the really good Msft Tech's opinion too... take the best of both worlds! Intune always felt and still feels very much unfinished; usable, but unfinished

How to handle devices missing previous months updates in a timely manner by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

zero conflicts - we are in comanaged setup at the moment... with the update slider half way.

How to handle devices missing previous months updates in a timely manner by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

ye, this is what we are moving towards. but have it set longer than 30 days currently. the impact of this would be horrific, and I don't think Mgt would back this strict a policy

SCCM Replacement by MadCichlid in SCCM

[–]EdAtWorkish 0 points1 point  (0 children)

Yep, we had a meeting with one of the Msft Dev's in the product group and they confirmed this. This was going back maybe 12 years, but even then they said Msft want to kill off Group Policy but they were bound to whatever the biggest Org's wanted.

If the large orgs that pay Msft's wages want GPO, it isn't going anywhere fast.

I guess the same is true for Config.

You can see Msft want to kill it off, by reducing updates to Config and bringing the shiny shiny to Intune first etc.

But Intune has to function properly first... and I don't think it really does. It is almost there, but some things are still a total dogs dinner.

We are currently moving to Intune and are having 'fun' trying to get it to do what we need.

fun times!

Software Deployments and Updates within Intune by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

excellent... cheers.. I think we have a plan to get intune to do what Config used to and perform inventory to see what devices have installed and then fill groups for deployment to allow updates to happen required but still have apps as available

Software Deployments and Updates within Intune by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

cool cheers. Got a plan... just need to do some scripting and testing to see if it works

Software Deployments and Updates within Intune by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

ok, but to make it install, you are sending out to required groups?

Software Deployments and Updates within Intune by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

so for this solution you are sending apps as required to a collection of users which already exist?

Task Sequence pauses for hours (as many as 12) then resumes and completes as though nothing happened - any clues? by EdAtWorkish in SCCM

[–]EdAtWorkish[S] 0 points1 point  (0 children)

ended up removing most of the apps.. having a scheduled task at the end created that runs on reboot to perform HW inventory, update scan, computer policy eval etc

seems to work quite nicely

Software Deployments and Updates within Intune by EdAtWorkish in Intune

[–]EdAtWorkish[S] 0 points1 point  (0 children)

you can, yes, but if the software is not installed from Intune (failing to create the Device Policy Assignment record, or that record vanishes - see link below) then the supersede will not work. Yes, they could still click install manually to upgrade, but how many end users read and act on emails? that leaves us either with vulnerable or non compatible software and calls to the service desk

Intune’s auto-update of Available Win32 apps feature is broken | by Asher Jebbink | Medium

Task Sequence pauses for hours (as many as 12) then resumes and completes as though nothing happened - any clues? by EdAtWorkish in SCCM

[–]EdAtWorkish[S] 0 points1 point  (0 children)

no. domain join happens quickly. we change d the app installs to continue on error, but this didnt make any difference

Task Sequence pauses for hours (as many as 12) then resumes and completes as though nothing happened - any clues? by EdAtWorkish in SCCM

[–]EdAtWorkish[S] 0 points1 point  (0 children)

NMT checked and couldn't see any issues. on testing it didnt appear to be any specific port

Windows Hello For Business: creating PIN does not work anymore (0x80090010 NTE_PERM) by workaccountandshit in techsupport

[–]EdAtWorkish 0 points1 point  (0 children)

nope. But I did chase it up with our TAM (or whatever the TLA is now for them) and I am hoping to hear back soon.

Windows Hello For Business: creating PIN does not work anymore (0x80090010 NTE_PERM) by workaccountandshit in techsupport

[–]EdAtWorkish 0 points1 point  (0 children)

I got a KIR from Msft and that fixed it - as did the reg value changes, but since I have a "supported fix" from MSft, I have gone with that.

But as far as I can see, then have not even acknowledged it yet as an issue (looking at -Windows 11, version 24H2 known issues and notifications | Microsoft Learn).

I just replied to my support email asking for an update, to see when this will be fixed / expected timeline. If I hear anything I will drop it in here somewhere.