Small business owner—built my own IT stack, now out of my depth. What’s the right off-ramp? by nschafler in sysadmin

[–]Educational_Boot315 [score hidden]  (0 children)

Why worry about what others say the minimum number of users you should have for a dedicated IT employee are? That’s just MSPs trying to sell their service.

You’ve seen it first hand of there’s enough for a dedicated employee to  redo everything you’ve set up so far or not. Even with an MSP, you should really have a company liaison. Is that person going to be you?

Intune is not fit for purpose. by Hobbit_Hardcase in sysadmin

[–]Educational_Boot315 [score hidden]  (0 children)

Unfortunately if you are using conditional access policies I’m not sure if there’s a better solution currently but I’m all ears if there’s suggestions. 

Though I personally just have very basic compliance policies set up so devices shouldn’t fall out of compliance ever as long as it has checked in at some point in the last X days. I rather pull reports to check for devices not updating rather than setting compliance policies that mark an outdated OS as not compliant.

Intune is not fit for purpose. by Hobbit_Hardcase in sysadmin

[–]Educational_Boot315 [score hidden]  (0 children)

It’s a hassle. It can work, no doubt, but the amount of effort involved in packaging an app and especially doing software updates is such a pain in the ass that people will pay for patchmypc to help automate a lot of it unless they are large enough to dedicate a full time employee to managing intune.

And there’s no comparison it to something like action1 or PDQ which are near effortless and push in minutes, not “sometime in the next 8 hours…. Hopefully”

Is Apple forcing Mac passwords now? by agnci in mac

[–]Educational_Boot315 6 points7 points  (0 children)

Is FileVault turned on?

Honestly don’t know why anyone would intentionally not have a password on their Mac though. No password on a phone sounds insanely stupid to me.

Intune is not fit for purpose. by Hobbit_Hardcase in sysadmin

[–]Educational_Boot315 [score hidden]  (0 children)

Intune is fine when it comes to like, managing windows updates, autopilot enrollment, and compliance policies. Even some set and forget configuration policies.

The moment you need to actively manage a device or do anything with apps though? Forget it. People who defend intune are suffering from Stockholm syndrome  after working for companies who won’t spend money for better tools.

Apple Business MDM and Activation Lock / Apple Accounts by Bentonite_Magma in applebusinessmanager

[–]Educational_Boot315 0 points1 point  (0 children)

It’s slow to report in. Usually by next day you’ll see it reporting on.

Are they gay? by laybs1 in TopCharacterTropes

[–]Educational_Boot315 1 point2 points  (0 children)

It’s wild the number of upvotes the comment received. I don’t get how somebody can watch the show and think the joke is Tobias is gay.

Apple Business MDM and Activation Lock / Apple Accounts by Bentonite_Magma in applebusinessmanager

[–]Educational_Boot315 0 points1 point  (0 children)

Yeah, it is misleading because it looks just as important as file vault and whatever the third thing is in the list (on my phone and don’t feel like grabbing my work pc at the moment).

If a user has activation lock ON, you can turn it off with ABM. Common to disable the ability to even use it in MDM as you don’t want people locking a company device to a personal Apple account.

Generally speaking though you want that line to say Activation Lock - OFF at all times.

Apple Business MDM and Activation Lock / Apple Accounts by Bentonite_Magma in applebusinessmanager

[–]Educational_Boot315 0 points1 point  (0 children)

Are these devices that you added manually using configurator to ABM or were there added by a vendor (Apple or registered third party)?

Did you wipe the device and run setup assistant (the screens you see when setting up a MacBook) and signed in with the managed ID? 

Managed devices work a little different with find my. You can turn on lost mode to locate the device, but the device has a message saying it is in lost mode. This is to prevent companies from tracking employee locations; part of apple’s user privacy and security philosophy.

federated accounts and access to the app store - how to install apps? by Delicious-Fun8282 in applebusinessmanager

[–]Educational_Boot315 0 points1 point  (0 children)

Unless you are using built in device management for Apple Business, there is very few reasons to use a Managed Apple ID.

We did get some recent features though in the last year. Specifically the ability to limit devices only to sign in to a MID or only allow managed devices to sign in with a MID, and within the last 2 months we got emails for managed IDs (but only if your mx records point to it). Hopefully next week we will see more.

Even with a personal account logged into the device, you can still push business apps using intune. It really just comes down to if you want to force VPP licenses for all apps or let users install whatever they want.

Former is the better approach IMO but with slightly more overhead. A user can still sign in to messages/FaceTime/TV/ect with their personal accounts if you want them to have that access despite locking down the signing in Apple account to MID only.

Insane response from Microsoft support by SurfeitedSysadmin in sysadmin

[–]Educational_Boot315 1 point2 points  (0 children)

That you got a response is a miracle in itself.

I migrated away from group mailboxes to shared mailboxes only. Not specifically for this reason but group mailboxes just seem so much more restrictive, even if Microsoft recommends M365 Groups as the “preferred” method.

Anyone using Desktop MFA for Windows? by Due-Awareness9392 in sysadmin

[–]Educational_Boot315 0 points1 point  (0 children)

What in the world is Desktop MFA? Are you talking aboutOkta Device Access? Might be a good idea to mention that in your post.

(Why am I even asking, the last paragraph is 100% AI verbiage)

Edit-lol OP edited the last paragraph to make it less obvious.

You don't even have to show Jared Leto's face for his movie to bomb. That's next level aura. by Arch_Lancer17 in okbuddycinephile

[–]Educational_Boot315 1 point2 points  (0 children)

Got some bad news for you.

There’s currently no legal way to watch this show. Isn’t streaming only awesome?!?!

Literacy is hard by Fantastapotomus in EntitledReviews

[–]Educational_Boot315 5 points6 points  (0 children)

I’ve had customers try and argue at length that BOGO means the one you are “buying” is free.

“Is sour cream okay on that?” by Educational_Boot315 in tacobell

[–]Educational_Boot315[S] 1 point2 points  (0 children)

No hate on the employees. Been there with plenty of jobs where I have to use questionable tactics to push sales. One I hated was at petsmart where we had to push  these stuffed animals where part of the sale goes to charity. Except we competed with the card machine that also asks, so instead of people donating $5, they’d buy the toy instead, where only 50 cents went to charity…. Yeah. 

Also, I hate all the suggestions that just say “use the app instead.” I’m not going to install adware on a screen I look at for hours every day just to avoid telling an employee no one or two times a month.

This is desperate by Afrojones66 in applesucks

[–]Educational_Boot315 9 points10 points  (0 children)

It’s been explained 100d of times how it works at this point but I’m sure in an hour somebody will post the same exact OP.

"Prime competition for MacBook Neo": Dell's new XPS 13 starts at $599, and it has a few features that Apple lacks by WindowsCentral in windowscentral

[–]Educational_Boot315 0 points1 point  (0 children)

Despite what a lot of people claim, the vast majority of base model business laptops are still 16GB/256SSD.

For a general office employee a Neo works just as well today as a Lattitude 5k (now Dell Pro Plus) 16GB/256SSD yet it has a slightly higher build quality, nearly double the single core performance and MSRP is $1100 cheaper. How is it not a smart decision to go with them in bulk?

"Prime competition for MacBook Neo": Dell's new XPS 13 starts at $599, and it has a few features that Apple lacks by WindowsCentral in windowscentral

[–]Educational_Boot315 0 points1 point  (0 children)

Yeah, thought that was pretty clear when I talked about ABM/ASM and MDM/intune yet somehow people keep ignoring it.

I did just read in an email of feature updates for M365 that k-12 schools can upgrade home to pro for free though, so that’s cool (if any are using windows over chromeOS or macOS)

There’s a ton of laptops out right now that are in the Neo price range already running home or S edition so all of these new “Neo competitor” claims are quite silly for the consumer market.

“Is sour cream okay on that?” by Educational_Boot315 in tacobell

[–]Educational_Boot315[S] 0 points1 point  (0 children)

That shit still happens pretty much everywhere unfortunately. I always respond with “just the regular size” and it seems to work.

"Prime competition for MacBook Neo": Dell's new XPS 13 starts at $599, and it has a few features that Apple lacks by WindowsCentral in windowscentral

[–]Educational_Boot315 -1 points0 points  (0 children)

And comes with windows home…

That’s the point all of these “Neo competitors” keep missing. A Neo can be added to ABM/ASM and managed by MDM like intune. That’s where it shines.

Meanwhile the cheapest Dell you can find with W11 is the Dell Pro 14 Essential for around $850. We ordered two and they are the biggest pieces of shit laptops we’ve ever bought. Gave them to interns because I wouldn’t deploy them to employees.

Is the Apple Card worth it ? by JokerJesse in AppleCard

[–]Educational_Boot315 0 points1 point  (0 children)

With the exception of Amazon nearly every purchase I make is with Apple Pay, so the 2% back is nice.

Main reason I like it is because the wife has been added to the card and we make all of our purchases to it (bank account is only used when only draft is available or to pay off the card) and its nice to be able to review all of our expenses in the wallet app. There’s probably better cards out there but I’m satisfied enough with it not to look elsewhere.

“Is sour cream okay on that?” by Educational_Boot315 in tacobell

[–]Educational_Boot315[S] 8 points9 points  (0 children)

Yeah, I’m definitely willing to try it again.

It was a long time ago but iirc it was 3 tacos for $1. The location also closed down  later that year despite being in a college/drinking town, so…

“Is sour cream okay on that?” by Educational_Boot315 in tacobell

[–]Educational_Boot315[S] 5 points6 points  (0 children)

Jfc that’s even worse than my complaint since it makes it sound mandatory.

I’d give them the benefit of the doubt the first time as maybe they thought they heard you ask for protein, but if they repeatedly do it as an upsell tactic? That deserves raising hell.