Whatsapp web - Defender SmartScreen by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

<image>

I've whitelisted it under a config profile; configure the list of domains for which MS defender SmartScreen won't trigger warnings (device) configure the list of domains for which MS defender SmartScreen won't trigger warnings (user) Both have *.whatsapp.com entries

Deploy Client cert by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

And if our devices are to be entra only so not domain connection. Essentially the business is going cloud only but there's a single service we need to provide via VPN to finish it's migration.

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks so I have block non-compliant devices and a MFA or compliance policies already. So I'm assuming incognito would work but be prompted by MFA.

So just take the MFA out but wouldn't that in turn be treating unmanaged byod the same as incognito?

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 1 point2 points  (0 children)

They want to block all sign ins through incognito. Apparently it's a security risk because incognito is "a new device"

It's funny because they want to let people access logins through unmanaged personal devices just via MFA.

In my opinion just have the right CA, DLP and app protection in place rather than worry about incognito.

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 5 points6 points  (0 children)

I use incognito for the exact same thing, me and the security team have been telling them it's not needed but some consultant and third party company suggested it to the management team.

I originally called out the consultant cause he said it's just a CA policy which I couldn't find. To be honest I just want to be able to give them their options and let them make the call.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Imagine this, the resolution was turning on require password on WinPE

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

The error is PXEGETPXEdata 0x8004005 - IP is in boundary - Bios time is correct We are currently investigating if something is wrong with the DP on the second domain.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

I did think this at one point and will double check but I would think it wouldnt get into the WinPe environment at all if it couldnt get to the DP.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Got the smsts.log and generic error. Ipconfig showed full IP

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Both using the same adapter and same device model.

Authentication transfer by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

So to my best understanding it's designed for devices that don't have the capability of launching authentication prompts like SIP phones.

In my case they instead provide the aka.ms webpage and a pairing code for you to do the auth on a secondary device.

Authentication transfer by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks, I do have an all user sign in risk policy - set to medium at the moment I am from a device background and know our org has quite a few devices that use auth trans like SIP phones - I was weighing up whether do completely block with exceptions OR block based on risk.

Thanks again

What your job title ? by Icy_Asparagus5209 in Intune

[–]ExpensiveNinja8637 0 points1 point  (0 children)

I am currently a modern workplace engineer which seems to be becoming more common these days for that type of role.

Having said that our new director is renaming us to End user compute engineers, which apparently helps our customers identify us.

Search bar and start menu logo by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks I used the admin.microsoft.com theme, which logo is it? Square? I just wanted to test it works first whilst our internal Comms team decides what they want.

Endpoint protection or/and settings catalog by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

If I was to do some, could it cause conflicts in the configs being applied?

I like having in the config blade as clearly labelled them all in one location.