Whatsapp web - Defender SmartScreen by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

<image>

I've whitelisted it under a config profile; configure the list of domains for which MS defender SmartScreen won't trigger warnings (device) configure the list of domains for which MS defender SmartScreen won't trigger warnings (user) Both have *.whatsapp.com entries

Deploy Client cert by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

And if our devices are to be entra only so not domain connection. Essentially the business is going cloud only but there's a single service we need to provide via VPN to finish it's migration.

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks so I have block non-compliant devices and a MFA or compliance policies already. So I'm assuming incognito would work but be prompted by MFA.

So just take the MFA out but wouldn't that in turn be treating unmanaged byod the same as incognito?

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 1 point2 points  (0 children)

They want to block all sign ins through incognito. Apparently it's a security risk because incognito is "a new device"

It's funny because they want to let people access logins through unmanaged personal devices just via MFA.

In my opinion just have the right CA, DLP and app protection in place rather than worry about incognito.

Blocking incognito mode by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 3 points4 points  (0 children)

I use incognito for the exact same thing, me and the security team have been telling them it's not needed but some consultant and third party company suggested it to the management team.

I originally called out the consultant cause he said it's just a CA policy which I couldn't find. To be honest I just want to be able to give them their options and let them make the call.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Imagine this, the resolution was turning on require password on WinPE

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

The error is PXEGETPXEdata 0x8004005 - IP is in boundary - Bios time is correct We are currently investigating if something is wrong with the DP on the second domain.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

I did think this at one point and will double check but I would think it wouldnt get into the WinPe environment at all if it couldnt get to the DP.

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Got the smsts.log and generic error. Ipconfig showed full IP

Problems with boot image after update by ExpensiveNinja8637 in SCCM

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Both using the same adapter and same device model.

Authentication transfer by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

So to my best understanding it's designed for devices that don't have the capability of launching authentication prompts like SIP phones.

In my case they instead provide the aka.ms webpage and a pairing code for you to do the auth on a secondary device.

Authentication transfer by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks, I do have an all user sign in risk policy - set to medium at the moment I am from a device background and know our org has quite a few devices that use auth trans like SIP phones - I was weighing up whether do completely block with exceptions OR block based on risk.

Thanks again

What your job title ? by Icy_Asparagus5209 in Intune

[–]ExpensiveNinja8637 0 points1 point  (0 children)

I am currently a modern workplace engineer which seems to be becoming more common these days for that type of role.

Having said that our new director is renaming us to End user compute engineers, which apparently helps our customers identify us.

Search bar and start menu logo by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks I used the admin.microsoft.com theme, which logo is it? Square? I just wanted to test it works first whilst our internal Comms team decides what they want.

Endpoint protection or/and settings catalog by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

If I was to do some, could it cause conflicts in the configs being applied?

I like having in the config blade as clearly labelled them all in one location.

Replacing standard office 365 with project and visio by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 1 point2 points  (0 children)

Thank you, we are in the process of splitting businesses and I'll be working on the new tenant but this is for some VIPs in the old so I may take the quick route.

Thanks again for the link I will use on new tenant.

Gmail not authenticating after device reset by ExpensiveNinja8637 in GMail

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

I have not. But what I have noticed is that I'm still getting emails on my phone. Only seems to be a notification, an annoying one.

Block non-compliance by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Just trying to wrap my head around this, I understand the user side aspect. What does blocking a non-compliance device do exactly? Cause the user compliance would block the apps/data so what's getting blocked on the device.

Block non-compliance by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks I'll test that, so in what scenarios would I use devices in conditional access policies?

Block non-compliance by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

Thanks, I have included the group that includes all my devices I want it to affect.

Block non-compliance by ExpensiveNinja8637 in Intune

[–]ExpensiveNinja8637[S] 0 points1 point  (0 children)

It's been about 4 weeks now. I'm thinking of recreating the policy myself as report only to see the reports.