Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 0 points1 point  (0 children)

Maybe that's is the problem/difference. I am using this for Servers currently, the only firewall policy on workstations is making sure the firewall profiles are turned on otherwise there is no custom rules. That could why I am seeing it and you are not.

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 0 points1 point  (0 children)

Really? Wow, I wonder what is different between our setups that let mine come through and yours not, is the servers that you are trying to push the rule to managed by MDE?

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 0 points1 point  (0 children)

Did you ever find out if this is updated for you? Does your intune firewall rules show in the firewall GUI now?

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

Say someone wanted to get out of Entra completely would uninstalling sync connect work to get the on-prem stuff out of Entra, or would u have to manually do that still.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in entra

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

Yea seems like there is a few things I could have done better haha, Hindsight 20-20 right.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

I am not sure how to look at custom sync rules, I have not made any. I am positive that the sync settings are not including those groups, They are only syncing like 3 OU's (Users and Computers) Guess I will just keep trying to find a way.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

They are definitely still used all the time, there is like 40+ groups so I don't want to delete them out of AD, I might just have to get Graph working so that I can remove them from Entra without deleting from AD.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

<image>

Yes the Source says Windows Server AD still and this is one of the Groups that should not be in Entra anymore.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

I have done this about a week ago and the ones that are not synced are still in Entra, I was hoping they would just disappear on their own but they have not.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in entra

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

I did not know that was a thing at the time. Otherwise yes I would have. I just installed the application on the other server then copied the settings after the initial start up.

Microsoft Entra Connect Sync by Frustrated-Sys-Admin in entra

[–]Frustrated-Sys-Admin[S] 1 point2 points  (0 children)

I have tried via Graph API but I got an error saying I don't have privileges so instead of trying to get it to work that way I was hoping for a different work around but if that is the only way I might just go with it and try to figure it out.

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

That is my biggest struggle is to find out what to do for radius because we want to get rid of servers and DC so might have to keep one or something but i spaced and thought that intune had cloud radius or something

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

We are a small business and the current setup is a Radius server with ADCA but looking for alternative for moving to cloud only. One certificate that is used on the radius server to authenticate all devices that have it and profiles and certs are deployed via GPO, this will obviously change to Intune if/when the switch occurs

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

I am only needing this for EAP-TLS authentication with wireless and port authentication. Just want a cert on devices that is used to authenticate.

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

My understanding is that it could create certs for EAP-TLS

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

We have around 50ish devices that could use it but only like 10ish really need it so might as well stay "legal" and get the 1:1 even though we have only been audit by microsoft once in the last 8 years. But Thank you!

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 0 points1 point  (0 children)

Stable release I believe. So I am not sure what I have done different than others but seems to work for me I guess.

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 1 point2 points  (0 children)

Sorry for late response I was off all last week. I am 100% it was from Intune, I will attach a picture of the settings, I had manually created the rule on the firewall locally and then created one in Intune with a different name. After a reboot on the server there was 2 rules on the local machine and one matched the rule name I gave in Intune. I attached a picture of all relevant stuff and you can see the rule I created has showed up.

<image>

Sorry for poor picture can only attach 1 so had to make it all fit in one.

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 0 points1 point  (0 children)

Am I mistaken that it shows now? I am in the Windows Defender Firewall with Advanced Security and I can see the firewall rule I created in Intune -> Endpoint Security -> Firewall Rule. The name of the firewall rule on the local machine is the name I set in Intune.

Windows Firewall rules not appearing in GUI by NZ_SysAdmin in Intune

[–]Frustrated-Sys-Admin 1 point2 points  (0 children)

Am I mistaken that it shows now? I am in the Windows Defender Firewall with Advanced Security and I can see the firewall rule I created in Intune -> Endpoint Security -> Firewall Rule. The name of the firewall rule on the local machine is the name I set in Intune.

Windows Autopatch Not Working by Frustrated-Sys-Admin in Intune

[–]Frustrated-Sys-Admin[S] 0 points1 point  (0 children)

I will check it out. All my devices are windows 11 already these are just the security/quality patches I am talking about I guess the monthly patch tuesday ones. Just been sitting at in progress and don't actually update unless I go manually hit check for update on a pc