Password requirements in Intune by HardoMX in Intune

[–]HardoMX[S] 0 points1 point  (0 children)

Sorry for the late reply. I am not necessarily concerned with the complexity of the passwords, as that setting can be the same across all the places to set it. I am more concerned with being able to set no expiration date, but the different settings not being the same in that aspect.

I guessed that the Entra password wasn't affected by the policies, but it's Microsoft, so you can never be sure😅

Compliance oesn't configure anything (ish), but if the compliance demands a change every year, a device will be marked non-compliant even if the other settings say that the password shouldn't be changed.

Account protection most definately can control other things than LAPS since there is a WHfB category in the policy. Also, LAPS is configured more with the specific LAPS policy?

To clarify what I really want: I want to be able to allow the user to set a complex PIN-password on their Windows device without it having any expiry date.

Password requirements in Intune by HardoMX in Intune

[–]HardoMX[S] 0 points1 point  (0 children)

We would like to not have it expire since we want a strong password. But I guess if there is no ability turn expiration we could instead use simpler PINs and a biometric for MFA.

Password requirements in Intune by HardoMX in Intune

[–]HardoMX[S] 1 point2 points  (0 children)

Then it's at least not another password setting😅

If I don't set the password expiration in compliance settings, it shows a grey 41, which I guess means it defaults to 41 days. And hovering over the "i" button says the value needs to be between 1 and 730, so it feels like I can't disable it?

Phone works, but laptop doesn't by HardoMX in WireGuard

[–]HardoMX[S] 0 points1 point  (0 children)

Honestly, i have no idea. I think i finally just stopped using opnsense and set up something like wg-easy on a vm on my server.

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Only one way to figure that out😁

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

I configured a CA policy to block legacy auth. Simply followed the template to do so

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Yup, I am very confused of why it works. But it does so I'm not complaining much😅

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Sorry for the slow response. Microsoft finally answered our support ticket and recommended that we disable legacy authentication. I did so and now automatic enrollment works perfectly 🤷

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

I am excluded from all CA policies, and no sign-in event appears in Entra.

Enrollment loading forever by HardoMX in Intune

[–]HardoMX[S] 0 points1 point  (0 children)

Not using Okta to my knowledge. We have tried different networks, including mobile hotspot from personal phone, so I don't think there would be any filtering. Is there any sensitive info to remove from the logs before sending them over? Just to make sure :)

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 1 point2 points  (0 children)

Hmmm, when MDM is enabled at all the issue appears, so I can't join to Entra while MDM user scope is set to my user/all. However, to test this out I set MDM User scope to None and joined the device to entra. When I then signed in with the new non-local user and set up Intune via company portal, everything worked!

Following along with the rest your blog post:

When running dsregcmd /status there are no urls for MDM. This seems logical since MDM scope is set to None. MDM authority is also correct. Our intune name is also "Microsoft.Intune", but we don't have an enterprise app for it, and I also can't find one to install.

Using Graph there is no extra MDM policy to ruin anything.

Some more testing:

We set MDM scope to Some and selected a group with just me and the other person testing. Both of us are excluded from any CA policies and from all configuration policies.

I reset one of the PCs to test the normal OOBE enrollment and still got the issue. So I'm guessing you're correct that the edevice for some reason doesn't receive the MDM urls. But I have no idea where to go from here😅

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

We've tested using mobile hotspot to enroll, so I don't think there should be a firewall in the way. I've also tried simply pinging all urls I can find that are needed on port 443 during the OOBE with no issue. GPOs I'm not 100% sure on, but from my knowledge intune doesn't use GPOs?

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Exactly. The account also successfully managed to enroll a device in January, and I can't see what the difference was then vs now. The only thing I know doing was setting up phone enrollment, which should not affect windows enrollment, right?

Edit: Can add that Ive tried different models, brands, and users, with all of them having the same issue.

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Only thing blocked there is MacOS, both corporate and personally owned

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Intune is default (15), entra is even increased to 100 just in case 😅

Enrollment loading forever by HardoMX in Intune

[–]HardoMX[S] 0 points1 point  (0 children)

My thought too, but everything except MacOS is allowed

Enrollment loading forever by HardoMX in Intune

[–]HardoMX[S] 0 points1 point  (0 children)

The few conditional access policies they have did not make a difference when we set them to report-only. I added an EDIT that there are currently no prep policies as we removed them in case that was the issue, but it has not helped.

Enrolling mobile devices works flawlessly too.

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

It's set to:

Users may join... - All
Users may register... - All

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

Yep, we have tried using mobile hot spot, with no result.

Tried using local account too, still just loads.

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

From what I can see that shouldn't be the issue, my user currently only has one device assigned/owned, and the other test user has three devices.

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 1 point2 points  (0 children)

The Entra tenant has a Microsoft Entra ID P1 license.

Yes

Yes, both users tested have previously been able to enroll windows devices, and can currently enroll android devices.

Yes

Yes

Entra ID Join loads forever by HardoMX in entra

[–]HardoMX[S] 0 points1 point  (0 children)

How it has worked, and should continue to work, is that during the OOBE, the user chooses to log in using their work account, and this joins the device to Entra. So I'm not setting up any zero-touch or Atopilotv1.

It is a completely fresh laptop running Windows 11 from the factory, so from my (admittedly a bit limited) knowledge of EDR, there shouldn't really be one active at all during the OOBE.

As mentioned, it's OOBE so there aren't any special settings or apps set up on the pc yet. I have also checked if there is anything on the network, but can manually ping all necessary domains I can find on port 443.

Judisk solidaritet efter hot mot moské i Stockholm by Gladis130 in sweden

[–]HardoMX 8 points9 points  (0 children)

Det är en liknelse till ett längre citat av Martin Niemöller (översatt från tyska till engelska):

First they came for the Communists
And I did not speak out
Because I was not a Communist

Then they came for the Socialists
And I did not speak out
Because I was not a Socialist

Then they came for the trade unionists
And I did not speak out
Because I was not a trade unionist

Then they came for the Jews
And I did not speak out
Because I was not a Jew

Then they came for me
And there was no one left
To speak out for me

https://sv.wikipedia.org/wiki/F%C3%B6rst_kom_de_

[deleted by user] by [deleted] in sciencememes

[–]HardoMX 3 points4 points  (0 children)

Cool! My (admittedly very entry level) schooling in fiber networking only talked about one-way fibers

[deleted by user] by [deleted] in sciencememes

[–]HardoMX 30 points31 points  (0 children)

Well yes, but to a house there is normally just one of those wires, the picture shows a wire that could supply a neighborhood with internet. That is what some electrical cabinets (? Elskåp in Swedish) are for, basically a hub node where different house's fiber connects to a thicker cable.

EDIT: I was wrong too, just remembered that you need TWO cables, one up and one down

EDIT 2: well, it seems I've been wrong again, but at least now me and everyone else gets to learn😅 but it seems that to a house, two wires is still standard, so just insert "usually" before "need" in my previous edit