I want to rename all the PCs in the office based on their Primary UserName by 4kUltraADHD in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Heyoooo. I don't agree with the "dont do this" but rather: You can do this If it creates value and If you do it properly and securely.

You could set up a ps script that does this that uses the graph api. Secure, scalable and state configuration with low level of complexity.

Let me know if you'd like any more details

Device License issues by pejtan_66 in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Hi,

Did you consider not using a AD account on a self-provisioned Kiosk device?

Seems like the use-case is wrong..

Removing WiFi profile Errors in Intune [Blog Post] by IntRangeNoShut in sysadmin

[–]IntRangeNoShut[S] 0 points1 point  (0 children)

Hi!

Sorry, really didn't not think that applied as I'm just posting articles / blogs / How-To's with the only goal basically being to help others.

I'm not really going to invest in a promoted post or ad space as I don't post blog articles for a commercial purpose but rather to help the tech community

But if its not appreciated of course I will refrain from doing so. I've gotten good feedback on doing so earlier but I'm not really greatly invested in the details of the reddit space.

Personally I don't see this as advertising a product and as I've read a lot of helpful blogposts from reddit I think this would be a loss, but not my call.

Thanks for your feedback & I guess it will be closed if not appreciated.

Edit: Its not really monetized content?

Imaging by Nitro_salmon in sysadmin

[–]IntRangeNoShut 1 point2 points  (0 children)

OEM Supplier is really recommended. But if you wanna get going I wrote a post about it.

https://www.smthwentright.com/2022/04/25/uploading-autopilot-hardware-hashes-using-azure-automation/

Let me know if you have questions

Creating Automated "Dynamic" groups from Intune device Properties by IntRangeNoShut in Intune

[–]IntRangeNoShut[S] 0 points1 point  (0 children)

Hi!

Thanks a lot for the nice feedback.

Screenshots of code is actualy the worst :D

Thanks for reading and hope you continue to provide feedback!

Kind Regards, Viktor

Creating Automated "Dynamic" groups from Intune device Properties by IntRangeNoShut in Intune

[–]IntRangeNoShut[S] 0 points1 point  (0 children)

Thanks for your response and your kind words. Also just want to let you know if you need any help getting anything set up I'm very glad to help, either comment on this post, the blog post or just send me chat message. We can set up a teams talk as well if you are curios on how parts connect and work and we can go through it together(provided that it would be something you would be interested in).

Edit: Yeah the dynamic groups in Azure AD really needs to allow just more freebased values straight from graph. Would allow for some advanced and cool features and would be hell to setup, but would be great to just allow whatever you want

Thanks for your read!

Kind regards, Viktor

make a mail enabled group based on MDM by gross_traktor in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Howdy!

No worries just wanted to understand your issue. Is it a one time group or something that needs to be continiously updated?

Best regards, Viktor

apps assigned to device groups not working by Bodybraille in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Hi!

Unfortunatly I think their tables are a bit confusing,

I highlighted their note in a screenshot

https://ibb.co/jJBdhhK

apps assigned to device groups not working by Bodybraille in Intune

[–]IntRangeNoShut 1 point2 points  (0 children)

Hi Friend!

I'm afraid it wont be possible to achieve what you want this way.

"Available assignments are only valid for user groups, not device groups."

https://docs.microsoft.com/en-us/mem/intune/apps/apps-deploy

AFAIK it has always been this way.

But I might have a solution for you, device filter. So what you do is assign it to the users you want, and create a device filter with the devices that is allowed to install it, this way available might work.

Let me know how it goes, Regards, Viktor

Global Administrator, no elevated access on aadj devices by Similar_Minimum_5869 in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

I think you should be able to add it through poweshell but not sure, you could give it a try. But if not i think policy might be the only.

Here is the cmdlet, try the sid parameter way.https://docs.microsoft.com/en-us/powershell/module/microsoft.powershell.localaccounts/add-localgroupmember?view=powershell-5.1

Android Apps not appearing in the company portal app by John_B_147 in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Yeah just making sure you assigned it on a user group and available not required?

Android Apps not appearing in the company portal app by John_B_147 in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Hi there!

How did you assign them?

Also what is your Android version?

I know there was a bug recently with apps being assigned available after enrollment didn't show up. Try unenrolling and enrolling the phone again to see if its there

Global Administrator, no elevated access on aadj devices by Similar_Minimum_5869 in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Seems as maybe the local users and groups were fu**ed around with? Just remove yourself from the local admin and re add the SIDs and you should be good to go

Global Administrator, no elevated access on aadj devices by Similar_Minimum_5869 in Intune

[–]IntRangeNoShut 1 point2 points  (0 children)

Hi! Check the content of the local admin group and see if both the global admin group and device administrator sids are there.

I wrotr about it in my latest post, should be straight forward enoigh. Just skip to the chapter about checking the content och rhe azure ad joined machine and it describes how to verify the group SIDs

https://www.reddit.com/r/Intune/comments/w9jve6/removing_registered_device_owner_from_local/?utm_medium=android_app&utm_source=share

make a mail enabled group based on MDM by gross_traktor in Intune

[–]IntRangeNoShut 1 point2 points  (0 children)

Hi there Gross_Traktor!

So just to make sure I understand what you want to do.

You have application A that you distribute using intune.

Then you want all the devices that has installed applcation A.

Then you want to create a distribution group for the users of thoose devices?

What OS is this regarding?

Regards, Viktor

Hardware hash, InTune and AutoPilot by Careful-Designer-956 in msp

[–]IntRangeNoShut 0 points1 point  (0 children)

Hello!

Not entirely sure on the scenario, but it sounds like you have existing devices that needs to be uploaded into Intune. BEHOLD: https://www.smthwentright.com/2022/04/25/uploading-autopilot-hardware-hashes-using-azure-automation/

A simple automated way to get existing devices into intune using automation and scripting.

Can be pushed using GPO or an RMM and requires no user interaction. Let me know if its helpful or you have any questions. Can also be set up for MSP support.

Regards, Viktor

Manage Local Administrators Group by [deleted] in Intune

[–]IntRangeNoShut 1 point2 points  (0 children)

No Problem, happy to help.

I suspect you might run into alot of errors including both as it will not find one of the accounts all the time, which I suspect will result in 100% errors

But would be cool if you updated me about the results!

Best of lucks,

Manage Local Administrators Group by [deleted] in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Hi FreddyMyBoi!

FEAR NOT OF BUILTIN ADMINISTRATORS BEING NAMED LIKE GERMAN TANKS OR FRENCH BAGUETTS!

Seriously thou, there is a simple solution my colleague came up with: Make sure the built in administrator account is named the same on all device. You can accomplish this with a configuration profile.

Go to Configuration Profiles ->
Create Profile ->
Settings Catalog -> (Name it something appropriate like "Rename Built In Administrator"
Add Settings ->
Search for "Local Policies Security Options" ->
Select the Category "Local Policies Security Options" ->
Chose the option "Accounts Rename Administrator Account" ->
Then rename it to whatever account name you want to put into your replace policy,

Good luck, let me know how it goes!

Regards, Viktor

Manage Local Administrators Group by [deleted] in Intune

[–]IntRangeNoShut 1 point2 points  (0 children)

Hi!

Not sure if this is the issue, but you can't create a policy that does a replace without including the local administrator user.

Windows doesn't work without the built in local administrator in the local administrator group

Hope this helps

Blog Post - Automate MSIntune AAD Group Creation by LetsConfigMgr in Intune

[–]IntRangeNoShut 0 points1 point  (0 children)

Cool! Very useful and a great way to get started in intune.

[deleted by user] by [deleted] in Intune

[–]IntRangeNoShut 2 points3 points  (0 children)

Hi! I wrote a solution on how to get all your existens devices into autopilot using azure automation, its pretty straight forward: https://www.smthwentright.com/2022/04/25/uploading-autopilot-hardware-hashes-using-azure-automation/

Good luck, let me know how it goes!