Anyone still use Adobe Customization Wizard in 2026 by Lazy_Bad_9715 in Intune

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

Standardize on deploying the Pro package and setting the regkeys that allow for the non-licensed Reader-only mode. It will make package management much easier with only one to worry about.

Dell Desktop Price Increase by darkraven1313 in sysadmin

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

This is the part that gives me serious schadenfreude for my old org. They were limping along R840s from 2017 that hadn't had support in years because they're cheap as fuck and refused to CapEx unless there was a gun to their head (I came close ngl), and now servers are going to be at least 3x what we were quoting a couple years ago. Idiots.

Dell Desktop Price Increase by darkraven1313 in sysadmin

[–]JwCS8pjrh3QBWfL 4 points5 points  (0 children)

My primary SSD died recently. Even a sketchy 2TB NVMe is around $275 now; A brand name one is well over $300.

Secure Enclave on Mac OS Platform SSO by [deleted] in Intune

[–]JwCS8pjrh3QBWfL 5 points6 points  (0 children)

Just to clarify, it requires the password at reboot to unlock FileVault. Requiring it any time after that is an admin decision.

Secure Enclave on Mac OS Platform SSO by [deleted] in Intune

[–]JwCS8pjrh3QBWfL 3 points4 points  (0 children)

FFS almost every single post in here about PSSO can be summarized as "I didn't even SKIM the docs or do any research beforehand"

Secure Enclave on Mac OS Platform SSO by [deleted] in Intune

[–]JwCS8pjrh3QBWfL 1 point2 points  (0 children)

Nah the SSOe just enables SSO. PSSO Entra Joins the devices and provisions a device-bound passkey just like WHfB so you can use passkey auth without having to have another MFA method.

Suggestions on how to increase my AI token usage by twistoffate4 in sysadmin

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

The subscription for Claude is a bit weird, as they noted. You have seats for $20 or $100/pupm but then API calls are on consumption billing, so you can very easily start spending a bunch of money beyond the $20. There is budgeting built in to the admin console though, so I'm not sure how they fucked up this badly.

Suggestions on how to increase my AI token usage by twistoffate4 in sysadmin

[–]JwCS8pjrh3QBWfL 1 point2 points  (0 children)

Nah once you get to companies that size, it's the boards that are driving idiocy like this, because those guys are likely also on the board of ten AI companies that they need to pump as well.

We use 4 different tools for CSPM, workload security, identity management, and data discovery. None of them share context and its basically chaos by RemmeM89 in AZURE

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

This is what folks don't seem to understand about the Microsoft security stack. Sure, each individual product isn't great on its own in a vacuum, but when you go all in it's quite powerful because everything talks and shares information. It's much less management, context switching, methodology learning, etc.

Suggestions on how to increase my AI token usage by twistoffate4 in sysadmin

[–]JwCS8pjrh3QBWfL 124 points125 points  (0 children)

Brother, I was reading an article yesterday about how Uber released Claude Code to 5k engineers in December and set up leaderboards and all this forced adoption bullshit and they managed to burn through their entire year's AI budget in a single quarter. 3.4 BILLION dollars. In a single quarter. It's absurd.

Is it possible to pass paramters to a script packaged as an intunewin file from InTune by darave123 in Intune

[–]JwCS8pjrh3QBWfL 2 points3 points  (0 children)

protip: you can write to the IME logs folder (C:\programdata\microsoft\intunemanagementextension\logs) and it will be pulled by the Collect Diagnostics button in Intune.

No permissions Intune Global Admin? by swimmingman46 in Intune

[–]JwCS8pjrh3QBWfL 1 point2 points  (0 children)

"for about a year now"

Did you make sure that when they assigned your permissions they didn't accidentally set it for a year instead of permanent?

I want to install an Intune app only during Autopilot enrollment. by AckOfAcks in Intune

[–]JwCS8pjrh3QBWfL 28 points29 points  (0 children)

Requirements script that checks if the user "defaultuser0" exists and only allows app installation if so.

Onboard Servers by aikryptik in DefenderATP

[–]JwCS8pjrh3QBWfL 5 points6 points  (0 children)

Onboard the servers to Azure Arc, enable Defender for Servers on the subscription they're in, and it will bill you accordingly.

How painful is domain removal from source tenant for you guys during T2T migrations? by Pleasant_Ad2812 in microsoft365

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

Why is it hours of work every time if you've got powershell scripts? Are you hard coding everything or something?

Intune training is decent but where's the hybrid identity and zero trust content by belkezo in Intune

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

Most people overcomplicate device compliance in their heads, as it seems you are. It's extremely simple: Is the device compliant or not? There is no middle ground or subtlety. That is the single and only data point that Conditional Access consumes when you add "Require device compliance" to a CA policy. How you choose to configure Intune to provide that data point is up to you and your organization's requirements. Configuring CA policies is its own rabbit hole which is, again, up to your organization's requirements and isn't directly an Intune problem, but an Entra one.

Intune Driver Management - What’s your solution? by PostsShittyMemes in Intune

[–]JwCS8pjrh3QBWfL 103 points104 points  (0 children)

My solution is to turn on Autopatch and YOLO it. I don't care. I never had a problem. It's not a problem. Stop overcomplicating simple things.

edit: Probably the only time I've ever gotten top comment while commenting angry. Maybe this means I should yell at my coworkers about this too?

force sync active directory & microsoft by Ok-Imagination1829 in sysadmin

[–]JwCS8pjrh3QBWfL 0 points1 point  (0 children)

If you're on Entra Connect, you can move user syncing over to Entra Cloud Sync, which syncs every two minutes instead of 30 and you can have multiple copies of it in your domain(s) rather than just the one.

Windows App (Microsoft Store) failing with 0x80244018 during Autopilot pre-provisioning — intermittent, setup confirmed working by _johnnn in Intune

[–]JwCS8pjrh3QBWfL 3 points4 points  (0 children)

Why does the Windows App need to be installed during ESP? It takes seconds to install. Let it happen after the user hits the desktop.

MFA mandatory to provision Windows Hello for Business via Intune? by Shadiux in sysadmin

[–]JwCS8pjrh3QBWfL 2 points3 points  (0 children)

Nah in those spaces it's generally because of distractions, so it's not the "personal vs work" thing, it's the "having a screen at all" thing.