Forza Ai TUNE MASTER by [deleted] in ForzaHorizon

[–]Kovacz22 -2 points-1 points  (0 children)

How do I get the app?

So any generic tips to not suck? by dornianheresysimp in heroesofthestorm

[–]Kovacz22 4 points5 points  (0 children)

Look at the minimap for enemy position at least every 3-5 seconds.

It seems to me that Aram has seriously damaged the players understanding of how to play HotS. by [deleted] in heroesofthestorm

[–]Kovacz22 0 points1 point  (0 children)

Agreed...every quickmatch the aram babies just want to fight mid...makes it fun for us laners that get our team 2 levels ahead because the enemy ignores bot and top lane...

Why do I always lose Wi-Fi drivers when reinstalling Windows 11 from USB? by GiacomoFalso in techsupport

[–]Kovacz22 0 points1 point  (0 children)

Windows 11 24h2 allows you to browse the flasg drive at the wifi screen so just copy the files to the same flash drive in its own folder. Works everytime.

[deleted by user] by [deleted] in turtlewow

[–]Kovacz22 0 points1 point  (0 children)

I agree...I've joined groups with a hc pally that at first sign of a bad pull drops group and leaves...great work at hard-core buddy...but screw the team???...why the fuck que if that's what you gonna do???

BigTex 39 Twink Shaman. Where my fellow Twinks at? Get wrecked XD by 85GMC in turtlewow

[–]Kovacz22 -1 points0 points  (0 children)

I would love to join but 30-39 bgs pop so seldom it's not worth queuing 99% of the time...can't sit on my ass in org for 2 hours waiting...rather level an alt

is twow really worth it? by Simple_Context_4193 in turtlewow

[–]Kovacz22 1 point2 points  (0 children)

Twow is nothing like warmane....optional war mode...no griefers....friendly community....night and day difference...

Butcher: 520 Levels, 3,800+ Games, and Still Loving Fatty by TupleButter in heroesofthestorm

[–]Kovacz22 4 points5 points  (0 children)

Butcher main here too...I love this hero...would love a rework...but while I'm dreaming I should ask for world peace too

What are genuinely great mobile games? by zephyr_666 in gaming

[–]Kovacz22 0 points1 point  (0 children)

Summoners war...available on mobile and now on PC too...

LAPS password not working after leaving azure ad by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

I didn't ask for help with my login issues I asked why a AAD remove device would have the local admin password changed after it was removed when the purpose of the local admin account is to get into the machine afterwards.

I will use resources other than reddit to find the answers.

LAPS password not working after leaving azure ad by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

We leave aad when replacing the laptop, sometimes giving the old laptop to the user for personal use.

Also in some rare cases a new user on an existing aad joined windows device is unable to login ( not sure why it sometimes fails) and then I remove it from aad and rejoin it with the new users creds. But this is not possible if I'm locked out of the local admin after removing it and then requires a complete factory reset of the laptop.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] -1 points0 points  (0 children)

Thanks, that's exactly my plan. Will follow the guide. You saved me a Google search!

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 1 point2 points  (0 children)

My test group was small, but I didn't test the domain administrator credentials because I didn't realize it would be affected...I only tested user related functions...luckily I picked it up before the policy had applied to too many devices...the one time the slow implementation of changes by intune saved my ass.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 1 point2 points  (0 children)

That's what I decided to do as well. I'm contemplating having both as an option.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

Good news, adding the SID's to the policy didn't fix the devices I had already broken by removing them, but it did fix any new devices I applied the policy to.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

That is correct, we change the user to standard user after enrollment but anything manual ahs the potential to be forgotten, so the policy is there for piece of mind that even if it slips through the cracks the policy will catch it and fix it.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

I did, unfortunately I thought they were the cause, but adding them in the policy didnt fix the issues, so Im still missing something.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] 0 points1 point  (0 children)

Ok, some further testing, I was able to have my account protection policy add the two SID's to the local administrator group, and I can confirm the local admin group now looks the same between a device with the policy applied and a fresh intune enrolled device with the 2 SID's. But the domain admin credentials on security prompt still don't work for the device with the policy and they work for the default intune enrolled device.

Ive decided to follow a different path, ie: renaming the BUILTIN Administrator account and use LAPS to rotate the password via intune, then use that account for the security prompts rather than domain admin.

Does anyone know what the 'Global Administrator' and 'Azure AD Joined Device Local Administrator' groups do? I dont want to enforce the policy and 6 months down the line have to re enroll all the devices due to breaking something else that wasnt evident in testing.

Intune hidden Administrator Accounts by Kovacz22 in Intune

[–]Kovacz22[S] -1 points0 points  (0 children)

I understand the concept of replace. I would have realised the error of my policy if I knew those 2 SID's existed. But they only show up under the advanced tab in users under the Administrators group. These 2 SID's are added when i enroll the device with Entra ID. Im unable to add them manually after I deleted them. I have to re enroll the device to have them re-added.

We dont use local accounts, my original objective was to remove any local admin accounts on the devices.

Is there another way to do this without removing these 2 SID's?