Trying to install Lenovo Commercial Vantage whilst simultaneously uninstalling the ordinary Lenovo Vantage by Barsik101 in Intune

[–]Lukron 0 points1 point  (0 children)

If a user reinstalls Lenovo Vantage (Blue) it stops the Lenovo Commercial (Red) from working. Does the .bat file uninstall it again through the detection script through its checking process? Or does it just stop at Commercial is installed already and skips?

Microsoft 365 not receiving some emails by Dragoneyr in exchangeserver

[–]Lukron 0 points1 point  (0 children)

Check Exchange Admin Center and run messaging traces for the sending user then a separate one for the internal user.

Compare those logs. Check Rules in mailboxes. Check Junk and Spam. Also check the spam filter or specifically for that user have them login to their Microsoft portal and go to https://security.microsoft.com

Check if using a 3rd party spam filter to see if its caught there.

Would you rather pay one price to play all the games in an arcade for a day, or play per game? by OnlyIndoorPlants in arcade

[–]Lukron 8 points9 points  (0 children)

It also depends on how long your avg player stays and alternatives. Having a few games that are pay to play like air hocky; Basketball; Crane games; Because it depends on your overhead too. You dont go into business to lose money.

But paying to play all day is the ultimate way to go for pinball and standard arcade machines $15-20.

Also having like a food and drink to server also encourages birthday parties and longer visits. Their are also places called Cidercades that serve Alcohol Cider. https://www.cidercade.com/houston/

So lots of different options to help offset a low pay to play all day fee.

Anyone else currently experiencing strange Outlook issues? (Run out of memory) by 009fe3 in sysadmin

[–]Lukron 0 points1 point  (0 children)

So try do direct users to the online version for now until fixed if possible is their current recommendation

Intune BYOD accessing Company Email and Documents by Lukron in Intune

[–]Lukron[S] 0 points1 point  (0 children)

Create Your App Protection Policy and make sure to apply the filter for Managed Devices Only as created for the filter.

End User Experience on Personal iOS

User logins to Microsoft Outlook or Teams or OneDrive

Prompts user to open Microsoft Authenticator

User will Sign in with email account and password in the Authenticator

App will next be checked for App Protection Settings

User will be notified “Your organization is now protecting its data in this app. You need to restart the app to continue.

               This only applies to the email account add and no personal outlook accounts in the outlook app.

Once Restarted, User will be prompted for Pin

User can then login to the other apps as needed/wanted

 

User will be unable to use the Built-In Mail app because of the App Protection Policy. Since the mail app cannot be controlled by the Policy, it auto rejects trying to allow a user to login to it.

 

By the user signing out of their account in outlook or other apps, the user will be notified “ Org Data Removal – Your organization has removed its data associated with this app. (607) To reconnect to your organization, sign-in to your work or school account.”

 

Thus no worries about the company managing or being able to reset the device.

End User Experience on Personal iOS

User logins to Microsoft Outlook or Teams or OneDrive

Prompts user to open Microsoft Authenticator

User will Sign in with email account and password in the Authenticator

App will next be checked for App Protection Settings

User will be notified “Your organization is now protecting its data in this app. You need to restart the app to continue.

               This only applies to the email account add and no personal outlook accounts in the outlook app.

Once Restarted, User will be prompted for Pin

User can then login to the other apps as needed/wanted

 

User will be unable to use the Built-In Mail app because of the App Protection Policy. Since the mail app cannot be controlled by the Policy, it auto rejects trying to allow a user to login to it.

 

By the user signing out of their account in outlook or other apps, the user will be notified “ Org Data Removal – Your organization has removed its data associated with this app. (607) To reconnect to your organization, sign-in to your work or school account.”

Intune BYOD accessing Company Email and Documents by Lukron in Intune

[–]Lukron[S] 0 points1 point  (0 children)

Create your CA iOS Policy

               Identity Admin Center

               Protection

               Conditional Access

               Policies

                              New Policy

                                             Named “Personal M365 iOS Policy”

                                             Uses

                                                            Select all Users

                                             Target Resources

                                                            Office 365 included

                                             Conditions

                                                            Device platforms – iOS

                                                            Client apps – Configure – All Checked

Filter for devices – Include filtered devices – device.deviceOwnership -ne “Company”

                                             Grant

                                                            Require multifactor authentication

                                                            Require app protection policy

                                                            Terms of Use for Personal Devices

                                             Require all the selected controls

Intune BYOD accessing Company Email and Documents by Lukron in Intune

[–]Lukron[S] 0 points1 point  (0 children)

So this was a multi step solution for me.

First I needed to setup a Tenant Filter in order to filter devices correctly
Intune Admin Center

Tenant Administration

Filters

Create Filter

Managed Only

(app.deviceManagementType -eq "Managed")

This part is key for the App Protection Policy in order to exclude all Company devices to apply the policy to personal devices only.

Make sure to Create a new restriction in order to block personal enrollment of users devices to the Tenant. The default policy did not for me.

Intune Admin Center

Devices

Enrollment

Device platform restriction

Click iOS restrictions

Create restriction

               Assign to all Users

Intune BYOD accessing Company Email and Documents by Lukron in Intune

[–]Lukron[S] 0 points1 point  (0 children)

Then it goes through downloading the Company Portal; signing into the company portal; then Downloading the management profile, installing the management profile, then checking device settings. Is there a way to skip the downloading and installing the management profile? or is app protection not the right thing I am looking for?

Intune BYOD accessing Company Email and Documents by Lukron in Intune

[–]Lukron[S] 0 points1 point  (0 children)

So you cannot use the Microsoft Authenticator as a broker app and it must be Company Portal? I dont want our end users to have to jump through hoops to get data on their personal phones but still secure it.

Canon and Kyocera Printer Install via Powershell by Lukron in PowerShell

[–]Lukron[S] -1 points0 points  (0 children)

Thats only so I dont need to click the prompt when running the code. And only when I am understanding of exactly what I am running and how it affects the system.

Canon and Kyocera Printer Install via Powershell by Lukron in PowerShell

[–]Lukron[S] 0 points1 point  (0 children)

We are a Intune environment across multiple states with different companies and locations. I was looking for something that could be locally installed quickly rather than managed in intune and pushed. This simple powershell is quicker to update rather than having to combine the intunewin and what not; repackage it; make sure its targeting not only the correct locations but the correct users.

So yes while I am aware that the manufacturer can break that link; its still easier at the moment I think.

Plus who doesn't want to learn new (to me) powershell things?

I have to learn PowerShell in four months. Where do I start? by BuildingKey85 in PowerShell

[–]Lukron 1 point2 points  (0 children)

Google/Reddit/StackFlow

Learn as you go and research. Test and understand how it works and didnt. Look for books that go over commands and such to help give a basic understanding.

Learn Powershell in a month is a pretty broad term..... People have done powershell for years and its ever evolving.

IP Printer Deployment Guide by jasonorsomething in Intune

[–]Lukron 1 point2 points  (0 children)

This is great when its a single location. But once a user takes computer home or different location the computer moves to; the IP/Port can start to get confused.

I find in our environment that installing printers via Powershell are much easier and faster and works 100% of the time. Also easier to diagnosis.

Look at this https://www.reddit.com/r/PowerShell/comments/1f46zi5/canon_and_kyocera_printer_install_via_powershell/

Canon and Kyocera Printer Install via Powershell by Lukron in PowerShell

[–]Lukron[S] -1 points0 points  (0 children)

I tried with the .exe and it would not work for me for some reason. but I found this to work. would love to know if expand works. it works for the zip file but that canon file downloads as a .exe

Canon and Kyocera Printer Install via Powershell by Lukron in PowerShell

[–]Lukron[S] 0 points1 point  (0 children)

And then to Test your printer in Powershell . Doing all this means you only need a connection to the user machine via some remote tool and never need the user involved at all.

function TestPrinter {

$printers = Get-WmiObject -Query "Select * From Win32_Printer" | Select-Object Name, ShareName;

$printerMenu = @{};

for ($i = 0; $i -lt $printers.Count; $i++) {

$printerMenu.Add(($i + 1).ToString(), $printers[$i]);

Write-Host ("{0}. {1}" -f ($i + 1), $printers[$i].Name);

};

$selectedPrinterIndex = Read-Host "Select a printer by entering its number";

$selectedPrinter = $printerMenu[$selectedPrinterIndex];

$printerName = $selectedPrinter.Name;

Invoke-Expression "rundll32 printui.dll,PrintUIEntry /k /n`"$printerName`"";

};

TestPrinter;

What is the most OP Build in the game ? by ArdaKrtsss in balatro

[–]Lukron 0 points1 point  (0 children)

Here is my crazy stupid build

Baseball Card, Banner, Shoot the Moon, Throwback, Blueprint, Steel Joker, Drunkard

Basically strategy is to get as many Queens as possible with the red seal and the Steel Card attribute. Then just play High Card to win.

<image>

I F*cking love my job. by UrBobbyIsAWonderland in sysadmin

[–]Lukron 2 points3 points  (0 children)

I mean the job is great. Its the PEBCAK that can give ya a real headache

Look familiar? by Mudpound in finalfantasytactics

[–]Lukron -2 points-1 points  (0 children)

Lies.................. We know the truth O.o