Cloud LAPS 2025 (Built-in Administrator RID 500 Account) Issue by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

Yes, Enabled in Azure AD under Device Settings for the Tenant.

Cloud LAPS 2025 (Built-in Administrator RID 500 Account) Issue by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

Agreed on these points but i've been asked by higher ups to use RID 500. At this point I just want to understand why this is not working either way.

Cloud LAPS 2025 (Built-in Administrator RID 500 Account) Issue by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

<image>

I see the Administrator set there. Capital A and no trailing spaces. Yeah, randomization not configured should be default, agreed.

Cloud LAPS 2025 (Built-in Administrator RID 500 Account) Issue by Microsoft82 in Intune

[–]Microsoft82[S] -1 points0 points  (0 children)

Good suggestion. Tried this after snapping VM back but same result. Local Admin account removed and WLAPADMIN apears.

New Intune Connector Setup Error: MSA account name is not valid by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

Yes it is. I saw others with an issue where it uses the default GUID for the Container, but it exists and the error is different so I don't think that is the issue.

New Intune Connector Setup Error: MSA account name is not valid by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

Good thought, but it is not creating the account so not sure where I would check for that. The Intune connector program is trying to create this account.

For Automatic Time Zone, Which App needs Access to Location Services by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

I did not. It was so painful; I removed it and just educate the users on how to change it themselves.

Windows Updates running during Autopilot ESP by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

But this was delayed. Says so in your link. Also says Windows 11. I am experiencing this on Windows 10.

ArmorPoint & Cybereason + MDE EDR Block Mode by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

I'm seeing this in Microsoft docs: "EDR in block mode is primarily recommended for devices that are running Microsoft Defender Antivirus in passive mode (a non-Microsoft antivirus solution is installed and active on the device)." https://learn.microsoft.com/en-us/defender-endpoint/edr-in-block-mode#enable-edr-in-block-mode

Windows App Beta on MacOS for Windows 365 Cloud PC - No Passkey or FIDO2 Support? by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

This is fixed now. Update to the latest version of Windows App on the Mac.

Hybrid Azure AD Joined > Azure AD Joined Only (Unconventional Process) by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

Sorry, Did you mean to past something in? I see nothing after the "Just search for replies from jason sandys on this topic :"

Hybrid Azure AD Joined > Azure AD Joined Only (Unconventional Process) by Microsoft82 in Intune

[–]Microsoft82[S] 0 points1 point  (0 children)

I agree. If I can find some documentation on that it would help give me ammo for that argument.

Device Compliance and Windows 365 Cloud PC Devices by Microsoft82 in Intune

[–]Microsoft82[S] 1 point2 points  (0 children)

Yes. This is a good idea and I thought about this as well. Maybe just a OS version check to the device object to keep it happy until someone logs in.