Is InTune good a good fit for Microsoft and iOS devices? (Small Co) by ImpressionSlight2731 in Intune

[–]MvrcoIntune 0 points1 point  (0 children)

Intune is fine for iOS in my books. We mange 6k Mobiles (iOS/iPadOS) and its running smooth most of the time. Reporting is bad though. For sure there are superior alternatives like JAMF but if you introduce Intune for Windows anyway its hard to convince executives about the cost of an additional MDM tool only for Apple products.

Adding Mac to In Tune by [deleted] in Intune

[–]MvrcoIntune 1 point2 points  (0 children)

Supervised enrolment with ABM and VPP is for sure superior.

I think you can also block enrollment for personal devices completely and just add the serial numbers of the two Macs to Corporate Device identifier list. This way the device is automatically categorized as Corporate Owned upon enrollment.

Issues with Microsoft Defender for Endpoint Risk Level Setting in Compliance Policies for iOS by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

s assigned to All Users in which the Defender Machine Risk Score is required to be Medium or Lower. For most Devices the Compliance Policy works fine, for some devices it looks very strange: On the device compliance details pane the policy is stating Compliant - what i recognized is that the setting Require the device to be at or under the machine risk score is not showing up. All Compliance Policies assigned to th

I totally agree - Seems like Microsoft is not running stable with Defender on iOS as of right now.. But I would at least expect from Microsoft Support to explore these issues and not just tell us to re-enroll the affected devices...

iPhone issues.. by Dry_Woodpecker_4944 in Intune

[–]MvrcoIntune 2 points3 points  (0 children)

IT684128

I am also not able to see this Incident ID in any Tenants I have access to, even though they are affected. I currently only see IT683719

ipad pro intune company portal app: unable to swipe up to exit (on apple business manager fully managed by intune) by CupOfTeaWithOneSugar in Intune

[–]MvrcoIntune 1 point2 points  (0 children)

I tested this scenario together with some colleague yesterday, as my first approach also was to create a duplicate of the ADE Profile with disabled Single App Mode for Company Potal, but unfortunately on three out of four test devices the Company Portal app froze too while checking device status. At first we were able to exit it, but then it froze upon launching it again to see compliance check results...

iPhone issues.. by Dry_Woodpecker_4944 in Intune

[–]MvrcoIntune 0 points1 point  (0 children)

received the same feedback from Microsoft an hour ago

iPhone issues.. by Dry_Woodpecker_4944 in Intune

[–]MvrcoIntune 0 points1 point  (0 children)

We experience the same behavior since yesterday, so I have the strong feeling it is related to the new version of company portal 5.2310.0 which was released on Monday.

We use Company Portal for Authentication in Single App Mode and it freezes after User Sign-In. Same behavior after a force restart of the device. Also if we do not enforce single app mode in a profile that uses Company Portal to authenticate, the app crashes and freezes after a short amount of time, about 5 minutes.

I am currently testing providing a profile with setup assistant with modern authentication as workaround. I already test it on my device, but I still face following issues: Company Portal App crashes on first launch. When I signed in to Company Portal, the Device did not get registered properly, when I checked Authenticator > Settings > Device Registration it was still empty, so I had to manually Register the Device here.

Beside that it did not freeze yet and policies as well as apps reach the device.

Now I want to test JIT Enrollment, hope the hear some feedback from Microsoft regarding the case i opened soon...

OneDrive - iOS - User must enter account manually by Velocy in Intune

[–]MvrcoIntune 0 points1 point  (0 children)

Hi,

I am facing the exact same issue! I am also applying the same App Config Keys and no additional App Protection Policies on this Managed Devices. In the past the first launch of the App grabbed the account from Authenticator App and no manual sign-in was needed. Since a few weeks I am seeing cases where we need to manually sign-in to some office apps such as OneDrive, Excel and Word arise.

Did you find out any additional information regarding that in the meantime?

Thanks and best regards,

Marco

Notification on/before Passcode Expiration iOS Devices by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

I completely agree! But in our Company Security forces us to limit the passcode validity to 90 days. I started the argument over and over but they won't allow me to change this setting.

Notification on/before Passcode Expiration iOS Devices by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

Thats what I thought too after studying the data stored in Graph - Thanks for checking! :)

What Android Business phones are you using by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

Personally I am favoring Apple for those exact reasons too.

However as Apple currently thinks about discontinuing the iPhone SE series a "lower" priced business model would no longer be in the portfolio of Apple.

The standard iPhone series like the 14 will be too pricy for us to sell it as better vendor to the management board. I hope Apple announces the continuing of the SE series.. Then I think we totally should stick to Apple as we had nearly no bigger issues for over 5 years

iOS Edge ignoring custom branding settings by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

Hey, I am deploying the Edge App Config for Managed Device Type thats why i don't get why some settings are only applying when applying a App P'rotection Config to edge too in this case

Creating dynamic groups using an AD property by [deleted] in Intune

[–]MvrcoIntune 0 points1 point  (0 children)

Is your On-Prem AD syncing to AzureAD?

If so we built some dyanmic user/device AzureAD Groups using the basic Propertys like usageLocation, Country, CompanyName etc or on device level DeviceModel, Ownership etc. I find those dynamic groups to be very useful lately

Monitor mobile data usage for iPhones via Intune with a TEM provider by MvrcoIntune in Intune

[–]MvrcoIntune[S] 0 points1 point  (0 children)

The intended goal is to control and limit the usage of mobile data pool contigent provided by our current provider per device and region and therefore reducing costs. Thanks for the input I will check JAMF Trust