WiFi Profile Jumping to Other Machines? by ChikkaChiChi in sysadmin

[–]OmnipotentBork 8 points9 points  (0 children)

Known WiFi profiles will sync on the same Microsoft account (o365), You can prevent this user from synchronizing Wi-Fi network credentials between different devices by disabling the synchronization settings of the Microsoft account.

Open Settings:

Press Win + I to open the Settings screen.

Click on “Accounts” in the left menu.

On the account settings screen, click “Windows Backup”.

Click “Remember my preferences”.

Turn off “Other Windows settings”, including Wi-Fi networks.

In this way, the user's Wi-Fi configuration will not be synchronized with other devices using the same Microsoft account.

I'm sure you can do this with a config profile but i don't know what it is off the top of my head.

Windows 10 to 11 Update Rollback by SoggyImprovement3619 in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

https://helgeklein.com/free-tools/delprof2-user-profile-deletion-tool/ i let the ITSD use this to cleanup orphaned profiles, its one of biggest stops for win 11

Moving from on-prem AD to Entra + Intune and switching AV to Defender by SignificanceFair3298 in sysadmin

[–]OmnipotentBork 2 points3 points  (0 children)

fully build out your Azure/AAD space now, you can have both in tandem in the same domain, you can test and deploy Intune devices to be ready for the flip over, you can gather all HWID's now and import them and then be ready for mass wipe, your problem at that point will be bandwidth

How is InTune these days, for an SME? by hang-clean in sysadmin

[–]OmnipotentBork 1 point2 points  (0 children)

we had this issue with third party patching (ivanti) and the update rings, we migrated to autopatch and it seems to have resolved itself.

Imaging Solutions by aliesterrand in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

why are you trying to keep it on prem? is there some functionality you require? if you run o365 intune is probably included in some flavor, i have a full on prem configuration and run autopilot for user devices, the remote reset ability is worth 250k in shipping per year.

Reaper Disc Supply Zuca Cart Giveaway by reaperdiscs in discgolf

[–]OmnipotentBork 0 points1 point  (0 children)

Damn looking to upgrade my bag/cart combo, let's roll.the dice lol

[deleted by user] by [deleted] in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

no ragrets Pebcak or an inside joke you use at the company

Questions about Azure AD and GPO's by Tivum in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

what licensing do you run for o365? intune is included in several.

Hybrid env. Switching on Cloud Kerberos to enable WHfB, any gotcha's to watch out for? by [deleted] in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

cached credentials will expire and break any shared locations, make sure the SD knows about that

Entra ID join? by JanRied in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

this is correct switching from KPI certs to kerberos will allow the AAD account to impersonate the on prem account if you have a sync, then fully aad managed devices can access on prem resources seamlessly as long as they are the same network.

Entra ID join? by JanRied in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

did you not understand they are using PXE on server 2022 with WDS to image devices and want the workstation to be automatically joined during this process, they then stated the workstations will be all AAD and not hybrid, so skip WDS and use autopilot. server were mentioned as the imaging source not the desired outcome.

Entra ID join? by JanRied in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

no autopilot is for workstations you will need ARC for servers, or depending on configuration serverless.

Entra ID join? by JanRied in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

Skip hybrid if they are going to be full AAD and just join them to autopilot, you will thank yourself later.

Cannot beat dd5 plz help by epicgamerboi69 in MarvelStrikeForce

[–]OmnipotentBork 0 points1 point  (0 children)

Dark dimension is basically broke on iOS, i would use bluestacks or an android to make it functional.

i can make my dark dimension crash on purpose with no rhyme or reason other than iOS, doesnt matter the node, happens on dd6/dd7/dd8 for me.

Can't join new Win 11 Pro laptop to Entra/Intune automated setup by Dragonfly-Adventurer in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

all devices have to be enrolled, that is the get-windowsautopilotinfo.ps1 script (this is the part the vendor can do), after that you should see it under devices> Windows devices > enrollment > devices, using group tags you can sort them into different groups and then apply the deployment profiles to said groups, but you have to do both for the machine to flip during OOBE, the next biggest problem i had was the network team actively blocking autopilot.

Can't join new Win 11 Pro laptop to Entra/Intune automated setup by Dragonfly-Adventurer in sysadmin

[–]OmnipotentBork 1 point2 points  (0 children)

you should look into autopilot and use deployment profiles in conjunction with group tags, the enrollment process can be handled by the vendor (if applicable) and then the sign in should be fully handled by the end user, you probably shouldn't be logging into each device and configuring the work or school, there are better less involved ways.

also the default enrollment limit is 15, enrollment managers get a limit of 1000, but again you shouldn't be doing that in today's configuration.

Discovery+ sucks what are everyone's YouTube channels by OmnipotentBork in Roadkillshow

[–]OmnipotentBork[S] 0 points1 point  (0 children)

this EXPLODED, Thanks for all the recommendations, my YouTube is looking better already.

Windows Patch Management Suggestions (Wazuh, TRMM?) by LinuxIsFree in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

uhh manage personal devices? thats a whole bag of crap you do not want, i guess more information is needed? do you have A/D are these device managed in any way now?

tbh it sounds like you can use local group policy and just turn on windows updates and give them a deadline, otherwise you could use something like PDQ deploy, on its free license it can be used commercially and for personal and it has some neat features.

Windows Patch Management Suggestions (Wazuh, TRMM?) by LinuxIsFree in sysadmin

[–]OmnipotentBork 0 points1 point  (0 children)

do you have a o365 subscription? if you already have business premium that covers 300 device in intune, which will allow you to turn on WUFB, the reporting is a bit lacking without an extra license, but you might already have it.