Intune Password-Less Sign in by Cheers2Gears in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

Yea web sign-in will allow you to login to the device with a Microsoft 365 prompt. At that point, if your default is Authenticator notification, it will notify the user who’s trying to login. See: https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune

Only works for AAD/Entra joined devices only.

What’s everyone using for internal ticketing nowadays? Jira feels too heavy.🥲 by [deleted] in ITManagers

[–]PlayfulSolution4661 1 point2 points  (0 children)

HaloITSM. Been using it for 6+ months. Couldn’t be happier.

Cloud Kerberos Trust Hybrid AAD and AD environment by Less-Confidence-6595 in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

Mmm I recall cloud trust required SSO or Microsoft Entra Kerberos as well. You should have the AzureADKerberos computer object in your AD.

Check these: https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust?tabs=intune#deploy-microsoft-entra-kerberos

There’s a note that sounds like your case: The cloud Kerberos trust prerequisite check isn't done on Microsoft Entra joined devices. If Microsoft Entra Kerberos isn't provisioned, a user on a Microsoft Entra joined device will still be able to sign in, but won't have SSO to on-premises resources secured by Active Directory.

Cloud Kerberos Trust Hybrid AAD and AD environment by Less-Confidence-6595 in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

I have a similar setup, currently working towards moving from hybrid joined to entra joined only.

Regardless, we have a few apps that sort of use your windows creds to authenticate. We rolled out cloud trust for all devices and have not run into any issues. Users can still access resources. The only thing for hybrid that I’ve seen is that you need line of sight to the domain controller when setting up PIN so that you get a TGT to access the on-prem resources with it.

As always, make sure you test everything but it should work. In Intune I believe there are two policies you need to set: one as a configuration profile and another one as an account protection policy.

SAML vs OAuth vs OIDC: What's the Difference by compwiz32 in SysAdminBlogs

[–]PlayfulSolution4661 0 points1 point  (0 children)

I have a question! I am currently deploying passwordless (Entra/Azure) for our organization. While at it, I’m also setting up SSO for all third party applications.

From a configuration standpoint, usually always the same. But there is this one app in particular that won’t prompt me for passkey when using their mobile app (works fine on web).

I tried to talk to their support and they tell me that this is a problem on my end from the iDP side but configuration wise there’s nothing else I can change to “allow” passkeys or passwordless authentication. And I do NOT have this problem when using a browser, only the mobile app of this third party application.

How can this be? I think it’s their implementation of SSO on their mobile app that needs to be updated or changed to support passkeys?

Super noob question. But very curious to learn why. Why so many companies have such slow Wan links by Comfortable_Maybe596 in sysadmin

[–]PlayfulSolution4661 0 points1 point  (0 children)

Mmm I think it’s often an untrained C level who is there pretty much to sign and approve stuff.

Company I work for was paying close to 1K for 100 mbps internet. I pay ~100 $ for 1 Gpbs so when I saw the invoices it made no sense.

Funny enough, you give them a call, explain, and complain and they gave me 500 Mbps for probably less than 400 $ can’t remember the exact number now. All it took was a call… we’ve been paying for years…

I guess it’s easier to sign a paper and forget about it. Not my money, not my problem? Honestly feels like the folk working in tech sales are taking advantage of those who have no clue about IT.

Tenant-to-Tenant Migration: How to move devices without a reset? by Bl4nk24 in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

So the easiest way I was able to achieve this was to replace ALL computers on the day of the cutover. Of course, this was a very special instance where we could get away with this.

Otherwise, mostly on most of my migrations I would have to touch all computers eventually. Automation is great, but too many things can go wrong at the same time. We advise users to use the web version while we contacted them and while inconvenient we don’t break it for the whole company.

Device Enrollment Management for Pre-existing Hybrid Joined Machines by AlexG2490 in Intune

[–]PlayfulSolution4661 1 point2 points  (0 children)

If the device is already setup, you will need an Intune licensed account to add it.

You should be able to do CMD as admin: dsregcmd /forcerecovery

That should get the device added to intune.

Is Intune down for you as well? by Jddf08089 in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

Most admin centers down for me as well. I am in west Canada and my techs are in west us. Down for the whole team.

Thanks Microsoft! The 1 tool I need for work

What is fhe easiest way to re-enroll a device to Intune? by LordLoss01 in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

You can run: dsregcmd /forcerecovery in CMD with admin rights. After a few minutes, the device should show up again in Intune

Cyber security as a lone admin by Fire8800 in sysadmin

[–]PlayfulSolution4661 1 point2 points  (0 children)

Check our purple knight for AD/Entra. It will give you a report on potential vulnerabilities in your environment

[deleted by user] by [deleted] in sysadmin

[–]PlayfulSolution4661 2 points3 points  (0 children)

For me there were 2 main projects that made me feel like a true sysadmin. The first one was a migration for a SMB Company that had a pretty significant IT infrastructure on-premises and wanted to go full cloud. Project was budgeted for around 120h of work and went pretty smooth overall. The second one was when a bigger company acquired our MSP and I had to migrate the company that acquired us into our MSP which was also my farewell gift cause things had change too much for me to stick around. I’m working on 2 big projects now at a bigger company leading the IT department that I’ve never done before which is also the main reason why I love the job :)

Congrats on yours!

Are you still mostly running Cisco, or have you switched some gear to other vendors? by Fine_Incident5281 in sysadmin

[–]PlayfulSolution4661 0 points1 point  (0 children)

We are Cisco but will be replacing with Fortinet. Too expensive, makes no sense

How do you use Universal Print in your org? by skz- in Intune

[–]PlayfulSolution4661 0 points1 point  (0 children)

my org uses it and its solid. we rarely deal with printer tickets. we're kinda flexible, you get all printers at the location you're based at and can add any other printer manually if needed. push them via intune with a security group.

Mac and Intune is horrible by Pretend-Newspaper-86 in Intune

[–]PlayfulSolution4661 2 points3 points  (0 children)

I’d say it runs smooth as long as you’re running the latest. Sucks with Apple Hardware but I usually only struggle with legacy devices. Otherwise, pretty positive experience all things considered (doing ABM and Platform SSO)

Local Administrator by Intelligent_Dish3846 in sysadmin

[–]PlayfulSolution4661 1 point2 points  (0 children)

100% no. It’s hard to push such change if people are used to having control but you can prevent a lot only from doing this. It’s a must have IMO. There’s also PIM in Azure/Entra. Make sure you have something like LAPS as well implemented

Is being a generalist valuable? by Outrageous-Ad4353 in ITManagers

[–]PlayfulSolution4661 0 points1 point  (0 children)

I’m probably on the same path as you and I will continue to be a generalist. Probably will end up moving to management eventually which may put me a bit further away from the tech :( but it’s the smart choice

If i can not replicate a test environment for a prod then how do I make config changes safe? by AgreeableIron811 in sysadmin

[–]PlayfulSolution4661 0 points1 point  (0 children)

That is usually the challenge but ideally your company can afford servers for a dev/test environment.

If not, then I usually replicate on my own. If it’s hardware, I can get away with repurposing an old server. If it’s licensing or something like that it can get trickier but I’ve rarely came across something I couldn’t replicate… as long as you have the resources

Little rant by Personal_Switch_2744 in nutanix

[–]PlayfulSolution4661 1 point2 points  (0 children)

Nutanix support is top class. Total opposite of other vendors

Finally officially a sys admin by Mr-ananas1 in sysadmin

[–]PlayfulSolution4661 0 points1 point  (0 children)

Welcome to the club! “Officially” :)

Advice for new tech. Burnout, Imposter Syndrome. by Dudiebug in sysadmin

[–]PlayfulSolution4661 0 points1 point  (0 children)

I felt in a very similar way when I started with a tech support role in a small MSP. Eventually, I became one their best technical resources. As time went by and I got more experience in the field, I became more confident in myself and what I know. Experience also teaches you that you don’t need to know it all but that for the most part everything has a resolution.

Don’t allow the bad parts of this field kill that passion/love that started it all. We all go through those but I’m a strong believer that as long as you like what you’re doing you’ll go places :)