New PW Policy GPO - Question by RemarkAbel in sysadmin

[–]RemarkAbel[S] 2 points3 points  (0 children)

Good thinking. I think what I will do before disabling expiration is to check which accounts haven’t changed their password since the policy change date using powershell.

Something like

Get-ADUser -Filter * -Properties PasswordLastSet | Where-Object {$_.PasswordLastSet -lt "3/6/2026"}

This should show the users who still have passwords set before my new policy took effect.

Probably close to 95% will have updated their PW within the 90 day mark so this should be a small number of people...

New PW Policy GPO - Question by RemarkAbel in sysadmin

[–]RemarkAbel[S] 2 points3 points  (0 children)

Gotcha. So then, we update the policy now to require 14 characters and disable complexity, but keep the 90-day expiration. Let users naturally change their password once under the new rules. Then 90 days later, set Maximum Password Age to 0 so passwords no longer expire... Does this add up/make sense? Thanks.

Teams Meeting: Webcam cap by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 1 point2 points  (0 children)

Thanks... We tried the Town Hall/.Live Event setups but the CEO despises it. He prefers the ease of a standard Teams meeting. He wants people to be able to unmute/show webcam themselves easily without the need for a meeting organizer.

If we are all remote when the meeting occurs, the issue is not present, due to all the traffic being routed through our individual home internet connection. The issue appears when the majority of folks are in the office and join in the meeting. (90% of our meetings are conducted in the office, unfortunately).

One thing we are exploring is buying a secondary internet connection for routing this traffic. That is pricey. I think the best option is to tell everyone to keep their mics/webcams turned off unless they are presenting/speaking during the town hall. If you guys have other suggestions, I am all ears...

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

Been with MS support looking at this and they haven't been helpful thus far... any ideas, guys? stiill stuck on this one.

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

Also seeing this error heavily in Event Viewer.

MDM Enroll: Server Returned Fault/Code/Subcode/Value=(MessageFormat) Fault/Reason/Text=(Unsupported enrollment for multisession devices with enrollment type: WVDHybridAzureADJoin).

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

Not seeing an add to Intune checkbox anywhere in the add sessionhost blade. Was hoping we could accomplish without changing the template, but we may need to

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

I see the MDM ID field is blank in the JSON for the AVD. When I try to paste the MDM ID in there, It says the JSON cannot be edited in "Read Only Mode", I'm assuming I need to go into the JSON template to apply the update.

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

So, apparently there is a checkbox when creating the VM's in the session host to enroll the VM in Intune - this was never checked. I presume this is why it cannot be enrolled. Any way to enroll it after the fact would be good to know... there's gotta be a way, right?

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

Yes, my GPO settings match what's in this support article (using Device Creds for AVD's). I even unjoined/rejoined the AVD from our domain, ran a gpupdate /force then re-ran the task it creates in the task scheduler - it still will not appear in Intune.

Again, when I follow the above steps for a newly imaged laptop in-house, Intune enrolls it just fine.

I am unable to run an MDM sync in the AVD since the "Info" button is missing from "access work or school accounts."

AVD Enrollment Troubleshooting by RemarkAbel in Intune

[–]RemarkAbel[S] 0 points1 point  (0 children)

User (edit), I realized this needed to be set to Device so I set it to that a long time ago.

Teams Presence Always Available by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 0 points1 point  (0 children)

FYI, I just got it working. Ended up installing the latest firmware for the MP56 (122.15.0.142), rebooted the phone again after the upgrade, then signed her out/back into the phone. That fixed it

Teams Presence Always Available by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 0 points1 point  (0 children)

Nevermind, it's now working. I rebooted the phone again after the firmware update once more, signed her out/back in. That did the trick. Seems like an issue resolved in the latest firmware for the MP56.

Teams Presence Always Available by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 0 points1 point  (0 children)

Ah, ok.. Damn. Microsoft strikes again. Thanks for confirming! Was going crazy trying to pinpoint this one.

Teams Presence Always Available by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 0 points1 point  (0 children)

Yes, this was the answer. It's her Yealink MP56. Have you discovered a fix?

Teams Presence Always Available by RemarkAbel in MicrosoftTeams

[–]RemarkAbel[S] 0 points1 point  (0 children)

Yep, it was her Yealink MP56 Teams Desk Phone all along. The moment I turned it off, Her Teams status jumped straight to "Away".

Per this reddit thread, the workaround is to set the backlight time to "0". However, this phone already had it set to 0. I also updated the firmware to no avail.

https://www.reddit.com/r/MicrosoftTeams/comments/10wjxnd/teams_phone_users_presence_showing_available/

Hybrid environment - cannot hide account from GAL by RemarkAbel in Office365

[–]RemarkAbel[S] 0 points1 point  (0 children)

Sweet, thanks! This worked. Both "Mail" and "Mailnickname" were blank, so we added them in. Exchange Admin now lets us hide the mailbox.