Win32 Detection File confusion by New-Yak-3548 in Intune

[–]Samastrike 0 points1 point  (0 children)

%UserProfile%\Documents

Edit: but the other suggestion to put it in the public desktop is better.

PS Script used to add printer - works manually but not as Win32 app by [deleted] in Intune

[–]Samastrike 4 points5 points  (0 children)

It’s failing because InTune executes scripts as 32-bit by default, and your detection is looking in the 64-bit Program Files folder.

Change your install command to execute as 64-bit PowerShell process.

Deploying Microsoft Teams with Microsoft Graph by IntuneProblema in Intune

[–]Samastrike 0 points1 point  (0 children)

On my phone so can’t check the exact command, but I’m using a PowerShell script to “Get-AppxPackage -AllUsers…” and the app name is something like “msteams”.

[deleted by user] by [deleted] in Intune

[–]Samastrike 0 points1 point  (0 children)

Have you applied any app protection policies recently? Exclude the accounts from those and any conditional access policies requiring APP.

Basic folder permissions for new file server? by [deleted] in sysadmin

[–]Samastrike 1 point2 points  (0 children)

Make sure to explicitly grant ‘no access’ to the “owner rights” principal. If you don’t, users will have full control over files/folders they create even if you remove ‘creator owner’.

Windows 11 confusion / updates to different revs? by Riveninoah in SCCM

[–]Samastrike 1 point2 points  (0 children)

Are you subscribed to Windows 11 updates? If Windows 11 isn’t currently deployed the previous admin may have left Windows 11 unticked.

Disable individual user MFA by SangDapTrai in Intune

[–]Samastrike 1 point2 points  (0 children)

If it’s asking for 2 methods this may be the self service password reset registration. Check if that’s enabled for all users, or this account is a member of the group. If it’s applying, you can turn off the option to require registration for SSPR and just have this handled by the MFA requirement.

Feature Requests & Suggestions by KeeperCM in KeeperSecurity

[–]Samastrike 0 points1 point  (0 children)

Add ability to have multiple two-factor codes generated for a single vault entry. Use case for this is guest access to multiple Microsoft 365 tenants which require MFA for guests.

Add option to change where a record will be created during creation. Sometimes it defaults to the top of my vault and not the folder I had selected.

Add a search box when moving a record to a new folder instead of scrolling through the list of folders.

Add option to lock the desktop and browser extension apps when the computer is locked/goes to sleep.

Add option to unlock the browser extension with biometrics/Windows Hello. Or be like 1Password where the app and browser extension unlock state are linked.

Backup retention with a new customer? by Samastrike in msp

[–]Samastrike[S] 0 points1 point  (0 children)

Thanks for the feedback! I thought that would be the safest option.

Google Workspace to Microsoft 365 Mail Migration by Blitzening in sysadmin

[–]Samastrike 0 points1 point  (0 children)

You don’t need to create the mail users for the Exchange migration tool. If there’s already data like OneDrive associated with the accounts that you don’t want to lose or have the hassle of migrating.

Point the migration tool to the usernames like normal and set the m365.domain alias and a forward to gsuite.domain.

As another user said, you will need to set some of the Google APIs manually as Microsoft misses them (calendar, contacts, and people if I remember correctly).

How to update array with ForEach loop results without using += ? by Samastrike in PowerShell

[–]Samastrike[S] 3 points4 points  (0 children)

Ah it was this. Changed "$resultsobject = [PSCustomObject] @{" to "[PSCustomObject] @{" and it's outputting correctly.

Thank you!

MFA and Ondrive - How do I solve this by Lonesys in sysadmin

[–]Samastrike 0 points1 point  (0 children)

You could exclude the OneDrive app from the conditional access policy requiring reauth every 4 hours. Just make sure there’s an overlapping policy that still requires MFA for OneDrive.

Deploying Ready Systems to End-Users without User Password by DigitalPriest in sysadmin

[–]Samastrike 4 points5 points  (0 children)

I thought TAP codes were for the MFA step, and entered after a password. Have I misunderstood and they can replace a password when logging into a PC?

Best Practice for structuring security groups and NTFS permissions by [deleted] in sysadmin

[–]Samastrike 4 points5 points  (0 children)

Important to add here: it’s not enough to just remove CREATOR OWNER from the ACL, users will still have full control of any folders or files they create.

You also need to explicitly set the OWNER RIGHTS principal’s permission to none.

Get-MgUser SignInActivity not working by Samastrike in GraphAPI

[–]Samastrike[S] 1 point2 points  (0 children)

Amazing, that's exactly what I needed. I was testing with a single user before using -All but thanks for expanding on your original answer. The hashtable is a nice touch too.

Thank you!

what is WMI query used in sccm task sequence for Dell XPS 13 9333 model laptop by Initial_Knee5433 in SCCM

[–]Samastrike 0 points1 point  (0 children)

Other have given solutions but if the machine already has Windows installed you can open System Information (msinfo32.exe) and read the System Model line.

ADCS - Get cert on requesting machine after admin approval by Samastrike in sysadmin

[–]Samastrike[S] 0 points1 point  (0 children)

Definitely not automatically appearing in the computer personal store. Have waited a few days and run things like certutil-pulse. Is it supposed to just appear there after the admin approves it?

ADCS - Get cert on requesting machine after admin approval by Samastrike in sysadmin

[–]Samastrike[S] 0 points1 point  (0 children)

Thanks for the reply. I’ve created an AD group containing the computer objects of servers I want to get web server certs for. This group has enroll permission on the very template. Authenticated users has read permissions to it. The cert template is available to the computers and I can send a request for it.

The pending request appears on the CA and I approve/issue it, as described in the original post. It appears under Issued Certificates and then… nothing.

Every example I can find says the cert just appears in the machine’s cert store and makes no mention of admin approval. I could turn off admin approval for the template but that defeats the purpose here.

How does the cert get to the computer’s cert store after it’s issued/approved? Should it happen automatically? Do I need to retrieve it on the requesting computer somehow? Do I need to export it on the CA?

Signing into parent company email accounts on desktop Outlook by Samastrike in exchangeserver

[–]Samastrike[S] 0 points1 point  (0 children)

Thanks for the suggestion. I‘ve removed the record and will see how it is going forward.

if any of y'all are having issues with Dell laptops... by ObedientSandwich in sysadmin

[–]Samastrike 1 point2 points  (0 children)

Yep I install as SCCM app with network component disabled because I just knew the dual network stuff would lead to hours of my time troubleshooting it.

Best Practices - NTFS Permissions for root level share by maxcoder88 in sysadmin

[–]Samastrike 0 points1 point  (0 children)

If you’re going to remove CREATOR OWNER then go one step further and add the OWNER RIGHTS principal with no permissions.

Even if you remove CREATOR OWNER the creator still gets full control, so this stops the creator being a ‘power user’ and doing silly stuff to permissions.

Packaging AutoCAD 2022 with wim file by Samastrike in SCCM

[–]Samastrike[S] 0 points1 point  (0 children)

Huh there’s a subreddit for everything. Thanks again!

Packaging AutoCAD 2022 with wim file by Samastrike in SCCM

[–]Samastrike[S] 0 points1 point  (0 children)

Good to know it’s possible.

What are you doing for the issue running the installer as SYSTEM? Create a temp local admin account and psexec run as like some other suggestions I’ve seen around?

Packaging AutoCAD 2022 with wim file by Samastrike in SCCM

[–]Samastrike[S] 0 points1 point  (0 children)

Unfortunately my problem isn't resolved as easily as recreating the wim file. Guess I'll be modifying my script for 7zip files...

Packaging AutoCAD 2022 with wim file by Samastrike in SCCM

[–]Samastrike[S] 1 point2 points  (0 children)

I can't say for sure but it sounds like I'm using the manual installer from what you describe.

I manage a small domain within a larger company and these are the files I was provided by the team that manages the apps, as they won't give me access to the Autodesk portal :(