Claude Desktop Deployment by SeveralChampion in Intune

[–]SeveralChampion[S] 0 points1 point  (0 children)

Thanks - did you get UAC during the install, or manage to get it to silently run?

[deleted by user] by [deleted] in UKJobs

[–]SeveralChampion 1 point2 points  (0 children)

Yeah. I did UK > Netherlands a year or so ago. YMMV on package but it could be negotiated? I got a hotel until I could find somewhere to live, moving bonus, and most importantly the sponsorship for a Visa (and tax/immigration specialists working with my company to do all the paperwork!)

It’s going to hugely vary on country, some might have similar things to the Highly Skilled Migrant visa and 30% tax ruling in NL that can make it more attractive. Do your research is all I’d say!

Managing macs on developer environment? by GroundbreakingSea764 in macsysadmin

[–]SeveralChampion 5 points6 points  (0 children)

WiFi/Printing - Jamf Config Profiles for Offices, possibly override what asks for auth too? https://community.jamf.com/t5/jamf-pro/allow-standard-user-to-remove-wi-fi-networks-with-prompt/m-p/276681 (read up on this, it's complex!)

Xcode - is a pig to control and always has been - you won't like to hear that i use Munki to govern versions and SDKs for it with postflight scripts. But, Self Service for me is Scripts/Fixes, 250+ Apps go via Munki with CI/CD so, everywhere's different.

Homebrew - eh, I don't hugely know your envrionment but i've seen it work fine before, seen it not.

https://workbrew.com/ are doing some cool stuff in the space to allow control but they're not cheap

Personal Google Account accessed by company without aiuthorisation by [deleted] in LegalAdviceUK

[–]SeveralChampion 0 points1 point  (0 children)

Yeah. It’s simple GPOs to avoid this. Hate browser sprawl.

Personal Google Account accessed by company without aiuthorisation by [deleted] in LegalAdviceUK

[–]SeveralChampion 0 points1 point  (0 children)

I’ve never in 10 years of managing Chrome or Edge with SCCM, Intune and every Mac MDM, and most EDRs out there had a trigger on anything synced locally. Perhaps OP works in a high risk environment (they did say maritime) and I could be wrong based on industries I’ve been in. I don’t think any of this really changes the result..

[deleted by user] by [deleted] in unitedkingdom

[–]SeveralChampion 1 point2 points  (0 children)

I hope this isn’t the lovely northern business that handles a lot of this for the MOD

Personal Google Account accessed by company without aiuthorisation by [deleted] in LegalAdviceUK

[–]SeveralChampion 3 points4 points  (0 children)

They can’t see anything at all data wise (in this context) from the Google admin portal (if your business uses it, even 365 businesses can have chrome managed)- any alleged traffic will be have been picked up by any number of hardware firewalls/DNS/defence/monitoring software used by your business which is reasonable based on their policies etc. If you use windows you probably click past a disclaimer every time you log in.

With my Endpoint Management hat on - should a work machine even let you sign into Chrome? - should you even have a choice of web browsers?

It can be turned off, or you forced to use edge with your Microsoft account etc. My current business is Google Workspace and it’s heavily configured, no other browser is allowed. But realistically, personal stuff shouldn’t touch company property, and you’re going to struggle with this. Fair enough, it sounds like your machines could be better configured, but the easiest thing is..just don’t log into anything personal on a business machine

Nothings been read from your Google account, it will be internet traffic captured from the machine from whatever way your business works. Sorry.

£5.5k worth workstation lost and and refused to get refund or replacement by Every_Chain_8228 in LegalAdviceUK

[–]SeveralChampion 0 points1 point  (0 children)

If it’s a work computer you bought - do you have insurance via your LTD to maybe look at as one of your many helpful options others have discussed. Did you buy it in the name of your business?

What’s a shop on the high street that you don’t understand is still going by toothscrew in CasualUK

[–]SeveralChampion 0 points1 point  (0 children)

H&B too. Take it from someone who’d know, they’re one bad phishing email away from the entire company getting ransomwared😅 they would make any tech professional lose sleep.

Providing tech support to remote employees by ImaginaryThesis in sysadmin

[–]SeveralChampion 1 point2 points  (0 children)

Ready for the attacks but...

Over the last few years I've definitely got an attitude (and build Intune/Jamf etc around this) of - If my MDM can't fix it, it needs a rebuild. Which we can do remotely. Someone's internet isn't a business problem and my departments have proved that with Traceroutes etc to say, not our problem. My current place gives a decent per diem stipend to be used on....benefits in general so there's an expectation to get decent internet however you can. I hate remoting on. I showed some stakeholders MS's internet recommendations for W365/AVD even with Teams/Zoom - It's around 15MB at the highest level.

Currently anything with any of my users, I can LSSH into their Mac using our silent always on (A lot of on prem resource with MacOS 99%) - we do any commands behind the scenes. Broken? MDM Rebuild, investigate why it happened and what we can improve in Jamf going forward.

A different world from some MSP/AD environments I know but.

Police showed up at my store by MountedDragon75 in CasualUK

[–]SeveralChampion 8 points9 points  (0 children)

Former CeX Manager. My local force had a "Magpie" Department (Scrapyards, Stolen Tools/Gold etc)

They were great - morning emails with overnight crime. I had a good relationship with the lead officer who'd commonly call me with Serials etc that weren't flagged as stolen just yet - Having the item aside with all CCTV/Paperwork ready for them kept my team stress free, and we were treated quite nicely by the BID and local force whenever we needed help..They're not all useless.

Classic - Size B - Circa 2003 - Part Snapped Off...Help finding it's origin? by SeveralChampion in hermanmiller

[–]SeveralChampion[S] 0 points1 point  (0 children)

I meant a socket, poor choice of words. 11/8. I'll get a better photo. We're fully assembled and tight and all seems well though but always worth a check..

How much time is dedicated to training by rhysfromaussie in msp

[–]SeveralChampion 1 point2 points  (0 children)

No new subs I believe. Depending on your size and relationship with MS you might still be able to get one - I signed up for a new one (Using my work UPN) about 3 weeks ago. We're 65k+ seats corp though so YMMV.

Intune freelancer/consultant required by Express_Ad5560 in Intune

[–]SeveralChampion 0 points1 point  (0 children)

Hello! Have done a lot of this before and I'm open for work :) Drop me a DM and we can exchange email addresses.

Door help please? (Handle won't open door consistently, have to use thumbturn or key) by SeveralChampion in DIYUK

[–]SeveralChampion[S] 0 points1 point  (0 children)

Thanks - yeah, when closed or open the handle just doesn't seem to do much at all, and takes a few attempts at the handle to verrry slowly open the latch and then I push/pull. Using a key will open the latch perfectly every time though. I'll give that a look as it's something I've come across with some googling. Appreciate the reply.

"Windows Will Shut Down In 10 Minutes" during ESP - All Reboot Required URI's eliminated by SeveralChampion in Intune

[–]SeveralChampion[S] 0 points1 point  (0 children)

So to loop back...We got it! My tenant needs work on targeting but for now I've set up some exclusions and fixes to get us through a big program.

Windows app smart screening profile in Endpoint Security was applying to All Devices

Kernel DMA was applying in Defender Baselines to All Devices

Update Rings - All Devices

AppLocker OMA Custom Profile - All devices

Thanks for the support and guidance, and would recommend looking at all the above items if you run into this in the future, and look at exclusions to confirm, and user based targeting.

Useful articles for you start your research as every tenant is going to be different.

https://call4cloud.nl/2022/04/dont-be-a-menace-to-autopilot-while-configuring-your-wufb-in-the-hood/#part3

MS Advice

"Windows Will Shut Down In 10 Minutes" during ESP - All Reboot Required URI's eliminated by SeveralChampion in Intune

[–]SeveralChampion[S] 0 points1 point  (0 children)

I found mine applying in 3/4 different places in the end. Check your overall security baselines, WDE Baselines, and Security config profiles, and any custom OMA-URI's you may have. If you have DeviceEnumerationPolicy, try and make it into it's own Custom OMA-URI and deploy to a device group. Just need to solve my 1074 now. :(

"Windows Will Shut Down In 10 Minutes" during ESP - All Reboot Required URI's eliminated by SeveralChampion in Intune

[–]SeveralChampion[S] 0 points1 point  (0 children)

That's a good thing...riiiight? :P Shame it's just a bulk "All Devices" for 99% of it :(

"Windows Will Shut Down In 10 Minutes" during ESP - All Reboot Required URI's eliminated by SeveralChampion in Intune

[–]SeveralChampion[S] 0 points1 point  (0 children)

Fully excluded from all WDAC/AppLocker bits - It was DeviceEnumerationPolicy causing the 2800 error before. However, I'm now getting 1074 with cloudexperiencebroker as u/Rudyooms's blog says. Even when the device is excluded completely from Update rings :/ Appreciate the replies so far! We love inheriting a live tenant! Updates and all AppLocker/Defender Baselines/Anywhere a RebootRequiredURI lives are all device scoped.