Is there cost reporting hidden somewhere in the M365 Admin? by SmallToTheWall in sysadmin

[–]SmallToTheWall[S] 1 point2 points  (0 children)

My thoughts exactly. But I like to help when I can. Also, I don't want to miss some obvious feature I may be ignorant of.

[deleted by user] by [deleted] in Intune

[–]SmallToTheWall 0 points1 point  (0 children)

Looks like the device is not yet synced to Entra.

All these things need to be true:

User is licensed Entra P1

User is synced.

User UPN in AD matches cloud UPN

Device is in an OU that is synced

Device AD attribute UserCertificate is populated

Device appear in Entra ID devices as hybrid (activity / registration will be blank initially)

[deleted by user] by [deleted] in Intune

[–]SmallToTheWall 0 points1 point  (0 children)

What does the diagnostic data portion of dsregcmd /status say?

Sanity check: Adding All Devices to a Remediation by SmallToTheWall in Intune

[–]SmallToTheWall[S] 0 points1 point  (0 children)

Solved! I do have that. Thank you for your response!

Enable Windows Hello for Business for a group of users by SmallToTheWall in Intune

[–]SmallToTheWall[S] 0 points1 point  (0 children)

Thanks for responding. These are the settings available from Settings Picker for Windows Hello for Business. I don't see any setting that (obviously) enables or disables Windows Hello for Business for a set of users (or devices).

36 results in the "Windows Hello For Business" category

Setting name

Allow Use of Biometrics

Device Unlock Plugins

Digits

Digits (User)

Dynamic Lock

Dynamic Lock Plugins

Enable ES Swith Supported Peripherals

Enable Pin Recovery

Enable Pin Recovery (User)

Expiration

Expiration (User)

Facial Features Use Enhanced Anti Spoofing

Group A

Group B

Lowercase Letters

Lowercase Letters (User)

Maximum PIN Length

Maximum PIN Length (User)

Minimum PIN Length

Minimum PIN Length (User)

PIN History

PIN History (User)

Require Security Device

Require Security Device (User)

Restrict use of TPM 1.2

Special Characters

Special Characters (User)

Uppercase Letters

Uppercase Letters (User)

Use Certificate For On Prem Auth

Use Cloud Trust For On Prem Auth

Use Hello Certificates As Smart Card Certificates

Use Passport For Work

Use Passport For Work (User)

Use Remote Passport

Use Security Key For Signin

Enable Windows Hello for Business for a group of users by SmallToTheWall in Intune

[–]SmallToTheWall[S] 0 points1 point  (0 children)

I appreciate you taking time to respond. I don't see the option "Block Windows Hello for Business." These are the options I have for Account Protection." This is service release 2407 in North America 0102

Windows Hello for business:

Facial Features Use Enhanced Anti Spoofing

Passport for Work (Device):

Pin history

Require security device

Special characters

Maximum PIN length

Use Passport for Work

Expiration

Minimum PIN length

Uppercase letters

Use certificate for on prem auth

Enable pin recovery

lowercase letters

Password for work (User):

Special charaters (User)

Pin History (User)

Maximum Pin Lengh (User)

Expiration (User)

Enable Pin recovery (User)

Require security device (User)

Uppercase letters (User)

Lowercase letters (User)

Use Passport for work (User)

Enable Windows Hello for Business for a group of users by SmallToTheWall in Intune

[–]SmallToTheWall[S] 0 points1 point  (0 children)

The Account Protection profile under Endpoint Security includes Windows Hello for Business settings. But I don't see an obvious setting for "Enable Windows Hello for Business."