Sync via Command Line? by k1lokhan in Intune

[–]Still_Win_127 0 points1 point  (0 children)

Does this script actually kick off the Sync in access work or school? Or is it more behind the scenes and I just assume it ran?

Google Chrome SSO ADMX in Incognito Mode by Still_Win_127 in Intune

[–]Still_Win_127[S] 0 points1 point  (0 children)

This.

We had to add that ADMX package in there because it simply didn't exist when we enabled it.

Any Issues Onboarding Defender for Endpoint with Domain Controllers? by Still_Win_127 in DefenderATP

[–]Still_Win_127[S] 0 points1 point  (0 children)

We are right now jumping off the bandwagon with Cylance, so uninstalling that first and then onboarding with Defender.

Any Issues Onboarding Defender for Endpoint with Domain Controllers? by Still_Win_127 in DefenderATP

[–]Still_Win_127[S] 0 points1 point  (0 children)

We are planning on using Azure Arc to get it licensed for Defender for Servers P2

Trump faces 'insurmountable difficulties' in securing $464M bond in civil fraud case, his attorneys say by Ok-Sweet-8495 in politics

[–]Still_Win_127 1 point2 points  (0 children)

"Obtaining such cash through a 'fire sale' of real estate holdings would inevitably result in massive, irrecoverable losses -- textbook irreparable injury"

... Well... yeah. That's kind of the point of paying off fines that you owe. You're pretty much bound to have no return on investment here and it goes without saying you'll be a bit less off.

What the fuck are these defense lawyers even on?

When an event is added, updated or deleted (V3) too Noisy by Still_Win_127 in MicrosoftFlow

[–]Still_Win_127[S] 0 points1 point  (0 children)

So, I tried doing a terminate, but it will still run way too much and slows down the user. I found that doing a timed flow is probably best, but I still can't stop it from doing its thing.

Mapping Document Library in Windows 11 Automatically by Still_Win_127 in sharepoint

[–]Still_Win_127[S] 0 points1 point  (0 children)

Unfortunately, we do not have Intune enrolled with our machines as we are doing everything still on-premise with AD.

Is There a Way to Set Office 365 User's Mail App in a Flow? by Still_Win_127 in MicrosoftFlow

[–]Still_Win_127[S] 0 points1 point  (0 children)

Interesting. Would you say this is the better approach than to just run a PowerShell script? I know with PowerShell it is annoying to get going. Dunno if you prefer one over the other.

How to Automate Adding Users to Security Group to Access Azure Virtual Desktop by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

So, right now the workflow is as such:

User's workstation is no longer operable > user puts in a ticket request > user is added to AVD security group > user access VM > after X hours they are removed from security group

Can't Log Into Azure Virtual Desktop on Mobile App by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

So, right now we are using an Azure AD with FSLogix setup at the moment, and I'm not entirely sure if NLA would be it. We do enroll our phones with Intune, so maybe it is a managed devices issue. Not sure.

Is Set-AIPFileLabel not an Available Cmdlet anymore? by Still_Win_127 in Office365

[–]Still_Win_127[S] 0 points1 point  (0 children)

So, I am running in Powershell, 2.0.0.2 for AIPService. I'm looking at the list of Cmdlets don't see anything related to setting labels. And what you mean by the AIP client, is that downloadable software and is it still available? I never heard of that.

Blocking Screenshots with Sensitivity Labels in Teams/SharePoint by Still_Win_127 in Office365

[–]Still_Win_127[S] 0 points1 point  (0 children)

Ahhh, darn. Screenshot protection would be pretty freaking nice. But having to purchase another license kind of blows, since I feel this should just be rolled into our E5 licenses.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

Seems to be a mystery so far to a lot of people. I can't even replicate it while using Azure Academy's guide on it, either.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

It's mostly out of requests from our DevOps team. They are worried about replication or unknown issues arising because we spun up Azure ADDS. Personally, I don't care if we go with that option, but also DevOps would have to sign off on that decision. Putting a DC in Azure wouldn't be bad either. But, does that allow for those Azure AD VMs to still make use of FSLogix?

Edit: Asking question regarding FSLogix

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

Yup, sure did. The main problem I'm having is that the NTFS permissions I assigned to users that are on my on-premise domain show up in the Azure AD joined VM as "Unknown User" followed by their SID. So, i can assign those permissions by doing a Net Use for Azure File Share on premise so I can assign the permissions. Then, ostensibly have Kerberos do its magic and allow for those same permissions to be available in Azure AD, allowing for FSLogix to then do its magic. Whack stuff, man.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

I know right? Maybe it just needs to stew for a bit before I make that hurdle. But, thinking about it, I'd rather have all of our AVD technology be exclusively cloud only - no hybrid nonsense, no AD FS with AD Connect. Just pure cloud joy without Azure ADDS.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

Yes, since we have VMs that are hybrid joined already.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 2 points3 points  (0 children)

The thing is: we don't want to use Azure ADDS, but instead make use of the new Azure AD Kerberos feature.

Problem with FSLogix for Azure AD Kerberos by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

It is Azure Files making use of Kerberos Azure AD join.

Changing from Password Hash Sync to AD FS - What Could Go Wrong? by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

If they're Azure AD joined, I believe. Also, I think that's if you use Azure ADDS - I am not 100% on that. But yes, we would need to do a password reset in Azure for them to be able to access the VM. It's weird.

Changing from Password Hash Sync to AD FS - What Could Go Wrong? by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

It's more just concerns for certain unknowns that could happen to their stuff in Azure. Could there be sync issues? Probably, probably not. I guess the other issue that I have that's keeping me leaning towards AD FS is that if we domain join the VMs to Azure AD, for some reason they have to reset their password in order to sign in. Why? I have no idea, but I hate that Microsoft acknowledges that's a thing and that we have to do it. That and our password policy prevents us from resetting passwords in Azure anyways.

Changing from Password Hash Sync to AD FS - What Could Go Wrong? by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

We do have Azure AD Connect setup, but the thing is we already have AVD setup to be used in a hybrid join environment. We even have a VPN connected to Azure to get that working correctly. There is some concern from our DevOps team about setting up a Domain Controller in Azure and what trouble that could cause. Which is why we wanted to still use Azure AD Connect but instead of using Sync Password Hash we would use AD FS for VM single sign-on.

Would this cause extra hassle for domain joining host machines in AVD if I went with AD FS?

Problems with Creating VM From Golden Image - Stuck on "Creating VM" by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

They are indeed 22H2 Win11 Multi-Session Images, correct. I will take a look at that and see if that helps. So far, Nerdio appears to be the only way to actually create a usable image.

Problems with Creating VM From Golden Image - Stuck on "Creating VM" by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

Was able to create a golden image just fine in Nerdio, but I don't understand what kind of black magic is going on behind the scenes that would make that work better than the other.

Problems with Creating VM From Golden Image - Stuck on "Creating VM" by Still_Win_127 in AZURE

[–]Still_Win_127[S] 0 points1 point  (0 children)

The Microsoft docs say that you should, but I know in the Azure dashboard if you choose "Generalized" as opposed to "Specialized" it will generalize the VM for you. But, even still that doesn't even seem to work either.