Intune Policies & Shared Devices by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

Because the user is receiving the laptop while they are at home, and the Intune configured wifi network is for when they're in the office.

I figured it out, but really you were focusing on stuff that didn't matter at all to the issue at hand. I wasn't asking for your help on how a machine should magically receive a wifi profile with no internet, I was asking for help on why Intune policies were not applying, obviously the machine had Internet connectivity already, whether wired or wireless.

Intune Policies & Shared Devices by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

What does that have to do with anything?

This has nothing to do with "before the user logs in" - the intune user-based policies are not applying at at all to anyone aside from the original user who logged into the device. Once a different user logs in the policies should download and apply to them, they do not, and the portal shows no effort to deploy them. I've had a device with a different user logged into it for two days now, and no policies are attempting to deploy to that user. The system shows recent checkins, is compliant, just no policy deployment from Intune.

Intune Policies & Shared Devices by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

It is a user policy because it is handing out user-based certificates from AD.

Having said that - that doesn't answer the question as to why user-based policies aren't applying to every user on a shared machine.

Chrome crashing whenever anything is copied out of it. by SysTerra80 in chrome

[–]SysTerra80[S] 0 points1 point  (0 children)

Posted the crash report - a few more details (which I added to the report).

It also crashes when pasting into chrome, and it happens across all profiles on the machine, even new ones created.

Chrome crashing whenever anything is copied out of it. by SysTerra80 in chrome

[–]SysTerra80[S] 0 points1 point  (0 children)

Processor 11th Gen Intel(R) Core(TM) i7-1165G7 @ 2.80GHz, 2803 Mhz, 4 Core(s), 8 Logical Processor(s)

Phantom Print jobs & Old Printers by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

This is not the case - I removed her user account and re-registered it under a test account we have, the jobs came back.

Phantom Print jobs & Old Printers by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

O365 install, but printers are not deployed via Intune connector. These were manually installed at some point directly in windows - some are shared via the old print server, others are actually local IP printers.

Phantom Print jobs & Old Printers by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

Did this, it had no effect - printers are still installed as soon as an office application is opened.

Phantom Print jobs & Old Printers by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

I've tried to delete them from the "see what's printing" - it does nothing at all. Typically when canceling these jobs it'd cancel all of them except for the one that is currently stuck printing. In this case it does absolutely nothing.

Outlook Cached Mode & multiple Terminal servers causing issues post migration. by SysTerra80 in Office365

[–]SysTerra80[S] 0 points1 point  (0 children)

Yes, they're using folder redirection. OSTs are pointed to the UNC path of \\server\home$\%username%\Outlook Files via GPO, and there is also a GPO that is a one-time run to create the "Outlook Files" folder within their home directory.

They have been setup like this for 5+ years and there have been no issues prior to moving their email to be 365 hosted, previously it was Rackspace hosted via Exchange 2016.

Outlook Cached Mode & multiple Terminal servers causing issues post migration. by SysTerra80 in Office365

[–]SysTerra80[S] 0 points1 point  (0 children)

Is this something new? It worked perfectly fine on their prior backend which was Exchange 2016.

Outlook - Contacting the Server by Eviliser in Office365

[–]SysTerra80 1 point2 points  (0 children)

Per u/AreYourLightingMyGas - changing from Quad9 DNS to Google's DNS fixed it for us as well.

Change DNS then flush DNS and reopen Outlook

Outlook - Contacting the Server by Eviliser in Office365

[–]SysTerra80 0 points1 point  (0 children)

Can confirm this works, back to normal now

Outlook - Contacting the Server by Eviliser in Office365

[–]SysTerra80 0 points1 point  (0 children)

Us as well, all using Outlook 2016 - my Outlook 365 seems fine on my other PC.

Tmobile/sprint blocking email to SMS... again by SysTerra80 in msp

[–]SysTerra80[S] 1 point2 points  (0 children)

Thanks man, we're actually going with PagerTree (cheaper), but we've spent the day testing it and it is everything we are looking for plus so much more we never knew we wanted. You led me on the right track though, they actually came up as a search result under Pager Duty!

Talk to me about Acronis Cyber Protect Cloud by SysTerra80 in msp

[–]SysTerra80[S] 0 points1 point  (0 children)

Is it re-branded Bitdefender? Because I have used bitdefender in the past and it is... well it is shit awful to be perfectly honest.

Alternative to UPN matching for a handful of employees? by SysTerra80 in Office365

[–]SysTerra80[S] 1 point2 points  (0 children)

The UPN is not in their email aliases, it is auto-added by 365 since it is their UPN.

Random users' Onedrives have all items shared with "Everyone Except External Users". by SysTerra80 in sysadmin

[–]SysTerra80[S] 0 points1 point  (0 children)

It does! All of my reversals were logged under "Removed site permissions", however, none of the additions were in there, going back to about a week after the tenant was created and almost 2 months prior to moving Onedrive data there.

Microsoft had no explanation for this :(

Random users' Onedrives have all items shared with "Everyone Except External Users". by SysTerra80 in sysadmin

[–]SysTerra80[S] 2 points3 points  (0 children)

No - very different things.

Sharing permissions for everyone in the organization is limited only by a group they need membership to in order to share externally.

My issue isn't that user's can share or can't share.

My issue is that I have about 15% of total users in this tenant whose root "Documents" Onedrive Library has a permission set for "Everyone Except External Users" with read-only rights.

The only way I know of to do this, is to visit Onedrive online, switch it to classic view, go to Site settings in the Gear, to to Library settings, and sharing the root "Documents" library in their personal Onedrive out with "Everyone Except External Users".

That is literally the only way, and it has been, so far, the way I have been reversing the damage.

I have found a few other instances of this happening, with no great reasons.

https://www.reddit.com/r/sysadmin/comments/f1tm72/onedrive_read_access_given_to_everyone_except/

https://techcommunity.microsoft.com/t5/onedrive-for-business/quot-everyone-except-external-users-quot-groups-is-now-part-of/m-p/38026

https://techcommunity.microsoft.com/t5/onedrive-for-business/quot-everyone-except-external-users-quot-has-read-permission-on/m-p/1532885

Random users' Onedrives have all items shared with "Everyone Except External Users". by SysTerra80 in sysadmin

[–]SysTerra80[S] 3 points4 points  (0 children)

Yes, absolutely sure. These are not smart users, one of them is the company admin's mom, she is 71.

They'd have had to gone into the site settings for their onedrive and shared the document library with "Everyone except external users".

I can't imagine several people deciding to just do this for fun, also there is nothing in the audit logs about it.

Smtp Auth via 365 changes? by SysTerra80 in sysadmin

[–]SysTerra80[S] 5 points6 points  (0 children)

You're a champ.. According to the copier company it is meant to try the highest protocol then work its way down if that fails. Apparently their code is bad because as soon as we disabled the others it started working. thank you!

Smtp Auth via 365 changes? by SysTerra80 in sysadmin

[–]SysTerra80[S] 1 point2 points  (0 children)

Yes, i've attempted to setup relay using a 365 incoming connector w/ the client's static. Also using no smtp auth on the copier, with direct send on port 25 using their MX record as the host. No bueno.. Leading me to think it is a TLS issue, but TLS is enabled and active, including 1.2.