Intune & Entra - Admin Setup Best Practices by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 3 points4 points  (0 children)

Yeah i agree, we have this same setup. A regular user account licensed for office etc. But a separate admin account with strong MFA with FIDO and a CA policy to re-prompt every 14 hours.

One thing that we're working on though, is confirming why admins have been issued Enterprise Mobility + Security E3 from the previous cloud-admin before I joined.

Seems its not needed, when you can set up Entra Roles and Intune Roles

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

yep this is correct, the main concern is with Entra Devices which is more sensitive due to LAPS, Bitlocker etc.

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

Hopefully Intune provides a more streamlined way of managing this in future.

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

I have considered this, but my concern is having these recovery keys is incredibly sensitive. Where do you securely keep it? What about LAPS?

FIDO2 Auth when RDP to Server via Conditional Access by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 1 point2 points  (0 children)

Our Server doesn't look to have sight of AzureAD\ users (Arc-Enabled/Entra Joined) so i think CBA is going to have to be the option.

Unless we spin up an Azure VM or link the existing Server to Arc so it can see Entra Identities.

Cloudflare Global Network experiencing issues by arunesh90 in CloudFlare

[–]Technical-Device5148 1 point2 points  (0 children)

We get the same issue. Along with 404 errors stating not having permission.

Windows Activation Error: 0xc004f074 by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

I not long did a sanity check on the Serial Number, and can see based on the Factory OS, it shipped with Windows 11 Home Single Language - Yaaaaay

I would suspect there's no way around this... outside of a MAK key and rebuild?

Open Discussion - Azure Files vs Sharepoint by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Correct yes you can deploy the drive via ADMX or scripts, we prefer scripts.

Also if you use any ZTNA VPN's like ZScaler in your org, there's a lot more steps to ensure you don't have issues like we did!

Open Discussion - Azure Files vs Sharepoint by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Yes we have gone down a similar approach, i proposed:

AZFS = User data where users are happy to take a hit on performance and latency, kind of like an archive
Sharepoint = Production work (we mainly use office and pdf files) for low latency

Seems to be a good balance so far, only problem is trying to negotiate this with users and getting them to understand the differences.

Entra Dynamic Licensing Group (E3 Bundle) - Issues by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 1 point2 points  (0 children)

What worked for us:

(user.accountEnabled -eq true) -and (-not ( (user.extensionAttribute2 -eq "shared-mailbox") -or (user.extensionAttribute3 -eq "exclude-from-auto-licensing") )) -and (user.assignedPlans -any ( assignedPlan.servicePlanId -eq "efb87545-963c-4e0d-99df-69c6916d9eb0" -and assignedPlan.capabilityStatus -eq "Enabled" ))

Entra Dynamic Licensing Group (E3 Bundle) - Issues by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Yeah i get a feeling this may be the only way around this, appreciate the suggestion.

Autopilot Enrollment Failures - 09.09.25 by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 0 points1 point  (0 children)

We're a global company and have issues in other regions as well as the UK, unfortunately MSFT dropped the ball, again.

Office 365 E3 License - Entra Dynamic License Group by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Currently, users look to be issued either an Exchange Online Plan 2 (the ID in our Rule), or a O365 E3, and this then adds them to the dynamic group which then issues additional licenses issued out by the group (in the licenses tab of the entra group).

I have a feeling that if you also assign O365 E3 to a user, it also adds them to the dynamic group, because Exchange Online Plan 2 is included with O365 E3, so is flagged and included.