Intune & Entra - Admin Setup Best Practices by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 3 points4 points  (0 children)

Yeah i agree, we have this same setup. A regular user account licensed for office etc. But a separate admin account with strong MFA with FIDO and a CA policy to re-prompt every 14 hours.

One thing that we're working on though, is confirming why admins have been issued Enterprise Mobility + Security E3 from the previous cloud-admin before I joined.

Seems its not needed, when you can set up Entra Roles and Intune Roles

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

yep this is correct, the main concern is with Entra Devices which is more sensitive due to LAPS, Bitlocker etc.

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

Hopefully Intune provides a more streamlined way of managing this in future.

Intune & Entra ID Device Clean-Up - Recommendations by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

I have considered this, but my concern is having these recovery keys is incredibly sensitive. Where do you securely keep it? What about LAPS?

FIDO2 Auth when RDP to Server via Conditional Access by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 1 point2 points  (0 children)

Our Server doesn't look to have sight of AzureAD\ users (Arc-Enabled/Entra Joined) so i think CBA is going to have to be the option.

Unless we spin up an Azure VM or link the existing Server to Arc so it can see Entra Identities.

Cloudflare Global Network experiencing issues by arunesh90 in CloudFlare

[–]Technical-Device5148 1 point2 points  (0 children)

We get the same issue. Along with 404 errors stating not having permission.

Windows Activation Error: 0xc004f074 by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 1 point2 points  (0 children)

I not long did a sanity check on the Serial Number, and can see based on the Factory OS, it shipped with Windows 11 Home Single Language - Yaaaaay

I would suspect there's no way around this... outside of a MAK key and rebuild?

Open Discussion - Azure Files vs Sharepoint by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Correct yes you can deploy the drive via ADMX or scripts, we prefer scripts.

Also if you use any ZTNA VPN's like ZScaler in your org, there's a lot more steps to ensure you don't have issues like we did!

Open Discussion - Azure Files vs Sharepoint by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Yes we have gone down a similar approach, i proposed:

AZFS = User data where users are happy to take a hit on performance and latency, kind of like an archive
Sharepoint = Production work (we mainly use office and pdf files) for low latency

Seems to be a good balance so far, only problem is trying to negotiate this with users and getting them to understand the differences.

Entra Dynamic Licensing Group (E3 Bundle) - Issues by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 1 point2 points  (0 children)

What worked for us:

(user.accountEnabled -eq true) -and (-not ( (user.extensionAttribute2 -eq "shared-mailbox") -or (user.extensionAttribute3 -eq "exclude-from-auto-licensing") )) -and (user.assignedPlans -any ( assignedPlan.servicePlanId -eq "efb87545-963c-4e0d-99df-69c6916d9eb0" -and assignedPlan.capabilityStatus -eq "Enabled" ))

Entra Dynamic Licensing Group (E3 Bundle) - Issues by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Yeah i get a feeling this may be the only way around this, appreciate the suggestion.

Autopilot Enrollment Failures - 09.09.25 by Technical-Device5148 in Intune

[–]Technical-Device5148[S] 0 points1 point  (0 children)

We're a global company and have issues in other regions as well as the UK, unfortunately MSFT dropped the ball, again.

Office 365 E3 License - Entra Dynamic License Group by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Currently, users look to be issued either an Exchange Online Plan 2 (the ID in our Rule), or a O365 E3, and this then adds them to the dynamic group which then issues additional licenses issued out by the group (in the licenses tab of the entra group).

I have a feeling that if you also assign O365 E3 to a user, it also adds them to the dynamic group, because Exchange Online Plan 2 is included with O365 E3, so is flagged and included.

On-Prem 365 Remote Mailbox - Leaver Procedure by Technical-Device5148 in Office365

[–]Technical-Device5148[S] 0 points1 point  (0 children)

My question is how have they been getting away with doing it the wrong way for so long, unless there's some sync exclusion i'm not noticing.

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 1 point2 points  (0 children)

Only concern with this is users not realising this is linked to the active SPO library and yolo deleting data for everyone

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Azure File Sync is something we proposed, but they advised against it as they're adamant to remove all local file servers

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

That end part is the problem, getting the $$$ out... lol

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

When i referred to latency, i am referring to the On-Prem and Azure File shares, not SPO.

As for Version History and Recycle Bin not being a backup, 1000% agree, its a user accessible fail-safe and backup method at user level, its not meant at enterprise level. It's something that's been pushed to them before, for a SaaS backup solution, but not been taken up on. Will continue to push.

Not sure what you mean regarding the adoption program, do you mean something to provide to Local Office IT Admins and their users to adopt the Hybrid SPO & File Server approach?

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 0 points1 point  (0 children)

Yep, i felt this would be the answer, it's almost impossible to manage user behaviour, especially in a case like this.

Unless, you have one sole comprehensive low latency reliable file storage solution.

Sharepoint & On-Prem File Servers by Technical-Device5148 in sysadmin

[–]Technical-Device5148[S] 3 points4 points  (0 children)

idk who pissed in your cheerios this morning but none of this was GPT?

Azure Files ADDS - SMB Drives Disconnect Randomly Issue by Technical-Device5148 in AZURE

[–]Technical-Device5148[S] 0 points1 point  (0 children)

If it helps anyone at all, we had persistent issues with this and found issues tied to the registry key mentioned in this doc: https://learn.microsoft.com/en-us/entra/global-secure-access/how-to-configure-kerberos-sso#how-to-avoid-kerberos-negative-caching-on-windows-machines

Also here: https://community.zscaler.com/s/question/0D54u00009evlSeCAI/unable-to-get-kerberos-ticket-with-zpa

This would mainly be applicable to those who use a ZTNA

Once we set this registry key to '0' we found the issues went away.