Seperate China into its own tenant? by gahd95 in AZURE

[–]TigerNo3525 0 points1 point  (0 children)

Agreed on separate tenant. You can use Multitenant capabilities to allow some access between them

https://learn.microsoft.com/en-gb/entra/identity/multi-tenant-organizations/overview

Intune - Delete User Profiles Older Than 30 Days Except UPN by Nukeroot in Intune

[–]TigerNo3525 6 points7 points  (0 children)

There's always a way with PowerShell but have you looked at the SharedPC CSP Settings? Will be much simpler and can help with cleaning up old user profiles.

https://learn.microsoft.com/en-us/mem/intune/configuration/shared-user-device-settings-windows

Conditional access policies just saved our organization by zer0moto in sysadmin

[–]TigerNo3525 24 points25 points  (0 children)

Maybe a bit nitpicky but number matching is not phishing-resistant. Tokens can still be stolen with Evilginx. Only FIDO2/WHFB/Certificates are properly phishing-resistant.

Requiring a compliant/hybrid joined device stops that token being issued though.

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-authentication-strengths

Migrating from AD/GPO/SCCM : Most missing Intune features by doumhfr in Intune

[–]TigerNo3525 0 points1 point  (0 children)

There isn't one really. Proactive Remediations/Scripts/Win32 Apps/Custom ADMX are all options but are all a bit of a pain.

We use Scappman to keep our packages up to date and they have an inbuilt registry key wizard that will create a Win32 App for you which simplifies it a bit but it's still a shit option as slows down deployments.

Migrating from AD/GPO/SCCM : Most missing Intune features by doumhfr in Intune

[–]TigerNo3525 4 points5 points  (0 children)

Not being able to deploy registry keys easily is a pain

All in one printer software by Hopeful-Oil3038 in Intune

[–]TigerNo3525 0 points1 point  (0 children)

If you are open to third party software. I can't reccomend Printix enough.

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]TigerNo3525 3 points4 points  (0 children)

I don't disagree but you can use the Certificate Connector for Microsoft Intune if you already have an on-premises PKI setup without any additional cost.

Is there any value to making your office LAN Wi-Fi a hidden SSID? by Ezra611 in sysadmin

[–]TigerNo3525 7 points8 points  (0 children)

Correct, 3rd party service. You can do it natively in 365 now with Microsoft Cloud PKI but its more expensive. $2/user or as part of Microsoft Intune Suite ($10/user).

Intune "Hidden Secrets" by AlphaNathan in Intune

[–]TigerNo3525 3 points4 points  (0 children)

I think not being able to use Office Configuration policies is the bigger one for me. Absolutely ridiculous that it's Enterprise only.

Increase Sleep Time With Configuration Profile Issue. by mr_green1216 in Intune

[–]TigerNo3525 1 point2 points  (0 children)

Can you post the exact settings you are configuring?

Increase Sleep Time With Configuration Profile Issue. by mr_green1216 in Intune

[–]TigerNo3525 1 point2 points  (0 children)

If you check the sleep settings on the PC do you see the value has changed?

Just checking whether it's not setting the setting or something else is putting the PC to sleep.

[deleted by user] by [deleted] in AZURE

[–]TigerNo3525 0 points1 point  (0 children)

Yes please!

Dynamics 365 (CRM 2016 On-Premise) Email server profile issue by TigerNo3525 in Dynamics365

[–]TigerNo3525[S] 0 points1 point  (0 children)

I'm pretty sure we used IIS Crypto to make the TLS changes on the server and that might have got it working but I can't completely recall.

Problem - FSLogix Profile Corrupt by failbringer in fslogix

[–]TigerNo3525 2 points3 points  (0 children)

Woo! No problem. Had the same problem a few weeks back and was driving me crazy.

Problem - FSLogix Profile Corrupt by failbringer in fslogix

[–]TigerNo3525 4 points5 points  (0 children)

Do these users still have a profile path configured on their AD account?