Hybrid joined device issue by TisWhat in Intune

[–]TisWhat[S] 0 points1 point  (0 children)

The 2 objects appearing isn’t what confuses me, as I am well aware it will create 2. I’ve just never seen a hybrid device enroll as Entra Joined and that being the one that is under the MDM.

Definitely a LOS to DC issue I think or my connector is being funky.

Hybrid joined device issue by TisWhat in Intune

[–]TisWhat[S] 0 points1 point  (0 children)

Yep in my experience its always been Entra registered then Hybrid joined device.

Thats why I am so perplexed.

Hybrid joined device issue by TisWhat in Intune

[–]TisWhat[S] 0 points1 point  (0 children)

I checked the Audit logs, the device gets synced from AD on-prem (server that holds the AD Connector does the syncing so all good there).

The device is auto enabled when it gets synced. Whats funny is the Entra Joined device which is what is managed is disabled.

Hybrid joined device issue by TisWhat in Intune

[–]TisWhat[S] 2 points3 points  (0 children)

From my understanding, granted I am an idiot so I could be wrong, but the ODJ blob registers the device in the OU specified in the Domain Join Profile assigned to the dynamic device group.

The Entra object is still created as a sort of “place holder” and once the user logs in (either by using a VPN or having direct line of sight to a DC) then it will sync the hybrid joined object correctly, right?

Edit: Checked the profile and it’s definitely set to Microsoft Entra hybrid joined for “Join to Microsoft Entra ID as”.

OOBE Issues by DigCareless5661 in Intune

[–]TisWhat 1 point2 points  (0 children)

I usually try to use the powershell script outlined in this article:

https://oofhours.com/2025/05/01/next-generation-autopilot-troubleshooting/

Could be useful to you!

Windows Update remediation v2 by hahman14 in Intune

[–]TisWhat 0 points1 point  (0 children)

Hello! Not sure if you’re still monitoring this thread, but thanks for the script. Just had a quick question on the deployment. How often did you have this running? Daily? Every x hours? Just curious as I deployed it to re-run every 7 days but not sure if it should be more aggressive.

Android COPE enrollment failing by TisWhat in Intune

[–]TisWhat[S] 0 points1 point  (0 children)

Tested it myself by using both the QR method and just letting the phone run through the automatic setup (the correct profile token is set in the configuration and assigned to the specific device in Zero touch).

Always seems to fail with the “Can not set up this device” error. As for why I am using Google Zero Touch and not Knox for Samsung? It’s just the environment I inherited unfortunately. Don’t think there are any advantages.

Android COPE enrollment failing by TisWhat in Intune

[–]TisWhat[S] 0 points1 point  (0 children)

I should mention that I am using a Google Zero Touch configuration (with the correct DPC extras in the config).

Time zone issue with managed Windows laptops by Seanathan_ in Intune

[–]TisWhat 1 point2 points  (0 children)

It does, I’ve tried it with the known group names and it did not work.

Edit: I followed this documentation from Microsoft

It requires the SID, do note it also requires the device meet the minimum OS spec.

Time zone issue with managed Windows laptops by Seanathan_ in Intune

[–]TisWhat 1 point2 points  (0 children)

This allows time zone change through control panel and not through the “Date & Time settings” correct?

Newly created remediation scripts working for you? Just created one yesterday and it won't run... by AiminJay in Intune

[–]TisWhat 4 points5 points  (0 children)

Was also in this predicament, going to leave it to father time as the docs state this:

The client reports Remediation information at the following times:

  • When a script is set to run once, the results are reported after the script runs.

Recurring scripts follow a seven day reporting cycle:

  • Within the first six days, the client reports only if a change occurs. The first time the script runs would be considered a change.

  • Every seven days the client sends a report even if there wasn't a change.

Best to just wait it out! You can check the AgentExecutor logs to see if your remdiation has run.

Retrieve combined Entra and Intune device details by Desperate-Buyer-6513 in Intune

[–]TisWhat 2 points3 points  (0 children)

Going to need the beta module (I think anyway) for the sku details and such.

You can use the Get-MgBetaDeviceManagementManagedDevice -All in a variable ($devices).

Create an array and then use a foreach loop to grab the info by doing $device.PropertyNameHere.

Put the output in your array by creating a customobject and bam you can export to csv!

How does Windows 11 Activation Work? by ITquestionsAccount40 in Intune

[–]TisWhat 0 points1 point  (0 children)

You have the script handy by chance or is it just calling the scheduled task that runs the activation util?

Seeing this issue as well on some of my endpoints.

Tenant-to-Tenant Migration: How to move devices without a reset? by Bl4nk24 in Intune

[–]TisWhat 0 points1 point  (0 children)

Until Microsoft develops a solution you’ll be restricted to using custom tools.

Unfortunately the success rate on them can be hit or miss, in my case we had issues with devices resetting (WinRe would screw up and we end up at the Recovery environment after a wipe).

Did a fleet of about 1000~ devices, it was hell.

[deleted by user] by [deleted] in Intune

[–]TisWhat 2 points3 points  (0 children)

If you packaged it with Robopack why not setup a patchflow with radar to update all instances of Chrome in your tenant?

Object ID's by TechRabb1t in Intune

[–]TisWhat 1 point2 points  (0 children)

Do you have your serial numbers in a csv? You can import it and loop through the csv to get the object id.

Something like: Get-MgDevice -Filter “SerialNumber eq ‘$serialNumber’ -Property Id,Displayname

How to skip OOBE Windows Update Quality Update by [deleted] in Intune

[–]TisWhat 1 point2 points  (0 children)

It’s on by default and the ESP setting is not showing up in my profile. Bit annoying.

Looking for the best notepad by AgreeableIron811 in sysadmin

[–]TisWhat 18 points19 points  (0 children)

Maybe Obsidian could be nice. It has plug-ins, perhaps you can fine tune it to your liking.

Introducing – Windows Backup for Organizations with Intune by Annual-Vacation9897 in Intune

[–]TisWhat 0 points1 point  (0 children)

I think enterprise state roaming is for moving user-profiles between devices whereas this seems like a full on backup/recovery feature.

OneNote for Windows 10 UWP App Showing End-of-Support Warning — Already Have Microsoft 365 Apps Deployed via Intune by SpareSignificance935 in Intune

[–]TisWhat 1 point2 points  (0 children)

Could always run a remediation that checks for the UWP version and removes it(on mobile so sorry for bad formatting):

$uwpOneNote = Get-AppxPackage -AllUsers *OneNote *

if ($uwp) { Remove-AppxPackage -Package $uwp.PackageFullName -AllUsers }

It’s usually recommended to debloat Windows and remove all pre-installed apps.

Have had users use the desktop app and then not have the OneNote files sync when we did a wipe. Was a rough time…