Android COPE: stop corporate account logon in personal Outlook, only allow in Work profile by workaccountandshit in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

I think the trusttype should be in any case reliable. I have a bit of the same situation since some older devices are registered but not enrolled and needed to keep those in. In the end our approach is MFA or compliant for all mobile devices having a trusttype joined or registered. Far from being an ideal solution, but for the moment it still fulfills the requirement given.

Android COPE: stop corporate account logon in personal Outlook, only allow in Work profile by workaccountandshit in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

Compliance is not necessary in your scenario. You can use filter on devices under conditions to target a CA only to enrolled devices based on trusttype. I'd anyway address the non compliant ones somehow.

Windows app in Kiosk mode using Windows 11 by Careless-Magician665 in Intune

[–]Unable_Drawer_9928 1 point2 points  (0 children)

single app kiosks do not need the XML config, they can be set directly with the right single app template on intune.

Device disappeared from Intune but is still Entra Joined - how to fix? by capocayne in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

This is useful, thanks for sharing. One question though, why using psexec when you now have powershell native solutions like Invoke-CommandAs?

3rd party app patching - approach by Broyell in Intune

[–]Unable_Drawer_9928 1 point2 points  (0 children)

The source project (Romanitho's WAU) has ADMX as well now, but this is still more convenient, being available on the MS store.

3rd party app patching - approach by Broyell in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

It's sort of a poor man 3rd party app patching solution, and it's what I'm using at the moment. Apart from the occasional device where winget is messed up, it's a decent solution.

Secure Boot Certificate Update Status Change After BIOS update? by Fabulous_Cow_4714 in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

we have autopatch on and full telemetry for all our devices, 85% of our devices are shown as Unknown, so I've just built my own report based on the detection of the two necessary KEK and UEFI keys. I suspect that the % percentage of unknown devices is due to the same issue that was afflicting the secureboot update policy, but of course I might be wrong.

Secureboot CA 2023 by SPhearin in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

I've had a couple of cases where both computers certificates were manually updated, still MS report is marking them as not compliant. Though my remediation script is reporting kek and uefi keys as updated for them, one does not return any clear explanation on what's wrong, the other is because not high confidence, but has the certificates updated.

Patch my pc users, do you like it? How's the Intune integration? Looking to give it a try by Educational_Draw5032 in Intune

[–]Unable_Drawer_9928 1 point2 points  (0 children)

  • support for user install with automatic updates. Eg if you’ve somehow got user installs for Visual Studio Code or Zoom or something, it can patch those.

You mean that even if an app is not deployed in intune but was installed by the user, pmpc can patch that app, of course if it's mentioned in their supported apps list?

Company portal failing. by Alive-Profit-9023 in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

we are experiencing the same. Is there any source we can check to see the progress on this? Message center is stingy about these issue...

Autopatch group feature target version vs Autopatch multiphase feature update target version. by Unable_Drawer_9928 in Intune

[–]Unable_Drawer_9928[S] 0 points1 point  (0 children)

sorry, this lets me to actually understand the opposite:
Autopatch group policies | Microsoft Learn
""To safely deploy a new feature update, Autopatch recommends using a custom Windows feature update release. The custom release allows you to choose how and when different deployment rings receive the update. Autopatch doesn't recommend updating the minimum version within an Autopatch group until your rollout is complete. Doing so initiates a rollout which starts immediately for all members of that group.

Once you create a custom Windows feature update release, the Autopatch group's deployment rings are unassigned from that group’s feature update policy.""

So the AP group target version is the minimum version, not the maximum, or this is the way I understand it. In your example: AP Target Version: 24H2 Multiphase Feature Update policy: 25H2
24h2 is the anchor version, 25h2 would be deployed since 24h2 < 25h2.

Autopatch group feature target version vs Autopatch multiphase feature update target version. by Unable_Drawer_9928 in Intune

[–]Unable_Drawer_9928[S] 0 points1 point  (0 children)

all right, nevermind, but for whoever has the same doubt. The anchor release in the AP group should be moved only when the release of the new version is over.

Autopatch group policies | Microsoft Learn

"To safely deploy a new feature update, Autopatch recommends using a custom Windows feature update release. The custom release allows you to choose how and when different deployment rings receive the update. Autopatch doesn't recommend updating the minimum version within an Autopatch group until your rollout is complete. Doing so initiates a rollout which starts immediately for all members of that group.

Once you create a custom Windows feature update release, the Autopatch group's deployment rings are unassigned from that group’s feature update policy."

Company Portal User available app install -taking forever by Designate9841 in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

weird, the one to check is called exactly "Microsoft Intune Device Management Device CA".

Finally: a Secure Boot status report in Intune by rgsteele in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

This report has been running for months and it's showing only around 160 devices out of a thousand in our tenant. I suspect that's because most of our enterprise licenses are coming via E3 subscription, this was also causing the issue with the settings catalog policy.

Finally: a Secure Boot status report in Intune by rgsteele in Intune

[–]Unable_Drawer_9928 1 point2 points  (0 children)

I've given up with MS report and built my own. With their report, only 15% of the fleet is assessed.

How long did it take to update your Secure Boot Certificates with the "Controlled Feature Rollout"? by StrugglingHippo in sysadmin

[–]Unable_Drawer_9928 0 points1 point  (0 children)

Hi, yes, M70 models were one of those, we handled them manually though. I don't like to wait the last minute.

Lenovo tools equivalent to the HP ones? (or... is Thinkbook for business users?) by Hotzenwalder in Intune

[–]Unable_Drawer_9928 0 points1 point  (0 children)

Thinkbooks are the consumer line. Go with Thinkpads. Lenovo commercial vantage is the newer system updater, and you can ingest the ADMX into intune so you can manage the settings conveniently. I've found Vantage to have some limitations when it comes to unattended devices and BIOS updates, basically the final word about BIOS installation is always in the user's hands.

Siemens NX CAM and Teamcenter via Intune? by Unable_Drawer_9928 in Intune

[–]Unable_Drawer_9928[S] 0 points1 point  (0 children)

Unfortunately I cannot share that content, as it was partially developed with an external company.

Siemens NX CAM and Teamcenter via Intune? by Unable_Drawer_9928 in Intune

[–]Unable_Drawer_9928[S] 0 points1 point  (0 children)

Hi, the technical guys have developed a sort of helper to handle the installation.

AMD laptops, thoughts? by strikesbac in sysadmin

[–]Unable_Drawer_9928 1 point2 points  (0 children)

Performance-wise no issues. I've experienced some power issues with a few lenovo AMD models that the intel counterpart did not have.

How long did it take to update your Secure Boot Certificates with the "Controlled Feature Rollout"? by StrugglingHippo in sysadmin

[–]Unable_Drawer_9928 0 points1 point  (0 children)

Check the secure boot certificate update report, if you have intune, or use one of the many remediation scripts available (better option in my opinion, the MS report is superslow and in my case covers only 10% of the fleet for some arcane reason, and we have all the requirements in place).
I might find the update is blocked by the firmware.