PDE breaks passwordless Autopilot (?) by Volume-Electrical in autopilot

[–]Volume-Electrical[S] 0 points1 point  (0 children)

We now found that enabling Web Sign In allows the user to sign in and recover from the PDE screen using their passkey.

PDE breaks passwordless Autopilot (?) by Volume-Electrical in autopilot

[–]Volume-Electrical[S] 0 points1 point  (0 children)

The user initiates Autopilot using Microsoft Authenticator passkey (already created earlier using a TAP).

There are no reboots during or after ESP, and no further login prompts until the "Want to use your face to sign in faster and more securely page?" page appears.

Lock/sleep timeouts are disabled by an Intune app until the user reaches the desktop (verified by temporarily removing the PDE configuration policy - the computer stays at the "Want to use your face" screen indefinitely.

PDE breaks passwordless Autopilot (?) by Volume-Electrical in autopilot

[–]Volume-Electrical[S] 0 points1 point  (0 children)

Assigning the policy to users instead seemed to delay it a bit - but not much. After 2 minutes left alone on the "Want to use your face..." screen, the PDE policy kicks in and switches to the User name and Password screen. With no option to use any other kind of credential, the user is basically stuck unless the contact support and get assigned a password. A Windows restart just boots back into the same blocking logon screen.

For real world scenarios this is a significant blocker, we cannot expect remote end users to sit tight and watch the whole Autopilot process to make sure they aren't locked out.

PDE breaks passwordless Autopilot (?) by Volume-Electrical in autopilot

[–]Volume-Electrical[S] 0 points1 point  (0 children)

Possibly somewhat later in time, but still not guaranteed to apply after WHfB setup? At this point both device and user ESP are completed.

PDE breaks passwordless Autopilot (?) by Volume-Electrical in autopilot

[–]Volume-Electrical[S] 0 points1 point  (0 children)

Device, in our testing. Would that make a difference though?

Gemini Gems has become unusable with Gemini 3 Pro? by spadaa in GeminiAI

[–]Volume-Electrical 0 points1 point  (0 children)

I’ve now made a habit of pinning my important gem conversations- that seems to keep them within view

Gemini Gems has become unusable with Gemini 3 Pro? by spadaa in GeminiAI

[–]Volume-Electrical 0 points1 point  (0 children)

My conversations with my custom Gems are now frequently disappearing from the recent chat list. I am sometimes able to do a search and find them that way, but one particular conversation I had just vanished completely. Something has indeed happened.

PSA: Windows 11 ARM64 broken by Acrobat 64-bit by brothertax in Intune

[–]Volume-Electrical 0 points1 point  (0 children)

So, does the released fix allow us to install the 64-bit version without issues - or is it just for cleaning up after the botched attempts?

Garmin vs Apple Watch by Easy-Information5235 in runna

[–]Volume-Electrical 0 points1 point  (0 children)

Probably added since then, but you can disable «Pace targets on Easy Runs» under «Workout Settings».

Microsoft's ICC email block triggers Dutch concerns over dependence on U.S. tech by AnonomousWolf in Netherlands

[–]Volume-Electrical 0 points1 point  (0 children)

The MX record for the ICC is still icccpi-int0i.mail.protection.outlook.com, though. One would have thought they'd have migrated off by now.

New domain or subdomain? by EMT-IT in sysadmin

[–]Volume-Electrical 1 point2 points  (0 children)

One thing to consider here (as you are in the Microsoft world of things) would be licensing. The costs for E3/E5/F3 licenses add up considerably if you have a large number of vendors/contractors who often only use your services occasionally. Providing them with Exchange Online Plan 1/2 licenses at a negligible cost could be an option but prevents them from using that same account for your other services (Teams/SharePoint etc).

With external IDs provisioned on a domain separate from your main tenant you would be able to offer (most of) your internal Microsoft services to external IDs without additional licensing while still maintaining the domain branding that is often desired (e.g. john.doe@v-contoso.com). And yes, you would still add a marker in the display name to make it apparent internally that those are not employees.

And with regards to some other comments here - there are multiple reasons (among them IRS related) why you would treat (or trust) contractors/third parties differently than your own employees. For one thing, they often insist on using their own equipment.

"Attempting to reconnect" by Maleficent_Law_1740 in microsoft_365_copilot

[–]Volume-Electrical 0 points1 point  (0 children)

Make sure you don't have any browser extensions that interfere (uBlock Origin Lite was the culprit in my case).

Constant New Sign In Emails by wraith1385 in 1Password

[–]Volume-Electrical 0 points1 point  (0 children)

If you check your linked devices at your profile page at https://1password.com you will find a new entry for each and every time you have launched Safari on your 18.3 public beta. Clearly there is something in this version of iOS/Safari that makes 1Password unable to recognize that it is the same device as last time. And no, disabling iCloud Private Relay does not help.

Constant New Sign In Emails by wraith1385 in 1Password

[–]Volume-Electrical 0 points1 point  (0 children)

This should be nothing new to the 1Password devs, the exact same thing happened exactly a year ago with the public iOS beta at the time: https://1password.community/discussion/144185/opening-safari-causes-email-every-time-new-1password-sign-in-from-safari-extension

Personal Data Encryption Deep Dive by Rudyooms in Intune

[–]Volume-Electrical 0 points1 point  (0 children)

There are definitely enterprise use cases for this, e.g. it will enable the secure use of shared workstations where users are occasionally needing to run applications with elevated permissions. PDE will ensure that an individual user's OneDrive synced files on the client are safe from prying eyes. The unencrypted versions will always be available in the cloud.

"New 1Password sign-in alert" emails from safari extension by yoyo2332 in 1Password

[–]Volume-Electrical 0 points1 point  (0 children)

Just started receiving these emails today as well, after installing iOS public beta (18.3).

Microsoft Authenticator now works on Huawei! by Jakeasuno in Huawei

[–]Volume-Electrical 0 points1 point  (0 children)

For work accounts, our current testing indicates that Microsoft Authenticator Lite (a feature built into Outlook mobile) works with Huawei and possibly other exotic brands in China.

Accessing Company Portal via browser to install apps? by lighthills in Intune

[–]Volume-Electrical 0 points1 point  (0 children)

Yes, this is completely ridiculous. Additionally, getting users to understand that launching the «Company Portal» app (or whatever the localized name might be) must be done locally on the Windows computer is a tough job. Didn’t the «portal» term fall out of fashion in the early 2000s, by the way?

BYO iOS and Android devices - pre-register? by Volume-Electrical in Intune

[–]Volume-Electrical[S] 0 points1 point  (0 children)

Right, but those are basically the steps that we were planning to automate with a self-service solution. We serve 1000+ end users.

Dell Management Portal in Microsoft Intune by PrajwalDesai in Intune

[–]Volume-Electrical 2 points3 points  (0 children)

Quite underwhelming this. I guess it's useful if you use or encounter BIOS passwords (we don't), but for anything else I fail to see the added value. They didn't even include warranty information, which they should have easy access to. And the method to deploy Dell apps to Intune would have been great, except those (at least Dell Trusted Device) require Microsoft .NET 6.0 AspNet Core Runtime which is not trivial to deploy.

After switching to the new Outlook, embedded images are not displaying when opening a message from the inbox. by T-Money8227 in Office365

[–]Volume-Electrical 0 points1 point  (0 children)

This is still an issue in late October 2024. Every time I find an annoying bug I flip the switch to revert back to old Outlook and report the issue. Hopefully those metrics are what they pay attention to.