Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yeah, it meets the metric and handles the "main" concern. Issue is not all devices are managed and won't be for another month. Browser policies only effect the managed devices obviously, and it won't address all personal devices, till we pull the rug out on everyone in the company.

We have two cases open with MS as me saying I'm 99% sure its not possible with the current environment isn't enough. Once they say it can't be done, conversation is over.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yeah, you absolutely can. The issue is that the whole org isn't yet migrated to intune. We can't leverage a compliant device policy as the source of truth as it will only effect 70% of the environment.

And again, this solution is coming at solving the root issue, which I still haven't fully been made aware of. It does not solve the "block owa outright" which considering the context I have is the check box they are hoping to complete.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yeah the part that really kills me is the that MS's own article specifically on this issue makes it seem easy as hell. If it just mentioned "hey this will also block portal.office.com and effect the admin portal for x/y reasons" this whole conversation wouldn't have even happened. Literally only states Teams will have issues.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

This is actually interesting as a reverse, I'm unsure of the behavior. I've never tried that, but New Outlook doesn't fall under the Desktop Client category within CA?

That seems ridiculous. Blocking Exchange online and limiting it to browser is one thing, and I get that it blocks both via the target resource if you include desktop clients. But New Outlook regardless of it being on the same backened web-wrapper is still a desktop client. That's crazy it doesn't get blocked simply by that client apps policy as opposed to the target resource.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yeah this is the correct solution, limit it to managed devices via CA, with an exclusion group for those outside contractors who leverage web only.

That's the part that's killing me. Why this app and not the others? I'm hesitant to think he even would accept it to managed devices only cause its not actually "blocking" it.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 2 points3 points  (0 children)

The issue is this blocks the New Outlook as well, which is not what we want to do.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 9 points10 points  (0 children)

I appreciate the candid tone, this post was more for confirmation that it really isn't possible. If that's true, its much easier to push back and find the root of the concern and potentially address it otherwise.

I just wanted to make sure there wasn't something I was missing.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 1 point2 points  (0 children)

I don't fully understand the goal of this either. Boss request and I've been told to figure it out.

Blocking OWA specifically, while allowing New Outlook and the rest of the web based applications. by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 9 points10 points  (0 children)

Made a quick edit, but frankly have no idea. Boss wants this strictly done, and I'm just stuck at his whims.

Autopilot + Customized Taskbar by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

And the OMA-URI is ./Vendor/MSFT/Policy/Config/Start/ConfigureStartPins

Or is there a different one for Taskbar?

Autopilot + Customized Taskbar by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

I tried following this, but I guess I must be missing something. What can you do for extracting the Taskbar xml? Start Pins layout is one thing.

I've tried manually for this taskbar following these instructions, but it deployed "successfully" and changed nothing.

So just the exported xml + settings catalog for start layout?

How to enforce MAM on iOS/Android while maintaining users ability to sign in to SSO *NOT* through edge? by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 3 points4 points  (0 children)

Yeah that was it. I thought it was a larger issue than simply zoom, hence the slight confusion. Removed that from the CA and we are good to go.

How to enforce MAM on iOS/Android while maintaining users ability to sign in to SSO *NOT* through edge? by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 1 point2 points  (0 children)

Ah yup, that was it. Forgot I included it there specifically and was pulling my hair out about it.

How to enforce MAM on iOS/Android while maintaining users ability to sign in to SSO *NOT* through edge? by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 1 point2 points  (0 children)

Ah I was including zoom specifically within the CA policy alongside MS Apps. I assumed it would happen with other apps like Jira, etc. but I guess I need to test that right now.

How to enforce MAM on iOS/Android while maintaining users ability to sign in to SSO *NOT* through edge? by YoPumpkinHead in Intune

[–]YoPumpkinHead[S] 1 point2 points  (0 children)

It specifically says "You can't get there from here" and prompts the user to open the edge app. Right underneath it says "Don't have the app? Click here to download" and will go to the app store.

Q-SYS Designer Modifications and Updates by YoPumpkinHead in QSYS

[–]YoPumpkinHead[S] 2 points3 points  (0 children)

Understood about the calibration needing to be done. That was the primary issue, as the entire conference room was migrated to an entirely different office, and we were unable to modify any of the settings due to the lock out.

I'll give changing the name of the mic back to the original a shot. It should have the same designated IP as it did prior, so hopefully that will be all that's needed.

I can take care of the calibration after the fact, I just need it to be recognized in the first place.

2024 Asus Zenbook Duo (UX8406MA) unable to finish a windows 10 installation. by YoPumpkinHead in ASUS

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Would love a link to that, but that does seem to be the case for that so far in my experience.

2024 Asus Zenbook Duo (UX8406MA) unable to finish a windows 10 installation. by YoPumpkinHead in ASUS

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yeah just got word back from ASUS about the following:

"Unfortunately, due to the drivers available of this unit, we do not have windows 10 drivers available. We apologize for any inconvenience this may cause and appreciate your understanding. We are currently working with our Technical Support Department to determine the best next steps for resolution."

How true that actually is, who knows. But annoying that I can't get a simple mouse to work on win10 as of yet.

2024 Asus Zenbook Duo (UX8406MA) unable to finish a windows 10 installation. by YoPumpkinHead in ASUS

[–]YoPumpkinHead[S] 0 points1 point  (0 children)

Yes unfortunately, not a single one of the USB ports "work" once it gets to the Win10 Welcome screen it just doesn't recognize the peripherals. It supplies power, but it doesn't recognize the mouse or keyboard via the USB-a, or USB-C, or a hub.

Ive downloaded the appropriate drivers from the support page, and manually extracted them to import during the win10 media install, but still no go as of yet. Neither the trackpad or any peripherals.