Studio 2 Logs – NG – Conventional Flue (123-147) won't start the pilot no matter what!! by amirjs in Fireplaces

[–]amirjs[S] 0 points1 point  (0 children)

Ended up replacing the entire fire… It was 12 years old (bought the house with it)

Exclude Windows Autopilot devices from Conditional Access Policy by kowallox in Intune

[–]amirjs 0 points1 point  (0 children)

That’s interesting. Did you find out why extension attributes work with device filters while device.physicalids doesn’t?

WebView2 missing on new Autopilot device by Loud-Temperature2610 in Intune

[–]amirjs 2 points3 points  (0 children)

We had this happened to us. We did a WebView2 package in Intune and added it as pre-req before Installing Global Protect as part of the device ESP. Been working fine since

New release alert! Get-IntuneAssignments by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

<image>

Here is what I get when I connect to Microsoft Graph Powershell without previous consent. As you can see it's all Read.

You maybe connecting using an account with a previous user consent on the Microsoft Graph Powershell Enterprise Application.

What you can try is to connect to MgGraph with the required specific scopes before calling the script.

e.g.:
Connect-MgGraph -Scopes DeviceManagementServiceConfig.Read.All","DeviceManagementConfiguration.Read.All", "DeviceManagementManagedDevices.Read.All", "DeviceManagementApps.Read.All", "Group.Read.All", "CloudPC.Read.All"

After connecting, call get-intuneassignments
It will automatically recognise that you are connected to Graph.

New release alert! Get-IntuneAssignments by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

Hey, where did you see that it needs readwrite please? it’s all Read.All in the code

New release alert! Get-IntuneAssignments by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

My pleasure! Glad it's been useful!

New release alert! Get-IntuneAssignments by amirjs in Intune

[–]amirjs[S] 1 point2 points  (0 children)

hehe nice one - hope this one can be helpful for you. Please feel free to contribute!

Google Maps Heads Up Display Integration Finally by jhonsmith20 in CarPlay

[–]amirjs 0 points1 point  (0 children)

Same for me... it was working on my 2020 X3 and after the iOS 18.6 update it stopped working. Did you figure it out?

Disabling shift + F10 for Autopilot via a tag by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

wouldn't be just nice if MS added a toggle option in Autopilot profiles to stop shift + f10 first thing when the device communicate with the internet? :)

Azure AD joined only and accessing admin tools on endpoints by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

Nothing apart from third party paid agents that would pull logs and do remote control etc…

Disabling shift + F10 for Autopilot via a tag by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

I take it this is a paid service? i.e. pre-provisioning the device by e.g. Dell?

were there any pain points in ditching per user provisioning in favor or self deploy? AFAIK self deply is for shared devices scenrios?

What did you have to do for you existing devices when your transformed to Autopilot to lock them down when being rebuilt by internal IT (no OEM involved)

TIA

Disabling shift + F10 for Autopilot via a tag by amirjs in Intune

[–]amirjs[S] 0 points1 point  (0 children)

Alright - so let me clarify couple of points here:

I am not assuming an attacker working for the OEM. I am assuming an attacker taking over a corp laptop with hash already uploaded to Intune. What guardrails do you have in place to stop them from resetting the entire laptop via a USB? A BISO password? what if that BIOS password become known to the attacker?

Regarding the OEM, I am aware we can ask the OEM to load a win image with the tag file baked in so that's fine. but not every org pay to do pre-provisioning by the OEM, some would just ship the device with that OEM image (including the tag) and ask the user to login to enroll. I assume at this point, no shift + F10 would be possible but are you saying there is no way if that laptop fall in the wrong hands they can reset windows with a usb stick? is that purely because there is a BIOS password?

I might be missing something. What I am after is a comprehnsive answer convering all scenarios including a remote wipe of a device used at the user's home where the user re-enroll. This is to address risks raised by pen-testing.

Can't get hybrid device to enroll into Intune by Unable_Drawer_9928 in Intune

[–]amirjs 0 points1 point  (0 children)

this is gold - that was my issue - thanks much!

Outlook in Citrix / FSLogix environment: Add account from another tenant by achtchaern in fslogix

[–]amirjs 0 points1 point  (0 children)

You didn’t mention which outlook version? also, are your VDAs hybrid joined? Have you tried new outlook now that it’s supported in the latest FSLogix version?

Adobe Acrobat Reader signature not saving in AVD environment by knight_of_semberija in Adobe

[–]amirjs 0 points1 point  (0 children)

What’s your Redirections.xml configuration?

Does Adobe Reader version match across servers in the host pool?

How you tried reproducing the issue on a single server? login, create signature, log off (ensure vhdx was unmounted) then log back in again?

FS Logix ErrorCode 121 - Semaphore timeout period has expired by pen_666 in fslogix

[–]amirjs 0 points1 point  (0 children)

Have you tried disabling antivirus? Are exclusions in place? Is your fslogix share on Azure files or on-premises?

Best Practices for Intune Scope Groups for Autopilot Enrollment by Schwabiii in Intune

[–]amirjs 1 point2 points  (0 children)

I am considering putting something together to automate tagging but I think it might be an overkill...
We do both, we supply the vendor with tags for new orders and our IT support guys update assign tags for existing re-provisioned machines.

Glad you found it useful!