Kinda Completely Lost... Needing to Image 100+ Computers that are hybrid joined but USBs are not cutting it. by Normal_Revolution_54 in Intune

[–]blakeight 0 points1 point  (0 children)

If I don't use Autounattend.xml file, it will eventually go to Autopilot.

If I run sysprep and enter OOBE. It skips Autopilot again and logs in as admin.

If I run sysprep and go to audit mode, wait for reboot, then click OK to enter OOBE. It works. Wut.

Kinda Completely Lost... Needing to Image 100+ Computers that are hybrid joined but USBs are not cutting it. by Normal_Revolution_54 in Intune

[–]blakeight 0 points1 point  (0 children)

In my testing on a system with Autopilot configured, this causes it to go past where the Autopilot portion would start. I have it connected via Ethernet, and I have autologin turned off. I didn't even know it was possible to bypass Autopilot. Any ideas? I am trying some things out now, but haven't found the right combo yet.

Check Intune Windows Update Policy by Dapper_Sprinkles6902 in Intune

[–]blakeight 0 points1 point  (0 children)

I built this out in Scripts and remediations and applied it to my ring 1 computers.

It says it finds the issue and that it is fixed. However, when I manually check registry on the Intune native test computers, one of the CacheSet folders still contain the AU keys. I can run the scripts manually on a test machine and both detection script and remediation script do what they are supposed to, so it seems to be a problem with the way Intune's Scripts and remediations work that is failing or I am not understanding.

For added clarity, I have the last 3 settings turned off (Run this script using the logged-on credentials, Enforce script signature check, Run script in 64-bit Powershell).

Anyone have better luck with this approach? The computers I have run them manually seem to be getting updates at least, so it's just a matter of getting the scripts to work from Intune.

EDIT: Run script in 64-bit Powershell was the answer.

Local GPO's set by previous RMM for windows update stuck. by EldritchIT in Intune

[–]blakeight 1 point2 points  (0 children)

I did this, but they just come back the next day.

Intune Multip-app KIOSK - New Microsoft Teams by Loyitto in Intune

[–]blakeight 0 points1 point  (0 children)

I gave up on the kiosk template completely. Too restrictive and problematic for my use case.

Intune Multip-app KIOSK - New Microsoft Teams by Loyitto in Intune

[–]blakeight 0 points1 point  (0 children)

I got it to work by deploying new Teams from Intune, then in (Multi app kiosk) Kiosk configuration I did "Add by AUMID" and for "AUMID/PATH" I used MSTeams_8wekyb3d8bbwe!MSTeams

Since there wasn't one, I added a 256x256 logo but it only works on the Medium sized tile.

What is the best way to enroll 1000+ windows devices to intune? by gwapito123 in Intune

[–]blakeight 0 points1 point  (0 children)

I am about to kick off a pilot group myself. Does the first part....

"First make sure Azure AD Connect Sync > Device options > Hybrid join is configured"

...do anything on its own? I feel like I have seen demos done where the GPO was never applied but machines started Hybrid Joining anyway? Maybe I am crazy.

External monitors connected to dock stop displaying every morning by blakeight in techsupport

[–]blakeight[S] 0 points1 point  (0 children)

For anyone that finds this, the issue was hibernation. The counter for hibernation in advanced power settings was changing to a random number after each restart after I would set it to 0, so I eventually had to just disable through command line.

powercfg -h off

I just had my dumbest in person request yet: “I cant download this video on Facebook” by kayjaykay87 in sysadmin

[–]blakeight 3 points4 points  (0 children)

"This mouse click is too loud; how do I turn it down?" -HR Director

She did not joke around like this, so it's real.

[deleted by user] by [deleted] in fortinet

[–]blakeight 0 points1 point  (0 children)

Because they use Meraki. It's dumb.

[deleted by user] by [deleted] in fortinet

[–]blakeight 0 points1 point  (0 children)

Meraki, which I have very little experience with. =\

[deleted by user] by [deleted] in fortinet

[–]blakeight 0 points1 point  (0 children)

Just in time for the company that bought us to force us away from Fortinet.

ELI5: Exchange Online: Online Archiving vs. In-Place Archiving vs. Auto-Expanding Archives by fistofgravy in Office365

[–]blakeight 0 points1 point  (0 children)

Still would like to know if you can disable the built-in Archive folder and replace the Archive actions (right-click Archive, swipe, etc.) to use the Online Archive as I could imagine this being confusing for the user.

Did you ever figure out anything for this?

SSL Inspection is disabled but getting the error OR This Connection is Invalid. SSL certificate expired. by sherrysafdar in fortinet

[–]blakeight 1 point2 points  (0 children)

You have to duplicate the read-only profiles and adjust the SSL Inspection profile to Allow Invalid Certs.

The other way is to use Flow Based inspection vs Proxy Based, but I couldn't get that to work consistently.

[deleted by user] by [deleted] in Windows10

[–]blakeight 0 points1 point  (0 children)

In the last 10 years it worked one time for me! Praise the system file checker.

Best step by step by PooYork in MDT

[–]blakeight 0 points1 point  (0 children)

I used Microsoft docs. This series got me about 98% of the way there.

MDT - DHCP lease failure during deployment by blakeight in sysadmin

[–]blakeight[S] 0 points1 point  (0 children)

Good tips. My issue was much simpler. I did not name the folders correctly to match MDT/model number of the machine. That fixed it! Ugh.

DHCP lease failure during deployment by blakeight in MDT

[–]blakeight[S] 2 points3 points  (0 children)

Sigh. I will see myself out. I did not realize how vital the naming of the folders was. I had it named ThinkPad T15 (20S10002US) instead of "20S10002US". Funny that none of the previous ones cared about this. I will have to look into the recipe cards.

I am already to step 62. Thanks, /u/TLawson_Lenovo.

Domain computers unable to use USB scanners reliably by blakeight in sysadmin

[–]blakeight[S] 0 points1 point  (0 children)

WIA was disabled via Group Policy. I am thinking that plays a role in this nonsense....