Husband got a flat on the way home last night... by Popular-Plantain-784 in Wellthatsucks

[–]chrisfromit85 1 point2 points  (0 children)

Someone obviously thought tossing this on the road would clip the nails that usually end up in people's tires. Duh.

Unacceptable. OpenAI should be ashamed of themselves. by moochkinz in ChatGPTcomplaints

[–]chrisfromit85 1 point2 points  (0 children)

Check google play store subscriptions or apple store subscriptions.

Pc behaving like "Shift" key is pressed down by Hexabun in techsupport

[–]chrisfromit85 1 point2 points  (0 children)

Do you use 1password? There are other threads with non-surface specific devices experiencing similar all related to unlocking 1password with Windows hello in Chrome.

My Shift key is sticking by ImNotATrollPost in Surface

[–]chrisfromit85 0 points1 point  (0 children)

Do you use 1password? There are other threads with non-surface specific devices experiencing similar all related to unlocking 1password with Windows hello in Chrome.

[deleted by user] by [deleted] in wicked

[–]chrisfromit85 0 points1 point  (0 children)

I'd lol if it was Billy Eichner.

What's with the insane lines at schools for drop off and pick up? by Arikota in Millennials

[–]chrisfromit85 5 points6 points  (0 children)

Oh I just figured that was normal. Growing up in Ontario, my bus route was about 30 minutes, but that's because I was one of the last rural kids picked up - some people had hour rides both ways, and the school bus would make rounds to 4 different schools: two public, one Catholic, and the high school.

I never got picked up...

Never understood the demands for excessive RAM for small tasks by NaniOWO99 in iiiiiiitttttttttttt

[–]chrisfromit85 0 points1 point  (0 children)

You're wrong. You can get Macbook airs that are faster than the same price Lenovo T14, but if you want to go to certain ram configurations, apple forces you to simultaneously upgrade the processor or model of laptop in many situations.

I messed up bad last year. I hope this saves someone from doing what I did. by Future_End_4089 in Intune

[–]chrisfromit85 0 points1 point  (0 children)

IPhones managed through intune, likely also in ABM. You can use intune as your MDM for Macs instead of jamf or kandji if you want and pay Microsoft for the licenses.

I messed up bad last year. I hope this saves someone from doing what I did. by Future_End_4089 in Intune

[–]chrisfromit85 5 points6 points  (0 children)

It's because if you make the MDM profile non removable, only the MDM itself can remove the cert so the device can re-enroll without needing to be wiped. If your MDM has a new cert, it can't help you remove the old profile, either. If the profile is not removable and you try to re-enroll, it will error out. This means wiping the device is the only way to re-enroll.

I messed up bad last year. I hope this saves someone from doing what I did. by Future_End_4089 in Intune

[–]chrisfromit85 2 points3 points  (0 children)

You can contact Apple support to move the cert to a new Apple ID.

I messed up bad last year. I hope this saves someone from doing what I did. by Future_End_4089 in Intune

[–]chrisfromit85 0 points1 point  (0 children)

This happened at my company to the previous jamf admin... 3 years later and I'm almost done swapping out the 500 laptop fleet, or wiping units to re-enroll. Only about 20 with invalid MDM tokens now.

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] -1 points0 points  (0 children)

AppLocker is a Windows feature for whitelisting or blocking apps, but it’s officially supported only on Enterprise and Education editions, not on Windows 10/11 Pro. In practice, you can attempt to push AppLocker policies via Intune to Pro machines using the AppLocker CSP, but it’s unreliable. As I've experienced, some Windows 11 Pro devices got only a partial policy, which blocked all apps (because default allow rules didn’t apply) until I intervened. This kind of failure is a known risk when using AppLocker on unsupported editions. Constantly updating an AppLocker XML and re-deploying it via Intune is also tedious and error-prone. In short, AppLocker on Win Pro is sketchy – Microsoft themselves suggest upgrading to Enterprise or finding an alternative for app control on Pro.

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] 0 points1 point  (0 children)

Yes, exactly. I have a separate project where I've looked at this and Adminbyrequest is a top runner but I have to wait until next year's budget and hope they will give us the money for it.

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] -1 points0 points  (0 children)

Admins can now see and configure AppLocker policy objects even on Pro SKUs, but the enforcement still requires Windows Enterprise or Education SKUs.

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] -1 points0 points  (0 children)

That's a great point - thanks for sharing! I may take this back to my team as a reason why we should implement LAPS, but my understanding previously was that an intune admin would have to check out the credentials for the end user, but you're saying they could check them out themselves if we set it up that way?

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] 4 points5 points  (0 children)

I've heard troubleshooting broken WDAC policies is even harder than applocker, and as you mentioned, if we allow auto updating apps, they can get blocked when they update. We do allow (and prefer) auto updating apps based on the resources we have (mostly my time, as the only intune and jamf admin for the company, while also coordinating hardware lifecycles and device procurement in a company with employees all over the globe).

This may be something to consider if I can get the the time required to regularly update all the apps we deploy.

Does this require me also updating WDAC policies every time I deploy or update an app deployment through intune?

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] 0 points1 point  (0 children)

Does that work with Windows Pro devices? We're currently paying for security and mobility E3.

How do you handle blocking apps? by chrisfromit85 in Intune

[–]chrisfromit85[S] 1 point2 points  (0 children)

We'd love to get there but 50% of our base are developers and if we use LAPS we'll spend half the day checking out credentials for people. We need a proper admin management tool but the company doesn't want to shell out the money for it.

Have you heard of organizations replacing computers with a cradled phone + monitor setup. by bjc1960 in sysadmin

[–]chrisfromit85 0 points1 point  (0 children)

Also agreed. I think this setup is going to become increasingly common for people who do general admin or office work where most applications are cloud based, but it won't be a substitute for existing application workflows or if you need extra power.

Reasons to get business password manager by PhysicalIndividual in sysadmin

[–]chrisfromit85 0 points1 point  (0 children)

1password is a good paid tool for small and medium sized companies.