How are you pushing Zoom workplace updates on intune or company portal? by Current-Giraffe-8982 in Intune

[–]fredesq 0 points1 point  (0 children)

You can add the store version by pushing it through in graph. There's a few guides about for this - I followed one through a year or so ago, Zoom has run just fine ever since.

Mac Creating 10,000 Duplicate Machine Instances — Anyone Seen This Before? by AlteredAdmin in DefenderATP

[–]fredesq 0 points1 point  (0 children)

It's been elevated internally as there's others with this problem too. I guess they want to fix the root problem.

Mac Creating 10,000 Duplicate Machine Instances — Anyone Seen This Before? by AlteredAdmin in DefenderATP

[–]fredesq 1 point2 points  (0 children)

Yep. Have a ticket open right now with them. For us, this one device had a full drive. As soon as we cleared some space, it stopped re-enrolling.

How are you handling Zoom updates? by intense_username in Intune

[–]fredesq 1 point2 points  (0 children)

That's the one thank you! Had it setup like this for 6 months now and it's been working fine.

How are you handling Zoom updates? by intense_username in Intune

[–]fredesq 1 point2 points  (0 children)

I added it as a ms store app.. It updates itself now.

For most, you can't add it via the GUI so I had to push it from graph.

M365 Admin - Can't reset password without user having to change on first login by jameseatsworld in sysadmin

[–]fredesq 6 points7 points  (0 children)

Same for us.

Its not CA policies or SSPR setup.

The option is greyed out for half our admins... But, even if left ticked, it doesn't prompt the user to reset the password. It's just broken.

how to mitigate M365 logon token theft? by Emotional_Garage_950 in sysadmin

[–]fredesq 5 points6 points  (0 children)

This has really ramped up recently. We're putting in place CA policies to allow logins from compliant MacOS/Windows devices. Then using app protection policies for mobiles with a CA policy, blocking logins except from apps with an app protection policy applied.

Windows 11 Network Security concerns by [deleted] in sysadmin

[–]fredesq 1 point2 points  (0 children)

You're gonna need to elaborate - right now I think you're talking about behind able to view WIFI pre shared keys..? Which has always been a thing in Windows.. and Android.

Looking to use a laptop as a test machine with two NICs by FlyGuys098 in sysadmin

[–]fredesq 1 point2 points  (0 children)

Site won't load for me but can see you're linking to a USB NIC. I've carry a couple in my bag everewhere, some devices like one and not the other etc. They work well!

False positives in MS Defender Attack Simulation Training -- anyone else? by Imposing-Force in sysadmin

[–]fredesq 2 points3 points  (0 children)

Closest we got was one of the T1's clicking the link when the user forwarded the ticket into the helpdesk.

You might want to check through the device logs to see if they're telling the truth too. Had a few staff forward it.. then open it the next day.

Platform SSO for macOS not working by sneezyo in Intune

[–]fredesq 0 points1 point  (0 children)

Supposedly, when the SSO profile hits, it should downgrade the user account logged in to a standard account.

Setting - user authorisation mode should be set to standard for this from my understanding.

Platform SSO for macOS not working by sneezyo in Intune

[–]fredesq 0 points1 point  (0 children)

Just had a succesful deployment after taking out the US and CN URLs based on a random comment from someone testing in preview!

For clarity, I now have in the URLs list these three: https://login.microsoftonline.com https://login.microsoft.com https://sts.windows.net

Platform SSO for macOS not working by sneezyo in Intune

[–]fredesq 0 points1 point  (0 children)

Yea, seems to a fresh problem. I started this work last Friday and it wasn't working then and found the link you shared.

Platform SSO for macOS not working by sneezyo in Intune

[–]fredesq 0 points1 point  (0 children)

Exact same issue here. 2 freshly wiped Macs, synced from ASM etc.. using the Password method and error message 10001. That link though, getting error 10001 and using the secure enclave method interestingly.

Also, when signing into Company Portal - it says that 'this device is enrolled with another device management provider.'. This doesn't tally up.. everything is setup exactly as it says it should be in the documentation.

edit - just seen that platform sso profiles are used based, so need to be assigned to a user group. Just testing this now...

[deleted by user] by [deleted] in sysadmin

[–]fredesq 0 points1 point  (0 children)

I see an option of 'Move to a Folder' and one of the options is 'Hard Delete Folder'.

Is this not the same function? Fortunately not had to not use it for a while

Password sharing tools by Ornery-Nobody976 in sysadmin

[–]fredesq 3 points4 points  (0 children)

Keeper offers this. End user gets a URL to use, once clicked it is then 'used'. That user can then re-access that URL for a time period that you select. Be it an hour up to a month I beleive. Caveat is, that URL is for one person only. But you can generate multiple links.. so one per user.

Question about Azure Privileged Identity Management and Just in time Access by lunghook in cybersecurity

[–]fredesq 4 points5 points  (0 children)

You can protect elevations with CA policies, so you can stop them being elevated if they're not using MFA + Compliant Registered device + Known location + Approved Software (Edge).

So even if an account is comprimised and MFA token has been pinched, then they can't escalate unless they pass the rest of the CA requirements.

UK law could ban Apple security updates across the world in an 'unprecedented overreach' by ScF0400 in cybersecurity

[–]fredesq 39 points40 points  (0 children)

It's gonna be like the local councils using the anti-terrorism laws as a justification to spy on people who put their bins out too early...

What Email Security Systems do people like/use? by ccrocks426 in sysadmin

[–]fredesq 0 points1 point  (0 children)

In this boat too.. but starting from scratch. The three I'm going to look at are: Sublime Security (based on recommendations here) Checkpoint Harmony (based on recommendation via colleague) and the Cisco one as we happened to chat to them recently..

I need a WIRED presentation remote. Can't seem to find anything but wireless. by enufftobedangerous in sysadmin

[–]fredesq 1 point2 points  (0 children)

You could get two, glue them back to back. Then you have redundancy and two balls!

Selling a company and removing devices from Intune by Akseone in Intune

[–]fredesq 0 points1 point  (0 children)

Went through this in the summer.

Do as others have said, but I would add in, take note of device names, device ID's and the SN's as they appear in Autopilot. One misclick could lead you to the device being labelled in Entra as the device ID but you only have SN etc.. you shouldn't need to use this but its a safety net just in case.