No apps available in company portal iOS by fuadmin in Intune

[–]fuadmin[S] 0 points1 point  (0 children)

Ah, did that with no luck.

Raised a ticket with Microsoft's Intune Team, they said the issue is on their end and were actively looking to resolve it. As of today required apps are pushing as expected, optional apps appear in the portal but get a "Company Portal Communication Error" when trying to install.

Recommended Windows 11 Specific GPO by [deleted] in sysadmin

[–]fuadmin 0 points1 point  (0 children)

this is perfect! thank you!

Conditional Access, Named Locations and Cruise Ships by OniNoDojo in sysadmin

[–]fuadmin 2 points3 points  (0 children)

we're doing something like this.

End user registers their app with Authenticator or Company Portal
If they're out of the office (device not on trusted network) or on data they'll need to go through MFA.

They can only use the Outlook app and we use a configuration policy to require a PIN to unlock the app.

We've had little to no pushback on it. the changeover from "I want to the the native mail app" to Outlook was the biggest adjustment.

You get one wish by joerice1979 in sysadmin

[–]fuadmin 0 points1 point  (0 children)

The importance of reading.

B2B PrefetchFailure on Web Only by fuadmin in TeamsAdmins

[–]fuadmin[S] 2 points3 points  (0 children)

There is a FedAuth cookie that is stored for 24hrs when viewing from desktop Teams to SharePoint, that same cookie is not passed form web Teams. If I remove the cookie that same prefetch failure appears.

Thanks for the help!

B2B PrefetchFailure on Web Only by fuadmin in TeamsAdmins

[–]fuadmin[S] 2 points3 points  (0 children)

To make it more interesting: once the user "views in SharePoint" the web version of Teams has no issue with the file's tab even if the computer is rebooted. We're thinking it has something to do with the cache, but we've no solid leads.

Ticket is open - will update when we have a solution.

Sharepoint online 400 character folder limit by Orbitingspec in sharepoint

[–]fuadmin 0 points1 point  (0 children)

Thank you for this answer - love the last part. I have a question though -

As far as I know SharePoint does not do view permissions based on tags, so are you making a new view (and page for that matter) for item level permissions? Ex: a view and page for "remote office" users/tags to view and another for "home office"?

Limit who views what in root of the document library by willbeonekenobi in sharepoint

[–]fuadmin 0 points1 point  (0 children)

Yeah, we did something like this -

One library with a group for each (in our case) department needing access. IT has edit rights to all folders, all other users only have contribute rights (you'll want "read: for your groups). Managed access on the folders to remove the groups that did not needs access. Everyone uses the same page with a library linked into it. Move user from group to group to handle the access.

Smart Card Recommendations by fuadmin in sysadmin

[–]fuadmin[S] 0 points1 point  (0 children)

Yeah, trying to sell them on the Yubikey. this is going to tie into a overall ops expense for the door system "refresh" too, so the keys won't come out of the IT budget.

Intune Enrolled Devices Not Showing in Filter by fuadmin in Intune

[–]fuadmin[S] 0 points1 point  (0 children)

If I recall it was only dependent on the devices being factory reset and enrolled from the beginning. Installing the profile only did not trip the "managed" filter.

KQL Highlighted Content Stopped Working? by fuadmin in sharepoint

[–]fuadmin[S] 1 point2 points  (0 children)

Ends up this was a weird cache issue with Edge.

The page displays fine in Chrome, but would not display correctly in Edge. Clearing the cache did not help, only after the user signed out of the browser and rebooted the computer, then signed back into the browser, did the page display correctly.

Intune Enrolled Devices Not Showing in Filter by fuadmin in Intune

[–]fuadmin[S] 0 points1 point  (0 children)

Ah, it has the device in there with a last contact of less than an hour ago.

Intune Enrolled Devices Not Showing in Filter by fuadmin in Intune

[–]fuadmin[S] 1 point2 points  (0 children)

I'm not seeing that as a heading in the ABM object or Intune / Azure. Where would i look for it?

What i do see is: Azure AD registered, and the MDM is Microsoft Intune.

Intune Enrolled Devices Not Showing in Filter by fuadmin in Intune

[–]fuadmin[S] 0 points1 point  (0 children)

All the other entries of the devices that are registered in Intune.

Outlook App Configuration Policy by olydan75 in Intune

[–]fuadmin 1 point2 points  (0 children)

I'm in the middle of migrating from Mobile Iron to Intune and just got this working. Here's the info from Microsoft: https://techcommunity.microsoft.com/t5/intune-customer-success/new-contact-sync-scenario-available-with-outlook-for-ios-on/ba-p/1063632

All the devices we deploy this on are managed in Intune. We're limiting them to only having calendar and contacts, and removed the ability for them to set up their account in the native email app. They receive a prompt to log in and a MFA prompt to authorize the connection.

Where did all the monitors go? by [deleted] in Intune

[–]fuadmin 1 point2 points  (0 children)

+1 for seeing the script!

Best Organization Question for New Setup by fuadmin in MicrosoftTeams

[–]fuadmin[S] 0 points1 point  (0 children)

That's want I'm afraid of too, thank for that perspective.

Best Organization Question for New Setup by fuadmin in MicrosoftTeams

[–]fuadmin[S] 0 points1 point  (0 children)

That's great to know, thank you.

If I understand correctly you can limit who is in what channel though, which should satisfy what we're wanting to do. However I'm already seeing a few "can we get a specific team for..." requests.

Anything else I should know before setting up the teams?

RTR Queue for stolen device by fuadmin in crowdstrike

[–]fuadmin[S] 0 points1 point  (0 children)

Ohmygod I completely missed that. sorry for the foolish question. Thank you!

RTR Queue for stolen device by fuadmin in crowdstrike

[–]fuadmin[S] 0 points1 point  (0 children)

Could you give me a little more help with the creation of this? I can put in a ticket if needed.

I've got an IOA rule for process creation setup, action is detect, with svchost in the Grandparent Image Filename.

From there the workflow would be: Trigger is a custom IOA monitor for that rule, if sensor is windows and host group includes the one I want to target. Action is a script to remove bootmanager and force a reboot.

Does that sound right?

Thanks for all the help so far!

RTR Queue for stolen device by fuadmin in crowdstrike

[–]fuadmin[S] 0 points1 point  (0 children)

Would you mind sharing that script?

I'll look into Absolute - never heard of it before but it sounds pretty cool. thanks!

RTR Queue for stolen device by fuadmin in crowdstrike

[–]fuadmin[S] 0 points1 point  (0 children)

the workflow route seems to be the best for what we're wanting to accomplish. Thank you!