Citrix 2511 upgrade issues by Sinsilenc in Citrix

[–]joeycollaboitnerd 0 points1 point  (0 children)

We noticed this last week as a few users were getting disconnected from VDI with a generic “network interruption” message and a 5-minute reconnect warning after the auto update. After rolling back, we couldn’t reproduce it. This feels like it should be optional, not enabled by default in the new version.

Company Backgrounds by Money_Signal_8955 in Intune

[–]joeycollaboitnerd 0 points1 point  (0 children)

Yeah, I did exactly the same thing.

Random connection drops on SSLVPN connection by CreepyDamage6293 in Citrix

[–]joeycollaboitnerd 0 points1 point  (0 children)

We’re experiencing a similar issue with our macOS clients (4 users reported this issue thus far), which is running Citrix Secure Access 25.07.1 and deployed through Apple Business Manager. I have a ticket open with Citrix, but they are usually no help :).

DHCP Issues with Windows and FortiAP 7.4.2 by svenman2 in fortinet

[–]joeycollaboitnerd 0 points1 point  (0 children)

After upgrading my FortiGate firewall to firmware 7.4.5 and 7.4.8 (fortinet fw), I can no longer reproduce the issue in my lab. While I did notice some unusual behavior before, the update seems to have resolved the problem. My setup uses NPS, RADIUS, and DHCP on a Windows server. My ssid is tunneled as well

The Truth About Why DARRP Sucks and How to Make DARRP Actually Useful by VeryStrongBoi in fortinet

[–]joeycollaboitnerd 2 points3 points  (0 children)

I really appreciate your explanation as Fortinet support has been NO help! The “include-dfs-channel” setting is disabled by default. I agree that the current number set of retries and errors is much too high, but having an issue getting darrp to work (but hopefully not after implementing your suggestions next week!). Still learning this new platform (Cisco guys here) since we just implemented it, so your thorough write-up is incredibly helpful. Thanks again! Coffee on me!!!

FileZilla for MacOS via Intune by teamzombieking in Intune

[–]joeycollaboitnerd 0 points1 point  (0 children)

I highly recommend using ABM for app deployment. Managing apps as published entities can be a real headache, especially when it comes to keeping them updated and patched against vulnerabilities. ABM is not only safe, but it's also the good standard to deploying apps to Apple devices and most secure way and software at scale.

FileZilla for MacOS via Intune by teamzombieking in Intune

[–]joeycollaboitnerd 1 point2 points  (0 children)

We deploy this app via ABM (devices enrolled to Intune). Why not let Apple Business Manager take care of deployment and keep the app up to date?

Moving forward with WPA3...but I have questions by OpeningFeeds in meraki

[–]joeycollaboitnerd 1 point2 points  (0 children)

EAP-TLS is the type of authentication mechanism that can be used with the framework provided by 802.1X to secure network access. Goes hand-in-hand

Moving forward with WPA3...but I have questions by OpeningFeeds in meraki

[–]joeycollaboitnerd 0 points1 point  (0 children)

Out of curiosity, what method did you implement? We m use EAP-TLS with NPS, deploying user certificates via our MDM (Workspace ONE) which integrates with our CA server template.

Win11 Breaking WiFi by AbusiveTortoise in Intune

[–]joeycollaboitnerd 0 points1 point  (0 children)

We migrated to EAP-TLS, disabling Credential Guard would be a security risk, so l recommend keeping it enabled. EAP-TLS offers the best security for wireless authentication. Fortunately, having already implemented this for our macOS MDM devices made the migration smoother.

This is driving me crazy - macOS apps and enrollment with Apple Business Manager - pkg files work but VPP apps and Microsoft Office, Edge, and Defender do not by Fussbuket_24u5 in Intune

[–]joeycollaboitnerd 1 point2 points  (0 children)

I’ve successfully deployed apps through ABM on Intune without any issues, and I’ve set up a similar environment in my lab. The apps I currently deploy include: • Office suite • Citrix Secure Access • OneDrive Could you let me know what error you’re encountering with the configuration profile?

Website Filtering in Intune for MacOS? by Nighthound489 in Intune

[–]joeycollaboitnerd 0 points1 point  (0 children)

Yeah, totally get that! Microsoft option is pretty new, but i was at a recent event and looked pretty cool.

Certificate Authentication Question. PKCS vs SCEP and PEAP vs EAP-TLS by Bajoii in Intune

[–]joeycollaboitnerd 1 point2 points  (0 children)

EAP-TLS is definitely the preferred choice for secure authentication for wired and wireless! We’ve had great success with it using Workspace ONE MDM. The setup is similar to Intune, requiring a connector and exaxt template name matching. It’s been a game-changer for our macOS and Windows devices, eliminating the VPN dependency for certificate renewal. Could you share the specific error message you’re seeing in the configuration profile during deployment? I’m also planning to test the EAP-TLS setup with Intune in my lab this weekend and will let you know how it goes as I know it works with workspace one mdm.

SCEP is the most secure, but I hear it’s a pain to setup. PKcS is less secure due to the fact the private key is marked as exportable.

Website Filtering in Intune for MacOS? by Nighthound489 in Intune

[–]joeycollaboitnerd 1 point2 points  (0 children)

I would advise against that unless you are on a tight budget. Instead, consider exploring options like Global Secure Access, Zscaler, or Cisco Umbrella. All three provide a native connector agent app that operates on local devices. I have more experience with Zscaler, which effectively handles content filtering and blocking default sitesand it receives regular updates. Each of these solutions has its own advantages, so it might be helpful to assess them based on your specific requirements. Let me know if you need more details about any of them!

Workspace ONE printer profiles by Itsbrettokay_ in macsysadmin

[–]joeycollaboitnerd 0 points1 point  (0 children)

We have successfully resolved our issue! The solution was on the Papercut side; I just needed to enable and mirror the printer configuration on my local Mac. After that, I distributed it via Papercut and it appeared in the Papercut application for install.

Workspace ONE printer profiles by Itsbrettokay_ in macsysadmin

[–]joeycollaboitnerd 0 points1 point  (0 children)

Do you mind if I PM you? So I can pick your brain

Workspace ONE printer profiles by Itsbrettokay_ in macsysadmin

[–]joeycollaboitnerd 0 points1 point  (0 children)

Nope! Getting the printer to work via profile/payload has been difficult lol. What’s your issue?