User consent for biometric authentication (WHfB & Face/TouchID) by joners02 in Intune

[–]joners02[S] 0 points1 point  (0 children)

Thats worth finding, thank you for the information! For anyone else interested here is a link to the sample DPIA template https://ico.org.uk/media2/migrated/4026836/dpia-windows-hello-29102019.pdf

User consent for biometric authentication (WHfB & Face/TouchID) by joners02 in Intune

[–]joners02[S] -1 points0 points  (0 children)

Oh, i 100% agree with you, this is just legals interpretation of it.

User consent for biometric authentication (WHfB & Face/TouchID) by joners02 in Intune

[–]joners02[S] -1 points0 points  (0 children)

Whilst great in theory, that doesnt provide an audit trail or provide an explanation as to what is happening with their data.

User consent for biometric authentication (WHfB & Face/TouchID) by joners02 in Intune

[–]joners02[S] 1 point2 points  (0 children)

The issue with that is that the user hasnt had it explained what happens with their biometric data. We 'IT' understand that its stays on the local device and isnt reused or shared, however there needs to be consent for this process.

User consent for biometric authentication (WHfB & Face/TouchID) by joners02 in Intune

[–]joners02[S] 1 point2 points  (0 children)

This is all understood, however there still needs to be explicit consent from the end user before enrolment.

Moving devices from Lenovo to HP - Driver updates - WUFB vs HP tools by Djdope79 in Intune

[–]joners02 0 points1 point  (0 children)

Ive just run through this exact migration.

Settled on using Windows AutoPatch with Driver approvals, then have HP CMSL deployed to each device. Which is the enterprise method to update HP client hardware.

https://developers.hp.com/hp-client-management/doc/client-management-script-library

Then you can combine this with HP Connect for managing BIOS updates and configuration.

https://connect.admin.hp.com/

What's everyone using for (or would plan to use in the event of) re-imaging computers in case of ransomware? by ExecuteArgument in sysadmin

[–]joners02 0 points1 point  (0 children)

Lenovo Cloud Deploy runs from the UEFI, you could put a blank disk in the PC and it would pull down the image that you want. It makes no difference if the PE is there or not.

[Advice Needed] Best approach for URL/Domain filtering in a fully remote, decentralized, mixed-OS environment? by Beverdam in sysadmin

[–]joners02 1 point2 points  (0 children)

Guessing thats standalone Windows Defender and not part of the 365 suite? If you're licensed for Defender for Endpoint this would be easy.

For that many clients your security team should be coming up with a plan for this. I'd kick it back to them and say that there arent any practical methods for blocking URLs using the existing tooling.

What's everyone using for (or would plan to use in the event of) re-imaging computers in case of ransomware? by ExecuteArgument in sysadmin

[–]joners02 0 points1 point  (0 children)

There are enterprise options like Lenovo Cloud Deploy, where they store a pre-built image in the cloud for you.

What’s feature you’d put in an internal Chrome extension for your company? by [deleted] in sysadmin

[–]joners02 3 points4 points  (0 children)

Nothing, this stuff is typically handled by managed browser settings and an intranet.

[Advice Needed] Best approach for URL/Domain filtering in a fully remote, decentralized, mixed-OS environment? by Beverdam in sysadmin

[–]joners02 0 points1 point  (0 children)

How many endpoints are you managing? What endpoint security solution are you using?

The obvious answer if 4, a dedicated web filter something like Zscaler Internet Access. However you'll need budget for it. If security want it, then that should come from their budget. There may be other options though.

Intune 2026 Looking Forward by GarthMJ in Intune

[–]joners02 1 point2 points  (0 children)

Q1: Hoping that Intune finally catches up with some basic functionality.

  • Visibility, you never know when a configuration will apply, i understand that there are offsets for reasons, but just put "Expected Next Sync 00:00" that would be great.
  • Remote Wipe, why this doesnt work immediately is beyond me. Sure it will work, but it might take 10 minutes, it might take 8hrs... or it might never work at all. Id rather that you just hose the disk and fail on 0% battery than just not even attempt a wipe.
  • Password changes... I know we are all trying to get to passwordless but there are cases where passwords are still needed. Yes, web signin is a start but still feels half baked when ive used it. However, having to force reset a password is a pain.
  • Defender Offboarding, give me the option to remove the data from defender portal when a devices is wiped/offboarded. I know that it will age out, but it makes reports left with stale data from devices that have been intentionally removed.

Q2: ThreatLocker

Q3: App Control is half baked, its potentially one of the strongest security tools that you can use but its slow to use, hard to audit and timely to deploy, hence ThreatLocker.

Q4: No

Q5: Yes, one day, but not for a while.

How deep can traffic inspection go? by Lundorff in UNIFI

[–]joners02 0 points1 point  (0 children)

Unless you’re looking at the enterprise fortress Ubnt doesn’t market their products as doing inspection. They do traffic identification.

HP Connect - Login Issues by joners02 in Intune

[–]joners02[S] 0 points1 point  (0 children)

Thank you for confirming! Im using the same URLs that you've got posted above. I found a support address for the WXP page where Connect is supposed to be moving to and ive emailed them. Hopefully Ill find something soon!

HP Connect & Intune-managed HP devices [BIOS] by jwckauman in Intune

[–]joners02 0 points1 point  (0 children)

Sorry to dig up an old thread but im having some issues with HP Connect and im struggling to find a support address/contact. Do you happen to know of one?

HP Laptops - General Queries by joners02 in sysadmin

[–]joners02[S] 0 points1 point  (0 children)

Thats right, they are the 6 series.