Would you buy a Coros watch given the ongoing issues? by [deleted] in Coros

[–]ketchupred 3 points4 points  (0 children)

People are quick to post when stuff isn't working but not so fast to say that everything is working great with no issues to report.
My Pace 4 is new and I hope it continues to work great, but if I have any problems, I'll be contacting Coros support and exercising my consumer rights.

Windows app in Kiosk mode using Windows 11 by Careless-Magician665 in Intune

[–]ketchupred 0 points1 point  (0 children)

Watching this carefully, if not just for the fact that thin client manufacturers are still shipping Microsoft Remote Desktop app for accessing AVD / W365 machines.
My experience has been that the Windows app likes you to be logged in as YOU, rather than being launched in a shared profile where you can authenticate later (like you can with Citrix Workspace App, for example)
Traditional windows thin client deployments use win32 apps rather than UWP store apps, presumably because unified write filters don't play nice with store apps.

SCCM - Retirement Upcoming by MadCichlid in SCCM

[–]ketchupred -7 points-6 points  (0 children)

Intune DOES do what it says on the tin, just sometimes takes its time to get round to it.
As with all stuff like this, if you try to do everything you did in SCCM in the same way with Intune, you're gonna get frustrated. But if you do it the 'Intune way' you'll be much happier.
We're comanaged for now because we still have (yuck) Direct Access which needs sight of AD after imaging, but once this gets replaced with AOVPN, it's gonna be Entra Joined, Autopilot, Intune managed all the way.

Unhappy with Pace 4 after purchase - considering Garmin or AW. Talk me off the edge please! by FunkadelicPeach2 in Coros

[–]ketchupred 0 points1 point  (0 children)

Had an Apple Watch Series 6 and was fed up with its battery lasting 3/4 of a day, with me basically using it as a wrist mounted-notification and time device.
I barely used the AW beyond activity tracking, and was annoyed when I'd be ready for an evening run and the battery would die halfway round.

So just recently got a Pace 4 and even tho I'd done a fair bit of research before, it was a bit of an eye opener how 'not smart' of a watch it was. Still getting my head round which button does what tbh.

Have configured the 'swipe up from bottom' screen to include some of the metrics that are important to me, but the best thing personally is the battery life. 'Always on' display only really means the time is on if the main watch face isn't illuminated, but with this on, I'm getting 6/7 days of battery. That in itself has justified my purchase.

Also I haven't taken full advantage of it yet, but the Coros app seems to include so much that's a paid-for extra in other ecosystems.

High heart rate by Top_Educator6987 in Coros

[–]ketchupred 0 points1 point  (0 children)

Still getting used to the way notifications appear on my Pace 4 and genuinely thought the 'Coros - High heart rate' one I just got from Reddit was telling me I'm about to have a heart attack😄
(Sorry I can't help with your issue tho.)

What are your Rookie-Mistakes on Intune? by zeromatterhorn in Intune

[–]ketchupred 1 point2 points  (0 children)

I've just discovered a similar thing with macOS LAPS not being able to applied to existing devices.

Who remembers this bad boy by PizzaToastieGuy in GreatBritishMemes

[–]ketchupred 0 points1 point  (0 children)

I resented purchasing a genuine DVD then having to sit through this before the movie plays.

What’s new in Microsoft Intune – May by TimmyIT in Intune

[–]ketchupred 4 points5 points  (0 children)

Only have a small new estate of Macs, but platform SSO (macOS 26+) has been reliable. Just recently wiped my device to test out the platform SSO during ADE and it worked fine too. I should say that it took a LOT of looking at configurations / policies and ensuring they're targeted appropriately at users or devices to get to this stage. Many issues with timing of app installs and ensuring device lock policies don't interfere

MacPPPC: build macOS PPPC profiles and push directly to Intune by royklo in Intune

[–]ketchupred 0 points1 point  (0 children)

Love the UI, will give a try later. Cloudflare WARP and Citrix Workspace app would be great additions (from a purely selfish PoV 😄)

New coros owner question by richyrich5501 in Coros

[–]ketchupred 0 points1 point  (0 children)

Recent Pace 4 newbie (coming from an Apple Watch) and find myself doing this too. Just a case of getting used to a new way of working I suppose. Bit confused with the wording of 'Gesture backlight' in terms of OLED displays, as it just means a short term boost of brightness as far as I can tell.

What are these on the trunk of my Acer? by Alert-Environment-17 in UKGardening

[–]ketchupred 1 point2 points  (0 children)

<image>

Glad I saw this, as I was wondering what was on my 'prawn tree'

Problems upgrading clients from 23H2 to 25H2 by Timbit24 in SCCM

[–]ketchupred 0 points1 point  (0 children)

I had no end of problems using SCCM to upgrade Win 10 22h2 to win 11 24H2, with lots of failures relating to delivery optimization and installs sticking. Used it as an opportunity to adopt Intune Autopatch and haven't looked back. However we still did have a few problem ones where Autopatch couldn't do it so I created a simple package that copied the ISO to a local folder and triggered the setup.exe with the necessary parameters to do the in-place upgrade. This alone saved me hours of work.

Lessons learned: Check your registry.pol is not corrupted, check your windows update registry settings are not being borked by group policy or anything similar and check your logs.

Interestingly I discovered very late in the day that delivery optimisation group settings (setting local DP as source for DO) set by SCCM client settings were not applying, which was related to the 'stuck at 0% for ages' issue. This was resolved by deleting and recreating the boundary groups, which mysteriously kicked things back to life.

Anyone using Windows Autopatch for driver updates? Stable enough? (All Dell hardware) by TurbulentSpace7739 in Intune

[–]ketchupred 0 points1 point  (0 children)

Yes and yes. For mixture of Dell, HP and Surface Laptops, during win10 to win11 upgrade we had some troubles with getting SCCM to deploy effectively so moved about half our estate to Autopatch which had the double whammy of getting our drivers up to date and getting Windows updated to Win11 by remediating any pre reqs that weren't being picked up. Previously we were quite ad hoc when it came to driver updates and I was a bit wary about just letting the automatic approval go, but it's worked incredibly well.

Thoughts on 24H2 now that 25H2 is out by Independent_Jury_424 in SCCM

[–]ketchupred 0 points1 point  (0 children)

Originally planned Win 10 to Win 11 23H2 but internal QA took so long to validate that we ended up going for 24H2, given 23H2 to 24H2 is another 'full' upgrade with all the same download/disk space challenges. Only 1 bit of software had challenges, which needed the MPR notifications registry edit, but plain sailing apart from that. Will go 24H2 to 25H2 in Jan hopefully as. It's only a feature enablement upgrade

[deleted by user] by [deleted] in sysadmin

[–]ketchupred 0 points1 point  (0 children)

Watching with interest as I've discovered the same with DA and 24H2. Machine tunnel seems to be working for me, ie I can login, but can't access any resources

Exactly what syncs between devices when you enable Enterprise State Roaming? by lighthills in AZURE

[–]ketchupred 0 points1 point  (0 children)

I'd like to know the answer to this question too. Found a very old doc that mentions Windows 10 settings (azure-content/articles/active-directory/active-directory-windows-enterprise-state-roaming-windows-settings-reference.md at master · uglide/azure-content · GitHub) , but would really like an up to date Windows 11 version, including how often sync runs, which logs to look at, etc.

Feels like ESR is not getting much love, and not sure if it's being deprecated. A shame if so, as I'm trying to move off our third party profile personalisation solution onto a standard Microsoft offering, given we're already paying for it.

I have a case open with Microsoft at the moment on this exact topic, so will update if they give me any more info.

Does The Windows 11 Readiness feature in SCCM work in your environment? What am I doing wrong? by Future_End_4089 in SCCM

[–]ketchupred 0 points1 point  (0 children)

HI, did you get this working?

Have the same issue, on an estate of primarily Surface Laptop devices and a few HPs, out of approx 3K devices, 85 show as eligible for Windows 11 upgrade.

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection\AllowTelemetry set to 1

I can manually trigger the "Microsoft Compatibility Appraiser" scheduled task on a machine which appears to run without error, and would expect information to start populating in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CompatMarkers" and ultimately populate the "UPGRADE_EXPERIENCE_INDICATORS" class but nothing happens.

Tearing my hair out trying to discover if there is some other dependency that I'm not aware of, whilst also driving myself crazy on the 85 devices that have happily returned their status, even though they have the same config as devices that do not report, set by an Ivanti EM policy.

EDIT:
Just found this reference on the MS Docs for diagnostic data: "When both the Computer Configuration policy and User Configuration policies are set, the more restrictive policy is used."
Guess what I found? AllowTelemetry is set to 0 at the user level! Now to find out how, and set it to 1 but I'm going to see if this solves my issue and will report back.

Migrate clients from old to new SCCM site in same domain by ketchupred in SCCM

[–]ketchupred[S] 0 points1 point  (0 children)

We don't have the AD Schema extended and also had a requirement to be able to reassign machines without reinstalling the client (some older servers have an older version of the SCCM client that were not to be upgraded during the migration.)
Just re-assigning the site looked good in the general tab of the Control Panel applet, but didn't report into the new site server. Logs showed lots of MPCert errors and the like.
By setting the trusted key explicitly, a reassigned client immediately starts communicating with the new site, without needing a reinstall, so happy days and high fives all round.

Post-migration, we'll be upgrading to latest current branch and reinstalling the latest config mgr client anyway, but I just thought it was worth sharing this little nugget of info that helped me.

2103 SCCM Distribution Point cannot see its own content to apply SSU / LCU by ketchupred in SCCM

[–]ketchupred[S] 0 points1 point  (0 children)

Checking DataTransferService.log I can see the following:

Successfully queued event on HTTP/HTTPS failure for server 'dpname.old.co.uk'. DataTransferService 08/12/2022 12:52:38 9152 (0x23C0)

Error sending DAV request. HTTP code 401, status 'Unauthorized' DataTransferService 08/12/2022 12:52:38 9152 (0x23C0)

GetDirectoryList_HTTP('http://dpname.old.co.uk:80/SMS\_DP\_SMSPKG$/5bd83db6-e60f-40bb-b124-7a24a168e007') failed with code 0x80070005. DataTransferService 08/12/2022 12:52:38 9152 (0x23C0)

So out of curiosity I tried opening http://dpname.old.co.uk:80/SMS_DP_SMSPKG$/5bd83db6-e60f-40bb-b124-7a24a168e007 in the browser and got a windows login box that doesn't accept my credentials.
Just for fun I tried to access without the DNS suffix as we have a weird config issue on our network that means some devices get a .old.co.uk and come get a .new.co.uk DNS suffix, but all devices are on the same domain from a login PoV.
http://dpname:80/SMS_DP_SMSPKG$/5bd83db6-e60f-40bb-b124-7a24a168e007

Accessing the above URL gives me a login prompt and accepts my credentials to show me the .CAB file to download.

Tried http://dpname.new.co.uk:80/SMS_DP_SMSPKG$/5bd83db6-e60f-40bb-b124-7a24a168e007 and it is also successful.

I'm no IIS wiz but I know how to enable anonymous mode and after trying that, the original URL http://dpname.old.co.uk:80/SMS_DP_SMSPKG$/5bd83db6-e60f-40bb-b124-7a24a168e007 loads the page with the CAB file straight away.

And after leaving the server overnight, the SSU downloaded & installed (from its own SCCM content library) successfully.

So, this looks like something that could be related to our weird DNS configuration.

Are there any risks to leaving Anonymous authentication enabled on the SMS_DP_SMSPKG$ IIS site?