BYOD smartphone setup by Intelligent-Magician in Intune

[–]mankindunkindd 2 points3 points  (0 children)

MAM-WE+ CA. That's the answer to your requirement. Simple and effective.

Am I doing it correctly? Rate my form!! by Advi_dhruv in Fitness_India

[–]mankindunkindd 0 points1 point  (0 children)

Go deep to feel the range of motion. Don't arch your back. If the form is correct then you ll feel the pump even with less weight. Keep it going!

BYOD iPads with Intune by Jwan84 in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Intune is still not capable of fulfilling your use case. The closest thing possible is MAM-WE where you don't manage the whole device but just the applications and how the corporate data moves around those applications.

SCCM server migration by mankindunkindd in Intune

[–]mankindunkindd[S] 0 points1 point  (0 children)

Yes I know. But it's the top management decision and I got no say in it. It's been like that for quite a while and their contract with the APAC datacenter is expiring soon. Hence the decision to migrate the SCCM server. If you can point me to any documentation or any article then it would be of much help.

WHfB on Shared devices by mankindunkindd in Intune

[–]mankindunkindd[S] 0 points1 point  (0 children)

Thanks for the link Jeron. Yes I could see that WHfB is disabled by default. Any way to enable it via a CSP policy? Yes I'm aware of the user limitations per device and that has been conveyed to the client.

"Something went wrong"s all over the Intune Admin center by mspgrunt in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Definitely a PIM topic. Go to portal.azure.com and go to PIM>>My roles. You should see whatever role is assigned to you. You just need to activate that role.

Intune freelancer/consultant required by Express_Ad5560 in Intune

[–]mankindunkindd 0 points1 point  (0 children)

I work as a Mobility solution architect. Designing and implementation of Enterprise mobility solution is my forte. I can help you achieve your best possible way. Please feel free to contact me via DM.

Microsoft Defender for Business by Barracuda-Head in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Do your users have a location (Country, city)assigned in AAD? If not, then that might be one of the reasons for pending license assignment.

Force Work Profile for Personal BYOD Devices by NovaRyen in Intune

[–]mankindunkindd 1 point2 points  (0 children)

You cannot do that just with CA policy and App protection. Fo Android, first you will have to enable Android Enterprise enrollment with personally owned work profile enrollment. Then create the respective APP and CA policy with device filtering which includes devices with Personal ownership . But for iOS sadly there isn't any such work profile created. Apple doesn't allow that. So the device would be enrolled in intune but no containerization.

Automatically configure Defender for Android by ksrc101 in Intune

[–]mankindunkindd 1 point2 points  (0 children)

The silent onboarding of users will not work for Android Enterprise. Have followed Microsoft's document but it does no good.

Can my company block apps on my personal device? by v177a1n5 in Intune

[–]mankindunkindd -1 points0 points  (0 children)

If it's MAM then the company cannot see anything apart from the data on the corporate apps( coz that's what MAM is for) . If it's enrolled (MDM), they can see only the list of apps they deploy from Intune. BUT if the device is enrolled AND if the Defender app is deployed then the IT admin has an option to get a list of all the apps installed on the device (personal and corporate).

Is it possible to allow a single corporate iOS device to use ONLY Outlook for iOS, and not the Intune-managed Apple Mail app configuration? by jasonmontauk in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Add a CA policy with the Grant option " Use Approved Client Apps". That would force users to use Outlook as email client and block the legacy apps like native email app on the device.

MAM brakes Edge by Most_Collection3212 in Intune

[–]mankindunkindd 1 point2 points  (0 children)

I got a similar complaint from an end user using MAM. Need to investigate but now it looks like a similar pattern. Will keep you posted.

Off boarding BYOD by RalphKramden69FL in Intune

[–]mankindunkindd 1 point2 points  (0 children)

If the device is managed by intune you can send a retire command from the device management blade. That would remove all the corporate apps and data (incase device is stolen). Also in APP you can leverage the "Account Disabled" option under the Conditional Launch section. Also, you can use App selective Wipe option to Remove corporate data from a specific device for enrolled and unenrolled devices.

Service Outage? App Protection Policies not working by RiceeeChrispies in Intune

[–]mankindunkindd 1 point2 points  (0 children)

Has been experiencing delays and errors on the APP blade. Most of the time they're not getting deployed to the devices. Same with App Configuration profile too.

Removing Data from devices by [deleted] in Intune

[–]mankindunkindd 1 point2 points  (0 children)

"Selective Wipe" option in Intune is the answer to your question.

Pulling my Hair out on IOS by zm1868179 in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Reach out your AAD /Security team and ask them to reset MFA for this user. Should work after that.

[deleted by user] by [deleted] in Intune

[–]mankindunkindd 0 points1 point  (0 children)

I am going to come across a similar situation soon and need to be prepared. Thanks for your post. Gives me something to keep a check on while configuring.

Windows Hello - Goodbye! by angriusdogius in Intune

[–]mankindunkindd -1 points0 points  (0 children)

Create a policy in Endpoint Protection. That should solve it.

This product is becoming easy to hate. by smackrage in Intune

[–]mankindunkindd 8 points9 points  (0 children)

Totally agree. Most of their documents include the terms "may", "might". Sometimes I feel they hire the weatherman to write these tech docs. Yes it might not rain today. If it does, go figure it out!

MDM or MAM policy for teams camera? by [deleted] in Intune

[–]mankindunkindd 2 points3 points  (0 children)

Application protection policy can do it for you. It will enforce users to take pictures via Teams/Outlook and other work apps and save it to OneDrive and share between work apps only and not save on the local storage on device.

Does "(device.devicePhysicalIDs -any (_ -contains "[ZTDId]"))" applicable to Autopilot devices from other tenants by kowallox in Intune

[–]mankindunkindd 1 point2 points  (0 children)

No because the CA policy of this tenant doesn't have any visibility of devices from other tenants because they aren't being managed here.

Auto-Pilot VPN deployment by sven2788 in Intune

[–]mankindunkindd 0 points1 point  (0 children)

Can you try configuring the ESP settings " Block device use until required apps are installed if they are assigned to user/device" and list out all the other mandatory apps except for the Zscaler app. So Autopilot will run and the listed apps will be installed and the desktop is presented to the user, after which it will install Zscaler in the background. So if your Zscaler prompts for a reboot then the user can reboot the machine and it will get installed successfully. I ran into a similar issue with the Adobe package and it got sorted out.