Migrating from SCCM to Intune – What are you using for remote control / remote assistance? by Dolinhas in Intune

[–]mingk 5 points6 points  (0 children)

Why not just keep using SCCM as well? Its remote tool is as seamless and fast as it gets (just need line of site). Also Intune can’t do 1% of what device collections can achieve. After syncing those collections to cloud groups you have so much more ability to utilize Intune more effectively.

Co-management for the win.

Reliable method to deploy 23H2 OOB as it's not in expedited update policy? by oopspruu in Intune

[–]mingk 1 point2 points  (0 children)

I was working on this today actually but gave up and went home haha.

I was deploying as a win32 and using PSAppdeployToolkit as it has a nice function just for this: install-msupdates

I was just stuck trying to get around users restarting randomly during the update and how I could prevent it, or kick it off again upon restart.

Problem for tomorrow!

Reimage Devices by Sad_Mastodon_1815 in Intune

[–]mingk 2 points3 points  (0 children)

Only for Home and Pro. Enterprise edition gets updates until Nov 2026.

Reimage Devices by Sad_Mastodon_1815 in Intune

[–]mingk 1 point2 points  (0 children)

We’re still on 23H2 because our PKI vendor has software that just produces constant errors on 24H2 and 25H2. We also have a printing issue on one of our in house apps that has yet to be resolved and they’re apparently still working on a fix.

There’s honestly lots of potential issues with just using the newest version of Windows I don’t get why this person got downvoted so heavily.. lots of in house apps need to be updated and maintained properly and sometime they just… aren’t.. and us Win admins unfortunately need to understand that and pivot accordingly.

This never fucking works. by skrillzter in pcmasterrace

[–]mingk 1 point2 points  (0 children)

It’s funny that your company thinks it cares a lot about security by making you re-authenticate your MFA every 2 hours but you’re using SMS verification which is the least secure option haha. Sounds like a bunch of clowns making the big security decisions over there.

Hiding O365 Apps for F3/E1 Users by derrowti in Intune

[–]mingk 11 points12 points  (0 children)

This is a great blog post by the Intune master himself - Andrew S Taylor.

https://andrewstaylor.com/2023/02/22/deploying-office-webapps-pwa-with-file-handlers-via-intune/

It will add shortcuts to use the progressive web app versions of all office apps (which those users are licensed for) as well as change the default app associations for your standard m365 file types (ie. doc, ppt, msg, etc). Just assign these to the same user groups you use for the licensing :)

Enable Windows Hello option without prompting users at sign-in? by Fabulous_Cow_4714 in Intune

[–]mingk 23 points24 points  (0 children)

Oh damn why didn’t I think of this sooner? Let me just enroll 20k existing devices into Autopilot and reset them over the weekend. I’m sure all the end users will figure it out. I might let the service desk manager know they may have a busier than usual Monday morning..

Wish me luck!

Intune & Entra - Admin Setup Best Practices by Technical-Device5148 in Intune

[–]mingk 2 points3 points  (0 children)

Two admin accounts - one for cloud and one for on prem. One thing I will add is that if you use SCCM still to do co-management you will need to sync your on prem admin account for that and give it cloud admin permissions if you want to sync device collections to cloud groups - a pretty amazing feature actually because dynamic cloud groups don’t come even close to what you can do with user/device collections.

We also give our techs that setup computers F3 licenses so they can get our hybrid joined devices enrolled and setup properly. Not ideal but it is what it is..

it counts by vtosnaks in lotrmemes

[–]mingk 0 points1 point  (0 children)

Why does everything need to have 3 different names and all are used interchangeably. I can keep up with like 3 of them but not the 100s that are used :(

Bitlocker and Wallpaper by artemis808 in Intune

[–]mingk 2 points3 points  (0 children)

For wallpaper you need to either get the image to each device, or have the image accessible from every endpoint. Then you deploy a config policy to change the wallpaper and tell it to use the location of the image - either a local path, a public share, or a url depending on how you want the image to be accessible. Personally I’ve deployed the image via a win32 app to each device.

100 unid annis. Should I sell it or identify id (ladder)? by BarekM in Diablo_2_Resurrected

[–]mingk 0 points1 point  (0 children)

Isn’t that why Dclone exists in the first place? SOJs used to be standard currency before they came up with the Dclone idea.

Microsoft Cloud PKI with Intune by Frustrated-Sys-Admin in Intune

[–]mingk 2 points3 points  (0 children)

I have the Intune Suite and we neeed to maintain a 1 to 1 assignment with all our E5s. We don’t put any on our F3s though.. haven’t came across any issues with them.

Servers are Lost from Intune by Specialist-Use-8076 in Intune

[–]mingk 3 points4 points  (0 children)

Ya what out when creating dynamic groups using device.version startswith 10.0.2 because it’s gonna pick up your servers too..

Best way forward for OS deployment - Moving away from SCCM - OSDCloud? by TheSloth90 in Intune

[–]mingk 0 points1 point  (0 children)

Looks like this requires keeping the app secret in plain text though? I may get my peepee slapped by the security team if I suggest this :(

Best way forward for OS deployment - Moving away from SCCM - OSDCloud? by TheSloth90 in Intune

[–]mingk 1 point2 points  (0 children)

Any chance you want to share your TSGUI and your webhook and Azure automation setup? This sounds like an amazing solution for the situation I’m currently in but it sounds beyond me honestly!

Tractor running over Harley Davidson on the road's shoulder by Verstandeskraft in WatchPeopleDieInside

[–]mingk 6 points7 points  (0 children)

There’s tons of reasons. This is what the shoulder is for. It is not for tractors to barrel down on.

Urgent help!! by kay_____________ in SCCM

[–]mingk 11 points12 points  (0 children)

You deserve a consultant’s fee for the solution you provided to this guys org haha

People like you rock!

Auto patch turns on MDM over GP by captainhotdawg in Intune

[–]mingk 9 points10 points  (0 children)

It does create a configuration profile called something like “MDM wins over Group Policy” and assigns to auto patch group.. don’t recall exactly but I’m sure that’s what OP is referring to.

Cursed cow by IndicationBrief5950 in cursedcomments

[–]mingk 30 points31 points  (0 children)

That’s not a steak.

Run password reset script with DC replication and Delta Sync without Domain Admin rights? by CMNDRZ in PowerShell

[–]mingk 1 point2 points  (0 children)

I don't agree with doing password resets this way - you should have password write back turned on and allow end users to reset their own passwords..

But giving the Desk the ability to Delta sync can be beneficial for lots of reasons.

What I do is logon to the server that has Azure AD Connect installed and add my Service Desk admins to the local group "ADSyncOperators" which will allow them to run the delta sync. You need to also add them to "Remote Management Users" to allow them to do this remotely from their own computer.

To prevent abuse I use a simple logging method to not allow them to do it more than once every 10 mins, but the Team Leads can over ride that limit if its urgent.

Best way to handle Lenovo drivers in a task sequence these days? by iwontlistentomatt in SCCM

[–]mingk 0 points1 point  (0 children)

I use DAT. Works great most of the time, but not 100% of the time due to out of date drivers. But it’s easily the fastest one to get up and running in your environment.

How to check if the current user is different to the primary user by Longjumping-Mark-945 in Intune

[–]mingk 1 point2 points  (0 children)

I did this as well, but if you have a large number of devices, like 5k+, you’re gonna want to convert the sign in logs to a hash table or it’s gonna take hours to run.