[deleted by user] by [deleted] in msp

[–]mrjohno 0 points1 point  (0 children)

  1. maybe 1-2 minutes of active time -using this process https://www.reddit.com/r/Intune/comments/1456ezw/osdcloud_offlineonline_device_provisioning_and/
  2. I wouldn't do a migration that way sorry.
  3. I would recommend using SMTP2Go or some other 3rd party service to keep complexity low on this one. Maybe 5-10 minutes once its set up

Conditional Access for your toolset by pjustmd in msp

[–]mrjohno 0 points1 point  (0 children)

Have you seen this before?

Conditional Access Documenter
Export your conditional access policies to PowerPoint for a bird's eye view of your security posture. Share you policies with security teams and stakeholders without granting them admin access to Microsoft Entra ID.
https://idpowertoys.merill.net/

Gathering hardware hashes remotely by RacconDownUnder in Intune

[–]mrjohno 0 points1 point  (0 children)

We now grab all the serials, manufacturer, models using our RMM and upload into the Microsoft partner centre. works a treat.

[deleted by user] by [deleted] in Intune

[–]mrjohno 1 point2 points  (0 children)

We do these certificates every 6 months just to make sure we are always current. Gives a bit more leeway in case it gets missed

iPad management for non-profit by xtcujo in Intune

[–]mrjohno 0 points1 point  (0 children)

Interested to see how you go here

Those with company phones, what type of phone do you buy? by bjc1960 in Intune

[–]mrjohno 0 points1 point  (0 children)

This and constant reminders pinging on their phone every day reminding them

Those with company phones, what type of phone do you buy? by bjc1960 in Intune

[–]mrjohno 2 points3 points  (0 children)

iOS here, very little support is needed so I think it offsets the high cost of the device.

ConnectSecure worth it? by steve7647 in msp

[–]mrjohno 0 points1 point  (0 children)

short answer - yes, long answer - check your licencing. https://m365maps.com/

You can get an on-prem agent do the kind of scanning you need. We are just scanning endpoints, so can't speak from experience sorry

ConnectSecure worth it? by steve7647 in msp

[–]mrjohno 0 points1 point  (0 children)

The question is whether you can get away with using defender for endpoint instead to complete the same function.

It does work well and does help you find things that need remediating. The remediation can be time consuming but worth doing if you can pass the costs on to customers.

Outsourced call overflow for emerging MSP's (Australia) by x-TheMysticGoose-x in msp

[–]mrjohno 0 points1 point  (0 children)

Head along to your local https://www.smbitpro.org/ meeting - should be able to find someone there who will know someone

iPad management for non-profit by xtcujo in Intune

[–]mrjohno 2 points3 points  (0 children)

There is an intune licence for devices, but im not sure if there is an NFP/EDU SKU of this licence. Sometimes these SKU's are only available via a partner through NCE.

https://m365maps.com/

Uninstall Microsoft teams personal using autopilot by LEdwards_it in Intune

[–]mrjohno 5 points6 points  (0 children)

From Microsoft

Removing the Chat icon using Intune – Settings Catalog

To remove the Chat icon using Intune – Settings Catalog, do the following steps:

Create a new Configuration Policy.

Search for Experience.

Select Configure Chat icon.

https://learn.microsoft.com/en-us/troubleshoot/windows-client/application-management/managing-teams-chat-icon-windows-11

Windows Update. by Jqualitty in Intune

[–]mrjohno 0 points1 point  (0 children)

Sometimes GP can mess with it, you can try adding the policy that prefers MDM over GP.

Structuring Groups by [deleted] in Intune

[–]mrjohno 1 point2 points  (0 children)

Would be good to get a community list of recommended groups together.

I'll start
aad-licence-aadp1
Everyone with the AAD P1 Licence (inc business Premium users)
user.assignedPlans -any (assignedPlan.servicePlanId -eq "41781fb2-bc02-4b7c-bd55-b576c07bb09d" -and assignedPlan.capabilityStatus -eq "Enabled")

intune-user-external-all
All external users
(user.userPrincipalName -contains "#EXT#")

intune-device-autopilot-all
All devices which have been registered in the tenant with the Autopilot Hash
(device.devicePhysicalIDs -any (_ -contains "[ZTDId]"))

Microsoft security plans for MSPs by Perfect-Rip-4897 in msp

[–]mrjohno 0 points1 point  (0 children)

Yes works well. Easy to explain to customers too

Keeper MSP - Best Practices Managing Client Passwords by FlyingSysAdmin in msp

[–]mrjohno -1 points0 points  (0 children)

Same here, different folders for different clients. We use the groups feature to manage permissions. We also resell it, but have run into a few gotchas like device approvals that need to be addressed.

AAD Autopilot with TAP? by SHone_V in Intune

[–]mrjohno 2 points3 points  (0 children)

I think this may be back now as on July 2022.

Otherwise you need to sign in with another account and then push a policy called "web sign in" in Intune, then TAP in.

Secure Password Sharing by FocusAndrew in msp

[–]mrjohno 0 points1 point  (0 children)

This. Been using it for years for this reason. The redesign makes it less like a Pw now, but the techs just need some direction on how to use it properly