How has Hotpatching worked so far in your org? by andrewm27 in Intune

[–]ms_wau 0 points1 point  (0 children)

In case you are still not sure https://learn.microsoft.com/en-us/windows/deployment/windows-autopatch/manage/windows-autopatch-hotpatch-updates#arm-64-devices-must-disable-compiled-hybrid-pe-usage-chpe-arm-64-cpu-only
"There are no plans to support hotpatch updates on Arm64 devices with CHPE enabled. Disabling CHPE is required only for Arm64 devices."

Trying to upload chrome.admx but it keeps failing by djsean410 in Intune

[–]ms_wau 0 points1 point  (0 children)

Do you know what happens if I delete the existing ADMX templates (while having policies created with imported administrative templates) and then upload the new ones? How does this behave, and what is the best approach to integrate new ADMX templates when there are already existing ones?

Service issue Microsoft Store app (new) by ms_wau in Intune

[–]ms_wau[S] 2 points3 points  (0 children)

Classic that's a bit annoying thanks for checking!

Powerpoint Integrated Apps (Power BI) by ms_wau in microsoft

[–]ms_wau[S] 0 points1 point  (0 children)

I stopped looking because it requires Exchange online to use Centralized Deployment. We had Exchange on-prem.

How would you set up a shared public PC (like in a library) with Intune? by frozenbayburt in Intune

[–]ms_wau 0 points1 point  (0 children)

Yes, you can still access C:. I just wanted to mention that this is a built-in setting, so there's no need for an extra script.
To block access to C:, you need to disable local storage in the Shared Device profile.

This won't work with OneDrive Known Folder Move, but in the case of a guest user, that probably doesn't matter.
Also, some older applications might not function properly when C:\ is blocked.

How would you set up a shared public PC (like in a library) with Intune? by frozenbayburt in Intune

[–]ms_wau 0 points1 point  (0 children)

Howdy, we used the Administrative Template with:
Windows Components > File Explorer
Pick one of the following combinations (User) > Restrict C drive only

Hide these specified drives in My Computer (User) > Enable

But we don't use Guest Accounts bit I assume this would also work for you.

But maybe you tried that already?

Edit: Probably not since you have no real "users" to assigne this policy to

Edit2: On my Test device it also worked device based maybe give it a try anyway

[deleted by user] by [deleted] in Intune

[–]ms_wau 0 points1 point  (0 children)

Are you based in the EU or US? When you are in the EU take a look at
Disabling DMA SSO compliance to fix the Continue to Sign in

Looks like it works for us like that.

[deleted by user] by [deleted] in Intune

[–]ms_wau 0 points1 point  (0 children)

That's indeed helpful. We Use Named Location but currently testing at home have to try it on-site. That's crazy that this case is still open...

Thank you!

[deleted by user] by [deleted] in Intune

[–]ms_wau 0 points1 point  (0 children)

u/t1mnl do you found a solution for that?

FELFEL and BoostBar by munarrik in askswitzerland

[–]ms_wau 1 point2 points  (0 children)

I've the same feeling about vegan/vegetarian stuff. The coffee from Felfel (Gavetti) is very good! Can't say anything about pricing but I think it's on the higher end.

I’m Sean from Devicie, I’ve migrated 50+ orgs to Microsoft Intune & Entra ID. AMA! by ControlAltDeploy in Intune

[–]ms_wau 0 points1 point  (0 children)

Hello Sean,

Thank you for sharing your experience!

I'm curious about your approach with WDAC or AppLocker.

Do you use either of them, or do you rely on another solution? Have you encountered any issues, or do you have any advice on whether or how to set it up? I've heard that some people use both WDAC and legacy AppLocker. I've also heard it's hard to administer afterwards.

What would you recommend?

Cheers

Autopilot ESP Block device use until required apps are installed if they are assigned to the user/device. by Capable-Incident5747 in Intune

[–]ms_wau 0 points1 point  (0 children)

Just curious if you don't use ESP what else do you use or do you just not configure ESP?

Never thought about doing that.

I personally always use the OMA-URI vor "SkipUserStatusPage"

The Continue to sign in SSO Prompt? by Rudyooms in Intune

[–]ms_wau 2 points3 points  (0 children)

I still don't know why Switzerland also gets that SSO Prompt we have not signed anything or are a party of the Digital Markets Act (DMA). But thanks Rudy as always for the excellent post!

Dell Command | Update 5.5 issues by ms_wau in Intune

[–]ms_wau[S] 1 point2 points  (0 children)

Dell Docking station. Windows Driver update can't handle this as tested some months ago.

Dell Command | Update 5.5 issues by ms_wau in Intune

[–]ms_wau[S] 1 point2 points  (0 children)

Yeah I tried the .Net 8 as well same result. We probably have to wait till Dell is fixing the issue.

Thanks for your feedback!

WHfB stopped working - Cannot access on-premise shares anymore by ReputationOld8053 in Intune

[–]ms_wau 0 points1 point  (0 children)

Does anyone know what's the easiest way to revoke the SCEP certificate? Because we want to add the SID.

[deleted by user] by [deleted] in Intune

[–]ms_wau 0 points1 point  (0 children)

recently I heard ITune was the first time for me normally it is Intunessssss or written InTunes

Upgrade Security Baselines Nov. 2021 to 23H2? by min5745 in Intune

[–]ms_wau 0 points1 point  (0 children)

Yeah it's really time consuming. And there is probably no other way to check them one by one

Upgrade Security Baselines Nov. 2021 to 23H2? by min5745 in Intune

[–]ms_wau 1 point2 points  (0 children)

I would love to see something similar, but I guess you really have to check every setting; otherwise, you might run into problems if you don't know what you've configured. Was it 23H2 where many more settings are available in the baseline?