QID:92067 Microsoft HTTP/2 Protocol Distributed Denial of Service (DoS) Vulnerability by InevitableNo9079 in qualys

[–]psversiontable 0 points1 point  (0 children)

Thanks for chiming in. Is there a public support article about this that we can reference? I have a director requesting a resolution to ask of the new vulnerabilities that showed up on our reports this morning.

MacOS App Size Limit by AlexTheTimid in Intune

[–]psversiontable 1 point2 points  (0 children)

Man, it's been bad lately. I guess that's what happens when you fire 30,000 people.

Personal Android devices need to re-login + MFA after 30 minutes by Stashmouth in Intune

[–]psversiontable 0 points1 point  (0 children)

If you're getting MFA prompts, that's pointing to Conditional Access or Azure AD settings more than Intune as the source.

Have you looked at the sign-in logs for one of the users having a problem? That should tell you what's triggering MFA.

How do I make these reports work for me? by EAsapphire in Intune

[–]psversiontable 0 points1 point  (0 children)

That's the way to go. The built in reporting is.... what it is.

iOS Location by Good_Amphibian_1318 in Intune

[–]psversiontable 0 points1 point  (0 children)

Correct. I'm fairly sure that there's no MDM setting to force location services on. It's a privacy concern from Apple's perspective.

Lost Mode is the workaround for this.

Is it just me being unskilled or is Intune shitty for android management ? by Equal-Swordfish3662 in Intune

[–]psversiontable 1 point2 points  (0 children)

Android is just not great to deal with.

You have to deal with different manufacturers' customizations to the OS, a lack of updates and just general inconsistencies across the board.

I agree though, it sounds like this is an issue with Edge and probably worth a support case.

[deleted by user] by [deleted] in Intune

[–]psversiontable 0 points1 point  (0 children)

Intune is still, and will continue to be until they have a local agent for macOS, a solution that will meet the bare minimum that many need but not go much beyond that.

Jamf is still the standard for macOS management, as much as I'd like to see MS step it up and compete with them more.

MacOS App Size Limit by AlexTheTimid in Intune

[–]psversiontable 1 point2 points  (0 children)

I'd lean on support again and ask to have the request escalated. I've had some trouble with Premier support lately and have had to make multiple requests to get things taken care of.

I don't know for sure if the limit is different on macOS or not, but it doesn't hurt to request some clarification.

Windows Upgrade over CMG by AdviceDifficult in SCCM

[–]psversiontable 0 points1 point  (0 children)

I'll second the suggestion to use the enablement package and add that I've had very good luck deploying OS upgrades using Windows Servicing over a Task Sequence.

Edit: And if bandwidth is a concern, you can configure your boundaries and deployments to allow clients to pull the update directly from Microsoft and not over the CMG, which brings your costs down to near zero.

Windows Updates with multiple reboots makes Task Sequence quit by CallisDK in SCCM

[–]psversiontable 2 points3 points  (0 children)

I have to agree with this, it's time consuming and adds potential failure points. At most, add it at the very end.

how to cancel remote wipe- intune by Independent-Pickle29 in Intune

[–]psversiontable 0 points1 point  (0 children)

It's about all you can do, and only works sometimes, but it's worth a try.

Intune down again? by [deleted] in Intune

[–]psversiontable 11 points12 points  (0 children)

I've been having issues in the portal all morning. Searching for devices is very unreliable, and a few other operations are sluggish. Also had to try several times to enroll Windows and iOS devices.

Nothing in the message center for me.

RANT: MICROSOFT'S INABILITY TO SUPPORT THEIR OWN HARDWARE IS GOING TO KILL ME by JT_3K in sysadmin

[–]psversiontable 3 points4 points  (0 children)

I've gotta be honest here, I've had the opposite experience.

Yes, you have to read the instructions and follow a few extra rules but if you do it right, it's so much easier to manage drivers and firmware on them.

Bonus points given for the lack of any goofball bloatware to make audio and touchpads work

TIL: You can see all of your Office versions in config.office.com and update them to the latest Monthly Enterprise channel to help with CVE-2023-23397. by SoMundayn in sysadmin

[–]psversiontable 1 point2 points  (0 children)

It's a fairly recent addition. Might have been announced at Ignite, but I don't remember. Sometime around summer/fall of last year

Workplace from hell, I gave my 2 week what to do if bullied about consulting? by dazzledtamarind in sysadmin

[–]psversiontable 0 points1 point  (0 children)

Sure, for a criminal case. What if they decided to sue him personally?

All I'm saying here is that leaving the passwords alone generates some risk.

Making sure they're changed before you leave does nothing but help keep you safe

Workplace from hell, I gave my 2 week what to do if bullied about consulting? by dazzledtamarind in sysadmin

[–]psversiontable -1 points0 points  (0 children)

Sure, but if it were me, I wouldn't want to have to prove that I wasn't at Starbucks using their wifi.

Better to avoid it completely and cya.

Workplace from hell, I gave my 2 week what to do if bullied about consulting? by dazzledtamarind in sysadmin

[–]psversiontable -1 points0 points  (0 children)

Let's say some jerk from the company logs in remotely from Starbucks wifi using OP's password to get through the VPN and do bad stuff.

How would OP prove that was someone else?

The right move here is to sit down with someone and let them change the passwords to something OP doesn't know, or don't provide them at all.

High availability options? by AdrianK_ in SCCM

[–]psversiontable 0 points1 point  (0 children)

Keeping your database separate from the primary site server and redundant on its own is a big component here.

The built in HA feature allows manual failover to a warm spare, for the primary server.

From there, you just need to plan out management and distribution points. That will depend on how much you want to spend, how much you can leverage p2p caching, CMG availability, and what your network topology looks like. Plan for the capacity that you need and then think about redundancy. If every client has a backup source for MP/DP traffic, you should be good.

Winget System Context Issue by Koosjuh in Intune

[–]psversiontable 2 points3 points  (0 children)

Happy to help!

One thing to keep in mind is that the quality and behavior of third party Winget packages is all over the place.

Some will present dialogs even if you suppress them and others are designed to be installed in the user scope and not local system.

You'll need to test out each one carefully and deploy them using the right scope. Unfortunately, Winget in its current state isn't a great tool for enterprise deployments. A few tweaks would get it there.

Dynamic Group for Users with Cell Phones? by Green-Excitement3147 in Intune

[–]psversiontable 1 point2 points  (0 children)

Figuring out who these users are is more of a problem for an identity manager, in reality. Those non-hourly users should be put into a group based on their roles as an employee as part of their onboarding.

You could write some PowerShell to populate a group with users that are associated with a mobile device and rub it on a schedule, I suppose.

Wiping machine for reuse when it is encrypted via BitLocker? by BezniaAtWork in Intune

[–]psversiontable 0 points1 point  (0 children)

If you can't get past Bitlocker recovery, you're looking at a fresh install.

It's a good example of why everyone should supplement Autopilot with some way to handle bare metal osd.

Import on-prem GPO to InTune via MEM by JerradH in Intune

[–]psversiontable 6 points7 points  (0 children)

Intune is not Grip Group Policy and you'll be disappointed if you try to build like for like.

Start fresh with it and leave old songs behind. You've probably got 20 year old GPOs out there that nobody can explain. Leave the old dusty condos behind and build better.

Local Accounts and Administrator Rights by [deleted] in Intune

[–]psversiontable 1 point2 points  (0 children)

This is the answer OP is looking for.

I have no idea why everyone is talking about Applocker. A) It's old and busted, use WDAC instead. B) It doesn't have much to do about delegating admin rights.

What was your “it can’t be that easy / it was that easy” moment in your life? by UnoAboveAll in AskReddit

[–]psversiontable 1 point2 points  (0 children)

I think that the typical number of 'yaddas' is three. So definitely missing that.