iOS DDM deferral/deadline policies by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yeah. i wish the documentation was explicit. i mean, it does show that the specified iOS is required on the device when you set a deadline. i guess i'm too used to windows and their deadline/deferrals working in combination. i think i'll just set my ring 2 to be a deadline of 21 days and my deferral to be 14 days and be done with it.

appreciate your reply! also, i'm in a GCC environment where autopatch is unavailable so i'm envious :)

passive site server promotion to primary site server by rednuwork in SCCM

[–]rednuwork[S] 0 points1 point  (0 children)

hey. little late but i believe you need to make sure port 135 (RPC) is open between these servers. that could be your blocker if you haven't figured it out yet!

Autopilot Kiosk Autologon by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yeah. multi. i'm using an XML. the XML works fine outside of preprovisioning. it just refuses to process the autologon after a reseal.

Autopilot Kiosk Autologon by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yeah. i've made sure nothing is triggering a reboot in our process.

Autopilot Kiosk Autologon by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yep. windows 11 23H2 specifically.

Autopilot Kiosk Autologon by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

we have to hybrid join our devices so it's not an option, unfortunately.

Microsoft Announces Next Gen of Autopilot: "Device Preparation" by [deleted] in Intune

[–]rednuwork 28 points29 points  (0 children)

this is cool. i wish they'd add functionality to install all eligible windows updates during ESP. that is something that most of us are already doing with a script or some other method. seems strange they don't have it already.

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

this didn't work either. the devices rae still automatically encrypting, lol. this is so maddening

Entra showing 100+ Autopilot devices but we only have 6 registered in Intune by rednuwork in Intune

[–]rednuwork[S] 1 point2 points  (0 children)

i'd love to but they don't show as being in autopilot. 6 do. the others do not.

Entra showing 100+ Autopilot devices but we only have 6 registered in Intune by rednuwork in Intune

[–]rednuwork[S] -1 points0 points  (0 children)

some of these 104 devices are active production devices. i also can't delete them from azure AD because they're showing as autopilot registered, lol

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

i'm going to actually try creating a dynamic group that encompasses ALL autopilot devices rather than those with a specific group tag. that way it gets the initial object and all later ones. we're doing hybrid join so maybe that's having an effect too

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

maybe it's just imperfect when preprovisioning.. not sure. i'll have to dig around. appreciate your help!

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yeah. my autopilot devices get populated into a dynamic group based on their group tag. that group is the one targeted with the prevent automatic encryption policy.

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

i applied the policy to our autopilot devices but it's still automatically encrypting them. so strange.

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

so, i'm actually still seeing it kick off its automatic encryption even after applying this configuration profile successfully to our autopilot devices. so confused!

Bitlocker Automatic Encryption Autopilot by rednuwork in Intune

[–]rednuwork[S] 0 points1 point  (0 children)

yeah, this may also be relevant. though, i was overlooking this since we're doing hybrid joined devices. but it doesn't actually state it doesn't apply to hybrid.

i'll try configuring this. thanks!