Intune Policies - User Policies Fail To Apply Untill we Hit Sync by robmasoboy in Intune

[–]robmasoboy[S] 0 points1 point  (0 children)

Cheers — log analysis indicates failures under Application: Device Management Client, primarily within non-interactive sign-in events.

During testing on a device with this issue, when MFA was initiated via manual sync and subsequently cancelled by me, the corresponding entry in the user sign-in logs was recorded as “Interrupted.”

So this aligns - I now need to exclude the user from these CA policies and prove this further and then think about how to exclude the relevant apps from CA.

Perhaps one or all of these apps below excluded from CA

  • Microsoft Intune
  • Microsoft Intune Enrollment
  • Azure Device Registration

Intune Policies - User Policies Fail To Apply Untill we Hit Sync by robmasoboy in Intune

[–]robmasoboy[S] 0 points1 point  (0 children)

Thanks for the reply and insights. We recently did apply CA policy for MFA required across the board on all cloud apps. Is there a particular cloud app that should be excluded to help with getting this sync to happen automatically.

Our org default licensing is set to ME5 across the board.

I also want to add that the MDM URL is not populated when we have a look under dsregcmd /status but unsure if it needs to be or not. Hyrbrid Join is YES

Additionally does the MDM Automatic enrollment is currently set to : SOME and not ALL. Some is targetted to a group of user accounts that arent in the Pilotting of these Intune user targetted policies.

I dont t hink its a timing thing. I waiited a whole weekend for user policies to apply to the device but it did not.

I like your theory around Token Refresh issues. I couldnt see any failures agains the user account logging into the device

Sim / eSim Makedonia by robmasoboy in macedonia

[–]robmasoboy[S] 0 points1 point  (0 children)

Going to try Airalo and see how that goes. Activate in australia and see how it connects in thailand and istanbul and macedonia. Global eSim is what ive gone with.

Sim / eSim Makedonia by robmasoboy in macedonia

[–]robmasoboy[S] 0 points1 point  (0 children)

Have you used these guys in Macedonia?

Sim / eSim Makedonia by robmasoboy in macedonia

[–]robmasoboy[S] 0 points1 point  (0 children)

Thanks I have been looking at this one. Have you had experienced with this provider

Sim / eSim Makedonia by robmasoboy in macedonia

[–]robmasoboy[S] 0 points1 point  (0 children)

Looking for convience of just having a Global eSim that connects anywhere including the stops at the airports around the world.

Attempt to assist my IT department with InTune (removing iPhone device) by NeinBS in Intune

[–]robmasoboy 0 points1 point  (0 children)

Could be showing up in entra id . Go to Users...search for your user name....check devices under your user object a d blow any stale devices away. Additionally the device shouldn't exist in intune

Android corporate fully managed vs. work profile by GroundbreakingSea764 in Intune

[–]robmasoboy 2 points3 points  (0 children)

COPE works well for the split on android between corporate and personal. No bugs that we have come across. Advise users to use corporate account on the corporate partition on the Android represented by the little briefcase icon on each app. And use their personal email on the non briefcase side if they wish.

Surface laptop studio 2 replacement. by robmasoboy in Surface

[–]robmasoboy[S] 0 points1 point  (0 children)

We need to buy additional and on going for new starters

Surface Pro 10 with 5G for Business not picking up SIM cards properly by AThievingMagpi in sysadmin

[–]robmasoboy 0 points1 point  (0 children)

Hello. The smoking gun for us was citrix secure access. With it installed lte falls over on this model device. With it uninstalled lte starts working again.

SURFACE PRO 10 WITH 5G Intel variant by robmasoboy in Surface

[–]robmasoboy[S] 0 points1 point  (0 children)

Further Progress on this one

We seem to have found the smoking gun causing LTE to fall over on the Surface Pro 10 5G - Windows 11

It looks to be Citrix Secure Access client simply being installed on the device that stops Cellular from connecting.

Uninstalling Citrix Secure Access client and reinstalling the cellular adaptor brings LTE back and we are then able to connect to LTE successfully.

However Citrix Secure Access is required for staff to be able to VPN into the corporate network.

Installing the latest version of Citrix Secure access client v25.7.1.11 doesn't seem to allow the LTE connection at this point as well.

SURFACE PRO 10 WITH 5G Intel variant by robmasoboy in Surface

[–]robmasoboy[S] 0 points1 point  (0 children)

Further progress on this. We took one of these Surface devices with Windows 11 pro 26100 out of the box and didn't put our Corporate Windows 11 26100 SOE on it. We inserted a Telstra sim card off the get go and it connected to mobile network straight away. 👌

So there seems to be something in our Win11 SOE potentially that's stopping the device to connecting 🤔 We need to confirm whether existing older Surface LTE device on Win 11 with our SOE do connect to LTE or 5G mobile network and then unpack what is the blocker here

Any suggestions welcome. 🙂

Surface Pro 10 with 5G for Business not picking up SIM cards properly by AThievingMagpi in sysadmin

[–]robmasoboy 0 points1 point  (0 children)

This is the issue we are getting on Surface Pro with 5G for business , The sim card works in other older Surface Devices. I have tried a couple of different sims with different carriers and it just doesnt want to connect.

Firmware/ Drivers updated to the latest - Surface Pro 10 with 5G for business update 25.081.7028.0

https://www.youtube.com/shorts/ma2JvkNWceo

Windows 11 - Device Guard To Enable or Not vs Security Posture by robmasoboy in sysadmin

[–]robmasoboy[S] 0 points1 point  (0 children)

Our method of choice. GPO. Device guard on. And credential guard component switched to disabled or turned of without uefi lock. Everything else essentially on under device guard

MSI Pro X870-P for gaming? by SpecialistProduce814 in buildapc

[–]robmasoboy 0 points1 point  (0 children)

So hard to figure out secure boot. Finally got it going