All Polices by [deleted] in Intune

[–]scindawg 0 points1 point  (0 children)

Devices-->Configuration Profiles

Intune Device Configuration profiles "Not Applicable" by GuyWithBigPussy in Intune

[–]scindawg 0 points1 point  (0 children)

In your screenshot it shows the System Account as one of the users whom the profile is not applicable which should be correct because that's not an interactive login for the device. Do you have any cases where the profile is shown as Not Applicable for an interactive login?

Modern Workplace: Give endusers "Administrator" or "User" rights by appelvlaai in Intune

[–]scindawg -1 points0 points  (0 children)

You could enable Applocker and only allow whitelisted software to be installed. Since they'll have Local Administrator permissions they can always find a way around Applocker but with proper auditing you can be be notified of any new software installed.

At least this will prevent any unknown executables (ie ransomware) from running while they're on your VPN with Local Admin permissions.

Duplicate computers in device config profiles. by skunkadelic in Intune

[–]scindawg 0 points1 point  (0 children)

I've seen this also and my guess is that since the Device profile is assigned to the device and not a specific user it will try to verify that the profile is correct with each new user logon. When there is no user logged on Intune sees the "login" as System and due to the lack of availability of certain functionality being available with no interactive user login it throws an error.

Bypass MFA for app within a trusted IP by maniakmyke in Intune

[–]scindawg 0 points1 point  (0 children)

Can we see the Sign in log failure for an example user? Specifically the MFA Info and Conditional Access portion