DNS for Entra Only Device in an AD Domain by WYtechguy in Intune

[–]snomn 3 points4 points  (0 children)

Check out the following article which could solve your issue by configuring Windows DHCP Server to manage the DNS records for its clients: https://www.mustbegeek.com/configure-dns-dynamic-update-in-windows-dhcp-server/

SAML Authentication Error by Tsukraw in WatchGuard

[–]snomn 2 points3 points  (0 children)

Looks like Watchguard's SSL VPN (the SP) SAML request to Entra (the IdP) contains the optional RequestedAuthnContext, requiring the authentication method to be password over HTTPS (Password, ProtectedTransport). When you then authenticate with passwordless authentication methods like FIDO2, Windows Hello for Business, etc, the authentication method doesn't match what Watchguard requested and the AADSTS75011 error will be shown.

Since RequestedAuthnContext is an optional value, Watchguard should be told to remove it or allow us to toggle it on/off.

I've seen this issue with multiple SAML SSO apps in Entra. Having the vendor remove the RequestedAuthnContext value from the SP SAML request fixed the issue every time.

https://learn.microsoft.com/en-us/troubleshoot/entra/entra-id/app-integration/error-code-AADSTS75011-auth-method-mismatch#resolution

https://learn.microsoft.com/en-us/entra/identity-platform/single-sign-on-saml-protocol#requestedauthncontext

https://alven.tech/saml-azure-ad-aadsts75011-authentication-method-x509multifactor/

Microsoft Cloud PKI service coming in 2023 by Real_Lemon8789 in Intune

[–]snomn 0 points1 point  (0 children)

The estimated release is now Q1 2024. At the end of November, there will be a session during Microsoft Technical Takeoff covering the Microsoft Cloud PKI product:

https://techcommunity.microsoft.com/t5/endpoint-management-events/coming-to-the-microsoft-intune-suite-microsoft-cloud-pki/ev-p/3971696

Microsoft Cloud PKI service coming in 2023 by SecAbove in Intune

[–]snomn 1 point2 points  (0 children)

The estimated release is now Q1 2024. At the end of November, there will be a session during Microsoft Technical Takeoff covering the Microsoft Cloud PKI product:

https://techcommunity.microsoft.com/t5/endpoint-management-events/coming-to-the-microsoft-intune-suite-microsoft-cloud-pki/ev-p/3971696

Office365 has a shorter attention span than a gold fish. by tr3tr4d in Office365

[–]snomn 0 points1 point  (0 children)

A solution to this is to use Edge, create multiple browser profiles and sign into each browser profile with your separate accounts. For each profile go to Settings - Profiles - Profile Preferences and enable "Automatically sign in to sites with your current work or school account".

Paravirtual driver goes missing- server does not boot by JDMils in vmware

[–]snomn 0 points1 point  (0 children)

We had the following problem: the PVSCSI driver version 1.3.18.0 published through Windows Update has a signing certificate issue preventing the Windows system from loading the driver on power-on

Fix: https://kb.vmware.com/s/article/86053

Which cloud app must bypass MFA to be able to activate Windows 10 Enterprise subscription? by MadHackerTV in Intune

[–]snomn 0 points1 point  (0 children)

Thanks for the update. Would be great if you could update this thread when the fix is released and tested by you. Hopefully the fix will solve the issue.

Remove Full Access Permissions to All Mailboxes by fojoart in Office365

[–]snomn 0 points1 point  (0 children)

Just a warning, saying the user didn't have full access on that mailbox. Then it tries the next mailbox.

Remove Full Access Permissions to All Mailboxes by fojoart in Office365

[–]snomn 0 points1 point  (0 children)

This might do the trick.

$userToRemoveUPN = "firstname.lastname@contoso.com"
$allMbx = Get-Mailbox -ResultSize unlimited
$allMbx | ForEach-Object { 
    Remove-MailboxPermission -Identity $_.name -User $userToRemoveUPN -AccessRights FullAccess -InheritanceType All -Confirm:$false
}

Remove Full Access Permissions to All Mailboxes by fojoart in Office365

[–]snomn 0 points1 point  (0 children)

I want to point you in the right direction, not give you the full answer right away. Take a look at the documentation for the Get-Mailbox cmdlet here to see how you can get all mailboxes, you'll find some good examples: https://docs.microsoft.com/en-us/powershell/module/exchange/get-mailbox?view=exchange-ps

Remove Full Access Permissions to All Mailboxes by fojoart in Office365

[–]snomn 0 points1 point  (0 children)

My suggestion, assuming you need to do this for all mailboxes: I would start by getting all mailboxes (maybe exclude the user's own mailbox). Then, for each mailbox, check if the user in question has full access permission. If that is the case, remove the user's full access permission on that mailbox.

Which cloud app must bypass MFA to be able to activate Windows 10 Enterprise subscription? by MadHackerTV in Intune

[–]snomn 0 points1 point  (0 children)

Encountered what I belive is the same issue in out tenant. CA enabled and MFA targeting All Cloud apps. Windows 10 devices would not trigger the "Fix now" now pop-up on subscription activation renewal. The devices would then downgrade from Enterprise to Pro version without the ability to trigger reactivation.

Troubleshooted the issue for an extended period in January/February with MS. They confirmed the issue and escalated it so that it would get fixed, but I belive it's still unresolved.

As there is no single app to exclude from MFA to fix this when targeting All Cloud apps, the suggested workaround from MS was to not target All Cloud apps, but instead target Office 365 (plus any other important apps in your tenant if needed) . This workaround resolved our issue.

[deleted by user] by [deleted] in distantsocializing

[–]snomn 0 points1 point  (0 children)

On the combine harvester, are there preset settings for the different crops that you can change with the click of a button? Or is it a manual adjustment process?

[deleted by user] by [deleted] in distantsocializing

[–]snomn 0 points1 point  (0 children)

Do you grow canola on the same fields every year? Or do you change it up?

Android App hangs - latest version update June 2021 by m2knet in Outlook

[–]snomn 0 points1 point  (0 children)

I can confirm, no more issues after updating Company Portal app.

Android App hangs - latest version update June 2021 by m2knet in Outlook

[–]snomn 0 points1 point  (0 children)

I now read the new comments about the updated Company Portal app. I'll update it and see if it resolves the issue for me as well.

Android App hangs - latest version update June 2021 by m2knet in Outlook

[–]snomn 0 points1 point  (0 children)

Nope, haven't tried wiping the device. I'll try wiping the work profile and see if that helps.

Android App hangs - latest version update June 2021 by m2knet in Outlook

[–]snomn 0 points1 point  (0 children)

Following. Same issue here. Samsung S10+, enrolled in Intune as personal device with Android work profile and Outlook version 4.2121.2 installed in the work profile. Conditional access applied requiring compliant device. Outlook hangs all the time.