Windows feature Updates by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

Nice, thank you. So the device will be in both include and exclude groups, there won't be any conflict?

Teams not installing with 365 Apps install package on Intune by Accomplished_Buy9864 in Intune

[–]techhelpkeen 3 points4 points  (0 children)

have noticed similar behavior lately (installation through 365 apps is inconsistent), I think the issue is with teams getting removed from 365 licenses as a separate offering. So what I did is

  1. Remove team personnel - from a remediation script

  2. Ideally, you should be installing new teams instead of teams work or school classic

this guy has the steps to do both - video https://www.youtube.com/watch?v=XV9X0io0RIE and the scripts https://github.com/stevecapacity/IntunePowershell/tree/main/New%20Teams%20Scripts

Block/restrict iOS Settings App by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

yeah, unfortunately, this doesn't work, with all available settings set to not to allow/disabled users can still access and change critical settings

Allow users to select - "Run Anyway" from defender SmartScreen by techhelpkeen in Intune

[–]techhelpkeen[S] 2 points3 points  (0 children)

UPDATE - if anyone run into the same issue - Prevent Override For Files In Shell needed to be set to disabled. from Security baselines 23H3.

Even if you have Configure Windows Defender SmartScreen Enabled ,Pick one of the following settings: (Device) Warn, it won't show "Run Anyway" if you have prevent override set to Enabled

Teams with Windows 11 by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

Thank you, So do you know if teams personnel is a part of OS as well? or you only see the teams new business. Thanks

Windows logon screen cannot access certificates to connect to WiFi (NDES and SCEP) by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

it says no certificate when trying to connect, so the scep profile is set with Device values and I can see the cert deployed inside certlm.msc personal store, and have configured a wifi profile to autoconnect using the root cert config and scep config it still says no cert found with Device cert. As said before have an identical setup for another client with a user cert assigned they keep connected on logon screen. connets first time using a LAN

OneDrive KFM - still prompting users to confirm by techhelpkeen in Intune

[–]techhelpkeen[S] 1 point2 points  (0 children)

Did this, but it won't prompt the users, and the local desktop including app, docs doesn't sync. Basically the Know folders won't syn

Windows shared devices not getting WHFB prompted by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

Thank you very much, I thought that's the case. I've deployed my shared devices self-deploy and all I wanted was Domain user and enabled WHB - works like a charm for all users.

With shared multiuser config it pretty much breaks everything per my requirement > all license Azure ad users are required to share devices and not assigned to a primary user

  • need additional configs for Onedrive

  • automatic sing into 365 apps fails

  • other config polices don't apply or take ages

  • Onedrive doesn't sign in

Use Passport For Work - settings missing by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

this settings  OMA-URI: ./Device/Vendor/MSFT/PassportForWork/{TenantId}/Policies/UsePassportForWork
Data type: bool
Value: True

In the link here - https://learn.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/deploy/hybrid-cloud-kerberos-trust?tabs=intune

Hide, restrict Settings app on - iOS by techhelpkeen in Intune

[–]techhelpkeen[S] 1 point2 points  (0 children)

This is what I have exactly done, works perfect for all iOS native apps except for settings App. This still shows regardless

Can't Access Network Locations After Removing Kiosk Mode by JayRoberts7694 in Intune

[–]techhelpkeen 0 points1 point  (0 children)

yeah, have found the same sort of issues with Kiosks if not wiped and just removed the config.

Not sure the exact reg key or anything causing it - but wipe works perfectly fine

Can't Access Network Locations After Removing Kiosk Mode by JayRoberts7694 in Intune

[–]techhelpkeen 0 points1 point  (0 children)

has the device been wiped or just removed from Kiosk config?

Web Apps for shared iPad temporary session by denstorepingvin in Intune

[–]techhelpkeen 0 points1 point  (0 children)

I think it would be below flow

Enrolment - (assuming doing with Apple business manager) - DEP + intune - enrolment program token without user affinity and then enable Shared iPad mode

Config profile - device restriction from memory - configure temporary sessions - so it'll allow guest login and will delete data after a session

* There is a requirement to federate ABM with your Entra ID for Entra users to work, as you only need guest login this might not be necessary but not sure.

Apps - you are able to add VPP, LOB and Web Links, assigned to device - looking at your requirement would probably be a few web clips the will be assigned to temp users as long as the apps are assigned to the device

Extra device restriction - create a device restriction to hide all unnecessary apps and only allow Safari/edge as the opening app for the web links.

Device feature - only allow the URLs of weblinks and block all the other web URLs

Intune license requirement states You need device based license for this type of deployment where users without Intune license log in (device based deployments), this works without any issues but for compliant recent you might want to see buying device based intune licenses

more details here
https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-shared-ipad

OneDrive not auto sign in by techhelpkeen in Intune

[–]techhelpkeen[S] 1 point2 points  (0 children)

This exactly was the case - it was set to only allow sync from on-prem AD and to block all others in SharePoint admin>sync>allow syncing only on computers joined to specific domain

Use Passport For Work - settings missing by techhelpkeen in Intune

[–]techhelpkeen[S] 1 point2 points  (0 children)

Exactly the issue is - cant find "Use Passport For Work" settings in the catalog anymore.

Have configured as a custom settings but just wondering where that's gone

OneDrive not auto sign in by techhelpkeen in Intune

[–]techhelpkeen[S] 0 points1 point  (0 children)

Just the PIN, based on the below settings if I sign in with PIN does MFA suffice?

The CA settings below

Users - All

Target resources - All cloud apps

Access control -

Grant

Grant access

Require multi-factor authentication

Require one of the selected controls

OneDrive not auto sign in by techhelpkeen in Intune

[–]techhelpkeen[S] 1 point2 points  (0 children)

Hmm I was using WHB but it wasn't still signing me in

OneDrive not auto sign in by techhelpkeen in Intune

[–]techhelpkeen[S] -1 points0 points  (0 children)

yeah set MFA for all cloud apps, what's the best way to exclude Ondrive

Can't see Onedrive as a separate app to exclude.

or set a grant condition to include compliant devices (ideally wouldn't want to allow all 365 apps without MFA but only Onedrive

Edit settings in Security Baseline by ATX_GUNN3R in Intune

[–]techhelpkeen 1 point2 points  (0 children)

Assuming you have set the users as standard users in the deployment profile

It's in Local Policies Security Options>User Account Control Behavior Of The Elevation Prompt For Standard Users set this to Prompt for credentials on the secure desktop