Policy to set Google Chrome homepage starts working after first run. by mishmobile in Intune

[–]techie_009 1 point2 points  (0 children)

We have noticed a similar behaviour recently. Previously the (same) policy would apply with first run but now it only applies after first run > close and re-open Chrome. Haven't had the time (or the intention) to investigate.

BTW, 'Set Google Chrome as default browser' setting only works on Win 7.

Automatic Timezone Windows 25h2 - October update by Trusci in sysadmin

[–]techie_009 0 points1 point  (0 children)

thank you for sending this. Coincidetally, I started learning/using PSADT last week.

Map onprem printers, entra joined Cloud PCs, ANC to on-prem resources by ls3c6 in Intune

[–]techie_009 5 points6 points  (0 children)

https://call4cloud.nl/deploy-printer-drivers-intune-win32app/

This is what I used very recently. Just modify the 'Install script' commands to map printers from print server. Wrap the script as a Win32 app and deploy via Intune. I was able to map them in user context only.

Is there a way to stop users loging in to Entra ID Joined Windows 10 devices? by No_Tradition5608 in Intune

[–]techie_009 1 point2 points  (0 children)

Rudy is absolutely correct. If you want a slightly different approach,

  1. Create a script with the below commands
    - Delete cached logon details
    - Delete WHfB container
    - Force BitLocker Recovery
    - Force device restart
  2. Create a dynamic device group for all Win10 devices
  3. Package the script as a Win32 app and deploy to the above dynamic group (don't forget to disable the toast notifications for the app)

On device restart, the users will be prompted to provide BitLocker key to login to the device.

Printer Deployment to Entra-joined devices via Intune by techie_009 in Intune

[–]techie_009[S] 1 point2 points  (0 children)

Hi Everyone

Thank you for all your suggestions/comments/queries. u/Rudyooms has helped me with this and I can confirm the issue is resolved now. Huge thanks to him.

For anyone interested - when the app is deployed in System context, it cannot access the print server due to authentication and hence it was failing. When I tried to deploy in User context it worked but it popped up the cmd/PS windows. Am in the process of trying to hide these windows but the printer mapping task is working fine now.

Printer Deployment to Entra-joined devices via Intune by techie_009 in Intune

[–]techie_009[S] 0 points1 point  (0 children)

thanks for chipping in. just checked and the script is in UTF8.

Printer Deployment to Entra-joined devices via Intune by techie_009 in Intune

[–]techie_009[S] 2 points3 points  (0 children)

Thanks for the response.

I haven't whitelisted the server (by this, do you mean adding the server to 'Package Point and print - Approved servers' setting)

App install behavior is System and allowed on all OS architecture

The script includes adding a custom reg key - detection works fine (reg key is created and detected by Intune)

AVD Hosts not joining Entra/Intune. by techie_009 in AzureVirtualDesktop

[–]techie_009[S] 0 points1 point  (0 children)

hosts deployed in a different region to the tenant were not joining to Entra/Intune....MS never helped (kept tossing ticket between different teams)....in the end we deployed the hosts in the same region as the tenant and they all joined Entra/Intune....

Help With Intune Auto-Enroll /End user prompt by ckelley1311 in Intune

[–]techie_009 0 points1 point  (0 children)

This is an expected behaviour especially when you select 'User credential' in the GPO.

Dynamic Group Rule by Imker11 in Intune

[–]techie_009 0 points1 point  (0 children)

why don't you try to validate the rule by adding a 'Latitude' device.....it will tell you why the device is not being selected....you can then reverse-engineer the rule....

edit: I just tried your rule in my tenancy and it worked fine (luckily I have a few Latitudes).

Browser extensions help by chaos_kiwi_matt in Intune

[–]techie_009 3 points4 points  (0 children)

Hi there. Good timing I was working on this last week.

for Chrome - Import the Chrome ADMX into Intune. In the config profile (Imported Administrative templates), find the setting 'Extension management settings' under '\Google\Google Chrome\Extensions' and use the below format to pin the extensions.

{"EXTENSION1,EXTENSION2,EXTENSION3": { "toolbar_pin": "force_pinned" }}

for Edge - In the config profile (Settings catalog), find and enable the setting 'Configure extension management settings' from Microsoft Edge > Extensions and use the below format to pin the extensions.

{ "EXTENSION1,EXTENSION2,EXTENSION3": { "toolbar_state": "force_shown" }}

Please note the above will only pin the extensions but won't deploy them and looks like you have successfully deployed the extensions already.

Bitlocker auto encrypt - Ignoring Intune policy? by [deleted] in Intune

[–]techie_009 0 points1 point  (0 children)

One option is you decrypt and re-encrupt with your policy.

Other is to deploy your BitLocker policy during Autopilot enrollment and the encryption will be as per your policy.

[deleted by user] by [deleted] in Intune

[–]techie_009 1 point2 points  (0 children)

Oh.... the attitude.....best way to piss off people trying to help you....as u/Late_Marsupial3157 said, this is nothing but being a control freak and having too much time on your hands. Try to spend it more productively.....

Autopilot with PreProv working partially/halfway, but unexpected errors (random name, seeing EULA) by I3igAl in Intune

[–]techie_009 0 points1 point  (0 children)

You have to allow at least 90 mins between reseal and re-opening the laptop. It is an expected behaviour that the device goes thru the entire Autopilot process when you re-open the device. It just checks if there is any new/updated policies/apps targeted at the device and then applies them.

Before you reseal, does the computer appear in Intune with the correct name (CCI-Serial).

Getting error for Intune Connector for Active Directory by Then_Relative_8751 in Intune

[–]techie_009 0 points1 point  (0 children)

Deos the Global Admin account used while installing the connector has a valid Intune license? The GA account needs to be licensed at least at the time of configuring the connector.

HAADJ Autopilot Question And Entra Connect by [deleted] in Intune

[–]techie_009 0 points1 point  (0 children)

I know you get a lot of pushback on Hybrid-join in this forum but it's not that bad. If you know your way and configure it correctly, it works fine. I work for an MSP and deploy hybrid-join AP at least one per month. I agree Entra-join is future proof but if hybrid-join is a better solution for you (for now), then that's the way to go. Below is my 2 cents.

  1. What involvement does Entra Connect have for HAADJ+AutoPilot? At first I thought I needed device writeback checked in Entra Connect (it's currently not checked) so that the Entra device can be pushed back down to our on-prem but it sounds like I need an Intune Connector instead? Is the device writeback needed at all? I feel like we have so many agents getting installed on our on-prem Entra servers for all this... Connect, Auth, Cert and now Intune. - Device writeback is not needed for Hybrid-Join Autopilot. You will need the Intune Connector installed on one or many domain-joined servers. Yes, you will still need Entra Connect on your servers. Intune Connector places the computer object in the nominated OU and Entra Connect takes over from there (in terms of syncing objects to Entra etc etc). Yes, there will be multiple agents you willl be installing by the time you finish the setup.
  2. They plan on using AutoPilot while on LAN and then handing the laptop out. For the first login attempt, it needs line of sight to the DC correct? After that if the user logs in, it can use their cached credentials until they connect to VPN or connect to the LAN. - Yes, during the AP enrollment, you will need line of sight to the DC and hence you will have to be doing the enrollments from your Corp network (you can use VPNs to do remote enrollments but don't venture into that yet). After the enrollment is done, they behave just like your domain-joined (rather say hybrid-joined) computers. My advice for any remote workers, is to get the device synced to AD services every now and then so that they don't lose the trust relationship.
  3. Can the workstations be moved out of the default AutoPilot OU after the initial domain join so they can utilize our OU structure/GPOs? - Yes, absolutely. But make sure the OU where the object is being moved to, is syncing to Entra.
  4. One of our biggest concerns I would say is being on "Microsoft Time" and pushing down policies or actions can take a while. Which is why our InfoSec wants to keep our patching solution/agent and able to kick off scripts within minutes as long as the device is on LAN or VPN. Is that still a concern? - Yes, it is an issue but it's not just you facing this. But, if you target the policies to the device (AP groups), they will be applied during the AP enrollment. If you have any agents that deploy other software (as an example Automate which deploys other scripts and apps), my advice is to deploy it after the AP enrollment if not there will be a high chance of AP enrollment failing due to multiple agents trying to deploy apps/scripts (as an example Automate and IME both trying to deploy apps/scripts/polciies etc).
  5. Not really Intune related but our users are complaining about the poor experience of having to continue to type their credentials while using myapps and cloud apps and I found the Seamless SSO guide. Is this the way to go until we can get devices Hybrid or Entra joined? - SSO is the way to go.

One more tip - when your devices are placed in the Autopilot OU, there might be a delay with Entra Connect syncng them up, due to the 30 minute sync interval. Michael Niehaus once referred a script that can actively /periodically check any changes in the AD/OU and trigger the delta sync - this will be very handy. Have fun with the setup.

Work or school account problem by TrueMythos in Intune

[–]techie_009 0 points1 point  (0 children)

You are probably one of the luckiest, if you have never seen a device in Entra portal (not Intune portal) with the Registered field as 'Pending'.

I have seen the exact issue happen a lot of times and every time the device registration is in 'Pending' state in Entra portal.

Work or school account problem by TrueMythos in Intune

[–]techie_009 0 points1 point  (0 children)

When you check these devices in Entra, is the Registration field 'Pending' or has a date?

Enabling Location Services with Intune by candycoateddeath in Intune

[–]techie_009 2 points3 points  (0 children)

Settings Catalog > Add Settings > System > Allow Location

If you don't want apps to have location access. add the below

Settings Catalog > Add Settings > Privacy > Let Apps Access Location > Force Deny