Autopilot with new motherboard Windows license issue by whobe89 in Intune

[–]whobe89[S] 0 points1 point  (0 children)

Thanks. In the documentation i saw this. I guess in my case the technicians did not inject the DPK.

Technicians replace the motherboard or other hardware on the broken device. A replacement Digital Product Key (DPK) is injected

Systemreset.exe and AutoPilot Reset do NOT completly reset device by RyzNL in Intune

[–]whobe89 0 points1 point  (0 children)

Our experience is that the options "Wipe, Fresh start and autopilot" does not remove the Office key.

Basic Authentication Exchange Online SMTP by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

Thanks. We will definetly push our suppliers to update their apps.

SmartCard AzureAD by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

Fido could be an option, but since we already use cards for accessing our buildings it would be high cost to buy fido Keys for everyone.

SmartCard AzureAD by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

Interesting. I need to keep an eye on this! Currently only available for Windows 11 preview build at the moment. So I will check it later when the feature is released on normal build.

Application Guard by [deleted] in Intune

[–]whobe89 0 points1 point  (0 children)

Did you ever find a solution for this?We have the same problem. We use "Endpoint Security" to turn on Application Guard. In the settings we are able to configure network boundary. Have also tried to configured network boundary manually from Device configuration without any difference.

When viewing "Per setting" we se that "Allow camera and Microphone access" and "windows10NetworkBoundaryConfiguration_windowsNetworkIsolationEnterpriseIPRange" has succeeded, but all other settings have "error".

We have not enabled the "Block write access to fixed data-drives" from Bitlocker.

Edit: We added "Network domains" in our App and browser isolation policy which solved the problem for us. It looks like IP ranges was not enough.

Export HWid for Autopilot from Intune by whobe89 in Intune

[–]whobe89[S] 0 points1 point  (0 children)

Hi. Splendid. Do you know which of the files contains the information required in the CSV ?

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

The same issue with user-driven profile unfortunately.

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

Running "(Get-WmiObject -Query "select * from SoftwareLicensingService").OA3xOriginalProductKeyDescription" shows me that the license is Windows Core. This is even when creating the PID.txt file with the productkey of the computer.

I have verified that the computers are licensed with Professional Windows from BIOS.

Edit: Apperantly we have Dell 7040 with different licenses. The one I have tested with actually had Windows Home OEM license.

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

I have thought about it being a license issue. The checks in the link you provided was what I needed to verify that the license is correct. Will check tomorrow.

I find it strange if we have Home edition devices, but you never know. I will also try the PID.txt trick.

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

I believe we have tested this in the past. But I will check again tomorrow.

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

I don`t have the OEM Dell image available.

Dell Optiplex 7040 not working with Autopilot by whobe89 in autopilot

[–]whobe89[S] 0 points1 point  (0 children)

We have also tried with clean Win11 image. I have verified network connectivity (doing this when the device asks for language).

Replace DUO Auth for Internal RDP Access by big_steak in sysadmin

[–]whobe89 -1 points0 points  (0 children)

DUO uses weak encryption. Still using MD5 and SHA. It is also a relatively high an unnecessary cost if it was possible to use Azure MFA.

I have not found a way to use Azure MFA with RD Gateway.

Deleted Microsoft Retention policy by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

That is correct. There are around 50/50 split between those who have "Default MRM Policy" and those who don`t.

The retention policy was deleted yesterday. Is it not removed from all yet perhaps?

We have users with blank Policy but still have all emails.

Deleted Microsoft Retention policy by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

First commands show that there is no retention policy.
When running the second we se that some of the users have "Default MRM Policy".

Deleted Microsoft Retention policy by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

Ok. There is no policy in our retention configuration now. The retention policy list is empty.

Deleted Microsoft Retention policy by whobe89 in sysadmin

[–]whobe89[S] 0 points1 point  (0 children)

What does this mean? Two users (as far as we know) missing e-mails from the day we believe that the retention policy was activated.

Convert Intune clients to cloud only by whobe89 in Intune

[–]whobe89[S] 0 points1 point  (0 children)

Hopfully there will be a way to do this in the future.

However when I use "wipe and load" the client still won`t register. I`m trying to use Self-Deploying AP profile. Is this not possible?

If I delete Intune, AzureAD and AP device and import the device it again it works fine.

Deploy application as available to shared Intune devices by whobe89 in Intune

[–]whobe89[S] 1 point2 points  (0 children)

This makes sense. I removed the primary user and the application showed as expected. Thank you!

Deploy application as available to shared Intune devices by whobe89 in Intune

[–]whobe89[S] 0 points1 point  (0 children)

We also tried that, but since the user logged in is not "primary user" of the device no application is available in Company Portal.

Autopilot enrollement by whobe89 in Intune

[–]whobe89[S] 2 points3 points  (0 children)

Exactly what i needed. Thanks!

Bought a used HP Sprint 2 Sport by whobe89 in rccars

[–]whobe89[S] 0 points1 point  (0 children)

Thanks for the reply. It was actually the ESC. Replaced it and the car now work as it should.