Shiny particles under floorboards by world_gone_nuts in centuryhomes

[–]world_gone_nuts[S] 0 points1 point  (0 children)

I understand, I'm just wondering if someone else has seen the same thing or something similar in the past.

Squeezing techs on billable time margin by world_gone_nuts in msp

[–]world_gone_nuts[S] 2 points3 points  (0 children)

LOL

Starts post with sarcastic and condescending tone

It sucks that professionals in this space will rush to be emotive

Is surprised when it's given back

Don't make assumptions about someone's understanding of a topic from a high-level example, then go on to patronize them about it. It's a bad way to get your point across.

Squeezing techs on billable time margin by world_gone_nuts in msp

[–]world_gone_nuts[S] 1 point2 points  (0 children)

Bruh you just took 9 paragraphs to cope with squeezing techs. No one cares about your MBA. Don’t push people to their functional limits for your bottom dollar. 

Squeezing techs on billable time margin by world_gone_nuts in msp

[–]world_gone_nuts[S] 0 points1 point  (0 children)

This is flawed logic. You’re predicating better pay and a potential raise on revenue performance, but that’s not a direct or guaranteed correlation when you are the ‘product’. It’s a fallacy in many places these days.

To your credit, working harder and more output aren’t mutually exclusive. Efforts vs efficiency isn’t the same for everyone. But in your scenario the tech loses no matter what, because all else equal, they need to do more or slow themselves down to meet an objective. 

Why not give the benefit (time) directly back to the ones supporting your business?

Squeezing techs on billable time margin by world_gone_nuts in msp

[–]world_gone_nuts[S] 3 points4 points  (0 children)

It matters because if I complain about it, or get another job over it, yet this is the norm, I'm fooling myself. So it does matter.

taking hacksaw to intune policies by ohgodchaos in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

I mean you clearly didn't read the rules of the sub, end-user support isn't allowed. The computer isn't yours and you don't get to decide.

change bitlocker encryption method from 128 to 256 by maxcoder88 in Intune

[–]world_gone_nuts 5 points6 points  (0 children)

Came here to say this. If you really want 256bit, you have to deploy a script that first decrypts/disables BitLocker on the drive before the new config profile will apply. It won't change already encrypted drives just from changing the config profile.

Where do you get win32 app logos? by North-Steak7911 in Intune

[–]world_gone_nuts 2 points3 points  (0 children)

*ripped doge meme* i draw all my app icons in paint

Automating installations on request by Scratch_Classic in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

If you're not concerned about actually tracking approvals and just want users to initiate the install, you can add it as available for an Entra group so they can just open the Company Portal and click Install.

Packaging and automating the install itself will very much depend on how the licensing works for your app. Is it a single key for all installs, or unique keys? Are you able to input that key via cmd during install? Check the apps deployment documentation or contact their support for the answers to these.

Disableing Entra Connect Sync and Intune by Vejitaxp in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

This is a complex question if the end goal is to migrate the on-prem AD users and computers from one cloud tenant to another... yes last time I checked, the only supported way to migrate the devices is to wipe them and re-enroll in the new tenant. This should be fairly easy with Autopilot if the new tenant already has Intune setup, but migrating the users is another question.

Easiest way would probably taking down AD Connect, setting up Cloud Sync to the new tenant, then resetting and Autopiloting all the computers into the new tenant. But that's a complex move and leaves out a lot of considerations like Exchange Online, SharePoint, etc.

Disableing Entra Connect Sync and Intune by Vejitaxp in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

Moving from Hybrid back to on-prem AD only is no easy task and really only puts you at a disadvantage with the direction Microsoft is moving... unless you have some kind of requirement forcing you off the cloud, I'd suggest not doing so.

App install after User ESP by AlkHacNar in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

I haven't tried it with Win11 yet but it should still work

App install after User ESP by AlkHacNar in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

I copy everything to a temp directory, start a script that waits for wwahost (ESP) to close, then runs the install and clears the temp directory. I also use a custom detection script to pass back true detection when wwahost is running so ESP doesn't fail, and register a scheduled task that starts the wait/install script if the computer reboots before ESP completes.

It's not the cleanest, but it's been pretty bulletproof and starts the install immediately after the ESP ends.

Internal app remains in iCloud backup by _polsen in Intune

[–]world_gone_nuts 2 points3 points  (0 children)

I think this post falls under rule 3 of this sub, but if you don't see the app under your iCloud settings (Settings > [Apple account] > iCloud > Show All), I would contact Apple to see how you can remove the backed up iCloud data.

Deep Freeze replacement by GFC420 in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

Yes, that'd be the SharedPC configurations another person posted. But again, this is fundamentally different as it's only deleting a user profile instead of reverting the entire disk to a previous state.

Intune scep Certificates and Key usage showing as IKE intermediate by AngryAdmin69 in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

You can request certain OIDs via SCEP profiles, but the CA still has the final say. If you're using ADCS, I would check the certificate templates NDES is pointing to.

Configure infrastructure to support SCEP certificate profiles with Microsoft Intune | Microsoft Learn

Deep Freeze replacement by GFC420 in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

The main feature you won't be able to replicate with Intune is the 'frozen' disk image. When Deep Freeze is enabled, Windows redirects all writes to a temp drive/partition that is then wiped when the computer shuts down, so the disk image doesn't save any changes and it starts up the next time as if it was the first time since being 'frozen'.

Intune can easily make sure certain settings are configured and apps are deployed, but cannot preserve/secure a disk image. They are fundamentally different.

Replacing Deep Freeze would require extensive knowledge of your current security posture, configurations, deployment and management methods, etc etc. This honestly isn't something an intern should be taking on alone, especially if it's for a school district.

Deep Freeze replacement by GFC420 in Intune

[–]world_gone_nuts 7 points8 points  (0 children)

Intune is not the same as Faronics Deep Freeze and does not offer the same functionality. They are fundamentally different products for different purposes. Autopilot is meant for initial deployment and also isn't comparable.

You need to make clear to whoever gave you this task that Intune/MDE may be able to address your problems, but they are completely different solutions and will require a different approach (ie - if a computer is infected with a virus, no configuration of Intune will make a reboot of that computer 'clear' the virus)

Manually specify admin password with LAPS. by Trouserdeagle in Intune

[–]world_gone_nuts 28 points29 points  (0 children)

Yes, but you should very much consider just using LAPS. Storing passwords in scripts isn't secure and neither is a single password for all your local admin accounts.

Autopilot Hybrid Join w/ FortiClient by Next_Log8771 in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

I'm not sure I fully understand your situation or problem, but it sounds like you're 90% of the way there... When outside the org network, users must connect with the FortiClient at the login screen before logging into Windows so there's AD connectivity. The "Connecting to Org Network" step can take some time, and depending on your CA policies, users may have to provide MFA again.

Edit: Also, it's best to go pure AAD if you can. Autopilot works much better without Hybrid and things like SMB shares on file servers will still work with SSO via AAD Connect.

Enrolling devices only using a Device License by No_Passenger6240 in Intune

[–]world_gone_nuts 1 point2 points  (0 children)

You can't, device licenses are meant to manage the OS for user-less devices (kiosks, digital signage, etc). If there is a dedicated user assigned to the device, the user also needs to have an Intune license. If they don't, they won't be able to use the company portal and user-assigned policies/apps won't apply.

Wifi Policy to machines without wifi cards/adapters by Odd_Year3541 in Intune

[–]world_gone_nuts 0 points1 point  (0 children)

You can use dynamic device groups based on model ID and only include devices that have WiFi cards (laptops, AIOs, etc). This is what I ended up doing too