Jump to content

Recommended Posts

Posted

Hello, a couple of Intune Qs

 

- should I enable and set password of the local built in administrator account (via PS), if the device is broken, WiFi broken or something I feel I might need it but research says I shouldn’t due to security.

 

- I have set a load of restrictions but can’t crack preventing changing power settings. Students could change sleep to e.g. 1 minute etc which would be annoying.

 

Thanks for any info.

Posted

MS are against the use of any local accounts due to security. I'm not using as any issues then I will reset the device and so again using autopilot.

 

Have you looked at the admx backed policies? https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider

 

Anything with admx_xx are for Windows insider preview build only, however will be implemented by MS after testing.

 

How have you got on with locking device down? MS are working on hide drive CSP policy in preview and I have used applocker scripts to stop exe, MSI etc.

Posted

Locking down the device is OK, it's a little disheartening to start all over again having spent years perfecting the local AD GPO's. A bit of a mess, but then that's MS.

 

I am also finding some profiles applied to student users, seem to affect whoever logs into the laptops..

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...