petben Posted March 23, 2021 Posted March 23, 2021 Hello, a couple of Intune Qs - should I enable and set password of the local built in administrator account (via PS), if the device is broken, WiFi broken or something I feel I might need it but research says I shouldn’t due to security. - I have set a load of restrictions but can’t crack preventing changing power settings. Students could change sleep to e.g. 1 minute etc which would be annoying. Thanks for any info.
deano Posted March 23, 2021 Posted March 23, 2021 MS are against the use of any local accounts due to security. I'm not using as any issues then I will reset the device and so again using autopilot. Have you looked at the admx backed policies? https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider Anything with admx_xx are for Windows insider preview build only, however will be implemented by MS after testing. How have you got on with locking device down? MS are working on hide drive CSP policy in preview and I have used applocker scripts to stop exe, MSI etc.
petben Posted March 24, 2021 Author Posted March 24, 2021 Locking down the device is OK, it's a little disheartening to start all over again having spent years perfecting the local AD GPO's. A bit of a mess, but then that's MS. I am also finding some profiles applied to student users, seem to affect whoever logs into the laptops..
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now