Jump to content

Recommended Posts

Posted

I have incorrectly set an education Intune profile on my Windows devices that 'Block access to administrative apps' (registry, PowerShell, CMD). I found this prevented some desired scripts to run, so I want to now allow these things.

 

There is no 'enable' or 'do not block' in the policy and even after removing the policy I am finding the devices are still being affected - 'This App has been blocked by your system administrator'. How can I remove this setting? Is it a reg key that has been set and even when the block policy is deleted the registry key remains as set?

 

 

 

block.jpg

Posted

Thanks, that works now. On the same note can you clear up the Q if we want a script that runs whenever anyone logs in how can we do this with Intune?

 

The 'Script' part of the this MS doc - https://docs.microsoft.com/en-us/mem/intune/apps/intune-management-extension

 

 

"..The Intune management extension agent checks with Intune once every hour and after every reboot for any new scripts or changes.

Once the script executes, it doesn't execute again unless there's a change in the script or policy.

If the script fails, the Intune management extension agent retries the script three times for the next three consecutive Intune management extension agent check-ins..."

 

 

so that implies you can't have a script that always runs (like an AD log on script)?

Posted
Thanks, that works now. On the same note can you clear up the Q if we want a script that runs whenever anyone logs in how can we do this with Intune?

 

The 'Script' part of the this MS doc - https://docs.microsoft.com/en-us/mem/intune/apps/intune-management-extension

 

 

"..The Intune management extension agent checks with Intune once every hour and after every reboot for any new scripts or changes.

Once the script executes, it doesn't execute again unless there's a change in the script or policy.

If the script fails, the Intune management extension agent retries the script three times for the next three consecutive Intune management extension agent check-ins..."

 

 

so that implies you can't have a script that always runs (like an AD log on script)?

I believe the way around that would be to have a script which creates a scheduled task to then run a script at user logon.

Posted
It needs to run the smoothwall authentication script which is a script that authenticates the current user so they get the correct filtering rules.
Posted
It needs to run the smoothwall authentication script which is a script that authenticates the current user so they get the correct filtering rules.

 

Not quite a direct answer to your question but.....

 

On our Intune managed devices we use the Smoothwall Cloud Filter extensions in the (newer) Edge browser. We do deploy a "one time" script to set the correct Smoothwall Cloud settings in the registry but after that the browser extension manages everything and works really well. Just need to ensure all other browsers are removed from the clients.

Posted
That screenshot is from the intune for education portal right? If you check in Big Intune can you see the if the policy is still being assignd? That policy shows up as a custom csp named something like Deny Adminstrative Apps.
Posted
Not quite a direct answer to your question but.....

 

On our Intune managed devices we use the Smoothwall Cloud Filter extensions in the (newer) Edge browser. We do deploy a "one time" script to set the correct Smoothwall Cloud settings in the registry but after that the browser extension manages everything and works really well. Just need to ensure all other browsers are removed from the clients.

 

Is this cloud filter purchased and configured in addition to our existing onsite smoothwall filter? Sounds possible, any catches?

Posted
Is this cloud filter purchased and configured in addition to our existing onsite smoothwall filter? Sounds possible, any catches?

 

No additional purchase necessary. Just speak to your account manager and they'll get the ball rolling.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...