Jump to content

mjhardisty

Members
  • Posts

    150
  • Joined

  • Last visited

Everything posted by mjhardisty

  1. I've received "kioskuser0 account has a password error." in Intune when there is a policy that prevents the PC having a local user, or the password policies are interfering with the creation and password of the local user. At one of our sites I've built the kiosk manually and am remotely managing the PC using RMM.
  2. There is a nice blog on the new eDiscovery processes here: https://techcommunity.microsoft.com/blog/microsoft-security-blog/getting-started-with-the-new-purview-ediscovery-e3/4412354 The export will still produce PST files that can be added into Outlook.
  3. Think DMJ is correct for most of these applications. They, for the majority, use an enterprise subscription to OpenAI (ChatGPT) and thus will have some control of what parameters are passed to the APIs in order to tailor any responses.
  4. £1 per device per year, increasing by £1 each year per device.
  5. Windows ESU licences are available until 2029 for Windows 10 machines. https://learn.microsoft.com/en-us/windows/whats-new/extended-security-updates
  6. There is a Power Management settings from the catalog or use the Device Restrictions template.
  7. Vanilla Windows 11 OS, Autopilot script, Autopilot branding, ESP for exisiting devices.
  8. Interested to what the device state is after a user has logged in that it can't be used? Have you tried something like the Intune Assignment Checker to see exactly what configurations that user has: https://intuneassignmentchecker.ugurkoc.de/
  9. That sounds complex!
  10. Happy to look over the Intune policies. Shared PC with OneDrive enabled needs to be set using CSP. They also need some local storage as OneDrive will use their local profile to create the appx and store files. You can restrict access to folders outside of OneDrive.
  11. Sounds like you might have to build a provisioning package in Windows Configuration Designer if you aren't using Intune. I think the Shared PC policies are exposed if you use that utility. My solution through Intune, which hopefully it will mirror, is that users only have access to Documents, Desktop, etc and no other folder and these are silently moved to OneDrive. Any save to "Documents" is automatically saved into OneDrive.
  12. I wouldn't recommend exporting existing GPOs ... don't bring the clutter with you.
  13. These are a series of pre-built configuration policies designed for Education: https://github.com/rbalsleyMSFT/IntuneScripts/tree/main/ConfigurationProfileSettings I would recommend joining the Microsoft EDU Endpoint Office hours group too.
  14. Use Windows Update Rings in Intune for Security/Feature updates for Windows devices. Action1 is useful for instant patching/deployment and fixing other vulunerabilities. Are your uses on A3 or above licencing? If so, then use Defender for Endpoint.
  15. How are you autopiloting machines?
  16. Configuration setting is the way then, to fofce GMT.
  17. Yep, it'll probably take US time from the default langauge of the OS. You can change it on the OOBE in deployment profiles or via configuration settings (Configure Time Zone).
  18. More than likely some issue with a recent update, or failed update or simliar that's prevented the upgrade. A good result though, just rebuild the troublesome devices!
  19. Have you the ability to autopilot reset one and see if it rebuilds and updates itself?
  20. Does your Feature Update include "When a device isn't eligible to run Windows 11, install the latest Windows 10 feature update" ticked? What happens if you do log onot one of these devices as admin and try to manually update it?
  21. You could setup an internal IIS server that allows anonymous access and just serves the cert, link it from the captive portal. Or could the file be copied to the UniFi controller using SSH and served from there?
  22. Something similar. You could probably use a remediation script to recopy the program to all user startup folders. https://www.edtechirl.com/p/deploying-desktopinfo-using-microsoft
  23. Might be the case? Microsoft updated its WIndows 11 SE page on 01/09/2024 so ... might still be available? https://learn.microsoft.com/en-us/education/windows/windows-11-se-overview
  24. We've a few Acer laptops on Windows 11 SE under Intune. The "apps" on the device are all webview wrapped, especially Office, so not native Windows versions of applications - much like the "new" Outlook. Not come across any issues so far, but colleagues are aware they operate much like a Windows Chromebook. Performance is pretty ... poor though.
  25. I've performed this on a few machines now, they appear as Corporate Ownership in Intune, just with limited abilities to reset them (since they have no ability to autopilot restore). I've had no issues with policies, apart from Bitlocker due to TPM, etc. In Azure they appear as "Entra joined" with no owner and MDM as Intune.
×
×
  • Create New...