craigcamacho
Members-
Posts
73 -
Joined
-
Last visited
Reputation
267 ExcellentAbout craigcamacho

Personal Information
-
Occupation
Senior ICT Technician
-
Location
Nelson
Employer (optional)
-
Company Represented
Lancashire County Council
-
Hi everyone, Hope you’re all doing well! 🎬 I’ve just posted my first video in a while, covering Filters in Microsoft Intune to help simplify targeted device management. It’s been a bit since I last made a video, so I’m a little rusty, but I’m hoping it’s still helpful! In the video, I walk through creating and applying filters, especially for those tricky cases where you need to target specific devices with apps or policies. I’d really appreciate any feedback, suggestions, or questions you might have—it’s all part of the learning journey! Here’s the link if you’d like to take a look: Thanks a bunch to anyone who gives it a watch, and I look forward to your thoughts! 😊
- 1 reply
-
- 2
-
-
No i hadn't updated the templates but have now so much appreciated for making me aware of that. It still didn't work even after I did this but you certainly got me in the right direction and I managed to figure it out. I had removed my Windows 11 test devices from the "Domain Computers" group and put them in their own temp "WIN11_Devices" group to isolate them from the main production policies in NPS. In my CA under the security tab of my wireless cert template it was only setup to auto enrol "Domain Computers". I have added in Win11_Devices" and ticked auto enrol and I think its fixed it. I am going to reimage both my test devices now and see if it still works.
-
Actually it doesnt look like it is getting the certificate. I have just logged and opened certs via mmc and requested a new cert and picked the one from my CA for wireless and as soon as I did it started working. Like I say im far from an expert in certs so i need to figure this out now. GPOs for Auto Enrol perhaps?
-
Yeah i think so. I just looked under Certlm and can see the cert and the expiration date matches up with what I have set. In Event Viewer under WLAN-AutoConfig on the client trying to connect to wifi I am getting an error messages about The authenticator is no longer present. Does this mean anything? I will be honest certs aren't my strong point.
-
Hi All, I am hoping some clever person on here can help with an issue I am having with my Windows 11 migration project and point out where I am going wrong with my Wireless, NPS and GPO settings. I know about the update that broke NPS/Radius a while back that I believe was down to Credential Guard now being on by default. Is disabling Credential Guard the typical thing to do or should I be looking to reconfigure NPS to make it work with Credential Guard? (I would have thought the second option but want to know what everybody else does). Everything else such as Radius Clients are already setup and my current polices that are live are working with Windows 10. For testing I have created new Connection Request, Network Policies and GPO that points to my test devices 1. Connection Request Policy 2.0 Network Policy (Overview) 2.1 Network Policy (Conditions) My test devices are in the group WIN11_Devices 2.2 Network Policy (Constraints) Have set this to Smart Card or Cert and selected valid cert thats in date 2.3 Network Policy (Settings) 3.0 GPO (Connection) 3.1 GPO (Security) 3.2 GPO (Security Certificate) Cert selected matches the one set in 2.2
-
Netsweeper Cloud Migration
craigcamacho replied to craigcamacho's topic in Internet Related/Filtering/Firewall
Do you mean the Netsweeper admin portal? if so we use https://lancashirecceducationdigitalservices.netsweeper.com/webadmin/start/ -
Hi All, Has anybody else had their Netsweeper migrated from a hosted solution to a cloud solution and if so what was your experience like? We had ours done just over a week ago by LCC\EDS and it's been horrific. Our internet speeds are pitiful and we have developed this strange problem where a lot of our devices will state they have "No Internet Access" when you hover over the network connection in the taskbar but using a browser and the internet works. The problem is that because Windows "thinks" it doesn't have internet access this then breaks Office. We use shared device licensing with SSO so when a user launches Word for example it isn't logging them because it can't get out to Microsoft to check the licensing.
-
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
I have done a few new ones since this thread and it would be great if you could take a look and provide any feedback. For any new people you can get to the channel via ------> https://www.youtube.com/channel/UCC2E2HikYlO1WBujjyRZ4CQ It would be great if you could like, subscribe and even provide any feedback on here of what kind of content you would like to see. -
[22h2] PEAP/MSCHAPv2 and 22H2 Credential Guard
craigcamacho replied to mitchell1981's topic in Windows 11
I have just come up against this. Thankfully it was only on the 3 XPS13 laptops the IT Support just got and imaged to Windows 11 22H2 and it didn't hit our production environment. When i set the above NPS and GPOs and then login to a laptop and the wifi tries to kick in I get a prompt saying action needed. Any ideas? -
It depends on a number of factors really such as budgets, current infrastructure and also confidence in your own abilities. I would always suggest SCCM if you are fully on-prem because its an absolutely amazing product but it can be quite pricy from a licensing point of view and some people just don't have it in their budgets. I don't even think its that difficult to setup and manage anymore but I've been doing it for about 13 years so my opinion on that is probably fairly skewed. There are plenty of guides out there on the internet that can talk you through setting up a basic standalone primary site with management, distribution and software update point roles. MDT is a free alternative you use for image deployment which tbh I have never had to have much dealings with and only ever set it up once many years go so cant really give much advice on that but I know its a decent tool. I would personally stay away from WDS (although SCCM works on top of it) as its a fairly old school way of doing it and there are free alternatives now such as MDT so why would you use WDS on its own? Whether you use SCCM or MDT I would always suggest staying away from baking software in and creating fat images and stick with a thin image even if its the vanilla install.wim from the sources folder on the OS installer media. Find a way of bolting your software on after the image is laid on the drive such as during a task sequence or other typical app deployment methods. When you need to update any of your apps its much easier packaging the new app and adding to a task sequence or deploying it than having to rebuild your entire image. A good way of creating images is using something like WimWitch or OSDBuilder. With these you can take the vanilla image and make changes such as removing built in windows apps, injecting updates and much more. They are both brilliant tools! I would love to suggest Autopilot and Intune as well but I know these aren't the easiest to implement in a school environment and get working with other services within school such as MIS, printing and any other on-prem roles especially in the time frames your thinking of.
-
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Also if you ever start a YouTube channel called "The DevOps Guy" let me know and I will subscribe. -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Thanks for the links and information which you obviously took time to compose. I am always receptive and appreciative of additional training, advice and new ways of working so thank you. I think what has perhaps gotten peoples backs up is that you have suggested there are other ways of doing particular tasks then gone full steam ahead with how you do it and completely dismissed the other ways that differ from yours such as point and click as "hobbiest". Whether this was meant or not it did sound patronising and undermining of the working methods that a lot of people on this forum probably use and you came across as a bit of a smart arse if I am honest. Everything in IT is implemented on a use case scenario as you well know. If you have a massive budget and have a need to facilitate thousands and thousands of endpoints and users across numerous locations then I agree your way might well be more appropriate and provide more consistent results for the task at hand. If you have a medium budget which only covers certain licensing, a reduced number of virtual servers because you've managed to migrate a lot of the roles to SaS and then you have between 1000-2000 endpoints on a single site I bet a lot of people on this forum would still use point and click. I went to a cyber security event yesterday hosted by a very reputable and cyber accredited company who are a Microsoft Gold Partner and every single demo they did were either in the Entra portal, Admin Center or one of the various Security portals. These demonstrations were ALL point and click. Were they wrong? No they were not. Again just different to how you do it. You were very quick to say you didnt agree with the approach I take. Does that mean I am wrong? No it doesn't it just means I do it differently to you based on a certain use case scenario. Are you doing it wrong? No your not infact probably far from it if I am honest but again this is based on your own use case scenario. Each of my videos does state at the beginning that they are for people just starting out with Intune and lets be honest cover pretty simple tasks. I would say 99% of the people searching and watching these videos are going to want to know how to do these tasks using point and click so I am catering for these people. A lot of what I have learnt over the years has come from various sources such as books, online training platforms such as Pluralsight, CBT Nuggets etc and following a number of MVPs (big up Arwidmark, Niehaus and all the other guys) on Twitter so I am demonstrating what I have learnt from the various platforms. Basically what I am trying to suggest is that neither of our methods are the right or wrong way of doing it. I have never in my life done anything on YouTube and I am more than happy with the number of subscriber's I have gotten in literally a handful of weeks. I have also gotten a spot on a weekly newsletter written by a Microsoft MVP in Enterprise Mobility for the 3 out of 4 weeks my channel has been going so I would like to think Im doing something of value. -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Ok thank you for your input. So with applications, configuration and compliance policies for example what is best practice to deploy these other than point and click from the Intune portal? -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
I have just dropped another video on how to package and deploy Office 365 as a Win32 app. The reason I do it this way is so I can install Office as part of my ESP but having a mix of app formats (msi, win32 etc) can cause a lot of conflicts and issues. -
Hi All, I have created a new YouTube channel called The Deployment Guy. Its only a few weeks old and up to now I have 209 subscribers most of which came from posting in Reddit subs but I completely forgot to post it on here. The first few videos I did are silent but I have voiced the last few. The nature of the videos up to now are quick nugget sized videos for people just starting out in Intune but I will be branching out into other things like Autopilot, ConfigMgr, Windows 365 etc. It would be great if you could take a look and give me any feedback on the quality of the videos and even suggestions of topics I could cover. https://www.youtube.com/channel/UCC2E2HikYlO1WBujjyRZ4CQ
- 27 replies
-
- 22
-
