craigcamacho
Members-
Posts
73 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by craigcamacho
-
Hi everyone, Hope you’re all doing well! 🎬 I’ve just posted my first video in a while, covering Filters in Microsoft Intune to help simplify targeted device management. It’s been a bit since I last made a video, so I’m a little rusty, but I’m hoping it’s still helpful! In the video, I walk through creating and applying filters, especially for those tricky cases where you need to target specific devices with apps or policies. I’d really appreciate any feedback, suggestions, or questions you might have—it’s all part of the learning journey! Here’s the link if you’d like to take a look: Thanks a bunch to anyone who gives it a watch, and I look forward to your thoughts! 😊
- 1 reply
-
- 2
-
-
No i hadn't updated the templates but have now so much appreciated for making me aware of that. It still didn't work even after I did this but you certainly got me in the right direction and I managed to figure it out. I had removed my Windows 11 test devices from the "Domain Computers" group and put them in their own temp "WIN11_Devices" group to isolate them from the main production policies in NPS. In my CA under the security tab of my wireless cert template it was only setup to auto enrol "Domain Computers". I have added in Win11_Devices" and ticked auto enrol and I think its fixed it. I am going to reimage both my test devices now and see if it still works.
-
Actually it doesnt look like it is getting the certificate. I have just logged and opened certs via mmc and requested a new cert and picked the one from my CA for wireless and as soon as I did it started working. Like I say im far from an expert in certs so i need to figure this out now. GPOs for Auto Enrol perhaps?
-
Yeah i think so. I just looked under Certlm and can see the cert and the expiration date matches up with what I have set. In Event Viewer under WLAN-AutoConfig on the client trying to connect to wifi I am getting an error messages about The authenticator is no longer present. Does this mean anything? I will be honest certs aren't my strong point.
-
Hi All, I am hoping some clever person on here can help with an issue I am having with my Windows 11 migration project and point out where I am going wrong with my Wireless, NPS and GPO settings. I know about the update that broke NPS/Radius a while back that I believe was down to Credential Guard now being on by default. Is disabling Credential Guard the typical thing to do or should I be looking to reconfigure NPS to make it work with Credential Guard? (I would have thought the second option but want to know what everybody else does). Everything else such as Radius Clients are already setup and my current polices that are live are working with Windows 10. For testing I have created new Connection Request, Network Policies and GPO that points to my test devices 1. Connection Request Policy 2.0 Network Policy (Overview) 2.1 Network Policy (Conditions) My test devices are in the group WIN11_Devices 2.2 Network Policy (Constraints) Have set this to Smart Card or Cert and selected valid cert thats in date 2.3 Network Policy (Settings) 3.0 GPO (Connection) 3.1 GPO (Security) 3.2 GPO (Security Certificate) Cert selected matches the one set in 2.2
-
Netsweeper Cloud Migration
craigcamacho replied to craigcamacho's topic in Internet Related/Filtering/Firewall
Do you mean the Netsweeper admin portal? if so we use https://lancashirecceducationdigitalservices.netsweeper.com/webadmin/start/ -
Hi All, Has anybody else had their Netsweeper migrated from a hosted solution to a cloud solution and if so what was your experience like? We had ours done just over a week ago by LCC\EDS and it's been horrific. Our internet speeds are pitiful and we have developed this strange problem where a lot of our devices will state they have "No Internet Access" when you hover over the network connection in the taskbar but using a browser and the internet works. The problem is that because Windows "thinks" it doesn't have internet access this then breaks Office. We use shared device licensing with SSO so when a user launches Word for example it isn't logging them because it can't get out to Microsoft to check the licensing.
-
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
I have done a few new ones since this thread and it would be great if you could take a look and provide any feedback. For any new people you can get to the channel via ------> https://www.youtube.com/channel/UCC2E2HikYlO1WBujjyRZ4CQ It would be great if you could like, subscribe and even provide any feedback on here of what kind of content you would like to see. -
[22h2] PEAP/MSCHAPv2 and 22H2 Credential Guard
craigcamacho replied to mitchell1981's topic in Windows 11
I have just come up against this. Thankfully it was only on the 3 XPS13 laptops the IT Support just got and imaged to Windows 11 22H2 and it didn't hit our production environment. When i set the above NPS and GPOs and then login to a laptop and the wifi tries to kick in I get a prompt saying action needed. Any ideas? -
It depends on a number of factors really such as budgets, current infrastructure and also confidence in your own abilities. I would always suggest SCCM if you are fully on-prem because its an absolutely amazing product but it can be quite pricy from a licensing point of view and some people just don't have it in their budgets. I don't even think its that difficult to setup and manage anymore but I've been doing it for about 13 years so my opinion on that is probably fairly skewed. There are plenty of guides out there on the internet that can talk you through setting up a basic standalone primary site with management, distribution and software update point roles. MDT is a free alternative you use for image deployment which tbh I have never had to have much dealings with and only ever set it up once many years go so cant really give much advice on that but I know its a decent tool. I would personally stay away from WDS (although SCCM works on top of it) as its a fairly old school way of doing it and there are free alternatives now such as MDT so why would you use WDS on its own? Whether you use SCCM or MDT I would always suggest staying away from baking software in and creating fat images and stick with a thin image even if its the vanilla install.wim from the sources folder on the OS installer media. Find a way of bolting your software on after the image is laid on the drive such as during a task sequence or other typical app deployment methods. When you need to update any of your apps its much easier packaging the new app and adding to a task sequence or deploying it than having to rebuild your entire image. A good way of creating images is using something like WimWitch or OSDBuilder. With these you can take the vanilla image and make changes such as removing built in windows apps, injecting updates and much more. They are both brilliant tools! I would love to suggest Autopilot and Intune as well but I know these aren't the easiest to implement in a school environment and get working with other services within school such as MIS, printing and any other on-prem roles especially in the time frames your thinking of.
-
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Also if you ever start a YouTube channel called "The DevOps Guy" let me know and I will subscribe. -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Thanks for the links and information which you obviously took time to compose. I am always receptive and appreciative of additional training, advice and new ways of working so thank you. I think what has perhaps gotten peoples backs up is that you have suggested there are other ways of doing particular tasks then gone full steam ahead with how you do it and completely dismissed the other ways that differ from yours such as point and click as "hobbiest". Whether this was meant or not it did sound patronising and undermining of the working methods that a lot of people on this forum probably use and you came across as a bit of a smart arse if I am honest. Everything in IT is implemented on a use case scenario as you well know. If you have a massive budget and have a need to facilitate thousands and thousands of endpoints and users across numerous locations then I agree your way might well be more appropriate and provide more consistent results for the task at hand. If you have a medium budget which only covers certain licensing, a reduced number of virtual servers because you've managed to migrate a lot of the roles to SaS and then you have between 1000-2000 endpoints on a single site I bet a lot of people on this forum would still use point and click. I went to a cyber security event yesterday hosted by a very reputable and cyber accredited company who are a Microsoft Gold Partner and every single demo they did were either in the Entra portal, Admin Center or one of the various Security portals. These demonstrations were ALL point and click. Were they wrong? No they were not. Again just different to how you do it. You were very quick to say you didnt agree with the approach I take. Does that mean I am wrong? No it doesn't it just means I do it differently to you based on a certain use case scenario. Are you doing it wrong? No your not infact probably far from it if I am honest but again this is based on your own use case scenario. Each of my videos does state at the beginning that they are for people just starting out with Intune and lets be honest cover pretty simple tasks. I would say 99% of the people searching and watching these videos are going to want to know how to do these tasks using point and click so I am catering for these people. A lot of what I have learnt over the years has come from various sources such as books, online training platforms such as Pluralsight, CBT Nuggets etc and following a number of MVPs (big up Arwidmark, Niehaus and all the other guys) on Twitter so I am demonstrating what I have learnt from the various platforms. Basically what I am trying to suggest is that neither of our methods are the right or wrong way of doing it. I have never in my life done anything on YouTube and I am more than happy with the number of subscriber's I have gotten in literally a handful of weeks. I have also gotten a spot on a weekly newsletter written by a Microsoft MVP in Enterprise Mobility for the 3 out of 4 weeks my channel has been going so I would like to think Im doing something of value. -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
Ok thank you for your input. So with applications, configuration and compliance policies for example what is best practice to deploy these other than point and click from the Intune portal? -
The Deployment Guy - New YouTube Channel
craigcamacho replied to craigcamacho's topic in Cloud Services
I have just dropped another video on how to package and deploy Office 365 as a Win32 app. The reason I do it this way is so I can install Office as part of my ESP but having a mix of app formats (msi, win32 etc) can cause a lot of conflicts and issues. -
Hi All, I have created a new YouTube channel called The Deployment Guy. Its only a few weeks old and up to now I have 209 subscribers most of which came from posting in Reddit subs but I completely forgot to post it on here. The first few videos I did are silent but I have voiced the last few. The nature of the videos up to now are quick nugget sized videos for people just starting out in Intune but I will be branching out into other things like Autopilot, ConfigMgr, Windows 365 etc. It would be great if you could take a look and give me any feedback on the quality of the videos and even suggestions of topics I could cover. https://www.youtube.com/channel/UCC2E2HikYlO1WBujjyRZ4CQ
- 27 replies
-
- 22
-
-
Figured it out in the end. Created an application in SCCM using OneDriveSetup.exe /AllUsers and deployed Created a package and deployed the below Powershell script using a command of "%Windir%\sysnative\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -Command .\RemoveDefaultOneDrive.ps1 https://byteben.com/bb/installing-the-onedrive-sync-client-in-per-machine-mode-during-your-task-sequence-for-a-lightening-fast-first-logon-experience/ #Create PSDrive for HKU New-PSDrive -PSProvider Registry -Name HKUDefaultHive -Root HKEY_USERS #Load Default User Hive Reg Load "HKU\DefaultHive" "C:\Users\Default\NTUser.dat" #Set OneDriveSetup Variable $OneDriveSetup = Get-ItemProperty "HKUDefaultHive:\DefaultHive\Software\Microsoft\Windows\CurrentVersion\Run" | Select -ExpandProperty "OneDriveSetup" #If Variable returns True, remove the OneDriveSetup Value If ($OneDriveSetup) { Remove-ItemProperty -Path "HKUDefaultHive:\DefaultHive\Software\Microsoft\Windows\CurrentVersion\Run" -Name "OneDriveSetup" } #Unload Hive Reg Unload "HKU\DefaultHive" #Remove PSDrive HKUDefaultHive Remove-PSDrive "HKUDefaultHive" In my OneDrive GPO I had to modify the regs below under User Preferences which fixed the keys for users who had already previously logged into a machine and ran the baked in OneDrive from AppData rather than Program Files HKCU\Software\Microsoft\OneDrive\OneDriveTrigger to C:\Program Files\Microsoft OneDrive\OneDrive.exe HKCU\Software\Microsoft\OneDrive\SilentBusinessConfigCompleted to 00000000
-
Hi, I have just migrated all my Staff and Students from on-prem file storage to OneDrive. I have all my GPOs set up so it logs them in automatically, files on demand, KFM etc. Ideally I would like it so that when they log in for the first time that it doesn't have that delay from having to run OneDriveSetup.exe from AppData for every user. I know I can download and run OneDriveSetup.exe /allusers for a machine wide install but this seems to throw up a UAC prompt when a user logs in. How have other people dealt with moving away from the the per-user install from appdata to per-device in Program Files? If using SCCM or MDT do you put this in your Task Sequence? How do you deal with deploying this for existing users?
-
To help me understand the problem a bit more is there a reason or scenario why a device wouldn't be using the BTLS cert? We have a GPO at the top of our forest which deploys the cert and sets the necessary reg keys and with our schools being from a similar background would have thought yours would be the same. The only devices that don't get the cert are Intune managed iPads which join a different SSID to the main school laptops but we have a separate Netsweeper policy for that and add in the shared lists etc. If it didn't work yesterday but is today is it possible Netsweeper was just having a moment? (wouldn't be the first time)
-
We have had Bing.com blocked on all our Netsweeper policies since the day it was implemented for this very reason and it is still working for us. Is it possible Students are bringing in portable editions of VPN apps on USB drives? We had the exact same scenario a number of years ago and we ended up blocking the use of external drives for students. Also is it possible the Students have discovered a proxy site that for whatever Netsweeper isn't categorising?
-
365, Autopilot and Intune Migration. Good Idea?
craigcamacho replied to craigcamacho's topic in Cloud Services
I have a very very basic Applocker policy in place using the OMA-URI ./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/IntuneEdu/EXE/Policy with an XML string which currently only blocks Microsoft things like Powershell, reg and terminal for Windows 11 which I target at 365 user groups. I think my worry is that the more and more configuration profiles I build up (especially ones targeted at users that apply at login) the more chance of them taking a while or not applying at all. How do you find Intune for this? I don't know if I am going about my profiles the wrong way because I still have my GPO head on but I have a selection of individual profiles such as one that sets Default AAD, OneDrive, Power Options as well as others that are pointed to groups of devices. I then have ones targeted at 365 User Groups like Start Menu customisations, Edge settings, Windows Store settings. Am I right in the way I am doing it or should be changing something? -
Hi, We are currently considering starting to move all our on-prem services to the cloud but starting to question whether its the right thing to do. It would be good to know what other peoples experiences were like when migrating and continue to be on a day to day basis using Azure, Autopilot, Intune etc. Do you find you get any delays in configuration policies applying? One of my worries is that I lock things down on student devices i.e. access to admin apps such as Powershell, cmd and regedit or even access to Settings but the polices don't apply straight away like they would with GPO's and Students have access to things they shouldn't. Also what is the experience with Printing and MIS like and how difficult was it to life and shift these services away from on-prem? If anybody on here is from the NW of England and has move fully away from on-prem it would be great if we could connect and maybe visit your site to have a look at how you are doing it.
-
Hi All, After the whole printnightmare debacle I am still experiencing the issue of the Follow-You print queue not mapping when logging in but its only happening for Students. I map the print queue using user preference in group policy and the same policy is applied to both Staff and Students. When I physically go to the share and try to manually install the Follow-You print queue I get an error message "Operation could not be completed (error 0x00000005). Access is denied". Has anybody else seen this?
-
So, how many passwords have you had to change today?
craigcamacho replied to Dos_Box's topic in General Chat
How are you finding this? I already have this setup but half dismissed the idea of giving all staff access to it because I was worried about the time to sync from AAD to our on-prem AD i.e. member of staff resets password in AAD but the student still cannot log in on a computer for up to 30 mins until it has synced and both Staff and Student assume it hasn't worked and they still end up at the IT office. -
Thanks for your reply. I have done it that way before but only for a couple of apps because i am still relatively new to Intune. Also I guess I do have the option of editing an msi file with something like orca and deploying that with Intune. I think I just have that mindset at the moment with the modern desktop buzz but maybe I don't need to modernise everything and even though MS are trying to push msix maybe its not quite there just yet and not what I need. I think I half knew that before I posted this but wanted other peoples take on msix and deploying apps with Intune.
-
Hi Guys, I have recently setup Co-Management with SCCM and Intune. Because of the pandemic a lot of my devices are now off site for prolonged periods of time. The first workload i have shifted from SCCM to Intune was Windows Updates which obviously when devices are away from site for weeks or months at a time makes perfect sense to do. I am investigating whether shifting the App deployment workload sometime in the future is worth doing but Intune doesn't seem to support App-V packages which most of mine are so there is going to be an element of repackaging. Microsoft seem to be pushing people away from traditional msi and App-V and towards msix so its seems thats the future and would make sense to go msix. Ive setup the msix packaging environment in Hyper-V and its actually really easy to package an application but one thing ive noticed is when i try and create a shortcut in a subfolder in the start menu it ignores it and just dumps it in the root. My current start menu is basically laid out in departmental sub folders i.e English, Maths and then shortcuts to the apps placed in them. Does anybody else package using msix and what are your opinions of it and is it all that?
