deano
Members-
Posts
382 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by deano
-
Have a look at Storage Sense. This is the best option to keep storage down on devices
-
Microsoft Intune Endpoint Protection- Login text
deano replied to EssentialRug's topic in Cloud Services
Not too sure that the Pro to Education will make a difference. I was thinking more about the Windows 10 Feature version (1909 etc). Some settings of Intune are only applied to devices with the latest and greatest feature of Win10 -
Microsoft Intune Endpoint Protection- Login text
deano replied to EssentialRug's topic in Cloud Services
Same win 10 version? -
Shared PC mode disables the use of OneDrive sync. I get the reason but MS should really give us the option to turn it on or off. I enabled the reg keys to turn the sync back on, however have noticed that second logon an error shows for OneDrive. One the OneDrive sync starts up the error disappears
-
MS are against the use of any local accounts due to security. I'm not using as any issues then I will reset the device and so again using autopilot. Have you looked at the admx backed policies? https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider Anything with admx_xx are for Windows insider preview build only, however will be implemented by MS after testing. How have you got on with locking device down? MS are working on hide drive CSP policy in preview and I have used applocker scripts to stop exe, MSI etc.
-
Not tried yet, but found this https://www.lieben.nu/liebensraum/2019/06/simplify-logon-scripts-in-intune-without-schedules/
-
Whilst the InTune.Training mentioned script works, in my testing I have found an issue. If the user say had an issue and I removed the user's local profile, when they log back on the script won't run again. In order to get the script to run again, you either need to modify remove script from within InTune and re-apply, or remove reg keys on device for InTune profiles. This was temperamental in my testing. I think scheduled task is best way forward, however not sure how to get a script on device through InTune and how I can get two different scripts called depending on user logged on e.g. staff team for staff, student team for student?
-
Personal Device InTune Management + Azure AD Registered Devices
deano replied to foofighterjim's topic in Cloud Services
Its more than likely because the previous settings are now not applicable in the new structure. I personally would open a ticket with Microsoft through your Office365 portal -
Personal Device InTune Management + Azure AD Registered Devices
deano replied to foofighterjim's topic in Cloud Services
Yes it is expected behaviour im afraid. You can restrict it somewhat using the attached link, but it will be the device limit restriction that you will be wanted to alter. Be aware though, this is global and will affect yourself and other admins on joining devices to Azure AD. https://docs.microsoft.com/en-us/mem/intune/enrollment/enrollment-restrictions-set -
Try Dataspire.co.uk The headquarters are in Manchester but have roaming engineers based in Midlands
-
You can manage the Windows Hello within the Enroll section of Intune. Its under Devices menu. Another thing to check is whether Require MFA to join devices is enabled. Log into Azure Portal, open Azure AD. Click Devices and then Device Settings from left side. I think this is now off by default but used to be on previously. If not used, i would recommend enabling Enterpise State Roaming from the same section. https://docs.microsoft.com/en-us/azure/active-directory/devices/enterprise-state-roaming-overview And yes, Intune licence is required per user
-
Then i think the next thing to ask yourself is what options you need from an onsite service, as this guide you on product/s and service. Do you want something bundled into the broadband that you dont own and have reduced access, or a broadband that only line and you plug in whatever firewall/filtering you want? Another question to ask, given the Pandemic and home learning, do you still want to manage filtering for schools devices regardless of location? If you do, then something like a Smoothwall can do this through Global Proxy or Connect for Chromebooks. There are other ways of providing offsite filtering/safeguarding such as Securly/Lightspeed/Impero Web:Check/Smoothwall Cloud Filter etc. however these are an additional cost on top of your filtering/firewall costs. Whereas the Smoothwall local option is included in your licensing. The only pro really of using a third party option for offsite filtering is that these are cloud based services with resilience and scalability for endless number of devices. The Smoothwall solution on site would require uptime of your firewall and internet to provide the service, as well as scaling for the number of devices.
-
This may be your issue then. The Self Deploy is still in Preview at this time at has certain requirements of the device, such as BitLocker TPM 2.0 etc. I would try removing the assignment of the profile for self deploy, and create a new profile with User Driven. Assign this to all devices and give it about 15 minutes. Then try kicking a device off again, which may have to be a device that has not been attempted before as the old InTune profile will have been pulled down to the failed device.
-
How have you configured the deployment profile for AutoPilot? Is it user driven or self deploy?
-
Have you tried on a unfiltered internet line? Also what autopilot enrolment profile have you configured, user driven?
-
are you using a seperate server for the gateway? Either way you need to port forward 443 to the server with the gateway role installed and then add an external record in your DNS provider to that external IP.
-
I presume you can browse to the login page remotely through the external DNS and port forwarding configured for 443? No config should be needed on the NPAS and you will also need to get a cert of some kind installed
-
Use a proxy PAC file and the DHCP options. It's not the best option but will work if you cant use a transparent proxy.
-
Internet speeds through smoothwall server
deano replied to Badaz52's topic in Internet Related/Filtering/Firewall
Turning features on Smoothwall will slow speeds, such as decryption/layer 7 etc. Also worth mentioning what’s running the Smoothwall. If it’s an appliance, then they they throughout maximums depending on model used -
worth also noting i had a similar issue to this before and after two days of troubleshooting i decided to blow the server away. This resolved the issue with exactly the same settings and deployment. REALLY IMPORTANT - if you do the above, make sure the devices are on and update GPOs straight away. I didnt and my devices were unable to talk to the domain anymore as the NRPT address was pointing to old IPV6 address. The solution is to locate the reg key below and delete the key for you internal domain. Restart the machine and then it will now connect to domain (HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient\DnsPolicyConfig)
- 16 replies
-
- direct access
- server 2016
-
(and 3 more)
Tagged with:
-
The IPHTTPS interface is not operational, last error code is 0x80190194 This looks to be your problem.
- 16 replies
-
- direct access
- server 2016
-
(and 3 more)
Tagged with:
-
62000 is required inbound and outbound from client to server. See below snippet from MS IP-HTTPS—Transmission Control Protocol (TCP) destination port 443, and TCP source port 443 outbound. When the DirectAccess server has a single network adapter, and the network location server is on the DirectAccess server, then TCP port 62000 is also required. Also, make sure firewall is not disabled on server and clients. You can turn off domain firewall but need public and private on
- 16 replies
-
- direct access
- server 2016
-
(and 3 more)
Tagged with:
-
You mention port 443. Have you also allowed port 62000 through firewall as well?
- 16 replies
-
- direct access
- server 2016
-
(and 3 more)
Tagged with:
