Jump to content

foofighterjim

Members
  • Posts

    1,672
  • Joined

Everything posted by foofighterjim

  1. Just to be clear, from what I understand (and please correct me if I am wrong), they are only removing the ability to create dynamic groups based of the "member of" other groups. This does not prevent you from nesting groups, for example you could have a dynamic group for users of school x and another for users of school y, they could then be nested together in a separate "assigned" group for all users, you could even skip this requirement by making the all users group a dynamic group with the same query used for the aforementioned groups. We used nested groups for everything from Configuration Profiles to App Assignments and don't have any issues with deployments. It could just be my use case, but I really don't see this as much of an issue.
  2. As far as OneDrive is concerned, the desktop is just another folder, just like Documents and Pictures; it is covered by KFM, files on demand and will be backed up with your OneDrive backup. I've not seen the need to prevent this since moving to OneDrive storage.
  3. Worth checking the Sign-in Frequency setting under the Session section, if not specified it will not prompt for MFA unless they have been inactive for 90 days on a device.
  4. It has been a while since I did a LOB app as Win32 apps have basically superseded this. In LOB, do you have the ability to update the version number of the app? This should make the devices check in for updates, although they still may not run the installer (and therefore your switch argument) again.
  5. Have you tried one of the other methods that are also supposed to keep the enrollment i.e. Autopilot Reset instead?
  6. Did you get anywhere with this? the quote above would make me question if the hybrid join was a red herring.
  7. I may have misunderstood, but if you are cloud only, why are you using user-driven Entra Hybrid join? This implies that there is a local AD for the device to connect to, unless you have also selected to skip AD connectivity check as part of the deployment profile (not sure why you would do that though)?
  8. The only other time I have seen anything like this is if there is an account lock policy set that is shorter than the power setting.
  9. Is there another policy in conflict that may have set this to 10 minutes previously?
  10. Not a bad idea, although that would involve a lot of groups for us, come September we are will have over 4,000 students and 500 staff on our tenancy. Still, it is something to think about and we can possibly automate creating some of this with Salamander. As for the time based groups, we're cloud only.
  11. I have been looking at this off and on for a while now, but just can't seem to crack it. I have a technician who uses admin.microsoft.com for day to day management of users, we leverage PIM if they need to do anything more than password management. What I would like to do is, allow them to access to the OneDrive tab (and the URL) for user accounts. Initial reading suggested that granting the SharePoint Administrator role was what was required, but unfortunately they still get access denied when navigating to the OneDrive tab. After delving a little deeper, it looks like with the SharePoint administrator role, they can search for the account within SharePoint Admin and then modify the accounts OneDrive permissions to grant themselves access, but this doesn't scale well if they need to do this several times a day, not to mention making sure the permissions are removed again afterwards. From what I can see, it only appears to be GA's that have the ability I am looking for, I have reviewed the GA permission set, but I can't see the specific Role permission (or combination of) that actually makes this work, as I could then add this into a custom role to keep the level of privilege down. Just to clarify, this is what I would like the technician to be able to access:
  12. Did you select the option of "All Devices" or just a group that contains all of your devices? I tend to refrain from using the former.
  13. We have just issued guidance for staff to stop using the New Outlook client now, we have had two separate issues in our office with it in recent weeks. The first one actually happened to me, I had the client running and I was working as normal, I was sending emails but wasn't receiving any replies, I eventually opened Outlook in the browser and there were about 20 emails that had been delivered to my mailbox that hadn't come through to the client, everything that I had sent had gone out though, closing and opening the client made the messages appear. Another issue happened to a colleague, they were sending emails last week to someone else in the office, but they weren't received. They checked their Sent Items but could not find the emails, the emails were eventually received yesterday, all in one batch, nearly 6 days after they were "sent", I ran a message trace and Exchange delivered it as soon as it received it. I have absolutely no reason to doubt the user concerned and they wouldn't have written the email again as it was time sensitive, leaving the finger pointing firmly at New Outlook.
  14. foofighterjim

    Gaming Chat

    I've been working my way through the Final Fantasy Pixel Remasters, Despite what people say about it I actually quite enjoyed FF2, particularly if you level up the way the developers intended, rather than gaming the system.
  15. I can't comment on if it is "right", but we also see the same. We also get the same behavior for the Configuration Profiles, so it is just Intune being Intune.
  16. Effectively yes, everything at the device level. You could look into using Company Portal to allow users to pull a specific application to a device but that really is geared more towards the 1:1 devices.
  17. It was at one of the last seminars that I attended that Ranulph Fiennes was one of the speakers. He was mainly promoting his book but it was still fascinating nonetheless, I even had the chance to have a brief chat with him at the end, definitely would never have met him otherwise. Also remember attending my first seminar not long after starting in education. I went to the backup session and realised the stupidity of us keeping the backup tapes on top of the server, and at the same time the relief that 90% of everyone else in the room had been doing the same up to that point.
  18. Only thing missing in the New Outlook that I've actually needed was the ability to export mailboxes to a PST file, only work around was to get a device and revert back to the classic version of Outlook.
  19. Intune is fine but you basically need to forget about user level policies, settings need to be at the device level for them to be applied reliably. So, shared devices can work without a problem, but everyone that uses them will have the same policies apply, in our scenario this lead to two device types; staff and students.
  20. +1 for scan to Email
  21. Interesting timing, I had quite a long conversation with Dell at BETT that it was disappointing that they only had a 10" screen Chromebook in their range, as with VI step one is usually a larger screen and then accessibility solutions on top of that. Acer on the other hand had a brilliant range of different types and sizes of Chromebook.
  22. A colleague has come up with this as an option: https://www.amazon.co.uk/Verbatim-Transmitter-Streaming-Transmission-Smartphone-gray/dp/B0CRL7HFWV?th=1 Might give it a try at that price point.
  23. Looking for recommendations on the best way to achieve this. We have a screen in our conference room that we need to wirelessly display to, but we don't want it to be discoverable on the network as a whole (this obviously rules out network based broadcast devices like Chromecast and Apple TV). The solution would need to work on predominantly Windows devices, but preferably not need an application installing on the device, as guests probably won't be able to install software on their devices. I've done lots of reading but can't really find a product that ticks all the boxes. All suggestions welcome.
  24. Yes, I moved my previous school to Cloudflare back in 2023, they were on the standard school domain. I don't recall having any issues getting the domain setup on there at all, although that may have been helped by the fact that the domain hadn't been hosted by the LA but by our ISP for a number of years prior.
  25. I'm due down tomorrow, if the trains are still running anyway, forecast isn't looking good.
×
×
  • Create New...