NicholasEsping
Members-
Posts
165 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by NicholasEsping
-
WDAC and Manually Installed Software Failures
NicholasEsping replied to petben's topic in Enterprise Software
In this scenario what you would need to do is create catalog files to allow the unsigned code. Deploy catalog files to support App Control for Business | Microsoft Learn -
Preventing student access to external shared documents
NicholasEsping replied to enjay's topic in Cloud Services
Depending on how your web filter works you could block sharepoint.com and onedrive.live.com and then add a allow rule that allows https://schoolname-my.sharepoint.com. -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
That would probably be the better way to do this, and I really should switch it. Since we already needed to deploy AppLocker to make the Managed Installers work I just left it in the AppLocker policy. -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
Here is my appx xml. I use the local group policy editor to create this on a test computer and then export the xml to push out with Intune. <AppLockerPolicy Version="1"> <RuleCollection Type="Appx" EnforcementMode="Enabled"> <FilePublisherRule Id="0a45d15c-5033-48fa-88c1-d1d2d875b511" Name="AdobeSystemsIncorporated.AdobeReader, version 0.0.0.0 and above, from CN=553ADC34-E6D7-49F5-B450-3BCAE6182ACB" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=553ADC34-E6D7-49F5-B450-3BCAE6182ACB" ProductName="AdobeSystemsIncorporated.AdobeReader" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="28ee9e16-1d2a-470f-be7a-7449242ce033" Name="Signed by 3CX Software DMCC" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=FB532F09-9100-4C71-89EC-9FE6CFC37A83" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="3a25d9df-87fd-4538-a24c-e33e61f61bf0" Name="PearsonEducationInc.TestNav, version 0.0.0.0 and above, from Pearson Education Inc" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=064058AF-B77F-42B8-82D3-37A4EFB14996" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="3d68107b-186e-45c3-b875-79b370d05d82" Name="McGraw-HillEducation.McGraw-HillK-12ConnectEDMobil, version 0.0.0.0 and above, from CN=40CD84DB-C8D5-4A33-9354-6243F1A9EDA6" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=40CD84DB-C8D5-4A33-9354-6243F1A9EDA6" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="5b24053c-4f9c-4358-a308-e49f9ff3d165" Name="AdobePhotoshopExpress" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=553ADC34-E6D7-49F5-B450-3BCAE6182ACB" ProductName="AdobeSystemsIncorporated.AdobePhotoshopExpress" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="721f1150-1e95-4c94-afae-480a8cc28b69" Name="Signed by INTEL CORP" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=EB51A5DA-0E72-4863-82E4-EA21C1F8DFE3" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="75c4e5fd-44ae-4e0a-9fd4-a0d18e569ea2" Name="Duolingo" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=FFBE6978-4D2C-4598-A465-8F4DB11260AC" ProductName="D5EA27B7.Duolingo-LearnLanguagesforFree" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="7ff9438e-e9e8-4989-83dc-f55afa7c6d94" Name="Signed by Data Recognition Corporation" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=B603712B-3BB5-48D0-8DD4-5EF501685EFC" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="828c8b94-c536-4fe5-a9f0-661985bbff2a" Name="Signed by HP Inc." Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=ED346674-0FA1-4272-85CE-3187C9C86E26" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="8738e104-5a12-41d3-a711-0993b319232b" Name="Signed by Microsoft Corp." Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=33F0F141-36F3-4EC2-A77D-51B53D0BA0E4" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="94acd254-3656-4e27-82c7-2398a515c393" Name="Signed by Apple Inc." Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=5BD5593D-A41B-4F89-884E-B4F3E0FBAA75" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="bbafb65c-20f2-49a5-b5fe-fa6810b28848" Name="Signed by Notepad++" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN="Notepad++", O="Notepad++", L=Saint Cloud, S=Ile-de-France, C=FR" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="bfc529c0-8dce-43ee-add0-ae6dd3d3985f" Name="Signed by Realtek Semiconductor Corp" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=83564403-0B26-46B8-9D84-040F43691D31" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="c96e4c83-1eb2-46ab-82b6-261db96d44c8" Name="All signed packaged apps-Microsoft Corporation" Description="Allows members of the Everyone group to run packaged apps that are signed." UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="ddb44d11-2ce1-431a-96a6-ebded18f935e" Name="All signed packaged apps-Microsoft Windows" Description="Allows members of the Everyone group to run packaged apps that are signed." UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="0.0.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> <FilePublisherRule Id="e8947f11-2d60-47f0-a998-2b6130f33cfb" Name="Signed by Pearson Education Inc" Description="" UserOrGroupSid="S-1-1-0" Action="Allow"> <Conditions> <FilePublisherCondition PublisherName="CN=064058AF-B77F-42B8-82D3-37A4EFB14996" ProductName="*" BinaryName="*"> <BinaryVersionRange LowSection="*" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> </RuleCollection> </AppLockerPolicy> -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
For store apps I just use an AppLocker policy to block/allow the ones we want students using. I ran into that same issue with my policy and found it a lot easier to just use AppLocker then try to block/allow them in the base policy. -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
Yes, I do Merge with the recommended block rules. Here are the options I have set in my policy. I used to have Dynamic Code Security on, but it started causing problems with our web filter functionality. -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
Yes, it should since Winget will be launched by the Intune management extension when deployed with Intune. If it's an app that auto updates you might run into issues when it updates if the updater is not a managed installer. If you control all updates through Intune, you should be fine. -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
Once you have the managed installer option set in your WDAC policy you can enable the Managed installer in a couple of different ways. There is an option in Endpoint security that will set the Intune Management extension as a managed installer. Otherwise, you can create your own AppLocker xml that can have additional managed installers. For example, I made our web filter a managed installer, so it is able to update everything without any issues. I then deploy this policy using proactive remediations. Here is the Microsoft documentation on creating managed installers and a GitHub page with example detection and remediation scripts. Allow apps deployed with an App Control managed installer | Microsoft Learn scripts/remediation.ps1 at main · ne8801/scripts · GitHub -
Windows Defender App Control (WDAC) and Papercut
NicholasEsping replied to petben's topic in Enterprise Software
Do you use managed installers? You might be able to just deploy the papercut client using Intune as long as the Intune management extension is set as a managed installer the WDAC policy should allow the application to run. I use WDAC on my student devices but do not currently have papercut. I was able to deploy MyQ which is a different print management solution with this method. -
I use proactive remediation to update my managed installers for WDAC. This uses AppLocker so you should be able to modify this with your AppLocker policy if you have access to proactive remediations. You could also do this as a win32 application if you do not have access to remediations. ne8801/scripts
-
Issue with a single user access to Office.com HELP !
NicholasEsping replied to 2097's topic in Cloud Services
Have you tried updating the proxy and target address to the SMTP:[email protected] format? I have not seen office 365 work with only x500:/o=ExchangeLabs listed for these. Also do you see any sign in attempts in their sign in logs when you are getting the username/password error? -
We have A5 here so it could definitely be a license thing, but I think that would be a weird setting to lock behind a license.
-
I can do folders as well. My sharing settings are set to Most permissive for both SharePoint and OneDrive and we expire the links after 90 days. I am not seeing any check boxes or anything related to the Password box.
-
-
We do not require MFA to access Company Portal or apps like OneDrive and office. We do require MFA if they are using a device that is not owned by the school though. I would recommend looking into your Windows hello for business policy. Whenever I have enabled that it has tried to force MFA to be set up for all users in our tenant.
-
I am not aware of any videos that would be helpful. I mostly just use Microsoft's documentation. Application Control for Windows | Microsoft Learn
-
We do not use either of these methods for log on. What we do is set up all computers as shared use in Intune. This allows all users to access the company portal and install applications that are assigned to them on any device they log into. For OneDrive we set the sync with Intune policies for on-demand files, so it does not fully sync the user's library.
-
How are you deploying these? Windows 11 first log on for us takes 30 seconds at most. Our image is pretty basic we preload office and set our application control policies then capture and deploy using FFU images.
-
App Control for Business is WDAC. We use WDAC but not the App Control for Business method since that did not exist when we implemented it. We use OMA-URI to deploy our WDAC policy and then use proactive remediation scripts to deploy the managed installer options in AppLocker. This allows us to easily add additional managed installers as necessary.
-
Intune Line of Business App - Command line arguments update
NicholasEsping replied to Bankesy's topic in Cloud Services
I would suggest packaging as Win32 and write a PowerShell script that checks for the license in the detection methods. -
From my experience Intune's configuration settings for power plans don't always change the sleep and display timeout settings unless they are defined in the policy.
-
I believe Intune does not change the sleep and display timeouts when changing the power plan unless you specify the timeouts in the policy from Intune. What I do for devices that need to Remote desktop is exclude them from the policy so the user can set the timeout to never.
-
iboss - looking for real k12 reviews
NicholasEsping replied to Digitaltek's topic in Internet Related/Filtering/Firewall
Yes, filtering and reporting are working great for us here. Admittedly, I don’t have much to compare it to, as we’ve been using iBoss for several years now. -
iboss - looking for real k12 reviews
NicholasEsping replied to Digitaltek's topic in Internet Related/Filtering/Firewall
We currently use iBoss in our district, with both their onsite appliance and cloud setup. Over the next year, we plan to phase out the onsite appliance due to its 1 gig connection limit. Fully utilizing the cloud will allow us to maximize our ISP speeds. Our district includes approximately 500 staff and 2700 students. We primarily use Windows devices for staff and students in grades 3-12, while iPads are used in pre-K through 2nd grade. We deploy iBoss cloud connectors to all Windows devices, which work great both on and off-site. For iPads, which are not sent home, we currently route traffic through the local appliance. However, iBoss offers a cloud connector app for iPads that can proxy traffic to the iBoss cloud. We do not use Chromebooks, so we do not know how well iBoss works with them, but they do have a connector for them as well.
