Jump to content

NicholasEsping

Members
  • Posts

    165
  • Joined

  • Last visited

Everything posted by NicholasEsping

  1. All I do to update an email address in office 365 is change the proxy address in our local ad and sync it to office 365 SMTP:email for primary smtp:email for aliases. Not sure if that is what you are trying to do.
  2. What we do is set a retention policy so if a user deletes items out of their mailbox they are still retained within office 365 and you can find them using a content search as a global admin. In office 365 if you go to Security and Compliance\Information governance\Retention This policy can apply to just exchange or you can set it for. Onedrive, Sharepoint, and groups as well. Education customers have the ability to retain information forever.
  3. We do not have these issues with Set up school PCs app. I am guessing you are trying to remove apps pre-installed by the device manufacturer. Enabling that setting increased the set up time by a lot for us. We use the USB stick to set the wifi network, change the pc name, set the Azure domain name, and add backgrounds. This takes approx. 5 minutes. For office we add that to the image using DISM and other apps we deploy though intune.
  4. I just checked our licenses and it looks like it got moved into the Office 365 A1 Plus license which is also free for education. For that error I would just uninstall the old dirsync and install ADConnect and set it up the way you need.
  5. Unless the AppLocker policy is assigned to everything I would just image the computer in a different OU and them move it when done.
  6. I could be wrong but I believe that is the global spam filter. Exchange Admin Center/Protection/Spam Filter
  7. Azure AD Basic is available for free to Education Customers and then you can install Azure AD Connect on a server to sync up your Active Directory users and devices to intune.
  8. I believe the GPO you are looking for is under User Configuration/Windows Settings/Folder Redirection. From there you can go into the properties of each folder and choose how you would like to redirect it in the past I have used the basic setting and then for target chose Redirect to the following location and in the settings tab chose Move the contents of Documents to the new location. This should save the files to the network share and keep them off the local hard drive.
  9. My guess is your redirection is not happening. The policies listed would not prevent someone from savings to c:\username\documents for example. Those policies will prevent users from saving to the root of c:\username and prevent users from seeing the c: drive.
  10. I believe Office Lens is only available through the windows store and on iOS and android. We moved to intune which allows deployment of store apps but we used to have the store allowed for students and used applocker to block and allow the apps we wanted the students to be able to use. This allowed them to browse the Microsoft store but only install what we allowed.
  11. You can update the upn in office 365 by using the following powershell. I would verify that the UPN, proxy address and target address are all correct in AD and then just update the office 365 UPN so it matches your local AD. Connect-MsolService Set-MsolUserPrincipalName -UserPrincipalName [email protected] -NewUserPrincipalName [email protected]
  12. iPads can be removed from DEP. If you are going to sell or recycle your iPads you should definitely release them from your DEP.
  13. I am not sure what it is trying to do at this point but when we were first starting out with intune we played around with autopilot and found that using the set up schools pc app worked better for us. The main issue we had with autopilot was every user was an administrator on the computer which might not be the case anymore. With set up schools USB sticks only users with administrator rights in Office 365 are admins on the computers. The other big benefit to using Set up schools is when the users get their device they are ready to go the USB stick takes care of enrollment into azure, installing some basic apps, setting backgrounds,etc. After the user logs in the computer will check into intune and pull down any additional profiles that are assigned to the user. Here is a link with some more info on Set up Schools https://docs.microsoft.com/en-us/education/windows/use-set-up-school-pcs-app
  14. I believe that policy will only work with Windows 10 enterprise or education. With Pro Microsoft decided to take away a lot of the useful GPO settings. Applocker also will not work with Windows 10 Pro see this article here https://social.technet.microsoft.com/Forums/en-US/5fe97abe-dcfa-4349-ad0d-8a647acfc331/applocker-in-windows-10-pro-1803-does-not-seem-to-work?forum=win10itprosecurity Your best bet is going to be an upgrade to enterprise or education if you want to make use out of all of the Group Policy settings.
  15. I would recommend going with windows 10 education instead of pro so you can make use of all group policy settings.
  16. You will want to install the company portal app with VPP. To do this make sure you have a VPP account set up, the company portal app purchased in VPP and the token set up with intune. You will go to device enrollment>enrollment program tokens>select your profile> open the properties. Under Authenticate with Company Portal instead of Apple Setup Assistant you can Install Company Portal with VPP.
  17. Im not sure if I totally follow you on this one and we don't use clever badges but do use clever and have SAML from azure with clever and GSuite setup so I'll try my best to help. The password stored in google should be irrevelant becuase with SAML setup it will use the SAML provider to authenticate the user and the password stored in google is pointless. It sounds like you changed the identity provider in GSuite from using azure to using clever so when logging into the chromebook you should not expect the azure login page but the clever badge page or clever login page. If you go to clever.com can you log into the site with the clever badge or what options does that give you when you select your school?
  18. The attribute you choose doesn't really matter as long as there is a match. For our orginization user.mail and user.userprinciplename are the users email address so it does not matter what attribute we pick to make the match. For us with google we use user.userprincipalname and for clever we are using user.mail but again it really doesn't matter if both attributes are the same. What we do to get users into clever is a oneroster sync from our sis.
  19. I believe so. The only change the user would really see would be when they type their email in at the Gsuite login page it will redirect to your office 365 tenant for the sign in. If you have SSO set up I beleive it will just log them in. All of their Gsuite files setting emails etc would remail unchanged.
  20. Depending on how you set it up there passwords will not change. You can set this up to just provision users or you can also set up SAML authentication to have your GSuite users sign in with their Office 365 credentials. If you go the SAML method your current users would need to start logging in with their Office 365 credentials.
  21. We have no issues with allowing the Microsoft store. If you have disabled the store it will cause a security risk because none of the store apps will receive any updates and that incudes apps like calendar and calculator which are installed by default. We force the private store and also implemented app locker through GPO to allow and deny apps we want on the devices.
  22. Users were able to use their own email because there was no ownership of the domain for the office 365 tenant. Once you verified ownership that would have stop users from being able to provision their own accounts.
  23. Whether or not it is necessary will depend on your local laws regarding information requests but this is totally possible to do with office 365. In the security and compliance center you can do a content search that will search all emails in your organization based on the keywords you choose. You can also select other conditions such as date, size, subject, etc.
  24. In the security and compliance center in office 365 you can enable retention settings that will keep a copy of emails, onedrive documents, etc for the amount of time you specify.
  25. oops here to go: https://www.tenforums.com/installation-upgrade/110119-how-enable-s-mode-windows-10-a.html
×
×
  • Create New...