Jump to content

DavR

Members
  • Posts

    1,930
  • Joined

Everything posted by DavR

  1. Odd that the messages are different, but, it could be that your message is particular to iOS15, as the messages I got for iOS12 and iOS16 were both different wording. So, I logged a call with Meraki first, who hinted there was a known problem with older versions of iOS, and gave me a call ref I could quote. Then I logged a call with Apple, who came back two days later and confirmed that there was definitely a known issue, and that their MDM team is working on it. No timeframe given. But it is almost certainly a fault at Apple's end. They better not be disowning the older devices - some of our oldest on iOS12 I can understand, but iOS15 and 16 I would be pretty hacked off about! Those devices are still with a reasonable lifespan IMO.
  2. Yup, sounds like exactly the problems we've been having. Doesn't matter which way you do a factory reset, it always comes up with an error trying to enrol into the MDM via device enrolment. We're Meraki too, I wonder if that's also a factor. The only way I've been able to reset devices is by taking them out of device enrolment and setting them up non-DEP. What iOS version are the devices you are trying to reset? See below error messages from two of ours, look familiar? If it would help you with Apple support, DM me, and I'll send you a case ref that links back to the known fault.
  3. An update, just in case anyone else is having this problem and/or finds themselves here. Apple support have just acknowledged that there is a current known bug with ADE for legacy versions of iOS, in my case I'm seeing it on iOS 12 and iOS16. I guess it's not creating many waves, as most people aren't factory resetting bunches of old(er) devices. New devices (iOS18) continue to go through just fine.
  4. ADE has been completely broken for us for the last few days, which is annoying as it's this time of year I wipe our shared iPad sets fresh for September. Every device I reset gets to the startup assistant, but then fails when it comes to enrolling into our MDM (Meraki) with either "Unable to Download Profile Configuration" (on iOS16) or "The Configuration is not available" (on legacy devices). This is stuck on a loop, we can go no further. I did accidentally let our ADE token expire, but fixed this, and still no dice. I've even deleted and recreated the whole ADE service in Meraki and Apple School Manager, but it's made no difference. They're talking to each other fine, but, I'm just always getting this message when I try and put a device through ADE setup. I've got Meraki support on the case, and they suggest that Apple may be having a problem with ADE for legacy versions of iOS lately, and have asked me to collect logs that I can't collect, due to being a startup loop. Has anyone else had any experience of this lately?
  5. Thanks @IAMCloud_Curt, I managed to work out the whole Delta thing OK. I agree though, having the API notify changes rather than sending endless requests, I suppose the programmatic equivalent of leaning on the F5 key, is the way forward if it can be made to work. Will this new mechanism appear in a coming version of V3, or will it be V4? And is there somewhere we can sign up to hear about such version upgrades?
  6. Thanks, that's good to know. I've been using mail merge from documents on a mapped drive successfully now since @speakercon mentioned it earlier in this discussion, and we're on v3.17. I don't share my mail merges though, so haven't come across the problem mentioned above. Has the latest version also managed to fix the issue with hyperlinking to folders on a CDM mapped drive? Similar to what's discussed above, if I try and hyperlink to a CDM mapped drive location, it links to the underlying \\IAMCloud\u34567 type address, not the simple S:\folder\directory address. Not the biggest problem, but it's useful being able to hyperlink to folders from an email (for example). I'll be testing the latest version in the next few weeks ahead of a summer rollout, fingers crossed.
  7. On a shared environment, it's OK syncing just the OneDrive IMO, assuming the user's OneDrive isn't too big. But even then, it can be a bit slow and miss files. I wouldn't go near using it to sync other libraries, such as SharePoint shared drives. It's designed for 1:1 and works much better in that scenario.
  8. Thanks, I will play with that. We never had any issues with throttling under v2, so we can definitely shave some time off that delay I reckon.
  9. This looks essentially like the same method as mapping SharePoint libraries via OneDrive and Group Policy, unless there's some extra capability I'm missing? This sounds like a great idea in theory, but we found it to be no good for us, using very large SharePoint sites and a lot of shared devices. The sync just couldn't keep up with the volumes in the times demanded.
  10. I've noticed version 3 does take a while for drive listings to update, although it's not something I've had time to investigate yet, or even put into the correct form of words. It's a bit of a nuisance, given the selling point for us in v2 was that access was always LIVE to the folder share with no lag and caching, but I get why that's not always possible. @itskdog do you have a link to info to control how often CDM v3 refreshes it's folder listings? We've noticed an increase in ActivInspire files corrupting too, but again, it's not something I've been able to link to any pattern just yet. I was rather hoping deploying the latest version in the summer would resolve it (the blind faith approach...).
  11. The Dymo sticker fell off.... FFS!
  12. Glad to hear it @mdrabble. You're very welcome 😁 Re the WiFi, when you get a chance, this is dead easy to do as a settings profile - https://learn.microsoft.com/en-us/intune/intune-service/configuration/wi-fi-settings-configure SIMS .Net though.... yeah, I remember that being a pig to install.
  13. I was thinking of going down the USB stick route for our setup, as either that or using the factory deployed OS image seems to the supported configuration these days. But I'm keeping hold of MDT for OS deployment for now, USB installs seems a backward step. It's obviously fixed something in your setup though, so can't complain there! Classic Intune deployment 😂
  14. DavR

    Intune

    We deploy our wireless settings to laptops, and we do this during initial setup (I normally re-image them with a LAN connection, to avoid ever having to have to enter the wifi details manually). For us, that puts all of our Intune laptops on the same SSID. You could put a base wireless policy on, that gives a basic level of access, and then deploy additional wireless policies based on users and groups. But, given how ponderously slow the user-side policies are, I wouldn't rely on it. You could be waiting an hour at a time for the wireless SSID policy to catch up with your change of user. In short, I don't think this is something you'd be easily able to achieve with Intune directly, you'd want another technology to allocate different users different SSIDs. What are you trying to achieve by putting different laptops on different SSIDs? If it's just different levels of Internet access, does your filtering solution have any AD / AAD group aware features to grant different levels of access?
  15. Sounds like the logic of your process is correct, at least, so that's good to know. Best of luck with the troubleshooting!
  16. I finally got a chance to test this with an extra graphics card in place, to replace the VGA splitter. After a brief suggestion that it might resolve our issue, no change 🙄 Our outputs are now VGA (projector) and DVI (monitor), with duplicate display set on the PC: If I turn PC on first, then the projector, duplicate display works perfectly If I turn on projector first, then PC, the projector doesn't detect the VGA input correctly, and I have to do a scan using the remote control to fix it. It's a minor issue in the grand scheme of things, but, because staff don't realise, they try and re-size the projector screen to match, and always b****r it up. There is a second VGA line up to the projector, I may experiment with that when I can get the ladders out during the summer, just in case the PnP line in VGA1 is damaged. Til then, I'll have to make do with a big Dymo tape sticker that says "PRESS SOURCE SEARCH" to fix display issues.....
  17. I wonder if it's delivering the wrong ESP page? You could try making a visible change on the default page, and seeing if that's the one that comes up first time round. Maybe your custom ESP page need to be deployed to users as well as devices. There aren't many settings in that ESP page - you could drop the custom one and put those into the Default, and see what difference that makes.
  18. This is a long shot, but do you have more than one ESP page configured? Could it be you're getting the system default ESP page, because the one you want to run is published to a device group that is not yet populated? I'm still thinking it's something around device groups / Intune membership not being "there" or correct in time. But that doesn't explain why apps you've deployed to All Devices aren't showing up.
  19. We're doing this by using the Device Enrolment Manager account in Intune to enrol the device. This means all of the install stuff happens during the DEM login, and then when that's completed, it's ready for a regular user. You may want to change or remove the primary user in Intune, but that's it. You may have to change restrictions on Entra-join numbers, but look at the reference page linked above. In practice I think each DEM has something like a 1000 device limit. Edit - just realised that you're trying to do this with Entra hybrid devices. Any reason to try and use hybrid join with Intune rather than go pure Entra join?
  20. This thread on Reddit seems to describe a similar problem to yours. The solution proposed seems to be "disable co-management".
  21. I wonder, for testing, could you put a delay then a reboot, between the hashed uploading in your TS, and the user logging in? I wonder if this might give it time for the device group memberships to complete. Alternatively, I suppose it could be that Intune membership "proper" doesn't complete until after the OOBE runs. Would be a pain if that's the case, but I wouldn't discount it yet.
  22. Honestly, I've had apps working just fine, that then started to cause errors when running during ESP, it's a pain. The latest batch I had were some print drivers, which didn't fail, they just hung, and hit the 30 minute timeout I had set on the app. Could timeouts be your issue rather than hard errors? Here's a thought - you can look at which apps have failed to install in the Intune console. It can take a little while to register, but under individual apps, you can look for install failures, and the error codes attached.
  23. Long time Veeam user here - Yes, you do need to complete to wizard for the file level restore, before it will allow to choose the files you wish to restore, they come up in the next wizard. Nothing to do with local, cloud, or whatever, that's the behaviour whatever you're doing.
  24. You may also find this page in your M365 console useful, telling you when your last sync ran. https://admin.microsoft.com/AdminPortal/Home#/dirsyncmanagement
  25. Are you installing your Windows 11 devices into a domain first, and then syncing them with Entra to achieve Hybrid joined devices, or do you have a method in place that does a straight Entra only join? If the former, I'd say it's probably the config of your sync tool, somewhere along the way, rather than some hidden script in the Windows 10 image. The Azure AD Sync tool can be targeted to OUs, so if your WIndows 11 devices are in different OUs to Windows 10, it's probably that. Have a look on your Domain Controllers, and see what the properties are for the Azure AD Sync Tool. If you've done nothing with it recently, you may also find that the tool itself needs upgrading.
×
×
  • Create New...