Intune
17 TopicsDisable "Windows Hello"
I am an admin, and attempting to disable "Windows Hello for Business" also referred to as 2-step authentication. From what I gather, this option is set as "disabled" by default. I confirmed this. However Whenever I join a device to Azure AD, it is always prompted with "Windows Hello" and to create a pin. Where can I find the option that allows me to disable this?332KViews0likes27CommentsHybrid Join for AVD Hostpool (Pooled)
Hi guys we are new to the topic AVD and are starting with configuring our first Hostpool in Azure. We would like to have a pooled Hostpool with Windows 11 Multi-Session. The users are synced from a On-Prem AD to Entra ID. The personas are pretty simple and just use M365 Apps, FSLogix and 2 Business Apps. I saw in a nice presentation from Marcel Meurer approx. 1 Year ago that having the AVD Sessionhosts in Intune when pooled is not a good idea. We know from Intune that doing a Hybrid-Join for Notebooks isn't a good idea and gives a lot more complexity. What is best practise for AVD in our case? Should we configure Hybrid-Join without having a DC in Azure or is it required to have one also in Azure to be able to configure GPO's or how do you managed the session host's? Configuring a AADDS does give me also more complexity in this case, right? Thanks for your feedback. MarcSolved1.2KViews0likes2CommentsAbility to enrol Win 10 Enterprise multisession to Intune?
Hi all, We've got an AVD Win 10 Enterprise Multisession machine that's joined to Azure AD but we want enrolled to Intune/Endpoint manager. I can't figure out how we can do this on this OS. Any help appreciated - thanks!1KViews0likes1CommentAzure Virtual Desktop and Azure AD Join with Enroll VM in Intune - possible pitfall!
Dear Azure Virtual Desktop friends, If you want to set up Azure Virtual Desktop infrastructure in Azure and you have chosen Azure AD Join and with Enroll VM with Intune, you may get the following error message: -------------------- [{"code":"VMExtensionProvisioningError","message":"VM has reported a failure when processing extension 'AADLoginForWindows'. Error message: \"AAD Join failed with status code: -2145648509. AzureSecureVMJoinOperation: DeviceEnroller::AzureSecureVMEnroll failed 0x801c0083.\"\r\n\r\nMore information on troubleshooting is available at https://aka.ms/vmextensionwindowstroubleshoot "}]} -------------------- This could possibly be because you have reached the limit for adding devices to Intune. You can find this information in the Intune Admincenter and increase the value. Either edit the default settings or set up a new Restriction policy. I realize it's not super, great, extra news, but I ran into these limitations during a deployment and the hints weren't necessarily obvious. Thank you for taking the time to read the article. Best regards, Tom Wechsler P.S. All scripts (#PowerShell, Azure CLI, #Terraform, #ARM) that I use can be found on github! https://github.com/tomwechsler7.1KViews2likes2CommentsAzue AD Device Management
Good day, I am new to Azure; currently moving workstations to the Cloud (Azure). There are several Windows "devices" DT-23, LT-12, that are visible on the Azure Active Directory devices that are duplicates; with a different 'owner' for the device. How would I ascertain which device should be deleted from the Azure AD? There are more than twice as many devices in the Azure AD than the devices in the organization. What, if any steps, do I take to prevent this?476Views0likes0CommentsIntune Windows 10 Security Baseline IE Settings
We have deployed the Intune Windows 10 Security Baseline, which includes the default IE Settings. However, via GPO we have published intranet sites to the intranet security zone via... GPO setting \User Configuration\Preferences\Windows Settings\Registry\IE Settings, which creates registry entries at ...HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap and we also allow our users to add sites to the zones as they deem necessary. This works as expected and has for many years.... However, machines that are enrolled in the Intune Windows 10 Security Baseline have all internet explorer security settings blocked including adding sites... It appears the setting in the baseline "Internet Explorer users adding sites: Disabled" does not function. I have changed this to "Not Configured" and "Enabled" with no change.. the add sites box is greyed out along with all IE Security options... Changing the setting "Internet Explorer security zones use only machine settings" to disabled does allow the sites published via GPO to show and be effective.... We are looking to publish specific intranet sites along with a few internet sites while retaining the ability of our users to add custom sites.... Any Thoughts/suggestions...Solved12KViews0likes7CommentsWVD Hosts and Personal Enrollment
Hi Folks, We have a real estate of desktops natively joined to azure AD. AutoPilot, MDM managed. We also have windows virtual desktop pools with some legacy published apps, one of which requires outlook to send emails. However i believe that running through the outlook profile is prompting the user to enroll the WVD host to intune and is then publishing applications to my WVD hosts and breaking the Shared Licensing for remote desktop because another version of office is being installed over the time. I appreciate i can block personal enrollment, but is there a more graceful way to block this happening on my WVD hosts. Its very annoying. Thanks RichardSolved1.4KViews0likes2CommentsCompliant intune device don't pass conditional access policy
Hey, I'm having problems configuring conditional access for unmanaged and managed devices when accessing ressources. I'm using the prebuild sharepoint CA rules(these are showing up in the CA portal when restricted access is activated in the ahrepoint admin portal under access controll menu) and added the condition that these rules are not applied when a hybrid joined or compliant device tries to get access. Unfortuantely this doesn't work, similar if I use a hybrid joined device or an intune joined compiant device. When I check the login logs in Azure AD I can see that the rules are applied and the fields(managed, compliant, connectiontype) under "device information" are empty so it seems Azure AD can't access the device state from the device itself when ressources are accessed from it. Does anyone know this issue, can reproduce it or have any ideas what needs to be done? Thanks and regards!1.2KViews0likes0CommentsAdding apps to Kiosk using Intune configuration policy
Hi All Is there away we can automatically install apps into the Intune Kiosk? We have over 100 users with Kiosk mobile phones with a selection of apps. All the phones are Android. The problem is we want to add more apps to the kiosk devices without the need for users interaction. I have tested it on a few test Android phones and it looks like the new apps first need to be installed on the devise before they can be added to the Kiosk. You can only install the apps through the Google App Store which can not be done within the kiosk. Maybe I am doing this wrong. Any help will be appreciated. Many thanks Alan1.1KViews0likes0Comments