entra id
5 TopicsDynamic device group from InTune user groups
We've onboarded a number of users into InTune, and we're all new to it. Previously, they were on MaaS360, which had both device groups and user groups, and you could assign to either individually. A bit shocked InTune can only assign down to the group level. (I know Filters exist, but these only filter by Devices, and take longer than just creating a new group)... Anyway, trying to rebuild things as closely to MaaS as possible. For onboarding, we created user groups, so when a user enrolled, they would automatically get the right policies. We couldn't create a device group until the devices were enrolled AND logged in, and showing in Entra. However, the tenant actually wants the groups to be by DEVICE for various reasons (replacing people, for example). So I have two questions - Is there a way to dynamically generate the device groups, based off each user's group association? Also, since devices can't be grouped without an associated Entra ID (either dynamically or manually), if a user leaves/signs out, will that device automatically lose all it's group associations? if there is another way to get the structure the tenant wants, I'm all ears. But essentially, the devices have different hardware, and they want their department to be tracked even if they have no user.Solved245Views0likes3CommentsError on Connect-MSGraph
Hello, I would like to use Powershell to sync Intune devices but when I launch the Connect-MSGraph command and enter the user credentials it responds with the following error message: AADSTS700016: Application with identifier d1ddf0e4-d672-4dae-b554-9d5bdfd93547 was not found in the directory 'Contoso'. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You may have sent your authentication request to the wrong tenant. Is there a problem with Azure Graph app? How can I fix it? Thank you very much.182Views2likes0Comments📢 Windows Devices not evalued compliance
🔥🚨 Hello everyone, It's been 1 week since I've been able to solve the problem and it's becoming urgent, so I need the community's help. I manage Windows devices in a hybrid environment. My case is only related to exiting devices. I have two GPOs applied, one that automatically registers to Entra ID and the other that registers to Intune. In the Entra ID console, the workstation is registered, but the user name is visible instead of the device name. In the Intune console, the same device is registered with the user's name. The result is that the device is managed by Intune, but no policy or application deployment is applied to it. the hardware inventory is not updated, and it's impossible to synchronize the device. I've already properly rewrapped the device - same error. I need your help Thank you in advance 🤙275Views0likes0CommentsHybrid join and device registered as username_windows_date_time instead of device name
Hello, I'm hybrid joining my company notebooks and have an issue with one of them; when I do all the operation to hybrid join the device, I see in Entra portal that it is hybrid joined but nothing more (only in 2 trial I've seen the owner field filled, the other like MDM and Security settings are empty). On the Intune side, I see many entries that as name have username_windows_date_time as format instead of device name, so for example, instead of pc-something, I see marcomangiante_Windows_3/13/2024_10:01 AM I tried many times to do an unjoin and a join (with instructions on link https://learn.microsoft.com/it-it/office/troubleshoot/activation/activation-error-0xcaa50021 in the section Leave and rejoin Microsoft Entra ID) but without luck. Tried to do a research on search engine, some people have same issue but have found nothing, only that maybe the problem is the device. Any help or suggestion?1.3KViews0likes2CommentsAfter primary email address change, user cannot login to the laptop with their new email
We're AAD only shop and we had a first user request whose last name changed and their email changed address changed as well. We require email address as the username login. We can see the email address changed under the Accounts sections of the settings but when they try to login to their laptop with the new email address, it says username or password is invalid and they can still login with the old email address? We use Okta as our SSO and user can login to Okta with the new email address as well as Outlook with the new email. Any idea what needs to be fixed?1.2KViews0likes1Comment