I just want to know 1 thing. what do i have to do to simply enable default (i.e. how it would be set for a consumer account out of the box / sync everything and don't restrict anything...)?
@teuniswoest14 сағат бұрын
Thanks for the info mate!
@ArminBoe14 сағат бұрын
Your graph series are absolutely great 👍
@getrubix13 сағат бұрын
Appreciate that!
@algoroy16 сағат бұрын
for some reason in my tenenat im running into the issue when I try to update the diagnostic settings and send the logs to the workspace I get the error: Authorization Failed, client with object xxxx, does not have authorization to perform action Micrsoft.Insights/register/action over scope xxxxx. I do have the correct role from my understanding: Log Analytics contributor, Security Admin, I even tried monitoring contributor. can you tell me what I may be doing wrong I even ask my admin to give me perms at the subscription level as well and I still can't send the logs
@getrubix13 сағат бұрын
It's hard to say from just the description. For troubleshooting, please join our Discord server at discord.gg/getrubix
@TDSWork_Күн бұрын
Can't see the video around autopilot provisioning yet - Does it exist? Keen!
@getrubix20 сағат бұрын
Yes, it is available to members Setup Autopilot Device Preparation with an Enhanced User Experience kzbin.info/www/bejne/jJLXiH-NbNGXoKs
@nakiqbekteshi3735Күн бұрын
Hi Steve, I know it's a long time since you have posted it but I was not able to find the script anymore from the getrubix website and github, maybe can you post it again.
@dirtdiggler9860Күн бұрын
Dumb
@jekbulakbol81252 күн бұрын
I'm getting this error: PS>TerminatingError(Invoke-RestMethod): "The remote server returned an error: (400) Bad Request." 2025-01-23 16:22:32 PM - Error setting primary user: The remote server returned an error: (400) Bad Request. The script gets completed. 1. Machine is removed from domain 2. Files are migrated to the new profile 3. The device is azurejoined as per dsregcmd/status The device is not showing in Intune
@getrubixКүн бұрын
Please hop into the discord server discord.gg/getrubix to troubleshoot :)
@jekbulakbol8125Күн бұрын
@getrubix joined and posted the issue on migration-solution
@jimmyroels76043 күн бұрын
Great Video Steve! How do you get rid of all the bloatware during the AutoPilot deployment?
@getrubix2 күн бұрын
The Autopilot Branding package by Michael Niehaus can debloat a device. If you search my channel, I have a few videos covering it
@kokkosbollful3 күн бұрын
AGREEE😥
@texasatvoffroad59013 күн бұрын
If the source tenant and destination tenants aren't using autopilot is this still usable?
@getrubix3 күн бұрын
Absolutely
@michaelpietrzak20673 күн бұрын
Got my W365 pc logging in automatically on my thin OS (RepurpOS). Very elegant solution. Thanks for the great content!
@getrubix3 күн бұрын
Awesome. How’s that working?
@michaelpietrzak2067Күн бұрын
@@getrubix Really well. Looking to repurpose some old non-TPM pc's and the thinclient os works great. The seemless login to W365 works great as well.
@p3lvikthrust4 күн бұрын
Any experience using W365 as a pseudo PAW / Jumpbox? Like a cloud accessible admin workstation with access to on-prem?
@getrubix4 күн бұрын
Yes. You could hybrid join the cloud PC to have access. Technically not PAW, but I see where you’re going 👍🏻
@AHumanMale4 күн бұрын
Steve, recently found your channel and have really been enjoying it. Subscribed-- totally worth it. Curious if your user profile was syncing Known Folders to OneDrive, would that still be the case post-migration?
@getrubix4 күн бұрын
Thanks! Yes, it should remain on
@JessieS4 күн бұрын
Just to confirm, once you flip the switch from Report-Only to On, will it stop reporting?
@getrubix4 күн бұрын
It will continue to report in user sign-ins
@Neyhityt4 күн бұрын
Hi Steven, is it possible to use your tool to migrate the workgroup (non-domain joined) computer to Intune without losing the data?
@getrubix4 күн бұрын
Yes
@Neyhityt2 күн бұрын
Which video is the best to follow to do that?
@KJA0094 күн бұрын
Would you be able to show an App Registration using a certificate ??
@getrubix4 күн бұрын
Yep- I'll add it to the list!
@sur6e5 күн бұрын
Why no backtick on that last PATCH command $ sign?
@getrubix3 күн бұрын
Had to watch again cause my memory is garbage. You only need the backtick with $ sign when using as a filter in the graph call. Basically, when you want PowerShell to NOT declare it a variable.
@mediamonk1005 күн бұрын
Are enterprises ditching AD and going cloud only or are companies sticking with classic AD joined computers?
@getrubix4 күн бұрын
Most companies are moving to cloud-only joined endpoints. Users objects and other resources will remain on Active Directory for the time being
@mediamonk1005 күн бұрын
yeah but how do you get Autopilot to join to your Active Directory domain? Otherwise its just a workgroup joined computer with you logged in with your M365 corporate account.
@getrubix4 күн бұрын
No, that's not how Autopilot works. There is not just "domain" or "workgroup" join. Read about Entra ID join here: learn.microsoft.com/en-us/entra/identity/devices/concept-directory-join
@mediamonk1004 күн бұрын
@@getrubix I guess you would need to use Entra hybrid deployment in order to support AD domains. I can see small businesses only using cloud only Entra ID, but I think going pure cloud for larger business, large orgs, and enterprises who have so much infrastructure tied into Active Directory would be a very tough thing to do.
@markcavalli14295 күн бұрын
Where or how does the install.xml get uploaded to Intune?
@getrubix5 күн бұрын
It should be baked into the win32 package. You store it in the folder that you package
@eddiegonzalez32135 күн бұрын
Have you done any videos regarding Apple MAC OS Automatic device enrollment videos?
@getrubix5 күн бұрын
kzbin.info/www/bejne/ZnS0p4Spbqhnm7M
@matthewmiles69135 күн бұрын
This is great, thank you. Quick question. You did a basic setup, but when the Cloud PC started up, you had a custom desktop background image. How did that get applied?
@getrubix5 күн бұрын
Looks like I had a desktop wallpaper policy applied to "all devices"
@slaweknos7486 күн бұрын
Great staff as usual!!
@michaelpietrzak20676 күн бұрын
I hope that with the new MS "thin client" cloud mini PC, it can be configured to power on and go right to a users assigned W365 cloud pc.
@getrubix6 күн бұрын
That’s the idea
@unkownuser23206 күн бұрын
please create video Azure virtual desktop terminology, how works like diagram, how to setup for minimum start, how intune will manage host sessions, custom images, fxlogic, policy, if user is 100 how plan azure desktops , what is buffer
@getrubix6 күн бұрын
Sorry. I don’t do AVD 😊
@iLikeBeer2166 күн бұрын
Great content! Love the concept of cloud PC and the ease of configuration and management. However, we have seen inconsistent performance issues over a few of the license SKUs that are preventing us from further rollouts. If you want users to be able to simply join a Teams call with audio and camera without doing anything else, you'll need to go higher than 4 vCPU and 16GB ram in my experience. This could quickly limit smaller companies to be priced out of the service altogether.
@getrubix5 күн бұрын
It's understandable- I would hope as adoption grows, they solve the issues. Personally I have not had performance issues but my machine is a bit beefier.
@nathanhopkins87807 күн бұрын
I'm all for using the 'modern approach' to gather this data. But the number of complicated steps to get from here to there is crazy. In SCCM, it was enable software metering, create an EXE rule and wait for data to collect and use a SCCM built-in report or if you are fancy, write your own SQL query to extract the data. Another side gripe: If you were are a SCCM engineer/admin with full admin permissions, you could do anything within the SCCM site. If you want to set up software metering for example, you could with just the few steps I mentioned. Once your SCCM site is set up and running, there's no real need to do much in the Active Directory space. In corporate environments (at least mine) there is a clear divide between Intune admins and Azure admins. Intune admins don't mess around in the Azure space and vise versa. Except now Intune relies heavily on Azure for things like software metering. This means that us Intune admins have to 'plead our case' to the Azure admins to do work for us. Maybe this is just a problem at my workplace? I don't know. Either way, just a real slow down in my case to do a quick POC. I love the content, please keep posting!
@getrubix7 күн бұрын
Thanks!
@JonHelm7 күн бұрын
Thanks!
@getrubix7 күн бұрын
Thank you!
@JonHelm7 күн бұрын
Thanks for this Steve. I'm trying to set this up as you did only deploying Autopilot Branding and Company Portal but when the OOBE up to login to the tenant, I'm able to login and it gets to the Apps and skips stating 'no setup needed'. I'm currently testing on VirtualBox with Windows 11 Pro 24H2. Any ideas why this wouldn't be deploying the apps during OOBE?
@getrubix7 күн бұрын
Are the apps assigned to your Autopilot Device group?
@JonHelm7 күн бұрын
@@getrubix Yep. In the available for enrolled devices
@JonHelm5 күн бұрын
Do the apps you choose to deploy in enrollment status page you want to deploy have to be set with device group as 'Required' in order for OOBE to install?
@sambinomio7 күн бұрын
Thank you for sharing this precious knowledge. I needed to try many times but finally worked and it's awesome.
@xkorbekx8 күн бұрын
interesting that MS categorize AP as an security feature
@xkorbekx8 күн бұрын
you never use the official autopilot dynamic query?
@getrubix8 күн бұрын
Not for assignments. I prefer group tags.
@xkorbekx8 күн бұрын
HI do you have a video/blog on how to convert all targeted devices to ap using ps script?
@getrubix8 күн бұрын
Yes it's been covered over at www.getrubix.com/blog/autopilot-shortcut?rq=shortcut
@RTB19108 күн бұрын
No macOS support is a no-go for third-party application packaging. Patch My PC has started a private preview for macOS. Hopefully, this will move to public preview as soon as possible.
@getrubix8 күн бұрын
Understandable. Hopefully it's coming on the roadmap for Robo...
@Robopack_Intune8 күн бұрын
Very much on the roadmap for us!
@eddiejimenez32838 күн бұрын
dang doesn't support macOS. no surprise there I guess
@xkorbekx8 күн бұрын
Thank you. User should sso into CP by default? Can you please share AP branding script app?
@getrubix8 күн бұрын
Autopilot Branding can be found here- github.com/mtniehaus/AutopilotBranding What do you mean by "CP"?
@xkorbekx8 күн бұрын
@@getrubixcompany portal. I find i have to click “sign in” it doesn’t automatically open signed. not a big deal just wondering normal behavior. I would like to customize it so company portal automatically launches on startup
@xkorbekx8 күн бұрын
@@getrubix awesome. thank you
@kimt.nielsen42747 күн бұрын
@@getrubix Think that it stands for Company Portal. My users are promped when they start Company Portal.
@jekbulakbol812510 күн бұрын
i think this would solve my problem with v7 migrating hybrid to same tenant. mine gets stuck after a reboot after unjoining the domain. wil give this a try. need this to the remaining 2.5k hybrid devices
@jekbulakbol81259 күн бұрын
worked on my domain-joined vm. i did change the length of the password for the user "MigrationInProgess" as our minimum password is set to 14 characters minimum in the GPO
@ramansingh1410 күн бұрын
Hey Steve, where is the 5 part video on group tags , I cant find it.
@getrubix9 күн бұрын
It’s a blog, not video series. Here: www.getrubix.com/blog/autopilot-group-tags-1
@ericeric409710 күн бұрын
always funny
@andywallace966110 күн бұрын
Is a conditional access policy required to trigger an app protection policy.
@getrubix10 күн бұрын
No.
@disketaverde11 күн бұрын
Learned a lot from you. Great guy and great series! Thank you very much! <3
@getrubix11 күн бұрын
Thanks!
@algoroy11 күн бұрын
Okay, for my org we are small. How would I be able to get the device hash if we was to just order the device from an amazon or get it from a local store near the user(international user). Would we need to pre-provsion the device, then ship it to the user?
@getrubix11 күн бұрын
You would have to manually pull the hardware hash from the device in that case. At that point, I would probably say look into Autopilot Device Preparation (a.k.a., Autopilot V2) as no hardware hash is required.
@MrMarcLaflamme11 күн бұрын
I never understood the toggle to allow or disallow pre-provisioning. If it's enabled and you don't need to use it, who cares? But if you need to use it, you need to remember to turn it on in the profile first. Is there some security risk I'm not seeing? I also wish device name templates could be more customizable (like variable suffix or prefixes based on certain parameters such as location tags or something...) Regarding Skip User ESP. I thought this was only necessary (or useful) when doing Hybrid AP (at least according to the blogs I've read that covered it). You're the only one I've come across so far that recommends skipping it for regular Entra join AP. I'm not saying you're wrong for recommending it, just really curious as to how beneficial it is when doing Entra joined AP. Finally - that damn "Only fail selected blocking apps in technician phase"... still don't get it... not sure I will ever get it!
@getrubix11 күн бұрын
Agreed, doesn't hurt to leave pre-provisioning enabled. I always skip User ESP because it just slows down Autopilot in general in my experience. I also don't see the benefit of leaving it enabled. Only fail selected blocking basically says "during white glove preprovisioning, even though you're only tracking apps A,B,C, and D for failure, go ahead and attempt apps E,F,G and H as well if they're assigned."
@MsAdam0911 күн бұрын
Interesting, when you are running your creat vm script from ark WAC, does that need to be local or can scripts be stored in azure so you have a central script repostory for all hyperv? Thansk
@getrubix11 күн бұрын
I've always stored locally, but I don't see what it wouldn't work without some tweaking.
@KJA00911 күн бұрын
We are looking to start using Autopilot more but we have lots of different sites and each site has its own computer name convention, what's the best approach to handle this, have multiple deployment profiles or update the name after??
@getrubix11 күн бұрын
Either way would work, but I wouldn't be me if I didn't challenge the need for having the complex naming ;)
@KJA00911 күн бұрын
@getrubix - what do you do when you have those complex naming requirements?? Also, can we get your desktop wallpapers 🤣 lol