2023E18 - Drive Encryption (I.T)
1:06:42
2023E13 - Device Configuration (I.T)
1:23:56
2023E09 - Linux Provisioning (I.T)
18:29
2023E08 - Android Provisioning (I.T)
27:45
2023E06 - iOS Provisioning (I.T)
53:28
2023E04 - Vanity Domain Name (I.T)
20:47
2023E03 - Company Branding (I.T)
21:41
2023E02 - Tenant Signup (I.T)
33:48
2023E01 - Introduction to Intune
29:24
Intune.Training Reboot Teaser
2:51
S04E17 - Windows LAPS(I.T)
37:40
Жыл бұрын
S04E16 - Event Hub Adventures (I.T)
1:02:54
S04E15 - Linux (I.T)
37:16
Жыл бұрын
Пікірлер
@andrewenglish3810
@andrewenglish3810 3 күн бұрын
What happens if you have Windows 11 and 10 workstations in your environment how do add both build numbers to the device properties?
@andrewenglish3810
@andrewenglish3810 3 күн бұрын
This doesn't work for me. As of right now, if I setup the enrollment like you have showen, then add the company portal app to my android and log in, I don't get any of the other setup options like you do, it just takes me to the apps screen and shows me "no app available". I even see a warning in the devices tab under "my andorid". Your device does not meet requirements to enroll and may not be able to gain access to some of the resources.
@AstroKev-Work
@AstroKev-Work 4 күн бұрын
"Whats a catalog folder? No clue, I've hit no every single time." LOL thanks for making me feel better by doing the same thing forever. ⁠😂😂 Glad you guys have been enjoying life but nice to see a long video too!
@DanielCarey-sp4xl
@DanielCarey-sp4xl 9 күн бұрын
Love these videos guys! It's kind of rough when you talk over each other but other than that the content is amazing!
@jamesg871
@jamesg871 9 күн бұрын
Did you guys release a newer version of this video?
@pedrosusana9372
@pedrosusana9372 11 күн бұрын
Can you have both Configuration Policy and Disk Encryption running to make sure devices are covered? I ask because we only set Config Policy and we have machines that are not encrypted or were previously encrypted and Intune did not escrow keys.
@squfucs
@squfucs 12 күн бұрын
nothing about non-user .ppkg / BPRT enrollment via powershell in SYSTEM context for non-domain devices with local user accounts only 😞 (my use cases are very specific)
@muhammademad-kt8kg
@muhammademad-kt8kg 13 күн бұрын
I got a certificate Authority and managed to configure the template and PKCS as per the company requirements. It's been working for almost a year with all platforms "Android, Windows, macOS." Everything seemed to be fine until we tried to enroll new macOS devices at the beginning of July. We noticed that the certificate policy doesn't work only with macOS devices. We checked Intune reports and found that everything works well in terms of deploying the policy, but it comes up with an error with no codes. We reviewed the root certificate on the app school manager, and it seems fine. The certificate type is: device. The subject alternative name: UPN. This problem takes place on just the new macOS devices as the oldest ones work well. Any insights?
@davidweiss238
@davidweiss238 16 күн бұрын
Hey guys, great video, thanks for the content! One thing I wasn't quite clear on: what prevents a user from using their work account in their personal folder? For example, if BYOD is set up with two versions of Outlook (one in the personal folder, one in the corporate folder), how can I restrict users from logging into Outlook with their corporate email in the personal folder? They might do this for convenience, but the issue I see is that I wouldn't be able to manage the corporate data in this scenario, which poses a security risk. Edit: I was thinking about using Conditional Access Policies (CAP) to ensure that Outlook only opens if the device is compliant. However, I still don’t see how this would prevent users from using their corporate email in their personal account.
@leogaudier6232
@leogaudier6232 18 күн бұрын
Very helpful videos. Please create a video about Dell Command Configure and Intune. Thank you!
@-MattPierce
@-MattPierce 20 күн бұрын
As always, very informative video. Any way y'all could do one that goes over enrolling the device as a Microsoft Entra Shared Mode device? I'm so lost on how SSO works on it with multiple users. I've set it up to test, but I am not sure I'm doing it right and I haven't found much documentation or any good videos on it. The purpose I am trying to fulfill is to provide an iPad for a certain Team that will need to have one user using it when they are in the office as an alternative to using a laptop, but it is also going to be needed for other users to use for events where they may play music connected to a bluetooth speaker or have it setup to do surveys so they can hand it to people to fill out. We are a University in Texas, and this will be used for multiple purposes and multiple users. So, I didn't think doing Enroll with User Affinity was the way to go. Any videos you could do on this particular mode would be great! Thanks guys!
@Jonathan-vx2qj
@Jonathan-vx2qj 20 күн бұрын
So you guys idea of the future is that admins have a computer at home to run printers? This seems highly unlikely. The whole video is anything but serious anthing but how a real company would want to do anything. I mean.... it's a useless tool for the home user and you guys "explain" it is a way thats completly useless and unprofesional for corperate users as well. A real company is not going to set a connector up on a random computer that is unmanaged in your example a random laptop. So what if the user takes the laptop home or the laptop is turned off? What a rubbish "demo"
@ecuasteelo
@ecuasteelo 21 күн бұрын
Great tutorial. Can you cover in a future video how and when it will be best to use a powershell script to install a win32 app and wrap it with intunewin?
@IntuneTraining
@IntuneTraining 21 күн бұрын
Not sure we need a whole video for it. Many people use tools like the PowerShell app deployment toolkit (PSADT) for EVERY app for consistency in user experience and logging. I prefer to go with the easiest options where possible. If it’s an MSI that’s pretty easy to install without a wrapper. Adding a transform to an MSI is a great way to customize. However if that’s a difficult skill then a wrapper can help accomplish the same things. Generally any app that doesn’t have command line customization options or when you need to perform pre and post install actions are good indicators of times when a wrapper is helpful.
@ecuasteelo
@ecuasteelo 21 күн бұрын
@@IntuneTraining Ah ok. Thanks for the quick response. I'll look at PSADT in more detail and how about a vid on PSADT and how you use it?
@IntuneTraining
@IntuneTraining 21 күн бұрын
There are numerous great tutorials out there that will do much better than anything we can present. Here’s a great one from the Patch My PC team. kzbin.info/www/bejne/rYumf6R8icqhb5Isi=Ef2MgcbJgP14LF6o
@ecuasteelo
@ecuasteelo 21 күн бұрын
@@IntuneTraining Great. Thanks for the link.
@allwayshype
@allwayshype 23 күн бұрын
Ahh thanks guys! This was great! Also, Adam, totally read the Adobe app the same way 🤭
@Hans-gb4mv
@Hans-gb4mv 24 күн бұрын
Impeccable timing 🤣I just spend a few days struggling with a CA policy and in the end having to actually build a solution to bypass it. We are doing deploys with Autopilot and, don't hate me for this, they are hybrid joined. Believe me when I say, I did my best to make them non-hybrid and we have placed it back on the roadmap, maybe next year, with Windows 12 as we are killing our last dependency on the hybrid join. But anyway, not the topic of this post. As everyone knows, hybrid is a pain in the ass because you need line of sight to your domain controllers when you initiate the account setup phase. For this, I can use our VPN provider which does provide a pre-logon authentication provider. The VPN solution also utilizes authentication through Intune and is guarded by conditional access. One of the requirements is that you either have a hybrid joined device or your device is compliant. This is to prevent the VPN software from being installed and used from a non company laptop. As some might have guessed, this does not work while you are in the OOBE. I could get the laptop to report as being compliant in Intune, but the CA always reported that the laptop was in fact not compliant. In the end I contacted Microsoft and they told me that it will most likely not work (can't really say they were sure of their own answer) until the laptop had completed the hybrid setup. So far, I luckily have not yet locked myself out of any tenant with those policies, but we did once get close on our firewalls. We were working with the vendor on onboarding new firewalls while in a migration project and at one point the engineer made a change on the already active firewalls that disabled the HA link between the active and standby firewall so both became active. All hell broke lose and I, as the newbie with a few days in this new company, was left with the only working browser session to the management platform. Saved us an emergency drive to the datacenter which on a good day is 40 minutes away. By the way, did you guys skip over the break-glass account you were going to set up first? Because that is an internal discussion we are currently having inside our company as MS appears to be enforcing MFA on those as well these days and mgmt isn't happy with the solutions being proposed.
@matthewdillon1210
@matthewdillon1210 24 күн бұрын
Been doing more and more CAP with APP on all my Intune projects lately - specifically blocking native mail and requiring Intune enrollment to use O365 apps. Good stuff as always. Please make some APP videos. I get them until I don't. LOL. Would love to see you guys setting them up.
@212judas
@212judas 24 күн бұрын
Wooo i miss you guys
@m3lki3l
@m3lki3l 28 күн бұрын
If you want to prevent users to gain permanent local admin rights by adding their Entra account to the loacal admins group, you can now use Endpoint security > Account protection > Local user group membership to remove all users from le Administrators group
@danielpovea8342
@danielpovea8342 28 күн бұрын
@10:55 I can't get to have this screen appearing in an iPad I'm testing with... both devices (configurator installed iphone and the new ipad) are in latest iOS17 version available, started both fresh and still can't see it. I don't see that having the 'configurator iphone' ABM enrolled in advance is a prereq, isn't it? what am I doing wrong here?
@Soulreigner
@Soulreigner 29 күн бұрын
Hey guy's is there an update method to this for 2024, or is this still the default?
@angelinesneha2491
@angelinesneha2491 Ай бұрын
Nailed it 😃
@richardgodollei6228
@richardgodollei6228 Ай бұрын
Hi there! I setted up properly everything, but I have an issue. After a computer enrolled in Intune, it gets the user cert, and the root cert, but when I want to connect to a Wi-Fi network, NPS says: "Authentication failed due to a user credentials mismatch. Either the user name provided does not map to an existing user account or the password was incorrect." The only thing what I found is the user missing the certificate from local AD userCertificate attribute. Does anybody faced with this? Thank you!
@ksmith578
@ksmith578 Ай бұрын
I'm still very much hybrid with AD/SCCM, but recently moved all our app installs over to Intune, slowly getting there!
@-MattPierce
@-MattPierce Ай бұрын
Howdy I.T Training! I was wondering if you would consider doing a new Intune/MacOS PSSO video using the password method instead of the User Enclave method and step us through it all. My understanding is that we shouldn't need to use the CP to do the enrollment where it wants to download a new management profile. Currently, ours is doing this and we aren't sure why. Thanks for the consideration.
@Totalrandomness2011
@Totalrandomness2011 Ай бұрын
How can you map the drive but use specific credentials?
@SwarupDhar-k6y
@SwarupDhar-k6y Ай бұрын
Please reboot this.
@vanvuite7332
@vanvuite7332 Ай бұрын
When you hit the sync button "multiple times" - I realise I wasn't alone in this world LOL. What about onprem printers? I am okay with file access.
@anthonyportillo444
@anthonyportillo444 Ай бұрын
Passed my md-102 today with the help of these videos. Watched all of your Intune videos from the last ~9 months and it really helped on the test. Ms-102 content next ?🙏🏽
@jamesg871
@jamesg871 23 күн бұрын
congrats - How was the exam? I've failed twice and found the scenario questions really unrealistic and hard. What other methods of study did you use?
@CGRealStudios
@CGRealStudios Ай бұрын
After deploying this I am getting " Incorrect PIN" I have tried resetting the PIN multiple times but still no luck, anyone seen anything like this?
@borjagomezvillar2982
@borjagomezvillar2982 Ай бұрын
Congrats guys for this channel and for helpful videos. You rock ❤
@melodym5993
@melodym5993 Ай бұрын
Awesome, thank you so much!!! When's Ben getting a title and some pay, and can we clone him? 😂😅😂 🎉🎉🎉❤❤❤
@itst0000
@itst0000 Ай бұрын
why do 'Available for enrolled devices' apps enroll quicker than required apps?
@ethanmackell5999
@ethanmackell5999 Ай бұрын
I'm fairly well versed in app packaging, but this was worth watching solely for the GIF integration portion! Never knew I needed this.
@InvaderProdigy
@InvaderProdigy Ай бұрын
Is the IntuneWinApp application ever going to be FIPS compliant? It is a little annoying for us to have to turn off the reg setting, build the package, then turn it back on.
@professor3095
@professor3095 Ай бұрын
When iam starting the company portal he wants to set up intune enrollment. But this was setting up at start so i dont understand why. All enrollment profiles are already installed but the portal show up its not enrolled. Any advice?
@-MattPierce
@-MattPierce Ай бұрын
We are having the same issue with our environment. We are using Enroll with User Affinity with Setup Assistant with modern authentication and the PSSO Configuration policy is set with the Password method instead of User secure enclave key. Everything with the register popup notifications work just fine. However, when we open the CP, it has a Begin button and wants us to begin the enrollment process. Shouldn't it already be enrolled and just take us to the CP Main screen where the device is listed?
@professor3095
@professor3095 Ай бұрын
@@-MattPierce I solved this issue in my case. The user who enrolled the mac was a „device enrollment manager“ in intune. This role have some restrictions in some features. All other users had worked
@professor3095
@professor3095 Ай бұрын
I still need to install the profiles after log in to the company portal. What is the problem here? Of course its not possible to install the profiles because they were enrolled automatically
@davidbolding8598
@davidbolding8598 Ай бұрын
I have zebra android scanners, and I was wondering about the dedicated management of these systems as they are focused tasks.
@ToTCaMbIu
@ToTCaMbIu Ай бұрын
This method no longer works. I tried removing the mail and Xbox apps (User and System context).
@RobertStoner-e2v
@RobertStoner-e2v Ай бұрын
What Im struggling to understand is how to transition from managing machines by OU in AD to Intune. I cant make groups off of an OU so I dont know how to group machines.
@matthewdillon1210
@matthewdillon1210 Ай бұрын
Love these videos. Windows Updates Reboot soon?
@leongcheechong1681
@leongcheechong1681 Ай бұрын
Is it possible If we have using the Hybrid ENV , and need to map drive the local AD (through by IP)?
@IntuneTraining
@IntuneTraining Ай бұрын
Yes. Thats possible. Hybrid devices are still fully AD joined and function as normal.
@ck5000
@ck5000 Ай бұрын
The beards are getting longer guys!
@gabrielluizbh
@gabrielluizbh Ай бұрын
Hello! I would like to know if these problems have already been corrected in 2024?
@IntuneTraining
@IntuneTraining Ай бұрын
Not sure which specific problems you refer to. However local group management works but just takes good planning.
@xkorbekx
@xkorbekx Ай бұрын
is byod user supposed to select 'join this device to AAD'? i thought "join" was only for corporate devices
@IntuneTraining
@IntuneTraining Ай бұрын
The join this device option will make the device Intune managed. Which for Windows is managed just like other Intune managed devices and not generally recommended.
@JohnnyKnodoff
@JohnnyKnodoff Ай бұрын
Thanks for the training videos, guys. I love the bubbling tension between you two just simmering under the surface at all times
@hyugai
@hyugai Ай бұрын
i love your video, steve im based in sydney as well and would love to meet up with you one day
@IntuneTraining
@IntuneTraining Ай бұрын
Make sure you come on down to workplace ninja in a couple of weeks 😏
@hyugai
@hyugai Ай бұрын
​@@IntuneTraining is it 27 august at denison north sydney?
@IntuneTraining
@IntuneTraining Ай бұрын
Sign up here www.meetup.com/workplace-ninja-user-group-australia/events/302012219
@AnthGags333
@AnthGags333 Ай бұрын
"Maybe, if you care"... lol
@IhateMYgam3rTAG
@IhateMYgam3rTAG Ай бұрын
Can you cover WDAC?
@brothertax
@brothertax Ай бұрын
Adam and Steve! Good to see you guys again. Great content.
@allwayshype
@allwayshype Ай бұрын
I was just thinking how I have missed the Steve and Adam show.. and there you all are!