Great content and a well-structured demo! I have a few questions regarding the Adobe settings you used, if you don't mind.First question, in your example, you created an elevation rule policy specifically for Adobe, targeting Fred as a user. I’m wondering: is it possible to apply this rule to all users within your tenant, rather than just Fred? Second question, besides the method you used to configure this policy for a specific app (in this case, Adobe), how would the configuration differ if the application is set as a required or available app for enrolled devices through the Company Portal?
@ahmadalnoor4533Ай бұрын
simple and clear, thank you for the video
@AminTorabi-it3 ай бұрын
This was really helpful, thank you!
@00_Ryan_003 ай бұрын
Very cool. So this is very similar to Group Policy "Software Restriction Policy" only more robust. I used to whitelist apps in that.
@ncdlloydАй бұрын
Thanks Jonathan, very helpful
@patrick__0073 ай бұрын
Great video! What is the great benefit over this instead of publishing the allowed apps via Company Portal as available? The first part about the idea of blocking is great.
15 күн бұрын
some of these cloud solutions like intune has these cool features like this - but with AD + GPO in a local environment, you cannot do these things natively unless you use a third party integration.
@mohamedfarith93363 ай бұрын
Intro was amazing!
@it-flex841013 күн бұрын
7:00 Where do you set up which email the request will be send to?
@parsley47653 ай бұрын
This is insane, I was setting this up a few days ago, if you uploaded this video sooner it would save me hours :D
@bearded365guy3 ай бұрын
@@parsley4765 Did it go well?
@SonnyTheITguy3 ай бұрын
Thanks for all the wonderful stuff ♥
@Dirkie763 ай бұрын
At my previous company they used AutoElevate for this, I'm not sure how to compare licensing/pricing but AutoElevate does have a few more additional features eg. mail notification to admins as requested below. But very interesting video thank you Jonathan
@bearded365guy3 ай бұрын
@@Dirkie76 Yes, there are some features missing in the Microsoft product. Mail notifications would be good.
@Wahinies3 ай бұрын
This is amazing John especially the part with deny and using that to filter a lot of junkware! This is a first party alternative to Admin By Request which has been great where I have used it as well. Ill have to look, did you do one on PIM too?
@bearded365guy3 ай бұрын
Haven’t yet….
@UAPКүн бұрын
What do you use to have that virtual machine?
@bearded365guyКүн бұрын
@@UAP hyper-v on Windows….
@Sergio-Here-In-Community3 ай бұрын
Excellent video, Very very good how you do the demo, that is very important to understand the concept. excellent video 😁😁😁😁😁
@addictedtotreasuretrash1083 ай бұрын
Hej . I have followed your instructions and made a back up disk to a spare external HD. Great, now how do i use it if something goes wrong on my laptop ? I have another laptop that had the ususal updates etc and after updates the screen went black, well you can see some kind of bluish black on the screen but i cant get into it. Is there a way i can get into my laptop without taking it into a repair shop ? Thanx
@codeforwhat3 ай бұрын
i have q about this :) is there any mail notifications for admins about user request to install an app?
@bearded365guy3 ай бұрын
@@codeforwhat I don’t think you can get mail notifications - which would be nice.
@townnine3 ай бұрын
Thank you for the excellent video, it was very informative. I use the company portal where applications are available for users to install since both .exe files and the Microsoft Store are blocked for me. The issue is that the new Microsoft Teams has to be installed separately. Could you create a video on how to install custom applications using the company portal?
@systech58083 ай бұрын
what about an app you gave elevated permissions to install. What if you want to allow the same user to be able to uninstall ? I am running into that now, where it's asking for admin credentials for uninstallation.
@systech58083 ай бұрын
I've come across another annoyance - after an update, the hash changes. This means that the next update can't be performed until the hash is updated. You often don't know about the next update until you're told. Additionally, some software won't allow you to use it unless it's been updated to the latest version, which can be a major headache. I'm also still trying to figure out how to allow uninstallation.
@ggates58592 ай бұрын
LAPS would be a slightly more clunky way to provide local admin creds.
@it-flex841013 күн бұрын
10:00 Specific policy for each app seems stupid, why not just package the app to Company Portal. I can see if there is an app that is not possible to automate the installation but othervice I dont get the point. Love your videos though :D
@louisayoub84283 ай бұрын
This falls short of something like ThreatLocker, doesn't it?
@bearded365guy3 ай бұрын
@@louisayoub8428 Threatlocker is an option, with more features.
@morpk13 ай бұрын
this is unreal, but from an MSP point of view how to we know that a support request has gone to enpoint manager, can an email be sent to our helpdesk as a ticket so we know to go review and approve
@bearded365guy3 ай бұрын
@@morpk1 No, I don’t think it can which is a shame. It needs some kind of process to use effectively as an MSP.