What's new in Microsoft Intune (2308)

  Рет қаралды 2,378

MSEndpointMgr - Jungling the Cloud

MSEndpointMgr - Jungling the Cloud

Күн бұрын

Пікірлер: 21
@bobbydk123
@bobbydk123 Жыл бұрын
Great content as always 🎉
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Thanks!
@Nozuka621
@Nozuka621 Жыл бұрын
Would you recommend using the Bitlocker settings in "Endpoint Security" shown here over a "device configuration profile"? And why? Feels a bit confusing, that you can do it in both places... not sure which one to choose.
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Good question. We ask the same. Endpoint Security is good to use if you have a seperate SecOps devision that you want to give access to policy. They can use the Entra role Security Admin to get access to these kind of policies. Settings Catalog is kind of the universal place we Intune admins use, but it can be hard sometimes to build the right policy pack, whereas Endpoint Security is more of a template kind of thing, THIS is the settings that you want to consider. Hope this helped you.
@Nozuka621
@Nozuka621 Жыл бұрын
​@@MSEndpointMgr Good points, thanks! Feels like they should just make the same profiles show up in both places then... oh well :)
@MrMarcLaflamme
@MrMarcLaflamme Жыл бұрын
Regarding turning off the Store. Maybe I missed you mentioning this but what about the built in Windows apps that are updated automatically through the Store? Such as Calculator, Notepad, Phone Link, etc. I didn't specifically deploy these as they came installed but they are updated via Store. Will they need to be re-deployed via Intune as a required store app to be updated?
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
They will continue to be updated. Everything you have that is installed via store will still be updated. By using this new policy you prohibit, manual store app shopping and also winget install locally.
@MrMarcLaflamme
@MrMarcLaflamme Жыл бұрын
@@MSEndpointMgr Okay that's good to know. Regarding your last point about winget locally, does that mean if I open a terminal prompt and run winget install x, this will not work?
@Minerva___
@Minerva___ Жыл бұрын
At 15:38 you mention that updates won’t be blocked, however, in the informational bubble in the Settings picker screen it states, “Access to the Store is required for installing app updates.” I wouldn’t put it past Microsoft forgetting to update this information, but have you successfully tested that updates are possible for UWP apps? I’m asking because we recently began vulnerability testing in which a large number of the UWP apps were missing updates. This was due to a GPO we configured to block access to the store. I’m trying to move away from a hybrid configuration in my environment and would like to configure this via Intune but need to make sure it works. Is there a way to test (or force) apps to fetch updates with this Configuration Profile in place? Also, it looks like this is only supported for Windows Enterprise or Windows Education. Unfortunately, we’re only running Windows Professional.
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
@@Minerva___ yes only for those platforms. The text in the setting is very clunky written. It is confirmed by MSFT that above stated is indeed the behavior. Apps will update
@KiwiEngineer-0
@KiwiEngineer-0 Жыл бұрын
Exciting changes with the Bitlocker configuration. Will you also be able to set the PIN on a global level ?
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Absolutely exciting! PIN on a global level, can you elaborate? You can assign the policy and thereby target your devices.
@KiwiEngineer-0
@KiwiEngineer-0 Жыл бұрын
@@MSEndpointMgr One of our customers requires the same bit locker startup PIN across all Intune MDM Windows endpoints. Is there a way to push the 6 digit PIN without end user interaction ?
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
@@KiwiEngineer-0 hmm so a startup pin which is the same for all devices and telling the user afterwards? Why bother to have PIN then? Shouldersurf one device and steal the code. It does not sound as a very good idea to be honest.
@webcomment8895
@webcomment8895 Жыл бұрын
@@MSEndpointMgrThe reason to do that is to automate applying an initial PIN on all devices. Standard users cannot create Bitlocker PINs; they can only change existing PINS. You would require users to change the PIN after they receive their device so they would not all have the same PIN. A simple way to ensure users will change the PIN ASAP is to set the initial PIN to be much longer and more complex than the minimum requirements. Set a 25 character default PIN and then tell users the minimum PIN length is 7 characters and they will all change the PIN to something else rather than keep using the PIN they were given.
@Lewis01Brown
@Lewis01Brown Жыл бұрын
Intune Win32 apps need an advanced option to be able to have an "Uninstall" package so we could use PSADT but without the installer files in the intunewin file
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
Preach it. We need more options, but let's add the feature request and keep asking until we get it :)
@AbdullahOllivierreIT
@AbdullahOllivierreIT Жыл бұрын
I do not get it. PSADT is only great when user interaction is required
@MSEndpointMgr
@MSEndpointMgr Жыл бұрын
@@AbdullahOllivierreIT it is also great for logging and standardizing your package estate
What's new in Microsoft Intune (2309)
34:11
MSEndpointMgr - Jungling the Cloud
Рет қаралды 2,8 М.
What's new in Windows 365 (2304) - Full Demo Frontline
57:55
MSEndpointMgr - Jungling the Cloud
Рет қаралды 695
Сестра обхитрила!
00:17
Victoria Portfolio
Рет қаралды 906 М.
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
What's new in Microsoft Intune (2306 & 2307)
59:13
MSEndpointMgr - Jungling the Cloud
Рет қаралды 1,3 М.
What's new in Microsoft Intune (2403+2404)
1:09:09
MSEndpointMgr - Jungling the Cloud
Рет қаралды 2,1 М.
Microsoft Intune Suite - Deploying Apps, Updates & Managing Security!
33:22
What's new in Microsoft Intune (2410+2411)
39:31
MSEndpointMgr - Jungling the Cloud
Рет қаралды 1,5 М.
What's new in Microsoft Intune (2311+2312)
45:34
MSEndpointMgr - Jungling the Cloud
Рет қаралды 1,3 М.
MSEndpointMgr meets Microsoft - S01 E01
58:44
MSEndpointMgr - Jungling the Cloud
Рет қаралды 726
Intune and Conditional Access Setup for Microsoft Teams Devices
33:33
Craig Chiffers
Рет қаралды 3,7 М.
Сестра обхитрила!
00:17
Victoria Portfolio
Рет қаралды 906 М.