Event banner

Windows Office Hours: May 16, 2024

Event Ended
Thursday, May 16, 2024, 08:00 AM PDT
In-Person

Event details

Get answers to your questions about adopting Windows 11 and managing the Windows devices used by remote, onsite, and hybrid workers across your organization. Get tips on keeping devices up to date effectively! Learn how to cloud attach your on-premises workloads!

Windows Office Hours is our continuing series of live Q&A for IT professionals here on Tech Community.

How does it work?
We will have a broad group of product experts, servicing experts, and engineers representing Windows, Microsoft Intune, Configuration Manager, Windows 365, Windows Autopilot, security, public sector, FastTrack, and more. They will be standing by here -- in chat -- to provide guidance, discuss strategies and tactics, and, of course, answer any specific questions you may have.

Post your questions in the Comments early and throughout the one-hour event.

Note: This is a chat-based event. There is no video or live meeting component. Questions and answers will appear in the Comments section below.

 

Char_Cheesman
Updated May 16, 2024

88 Comments

  • Tim Crosby's avatar
    Tim Crosby
    Copper Contributor
    We are currently preparing for Autopilot in a hybrid joined setup. With hybrid you have very limited options in naming your devices according to a company standard. Is there any work planned to expand this with additional logic that would allow something like including the device serial number in the name during the hybrid join process?
    • Joe_Lurie's avatar
      Joe_Lurie
      Icon for Microsoft rankMicrosoft

      Hi Tim Crosby thanks for joining us today. No, we don't plan to add this functionality to Autopilot Hybrid joined profiles. Our official recommendation is to not use hybrid-join with Autopilot, but to use Entra-joined/Intune-managed (what we call cloud-native). Hybrid is fine for your existing devices, but once they are replaced or refreshed/repurposed or new devices are purchased, we recommend starting that cloud-native journey. For the devices that are being repurposed and must remain hybrid-joined you should continue using your current imaging solution. 

      If you have to do hybrid-join, and still feel Autopilot is the right solution for you, there are scripts you can find online to help you name the device during the Autopilot process. Note that they aren't written or supported by Microsoft so please test them thoroughly before using them in production.

  • Dom_Cote's avatar
    Dom_Cote
    Brass Contributor
    We deployed Firewall and other security policies according to M365 security center recommendations. However, these policies block certain apps that require a _direct_ connection to other devices. Examples: Miracast and German government eID app, which connects to your smartphone for use as an NFC reader. Obviously, the network policies are designed for max security, but in certain cases they block user from doing stuff they need to. How can we determine which policies are disrupting these connections and open them selectively? We have a ticket open with M365 support, but beyond standard advice to allow services through the firewall, we have made no progress. Which, btw, indicates that blockage is happening at a different level than Firewall. Thanks!
  • Dom_Cote's avatar
    Dom_Cote
    Brass Contributor
    When we export policies from M365, they are usually exported with their Entra OID. In which situations would it be helpful or detrimental to re-import those policies with their original OIDs in to new tenants? Use case: we are an MSP with a baseline config with over 800 settings in it and need to deploy this to new tenants with minimal risk and effort. Thanks!
  • Dom_Cote's avatar
    Dom_Cote
    Brass Contributor
    I recently took a close look at M365 Lighthouse and was, frankly, disappointed. It doesn't seem to support custom policies beyond Intune. For example, how would I use Lighthouse to configure Teams and Compliance Center (IP labels)? Or custom Entra authentication policies? When can we expect Lighthouse to support ALL key services in M365? Currently, it feels more like "Intune Lighthouse" rather than M365 Lighthouse. Thanks!
    • Joe_Lurie's avatar
      Joe_Lurie
      Icon for Microsoft rankMicrosoft

      Hi Dom_Cote. Thanks for the feedback. This Office Hours is for Windows and Intune, so the people monitoring this chat are Windows and Intune SMEs and PG. You'd be better off posting the feedback in the Microsoft 365 forums, like this one: Microsoft 365 - Microsoft Community Hub

       

      Good luck- 

  • reastman1966's avatar
    reastman1966
    Brass Contributor
    I have recently used the Feature update to upgrade from Windows 10 22H2 to Windows 11 23H2. Now I am being asked to Sign in to verify my Work or School account. I can sign in and it will go away for a few days then a new notification will show up. I have another user that is getting this too. I tried to open a ticket with Intune support since it happened after the Feature update but was told that wasn't the way to get support. I was told to use the Get Help on the window in Settings -> System -> Activation. This didn't help much since it just said contact your IT department.
    • David_Guyer's avatar
      David_Guyer
      Icon for Microsoft rankMicrosoft
      After conferring with a couple of colleagues, we recommend opening a support ticket with Windows support. It's appropriate Intune wouldn't be the best for something that happens after a successful feature update. Sorry I don't have a better answer, but this isn't a common problem.
  • reastman1966's avatar
    reastman1966
    Brass Contributor
    I am working on setting up admin permissions for some help desk users to manage a small group of devices. I have down the group, but I am struggling on what is really necessary in the custom role I am creating. These are Zebra Android based scanners if it matters. They will need to be able to do the enrollment and some other basic tasks. No need to adjust any profiles as that will be handled by another team.
Date and Time
May 16, 20248:00 AM - 9:00 AM PDT