Vertrauenswürdige Speicherorte in Intune konfigurieren

%3CLINGO-SUB%20id%3D%22lingo-sub-2979080%22%20slang%3D%22de-DE%22%3EConfigure%20trusted%20locations%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2979080%22%20slang%3D%22de-DE%22%3E%3CP%20class%3D%22%22%3EHello%20in%20the%20round%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Esince%20I%20can't%20get%20any%20further%20with%20the%20Google%20SuFu%2C%20I%20try%20my%20luck%20here.%20The%20following%20scenario%3A%3C%2FP%3E%3CP%20class%3D%22%22%3E-%20Company%20works%20exclusively%20with%20Windows%2010%20clients%3C%2FP%3E%3CP%3E-%20Joined%20all%20devices%20in%20Azure%20AD%3C%2FP%3E%3CP%3E-%20Customer%20uses%20a%20NAS%20in%20the%20local%20network%20(provided%20by%20connected%20network%20drive)%3C%2FP%3E%3CP%3E-%20Data%20is%20stored%20on%20the%20NAS%20(DOC%20or.DOCX%20etc.)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22%22%3EWhen%20the%20customer%20now%20opens%20Word%2FExcel%20Files%20from%20the%20NAS%2C%20the%20error%20message%20appears%20(see%20Appendix%20%221%22)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOf%20course%2C%20I%20can%20now%20adjust%20this%20via%20the%20Office%20settings%20of%20Word%2FExcel.%20However%2C%20since%20the%20customer%20is%20well%20over%20300%20men%20in%20size%2C%20I%20would%20like%20to%20realize%20the%20whole%20thing%20via%20Intune.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20do%20this%2C%20I%20created%20a%20new%20profile%20in%20the%20Intune%20portal%20under%20Devices%20%26gt%3B%20Windows%20%26gt%3B%20Configuration%20Profiles%20%26gt%3B%20and%20included%20the%20corresponding%20groups%20in%20the%20assignment.%20The%20configuration%20settings%20are%20as%20follows%3A%20(see%20Appendix%20%222%22)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlthough%20the%20policy%20takes%20effect%2C%20the%20files%20are%20still%20opened%20with%20Protected%20View.%20Anyone%20have%20any%20idea%20what%20I%20did%20wrong%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEdit%3A%20In%20addition%2C%20I%20tried%20to%20create%20an%20Office%20app%20policy%20via%20Intune%2C%20which%20also%20failed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20in%20advance%20for%20your%20help!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2979080%22%20slang%3D%22de-DE%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2979178%22%20slang%3D%22en-US%22%3ERe%3A%20Vertrauensw%C3%BCrdige%20Speicherorte%20in%20Intune%20konfigurieren%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2979178%22%20slang%3D%22en-US%22%3EHi%2C%20Good%20morning..%3CBR%20%2F%3E%3CBR%20%2F%3ELooking%20at%20the%20screenshots%20and%20that%20you%20are%20telling%20that%20the%20policy%20is%20deployed..%20Could%20you%20show%20us%20the%20screenshot%20that%20the%20settings%20are%20also%20available%20in%20word%3F%20What%20happens%20when%20you%20are%20trying%20to%20change%20the%20path%20to%20use%20%5C%5C%20instead%20of%20only%20the%20IP%20address%3F%20or%20maybe%20also%20add%20%5C%5Cnas%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2979227%22%20slang%3D%22de-DE%22%3ERe%3A%20Configure%20trusted%20locations%20in%20Intune%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2979227%22%20slang%3D%22de-DE%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F620702%22%20target%3D%22_blank%22%3E%40Rudy_Ooms%3C%2FA%3E%3C%2FP%3E%3CP%3EThanks%20for%20the%20feedback.%20In%20Word%2C%20the%20settings%20are%20not%20set.%20I%20can%20see%20in%20Intune%20that%20the%20policy%20has%20been%20deployed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20also%20tried%20the%20DNS%20name%20instead%20of%20the%20IP%20address.%20As%20well%20as%20all%20variants%20such%20as%3A%3C%2FP%3E%3CP%3E%5C%5Cnas%5C%3C%2FP%3E%3CP%3E%5C%5Cnas%3C%2FP%3E%3CP%3ENas%3C%2FP%3E%3CP%3Enas%5C%3C%2FP%3E%3CP%3E%5C%5CIP%20Address%5C%3C%2FP%3E%3CP%3E%5C%5CIP%20address%3C%2FP%3E%3CP%3EIP%20address%3C%2FP%3E%3CP%3EIP%20Address%5C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20without%20success.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hallo in die Runde,

 

da ich mit der Google SuFu nicht weiter komme, versuche ich mein Glück hier. Folgendes Szenario:

- Unternehmen arbeitet ausschließlich mit Windows 10 Clients

- Alle Geräte in Azure AD beigetreten

- Kunde nutzt eine NAS im lokalen Netzwerk (Bereitgestellt durch angebundenes Netzlaufwerk)

- Auf der NAS sind Daten abgelegt (DOC bzw. DOCX usw.)

 

Wenn der Kunde nun Word/Excel Files von der NAS aus öffnet, erscheint die Fehlermeldung

1.png

 

Ich kann das natürlich jetzt über die Office-Einstellungen von Word/Excel anpassen. Da der Kunde jedoch weit über 300 Mann groß ist, möchte ich das ganze via Intune realisieren.

 

Dazu habe ich im Intune-Portal unter Geräte > Windows > Konfigurationsprofile > ein neues Profil erstellt und die entsprechenden Gruppen in die Zuweisung eingebunden. Die Konfigurationseinstellungen sehen wie folgt aus:

2.png

 

Die Richtlinie greift zwar, geöffnet werden die Dateien aber immer noch mit der geschützten Ansicht. Jemand ne Ahnung, was ich falsch gemacht habe?

 

Edit: Zusätzlich habe noch versucht über Intune eine Office-App Richtlinie zu erstellen, was auch fehlgeschlagen ist.

 

Danke vorab für eure Hilfe!

6 Replies
Hi, Good morning..

Looking at the screenshots and that you are telling that the policy is deployed.. Could you show us the screenshot that the settings are also available in word? What happens when you are trying to change the path to use \\ instead of only the IP address? or maybe also add \\nas

@Rudy_Ooms

Danke für das Feedback. In Word werden die Einstellungen nicht gesetzt. Ich kann in Intune sehen, dass die Policy deployed wurde.

 

Den DNS-Namen anstatt der IP-Adresse habe ich auch probiert. Ebenso alle Varianten wie:

\\nas\

\\nas

nas

nas\

\\IP-Adresse\

\\IP-Adresse

IP-Adresse

IP-Adresse\

 

Alle ohne Erfolg.

Hi,

Good morning,
Could you check out the registry of the current user to determine if the polices are indeed applied/arrived at the device?

What happens when you try it the "old school" way and add the \\nas or IP address to the trusted locations like described here

https://deploywindows.com/2019/05/13/complete-guide-to-trusted-sites-with-intune/
Gelöst!
Konfigurationsprofil erstellen:
- Profiltyp > Einstellungskatalog (Vorschau)
- Windows-Komponenten > Internet Explorer > Internetsystemsteuerung > Sicherheitsseite > "Site to Zone Assigment List"
- Hier entsprechend den freizugebenden UNC-Pfad eintragen.
So the old school way it was :)