User Profile
mikerowlandlondon
Brass Contributor
Joined Jan 03, 2018
User Widgets
Recent Discussions
DFE Web Protection vs Smartscreen for Edge IOS
Scenario I have is fully enrolled corp managed IOS devices I need to enable smart screen for edge automatically and make sure the user can't turn it off. Problem 1 is I can't seem to find a way to do that, problem 2 is trying to find the differences between smart screen and DFE web protection. Ultimately I want the SS protection of a nice "this site was blocked" type message to satisfy my cyber guys. Does web protection pop anything similar? or just block a malicious site? Any assistance or experience gratefully received313Views0likes0CommentsOverrides and false positives in DLP policy end user experience
Ok so a user gets a policy applied to his/her document for let's say PCI compliance. On the policy tip we give the user the option to override with a business justification or to report as a false positive. If they click the "report" button in the policy tip where does that go? where do I as an admin go to review those and presumably take some kind of action on that report? allow and reclassify or keep the classification and inform the user. I'd expect to see something in the S&C reports but I can't see a thing. I can view my overrides report and view where a user has overridden a classification but nothing anywhere else that lets me interact with any reported "cases"Solved53KViews1like18CommentsAIP question on alerts
I'm starting to switch over from labelling and classification In the S&C centre over to AIP (pending the hopefully soon integration of the two). In the S&C DLP I can set alerts, so for example if someone attempts to send out a bunch of Credit Card data I can get an alert emailed to an admin. I cannot find how to do this in AIP, where can I configure alerts? All I can find is Powershell stuff around interrogating the logfiles. I hope I'm missing something really obvious!1.9KViews0likes2CommentsPIM wont activate
I've got a problem in PIM - when I click on a role to activate it it just sits at LOADING and the activate button doesn't ever come live. I've got MFA turned on as well and my account is authenticated. This has only just started happening, it's been happily working for months. I've tried different devices, browsers etc. Same issue. Anyone seen this or can help?1.9KViews0likes1CommentRe: Auto Pilot White Glove failures
Thijs Lecomte thanks for that, interesting blog..! Some more investigation, seems to be failing at Bitlocker and ATP stages. Just trying to find anyone that has this successfully working in Hybrid or been through similar issues. TPM all looks good!3.9KViews0likes0CommentsAuto Pilot White Glove failures
Cross posting this here - Bit of a head scratcher. Has anyone managed to successfully get Auto Pilot White Glove working in Hybrid join with 1903? (with update kb4517211-x64). We're just seeing multiple errors and have had an open call with Unified Support for well over a week on this and getting no where. A google throws up multiple issues and we've been through everyone. Machine names, various Intune changes, dynamic goups, static groups. Just would love to hear someone has this working! All deploying down to multiple Surface Gos. Manual AutoPilot works absolutely fine, just Whiteglove process isn't even starting, just hangs and throws back the Red screen of deathSolvedSurface Go - Autopilot WhiteGlove
Cross posting this here - Bit of a head scratcher. Has anyone managed to successfully get Auto Pilot White Glove working in Hybrid join with 1903? (with update kb4517211-x64). We're just seeing multiple errors and have had an open call with Unified Support for well over a week on this and getting no where. A google throws up multiple issues and we've been through everyone. Machine names, various Intune changes, dynamic goups, static groups. Just would love to hear someone has this working! All deploying down to multiple Surface Gos. Manual AutoPilot works absolutely fine, just Whiteglove process isn't even starting, just hangs and throws back the Red screen of death630Views0likes0CommentsWindows 10 1903 Autopilot Whiteglove Hybrid Join
Bit of a head scratcher. Has anyone managed to successfully get Auto Pilot White Glove working in Hybrid join with 1903? (with update kb4517211-x64). We're just seeing multiple errors and have had an open call with Unified Support for well over a week on this and getting no where. A google throws up multiple issues and we've been through everyone. Machine names, various Intune changes, dynamic goups, static groups. Just would love to hear someone has this working!916Views0likes0CommentsBYOD, Windows 10 force Azure AD registration for MAM to correctly apply
Our BYOD policy requires us to lock down access to 365 via browser only and prevent data egress. We can do this using app protection but it only works 100% as required once the device is azure ad registered. As far as I can see this is a user driven task - this will never work as probably 50%+ of users wouldn't bother - is there a way to force a user down this route? Or is there another option we haven't thought of? Second issue is we have requirements around both MAM and MDM which is causing a headache but that's secondary. If I could fix issue 1 above then I can probably win the argument on the rest. How is everyone else approaching intune and BYOD?Re: Intune cannot have two different mailboxes from different managed tenants on a single device
Update on this. So we've been told by an MS Partner that there is a way to achieve this by using the managed browser / Edge. We've not managed to get this working though, it uses the Authenticator app for this supposed fix but it just gets stuck in an endless loop bouncing between the two accounts - anyone got that route working?910Views0likes0CommentsIntune cannot have two different mailboxes from different managed tenants on a single device
We have an issue with some VIP users. They work for two organisations both who use Intune to manage devices. Now of course I know that this will not work - however... There have been hints dropped around that you could use Managed Browser / Edge to achieve this. But we've drawn a blank. Has anyone anywhere managed a workaround to achieve this? (and yep our VIPs are strictly against carrying two devices) (IOS decices only)973Views0likes2CommentsSFB Online and Citrix
Just wondered on other peoples experiences. We are running Citrix 6.5 (programme in place to upgrade) and we cannot get screen sharing working with any kind of consistency with SFB Online. I'm kinda at the point of "forget it till you upgrade Citrix" but wondered if anyone else has faced this? All Citrix optimisation packs etc have been installed for 365. As an aside through the Teams browser app in Citrix it's hit and miss with regards to adding new tabs in channels particularly for external web services - VSTS for example just returns a totally black screen. Thanks in advance!Re: Overrides and false positives in DLP policy end user experience
I think that's the conclusion I'm coming to. There is no way to actually do what I'm expecting - which I think would make total sense to be able to interact and deal with these incidents rather than having to go find a user and have a chat with them. I have it set up to alert me and it sounds like that's the best I can hope for. That's all I needed - no one was able to tell me if I was missing anything or not but you've got the same experience so sounds like it is what it is. Thanks so much for your help!50KViews0likes1CommentRe: Overrides and false positives in DLP policy end user experience
Thanks Simon! I get that report but I can't interact with it? Are you able to? As my point above I can see someone has reported something as a false positive but there seems to no way for an admin to say "ah ok, that's fine, I'll reclassify it and away you go" Thanks for your help!50KViews0likes9CommentsRe: Overrides and false positives in DLP policy end user experience
Maybe I'm looking at the wrong thing? This isn't a new feature. I get a policy tip for a DLP rule I have the option to "report" my content as a false positive where the dickens does that report button end up? I am expecting if there's a report button that somewhere I can go as a sec admin, view that report and either dismiss it and reply to the data owner or opt to reclassify and allow sharing. There seems no information anywhere about this and no one at Microsoft seems to have a clue about it from what I can see. If you have a report button then it must go somewhere or why have the button?50KViews0likes13Comments
Recent Blog Articles
No content to show