Intune MDM
5 TopicsIntune Windows 10 Security Baseline IE Settings
We have deployed the Intune Windows 10 Security Baseline, which includes the default IE Settings. However, via GPO we have published intranet sites to the intranet security zone via... GPO setting \User Configuration\Preferences\Windows Settings\Registry\IE Settings, which creates registry entries at ...HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap and we also allow our users to add sites to the zones as they deem necessary. This works as expected and has for many years.... However, machines that are enrolled in the Intune Windows 10 Security Baseline have all internet explorer security settings blocked including adding sites... It appears the setting in the baseline "Internet Explorer users adding sites: Disabled" does not function. I have changed this to "Not Configured" and "Enabled" with no change.. the add sites box is greyed out along with all IE Security options... Changing the setting "Internet Explorer security zones use only machine settings" to disabled does allow the sites published via GPO to show and be effective.... We are looking to publish specific intranet sites along with a few internet sites while retaining the ability of our users to add custom sites.... Any Thoughts/suggestions...Solved12KViews0likes7CommentsWill my OS will be reset if I use Autopilot to enroll Windows devices in Intune
I want to use Autopilot to enroll our existing Windows 10 devices in Intune, will the devices will be reset if I use this https://docs.microsoft.com/en-us/mem/intune/enrollment/tutorial-use-autopilot-enroll-devices1.1KViews1like1CommentAdding apps to Kiosk using Intune configuration policy
Hi All Is there away we can automatically install apps into the Intune Kiosk? We have over 100 users with Kiosk mobile phones with a selection of apps. All the phones are Android. The problem is we want to add more apps to the kiosk devices without the need for users interaction. I have tested it on a few test Android phones and it looks like the new apps first need to be installed on the devise before they can be added to the Kiosk. You can only install the apps through the Google App Store which can not be done within the kiosk. Maybe I am doing this wrong. Any help will be appreciated. Many thanks Alan1.1KViews0likes0CommentsIntune and Conditional Access
Hi All, I have been asked a few questions about Intune and Conditional Access and I was hoping to get some advice. The question I was asked: ***************** As discussed we have a situation that I believe MS InTune would address. That said, I don’t know what I don’t know, so your direction around the subject would be appreciated. We have migrated 99% of the e-mail estate to Office 365. Over the next month, we will migrate our home and shared drives. In migrating the e-mail users, we have found that a small percentage of the estate, ~20% (15-20 users), were using Corporate e-mail on personal devices. The devices vary from iOS, Android, Mac OSX, Windows. We need to have full control of e-mail residing on third-party devices. It needs to be secure; we need to be able to monitor and track the e-mails. Note, we currently use SOTI for Android device management. We will need to understand if there are any implications associated with coexistence. In parallel to the above, we need to develop our full e-mail policy. We would also need documentation and training on how to administer Intune once live. The documentation is essential. Hopefully the above gives you enough to start with. Please let me know what it would cost to get the above in place. Ignore licenses, I’ll deal with those. While writing, do you know of a way to prevent Office 365 users from downloading or printing from a browser, but only when outside of the corporate network? ***************** Do you know how I would use Intune and Conditional Access to achieve these requirements? I hope you can help, Alan910Views0likes0CommentsSomeone else is still using this PC. If you shut down now, they could loss unsaved work
Hi All, After testing connecting devices to our Azure AD network using MS Intune and Azure Conditional Access we are having issues with the devices. We can successfully connect to the Azure AD network, but when the device user restarts or shuts down their device they get a "Someone else is still using this PC. If you shut down now, they could loss unsaved work" warning. Even when we have completely disconnect the device from the Azure AD network they still get the warning. We are currently testing Intune and Azure Conditional Access. What we can not understand is why we would get this warning even after the device has disconnected from the Azure AD network. Has anyone on the beautiful planet called Earth, any idea why this is happening? I hope you can help CourtneySolved4.8KViews0likes1Comment