Intune
12 TopicsDisable "Windows Hello"
I am an admin, and attempting to disable "Windows Hello for Business" also referred to as 2-step authentication. From what I gather, this option is set as "disabled" by default. I confirmed this. However Whenever I join a device to Azure AD, it is always prompted with "Windows Hello" and to create a pin. Where can I find the option that allows me to disable this?335KViews1like27CommentsIntune Windows 10 Security Baseline IE Settings
We have deployed the Intune Windows 10 Security Baseline, which includes the default IE Settings. However, via GPO we have published intranet sites to the intranet security zone via... GPO setting \User Configuration\Preferences\Windows Settings\Registry\IE Settings, which creates registry entries at ...HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap and we also allow our users to add sites to the zones as they deem necessary. This works as expected and has for many years.... However, machines that are enrolled in the Intune Windows 10 Security Baseline have all internet explorer security settings blocked including adding sites... It appears the setting in the baseline "Internet Explorer users adding sites: Disabled" does not function. I have changed this to "Not Configured" and "Enabled" with no change.. the add sites box is greyed out along with all IE Security options... Changing the setting "Internet Explorer security zones use only machine settings" to disabled does allow the sites published via GPO to show and be effective.... We are looking to publish specific intranet sites along with a few internet sites while retaining the ability of our users to add custom sites.... Any Thoughts/suggestions...Solved12KViews0likes7CommentsSomeone else is still using this PC. If you shut down now, they could loss unsaved work
Hi All, After testing connecting devices to our Azure AD network using MS Intune and Azure Conditional Access we are having issues with the devices. We can successfully connect to the Azure AD network, but when the device user restarts or shuts down their device they get a "Someone else is still using this PC. If you shut down now, they could loss unsaved work" warning. Even when we have completely disconnect the device from the Azure AD network they still get the warning. We are currently testing Intune and Azure Conditional Access. What we can not understand is why we would get this warning even after the device has disconnected from the Azure AD network. Has anyone on the beautiful planet called Earth, any idea why this is happening? I hope you can help CourtneySolved4.8KViews0likes1CommentHow to do a App Selective Wipe of a Mac computer. Intune App Protection policy.
Hi All, Is it possible to do an App Selective Wipe of an unmanaged Mac computer device? I know how to do it on an Android and iOS devices using App Protection Policies, but I need to test it on a Mac computer. The Mac computer is a personal device (BYOD) so I do not want to manage it using Intune. Maybe there is another way to do a App Selective Wipe of a Mac computer instead of using a App Protection policy. I hope you can help !! AlanSolved2.7KViews0likes3CommentsHow to prevent a group of users downloading SharePoint and MS Teams documents
Hi All, We need to prevent a group of users downloading files from SharePoint, and MS Teams. We want them to be able to access and edit the files using office online, but not download and edit them locally. We have been able to do this for Outlook using these instructions https://www.b-fortyone.com/single-post/2016/06/07/Office-365-Prevent-downloading-attachments-via-Outlook-Web-App but we cannot do it for the SharePoint and MS Teams. I hope you can help Colin1.5KViews0likes0CommentsCompliant intune device don't pass conditional access policy
Hey, I'm having problems configuring conditional access for unmanaged and managed devices when accessing ressources. I'm using the prebuild sharepoint CA rules(these are showing up in the CA portal when restricted access is activated in the ahrepoint admin portal under access controll menu) and added the condition that these rules are not applied when a hybrid joined or compliant device tries to get access. Unfortuantely this doesn't work, similar if I use a hybrid joined device or an intune joined compiant device. When I check the login logs in Azure AD I can see that the rules are applied and the fields(managed, compliant, connectiontype) under "device information" are empty so it seems Azure AD can't access the device state from the device itself when ressources are accessed from it. Does anyone know this issue, can reproduce it or have any ideas what needs to be done? Thanks and regards!1.2KViews0likes0CommentsWill my OS will be reset if I use Autopilot to enroll Windows devices in Intune
I want to use Autopilot to enroll our existing Windows 10 devices in Intune, will the devices will be reset if I use this https://docs.microsoft.com/en-us/mem/intune/enrollment/tutorial-use-autopilot-enroll-devices1.1KViews1like1CommentAdding apps to Kiosk using Intune configuration policy
Hi All Is there away we can automatically install apps into the Intune Kiosk? We have over 100 users with Kiosk mobile phones with a selection of apps. All the phones are Android. The problem is we want to add more apps to the kiosk devices without the need for users interaction. I have tested it on a few test Android phones and it looks like the new apps first need to be installed on the devise before they can be added to the Kiosk. You can only install the apps through the Google App Store which can not be done within the kiosk. Maybe I am doing this wrong. Any help will be appreciated. Many thanks Alan1.1KViews0likes0Comments