conditional access
697 TopicsError 80180014 due to device restrictions for Windows Autopilot devices
Hello, We've encountered an issue due to device restrictions. We wanted to block personal devices to register in AAD. Due to this policy we are unable to deploy Windows Autopilot devices because When we blocked personal devices it also blocks AAD join during Windows Autopilot (error code 80180014). Is there a way to set the device as corporate device when importing hardware ID in order to by pass this issue or with conditional access block personal device without affecting Windows Autopilot ? Thanks for your help.Solved446KViews0likes6CommentsMultiple Tenants on One Device
Hello, I have a scenario that I am not sure if it would work or not and wanted to get some clarification: 2 companies, each setup with Intune and MAM policies for mobile. Would I be able to setup both emails on a BYOD device? I don't think it is possible, because the device will need to be registered in Intune Company Portal app to retrieve the policies and check security etc. When you try to add the other address, it will require you to register in Company Portal again, but as far as I know, you can only have 1 company registered at a time?Solved138KViews1like12CommentsAllow Use of Microsoft Authenticator OTP in Azure AD
Hi All, We wanted to enabled number matching and Passwordless with Microsoft Authenticator app and when I go to there I could see the below setting under configurations. But I wanted to make sure what that setting is and what it the recommended configurations for this "Allow Use of Microsoft Authenticator OTP" before configure in production environment. appreciate if anyone could help me on this. Thanks, DilanSolved63KViews0likes7CommentsHybrid Azure AD join devices MDM set to "none"?
Good afternoon, We have recently upgraded all of our servers and as part of that I'm re-configuring Azure AD Connect for the hybrid environment. Users are syncing properly. Devices, however, seem to fail to be picked up by Intune and thus, MDM. IT is set to "none" and on top of that is not replacing the existing record for the device, so currently there's a Hybrid Azure AD join device and a Azure AD registered record assigned to the user that uses it (myself). I'm trying to use auto-enrollment via GPO, the specific GPO is "Enable Automatic MDM enrollment using default Azure AD credentials". Something I've noticed (and if memory servers me well), is the fact that the generated task in task scheduler is named differently. If I remember correct, the name should match or be similar to that of the GPO, it is now called "Schedule created by enrollment client for automatically enrolling in MDM from AAD". So I'm not too sure if the policy is, for whatever reason, generating the wrong task? At any rate, below is the information of one of the devices: | Device State | +----------------------------------------------------------------------+ AzureAdJoined : YES EnterpriseJoined : NO DomainJoined : YES DomainName : DOMAIN SSO State | +----------------------------------------------------------------------+ AzureAdPrt : NO AzureAdPrtAuthority : EnterprisePrt : NO EnterprisePrtAuthority : I'm aware that AzureAdPrt is set to NO, but I understand that isn't an issue if you are trying to enroll via default user credentials? (Correct me if I'm wrong). As for Intune, auto-enrollment is activated for everyone and anyone with the correct license. It has been a while since I last worked with this and perhaps I'm missing something obvious, but having look at Microsoft's docs and following some of the trouble shooting advice, I cannot see anything wrong with my setup. Please, if you need any more information do let me know. Thank you62KViews1like21CommentsCreating a folder containing multiple files and sending to devices via intune
Hi all, I desperately need some help! And just thought Id post on here to see if someone can help! I need to create a folder on client machines in the c drive (Folder name: Spanish Games) which I then deploy a bunch of files to this folder I create I have had a look and seems like I need to create a win32 app container with all in, script and files. What would I need to include in the script to get this to work? I have had a look at docs online but cant find one that deploys a folder and files too. I have found this: https://pariswells.com/blog/intune/copy-file-to-workstations-with-windows-intune but dont really understand some of it. Any help would be great!! Thanks in advanceSolved60KViews0likes22CommentsMicrosoft Edge on iOS and Android now supports conditional access and single sign-on
Microsoft Enterprise Mobility + Security (EMS) is excited to deliver Azure Active Directory conditional access protection for Microsoft Edge on iOS and Android. This integration expands the Microsoft Intune management capabilities as you deploy Microsoft Edge for the best browsing experience across all endpoints in the enterprise. Users get easy, secure access to Office 365 and all your web apps that use Azure Active Directory, with the same application management and security capabilities that previously required Intune Managed Browser.57KViews3likes4CommentsiOS Profile installation fails on corporate owned devices. Resolution to allow personal ones?
Hi community We are trying to protect our tenant from users enrolling their personal devices. This works up to the point where we are enrolling iOS devices. When trying to install the management profile on the Apple device, we receive the following error: Profile Installation Failed. Connection to the server could not be established. https://docs.microsoft.com/en-gb/intune/enrollment/troubleshoot-ios-enrollment-errors Why would they give us the option to block personally owned devices, yet not allow iOS to make contact with the server to install the management profile? At the moment, our workaround is to temporarily allow personal iOS devices when enrolling one, then disabling it. This works, but feels like we need to work around their contradictive setup. We have added the device serial to Corporate device identifiers. It is marked as enrolled status after the above workaround. It's status is "not contacted" if personal devices is blocked. This is not an issue with Android devices. Am I missing something or does Microsoft need to find a way to fix this? Do they even care seeing as it's an issue related to Apple devices?Solved54KViews0likes6Comments