microsoft intune
7 TopicsExtend M365 Archive Quota capacity
In my organization, we are currently on the O365 E5 License with default 100GB mailbox size per user and 1.5TB archive quota. However, due to organizational policy and regulatory requirements, we are expected to keep all the data from inception. Hence, the requirement for a solution to extend our archive size from 1.5TB. From the official Microsoft documentation, https://learn.microsoft.com/en-us/office365/servicedescriptions/exchange-online-archiving-service-description/exchange-online-archiving-service-description#archive-storage-quota the maximum expansion of the archive mailbox is 1.5TB. Is it possible to extend the archive storage to an Azure blob? Like an automated script that moves the data from the Archive mailbox for each user to the Azure blob or any other storage service that does not have storage size limitation. I am open to suggestions. Thanks177Views1like2CommentsIntune: Windows & MS365 Apps Updating
Pardon the noobness... I am new (ish) to MS365 Admin and Endpoint management. I see that I can keep the OS updated and MS 365 Apps update using 2 different methods. I can use the Settings Catalog (Intune->Devices->Windows->Configuration) to update MS 365 Apps and ((Intune->Devices->Windows->Windows Updates) to update the OS. I just learned about MS AutoPatch (Intune->Tennant Administration->Windows AutoPatch) to keep both updated. My question is which is preferred at this point? The AutoPatch option seems a bit easier to configure maybe? Looking for advice... J95Views0likes2CommentsSplitting a 365 Tenancy?
Hi, So the situation is that a company has two branches, one local (to me) and the other overseas. Currently all the IT is based around a single Microsoft 365 Tenancy (with third party extensions for DMARC and email spam/phishing protection) administered from the overseas branch. This is reportedly leading to some issues, the two branches have different security requirements (the local branch can afford to be more open with regards to BYOD for example), having to go through the overseas admins for almost every change is inconvenient, and also importantly some data should be compartmentalized (notably there is local information that ideally should not be visible to anybody in the overseas department, including the admins). So having been asked to look into options, and being quite new to the inner workings of 365, after some investigation it seems prima facia that a solution might be to split the tenancy into two, moving the local office members into the new tenancy which would be controlled by a local admin, and then connecting the two possibly with a multi-tenant organization. Obviously everyone would need to keep the same email addresses. So, what I would like to check is 1) Is this possible? 2) Is this a sensible solution to the problem? 3) (Assuming the first answer is "yes" and the second at least a "maybe") any pointers to how to do it and any things to watch out for? Any help/suggestions would be greatly appreciated.732Views0likes5CommentsSelf Service Reset password (SSPR)
Hi I have an odd situation with random users. When SSPR is enabled for them, they cannot login email on their iPhone corporate Intune device, is pushing the login to conditional access trusted locations blocked. Email works just fine with SSPR disabled. Anyone experience something similar.SSPR at the windows sign-in screen by creating a device policy in Intune
Hi We are gradually deploying SSPR at the windows sign-in screen by creating a device policy in Intune. Option B mentioned in this https://learn.microsoft.com/en-us/entra/identity/authentication/howto-sspr-windows is to deploy a registry. My question is, does the registry get deployed with the Intune device policy? Because I have the registry below and I did not add it. HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AzureADAccount "AllowPasswordReset"=dword:00000001365Views0likes1CommentNetwork Configuration Operators - Intune - Not working
Hi All, I have been doing some testing with intune and local user groups. I have managed to get non-admin user accounts to remove them from the local admin groups and also added Admin accounts to the local admin group. There is some uses in our organisation that require access to change their network settings (they are network engineers) I have managed to create a PS script with intune that puts the users in the network configuration operators group which I can see has populated. However when the user goes to change their IP they get the UAC prompt (expected) and they put their standard user (in the NCO group) credentials in. However windows 11 just kicks back another UAC prompt. No error message. Anyone else use network configuration operators on Windows 11? Thanks for any help offered.4.8KViews0likes4CommentsMicrosoft MFA Prompt when connecting school account in Windows
For reference I'm talking about ( Windows under settings -> Accounts > Connect a work or school account) When our users choose to connect their school or work account they are getting both our DUO MFA that is configured with conditional access, and the Microsoft MFA prompts. We don't use Microsoft MFA, it's not enabled in conditional access, and it's not enabled in our Intune device management. How do we stop the Microsoft MFA prompt so the user is only getting the single DUO MFA prompt?Solved1.4KViews0likes3Comments