Windows 11 24H2 Overview
This past week, we saw a new version of Windows 11 (highly anticipated as well) with 24H2. It’s a very […]
This past week, we saw a new version of Windows 11 (highly anticipated as well) with 24H2. It’s a very […]
The article discusses the author’s positive experience with Windows Autopilot v2, focusing on the integration of corporate identifiers into Intune through a Power Automate solution. It details the process of extracting data from CDW emails, filtering valid device purchases, and constructing API requests for device identity import, ultimately enhancing device management efficiency.
Microsoft is prioritizing Entra joined devices without neglecting hybrid environments. Entra Hybrid Join still has value, especially for leveraging group policy and certain applications. Embracing a strategy that starts with hybrid and transitions to Cloud Native gradually can lead to successful adoption. Hybrid is a bridge to the future and should not be underestimated.
Microsoft Intune released mprovements to Discovered Apps Report and Intune Management Extension (IME) logs for Win32 Apps. The IME handles WinGet Apps, Win32 Apps, PowerShell Scripts, Remediations, App Control for Business Managed Installer, Device Compliance, and Analytics. The new AppWorkload.log provides detailed Win32 app deployment/validation process information. Overall, Intune’s logging on application installs is praised for its detailed insights.
Windows Autopilot Device Preparation is a new solution from Microsoft that simplifies the onboarding process for Windows devices. It streamlines device setup, enhancing user experience while reducing IT time investment. The process involves setting up device groups, configuring policies, and importing corporate identifiers. This user-driven flow supports Entra joined devices and offers improved reporting capabilities.
CrowdStrike faces a major outage due to a driver channel file causing widespread BSOD. Intune scripts detect and remove problematic files. Intune can also enable users to self-service BitLocker keys. Conditional Access can control key access and Audit Logs can monitor key usage. Compliance ensures key access from compliant devices only.
Since COVID, focus has been on BCP and DR. Windows 365 now offers new capabilities like Cross Region Disaster Recovery, Enterprise State Roaming, and Cloud PC resiliency. These features ensure 99.9% uptime, RPO of ~0, and easy activation and deactivation of fallback devices. The new DR feature costs $4.50/user.
This article explores the importance of Microsoft Word security policies and the issues that can arise with Office security baselines. It covers challenging settings such as add-in signing and trust bar notifications, and provides a solution using Microsoft Intune to address trusted publisher issues. Proper implementation of security baselines is emphasized to avoid potential problems.
The article discusses the concept of Temporary Access Passes (TAP) as an alternative to passwords for authentication. It covers the configuration of TAP, its use during onboarding, and for web-based sign-in. The author recommends using TAP to enroll in Microsoft Authenticator and activate passkeys for a seamless and secure user experience.
This multi-part series on Windows 11 best practices has covered onboarding, security, and advanced security. Part 4 delves into user experiences, addressing Windows Hello for Business with Cloud Kerberos Trust, OneDrive best practices, Microsoft Edge configuration, user password solutions, 3rd party ADMX integrations with Intune, self-service password reset, and Office 365 cloud app policies. These components aim to enhance the end user’s experience.