Hacking Windows kiosk mode – Single Intune config for multiple devices needing unique URL’s, with self-provisioning autopilot.

This writeup will show you how to hack the windows kiosk mode so you can use one config to target a multitude of devices requiring their own unique url. Unique kiosk device URL’s normally means unique configuration profiles in intune – or does it?

pointing

Setting up cloud kerberos trust – passwordless access to on-prem resources.

This post will show you how to set up your environment to support AzureAD joined devices authenticating with your on-prem resources. When devices are setup as pure azure ad joined, and not hybrid joined, devices we need to handle authentication to your on-prem resources in a better way. Your on-prem resources does not in itself understand the authentication from these devices. It will also add support for using Windows Hello for Business/biometrics, FIDO security keys

E-mail flow.

Using Valimail to help with SPF,DKIM,DMARC monitoring with Microsoft 365

This post revolves around the e-mail concepts for SPF/DKIM and DMARC to increase your e-mail reputation as well as protecting your domain from being misused by others i.e impersonation. We will also go through the tool provided by Valimail to have this monitored, all integrated with your Azure AD for SSO.

Enabling Microsoft “Cloud enabled LAPS” (Local Admin Password Solution)

LAPS – Local Admin Password Solution, has for a long time been one of those great tools to have in the toolbox when it comes to securing your devices from lateral movement from a potential attacker. And Microsoft LAPS have been around for quite some time already.

This tool was orginally available for deployment to server/desktop devices connected to a traditional domain (on-prem) setup.

This changed as of April 2023, and Microsoft have now introduced Microsoft LAPS (Preview) with support for configuration with Intune, and saving the passwords to Azure AD, giving us – once again – a native LAPS solution to handle the local admin account.

Microsoft Teams Banner

Microsoft Teams unable to send and receive calls after update to 1.5.x

Users are currently experiencing outage to expected functions inside Microsoft Teams. Vital functions inside the apps like the ability to do calls, video, meetings etc, are broken for a random group of users across a multitude of user groups.
Around where I am based the discussion started to show itself at the end of january. Troubleshoothing has been ongoing since then, with limited results to an acualt fix.
The temporary fix have been around rolling back to version 1.4 for users that have experienced the issues. But, as Teams gets updated automatically, this is very temporary.
There has also not been very clear as to why only some users have been affected.
During the last week or so, this has become more clear.

Read on for details and a temporary workaround until this gets resolved

How to configure screensaver settings on non-enterprise editions of Windows with Intune

his is another post to deal with one of thelimitations of the various licensing editions of Windows.
To be specific, there are certain features that are only available if you have an Enterprise or Education edition of Windows.
This post beeing around the limitation of controlling the settings around enforcing and controlling the screen saver on devices via intune.
As always, every problem has a solution, or a viable workaround.

problem

Solved: Error opening files from SharePoint / OneDrive

Have been seeing some users getting the following errors when trying to open files from OneDrive for Business.

It doesn’t happen on all files, but for some, no specific event causing the behavior. .
If the user takes a copy of the file giving the error, then opening the copy, works as expected

pointing

Manageability – Part 1: Naming Conventions

When it comes to managing anything within IT, it will always be a good thing to keep things organized, in one way or another. You should also make sure that the way you organize things, is made understandable for others as well (maybe you share the responsibility of management with a group, or may do so in the future).
Make it a habit to creating an organizational model that others can jump in or out of over time, that is logical and understandable by others than yourself. Document the logic/model that is defined, and make sure not to deviate from the actual definition as time goes by.

Office 365 Splash

Security: O365 – did you remember to disable legacy authentication before October 13, 2020?

If you have kept up to date with the many announcements around 365 – spesifically Exchange Online, from Microsoft, you may remember that they announced that end of support for basic authentication were coming to various parts of Exchange Online in 365.
Subscribers of O/M365 should move to using modern authentication, as this is more secure and gives alot of other benefits.
The said date for this change was set to October 13 2020,

Office 365 Splash

Office 365: Hvordan be om flytting av dine 365 data til Norge.

april ble det mulighet for å ha Office 365 kjernedata lokalisert til Norsk lokasjon hos Microsoft.
Dersom du har 365 tjenester idag, så er disse ved annen lokasjon i Europa, og dersom du ønsker det, kan du nå be om å få dette “tidlig” flyttet til Norge.
Ett begrenset opt-in vindu er nå tilgjengelig i 6 måneder for å be om tidlig migrering. Etter dette vil det være betydelig vanskeligere å få gjennomført migrering til Norge. Les mer for å se hvordan du ber om flytting.

%d bloggers like this: