Enabling Microsoft “Cloud enabled LAPS” (Local Admin Password Solution)

LAPS – Local Admin Password Solution, has for a long time been one of those great tools to have in the toolbox when it comes to securing your devices from lateral movement from a potential attacker. And Microsoft LAPS have been around for quite some time already.

This tool was orginally available for deployment to server/desktop devices connected to a traditional domain (on-prem) setup.

This changed as of April 2023, and Microsoft have now introduced Microsoft LAPS (Preview) with support for configuration with Intune, and saving the passwords to Azure AD, giving us – once again – a native LAPS solution to handle the local admin account.

How to configure screensaver settings on non-enterprise editions of Windows with Intune

his is another post to deal with one of thelimitations of the various licensing editions of Windows.
To be specific, there are certain features that are only available if you have an Enterprise or Education edition of Windows.
This post beeing around the limitation of controlling the settings around enforcing and controlling the screen saver on devices via intune.
As always, every problem has a solution, or a viable workaround.

Holding back the upgrade to Windows 11 with Intune

With Windows 11 pushing its way towards your environment’s devices, you may find the need to hold back this upgrade to some or maybe all your devices, for any reason. Holding back the upgrade can be done via Intune for easy deployment to your devices. Script can be found in the post.

problem

Solved: Visma Lønn, random errors when showing “print” previews

This is just a quick post for an issue with Visma’s “Visma Lønn” application, that it may be nice to be aware of.
In Norway there are a few companies using “Visma Lønn” for payslips etc.
Some users may experience issues when doing some of the processes in the application, especially reports that involve the “Crystal reports” component.
When generating the reports, and when expecting the preview to show inside the application window, the user may get some “random” error messages.

Read on for the cause and workaround

problem

Solved: Logitech Webcam + Citrix CVAD seamless apps = reconnection problem

Sometimes its the small things causing problems in IT. Alot of hardware, drivers, software etc, can make a mess of each other. Recently I experienced this with the combination of Citrix Published Applications and a device from Logitech. Read on for details.

pointing

Manageability – Part 1: Naming Conventions

When it comes to managing anything within IT, it will always be a good thing to keep things organized, in one way or another. You should also make sure that the way you organize things, is made understandable for others as well (maybe you share the responsibility of management with a group, or may do so in the future).
Make it a habit to creating an organizational model that others can jump in or out of over time, that is logical and understandable by others than yourself. Document the logic/model that is defined, and make sure not to deviate from the actual definition as time goes by.

Security: How to enable sign-in with FIDO2 security keys on Windows 10 Devices and Azure AD

FIDO2 security keys are an unphishable standards-based passwordless authentication method that can come in any form factor. Fast Identity Online (FIDO) is an open standard for passwordless authentication. FIDO allows users and organizations to leverage the standard to sign in to their resources without a username or password using an external security key or a platform key built into a device. Read the post to see how you can enable this for your Azure ad and windows 10 devices.

Intune: Setting custom wallpaper and lockscreen on Windows 10 devices with PowerShell and Azure Storage Blobs

Many organizations want to deploy custom branded wallpapers and lockscreens on corporate managed devices. Doing this with Microsoft Intune is natively limited to Windows 10 Enterprise and Education. Follow this guide to see how you can do this with Intune and PowerShell toghether with Azure Storage Blobs.

Citrix Files: Setting default settings for desktop app with powershell

If you are using Citrix Content Collaboration and alongside it, using the Citrix Files app, you may be familiar with the fact that you cannot deploy centrally configured settings for the Citrix Files desktop app.
(PS: Citrix – why did you find it useful to name the service Content Collaboration, and then call the apps Citrix files? Please stop confusing the users.)

[…]

Citrix FAS: Sample setup leveraging FAS/ Azure iDP/ ShadowAccounts and Hybrid domain join.

Here’s an example of a usecase where Citrix FAS comes into play.
If you are not familiar with Citrix FAS and the use of it you may find this useful to get some insight to the usecases.
[…]

%d bloggers like this: