Enabling Microsoft “Cloud enabled LAPS” (Local Admin Password Solution)

LAPS – Local Admin Password Solution, has for a long time been one of those great tools to have in the toolbox when it comes to securing your devices from lateral movement from a potential attacker. And Microsoft LAPS have been around for quite some time already.

This tool was orginally available for deployment to server/desktop devices connected to a traditional domain (on-prem) setup.

This changed as of April 2023, and Microsoft have now introduced Microsoft LAPS (Preview) with support for configuration with Intune, and saving the passwords to Azure AD, giving us – once again – a native LAPS solution to handle the local admin account.

How to configure screensaver settings on non-enterprise editions of Windows with Intune

his is another post to deal with one of thelimitations of the various licensing editions of Windows.
To be specific, there are certain features that are only available if you have an Enterprise or Education edition of Windows.
This post beeing around the limitation of controlling the settings around enforcing and controlling the screen saver on devices via intune.
As always, every problem has a solution, or a viable workaround.

Holding back the upgrade to Windows 11 with Intune

With Windows 11 pushing its way towards your environment’s devices, you may find the need to hold back this upgrade to some or maybe all your devices, for any reason. Holding back the upgrade can be done via Intune for easy deployment to your devices. Script can be found in the post.

pointing

Manageability – Part 1: Naming Conventions

When it comes to managing anything within IT, it will always be a good thing to keep things organized, in one way or another. You should also make sure that the way you organize things, is made understandable for others as well (maybe you share the responsibility of management with a group, or may do so in the future).
Make it a habit to creating an organizational model that others can jump in or out of over time, that is logical and understandable by others than yourself. Document the logic/model that is defined, and make sure not to deviate from the actual definition as time goes by.

Security: How to enable sign-in with FIDO2 security keys on Windows 10 Devices and Azure AD

FIDO2 security keys are an unphishable standards-based passwordless authentication method that can come in any form factor. Fast Identity Online (FIDO) is an open standard for passwordless authentication. FIDO allows users and organizations to leverage the standard to sign in to their resources without a username or password using an external security key or a platform key built into a device. Read the post to see how you can enable this for your Azure ad and windows 10 devices.

Intune: Setting custom wallpaper and lockscreen on Windows 10 devices with PowerShell and Azure Storage Blobs

Many organizations want to deploy custom branded wallpapers and lockscreens on corporate managed devices. Doing this with Microsoft Intune is natively limited to Windows 10 Enterprise and Education. Follow this guide to see how you can do this with Intune and PowerShell toghether with Azure Storage Blobs.

Citrix FAS: Sample setup leveraging FAS/ Azure iDP/ ShadowAccounts and Hybrid domain join.

Here’s an example of a usecase where Citrix FAS comes into play.
If you are not familiar with Citrix FAS and the use of it you may find this useful to get some insight to the usecases.
[…]

Windows Autopilot – Failing on app configuration when running Windows 10:1903

If you are running Windows autopilot on devices you may experience issues during enrollment/configuration after the 1903 update.
The issue comes when deploying Windows store apps with autopilot, and you may get faced with the enrollment process giving you an error when it gets to this step.

[…]

Intune – Publishing win32 applications with Intune

So, you got licenses for Microsoft Intune, and want to roll out some applications to your devices.
If you are new to this you may be faced with some issues, especially regarding what kind of applications you can publish, and how to do so.
There are numerous formats for applications to manage these days – you got the Windows store applications (appx) from Windows 8>>, Line of business apps in the form of MSI installers, and win32 apps.
I will not go into detail on MSI and Windows store here, as these are rather easy to deploy via the information in the web gui.

[…]
%d bloggers like this: