@StevenKister1@PatchMyPC Fantastic! Thanks! What I was able to watch really useful information so I definitely want to go back for the whole thing and while less distracted.
We’re going live in 1 hour! ⏰
Secure Boot “checked” but not fully validated? This is your moment.
Devices can look healthy and still be exposed. No noise. No clear signal.
We’ll show you how to actually prove coverage 👉 bit.ly/4sHDU6y#MSIntune#ConfigMgr#CyberSecurity
@PJ_Marcum@miketerrill@2pintsoftware@mniehaus@gwblok@jarwidmark We’ll OSD for the foreseeable future. Quickly gets devices how we want them before user logs on. Pretty useful in K-12 when thousands of students get their laptops on the same day. We are keeping an eye on this if SCCM OSD disappears as an option or if this becomes a better.
@viamonstra@jarwidmark@AndrewJNet The recording link in this tweet looks like it is the "Life after MDT Training"? I'm going to watch both though! We are about 95% through our Win11 upgrade, but I may pick up tips for the remaining and also for the next Win11 to next Win11 version upgrade. Thank you for these!
@djammmer@bdam555 Time it takes us to get a device to the configurations and apps we want installed before the user logs on. Also reliability. SCCM OSD gets everything setup quickly and reliably.
What are the biggest gaps people are still having with Autopilot vs #configmgr OSD or MDT? And what are you currently using for imaging solution?
#msintune#windows
@MyNameIsMurray We’re about to re-evaluate student devices and Surface was going to be on the list. OSD is still the best option for us. Surface USB-C to Ethernet adapters are not an option? You are knowledgeable about this so I’m sure the answer is “no” for you and I want to understand why.
We have over 2000 Surface devices. We are in a position where we cannot yet use Autopilot without Hybrid-Join, but that configuration isn't ideal, so we need to continue ConfigMgr OSD for the time being instead. We need PXE support. And we deploy hundreds of devices at once...
Hey @surface team, now that it appears all but confirmed that the Surface Gigabit Ethernet Adaptors are EOL and are not included in the InCase deal, will you be releasing firmware that allows all our devices to PXE boot from third-party adaptors instead? I think this is required.
@rafal_fitt@AdamGrossTX@MicrosoftTeams We were looking into this for students, but personal accounts could still be used for Teams in browser so we decided it wouldn’t really help what we were trying to solve.
@PotentEngineer@gwblok@bdam555@TheWMIGuy Imaging is very important to us. Quickly and reliably gets a computer on the OS we want, latest security updates, and apps that are default in our environment. User logs in and is ready to go immediately.
@IntuneSuppTeam@Windows Can you help with this? Customer is using XML to configure Taskbar icons for Windows 11 based on this doc, which has been working for years. We notice that in Windows 11 23H2 (August patched), users can no longer pin any apps to the Start menu, but an older patching level example March updated Windows 11 23H2 can pin apps to the Start menu. Different build Windows and both are using the same Intune policy, with the same XML that only configured Taskbar settings, not any Start menu settings are configured. #MSIntune#Windows11learn.microsoft.com/en-us/windows/…
@JasonSandys@awakecoding@MSWindowsITPro Downloaded Store app content we package for a SW Center install would be helpful for us. Don't know if it is just our environment, but some Store apps often fail to download (not always) even from the MS Store. Not sure if we would have the same issue if deployed through Intune.
@JasonSandys@awakecoding@MSWindowsITPro We image devices and the 2 biggest reasons we opt for SW Center and not use Company Portal for installs: 1) The delay in the Company Portal being available. 2) Needing to be primary user (or getting needed devices to shared state).
You can now use WinGet to download Microsoft Store apps for offline distribution to other devices in your network. Looking for details? Check out the Windows IT Pro Blog: techcommunity.microsoft.com/t5/windows-it-…#Windows#Apps
@awakecoding@MSWindowsITPro That would be nice- we can’t universally use Powershell in user context in our environ to install with add-appxpackage. Might be helpful for some apps we provision during OSD though.
@MSWindowsITPro "Run the command Add-AppxPackage -Path C:\Users\username\downloads\9WZDNCRFHVN5\Calculator.appx to install the Calculator app on another device."
Well, that's disappointing, it's just saving the raw installer? You don't use the winget CLI again to install from the other machine?
@bdam555@PaulEAndrews That is what it looks like to me also and why they say you may have to use Group Policy to undo some keys- keys that ConfigMgr was setting before the new KB.
@PaulEAndrews Near as I can tell, and have no time to test for real at the moment, this KB simply stops the #ConfigMgr agent from trying to configure the Scan Source policies.
That's it: nothing more, nothing less.
This allows you to manage them as you see fit via GPO/Local Policy/Registry.
#ConfigMgr Hotfix (KB28458746) was just released.
It addresses one single issue: ConfigMgr trying, and generally failing, to properly set #Win11 Scan Source policies.
In short, it seems like they're giving up trying; allowing us to set it via GPO.
learn.microsoft.com/en-us/mem/conf…
@PaulEAndrews@bdam555 I found that they would show up if I manually ran one of the 2 Software Updates XXX actions from ConfigMgr Control Panel. I can’t remember which one though or if it was either.
@PaulEAndrews@bdam555 From what I was seeing, I think ConfigMrg was creating the SetPolicyDrivenUpdateSorceForXXX keys when it shouldn’t have. After a fresh image they were not there after a gp update, but showed up sometime later.