Get Rubix
Get Rubix
  • 211
  • 130 444
How to package apps with Intune - Part 2: Working with executables
Apparently, I made a video about packaging apps for Intune back in November and promised to make a "Part 2". I guess I forgot about it.
Thankfully, more people watch now and can call me out on those things.
So, by popular demand, here is Part 2 of how to package applications with Intune where we work with executable installers and talk about how to find their install switches, uninstall commands, and detection rules.
Here is Part 1:
ua-cam.com/video/E5RevbHL8tw/v-deo.html
Join the official Discord server
discord.gg/getrubix
Read more at
www.getrubix.com
Chapters
0:00:00 Broadway and rock concerts
0:01:12 More advanced packaging
0:01:28 EXE vs MSI
0:02:10 Finding the install parameters
0:03:43 Test install
0:04:15 Take notes!!!
0:04:41 Finding the uninstall string
0:06:50 Package and upload
0:10:21 That's all for now
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm
Переглядів: 158

Відео

How to detect and block applications with Intune and Defender for Endpoint
Переглядів 9684 години тому
You know the problem- you issue corporate laptops to your users for business only, and then sooner or later you see someone playing World of Warcraft. Don't you hate it when that happens? Today I'll show you how to detect for unwanted apps in your environment with Defender for Endpoint, and then how to block them from launching or installing with an Intune AppLocker policy. Join the official Di...
How to use Autopilot pre-provisioning
Переглядів 64814 годин тому
You would think with all the yapping I do about Autopilot that I must have covered the topic of pre-provisioning. But wouldn't ya know... I didn't! So today, get ready for a (long overdue) deep-dive into how to use Autopilot pre-provisioning. Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com Chapters 00:00:00:00 It's too hot 00:01:09:26 Architecture of pre-provi...
How to find the "hidden" winget apps in Intune
Переглядів 69016 годин тому
Don't you hate when you're searching the "new" Microsoft Store for winget apps, only to find that they're not available? Well it turns out, they actually are. Today I'll show you how, with a little help from Postman, we can find the hidden winget apps inside Intune. Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com Chapters 0:00:00 The lost art of Karaoke 0:01:1...
Device migration update: unjoining the domain
Переглядів 37821 годину тому
Thanks to all who have been testing the V7 of our migration script. Based on the first round of feedback, here is a look at the first major update to address some of the issues around unjoining the local domain. Intune Device Migration solution: stevecapacity.github.io/intune-device-migration-documentation/ Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com Chapt...
Troubleshooting Device Migration Part 1: Bulk refresh token
Переглядів 271День тому
Today we're going to start troubleshooting some common issues with device migration, mainly looking at the bulk primary refresh token and getting access to your destination tenant. New Azure Service Principal cmd: New-AzureADServicePrincipal -AccountEnabled $true -AppId 00000014-0000-0000-c000-000000000000 -AppRoleAssignmentRequired $False -DisplayName Microsoft.Azure.SyncFabric -Tags {WindowsA...
How to speed up Autopilot deployment
Переглядів 1,8 тис.14 днів тому
I always get asked "Steve, what's with all the tacos and pop-tarts in your UA-cam thumbnails?" That I prefer not to answer. The other question I get asked is "how do I speed up my Autopilot deployment?" After being inspired by a post from fellow MVP Lewis Barry, here are the best practices to implement in Intune for giving users a speedy Autopilot deployment. Policy from the video: ./Vendor/MSF...
Migrate a PC from domain to cloud
Переглядів 1,5 тис.14 днів тому
So as soon as I show the first demo of V7, the response seemed pretty unanimous... "Steve, that's great and all, but show us the domain to cloud migration!" Understood. Here is the Intune Device Migration V7 tool migration an on-premises domain joined PC to full cloud native Entra joined and Intune managed. Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com Chapt...
Intune Device Migration V7: Demo
Переглядів 66521 день тому
Enough talk (I know, that's hard for me). Who wants to see V7 in action? Remember, the beta goes live Monday, August 5th so if you want access make sure you're a member of our Discord server (link in below). Want beta access on August 5th? Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com Chapters 0:00:00 I won't go skydiving 0:00:56 Quick updates before the dem...
Intune Device Migration V7: Preview
Переглядів 1,3 тис.21 день тому
I've been waiting a long time to start sharing this with everyone. Finally, the Intune Device Migration tool version 7 is coming out, and will include scenarios to migrate a PC between Intune tenants in addition to migrating the device state from domain or hybrid join to pure cloud native. Want to fully migrate from SCCM or comanaged? We can do that too. And forget about 4 reboots... we're taki...
How to setup Windows 365 restore points
Переглядів 17921 день тому
Windows 365 is an amazing platform for quickly and easily deploying Cloud PCs to end users. But last week is when it's true colors really showed. Folks that had Cloud PCs affected by the CrowdStrike issue were simply able to roll back to a prior state and fix the issue with minimal downtime. Today, I'll show you how to setup Windows 365 restore points. Join the official Discord server discord.g...
The GetRubix PODCAST - Episode 21: Analytics and Automation
Переглядів 20228 днів тому
The podcast is back, and I think you're all going to like this one- there are no mentions of CrowdStrike or recovery screens. If you don't already follow Max Allen, then you're missing out on some killer content about Azure functions, automation, and log analytics. Today, Max and I had a great conversation about creating solutions for endpoint management using these tools, and then proceeded to...
Updated BitLocker Key rotation
Переглядів 49628 днів тому
Well, it looks like we have a slight issue with today's automatic BitLocker key rotation solution. Watch it here: ua-cam.com/video/l0AK3TPVU7w/v-deo.html Despite the documentation, the required "BitockerKey.Read.All" permission is not available as an Application permission (only Delegated). Hopefully, this will get sorted out soon, which means the original solution will work. In the meantime, I...
How to automatically rotate your BitLocker recovery keys every 30 days
Переглядів 57528 днів тому
UPDATE: There is currently an issue with the graph API permissions for reading the BitLocker recovery key info (the createdDateTime). Watch here: ua-cam.com/video/vr08g2L86p8/v-deo.html In the meantime, check out my updated version which uses a self-declared time stamp to rotate every 30 days: github.com/stevecapacity/IntunePowershell/tree/main/bitlockerAutoRotate/V2 Stay tuned Last week wasn't...
More TPM attestation and diving into MDM hardening
Переглядів 301Місяць тому
More TPM attestation and diving into MDM hardening
Intro to Device Attestation Status with Intune
Переглядів 527Місяць тому
Intro to Device Attestation Status with Intune
How to create a PowerShell module
Переглядів 381Місяць тому
How to create a PowerShell module
Getting started with the new Entra PowerShell module
Переглядів 1,1 тис.Місяць тому
Getting started with the new Entra PowerShell module
Autopilot onboarding experience for new users
Переглядів 706Місяць тому
Autopilot onboarding experience for new users
How to configure Endpoint Privilege Management Support-Approved Elevations
Переглядів 431Місяць тому
How to configure Endpoint Privilege Management Support-Approved Elevations
Update about Intune Config Refresh
Переглядів 488Місяць тому
Update about Intune Config Refresh
How to setup Intune Config Refresh
Переглядів 745Місяць тому
How to setup Intune Config Refresh
Conditional Access Part 3: Windows App Protection (MAMWE)
Переглядів 558Місяць тому
Conditional Access Part 3: Windows App Protection (MAMWE)
Prepare for Autopilot Device Preparation with a Provisioning Package
Переглядів 956Місяць тому
Prepare for Autopilot Device Preparation with a Provisioning Package
Conditional Access Part 2: Managed VS unmanaged devices
Переглядів 532Місяць тому
Conditional Access Part 2: Managed VS unmanaged devices
Conditional Access Part 1: What is it and how to get started
Переглядів 486Місяць тому
Conditional Access Part 1: What is it and how to get started
How to setup Mobile App Management without Enrollment (MAMWE)
Переглядів 583Місяць тому
How to setup Mobile App Management without Enrollment (MAMWE)
How to remove the Classic Teams client with Intune
Переглядів 1,3 тис.Місяць тому
How to remove the Classic Teams client with Intune
How to setup Patch My PC with Intune
Переглядів 7622 місяці тому
How to setup Patch My PC with Intune
How to package and deploy the New Teams app (and remove the "personal" Teams client)
Переглядів 2,5 тис.2 місяці тому
How to package and deploy the New Teams app (and remove the "personal" Teams client)

КОМЕНТАРІ

  • @EndpointManagementBR
    @EndpointManagementBR 3 години тому

    Amazing content, I recently had to use applocker to block apps, but I started learning that wdac is the future, although still using applocker for some simpler cases

  • @JustFixItGoldCoast
    @JustFixItGoldCoast 3 години тому

    awesome

  • @jonathang8571
    @jonathang8571 4 години тому

    Awesome video! Testing this out and able to add the Adobe Creative Cloud and Teams. Think this will come in very handy. Really appreciate the content you've been sharing.

  • @BobSince1981
    @BobSince1981 5 годин тому

    7:28

    • @getrubix
      @getrubix 3 години тому

      I throw in easter eggs to see who watches the whole thing lol

  • @TakeingCrazyPills
    @TakeingCrazyPills 8 годин тому

    Does this work for apps that are on winget? An example, iCloud has a store version, but iTunes is winget only.

  • @gabrielluizbh
    @gabrielluizbh 11 годин тому

    Hello! I have a question regarding Autopilot V1 and V2. Autopilot V1 I have to enter information into Intune, such as hardware hash. In the case of Autopilot V2, I no longer need to execute the process. How should I proceed with the acquisition of new devices with Dell, since there is no longer a need to have the hardware hash. Just ask the manufacturer to send the devices and that's it?

  • @fbifido2
    @fbifido2 День тому

    if you have Autopilot V1 and Autopilot V2 configure which will intune use?

  • @fbifido2
    @fbifido2 День тому

    is there a builtin power-shell command to get the corporate device identifier in csv to manually upload it?

  • @gaelnicolas1728
    @gaelnicolas1728 День тому

    Thanks for another great video Steve!

  • @DaysofIresh
    @DaysofIresh День тому

    Hi, after implementing this, have there been any changes to the Defender portal?

  • @bigboibungus9725
    @bigboibungus9725 День тому

    I appreciate shedding light on applocker, as it’s a very underutilzied tool. I do think the scenario you are showcasing is not the correct way of going about it though. If an application is spotted that should not be allowed to run, it should simply just be uninstalled remotely. Applocker policies should restrict anything not whitelisted from being installed. To take it a step further i would only do explicit blocks on LOLBINs to prevent misuse of the default allow policies for malicious use. Also, doing path level blocks/allows is silly. Whos to say the path isnt different than specified? Any user can see what policies are deployed if they know how to look. File hashes and publishers are the way to go

    • @getrubix
      @getrubix День тому

      Makes sense. This scenario is meant to offer a basic understanding of how it works. There are many different ways to utilize depending on the situation. Thanks!

  • @andyeeaust
    @andyeeaust День тому

    Can't find "Microsoft Intune" in the exclusion list. "Microsoft Intune Enrollment" is available. When i would add "Microsoft Intune" via Powershell it says, that it's allready assigned. Do i need intune?

  • @royvdhoek
    @royvdhoek День тому

    When you created the Applocker default rules all executables in the Program Files and Windows folders are allowed by default. What about MS Teams?, that application executable is stored in the User folder or ProgramData folder? Can you still open Teams? and check that in your lab environment? And maybe it is a good idea to make an allow rule to run all signed Microsoft executables, just in case there are Microsoft executables in ProgramData that needs to run.

  • @jonathang8571
    @jonathang8571 2 дні тому

    Haven't had a need for this (yet), but your video makes it quite clear how to implement this if/when we need to do so. Much appreciated!

  • @slundy
    @slundy 2 дні тому

    So when you added Thunderbird to the policy, you just appended it to the end of the value in Intune?

  • @orionyt9323
    @orionyt9323 2 дні тому

    I love you. That's all.

    • @getrubix
      @getrubix 2 дні тому

      Right back at ya!

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 дні тому

    Thanks for another great video Steve!! I definitely will be using this AppLocker Method! Thank you for saving the day! Very Helpful and much needed!!

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 дні тому

    Hey Steve My Friend! Another great video! With the Autopilot pre-visioning configurations setup, what makes this method different from this New Windows Autopilot device preparation method?

  • @eugenemeenan3703
    @eugenemeenan3703 2 дні тому

    brilliant - here's something - PC's that are hybrid will I have to remove them from intune and Entra first

    • @getrubix
      @getrubix 2 дні тому

      No, this will work for hybrid

  • @kyleutech8191
    @kyleutech8191 2 дні тому

    Have you ever seen an error where one file share occasionally has a connection issue, but none of the others do? I followed your instructions and it works, except one of the file shares (which is configured exactly the same way in GSA as the others) occasionally will give an error: networksharename is not accessible. You might not have permission to this network resource. We only run into this with one share, the other 5 work perfectly, all using same SMB share app in Entra and group access.

  • @souravdutta9734
    @souravdutta9734 2 дні тому

    Thanks for this . I created a configuration profile in Intune with this trick and it worked really well on most of the devices . But I was reported that only 2 users were unable to open MS outlook, Teams , Company portal apps once the policy is applied . And when I removed the policy from these 2 users , they can access the MS apps again . Can you please check this and let me know why this happened ? Note - I did exactly what you shared.

  • @ShawnOfeoiwnofne
    @ShawnOfeoiwnofne 5 днів тому

    I had turn off Pre-Provisioning. Every time we let our workstations sit for a day or more after reseal, it would forget that it was in the middle of the Autopilot process and skip past the user provisioning part causing all kinds of issues.

  • @pontuswendt767
    @pontuswendt767 5 днів тому

    Thanks for the video, do you have the diagram anywhere? :)

    • @getrubix
      @getrubix 5 днів тому

      Not yet but I have something new coming where I'll be posting all the diagrams/docs used in the videos 😃

    • @pontuswendt767
      @pontuswendt767 4 дні тому

      @@getrubix Thanks man! :D

  • @ironmaidenfreak001
    @ironmaidenfreak001 5 днів тому

    Thanks for the video. It might be a stupid question, but is this already with Autopilot V2? because it had the classic ESP layout. And can we monitor the install process in Intune?

    • @getrubix
      @getrubix 5 днів тому

      Pre-provisioning is not available in APV2

  • @XsterTHEmINEK
    @XsterTHEmINEK 5 днів тому

    Very helpful and good video 👍

  • @Motoralist
    @Motoralist 6 днів тому

    It looks completly different in my Intune ...Windows365 is not accessable despite the fact that we have all the necessary licences and admin roles.

  • @Timmy-Hi5
    @Timmy-Hi5 6 днів тому

    any soution for the N-able client :)

  • @adrianbishop694
    @adrianbishop694 6 днів тому

    Does apps automatically update using the new win store method including ones like creative cloud?

    • @getrubix
      @getrubix 6 днів тому

      Haven't tested yet. Also depends if the app is auto updating

    • @martinzonderland1543
      @martinzonderland1543 6 днів тому

      @@getrubix this is exactly the problem I see with my customers, VLC player in your video is a good example, at this moment it's installing 3.0.16 and there's no auto updating... The app itself you can check manually for updates and you will see that there's a newer version 3.0.20 (on the site 3.0.21). But you will need administrative rights if you will try to update as an enduser this application (not working for us). It seems to be that also VLC is not updating the Win32 version in the Windows Store. Some apps it's working fine, like Adobe Reader, after installing auto-update from Adobe is working (in the background, you don't need administrator rights for the updates), it installs not the newest version but will update to the latest version after installation. For an Enterprise environment you will need not only a simple deployment, but also a simple patch management process for your apps.

    • @TakeingCrazyPills
      @TakeingCrazyPills 8 годин тому

      @@martinzonderland1543 A proactive remediation could be deployed to keep up to date.

  • @nebraskayak7632
    @nebraskayak7632 7 днів тому

    Amazing content again! I can’t believe how you are able to provide so much unique content that every Intune admin is looking for.

    • @getrubix
      @getrubix 6 днів тому

      Thanks! I'm glad it's useful

  • @MrMarcLaflamme
    @MrMarcLaflamme 7 днів тому

    I have so many apps in my list to add to Company Portal that aren't "ready" yet. Not ready to do it this way but cool to see that it's possible. I wonder why it doesn't like the version code for that example? One of the apps that's annoying right now is Notepad++. Shows up with winget search and it's in the winget repo but the Add App in Intune comes back with 0 results. 🤷‍♂

  • @DLSC2374
    @DLSC2374 7 днів тому

    Amazing

  • @jerloper
    @jerloper 8 днів тому

    What would be the advantage of using the remediation script for removing Personal Teams vs using a Configuration Profile? I have a configuration profile that removes the Chat icon from the taskbar and that also seems to remove Teams Personal.

    • @getrubix
      @getrubix 7 днів тому

      No advantage, just different options. I say, do what works!

  • @tothemoonisuppose
    @tothemoonisuppose 9 днів тому

    Thank you!

  • @ifoam
    @ifoam 9 днів тому

    If I'm understanding this correctly, I need to setup a connector on each server that I want to have accessed in this method. I then control the ports available through the enterprise applications. However, this doesn't limit the physical server access on those ports right? If another device was on the same network as a server on this platform, it could communicate and access that device as normal?

    • @getrubix
      @getrubix 9 днів тому

      That is correct.

  • @chandrashekhar6545
    @chandrashekhar6545 9 днів тому

    Hey thanks so much for the tutorial...How about if someone wants to migrate their devices from a RMM platform like Ninjaone to Intune..how can we do that without performing a reset on the devices

    • @getrubix
      @getrubix 9 днів тому

      It's a bit hard as each rmm tool will require some modification. But it is possible

  • @summoner2100
    @summoner2100 9 днів тому

    I agree with you re: self service.. but you haven't met my users clearly, I've been trying to build self service first policy for a few years lol

    • @getrubix
      @getrubix 9 днів тому

      I hear ya. It can be a struggle 😁

  • @ashisharya65
    @ashisharya65 10 днів тому

    Hi, Thank you so much for making this video. Can you please also make a video on how to automate the corp identifier upload using Azure Functions as well.

  • @christophercass5713
    @christophercass5713 11 днів тому

    I find that using a Windows VM, 10 or 11, Workgroup and not joined to any tenant/domain to create PPKGs works the best. I have used PPKGs to migrate devices using Forensit Profile Migration tool for many clients as well as adding the Forensit tool to CP to do tenant to tenant migrations. Sometimes I would get a failure on the tenant enroll side and produced the following to force the device into the new tenant. Sorry, this is a bit messy, but it works. Run as system and I would use a tool like ConnectWise Screen connect to backstage into a remote PC and run these #Sometimes the device failed to leave the old tenant, running as system this should kick it off join dsregcmd /debug /leave #The following cleans up the registry, when the PPKG fails to join the PC it can be due to the old tenant enrollments. This data is not purged when a device is unjoined from UI or cmd. $EnrollmentsKey = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments -Exclude Context,OwnerShip,Status,ValidNodePaths | Where {$_.Property -contains "UPN"} foreach ($Key in $EnrollmentsKey){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\$KeyToDelete" -Force -Recurse} $EnrollmentsKey1 = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\Status | Where {$_.Property -contains "LifecycleNotificationHResult"} foreach ($Key in $EnrollmentsKey1){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\Status\$KeyToDelete" -Force -Recurse} $EnrollmentsKey2 = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\Diagnostics\Enrollment -Exclude Context,OwnerShip,Status,ValidNodePaths | Where {$_.Property -contains "Time"} foreach ($Key in $EnrollmentsKey2){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\Diagnostics\Enrollment\$KeyToDelete" -Force -Recurse} $EnrollmentsKey3 = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Logger | Where {$_.Property -contains "OmaDmPrc"} foreach ($Key in $EnrollmentsKey3){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Logger\$KeyToDelete" -Force -Recurse} Remove-ItemProperty "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Logger" -Name CurrentEnrollmentId -Force Remove-ItemProperty "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Logger\Provisioning" -Name OmaDmSession -Force Remove-ItemProperty "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\MDMDeviceID" -Name DeviceClientId -Force $EnrollmentsKey4 = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Sessions foreach ($Key in $EnrollmentsKey4){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Sessions\$KeyToDelete" -Force -Recurse} $EnrollmentsKey5 = Get-ChildItem "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\EnterpriseMgmt" foreach ($Key in $EnrollmentsKey5){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\EnterpriseMgmt\$KeyToDelete" -Force -Recurse} $EnrollmentsKey6 = Get-ChildItem "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\Status" foreach ($Key in $EnrollmentsKey6){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Enrollments\Status\$KeyToDelete" -Force -Recurse} $EnrollmentsKey7 = Get-ChildItem "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\AdmxDefault" foreach ($Key in $EnrollmentsKey7){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\AdmxDefault\$KeyToDelete" -Force -Recurse} $EnrollmentsKey8 = Get-ChildItem Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Accounts | Where {$_.Property -contains "RoamingCount"} foreach ($Key in $EnrollmentsKey8){$KeyToDelete = $Key.PSChildName;Remove-Item "Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Provisioning\OMADM\Accounts\$KeyToDelete" -Force -Recurse} #Other commands to have at the ready Get-ProvisioningPackage dsregcmd /join dsregcmd /status gpupdate /force Write-Host Join One last note, adding logging to your PPKG install. Add the date when the bulk token will expire, so you know not to use it after that date. Have the PPKG install a remote tool, like ConnectWise Control. Powershell.exe Install-ProvisioningPackage -PackagePath C:\Users\defaultuser0\Documents\ConnectWiseControl\Files\Company_PPKG_8AUG_atOOBE_noWIFI_wCWC_EXP03FEB2024.ppkg" -ForceInstall -QuietInstall -LogsDirectoryPath C:\PPKG_Install.log

  • @sandeepsharmaynr
    @sandeepsharmaynr 11 днів тому

    Hello I am getting following error during the export package. PS C:\WINDOWS\system32> winget-intune package 7zip.7zip --package-folder C:\WinGet winget-intune : The term 'winget-intune' is not recognized as the name of a cmdlet, function, script file, or operable program. Check the spelling of the name, or if a path was included, verify that the path is correct and try again. At line:1 char:1 + winget-intune package 7zip.7zip --package-folder C:\WinGet + ~~~~~~~~~~~~~ + CategoryInfo : ObjectNotFound: (winget-intune:String) [], CommandNotFoundException + FullyQualifiedErrorId : CommandNotFoundException

    • @sandeepsharmaynr
      @sandeepsharmaynr 11 днів тому

      Event i have installed all the required package.

  • @DaysofIresh
    @DaysofIresh 11 днів тому

    Manually joining to Entra ID, after restarting clients are going to the Windows autopilot screen instead of logging directly, what does it cause?

    • @getrubix
      @getrubix 11 днів тому

      Is it the Autopilot sign in or the ESP?

    •  10 днів тому

      Don’t allow the ESP to show outside of the OOBE. It’s a setting in the ESP.

    • @DaysofIresh
      @DaysofIresh 10 днів тому

      @@getrubix No ESP. Once we join manually and reboot the device.

    • @DaysofIresh
      @DaysofIresh 9 днів тому

      I tried that still showing.

  • @rashkam8458
    @rashkam8458 12 днів тому

    Always i learn new things. Thanks alot and keep doing the good job!

  • @charlie_khan
    @charlie_khan 12 днів тому

    Once it is done it asks me to login with my new tenant account but when I try it tells me. The user name or password is incorrect. Has anyone seen this before?

  • @jonathang8571
    @jonathang8571 12 днів тому

    Appreciate the great video! Actually just working on setting up the ESP, after having it simply disabled for a long while. Love the idea of skipping the user section and going to test that out! One thing I'll add - been trying to include just Office 365 apps and Company Portal (deployed in system context) as required, but CP seems to be hit or miss on it actually appearing when reaching the desktop.

    • @emekanwosu6786
      @emekanwosu6786 9 днів тому

      This is so true. Also I have noticed that deploying CP from the new store, is mega Hit or Miss. I found a remediation script that has pushed my installation rate from 20% to over 85%.

    • @jonathang8571
      @jonathang8571 8 днів тому

      @@emekanwosu6786 Do you have a link to the remediation script you found?

  • @dougsmith5502
    @dougsmith5502 12 днів тому

    Your video says the OMA-URI is ./Vendor/MSFT/DMClient/Providers/...... but should it be ./Vendor/MSFT/DMClient/Provider/......

  • @TheoDeyle
    @TheoDeyle 12 днів тому

    That shirt is a smack of nostalgia at 6 in the morning! Thank you for that sir!

  • @lowlevelretro
    @lowlevelretro 13 днів тому

    Thanks Steve... line 3 of Remdiate.ps1 , I'de put -AllUsers in on the Remove-AppxPackage line ... and your detect script has 2 messages saying found teams :)

  • @iliyatodorov9320
    @iliyatodorov9320 13 днів тому

    Question? - will it rotate all drives or just system?

    • @getrubix
      @getrubix 13 днів тому

      Depends on the policy in Intune.

  • @CAHOP2401
    @CAHOP2401 13 днів тому

    I thought this new user-centric deployment would be cool. I can have separate user groups that would put their machines in different device groups and the big thing for me was a device naming standard. Users at different sites would have machines with a different prefix, easy-peasy. I go to demo this out and realize you CAN'T set the device name (yet) in the OOBE profile. I'm going to test pushing a script to rename the computer and hopefully it will only rename the computer once after a reboot.

  • @Tamis_ExploringAlberta
    @Tamis_ExploringAlberta 14 днів тому

    Hi .. i am getting error opening new teams app.. i made sure the app exists by running appx command in PS. The error is Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item

  • @AlanSantos-k5j
    @AlanSantos-k5j 14 днів тому

    How do you handle granular file/folder permissions say giving access to file, five folders down the SMB share to a user or group

    • @getrubix
      @getrubix 14 днів тому

      That should be handled the same way it is on premises. The user permissions still come from AD.