@Shikata_VX@techspence LAPS controls the account you specify, able to create a new account and leave the rid 500 one disabled like it should be. Other local admin accounts should be managed through delegation groups together with restricted group option via gpo.
@PJ_Marcum@tybyrnabeaux Now we just need smb over the Internet, which most firewalls are blocking as being best-practice. Working with Global Secure Access or VPN sounds better to me.
Testing enabled SSL and TLS protocols on servers is something I have to do for hardening and security purposes. You can do that using PowerShell with the Test-TlsProtocols Module from TechnologyAnimal.
#PowerShell#Security#Networking
https://t.co/N9yGtTWpr3
Wondering why, all of a sudden, Win32Apps are not being installed or updated on your device?
Let me start by explaining that you need to be very very careful when changing the Intune Management Extension config file.
Why? Because any change can cause the IME to stop working the way you expect.
Even something small, like switching the logging mode to verbose, can cause the IME to load the wrong DLL assemblies, and when that happens, all your Win32 app installations donโt even start. With it, the Company Portal stays stuck on โDownloadingโ with no real clue of what went wrong.
The full story and the fix are in the blog. (Be aware: this is a rudy deep-dive)
https://t.co/K3HdksZFLw
#Intune #MSintune #Windows #Windows11 #WindowsAutopilot