Featured posts

Building a Secure LAPS Password Portal with Azure and Microsoft Graph

Continue reading “Building a Secure LAPS Password Portal with Azure and Microsoft Graph”

Soft‑Deleted Entra ID Group Broke an Intune Role

Recently, I ran into a confusing Intune issue that looked like a permissions problem… but turned out to be something completely different and far more subtle.
If you work with Intune RBAC, custom roles and scope tags, this story may save you a lot of troubleshooting.

Continue reading “Soft‑Deleted Entra ID Group Broke an Intune Role”

Create a Custom Entra ID Role to View LAPS Passwords in Microsoft Intune

We’re planning to roll out Windows Local Administrator Password Solution (LAPS), and a key requirement is that our helpdesk staff and workplace admins can access the LAPS password. This post shows how to view LAPS passwords in Intune without granting to much permissions. I will explain how to create a custom Microsoft Entra ID role that allows controlled visibility of LAPS passwords, and how to integrate this role seamlessly with existing Privileged Identity Management (PIM) group.

Continue reading “Create a Custom Entra ID Role to View LAPS Passwords in Microsoft Intune”

Error 0X800F0954 installing Feature on demand like Basic typing, handwriting, text-to-speech, etc.

Employees using our managed workstations have recently encountered issues installing Windows 11 language packs FOD. While the language packs install without a hitch, additional features such as Basic typing, handwriting, and text-to-speech fail to install across all attempted languages. In this post I will explain the cause of the problem and provide a solution.

Continue reading “Error 0X800F0954 installing Feature on demand like Basic typing, handwriting, text-to-speech, etc.”

Postpone or enable MFA for cloud admin accounts to access Microsoft admin Portals

Microsoft is set to enforce Multi-Factor Authentication (MFA) on admin accounts accessing the Microsoft Entra Admin Center, Azure portal and Microsoft Intune Admin Center starting October 15, 2024.

This article will guide you through the steps to either postpone this enforcement or immediately implement MFA for your admin accounts.

Continue reading “Postpone or enable MFA for cloud admin accounts to access Microsoft admin Portals”

Teams Outlook add-in missing after uninstall Classic Teams

Last week we were getting reports from employees that the Teams add-in in Outlook suddenly disappeared. After some research we discovered this happened because the Classic Teams was uninstalled automatically in the background by the Microsoft policy. These employees already were working with Teams 2.0. There are a few ways to get the Outlook add-in working again. In this post I will show how you can fix this, form a manual action to running a script.

Continue reading “Teams Outlook add-in missing after uninstall Classic Teams”

Great tool to change MECM content path locations

Just a tip for a really useful tool. Our storage department was planning a storage migration so the content share used for applications, packages, etc in MECM (SCCM) changed. We already used a cname to point to the content share for a lot of objects but not for all of them. So I was looking for a tool to change content paths to the correct cname share in MECM.

This tool does the job! I can really recommend it!

Continue reading “Great tool to change MECM content path locations”

Deploy Microsoft Project and Visio (Click-to-run)

I got a request at work if I could create the deployment of the latest versions (Click-to-run) of Microsoft Visio and Project and set the Monthly update channel. The deployment of the applications should be made available in the Company Portal for users that are a member of the Entra ID synced Active Directory group to which the Visio and or Project Online plan licenses are assigned to.
We still run a 32 bits MS365 Apps on devices so got a mix of 32 bits and 64 bits MS 365 apps. The deployment should automatically detect the MS 365 apps architecture and then install the correct 32 or 64 bits version of Project and / or Visio. In this post I will show you how I did this. I will also provide all the sources and scripts you need to accomplish this.

Continue reading “Deploy Microsoft Project and Visio (Click-to-run)”

Change Intune device category with PowerShell and MS Graph Intune module

I tried to find a way to be able to change the category assigned to an Intune device without having to use the Intune portal. I found a lot of information about it and even working scripts. But these scripts didn’t do exactly what I wanted. So I used some scripts and information about PowerShell and the MS Graph Intune module and merged them into my script. Some results I wanted to accomplish were to change an Intune device category by using the device name and the category name not the device ID or category ID. I also build in some checks. I wrote this post about it and I hope you find it useful.

Continue reading “Change Intune device category with PowerShell and MS Graph Intune module”

Deploy the Company Portal with Intune

In this post I will show you how to deploy the Company Portal App from the Microsoft Store app (new) with Intune. The company portal is an essential app you should deploy on the devices you want to manage with Intune. With the Company Portal users can securely access their company apps and data, install or reinstall applications, check if the device meets compliancy and more.

You can install the company portal on Windows 10/11, macOS, Android and iOS, but I will cover the Windows deployment in this post.

Continue reading “Deploy the Company Portal with Intune”
Theme: Overlay by Kaira