Posts

Run remediation on-demand on Windows Client using Microsoft Intune

Image
In this new article, we will focus on an option that has been available in Preview for a few months now, it is Remediation on-demand The proactive remediations is scripts package available in the Microsoft Intune administration console. They detect and resolve common support issues on a user's device before they even realize there is a problem. We will see below what the necessary prerequisites are and how to use this new functionality. Prerequisites Whether enrolling devices via Intune or Configuration Manager, Remediation scripting has the following requirements: Devices must be Microsoft Entra joined or Microsoft Entra hybrid joined and meet one of the following conditions: Is managed by Intune and runs an Enterprise, Professional, or Education edition of Windows 10 or later. A co-managed device running Windows 10, version 1903 or later. Co-managed devices on preceding versions of Windows 10 will need the Client apps workload pointed to Intune (only applicable up to version 1607

How to disable Copilot on Windows using Microsoft Intune

Image
  In this article, we will see how to disable Copilot on Windows using the Microsoft Intune solution. As a reminder, Windows Copilot is an Artificial Intelligence feature introduced by Microsoft in Windows 11 and which acts as a personal assistant by providing you with personalized recommendations, information and streamlined workflows to improve productivity and user experience . In some cases, it may be necessary to consider deactivating Windows Copilot and to do so, there are several possibilities :  GPO OMA-URI Settings Catalog Here, we will see the method via Settings Catalog . Disable Copilot for Windows with Settings Catalog Go to the Intune.microsoft.com console then perform the following actions: Go to Devices , Windows , Configuration Profiles and click on Create and New Policy In the Create Profile section, choose the following options: Platform : Windows 10 and later Profile Type Settings catalog Click Create In the Create a profile section, complete the fields : Name D

Block access to the Microsoft Store using Microsoft Intune

Image
A secure work environment involves the implementation of processes, particularly those related to packaging, to allow the user to access reliable applications that have been tested and validated by the IT team. As soon as this first step is completed, it is necessary to restrict access to the Microsoft Store so that users can only install software provided through the corporate catalog. We'll see below how to block access to the Store through the Microsoft Intune solution, while still allowing apps flowing from it to continue receiving updates. Block access to the Microsoft Store Log on to Intune.microsoft.com and perform the following steps: Click on Devices / Windows  And select  Configuration Profiles Click on Create and New Policy When creating, select the following parameters Platform: Windows 10 and later Profile Type: Settings Catalog Click Create Complete Name field and click Next Then click Add Settings In the Search box , find, add and configure the following: Turn of

Copilot on your keyboard !

Image
Microsoft has just announced that the next generation of computers equipped with Windows 11 will have a keyboard key dedicated to Copilot. 

Enabling Edge Workspaces on Windows 11 with Microsoft Intune

Image
Présentation Edge Workspaces provides an incredible way for customers to organize their browsing tasks into dedicated windows. Each Edge Workspace contains its own sets of tabs and favorites, all created and curated by the user and their collaborators. Edge Workspaces are automatically saved and kept up to date. Workspaces are accessible anywhere customers use Microsoft Edge with their Microsoft Entra accounts. Prérequisites Users must have a Microsoft Entra tenant and Microsoft Edge version 114 or later installed or  Microsoft Edge for Business version 116 To manage via group policy, Admins must have Microsoft Edge version 114 or later installed and version 114 of the policy files. Users must have access to a OneDrive for Business license to create an Edge Workspace Enable feature with Microsoft Intune Go to intune.microsoft.com Select Devices / Windows / Configuration Profiles and click Create Create profile Platform : Windows 10 and later Profile type : Settings catalog Complete

Allow Windows 365 users to reset their Cloud PC

Image
A new option for Windows 365 Cloud PC users has just appeared. It allows you to delegate a right allowing the user to reset his cloud PC. In this blog post, we can see how to configure this option and  Reset option's configuration Go to Intune.microsoft.com Navigate to Devices / Windows 365 Click on tab  User settings Click ADD for create a new rule or select an existing rule for modify them configuration Tick the case :  Enable users to reset their Cloud PC Click Next Assignment, Select User group and click Next Review + create, click Create Launch reset from Windows 365 client Open Windows 365 client Click on the three small dots Select Reset Tick the case Yes, I am sure I want to reset this Cloud PC and click Reset The reset takes about 20 to 30 minutes. As soon as provisioning is complete, the cloud reappears in the Windows 365 client.

Windows 365, disable local drive redirection using Microsoft Intune

Image
In the interests of securing AVD and Windows 365 environments, it may be interesting to ask the question of the redirection of local drive or folder to remote session. Often, Windows 365 users use a personal and potentially insecure computer to access a customer's Windows 365/AVD services. It is therefore essential to guard against the dangers that this type of scenario may entail. To avoid this, it is possible to prohibit the mounting of local drives in a remote session. To do this, I invite you to follow the procedure below. Configuration profile creation Go to intune.microsoft.com Go to  Devices / Windows / Configuration Profiles Click  Create Profile Select :  Platform :  Windows 10 and later Profile Type :  Settings Catalog Complete the Name field  and click  Next Click Add settings Go to Administrative Templates \ Windows Components \ Remote Desktop Services \ Remote Desktop Session Host \ Device and Resource Redirection Select Do not allow drive redirection Close the pane