Posts

Windows Autopilot and Pre-Provisioned deployment

Image
 Windows Autopilot offers several deployment scenarios, including pre-provisioning. This allows to respond to some use cases such as:  Provide a workstation prepared via Windows Autopilot and then send it to low bandwidth sites for example.   But also to provide the end user, a ready-to-use experience by relieving them of sometimes tedious provisioning tasks. In the following, I will detail all the prerequisites as well as the steps to pre-provision a workstation with Microsoft Intune and Windows Autopilot. Prerequisites Device : Microsoft Intune tenant  with MDM authority  "Set to Intune" Windows Autopilot User Driven AAD or HAAD join devices Windows 10 1903 and above  (Enterprise, Pro and Education) Physical devices with TPM 2.0 with device attestation  (check your hardware compatibility) Virtual machines are not supported Network : Wired ethernet connection   TPM attestation validation process  requires access to the URLs below : *.microsoftaik.azure.net Intel:  https://ek

Compliance settings for Ubuntu in Microsoft Intune

Image
The integration of linux in Microsoft Intune offers the possibility of creating and applying compliance rules on this device.  At the moment, the possibilities remain limited but still make it possible to apply security policies to workstations which very often find themselves isolated. Compliance rules possibilities Here is the list of compliance rules currently available : Allowed distributions Custom Compliance Device Encryption Password Policy List of prerequisites Ubuntu 20.04 or 22.04 LTS Download Ubuntu Desktop | Download | Ubuntu Microsoft Edge 102.x or later installed How to install Microsoft Edge on Ubuntu (ccmtune.fr) Microsoft Intune App for Linux How to enroll your Linux device to Microsoft Intune (ccmtune.fr) Create a compliance rule for Ubuntu Go to Endpoint.microsoft.com Click Devices / Linux / Compliance policies Select Create policy and click Create Enter a rule name and click Next Click Add settings Select one or more settings  to be configured In my case, i choice

Microsoft Store app (new) in Microsoft Intune

Image
The Microsoft Store for Business that we know will be retired in the first quarter of 2023 . In the meantime, Microsoft has made new tools available to improve the way we manage our application deployments. There's the Windows Package Manager (Winget). (https://www.ccmtune.fr/2022/12/winget-presentation-and-usage.html) And recently, the new Microsoft Store App has appeared, followed by a new application deployment feature, called Microsoft Store app (New) , in the Microsoft Intune console. How to deploy an application with the new feature Go to Endpoint.microsoft.com Select Windows and click Add Select Microsoft Store app (new) and click Select Click "Search the Microsoft Store app (new)" Search and select an application and click Next Select a device or user group for deployed this application and click Next Review + create , click Create Client side verification Installation of vlc is successful.

Winget - Presentation and usage

Image
Winget is a tool using the command line to install, uninstall or update applications on a computer equipped with Windows 10 or 11. Winget installation Winget Tool is already present in Windows 11 and as well as in recent versions of windows 10. For other versions of Windows 10, the application is available in the Microsoft Store :  Link for download Winget The winget command-line tool is only supported on Windows 10 1709 (build 16299) or later at this time. Supported installer formats Below is the list of installers supported by the Winget tool EXE (with Silent and SilentWithProgress indicators) INNO NULLSOFT MSI and MSIX APPX BURN PORTABLE Using Winget 1. Search an application For search an application, Use the following command line : winget  search   ApplicationName For example, with Adobe Reader application : 2. Application installation Before starting the installation of an application, it is important to know the list of available command options. To do this, simply run the follo

How to implement Applocker with Microsoft Intune

Image
Applocker is tool included in Windows 10 and 11. It permit to set up policies or rules for allow or deny apps from running on your device.  We can create Applocker rules for below file types:  EXE files : .exe and .com Windows Installer files : .msi, mst, and .msp Scripts : .ps1, .bat, .cmd, .vbs, and .js DLLs : .dll and .ocx Packaged apps and packaged app installers : .appx and .msix. Sources :  https://learn.microsoft.com/fr-fr/windows/security/threat-protection/windows-defender-application-control/applocker/understanding-applocker-rule-collections The Applocker solution purpose a multiple possibilities for secure your device. We have possibilities to block or allow apps. By default, it is recommended to allow all applications and add a custom rules for a scpecific application. Prérequisites for used Applocker Device with Windows 10 or 11 for prepare the Applocker rules Application Identity service enabled Enable Applocker For create an Applocker policy, you need to login as an admin

Microsoft Teams, Progressive Web APP on Ubuntu

Image
Recently, Microsoft applications are beginning to appear on Ubuntu and with the arrival of Progressiv Web Apps (PWA), this greatly facilitates their porting. The latest application is Microsoft Teams. https://techcommunity.microsoft.com/t5/microsoft-teams-blog/microsoft-teams-progressive-web-app-now-available-on-linux/ba-p/3669846 In this blog post, we will see how to install Microsoft Teams using the PWA. Prerequisites Below is the list of prerequisites Microsoft Edge or Chrome Install Microsoft Teams PWA On your Ubuntu computer, open Microsoft Edge or Chrome Connect to Teams Web site   https://teams.microsoft.com Enter your credential informations Click on the icon below Select Install Teams is installed on your computer Uninstall Teams PWA Open Microsoft Edge or Chrome Go to Menu / Apps / Manage Apps Click on the three little dots Select Uninstall Teams PWA - Auto-start on device login Recently, you can activate the automatic launch of Microsoft Teams PWA via Microsoft Edge. To

How to install Microsoft Edge on Ubuntu

Image
Microsoft is beginning to port some of its applications to various platforms including Ubuntu. In this blog post, we will see how to install and uninstall Microsoft Edge on an Ubuntu environment. It is good to know that Microsoft Edge is a prerequisite for many tools published by Microsoft on Ubuntu. Install Microsoft Edge for Linux Go to  https://www.microsoft.com/en-us/edge?form=MA13FJ In this page, click on  Linux (.deb) On the downloaded package ,  right click  and choose this option :  Open With Other Application Select  Software Install Click  Install Microsoft Edge is installed Install Microsoft Edge with the Terminal You want to install Microsoft Edge from the command line, follow the procedure below. First, add the repository to your system and import the Microsoft GPG key to authenticate packages curl https://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor > microsoft.gpg sudo install -o root -g root -m 644 microsoft.gpg /etc/apt/trusted.gpg.d/  sudo sh -c '