This blog will be about me experimenting with Conditional Access and with experimenting, I mean to change the JSON myself and upload it! Why? Just for fun and to include […]
Birds of Printer Nightmares
When I started this blog, it was all about showing you the options you have when you want to make sure the end user (without admin permissions) can still install […]
How to Force Sync Microsoft Edge Settings Using Custom ADMX in Intune
Managing browser settings across an organization is a critical aspect of IT management, especially when it comes to ensuring consistency, security, and compliance. Microsoft Edge, with its deep integration into […]
Guardians of the Local Admin rights
Granting your users local admin permissions when deploying Windows 10 is really really best practice…I’m joking, no it’s not! I must be saying this a lot lately. You need to […]
The never-ending Command Prompt
This blog will be about some new ADMX-backed policies for MDM to block access to the Command Prompt (DisableCMD). After trying them out, I encountered some weird behavior. 1. Introduction […]
Things to block in Denver When You’re an IT Admin
In this updated guide, we’ll explore effective strategies for blocking access to administrative tools such as Regedit (Block Regedit), the Command Prompt (Block CMD), and PowerShell (Block PowerShell). We’ll break […]
Interview with the ASR rules
Protecting your devices with Microsoft Defender ASR rules is best practice, but ensure you know the caveats. The sun was probably shining when you configured your ASR rules! After deciding […]
Reservoir update logs
Making sure your devices are up to date with the latest Microsoft updates is one of the key pillars of hardening your endpoints. Updating your devices through Intune is a piece of cake. […]
The Windows Defender Firewall rises
This blog is the seventh part of the Endpoint Security Series. In it, I’ll explain how to deploy your Windows Defender firewall baseline policy rules into Intune. 1. Some Background […]
Better Together
“Better Together” is the intended strategy for Microsoft Endpoint Manager Configuration Manager and Microsoft Azure for managing Windows 10 systems.