Open in app

Sign In

Write

Sign In

Niklas Tinner
Niklas Tinner

13 Followers

Home

About

Sep 12

Bulk Autopilot device renaming

This post is just a little documentation on Autopilot device renaming with PowerShell. Autopilot attributes Find more information on Autopilot identities and assignments (oceanleaf.ch) For this action, only the serial number and device name is relevant. The hardware vendor may not be able to add the hostname, but can provide a csv…

Intune

2 min read

Bulk Autopilot device renaming
Bulk Autopilot device renaming
Intune

2 min read


Aug 22

Microsoft Entra Private Access — secure any app with Conditional Access

This short post will explain the new capabilities of Microsoft Entra Private Access to: Enable access to internal apps and protocols when connected with the Global Secure Access client Secure access with Conditional Access Enable MFA for protocols which never was possible before! In the next steps I am going to briefly show you how to setup Private Access…

Entra Id

4 min read

Microsoft Entra Private Access — secure any app with Conditional Access
Microsoft Entra Private Access — secure any app with Conditional Access
Entra Id

4 min read


Jun 9

Windows LAPS post-authentication bug

During my research and testing with the new Windows LAPS I have discovered a strange behavior for the post-authentication action. Continue reading if you are interested in the blog and how I was in contact with Microsoft resolving it. View my full blog post: Windows LAPS: the comprehensive guide (oceanleaf.ch) Post-authentication action …

Windows

2 min read

Windows LAPS post-authentication bug
Windows LAPS post-authentication bug
Windows

2 min read


May 7

Create Entra Azure AD custom roles with PowerShell

Are you looking for a way to create Entra Azure AD custom roles with PowerShell? Read on to learn how. How it works For it to work we are going to leverage Microsoft Graph + PowerShell + Invoke-Webrequest. First we manually need to create a custom role, go to Azure AD>Roles and administrators>New…

Azure Ad

2 min read

Create Entra Azure AD custom roles with PowerShell
Create Entra Azure AD custom roles with PowerShell
Azure Ad

2 min read


Apr 28

Windows LAPS Azure AD Custom Role and Administrative Units

If you are looking for a way to granularly control access to LAPS local admin passwords, you should consider Azure Administrative Units. How it works You can collect users, groups and devices into a virtual container, called Administrative Unit (AU). Membership election can be assigned, but also Dynamic User/Device. Here you can add Roles and administrators. All these assignments are only effective for the users, groups and devices in the Administrative Unit.

Windows Laps

2 min read

Windows LAPS Azure AD Custom Role and Administrative Units
Windows LAPS Azure AD Custom Role and Administrative Units
Windows Laps

2 min read


Apr 5

Sleep & lock device on lid close — Intune configuration profile power management

Windows offers some energy and power management settings. Of course we can configure them through Intune. But first on the Windows side we have the following options: Energy plan Actions

Microsoft Intune

2 min read

Sleep & lock device on lid close — Intune configuration profile power management
Sleep & lock device on lid close — Intune configuration profile power management
Microsoft Intune

2 min read


Mar 24

Conditional Access block specific device

Some time ago there was a use case to block some selected devices that are Azure AD joined from company resource access. Of course we think of a Conditional Access control policy. But what if you cant identify the(se) device(s) through any condition? …

Azure Ad

2 min read

Conditional Access block specific device
Conditional Access block specific device
Azure Ad

2 min read


Mar 8

The way around device and user assignments (mixing)

I am sure we are all aware that for Intune assignments we can’t use user and device groups for the include or exclude intent of the same profile, at the same time. This “mix” is an unsupported scenario and leads to unexpected behaviors, errors, generally a conflict. …

Microsoft Intune

3 min read

The way around device and user assignments (mixing)
The way around device and user assignments (mixing)
Microsoft Intune

3 min read


Mar 2

Remote actions for an end user with Intune

There are several remote actions for an end user that affect his devices and involve Intune or Azure AD. This short post will give an overview about the capabilities. Mainly there are the following portals: My Account — Devices Here are all devices listed where the user signed-in, which resulted in an Azure AD…

Microsoft Intune

2 min read

Remote actions for an end user with Intune
Remote actions for an end user with Intune
Microsoft Intune

2 min read


Feb 23

Deny Local Log On for Azure AD accounts

Windows can be setup in shared PC or Kiosk mode. I have already written a blogpost about this. The aim is to provide a Windows experience for multiple users on one device, where the user may not even has his own (AAD) account. Now on these devices you may want…

Microsoft Intune

2 min read

Deny Local Log On for Azure AD accounts
Deny Local Log On for Azure AD accounts
Microsoft Intune

2 min read

Niklas Tinner

Niklas Tinner

13 Followers

https://oceanleaf.ch/ | #EnterpriseMobility #Security #MEM #ModernWorkplace

Following
  • Nicola

    Nicola

  • John Gruber

    John Gruber

  • Scott Duffey

    Scott Duffey

  • Loris Ambrozzo

    Loris Ambrozzo

  • Jannik Reinhard

    Jannik Reinhard

See all (6)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams