Saturday, July 6, 2024

Intune & macOS management - Couldn't add your device. Your IT support doesn't allow OSX devices to be added to management

After creating Apple MDM push certificate in Intune portal and while testing in the macOS device, after you install the company portal and login and try to enrol, the app shows error as 

"Couldn't add your device.

Your IT support doesn't allow OSX devices to be added to management." 


First step is to check in Intune portal - devices - enrollment - monitor - enrollment failure for any entry for the affected user.


In this scenario, the issue was due to the device type restrictions that was blocking the macOS devices.

Solution:

Open intune portal -  Devices - Enrollment - click Apple.

Select device platform restrictions and switch to MacOS restrictions tab.

Your administrator would have created a device restriction to block the enrollment of MacOS earlier. If there are multiple restrictions created for devices open one by one and make sure the macOS platform is allowed for enrollment. 

When you edit the restrictions and go to the properties and under platform settings, you can find out whether the macOS devices are allowed to enroll or if they are blocked.

Wednesday, July 3, 2024

W365: Last connected state shows incorrect date

In the windows app, if you try to access a cloud pc, the last connected info displays wrong information. Below screen shows last connected as 1 day ago. whereas, in fact the cloud pc was accessed and closed few minutes before to accessing as a new session.


Also in the browser session, the information is displayed 19hrs ago. This in-fact should show as few minutes before as even in the browser, the cloud pc was accessed and closed some minutes ago.

I believe it's taking quite sometime to get updated in the backend which shouldn't be the case and should get updated quicky to avoid confusion.

This seems to be a bug  in windows app which I have raised as a feedback. Kindly upvote to get Microsoft visibility on this.

https://feedbackportal.microsoft.com/feedback/idea/5ff778b4-1f3d-ef11-a296-000d3a044d12

Note: The browser session seems to fetch the last connected state some what quicker than the windows app once the cloud pc is disconnected. The windows app still displays wrong info.

Update (10/07/2024):

Had raised a support ticket and we had this tested out.It seems the windows app displays the last connected time in UST but the browser displays in local time. I have cross checked and it’s correct that the Windows app display last connected in UST time.

Have asked Microsoft support that this needs to be shared in Microsoft article that the windows app will display last connected state in UST format or else add the UST at end of the time stamp in windows app, so that user will be aware of this. 

This will avoid confusion and the user will understand if UST is added at end of time in the last connected in windows app.

Sunday, June 30, 2024

w365: Enabling Screen Capture Protection for Windows 365 in Intune

As the hybrid work environment becomes the new normal, securing virtual desktops is more critical than ever. Windows 365, Microsoft's cloud PC solution, includes a valuable feature: Screen Capture Protection. This feature prevents unauthorized screen captures of sensitive information displayed on a Windows 365 Cloud PC. Managing this through Microsoft Intune ensures a seamless and centralized approach. In this blog, we will provide a straightforward guide on enabling Screen Capture Protection in Intune that disables screen capture using screen capture tools prntscn/SnippingTool. 

Simple Steps to Enable Screen Capture Protection in Intune

1. Log into Microsoft Intune:
   
2. Navigate to Configuration Profiles:
   Go to Devices > Configuration profiles

3. Create a New Profile:
   Click on Create profile, Choose Windows 10 and later as the platform. Select Templates for the profile type, then choose Administrative Templates.

4. Configure Screen Capture Settings:
   - In the settings picker, browse to Administrative templates > Windows Components > RemoteDesktop Services > Remote Desktop Session Host > Azure Virtual Desktop.
   - Find and select Enable screen capture protection.
   - Set this policy to Enabled.
Turn off the another setting as it stops tools and services on the session host from capturing the screen, as well as screen capture from the client of programs running in the remote session.




5. Assign the Profile:
   - Assign this profile to the group of users or devices that will use Windows 365 Cloud PCs.
   
6. Review and Create:
   - Review the settings and click Create. 
   - The profile will be pushed to the assigned devices and users, enabling screen capture protection.

7. Restart the cloud pc for setting to take effect.

Before:


After:



Demo:


Important Considerations When Using Screen Capture Protection

Web Browser Access and Screen Sharing

When screen capture protection is enabled, any connection through the web browser or remote desktop app in Android or iOS will fail, presenting an error message like below.  Additionally, if you join Teams meetings through your Cloud PC, you will no longer be able to share your screen.



Though the second screen shows "you need to enable screen capture protection", it should actually say to disable the screen protection to access cloud pc in the browser session. 

Update (28/08/2024): Microsoft has fixed the error message with screen capture protection enabled and accessed through  browsers.




when accessing through Remote desktop client in iOS, below error is shown.

Saturday, June 29, 2024

w365:Exploring the Windows 365 Switch: Adding Cloud PC to Task View

 As technology advances, the line between local computing and cloud computing continues to blur. Microsoft’s Windows 365, a revolutionary cloud PC service, has introduced an exciting new feature called Windows 365 Switch. This feature seamlessly integrates your cloud PC into the Windows 11 Task View, making the transition between your local desktop and cloud PC effortless. In this blog, we’ll delve into what the Windows 365 Switch is, its benefits, and how to make the most of this powerful feature.

What is Windows 365 Switch?

Windows 365 Switch is a feature within Windows 365 that allows users to add their cloud PC to the Task View of their local Windows 11 machine. Task View, a familiar tool for Windows users, lets you quickly switch between open applications and virtual desktops. With the addition of Windows 365 Switch, you can now easily toggle between your local desktop environment and your cloud PC, providing a seamless hybrid computing experience.


Key Benefits of Windows 365 Switch

1. Seamless Transition

The primary benefit of Windows 365 Switch is the seamless transition it provides between your local desktop and your cloud PC. Whether you're working on a document locally or need to access specialized software on your cloud PC, switching between the two environments is as simple as clicking a button in Task View.

2. Enhanced Productivity

By integrating your cloud PC into Task View, Windows 365 Switch enhances your productivity. You no longer need to log in and out of different systems or manage multiple sets of files manually. Everything you need is just a click away, allowing you to maintain your workflow without interruptions.

3. Consistent User Experience

Windows 365 Switch ensures a consistent user experience across both your local and cloud environments. Your settings, applications, and files are always synchronized, providing a unified workspace that adapts to your needs, whether you're working locally or in the cloud.

 4. Flexibility and Mobility

In today’s hybrid work environment, flexibility is crucial. Windows 365 Switch allows you to access your cloud PC from any Windows 11 device, providing the mobility to work from anywhere. This flexibility is especially beneficial for remote workers, freelancers, and teams spread across different locations.

5. Simplified Management

For IT administrators, managing a hybrid workforce becomes simpler with Windows 365 Switch. Centralized management tools ensure that both local desktops and cloud PCs are secure, updated, and compliant with organizational policies. This unified management approach reduces complexity and enhances overall security.

How to Use Windows 365 Switch

Using Windows 365 Switch is straightforward. Here’s a step-by-step guide to get you started:

Step 1: Set Up Windows 365

Ensure you have a Windows 365 subscription and your cloud PC is set up. Follow the setup instructions provided by Microsoft to get your cloud PC running.

Step 2: Access Task View

On your local Windows 11 machine, access Task View by clicking the Task View icon on the taskbar or by pressing `Windows + Tab` on your keyboard.

Step 3: Add Cloud PC to Task View

Open the Windows app, choose one Cloud PC, select the ellipses, and then select Add to Task view.


 You can add one or more cloud pc to your Task view, however the first Cloud PC will only be visible in the task view. The others will be arranged in stack and if the first one is removed, the next one will be visible.

https://learn.microsoft.com/en-us/windows-365/enterprise/windows-365-switch-known-issues#support-for-only-one-cloud-pc

Step 4: Switch Between Environments

Click on your cloud PC in Task View to switch to it. You can now work on your cloud PC as if it were a local desktop. To return to your local environment, simply use Task View again and select your local desktop.

Keyboard Navigation:

To use keyboard shortcuts to switch between local pc and cloud pc in task view use the below combination keys.

WIN + Ctrl + left or right arrows

Step 5: Disconnect from cloud pc

To disconnect from a Cloud PC, select the Task view in the taskbar, right-click on the Cloud PC, and then select Disconnect.

Caveats:

you can add more than one Cloud PC to the task view using the Windows app but only one the first one added is ever shown and not the second or third ones.

The Cloud PCs are added in a stack fashion, so if you remove the first CPC you added, the second one will take its place.

What if you have deprovisoned the cloud pc and not able to remove from task view? 

Try checking this registry key:

Remove the Reg keys under the below branch and restart explorer.exe or reboot and it should be gone.

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RemoteSystemProviders\

If it doesn’t work, check the windows 365 switch known issues article and follow the same.