Martin Himken | MVP's Avatar

Martin Himken | MVP

@intune.best.bsky.social

#MVP #Intune, plus #ITSec #EMS #Azure and #ConfigMgr - Managing your endpoints with Microsoft since 2012. Posts are my own and do not represent my employer. Blog: https://manima.de

146 Followers  |  50 Following  |  64 Posts  |  Joined: 10.11.2024  |  1.5927

Latest posts by intune.best on Bluesky

Although it's possible to migrate a cloud group from on-premises to Entra and sync group members managed in the cloud back to AD, the documentation omits crucial steps. I hope this helps you experiment with this process.

01.08.2025 22:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Firstly, yes, this is reversible.
Secondly, the SID stays the same.
Thirdly, your groups need to be universal in order to sync back from Entra to ADDS. This isn't documented properly.
Fourthly, Cloud Sync is a prerequisite but doesn't explain how to set it up properly.

01.08.2025 22:26 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Embrace cloud-first posture and convert Group Source of Authority (SOA) to the cloud (Preview) - Microsoft Entra ID Learn about Source of Authority (SOA), including prerequisites, supported scenarios, and step-by-step guidance for IT Architects and Administrators.

You can now specify whether an #ADDS group is an #EntraID group or on-premises. This is called a 'change of SOA'. However, be aware that, since @ajf8729.com and I have only just tried this out, the documentation is incomplete for now. Let me explain...🧡
learn.microsoft.com/en-us/entra/...

01.08.2025 22:26 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 1    πŸ“Œ 2
Preview
toolbox/Intune/Platform Scripts/Reset-WindowsUpdateSettings.ps1 at main Β· MHimken/toolbox This is my toolbox. Watch where you step. Contribute to MHimken/toolbox development by creating an account on GitHub.

#WindowsUpdate: Thinking of moving to #Intune and/or #Autopatch? Used GPOs or any RMM tool (yes CM too) to adjust the update settings? This cleanup script is for you. I recently received some requests for this again, so I'll share it once more.
github.com/MHimken/tool...
#MVPBuzz

31.07.2025 12:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Windows 11 cloud-native migration with Microsoft Intune - Windows IT Pro Blog Learn how to migrate domain-joined, co-managed Windows 10 devices to Microsoft Intune managed Windows 11.   

'Windows 11 cloud-native migration with Microsoft Intune'.
There's a great article from @onpremcloudguy.com with lots of useful information in the links. Afterwards, you can read my blog to find out about other relevant technologies πŸ˜‰
techcommunity.microsoft.com/blog/windows...

29.07.2025 09:49 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Unattended access with Remote Help is on its way!
Bear in mind that this is the GA date, so there may be a (private) preview available to join. I still highly recommend checking out the MMCCP to participate in early previews. techcommunity.microsoft.com/blog/windows...
#MVPBuzz

29.07.2025 09:12 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Internet-facing File Servers, with a dash of Entra Authentication! Now that the the β€œAzure AD based Windows Login” extension is available (docs here), a Windows server running in Azure or that is Arc-enabled can now be signed into via Entra ID. When I …

Internet-facing file servers, using SMB over QUIC, and secured using Entra authentication! This turned out to be really easy to get up and running. ajf.one/entrafs #Entra #EntraID

27.07.2025 21:23 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Set up local admin account creation and password management for macOS devices - Microsoft Intune Set up macOS account configuration with LAPS through automatic device enrollment for macOS devices in Intune.

Since I don't do a lot of macOS administration I completely missed this (thanks Andreas!). LAPS for macOS is here :)

learn.microsoft.com/en-us/intune...
#MVPBuzz

25.07.2025 06:50 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
July 22, 2025β€”KB5062660 (OS Build 26100.4770) Preview - Microsoft Support

⚠️⚠️The preview update for #Windows 24H2 allows you to pin apps to the start menu ONCE (aka boolean). No mention of how yet though πŸ™ˆFinally, no more playing around with start2.bin

Also: Quick Machine Recovery and many more things - go read now!

support.microsoft.com/en-us/topic/...
#MVPbuzz

23.07.2025 20:45 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Yes I did. Even after fully removing all Graph modules and only installing the modules required I saw authentication errors. I think I went back as far as 2.20 to make it work. If you’re curious I can look up the module that failed.

22.07.2025 09:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

This post does not have enough attention yet. 2.29.1 seems to finally solve the authentication issues that existed in Microsoft.Graph.Authentication for a good while now. Run your Update-Module now!

22.07.2025 08:00 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Windows Autopilot requirements Software, Networking, Licensing, and Configuration requirements for Windows Autopilot.

In case you're using a Windows 11 IoT version and it isn't a Microsoft Teams Room device, here's a reminder that (since may actually) Autopilot is _not_ supported.
learn.microsoft.com/en-us/autopi...
I can only assume that's because it - by default - skips the OOBE.

21.07.2025 14:56 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Overview of NTLM auditing enhancements in Windows 11, version 24H2 and Windows Server 2025 - Microsoft Support Summary of new auditing features and deployment details

Part 8053 of eleventy billion on our path to killing NTLM: way way way way way better auditing.

support.microsoft.com/en-us/topic/...

13.07.2025 16:35 β€” πŸ‘ 47    πŸ” 13    πŸ’¬ 3    πŸ“Œ 0
Preview
Windows Hello for Business policy settings Learn about the policy settings to configure Configure Windows Hello for Business.

TIL: Using #Windows #24H2 with activated VBS (which is enabled by default on Windows 11) #WHfB PIN expiration and history are _not supported_. Time to change change some policies...
learn.microsoft.com/en-us/window...

08.07.2025 08:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Get ready for Windows 11, version 25H2 - Windows IT Pro Blog Ready for the next feature update? Windows 11, version 25H2 is coming as an enablement package (eKB) later this year!

See? Not called Windows12 Β―\_(ツ)_/Β―
techcommunity.microsoft.com/blog/Windows...

27.06.2025 20:29 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

Oh wow, I just set up another PoC for GSA and checked the recommended ports for domain controllers. That list was extended by a _lot_. This will be hard to argue with some security folks. Mind you the 4 ports before were enough to get a TGT. learn.microsoft.com/en-us/entra/...

27.06.2025 06:28 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image Post image

@jgkps and I will be speaking at not just one, but two sessions at #WPNinjasUK25! I'm looking forward to seeing Scotland and meeting more people to discuss passwordless and cloud-native devices with!

wpninjas.uk

Bring your questions if you've signed up!

31.05.2025 20:02 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

And you’re as correct there as here β€οΈπŸ‘ŒπŸ»

30.05.2025 18:23 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Almost all customers requested this when we did the PoC. β€žWe can’t protect the client otherwise!β€œ. Right, but you should worry about the identity first and you don’t even enforce MFA let alone phishing resistant auth…

30.05.2025 09:40 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
Announcing Windows Backup for Organizations - Windows IT Pro Blog Apply for the limited public preview of Windows Backup for Organizations.

#Windows #Backup for organizations is finally showing up on public radar!
This will allow you to save and restore ... things from W10 to W11 or W11 to W11 (think wipe).
Accessing the MMCCP also just became easier - I recommend joining πŸ˜‰
techcommunity.microsoft.com/blog/Windows...

27.05.2025 21:58 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

Finally getting a chance to use my mug from @intune.best from @mmsmoa.bsky.social.

Sure makes my morning coffee thst much better 😁 Thank you, Martin!

27.05.2025 16:09 β€” πŸ‘ 3    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Migrating BitLocker Recovery Key Management from ConfigMgr to Intune: A Practical Guide | Microsoft Community Hub Hi, I'm Herbert Fuchs, a Cloud Solution Architect. In this blog, I’ll guide you through migrating existing BitLocker recovery keys from Configuration Manager...

Nice Tech Community post on migrating BitLocker from #ConfigMgr to #Intune - techcommunity.microsoft.com/blog/CoreInf...

19.05.2025 01:50 β€” πŸ‘ 4    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Dealing With CVE-2023-24932, aka Remediating BlackLotus CVE-2023-24932. 2023 feels like so long ago, and yet, this is still an issue. Why? Because it’s quite frankly a mess to deal with and has multiple moving parts. I highly recommend reading tho…

My take on remediating #BlackLotus via #Intune Remediations & #ConfigMgr CIs. It sure was fun to code up and test as much as I was able to. Please let me know if you have any feedback or run into any issues if you try the scripts out!

ajf.one/blacklotus

19.05.2025 13:54 β€” πŸ‘ 4    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0
Preview
Moving Teams Android Devices to AOSP Device Management | Microsoft Community Hub Take action now if you Administer Android Based Teams Devices in your Organization

Reminder that starting TOMORROW (15th of May) your current Microsoft Teams Android devices will start moving to Intune Android Open Source Project device management. Here's a list of dates and devices that will be impacted.
techcommunity.microsoft.com/blog/microso...

14.05.2025 13:10 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
OneDrive und persΓΆnliche Microsoft Accounts – mAnimA.de OneDrive darf im GeschΓ€ftsumfeld standardmÀßig persΓΆnliche Accounts verwenden. Jetzt werden Benutzer auch dazu aufgefordert. Ein Risiko?

Ausnahmsweise gibt es heute einen Beitrag auf Deutsch: OneDrive und MSA (also persΓΆnliche Accounts) sind momentan hier und auf anderen Plattformen in aller Munde. Zu Unrecht. Viele machen aus zwei bereits lange bekannten Einstellungen einen Elefanten.
manima.de/2025/05/oned...

11.05.2025 21:05 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Post image

#MMS MOA HAS STARTED! Looking forward to meeting a lot of people! Here is a couple of em:
@jgkps.bsky.social @conditionalaccess.uk @skotheimsvik.no

05.05.2025 00:32 β€” πŸ‘ 11    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Time to leave for #MMS into Iceland to pick up the great @jgkps.bsky.social! If you’re there I’ll see you soon! For everyone else: I’ll be out of commission for a week πŸ‘Œ

03.05.2025 11:22 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Upcoming network requirement changes - yes, including Intune – mAnimA.de Intune network requirements are changing, if you're controlling outgoing traffic flow, you might want to read this!

#Intune #Azure #DevOps
In case you hadn't noticed: There are still ongoing changes to all azureedge.net endpoints. If you filter outgoing traffic, please make sure you adjust your network accordingly.
manima.de/2025/04/upco...

30.04.2025 20:23 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

#CIS Benchmark v4 for #Intune and #Windows11 has been published as of two days ago! I recommend you check out the changes as soon as you get access to it. This has been in the work for months! #cybersecurity

28.04.2025 13:08 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

And that’s a wrap! #MEMsummit 2025 was great! Thanks for everyone attending my sessions, I hope they brought value to your life 😊

Let’s hope we’ll meet again next year. Wish me luck on getting home because my train has been cancelled.
#DeutscheBahn didn’t deliver!

25.04.2025 15:07 β€” πŸ‘ 6    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@intune.best is following 20 prominent accounts