- 334
- 271 731
Get Rubix
United States
เข้าร่วมเมื่อ 20 ก.ค. 2020
Steve Weiner is a Microsoft MVP who discusses best practices with Microsoft Enterprise Mobility and Security. The mission is to help reduce the gaps in skills for IT Admins when implementing and learning about Intune, Autopilot and advanced security features for managing devices in your organization
Getting Started with Graph Part 6: Querying Attributes Across Objects
I get it- most magic shows aren't real. But some must be, right?
Speaking of what's real, today I'll show you how to use attributes from an Intune device, the user object, and the Entra object to string together your own custom properties.
Become a GetRubix TH-cam member for additional videos and exclusive content:
th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmljoin
Join the official Discord server
discord.gg/getrubix
Read more at
www.getrubix.com
Chapters
00:00:00 Magic shows probably aren't real
00:01:01 New wallpaper - who this?
00:01:35 Our flow
00:02:42 Get the managed device object
00:04:49 Get the user object
00:05:37 Get the usage location
00:06:46 Get the Entra device object
00:09:30 Patch the usage location
00:13:10 You're getting good
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm
Speaking of what's real, today I'll show you how to use attributes from an Intune device, the user object, and the Entra object to string together your own custom properties.
Become a GetRubix TH-cam member for additional videos and exclusive content:
th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmljoin
Join the official Discord server
discord.gg/getrubix
Read more at
www.getrubix.com
Chapters
00:00:00 Magic shows probably aren't real
00:01:01 New wallpaper - who this?
00:01:35 Our flow
00:02:42 Get the managed device object
00:04:49 Get the user object
00:05:37 Get the usage location
00:06:46 Get the Entra device object
00:09:30 Patch the usage location
00:13:10 You're getting good
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm
มุมมอง: 90
วีดีโอ
Intune Filters: Switch from Dynamic Group Assignment
มุมมอง 5189 ชั่วโมงที่ผ่านมา
I'm so frustrated with the Cheesecake Factory I can't even talk about it. So instead, let's talk about transitioning from dynamic group assignment for Intune apps and policies to device filters. Group Tag blog: www.getrubix.com/blog/autopilot-group-tags-1?rq=group tag Become a GetRubix TH-cam member for additional videos and exclusive content: th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmljoin...
Getting Started with Graph Part 5: Creating with the POST Method
มุมมอง 26619 ชั่วโมงที่ผ่านมา
What's with Starbucks cranking out orders for invisible customers? Anyway, today we'll talk about creating things with the Graph, like dynamic device groups using POST requests in our PowerShell. Become a GetRubix TH-cam member for additional videos and exclusive content: th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmljoin Join the official Discord server discord.gg/getrubix Read more at www.ge...
Getting Started with Graph Part 4: Automate Everyday Admin Tasks
มุมมอง 81521 ชั่วโมงที่ผ่านมา
Don't you hate it when your spouse finds your secret toy room/recording studio? One thing you don't have to hate anymore is the long list of every day tasks you need to do as an Intune admin. Today, we'll talk about automating those with PowerShell and the Graph modules. Become a GetRubix TH-cam member for additional videos and exclusive content: th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmlj...
Intune Enhanced Hardware Inventory: Reporting and Device Activity
มุมมอง 699วันที่ผ่านมา
Have you every had to be seated at a diner, only to have the waiter to real-time, hardcore repair work on your table? It's unbelievable. Speaking of unbelievable, it seems our devices finally started reporting back some hardware info to Intune. Today we'll conclude our Enhanced Hardware Inventory walkthrough by looking at the reporting and what the local device is doing. Check out this incredib...
How to Configure Enhanced Hardware Inventory with Intune
มุมมอง 1.2Kวันที่ผ่านมา
UPDATE: Part 2 now available - th-cam.com/video/KB0sIxOC78s/w-d-xo.html I promise, we will get back to our Microsoft Graph series. But I thought it was critical to give you my first look at the newly added Enhanced Hardware Inventory capabilities for getting detailed device information through Intune. Become a GetRubix TH-cam member for additional videos and exclusive content: th-cam.com/channe...
Microsoft Graph series
มุมมอง 313วันที่ผ่านมา
Haven't seen the latest series about Microsoft Graph? You're missing out! th-cam.com/play/PLKROqDcmQsFls8cPHk3HFz2mUURHx46_O.html&si=ytBpSp2SIwmsN40c Join the official Discord server discord.gg/getrubix Read more at www.getrubix.com #intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotr...
Getting Started with Graph Part 3: Learn to use PowerShell with Graph
มุมมอง 623วันที่ผ่านมา
I know a lot of folks are asking me about GetRubix merch, but I have a better idea- the GetRubix game show! Speaking of that, today we start learning about using the Microsoft Graph PowerShell module Become a GetRubix TH-cam member for additional videos and exclusive content: th-cam.com/channels/F6q8UjlE5AFO52ht-G_L6A.htmljoin Join the official Discord server discord.gg/getrubix Read more at ww...
Getting Started with Graph Part 2: What can we do with it?
มุมมอง 61314 วันที่ผ่านมา
Getting Started with Graph Part 2: What can we do with it?
Getting Started with Graph Part 1: What is the Microsoft Graph API?
มุมมอง 1.4K14 วันที่ผ่านมา
Getting Started with Graph Part 1: What is the Microsoft Graph API?
Intune at Ignite: Thanksgiving Special
มุมมอง 35714 วันที่ผ่านมา
Intune at Ignite: Thanksgiving Special
From Zero Touch to Zero Trust: Live (ish) from Ignite
มุมมอง 81021 วันที่ผ่านมา
From Zero Touch to Zero Trust: Live (ish) from Ignite
Intune at Ignite: a Thanksgiving Special
มุมมอง 30621 วันที่ผ่านมา
Intune at Ignite: a Thanksgiving Special
How to Manage Edge Browser Policies from the Microsoft Admin Center
มุมมอง 1.1K21 วันที่ผ่านมา
How to Manage Edge Browser Policies from the Microsoft Admin Center
The GetRubix PODCAST - Episode 22: Get Ready for Microsoft Ignite
มุมมอง 339หลายเดือนก่อน
The GetRubix PODCAST - Episode 22: Get Ready for Microsoft Ignite
How to Deploy a Scheduled Task with Intune
มุมมอง 917หลายเดือนก่อน
How to Deploy a Scheduled Task with Intune
How to Register a Virtual Machine in Autopilot
มุมมอง 850หลายเดือนก่อน
How to Register a Virtual Machine in Autopilot
How to Document Your Conditional Access Policies
มุมมอง 2Kหลายเดือนก่อน
How to Document Your Conditional Access Policies
How to Configure the new LAPS policies for Windows 24H2 with Intune
มุมมอง 1.5Kหลายเดือนก่อน
How to Configure the new LAPS policies for Windows 24H2 with Intune
Autopilot Device Preparation: Reflection with Dean and Steve
มุมมอง 698หลายเดือนก่อน
Autopilot Device Preparation: Reflection with Dean and Steve
How to Setup Windows Autopatch for Intune
มุมมอง 2Kหลายเดือนก่อน
How to Setup Windows Autopatch for Intune
How to setup Microsoft Connected Cache for Enterprise
มุมมอง 1.7Kหลายเดือนก่อน
How to setup Microsoft Connected Cache for Enterprise
ZeroTouch.ai Automation: The Security and Simplicity of Intune App Management
มุมมอง 637หลายเดือนก่อน
ZeroTouch.ai Automation: The Security and Simplicity of Intune App Management
How to customize the taskbar in Windows 11
มุมมอง 1.4K2 หลายเดือนก่อน
How to customize the taskbar in Windows 11
How to deploy and install fonts with Intune
มุมมอง 7892 หลายเดือนก่อน
How to deploy and install fonts with Intune
Onboard users with Temporary Access Pass (TAP) and Autopilot
มุมมอง 1.2K2 หลายเดือนก่อน
Onboard users with Temporary Access Pass (TAP) and Autopilot
Could you please tell me where I can find the application "Tenant to Tenant Migration"?
@getrubix Thank you Steven, I have a question is this solution is going to work with a full Intune Migration from Tenant to Tenant "Application, Setting, Security profile, etc." or just for devices? Thanks Again
Just the device... this is an old video. Here is the latest version of the tool with documentation: stevecapacity.github.io/intune-device-migration-documentation/
Hey - Given that you have covered Device Inventory and you also cover MS Graph subjects, do you know if the Device Inventory data is accessible from Graph - and of so - do you know the resource name / location? Thanks
Right now, the data is not accessible... we'll have to wait and see if Microsoft changes it any time soon :)
I use Intune filters frequently because they are faster. However, you can only apply one filter for inclusion or exclusion per assignment. This limitation can be a downside, especially when managing a mix of devices, such as physical devices, W365, and AVD session hosts..
Correct- you would need to create one filter that includes multiple parameters to achieve this. Not ideal at the moment for some scenarios...
Could you use this to keep systems on a domain trust you think?
That's not really the intent...
@getrubix understood, just looking at this at hybrid use case if need be.
It's a backtick or grave 🙂 If you put the line in single quotes, doesn't that mean literal $ and if you use double then it expands?
The usability of this feature would be massive if MS did two things: 1. Increase the amount of filterable attributes 2. Have filter assignments available to all types of deployments.
I had the misconcception that ztid query was required. great to know filters can be used with an ‘All Devices” assignment did you disable Whfb for both users and devices?
In this example policy it was devices. Maybe I should have picked a different example as there is a LOT more to WHfB 😊
You can only use 1 filter per assignment and using Enrollment profile name is significantly flawed when you either need to rename it or you want to reassign a device but dont want to affect an existing device. be careful out there.
Filters are very handy and I do use, them, however I would use them more if they were available everywhere in Intune! There are areas where its not available such as platform scripts.
Agreed, I think they need to expand their use.
Hi! Thank you for great content, as usual :) learned some nice things thanks to you! At this point, I use group tags in every Windows deployment even if there is only one autopilot deployment profile. It keeps the flexibility to create a whole new setup next to the existing one. The reason why I don't use (and don't like) "All devices" is the lack of flexibility. Yes there is the possibility to use a filter but you can only apply 1 filter to "All devices" so if you want to assign a policy to multiple devices, you need to create a specific filter that scopes the group of device you want to target or you need to create the policy multiple times. Using the dynamic group based on group tags solves this very easy. I only use the "All devices" with a filter for macOS deployments because Microsoft recommends it, this only for the configuration. They see the device faster than a dynamic group which is needed for the enrolment with the "Apple autopilot" part.
I definitely agree. I’m a firm believer in group tags (hence the “novel” I wrote on them). But, MS is definitely pushing the filter thing. I figure somewhere in between is the compromise 😊
Quick and eazy explenation! Love that!💪🏻
I try 😊
so does Steve have an OnlyFans.....
shhhhh.....
Hello Steve, first, thanks for the great content. Second, I want to mention "Import-Module Microsoft.Graph" may end up with an error "cannot be created because function capacity 4096 has been exceeded for this scope." So you may need to change the values of 2 variables, "$MaximumVariableCount" and "$MaximumFunctionCount," from 4096 to 10000. This is what I faced in the past.
Thank you for the fruitful clip. May I know how I can allow data transfer from outlook to whatsApp?while restricting other apps I'm trying to allow whatsap to share data from corporate apps While blocking other apps. It will be much more appreciated if you can help
What's app would need to be supported by the MS app protection SDK
Cheesecake Factory is overrated. Not worth waiting even 30 minutes.
Absolutely! It’s like a fake restaurant someone built for a movie set
Interesting, thanks again! What would be the steps to automate the notification by mail? Lets say we want our helpdesk to be notified about noncompliant devices every week or month.
You would have to run that sequence on a schedule. I'll be covering it in an upcoming video :)
@getrubix Appreciate that! Have a nice weekend!
Cool stuff. I have already tested changing the created group using the PATCH method, which actually worked. I'm excited to see what else you will surprise us with. 😊
Cool 😂
Well that was unexpected! Hi Steve’s wife!
I noticed you didnt do anything under "network access properties" do you not need to config anything in there? On the enterprise app that was made i mean
Not for the setup I showed, but this was an early look. I need to revisit again
I'm following your guidance, one question is do we need to think about costs of this? Harvesting all this data, is it going to rack up a large bill? hopefully you got a discount in the restaurant...
This is part of the core Intune license. There is no additional cost
Goood content brow
It's 2024, why is a new properties display set to show memory in bytes lol geez.
Thank you! I did number of videos but this made it so clear.
I'm glad it helped!
What if most of your devices are turned off at night?
Pretty sure it will pick up when turned back on
Heh, it's working for me too. I'm looking at Windows QFE, which seems to be patches. When I sort by 'Installed date' it does it in alphabetical order. Not date order. (I'm using dd/mm/yyyy) so it goes 20/11/2024, 20/09/2024, 19/11/2024... So that's embarrassing. I confess, I'm not feeling the love. The battery info is kinda useful if a user brings it up, but machine by machine it's all a bit 'meh'
Have to agree with you. Having tenant wide and group capabilities will be way more useful
Thanks for the update!
Hi Steve, Thanks for part 2, i have a few questions if you dont mind 😊 1. your ”issue” yesterday, was it a ”time-question” or did you have to debugg and actually resolve something in order to get the report back to intune? 2. How often are the agent sending the inventory to intune? Is it every time the PC cheks in with intune or do we have a static time-period? 3. What is the Max numper of PC that i Can run this policy on today? (Sorry for my bad english, you know i love your videos❤️❤️, greatings from Sweden 🇸🇪 )
No problem at all. 1. It was a Microsoft issue. Just had to wait :) 2. The refresh period is 24 hours 3. I'm not aware of a maximum limit regarding the policy. Hope that helps!
@@getrubixThank you so much for your time, i have 280 pc’s that i am going to test this on, i let you know if something funny happens 😂😂
Been eagerly awaiting this feature in our tenant!
When available in out tenant, will definitely check out.
If you change the local clock time to right before that date. Does it kick the processing? lol... The issue I have with that, is why is it a property catalog? All of that data should just in the computer object record regardless.
It has so little value if you can’t query it or process it. How is it not in graph? It’s a strange product for sure.
Just deployed this on a test machine group ... Once again, gotta wait until it's uploaded!
Great content, as always! Just a quick off-topic question: I have a SafePal wallet with USDT, and I have the seed phrase. (alarm fetch churn bridge exercise tape speak race clerk couch crater letter). Could you explain how to move them to Binance?
Still to available in 😢 france 🇫🇷
Really good sir! Love it when you go ”under the hood” like showing us where the files are and what they do etc…💪🏻
Hello- I know is this old, do the update groups needs to be excluded from the update rings in order to see the update?
I believe so. I'll have to rewatch 😁
Great vid! Can't wait for part 2. Still using PDQ for hardware inventory but this is surely a nice feature to have.
Interesting. Additional licensing needed?
Nope :)
@@getrubix Sweet. Thanks
Excellent presentation - thanks for sharing!
Hey Steve, are you planning to cover scenarios where we can't use the graph cmdlets? There may be scenarios where the enterprise app mggraph is disabled and admins must use the graph calls directly from powershell
100% :) That is coming up this week.