James Robinson | MVP's Avatar

James Robinson | MVP

@skiptotheendpoint.co.uk

Microsoft MVP - Intune and Windows Cloud-Native Endpoint Advocate Neurodivergent Loudmouth

918
Followers
143
Following
61
Posts
28.11.2023
Joined
Posts Following

Latest posts by James Robinson | MVP @skiptotheendpoint.co.uk

Preview
M365 Companion Apps: A (P)review M365 Companion Apps are coming! What are they, what does this mean as an admin, and what do I think?

There's some companion apps coming to #Windows11 via the M365 Desktop Apps that might catch admins or users off-guard, so I've put some thoughts and information together in a mini-blog.
skiptotheendpoint.co.uk/m365-compani...

14.07.2025 13:08 ๐Ÿ‘ 4 ๐Ÿ” 3 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
a cartoon of a capybara with the words you 've just been capybara 'd below it ALT: a cartoon of a capybara with the words you 've just been capybara 'd below it
13.05.2025 21:30 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Release windows-v3.6 ยท SkipToTheEndpoint/OpenIntuneBaseline Windows v3.6 - 2025-05-13 - Post-MMS Edition Added Settings Catalog Win - OIB - SC - Microsoft Office - D - Device Security - v3.6 Win - OIB - SC - Microsoft Office - U - User Security - v3.6 By po...

๐Ÿ“ฐ #OIB Windows v3.6 - Post-MMS Edition!
- More 24H2 baseline settings
- New LAPS account management
- M365 Apps Baseline!

Check out the release notes below:
github.com/SkipToTheEnd...

13.05.2025 12:27 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I'll find someone here to bring one back for you ๐Ÿ˜‰

04.05.2025 23:44 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

#MMSMOA is almost upon us!
Start your conference right with a dose of the #OpenIntuneBaseline, and asking a good question may reward you with a special shiny SkipToTheEndpoint sticker!

8am, Lakes B!

Sign up here: stte.me/mmsoib

04.05.2025 16:36 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
From Criticism to Confidence: Windows Recall Windows Recall is a powerful tool, but is it secure, should you be concerned, and how do you manage it?!

๐Ÿ“ฌ #Windows Recall had a rocky start, but where do we stand now as it moves into GA? With a complete security overhaul, fresh admin controls, and a default-off strategy, the improvements are promising!

Interested to read a more optimistic view?
stte.me/recallisgreat

28.04.2025 12:06 ๐Ÿ‘ 3 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

They've addressed the enterprise-readiness because yeah, the initial announcement was awful.
While I somewhat agree as I also work across physical and virtual devices, the security necessary for it so heavily ties it to a device.
I've been loving the Snapdragon Surface though!

15.04.2025 10:59 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

After picking up a Surface and having some time to play with #Windows #Recall, I'm working on a blog all about it, but am already fed up with seeing posts about policy not working.

So let me make this as clear as I can:

15.04.2025 10:46 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

It's an absolute pleasure to be invited back to the @mmsmoa.bsky.social to talk all about the #OpenIntuneBaseline!

Interested in how it all started? Not sure how to get the most of it in your environment? I'm stoked to be able to tell you all about it!

sched.co/1uF7c

02.04.2025 10:09 ๐Ÿ‘ 9 ๐Ÿ” 1 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

I am deeply unhappy that these things now qualify as being "dad rock". And that I'm the dad.

17.03.2025 19:08 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Release windows-v3.5 ยท SkipToTheEndpoint/OpenIntuneBaseline Windows v3.5 - 2025-02-20 - 24H2 Baseline Edition (Mostly) Added Settings Catalog Win - OIB - SC - Device Security - D - Windows Package Manager - v3.5 Added configuration that will be being adde...

๐Ÿ“ฐ OIB Windows v3.5 - 24H2 Baseline Edition!
A surprise drop of some settings and an updated 24H2 Intune baseline brings some of those additions (and some extra goodies) to the Windows OIB.

Check out the changelog below!
github.com/SkipToTheEnd...

20.02.2025 11:40 ๐Ÿ‘ 11 ๐Ÿ” 4 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Since about April last year. It's also a bypass to other policies blocking access to the Store (mostly).
Though those policies are largely security by obscurity and not a valid alternative to proper Application Control.

11.02.2025 22:20 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Intune Settings Rundown - 2501 Intune 2501 - Stay informed of the latest Intune settings policy and UI changes!

๐Ÿ“ฌ It's been a quiet couple of months on the #Intune front, so what's better than getting Intune 2501 in February!
New Edge settings, more Apple DDM, and CSP control over the upcoming #Windows #Recall feature.

skiptotheendpoint.co.uk/settings-run...

06.02.2025 11:26 ๐Ÿ‘ 8 ๐Ÿ” 3 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

So you're saying I should have jumped straight to v95? ๐Ÿ˜…

28.01.2025 00:06 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

The multiple entry points to configure things like this and WHfB confuse so many people.
Like Windows LAPS, I think they should only be configurable via Endpoint Security > Encryption.

27.01.2025 11:55 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Release windows-v3.4 ยท SkipToTheEndpoint/OpenIntuneBaseline Windows v3.4 - 2025-01-24 ImportantA UI change in November '24 has made all policy types visible in the Configuration blade. This has caused a lot of confusion when trying to identify policies conf...

๐Ÿšจ #OpenIntuneBaseline Windows v3.4 Released!
New additions and some things to be aware of, such as the fact all policy names have been updated.
Thanks for all the community input. You guys rock.
Check out the release changelog below:

github.com/SkipToTheEnd...

24.01.2025 15:05 ๐Ÿ‘ 27 ๐Ÿ” 8 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 1

Haha. Also not wrong.
That being said, I've seen the mechanism for configuring the start menu break like 5 times in the last few years. There's far better things for admins to be worrying about on a daily basis than chasing a goose with a knife ;)

22.01.2025 23:37 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Haha, tell me about it. That naming scheme alone is a labour of love.
If they're not descriptive and someone who's not sure can't at least take a guess at where a thing might be configured, what's the point?!

22.01.2025 12:50 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐Ÿ“ฐ OIB 3.4 News!
I'm busy finalising changes/updates to v3.4 of the #OpenIntuneBaseline.
Some forewarning of a "breaking change" in that all policies have been renamed to show where they actually exist (ES - Endpoint Security, SC - Settings Catalog).
I still don't like it :(

22.01.2025 11:47 ๐Ÿ‘ 8 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Another day, another "x policy/remote action isn't working on our iOS devices" issue.
Just because you used Corp Identifiers, or switched it from Personal to Corp doesn't mean that device is Supervised.

Stuff won't work as you expect.

Enrol your devices properly, guys!

20.01.2025 14:49 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Is this another hilarious #Windows en-GB install media localisation issue where "checked" has been replaced with "ticked"?
24H2 26100.2605

14.01.2025 12:04 ๐Ÿ‘ 3 ๐Ÿ” 2 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Copy > Paste > Scale

24.12.2024 21:57 ๐Ÿ‘ 3 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Thanks! Glad they were valuable.
Pretty sure I just had to stop and disable AppArmor entirely, though I'm not sure if that's necessarily the best thing to do:
ubuntu.com/server/docs/...

20.12.2024 12:31 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Windows CSP: A Tale of Magic, Betrayal, and Intrigue - Part 2 Part 2 on how Windows handles policy, the 2 major reasons people struggle, as well as a taste of the future.

๐Ÿ“ฌ Following from last week, Part 2 in the story of #Windows CSP and #Intune policy deployment.
ControlPolicyConflict, Policy Scope and MMP-C, oh my!

Happy Holidays!

skiptotheendpoint.co.uk/windows-csp-...

19.12.2024 15:13 ๐Ÿ‘ 12 ๐Ÿ” 4 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Preview
Windows CSP: A Tale of Magic, Betrayal, and Intrigue - Part 1 Creating an Intune policy is easy, but what happens then? How go they get there, and why you should know and care.

๐Ÿ“ฌ Do you administer #Intune or support Intune-managed devices?
Do you know how policy gets delivered to devices, and how the OS handles them?

Check out part 1 of 2 all about the nuance and intricacies of #Windows CSP's!

skiptotheendpoint.co.uk/windows-csp-...

12.12.2024 13:43 ๐Ÿ‘ 18 ๐Ÿ” 2 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

Oh my I think it finally happened! The #Defender security "recommendation" to implement a now-defunct version of LAPS has disappeared!
Can't seem to find any official changelog though.

It's a Festivus miracle! ๐ŸŽ‰

11.12.2024 15:18 ๐Ÿ‘ 4 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Preview
Customization settings Provides steps for configuring customizations for Microsoft Edge management service.

There are also some super cool capabilities in the EMS, like a one-click way to automatically block all other browsers which deploys a pre-built AppLocker config in Intune!
learn.microsoft.com/en-us/deploy...

06.12.2024 13:25 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Post image

๐ŸšจYou can now enable monitoring of channels and updates in the #Edge Management Service!
learn.microsoft.com/en-us/deploy...

You may also notice all #Intune Settings Catalog policies in the "Configuration policies" list.
I'm writing a blog as there's some chance for danger here...

06.12.2024 13:20 ๐Ÿ‘ 5 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image

Is this #Defender #ASR recommendation notification new?!
Incredibly cool that it's analysed the logs, seen no audit or warn events and actively suggesting to deploy it with as associated user impact!

05.12.2024 09:44 ๐Ÿ‘ 11 ๐Ÿ” 1 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
Post image
03.12.2024 17:06 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0