Windows Intune and ADFS Location

Hi,
I am in the middle of setting up SCCM and Intune together, and was wondering where on the network the ADFS should be sited, inside the network or outside or on a DMZ?

ADFS does not in any way provide any syncing. ADFS is an authentication trust mechanism. In the context of Windows Azure AD, which is used by Intune and O365 among other things, all authentication needed by these services is automatically redirected
back to your on-prem ADFS which in turn enables your users to authenticate against your AD. ADFS then passes a token back to WAAD saying that you should be trusted because WAAD trusts your ADFS.
To synchronize your on-prem AD to WAAD, which is required for Intune in the hybrid (aka ConfigMgr integrated) scenario, you need to set up DirSync. DirSync can also synchronize user passwords (actually hashes of user passwords -- once the password is set
there's no way to actually get it back) to WAAD thus more or less enabling single-sign on.
As Nikos pointed out, synching the password hashed up to WAAD -- for many different reasons -- doesn't sit well with some/many and so that's where ADFS comes in as it enables, as mentioned, WAAD to redirect the auth request to your directory services instead.
Jason | http://blog.configmgrftw.com

Similar Messages

  • Windows Intune and Service now Integration

    Please help me  to get the feasibility of Windows Intune Integration with Service now Application Please share me the procedure or Documents

    Hi,
    I would like to confirm that do you mean that you want to integrate Windows Intune with Service Now, if this is the case, then I would like to suggest you post in the Window Intune and Service Now forum.
    Regards,
    Yan Li
    Regards, Yan Li

  • Trying to uninstall CS5.5 Master Collection, but programs don't appear in standard Windows Programs and Features location

    I'm uninstalling CS5.5 after deactivation in order to gain space for CC, but am having problems doing so.  I'm on 64-bit Windows 7 and installed from the Master Collection disks on both my desktop and laptop - neither one has any of the Master Collection programs showing up in the standard uninstall location, which is the only recommended Adobe uninstall method.
    If I run the original install disk, it recognises the existing CS5.5 programs, but only gives the option of installing further program options rather than uninstalling existing ones - is there any way to use the disks to uninstall programs?

    Fixed it - used the disk to reinstall one of the existing CS5.5 apps, and then the Adobe Master Collection showed up as an item in the Programs and Features location, which I could select and uninstall all apps.

  • Specifiy external window size and screen location?

    Hello, I have this ActionScript:
    function openNewCart(evt:Event):void {
    navigateToURL(new URLRequest("http://www.3dcart.com"),"_blank");
    OpenCartPage.addEventListener("click",openNewCart);
    Is there a way that I can have it open a 5 pixel window that automatically closes after it loads? Also, is there a way to specify within the actionscript where on the screen I want the new window to open?
    I'm newer to flash. What I'd like to do is have it add a product to the shopping cart and close back down. If I can't do it straight from flash, I'm sure I can have the flash page open up an html page which redirects to the add to cart page and automatically closes, but obviously a much bigger pain in the butt, and it will only work anyway if I can specify in the actionscript for it to open a 5 x 5 pixel window.
    Thanks, Dan

    you can use javascript to control the popup window.
    that can be done in you new urlrequest() function but, the best way is to add javascript functions to your embedding html and use the externalinterface class to call the js functions.

  • Windows Intune - customise look and feel

    Hi all,
    I have a question regarding Windows Intune.
    To provide some background, I have a customer evaluating Windows Intune and one of the questions were.
    Windows Intune will be integrated with SCCM 2012 R2.
    Can you lockdown the home screen, set wallpapers and other display settings to display the corporate colours and layout? this requirement is cross all devices IPhone, Ipad, Android and Windows Phone.
    thanks in advance
    cheers

    There are only a couple of customisations you can make eg. company name, portal colour.
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Window Intune Center greyed out

    Hello We are currently trialling Windows Intune and Kaspersky (as Windows Intune does not work on servers) and I have 2 issues.
    1. When right clicking on the Intune agent icon in in taskbar the Windows Intune Center option is greyed out this means users will have to go to Start - All Programs - Windows Intune Center to be able to install applications, request support etc.
    2. Since installing Kaspersky Windows Intune portal says that my laptop has not contacted it in "nDays" I have checked Kaspersky settings etc and cannot see anything wrong. I've even tried disabling Kaspersky and seeing if that makes a difference
    but it doesn't. Has anyone got any experience using Intune and Kaspersky or another AV solution?

    I know this is old but I’m trying to clean up old posts. Did you ever solve this? If so it would be good if you could post the solution to assist others. If not, at this stage,
    as nobody has answered, I would recommend that you call Intune support.
    You will find your local Intune support number here
    http://technet.microsoft.com/en-US/jj839713.aspx
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

  • Availability of Update to Windows Intune for Samsung KNOX Standard

    I don't understand how Windows Intune supports Samaung KNOX ? KNOX is also a MDM solution, and its security features that enable business and personal content to coexist on the same handset. How to enroll the Samsung KNOX device? Via KNOX
    APP or Company Portal from Google Play? BTW, do these two MDM Solution, Windows Intune and Samsung KNOX, exist at same time on the same handset? Could someone give some ideas?

    Intune simply takes over and manages the KNOX layer, it does not add anything to KNOX enabled devices. The COmpany Portal App is just that, a app that enables registration and enrollment of the device and facilitiates the management of the KNOX layer.
    This is similar to what happens on other devices including iOS and WP8 where the MDM/management layer is already built into the device.
    Jason | http://blog.configmgrftw.com

  • Windows 8.1 mobile device management using integrated environment of SCCM 2012 R2 and Windows intune

    Can we avoid the dependency on the Symantec certificate  for enabling windows phone enrollment under Administration->Cloud services -> Windows InTune subscriptions - Windows Phones. My environment will have only windows 8.1 phones.
    Regards
    Leela

    See http://status.manage.microsoft.com/StatusPage/ServiceDashboard. 
    Engineers are investigating a service issue impacting access to portal via mobile devices.
    (Started on 12/30/2014 8:00:00 AM UTC)
    1/8/2015 11:42:49 PM (UTC)
    Current Status: Engineers are continuing to troubleshoot potential issues related to Active Directory Federation Services (ADFS). Engineers have gathered additional traces and logging data for deeper analysis. User Experience: Affected users with Windows Phone,
    iOS, or Android devices are unable to access their company portal and receive repeated prompts to enter credentials. If incorrect credentials are entered, users will receive an error stating that they have entered a bad password. Customer Impact: Engineers
    have received reports that some customers are experiencing this issue. A subset of users are affected by this event. Other users remain unaffected. Incident Start Time: Tuesday, December 30, 2014, at 8:00 AM UTC Next Update by: Tuesday, January 13, 2015, at
    12:00 AM UTC
    Torsten Meringer | http://www.mssccmfaq.de

  • I started downloading my Upgrade to Photoshop Elements Version 13 and received my upgrade confirmation and cannot locate the download on my PC running Windows 7,what is the exact name of the download and where should I find it?

    I cannot locate the upgrade to Photoshop Elements 11 to Version 13, which I purchased today and started the download as per the Order Confirmation. My order No. is AD014117711. I am running Windows 7 on my PC and cannot locate the Download. How do I find it? What is the exact name of the Download?

    EdWeidman by default the download will be saved to your Download folder.  I do not know the exact name of the file which was provided to you.

  • Can't enroll device for user and this user account is not authorized to use Windows Intune.

    Hello,
    We have SCCM 2012 R2 inegrated with intune via an intune subscription. When I enroll a device with my admin account there are no problems, but when I want to add it with another user account which is a member of the Intune users collection, it can't be enrolled.
    When I tested on https://portal.manage.microsoft.com with the credentials of the user I couldn't connect and received the following error: This user account is not authorized to use Windows Intune.
    Do I have to do anything in the https://accounts.manage.microsoft.com as there is a checkbox saying Windows Intune. this is unchecked now for all the users even my own account on which I'm able to enroll a device.
    Or is this a license problem? I know configuration Manager uses licenses for Intune but where can we track how many licenses are used and how many available? Is there some kind of report available?
    I hope someone can help me
    Kind regards,
    Robben

    I added them yesterday and this morning I was still not able to enroll a device with the added user his credentials.
    The UPN is correct. Maybe I need to force the DirSync then? Or will one day of waiting be enough normally?
    I can see the user in the intune management portal. Does this means it has been synced?
    Another thing I noticed is the cloudusersync.log doesn't show them being added? What I was thinking is I first used the all Users collection in the subscription and afterwards I changed it to a specific collection with only the test users. Could it be that
    they all synced already and the log doesn't show them anymore?
    A warning in this log shows this also:
    WARNING: Failed to get lsu url. default release one will be used. exception = System.NullReferenceException: Object reference not set to an instance of an object.~~   at Microsoft.ConfigurationManager.DmpConnector.UserSync.CloudUserUpload..ctor()  
     SMS_CLOUD_USERSYNC    23/04/2014 15:02:18    7684 (0x1E04)
    I don't know if that has anything to do with this?
    this is an extract of that log:
    CCloudUserSync::Process - User sync processing thread is now stopping.    SMS_CLOUD_USERSYNC    23/04/2014 14:59:42    8144 (0x1FD0)
    SMS_EXECUTIVE started SMS_CLOUD_USERSYNC as thread ID 7684 (0x1E04).    SMS_CLOUD_USERSYNC    23/04/2014 15:02:15    7572 (0x1D94)
    CCloudUserSync::Process - User sync processing has started.    SMS_CLOUD_USERSYNC    23/04/2014 15:02:15    7684 (0x1E04)
    Starting user sync ...    SMS_CLOUD_USERSYNC    23/04/2014 15:02:15    7684 (0x1E04)
    WARNING: Failed to get lsu url. default release one will be used. exception = System.NullReferenceException: Object reference not set to an instance of an object.~~   at Microsoft.ConfigurationManager.DmpConnector.UserSync.CloudUserUpload..ctor()  
     SMS_CLOUD_USERSYNC    23/04/2014 15:02:18    7684 (0x1E04)
    Starting user delta sync, raise failure status messages = True    SMS_CLOUD_USERSYNC    23/04/2014 15:02:18    7684 (0x1E04)
    Total received users from SCCM to be removed from cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:02:19    7684 (0x1E04)
    Successfully removed users from cloud 0    SMS_CLOUD_USERSYNC    23/04/2014 15:02:19    7684 (0x1E04)
    Total received users to add from SCCM = 0, Total Successfully added users to Cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:02:19    7684 (0x1E04)
    UserDeltaSync:- Users Added = 0, Users Removed = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:02:19    7684 (0x1E04)
    Starting user delta sync, raise failure status messages = True    SMS_CLOUD_USERSYNC    23/04/2014 15:07:19    7684 (0x1E04)
    Total received users from SCCM to be removed from cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:07:19    7684 (0x1E04)
    Successfully removed users from cloud 0    SMS_CLOUD_USERSYNC    23/04/2014 15:07:19    7684 (0x1E04)
    Total received users to add from SCCM = 0, Total Successfully added users to Cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:07:19    7684 (0x1E04)
    UserDeltaSync:- Users Added = 0, Users Removed = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:07:19    7684 (0x1E04)
    Starting user delta sync, raise failure status messages = True    SMS_CLOUD_USERSYNC    23/04/2014 15:12:19    7684 (0x1E04)
    Total received users from SCCM to be removed from cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:12:19    7684 (0x1E04)
    Successfully removed users from cloud 0    SMS_CLOUD_USERSYNC    23/04/2014 15:12:19    7684 (0x1E04)
    Total received users to add from SCCM = 0, Total Successfully added users to Cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:12:19    7684 (0x1E04)
    UserDeltaSync:- Users Added = 0, Users Removed = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:12:19    7684 (0x1E04)
    Starting user delta sync, raise failure status messages = True    SMS_CLOUD_USERSYNC    23/04/2014 15:17:19    7684 (0x1E04)
    Total received users from SCCM to be removed from cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:17:19    7684 (0x1E04)
    Successfully removed users from cloud 0    SMS_CLOUD_USERSYNC    23/04/2014 15:17:19    7684 (0x1E04)
    Total received users to add from SCCM = 0, Total Successfully added users to Cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:17:19    7684 (0x1E04)
    UserDeltaSync:- Users Added = 0, Users Removed = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:17:19    7684 (0x1E04)
    Starting user delta sync, raise failure status messages = True    SMS_CLOUD_USERSYNC    23/04/2014 15:22:19    7684 (0x1E04)
    Total received users from SCCM to be removed from cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:22:19    7684 (0x1E04)
    Successfully removed users from cloud 0    SMS_CLOUD_USERSYNC    23/04/2014 15:22:19    7684 (0x1E04)
    Total received users to add from SCCM = 0, Total Successfully added users to Cloud = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:22:20    7684 (0x1E04)
    UserDeltaSync:- Users Added = 0, Users Removed = 0    SMS_CLOUD_USERSYNC    23/04/2014 15:22:20    7684 (0x1E04)
    kind regards,
    Robben

  • Windows Phone 8 and Windows InTune

    I just signed up for a 30-day Windows InTune trial account and I'm in the process of setting up mobile device management for Windows Phone 8 devices.  After looking through the documentation, I just want to verify that
    before I can even enroll any Windows Phone 8 devices for management in Windows InTune I need to...
    1. Purchase a $99/yr subscription to establish a Company (not an Individual) account on the Windows Phone Dev Center (to get a Symantec Publishing ID)
    2. Purchase a $299/yr subscription for a Symantec Enterprise Mobile Code Signing Certificate to obtain an enterprise mobile code-signing certificate using the Symantec Publishing ID from step #1
    3. Download, sign the Company Portal App with the XapSignTool tool using the Symantec enterprise mobile code-signing certificate, and upload the app back into Windows InTune
    Is this correct?
    Regards,
    JJ

    An important update to this thread - as of November 2014, you can now enroll Windows Phone 8.1 devices for management in Windows Intune without having to purchase a Symantec certificate. For details, see
    http://blogs.technet.com/b/microsoftintune/archive/2014/11/18/improvements-to-the-windows-phone-8-1-enrollment-process-for-intune.aspx
    As of 4/2/2015, hybrid configurations still require a Symantec cert to enroll a phone, but you can get the Company Portal app for WinPhone in the Store and you can send deep links and web links to hybrid phones via that portal. The ability to enroll WinPhone
    8.1 in hybrid without a cert is in the works. Stay tuned to the Intune blog for the announcement when that comes. Or you can ping me by replying to this thread, and ask me if certless hybrid is available yet.
    Cathy Moya PM, Windows Intune/System Center Configuration Manager This posting is provided AS IS with no warranties and confers no rights.

  • TS3212 i have windows 7 and when trying to install itunes i get the error message "can not access network location %PUBLIC%\Desktop\."

    i have windows 7 and am having trouble installing itunes 10. during the installation process, i get the error message "can not access the network location %PUBLIC%\Desktop\." i cant find anything online that helps me and without itunes my ipod touch ios basically useless. please help me!!

    I've seen a report here of the following instructions helping with that particular variation of the 1606 error message:
    http://quicksolver.blogspot.in/2012/02/unable-to-install-office-2010-on.html

  • How to uninstall Windows Intune Center and its related programs permanently from the Windows 7 64 bit OS?

    Hi,
    I am Srikar,
    I installed Windows Intune End Point protection in my PC (Windows 7 64bit).
    I am not able to uninstall it.It is eating all the resources and my pc is getting slower down day by day.
    I tried uninstalling via Control Panel->Programs and Feature->Windows Intune End point Protection.
    Its uninstalled,and after some time,it is installed automatically in my PC.
    Don't know whats happening.Please Please any one guide me.My PC is not even responding some times.
    Regards,
    Srikar Ananthula,
    Srikar

    Yes, removing a device will uninstall Windows Intune Center and its association with Windows Intune. Check this:
    http://onlinehelp.microsoft.com/en-us/windowsintune.latest/hh949661.aspx [Removing a Device by Using the Windows Intune Company Portal], and
    http://technet.microsoft.com/en-us/library/hh441723.aspx [Add Computers, Users, and Mobile Devices to Windows Intune].
    Hope this helps..
    Chaitanya( Twitter |
    Blogs )
    This posting is provided "AS IS" with no warranties, and confers no rights.

  • I am trying to reinstall iTunes on my PC (Windows Vista) and download stalls at the end and message reads "The procedure entry point kCMByteStreamNotification_AvailableLengthChanged could not be located in the dynamic link library Core Media.dll"

    I am trying to reinstall iTunes on my PC (Windows Vista) and the download stops just before completion with the following message: "The procedure entry port kCMByteStreamNotification_AvailabileLengthChanged could not be located in the dynamic link library Core Media.dll"  Also "error 127. Any suggestions?

    Okay. Trouble at the "publishing production information" stage also suggests trouble with Apple Application Support.
    Let's try a standalone Apple Application Support install. It still might not install, but fingers crossed any error messages will give us a better idea of the underlying cause of the issue.
    Download and save a copy of the iTunesSetup.exe (or iTunes64setup.exe) installer file to your hard drive:
    http://www.apple.com/itunes/download/
    Download and install the free trial version of WinRAR:
    http://www.rarlab.com/
    Right-click the iTunesSetup.exe (or iTunes64Setup.exe), and select "Extract to iTunesSetup" (or "Extract to iTunes64Setup"). WinRAR will expand the contents of the file into a folder called "iTunesSetup" (or "iTunes64Setup").
    Go into the folder and doubleclick the AppleApplicationSupport.msi to do a standalone AAS install.
    Does it install properly for you? If so, does iTunes launch properly now?
    If instead you get an error message during the install, let us know what it says. (Precise text, please.)

  • What is the location for the swatches file in the illustrator product part of Adobe Creative Suite 3 Design Premium for windows (date and lenght)? File that manges its funcionallity.  Thanks

    As per adobe agent chat representative, the following question is posted on the fórum to obtain an answe from adobe.
    What is the location for the swatches file in the illustrator product part of Adobe Creative Suite 3 Design Premium for windows (date and lenght)? File that manges its funcionallity.
    Thanks
    <moved from downloading,installing,setting up - kglad>

    Illustrator is not working as it should...
    I want them to compare the original size and date of creation with what I have installed on my computer... I have installed several times with my original CD and I tried once downloading the files from the adobe site (using my own license). I suspect the files has been modified or renamed on my laptop by an external unauthorized user causing the malfunction of the application. 
    Customer services does not support CS3 anymore and the updates / patches in the adobe site does not solve the problem... They redirect me to the forums for support...
    Presently, my problem is that after creating a swatch and drag it to the swatch panel, it does not fill as it should a new form... Now, after deactivating and activating my license the swatch seems to fill the new form but when the filter that the swatch has is persistence in the next filling object created even though a different color is being used as a fill (X)... Help in the creation of a swatch over the internet just complicate the issue.
    That's why I would like to know whether updates on my product are being received or files are being replaced without my knowledge...
    Thanks...
    PS Do you know how to contact a staff adobe employer on the forums?

Maybe you are looking for

  • How to clear variable value in BPS WIB?

    Hi Experts:                 I want to clear variable value in BPS,and I use this function 'API_SEMBPS_VARIABLE_SET' to set its value to '#'. I got 1 question:      After I changed this variable manually in IE, the system 'remember' this variable in t

  • How do I extend loops i have created?

    Hello! Sorry if this is blindingly obvious to everyone but me, but... OK, so here's the scenario: I create a few bars of music using percussion, bass sounds, organ sounds, etc. all on separate tracks. I then edit the piece so that I just have the sec

  • Names changed in itunes don't update on iPod Touch

    I have a brand new 32 gb iPod touch which won't hold all of my music. I checked the convert to 128 kbps AAC so that I can get the whole collection on. The problem is I was cleaning up the names of some of my ripped music and I had a band that was lis

  • Can't see BlazeDS server side log

    Hi, I'm running JBoss 5 EAP and BlazeDS 3. I don't see any server side log for BlazeDS even though I followed BlazeDS documentation. Following is the logging section in my services-config.xml:     <logging>         <target class="flex.messaging.log.S

  • How do InDesign documents compare on retina and non-retina screens?

    I've heard that InDesign looks bad on retina screens, but I don't live near a mac dealer and I can't see any photos anywhere to judge for myself. Does anyone have any photos which could show how it compares to a non-retina mac?