<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Windows-10 on Nicola Suter</title><link>https://nicolasuter.ch/tags/windows-10/</link><description>Recent content in Windows-10 on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Fri, 19 Jul 2019 07:32:46 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/windows-10/rss.xml" rel="self" type="application/rss+xml"/><item><title>Automating network drive mapping configuration with Intune</title><link>https://nicolasuter.ch/next-level-network-drive-mapping-with-intune/</link><pubDate>Fri, 19 Jul 2019 07:32:46 +0000</pubDate><guid>https://nicolasuter.ch/next-level-network-drive-mapping-with-intune/</guid><description>&lt;p&gt;I&amp;rsquo;m thrilled to introduce the &lt;a href="https://intunedrivemapping.azurewebsites.net/DriveMapping" target="_blank" rel="noreferrer"&gt;intune-drive-mapping-generator&lt;/a&gt; which creates PowerShell scripts to map network drives with Intune. The tool is open source and built on ASP.NET Core MVC.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://intunedrivemapping.azurewebsites.net/DriveMapping" target="_blank" rel="noreferrer"&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="intune-drivemapping-generator"
 src="https://nicolasuter.ch/content/images/2019/07/intune-drivemapping-generator.png"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The intune-drive-mapping-generator is your tool of choice to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Generate an Intune PowerShell script to map network drives on Azure AD joined devices&lt;/li&gt;
&lt;li&gt;Seamlessly migrate existing network drive mapping group policies&lt;/li&gt;
&lt;li&gt;Generate a network drive mapping configuration from scratch&lt;/li&gt;
&lt;li&gt;Use an existing Active Directory group as a filter to deploy all your drive mapping configurations within one script&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;This all happens without scripting effort. You receive a fully functional PowerShell script for the deployment with Intune.&lt;/em&gt;&lt;/p&gt;

&lt;h2 class="relative group"&gt;Architecture
 &lt;div id="architecture" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#architecture" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;This tool is designed to work best with the following components although it can be useful for other purposes(?) :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Azure AD Joined and Intune enrolled Windows 10 devices&lt;/li&gt;
&lt;li&gt;Synced user account from Active Directory to Azure Active Directory (Azure AD Connect)&lt;/li&gt;
&lt;li&gt;On-premises file servers&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Howto
 &lt;div id="howto" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#howto" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;Export existing group policy
 &lt;div id="export-existing-group-policy" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#export-existing-group-policy" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;To convert your existing drive mapping group policy configuration, save the GPO as XML report with the group policy management console.&lt;/p&gt;</description></item><item><title>Intune configure lid close action</title><link>https://nicolasuter.ch/intune-lid-close-action/</link><pubDate>Sun, 19 May 2019 19:08:00 +0000</pubDate><guid>https://nicolasuter.ch/intune-lid-close-action/</guid><description>&lt;p&gt;When using your notebooks and portable devices together with a docking station your users might like to close the lid. The Windows 10 1903 release &lt;a href="https://docs.microsoft.com/en-us/windows/client-management/mdm/new-in-windows-mdm-enrollment-management#whats-new-in-mdm-for-windows-10-version-1903" target="_blank" rel="noreferrer"&gt;introduces additional power CSP settings&lt;/a&gt;. One of them allows you to configure the lid close action while on ac power - so the device doesn&amp;rsquo;t switch to hibernate mode as by default.&lt;/p&gt;

&lt;h1 class="relative group"&gt;Policy CSP configuration
 &lt;div id="policy-csp-configuration" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#policy-csp-configuration" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;To configure this policy with Microsoft Intune use the following OMA-URI configuration within a new custom device configuration:&lt;/p&gt;
&lt;p&gt;| Name | SelectLidCloseActionPluggedIn |
| Description | Action that Windows takes when a user closes the lid on a mobile PC. |
| OMA-URI | ./Device/Vendor/MSFT/Policy/Config/Power/SelectLidCloseActionPluggedIn |
| Data type | Integer |
| Value | 0 |&lt;/p&gt;
&lt;p&gt;Other possible values are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;0 - Take no action&lt;/li&gt;
&lt;li&gt;1 - Sleep&lt;/li&gt;
&lt;li&gt;2 - System hibernate sleep state&lt;/li&gt;
&lt;li&gt;3 - System shutdown&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;a href="https://nicolasuter.ch/content/images/2019/05/intune-lid-action-config.png" &gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Intune OMA-URI Lid Action"
 src="https://nicolasuter.ch/content/images/2019/05/intune-lid-action-config.png"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;

&lt;h2 class="relative group"&gt;End user experience
 &lt;div id="end-user-experience" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#end-user-experience" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;After the next MDM policy refresh the configured policy takes effect and is visible under the power options in control panel:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://nicolasuter.ch/content/images/2019/05/power-options-2.png" &gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Intune Lid Action End User Experience"
 src="https://nicolasuter.ch/content/images/2019/05/power-options-2.png"
 &gt;&lt;/figure&gt;
&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Introducing the OneDrive AutoMountTeamSites setting</title><link>https://nicolasuter.ch/onedrive-automountteamsites/</link><pubDate>Sun, 17 Mar 2019 16:03:09 +0000</pubDate><guid>https://nicolasuter.ch/onedrive-automountteamsites/</guid><description>&lt;p&gt;Reviewing the latest OneDrive features I wanted to try the new &lt;em&gt;AutoMountTeamSites&lt;/em&gt; setting which lets you preconfigure SharePoint online sites to sync automatically for defined users and devices.&lt;/p&gt;
&lt;p&gt;&lt;mark&gt;&lt;strong&gt;Updated on 12.07.2019&lt;/strong&gt;: &lt;a href="#intune-administrative-template-configuration"&gt;Included the Intune administrative template configuration&lt;/a&gt;&lt;/mark&gt;&lt;/p&gt;
&lt;p&gt;The setting is officially described as follow:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;This setting lets you specify SharePoint team site libraries to sync automatically the next time users sign in to the OneDrive sync client. (Microsoft)&lt;/p&gt;
&lt;/blockquote&gt;&lt;blockquote&gt;&lt;p&gt;If you enable this setting, the OneDrive sync client will automatically download the contents of the libraries you specified as online-only files the next time the user signs in. The user won&amp;rsquo;t be able to stop syncing the libraries. (Microsoft)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 class="relative group"&gt;Prerequisites
 &lt;div id="prerequisites" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#prerequisites" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;In order to get things up an running we need at least:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;OneDrive sync client version 19.012.0121.0011 or newer&lt;/li&gt;
&lt;li&gt;Windows 10 Version 1709 or newer&lt;/li&gt;
&lt;li&gt;OneDrive Files On-Demand enabled (&lt;a href="https://nicolasuter.ch/onedrive-automountteamsites/#intune-administrative-template-configuration" &gt;described below&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Be aware that this feature is not supported with on-premises SharePoint sites and not recommended to enable this setting for more than 1'000 devices. The device limit is related to the Windows Push Notification Service which tells the OneDrive clients when a file change occurs on a server side. When you exceed that limit clients will find themselves in a polling mode. &lt;a href="https://hansbrender.com/2019/04/04/onedrive-update-for-gpo-team-site-libraries-to-sync-automatically/" target="_blank" rel="noreferrer"&gt;Hans Brender explains this behavior well on his blog&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Intune map network drives and execute PowerShell script on each user logon</title><link>https://nicolasuter.ch/intune-execute-powershell-script-on-each-user-logon/</link><pubDate>Fri, 11 Jan 2019 20:51:36 +0000</pubDate><guid>https://nicolasuter.ch/intune-execute-powershell-script-on-each-user-logon/</guid><description>&lt;p&gt;Recently a customer needed a drive mapping solution to access his on premise file shares during his transition phase to a cloud-only workplace. I wanted to share the solution with you because it&amp;rsquo;s  a frequently asked question around a modern workplace migration. The following solution can also be extended or modified for a printer mapping or other PowerShell scripts which need to run on each user logon.&lt;/p&gt;
&lt;!--kg-card-begin: markdown--&gt;
&lt;p&gt;&lt;mark&gt;&lt;strong&gt;Updated 04.08.2019&lt;/strong&gt;: I&amp;rsquo;ve developed an automated solution to generate network drive mapping configurations with an online tool which also migrates group policy network drive mappings. See: &lt;a href="https://tech.nicolonsky.ch/next-level-network-drive-mapping-with-intune"&gt;next-level-network-drive-mapping-with-intune&lt;/a&gt;.&lt;/mark&gt;&lt;/p&gt;
&lt;!--kg-card-end: markdown--&gt;&lt;!--kg-card-begin: markdown--&gt;
&lt;p&gt;&lt;a href="https://github.com/nicolonsky/Techblog/tree/master/IntuneNetworkDrives" target="_blank" rel="noreferrer"&gt;Direct link to the final scripts&lt;/a&gt;&lt;/p&gt;
&lt;!--kg-card-end: markdown--&gt;
&lt;p&gt;Lets assume we have the following scenario:&lt;/p&gt;
&lt;figure class="kg-card kg-image-card"&gt;&lt;img src="https://nicolasuter.ch/content/images/2019/01/Hybrid-AAD.png" class="kg-image"&gt;&lt;/figure&gt;
- Customer with hybrid user-identities (Azure AD Connect)
- On premise ressources with legacy file shares
- Devices are Azure AD joined &amp;nbsp;( **not** hybrid joined)
- MDM managed with Intune
- [Optional] Always on VPN for external on-premise resource access
- [Optional] Windows Hello for Business deployment as described [here](https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-aadj-sso) 

&lt;h2 class="relative group"&gt;Architecture
 &lt;div id="architecture" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#architecture" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;With my colleague &lt;a href="https://blog.alschneiter.com/" target="_blank" rel="noreferrer"&gt;Alain Schneiter&lt;/a&gt; I designed the following solution:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Main PowerShell script stored on Azure blob storage which handles the drive mapping -  driveletters, UNC paths and descriptions can be configured within the script  &lt;/li&gt;
&lt;li&gt;Client side script deployed with Intune which triggers the main script during logon.  The main script is not stored locally which makes it easy to customize (no updates oder changes needed on client side)&lt;/li&gt;
&lt;li&gt;Deployment is user targeted via Azure AD group and Intune&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Azure blob storage configuration
 &lt;div id="azure-blob-storage-configuration" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#azure-blob-storage-configuration" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;We wanted to store the script within Azure because the customer was already using Azure blob storage. It&amp;rsquo;s also possible to store the PowerShell script on GitHub if you don&amp;rsquo;t want to use Azure.&lt;/p&gt;</description></item><item><title>Deploy OneDrive KFM with Microsoft Intune OMA-URI</title><link>https://nicolasuter.ch/onedrive-known-folder-move-ms-intune/</link><pubDate>Thu, 06 Sep 2018 18:37:21 +0000</pubDate><guid>https://nicolasuter.ch/onedrive-known-folder-move-ms-intune/</guid><description>&lt;p&gt;OneDrive KFM (Known Folder Move) allows you to redirect common Windows folders (Desktop, Documents and Pictures) to the users personal OneDrive. OneDrive Known Folder Move is the modern replacement for the well known folder redirection group policy. The deployment with Microsoft Intune allows you to trigger or automate the OneDrive KFM configuration for your end users.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Updated on 04.08.2019&lt;/strong&gt;: Added administrative template configuration&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This post is based on a great article from Oliver Kieselbach about &lt;a href="https://oliverkieselbach.com/2017/11/07/deep-dive-admx-ingestion-to-configure-silentaccountconfig-with-onedrive/" target="_blank" rel="noreferrer"&gt;Deep dive ADMX ingestion to configure SilentAccountConfig with OneDrive&lt;/a&gt;. I used his blog to play around with the admx ingestion.&lt;/p&gt;

&lt;h2 class="relative group"&gt;Prerequisites
 &lt;div id="prerequisites" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#prerequisites" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;To automatically deploy OneDrive Known Folder Move the following prerequisites must be met:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;OneDrive sync client with build 18.111.0603.0004 or greater&lt;/li&gt;
&lt;li&gt;Azure AD Joined or Hybrid Azure AD Joined Windows 10 Device Running Windows 10 1709 or later&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class="relative group"&gt;Intune Configuration
 &lt;div id="intune-configuration" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#intune-configuration" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;Configure SilentAccountConfig
 &lt;div id="configure-silentaccountconfig" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#configure-silentaccountconfig" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;

&lt;h4 class="relative group"&gt;Option #1 - ADMX Templates
 &lt;div id="option-1---admx-templates" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#option-1---admx-templates" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h4&gt;
&lt;p&gt;With SilentAccountConfig enabled OneDrive for Business gets automatically configured with the current user account who&amp;rsquo;s signing in to Windows.&lt;/p&gt;</description></item><item><title>Windows 10 1709 Cannot Access SMB2 Share Guest Access</title><link>https://nicolasuter.ch/windows-10-1709-cannot-access-smb2-share-guest-access/</link><pubDate>Thu, 19 Oct 2017 17:51:57 +0000</pubDate><guid>https://nicolasuter.ch/windows-10-1709-cannot-access-smb2-share-guest-access/</guid><description>&lt;p&gt;After Upgrading to Windows 10 1709 (Fall Creators Update) I couldn&amp;rsquo;t access my Synology NAS anymore. Therefore I started troubleshooting the Windows 10 1709 Cannot Access SMB2 Share Guest Access error:&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Windows 10 1709 Cannot Access SMB2 Share Guest Access"
 src="https://nicolasuter.ch/content/images/2017/10/2017-10-19_1725-300x171.png"
 &gt;&lt;/figure&gt;
&lt;blockquote&gt;&lt;p&gt;An error occurred while reconnecting X: to &lt;code&gt;\\nas\data&lt;/code&gt;
Microsoft Windows Network: You can&amp;rsquo;t access this shared folder because your organization&amp;rsquo;s security policies block unauthenticated guest access. These policies help protect your PC from unsafe or malicious devices on the network.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 class="relative group"&gt;Cause
 &lt;div id="cause" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#cause" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Starting with Windows 10 1709, Windows prevents you from accessing network shares with guest access enabled. Guest access means connecting to network shares without authentication, using the built-in &amp;ldquo;guest&amp;rdquo; account.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;This has no reference to the SMB1 protocol which was disabled in the latest Windows 10 release.&lt;/strong&gt;&lt;/p&gt;

&lt;h2 class="relative group"&gt;Resolution
 &lt;div id="resolution" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#resolution" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;To enable guest access again, configure the following GPO:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;Computer configuration &amp;gt; administrative templates &amp;gt; network &amp;gt; Lanman Workstation: &amp;quot;Enable insecure guest logons&amp;quot; = Enabled&lt;/code&gt;&lt;/p&gt;
&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt="Windows 10 1709 Cannot Access SMB2 Share Guest Access"
 src="https://nicolasuter.ch/content/images/2017/10/2017-10-19_1740-1024x726.png"
 &gt;&lt;/figure&gt;

&lt;h3 class="relative group"&gt;Registry Key
 &lt;div id="registry-key" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#registry-key" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;p&gt;The according registry key is located under:&lt;/p&gt;</description></item></channel></rss>