Category: Microsoft
Category Archives: Microsoft
Remove MSP Admin Access to Tenant
Hi All,
I am taking over IT responsibilites for a mid-size company. Currently, we are dealing with a roque MSP who has admin credentials for everything including our M365 tenant. No internal employees of the company, including owner, have been provided admin rights.
I should add that this MSP is a one-man shop, I seriously doubt he has any formal partner relationship with Microsoft, but I may be wrong about that.
My feeling is that he has not registered the tenant the correct way and ownership shows his name rather than the company, but I can’t prove that.
due to conflicts, there is an eminent possibility that he will begin deleting accounts, removing licenses or otherwise interrupting business.
Is anyone aware of a method for contacting Microsoft to deal with these sorts of disputes? without an admin account, I don’t even have the option to raise a support case with them right now.
We may be in a tough situation given that we pay him directly for services, so the invoice and payments will probably be in his name.
any thoughts or suggestions are appreciated!
Hi All, I am taking over IT responsibilites for a mid-size company. Currently, we are dealing with a roque MSP who has admin credentials for everything including our M365 tenant. No internal employees of the company, including owner, have been provided admin rights. I should add that this MSP is a one-man shop, I seriously doubt he has any formal partner relationship with Microsoft, but I may be wrong about that. My feeling is that he has not registered the tenant the correct way and ownership shows his name rather than the company, but I can’t prove that. due to conflicts, there is an eminent possibility that he will begin deleting accounts, removing licenses or otherwise interrupting business. Is anyone aware of a method for contacting Microsoft to deal with these sorts of disputes? without an admin account, I don’t even have the option to raise a support case with them right now. We may be in a tough situation given that we pay him directly for services, so the invoice and payments will probably be in his name. any thoughts or suggestions are appreciated! Read More
two sccm to one tenant intune
I have a number of devices configured in SCCM “A” co-management with an intune tennant “A”
I have a number of devices configured in SCCM “B” co-management with an intune “B” tennant.
Now I need to undo the SCCM comanagement “A” and make a new co-management the intune tenant “B”
What are the risks and process to do this?
I have a number of devices configured in SCCM “A” co-management with an intune tennant “A”I have a number of devices configured in SCCM “B” co-management with an intune “B” tennant.Now I need to undo the SCCM comanagement “A” and make a new co-management the intune tenant “B”What are the risks and process to do this? Read More
Windows 11 Insider Preview 10.0.26120.1542 (ge_release_svc_betaflt_upr) nvidia geforce rtx 3080 err
Hello microsoft,
Yesterday I faced issues to download the update as it always stopped at 8%, today i was able to update to Windows 11 Insider Preview 10.0.26120.1542 (ge_release_svc_betaflt_upr) but as of today my nvidia geforce rtx 3080 is not visable and detectable anymore.
I have an acer predator triton 300 nvidia geforce rtx 3080
I tried:
windows x –> device management (show hidden ) -> analyze for changes – but not shown
checked for bios updates
tried to install latest drivers from nvidia but keep the error of not detected
out of options, seems to be the error related to the latest insiders update as it started after 20th of august *came back from holiday and updated to latest and issues started
not able to detect my dell external monitor via hdmi – even bought a new cable, error still there but not when other pc’s connected)
please help me to fix as i am nowhere w/o my rtx
Hello microsoft, Yesterday I faced issues to download the update as it always stopped at 8%, today i was able to update to Windows 11 Insider Preview 10.0.26120.1542 (ge_release_svc_betaflt_upr) but as of today my nvidia geforce rtx 3080 is not visable and detectable anymore.I have an acer predator triton 300 nvidia geforce rtx 3080I tried: windows x –> device management (show hidden ) -> analyze for changes – but not shownchecked for bios updatestried to install latest drivers from nvidia but keep the error of not detectedout of options, seems to be the error related to the latest insiders update as it started after 20th of august *came back from holiday and updated to latest and issues startednot able to detect my dell external monitor via hdmi – even bought a new cable, error still there but not when other pc’s connected)please help me to fix as i am nowhere w/o my rtx Read More
Organize posts in teams
Hello!
Is there a way to put posts in a folder? Not files that you send via teams. Posts. Maybe it’s an announcement or transcript that is made via a post. I’m not able to see the option where I save the transcripts to folder. Is this an option in teams?
Hello!Is there a way to put posts in a folder? Not files that you send via teams. Posts. Maybe it’s an announcement or transcript that is made via a post. I’m not able to see the option where I save the transcripts to folder. Is this an option in teams? Read More
AVD Truly Non-Persistent
We have an environment where there are machines available for public use (a public library). Users should be able to create documents and the like on the machine, and save them to locally attached storage, or e-mail/cloud storage, etc.
When a user logs out, the machine should completely reset; all changes made, documents created, history, and the like should be erased and the machine should automatically reset to the base image.
Everything in the MS documentation I can find that mentions non-persistent machines just means pooled machines, which doesn’t do this. If I want to set up an AVD pool that does this, how would I accomplish that?
We have an environment where there are machines available for public use (a public library). Users should be able to create documents and the like on the machine, and save them to locally attached storage, or e-mail/cloud storage, etc. When a user logs out, the machine should completely reset; all changes made, documents created, history, and the like should be erased and the machine should automatically reset to the base image. Everything in the MS documentation I can find that mentions non-persistent machines just means pooled machines, which doesn’t do this. If I want to set up an AVD pool that does this, how would I accomplish that? Read More
Rearrange columns with partial matching numbers
I’ll be working with three columns, including column A, which has the full number for an event; Ecode, which will have a partial number (the last five digits of column A); and column C, which will have a score related to column B. The difficult thing I’m trying to figure out is how to rearrange column B (and, by extension, C) so they match up with the full numbers of column A without moving the values of column A.
I’ll be working with three columns, including column A, which has the full number for an event; Ecode, which will have a partial number (the last five digits of column A); and column C, which will have a score related to column B. The difficult thing I’m trying to figure out is how to rearrange column B (and, by extension, C) so they match up with the full numbers of column A without moving the values of column A. Read More
Transform xml
Dear team,
While implementing this action in logic app, I need to pass the connection string for map to refer the assemblies from integration account that needs to be secured. Instead of key vault, please suggest how to implement this connection string parameter in this action
Thanks and regards,
MH
Dear team, While implementing this action in logic app, I need to pass the connection string for map to refer the assemblies from integration account that needs to be secured. Instead of key vault, please suggest how to implement this connection string parameter in this action Thanks and regards,MH Read More
Dynamic Content in PowerPoint
Once I created a PowerAutomate flow that collected responses in MS Forms, fed them through Sharepoint, and then populated an MS Word template with Quick Parts/Fields. I would like to do something similar with a PowerPoint template.
I will be attending a trade show in which I would like users to answer a question using some kind of input, and then that response would feed into a PowerPoint slide. The PowerPoint slide could then be easily sent to the user (from an iPad) for sharing on social media.
Any ideas on how I can do this?
Once I created a PowerAutomate flow that collected responses in MS Forms, fed them through Sharepoint, and then populated an MS Word template with Quick Parts/Fields. I would like to do something similar with a PowerPoint template.I will be attending a trade show in which I would like users to answer a question using some kind of input, and then that response would feed into a PowerPoint slide. The PowerPoint slide could then be easily sent to the user (from an iPad) for sharing on social media.Any ideas on how I can do this? Read More
Microsoft hosted Copilot for Microsoft 365 user trainings for CSP customers
To support our CSP Partners driving Copilot usage with their customers, we are happy to announce that on September 16th, Microsoft will be hosting a 2.5-hour Copilot training workshop for end users in 5 different languages across multiple time zones. The workshop includes an overview of Copilot for Microsoft 365, hands-on prompt training, Demos across roles in HR, Marketing, Sales, and other disciplines, real time support, and Q&A.
For Partners that are interested and have the capacity to deliver adoption training themselves, we offer Train the Trainer sessions and the content for delivery.
Sign up for the Train the Trainer session
Download email template to invite your customers
Microsoft Tech Community – Latest Blogs –Read More
How to use Company Slide Deck Branding on PPT with Copilot
Hello,
The company that I work for has a PPT template with company branding on it. When I use Copilot on the branded PPT, it requires me to approve a blank PPT first as the Copilot will not work on top of/with the company branded PPT.
Does anyone know a work around this? To merge company branded PPT and Copilot?
Thanks!
Hello,
The company that I work for has a PPT template with company branding on it. When I use Copilot on the branded PPT, it requires me to approve a blank PPT first as the Copilot will not work on top of/with the company branded PPT.
Does anyone know a work around this? To merge company branded PPT and Copilot?
Thanks! Read More
Coordinated Universal Time in Outlook
When I create a new calendar event in Outlook, and sync it to Google Calendar, it shows up in Coordnated Universal Time instead of Eastern Time. I was wondering if this could be changed. Thanks!
When I create a new calendar event in Outlook, and sync it to Google Calendar, it shows up in Coordnated Universal Time instead of Eastern Time. I was wondering if this could be changed. Thanks! Read More
User Cannot Access One Specific Site and I Can’t Figure Out Why
User can access other sites, but this one particular site, which many other users can access, they cannot. I’ve tried:
Granting direct access (typical access is via Members group).Granting direct access to a file or folder.Removing and re-granting access.Granting access via sharing link.Had them sign out and back into their M365 account.Had them use a different browser.Had them try incognito mode.They are on a VDI machine, so it is a new machine every day (no need to try rebooting).
Their permissions include a number of “web-only limited access” entries, but my understanding is that is because they were granted access to a file or folder deeper in the file structure (there are over 28K files), most likely through an access request that was approved. Even though their requests were approved, they never were able to access what was granted.
Any ideas?
User can access other sites, but this one particular site, which many other users can access, they cannot. I’ve tried:Granting direct access (typical access is via Members group).Granting direct access to a file or folder.Removing and re-granting access.Granting access via sharing link.Had them sign out and back into their M365 account.Had them use a different browser.Had them try incognito mode.They are on a VDI machine, so it is a new machine every day (no need to try rebooting).Their permissions include a number of “web-only limited access” entries, but my understanding is that is because they were granted access to a file or folder deeper in the file structure (there are over 28K files), most likely through an access request that was approved. Even though their requests were approved, they never were able to access what was granted.Any ideas? Read More
Picklist creating error when Excel file is sent to another device
I’ve been modifying an Excel workbook for our employees as it stopped calculating properly. I copied and pasted the data from the original workbook to a fresh one to work with and got it to calculate and function properly (the issue appears to be that the original workbook was calling upon a URL that no longer works to get data for some of the calculations).
However, even though the workbook now works properly on my device, when I send it to a colleague, they are no longer able to use the picklists that are contained in the workbook. I’ve tried this out and encountered the same problem when opening on a different device. How can I ensure that the picklists work properly? I’ve attached the error that occurs for one such picklist.
All devices that have been involved so far are Windows devices.
I’ve been modifying an Excel workbook for our employees as it stopped calculating properly. I copied and pasted the data from the original workbook to a fresh one to work with and got it to calculate and function properly (the issue appears to be that the original workbook was calling upon a URL that no longer works to get data for some of the calculations). However, even though the workbook now works properly on my device, when I send it to a colleague, they are no longer able to use the picklists that are contained in the workbook. I’ve tried this out and encountered the same problem when opening on a different device. How can I ensure that the picklists work properly? I’ve attached the error that occurs for one such picklist. All devices that have been involved so far are Windows devices. Read More
Migrate MS Sentinel from one tenant to another tenant
I need to migrate Microsoft Sentinel with all its resources (playbooks, workbook, connectors, analytics rules), I would need a step by step, since I see that among the documentation that Microsoft has, it does not have it. I would like to know if there is any tool or functionality that allows me to do this, without having to rebuild everything
I need to migrate Microsoft Sentinel with all its resources (playbooks, workbook, connectors, analytics rules), I would need a step by step, since I see that among the documentation that Microsoft has, it does not have it. I would like to know if there is any tool or functionality that allows me to do this, without having to rebuild everything Read More
I don’t have any of the 24H2 update features
I just recently installed the new update and my computer doesn’t have any of the features that should have come with the update, even signed in for the insider program incase it was available there, but nothing.
I just recently installed the new update and my computer doesn’t have any of the features that should have come with the update, even signed in for the insider program incase it was available there, but nothing. Read More
What’s the biggest challenge your small business is facing with technology right now?
Hi everyone,
We’re curious to hear from you all about any technology challenges your business is currently facing. Whether it’s managing remote work, cybersecurity concerns, or finding the right tools to streamline operations, let’s share our experiences and solutions. Your insights could help others in the community who might be facing similar issues.
Looking forward to hearing your thoughts!
Hi everyone,
We’re curious to hear from you all about any technology challenges your business is currently facing. Whether it’s managing remote work, cybersecurity concerns, or finding the right tools to streamline operations, let’s share our experiences and solutions. Your insights could help others in the community who might be facing similar issues.
Looking forward to hearing your thoughts! Read More
Managed Identity support for WordPress on App Service
We’re thrilled to share with you that WordPress on App Service now supports Managed Identity. This means your WordPress site can securely access other Azure resources, like Azure Database for MySQL Flexible Server and Azure Communication Service Email, without the hassle of managing connection strings and secrets.
What is a managed Identity and why should you implement it for WordPress on App Service?
A frequent issue developers face is handling secrets, credentials, certificates, and keys needed for secure communication between services. Managed identities remove the necessity for developers to oversee these credentials.
Even though developers can securely store secrets in Azure Key Vault, services still require a method to access it. Managed identities offer an automatically managed identity in Microsoft Entra ID that applications can use to connect to resources supporting Microsoft Entra authentication. Using managed identities, applications can acquire Microsoft Entra tokens without needing to manage any credentials.
Managed identities are an excellent way to enhance the security of your WordPress application. They eliminate the need to manage credentials, as they integrate seamlessly with various Azure services, providing secure access without explicit credentials. Best of all, you can use managed identities at no additional cost.
There are two types of managed identities: System-assigned and User-assigned. To learn more about managed identities and its types visit https://learn.microsoft.com/entra/identity/managed-identities-azure-resources/overview
How does WordPress on App Service use a managed Identity?
WordPress on App Service now uses a user-assigned managed identity configured with App Service. This managed identity allows access to other Azure resources, such as the Azure Database for MySQL flexible server or Azure Communication Services Email, without needing to store credentials in Application settings as we did before. https://github.com/Azure/wordpress-linux-appservice/blob/main/WordPress/wordpress_application_settings.md
This approach also eliminates the need for connection strings and storing secrets in Key Vault. Moving forward, this will be the default behavior for WordPress on App Service. We recommend adopting this approach. For new websites created on or after September 9, 2024, managed identities will be configured by default if the Managed Identity checkbox in the Add-ins tab is checked during the creation process. https://portal.azure.com/#create/WordPress.WordPress
How to configure managed identity for WordPress on App Service?
For new website deployments (on or after 9 September 2024), managed identity is configured by default. In the creation experience, navigate to the Add-ons tab, where you will see that managed identity is enabled by default. We highly recommend following this approach. However, you can disable this feature if you need to manually set up managed identities or if your policies require a different approach.
For older websites, we need to follow the steps below to configure Managed Identity for WordPress on App Service.
Step 1. Create a user assigned managed identity resource.
Follow the steps here: https://learn.microsoft.com/entra/identity/managed-identities-azure-resources/how-manage-user-assigned-managed-identities?pivots=identity-mi-methods-azp#create-a-user-assigned-managed-identity to create a new user assigned managed identity.
Or you can directly go to the create flow here: https://portal.azure.com/#create/Microsoft.ManagedIdentity
We recommend that you select the same Resource group and Region for your managed identity as with other resources of WordPress on App Service. This will make it easier for you to manage these resources together.
Step 2. Configure managed identity for App Service
Follow the steps here: https://learn.microsoft.com/azure/app-service/overview-managed-identity?tabs=portal%2Chttp#add-a-user-assigned-identity
Step 3. Enable managed identity authentication for Azure Database for MySQL flexible server
This step has two parts:
Part 1: Enable MySQL database authentication using managed identity
Go to Azure database for MySQL resource. Go to Security > Authentication.
Select ‘Microsoft Entra authentical only’ option in the authentication section. The allows authentication only using Microsoft Entra account and disables MySQL native password-based authentication. We highly recommend this approach. Although you could select ‘MySQL and Microsoft Entra authentication’ to enable authentication using both methods.’
In the Select Identity section, select the user assigned managed identity you had crated in Step1.
In the ‘Microsoft Entra Admins’ section click on ‘Select’. In the search option search for the Managed Identity name, and you will find an Admin with the same name of type ‘Enterprise application’. Select that option and click on ‘Select’.
Now Azure database for MySQL has been configured to authenticate with the managed Identity. For more details, visit: https://learn.microsoft.com/azure/mysql/flexible-server/how-to-azure-ad#configure-the-microsoft-entra-admin
Part 2: Update application settings: Go to App Service Resource > Settings > Environment variables.
Add these settings:
ENTRA_CLIENT_ID
<Client ID of managed identity>
ENABLE_MYSQL_MANAGED_IDENTITY
true
You can find the client ID of the managed Identity in the overview section of the managed identity resource.
Edit these settings:
DATABASE_USERNAME
<Microsoft Entra Admin>
This is the Microsoft Entra Admin we added in Part 1 earlier. This is usually same as the name of the managed identity.
Step 4. Enable managed identity authentication for Azure Communication Services Email
Go to App Service resource > Settings > Environment variables.
Add this application setting:
ENABLE_EMAIL_MANAGED_IDENTITY
true
Step 5. Make code level changes.
Next you need to make code level changes to make sure that WordPress is able to access the database and email server. This includes making changes to wp-config.php and the email plugin.
We have created a script to help you make this code changes faster. Go to Kudu SSH and run this script:
/usr/local/bin/managed-identity-setup.sh
Now you have successfully enabled WordPress on App Service to use managed identity.
Note: You can log in to phpMyAdmin by using the value from DATABASE_USERNAME environment variable as the username and the token as the password. To find the token use your Kudu SSH to run the following command:
/usr/local/bin/fetch-mysql-access-token.sh
Support and Feedback
Did you like this article? Please click on like if you do. Also, leave your comments, and help us to make this article better.
If you need any assistance, feel free to open a support request through the Microsoft Azure portal.
You can also report an issue on our GitHub repository Issues
For more details about our offering, check out the announcement on the General Availability of WordPress on Azure App Service.
Also, you can find here all articles related to WordPress on App Service.
You can share your thoughts and suggestions on our community page.
Would love to know about your experience & issues you are facing, and you can start a conversation with us by emailing to wordpressonazure@microsoft.com
Microsoft Tech Community – Latest Blogs –Read More
What’s new in Microsoft Device Ecosystem Platform (MDEP) 2024.3 Release
The Microsoft Device Ecosystem Platform (MDEP) continues its forward momentum with the release of MDEP 2024.3, bringing a suite of powerful new tools and enhancements designed for OEMs and third-party developers. This latest update introduces advanced security features, improved API functionalities, and expanded customization options, all aimed at streamlining device management, improving integration, and ensuring a secure, seamless user experience across diverse hardware configurations and form factors.
Juha Kuosmanen, Head of MDEP, shares: “These updates to MDEP reinforce our commitment to providing industry-leading device management, and security. With these enhancements, OEMs and developers now have even more capabilities to build secure, user-centric, and customizable device experiences, ultimately empowering organizations to deliver better meeting experiences built on MDEP.”
Let’s dive into the key features and improvements in this release:
MDEP Configuration API
The MDEP Configuration API acts as a centralized interface that simplifies the interaction between partner services and the platform. OEMs can now manage essential features like device pairing, synchronization, administrative sessions, and device settings updates with greater ease. The API is designed to abstract the complexity of each system, making runtime device management simpler and more efficient. This extensible tool is available through the Microsoft SDK, providing easy integration for OEMs and developers.
MDEP Public API SDK
The MDEP Public SDK is a game-changer for developers, offering tools and libraries to simplify app development and integration with the MDEP platform. It allows for the separation of apps from internal platform services and provides a user-friendly environment for OEMs and third-party partners, including VaaS providers. The SDK includes public APIs, an Android Studio plugin, and comprehensive documentation within the IDE, enabling functions like enabling/disabling Wi-Fi/Ethernet, rebooting, and using stress tools for virtual devices.
App Integrity Service
Security is paramount in MDEP, and the App Integrity Service takes this focus to the next level. This service enables apps to securely share tokens with clients, including cloud services, to verify application and device identity. With a cloud component and reference implementation, the App Integrity Service offers a robust solution for maintaining app security and protecting sensitive data.
SOC Secure Enclave Abstraction
The SOC Secure Enclave Abstraction enhances security by scaling hardware attestation, zero trust, and other key security features across all silicon platforms. This ensures a consistent level of protection across devices, regardless of hardware configuration, safeguarding against unauthorized access and data breaches.
Deprecation of TLS 1.0/1.1
With the retirement of TLS 1.0 and 1.1, MDEP has implemented crucial design changes and a support plan to facilitate a smooth transition to newer TLS versions. This update is essential for maintaining secure communication channels, as newer TLS versions provide enhanced security protocols.
Teams Panels & Room Scheduling Support
MDEP now extends its support to Microsoft Teams Panels and room scheduling displays, offering the same level of security and customization as other MDEP-powered devices. This update ensures a seamless, secure experience for meeting room scheduling and management.
Enhanced Systems App Customization
Customization is key, and MDEP 2024.3 introduces a new system-wide Light Theme mode. This expanded customization option gives OEMs more flexibility in designing their user interfaces while ensuring consistency across devices, providing a cohesive look and feel for users.
IP Phones – Partner Preview
Partners can now preview the baseline functionality for Teams Phones and IP phones. This early release allows for exploration and integration into new devices, providing an exciting glimpse into the future of connected device experiences.
Enterprise & Government-Grade Networking: EAP Over LAN – Partner Preview
MDEP introduces enterprise and government-grade networking capabilities with built-in support for Extensible Authentication Protocol (EAP) over LAN. Available through the Configuration API and SDK, this feature meets the stringent security requirements of enterprise and government environments, ensuring robust and secure networking.
To learn more about MDEP, visit https://aka.ms/mdep
Microsoft Tech Community – Latest Blogs –Read More
New Planner – API available?
Hello,
anyone knows if and when there will be an API available for the new planner?
I did some tests with the current graph api (1.0) for planner, but it seems it is only working for “classic” planner plans, not for plans of a premium plan.
Hello, anyone knows if and when there will be an API available for the new planner? I did some tests with the current graph api (1.0) for planner, but it seems it is only working for “classic” planner plans, not for plans of a premium plan. Read More
Forms Auto Populating Fields Based on Unique Code
Mailing an offer providing recipients a complimentary item. To redeem the offer, the recipients will receive a unique code to enter into a form. Based on that unique code, I’d like Forms to auto populate the remaining fields (name, address, etc.). I understand I will have to provide Forms that information. Is this doable?
Mailing an offer providing recipients a complimentary item. To redeem the offer, the recipients will receive a unique code to enter into a form. Based on that unique code, I’d like Forms to auto populate the remaining fields (name, address, etc.). I understand I will have to provide Forms that information. Is this doable? Read More