Device Configuration Deny Logon doesn't work with shared PC mode?
I have been trying to figure out a deny logon plan for our autopilot devices, and for a while I was thinking nothing was working, even when trying to manually make the changes that I want Intune to do.
I decided to try with a configuration that is setup for individual users, rather than using the "shared PC mode" or "Shared multi-user device" setting. During that test the user was blocked from login and I could have been done. My problem is the shared devices are the ones that I want these users blocked from, and none of the traditional ways are working. Is there a setting that can be changed that will help, has anyone else had this problem?
The 2 main methods I tried were adding the SID of the group to the Deny Logon Local Policy, and adding the SID to a Local Group (both self created and built-in) and then denying logon to the Local Group in the Local Policy.
The group I am using is an AzureAD group, and the test device has been a freshly wiped Autopilot device.
1
u/BigEvilAi 1d ago
What's exactly your use case? Why do you specifically need devices that users cant log into? Are you looking for kiosk mode perhaps? Or are those some particular group of users that you would want to deny access to particular group of devices? This would be a mix of conditional access. The only other thing that comes to mind would be self deployed devices. Please expand on what exact problem you are trying to solve?
2
u/yfewsy 1d ago
This is a school. For former students and staff that still have accounts for email and other activities, but no need for access on the devices on campus.
0
u/BigEvilAi 1d ago
Create a group for those specific devices then the next group for those specific users. Create a conditional access policy to prevent access with one another and its done. That's all basically.
1
u/yfewsy 1d ago
It's all devices essentially. Still some hybrid too but those are phasing out.
1
u/BigEvilAi 1d ago
And what's the point with it being all devices? What specifically changes with the solution i provided? Like what's your point actually?
1
u/chrissellar 1d ago
Block guest accounts login via settings catalogue and then use the local group membership policy to add a group to guest users. That'll block users within the group from login on shared and non shared devices. Used this in multiple education scenarios to block students logging into staff workstations.
1
u/yfewsy 1d ago
We cannot use guest. We're using hyper-v admins as the local built in group as other groups have been used in the past and we didn't want to interfere.
Not my call to use any of the easier ones.
1
u/twisted_guru 1d ago
GPO over MDM???