question

AndrewW-4600 avatar image
0 Votes"
AndrewW-4600 asked pvup answered

Standard Users Unable to Change Network Profile from Public to Private

My organisation has just started joining our endpoints to AAD using Endpoint Manager rather than using local AD.

I have noticed since joining a device, standard users are unable to change the network profile from Public to Private, which they were able to do when connected to Local AD. It now asks for admin creds to change the setting.

This is an issue as one of the company apps we use adds a firewall rule on install that blocks it from working on public networks. Not to mention I would rather have more restricted firewall settings for public networks.

Ideally, I would like to be able to let users change the network profile so they can change their home network to a private network rather than a public one. I am quite new to Microsoft Endpoint Manager so do not know what to change to allow them to do this.

All of our devices are Windows 10.

Any suggestion would be much appreciated.

Thanks, A

mem-intune-general
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Jason-MSFT avatar image
0 Votes"
Jason-MSFT answered

First note that Intune doesn't join devices to AAD or AD; however, you can use Autopilot to facilitate a device joining AAD or AD (because it is hybrid Azure AD domain joined).

I don't know off-hand why there's a difference between AD and AAD joined Win10 devices -- I just tested in my lab and experience the same behavior.

There is a setting under Admin Templates→Network→Network Connections named "Require domain users to elevate when setting a network's location". By default though, this setting is not configured which equates to allowing users to change without elevating. It's curious that the setting name calls out "domain users". I think that's just a by-product of long ago when there were only on-prem AD domains, but it's still odd. Changing that setting to disabled did not allow my AAD user to change the profile though.

I'm going to ask around to see if anyone else has seen this ...

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

pvup avatar image
0 Votes"
pvup answered

any update on this? i would like to allow standard users to change the network profile, as currently the public is blocking even intune on ethernet lan connection.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.