0% found this document useful (0 votes)
16 views45 pages

Microsoft Intune Device Management Guide

Module-2 provides an overview of Microsoft Intune, focusing on device enrollment, policy configuration, and Mobile Device Management (MDM) strategies. It details various enrollment methods for devices, management capabilities, and compliance policies to protect organizational resources. The module also covers the integration of Intune with Azure AD for device management and compliance reporting.

Uploaded by

Anuprita Muley
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views45 pages

Microsoft Intune Device Management Guide

Module-2 provides an overview of Microsoft Intune, focusing on device enrollment, policy configuration, and Mobile Device Management (MDM) strategies. It details various enrollment methods for devices, management capabilities, and compliance policies to protect organizational resources. The module also covers the integration of Intune with Azure AD for device management and compliance reporting.

Uploaded by

Anuprita Muley
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Module-2

• Introduction to Intune
• Device enrollment and inventory
• Policy configuration and compliance
• Mobile Device Management (MDM)
• MDM deployment strategies
Introduction to Intune

• What is Intune ?
Microsoft Intune is a cloud-based
endpoint management solution. It
manages user access to
organizational resources and
simplifies app and device
management across your many
devices, including mobile devices,
desktop computers, and virtual
endpoints.
Device enrollment and inventory
Intune offers several device enrollment
methods, including Windows
Autopilot, manual enrollment via the
Company Portal app or account
settings, and administrator-driven
methods like Azure AD join, Apple's
Automated Device Enrollment (ADE),
and bulk enrollment using provisioning
packages. These methods
accommodate both corporate-owned
and personally-owned devices across
various platforms like Windows, iOS,
and Android.
Manage device authentication

01 02 03 04
Describe Azure AD Examine Azure AD Join devices to Manage devices
join (Microsoft Entra join (Microsoft Entra Azure AD (Entra ID) joined to Azure AD
join) join) prerequisites (Entra ID)
limitations and
benefits
Describe Azure AD join (Microsoft Entra join)

• Windows Pro or Enterprise Edition can join Azure AD (Entra ID) and AD DS
• Azure AD (Entra ID) joined devices cannot be managed with Group Policy
• Typical scenarios for joining a device to Azure AD (Entra ID):
– If applications and resources that you use are mostly in the cloud
– If you want to separate temporary accounts
– If you want to enable users to join their device to the corporate environment
– You want to transition to cloud-based infrastructure
– You have remote branch offices with limited on-premises infrastructure
• Join devices to Azure AD (Entra ID) during initial setup or later by using system settings
• Use Hybrid Azure AD (Entra ID) to automatically register on-premises domain-joined devices with
Azure AD (Entra ID)
Examine Azure AD join (Entra join) prerequisites
limitations and benefits
Azure AD (Entra ID) limitations Scenarios enabled by using Azure
Azure AD (Entra ID) is not a part of the core AD (Entra ID) with on-premises AD
infrastructure infrastructure
• Ease of transition to cloud-based infrastructure
Azure AD (Entra ID) does not have the same and MDM
management capabilities as AD DS
• When on-premises domain join is not possible
(tablets, phones, etc.)
Azure AD (Entra ID) benefits • When users primarily need to access Microsoft 365 or
Single Sign On (SSO) other SaaS apps integrated with Azure AD (Entra ID)
Roaming of user settings across joined devices • You want to manage a group of users in Azure AD
Windows Hello support (Entra ID) instead of in Active Directory
• You want to provide joining capabilities to workers in
Restriction of access to apps from only compliant devices
remote branch offices with limited on-premises
Seamless access to on-premises resources infrastructure
Join devices to Azure AD (Entra ID)
1 Joining a device to Azure AD (Entra ID) is simple procedure

You can join to Azure AD (Entra ID) after Windows installation, or you can do it later, at any
2
time by using Settings pane

3 You need Azure AD (Entra ID) credentials to join device to Azure AD (Entra ID)
Manage devices joined to Azure AD
(Entra ID)
1 Group Policy manages devices that join on-premises AD DS

2 Group Policy is not always available or supported for devices that join Azure AD (Entra ID)

Azure AD (Entra ID) supports integration with mobile device management applications
3
such as Intune

When integration between Intune and Azure AD (Entra ID) is configured, a device that joins
4
Azure AD (Entra ID) automatically enrolls with Intune
Enroll devices using Microsoft Configuration Manager

• Deploy the Microsoft Configuration Manager client


• Monitor the Microsoft Configuration Manager client
• Manage the Microsoft Configuration Manager client
Deploy the Microsoft Configuration Manager client

Benefits of the Microsoft Configuration Client Deployment Options


Manager client • Client push
• Enables tracking of software installed on a client • Manual deployment
device • OS deployment
• Provides hardware inventory information • Microsoft Intune
• Ability to manage and deploy the OS and line-of-
business (LoB) applications
• End-user access to self-service catalog of
software
Client Deployment Options

Client push Manual deployment OS deployment Microsoft Intune


Deploys the Microsoft Deploys the Microsoft When installing and setting up Intune drives Microsoft
Configuration Manager client Configuration Manager client Windows using a task sequence, Configuration Manager client
directly from the Microsoft installation source files and a slip-stream the Microsoft installation and registers the
Configuration Manager console script file containing the Configuration Manager client into device with the Cloud
install parameters the Windows setup and provide it Management Gateway
Device discovery (Active Directory with the necessary installation
Lightweight Directory Access Executes from the [Link] parameters Manage each respective
Protocol (LDAP) integration) file or from the MSI that is workload from either Intune or
part of the client files Must be installed when a Microsoft Configuration
Copies the files to the source device is built for the Manager after installation
computer and initiates the install Can be time consuming as a first time (or rebuilt)
automatically delivery mechanism
Initial copy process may
increase network traffic
Monitor the Microsoft Configuration
Manager client
1Client online status. Online (connected to its assigned management point) or offline.

Client activity. Active (it has communicated with Microsoft Configuration Manager in the past seven days) or
2 inactive.

Primary User. The primary user of this device, calculated over a 60-day period of the most frequent Sign-in
3 attempts.

Operating System Build. See the OS version of a device without having to connect to or perform any remote
4 management.

Client check. State of the periodic evaluation that the Microsoft Configuration Manager client runs on the
5 device. The evaluation checks the device and can remediate some of the problems it finds.
Manage the Microsoft Configuration Manager client

• Device appears in Assets and Compliance workspace in the Devices node after Microsoft
Configuration Manager client installation and site assignment
• Collections
– Represent devices or users that have some commonality in Microsoft Configuration Manager.
– Perform tasks, such as target a deployment or run a report, on devices in a collection.
• Management options apply to devices in a collection or individual devices
– Start Resource Explorer.
– Start Policy Retrieval.
– Add to a collection.
– Client Settings Resultant Set of Policies (RSOP).
Module 3: Enroll devices using Microsoft Intune

• Manage mobile devices with Intune


• Enable mobile device management
• Explain considerations for device enrollment
• Manage corporate enrollment policy
• Enroll Windows devices in Intune
• Enroll Android devices in Intune
• Enroll iOS devices in Intune
• Explore device enrollment manager
• Monitor device enrollment
• Manage devices remotely
Manage mobile devices with Intune

• The Intune admin center console includes all the management capabilities
provided by Intune.
• The Intune Company Portal is used to self-manage device enrollment and
to access published applications.
• Device Management Lifecycle
– Enroll
– Configure
– Protect
– Retire
Manage mobile devices with Intune
Enable mobile device
management
• Mobile device management (MDM) is an
industry standard for managing mobile
devices, such as smart phones, tablets,
laptops and desktop computers.
• To enable the enrollment of mobile
devices, the MDM Authority must be set
in the Intune configuration.
• By default, Intune allows enrollment of
Windows, Android and Samsung Knox
Standard devices. To manage iOS and
macOS devices, an Apple MDM push
certificate is required.
Explain considerations for device
enrollment
Determine enrollment method
• Group Policy
• Joining Azure AD
• Manually (Settings, Provision Package, Company Portal App)

Supported Devices
• Windows 10/11 (Home, Pro, Education, S mode, and Enterprise versions)
• Windows 10/11 Cloud PCs on Windows 365
• Windows 10 IoT and Windows 10 Holographic
• Windows 10 2019 LTSC
• Windows RT 8.1, and Windows 8.1 (sustaining mode)
• Apple iOS/iPadOS 13.0 and later
• macOS X 10.15 and later
• Android 6.0 and later, including Samsung Knox 2.4 and later and Android for Work

Determine devices allowed and criteria

Determine if enrollment is optional or mandatory


Manage corporate enrollment policy

• Your initial Azure AD (Entra ID) domain will follow the model:
– [Link]
• Add one or more of your custom domain names, i.e., [Link]
(recommended)
• Add custom domain names in the Microsoft 365 management portal
• Configure Automatic MDM enrollment (recommended)
OR
Create CNAME records to simplify enrollment and device registration when
not licensed for Azure AD (Entra ID) Premium
Enroll Windows devices in Intune

Many ways to enroll Windows devices in Microsoft Intune:

• Add work or school account


• Enroll in MDM only (user driven)
• Azure AD (Entra ID) join (Out of Box Experience (OOBE))
• Azure AD (Entra ID) join (Autopilot – User-driven deployment mode)
• Azure AD (Entra ID) join (Autopilot self-deploying mode)
• Enroll in MDM only (Device Enrollment Manager)
• Microsoft Configuration Manager co-management
• Azure AD (Entra ID) join (bulk enrollment)
Enroll Android devices in Intune

Enrollment of Android devices is Android Enterprise


typically performed by the end-user:
• Download the Company Portal app from • Android Work Profile
Google Play
• Android Enterprise dedicated
• Open the Company Portal app, sign-in with a work
or school account • Android Enterprise fully managed

• Follow the instructions given in the app


Enroll iOS devices in Intune

• Enrollment of iOS devices can be done by the user or automatically


• To enroll an iOS device using the Company Portal app
– Download the Company Portal app from the Apple app store
– Sign-in to Company Portal app with a work or school account and follow instructions
• Intune support for company-owned iOS device enrollment methods
– Apple's Device Enrollment Program (DEP)
– Apple School Manager
– Apple Configurator Setup Assistant enrollment
– Apple Configurator direct enrollment
– With a device enrollment manager account.
• Supervised mode
Explore device enrollment manager

Existing Azure AD users may be added to the device enrollment manager (DEM) user account,
allowing them to enroll up to 1000 devices through the Company Portal.
• Limitations of devices enrolled using a DEM account
• Permissions for DEM
Global or Intune Service Administrator Azure AD roles are required to:
• Complete tasks that are related to DEM enrollment in the Admin Portal
• Access all DEM users despite role-based access control (RBAC) permissions being listed and available under the
custom User role
Monitor device enrollment

Use Intune admin center Use Azure (Entra) portal

• Information about the individual devices • Intune admin center only shows enrolled devices
• How many devices are using the different • Azure-AD (Entra ID) joined devices
platforms, including Windows, Android
and iOS • Device settings
• Configure Enterprise state roaming
• Audit Logs
Manage devices remotely

• Perform remote device actions


– Such as Retire, Wipe, Delete, Remote lock, Restart, Sync, Quick Scan and Full Scan, etc.
• Available actions depend on device platform and configuration of the
device.
• Manage and monitor device information
– Hardware
– Discovered apps
– Device Compliance policies
– Device Configuration policies
[Link] configuration and compliance

• Protect access to resources using Intune


• Explore device compliance policy
• Deploy a device compliance policy
• Explore conditional access
• Create conditional access policies
Protect access to resources using Intune

• Allow access to e-mail and documents only from devices that are managed by MDM and comply with
company policy, such as by specifying that user passwords must be complex, local data on devices
must be encrypted, the use of multi-factor authentication (MFA), and the latest updates are installed.
• Define company policies by using the Device Security policy in Microsoft 365 or Device Compliance in
Intune.
• Use Conditional Access policies to control access to e-mail, documents, and other cloud apps as well as
evaluate sign-in risk, device type, location, and client apps.
• If a device isn't enrolled to Intune, its compliance can’t be evaluated, but you can prevent access to
mailboxes, documents, and cloud apps from such devices.
Explore device compliance policy

• Consists of rules that include:


– Password settings
– Encryption settings
– Jail-broken or rooted devices
– The min/max operating-system version
– The maximum Mobile Threat Defense level
• Device compliance policies can be used with or without conditional access
• Deployed based on the user, not on the device
• Monitored from the Device Compliance Dashboard
• Noncompliant actions:
– Notify end users via email
– Mark device noncompliant
Deploy a device
compliance policy
Device compliance policy prerequisites:
• Licensed for Azure AD (Entra ID) Premium P1 or
Azure AD (Entra ID) Premium P2 and Intune
• Devices run on a supported platform
• Devices must be enrolled in Intune

Define general compliance settings


• Enable marked devices with no policy assigned
• Enhanced jailbreak detection
• Compliance status for devices that do not report

You can deploy compliance policy to


users in user groups or devices in device
groups.
Explore conditional access

• Provides policy-based granular access to resources


• Allows users to work from essentially anywhere on most devices while helping to maintain security
• Requires Intune and Azure AD (Entra ID) for mobile devices
• Guides the user through fixing a denied access request
• Common scenarios for conditional access are:
– Conditional access based on app
– Conditional access based on network
– Conditional access based on device trust
Create conditional access policies

• You use conditions and controls to create conditional access policies.


• Conditions can be based on the:
– Device platform that is accessing the data
– Location from where the data is being accessed
– Client applications that are used to access the data
• Controls include:
– Blocking access
– Granting access if one or more additional requirements are met
• Configure conditional access from the Intune console in the Microsoft Intune admin
center, including more granular control such as:
– Allow or block certain platforms
– Immediately block devices that are not managed by Intune
Generate inventory and compliance reports

• Report enrolled devices inventory in Intune


• Monitor and report device compliance
• Build custom Intune inventory reports
Report enrolled devices inventory in Intune

You can download reports (csv format) for For richer reports:
all your devices and applications within the
• Use Intune Data Warehouse and Power BI
Intune Portal
• Microsoft Graph API lets you access all
You can also download Audit logs which Intune data
provide a record of activities that generate a – Create reports using Power BI or Excel based
change in Intune. on the data
– Microsoft Graph also enables you to script
almost everything in Azure AD (Entra ID)
and Intune
Monitor and report device compliance

You can perform


basic device
monitoring
in Intune
Device Compliance
• Summary and
aggregate views
• Select filters and define
search criteria
• View individual devices
• View device compliance
trends over time
Build custom Intune inventory reports

Intune Data Warehouse


stores Intune historical data

Use Power BI to load data


and generate reports.
Import Power BI file
Connect to data using
Data link.
Use the Power BI Intune
Compliance app
Uses the web version of
Power BI and allows for
customization and sharing
of pre-configured reports
focused on device
compliance reporting
Mobile Device Management (MDM)
• Configuring features built into the device, like enabling Bluetooth and preventing automatic
connections to Wi-Fi hotspots
• Securing the devices and preventing unauthorized access to organization resources from the
devices, like using mobile threat defense and encrypting hard disks
• Creating compliance rules that maintain device integrity, like setting a minimum OS version and
preventing simple passwords
• Being responsible for organization owned devices and personally owned devices that access your
organization resources
Explore Intune device profiles

Microsoft Intune includes settings and features that you can enable or
disable on different devices within your organization

Administrative templates Endpoint protection


Certificates Identity protection
Device features – iOS and macOS Kiosk
Device restrictions VPN
Edition upgrade and mode switch Wi-Fi
Email Custom profile
MDM deployment strategies
Set up Intune

• Confirm your devices are supported, create your Intune tenant, add
users & groups, assign licenses.
• This step focuses on setting up Intune and getting it ready for you to
manage your user identities, apps, and devices. Intune uses many
features in Microsoft Entra ID, including your domain, your users, and
your groups.
Add and protect apps

• Create a baseline of apps that devices must have, and then assign
these app policies during enrollment of the devices.
• On apps that need extra security, also use app protection policies.

• Before users enroll their devices, you can use Intune to assign these
apps to their devices. During enrollment, the app policies are
automatically deployed. When enrollment completes, the apps install
and are ready to use.
Use compliance and Conditional Access

• Create a baseline of compliance policies that devices must have, and


then assign these compliance policies during enrollment.
• Enable Conditional Access to enforce your compliance policies.

• When users enroll their devices in Intune, the enrollment process can
automatically deploy your compliance policies. When enrollment
completes, admins can check the compliance status and get a list of
devices that don't meet your rules.
Configure device features and
settings
• Create baseline of security features and device features that should
be enabled or blocked. Assign these profiles during enrollment.

• These settings are added to device configuration and endpoint


security profiles. Microsoft recommends you assign key security and
device configuration policies during enrollment. When enrollment
starts, the device configuration profiles are automatically assigned.
Enroll your device
• To fully manage devices, the devices must be enrolled in Intune to
receive the compliance & Conditional Access policies, app policies,
device configuration policies, and security policies you create. As an
admin, you create enrollment policies for your users and devices.
Each device platform (Android, iOS/iPadOS, Linux, macOS, and
Windows) has different enrollment options. You choose what's best
for your environment, your scenarios, and how your devices are used.
• Depending on the enrollment option you choose, users can enroll
themselves. Or, you can automate enrollment so users only need to
sign in to the device with their organization account.
Summary
• In this module we discuss about Intune overview, subscription and
setting Intune.
• Discussed about enrolling different devices
• Configuring compliance and device policies
• Mobile Device Management (MDM) and MDM deployment
strategies

You might also like