How to Change Intune Security Baseline Policy to Version 23H2?

I'm excited to see the new Security Baseline version is finally available in Intune. Version 23H2 for Windows 10/11. This is a quick look at the policy and useful details on migration to the new policy. What you will see in the Security Baselines nowWhat's Available in Version 23H2Some Notable SettingsMigrating from an older BaselineIf … Continue reading How to Change Intune Security Baseline Policy to Version 23H2?

How to Use Intune to Create a Dell BIOS Config Profile?

Creating BIOS Configs and ingesting it during the imaging process is a tad bit old school when you think about moving to newer technologies that can do the same. Microsoft Intune recently introduced the BIOS Config Profile as a template in Intune. At this stage, DELL devices can be set up with this. At the … Continue reading How to Use Intune to Create a Dell BIOS Config Profile?

Control Device Code Flow With Entra ID Conditional Access Policies

With the latest developments in Entra ID Protection space, Conditional Access Policies got a bit of a facelift with the Authentication Flow control feature. Still, in Preview, Device Code Flow and Authentication Transfer are the features introduced with the Authentication Flows. I want to cover the Authentication Transfer process in a different article so this … Continue reading Control Device Code Flow With Entra ID Conditional Access Policies

Why Does Group Policy Analytics Matter In Microsoft Intune?

"We never know what that GPO really does", and "The person who created this GPO is not in the business anymore". Sounds familiar? Most of the businesses that have a Microsoft ecosystem and who have been using AD/ GPO for a long time always have stories to tell about the Group Policies. This blog is … Continue reading Why Does Group Policy Analytics Matter In Microsoft Intune?

5 Practical Usages of PIM for Groups Explained

I have always been a huge advocate of Entra ID Governance and its usage. It is paramount to make sure the Identity Governance health is in a good position while applying the best practices because Identity is an attack vector, period. Once a bad actor gets hold of the identity, accessing confidential data, Azure resources, … Continue reading 5 Practical Usages of PIM for Groups Explained

Microsoft Intune Enterprise App Catalog is Here!

As announced in Microsoft Ignite 2023, the latest addition to the Intune Suite features the Enterprise Application Management and it's Enterprise App Catalog is finally GA as of today. This will remove a lot of hassle that the Device Management Admins need to go through in re-packaging apps in to a .intunewin file and adding … Continue reading Microsoft Intune Enterprise App Catalog is Here!

How a Synthetic Registration in Entra ID Can Protect the Devices ASAP with Defender for Endpoint?

One of the popular queries I have got by working with many customers for their Defender for Endpoint deployment projects is We need the Defender Security Policies to be assigned and working as soon as the device is onboarded to MDE.Having Onboarded to MDE, if and when Intune enrollment and Device Registration in Entra ID … Continue reading How a Synthetic Registration in Entra ID Can Protect the Devices ASAP with Defender for Endpoint?

Device Hardening with Intune Security Baseline for Windows Policy

The word on the street is not "If I get hacked" but "when I will get hacked" and securing your infrastructure starts from your end users and devices and hardening those devices that the users use every day has never been so important. Security Baseline policy for Windows 10 and later. This is one of … Continue reading Device Hardening with Intune Security Baseline for Windows Policy

From ConfigMgr to Fully Intune Managed in 2024. Let’s Make That a Reality

If you have Config Manager today and if you are thinking or planning on moving the devices and the workloads to Intune, this article is for you. If you are in that state today, chances are you have a stable (or near stable) method of managing the devices, patch updates, and GPOs. Moving the capabilities … Continue reading From ConfigMgr to Fully Intune Managed in 2024. Let’s Make That a Reality

Adopting Microsoft Entra ID Governance – A Deep Dive

Lately, there has been a lot happened/ changed/ introduced in the Microsoft Entra ID Governance space and this is one of my favorite topics to write and explain as well. The main reason is that Entra ID Governance features are all interconnected and organizations can easily create an eco-system and start using its features. Not … Continue reading Adopting Microsoft Entra ID Governance – A Deep Dive

6. Windows Autopatch – Release Management, Reports and Notifications

In this last section, I want to discuss Release Management, Reports, and Email and Message notifications. These are all must-know sections when you are planning on deploying Autopatch. Release ManagementWhere to find this?Windows Feature Management explainedRelease StatusesPhase StatusesRelease AnnouncementsRelease SettingsAutopatch GroupsPlanning for a New Release (Custom Release)Setting the Release PhaseNotifications - Email and Portal MessagesQuality … Continue reading 6. Windows Autopatch – Release Management, Reports and Notifications

5. Windows Autopatch – Entra ID Groups, and Policies

In this section I would like to deep dive on few things that is getting created as a part of the Tenant Enrollment. The good thing about this is that your Autopatch environment will be ready for you and ready to go when you enrolled it. Entra ID groups, Update Rings and Policies. Microsoft Learn … Continue reading 5. Windows Autopatch – Entra ID Groups, and Policies

4. Tenant Enrollment and Device Registration in Windows Autopatch

Tenant Enrollment for Windows Autopatch For the next steps of getting Autopatch to work, let's check the tenant Enrollment. Now that you have setup the prerequisites and other requirements, the enrollment will be pretty much following the bouncing ball type task. Path to enable Windows Autopatch Intune Portal > Tenant Administration > Tenant Enrollment (under … Continue reading 4. Tenant Enrollment and Device Registration in Windows Autopatch

3. Windows Autopatch Device Readiness

Existing GPOs, Registry Settings, Config Manager and MDM Settings In this section, I would like to go through some important changes required in your environment before moving to Widows Autopatch. Ideally, this comes in step 3 of the development journey - Pilot. With everything in place, you may have selected the devices that need to … Continue reading 3. Windows Autopatch Device Readiness

2. Setting up Prerequisites for Windows Autopatch

Windows Autopatch Guide Blog 2 of 7 In this section, I will look at the prerequisites that need to be setup in order to carry out a successful Windows Autopatch implementation. Minimum Windows OS Version (at the time of writing)RBAC SetupLicenses for AutopatchNetwork ConfigurationDevice ManagementWrapping Up Minimum Windows OS Version (at the time of writing) … Continue reading 2. Setting up Prerequisites for Windows Autopatch

Quick Defender SmartScreen Deep Dive with Niklas Tinner

Recently I got the opportunity to sit with Niklas Tinner, a like-minded tech guru and an End User Computing specialist to discuss Defender SmartScreen and its benefits, advanced hunting for SmartScreen incidents, policies, and best practices. https://www.youtube.com/watch?v=YI_x_dtrSFQ And detailed blog post on the same can be found below. https://shehanperera.com/2022/12/14/defender-smartscreen-deep-dive-02/

How to Track Devices with a Faulty MDE Sensor Health State, Using a Logic App Workflow?

The MDE Sensor Health what we like to see is "Active". The sensor health we don't want is "Inactive" or "Misconfigured". But sometimes it is almost impossible to track the sensor status of all the devices every day so the devices will be all healthy. However, in order to properly communicate with Defender, the endpoint's … Continue reading How to Track Devices with a Faulty MDE Sensor Health State, Using a Logic App Workflow?

🔗IntuneMaps – Device Profile Templates

Going one step ahead from my previous IntuneMaps.com click-friendly infographic. For anyone who is starting out with Microsoft Intune or wants to know what templates to set up and why, I hope this will be helpful to understand what Intune's Windows-based (Windows 10 and later) built-in config profiles are and how to apply them.  Microsoft Learn can … Continue reading 🔗IntuneMaps – Device Profile Templates