From ConfigMgr to Fully Intune Managed in 2024. Let’s Make That a Reality

If you have Config Manager today and if you are thinking or planning on moving the devices and the workloads to Intune, this article is for you. If you are in that state today, chances are you have a stable (or near stable) method of managing the devices, patch updates, and GPOs. Moving the capabilities … Continue reading From ConfigMgr to Fully Intune Managed in 2024. Let’s Make That a Reality

Adopting Microsoft Entra ID Governance – A Deep Dive

Lately, there has been a lot happened/ changed/ introduced in the Microsoft Entra ID Governance space and this is one of my favorite topics to write and explain as well. The main reason is that Entra ID Governance features are all interconnected and organizations can easily create an eco-system and start using its features. Not … Continue reading Adopting Microsoft Entra ID Governance – A Deep Dive

Quick Defender SmartScreen Deep Dive with Niklas Tinner

Recently I got the opportunity to sit with Niklas Tinner, a like-minded tech guru and an End User Computing specialist to discuss Defender SmartScreen and its benefits, advanced hunting for SmartScreen incidents, policies, and best practices. https://www.youtube.com/watch?v=YI_x_dtrSFQ And detailed blog post on the same can be found below. https://shehanperera.com/2022/12/14/defender-smartscreen-deep-dive-02/

How to Track Devices with a Faulty MDE Sensor Health State, Using a Logic App Workflow?

The MDE Sensor Health what we like to see is "Active". The sensor health we don't want is "Inactive" or "Misconfigured". But sometimes it is almost impossible to track the sensor status of all the devices every day so the devices will be all healthy. However, in order to properly communicate with Defender, the endpoint's … Continue reading How to Track Devices with a Faulty MDE Sensor Health State, Using a Logic App Workflow?

🔗IntuneMaps – Device Profile Templates

Going one step ahead from my previous IntuneMaps.com click-friendly infographic. For anyone who is starting out with Microsoft Intune or wants to know what templates to set up and why, I hope this will be helpful to understand what Intune's Windows-based (Windows 10 and later) built-in config profiles are and how to apply them.  Microsoft Learn can … Continue reading 🔗IntuneMaps – Device Profile Templates

4 Steps to Configure Azure AD PIM for Groups

Few uses of PIM-managed groupsChallengeSolutionFew NotesPrerequisites - LicensesStep 1 - Group CreationStep 2 - Onboard the group for PIMStep 3 - Add PIM AssignmentsStep 4 - Setup Role SettingsUser ActivationUse Access ReviewsWrapping Up When I 1st posted the below infographic in my Socials, I thought I made myself clear that this is not an Azure … Continue reading 4 Steps to Configure Azure AD PIM for Groups

Setup Prerequisites for Windows LAPS in Azure AD

By now you may have seen a lot of updates and posts on how to configure Windows LAPS in Azure AD. Credit goes to all the wonderful gurus out there who really contribute to the community in different ways. My approach in this post is to prepare for the Windows LAPS in Azure AD so … Continue reading Setup Prerequisites for Windows LAPS in Azure AD

🔗IntuneMaps

This is a small passion project of mine.Microsoft Intune has evolved like never before and continues to add more features as we speak. I always wanted to create a one-stop location for all things Intune Windows Platform that can be helpful to anyone who is starting out with the product, looking for the right Learn … Continue reading 🔗IntuneMaps

Mergers, Acquisitions and Day 1 – Entra ID Cross-Tenant Synchronization

I would like to dedicate this post to writing something on a much-needed topic that personally got me to try a lot of methods and to be creative because this is one of the main tasks that an organization/ management is looking to get done from an IT Specialist. The Day 1. More precisely the … Continue reading Mergers, Acquisitions and Day 1 – Entra ID Cross-Tenant Synchronization

Use Authentication Context with Strong Auth on PIM Role Activation

What is Authentication Context? Authentication Contexts are being used to further secure your application data and actions. You may already have enabled Multi-Factor Authebtaion in your Azure AD tenant and everyone is using the MFA in the same way. However, imagine you have an application where you need to maintain confidential data that only a … Continue reading Use Authentication Context with Strong Auth on PIM Role Activation

BYOD – Part 2 – Manage Your Azure AD Registered Devices

Previously on BYOD... I discussed the restrictions and conditions you can make so the BYOD fleet can be managed well. Read below if you haven’t. My focus was the Azure AD and Intune side of things when it comes to managing the fleet. https://shehanperera.com/2023/01/26/byod-01/ However, part 2 of this series is focusing on the scenario … Continue reading BYOD – Part 2 – Manage Your Azure AD Registered Devices

BYOD – Part 1 – The Love-Hate Relationship

This is a 2 part series and I would like to get to the nitty gritty of BYOD because as IT Pros or leaders who are managing IT in an organization, we have dealt with BYOD (Bring Your Own Device) related questions at least once in our career. Not once, but maybe daily or maybe … Continue reading BYOD – Part 1 – The Love-Hate Relationship

It’s 2023. Let’s Talk About Azure AD Connect Cloud Sync

The first post for 2023 and I thought I want to focus on something that will take over the main stage soon (probably). Azure AD Connect Cloud Sync. This has been there for a while and its capabilities (some capabilities) are proven to minimize that admin overhead and if you have dealt with the Azure … Continue reading It’s 2023. Let’s Talk About Azure AD Connect Cloud Sync

Microsoft Intune Bulk Device Actions

This will be a short blog post, but I want to cover something that is important when you have a large device fleet. This is a useful feature if you haven't seen it yet or not tried it yet, because rather than using a CLI, you can use the Intune Portal to perform bulk actions. … Continue reading Microsoft Intune Bulk Device Actions

Azure AD Cross-Tenant Access with B2B Direct Connect

This is my take on the Azure AD Cross-Tenant access settings. This was something I was hoping to configure a while back. However the capabilities weren't available at that time, but the need for some kind of a trust relationship between two Azure AD tenants was bubbling up. Gone of days organizations set up trust … Continue reading Azure AD Cross-Tenant Access with B2B Direct Connect

Microsoft Defender SmartScreen Deep Dive

Microsoft Defender SmartScreen is the frontline defense against all threats. Did I put that right? It truly is the frontline protector in the Windows computer and the Edge browser on any OS platform. I've been dealing with a lot of SmartScreen configuration tasks, and troubleshooting scenarios when working with customers and I wanted to write … Continue reading Microsoft Defender SmartScreen Deep Dive

How to Plan for a Windows 365 Cloud PC Deployment?

In my 1st blog post related to Windows 365, I discussed how to get started with the product. This is post #2 of the series and in this, I want to discuss what to think when planning for your Windows 365 deployment and especially how to set up RBAC. Before jumping into the technical side … Continue reading How to Plan for a Windows 365 Cloud PC Deployment?