This video will explain information on how to onboard windows 10 devices into Microsoft Defender portal with Microsoft Intune.
Hope you enjoyed this video !!
Diversified Cloud Spot
This video will explain information on how to onboard windows 10 devices into Microsoft Defender portal with Microsoft Intune.
Hope you enjoyed this video !!
Microsoft has invested a lot of new upgrades in end point security in the last few of years. We can use Intune endpoint security policies for account protection to safeguard users’ identities and accounts, as well as control device built-in group memberships. In the end point security policies we can do the account protection and we will have a look at the settings in this article
To get started navigate to endpoint security and click on account protection. Here we have the opportunity to create an account protection policy.
When creating the new policy at the time of writing this blog we have option to create the policy for the platform Windows 10 and later. And the profile is targeted for two profiles local user group membership or account protection which is in preview state at this moment.
When creating for local user group we have the below options where we can select administrators and other set of user groups as we see below.
Continue readingIn previous article we had a look at how to manage the Logitech Peripherals from the the LogiSync Portal. In a small scale deployment installing them manually from handful of devices will be an easier approach. However when we have more number of devices that needs this installation and if they are present in different locations sharing the local admin passwords to the local support might also be a bit risky approach.
If the devices are Azure AD joined and Intune registered in this case we can benefit the remote installation of this client via Microsoft Intune Apps. Logitech has provided option to install them remotely from an SCCM instance as well which might be beneficial if you have the device managed via SCCM. In this article we will run through the steps that we will be doing to install the LogiSync Agent from the Microsoft Intune.
As a first step we need to download the Windows Sync Provisioning Bundle by logging into https://sync.logitech.com System–>Bulk provisioning.
In our case we are choosing windows since we are attempting the automated agent installation via Microsoft Intune.
Now we can use PowerBI and use the Microsoft intune data warehouse to build reports for the entire organization to foresee the intune analytics and the status. PowerBI being a very potential platform for data gathering and analysis this intune data warehouse can help in terms of analyzing the Microsoft intune statistics and provide us the overall metrics.
When we look into the get data from the PowerBI desktop version, we do see the option Intune Data WareHouse Beta Preview connector. Once authenticated with the account we can select this connector
At this point of writing this blog , we could see that this connector is integrated with a 3rd party service as of now and it in the progress of full mature version and can expect more improvements in the future.
Continue readingMicrosoft Teams have been the highly adopted collaborative platform in few months time.It has been helping a ton worldwide and the new features that is been released every now and then makes us stay connected and expands the efficiency in every organization who have been using them.
By default Microsoft Certified Room systems are forward compatible with the new Skype for Business or Teams services while maintaining the same client user experience.Usually when any organization has only Skype then these meeting rooms will have the options only Skype enabled on them.
In this article we will be looking at how to enable the existing Skype room systems to have the capacity to host Teams Meetings in them.
Example screen of a Skype room system panel where we have the below options on the supported meeting mode while configuring them at the initial stage .
These devices are basically on KIOSK mode running on recommended versions of Windows 10 currently supported one being 1909 at the time of writing this blog.
Continue readingMicrosoft Teams being the best collaborative solution there are lots of supported smart devices which are equipped with Microsoft teams App for providing the smart meeting room systems with modern cameras, microphones and display screens. The nicest aspect of Teams room application is that it can function well in all ranges of supported devices as stated here with a support of basic hardware and running on a windows 10 IOT operating system running in appliance mode.
While there are numerous approaches to monitor the Microsoft Teams room systems this article we will go through the steps to monitor them through Azure Log Analytics.Like other applications Microsoft Teams App running on room devices will write all the events on the event logs.Through the Microsoft Monitoring agent in Microsoft Teams it allows these events to be collected in Azure log Analytics.
Prerequisites:
Since we are going to leverage Azure Log Analytics as a monitoring solution for our room systems the first step here is to Create Azure Log Analytics and integrate them with Microsoft windows agent.
Continue readingIn a huge enterprise scale deployments there will be various teams who handles the services with multiple administrator accounts.These executives must be furnished with administrator accounts which are appropriate to their boundaries.Microsoft intune being a device,apps and office 365 administration management there are high prospects that this element may be used over various departments,applications,devices and from various areas. Microsoft Intune having lots of features and capabilities now most of the organizations are moving as managed tenant with Microsoft intune.
For instance there can be multiple app protection policies, device compliance policies, app configuration policies ,etc., are created for multiple services one for meeting room management, another for BYOD devices and for corporate windows devices. In these situations we need to create customized role based access control for each users.
Continue readingThe Azure AD terms of use functionality have been recently upgraded. In this article we will have a look at configuring the Azure Azure AD terms of use functionality for Microsoft Intune while enrolling the devices.
Navigate to Terms of use at https://aka.ms/catou
Search for Conditional Access – Terms of Use – Click on terms of use – Select New Terms
Create a new terms of use. Here we have an option to upload our own company terms of use PDF. There is an option to choose the language format for the terms of use.
Continue readingMicrosoft intune is a cloud service which was introduced in office365. This intune service is charged per user license. It can be configured for cloud only users as well as hybrid users.
Intune can be used for end users end point protection, MDM ,MAM ,application distributed storage, software license inventory reports , hardware inventory reports , mobile device app publishing, security monitoring.
This blog focuses only on configuring the in tune MDM\MAM for cloud only users to secure the office 365 services configured in mobile devices.Using this we would be able to enroll Mobile devices, manage devices and applications, protect the corporate data and retire them when required.
First thing is to see the license required for intune to assign them to end users.
Get-MsolAccountSku
We need to see the MDM user Scope set in the azure portal.
By default it is not set to any users. We can create a group and assign the scope to the group. This will perform the MDM enrollment for Android, iOS devices.
Here we have three URL’s:
All the above options can be customized based or left blank based on the current MDM/MAM setup. If we are rolling out the MDM/MAM first time for all users then we can leave these url’s as default and can update only the terms of use and compliance url as per the company’s security policy.
Now we need to create below policies:
Create Device Compliance Policy-
We need to navigate to the https://portal.office.com – Admin – Select Microsoft Intune and navigate to intune blade
We need to create compliance policy for Android and IOS devices.Example below for Android where the minimum version is 7.1 and blocking rooted devices can be done.
Compliance policies conditions and actions can be created based on the requirement.
Create Configuration Policy:
Configuration policies can be created for Android, Android Enterprise and IOS in our case , since we are focusing only on configuring the MDM for mobile devices.
Example of creating one configuration policy for Android devices and restrictions that can be applied to secure corporate data like disable screen capture, copy paste.
App Protection Policy:.
The app protection policy can be used to protect and enforce policy only on selective apps. This helps the admins to control only the corporate data even on BYOD devices.
Targeted apps can be selected here we can select only required corporate apps.
We have policy settings which can be controlled for the apps installed on the mobile phone.
Example we have an option to choose which storage can be enforced to end users to save the data. These restrictions are applicable only for the targeted apps which we have selected in the previous section.
Further sign in security requirements can be controlled based on Device Manufacturers, Pin Attempts etc..,
Create Client Apps:
Also Intune Client apps can be assigned Android/IOS to end users through intune company portal.
Example one created for publishing VLC player in the Intune Company portal for Android Users.
Once applied end user can see this apps from the android device from the Intune Company Portal App.
Conditional Access Policy for MDM can be created like below:
Select apps – Create one only for Exchange Online
Login location can be set from where the user access can be controlled based on physical location.
Required approved client app only can be selected.
List of Intune enrolled devices can be seen.
When drill down further it would show all the installed apps in the discovered apps section.
Further we can see the device compliance status. In below case my device is compliant except for the password which i did not configure as per the password policy set for Android devices.
From the client side in Android device user needs to download the company portal to access all Intune features.
Notes: