Cloud-Native Endpoint Deployment with Microsoft Intune

Cloud-Native Endpoint Deployment with Microsoft Intune

You plan to migrate to Intune? Then do this Cloud Native! Use the chance and get rid of your on-premises environment, maintenance of the infrastructure and move this responsibility to Microsoft. In this blog I want to explain what cloud native is and what Intune provides you to make your journey to a success. If you want to validate the provisioning part first, start with a Windows Autopilot test lab.

Cloud native endpoint deployment with Intune
Read More »
Automate Local Admin Rights Removal with Privilege Manager

Automate Local Admin Rights Removal with Privilege Manager

This is the second guest post from my partner Recast Software. 
Imagine reducing 90% of critical security vulnerabilities with a single change to your IT policy. Removing local admin rights can achieve this. IT departments face a constant influx of tickets and issues to manage. Many of these result from a need to elevate permissions, perhaps to update a piece of software or access a resource. The old way of getting around this issue was to give end users local admin permissions on their device. I know many of you are cringing just reading that—so am I. There are many, many reasons not to give end-users local admin permissions. The risks associated with local admin rights greatly outweigh the benefit of fewer tickets from end-users.

Read More »
Reenrol devices without wipe

Reenrol devices without wipe

Enrolled Intune devices occasionally face trust issues due to MDM or Microsoft Azure certificate problems, among other factors. While wiping and re-enrolling is a standard fix, it’s straightforward for regular devices, with minimal data loss thanks to services like OneDrive. However, this process is more complex for specialized field devices, particularly those with custom configurations and vendor-installed software, especially if the vendor no longer exists. Creative strategies are essential in these cases. This blog post delves into an experimental approach to seamlessly bring such devices back under management.

Reenrol devices without wipe
Read More »
New Version of the intune group assignment script

New Intune Group Assignment Script (Updated)

This post introduces the new and Updated Intune Group Assignment Script. The original was useful but limited; the New version of the Intune Group Assignment Script supports dynamic groups, scope tags, exclusion assignments, and a much cleaner CLI for use in pipelines.

A few months ago I released a script which lists you all assignments of a Microsoft Entra ID group in intune. With this blog post I will release a new version of this script which includes more configuration objects and improves a lot of the code parts.

New Version of the intune group assignment script
Read More »
Get started with Intune driver update management

Intune Driver Update Management — Quick Start

This is a quick start guide to Intune driver update management — the policy class that finally gives endpoint admins a controllable, transparent way to roll driver updates across a fleet of Windows devices. From profile creation to ring-based deployment, in under 30 minutes.

Many Intune admins have been waiting for the Intune driver update management feature. Now it is here. In this blog post I want to describe what’s behind this feature, how it works, and how you can get started with it.

Get started with Intune driver update management
Read More »
Tracking Windows 11 Upgrades with Azure Automation and Intune

Tracking Windows 11 Upgrades with Azure Automation and Intune

In today’s blog, I will address a question from one of our community members, who is looking to create a report for tracking Windows 11 upgrades via Azure Automation Runbook and Microsoft Intune. He has tried to gather enrolled devices details using a runbook but hasn’t found a solution yet. In this post, we will demonstrate how to generate a report on Windows 11 upgrade tracking with Intune and Azure Automation.

Tracking Windows 11 Upgrades with Azure Automation and Intune
Read More »