Activate Mac FileVault using Intune

Activate Mac FileVault using Intune

Activate Mac FileVault using Intune

Encrypting the disk of a workspace is one of the basic settings that every managed device should have. Everyone who manages Windows PCs knows BitLocker. The solution that is integrated in macOS to encrypt disks is called FileVault. In this blog I want to explain you how to Activate Mac FileVault using Intune, step by step, so that every Mac in your fleet is encrypted automatically. By the end you will know exactly how to Activate Mac FileVault using Intune and how to retrieve the recovery key when you need it.

Read More » Activate Mac FileVault using Intune
Remove Windows 11 build-in teams app with Intune

Remove Windows 11 Built-in Teams App with Intune

Remove Windows 11 Built-in Teams App with Intune

Windows 11 ships with a consumer-flavoured Microsoft Teams app pre-installed, separate from the enterprise Teams client your organization actually deploys. For most managed fleets you’ll want exactly one Teams app on the device (the enterprise version), and the consumer one is at best confusing and at worst a support-ticket generator. The good news is that you can remove the built-in Teams app with Intune in a fully automated, repeatable way. This post walks through three options to clean it up: a one-line PowerShell remediation that uninstalls the consumer Teams package per-user, a configuration-profile approach that hides the Chat icon for new and existing profiles, and the tamper-resistant route for locked-down deployments.

A built-in Teams client is shipped with Windows 11. This client can only be used with a personal Microsoft account, so it is usually not welcome in corporate environments where the managed enterprise Teams client is the only one users should see. How to remove this built-in client with the help of Intune I will show you step by step in this blog post.

Read More » Remove Windows 11 Built-in Teams App with Intune
Add Azure AD Users and Groups to Local Groups with Intune

Add Microsoft Entra ID Users and Groups to Local Groups with Intune

Add Microsoft Entra ID Users and Groups to Local Groups with Intune

In this blog we will look at how you can add an Azure AD group to local group membership using Intune and custom profiles. Adding a Microsoft Entra ID (formerly Azure AD) group or user to a local group is one of the most common requests for endpoint admins who want to grant elevated rights without managing each device by hand. By the end of this guide you will be able to add an Azure AD group to local group membership on every managed Windows device in a fully automated, repeatable way.

Read More » Add Microsoft Entra ID Users and Groups to Local Groups with Intune