Microsoft Intune Device Management: Deep Dive

Comprehensive guide to managing Windows, Android, and iOS devices using Microsoft Intune.

Microsoft Intune Devices & Groups

Devices

Devices in Intune represent all managed endpoints, including desktops, laptops, phones, and tablets (Windows, Android, iOS/iPadOS, macOS). [cite: Microsoft Intune Documentation]

What are Groups in Intune?

In Intune, Groups are logical groupings of users or devices. [cite: Microsoft Intune Documentation] They are essential for targeting policies and applications.

How Groups Work

Group Type Description
Assigned Groups Manually add specific users or devices. Membership is static until manually changed.
Dynamic Groups Automatically include members based on defined rules (queries). Membership updates dynamically.

Step-by-Step: Create a Dynamic Device Group

  1. Open Microsoft Intune Admin Center: endpoint.microsoft.com
  2. Navigate to Groups → Click + New group
  3. Basics Tab:
    • Group type: Security or Microsoft 365
    • Group name: Windows 10 Devices
    • Membership type: Dynamic Device
  4. Dynamic membership rules Tab: Click + Add dynamic query
    • Rule syntax: All or Any (for multiple rules)
    • Add expression:
      • Property: operatingSystem
      • Operator: Equals
      • Value: Windows

      Click + Add expression again:
      • Property: operatingSystemVersion
      • Operator: StartsWith
      • Value: 10.0
  5. Click Save. The group membership will update automatically based on the rule.

Create a Dynamic User Group

  1. Go to: Groups → Click + New group
  2. Group type: Security or Microsoft 365
  3. Group name: Marketing Department Users
  4. Membership type: Dynamic User
  5. Dynamic membership rules Tab: Click + Add dynamic query
    • Rule syntax: All
    • Add expression:
      • Property: department
      • Operator: Equals
      • Value: Marketing
  6. Click Save. The group membership will update automatically based on the rule.

Example: iOS Devices Query

  (device.operatingSystem -eq "iPhone" -or device.operatingSystem -eq "iPad")
      

Best Practices

Common Issues & Troubleshooting

Issue Resolution
Group membership not updating Verify the dynamic group rule syntax and device/user attributes. Allow some time for synchronization.
Device/user not in the expected group Review the dynamic group rule to ensure it accurately captures the desired criteria.
Slow dynamic group updates Simplify complex dynamic group rules.
Unable to add members to assigned group Ensure the user or device exists in Azure AD and is not already a member.

Bonus Tips

← Hide Details

Microsoft Intune Device Enrollment: Detailed Steps

Enrollment Overview

Device Enrollment is the foundational process for managing devices with Microsoft Intune. The specific steps vary significantly based on the device's operating system (Windows, Android, iOS/iPadOS, macOS) and its ownership model (corporate-owned or Bring Your Own Device - BYOD). Understanding these nuances is key to a successful deployment. [cite: Microsoft Intune Documentation]

Detailed Enrollment Methods and Steps by Platform

Windows Enrollment

Corporate-Owned
  1. Azure AD Join:
    • Prerequisites: Azure AD tenant, devices may need to be pre-registered in Azure AD. Auto-enrollment for Intune should be configured in Azure AD.
    • Step 1 (During OOBE): On a new device or after a reset, during the initial setup (Out-of-Box Experience), the user selects "Set up for work or school."
    • Step 2 (Authentication): The user signs in with their corporate Azure AD credentials.
    • Step 3 (Automatic Enrollment): If auto-enrollment is configured, the device automatically registers with Intune.
    • Step 4 (Policy Application): Intune policies and configurations begin to apply to the device.
  2. Hybrid Azure AD Join:
    • Prerequisites: Azure AD Connect synchronizing on-premises Active Directory with Azure AD, devices domain-joined to on-premises AD, Intune auto-enrollment configured for targeted users.
    • Step 1 (Domain Join): The device is joined to the on-premises Active Directory domain.
    • Step 2 (Azure AD Registration): The device registers with Azure AD (this can happen automatically or via Group Policy).
    • Step 3 (Automatic Enrollment): If auto-enrollment is configured for the signed-in user, the device enrolls in Intune.
    • Step 4 (Policy Application): Intune policies and configurations are applied.
  3. Windows Autopilot:
    • Prerequisites: Azure AD Premium, Intune subscription, devices registered in Intune (hardware hashes uploaded), Autopilot deployment profile created and assigned to an Azure AD group.
    • Step 1 (Device Boot-up): The device is powered on and connected to the internet.
    • Step 2 (Autopilot Profile Download): The device identifies itself and downloads its assigned Autopilot deployment profile from the Autopilot service.
    • Step 3 (Provisioning): The device is automatically joined to Azure AD (or Hybrid Azure AD), enrolled in Intune, and configured according to the profile.
    • Step 4 (User Sign-in): The user signs in, and the device is ready for use with applied policies and apps.
  4. Bulk Enrollment (Provisioning Packages):
    • Prerequisites: Windows Configuration Designer (WCD) tool installed, provisioning package created with enrollment settings.
    • Step 1 (Package Creation): An IT admin uses WCD to create a provisioning package containing the Azure AD bulk enrollment token and optional configurations/apps.
    • Step 2 (Package Application): The provisioning package is applied to devices via USB drive during the OOBE or on existing devices.
    • Step 3 (Enrollment): The device uses the bulk enrollment token to join Azure AD and enroll in Intune without individual user credentials during this phase.
    • Step 4 (User Association): Once enrolled, users sign in with their Azure AD accounts, and user-targeted policies apply.
Bring Your Own Device (BYOD)
  1. User Enrollment:
    • Prerequisites: Intune configured for user enrollment.
    • Step 1 (Company Portal Installation): The user downloads and installs the Microsoft Intune Company Portal app from the Microsoft Store or a web browser.
    • Step 2 (Sign-in): The user signs in to the Company Portal app with their corporate Azure AD credentials.
    • Step 3 (Enrollment Initiation): The user follows the prompts within the Company Portal to begin the enrollment process. This typically involves agreeing to organizational policies.
    • Step 4 (Workplace Join - Optional): In some scenarios, the device might also be Workplace Joined to Azure AD, providing SSO and basic access control.
    • Step 5 (Policy Application): Intune policies targeted to the user are applied to the device.
  2. Workplace Join (Limited Management):
    • Prerequisites: Azure AD enabled for Workplace Join.
    • Step 1 (Initiate Join): The user goes to Settings > Accounts > Access work or school > Connect and chooses "Join this device to Azure Active Directory."
    • Step 2 (Sign-in): The user signs in with their corporate Azure AD credentials.
    • Step 3 (Join Completion): The device is registered with Azure AD, enabling SSO and basic access control. This method provides limited management capabilities compared to full Intune enrollment.

Android Enrollment

Corporate-Owned
  1. Android Enterprise (Dedicated Devices):
    • Prerequisites: Intune connected to Managed Google Play, enrollment profile for Dedicated Devices created.
    • Step 1 (Factory Reset): The device is typically factory reset.
    • Step 2 (Enrollment Initiation): During setup, the user enters a specific enrollment token or scans a QR code provided by the IT admin.
    • Step 3 (Device Provisioning): The device enrolls in Intune as a fully managed, kiosk-style device.
    • Step 4 (Policy and App Deployment): Intune policies and required apps are automatically deployed.
  2. Android Enterprise (Fully Managed):
    • Prerequisites: Intune connected to Managed Google Play, enrollment profile for Fully Managed devices created.
    • Step 1 (Factory Reset): The device is typically factory reset.
    • Step 2 (Enrollment Initiation): During setup, the user enters "afw#setup" or scans a QR code to initiate Android Enterprise enrollment.
    • Step 3 (Account Sign-in): The user signs in with their Managed Google Play account (often provisioned by the organization).
    • Step 4 (Device Management): The device is fully managed by Intune.
    • Step 5 (Policy and App Deployment): Intune policies and apps are deployed.
  3. Android Enterprise (Corporate-Owned Work Profile):
    • Prerequisites: Intune connected to Managed Google Play, enrollment profile for Corporate-Owned Work Profile devices created.
    • Step 1 (Enrollment via Company Portal): The user installs and opens the Company Portal app.
    • Step 2 (Sign-in): The user signs in with their corporate Azure AD account.
    • Step 3 (Work Profile Creation): The Company Portal guides the user through creating a separate work profile on the device.
    • Step 4 (Management): Intune manages the apps and data within the work profile.
  4. Zero-Touch Enrollment:
    • Prerequisites: Devices purchased through a participating reseller and configured in the Zero-Touch portal, Intune connected to Managed Google Play, enrollment profile created.
    • Step 1 (Device Boot-up): The device automatically enrolls in Intune during the initial setup without user interaction beyond connecting to Wi-Fi.
    • Step 2 (Provisioning): The device is provisioned according to the configured Intune profile.
  5. Samsung Knox Mobile Enrollment:
    • Prerequisites: Samsung Knox devices, Knox Mobile Enrollment portal configured and linked with Intune, enrollment profile created in Intune.
    • Step 1 (Device Boot-up): The device connects to the internet and contacts the Knox Mobile Enrollment service.
    • Step 2 (Profile Download): The device downloads its Intune enrollment profile.
    • Step 3 (Automatic Enrollment): The device automatically enrolls in Intune.
Bring Your Own Device (BYOD)
  1. Android Enterprise (Personal Work Profile): (Steps are similar to Corporate-Owned Work Profile)
    • User installs and opens the Company Portal app, signs in, and follows prompts to create a work profile. Intune manages only the work profile.
  2. Device Administrator (Legacy):
    • Note: This is a legacy method with reduced security and functionality. Android Enterprise is the recommended approach.
    • Step 1 (Company Portal Installation): User installs and opens the Company Portal app.
    • Step 2 (Sign-in): User signs in with their corporate Azure AD account.
    • Step 3 (Device Admin Activation): User grants Device Administrator permissions to the Company Portal.
    • Step 4 (Policy Application): Intune policies are applied to the entire device.

iOS/iPadOS Enrollment

Corporate-Owned
  1. Automated Device Enrollment (ADE) via ABM/ASM:
    • Prerequisites: ABM/ASM account linked with Intune, ADE enrollment profile created and assigned to devices in ABM/ASM.
    • Step 1 (Device Activation): When the device is activated and connected to the internet, it contacts Apple's activation servers.
    • Step 2 (MDM Profile Download): Apple's servers redirect the device to Intune to download the MDM enrollment profile.
    • Step 3 (Automatic Enrollment): The device automatically enrolls in Intune (depending on the profile configuration, user interaction might be minimal or skipped).
    • Step 4 (Supervision - Optional): Devices can be set to supervised mode for enhanced management capabilities.
  2. Apple Configurator (USB-based Enrollment):
    • Prerequisites: Apple Configurator 2 installed on a Mac, devices connected via USB.
    • Step 1 (Profile Creation): An MDM server (Intune) is prepared in Apple Configurator 2.
    • Step 2 (Device Preparation): Devices are connected to the Mac, and the Intune enrollment profile is applied via USB.
    • Step 3 (Enrollment): The devices are enrolled in Intune. This method is typically used for devices not purchased through ABM/ASM.
Bring Your Own Device (BYOD)
  1. User Enrollment (with Managed Apple IDs):
    • Prerequisites: Managed Apple IDs provisioned in ABM/ASM, User Enrollment configured in Intune.
    • Step 1 (Initiate Enrollment): The user navigates to Settings > General > VPN & Device Management > Sign in to Work or School Account.
    • Step 2 (Managed Apple ID Sign-in): The user signs in with their Managed Apple ID.
    • Step 3 (Enrollment Profile Download): An enrollment profile is downloaded and installed.
    • Step 4 (Management): Intune manages a separate partition for work data.
  2. Device Enrollment (Legacy):
    • Note: This is a legacy method. User Enrollment is the recommended approach for BYOD iOS/iPadOS.
    • Step 1 (Company Portal Installation): User installs the Company Portal app from the App Store.
    • Step 2 (Profile Installation): User signs in and is guided to download and install an MDM enrollment profile from Intune via Safari.
    • Step 3 (Trust Profile): User trusts the downloaded profile in Settings.
    • Step 4 (Enrollment Completion): The device is enrolled in Intune.

macOS Enrollment

Corporate-Owned
  1. Automated Device Enrollment (ADE) via ABM/ASM: (Steps are similar to iOS/iPadOS ADE)
    • Devices purchased through ABM/ASM can be automatically enrolled during setup.
  2. Direct Enrollment (via Company Portal or Setup Assistant):
    • Prerequisites: Devices prepared for enrollment.
    • Step 1 (Company Portal): User downloads and installs the Company Portal app and follows the enrollment prompts.
    • Step 1 (Setup Assistant): During the macOS Setup Assistant, the user can enroll in MDM by authenticating with their corporate credentials. This often requires a предварительно настроенный профиль MDM.
Bring Your Own Device (BYOD)
  1. Device Enrollment (via Company Portal): (Steps are similar to corporate-owned direct enrollment via Company Portal)
    • User downloads and installs the Company Portal app and follows the enrollment prompts.
  2. User Enrollment (with Managed Apple IDs): (Steps are similar to iOS/iPadOS User Enrollment)
    • User enrolls via System Settings > Privacy & Security > Profiles.

Best Practices for Enrollment (Reiterated)

Common Enrollment Issues & Troubleshooting (Reiterated)

IssueTroubleshooting Steps
Enrollment fails with errorsCheck logs, network, prerequisites, licensing.
Devices not appearing in IntuneVerify registration, profile assignment, network, force sync.
BYOD issuesVerify user enrollment settings, Company Portal, enrollment restrictions.
ADE issuesCheck ABM/ASM token, profile assignment, network, device setup logs.
Hybrid Azure AD Join failuresVerify AAD Connect, hybrid join status, device registration.

Further Resources (Reiterated)

← Hide Details

Microsoft Intune Policy Implementation

Policy Types in Intune

Microsoft Intune uses various policy types to manage and secure devices and applications. Understanding these types is crucial for effective endpoint management. [cite: Microsoft Intune Documentation]

Configuration Profiles (MDM Policies)

Configuration Profiles allow you to configure settings on managed devices. The available settings vary by platform. [cite: Microsoft Intune Documentation]

App Protection Policies (MAM Policies)

App Protection Policies (APP) manage and protect your organization's data within applications on both managed and unmanaged devices. [cite: Microsoft Intune Documentation]

Compliance Policies

Compliance Policies define the rules that devices and users must meet to be considered compliant with your organization's security standards. [cite: Microsoft Intune Documentation]

Security Baselines

Security Baselines are pre-configured groups of settings that help you enforce a known security configuration. Intune includes baselines for various Microsoft products. [cite: Microsoft Intune Documentation]

Endpoint Security Policies

Endpoint Security Policies provide dedicated settings for managing security features on your endpoints. [cite: Microsoft Intune Documentation]

Step-by-Step: Create a Windows 10 Configuration Profile

  1. Open Microsoft Intune Admin Center: endpoint.microsoft.com
  2. Navigate to DevicesWindowsConfiguration profiles+ Create profile
  3. Platform: Choose Windows 10 and later
  4. Profile type: Select a relevant profile type (e.g., Settings catalog, Administrative templates, Custom).
  5. Settings catalog (Example):
    • Click + Add settings.
    • Search for and select the desired settings categories (e.g., Password, Device lock).
    • Configure the specific settings within the selected categories (e.g., require a password, set password complexity).
  6. Assignments: Assign the profile to Azure AD user or device groups.
  7. Click Create.

Step-by-Step: Create an iOS/iPadOS App Protection Policy

  1. Navigate to AppsApp protection policies+ Create policyiOS/iPadOS.
  2. Basics: Enter a name and description for the policy.
  3. Apps: Choose how to target apps (e.g., all apps, Microsoft managed apps, core Microsoft apps, custom apps).
  4. Data protection: Configure settings related to data transfer, copy/paste restrictions, save as, etc.
  5. Access requirements: Set PIN or biometric access requirements.
  6. Conditional launch: Configure app conditions for launch (e.g., minimum OS version, jailbreak detection).
  7. Assignments: Assign the policy to Azure AD user groups.
  8. Click Create.

Step-by-Step: Create a Windows 10 Compliance Policy

  1. Navigate to DevicesCompliance policies+ Create policyWindows 10 and later.
  2. Settings: Configure compliance rules (e.g., require BitLocker, minimum OS version, firewall).
  3. Actions for noncompliance: Configure actions to take when a device is not compliant (e.g., mark device non-compliant, send email, retire device).
  4. Assignments: Assign the policy to Azure AD user or device groups.
  5. Click Create.

Best Practices for Policy Implementation

Common Policy Implementation Issues & Troubleshooting

Issue Troubleshooting Steps
Policies not applying to devices Verify policy assignments, check device sync status, review Intune Management Extension logs (Windows), ensure the device is properly enrolled.
Conflicting policies Review all policies applied to a device or user to identify potential conflicts. Understand policy precedence.
Compliance status incorrect Manually sync the device, review compliance policy rules and device settings, check Intune logs for compliance evaluation errors.
App protection policies not working Ensure the targeted apps are Intune-managed, verify user assignments, check app logs for policy application issues.

Further Resources

← Hide Details

Microsoft Intune Troubleshooting

General Troubleshooting Steps

When encountering issues with Microsoft Intune, a systematic approach can help identify and resolve problems efficiently. [cite: Microsoft Intune Documentation]

Troubleshooting Windows Devices

Troubleshooting Windows devices managed by Intune often involves examining local device logs and the Intune Management Extension (IME). [cite: Microsoft Intune Documentation]

Troubleshooting Android Devices

Troubleshooting Android devices may involve checking Company Portal logs and device-specific settings. [cite: Microsoft Intune Documentation]

Troubleshooting iOS/iPadOS Devices

Troubleshooting iOS and iPadOS devices often involves examining device console logs and ensuring proper certificate configuration. [cite: Microsoft Intune Documentation]

Troubleshooting macOS Devices

Troubleshooting macOS devices involves examining system logs and the MDM client. [cite: Microsoft Intune Documentation]

Common Troubleshooting Scenarios

Scenario Common Causes Troubleshooting Steps
Device Enrollment Failures Network issues, incorrect enrollment profiles, device restrictions, expired certificates, issues with ABM/ASM or Managed Google Play. Verify network connectivity, review enrollment profiles, check device restrictions, ensure certificates are valid, check ABM/ASM or Managed Google Play status.
Policies Not Applying Device not syncing, incorrect policy assignments, policy conflicts, IME or MDM client errors, network issues. Force device sync, verify policy assignments, review relevant device logs (IME, Event Viewer, Console), check for conflicting policies.
App Installation Failures Network issues, insufficient device storage, app dependencies not met, incorrect deployment type, app store issues. Verify network connectivity, check device storage, ensure dependencies are installed, review app deployment settings, check app store access.
Compliance Issues Device not meeting policy requirements, delayed compliance evaluation, incorrect compliance policy configuration. Review compliance policy settings, check device settings against policy requirements, force device sync, review Intune compliance reports.

Further Assistance

← Hide Details

Microsoft Intune Collaboration & Integration

Importance of Collaboration

Effective management of Microsoft Intune often requires close collaboration with various teams within an organization. This ensures seamless integration with existing infrastructure and alignment with security policies. [cite: Best Practices for Intune Deployment]

Integration with Azure Active Directory (AAD)

Intune heavily relies on Azure Active Directory (AAD) for user and device identity, authentication, and group management. Collaboration with the identity management team is crucial. [cite: Azure AD and Intune Integration Guide]

Collaboration with Security Teams

Working closely with the security team ensures that Intune policies align with the organization's overall security strategy and compliance requirements. [cite: Intune Security Best Practices]

Integration with Microsoft Endpoint Configuration Manager (MECM)

In organizations using both Intune and MECM (co-management or migration scenarios), collaboration between the teams managing these tools is vital. [cite: Co-management with Intune and Configuration Manager]

Collaboration with Infrastructure Teams

The infrastructure team plays a crucial role in ensuring the underlying infrastructure supports Intune effectively. [cite: Intune Infrastructure Requirements]

Strategies for Effective Collaboration

Troubleshooting Collaboration Issues

Conditional Access policies blocking legitimate users Conflicts arising from co-management workloads Inconsistent policy application due to group management issues
IssuePotential Collaboration GapsTroubleshooting Approach
Enrollment failures due to network issues Lack of communication with the network team regarding required endpoints. Involve the network team to verify firewall rules and network connectivity. Review Intune network requirements documentation together.
Security team implemented policies without fully understanding Intune device compliance status. Hold a joint session to review Conditional Access policies and Intune compliance policy configurations. Ensure alignment on compliance requirements.
Unclear understanding of which authority manages specific workloads. Revisit the co-management workload configuration and ensure clear communication between the Intune and MECM teams on workload ownership.
Lack of communication with the identity team regarding AAD group membership and synchronization. Collaborate with the identity team to verify AAD Connect health and group membership rules. Ensure Intune is targeting the correct AAD groups.

Further Resources

← Hide Details

Microsoft Intune Monitoring & Reporting

Overview of Monitoring and Reporting

Effective monitoring and reporting are essential for understanding the health, compliance, and status of your managed devices and applications within Microsoft Intune. Intune provides various built-in tools and integrations for this purpose. [cite: Microsoft Intune Documentation]

Intune Built-in Reports

The Intune Admin Center offers a range of built-in reports that provide valuable information about your managed environment. [cite: Microsoft Intune Documentation]

Utilizing Microsoft Graph API for Reporting

The Microsoft Graph API provides programmatic access to Intune data, allowing you to create custom reports, dashboards, and automate reporting tasks. [cite: Microsoft Graph Documentation]

Power BI Integration

Connecting Intune data to Power BI enables advanced data visualization and analysis capabilities. You can create interactive dashboards and gain deeper insights into your Intune environment. [cite: Microsoft Intune Documentation on Power BI]

Alerts and Notifications

Intune allows you to configure alerts and notifications for critical events, enabling proactive management and issue resolution. [cite: Microsoft Intune Documentation on Alerts]

Step-by-Step: Accessing Built-in Reports

  1. Open Microsoft Intune Admin Center: endpoint.microsoft.com
  2. Navigate to Reports in the left-hand menu.
  3. Browse the available report categories (e.g., Device compliance, Apps, Device enrollment).
  4. Select a specific report (e.g., "Compliance status").
  5. Configure filters (e.g., platform, compliance state) and click Generate report.
  6. View the report data in the portal or export it to CSV.

Step-by-Step: Using Microsoft Graph Explorer for Reporting

  1. Go to Microsoft Graph Explorer.
  2. Sign in with your Azure AD credentials that have the necessary permissions to access Intune data.
  3. In the query box, enter a Graph API endpoint for Intune reporting (e.g., /deviceManagement/managedDevices to list all managed devices).
  4. Click Run query.
  5. Review the JSON response containing the requested data.
  6. Explore other Intune Graph API endpoints for specific reporting needs (e.g., compliance status: /deviceManagement/deviceComplianceDeviceStatuses, app installation status: /deviceAppManagement/mobileAppDeviceStatuses).

Step-by-Step: Connecting Intune Data to Power BI (Conceptual)

  1. Prerequisites: Power BI Desktop installed, understanding of Power BI data sources.
  2. Configure Azure AD App Registration: Register an application in Azure AD with permissions to access Intune data via the Microsoft Graph API.
  3. Get Data in Power BI:
    • In Power BI Desktop, select Get Data.
    • Choose Web as the data source.
    • Use the Microsoft Graph API endpoint for Intune data as the URL.
    • Configure authentication using the Azure AD app registration details.
  4. Transform Data: Use the Power BI Query Editor to shape and transform the retrieved data.
  5. Create Visualizations: Build charts, graphs, and tables to visualize key Intune metrics.
  6. Publish Dashboard: Publish your Power BI report to the Power BI service to create interactive dashboards.

Step-by-Step: Configuring Alerts

  1. Navigate to Tenant administrationAlerts in the Intune Admin Center.
  2. Review the existing alerts and their status.
  3. Click + Create alert rule.
  4. Configure the alert rule details, including name, description, severity, and conditions (e.g., device compliance, app installation failures).
  5. Configure notifications (e.g., email recipients, portal notifications).
  6. Click Create.

Best Practices for Monitoring & Reporting

Common Monitoring & Reporting Issues & Troubleshooting

IssueTroubleshooting Steps
Reports not showing the latest dataEnsure devices are syncing with Intune regularly. Check the report generation time. For custom reports via Graph API, verify the API calls are correct and data is being retrieved.
Unable to access reportsVerify that your account has the necessary Intune RBAC (Role-Based Access Control) permissions to view reports.
Power BI connection errorsDouble-check the Azure AD app registration permissions, the Graph API endpoint in Power BI, and the authentication method.
Alerts not being triggeredReview the alert rule configuration to ensure the conditions are correctly defined. Check the notification settings.

Further Resources

← Hide Details

PowerShell Scripting for Intune Automation

PowerShell can be used to automate various Intune tasks, enhancing efficiency and providing more control over your environment. This section provides examples for automatic enrollment, policy deployment, and remediations using the Microsoft Graph API. [cite: Microsoft Graph PowerShell SDK Documentation]

Automating Device Enrollment (Example: Adding Devices to Autopilot Group)

This script demonstrates how to add devices to an Azure AD group that is targeted by an Autopilot deployment profile.

      
# Prerequisites: Install Microsoft.Graph.Intune PowerShell SDK
# Install-Module Microsoft.Graph.Intune

# Connect to Microsoft Graph with necessary permissions
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.ReadWrite.All", "Group.ReadWrite.All"

# --- Configuration ---
$AutopilotGroupName = "Autopilot Devices" # Name of your Autopilot Azure AD Group
$DeviceSerialNumbers = @("DEVICE_SERIAL_1", "DEVICE_SERIAL_2") # Array of device serial numbers to add

# --- Script ---
# Get the Autopilot Azure AD Group ID
$AutopilotGroup = Get-MgGroup -Filter "displayName eq '$AutopilotGroupName'"
if (-not $AutopilotGroup) {
  Write-Error "Autopilot group '$AutopilotGroupName' not found."
  exit
}
$AutopilotGroupId = $AutopilotGroup.Id

foreach ($SerialNumber in $DeviceSerialNumbers) {
  # Get the Intune managed device object by serial number
  $ManagedDevice = Get-MgDeviceManagementManagedDevice -Filter "serialNumber eq '$SerialNumber'"
  if ($ManagedDevice) {
      $DeviceId = $ManagedDevice.Id
      Write-Host "Found device with serial number '$SerialNumber', ID: '$DeviceId'"

      # Check if the device is already a member of the group
      $IsMember = Get-MgGroupMember -GroupId $AutopilotGroupId -All -Filter "id eq '$DeviceId'"
      if (-not $IsMember) {
          # Create the body for adding the device to the group
          $RequestBody = @{
              "@odata.id" = "https://graph.microsoft.com/v1.0/devices('$DeviceId')"
          }

          # Add the device to the Autopilot group
          try {
              Invoke-MgGraphRequest -Method POST -Uri "groups/$AutopilotGroupId/members/\$ref" -Body $RequestBody
              Write-Host "Successfully added device with serial number '$SerialNumber' to group '$AutopilotGroupName'."
          } catch {
              Write-Error "Failed to add device with serial number '$SerialNumber' to group '$AutopilotGroupName': $($_.Exception.Message)"
          }
      } else {
          Write-Host "Device with serial number '$SerialNumber' is already a member of group '$AutopilotGroupName'."
      }
  } else {
      Write-Warning "Device with serial number '$SerialNumber' not found in Intune."
  }
}

Disconnect-MgGraph
      
  

Automating Policy Deployment (Example: Assigning a Configuration Profile)

This script demonstrates how to assign an existing Intune configuration profile to an Azure AD group.

      
# Prerequisites: Install Microsoft.Graph.Intune PowerShell SDK
# Install-Module Microsoft.Graph.Intune

# Connect to Microsoft Graph with necessary permissions
Connect-MgGraph -Scopes "DeviceManagementConfiguration.ReadWrite.All", "Group.Read.All"

# --- Configuration ---
$ProfileName = "Windows Defender Settings" # Name of the Configuration Profile to assign
$GroupName = "Windows 10 Devices" # Name of the Azure AD Group to assign the profile to

# --- Script ---
# Get the Configuration Profile ID
$ConfigurationProfile = Get-MgDeviceManagementDeviceCompliancePolicy -Filter "displayName eq '$ProfileName'"
if (-not $ConfigurationProfile) {
  Write-Error "Configuration profile '$ProfileName' not found."
  exit
}
$ProfileId = $ConfigurationProfile.Id

# Get the Azure AD Group ID
$Group = Get-MgGroup -Filter "displayName eq '$GroupName'"
if (-not $Group) {
  Write-Error "Azure AD group '$GroupName' not found."
  exit
}
$GroupId = $Group.Id

# Check if the assignment already exists (optional)
$ExistingAssignment = Get-MgDeviceManagementDeviceCompliancePolicyAssignment -DeviceCompliancePolicyId $ProfileId -Filter "target/groupId eq '$GroupId'"
if (-not $ExistingAssignment) {
  # Create the assignment body
  $RequestBody = @{
      "@odata.type" = "#microsoft.graph.deviceManagementScriptGroupAssignment"
      target = @{
          "@odata.type" = "#microsoft.graph.deviceAndAppManagementAssignmentTarget"
          groupId = $GroupId
      }
  }

  # Assign the Configuration Profile to the group
  try {
      $Assignment = New-MgDeviceManagementDeviceCompliancePolicyAssignment -DeviceCompliancePolicyId $ProfileId -Body $RequestBody
      Write-Host "Successfully assigned configuration profile '$ProfileName' to group '$GroupName'."
  } catch {
      Write-Error "Failed to assign configuration profile '$ProfileName' to group '$GroupName': $($_.Exception.Message)"
  }
} else {
  Write-Host "Configuration profile '$ProfileName' is already assigned to group '$GroupName'."
}

Disconnect-MgGraph
      
  

Automating Remediations (Example: Triggering Device Sync)

This script demonstrates how to trigger a device sync for non-compliant devices.

      
# Prerequisites: Install Microsoft.Graph.Intune PowerShell SDK
# Install-Module Microsoft.Graph.Intune

# Connect to Microsoft Graph with necessary permissions
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.ReadWrite.All", "DeviceManagementManagedDevices.Read.All"

# --- Configuration ---
$ComplianceStatus = "NonCompliant" # Filter for non-compliant devices

# --- Script ---
# Get all managed devices
$ManagedDevices = Get-MgDeviceManagementManagedDevice -All
if (-not $ManagedDevices) {
  Write-Warning "No managed devices found."
  exit
}

# Filter for non-compliant devices
$NonCompliantDevices = $ManagedDevices | Where-Object {$_.deviceComplianceState -eq $ComplianceStatus}

if ($NonCompliantDevices) {
  Write-Host "Found $($NonCompliantDevices.Count) non-compliant devices. Triggering sync..."
  foreach ($Device in $NonCompliantDevices) {
      $DeviceId = $Device.Id
      Write-Host "Triggering sync for device: $($Device.deviceName) (ID: $DeviceId)"
      try {
          Invoke-MgGraphRequest -Method POST -Uri "deviceManagement/managedDevices/$DeviceId/syncDevice"
          Write-Host "Successfully triggered sync for device: $($Device.deviceName)."
      } catch {
          Write-Error "Failed to trigger sync for device $($Device.deviceName): $($_.Exception.Message)"
      }
      # Add a delay to avoid throttling (optional)
      Start-Sleep -Seconds 5
  }
} else {
  Write-Host "No non-compliant devices found."
}

Disconnect-MgGraph
      
  

Important Considerations for PowerShell Automation

Further Resources

← Hide Details

Microsoft Intune OS Deployment

OS Deployment with Intune

Microsoft Intune offers various methods for deploying and managing operating systems on devices, primarily focusing on Windows. While Intune doesn't directly perform traditional OS imaging like SCCM, it leverages modern deployment techniques. [cite: Microsoft Intune Documentation]

Windows OS Deployment Methods with Intune

Step-by-Step: Deploying Windows 10/11 Feature Updates

  1. Prerequisites: Devices must be enrolled in Intune and managed.
  2. Navigate to Feature Updates:
    • Open Microsoft Intune Admin Center: endpoint.microsoft.com
    • Go to DevicesWindowsWindows updatesCreateFeature update deployment for Windows 10 and later.
  3. Basics: Provide a name and description for the deployment policy.
  4. Update settings:
    • Servicing channel: Choose the desired servicing channel (e.g., Semi-Annual Channel).
    • Feature update to deploy: Select the target Windows 10 or 11 version.
    • Rollout options: Configure how and when the update is deployed.
      • Make update available as soon as possible: Deploys immediately to assigned devices.
      • Make update available on a specific date: Schedules the deployment for a future date.
      • Gradually rollout updates: Deploys the update in stages to reduce potential impact.
    • User experience settings: Configure user notifications and restart behavior.
  5. Assignments: Assign the feature update policy to Azure AD device groups.
  6. Click Create.

Step-by-Step: Upgrading to Windows 10/11 (using Feature Updates)

The process for upgrading to a newer Windows version (e.g., from Windows 10 to Windows 11) using Intune is similar to deploying Feature Updates. You would select the target Windows 11 version in the "Feature update to deploy" setting of the Feature update policy.

  1. Prerequisites: Devices must meet the minimum hardware requirements for the target OS.
  2. Follow the steps for deploying Feature Updates, ensuring you select the desired upgrade version (e.g., Windows 11).
  3. Monitor the deployment status and address any compatibility issues.

OS Updates for Android and iOS/iPadOS

Intune provides policies to manage OS updates for mobile platforms, but the level of control differs from Windows Feature Updates. [cite: Microsoft Intune Documentation]

Best Practices for OS Deployment with Intune

Common OS Deployment Issues & Troubleshooting

IssueTroubleshooting Steps
Feature updates failing to installReview Intune update deployment reports, check device event logs for update errors, ensure sufficient disk space, verify network connectivity.
Upgrade to newer OS failingVerify device hardware compatibility with the target OS, review setup logs on the device, ensure all prerequisites are met.
Slow update downloadsCheck network bandwidth, configure Delivery Optimization settings, consider using a local update cache (if applicable).
User experience issues after updateThoroughly test updates before broad deployment, provide user training and support, consider rollback options if critical issues arise.

Further Resources

← Hide Details

Microsoft Intune Application Deployment

Application Deployment Overview

Microsoft Intune allows you to deploy and manage applications on enrolled devices (Windows, Android, iOS/iPadOS, macOS). You can deploy various app types, ensuring users have the necessary tools while maintaining security and compliance. [cite: Microsoft Intune Documentation]

Supported Application Types

PlatformSupported App Types
Windows Win32 apps (.exe, .msi), Microsoft Store apps (new and classic), Web links, Microsoft 365 Apps, Universal Apps (.appx, .msix), Line-of-business (LOB) apps (.msi, .appx, .msix).
Android Google Play Store apps, Managed Google Play apps, Web links, Line-of-business (LOB) APKs.
iOS/iPadOS App Store apps, Volume Purchase Program (VPP) apps, Web links, Line-of-business (LOB) IPA files.
macOS macOS apps (.pkg, .dmg), Mac App Store apps (VPP), Web links, Line-of-business (LOB) .pkg files.

Step-by-Step: Deploying a Win32 Application (.exe)

  1. Prepare App Content: Ensure you have the application installer (.exe), any necessary command-line arguments for silent installation, and detection rules.
  2. Add the App to Intune:
    • Open Microsoft Intune Admin Center: endpoint.microsoft.com
    • Navigate to AppsWindows+ AddWindows app (Win32)Select app package file.
    • Upload the .intunewin file (created using the Microsoft Win32 Content Prep Tool).
  3. App Information: Configure app details (name, description, publisher, etc.).
  4. Program: Specify the install command, uninstall command, and any required behavior (e.g., install as system, reboot behavior).
  5. Requirements: Define operating system architecture, minimum OS version, and other requirements.
  6. Detection rules: Configure rules to detect if the app is already installed (e.g., check for a specific file or registry key).
  7. Dependencies: Specify any prerequisite apps that need to be installed first.
  8. Assignments: Assign the app to Azure AD user or device groups (e.g., Available for enrolled devices, Required, Uninstall).
  9. Click Create.

Step-by-Step: Deploying an Android Store App

  1. Connect to Managed Google Play: Ensure Intune is connected to your Managed Google Play account.
  2. Add the App:
    • Navigate to AppsAndroid+ AddManaged Google Play appApprove the desired app from the Google Play Store.
    • Sync the approved app to Intune.
  3. App Information: Configure app details (name, description, etc.).
  4. Assignments: Assign the app to Azure AD user or device groups (e.g., Available for enrolled devices, Required, Uninstall).
  5. Configuration settings (optional): Configure managed app configuration if the app supports it.
  6. Click Create.

Step-by-Step: Deploying an iOS/iPadOS App Store App

  1. Connect to Apple App Store: Ensure your Intune tenant is connected to the Apple App Store.
  2. Add the App:
    • Navigate to AppsiOS/iPadOS+ AddApp Store app → Search for and select the desired app.
  3. App Information: Configure app details (name, description, etc.).
  4. Assignments: Assign the app to Azure AD user or device groups (e.g., Available for enrolled devices, Required, Uninstall).
  5. Volume Purchase Program (VPP) (optional): If using VPP, select the VPP token and configure license assignment.
  6. Click Create.

Best Practices for App Deployment

Common App Deployment Issues & Troubleshooting

IssueTroubleshooting Steps
App installation failsReview Intune app deployment status, check device logs (IME logs for Win32), ensure device meets app requirements, verify network connectivity.
App not appearing in Company PortalVerify app assignments, ensure the user/device is in the assigned group, sync the device.
App uninstall failsReview uninstall command in the app properties, check device logs for uninstall errors.
Issues with VPP apps (iOS/iPadOS)Verify VPP token status, ensure sufficient licenses are available, check user/device assignments for VPP.

Further Resources

← Hide Details