Hybrid Azure AD Join + Intune Enrollment – Prerequisites Checklist and Process Flow

Hybrid Azure AD Join + Intune Enrollment – Prerequisites Checklist and Process Flow

I'm a simple person, and sometimes it just helps to have a checklist to refer to when you're troubleshooting rather than navigating the sparse pages of docs.microsoft.com.  In this blog, I  explain the prerequisites for the Hybrid Azure AD Join (HAADJ) + automatic (GPO controlled) Intune MDM enrollment scenario and the process from start to end, as simply and concisely as I can (not easy!)  There are no screenshots and it's not a click-by-click:…
Microsoft 365 Updates from Build 2020

Microsoft 365 Updates from Build 2020

Build 2020 had some nice bits of M365 related news.  Microsoft deserves commendation for sticking to the schedule and pulling this off (remotely) during the COVID-19 lockdown - Apple has delayed WWDC and Google just gave up on I/O.  I've summarised (bullet points!) my favourite updates below.  I will update it I find I've missed something good. Azure AD Publisher Verification lets developers verified through the Microsoft Partner Center stick a verified badge on…
Register Domain-Joined Computers as Devices – The Redundant and Broken Hybrid Azure AD Join GPO

Register Domain-Joined Computers as Devices – The Redundant and Broken Hybrid Azure AD Join GPO

The group policy object Register domain-joined computers as devices, or Automatically workplace join client computers in older templates, was previously a requirement for enabling Hybrid Azure AD Join.  After configuring Azure AD Connect and your Seamless SSO GPOs, this had to be enabled. Since Windows 10 1607 ("Anniversary Update"), in Azure AD Connect environments, on-premises Active Directory joined computers become Azure Active Directory registered when a synchronised user signs in to a synchronised computer;…
Connect a Work or School Account – MDM vs. MAM in Self Enrolment

Connect a Work or School Account – MDM vs. MAM in Self Enrolment

A Windows 10 user can self-enrol in MDM or MAM from Settings > Accounts > Access work or school > Connect. What happens next depends on how Mobility (MDM and MAM) is configured in Azure Active Directory and device ownership.  For a personal device, if user scope for both MDM and MAM overlaps for the enrolling user, MAM will win.  The opposite is true of corporate devices. Intune devices are considered personal by default…
Windows Information Protection (WIP) App Protection Policies: Protected and Exempt; Denied and Allowed – What Do They Mean?

Windows Information Protection (WIP) App Protection Policies: Protected and Exempt; Denied and Allowed – What Do They Mean?

One of things that strikes me as vague in Windows Information Protection (WIP) policies in Intune is configuring targeted apps:  what's the exact difference between a protected app and an exempt app; and what does allow or deny exactly do for both of those? A recap on some terminology before explaining what-does-what. Targeted apps are ones the WIP service will implement controls over. Unenlightened apps cannot differentiate between work and personal data.  They have no…