How to Control Intune Enrollment with Enrollment Restrictions
by Ru Campbell
Enrollment restrictions are sets of rules assigned to Azure AD groups. There are two types of enrollment restrictions: device type and device limit.
Ruairidh Campbell is a Public Cloud Technical Consultant, helping customers with security, compliance, and modern device management. Specializing in Microsoft 365 Enterprise Mobility + Security and Microsoft Defender, you can connect with Ru on Twitter @rucam365.
by Ru Campbell
Enrollment restrictions are sets of rules assigned to Azure AD groups. There are two types of enrollment restrictions: device type and device limit.
by Ru Campbell
On-premises Active Directory domain-joined PCs have typically been managed with tools such as Group Policy. At larger scales, you may have Configuration Manager or third-party tools. The availability of Intune (part of Endpoint Manager) in Microsoft 365 subscriptions such as Business Premium and E3 has opened up an alternative. The benefit many are seeing over… Read More
with 1 Comment by Ru Campbell
Intune Administrators can deploy, make optionally available, or uninstall Win32 apps with the help of Windows 10's Intune Management Extension (IME). The IME is a service installed on Windows 10 that acts as the engine to execute these actions and, additionally, PowerShell scripts (which were originally its only purpose). Win32 apps in the context of… Read More
by Ru Campbell
To protect data at rest on your Intune-managed Windows devices, BitLocker disk encryption can be applied automatically using the BitLocker CSP. If you are deploying devices with Autopilot, this will also allow you to encrypt them at the time of deployment. Existing devices will be encrypted as soon as the device checks in with Intune… Read More
by Ru Campbell
Microsoft Defender has many layers and trying to understand all of the different components can be complex.