Event banner

AMA: Enabling cloud-based device management with cloud attach

Event Ended
Thursday, Jul 21, 2022, 11:00 AM PDT
Online

Event details

We know lots of customers have Configuration Manager managed devices. Learn how to extend management capabilities to the cloud with cloud attach. Tips on optimizing across on-prem and cloud management, best practices for security policy configuration, the co-management "slider" and more!

Join us for a special Ask Microsoft Anything (AMA) live stream on enabling cloud-based management of your devices with cloud attach.

This is a great opportunity to learn from Microsoft experts. Add this event to your calendar, RSVP to receive notifications, then join us here for the live stream on the Tech Community on Thursday, July 21.

 

Submit your questions anytime during the hour or post them early in the Comments below.

Heather_Poulsen
Updated Dec 27, 2024

40 Comments

    • Jason_Sandys's avatar
      Jason_Sandys
      Icon for Microsoft rankMicrosoft

      Not on a technical level, however, co-management is *not* a remote management solution and you will have issues if the ConfigMgr agent cannot communicate with the ConfigMgr site for an extended period of time. Thus, I strongly recommend not doing this if remote management is in scope and you have no other regular connectivity between the managed endpoints and ConfigMgr (like a VPN).

    • Rachelle_Blanchard's avatar
      Rachelle_Blanchard
      Icon for Microsoft rankMicrosoft
      No, CMG is not required for co-management. If there is documentation somewhere out that states this, please let us know so we can fix it.
  • Olaf_Thyssen's avatar
    Olaf_Thyssen
    Brass Contributor
    For Windows enrollment I can assign a co-management authority profile to a group, but excluding a group is not available yet. Is it going to be implemented soon ? Purpose: we have some devices like PAW (maintained in a group) where MECM client should not be installed during provisioning
    • Rachelle_Blanchard's avatar
      Rachelle_Blanchard
      Icon for Microsoft rankMicrosoft

      Admin reply: This question was answered live. Please refer to the recording for more details.

  • Don't be shy. This is a great forum to ask your questions about managing devices on-prem while adding additional value and simplicity via the cloud, but also to share information about use cases and scenarios you need to support. Post your questions now in the Comments.

  • dsmodus's avatar
    dsmodus
    Brass Contributor
    Is it possible that a co-managed device with Endpoint Security sliders moved to Intune to get the policies from ConfigMgr or GPO if these are still targeted to that device via some collection, group?
    • Olaf_Thyssen's avatar
      Olaf_Thyssen
      Brass Contributor
      Keep in mind that it will add complexity and unknown side effects if settings are applied from Intune and GPO. Give up the GPO and setup the settings within the Endpoint Protection hive of Intune. If you love your collections you can sync them to Azure AD groups and use those for assigment in Intune
    • Rachelle_Blanchard's avatar
      Rachelle_Blanchard
      Icon for Microsoft rankMicrosoft

      Admin reply: This question was answered live. Please refer to the recording for more details.

      • Matt_Call's avatar
        Matt_Call
        Icon for Microsoft rankMicrosoft
        When the Endpoint Protection slider is moved to Intune, Endpoint Protection policies will stop applying from Configuration Manager. Group Policy is completely orthogonal to the management plane and will continue to apply regardless of ConfigMgr Co-management status.
  • Welcome to Tech Community Live: Endpoint Manager edition and the Cloud attach AMA. Let's get started! Post your questions in the Comments. We will be answering questions in the live stream—and others will be answering here in the chat.

  • Gibson99's avatar
    Gibson99
    Copper Contributor

    Right now in endpoint.microsoft.com I just see a bunch of empty blocks saying contact your intune admin to get access. What rights do I need to properly use the product? We're currently 100% on-prem, nothing in intune and no tenant attach yet.

     

    we aren't on anything cloud yet because previous mgmt was a million% anti-cloud and only now are they relaxing about it. with covid we already had a big VDI farm and big vpn capacity so it wasn't a big deal.

      • Gibson99's avatar
        Gibson99
        Copper Contributor
        that sounds like a global admin - are there more granular rights that can be assigned? like is there an article somewhere that explains waht rights are needed for which roles, like reporting, server admins, workstation admins, view-only, app packager, etc?
Date and Time
Jul 21, 202211:00 AM - 12:00 PM PDT