Home
%3CLINGO-SUB%20id%3D%22lingo-sub-707221%22%20slang%3D%22en-US%22%3ESupport%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-707221%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%2C%20today%20we%20have%20a%20great%20post%20by%20Intune%20support%20engineer%20%3CSTRONG%3EBetty%20Jia%3C%2FSTRONG%3E%20where%20she%20walks%20you%20through%20resolving%20an%20issue%20you%20might%20encounter%20when%20co-management%20is%20enabled%2C%20but%20even%20better%2C%20she%20goes%20on%20to%20talk%20about%20how%20pre-release%20features%20work%20in%20Configuration%20Manager%20and%20offers%20some%20insight%20into%20how%20you%20can%20turn%20these%20on%20and%20off%20and%20verify%20the%20configuration%20in%20your%20environment.%20Whether%20you%20use%20co-management%20today%20or%20have%20plans%20to%20do%20so%20in%20the%20future%2C%20this%20is%20one%20you%E2%80%99ll%20want%20to%20bookmark.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3D%3D%3D%3D%3D%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECo-management%20is%20a%20great%20solution%20that%20allows%20you%20to%20concurrently%20manage%20Windows%2010%20devices%20by%20using%20both%20Configuration%20Manager%20and%20Microsoft%20Intune.%20It%20lets%20you%20cloud-attach%20your%20existing%20investment%20in%20Configuration%20Manager%20by%20adding%20new%20functionality%20and%20allowing%20you%20to%20control%20which%20workloads%20are%20controlled%20by%20which%20service.%20You're%20also%20able%20to%20pilot%20a%20workload%20with%20a%20separate%20collection%20of%20devices.%20Piloting%20allows%20you%20to%20test%20the%20Intune%20functionality%20with%20a%20subset%20of%20devices%20before%20switching%20a%20larger%20group.%20Similar%20to%20piloting%2C%20co-management%20also%20allows%20you%20to%20enable%20certain%20prerelease%20features%20for%20early%20testing%2C%20and%20this%20is%20the%20core%20of%20what%20I%E2%80%99ll%20be%20covering%20in%20this%20post.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20example%2C%20let%E2%80%99s%20say%20you%E2%80%99ve%20configured%20co-management%20but%20you%20notice%20that%20apps%20and%20PowerShell%20scripts%20deployed%20from%20Intune%20to%20co-managed%20devices%20show%20a%20status%20of%20%3CSTRONG%3ENot%20applicable%3C%2FSTRONG%3E%2C%20whereas%20the%20same%20are%20successfully%20deployed%20to%20devices%20managed%20solely%20by%20Intune.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119723iC1ED5265922068F8%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22102556-jc1.png%22%20title%3D%22102556-jc1.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EAs%20mentioned%20earlier%2C%20co-management%20allows%20you%20to%20control%20which%20workloads%20are%20controlled%20by%20Intune%20and%20which%20are%20controlled%20by%20Configuration%20Manager%20(more%20on%20that%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsccm%2Fcomanage%2Fworkloads%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehere%3C%2FA%3E)%2C%20however%20you%20notice%20that%20the%20problem%20remains%20even%20after%20switching%20all%20available%20workloads%20to%20%3CSTRONG%3EIntune%3C%2FSTRONG%3E%20or%20%3CSTRONG%3EPilot%20Intune%3C%2FSTRONG%3E%20in%20the%20Configuration%20Manager%20console%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20384px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119724i67C2248C7CD41278%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22102556-jc2.png%22%20title%3D%22102556-jc2.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EDo%20you%20notice%20anything%20missing%20in%20the%20screen%20shot%20above%3F%20When%20you%20review%20the%20workloads%20listed%20in%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsccm%2Fcomanage%2Fworkloads%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ethis%20article%3C%2FA%3E%20and%20in%20the%20screen%20shot%20above%2C%20notice%20how%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20is%20not%20there%20even%20though%20the%20article%20states%20that%20co-management%20supports%20the%20following%20workloads%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECompliance%20policies%3C%2FLI%3E%0A%3CLI%3EWindows%20Update%20policies%3C%2FLI%3E%0A%3CLI%3EResource%20access%20policies%3C%2FLI%3E%0A%3CLI%3EEndpoint%20Protection%3C%2FLI%3E%0A%3CLI%3EDevice%20configuration%3C%2FLI%3E%0A%3CLI%3EOffice%20Click-to-Run%20apps%3C%2FLI%3E%0A%3CLI%3E%3CSTRONG%3E%3CFONT%20color%3D%22%23FF0000%22%3EClient%20apps%3C%2FFONT%3E%3C%2FSTRONG%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3ESo%20what%E2%80%99s%20going%20on%3F%20When%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20is%20switched%20to%20Intune%20(or%20Intune%20Pilot)%2C%20you%20can%20deploy%20apps%20from%20Intune%20portal%20to%20co-managed%20devices.%20However%2C%20if%20this%20workload%20is%20not%20switched%20to%20Intune%2C%20the%20client%20apps%20cannot%20be%20deployed%20successfully%20from%20Intune.%20You%20will%20also%20notice%20that%20besides%20the%20client%20apps%2C%20PowerShell%20script%20profiles%20and%20Win32%20apps%20also%20cannot%20be%20deployed%20successfully%20from%20Intune.%20This%20is%20because%20the%20Intune%20Management%20Extension%20(IME)%20that%20serves%20to%20supplement%20the%20in-box%20Windows%2010%20MDM%20features%20is%20only%20installed%20when%20a%20PowerShell%20script%20or%20a%20Win32%20app%20is%20deployed%20to%20a%20user%20or%20device%20security%20group%20(see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fintune%2Fintune-management-extension%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fintune%2Fintune-management-extension%3C%2FA%3E%3CSPAN%3E%20for%20more%20information%20on%20this)%3C%2FSPAN%3E.%20If%20the%20Client%20apps%20workload%20is%20not%20switched%20to%20Intune%2C%20IME%20will%20not%20get%20installed%2C%20thus%20PowerShell%20Scripts%20and%20Win32%20apps%20will%20also%20fail%20to%20deploy.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EBased%20on%20all%20of%20this%20you%20can%20probably%20now%20figure%20out%20why%20apps%20and%20PowerShell%20scripts%20deployed%20from%20Intune%20to%20co-managed%20devices%20show%20a%20status%20of%20%3CSTRONG%3ENot%20applicable%3C%2FSTRONG%3E%20%E2%80%93%20because%20the%20workload%20has%20not%20been%20switched%20to%20Intune.%20But%20why%20is%20that%2C%20and%20why%20do%20you%20not%20see%20the%20option%20to%20switch%20the%20Client%20apps%20workload%20to%20Intune%3F%20The%20answer%20is%20because%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20is%20a%20pre-release%20feature.%3C%2FP%3E%0A%3CP%3EPre-release%20features%20are%20features%20that%20are%20in%20the%20current%20branch%20for%20early%20testing%20in%20a%20production%20environment.%20These%20features%20are%20fully%20supported%20but%20still%20in%20active%20development%2C%20thus%20they%20might%20receive%20changes%20until%20they%20move%20out%20of%20the%20pre-release%20category.%20To%20use%20pre-release%20features%2C%20you%20must%20first%20give%20consent%20and%20then%20enable%20them%20in%20the%20console.%20Here%E2%80%99s%20how%20that%20is%20done%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIn%20the%20Configuration%20Manager%20console%20under%20%3CSTRONG%3EHierarchy%20Settings%3C%2FSTRONG%3E%20properties%2C%20you%20will%20see%20the%20option%20%3CSTRONG%3EConsent%20to%20use%20Pre-Release%20features%3C%2FSTRONG%3E.%20The%20first%20step%20is%20to%20grant%20consent%20by%20checking%20the%20box%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20365px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119725iC54019A860785364%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22102556-jc3.png%22%20title%3D%22102556-jc3.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENext%2C%20under%20%3CSTRONG%3EUpdates%20and%20Servicing%3C%2FSTRONG%3E%2C%20turn%20on%20Mobile%20apps%20for%20co-managed%20devices%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119726i077415049B741F18%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22102556-jc4.png%22%20title%3D%22102556-jc4.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ELastly%2C%20go%20back%20to%20the%20%3CSTRONG%3EWorkloads%3C%2FSTRONG%3E%20tab%20and%20you%E2%80%99ll%20see%20that%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20now%20appears%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20389px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119727iA17F7C380002E650%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22102556-jc5.png%22%20title%3D%22102556-jc5.png%22%20%2F%3E%3C%2FSPAN%3E-%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESwitch%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20to%20Intune%20and%20you%E2%80%99re%20good%20to%20go.%20At%20this%20point%2C%20apps%20and%20PowerShell%20scripts%20deployed%20from%20Intune%20to%20co-managed%20devices%20should%20successfully%20install.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EAdditional%20Reading%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EAnother%20common%20question%20I%20get%20when%20talking%20about%20this%20is%20how%20to%20check%20whether%20the%20Client%20apps%20workload%20is%20switched%20to%20Intune%20from%20the%20client%20device.%20To%20answer%20that%20question%20we%E2%80%99ll%20need%20to%20take%20a%20closer%20look%20at%20co-management%20capabilities.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOnce%20the%20device%20is%20co-managed%2C%20in%20Configuration%20Manager%20properties%20you%20will%20see%20that%20the%20%3CSTRONG%3ECo-management%3C%2FSTRONG%3E%20property%20value%20is%20set%20to%20%3CSTRONG%3EEnabled%3C%2FSTRONG%3E%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20414px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119728iF15263E1F512AC77%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22102556-jc6.png%22%20title%3D%22102556-jc6.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYou%20will%20also%20notice%20a%20%3CSTRONG%3ECo-management%20capabilities%3C%2FSTRONG%3E%20property%20and%20value%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20402px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119729i8E8996BED3BD6B06%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22102556-jc7.png%22%20title%3D%22102556-jc7.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20value%20is%20a%20reflection%20of%20the%20co-management%20workloads%20configured%20in%20Configuration%20Manager%20and%20is%20a%20sum%20of%20settings%20you%20configured.%20The%20maximum%20value%20of%20%3CSTRONG%3ECo-management%20capabilities%3C%2FSTRONG%3E%20is%20255%2C%20which%20is%20the%20sum%20of%20all%20these%20values%20as%20listed%20in%20the%20chart%20below.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CTABLE%20width%3D%22546%22%3E%0A%3CTBODY%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3EValue%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EWorkload%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E1%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EInventory.%20It%20simply%20means%20co-management%20is%20configured%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E2%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3ECompliance%20policies%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E4%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EResource%20access%20policies%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E8%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EDevice%20Configuration%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E16%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EWindows%20Update%20policies%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E32%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EEndpoint%20Protection%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E64%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EClient%20apps%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3CTR%3E%0A%3CTD%20width%3D%2260%22%3E%3CP%3E128%3C%2FP%3E%0A%3C%2FTD%3E%0A%3CTD%20width%3D%22485%22%3E%3CP%3EOffice%20Click-to-run%20apps%3C%2FP%3E%0A%3C%2FTD%3E%0A%3C%2FTR%3E%0A%3C%2FTBODY%3E%0A%3C%2FTABLE%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20means%20that%20if%20we%20only%20switch%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20to%20Intune%2C%20the%20%3CSTRONG%3ECo-management%20capabilities%3C%2FSTRONG%3E%20value%20would%20be%201%2B64%2C%20or%2065.%20So%20for%20a%20value%20of%20175%20as%20in%20our%20example%20above%2C%20that%20means%20the%20workloads%20switched%20to%20Intune%20are%20Inventory%20(1)%20%2B%20Compliance%20polices%20(2)%20%2B%26nbsp%3B%20Resource%20access%20polices%20(4)%20%2B%20Device%20Configuration%20(8)%20%2B%20Endpoint%20Protection%20(64)%20%2B%20Office%20click-to-run%20apps%20(128)%3D%20175.%20We%20can%20verify%20this%20by%20checking%20in%20the%20Configuration%20Manager%20console%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20390px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119730iE685A6DDA9972B73%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22102556-jc8.png%22%20title%3D%22102556-jc8.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ETaking%20this%20a%20step%20further%2C%20if%20we%20switch%20the%20%3CSTRONG%3EClient%20apps%3C%2FSTRONG%3E%20workload%20(a%20value%20of%2064)%20to%20Intune%2C%20the%20value%20for%20%3CSTRONG%3ECo-management%20capabilities%3C%2FSTRONG%3E%20will%20become%20239%20(175%2B64)%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20389px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119731i82E63680350B4CB9%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22102556-jc9.png%22%20title%3D%22102556-jc9.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%20style%3D%22text-align%3A%20center%3B%22%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20395px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F119732i4D7288C1B81DAD10%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22102556-jc10.png%22%20title%3D%22102556-jc10.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHopefully%20this%20sheds%20a%20little%20more%20light%20not%20only%20on%20why%20apps%20and%20PowerShell%20scripts%20deployed%20from%20Intune%20to%20co-managed%20devices%20might%20show%20a%20status%20of%20%3CSTRONG%3ENot%20applicable%3C%2FSTRONG%3E%2C%20but%20also%20how%20you%20can%20work%20with%20and%20enable%20pre-release%20features%20in%20Configuration%20Manager.%20As%20always%2C%20I%20appreciate%20any%20comments%20or%20feedback%20so%20feel%20free%20to%20leave%20me%20a%20note%20in%20the%20comments%20below.%3C%2FP%3E%0A%3CP%3E%3CBR%20%2F%3E%3CSTRONG%3E%3CEM%3EBetty%20Jia%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3ESupport%20Engineer%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%3CEM%3EMicrosoft%20Intune%20Support%20Team%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-707221%22%20slang%3D%22en-US%22%3E%3CP%3EIntune%20Support%20Engineer%20Betty%20Jia%20walks%20through%20resolving%20an%20issue%20you%20can%20see%20when%20co-management%20is%20enabled%20and%20talks%20about%20how%20to%20enable%20pre-release%20features%20in%20Configuration%20Manager.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709599%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709599%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Betty%3C%2FP%3E%3CP%3EGreat%20article%2C%20you%20should%20join%20the%20team%20that%20writes%20the%20documentation!%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EI%20do%20have%20one%20additional%20question%20that%20I%20hope%20you%20may%20be%20able%20to%20answer.%3C%2FP%3E%3CP%3EOnce%20the%20workload%20for%20'%3CSTRONG%3EClient%20Apps%3C%2FSTRONG%3E'%20is%20switched%20to%20Pilot%2FIntune%2C%20what%20happens%20to%20the%20SCCM%20capabilities%20to%20deploy%20applications%3F%20Can%20SCCM%20and%20Intune%20now%20%3CSTRONG%3Eboth%3C%2FSTRONG%3E%20be%20used%20to%20deploy%20apps%20or%20is%20it%20Intune%20only%20from%20that%20point%20on%3F%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EJan%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-709645%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-709645%22%20slang%3D%22en-US%22%3E%3CP%3EYes-%20I%20do%20exactly%20have%20the%20same%20question%20as%20Jan.%20Thanks%20Jan%20for%20bringing%20this%20up.%20We%20are%20currently%20working%20on%20Autopilot%20managed%20through%20Intune-%20but%20would%20like%20to%20have%20the%20SCCM%20agent%20installed%20on%20these%20devices%20-%20so%20that%20we%20want%20to%20make%20our%20users%20use%20our%20internal%20shopping%20portal%20for%20which%20apps%2C%20when%20shopped%2C%20get%20delivered%20via%20CM.%20So%20wanted%20to%20know-%20can%20we%20make%20the%20apps%20delievered%20by%20both%20CM%20and%20Intune%20as%20we%20would%20like%3F%20I%20wish-%20i%20get%20the%20response%20as%20%22yes%22%20%3B)%3C%2Fimg%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%3C%2FP%3E%3CP%3EAnantha%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-712785%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-712785%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20raising%20your%20questions%20Jan%20and%20Anantha!%20Betty%20will%20respond%20to%20your%20question%20shortly.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EJet%20Zhu%3C%2FP%3E%0A%3CP%3E%3CEM%3EMicrosoft%20Intune%20Support%20Team%3C%2FEM%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713113%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713113%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Jan%20%26amp%3B%20Anantha%2C%3C%2FP%3E%0A%3CP%3EThank%20you%20for%20posting%20comments.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOnce%20the%20workloads%20is%20switched%20to%20Intune%2C%20Intune%20will%20have%20the%20capability%20to%20deploy%20apps%2C%20and%20at%20the%20same%20time%20for%20SCCM%2C%20the%20capabilities%20is%20not%20removed.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20style%3D%22color%3A%20%23000000%3B%20font-family%3A%20'Segoe%20UI'%2C%20SegoeUI%2C%20'Segoe%20WP'%2C%20'Helvetica%20Neue'%2C%20Helvetica%2C%20Tahoma%2C%20Arial%2C%20sans-serif%3B%20font-size%3A%2016px%3B%20font-style%3A%20normal%3B%20font-variant-ligatures%3A%20normal%3B%20font-variant-caps%3A%20normal%3B%20font-weight%3A%20400%3B%20letter-spacing%3A%20normal%3B%20orphans%3A%202%3B%20text-align%3A%20start%3B%20text-indent%3A%200px%3B%20text-transform%3A%20none%3B%20white-space%3A%20normal%3B%20widows%3A%202%3B%20word-spacing%3A%200px%3B%20-webkit-text-stroke-width%3A%200px%3B%20background-color%3A%20%23ffffff%3B%20text-decoration-style%3A%20initial%3B%20text-decoration-color%3A%20initial%3B%20display%3A%20inline%20!important%3B%20float%3A%20none%3B%22%3EAfter%20you%20transition%20this%20workload%2C%20any%20available%20apps%20deployed%20from%20Intune%20are%20available%20in%20the%20Company%20Portal.%20Apps%20that%20you%20deploy%20from%20Configuration%20Manager%20are%20available%20in%20Software%20Center.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EI%20just%20finished%20testing%20deploying%20.msi%20app%20installer%20as%20available%20type%20from%20SCCM%20to%20co-management%20devices%20after%20client%20app%20workload%20switched%20to%20Intune.%20The%20app%20will%20still%20appear%20in%20Software%20center%20and%20can%20be%20installed%20without%20any%20issue.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713294%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713294%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20much%20Betty.%20This%20does%20clear%20few%20things.%20Thanks%20again.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECheers%2C%3C%2FP%3E%3CP%3EAnantha%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713337%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713337%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Betty%20-%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESorry-another%20one%20just%20dawned%20on%20my%20mind.%20With%20this%20setting%20of%20Co-management%20as%20briefed%20in%20this%20article%2C%20may%20I%20know%20what%20will%20be%20the%20impact%20of%20the%20existing%20devices%20managed%20by%20SCCM.%20I%20mean%20we%20are%20currently%20not%20looking%20at%20our%20on-prem%20devices%20to%20be%20co-managed%20from%20Intune%2C%20but%20only%20want%20the%20Autopilot%20devices%20to%20be%20co-managed%20by%20SCCM.%20Can%20you%20advice%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20Thanks%3C%2FP%3E%3CP%3EAnantha%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713351%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713351%22%20slang%3D%22en-US%22%3E%3CP%3EI%20guess%20as%20long%20as%20the%20on-prem%20device%20is%20NOT%20Hybrid%20Azure%20AD%20joined%2C%20the%20on-prem%20devices%20will%20continue%20to%20be%20managed%20ONLY%20by%20SCCM%20whereas%20for%20the%20Autopilot%20devices%2C%20it%20can%20leverage%20the%20CM%20SW%20deployment%20features%20as%20mentioned%20in%20your%20earlier%20response%20even%20its%20just%20Azure%20AD%20joined.%20Do%20correct%20me%20if%20am%20wrong%20in%20my%20understanding.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMany%20Thanks%2C%3C%2FP%3E%3CP%3EAnantha%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-713553%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-713553%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F364325%22%20target%3D%22_blank%22%3E%40Betty_Jia%3C%2FA%3E%3C%2FP%3E%3CP%3EThanks%20for%20that%20clarification!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-715135%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-715135%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F364325%22%20target%3D%22_blank%22%3E%40Betty_Jia%3C%2FA%3E%26nbsp%3BThanks%20for%20more%20clarification%20on%20this%20preview%20feature.%20Hoping%20for%20more.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-719056%22%20slang%3D%22en-US%22%3ERe%3A%20Support%20Tip%3A%20Configuring%20workloads%20in%20a%20co-managed%20environment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-719056%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F84766%22%20target%3D%22_blank%22%3E%40Anantha%20Subramanian%20Srinivasan%3C%2FA%3E%20%EF%BC%8Cyou%20are%20correct%2C%20on-promises%20SCCM%20and%20not%20hybrid%20AAD%20joined%20devices%2C%20will%20not%20be%20co-managed.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Hi everyone, today we have a great post by Intune support engineer Betty Jia where she walks you through resolving an issue you might encounter when co-management is enabled, but even better, she goes on to talk about how pre-release features work in Configuration Manager and offers some insight into how you can turn these on and off and verify the configuration in your environment. Whether you use co-management today or have plans to do so in the future, this is one you’ll want to bookmark.

 

=====

 

Co-management is a great solution that allows you to concurrently manage Windows 10 devices by using both Configuration Manager and Microsoft Intune. It lets you cloud-attach your existing investment in Configuration Manager by adding new functionality and allowing you to control which workloads are controlled by which service. You're also able to pilot a workload with a separate collection of devices. Piloting allows you to test the Intune functionality with a subset of devices before switching a larger group. Similar to piloting, co-management also allows you to enable certain prerelease features for early testing, and this is the core of what I’ll be covering in this post.

 

For example, let’s say you’ve configured co-management but you notice that apps and PowerShell scripts deployed from Intune to co-managed devices show a status of Not applicable, whereas the same are successfully deployed to devices managed solely by Intune.

 

102556-jc1.png

As mentioned earlier, co-management allows you to control which workloads are controlled by Intune and which are controlled by Configuration Manager (more on that here), however you notice that the problem remains even after switching all available workloads to Intune or Pilot Intune in the Configuration Manager console:

 

102556-jc2.png

 

Do you notice anything missing in the screen shot above? When you review the workloads listed in this article and in the screen shot above, notice how the Client apps workload is not there even though the article states that co-management supports the following workloads:

 

  • Compliance policies
  • Windows Update policies
  • Resource access policies
  • Endpoint Protection
  • Device configuration
  • Office Click-to-Run apps
  • Client apps

So what’s going on? When the Client apps workload is switched to Intune (or Intune Pilot), you can deploy apps from Intune portal to co-managed devices. However, if this workload is not switched to Intune, the client apps cannot be deployed successfully from Intune. You will also notice that besides the client apps, PowerShell script profiles and Win32 apps also cannot be deployed successfully from Intune. This is because the Intune Management Extension (IME) that serves to supplement the in-box Windows 10 MDM features is only installed when a PowerShell script or a Win32 app is deployed to a user or device security group (see https://docs.microsoft.com/intune/intune-management-extension for more information on this). If the Client apps workload is not switched to Intune, IME will not get installed, thus PowerShell Scripts and Win32 apps will also fail to deploy.

 

Based on all of this you can probably now figure out why apps and PowerShell scripts deployed from Intune to co-managed devices show a status of Not applicable – because the workload has not been switched to Intune. But why is that, and why do you not see the option to switch the Client apps workload to Intune? The answer is because the Client apps workload is a pre-release feature.

Pre-release features are features that are in the current branch for early testing in a production environment. These features are fully supported but still in active development, thus they might receive changes until they move out of the pre-release category. To use pre-release features, you must first give consent and then enable them in the console. Here’s how that is done:

 

In the Configuration Manager console under Hierarchy Settings properties, you will see the option Consent to use Pre-Release features. The first step is to grant consent by checking the box:

 

102556-jc3.png

 

Next, under Updates and Servicing, turn on Mobile apps for co-managed devices:

 

102556-jc4.png

 

Lastly, go back to the Workloads tab and you’ll see that the Client apps workload now appears:

 

102556-jc5.png-

 

Switch the Client apps workload to Intune and you’re good to go. At this point, apps and PowerShell scripts deployed from Intune to co-managed devices should successfully install.

 

Additional Reading

Another common question I get when talking about this is how to check whether the Client apps workload is switched to Intune from the client device. To answer that question we’ll need to take a closer look at co-management capabilities.

 

Once the device is co-managed, in Configuration Manager properties you will see that the Co-management property value is set to Enabled:

 

102556-jc6.png

 

You will also notice a Co-management capabilities property and value:

 

102556-jc7.png

 

This value is a reflection of the co-management workloads configured in Configuration Manager and is a sum of settings you configured. The maximum value of Co-management capabilities is 255, which is the sum of all these values as listed in the chart below.

 

Value

Workload

1

Inventory. It simply means co-management is configured

2

Compliance policies

4

Resource access policies

8

Device Configuration

16

Windows Update policies

32

Endpoint Protection

64

Client apps

128

Office Click-to-run apps

 

This means that if we only switch the Client apps workload to Intune, the Co-management capabilities value would be 1+64, or 65. So for a value of 175 as in our example above, that means the workloads switched to Intune are Inventory (1) + Compliance polices (2) +  Resource access polices (4) + Device Configuration (8) + Endpoint Protection (64) + Office click-to-run apps (128)= 175. We can verify this by checking in the Configuration Manager console:

 

102556-jc8.png

 

Taking this a step further, if we switch the Client apps workload (a value of 64) to Intune, the value for Co-management capabilities will become 239 (175+64):

 

102556-jc9.png

 

102556-jc10.png

 

Hopefully this sheds a little more light not only on why apps and PowerShell scripts deployed from Intune to co-managed devices might show a status of Not applicable, but also how you can work with and enable pre-release features in Configuration Manager. As always, I appreciate any comments or feedback so feel free to leave me a note in the comments below.


Betty Jia

Support Engineer

Microsoft Intune Support Team

10 Comments
Occasional Contributor

Hi Betty

Great article, you should join the team that writes the documentation! :)

I do have one additional question that I hope you may be able to answer.

Once the workload for 'Client Apps' is switched to Pilot/Intune, what happens to the SCCM capabilities to deploy applications? Can SCCM and Intune now both be used to deploy apps or is it Intune only from that point on?

Thanks,

Jan

Yes- I do exactly have the same question as Jan. Thanks Jan for bringing this up. We are currently working on Autopilot managed through Intune- but would like to have the SCCM agent installed on these devices - so that we want to make our users use our internal shopping portal for which apps, when shopped, get delivered via CM. So wanted to know- can we make the apps delievered by both CM and Intune as we would like? I wish- i get the response as "yes" ;) 

 

Thanks,

Anantha

Microsoft

Thanks for raising your questions Jan and Anantha! Betty will respond to your question shortly.

 

Jet Zhu

Microsoft Intune Support Team

Microsoft

Hi Jan & Anantha,

Thank you for posting comments. 

Once the workloads is switched to Intune, Intune will have the capability to deploy apps, and at the same time for SCCM, the capabilities is not removed. 

After you transition this workload, any available apps deployed from Intune are available in the Company Portal. Apps that you deploy from Configuration Manager are available in Software Center.

I just finished testing deploying .msi app installer as available type from SCCM to co-management devices after client app workload switched to Intune. The app will still appear in Software center and can be installed without any issue. 

 

 

Thanks much Betty. This does clear few things. Thanks again.

 

Cheers,

Anantha

Hi Betty - 

 

Sorry-another one just dawned on my mind. With this setting of Co-management as briefed in this article, may I know what will be the impact of the existing devices managed by SCCM. I mean we are currently not looking at our on-prem devices to be co-managed from Intune, but only want the Autopilot devices to be co-managed by SCCM. Can you advice?

 

Many Thanks

Anantha

I guess as long as the on-prem device is NOT Hybrid Azure AD joined, the on-prem devices will continue to be managed ONLY by SCCM whereas for the Autopilot devices, it can leverage the CM SW deployment features as mentioned in your earlier response even its just Azure AD joined. Do correct me if am wrong in my understanding.

 

Many Thanks,

Anantha

Occasional Contributor

Hi @Betty_Jia

Thanks for that clarification!

Senior Member

@Betty_Jia Thanks for more clarification on this preview feature. Hoping for more.

Microsoft

Hi @Anantha Subramanian Srinivasan , you are correct, on-promises SCCM and not hybrid AAD joined devices, will not be co-managed.