Cloud attach and Microsoft Endpoint Manager

%3CLINGO-SUB%20id%3D%22lingo-sub-1498577%22%20slang%3D%22en-US%22%3ECloud%20attach%20and%20Microsoft%20Endpoint%20Manager%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1498577%22%20slang%3D%22en-US%22%3E%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EToday%20we%20take%20an%20in-depth%20look%20at%20Cloud%20Attach%20and%20Microsoft%20Endpoint%20Manager%2C%20as%20modern%20management%20becomes%20increasingly%20crucial.%20After%20a%20quick%20overview%20of%20cloud%20attach%2C%20we%20dive%20into%20the%20phases%20of%20cloud%20attach%20and%20finally%20tenant%20attach.%20This%20session%20is%20packed%20with%20valuable%20information%20including%20prerequisites%2C%20licensing%20information%2C%20dashboards%20and%20more.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22enabling-remote-work.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F184867i95686E6CFCC29173%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22enabling-remote-work.png%22%20alt%3D%22enabling-remote-work.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CDIV%20style%3D%22position%3A%20relative%3B%20padding-bottom%3A%2056.25%25%3B%20padding-top%3A%2030px%3B%20height%3A%200%3B%20overflow%3A%20hidden%3B%20min-width%3A%20320px%3B%22%3E%3CIFRAME%20src%3D%22https%3A%2F%2Fwww.microsoft.com%2Fen-us%2Fvideoplayer%2Fembed%2FRE4zhpp%3Fautoplay%3Dfalse%22%20frameborder%3D%220%22%20allowfullscreen%3D%22allowfullscreen%22%20style%3D%22position%3A%20absolute%3B%20top%3A%200%3B%20left%3A%200%3B%20width%3A%20100%25%3B%20height%3A%20100%25%3B%22%20class%3D%22video-iframe%22%20your%3D%22%22%20video%3D%22%22%20title%3D%22%E2%80%9Dput%22%20here%3D%22%22%3E%3C%2FIFRAME%3E%3C%2FDIV%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%20font-family%3A%20'Segoe%20UI'%2C%20Segoe%2C%20Tahoma%2C%20Geneva%2C%20sans-serif%3B%20font-weight%3A%20600%3B%20font-size%3A%2020px%3B%20color%3A%20%23333333%3B%22%20id%3D%22toc-hId--1322023885%22%20id%3D%22toc-hId--1322023859%22%3ELearn%20more%E2%80%AF%26nbsp%3B%3C%2FH2%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EWhile%20not%20mentioned%20specifically%20in%20this%20session%2C%20here%20are%20some%20additional%20resources%20you%20might%20find%20helpful%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%20style%3D%22margin-bottom%3A%208px%3B%20margin-top%3A%2020px%3B%22%3E-ERR%3AREF-NOT-FOUND-Microsoft%20COVID-19%20response%20site%3C%2FLI%3E%0A%3CLI%20style%3D%22margin-bottom%3A%208px%3B%22%3E-ERR%3AREF-NOT-FOUND-Enabling%20Remote%20Work%3C%2FLI%3E%0A%3CLI%20style%3D%22margin-bottom%3A%208px%3B%22%3E-ERR%3AREF-NOT-FOUND-Microsoft%20Endpoint%20Manager%20remote%20work%20blog%3C%2FLI%3E%0A%3CLI%20style%3D%22margin-bottom%3A%208px%3B%22%3E-ERR%3AREF-NOT-FOUND-Work%20remotely%2C%20stay%20secure%3C%2FLI%3E%0A%3CLI%20style%3D%22margin-bottom%3A%208px%3B%22%3E-ERR%3AREF-NOT-FOUND-2%20weeks%20in%3A%20what%20we've%20learned%20about%20remote%20work%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%20font-family%3A%20'Segoe%20UI'%2C%20Segoe%2C%20Tahoma%2C%20Geneva%2C%20sans-serif%3B%20font-weight%3A%20600%3B%20font-size%3A%2020px%3B%20color%3A%20%23333333%3B%22%20id%3D%22toc-hId-1165488948%22%20id%3D%22toc-hId-1165488974%22%3EFrequently%20asked%20questions%3C%2FH2%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20Is%20co-managed%20the%20same%20as%20cloud%20attach%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3ECo-management%20is%20fully%20managed%20by%20both%20Configuration%20Manager%20and%20Microsoft%20Intune%20with%20explicit%20admin%20intent%20on%20which%20workload%20is%20managed%20by%20either%20Configuration%20Manager%20or%20Intune.%20Cloud%20attach%20is%20Configuration%20Manager%20only%20managed%20devices%20that%20show%20up%20in%20the%20cloud%20portal.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20When%20you%20enable%20co-management%20in%20the%20wizard%2C%20the%20Microsoft%20docs%20state%20that%20a%20Global%20Admin%20account%20is%20required%20to%20login.%20Is%20that%20really%20the%20case%20or%20can%20we%20use%20an%20Intune%20licensed%20account%20that%20has%20the%20Intune%20Administrator%20role%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3EYes%2C%20the%20Global%20Admin%20account%20is%20required.%20There%20are%20a%20couple%20of%20specific%20Azure%20AD%20object%20that%20are%20created%20(app%20registrations%20to%20be%20specific)%20that%20require%20this.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20What%20has%20changed%20or%20been%20added%2Fimproved%20with%20Microsoft%20Endpoint%20Manager%20since%20Ignite%202019%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3EKeep%20in%20mind%20that%20Intune%20and%20Configuration%20Manager%2C%20while%20becoming%20more%20integrated%2C%20are%20still%20two%20separate%20entities%20with%20different%20release%20schedules.%20Intune%20releases%20new%20functionality%20every%20month%20while%20Configuration%20Manager%20releases%20new%20functionality%20approximately%20every%20four%20months.%20For%20Intune%2C%20see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fwhats-new%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CU%3EWhat's%20new%20in%20Microsoft%20Intune%3C%2FU%3E%3C%2FA%3E%26nbsp%3Band%20for%20Configuration%20Manager%20see%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fmem%2Fconfigmgr%2Fcore%2Fplan-design%2Fchanges%2Fwhats-new-incremental-versions%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CU%3EWhat's%20new%20in%20Configuration%20Manager%3C%2FU%3E%3C%2FA%3E.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20Should%20I%20start%20Cloud%20Attach%20without%20Cloud%20Management%20Gateway%20first%20and%20then%20do%20it%20later%20if%20I%20need%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3EYou%20could%20go%20this%20route.%20Attaching%20to%20the%20cloud%20allows%20your%20devices%20to%20take%20advantage%20of%20cloud%20features%3B%20CMG%20allows%20Configuration%20Manager%20to%20manage%20your%20devices%20directly%20over%20the%20internet.%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20I%20have%20a%20CSP%20sandbox%20tenant%20where%20creating%20VMs%20in%20Azure%20is%20now%20allowed.%20This%20is%20a%20permanent%20testing%20environment.%20Can%20I%20still%20populate%20the%20CMG%20there%20or%20will%20that%20also%20be%20forbidden%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3EUnfortunately%2C%20CSP-based%20subscriptions%20do%20not%20support%20CMG.%20You%20need%20a%20separate%20non-CSP%20subscription%20to%20support%20CMG.%20This%20is%20documented%20in%20the%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fconfigmgr%2Fcore%2Fclients%2Fmanage%2Fcmg%2Fplan-cloud-management-gateway%23azure-resource-manager%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CU%3EAzure%20Resource%20Manager%3C%2FU%3E%3C%2FA%3E%20section%20of%20the%20article%2C%20%22Plan%20for%20the%20cloud%20management%20gateway%20in%20Configuration%20Manager%22(see%20the%20note).%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EQ%3A%3C%2FSTRONG%3E%E2%80%AF%20Should%20Azure%20AD%20sync%20be%20what%20onboards%20the%20co-management%3F%20Or%20the%20Configuration%20Manager%20client%3F%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%3CSTRONG%3EA%3A%20%3C%2FSTRONG%3EAD%20Connect%20syncs%20identities%2C%20so%20that%20is%20required%20to%20enable%20your%20devices%20to%20be%20hybrid%20Azure%20AD%20joined.%20Once%20your%20devices%20have%20a%20cloud%20identity%20(they%20are%20hybrid%20Azure%20AD%20joined)%2C%20Configuration%20Manager%20will%20coordinate%20the%20enrollment%20to%20Intune%2C%20based%20on%20your%20co-management%20settings%20in%20the%20ConfigMgr%20console.%3C%2FP%3E%0A%3CH2%20style%3D%22margin-top%3A%2036px%3B%20margin-bottom%3A%2020px%3B%20font-family%3A%20'Segoe%20UI'%2C%20Segoe%2C%20Tahoma%2C%20Geneva%2C%20sans-serif%3B%20font-weight%3A%20600%3B%20font-size%3A%2020px%3B%20color%3A%20%23333333%3B%22%20id%3D%22toc-hId--641965515%22%20id%3D%22toc-hId--641965489%22%3EFeedback%3C%2FH2%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3EWe%20hope%20you%20find%20this%20session%20useful.%20We'd%20love%20your%20feedback%20and%20ideas%20for%20future%20sessions%20so%20please%26nbsp%3B-ERR%3AREF-NOT-FOUND-%3CSTRONG%3Efill%20out%20this%20short%20survey%3C%2FSTRONG%3E.%20Thank%20you!%3C%2FP%3E%0A%3CP%20style%3D%22margin-top%3A%2020px%3B%22%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1498577%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECMG%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EConfiguration%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Endpoint%20Manager%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Intune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Today we take an in-depth look at Cloud Attach and Microsoft Endpoint Manager, as modern management becomes increasingly crucial. After a quick overview of cloud attach, we dive into the phases of cloud attach and finally tenant attach. This session is packed with valuable information including prerequisites, licensing information, dashboards and more.

 

enabling-remote-work.png

 

Learn more  

While not mentioned specifically in this session, here are some additional resources you might find helpful:

Frequently asked questions

Q:  Is co-managed the same as cloud attach?

A: Co-management is fully managed by both Configuration Manager and Microsoft Intune with explicit admin intent on which workload is managed by either Configuration Manager or Intune. Cloud attach is Configuration Manager only managed devices that show up in the cloud portal.

Q:  When you enable co-management in the wizard, the Microsoft docs state that a Global Admin account is required to login. Is that really the case or can we use an Intune licensed account that has the Intune Administrator role?

A: Yes, the Global Admin account is required. There are a couple of specific Azure AD object that are created (app registrations to be specific) that require this.

Q:  What has changed or been added/improved with Microsoft Endpoint Manager since Ignite 2019?

A: Keep in mind that Intune and Configuration Manager, while becoming more integrated, are still two separate entities with different release schedules. Intune releases new functionality every month while Configuration Manager releases new functionality approximately every four months. For Intune, see What's new in Microsoft Intune and for Configuration Manager see What's new in Configuration Manager.

Q:  Should I start Cloud Attach without Cloud Management Gateway first and then do it later if I need?

A: You could go this route. Attaching to the cloud allows your devices to take advantage of cloud features; CMG allows Configuration Manager to manage your devices directly over the internet.

Q:  I have a CSP sandbox tenant where creating VMs in Azure is now allowed. This is a permanent testing environment. Can I still populate the CMG there or will that also be forbidden?

A: Unfortunately, CSP-based subscriptions do not support CMG. You need a separate non-CSP subscription to support CMG. This is documented in the Azure Resource Manager section of the article, "Plan for the cloud management gateway in Configuration Manager"(see the note).

Q:  Should Azure AD sync be what onboards the co-management? Or the Configuration Manager client?

A: AD Connect syncs identities, so that is required to enable your devices to be hybrid Azure AD joined. Once your devices have a cloud identity (they are hybrid Azure AD joined), Configuration Manager will coordinate the enrollment to Intune, based on your co-management settings in the ConfigMgr console.

Feedback

We hope you find this session useful. We'd love your feedback and ideas for future sessions so please fill out this short survey. Thank you!

 

0 Replies