Intune deployment help

%3CLINGO-SUB%20id%3D%22lingo-sub-1436078%22%20slang%3D%22en-US%22%3EIntune%20deployment%20help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1436078%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20there%2C%3C%2FP%3E%3CP%3EIm%20new%20to%20the%20Intune%20and%20would%20like%20to%20roll%20out%20just%20for%20the%20laptop%20for%20now%20and%20later%20for%20cell%20phone%20and%20desktop.%3C%2FP%3E%3CP%3EI%20was%20able%20to%20work%20on%20the%20azure%20and%20was%20able%20to%20hybrid%20join%20for%20the%20laptops.%20Now%20I%20would%20like%20to%20know%20what%20direction%20I%20should%20move%20or%20the%20best%20practice%20to%20securing%20my%20laptops%20with%20less%20hassle%20or%20is%20possible%20zero%20touch%20deployment%20%3F%3C%2FP%3E%3CP%3EI%20would%20like%20to%20secure%20the%20laptops%20in%20all%20cases%20ie%2C%20check%20for%20compliance%20polices%2C%20make%20sure%20windows%20up%20to%20date%2C%20Anti%20Virus%2C%20enable%20bitlocker%20and%20also%20would%20like%20to%20push%20out%20some%20bookmarks%20and%20basic%20apps%20like%20chrome%2C%20anti%20virus%2C%20office%20365%20apps.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1436078%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1439026%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20deployment%20help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1439026%22%20slang%3D%22en-US%22%3EHi%20Sam%2C%3CBR%20%2F%3E%3CBR%20%2F%3EDevice%20Compliance%20Policies%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22http%3A%2F%2Fwww.rebeladmin.com%2F2018%2F12%2Fstep-step-guide-microsoft-intune-device-compliances%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttp%3A%2F%2Fwww.rebeladmin.com%2F2018%2F12%2Fstep-step-guide-microsoft-intune-device-compliances%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EEnable%20Silent%20Bitlocker%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.inthecloud247.com%2Fwindows-10-failed-to-enable-silent-encryption%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.inthecloud247.com%2Fwindows-10-failed-to-enable-silent-encryption%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EBookmarks%20on%20Edge%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.inthecloud247.com%2Fcontrolling-managed-favorites-for-edge-with-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.inthecloud247.com%2Fcontrolling-managed-favorites-for-edge-with-microsoft-intune%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EInstall%20Office%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fallthingscloud.blog%2Fdeploy-office-365-with-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fallthingscloud.blog%2Fdeploy-office-365-with-microsoft-intune%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EInstall%20Chrome%2C%20same%20principle%20apply%20for%20other%20exe%20or%20MSI%20files%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fwww.robinhobo.com%2Fhow-to-deploy-win32-applications-with-microsoft-intune%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.robinhobo.com%2Fhow-to-deploy-win32-applications-with-microsoft-intune%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EGood%20luck!%3CBR%20%2F%3EHope%20this%20helps!%3CBR%20%2F%3EMoe%3CBR%20%2F%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1436120%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20deployment%20help%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1436120%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F680062%22%20target%3D%22_blank%22%3E%40samcook%3C%2FA%3E%26nbsp%3BThis%20should%20get%20you%20started%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.edx.org%2Fcourse%2Fwindows-10-features-for-a-mobile-workforce-windows%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.edx.org%2Fcourse%2Fwindows-10-features-for-a-mobile-workforce-windows%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hi there,

Im new to the Intune and would like to roll out just for the laptop for now and later for cell phone and desktop.

I was able to work on the azure and was able to hybrid join for the laptops. Now I would like to know what direction I should move or the best practice to securing my laptops with less hassle or is possible zero touch deployment ?

I would like to secure the laptops in all cases ie, check for compliance polices, make sure windows up to date, Anti Virus, enable bitlocker and also would like to push out some bookmarks and basic apps like chrome, anti virus, office 365 apps.

7 Replies
Highlighted
Highlighted
If you are getting started in Intune, check out the Intune.Training Youtube series.
It's created by MVP's which go over every aspect from Intune
Highlighted

@Moe_Kinani 

 

Hello

 

Thank you for your reply but none of these guide shows how to manage AAD hybrid join PCs/Laptop.

 

I'd setup the Deployment profile in Intune Portal and assign it to the test computer groups but none of the PCs are showing up there.

I also add some security policies and compliance polices and not seeing delivered to the PC at all.

 

BTW, Im not testing within the domain network, I've joined the PC to domain and setup for AAD hybrid and now I want to see how can I manage that PC outside of corporate network. But none of my test PCs are showing up under Intune managed device, what Im doing wrong here ?

Highlighted
Hi Sam,

The Config Policies that I sent apply to AAD and Hybrid AAD.

In order to see your pcs in Intune devices, you need to enroll them to intune (This Applies to all existing PCs that not enrolled with AutoPilot)

https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enroll

https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatica...

You can also enroll the PCs manually (not from gpo) from Work or School Accounts-> I think Device Enrollment.

I usually prefer to sync devices to AAD so I can assign the policies for Devices not users.

Hope this helps!
Moe
Highlighted

Thanks Moe,

 

I followed your recommendations and was very helpful but still need you're help ..

 

On my GPO policy I've setup the 'Device Credentials' which doesn't assign the MDM licenses automatically even I dynamic security group to look for AAD hybrid join and assign license.

And If I change the GPO to 'User Credentials' It works fine and assign the licenses as soon as user logs in.

 

But I don't was to go with the second method, I want the GPO as device credentials so devices get the MDM.

What could be the wrong with first method ?

 

 

Highlighted
This policy applied to Windows 10 1903 or later. My recommendation, upgrade to the latest version and it should work.

Moe

https://docs.microsoft.com/en-us/windows/client-management/mdm/enroll-a-windows-10-device-automatica...