newbie needs help with policies and enrolling users/devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1166885%22%20slang%3D%22en-US%22%3Enewbie%20needs%20help%20with%20policies%20and%20enrolling%20users%2Fdevices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166885%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI%20am%20sort%20of%20new%20to%20Intune%20and%20Azure%20AD%2C%20and%20I%20am%20trying%20to%20understand%20the%20best%20I%20can%20how%20things%20work.%20My%20company%20is%20small%20and%20I%20only%20have%20so%20much%20time%20to%20put%20into%20it-administration%2C%20but%20I%20really%20would%20like%20some%20things%20to%20work.%20Now%2C%20they%20do%20not.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPrimarily%2C%20I%20want%20to%20to%20be%20able%20to%20configure%20Edge%20policies%20and%20a%20client%20app%20for%20selected%20user%20groups.%20And%20I%20think%20the%20devices%20(or%20users%3F)%20must%20be%20connected%20to%20Intune%20to%20accomplish%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20did%20manage%20to%20enroll%20my%20own%20computer%20to%20intune%20using%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fenrollment%2Fquickstart-enroll-windows-device%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20guide%3C%2FA%3E%2C%20but%20that%20seems%20not%20to%20affect%20the%20Edge%20settings%20in%20the%20computer%2C%20so%20something%20must%20be%20missing%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EDevices%20are%20all%20Windows%2010%20(pro%20or%20enterprise)%20and%20Azure%20joined%3C%2FLI%3E%3CLI%3EThere%20are%20no%20devices%20listed%20in%20Intune.%20All%20users%20are%20listed%20in%20Intune.%3C%2FLI%3E%3CLI%3EAll%20devices%20are%20listed%20in%20Azure.%20All%20users%20are%20listed%20in%20Intune.%3C%2FLI%3E%3CLI%3EWe%20do%20not%20have%20a%20server%20and%20no%20machines%20running%20Windows%20server.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3ECould%20someone%20please%20guide%20me%20to%20how%20I%20should%20proceed%3F%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E---------------------------------------------------%3C%2FP%3E%3CP%3EBackground%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20first%20aim%20is%20to%3C%2FP%3E%3COL%3E%3CLI%3Ea)%20configure%20Edge%20(77%2B)%20for%20my%20company%2C%20and%3C%2FLI%3E%3CLI%3Eb)%20deploy%20an%20app%20via%20Intune%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20configure%20Edge%2C%20I%20have%3A%3C%2FP%3E%3COL%3E%3CLI%3Efollowed%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fdeployedge%2Fconfigure-edge-with-intune%2520%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20guide%3C%2FA%3E%20to%20create%20a%20policy%20(for%20starters%2C%20I%20only%20changed%20and%20activated%20the%20Start%20page%20url%2C%20default%20New%20tab%20url%2C%20and%20Company%20logo%20to%20see%20how%20it%20would%20behave)%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%2216f1540a-5d38-493c-8cb2-8d43fb92466e.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170375iD31181EA453398B6%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%2216f1540a-5d38-493c-8cb2-8d43fb92466e.png%22%20alt%3D%2216f1540a-5d38-493c-8cb2-8d43fb92466e.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FLI%3E%3CLI%3Eand%20then%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fconfiguration%2Fdevice-profile-assign%2520%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ethis%20guide%3C%2FA%3E%26nbsp%3Bto%20assign%20the%20policy%20to%20a%20user%20group.%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22af955f0b-5af2-4238-8232-b7843c01ddff.png%22%20style%3D%22width%3A%20845px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F170374iAFBC676B96244F87%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22af955f0b-5af2-4238-8232-b7843c01ddff.png%22%20alt%3D%22af955f0b-5af2-4238-8232-b7843c01ddff.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20deploy%20the%20app%2C%20I%20have%20followed%20%3CA%20href%3D%22https%3A%2F%2Fwww.altitude365.com%2F2017%2F08%2F18%2Fdefault-template-microsoft-office%2F%22%20target%3D%22_self%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ethis%20guide%3C%2FA%3E%26nbsp%3Bto%20create%20an%20MSI%20that%20I%20have%20uploaded%20to%20the%20app%20catalogue%20in%20Intune%20(%3CA%20href%3D%22https%3A%2F%2Fportal.azure.com%2F%23blade%2FMicrosoft_Intune_Apps%2FMainMenu%2F1%2FselectedMenuItem%2FOverview%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fportal.azure.com%2F%23blade%2FMicrosoft_Intune_Apps%2FMainMenu%2F1%2FselectedMenuItem%2FOverview%3C%2FA%3E)%20and%20assigned%20it%20to%20a%20user%20group.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20%E2%80%93%20neither%20Edge%20policies%20nor%20the%20app%20is%20working%20for%20the%20users%20in%20the%20selected%20group.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1166885%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1166986%22%20slang%3D%22en-US%22%3ERe%3A%20newbie%20needs%20help%20with%20policies%20and%20enrolling%20users%2Fdevices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1166986%22%20slang%3D%22en-US%22%3EHave%20you%20tried%20pushing%20Edge%20through%20the%20built-in%20deployment%3F%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapps%2Fapps-windows-edge%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapps%2Fapps-windows-edge%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EIF%20you%20check%20the%20install%20status%2C%20what%20does%20it%20say%3F%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1167085%22%20slang%3D%22en-US%22%3ERe%3A%20newbie%20needs%20help%20with%20policies%20and%20enrolling%20users%2Fdevices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1167085%22%20slang%3D%22en-US%22%3EDo%20you%20see%20any%20installations%20pending%3F%3CBR%20%2F%3ECan%20you%20please%20provide%20a%20screenshot%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1167076%22%20slang%3D%22en-US%22%3ERe%3A%20newbie%20needs%20help%20with%20policies%20and%20enrolling%20users%2Fdevices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1167076%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3EYes%2C%20I%20have.%20Installation%20status%20says%200%20devices%2C%200%20users.%3C%2FLINGO-BODY%3E
Occasional Contributor

Hi,

I am sort of new to Intune and Azure AD, and I am trying to understand the best I can how things work. My company is small and I only have so much time to put into it-administration, but I really would like some things to work. Now, they do not.

 

Primarily, I want to to be able to configure Edge policies and a client app for selected user groups. And I think the devices (or users?) must be connected to Intune to accomplish this?

 

I did manage to enroll my own computer to intune using this guide, but that seems not to affect the Edge settings in the computer, so something must be missing?

 

  • Devices are all Windows 10 (pro or enterprise) and Azure joined
  • There are no devices listed in Intune. All users are listed in Intune.
  • All devices are listed in Azure. All users are listed in Intune.
  • We do not have a server and no machines running Windows server.

 

Could someone please guide me to how I should proceed?

 

---------------------------------------------------

Background:

 

My first aim is to

  1. a) configure Edge (77+) for my company, and
  2. b) deploy an app via Intune

 

To configure Edge, I have:

  1. followed this guide to create a policy (for starters, I only changed and activated the Start page url, default New tab url, and Company logo to see how it would behave)
    16f1540a-5d38-493c-8cb2-8d43fb92466e.png
  2. and then this guide to assign the policy to a user group.
    af955f0b-5af2-4238-8232-b7843c01ddff.png

 

To deploy the app, I have followed this guide to create an MSI that I have uploaded to the app catalogue in Intune (https://portal.azure.com/#blade/Microsoft_Intune_Apps/MainMenu/1/selectedMenuItem/Overview) and assigned it to a user group.

 

However – neither Edge policies nor the app is working for the users in the selected group.

11 Replies
Have you tried pushing Edge through the built-in deployment?
https://docs.microsoft.com/en-us/intune/apps/apps-windows-edge

IF you check the install status, what does it say?
Hi,
Yes, I have. Installation status says 0 devices, 0 users.
Do you see any installations pending?
Can you please provide a screenshot
Thanks,
No installations pending, as far as I can see. Screenshot attached. (Device and user tabs look the same)
To what group have you assigned this install and how (required, available...)?
Is it a group of devices/users?

Please include a screenshot of the members of the group

@Thijs Lecomte 

Thanks for the effort you put into this :)

It is a user group created for testing, with only one member. Owner of the group (me) is not a member of the group.

 

I thought in the beginning, that adding an app and assigning it to a user group would automatically push it to the user's Azure AD joined devices. But that is maybe not the way it works?

 

The app settings are the same for Edge and the LOB client app (MSI) that I try to deploy.

 

1.png

 

2.png

That is how it should work. So I am a bit confused why it's not working.

You say all your devices are AAD Joined.
Are they also Intune registered?

Do you see them if you go to devicemanagement.microsoft.com => devices ?

@Thijs Lecomte 

 

Devices seem to be either joined or registered. I have used the exactly same method of connecting to AAD with all the computers, but some are registered and some joined (fresh Windows install - log in with Admin user account) The owner, user Admin, is member of the group testgrupp that I have assigned Edge.

2.png

 

No devices appear in Intune, apart from the one computer that I manually added via MDM yesterday (this computer is owned by me, and I am not a member of the testgrupp group.

ewse.png

4.png

 

Intune enrollment is set to Automatic for the user group testgrupp.

kihjnbn.pngergfdg.png

 

Also, no apps appear in the Company portal on a AAD joined device owned by testgrupp member Admin. The Company portal app also says that the device is not configured. (I am not really interested in using the Company portal, this was only a test to see if that would work)

Hi @Mårten Markne 

 

Very strange. All your settings look good and this how I have pushed on my end.

 

For fun, could you please add the workstation to the test group and give it another try?

Moe

 

@Mårten Markne 

 

The device that the user in testgrupp uses needs to be MDM enrolled, otherwise Intune policies won't have any affect.

 

You can manually enroll it into Intune to test it.

@Moe_Kinani 

 

Good to kow it's not me, then :)

 

I created a new group and added two devices: the one that I added manually via MDM yesterday, and another device. I then assigned the group to Edge. However, the group info says there are no device members in the group. I have restarted the two devices.

 

111111111111.png

 

222222222222.png