microsoft intune
503 TopicsBest approach for migrating AD joined devices to Entra ID without wiping user profiles?
We’ve seen many organizations struggle with device migration when moving from traditional Active Directory (AD) or hybrid environments to Microsoft Entra ID. The biggest challenge is avoiding user disruption especially when wiping devices causes profile loss, app reconfiguration, and downtime. In large environments, wipe-and-reload becomes difficult to scale and impacts productivity significantly. Curious to know how others are handling this: Are you still using wipe/reimage methods, or are you using alternative approaches that preserve user profiles, applications, and settings? Would love to hear practical experiences from the community.951Views2likes8CommentsFeature Request: Extend Security Copilot inclusion (M365 E5) to M365 A5 Education tenants
Background At Ignite 2025, Microsoft announced that Security Copilot is included for all Microsoft 365 E5 customers, with a phased rollout starting November 18, 2025. This is a significant step forward for security operations. The gap Microsoft 365 A5 for Education is the academic equivalent of E5 — it includes the same core security stack: Microsoft Defender, Entra, Intune, and Purview. However, the Security Copilot inclusion explicitly covers only commercial E5 customers. There is no public roadmap or timeline for extending this benefit to A5 education tenants. Why this matters Education institutions face the same cybersecurity threats as commercial organizations — often with fewer dedicated security resources. The A5 license was positioned as the premium security offering for education. Excluding it from Security Copilot inclusion creates an inequity between commercial and education customers holding functionally equivalent license tiers. Request We would like Microsoft to: Confirm whether Security Copilot inclusion will be extended to M365 A5 Education tenants If yes, provide an indicative timeline If no, clarify the rationale and what alternative paths exist for education customers Are other EDU admins in the same situation? Would appreciate any upvotes or comments to help raise visibility with the product team.700Views13likes3CommentsBest approach to detect multiple user accounts signing in from the same physical device
Hi Everyone, Working on environment: D365 Finance & Operations (cloud). Goal: I need to detect when more than one Dynamics user account is being used from the same physical device, and ideally count how many distinct users are active on that device. The business reason is this is not permissible to login with more than one account in the same device. For example: User X has device D1, User Y has device D2. User X logged in with his account using Device D2 (which is user's Y device). I want to know if this happened, cause it's not permissible behavior in the organization. For more illustration some users have blank devices id when I see Microsoft Entra. Or if I could find out when a user logs in and integrate it with D365 F&O to store the device the user logged into in a custom log table or anything that tells me that this user account is opened on more than one device or this device has more than one logged-in user account. .96Views0likes1CommentMoved to June > MSFT Skills in Action: Intune, AI‑Powered Power Apps, & Career Pathways in Tech
Rescheduling from May -> The Ananse Tech Community June 2026 Monthly Meeting brings together learners, technologists, and community members for an engaging evening focused on Microsoft technologies, practical skill-building, and the value of community within the Microsoft ecosystem. This month’s event features beginner‑friendly technical sessions with live demos, including an introduction to Microsoft Intune for modern device management and a hands‑on look at AI‑assisted Power Apps development using Power Platform tools. In addition to technical learning, the event includes a community-focused session highlighting the importance of tech communities in career growth, knowledge sharing, mentorship, and giving back. Together, these sessions reflect Ananse’s mission to make Microsoft knowledge accessible while strengthening the connections that help individuals and communities grow! --------------- Topic Details ---------------- Topic Title: AI-Assisted Canvas App Development: Leveraging Claude AI in Power Apps Description This session demonstrates a practical approach to building Power Apps canvas applications using Claude AI as a development partner. We’ll cover app architecture, data integration, UI design, and formula generation, showing how AI can reduce development time while improving quality. Perfect for Power Platform developers aiming to enhance productivity and innovation. Speaker: Tchesco Ayih About the Speaker Ayih Tchesco is a Microsoft Certified Trainer (MCT), Microsoft MVP, and experienced technology speaker specializing in the Microsoft Power Platform. With a strong background in building business solutions using Power Apps, Power Automate, Power Pages, Dataverse, and Copilot Studio, he empowers individuals and organizations to unlock the full potential of low-code and AI-driven development. ---- Topic Title: Microsoft Intune 101: Managing Devices the Modern Microsoft 365 Way Description As more people work remotely and across multiple devices, organizations need simple ways to manage and protect their laptops and phones. In this beginner‑friendly session, we’ll introduce Microsoft Intune and explain how it fits into the Microsoft 365 ecosystem. You’ll learn what Intune is, the types of devices it manages, and why it’s becoming a must‑know skill for modern IT and Microsoft professionals. Speaker: Wilfred Andrew Delamy About the Speaker n accomplished IT systems engineer, educator, and community builder with over 17 years of experience in enterprise technology and Microsoft ecosystems. His expertise spans Azure Administration, Office 365, Windows Server, Active Directory, Intune, and enterprise servers and storage systems from HP, IBM, Dell, EMC, and Oracle Sun. Beyond his technical career, Wilfred is deeply committed to education and empowerment. He is the founder and content creator of Kou Louise Academy, a nonprofit e-learning initiative created in memory of his grandmother, dedicated to making IT education free and accessible worldwide. Through this platform, he mentors aspiring technologists, helping them gain the skills needed to launch successful careers in technology. Wilfred’s passion for knowledge sharing extends to his work as a former Microsoft Certified Trainer and an active community organizer. He regularly contributes tutorials, workshops, and online content—including his YouTube channel—to inspire learners and professionals alike. Blending technical mastery with a vision for inclusive education, Wilfred continues to shape both the IT industry and the communities he serves, embodying the belief that “education should be free.” ---- Title: Breaking Into Tech: My Career Journey, Lessons Learned & Practical Description: How do you break into tech—and grow once you’re there? In this Ananse Tech Community spotlight, Segu Essandoh shares his personal career journey into the tech industry, including how he got started, the pivots he made along the way, and the lessons he learned navigating real‑world roles and challenges. This session is designed for students, career‑switchers, and early‑career professionals looking for honest insight, practical tips, and encouragement from someone who’s walked the path. Speaker: Segu Essandoh About the Speaker Segu Essandoh is currently Co-CEO of Sesa Technology, Ltd., focused on consulting, training, development, and other tech services and CTO for NTC Tech Consultancy, LLC, another Microsoft Partner company with similar focus. Segu is an accomplished speaker, founder, tech leader, event organizer, and advocate. As far as community, Segu is co-founder of Ananse Tech community, the Ghana-based tech community for Microsoft tech professionals, and The Microsoft Productivity Power Hour, the tech community for business leaders and owners.250Views0likes3CommentsI built a free, open-source M365 security assessment tool - looking for feedback
I work as an IT consultant, and a good chunk of my time is spent assessing Microsoft 365 environments for small and mid-sized businesses. Every engagement started the same way: connect to five different PowerShell modules, run dozens of commands across Entra ID, Exchange Online, Defender, SharePoint, and Teams, manually compare each setting against CIS benchmarks, then spend hours assembling everything into a report the client could actually read. The tools that automate this either cost thousands per year, require standing up Azure infrastructure just to run, or only cover one service area. I wanted something simpler: one command that connects, assesses, and produces a client-ready deliverable. So I built it. What M365 Assess does https://github.com/Daren9m/M365-Assess is a PowerShell-based security assessment tool that runs against a Microsoft 365 tenant and produces a comprehensive set of reports. Here is what you get from a single run: 57 automated security checks aligned to the CIS Microsoft 365 Foundations Benchmark v6.0.1, covering Entra ID, Exchange Online, Defender for Office 365, SharePoint Online, and Teams 12 compliance frameworks mapped simultaneously -- every finding is cross-referenced against NIST 800-53, NIST CSF 2.0, ISO 27001:2022, SOC 2, HIPAA, PCI DSS v4.0.1, CMMC 2.0, CISA SCuBA, and DISA STIG (plus CIS profiles for E3 L1/L2 and E5 L1/L2) 20+ CSV exports covering users, mailboxes, MFA status, admin roles, conditional access policies, mail flow rules, device compliance, and more A self-contained HTML report with an executive summary, severity badges, sortable tables, and a compliance overview dashboard -- no external dependencies, fully base64-encoded, just open it in any browser or email it directly The entire assessment is read-only. It never modifies tenant settings. Only Get-* cmdlets are used. A few things I'm proud of Real-time progress in the console. As the assessment runs, you see each check complete with live status indicators and timing. No staring at a blank terminal wondering if it hung. The HTML report is a single file. Logos, backgrounds, fonts -- everything is embedded. You can email the report as an attachment and it renders perfectly. It supports dark mode (auto-detects system preference), and all tables are sortable by clicking column headers. Compliance framework mapping. This was the feature that took the most work. The compliance overview shows coverage percentages across all 12 frameworks, with drill-down to individual controls. Each finding links back to its CIS control ID and maps to every applicable framework control. Pass/Fail detail tables. Each security check shows the CIS control reference, what was checked, what the expected value is, what the actual value is, and a clear Pass/Fail/Warning status. Findings include remediation descriptions to help prioritize fixes. Quick start If you want to try it out, it takes about 5 minutes to get running: # Install prerequisites (if you don't have them already) Install-Module Microsoft.Graph, ExchangeOnlineManagement -Scope CurrentUser Clone and run git clone https://github.com/Daren9m/M365-Assess.git cd M365-Assess .\Invoke-M365Assessment.ps1 The interactive wizard walks you through selecting assessment sections, entering your tenant ID, and choosing an authentication method (interactive browser login, certificate-based, or pre-existing connections). Results land in a timestamped folder with all CSVs and the HTML report. Requires PowerShell 7.x and runs on Windows (macOS and Linux are experimental -- I would love help testing those platforms). Cloud support M365 Assess works with: Commercial (global) tenants GCC, GCC High, and DoD environments If you work in government cloud, the tool handles the different endpoint URIs automatically. What is next This is actively maintained and I have a roadmap of improvements: More automated checks -- 140 CIS v6.0.1 controls are tracked in the registry, with 57 automated today. Expanding coverage is the top priority. Remediation commands -- PowerShell snippets and portal steps for each finding, so you can fix issues directly from the report. XLSX compliance matrix -- A spreadsheet export for audit teams who need to work in Excel. Standalone report regeneration -- Re-run the report from existing CSV data without re-assessing the tenant. I would love your feedback I have been building this for my own consulting work, but I think it could be useful to the broader community. If you try it, I would genuinely appreciate hearing: What checks should I prioritize next? Which security controls matter most in your environment? What compliance frameworks are most requested by your clients or auditors? How does the report land with non-technical stakeholders? Is the executive summary useful, or does it need work? macOS/Linux users -- does it run? What breaks? I have tested it on macOS, but not extensively. Bug reports, feature requests, and contributions are all welcome on GitHub. Repository: https://github.com/Daren9m/M365-Assess License: MIT (free for commercial and personal use) Runtime: PowerShell 7.x Thanks for reading. Happy to answer any questions in the comments.3.8KViews2likes2Comments