Mobile Jon's headlines

HEADLINES:

HEADLINES:

Building a Windows 365 Custom Image

Mobile Jon's Blog

Category: Office 365

Windows 11 Best Practices Part Two: Security

The recent security article covered best practices for Windows 11. It stresses personalization of security policies and highlights the significance of the Windows Autopatch feature. Additionally, it addressed the management of security baselines, Microsoft Defender for Endpoint settings, BitLocker usage, personal data encryption, certificate authentication strategies, and device compliance best practices. The emphasis was on utilizing Microsoft Cloud PKI and SCEPman and leveraging custom compliance scripts for specific compliance requirements. This aligns with the focus on modern CSPs and core Intune components for securing Windows 11 effectively. Future chapters will delve into more complex features like EPM, App Control, and Device Control.

Read More »

Windows 11 Best Practices Part One: Onboarding

Windows 11 best practices are often challenging. It’s a loaded question that encompasses many areas. Today, we will focus on onboarding best practices like Windows Autopilot, debloating, imaging, device join, and much more!

Read More »

Demystifying Passkeys and Extending Microsoft Entra with Passwordless Authentication

Passkeys, introduced in Entra, are receiving much attention for their cryptographic and phishing-resistant authentication model. They are user-centric, unique per service, and stored only on the user’s device. Supported by Windows with TPM, they provide strong security and cross-device authentication. Implementing passkeys in Entra and Windows is straightforward, enhancing device security.

Read More »

The Workspace ONE Admin’s Guide to Microsoft Intune Part 4: SECURITY!

In part 4, of the Workspace ONE Admin’s Guide to Microsoft Intune. It covers security capabilities including Windows patching, security baselines, leveraging profiles for security hardening, account protection, conditional access, and remediations. Final thoughts include an upcoming webinar and future articles on API comparisons.

Read More »

Deep Dive into Windows Patching with Microsoft Intune

Microsoft Intune presents a new approach to Windows patching, replacing on-prem servers with Windows Update for Business (WUfB). It offers features like Update Rings, Automatic Update Behavior, and a Deployment Service. Windows Autopatch on Intune automates patch deployment, but requires specific software/licensing. Best-in-class reporting is also available, addressing traditional reporting issues.

Read More »

Securing Local Administration with Microsoft Intune

The article discusses securing local administrators with Microsoft Intune, covering creating the admin account, deploying the LAPS policy, protecting local administration groups, and working with Entra users and groups. It emphasizes the ease of using Intune for these purposes and shares insights on Entra user and group challenges. Overall, it advocates leveraging Microsoft’s EPM alongside Intune for robust security.

Read More »
Scroll to Top