Intune

intune, Security, Windows

Windows 11 Best Practices Part Three: Security Advanced

The latest article delves into advanced security technologies for Windows 11, including Endpoint Privilege Management (EPM), Windows Defender Application Control (WDAC), Application Patch Management, and Device Control. EPM leverages Microsoft Intune and features automatic elevation and reporting capabilities. WDAC focuses on restricting app execution, requiring signed apps, and managing policies. Additionally, it provides a detailed outlook on managing WDAC policies and policy considerations, such as managing internal and 3rd party apps, enforcing code signing, and ensuring a scalable approach. The article also explores options for Windows Application Patch Management and Device Control in Microsoft Defender for Endpoint (MDE), emphasizing the importance of tailoring security capabilities to organizational needs to avoid creating an unmanageable security environment.

Security, Windows

Windows 11 Best Practices Part Two: Security

The recent security article covered best practices for Windows 11. It stresses personalization of security policies and highlights the significance of the Windows Autopatch feature. Additionally, it addressed the management of security baselines, Microsoft Defender for Endpoint settings, BitLocker usage, personal data encryption, certificate authentication strategies, and device compliance best practices. The emphasis was on utilizing Microsoft Cloud PKI and SCEPman and leveraging custom compliance scripts for specific compliance requirements. This aligns with the focus on modern CSPs and core Intune components for securing Windows 11 effectively. Future chapters will delve into more complex features like EPM, App Control, and Device Control.

intune, Security

Deep Dive into Windows Patching with Microsoft Intune

Microsoft Intune presents a new approach to Windows patching, replacing on-prem servers with Windows Update for Business (WUfB). It offers features like Update Rings, Automatic Update Behavior, and a Deployment Service. Windows Autopatch on Intune automates patch deployment, but requires specific software/licensing. Best-in-class reporting is also available, addressing traditional reporting issues.

intune

Securing Local Administration with Microsoft Intune

The article discusses securing local administrators with Microsoft Intune, covering creating the admin account, deploying the LAPS policy, protecting local administration groups, and working with Entra users and groups. It emphasizes the ease of using Intune for these purposes and shares insights on Entra user and group challenges. Overall, it advocates leveraging Microsoft’s EPM alongside Intune for robust security.

intune, Workspace ONE, WS1 Intelligence

The Workspace ONE Admin’s Guide to Microsoft Intune Part 1

The author details their transition from VMware to the Microsoft stack and introduces a series called “The Workspace ONE Admin’s Guide to Intune.” In Part 1, they discuss UEM Core components in both Workspace ONE and Intune, covering infrastructure, device compliance, and integrations. They also compare device enrollment and compliance in both platforms, highlighting their differences and similarities.

The author plans to continue the series with a focus on profiles, policies, and scripts.

intune, Security

Microsoft Cloud PKI: SCEPman Killer?

The post discusses the introduction of Microsoft Cloud PKI as an alternative to SCEPman, highlighting its features, cost comparison, and user experiences. It covers the process of building a Microsoft Cloud PKI Root CA and Issuing CA, deploying certificates, and the platform’s reporting aspects. The author expresses a positive outlook towards Cloud PKI’s capabilities and future implications.

Scroll to Top