Microsoft Intune Deployment & Optimization

Job ID: 40106768

Budget: ₹12,500 – ₹37,500 INR

1 Microsoft Intune Professional Services (Project Scope)

• Plan for the required privileged users.

• Identify pilot users & devices representing different departments.

• Develop a detailed project action plan.

• Develop a communication plan that includes informing all relevant stakeholders about the deployment process.

• Schedule regular meetings to discuss project progress and address any issues.

• Setup remediation plan, Timeline, and checkpoints.

• Prepare a rollback plan in case any issues or unforeseen problems arise during migration
Environment Assessment

• Currently, Marketing Co is using TrendMicro Endpoint security. But they will replace it with
MDE.

• Review existing Intune and Defender for Endpoint deployments, including integration with Microsoft
365 Defender and Microsoft Entra ID.

• Assess enrolled devices (Windows 10, 11) to validate enrollment methods, sensor deployment, and endpoint visibility.

• Evaluate role-based access control (RBAC) settings within Intune and Microsoft 365 Defender for proper segregation of duties.

• Verify policy alignment with organizational needs and Microsoft best practices.

2- Microsoft Intune

• Review device enrollment restrictions, auto-enrollment configurations, and group assignment.

• Review device compliance policies (passwords, encryption, OS health, minimum OS versions).

• Assess configuration profiles (Wi-Fi, VPN, certificates, email, restrictions).

• Evaluate update rings and feature update policies for OS patching.

• Validate application deployment for LOB apps, Office apps, and Store apps.

• Review security baselines applied across devices and compare against Microsoft recommendations.

• Review and fine-tune Conditional Access integration to enforce Zero Trust principles.

• Review Mobile Application Management (MAM) and App Protection Policies for data protection on
BYOD mobile devices (iOS, Android).

• Validate reporting dashboards for visibility into compliance and device health.

3- Microsoft Defender for Endpoint

• Marketing Co Team will be responsible for removing current TrendMicro agents.

• Review real-time protection, cloud delivered protection, and sample submission settings.

• Validate antivirus exclusions and ensure they follow Microsoft best practices

• Review Windows Defender Firewall policies.

• Validate configuration of web protection and network filtering features.

• Deploy ASR rules to devices and confirm enforcement mode (audit or block).

• Review controlled folder access settings to protect sensitive data.

• Assess exploit protection rules and custom mitigation policies.

• Review EDR sensor configuration and data collection.

• Assess configuration of live response capabilities and isolation policies.

• Review use of device control policies (e.g., removable storage, printer control, Bluetooth).

4- Microsoft Defender for Servers MDE Configuration

• Collect Total count of servers by operating system version.

• Identify the management engine name that will be used for configuration.

• Organize devices into groups:

• Deploy application control policies.