Intune Configurations
Budget: $30 – $250 USD
Intune documentation needed for setting up the below-mentioned scenario:
We have already set up some of the settings below.
Key Requirements:
Having four groups in Entra, we need to assign the users to enforce the necessary policies for the following user groups.
The users are assigned to one mobile device management group and to one device management group
Mobile device management group:
a) BYOD Mobile Devices (the user account is added to this group if he is using a BYOD iOS Device)
b) Corporate Mobile Devices (the user account is added to this group if he is using a Corporate iOS Device)
Workstation devices group
a) BYOD Workstation Devices (the user account is added to this group if he is using a BYOD Windows 11)
b) Corporate Workstation Devices (the user account is added to this group if he is using a Corporate Windows 11 Device)
We need the following policies - configurations:
BYOD Mobile Devices:
- Typically this is the use-case when they install Teams, and are using iOS Native E-Mail Application for accessing corporate data.
Needed configurations and policies:
a) Device to be encrypted
b) Device to be accessible via 4 digit PassCode
Corporate Mobile Devices:
- Typically, this is the use-case when the users have corporate-purchased mobile devices (We do have the list of the users using corporate devices and also the Serial Numbers of the Corporate Mobile Devices)
a) Devices must be enrolled into full MDM Solution
b) Defender is a must for the devices
c) Only from compliant devices can be accessed Teams and Outlook
BYOD Windows 11 Workstations :
- Typically, this is the use-case when they log into Microsoft 365 Services from their own laptop. Also, there are cases when they Install Teams and Office using the corporate license on these devices.
Needed configurations and policies:
We need to ensure that either only using Exchange OWA, the devices will be triggered to get MDM Intune Managed:
a) The Device to be encrypted via BitLocker
b) The device to be up-to-date and should push the update via Intune Rings
Corporate Windows 11 Workstations :
- Typically, this is the use-case when the users have corporate-purchased Windows 11 workstations (We do have the list of the users using corporate devices and also the Serial Numbers of the Corporate Laptops)
a) The Device to be encrypted via BitLocker
b) The device to be up-to-date and should push the update via Intune Rings
c) The device should be Entra joined and triggered to be Intune-managed
d) Defender must be enforced
Because of GDPR and Security Reasone, we are not able to give access to the tenant, so we need a step-by-step document based on which we configure this.
We have already set up some of the settings below.
Key Requirements:
Having four groups in Entra, we need to assign the users to enforce the necessary policies for the following user groups.
The users are assigned to one mobile device management group and to one device management group
Mobile device management group:
a) BYOD Mobile Devices (the user account is added to this group if he is using a BYOD iOS Device)
b) Corporate Mobile Devices (the user account is added to this group if he is using a Corporate iOS Device)
Workstation devices group
a) BYOD Workstation Devices (the user account is added to this group if he is using a BYOD Windows 11)
b) Corporate Workstation Devices (the user account is added to this group if he is using a Corporate Windows 11 Device)
We need the following policies - configurations:
BYOD Mobile Devices:
- Typically this is the use-case when they install Teams, and are using iOS Native E-Mail Application for accessing corporate data.
Needed configurations and policies:
a) Device to be encrypted
b) Device to be accessible via 4 digit PassCode
Corporate Mobile Devices:
- Typically, this is the use-case when the users have corporate-purchased mobile devices (We do have the list of the users using corporate devices and also the Serial Numbers of the Corporate Mobile Devices)
a) Devices must be enrolled into full MDM Solution
b) Defender is a must for the devices
c) Only from compliant devices can be accessed Teams and Outlook
BYOD Windows 11 Workstations :
- Typically, this is the use-case when they log into Microsoft 365 Services from their own laptop. Also, there are cases when they Install Teams and Office using the corporate license on these devices.
Needed configurations and policies:
We need to ensure that either only using Exchange OWA, the devices will be triggered to get MDM Intune Managed:
a) The Device to be encrypted via BitLocker
b) The device to be up-to-date and should push the update via Intune Rings
Corporate Windows 11 Workstations :
- Typically, this is the use-case when the users have corporate-purchased Windows 11 workstations (We do have the list of the users using corporate devices and also the Serial Numbers of the Corporate Laptops)
a) The Device to be encrypted via BitLocker
b) The device to be up-to-date and should push the update via Intune Rings
c) The device should be Entra joined and triggered to be Intune-managed
d) Defender must be enforced
Because of GDPR and Security Reasone, we are not able to give access to the tenant, so we need a step-by-step document based on which we configure this.