Dave light – systems administrator – Lancaster-Lebanon IU13 Intune for Education Dave light – systems administrator – Lancaster-Lebanon IU13
LLVS Program Currently domain bound Moving to Azure AD Joined Background LLVS Program Currently domain bound Moving to Azure AD Joined
Assign Licenses Enterprise Mobility + Security E3 Azure AD Licenses > Products > EM + Sec e3 > Licensed Groups PowerShell Get-ADGroupMember "CN=EMS License Group,OU=Role Groups,OU=Resources,OU=your,DC=domain,DC=here" | foreach { get-aduser $_.samaccountname | select userprincipalname } | Set-MsolUserLicense -AddLicenses “o365TenantDomain:EMS" https://docs.microsoft.com/en-us/intune/licenses-assign Get-ADGroupMember "CN=EMS License Group,OU=Role Groups,OU=Resources,OU=your,DC=domain,DC=here" | foreach { get-aduser $_.samaccountname | select userprincipalname } | Set-MsolUserLicense -AddLicenses “o365TenantDomain:EMS"
Enable in O365 Set the mDM Authority Setting Enable Device Enrollment – Windows – Automatic enrollment Configure MDM User scope Create CNAME records for windows enrollment - Intune Standalone -https://portal.azure.com/ Choose All services > Intune. Intune is located in the Monitoring + Management section. - Select the orange banner to open the Mobile Device Management Authority setting. - We have ours set to Intune – Intune – Device Enrollment – Top right corner – MDM authority Enable Device Enrollment – Windows – Automatic Enrollment - Azure AD – Mobility – Microsoft Intune Configure MDM User Scope – We have ours set to technology services – specifies which devices can automatically enroll for management with Microsoft Intune Create CNAME – in DNS, below https://docs.microsoft.com/en-us/intune/windows-enroll#simplify-windows-enrollment-without-azure-ad-premium
Setting up Groups AD Groups or Intune only groups Membership Type Assigned Dynamic User Dynamic Device Intune > Groups > All Groups > New Group
Setting up Admins Intune vs Intune for EDU Groups Intune > All Roles > Add Custom Enrollment Managers – Intune vs Intune for EDU Admin Groups > Intune vs Intune for EDU – Intune allows for role based access groups. Intune for EDU is more simplified. Intune > All Roles > Add Custom - Assign Permissions – Save then create Assignments – Set Admin Groups – Set delegated Group to Control Intune for EDU > Groups > Dave Test > Admins > Add Admins
Intune vs Intune for EDU Configure Policies Intune vs Intune for EDU Intune > Device Configuration > Profiles > Default Policies for EDU Intune for EDU > Groups > Settings > Windows Device Settings
Set Up School PC’s App Demo! Create the USB Drive Deploy to new computer Apply Policies Deploy Software
Windows 10 Automatic Re-Deployment Demo re-deploying from the lock screen. Show which policies need set to enable this. Demo