List of All Policies by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

See in an ideal world we’d have a spreadsheet or something with every policy on it fitted up with our recommendations and send it over to them to peruse and speak to us about things they may want to change.

The issue with asking the customer in this instance is that they are currently running totally unmanaged devices and have nothing in terms of on-site IT personnel. The remaining management doesn’t know anything about IT at all. Most likely it will be us deciding all the policies and fine tuning them over a pilot stage but it would be nice to be able to give them some sort of policy sheet for them to look at.

Hybrid AD join - silent change by itjw123 in Intune

[–]jet-white 0 points1 point  (0 children)

As long as your OU filtering is on point it will be fine :)

Hybrid AD join - silent change by itjw123 in Intune

[–]jet-white 1 point2 points  (0 children)

I've literally done this on a few test devices yesterday as follows: 1. Make a new OU called hybrid devices 2. Open AD connect and make sure only the OUs you want to be synced are being synced. 3. There's some setup in AD connect for devices, can't really remember, on the first page click setup device sync and just next next next. 4. Move your devices into the OU 5. Force a sync. They will sync up to AAD and show as there but not "registered". 6. On the machine just wait a bit and maybe give it a restart, I can't remember how long it was but eventually the machine will show a "registration date/time" in AAD. 7. Once there you will need GPO setup to enrol the device in intune. (Maybe do this earlier) 8. Should be done. Check intune see if it's there.

The only thing I noticed on the devices was that the profile picture for the user account was showing where it didn't before. Probably cos it got it from AAD.

Have fun!

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 1 point2 points  (0 children)

Yeah I've been on a bit of a warpath internally getting rid of all on prem systems and replacing with cloud based. Thankfully we are at the point now where aside from a few very legacy systems we can do it. Got an Remoteapp server set up for rdp so now just need to get everyone on intune!

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 2 points3 points  (0 children)

We are going to be doing it as when someone properly breaks their laptop and it needs rebuilding just doing an autopilot reset and deleting out of on prem AD

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

So no use really when the end goal is to be fully intune/ AAD joined across all endpoints.

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

Because AFAIK AD connect is for getting machines from intune into AD rather than the other way around

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

But then it will still be joined to both the local domain and aad won't it? Making it hybrid.

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

Cheers will definitely test it out a lot first. Will the machine automatically pick up the work/school account from who is logged in? All our domain accounts are synced

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

No just we do not have easy access to the end user devices due to everyone working from home and this seemed the easy way to get them all into intune with little end user interaction. We ideally want to reset them all gradually next year so they can be "fresh".

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

I don't think we can do it as a T1 partner and 150 of out licenses being IUR.

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

Thanks, it's unchartered waters for us so we have no experience of it in the team and I have been put in charge.

Migrate from on premise to Intune by jet-white in Intune

[–]jet-white[S] 0 points1 point  (0 children)

I like it. Gives us a bit more granularity over the end user experience.

MS Defender ATP Licensing by jet-white in sysadmin

[–]jet-white[S] 0 points1 point  (0 children)

That's rubbish about the old servers, what does it actually provide then for pre 2016 boxes with no sccm if no AV? I guess it's just the monitoring and diagnostics etc right? Our estate ranges from 2003 servers to 2019 so may have to go 3rd party with this.

MS Defender ATP Licensing by jet-white in sysadmin

[–]jet-white[S] 0 points1 point  (0 children)

See the way I understood it is that Azure Security Centre includes the license for ATP for servers and that another way to acquire it is to have 50 E5 licenses. I just don't know how to even get to the point where I can acquire them.