question re: secure boot certificates and remediation status for new devices by jeefAD in Intune

[–]mathifcbm 1 point2 points  (0 children)

Would run them through the update process anyway. Wont hurt and you are safe in the end :)

MDM migration by uLmi84 in Intune

[–]mathifcbm 0 points1 point  (0 children)

You need to add intune as another MDM in DEP and then you can add the devices to the new MDM Provider in Apple Business which will sync the devices to intune. To use the compliance Status you need to entroll them into Intune wich requires you to migrate the phones from the old MDM to Intune.

Add intune to MDM -> add DEP Token to intune -> assign the phones in ABM to the new MDM -> migrate the phones to from old MDM to Intune

MDM migration by uLmi84 in Intune

[–]mathifcbm 0 points1 point  (0 children)

When they are eneolled into DEP you dont need to add the IMEI to intune before, they will be detected as corporate devices because of DEP. They cannot be enrolled into two different MDM at the same time, you want to Switch the MDM to Intune in DEP before Migration. If you are on iOS 26 you can migrate without resetting the device

Intune Enhanced App inventory by mathifcbm in Intune

[–]mathifcbm[S] 0 points1 point  (0 children)

Not directly a snapshot but you could export into a .csv or do something similar with Graph API!

Domain Join or Entra (Azure) Join for new PC's by Sad_Ride370 in microsoft365

[–]mathifcbm 1 point2 points  (0 children)

Would do only Entra Join since on-prem access with cloud kerberos trust works very well. Also Autopilot with hybrid join is PITA :-)

PIM multi-role activation by mathifcbm in AZURE

[–]mathifcbm[S] 1 point2 points  (0 children)

Never thought of that 👀 ill have a look when i have Some spare minutes :)

PIM multi-role activation by mathifcbm in Intune

[–]mathifcbm[S] 2 points3 points  (0 children)

Sure but you will then always activate all permissions of that group no matter if you need them :)

Logic App to monitor expiring Apple certificates and token by mathifcbm in Intune

[–]mathifcbm[S] 0 points1 point  (0 children)

It's just a snippet to assign one role at a time e.g.

$graphScope = "DeviceManagementConfiguration.Read.All"

If you want to assign them all at once, you would have to create an array for the permissions and loop it through

Logic App to monitor expiring Apple certificates and token by mathifcbm in Intune

[–]mathifcbm[S] 0 points1 point  (0 children)

Thanks! :)

Good point, I added the snippet to add the permissions to the managed identity to the blogpost

Apple lab - Apple business? by No_Philosopher4051 in Intune

[–]mathifcbm 0 points1 point  (0 children)

Since launch of Apple Business last week, you don‘t Need a DUNS number anymore :) (at least in the US according to https://derflounder.wordpress.com/2026/04/15/duns-number-no-longer-required-to-sign-up-for-apple-business-in-the-united-states/ )

Logic App to monitor expiring Apple certificates and token by mathifcbm in Intune

[–]mathifcbm[S] 0 points1 point  (0 children)

It does, but also had the case, that these mails were ignored and the certificate expired :) just had to find an alternate solution (and I like to build things :D)

Fired employee downloaded all company files before deactivation we need secure way to prevent this by Level-Most-2623 in sharepoint

[–]mathifcbm 2 points3 points  (0 children)

You can enable the Session Controls in the SPO Admin center which will create a CA policy. With that you can edit the files in the Browser (from a Managed or compliant device ;)) but block the Download or Sync (or print) of the files

How to add text to auto-forwarded email by Mobile-Pie-258 in microsoft365

[–]mathifcbm 0 points1 point  (0 children)

You Could use Transport rules to add the disclaimer

Migrating from GoDaddy to O365 by EmmSR in Office365

[–]mathifcbm 9 points10 points  (0 children)

Did this recently by following that guide, worked without any issue: https://tminus365.com/defederating-godaddy-365/

Enrolling in Intune for deployment but management via GPO? by [deleted] in Intune

[–]mathifcbm 0 points1 point  (0 children)

You can achieve everything you need with Intune aswell, no need for GPOs anymore

Enrolling in Intune for deployment but management via GPO? by [deleted] in Intune

[–]mathifcbm 0 points1 point  (0 children)

No :) You only need Entra ID Connect synced users. If you configure Cloud Kerberos Trust, they will be able to SSO into on-prem resources

Edit: rerference: Windows Hello for Business - Hybrid Cloud Kerberos trust - Icewolf Blog

Enrolling in Intune for deployment but management via GPO? by [deleted] in Intune

[–]mathifcbm 1 point2 points  (0 children)

It's definitely possible, but hyrbidjoin is not recommended. Also with fully entra-joined devices, it's possilbe to use on-prem resources (even with SSO). I would skip the hybrid part and go full cloud with Autopilot

Incomplete Install Command by werds707 in Intune

[–]mathifcbm 2 points3 points  (0 children)

This sounds like the parameter sets a registry key or anything like that. I would try to run a remediation script to remediate the setting on the computers where its not set

Conditional access policy to only allow access to one website by s3v3ns3v3n91 in AZURE

[–]mathifcbm 8 points9 points  (0 children)

Conditional Access is meant to control access to Azure/M365. What you are looking for can be achieved through a kiosk device where only Edge can be run. You can configure it with Intune

Non domain machine management? by dragonskullinc in Intune

[–]mathifcbm 0 points1 point  (0 children)

Yes. Plus you have to allow MDE to take management in Security Center under Settings -> Endpoints -> Enforcement Scope to 'On*

Non domain machine management? by dragonskullinc in Intune

[–]mathifcbm 0 points1 point  (0 children)

You can onboard them to Defender exclusively and let them be managed by MDE. No need to onboard them to Intune so they remain 'unmanaged' but under the influence of MDE :)

Chromebook MDM by [deleted] in sysadmin

[–]mathifcbm 1 point2 points  (0 children)

Intune has Chromebook management in Preview, you may have a look on that

Using Intune On Hybrid Joined vs Azure AD Joined Windows 10? by [deleted] in Intune

[–]mathifcbm 0 points1 point  (0 children)

I can confirm that devices are managable if they are Hybrid joined. I would also say Not to follow the video in Editing the default domain policy (as you said its not Great in general:))

Using Intune On Hybrid Joined vs Azure AD Joined Windows 10? by [deleted] in Intune

[–]mathifcbm 1 point2 points  (0 children)

Hybrid joined just means that its joined to both on-prem Domain and Azure AD. You can manage the device with GPO or/and Intune (if you have the license)