Jump to content

Recommended Posts

Posted

So, I used to know InTune pretty well, about 6 years back I used it to set device restrictions (Pin detection, encryption and the like) for staff who wanted to automatically sync their email to phones. This has worked as expected, downloading the Company Portal app and profile to ensure compliance. I’ve been looking around InTune with a view to enrolling our DfE managed devices into our tenancy, I now realise my understanding of InTune is very out of date.

 

For a start I can’t even find the policy that is being applied to staff accounts for their personal devices, anymore. I have found everything I think I need in Endpoint Manager and I can see the InTune managed devices, but I can’t see what polices are applied to them. I also search by user, can see their devices, but can’t see any policies that are applicable to the user or device. In Endpoint Manager, all of these devices show as being Personal and Managed by Intune.

 

I’m not sure if I should be concerned or not but in AAD > Devices I can also see loads more devices including student ones. I think these are personal devices and are showing because they have had O365 activated on them. They are all listed as Azure AD Registered, I am just concerned if I should have any visibility of these devices at all. Also, with all of this in mind, do I need to be making any changes to prevent personal Windows devices from being Azure AD Joined. i.e. if they use their school credentials in the OOBE, I believe it may Azure AD Join it.

 

All this and I haven’t even attempted to join a DfE device yet!

Posted

If your DfE devices have shipped unmanaged then I suggest you AutoPiliot them:

 

https://oofhours.com/?s=autopilot (this is the guy who, while he worked for MS, wrote the scripts that make this possible)

 

https://docs.microsoft.com/en-us/mem/autopilot/ (official documentation)

 

Microsoft filter the data you can see from personal devices, so even if they are taking policy (for example Defender) you don't get the deep telemetry from them that you get from "corporate" owned devices.

Posted
If your DfE devices have shipped unmanaged then I suggest you AutoPiliot them.

 

DfE devices are currently managed, I have a list of all the hardware hashes but I think I need to let them know when I want to enrol specific devices. I don't believe you can just register a device if it is already associated with another tenancy.

 

Regarding the Azure AD Registered devices, I was just wondering if this was actually expected behaviour or if something I have done in the past has caused devices to show this way.

Posted
Yes it is expected behaviour im afraid.

 

Thanks for confirming @deano, I just wanted to ensure that it wasn't because of something I have done.

 

I still can't find why personal devices are still downloading the company portal and profile, I know I set this years ago but I don't see a single actively applied policy that would be making this happen. This is mainly an issue because I want to ensure that students can't enrol their devices in Intune, or at least not until we review and raise awareness of what this means for them if they do chose to do so. Oh the joys of trying to refamiliarize yourself to a system on a live environment!

Posted
Its more than likely because the previous settings are now not applicable in the new structure. I personally would open a ticket with Microsoft through your Office365 portal
  • Thanks 1
Posted
Its more than likely because the previous settings are now not applicable in the new structure. I personally would open a ticket with Microsoft through your Office365 portal

 

Bumping my own thread, in case it helps anyone else.

 

I have actually just rediscovered the policies I created years ago. If you find yourself in a similar situation you can find old policies like this under: Endpoint Manager> Conditional Access> Classic Policies

 

The policies will not necessarily have the same name as you gave them in the old Azure / Intune interface. All you can do with them is view or disable, this article outlines everything: https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/policy-migration

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...