Windows 10 enrollment in Intune

SM 21 Reputation points
2021-10-28T06:18:19.11+00:00

Hi,

Question is not about the steps but conceptional. When someone has onprem AD and doing Hybrid Azure AD Join and want to Intune enroll(No SCCM). What kind of policies need to be used we know group policies are coming from AD Already, so what will be best practice we can use from Intune enrollment for Windows 10 apart from Auto-pilot.

thanks

SM

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,715 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-10-28T14:37:10.357+00:00
    0 comments No comments

  2. SM 21 Reputation points
    2021-10-28T22:10:37.933+00:00

    Thanks Jason, may be my question wasn't clear. I know how to do hybrid azure ad join and steps involved in it.
    Question is.
    1- When device is enrolled in Intune and hybrid azuread join, best practice is still to use GPO for normal computer policies?
    2- If yes, then in this situation, what kind of policies/configuration profiles are recommended from Intune itself

    Thanks

    SM


  3. Crystal-MSFT 42,956 Reputation points Microsoft Vendor
    2021-10-29T01:35:39.797+00:00

    @syedfasial-7607, For your questions, here are my answers for the reference:
    Q1- When device is enrolled in Intune and hybrid azured join, best practice is still to use GPO for normal computer policies?
    A1: Autopilot Hybrid Hybrid Azure AD join is available for devices that must be joined to both Azure Active Directory and your on-prem Active Directory domain. This is done during the OOBE (out-of-box-experience) in Windows 10. Meaning its meant for new devices or existing devices that you either re-image, re-install or reset the device. For Autopilot, we can also configure whether users are administrators or standard users on the device. we can see more details in the following link:
    https://learn.microsoft.com/en-us/mem/autopilot/windows-autopilot

    For GPO enrollment, this is usually for existing devices. When the GPO is applied, a task scheduler will be created to do the enrollment for current logging user. There's no need to reset.

    If we don't want to reset the device, we can choose GPO enrollment. For new devices, we can choose Autopilot to set and pre-configure the new devices.

    Q2- If yes, then in this situation, what kind of policies/configuration profiles are recommended from Intune itself
    A2: For configuration policy, we can configure it according to our requirement. They are some settings we can enable or configure on devices in a batch via Intune. We can see the different types of profiles we can create in the following link:
    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profiles

    Meanwhile, in Intune, we can also manage apps, set app protection policy, configure compliance policy which help protect organizational data by requiring users and devices to meet some requirements. Here are the docs about Intune we can read for the reference:
    https://learn.microsoft.com/en-us/mem/intune/

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments