Server Enrollment in Intune/Azure

Sumit Kumar Jha 5 Reputation points
2024-07-12T08:19:17.6466667+00:00

Hello,

We have multiple production Servers for Different Purpose, and we are using Azure AD to manage users, and to manage Devices we use Intune I wanted to Know can we apply Security Baseline or other Intune Security Policies on these Servers if Yes then how we can enroll these servers in Intune/Azure AD to apply baseline policy. Does the Server enrollment in Intune required any Licenses for Sever Enrollment.

If this is possible then can you please share the process doc with me for understanding the process because I don't know how to enroll Servers in Intune or Azure AD. I am not seeing option of Work or School account to enroll server into Intune.

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
435 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,374 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,207 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Xenia-MSFT 2,670 Reputation points Microsoft Vendor
    2024-07-15T01:50:43.1966667+00:00

    @Sumit Kumar Jha Thanks for posting in our Q&A.

    Intune doesn't support sever enrollment. For windows, intune only supports windows client. Please refer to the following article:

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/supported-devices-browsers

    Hope it is helpful.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Sumit Kumar Jha 5 Reputation points
    2024-08-01T06:41:33.6733333+00:00

    Hi Xenia-MSFT
    Sorry for delay in response I did not get the answer that I was looking for.

    Intune doesn't support sever enrollment. For windows, Intune only supports windows client. Please refer to the following article:

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/supported-devices-browsers

    Can you tell me does ASR and Defender Policy Supported by Windows Server if Yes How we can apply this policy to Servers and does this required additional separate Licenses Like Business Premium, E3, E5?

    Can you share process doc for ASR and Defender Policy for the Servers?

    0 comments No comments

  3. Xenia-MSFT 2,670 Reputation points Microsoft Vendor
    2024-08-08T02:09:58.8133333+00:00

    @Sumit Kumar Jha Currently devices on the Windows Server platform don’t support mobile device management (MDM) and can’t enroll in Microsoft Intune. With the Microsoft Defender for Endpoint (MDE) Security Management feature, Windows Servers can receive security management policies from Intune.

    https://learn.microsoft.com/en-us/mem/intune/protect/mde-security-integration

    So, ASR and Defender Policy are supported by Windows Servers.

    For ASR, please refer to the following article:

    https://learn.microsoft.com/en-us/mem/intune/protect/endpoint-security-asr-policy

    It is needed to have Windows 10 Enterprise E5 or E3 License. Although attack surface reduction rules don't require a Windows E5 license, with a Windows E5 license, you get advanced management capabilities including monitoring, analytics, and workflows available in Defender for Endpoint, as well as reporting and configuration capabilities in the Microsoft Defender XDR portal. These advanced capabilities aren't available with an E3 license, but you can still use Event Viewer to review attack surface reduction rule events. So, choosing an E5 or E3 license depends on whether you need advanced management capabilities.

    https://learn.microsoft.com/en-us/defender-endpoint/enable-attack-surface-reduction#requirements

    Hope it is what you want.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.