Transition to co-management or tenants attach

河瀬 友秀 36 Reputation points
2021-06-24T12:10:56.487+00:00

I currently run Microsoft Endpoint Configration Manager (MECM) and Intune.
We do not co-management or tenants attach.

Currently, I manage Windows 10 (Defender for Anti-Virus / Office365ProPlus / WindowsPatch) with MECM.
MacOS, Android and iOS are managed by Intune.
I also use Defender for endpoint.
Active Directory and Azure AD are in sync. (User synchronization)
Hybrid AD join is not done.

As mentioned above, we use multiple management consoles, so we would like to move to joint management in the future.

・ Is it possible to cancel after implementing tenants attach?
・ Is it possible to cancel after implementing co-management?
・ If it can be canceled, please tell me what kind of procedure to do.
・ When performing joint management, is it okay to understand that the Intune Agent is additionally installed on the MECM Agent on Windows 10?
・ I want to install Intune automatically at Hybrid AD join. Is this feasible?

I'm sorry for the many questions.
Thank you.

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jason Sandys 31,411 Reputation points Microsoft Employee Moderator
    2021-06-24T17:09:11.053+00:00

    Is it possible to cancel after implementing tenants attach?

    Yes, there is a new offboarding feature for tenant attach. This will be included in a future release (hopefully 2107). This was initially previewed in TP 2014; see https://learn.microsoft.com/en-us/mem/configmgr/core/get-started/2021/technical-preview-2104#bkmk_offboard for details.

    Is it possible to cancel after implementing co-management?

    Yes. There is no process here, just disable it in ConfigMgr and unenroll endpoints from Intune.

    When performing joint management, is it okay to understand that the Intune Agent is additionally installed on the MECM Agent on Windows 10?

    There's no such thing as an Intune agent. Intune uses the MDM stack built into Win 10. Intune does deploy a supplemental agent called the Intune Management Extension, and yes, this is fully supported -- it would make no sense if it wasn't since co-management is explicitly the management by both.

    I want to install Intune automatically at Hybrid AD join. Is this feasible?

    There's nothing to "install". Co-management in ConfigMgr is explicitly about enrolling devices into Intune though. This can be initiated by ConfigMgr or group policy assuming you've configured all of the HAADJ prereqisites.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.