Intune policies on Hybrid Azure AD joined device

Ask Intune Question 21 Reputation points
2022-04-25T04:22:44.97+00:00

Can Intune manage(or specifically saying, apply Intune policies) on Hybrid Azure AD Joined devices. I have not enabled Co-management.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,720 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,248 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
0 comments No comments
{count} votes

5 answers

Sort by: Most helpful
  1. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2022-04-25T05:49:52.013+00:00

    @Ask Intune Question , Based as I know, most policies can apply to Hybrid Azure AD join device which is enrolled into Intune. Which policy you want to configure? We can check the detail of the specific setting article to see if there's any limitation with the join type.
    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-create

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  2. Rahul Jindal [MVP] 9,146 Reputation points MVP
    2022-04-25T07:37:24.45+00:00

    If you are using ConfigMgr then you will need to enable co-management to allow management of end user devices using Intune without any limitations.

    0 comments No comments

  3. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2022-04-25T08:43:32.673+00:00

    @Ask Intune Question , For windows 11, the steps is the same as windows 10. you can choose one windows 11 device and open local group policy editor via gpedit.msc.

    1. Create default rules.
      196015-image.png
    2. Create Executable Rule to disable notepad via Publisher.
      196073-image.png
      196005-image.png

    For the detailed steps, you can refer to the steps under "Creating the Applocker Policy" which is an example to block notepad.
    https://learn.microsoft.com/en-us/archive/blogs/matt_hinsons_manageability_blog/blocking-apps-with-intune-and-applocker-csp#creating-the-applocker-policy


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  4. Ask Intune Question 21 Reputation points
    2022-04-25T15:38:26.967+00:00

    Hello I tried to create the policy for Windows 11.

    The difference in Windows 11 is, the default windows apps like paint, notepad are present in Windows Apps folder unlike in Windows 10 where it was in system32. Hence while importing application as publisher we are getting a error. Hence I used path as an alternative option.

    Getting this on Intune:

    196225-image.png

    Also the policy is not working for me on the device.

    How to verify whether the policy has reached to the device ?


  5. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2022-04-28T07:46:11.803+00:00

    @Ask Intune Question , I have done more test and find on windows 11 device, I can block Notepad successfully with the following steps:

    1. Create a custom profile in Intune and configure the settings as below:
      OMA-URI: ./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/Native/StoreApps/Policy
      Data Type: String
      Value:
      <RuleCollection Type="Appx" EnforcementMode="Enabled">
      <FilePublisherRule Id="4c7be880-5791-4e1a-9012-ecdf24b96a82" Name="Microsoft.WindowsNotepad, version 10.2103.0.0 and above, from Microsoft Corporation" Description="" UserOrGroupSid="S-1-1-0" Action="Deny">
      <Conditions>
      <FilePublisherCondition PublisherName="CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" ProductName="Microsoft.WindowsNotepad" BinaryName="">
      <BinaryVersionRange LowSection="10.2103.0.0" HighSection="
      "/>
      </FilePublisherCondition>
      </Conditions>
      </FilePublisherRule>
      <FilePublisherRule Id="a9e18c21-ff8f-43cf-b9fc-db40eed693ba" Name="(Default Rule) All signed packaged apps" Description="Allows members of the Everyone group to run packaged apps that are signed." UserOrGroupSid="S-1-1-0" Action="Allow">
      <Conditions>
      <FilePublisherCondition PublisherName="" ProductName="" BinaryName="">
      <BinaryVersionRange LowSection="0.0.0.0" HighSection="
      "/>
      </FilePublisherCondition>
      </Conditions>
      </FilePublisherRule>
      </RuleCollection>

    197216-image.png
    2. After the policy is deployed to windows 11, I find the policy has been deployed to the device under C:\Windows\Systematic2\AppLocker\MDM.
    197218-image.png
    3. Also when I check the Advanced Diagnostic Report, I find the setting is applied:
    197160-image.png
    197235-image.png
    4. And the notepad is also block when I open it.
    197255-image.png
    We can see more details in the following link:
    https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-using-applocker-to-create-custom-intune-policies-for/ba-p/364981

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.