Block Linux enrollment into Microsoft Intune with Conditional Access

Microsoft recently released the option to be able to enroll and manage devices running Linux (Ubuntu at this time) in Microsoft Intune. https://learn.microsoft.com/en-us/mem/intune/fundamentals/whats-new?source=recommendations#linux-device-management-available-in-microsoft-intune https://learn.microsoft.com/en-us/mem/intune/user-help/enroll-device-linux If you want to start playing around with this new feature, I highly recommend checking out Paul Winstanley (SCCMentor) article on it here: https://sccmentor.com/2022/10/19/first-steps-into-linux-management-via-microsoft-intune/ No Enrollment

First look at “Link your zero-touch account to Intune and manage zero-touch enrollment” from the Endpoint Manager admin center

A few weeks back in Microsofts service release for Endpoint Manager 2208 there was one thing that caught my attention and that was the introduction to a feature that were related to Android Zero Touch. Week of August 15, 2022 (Service release 2208) https://docs.microsoft.com/en-us/mem/intune/fundamentals/whats-new#configure-zero-touch-enrollment-from-microsoft-endpoint-manager-admin-center The documentation on this is somewhat

Single Sign-on with Windows Hello For business on Azure AD devices using cloud trust

There are a few different ways of getting Single Sign-on (SSO) with Windows Hello For Business (WHfB) up and running for Azure AD devices however in my opinion it has been very complex and the documentation from Microsoft have been hard to get my head around. There are so many

Restrict Windows 10 and Windows 11 logon to the current user or user who enrolled the device during Autopilot

A while back I investigate if there was any possibility to lock down a Windows 10 or 11 device that gets provisioned with Autopilot and enrolled in to Azure AD and Intune to only allow the user who enrolled the device to be able to logon to that specific machine.

Intune – Knox Platform for Enterprise (OEMConfig) claim your 2 year free license for Premium features

If you have been working with OEMConfig in Intune for Samsung devices you might have seen that there are some specific policies that says “Premium Features” on them when looking through the list of settings. https://www.samsungknox.com/en/solutions/it-solutions/knox-platform-for-enterprise How to claim your 2 year free license Go to https://www.samsungknox.com/ and login if

Intune and Knox E-fota – Automatic E-fota app installation and enrollment

This is a follow up article to the one I wrote last week where we had a look at managing updates for our Samsung devices with E-fota and Intune. If you haven’t seen it you can read it here: To be able to enroll and manage our Samsung devices in