Report on Everything an Entra ID Group Touches with Microsoft Graph
Before you rename, rescope or delete a group, find out what it's wired to. Members, owners, licenses, apps and Intune policies, in one report.
Across the notebook
Entries sharing this tag, wherever they're filed.
Before you rename, rescope or delete a group, find out what it's wired to. Members, owners, licenses, apps and Intune policies, in one report.
For the Entra-joined PC that never showed up in Intune. Check it's ready, kick off enrollment, and see why it failed if it does.
Thread: Getting devices into Intune ↗A plain-spoken tour of what Intune actually handles, where it stops, and the identity decisions you want settled before the first device shows up.
Thread: Getting devices into Intune ↗The Settings app route into Intune, which of its three options to pick, and why the device might show up as personal when you didn't want it to.
Thread: Getting devices into Intune ↗A practical checklist for taking a device that gets its security policy through Defender for Endpoint and enrolling it in Intune without leaving a gap.
How I think about patch risk now. Sort updates by blast radius, roll them out in rings, decide what "bad" looks like up front, and know your way back before you need it.
One script that reads the WSUS, scan-source and Windows Update for Business settings on a device and tells you where it's really getting updates from, with a safe reset for leftovers.
How to build a configuration profile in Intune, roll it out to machines that are already in people's hands, and confirm it actually landed.
Onboarding to Defender for Endpoint and enrolling in Intune are two different things, and you almost never have to offboard one to get the other.
The hardware hash script behind Windows Autopilot, explained. Upload straight to Intune with -Online, or export a CSV when the device can't reach the tenant.
Thread: Getting devices into Intune ↗