Author: Eswar Koneti

Microsoft Ignite 2020 is a virtual event with so much interesting content around Microsoft endpoint manager. Following are some of the key takeaways from the ignite 2020 with MEM Program Manager’s on Managing Android devices with Microsoft Endpoint Manager. Intune has full android enterprise support across all scenarios. Recent public preview release for the management of corporate-owned devices with a work profile. Google is decreasing support for device administrator management and recommended to move to work profile using android enterprise Extensive configuration of the Microsoft Launcher app on fully managed devices Support for management of rugged devices with OEMconfig Support…

Read More

Microsoft released an in-console update (KB4580678) that helps you to enables the Run scripts feature from the Microsoft Endpoint Manager admin center (Intune) and is now available to the customers who have enabled the tenant attach in Configuration Manager. This update also resolves other tenant attach related issues and is a prerequisite to use the Run scripts feature from the admin center (Intune). If you have not yet started the tenant attach process, please start now https://docs.microsoft.com/en-us/mem/configmgr/tenant-attach/ and take actions of your devices from mobile anywhere without accessing the configuration manager console. Along with enabling the run script features from MEM admin…

Read More

Microsoft has released Microsoft Endpoint Manager Configuration Manager build 2006 (MEMCM) via the opt-in method (fast-ring) on 8th of August, followed by slow-ring (GA) on 31st Aug. If you want to install a new Configuration Manager site (fresh build), you can download the baseline version which is 2003 from the volume licensing portal, and then do an in-console update to 2006. For more information about what’s new in Configuration Manager 2006, please refer https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/changes/whats-new-in-version-2006 And for a step-by-step guide to 2006, https://systemcenterdudes.com/step-by-step-sccm-2006-upgrade-guide/ Once you complete the CAS/Primary site server update, you need to manually upgrade any secondary sites by right-clicking on…

Read More

Azure Active Directory (Azure AD) is the future and is Microsoft’s cloud-based identity and access management service, which helps your users to sign in and access resources. Azure AD contains a large number of enterprise applications such as the gallery, on-premise, custom-developed, and non-gallery applications. For more information about Application Management in Azure AD, please refer https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/what-is-application-management Most of the Enterprise apps with Microsoft as a publisher in the Azure AD comes with the default properties such as Enabled for users to sign-in’ and ‘AppRoleAssignmentRequired’ which will have DLP issues if you don’t closely monitor the application behaviour. For example,…

Read More

Microsoft released Configuration Manager Technical preview build 2009 with some cool features applicable to cloud management gateway. This technical preview is for lab purpose ONLY and can be installed on 3 successive build versions which are from 1906,1907 and 1908. The latest active baseline version available is 2007 and can be downloaded from the Evaluation Center. If you want to build lab, download the baseline version (2007) and then do in-console update to latest preview build 2009. The following features are available with Configuration Manager technical preview build 2009: Cloud management gateway with Azure VM scale set Cloud management gateway…

Read More

With COVID-19 around the globe, the organizations who are using Configuration Manager have shown much interest in Cloud Management Gateway. Cloud Management Gateway helps you to manage the clients on the internet. For more information on how to setup CMG, please refer https://docs.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/setup-cloud-management-gateway A customer who recently deployed Cloud management gateway, wanted to monitor the software update compliance for the CMG connected devices ONLY. As these CMG devices are on internet and focus for patch compliance status is always have high visibility from the management prospective. I know that there are several default software update compliance reports available and i…

Read More

Configuration Manager uses collection evaluation to update collection membership, based on the collection rules you define. Collection evaluation scope and timing differ depending on site and collection configuration and evaluation type. With Configuration Manager Technical preview release 2008, a new feature is introduced that helps to integrate collection Evaluation viewer into the configuration manager console directly. With this new feature, we don’t need to run the standalone tool ceviewer,exe (servertools) to monitor collection evaluation data. We can now use the console to view and monitor the collection evaluation process for troubleshooting issues such as slow collection evaluation. The configuration manager console now…

Read More

After the configuration manager current branch 2002 released, there are 4 update rollups and 1 hotfix (out-of-band) (if am tracking them correctly) released by Microsoft. Following are the complete list of update rollups (first 4) and hotfix (last) for configuration manager version 2002. KB4553501 KB4563473 KB4567007 KB4560496 KB4575774 KB4575339 Today, Microsoft has released hotfix (out-of-band) for the following issue: After updating to Configuration manager current branch, version 2002, the New-CMTSStepPrestartCheck PowerShell cmdlet returns an error resembling the following when used. The action "Check Readiness for Upgrade" is invalid. The property OSArchitecture contains an unsupported value 64-bit. The task sequence must…

Read More