Author: Eswar Koneti

we had a requirement to hide the notification previews for teams and also outlook when there is any mail or conversation that happens on mobile devices due to security reasons. Microsoft Endpoint Manager (Intune) app protection policies has setting for admins to be able to block organizational data from appearing in Teams mobile notifications (e.g. message preview, channel, or sender name) on both iOS and Android end-user lock screens using the Intune Application Protection Policy (APP). This will allow you to specify how org data is shared via OS notifications for org accounts. In your intune app protection policies, edit…

Read More

Another month pass by and Microsoft released Technical preview for Configuration Manager 2010. These technical previews will be released every month and is for lab purpose ONLY.For more information about the technical preview and how to use it, please refer https://docs.microsoft.com/en-us/mem/configmgr/core/get-started/technical-previewThe active baseline version as of today for technical preview is 2007 and this can be downloaded from Evaluation Center.Following are the new features in Technical preview 2010.Deploy a task sequence to a user as an app model deployment typeStarting in the release, you can now deploy a non-OS deployment task sequence to a user-based collection when you add a…

Read More

Microsoft Ignite 2020 is a virtual event with so much interesting content around Microsoft endpoint manager. Following are some of the key takeaways from the ignite 2020 with MEM Program Manager’s on Managing Android devices with Microsoft Endpoint Manager. Intune has full android enterprise support across all scenarios. Recent public preview release for the management of corporate-owned devices with a work profile. Google is decreasing support for device administrator management and recommended to move to work profile using android enterprise Extensive configuration of the Microsoft Launcher app on fully managed devices Support for management of rugged devices with OEMconfig Support…

Read More

Microsoft released an in-console update (KB4580678) that helps you to enables the Run scripts feature from the Microsoft Endpoint Manager admin center (Intune) and is now available to the customers who have enabled the tenant attach in Configuration Manager. This update also resolves other tenant attach related issues and is a prerequisite to use the Run scripts feature from the admin center (Intune). If you have not yet started the tenant attach process, please start now https://docs.microsoft.com/en-us/mem/configmgr/tenant-attach/ and take actions of your devices from mobile anywhere without accessing the configuration manager console. Along with enabling the run script features from MEM admin…

Read More

Microsoft has released Microsoft Endpoint Manager Configuration Manager build 2006 (MEMCM) via the opt-in method (fast-ring) on 8th of August, followed by slow-ring (GA) on 31st Aug. If you want to install a new Configuration Manager site (fresh build), you can download the baseline version which is 2003 from the volume licensing portal, and then do an in-console update to 2006. For more information about what’s new in Configuration Manager 2006, please refer https://docs.microsoft.com/en-us/mem/configmgr/core/plan-design/changes/whats-new-in-version-2006 And for a step-by-step guide to 2006, https://systemcenterdudes.com/step-by-step-sccm-2006-upgrade-guide/ Once you complete the CAS/Primary site server update, you need to manually upgrade any secondary sites by right-clicking on…

Read More

Azure Active Directory (Azure AD) is the future and is Microsoft’s cloud-based identity and access management service, which helps your users to sign in and access resources. Azure AD contains a large number of enterprise applications such as the gallery, on-premise, custom-developed, and non-gallery applications. For more information about Application Management in Azure AD, please refer https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/what-is-application-management Most of the Enterprise apps with Microsoft as a publisher in the Azure AD comes with the default properties such as Enabled for users to sign-in’ and ‘AppRoleAssignmentRequired’ which will have DLP issues if you don’t closely monitor the application behaviour. For example,…

Read More

Microsoft released Configuration Manager Technical preview build 2009 with some cool features applicable to cloud management gateway. This technical preview is for lab purpose ONLY and can be installed on 3 successive build versions which are from 1906,1907 and 1908. The latest active baseline version available is 2007 and can be downloaded from the Evaluation Center. If you want to build lab, download the baseline version (2007) and then do in-console update to latest preview build 2009. The following features are available with Configuration Manager technical preview build 2009: Cloud management gateway with Azure VM scale set Cloud management gateway…

Read More

With COVID-19 around the globe, the organizations who are using Configuration Manager have shown much interest in Cloud Management Gateway. Cloud Management Gateway helps you to manage the clients on the internet. For more information on how to setup CMG, please refer https://docs.microsoft.com/en-us/mem/configmgr/core/clients/manage/cmg/setup-cloud-management-gateway A customer who recently deployed Cloud management gateway, wanted to monitor the software update compliance for the CMG connected devices ONLY. As these CMG devices are on internet and focus for patch compliance status is always have high visibility from the management prospective. I know that there are several default software update compliance reports available and i…

Read More