Author: Eswar Koneti

Windows information protection (WIP) helps to protect enterprise apps and data against accidental data leak on enterprise-owned devices and personal devices that employees bring to work without requiring changes to your environment or other apps. For more information about WIP, please refer here I recently installed the Microsoft To-Do application on my windows 10 from the Windows store. After installing Microsoft To DO and try to sign-in, it throws an error ‘ A windows information protection (WIP) policy is preventing the use of Microsoft To-Do on this device’ This issue occurs because the device is enrolled to intune and there…

Read More

Windows Autopilot is a collection of technologies used to set up and pre-configure new devices, getting them ready for productive use. You can also use Windows Autopilot to reset, repurpose and recover devices. This solution enables an IT department to achieve the above with little to no infrastructure to manage, with a process that's easy and simple. For more information about windows autopilot, please read https://docs.microsoft.com/en-us/windows/deployment/windows-autopilot/windows-autopilot I was testing windows autopilot in the lab with some specific requirements for customer. There are many videos and series of guides available on how to get windows autopilot working. When you create an…

Read More

Microsoft's System Center Configuration Manager (SCCM) delivers an "umbrella" approach for patch and application management, but when it comes to third-party application management and system management operations the process is still tiresome. SCCM current branch allows you to subscribe to third-party catalogs, publish updates to your software update point (SUP), and then deploy them to clients however it has limitations patching third-party components running on a network. With a huge number of security vulnerabilities attributed to non-Microsoft applications, it is mandatory to patch these applications to shield your enterprise from data breaches. To be more precise, Adobe and Mozilla applications…

Read More

Microsoft released the technical preview for Configuration Manager, version 1910. These technical preview introduces new functionality that Microsoft is working on and It introduces new features that aren't yet included in the current branch .You can Install this version to update and add new features to your technical preview site but not available as baseline for new installation.If you want to install Technical preview in lab ,then you need to download baseline version technical preview 1907 and then do console update. Download baseline versions from the TechNet Evaluation Center.Technical preview version 1910 has the following features/improvements:Deploy Microsoft Edge, version 77…

Read More

About an year ago (Sep 2018),Microsoft announced the support for Win32 app management capabilities using Intune. Intune-only customers can now leverage management capabilities for their Win32 line-of-business (LOB) apps . For more information about Intune Standalone - Win32 app management read here. Microsoft Win32 Content Prep Tool to pre-process Windows Classic apps. The packaging tool converts application installation files into the .intunewin format. The packaging tool also detects the parameters required by Intune to determine the application installation state. After you use this tool on your apps, you will be able to upload and assign the apps in the Microsoft…

Read More

Microsoft recently announced that ,Adobe has integrated Microsoft Intune application protection directly into the Adobe Acrobat Reader mobile app for iOS and android. For more information, please refer https://www.microsoft.com/en-us/microsoft-365/blog/2019/09/05/adobe-acrobat-ios-android-microsoft-365-app-protection/ To deliver the best experience, Adobe will discontinue support for the Adobe Acrobat Reader Intune mobile app on November 30, 2019. All customers must migrate to Adobe Acrobat Reader mobile app, which now supports Microsoft Intune, to continue working in Acrobat on the go. For more information,please refer https://helpx.adobe.com/acrobat/kb/intune-app-end-of-life.html With this new app for iOS , there are some changes introduced which may confuse the end users on how to sign…

Read More

  Recently, we had a requirement from customer, that they wanted to deploy applications /apply device configurations etc. from Intune to Azure AD Joined devices ONLY but not other devices like BYOD intune enrolled devices. (MAM/MDM) With intune, you can target apps ,device configurations, profiles ,deployments to both user groups OR device groups but not to specific users or device. If you target to user groups ,then it will apply to user irrespective of device join type whether it is intune enrolled (BYOD) or Azure AD join (Corporate device) . If you perform Azure AD join through auto-pilot then the…

Read More

SCCM has multiple discovery methods help you discover devices on your network, devices and users from Active Directory, or users from Azure Active Directory (Azure AD). Read more about the discovery methods in SCCM https://docs.microsoft.com/en-us/sccm/core/servers/deploy/configure/about-discovery-methods AD system discovery help to discover computer resources that can be used to create collections and queries. You can also install the SCCM Client client on a discovered device by using client push installation. In order to successfully discover the computer (by creating the DDR Record) in domain by AD system Discovery , it must be able to identify the computer account and then successfully…

Read More