Part 2 – Configure Microsoft Intune – Windows hello and Mobility (MDM and MAM)

In the previous Part, I guided you to create a new tenant on demos.microsoft.com. This one is working and we can use this tenant to configure Microsoft Intune to manage a Windows 10 device.

In this part, we go further with Microsoft Intune.

We are going to enable Windows 10 automatic enrollment. Go to the Azure Portal – > Azure Active Directory -> Microsoft Intune

For test purpose is user scope All enough. So, set the scope on All. You could change this later for a specific user group, for MDM as MAM. Hit the save button.

What does this function do? This function will automatically enroll the Windows 10 device into Microsoft Intune if they are Azure AD joined. As a user, you can join the Windows 10 device into Azure AD. During this joining process/registration, the device will also be enrolled into Microsoft Intune automatically.

We go further with configuring Microsoft Intune. We have to enable Windows device enrollment. You will need, of course, the Intune portal. Go to All Services (because by default the Intune icon is not in the left side menu) -> search for Intune -> click on Intune (you can also click on the * for adding Intune into the side menu) -> Device enrollment -> Windows enrollment.

Go to Windows Hello for Business

Click on Default

Click Settings

Click on the button Not configured and choose for enabled. You will get more settings. These are my settings for Windows 10 device. TPM is not required because I’m using a virtual machine without TPM.

Click on the Save button and go back to the begin in Microsoft Intune portal.

Let’s try if enrollment works. Go to your Windows 10 device. Crab a random user from Azure AD and try to sign in.

Enter the password.

We have to do some extra security verifications.

Choose your favorite option to verify. I choose always text message.

I received a text message.

We have to create an app password, but this is for later.

Click Next, we are not done yet.

Please choose your option and click Accept.

Please choose your option and click Accept.

Please choose your option and click Accept.

Please choose your option and click Accept.

Please choose your option and click Accept.

Please choose your option and click Accept.

Please choose your option and click Accept.

Windows 10 is Azure AD joined and enrolled into MS Intune. We have enabled Windows Hello in MS Intune and because of that you see this message “Your organization requires Windows Hello” This is a good sign and that applies our configuration in MS Intune.

We must create a PIN. Let’s try 1234… Tis PIN is not allowed by our Windows Hello configuration. You will get this message.

Let’s try 8888 and still it is not allowed, they are too simple. So, I go for a complex one, like 7948. This one is allowed, and everything is all set.

To verify if Windows 10 is joined and enrolled, you have to go settings -> Accounts -> Access Work or School.

You see the name of the Azure AD tenant and beneath that the account name which you have used. Click on that and will get some buttons. Click on the info button.

This gives us information about the sync status with Microsoft Intune.

Go to the Intune portal to verify the sync. From the portal go to Devices -> All Devices. You have to see your enrolled Windows 10 device. The device is managed by MDM. This is all good and your device is managed by Mobile Device Management (MDM)

End of part 2

Advertisements

4 thoughts on “Part 2 – Configure Microsoft Intune – Windows hello and Mobility (MDM and MAM)

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.