Series: 30 Days of Microsoft 365 Admin
π― Day-6 Objective
Todayβs goal is to:
- Enable device management
- Bring devices under Microsoft control
- Prepare for device-based Conditional Access
1οΈβ£ Verify Microsoft Intune is Enabled
π§ Steps
- Open Microsoft Intune Admin Center
- Go to Tenant administration
- Click Tenant status
β Confirm
- Intune status = Active
- MDM authority = Microsoft Intune
π If MDM authority is not set β devices cannot be managed
2οΈβ£ Check MDM Auto-Enrollment Settings
π§ Steps
- Intune Admin Center
- Devices β Enroll devices
- Click Automatic enrollment
β Configure
- MDM user scope: All users (or Test group)
- Save changes
π§ This allows devices to auto-enroll when users sign in.
3οΈβ£ Configure Device Enrollment Restrictions
π§ Steps
- Intune Admin Center
- Devices β Enroll devices
- Click Enrollment restrictions
- Open Default restriction
π Verify
- Platform: Windows = Allowed
- Personal devices = Allowed (for lab)
π In production, personal devices are usually restricted.
4οΈβ£ Register a Windows Device (Hands-On)
π§ On Windows Machine
- Open Settings
- Go to Accounts
- Click Access work or school
- Click Connect
- Sign in with M365 test user
β Result
- Device is registered in Entra ID
- User can access M365 apps
5οΈβ£ Verify Device in Entra ID
π§ Steps
- Entra Admin Center
- Devices β All devices
- Locate the registered device
π Check
- Join type: Azure AD registered
- Owner: User name
- Status: Active
6οΈβ£ Verify Device in Intune
π§ Steps
- Intune Admin Center
- Devices β All devices
- Select the device
π You Can See
- Device name
- OS version
- Compliance status (Not evaluated yet)
π Device is now manageable.
7οΈβ£ Understand Device Compliance Status
π§ Where to Check
Intune β Devices β All devices β Device β Compliance
Default Status
- Non-compliant (no policy assigned)
π§ This is important:
Conditional Access checks compliance, not just registration.
8οΈβ£ Connect Devices with Conditional Access (Preview)
π Scenario
- User signs in
- MFA passes
- Device = Non-compliant
- Access = Blocked (once policy applied)
π Actual enforcement comes in Day-7.
β End of Day-6 Outcome
After Day-6, you can:
β Enable Intune correctly
β Register devices
β Verify device status
β Understand compliance dependency
β Explain device-based access in interviews
π DAY-7 PREVIEW (NEXT DAY PLAN)
Day-7: Intune Compliance & Configuration Policies
We will:
πΉ Create compliance policies
πΉ Enforce BitLocker & OS version
πΉ Mark devices compliant / non-compliant
πΉ Block access for non-compliant devices
πΉ Validate using Conditional Access
