Articles

[5.3.1] BitLocker: Designing Encryption Policy That Works

BitLocker policy in Intune looks straightforward until you try to deploy it silently and it doesn’t work. The settings that control silent encryption are non-obvious, the policy type matters more than most people realize, and hybrid joined devices behave differently…

[4.1.3] Hardware Hash Registration

Before Autopilot can provision a device, that device needs to be registered. Registration ties a specific piece of hardware to your tenant. Without it, the device powers on and goes through a standard Windows setup – Autopilot never triggers. There…

[4.1.1] Autopilot Profiles and Deployment Modes

The Autopilot profile is the first decision point in the provisioning flow. It determines the deployment mode, the out-of-box experience, and how much control the user has during setup. Most environments need one profile. Some need two. Almost nobody needs…

[3.4] Mobile Enrollment: Setting the Stage for Phase 9

Mobile enrollment is where Intune’s flexibility becomes its complexity. Windows and Mac enrollment paths are relatively constrained. Mobile is not. iOS and Android each have multiple enrollment modes, each with different management capabilities, different user experiences, and different implications for…

[3.1.1] Configuring Enrollment Restrictions in Practice

Enrollment restrictions are the first line of control over what gets into your Intune environment. Most deployments leave them at default. That’s a mistake. The default enrollment restriction allows any device on any platform to enroll. That’s fine for a…

[2.3.1] The Naming Convention Playbook

Naming conventions are not bureaucracy. In an environment without the hierarchy that Group Policy provided, names are the only structural documentation you have. The architecture article explained why naming discipline matters – Intune has no OU structure, no inheritance, no…