Articles

[5.2] Configuration Profiles and the OIB Approach

The previous article established why Microsoft’s monolithic baselines create operational friction and introduced the two policy surfaces – Configuration Profiles and Endpoint Security – as distinct tools doing different jobs. This article focuses on the Configuration Profiles layer and how…

[1.0] What Intune Is (and What I Had to Re-Anchor)

The instincts I relied on for years still worked – just enough to be misleading. I didn’t come into Microsoft Intune green. I came into it with years of experience managing Windows devices in environments where authority was clear, timing…

[1.1.3] Naming, Scope, and Assignment Discipline

Once configuration is separated into modular policies, the next problem is obvious: how do you keep that structure understandable six months from now, when you’re not the only one looking at it? Intune doesn’t give you hierarchy. It gives you…

[1.1.2] Why I Design Baselines in Modular Sections

Microsoft’s security baselines exist for a good reason. The intent behind them is solid – consolidate recommended settings, reduce decision fatigue, give teams a defensible starting point. On paper, that’s exactly what a baseline should do. Where I’ve found consistent…

[1.3] Why the Trust Model Changed

The move to cloud management didn’t just change where policy lives. It changed what trust means and how it’s established. In a traditional model, trust is largely implied. A device is joined to the domain. It sits on the corporate…

[1.2] Understanding What Intune Actually Is

One of the most common mistakes I see is treating Intune as if it owns the entire device lifecycle. It doesn’t – and that distinction matters more than most people realize when they’re starting out. Intune does not authenticate users.…

[1.1] From Group Policy to Cloud Policy

From Group Policy to Cloud Policy The move to Intune is often framed as moving policy to the cloud. That framing is close enough to feel accurate and wrong enough to cause real problems. In a traditional domain environment, policy…

[3.2.1] Windows Enrollment Methods Explained

Windows enrollment looks simpler than it is. Entra ID join, hybrid join, and device registration are easy to conflate – they all result in a device appearing in your tenant, and the differences between them aren’t always obvious until something…