Articles

[7.4] Assignment Intent: Required, Available, and Uninstall

Assignment intent is one of the most consequential decisions in application deployment and one of the least deliberate. Required, Available, and Uninstall aren’t interchangeable options for achieving the same outcome – they’re fundamentally different contracts between Intune and the device,…

[7.3] Detection Logic: The Part Everyone Gets Wrong

Detection logic is where application deployment fails silently. The application installs. The user can open it. The help desk has no tickets. And Intune keeps reinstalling it every few hours because the detection rule never returns true. This happens more…

[11.6] Migrating Macs to Intune from Jamf or No MDM

This entry is part 8 of 9 in the series Phase 11 - macOS

Most Mac fleets arriving at Intune aren’t starting from zero. They’re either managed by Jamf and the organization is consolidating to Intune, or they’re unmanaged – devices that have accumulated years of local configuration, user-installed software, and no management footprint…

[2.2.2] Privileged Identity Management: Architecture and Build Guide

This guide documents the architecture, configuration, and deployment of Privileged Identity Management across a Microsoft Entra tenant. It is an internal methodology document covering break glass account setup, authentication context design, Conditional Access policy construction, PIM group structure, and role…