Aaron

Aaron

[6.1.1] Building Compliance Policies in Practice

Compliance policies are the bridge between Intune configuration and Conditional Access enforcement. Before you build individual policies, two tenant-wide settings need to be set correctly – and most environments have them wrong by default. Tenant-wide compliance settings first In Intune,…

[5.3.2] ASR Rules: Staged Enforcement From Audit to Block

ASR rules are one of the highest-value security controls available in a Microsoft Defender environment. They’re also one of the easiest ways to break legitimate applications if you deploy them without understanding what you’re doing. The staged approach – Audit,…

[5.3.1] BitLocker: Designing Encryption Policy That Works

BitLocker policy in Intune looks straightforward until you try to deploy it silently and it doesn’t work. The settings that control silent encryption are non-obvious, the policy type matters more than most people realize, and hybrid joined devices behave differently…

[4.1.3] Hardware Hash Registration

Before Autopilot can provision a device, that device needs to be registered. Registration ties a specific piece of hardware to your tenant. Without it, the device powers on and goes through a standard Windows setup – Autopilot never triggers. There…

[4.1.1] Autopilot Profiles and Deployment Modes

The Autopilot profile is the first decision point in the provisioning flow. It determines the deployment mode, the out-of-box experience, and how much control the user has during setup. Most environments need one profile. Some need two. Almost nobody needs…