Aaron

Aaron

[4.2] Provisioning without Autopilot

Autopilot is the preferred provisioning path. It removes human variability, produces consistent enrollment outcomes, and scales without proportional IT effort. But not every device can go through Autopilot, and not every organization is ready for it. Designing a provisioning approach…

[3.3] MacOS Enrollment

macOS enrollment into Intune looks similar to Windows enrollment on the surface – a device appears in the management plane, policies apply, compliance is evaluated. The underlying mechanics are meaningfully different, and treating macOS like a Windows variant produces deployments…

[2.1.3] Licensing

Licensing conversations in Microsoft environments are uncomfortable because they’re usually happening at the wrong time – after someone has already designed a deployment around capabilities that turn out to require a higher license tier than the organization has. This article…

[1.1.1] How Intune Evaluates Configuration Profiles

Understanding how Intune actually processes and evaluates configuration profiles changes how you design them. Not just conceptually – it changes specific decisions about how many profiles to create, how to structure assignments, and how to troubleshoot when something doesn’t apply…

[7.2] Packaging Models: Win32, LOB, MSIX, and When to Use Each

Intune supports multiple application packaging models and the choice between them is consequential. Not because one is universally better, but because each model makes different assumptions about installer behavior, detection capability, and deployment reliability – and choosing wrong produces failures…

[6.2] Designing Compliance Rules That Mean Something

The most common compliance policy failure I see isn’t misconfiguration – it’s compliance theater. Rules that look thorough on paper but don’t actually reflect meaningful trust requirements. Environments where the compliance dashboard is green, but the signal feeding Conditional Access…