Category Intune

Designing, deploying, and operating Microsoft Intune. Home of the Intune Deployment Guide.

[1.1.1] How Intune Evaluates Configuration Profiles

Understanding how Intune actually processes and evaluates configuration profiles changes how you design them. Not just conceptually – it changes specific decisions about how many profiles to create, how to structure assignments, and how to troubleshoot when something doesn’t apply…

[7.2] Packaging Models: Win32, LOB, MSIX, and When to Use Each

Intune supports multiple application packaging models and the choice between them is consequential. Not because one is universally better, but because each model makes different assumptions about installer behavior, detection capability, and deployment reliability – and choosing wrong produces failures…

[6.2] Designing Compliance Rules That Mean Something

The most common compliance policy failure I see isn’t misconfiguration – it’s compliance theater. Rules that look thorough on paper but don’t actually reflect meaningful trust requirements. Environments where the compliance dashboard is green, but the signal feeding Conditional Access…

[5.5] Updates: Autopatch as Default, Rings as the Alternative.

Patch management has a reputation for being a maintenance task. In a cloud-managed environment it’s a security control – and the distinction matters for how you design it. Devices that aren’t current aren’t just inconvenient. They’re non-compliant, and non-compliant devices…

[5.2] Configuration Profiles and the OIB Approach

The previous article established why Microsoft’s monolithic baselines create operational friction and introduced the two policy surfaces – Configuration Profiles and Endpoint Security – as distinct tools doing different jobs. This article focuses on the Configuration Profiles layer and how…