<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-4344063455110164362</atom:id><lastBuildDate>Fri, 27 Mar 2026 23:23:24 +0000</lastBuildDate><category>ConfigMgr</category><category>SCCM</category><category>Intune</category><category>System Center 2012</category><category>Mobile Device Management</category><category>EMS</category><category>Enterprise Mobility Suite</category><category>MDM</category><category>Configuration Manager</category><category>R2</category><category>Mobile Application Management</category><category>Azure</category><category>MAM</category><category>Current Branch</category><category>Windows 10</category><category>MEM</category><category>M365</category><category>Windows 8 Phones</category><category>1511</category><category>Azure Active Directory Premium</category><category>CMG</category><category>Cloud Management Gateway</category><category>Microsoft Endpoint Manager</category><category>macOS</category><category>System Center</category><category>Android</category><category>AutoPilot</category><category>Direct Access</category><category>Endpoint Protection</category><category>SCEP</category><category>iOS</category><category>Imaging</category><category>WVD</category><category>Windows 8</category><category>MBAM</category><category>MDT</category><category>ADK</category><category>Azure AD Premium</category><category>PowerShell</category><category>Secunia</category><category>Software Updates</category><category>Windows Virtual Desktop</category><category>1E</category><category>Endpoint Manager</category><category>Rights Managment</category><category>Apple</category><category>BitLocker</category><category>CSI</category><category>Linux</category><category>Nomad</category><category>Defender</category><category>MSIntune</category><category>RMS</category><category>SQL</category><category>Third Party patching</category><category>Windows 7</category><category>1602</category><category>1610</category><category>Agents</category><category>Azure Active Directory</category><category>CSP</category><category>Copilot</category><category>HAADJ</category><category>On premise MDM</category><category>SaaS</category><category>WSfB</category><category>1909</category><category>Azure AD</category><category>Backup</category><category>CD.Latest</category><category>CDP</category><category>Cloud Distribution Point</category><category>Conditional Access</category><category>DefenderforEndpoint</category><category>Easy Setup</category><category>Entra</category><category>FSLogix</category><category>GlobalSecureAccess</category><category>MDE</category><category>MEMCM</category><category>Management Point</category><category>Migration</category><category>OSD</category><category>Service Connection Point</category><category>Upgrade</category><category>VPP</category><category>WAIK</category><category>WMUG</category><category>WiFi Profile</category><category>Windows Defender ATP</category><category>WoL</category><category>co-management</category><category>comanagement</category><category>enrollment</category><category>1706</category><category>1803</category><category>1810</category><category>2002</category><category>APP</category><category>Activation</category><category>Apple Business Manager</category><category>Azure Monitor</category><category>Azure Storage</category><category>Baseline</category><category>Book</category><category>Cloud App Discovery</category><category>Cloud PKI</category><category>CloudNative</category><category>EA</category><category>EBF</category><category>EPA</category><category>Edge</category><category>Endpoint Analytics</category><category>EntraPrivateAccess</category><category>FileVault</category><category>Flexera</category><category>Intune suite</category><category>LAPS</category><category>M365 E</category><category>Mac</category><category>Mandatory Profile</category><category>Microsoft365apps</category><category>NDES</category><category>OMS</category><category>Office</category><category>PKG</category><category>PXE</category><category>PoSH</category><category>Power BI</category><category>Recovery</category><category>Restore</category><category>Security Copilot</category><category>Sysprep</category><category>Telemetry</category><category>Upgrade Readiness</category><category>VPN Profile</category><category>WSUS</category><category>Win32</category><category>Windows10</category><category>Windows11</category><category>Zebra</category><category>encryption</category><category>hybrid</category><category>in place upgrade</category><category>kiosk</category><category>language pack</category><category>modern</category><category>search</category><title>Gerry Hampson Device Management</title><description>Gerry Hampson Device Management</description><link>http://gerryhampsoncm.blogspot.com/</link><managingEditor>noreply@blogger.com (Gerry Hampson)</managingEditor><generator>Blogger</generator><openSearch:totalResults>388</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-1515748931978624407</guid><pubDate>Sat, 03 Jan 2026 15:28:00 +0000</pubDate><atom:updated>2026-01-03T15:28:56.809+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agents</category><category domain="http://www.blogger.com/atom/ns#">Copilot</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>My first look at Intune Agents (part3)</title><atom:summary type="text">This is the third is a series of blog posts about Intune Agents.&amp;nbsp;Intune Agents (also known as Security Copilot agents) are AI-powered assistants, available in the Intune Admin Center, that enhance enterprise security. They automate tasks for endpoint protection, identity management, threat intelligence, and device configuration, and they help IT teams quickly address vulnerabilities, policy </atom:summary><link>http://gerryhampsoncm.blogspot.com/2026/01/my-first-look-at-intune-agents-part3.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmcB-8wtAWs0eazzr_5ovzypCIv1sOT6OZbgPBQdYXuj2H4cGal_MzleePxmoSsF0uFeyg20KxDWZLZ1q7mybx7rMEPgSSq0gwh9ObPMIgpRq7otLxrXKpePriiR_4w8r8X2JqapdqQv_N6q9Z0miZkGuuUErKSSaSCWXmd743BNhyphenhyphenUZCU4-UIKQxi2ic/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-1749341572893893691</guid><pubDate>Wed, 17 Dec 2025 17:50:00 +0000</pubDate><atom:updated>2026-01-03T15:32:54.433+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agents</category><category domain="http://www.blogger.com/atom/ns#">Copilot</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>My first look at Intune Agents (part2)</title><atom:summary type="text">This is a continuation of the blog post I published last week. In&amp;nbsp;that post&amp;nbsp;I had my first look at Intune Agents and looked more closely at the Change Review Agent. This time I&#39;ll be looking at the Device Onboarding Agent. This agent identifies stale devices across Intune and Entra ID, provides actionable insights, and offboards stale devices for you.Some things to know:To run an Agent,</atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/12/my-first-look-at-intune-agents-continued.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjGE3NjOQqgRqusL2L_sa3fBNOLP0hIK0kqFkwSa_4uq6VK-PMnZgPHXWgLrXZOlvL9Aer5XPeR-DTWNAteFeMmyoGh-c3-e8EsGYx8pzln7uM1AhujzCYUyeIjwljLFZ2duKA7g5Qqu9iunWDCo2nZTsyUa3xM0qYRbxj0knAjB9L5jTS5eym2M8VKjxw/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-2708290355746438006</guid><pubDate>Sat, 13 Dec 2025 20:39:00 +0000</pubDate><atom:updated>2026-01-03T15:31:43.560+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agents</category><category domain="http://www.blogger.com/atom/ns#">Copilot</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365 E</category><category domain="http://www.blogger.com/atom/ns#">Security Copilot</category><title>My first look at Intune Agents (part1)</title><atom:summary type="text">Unless you&#39;ve been sleeping for the past year you&#39;ll have heard about Microsoft&#39;s Copilot offering. There are different flavours: M365 Copilot, Security Copilot, GitHub Copilot etc. I&#39;m an Intune guy, so I&#39;m mostly interested in Security Copilot. In this blog post I&#39;ll discuss how to get started and my first look at the Intune Agents, which are in Public Preview and use Security Copilot under the</atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/12/my-first-look-at-intune-agents.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKruhG26bPtK-qSRPU4-ZDJYn63ULBDBhcBGKXd4tnIO0paBmf8b3Mrerix3l0pyfzpuLL6VgRy_BjZDo3QGaw7m8oBdhZ0GGwlDZIQc52rVmBae4Foe9c-0colk8eGfvU-n7DvTWt9SuXjUmAt-CHGmQ4_hFRmIKIZ4VgG_EiYXB_03mSGV-0anqYHGU/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-4637940586553410391</guid><pubDate>Sat, 26 Jul 2025 13:56:00 +0000</pubDate><atom:updated>2025-07-26T14:56:36.415+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AutoPilot</category><category domain="http://www.blogger.com/atom/ns#">enrollment</category><category domain="http://www.blogger.com/atom/ns#">Entra</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>Autopilot - this user is not authorized to enroll (80180003)</title><atom:summary type="text">I was setting up a new demo tenant for testing this week and I encountered something I hadn&#39;t seen before. I had configured an Autopilot solution using deployment profiles but experienced this problem during testing.I could see that my test device had been assigned a profile.This was validated when I saw the Company Branding on the test device.However I received the error:&quot;Something went wrong. </atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/07/autopilot-this-user-is-not-authorized.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieIVRXdn_6LeorKRylbsx1-b4vA5OFla0fWFhE8QDRtQMp83TVz0RWJxTbLFR5rvPDIKrHqMGinBvpDB0CA1brY75CYnMivlTR2GsHFzNEcAcV3uWk_QHUVZuGWo4NyFK_O6rgUqbiwRDmumvuN-qaq6QxgmoY-ZZle59EN95Zf5JtTSPYCMfEogRPja0/s72-c/14.png" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-3524700444438525957</guid><pubDate>Fri, 18 Apr 2025 16:09:00 +0000</pubDate><atom:updated>2025-04-18T17:09:11.605+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Apple</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">iOS</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><category domain="http://www.blogger.com/atom/ns#">Software Updates</category><title>Managed software updates on Apple devices with Intune</title><atom:summary type="text">We&#39;ve been able to configure software update policies on iOS and macOS devices for a while, right. However this is new and different, released in March 2025 (Service release 2503). &quot;Managed software updates&quot; means something very specific. We can now configure devices to automatically update to the latest OS version using Apple Declarative device management.Declarative device management (DDM) is </atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/04/managed-software-updates-on-apple.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdhyAydYm5kkdIIlZx0DX4dHUuCVp4EcxjRCJp-O3rBAKgWTfciOTHnjYH4UpoDV2T1lVt4CAfgEBwv8KIKxgToT3k_mnKncxjyPxfTu3rvRpgqTJZG39EnS-WoLz_pzVyhZU-9Yed7dnW9uvbWj6y8hrICUQLywRmsWDuwq7GKDolkoTXjS57odJaaIM/s72-c/1.png" height="72" width="72"/><thr:total>2</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-3338476528962044079</guid><pubDate>Sat, 12 Apr 2025 15:35:00 +0000</pubDate><atom:updated>2025-04-12T16:43:59.011+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">CloudNative</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>On-premises printing with cloud native devices</title><atom:summary type="text">In the past year my colleagues and I have helped many customers to prepare their environments for cloud native devices.&amp;nbsp;What is a cloud native device? It&#39;s a device where all management is provided by the cloud. In the Microsoft world this means a device which is Entra joined and enrolled in Intune. The key here is the authentication. The device must authenticate with Entra. Entra hybrid </atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/04/on-premises-printing-with-cloud-native.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdwwSGbBzExC29PaF8EqKxyMMAiSt3QpuWrcAKEkNz5QkG0WvqAciPQ-t3PvYYW22FzaTGmE5-yIJsYbvVQtL0_wNzMsj8TIUZobb20ECzlq6qrg4EkIWfGziD8fyNMiGxXvPK0wEp0dOWY8iSxoavH0rEhNbhDTN4dg2AC8xuZHBervTnHYVS5FJbGtw/s72-c/1.png" height="72" width="72"/><thr:total>7</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-2599443316297786045</guid><pubDate>Sat, 08 Mar 2025 19:06:00 +0000</pubDate><atom:updated>2025-03-08T19:07:46.107+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>Apple Rapid Security Response and Intune</title><atom:summary type="text">Back to main macOS pageRapid Security Responses (RSR) are a type of software release for iPhone, iPad, and MacOS devices. They deliver important security improvements between major software updates. They can also be used to mitigate some security issues more quickly. Rapid Security Responses are supported for versions starting with iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1.By default, Apple </atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/03/apple-rapid-security-response-and-intune.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj6V0_DFPKs2C6IkX_29k_7it-hnwq81rcjPMDHKenAGLQQwb5gDl8p5nHYngTc0iQWC34fM_fsdBdpfYvcWGlTrw_v6tFFIh5dFlFibBhK61UliD7iEZ_8AFzcn_mqeRHamclm9W3cLVckJwV5bf001vAcA3A_fk0Gr4XL6Vs74InK2qPngJ-aSsNhbLg/s72-c/1.png" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-3844579048776926106</guid><pubDate>Fri, 07 Feb 2025 12:55:00 +0000</pubDate><atom:updated>2025-02-07T13:01:54.104+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">NDES</category><category domain="http://www.blogger.com/atom/ns#">SCEP</category><title>Help, NDES is broken......</title><atom:summary type="text">I was working with a new customer recently and they pointed out that they were having a problem with NDES.&amp;nbsp;What is NDES?&amp;nbsp;The Network Device Enrollment Service (NDES) is one of the role services of Active Directory Certificate Services (AD CS). NDES acts as a Registration Authority to enable devices running without domain credentials to get certificates from the internal Certificate </atom:summary><link>http://gerryhampsoncm.blogspot.com/2025/02/help-ndes-is-broken.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgmEk_shcKoKtRNvRiKWzdgpPPDSrgAB6zmCg48oGvqJnEWEkjGIPk-hywH3gvyt51PONaKk0flvUzwMYaMQmXROoiwdP3wg-tqEuZyyC4P8YxqPoEM_IN1Bm3fhUIb6ZzL1dE6gre-HPqcx1X9U56PTr6fjoNGZREosP3MG10VHFZK1PIWCc_DdD5NbZk/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-2365412035884462632</guid><pubDate>Fri, 20 Sep 2024 18:15:00 +0000</pubDate><atom:updated>2024-09-20T19:25:40.929+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">EPA</category><category domain="http://www.blogger.com/atom/ns#">GlobalSecureAccess</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><title>Entra Private Access and Exchange On-premises</title><atom:summary type="text">Entra Private Access enables secure access over the Internet to any on-premises application, based on any port or protocol that uses TCP or UDP.I previously published a&amp;nbsp;blog post&amp;nbsp;on my first look at Entra Private Access. In that post I showed how to configure enterprise applications to allow RDP and filesharing to on-premises resources. In this blog post I want to show how I configured </atom:summary><link>http://gerryhampsoncm.blogspot.com/2024/09/entra-private-access-and-exchange-on.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf04372Y3IfMraqfonF5pi2WaC4LCdYEiK5LcyxsayR7ef_BHcssxPckvbqWo-FEGapYX9KRXYK98Elnlpu1sf6T7tIEsXUGprHNltyTYDK4mk5irAOvaLsZQubcj3dpdHVvdoef7-DWahB7mBGfOtA5sxNVgdLanHV7d9cwGcqOu_kZa2ViB2PLqUn2c/s72-c/1.PNG" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-5294528134425466873</guid><pubDate>Thu, 23 May 2024 14:47:00 +0000</pubDate><atom:updated>2024-05-23T15:52:47.093+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Cloud PKI</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">Intune suite</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>Secure email with Intune Cloud PKI in less than 15 minutes</title><atom:summary type="text">This is incredible. I have experience with deploying PKI solutions in the past and it can be time-consuming and complex. My customer has a requirement to encrypt email but they have no internal PKI. I wanted to see how this could be achieved with the new Intune Cloud PKI. I was amazed, I was able to configure the entire solution in my lab in less than 15 minutes and now I can concentrate on the </atom:summary><link>http://gerryhampsoncm.blogspot.com/2024/05/secure-email-with-intune-cloud-pki-in.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglVJsiG-D8punM48cniw8WP-SRgTaYXp53qbV71s8txdCipR-inwaGxDYjHZcI6JYqLkQnX6UaevJD1PlJExyPunwOuBZ31wWeCUfAHbpn262iEjgCxnhxB1KLMidvKFwYZdxBinqAvKp5RYznpVRhehKvhNvG9t-F0o5ebKMKx07FxSJuS7eR0RlqaEQ/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-1746200813761201222</guid><pubDate>Wed, 27 Mar 2024 17:55:00 +0000</pubDate><atom:updated>2024-03-27T17:58:10.267+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">Mac</category><title>macOS management with Intune - activation lock</title><atom:summary type="text">Back to main macOS pageYou can set up Find My on your Mac so you can locate it and protect it if it’s ever lost or stolen. You can also share your location with others. When you add your Mac to Find My, Activation Lock is automatically turned on. After it&#39;s enabled, the user&#39;s Apple ID and password must be entered before anyone can:Turn off Find My MacErase the deviceReactivate the deviceWhile </atom:summary><link>http://gerryhampsoncm.blogspot.com/2024/03/macos-management-with-intune-activation.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgfC92LJdneWNJjSoN9Ebbje2UbEQ5QLxxwXOcQsZrMIJcnRhMkx_hafqoVgYhwedlTWUTkuEu20NKHsEy8qMlGwKy_23S1nL92hp-FISn-2vpOX46S968jKQCRQQLefT3GQCs0hCUiwS6m_e1VrI9JUC3nX6g-GgTv6jMAiOdEuYlUKtyg5vJNIx2MEpg/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-7213396211052433434</guid><pubDate>Tue, 19 Mar 2024 23:34:00 +0000</pubDate><atom:updated>2024-03-19T23:34:24.024+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - Gatekeeper</title><atom:summary type="text"> Back to main macOS pageNext up we&#39;ll talk about Gatekeeper. By default, Gatekeeper helps to ensure that all macOS installed software has been signed by the App Store or signed by a registered developer and notarized by Apple. It verifies that the software is free of known malicious content and hasn’t been altered.We&#39;ll start with a macOS configuration profile. Navigate to Devices &amp;gt; macOS &amp;gt;</atom:summary><link>http://gerryhampsoncm.blogspot.com/2024/03/macos-management-with-intune-gatekeeper.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDLK8VoxNTpSryyQvN0yLwYvoviR8n6xuLmq3WzipUc5iyVLBd2x9C4Qko23ijRxvZgoYHypciW7bJmxBmzw0PNhD7drA_pU0Ot2iv1U0MY_k06q4eJGncy9oJ8TbMPhpGgxPU3IA6oRUrGtgb9tfBv0xZ3O-864LMIFLMKQ7B-AycvweL-i93OCDEnxQ/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-2148436944611763313</guid><pubDate>Fri, 08 Mar 2024 10:05:00 +0000</pubDate><atom:updated>2024-05-22T13:23:52.825+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Entra</category><category domain="http://www.blogger.com/atom/ns#">EntraPrivateAccess</category><category domain="http://www.blogger.com/atom/ns#">GlobalSecureAccess</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><title>First look at Microsoft Entra Private Access</title><atom:summary type="text">Flexible work arrangements and accelerating digital transformation have changed the way we need to secure access. Organizations need an easier, more agile approach to protecting access to all applications and resources. Traditional network security approaches like VPNs don’t scale to these modern demands, they don’t give end users a good experience, and they grant excessive access to the entire </atom:summary><link>http://gerryhampsoncm.blogspot.com/2024/03/first-look-at-microsoft-entra-private.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiY9A0yJUnC5rabx1nCwyJCwuZ_UjtG_yjsVMvsqmiYbrZQFKHYr9uheIHMw02q9JxyhkMmKJy-fYhg4ivpDUNWs3opYiU__r4lkxZxrhvdjzEbe9doNbBz5ZBUR-KIyX4BaSfQHFk5e69iNeBu1MmVG9yxE-h0mwtMqlRx5K2lXPP5h71PmF5xdlSNP9A/s72-c/1.PNG" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-4934523819040418915</guid><pubDate>Tue, 14 Nov 2023 12:51:00 +0000</pubDate><atom:updated>2023-11-14T12:51:41.504+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - compliance</title><atom:summary type="text">Back to main macOS pageCompliance policies in Intune define the rules and settings that users and devices must meet to be compliant. They include actions that apply to devices that are noncompliant. Compliance policies can be combined with Conditional Access, which can then block users and devices that don&#39;t meet the rules.First I want to figure out what configurations I can make in my compliance</atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-compliance.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjioUv9viPuM4w8o4buNdKYyJRETKzfhyphenhyphen0JCUv6XkBwVnd4OvhBDTbUyGXU1zZ70p9VwF7STF8b8dM6qa24tpH_2L281cWg_KFj2NSHBFYfVneb68KCF7_twTjN7q3bWotRvLfbZDD_voj2_SB8c_38Dg3TpwyFF_jpbDB4uv-vuObp6_zXbrYKjEI-Ddk/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-3614574349540800886</guid><pubDate>Tue, 14 Nov 2023 12:11:00 +0000</pubDate><atom:updated>2023-11-14T12:11:14.707+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><category domain="http://www.blogger.com/atom/ns#">PKG</category><title>macOS management with Intune - PKG apps (Chrome)</title><atom:summary type="text">Back to main macOS pagePKG files are compressed installer files that are used to install macOS applications. Intune can deploy these apps to managed macOS devices where the file is smaller than 2GB. The Microsoft Intune management agent for macOS is also required.The PKG file for Google Chrome can be downloaded from&amp;nbsp;hereSelect Apps &amp;gt; macOS apps &amp;gt; Add. Under the Other app types, select </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-pkg-apps.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgKlYcQBNcWmgfOrVt9qNVO2zPpfi7Yn-c7OhuCechrqibjgKjfl8IsHpYvqTvx2O5sdA-0gPI8R9lL5Zc0YSvvoSmbGyssgrlrtMLrc4O09OA04EU1jl_JRsxKdENsTjlZ3AkT1qY8mfPnY18uiAHTP_Qhf7TJ0H5LmVrTDtPSNm-pPHc9o8cnjV54XLw/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-1944367099697275782</guid><pubDate>Tue, 14 Nov 2023 11:55:00 +0000</pubDate><atom:updated>2023-11-14T12:01:49.045+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Edge</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - Microsoft Edge</title><atom:summary type="text">Back to main macOS pageOne of the available Intune app types for macOS is Microsoft Edge version 77 and later. To help keep Edge more secure and up to date, the app comes with Microsoft AutoUpdate (MAU), more about this in a later blog post.Select Apps &amp;gt; macOS apps &amp;gt; AddSelect Microsoft Edge, version 77 and later for macOSEdit app details as required and click Next.Select the Stable channel</atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-microsoft_14.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBdZ70ABQZve_lqy6SiBOsKkaUyIQat9O6NL3OjRn7oJ-Bmb0IGzLs9WClyNMagFcHV36M3payvPoIAOWX4cA4M3TIFrzhUf6YTDFyVJZvRwcmGDTboIPUAuXcK2HdA3y76lL2ymBL-JEnwg2N1Y208kVQQHmJMkHgkdElD-ntWko9fP_fhZumpsZHT1E/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-681766065217818279</guid><pubDate>Tue, 14 Nov 2023 11:39:00 +0000</pubDate><atom:updated>2023-11-14T11:39:54.981+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><category domain="http://www.blogger.com/atom/ns#">Microsoft365apps</category><category domain="http://www.blogger.com/atom/ns#">Office</category><title>macOS management with Intune - Microsoft 365 apps</title><atom:summary type="text">Back to main macOS pageIntune makes it very easy for you to assign Microsoft 365 apps to macOS devices. By using this app type, you can install Word, Excel, PowerPoint, Outlook, OneNote, and Teams. To help keep the apps more secure and up to date, the apps come with Microsoft AutoUpdate (MAU), more about this in a later blog post.Select Apps &amp;gt; macOS apps &amp;gt; AddSelect Microsoft 365 app for </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-microsoft.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiQg9ihFc00vMJA2fajEEDmVSjxDT0YZYsTJzIT-vrA1GwCtUyQ0CecBrOmp3UiaJo7RtygsEz3jx_TFIdTTUIKn0vjQyQitCZOp5dZTrf1NkyI_bit2_9OxVOP6SU83WprE2YfZk7lrVy01h3wNo-KpIjEHLhoRiy-8PShFkc6u-A0sU7uOmQjRi8M0Q/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-2581724813510069453</guid><pubDate>Tue, 14 Nov 2023 06:48:00 +0000</pubDate><atom:updated>2023-11-14T06:48:46.653+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">encryption</category><category domain="http://www.blogger.com/atom/ns#">FileVault</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - FileVault encryption</title><atom:summary type="text">Back to main macOS pageFileVault is full-disk encryption that is included with macOS. With Intune you can deploy policies that configure FileVault, and then manage recovery keys on devices that run macOS 10.13 or later. There are two methods of configuring FileVault policies with Intune.Option 1: Endpoint Security &amp;gt; Disk encryptionOption 2: Device configuration profile for endpoint </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-filevault.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXMY7nlQkSHoIZiLoCi5vof1fqjBwO7bOrc_6VsqutKWbQFMYBaYanCB8Ax6rjIzB5nX6FldVf1msGO0KwYF7beysDn9U2oaDDXJO0Aog9FLVg7z_Y58_o2ymvAGZ2Cnsu7LE7o5QVOd0gxOmJhkyF8QrZShBeONpkIJVrR_4Gum8gU4npAfTmeJvqFwc/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-7921611345737378738</guid><pubDate>Tue, 14 Nov 2023 06:17:00 +0000</pubDate><atom:updated>2023-11-14T06:17:31.862+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><category domain="http://www.blogger.com/atom/ns#">Software Updates</category><title>macOS management with Intune - software updates</title><atom:summary type="text">Back to main macOS pageThis blog post is about the traditional way to deploy software updates to macOS devices. I&#39;ll discuss declarative software updates in a later post. With declarative updates you can be selective about the update that you want to deploy.Anyway, back to the job at hand, software updates.&amp;nbsp;You can use Microsoft Intune to manage software updates for macOS devices that are </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-software.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhtxLfxpLM-7BjZK1R2YLde9MgSFDgZ-1IOUl4je_4DbVi2u5-FStyDM97Zr1syM3UfGl2oHdn2RUzM1jqX4us2ZZ6xF5POmELOPw3CKxH1F8xFGWhIbtCYR_DIOduoB198Eyrp5lSFtf4F6Uo2-RwDMetFE7MP0zyTskqg7SbyUJ3wSSGUfzH30jMDJqo/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-3479707818892328057</guid><pubDate>Thu, 09 Nov 2023 17:43:00 +0000</pubDate><atom:updated>2023-11-15T12:15:11.236+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - DMG apps</title><atom:summary type="text">Back to main macOS pageDMG files are macOS disk image files. They are containers for apps in macOS. You open them, drag the app to your Applications folder, and then eject them, instead of the traditional installation. There are a couple of rules when deploying DMG apps with Intune.The maximum app size is 2GB.The Intune management agent for macOS must be installed. This will be installed before </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-dmg-apps.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEib9p1YfX2szAhI5A0uIcBeZ86ukE8NtnCZUIZzrXTlKJaDmX49H8JTVt_YZ7KQhjLfvxTR20thd0LB08IIay-u7ifdCZaPdtB2OwsvJxQjjVCLvghQ_scow-cefCsxZhcEtxRGQcewowmPrisN78CBoN2EGQYm0ZqCWtd9WZzH6UUfEpuzBdgkS_5lIgI/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-9050550005591063680</guid><pubDate>Thu, 09 Nov 2023 17:43:00 +0000</pubDate><atom:updated>2023-11-09T17:51:38.530+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - agent for macOS</title><atom:summary type="text">Back to main macOS pageThe Microsoft Intune management agent enables advanced device management capabilities that aren&#39;t supported by the native macOS operating system. It is the equivalent to the Microsoft Intune Management Extension for Windows (codename Sidecar), which adds support for Win32 app and script deployment.The Intune management agent:is a prerequisites before a macOS DMG app is </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-agent-for.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiGHnMJr_sXrhhT3FjAJqJ8w-7PEZL4s7LiTY8pFqaAmscoZZCDdqt9o1iMSsRBGs0zum044hIPAecjnTvSC6xy0PaqoeP5tMHdgl0j5IA5k3LBqei_8X7jt81NH39mQiuMG02EBm78dq7lH6TH6q09tGlGzj589uOaZZMi7jqxefXFjE7Qk6BBffU9AKo/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-261803645704690829</guid><pubDate>Thu, 09 Nov 2023 17:43:00 +0000</pubDate><atom:updated>2023-11-09T17:51:07.401+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - enrol</title><atom:summary type="text">Back to main macOS pageNow that all the prerequisites have been verified you can enrol a macOS device. First ensure that there are no restrictions preventing that.&amp;nbsp;Navigate to Devices &amp;gt; Enrol devices &amp;gt; Enrolment device platform restrictions. Verify that personally owned macOS is allowed.There are a number of device enrollment scenarios for macOS.User-owned (BYOD) - allows users to </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune-enrol.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpizlq6lIg7KMgpqvChkHz3jrCcSaKWMA3OwOBhwA4E_dDlmemjDfRn9cDCrc5d9a7f8GI6Y8_Jk6GOrohilFlEaRbw8DegnNlr6CzT-BYk_hA9koHcBJazBupXE6DzfI2t3AXljaC6o8mutmvmUwSSzycwocHVDbrCqRX-gWDAv7SUScyv1IEuvKefTk/s72-c/4.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-4293000546714298076</guid><pubDate>Thu, 09 Nov 2023 17:42:00 +0000</pubDate><atom:updated>2025-03-08T19:10:05.778+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>Management of macOS devices using Intune</title><atom:summary type="text">Recently I had the opportunity to deploy an Intune solution for macOS management for one of my customers. I configured everything in my lab first and tested using my trusty MacBook Air (Monterey 12.6.1). I&#39;m finally getting around to blog about the experience.&amp;nbsp;I&#39;ll use this page as a landing page and add links to the content as I go.PrerequisitesEnrollmentSoftware updatesFileVault </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/management-of-macos-devices-using-intune.html</link><author>noreply@blogger.com (Gerry Hampson)</author><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-7493786366875591449</guid><pubDate>Thu, 09 Nov 2023 17:42:00 +0000</pubDate><atom:updated>2023-11-09T17:50:38.528+00:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">macOS</category><title>macOS management with Intune - prerequisites</title><atom:summary type="text">Back to main macOS pageThere are some prerequisites before you can manage your macOS devices with Intune, but not many, and you have probably satisfied them already. Here goes:Devices, users and licenses:macOS 11.0 and later devices are supported.Your users must exist in Azure AD. They can be cloud only but many organizations use Entra ID Connect to synchronize users from Active Directory. That&#39;s</atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/11/macos-management-with-intune.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgp_7RxbW8d4wO5kvZ1STdycbP2TxGBLZe0fFB4d8_vAafbsA4QYstFirt9rL1cz7xvS151hOrJNNd1761lYvjpfm8b4HBkcFa8eiynhEj_zfvdjaoC-iRJg3cRoQVvKJLLAKQSHL3jc91Fng9CIzdeAilVZRhyphenhyphenWpA3BT9snNQG5Z4GBkFOVHGArjm_Stc/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-4344063455110164362.post-9032313938702376277</guid><pubDate>Mon, 16 Oct 2023 14:23:00 +0000</pubDate><atom:updated>2023-10-16T15:23:28.410+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">APP</category><category domain="http://www.blogger.com/atom/ns#">Intune</category><category domain="http://www.blogger.com/atom/ns#">M365</category><category domain="http://www.blogger.com/atom/ns#">MAM</category><category domain="http://www.blogger.com/atom/ns#">MSIntune</category><title>Wipe corporate data from non enrolled device</title><atom:summary type="text">A customer asked me about this last week so I decided to test it. What happens when an unenrolled BYOD device is lost or stolen but is protected by Intune App Protection Policies? Can the corporate data be wiped? He was specifically talking about Android and iOS devices. The answer is yes. That can be achieved using the Selective Wipe feature of Intune, which will wipe corporate data from Intune </atom:summary><link>http://gerryhampsoncm.blogspot.com/2023/10/wipe-corporate-data-from-non-enrolled.html</link><author>noreply@blogger.com (Gerry Hampson)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiykzDSxKjTIIN5gflPdofmG6rm2_QbcgTH59i4JEnlapTJNYWtkEPt-llomDcWgr9p8AnSXshVCweFYi7htL7gFciiTf_F7XgUtM9zB4AyIXOQMGI33QbnCqSC0D-ISzzl-NZW6p9kcPIcvyC4ENqy4dS97lqkKIYaKDEYhyphenhyphennwJXZ5BJCRJqtEYFSfXS8/s72-c/1.png" height="72" width="72"/><thr:total>0</thr:total></item></channel></rss>