This is so helpful as someone who is looking to migrate from AD to AAD.
@fordhamfamilyfarms10 ай бұрын
Hey Andy love your work. Doing some intune work with hybrid devices and would love an updated version of this ;)
@PrinceJohn842 жыл бұрын
Hi Andy. Great videos by the way. just for clarity but you absolutely can manage machines that are Azure AD Hybrid joined using Intune. We do exactly this. You need to enable a group policy that enrolls the device in MDM first. The setting is under Computer\Windows Components\MDM 'Enable Automatic MDM Enrolment using default Azure AD credentials'. Our client machines are currently joined to our on premise AD but are co managed in Intune, the idea being that we slowly but surely shift management of the endpoints away from group policy and into Endpoint Manager over time. Eventually, we'll be in a position to have all our endpoints completely cloud native ☁️
@AndyMaloneMVP2 жыл бұрын
You are indeed partly correct. SCCM in hybrid or co management allows you to SEE both segments for convenience. But I am correct when I say only either AD or AAD can authenticate. Current branch mode allows you to manage both in either product, to a point for convenience. But ultimately it’s not a long term solution. That said you make some great points and I really appreciate the comment👍😊
@PrinceJohn842 жыл бұрын
@@AndyMaloneMVP Absolutely. With the rise of work from home and client mobility, endpoints have to be cloud native going forward and that is our goal. Cheers!
@user-zo6iw2oz9c2 жыл бұрын
Agreed!
@richarddinel4762 Жыл бұрын
You help me and my partner so much in getting our O365 to Intune. Part of our cmmc certification and securing our tenant.
@AndyMaloneMVP Жыл бұрын
My pleasure and you’re very welcome. The very best of luck 😊
@tonytango482 жыл бұрын
Another cracking video Andy!
@AndyMaloneMVP2 жыл бұрын
Thanks Tony👍😀
@emmanuelchrispher89582 жыл бұрын
I'm a subscriber of your channel, and i will follow you all of the time. i do appreciate all of you videos . continue
@AndyMaloneMVP2 жыл бұрын
Thank you most kindly and I really do appreciate your support 👍😊
@emmanuelchrispher89582 жыл бұрын
@@AndyMaloneMVP i am sure we will talk one day soon, personally
@AndyMaloneMVP2 жыл бұрын
@@emmanuelchrispher8958 why not, we’re all human 😊 Have a great day 👍
@jessesack30653 ай бұрын
Great informative video sir! Many thanks.
@Elscorpio6062 жыл бұрын
great learning videos, thanks for uploading them Andy
@AndyMaloneMVP2 жыл бұрын
My pleasure!
@OldFellaDave Жыл бұрын
Hi Andy, What is the downside of joining my 90 odd PC's and Laptops to Hybrid Azure AD? I want to get rid of Sophos Intercept X (cost) and use Microsoft Defender/Endpoint instead (that we are already licensed for), and for that we need to go down the route of enrolling in Intune. The process seems easy enough to do (via our already running AAD Connect on a DC) but you seem (from what you said at the start) to not like Hybrid joining? I am in no real hurry or any real desire to give up my On-Prem environment with all my GPO's, fileshares, SQL based accounting package etc ;)
@AndyMaloneMVP Жыл бұрын
Hi Dave. This is a question I asked a lot :-) Personally I think there is very little in having client PCs hybrid joined. Yes you can apply conditional access policies. But in terms of management it's expensive with the fact that it's managed on-prem with SCCM & Intune Add ins. If you Azure AD join your PCs directlty you can migrate group policy settings across and it's already configured for SSO AND you can manage it directly from the cloud. You don't need sophos as Windows Defender rocks. That's my opinion :-)
@NickLaoutaris Жыл бұрын
Hi Andy , this is great man ! keep it up. Thank you for this amazing video.
@AndyMaloneMVP Жыл бұрын
Thanks Nick, you’re very welcome 😊
@MattTruVu2 ай бұрын
After azure joining what credentials did you sign back with? AD credentials or Entra ID credentials?
@AndyMaloneMVP2 ай бұрын
EntraID
@barclayjamesharvest93542 жыл бұрын
Hope to be a guru one day thanks to you.For now just a basic computer technician.Just discover you chanels few days ago and subscribe right away.Thanks
@AndyMaloneMVP2 жыл бұрын
Live the dream my friend. Great to have you on board 🙂
@devemanuelangelo11 ай бұрын
Hi Everyone, I just upgraded our users from Windows 11 Home to Windows 11 Pro. Some were able to join Join this device to Azure Active Directory but two of our users don't have the Join this device to Azure Active Directory option.
@AndyMaloneMVP11 ай бұрын
I suspect because the home edition is not comparable
@tomirvine34498 ай бұрын
Hi Andy, Great Video. My tenant has a whole bunch of devices I have connected to the basic Azure AD, I want to move them to intune. What's the process to move them from Azure to Intune?
@AndyMaloneMVP7 ай бұрын
Assign a licence. Follow the documentation. techcommunity.microsoft.com/t5/microsoft-intune/onboarding-devices-from-aad-to-intune-and-beyond/m-p/3697731 and here call4cloud.nl/2020/05/intune-auto-mdm-enrollment-for-devices-already-azure-ad-joined/
@TanuchiSacin2 ай бұрын
Today, I was testing a PC to join AAD (we usually do the Autopilot route), but I couldn't see the "Join this device to Microsoft Entra ID", just missing. I found a forum where somebody mentioned switching the workgroup from WORKGROUP to MSHOME, so I tried that. After the reboot, I was able to see the option. Do you know if this is documented somewhere?
@AndyMaloneMVP2 ай бұрын
Unfortunately, this is common knowledge. Once a machine has been deployed with active directory you need to re-image that machine
@techman219211 ай бұрын
I enjoy your videos, I have one question: do you have to use answer files with deploying software apps in Intune?
@AndyMaloneMVP11 ай бұрын
No
@jojolization2 ай бұрын
quetions: 1. can I use intune to depoly app to the Hybrid Azure AD Joined Devices? 2. other than using GP, can I set configuation profiles in tune and deploy to the Hybrid Azure AD Joined Devices?
@AndyMaloneMVP2 ай бұрын
No, and no, I’m afraid. In tune works with enter ID join devices and users need an appropriate license. As I’ve mentioned in the video hybrid devices are managed by active directory not in tune. You can see limited attributes in the device pain of the user account and can use conditional access However to get the full benefit you require in tune. Device profiles are managed by enterprise state roaming and in tune.
@rkh11 Жыл бұрын
Many Thanks for your work and affords. I've red that Hybrid Azure AD joined devices require network line of sight to your on-premises domain controllers periodically. If I've added device to on-prem AD and logged in under domain user, then that device has been given to the user who won't have that periodic connectivity. Does it mean the after some time that user won't be able to login under domain account?
@AndyMaloneMVP Жыл бұрын
Not at all. However, after a period of time has gone by the user may have to re-authenticate using multifactor authentication.
@Naveed67857 Жыл бұрын
He'llo Andy Give me answer please I have very basic requirement that normal users cannot install any software without admin privileges. Please guide me. As some policy I used but it restrict only from installing app from windows app store only but over all so when they need I can use admin privileges to install any software or application in windows intune devices
@AndyMaloneMVP Жыл бұрын
It appears that there is obviously a restriction in place here. You need to have some form of admin privileges to continue. If you want to learn the subject, I recommend creating a Microsoft 36 E5 subscription with EM&S as this will allow you to practice. You can also check out the full learning content at lauren.microsoft.com. I wish you the very best of luck 👍
@Naveed67857 Жыл бұрын
@@AndyMaloneMVP Mentioned URL is not working
@AndyMaloneMVP Жыл бұрын
@@Naveed67857 the dangers of speaking text messages, it should have been learn.microsoft.com
@Naveed67857 Жыл бұрын
@@AndyMaloneMVP Thank you for your kind reply. Please recommend some channel that will help me to deploy Microsoft intune focus will be on windows 10 and 11. I have gone through intune videos but I need further training
@AndyMaloneMVP Жыл бұрын
@@Naveed67857 not sure I’m afraid. I do included but it’s not dedicated. If I find something I’ll let you know.
@gutodalkimin2 жыл бұрын
Great Andy! Thanks
@AndyMaloneMVP2 жыл бұрын
You’re welcome 😊👍
@ThePatsev Жыл бұрын
Hi Andy, does each user who logs into a device managed by Intune, needs to have an Intune license or just the admin has to have it? Thank you
@AndyMaloneMVP Жыл бұрын
It’s per user licensing, I’m afraid.
@isabel82tisha8 ай бұрын
Hi Andy, why is the Azure user JoniS an administrator after the device has been registered with the name? It's the same for me, but that can't quite fit if JoniS is not an administrator at all. I couldn't register the device with a local account, so not admin. The selection for this was not displayed.
@AndyMaloneMVP8 ай бұрын
This would not happen today. Use the LAPS service in Intune. Read the documentation at learn.microsoft.com
@kb8570 Жыл бұрын
Thank you for information Andy, it is very clear and easy to understand. Could you please explain the difference between accessing corporate data on a personal laptop if using the Microsoft Company Portal app compared to the option within 'Settings' > Account > 'Add a Work or School account'?
@AndyMaloneMVP Жыл бұрын
The company portal allows you to access content in a bubble. For example, when you open documents, it opens it within a portal. You cannot cut copy or paste content or take screenshots from within the portal to other applications. Thus ensuring security. This is perfect in a BYOD environment. In a full corporate deployment, the entire device is managed by corporate, i.e. all the settings and configuration. I hope this helps and thanks again, Andy
@kb8570 Жыл бұрын
@@AndyMaloneMVP Thank you Andy for your reply and help. Does Azure or Endpoint/Intune give you the option to enforce a policy whereby any staff using a personal laptop and wishing to access Work Emails/Organisation OneDrive/Corporate MS Teams account must use the Microsoft Company Portal app? Therefore preventing staff from simply accessing business Office365 applications from the browser on their personal laptop.
@AndyMaloneMVP Жыл бұрын
@@kb8570 it does yes. For noncorporate devices, however, conditional access guest policies are really good.
@kb8570 Жыл бұрын
@@AndyMaloneMVP Thank you Andy. I will see what I can do with conditinal access. I am a newbie and just started working with Endpoint and Azure. Thank you for your videos!
@srikanths6512 жыл бұрын
The Video is indeed for me...Thank you so much for your efforts. one question from my end. How will we join AD installed in Server 2012 users and computers to AAD. are the existing Group Policies will Apply post sync to AAD? OR do we need to add different roles to Computers /Devices in AAD For Managing them.?
@AndyMaloneMVP2 жыл бұрын
Thanks for the question. Here is a video on Azure AD connect. This is the tool that sets up a hybrid connection. In terms of group policy you can either use the group policy analytics tool in Intune that can help migrate policies. Or just start fresh.kzbin.info/www/bejne/o6arh5WbhLN6p6M with way check out docs.Microsoft.com they have some great documentation 😊👍 Good luck
@ts-cj2ym2 жыл бұрын
Hi Andy great video. I have 40 laptops not in On-premise AD and 40 in On-premise AD. We like to use intune for mangement. How do we go from here? AD server is Windows 2022. All run win 10 and 11 (with Office 365 business premium) Im thinking of letting all laptops join Azure AD and connect the AD server to Azure. That will give a mix of computer only in Azure AD and some in On-premiere AD, connected to Azure. Will that work? Or do we need to let all devices join on-premise AD before connevting the server to Azure
@AndyMaloneMVP2 жыл бұрын
Thanks very much for your question. The answer is absolutely you can set these up to talk to Azure AD. I think you’ll find this playlist really helpful for youkzbin.info/aero/PLEgclf_4HA-iIHhRTlzgZOIIxJ--Pxz9C
@bechirbendhief6086 Жыл бұрын
I'd like to thank you for this Great efforts it's very helpful
@AndyMaloneMVP Жыл бұрын
You’re very welcome and thanks for your kind comments. I’m delighted you’re enjoying the content. All the best, Andy 😊
@TechITStudy Жыл бұрын
Awesome Video
@mikemiguelhije27802 жыл бұрын
Thank you for that info, what is the difference between account protection Intune vs Device administrators?
@AndyMaloneMVP2 жыл бұрын
Admin roles allow you to delegate specific admin roles to users. See the doc here docs.microsoft.com/en-us/mem/intune/fundamentals/role-based-access-control whereas account protection policies are a new preview feature (not reviewed by me yet) details here docs.microsoft.com/en-us/mem/intune/protect/endpoint-security-account-protection-policy#:~:text=Use%20Intune%20endpoint%20security%20policies,Microsoft%20Endpoint%20Manager%20admin%20center. Device admin role here docs.microsoft.com/en-us/azure/active-directory/devices/assign-local-admin
@mikemiguelhije27802 жыл бұрын
@@AndyMaloneMVP thank you for the reference
@AndyMaloneMVP2 жыл бұрын
@@mikemiguelhije2780 you’re very welcome 👍😊
@livestronger19814 ай бұрын
Why can I not use Group accounts to assign to "Device Administrator, Assignments"? It only shows users.
@AndyMaloneMVP4 ай бұрын
You are correct.
@uYahbonaEmbo2 жыл бұрын
This video was meant for me no doubt about it. Our organization recently implemented a Teams VoIP telephony with yealink desk phones. The issue we are experiencing is some devices are not completing the sign up process on Company portal for intune and these are all Android OS devices. Is possible Andy to do a video on enrollment of Teams Android based desktop phones which will include MDM & Conditional access of these devices
@AndyMaloneMVP2 жыл бұрын
Hey thanks for the nice comment and great to have you on board. I recorded a video on Teams voice a while back. You should check it out. I’ll be honest here, when I get specific requests like this it’s tricky as some feature even I don’t use. Android being one of them. So I’m really sorry, like I’ve said I’m an instructor and a support help desk and although I try my best, sometimes I can’t fufil every request, I hope you understand. Good resources for you though would be docs.Microsift.com and the Microsoft tech community. Also make sure all of your users are licensed. Good luck 👍😊
@uYahbonaEmbo2 жыл бұрын
@@AndyMaloneMVP thanks maine for your honest response will post my issue in community
@leighgc1855 Жыл бұрын
Hi Andy, is it possible to add a device to Intune after they are already registered with Azure AD? I have enabled MDM for some users, added a security group, and included the usesr in the security group. However, when the user logs on, their Azure AD device doesn't enrol in Intune, all users have Office 365 premium licenses
@AndyMaloneMVP Жыл бұрын
Not the same device but other devices yes
@leighgc1855 Жыл бұрын
@@AndyMaloneMVP Thanks
@syedmali77724 ай бұрын
how to join the device as standard user type using the Azure active directory method.
@AndyMaloneMVP4 ай бұрын
School and workplace join in windows 11. You can join a device as long as you are authorised.
@Bbill2k2 Жыл бұрын
So outside conditional access theirs no real point to have Azure AD devices being hybrid enrolled?
@AndyMaloneMVP Жыл бұрын
Agreed😊👍
@sastreaj2 жыл бұрын
Thank you for the video Andy, is there any way to unjoint on-premises devices and join them to Azure AD without having users create a new profile?
@AndyMaloneMVP2 жыл бұрын
Unfortunately not. That said it’s the device that your authenticating, not necessarily the user
@sastreaj2 жыл бұрын
@@AndyMaloneMVP Thank you for the quick replyAndy. The devices are assigned to the user and my idea is to eventually turn off the on-premises AD.
@AndyMaloneMVP2 жыл бұрын
@@sastreaj Your users can be active directory joined but the devices can be Azure AD joined. I would advise you also to take a quick look at docs.microsoft.com this is the definitive repository for all documentation for Microsoft 365 if there is an answer, this is where you’ll find it.
@sastreaj2 жыл бұрын
You’re totally correct Andy. I now get it, I didn’t see it like that. I’ll worry about joining the device and keep the user in AD.
@AndyMaloneMVP2 жыл бұрын
@@sastreaj No worries and thanks for the question 😊👍
@kevinjackson51912 жыл бұрын
Hi Andy, as always a fantastic insight. However, i have a question that no one putting up videos of Azure AD joining seems to cover. When you login to a device as the admin and join a standard user to AAD, it seems to then turn them into an administrator (presumably of the device they are logged in to). This can't be a good practice, surely. So how do you join them as standard users?
@AndyMaloneMVP2 жыл бұрын
This is a common one. In the Intune autopilot OOBE (out of the box) settings there is an option to install as regular user or local admin. I’ll bet you’ve chosen the latter by mistake. joymalya.com/manage-local-admin-accounts-with-intune/ & here docs.microsoft.com/en-us/answers/questions/129120/enabling-local-administrator-account-on-windows-10.html
@robertojosesiulemus3205 Жыл бұрын
The Best!!!
@ThePatsev2 жыл бұрын
Hi Andy, what about Azure registered devices? It's registered the same way as Azure joined. I can't really see the difference. Thank you for your informative videos!
@AndyMaloneMVP2 жыл бұрын
Azure AD registered device work in the same way. Except, that when you deploy applications, they appear in a portal on the users phone. Do you remember that registered devices are BYOD or bring your own device and are owned and managed by us, not corporate.
@ThePatsev2 жыл бұрын
@@AndyMaloneMVP Thank you, Andy!
@fbifido22 жыл бұрын
say you have a small office of around 25 works (to be 30 next year) and they work in 3-shift and only 10 laptops that are shared at each shift. - can we prevent user from joining device to Azure AD or Intune ? - can an admin join them to azure ad + Intune, and allowed the staff to sign-in to any of the device using their azure account and allows their settings to follow them ? - I don't want an ADDS Server, just Cloud only system { Microsoft 365 Apps }
@AndyMaloneMVP2 жыл бұрын
You can set that only specific users can do an azure ad domain join. In my video chat did all. But you can select specific users. Also specific admins as well. In terms of using laptops which are shared you may want to take a look at this. I think you’ll find it useful docs.microsoft.com/en-us/mem/intune/configuration/shared-user-device-settings
@cpuuk2 жыл бұрын
When joining AzureAD, what happens to the computer local User accounts- are they still there?
@AndyMaloneMVP2 жыл бұрын
Yea they are. You can disconnect if you wish. Also intune provides full policy control.
@kedargiri53977 ай бұрын
How to Microsoft Entra join existing windows server vm ??
@AndyMaloneMVP7 ай бұрын
This was the video
@fbifido22 жыл бұрын
@8:40 😍😍✔✔
@soodshubham76712 жыл бұрын
Cool 😊
@AchtungEnglander2 жыл бұрын
6:00 The Azure Directory option has been removed. When I log into my work account that account is added to my personal Microsoft account. I cannot then log in or out the two accounts as I used on Win 10. I see one log in with 2 accounts. This is NUTS ! EDIT - I am using Win 11 Home, I presume I need to install Win 11 Pro to get Azure?
@AndyMaloneMVP2 жыл бұрын
I think you answered your own question. Does not support home. Sorry.
@markstuffАй бұрын
How can you do this without knowing Joni's or Aaron's passwords?
@AndyMaloneMVPАй бұрын
Because I’m deploying machine not logging on the users the user would still log on with the credentials
@JohnieDSM2 жыл бұрын
Hi - I have a question, maybe someone has an answer - I tried to connect my laptop to customers Azure network and got message on the screen that my laptop is registered with another Azure domain and welcomed me to connect to that Azure domain - any ideas what it is - some kind of protection? Thanks a lot!
@AndyMaloneMVP2 жыл бұрын
I'll bet that the laptop you're using is connected to your Microsoft 365 account. You can tell if you go into a web browser to portal.office.com If it does not prompt you for a username etc. You're already connected. Another way is to go into accessories - Accounts - School and workplace join . If you're already connected you'll see the account details here. Another obvious Q, what edition of Windows are you using? Pro or Enterprise. As I said in the video Win 10/11 devices can only be connected to one domain at a time. Either On prem Windows Server AD or Azure AD (Microsoft 365). I hope this helps and good luck.
@JohnieDSM2 жыл бұрын
@@AndyMaloneMVP This laptop doesnt have MS 365 installed, it was returned from the rent and fresh Win10Pro installed - also doesnt have any connections to any domains so far. I quess Azure uses some hardware identification/authorisation since how the current Azure domain (to which I'm going to connect knows about the old one and doesnt allow me to connect)?
@AndyMaloneMVP2 жыл бұрын
Sounds like the OS build has some kind of connection built in. I'd take it too support it to be checked. Also perhaps you don't have admin rights
@AndyMaloneMVP2 жыл бұрын
@@JohnieDSM I’m sorry sounds like you need to go to a support specialist. Best of luck 😊
@cqajagsaw2 жыл бұрын
how do you enable Intune Auth?
@AndyMaloneMVP2 жыл бұрын
A user must have an Azure AD account and the device must be Azure AD joined then the user just signs in using standard single sign on. Check out docs.microsoft.com for more details.
@ANAND-ip2wu2 жыл бұрын
Hiiii sir, this is anandhakumar from India Chennai I learning windows server how to I get job in abroad any app is there in playstore
@AndyMaloneMVP2 жыл бұрын
Not sure about apps, but there are plenty of sites than can help you. Earlier this year I recorded a session on how to get certified. I put lots of tips and advice into that. You can find it here. kzbin.info/www/bejne/p3KYeaxpa9ShmNk I wish you the very best of luck my friend 👍😊
@balarajuc50487 ай бұрын
thanks lot
@micah7448Ай бұрын
10:14 I wish you showed how this was actually done!