This document summarizes how to manage Windows 10 devices in a cloud-only world using Azure Active Directory (Azure AD) joining and Microsoft Intune mobile device management (MDM) enrollment. It discusses auto-enrolling Windows 10 devices into Intune via Azure AD joining, Azure AD joining features, Microsoft Passport, Intune MDM limitations, using OMA-URI for configuration policies, and demonstrations of Intune inventory, software deployment, and policies. The document also briefly mentions the Windows Store for Business.
2. EWUG.dk
Notes from the trenches
How to get around Windows 10 management in a cloud only world.
Per Larsen, Senior Consultant
Blog: https://osddeployment.wordpress.com/
Twitter: @PerLarsen1975
LinkedIn: http://dk.linkedin.com/in/perlarsen1975
3. EWUG.dk
Agenda
How to auto enroll Windows 10 into Microsoft Intune with Azure AD join (Experience with
coexistence of MDM authority)
Azure AD join – what is two-step verification/Microsoft Passport
Microsoft Intune and MDM joined devices
Limitations
Software Deployment
What are OMA-URI, policy CSP and how to use OMA-URI for configuration.
Windows Store for Business
How to get around Windows 10 management in a cloud only world.
6. EWUG.dk
How to auto enroll Windows 10 into
Microsoft Intune with Azure AD join
Requirements
Azure AD Premium
Settings in Azure AD
AzureAD Maximum number of devices per user = 20
Intune Maximum number of devices per user = 5
Intune - Custom URI settings for Windows 10 devices
Experience/AllowManualMDMUnenrollment
How to AzureAD Join a Windows 10 device
Demo
Experience with coexistence of MDM authority
7. EWUG.dk
Azure Active Directory Join – Windows 10 only
features
Free/basic Premium
Join a device to Azure AD, Desktop SSO,
Microsoft Passport for Azure AD, Administrator
Bitlocker recovery
MDM auto-enrolment, Self-Service Bitlocker
recovery, Additional local administrators to
Windows 10 devices via Azure AD Join
8. EWUG.dk
Azure AD join – what is two-step
verification/Microsoft Passport
What is Microsoft Passport
Microsoft Passport is set up on the user's device
The user sets a gesture, which can be Windows Hello or a PIN
Requirements for Microsoft Passport
Initial two-step verification during Microsoft Passport enrollment
How to disable or configure Microsoft Passport (Intune)
9. EWUG.dk
Microsoft Intune and MDM joined devices
Limitations
Intune Client MDM
Software Deployment
Software Update
Endpoint Protection
11. EWUG.dk
What are OMA-URI, policy CSP and how to
use OMA-URI for configuration.
Open Mobile Alliance Device Management (OMA DM) and OMA Client
Provisioning
Policy CSP
https://msdn.microsoft.com/en-
us/library/windows/hardware/dn904962(v=vs.85).aspx
Custom URI settings for Windows 10 devices
https://technet.microsoft.com/en-
us/library/mt126215.aspx