<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>MDM on wporter.org</title>
    <link>https://wporter.org/categories/mdm/</link>
    <description>Recent content in MDM on wporter.org</description>
    <generator>Hugo</generator>
    <language>en-US</language>
    <lastBuildDate>Sat, 23 Aug 2025 12:00:00 +0000</lastBuildDate>
    <atom:link href="https://wporter.org/categories/mdm/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Microsoft MD-102 (Endpoint Administrator): Pass!</title>
      <link>https://wporter.org/microsoft-md-102-endpoint-administrator-pass/</link>
      <pubDate>Sat, 23 Aug 2025 12:00:00 +0000</pubDate>
      <guid>https://wporter.org/microsoft-md-102-endpoint-administrator-pass/</guid>
      <description>&lt;h2 id=&#34;my-thoughts-on-the-certification&#34;&gt;My thoughts on the certification&lt;/h2&gt;&#xA;&lt;p&gt;I passed the Intune test!&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s been about a year since I started working at a shop that uses Intune (a bit - for iOS and Macs), so on a whim I decided I should get the cert. It took me about three weekends, plus a few hours of study during the week.&lt;/p&gt;&#xA;&lt;p&gt;I had a decent bit of experience with Intune, but don&amp;rsquo;t use it daily.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring silent OneDrive sign-in and Known Folders sync</title>
      <link>https://wporter.org/configuring-silent-onedrive-sign-in-and-known-folders-sync/</link>
      <pubDate>Sun, 17 Aug 2025 17:00:00 +0000</pubDate>
      <guid>https://wporter.org/configuring-silent-onedrive-sign-in-and-known-folders-sync/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/sharepoint/use-silent-account-configuration&#34;&gt;MS Learn link here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;You can do this via Group Policy or Intune, depending on how your environment is configured, but the policies are the same.&lt;/p&gt;&#xA;&lt;h2 id=&#34;deploying-silent-onedrive-sync-with-intune&#34;&gt;Deploying silent OneDrive sync with Intune&lt;/h2&gt;&#xA;&lt;p&gt;For successful, silent sync, you MUST configure these three policies:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Silently move known folders to OneDrive&lt;/li&gt;&#xA;&lt;li&gt;Silently sign users in to OneDrive with their Windows credentials&lt;/li&gt;&#xA;&lt;li&gt;Enable Files on Demand&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Here is an example of this minimal configuration in Intune. Choose just these settings from the Settings Catalog and enable them:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Onboarding Microsoft Defender for Endpoint with Intune</title>
      <link>https://wporter.org/onboarding-microsoft-defender-for-endpoint-with-intune/</link>
      <pubDate>Sun, 17 Aug 2025 16:45:00 +0000</pubDate>
      <guid>https://wporter.org/onboarding-microsoft-defender-for-endpoint-with-intune/</guid>
      <description>&lt;h2 id=&#34;licensing-prerequisites&#34;&gt;Licensing Prerequisites&lt;/h2&gt;&#xA;&lt;p&gt;Your tenant requires a license for Defender for Endpoint - either a Microsoft Defender for Endpoint P1 or P2, Microsoft Defender for Server, or Microsoft Defender for Business (&amp;ldquo;P1.5&amp;rdquo; edition for SMBs included with Microsoft 365 Business Premium).&lt;/p&gt;&#xA;&lt;p&gt;Without one of these licenses, you will not see the Assets &amp;gt; Devices tab or the Settings &amp;gt; Endpoints menu, and cannot onboard devices to MDE.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;It may take up to 24 hours for your Defender tenant to be provisioned&lt;/strong&gt; once you have purchased and assigned the required licensing. Your admin account does &lt;strong&gt;not&lt;/strong&gt; need to be licensed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Intune Assignment Filters</title>
      <link>https://wporter.org/microsoft-intune-assignment-filters/</link>
      <pubDate>Sun, 17 Aug 2025 16:30:00 +0000</pubDate>
      <guid>https://wporter.org/microsoft-intune-assignment-filters/</guid>
      <description>&lt;p&gt;For info on designing filters for performance and manageability, &lt;a href=&#34;https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/filters-performance-recommendations&#34;&gt;see MS docs&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Device assignment filters allow you to select what devices a policy assigned to users will apply to, and let you select what devices in a device group are eligible for a policy.&lt;/p&gt;&#xA;&lt;p&gt;App assignment filters allow you to select what devices specific app protection policies apply to.&lt;/p&gt;&#xA;&lt;p&gt;They&amp;rsquo;re both useful tools for scoping down your Intune configuration policies. Let&amp;rsquo;s have a look at them!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Deploying Windows LAPS for client PCs with Microsoft Intune</title>
      <link>https://wporter.org/deploying-windows-laps-for-client-pcs-with-microsoft-intune/</link>
      <pubDate>Sat, 09 Aug 2025 16:35:00 +0000</pubDate>
      <guid>https://wporter.org/deploying-windows-laps-for-client-pcs-with-microsoft-intune/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;The Windows Local Administrator Password Solution (LAPS) allows administrators to configure a randomized, automatically rotated administrative password for Windows devices. This is a distinct feature from macOS LAPS.&lt;/p&gt;&#xA;&lt;p&gt;Windows LAPS, integrated with Entra ID, replaces the older &amp;rsquo;legacy&amp;rsquo; Microsoft LAPS solution as of Windows 11 23H2. Microsoft is no longer updating &amp;rsquo;legacy&amp;rsquo; LAPS and its .msi package will be blocked from installing on Windows 11 24H2, Server 2025, and newer OSes.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
