Explore MDM Flashcards
What makes up the Desktop Life Cycle Model ?
Plan / Purchase / Deploy / Operate / Support / Upgrade / Retired
What are the too types of azure accounts?
Member and Guest
How Do you create Azure Accounts
Directory Sync and On the Cloud
What is Password Hash Synchronization?
Passwords are the same in both the cloud and Local
What is password Passthrough ?
Does not keep password in the cloud
What Type of devices can Join Azure AD?
Windows Home (including Pro & Enterprise), iOS or Android
What is Hybrid Azure AD join?
Hybrid Azure AD join is a process to automatically register your on-premises domain-joined devices with Azure AD
What devices are supported in Hybrid Azure AD join scenarios
Windows 10 or later
Windows Server 2016 or later
Windows 8.1
Windows Server 2012 R2
What authentication protocols does azure ad join require ?
WS-Fed and WS-Trust username/password endpoint
Where do you access intune?
https://endpoint.microsoft.com
What is a csr?
Certificate Signing Request (CSR)
Remember 1
Automatic enrollment to MDM works for Windows devices, because only Windows devices can be joined to an on-premises AD DS and Azure AD
How do you join devices to MDM that are not Windows ?
Other devices, such as Android and iOS devices, can only be enrolled manually to MDM by using the Company Portal app
What are the Intune Supported Devices ?
Windows 10/11 (Home, Pro, Education, S mode, and Enterprise versions)
Windows 10/11 Cloud PCs on Windows 365
Windows 10 IoT and Windows 10 Holographic
Windows 10 2019 LTSC
Windows RT 8.1, and Windows 8.1 (sustaining mode)
Apple iOS/iPadOS 13.0 and later
Mac OS X 10.15 and later
Android 6.0 and later, including Samsung Knox 2.4 and later and Android for Work
what is the default number of devices users can enroll in Intune?
By default, this is set to five devices per user
What type of device can be configured for automatic enrollment ?
Windows Only
what is the user driven method?
enrolls only intune but not azure ad joined
what is Azure AD join (OOBE)?
enrolls the device as a join work scenario
what is DEM?
A Device Enrollment Manager (DEM) account. A DEM account is useful for scenarios where devices are enrolled and prepared before handing them out to the users of the devices. The DEM would enroll the device, log on to the company portal and install the apps required by the user
WHAT IS CO-MANAGEMENT ?
Co-management enables you to concurrently manage Windows devices by using both Configuration Manager and Intune. It’s a solution that provides a bridge from traditional to modern management and gives you a path to make the transition using a phased approach
what do you use to make a provisioning pack ?
Windows Configuration Designer app
how many devices can a dem enroll?
1000
what is enterprise state roaming?
Enterprise State Roaming defines which groups may sync settings and app data across devices.
what is fresh start?
Fresh Start (Windows 10 and later only). Removes any apps that are installed on a PC. Fresh Start helps remove pre-installed (OEM) apps that are typically installed with a new PC.
what is retire?
Retire. Removes managed app data (where applicable), settings, and email profiles that were assigned by using Intune. The device is removed from Intune management
what is wipe ?
Wipe. Restores a device to its factory default settings. The user data is kept if you choose the Retain enrollment
how to you create a device configuration profile?
In the Endpoint Manager admin center, select Devices, then select Windows platform, then select Configuration Profiles.
Select Create Profile.
Enter the following properties:
Platform: Choose which versions of Windows to include.
Profile type: Select the type you want to create.
what is csp?
Configuration Service Provider (CSP)
how to monitor device profiles ?
In the Endpoint Manager admin center, select Devices.
On the Devices overview page, select Monitor , then select Assignment status
what is device sync?
The Sync device action forces the selected device to immediately check in with Intune. When a device checks in, it immediately receives any pending actions or policies that have been assigned to it
how do you view device sync status?
Devices > Monitor > Device actions
what are Configuration policies?
Commonly used to manage security settings and features on your devices, including access to company resources. Get started at Intune device profiles.
what are Device compliance policies?
Define the rules and settings that a device must comply with to be considered compliant by conditional access policies. You can also use compliance policies to monitor and remediate the compliance of devices independent of conditional access.
what are Conditional access policies ?
Help secure email and other services, depending on conditions that you enter.
what are Corporate device enrollment policies?
Intune supports the enrollment of corporate-owned iOS devices using the Apple Device Enrollment Program (DEP) or the Apple Configurator tool running on a Mac computer.
how many attempts does a device make to if it does not check in with intune?
3
what does the Intune management extension do ?
lets you upload PowerShell scripts in Intune to run on Windows devices, as well as shell scripts for the macOS
what are Intune management extension requirements ?
Windows
Version 1607 or later.
version 10.12 or later
Devices must be joined to Azure AD, including Hybrid AD joined devices.
Devices are managed by Intune.
Automatic MDM enrollment must be enabled in Azure AD.
mac
Shell scripts begin with #! and must be in a valid location such as #!/bin/sh or #!/usr/bin/env zsh.
Command-line interpreters for the applicable shells are installed.
what is a user profile ?
A user profile is a set of files and folders. It is personal to each user who has signed in to the computer, and it’s stored in the Users folder
what is a default user profile ?
A default profile is a pre-configured baseline profile, which contains all of the initial settings to be included, whenever a new profile is created.
what are the four types of user profiles ?
Local User Profile. This type is available on a single computer only.
Roaming User Profile. This type can roam between computers that are domain members.
Mandatory User Profile. This is a special type of pre-configured user profile that does not store user changes between sign-ins.
Temporary User Profiles. A temporary profile is issued each time that an error condition prevents the user’s profile from loading.
what are the profile extensions for user profiles
Windows 8.1
Windows Server 2012 R2
V4
Windows 10, version 1607 and later.
Windows Server 2016 and later
V6
what are quotas for user profiles ?
An option to limit user profile sizes is to use quotas. You can use the same approach to limit the disk space that a user consumes in general, and it applies to limiting user profile sizes. You can set a disk quota on a local Windows volume by using volume properties
what is folder redirection ?
Folder Redirection is a Group Policy setting that is most often used for configuring user profiles. Administrators can use Folder Redirection to redirect individual folders from a user profile to a new location
how many folder can be redirected
13 folders
what can enterprise state roaming do?
Enterprise State Roaming can sync only settings and not data
more on enterprise state roaming ?
Enterprise State Roaming syncs settings across Azure AD joined devices and provides users with the same experience across their devices. Enterprise State Roaming provides the following benefits
Enterprise State Roaming syncs only state of the business UWP apps.
what does Azure Rights Management (Azure RMS) do ?
Encrypt data settings
how long is enterprise state roaming data kept for ?
90 days
more on ESR
Enterprise State Roaming (ESR) does not provide a mechanism for synchronizing user files, such as documents and pictures
WHAT DOES Microsoft Edge sync BACK UP?
Favorites
Passwords
Form-fill
History
Open tabs (sessions)
Settings (preferences)
Extensions
WHAT IS User Experience Virtualization (UE-V)?
User Experience Virtualization (UE-V) is a Windows Enterprise edition feature that enables the synchronization of operating-system settings, desktop-application settings, Microsoft Store app settings, network printers, and user credentials between Windows Enterprise edition computers in the same AD DS domain environment.
How do you enable Enterprise state roaming?
azure Active Directory > Devices > Enterprise State Roaming
All or Selected next to Users may sync settings and app data across devices
what type of data is backed up by esr?
Theme, which includes features such as desktop theme and taskbar settings.
Internet Explorer settings, including recently opened tabs and favorites.
Passwords, including Internet passwords, Wi-Fi profiles, and others.
Language preferences, which include settings for keyboard layouts, system language, date and time, and more.
Ease of access features, such as high-contrast theme, Narrator, and Magnifier.
Other Windows settings, such as mouse settings.
what is MAM?
Intune Mobile Application Management (MAM) refers to the suite of Intune management features you can use to publish, push, configure, secure, monitor, and update mobile apps for your users
What is Intune MDM + MAM?
IT administrators can only manage apps using MAM and app protection policies on devices that are enrolled with Intune MDM.
MAM without device enrollment?
MAM without device enrollment (MAM-WE) allows IT administrators to manage apps using MAM and app protection policies on devices not enrolled with Intune MDM. This means apps can be managed by Intune on devices enrolled with third-party Enterprise Mobility Management (EMM) providers. Also, apps can be managed by Intune on devices enrolled with third-party EMM providers or not enrolled with an MDM at all.
why are app protection policies important ?
The important benefits of using app protection policies are:
Protecting your company data at the app level. Because mobile app management doesn’t require device management, you can protect company data on both managed and unmanaged devices. The management is centered on the user identity, which removes the requirement for device management.
End-user productivity isn’t affected, and policies don’t apply when using the app in a personal context. The policies are applied only in a work context, which gives you the ability to protect company data without touching personal data.
what can you use to protect app data?
You can enable your apps to use app protection policies by using either the Intune App Wrapping Tool or the Intune App SDK.
what is the Intune App Wrapping Tool
The App Wrapping Tool is used primarily for internal line-of-business (LOB) apps. The tool is a command-line application that creates a wrapper around the app, which then allows the app to be managed by an Intune app protection policy.
what is Intune App SDK
The Intune App SDK is designed mainly for customers who have apps in the Apple App Store or Google Play Store, and want to be able to manage the apps with Intune. However, any app can take advantage of integrating the SDK, even line-of-business apps.