Learn Intune Beginners Guide MDM MAM MIM

Loads of people have requested an Intune starter kit, as I have one for SCCM. I think the SCCM  starter kit page was helpful in the IT community. Mobile device management is new for most IT Pros in the device management world.

This post would be helpful for Intune newbies. It details “Beginners Guide to Learn Intune MDM MAM MIM—Learn Microsoft Intune.”

In this post, I will concentrate on Intune standalone. I won’t cover SCCM Hybrid/Mixed Intune and Office 365 Intune MDM. In most scenarios (for Intune Standalone), there is no or minimal need for on-premises infrastructure.

Intune standalone is the way to go when you want to take the path of modern management. Most of the Intune components are hosted in Microsoft Azure. I’ll keep this post updated with new Intune features.

Patch My PC

Table of Contents

My latest Intune posts are available at https://www.anoopcnair.com/intune/

Learn Intune Beginners Guide MDM MAM MIM – Great Learning for Intune Beginners

SCCM is excellent, and it will not die, as per Microsoft. But don’t abandon Intune learning. I strongly recommend going through the Intune learning process. What to Learn Intune? Great Resource Around you!

Adaptiva

Intune for SCCM Admins

Microsoft Intune is a modern device management solution. I recommend that SCCM admins start learning it. I have a series of posts to explain the difference between SCCM and Intune administration and architecture. Check out those posts:

  1. Microsoft Intune for SCCM Admins Part 1 (the video post here)
  2. Microsoft Intune for SCCM Admins Part 2
  3. Microsoft Intune for SCCM Admins Part 3 (sometime in future ;))

Intune Very High-Level Architecture Flow 

We already have a Facebook group for Intune Professionals. To join the Intune Professionals Facebook community, click here. You can also subscribe to the YouTube channel, which has loads of Intune tutorials

Learn Intune Beginners Guide MDM MAM MIM - Fig.1
Learn Intune Beginners Guide MDM MAM MIM – Fig.1

Why Learn Microsoft Intune as a Beginner?

When you look at the Desktop (43.29%), mobile (52.29%), and tablet (4.42%) Market Share Worldwide for last year, you can see that mobile devices are the leaders.

So, Mobile Device Management is critical, and this is a new world of opportunities for IT Pros like us. From my perspective, Learning Microsoft Intune is essential for SCCM admins.

I don’t think SCCM will disappear for another 5-6 years. I know some SCCM 2007 environments are managing more than 40K devices. So, it will take a long time to migrate corporate organizations to modern device management solutions.

However, I also agree that we must Learn Microsoft Intune Mobile Device Management (MDM) and mobile Application Management (MAM) technologies, etc. This is why it’s essential to learn Microsoft Intune, which is important for SCCM admins.

Mobile Device Management (MDM) is not used only for managing or administrating mobile devices. Instead, MDM also includes administering a wide range of new laptops, desktops, etc. For example, with Windows 10, all desktops and laptops can be managed through the MDM channel.

Learn Intune Beginners Guide MDM MAM MIM - Fig.2
Learn Intune Beginners Guide MDM MAM MIM – Fig.2

What is Microsoft Intune, and How is it Different?

Intune is a Microsoft enterprise mobility management (EMM) solution. The EMM provider helps to manage mobile devices, network settings, and other mobile services and settings.

Microsoft Intune combines Devices, Applications, Information Protection, Endpoint Protection (antivirus software), and a Security/Configuration policy management solution (SaaS) facilitated by Microsoft in the Cloud.

Additionally, Azure AD has a feature where admins can create a “Conditional Access (CA)” policy to access company resources. This Azure AD CA policy can be combined with Intune compliance policies. Only Intune will provide access to company or corporate resources (corporate email, SharePoint, etc.). Intune is pure cloud architecture, and it’s fun to Learn Microsoft Intune.

Previously, I mentioned Microsoft Intune as a lighter version of SCCM or ConfigMgr in the cloud. However, I don’t want to make the comparison so simple this time.

Intune architecture is entirely cloud-based and agile. The video below provides a more detailed idea about Microsoft Intune. Yes, this video is old and outdated, but very well explained.

How to Start Working with Intune as a Beginner

You can download the Microsoft EMS step-by-step setup guide from here. This guide will help you get a trial version of Office 365, Azure AD, and Intune subscription.

As I posted on the blog here, if you already have an Azure AD (Azure AD premium) subscription, things are very straightforward. First and foremost, you must have a strong desire and determination to Learn Microsoft Intune.

If you don’t have an Azure AD subscription, it’s better to start with an Enterprise Mobility Suite (EMS) trial account, Azure Free Trial Account, or Office 365 free trial subscription.

The Azure trial account has already been created as an EMS trial account. It’s better to make a NEW outlook.com account and get ready with Credit Card details to activate the Azure trial subscription.

Getting a trial version of Azure AD, Office 365, and Intune is very straightforward if you have never done this same process with your credit card and mobile number. Azure AD and Office 365 are prerequisites for Intune if you want to test all its features.

  • Note: Intune can also be signed up separately from here. This is the way to go if you are interested in testing only Intune now.
Learn Intune Beginners Guide MDM MAM MIM - Fig.3
Learn Intune Beginners Guide MDM MAM MIM – Fig.3

Intune Quick Start Tips

What are the Management Options in Intune?

Intune can manage Mac-OS, Android, iOS, and Windows devices via the MDM (Mobile Device Management) channel. I cover MAM (Mobile Application Management) in the section below.

NOTE! – Different Microsoft Intune Enrollment options are explained in the following post. https://microscott.azurewebsites.net/2018/08/31/managing-windows-10-with-intune-the-many-ways-to-enrol/

We can manage devices (via MDM) with an Intune client agent and arguably without one. However, to manage iOS, Android, and Mac-OS devices, Intune needs an agent to be present on the device. 

The Intune company portal application is the Intune agent. Details are available in different app stores, such as Google Play and Apple Store.

So, when you install the Intune company portal onto your Android or iOS devices, you are performing Intune agent-based management. An Intune MSI client can be downloaded for Windows 7 and 8 devices.

For Windows 10, Intune builds the operating system’s MDM stack. Enrolling devices and decision-making regarding this is a critical step in Learning Microsoft Intune.

Learn Intune Beginners Guide MDM MAM MIM - Fig.4
Learn Intune Beginners Guide MDM MAM MIM – Fig.4

Windows 10 Device Enrollment – Manual

More details are in the following posts: Windows 10 Intune Enrollment Process BYOD Scenario and Windows 10 Azure AD Join Manual Process – CYOD.

  • Enrolled via Installation of Intune MSI client
  • Enrolled via the Intune company portal
  • Enrolled via Windows 10 1607 and later in build Azure AD join and MDM enrolment
  • MAM without MDM enrolment
Learn Intune Beginners Guide MDM MAM MIM – Video 1

What is Modern Workplace OSD Replacement (Windows AutoPilot)?

I have more posts related to Windows Autopilot at the following linkhttps://www.anoopcnair.com/windows-autopilot/.

Learn Intune Beginners Guide MDM MAM MIM – Video 2

Intune MAM Enabled Applications

Updated List of Microsoft Intune MAM-protected apps https://docs.microsoft.com/en-us/intune/apps-supported-intune-apps.

How to Start Using Intune Console?

The Intune blade (console) is part of the Azure portal, which has many new features and functionalities. This section will provide an overview of the New Azure Intune Portal. Try it out at https://portal.azure.com.

The following documentation is where you can start reading about all the Intune topics:- Microsoft documentation Intune quick start guide here. Another post gives a “Quick Overview of New Intune Azure.” Also, you can look at the video tutorial here to understand the Intune Azure console.

What are Intune Team’s Roles & Responsibilities?

The roles and responsibilities of the Intune team are summarized below at a high level. Some parts of it involve Azure AD and other teams of the organization.

Understanding the roles and responsibilities will help the IT Pros understand how Intune works. And how will Intune be deployed within the organization? More details are available in my previous post, “Intune Team’s Roles and Responsibilities.”

  • Setting up a team is also part of the Learn Microsoft Intune process.
  • User Management
  • Application Creation and Deployment/Assignment
  • Service Administration
  • Mobile Application Management
  • Device/Profile Management
  • Conditional Access
  • Company Resource Access
  • Software Update Management

What is Intune MDM Authority?

Setting up a mobile device management authority (MDM) is essential before working with Intune. The MDM authority determines where you will perform mobile device management tasks.

Microsoft provides 3 options to set the MDM authority: Microsoft Intune using the Intune Azure console or SCCM using the SCCM CB console. Understanding the details about MDM authority when learning Microsoft Intune is important.

  • Microsoft Intune
  • Office 365 (lightweight Intune)

The best design decision is to set Mobile Device Management (MDM) authority as Intune. You can set MDM authority Microsoft_Intune_Enrollment / OverviewBlade /overview section from Azure Portal.

Learn Intune Beginners Guide MDM MAM MIM - Fig.5
Learn Intune Beginners Guide MDM MAM MIM – Fig.5

How to Start Managing Devices with Intune?

Windows 10 device management is straightforward with Intune. It takes 10 minutes to sync your Windows Store for Business and Microsoft Intune. The post “Integrate Windows Store for Business” provides more details. Learning Microsoft Intune is important if you work in Device management.

If you want to install store apps with the corporate account, we can sync the Windows Store for Business with Intune. Once the store apps are synced with Intune, we can deploy them to Windows 10 devices. Read the following blog post for more details: “How to Add Apps to Business Store and Install Intune Company Portal without Using MS Account.”

Intune Windows 10 MDM YouTube Playlist

Google provides two management channels for Android devices: one for general management and the other for Android Work (Android for Work) device management.

  • Android (General)
  • Android for Work

Intune supports both management channels. Google’s strategic approach is to help management only via the Android Work channel. Learning Microsoft Intune should be part of SCCM Admin’s strategic approach.

In one of my previous posts, I explained how to set up Android Work from the Intune Azure Portal. You need a Google account to complete the setup of Android for Work in the Intune console. The following post provides more details about Android for Work Enrolment readiness: Step by Step Video Guide Intune Azure Portal How to Setup Android Work Support.

Videos Android Devices Management via Intune

iOS\MAC OS device management has certificate requirements, and we need to go to the Apple portal, upload your cert for the tenant and get the certificate for your Intune tenant. Similar to Android, iOS and Mac-OS have two channels of management. One is traditional management, and the other is advanced management via Apple DEP management.

The first iOS and MAC OS device enrollment requirement is the Apple MDM push cert setup. You need to download a different certificate signing request (CSR) from the Intune tenant and upload it to the Apple portal. Once uploaded successfully, you can download the Apple MDM push cert from the Apple portal.

Intune Step-by-Step Video Tutorials for iOS

In the following post, I explain the iOS/macOS onboarding process: “How to Get Intune Environment Ready for iOS and Mac OS Devices.”

Intune Automatic Policy Refresh Update? 

Here are the details of the Intune Policy Sync Time. You will better understand these refresh timings as part of Learning Microsoft Intune. When a policy or app is deployed, Intune immediately notify the device to check in with the Intune service. This typically takes less than five minutes.

Intune makes three more attempts if a device doesn’t check in to get the policy after sending the first notification. If the device is offline (for example, turned off or disconnected from a network), it might not receive the notifications.

Learn Intune Beginners Guide MDM MAM MIM - Fig.6
Learn Intune Beginners Guide MDM MAM MIM – Fig.6

A Sequence of Intune Policy Creation

Intune has different types of policies, all of which are used for managing and securing mobile devices. In my opinion, we need to start creating Intune policies in the following sequence.

The sections below of this post provide more details about each type of Intune policy. Understanding this flow is an essential step in learning Microsoft Intune.

A Sequence of Intune Policy Creation
Enrollment Restriction Policy
Conditional Access Policy (Azure AD)
Compliance Policy
Configuration Policy (Device Restriction Policy)
Resource Policy (Wi-Fi, VPN profiles)
Learn Intune Beginners Guide MDM MAM MIM – Table 1
Learn Intune Beginners Guide MDM MAM MIM - Fig.7
Learn Intune Beginners Guide MDM MAM MIM – Fig.7

Why Set Enrollment Restriction Policies

Device Enrollment is the first step of Mobile Device Management (MDM). When a device is enrolled in Intune, it receives an MDM certificate, which it uses to communicate with the Intune service.

From a security perspective, it’s best to restrict devices from enrolling in the Intune environment. Enrolment restriction policies can achieve this. Difference Between Intune Enrollment Restriction Vs. Device Restriction Profile

Why Deploy Intune Compliance Policies?

Compliance policy rules might include using a password/PIN to access devices and encrypting data stored on devices. This set of such rules is called a compliance policy. The best option is to use a compliance policy with Azure AD Conditional Access.

Intune compliance policies are the first step of protection before providing access to corporate apps and data. I have a post that explains “How to Plan and Design Intune Compliance Policy.

Intune Compliance Policy Support Details

The following table lists the device types that compliance policies support. Intune can automatically remediate or quarantine.  The table also describes how non-compliant settings are managed when a compliance policy is used with a conditional access policy. More details here.

Deploy Intune Device Restriction Policy

Intune Device restriction profiles are policies similar to GPO from the traditional device management world. Most enterprise organizations use GPO to restrict corporate-owned devices with these policies.

Restriction policies are security policies that need to be applied to devices. Intune Device restriction policies control mobile devices’ wide range of settings and features (iOS, Android, and Windows 10). My previous blog, “How to Restrict Personal Android Devices from Enrolling into Intune.” I love to learn about Microsoft Intune as it has a 100% return on investment (ROI).

Learn Intune Beginners Guide MDM MAM MIM - Fig.8
Learn Intune Beginners Guide MDM MAM MIM – Fig.8

Deploy Resource Policies (Wi-Fi Profile)

Intune Resource policies help devices connect to corporate resources. Deployment of SCEP profiles helps devices connect to corporate resources through Wi-Fi and VPN profiles, etc. You must develop and deploy a certificate chain before creating an iOS SCEP profile in Intune.

  • My previous post, How to Create and Deploy SCEP Profile to iOS Devices via Intune, provides more details about the Intune resource policy.

Deploy Applications to Devices using Intune

One of Intune’s essential use cases is deploying applications to different devices of different flavors. The applications that Intune supports now are EXE, MSI (Windows Installer and Windows Installer through MDM), APK, IPA, XAP, APPX – APPXBUNDLE for Windows app package and Windows Phone app package.

You can also deploy store applications from the Windows Store, Google Store, and Apple Store using Intune Azure Portal. The following links provide more details about deploying the application via Intune.

MSI application deployment is one of Intune’s best use cases for enterprise customers. My previous post, Intune Azure Step by Step MSI Application Deployment Video Guide, provides more details.

Intune Application Model Support (Complex MSI) 

Now, Intune can deploy all the complex applications to Windows 10 MDM-managed devices using a new agent called Sidecar.

Mobile App Mgmt without Enrollment (MAM)

Microsoft Intune supports MAM without enrollment (MAM WE) and Conditional Access policies for Android devices. There are two types of management options for Windows, Android, and iOS devices with Intune.

The first is the traditional MDM management method, and the second is the light management of Android, iOS, and Windows apps via Intune.

BYOD devices are suitable for the MAM WE type of Intune management. Intune can also have Conditional Access policies assigned to MAM users.

Intune and Mac Device Management

Intune natively supports Mac Device management, but this support is very generic. Jamf is the one third-party solution that Microsoft advised all organizations to look into if they want more deep-level management of Mac Devices with Intune.

More details are available at https://nohuman.dk/ems-jamf-connect-jamf-connect-login/. 

Learn to Troubleshoot Intune Issues

The Azure portal makes troubleshooting Intune easy. Whenever you face an issue with Intune, it’s recommended that you start with the “Microsoft Intune—Help and Support” page.

How to Troubleshoot Android Device​ for Intune Issue

Open the Company Portal app Menu > Help and Feedback
CompanyPortalX.log. This log file contains much information about the communication between the device and Microsoft Intune.​

Omadmlog.log. OMA-DM is an open mobile standard for managing mobile devices. com.microsoft.intune.mam.managedAppName.log. For each managed application, you have a log file with the name of the managed application.​

How to Troubleshoot iOS Device​ for Intune Issue

https://docs.microsoft.com/en-us/intune/enduser/troubleshoot-your-device-ios ​Intune Company portal – User Profile – About – Send Diagnostic Report​CompanyPortal-Log.log​.

How to Troubleshoot Windows Device​ for Intune Issues

Let’s discuss how to troubleshoot Windows Devices​ for Intune issues. Troubleshoot Windows Device​ for Intune Issues. The link is given below.

https://docs.microsoft.com/en-us/intune/enduser/troubleshoot-your-device-windows ​
Registry Keys​
Event Logs​
WMI

How to Start Learning Intune – Microsoft Graph API

More details on Microsoft Intune Graph API are in the following post. This post allows us to dive into many technical areas.

Intune PowerShell Script Samples

You can download Intune PowerShell script samples from GitHub.

Where is the Information Intune MIM in this Post?

EMM, MIM, and MAM are subsets of MDM, so it’s very well part of your Intune MDM policies. This is not me ranting. 🙂 Check this out from Microsoft.

Intune Group Policy Deployment

Let’s learn how to create and deploy Group policies using the Intune Administrative Template. We can use the Intune Administrative Template to deploy the “Cloud” Group Policy for modern managed devices.

NOTE!More details are available in the step-by-step guide https://howtomanagedevices.com/intune/1671/intune-administrative-template/

Ignite Videos Intune

Let’s discuss Ignite Videos Intune. The list below shows the links related to Ignite Videos Intune.

Ignite 2017 Video  Windows 10 & Office 365 ProPlus:

Let’s discuss the Ignite 2017 Video  Windows 10 & Office 365 ProPlus. The list below helps you show more details about the Ignite 2017 Video  Windows 10 & Office 365 ProPlus.

All PPT decks can be found here (updated).

We are on WhatsApp now. To get the latest step-by-step guides, news, and updates, Join our Channel. Click here. HTMD WhatsApp.

Author

Anoop C Nair is Microsoft MVP! He is a Device Management Admin with more than 20 years of experience (calculation done in 2021) in IT. He is a Blogger, Speaker, and Local User Group HTMD Community leader. His main focus is on Device Management technologies like SCCM 2012, Current Branch, and Intune. He writes about ConfigMgr, Windows 11, Windows 10, Azure AD, Microsoft Intune, Windows 365, AVD, etc.

5 thoughts on “Learn Intune Beginners Guide MDM MAM MIM”

  1. Good job
    Maybe could you help me?
    I use autoenrolment scenario for domain joined computer. Intune is set up to standalone. I have ADFS. My device is joined to ad azure (connect type Hybrid Join) with success, device is enrolled to Intune but without user assigment. When I open company portal I see “This device hasn’t been set up for corparate use yet….” . When I try assign I see message that “device is already beging managed by an organization “. In Intune console I see this device and MDM is enabled. What can I do to assign user to device? In event viewer i see 75 event Enroll success
    My previous expirence is that after auto enrolment I open company portal and only choose device category .

    Reply
  2. Hi Anoop,

    I need help in understanding few points.

    1. Is it possible to force company portal application installation on Android, iOS and Windows phone which are not managed, not by applying conditional access. I mean to say no manual intervention required to instay app from the app store.

    2. Certified based WiFi profile. My certificate is per user based, it will have password information for individual user, every user different certificate, what should I do in this case to push this certificate on every win 10 and win7 and mobile devices using Intune.

    3. Intune with Sccm and cloud management gateway to manage remote machines not connected to my network.

    Please share some details for this.

    Reply

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.