Microsoft Intune for SCCM Admins Part 1

0
Microsoft Intune for SCCM Admins

I’m hoping to give some fair bit of idea about Microsoft Intune for SCCM admins. I don’t want to make this post very long, hence planning to divide into multiple posts. In the first part of Intune for SCCM admins, I will cover the basics.

NOTE! – This post is from an SCCM Admin (Windows Device Management) perspective. You might have a different perspective, depending on your job role.

What is Microsoft Intune for SCCM Admins?

Intune can perform most of the functionalities of SCCM. As per Microsoft, Microsoft Intune is built on modern modular cloud components. This solution was decoupling the services in the monolith from development, deployment, and maintenance perspectives.

Intune is ready-to-use SaaS (Software-As-A-Service) solution for device management from Microsoft

Microsoft Intune is an Enterprise Mobility Management (EMM) solution from Microsoft. Microsoft Intune helps to manage all flavors of devices (Windows, iOS, Android, and MacOS). This solution helps to deliver network settings and other device management settings. 

Microsoft Intune is a combination of Device, Application, Information Protection, Endpoint Protection (antivirus software), Security, and Configuration policy management solution.

Intune Servers & Management?

Microsoft Intune for SCCM Admins
Many Intune Tenants Hosted under one cloud infra within Microsoft Data Center – Really? I don’t know.

Microsoft handles intune Servers and management of those servers. Microsoft Intune is a Software As A Service (SaaS) solution from Microsoft. Following are some of the points which are useful with Intune from some of the organization’s perspective.

  • There is no Servers requirement to install Intune (Purchase EMS or Microsoft 365 license and start using it) – Managed by Microsoft
  • Maintenance of Servers are not required to update Intune to latest version – Managed by Microsoft
  • Intune Web Console access anytime anywhere – Managed by Internal IT (Intune Admin)
  • Intune admin won’t be able to check and edit Intune Database unlike SCCM Database – Managed by Microsoft
  • Intune Admin don’t have any option to go back to previous Intune version
  • Perform Intune Server side troubleshooting – Managed by Microsoft
Intune Version - Microsoft Intune for SCCM Admins
Intune Version 1905 👍 – Microsoft Intune for SCCM Admins

Intune Infra Administration

As I mentioned above, Intune server infra is managed by Microsoft as this solution is SaaS. As an SCCM admin, all infra admin tasks are located in Administration workspace. The logical view of Microsoft Intune for SCCM Admins.

There are very less or no server admin tasks for Intune admins. However, you might still need to install connectors, global policies before start Intune deployment. Most of these activities are one time activities. You can just setup Intune and forget.

You might need to configure the following components from an Infra administration perspective.

Logical View of Intune Administration - Microsoft Intune for SCCM Admins
Logical View of Intune Administration – Microsoft Intune for SCCM Admins

Discovery of User, Groups, & Devices

SCCM can discover the resources from the network (Active Directory or Azure Active AD or Network discovery) and install clients on those devices. For Intune, you don’t have to do this type of configuration.

Intune is tightly integrated with Azure Active Directory and Intune blade will have all the Device, User, and Group resources available for you to use without doing any discovery configurations.

Users, Devices, and Groups - Microsoft Intune for SCCM Admins
Users, Devices, and Groups – Microsoft Intune for SCCM Admins

NOTE! Microsoft Intune Setup steps explained in Microsoft Docs.

Client Installation & Upgrade

SCCM client installation and enrollment methods are different from Intune enrollment options.

Unlike SCCM, Intune doesn’t have any separate client component. Intune is managing Windows devices by in-build MDM component of Window 10 Operating System. So, there is no need to Install Intune client on Windows 10 devices.

NOTE!Intune Company Portal is end user application for Microsoft Intune. This app can be installed as Intune client component on a Windows 10 device.

Two main Intune Enrollment Options are explained in the following blog posts. More details are available in my Intune Learning post. Also, Intune enrollment can be done via Microsoft Autopilot (Windows Autopilot).

MDM Client is part of Windows 10 OS - Microsoft Intune for SCCM Admins
MDM Client is part of Windows 10 OS

NOTE 1 – No, there is nothing called Intune Client upgrade for Windows devices. Intune is using Windows 10 MDM component for management. So, the MDM component will get updated with Windows 10 updates.

NOTE 2 – Intune also uses Intune Management Extension agent for Win32 App deployment. The installation & Update of this Intune Management Extension agent is handled automatically in 99% of the scenarios.

Collections & Groups

SCCM collections are used to group the resources which you want to manage. There is no collection concept in Microsoft Intune.

Intune uses Azure AD User & Device groups in the place of collections. So, you can create the following type of groups in Azure AD and deploy applications and policies to those Azure AD groups.

Azure AD Groups Vs SCCM Collections - Microsoft Intune for SCCM Admins
Azure AD Groups Vs SCCM Collections

NOTE! – Many years (I feel like) before even Intune had their own separate Intune Groups and they removed Intune Groups as part of Azure Intune portal migration from Intune Silverlight portal.

Configuration Items & Compliance Policies

SCCM CI (Configuration Items), Baselines, Compliance Policies, and others are available in Microsoft Intune. The following details would be helpful in Microsoft Intune for SCCM admins context.

In the Intune portal, you can create similar policies (as mentioned above) from Device Compliance, Device Configuration, and Device Security nodes.

SCCM CI & Compliance Policies - Microsoft Intune for SCCM Admin
SCCM CI & Compliance Policies – Microsoft Intune for SCCM Admin

NOTE! – I will continue more settings and other details in upcoming posts (Microsoft Intune for SCCM Admins Part 2). So, in this post, I covered the SCCM Administration, Assets & Compliance Workspace.

Resources

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.