Windows 10 and later
Patching Gaps in the CIS Windows 11 Benchmark - Level 1 Windows Autopilot
Intune
Windows 10 and later
Security
Center for Internet Security (CIS)
Windows Autopilot
Windows Hello
Settings Catalog
PowerShell
With the CIS BitLocker and associated DMA settings reviewed and updated, now is time to delve into the Windows 11 specific settings that exist in the CIS Level 1 benchmark. What issues do they bring to Windows Autopilot, what solutions can we find? Honestly, who knows.
Patching Gaps in the CIS Windows 11 Benchmark - BitLocker
Intune
Windows 10 and later
Security
Center for Internet Security (CIS)
Custom Profiles
BitLocker
Direct Memory Access
Settings Catalog
Endpoint Security
Everyone loves a security benchmark, and with the imminent move to Windows 11 for everyone, the Center for Internet Security released version 3.0.1 of theirs, including a build kit for Microsoft Intune, but what does this build kit break for BitLocker encryption?
Risk Based Windows 11 Feature Update Deployment - Automation
Intune
Windows 10 and later
Software Updates
Feature Updates
Dynamic Groups
PowerShell
Graph API
Automation
The final part in this series looks at how to bring everything together under a single, repeatable script, allowing for the capture of readiness state, the tagging of devices to support the distribution of Windows 11 23H2.
Risk Based Windows 11 Feature Update Deployment - Feature Updates
Intune
Windows 10 and later
Software Updates
Feature Updates
Dynamic Groups
PowerShell
Graph API
Using the data captured from a Windows 11 Feature Update Readiness report to successfully tag device attributes to device objects, and group them based on risk, we now look at how to deploy Feature Updates to these devices in a controlled manner.
Risk Based Windows 11 Feature Update Deployment - Device Attributes
Intune
Windows 10 and later
Software Updates
Feature Updates
Dynamic Groups
PowerShell
Graph API
Automation
Having looked into capturing the Feature Update Readiness data for Windows 11 23H2 for our Windows devices, we can now use this risk based data to tag them with their associated risk, grouping them together to allow for sensible Feature Update profile assignment.
Risk Based Windows 11 Feature Update Deployment - Reporting
Intune
Windows 10 and later
Software Updates
Feature Updates
Dynamic Groups
PowerShell
Graph API
Automation
With Windows 10 support coming to an end sooner than you’d expect, in the first part of this series we look at ways to capture Feature Update Readiness Report data using PowerShell and Graph to help with the rollout of the new Windows 11 operating system.
Remediating BitLocker DMA Exception Errors with Microsoft Intune
Intune
Windows 10 and later
BitLocker
PowerShell
Security
Direct Memory Access
So you’ve configured BitLocker encryption in Microsoft Intune, but some of your devices are failing to encrypt complaining about a DMA exception issue as part of Automatic Encryption. How can we fix that without creating a gaping security hole?
Creating Reusable Groups of Firewall Settings for Microsoft Online Services
Intune
Windows 10 and later
Security
PowerShell
Graph API
Settings Catalog
Firewall
Automation
Endpoint Security
It’s time to remove another manual process, this time the creation of Microsoft 365 network endpoints for Windows Firewall Rules in Microsoft Intune, because nobody should be creating these manually.
A Flexible Approach to Microsoft Update Deployments
Intune
Windows 10 and later
Software Updates
Dynamic Groups
Security
National Cyber Security Centre (NCSC)
It’s been a while since we’ve looked at deploying Microsoft and Windows Updates using Microsoft Intune, this time we look at different ways to phase our deployments across a device estate.