Skip to main content

Security

Lower-Touch Defender for Endpoint Onboarding for Android Devices
Intune Android Microsoft Defender Security OEMConfig
Can we improve upon the onboarding of Android Enterprise devices to Defender for Endpoint and make users lives a little easier, and Security Teams hearts a little less restless having to rely on end users to implement their own security controls?
Forcing Windows 11 Feature Update Readiness Assessments
Intune Windows 10 and later Software Updates Feature Updates Remediation Scripts PowerShell Security
As a migration to Windows 11 is fast upon us, I thought I’d help your devices on their way into understanding whether they will support Windows 11 and what risks you may encounter with the update, by forcing devices to evaluate their readiness states.
Converting AppLocker Policies to Intune Profiles
Intune Windows 10 and later AppLocker Security PowerShell Custom Profiles Graph API Endpoint Security
We know that there is no native configuration for AppLocker in Intune, and we should be looking at App Control for Business already, but there is still a place for AppLocker, and I haven’t got time to manually do anything, so let’s use PowerShell to create out AppLocker policies from exported XML files.
Scheduling Defender for macOS Antivirus Scans in Intune
Intune macOS Configuration Custom Profiles PowerShell Security Jamf Endpoint Security Microsoft Defender
You’d think creating Defender antivirus scan schedules should be pretty easy, even if the devices you’re working with are running macOS. Why are we having to create mobileconfig files for this in Microsoft Intune? Surely we can make this a little better?
Self-Service Software Update Deployments
Intune Windows 10 and later macOS iOS/iPadOS Android Software Updates Dynamic Groups Security
Fancy letting your end users select what day of the week they get their device updates allowing them to be truly empowered but still ensure a level of device security, sure you do.
Patching Gaps in the CIS Windows 11 Benchmark - Level 2 Windows 11
Intune Windows 10 and later Security Center for Internet Security (CIS) Custom Profiles Settings Catalog Remediation Scripts PowerShell
This is the last part in the series around the CIS (Center for Internet Security) benchmark for Windows 11, and we’d like to say that we’ve saved the best post for last, but we’d be lying. Surely the Level 2 settings can’t be worse than the Level 1?
Microsoft Intune and the Curious Case of the Converting Firewall Rule Policy
Intune Windows 10 and later Settings Catalog Security Firewall Endpoint Security PowerShell
When did Microsoft go all covert ops (maybe don’t answer that question) and start making changes to your very own Firewall Rule policies in Microsoft Intune without letting anyone know? Or did they?
Patching Gaps in the CIS Windows 11 Benchmark - Level 1 Windows 11
Intune Windows 10 and later Security Center for Internet Security (CIS) Endpoint Security Remediation Scripts PowerShell Settings Catalog Custom Profiles
The impact of the CIS settings on BitLocker and Windows Autopilot now done and dusted, we should broaden our horizons and start to look at what other problems the CIS level 1 benchmark brings to Windows 11 as a whole. Are there any? Will it be smooth sailing? Yeah, no.
Patching Gaps in the CIS Windows 11 Benchmark - Level 1 Windows Autopilot
Intune Windows 10 and later Security Center for Internet Security (CIS) Windows Autopilot Windows Hello Settings Catalog PowerShell
With the CIS BitLocker and associated DMA settings reviewed and updated, now is time to delve into the Windows 11 specific settings that exist in the CIS Level 1 benchmark. What issues do they bring to Windows Autopilot, what solutions can we find? Honestly, who knows.