Skip to content
The Lazy Administrator
  • Home
  • Disclaimer
  • Contact
  • About Me
  • Search Icon

The Lazy Administrator

Finding ways to do the most work with the least effort possible

Configure and Deploy Intune MDM

Configure and Deploy Intune MDM

November 19, 2018 Brad Wyatt Comments 21 comments

Table of Contents

  • Description
  • Solution
    • Configure MDM Authority
    • Configure APN Certificate
    • Configure MDM DNS Records
    • Configure Company Portal
      • Configure Portal Terms and Conditions
    • Device Enrollment Administrator
    • Device Enrollment and Type Restrictions
    • Device Group Mappings
      • Step 1: Device Categories
      • Step 2: Create Azure Active Directory Dynamic Device Security Groups
      • Step 3: Select Device Category
        • Windows
        • iOS
    • Intune Policies
      • Compliance Policies
      • Configuration Policies
        • Basic Configuration Policy Overview
        • Uninstall Restricted Applications
        • Configure Email Profiles
        • Modify iOS Dock
      • Software Update Policies
        • Windows
        • iOS
    • Enable Windows 10 automatic enrollment
    • Enroll Devices into Intune
      • iOS
      • Windows
        • Online Portal
        • Microsoft Store App
        • Windows Settings App
    • Deploy Client Apps to Managed Intune Devices

Description

In this article I will be configuring and deploying Intune as a stand-alone MDM solution. This article will walk you through deploying applications to devices, configuring your Company Portal, enrolling end user devices, creating policies and more.

Solution

Configure MDM Authority

  1. First we must configure Intune as my MDM authority. Since I am doing a stand alone I want Intune as the only authority and not Configuration Manager. By logging into portal.azure.com I can expand the Itune node and select “Device Enrollment”
  2. Select  “Intune MDM Authority” and then click “Choose”
  3. I will get a notification that my changes were saved successfully

Configure APN Certificate

To manage iOS devices you must have an Apple Push certificate.

  1. In the Intune blade we want to go to Device Enrollment and then Apple Enrollment and select “Apple MDM Push Certificate”
  2. Agree to the terms in step 1 and then download the CSR
  3. It will download the file, “IntuneCSR.csr”
  4. Next, click “Create your MDM push certificate.” You will need to have an Apple ID so if you do not have one you will need to create one
  5. Sign in with your Apple ID into the Apple Push Certificates Portal
  6. Now click “Create a Certificate” after you have successfully signed into the portal with your Apple ID.
  7. Navigate to your CSR file that you downloaded from the Intune portal above and then select “Upload”
  8. Once you have a green confirmation, download your certificate
  9. Go back to the Intune portal and in step 4, enter your Apple ID you used to create the certificate. In step 5 browse to the downloaded certificate and then press “Upload”
  10. Once we finish the upload, we can scroll up and see details regarding our certificate, including the expiration data

Configure MDM DNS Records

For Windows devices, there are two DNS CNAME records you need to create (pictured below):

  1. There are two CNAME records you will need to add. Once
  2. Checking my DNS for MDM again, I can see that the records are now in place and valid
  3. Back in the Intune azure portal, under Device Enrollment, go to Windows enrollment and then CNAME Validation
  4. Verify that your domain comes back successful

Configure Company Portal

The company portal is a web page and a mobile device application that supports BYOD users. It gives them a centralized location to install published applications, self management, and retrieve information.

  1. Currently the Company Portal can be configured on the legacy Intune Portal at admin.manage.microsoft.com
  2. On the iOS Company Portal application under support you can see the email and website we specified for help. This is handy for end users as they have a very simple and clear way to contact you or your IT team.
  3. At the bottom, once you save your Company Portal changes you can launch the portal website (https://portal.manage.microsoft.com/)
  4. Here I can see the basic portal
Configure Portal Terms and Conditions

The Terms and Conditions can be prompted to users prior to them accessing the Intune Company Portal. In the Azure Intune portal you can configure your policies, apply to users or groups, and review the acceptance reporting.

  1. Log into the Azure Intune Portal
  2. Navigate to the Intune blade, then Device Enrollment > Terms and Conditions and then click “Create”
  3. Create the required information regarding your Terms and Conditions and then press OK
  4. You will get a notification that your policy must be assigned to users or groups in your environment
  5. Under your Terms and Conditions overview select “Assignments”
  6. Select the Users or Groups you want to assign the Terms and Conditions to and then press Save
  7. Next time you or your users log into the Company Portal they will be greeted with the Terms and Conditions that were assigned to them.

Device Enrollment Administrator

Device Enrollment Administrators are users that are able to enroll more than the default of 5 devices to Intune. This is meant for a standard user and not an Administrator account

  1. Navigate to the Azure Portal and expand the Intune blade
  2. Expand “Device Enrollment” and select “Device Enrollment Managers”
  3. Click Add and then enter your users UserPrincipalName and then select the “Add” button on the bottom

Device Enrollment and Type Restrictions

The default amount of devices a regular users can enroll into Intune is 5 unless you have granted the user to be a Device Enrollment Administrator (above). You can also change the default amount for users in the Portal.

  1. Log into the Azure portal and select the Intune blade
  2. Select “Device Enrollment” and then click “Enrollment Restrictions”
  3. Here you can either edit your restriction policies or create a new restriction policy
  4. Here I am changing the device limit from the default of 5 to 3 and then saving my changes
  5. If I want to change the Device Type Restriction Policy I can go back to the Enrollment Restrictions pane and select the Device Type Restriction policy
  6. Here I am making a change to the Android Work Profile (seen in purple) and saving my changes

Device Group Mappings

Use Microsoft Intune device categories to automatically add devices to groups based on categories that you define. This makes it easier for you to manage those devices.

Step 1: Device Categories

In my example I am going to create two (2) device categories. One category is for BYOD devices, or personal devices. These will be devices that end users own but may use them for work. The other category will be Company Owned Devices. These devices are purchased by the company, and given to the end users through the IT department.

  1. In the Azure Portal, expand the Intune blade.
  2. Select “Device Enrollment” and then click “Device Categories”
  3. To add a new category, click Create Device Category and then supply a valid name and press “Create”
    You can create any device categories you want. For example:

    • Point-of-sale device
    • Demonstration device
    • Sales
    • Accounting
    • Manager

Step 2: Create Azure Active Directory Dynamic Device Security Groups

In this step, you will create dynamic groups in the Azure portal, based on the device category and device category name.

Use the information in this section to create a device group with an advanced rule, by using the deviceCategory attribute. For example: device.deviceCategory -eq “Personal Device“.

When users of iOS and Android devices enroll their device, they must choose a category from the list of categories you configured. After they choose a category and finish enrollment, their device is added to the Intune device group, or the Active Directory security group that corresponds with the category they chose.

Windows users should use the Company Portal website to select a category.

Regardless of platform, your users can always go to portal.manage.microsoft.com after enrolling the device. Have the user access the Company Portal website, and go to My Devices. The user can choose an enrolled device listed on the page, and then select a category.

After choosing a category, the device is automatically added to the corresponding group you created. If a device is already enrolled before you configure categories, the user sees a notification about the device on the Company Portal website. This lets the user know to select a category the next time they access the Company Portal app on iOS or Android.

  1. In the Intune blade, select Groups, and the select “All Groups” and click “New Group”
  2. Give your group the required properties like type, name and description. We will want to add a dynamic membership rule. The one below will contain all devices that a user selects as their Personal Device.
  3. Once you have your new Group with the correct properties and query, click “Create”
  4. Now back in my Azure Groups pane, I can see my newly created groups
Step 3: Select Device Category
Windows
  1. When users enroll their Windows devices they will need to assign a category in the online Intune portal
  2. Clicking on the device will show them the outstanding notification and allow them to select a category
  3. In the top right of the portal they will also see a notification
  4. Here we see the two categories I set up for the users to select. Since this machine is a Company Owned Device I will select the category. Behind the scenes, this device is added to that dynamic group and allows for a better management experience.
iOS
  1. When users enroll their devices using the Company Portal application, they will select which category the device should be placed in

Intune Policies

Compliance Policies

Compliance policies in Intune define the rules and settings that a device must comply with in order to be considered compliant by conditional access policies.

  1. Navigate to the Azure portal and select the Intune blade
  2. Select “Device Compliance” and then “Policies”
  3. Click “Create Policy” and then I am going to create a policy that I will apply to my end users personal devices. This will be a policy for the group we created earlier. Once we specify a name and platform we will have different compliance settings that we can configure become available.
  4. Once you have configured all of your Compliance settings, save the policy.
  5. Next, we will need to assign this policy to devices or users. Click the Assignments item under Manage
  6. Once I click “Select groups to include” I can select my Intune – Personal Devices dynamic group and then save.
  7. If I want to make sure the policy goes into effect immediately on a device, I can go to All Devices and find my device and force a resync.
  8. If you set a passcode setting and the users current passcode does not match, they will be greeted with a password expiration notification. From there they can set their own passcode.
Configuration Policies

Commonly used to manage security settings and features on your devices, including access to company resources.

Basic Configuration Policy Overview
  1. Expand the Intune blade and then select “Device Configuration”, “Profiles” and then click “Create Profile” to create a new device configuration profile.
  2. Enter the appropriate information regarding your profile / policy. In my example I will be making a policy that is applied to corporate owned Windows 10 devices.
  3. Configure the necessary settings for your specific policy
  4. Once you have configured all of the settings you’d like, press “Create” under the create profile blade.
  5. Next, click “Assignments” so we can assign this policy
  6. From there I will select my Intune – Company Devices group to apply this policy to.
Uninstall Restricted Applications

In this example I will be configuring a restricted application and applying it to my iOS devices.  Restricted applications are applications that users are not allowed to install and run. Users are not prevented from installing a prohibited app, but if they do so, this is reported to you.

  1. In the Intune blade select Device configuration > Profiles and then select your profile you want to edit or create a new one. In my example I will modify the profile applied to iOS devices.
  2. In the profile select Settings > Restricted Apps, and then under type of restricted apps list select Prohibited Apps. In the next section we will configuring the application we are going to restrict
  3. Open a tab in IE, Firefox, Chrome, etc and look up your application and note the itunes store URL
  4. Back in the Azure Portal, past the link and then click “Add”
  5. When you have finished your restricted apps list, click OK at the bottom and then save your profile / policy.
  6. The company portal will display a message that I must uninstall the Twitter application since it is now a disallowed application.
Configure Email Profiles
  1. Expand the Intune blade and then select “Device Configuration”, “Profiles” and then click “Create Profile” to create a new device configuration profile.
  2. Give your new profile a name and description. Select the platform that best fits your needs. under profile type select “Email”. In the email blade configure the email profile and then press OK and then Create to create the profile.
  3. Click Assignments to assign your profile to a group or all devices.
  4. In my example, I am applying it to all devices. This will apply to all iOS devices. If there are other devices, such as Android, it will just list as not applicable.
  5. Back on my iOS device it will automatically add the account. On an iOS device the account is in Settings > Password and Accounts. When I open the settings application it immediately asks me for my password
  6. When I go to Passwords and Accounts I can see that the account was automatically added
Modify iOS Dock

In this example I will be showing you how Intune can modify users home docks. I will be making a profile / policy that will ensure the default Phone application is on the dock.

  1. Expand the Intune blade and then select “Device Configuration”, “Profiles” and then click “Create Profile” to create a new device configuration profile.
  2. The platform must be iOS and the Profile type is going to be “Device Features”. In the device features blade select Home Screen Layout and select Dock.
  3. When adding a new application you will need to know the App Bundle ID. If the application is not a default iOS application you can follow these steps to obtain the bundle ID.
  4. The application will automatically be placed on the dock on iOS devices once the profile gets pushed to the device.
Software Update Policies

With Software Update Policies you can control when users can update to the newest iOS, you can restrict it so they cannot download it during business hours, or how long they must wait after it has been released until they can install it. With Windows Devices you can control devices servicing channel (Insider, Semi-Annual, etc), auto updates, maintenance windows, and more.

Windows
  1. To create a Windows Software Update policy first select the Intune blade > Software Updates > Windows 10 Update Rings, and then “Create”
  2. Give your policy a name and description. In the Settings you can begin configuring the policy settings. Below I am putting my devices on the Windows Insider update ring. They will also get Microsoft product  updates, and drivers. You can configure a deferral period which may be recommended for a production environment. In the User Experience Settings administrators can configure maintenance hours, in my environment I am auto installing the updates anywhere from 3PM to 11PM.
  3. Once you have the policy settings configured to your needs you can add scope tags and then press “Create” to create the policy.
  4. Once the policy has been created, click “Assignments” to assign the policy to devices or groups.
  5. You can apply to all devices using the “Assign to” drop down, or in my case I will apply it to one of my dynamic groups I created earlier by click the “Select groups to include” and then selecting my “Intune – Company Devices” group.
  6. In my Group settings I can see that my windows machine SB-01 is a member of that group so I can be sure that the policy will be applied to that machine.
  7. A few minutes later, that machine gets a toast notification regarding my build change
  8. In the Settings application on the device I can see that my computer is pending a reboot. After the reboot I will be on the correct build.
iOS
  1. To create a Windows Software Update policy first select the Intune blade > Software Updates > Update Policies for iOS, and then “Create”
  2. Give you policy a name and a description and then configure your settings. In my example I am disabling users from updating to the newest iOS during the work week and during work hours. iOS updates are also deferred for 2 weeks.
  3. Once you have your policy set to your liking, press the Create bottom of the blade
  4. Click “Assignment” to assign your policy to groups or devices.
  5. In my example I will apply this policy to Company Devices only.
  6. You will now see your newly created policy

Enable Windows 10 automatic enrollment

Automatic enrollment lets users enroll their Windows 10 devices in Intune. To enroll, users add their work account to their personally owned devices or join corporate-owned devices to Azure Active Directory. In the background, the device registers and joins Azure Active Directory. Once registered, the device is managed with Intune.

  1. In the Azure Portal select Azure Active Directory and then click “Mobility (MDM and MAM) and select “Microsoft Intune”
  2. Configure MDM User scope. Specify which users’ devices should be managed by Microsoft Intune. These Windows 10 devices can automatically enroll for management with Microsoft Intune.
    • None – MDM automatic enrollment disabled
    • Some – Select the Groups that can automatically enroll their Windows 10 devices
    • All – All users can automatically enroll their Windows 10 devices

     Important

    If both MAM user scope and automatic MDM enrollment (MDM user scope) are enabled for a group, only MAM is enabled. Only MAM is added for users in that group when they workplace join personal device. Devices are not automatically MDM enrolled.

Enroll Devices into Intune

iOS
  1. Have your users download and install the Company Portal from the iOS App Store
  2. Once they launch the application and sign in they can begin to Intune enrollment process
  3. The application will show the end user the permissions the IT Administrator will have on the device.
  4. They will then be shown the step by step instructions that the application will take to enroll the device
  5. An MDM iOS Profile will be installed on the device

  6. And finally, the user will select a category (set up earlier) to put their device under. This allows for a better administrator management experience
  7. The Company Portal will show the end users any available apps you have granted them, all of their Intune devices, support options we set up previously and notifications.
Windows

Windows users can install the Company Portal from the Windows store, use the web Company Portal, or use the Windows Settings app to enroll their Windows devices into Intune.

Online Portal
  1. Navigate to the online Company Portal at https://portal.manage.microsoft.com
  2. Once the user signs into the Company Portal they can add a device under Devices
  3. Click “Add”
  4. Have them sign in and then press Next
  5. The user will be prompted to enter their account password and then press “Sign In”
  6. Once complete they will be prompted with a successful message.
Microsoft Store App
  1. Have your users download and install the Company Portal application from the Microsoft Store
  2. They will be prompted to sign in
  3. They will be prompted for the password
  4. Check “Allow my organization to manage my device” and then click Yes
  5. Finally, the Company Portal will prompt them to select a device category that we set up earlier
  6. The Company Portal will now show the newly enrolled device
Windows Settings App
  1. Open the Windows Settings application and select “Accounts”
  2. Select “Access work or school” in the right hand pane, and then press “Connect”
  3. Sign in using your work account
  4. Enter your work account password and then press Sign In
  5. Once complete you will get a successful message
  6. Back in the Settings app you will now see your account

Deploy Client Apps to Managed Intune Devices

The Company Portal allows and administrator to push, install, uninstall, and make available, applications for end users. Applications can include Office 365 apps, web apps, Microsoft Store apps, iOS Apps and more. The Company Portal will only display applications that is relevant to the device they are on, if they are on an iPhone it will not display your published applications for Windows even if the device is in the same group.

  1. Expand the Intune blade in the Azure portal and the go to “Client Apps”, “Apps” and then select “Add”
  2. For my example, I will be deploying Office 365 ProPlus to my devices so I will select Windows 10 under Office 365 Suite
  3. I will configure the app settings to fit my company needs
  4. I can even configure the update channel, EULA and more
  5. I will make this application required for all users in my assignments setting
  6. After a little bit I can see that Office is installing on my end user machine in Task Manager
  7. If I had not made the app required and just made it available, end users could choose to install it from the Company Portal
  8. Once the install is complete I can check the start menu to see all of my newly installed applications
  9. In the Intune portal under my applications, I can see that I have Office 365 ProPlus successfully installed on 1 device, and not applicable on 1 device (iOS)
Brad Wyatt
Brad Wyatt

My name is Bradley Wyatt; I am a 5x Microsoft Most Valuable Professional (MVP) in Microsoft Azure and Microsoft 365. I have given talks at many different conferences, user groups, and companies throughout the United States, ranging from PowerShell to DevOps Security best practices, and I am the 2022 North American Outstanding Contribution to the Microsoft Community winner.


Intune
Intune, MAM, MDM, Office 365

Post navigation

PREVIOUS
Customize your Office 365 Encrypted Messages with your Organizations Brand in Office 365
NEXT
Sync Office 365 / AzureAD down to ADDS

21 thoughts on “Configure and Deploy Intune MDM”

  1. Jay says:
    November 20, 2018 at 11:30 am

    Great stuff man. Really solid, thorough work.

    Reply
  2. Imran says:
    November 21, 2018 at 3:01 am

    Great blog. Thank you.

    Reply
  3. Robin Makkus says:
    November 22, 2018 at 5:31 am

    Defenitly bookmarking this one! Good guide, very clear.

    Reply
  4. Deniz Adams says:
    March 27, 2019 at 5:53 pm

    Great resource.

    Reply
  5. Jose Ramo says:
    April 1, 2019 at 6:31 am

    Very professional and details resource……!

    Reply
  6. Mickey says:
    April 24, 2019 at 7:51 am

    Very great walkthrough! Nice work.
    If I got 100 Azure AD registered devices (windows 10), cant they be enrolled to MDM automatically?
    Enrolling devices as you do in the guide, will only Azure AD register the devices, right – and not Azure AD Join.

    Reply
  7. Jeremy Hagan says:
    May 8, 2019 at 9:54 pm

    The legacy Intune portal is now defunct. Any chance of updating this article?

    Reply
    1. Brad Wyatt says:
      May 14, 2019 at 8:10 am

      Yep! will try to update it soon, hard to keep up with MSFT 🙂

      Reply
  8. Gene Averett says:
    June 3, 2019 at 4:33 pm

    How do you get a new laptop to join without making the user an admin? windows 10 always sets the first account as admin.

    Reply
    1. Brad Wyatt says:
      June 26, 2019 at 9:48 am

      have you looked into autopilot?

      Reply
      1. Al says:
        July 18, 2019 at 10:29 pm

        Would you have a guide on Autopilot?

        Reply
  9. Chaz says:
    June 18, 2019 at 3:39 pm

    Nice Job. Much simpler than Microsoft docs to just get the basics down.

    Reply
  10. Keith says:
    July 19, 2019 at 10:23 am

    This is some great information but one concern I have is with the following scenario:

    We have users who are office employees only. They should only be accessing e-mail from within the corporate offices. Otherwise, access to E-mail, SharePoint Online and other services where company data is stored should be blocked. I cannot allow these users to enroll a personal device and start accessing e-mail.

    The other set of users are the execs, IT and remote sales people. Some of these users brought their own phones into the company, the others had phones issued by IT. I believe I’ve configured this correctly but I need them to be able to enroll two devices: their phone and their laptop. Additional devices would require approval and we would need to have a policy/device restriction limit for those who might have 3 devices.

    Lastly, I need to ensure that mail and SPO are accessed through Outlook for iOS and the SharePoint apps. I don’t want the users to download or have the ability to download Outlook for iOS on their own and configure it. I want the application to be provisioned so that if the device is marked as non-compliant, access to mail, SPO, onedrive, etc is blocked.

    I know the first two should be possible but I’m not sure how to achieve the last part. I believe I need at least 3 conditional access policies to accommodate for everything that I want to do but there could be more.

    Thanks for the super helpful post though! This helped me get going late last year.

    Reply
  11. Andraes Baum says:
    November 27, 2019 at 5:56 am

    very nice! thank you!

    Reply
  12. Kim says:
    January 4, 2020 at 5:31 pm

    Great post!! Thank you!!

    Reply
  13. Josh Moulin says:
    April 26, 2020 at 12:22 am

    Very helpful information. I know this took a lot of work and I really appreciate you taking the time!

    Reply
  14. Pingback: How To Set Up Intune Company - Install Intune Company Portal On Devices - Microsoft Managed ...
  15. Max says:
    July 29, 2021 at 10:20 am

    any chance we can get an updated guide since intune is gone now.

    Reply
  16. Pingback: Gpo Company Portal - LoginWave
  17. Swastikau698 says:
    December 23, 2021 at 2:20 am

    Very helpful information. and I really appreciate you taking the time!

    Reply
  18. Timo says:
    March 9, 2023 at 1:30 am

    your guide really helped me to get the basics of my intune setup down – thank you so much! Much easier to read & understand than msft docs.

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe

Email


Categories

  • Active Directory (8)
  • AI (3)
  • API (1)
  • AutoPilot (2)
  • Azure (15)
  • Bicep (4)
  • Connectwise (1)
  • Defender for Cloud Apps (1)
  • Delegated Admin (1)
  • DevOps (6)
  • Graph (6)
  • Intune (16)
  • LabTech (1)
  • Microsoft Teams (6)
  • Office 365 (19)
  • Permissions (2)
  • PowerShell (51)
  • Security (1)
  • SharePoint (3)
  • Skype for Business (1)
  • Terraform (1)
  • Uncategorized (2)
  • Yammer (1)

Recent Comments

  • Darren Heath on Get a New Computer’s Auto Pilot Hash Without Going Through the Out of Box Experience (OOBE)
  • Ryan on Auto Deploy Progressive Web Applications (PWA) using Intune or PowerShell
  • 91 Club Lottery on Get a New Computer’s Auto Pilot Hash Without Going Through the Out of Box Experience (OOBE)
  • Naomi on Master User Creator [PowerShell GUI Software] v2 Update
  • tt789 app on Get a New Computer’s Auto Pilot Hash Without Going Through the Out of Box Experience (OOBE)

1,809,680 People Reached

© 2025   All Rights Reserved.