Intune Comanagement
Intune Comanagement
Intune Comanagement
(Note: When you manage devices with Configuration Manager and enroll to a third-party MDM
service and not Intune, this configuration is called Coexistence)
Begin:
Prerequisites:
- Licensing: Azure AD Premium, At least one Intune license for you as the administrator to access
the Microsoft Endpoint Manager admin center.
- SCCM: Co-management requires Configuration Manager version 1710 or later.
Steps:
- The phrase Pilot group is used throughout the co-management feature and configuration
dialogs. Use a pilot group in SCCM for your initial testing, adding devices as needed, until you're
ready to move the workloads for all Configuration Manager devices.
- When setting up Azure AD Connect you will be given to choice (step 5 of instructions) between
several authentication methods between your Active Directory and Azure Active Directory. Below
is a table of common hybrid identity and access management scenarios with recommendations
as to which hybrid identity option (or options) may be appropriate for your organization:
- After downloading the Azure AD Connect tool, open the file and agree to the license terms and
privacy notice by checking the checkbox. Click ‘Continue’.
- From the 'Express Settings' tab, select the Customize button.
- From the 'Install Required Components' tab, check the 'Use an existing service account' and set the
required information. You will need to type your domain administration credentials. Click ‘Install’
- From the 'User Sign-In' tab you will need to set your desired selection of the Single Sign-On
method. Each selection might add more steps and requirements. We recommend using
Password Synchronization or Do not configure options.
- From the 'Connect to Azure AD' tab, you will need to type you Active Directory credentials, this may
also be known as Office 365 administrator credentials.
- From the 'Connect Directories' tab, you will need to enter your current deployment directory
information.
- On the 'Azure AD sign-in configuration' tab, our recommendation is to set the on-premise
attribute (in this case your on-premise will be your deployment) to be used in the Azure AD to
userPrincipalName. If your domain is still not verified, you can check the ‘Continue’ without any
verified domains checkbox to continue
- On the Domain and OU filtering, leave everything as default to sync the entire directory data. You can
also filter this data by only selecting the desire domain and OUs.
- From the 'Uniquely identifying your users' tab, our recommendation is to leave the default settings for
basic setups, of one forest, one domain, one azure AD. For more complicated setups you may want
other options where you will need to match your users using a particular attribute across all directories.
On the user identification option in the Azure AD we recommend leaving the default option of using the
'ObjectGUID', the system will use this to generate an ID and use it for mapping users in the system
- From the 'Filter users and devices' tab, you can sync all users and devices or you can specify a
group.
- On the 'Optional features' tab, select any additional feature that you would like to activate. Each
feature has an icon for more information on each feature.
- From the 'Ready to configure' tab, you select the 'Start the synchronization process when configuration
completes' if you want to start automatically.
- On the Configure view, wait until the configuration is completed and click on Exit when it’s done
- Sign in to the Azure portal and select Azure Active Directory > Mobility (MDM and MAM) > Microsoft
Intune.
- Configure MDM user scope. Specify one of the following to configure which users' devices are managed by
Microsoft Intune and accept the defaults for the URL values.
o Some: Select the Groups that can automatically enroll their Windows 10 or later devices
o All: All users can automatically enroll their Windows 10 or later devices
o None: Disable MDM automatic enrollment
- Save and Exit
2. Existing Intune configured/enrolled devices
Note:
- This CMG/CDP prerequisite is applicable only when you want to install ConfigMgr/SCCM client
on to Intune Windows 10 devices from the internet when the client doesn’t have the SCCM on-
prem infra reachability. They both are Platform as a Service (PaaS) solutions in Azure.
- CMG: Cloud Management Gateway: provides a simple way to manage Configuration Manager
clients over the internet. You deploy CMG as a cloud service in Microsoft Azure.
Then without more on-premises infrastructure, you can manage clients that roam on the
internet or are in branch offices across the WAN.
You also don't need to expose your on-premises infrastructure to the internet.
A client from internet contacts SCCM to get policies.
The request will reach CMG. And the CMG will forward this request from a client to on-prem
SCCM components.
The on prem SCCM component will validate the request and provide policies via CMG.
- CDP: Cloud Distribution Point: Provide software content to internet-based clients without
additional on-premises infrastructure
Cloud-enable your content distribution system
Reduce the need for traditional distribution points
Pre-requisites:
- Licenses: Azure Subscription, Azure Active Directory Premium, Microsoft Intune subscription
Steps:
SCCM: Enable Co-management: This procedure is exactly same as mentioned in the first path
SCCM: Configure CMG: I have not covered this topic here as it is too complex. However, after going
through many blogs, I find this one as comprehensive material to follow
https://www.prajwaldesai.com/setup-sccm-cloud-management-gateway/#Allow-access-to-cloud-
distribution-points
- Sign in to the Azure portal and select Azure Active Directory > Mobility (MDM and MAM) > Microsoft
Intune.
- Configure MDM user scope. Specify one of the following to configure which users' devices are managed by
Microsoft Intune and accept the defaults for the URL values.
o Some: Select the Groups that can automatically enroll their Windows 10 or later devices
o All: All users can automatically enroll their Windows 10 or later devices
o None: Disable MDM automatic enrollment
- Save and Exit
Intune: Deploy SCCM Client
- If you're planning to deploy the Configuration Manager client to devices going through Autopilot, it's
recommended to target users for the assignment of the Configuration Manager client instead of devices.
This action will avoid a conflict between installing line-of-business apps and Win32 apps during Autopilot
- Assign this App to the devices: MEM > Apps > All Apps
- Select Configuration Manager Client > Properties > Edit > Assignments > Add Group
- Choose the Group that we created
- Review + save and then Save the configuration
Note: There are various methods to check the status of Co-management which would be part of troubleshooting.