Event banner
AMA: Improve your security posture with Intune
Event Ended
Tuesday, Oct 01, 2024, 10:30 AM PDTEvent details
Has your organization applied Zero Trust principles to Intune? Curious about ensuring you have a solid security baseline configuration deployed across all your devices? Need to understand the best practices for device security and conditional access? Security is critical for all organizations to understand and deploy for all platforms. Join the Intune product team and engineers responsible for device security in this security-focused Ask Microsoft Anything session!
Post your questions in the Comments below. We'll have experts responding in the live stream and others in chat.
This session is part of Microsoft Intune: Tech Community Live. Add it to your calendar, RSVP for event reminders, and post your questions and comments below! This session will also be recorded and available on demand shortly after conclusion of the live event. |
Heather_Poulsen
Updated Dec 27, 2024
- Heather_Poulsen
Community Manager
That concludes today’s Improve your security posture with Intune AMA and today’s edition of Tech Community Live! Thanks to everyone who was able to join us live - and to those catching up on demand! We’ll leave Q&A open until 12:00 p.m. PT on Friday, October 4th.
- MaenXeBrass ContributorI would love to see some AI functionality added to the scripts sections to suggest ways to accomplish goals. Especially around making Compliance or Remediation scripts cross-platform compatible. I can write a script in PowerShell, and then utilize AI to write a similar script in BASH or Python so that the script can be executed on Linux or MacOS. Are there any plans for this in the future? With functionality like this, you can re-tool the scripts pages to have a script for accomplishing a given task, and choose to apply it to multiple Operating Systems, rather than managing them separately for every task AND every OS.
- ntnchoudhary666Copper ContributorWe have windows 11 autopilot device where device guard policy is enabled in security baseline. But we also have to create a relaxed policy which doesn't enable device guard and also wants to disable core isolation code Integrity settings or any way to allow user to control it...how we can configure it?
- RichP1930Brass ContributorAsking again please help! When looking in Itune Device Configuration Profile setting, you can see a conflict, When you select that conflict and click on it it gives you a setting / state and source but only shows the current policy not what other policy it's conflicting with. How can we find that conflict easily i.e EnableSmartScreenInShell [./Device/Vendor/MSFT/Policy/Config/SmartScreen/EnableSmartScreenInShell] STATE Conflict in profiles SOURCE PROFILES Source Profile Modern Workplace Security Baseline v16
- RichP1930Brass ContributorWhere is the troubleshooting blade?
- SalonaS605Copper ContributorADE enrolled iPhones (dynamic device group) wish to be excluded from the User grouped MAM Policy. what is the best way to achieve this ? Will Exclusion of User group help me achieve it or any other suggestion ?
- SalonaS605Copper ContributorMAM Android Block Print: In addition to block Printing, Is there a way we could also block the users from printing it into a PDF? (for now the users can share the PDF over Whatsapp or other unmanaged app)
- davidrcushmanCopper ContributorThis sounds like an issue that could be handled with application protection policies. Have you given this a try?
- SalonaS605Copper ContributorYes, it is a result of the App protection policy that has no control over this feature. I am looking for answers/options.
- SalonaS605Copper ContributorMAM iOS Outlook Contact Sync: My scenario : When I exceute a User-Based Wipe for iOS BYOD , particularly testing Outlook here: The Outlook corporate data(Email) gets removed and user is logged out but the Outlook Contacts that were synced (due to the App Config Policy to Save Contacts) are left behind in the iOS Contact Address book. Ask: I want those Outlook contacts also to get removed so that when user leaves organization, he does not have access to ex-company contacts . So, How to remove the Synced Outlook contacts from Native Contact app in iOS after a Wipe is done? otherwise, without this Config Policy, is there any way that users can see the Phone number to know who is calling? Settings: App Protection Policy: Sync policy managed app data with native apps or add-ins: Allow Managed Apps App Configuration Policy, Outlook Save Contacts: Yes Allow user to change setting: Yes On iOs Phone, Outlook App Settings, Save Contacts with Corp Account is :Enabled
- cplaughlinOccasional ReaderWith two Local user group membership policies even if they are both Add (Update) currently if both are targeted to the same group will result in a conflict since this is same csp but different values. Is there a way Intune can see this and merge the polices before the csp is applied on the device. Hope this makes sense.
- RichP1930Brass ContributorWhen looking in Itune Device Configuration Profile setting, you can see a conflict, When you select that conflict and click on it it gives you a setting / state and source but only shows the current policy not what other policy it's conflicting with. How can we find that conflict easily i.e EnableSmartScreenInShell [./Device/Vendor/MSFT/Policy/Config/SmartScreen/EnableSmartScreenInShell] STATE Conflict in profiles SOURCE PROFILES Source Profile Modern Workplace Security Baseline v16
- MaenXeBrass ContributorAre there any plans to merge Custom Compliance Scripts and Remediation Scripts? I prefer the functionality for affecting change of Remediation Scripts, but it'd be nice to leverage that system for defining and reporting compliance.
- MP_35Brass ContributorI second this, similar to how a CM baseline can be marked to be used as part of a compliance policy. Or maybe just the ability to define custom compliance policies, if it needs to be separate from config items like CSP's then it could limit it to just the discovery/evaluation script.
- davidrcushmanCopper ContributorIt's been some time since I've looked, but I recall "remediation scripts" being an add-on feature with additional cost. If that is correct, I'd expect to see that these features will likely remain separate.
- MaenXeBrass ContributorIt's available, and extremely useful, for us, and we are at the E3 level.