Event banner
Unpacking endpoint management: Windows Autopilot for co-managed devices
Event Ended
Friday, Jun 10, 2022, 08:00 AM PDTEvent details
We recently released a long-awaited capability called Co-management Settings. This allows your devices to be "cloud born" with Windows Autopilot and immediately enrolled into co-management. Join in on this conversation with the feature PM, devs, and real-world IT pros to discuss the new capability, how best to use it, and what's next.
Special guests today include PMs Daniel Weisberg and Bruno Venturi plus Microsoft MVPs Johannes Kristjansson and Adam Gross.
We'll also be answering your questions so post them below in the Comments.
Bookmark https://aka.ms/UnpackingEndpointManagement for links to previous episodes on demand and details on upcoming episodes. |
Heather_Poulsen
Updated Dec 27, 2024
- Nick WileyBrass ContributorAdding on to Adam's previous question about the set all workloads to Intune tick box, if you tick the box to have all in Intune, is there a method to move workloads back to CM if you workload sliders are not currently all moved over?
- MattyPtheOGCopper ContributorIt would be nice to put the sliders from Pilot to Intune, but if you have just one instance of needing something to not get enrolled/managed by Intune, then you need it. For example--VDI/gold images, Deep Freeze machines. Am I missing something?
- Agreed! I've been bugging Danny about this for a while. We need a way to exclude specific devices somehow without leaving the sliders in pilot.
- Nick WileyBrass ContributorThis is 100% why we have workloads in Pilot. Hence my other question. I want to use a full Intune experience for the ESP, but because of the collections are set to pilot, if we used this, the workload would be set to CM for apps and then the Intune ESP I would think, would not install.
- ajf8729Copper ContributorThe biggest issue in regards to Adam's comments about the sliders is people using pilot collections for unintended purposes. Piloting is for testing on existing devices. It shouldn't be used for controlling new devices. Need to get those sliders moved to full Intune!!!
- KensCloudCopper ContributorIf we used an internal certificate for CMG it looks like we would need to move to a public cert for CMG to make this work reliably?
- Great question! I recently went through this. The main issue that we found was that our PKI CRL wasn't accessible externally (from the internet). So if you're doing Autopilot off the business network, clients can't find the CRL so they will fail to install. So the workaround for us was to use a public certificate.
- tmillsCopper ContributorSo we currently deliver the memcm client via PSADT and it works well. I like the idea of this new profile, but I didn't get a good answer on how to monitor it -- not so much 'it shows up in sccm' - but if something goes wrong. Perhaps a cert is not there, or something else. Really, looking for an answer on this. TIA!
- If the client fails to install, it will cause Autopilot to fail during the "Preparing your device for mobile management" step. You would be able to look at the regular ccmsetup client logs or at Autopilot monitoring within the Intune console to see failed deployments. Additionally you would be able to use the Autopilot diagnostics directly on the device you're provisioning.
- Josh HippleIron ContributorDoes this support Preprovisioning process (formerly white-glove)?
- Venkata_Pampana
Microsoft
Not at the moment.
- KensCloudCopper ContributorOnce configured will this reinstall over existing clients?
- Joe_Lurie
Microsoft
This occurs during Autopilot, so assuming no managed OS on the device. Can you clarify your question?- KensCloudCopper ContributorIf the ConfigMan client was installed on devices previous to this setting existing and they get targeted outside of Autopilot.
- Venkata_Pampana
Microsoft
Yes, it can be targeted to already enrolled devices.
- Nick WileyBrass ContributorNice! Where in the Autopilot process does this co-management step actually run?
- In the "Preparing your device for mobile management" step - first section of the ESP.
- Joe_Lurie
Microsoft
In the Preparing your device for mobile management part of ESP (enrollment status page)- Nick WileyBrass ContributorSo if the device is not picked up as part of a pilot group or full workload moved for Apps to Intune, it will not install any apps that would be required during ESP then?
- NigelIron Contributor
With PROVISIONTS supported, can we know directly launch desired task sequences with this process? We literally have an environment using the scheduled task method and want to optimize it!
- Yes you can
- tmillsCopper ContributorBest way to monitor and confirm on the endpoint it got this profile ?