
I am happy to announce that Windows 11 24H2 finally supports that you can now directly disable UseRasCredentials in the Microsoft Intune Always On VPN Custom OMA-URI Settings profile.
Continue reading

I am happy to announce that Windows 11 24H2 finally supports that you can now directly disable UseRasCredentials in the Microsoft Intune Always On VPN Custom OMA-URI Settings profile.
Continue reading
Recently, Windows LAPS for Windows Server Active Directory was made available to the public, and I shared my initial test impressions:
Getting to Know Windows LAPS for Active Directory – First Look
As of April 21st, 2023, Windows LAPS for Azure Active Directory is now also accessible in a public preview. This presents an opportunity to test it in a cloud-only environment, and in this blog post, I will be sharing my initial testing impressions of Windows LAPS with Azure Active Directory in this scenario.
Continue reading
Endpoint Privilege Management (EPM) is one of the most anticipated features of the Microsoft Intune premium add-on suite and was already announced at Microsoft Ignite 2022. With EPM, Microsoft has finally developed a solution for assigning temporary administrator rights. Users no longer need to be made local administrators. Instead, your users can be given standard account permissions and be designated administrators for specific tasks. Microsoft has now released a first public preview. This blog article covers first test impressions about the new Microsoft Intune Endpoint Privilege Management feature.

While AppLocker has been around since Windows 7 and Windows Server 2008 R2, I have rarely found the solution in enterprises. The main reason was always that the implementation is very time and resource consuming and that you must constantly maintain a whitelist. This is a bummer, because the security gain is enormous when a solution like AppLocker is used. If you deal with the AppLocker rules intensively and have developed a good concept at the beginning, you will realize that you do not have to adjust the rule regularly and that the operation is not as complex as you thought.
This blog article shows the important things to consider when implementing AppLocker, how to create a usable basic ruleset that requires minimal maintenance, and how to manage with Microsoft Intune.

This blog article covers the new Windows 11 22H2 security feature Enhanced Phishing Protection in Microsoft Defender SmartScreen and gives first impressions.

The Local Administrator Password Solution (LAPS) from Microsoft has been around since 2015 and I have always liked using it because it was quite easy to implement and manage. Unfortunately, Azure AD (Cloud Only) support was missing and LAPS could only be used with an on-premises Active Directory. Therefore, in a cloud only environment, you had to use alternatives such as the community solution CloudLAPS. Fortunately, Microsoft is working on a new LAPS solution with the name Windows LAPS that finally offers the long-awaited support for cloud-only devices.
This blog article presents the 10 most essential details about the new Windows LAPS solution.

Back in 2021, Microsoft announced that Microsoft Intune would get driver management and integration for the new Microsoft Store. For a long time, however, there was no significant news until new developments and first release dates were announced on October 25, 2022 at The Microsoft Technical Takeoff: Windows and Microsoft Intune online event, which is currently taking place from October 24 to 28.
Continue reading
This blog article shows how to master the security recommendations of Microsoft Defender for Endpoint (MDE) with Microsoft Intune and achieve a device secure score above 95%.

This blog article covers how to deploy Windows Features like Windows Sandbox or Hyper-V with Microsoft Intune.

This blog article covers the implementation options of the different Microsoft Intune security baselines and gives an overview of policies that can impact your users.