Reader small image

You're reading from  Mastering Microsoft Intune - Second Edition

Product typeBook
Published inMar 2024
PublisherPackt
ISBN-139781835468517
Edition2nd Edition
Right arrow
Authors (2):
Christiaan Brinkhoff
Christiaan Brinkhoff
author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

Per Larsen
Per Larsen
author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen

View More author details
Right arrow

Intune Suite

In this chapter, you’ll learn everything you need to know about all the new modules that are part of Microsoft Intune Suite. One of the main questions we will answer is how you can leverage those new features on top of Microsoft Intune to build a more secure and robust Windows platform in your enterprise.

In this chapter, we will cover the following topics:

  • What is Intune Suite?
  • How to get started – requesting a trial
  • Specialty device management
  • Endpoint Privilege Management:
  • Enterprise Application Management:
  • How to install applications
  • How to update/do versioning of applications
  • Cloud certificate management (Cloud PKI)
  • Advanced Endpoint Analytics
  • Why Windows 365 and Intune Suite are a great combination

What is Intune Suite?

Microsoft Intune is continually evolving and enhancing, providing IT administrators with more tools to implement the least privilege principle on their managed endpoints. The introduction of the Microsoft Intune Suite has ushered in advanced features that were once only accessible through third-party solutions.

Intune Suite answers many challenges that you, as an IT administrator or manager/CIO, might have, particularly the challenges around remote working and different types of management solutions and devices. The complexity of enterprises is higher than ever before.

The major benefits of Intune Suite are simplification, the ability to reduce IT support costs, and the sunset third-party software that is used as add-ons, to leverage cost-effective Microsoft 365 plans, and decrease surface attacks.

Figure 11.1: Intune Suite benefits

Ok, so what does Intune Suite cover? Let us explain the different components first, and then we will go deeper...

How to get started with Intune Suite

If you want to kick the tires and try things out in your own tenant, you can use the free trial, which gives you a 90-day period to use the Intune add-on capability without any charge. Trials can be applied to up to 250 users per tenant. At the end of the trial period, there’s a 30-day grace period. After this point, you’ll be unable to use the Intune add-on capability in Microsoft Intune for users within your tenant unless you’ve purchased the appropriate licenses. There’s a one-time limit to start a trial for each tenant.

If you want to test out EPM, as one example, we recommend that you enable a separate EPM trial license, as a trial license can only be activated once per tenant. This means if, at a later point in time, you want to try another product, you can still enable the Intune Suite trial in your tenant as it has not been activated before.

Purchasing licenses lets you use the Intune add-on capability...

Specialty Device Management

Specialty devices can be AR/VR devices, HoloLens, RealWear, HTC, Team Rooms systems, and other types of devices running both Windows and Android.

For Microsoft Teams Rooms devices, including Surface Hub, you are properly licensed with a Teams license that includes Intune management.

For Microsoft HoloLens, subscribers of Microsoft Intune (Plan 1) aren’t required to proactively add the Intune Plan 2 license to their tenant. You can keep managing it, as done previously, as an interim solution until Microsoft has found a solution to integrate it as part of the Microsoft subscriptions.

As for any other licenses, always have a conversation with your licensing partner so that you can ensure that you are license-compliant.

Endpoint Privileged Management

Endpoint Privilege Management (EPM) supports your zero-trust journey by enabling your organization to establish a broad user base operating with minimal privileges, while still permitting users to execute tasks authorized by your organization, thus maintaining productivity. The key features of EPM are:

  • Automatic, user-confirmed, or support-approved elevation
  • Insights based on elevation audits
  • Effective control of child processes
  • Rules based on organizational requirements
  • Easy addition or removal of rules
  • Tenant-level enablement per device rollout

How to configure EPM

EPM is a feature that allows users to run as a standard user (without administrator rights) and complete tasks that require elevated privileges.

To configure EPM, you need to have the following prerequisites:

  • Microsoft Intune Plan 1 license
  • Microsoft Entra joined or Microsoft Entra hybrid joined
  • Microsoft Intune...

Cloud certificate management (Cloud PKI)

Cloud PKI offers several advantages over traditional on-premises PKI. Cloud PKI provides the following benefits:

  • Lower total cost of ownership (TCO): Cloud PKI eliminates the need for expensive hardware and software, reducing the overall cost of ownership. Reduces on-premises CA workload and operations (patching and maintaining servers, etc.).
  • Increased security: Cloud PKI providers have the expertise and resources to ensure the security of the infrastructure, which is often more secure than on-premises solutions.
  • Easier certificate management: Cloud PKI solutions offer a centralized platform for certificate management, making it easier to manage certificates across multiple domains.
  • Less complex: With a cloud-based infrastructure, you do not need to implement and secure a Simple Certificate Enrolment Protocol (SCEP) server as is it built into the solution. No need for a reverse proxy (Entra application proxy or...

Summary

This concludes the last of the chapters relating to Intune Suite. We’ve explained what Intune Suite is, how you can request a trial, and how to configure it as an IT admin and use it as an end user. Intune Suite will soon become one of the mainstream services used by enterprises. With this chapter, we wanted you to feel confident talking about both the business benefits as well as technical details – and we hope we succeeded!

In the next chapter, you will learn about the different tools that are available for profile management.

Questions

  1. What license do you need for Enterprise App Management?
    1. Intune Core
    2. Intune Suite
    3. Windows E3 or E5
  2. Does EPM support IT admin approval for the elevation of installation rights?
    1. Yes
    2. No
  3. Windows 365 Cloud PCs and EPM take zero-trust and security to the next level!
    1. True
    2. False

Answers

  1. (b)
  2. (a)
  3. (a)

Further reading

If you want to learn more after reading this chapter, please use the following free online resource:

Learn more on Discord

To join the Discord community for this book – where you can share feedback, ask questions to the author, and learn about new releases – follow the QR code below:

https://packt.link/SecNet

lock icon
The rest of the chapter is locked
You have been reading a chapter from
Mastering Microsoft Intune - Second Edition
Published in: Mar 2024Publisher: PacktISBN-13: 9781835468517
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
undefined
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime

Authors (2)

author image
Christiaan Brinkhoff

Christiaan Brinkhoff works as a Principal Program Manager and Community Director for Windows 365 and AVD at Microsoft, in his role at Microsoft, he works on features such as Windows 11, Windows 365 app, Switch and Boot. Christiaan is also an Author (3 books) and Inventor (3 patents). His mission is to drive innovation while bringing Windows 365, Windows, and Microsoft Intune closer together, drive community efforts around virtualization to empower Microsoft customers in leveraging new cloud virtualization scenarios. Christiaan joined Microsoft in 2018 as part of the FSLogix acquisition. He has also been rewarded with the Microsoft MVP, Citrix CTP, and VMware vExpert community achievements - for his continued support in the EUC community.
Read more about Christiaan Brinkhoff

author image
Per Larsen

Per Larsen works as a Senior Program Manager for Microsoft Endpoint Manager - Customer Acceleration Team - Commercial Management Experiences (CMX) Engineering, where he takes learnings from Microsoft's largest and most strategic customers back into the rest of engineering to drive improvements for the service so that customers have a continuously improving product experience. He also helps deploy and adopt Microsoft Endpoint Manager - Microsoft Intune. Per mainly focuses on the management of Windows and special devices such as HoloLens 2, Surface Hub, and Microsoft Teams Room System. Per was also an MVP in Enterprise Mobility, from 1st July 2016 to when he joined Microsoft on 1st April 2018.
Read more about Per Larsen