Intro:
This is the first article about getting started with Windows modern management. Kind of a “A to (Z)” guide. I will never get to Z, as things is changing all the time. But at least this will get you started.
Pre-Req: You need to have a Microsoft Entra ID P2 with a global administrator account.
This is part 1 of the “Modern Management” series.
Accounts
It is not recommended to use your global admin account on a daily basis. For that we need to create another account.
Sign in to the Home – Microsoft Azure | |
Search for “intr” and click “Microsoft Entra ID“ | |
Click Users | |
Click New user -> Create new user | |
Fill in User principal name + Display name + Password (If you don’t want to have a auto-generated) Click Review + Create | |
Review the user account details. Click Create | |
To assign “Usage location” to the new user click On the username | |
Click Properties | |
Click Settings | |
Select the Usage location -> Click Save | |
Click Licenses | |
Click Assignments | |
Select the licens -> Click Save | |
You can see that the license has been assigned in the overview |
Privileged Identity
Sign in to the Home – Microsoft Azure | |
Find and open “Privileged Identity Management” | |
Click Microsoft Entra roles | |
Click Assign Eligibility | |
Click Add assignments | |
Under Membership -> select a role -> Select member of the role. Click Next | |
Under setting -> modify the setting as you desire. Click Assign | |
Click Roles -> Search for the Intune Administrator role -> click on it. | |
Click Role settings -> Click Edit | |
Modify the setting as you desire. Click Next: Assignment | |
Modify the setting as you desire. Click Next: Notification | |
Modify the setting as you desire. Click Update |
To enable PIM on your account:
Login to Azure -> Search for pri -> Click Microsoft Entra Privilege Identity Management | |
Click My roles | |
Click Activate on the role that you want. | |
Select the Duration (Hours) -> Type a reason -> Click Activate | |
To verify -> Click Active assignments You can see that I have activated the Intune Administrator |
Azure settings
Sign in to the Home – Microsoft Azure | |
Search for “intr” and click “Microsoft Entra ID” | |
Click Mobility (MDM and MAM) -> Microsoft Intune | |
Select All in the MDM user scope Select All in the MAM user scope | |
Click X | |
Click Company branding | |
Click Default sign-in -> Click Customize | |
Modify the setting that you desire. Click Review + Create | |
Click Create |
Azure is now setup. Continue to part 2 to configure Intune.