Intro:
This is the first article about getting started with Windows modern management. Kind of a “A to (Z)” guide. I will never get to Z, as things is changing all the time. But at least this will get you started.
Pre-Req: You need to have a Microsoft Entra ID P2 with a global administrator account.
This is part 1 of the “Modern Management” series.
Accounts
It is not recommended to use your global admin account on a daily basis. For that we need to create another account.
Sign in to the Home – Microsoft Azure | ![]() |
Search for “intr” and click “Microsoft Entra ID“ | ![]() |
Click Users | ![]() |
Click New user -> Create new user | ![]() |
Fill in User principal name + Display name + Password (If you don’t want to have a auto-generated) Click Review + Create | ![]() |
Review the user account details. Click Create | ![]() |
To assign “Usage location” to the new user click On the username | ![]() |
Click Properties | ![]() |
Click Settings | ![]() |
Select the Usage location -> Click Save | ![]() |
Click Licenses | ![]() |
Click Assignments | ![]() |
Select the licens -> Click Save | ![]() |
You can see that the license has been assigned in the overview | ![]() |
Privileged Identity
Sign in to the Home – Microsoft Azure | ![]() |
Find and open “Privileged Identity Management” | ![]() |
Click Microsoft Entra roles | ![]() |
Click Assign Eligibility | ![]() |
Click Add assignments | ![]() |
Under Membership -> select a role -> Select member of the role. Click Next | ![]() |
Under setting -> modify the setting as you desire. Click Assign | ![]() |
Click Roles -> Search for the Intune Administrator role -> click on it. | ![]() |
Click Role settings -> Click Edit | ![]() |
Modify the setting as you desire. Click Next: Assignment | ![]() |
Modify the setting as you desire. Click Next: Notification | ![]() |
Modify the setting as you desire. Click Update | ![]() |
To enable PIM on your account:
Login to Azure -> Search for pri -> Click Microsoft Entra Privilege Identity Management | ![]() |
Click My roles | ![]() |
Click Activate on the role that you want. | ![]() |
Select the Duration (Hours) -> Type a reason -> Click Activate | ![]() |
To verify -> Click Active assignments You can see that I have activated the Intune Administrator | ![]() |
Azure settings
Sign in to the Home – Microsoft Azure | ![]() |
Search for “intr” and click “Microsoft Entra ID” | ![]() |
Click Mobility (MDM and MAM) -> Microsoft Intune | ![]() |
Select All in the MDM user scope Select All in the MAM user scope | ![]() |
Click X | ![]() |
Click Company branding | ![]() |
Click Default sign-in -> Click Customize | ![]() |
Modify the setting that you desire. Click Review + Create | ![]() |
Click Create | ![]() |
Azure is now setup. Continue to part 2 to configure Intune.

