Intro:

This is the first article about getting started with Windows modern management. Kind of a “A to (Z)” guide. I will never get to Z, as things is changing all the time. But at least this will get you started.

Pre-Req: You need to have a Microsoft Entra ID P2 with a global administrator account.

This is part 1 of the “Modern Management” series.


Accounts

It is not recommended to use your global admin account on a daily basis. For that we need to create another account.

Sign in to the Home – Microsoft Azure
Search for “intr” and click “Microsoft Entra ID
Click Users
Click New user -> Create new user
Fill in User principal name + Display name + Password (If you don’t want to have a auto-generated)

Click Review + Create
Review the user account details.

Click Create
To assign “Usage location” to the new user click On the username
Click Properties
Click Settings
Select the Usage location -> Click Save
Click Licenses
Click Assignments
Select the licens -> Click Save
You can see that the license has been assigned in the overview

Privileged Identity

Sign in to the Home – Microsoft Azure
Find and open “Privileged Identity Management
Click Microsoft Entra roles
Click Assign Eligibility
Click Add assignments
Under Membership -> select a role -> Select member of the role.

Click Next
Under setting -> modify the setting as you desire.

Click Assign
Click Roles -> Search for the Intune Administrator role -> click on it.
Click Role settings -> Click Edit
Modify the setting as you desire.

Click Next: Assignment
Modify the setting as you desire.

Click Next: Notification
Modify the setting as you desire.

Click Update

To enable PIM on your account:

Login to Azure -> Search for pri -> Click Microsoft Entra Privilege Identity Management
Click My roles
Click Activate on the role that you want.
Select the Duration (Hours) -> Type a reason -> Click Activate
To verify -> Click Active assignments

You can see that I have activated the Intune Administrator

Azure settings

Sign in to the Home – Microsoft Azure
Search for “intr” and click “Microsoft Entra ID”
Click Mobility (MDM and MAM) -> Microsoft Intune
Select All in the MDM user scope

Select All in the MAM user scope
Click X
Click Company branding
Click Default sign-in -> Click Customize
Modify the setting that you desire.

Click Review + Create
Click Create

Azure is now setup. Continue to part 2 to configure Intune.

twitterlinkedin

By Claus