How to install Windows 11 in Hyper-V
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Windows 11 has now been released over a month ago and many companies are now considering the switch. It is always good to test extensively first and get some hands-on experience.  If you don’t have a physical PC available to test Windows 11, a good alternative is to do this in a virtual machine (VM). Personally, I use VMs a lot when I need to test Microsoft Intune configurations or when giving demos. In this blog In this short blog I explain step by step how to install Windows 11 as a VM in Hyper-V on a Windows 10 or Windows 11 host. I will do this in the following steps; Check if the Hy ..read more
Visit website
How to start with Shared iPads for Business with Microsoft Endpoint Manager (Intune) and Apple Business Manager
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
I get the following question regularly; “can we configure our Apple iPads as Shared device. Where you as a user, can login and logoff without seeing each other’s data?”. Most of the time it’s about medical personal that works in shifts and don’t have a personal device. But you can also think of maintenance and field agents or flight crew members for example. In this case you want to let the employees use their applications across a pool of shared devices. They should be able to pick any random device from that pool, login and do their work. At the end of their shift or workday, they should be ..read more
Visit website
Call to Action : Add the new Microsoft Office (Hub) app for iOS and Android to your current Microsoft Endpoint Manager / Microsoft Intune App Protection Policies
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
In the last few weeks I have had contact with a few companies that use Microsoft Endpoint Manager / Microsoft Intune for managing their mobile devices. In most cases they do this for a longer time and they also use Mobile Application Management (App protection policies) for securing the company data, for example, on BYOD (Bring Your Own Devices / Private owned devices). And this is a good thing if you want to isolate company data in a secure container, but in some cases they did not know about the existence of the new Microsoft Office (Hub) application. Without securing this application, end u ..read more
Visit website
How to add or remove system apps in the Android Enterprise Work Profile with Microsoft Intune
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Depending on the use cases and the requirements of the company, Android Enterprise Work Profile can be a great enrollment mode for both BYOD devices and company owned devices (in fully managed mode) when using Microsoft Intune. With an Android Enterprise Work Profile, you separate private apps and data from the corporate apps and data to prevent data leakage. Depending on the manufacture and the ROM that is installed on the Android device some system apps will be installed within the Android Enterprise Work Profile. In this example on a Samsung Galaxy A6, the Contacts, My Files and the Play S ..read more
Visit website
How to configure Windows AutoPilot with White Glove deployment
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Some time ago I wrote a blog about “How to setup Windows AutoPilot and add existing devices the quickest way”. At that time, White Glove did not exist yet. And it’s great to know how to setup Windows AutoPilot and add existing devices the fastest way, but how to get endusers to work on a new device the fastest way? What is White Glove? That’s where White Glove comes into play. White Glove is a feature that enables pre-enrollment staging. All device based policies, including certificates, applications and settings will be pre-installed on the device. This will result that the user enrollment on ..read more
Visit website
How to update Security Baselines in Microsoft Intune to a newer version
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Security Baselines in Microsoft Intune are templates that contains policy configurations that by default are configured with the best practice from the Microsoft security teams. And that makes a Security Baseline the perfect starting point when creating a new policy set for the modern workplace. When creating a Security Baseline, all settings are pre-configured with the security best-practice from Microsoft. However, you are able to change the settings to a value of your needs. There are Security Baselines available for Windows 10 and later, Microsoft Defender for Endpoint, Microsoft Edge and ..read more
Visit website
How to exclude Shortcuts from syncing to OneDrive with Microsoft Endpoint Manager – Microsoft Intune
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Microsoft OneDrive is a great service for storing your files. And when you have “Known Folder Redirection” enabled, your Desktop, Documents and Pictures folders are redirected to OneDrive and synched to the cloud. This way you have the same Desktop, Documents and Pictures folders available on every device which benefits the user experience. However, you have applications that place a shortcut on the desktop the first time you log in to a new system, for example the Microsoft Edge browser and Microsoft Teams. This results in many of the same shortcuts on your desktop (copy offs) if you switch d ..read more
Visit website
How to control iOS app uninstall behavior at device unenrollment with Microsoft Intune
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
Previously, during a device unenrollment, all applications were removed that where pushed/installed via  Microsoft Intune by default. This is not always handy, for example take the Microsoft Office applications. You can add multiple accounts within these applications and if you are using Microsoft Outlook for your work mail and also for your private mail. You want Microsoft Outlook to stay on your mobile device after an unenrollment. With the August 12, 2019 update of Microsoft Intune it is now possible to control the app uninstall behavior at device unenrollment for iOS devices. To confi ..read more
Visit website
How to move or restore a Windows 11 VM in Hyper-V with TPM enabled (Shielded VMs)
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
In my previous blog I showed you step-by-step how to install Windows 11 as a VM in Hyper-V. The difference with Windows 10 is that Windows 11 requires a TPM (Trusted Platform Module) chip in order to boot. As you could read in my previous blog, this is no problem at all. However, I’m the kind of guy that regularly reinstalls my laptop/desktop and also uses multiple devices to run the same VMs on. And in that case it gets a bit more complex. A VM that is enabled with a TPM will be shielded, what means that it will be protected with encryption keys bound to the host. So if you copy the VM to ano ..read more
Visit website
How to add iOS devices manually in the Apple Business Manager (ABM) for automatic Microsoft Endpoint Manager – Microsoft Intune enrollment
Robin Hobo » Enterprise Mobility + Security
by Robin Hobo
1y ago
It’s a best practice to enroll corporate owned iOS/iPadOS devices via the Apple Automated Device Enrollment (ADE) program (PKA Device Enrollment Program – DEP). It offers “out of the box” security because the enrollment with the MDM solution will start automatically and the user can’t work around it. Next to automatic device enrollment it makes it possible to set devices in supervised mode, which offers more policy settings to apply and in combination with the Apple Volume Purchase Program (VPP), no Apple ID is required during enrollment and for installing company published applications. The g ..read more
Visit website

Follow Robin Hobo » Enterprise Mobility + Security on FeedSpot

Continue with Google
Continue with Apple
OR