Book Image

Mastering Microsoft Endpoint Manager

By : Christiaan Brinkhoff, Per Larsen
5 (1)
Book Image

Mastering Microsoft Endpoint Manager

5 (1)
By: Christiaan Brinkhoff, Per Larsen

Overview of this book

Microsoft Modern Workplace solutions can simplify the management layer of your environment remarkably if you take the time to understand and implement them. With this book, you’ll learn everything you need to know to make the shift to Modern Workplace, running Windows 10, Windows 11, or Windows 365. Mastering Microsoft Endpoint Manager explains various concepts in detail to give you the clarity to plan how to use Microsoft Endpoint Manager (MEM) and eliminate potential migration challenges beforehand. You'll get to grips with using new services such as Windows 365 Cloud PC, Windows Autopilot, profile management, monitoring and analytics, and Universal Print. The book will take you through the latest features and new Microsoft cloud services to help you to get to grips with the fundamentals of MEM and understand which services you can manage. Whether you are talking about physical or cloud endpoints—it’s all covered. By the end of the book, you'll be able to set up MEM and use it to run Windows 10, Windows 11, and Windows 365 efficiently.
Table of Contents (24 chapters)
1
Section 1: Understanding the Basics
4
Section 2: Windows 365
7
Section 3: Mastering Microsoft Endpoint Manager
19
Section 4: Tips and Tricks from the Field

Identity roles and privileges for Microsoft Intune

In order to configure MEM, you first have to make sure that you have the required privileges to do so. The first user created in your Azure Active Directory (AD) tenant will automatically become the global admin, as a member of the Global Admin role. The Global Admin role has full Microsoft Intune rights.

There are also other roles that could help you in delegating access as part of your user-role design. Some of the next steps for Intune require the Global Admin role, so we recommend using this type of account for the initial setup.

Here's a list of the supported roles within MEM.

Compliance Administrator

Users with this role have permission to manage compliance-related features in the Microsoft 365 compliance center, Azure, the Microsoft 365 admin center, and Microsoft Compliance Center.

Users with this role can view all Intune audit data.

Compliance Data Administrator

Users with this role have permission...