Book Image

Mastering Microsoft Endpoint Manager

By : Christiaan Brinkhoff, Per Larsen
5 (1)
Book Image

Mastering Microsoft Endpoint Manager

5 (1)
By: Christiaan Brinkhoff, Per Larsen

Overview of this book

Microsoft Modern Workplace solutions can simplify the management layer of your environment remarkably if you take the time to understand and implement them. With this book, you’ll learn everything you need to know to make the shift to Modern Workplace, running Windows 10, Windows 11, or Windows 365. Mastering Microsoft Endpoint Manager explains various concepts in detail to give you the clarity to plan how to use Microsoft Endpoint Manager (MEM) and eliminate potential migration challenges beforehand. You'll get to grips with using new services such as Windows 365 Cloud PC, Windows Autopilot, profile management, monitoring and analytics, and Universal Print. The book will take you through the latest features and new Microsoft cloud services to help you to get to grips with the fundamentals of MEM and understand which services you can manage. Whether you are talking about physical or cloud endpoints—it’s all covered. By the end of the book, you'll be able to set up MEM and use it to run Windows 10, Windows 11, and Windows 365 efficiently.
Table of Contents (24 chapters)
1
Section 1: Understanding the Basics
4
Section 2: Windows 365
7
Section 3: Mastering Microsoft Endpoint Manager
19
Section 4: Tips and Tricks from the Field

Identity roles and privileges for a Windows 365 cloud PC

In order to use a Windows 365 cloud PC, your Azure AD configuration should be hybrid Azure AD-joined (HAADJ) to enroll your cloud PCs into Intune.

Azure Subscription Owner

Users with this role have global access to all resources in the Azure subscription. These rights are needed for the initial setup of Windows 365.

This role grants users full access to manage all resources, including the ability to assign roles in Azure RBAC.

Intune Administrator

Users with this role have global permissions within Microsoft Intune.

The Intune Administrator role contains the ability to manage users and devices in order to associate policies, as well as creating and managing all security groups in Azure AD.

Important Note

Intune Administrator does not have admin rights over Office groups.

Domain Administrator

Users with this role will be able to create computer accounts in your on-premises domain. This is needed...