Home avatar

A collection of solutions, ideas, and insights into problems you probably didn't know existed with Modern Endpoint Management products.

Patching Gaps in the CIS Windows 11 Benchmark - BitLocker

Everyone loves a security benchmark, and with the imminent move to Windows 11 for everyone, the Center for Internet Security released version 3.0.1 of theirs, including a build kit for Microsoft Intune, but what does this build kit break for BitLocker encryption?

Creating Windows Autopilot Virtual Machines on macOS

With all this chat about macOS device management in Microsoft Intune, I wonder how many people are macOS users but still need to test Microsoft Intune settings on Windows devices? Well fear not, there is a way to deploy a Windows Autopilot Virtual machine on your macOS device for testing.

Risk Based Windows 11 Feature Update Deployment - Automation

The final part in this series looks at how to bring everything together under a single, repeatable script, allowing for the capture of readiness state, the tagging of devices to support the distribution of Windows 11 23H2.

Risk Based Windows 11 Feature Update Deployment - Feature Updates

Using the data captured from a Windows 11 Feature Update Readiness report to successfully tag device attributes to device objects, and group them based on risk, we now look at how to deploy Feature Updates to these devices in a controlled manner.

Risk Based Windows 11 Feature Update Deployment - Device Attributes

Having looked into capturing the Feature Update Readiness data for Windows 11 23H2 for our Windows devices, we can now use this risk based data to tag them with their associated risk, grouping them together to allow for sensible Feature Update profile assignment.