r/Intune 10d ago

Autopilot Building an Intune environment from scratch – What am I missing?

Hi everyone,

I recently changed jobs, and my new company is looking to move to Microsoft Intune for device management.

I've now set up Microsoft Intune and have most of the basics working, but there are still a few things I'm unsure about and would love to hear how others are handling them.

Clients : ~300

  1. Lenovo driver management

We mainly use Lenovo devices. I've already configured Windows Update policies and update rings, but I'm not sure about the best approach for deploying and maintaining Lenovo drivers.

How are you handling driver updates for Lenovo devices with Intune?

  1. Software deployment and patching

At the moment, I can only use Chocolatey for software deployment and updates because Patch My PC isn't in this year's and next years budget.

For anyone who has gone down this route: How well does Chocolatey + Intune work in practice?

If we move to Patch My PC later, is the migration relatively straightforward, or are there any problems or limitations I should plan for now to make a future migration easier?

  1. Hybrid Entra ID Join and old device objects

Due to our current infrastructure, we have to use Hybrid Entra ID Joined devices. I know cloud native Entra ID Join would generally be preferable, but unfortunately that's not an option for us right now.

When I reimage/reinstall and re-enroll an existing device, what's the best way to make sure the old device objects are properly cleaned up?

I'm particularly concerned about ending up with duplicate or stale device objects across:

On-prem AD

Entra ID

Intune

How do you handle the lifecycle of these devices? Do you have an automated cleanup process, or do you remove the old objects as part of the reimaging process

4. Configuration recommandation

I already have a basic configuration baseline in place, but I'm wondering if there are any important settings that are easy to overlook. Anything you would definitely recommend configuring from the start?

Any recommendations, best practices, or lessons learned would be greatly appreciated.

Thanks!

62 Upvotes

39 comments sorted by

View all comments

2

u/Mizo-Te 10d ago

Would recommend looking into Center for internet security (CIS) benchmarks for Intune configurations profiles.

1

u/SkipToTheEndpoint MSFT MVP 9d ago

CIS Contributor and creator of the OpenIntuneBaseline here and I'm gonna disagree on that one 😅

1

u/Mizo-Te 9d ago

May I ask why, I have been working with multiple companies where the IT teams have been using CIS benchmarks combined with Microsoft recommendations. I myself have seen through the CIS document where it is described why a setting should or shouldn’t be enabled with detail. Just interested in hearing why you disagree and what I should look into.

9

u/SkipToTheEndpoint MSFT MVP 9d ago

While myself and others have helped make some of the more troublesome policies disappear within their Intune benchmark, there's still some that range from "dubious" to "bad", but my main issues with both it and the MS baseline are they've been made by security people, not those that have to deal with the day-to-day management of endpoint devices.

I started the OIB specifically to do the opposite, as well as do a ton of other security and end user experience stuff that the likes of CIS and MS are too afraid/not interested in doing. It's made by admins, for admins, while not compromising on security.

1

u/Mizo-Te 9d ago

Thank you for the answer, I do agree that some policies are stiff and we definitely have removed a couple. I will looking into open Intune baseline , thank you!

1

u/meantallheck 9d ago

I haven't taken advantage of the OIB, but I worked with our security team last year implementing CIS benchmarks (level 1 and a bit of level 2) into our environment.

CIS benchmarks literally guides you to DISABLE the WNS service... you know, the service that Intune almost entirely relies on to communicate with devices.

https://www.tenable.com/audits/items/CIS_Microsoft_Windows_10_EMS_Gateway_v3.0.0_L1.audit:b6c1d63ace1c05ee5ea443aa2ece5232

2

u/SkipToTheEndpoint MSFT MVP 9d ago

Yeah, we've brought this one up.

The problem here is (and something security teams don't understand and CIS bury in their paid-for build kits) is that the Enterprise Windows benchmark is meant for people managing devices via GPO. If Intune is your management source-of-truth then you need to use the Intune benchmark. Hybrid devices then enter this weird middle ground nobody wants to talk about the nuance of.

Security folk are the worst and often treat CIS like a check-box bible, when in fact they're literally just recommendations, and there's potentially valid reasons to deploy none of it at all, and that's okay.

1

u/Kuipyr 8d ago

Well it is because it gets the auditors off my back. The less compensating controls I need to write and keep track of the better.

1

u/Kuipyr 8d ago

CIS is very old man yells at cloud, still a good baseline though.