Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Licensing Support

Discover the benefits of both CSP and On-premises licensing options and find the best fit for your unique business needs. From cost savings to flexibility, we’ve got you covered.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

Windows Intune: Policy

August 13, 2014

This is part of a continuing series about Windows Intune. This section will focus on creating policies for the different types of clients. If you are familiar with setting client policies in SCCM, this will be very similar.

Adding Policies

To add a policy, click “Add Policy” under Tasks in the Policy node of the web interface. There will be four options. We are going to focus primarily on Mobile Device Security Policy and Windows Intune Agent Settings.

Mobile Device Security Policy

To begin, select “Mobile Device Security Policy” and select the “Create and Deploy a Custom Policy” button. To begin, give your policy a name. Next, take a look through the security section. Most of these policies apply to Windows Phone, Window RT, iOS, and Android. There are a few exceptions, so be sure to note those. Some key policies to pay attention to are “Require a password to unlock mobile devices”, “Require a password type”, and “Minimum password length”. All of these are important if mobile devices can access company data.

If you wish to let the end user decide on any of these, simply click the switch to off. Anything that is switched off will appear greyed out and will not say which operating system this applies too. As soon as you turn it on, you are given that information. One of the security policies that is disabled by default is “Allow fingerprint unlock”. I would suggest thinking about this option, especially with new iOS and Android devices supporting this feature.

The next section is encryption. There are two setting available – encrypt the device and encrypt the storage cards. I would carefully weigh these options and decide what is best for your organization. If you mouse over the information icon, Microsoft has a recommended setting, and some more information about what the policy does.

I am going to skip over the Malware section, as these policies only apply to Windows RT. Next is the System section. This section deals with a lot of iOS-specific items, though there are some Windows Phone and RT settings available. Two things that you should think about here are “Require Automatic Updates” and “User Account Control”. Both of these apply to Windows 8.1 RT or Pro. The User Account Control option provides the same levels as Windows.

Next is Cloud, which deals mostly with iCloud and iOS. Set these as your organization would like. Two things that deal with Windows are providing the URL for Work Folders, and allowing Microsoft accounts.

Next are some general email settings. One important one here is allowing the download of email attachments. This setting could be important for organizations that are concerned about virus being delivered via email. Also, you elect to specify whether or not “other” email accounts are allowed on the device, thereby preventing users from receiving personal email on company devices.

Next are various application settings, such as allowing a web browser, enabling a pop-up blocker, or allowing active scripting. All of these settings can be configured for Windows 8.1, and a few can be set for iOS. Further down are more apps options, such as disabling the app store (available for iOS and Windows Phone 8.1), and whether or not to allow in-app purchases. Finally, you can disable Game Center and multiplayer games on iOS.

Finally, we have Device Capabilities. Here we disable the devices camera, Wi-Fi, Wi-Fi tethering, etc. Further, we can disable roaming and voice assistants. All of this should be configured to meet your company’s policies.

Once you have your policy set, create it. You deploy it to a group during the creation process, or from the “All Policies” screen.

Windows Intune Agent Settings

These settings will apply to computers. First, we have Endpoint Protection. You can elect to install and enable it. Various settings can also be defined, such as enabling real-time protection (and what it looks at), to defining daily scans. As with Endpoint Protection in SCCM, we can also exclude files, folders, and processes from the scan process.

Next, we can define update settings. You will want to pay attention to these, especially the ones about computer restarts. I would recommend keeping the “Allow logged on user to control Windows restart after installation of scheduled updates” set to “Yes” so that the computer does not automatically restart.

Finally, you can define whether or not a user can define there one user-device link. This works similarly to User/Device Affinity in SCCM. I would recommend keeping this set as “No”.

Policy Conflicts

One neat feature of Windows Intune is the ability to show you conflicts between policies. You can click on “Policy Conflicts” to view any and remediate them.

Disclaimer

All content provided on this blog is for information purposes only. Windows Management Experts, Inc makes no representation as to accuracy or completeness of any information on this site. Windows Management Experts, Inc will not be liable for any errors or omission in this information nor for the availability of this information. It is highly recommended that you consult one of our technical consultants, should you need any further assistant.

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

More Posts

Copilot Cowork: Credit-Based Billing

Until now, Copilot Cowork has been included with M365 Copilot Premium licenses. Now that Cowork has moved out of public preview, Cowork is introducing a ...
Read Full Article
SharePoint OTP Retirement Is Coming in July 2026

SharePoint OTP Retirement Is Coming in July 2026 — What IT Admins Need to Do Before Access Breaks

Starting July 2026, external users who access OneDrive and SharePoint files through legacy SPO OTP links will start receiving access denied — silently, with no ...
Read Full Article
Power Virtual Agents Is Gone. Here's What Replaced It and Why It Matters.

Power Virtual Agents Is Gone. Here’s What Replaced It and Why It Matters.

If someone on your team still calls it “Power Virtual Agents,” they’re working from an outdated map. Microsoft retired the product on November 15, 2023 ...
Read Full Article

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.
Subscription Form email