Our Story

Who we are and how we solve complex IT challenges.

Our Certifications

Microsoft certifications and partnerships validating our technical expertise.

Leadership

Meet the Experienced Leadership Team Driving WME’s Success

Advisory Updates

Expert guidance on Microsoft, security, and compliance developments.

Case Studies

Real-world outcomes from complex Microsoft-focused IT engagements.

Financial Industry

Secure technology solutions for regulated banks and financial institutions.

Healthcare

Secure Microsoft solutions for compliant, connected, and modern healthcare organizations.

Manufacturing

Cloud and security solutions supporting modern manufacturing operations.

Non-Profit

Cost-efficient Microsoft solutions for mission-driven organizations.

Public Sector

Microsoft-based IT services for secure public sector modernization.

High Tech

Scalable cloud, security, and staffing for fast-growing technology companies.

SMBs

Scalable cloud, security, and staffing for fast-growing technology companies.

Cloud Migration Services

Transition your workloads to the cloud securely for greater scalability and performance.

Data Migration Services

Securely transfer your business data with minimal downtime and maximum integrity.

Application Migration Services

Move your applications seamlessly to modern platforms with minimal business disruption.

Identity & Security Migration Services

Strengthen identity management and security while transitioning to modern Microsoft solutions.

IT Staffing

Connect with skilled IT professionals to strengthen your team and accelerate project delivery.

Accounting & Finance

Connect with experienced accounting and finance professionals to support your business goals.

Licensing Support

Discover the benefits of both CSP and On-premises licensing options and find the best fit for your unique business needs. From cost savings to flexibility, we’ve got you covered.

Power Platform

Unlock the full potential of the Microsoft Power Platform Suite to streamline operations, automate repetitive tasks, and gain real-time insights that drive business growth.

Sharepoint Solutions

Supercharge your business productivity and enhance visibility through our proven SharePoint expertise.

Security Solutions

Protect your business with proactive cybersecurity, compliance, and risk management solutions.

Endpoint Management

Secure, manage, and monitor every device with modern endpoint management solutions.

Microsoft Endpoint Manager Overview, Trial Registration and Basic Configuration

May 3, 2021

This is the first of a three-part step-by-step series on Microsoft Endpoint Manager. We’ll show how to set it up and optimize it’s settings to get you up-and-running fast. Bookmark the page to catch parts two and three! Let’s dive in.

It’s the foundation of a modern endpoint management service strategy, combining on-premises control with cloud-based scalability and security.

Microsoft Endpoint Manager (MEM) is a one-piece solution for managing computers, servers, virtual machines, virtual desktops, and mobile devices.

Microsoft Endpoint Manager includes:

Azure Intune – a 100%-cloud MDM/MAM solution for iOS, Android, macOS and Windows management. I will cover Intune features in detail below.

Azure Active Directory – Microsoft’s identity and access management service helps users sign in and access their corporate data, on-premises cloud services and apps.

Microsoft Endpoint Configuration Manager – (MECM is also known as Configuration Manager or ConfigMgr, formerly SCCM) on-premise service to manage desktop and servers (application deployment, OS deployment, OS updates management and a lot of other important features) that can be integrated with cloud-services like Azure AD and Microsoft Defender ATP. Also, a co-management scenario can bring “cloud benefits” to on-premise infrastructure like Azure AD Conditional Access for compliant devices (Intune compliance policies).

Windows Autopilot – helps with computer provisioning and preparation for use. During the provisioning process, pre-installed Microsoft Windows 10 joins to Azure AD and the computer downloads all required settings (policies, apps, scripts, etc.) from Intune.

Desktop Analytics – a cloud solution integrated with MECM which provides information about deployed security updates, helps with app compatibility issues, and Windows 10 implementation planning.

Let’s get started with the first in a series of blogs on how to manage Windows 10 with Azure Intune.

First, let me explain Microsoft Intune features which we can configure:

  • Device restrictions
  • Device compliance policies
  • Administrative templates (similar to GPO in Active Directory)
  • Endpoint protection – firewall, Defender and Bitlocker
  • Security and feature updates
  • Managing apps
  • Basic software and hardware inventory
  • Remote management – wipe, lock, restart, etc.
  • Security baseline
  • Windows Hello for Business
  • PowerShell scripts
  • App protection policies
  • VPN, Wi-Fi, certificates, and email profiles
  • Reports

High-level architecture for Microsoft Intune

As you see Azure Intune and cloud apps use Azure AD as the identity and authorization service, so we need to have the Azure AD tenant first. For both labs and demo environments I prefer to use Microsoft 365 Developer Program that gives you a fully functioned trial Azure AD and Intune tenant:

Click on Join now and then on Set up E5 subscription. You need to provide a user name, your Azure AD domain name, password and region:

Your first domain will have a name yourtenant.onmicrosoft.com and you cannot change it later, but you can add your own domain like company.com later if needed.

Then add your phone number for security:

After registration is completed you get a fully functioning trial tenant with almost 60(!) different licenses available for 25 users:

The most important licenses for us are:

  • Azure Active Directory Premium P2
  • Azure Information Protection Premium P2
  • Exchange Online (Plan 2)
  • Microsoft 365 Apps for enterprise
  • Microsoft 365 Defender
  • Microsoft Azure Multi-Factor Authentication
  • Microsoft Cloud App Security
  • Microsoft Intune

This means we can join our Windows 10 machines to Azure AD, enroll them to Intune, protect them with Defender, deploy Microsoft 365 apps, and many other options.

Let’s do a basic configuration of our Azure AD and Intune. Go to Azure portal and click on Azure Active Directory:

Then choose Mobility (MDM and MAM):

We need to make Intune our MDM solution for this Azure AD tenant. Click on Microsoft Intune and configure:

  • MDM user scope – All
  • MAM user scope – All

And Save it.

Then repeat it for Microsoft Intune Enrollment:

This means all devices joined to Azure AD will be automatically enrolled into Intune.

All users you create in your Azure AD will have accounts like username@yourtenant.onmicrosoft.com. If you want to change domains from onmicrosoft.com to your own, you can add it on Microsoft 365 admin centerSettingsDomainsAdd domain:

Provide your domain name, click Use this domain, and then choose an option for how you want to verify your domain. I chose Add a TXT record to the domain’s DNS records:

Then I need to create a TXT record using the administrative console which my hosting company provides:

After that, we need to come back on the Verify you own this domain step and click Verify. Click Continue, remove a checkbox from ‎Exchange‎ and ‎Exchange Online Protection, click Continue again, and Done.

This setup process is a foundational step within a complete endpoint management service, ensuring Azure AD and Intune work together seamlessly for device onboarding and compliance.

That takes care of installation and basic configuration. Read Part II here where we get into Users, Groups and Licenses of Microsoft Endpoint Manager. See you soon!

If you want to be the first to know when articles are published, get on our email list using the form at the bottom of the page. Have a more specific question about this topic or something else? to contact our experts.

Start your hybrid management strategy

with a free consultation.

Talk to our experts

Share:

Facebook
Twitter
LinkedIn

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.

More Posts

Copilot Cowork: Credit-Based Billing

Until now, Copilot Cowork has been included with M365 Copilot Premium licenses. Now that Cowork has moved out of public preview, Cowork is introducing a ...
Read Full Article
SharePoint OTP Retirement Is Coming in July 2026

SharePoint OTP Retirement Is Coming in July 2026 — What IT Admins Need to Do Before Access Breaks

Starting July 2026, external users who access OneDrive and SharePoint files through legacy SPO OTP links will start receiving access denied — silently, with no ...
Read Full Article
Power Virtual Agents Is Gone. Here's What Replaced It and Why It Matters.

Power Virtual Agents Is Gone. Here’s What Replaced It and Why It Matters.

If someone on your team still calls it “Power Virtual Agents,” they’re working from an outdated map. Microsoft retired the product on November 15, 2023 ...
Read Full Article

Get Microsoft Updates Before They Cost You Downtime

Retirement dates, licensing changes, and security updates from a Microsoft-exclusive team, sent when they matter, not on a filler schedule.
Subscription Form email