Getting started with Administrator protection

This week is all about the new functionality on Windows devices to help protect administrator users. That new functionality is Administrator protection. Administrator protection is aimed at protecting the users while still allowing them to perform their required elevated actions with just-in-time administrator privileges. That makes sure that when dealing with users that have local administrator privileges, instead of those users always having those high privileges, Administrator protection makes sure that those users must consent to actually activate those higher privileges. That makes sure that, by default, the user is now operating according to the least privilege concept and only gets those higher privileges when actually needed. In the end that lowers the attack vector for those users and makes sure that nothing happens without …

Read more

Adding additional hardware properties to the device inventory

This week is all about enhancing the device inventory for Windows devices. Device inventory is a new feature in Microsoft Intune that is specifically focused on enhancing the existing device inventory for Windows devices. That enables the IT administrator to add additional hardware properties to the existing inventory of Windows devices, by relying on the available properties in the Intune data platform. The additional hardware properties can help the organization to better understand the state of the Windows devices and to make potential business decisions based on that information. It really adds additional insights into Microsoft Intune that help with getting in more control and getting better overviews of the Windows devices within the environment. Basically, getting richer reporting information. This blog post will start …

Read more

Enabling hotpatch for Windows 11 Enterprise

This week is all about the latest changes in updating Windows 11 devices. That change is the introduction of hotpatch updates for Windows 11 Enterprise. Hotpatching helps organizations with keeping Windows secure, while minimizing the disruptions for the user. A significant step in keeping Windows more secure and productive. Hotpatching removes the requirement for Windows devices to reboot after every update installation, while still providing a complete set of security fixes. That’s exactly the point of importance for the user experience, as the device has less required reboots. This post will start with a brief introduction about Windows hotpatch, followed with the configuration steps. This post will end with experiencing the configuration. Note: The hotpatch technology is already being used for two years on Windows …

Read more

Working with device compliance for Windows Subsystem for Linux

This week is all about the device compliance capabilities for Windows Subsystem for Linux (WSL). WSL is a feature of Windows that allows the user to run a Linux environment on their Windows device, without needing a separate VM or a dual boot. It’s designed to provide a seamless experience for users that want to use Windows and Linux at the same time. By default, Ubuntu is used as the Linux distribution. There are, however, more options such as Debian, Kali, and SUSE. For the IT administrator it’s good to have the ability to be able to check the Linux distribution and version that is used. That can be achieved by using device compliance policies, as there is now a section specifically focused on adding …

Read more