Dean Ellerby MVP
Dean Ellerby MVP
  • 110
  • 309 406
A quick guide to Defender for Endpoint deployment via Microsoft Intune
Get 50% off your Academy Subscription here ** learn.alpenshield.io/intro-offer/ **
Hello! In this video, I talk about protecting Windows clients using Microsoft Defender for Endpoint. I start by explaining what Defender for Endpoint is, and what it's not, to ensure we're all on the same page.
Then, I dive into the onboarding process, configuring Windows devices for protection using Defender for Endpoint and Microsoft Intune.
I also discuss the different plans available-Plan 1, Plan 2, and Defender for Business-and their respective features. Key topics include security configurations, automated investigations, and endpoint detection and response (EDR).
I'll show you how to get started with licensing, configuration, and the key functionalities that make this tool a powerful security solution for enterprises. Tune in to learn more and enhance your security posture with Microsoft technologies!
Переглядів: 270

Відео

Free Microsoft Lab for Hybrid Entra ID and ConfigMgr - here's how!
Переглядів 1,6 тис.4 години тому
Hey everyone! In this video, I'm giving you a quick overview of how I rebuilt my lab environment after my trial tenant expired. This setup is super important for getting ready for the upcoming Alpen Shield Academy live courses, where we'll cover stuff like Defender for Endpoint, Intune, Autopilot, and even certification courses like SC300 and SC200. I'll show you the tools I'm using, like the W...
Finally! A solution to macOS app updates !
Переглядів 1,1 тис.14 днів тому
In this video, I share my first impressions of Root3's App Catalog solution for macOS, which seamlessly integrates with Microsoft Intune. As someone who has been on the lookout for an effective and comprehensive app catalog for macOS, I was excited to dive into Root3's offering. 🌟 Highlights of the Video: - A detailed overview of Root3's App Catalog interface and features. - My initial thoughts...
Ultimate Guide to Windows Autopilot - 2024 edition
Переглядів 5 тис.Місяць тому
Welcome to the updated version of my ultimate guide to Windows Autopilot! In this video, I'll take you through everything you need to know to get started with Windows Autopilot, from setup to deployment. This video is part of a longer series of courses on Windows Autopilot at the AlpenShield CyberSecurity Academy - Check it out at learn.alpenshield.io What You'll Learn: Windows Autopilot: Under...
I was WRONG about Autopilot Device Prep Corporate Identifiers
Переглядів 1,7 тис.2 місяці тому
Einstein famously remarked, "Anyone who has never made a mistake has never tried anything new". Which is why I endeavour to be wrong at least once every day. And today, I make no exception.
No Hardware Hash for Windows Autopilot v2? Does it really work?
Переглядів 3,6 тис.2 місяці тому
How does Windows Autopilot Device Preparation work without a hardware hash? He's the theory, followed by a demonstration of how NOT to use Corporate Device Identifiers!
Windows Autopilot V2? Or just a new profile type? Who cares! It's here!
Переглядів 4,8 тис.2 місяці тому
Windows Autopilot v2, or the New Windows Autopilot Profile Type, or the Evolution of Windows Autopilot, or Next Generation of Windows Autopilot, or the Windows Autopilot Update, or Windows Autopilot Device Preparation?? WHATEVER YOU CALL IT, LET'S SEE HOW IT LOOKS! There has been a significant release of Windows Autopilot this week. Join Dean as we take a first look at how it works! Next Genera...
Working with Intune Apps? You NEED to see this!
Переглядів 3,6 тис.2 місяці тому
In this video, I dive into Robopack’s 35,000 Package Library. Gain instant access to a vast library of over 35,000 apps. Seamlessly integrate these apps into Intune and enjoy the convenience of auto-updates, ensuring your apps are always up-to-date. Robopack have also just announced their FREE licenses for NGOs and small businesses… Free 😱 🔗 Links Mentioned in the Video: www.robopack.com 🔔 Subs...
Is This the Ultimate App Deployment Tool for Microsoft Intune?
Переглядів 8 тис.2 місяці тому
In this video, we dive deep into Patch My PC's new Cloud Publisher Portal, the latest tool designed to streamline your application deployment process within Microsoft Intune. If you're looking for an efficient way to manage your apps, this is a must-watch! Patch My PC's Cloud Publisher Portal revolutionizes the way you handle application deployment. From automated updates to seamless integratio...
Want to use PSADT with Microsoft Intune?? Here's how!
Переглядів 2,1 тис.3 місяці тому
The PowerShell App Deploy Toolkit is a powerful and versatile tool to help with Enterprise App Deployments. It works with ConfigMgr, Intune, and many other MDMs. Here's how to get it working with Microsoft Intune! Win32 Content Prep Tool: github.com/microsoft/Microsoft-Win32-Content-Prep-Tool/blob/master/IntuneWinAppUtil.exe AlpenShield CyberSecurity Academy is launching soon at learn.alpenshie...
New to PowerShell App Deploy Toolkit? Here's how to get started!
Переглядів 4 тис.3 місяці тому
New to PowerShell App Deploy Toolkit (PSADT)? This beginner-friendly video will introduce you to the basics and help you get started with this powerful tool. With PSADT, we're able to deploy complex, or even just simple apps and complete all of our testing locally - take a look! ServiceUI.exe link: github.com/andrew-s-taylor/public/blob/main/Install-Scripts/ServiceUI.exe AlpenShield CyberSecuri...
Major Microsoft 365 Developer Program Changes - What are your options?
Переглядів 5 тис.4 місяці тому
With the massive, breaking changes to the M365 Developer Program (also known as the M365 Dev Program) , announced in January, many learners are no longer able to access the platform to get familiar with the technology. Now, anyone who needs to renew or sign up to the Dev Program must have a Visual Studio Enterprise Subsription! (devblogs.microsoft.com/microsoft365dev/stay-ahead-of-the-game-with...
Conversations at MVP Summit 2024 - Daniel McLoughlin
Переглядів 934 місяці тому
After a long day of MVP Summit 2024 Sessions, Daniel McLoughlin and I found a few minutes to catch up over a couple of soft drinks! Cheers!
Conversations at MVP Summit 2024 - James Robinson
Переглядів 1144 місяці тому
I had the pleasure of catching up to James Robinson - we were walking between Microsoft Buildings 36 and 41, and had a chance for a brief chat!
How to Create Device Configuration Profiles in Microsoft Intune
Переглядів 1,9 тис.4 місяці тому
This video is a clip from my most recent update to my Microsoft Intune for Windows training course on Udemy. In this clip, we talk through the various methods of creating Device Configuration Profiles in Microsoft Intune, including Administrative Templates, Settings Catalog, and Custom Profiles! Want to see more? Here's the course link with a discount: www.udemy.com/course/learn-intune/?referra...
Configure Web Filtering in Microsoft Defender for Endpoint
Переглядів 2,6 тис.5 місяців тому
Configure Web Filtering in Microsoft Defender for Endpoint
Is Intune’s macOS management capability finally complete?!
Переглядів 3,4 тис.5 місяців тому
Is Intune’s macOS management capability finally complete?!
Handling Apple ID conflicts during Entra and Apple Business Manager Federation
Переглядів 3,2 тис.6 місяців тому
Handling Apple ID conflicts during Entra and Apple Business Manager Federation
Automatically create Apple IDs for your users? Here's how!
Переглядів 4,8 тис.6 місяців тому
Automatically create Apple IDs for your users? Here's how!
Automated App Updates for macOS - does it work?
Переглядів 7906 місяців тому
Automated App Updates for macOS - does it work?
Are you ready for the Festive Cyberattack?
Переглядів 3727 місяців тому
Are you ready for the Festive Cyberattack?
Microsoft Entra Private Access - initial configuration first look!
Переглядів 3,9 тис.8 місяців тому
Microsoft Entra Private Access - initial configuration first look!
What's better than Windows Security Baselines in Microsoft Intune? Let's see!
Переглядів 2,2 тис.8 місяців тому
What's better than Windows Security Baselines in Microsoft Intune? Let's see!
Import and Export Settings Catalog Profiles... uh... Policies...
Переглядів 4548 місяців тому
Import and Export Settings Catalog Profiles... uh... Policies...
Declarative Device Management Software Update deployment with macOS and Intune (it worked!!)
Переглядів 1,3 тис.8 місяців тому
Declarative Device Management Software Update deployment with macOS and Intune (it worked!!)
macOS Settings Catalog and Declarative Device Management first look!
Переглядів 5778 місяців тому
macOS Settings Catalog and Declarative Device Management first look!
Best outtake 2023 - fun with Security Groups
Переглядів 3058 місяців тому
Best outtake 2023 - fun with Security Groups
Configure macOS devices with Microsoft Intune
Переглядів 7748 місяців тому
Configure macOS devices with Microsoft Intune
Configure Microsoft Office on macOS using Microsoft Intune
Переглядів 7109 місяців тому
Configure Microsoft Office on macOS using Microsoft Intune
5 Tips for Microsoft Entra Conditional Access
Переглядів 1,6 тис.9 місяців тому
5 Tips for Microsoft Entra Conditional Access

КОМЕНТАРІ

  • @pa1089
    @pa1089 4 години тому

    Hi There. Thank you for the video. I do have E5 developer licenses without windows and cannot seem to get a trail license to test similar to you. Can you please let me know how can i get one? Thank you

  • @user-kl1bm2gt4e
    @user-kl1bm2gt4e 17 годин тому

    Please make playlist for defender for endpoint though Intune

  • @aligenel
    @aligenel 19 годин тому

    How do i can get MSI product code for any MSI file?

  • @CulinarySmash
    @CulinarySmash День тому

    Thanks for the work, Dean!

  • @user-ex7rl9rz5c
    @user-ex7rl9rz5c День тому

    Hi, Realy thank you , i appreciate if you make a video for how to remove an Autopilot devices from the endpoint and how i can rejoine it again to autopilot as a new device , Facing this issue

  • @anuradhasinha5592
    @anuradhasinha5592 2 дні тому

    Great video. Can we do this in bulk?

  • @patrick__007
    @patrick__007 2 дні тому

    Absolutely useful! What happens in case of using an active sync from on prem to Entra but the trial expires?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 2 дні тому

      I typically refresh my labs every few months, so it doesn’t really affect me. If you wanted to keep your AD / ConfigMgr lab, just uninstall Entra Connect and connect it to the new tenant when you’re ready.

    • @DreamRevelations
      @DreamRevelations 2 дні тому

      Hi Dean. Pretty good stuff as usually. But how do we get the Office365 trial licenses?? Common "techniques"😊 like the one to get a dev account previously used don't work anymore.

    • @patrick__007
      @patrick__007 День тому

      Getting stuck on the Azure AD signin configuration of Entra Connect. Since the configured domain in AD is not owned by me, I can't proceed..

    • @martijncornelissen2194
      @martijncornelissen2194 20 годин тому

      @@DeanEllerbyMVP Is it possible to extend the trial period with the slmgr /rearm command?

  • @patrick__007
    @patrick__007 2 дні тому

    Thanks Dean for uploading. I get the following error 0x8007EA61 when deploying it to a demo device group.

    • @patrick__007
      @patrick__007 2 дні тому

      Managed solving the issue by adding the $dirFiles. Must overwatched your comment about that.

  • @kauwabinga
    @kauwabinga 3 дні тому

    Many Thanks for this information 🙏🏻

  • @asentertainment2051
    @asentertainment2051 7 днів тому

    Does anyone know the bad vs good between win32 and line-of-business methods? I figured the web gui method would've been the most modern way to go about it.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 7 днів тому

      LOB is an older approach. Win32 has improved logging capability, and allows a more flexible deployment. The recommendation is to wrap MSIs as Win32 Apps, to get access to those better features.

    • @asentertainment2051
      @asentertainment2051 7 днів тому

      @@DeanEllerbyMVP Perfect! thank you!. Also thank you for the folder tip! i was following other howtos and had several msi files in my folder. So they were all getting packaged into one file like your example.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 7 днів тому

      You're welcome. It's an easy mistake to make, because it's not too clear in the interface in my opinion!

  • @DruDubay
    @DruDubay 7 днів тому

    FYI, the Device policy will disable OneDrive, you can find the setting under "System\Disable One Drive File Sync" which is set to "Sync disabled"

  • @Krully
    @Krully 7 днів тому

    Hi, what licence you have, because im searching for makeing groups in my panel, ad dont find it

  • @devraj_thezeus
    @devraj_thezeus 8 днів тому

    I like how firmly u say hybrid autopilot isnt th way, if only we could convince people of that

  • @marioveras6768
    @marioveras6768 8 днів тому

    Awesome! I like how you go straight to the point. No BS or endless preamble. Great demo!

  • @jbreezecoleman5345
    @jbreezecoleman5345 8 днів тому

    I really appreciate this video from you!!

  • @randomgaminginfullhd7347
    @randomgaminginfullhd7347 8 днів тому

    Hello Dean. You're a really good teacher and certainly very knowledgeable. Let me ask: If one's going to work as a system admin, what certifications are of the most value when it comes to getting hired, ticking HR checkboxes etc?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 7 днів тому

      If it's a Windows sysadmin, I would focus on all of the fundamentals (SC-900, MS-900, etc). These are relatively cheap, and relatively easy, and give a great overview and base for both skills, and recognition. After that, a focus on the topics you find most interesting - is it Security, or Management? The MS-102 would be a great 'target': learn.microsoft.com/en-us/credentials/certifications/exams/ms-102/ You can then specialise in MD, or SC, or any other track. I'm building a series of courses for certification with other MVPs and authors over at the AlpenShield Academy, learn.alpenshield.io which is launching August 1st!

  • @claytonseager8554
    @claytonseager8554 9 днів тому

    If you do not use ISE for PowerShell, you are done in my book. ISE is the cult classic. Love the video, thanks for sharing!

    • @Pk223-r1t
      @Pk223-r1t 2 дні тому

      says the guy probably stuck in tech support for the last few years :D

  • @trignite
    @trignite 10 днів тому

    Robopacks 35,000 applications sounds good... until you realize most of them aren't actually packaged by them, most of them are literally just winget packages, which really dont run all that well.

  • @thepete1338
    @thepete1338 12 днів тому

    Brilliant as always!

  • @jonathang8571
    @jonathang8571 13 днів тому

    Impressive looking solution! We've started using Robopack for Windows and hoping they will eventually add Mac, but this looks like it might be a good solution if that doesn't come to fruition.

  • @laze1111
    @laze1111 13 днів тому

    After enabling the Connection into ABM, we see this entra info under "Provisioning" -> Out of the box automatic provisioning to Apple Business Manager is not supported today. Ensure that Apple Business Manager supports the SCIM standard for provisioning and request support for the application as described here. To determine if the application supports SCIM, please contact the application developer.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 7 днів тому

      True! It seems like they moved away from SCIM and managed the synchronisation natively using an Enterprise App. Shame they didn't update their docs!

  • @flove7808
    @flove7808 14 днів тому

    What are the options for windows? - We tried winget + Winget-AutoUpdate which is unreliable... - Not tested, chocolatey...

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 14 днів тому

      Patch My PC: ua-cam.com/video/QkZIRcDCszk/v-deo.html Robopack: ua-cam.com/video/HY6QCkCok1k/v-deo.html

  • @ulrikboesen
    @ulrikboesen 14 днів тому

    Thanks for another great video.

  • @UnforgivingEnd
    @UnforgivingEnd 14 днів тому

    This looks VERY promising - we have been looking for a simple App management solution for deploying apps to MacOS for years - and this even included updating. This still doesn't entirely account for the needs of MSP's - hopefully a multi-tenant solution is added down the line! I have experienced the same thing you have, where Munki is the go to solution. The issue with Munki, in my opinion, is that it does not scale very well across many customers, and still require manual labor to update apps. Question: I noticed that "enforcing" apps to be installed, required a script. Is it possible to "bundle" a script for multiple software? Having a lot of scripts, would be a bit cumbersome across customers.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 14 днів тому

      Fantastic question - I'll test it out and check with Root3 also. They reached out to let me know that I could have done the Intune integration bit much easier too, so as soon as I've fixed my mic, I'll be recording an update :-)

  • @abhishekhavanur3865
    @abhishekhavanur3865 14 днів тому

    Hi Dean, Thanks for this video, However i would like to know your inputs on how to notify users about unused apps on windows set to specific days in Microsoft defender

  • @ToTCaMbIu
    @ToTCaMbIu 14 днів тому

    Looks great. Do you know how the tool handles updates when the app is being used?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 7 днів тому

      no! but great question. I'm recording a new video to cover what I got wrong in this one, so I'll try it out.

  • @ItsSaulter
    @ItsSaulter 14 днів тому

    Great review. I’ve been using Automox for the past few years, but with each Apple chip update the agent breaks. So this may be my replacement.

  • @Visualization1
    @Visualization1 14 днів тому

    Nice vid! However because Apple moves fast I believe you need an MDM for Apple devices only. I really like Kandji. The big ones don’t prioritize Apple but most of the time windows.

    • @ToTCaMbIu
      @ToTCaMbIu 14 днів тому

      FYI, Intune provides zero-day support for any new MDM features released by Apple. This means that when a new MDM feature is officially launched, it will be immediately available to you in the settings catalog. Recently, Apple introduced support for platform SSO, allowing users to sign in to macOS using Entra ID. I bet all macOS-centric MDM providers are scratching their heads over this development.

  • @johnstevens4364
    @johnstevens4364 14 днів тому

    I've used this tool with JAMF, and was going to look into this for my Intune role coming up, also there's Installomator and Patchomator just FYI... Also, there is this third-party company as well. Alectrona Patch

  • @strikesbac
    @strikesbac 14 днів тому

    We use PatchManagerPlus, its agent based and updated Windows, Mac, and Nix.

  • @-maphias-
    @-maphias- 14 днів тому

    This is great. App catalog + updates were probably the one thing that had me hesitant to move away from my current MDM to Intune...but this is reasonable solution. Seems like PMPC needs to acquire these folks! I've been using some of your content recently to build out Intune for my Mac endpoints with the intention of moving off of JAMF. Glad to see an Intune MVP out there that is taking macOS seriously. Keep up the great work.

  • @whoanelly-
    @whoanelly- 15 днів тому

    Good video, 'cept your negative bias against hybrid. Not ALL places are full AzureAD or will be going that way.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 14 днів тому

      I have no negative bias against hybrid. I have a negative bias against Hybrid Autopilot. Hybrid is great, it's the situation most organisations will be in for a long time. It works very well. Most of my customers are hybrid, and I recommend it quite often. Just don't try to be all fancy and use a cloud-native provisioning solution for your traditional hybrid organisation :-)

  • @burakalkan5639
    @burakalkan5639 16 днів тому

    Hi Dean, Thanks for the AP guide. Would you mind explaining why we shouldn't select Microsoft Entra hybrid Joined option (28.16) ? I have hybrid AD environment and I want the new devices automatically join my domain so just wondering why it's wrong? Thanks in advance :)

    • @DeanEllerbyMVP
      @DeanEllerbyMVP 14 днів тому

      Hello! Autopilot works best when doing cloud-native (or cloud only). Using it for hybrid join is more complicated and is usually the cause of most problems with Autopilot. You've been building devices for many years, and they can become hybrid using Entra ID Connect. It works well. I'd say keep doing what has worked for many years for Hybrid devices. If there's a subset of devices that can go cloud-native, use Autopilot for them and enjoy the benefits of cloud-native provisioning :-)

  • @simonbruncke5570
    @simonbruncke5570 20 днів тому

    I know I'm a little late here, but because our devices have their autopillot started by a 3rd party offsite, I don't see the need to switch from our current AutoPilot V1 setup to this new V2 option. However, if they added the option to include configuration profiles in V2, that would definitely make me switch

  • @lindsaydunlap7220
    @lindsaydunlap7220 23 дні тому

    This was very easy to follow and not overwhelming, thank you.

  • @ColemanWorld
    @ColemanWorld 23 дні тому

    This option is no longer there, when I go to Provisioning inb Microsoft Entra, this is the message that comes up: Out of the box automatic provisioning to Apple Business Manager is not supported today. Ensure that Apple Business Manager supports the SCIM standard for provisioning and request support for the application as described here. To determine if the application supports SCIM, please contact the application developer.

  • @jack4553
    @jack4553 27 днів тому

    I have configured hybrid autopilot for a 1500 user company, it was challenging but got there in the end, one of the major advances was pushing a manual ad sync when a new computer object joined the forest, that made the hybrid ad join alot quicker.

  • @ZeR0X04
    @ZeR0X04 27 днів тому

    Ty for such a detailed guide!, However I'm having a problem when using the "Get-WindowsAutopilotInfo -Online" command on PS when on the OOBE screen, I get an error msg in the authentication box that pops up that says "Update your browser". This is a Windows 11 23H2 fully patched. Any ideas on how to fix this problem?

  • @dearshomy
    @dearshomy 29 днів тому

    I've just bought your intune course on Udemy.

  • @HenkStoop
    @HenkStoop 29 днів тому

    Hi! you are talking about security risks of deploying the managed installer of Intune, which allows apps from Intune. What are those security risks?

  • @gangisivanandini8644
    @gangisivanandini8644 Місяць тому

    Hi, thanks for sharing the knowledge, it's really useful with detailed explanation. please guide me, to restrict the local device admin access for corporate MacOS and iOS devices? do there is any such option? I have been searching for a long, but I was unable to identify the sol, please share your knowledge on this area as well?

  • @littletoes6622
    @littletoes6622 Місяць тому

    Hi Dean, I would need ur help as i have to migrate 50 MAC corp devices on Intune, which are currently being managed by local IT only, no option to set up ABM, So can i follow this practice and manually change the ownership to corp ? Kindly suggest

  • @ShibuGeorgeMac
    @ShibuGeorgeMac Місяць тому

    Excellent video

  • @Dynomitech
    @Dynomitech Місяць тому

    Funny. I've been waiting.. thinking my configuration was messed up. Then I restarted the machine when you did and boom, pop up for FileVault.

  • @AbidSheikh-kg9tv
    @AbidSheikh-kg9tv Місяць тому

    Excellent! very detailed video for IT Administrator to follow to setup windows autopilot.

  • @GaryRohrer
    @GaryRohrer Місяць тому

    Very helpful, now to figure out what to tell our 400+ conflicting users....

  • @DoubleA-ARon
    @DoubleA-ARon Місяць тому

    Dean, the fact that you "do it live" makes your content the best. Thanks for keeping it real!

  • @user-zw4zd4ft4g
    @user-zw4zd4ft4g Місяць тому

    what happens to the existing trial plans? mine is expiring in a month. will i get a free extension?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP Місяць тому

      Existing developer trials only extend if you meet the new criteria.

  • @federicoo_
    @federicoo_ Місяць тому

    The only free option working. Thanks Dean!!