Windows 8.1 MDM through Intune/SCCM

We've been testing Intune with SCCM for a while now and it does pretty much all we currently need. Our focus has lately been on securing our devices, require PIN, complexity, device encryption. These all work great on iOS, Windows Phone and Android, but
do not on Windows 8.1.
Windows 8.1 gets certificates through NDES, VPN profiles, but the settings for UAC, encryption, requiring password, account lockout are not applied. Are these settings even supported on Windows 8.1? I'm having a hard time finding documentation on what exactly
is supported and how to apply these.

I'm still struggling with this. One of the questions I have is do I need to install the Company Portal for these settings to take affect?
You have confused me in this post. I am going to have to guess Windows 8.1 is on a tablet in this case, as you are referring to mobile devices.
If it is not a mobile device then you dont need to install this on a Windows machine. It is a web page.
The article linked above talks about compatibility with Windows mobile devices with Windows Intune.
http://technet.microsoft.com/en-us/library/dn376523.aspx
It states:
Windows 8.1 and Windows RT 8.1 (enrolled by Microsoft Intune)
So I would take the last bit as the device needs to be enrolled through Intune in order to achieve this.
Have a look at Gerrys blog here:
http://gerryhampsoncm.blogspot.co.uk/2014/01/mdm-in-sccm-0212-r2-windows-rt.html

Similar Messages

  • Deploy Windows 8 To Go through SCCM 2012 SP1

    First a little backgroud:
    I have SCCM 2012 SP1 with MDT 2012 Update 1 integrated. I am using an MDT UDI task sequence to deploy windows 8 and it works perfectly. My Windows 8 image is fairly thin (only containing OS updates and C++ runtimes), and I am using the MDT database
    and an MDT task sequence in SCCM 2012  to dynamically set a list of SCCM Applications to install as well as settings based on location. 
    Now I want to get Windows To Go provisioning working in SCCM 2012 SP1. I had a powershell script that preparied the drive and applied a thick image (including office and other apps) to it then updated unattend.xml with a computer name and the domain join
    info.  That worked for me however I'd like to levarage the dynamic task sequence that I described above to build these To Go sticks the same as my other Windows 8 machines without having to keep updating the thick image evertime something changes. 
    There isn't much info out there that Iv'e found on setting up SCCM 2012 SP1 to provision windows to go here are the two that I have found 
    http://ixrv.blogspot.com/2012/10/provisioning-windows-8-to-go-with.html
    http://technet.microsoft.com/en-us/library/jj651035.aspx
    I followed the instructions in the first link and was able to run the Windows to Go Creator program and apply the prestaged wim to the USB stick. I rebooted from the USB stick Windows PE started and started to run my task sequence then it errored out on
    the apply image step. At this point it occured to me that the MDT SCCM task sequence was probably not setup for prestaged media and or Windows To Go. 
    So my question is am I on the right track? Do I just need to examine each step in my task sequence and make sure that it will work properly with my Prestaged/Windows To Go stick? If so has anyone actually gotten this to work that could give me some advice?
    Or is it asking too much to have a dynamic Windows To Go task sequence and I should just be building a thick image and using a second task sequence specifically for Windows to go? 
    are there any other resources for Windows To Go with SCCM that I'm missing? 
    Thanks, 
    Tony

    First of all sorry I missed your last three posts I have to check my email notifications. I'll try to answer all of them even though I think the last part is the only one where you are still stuck. 
    When I created my prestaged media I didn't put anything into it except for the the OS image and my PE image. On the Select Application and Select Package screen in the prestaged media wizard remove any application or packages that are added automatically.
    The task sequence is supposed to be smart enough to know if the version of the package that is on the prestaged media is out of date and go to a DP to get it but that didnt work for me. The only way I was able to get it to work was to remove all the packages
    from the prestaged media even the Customsettings package, the MDT toolkit package, USMT, etc.. 
    http://social.technet.microsoft.com/Forums/en-US/configmgrosd/thread/d729d0ff-829f-4af8-91af-2131b3355fd0/
    This thread which is about prestaged media in SCCM 2007 helped me to understand how prestaged media is supposed to work. Basically what I learned is that once the computer is rebooted from the ToGo stick into PE the task sequence will run the same as any
    other task sequence installing any applications and setting up your ToGo stick just like any other computer that runs the task sequence they dont need to be in your prestaged media for this to happen. 
    You shouldn't need to worry about partitioning WTGCreator.exe will partition the ToGo stick for you I'm just using the standard MDT Integrated partitioning in my task sequence. The one thing that I did was set the Windows To Go Creator package to "run from
    distribution point" which speed things up because then it didnt download the prestaged wim then apply it to the USB drive. 
    Is it booting into PE then rebooting? Did you check the "Allow unattend operating system deployment" check box when you made your prestaged media? If so it wants you to have set the task sequence to run in a task sequence variable SMSTSPreferredAdvertID
    to the task sequence ID you want to run. I'd just remake the media and leave that box unchecked. 
    Good luck and let me know how it works for you. I'll check back sooner this time I promise. 

  • Email are not sync while deploying Email Profiles to Mobile Device through Intune

    Hi,
    I am facing Email synchronization issue while deploying the Email Profiles Policy to Mobile Devices (Windows Phone 8.1, Ios and Androids all mobile devices).. through Intune .Email Profile deployed to Mobile devices but the emails are note getting downloading..
    In my infra there is exchange Online  and also ADFS deployed in onpremise.. the Exchange Active sync is
    outlook.office 365.com for any exchange online email accounts but there is some rules configured in ADFS that all the emails will routed through
    [email protected], and through [email protected]
    email are getting downloaded in mobile devices that currently configured through Airwach MDM sultions..
    but, now i have to manage the mobile device through Intune and while deploying the Email profiles Emails are note getting downloaded ,even i tried to use outlook.office365.com
    and [email protected] both as Active Sync Server name..
    I haven`t any idea to solve this issue, please guide is anything i need to configure ion ADFS rule of Intune Attributes ( that will allow mobile devices to download the emails )etc..  please suggest for solution..
    Shailendra Dev

    Intune really has *nothing* to do with the proper functionality of the e-mail client on the mobile device. All Intune does is create the profile -- what the e-mail client does with that information is up to the e-mail client.
    Have you verified that the profile that Intune created is correct?
    Jason | http://blog.configmgrftw.com | @jasonsandys

  • Looking to run windows on my MBPro through Bootcamp or Parallels, but would like to use a downloaded Windows 7, is it possible to install without the Windows Disc?

    Looking to run windows on my MBPro through Bootcamp or Parallels, but would like to use a downloaded Windows 7, is it possible to install without the Windows Disc?
    Need to set up a workstation on my MBPro that will only run on Windows. Im willing to use Bootcamp or Parallels to see what works best. Need to get this set up this week to enable working from home on my MB - rural and hoping to buy Windows 7 online - am I able to get windows working through either bootcamp or Parallels without the actual Windows disc? Bootcamp set up guide calls for a disc.

    Welcome to Apple Support Communities
    First, the answer to your question is yes, it IS possible to install Windows in Parallels without a disc, using an .iso image file.
    Boot Camp since OS X 10.8 also installs Windows without a disc: https://discussions.apple.com/thread/4889551?tstart=0
    Parallels has complete documentation, series of forums, and a knowledgebase. You can also download the current release of Parallels 9 and try it for free for a few weeks before you decide to purchase it.
    The Parallels Desktop for Mac product page: http://www.parallels.com/products/desktop/
    The Desktop for Mac forums: http://forum.parallels.com/forumdisplay.php?58-Parallels-Desktop-for-Mac
    Documentation: http://www.parallels.com/support/desktop-virtualization/desktop/#c12970
    The Knowledgebase for Desktop for Mac: http://kb.parallels.com
    The primary difference between a Boot Camp installation and a Parallels installation is that in the Boot Camp installation, you're installing Windows into a separate partition on your internal mass storage device (hard drive or SSD) and then rebooting your Mac directly into Windows.
    In Parallels, you're always running OS X on the Mac and Parallels is running a Windows virtual machine.
    Not to get too technical here, but it is also possible for Parallels to run an installed Windows Boot Camp partition as a virtual machine. If you're evaluating system performance with a trial copy, that might be the way to go, because you only have to install Windows once on Boot Camp as a dual-boot system, then install Parallels Desktop and run the Boot Camp partition as the virtual machine.
    There is a performance difference between the two, with the Boot Camp Windows installation being faster, but without the convenience of running both Mac and Windows applications simultaneously offered by Parallels. Sometimes that convenience outweighs a performance hit.
    I can't give you more Mavericks and Parallels 9 specifics, because I'm currently running Windows 7 with Parallels 7 on OS X 10.8.5. Parallels 7 will not run on OS X 10.9 Mavericks.
    I've been using Parallels (to run a few old rarely-used WIndows applications with features that would require a steep learning curve and major expense to purchase and learn a similar Mac app) occasionally since Parallels 3 and Windows XP. With each new release of OS X, each new release of Parallels, and each new Windows release, there are ALWAYS 'early adopter' bugs that get worked out over time.
    Message was edited by: kostby

  • Master Data Load to APO from SAP MDM through SAP PI

    Hi SDners,
    This is a Parts Master Data Solution for one of the Largest Auto Manufacturer where SAP MDM will be the central hub of all the Global and Local attributes of Parts . The subscribing system is SAP SCM APO . Please advice if there is any possibility of direct integration between APO -MDM through PI. Does PI has the standard IDOC types to communicate with APO.
    Also does APO has some RFC/BAPI to do master data load for Product Master /n/sapapo/mat1
    Thanks,
    Prabuddha

    Hi,
    Check the LUWs in SM58 in source system and then execute it. Else check in BD87 and push the IDocs manually in ECC.
    Thanks
    Reddy
    Edited by: Surendra Reddy on Feb 24, 2009 10:59 AM

  • HT1338 I have been trying to install window 7 operating system through booth camp assistant, i will finish all the stages for windows to complete installation it will hook at that stage please i need help.

    I have been trying to install window 7 operating system through booth camp assistant, i will finish all the stages for window to complete installation it will hook. the installation cannot be able to complete and i really install windows on it, please i need an assistance on how to go about it.

    Right now I have 6 different systems installed. Windows XP, 7, and 8 plus Linux Mint, Commodore, and OS X Snow Leopard (for old times sake), all running on Mountain Lion.
    I recommend reading the user manual as it greatly helps getting through the steps, however an intuitive person should pick it up fairly easily.
    Thanks to BobTheFisherman for the link.
    There are other ways to get Windows on a Mac but I'm a big fan of open-source software.
    Give it a try. You might like it or it may not be your cup of tea.

  • Using Windows Vista on mac through VMWARE, but no wirless internet conn

    Please help!!!
    I am unable to connect to the internet via windows on my mac through vmware
    mark

    Questions regarding VMWare go on the VMWare Community forums:
    http://communities.vmware.com/community/vmtn/desktop/fusion

  • How to reduce configuration cache file Quota size located in ( C:\Windows\ccmcache ) for all client from SCCM 2012 server

    How to reduce configuration cache file Quota size located in ( C:\Windows\ccmcache ) for all client from SCCM 2012 server
    Thanks in Advance
    NTRao

    Hi,
    There are numerous ways to change the cache size.
    You could deploy a vbscript to a collection of the devices.
    On Error Resume Next
    Dim UIResManager
    Dim Cache
    Dim CacheSize
    CacheSize=20000
    Set UIResManager = createobject("UIResource.UIResourceMgr")
    Set Cache=UIResManager.GetCacheInfo()
    Cache.TotalSize=CacheSize
    Or you could use a configuration item.
    http://blog.coretech.dk/heh/configuration-items-and-baselines-using-scripts-powershell-example/
    You can also use the right click tools by Now Micro on a collection, if all the servers are on this would be the easiest / quickest way.
    http://www.nowmicro.com/recast/right-click-tools/
    http://www.david-obrien.net/2013/02/how-to-configure-the-configmgr-client/
    select SMS_R_SYSTEM.ResourceID, SMS_R_SYSTEM.ResourceType, SMS_R_SYSTEM.Name, SMS_R_SYSTEM.SMSUniqueIdentifier, SMS_R_SYSTEM.ResourceDomainORWorkgroup, SMS_R_SYSTEM.Client from SMS_R_System where SMS_R_System.OperatingSystemNameandVersion like '%6.2%'
    https://msdn.microsoft.com/en-us/library/windows/desktop/ms724832%28v=vs.85%29.aspx?f=255&MSPPError=-2147217396

  • Windows 8.1 OSD supported with SCCM 2012 ?

    Windows 8.1 OSD supported with SCCM 2012

    CU3 only supports the following for 8.1
    ‘This update adds support for Windows 8.1-based client computers in Microsoft System Center 2012 Configuration Manager Service Pack 1. Windows 8.1 is added to the supported platform list for the following features:
    Software distribution
    Software update management
    Compliance Settings’
    For complete OSD support you must be running R2. Here's a great starter guide.
    http://www.scconfigmgr.com/2013/10/19/deploy-windows-8-1-with-configmgr-2012-r2/
    Cheers
    Paul | sccmentor.wordpress.com
    OSD of Windows 8.1 is fully supported on SCCM 2012 SP1 CU3.
    More info: http://blogs.technet.com/b/configmgrteam/archive/2013/10/21/how-to-enable-windows-8.1-deployment-in-sc-2012-configmgr-sp1-cu3.aspx
    Ronni Pedersen | Microsoft MVP - ConfigMgr | Blogs:
    www.ronnipedersen.com/ and www.SCUG.dk/ | Twitter
    @ronnipedersen

  • Security Update for Windows 7 (KB2667402) downloaded through Windows Update, but cannot be installed!

    Security Update for Windows 7 (KB2667402) downloaded through Windows Update, but cannot be installed!
    OS:
    Windows  7 Home Premium, SP1, 32-bit
    Windows Update-Error 8024200d
    Microsoft Fix it ”Fix the problem with Microsoft Windows Update that is not working” was no use!
    The patch "Windows6.1-KB2667402-v2-x86.msu" downloaded directly, but
    could not be installed!
    System Update Readiness tried, but no use!
    PC Tools Security Product disabled, but no use!
    cmd.exe tried, but no use! 
    Microsoft Support through phone, but no use!
    So, what to do now?

    delete this subkey
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp
    and run check for update
    http://support2.microsoft.com/kb/2667402/en-us
    or please check that the download hasn't already been installed - look in the Installed Updates listing for an entry
    If it exists there, uninstall it, and then force a Check For Updates, and retry the install

  • 6735s -- Windows Hard Drive boot through Cd drive connection?

    I recently broke my sata interface on my 6735s laptop motherboard while installing a new hard drive
    Now instead of buying a new motherboard I'm thinking of buying a hd caddy and by taking out my cd/dvd drive and fitting the hard drive through the optical interface on the motherboard
    If i have windows installed on this hard drive and by booting the machine up with the hard drive connected this way, will the laptop boot up into windows without any problems, through this procedure?
    Any solutions to my question will be greatly appreciated

    Put the seagate drive onto the Mac and format it Mac OS extended journaled. (HFS+ for short) and you will also need to change the partition over to GUID from MBR.
    TC has very limited formats it can recognise.. FAT32 and HFS+ (well FAT16 but that doesn't count). exfat no, ntfs no, Really with FAT32 being hopeless.. you have one choice .. HFS+.
    The Windows machines can handle files to the drive just fine.. because it is a network drive.. it is offered to the network as SMB protocol.. in windows it will look like NT server. The precise format of the drive is irrelevant and is handled by the firmware of the TC.
    But do reset the partition scheme to GUID.. not MBR.
    http://support.apple.com/kb/ph5845
    You can even put 2 or more partitions on it.. but only one is fine.

  • I have take pictures from my ipad 4. How to download to my computer with windows operating system conneted through USB cable with out using internet

    I have take pictures from my ipad 4. How to download to my computer with windows operating system conneted through USB cable with out using internet

    Plug your iPad into your computer. THere may be a delay while it installs drivers but if you can see your iPad in windows explorer, use that to get to your photos.
    Click on your iPad and you should see a DCIM folder. Click thorugh that to find your photos.
    Windows explorer will see your iPad as nothing more than a digital camera, and that's the part you're trying to access.

  • Upload Images and PDFs into MDM through UI

    Hi All,
    I have a requirement where in we need to perform a mass upload of Images and PDFs into the respective tables of MDM through a UI.
    It is like, I browse the files through UI and click on Upload button, all those Images and PDFs should be uploaded in MDM.
    Is this a possible scenario? I have searched through sdn but could find no information pertaining to it.
    Please let me know if this is a possible scenario and provide some links to any documents related to it.
    TIA,
    Sravan

    upload of images and pdfs are dome from the data manager in MDM.
    ideally whatever u do in the DM is possible to be achieved by using the MDM APIs.
    so in ur UI (Webdynpro/ Java) u should call the APIsfor upload to the respective tables and its very much possible.
    check the MDM API list for more details.
    thanks
    -Adrivit

  • Troubleshooting InTune, SCCM, and Windows 8.1 Phones

    Howdy...
    I've setup various components but when I use my Windows 8.1 Samsung phone "Workplace Account" feature, the phone gets stuck on "We're looking for your settings...", it will stay on this for 15+mins if I let it.
    What can I do for further troubleshooting?
    Here are my components used:
    InTune Trail Subscription
    Verified to use my public domain via the custom TXT DNS record
    UPN settings configured (UPN = public email format = [email protected])
    Single Sign On into InTune admin console and user portal configured via ADFS
    Logon tests from a PC are successful internally and externally into the admin console and user portal
    Used DirSync on Win2012r2 to sync my AD to the Azure cloud - works fine
    ADFS servers (and DirSync) on 2012r2
    ADFS Web Application Servers on 2012r2
    System Center Configuration Manager has Intune Subscription configured
    System Center Configuration Manager ha the trail certificate, InTunes role installed, and distro.point set to manage.microsoft.com, and trail apps that came with trail certificate
    ...note sure if I've forgotten anything - definitely not the easiest thing to get working!!
    I've also done a packet capture from the firewall - they (firewall company) have ruled out their device as the problem.
    I've been using a few URLs to help,
    this is one of them

    The Microsoft Intune team has confirmed this was an issue.  The temp solution was to disable a checkbox in my ADFS server...  In a few weeks I will call back on my ticket and see if there is a better solution, otherwise this is the only thing I
    could do.
    ADFS Server > ADFS Console > Authentication Policies
    Global Settings > Edit
    Primary Tab > Uncheck "Enable Device Authentication"
    Microsoft Tech Support Comment:
    I am confirming the only known solution, which is a short term workaround being suggested by the PG/engineering, which is to Disable device auth properties check box on ADFS side.
    The long term solution is already well underway and in testing by the Product team and should be released in the upcoming weeks. 
    Public facing documentation for this issue should be available soon but we do not have a specific date.

  • Intune, SCCM, EAS Clarification

    Hi All,
    I'm trying to understand the expected behaviour in the scenario below:
    Say we have UDM with SCCM and Intune, we enrol a new device for a user, they get the security policy defined in SCCM with the email profile and can access EAS with the security policy the business has defined.
    What's to stop the user just enrolling the device directly in EAS and circumventing the remainder of the security policy that is defined in SCCM? Or does in not work like that? Does the Exchange SCCM (or Intune) connector mean that SCCM knows about the device
    and applies the policy irrespective of whether it has been enrolled through the company portal or directly in EAS?
    Thanks.

    It's called "Conditional Access Policy" and will be available in the next Intune release (Q4 of 2014 for Intune, probably Q1 of 2015 for SCCM/Intune Extension). You can read about it here
    http://blogs.technet.com/b/windowsintune/archive/2014/05/12/what-s-coming-next-with-windows-intune.aspx
    Gerry Hampson | Blog:
    www.gerryhampsoncm.blogspot.ie | LinkedIn:
    Gerry Hampson | Twitter:
    @gerryhampson

Maybe you are looking for