Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune

Now that we have configured the Exchange 2016 Office 365 hybrid setup and are able to successfully migrate mailboxes we need a way for users to securely access their Office 365 mail and other services from their mobile devices.  To do this we need to setup and configure Microsoft Intune.

We were actually migrating users from VMware’s Airwatch to Microsoft Intune.  Before we could migrate them we had to do the below to get Intune working correctly.  All of the settings below can be customised according to your own setups, I have just laid out a basic framework that will get Intune up and running and keep it secure.

Conditional Access

In order for mobile users to be able to use Intune and connect to Office 365 we first had to make some amendments to the Conditional Access policy.  I changed the original policy that only allows access to MyCompany IP addresses from All platforms to Windows and macOS machines. This was so that I could set a different access policy for mobile devices.

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-2




I then created a new access policy called Grant Mobile Access and changed the condition so that only Android, IOS and Windows phone devices could connect.

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-3

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-4

Under Access controls we set the policy to grant access if the device is marked as compliant.

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-5

Compliance Policy

To create a compliance policy for your devices open the Intune portal and go to Device Compliance – Policies and click create Policy:

Compliance Policy To create a compliance policy for your devices open the Intune portal and go to Device Compliance – Policies and click create Policy:




Give the policy a name and a description.

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-7

Configure as follows:

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-8

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-9

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-10





Configure System Security as follows:

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-11

Actions for non compliance

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-12

 

We leave the Assignments set to All Users

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-13

To check device compliance open Intune>Device Compliance>Device Compliance

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-14




Managing Applications

To add an app go to Intune>Client apps>Apps>Add

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-15

To add Outlook change the app store to UK and search the App store for Outlook

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-16

Configure Outlook as follows:

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-17

Click Assignments and set the requirement type as Required and it will be installed automatically

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-18

App protection policies

Open Intune and go to Client Apps> App protection policies

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-19

Click add a policy and give it a name, leave target to all app types

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-20




Select Assignments and choose which groups you want to include.  You can setup AD groups on your on-premise AD servers and sync them to Azure for this.

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-21

Select the apps that you want to target with the policy:

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-22

Configure the policy settings as below:

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-23

Migrating to Office 365 from Microsoft Exchange Step By Step – Stage 6 Configuring Intune-24




Leave a Reply

Your email address will not be published. Required fields are marked *