15Jan2019
14Jan2019
Protect messages and documents in Microsoft 365 Business with AIP, part 2: AIP labels
Azure Information Protection (AIP) uses “labels” to classify and protect data. Labels are published to end users for eventual consumption and use through a “policy.” In the olden days, applying permissions and restricting access to files was more rudimentary—again, it was based on the concept of the “four walls.” We would erect...
19Dec2018
Why Microsoft 365 Business should include Azure AD Premium
I have written at length about this product; for the most part, I really love it for the SMB. But there is one thing that I wish Microsoft would have included in this bundle, even if it meant increasing the price point a little bit. And that one thing is:...
12Dec2018
Navigating Device management in Microsoft 365: Registered vs. Joined vs. Hybrid Joined… and Intune
Device management is not a straightforward thing in Azure AD. I think that one major point of confusion for people is understanding the difference between various device states--for example, what is the difference between a device which is merely registered with Azure AD, versus one that is actually Azure AD...
03Dec2018
How to require MFA for Azure AD Join, and enable Enterprise State Roaming
Hey folks! We have already covered a few posts on Azure AD Premium and Conditional access; and that's great--because you do things like enforce requirements like Multi-factor Auth, but only in situations where devices are unmanaged. This provides a way better user experience than enabling MFA across...
29Nov2018
Leveraging Conditional Access to enforce either MDM or MAM–user’s choice
In some circumstances, you might want users to have their choice: Use the native mail apps and have their mobile devices managed via Intune MDM, OR, Use a managed application such as Outlook on their own personal devices, and opt out of full device management. The catch is, they must go...
21Nov2018
How to enforce the use of managed applications (e.g. the Outlook app for Exchange Online) using Conditional Access in Azure AD Premium
In a previous post I demonstrated how easy it is to create a Mobile Application Management policy in Microsoft 365. With the addition of Azure AD Premium P1, we can also leverage Conditional Access polices that will require users to interact with corporate data through the Microsoft applications such as...
20Nov2018