Tag - Microsoft 365 Enterprise

The evolution of small business networks

I believe there are only three basic types of networks alive in the small and mid-sized business market today.* Legacy, Hybrid and Modern. Now the labeling on these categories is purposeful--the language represents a progression in time, but it is important to remember that there still exist "legacy" environments, just...
Read more...

Give extra Consideration before implementing WIP (Windows 10 App protection policies)

In Microsoft 365 plans it is possible to configure application protection policies for Android, iOS and Windows 10, right from the 365 Admin center under Devices > Policies. Once built, these correspond to policies that you can find within the Intune / Device management portal under Client apps > App...
Read more...

My favorite Conditional Access Policies for the SMB

It's not even a question in my mind anymore--every org who moves their email and other data sets into Office 365 should be protected with Enterprise Mobility + Security (also available in Microsoft 365 Enterprise plans). If you are in the Business subscription of Microsoft 365, this means adding Azure...
Read more...

Super-charging security on non-Microsoft 365 E5 plans

This article was updated in April of 2020 Microsoft 365 E5 is the Cadillac of plans. Basically every product in the 365 universe is bundled into this level subscription, and that includes a ton related to security. Recently, Microsoft announced two new bundles aimed at security & compliance. The idea behind these...
Read more...

Add-ons that are NOT compatible with Microsoft 365 Business (yet)

Update 3/9/2019: I had to update this article. I am moving some former content on Identity & Threat Protection to its own article, and expanding on it there. Microsoft 365 Business is a fantastic value, and contains most of what we would like to see in a small business subscription. However,...
Read more...

Office 365 Advanced Threat Protection Plan 2

Recently, Microsoft changed up some of the SKU's relating to security & compliance out in the Microsoft/Office 365 universe. As part of these announcements, they renamed Office 365 Advanced Threat Protection (ATP) to Office 365 ATP Plan 1. Then, to create Office 365 ATP Plan 2, they simply bundled Plan...
Read more...

What are the benefits of using Autopilot in Microsoft 365? And, how to configure it.

Autopilot is a "low touch" or "no touch" deployment method that can be leveraged by IT departments to enable self-service computer deployments. Users can basically pick up a new Windows 10 device, sign in, and have all of their applications and data come to them (no profile migration, etc. required). But...
Read more...

Navigating Device management in Microsoft 365: Registered vs. Joined vs. Hybrid Joined… and Intune

Device management is not a straightforward thing in Azure AD.  I think that one major point of confusion for people is understanding the difference between various device states--for example, what is the difference between a device which is merely registered with Azure AD, versus one that is actually Azure AD...
Read more...

How to require MFA for Azure AD Join, and enable Enterprise State Roaming

Hey folks! We have already covered a few posts on Azure AD Premium and Conditional access; and that's great--because you do things like enforce requirements like Multi-factor Auth, but only in situations where devices are unmanaged. This provides a way better user experience than enabling MFA across the board, and without...
Read more...

Helping IT Consultants Succeed in the Microsoft Cloud

Have a Question? Contact me today.