{"id":1617,"date":"2025-10-26T21:39:14","date_gmt":"2025-10-26T21:39:14","guid":{"rendered":"https:\/\/www.ultrexstaff.com\/?p=1617"},"modified":"2025-10-26T21:39:14","modified_gmt":"2025-10-26T21:39:14","slug":"entra-and-intune-research-notes","status":"publish","type":"post","link":"https:\/\/www.ultrexstaff.com\/?p=1617","title":{"rendered":"Entra and Intune Research Notes"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Entra and Intune Research Notes<\/h3>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<p>What I need to know:<\/p>\n\n\n\n<p>What do I gain security wise on MS365 premium and how do I make it happen?<\/p>\n\n\n\n<p>Entra vs intune, and what does the oobe do instead of enrollment?<\/p>\n\n\n\n<p>ALL 24H2<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T1- no network connection, default key.<\/p>\n\n\n\n<p>Logged in as local user<\/p>\n\n\n\n<p>Went to work or school account page, used main button, then main box<\/p>\n\n\n\n<p>Logged in, then rebooted computer<\/p>\n\n\n\n<p>Device is now enrolled in ENTRA, and after a few extra minutes, intune as well<\/p>\n\n\n\n<p>DOES show up in defender portal<\/p>\n\n\n\n<p>Does not allow you to log in to machine as company user<\/p>\n\n\n\n<p>Edge does Sync auto- no login needed<\/p>\n\n\n\n<p>Start menu is updated to company<\/p>\n\n\n\n<p>Onedrive not auto logged in, but I signed in<\/p>\n\n\n\n<p>Activation is still not active &#8211; relies on device key, not taking from MS365 license<\/p>\n\n\n\n<p>So very clearly this method gives the company control, but it\u2019s still your device, your users, and your<\/p>\n\n\n\n<p>Windows licensing<\/p>\n\n\n\n<p>RESULT :<\/p>\n\n\n\n<p>This is likely the best option for BYOB Organizations<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T2- no network connection, default key<\/p>\n\n\n\n<p>Went to join to work or school, main connect button, and then clicked option to join Entra bottom of that<\/p>\n\n\n\n<p>box.<\/p>\n\n\n\n<p>Initially login is still main user (local account)<\/p>\n\n\n\n<p>Adding onedrive- first login still required PW\/MFA<\/p>\n\n\n\n<p>Left allow my org to manage this device checked<\/p>\n\n\n\n<p>After this: edge has my account, no login required.<\/p>\n\n\n\n<p>Word\/office is logged in auto<\/p>\n\n\n\n<p>Windows not showing active, including still running pro<\/p>\n\n\n\n<p>Restart and sign in as Jim@Ultrex.com on login page<\/p>\n\n\n\n<p>Signing in as Jim@Ultrex- start menu still personal mode<\/p>\n\n\n\n<p>Rebooted- went back to local user as default<\/p>\n\n\n\n<p>Logged in with company email again<\/p>\n\n\n\n<p>Had to go to activation page, then click to log in again- now device shows proper on all activation settings<\/p>\n\n\n\n<p>In Intone and Entra dashboards- these two machines (oobe and this) appear fully equal on that front<\/p>\n\n\n\n<p>After a power down and turn back on, activation has popped out again and wants me to sign back in on<\/p>\n\n\n\n<p>the activation page<\/p>\n\n\n\n<p>Device IS on the defender premium page<\/p>\n\n\n\n<p>Further reboots still default to local user<\/p>\n\n\n\n<p>Logged in as Jim@Ultrex then deleted local user<\/p>\n\n\n\n<p>Still logs in as now deleted user by default.<\/p>\n\n\n\n<p>T oo Messy- Don\u2019t like this option<\/p>\n\n\n\n<p>RESULT :<\/p>\n\n\n\n<p>If someone has an existing user, and doesn\u2019t want to start over with a new user profile, they can join Entra<\/p>\n\n\n\n<p>and Intune, and just leave their current user. When they want to log into the device as an email, they\u2019ll<\/p>\n\n\n\n<p>need to reload\/lose the current user profile<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T3- Still on OOBE. Untouched post-install<\/p>\n\n\n\n<p>Runs oobebypassnro and login with a local offline user<\/p>\n\n\n\n<p>Plug machine into network post loading in<\/p>\n\n\n\n<p>MS store- company portal<\/p>\n\n\n\n<p>Log in, and leave \u201clet company manage this device checked)<\/p>\n\n\n\n<p>Device shows up in Entra Dashboard<\/p>\n\n\n\n<p>Search box is company<\/p>\n\n\n\n<p>Edge is logged in, no auth needed, bookmarks ext etc all there<\/p>\n\n\n\n<p>Device now shows up in intune as well. BEFORE onedrive login (maybe 5 minutes)<\/p>\n\n\n\n<p>Onedrive signs in, auth required<\/p>\n\n\n\n<p>Still local user<\/p>\n\n\n\n<p>Sign out<\/p>\n\n\n\n<p>OOBEd again, going back to OOBE enviro<\/p>\n\n\n\n<p>Can\u2019t re-enroll the device, fails on OOBE so would need wiped and reloaded at this point<\/p>\n\n\n\n<p>Based on later findings, I could have deleted from the panel for Entra and Intune, and Joined again.<\/p>\n\n\n\n<p>Even without that- DID show up in Defender portal for security- doesn\u2019t need email login for security<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T4- Logging in with MS365 account from main oobe page (installed pro in the first place)<\/p>\n\n\n\n<p>Very first login, start menu is Ultrex tied (company logo search etc)<\/p>\n\n\n\n<p>Initial one drive sign in needed no pw<\/p>\n\n\n\n<p>Edge was pre logged into my account<\/p>\n\n\n\n<p>Edge was signed into outlook.com from my very first opening. No MFA, No anything<\/p>\n\n\n\n<p>RESULT :<\/p>\n\n\n\n<p>No surprise- if you can do OOBE on pro in the first place, the world is an infinitely better place<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T8 &#8211; windows 24H2 Home installed fresh<\/p>\n\n\n\n<p>Local user, 11 Home<\/p>\n\n\n\n<p>Accounts\/COnnect to work account, main option<\/p>\n\n\n\n<p>Log in as me<\/p>\n\n\n\n<p>Device is enrolled in Entra<\/p>\n\n\n\n<p>Device shows up in intune<\/p>\n\n\n\n<p>T ook offline, used 3v66t key and upgraded to pro<\/p>\n\n\n\n<p>Gave back network conection<\/p>\n\n\n\n<p>OOBE\/Sysprep can\u2019t generalize<\/p>\n\n\n\n<p>Ran Normal OOBE<\/p>\n\n\n\n<p>Set up for work or school, but can\u2019t because the device is already enrolled<\/p>\n\n\n\n<p>Can go into intune and Entra and delete the device from both dashboards, then click try again<\/p>\n\n\n\n<p>no sooner than 60 seconds later<\/p>\n\n\n\n<p>Onedrive automatic (No auth needed), edge sync auto, start menu company<\/p>\n\n\n\n<p>Device shows in Intune and Entra perfectly<\/p>\n\n\n\n<p>Defender not showing up? (see note below)<\/p>\n\n\n\n<p>ACTIVATION STATUS: PERFECTION DAMMIT<\/p>\n\n\n\n<p>This works!<\/p>\n\n\n\n<p>RESULT :<\/p>\n\n\n\n<p>If someone has a machine on home, you can join it to Entra and Intune, and then only upgrade<\/p>\n\n\n\n<p>to pro if they need it for some other reason, and if they do need to upgrade to pro, you\u2019ll have to<\/p>\n\n\n\n<p>go delete the device from intune and entra dashbpoards. If you do that, then all works well<\/p>\n\n\n\n<p>\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014<\/p>\n\n\n\n<p>T9<\/p>\n\n\n\n<p>Windows 11 Home<\/p>\n\n\n\n<p>DIDN\u2019T join to company Entra or Intune before upgrading<\/p>\n\n\n\n<p>Just local user, logged in, upgraded using 3v66t code (like a new purchase)<\/p>\n\n\n\n<p>Gave back network connection<\/p>\n\n\n\n<p>Can\u2019t generalize<\/p>\n\n\n\n<p>Just ran main sysprep<\/p>\n\n\n\n<p>On next bootup, chose set up for work or school, works perfect, logs in as email, and is<\/p>\n\n\n\n<p>company controlled<\/p>\n\n\n\n<p>Signing in to onedrive is fully auto- no pw or MFA needed<\/p>\n\n\n\n<p>Search box is company info<\/p>\n\n\n\n<p>Edge is synced auto<\/p>\n\n\n\n<p>Device shows in Intune and Entra perfectly<\/p>\n\n\n\n<p>Defender not showing up (see note below)<\/p>\n\n\n\n<p>ACTIVATION STATUS: PERFECTION DAMMIT<\/p>\n\n\n\n<p>Note from MS:<\/p>\n\n\n\n<p>Windows 11 Home devices that have been upgraded to one of the below supported editions<\/p>\n\n\n\n<p>might require you to run the following command before onboarding:<\/p>\n\n\n\n<p>DISM \/online \/Add-Capability \/CapabilityName:Microsoft.Windows.Sense.Client~~~~<\/p>\n\n\n\n<p>. For more information about edition upgrades and features, see Features)<\/p>\n\n\n\n<p>Was able to confirm that in OS\u2019s upgraded from home, you can run this command, it had a 50%<\/p>\n\n\n\n<p>success rate across 4 identical VM\u2019s. (literally clones of each other). Even on the ones where it<\/p>\n\n\n\n<p>ran, it did not bring them into defender management. SO our new default is use Entra and<\/p>\n\n\n\n<p>Intune if that\u2019s what\u2019s wanted- and you can leave it on HOME. But if you want pro, just freaking<\/p>\n\n\n\n<p>install Pro in the first place. I\u2019ve also now updated an ISO of 24H2 so it will ALWAYS ask for the<\/p>\n\n\n\n<p>key, AND let you not put a key, and still select what version of windows to install clean (even if<\/p>\n\n\n\n<p>one is saved in the EFI or BIOS). From now on, we use that one, please update your ventoy<\/p>\n\n\n\n<p>soon as possible.<\/p>\n\n\n\n<p>Final Notes:<\/p>\n\n\n\n<p>Company portal app is enrolling device in entra\/intune<\/p>\n\n\n\n<p>Entra and intune can both be done with windows home<\/p>\n\n\n\n<p>Entra is access to stuff based on identity<\/p>\n\n\n\n<p>Intune is device management<\/p>\n\n\n\n<p>Defender portal is weak, and not worth much- but only comes on clean, initial W11 Pro installs.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Entra and Intune Research Notes What I need to know: What do I gain security wise on MS365 premium and how do I make it happen? Entra vs intune, and what does the oobe do instead of enrollment? ALL 24H2 \u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014\u2014 T1- no network connection, default key. Logged in as local user Went to work [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[116],"tags":[],"class_list":["post-1617","post","type-post","status-publish","format-standard","hentry","category-intune-and-entra","post-preview"],"_links":{"self":[{"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/1617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1617"}],"version-history":[{"count":1,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/1617\/revisions"}],"predecessor-version":[{"id":1618,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=\/wp\/v2\/posts\/1617\/revisions\/1618"}],"wp:attachment":[{"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ultrexstaff.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}