Microsoft Intune Lab

A lab environment for testing Windows device management with Microsoft Intune: enrollment, configuration and compliance policies, and app deployment.

  • Status: In progress
  • Lab project
  • Concept

Overview

A separate Microsoft 365 test tenant with a small number of Windows virtual machines, used to practise the full device lifecycle in Intune: enrollment, configuration, compliance, application deployment and retirement.

Problem / Objective

  • Practise Intune configuration end to end without touching a production tenant.
  • Understand how enrollment method (Autopilot, manual Entra join) affects what policies apply and when.
  • Build a repeatable baseline: configuration profiles, compliance policies and a small set of apps.
  • Use PowerShell and Microsoft Graph to read and report on device state instead of clicking through the portal.

Architecture

  1. Hyper-V / Proxmox VMWindows 11 Pro/Enterprise
  2. Windows AutopilotHardware hash registered
  3. Microsoft Entra IDEntra join, dynamic device group
  4. Microsoft IntuneProfiles, compliance, apps
  5. ReportingPowerShell + Microsoft Graph
Concept — planned device flow in the lab tenant
Tenant
Dedicated test tenant (not connected to any employer environment)
Devices
Windows 11 virtual machines
Join type
Microsoft Entra join (cloud-only)
Groups
Dynamic device groups based on Autopilot group tag

Implementation

  1. Create the test tenant and assign Intune and Entra ID P1 licences to test users.
  2. Set MDM user scope for automatic enrollment.
  3. Collect the hardware hash from each VM and import it into Windows Autopilot.
  4. Create a dynamic device group for Autopilot devices with a group tag.
  5. Create an Autopilot deployment profile and an Enrollment Status Page.
  6. Assign configuration profiles, compliance policies and apps to the device group.
  7. Enroll a VM, then verify policy and app status in Intune and on the device.
powershell
# Run as administrator on the Windows VM
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned -Force
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -OutputFile C:\Temp\autopilot-hash.csv
Example — collecting the Autopilot hardware hash on a lab VM
text
(device.devicePhysicalIds -any (_ -eq "[OrderID]:LAB-WIN"))
Example — dynamic membership rule for devices with a group tag

Configuration

Compliance
BitLocker required, minimum OS version, firewall on, Defender antivirus on
Configuration
Settings catalog: BitLocker, Windows Update rings, OneDrive Known Folder Move
Endpoint security
Antivirus and firewall profiles
Apps
Microsoft 365 Apps, one Win32 app (.intunewin) with detection rule
Updates
Two update rings: pilot and broad

Troubleshooting

Diagnostic sources used during the lab. Real issues encountered will be documented here with cause and fix.

  • Intune admin center: device → Device configuration / Compliance / Managed apps status
  • Event Viewer: Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin
  • Settings → Accounts → Access work or school → Info → Sync (forces a check-in)
  • IntuneManagementExtension logs for Win32 apps and scripts: C:\ProgramData\Microsoft\IntuneManagementExtension\Logs
  • mdmdiagnosticstool.exe to export an MDM diagnostic report

No issues documented yet.

Security considerations

  • Separate tenant and separate admin accounts; no personal or employer data in the lab.
  • Role-based access in Intune instead of Global Administrator for daily work.
  • Microsoft Graph scripts use the smallest scopes needed (read-only where possible).
  • No secrets committed to Git; app registrations use certificates or are deleted after testing.

Lessons learned

To be written once the lab stages are completed.

Screenshots / Diagrams

Screenshots will be added as the lab progresses. Tenant IDs and names will be redacted.

Back to all projects