Microsoft Intune Lab
A lab environment for testing Windows device management with Microsoft Intune: enrollment, configuration and compliance policies, and app deployment.
- Status: In progress
- Lab project
- Concept
Overview
A separate Microsoft 365 test tenant with a small number of Windows virtual machines, used to practise the full device lifecycle in Intune: enrollment, configuration, compliance, application deployment and retirement.
Problem / Objective
- Practise Intune configuration end to end without touching a production tenant.
- Understand how enrollment method (Autopilot, manual Entra join) affects what policies apply and when.
- Build a repeatable baseline: configuration profiles, compliance policies and a small set of apps.
- Use PowerShell and Microsoft Graph to read and report on device state instead of clicking through the portal.
Architecture
- Hyper-V / Proxmox VMWindows 11 Pro/Enterprise
- Windows AutopilotHardware hash registered
- Microsoft Entra IDEntra join, dynamic device group
- Microsoft IntuneProfiles, compliance, apps
- ReportingPowerShell + Microsoft Graph
- Tenant
- Dedicated test tenant (not connected to any employer environment)
- Devices
- Windows 11 virtual machines
- Join type
- Microsoft Entra join (cloud-only)
- Groups
- Dynamic device groups based on Autopilot group tag
Implementation
- Create the test tenant and assign Intune and Entra ID P1 licences to test users.
- Set MDM user scope for automatic enrollment.
- Collect the hardware hash from each VM and import it into Windows Autopilot.
- Create a dynamic device group for Autopilot devices with a group tag.
- Create an Autopilot deployment profile and an Enrollment Status Page.
- Assign configuration profiles, compliance policies and apps to the device group.
- Enroll a VM, then verify policy and app status in Intune and on the device.
# Run as administrator on the Windows VM
Set-ExecutionPolicy -Scope Process -ExecutionPolicy RemoteSigned -Force
Install-Script -Name Get-WindowsAutopilotInfo -Force
Get-WindowsAutopilotInfo -OutputFile C:\Temp\autopilot-hash.csv(device.devicePhysicalIds -any (_ -eq "[OrderID]:LAB-WIN"))Configuration
- Compliance
- BitLocker required, minimum OS version, firewall on, Defender antivirus on
- Configuration
- Settings catalog: BitLocker, Windows Update rings, OneDrive Known Folder Move
- Endpoint security
- Antivirus and firewall profiles
- Apps
- Microsoft 365 Apps, one Win32 app (.intunewin) with detection rule
- Updates
- Two update rings: pilot and broad
Troubleshooting
Diagnostic sources used during the lab. Real issues encountered will be documented here with cause and fix.
- Intune admin center: device → Device configuration / Compliance / Managed apps status
- Event Viewer: Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin
- Settings → Accounts → Access work or school → Info → Sync (forces a check-in)
- IntuneManagementExtension logs for Win32 apps and scripts: C:\ProgramData\Microsoft\IntuneManagementExtension\Logs
- mdmdiagnosticstool.exe to export an MDM diagnostic report
No issues documented yet.
Security considerations
- Separate tenant and separate admin accounts; no personal or employer data in the lab.
- Role-based access in Intune instead of Global Administrator for daily work.
- Microsoft Graph scripts use the smallest scopes needed (read-only where possible).
- No secrets committed to Git; app registrations use certificates or are deleted after testing.
Lessons learned
To be written once the lab stages are completed.
Screenshots / Diagrams
Screenshots will be added as the lab progresses. Tenant IDs and names will be redacted.