How to Setup Azure AD Company Branding

In this post, I’ll shows how to setup Azure AD company branding options. You can se your organization’s logo and custom color schemes to provide a consistent look-and-feel on your Azure Active Directory.

Add Company Branding

Prerequisites: The user account requires Azure Active Directory Premium 1 or Premium Licenses.

Step 1: Connect to Azure Active Directory admin center (https://aad.portal.azure.com)

Step 2: Navigate to Azure Active Directory -> Company branding and select to Configure icon to Configure / Edit Company branding

How to Setup Azure AD Company Branding
How to Setup Azure AD Company Branding

Step 3: Click Configure or Edit the branding configuration and provide the information as show in the screenshot below and Save.

Note: The language is automatically set as your default language based on the Azure subscription setup and it can’t be changed. However, you can configure additional languages by select the New Language option.

How to Setup Azure AD Company Branding
How to Setup Azure AD Company Branding

Step 4: The Company branding page is saved in Azure Active Directory

How to Setup Azure AD Company Branding
How to Setup Azure AD Company Branding

Step 5: After you’ve created the Custom branding, you can access the page by https://login.microsoftonline.com/<domain name>

How to Setup Azure AD Company Branding 1
How to Setup Azure AD Company Branding

Resources

Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

In this post, you learn to Configure MDM authority & user scope configuration who can enroll their devices into Intune. If you have not read my previous posts, I recommend reading the following posts to get a full understanding of the Intune guide.

Prerequisites

The below Prerequisites are required to enroll the Windows 10 devices:

  • Intune enabled as the MDM authority
  • Windows 10 1703 and above for testing
  • EMS E3 licenses (or at the very least Intune and Azure AD premium P1)

In this series of posts, I’m going to explain end to end process to build an Intune lab environment. It’s assumed that you already have a domain controller and all the on-prem servers. More details about building a domain controller here.

Enable MDM (Mobile Device Management)

From Tenants with 1911 service release, the MDM authority is enabled by default set to Intune

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

For pre-1911 service release tenants,

In the Microsoft Endpoint Manager admin center, select the orange banner to configure the MDM authority,

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 2
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 27

Select Intune MDM Authority

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Configuring Intune MDM User Scope and MAM User Scope

To configure your MDM and MAM user scope go to,

Login into https://portal.azure.com/ -> Navigate Azure Active Directory

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

In the left-hand panel, select the Mobility (MDM and MAM) and open the Microsoft Intune

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope
  • In MDM user scope tab,
  • Enable the Some in MDM user scope
  • To select the Intune user groups, click  No Group selected,
  • Select the Intune User security Group (I have created the Azure security group to add Users to be part of Intune enrollment)
  • Click Select the Azure security Group
  • Click Save the settings
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope
  • In MAM user scope tab,
  • Enable the Some in MAM user scope
  • To select the Intune user groups, click  No Group selected,
  • Select the Intune User security Group (I have created the Azure security group to add Users to be part of Intune enrollment)
  • Click Select the Azure security Group
  • Click Save the settings
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Configuration has been saved successfully

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

In the left-hand panel, select the Mobility (MDM and MAM) and open the Microsoft Intune Enrollment

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope
  • In Microsoft Intune Enrollment tab,
  • Enable the Some in MDM user scope
  • To select the Intune user groups, click  No Group selected,
  • Select the Intune User security Group (I have created the Azure security group to add Users to be part of Intune enrollment)
  • Click Select the Azure security Group
  • Click Save the settings
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Configuration has been saved successfully

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Windows 10 Enrollment

Add the out of box Windows 10 device into Azure AD

Enter the User name , Click Next

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Enter the password of Domain account and click Next

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Device configuration is in progress

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 3
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 28

Click Yes to continue the device setup

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 4
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 29

Windows 10 device is joined to Azure AD, using Settings verify the user account information

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 5
Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope 30

The device is Azure AD joined, MDM is compliant

Intune Guide Post 3 - Configure MDM Authority User Scope MAM User Scope
Intune Guide Post 3 – Configure MDM Authority User Scope MAM User Scope

Reference:

Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler

In this post, we are explaining the Installation and configuration of the Azure AD Connect (AAD sync scheduler) to an on-premise Domain to manage the Windows 10 devices. To enable the Co-management feature, the Windows 10 devices to be connected to Hybrid Azure AD joined or directly joined to AAD.

In this series of posts, I’m going to explain end to end process to build an Intune lab environment. It’s assumed that you already have a domain controller and all the on-prem servers. More details about building a domain controller here.

Introduction

ADSyncScheduler is Azure AD connect component to synchronize the changes occurring in on-premise active directory. The Scheduler configurations are saved in Azure AD.

The scheduler will perform the

  1. Password Sync
  2. Object/Attribute Sync and maintenance task

How to check the Scheduler configuration

Run the PowerShell command Get-ADSyncScheduler to view the current configuration in the environment.

Intune Guide Post 2 - ADD Connect Sync ADSyncScheduler
ADSyncScheduler – Intune Guide Post 2 – ADD Connect Sync ADSyncScheduler
  • AllowedSyncCycleInterval. The shortest time interval between synchronization cycles allowed by Azure AD. You cannot synchronize more frequently than this setting and still be supported.

Default sync time is 30 minutes

  • CurrentlyEffectiveSyncCycleInterval. The schedule currently in effect. It has the same value as CustomizedSyncInterval (if set) if it is not more frequent than AllowedSyncInterval. If you use a build before 1.1.281 and you change CustomizedSyncCycleInterval, this change takes effect after next synchronization cycle. From build 1.1.281 the change takes effect immediately.

Default sync time is 30 minutes

  • CustomizedSyncCycleInterval. If you want the scheduler to run at any other frequency than the default 30 minutes, then you configure this setting. In the picture above, the scheduler has been set to run every hour instead. If you set this setting to a value lower than AllowedSyncInterval, then the latter is used.
  • NextSyncCyclePolicyType. Either Delta or Initial. Defines if the next run should only process delta changes, or if the next run should do a full import and sync. The latter would also reprocess any new or changed rules.
  • NextSyncCycleStartTimeInUTC. Next time the scheduler starts the next sync cycle.
  • PurgeRunHistoryInterval. The time operation logs should be kept. These logs can be reviewed in the synchronization service manager. The default is to keep these logs for 7 days.
  • SyncCycleEnabled. Indicates if the scheduler is running the import, sync, and export processes as part of its operation.
  • MaintenanceEnabled. Shows if the maintenance process is enabled. It updates the certificates/keys and purges the operations log.
  • StagingModeEnabled. Shows if staging mode is enabled. If this setting is enabled, then it suppresses the exports from running but still run import and synchronization.
  • SchedulerSuspended. Set by Connect during an upgrade to temporarily block the scheduler from running.

The below example when AD connect Sync in progress

Intune Guide Post 2 - ADD Connect Sync ADSyncScheduler
Intune Guide Post 2 – ADD Connect Sync ADSyncScheduler

Important : When AD Connect sync in progress, you cannot make changes in AD connector Scheduler

Intune Guide Post 2 - ADD Connect Sync ADSyncScheduler
Intune Guide Post 2 – ADD Connect Sync ADSyncScheduler

How to manually Start the Scheduler

Using Start-ADSyncSyncCycle PowerShell command, you can initiate the Delta and Full Sync

  • To initiate Delta Sync PS command line : Start-ADSyncSyncCycle -PolicyType Delta

The following step for Delta Sync

  1. Delta import on all Connectors
  2. Delta sync on all Connectors
  3. Export on all Connectors
Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 6
Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 40
  • To initiate the Full sync PS command line : Start-ADSyncSyncCycle -PolicyType Initial

The following step for Full Sync

  1. Full Import on all Connectors
  2. Full Sync on all Connectors
  3. Export on all Connectors
Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 7
Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 41

Synchronization Service Manager GUI

The Synchronization server Manager GUI is available in

“%Program Files%\Microsoft Azure AD Sync\UIShell\miisclient.exe”

Using the GUI, the entire history of Sync data is updated in the tool.

Intune Guide Post 2 - ADD Connect Sync ADSyncScheduler
Intune Guide Post 2 – ADD Connect Sync ADSyncScheduler

The GUI tool has an options to initiate the Full or Delta Sync or import the objects from on premises directory.

Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 8
Intune Guide Post 2 | ADD Connect Sync | ADSyncScheduler 42

The Synchronization Statistics will be available once the sync task is completed

Intune Guide Post 2 - ADD Connect Sync ADSyncScheduler
Intune Guide Post 2 – ADD Connect Sync ADSyncScheduler

Resources

Intune Guide Post 1 – How to Install Configure Azure AD Connect

In this post, we are explaining the Installation and configuration of the Azure AD Connect (Install Configure Azure AD Connect) to an on-premise Domain to manage the Windows 10 devices. To enable the SCCM Co-management feature, the Windows 10 devices to be connected to Hybrid Azure AD joined or directly joined to AAD.

In this post, I’m going to explain end to end process to build an Intune in this blog post series. It’s assumed that you already have a domain controller and all the on-prem servers. More details about building a domain controller here.

Prerequisites

How to configure the Azure AD connect

  • Post-installation of Azure AD connect tool,
  • Launch the Microsoft Azure AD connect
Install Configure Azure AD connect
Install Configure Azure AD connect
  • Select I agree to the License terms and privacy notice
  • Click Continue
Install Configure Azure AD connect
Install Configure Azure AD connect

Select and click Use express settings

Intune Guide Post 1 - How to Install Configure Azure AD Connect 9
Intune Guide Post 1 - How to Install Configure Azure AD Connect 79
  • Enter the Username and Password of the Global Administrator ID
  • Click Next
Install Configure Azure AD connect
Install Configure Azure AD connect

Configuring is in progress…

Intune Guide Post 1 - How to Install Configure Azure AD Connect 10
Intune Guide Post 1 - How to Install Configure Azure AD Connect 80

Enter the Username and Password of the Enterprise Admin ID of local Active Directory Domain Service

Install Configure Azure AD connect
Install Configure Azure AD connect

Configuration is in progress…

Intune Guide Post 1 - How to Install Configure Azure AD Connect 11
Intune Guide Post 1 - How to Install Configure Azure AD Connect 81
  • Select Continue without matching all UPN suffixes to verified domains
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 12
Intune Guide Post 1 - How to Install Configure Azure AD Connect 82
  • Select Start the Synchronization process when configuration completes
  • Click Install
Intune Guide Post 1 - How to Install Configure Azure AD Connect 13
Intune Guide Post 1 - How to Install Configure Azure AD Connect 83

Configuring the Checking installation of Azure AD connect synchronization service

Intune Guide Post 1 - How to Install Configure Azure AD Connect 14
Intune Guide Post 1 - How to Install Configure Azure AD Connect 84

Configuring the Microsoft SQL Server Express LocalDB

Intune Guide Post 1 - How to Install Configure Azure AD Connect 15
Intune Guide Post 1 - How to Install Configure Azure AD Connect 85

Configuring the Synchronization Service

Intune Guide Post 1 - How to Install Configure Azure AD Connect 16
Intune Guide Post 1 - How to Install Configure Azure AD Connect 86

Configuring the Verifying synchronization service connectivity to Azure Active Directory

Intune Guide Post 1 - How to Install Configure Azure AD Connect 17
Intune Guide Post 1 - How to Install Configure Azure AD Connect 87

Configuring the Creating the Azure Active Directory Synchronization Account

Intune Guide Post 1 - How to Install Configure Azure AD Connect 18
Intune Guide Post 1 - How to Install Configure Azure AD Connect 88

Configuring the Updating synchronization rules of the AAD

Intune Guide Post 1 - How to Install Configure Azure AD Connect 19
Intune Guide Post 1 - How to Install Configure Azure AD Connect 89

Configuring the Domain (ann.com)

Intune Guide Post 1 - How to Install Configure Azure AD Connect 20
Intune Guide Post 1 - How to Install Configure Azure AD Connect 90

Configuring the Updating synchronization rules of the domain (ann.com)

Intune Guide Post 1 - How to Install Configure Azure AD Connect 21
Intune Guide Post 1 - How to Install Configure Azure AD Connect 91

Configuring the Updating partition information of the domain (ann.com)

Install Configure Azure AD connect
Install Configure Azure AD connect

Configuring the Password hash synchronization

Intune Guide Post 1 - How to Install Configure Azure AD Connect 22
Intune Guide Post 1 - How to Install Configure Azure AD Connect 92

Installing Azure AD connect health agent for sync

Intune Guide Post 1 - How to Install Configure Azure AD Connect 23
Intune Guide Post 1 - How to Install Configure Azure AD Connect 93

Configuration is completed

Click Exit

Install Configure Azure AD connect
Install Configure Azure AD connect

Review of audit logs during the Setup

Intune Guide Post 1 - How to Install Configure Azure AD Connect 24
Intune Guide Post 1 - How to Install Configure Azure AD Connect 94

Setup is completed successfully

Intune Guide Post 1 - How to Install Configure Azure AD Connect 25
Intune Guide Post 1 - How to Install Configure Azure AD Connect 95

How to Configure Hybrid AD Join or Azure A join

  • Launch the Microsoft Azure Active Directory Connect
  • Select Configure device options
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 26
Intune Guide Post 1 - How to Install Configure Azure AD Connect 96

Click Next

Intune Guide Post 1 - How to Install Configure Azure AD Connect 27
Intune Guide Post 1 - How to Install Configure Azure AD Connect 97
  • Enter the Azure cloud Username and password which has Global administrator role access
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 28
Intune Guide Post 1 - How to Install Configure Azure AD Connect 98

The username will be validated to connect to the Azure portal

Intune Guide Post 1 - How to Install Configure Azure AD Connect 29
Intune Guide Post 1 - How to Install Configure Azure AD Connect 99
  • Select Configure Hybrid Azure AD join
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 30
Intune Guide Post 1 - How to Install Configure Azure AD Connect 100
  • select Windows 10 or later domain-joined devices
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 31
Intune Guide Post 1 - How to Install Configure Azure AD Connect 101
  • In SCP configuration, Click Add to add the on-premise Domain
  • Click Next
Intune Guide Post 1 - How to Install Configure Azure AD Connect 32
Intune Guide Post 1 - How to Install Configure Azure AD Connect 102
  • Enter the on-premise Credentials which has Enterprise admin access
  • Click OK
Install Configure Azure AD connect
Install Configure Azure AD connect

Checking the installed components…

Intune Guide Post 1 - How to Install Configure Azure AD Connect 33
Intune Guide Post 1 - How to Install Configure Azure AD Connect 103

Click Configure to initiate the setup

Intune Guide Post 1 - How to Install Configure Azure AD Connect 34
Intune Guide Post 1 - How to Install Configure Azure AD Connect 104

Setup is completed, click Exit

Install Configure Azure AD connect
Install Configure Azure AD connect

Results – Install Configure Azure AD connect

On-premise domain joined computers are updated as Hybrid Azure AD joined in Azure ADD devices.

Intune Guide Post 1 - How to Install Configure Azure AD Connect 35
Intune Guide Post 1 - How to Install Configure Azure AD Connect 105

Resources

ConfigMgr Admin Tips | List of Views Tables Functions IP Address Views information by Karthick | SQL Query Tips | SCCM

This is the quick post to provide additional tips to ConfigMgr Admins (ConfigMgr Admin Tips) to find out the list of Views, Tables, Functions, and IP addresses view information. Special Thanks to Karthick for all the tips 👇👇!

All these points are discussed and demoed in the ConfigMgr SSRS Report Creation Process Explained by Kannan CS SQL Query Tips Tricks for Admins | Video.

List of Views Tables Functions for ConfigMgr

  • This 👇 query shows what views and table-value functions are supported
select * from sys.all_objects
select * from sys.all_objects where type = 'v'
ConfigMgr Admin Tips
List of Views Tables Functions for ConfigMgr – ConfigMgr Admin Tips
  • The Type will provide the detail information of each SQL information

Download Details of ConfigMgr 2002

Download Spreadsheet 👉👉https://github.com/AnoopCNair/SQL-sys.all_objects-SCCM-ConfigMgr

IP Address Views Information from SCCM

The following query will give you the the views which has IP address information related views from SCCM database.

select * from sys.views where name like '%IP%'
IP address information related views from SCCM database. - ConfigMgr Admin Tips
IP address information related views from SCCM database. – ConfigMgr Admin Tips

Boundary Related Views from SCCM ConfigMgr

select * from sys.views where name like '%boundary%'
Boundary Related Views from SCCM ConfigMgr
Boundary Related Views from SCCM ConfigMgr

Another tip – SQL Views ConfigMgr SCCM

select * from sys.views where name like '%client%'
select * from sys.views where name like '%clienthealth%'

Resources

ConfigMgr SSRS Report Creation Process Explained by Kannan CS SQL Query Tips Tricks for Admins | Video

I have conducted a How To Manage Device Community Weekend Teams Live meeting session to share my real-world experience of ConfigMgr SSRS report creation. I have been helping many of my clients to build custom SCCM reports. The recording is available in this post is available in the below section of the post.

Related Post SCCM Patching Basics Video Recording Available Now | ConfigMgr

Requirements of SSRS Report Creation

Data

Graphs in SCCM SSRS Reports Creation

  • The report data to be presented in graphic view with data
  • The report to be clean and add charts if possible.
  • Microsoft proves it console-like Client Health & Office 365 Client Management
  • Add links between reports to the reader to move next report

Demo

  • How to create the ConfigMgr SSRS report
  • How to add the graph in the Report
  • Sample SCCM SSRS Reports creation
  • About SSRS Report subscription

Video Recording

SSRS Reports Creation – ConfigMgr SCCM
SSRS Report Creation SCCM ConfigMgr
SSRS Report Creation SCCM ConfigMgr

Resources