Yesterday we reviewed the concept of device attestation and how it relates to Intune, but that was just the surface (no Microsoft pun intended).
Today we're going to take a much deeper look into the TPM attestation as it relates to Intune enrollment and Windows MDM hardening.
Special thanks to Rudy Ooms for reaching out and taking me through the Autopilot TPM saga.
Rudy's MDM hardening blog:
https://call4cloud.nl/2024/07/mdm-x-t...
Join the official Discord server
/ discord
Read more at
https://www.getrubix.com
Chapters
0:00:00 When baseball goes wrong
0:01:34 Health attestation VS TPM attestation
0:02:31 Flashpoint!
0:03:47 The hardening
0:04:19 Changes to Intune
0:05:26 Looking at the device certificates
0:07:56 Manually trigger an attestation attempt
0:08:56 Using the filter
0:10:43 Thanks, Rudy!
#intune #autopilot #windows10 #windows11 #microsoftgraph #azureadministrator #azure #powershellscripting #powershell #activedirectory #bitlocker #windows365 #zerotrust #certificate #entra #microsoftdefender #zerotrust #mdm