Microsoft Intune Microsoft Intune

Referenz für Intune Admin Center, Enrollment, Autopilot, Compliance, App-Schutz und deviceManagement APIs. Reference for the Intune admin center, enrollment, Autopilot, compliance, app protection, and deviceManagement APIs.

4
Plattformen im Fokus Platforms in focus
3
Autopilot Modi Autopilot modes
MAM
App-Schutz ohne Enrollment App protection without enrollment
Graph
deviceManagement APIs deviceManagement APIs
Geräte- und App-Schutz kombinieren Combine device and app protection

Intune entfaltet den größten Wert zusammen mit Entra Conditional Access, Defender und klaren Ownership-Modellen für Corporate und BYOD. Intune delivers the most value when combined with Entra Conditional Access, Defender, and clear ownership models for corporate and BYOD devices.

🛠️ Admin Center 🛠️ Admin Center

Bereiche und Scope Tags Areas and scope tags

📥 Enrollment 📥 Enrollment

Plattformen und Methoden Platforms and methods

✅ Compliance ✅ Compliance

Richtlinien pro Plattform Policies per platform

🌐 Graph API 🌐 Graph API

deviceManagement Endpunkte deviceManagement endpoints

🛠️ Überblick & Admin Center 🛠️ Overview & admin center

Das Intune Admin Center vereint Geräte, Apps, Endpoint Security, Enrollment, Reports und Troubleshooting. Scope Tags und RBAC sind entscheidend für Delegation zwischen Regionen oder Support-Teams. The Intune admin center brings together devices, apps, endpoint security, enrollment, reports, and troubleshooting. Scope tags and RBAC are essential for delegation between regions or support teams.

Bereich Area Wichtige Aufgaben Key tasks Kommentar Comment
Devices Devices Bestand, Compliance, Aktionen, Gerätezustand Inventory, compliance, actions, device health Zentrale tägliche Betriebsansicht Primary day-to-day operational view
Apps Apps Pakete, Zuweisungen, App Protection Policies Packages, assignments, app protection policies Trennt MDM und MAM Szenarien Separates MDM and MAM scenarios
Endpoint security Endpoint security AV, Firewall, Disk Encryption, EDR, ASR AV, firewall, disk encryption, EDR, ASR Überschneidung mit Security Teams beachten Coordinate with security teams
Reports Reports Enrollment Failures, Compliance Trends, Device Health Enrollment failures, compliance trends, device health Wichtig für Rollout und Incident Response Important for rollout and incident response

📥 Enrollment je Plattform 📥 Device enrollment by platform

Plattform Platform Methoden Methods Wichtige Hinweise Important notes
Windows Windows Autopilot, Bulk Enrollment, manuell, GPO/Co-Management Autopilot, bulk enrollment, manual, GPO/co-management Entra Join, Hybrid Join und bestehende SCCM-Szenarien berücksichtigen Consider Entra join, hybrid join, and existing SCCM scenarios
iOS/iPadOS iOS/iPadOS DEP/Automated Device Enrollment, BYOD User Enrollment, manuell DEP/automated device enrollment, BYOD user enrollment, manual Apple Business Manager und Zertifikate sind Pflichtbausteine Apple Business Manager and certificates are required building blocks
Android Android Android Enterprise Work Profile, Fully Managed, Dedicated, COPE, BYOD Android Enterprise work profile, fully managed, dedicated, COPE, BYOD Managed Google Play sauber integrieren Integrate Managed Google Play correctly
macOS macOS Automated Device Enrollment, Company Portal, manuell Automated device enrollment, Company Portal, manual FileVault, Zertifikate und Update-Strategie früh definieren Define FileVault, certificates, and update strategy early

🚀 Windows Autopilot 🚀 Windows Autopilot

Autopilot standardisiert Windows Bereitstellung. Profile, ESP, Geräteimport, Pre-Provisioning und Lizenz-/Join-Modell müssen aufeinander abgestimmt sein. Autopilot standardizes Windows provisioning. Profiles, ESP, device import, pre-provisioning, and the licensing/join model must be aligned.

Profil Profile Einsatz Use case Kommentar Comment
User-driven User-driven Standard für Benutzergeräte mit Sign-in durch Anwender Standard for user devices with user sign-in Typisch für Office-Arbeitsplätze Typical for office endpoints
Self-deploying Self-deploying Kiosk, Shared Device, ohne primären Benutzer Kiosk, shared device, without a primary user Benötigt TPM-gestützte Voraussetzungen Requires TPM-based prerequisites
Pre-provisioned Pre-provisioned IT oder Lieferant bereitet Gerät vor, Benutzer übernimmt später IT or partner pre-provisions the device, the user completes setup later Gut für große Rollouts und Versand an Endanwender Good for large rollouts and direct shipping to end users

✅ Compliance Policies ✅ Compliance policies

Plattform Platform Beispiele Examples Kontrollziel Control objective
Windows Windows BitLocker erforderlich, Mindest-OS-Version, Passwort, Secure Boot, Threat Level Require BitLocker, minimum OS version, password, Secure Boot, threat level Gerätehärtung und Defender-Integration Device hardening and Defender integration
iOS/iPadOS iOS/iPadOS Nicht gejailbreakt, Mindestversion, Passcode, verschlüsselt Not jailbroken, minimum version, passcode, encrypted Mobile Datenschutz- und Basissicherheit Mobile privacy and baseline security
Android Android Nicht gerootet, Mindestversion, Passcode, Google Play Integrity Not rooted, minimum version, passcode, Google Play Integrity BYOD und Corporate Android absichern Protect BYOD and corporate Android
macOS macOS Mindestversion, Passwort, FileVault, System Integrity Minimum version, password, FileVault, system integrity Desktop Compliance für Apple Geräte Desktop compliance for Apple devices

⚙️ Configuration Profiles ⚙️ Configuration profiles

Settings catalog Settings catalog

Bevorzugter Ansatz für moderne Windows- und Plattformsettings mit Suchfunktion und klarer Dokumentation. Preferred approach for modern Windows and platform settings with search and clear documentation.

Templates Templates

Vordefinierte Profile für typische Aufgaben wie Wi-Fi, VPN, Zertifikate oder E-Mail. Predefined profiles for common tasks such as Wi-Fi, VPN, certificates, or email.

ADMX ADMX

Für viele klassische Gruppenrichtlinien-Settings weiterhin relevant. Still relevant for many traditional group policy settings.

OMA-URI OMA-URI

Flexibler Low-Level-Ansatz für CSP-basierte Konfiguration. Flexible low-level approach for CSP-based configuration.

📦 App Management 📦 App management

App-Typ App type Beispiele Examples Hinweis Note
Win32 Win32 .intunewin mit Detection Rules und Requirements .intunewin with detection rules and requirements Standard für klassische Windows Anwendungen Standard for traditional Windows applications
LOB LOB MSI, APPX, PKG, IPA je Plattform MSI, APPX, PKG, IPA by platform Plattformabhängige Signierung beachten Mind platform-specific signing requirements
Store Apps Store apps Microsoft Store new, Managed Google Play, Apple VPP Microsoft Store new, Managed Google Play, Apple VPP Effizient für Standardsoftware Efficient for standard software
Web Apps Web apps SaaS Apps als Shortcut oder managed app SaaS apps as shortcuts or managed apps Hilfreich in Frontline- oder Kiosk-Szenarien Helpful for frontline or kiosk scenarios

🛡️ App Protection Policies 🛡️ App protection policies

MAM-Richtlinien schützen Daten in unterstützten mobilen Apps auch ohne vollständiges Enrollment. Zentrale Felder sind Data Protection, Access Requirements und Conditional Launch. MAM policies protect data in supported mobile apps even without full enrollment. Key areas are data protection, access requirements, and conditional launch.

🧰 Device Actions 🧰 Device actions

Aktion Action Wirkung Effect Wann nutzen When to use
Sync Sync Fordert sofortige Richtlinienabfrage an Triggers an immediate policy check-in Nach dringenden Richtlinienänderungen After urgent policy changes
Restart Restart Gerät wird neu gestartet Device is rebooted Für kontrollierte Remediation For controlled remediation
Remote lock Remote lock Sperrt das Gerät Locks the device Verlust oder unbeaufsichtigte Geräte Loss or unattended devices
Retire Retire Entfernt Unternehmensdaten, belässt private Daten soweit möglich Removes corporate data while preserving personal data where possible BYOD Offboarding BYOD offboarding
Wipe Wipe Werkseinstellung oder komplette Zurücksetzung Factory reset or full reset Verlust, Diebstahl, schwere Kompromittierung Loss, theft, severe compromise

🔐 Conditional Access Integration 🔐 Conditional Access integration

Intune und Entra Conditional Access arbeiten eng zusammen. Typische Zugriffsanforderungen sind Require compliant device oder Require app protection policy. Intune and Entra Conditional Access work closely together. Typical access requirements are Require compliant device or Require app protection policy.

🛡️ Endpoint Security 🛡️ Endpoint security

Bereich Area Beispiele Examples Ziel Goal
Antivirus Antivirus Microsoft Defender Antivirus Policies Microsoft Defender Antivirus policies Basisschutz und Signatursteuerung Baseline protection and signature control
Encryption Encryption BitLocker, FileVault BitLocker, FileVault Datenschutz bei Geräteverlust Data protection for lost devices
Firewall Firewall Windows Defender Firewall Settings Windows Defender Firewall settings Netzwerksegmentierung und Angriffsschutz Network segmentation and attack protection
EDR EDR Defender for Endpoint Integration Defender for Endpoint integration Erweiterte Erkennung und Reaktion Advanced detection and response
ASR ASR Attack Surface Reduction Rules Attack Surface Reduction rules Reduziert Makro-, Script- und Exploit-Risiken Reduces macro, script, and exploit risks

📈 Reporting 📈 Reporting

Wichtige Berichte sind Enrollment Failures, Device Compliance, Endpoint Security Status, App Install Status und Assignment Errors. Für große Rollouts sind Export und Trendanalyse entscheidend. Important reports include enrollment failures, device compliance, endpoint security status, app install status, and assignment errors. Export and trend analysis are essential for large rollouts.

🌐 Graph API deviceManagement 🌐 Graph API deviceManagement

Endpunkt Endpoint Zweck Purpose Beispiel Example
/deviceManagement/managedDevices /deviceManagement/managedDevices Verwaltete Geräte lesen und filtern Read and filter managed devices Inventar, Compliance, Benutzerbindung Inventory, compliance, user binding
/deviceManagement/deviceConfigurations /deviceManagement/deviceConfigurations Konfigurationsprofile verwalten Manage configuration profiles Windows, iOS, Android Settings Windows, iOS, Android settings
/deviceManagement/deviceCompliancePolicies /deviceManagement/deviceCompliancePolicies Compliance Policies lesen/anlegen Read or create compliance policies Regelwerke für Plattformen Policy sets for platforms
/deviceAppManagement/mobileApps /deviceAppManagement/mobileApps Apps inventarisieren und verwalten Inventory and manage apps Win32, Store, VPP, Managed Google Play Win32, Store, VPP, Managed Google Play
/deviceAppManagement/managedAppPolicies /deviceAppManagement/managedAppPolicies MAM Policies verwalten Manage MAM policies App Protection für BYOD App protection for BYOD
PowerShell PowerShell

# Beispiel: Managed Devices per Graph lesen
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.Read.All"

Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/v1.0/deviceManagement/managedDevices?$top=10"

# Beispiel: Compliance Policies lesen
Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/v1.0/deviceManagement/deviceCompliancePolicies"

# Beispiel: Mobile Apps lesen
Invoke-MgGraphRequest -Method GET -Uri "https://graph.microsoft.com/v1.0/deviceAppManagement/mobileApps"

deviceManagement Endpoint ReferenzdeviceManagement endpoint reference

EndpointEndpointNutzenUse
/deviceManagement/managedDevices/deviceManagement/managedDevicesVerwaltete Geräte inventarisieren.Inventory managed devices.
/deviceManagement/deviceConfigurations/deviceManagement/deviceConfigurationsKonfigurationsprofile lesen.Read configuration profiles.
/deviceManagement/deviceCompliancePolicies/deviceManagement/deviceCompliancePoliciesCompliance Policies lesen.Read compliance policies.
/deviceManagement/deviceShellScripts/deviceManagement/deviceShellScriptsShell Scripts verwalten.Manage shell scripts.
/deviceManagement/deviceManagementScripts/deviceManagement/deviceManagementScriptsWindows PowerShell Skripte verwalten.Manage Windows PowerShell scripts.
/deviceManagement/groupPolicyConfigurations/deviceManagement/groupPolicyConfigurationsAdministrative Templates lesen.Read administrative templates.
/deviceManagement/reports/deviceManagement/reportsIntune Berichte abrufen.Retrieve Intune reports.
/deviceManagement/roleDefinitions/deviceManagement/roleDefinitionsRBAC Rollendefinitionen lesen.Read RBAC role definitions.
/deviceManagement/roleAssignments/deviceManagement/roleAssignmentsRBAC Rollenzuweisungen lesen.Read RBAC assignments.
/deviceManagement/assignmentFilters/deviceManagement/assignmentFiltersIntune Assignment Filters verwalten.Manage Intune assignment filters.
/deviceAppManagement/mobileApps/deviceAppManagement/mobileAppsMobile und Win32 Apps inventarisieren.Inventory mobile and Win32 apps.
/deviceAppManagement/managedAppPolicies/deviceAppManagement/managedAppPoliciesApp Protection Policies lesen.Read app protection policies.
/deviceManagement/windowsAutopilotDeviceIdentities/deviceManagement/windowsAutopilotDeviceIdentitiesAutopilot Geräte verwalten.Manage Autopilot devices.
/deviceManagement/virtualEndpoint/deviceManagement/virtualEndpointCloud PC / Windows 365 Daten lesen.Read Cloud PC / Windows 365 data.
/deviceManagement/detectedApps/deviceManagement/detectedAppsErkannte Apps auswerten.Evaluate detected apps.
/deviceManagement/importedWindowsAutopilotDeviceIdentities/deviceManagement/importedWindowsAutopilotDeviceIdentitiesAutopilot Imports verfolgen.Track Autopilot imports.
/deviceManagement/deviceHealthScripts/deviceManagement/deviceHealthScriptsProactive Remediations lesen.Read proactive remediations.
/deviceManagement/intents/deviceManagement/intentsSettings Catalog Intents auswerten.Evaluate settings catalog intents.

Top 30 Windows CSPsTop 30 Windows CSPs

CSPCSPHinweisNote
Policy/Config/BitLockerPolicy/Config/BitLockerWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/DefenderPolicy/Config/DefenderWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/FirewallPolicy/Config/FirewallWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/UpdatePolicy/Config/UpdateWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/DeviceLockPolicy/Config/DeviceLockWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/ExperiencePolicy/Config/ExperienceWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/SystemPolicy/Config/SystemWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/BrowserPolicy/Config/BrowserWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/SmartScreenPolicy/Config/SmartScreenWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/ApplicationManagementPolicy/Config/ApplicationManagementWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/AboveLockPolicy/Config/AboveLockWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/AuthenticationPolicy/Config/AuthenticationWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/CertificatesPolicy/Config/CertificatesWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/ConnectivityPolicy/Config/ConnectivityWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/CredentialProvidersPolicy/Config/CredentialProvidersWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/DataProtectionPolicy/Config/DataProtectionWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/DeliveryOptimizationPolicy/Config/DeliveryOptimizationWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/DeviceInstallationPolicy/Config/DeviceInstallationWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/EnterpriseCloudPrintPolicy/Config/EnterpriseCloudPrintWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/LocalPoliciesSecurityOptionsPolicy/Config/LocalPoliciesSecurityOptionsWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/LocalUsersAndGroupsPolicy/Config/LocalUsersAndGroupsWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/NetworkIsolationPolicy/Config/NetworkIsolationWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/PassportForWorkPolicy/Config/PassportForWorkWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/PowerPolicy/Config/PowerWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/PrintersPolicy/Config/PrintersWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/RemoteDesktopServicesPolicy/Config/RemoteDesktopServicesWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/SearchPolicy/Config/SearchWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/StartPolicy/Config/StartWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/TaskbarPolicy/Config/TaskbarWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.
Policy/Config/WiFiPolicy/Config/WiFiWichtiger CSP für Windows Richtlinien, Security oder Device Experience.Important CSP for Windows policy, security, or device experience.

Wichtige RBAC RollenImportant RBAC roles

RolleRoleBeschreibungDescription
Help Desk OperatorHelp Desk OperatorBasis-Troubleshooting ohne Volladmin.Baseline troubleshooting without full admin.
Policy and Profile ManagerPolicy and Profile ManagerVerwaltet Gerätekonfigurationen und Compliance.Manages device configuration and compliance.
Application ManagerApplication ManagerPflegt App-Bereitstellungen.Maintains app deployments.
Read Only OperatorRead Only OperatorNur lesender Zugriff für Audits.Read-only access for audits.
School AdministratorSchool AdministratorBildungsspezifische Intune Administration.Education-specific Intune administration.
Endpoint Security ManagerEndpoint Security ManagerFokus auf Security Baselines und Defender.Focus on security baselines and Defender.

Intune Filter SyntaxIntune filter syntax

BeispielExampleBedeutungMeaning
(device.deviceOwnership -eq "Corporate")(device.deviceOwnership -eq "Corporate")Nur Firmenbesitz.Corporate-owned only.
(device.manufacturer -contains "Dell")(device.manufacturer -contains "Dell")Herstellerfilter.Manufacturer filter.
(device.model -startsWith "Surface")(device.model -startsWith "Surface")Modellpräfix.Model prefix.
(device.osVersion -ge "10.0.22631")(device.osVersion -ge "10.0.22631")OS-Mindeststand.Minimum OS level.
(device.enrollmentProfileName -eq "Autopilot-Standard")(device.enrollmentProfileName -eq "Autopilot-Standard")Autopilot-Profilbezug.Autopilot profile targeting.
(device.category -eq "Kiosk")(device.category -eq "Kiosk")Gerätekategorie.Device category.
PowerShellPowerShell
Connect-MgGraph -Scopes "DeviceManagementManagedDevices.Read.All","DeviceManagementConfiguration.Read.All"
Get-MgDeviceManagementAssignmentFilter | Select-Object DisplayName,Platform,Rule

Proactive RemediationsProactive remediations

Proactive Remediations bestehen aus Detection Script, Remediation Script, Zeitplan, Scope und Reporting. Sie eignen sich für Health Checks, Drift Correction und schnelle Reparaturen ohne vollständige Paketierung.Proactive remediations consist of a detection script, remediation script, schedule, scope, and reporting. They fit health checks, drift correction, and quick repairs without full packaging.

PowerShellPowerShell
$service = Get-Service -Name w32time
if ($service.Status -ne "Running") { exit 1 }
exit 0

Win32 Packaging GuideWin32 packaging guide

PowerShellPowerShell
.\IntuneWinAppUtil.exe -c C:\Packageszip -s 7z2301-x64.msi -o C:\Packages\Output

GitHub ReferenzenGitHub references

RepositoryRepositoryNutzenUse
microsoft/Intune-PowerShell-SDKmicrosoft/Intune-PowerShell-SDKPowerShell SDK und Beispiele für ältere sowie hybride Workflows.PowerShell SDK and samples for older and hybrid workflows.
microsoftgraph/powershell-intune-samplesmicrosoftgraph/powershell-intune-samplesGraph-PowerShell Beispiele für Intune Administration.Graph PowerShell samples for Intune administration.
microsoft/Microsoft-Win32-Content-Prep-Toolmicrosoft/Microsoft-Win32-Content-Prep-ToolWin32 Content Prep Tool für .intunewin Pakete.Win32 content prep tool for .intunewin packages.