Home›Endpoint Security›Hardening & compliance
Section
Hardening & compliance
Device compliance, enrollment, baselines, and configuration.
"Device authentication failed": hybrid join, the PRT and Intune, end to end
How a hybrid-joined PC gets its identity, how that becomes the user's PRT, and how both feed Intune. Then a real AADSTS50155 case: the evidence, the fix, and the validation, without wiping anything.
Read →Windows Hello for Business via Intune: the two paths, and picking the right one
The enrollment-path tenant default vs the group-scoped device-configuration profile — prerequisites, PIN and security-device settings, reading the check-in results, and remediating the errors.
Read →Rotating every local admin password with Intune LAPS
Windows LAPS gives each device its own rotating admin password, escrowed to Entra where only the right people can read it — the concept, prerequisites, config, reading the results, and remediating the errors.
Read →Hybrid Intune auto-enrollment, end to end
The complete path a hybrid Azure AD-joined device takes to enrol itself into Intune automatically — every requirement in the chain, how the GPO trigger fires, how to force it, and why a stubborn few refuse.
Read →