Your client said the logs stay in the building.
Your EDR still ships them to a vendor cloud.
Endpointward keeps protection on the machine for that case. Self-host HQ. MSP seats $3-8 per endpoint a month.
Happy on Falcon, SentinelOne, or Microsoft? Stay there.
@aruntikaram Intune control 'coming soon' is the part that matters for anyone managing more than a handful of boxes. until then is it GPO/registry only, or is there a CSP you can push through OMA-URI? permissive-then-enforce is right but nobody reads the log on 300 machines by hand
@Don_henzo mover is the step I'd want to see. leaver is easy to audit, but mover quietly stacks access over a few role changes. does your pipeline strip old groups on department change automatically, or send the removal to the old manager to sign off?
@LorisAmbrozzo useful, didn't know the built-in policy skipped some sub-plans. which ones did it miss in your testing? and does it also leave them off when a new subscription gets created later, or is that only on the initial assignment?
@kkaminsk the Connect Health one surprised me. is that the registration role change, or something that only shows if you still have the agent on old DCs? trying to work out if it's worth checking on small tenants that barely touch hybrid
@adriananglin putting an end date in the policy name, like 'RO until 22 Oct', is crude but it makes it show up in every review. do you alert on how long something's been report-only, or just catch it in audits?
@penasarajarvi yeah self-updaters wreck version-based detection. are you detecting on file version or just existence? existence is lazier but survives the auto-update
@NANDSHARMA1991 Good list. The one I'd put first is device compliance tied to Conditional Access. Identity rules mean little if an unmanaged laptop can still sign in.
@StevenKister1@Mister_MDM Good question. I'd test it on one device first and check what actually lands in secpol before it goes wide. A wrong SID in User Rights fails quietly.
@PerLarsen1975 fair. baseline test before broad deploy is the part we should have led with. credential guard still bites some of our line-of-business apps though
@chidodike yeah the pending restart one is the silent killer. we started having desk check reboot-pending before they even open the ticket notes. cuts a lot of "push failed" noise
@AdamGell honestly if you've got a quiet test box, try CMTrace Open on an IME failure during ESP and tell me if the Event Viewer filter saves a step. that's the whole ask
@ihor43us@ghostinthecable Agree it's mostly process. A quarantined driver that Intune pushed should come with context before anyone pages on-call. Do your analysts get deployment info alongside EDR alerts?
@MGProTechCA Agree. For small clients the hardest part is getting device compliance tied into sign-in without breaking the owner's phone. How are you handling BYOD on Business Premium?
@alrafayglobal Rolling out to a pilot group first saves so much pain. We also keep a break-glass account out of every CA policy before touching compliance. Learned that one the hard way.