What’s Changed in Enterprise Mobility Suite:
Enterprise Mobility Suite is renamed as Enterprise Mobility and Security. The existing enterprise Mobility Suite becomes Enterprise Mobility + Security E3 with no change for existing customers. A new upcoming plan will be known as Enterprise Mobility + Security E5.
Intune and its changes:
New Management Capabilities which includes Windows Updates, Windows Firewall and Endpoint protection
Azure AD Premium and its changes:
The existing Azure Active Directory Premium becomes Azure Active Directory Premium P1 with no change for existing customers
Azure Active Directory Premium P2 which will be available in coming days includes all the capabilities of Azure Active Directory Premium P1 as well as Identity Protection and Privileged Identity Management capabilities
Azure RMS and its Changes:
Azure Rights Management Premium becomes Azure Information Protection Premium P1 with no change in existing customers and Azure Information Protection Premium P2 adds advanced capabilities
Managing Windows with Microsoft Intune Client software:
Get a trial version of EMS here
Instead of enrolling windows PC as a mobile device, we can now enroll and manage windows PC’s by installing a client software. This has got the new management capabilities which supports Software updates, windows firewall and Endpoint protection
The following management capabilities are added with Intune client software:
- Application Management : Deploying Applications
- Endpoint protection : Managing and monitor malware attacks
- Windows Firewall : Configuring windows firewall settings
- Hardware and software inventory
- Remote control : Remote assistance request
- Software updates : Managing software updates
In this discussion, I am showcasing the software updates capabilities with Windows Intune Client software
- Download the client software
Intune Client software can be downloaded from here Or from the Intune Admin Console as shown below
Login to Intune portal at https://manage.microsoft.com
2. Enroll the windows Machine
Once the Intune Client software is downloaded and installed, the windows machine reports to Intune
We can check the status of the machine in company portal too at https://portal.manage.microsoft.com
Now we can manage the updates for this Windows Machine with Intune
Software Updates in Windows Intune:
This feature is similar to the software update feature in System Center Configuration Manager where we can keep the windows Machines up to date with the latest software updates. These updates can be from Microsoft/non-Microsoft. When we enroll a Windows Machine in Intune with Intune Client software, that Machine reports to Intune wherein we can see the no of updates required, manage the updates by approving/declining, see the status of the installation and compliance.
A sample Intune Dashboard showing software updates
Different Types of Updates: There are 7 different types of updates available out of which some are mandatory updates which doesn’t prompt for approval
Microsoft vs Non-Microsoft Updates:
Software Updates by Microsoft: Before we configure Microsoft updates, we have to configure product categories and update classifications
Navigate to Intune console – > Admin -> Updates where we can select the category and classification as per our requirement
Now, as we selected the product category and update classification, all the updates are synchronized to Intune console
Automatic approval rules – These rules automatically approve specified types of update and reduce your administrative overhead. For example, you might want to automatically approve all critical software updates.
Update Software not made from Microsoft:
We can also update the software which is not from Microsoft. To achieve this, we have to upload the software through upload wizard which will be saved in the cloud storage and later we can approve/decline and deploy to the specific collection as we do for Microsoft updates
Deploying a sample Microsoft update to enrolled computer:
Now, we installed a Intune client software, enrolled a computer to Intune console, selected the product category and classification, synchronised the updates to Intune. Let us try deploying a security update to the enrolled computer.
The enrolled computer has 96 software updates that need approval
Select any update and approve it
Create a collection ( group ) and deploy the update to the collection
Select the approval settings. These are similar to the settings in System Center Configuration Manager
Select the deadline to install the update
Open Microsoft Intune Center ( This is similar to Software Center in System Center Configuration Manager ) in the client machine and check for updates

You can see that the updates are getting installed
Check for the updates installation in control panel
Deploying a sample Non – Microsoft update to enrolled computer:
We can even deploy Non-Microsoft Applications and updates with Intune by uploading the application/update to the Intune storage and then deploying to the specific collection or a group. In this case, I have chosen Google chrome as a Non-Microsoft application which is to be deployed to the enrolled computer. We can also try with Java updates as Non-Microsoft updates if Java is installed in the machine
Navigate to Intune console -> updates -> All Updates and click on upload
Specify the location of update setup file
This is quite interesting section. This will allow to select the architecture and Operating system so that we can have these filters at deployment level
This section will gives the system the ability to check if the update/application is already installed in the targeted machine. This will avoid the re installation of the same application and avoids the overriding of previous versions
In this section we can specify command line arguments for custom installation
Approve
Deploy to the collection ( group )
Select the approval settings
Open Microsoft Intune Center in the client machine and check for the updates.
Confirm the installation in Control Panel
Awesome post… Thanks so much for sharing this KB..
LikeLike