Skip to content

Commit 07b6c6a

Browse files
authored
Merge pull request #6241 from MicrosoftDocs/main
11/30/2021 AM Publish
2 parents e229c48 + 790ef9a commit 07b6c6a

3 files changed

Lines changed: 10 additions & 5 deletions

File tree

memdocs/intune/configuration/device-profile-troubleshoot.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 04/15/2021
10+
ms.date: 11/29/2021
1111
ms.topic: troubleshooting
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -110,7 +110,9 @@ When you delete a profile, or remove a device from a group that's assigned the p
110110
- Allow data roaming
111111
- Allow automatic synchronization while roaming
112112

113-
- **Windows devices**: Intune settings are based on the Windows configuration service provider (CSPs). The behavior depends on the CSP. Some CSPs remove the setting, and some CSPs keep the setting, also called tattooing.
113+
- **Windows devices**: After you remove or unassign the profile, have the Azure AD user sign in to the device, and [sync with the Intune service](../user-help/sync-your-device-manually-windows.md).
114+
115+
Intune settings are based on the Windows configuration service provider (CSPs). The behavior depends on the CSP. Some CSPs remove the setting, and some CSPs keep the setting, also called tattooing.
114116

115117
- A profile applies to a user group. Later, a user is removed from the group. For the settings to be removed from that user, it can take up to 7 hours + the [platform-specific policy refresh cycle](#how-long-does-it-take-for-devices-to-get-a-policy-profile-or-app-after-they-are-assigned) (in this article).
116118

memdocs/intune/fundamentals/groups-add.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: ErikjeMS
99
ms.author: erikje
1010
manager: dougeby
11-
ms.date: 11/20/2019
11+
ms.date: 11/29/2021
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: fundamentals
@@ -33,6 +33,9 @@ ms.collection: M365-identity-device-management
3333

3434
Intune uses Azure Active Directory (Azure AD) groups to manage devices and users. As an Intune admin, you can set up groups to suit your organizational needs. Create groups to organize users or devices by geographic location, department, or hardware characteristics. Use groups to manage tasks at scale. For example, you can set policies for many users or deploy apps to a set of devices.
3535

36+
> [!NOTE]
37+
> Default groups created from [Microsoft 365 admin center](https://go.microsoft.com/fwlink/p/?linkid=2024339) are not security enabled. You must explicitly create security enabled Microsoft 365 groups in [Microsoft 365 admin center](https://go.microsoft.com/fwlink/p/?linkid=2024339), the [Azure AD admin center](https://portal.azure.com/), or [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431).
38+
3639
You can add the following types of groups:
3740

3841
- **Assigned groups** - Manually add users or devices into a static group.

memdocs/intune/protect/remove-certificates.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: brenduns
99
ms.author: brenduns
1010
manager: dougeby
11-
ms.date: 05/13/2021
11+
ms.date: 11/30/2021
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: protect
@@ -32,7 +32,7 @@ ms.reviewer: lacranda
3232

3333
In Microsoft Intune, you can use Simple Certificate Enrollment Protocol (SCEP) and Public Key Cryptography Standards (PKCS) certificate profiles to add certificates to devices.
3434

35-
These certificates can be removed when you [wipe](../remote-actions/devices-wipe.md#wipe) or [retire](../remote-actions/devices-wipe.md#retire) the device. There are also scenarios where certificates are automatically removed, and scenarios where certificates stay on the device. This article lists some common scenarios and their effect on PKCS and SCEP certificates.
35+
These certificates can be removed when you [wipe](../remote-actions/devices-wipe.md#wipe) or [retire](../remote-actions/devices-wipe.md#retire) the device. Certificates that were provisioned by Intune are also removed when the profile that provisioned the certificate no longer targets the device or user. There are other scenarios where certificates are automatically removed, and scenarios where certificates stay on the device. This article lists some common scenarios and their effect on PKCS and SCEP certificates.
3636

3737
> [!NOTE]
3838
> To remove and revoke certificates for a user who's being removed from on-premises Active Directory or Azure Active Directory (Azure AD), follow these steps in order:

0 commit comments

Comments
 (0)