📖 What is Co-management?
Co-management is a management state where Windows 10/11 devices are managed by both Microsoft Configuration Manager and Microsoft Intune. This allows organizations to transition workloads, such as compliance policies or app deployment, from on-premises management to the cloud.
"Study the 'workload sliders'; the exam often asks which authority (ConfigMgr or Intune) controls a specific management task."
📚 Certification: Microsoft 365 Administrator (MS-102)
🔑 What are the Key Concepts of Co-management?
- ▸ Workload sliders allow administrators to shift authority for specific management tasks, such as compliance or apps, from Configuration Manager to Intune.
- ▸ Devices must be Azure AD joined or Hybrid Azure AD joined to support co-management, ensuring a cloud identity exists for Intune enrollment.
- ▸ The Configuration Manager client acts as the primary agent that triggers the automatic enrollment of the device into Microsoft Intune.
- ▸ Management authority is exclusive per workload, meaning only one tool controls a specific setting to prevent conflicting configurations on the endpoint.
- ▸ Co-management enables a phased migration to cloud-native management, allowing organizations to modernize their infrastructure at their own pace.
🎯 How does Co-management appear on the MS-102 Exam?
A scenario might describe a company wanting to move compliance policy management to the cloud while keeping app deployment on-premises; you must identify the specific workload slider to shift.
You may be asked to identify the prerequisite identity state for a device to be co-managed, specifically focusing on why Hybrid Azure AD Join is required for on-premises devices.
Expect questions where you must determine which management tool takes precedence for a specific task, such as Windows Update for Business, based on the current position of the workload sliders.
❓ Frequently Asked Questions
Can a device be co-managed if it is only joined to a local Active Directory?
No, devices must be either Azure AD joined or Hybrid Azure AD joined. Local AD join alone is insufficient because Intune requires an Azure AD identity for authentication and enrollment.
What is the purpose of the 'Pilot Intune' setting on a workload slider?
Pilot Intune allows administrators to transition a specific workload to Intune for a select group of devices while keeping the rest of the organization under Configuration Manager control.