AMA: Best practices for applying Zero Trust using Intune @WindowsAtWork
AMA: Best practices for applying Zero Trust using Intune  @WindowsAtWork
Uploaded January 2026 | Updated September 2026, 6 hours ago
Post your questions now at https://aka.ms/AMA/IntuneZeroTrust!

Never trust, always verify. Tune in for tips and insights to help you secure your endpoints using Microsoft Intune as part of your larger Zero Trust strategy. Find out how you can use Intune to protect both access and data on organization-owned devices and personal devices used for work. Ask Microsoft Anything (AMA) and get the answers you need to implement the right policies, security settings, device configurations, and more. Only at Tech Community Live! 

This Ask Microsoft Anything (AMA) is part of Tech Community Live: Microsoft Intune edition. 📃 For the full agenda, see: https://aka.ms/TCL/Intune

0:00 – Welcome & introductions

2:23 – Question – Systems Architect for ~200 users in fully cloud M365 environment. What is Microsoft's or your own opinions on enforcing Zero Trust with CA policies? I took over an existing CA setup a year ago and although it works, it's very dependent on static grouping and I want something that can be easily scaled without relying on not missing adding someone to a group.

9:11 – Question – One shortcoming for Intune management is a standardized connectivity test that reports on connectivity issues and helps Intune admins check and act on connectivity issues; it would even enable security admins and network admins to smoke test Intune pro-actively when making changes and thus avoid disruptions for Intune. What is the Intune team's opinion on this?

18:09 – Question – I love the Zero Trust Workshop Assessment and workbook, but it is overwhelming. Is there a recommended approach to tackling the "to do" list?

24:04 – Question – Using GSA for part of my Zero trust solution. Global Secure Access on BYOD (Android and iOS) not depending on the Microsoft Defender app is needed. Maybe an app just for GSA, similar to Windows. Asking users to install the Microsoft Defender app on their BYOD device is way too much. For my organization, GSA on Android was blocked, issues with Android version 15 and many other issues and just never working on some devices. Recommendation for Android welcome!!
AMA: Best practices for applying Zero Trust using IntuneMigrating from VDI to Windows 365Experience next-gen productivity with Windows 365 AI-enabled Cloud PCsData protection with hardware-based security and Windows 11 – Microsoft Technical TakeoffCultivating curiosity and opportunity: IT generation.next - Tackling TechWindows cloud security best practices - Windows in the CloudAMA: Microsoft Connected Cache and Delivery OptimizationIntroducing Azure Virtual Desktop for hybrid environments | Windows in the CloudAsk Microsoft Anything: Secure Boot - February 2026AMA: Unified update management for WindowsUnified security: Intune + Microsoft Defender for Endpoint – Microsoft Technical TakeoffMicrosoft em português: Microsoft Intune Suite  - Parte 2
Windows At Work |

AMA: Best practices for applying Zero Trust using Intune

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER