Endpoint management
Microsoft Intune
Before you start
6 min
verify your environment meets these requirements supported hardware {{ch}} , 7 0 2 x or later supported operating systems w indows server 2016 or later required infrastructure a windows server joined to your active directory domain that acts as the enterprise ca a windows server joined to your active directory domain that acts as the network device enrollment service (ndes) service required access an account on the {{ch}} with administrator permissions to deploy new services local administrator access on the enterprise ca and network device enrollment service (ndes) windows servers network and firewall allow outbound tcp port 2001 (default host api port) from the enterprise ca windows server to the {{ch}} , specified by fqdn (for example, cryptohub example com ) or cidr (for example, 10 0 0 0/24 ) tls inspection or ssl proxies can break mutual tls handshakes exempt the {{ch}} fqdn(s) from inspection configure the {{ch}} with a fqdn so the exemption applies