IIS Configuration
It is recommended to set up a service account for the operation of Intune Manager.
This service account can be used to granularly control required MECM and database permissions.
Required roles and features
In Addition to the Features installed by default, the following Features must also be installed:
- ASP.NET 4.7
In addition to the roles installed by default, the following roles must also be installed:
- Basic Authentication
- Centralized SSL Certificate Support
- Windows Authentication
Service account assignment
To run Intune Manager in the context of a service account, perform the following steps within IIS:
Configuration SSL certificate
The prerequisite for authentication and authorization via Azure AAD is a configured SSL certificate.
An existing certificate can be used, or alternatively a self-signed certificate can be used.
The creation and assignment of a self-signed certificate is described below.
To create an SSL certificate within the IIS, the following steps must be performed: