<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Zero Trust on Kürşat Bal</title><link>http://kursatbal.com/tags/zero-trust/</link><description>Recent content in Zero Trust on Kürşat Bal</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Mon, 10 Feb 2025 00:00:00 +0000</lastBuildDate><atom:link href="http://kursatbal.com/tags/zero-trust/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Intune Gelişmiş Güvenlik Yapılandırma Rehberi</title><link>http://kursatbal.com/p/microsoft-intune-geli%C5%9Fmi%C5%9F-g%C3%BCvenlik-yap%C4%B1land%C4%B1rma-rehberi/</link><pubDate>Mon, 10 Feb 2025 00:00:00 +0000</pubDate><guid>http://kursatbal.com/p/microsoft-intune-geli%C5%9Fmi%C5%9F-g%C3%BCvenlik-yap%C4%B1land%C4%B1rma-rehberi/</guid><description>&lt;p&gt;Microsoft Intune, uç nokta yönetimi ve güvenliğini tek platformda birleştiren bulut tabanlı bir MDM/MAM çözümüdür. Bu rehber, kurumsal ortamda Intune üzerinden güvenliğin katmanlı olarak nasıl yapılandırılacağını ele alır.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="lisanslama-ve-ön-koşullar"&gt;Lisanslama ve Ön Koşullar
&lt;/h2&gt;&lt;p&gt;Intune&amp;rsquo;un tam güvenlik özelliklerini kullanabilmek için asgari lisans gereksinimleri:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Lisans&lt;/th&gt;
&lt;th&gt;Kapsam&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft 365 Business Premium&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;KOBİ için MEM + Defender for Business&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft 365 E3&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;MDM + MAM + temel koşullu erişim&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Microsoft 365 E5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;E3 + Defender for Endpoint P2 + Microsoft Purview DLP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;EMS E3 / E5&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Bağımsız Enterprise Mobility + Security paketleri&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Intune Plan 1&lt;/strong&gt; tüm M365/EMS lisanslarında dahilidir. &lt;strong&gt;Plan 2&lt;/strong&gt; (Advanced Endpoint Analytics, Tunnel, Remote Help) ayrıca lisanslanır.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="kimlik-yönetimi-ve-güvenli-erişim"&gt;Kimlik Yönetimi ve Güvenli Erişim
&lt;/h2&gt;&lt;h3 id="microsoft-entra-id-conditional-access"&gt;Microsoft Entra ID Conditional Access
&lt;/h3&gt;&lt;p&gt;Conditional Access, &amp;ldquo;Doğru kullanıcı, doğru cihaz, doğru koşul&amp;rdquo; ilkesiyle çalışır. Temel politika yapısı:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Assignments:&lt;/strong&gt; Kullanıcı/grup kapsamı, bulut uygulamaları, cihaz platformu/durumu, ağ konumu&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Conditions:&lt;/strong&gt; Sign-in risk, user risk (Identity Protection), cihaz uyumluluk durumu&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Access controls:&lt;/strong&gt; MFA zorunluluğu, uyumlu cihaz zorunluluğu, erişim engeli&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Kritik politika örnekleri:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Politika&lt;/th&gt;
&lt;th&gt;Kapsam&lt;/th&gt;
&lt;th&gt;Kontrol&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Tüm uygulamalar — MFA&lt;/td&gt;
&lt;td&gt;Tüm kullanıcılar&lt;/td&gt;
&lt;td&gt;MFA zorunlu&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Admin portalları&lt;/td&gt;
&lt;td&gt;Yönetici rolleri&lt;/td&gt;
&lt;td&gt;MFA + Uyumlu cihaz&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;High risk sign-in&lt;/td&gt;
&lt;td&gt;Tüm kullanıcılar&lt;/td&gt;
&lt;td&gt;Erişimi engelle veya MFA + şifre sıfırla&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compliant device&lt;/td&gt;
&lt;td&gt;M365 uygulamaları&lt;/td&gt;
&lt;td&gt;Sadece Intune&amp;rsquo;a kayıtlı, uyumlu cihazlar&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="mfa-ve-windows-hello-for-business"&gt;MFA ve Windows Hello for Business
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;MFA yöntemleri (güçten zayıfa):&lt;/strong&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;FIDO2 güvenlik anahtarı (fiziksel — kimlik avı dayanıklı)&lt;/li&gt;
&lt;li&gt;Windows Hello for Business (biyometri/PIN — cihaza bağlı)&lt;/li&gt;
&lt;li&gt;Microsoft Authenticator (telefon onayı)&lt;/li&gt;
&lt;li&gt;TOTP uygulaması (Google Authenticator vb.)&lt;/li&gt;
&lt;li&gt;SMS/çağrı (en zayıf — SIM swap riski)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Windows Hello for Business (WHfB) Yapılandırması:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Intune → Endpoint Security → Account protection → Windows Hello for Business policy:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;span class="lnt"&gt;7
&lt;/span&gt;&lt;span class="lnt"&gt;8
&lt;/span&gt;&lt;span class="lnt"&gt;9
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Use Windows Hello for Business : Enabled
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Minimum PIN length : 8
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Maximum PIN length : 127
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Lowercase letters in PIN : Allowed
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Uppercase letters in PIN : Allowed
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Special characters in PIN : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;PIN expiration (days) : 0 (süresiz — biyometri kullanımı ön planda)
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;PIN history : 10
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Enable enhanced anti-spoofing : Enabled (IR kamera zorunluluğu)
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;hr&gt;
&lt;h2 id="uç-nokta-güvenliği"&gt;Uç Nokta Güvenliği
&lt;/h2&gt;&lt;h3 id="microsoft-defender-for-endpoint-entegrasyonu"&gt;Microsoft Defender for Endpoint Entegrasyonu
&lt;/h3&gt;&lt;p&gt;Intune ↔ Defender for Endpoint entegrasyonu için:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Microsoft Endpoint Manager admin center → Endpoint Security → Microsoft Defender for Endpoint&lt;/li&gt;
&lt;li&gt;&amp;ldquo;Allow Microsoft Defender for Endpoint to enforce Endpoint Security Configurations&amp;rdquo; → On&lt;/li&gt;
&lt;li&gt;Defender portalında Intune bağlantısını etkinleştirin&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Entegrasyon sonrası cihazın Defender risk seviyesi Intune compliance policy&amp;rsquo;de değerlendirilebilir:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Device Threat Level : Secured / Low / Medium / High
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;h3 id="attack-surface-reduction-asr-kuralları"&gt;Attack Surface Reduction (ASR) Kuralları
&lt;/h3&gt;&lt;p&gt;Intune → Endpoint Security → Attack surface reduction:&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;ASR Kuralı&lt;/th&gt;
&lt;th&gt;Mod&lt;/th&gt;
&lt;th&gt;Açıklama&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Block Office macros from creating child processes&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;td&gt;Office zararlı yazılım zincirini keser&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Block credential stealing from LSASS&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;td&gt;Mimikatz ve benzeri araçları engeller&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Block executable content from email&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;td&gt;E-posta tabanlı yayılımı önler&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Block abuse of exploited vulnerable signed drivers&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;td&gt;BYOVD saldırılarına karşı&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Block untrusted/unsigned USB execution&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;td&gt;USB tabanlı saldırıları önler&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;blockquote&gt;
&lt;p&gt;Kuralları önce &lt;strong&gt;Audit&lt;/strong&gt; modda çalıştırın, 2 hafta log inceleyin, sonra &lt;strong&gt;Block&lt;/strong&gt;&amp;lsquo;a alın.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="compliance-politikaları"&gt;Compliance Politikaları
&lt;/h2&gt;&lt;p&gt;Uyumluluk politikaları cihazın Conditional Access&amp;rsquo;e dahil olabilmesi için karşılaması gereken minimum güvenlik çıtasını belirler.&lt;/p&gt;
&lt;h3 id="windows-compliance-policy-önerilen-minimum"&gt;Windows Compliance Policy (Önerilen Minimum)
&lt;/h3&gt;&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;span class="lnt"&gt;7
&lt;/span&gt;&lt;span class="lnt"&gt;8
&lt;/span&gt;&lt;span class="lnt"&gt;9
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;OS Version : Windows 10 21H2 veya üzeri
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;BitLocker : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Secure Boot : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Code Integrity : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Defender : Real-time protection enabled, up-to-date signatures
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Firewall : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Antivirus : Required
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Password : Required, min 8 karakter, max 5 dk boşta kalma
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Device Threat Level: Low veya daha iyi
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Non-compliance aksiyonu:&lt;/strong&gt; 15 gün uyumsuz cihaz işaretlenir → 30. günde uzaktan kilitleme bildirimi → 45. günde koşullu erişim bloke.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="mam--uygulama-bazlı-veri-koruma-dlp"&gt;MAM — Uygulama Bazlı Veri Koruma (DLP)
&lt;/h2&gt;&lt;p&gt;Mobile Application Management (MAM), cihaz yönetimi olmadan uygulama düzeyinde veri koruma sağlar (BYOD senaryoları için idealdir).&lt;/p&gt;
&lt;h3 id="intune-app-protection-policy-app"&gt;Intune App Protection Policy (APP)
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;Veri transferi kısıtlamaları:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Ayar&lt;/th&gt;
&lt;th&gt;Değer&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Send org data to other apps&lt;/td&gt;
&lt;td&gt;Policy managed apps only&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Receive data from other apps&lt;/td&gt;
&lt;td&gt;Policy managed apps only&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Save copies of org data&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Backup org data to&amp;hellip;&lt;/td&gt;
&lt;td&gt;Block&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Restrict cut, copy, paste&lt;/td&gt;
&lt;td&gt;Policy managed apps&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Screen capture&lt;/td&gt;
&lt;td&gt;Block (Android)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Erişim gereksinimleri:&lt;/strong&gt;&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Ayar&lt;/th&gt;
&lt;th&gt;Değer&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;PIN for access&lt;/td&gt;
&lt;td&gt;Required&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Biometric instead of PIN&lt;/td&gt;
&lt;td&gt;Allow&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Recheck access requirements&lt;/td&gt;
&lt;td&gt;30 dakika&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Offline grace period&lt;/td&gt;
&lt;td&gt;720 saat&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Wipe data after failed PIN attempts&lt;/td&gt;
&lt;td&gt;5 deneme sonrası&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="windows-autopilot"&gt;Windows Autopilot
&lt;/h2&gt;&lt;p&gt;Autopilot, cihazların kutusundan çıkıp son kullanıcı eline geçene kadar IT departmanına dokunmadan Intune ile yapılandırılmasını sağlar.&lt;/p&gt;
&lt;h3 id="deployment-profile-ayarları"&gt;Deployment Profile Ayarları
&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;User-driven mode&lt;/strong&gt; (en yaygın):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;div class="chroma"&gt;
&lt;table class="lntable"&gt;&lt;tr&gt;&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code&gt;&lt;span class="lnt"&gt;1
&lt;/span&gt;&lt;span class="lnt"&gt;2
&lt;/span&gt;&lt;span class="lnt"&gt;3
&lt;/span&gt;&lt;span class="lnt"&gt;4
&lt;/span&gt;&lt;span class="lnt"&gt;5
&lt;/span&gt;&lt;span class="lnt"&gt;6
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;
&lt;td class="lntd"&gt;
&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Deployment mode : User-driven
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Join to Azure AD as : Azure AD joined
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Microsoft Software License Terms : Auto-accept
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Privacy settings : Hide
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Hide change account : Hide
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;User account type : Standard User
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;
&lt;/div&gt;
&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Pre-provisioning (White Glove):&lt;/strong&gt; IT, cihazı son kullanıcıya vermeden önce kurum politikalarını ve uygulamaları önceden yükler. Kullanıcıya sadece kendi kimlik bilgilerini girecek bir cihaz ulaşır.&lt;/p&gt;
&lt;h3 id="enrollment-status-page-esp"&gt;Enrollment Status Page (ESP)
&lt;/h3&gt;&lt;p&gt;ESP, kullanıcının masaüstüne geçmeden önce tüm kritik uygulama ve politikaların yüklenmesini garanti eder:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Block device use until all apps and profiles are installed:&lt;/strong&gt; Yes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Show error when installation takes longer than:&lt;/strong&gt; 60 dakika&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Allow users to collect logs:&lt;/strong&gt; Yes (sorun giderme kolaylığı)&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="sonuç"&gt;Sonuç
&lt;/h2&gt;&lt;p&gt;Intune üzerinde güvenliği katmanlı yapılandırmak; kimlik doğrulamadan cihaz uyumluluğuna, uygulama korumasından uç nokta tehdit zekasına kadar uzanan bir Zero Trust zinciri oluşturur. Her katman tek başına yetersizdir; güç, katmanların birlikte çalışmasından gelir.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Katman&lt;/th&gt;
&lt;th&gt;Araç&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Kimlik&lt;/td&gt;
&lt;td&gt;Entra ID + Conditional Access + MFA/WHfB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cihaz&lt;/td&gt;
&lt;td&gt;Intune MDM + Compliance Policy + BitLocker&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Uygulama&lt;/td&gt;
&lt;td&gt;MAM + App Protection Policy&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Tehdit&lt;/td&gt;
&lt;td&gt;Defender for Endpoint + ASR&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Süreç&lt;/td&gt;
&lt;td&gt;Autopilot + ESP&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;</description></item></channel></rss>