Understand endpoint management strategies and Microsoft Intune
Introduces Microsoft Intune, management models (cloud-only, hybrid, co-managed), and how Microsoft Entra ID supports device management.
- What is Microsoft Intune and how does it work?
- Compare Configuration Manager, Intune, and co-management
- Understand the role of Microsoft Entra ID in Intune
- Evaluate device management models
- Explore MDM capabilities in Intune
Configure Microsoft Entra ID for device and policy management
Configure user and device identity, admin roles, registration settings, and dynamic groups to support Intune policy targeting.
- Understand the role of Microsoft Entra ID in endpoint management
- Create and manage users and groups in Microsoft Entra ID
- Assign Microsoft Entra ID roles for device management
- Configure Microsoft Entra ID device registration settings
- Use dynamic group membership and filters in Microsoft Entra ID
Administer device identity and authentication using Microsoft Entra ID
Explore device object lifecycle, join types, trust models, and troubleshooting join and authentication failures in Microsoft Entra ID.
- Understand device identities in Microsoft Entra ID
- Compare device registration, Microsoft Entra join, and hybrid join
- Understand authentication methods—key trust, certificate trust, and TPM
- Configure device trust and join settings
- Validate and troubleshoot device identity and trust issues
Plan and implement device enrollment using Microsoft Intune
Covers enrollment strategy selection, step-by-step platform enrollment guidance for Windows, iOS/iPadOS, macOS, and Android, plus enrollment restrictions and troubleshooting.
- Choose an enrollment strategy
- Enroll Windows devices using Microsoft Intune
- Enroll iOS and iPadOS devices
- Enroll macOS devices
- Enroll Android devices
- Configure enrollment restrictions
- Troubleshoot device enrollment
Deploy Windows devices using Windows Autopilot
Covers Windows Autopilot registration, deployment profiles, pre-provisioning, monitoring, and common troubleshooting scenarios.
- Understand Windows Autopilot scenarios and benefits
- Register and import devices into Autopilot
- Configure Autopilot profiles and deployment modes
- Pre-provision devices using Autopilot
- Assign profiles and monitor Autopilot deployments
- Troubleshoot Autopilot deployment issues
Configure device profiles and policy management using Microsoft Intune
Configure and assign device configuration and compliance policies, and analyze Group Policy migrations using Microsoft Intune.
- Understand device configuration profiles and their role in policy enforcement
- Create configuration profiles
- Assign configuration profiles using groups and filters
- Create compliance policies
- Assign compliance policies using groups and filters
- Analyze and migrate Group Policy using Group Policy analytics
- Troubleshoot device configuration and policy application issues
Monitor and maintain devices using Microsoft Intune
Use Endpoint Analytics, proactive remediation, reporting, and automation to monitor and maintain device health and compliance.
- Understand the role of monitoring in endpoint management
- Use Endpoint Analytics to monitor device health and performance
- Use Remediations to fix common device issues
- Monitor Windows Update rings and feature update deployments
- View device and policy health in the Intune admin center
- Generate and interpret device and compliance reports
- Automate management tasks using PowerShell
Manage Windows updates and lifecycle using Microsoft Intune
Configure update rings, feature updates, Hotpatch, and Autopatch to manage Windows servicing and lifecycle using Intune.
- Understand the Windows servicing model and update types
- Implement update rings and feature update policies in Intune
- Configure and manage Hotpatch with Microsoft Intune
- Manage Windows servicing channels for enterprise devices
- Implement Windows Autopatch for automated update management
- Troubleshoot update deployment and compliance issues
- Retire and reset devices using Microsoft Intune
Troubleshoot device and policy issues using Microsoft Intune
Investigate and resolve device enrollment, configuration, and policy application issues using Intune diagnostics and remediation techniques.
- Understand the troubleshooting workflow in Microsoft Intune
- Troubleshoot device enrollment and compliance failures
- Troubleshoot configuration profile and policy conflicts
- Use logs and diagnostics to investigate device issues
- Use the Intune Troubleshooting blade for user-based diagnostics
- Automate issue resolution using remediation scripts
Deploy and manage applications using Microsoft Intune
Plan and deploy applications across Windows devices using Microsoft Intune, including Microsoft Store, Microsoft 365, Win32, and line-of-business apps.
- Example scenario
- Understand application deployment options in Microsoft Intune
- Plan application deployment for your organization
- Deploy Microsoft Store apps using Microsoft Intune
- Deploy Microsoft 365 apps using Microsoft Intune
- Deploy Win32 apps using Microsoft Intune
- Deploy line-of-business (LOB) apps using Microsoft Intune
- Configure app availability, targeting, and install behavior
- Configure app update and assignment settings
- Monitor app deployment and troubleshoot failures
- Manage app deployment failures using logs and troubleshooting tools
- Key takeaways
Implement application protection and security using Microsoft Intune
Plan, configure, assign, monitor, and troubleshoot Microsoft Intune Mobile Application Management (MAM) and App Protection Policies to secure corporate data on BYOD and corporate devices.
- Understand Mobile Application Management (MAM) and App Protection Policies
- Plan application protection strategies for BYOD and corporate devices
- Configure App Protection Policies for unenrolled BYOD devices
- Configure App Protection Policies for enrolled corporate devices
- Define data protection, encryption, and app restriction settings
- Define access requirements and conditional launch behaviors
- Configure Conditional Access policies for application access control
- Assign and monitor App Protection Policies
- Troubleshoot application protection policy issues
Manage application lifecycle and user experience using Microsoft Intune
Learn how to manage applications across the full Microsoft Intune lifecycle, including deployment, configuration, protection, monitoring, update, and retirement.
- Understand application lifecycle management in Microsoft Intune
- Update and retire applications in Microsoft Intune
- Assign applications using groups, filters, and targeting
- Manage user and device groups for application delivery
- Configure default application settings and user experience
- Enforce compliance requirements for applications
- Monitor app lifecycle and usage analytics
Monitor and optimize application performance using Microsoft Intune
Monitor application health, deployment status, and performance across managed devices using Microsoft Intune reports and Endpoint analytics.
- Understand app health and performance in modern environments
- Monitor app deployment and compliance using Intune
- Track installation success and failure reports
- Use Endpoint Analytics to measure app performance and startup times
- Use Intune reporting tools to identify and resolve performance issues
- Optimize user experience with actionable insights
Manage Enterprise App Catalog applications
Discover, deploy, configure, update, and monitor prepackaged Win32 applications from the Microsoft Intune Enterprise App Catalog.
- Discover and deploy apps from the catalog
- Configure default install and detection settings
- Monitor updates and supersedence
- Use the Managed Apps report for insights
Implement endpoint security with Microsoft Defender and Microsoft Intune
Onboard devices to Microsoft Defender with Microsoft Intune, configure security baselines and EDR policies, and investigate and triage incidents in the Microsoft Defender portal.
- Understand how Microsoft Defender protects endpoints
- Onboard devices to Microsoft Defender using Intune
- Configure Microsoft Defender endpoint security settings and baselines
- Configure Endpoint Detection and Response policies
- Investigate and respond to endpoint threats using Microsoft Defender
- Monitor and triage incidents in the Microsoft Defender portal
Implement device encryption and security policies using Microsoft Intune
Deploy and manage BitLocker device encryption on Windows endpoints using Microsoft Intune, including policy configuration, recovery key management, and compliance monitoring.
- Understand the importance of device encryption for compliance and security
- Configure BitLocker policies using Microsoft Intune
- Manage BitLocker recovery keys and user self-service options
- Monitor BitLocker compliance and encryption status in Microsoft Intune
- Audit device encryption with Microsoft Defender
Implement advanced threat protection using Microsoft Intune and Microsoft Defender
Apply layered endpoint defenses by combining Microsoft Intune policy enforcement with Microsoft Defender for SaaS app discovery, Attack Surface Reduction rules, Zero Trust device access, and proactive remediation.
- Understand advanced threat protection strategies for endpoint environments
- Discover and monitor cloud apps with Microsoft Defender
- Configure Attack Surface Reduction rules using Microsoft Intune
- Apply Zero Trust principles for endpoint protection
Enforce compliance and remediate security issues by using Microsoft Intune
Design, assign, and monitor Microsoft Intune compliance policies, configure graduated noncompliance actions, and automate remediation for noncompliant devices.
- Understand compliance policies and risk-based enforcement
- Create compliance policies for supported platforms
- Assign and scope compliance policies using groups and filters
- Configure actions for noncompliant devices
- Remediate device issues using compliance and configuration policies
- Monitor and report on compliance results
Secure mobile access using Microsoft Tunnel
Learn how to deploy and manage Microsoft Tunnel Gateway to securely extend access to on-premises resources for enrolled and unenrolled mobile devices.
- Configure Tunnel gateway
- Extend support to MAM devices
- Monitor and troubleshoot Tunnel connections
Implement Microsoft Cloud PKI
Stand up a cloud-hosted certificate authority hierarchy in Microsoft Intune, automate SCEP issuance and renewal, and monitor certificate health across managed devices.
- Set up cloud-based PKI
- Automate certificate issuance and renewal
- Monitor certificate health and compliance
Automate endpoint management using PowerShell and Microsoft Graph
Automate Microsoft Intune operations at scale using PowerShell and the Microsoft Graph PowerShell SDK, including device management, policy assignment, and secure authentication.
- Understand automation options for managing Microsoft Intune
- Register and secure Microsoft Graph API access for Intune
- Authenticate and use the Microsoft Graph API for Intune
- Use PowerShell to run scripts against Microsoft Intune
- Automate device and policy tasks using Microsoft Graph
- 08 - Summary
Optimize device management using AI and Copilot tools
Use AI and Copilot tools across Microsoft Intune and Microsoft Defender to prioritize endpoint issues, investigate threats, and apply targeted remediation actions.
- Understand the role of AI in modern endpoint management
- Use Microsoft Security Copilot to investigate threats
- Use AI-powered recommendations in Microsoft Intune
- Use Microsoft Defender insights to support endpoint decisions
Monitor and optimize endpoint performance using Microsoft Intune
Monitor endpoint performance and implement proactive remediation using Microsoft Intune and Endpoint analytics.
- Understand performance optimization in cloud-managed environments
- Use Endpoint Analytics to optimize device performance
- Configure remediation scripts using Microsoft Intune
- Monitor endpoint reliability and user experience with Endpoint Analytics
Implement reporting and data visibility using Microsoft Intune
Access, customize, and share Microsoft Intune reports, workbooks, and dashboards to deliver actionable operational insights across your organization.
- Understand built-in reporting options in Microsoft Intune
- Customize Intune reports and filters for actionable insights
- Use Microsoft Intune workbooks and dashboards
- Export, schedule, and share reporting data securely
Apply RBAC and admin delegation in Microsoft Intune
Configure role-based access control, scope tags, role assignments, and auditing to delegate Microsoft Intune administration safely across your organization.
- Understand RBAC and scope tags in Microsoft Intune
- Assign roles and permissions for multi-admin environments
- Configure scoped administration for regional or business unit separation
- Audit admin actions and monitor configuration changes
Maintain tenant health and support readiness
Monitor Microsoft Intune tenant health, configure proactive alerts, use built-in support tools, and document changes to maintain operational readiness.
- Monitor tenant health and Intune service communications
- Configure alerts and notifications in Microsoft Intune
- Use support tools and troubleshoot service-related issues
- Document tenant changes and establish operational baselines
Explore Microsoft Intune Suite capabilities
Identify Microsoft Intune Suite add-on components, evaluate how they extend core Intune capabilities, and plan licensing and deployment strategies for advanced endpoint management scenarios.
- Understand the purpose and value of the Microsoft Intune Suite
- Identify key components of the Microsoft Intune Suite
- Compare Microsoft Intune Suite features to core Intune capabilities
- Plan licensing and deployment strategies for the Microsoft Intune Suite
Implement Remote Help scenarios using Microsoft Intune
Configure and deploy Microsoft Intune Remote Help, assign helper and sharer permissions, monitor support sessions, and evaluate privacy considerations for managed remote support.
- Understand Remote Help and its role in end-user support
- Configure and deploy Remote Help with Microsoft Intune
- Support and monitor Remote Help sessions
- Evaluate privacy, permission, and compliance considerations
Analyze advanced device signals with Microsoft Intune Suite
Use Microsoft Intune Suite Advanced Analytics, anomaly detection, and integration with Microsoft Defender to surface real-time device health and risk signals and drive risk-based policy decisions.
- Explore advanced reporting with Intune Suite analytics
- Identify and respond to anomaly detection insights
- Integrate Intune with Microsoft Defender for proactive threat signals
- Use advanced insights to support risk-based policy decisions
Evaluate Endpoint Privilege Management with Microsoft Intune
Evaluate Microsoft Intune Endpoint Privilege Management — design just-in-time elevation, configure elevation policies, monitor elevated actions, and troubleshoot and refine the deployment.
- Understand just-in-time elevation in Endpoint Privilege Management
- Configure elevation policies and rules
- Monitor elevated actions and review reports
- Troubleshoot and refine an EPM deployment
Explore Windows 365 for cloud PC deployment
Explore Windows 365 — its role for cloud PC deployment, how it compares to traditional VDI, licensing and prerequisites, common use cases, and endpoint experience options like Windows 365 Boot and Switch.
- Understand the role of Windows 365
- Compare Windows 365 to traditional VDI
- Identify Windows 365 licensing, service plans, and prerequisites
- Identify Windows 365 use cases
- Explore the Windows 365 endpoint experience
Configure and manage Windows 365 with Microsoft Intune
Configure Windows 365 provisioning policies, assign and manage Cloud PCs, apply configuration profiles and security policies, and monitor Cloud PC usage, performance, and health with Microsoft Intune.
- Set up Windows 365 provisioning policies
- Assign and manage Cloud PCs
- Apply configuration profiles and policies to Cloud PCs
- Monitor Cloud PC usage, performance, and health
Explore Azure Virtual Desktop
Explore Azure Virtual Desktop architecture, compare it with Windows 365, and learn how host pools, session hosts, and scaling deliver virtualized Windows desktops and apps from Azure.
- Understand Azure Virtual Desktop architecture
- Compare Azure Virtual Desktop with Windows 365
- Examine host pools, session hosts, and scaling
Integrate Azure Virtual Desktop with Microsoft Intune
Enroll Azure Virtual Desktop session hosts in Microsoft Intune, apply compliance and configuration policies, monitor and troubleshoot virtual desktops, and address governance, licensing, and hybrid scenarios.
- Enroll Azure Virtual Desktop session hosts in Microsoft Intune
- Apply compliance and configuration policies to session hosts
- Monitor and troubleshoot Azure Virtual Desktop with Microsoft Intune
- Address governance, licensing, and hybrid scenarios