Get in Touch
 Duration 21 hours

Course Outline

Module 1: Introduction and Core Concepts

  • Overview of Microsoft Intune and Endpoint Manager.
  • Interactions with Configuration Manager (co-management, cloud attach).
  • Advantages of modern endpoint management approaches.
  • Key entities: devices, applications, data, and users.
  • Intune architecture, roles, and licensing models.

Module 2: Identity and Access Control

  • Core concepts of Microsoft Entra ID and Azure AD.
  • Syncing from AD to Entra ID using Azure AD Connect.
  • Device join methods: Azure AD Join and Hybrid AD Join.
  • Managing roles, groups, and permissions within Intune.
  • Integration of Conditional Access with Intune.

Module 3: Device Enrollment Processes

  • Enrollment methods for Windows, iOS, Android, and macOS.
  • Windows Autopilot: concepts, profiles, and workflows.
  • Automated enrollment via DEP (Apple) and Zero-touch (Android).
  • Distinguishing between personal (BYOD) and corporate device management.
  • Differences between MDM and MAM (Mobile Device Management vs Mobile Application Management).

Module 4: Configuration and Compliance Policies

  • Establishing device compliance policies.
  • Creating configuration policies (Configuration Profiles).
  • Applying device restrictions and security controls.
  • Implementing App Protection Policies.
  • Defining conditional access policies linked to compliance status.

Module 5: Application Management

  • Application types in Intune: Line of Business (LOB), Win32, Microsoft Store, and web apps.
  • Cycles of deployment, installation, uninstallation, and updates.
  • Safeguarding application data.
  • Balancing application policies with corporate data protection.
  • Managing licenses and assignments.

Module 6: Updates and Patch Management

  • Windows Update for Business and its integration with Intune.
  • Strategies for feature and quality updates.
  • Utilizing deployment ring models.
  • Tracking update status and compliance.
  • Effective update strategies in corporate settings.

Module 7: Security and Protection Mechanisms

  • Microsoft Defender for Endpoint and its synergy with Intune.
  • Applying Microsoft security baselines and templates.
  • Threat protection measures (antimalware, firewall, etc.).
  • Device encryption using BitLocker and related policies.
  • Certificate management and secure VPN/Wi-Fi profile configuration.

Module 8: Monitoring, Reporting, and Troubleshooting

  • Interpreting dashboards and standard reports.
  • Analyzing logs and diagnostics (e.g., enrollment errors, policy issues).
  • Leveraging built-in support and troubleshooting tools.
  • Utilizing administration portals (device and company portals).
  • Configuring alerts and notifications.

Module 9: Advanced Scenarios and Integrations

  • Co-management workflows with Configuration Manager.
  • Managing devices without traditional enrollment (e.g., Autopilot for existing devices).
  • Integrations with broader Microsoft services (Defender, Azure, Copilot, etc.).
  • Automation using PowerShell and the Graph API.
  • Designing governance strategies and enterprise-scale structures.
  • Best practices for system design and implementation.

Summary and Path Forward

Requirements

  • Basic understanding of Microsoft 365 and Azure environments
  • Practical experience with Windows or mobile device management
  • Knowledge of core organizational IT security principles

Target Audience

  • System administrators
  • Endpoint management specialists
  • IT professionals responsible for enterprise device and security policy management

Testimonials (1)

Related Categories