Get in Touch
 Duration 21 hours

Course Outline

Module 1: Foundations and Core Concepts

  • Overview of Microsoft Intune / Endpoint Manager
  • Integration with Configuration Manager (co-management, cloud attach)
  • Advantages of modern endpoint management strategies
  • Core elements: devices, applications, data, and user identities
  • Intune architecture, role definitions, and licensing models

Module 2: Identity and Access Control

  • Key concepts in Microsoft Entra ID / Azure AD
  • Synchronizing data from AD to Entra ID via Azure AD Connect
  • Device join methodologies: Azure AD Join and Hybrid AD Join
  • Managing roles, groups, and permissions within Intune
  • Conditional Access policies and their synergy with Intune

Module 3: Device Registration and Onboarding

  • Enrollment techniques for Windows, iOS, Android, and macOS
  • Windows Autopilot: principles, profiling, and workflow
  • Automated enrollment using DEP (Apple) and Zero-touch (Android)
  • Differentiating between BYOD and corporate-owned device management
  • Distinguishing MDM from MAM (Mobile Device Management vs Mobile Application Management)

Module 4: Configuration and Compliance Standards

  • Defining device compliance policies
  • Establishing configuration policies and profiles
  • Applying device restrictions and security controls
  • Implementing App Protection Policies
  • Conditional access rules driven by compliance status

Module 5: Application Lifecycle Management

  • Application categories in Intune: LOB, Win32, Microsoft Store, and web apps
  • Processes for deploying, installing, updating, and removing applications
  • Safeguarding application data
  • Applying policies to isolate corporate data from personal apps
  • Managing licenses and user assignments

Module 6: Updates and Patch Management

  • Integrating Windows Update for Business with Intune
  • Defining feature and quality update policies
  • Implementing deployment ring models
  • Tracking and monitoring update status
  • Strategies for update rollout in enterprise settings

Module 7: Security and Threat Mitigation

  • Microsoft Defender for Endpoint and its integration with Intune
  • Applying Microsoft security baselines and templates
  • Threat protection measures (antimalware, firewall, etc.)
  • Device encryption (BitLocker) and related encryption policies
  • Managing certificates and secure VPN/Wi-Fi profiles

Module 8: Monitoring, Reporting, and Diagnostics

  • Utilizing dashboards and standard reports
  • Reviewing logs and diagnostics (e.g., enrollment issues, policy failures)
  • Leveraging built-in Intune support and troubleshooting utilities
  • Navigating administration portals (device and company portals)
  • Setting up alerts and notification systems

Module 9: Advanced Scenarios and Integrations

  • Co-management workflows with Configuration Manager
  • Managing existing devices without traditional enrollment (Autopilot for legacy fleets)
  • Integration with other Microsoft services (Defender, Azure, Copilot, etc.)
  • Automation via PowerShell and Graph API
  • Governance frameworks and enterprise-scale architecture
  • Best practices for design and implementation

Conclusion and Path Forward

Requirements

  • Solid understanding of Microsoft 365 and Azure infrastructure
  • Practical experience in Windows or mobile device administration
  • Knowledge of core organizational IT security standards

Target Audience

  • System administrators
  • Endpoint management specialists
  • IT professionals responsible for enterprise device oversight and security policy enforcement

Testimonials (1)

Upcoming Courses

Related Categories