Get in Touch
 Duration 21 hours

Course Outline

Module 1: Introduction and Core Concepts

  • Overview of Microsoft Intune and Endpoint Manager
  • Integration with Configuration Manager (co-management, cloud attach)
  • Advantages of modern endpoint management strategies
  • Foundational elements: devices, applications, data, and users
  • Intune architecture, role definitions, and licensing models

Module 2: Identity and Access Management

  • Core principles of Microsoft Entra ID / Azure AD
  • Syncing from on-premises AD to Entra ID (using Azure AD Connect)
  • Device joining mechanisms: Azure AD Join, Hybrid AD Join
  • Managing roles, groups, and permissions within Intune
  • Conditional Access and its synergy with Intune

Module 3: Device Enrollment Processes

  • Enrollment techniques for Windows, iOS, Android, and macOS
  • Windows Autopilot: key concepts, profile setup, and workflows
  • Automated enrollment via DEP (Apple) and Zero-touch (Android)
  • Distinguishing between personal (BYOD) and corporate device management
  • Differences between MDM and MAM (Mobile Device Management / Mobile Application Management)

Module 4: Configuration and Compliance Frameworks

  • Establishing device compliance standards
  • Setting up configuration policies (Configuration Profiles)
  • Applying device restrictions and security controls
  • Implementing App Protection Policies
  • Conditional access rules driven by compliance status

Module 5: Application Lifecycle Management

  • Categories of Intune applications: Line of Business (LOB), Win32, Microsoft Store, and web apps
  • Managing deployment, installation, removal, and updates of applications
  • Safeguarding application data
  • Balancing application policies with corporate data protection
  • Managing licenses and assignments

Module 6: Updates and Patch Management

  • Integrating Windows Update for Business with Intune
  • Defining feature and quality update policies
  • Utilizing deployment ring models
  • Tracking update status and progress
  • Formulating update strategies for corporate environments

Module 7: Security and Threat Defense

  • Microsoft Defender for Endpoint and its integration with Intune
  • Leveraging Microsoft security baselines and templates
  • Threat mitigation measures (antimalware, firewall, etc.)
  • Device encryption (BitLocker) and encryption policy configuration
  • Certificate administration and secure VPN/Wi-Fi profile setup

Module 8: Monitoring, Reporting, and Issue Resolution

  • Reviewing dashboards and standard reports
  • Analyzing logs and diagnostics (e.g., enrollment issues, policy enforcement)
  • Utilizing support and troubleshooting tools within Intune
  • Operating administration portals (device portal, company portal)
  • Managing alerts and notifications

Module 9: Advanced Scenarios and Integrations

  • Co-management strategies with Configuration Manager
  • Managing devices without traditional enrollment (e.g., Autopilot for existing devices)
  • Integrating with other Microsoft services (Defender, Azure, Copilot, etc.)
  • Automation using PowerShell and Graph API
  • Governance frameworks and enterprise-scale architecture
  • Best practices for design and deployment

Summary and Future Steps

Requirements

  • A solid grasp of Microsoft 365 and Azure environments
  • Practical experience in managing Windows or mobile devices
  • Knowledge of organizational IT security frameworks

Target Audience

  • System administrators
  • Endpoint management experts
  • IT professionals responsible for enterprise device oversight and security policies

Testimonials (1)

Related Categories