Get in Touch
 Duration 21 hours

Course Outline

Module 1: Introduction and Fundamentals

  • Overview of Microsoft Intune and Endpoint Manager
  • Integration with Configuration Manager (including co-management and cloud attach)
  • Advantages of modern endpoint management approaches
  • Core concepts: devices, applications, data, and users
  • Intune architecture, roles, and licensing models

Module 2: Identity and Access

  • Key concepts of Microsoft Entra ID (formerly Azure AD)
  • Synchronizing Active Directory to Entra ID using Azure AD Connect
  • Types of device joins: Azure AD Join and Hybrid AD Join
  • Managing roles, groups, and permissions within Intune
  • Conditional Access policies and their integration with Intune

Module 3: Device Enrollment

  • Enrollment methods for Windows, iOS, Android, and macOS
  • Windows Autopilot: underlying concepts, profiles, and workflows
  • Automated enrollment using DEP (Apple) and Zero-touch (Android)
  • Distinguishing between personal device (BYOD) and corporate device management
  • Comparison of MDM (Mobile Device Management) and MAM (Mobile Application Management)

Module 4: Configuration and Compliance Policies

  • Establishing device compliance policies
  • Creating configuration policies (Configuration Profiles)
  • Applying device restrictions and security controls
  • Implementing App Protection Policies
  • Defining conditional access policies linked to compliance status

Module 5: Application Management

  • Categorizing applications in Intune: Line of Business (LOB), Win32, Microsoft Store, and web apps
  • Processes for deploying, installing, uninstalling, and updating applications
  • Safeguarding application data
  • Distinguishing between application policies and corporate data protection
  • Managing licenses and assignments

Module 6: Updates and Patches

  • Integrating Windows Update for Business with Intune
  • Setting policies for feature and quality updates
  • Implementing deployment ring models
  • Monitoring the status of updates
  • Strategizing updates within corporate environments

Module 7: Security and Protection

  • Integrating Microsoft Defender for Endpoint with Intune
  • Utilizing Microsoft security baselines and templates
  • Threat protection measures (including antimalware and firewall settings)
  • Managing device encryption (BitLocker) and related policies
  • Handling certificate management and secure VPN/Wi-Fi profiles

Module 8: Monitoring, Reporting, and Troubleshooting

  • Reviewing dashboards and default reports
  • Analyzing logs and diagnostics (such as enrollment errors and policy management issues)
  • Leveraging support and troubleshooting tools within Intune
  • Using administration portals (device and company portals)
  • Configuring alerts and notifications

Module 9: Advanced Scenarios and Integrations

  • Implementing co-management with Configuration Manager
  • Managing devices without standard enrollment (e.g., Autopilot for existing devices)
  • Integrating with other Microsoft services (Defender, Azure, Copilot, etc.)
  • Automating tasks using PowerShell and the Graph API
  • Developing governance strategies and enterprise-scale structures
  • Adopting best practices for design and implementation

Summary and Next Steps

Requirements

  • A solid grasp of Microsoft 365 and Azure environments
  • Practical experience in managing Windows or mobile devices
  • Knowledge of fundamental organizational IT security principles

Target Audience

  • System administrators
  • Endpoint management specialists
  • IT professionals responsible for enterprise device and security policy management

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories