Get in Touch
 Duration 21 hours

Course Outline

Module 1: Introduction and Core Concepts

  • Understanding Microsoft Intune and Endpoint Manager
  • Interaction with Configuration Manager (co-management, cloud attach)
  • Advantages of modern endpoint management strategies
  • Fundamental concepts: devices, applications, data, and users
  • Intune architecture, role definitions, and licensing

Module 2: Identity and Access Management

  • Key concepts in Microsoft Entra ID and Azure AD
  • Directory synchronization from AD to Entra ID (Azure AD Connect)
  • Device join mechanisms: Azure AD Join and Hybrid AD Join
  • Managing roles, groups, and permissions within Intune
  • Implementing Conditional Access and its synergy with Intune

Module 3: Device Enrollment Strategies

  • Enrollment processes for Windows, iOS, Android, and macOS
  • Windows Autopilot: core concepts, profiles, and workflows
  • Automated enrollment via Apple DEP and Android Zero-touch
  • Differentiating between BYOD and corporate device management
  • Distinguishing MDM from MAM (Mobile Device Management vs. Mobile Application Management)

Module 4: Configuration and Compliance Frameworks

  • Defining device compliance policies
  • Setting up configuration policies (Configuration Profiles)
  • Applying device restrictions and security controls
  • Establishing App Protection Policies
  • Creating conditional access policies driven by compliance status

Module 5: Application Management

  • App categories in Intune: Line of Business (LOB), Win32, Microsoft Store, and web apps
  • Cycles of app deployment, installation, removal, and updates
  • Securing application data
  • Balancing application policies with corporate data needs
  • Managing licenses and user assignments

Module 6: Update and Patch Management

  • Integrating Windows Update for Business with Intune
  • Defining feature and quality update policies
  • Utilizing deployment ring models
  • Tracking and monitoring update compliance
  • Formulating update strategies for corporate settings

Module 7: Security and Protection Measures

  • Microsoft Defender for Endpoint and its integration with Intune
  • Applying Microsoft security baselines and templates
  • Threat mitigation (antimalware, firewall, and more)
  • Device encryption (BitLocker) and encryption policy enforcement
  • Certificate management and secure VPN/Wi-Fi profile configuration

Module 8: Monitoring, Reporting, and Troubleshooting

  • Utilizing dashboards and standard reports
  • Analyzing logs and diagnostics (e.g., enrollment issues, policy conflicts)
  • Leveraging Intune support and troubleshooting utilities
  • Working with administrative portals (device portal, company portal)
  • Configuring alerts and notification systems

Module 9: Advanced Scenarios and Integrations

  • Co-management workflows with Configuration Manager
  • Managing devices without traditional enrollment (Autopilot for existing devices)
  • Connecting with other Microsoft services (Defender, Azure, Copilot, etc.)
  • Automation techniques using PowerShell and Graph API
  • Governance models and enterprise-scale architecture
  • Best practices for solution design and execution

Summary and Future Directions

Requirements

  • A solid grasp of Microsoft 365 and Azure environments
  • Practical experience in managing Windows or mobile devices
  • Knowledge of organizational IT security standards

Target Audience

  • System administrators
  • Endpoint management specialists
  • IT professionals responsible for enterprise device and security policy management

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories