Explore Endpoint Management
Explore the concepts, technologies, and lifecycle processes used to manage enterprise endpoints across different operating systems, platforms, and device types.
- Explore modern endpoint management
- Examine the enterprise desktop lifecycle
- Compare Windows editions and capabilities
- Explore Windows installation and deployment methods
- Identify endpoint management planning considerations
- Explore Microsoft Intune as a unified endpoint management platform
Manage Microsoft Entra Identities
Prepare the identity infrastructure required to manage users, groups, devices, roles, and access within a Microsoft 365 environment.
- Explore Microsoft Entra ID
- Compare Microsoft Entra ID with Active Directory Domain Services
- Create and manage users and groups
- Configure administrative roles and role-based access control
- Manage device identities in Microsoft Entra ID
- Configure hybrid identity synchronization
- Manage identities by using PowerShell
Prepare Microsoft Intune for Device Management
Configure the Microsoft Intune tenant, administrative controls, device platforms, and enrollment settings required to manage organizational endpoints.
- Configure the Microsoft Intune tenant
- Configure supported device platforms
- Manage Intune roles and scope tags
- Configure enrollment restrictions
- Configure device categories and corporate identifiers
- Implement multi-admin approval
- Monitor Intune tenant and service health
Enroll Devices in Microsoft Intune
Implement enrollment methods for Windows, Apple, and Android devices and manage devices throughout the enrollment lifecycle.
- Configure automatic enrollment for Windows devices
- Enroll Windows devices in Microsoft Intune
- Configure Windows enrollment options
- Enroll macOS, iOS, and iPadOS devices
- Configure Apple automated device enrollment
- Configure Android Enterprise enrollment
- Manage personally owned and corporate-owned devices
- Troubleshoot device enrollment
Configure Device Profiles
Create and manage configuration profiles, security settings, and policies that control the behavior of managed devices.
- Create device configuration profiles
- Configure settings catalog policies
- Configure administrative templates
- Manage Windows device settings
- Configure Apple and Android device settings
- Configure shared and specialized devices
- Manage local users and groups
- Monitor configuration profile deployment
Manage Authentication, Access, and Compliance
Implement authentication, compliance, and access controls that protect organizational resources and support secure device access.
- Configure device compliance policies
- Configure compliance notifications and actions
- Integrate device compliance with Conditional Access
- Configure multifactor authentication
- Implement Windows Hello for Business
- Configure passwordless authentication
- Implement Windows Local Administrator Password Solution
- Monitor and troubleshoot device compliance
Deploy Windows Devices
Plan and implement modern Windows deployment and provisioning solutions using Microsoft Intune and Windows Autopilot.
- Plan Windows deployment strategies
- Configure Windows Autopilot deployment profiles
- Configure the Enrollment Status Page
- Deploy devices with Windows Autopilot
- Implement self-deploying and pre-provisioned deployment
- Manage Windows edition upgrades
- Configure Windows activation
- Implement Windows Backup and Restore
- Troubleshoot Windows deployment
Manage Device Updates
Plan, deploy, and monitor operating system and feature updates across managed endpoint platforms.
- Plan an endpoint update strategy
- Configure Windows update rings
- Deploy Windows feature and quality updates
- Configure driver and firmware updates
- Implement Windows Autopatch
- Configure Windows Hotpatch
- Manage Apple and Android operating system updates
- Configure Delivery Optimization
- Monitor and troubleshoot update deployment
Deploy and Manage Applications
Prepare, deploy, configure, update, and monitor applications across Windows, Apple, and Android devices.
- Prepare applications for deployment
- Deploy Win32 applications
- Deploy line-of-business applications
- Deploy Microsoft Store applications
- Deploy Microsoft 365 Apps
- Configure application requirements and dependencies
- Configure application supersedence
- Manage Apple and Android applications
- Monitor and troubleshoot application deployment
Protect Applications and Organizational Data
Use application protection and configuration policies to protect organizational information on managed and unmanaged devices.
- Configure application protection policies
- Protect data on personally owned devices
- Configure application configuration policies
- Implement data transfer and access restrictions
- Configure Conditional Access for protected applications
- Manage mobile application management without enrollment
- Monitor application protection status
- Troubleshoot application protection policies
Manage Endpoint Security
Configure Microsoft Intune and Microsoft Defender for Endpoint controls to secure devices, applications, identities, and organizational data.
- Configure endpoint security policies
- Manage Microsoft Defender Antivirus
- Configure Microsoft Defender Firewall
- Manage disk encryption and BitLocker
- Configure attack surface reduction policies
- Implement security baselines
- Configure App Control for Business
- Integrate Intune with Microsoft Defender for Endpoint
- Onboard devices to Microsoft Defender for Endpoint
- Monitor endpoint security and remediation status
Perform Remote Device Management
Manage, troubleshoot, secure, and retire enrolled devices using remote actions and diagnostic tools.
- Perform remote device actions
- Restart, rename, sync, and locate devices
- Retire, wipe, and delete devices
- Reset device passcodes
- Collect device diagnostics
- Review device logs and management status
- Perform bulk device actions
- Troubleshoot managed devices
Implement Microsoft Intune Suite Capabilities
Use advanced Microsoft Intune Suite capabilities to enhance endpoint security, application delivery, support, connectivity, and certificate management.
- Explore Microsoft Intune Suite capabilities
- Configure Endpoint Privilege Management
- Deploy applications from the Enterprise App Catalog
- Implement Microsoft Intune Remote Help
- Configure Microsoft Cloud PKI
- Implement Microsoft Tunnel
- Explore Advanced Analytics
- Evaluate Intune Suite licensing and deployment considerations
Manage Cloud-Based Desktops
Plan, deploy, configure, and manage cloud-hosted desktops using Windows 365 and Azure Virtual Desktop.
- Explore Windows 365 capabilities
- Plan Windows 365 Cloud PC deployment
- Configure provisioning policies
- Manage Cloud PC images and network connections
- Monitor and troubleshoot Cloud PCs
- Explore Azure Virtual Desktop
- Manage Azure Virtual Desktop endpoints
- Secure access to cloud-hosted desktops
Automate Endpoint Management
Use PowerShell and Microsoft Graph to automate administrative tasks, retrieve endpoint data, and manage Intune resources at scale.
- Explore endpoint management automation
- Manage Microsoft Intune with PowerShell
- Connect to Microsoft Graph
- Use Microsoft Graph PowerShell
- Retrieve device, user, policy, and application information
- Automate repetitive endpoint management tasks
- Manage resources through Microsoft Graph
- Apply permissions and security considerations to automation
Use Microsoft Security Copilot for Endpoint Management
Use Microsoft Security Copilot to investigate endpoint issues, analyze security information, summarize findings, and support administrative decision-making.
- Explore Microsoft Security Copilot capabilities
- Use natural language prompts for endpoint administration
- Investigate device and security issues
- Analyze endpoint security data
- Summarize incidents and recommendations
- Use Security Copilot with Microsoft Intune
- Use Security Copilot with Microsoft Defender for Endpoint
- Review AI-generated results before taking action
Monitor and Optimize Endpoint Operations
Monitor endpoint health, performance, compliance, security, and user experience using Intune reporting and analytics capabilities.
- Monitor device health and compliance
- Create and review Intune reports
- Use Endpoint Analytics
- Analyze startup performance and application reliability
- Use proactive remediations
- Create remediation scripts
- Monitor policy and application deployment
- Review operational dashboards and alerts
- Troubleshoot endpoint management issues