The Microsoft Intune and Cloud Endpoint Management Training Course provides participants with practical knowledge of modern cloud-based endpoint and device management using Microsoft Intune. The course introduces the fundamentals of cloud endpoint management and covers device enrollment, configuration, application deployment, security policies, compliance management, and ongoing administration of organizational devices.
Participants will learn how Microsoft Intune supports the management of Windows, macOS, Android, and iOS/iPadOS devices within a modern enterprise environment. The course also introduces Microsoft Entra ID integration, Conditional Access concepts, Windows Autopilot, endpoint security, application protection, monitoring, reporting, and troubleshooting.
The course is designed for IT professionals who need a general but practical understanding of implementing and administering Microsoft Intune and cloud-managed endpoints.
Duration 4 Days – 28 hrs.
Objectives
- Explain the fundamentals of cloud-based endpoint management.
- Understand the role and architecture of Microsoft Intune.
- Navigate and configure the Microsoft Intune admin center.
- Understand the relationship between Microsoft Intune and Microsoft Entra ID.
- Plan and configure device enrollment.
- Manage Windows, macOS, Android, and iOS/iPadOS devices.
- Create and deploy device configuration profiles.
- Configure device compliance policies.
- Understand and implement Conditional Access concepts for managed devices.
- Deploy and manage applications through Microsoft Intune.
- Configure mobile application management and application protection policies.
- Implement endpoint security policies.
- Understand Windows Autopilot and modern Windows provisioning.
- Manage device updates and configuration settings.
- Monitor device health, compliance, and deployment status.
- Perform common Intune administration and troubleshooting tasks.
- Apply recommended practices for managing enterprise endpoints through the cloud.
Target Audience
- IT Administrators
- System Administrators
- Microsoft 365 Administrators
- Endpoint Administrators
- Desktop Support Engineers
- Technical Support Specialists
- Infrastructure Engineers
- Cloud Administrators
- Network and Systems Engineers
- IT Operations Personnel
- IT Security Personnel
- Professionals responsible for organizational laptops, desktops, smartphones, and tablets
- IT professionals transitioning from traditional endpoint management to cloud-based management
Prerequisites
- Basic knowledge of Windows operating systems.
- Basic understanding of Microsoft 365 environments.
- Familiarity with user accounts, groups, devices, and permissions.
- Basic knowledge of networking and internet connectivity.
- General understanding of IT administration and endpoint management.
- Familiarity with Microsoft Entra ID is beneficial but not required.
- Previous Microsoft Intune experience is not required.
Course Outline
Day 1 – Microsoft Intune and Cloud Endpoint Management Fundamentals
Module 1: Introduction to Modern Endpoint Management
- Traditional versus cloud-based endpoint management
- Modern workplace and endpoint management concepts
- Cloud-managed and hybrid-managed environments
- Endpoint management lifecycle
- Overview of Microsoft Intune capabilities
- Supported operating systems and device platforms
Module 2: Microsoft Intune Architecture and Administration
- Microsoft Intune architecture
- Microsoft Intune admin center
- Understanding tenants, users, groups, and devices
- Licensing considerations
- Administrative roles and permissions
- Role-Based Access Control (RBAC)
- Scope tags and administrative boundaries
Module 3: Microsoft Entra ID Integration
- Introduction to Microsoft Entra ID
- Users and groups
- Device identities
- Microsoft Entra registered devices
- Microsoft Entra joined devices
- Hybrid Microsoft Entra joined devices
- Intune and Microsoft Entra integration
- Device ownership and management concepts
Module 4: Device Enrollment and Management
- Device enrollment concepts
- Enrollment planning
- Enrollment restrictions
- Enrollment status
- Corporate versus personally owned devices
- Windows device enrollment
- Android device enrollment
- Apple iOS/iPadOS enrollment
- macOS enrollment
- Device enrollment troubleshooting
Day 2 – Device Configuration, Compliance, and Access
Module 5: Device Configuration Management
- Configuration profiles
- Settings Catalog
- Administrative Templates
- Device restrictions
- Security and operating system settings
- Network and connectivity profiles
- Wi-Fi and VPN configuration concepts
- Certificate deployment concepts
- Profile assignment and deployment
Module 6: Device Compliance Management
- Understanding device compliance
- Creating compliance policies
- Windows compliance policies
- Android and Apple device compliance
- Compliance policy assignments
- Compliance status
- Noncompliant devices
- Actions for noncompliance
- Monitoring compliance results
Module 7: Conditional Access Fundamentals
- Introduction to Conditional Access
- Relationship between Intune and Conditional Access
- Users, groups, applications, and conditions
- Requiring compliant devices
- Device-based access controls
- Common Conditional Access scenarios
- Planning secure access policies
- Avoiding administrator lockout scenarios
Module 8: Managing Device Settings and Policies
- Policy assignment concepts
- User-based versus device-based assignments
- Include and exclude groups
- Assignment filters
- Policy conflicts
- Configuration precedence
- Monitoring policy deployment
- Troubleshooting configuration policies
Day 3 – Application Management and Endpoint Security
Module 9: Application Management with Microsoft Intune
- Application management concepts
- Supported application types
- Microsoft Store applications
- Microsoft 365 Apps
- Win32 applications
- Line-of-business applications
- Application assignments
- Required and available applications
- Application installation monitoring
- Application deployment troubleshooting
Module 10: Mobile Application Management
- Mobile Device Management versus Mobile Application Management
- Application protection policies
- Protecting organizational information
- Data transfer restrictions
- Copy, paste, save, and sharing controls
- Managed applications
- Protecting corporate data on personal devices
- Selective wipe concepts
Module 11: Endpoint Security Management
- Endpoint security architecture
- Security baselines
- Antivirus policies
- Microsoft Defender integration concepts
- Firewall policies
- Disk encryption and BitLocker management
- Attack surface reduction concepts
- Account protection
- Security policy assignments
- Monitoring endpoint security
Module 12: Device Updates and Maintenance
- Windows update management
- Update rings
- Feature update policies
- Quality updates
- Driver and firmware update concepts
- Restart behavior
- Update deployment monitoring
- Maintaining endpoint security and reliability
Day 4 – Windows Autopilot, Monitoring, and Troubleshooting
Module 13: Windows Autopilot and Modern Provisioning
- Introduction to Windows Autopilot
- Traditional imaging versus modern provisioning
- Windows Autopilot deployment scenarios
- Device registration
- Deployment profiles
- Enrollment Status Page
- User-driven deployment
- Pre-provisioned deployment concepts
- Autopilot deployment lifecycle
- Troubleshooting Autopilot deployment
Module 14: Remote Device Administration
- Device inventory
- Device properties
- Synchronizing devices
- Restarting managed devices
- Remote lock
- Retire and wipe operations
- Fresh Start and device reset concepts
- Lost or compromised device considerations
- Remote administrative actions
Module 15: Monitoring and Reporting
- Intune monitoring capabilities
- Device configuration reports
- Compliance reports
- Application deployment reports
- Endpoint security reports
- Enrollment monitoring
- Device health information
- Audit logs
- Operational monitoring practices
Module 16: Intune Troubleshooting and Administration Best Practices
- Common enrollment problems
- Policy deployment issues
- Application deployment failures
- Compliance troubleshooting
- Synchronization problems
- Device communication issues
- Reviewing logs and diagnostic information
- Troubleshooting workflow
- Administrative best practices
- Security and governance considerations
- Planning an effective cloud endpoint management environment

