Learning Path 1: Prepare infrastructure for devices using Microsoft Intune and Microsoft Entra ID
Module 1: Understand endpoint management strategies and Microsoft Intune
- What is Microsoft Intune and how does it work?
- Compare Configuration Manager, Intune, and co-management.
- Understand the role of Microsoft Entra ID in Intune.
- Evaluate device management models.
- Explore MDM capabilities in Intune.
Module 2: Configure Microsoft Entra ID for device and policy management
- Understand the role of Microsoft Entra ID in endpoint management.
- Create and manage users and groups in Microsoft Entra ID.
- Assign Microsoft Entra ID roles for device management.
- Configure Microsoft Entra ID device registration settings.
- Use dynamic group membership and filters in Microsoft Entra ID.
Module 3: Administer device identity and authentication using Microsoft Entra ID
- Understand device identities in Microsoft Entra ID.
- Compare device registration, Microsoft Entra join, and hybrid join.
- Understand authentication methods including key trust, certificate trust, and TPM.
- Configure device trust and join settings.
- Validate and troubleshoot device identity and trust issues.
Module 4: Plan and implement device enrollment using Microsoft Intune
- Choose an enrollment strategy.
- Enroll Windows devices using Microsoft Intune.
- Enroll iOS and iPadOS devices.
- Enroll macOS devices.
- Enroll Android devices.
- Configure enrollment restrictions.
- Troubleshoot device enrollment.
Module 5: Deploy Windows devices using Windows Autopilot
- Understand Windows Autopilot scenarios and benefits.
- Register and import devices into Autopilot.
- Configure Autopilot profiles and deployment modes.
- Pre-provision devices using Autopilot.
- Assign profiles and monitor Autopilot deployments.
- Troubleshoot Autopilot deployment issues.
Learning Path 2: Manage and maintain devices using Microsoft Intune
Module 6: Configure device profiles and policy management using Microsoft Intune
- Understand device configuration profiles and their role in policy enforcement.
- Create configuration profiles.
- Assign configuration profiles using groups and filters.
- Create compliance policies.
- Assign compliance policies using groups and filters.
- Analyze and migrate Group Policy using Group Policy analytics.
- Troubleshoot device configuration and policy application issues.
Module 7: Monitor and maintain devices using Microsoft Intune
- Monitor device health and performance.
- Use Endpoint Analytics.
- Use proactive remediations.
- Generate compliance and device reports.
- Automate routine management tasks with PowerShell.
Module 8: Manage Windows updates and lifecycle using Microsoft Intune
- Understand Windows servicing models.
- Configure update rings.
- Configure feature update policies.
- Implement Windows Autopatch.
- Configure Hotpatch.
- Maintain Windows device update compliance and lifecycle.
Module 9: Troubleshoot device and policy issues using Microsoft Intune
- Troubleshoot enrollment failures.
- Troubleshoot compliance issues.
- Identify and resolve policy conflicts.
- Use diagnostic tools and logs.
- Use the Intune Troubleshooting blade.
- Automate issue remediation.
Learning Path 3: Manage applications using Microsoft Intune
Module 10: Deploy and manage applications using Microsoft Intune
- Identify application deployment options in Microsoft Intune.
- Plan application deployment strategies.
- Deploy Microsoft Store apps.
- Deploy Microsoft 365 Apps.
- Deploy Win32 apps.
- Deploy line-of-business applications.
- Configure application availability and targeting.
- Configure application update and assignment settings.
- Monitor application deployment.
- Troubleshoot installation failures.
Module 11: Implement application protection and security using Microsoft Intune
- Understand Mobile Application Management and App Protection Policies.
- Plan application protection strategies for BYOD and corporate devices.
- Configure App Protection Policies for unenrolled BYOD devices.
- Configure App Protection Policies for enrolled corporate devices.
- Define data protection, encryption, and application restriction settings.
- Define access requirements and conditional launch behavior.
- Configure Microsoft Entra Conditional Access for application access.
- Assign, monitor, and troubleshoot App Protection Policies.
Module 12: Manage application lifecycle and user experience using Microsoft Intune
- Understand application lifecycle management.
- Update and retire applications.
- Assign applications using groups, filters, and targeting.
- Manage user and device groups for application delivery.
- Configure application settings and user experience.
- Enforce application compliance requirements.
- Monitor application lifecycle and usage analytics.
Module 13: Monitor and optimize application performance using Microsoft Intune
- Understand application health and performance.
- Monitor application deployment and compliance.
- Track installation success and failure.
- Use Endpoint Analytics to measure application performance and startup times.
- Use Intune reporting to identify application issues.
- Optimize application user experience.
Module 14: Manage Enterprise App Catalog applications
- Discover and deploy applications from the Enterprise App Catalog.
- Configure default installation and detection settings.
- Monitor application updates and supersedence.
- Use the Managed Apps report to review deployment status.
Learning Path 4: Protect devices using Microsoft Intune
Module 15: Implement endpoint security with Microsoft Defender and Microsoft Intune
- Understand how Microsoft Defender protects endpoints.
- Onboard devices to Microsoft Defender using Intune.
- Configure Microsoft Defender endpoint security settings and baselines.
- Configure Endpoint Detection and Response policies.
- Investigate and respond to endpoint threats.
- Monitor and triage incidents.
Module 16: Implement device encryption and security policies using Microsoft Intune
- Understand device encryption requirements.
- Configure BitLocker policies.
- Manage BitLocker recovery keys.
- Configure user self-service recovery.
- Monitor encryption compliance.
- Audit device encryption.
Module 17: Implement advanced threat protection using Microsoft Intune and Microsoft Defender
- Understand advanced endpoint threat protection.
- Discover and monitor cloud applications.
- Configure Attack Surface Reduction rules.
- Apply Zero Trust principles to endpoint protection.
Module 18: Enforce compliance and remediate security issues by using Microsoft Intune
- Understand compliance policies and risk-based evaluation.
- Create compliance policies for supported platforms.
- Assign and scope compliance policies using groups and filters.
- Configure actions for noncompliant devices.
- Remediate device issues using compliance and configuration policies.
- Monitor and report compliance results.
Module 19: Secure mobile access using Microsoft Tunnel
- Configure Microsoft Tunnel Gateway.
- Extend Microsoft Tunnel support to MAM devices.
- Monitor and troubleshoot Tunnel connections.
Module 20: Implement Microsoft Cloud PKI
- Set up cloud-based PKI.
- Automate certificate issuance and renewal.
- Monitor certificate health and compliance.
Learning Path 5: Extend Endpoint Capabilities Using Microsoft Intune Suite
Module 21: Explore Microsoft Intune Suite capabilities
- Explore Microsoft Intune Suite capabilities.
- Understand Endpoint Privilege Management.
- Explore Enterprise Application Management.
- Explore Microsoft Intune Remote Help.
- Explore Microsoft Cloud PKI.
- Explore Microsoft Tunnel for Mobile Application Management.
- Explore Microsoft Intune Advanced Analytics.
Learning Path 6: Optimize endpoint operations using automation, monitoring, and reporting
Module 22: Automate endpoint management using PowerShell and Microsoft Graph
- Understand automation options for managing Microsoft Intune.
- Automate common Intune management tasks.
- Manage devices at scale using PowerShell.
- Use Microsoft Graph for endpoint management.
- Integrate security signals into endpoint workflows.
- Build repeatable endpoint management workflows.
Module 23: Use Microsoft Security Copilot agents for endpoint management
- Investigate threats identified by Security Copilot agents in Intune.
- Analyze device performance using Security Copilot agents.
- Review Security Copilot agent recommendations.
- Use agent recommendations to support endpoint management decisions.
Module 24: Monitor and optimize endpoint health using Intune
- Implement reporting and data visibility in Microsoft Intune.
- Customize reports and filters.
- Use workbooks and dashboards.
- Export reporting data.
- Monitor endpoint performance using Endpoint Analytics.
- Configure proactive remediation scripts.
- Analyze endpoint reliability and user experience.
- Monitor tenant health and Intune service communications.
- Configure alerts and notifications for policy and compliance changes.