Get in Touch

Course Outline

Module 1: Overview and Core Principles

  • Overview of Microsoft Intune and Endpoint Manager capabilities
  • Integration with Configuration Manager (co-management, cloud attach scenarios)
  • Strategic advantages of modern endpoint management for government operations
  • Core components: device inventories, application deployment, data controls, and user administration
  • Intune architecture, role-based access control, and licensing requirements

Module 2: Identity Verification and Access Control

  • Microsoft Entra ID / Azure AD: foundational concepts and governance
  • Directory synchronization from on-premises AD to Entra ID (Azure AD Connect)
  • Device registration models: Azure AD Join and Hybrid AD Join
  • Definition of administrative roles, group structures, and permission sets in Intune
  • Conditional Access policies and their linkage to Intune compliance states

Module 3: Device Registration and Onboarding

  • Registration procedures for Windows, iOS, Android, and macOS platforms
  • Windows Autopilot: operational frameworks, profile definitions, and workflow processes
  • Automated onboarding via DEP (Apple) and Zero-touch deployment (Android)
  • Distinction between personal device (BYOD) protocols and corporate device management standards
  • Comparison of MDM (Mobile Device Management) and MAM (Mobile Application Management) approaches

Module 4: Configuration and Compliance Frameworks

  • Establishment of device compliance benchmarks and verification methods
  • Development of configuration policies (Configuration Profiles) for standardized settings
  • Implementation of device restrictions and security controls
  • Deployment of App Protection Policies to safeguard sensitive data
  • Enforcement of conditional access rules driven by compliance status

Module 5: Application Deployment and Governance

  • Categorization of applications in Intune: Line of Business (LOB), Win32, Microsoft Store, and web applications
  • Processes for application deployment, installation, removal, and version management
  • Strategies for protecting application-level data integrity
  • Differentiation between application policies and corporate data protection measures
  • Management of licensing entitlements and user/device assignments

Module 6: Update and Patch Management

  • Integration of Windows Update for Business with Intune workflows
  • Definition of feature update and quality update policies
  • Utilization of deployment ring models for phased rollouts
  • Continuous monitoring of update compliance and status
  • Formulation of update strategies aligned with corporate operational requirements

Module 7: Security Posture and Risk Mitigation

  • Integration of Microsoft Defender for Endpoint with Intune for unified threat defense
  • Application of Microsoft security baselines and standardized templates
  • Implementation of threat protection mechanisms, including antimalware and firewall rules
  • Device encryption protocols (BitLocker) and associated encryption policies
  • Management of certificates and secure communication profiles (VPN/Wi-Fi)

Module 8: Monitoring, Reporting, and Diagnostics

  • Analysis of executive dashboards and standard reporting modules
  • Review of logs and diagnostic data for enrollment and policy issues
  • Utilization of Intune support and troubleshooting utilities
  • Interaction with administration interfaces (device portal and company portal)
  • Configuration of alerts and notification systems for incident response

Module 9: Advanced Architectures and System Integrations

  • Deep-dive into co-management strategies with Configuration Manager
  • Management of existing devices using Autopilot without full re-enrollment
  • Integration pathways with adjacent Microsoft services (Defender, Azure, Copilot, etc.)
  • Automation techniques using PowerShell and the Microsoft Graph API
  • Development of governance strategies and enterprise-scale structural designs
  • Adoption of best practices for architectural design and implementation

Conclusion and Recommended Action Plan

Requirements

  • Working knowledge of Microsoft 365 and Azure environments
  • Practical experience in Windows or mobile device administration
  • Proficiency in organizational IT security principles and standards

Target Audience

  • System administrators responsible for infrastructure oversight
  • Endpoint management specialists
  • IT professionals charged with managing enterprise devices and security policy compliance
 21 Hours

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories