Table of Contents
Introduction
Module 1: Prepare infrastructure for devices
Lesson 1: Add devices to Microsoft Entra ID
1.1 Overview of identity solutions
1.2 Choose an appropriate device join type
1.3 Plan and implement groups for devices in Microsoft Entra ID
Lesson 2: Enroll devices to Microsoft Intune
2.1 Configure enrollment settings
2.2 Configure enrollment for Windows and iOS
2.3 Configure enrollment for Android devices
Lesson 3: Implement identity and compliance
3.1 Manage roles in Intune
3.2 Implement compliance policies
3.3 Implement Conditional Access policies
3.4 Configure Windows Hello for Business, SSPR, and MFA
3.5 Implement and manage LAPS and local group membership
3.6 Synchronizing on-premises users and groups
Module 2: Manage and maintain devices
Lesson 4: Deploy and upgrade Windows clients by using cloud-based tools
4.1 Select a deployment tool
4.2 Plan and implement provisioning packages
4.3 Overview of Windows Autopilot
4.4 Create and assign deployment profiles
4.5 Extract and upload hardware information
4.6 Deploy Windows 11
4.7 Troubleshoot Autopilot deployment
4.8 Plan and implement device upgrades for Windows 11
4.9 Implement a Windows 365 cloud PC deployment
Lesson 5: Plan and implement device configuration profiles
5.1 Plan device profiles
5.2 Migrate settings from Group Policy
5.3 Implement device profiles
5.4 Manage device profiles
5.5 Monitor, report, and implement Endpoint Analytics
Lesson 6: Implement Intune Suite add-on capabilities
6.1 Implement Intune Suite add-ons
6.2 Implement Microsoft Tunnel
Lesson 7: Perform remote actions on devices
7.1 Manage Intune devices
7.2 Implement Windows PowerShell Remoting
7.3 Implement Windows Admin Center
Module 3: Manage applications
Lesson 8: Deploy and update apps
8.1 Deploy apps with Intune
8.2 Deploy Microsoft 365 Apps
8.3 Manage apps
Lesson 9: Plan and implement app protection and app configuration policies
9.1 Plan and implement app protection policies
9.2 Plan and implement app configuration policies and implement Conditional Access policies for app protection policies
Module 4: Protect devices
Lesson 10: Configure endpoint security
10.1 Implement Microsoft Defender Credential Guard
10.2 Implement Microsoft Defender Exploit Guard
10.3 Implement Microsoft Defender Application Guard
10.4 Implement Microsoft Defender for Endpoint
10.5 Integrate Microsoft Defender Application Control
10.6 Manage Microsoft Defender Antivirus
10.7 Create disk encryption policies
10.8 Create firewall policies
10.9 Plan and implement security baselines
10.10 Configure Attack surface reduction policies
Lesson 11: Manage device updates by using Intune
11.1 Plan for Windows updates
11.2 Deploy device updates
11.3 Monitor updates
Summary