| Section | Weight | Objectives |
| Topic 1: Prepare infrastructure for devices | 20-25% | - Add devices to Microsoft Entra ID
- 1. Choose an appropriate device join type, including device registration and Microsoft Entra join
- 2. Register devices to Microsoft Entra ID
- 3. Implement and manage Windows Local Administrator Password Solution (Windows LAPS) by using Microsoft Intune and Microsoft Entra ID
- 4. Plan and implement groups for devices in Microsoft Entra ID, including dynamic group membership rules
- 5. Join devices to Microsoft Entra ID
- 6. Configure Windows Hello for Business by using Intune
- 7. Manage the membership of local groups on Windows devices by using Intune
|
| Topic 2: Optimize endpoint operations by using automation, monitoring, and reporting | 10-15% | - Automate management tasks
- 1. Automate Intune management tasks by using PowerShell and Microsoft Graph
- 2. Analyze device performance by using Security Copilot agents in Intune
- 3. Extend device compliance by using PowerShell
- 4. Review and respond to Security Copilot agent recommendations to make management decisions
- 5. Investigate threats identified by Security Copilot agents in Intune
- Monitor and optimize health
- 1. Monitor tenant health and Intune service communications, including service health dashboards, Message Center notifications, and operational baselines
- 2. Monitor endpoint performance by using Endpoint Analytics, including proactive remediations, device health scores, and app startup performance
- 3. Analyze endpoint reliability and user experience scores, including startup performance, restart frequency, and application reliability metrics
- 4. Implement reporting and data visibility in Microsoft Intune, including customized reports and filters, workbooks, dashboards, and reporting data exports
- 5. Configure alerts and notifications for policy and compliance changes, including compliance drift, enrollment failures, and configuration conflicts
- 6. Configure and manage proactive remediation scripts, including detecting and fixing common device issues and scheduling remediation runs
|
| Topic 3: Manage and secure applications | 15-20% | - Deploy and update apps
- 1. Configure policies for Office apps by using Microsoft Intune or the Microsoft 365 Apps admin center
- 2. Deploy apps from platform-specific app stores by using Intune, including Apple Volume Purchase Program and Google Play
- 3. Deploy Microsoft 365 Apps by using Intune
- 4. Deploy Microsoft 365 Apps as part of a Windows Autopilot deployment, including the Office Deployment Tool or Microsoft Intune
- 5. Prepare applications for deployment by using Intune
- 6. Manage Microsoft 365 Apps by using the Microsoft 365 Apps admin center
- 7. Monitor app deployment status and troubleshoot installation failures by using Microsoft Intune
- 8. Deploy apps by using Intune, including Win32, line-of-business, and Microsoft Store apps
- 9. Configure Quiet Time policies for Android and iOS apps
- Plan and implement app protection and app configuration policies
- 1. Plan and implement app protection policies for managed and unmanaged (BYOD) devices by using Microsoft Intune
- 2. Implement Microsoft Entra Conditional Access policies for app protection policies
- 3. Plan and implement app configuration policies for managed apps and managed devices
|
| Topic 4: Protect devices | 15-20% | - Manage device updates
- 1. Implement Windows Autopatch and configure Hotpatch policies
- 2. Configure Windows client Delivery Optimization by using Intune
- 3. Plan for device updates by using Intune
- 4. Create and manage update policies for iOS/iPadOS and macOS devices by using the Settings Catalog in Microsoft Intune
- 5. Monitor device updates by using Intune
- 6. Manage Android updates by using configuration profiles or firmware-over-the-air deployments
- 7. Create and manage update rings, feature updates, and quality updates for Windows devices by using Intune
- Configure endpoint security
- 1. Plan and implement security baselines by using Microsoft Intune
- 2. Integrate Intune with Microsoft Defender for Endpoint, including EDR policies, endpoint threat investigation, and incident triage
- 3. Create antivirus policies by using Microsoft Intune
- 4. Configure Attack surface reduction policies by using Microsoft Intune, including Zero Trust principles for endpoint protection
- 5. Onboard devices into Microsoft Defender for Endpoint
- 6. Create and manage disk encryption policies by using Microsoft Intune, including BitLocker recovery keys, user self-service recovery, and encryption compliance monitoring
- 7. Create firewall policies by using Microsoft Intune
- 8. Configure App Control for Business policies by using Microsoft Intune
|
| Topic 5: Manage and maintain devices | 25-30% | - Plan and implement device configuration profiles
- 1. Create device configuration profiles for Android devices
- 2. Create device configuration profiles for macOS devices
- 3. Create device configuration profiles for specialty devices, including Teams Rooms, HoloLens 2, and Zebra
- 4. Create device configuration profiles for iOS/iPadOS devices
- 5. Target a profile by using assignment filters and enrollment time grouping
- 6. Create device configuration profiles for Windows devices, including importing ADMX files and using Group Policy analytics
- Perform remote actions on devices
- 1. Collect device diagnostics and logs by using Microsoft Intune, including the Troubleshooting blade for user-based diagnostics
- 2. Run a device query by using KQL
- 3. Update Microsoft Defender Antivirus security intelligence
- 4. Sync, restart, retire, or wipe devices
- 5. Rotate local administrator passwords
- 6. Perform bulk remote actions
- 7. Rotate BitLocker recovery keys
- Deploy and upgrade Windows clients by using cloud-based tools
- 1. Provision and configure Windows 365 Cloud PCs by using Intune, including provisioning policies, network connections, and image management
- 2. Choose between Windows Autopilot deployment profiles and device preparation policies
- 3. Create an Enrollment Status Page (ESP)
- 4. Implement Windows Backup and Restore by using Intune
- 5. Apply a device name template by using Windows Autopilot
- 6. Choose between Windows Autopilot deployment modes, including user-driven, pre-provisioning, and self-deploying
- 7. Implement Windows client deployment by using Windows Autopilot
- 8. Plan and implement device upgrades for Windows 11 by using Intune
- Implement Intune Suite add-on capabilities
- 1. Configure Microsoft Intune Remote Help
- 2. Plan and implement Microsoft Cloud PKI, including cloud-based PKI, automated certificate issuance, and certificate health monitoring
- 3. Configure Endpoint Privilege Management, including elevation policies, monitoring elevated actions, and EPM settings
- 4. Implement Microsoft Intune Advanced Analytics, including anomaly detection, proactive insights, and risk-based policy recommendations
- 5. Implement Microsoft Tunnel for Mobile Application Management, including Tunnel Gateway, MAM device support, and tunnel monitoring
- 6. Manage applications by using the Enterprise App Catalog
|