Course Overview

Microsoft Intune is a cloud-based endpoint management platform that enables organizations to manage, secure, and monitor devices, applications, and corporate data from a centralized platform. With modern workplaces relying on Windows, Android, and iOS devices, Intune plays a critical role in enforcing security policies, supporting Zero Trust, and maintaining consistent endpoint configurations without depending on traditional on-premises management infrastructure. This course begins with Intune fundamentals, tenant and licensing setup, and Windows and mobile device enrollment. It then covers configuration profiles, compliance policies, Conditional Access, security baselines, Microsoft Defender for Endpoint integration, application deployment and protection, Attack Surface Reduction, Firewall, Endpoint Privilege Management, Windows Update for Business, monitoring and troubleshooting, and Windows Autopilot provisioning. Extensive hands-on labs reinforce each major capability. By completing this course, you will be able to deploy, manage, secure, monitor, troubleshoot, and provision enterprise endpoints using Microsoft Intune and its integrated Microsoft security services.

What You Will Learn

  • Understand Microsoft Intune architecture and how it integrates with Entra ID, Microsoft 365, and modern endpoint management.
  • Enroll and manage Windows 10 and Windows 11 devices using enterprise-ready Intune enrollment and management methods.
  • Configure and validate device compliance policies across Windows, iOS, and Android and understand their impact on Conditional Access.
  • Create, assign, and validate device compliance policies and understand how they impact Conditional Access decisions.
  • Deploy and troubleshoot applications using Microsoft Store apps, Win32 apps, and detection rules in Intune.
  • Apply security baselines and configuration profiles to harden endpoints and reduce attack surface.
  • Troubleshoot real-world Intune issues using device status, logs, policy sync, and endpoint validation techniques.
  • Understand Intune from a security and SOC perspective, including compliance signals, access control, and risk-based decisions.
  • Implement Windows Autopilot to automate zero-touch Windows device deployment using Microsoft Intune.
  • Create and assign Windows Autopilot Deployment Profiles, Dynamic Device Groups, and Enrollment Status Page (ESP) configurations.
  • Deploy enterprise applications during Windows Autopilot provisioning, including Microsoft 365 Apps and Google Chrome Enterprise.
  • Perform end-to-end Windows Autopilot deployments and troubleshoot common deployment issues using Microsoft Intune.

Program Curriculum

  • Training Introduction
  • Objectives
  • What is Intune?
  • Intune vs. SCCM
  • Intune + Entra ID + Defender = Unified Endpoint Security
  • Licensing Requirements
  • Supported Device Types
  • Lab: Creating a Tenant (onmicrosoft.com)
  • Lab: Activating E5 License (Trial)
  • Lab: Verify Intune Licensing and Portal Access
  • Lab: Configure MDM + WIP Authority
  • Lab: Create Intune Admin + Test User
  • Chapter 1 Quiz

  • Objectives
  • Why Enrolment Methods Matters?
  • Entra ID Join + Intune Auto-enrolment
  • What "Successful Enrolment" Really Mean?
  • Lab: Prepare Windows 10/11 Device for Intune Enrolment
  • Lab: Entra ID Join and Automatic Intune Enrolment
  • Lab: Validate Enrolment and MDM Management State
  • Mobile Device Enrolment (Android and iOS) - Objectives
  • Prepare Intune for Mobile Device Enrolment
  • Enrol Android BYOD Devices Using Work Profile
  • Configure Apple APNs for IOS Management
  • Enrol iOS Devices Using Company Portal
  • Validate and Compare Mobile Device Management
  • Lab: Connect Managed Google Play (Android Enterprise)
  • Lab: Enrol Android Device (Work Profile)
  • Lab: Configure Apple MDM Push Certificate (APNs)
  • Lab: Enrol iOS/iPadOS Device Using Company Portal
  • Chapter 2 Quiz

  • Objectives
  • Profile Types in Intune
  • Assignments, Scope Tags, and Filter
  • Verification and Troubleshooting
  • Lab: Create a Baseline Windows Hardening Profile (Settings Catalog) Part 1
  • Lab: Create a Baseline Windows Hardening Profile (Settings Catalog) Part 2
  • Lab: Device Restrictions: Block USB and Control Features
  • Lab: Block Control Panel Using Administrative Templates
  • Chapter 3 Quiz

  • Objectives
  • Device Compliance Fundamentals
  • Building Windows Compliance Policies
  • Conditional Access + Device Compliance
  • Testing Compliance vs. Non-compliant Behavior
  • Lab: Create a Windows Compliance Policy - Part 1
  • Lab: Verify and Resolve "BitLocker Not Compliant" - Part 2
  • Lab: Create a Conditional Access Policy Using Device Compliance
  • Lab: Test Compliant vs. Non-compliant Device Access
  • Chapter 4 Quiz

  • Objectives
  • Microsoft Security Baselines
  • Baselines vs. Configuration Profiles
  • What a Security Baselines Actually Configure
  • Applying a Security Baseline
  • Baseline Conflicts and Overlaps
  • Lab: Apply a Microsoft Security Baseline to Windows 11
  • Lab: Analyze Baseline Conflicts and Remediate Errors
  • Chapter 5 Quiz

  • Objectives
  • What is Microsoft Defender for Endpoint?
  • Defender for Endpoint Architecture and Intune Integration
  • Device Risk Levels and Threat Signals
  • Defender + Intune + Conditional Access
  • Onboarding Devices to Defender
  • Threat Detection, Alerts, and Automated Response
  • Defender Telemetry, Timeline, and Validation
  • Lab: Onboard Windows Device to Microsoft Defender for Endpoint
  • Lab: Trigger Defender Alerts and Investigate Incidents
  • Lab: Automated Response, Device Isolation, and Remediation
  • Lab: Defender Device Risk + Intune Compliance + Cond. Access Enforcement
  • Chapter 6 Quiz

  • Objectives
  • Application Types in Intune
  • WIN32 Application Packaging and Deployment
  • Microsoft Store App Deployment
  • Application Assignments and User Experience
  • App Protection Policies (MAM)
  • Validating App Deployment and Troubleshooting
  • Lab: Deploy a WIN32 App
  • Lab: Break a WIN32 App and Troubleshoot
  • Lab: Deploy Microsoft Store App
  • Lab: App Protection Policy (MAM) on iOS (Microsoft Edge)
  • Wrap-up
  • Chapter 7 Quiz

  • Objectives
  • Attack Surface Reduction (ASR)
  • Microsoft Defender Firewall Management
  • Endpoint Privilege Management (EPM)
  • Endpoint Security as a Zero Trust Control
  • Validation and Troubleshooting
  • Lab: Create an ASR Policy (Block Office Macros)
  • Lab: Create a Firewall Policy (Allow/Block App)
  • Lab: Test ASR, Validate Defender Logs
  • Chapter 8 Quiz

  • Objectives
  • Why Update Management Matters?
  • Windows Update for Business (WUfB) Basics
  • Update Rings and Deployment Strategy
  • User Experience and Restart Control
  • Monitoring, Compliance, and Troubleshooting
  • Lab: Create a Windows Update Ring
  • Wrap-up
  • Chapter 9 Quiz

  • Objectives
  • Intune Monitoring and Troubleshooting Portal
  • Reading Policy Deployment and Device Health Signal
  • Proactive Remediation and Scripts
  • Reporting and Exporting Evidence
  • Common Intune Problems and Real Fixes
  • Wrap-up
  • Lab: Use Intune Troubleshooting Portal
  • Lab: Export an Intune Management Report
  • Chapter 10 Quiz

  • Objectives
  • Autopilot Fundamentals
  • How Autopilot Works with Intune
  • User Experience Flow
  • Enterprise Use Cases
  • Key Limitations and Expectations
  • Lab: Register the Windows 11 Device with Windows Autopilot
  • Lab: Create and Assign a Windows Autopilot Deployment Profile
  • Lab: Deploy Required Corporate Applications
  • Lab: Deploy Google Chrome Enterprise
  • Lab: Configure the Enrolment Status Page (ESP)
  • Lab: Perform the Windows Autopilot Deployment
  • Lab: Troubleshoot Windows Autopilot Deployments
  • Chapter 11 Quiz
Load more modules

Instructor

Yasir Mehmood

Yasir holds industry-recognized certifications including GIAC GCIH, GSEC, GFACT, EC-Council CEH, CompTIA Security+, Microsoft SC-200, and MS-500. His teaching philosophy is simple: learn by doing. Through real-world enterprise labs, practical demonstrations, and step-by-step guidance, he helps learners understand not just how technologies work, but why and where they are applied. His goal is to empower cybersecurity professionals with practical skills, confidence, and expertise to advance their careers.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50