Phase 4: Endpoint Management

Intune and Windows endpoint-management evidence covering enrolment, compliance, security, application deployment, delegated administration and Windows Update management.

This phase documents Windows enrolment, compliance, Conditional Access, configuration, application delivery, Intune RBAC, browser security and Windows Update management through Microsoft Intune.

Lab 15: Cloud-Native Entra Join and Intune Enrolment

Microsoft Entra join, automatic MDM enrolment and managed-device validation.

Open Lab

Lab 16: Hybrid Entra Join and Intune Enrolment

Hybrid device identity, Intune enrolment and device-side validation.

Open Lab

Lab 17: Device Compliance Policy Pilot

Compliance requirements, pilot assignment and reporting.

Open Lab

Lab 18: Conditional Access Admin MFA Baseline

Report-only Conditional Access, MFA requirements and sign-in validation.

Open Lab

Lab 19: Intune Configuration Profiles

Settings Catalog configuration, pilot assignment and endpoint validation.

Open Lab

Lab 20: Intune Device Restrictions Baseline

Windows device restrictions, pilot assignment and policy verification.

Open Lab

Lab 21: Intune App Deployment and Company Portal

Application assignment, Company Portal delivery and installation validation.

Open Lab

Lab 22: Intune RBAC and Scope Tags

Delegated administration, scope groups and scope-tag awareness.

Open Lab

Lab 23: Microsoft Edge Security Baseline

Endpoint Security baseline assignment and browser-policy validation.

Open Lab

Lab 24: Windows Update Ring Pilot

Update ring configuration, pilot deployment and restart behaviour.

Open Lab

Lab 25: Feature Update Policy Windows 11

Target Windows feature version and validate deployment reporting.

Open Lab

← Previous Phase Microsoft Infrastructure