Phase 4: Endpoint Management
Intune and Windows endpoint-management evidence covering enrolment, compliance, security, application deployment, delegated administration and Windows Update management.
This phase documents Windows enrolment, compliance, Conditional Access, configuration, application delivery, Intune RBAC, browser security and Windows Update management through Microsoft Intune.
Lab 15: Cloud-Native Entra Join and Intune Enrolment
Microsoft Entra join, automatic MDM enrolment and managed-device validation.
Open LabLab 16: Hybrid Entra Join and Intune Enrolment
Hybrid device identity, Intune enrolment and device-side validation.
Open LabLab 17: Device Compliance Policy Pilot
Compliance requirements, pilot assignment and reporting.
Open LabLab 18: Conditional Access Admin MFA Baseline
Report-only Conditional Access, MFA requirements and sign-in validation.
Open LabLab 19: Intune Configuration Profiles
Settings Catalog configuration, pilot assignment and endpoint validation.
Open LabLab 20: Intune Device Restrictions Baseline
Windows device restrictions, pilot assignment and policy verification.
Open LabLab 21: Intune App Deployment and Company Portal
Application assignment, Company Portal delivery and installation validation.
Open LabLab 22: Intune RBAC and Scope Tags
Delegated administration, scope groups and scope-tag awareness.
Open LabLab 23: Microsoft Edge Security Baseline
Endpoint Security baseline assignment and browser-policy validation.
Open LabLab 24: Windows Update Ring Pilot
Update ring configuration, pilot deployment and restart behaviour.
Open LabLab 25: Feature Update Policy Windows 11
Target Windows feature version and validate deployment reporting.
Open Lab