Looking for your active Pro access before showing Course Notes. This usually takes just a moment.
Course Notes preview
Unlock Pro for the full per-exam reference guide.
Preview one piece from each section. Pro includes every Course Notes section, summary, key point, common mistake, exam tip, related-question review, and PDF export.
Includes full Course Mode and Course Notes.
Section 1Manage and secure applicationsPreview
More in this section
3 more key points in Pro version
1 more common mistakes in Pro version
1 more exam tips in Pro version
32 more related questions in Pro version
Summary
This objective covers deploying and updating applications within Intune, emphasizing the diverse behaviors associated with different application types and assignment options. Understanding these differences is crucial for successful application management and troubleshooting. Implement app protection and app configuration policies to manage and secure applications, focusing on data protection and access control strategies.
Key Points
Intune supports multiple application types (Store, Line-of-Business, Microsoft 365 Apps, Web, Win32) each with distinct packaging, detection, requirement, assignment, and update behaviors.
Common Mistakes
Store apps are managed through the Microsoft Store, while Win32 apps require Intune Management Extensions and detailed detection rules.
Exam Tips
Carefully identify the application type before selecting any configuration options. The type dictates the available management controls.
Section 2Prepare infrastructure for devicesPreview
More in this section
5 more key points in Pro version
2 more common mistakes in Pro version
2 more exam tips in Pro version
42 more related questions in Pro version
Summary
This objective covers enrolling devices into Microsoft Intune, including Windows automatic enrollment and other methods. Understanding prerequisites, restrictions, and enrollment methods is critical for successful device integration. This objective covers preparing infrastructure for devices by implementing identity and compliance controls within Intune. It centers on leveraging Intune's capabilities to enforce device security posture, including utilizing Conditional Access and understanding the nuances of compliance policies, grace periods, and credential types. Add devices to Microsoft Entra ID by selecting the appropriate device identity type. Understanding the differences between registered, joined, and hybrid joined devices is crucial for proper device management and security.
Key Points
MDM User Scope: Defines the scope of devices eligible for enrollment.
Common Mistakes
Platform Restrictions vs. Device Limits: Platform restrictions block entire device types (e.g., Android), while device limits restrict the number of devices a user can enroll.
Exam Tips
Check the enrollment method selected and its associated prerequisites.
Section 3Protect devicesPreview
More in this section
3 more key points in Pro version
1 more common mistakes in Pro version
1 more exam tips in Pro version
32 more related questions in Pro version
Summary
Implement endpoint security policies and Defender integration by leveraging focused management, evaluating baselines, and understanding the limitations of each component. Manage operating system updates by leveraging Windows update rings to control deployment stages and user experience, alongside feature update policies for targeted releases, and Autopatch for automated management.
Intune Endpoint Security Policies vs. Security Baselines: Policies are focused, while baselines are recommended and require evaluation.
Exam Tips
Prioritize focused policy deployments over broad baseline rollouts.
Section 4Manage and maintain devicesPreview
More in this section
7 more key points in Pro version
3 more common mistakes in Pro version
3 more exam tips in Pro version
52 more related questions in Pro version
Summary
Implement Windows deployment and provisioning using Windows Autopilot, leveraging OEM-installed Windows images and cloud-based configurations. Focus on user-driven or self-deploying modes. Manage devices by using Intune Suite capabilities, specifically focusing on Endpoint Privilege Management, Remote Help, and Cloud PKI to control access and manage certificates. Configure and manage device configuration profiles by leveraging the settings catalog, custom profiles, and assignment filters to deliver targeted device settings and enforce compliance. This objective covers using Intune's remote actions to manage devices and diagnose issues. It covers actions like Retire, Sync, Restart, Wipe, and Collect Diagnostics, emphasizing the importance of verifying action status and understanding the implications of each action.
Key Points
Autopilot utilizes a cloud-based configuration alongside an OEM-installed Windows image for device provisioning. Device preparation establishes the initial configuration.
Common Mistakes
User-driven Autopilot requires a user sign-in and is designed for individual devices, whereas self-deploying mode is for shared or kiosk devices and does not require user credentials.
Exam Tips
Focus on the specific requirements of the deployment scenario.
Section 5Optimize endpoint operations by using automation, monitoring, and reportingPreview
More in this section
3 more key points in Pro version
1 more common mistakes in Pro version
1 more exam tips in Pro version
27 more related questions in Pro version
Summary
Monitor and improve endpoint operations by leveraging data-driven insights, automated remediation, and comprehensive reporting. Automate Intune endpoint management using PowerShell and Microsoft Graph. Implement robust automation strategies focusing on least privilege, error handling, and secure authentication to ensure reliable and scalable operations.
Key Points
Endpoint Analytics Insights identify conditions to investigate, not definitive root causes.
Common Mistakes
Endpoint Analytics insights are hypotheses needing validation.
Exam Tips
Prioritize Endpoint Analytics evidence to understand the specific device condition.
Search catalog
Find a practice exam
Flexible search understands AI-901, ai901, ai 901, 901, ai, network plus, and saa c03.