Microsoft Intune Endpoint Management Training Course
| Course code | SD-IT-018 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Managing Windows, macOS, iOS and Android endpoints through Microsoft Intune requires more than creating a few compliance policies. IT teams must decide how devices are enrolled, which identities and groups receive configuration, how corporate data is protected on unmanaged devices, and how conditional access responds when a device falls out of compliance. Poorly structured Intune tenants create duplicate policies, inconsistent user experiences, excessive local administration and avoidable security exceptions. This course equips endpoint administrators to design and operate an Intune service that is supportable at scale.
Participants work through the Microsoft Intune administration lifecycle: tenant and role planning, device enrolment, Microsoft Entra ID groups, configuration profiles, endpoint security, application deployment, compliance policies, Conditional Access integration, Windows Autopilot and reporting. They learn to distinguish device management from mobile application management, select appropriate policy types, use assignment filters, manage update rings, investigate deployment failures and build an escalation path using Intune reports and logs. The course also addresses practical governance decisions, including naming conventions, pilot rings, policy ownership and change control.
Instructor-led demonstrations are followed by guided labs in a Microsoft 365 test environment and scenario-based design workshops. Participants configure a managed endpoint baseline, deploy applications and updates, create compliance-driven access controls, and troubleshoot realistic enrolment and policy issues. Each participant leaves with a documented Intune implementation blueprint containing an enrolment approach, policy catalogue, assignment model, pilot plan, reporting measures and remediation actions that can be adapted for their own organisation.
The course is suited to professionals who already support endpoint services or Microsoft 365 environments and now need hands-on responsibility for Intune administration, deployment or service improvement.
Course objectives
By the end of this course, participants will be able to:
- Design an Intune tenant structure using administrative roles, scope tags, Microsoft Entra ID groups and assignment filters
- Configure Windows, macOS, iOS and Android enrolment methods, including automated device enrolment and Windows Autopilot
- Build device configuration profiles for security settings, certificates, Wi-Fi, VPN and endpoint restrictions
- Create compliance policies and connect their evaluation results to Microsoft Entra Conditional Access decisions
- Deploy Win32, Microsoft Store and mobile applications with requirement rules, detection logic and staged assignments
- Implement endpoint security policies for Microsoft Defender, BitLocker, firewall settings and attack surface reduction rules
- Manage Windows feature updates, quality updates and update rings through Intune policy assignments
- Produce an Intune operational blueprint with policy ownership, pilot rings, reporting metrics and troubleshooting procedures
Benefits of attending
For you
- Gain practical experience configuring Intune policies rather than only interpreting Microsoft documentation
- Build evidence for endpoint administration, Microsoft 365 operations and modern workplace roles
- Learn to diagnose enrolment, application deployment and compliance failures using Intune reporting data
- Develop a reusable policy and rollout blueprint for presenting Intune improvements to technical stakeholders
- Strengthen capability to lead Windows Autopilot and cloud endpoint management migrations
For your organisation
- Establishes more consistent endpoint configurations across Windows, macOS, iOS and Android devices
- Reduces manual device provisioning effort through repeatable enrolment and Windows Autopilot workflows
- Improves access control by linking device compliance status to Microsoft Entra Conditional Access policies
- Lowers endpoint security exposure through standardised encryption, firewall, Defender and update controls
- Creates a documented operating model for pilot deployments, policy ownership, reporting and incident remediation
Target competencies
Who should attend
- Endpoint Administrators — who configure, secure and support corporate devices across multiple operating systems
- Microsoft 365 Administrators — who need to connect Intune controls with Microsoft Entra ID and Conditional Access
- Desktop Support Leads — who are moving from image-based PC management to cloud-managed endpoints
- Infrastructure Engineers — who design device services, identity integrations and operational support models
- Cybersecurity Analysts — who need to validate device compliance and endpoint security enforcement
- IT Service Delivery Managers — who oversee endpoint standards, rollout governance and support performance
Requirements and prerequisites
Participants should have working experience administering Windows client devices and supporting users in a business IT environment. Familiarity with Microsoft 365 administration, Microsoft Entra ID users and groups, basic networking concepts, and the purpose of device configuration and security policies is assumed. Experience with PowerShell, Microsoft Configuration Manager or prior Intune administration is helpful but not required. Participants do not need to be software developers or security specialists. A laptop capable of accessing a modern web browser and a Microsoft 365 training tenant, where provided, is sufficient for the practical labs.
Training methodology
The course combines focused instructor demonstrations in the Microsoft Intune admin center with guided configuration labs using a controlled Microsoft 365 environment. Participants enrol test devices, create and assign policies, deploy applications, interpret compliance results and investigate failed deployments. Short case studies require teams to choose controls for scenarios such as remote workers, BYOD access and a new-device rollout. Each day closes with a practical output that feeds into an end-of-course Intune implementation blueprint and 90-day application plan.
Course outline
Day 1: Intune foundations, architecture and enrolment
- Microsoft Intune service architecture and endpoint management use cases
- Microsoft Entra ID tenants, users, groups and dynamic membership
- Intune administrative roles, scope tags and least-privilege administration
- Device platform support, licensing considerations and management boundaries
- Corporate-owned, personally owned and shared-device management models
- Windows enrolment methods and enrolment restriction policies
- Windows Autopilot profiles, device preparation and deployment profiles
Workshop: Configure a pilot Intune structure with administrative roles, device groups, enrolment restrictions and a Windows Autopilot deployment profile.
Day 2: Configuration profiles and endpoint security
- Settings catalog versus templates and administrative templates
- Configuration profile design for Windows, macOS, iOS and Android
- Wi-Fi, VPN, certificate and email profile deployment
- Endpoint security policy categories and policy conflict management
- BitLocker encryption, recovery key escrow and disk encryption reporting
- Microsoft Defender Antivirus, firewall and attack surface reduction policies
- Security baselines, policy assignments and assignment filters
Workshop: Build and test a secure Windows endpoint baseline containing encryption, Defender, firewall, Wi-Fi and configuration settings.
Day 3: Applications, updates and mobile data protection
- Managed application lifecycle and application assignment strategies
- Win32 application packaging with the Microsoft Win32 Content Prep Tool
- Requirement rules, detection rules, dependencies and supersedence
- Microsoft Store app deployment and app update behaviour
- iOS and Android application deployment through managed app stores
- Windows update rings, feature updates and expedited quality updates
- App protection policies for mobile application management without enrolment
Workshop: Package and deploy a Win32 application, configure staged update rings and create an app protection policy for mobile users.
Day 4: Compliance, Conditional Access and operations
- Compliance policy settings, grace periods and non-compliance actions
- Device compliance reporting and common status interpretation
- Microsoft Entra Conditional Access policy design for managed access
- Risk-based access decisions and Microsoft Defender for Endpoint signals
- Device actions, remote support considerations and lifecycle management
- Intune reporting, audit logs and endpoint analytics
- Troubleshooting enrolment, policy conflicts and application deployment failures
Workshop: Investigate a simulated non-compliant device, identify the policy cause and design a Conditional Access response and remediation workflow.
Day 5: Governance, migration and implementation planning
- Intune policy naming standards, documentation and ownership models
- Pilot rings, phased deployment and rollback planning
- Co-management and migration considerations for Microsoft Configuration Manager environments
- Endpoint governance for BYOD, contractors and shared devices
- Change control, exception handling and policy review cycles
- Service metrics for compliance, deployment success and update adoption
- Intune implementation roadmap and operational handover planning
Workshop: Produce and present an Intune implementation blueprint covering policy architecture, pilot deployment, controls, metrics and support handover.
Tools & standards covered
Microsoft Intune admin center, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
IT Governance for IT Managers Training Course
IT managers are routinely asked to deliver services faster, control technology risk, justify investment decisions, and prove that operationa…
Retail IT Systems and Store Technology Management Training Course
Retail stores depend on interconnected point-of-sale, payment, network, endpoint, inventory, and customer-facing systems that must work reli…
Public Sector IT Infrastructure Management Training Course
Public-sector IT teams must keep essential services available while operating within procurement rules, audit requirements, constrained budg…
Docker Container Deployment and Management Training Course
Docker deployments often become fragile when teams rely on manually built images, inconsistent environment variables, untracked container ch…