Microsoft Intune Endpoint Management Training Course

5 days Information Technology Certificate on completion
Course codeSD-IT-018
Duration5 days
LevelIntermediate
CategoryInformation Technology
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Managing Windows, macOS, iOS and Android endpoints through Microsoft Intune requires more than creating a few compliance policies. IT teams must decide how devices are enrolled, which identities and groups receive configuration, how corporate data is protected on unmanaged devices, and how conditional access responds when a device falls out of compliance. Poorly structured Intune tenants create duplicate policies, inconsistent user experiences, excessive local administration and avoidable security exceptions. This course equips endpoint administrators to design and operate an Intune service that is supportable at scale.

Participants work through the Microsoft Intune administration lifecycle: tenant and role planning, device enrolment, Microsoft Entra ID groups, configuration profiles, endpoint security, application deployment, compliance policies, Conditional Access integration, Windows Autopilot and reporting. They learn to distinguish device management from mobile application management, select appropriate policy types, use assignment filters, manage update rings, investigate deployment failures and build an escalation path using Intune reports and logs. The course also addresses practical governance decisions, including naming conventions, pilot rings, policy ownership and change control.

Instructor-led demonstrations are followed by guided labs in a Microsoft 365 test environment and scenario-based design workshops. Participants configure a managed endpoint baseline, deploy applications and updates, create compliance-driven access controls, and troubleshoot realistic enrolment and policy issues. Each participant leaves with a documented Intune implementation blueprint containing an enrolment approach, policy catalogue, assignment model, pilot plan, reporting measures and remediation actions that can be adapted for their own organisation.

The course is suited to professionals who already support endpoint services or Microsoft 365 environments and now need hands-on responsibility for Intune administration, deployment or service improvement.

Course objectives

By the end of this course, participants will be able to:

  • Design an Intune tenant structure using administrative roles, scope tags, Microsoft Entra ID groups and assignment filters
  • Configure Windows, macOS, iOS and Android enrolment methods, including automated device enrolment and Windows Autopilot
  • Build device configuration profiles for security settings, certificates, Wi-Fi, VPN and endpoint restrictions
  • Create compliance policies and connect their evaluation results to Microsoft Entra Conditional Access decisions
  • Deploy Win32, Microsoft Store and mobile applications with requirement rules, detection logic and staged assignments
  • Implement endpoint security policies for Microsoft Defender, BitLocker, firewall settings and attack surface reduction rules
  • Manage Windows feature updates, quality updates and update rings through Intune policy assignments
  • Produce an Intune operational blueprint with policy ownership, pilot rings, reporting metrics and troubleshooting procedures

Benefits of attending

For you

  • Gain practical experience configuring Intune policies rather than only interpreting Microsoft documentation
  • Build evidence for endpoint administration, Microsoft 365 operations and modern workplace roles
  • Learn to diagnose enrolment, application deployment and compliance failures using Intune reporting data
  • Develop a reusable policy and rollout blueprint for presenting Intune improvements to technical stakeholders
  • Strengthen capability to lead Windows Autopilot and cloud endpoint management migrations

For your organisation

  • Establishes more consistent endpoint configurations across Windows, macOS, iOS and Android devices
  • Reduces manual device provisioning effort through repeatable enrolment and Windows Autopilot workflows
  • Improves access control by linking device compliance status to Microsoft Entra Conditional Access policies
  • Lowers endpoint security exposure through standardised encryption, firewall, Defender and update controls
  • Creates a documented operating model for pilot deployments, policy ownership, reporting and incident remediation

Target competencies

Intune policy designDevice enrolment managementConditional Access integrationApplication deploymentEndpoint security configurationAutopilot deployment planning

Who should attend

  • Endpoint Administrators — who configure, secure and support corporate devices across multiple operating systems
  • Microsoft 365 Administrators — who need to connect Intune controls with Microsoft Entra ID and Conditional Access
  • Desktop Support Leads — who are moving from image-based PC management to cloud-managed endpoints
  • Infrastructure Engineers — who design device services, identity integrations and operational support models
  • Cybersecurity Analysts — who need to validate device compliance and endpoint security enforcement
  • IT Service Delivery Managers — who oversee endpoint standards, rollout governance and support performance

Requirements and prerequisites

Participants should have working experience administering Windows client devices and supporting users in a business IT environment. Familiarity with Microsoft 365 administration, Microsoft Entra ID users and groups, basic networking concepts, and the purpose of device configuration and security policies is assumed. Experience with PowerShell, Microsoft Configuration Manager or prior Intune administration is helpful but not required. Participants do not need to be software developers or security specialists. A laptop capable of accessing a modern web browser and a Microsoft 365 training tenant, where provided, is sufficient for the practical labs.

Training methodology

The course combines focused instructor demonstrations in the Microsoft Intune admin center with guided configuration labs using a controlled Microsoft 365 environment. Participants enrol test devices, create and assign policies, deploy applications, interpret compliance results and investigate failed deployments. Short case studies require teams to choose controls for scenarios such as remote workers, BYOD access and a new-device rollout. Each day closes with a practical output that feeds into an end-of-course Intune implementation blueprint and 90-day application plan.

Course outline

Day 1: Intune foundations, architecture and enrolment

  • Microsoft Intune service architecture and endpoint management use cases
  • Microsoft Entra ID tenants, users, groups and dynamic membership
  • Intune administrative roles, scope tags and least-privilege administration
  • Device platform support, licensing considerations and management boundaries
  • Corporate-owned, personally owned and shared-device management models
  • Windows enrolment methods and enrolment restriction policies
  • Windows Autopilot profiles, device preparation and deployment profiles

Workshop: Configure a pilot Intune structure with administrative roles, device groups, enrolment restrictions and a Windows Autopilot deployment profile.

Day 2: Configuration profiles and endpoint security

  • Settings catalog versus templates and administrative templates
  • Configuration profile design for Windows, macOS, iOS and Android
  • Wi-Fi, VPN, certificate and email profile deployment
  • Endpoint security policy categories and policy conflict management
  • BitLocker encryption, recovery key escrow and disk encryption reporting
  • Microsoft Defender Antivirus, firewall and attack surface reduction policies
  • Security baselines, policy assignments and assignment filters

Workshop: Build and test a secure Windows endpoint baseline containing encryption, Defender, firewall, Wi-Fi and configuration settings.

Day 3: Applications, updates and mobile data protection

  • Managed application lifecycle and application assignment strategies
  • Win32 application packaging with the Microsoft Win32 Content Prep Tool
  • Requirement rules, detection rules, dependencies and supersedence
  • Microsoft Store app deployment and app update behaviour
  • iOS and Android application deployment through managed app stores
  • Windows update rings, feature updates and expedited quality updates
  • App protection policies for mobile application management without enrolment

Workshop: Package and deploy a Win32 application, configure staged update rings and create an app protection policy for mobile users.

Day 4: Compliance, Conditional Access and operations

  • Compliance policy settings, grace periods and non-compliance actions
  • Device compliance reporting and common status interpretation
  • Microsoft Entra Conditional Access policy design for managed access
  • Risk-based access decisions and Microsoft Defender for Endpoint signals
  • Device actions, remote support considerations and lifecycle management
  • Intune reporting, audit logs and endpoint analytics
  • Troubleshooting enrolment, policy conflicts and application deployment failures

Workshop: Investigate a simulated non-compliant device, identify the policy cause and design a Conditional Access response and remediation workflow.

Day 5: Governance, migration and implementation planning

  • Intune policy naming standards, documentation and ownership models
  • Pilot rings, phased deployment and rollback planning
  • Co-management and migration considerations for Microsoft Configuration Manager environments
  • Endpoint governance for BYOD, contractors and shared devices
  • Change control, exception handling and policy review cycles
  • Service metrics for compliance, deployment success and update adoption
  • Intune implementation roadmap and operational handover planning

Workshop: Produce and present an Intune implementation blueprint covering policy architecture, pilot deployment, controls, metrics and support handover.

Tools & standards covered

Microsoft Intune admin center, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You do not need previous hands-on Intune administration, but you should understand Windows endpoint support and basic Microsoft 365 administration. The course starts by establishing the tenant, identity and enrolment model before progressing to policy and troubleshooting labs.

Bring a laptop with a current web browser and permission to use the course lab environment. A controlled Microsoft 365 and Intune environment is used for exercises, so access to your production tenant is not required.

It is designed for endpoint administrators, Microsoft 365 administrators, desktop support leads and infrastructure engineers with responsibility for managed devices. Security professionals and service delivery managers also benefit when they need to understand how device compliance is enforced operationally.

This course concentrates on Microsoft Intune as the cloud endpoint management platform, including enrolment, policy design, applications, updates, compliance and Autopilot. It covers Microsoft Configuration Manager only where co-management or migration decisions affect an Intune implementation.

You can apply the methods to build pilot groups, standardise policies, deploy applications, improve update control and investigate compliance failures. The implementation blueprint provides a practical starting point for an internal Intune rollout or service improvement initiative.

You leave with a documented Intune implementation blueprint covering enrolment, policy assignments, endpoint security, compliance controls, pilot stages and reporting measures. You also receive a certificate of completion for the five-day instructor-led course.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Information Technology

5 Days Certificate

IT Governance for IT Managers Training Course

IT managers are routinely asked to deliver services faster, control technology risk, justify investment decisions, and prove that operationa…

5 Days Certificate

Retail IT Systems and Store Technology Management Training Course

Retail stores depend on interconnected point-of-sale, payment, network, endpoint, inventory, and customer-facing systems that must work reli…

5 Days Certificate

Public Sector IT Infrastructure Management Training Course

Public-sector IT teams must keep essential services available while operating within procurement rules, audit requirements, constrained budg…

5 Days Certificate

Docker Container Deployment and Management Training Course

Docker deployments often become fragile when teams rely on manually built images, inconsistent environment variables, untracked container ch…