Contenu
Examine the enterprise desktop
After completing this module, you will be able to:
- Describe the benefits of Modern Management.
- Explain the enterprise desktop life-cycle model.
- Describe considerations for planning hardware strategies.
- Describe the steps in planning OS and app deployment.
- Describe considerations for post-deployment and retirement.
Explore Azure Active Directory
After this module, you should be able to:
- Describe Azure AD.
- Compare Azure AD to Active Directory Domain Services (AD DS).
- Describe how Azure AD is used as a directory for cloud apps.
- Describe Azure AD Premium P1 and P2.
- Describe Azure AD Domain Services.
Manage identities in Azure Active Directory
After this module, you should be able to:
- Describe RBAC and user roles in Azure AD.
- Create and manage users in Azure AD.
- Create and manage groups in Azure AD.
- Use Windows PowerShell cmdlets to manage Azure AD.
- Describe how you can synchronize objects from AD DS to Azure AD.
Manage device authentication
After completing this module, you will be able to:
- Describe Azure AD join.
- Describe Azure AD join prerequisites, limitations and benefits.
- Join device to Azure AD.
- Manage devices joined to Azure AD.
Enroll devices using Microsoft Endpoint Configuration Manager
After completing this module, you will be able to:
- Describe Microsoft Endpoint Manager.
- Understand the advantages of managing a client with Configuration Manager.
- Deploy the Configuration Manager client.
- Monitor the Configuration Manager client.
- Manage Configuration Manager devices.
Enroll devices using Microsoft Intune
After completing this module, you will be able to:
- Prepare Microsoft Intune for device enrollment.
- Configure Microsoft Intune for automatic enrollment.
- Explain how to enroll Windows, Android and iOS devices in Intune.
- Explain when and how to use Intune Enrollment Manager.
- Understand how to monitor and perform remote actions on enrolled devices.
Implement device profiles
After completing this module, you will be able to:
- Describe the various types of device profiles in Intune.
- Explain the difference between built-in and custom profiles.
- Create and manage profiles.
Monitor device profiles
After completing this module, you will be able to:
- Monitor the assignments of profiles.
- Understand how profiles are synchronized and how to manually force synchronization.
- Use PowerShell to execute and monitor scripts on devices.
Manage user profiles
After completing this module, you will be able to:
- Explain the various user profile types that exist in Windows.
- Describe how a user profile works.
- Configure user profiles to conserve space.
- Explain how to deploy and configure Folder Redirection.
- Explain Enterprise State Roaming.
- Configure Enterprise State Roaming for Azure AD devices.
Implement mobile application management
After this module, you should be able to:
- Explain Mobile Application Management
- Understand application considerations in MAM
- Explain how to use Configuration Manager for MAM
- Use Intune for MAM
- Implement and manage MAM policies
Deploy and update applications
After this module, you should be able to:
- Explain how to deploy applications using Intune
- Learn how to deploy applications using Group Policy
- Understand Microsoft Store for Business
- Learn how to configure Microsoft Store for Business
- Explain how to use Microsoft Store for Business
Administer applications
After this module, you should be able to:
- Explain how to manage apps in Intune
- Understand how to manage apps on non-enrolled devices
- Understand how to deploy Microsoft 365 Apps using Intune
- Learn how to configure and manage IE mode in Microsoft Edge
- Learn about app inventory options in Intune
Implement device data protection
After this module, you should be able to:
- Describe Windows Information Protection
- Plan for Windows Information Protection usage
- Implement and use Windows Information Protection
- Describe the Encrypting File System (EFS)
- Describe BitLocker
Manage Microsoft Defender for Endpoint
After this module, you should be able to:
- Describe Microsoft Defender for Endpoint
- Describe key capabilities of Microsoft Defender for Endpoint
- Describe Microsoft Defender Application Guard
- Describe Microsoft Defender Exploit Guard
- Describe Windows Defender System Guard
Manage Microsoft Defender in Windows client
After this module, you should be able to:
- Describe Windows Security capabilities
- Describe Windows Defender Credential Guard
- Manage Microsoft Defender Antivirus
- Manage Windows Defender Firewall
- Manage Windows Defender Firewall with Advanced Security
Protect identities in Azure AD
After this module, you should be able to:
- Describe Windows Hello for Business
- Describe Windows Hello deployment and management
- Describe Azure AD Identity Protection
- Describe and manage self-service password reset in Azure AD
- Describe and manage multi-factor authentication
Enable organizational access
- Describe how you can access corporate resources
- Describe VPN types and configuration
- Describe Always On VPN
- Describe how to configure Always On VPN
Implement device compliance policies
After this module, you should be able to:
- Describe device compliance policy
- Deploy a device compliance policy
- Describe conditional access
- Create conditional access policies
Generate inventory and compliance reports
After this module, you should be able to:
- Generate inventory reports and Compliance reports using Microsoft Intune
- Report and monitor device compliance
- Create custom reports using the Intune Data Warehouse
- Use the Microsoft Graph API for building custom reports
Assess deployment readiness
After completing this module, you will be able to:
- Describe the guidelines for an effective enterprise desktop deployment.
- Explain how to assess the current environment.
- Describe the tools that you can use to assess your current environment.
- Describe the methods of identifying and mitigating application compatibility issues.
- Explain considerations for planning a phased rollout.
Deploy using the Microsoft Deployment Toolkit
After completing this module, you will be able to:
- Describe the fundamentals of using images in traditional deployment methods.
- Describe the key benefits, limitations, and decisions when planning a deployment of – Windows using Microsoft Deployment Toolkit (MDT).
- Describe how Configuration Manager builds upon MDT and how both can work in harmony.
- Explain the different options and considerations when choosing the user interaction experience during deployment, and which methods and tools support these experiences.
Deploy using Endpoint Configuration Manager
After completing this module, you’ll be able to:
- Describe the capabilities of Configuration Manager.
- Describe the key components of Configuration Manager.
- Describe how to troubleshoot Configuration Manager deployments.
Deploy new devices
After completing this module, you will be able to:
- Explain the benefits of modern deployment for new devices.
- Describe the process of preparing for an Autopilot deployment.
- Describe the process of registering devices in Autopilot.
- Describe the different methods and scenarios of Autopilot deployments.
- Describe how to troubleshoot common Autopilot issues.
- Describe the process of deployment using traditional methods.
Implement dynamic deployment methods
After completing this module, you will be able to:
- Describe how Subscription Activation works.
- Describe the benefits of Provisioning Packages.
- Explain how Windows Configuration Designer creates Provisioning Packages.
- Describe the benefits of using MDM enrollment with Azure AD join.
Plan a transition to modern management
After completing this module, you should be able to:
- Identify usage scenarios for Azure AD join.
- Identify workloads that you can transition to Intune.
- Identify prerequisites for co-management.
- Identify considerations for transitioning to modern management.
- Plan a transition to modern management using existing technologies.
- Plan a transition to modern management using Microsoft Intune.
Manage Cloud PCs and Virtual Desktops
After completing this module, you should be able to:
- Describe the differences between Azure Virtual Desktop and Windows 365.
- Configure Windows 365 using Endpoint Manager admin center.
- Create a provisioning policy to deploy a Windows 365 desktop.
- Reprovision and resize Windows 365 desktops.
Update Windows client
After completing this module, you will be able to:
- Describe Windows servicing options and channels.
- Explain available methods for applying updates to Windows.
- Configure Windows Update settings in Windows.
- Describe available Group Policy settings for configure Windows Update.
- Explain how Windows Insider for Business works.
Update clients using Windows Update for Business
After completing this module, you’ll be able to:
- Describe Windows Update for Business.
- Configure Windows Update for Business.
- Identify scenarios for using Windows Update for Business.
Explore Desktop Analytics
After completing this module, you will be able to:
- Describe the benefits of Desktop Analytics.
- Describe how Desktop Analytics is configured.
- Explain how Desktop Analytics can assess compatibility and monitor health.
- Describe how Desktop Analytics can be used to create a deployment plan
Explore Endpoint Analytics
After completing this module, you will be able to:
- Describe the benefits of Endpoint Analytics.
- Describe how Endpoint Analytics can monitor performance and the user experience.
- Describe how Endpoint Analytics can identify application issues.
- Describe how Endpoint Analytics can be used to help transition to modern management and Windows 11