Microsoft Learn references
Microsoft Intune Field Guides: The Complete Collection
Every reference the book lists, as a link, under the book's own headings. If a page has moved, search Microsoft Learn for its title.
Part 1: Intune Device Management and Enrollment
Intune Fundamentals, Licensing, and Planning
- Microsoft Intune licensing
- Microsoft Intune planning guide
- Microsoft Intune advanced capabilities
- Get started with your Microsoft Intune deployment
Mobile Application Management (MAM)
RBAC, Roles, and Scope Tags
- Role-based access control (RBAC) with Microsoft Intune
- Assign Microsoft Intune roles for role-based access control
- Use role-based access control (RBAC) and scope tags for distributed IT
Device Identity and Join Types
- What is a device identity?
- Microsoft Entra joined devices
- Microsoft Entra hybrid joined devices
- Microsoft Entra joined vs. Hybrid Microsoft Entra joined in cloud-native endpoints
- Understanding Primary Refresh Token (PRT)
Windows Enrollment and Autopilot
- Set up automatic enrollment for Windows devices
- Overview - Windows Autopilot
- Configure Windows Autopilot profiles
- Enrollment guide: Enroll Windows client devices in Microsoft Intune
Apple Device Enrollment
- Overview of Apple Automated Device Enrollment for iOS/iPadOS
- Set up automated device enrollment for iOS/iPadOS
- Set up iOS/iPadOS device enrollment with Apple Configurator
- Set up account driven Apple User Enrollment
- Overview of Apple User Enrollment in Microsoft Intune
Android Enterprise Enrollment
- Connect your Intune account to your managed Google Play account
- Enroll your Android Enterprise dedicated, fully managed, or corporate-owned with work profile devices
- Enrollment guide: Enroll Android devices in Microsoft Intune
Groups, Targeting, and Assignment Filters
- Use assignment filters to assign your apps, policies, and profiles in Microsoft Intune
- App and device properties, operators, and rule editing when creating assignment filters
Compliance Policies and Partners
- Create a compliance policy in Microsoft Intune
- Use compliance policies to set rules for devices you manage with Intune
- Support third-party device compliance partners in Intune
Conditional Access
- Learn about Conditional Access and Intune
- Common ways to use Conditional Access with Intune
- Require device compliance with Conditional Access
Windows Security Hardening (WHfB, LAPS, Local Admin)
- Configure Windows Hello for Business on devices when they enroll with Intune
- Microsoft Intune support for Windows LAPS
- Deploy Windows LAPS policy with Microsoft Intune
- Account protection policy for endpoint security in Intune
- Policy CSP - LocalUsersAndGroups
Enrollment Restrictions
- What are enrollment restrictions?
- Create device platform restrictions
- Create device limit restrictions in Intune
Part 2: Windows Autopilot and Deployment
Autopilot Overview and Scenarios
- Overview of Windows Autopilot
- Windows Autopilot self-deploying mode
- Windows Autopilot and Surface devices
- Windows Autopilot FAQ
Requirements, Licensing, and Tenant Readiness
- Windows Autopilot requirements
- Set up automatic enrollment for Windows devices
- Automatic MDM enrollment in the Intune admin center
Registering Devices and the Hardware Hash
- Windows Autopilot registration overview
- Manually register devices with Windows Autopilot
- Surface Registration Support for Windows Autopilot
- Windows Autopilot motherboard replacement scenario guidance
- Create device groups for Windows Autopilot
Deployment Profiles and Deployment Modes
User-Driven, Pre-Provisioned, and Hybrid Join
- Windows Autopilot for pre-provisioned deployment
- Step by step tutorial for Windows Autopilot for pre-provisioned deployment Microsoft Entra join
- Deploy Microsoft Entra hybrid joined devices by using Intune and Windows Autopilot
- User-driven Microsoft Entra hybrid join: Install the Intune Connector for Active Directory
Enrollment Status Page
- Set up the Enrollment Status Page
- EnrollmentStatusTracking configuration service provider (CSP)
- DMClient configuration service provider (CSP)
- Troubleshooting Microsoft Entra device registration and Windows Autopilot
Device Lifecycle: Reset, Fresh Start, Wipe, Retire
- Windows Autopilot Reset
- Reset devices with remote Windows Autopilot Reset
- Device action: Autopilot Reset
- Device action: Fresh Start
- Device action: Retire
- Device actions
Windows Autopilot Device Preparation
- Overview of Windows Autopilot device preparation
- Windows Autopilot device preparation requirements
- Enrollment time grouping in Microsoft Intune
- Compare Windows Autopilot device preparation and Windows Autopilot
- Windows Autopilot device preparation FAQ
Provisioning Packages and Windows Configuration Designer
- Bulk enrollment for Windows devices
- Create a provisioning package (desktop wizard)
- Bulk enrollment using Windows Configuration Designer
- Provisioning CSP
Windows 11 Upgrades and Feature Update Policies
- Manage Windows feature updates
- Manage Windows Update ring policies
- Windows 11 requirements
- Safeguard holds
- Windows Autopatch prerequisites
- What is Windows Autopatch?
Windows 365 Cloud PC
- Windows 365 provisioning overview
- Create provisioning policies
- Windows 365 Azure network connection
- Device images overview
- Add or delete custom device images
Configuration Profiles, Settings Catalog, and ADMX
- Use the Intune settings catalog to configure settings
- Configure ADMX settings using the settings catalog in Microsoft Intune
- Import custom ADMX and ADML administrative templates into Microsoft Intune
- Windows policy CSPs
Co-management with Configuration Manager
Part 3: Intune Application Management
App Management Foundations and Lifecycle
- What is Microsoft Intune app management?
- Overview of the app lifecycle in Microsoft Intune
- Add apps to Microsoft Intune
- Learn about managing your apps and app data in Microsoft Intune
- What is Microsoft Intune?
Licensing, Plans, and Add-ons
Intune Management Extension and Prerequisites
- Intune Management Extension for Windows
- Use PowerShell scripts on Windows devices in Intune
- Network endpoints for Microsoft Intune
Win32 App Packaging and Deployment
- Win32 app management in Microsoft Intune
- Prepare Win32 app content for upload
- Add, assign, and monitor a Win32 app in Microsoft Intune
- Add Win32 app supersedence
- Support tip: Understanding the flow behind deployment, delivery, and processing of a Win32 application through Intune
Enterprise App Management and the Enterprise App Catalog
- Microsoft Intune Enterprise Application Management
- Add an Enterprise App Catalog app (Win32) to Microsoft Intune
Microsoft 365 Apps
- Add Microsoft 365 Apps to Windows devices using Microsoft Intune
- Set the Microsoft 365 Apps update channel using the settings catalog in Microsoft Intune
Store Apps and Volume Purchase
- Add Microsoft Store apps to Microsoft Intune
- How to manage iOS and macOS apps purchased through Apple Business Manager with Microsoft Intune
- How to manage iOS/iPadOS eBooks purchased through a volume-purchase program
Line-of-Business, Web, and Built-In Apps
- Add a Windows line-of-business app to Microsoft Intune
- Add an iOS/iPadOS line-of-business app to Microsoft Intune
- Use iOS app provisioning profiles to prevent your apps from expiring
- Add web apps to Microsoft Intune
- Add built-in apps to Microsoft Intune
Android and Managed Google Play
- Add Managed Google Play apps to Android Enterprise devices with Intune
- Add an Android line-of-business app to Microsoft Intune
App Assignment and Filters
- Assign apps to groups with Microsoft Intune
- Include and exclude app assignments in Microsoft Intune
- Use assignment filters to assign your apps, policies, and profiles in Microsoft Intune
- App and device properties, operators, and rule editing when creating assignment filters
- Assignment filter reports and troubleshooting in Microsoft Intune
App Protection Policies (MAM)
- How to create and assign app protection policies
- Data protection framework using app protection policies
- Frequently asked questions about MAM and app protection
- Deployment guide: Mobile Application Management (MAM) for unenrolled devices in Microsoft Intune
- Quiet time policies for iOS/iPadOS and Android apps
Conditional Access and App Protection
- Require approved client apps or app protection policy
- Migrate approved client app to application protection policy in Conditional Access
- Conditional Access: Grant
App Configuration Policies
- App configuration policies for Microsoft Intune
- App configuration policies for Intune App SDK managed apps
Monitoring and Troubleshooting
- Monitor app information and assignments with Microsoft Intune
- Troubleshooting Intune app installation issues
Part 4: Intune Endpoint Security and Updates
Endpoint Security Node and Zero Trust
- Manage endpoint security in Microsoft Intune
- Manage device security with endpoint security policies in Microsoft Intune
- Manage devices with endpoint security in Microsoft Intune
- Protect data and devices with Microsoft Intune
- Overview - Zero Trust with Microsoft Intune
- Zero Trust deployment approach with Microsoft Intune
Licensing, Prerequisites, and Admin Roles
- Microsoft Intune licensing
- Microsoft Intune advanced capabilities
- Microsoft Intune planning guide - Determine costs and licensing
- Role-based access control (RBAC) with Microsoft Intune
- Assign Microsoft Intune roles for role-based access control
Antivirus and the Windows Security Experience
- Manage tamper protection for your organization using Microsoft Intune
- Protect security settings with tamper protection
- Settings for the Windows Security experience profile in Microsoft Intune
- Configure remediation for Microsoft Defender Antivirus detections
- Protect macOS security settings with tamper protection
Disk Encryption: BitLocker, Personal Data Encryption, and FileVault
- Encrypt Windows devices with BitLocker using Intune
- Disk encryption policy for endpoint security in Intune
- Personal Data Encryption settings and configuration
- Encrypt macOS devices with FileVault using Intune
- Troubleshooting BitLocker with the Intune encryption report
Firewall and Reusable Settings Groups
Attack Surface Reduction, Device Control, and Exploit Protection
- Attack surface reduction (ASR) rules overview
- Attack surface reduction (ASR) rules reference
- Attack surface reduction policy settings for endpoint security in Intune
- Enable your attack surface reduction (ASR) rules deployment
- Deploy and manage device control in Microsoft Defender for Endpoint with Microsoft Intune
- Device control policies in Microsoft Defender for Endpoint
- Customize exploit protection
- Import, export, and deploy exploit protection configurations
Endpoint Detection and Response and Account Protection
- Deploy endpoint detection and response policy with Intune
- Configure Microsoft Defender for Endpoint with Intune and onboard devices
- Use Intune endpoint security policies to manage Defender for Endpoint on devices not enrolled with Intune
- Account protection policy for endpoint security in Intune
- Use identity protection profiles to manage Windows Hello for Business in Microsoft Intune
- Configure Credential Guard
- Microsoft Intune support for Windows LAPS
- Deploy Windows LAPS policy with Microsoft Intune
Security Baselines
- Use security baselines to help secure Windows devices you manage with Microsoft Intune
- Manage security baseline profiles in Microsoft Intune
Intune and Microsoft Defender for Endpoint Integration
- Device compliance settings for Windows in Intune
- Use Microsoft Intune security tasks to remediate device vulnerabilities identified by Microsoft Defender for Endpoint
- Remediate vulnerabilities with Microsoft Defender Vulnerability Management
- Enable Conditional Access to better protect users, devices, and data
- Run a detection test on a device recently onboarded to Microsoft Defender for Endpoint
Security Copilot in Intune
- Microsoft Copilot in Intune
- Security Copilot in Microsoft Intune
- Prompting in Microsoft Security Copilot
Windows Update Management: Rings, Feature, Quality, Hotpatch, Drivers
- Windows update management overview
- Manage Windows Update ring policies
- Manage Windows feature updates
- Manage Windows quality updates
- Hotpatch for Windows quality updates
- Configure Windows driver update policies
Windows Autopatch, Apple DDM, Android FOTA, and Delivery Optimization
- What is Windows Autopatch
- Windows Autopatch prerequisites
- Manage Windows Autopatch groups
- Hotpatch updates (Windows Autopatch)
- Configure update policies for Apple devices
- Manage Firmware Over-the-Air updates on Android
- Zebra LifeGuard Over-the-Air Integration with Microsoft Intune
- What is Delivery Optimization?
- Delivery Optimization reference
- Delivery Optimization settings for Windows devices in Intune
- Microsoft Connected Cache for Enterprise and Education Overview