Module 1: Intune Overview & Admin Center Navigation

🎯 Intune Course · Module 1 of 7

Intune Overview & Admin Center

📂 Course: Intune & Endpoint Management
📦 Module: 1 of 7
🎯 Exam: MD-102
Read time: ~20 min
MD-102
MD-102 Exam Alignment
MD-102
  • Know that MDM (Mobile Device Management) manages the entire device — IT can enforce policies, wipe, and control the device. MAM (Mobile Application Management) manages only specific apps and their data, without controlling the whole device
  • Know that Intune requires either an Intune standalone licence, Microsoft 365 E3/E5, EMS E3/E5, or Microsoft 365 Business Premium
  • Know the URL for the Intune admin center: endpoint.microsoft.com
  • Know that Intune uses Entra ID (Azure AD) for user identity, device registration, and group-based assignment of all policies and apps
Exam Tip: The MD-102 frequently tests the distinction between MDM and MAM. MDM = device-level control (company owns the device experience). MAM = app-level control without device enrolment (user’s personal device, company controls only the work app). A device can be MDM-enrolled AND have MAM policies applied — these are not mutually exclusive.
Microsoft Intune is Microsoft’s cloud-based unified endpoint management (UEM) platform. It allows IT administrators to manage and secure Windows PCs, Macs, iOS, iPadOS, Android, and Linux devices from a single web console — without any on-premises infrastructure. Intune handles device enrolment, policy enforcement, app deployment, compliance checking, and security baseline application.

🖥️ What Is Microsoft Intune?

Capability What Intune Provides
Mobile Device Management (MDM) Full device management — enrol devices, push configuration profiles, enforce compliance, deploy certificates, remote wipe, and track inventory for Windows, iOS, Android, macOS, and Linux
Mobile Application Management (MAM) App-level protection without device enrolment — control copy/paste, screen capture, data transfer between apps, and enforce PIN for managed apps on personal (BYOD) devices
Endpoint Security Deploy security baselines, configure Antivirus/Firewall/Disk Encryption policies, and integrate with Microsoft Defender for Endpoint for threat detection and response
App Deployment Deploy Microsoft Store apps, Line-of-Business (LOB) apps, Win32 packages, web apps, and Microsoft 365 Apps to enrolled devices, with Required or Available deployment intent
Reporting & Monitoring Device compliance reports, app deployment status, policy assignment failure reports, and Endpoint Analytics for device performance and startup health

🆔 MDM vs MAM — Key Distinction

Dimension MDM (Device Management) MAM (App Management)
What is managed The entire device — OS settings, apps, certificates, network Only specific managed apps and their data
Enrolment required? Yes — device must be enrolled in Intune No — MAM without enrolment (MAM-WE) works on unmanaged devices
Typical use case Corporate-owned devices where IT needs full control BYOD (employee’s personal phone) where only work data needs protection
Data wipe capability Full wipe (factory reset) or selective wipe of corporate data Selective wipe only — removes managed app data, leaves personal data intact
Example Corporate Windows PC enrolled via Autopilot Employee’s iPhone using Outlook with an App Protection Policy applied

📜 Intune Licensing

Licence Includes Intune Notes
Microsoft Intune Plan 1 ✅ Standalone Intune Purchased separately or as add-on. Full MDM + MAM capabilities
Microsoft 365 E3 / E5 ✅ Included E3 includes Intune Plan 1. E5 adds advanced analytics and Endpoint Privilege Management
Microsoft 365 Business Premium ✅ Included For organisations up to 300 users. Includes Intune + Defender for Business
EMS E3 / E5 ✅ Included Enterprise Mobility + Security — includes Intune, Entra ID P1/P2, Azure Information Protection
Microsoft 365 E1 / F1 / F3 ❌ Not included Must add Intune Plan 1 separately

🗺️ The Intune Admin Center — Navigation

The Intune admin center is accessed at endpoint.microsoft.com. The left navigation contains all key sections:

Section Key Functions
Devices View all enrolled devices, enrolment methods, enrolment restrictions, configuration profiles, compliance policies, and device inventory. All device management starts here.
Apps Add, configure, and assign apps to devices and users. Manage App Protection Policies (MAM), App Configuration Policies, and view app deployment status.
Users View Entra ID users and their assigned devices, policies, and app deployments. Shortcuts to Entra ID blade.
Groups View and manage Entra ID groups used for policy and app targeting. All assignments in Intune use Entra ID user/device groups.
Endpoint security Security baselines, Antivirus, Disk Encryption, Firewall, Attack Surface Reduction, and Endpoint Detection & Response policies. Microsoft Defender for Endpoint integration is here.
Reports Device compliance reports, Feature update deployment reports, Endpoint analytics (startup performance), and configuration assignment failure reports.
Tenant administration Connector setup (Apple APNs, Google Play), role assignments (Intune RBAC), audit logs, and customisation of Company Portal app branding.

💡 Best Practices

  • Always assign policies to Entra ID groups, not individual users or devices — group-based assignment is scalable and supports dynamic membership rules for auto-assignment as new devices are enrolled
  • Use filters (Devices → Filters) in addition to groups to target specific device attributes (e.g., OS version, device model, corporate vs personal ownership) without creating new groups
  • Enable Endpoint analytics (Reports → Endpoint analytics) early — it provides a 28-day baseline of device startup performance, app reliability, and restart frequency before you make configuration changes

🎓 Interview Q&A

Q: What is the difference between MDM and MAM, and when would you use each?
MDM (Mobile Device Management) enrolls the entire device into Intune, giving IT control over the OS, apps, certificates, and network settings. Use MDM for corporate-owned devices where IT needs full control — deploying configuration profiles, enforcing compliance, and performing remote wipe. MAM (Mobile Application Management) manages specific apps and their data without enrolling the device. Use MAM for BYOD scenarios where employees use personal phones for work — you protect company data in Outlook, Teams, and OneDrive without touching their personal photos or apps.
🎯 MD-102 Mock Test
Module 1 — Intune Overview & Admin Center
5 questions · Pass mark: 70%

Q1 OF 5

An employee wants to use their personal iPhone to access company email and Teams. IT needs to protect company data in those apps but not manage the employee’s personal device. Which Intune approach is appropriate?

AEnrol the iPhone using MDM — IT needs to control the device to protect company data
BRequire the employee to use a company-issued device instead
CApply App Protection Policies (MAM without enrolment) to the managed apps on the personal device
DUse a Compliance Policy to check if the device meets requirements before allowing access

C. App Protection Policies (MAM-WE — MAM without enrolment) allow IT to protect company data in specific apps (Outlook, Teams, OneDrive) on personal devices without enrolling the device into Intune MDM. The employee’s personal photos, apps, and settings remain private. Compliance policies (D) require MDM enrolment and don’t apply to unmanaged personal devices.

Q2 OF 5

Which URL is used to access the Microsoft Intune admin center?

Aintune.microsoft.com
Bendpoint.microsoft.com
Cportal.azure.com/intune
Dadmin.microsoft.com/intune

B. The Microsoft Intune admin center is accessed at endpoint.microsoft.com. This is the unified endpoint management portal that replaced the older intune.microsoft.com URL.

Q3 OF 5

A company has Microsoft 365 E1 licences for all employees. They want to use Intune to manage corporate Windows laptops. What additional licence is required?

AMicrosoft Intune Plan 1 — must be added as a separate licence since M365 E1 does not include Intune
BNo additional licence needed — M365 E1 includes Intune
CMicrosoft 365 Business Premium must replace E1 to get Intune
DEntra ID P2 includes Intune — upgrade E1 to include Entra P2

A. Microsoft 365 E1 does NOT include Intune. To use Intune with E1, you must add Microsoft Intune Plan 1 as a separate licence per user. Intune is included in M365 E3, E5, Microsoft 365 Business Premium, and EMS E3/E5 — but not E1, F1, or F3.

Q4 OF 5

An IT admin wants to deploy a VPN configuration profile to all Windows devices in the Sales department. Which Intune feature is used to target the profile only to Sales department devices?

AAssign the profile to individual device objects in the admin center
BCreate a scope tag named “Sales” and apply it to the profile
CUse a Compliance Policy exclusion to exclude non-Sales devices
DAssign the profile to an Entra ID group containing Sales department users or devices

D. All Intune policy and app assignments use Entra ID groups as targets. Create an Entra ID group containing Sales department users or devices (using dynamic membership rules for automatic population), then assign the VPN profile to that group. Scope tags (B) control who can see and manage a policy in the admin center — they don’t control which devices receive the policy.

Q5 OF 5

Where in the Intune admin center would you go to set up the connection between Intune and Apple Business Manager to enable Automated Device Enrolment for iPhones?

ADevices → iOS/iPadOS → Enrolment
BEndpoint security → Connectors
CTenant administration → Connectors and tokens → Apple MDM Push certificate and Apple enrollment tokens
DApps → iOS/iPadOS → App connectors

C. Apple connector setup is in Tenant administration → Connectors and tokens. This is where you upload the Apple MDM Push Certificate (required to manage ANY Apple device) and add an Apple enrollment token (VPP/ABM token for Automated Device Enrolment). Without the MDM Push Certificate, Intune cannot communicate with Apple devices at all.



🔒

Module locked — Complete the previous module first.