Intune Overview & Admin Center
📦 Module: 1 of 7
🎯 Exam: MD-102
⏱ Read time: ~20 min
MD-102 Exam Alignment
MD-102
- Know that MDM (Mobile Device Management) manages the entire device — IT can enforce policies, wipe, and control the device. MAM (Mobile Application Management) manages only specific apps and their data, without controlling the whole device
- Know that Intune requires either an Intune standalone licence, Microsoft 365 E3/E5, EMS E3/E5, or Microsoft 365 Business Premium
- Know the URL for the Intune admin center: endpoint.microsoft.com
- Know that Intune uses Entra ID (Azure AD) for user identity, device registration, and group-based assignment of all policies and apps
🖥️ What Is Microsoft Intune?
| Capability | What Intune Provides |
|---|---|
| Mobile Device Management (MDM) | Full device management — enrol devices, push configuration profiles, enforce compliance, deploy certificates, remote wipe, and track inventory for Windows, iOS, Android, macOS, and Linux |
| Mobile Application Management (MAM) | App-level protection without device enrolment — control copy/paste, screen capture, data transfer between apps, and enforce PIN for managed apps on personal (BYOD) devices |
| Endpoint Security | Deploy security baselines, configure Antivirus/Firewall/Disk Encryption policies, and integrate with Microsoft Defender for Endpoint for threat detection and response |
| App Deployment | Deploy Microsoft Store apps, Line-of-Business (LOB) apps, Win32 packages, web apps, and Microsoft 365 Apps to enrolled devices, with Required or Available deployment intent |
| Reporting & Monitoring | Device compliance reports, app deployment status, policy assignment failure reports, and Endpoint Analytics for device performance and startup health |
🆔 MDM vs MAM — Key Distinction
| Dimension | MDM (Device Management) | MAM (App Management) |
|---|---|---|
| What is managed | The entire device — OS settings, apps, certificates, network | Only specific managed apps and their data |
| Enrolment required? | Yes — device must be enrolled in Intune | No — MAM without enrolment (MAM-WE) works on unmanaged devices |
| Typical use case | Corporate-owned devices where IT needs full control | BYOD (employee’s personal phone) where only work data needs protection |
| Data wipe capability | Full wipe (factory reset) or selective wipe of corporate data | Selective wipe only — removes managed app data, leaves personal data intact |
| Example | Corporate Windows PC enrolled via Autopilot | Employee’s iPhone using Outlook with an App Protection Policy applied |
📜 Intune Licensing
| Licence | Includes Intune | Notes |
|---|---|---|
| Microsoft Intune Plan 1 | ✅ Standalone Intune | Purchased separately or as add-on. Full MDM + MAM capabilities |
| Microsoft 365 E3 / E5 | ✅ Included | E3 includes Intune Plan 1. E5 adds advanced analytics and Endpoint Privilege Management |
| Microsoft 365 Business Premium | ✅ Included | For organisations up to 300 users. Includes Intune + Defender for Business |
| EMS E3 / E5 | ✅ Included | Enterprise Mobility + Security — includes Intune, Entra ID P1/P2, Azure Information Protection |
| Microsoft 365 E1 / F1 / F3 | ❌ Not included | Must add Intune Plan 1 separately |
🗺️ The Intune Admin Center — Navigation
The Intune admin center is accessed at endpoint.microsoft.com. The left navigation contains all key sections:
| Section | Key Functions |
|---|---|
| Devices | View all enrolled devices, enrolment methods, enrolment restrictions, configuration profiles, compliance policies, and device inventory. All device management starts here. |
| Apps | Add, configure, and assign apps to devices and users. Manage App Protection Policies (MAM), App Configuration Policies, and view app deployment status. |
| Users | View Entra ID users and their assigned devices, policies, and app deployments. Shortcuts to Entra ID blade. |
| Groups | View and manage Entra ID groups used for policy and app targeting. All assignments in Intune use Entra ID user/device groups. |
| Endpoint security | Security baselines, Antivirus, Disk Encryption, Firewall, Attack Surface Reduction, and Endpoint Detection & Response policies. Microsoft Defender for Endpoint integration is here. |
| Reports | Device compliance reports, Feature update deployment reports, Endpoint analytics (startup performance), and configuration assignment failure reports. |
| Tenant administration | Connector setup (Apple APNs, Google Play), role assignments (Intune RBAC), audit logs, and customisation of Company Portal app branding. |
💡 Best Practices
- Always assign policies to Entra ID groups, not individual users or devices — group-based assignment is scalable and supports dynamic membership rules for auto-assignment as new devices are enrolled
- Use filters (Devices → Filters) in addition to groups to target specific device attributes (e.g., OS version, device model, corporate vs personal ownership) without creating new groups
- Enable Endpoint analytics (Reports → Endpoint analytics) early — it provides a 28-day baseline of device startup performance, app reliability, and restart frequency before you make configuration changes
🎓 Interview Q&A
An employee wants to use their personal iPhone to access company email and Teams. IT needs to protect company data in those apps but not manage the employee’s personal device. Which Intune approach is appropriate?
Which URL is used to access the Microsoft Intune admin center?
A company has Microsoft 365 E1 licences for all employees. They want to use Intune to manage corporate Windows laptops. What additional licence is required?
An IT admin wants to deploy a VPN configuration profile to all Windows devices in the Sales department. Which Intune feature is used to target the profile only to Sales department devices?
Where in the Intune admin center would you go to set up the connection between Intune and Apple Business Manager to enable Automated Device Enrolment for iPhones?