Skip to content

02 Endpoint Administration

Modern enterprise security depends heavily on endpoint administration.

Users may access business resources from:

Corporate Laptops
Windows Desktops
Remote Devices
Virtual Desktops
Mobile Devices
Personally Owned Devices

The security challenge is not simply:

Can the Device Connect?

The real question is:

Should This Device Be Trusted
to Access Corporate Resources?

Endpoint administration helps organizations answer that question through:

Enrollment
Configuration
Compliance
Application Management
Security Policies
Updates
Monitoring
Access Control

Certification Area: Endpoint Administration
Level: Beginner → Intermediate
Primary Focus: Windows endpoint management and security
Core Platform: Microsoft Intune and Microsoft endpoint-management concepts
Career Relevance: Endpoint Administrator, Modern Workplace Administrator, Endpoint Security Engineer, SOC Analyst, Identity Engineer, Cloud Security Engineer

By the end of this lesson, you should be able to:

  • Explain endpoint administration
  • Understand the device lifecycle
  • Understand Microsoft Intune
  • Explain device enrollment
  • Understand device ownership
  • Understand join and registration concepts
  • Explain configuration profiles
  • Understand compliance policies
  • Understand Conditional Access integration
  • Explain application management
  • Understand Windows update management
  • Understand endpoint security policies
  • Understand disk encryption concepts
  • Understand firewall and antivirus management
  • Understand endpoint detection and response concepts
  • Review endpoint inventory
  • Troubleshoot common endpoint-management problems
  • Connect endpoint administration with Microsoft Entra ID
  • Understand endpoint security responsibilities
  • Prepare for endpoint-administration interviews and practical work

Part 01 — What Is Endpoint Administration?

Section titled “Part 01 — What Is Endpoint Administration?”

Endpoint administration is the process of managing devices throughout their lifecycle.

A simplified lifecycle is:

PURCHASE / PROVISION
ENROLL
CONFIGURE
SECURE
DEPLOY APPLICATIONS
MONITOR
UPDATE
SUPPORT
RETIRE

The goal is to maintain:

Usability
+
Security
+
Compliance
+
Visibility

Historically, organizations often managed devices through:

Active Directory
Group Policy
Software Distribution
Local Network

This model worked well when devices were:

Inside Corporate Offices
Connected to Domain Networks
Managed Primarily On-Premises

Modern organizations support:

Remote Users
Cloud Applications
Internet-Based Management
Hybrid Work
Mobile Devices
Cloud Identity

A modern model may look like:

USER
Microsoft Entra ID
DEVICE
Microsoft Intune
Configuration + Compliance
Microsoft 365 / Cloud Resources

Part 02 — Why Endpoint Administration Matters for Security

Section titled “Part 02 — Why Endpoint Administration Matters for Security”

Endpoints are frequently where:

Users Authenticate
Passwords Are Entered
Tokens Are Stored
Business Data Is Opened
Applications Execute
Email Is Accessed

If an endpoint is compromised, an attacker may gain access to:

Credentials
Sensitive Data
Cloud Sessions
Corporate Applications
Internal Resources

Therefore endpoint administration is also a security discipline.

IDENTITY
DEVICE
CONFIGURATION
APPLICATION
DATA
MONITORING

Microsoft Intune is a cloud-based endpoint-management service.

It can help organizations manage:

Devices
Applications
Configuration
Compliance
Security Policies
Microsoft Entra ID
USER
DEVICE
INTUNE
+-----------------------+
| Configuration |
| Compliance |
| Applications |
| Security |
| Updates |
+-----------------------+

Intune is not only:

Mobile Device Management

It can participate in broader enterprise endpoint management across:

Windows
Mobile Platforms
Applications
Security
Compliance

depending on organizational design and licensing.

A well-managed device should have a clear lifecycle.

ORDER
REGISTER
ENROLL
ASSIGN
CONFIGURE
SECURE
MONITOR
REASSIGN / RETIRE

At every stage ask:

Who Owns This Device?
Who Uses It?
Is It Still Authorized?
Does It Meet Security Policy?
Should It Still Have Access?

Devices may be:

Corporate-Owned
Personally Owned
Shared
Dedicated
Virtual

Device ownership affects:

Management Depth
Privacy
Security Controls
Application Deployment
Data Protection

Organizations usually have greater control over:

Configuration
Applications
Security Policies
Updates
Data Handling

Bring-your-own-device environments require careful separation between:

Corporate Requirements

and:

User Privacy

Security architecture may use:

Application Protection
Access Conditions
Data Controls
Limited Device Management

depending on requirements.

Part 06 — Device Registration and Join Concepts

Section titled “Part 06 — Device Registration and Join Concepts”

In Microsoft environments, devices may have different relationships with identity systems.

At a high level, understand concepts such as:

Registered Device
Cloud-Joined Device
Hybrid-Joined Device
Traditional Domain-Joined Device

Exact deployment choice depends on architecture.

Windows Device
Active Directory
Domain Authentication
Group Policy
Windows Device
Microsoft Entra ID
Cloud Identity
Cloud Management
Active Directory
+
Microsoft Entra ID
Hybrid Device Environment

Enrollment allows an endpoint-management platform to manage a device.

Conceptually:

DEVICE
IDENTITY
ENROLLMENT
MANAGEMENT
POLICY

Enrollment enables capabilities such as:

Configuration Deployment
Compliance Evaluation
Application Management
Security Policy
Inventory
Remote Administrative Actions

Ask:

Who Can Enroll?
Which Devices Can Enroll?
How Many Devices Per User?
Are Personal Devices Allowed?
Are Unsupported Devices Blocked?

Modern endpoint administration aims to reduce manual provisioning.

Instead of:

IT Receives Device
Manually Installs Everything
Hands Device to User

modern deployment may aim for:

Device Delivered
User Signs In
Identity Verified
Policies Applied
Applications Installed
Device Ready

Automation improves:

Consistency
Speed
Repeatability
Reduced Manual Error

Configuration profiles define desired settings for managed devices.

Examples may include:

Password / Lock Settings
Browser Configuration
Network Configuration
Security Settings
Device Restrictions
Certificates
SECURITY REQUIREMENT
CONFIGURATION PROFILE
DEVICE GROUP
MANAGED ENDPOINT

Manual approach:

Device 1 → Configure
Device 2 → Configure
Device 3 → Configure

Managed approach:

Policy
Device Group
Many Devices

Policies are typically assigned based on:

Users
Groups
Devices
Device Categories
Organizational Requirements

Avoid:

Everyone Gets Every Policy

Prefer:

Role / Device Type
Required Policy

Endpoints may receive multiple policies.

Potential issues include:

Conflicting Settings
Unexpected Inheritance
Different Scope
Multiple Management Sources

Troubleshooting should ask:

Which Policy Applied?
Which Policy Failed?
Which Setting Won?
Which Group Assigned It?

Compliance evaluates whether a device satisfies organizational security requirements.

Conceptually:

DEVICE STATE
COMPLIANCE POLICY
COMPLIANT
or
NONCOMPLIANT

A policy may evaluate conditions such as:

Supported Operating System
Required Security Settings
Encryption
Password Requirements
Security Health

This distinction matters.

Configuration Policy
Sets or Controls Settings
Compliance Policy
Evaluates Device State

Compliance becomes more powerful when combined with identity access control.

Conceptually:

USER
+
DEVICE
+
COMPLIANCE
ACCESS DECISION
User Has Correct Password
MFA Successful
Device Is Noncompliant
Access Restricted

This is stronger than evaluating identity alone.

Part 14 — Conditional Access Integration

Section titled “Part 14 — Conditional Access Integration”

Conditional Access can evaluate signals such as:

User
Device
Application
Risk
Location
Compliance

and then make an access decision.

ACCESS REQUEST
Identity Verified
Device Evaluated
Policy Evaluated
Allow / Require Control / Block

This supports:

Verify Explicitly
Use Least Privilege
Assume Breach

Endpoint administrators also manage applications.

Tasks may include:

Deploy
Install
Update
Remove
Restrict
Monitor
APP APPROVED
PACKAGE / CONFIGURE
ASSIGN
INSTALL
UPDATE
RETIRE

For every enterprise application ask:

Is It Approved?
Is It Required?
Is It Updated?
Who Can Install It?
What Data Can It Access?
Can Users Add Unapproved Software?

Part 16 — Required vs Available Applications

Section titled “Part 16 — Required vs Available Applications”

Applications may conceptually be:

Required

or:

Available

Required applications may be automatically deployed.

Available applications may be user-selectable through approved enterprise mechanisms.

Controlled application delivery reduces:

Shadow IT
Unapproved Software
Inconsistent Versions
Manual Installation

In some environments, organizations need to protect corporate data even when full device management is not appropriate.

Application-focused controls may help manage:

Corporate Data
Copy/Paste Behavior
Saving Data
Sharing
Application Access

especially in mobile or BYOD scenarios.

Endpoint security requires timely updates.

Updates may address:

Security Vulnerabilities
Reliability
Compatibility
Features
UPDATE AVAILABLE
TEST
DEPLOY IN RINGS
MONITOR
EXPAND
VALIDATE

Instead of:

Update Every Device Immediately

organizations may use:

Pilot Group
Early Adopters
Broad Deployment

This helps balance:

Security
+
Stability

Delayed updates can increase exposure.

But uncontrolled updates can impact:

Applications
Drivers
Business Operations

Therefore:

FAST

does not mean:

UNTESTED

Use risk-based deployment.

Endpoint security management may cover areas such as:

Antivirus
Firewall
Disk Encryption
Attack Surface Reduction
Account Protection
Device Security

The exact capabilities depend on environment and licensing.

The endpoint should maintain:

PREVENT
+
DETECT
+
RESPOND

Antivirus technologies help identify known and suspicious malicious content and behavior.

A modern security posture should consider:

Real-Time Protection
Cloud Protection
Signature / Intelligence Updates
Tamper Protection
Monitoring

Antivirus alone does not provide complete security.

It should operate alongside:

Identity Security
Patching
Firewall
Endpoint Detection
Least Privilege
User Awareness

Part 22 — Endpoint Detection and Response

Section titled “Part 22 — Endpoint Detection and Response”

Endpoint Detection and Response, or EDR, provides deeper visibility into endpoint activity.

Conceptually:

PROCESS
FILE
NETWORK
IDENTITY
TELEMETRY
DETECTION
INVESTIGATION

EDR can help security teams investigate:

Suspicious Process
Malicious File
Credential Activity
Persistence
Network Connections

Windows endpoints should have host-level network controls aligned with business requirements.

Think:

NETWORK
WINDOWS FIREWALL
APPLICATION
Is It Enabled?
Which Profiles Apply?
Which Applications Are Allowed?
Which Inbound Rules Exist?
Are Exceptions Required?
Are Rules Centrally Managed?

Disk encryption helps protect data when:

Laptop Is Lost
Device Is Stolen
Drive Is Removed

The goal is:

Physical Device Loss
Data Remains Protected

Encryption also requires:

Recovery Key Management
Access Control
Operational Recovery

Local administrator rights are high-risk.

An administrator can often:

Install Software
Change Security Settings
Access Sensitive Data
Create Users
Disable Controls
Standard User
Approved Administrative Need
Controlled Elevation

rather than:

Every User
=
Local Administrator

Least privilege reduces the potential impact of:

Malware
Credential Theft
User Error
Malicious Applications

Ask:

Who Is Local Administrator?
Why?
Is Access Permanent?
Is It Reviewed?
Can Elevation Be Controlled?

Security teams need to know what they manage.

Inventory should answer:

Which Devices Exist?
Who Owns Them?
Which OS Version?
Which Applications?
Which Security State?
Which Compliance State?
DEVICE
OWNER
OPERATING SYSTEM
SECURITY STATE
COMPLIANCE
LAST CHECK-IN

A device may be technically enrolled but still have security problems.

Review:

Compliance
Update State
Security Controls
Last Contact
Configuration Errors

A device that has not checked in for an extended period may represent:

Unused Device
Lost Device
Retired Device
Broken Device
Former Employee Device

Stale devices require lifecycle review.

When a device is no longer required:

REMOVE CORPORATE ACCESS
PROTECT / REMOVE DATA
RETIRE DEVICE
UPDATE INVENTORY
Is Corporate Data Removed?
Is Device Access Revoked?
Is Ownership Recorded?
Is the Device Reused or Disposed?
Are Recovery Keys Handled Correctly?

Endpoint-management platforms may support actions such as:

Sync
Restart
Retire
Wipe
Lock

depending on platform and ownership.

High-impact remote actions should be:

Authorized
Audited
Used Carefully
Appropriate to Device Ownership

Part 32 — Windows Configuration Security

Section titled “Part 32 — Windows Configuration Security”

A managed Windows endpoint may require configuration across:

Accounts
Firewall
Encryption
Applications
Updates
Browser
Security Features
Device Restrictions

Instead of configuring each control independently, organizations may define an approved:

Endpoint Security Baseline
Known Secure Starting Point
Consistent Deployment
Monitoring
Drift Detection

A device may start secure and later change.

Example:

Approved State:
Firewall Enabled

later becomes:

Troubleshooting Change:
Firewall Disabled

and never restored.

This is:

Configuration Drift
Baseline
Monitor
Detect Difference
Investigate
Remediate

Part 34 — Group Policy and Modern Management

Section titled “Part 34 — Group Policy and Modern Management”

Many organizations still use:

Group Policy

while also adopting:

Cloud Endpoint Management

Hybrid environments may therefore contain:

Active Directory
Group Policy

plus:

Microsoft Entra ID
Intune Policies

Multiple management systems can create:

Policy Conflict
Configuration Confusion
Drift
Ownership Problems

Clear management architecture is important.

Part 35 — Endpoint and Identity Relationship

Section titled “Part 35 — Endpoint and Identity Relationship”

Endpoint administration cannot be separated from identity.

USER
Microsoft Entra ID
DEVICE
ACCESS

Security decisions increasingly depend on both:

Who Are You?

and:

What Device Are You Using?

Endpoints frequently access:

Exchange Online
Teams
SharePoint
OneDrive
Enterprise Applications

A compromised endpoint can therefore affect:

Email
Files
Identity
Cloud Sessions

Endpoint-management data supports SOC investigations.

The SOC may need to know:

Device Owner
OS Version
Compliance Status
Security Tools
Recent User
Device Risk
ALERT
DEVICE
USER
PROCESS
NETWORK
SECURITY STATE

Part 38 — Endpoint and Incident Response

Section titled “Part 38 — Endpoint and Incident Response”

During an incident, response may involve:

Identify Device
Identify User
Assess Risk
Restrict Access
Isolate Where Supported
Collect Evidence
Remediate
Restore

Endpoint management and endpoint security therefore complement incident response.

A Zero Trust endpoint decision may consider:

User Identity
Authentication Strength
Device Ownership
Compliance
Risk
Application
User
MFA
Managed Device
Compliant Device
Low Risk
Corporate Application

Part 40 — Practical Exercise — Build a Device Inventory

Section titled “Part 40 — Practical Exercise — Build a Device Inventory”

Create:

Device Owner Type Managed Compliant
LAP-001 Alice Corporate Yes Yes
LAP-002 Bob Corporate Yes No
BYOD-001 Charlie Personal Limited Review

Ask:

Which Device Should Access Sensitive Data?
Why?

Part 41 — Practical Exercise — Build a Policy Model

Section titled “Part 41 — Practical Exercise — Build a Policy Model”

Create three groups:

Standard Users
Administrators
Contractors

Now map:

Standard Users
Standard Device Baseline
Administrators
Stronger Security Policy
Contractors
Restricted Access

Part 42 — Practical Exercise — Compliance Scenario

Section titled “Part 42 — Practical Exercise — Compliance Scenario”

Scenario:

Corporate Laptop
Disk Encryption Disabled
Compliance Evaluation

Expected result:

Noncompliant

A linked access-control policy might then:

Restrict Access

until the issue is corrected.

Part 43 — Practical Exercise — Lost Device

Section titled “Part 43 — Practical Exercise — Lost Device”

Scenario:

Employee Reports
Corporate Laptop Lost

Your response should consider:

Identify Device
Identify User
Confirm Device Ownership
Assess Encryption
Review Recent Activity
Restrict Access
Use Approved Remote Actions
Document Incident

Part 44 — Practical Exercise — Local Administrator

Section titled “Part 44 — Practical Exercise — Local Administrator”

Scenario:

User Requests
Permanent Local Administrator Rights

Ask:

Why Is It Required?
Which Task?
How Often?
Can Controlled Elevation Be Used?
Can the Application Be Changed Instead?

Apply:

Least Privilege

Part 45 — Practical Exercise — Update Ring

Section titled “Part 45 — Practical Exercise — Update Ring”

Design:

Ring 1
IT Test Devices
Ring 2
Early Users
Ring 3
General Workforce

Your objective is to balance:

Patch Speed
+
Application Stability

Part 46 — Endpoint Troubleshooting Workflow

Section titled “Part 46 — Endpoint Troubleshooting Workflow”

When a managed device has a problem, use:

DEVICE
IDENTITY
ENROLLMENT
LICENSE / ENTITLEMENT
GROUP ASSIGNMENT
POLICY
DEVICE CHECK-IN
LOCAL STATE
LOGS

Investigate:

Is Device Enrolled?
Is User/Device in Correct Group?
Is Policy Assigned?
Did Device Sync?
Is Another Policy Conflicting?
Does the Setting Apply to This Platform?

Investigate:

Which Compliance Rule Failed?
Is Device Reporting Current State?
Was Required Setting Applied?
Is There a Grace Period?
Is the Device Supported?

Check:

Identity
Authentication
Conditional Access
Device Compliance
Application
Service Health

Do not assume the issue is only endpoint-related.

Investigate:

Assignment
Device Architecture
Application Requirements
Dependencies
Disk Space
Network
Installation Status

Investigate:

Internet Connectivity
Enrollment
Device State
User Activity
Management Service
Device Retirement Status

Part 47 — Endpoint Security Assessment Questions

Section titled “Part 47 — Endpoint Security Assessment Questions”

A security reviewer should ask:

Are All Devices Inventoried?
Are Devices Enrolled?
Are Unsupported Devices Blocked?
Are Security Baselines Applied?
Is Disk Encryption Required?
Is Endpoint Protection Healthy?
Are Firewalls Active?
Are Users Local Administrators?
Are Updates Managed?
Are Noncompliant Devices Restricted?
Are Lost Devices Handled?
Are Stale Devices Removed?

Common endpoint risk areas include:

Unmanaged Devices
Unsupported Operating Systems
Missing Updates
Local Administrator Rights
Disabled Firewall
Missing Encryption
Unapproved Applications
Security Agent Failure
Stale Devices
Weak Access Controls
Finding:
Unmanaged Device Access
Observation:
A device accessing corporate applications
is not enrolled in the organization's
endpoint-management platform.
Risk:
The organization cannot reliably enforce
security configuration, compliance, or
device lifecycle controls.
Recommendation:
Require appropriate device management or
apply an approved restricted-access model
before allowing access to sensitive
corporate resources.
Finding:
Excessive Local Administrative Access
Observation:
Standard users possess permanent local
administrator privileges on managed
endpoints without documented business
requirements.
Risk:
Malware or credential compromise may gain
greater control of the device.
Recommendation:
Remove unnecessary local administrator
rights and use controlled administrative
elevation where required.
Finding:
Endpoint Disk Encryption Not Enforced
Observation:
Corporate devices can remain compliant
without required disk encryption.
Risk:
Loss or theft of a device could expose
locally stored business information.
Recommendation:
Require approved disk-encryption controls
and securely manage recovery information.
Finding:
Endpoint Security Updates Delayed
Observation:
Managed endpoints remain behind the
organization's approved security-update
baseline.
Risk:
Known vulnerabilities may remain exposed
longer than the approved remediation
window.
Recommendation:
Implement controlled update deployment
rings, monitor failures, and enforce
remediation according to risk.

Study endpoint administration in layers.

Understand:

Ownership
Enrollment
Join
Inventory
Lifecycle

Understand:

Intune
Profiles
Assignments
Applications
Updates

Understand:

Compliance Policy
Device State
Noncompliance

Understand:

Microsoft Entra ID
Conditional Access
Compliant Device Requirements

Understand:

Firewall
Encryption
Antivirus
EDR
Least Privilege

Do not confuse:

Configuration

with:

Compliance

Do not confuse:

Enrollment

with:

Identity Authentication

Do not confuse:

Device Management

with:

Threat Investigation

Do not confuse:

Device Compliance

with:

Device Is Completely Secure

Use:

01 Identify Device Type
02 Identify Ownership
03 Identify Requirement
04 Determine Management Need
05 Determine Security / Compliance Need
06 Select Best-Fit Control

Endpoint administration supports roles such as:

Endpoint Administrator
Modern Workplace Administrator
Windows Administrator
Endpoint Security Engineer
Microsoft Security Engineer
SOC Analyst
Cloud Security Engineer

You should eventually be able to:

Enroll a Device
Review Device Inventory
Assign Configuration
Review Compliance
Deploy Applications
Manage Updates
Review Endpoint Security
Troubleshoot Policy
Support Access Decisions
Retire Devices

What is Microsoft Intune?

A cloud-based endpoint-management platform used to manage areas such as:

Devices
Applications
Configuration
Compliance
Security

What is the difference between configuration and compliance?

Configuration
Defines / Applies Desired Settings

while:

Compliance
Evaluates Whether the Device
Meets Required Conditions

Why integrate endpoint compliance with Conditional Access?

Because access decisions can consider:

Identity
+
Device Security State

rather than trusting identity alone.

Why should users not normally have permanent local administrator rights?

Because excessive privilege can increase the impact of:

Malware
User Error
Credential Compromise

How would you troubleshoot a policy that is not applying?

Check:

Enrollment
Assignment
Group Membership
Device Sync
Policy Conflict
Platform Support
Local State

40 Endpoint Administration Interview Questions

Section titled “40 Endpoint Administration Interview Questions”
  1. What is endpoint administration?
  2. What is Microsoft Intune?
  3. What is device enrollment?
  4. What is device registration?
  5. What is a cloud-joined device?
  6. What is a hybrid-joined device?
  7. What is device ownership?
  8. What is BYOD?
  9. What is a configuration profile?
  10. What is a compliance policy?
  11. What is the difference between configuration and compliance?
  12. What is device compliance?
  13. How does Conditional Access use device state?
  14. What is Zero Trust?
  15. What is application deployment?
  16. What is application protection?
  17. What is Windows update management?
  18. What is an update ring?
  19. Why are phased updates useful?
  20. What is endpoint security?
  21. What is antivirus?
  22. What is EDR?
  23. Why is host firewalling important?
  24. Why is disk encryption important?
  25. What is least privilege?
  26. Why are local administrators risky?
  27. What is endpoint inventory?
  28. What is a stale device?
  29. What is configuration drift?
  30. What is an endpoint security baseline?
  31. What is remote wipe?
  32. What is device retirement?
  33. How do endpoints relate to Microsoft Entra ID?
  34. How do endpoints relate to Microsoft 365?
  35. Why is endpoint telemetry valuable to the SOC?
  36. How would you respond to a lost corporate laptop?
  37. How would you troubleshoot a noncompliant device?
  38. How would you troubleshoot application deployment?
  39. How would you troubleshoot a missing policy?
  40. What controls would you prioritize on a corporate Windows endpoint?

Endpoint Administration Readiness Checklist

Section titled “Endpoint Administration Readiness Checklist”
  • Understand device lifecycle
  • Understand device ownership
  • Understand enrollment
  • Understand device registration/join concepts
  • Understand corporate vs personal devices
  • Understand Microsoft Intune
  • Understand policy assignment
  • Understand configuration profiles
  • Understand inventory
  • Understand remote-management concepts
  • Understand compliance policies
  • Understand compliant vs noncompliant
  • Understand remediation
  • Understand compliance reporting
  • Understand Conditional Access integration
  • Understand application deployment
  • Understand required vs available applications
  • Understand application lifecycle
  • Understand application-protection concepts
  • Understand Windows update management
  • Understand deployment rings
  • Understand testing
  • Understand update validation
  • Understand antivirus
  • Understand EDR
  • Understand firewall
  • Understand disk encryption
  • Understand least privilege
  • Understand local administrator risk
  • Understand device health
  • Understand stale devices
  • Understand troubleshooting workflow
  • Understand device retirement
  • Understand configuration drift

Remember endpoint administration as:

IDENTITY
DEVICE
ENROLL
CONFIGURE
SECURE
COMPLIANCE
ACCESS
MONITOR
UPDATE
RETIRE

You now understand how modern Microsoft endpoint administration connects:

Windows Devices
Microsoft Intune
Microsoft Entra ID
Compliance
Conditional Access
Applications
Updates
Endpoint Security

The key security lesson is:

A Correct Password
Should Not Be the Only Requirement
for Corporate Access

Modern enterprise access increasingly evaluates:

Identity
+
Device
+
Security State
+
Risk

➡️ 03 — Microsoft Identity & Security

In the next lesson, you will move from device trust into one of the most important areas of modern cybersecurity:

IDENTITY

You will explore:

Microsoft Entra ID
Users and Groups
Authentication
MFA
Conditional Access
Roles
Privileged Identity
Access Reviews
Application Identities
Identity Protection
Zero Trust

Your Microsoft certification sequence continues:

01 Microsoft 365 Fundamentals
02 Endpoint Administration
03 Microsoft Identity & Security
Lab 01 — Active Directory
Lab 02 — Endpoint Security
Lab 03 — Identity Security
Lab 04 — Microsoft 365 Security
Lab 05 — Windows Security