Microsoft 365 Endpoint Administrator flashcards
130 free flashcards. Tap a card to flip it.
App protection policies (APP)
Flip cardRules that ensure an organization's data remains safe or contained in a managed app, even on unmanaged devices. They prevent data leakage and enforce security requirements within the app itself.
- Protect organizational data at the app level.
- Can be applied to both managed and unmanaged devices.
- Control actions like copy/paste, save-as, and access to corporate data.
Memory trick: Apps Protect Data Everywhere, securing your digital sphere.
Intune Security Baselines
Flip cardPre-configured groups of settings for Windows devices that align with security best practices recommended by Microsoft, designed for easy deployment.
- Simplifies deployment of security configurations.
- Based on Microsoft's security recommendations.
- Can be customized and assigned to groups.
Memory trick: Baselines are the bedrock of security, pre-built for stability.
Sensitivity Label Publishing
Flip cardThe process of making a created sensitivity label available to specific users or groups within an organization so they can apply it to their content.
- Labels are useless until published.
- Published via label policies in Microsoft Purview.
- Targeted to specific users/groups.
Memory trick: To use the label, you first have to share it with everyone.
Conditional Access Location Condition
Flip cardA feature within Microsoft Entra Conditional Access that allows administrators to define access policies based on the network location from which a user is attempting to access resources.
- Can restrict access from specific countries/regions.
- Can require MFA when accessing from untrusted locations.
- Requires named locations to be configured in Microsoft Entra ID.
Memory trick: Location locks down access, Conditional Access makes it happen.
Azure AD Connect
Flip cardA Microsoft tool designed to meet and accomplish your hybrid identity goals. It synchronizes user identities, groups, and device objects between on-premises Active Directory and Azure Active Directory.
- Handles synchronization of user accounts, groups, and device objects.
- Supports password hash synchronization, pass-through authentication, and federation.
- Essential for hybrid identity scenarios, including object lifecycle management (creation, updates, deletions).
Memory trick: Connect the halves, keep identities in sync, no user left behind.
Automatic MDM Enrollment (Azure AD Premium)
Flip cardA feature in Azure AD that allows devices to automatically enroll in a Mobile Device Management (MDM) solution like Intune when they are joined to Azure AD or registered with Azure AD.
- Requires Azure AD Premium license.
- Configured in Azure AD > Mobility (MDM and MAM).
- Applies to devices that are Azure AD joined or Hybrid Azure AD joined.
Memory trick: Enrollment's key: automatic ease for corporate peace.
Conditional Access
Flip cardA feature of Azure Active Directory that enables organizations to enforce policies for accessing resources based on specific conditions, such as user location, device state, application, and sign-in risk.
- Acts as a gatekeeper for resource access.
- Can require multi-factor authentication, compliant devices, or trusted locations.
- Integrates with Intune for device compliance checks.
Memory trick: Conditional Access: Only if conditions are right, the door opens with all its might.
Intune PowerShell Script Deployment
Flip cardA feature in Microsoft Intune that allows administrators to upload and deploy custom PowerShell scripts to Windows devices, providing options for execution context, retry behavior, and reporting.
- Supports running scripts in user or system context.
- Provides success/failure reporting for script execution.
- Ideal for automating tasks, configuring settings not available via profiles, or running diagnostics.
Memory trick: Script's the way for custom play, on every PC, come what may.
Intune Compliance Policy
Flip cardA set of rules in Microsoft Intune that devices must meet to be considered compliant. Non-compliant devices can be restricted from accessing corporate resources.
- Defines device health and configuration requirements.
- Can include settings for passcodes, OS versions, encryption, and jailbreak detection.
- Integrates with Conditional Access to enforce access for compliant devices only.
Memory trick: Compliance checks the box, securing my device's lock.
Android Enterprise (Work profile)
Flip cardAn Intune enrollment method for corporate-owned Android devices that creates a separate work profile to isolate and manage corporate apps and data, while allowing personal use of the device.
- Separates corporate and personal data.
- IT manages only the work profile.
- Suitable for corporate-owned devices with personal use.
Memory trick: Work Profile keeps your work life separate from your personal life on your phone.
Conditional Access Policy Exclusions
Flip cardSpecific users, groups, or roles that are intentionally excluded from the scope of a Conditional Access policy, often as a safety measure to prevent administrative lockouts.
- Global Administrator role is often excluded by default from new CA policies.
- Exclusions take precedence over inclusions.
- Critical for maintaining access in case of misconfigured policies.
Memory trick: First exclude, then include, then conditions subdue.
Corporate-Owned, Single-Purpose (COSU) Device Enrollment
Flip cardEnrollment methods for corporate-owned mobile devices designed for specific functions (e.g., kiosk, digital signage, frontline worker tools) that offer high levels of management and often zero-touch deployment.
- Examples: Apple Automated Device Enrollment (ADE), Android Enterprise Dedicated Devices.
- Provides granular control over device settings, apps, and restrictions.
- Simplifies initial setup for end-users, often requiring no user interaction.
Memory trick: Enrollment's path: personal, bulk, or corporate's dedicated wrath.
Apple Business Manager (ABM) Enrollment
Flip cardA zero-touch enrollment method for corporate-owned iOS/iPadOS devices purchased directly from Apple, allowing automatic MDM enrollment during initial device setup.
- Requires integration with Intune.
- Provides automatic, mandatory enrollment.
- Ideal for large-scale corporate deployments.
Memory trick: Apple Business Manager streamlines device setup right out of the box.
Azure AD Device States and Compliance
Flip cardAzure AD device states (Registered, Joined, Hybrid Joined) define how a device connects to Azure AD, while Intune compliance status indicates if it meets organizational policies.
- Registered: BYOD, provides SSO.
- Joined/Hybrid Joined: Corporate, full management.
- Compliance requires MDM (e.g., Intune) evaluation.
Memory trick: Registered is good, compliant is golden, together they unlock access.
Conditional Access: Locations Condition
Flip cardA condition in Conditional Access policies that allows defining trusted or untrusted network locations (IP ranges, countries) to control access to resources.
- Uses named locations (IP ranges).
- Can include or exclude specific locations.
- Essential for geographically restricted access.
Memory trick: Locations condition is the bouncer checking where you're coming from.
Conditional Access Device State Condition
Flip cardA condition within Conditional Access policies that allows administrators to define access requirements based on the management and compliance status of a device (e.g., Compliant, Hybrid Azure AD joined, Azure AD registered).
- Crucial for enforcing 'managed device' or 'compliant device' access policies.
- Leverages Intune's device compliance status.
- Can be combined with other conditions for granular control.
Memory trick: Conditions define the access gate, by user, app, or device's state.
Conditional Access: Require Compliant Device
Flip cardA grant control in Conditional Access that mandates a device must be marked as compliant by an MDM solution (like Intune) to gain access to protected resources.
- Enforces device health and security standards.
- Integrates with Intune compliance policies.
- Fundamental for Zero Trust device access.
Memory trick: Grant controls are the 'then' statements, defining what access requires.
Intune Policy Assignment
Flip cardThe process of linking a created policy (e.g., compliance, configuration, app protection) to specific user groups or device groups within Microsoft Intune, enabling the policy to be evaluated and enforced on those targets.
- Policies are inactive until assigned.
- Can be assigned to user groups or device groups.
- Assignment determines the scope of policy application.
Memory trick: Create, Assign, Monitor: The Intune policy's journey, in order.
Sensitivity Labels (Microsoft Purview)
Flip cardLabels that classify and protect organizational data, allowing for the automatic application of encryption, access restrictions, visual markings, and other protection settings based on data sensitivity.
- Part of Microsoft Purview Information Protection (MPIP).
- Can be applied manually by users or automatically by policies.
- Enforce protection like encryption and access control, persistent with the data.
Memory trick: Label it right, encrypt it tight, keep your data out of sight.
Managed Google Play
Flip cardA customized version of the Google Play Store for Android Enterprise deployments, used by IT administrators to approve, distribute, and manage applications for corporate-managed Android devices.
- Integrates with Intune for app management on Android Enterprise devices.
- IT admins approve apps before they are available to users/devices.
- Used for both public apps and private line-of-business (LOB) apps.
Memory trick: Managed Google Play, for corporate apps, saves the day.
Retention Policy (Microsoft Purview)
Flip cardA policy that defines how long an organization keeps content (e.g., emails, documents, Teams messages) and, optionally, when to delete it after the retention period.
- Retains content for compliance.
- Can also automatically delete content.
- Applies across various Microsoft 365 services.
Memory trick: Retention keeps data for a time, then sends it to the bin.
Retention Policies (Microsoft Purview)
Flip cardRules that govern the lifecycle of data within Microsoft 365, specifying how long content should be retained (or deleted) to meet regulatory, legal, and business requirements.
- Apply to various locations: Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats/channels.
- Can retain content for a specified period, delete content after a period, or both.
- Prevent permanent deletion during the retention period.
Memory trick: Retention's rule: Keep it, then toss it, by the compliance pool.
Conditional Access: Device State
Flip cardA condition in Conditional Access policies that evaluates whether a device is Azure AD registered/joined and/or compliant with Intune policies, influencing access decisions.
- Checks device registration/join status.
- Verifies device compliance from Intune.
- Critical for 'trusted device' access scenarios.
Memory trick: Device State is the gatekeeper checking your device's health pass.
Intune Custom Compliance Settings
Flip cardAllows administrators to extend Intune's compliance capabilities by defining custom rules using PowerShell scripts, enabling checks for specific device configurations or application states.
- Uses PowerShell scripts to evaluate compliance.
- Enables checks beyond built-in compliance settings.
- Reports device compliance status back to Intune.
Memory trick: Custom compliance scripts let you define your own strict rules.
Service-Side Automatic Labeling
Flip cardA Microsoft Purview feature that automatically applies sensitivity labels to content at rest in cloud services (e.g., SharePoint, OneDrive, Exchange) based on defined conditions.
- Applies labels to existing content in cloud locations.
- Uses sensitive information types (SITs) for detection.
- Does not require user interaction for application.
Memory trick: Services in the cloud automatically label data sitting there.
Device Compliance Policy
Flip cardA set of rules that devices must meet to be considered 'compliant' within Microsoft Intune, often used as a condition for Conditional Access.
- Defines security and health requirements for devices.
- Used to report compliance status to Intune.
- Can trigger Conditional Access restrictions for non-compliant devices.
Memory trick: Compliance checks if devices are aligned with company standards.
Azure AD BitLocker Key Escrow Location
Flip cardBitLocker recovery keys for Azure AD-joined or Hybrid Azure AD-joined devices are automatically escrowed and stored securely within the device object in Azure Active Directory, accessible via the Azure portal.
- Keys are stored under the device object in Azure AD.
- Accessible by users with appropriate permissions (e.g., Cloud Device Administrator).
- Crucial for data recovery if a device is locked out.
Memory trick: Device's Keys: Find them with the Device, not the User.
Intune macOS LOB App (DMG)
Flip cardA Microsoft Intune application type used to deploy custom Line-of-Business (LOB) applications to macOS devices when the application is packaged as a .DMG (Disk Image) file.
- Specifically for macOS applications packaged as .DMG files.
- Allows deployment of custom, in-house, or third-party applications.
- Intune handles mounting the DMG and copying the application to the Applications folder.
Memory trick: Match the Apple package to the Intune type.
Intune Wi-Fi Profile (EAP-TLS)
Flip cardA Microsoft Intune configuration profile used to deploy Wi-Fi network settings to devices, including SSID, security type (e.g., WPA2 Enterprise), and authentication method (e.g., certificate-based EAP-TLS).
- Automates Wi-Fi connection setup for users.
- Supports various security types, including enterprise-grade 802.1X.
- Can use certificates for secure authentication (EAP-TLS).
Memory trick: Wi-Fi profiles connect your devices securely with certificates.
Intune Driver and Firmware Update Policies
Flip cardIntune's Driver and firmware update policies provide granular control over the deployment of drivers and firmware updates to Windows devices, allowing administrators to approve, pause, or roll back specific updates independently from OS updates.
- Separate management from Feature and Quality Updates.
- Allows for testing and phased deployment of drivers/firmware.
- Crucial for stability and compatibility in enterprise environments.
Memory trick: Drivers/Firmware: Separate policies for precision control.
Android Enterprise Dedicated Devices (Kiosk)
Flip cardAndroid Enterprise dedicated devices, managed by Intune, are corporate-owned devices used for a single purpose (e.g., kiosk, digital signage). They can be configured in kiosk mode to lock down the device to one or more specific applications, restricting user access to other device functions.
- Ideal for shared, single-purpose devices.
- Achieved through 'Dedicated devices' enrollment.
- Kiosk mode configured via device restriction profiles.
Memory trick: Dedicated Devices: For the Single-App Kiosk Life.
Android Enterprise Device Restrictions
Flip cardIntune configuration profiles for Android Enterprise that allow administrators to control various aspects of device functionality, including access to hardware features, system settings, and app behavior.
- Applies to fully managed, dedicated, and corporate-owned work profile devices.
- Granular control over settings like Wi-Fi, Bluetooth, camera, app installation.
- Helps enforce corporate security and usability policies.
Memory trick: Device Restrictions are the 'master switches' for Android settings.
Intune BitLocker Policy
Flip cardA Microsoft Intune policy under Endpoint Security used to manage BitLocker Drive Encryption on Windows devices, including encryption settings and recovery key escrow.
- Enables BitLocker on OS drives and fixed/removable data drives.
- Automatically escrows recovery keys to Azure AD for easy retrieval.
- Can configure user interaction during setup.
Memory trick: Disk Encryption Secures Keys Automatically.
Intune Device Configuration Profile
Flip cardA Microsoft Intune device configuration profile is a set of settings that can be deployed to devices to manage their features, security, and behavior.
- Manages device-level settings.
- Applicable across various OS platforms (Windows, iOS, Android, macOS).
- Used for restrictions, Wi-Fi, VPN, email profiles, etc.
Memory trick: Configuration profiles set the device's main 'config'.
Intune macOS LOB App Deployment
Flip cardDeploying proprietary or in-house macOS applications (often .pkg installers) to managed devices using Microsoft Intune.
- Uses the 'Line-of-business app (macOS)' application type.
- Supports .pkg installer files.
- Allows for silent installation and management of custom apps.
Memory trick: LOB for PKG, DMG for DMG, easy as ABC.
Intune Windows Update Rings
Flip cardIntune policies that configure Windows Update for Business settings on managed Windows devices, allowing administrators to manage update deferrals, installation behavior, and restart options for both quality and feature updates.
- Manages both quality (monthly) and feature (semi-annual) updates.
- Allows deferral periods for different update types.
- Configures active hours and restart options to minimize user disruption.
Memory trick: Update Rings are the 'scheduling manager' for Windows updates.
Android Enterprise Dedicated Devices
Flip cardAn Android Enterprise management scenario in Microsoft Intune designed for corporate-owned, single-purpose, or shared devices that need to be locked down to a limited set of applications (kiosk mode).
- Ideal for shared devices, kiosks, or task-oriented devices.
- Devices are fully managed by the organization.
- Users are restricted from accessing device settings or installing unauthorized apps.
- Can be configured for single-app or multi-app kiosk mode.
Memory trick: Match the owner and purpose to the profile type.
Intune Required App Assignment
Flip cardAn Intune application assignment type that mandates the installation of an application on target devices and automatically reinstalls it if it is removed by the user or other means.
- Ensures compliance with mandatory application policies.
- Automatically installs applications without user intervention.
- Actively remediates non-compliance by reinstalling uninstalled apps.
Memory trick: Required Apps: Install, Enforce, Reinstall.
Intune Win32 App Deployment
Flip cardA method in Microsoft Intune to deploy complex Windows applications (e.g., .exe, .msi with transforms, multi-file setups) with custom installation commands, detection rules, and uninstall capabilities.
- Requires the Microsoft Win32 Content Prep Tool (.intunewin).
- Supports custom install and uninstall commands.
- Allows for detection rules to verify successful installation.
Memory trick: Intune's app types are like different 'toolboxes' for different deployment jobs.
Intune BitLocker Key Escrow to Azure AD
Flip cardThe process of configuring Microsoft Intune to automatically store BitLocker recovery keys for Windows devices in Azure Active Directory, allowing administrators to retrieve them for device recovery.
- Crucial for device recovery and administrative access.
- Configured via 'Configuration profiles' in Intune.
- Specific setting: 'Store recovery information in Azure Active Directory'.
- Ensures keys are securely accessible by authorized personnel.
Memory trick: Keys ascend to Azure AD for safe keeping.
Intune macOS App Source Restriction
Flip cardA device restriction setting in Intune for macOS that controls which sources users are allowed to install applications from.
- Can enforce installation only from the Apple App Store.
- Leverages macOS Gatekeeper settings.
- Enhances security by limiting software origins.
Memory trick: App Store Only: The Apple-approved gatekeeper.
Azure AD MDM User Scope
Flip cardA setting in Azure AD that determines which users' Windows devices will automatically enroll into an MDM solution (like Intune) when they sign in with their Azure AD account.
- Controls automatic MDM enrollment for Windows devices.
- Configured in Azure AD > Mobility (MDM and MAM).
- Can be set to None, Some (specific groups), or All.
Memory trick: Azure AD's scope guides devices to Intune's home.
Intune Quality Update Deferral
Flip cardA setting within a Windows Update Ring policy in Microsoft Intune that specifies the number of days to delay the availability of Windows quality (monthly security) updates to managed devices.
- Applies to cumulative updates and security patches.
- Allows organizations to test updates before broad deployment.
- Measured in days from the update's release date.
Memory trick: Deferring Updates Saves Everyone Time.
Intune Windows Driver/Firmware Updates
Flip cardIntune policy settings within Windows Update Rings that control the automatic installation and deferral periods for driver and firmware updates on Windows 10/11 devices.
- Managed within 'Update rings for Windows 10 and later'.
- Includes settings for 'Windows drivers'.
- Allows deferral periods to be configured.
- Ensures device stability and compatibility with hardware.
Memory trick: Update Rings manage all Windows update streams.
Intune Custom Configuration Profile (OMA-URI)
Flip cardAn Intune profile type that allows administrators to deploy custom settings to devices by specifying an OMA-URI (Open Mobile Alliance Uniform Resource Identifier) and its corresponding value.
- Used for settings not available in standard templates or settings catalog.
- Requires knowledge of the OMA-URI path, data type, and value.
- Provides maximum flexibility for device configuration.
Memory trick: Custom Profile is your 'blank canvas' for unique OMA-URI settings.
Intune macOS LOB App (.PKG)
Flip cardA Microsoft Intune application type used to deploy single .pkg (macOS installer package) files to managed macOS devices, typically for straightforward, silent installations.
- Designed for standard macOS installer packages.
- Does not support complex pre/post-installation scripting directly.
- Simple to configure for silent, automatic deployment.
Memory trick: Think of .PKG as a 'pre-wrapped present' for macOS LOB.
Intune PowerShell Scripts
Flip cardA Microsoft Intune feature that enables administrators to deploy, execute, and monitor custom PowerShell scripts on managed Windows devices for various configuration and automation tasks.
- Supports running scripts in user or system context.
- Provides detailed reporting on script execution status (success/failure).
- Ideal for custom configurations, automation, and troubleshooting.
Memory trick: Script's Goal: Run, Report, and Intune Controls.
Intune Line-of-Business App (Android)
Flip cardAn Intune application type used to deploy custom-developed Android applications (APK files) that are not published in the Google Play Store to managed Android devices.
- Requires uploading the APK file directly to Intune.
- Supports silent installation on Android Enterprise devices.
- Ideal for internal, proprietary applications.
Memory trick: Android App: LOB is the custom key.
Intune Quality Update Deferral Calculation
Flip cardCalculating the effective installation date for Windows Quality Updates involves adding the deferral period to the release date, then adding the installation deadline, and finally adding any grace period.
- Release Date + Deferral Days = Availability Date.
- Availability Date + Deadline Days = Installation Deadline.
- Installation Deadline + Grace Period Days = Latest Installation Date.
Memory trick: Defer, Dead, Grace: The Update's Final Race.
Intune Custom OMA-URI Profile
Flip cardAn Intune device configuration profile that allows administrators to deploy custom settings to Windows devices using Open Mobile Alliance Uniform Resource Identifier (OMA-URI) strings, directly interacting with Configuration Service Providers (CSPs).
- Used for settings not available in standard profiles
- Requires OMA-URI string, data type, and value
- Directly configures CSPs on Windows devices
- Can be used to modify registry keys via CSPs
Memory trick: Custom Keys Need Open Paths, OMA-URI Knows the Maths.
Intune Scripts Policy (PowerShell)
Flip cardAn Intune feature for deploying and managing PowerShell scripts on Windows devices, offering execution status reporting and run-once options.
- Dedicated policy type for PowerShell scripts
- Provides execution status reporting in Intune
- Can be configured to run once or repeatedly
- Supports running with user or system context
Memory trick: Scripts Simplify System Setup, Reporting Status Up.
Intune iOS Device Restrictions
Flip cardAn Intune configuration profile type used to control various hardware, system, and app-related settings on iOS/iPadOS devices, including security features like passcodes and app source restrictions.
- Configured via Configuration Profiles in Intune.
- Enforces security settings like passcode length and auto-lock.
- Can restrict App Store access, camera, AirDrop, etc.
Memory trick: Restrictions secure the device's core functions.
iOS App Store Restriction
Flip cardAn Intune device restriction setting for iOS/iPadOS that blocks access to the App Store, preventing users from installing new applications.
- Located within a 'Device restrictions' configuration profile.
- Also restricts access to other Apple content services.
- Used to enforce a curated app environment on corporate devices.
Memory trick: To block the App Store, think of a 'red light' for the shopping cart.
Azure AD Automatic MDM Enrollment
Flip cardA feature that automatically enrolls Windows devices into Microsoft Intune when they are joined to Azure Active Directory.
- Requires configuration in Azure AD's Mobility (MDM and MAM) settings.
- Ensures devices are managed by Intune from the moment they join Azure AD.
- Applies to devices joined or registered with Azure AD.
Memory trick: Join Azure AD, then MDM will automatically lead.
Intune Device Configuration Profiles
Flip cardA broad category of Intune policies used to deploy various settings, restrictions, and features to managed devices across different platforms.
- Includes settings for passcode, device features, network (Wi-Fi, VPN), and more.
- Platform-specific options (e.g., iOS/iPadOS, Windows).
- Used to enforce security and standardize user experience.
Memory trick: Configuration for the 'how', Compliance for the 'if'.
Intune Custom Configuration Profile
Flip cardA type of device configuration profile in Microsoft Intune that allows administrators to deploy settings using OMA-URI (Open Mobile Alliance Uniform Resource Identifier) for settings not available in standard templates.
- Uses OMA-URI for custom settings.
- Supports various data types (string, integer, boolean).
- Provides flexibility for niche configurations.
Memory trick: When standard templates don't fit, a Custom profile is your special tool.
Intune Custom ADMX Deployment (OMA-URI)
Flip cardDeploying settings from custom ADMX files in Intune by creating a 'Custom' device configuration profile and manually mapping the ADMX settings to OMA-URI (Open Mobile Alliance Uniform Resource Identifier) paths.
- Used for settings not available in standard Intune profiles or Settings Catalog.
- Requires knowledge of ADMX structure and OMA-URI syntax.
- Enables granular control over specific Windows policy settings.
Memory trick: ADMX to OMA-URI for custom settings, it's a mapping task.
Intune Windows Device Restrictions
Flip cardAn Intune configuration profile type for Windows devices used to control various device functionalities, security settings, and user access to system features like app uninstallation or command-line tools.
- Configured via Configuration Profiles > Device restrictions.
- Manages user access to features like Control Panel, Settings, Command Prompt.
- Can prevent application uninstallation.
- Crucial for locking down corporate-owned devices.
Memory trick: Restrictions prevent unauthorized device actions.
Group Policy MDM Enrollment
Flip cardA method to automatically enroll existing Active Directory-joined Windows devices into Microsoft Intune when users sign in with their Azure AD credentials.
- Requires Hybrid Azure AD Join
- Configured via Group Policy Objects (GPOs)
- Triggers MDM enrollment for users signing in to AD-joined devices
Memory trick: Many Devices Easily Enroll, Linking On-Prem to Cloud.
Intune LOB App (iOS)
Flip cardA Microsoft Intune application type used to deploy custom, in-house developed iOS applications packaged as .ipa files directly to managed iOS/iPadOS devices.
- Requires the .ipa file to be uploaded to Intune.
- Used for apps not available in the public Apple App Store.
- Deployment is managed directly by Intune, bypassing the App Store.
Memory trick: iOS Apps Deliver Easily Through Intune.