Microsoft 365 Endpoint Administrator flashcards
130 free flashcards. Tap a card to flip it.
System Restore Point
Flip cardA snapshot of your Windows system files, installed applications, Windows Registry, and system settings at a particular point in time, allowing you to revert your system to that state without affecting personal files.
- Does not affect personal data (documents, pictures).
- Can undo system changes caused by new software or drivers.
- Requires System Protection to be enabled.
Memory trick: System Restore is your time machine for system settings, preserving precious memories (files).
Windows Autopilot Self-Deploying Mode
Flip cardAn Autopilot deployment mode that allows devices to enroll into Azure AD and Intune, apply device-based policies (like BitLocker), and install applications without any user interaction from the first boot.
- Ensures device-based policies are applied before user login.
- Ideal for kiosks, shared devices, or scenarios requiring pre-login encryption.
- Requires TPM 2.0 and active internet connection.
Memory trick: Self-deploying ensures encryption before anyone logs in.
Conditional Access Device State
Flip cardThe Device state condition in Conditional Access allows policies to evaluate if a device is compliant with Intune policies or if it is hybrid Azure AD joined, which are crucial for secure access.
- Evaluates if a device is 'Marked as compliant' by Intune.
- Evaluates if a device is 'Hybrid Azure AD joined'.
- Essential for 'Require compliant device' grant control.
Memory trick: To access the exclusive club, your device's 'state' must be elite: compliant or hybrid joined.
Intune Configuration Profile
Flip cardA Microsoft Intune configuration profile is a container for settings that you can deploy to devices to configure features, security settings, Wi-Fi, VPN, email, and more.
- Used to configure specific device settings.
- Supports various platforms (Windows, iOS, Android, macOS).
- Can enforce security features like BitLocker.
Memory trick: Configuring devices is like setting up a new phone, you need a profile for all the settings.
Auto-labeling Policy (Microsoft Purview)
Flip cardAn auto-labeling policy in Microsoft Purview automatically applies sensitivity labels to content in SharePoint, OneDrive, and Exchange based on defined conditions, such as the presence of sensitive information types.
- Automates sensitivity label application.
- Works with sensitive information types (SITs).
- Applies to SharePoint, OneDrive, and Exchange.
- Enforces protection settings defined in the label.
Memory trick: The 'auto-labeling policy' is like a smart librarian, automatically stamping books with their correct classification and rules.
Intune iOS Wi-Fi PEAP Profile
Flip cardConfiguring an Enterprise Wi-Fi profile in Intune for iOS devices that uses PEAP (Protected Extensible Authentication Protocol) for 802.1X authentication with username/password credentials.
- PEAP uses a server certificate for server authentication and then username/password for client authentication.
- Commonly integrated with Active Directory or Azure AD credentials.
- Suitable for WPA2 Enterprise networks requiring credential-based authentication.
Memory trick: PEAP for Passwords, TLS for Certificates.
Azure AD Automatic MDM Enrollment Scope
Flip cardConfiguring the 'MDM user scope' in Azure AD's Mobility (MDM and MAM) settings to control which user groups are eligible for automatic device enrollment into Microsoft Intune upon Azure AD Join.
- Crucial for staged rollouts of Intune enrollment.
- Located in Azure AD under Mobility (MDM and MAM).
- Options are None, Some (with group selection), or All.
Memory trick: Mobility scope controls the 'Move' to Intune.
Intune Android Enterprise Single-App Kiosk
Flip cardConfiguring an Android Enterprise dedicated device to run a single, specified application exclusively, preventing access to other apps, settings, or the home screen.
- Used for kiosk, digital signage, or task-specific devices.
- Achieved through a device restrictions profile in Intune.
- Locks the device into one chosen application.
Memory trick: Single app for simple kiosks, multi for flexibility.
Intune Endpoint Security BitLocker
Flip cardUsing Microsoft Intune's Endpoint Security Disk encryption profile to manage BitLocker settings, including automatic recovery key escrow to Azure AD.
- Dedicated profile for disk encryption.
- Ensures recovery keys are safely stored in Azure AD.
- Applies to Windows 10/11 devices.
Memory trick: Endpoint Security 'secures' your BitLocker keys.
Intune LOB App Deployment (MSIX)
Flip cardDeploying custom, in-house developed applications packaged as MSIX files directly through Microsoft Intune's Line-of-Business app capability.
- Supports MSIX, APPX, .MSI, .APK, .IPA packages.
- Ideal for simple installations without complex scripting.
- Managed updates directly through Intune.
Memory trick: Simple packages use LOB, complex ones use Win32.