MD 102T00 ENU PowerPoint - 02
MD 102T00 ENU PowerPoint - 02
Execute device
enrollment
MD-102 Microsoft 365 Endpoint Administrator
01 02 03 04
Describe Azure AD Examine Azure AD Join devices to Manage devices
join (Microsoft join (Microsoft Azure AD (Entra joined to Azure AD
Entra join) Entra join) ID) (Entra ID)
prerequisites
limitations and
benefits
• Windows Pro or Enterprise Edition can join Azure AD (Entra ID) and AD DS
• Azure AD (Entra ID) joined devices cannot be managed with Group Policy
– If you want to enable users to join their device to the corporate environment
• Join devices to Azure AD (Entra ID) during initial setup or later by using system
settings
• Use Hybrid Azure AD (Entra ID) to automatically register on-premises domain-
joined devices with Azure AD (Entra ID)
© Copyright Microsoft Corporation. All rights reserved.
Examine Azure AD join (Entra join) prerequisites
limitations and benefits
Azure AD (Entra ID) limitations Scenarios enabled by using Azure AD (Entra
Azure AD (Entra ID) is not a part of the core ID) with on-premises AD infrastructure
infrastructure Ease of transition to cloud-based infrastructure
Azure AD (Entra ID) does not have the same and MDM
management capabilities as AD DS When on-premises domain join is not possible
(tablets, phones, etc.)
Azure AD (Entra ID) benefits When users primarily need to access Microsoft 365
Single Sign On (SSO) or other SaaS apps integrated with Azure AD (Entra
ID)
Roaming of user settings across joined devices
You want to manage a group of users in Azure AD
Windows Hello support (Entra ID) instead of in Active Directory
Restriction of access to apps from only compliant You want to provide joining capabilities to workers in
devices remote branch offices with limited on-premises
Seamless access to on-premises resources infrastructure
You can join to Azure AD (Entra ID) after Windows installation, or you can
2
do it later, at any time by using Settings pane
Group Policy is not always available or supported for devices that join
2
Azure AD (Entra ID)
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Module 2: Enroll devices
using Microsoft Configuration
Manager
1 Client online status. Online (connected to its assigned management point) or offline.
Client activity. Active (it has communicated with Microsoft Configuration Manager in
2 the past seven days) or inactive.
Primary User. The primary user of this device, calculated over a 60-day period of the
3 most frequent Sign-in attempts.
Operating System Build. See the OS version of a device without having to connect to
4 or perform any remote management.
Client check. State of the periodic evaluation that the Microsoft Configuration Manager
5 client runs on the device. The evaluation checks the device and can remediate some of
the problems it finds.
– Add to a collection.
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Module 3: Enroll devices
using Microsoft Intune
• The Intune admin center console includes all the management capabilities
provided by Intune.
• The Intune Company Portal is used to self-manage device enrollment and to
access published applications.
• Device Management Lifecycle
– Enroll
– Configure
– Protect
– Retire
Supported Devices
• Windows 10/11 (Home, Pro, Education, S mode, and Enterprise versions)
• Windows 10/11 Cloud PCs on Windows 365
• Windows 10 IoT and Windows 10 Holographic
• Windows 10 2019 LTSC
• Windows RT 8.1, and Windows 8.1 (sustaining mode)
• Apple iOS/iPadOS 13.0 and later
• macOS X 10.15 and later
• Android 6.0 and later, including Samsung Knox 2.4 and later and Android for Work
• Your initial Azure AD (Entra ID) domain will follow the model:
– your-domain.onmicrosoft.com
OR
Create CNAME records to simplify enrollment and device registration when
not licensed for Azure AD (Entra ID) Premium
• Supervised mode
• Access all DEM users despite role-based access control (RBAC) permissions being listed and
available under the custom User role
• Audit Logs
– Discovered apps
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Practice Labs
© Copyright Microsoft Corporation. All rights reserved. © Copyright Microsoft Corporation. All rights reserved.
Learning Path Recap
In this learning path, we learned to: