Manage Identity
- Support Windows Store and cloud apps
- Install and manage software by using Microsoft Office 365 and Windows Store apps, sideload apps by using Microsoft Intune, sideload apps into online and offline images, deeplink apps by using Microsoft Intune, integrate Microsoft account including personalization settings
- Support authentication and authorization
- Identifying and resolving issues related to the following: Multi-factor authentication including certificates, Microsoft Passport, virtual smart cards, picture passwords, and biometrics; workgroup vs. domain, Homegroup, computer and user authentication including secure channel, account policies, credential caching, and Credential Manager; local account vs. Microsoft account; Workplace Join; Configuring Windows Hello
Plan desktop and device deployment
- Migrate and configure user data
- Migrate user profiles; configure folder location; configure profiles including profile version, local, roaming, and mandatory
- Configure Hyper-V
- Create and configure virtual machines including integration services, create and manage checkpoints, create and configure virtual switches, create and configure virtual disks, move a virtual machine’s storage
- Configure mobility options
- Configure offline file policies, configure power policies, configure Windows To Go, configure sync options, configure Wi-Fi direct, files, powercfg, Sync Center
- Configure security for mobile devices
- Configure BitLocker, configure startup key storage
Plan and implement a Microsoft Intune device management solution
- Support mobile devices
- Support mobile device policies including security policies, remote access, and remote wipe; support mobile access and data synchronization including Work Folders and Sync Center; support broadband connectivity including broadband tethering and metered networks; support Mobile Device Management by using Microsoft Intune, including Windows Phone, iOS, and Android
- Deploy software updates by using Microsoft Intune
- Use reports and In-Console Monitoring to identify required updates, approve or decline updates, configure automatic approval settings, configure deadlines for update installations, deploy third-party updates
- Manage devices with Microsoft Intune
- Provision user accounts, enroll devices, view and manage all managed devices, configure the Microsoft Intune subscriptions, configure the Microsoft Intune connector site system role, manage user and computer groups, configure monitoring and alerts, manage policies, manage remote computers
Configure Networking
- Configure IP settings
- Configure name resolution, connect to a network, configure network locations
- Configure networking settings
- Connect to a wireless network, manage preferred wireless networks, configure network adapters, configure location-aware printing
- Configure and maintain network security
- Configure Windows Firewall, configure Windows Firewall with Advanced Security, configure connection security rules (IPsec), configure authenticated exceptions, configure network discovery
Configure Storage
- Support data storage
- Identifying and resolving issues related to the following: DFS client including caching settings, storage spaces including capacity and fault tolerance, OneDrive
- Support data security
- Identifying and resolving issues related to the following: Permissions including share, NTFS, and Dynamic Access Control (DAC); Encrypting File System (EFS) including Data Recovery Agent; access to removable media; BitLocker and BitLocker To Go including Data Recovery Agent and Microsoft BitLocker Administration and Monitoring (MBAM)
Manage data access and protection
- Configure shared resources
- Configure shared folder permissions, configure HomeGroup settings, configure libraries, configure shared printers, configure OneDrive
- Configure file and folder access
- Encrypt files and folders by using EFS, configure NTFS permissions, configure disk quotas, configure file access auditing Configure authentication and authorization
Manage remote access
- Configure remote connections
- Configure remote authentication, configure Remote Desktop settings, configure VPN connections and authentication, enable VPN reconnect, configure broadband tethering
- Configure mobility options
- Configure offline file policies, configure power policies, configure Windows To Go, configure sync options, configure Wi-Fi direct
Manage apps
- Deploy and manage Azure RemoteApp
- Configure RemoteApp and Desktop Connections settings, configure Group Policy Objects (GPOs) for signed packages, subscribe to the Azure RemoteApp and Desktop Connections feeds, export and import Azure RemoteApp configurations, support iOS and Android, configure remote desktop web access for Azure RemoteApp distribution
- Support desktop apps
- The following support considerations including: Desktop app compatibility using Application Compatibility Toolkit (ACT) including shims and compatibility database; desktop application co-existence using Hyper-V, Azure RemoteApp, and App-V; installation and configuration of User Experience Virtualization (UE-V); deploy desktop apps by using Microsoft Intune
Manage updates and recovery
- Configure system recovery
- Configure a recovery drive, configure system restore, perform a refresh or recycle, perform a driver rollback, configure restore points
- Configure file recovery
- Restore previous versions of files and folders, configure File History, recover files from OneDrive
- Configure and manage updates
- Configure update settings, configure Windows Update policies, manage update history, roll back updates, update Windows Store apps