Microsoft 365 Endpoint Administrator — knowledge map
The 51 core concepts of Microsoft 365 Endpoint Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.
Concepts (51)
Microsoft Intune
A cloud service to manage/secure devices and apps; MDM manages the device itself, MAM manages in-app data; integrates with Conditional Access.
Prerequisites: Conditional Access
Microsoft Entra join
A method that fully, cloud-natively joins an organization-owned device to Microsoft Entra ID. The device authenticates solely against Entra ID and can be brought under full management via Intune auto-enrollment (automatic MDM enrollment). It does not join on-prem AD, making it the default choice for cloud-only organizations or new devices.
Prerequisites: Microsoft Entra ID、Microsoft Intune
Related: Microsoft Entra hybrid join、Automatic enrollment (Intune)
Automatic enrollment (Intune)
A mechanism where a Windows device is automatically enrolled into Intune at the same time it performs Microsoft Entra join (or hybrid join). With auto-enrollment enabled in the MDM authority settings, a user simply signs in and the device comes under management without a manual enrollment step—foundational for bulk deployment of corporate-owned devices.
Prerequisites: Microsoft Entra hybrid join、Microsoft Intune
Related: Microsoft Entra join、Enrollment restrictions (Intune)
Apple Business Manager
Apple's web portal that links organization-purchased Apple devices to any MDM solution—Jamf, Intune, and others—so they auto-enroll and configure via Automated Device Enrollment (formerly DEP) out of the box. It also manages app and book licenses (formerly the Volume Purchase Program/VPP, now integrated into ABM's "Apps and Books"), bringing both devices and apps under centralized corporate management.
Prerequisites: Microsoft Intune
Related: Google Zero Touch Enrollment、Samsung Knox Mobile Enrollment
Apple Volume Purchase Program (VPP)
A mechanism to bulk-purchase paid/free Apple App Store apps at the organization level, sync them into Intune via Apple Business Manager, and assign/reclaim licenses per device or user. Device-based assignment lets apps be distributed without requiring a personal Apple ID, enabling app deployment on BYOD without compromising personal privacy.
Prerequisites: Apple Business Manager、Microsoft Intune
Related: Quiet Time policies、Managed Google Play
Conditional Access
Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).
Microsoft Entra ID
Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.
Prerequisites: Conditional Access
Microsoft Entra hybrid join
A method that joins a device already joined to on-premises Active Directory to Entra ID as well, via Entra Connect synchronization, giving it both authorities. Used by organizations in a migration period wanting to run on-prem Group Policy (GPO) alongside Intune/Conditional Access, or in environments with legacy apps still dependent on on-prem AD.
Prerequisites: Conditional Access、Microsoft Entra ID、Microsoft Intune
Related: Microsoft Entra join
Samsung Knox Mobile Enrollment
Samsung's own bulk-deployment service that registers Samsung Android devices in the Knox portal so they auto-enroll into Intune and configure at first boot. It plays a similar role to Google Zero Touch, but integrates with Samsung-specific Knox security features.
Prerequisites: Google Zero Touch Enrollment、Automatic enrollment (Intune)、Microsoft Intune
Related: Apple Business Manager
App protection policy (MAM)
A policy protecting organizational data inside apps via MAM (Mobile Application Management). It sets restrictions like copy/paste out of the app, encryption, an access PIN/biometric, and data-transfer limits to other apps (data protection only). Enrollment is not required, so it applies to apps on unenrolled BYOD, and on offboarding it can selectively wipe only the org data within the app.
Prerequisites: Remote actions (retire / wipe / device query)
Google Zero Touch Enrollment
A mechanism where supported Android devices, registered with Google's portal via a reseller, automatically pick up a management profile from any EMM (DPC) such as Intune on first boot. It's a generic enrollment method provided by Google, not tied to a specific EMM, and reaches a fully managed configuration with no user interaction, suiting bulk corporate procurement deployments.
Prerequisites: Microsoft Intune
Related: Apple Business Manager
ADMX import (Intune)
A feature that ingests registry-based settings defined in administrative templates (ADMX/ADML files) into Intune, making them deployable as an "Imported Administrative templates" configuration profile. Third-party ADMX settings not yet in the Settings Catalog (e.g., for Office) can also be added as custom ADMX.
Prerequisites: Settings Catalog (Intune)、Microsoft Intune
Related: Group Policy analytics
Advanced Analytics (Intune Suite)
An Intune Suite add-on that extends standard Endpoint Analytics metrics with proactive analysis across the fleet, such as anomaly detection and root-cause analysis of device failures. It surfaces trends before issues become widespread, giving IT an early trigger to remediate.
Prerequisites: Endpoint Analytics、Microsoft Intune
Related: Remote Help (Intune Suite)
Antivirus policy (Intune)
An Endpoint security policy type that deploys Microsoft Defender Antivirus settings—real-time protection, cloud-delivered protection, scan schedules—to devices. It focuses specifically on malware detection/removal, including notifications and exclusions; a separate layer from a security baseline or ASR, configuring the detect/remove behavior itself.
Prerequisites: Microsoft Defender XDR、Security baseline (Intune)、Microsoft Intune
Quiet Time policies
An Intune app-configuration capability for Android/iOS that suppresses mobile app notifications during a specified window (e.g., off-hours or overnight). Aimed at work-life balance or keeping frontline workers focused, it can selectively mute notifications from work apps during that window.
Prerequisites: Microsoft Intune
Related: Apple Volume Purchase Program (VPP)、Managed Google Play
Remote Help (Intune Suite)
An Intune Suite add-on letting help desk staff remotely connect to an end user's device for view-only or full-control remote assistance. Entra ID-based authentication and RBAC govern help desk permissions, and connections work without a VPN even from outside the corporate network.
Prerequisites: Microsoft Entra ID、Microsoft Intune
Related: Advanced Analytics (Intune Suite)
Settings Catalog (Intune)
A method that lets admins search and pick from every setting Intune exposes and freely combine them into a custom configuration profile. Unlike pre-templated profile types, it offers fine-grained flexibility by selecting only the settings needed from the catalog, and new OS settings are added over time.
Prerequisites: Microsoft Intune
Related: Specialty devices (Intune)
App Control for Business
An allowlist-based application-control feature (formerly Windows Defender Application Control/WDAC) that predefines which apps, drivers, and scripts may run, blocking everything else by default. A zero-trust-leaning control that prevents malware or unapproved software from running at all, with policies deployable from Intune.
Prerequisites: Microsoft Intune
Related: Firewall policy (Intune)
Device registration
A method that registers a personally-owned device (BYOD) with Entra ID, giving the device an Entra ID identity for accessing company resources without placing the device itself under organizational management. Typically registered with a personal account, with app-level protection applied via MAM (mobile application management). Its management scope differs from Entra join / hybrid join, which manage the entire device.
Prerequisites: App protection policy (MAM)、Microsoft Entra ID、Microsoft Entra hybrid join、Microsoft Entra join
Group Policy analytics
An Intune feature that imports and analyzes existing on-prem GPOs (Group Policy Objects) to assess whether each setting can migrate to an Intune MDM setting. It surfaces unsupported or deprecated settings for pre-migration planning (analysis only—actual conversion/application is a separate step).
Prerequisites: Microsoft Intune
Related: ADMX import (Intune)
Alerts and notifications (Intune)
An Intune feature that notifies admins based on preconfigured alert rules when it detects events like compliance drift, a spike in enrollment failures, or configuration conflicts. Distinct from report visualization, its role is proactively pushing notifications when a threshold is crossed.
Prerequisites: Microsoft Intune
Related: Reporting and data visibility (Intune)、Service health
Cloud PKI (Intune Suite)
An Intune Suite add-on that creates root/issuing CAs in the cloud and automates certificate lifecycle (issuance, renewal, revocation) without building an on-prem PKI. Used together with certificate-delivery profiles for Wi-Fi, VPN, and authentication.
Prerequisites: Microsoft Intune
Related: Microsoft Tunnel
Enrollment restrictions (Intune)
A policy mechanism restricting which device platforms (iOS/Android/Windows, etc.), OS versions, or personally owned (BYOD) devices may enroll. A default restriction and custom restrictions for specific groups are applied by priority order, letting admins block enrollment from unsupported old OS versions or disallowed platforms.
Prerequisites: Microsoft Intune
Related: Automatic enrollment (Intune)
Reporting and data visibility (Intune)
A set of features in the Intune admin center that visualize compliance and deployment status through org/device/policy-level reports, workbooks, and dashboards, and let admins export data (e.g., to CSV) for further analysis. Covers both operational reports and organization-wide dashboards.
Prerequisites: Microsoft Intune
Specialty devices (Intune)
"Specialty devices" is an official Intune management category (Intune admin center: Devices > Specialty devices) for purpose-built devices distinct from typical PCs/mobiles, such as Teams Rooms, Microsoft HoloLens 2, and Surface Hub. Dedicated configuration profiles and app-delivery methods are provided, managing these purpose-built devices together, separately from ordinary platform-based (Windows/Android/iOS) device management.
Prerequisites: Microsoft Intune
Related: Settings Catalog (Intune)
Update rings (Intune)
A policy-based mechanism that codifies Windows Update for Business settings, staging update rollout timing (deferral days) and restart grace periods differently per device group (ring). Detecting problems in an early ring (IT/pilot group) before rolling out to broader rings limits the blast radius of a bad update.
Prerequisites: Microsoft Intune
Managed Google Play
Integrates an organization's Google Play store into Intune, allowing approval/distribution of public apps as well as private in-house apps. Used together with Android Enterprise enrollment (fully managed, work profile, etc.), it also centrally manages app auto-updates and app configuration.
Prerequisites: Android Enterprise enrollment types、Microsoft Intune
Related: Apple Volume Purchase Program (VPP)、Quiet Time policies
Device compliance policy
Evaluates compliant/noncompliant whether a device meets requirements like encryption and minimum OS (Conditional Access enforces on the result; evaluation and enforcement are separate layers).
Prerequisites: Conditional Access
Disk encryption (BitLocker)
Encrypts Windows disks and securely stores/retrieves recovery keys in Intune; self-service recovery lets locked-out users retrieve their own recovery key.
Prerequisites: Microsoft Intune
Remote actions (retire / wipe / device query)
Retire removes only org data/management and keeps personal data (e.g., BYOD offboarding); wipe fully resets the device (lost/redeploy); device query queries device state on the fly with KQL; rotate BitLocker recovery keys refreshes keys.
Prerequisites: Disk encryption (BitLocker)
Microsoft Tunnel
A standard, no-extra-cost Intune feature—a Linux-based gateway VPN providing secure access to MDM-enrolled devices. Providing per-app access to unenrolled BYOD devices managed only via MAM requires a separate product, Microsoft Tunnel for Mobile Application Management (Tunnel for MAM), part of the Intune Suite/MAM add-on; it is this MAM version that integrates with app protection policy to restrict access to internal resources to work apps only.
Prerequisites: App protection policy (MAM)、Microsoft Intune
Related: Cloud PKI (Intune Suite)
Microsoft 365 Apps deployment
Delivers and updates client Office (Word/Excel) via Click-to-Run. Update channels (Current/Monthly Enterprise/Semi-Annual) control update cadence.
Microsoft Defender XDR
Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).
Endpoint Analytics
An Intune analytics feature that visualizes endpoint performance/reliability and user experience through metrics like device health scores (startup, battery, driver health), startup performance (boot-time breakdown), and application reliability (app crash/unresponsive frequency). It specializes in visualization and does not itself automatically fix detected issues.
Prerequisites: Microsoft Intune
Security baseline (Intune)
A mechanism applying Microsoft's pre-defined bundle (template) of security-expert-recommended settings—for Windows, Edge, Defender for Endpoint, etc.—in one go. It saves the effort of picking every setting individually, serving as an industry-aligned starting point that can still be overridden setting by setting.
Prerequisites: Microsoft Intune
Update types (feature updates / quality updates)
A classification of Windows updates by purpose. Feature updates are large, roughly annual releases that add new capabilities (equivalent to moving to a new OS version); quality updates are monthly releases (centered on Patch Tuesday, the second Tuesday) carrying security and bug fixes. Update rings let admins set separate deferral days for each type.
Prerequisites: Update rings (Intune)
Android Enterprise enrollment types
Android management modes: fully managed (corporate, fully managed), dedicated (single-purpose kiosk), corporate-owned work profile (corporate with work/personal separation), personally-owned work profile (personal with a work container)—chosen by ownership and use.
Device configuration profile
Centrally distributes settings (language, security) to devices from Intune (distributes settings—distinct from a compliance policy that evaluates).
Prerequisites: Device compliance policy、Microsoft Intune
Endpoint Privilege Management (EPM)
An Intune Suite add-on that temporarily elevates standard users for specific actions only, without standing admin (least privilege).
Prerequisites: Microsoft Intune
App types (Win32 / LOB / Microsoft Store)
A Win32 app is a classic desktop app packaged as .intunewin; a line-of-business (LOB) app is an in-house app; a Microsoft Store app is store-delivered. Deploy by format.
Service Health (Microsoft 365)
In the Microsoft 365 admin center, shows Microsoft-side service incidents/advisories (outage, degradation, planned maintenance) and configures notifications. Distinct from Network connectivity insights (your network path).
Prerequisites: Service health
Office Deployment Tool (ODT)
A command-line tool that finely controls a Click-to-Run installation of Microsoft 365 Apps (Office) via an XML configuration file. It specifies which apps, languages, update channel, and excluded components to include, producing a custom package deployable as an Intune Win32 app or via a distribution share.
Prerequisites: App types (Win32 / LOB / Microsoft Store)、Microsoft Intune、Microsoft 365 Apps deployment
Service health
Shows status, incidents, planned maintenance, and advisories in real time in the admin center (the "current state" vs the SLA "promise").
Related: Alerts and notifications (Intune)、Reporting and data visibility (Intune)
Windows Autopatch
A managed update service where Microsoft takes over update-ring management and rollout monitoring for Windows, Microsoft 365 Apps, Microsoft Edge, and Teams. Devices are automatically sorted into four default deployment rings (Test/First/Fast/Broad), and Microsoft pauses/investigates on issues—aimed at reducing IT's update-management workload.
Prerequisites: Microsoft 365 Apps deployment
App configuration policy
A mechanism that pushes app behavior settings (server connection URL, default sign-in domain, feature toggles, etc.) in advance so users don't have to configure them manually. It comes in a managed-device flavor and a managed-app (MAM) flavor; unlike an app protection policy, its role is delivering the app's configuration values themselves, not data protection.
Prerequisites: App protection policy (MAM)
Firewall policy (Intune)
An Endpoint security policy type that governs a device's inbound/outbound traffic via rules. It centrally deploys Windows Defender Firewall settings (per-profile on/off, rules, notification suppression) from Intune to allow/deny traffic for specific ports or apps. Whereas App Control restricts which apps may run, this restricts network communication.
Prerequisites: Microsoft Intune
Related: App Control for Business
Multi-admin approval (Intune)
A mechanism that holds high-impact configuration changes (e.g., running a script) pending approval from an admin other than the requester before applying them. Implements a four-eyes principle preventing a single admin's mistake or insider misuse from immediately hitting production.
Prerequisites: Microsoft Intune
Related: Scope tags (Intune)
Proactive remediations
An Intune feature named Remediations (formerly Proactive remediations, managed under Endpoint Analytics' Scripts) that pairs a detection script with a remediation script to auto-detect and auto-fix common issues (low disk space, a stopped service, etc.). The remediation script runs when the detection script's exit code is non-zero (failure); you can schedule the run and assign it by device group with RBAC. It's an execution counterpart to Endpoint Analytics' visualization, forming a detect-then-fix loop.
Prerequisites: Endpoint Analytics、Microsoft Intune
Windows Autopilot
Reuses existing hardware and automates Microsoft Entra join + Intune enrollment + configuration via OOBE (replaces traditional imaging). Modes: user-driven (user signs in to self-configure), pre-provisioning (IT preps in advance), self-deploying (no interaction, for kiosks).
Prerequisites: Microsoft Entra join、Microsoft Intune
Security Copilot agents in Intune
Uses AI in Intune to investigate threats, analyze device performance, and review/act on recommendations. Versus deterministic PowerShell/Microsoft Graph automation you write, its role is AI-assisted investigation/analysis/recommendations (review before applying).
Prerequisites: Microsoft Intune

