Instiq

Microsoft 365 Endpoint Administrator — knowledge map

The 51 core concepts of Microsoft 365 Endpoint Administrator and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.

Concepts (51)

  • Microsoft Intune

    A cloud service to manage/secure devices and apps; MDM manages the device itself, MAM manages in-app data; integrates with Conditional Access.

    Prerequisites: Conditional Access

  • Microsoft Entra join

    A method that fully, cloud-natively joins an organization-owned device to Microsoft Entra ID. The device authenticates solely against Entra ID and can be brought under full management via Intune auto-enrollment (automatic MDM enrollment). It does not join on-prem AD, making it the default choice for cloud-only organizations or new devices.

    Prerequisites: Microsoft Entra IDMicrosoft Intune

    Related: Microsoft Entra hybrid joinAutomatic enrollment (Intune)

  • Automatic enrollment (Intune)

    A mechanism where a Windows device is automatically enrolled into Intune at the same time it performs Microsoft Entra join (or hybrid join). With auto-enrollment enabled in the MDM authority settings, a user simply signs in and the device comes under management without a manual enrollment step—foundational for bulk deployment of corporate-owned devices.

    Prerequisites: Microsoft Entra hybrid joinMicrosoft Intune

    Related: Microsoft Entra joinEnrollment restrictions (Intune)

  • Apple Business Manager

    Apple's web portal that links organization-purchased Apple devices to any MDM solution—Jamf, Intune, and others—so they auto-enroll and configure via Automated Device Enrollment (formerly DEP) out of the box. It also manages app and book licenses (formerly the Volume Purchase Program/VPP, now integrated into ABM's "Apps and Books"), bringing both devices and apps under centralized corporate management.

    Prerequisites: Microsoft Intune

    Related: Google Zero Touch EnrollmentSamsung Knox Mobile Enrollment

  • Apple Volume Purchase Program (VPP)

    A mechanism to bulk-purchase paid/free Apple App Store apps at the organization level, sync them into Intune via Apple Business Manager, and assign/reclaim licenses per device or user. Device-based assignment lets apps be distributed without requiring a personal Apple ID, enabling app deployment on BYOD without compromising personal privacy.

    Prerequisites: Apple Business ManagerMicrosoft Intune

    Related: Quiet Time policiesManaged Google Play

  • Conditional Access

    Grants or challenges access based on conditions like location, device, or risk (a Zero Trust implementation).

  • Microsoft Entra ID

    Cloud identity/access management (formerly Azure AD) providing MFA/SSO/Conditional Access; distinct from on-prem AD DS.

    Prerequisites: Conditional Access

  • Microsoft Entra hybrid join

    A method that joins a device already joined to on-premises Active Directory to Entra ID as well, via Entra Connect synchronization, giving it both authorities. Used by organizations in a migration period wanting to run on-prem Group Policy (GPO) alongside Intune/Conditional Access, or in environments with legacy apps still dependent on on-prem AD.

    Prerequisites: Conditional AccessMicrosoft Entra IDMicrosoft Intune

    Related: Microsoft Entra join

  • Samsung Knox Mobile Enrollment

    Samsung's own bulk-deployment service that registers Samsung Android devices in the Knox portal so they auto-enroll into Intune and configure at first boot. It plays a similar role to Google Zero Touch, but integrates with Samsung-specific Knox security features.

    Prerequisites: Google Zero Touch EnrollmentAutomatic enrollment (Intune)Microsoft Intune

    Related: Apple Business Manager

  • App protection policy (MAM)

    A policy protecting organizational data inside apps via MAM (Mobile Application Management). It sets restrictions like copy/paste out of the app, encryption, an access PIN/biometric, and data-transfer limits to other apps (data protection only). Enrollment is not required, so it applies to apps on unenrolled BYOD, and on offboarding it can selectively wipe only the org data within the app.

    Prerequisites: Remote actions (retire / wipe / device query)

  • Google Zero Touch Enrollment

    A mechanism where supported Android devices, registered with Google's portal via a reseller, automatically pick up a management profile from any EMM (DPC) such as Intune on first boot. It's a generic enrollment method provided by Google, not tied to a specific EMM, and reaches a fully managed configuration with no user interaction, suiting bulk corporate procurement deployments.

    Prerequisites: Microsoft Intune

    Related: Apple Business Manager

  • ADMX import (Intune)

    A feature that ingests registry-based settings defined in administrative templates (ADMX/ADML files) into Intune, making them deployable as an "Imported Administrative templates" configuration profile. Third-party ADMX settings not yet in the Settings Catalog (e.g., for Office) can also be added as custom ADMX.

    Prerequisites: Settings Catalog (Intune)Microsoft Intune

    Related: Group Policy analytics

  • Advanced Analytics (Intune Suite)

    An Intune Suite add-on that extends standard Endpoint Analytics metrics with proactive analysis across the fleet, such as anomaly detection and root-cause analysis of device failures. It surfaces trends before issues become widespread, giving IT an early trigger to remediate.

    Prerequisites: Endpoint AnalyticsMicrosoft Intune

    Related: Remote Help (Intune Suite)

  • Antivirus policy (Intune)

    An Endpoint security policy type that deploys Microsoft Defender Antivirus settings—real-time protection, cloud-delivered protection, scan schedules—to devices. It focuses specifically on malware detection/removal, including notifications and exclusions; a separate layer from a security baseline or ASR, configuring the detect/remove behavior itself.

    Prerequisites: Microsoft Defender XDRSecurity baseline (Intune)Microsoft Intune

  • Quiet Time policies

    An Intune app-configuration capability for Android/iOS that suppresses mobile app notifications during a specified window (e.g., off-hours or overnight). Aimed at work-life balance or keeping frontline workers focused, it can selectively mute notifications from work apps during that window.

    Prerequisites: Microsoft Intune

    Related: Apple Volume Purchase Program (VPP)Managed Google Play

  • Remote Help (Intune Suite)

    An Intune Suite add-on letting help desk staff remotely connect to an end user's device for view-only or full-control remote assistance. Entra ID-based authentication and RBAC govern help desk permissions, and connections work without a VPN even from outside the corporate network.

    Prerequisites: Microsoft Entra IDMicrosoft Intune

    Related: Advanced Analytics (Intune Suite)

  • Settings Catalog (Intune)

    A method that lets admins search and pick from every setting Intune exposes and freely combine them into a custom configuration profile. Unlike pre-templated profile types, it offers fine-grained flexibility by selecting only the settings needed from the catalog, and new OS settings are added over time.

    Prerequisites: Microsoft Intune

    Related: Specialty devices (Intune)

  • App Control for Business

    An allowlist-based application-control feature (formerly Windows Defender Application Control/WDAC) that predefines which apps, drivers, and scripts may run, blocking everything else by default. A zero-trust-leaning control that prevents malware or unapproved software from running at all, with policies deployable from Intune.

    Prerequisites: Microsoft Intune

    Related: Firewall policy (Intune)

  • Device registration

    A method that registers a personally-owned device (BYOD) with Entra ID, giving the device an Entra ID identity for accessing company resources without placing the device itself under organizational management. Typically registered with a personal account, with app-level protection applied via MAM (mobile application management). Its management scope differs from Entra join / hybrid join, which manage the entire device.

    Prerequisites: App protection policy (MAM)Microsoft Entra IDMicrosoft Entra hybrid joinMicrosoft Entra join

  • Group Policy analytics

    An Intune feature that imports and analyzes existing on-prem GPOs (Group Policy Objects) to assess whether each setting can migrate to an Intune MDM setting. It surfaces unsupported or deprecated settings for pre-migration planning (analysis only—actual conversion/application is a separate step).

    Prerequisites: Microsoft Intune

    Related: ADMX import (Intune)

  • Alerts and notifications (Intune)

    An Intune feature that notifies admins based on preconfigured alert rules when it detects events like compliance drift, a spike in enrollment failures, or configuration conflicts. Distinct from report visualization, its role is proactively pushing notifications when a threshold is crossed.

    Prerequisites: Microsoft Intune

    Related: Reporting and data visibility (Intune)Service health

  • Cloud PKI (Intune Suite)

    An Intune Suite add-on that creates root/issuing CAs in the cloud and automates certificate lifecycle (issuance, renewal, revocation) without building an on-prem PKI. Used together with certificate-delivery profiles for Wi-Fi, VPN, and authentication.

    Prerequisites: Microsoft Intune

    Related: Microsoft Tunnel

  • Enrollment restrictions (Intune)

    A policy mechanism restricting which device platforms (iOS/Android/Windows, etc.), OS versions, or personally owned (BYOD) devices may enroll. A default restriction and custom restrictions for specific groups are applied by priority order, letting admins block enrollment from unsupported old OS versions or disallowed platforms.

    Prerequisites: Microsoft Intune

    Related: Automatic enrollment (Intune)

  • Reporting and data visibility (Intune)

    A set of features in the Intune admin center that visualize compliance and deployment status through org/device/policy-level reports, workbooks, and dashboards, and let admins export data (e.g., to CSV) for further analysis. Covers both operational reports and organization-wide dashboards.

    Prerequisites: Microsoft Intune

    Related: Alerts and notifications (Intune)Service health

  • Specialty devices (Intune)

    "Specialty devices" is an official Intune management category (Intune admin center: Devices > Specialty devices) for purpose-built devices distinct from typical PCs/mobiles, such as Teams Rooms, Microsoft HoloLens 2, and Surface Hub. Dedicated configuration profiles and app-delivery methods are provided, managing these purpose-built devices together, separately from ordinary platform-based (Windows/Android/iOS) device management.

    Prerequisites: Microsoft Intune

    Related: Settings Catalog (Intune)

  • Update rings (Intune)

    A policy-based mechanism that codifies Windows Update for Business settings, staging update rollout timing (deferral days) and restart grace periods differently per device group (ring). Detecting problems in an early ring (IT/pilot group) before rolling out to broader rings limits the blast radius of a bad update.

    Prerequisites: Microsoft Intune

  • Managed Google Play

    Integrates an organization's Google Play store into Intune, allowing approval/distribution of public apps as well as private in-house apps. Used together with Android Enterprise enrollment (fully managed, work profile, etc.), it also centrally manages app auto-updates and app configuration.

    Prerequisites: Android Enterprise enrollment typesMicrosoft Intune

    Related: Apple Volume Purchase Program (VPP)Quiet Time policies

  • Device compliance policy

    Evaluates compliant/noncompliant whether a device meets requirements like encryption and minimum OS (Conditional Access enforces on the result; evaluation and enforcement are separate layers).

    Prerequisites: Conditional Access

  • Disk encryption (BitLocker)

    Encrypts Windows disks and securely stores/retrieves recovery keys in Intune; self-service recovery lets locked-out users retrieve their own recovery key.

    Prerequisites: Microsoft Intune

  • Remote actions (retire / wipe / device query)

    Retire removes only org data/management and keeps personal data (e.g., BYOD offboarding); wipe fully resets the device (lost/redeploy); device query queries device state on the fly with KQL; rotate BitLocker recovery keys refreshes keys.

    Prerequisites: Disk encryption (BitLocker)

  • Microsoft Tunnel

    A standard, no-extra-cost Intune feature—a Linux-based gateway VPN providing secure access to MDM-enrolled devices. Providing per-app access to unenrolled BYOD devices managed only via MAM requires a separate product, Microsoft Tunnel for Mobile Application Management (Tunnel for MAM), part of the Intune Suite/MAM add-on; it is this MAM version that integrates with app protection policy to restrict access to internal resources to work apps only.

    Prerequisites: App protection policy (MAM)Microsoft Intune

    Related: Cloud PKI (Intune Suite)

  • Microsoft 365 Apps deployment

    Delivers and updates client Office (Word/Excel) via Click-to-Run. Update channels (Current/Monthly Enterprise/Semi-Annual) control update cadence.

  • Microsoft Defender XDR

    Unifies protection across endpoints/email/identity/SaaS, correlating signals across domains (Endpoint/Office 365/Identity/Cloud Apps).

  • Endpoint Analytics

    An Intune analytics feature that visualizes endpoint performance/reliability and user experience through metrics like device health scores (startup, battery, driver health), startup performance (boot-time breakdown), and application reliability (app crash/unresponsive frequency). It specializes in visualization and does not itself automatically fix detected issues.

    Prerequisites: Microsoft Intune

  • Security baseline (Intune)

    A mechanism applying Microsoft's pre-defined bundle (template) of security-expert-recommended settings—for Windows, Edge, Defender for Endpoint, etc.—in one go. It saves the effort of picking every setting individually, serving as an industry-aligned starting point that can still be overridden setting by setting.

    Prerequisites: Microsoft Intune

  • Update types (feature updates / quality updates)

    A classification of Windows updates by purpose. Feature updates are large, roughly annual releases that add new capabilities (equivalent to moving to a new OS version); quality updates are monthly releases (centered on Patch Tuesday, the second Tuesday) carrying security and bug fixes. Update rings let admins set separate deferral days for each type.

    Prerequisites: Update rings (Intune)

  • Android Enterprise enrollment types

    Android management modes: fully managed (corporate, fully managed), dedicated (single-purpose kiosk), corporate-owned work profile (corporate with work/personal separation), personally-owned work profile (personal with a work container)—chosen by ownership and use.

  • Device configuration profile

    Centrally distributes settings (language, security) to devices from Intune (distributes settings—distinct from a compliance policy that evaluates).

    Prerequisites: Device compliance policyMicrosoft Intune

  • Endpoint Privilege Management (EPM)

    An Intune Suite add-on that temporarily elevates standard users for specific actions only, without standing admin (least privilege).

    Prerequisites: Microsoft Intune

  • App types (Win32 / LOB / Microsoft Store)

    A Win32 app is a classic desktop app packaged as .intunewin; a line-of-business (LOB) app is an in-house app; a Microsoft Store app is store-delivered. Deploy by format.

  • Service Health (Microsoft 365)

    In the Microsoft 365 admin center, shows Microsoft-side service incidents/advisories (outage, degradation, planned maintenance) and configures notifications. Distinct from Network connectivity insights (your network path).

    Prerequisites: Service health

  • Office Deployment Tool (ODT)

    A command-line tool that finely controls a Click-to-Run installation of Microsoft 365 Apps (Office) via an XML configuration file. It specifies which apps, languages, update channel, and excluded components to include, producing a custom package deployable as an Intune Win32 app or via a distribution share.

    Prerequisites: App types (Win32 / LOB / Microsoft Store)Microsoft IntuneMicrosoft 365 Apps deployment

  • Service health

    Shows status, incidents, planned maintenance, and advisories in real time in the admin center (the "current state" vs the SLA "promise").

    Related: Alerts and notifications (Intune)Reporting and data visibility (Intune)

  • Windows Autopatch

    A managed update service where Microsoft takes over update-ring management and rollout monitoring for Windows, Microsoft 365 Apps, Microsoft Edge, and Teams. Devices are automatically sorted into four default deployment rings (Test/First/Fast/Broad), and Microsoft pauses/investigates on issues—aimed at reducing IT's update-management workload.

    Prerequisites: Microsoft 365 Apps deployment

  • App configuration policy

    A mechanism that pushes app behavior settings (server connection URL, default sign-in domain, feature toggles, etc.) in advance so users don't have to configure them manually. It comes in a managed-device flavor and a managed-app (MAM) flavor; unlike an app protection policy, its role is delivering the app's configuration values themselves, not data protection.

    Prerequisites: App protection policy (MAM)

  • Firewall policy (Intune)

    An Endpoint security policy type that governs a device's inbound/outbound traffic via rules. It centrally deploys Windows Defender Firewall settings (per-profile on/off, rules, notification suppression) from Intune to allow/deny traffic for specific ports or apps. Whereas App Control restricts which apps may run, this restricts network communication.

    Prerequisites: Microsoft Intune

    Related: App Control for Business

  • Multi-admin approval (Intune)

    A mechanism that holds high-impact configuration changes (e.g., running a script) pending approval from an admin other than the requester before applying them. Implements a four-eyes principle preventing a single admin's mistake or insider misuse from immediately hitting production.

    Prerequisites: Microsoft Intune

    Related: Scope tags (Intune)

  • Proactive remediations

    An Intune feature named Remediations (formerly Proactive remediations, managed under Endpoint Analytics' Scripts) that pairs a detection script with a remediation script to auto-detect and auto-fix common issues (low disk space, a stopped service, etc.). The remediation script runs when the detection script's exit code is non-zero (failure); you can schedule the run and assign it by device group with RBAC. It's an execution counterpart to Endpoint Analytics' visualization, forming a detect-then-fix loop.

    Prerequisites: Endpoint AnalyticsMicrosoft Intune

  • Scope tags (Intune)

    A delegation mechanism that tags objects (policies, apps, devices) so only admins whose role is scoped to that tag can manage or view them. Used by large organizations wanting to split administration by region or department—narrowing the target scope on top of RBAC role permissions.

    Prerequisites: Microsoft Intune

    Related: Multi-admin approval (Intune)

  • Windows Autopilot

    Reuses existing hardware and automates Microsoft Entra join + Intune enrollment + configuration via OOBE (replaces traditional imaging). Modes: user-driven (user signs in to self-configure), pre-provisioning (IT preps in advance), self-deploying (no interaction, for kiosks).

    Prerequisites: Microsoft Entra joinMicrosoft Intune

  • Security Copilot agents in Intune

    Uses AI in Intune to investigate threats, analyze device performance, and review/act on recommendations. Versus deterministic PowerShell/Microsoft Graph automation you write, its role is AI-assisted investigation/analysis/recommendations (review before applying).

    Prerequisites: Microsoft Intune