What's changed: Created MD-102 Chapter 2 (domain: Manage and maintain devices). Deploy Windows clients (Windows Autopilot deployment profiles/device preparation policies, modes user-driven/pre-provisioning/self-deploying, Enrollment Status Page, Windows 11 upgrades, Windows 365 Cloud PC, Windows Backup), configuration profiles (device configuration profiles, ADMX import, Group Policy analytics, specialty devices, assignment filters, enrollment time grouping), and Intune Suite/remote actions (EPM, Remote Help, Cloud PKI, Microsoft Tunnel, Advanced Analytics, remote actions retire vs wipe, rotate BitLocker keys, device query KQL).
2.3Intune Suite and remote actions
Understand Intune Suite add-ons (Endpoint Privilege Management, Remote Help, Cloud PKI, Microsoft Tunnel, Advanced Analytics) and remote actions (sync/restart/retire/wipe, rotate BitLocker keys, device query KQL).
Strengthen operations with Intune Suite add-ons and remote actions on devices.
2.3.1Intune Suite add-ons
Endpoint Privilege Management (EPM) temporarily elevates standard users to admin only when needed, avoiding standing admins. Remote Help provides remote assistance (screen share/control); Cloud PKI issues/automates certificates in the cloud; Microsoft Tunnel is a VPN for MAM giving secure per-app access; Advanced Analytics does anomaly detection/proactive insights.
2.3.2Remote actions
Use remote actions: sync (policy sync), restart, retire (remove only org data/management, leaving personal data—for BYOD retirement), wipe (fully reset the device—for loss/redeployment). Distinguish "remove org data only" = retire from "full reset" = wipe. On loss, rotate BitLocker recovery keys to stay secure, and use device query (KQL) to query device state with KQL for investigation.
Cues: "temporarily elevate standard users only when needed" = Endpoint Privilege Management (EPM). "remote screen assistance" = Remote Help. "issue certificates in the cloud" = Cloud PKI. "VPN for MAM" = Microsoft Tunnel. "remove org data only (BYOD retire)" = retire. "full reset (loss/redeploy)" = wipe. "query device info with KQL" = device query.
Watch the mix-ups: (1) Retire (remove org data only, keep personal) vs wipe (full reset). (2) EPM (temporary elevation) vs granting standing admin. (3) Microsoft Tunnel (VPN for MAM) vs Cloud PKI (certificates) are different add-ons. (4) Device query (KQL) is for remote data collection/diagnostics.
2.3.3Section summary
- Intune Suite = EPM (temp elevation)/Remote Help/Cloud PKI/Microsoft Tunnel/Advanced Analytics
- Retire = remove org data only; wipe = full reset—choose by need
- Rotate BitLocker recovery keys; device query (KQL) queries device state
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. You want to temporarily elevate standard users for specific actions only, without granting standing admin. Best?
Q2. From a departing employee’s BYOD device, you want to remove only org data/management while keeping personal data. Best?
Q3. You want to fully reset a lost org-owned device for redeployment. Best?
Q4. You want help desk to remotely assist users via screen sharing on Windows devices. Best Intune Suite capability?
Q5. You want to query device state (OS, storage, config) across many devices on the fly using KQL. Best?

