Instiq
Chapter 5 · Optimize endpoint operations·v1.0.0·Updated 6/30/2026·~12 min

What's changed: Created MD-102 Chapter 5 (domain: Optimize endpoint operations). Automate management tasks (PowerShell/Microsoft Graph, custom compliance, Security Copilot agents in Intune), monitor/optimize health (Endpoint Analytics device health scores/startup performance/application reliability, proactive remediations detection/remediation scripts), and reporting/alerts (reporting/workbooks/dashboards/export, tenant health/service health dashboard/message center, alerts and notifications compliance drift/enrollment failures/configuration conflicts). This completes the MD-102 textbook: all 5 chapters / 13 sections.

5.1Automate management tasks

Key points

Understand automating Intune management tasks with PowerShell and Microsoft Graph, extending compliance with PowerShell, and using Security Copilot agents in Intune for threat investigation, performance analysis, and acting on recommendations.

Automate repetitive ops with scripts, and accelerate investigation/analysis with AI assistance.

5.1.1Script automation

Use PowerShell and Microsoft Graph to script and automate Intune management tasks (bulk assignment, configuration, report export). When built-in compliance policies are not enough, extend compliance with PowerShell (custom compliance scripts). These are "deterministic automation you write yourself"

5.1.2Security Copilot agents

Intune Security Copilot agents assist operations with AI: investigate threats, analyze device performance, and review and act on recommendations (aiding management decisions). Compared to scripts (deterministic work you write), Security Copilot agents’ role is "AI-assisted investigation/analysis/recommendations"—review recommendations before applying them.

Exam point

Cues: "script-automate Intune management tasks yourself" = PowerShell/Microsoft Graph. "supplement compliance beyond built-in" = custom compliance via PowerShell. "AI threat investigation/performance analysis/recommendations" = Security Copilot agents in Intune.

Warning

Watch the mix-ups: (1) PowerShell/Graph (deterministic automation you write) vs Security Copilot agents (AI-assisted investigation/analysis/recommendations). (2) Custom compliance scripts supplement built-in compliance policies. (3) Review Copilot recommendations before applying.

Diagram: PowerShell and Microsoft Graph deterministically script Intune management tasks (bulk assignment/config/report export), and custom compliance via PowerShell supplements built-in evaluation; Security Copilot agents in Intune use AI to assist threat investigation, device performance analysis, and reviewing/acting on recommendations (scripts = deterministic, Copilot = AI assistance — distinct roles).
Deterministic vs AI

5.1.3Section summary

  • Automate Intune tasks and extend compliance with PowerShell/Microsoft Graph
  • Security Copilot agents in Intune provide AI threat investigation/performance analysis/recommendations
  • Scripts = deterministic automation; Copilot = AI assistance—different roles

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. You want to deterministically script repetitive tasks like policy assignment and report export across hundreds of devices. Best?

Q2. You want to evaluate custom conditions not covered by built-in compliance policies, via scripts. Best?

Q3. In Intune, you want to use AI to investigate threats, analyze device performance, and review recommendations. Best?

Q4. What correctly distinguishes PowerShell/Graph from Security Copilot agents?

Q5. What is the appropriate stance for an admin toward recommendations from Security Copilot agents?

Check your understandingPractice questions for Chapter 5: Optimize endpoint operations

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.