<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="36349" language="en" source="https://portal.flane.ch/swisscom/en/xml-course/masterclass-imdmb" lastchanged="2026-03-04T18:08:46+01:00" parent="https://portal.flane.ch/swisscom/en/xml-courses"><title>Master Class: Intune Modern Device Management Intensive Bundle</title><productcode>IMDMB</productcode><vendorcode>MT</vendorcode><vendorname>Master Class</vendorname><fullproductcode>MT-IMDMB</fullproductcode><version>1.0</version><objective>&lt;p&gt;After completing this workshop, participants will have knowledge in the following areas:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Setup and operation of hybrid Microsoft Entra ID environments for all platforms&lt;/li&gt;&lt;li&gt;Implementation of various enrollment strategies for Windows, macOS, iOS and Android&lt;/li&gt;&lt;li&gt;Automated device management with Windows Autopilot and Apple Business Manager&lt;/li&gt;&lt;li&gt;Android Enterprise Deployment&lt;/li&gt;&lt;li&gt;Extended compliance and conditional access strategies, cross-platform&lt;/li&gt;&lt;li&gt;Mobile Application Management (MAM) for iOS and Android&lt;/li&gt;&lt;li&gt;PowerShell-based automation and community tools&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;h5&gt;Required:&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Sound Windows 10/11 Administration&lt;/li&gt;&lt;li&gt;Active Directory Domain Services experience&lt;/li&gt;&lt;li&gt;PowerShell basic knowledge&lt;/li&gt;&lt;li&gt;Basic understanding of network and PKI&lt;/li&gt;&lt;li&gt;Basic understanding of iOS and Android platforms&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Recommended:&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Microsoft 365/Microsoft Entra ID experience&lt;/li&gt;&lt;li&gt;Group Policy Management knowledge&lt;/li&gt;&lt;li&gt;SCCM/Configuration Manager Background&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;ul&gt;
&lt;li&gt;IT professionals who want to centrally manage all device platforms with Intune&lt;/li&gt;&lt;li&gt;System Engineers with a focus on Modern Device Management (Desktop &amp;amp; Mobile)&lt;/li&gt;&lt;li&gt;People migrating from traditional MDM solutions to Microsoft Intune&lt;/li&gt;&lt;li&gt;IT consultants who carry out complete Intune implementations&lt;/li&gt;&lt;li&gt;Mobile device managers who want to expand their desktop skills&lt;/li&gt;&lt;li&gt;This workshop is aimed at experienced IT professionals who want to master the full spectrum of modern device management. Ideal for teams who need a comprehensive yet efficient introduction to all Intune platforms.&lt;/li&gt;&lt;/ul&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Microsoft 365 Tenant Setup for Desktop Management&lt;/li&gt;&lt;li&gt;Hybrid Identity with Entra Connect&lt;/li&gt;&lt;li&gt;Device Identity Strategies&lt;/li&gt;&lt;li&gt;Windows Autopilot Deployment&lt;/li&gt;&lt;li&gt;Windows Configuration Management&lt;/li&gt;&lt;li&gt;Application Deployment for Windows&lt;/li&gt;&lt;li&gt;Apple Business Manager Integration&lt;/li&gt;&lt;li&gt;macOS Enrollment and Management&lt;/li&gt;&lt;li&gt;Cross-Platform Compliance and Security&lt;/li&gt;&lt;li&gt;iOS/iPadOS Enrollment Strategies&lt;/li&gt;&lt;li&gt;iOS Configuration Management&lt;/li&gt;&lt;li&gt;iOS Application Management&lt;/li&gt;&lt;li&gt;iOS Security and Compliance&lt;/li&gt;&lt;li&gt;Android Enterprise Framework&lt;/li&gt;&lt;li&gt;Android Device Management&lt;/li&gt;&lt;li&gt;Android Application Management&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h4&gt;Day 1: Foundation &amp;amp; Hybrid Identity&lt;/h4&gt;&lt;h5&gt;Microsoft 365 Tenant Setup for Desktop Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Microsoft Entra ID Tenant configuration and licensing&lt;/li&gt;&lt;li&gt;Intune Service Setup and DNS-Integration&lt;/li&gt;&lt;li&gt;Integration with existing AD DS environments&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Hybrid Identity with Entra Connect&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Password Hash Sync vs. Passthrough Authentication&lt;/li&gt;&lt;li&gt;Microsoft Entra Connect Health Monitoring&lt;/li&gt;&lt;li&gt;Seamless SSO configuration for Windows and macOS&lt;/li&gt;&lt;li&gt;Troubleshooting synchronization problems&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Device Identity Strategien&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Microsoft Entra ID Registration vs. Entra ID Domain Join&lt;/li&gt;&lt;li&gt;Hybrid Entra ID Join implementation&lt;/li&gt;&lt;li&gt;Device-based Conditional Access Policies&lt;/li&gt;&lt;li&gt;Kerberos authentication in hybrid scenarios&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 2: Windows Management Basics&lt;/h4&gt;&lt;h5&gt;Windows Autopilot Deployment&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Hardware Hash Import and Device Registration&lt;/li&gt;&lt;li&gt;Self-Deploying Mode and User-Driven Deployment&lt;/li&gt;&lt;li&gt;Autopilot Reset and Reprovisioning&lt;/li&gt;&lt;li&gt;Windows Autopilot device preparation (Autopilot V2)&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Windows Configuration Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Settings Catalog for Windows 11 specific settings&lt;/li&gt;&lt;li&gt;Security Baselines Implementation&lt;/li&gt;&lt;li&gt;Windows Update for Business Integration&lt;/li&gt;&lt;li&gt;Custom Configuration Service Provider (CSP) Policies&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Application Deployment for Windows&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;MSI, Store and Win32 App Deployment&lt;/li&gt;&lt;li&gt;PowerShell Script Deployment with Intune Management Extension&lt;/li&gt;&lt;li&gt;Microsoft Store App Management&lt;/li&gt;&lt;li&gt;App Installation Monitoring and Reporting&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 3: macOS Management &amp;amp; Cross-Platform Security Features&lt;/h4&gt;&lt;h5&gt;Apple Business Manager Integration&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Apple Business Manager Account Setup&lt;/li&gt;&lt;li&gt;Apple Push Certificates Management&lt;/li&gt;&lt;li&gt;Device Enrollment Program (DEP) Konfiguration&lt;/li&gt;&lt;li&gt;Volume Purchase Program (VPP) for app licenses&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;macOS Enrollment and Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Automated Device Enrollment (ADE) for macOS&lt;/li&gt;&lt;li&gt;User Enrollment vs. Device Enrollment Strategien&lt;/li&gt;&lt;li&gt;macOS Configuration Profiles&lt;/li&gt;&lt;li&gt;Shell Script Deployment for macOS&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Cross-Platform Compliance and Security&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Unified Compliance Policies for Windows und macOS&lt;/li&gt;&lt;li&gt;Conditional access for both platforms&lt;/li&gt;&lt;li&gt;BitLocker and FileVault Management&lt;/li&gt;&lt;li&gt;Certificate-based Authentication (SCEP/PKCS)&lt;/li&gt;&lt;li&gt;Microsoft Defender for Windows and macOS&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 4: iOS Management &amp;amp; Apple Enterprise Integration&lt;/h4&gt;&lt;h5&gt;iOS/iPadOS Enrollment Strategies&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Automated Device Enrollment (ADE) Configuration&lt;/li&gt;&lt;li&gt;User Enrollment vs. Device Enrollment&lt;/li&gt;&lt;li&gt;Apple Configurator Enrollment&lt;/li&gt;&lt;li&gt;BYOD Scenarios with Apple Account Integration/Federation&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;iOS Configuration Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;iOS Configuration Profiles&lt;/li&gt;&lt;li&gt;Supervised vs. Unsupervised Device Management&lt;/li&gt;&lt;li&gt;Restrictions and Compliance Policies f&amp;uuml;r iOS&lt;/li&gt;&lt;li&gt;HomeScreen Layout and App Organization&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;iOS Application Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;App Store apps via VPP&lt;/li&gt;&lt;li&gt;Line-of-Business (LOB) apps for iOS&lt;/li&gt;&lt;li&gt;App Protection Policies (MAM) for iOS&lt;/li&gt;&lt;li&gt;Per-app VPN configuration for iOS&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;iOS Security and Compliance&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;iOS Passcode Policies and Touch/Face ID&lt;/li&gt;&lt;li&gt;iOS Device Compliance Requirements&lt;/li&gt;&lt;li&gt;Conditional Access for iOS Devices&lt;/li&gt;&lt;li&gt;iOS Data Loss Prevention (DLP)&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Day 5: Android Enterprise&lt;/h4&gt;&lt;h5&gt;Android Enterprise Framework&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Android Enterprise Enrollment Modi (Work Profile, Fully Managed, Dedicated)&lt;/li&gt;&lt;li&gt;Google Play Console Integration&lt;/li&gt;&lt;li&gt;Managed Google Play Store Setup&lt;/li&gt;&lt;li&gt;Android Zero-Touch Enrollment&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Android Device Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Android Enterprise Work Profile Management&lt;/li&gt;&lt;li&gt;Fully Managed Device Scenarios&lt;/li&gt;&lt;li&gt;Android Dedicated Device (Kiosk) Configuration&lt;/li&gt;&lt;li&gt;Samsung Knox Integration&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Android Application Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Managed Google Play Apps&lt;/li&gt;&lt;li&gt;Private Apps n the Managed Google Play Store&lt;/li&gt;&lt;li&gt;App Protection Policies (MAM) for Android&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>After completing this workshop, participants will have knowledge in the following areas:


- Setup and operation of hybrid Microsoft Entra ID environments for all platforms
- Implementation of various enrollment strategies for Windows, macOS, iOS and Android
- Automated device management with Windows Autopilot and Apple Business Manager
- Android Enterprise Deployment
- Extended compliance and conditional access strategies, cross-platform
- Mobile Application Management (MAM) for iOS and Android
- PowerShell-based automation and community tools</objective_plain><essentials_plain>Required:


- Sound Windows 10/11 Administration
- Active Directory Domain Services experience
- PowerShell basic knowledge
- Basic understanding of network and PKI
- Basic understanding of iOS and Android platforms
Recommended:


- Microsoft 365/Microsoft Entra ID experience
- Group Policy Management knowledge
- SCCM/Configuration Manager Background</essentials_plain><audience_plain>- IT professionals who want to centrally manage all device platforms with Intune
- System Engineers with a focus on Modern Device Management (Desktop &amp; Mobile)
- People migrating from traditional MDM solutions to Microsoft Intune
- IT consultants who carry out complete Intune implementations
- Mobile device managers who want to expand their desktop skills
- This workshop is aimed at experienced IT professionals who want to master the full spectrum of modern device management. Ideal for teams who need a comprehensive yet efficient introduction to all Intune platforms.</audience_plain><contents_plain>- Microsoft 365 Tenant Setup for Desktop Management
- Hybrid Identity with Entra Connect
- Device Identity Strategies
- Windows Autopilot Deployment
- Windows Configuration Management
- Application Deployment for Windows
- Apple Business Manager Integration
- macOS Enrollment and Management
- Cross-Platform Compliance and Security
- iOS/iPadOS Enrollment Strategies
- iOS Configuration Management
- iOS Application Management
- iOS Security and Compliance
- Android Enterprise Framework
- Android Device Management
- Android Application Management</contents_plain><outline_plain>Day 1: Foundation &amp; Hybrid Identity

Microsoft 365 Tenant Setup for Desktop Management


- Microsoft Entra ID Tenant configuration and licensing
- Intune Service Setup and DNS-Integration
- Integration with existing AD DS environments
Hybrid Identity with Entra Connect


- Password Hash Sync vs. Passthrough Authentication
- Microsoft Entra Connect Health Monitoring
- Seamless SSO configuration for Windows and macOS
- Troubleshooting synchronization problems
Device Identity Strategien


- Microsoft Entra ID Registration vs. Entra ID Domain Join
- Hybrid Entra ID Join implementation
- Device-based Conditional Access Policies
- Kerberos authentication in hybrid scenarios
Day 2: Windows Management Basics

Windows Autopilot Deployment


- Hardware Hash Import and Device Registration
- Self-Deploying Mode and User-Driven Deployment
- Autopilot Reset and Reprovisioning
- Windows Autopilot device preparation (Autopilot V2)
Windows Configuration Management


- Settings Catalog for Windows 11 specific settings
- Security Baselines Implementation
- Windows Update for Business Integration
- Custom Configuration Service Provider (CSP) Policies
Application Deployment for Windows


- MSI, Store and Win32 App Deployment
- PowerShell Script Deployment with Intune Management Extension
- Microsoft Store App Management
- App Installation Monitoring and Reporting
Day 3: macOS Management &amp; Cross-Platform Security Features

Apple Business Manager Integration


- Apple Business Manager Account Setup
- Apple Push Certificates Management
- Device Enrollment Program (DEP) Konfiguration
- Volume Purchase Program (VPP) for app licenses
macOS Enrollment and Management


- Automated Device Enrollment (ADE) for macOS
- User Enrollment vs. Device Enrollment Strategien
- macOS Configuration Profiles
- Shell Script Deployment for macOS
Cross-Platform Compliance and Security


- Unified Compliance Policies for Windows und macOS
- Conditional access for both platforms
- BitLocker and FileVault Management
- Certificate-based Authentication (SCEP/PKCS)
- Microsoft Defender for Windows and macOS
Day 4: iOS Management &amp; Apple Enterprise Integration

iOS/iPadOS Enrollment Strategies


- Automated Device Enrollment (ADE) Configuration
- User Enrollment vs. Device Enrollment
- Apple Configurator Enrollment
- BYOD Scenarios with Apple Account Integration/Federation
iOS Configuration Management


- iOS Configuration Profiles
- Supervised vs. Unsupervised Device Management
- Restrictions and Compliance Policies für iOS
- HomeScreen Layout and App Organization
iOS Application Management


- App Store apps via VPP
- Line-of-Business (LOB) apps for iOS
- App Protection Policies (MAM) for iOS
- Per-app VPN configuration for iOS
iOS Security and Compliance


- iOS Passcode Policies and Touch/Face ID
- iOS Device Compliance Requirements
- Conditional Access for iOS Devices
- iOS Data Loss Prevention (DLP)
Day 5: Android Enterprise

Android Enterprise Framework


- Android Enterprise Enrollment Modi (Work Profile, Fully Managed, Dedicated)
- Google Play Console Integration
- Managed Google Play Store Setup
- Android Zero-Touch Enrollment
Android Device Management


- Android Enterprise Work Profile Management
- Fully Managed Device Scenarios
- Android Dedicated Device (Kiosk) Configuration
- Samsung Knox Integration
Android Application Management


- Managed Google Play Apps
- Private Apps n the Managed Google Play Store
- App Protection Policies (MAM) for Android</outline_plain><duration unit="d" days="5">5 days</duration><pricelist><price country="DE" currency="EUR">4995.00</price><price country="AT" currency="EUR">4995.00</price><price country="SI" currency="EUR">4995.00</price><price country="CH" currency="CHF">4995.00</price></pricelist><miles/></course>