Reference
The key Microsoft Intune terms explained in plain language - 34 entries, each with the Intune path and a link to the matching Microsoft Learn article.
Foundation
Identity & Entra
Enrollment & Autopilot
- Android EnterpriseGoogle's management framework for Android - separates work and personal.
- Autopilot device preparationNewer, more robust Autopilot approach without hardware-hash import.
- Device enrollmentThe process of bringing a device under Intune management.
- Enrollment Status Page (ESP)Shows provisioning progress at first boot and can block the device until done.
- Hardware hashThe unique device fingerprint Autopilot uses to recognize a device.
- Windows AutopilotProvision new Windows devices ready-to-use without imaging.
Configuration & Policies
- Administrative templates (ADMX)Group-Policy-like settings in Intune, including custom ADMX files.
- Assignment filterRefines an assignment by device properties (OS, model, ownership).
- Configuration profileA bundle of settings you assign to device or user groups.
- Settings catalogEvery available setting, searchable and individually selectable - the cloud-native GPO equivalent.
Compliance & Security
- Attack Surface ReductionDefender rules that block common malware behaviors.
- BitLockerWindows drive encryption, managed via the Intune disk-encryption policy.
- Compliance policyRules that define when a device counts as "compliant".
- Conditional AccessIf-then rules that allow or block access based on signals.
- Microsoft Defender for EndpointEndpoint security platform that integrates with Intune for risk scoring.
- Security baselineMicrosoft-preconfigured, recommended security settings as a template.
- Windows LAPSManages and rotates the local administrator password, backed up to Entra ID.
App Deployment
- App configuration policySupplies apps with preconfigured settings before the user runs them.
- App protection policy (MAM)Protects company data inside apps - even on unmanaged personal devices.
- Company PortalThe app where users enroll devices and install assigned apps.
- Win32 appClassic Windows desktop apps, deployed as an .intunewin package.
Operations & Diagnostics
- Co-managementManaging a Windows device with Configuration Manager and Intune at once.
- Intune Management Extension (IME)The Windows agent that runs Win32 apps and PowerShell scripts.
- PowerShell scriptsCustom scripts Intune runs on devices via the Management Extension.
- RemediationsScript packages that automatically detect and fix support issues.
- Role-based access controlControls which actions an admin may perform in Intune, via roles.
- Scope tagsTags that control which objects an admin can see (distributed IT).
- Windows update ringsPhased control of when Windows updates roll out to device groups.