Microsoft Entra ID
Microsoft Entra ID (formerly Azure AD) is Microsoft's identity and directory service. Intune stores no identities itself - it relies on Entra for authentication, users/groups, and Conditional Access.
Entra security groups are the foundation for assigning policies, profiles, and apps.
Path in the Intune admin center
📍 entra.microsoft.comHands-on tasks
- Understand and place IntuneApprentice training Intune · Module 02
- Understand how a policy reaches a deviceApprentice training Intune · Module 04
- Find tenant facts and key portal areasApprentice training Intune · Module 05
- Check the Intune license of a test userApprentice training Intune · Module 06
- Create a dynamic device group AZ-[initials]-WindowsApprentice training Intune · Module 07
- Review group membership and assignment targetApprentice training Intune · Module 07
- Create a user-driven Autopilot profile and assign it to the apprentice groupApprentice training Intune · Module 08
- Validate the Autopilot profile assignment and deployment readinessApprentice training Intune · Module 08
- Plan an MFA rule in report-only modeApprentice training Intune · Module 14
- Read Conditional Access results in sign-in logsApprentice training Intune · Module 14
- Collect tenant core data from the admin centerMicrosoft Intune - Hands-on Course · Module 01
- Provision a test user with an Intune licenseMicrosoft Intune - Hands-on Course · Module 02
- Assign Intune licenses via groups (group-based licensing)Microsoft Intune - Hands-on Course · Module 02
- Create the six personas and the scenario groupsMicrosoft Intune - Hands-on Course · Set up the course scenario
- Dynamic Autopilot group (group tag) and user groupMicrosoft Intune - Hands-on Course · Module 03
- Validate dynamic group membershipMicrosoft Intune - Hands-on Course · Module 03
- Create a user group - and understand device vs. user assignmentMicrosoft Intune - Hands-on Course · Module 06
- Review group and assignment modelMicrosoft Intune - Hands-on Course · Module 06
- Read dsregcmd and distinguish join pathsMicrosoft Intune - Hands-on Course · Module 08
- Control local admin rights on Entra-joined devicesMicrosoft Intune - Hands-on Course · Module 08
- Classify Entra join issues with dsregcmdMicrosoft Intune - Hands-on Course · Module 08
- Create and understand your first CA policyMicrosoft Intune - Hands-on Course · Conditional Access
- Block legacy authentication - the most important baseline policyMicrosoft Intune - Hands-on Course · Conditional Access
- Practical case – why does configuration not reach the pilot device?Microsoft Intune - Hands-on Course · Module 22
- Secure enrollment operations and device identityMicrosoft Intune - Hands-on Course · Enrollment operations and device identity
- Triage enrollment failures systematicallyMicrosoft Intune - Hands-on Course · Enrollment operations and device identity
- Prepare domain, admin accounts and test usersTenant onboarding (guided) · Module 02
- Configure MDM user scope and enrollment pilot groupTenant onboarding (guided) · Module 03
- Enroll the first Windows test device and prove managementTenant onboarding (guided) · Module 03
Jump straight to the matching course task (sign-in required).
On Microsoft Learn