M20398: Planning for and Managing Devices in the Enterprise - Enterprise Mobility Suite (EMS) & On-Premises Tools

5 Day Course
Hands On
Official Microsoft Curriculum
Code M20398

This course has been retired. Please view currently available Microsoft Windows 2016 Training Courses.


Hide all

Using devices in the enterprise environment (6 topics)

  • Overview of devices in an enterprise
  • Device management features
  • Overview of the Enterprise Mobility Suite
  • Lab: Planning for device management
  • Selecting the appropriate products and technologies for device management
  • Working with mobile devices

Implementing and administering Azure AD (8 topics)

  • Overview of AD DS
  • Overview of Azure AD
  • Creating and managing Azure AD
  • Managing authentication in Azure AD
  • Lab: Working with Azure AD and providing access to claims-aware applications
  • Managing Azure AD users and groups
  • Joining a Windows 10 device to Azure AD
  • Accessing cloud applications with SSO

Connecting AD DS with Azure AD (7 topics)

  • Preparing AD DS for directory synchronization
  • Implementing Azure AD Connect
  • Planning and implementing federation
  • Lab: Synchronizing on-premises AD DS with Azure AD
  • Implementing Azure AD Connect
  • Verifying synchronization of new objects
  • Implementing and using Azure AD Premium features

Managing devices in Office 365 (4 topics)

  • Overview of Office 365
  • MDM for Office 365
  • Lab: Managing devices in Office 365
  • Configuring and testing mobile device management in Office 365

Planning and implementing Microsoft Intune (8 topics)

  • Planning for Intune
  • Deploying Intune clients
  • Basic Intune administration
  • Lab: Planning and implementing Intune
  • Deploying Intune clients and linking computers to users
  • Create Intune users
  • Delegating Intune permissions
  • Creating Intune groups

Managing devices by using Intune (9 topics)

  • Working with Microsoft Intune policies
  • Mobile device management
  • Managing updates and Windows Defender
  • Lab: Using Microsoft Intune policies to manage devices
  • Configuring Azure AD with automatic mobile device management enrollment
  • Working with Microsoft Intune policies
  • Lab: Managing updates and Windows Defender
  • Managing updates by using Intune
  • Managing Windows Defender by using Intune

Using Microsoft Intune to manage applications and resource access (8 topics)

  • Application lifecycle management
  • Application deployment process
  • Managing access to company resources
  • Lab: Using Intune to deploy and monitor applications
  • Using Intune to deploy and monitor applications
  • Lab: Using Intune to manage resource access
  • Configuring certificate deployment in Intune
  • Configuring conditional access policies

Planning and implementing Azure RMS (5 topics)

  • Overview of Azure RMS.
  • Implementing Azure RMS.
  • Lab: Using Azure RMS to protect documents and data
  • Protecting documents with Azure RMS
  • Using FCI with Azure RMS

Planning and implementing app support (6 topics)

  • Planning and implementing application compatibility options
  • Publishing and using RemoteApp programs
  • Publishing and using Azure RemoteApp
  • Lab: Publishing and using RemoteApp and Azure RemoteApp
  • Publishing and accessing RemoteApp programs
  • Publishing and accessing Azure RemoteApp programs

Planning and implementing remote access (12 topics)

  • Overview of remote access solutions
  • Implementing remote infrastructure access
  • Planning and implementing Work Folders
  • Implementing cloud data access
  • Planning and implementing mobility options
  • Lab: Configuring and using VPN and Work Folders
  • Configuring a VPN server and a VPN client
  • Configuring and using Work Folders
  • Lab: Using Offline Files and OneDrive
  • Configuring and using Offline Files
  • Synchronize settings between Windows 10 devices
  • Configuring and using OneDrive

Planning and implementing Dynamic Access Control and auditing (8 topics)

  • Planning and implementing Dynamic Access Control
  • Accessing resources with Dynamic Access Control
  • Planning and deploying advanced audit policies
  • Lab: Implementing secure data access
  • Preparing for Dynamic Access Control deployment
  • Implementing Dynamic Access Control
  • Validating and remediating Dynamic Access Control
  • Using advanced audit policies

Planning and protecting data (6 topics)

  • Planning and implementing encryption
  • Planning and implementing BitLocker
  • Protecting data on devices
  • Lab: Protecting data by using encryption and BitLocker
  • Encrypting and recovering access to encrypted files
  • Using BitLocker to protect data

Recovering data and operating systems (8 topics)

  • Planning and implementing file recovery
  • Planning and implementing device recovery
  • Planning and implementing updates
  • Lab: Implementing file recovery and device recovery
  • Using File History to recover files
  • Using Previous Versions to recover files
  • Recovering a device with a restore point
  • Using the advanced startup options to recover a device


  • TCP/IP networking fundamentals
  • Understanding of Domain Name System (DNS)
  • Working knowledge of Active Directory principles
  • Understanding of the public key infrastructure (PKI) fundamentals
  • Understanding of cloud-based service concepts
  • Windows Server 2012 R2 fundamentals, including Remote Desktop Services
  • Experience with Windows 10
  • Familiarity with Windows PowerShell
  • Basic knowledge of mobile platforms

Relevant Certifications

  • Microsoft Certified Solutions Expert (MCSE): Mobility certification

Course PDF