|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/microsoftintunetraining/
课程评论:没有评论
课程名称:微软 Intune 培训:2025 年最更新课程 课程概述: 微软 Intune 是一种基于云的企业移动管理(EMM)工具,帮助组织管理和保护员工使用的设备,以安全访问公司数据和应用程序,如电子邮件。它确保组织在保护企业数据的同时保持生产力。微软 Intune 可在 Azure 门户中使用,并与其他微软安全与合规解决方案无缝集成。 课程内容: 1. **微软 Intune 的能力** - 保护本地电子邮件和数据,包括 Office 365 邮件和数据。 - 确保移动设备对公司数据的安全访问。 - 管理访问公司数据的公司拥有的移动设备和 PC。 - 控制组织中使用的移动应用程序。 - 强制实施安全策略以控制公司信息的访问和共享。 - 确保设备和应用程序符合公司安全要求。 2. **微软 Intune 的关键功能** A. 设备和策略管理 - 配置文件:自动化配置设置,如 Wi-Fi、VPN、电子邮件等。 - 合规性策略:强制实施加密、PIN 码和操作系统更新等安全标准。 - 应用保护策略:保护应用程序并限制公司外部的数据共享。 - 有条件访问:根据设备合规性和安全状况限制数据访问。 - 与 SCCM 的共同管理:混合方式管理设备。 B. 安全和终端保护 - 端点安全策略:配置设备安全设置,包括防病毒和防火墙。 - 微软 Defender for Endpoint(EDR):检测、调查和响应高级威胁。 - 攻击面减小(ASR)规则:减轻攻击和限制恶意软件攻击风险。 - 本地管理员密码解决方案(LAPS)政策:安全管理本地管理员凭据。 C. 身份和认证管理 - 混合 Azure AD 加入:使设备加入本地 AD 和 Azure AD。 - GPO 迁移:将组策略对象(GPO)转换为 Intune 策略。 - 域上的 AD 连接:与 Azure AD 同步本地 AD以实现无缝身份管理。 D. 部署和应用管理 - Windows Autopilot:新设备的零接触部署。 - 混合 Autopilot:通过 Intune 将设备加入本地 AD。 - Entra Autopilot:直接加入 Azure AD(现为 Entra ID)。 - 应用程序打包和部署:部署 Win32 应用、微软应用商店应用和自定义 LOB 应用。 - 组创建和管理:通过 Entra ID 组动态组织设备和用户。 E. 远程管理和数据保护 - 远程清除与重置:在必要时安全擦除公司数据或重置设备。 - 设备库存与报告:获取关于设备健康、合规性和安全风险的见解。 - BitLocker 加密强制执行:确保设备符合加密标准。 3. **微软 Intune 如何解决企业移动挑战** - 确保安全的本地电子邮件和数据访问,以合规方式使员工能够访问公司数据。 - 确保 office 365 的安全访问,防止未授权访问。 - 公司设备管理:简化公司设备的部署、配置和生命周期管理。 - BYOD 安全:允许员工使用个人设备,同时强制实施保护公司数据的安全策略。 - 共享设备管理:支持多用户共享设备场景,如自助服务终端或前线工人设备。 - 有条件访问:确保只有受信任、合规和管理的设备才能访问公司资源。 此课程旨在为学员提供最新、全面的微软 Intune 使用指南,帮助他们更好地管理企业的移动设备和数据安全。
Microsoft Intune - Cloud-Based Enterprise Mobility ManagementMicrosoft Intune is a cloud-based Enterprise Mobility Management (EMM) tool that helps organizations manage and secure devices used by employees to access corporate data and applications, such as email. It ensures organizations remain productive while keeping corporate data protected.Microsoft Intune is available in the Azure portal and integrates seamlessly with other Microsoft security and compliance solutions.- Capabilities of Microsoft IntuneWith Intune, organizations can:Protect on-premises email and data, including Office 365 mail and data.Ensure secure access to corporate data on mobile devices.Manage corporate-owned mobile devices and PCs that access company data.Control mobile applications used within the organization.Enforce security policies to control access and sharing of corporate information.Ensure compliance with company security requirements for devices and applications.- Key Features of Microsoft IntuneA. Device and Policy ManagementConfiguration Profiles - Automate settings deployment like Wi-Fi, VPN, email, and more.Compliance Policies - Enforce security standards such as encryption, PIN codes, and OS updates.App Protection Policies - Secure applications and restrict data sharing outside managed apps.Conditional Access - Restrict data access based on device compliance and security posture.Co-Management with SCCM - Manage devices with both Intune and SCCM for a hybrid approach.B. Security and Endpoint ProtectionEndpoint Security Policies - Configure settings for device security, including antivirus and firewall.Microsoft Defender for Endpoint (EDR) - Detect, investigate, and respond to advanced threats.Attack Surface Reduction (ASR) Rules - Mitigate exploits and limit exposure to malware attacks.Local Administrator Password Solution (LAPS) Policy - Secure and manage local admin credentials.C. Identity and Authentication ManagementHybrid Azure AD Join - Enable devices to be joined to both on-premises AD and Azure AD.GPO Migration - Convert Group Policy Objects (GPOs) to Intune policies for modern management.AD Connect on Domain - Sync on-premises AD with Azure AD for seamless identity management.Intune Connector for AD - Required for Hybrid Autopilot and on-premises domain-joined deployments.D. Deployment and Application ManagementWindows Autopilot - Zero-touch deployment for new devices.Hybrid Autopilot - Joins devices to on-premises AD via Intune.Entra Autopilot - Joins devices directly to Azure AD (now Entra ID).Application Packaging and Deployment - Deploy Win32 apps, Microsoft Store apps, and custom LOB apps.Group Creation and Management - Organize devices and users dynamically with Entra ID groups.E. Remote Management and Data ProtectionRemote Wipe & Reset - Securely wipe corporate data or reset devices when necessary.Device Inventory & Reporting - Get insights into device health, compliance, and security risks.BitLocker Encryption Enforcement - Ensure that devices meet encryption standards.F. How Microsoft Intune Solves Enterprise Mobility ChallengesSecure On-Premises Email & Data - Ensures employees can securely access corporate data while maintaining compliance.Secure Office 365 Access - Controls and secures access to Microsoft 365 services, preventing unauthorized access.Corporate-Owned Device Management - Simplifies deployment, configuration, and lifecycle management of corporate devices.BYOD Security - Allows employees to use personal devices while enforcing security policies to protect corporate data.Shared Device Management - Supports multi-user shared device scenarios, such as kiosk mode or frontline worker devices.Conditional Access - Ensures only trusted, compliant, and managed devices can access corporate resources.