About this Course
This 5-day course provides administrators with the knowledge and skills needed to deploy and manage Windows 10 desktops, devices, and applications in an enterprise environment. Students learn how to plan and implement Windows 10 deployments in large organizations. Students also learn how to manage the Windows 10 installations after deployment to provide secure identity and data access using technologies related to Group Policy, Remote Access, and Device Registration. To support a variety of device and data management solutions, Microsoft Azure Active Directory, Microsoft Intune, and Microsoft Azure Rights Management are introduced. These services are part of the Enterprise Mobility Suite which provide identity and access management, cloud-based device, application, and update management, and secure data access to information stored both in the cloud and on any location within your corporate network.
Audience Profile
This course is intended for IT Professionals who are interested in specializing in Windows 10 desktop and application deployments and managing the cloud-based application and data service environments for medium-to-large enterprise organizations. These professionals typically work with networks that are configured as Windows Server domain-based environments with managed access to the Internet and cloud services.
This course is also intended to provide skills for individuals who seek to pass the 70-697 Windows 10 Configuring exam.
This course is related to the course:
- 20697A-1: Installing and Configuring Windows 10
At Course Completion
After completing this course, students will be able to:
- Describe the challenges and solutions for desktop and device management in an enterprise environment.
- Deploy Windows 10 Enterprise desktops.
- Manage user profiles and user state virtualization.
- Manage Windows 10 sign-in and identity.
- Manage desktop and application settings by using Group Policy.
- Manage data access for Windows-based devices.
- Manage remote access solutions.
- Configure and manage client Hyper-V.
- Manage Windows 10 devices by using enterprise mobility solutions.
- Manage desktop and mobile clients by using Microsoft Intune.
- Manage updates and endpoint protection by using Microsoft Intune.
- Manage application and resource access by using Microsoft Intune.
Prerequisites
Before attending this course, students should have:
- At least two years of experience in the IT field.
- Attended Course 20697-1: Installing and Configuring Windows 10, or have equivalent knowledge.
- Basic awareness of Windows deployment tools.
Course Outline
Module 1: Managing Desktops and Devices in an Enterprise Environment
This module explains the most current trends and information related to desktop and device management in the enterprise. It also provides an overview on how to extend device management to the cloud.
Lessons
- Managing Windows 10 in the Enterprise
- Managing a Mobile Workforce
- Supporting Devices in the Enterprise
- Extending IT Management and Services to the Cloud
Lab : Planning for Windows 10 and Device Management in the Enterprise
- Reading the Scenario
- Answering the Questions
After completing this module, students will be able to:
- Manage Windows 10 in the enterprise.
- Manage a mobile workforce.
- Support devices in the enterprise.
- Extend IT management and services to the cloud.
Module 2: Deploying Windows 10 Enterprise Desktops
This module explains the various deployment scenarios of Windows 10 and the considerations to keep in mind while performing these deployments. This module also explains how to deploy Windows 10 by using the Windows Assessment and Deployment Kit (WADK) and the Microsoft Deployment Toolkit (MDT). This module also explains how to maintain Windows 10 by using DISM and Windows Imaging and Configuration Designer (ICD).
Lessons
- Overview of Windows 10 Enterprise Deployment
- Customizing Enterprise Desktop Deployments
- Deploying Windows 10 by Using the Microsoft Deployment Toolkit
- Maintaining a Windows 10 Installation
- Managing Volume License Activation for Windows 10
Lab : Building a Reference Image by Using WADK Tools
- Configuring Custom Windows PE Boot Media
- Modifying a Custom Answer File by Using Windows SIM
- Installing a Reference Computer by Using an Answer File
- Preparing a Reference Computer by Using Sysprep
- Capturing a Reference Computer
Lab : Using MDT to Deploy Windows 10 Desktops
- Creating and Configuring the MDT Deployment Share
- Creating a Task Sequence
- Deploying a Windows 10 Image by Using MDT
Lab : Maintaining a Windows 10 Installation using Windows ICD
- Creating and Configuring a Windows ICD Provisioning Package
After completing this module, students will be able to:
- Describe the deployment options for Windows 10 desktops.
- Customize enterprise desktop deployments.
- Deploy Windows 10 by using the Microsoft Deployment Toolkit.
- Maintain a Windows 10 installation.
- Manage volume license activation for Windows 10.
Module 3: Managing User Profiles and User State Virtualization
This module explains user states and user state virtualization and explains how to deploy and maintain user experience virtualization (UE-V). This module also explains how to use tools such as ScanState and LoadState to migrate user states.
Lessons
- Managing User Profile and User State
- Implementing User State Virtualization by Using Group Policy
- Configuring User Experience Virtualization
- Managing User State Migration
Lab : Configuring User Profiles and User State Virtualization
- Configuring Roaming User Profiles and Folder Redirection
- Implementing and Configuring UE-V
Lab : Migrating User State by Using USMT
- Creating and Customizing USMT XML Files
- Capturing and Restoring User State to a Target Computer
After completing this module, students will be able to:
- Manage user profile and user state.
- Implement user state virtualization by using Group Policy.
- Configure UE-V.
- Manage user state migration.
Module 4: Managing Windows 10 Sign-In and Identity
This module explains the concept of identity and the methods to enhance identity security. This module also explains cloud identities and the use of Azure Active Directory Premium in enterprise organizations.
Lessons
- Overview of Enterprise Identity
- Planning for Cloud Identity Integration
Lab : Integrating a Microsoft Account with a Domain Account
- Signing up for a Trial Microsoft Account
- Connecting a Microsoft Account to a Domain Account
Lab : Joining Windows 10 to Azure Active Directory
- Signing Up for an Azure Active Directory Trial Subscription
- Joining Windows 10 to Azure Active Directory
After completing this module, students will be able to:
- Describe the concept of enterprise identity.
- Plan for cloud identity integration.
Module 5: Managing Desktop and Application Settings by Using Group Policy
This module explains how to manage Group Policy inheritance, administrative templates, and common enterprise desktop settings. This module also explains how to apply policies using targeting and filtering.
Lessons
- Managing Group Policy Objects
- Configuring Enterprise Desktops Using Group Policy
- Overview of Group Policy Preferences
Lab : Configuring Group Policy Objects and Settings
- Managing Windows 10 by Using Group Policy
Lab : Using Group Policy Preferences to Manage Desktop Settings
- Configuring Group Policy Preferences to Apply Drive and Printer Mapping
After completing this module, students will be able to:
- Manage Group Policy objects.
- Configure enterprise desktops by using Group Policy.
- Describe Group Policy preferences.
Module 6: Managing Data Access for Windows-based Devices
This module explains how to implement Device Registrations and Work Folders. This module also explains how to configure and share data stored in Microsoft OneDrive.
Lessons
- Overview of Data Access Solutions
- Implementing Device Registration
- Implementing Work Folders
- Managing Online Data Using Cloud-Based Storage Solutions
Lab : Configuring Data Access for Non-Domain Joined Devices
- Implementing Device Registration
- Configuring Work Folders
Lab : Managing Data Access Using OneDrive
After completing this module, students will be able to:
- Describe the solutions for accessing data.
- Implement Device Registration.
- Implement Work Folders.
- Manage online data by using cloud-based storage solutions.
Module 7: Managing Remote Access Solutions
This module explains how to configure a virtual private network (VPN) and DirectAccess in Windows 10. This module also explains how to publish applications in Microsoft Azure RemoteApp.
Lessons
- Overview of Remote Access Solutions
- Configuring VPN Access to Remote Networks
- Using DirectAccess with Windows 10
- Supporting RemoteApp
Lab : Implementing DirectAccess
- Configuring the DirectAccess Server
- Configuring the DirectAccess Clients
- Validating Remote Connectivity
Lab : Configuring Azure RemoteApp
- Creating a RemoteApp Collection
- Publishing an Application Using Azure RemoteApp
- Validating Remote Connectivity
After completing this module, students will be able to:
- Describe the types of remote access solutions.
- Configuring VPN access to remote networks.
- Use DirectAccess with Windows 10.
- Support RemoteApp.
Module 8: Configuring and Managing Client Hyper-V
This module explains how to create virtual switches, virtual hard disks, and virtual machines.
Lessons
- Installing and Configuring Client Hyper-V
- Configuring Virtual Switches
- Creating and Managing Virtual Hard Disks
- Creating and Managing Virtual Machines
Lab : Configuring Virtual Machines by Using Client Hyper-V
- Installing Client Hyper-V
- Creating a virtual machine
After completing this module, students will be able to:
- Install and configure client Hyper-V.
- Configure virtual switches.
- Create and manage virtual hard disks.
- Create and manage virtual machines.
Module 9: Managing Windows 10 Devices Using Enterprise Mobility Solutions
This module explains the use of the Enterprise Mobility Suite and its components, Azure Active Directory Premium, Azure Rights Management, and Microsoft Intune.
Lessons
- Overview of the Enterprise Mobility Suite
- Overview of Azure Active Directory Premium
- Overview of Azure Rights Management
- Overview of Microsoft Intune
Lab : Implementing a Microsoft Intune Subscription
- Signing Up for a Microsoft Intune Trial Subscription
- Adding Microsoft Intune Users
After completing this module, students will be able to:
- Describe the use and components of the Enterprise Mobility Suite.
- Manage directory services by using Azure Active Directory Premium.
- Protect devices by using Azure Rights Management.
- Explore the options in Microsoft Intune.
Module 10: Managing Desktop and Mobile Clients Using Microsoft Intune
This module explains how to configure and assign configuration policies. This module also explains how to create Mobile Device Management (MDM) policies and enroll mobile devices to Intune.
Lessons
- Deploying the Intune Client Software
- Overview of Microsoft Intune Policies
- Mobile Device Management Using Intune
Lab : Installing the Intune Client Software and Configuring Policies
- Installing the Intune Client Software
- Creating Intune Policies
Lab : Managing Mobile Devices Using Microsoft Intune
- Configuring and Enrolling Mobile Devices into Microsoft Intune
After completing this module, students will be able to:
- Deploying the Intune client software.
- Configure Intune policies.
- Manage mobile devices using Intune.
Module 11: Managing Updates and Endpoint Protection Using Microsoft Intune
This module explains how to configure updates and Endpoint Protection settings and reports.
Lessons
- Managing Updates Using Microsoft Intune
- Managing Endpoint Protection
Lab : Managing Updates and Endpoint Protection Using Microsoft Intune
- Configuring Updates in Microsoft Intune
- Configuring Endpoint Protection in Microsoft Intune
After completing this module, students will be able to:
- Manage updates by using Intune.
- Manage Endpoint Protection.
Module 12: Application and Resource Access Using Microsoft Intune
This module explains how to use the Microsoft Intune Software Publisher and deploy applications to managed clients. This module also explains the use of certificate profiles, Wi-Fi profiles, and VPN profiles to control access to company resources.
Lessons
- Overview of Application Management Using Intune
- The Application Deployment Process
- Controlling Access to Company Resources
Lab : Deploying Applications by Using Microsoft Intune
- Uploading an Application to Microsoft Intune
- Deploying an Application to Managed Clients
Lab : Managing Resource Access by Using Microsoft Intune
- Configuring Profile Deployment
- Configuring Conditional Access Policies
After completing this module, students will be able to:
- Describe application management by using Intune.
- Describe the application deployment process.
- Control access to company resources.