0:00–0:20
Review
0:20–0:35
VM tidy
0:35–1:40
Assessment
1:40–2:00
Debrief
0:00 – 0:20Review · 20 min

Week 6 consolidation — the complete endpoint governance stack

Connect five days of endpoint work into one governance picture before the assessment opens.

Instructor note — pre-seed the assessment scenario: Before class, on WIN-CLIENT-02: (1) disable Windows Defender Real-time protection, (2) turn off Windows Firewall, (3) if possible, check that BitLocker is not active (it may never have been on a VM — note this). These create a multi-setting non-compliance state that students must find and fix individually. Do not tell students which settings are broken — finding them via the Intune Device compliance tab is Section A of the assessment.
0:20 – 0:35VM tidy · 15 min

Final self-audit before the assessment window opens

Assessment boundary: At 0:35 no further tenant or VM changes are permitted unless directed by the assessment sheet. The instructor's pre-seeded non-compliance state on WIN-CLIENT-02 is now live.
0:35 – 1:40Assessment · 65 min

Week 6 assessment — the Lakeview Logistics non-compliant device incident

WIN-CLIENT-02 has been reported non-compliant in Intune. The user assigned to it cannot access M365. Students investigate, remediate, verify, and explain.

SectionWhat is assessedMarks
Section A — InvestigationNavigate to WIN-CLIENT-02's compliance detail in Intune, identify all non-compliant settings, record their current state, and explain how each one violates the LL — Windows Baseline Compliance policy.25 pts
Section B — RemediationFix all non-compliant settings on WIN-CLIENT-02, force a sync, verify the compliance state returns to Compliant in Intune, and verify M365 access is restored for the assigned user.25 pts
Section C — CA chain explanationWritten: explain the complete chain from the moment a setting became non-compliant to the moment M365 access was blocked, and from remediation to access restoration — including every component (Intune, Entra ID cached state, CA policy evaluation, token issuance).25 pts
Section D — Governance recommendationGiven the incident, design and implement one Intune control that would either prevent the non-compliance from occurring, detect it faster, or automatically remediate it. Implement the change in the tenant and document it.25 pts
Instructor note: Section A requires Intune → Devices → WIN-CLIENT-02 → Device compliance tab. The specific failing settings depend on what was pre-seeded — students must find them without being told. Section C is the most intellectually demanding section — distinguishing the Intune compliance evaluation, the Entra ID cached state, and the CA sign-in evaluation is where strong students separate from weaker ones. Section D has three defensible answers: a shorter check-in interval, a non-compliance notification to the manager, or a remediation script. Marks are for quality of reasoning and implementation, not for choosing a specific option.
1:40 – 2:00Debrief · 20 min

Assessment debrief & Week 7 preview

Assessment rubric — marking guidance

CriterionFull marksPartialNo marks
Section AAll pre-seeded non-compliant settings found via correct path, each setting's policy violation explained accuratelySome settings found, others missed, or correct path not documentedNon-compliant settings not found
Section BAll settings remediated, sync forced, Compliant state confirmed in Intune, M365 access verified with evidenceSettings fixed but verification incomplete or M365 access not testedSettings not remediated
Section CFull chain documented accurately: Intune evaluation, cached state, CA evaluation, token, block, remediation path — timing and asynchrony addressedChain partially correct — missing the asynchronous evaluation or the token/cached state mechanismChain not described or fundamentally incorrect
Section DRoot cause identified, appropriate control chosen and implemented in tenant, clear reasoning for why it addresses the gapGap identified, control chosen but not implemented or reasoning weakGap not identified

Learning outcomes — by end of Week 6, students can…

Build hybrid identityInstall Entra ID Connect and hybrid-join Windows machines from scratch
Enforce device complianceCreate and assign compliance policies and observe non-compliant states
Deploy configuration profilesUse Settings Catalog, Update rings, and Security Baselines to configure enrolled devices
Package and deploy appsUse IntuneWinAppUtil and deploy Win32 and Store apps to Windows devices
Manage Linux endpointsEnrol Ubuntu 22.04 via the Intune agent and apply Linux compliance policies
Explain the CA chainTrace the full path from device non-compliance to M365 access block and back
Week 7 →Week 6 Overview