7.1 Intune, Co-management, Endpoint Analytics, Autopilot, and Autopatch
Key Takeaways
- Microsoft Intune is a cloud mobile device management (MDM) and mobile application management (MAM) service for Windows, macOS, iOS/iPadOS, and Android, with no required on-premises management servers
- Co-management lets a Windows device run the Configuration Manager client and be enrolled in Intune at the same time so you can move workloads such as compliance, Windows Update, and device configuration to the cloud gradually
- Endpoint Analytics scores startup performance, application reliability, and work-from-anywhere readiness so IT can find device issues before they become tickets
- Windows Autopilot is cloud provisioning that turns a new or reset OEM Windows device into a business-ready PC; user-driven mode needs the employee to sign in, while self-deploying mode is for kiosks and shared devices with little or no user interaction
- Windows Autopatch is a Microsoft-managed cloud service that automates quality and feature updates for Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams on eligible licensed devices
Quick Answer: Microsoft Intune is the cloud mobile device management (MDM) and mobile application management (MAM) service for Windows, macOS, iOS/iPadOS, and Android. Co-management keeps Configuration Manager and Intune on the same Windows PC so you can move workloads to the cloud gradually. Endpoint Analytics scores startup, app reliability, and work-from-anywhere health. Windows Autopilot provisions new or reset Windows devices from the cloud. Windows Autopatch is Microsoft-managed update delivery for Windows, Microsoft 365 Apps, Microsoft Edge, and Microsoft Teams.
The April 30, 2025 MS-900 outline asks you to describe the endpoint management capabilities of Microsoft 365 including Microsoft Intune, co-management with Configuration Manager, Endpoint Analytics, Windows Autopilot, and Windows Autopatch. This is a recommend-the-service skill. You will not be asked to author a compliance JSON, size a distribution point, or click through the Microsoft Intune admin center. You will be asked which capability enrolls and configures phones, which one protects Outlook on a personal tablet without enrollment, which one keeps an on-premises Configuration Manager investment while adding cloud policies, which one explains why laptops boot slowly, which one turns a factory Windows PC into a business-ready device, and which one lets Microsoft run the update rings for Windows and Microsoft 365 Apps.
Microsoft Intune: cloud MDM and MAM
Microsoft Intune is a cloud-based endpoint management service. Official Learn language is the scoring key: use Intune to enroll, configure, secure, and update devices, deploy and protect apps, and control which users and devices can access organization resources. The service runs in the Microsoft cloud. You do not stand up an on-premises Intune server. Admins work in the Microsoft Intune admin center. Identity is Microsoft Entra ID: users sign in with Entra credentials, you assign policies to Entra groups, and Intune sends device compliance state to Entra so Conditional Access can require a healthy device before Exchange Online or SharePoint opens.
MS-900 cares about two management modes that you can use separately or together.
Mobile device management (MDM) enrolls the whole device. Corporate Windows PCs, company iPhones, and supervised Android devices typically take this path. After enrollment, Intune can push configuration profiles, require encryption and a PIN, deploy apps, and — if the laptop is lost — wipe the device. Enrollment can be user-driven through the Company Portal, or automatic through Windows Autopilot, Apple Automated Device Enrollment, or Android Enterprise.
Mobile application management (MAM) manages only the work apps and the corporate data inside them. The rest of the phone stays personal. This is the BYOD answer. Official Learn is explicit: you can use app protection policies independent of any MDM solution. A policy can require a PIN or biometric to open Outlook in the work account, block copy/paste from a work message into a personal app, and stop saving corporate files to personal storage. When the employee leaves, a selective wipe removes organization data from the managed apps and leaves photos, personal mail, and personal apps alone. You can also run MAM on an MDM-enrolled corporate phone when you want a second layer around especially sensitive apps.
The exam phrase that points to MAM without enrollment is almost always protect corporate data on a personal device without managing the whole device. The phrase that points to MDM is enroll the device, set device compliance, or wipe the hardware.
Compliance policies are the rules a managed device must meet to be considered compliant — for example a minimum OS version, encryption on, or not jailbroken. Compliance is not the same as a configuration profile. A configuration profile sets the PIN or BitLocker requirement. A compliance policy evaluates whether the device currently meets the bar and reports that state to Entra. Conditional Access can then allow or block access based on that signal. Do not say “compliance installs the VPN.” Compliance scores the device; configuration and apps change it.
Supported platforms you should name on this exam are Windows, macOS, iOS/iPadOS, and Android. Intune also documents Linux and some specialty Apple platforms; those are real products, but MS-900 scenarios almost always use the four mainstream families.
Configuration Manager and co-management
Microsoft Configuration Manager (ConfigMgr), also called Microsoft Endpoint Configuration Manager (MECM) and formerly System Center Configuration Manager (SCCM), is the long-standing on-premises client-management product. Organizations use it for imaging, software distribution from distribution points, software updates, and inventory of Windows PCs that may rarely leave the corporate network. Configuration Manager is not Intune, and it is not retired just because Intune exists.
Co-management is how you attach that existing Configuration Manager investment to the Microsoft 365 cloud. Official definition: a Windows device has the Configuration Manager client and is enrolled in Intune, and you control which workloads — if any — switch authority from Configuration Manager to Intune. You do not have to switch anything on day one. Configuration Manager keeps every workload you leave on it, plus every ConfigMgr feature that co-management does not cover.
Two official paths reach co-management:
- Existing Configuration Manager clients. The PCs already have the ConfigMgr client. You connect them to Microsoft Entra ID (typically Microsoft Entra hybrid join) and enroll them in Intune.
- New internet-based devices. New Windows PCs join Microsoft Entra ID, enroll automatically in Intune, and then receive the Configuration Manager client so they become co-managed.
Workloads you can move individually, in a Pilot Intune collection first, or all at once, are:
| Workload | What switches to Intune when you move it |
|---|---|
| Compliance policies | The rules Conditional Access uses to decide whether the device is healthy |
| Windows Update policies | Windows Update client policies for quality and feature updates |
| Resource access policies | Historically VPN, Wi-Fi, email, and certificates (this older ConfigMgr surface is deprecated; device configuration now covers the modern path) |
| Endpoint Protection | Defender antivirus, firewall, BitLocker, and related protection settings |
| Device configuration | Settings and profiles; moving this also covers resource access and Endpoint Protection |
| Office Click-to-Run apps | Microsoft 365 Apps deployment and update authority |
| Client apps | Intune app and script delivery; ConfigMgr apps can remain in Software Center |
Microsoft’s own FAQ is the exam hint: compliance is the workload most customers switch first, because it unlocks Conditional Access with Intune compliance while Configuration Manager can still evaluate settings. After that, Office Click-to-Run, client apps, and Windows Update policies are common next moves.
Two identity traps sit next to this topic. Co-management is a management option. Microsoft Entra hybrid join is an identity option. A hybrid-joined PC is not automatically co-managed. A co-managed PC is not automatically hybrid-joined. And coexistence is the different word Microsoft uses when Configuration Manager shares a device with a third-party MDM. Coexistence is not co-management; the two authorities are not orchestrated the same way.
Endpoint Analytics
Endpoint Analytics is the reporting surface that tells you whether managed Windows devices are actually usable. Official Learn: it provides data-driven insights into device performance, startup times, app reliability, and battery health so IT can find and fix issues that hurt productivity. You view it in the Intune admin center. Devices can be Intune-managed, co-managed, or Configuration Manager-managed through tenant attach.
Scores run from 0 to 100. Lower is worse. The overall Endpoint analytics score is a weighted average of three official subscores:
| Score | What it measures |
|---|---|
| Startup performance | How quickly users go from power-on to a usable desktop (boot time plus sign-in time) |
| Application reliability | How often desktop apps crash versus how long people use them |
| Work from anywhere | Whether devices are ready for secure, productive remote work |
Endpoint Analytics also contributes device-level insight to the technology experiences category of Microsoft Adoption Score. The exam signal is “users complain that laptops take too long to become usable after they press the power button” or “which report shows which apps keep crashing.” The answer is Endpoint Analytics, not Autopilot and not Autopatch. Autopilot provisions. Autopatch updates. Analytics measures.
Microsoft also sells Intune Advanced Analytics as a deeper add-on (anomalies, richer device timelines). You do not need unpublished add-on SKUs for MS-900. You need the core idea: scores, baselines, and a prioritized insights list that points at slow boots and unreliable apps.
Windows Autopilot: cloud provisioning, not a slogan
Windows Autopilot is a collection of cloud technologies that set up and pre-configure Windows devices so they are ready for work. It uses the OEM-optimized Windows that already shipped on the PC. You do not have to maintain a custom image and a driver pack for every hardware model. Autopilot transforms the existing Windows installation into a business-ready state: apply settings and policies, install apps, join Microsoft Entra ID (or Microsoft Entra hybrid join), auto-enroll in Intune, and even change the edition (for example Windows Pro to Windows Enterprise) when the license allows.
That is why “Autopilot replaces imaging” is only half-true. Autopilot replaces the typical new-PC or reset-PC imaging ritual for cloud-managed Windows. It is not a Configuration Manager task-sequence clone, and it does not invent a new operating system in the cloud. The device still boots the Windows that came on the disk. Policies and apps then make it your PC.
Two deployment modes are the ones MS-900 expects you to contrast.
User-driven mode is the standard employee laptop story. The OEM or reseller ships the PC to the person who will use it. That person connects to a network, sees a customized out-of-box experience (OOBE), and signs in with work credentials. The Autopilot profile is associated with that user. The device can be Microsoft Entra joined or Microsoft Entra hybrid joined. After sign-in, Intune finishes apps, certificates, and compliance. IT does not have to touch the box.
Self-deploying mode is for a device that is not “this is Maria’s laptop.” Official Learn: little or no user interaction; designed for a kiosk, shared-use, or digital signage device. On Ethernet, no user interaction is required. On Wi-Fi, someone may only pick language and connect to the network. The profile is not associated with the enrolling user, so user-targeted compliance does not apply — only device-targeted compliance. Self-deploying supports Microsoft Entra join only, not hybrid join, and it requires a device with a usable TPM 2.0 (a typical virtual machine fails this check).
Related official capabilities you can name without turning this into MD-102: pre-provisioned deployment (a technician or partner completes the heavy setup before the user gets the device, then the user still does a short user-driven sign-in) and Windows Autopilot Reset (wipe a PC back to a business-ready state for the next person). Reset and self-deploying are how Autopilot covers repurpose and recover, not only brand-new hardware.
Windows Autopatch
Windows Autopatch is a cloud service that automates updates for Windows, Microsoft 365 Apps for enterprise, Microsoft Edge, and Microsoft Teams. Microsoft sequences releases through deployment rings, watches reliability signals, and aims to keep registered devices current with less admin planning. That is the opposite of “IT builds every ring by hand and hopes Patch Tuesday is quiet.” It is also not Autopilot. Autopilot provisions a device once (or after a reset). Autopatch keeps it updated after it is in the fleet.
Official prerequisites (Microsoft Learn, Windows Autopatch) list these licenses:
- Microsoft 365 Business Premium
- Windows 10/11 Education A3 or A5 (included in Microsoft 365 A3 or A5)
- Windows 10/11 Enterprise E3 or E5 (included in Microsoft 365 F3, E3, or E5)
- Windows 10/11 Enterprise E3 or E5 VDA
In April 2025 Microsoft removed a separate feature-activation step and made Autopatch features available to Business Premium and A3+ as well as the Enterprise/F3 family. Support requests to the Autopatch service engineering team remain an E3+ and F3 entitlement. Do not invent other SKUs.
Devices must already be enrolled in Intune, or co-managed with at least the Windows Update and Device configuration workloads set to Pilot Intune or Intune. They must be corporate-owned (Windows BYOD is blocked at registration), have talked to Intune in the last 28 days, and be able to reach Microsoft update endpoints. Configuration Manager-only devices are not enough.
Once registered, Autopatch can manage update rings, Autopatch groups, Windows quality and feature updates, driver and firmware updates, Microsoft 365 Apps on the Monthly Enterprise Channel, Edge on the Stable channel, and Teams automatic updates. Hotpatch (security updates without a reboot) exists as a related Autopatch capability; MS-900 only needs you to know Autopatch is the Microsoft-managed update service, not to configure a hotpatch calendar.
| Capability | Job on the exam |
|---|---|
| Intune | Cloud MDM/MAM for Windows, macOS, iOS, Android; compliance; app protection |
| Co-management | ConfigMgr + Intune on one Windows PC; move workloads gradually |
| Endpoint Analytics | Startup, reliability, and work-from-anywhere scores |
| Windows Autopilot | New or reset Windows device → business-ready from the cloud |
| Windows Autopatch | Microsoft-managed updates for Windows, Microsoft 365 Apps, Edge, Teams |
Realistic exam-style scenarios
BYOD mail. Marketing uses personal iPhones. Legal will not allow full device enrollment. App protection policies wrap Outlook and Teams, require a work PIN, and block saving to personal storage. That is MAM without MDM, not Autopilot.
Lost corporate laptop. The device is Intune-enrolled. Wipe or retire from Intune. Compliance told Conditional Access the device was healthy yesterday; the wipe is an MDM action, not Endpoint Analytics.
Keep ConfigMgr, add Conditional Access. Ten thousand existing ConfigMgr clients need “compliant device” before they open Exchange Online. Enable co-management and switch the compliance workload (often first, often in a pilot collection). Do not rip out Configuration Manager on day one.
Slow boot tickets. Help desk sees a spike in “it takes forever to get a desktop.” Open Endpoint Analytics startup performance. Do not buy Autopatch to measure boot time.
Ship-to-home onboarding. A new hire in another city needs a laptop next Monday. Register the hardware hash, assign a user-driven Autopilot profile, ship the OEM device. The hire signs in; Intune finishes the rest. That is not a technician imaging every SKU in a warehouse.
Lobby kiosk. A device in the reception area should enroll with no employee account. Self-deploying Autopilot on Entra join, TPM 2.0, device-based compliance. User-driven is the wrong mode because there is no “the user who owns this PC.”
Stop running Patch Tuesday by hand. Eligible Enterprise or Business Premium Windows devices should get Windows, Microsoft 365 Apps, Edge, and Teams updates in rings with Microsoft watching quality. That is Windows Autopatch, not Autopilot and not “Intune exists, so updates are automatic with no service.”
Exam traps
- MAM is not MDM. App protection can secure Outlook on a phone that Intune never enrolled. Compliance policies and full wipe need device management.
- Co-management is not hybrid join. One is who manages the PC. The other is how the PC identifies to Entra ID.
- Co-management is not “ConfigMgr is gone.” You can leave every workload on Configuration Manager and still be co-managed.
- Autopilot is not Autopatch. Autopilot provisions. Autopatch updates.
- Autopilot is not a custom WIM for every model. It starts from OEM Windows and applies cloud policy. Self-deploying is not the default for a named employee laptop.
- Endpoint Analytics does not deploy Windows. It scores the experience after the device is managed.
- Do not invent Autopatch licenses. Use the official Business Premium, Education A3/A5, Enterprise E3/E5 (including F3/E3/E5 bundles), and Enterprise VDA list.
Official sources
- What is Microsoft Intune? — cloud MDM/MAM, platforms, Entra Conditional Access
- App protection policies overview — MAM with or without enrollment; selective wipe
- Co-management for Windows devices — both clients, two paths, workloads
- Co-management workloads — compliance, updates, apps, configuration
- Endpoint analytics overview — startup, reliability, work-from-anywhere scores
- Overview of Windows Autopilot — OEM Windows to business-ready; reset and recover
- Windows Autopilot user-driven mode and self-deploying mode — named user versus kiosk/shared
- What is Windows Autopatch? and Prerequisites — products updated and eligible licenses
- Study guide for Exam MS-900 — endpoint management skill
A company wants to protect corporate email and files inside Outlook and Teams on employee-owned phones without enrolling those phones in mobile device management. Which Intune capability matches that requirement?
What does co-management with Configuration Manager mean for a Windows device?
Help desk reports that many managed Windows laptops take a long time to become usable after power-on and that a line-of-business desktop app crashes often. Which Microsoft 365 capability is designed to score those problems?
Which statement correctly describes Windows Autopatch?