Microsoft Intune Device Deployment + Compliance Case Study

I built this lab to practise the device side of Level 1 IT support using Microsoft Intune and a Windows 11 virtual machine.

I enrolled the Windows device into my Yarra River Services test tenant, confirmed Intune management, synced the endpoint, assigned a compliance policy and verified the final compliance result.

I also created an asset register and a device deployment and handover checklist so the exercise covered both technical administration and support documentation.

Support Scenario

Request

Prepare a Windows 11 device for Liam Carter and bring the endpoint under Microsoft Intune management.

The device should appear in the organisation inventory, receive an assigned compliance policy, successfully sync and return a verified compliance result.

The endpoint also needs to be documented in the asset register and device handover process.

Windows Device Enrollment

1

Connect the work account

I used a Windows 11 virtual machine as the endpoint for this lab.

Inside Windows I connected Liam Carter’s Microsoft 365 work account through Access work or school.

Windows then showed that the device was managed by Yarra River Services.

Windows 11 device managed by Yarra River Services
Windows 11 showing organisational management and successful device sync.

Result

The endpoint had an active management relationship with my Microsoft Intune test tenant.

The device management page also confirmed a successful sync.

2

Confirm the device in Intune

I opened Microsoft Intune Admin Center and checked the device inventory.

The Windows endpoint appeared under All devices.

Intune showed the endpoint as managed by Intune with Liam Carter as the primary user.

Windows device visible in Microsoft Intune
Windows endpoint successfully enrolled and visible in Microsoft Intune.
3

Review the device record

I opened the individual endpoint record to review information available to the support technician.

The record showed Liam Carter as the primary user, Windows as the operating system and Intune as the management platform.

Microsoft Intune Windows device details
Endpoint record showing user assignment, device information and Intune management status.

Support takeaway

The Intune device record gives support staff useful endpoint information before they even contact the user.

This can help with ownership checks, operating system information, compliance investigation and endpoint troubleshooting.

Compliance Policy

4

Create the compliance policy

I created a Windows compliance policy called VIC Lab Windows Compliance.

For this controlled exercise I configured a minimum Windows operating system version of 10.0.22000.0.

The policy was assigned only to my VIC Lab Windows test group.

I deliberately kept the test scope limited instead of applying the configuration across the tenant.

Microsoft Intune Windows compliance policy assignment
Windows compliance policy assigned to the dedicated lab group.
5

Sync and verify compliance

After creating the policy I synced the Windows endpoint so it could receive the latest management configuration.

I then checked the policy results in Microsoft Intune.

Microsoft Intune compliance policy showing compliant Windows device
Policy specific result confirming that the enrolled Windows endpoint passed the assigned compliance requirement.

Result

One Windows endpoint was evaluated.

One endpoint returned Compliant.

Zero endpoints returned Noncompliant.

This confirmed that the endpoint was enrolled, communicating with Intune and successfully evaluated by the assigned policy.

Asset Register

6

Document the endpoint

Endpoint management also requires accurate asset records.

I created a Yarra River Services asset register containing fictional support assets together with the Windows lab endpoint.

The register records asset ID, device type, assigned user, location, status, warranty information and support notes.

Yarra River Services IT asset register
Asset register used to track device assignment, location, status and support information.

Why this matters

A support team needs to know what equipment exists, who has it, where it is located and its current operational state.

The technical device record and asset record should support each other.

Device Deployment and Handover

7

Complete the handover checklist

I created a device deployment and handover checklist to document the checks completed before releasing an endpoint to a user.

Device preparation checks

Confirm asset ID and assigned user

Check Windows edition and version

Review Windows updates

Check Device Manager

Confirm required applications

Confirm Microsoft 365 access

Review encryption status

Confirm Intune enrollment

Sync the endpoint

Verify compliance

Record handover and known issues

Windows device deployment and handover checklist
Device preparation checklist documenting the checks completed during the lab handover process.

Device Management Workflow

Prepare user and test scope

Liam Carter was included in the controlled device management scope.

Connect the endpoint

The Microsoft 365 work account was connected to the Windows 11 virtual machine.

Confirm enrollment

The endpoint appeared in Microsoft Intune device inventory.

Assign compliance requirements

The Windows compliance policy was assigned to the dedicated lab group.

Sync and verify

The endpoint successfully synced and returned a compliant policy result.

Document the device

The asset register and deployment checklist were updated to complete the device lifecycle record.

What I Learned

This lab helped me understand the difference between simply opening Microsoft Intune and actually using it to manage an endpoint.

Microsoft Entra ID handles identity and access while Microsoft Intune provides endpoint management, inventory, policy and compliance information.

I also learned that enrollment alone is not enough.

A support technician needs to confirm the endpoint record, check user assignment, sync the device, review policy results and document the work completed.

The asset register and handover checklist also helped connect the technical configuration with normal service desk documentation.

Skills Demonstrated

Microsoft Intune

Windows 11

Device Enrollment

Endpoint Management

Device Inventory

Compliance Policy

Device Sync

Compliance Verification

Asset Management

Device Deployment

Device Handover

Microsoft Entra ID

Support Summary

I enrolled a Windows 11 test endpoint into Microsoft Intune using a fictional Microsoft 365 user.

I confirmed the endpoint appeared in inventory, reviewed its management information, created and assigned a Windows compliance policy, synced the endpoint and verified a compliant result.

I then documented the endpoint in an asset register and completed a device deployment and handover checklist.

The final result was a complete basic endpoint management workflow rather than only viewing the Intune portal.

Lab Disclosure

This case study was completed in my controlled Microsoft Intune test environment.

Yarra River Services and Liam Carter are fictional lab identities.

The Windows endpoint is a virtual machine used only for training.

The screenshots show configuration and verification completed in my own test environment.

Sensitive device identifiers and recovery information are not included in the public portfolio.