70-398: Planning for and Managing Devices in the Enterprise Exam Guide
Exam 70-398, Planning for and Managing Devices in the Enterprise, was designed to validate enterprise device-management skills across identity, access, protection, applications, and data. Microsoft identified IT professionals as the intended audience and listed device administration, Windows networking, Active Directory, and Microsoft Intune as relevant background. This guide helps you make the key preparation decision: whether your existing Windows and enterprise mobility experience is strong enough to study from the objectives, or whether you need structured lab work before considering an exam appointment.
What 70-398 was designed to validate
70-398 was built around planning and managing enterprise devices rather than isolated desktop configuration. The official objective document describes skills involving cloud and hybrid identities, device-management identity infrastructure, device access and protection, data protection, mobile-device security, application delivery, and enterprise application management.
Microsoft’s title for the exam was “Planning for and Managing Devices in the Enterprise.” The objective-domain document was published on December 7, 2015, so its technology context is important when interpreting the syllabus. The listed technologies included Windows 10, Microsoft Intune, Microsoft Azure Active Directory, and Enterprise Mobility Suite.
This is therefore a legacy-oriented exam guide, not a claim that the objectives describe every current Microsoft device-management feature. Use the official objective document as the controlling reference for what 70-398 covered, then use Microsoft’s current credentials catalogue to check whether the exam can still be scheduled before investing in an appointment or materials.
The practical audience
Microsoft identified IT professionals as the intended audience. The document also listed device administration, maintenance, and troubleshooting experience as expected technical background, alongside Windows networking, Active Directory, and Microsoft Intune knowledge.
That profile points to candidates who already understand how enterprise devices are identified, connected, configured, protected, and supported. A candidate who has only read product descriptions should not treat recognition of feature names as readiness. The exam’s planning emphasis calls for decisions about policy, identity, access, application delivery, and protection in an enterprise setting.
How to interpret the measured skills
Start with the objective domains, not with a random list of products. The official blueprint assigns 15–20% to designing for cloud or hybrid identity, 15–20% to device access and protection, and 15–20% to data access and protection. Each area deserves deliberate study because the published ranges are substantial and overlap with the central device-management scenario.
Designing for cloud or hybrid identity includes planning and designing cloud and hybrid identities and supporting identity infrastructure for device management. Your study should connect identity decisions to device enrollment, access, and administration rather than treating directory services as a separate theory topic.
Device access and protection covers the controls that determine whether devices and users can reach organizational resources safely. Build a decision matrix for access conditions, device security, mobile-device management, and administrative responsibilities. The objective document specifically includes managing and securing mobile devices.
Data access and protection includes planning Data Loss Prevention policies. Study DLP as a policy-design problem: identify the information being protected, the users and devices handling it, the action that should be controlled, and the operational effect of the policy. Avoid memorizing terminology without being able to explain why a policy belongs in a particular design.
Application delivery and management
The objectives include designing a platform for delivering applications to devices through Hyper-V virtualization and managing applications through the Company Portal or Windows Store. Prepare by comparing delivery approaches according to the user, device, application, and security requirement rather than assuming that one method fits every enterprise.
For each application scenario you study, ask five questions: where does the application run, how is it assigned, what identity is required, what data can it access, and how is it removed or updated? This sequence turns product knowledge into a repeatable design method.
Do not turn the percentages into a false ranking
The official document presents 15–20% ranges for designing for cloud or hybrid identity, device access and protection, and data access and protection. Those are labeled domain weights, not a guarantee of an exact question allocation. Do not compare bare percentages or infer that an area outside the quoted ranges can be ignored.
A practical recommendation is to give every published domain an initial pass, then spend extra time where your diagnostic work shows weak reasoning. A candidate who knows identity vocabulary but cannot select a workable protection design still has a meaningful gap in the identity domain.
Check your starting point before choosing a study plan
Use a short diagnostic to decide whether you need foundation work or objective-driven revision. The right plan depends less on your job title than on whether you can explain enterprise device-management choices using identity, networking, security, application, and data concepts.
Create four columns labeled identity, device protection, data protection, and application delivery. Under each, write what you can configure, what you can troubleshoot, and what you can design. Mark every statement that you can only define but cannot apply to a scenario. Those marks identify the first topics for hands-on practice.
You should be able to explain the relationship among Windows networking, Active Directory, Microsoft Intune, Azure Active Directory, and the device-management outcome. You do not need to pretend that a historical product list is a current architecture. You do need to understand the role each listed technology played in the exam’s documented context.
If your experience is mostly endpoint support, begin with identity and policy dependencies before studying advanced design choices. If your experience is mostly directory administration, begin with device enrollment, access controls, mobile management, DLP, and application delivery. If you have worked across both areas, use the domains as a revision checklist and focus on gaps revealed by scenario analysis.
A useful readiness test
For each objective topic, answer three questions without looking at notes: what business problem does the control solve, what prerequisite must exist, and what unintended consequence should an administrator monitor? This test is more useful than asking whether a term looks familiar.
Examples of weak readiness include confusing authentication with authorization, treating DLP as a substitute for device security, choosing an application-delivery method without considering virtualization, or describing mobile-device management without explaining how access is protected. These mistakes indicate that your study should include design reasoning, not only definitions.
Build a study sequence that follows dependencies
Study identity and infrastructure first, then device access and protection, followed by data protection and application delivery. This order reflects how device-management decisions depend on who the user and device are, what access is allowed, how information is protected, and how software reaches the endpoint.
The sequence is a practical recommendation, not an additional Microsoft requirement. It prevents a common error: studying individual Intune or Windows features before understanding the identity and network conditions that make those features usable in an enterprise design.
Stage one: map identities and infrastructure
Begin by drawing a simple hybrid identity model. Identify on-premises directory services, cloud identity, users, devices, administrators, and the resources being accessed. Then annotate which identity is evaluated at each access point and which administrative system applies device policy.
Review Windows networking and Active Directory concepts that affect device administration. Connect those concepts to Intune and Azure Active Directory in the documented technology context. Your notes should explain dependencies and boundaries, not merely list components.
Practice with scenarios involving a device that is connected to the network but cannot obtain the expected policy, a user who authenticates but lacks resource authorization, and an administrator who needs to separate device-management duties from broader directory privileges.
Stage two: design access and protection
Next, create a device-protection checklist covering enrollment or management state, user access, device security, mobile-device controls, and administrative response. For every control, record its purpose, the condition it evaluates, and the action taken when the condition is not met.
Use contrast exercises. Compare a managed device with an unmanaged device, a compliant device with a noncompliant device, and a corporate mobile device with a personally owned device. The goal is not to invent undocumented policy behavior; it is to make your assumptions explicit and test them against the official objectives and product documentation available to you.
Stage three: protect organizational data
Study DLP policy planning after you understand access controls. Define the data category, the users or devices involved, the permitted and restricted actions, and the response to a violation. Consider how a policy affects legitimate work, administration, and troubleshooting.
Write one-page design summaries instead of collecting isolated commands. Each summary should state the requirement, the proposed policy, the identity and device prerequisites, the likely exception, and the evidence you would inspect if the policy did not behave as expected.
Stage four: deliver and manage applications
Finish with the application objectives. Compare Hyper-V virtualization with application management through the Company Portal or Windows Store according to delivery, isolation, user experience, data access, and lifecycle needs.
A strong revision exercise is to take one application and produce two designs: one using a virtualized delivery approach and one using managed application distribution. Explain why each design is appropriate, what identity and device controls it depends on, and how an administrator would handle updates or removal.
Use labs to test decisions, not to chase screenshots
Hands-on work is most valuable when it tests a design decision from the objectives. Build small, repeatable exercises around identity, device policy, mobile security, DLP planning, and application delivery. Record the starting condition, the change made, the expected result, and the evidence that confirms or disproves it.
The official document identifies Windows 10, Microsoft Intune, Microsoft Azure Active Directory, and Enterprise Mobility Suite in the technology list. Because that list belongs to a document published in 2015, current lab availability and interface behavior may differ. Treat a modern lab as a way to understand durable concepts, not as proof that an old interface or workflow will appear in an exam.
Do not spend all your time making a lab look perfect. A smaller environment that lets you investigate identity, policy assignment, access failure, and application-management outcomes is more useful than a large environment you only observe. When a feature is unavailable, document the intended design and the dependency rather than filling the gap with an unsupported assumption.
A four-part lab journal
For identity exercises, record the identity source, device relationship, administrator role, and access result. For protection exercises, record the device condition, policy condition, enforcement action, and recovery path.
For DLP exercises, record the protected data, triggering activity, policy response, and expected exception process. For application exercises, record the delivery mechanism, assignment method, user experience, and removal or update plan.
After each exercise, write a short failure analysis. State whether the problem came from identity, connectivity, policy scope, permissions, application delivery, or data-protection logic. This habit develops the diagnostic thinking implied by the exam title and background requirements.
Avoid the preparation mistakes that create false confidence
The most damaging mistake is studying answer patterns instead of learning the documented skills. Memorized material cannot replace the ability to reason about identity dependencies, policy scope, protection trade-offs, or application delivery. Use practice questions only to expose gaps, and never rely on dumps, leaked questions, or claims that memorization guarantees a pass.
A second mistake is treating every product name as a separate topic. The exam’s objectives connect technologies to enterprise outcomes. A feature is worth studying when you can explain the problem it solves, the prerequisite it needs, and the effect it has on users, devices, applications, or data.
A third mistake is ignoring the age of the objective document. The official document was published on December 7, 2015. Do not silently replace its scope with a current product exam, and do not assume that a current feature is covered merely because it resembles an older feature. Check the objective wording and current Microsoft credential information before committing to a study purchase or appointment.
A fourth mistake is scheduling before checking availability. Microsoft’s current retirement guidance says that a retired exam cannot be taken and its associated certification or credential cannot be newly earned after the retirement date. The guidance also says that credentials already earned remain on the Microsoft Learn transcript. Confirm the current status through Microsoft’s official credentials pages rather than relying on an old marketplace listing.
Separate official facts from useful advice
Official facts include the title, intended audience, documented background, technology list, objective domains, historical language notation, and provider identified in the objective document. Recommendations in this guide—such as the study order, lab journal, and diagnostic method—are practical preparation choices, not Microsoft requirements.
This distinction matters particularly for delivery details. The historical objective document identified VUE, while Microsoft’s current registration guidance explains that provider options appear on the certification detail page and that candidates taking a certification independently or through training generally select Pearson VUE when that option is offered. The current scheduling page should control any appointment decision.
Verify status and delivery before you schedule
Check the current Microsoft credentials catalogue and the official exam or certification detail page immediately before scheduling. The supplied objective document is historical, and the available sources do not establish a current 70-398 retirement date or confirm that a live appointment is available today.
Microsoft’s registration instructions say to begin from the certification overview or browse the certifications catalogue, open the certification detail page, scroll to “Schedule exam,” and select the exam-provider button. When you click the schedule button, you may be prompted to sign in to or create a Learn Profile. Use the official page rather than a third-party listing as the final availability check.
The current registration guidance states that certification exams can be scheduled no more than 90 days in advance. It also states that, through Pearson VUE, a candidate can have a maximum of two Microsoft Certification exams scheduled at a time, either on the same day or on separate days. These are current scheduling rules for the supported Microsoft process, not evidence that 70-398 itself remains open for booking.
Where an online option is shown, Microsoft’s guidance says candidates must ensure that the computer and exam area meet security standards and should run the system pre-check before registering. A test center may be preferable if you want a pre-configured environment. If an online option is not shown, Microsoft notes that it is not available from the exam provider.
Accommodations and identity details
If you need exam accommodations, request them before scheduling so the provider has time to review the request and confirm that the environment can support it. Microsoft also instructs candidates to ensure that the legal name on the Learn Profile matches the legal identification required by the provider.
These are administrative steps, but they belong in the study plan. Resolve profile, identification, accommodation, and delivery questions before your preferred appointment window rather than discovering a mismatch after booking.
What retirement would mean
Microsoft’s retirement guidance says candidates preparing for an exam scheduled for retirement should take it before the retirement date because the exam cannot be taken afterward. It also says an already earned credential remains on the learner’s Microsoft Learn transcript. The supplied evidence does not provide a retirement date for 70-398, so verify rather than infer its status.
Do not assume that a legacy exam automatically converts into a newer role-based certification. Microsoft’s transition-exam material describes special, explicitly announced, time-limited exams created for particular moves between certification models. The Microsoft Q&A material likewise explains that automatic conversion is not the general rule and that an expired certification cannot be renewed. Check the specific official announcement if you are considering a replacement credential.
A practical final-week roadmap
In the final study period, stop expanding your notes and start testing your ability to make and defend decisions. Revisit the official domains, complete targeted troubleshooting scenarios, and verify the administrative details that could affect scheduling.
Use the first study block to redraw the identity and device-management model from memory. Include cloud or hybrid identity, device-management infrastructure, users, devices, administrators, and protected resources. Then explain what changes when a device is unmanaged, a user lacks authorization, or a policy is assigned to the wrong scope.
Use the next block for protection and data. Work through mobile-device security and DLP policy scenarios. For each answer, state the requirement, the control, the dependency, and the operational consequence. If you cannot explain why an alternative is unsuitable, return to the relevant objective instead of guessing from wording.
Use another block for applications. Compare Hyper-V virtualization with Company Portal or Windows Store management, then explain how identity, access, protection, and lifecycle requirements influence the choice. Keep the exercise tied to the documented objectives and technology context.
Finish with a closed-book review of weak areas. Recheck historical details against the official objective-domain document, but do not use those details to infer current scheduling status. Confirm availability, provider options, delivery mode, profile information, accommodation needs, and the appointment window through Microsoft’s current registration process.
A sensible stopping rule is to stop adding new resources when you can consistently explain a scenario in terms of identity, device state, policy scope, data risk, application delivery, and troubleshooting evidence. At that point, further progress is more likely to come from correcting a specific gap than from collecting another generic practice set.
Your last checklist
Confirm that you can describe the purpose of each documented domain: designing for cloud or hybrid identity, device access and protection, and data access and protection. Confirm that you have reviewed application delivery through Hyper-V virtualization and application management through the Company Portal or Windows Store.
Confirm that your notes cover Windows networking, Active Directory, Microsoft Intune, Azure Active Directory, Windows 10, and Enterprise Mobility Suite in their documented context. Confirm that you have practiced both design and troubleshooting explanations.
Finally, check the live Microsoft credentials and registration pages. The official sources supplied for this guide do not establish a current 70-398 exam date, price, question count, duration, or active delivery language beyond the historical ENU notation, so those details should not be guessed or copied from an unverified listing.
Choose the next credential deliberately
70-398 may still be useful as a historical skills reference for enterprise device administration, but a candidate seeking a current Microsoft credential should compare it with the certifications currently listed in Microsoft’s credentials catalogue. Do not assume that a related modern credential is a conversion, replacement, or shorter path unless Microsoft explicitly documents that relationship.
If your immediate goal is to understand the legacy exam, finish the objective-led roadmap and verify whether an official scheduling path exists. If your goal is a current role-based credential, use the current catalogue and its own study requirements as the decision source. In either case, keep the distinction clear: passing or studying 70-398 does not, on the supplied evidence, automatically establish a newer certification.
Your next action is therefore simple: open the official objective-domain document, mark your confidence in each skill area, and then check Microsoft’s current credentials and registration pages. Schedule only after the exam’s status, provider, delivery option, profile requirements, and available appointment window have been confirmed.
Conclusion
Prepare 70-398 as an objective-driven enterprise device-management exam, not as a vocabulary exercise. Build from identity and infrastructure into device protection, data protection, and application delivery; use labs to investigate dependencies and failures; and keep historical objectives separate from current Microsoft scheduling information. Before making any appointment or replacement-certification decision, verify the live status and requirements through Microsoft’s official credentials and registration pages.