70-398 Exam Guide: Planning for and Managing Devices in the Enterprise
Microsoft exam 70-398, “Planning for and Managing Devices in the Enterprise,” was designed to validate IT professionals’ ability to plan device management across cloud and hybrid identity, device protection, data protection, applications, and mobile devices. Its objective document is dated December 7, 2015, so the most important decision today is whether you are pursuing a currently available exam or using 70-398 as a historical skills reference. This guide helps you check that status, interpret the objectives, and choose a sensible preparation path without relying on leaked questions.
Is 70-398 still the right exam to schedule?
Check Microsoft’s current certification and exam listings before committing study time. The 70-398 objective document is historical, having been published on December 7, 2015, while Microsoft’s current credentials program is organized around credentials and role-based certifications that may not match an older 70-xxx exam.
The supplied official material does not provide a current retirement date or a current booking page specifically for 70-398. Therefore, this guide does not present the exam as currently schedulable. Use Microsoft Learn’s credential browser and the official retirement information to determine whether the exam is listed, retired, or retained only for reference.
This status check is not a formality. If Microsoft has retired an exam, its current policy says that the exam cannot be taken and the associated certification or credential cannot be newly earned after the retirement date. Credentials already earned before retirement remain on the learner’s Microsoft Learn transcript.
Do not assume that an older exam automatically converts into a newer role-based certification. Microsoft’s transition material describes explicitly announced, limited-time transition exams for particular legacy exams. The general replacement pattern is not an automatic conversion. If your objective is a current credential, identify the current certification independently and read its own requirements.
A practical status-check sequence
Start at Microsoft Learn’s Browse Credentials page and search for the exam number and title. If you find a current detail page, confirm that it includes a schedule option and that its objectives still match your intended outcome.
Next, review Microsoft’s retirement page for the exam or its associated certification. Retirement information can change, so treat the official page as the authority rather than an old training listing, forum post, or third-party catalog entry.
If 70-398 is unavailable, compare its subject areas with current credentials in Microsoft Learn’s catalog. Use the old objectives to identify transferable knowledge, not as evidence that a replacement certification has identical content.
What does 70-398 validate?
The exam title points to an enterprise device-management planning role, and Microsoft’s objective document describes skills spanning identity, device access, data protection, mobile-device security, and application delivery. The exam was intended for IT professionals who could connect policy choices with the operational needs of managed Windows devices.
The document specifically states that 70-398 validates planning and designing cloud and hybrid identities and supporting identity infrastructure for device management. That emphasis makes identity a foundation for the rest of the study plan: device enrollment, access decisions, protection controls, and application delivery should be studied as related design problems rather than isolated product features.
The objectives also include planning Data Loss Prevention policies and managing and securing mobile devices. This means preparation should include both governance decisions and administration tasks. A candidate should be able to explain why a control belongs in a design, what it protects, and how it affects users or administrators.
Application delivery is another stated area. Microsoft included designing a platform for delivering applications to devices through Hyper-V virtualization and managing applications through the Company Portal or Windows Store. Study should therefore cover delivery choices, distribution control, and the relationship between application access and device management.
The technology context in the official document
Microsoft’s technology list for 70-398 included Windows 10, Microsoft Intune, Microsoft Azure Active Directory, and Enterprise Mobility Suite. These names establish the historical context of the objectives and should be read alongside the document’s publication date rather than treated as a current product roadmap.
The practical implication is that terminology may be dated even when the underlying design themes remain useful. Identity integration, policy enforcement, mobile-device management, application distribution, and data protection are durable study themes. Product names, portal experiences, and current feature availability must be checked against current Microsoft documentation before you use them in a present-day project or certification plan.
How are the objective domains weighted?
The official objective document assigns 15–20% to designing for cloud or hybrid identity, 15–20% to device access and protection, and 15–20% to data access and protection. Treat each named domain as a substantial study block; the published ranges do not justify ignoring any one of them.
Because the supplied facts do not reproduce a complete objective list or all domain labels, avoid creating a more detailed percentage table from memory. Build your notes around the three documented domains and add the related application, mobile-device, DLP, and virtualization topics as implementation threads that connect the domains.
A percentage is useful only when it remains attached to its official domain. Do not compare bare percentages or turn the ranges into a claim about the exact number of questions. The source provides domain weighting, not a guaranteed question distribution.
Designing for cloud or hybrid identity — 15–20%
For designing for cloud or hybrid identity — 15–20% — focus on the identity infrastructure that allows enterprise devices to be recognized, managed, and granted appropriate access. Review how identity architecture affects enrollment, user access, administrative separation, and the boundary between on-premises directory services and cloud services.
A useful study exercise is to draw two designs: one for an organization whose device-management dependencies remain on premises and another that uses cloud identity services. For each design, record the identity source, the device-management dependency, the access decision, and the failure or troubleshooting point you would investigate first.
The expected background includes Active Directory, Windows networking, and Microsoft Intune knowledge. If you cannot explain the role of each in a hybrid device-management scenario, pause advanced design study and repair that foundation before memorizing terminology.
Device access and protection — 15–20%
For device access and protection — 15–20% — study how an organization decides which devices may connect, what conditions must be satisfied, and which controls reduce the risk of an unmanaged or compromised endpoint. Connect access rules to administration, maintenance, and troubleshooting rather than studying them as purely theoretical security settings.
Create a decision matrix for managed, partially managed, and noncompliant devices. For each category, write the permitted access, required remediation, responsible administrator, and likely user impact. This exercise helps you reason through scenario-based questions without depending on recalled wording from an unauthorized source.
Microsoft identified device administration, maintenance, and troubleshooting experience as expected technical background. Use that guidance to prioritize practical diagnosis: determine whether a problem originates in identity, enrollment, policy application, connectivity, compliance, or application delivery.
Data access and protection — 15–20%
For data access and protection — 15–20% — concentrate on how policies protect information while allowing legitimate work. The official objectives specifically include planning Data Loss Prevention policies, so your notes should connect data classification and access decisions with the device and application context in which data is used.
Work through policy-design questions using business outcomes rather than product labels. Identify the sensitive data, the users and devices that require access, the action that should be blocked or monitored, and the exception process. Then consider how a mobile device or locally installed application changes the risk.
A common mistake is to treat DLP as a stand-alone policy exercise. In this exam’s device-management context, data protection interacts with identity, device posture, application delivery, and mobile security. Your revision notes should show those dependencies explicitly.
What background should you have before studying?
Begin with the prerequisites Microsoft actually identified: device administration, maintenance, and troubleshooting experience, plus knowledge of Windows networking, Active Directory, and Microsoft Intune. These are expected background areas, not a formal prerequisite claim in the supplied material.
Candidates who already support Windows endpoints can usually start with the objective domains and use labs to expose gaps. Candidates coming from a purely conceptual security background should first learn the administrative lifecycle of a device: identity, enrollment, configuration, application deployment, compliance, maintenance, and retirement.
Do not measure readiness by how many product terms you recognize. A stronger test is whether you can explain a complete management decision and troubleshoot the consequences when the user, device, network, identity, or policy does not behave as expected.
Foundation checklist
Review Windows networking concepts that affect device reachability and service access. Include name resolution, authentication dependencies, connectivity boundaries, and the evidence you would collect when a managed device cannot receive policy or application content.
Refresh Active Directory concepts that support identity and administration. Pay attention to the relationship between directory objects, users, groups, permissions, and hybrid identity design. The goal is not to reproduce an old interface; it is to understand how directory decisions affect device access.
Revisit Microsoft Intune administration as described in the historical objective context. Practice organizing devices, users, policies, applications, and compliance decisions so that each configuration has a clear purpose and an observable result.
Use troubleshooting as a learning method. When a lab fails, write down the symptom, the suspected layer, the test performed, the result, and the corrective action. This produces more useful revision material than copying configuration steps without understanding them.
How should you study the objectives?
Use a domain-first plan: map every objective statement you can verify to a knowledge note, a hands-on task, and a scenario explanation. The purpose is to move from recognition to design judgment. Because the official document is old, validate product-specific details against current Microsoft documentation and keep historical facts clearly separated from current platform behavior.
A practical study cycle has four passes. First, read the objective document and mark familiar, uncertain, and unknown topics. Second, study the foundations behind the unknown topics. Third, build or simulate designs and troubleshoot them. Fourth, explain each design aloud or in writing without looking at your notes.
Do not begin with memorization material that claims to reproduce the exam. Such material cannot establish current availability or legitimate preparation value, and memorizing purported answers does not demonstrate the skills described by Microsoft.
Turn each objective into evidence of competence
For an identity objective, produce an architecture diagram and explain the trust, access, and management flow. For a device-protection objective, create a compliance and remediation decision. For a data-protection objective, write a DLP policy rationale and identify an exception. For an application objective, describe how an approved application reaches an eligible device.
For mobile-device security, list the device condition, user identity, data exposure, and administrative response. For Hyper-V-based application delivery, document why virtualization is appropriate, what the device needs, and how the organization controls delivery. These exercises are study artifacts, not claims about the live exam interface.
After each exercise, ask three questions: What assumption did I make? What would fail first? What evidence would prove the policy worked? Those questions develop the analysis needed for planning and troubleshooting scenarios.
Build a compact revision system
Keep one page for each named domain and separate pages for cross-domain topics. On every page, include definitions, dependencies, a design pattern, a failure mode, and a short explanation of the trade-off. This structure makes last-stage revision active instead of a passive reread.
Use a distinction log for concepts you confuse. Examples include identity versus device compliance, application availability versus application authorization, and data protection versus device protection. Write the difference in your own words and attach a scenario to it.
Update the log when current Microsoft documentation uses different terminology from the historical 70-398 document. Do not silently rewrite the old objective into a modern product claim. Record both the historical exam context and the current technology interpretation.
What does a practical study roadmap look like?
A flexible roadmap should match your starting point and the exam’s verified status. First establish whether there is a legitimate booking path. Then spend the opening study period on identity and device-management foundations, the middle period on domain-linked designs and labs, and the final period on timed reasoning and weak-area repair. Do not set a test date until the official listing supports it.
The roadmap below is a sequence of decisions rather than a promise about how long preparation will take. Adjust the pace according to work experience, lab access, and the number of objectives you can explain without notes.
Stage 1: Confirm the target and baseline
Check Microsoft Learn for 70-398 and read the retirement guidance. Save the official objective document and record its publication date, intended audience, technology list, named background knowledge, and domain weights.
Complete a baseline without looking up answers. Explain hybrid identity, device access, DLP, mobile-device security, application delivery, and troubleshooting. Label each topic strong, usable, or weak. Your weak list becomes the first study queue.
If the exam is not available, stop short of booking and decide whether your goal is historical knowledge, employer-specific device-management competence, or a current Microsoft credential. Each goal requires a different source and study plan.
Stage 2: Repair the foundations
Study Windows networking, Active Directory, Intune, device administration, maintenance, and troubleshooting in that order if those areas are unfamiliar. Use a small lab or documented design exercise to connect users, devices, policies, applications, and access outcomes.
At the end of this stage, write a complete device lifecycle from identity and enrollment through configuration, application delivery, compliance, data protection, maintenance, and troubleshooting. Any unexplained transition is a gap to investigate before moving on.
Stage 3: Study the domains through scenarios
Work through the three named domains as design cases. Begin with identity, then device access and protection, then data access and protection. Add mobile security, DLP, Company Portal or Windows Store application management, and Hyper-V application delivery where they cross those domains.
For every case, state the business requirement, proposed control, dependency, user effect, administrative task, and validation evidence. Compare alternatives only after you can explain the baseline design. This prevents product-name memorization from replacing reasoning.
Stage 4: Test recall and troubleshoot gaps
Close your notes and reconstruct the main designs from memory. Explain why a particular identity or protection decision is necessary, what it depends on, and how you would diagnose a failure. Use practice questions only as prompts for reasoning, not as substitutes for official objectives or leaked content.
Return to your distinction log and baseline list. Spend the remaining preparation time on errors that affect multiple domains, such as misunderstanding identity dependencies or confusing device compliance with data-protection policy.
Stage 5: Make the scheduling decision
Schedule only after the official Microsoft page confirms that 70-398 is available and provides a valid provider path. If the exam is listed, follow the current registration instructions rather than relying on the historical provider information in the objective document.
If the official listing is unavailable, select a current Microsoft credential based on your role and verify its own skills outline. Treat 70-398 study as transferable background, not as proof that the newer credential has the same objectives or delivery process.
What delivery details are actually evidenced?
The historical 70-398 objective document identified VUE as the exam provider and specified English (ENU) availability. Microsoft’s current registration guidance explains that provider options are shown on the relevant certification detail page, so current delivery choices must be confirmed there rather than inferred from the old document.
For a current Microsoft exam, the registration page says candidates generally begin from the certification overview or credential browser, open the certification detail page, scroll to “Schedule exam,” and select the provider button. The page distinguishes Pearson VUE for candidates taking a certification independently or through a training program from Certiport options used in specified academic or Microsoft Office Specialist contexts.
Microsoft states that certification exams can be scheduled no more than 90 days in advance and that a candidate can have a maximum of two Microsoft Certification exams scheduled at a time through Pearson VUE. These are current scheduling-policy facts, not 70-398 exam-format facts.
The current guidance says that online or test-center choices may be available, but availability depends on the provider. If an online option is shown, candidates must complete a system pre-check and meet the online environment requirements. The supplied evidence does not establish that either option is available for 70-398 today.
Before you book
Sign in to or create the Microsoft Learn profile requested during scheduling, and make sure the legal name on the profile matches the legal identification requirement described by the provider. Request any needed accommodations before scheduling so the provider has time to review them.
If you select online delivery for an available exam, run the system pre-check on the computer and network you intend to use. If you prefer a controlled environment or do not want to manage the technical requirements, check whether a local test center is offered.
Record the appointment details in your own calendar and use the Learn profile to manage permitted rescheduling or cancellation actions. Do not assume an old 70-398 listing, provider reference, language, or delivery option is still active.
Which mistakes waste the most preparation time?
The largest mistake is studying an old exam as though its availability and content were current. Confirm status first, then separate historical objective evidence from present-day certification decisions. The next major mistake is preparing by product vocabulary alone; the stated objectives require planning, protection, management, and troubleshooting connections.
Another common error is allocating all study time to a familiar platform. A Windows administrator may underestimate DLP and mobile security, while a security specialist may overlook device maintenance, networking, and enrollment dependencies. Use the domain labels and expected background to expose both kinds of imbalance.
Do not treat the published 15–20% ranges as permission to skip a domain. Each named domain has a meaningful allocation in the official document, and the surrounding application, identity, mobile, and virtualization topics can connect several areas at once.
Avoid copying a lab without recording why each setting exists. When a scenario changes the identity source, device state, data type, or application requirement, procedural memory may fail. Design notes and troubleshooting evidence are more durable than a sequence of clicks.
Finally, do not use exam dumps or purported live questions. They do not validate competence, may be inaccurate or outdated, and do not turn memorization into a reliable preparation method. Use official objectives, legitimate technical documentation, and your own scenario analysis instead.
A final readiness check
You are in a stronger position when you can identify the affected domain, state the design objective, name the dependency, predict the user or administrator impact, and describe how to verify the result. If you can only recognize a term but cannot explain its decision context, keep studying that topic.
Before scheduling, verify the official status again, check the current exam page for provider and delivery information, and confirm that your study notes distinguish the 2015 objective document from current Microsoft terminology.
What should you do next?
Open the official Microsoft Learn credential browser and search for 70-398. If it is available, compare the live detail page with the historical objective document and follow the current scheduling route. If it is not available, choose a current credential that matches your intended role and use the 70-398 objectives to identify transferable device-management foundations.
Then create a one-page gap assessment covering cloud or hybrid identity, device access and protection, data access and protection, mobile-device security, DLP, application delivery, virtualization, Windows networking, Active Directory, and Intune. Rank gaps by dependency: identity and networking issues can undermine several later topics.
Your immediate study action should be small but diagnostic. Draw a device-management architecture, explain the identity flow, add an access and protection decision, and show where a DLP policy or application-delivery control applies. Mark every assumption you cannot defend. That list is a more reliable starting point than a generic promise of exam readiness.
Keep checking official Microsoft pages when making a booking or replacement-certification decision. Retirement status, credential listings, provider availability, and current technology guidance can change, while the supplied 70-398 objective document remains a dated description of the exam’s historical scope.
Conclusion
70-398 is best approached as a historical Microsoft device-management exam whose documented scope remains useful for understanding identity, endpoint protection, data controls, mobile security, and application delivery. The responsible preparation decision comes first: verify whether Microsoft still offers the exam. If it does, study the named domains through designs and troubleshooting. If it does not, carry the underlying skills into a current credential after checking that credential’s own official requirements.