@AX150 Thanks for posting in our Q&A. I will try my best to answer these questions:
Q1: Yes, we refer to the following link to manage local administrators.
https://www.petervanderwoude.nl/post/managing-local-administrators-via-windows-10-mdm/
Note: Non-Microsoft link, just for the reference.
Q2: We can wipe the device. The Wipe action restores a device to its factory default settings.
https://video2.skills-academy.com/en-us/mem/intune/remote-actions/devices-wipe
Q3: This policy can be configured to whether remote access to computers by using Remote Desktop Services
https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-allowuserstoconnectremotely
Q4: The following article lists the type of apps in windows 10.
https://video2.skills-academy.com/en-us/mem/intune/apps/apps-windows-10-app-deploy
Q5: To clarify this, are you trying to block the private store or the public store? The policy you are using blocks the public store. There's no way to block the private store.
https://video2.skills-academy.com/en-us/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-requireprivatestoreonly
Q6: When deploying app via intune, we need to assign group to the app. If we assign the user group, only the devices that these users login will install the app. The following article shows how to assign apps to groups.
https://video2.skills-academy.com/en-us/mem/intune/apps/apps-deploy
Q7: We can deploy trusted certificate profiles via intune.
https://video2.skills-academy.com/en-us/mem/intune/protect/certificates-trusted-root
Q8: For this issue, I have done a lot of research. I find some information about Microsoft Tunnel, but I'm not sure if this is what you need.
https://video2.skills-academy.com/en-us/mem/intune/protect/microsoft-tunnel-overview
Hope the above information will help.
If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.