Microsoft 365 Endpoint Administrator Training (MD-102)
Course 8676
5 DAY COURSE
Course Outline
This five-day, hands-on course teaches IT professionals how to plan and implement an endpoint deployment, configuration, security, and management strategy using Microsoft Intune as a unified endpoint management platform.
Participants learn to prepare identity and device infrastructure with Microsoft Entra ID, enroll and configure devices across multiple platforms, deploy and protect applications, manage updates, and secure endpoints and organizational data.
The course also explores automation with PowerShell and Microsoft Graph, AI-assisted endpoint management with Microsoft Security Copilot, advanced Microsoft Intune Suite capabilities, and cloud-hosted desktops using Windows 365 and Azure Virtual Desktop.
This course helps prepare learners for the Microsoft 365 Certified: Endpoint Administrator Associate certification.
Microsoft 365 Endpoint Administrator Training (MD-102) Benefits
-
In this course, participants will learn how to:
- Prepare Microsoft Entra ID and Microsoft Intune infrastructure for endpoint management
- Enroll and manage Windows, macOS, iOS, iPadOS, and Android devices
- Configure device profiles, policies, security settings, and compliance requirements
- Deploy, configure, update, and protect applications using Microsoft Intune
- Implement Windows Autopilot and other cloud-based deployment solutions
- Protect endpoints with Microsoft Defender for Endpoint and Intune security capabilities
- Manage Windows 365 Cloud PCs and Azure Virtual Desktop environments
- Use advanced Microsoft Intune Suite capabilities
- Automate endpoint management tasks with PowerShell and Microsoft Graph
- Use Microsoft Security Copilot to support endpoint investigation, analysis, and management
Audience
This course is intended for endpoint administrators and other IT professionals responsible for deploying, configuring, securing, managing, and monitoring devices and client applications in Microsoft 365 environments.
Endpoint administrators work with architects, Microsoft 365 administrators, security administrators, and other technology professionals to plan and implement modern workplace strategies that meet organizational requirements.
Training Prerequisites
Participants should have:
- Experience with Microsoft Entra ID, Microsoft 365, and Microsoft Intune
- Experience deploying, configuring, and maintaining Windows client devices
- Familiarity with managing non-Windows devices
- An understanding of networking, client security, identity, access, applications, and device management concepts
-
Certification Information
This course can help you prepare for the following Microsoft role-based certification exam — Exam MD-102: Endpoint Administrator.
Manage and Secure Microsoft 365 Endpoints by Using Intune (MD-102) Training Outline
Learning Objectives
Explore Endpoint Management
Explore the concepts, technologies, and lifecycle processes used to manage enterprise endpoints across different operating systems, platforms, and device types.
- Explore modern endpoint management
- Examine the enterprise desktop lifecycle
- Compare Windows editions and capabilities
- Explore Windows installation and deployment methods
- Identify endpoint management planning considerations
- Explore Microsoft Intune as a unified endpoint management platform
Manage Microsoft Entra Identities
Prepare the identity infrastructure required to manage users, groups, devices, roles, and access within a Microsoft 365 environment.
- Explore Microsoft Entra ID
- Compare Microsoft Entra ID with Active Directory Domain Services
- Create and manage users and groups
- Configure administrative roles and role-based access control
- Manage device identities in Microsoft Entra ID
- Configure hybrid identity synchronization
- Manage identities by using PowerShell
Prepare Microsoft Intune for Device Management
Configure the Microsoft Intune tenant, administrative controls, device platforms, and enrollment settings required to manage organizational endpoints.
- Configure the Microsoft Intune tenant
- Configure supported device platforms
- Manage Intune roles and scope tags
- Configure enrollment restrictions
- Configure device categories and corporate identifiers
- Implement multi-admin approval
- Monitor Intune tenant and service health
Enroll Devices in Microsoft Intune
Implement enrollment methods for Windows, Apple, and Android devices and manage devices throughout the enrollment lifecycle.
- Configure automatic enrollment for Windows devices
- Enroll Windows devices in Microsoft Intune
- Configure Windows enrollment options
- Enroll macOS, iOS, and iPadOS devices
- Configure Apple automated device enrollment
- Configure Android Enterprise enrollment
- Manage personally owned and corporate-owned devices
- Troubleshoot device enrollment
Configure Device Profiles
Create and manage configuration profiles, security settings, and policies that control the behavior of managed devices.
- Create device configuration profiles
- Configure settings catalog policies
- Configure administrative templates
- Manage Windows device settings
- Configure Apple and Android device settings
- Configure shared and specialized devices
- Manage local users and groups
- Monitor configuration profile deployment
Manage Authentication, Access, and Compliance
Implement authentication, compliance, and access controls that protect organizational resources and support secure device access.
- Configure device compliance policies
- Configure compliance notifications and actions
- Integrate device compliance with Conditional Access
- Configure multifactor authentication
- Implement Windows Hello for Business
- Configure passwordless authentication
- Implement Windows Local Administrator Password Solution
- Monitor and troubleshoot device compliance
Deploy Windows Devices
Plan and implement modern Windows deployment and provisioning solutions using Microsoft Intune and Windows Autopilot.
- Plan Windows deployment strategies
- Configure Windows Autopilot deployment profiles
- Configure the Enrollment Status Page
- Deploy devices with Windows Autopilot
- Implement self-deploying and pre-provisioned deployment
- Manage Windows edition upgrades
- Configure Windows activation
- Implement Windows Backup and Restore
- Troubleshoot Windows deployment
Manage Device Updates
Plan, deploy, and monitor operating system and feature updates across managed endpoint platforms.
- Plan an endpoint update strategy
- Configure Windows update rings
- Deploy Windows feature and quality updates
- Configure driver and firmware updates
- Implement Windows Autopatch
- Configure Windows Hotpatch
- Manage Apple and Android operating system updates
- Configure Delivery Optimization
- Monitor and troubleshoot update deployment
Deploy and Manage Applications
Prepare, deploy, configure, update, and monitor applications across Windows, Apple, and Android devices.
- Prepare applications for deployment
- Deploy Win32 applications
- Deploy line-of-business applications
- Deploy Microsoft Store applications
- Deploy Microsoft 365 Apps
- Configure application requirements and dependencies
- Configure application supersedence
- Manage Apple and Android applications
- Monitor and troubleshoot application deployment
Protect Applications and Organizational Data
Use application protection and configuration policies to protect organizational information on managed and unmanaged devices.
- Configure application protection policies
- Protect data on personally owned devices
- Configure application configuration policies
- Implement data transfer and access restrictions
- Configure Conditional Access for protected applications
- Manage mobile application management without enrollment
- Monitor application protection status
- Troubleshoot application protection policies
Manage Endpoint Security
Configure Microsoft Intune and Microsoft Defender for Endpoint controls to secure devices, applications, identities, and organizational data.
- Configure endpoint security policies
- Manage Microsoft Defender Antivirus
- Configure Microsoft Defender Firewall
- Manage disk encryption and BitLocker
- Configure attack surface reduction policies
- Implement security baselines
- Configure App Control for Business
- Integrate Intune with Microsoft Defender for Endpoint
- Onboard devices to Microsoft Defender for Endpoint
- Monitor endpoint security and remediation status
Perform Remote Device Management
Manage, troubleshoot, secure, and retire enrolled devices using remote actions and diagnostic tools.
- Perform remote device actions
- Restart, rename, sync, and locate devices
- Retire, wipe, and delete devices
- Reset device passcodes
- Collect device diagnostics
- Review device logs and management status
- Perform bulk device actions
- Troubleshoot managed devices
Implement Microsoft Intune Suite Capabilities
Use advanced Microsoft Intune Suite capabilities to enhance endpoint security, application delivery, support, connectivity, and certificate management.
- Explore Microsoft Intune Suite capabilities
- Configure Endpoint Privilege Management
- Deploy applications from the Enterprise App Catalog
- Implement Microsoft Intune Remote Help
- Configure Microsoft Cloud PKI
- Implement Microsoft Tunnel
- Explore Advanced Analytics
- Evaluate Intune Suite licensing and deployment considerations
Manage Cloud-Based Desktops
Plan, deploy, configure, and manage cloud-hosted desktops using Windows 365 and Azure Virtual Desktop.
- Explore Windows 365 capabilities
- Plan Windows 365 Cloud PC deployment
- Configure provisioning policies
- Manage Cloud PC images and network connections
- Monitor and troubleshoot Cloud PCs
- Explore Azure Virtual Desktop
- Manage Azure Virtual Desktop endpoints
- Secure access to cloud-hosted desktops
Automate Endpoint Management
Use PowerShell and Microsoft Graph to automate administrative tasks, retrieve endpoint data, and manage Intune resources at scale.
- Explore endpoint management automation
- Manage Microsoft Intune with PowerShell
- Connect to Microsoft Graph
- Use Microsoft Graph PowerShell
- Retrieve device, user, policy, and application information
- Automate repetitive endpoint management tasks
- Manage resources through Microsoft Graph
- Apply permissions and security considerations to automation
Use Microsoft Security Copilot for Endpoint Management
Use Microsoft Security Copilot to investigate endpoint issues, analyze security information, summarize findings, and support administrative decision-making.
- Explore Microsoft Security Copilot capabilities
- Use natural language prompts for endpoint administration
- Investigate device and security issues
- Analyze endpoint security data
- Summarize incidents and recommendations
- Use Security Copilot with Microsoft Intune
- Use Security Copilot with Microsoft Defender for Endpoint
- Review AI-generated results before taking action
Monitor and Optimize Endpoint Operations
Monitor endpoint health, performance, compliance, security, and user experience using Intune reporting and analytics capabilities.
- Monitor device health and compliance
- Create and review Intune reports
- Use Endpoint Analytics
- Analyze startup performance and application reliability
- Use proactive remediations
- Create remediation scripts
- Monitor policy and application deployment
- Review operational dashboards and alerts
- Troubleshoot endpoint management issues
- choosing a selection results in a full page refresh