MD-102 - Manage and Secure Microsoft 365 Endpoints by Using Intune
Course Description
This five-day, hands-on course teaches IT professionals how to plan and implement an endpoint deployment, configuration, security, and management strategy using Microsoft Intune as a unified endpoint management platform. Participants learn to prepare identity and device infrastructure with Microsoft Entra ID, enroll and configure devices across multiple platforms, deploy and protect applications, manage updates, and secure endpoints and organizational data. The course also explores automation with PowerShell and Microsoft Graph, AI-assisted endpoint management with Microsoft Security Copilot, advanced Microsoft Intune Suite capabilities, and cloud-hosted desktops using Windows 365 and Azure Virtual Desktop. This course helps prepare learners for the Microsoft 365 Certified: Endpoint Administrator Associate certification.
Duration: 5 days
Audience Profile
This course is intended for endpoint administrators and other IT professionals responsible for deploying, configuring, securing, managing, and monitoring devices and client applications in Microsoft 365 environments. Endpoint administrators work with architects, Microsoft 365 administrators, security administrators, and other technology professionals to plan and implement modern workplace strategies that meet organizational requirements.
Prerequisites
Participants should have: Experience with Microsoft Entra ID, Microsoft 365, and Microsoft Intune Experience deploying, configuring, and maintaining Windows client devices Familiarity with managing non-Windows devices An understanding of networking, client security, identity, access, applications, and device management concepts
Certification Information
This course can help you prepare for the Microsoft role-based certification exam MD-102: Endpoint Administrator and the Microsoft 365 Certified: Endpoint Administrator Associate certification.
Learning Outcomes
Prepare Microsoft Entra ID and Microsoft Intune infrastructure for endpoint management Enroll and manage Windows, macOS, iOS, iPadOS, and Android devices Configure device profiles, policies, security settings, and compliance requirements Deploy, configure, update, and protect applications using Microsoft Intune Implement Windows Autopilot and other cloud-based deployment solutions Protect endpoints with Microsoft Defender for Endpoint and Intune security capabilities Manage Windows 365 Cloud PCs and Azure Virtual Desktop environments Use advanced Microsoft Intune Suite capabilities Automate endpoint management tasks with PowerShell and Microsoft Graph Use Microsoft Security Copilot to support endpoint investigation, analysis, and management
Module 1: Explore Endpoint Management
Explore modern endpoint management Examine the enterprise desktop lifecycle Compare Windows editions and capabilities Explore Windows installation and deployment methods Identify endpoint management planning considerations Explore Microsoft Intune as a unified endpoint management platform
Module 2: Manage Microsoft Entra Identities
Explore Microsoft Entra ID Compare Microsoft Entra ID with Active Directory Domain Services Create and manage users and groups Configure administrative roles and role-based access control Manage device identities in Microsoft Entra ID Configure hybrid identity synchronization Manage identities by using PowerShell
Module 3: Prepare Microsoft Intune for Device Management
Configure the Microsoft Intune tenant Configure supported device platforms Manage Intune roles and scope tags Configure enrollment restrictions Configure device categories and corporate identifiers Implement multi-admin approval Monitor Intune tenant and service health
Module 4: Enroll Devices in Microsoft Intune
Configure automatic enrollment for Windows devices Enroll Windows devices in Microsoft Intune Configure Windows enrollment options Enroll macOS, iOS, and iPadOS devices Configure Apple automated device enrollment Configure Android Enterprise enrollment Manage personally owned and corporate-owned devices Troubleshoot device enrollment
Module 5: Configure Device Profiles
Create device configuration profiles Configure settings catalog policies Configure administrative templates Manage Windows device settings Configure Apple and Android device settings Configure shared and specialized devices Manage local users and groups Monitor configuration profile deployment
Module 6: Manage Authentication, Access, and Compliance
Configure device compliance policies Configure compliance notifications and actions Integrate device compliance with Conditional Access Configure multifactor authentication Implement Windows Hello for Business Configure passwordless authentication Implement Windows Local Administrator Password Solution Monitor and troubleshoot device compliance
Module 7: Deploy Windows Devices
Plan Windows deployment strategies Configure Windows Autopilot deployment profiles Configure the Enrollment Status Page Deploy devices with Windows Autopilot Implement self-deploying and pre-provisioned deployment Manage Windows edition upgrades Configure Windows activation Implement Windows Backup and Restore Troubleshoot Windows deployment
Module 8: Manage Device Updates
Plan an endpoint update strategy Configure Windows update rings Deploy Windows feature and quality updates Configure driver and firmware updates Implement Windows Autopatch Configure Windows Hotpatch Manage Apple and Android operating system updates Configure Delivery Optimization Monitor and troubleshoot update deployment
Module 9: Deploy and Manage Applications
Prepare applications for deployment Deploy Win32 applications Deploy line-of-business applications Deploy Microsoft Store applications Deploy Microsoft 365 Apps Configure application requirements and dependencies Configure application supersedence Manage Apple and Android applications Monitor and troubleshoot application deployment
Module 10: Protect Applications and Organizational Data
Configure application protection policies Protect data on personally owned devices Configure application configuration policies Implement data transfer and access restrictions Configure Conditional Access for protected applications Manage mobile application management without enrollment Monitor application protection status Troubleshoot application protection policies
Module 11: Manage Endpoint Security
Configure endpoint security policies Manage Microsoft Defender Antivirus Configure Microsoft Defender Firewall Manage disk encryption and BitLocker Configure attack surface reduction policies Implement security baselines Configure App Control for Business Integrate Intune with Microsoft Defender for Endpoint Onboard devices to Microsoft Defender for Endpoint Monitor endpoint security and remediation status
Module 12: Perform Remote Device Management
Perform remote device actions Restart, rename, sync, and locate devices Retire, wipe, and delete devices Reset device passcodes Collect device diagnostics Review device logs and management status Perform bulk device actions Troubleshoot managed devices
Module 13: Implement Microsoft Intune Suite Capabilities
Explore Microsoft Intune Suite capabilities Configure Endpoint Privilege Management Deploy applications from the Enterprise App Catalog Implement Microsoft Intune Remote Help Configure Microsoft Cloud PKI Implement Microsoft Tunnel Explore Advanced Analytics Evaluate Intune Suite licensing and deployment considerations
Module 14: Manage Cloud-Based Desktops
Explore Windows 365 capabilities Plan Windows 365 Cloud PC deployment Configure provisioning policies Manage Cloud PC images and network connections Monitor and troubleshoot Cloud PCs Explore Azure Virtual Desktop Manage Azure Virtual Desktop endpoints Secure access to cloud-hosted desktops
Module 15: Automate Endpoint Management
Explore endpoint management automation Manage Microsoft Intune with PowerShell Connect to Microsoft Graph Use Microsoft Graph PowerShell Retrieve device, user, policy, and application information Automate repetitive endpoint management tasks Manage resources through Microsoft Graph Apply permissions and security considerations to automation
Module 16: Use Microsoft Security Copilot for Endpoint Management
Explore Microsoft Security Copilot capabilities Use natural language prompts for endpoint administration Investigate device and security issues Analyze endpoint security data Summarize incidents and recommendations Use Security Copilot with Microsoft Intune Use Security Copilot with Microsoft Defender for Endpoint Review AI-generated results before taking action
Module 17: Monitor and Optimize Endpoint Operations
Monitor device health and compliance Create and review Intune reports Use Endpoint Analytics Analyze startup performance and application reliability Use proactive remediations Create remediation scripts Monitor policy and application deployment Review operational dashboards and alerts Troubleshoot endpoint management issues