MD-102 - Manage and Secure Microsoft 365 Endpoints by Using Intune


Course Description

This five-day, hands-on course teaches IT professionals how to plan and implement an endpoint deployment, configuration, security, and management strategy using Microsoft Intune as a unified endpoint management platform. Participants learn to prepare identity and device infrastructure with Microsoft Entra ID, enroll and configure devices across multiple platforms, deploy and protect applications, manage updates, and secure endpoints and organizational data. The course also explores automation with PowerShell and Microsoft Graph, AI-assisted endpoint management with Microsoft Security Copilot, advanced Microsoft Intune Suite capabilities, and cloud-hosted desktops using Windows 365 and Azure Virtual Desktop. This course helps prepare learners for the Microsoft 365 Certified: Endpoint Administrator Associate certification.

Duration: 5 days


Audience Profile

This course is intended for endpoint administrators and other IT professionals responsible for deploying, configuring, securing, managing, and monitoring devices and client applications in Microsoft 365 environments. Endpoint administrators work with architects, Microsoft 365 administrators, security administrators, and other technology professionals to plan and implement modern workplace strategies that meet organizational requirements.

Prerequisites

Participants should have: Experience with Microsoft Entra ID, Microsoft 365, and Microsoft Intune Experience deploying, configuring, and maintaining Windows client devices Familiarity with managing non-Windows devices An understanding of networking, client security, identity, access, applications, and device management concepts

Certification Information

This course can help you prepare for the Microsoft role-based certification exam MD-102: Endpoint Administrator and the Microsoft 365 Certified: Endpoint Administrator Associate certification.

Learning Outcomes

Prepare Microsoft Entra ID and Microsoft Intune infrastructure for endpoint management Enroll and manage Windows, macOS, iOS, iPadOS, and Android devices Configure device profiles, policies, security settings, and compliance requirements Deploy, configure, update, and protect applications using Microsoft Intune Implement Windows Autopilot and other cloud-based deployment solutions Protect endpoints with Microsoft Defender for Endpoint and Intune security capabilities Manage Windows 365 Cloud PCs and Azure Virtual Desktop environments Use advanced Microsoft Intune Suite capabilities Automate endpoint management tasks with PowerShell and Microsoft Graph Use Microsoft Security Copilot to support endpoint investigation, analysis, and management

Module 1: Explore Endpoint Management

Explore modern endpoint management Examine the enterprise desktop lifecycle Compare Windows editions and capabilities Explore Windows installation and deployment methods Identify endpoint management planning considerations Explore Microsoft Intune as a unified endpoint management platform

Module 2: Manage Microsoft Entra Identities

Explore Microsoft Entra ID Compare Microsoft Entra ID with Active Directory Domain Services Create and manage users and groups Configure administrative roles and role-based access control Manage device identities in Microsoft Entra ID Configure hybrid identity synchronization Manage identities by using PowerShell

Module 3: Prepare Microsoft Intune for Device Management

Configure the Microsoft Intune tenant Configure supported device platforms Manage Intune roles and scope tags Configure enrollment restrictions Configure device categories and corporate identifiers Implement multi-admin approval Monitor Intune tenant and service health

Module 4: Enroll Devices in Microsoft Intune

Configure automatic enrollment for Windows devices Enroll Windows devices in Microsoft Intune Configure Windows enrollment options Enroll macOS, iOS, and iPadOS devices Configure Apple automated device enrollment Configure Android Enterprise enrollment Manage personally owned and corporate-owned devices Troubleshoot device enrollment

Module 5: Configure Device Profiles

Create device configuration profiles Configure settings catalog policies Configure administrative templates Manage Windows device settings Configure Apple and Android device settings Configure shared and specialized devices Manage local users and groups Monitor configuration profile deployment

Module 6: Manage Authentication, Access, and Compliance

Configure device compliance policies Configure compliance notifications and actions Integrate device compliance with Conditional Access Configure multifactor authentication Implement Windows Hello for Business Configure passwordless authentication Implement Windows Local Administrator Password Solution Monitor and troubleshoot device compliance

Module 7: Deploy Windows Devices

Plan Windows deployment strategies Configure Windows Autopilot deployment profiles Configure the Enrollment Status Page Deploy devices with Windows Autopilot Implement self-deploying and pre-provisioned deployment Manage Windows edition upgrades Configure Windows activation Implement Windows Backup and Restore Troubleshoot Windows deployment

Module 8: Manage Device Updates

Plan an endpoint update strategy Configure Windows update rings Deploy Windows feature and quality updates Configure driver and firmware updates Implement Windows Autopatch Configure Windows Hotpatch Manage Apple and Android operating system updates Configure Delivery Optimization Monitor and troubleshoot update deployment

Module 9: Deploy and Manage Applications

Prepare applications for deployment Deploy Win32 applications Deploy line-of-business applications Deploy Microsoft Store applications Deploy Microsoft 365 Apps Configure application requirements and dependencies Configure application supersedence Manage Apple and Android applications Monitor and troubleshoot application deployment

Module 10: Protect Applications and Organizational Data

Configure application protection policies Protect data on personally owned devices Configure application configuration policies Implement data transfer and access restrictions Configure Conditional Access for protected applications Manage mobile application management without enrollment Monitor application protection status Troubleshoot application protection policies

Module 11: Manage Endpoint Security

Configure endpoint security policies Manage Microsoft Defender Antivirus Configure Microsoft Defender Firewall Manage disk encryption and BitLocker Configure attack surface reduction policies Implement security baselines Configure App Control for Business Integrate Intune with Microsoft Defender for Endpoint Onboard devices to Microsoft Defender for Endpoint Monitor endpoint security and remediation status

Module 12: Perform Remote Device Management

Perform remote device actions Restart, rename, sync, and locate devices Retire, wipe, and delete devices Reset device passcodes Collect device diagnostics Review device logs and management status Perform bulk device actions Troubleshoot managed devices

Module 13: Implement Microsoft Intune Suite Capabilities

Explore Microsoft Intune Suite capabilities Configure Endpoint Privilege Management Deploy applications from the Enterprise App Catalog Implement Microsoft Intune Remote Help Configure Microsoft Cloud PKI Implement Microsoft Tunnel Explore Advanced Analytics Evaluate Intune Suite licensing and deployment considerations

Module 14: Manage Cloud-Based Desktops

Explore Windows 365 capabilities Plan Windows 365 Cloud PC deployment Configure provisioning policies Manage Cloud PC images and network connections Monitor and troubleshoot Cloud PCs Explore Azure Virtual Desktop Manage Azure Virtual Desktop endpoints Secure access to cloud-hosted desktops

Module 15: Automate Endpoint Management

Explore endpoint management automation Manage Microsoft Intune with PowerShell Connect to Microsoft Graph Use Microsoft Graph PowerShell Retrieve device, user, policy, and application information Automate repetitive endpoint management tasks Manage resources through Microsoft Graph Apply permissions and security considerations to automation

Module 16: Use Microsoft Security Copilot for Endpoint Management

Explore Microsoft Security Copilot capabilities Use natural language prompts for endpoint administration Investigate device and security issues Analyze endpoint security data Summarize incidents and recommendations Use Security Copilot with Microsoft Intune Use Security Copilot with Microsoft Defender for Endpoint Review AI-generated results before taking action

Module 17: Monitor and Optimize Endpoint Operations

Monitor device health and compliance Create and review Intune reports Use Endpoint Analytics Analyze startup performance and application reliability Use proactive remediations Create remediation scripts Monitor policy and application deployment Review operational dashboards and alerts Troubleshoot endpoint management issues


Endpoint Microsoft 365 MD102 MD-102 Intune Microsoft Entra ID Windows 365 Azure Virtual Desktop Microsoft Defender for Endpoint Microsoft Graph PowerShell Microsoft Security Copilot Windows Autopilot