
Join an experienced instructor for the md-102 endpoint administrator associate course with sims, delivering hands-on demonstrations and browser-based simulations available 24/7, plus exam-focused prep aligned to official Microsoft objectives.
This is Part 1 of 3 of a drawing and explanation I will do to help you understand foundational concepts. In this lecture, I will help you understand the reasons why Microsoft Active Domains are important to business
This is Part 2 of 3 of a drawing and explanation I will do to help you understand foundational concepts. In this lecture, I will help you understand the concepts behind Remote Access Services (RAS), Demilitarized Zones (DMZ), and Virtualization.
Explore hands-on practice options for the MD-102 course, noting that setting up a practice lab is optional; you can learn via watching or simulations anytime.
This video will help you understand how to use assignments in the course
Understand why foundational concepts are taught in a learner-friendly order rather than exam objectives. Note that objectives may be renamed or covered in multiple or split videos, including advanced concepts.
Download the Windows Server 2022 ISO from Microsoft or the exam lab practice site, right-click the link and save link as, and save the file to your desktop.
Discover how to install and configure Hyper-V on Windows, including requirements for professional or enterprise editions, enabling Hyper-V features, and opening Hyper-V manager to create virtual machines.
Download the Windows 11 ISO for a virtual machine from exam lab practice, choose English United States 64-bit edition, and follow the form steps to initiate the download.
Set up a personal lab with Microsoft 365 and Azure, obtain a free Office 365 E5 trial, activate Microsoft 365 E5, and explore optional Teams trials across regions.
Create a free Microsoft 365 and Azure trial account, verify with a phone number, navigate licensing and activation, and learn how to cancel the trial for hands-on admin practice.
Choose the right join type, including registered, joined, and hybrid joined, for devices in Microsoft Entra ID, balancing BYOD realities with enterprise control and Intune.
Register a personal device to Microsoft Entra ID to apply policy with limited control, and distinguish it from a joined device shown in portal.azure.com.
Plan and implement device groups in Microsoft Entra ID by creating a dynamic security group based on device OS type and version, enabling automatic Windows, Android, and iOS device inclusion.
Learn how to redo simulations after completing an assignment by following simple steps: go to summary, return to the assignment, open instructions, and access the simulation link anytime.
Explore Microsoft Intune, an MDM and MAM for enrolling and managing devices across Windows, iOS, macOS, Android, and Linux. See how it deploys apps and policies and replaces group policies.
Configure automatic and bulk enrollment across Windows, Apple, and Android using Intune, group policy, provisioning packages, Apple Configurator, and zero-touch enrollment.
Configure policy sets by grouping apps policies and other management objects in Intune. Deploy these objects to devices or users from a single place, aligning with a security baseline.
Explore how to view, search, and assign roles in the Microsoft 365 admin center, including IntraID roles, role groups, and permissions across Exchange Online, Intune, Defender XDR, and Purview.
Configure scope tags and scoped administration in Intune, create US and UK device and admin groups, and define custom roles to govern tagged devices and policies.
Learn how Intune compliance policies define rules to verify device settings, enforce criteria, generate reports, and block access for noncompliant devices, including pin, encryption, jailbroken or rooted, and health attestation.
Explore how conditional access uses signals from identities, devices, applications, and data to enforce zero-trust policies across Azure and Microsoft 365, including risk-based decisions, MFA, device compliance, and app protection.
Monitor device compliance in the Microsoft Intune portal, identify non-compliant devices, and generate or export reports on firewall, spyware, and antivirus status.
Discover Windows Hello for business, a passwordless sign-in using hardware backed by a TPM, managed with Intune to securely sign in on Windows devices.
Learn how to manage local group membership on Windows devices with Intune, granting admin rights across all devices via the Local User Group Membership policy, including sync and verification steps.
Create, validate, and assign autopilot deployment profiles by linking devices with device IDs to a dynamic security group, then enroll devices via Azure AD joined autopilot.
Discover how to deploy Windows devices with Autopilot by creating deployment profiles, running Sysprep for the out-of-box experience, and confirming device enrollment in Intune and Azure Active Directory.
Understand the Windows autopilot process flow, ensure profile download linked to device ID or group, and verify Azure AD join and Intune MDM enrollment with status page diagnostics.
Learn to create and deploy cross-platform configuration profiles with Microsoft Intune to manage certificates, VPN, Wi-Fi, and device restrictions across Windows, macOS, iOS, iPadOS, and Android.
Deploy Android Enterprise and iOS profiles with Intune, choose device types, apply restrictions (camera, screen capture, block in-app purchases, App Store), and assign via groups and scope tags.
Enable Microsoft Intune Advanced Analytics by provisioning licenses and creating a Windows health monitoring profile. Endpoint analytics collects health data, which can take over 24 hours to appear.
Configure remote help in Intune to enable operators to remotely assist Windows 10 and 11 devices through the remote help add-on license, with role-based access and port 443 connectivity.
Understand the Microsoft tunnel for Intune, a Linux container VPN gateway enabling on-premise access for iOS and Android with Azure AD authentication, conditional access, and split tunneling.
Explore how Intune manages enrolled devices with actions like retire, delete, wipe, restart, and sync, plus mobile remote lock and reset passcode on Windows, Android, and iOS.
Learn how to perform bulk actions on multiple devices in Intune by selecting all devices, choosing Windows, and applying actions such as delete, retire, wipe, or sync.
Configure and deploy Windows Defender security intelligence updates via Microsoft Intune, adjust antivirus settings, enable real-time and cloud protection, and apply policy assignments to protect devices.
demonstrates rotating BitLocker keys on a Windows device using Intune, with keys escrowed to Microsoft Entra ID or Active Directory, and old keys deleted after restart.
Explore KQL queries in Intune analytics to extract device details (BIOS, CPU, disk, system info) via device query; licensing is required, and multi-machine queries aren’t supported in Intune.
Explore how to create and deploy endpoint security policies in Microsoft Intune, including antivirus, firewall, EDR, and attack surface reduction, with Defender for Endpoint integration.
Microsoft Defender for Endpoint provides enterprise-grade security with threat and vulnerability management, attack surface reduction, and endpoint detection and response. Cloud analytics and threat intelligence enhance automated investigation and remediation.
Learn to onboard devices to Microsoft Defender for Endpoint and implement automated response by linking to Intune, assigning licenses, and creating an EDR policy for Windows devices.
This course is way more then the average training course on Udemy! Have access to the following:
Training from an instructor of over 25 years who has helped thousands on their certification journey
Lecture that explains the concepts in an easy to learn method for someone that is just starting out with this material
Instructor led hands on that can be followed even if you have little to no experience
Hands on tutorials that can be practiced 24/7 regardless of if you have Windows 10/11 in front of you
This course prepares you for MD-102 and is also updated to support the new MD-102 Endpoint Administrator exam objectives!
TOPICS COVERED INCLUDING HANDS ON LECTURE AND PRACTICE TUTORIALS:
Introduction
Welcome to the MD-102 course!
A foundation for Microsoft Active Directory Domains
A foundation for Remote Access, DMZs, and Virtualization
A foundation of the Microsoft Cloud Services
Introduction to practicing hands on
Using assignments in the course
Questions for John Christopher
Order of concepts covered in the course
Setting up for hands on
Introduction to practicing hands on
Downloading Windows Server 2022 ISO
Getting Hyper-V Installed on Windows
Creating a Virtual Switch in Hyper-V
Installing a Windows Server 2022 Virtual Machine
Downloading the Windows 11 ISO
Installing a Windows 11 virtual machine
Deploy and manage domain controllers on-premises
Joining Windows 11 to a domain
Creating a trial Microsoft 365/Azure Account
Adding a subscription to your Azure account
Add devices to Microsoft Entra ID
Choose an appropriate device join type
Join devices to Microsoft Entra ID
Register devices to Microsoft Entra ID
Plan and implement groups for devices in Microsoft Entra ID
Enroll devices to Microsoft Intune
Introduction to Microsoft Intune
Configure enrollment settings
Enrollment for Windows, Apple, and Android devices
Configure automatic and bulk enrollment, including Windows, Apple, and Android
Configure policy sets
Sync, restart, retire, or wipe devices
Implement identity and compliance
Understanding roles in Azure, Microsoft 365 and Entra ID
Implement Role Based Access Control within Entra ID
Working with roles in Microsoft 365
Manage built-in & custom roles for Intune & Windows 365, with role assignments
Visualizing how scope tags work for scoped administration in Intune
Configure scope tags and scoped administration for multi-admin environments
Specify compliance policies to meet requirements
Implement compliance policies
Understanding Conditional Access policies
Implement Conditional Access policies that require a compliance status
Manage notifications for compliance policies
Monitor device compliance
Configure Windows Hello for Business
Implement and manage Local Administrative Passwords Solution (LAPS) for Entra ID
Manage the membership of local groups on Windows devices by using Intune
Deploy and upgrade Windows clients by using cloud-based tools
Visualizing device registration for Autopilot
Choose between Windows Autopilot deployment profiles and device prep policies
Configure device registration for Autopilot
Create, validate, and assign deployment profiles
Create an Enrollment Status Page (ESP)
Implement Windows client deployment by using Windows Autopilot
Troubleshoot an Autopilot deployment
Plan and implement device configuration profiles
Specify configuration profiles to meet requirements
Implement configuration profiles
Monitor and troubleshoot configuration profiles
Configure and implement Windows kiosk mode
Configure and implement profiles on Android and iOS devices
Understanding Microsoft Tunnel for Intune
Implement Intune Suite add-on capabilities
Implement Microsoft Intune Advanced Analytics
Configure Remote Help in Intune
Understanding Microsoft Tunnel for Intune
Perform remote actions on devices
Sync, restart, retire, or wipe devices
Perform bulk remote actions
Update Windows Defender security intelligence
Rotate BitLocker recovery keys
Run a device query by using KQL
Configure endpoint security
Implement and manage security baselines in Intune
Create & manage configuration policies for Endpoint security including AV,FW,EDR,ASR
Understanding Defender for Endpoint
Onboard devices to Defender for Endpoint and implement automated response
Manage device updates
Plan for device updates for Windows
Create and manage update rings and policies by using Intune
Manage Android updates by using configuration profiles
Create and manage update policies by using Intune, including iOS and Mac OS
Monitor updates
Troubleshoot updates in Intune
Configure Windows client delivery optimization by using Intune
Deploy and update apps
Deploy apps by using Intune
Manage Microsoft 365 Apps by using the Microsoft 365 Apps admin center
Configure Microsoft 365 Apps using the Office Deployment Tool or Office Customization Tool (OCT)
Deploy Microsoft 365 Apps by using Intune
Configure policies for Office apps by using Group Policy or Intune
Deploy apps using platform-specific app stores by using Intune
Plan and implement app protection and app configuration policies
Plan and implement app protection policies for iOS and Android
Manage app protection policies
Implement Conditional Access policies for app protection policies
Plan and implement app configuration policies for managed apps and managed devices
Automate management tasks
Concepts of PowerShell vs Microsoft Graph
If you skipped the PowerShell foundation, go back and watch it
Installing and connecting to MS Graph to support cloud services with PowerShell
Using PowerShell with MS Graph to manage Entra ID
Automate Intune management tasks by using PowerShell and Microsoft Graph
Concepts of Security Copilot
How to generate some sample data to query
Concepts of Security compute units (SCUs) in use with Security Copilot
Warning before allocating Security compute units (SCUs) for Security Copilot
Implement a workspace in Security Copilot and allocate SCUs
Allocating permissions when using Security Copilot
Using Prompts, Promptbooks, Roles and Plugins in Security Copilot
Supporting plugins in Security Copilot
Investigate an incident identified using Security Copilot involving a VM