
Deploy and manage Windows clients and mobile devices, configure identities, and monitor compliance with Microsoft Intune for MDM and MAM, and deploy apps and Office products via Microsoft Entra ID.
Choose Windows editions by matching use case to features, from Windows Home to Windows Pro, Education, Enterprise, Pro for Workstation, and LTSC, highlighting domain join, Remote Desktop, and BitLocker.
Determine if hardware can install Windows 11: 8th generation Intel or Ryzen 3+ CPU, quad-core, 64-bit, 4 GB RAM; TPM 2.0 with UEFI, Secure Boot, DirectX 12, and WDDM 2.0.
Explore how to customize WinPE with ADK by using DISM, CopyPE, and MakeWinPE to service the boot.wim, create a WinPE ISO, and prepare deployment images for Windows 11 22H2.
Create an unattend.xml answer file with WSIM for automated Windows deployments, selecting a WIM install image and catalog, and configuring disk partitions, locale, and oobe settings.
Explore on-prem and cloud Windows deployment tools, including WDS, MDT, SCCM, ADK, Autopilot, Windows 365, and Intune, with guidance on when to use each and hybrid options.
Learn to migrate Windows clients with USMT as part of the Windows ADK, choosing wipe-and-load or side-by-side strategies, capturing and restoring user state using ScanState, LoadState, and the USMT utility.
Explore migrations and rebuilds to preserve user data and system state during device deployments and operating system upgrades.
Configure Windows provisioning packages to automate domain join and basic system setup using Windows Configuration Designer and the Windows ADK. Deploy packages via network shares or USB, including PuTTY.
Explore modern imaging and provisioning for endpoint administration, including bit-by-bit operating system images, automation, and tools like Windows Deployment Services, ADK, WinPE, and DISM.
Learn how subscription-based activation silently upgrades Windows pro to enterprise or education, enabling dynamic license reassignment, BYOD support with Intune, and seamless migration from older activation methods.
Configure and implement autopilot to pre-configure and register Windows devices, using hardware hashes, manual or automatic enrollment, and group-based device deployment in Intune.
Create and configure Autopilot deployment profiles in the Windows Autopilot deployment program to automate the out-of-box experience, Azure AD joined devices, and policy-driven enrollment via the Intune Admin Center.
Deploy enrollment status pages (ESP) in Intune for MD-102: endpoint administrator, showing installation progress during Windows autopilot deployments, customizing time limits and error messages, and managing priorities across device groups.
Learn to deploy Windows devices with Autopilot by importing device hashes into Intune, applying a deployment profile, and enrolling devices via the OOBE for automatic Autopilot management.
Learn practical troubleshooting for Autopilot deployments by using the Windows Autopilot diagnostic page and Enrollment Status Page, validating ESP settings, network connectivity, and log exports.
Learn how to implement the Microsoft Deployment Toolkit to deploy Windows clients and servers, configure deployment shares, import images, automate unattended installations, and leverage USMT and PowerShell commands.
Import, manage, and deploy Windows images with MDT using the deployment workbench. Create deployment shares, import operating systems and drivers, and build task sequences for deployment.
Enable monitoring for MDT deployments using the deployment workbench and configure monitoring ports and firewall rules. Troubleshoot with event logs, documentation, and MDT monitor endpoints.
Explore how to configure and connect to remote Windows desktops using the remote desktop connection software (MSTSC), including enabling remote desktop, port 3389, RDP files, and managing local resources.
Configure remote management for Windows clients using PowerShell remoting and WinRM, set trusted hosts, and run remote commands across multiple machines in workgroup or domain environments.
Enable remote help in Intune to deliver cross-network, user-driven support with an enrolled helper device, a security code, and privacy options during the session.
Learn to deploy Windows Admin Center, a browser-based tool to centrally manage Windows 10 and Windows 11 clients, servers, and hyper-converged infrastructure, using Edge, admin rights, and PS remoting.
Learn how to implement compliance policies in Intune to control device access, enforce configurations, and apply conditional access to quarantine or retire non-compliant devices.
Learn to manage and edit device compliance policies in Intune, including lifecycle, assignment, rescoping, and retirement, with practical steps for Windows and Android profiles.
Explore implementing conditional access with Intune and Azure AD Entra, covering device-based and app-based policies, risk-based controls, and BYOD strategies to protect corporate resources.
Learn to create and customize device compliance notifications in Intune, including message templates, branding, locale, contact info, and default settings to inform users of non-compliance.
Learn to monitor device compliance in Intune, evaluate policy deployment across platforms, drill into non-compliant devices, and troubleshoot policy assignments with endpoint security and conditional access.
Learn to troubleshoot Intune device compliance policies using the built-in Intune troubleshooter, diagnose non-compliant devices, review devices and policies, and perform client-side syncs and check-ins.
Explains implementing user authentication on Windows devices with Microsoft accounts, Authenticator, and security keys. Shows Windows Hello and Windows Hello for Business, biometrics, MFA, and passwordless options.
Discover how Windows groups organize users and resources across local, domain, and cloud environments, using security, distribution, and mail-enabled security groups with dynamic membership and licensing.
Explore role-based access control in Intune by defining permission-based roles, using default and customizable templates, and assigning them to users via Azure AD groups for targeted administration.
Learn how to register and join devices to Microsoft Entra ID (formerly Azure AD), enabling BYOD, COPE, and corporate access with Intune, the company portal, and policy control.
Implement the Intune connector for Active Directory to enable on-prem autopilot deployments in hybrid environments, linking cloud Intune with your on-prem Active Directory.
Learn how the local administrator password solution (laps) works with Entra and Intune. Enable laps, configure policies, and rotate built-in administrator passwords across devices.
Enroll devices into Microsoft Intune to centralize mobile device management and apply security policies, access company resources, and streamline endpoint administration across Windows, iOS, Android, Linux, and Chrome OS.
Learn how to enroll Windows devices into Intune, covering requirements (Windows 10 17.03 and later, Azure AD tenant, mobility license, company portal), enrollment methods like automatic enrollment and Windows Autopilot, and policy-driven verification.
Configure bulk enrollment for iOS devices in Microsoft Intune to streamline device provisioning, using Apple MDM Push Certificate, Apple Configurator, direct enrollment, and BYOD workflows.
Explore configuring Android enrollment using Microsoft Intune, including Android device enrollment, work profiles, company portal setup, and compliance policies for secure access to corporate resources.
Configure Chrome OS enrollment in Intune by connecting Google Workspace Admin to Intune via the Chrome OS connector, enabling unified management of Chrome OS devices.
Configure automatic enrollment with Intune to onboard Windows and mobile devices via Azure AD, enabling zero-touch enrollment for corporate and BYOD. Understand licensing and scope for MDM and MAM.
Configure policy sets in Intune to group apps, app configurations, and device policies, then deploy them at once to role-based groups and regional targets while meeting GDPR and CPRA compliance.
Learn to remotely wipe or retire managed devices with Intune, including factory resets to the oobe, and understand how Azure Active Directory records respond.
Configure security baselines in Intune by deploying Windows settings as profiles and tailoring Defender configurations to strengthen your security posture.
Explore how endpoint security policies group focused settings across Windows, iOS, and Android, differentiate them from security baselines, and deploy them via profiles in Intune, including ASR and BitLocker.
Onboard devices into Microsoft Defender for Endpoint using Intune or hybrid methods with scripts, enabling centralized visibility, automated investigations, and vulnerability management for endpoint security.
Learn how automated response in Defender for Endpoint enables automated investigation and remediation of incidents and alerts, strengthening security posture through zero trust and EDR.
Learn to use the Microsoft Defender vulnerability management dashboard to discover, remediate vulnerabilities, view exposure and secure scores, and apply recommendations across Windows, macOS, Linux, Android, iOS, and network devices.
Create and manage Intune update policies to centrally control multi-platform updates—Windows, iOS/iPadOS, Android, and Mac OS—using update rings, feature and quality updates, and third-party drivers.
Explore how Microsoft Intune uses Android Enterprise configuration profiles to centrally manage updates, including Android device administrator, Android Enterprise, and the Android Open Source Project, with policy assignments to groups.
Create and manage update rings in Intune to control Windows as a service updates, assign policies to device groups for staged rollout of feature updates and quality updates.
Configure Windows client delivery optimization with Intune using a device profile to manage update delivery, set bandwidth by business hours, and scope and monitor outcomes.
Monitor and troubleshoot configuration profiles in Intune by reviewing assignment failures, policy status, device check-ins, and licensing via the troubleshooting location.
Discover how to monitor devices with Intune and Azure Monitor, examining device compliance, BitLocker requirements, last check-in, and diagnostic settings with Log Analytics workspaces.
Explore endpoint analytics and the adoption score to measure and improve end-user experience across cloud-based and on-prem devices, using Intune, Entra ID, and Microsoft 365 admin center.
Learn to specify configuration profiles to meet requirements with Microsoft Intune, centralizing Wi‑Fi, VPN, updates, and BitLocker drive encryption across Windows devices.
Configure device configuration profiles with Intune by creating Windows 10/11 identity protection policies, using templates and settings catalogs to enforce Windows Hello for Business, PIN rules, and group-based assignments.
Monitor and troubleshoot updates in Intune, diagnose configuration errors, and verify device groups, licensing, and per update ring deployment status using Intune monitor and troubleshooting tools.
Configure and implement Windows kiosk mode using Intune to create single-app or multi-app configurations on public-facing devices. Deploy via device configuration profiles with kiosk browser, idle refresh, and maintenance windows.
Configure Android devices with Intune by creating device configuration profiles, using templates to push VPN and Wi-Fi settings, and understand Android Enterprise versus legacy options.
Plan and implement Microsoft tunnel for Intune to provide encrypted VPN gateway access for iOS and Android devices using Linux hosts, Docker or Podman, and TLS certificates.
Deploy apps with Intune using mobile application management, configuring MAM authorities, and distributing Microsoft 365, Win32, and mobile apps across Android, iOS, macOS, and Windows with monitoring and policy controls.
Configure and deploy Microsoft 365 apps with the Office deployment tool and Office customization tool, using configuration XML files to enable centralized, automated, silent installations.
Learn to deploy Microsoft 365 apps with the Office Customization Tool (oct) in the Microsoft 365 Apps Admin Center, configuring 64-bit deployment, enterprise apps, language, and update channel.
Explore the Microsoft 365 Apps Admin Center as a cloud-based, centralized interface to manage deployments using standard configurations, prebuilt XML files, and the Office Deployment Tool and Office Customization Tool.
Explore deploying Microsoft 365 apps with Intune using mobile application management and MDM, including Azure AD prerequisites, enrollment scopes, app publishing, configuration, company portal access, and ongoing monitoring of compliance.
Configure policies for office apps with Intune to control which office apps are available, set default file formats, and enforce security features like protected view, macros, and RMS.
Learn to prepare on-prem Active Directory for group policy by importing ADMX/ADML templates to configure Microsoft 365 apps and Office policies, including update channels and deployment settings.
Explore how to deploy apps to app stores with Intune using mobile application management across Android, iOS, Windows, and macOS stores.
Implement app protection policies in Intune to safeguard corporate data across Android, iOS, and Windows, leveraging Windows Information Protection and enforcing encryption, access controls, and app-level restrictions for Microsoft apps.
Manage app protection policies in Microsoft Intune to protect organizational data on Android, iOS, iPadOS, and Windows with WIP, while editing, assigning, and reviewing settings to enforce encryption.
learn to implement conditional access for intune app protection policies, test in azure security, and manage policy modes (report only, enable, off) with careful user exclusions.
Plan and implement app configuration policies in Microsoft Intune for Android Enterprise and managed devices, using the Intune SDK or wrapper tool to apply settings, assign policies, and manage lifecycle.
Explore how to manage app configuration policies in Microsoft Intune, covering policy lifecycle, reconfiguration, removal or decommissioning, and assignments across Azure Active Directory and device lifecycles.
The MD-102 Endpoint Administrator course will show and help the learner to deploy, manage, and maintain Windows client operating systems. Following the course, the learner will be able to implement and manage device lifecycles, including enrollment, configuration, security, and compliance, using Microsoft Intune. Finally, the learner will be able to deploy, configure, and secure applications using Group Policy, Microsoft Intune and Microsoft 365.
An Endpoint Administrator is responsible for managing and securing endpoints such as computers, mobile devices, and other connected devices within an organization.
Experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, is essential. Furthermore, a robust skill set and practical experience in the deployment, setup, and upkeep of both Windows and non-Windows devices are prerequisites.
Skills measured
· Deploy Windows client (25–30%)
· Manage identity and compliance (15–20%)
· Manage, maintain, and protect devices (40–45%)
· Manage applications (10–15%)
The MD-102 Endpoint Administrator course will show and help the learner to deploy, manage, and maintain Windows client operating systems. Following the course, the learner will be able to implement and manage device lifecycles, including enrollment, configuration, security, and compliance, using Microsoft Intune. Finally, the learner will be able to deploy, configure, and secure applications using Group Policy, Microsoft Intune and Microsoft 365.
An Endpoint Administrator is responsible for managing and securing endpoints such as computers, mobile devices, and other connected devices within an organization.
Experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, is essential. Furthermore, a robust skill set and practical experience in the deployment, setup, and upkeep of both Windows and non-Windows devices are prerequisites.