
MD-102 Microsoft 365 endpoint admin associate certification, outlining four modules—preparing infrastructure, autopilot and device management, app management, and device protection—plus resources and live demonstrations.
Prepare device infrastructure in Intune, review device join types, configure enrollment settings including automatic enrollment, and explore RBAC, compliance policies, conditional access, Windows Hello for Business, and LAPS.
Choose the right device join type in Microsoft Entra ID by comparing intra registration, Microsoft Entra join, and hybrid join for BYO and corporate devices.
Learn how to join devices to Microsoft Entra ID by meeting basic requirements, enabling user join, and leveraging MDM enrollment, conditional access, and Windows Hello for business.
Register devices to Microsoft Entra ID to create a secure identity-based foundation for access, with BYOD support and enrollment options across Windows, macOS, Linux, iOS, and Android.
Explore device groups in Microsoft Entra ID, including dynamic membership rules, planning considerations, and how to create and manage dynamic device groups for Intune policies and conditional access.
Configure enrollment settings to apply MDM and Windows Information Protection user scopes, and understand precedence across corporate owned, BYOD, and personal devices in the three interfaces.
Configure automatic enrollment for Windows with an Intune subscription, P1/P2 licenses, and global admin rights; set the MDM user scope and save, then review the enrollment URLs.
Configure bulk enrollment for iOS, iPadOS, and Android devices to streamline provisioning with Intune, linking Apple Business Manager for automated enrollment and deploying enrollment profiles across corporate owned and BYOD.
Explore enrollment profiles for Android devices in Intune, including Android Enterprise work profile, fully managed, dedicated devices, and COPE, covering enrollment methods, managed Google Play, key considerations, and interface steps.
Master Intune roles with rbac, exploring built-in and customizable roles, permissions, scope tags, and assignments while reviewing the interface for policy and profile management.
Implement Intune compliance policies to protect organizational data and enforce security baselines. Configure across Windows, macOS, iOS, Android, and Linux devices and integrate with conditional access for access control.
Implement conditional access policies with Microsoft Entra and Intune by using signal types like user risk and device compliance, test in report mode, and monitor sign-ins.
Configure Windows Hello for business as a device-bound authentication system that replaces passwords with biometrics and TPM-backed keys, and manage tenant-wide enrollment and account protection policies.
Explore the local administrator password solution (laps) in Microsoft Entra ID and deploy it end-to-end via Intune using account protection policies, RBAC, and CSPs.
Manage Windows local groups in Intune using account protection policies to enforce least privilege across devices. Configure group membership via CSP and LAPS for centralized control.
Master module two: manage devices with Windows Autopilot, provisioning packets, device name templates, enrollment status pages, Windows 365 cloud PC, cross-platform configuration, and EPM with cloud PKI.
Compare Windows Autopilot and provisioning packages for large-scale deployments. Autopilot is cloud-based with Intune enrollment and zero-touch options; provisioning packages enable offline, small-scale setups via USB or network shares.
Explore Windows Autopilot deployment modes—user driven, self deploying, pre-provisioned, and existing devices—and align device delivery, setup, and enrollment strategies for modern endpoint provisioning.
Apply a device name template in Windows Autopilot deployments to standardize names, using serial or ran suffixes in Intune deployment profiles within a 15-character limit.
Demonstrate configuring a device name template in Microsoft Intune Autopilot deployment profiles for Windows devices; apply a laptop with a random three-digit value and assign groups.
Implement deployments with Windows Autopilot by configuring a cloud deployment profile, importing hardware identifiers to Intune, and enrolling devices via Microsoft Entra ID during the Oobe.
Configure an enrollment status page (ESP) in Intune to display real-time Windows Autopilot provisioning stages. Understand ESP tracking phases and how device-targeted apps speed provisioning and reduce post-enrollment issues.
Learn to create an enrollment status page in Microsoft Intune via the wizard, configure progress and custom messages, and assign groups for deployment.
Plan and implement provisioning packages with Windows configuration designer to configure offline Windows devices, install apps, join Azure AD, and enroll in MDM for quick, small-scale deployments.
Plan and implement Windows 11 device upgrades with a structured approach, validating hardware, TPM 2.0, secure boot, and upgrade methods like Windows Update for Business, Intune, and Configuration Manager.
Implement and manage Windows 365 cloud PC deployments with per-user licensing, Intune and Entra ID integration, Azure network connections, provisioning policies, and persistent state across sessions.
Create and manage Windows device configuration profiles in Intune, using settings catalog and ADM templates, import custom ADM files, enforce security policies, and monitor assignments for compliance.
Demonstrates creating a Windows device configuration profile in Microsoft Intune. Learn to select Windows 10 and later, choose templates, configure password policies, assign groups, and review profile status.
Create Android configuration profiles in Intune, covering Android Enterprise enrollment options (work profile, corporate owned, cope, dedicated devices), and deploy Wi-Fi, VPN, certificates, and restrictions.
Demonstrates creating an Android device configuration profile in Microsoft Intune, using Android Enterprise settings, templates, and enrollment types, then assigning to a sales group and reviewing deployment status.
Learn to create iOS configuration profiles in Intune, configuring passcodes, Wi-Fi and VPN, email, web content filtering, and home screen layout for secure, consistent device management.
Demonstrate creating an iOS configuration profile in Microsoft Intune using templates for device restrictions. Assign the profile to a help desk group, require a password, and review, edit, and save.
Create and manage macOS device configuration profiles in Microsoft Intune, covering profile types, best practices, assignment, and monitoring to enforce security and customize the user experience.
Shows how to configure macOS device profiles in Microsoft Intune, create a macOS policy, choose templates and password settings, assign to the sales team, and review deployment status.
Create and manage device configuration profiles for enterprise multi-session devices in Intune. Learn best practices, OS edition filtering, and profile types like settings catalog, certificates, VPN, and scripts.
Demonstrates creating and deploying an Intune settings catalog policy for enterprise multi-session devices, including OS edition filtering and Defender and other settings configuration.
Target profiles with dynamic filters in Microsoft Intune to apply policies fine-grained by device attributes without extra groups. Create reusable filters via rule builder or syntax and apply to policies.
Demonstrates targeting profiles with assignment filters in Microsoft Intune, showing how to create, configure, and apply rules (OS version, platform) to device groups via the admin center.
Configure endpoint privilege management in Microsoft Intune to enforce least privilege by elevating approved apps, using automatic, user confirmed, or support approved types, with monitoring and best practices.
Demonstrates how to enable endpoint privilege management in Microsoft Intune by creating an elevation settings policy for Windows, configuring required support approval, and reviewing post-deployment reports and endpoint check-ins.
Manage apps with the enterprise app catalog in Microsoft Intune, a centralized repository of prepackaged Win32 apps that streamlines deployment, with detection rules, requirements, and enrollment status page integration.
Explore deploying a Win32 app through the enterprise app catalog in Intune, configuring installation, requirements, detection rules, assignments, and monitoring for deployments.
Explore implementing Microsoft Intune advanced analytics to gain real-time insights, anomaly detection, and enhanced reporting for endpoint health, user experience, and device performance.
Configure Microsoft Intune remote help to provide secure, real-time remote assistance across Windows, Android, and macOS devices; enforce RBAC, elevation, auditing, and least-privilege best practices.
Explore cloud PKI in Microsoft Intune, identifying use cases, benefits, and best practices. Learn how to deploy, automate certificate lifecycle, and integrate with Entra ID for secure zero-trust access.
Microsoft Tunnel for Mam provides a lightweight VPN that secures access to on-prem resources from Android and iOS devices, supports BYOD, and integrates with Intune app protection policies.
Master remote actions in Microsoft Intune across Windows, macOS, iOS, iPadOS, and Android, including resets, wipes, restarts, and diagnostics, with RBAC and enrollment types.
Learn to manage Windows Defender security intelligence updates via Intune policies. Configure update channels, monitor compliance, and troubleshoot update issues with centralized endpoint management.
Learn how to rotate BitLocker recovery keys with Microsoft Intune, escrow new keys to Microsoft Entra ID, and enforce best practices, prerequisites, and monitoring in a zero-trust environment.
Use the Kusto query language (KQL) to run device queries in Microsoft Intune, retrieving Windows device inventory data with prerequisites, an editor interface, and optional CSV exports.
Explore preparing and deploying applications with Microsoft Intune Admin Center, configuring Office policies, using the Office Deployment Tool and Office customization tool, and covering app protection and configuration policies.
Learn to prepare and package applications for deployment with Microsoft Intune, including metadata, detection rules, dependencies, and supersedes, using Win32 content prep tool to create Intune win packages for deployment.
Deploy apps using Microsoft Intune across managed devices using role-based access, targeting, and policy-driven delivery to maintain software consistency and security.
Demonstrates deploying apps in Microsoft Intune via the Intune Admin Center, including selecting app type, channel, language, assigning groups, and reviewing, creating, and monitoring install status.
Learn to deploy Microsoft 365 apps to Windows devices with Intune, configure update channels, targeting options, and licensing, then monitor post-deployment app health and install status.
Demonstrates deploying Microsoft 365 apps with Intune by configuring app type, update channels, licensing, group targeting, and monitoring installation status.
Learn to configure Office app policies with Intune and the Microsoft 365 app Admin Center, covering policy scope, deployment options, and monitoring policy behavior.
Demonstrates configuring policies for Microsoft 365 apps in the Intune Admin Center and the Microsoft 365 Apps Admin Center, including creating, scoping to groups, and publishing.
Deploy Microsoft 365 apps with the office deployment and configuration tools to generate a configuration xml for silent installations. Configure architecture, update channels, languages, and licensing via gui and cli.
Learn to use the Office Deployment Tool and the Office Configuration Tool to generate XML configuration files and deploy Microsoft 365 with customized settings.
Explore the Microsoft 365 Apps Admin Center to manage deployments, track app inventory, control security updates and servicing, monitor app health and OneDrive sync health, and apply cloud policy settings.
Explore the Microsoft 365 Apps Admin Center to monitor cloud updates, app health, and service health, and configure policies, device configurations, and deployment inventory.
Learn to deploy platform-specific apps with Microsoft Intune to the Microsoft Store, Apple App Store, and Google Play, using store app type, assignments, and automatic updates.
Learn to deploy apps to platform-specific stores in Microsoft Intune by selecting the app type, choosing the relevant store (Android, iOS, or Microsoft Store), and assigning groups.
Explore app protection policies in Intune that secure corporate data within apps like Outlook, Word, Excel, and Teams on managed or BYOD devices.
Demonstrates implementing app protection policies in the Intune admin center, configuring data loss prevention controls, app and device conditions, and assigning policies to groups with troubleshooting insights.
Explore how conditional access integrates with Intune app protection policies to protect corporate data across apps and devices, covering policy settings, scenarios, and safe rollout best practices.
Learn to create conditional access policies for app protection in Microsoft Intune and the Entra admin center, targeting users and resources, with pilot testing and report-only mode.
Explore planning and implementing app configuration policies with Intune, covering MDM and MAM channels, key-value settings, platform scope, and targeted assignments for managed devices or apps.
Learn to deploy app configuration policies in Microsoft Intune by creating configurations for managed devices, selecting platform types (Android or iOS/iPadOS), and configuring corporate, BYOD, and personally owned work profiles.
Explore antivirus, disk encryption, firewall, and ASR policies, security baselines, and Defender for Endpoint integration with Intune, plus onboarding, update management across Windows, iOS, iPadOS, macOS, and Android, and monitoring.
Learn to create and manage antivirus policies in Microsoft Intune, configure Microsoft Defender Antivirus settings across Windows 10/11 endpoints, and monitor status, exclusions, and reporting from endpoint security.
Create and deploy endpoint antivirus policies in Microsoft Intune by configuring Microsoft Defender Antivirus settings, adding exclusions, and using assignment filters to target devices, then review policy status.
Create disk encryption policies in Microsoft Intune, configuring BitLocker on Windows and personal data encryption; for Mac use FileVault, and monitor with encryption reports and recovery keys.
Create and deploy disk encryption policies in Microsoft Intune, selecting BitLocker for Windows, configuring encryption level, startup authentication options, and assigning policies to groups.
Create and manage firewall policies in Microsoft Intune for Windows and macOS, centralizing Windows Defender Firewall and macOS firewall configurations within endpoint security, with monitoring, reporting, and RBAC controls.
Demonstrates creating endpoint firewall policies in Microsoft Intune using the Intune Admin Center and Windows Firewall. Assign policies to Microsoft Entra Groups and review status in the firewall policies view.
Learn to create and customize attack surface reduction policies in Microsoft Intune, including choosing a profile type, setting block or audit, exclusions, and assignments.
Explore configuring attack surface reduction policies in Microsoft Intune, covering ASR rules, modes, device control, app isolation, exploit protections, and monitoring, with a walkthrough of policy creation and assignments.
Explore planning and implementing security baselines in Microsoft Intune, including baseline profiles, versions, and configuration service providers, with conflict handling, monitoring, and creation through endpoint security.
Learn to create and deploy security baselines in Microsoft Intune, configuring template settings, applying scope tags, assigning groups, and reviewing device and user status.
Integrate Microsoft Intune with Defender for Endpoint to onboard devices, enforce risk-based compliance and conditional access, and monitor security across Windows, macOS, Linux, Android, and iOS.
Demonstrates integrating Microsoft Intune with Microsoft Defender for Endpoint, detailing prerequisites, licensing, and configuring the connector and platform status for Android and iOS endpoints.
Onboard devices into Microsoft Defender for Endpoint to enable real-time telemetry, threat detection, and automated response across Windows, macOS, Linux, Android, and iOS, using Intune or Group Policy.
Onboard devices into Microsoft Defender for Endpoint by using the admin portal to select Windows 10/11 and run the onboarding script, then verify with a device detection test.
Plan and manage device updates with Intune's Windows Update for Business policies, using update rings to schedule feature, quality, and driver updates, test groups, deferrals, and restart timings.
Learn to create and manage update rings in Microsoft Intune to control Windows update behavior, deferrals, restarts, and driver updates, across Windows 10 version 1607 and later.
Create and deploy update ring policies in the Intune admin center to control Windows updates, configure update settings, and assign policies to East US devices.
Create and manage update policies in Microsoft Intune for iOS, iPadOS, and macOS, using declarative device management, update types, installation behavior, settings catalog, and ongoing monitoring and reporting.
Demonstrates creating update policies in Microsoft Intune for iOS, iPadOS, and macOS, showing how to configure update rings, schedules, and assignments in the Intune admin center.
Explore how to manage Android updates with Intune configuration profiles, using system update settings, firmware over-the-air deployments, and vendor options like Zebra Lifeguard and Samsung Enterprise.
Configure Windows client delivery optimization in Intune to download updates from Microsoft or peers, with settings like download mode, group IDs, and cache server for efficient updates.
The instructor thanks students, emphasizes four modules, and points to resources such as slides, lesson notes, live demonstrations, and useful URLs to help you succeed on the exam.
Are you ready to become a certified Microsoft 365 Endpoint Administrator Associate (MD-102) and take your IT career to the next level? This in-depth Microsoft MD-102 training course is designed to fully prepare you for the official Microsoft 365 Endpoint Administrator certification exam while giving you the practical, hands-on skills you need to succeed in real-world enterprise environments.
As organizations move rapidly to the cloud, the role of the Endpoint Administrator has become critical. Employers need IT professionals who can manage, deploy, secure, and troubleshoot devices across Microsoft 365 environments using Intune, Microsoft Entra ID (formerly Azure AD), Autopilot, and modern endpoint security practices. Whether you are an IT support specialist, systems administrator, or aspiring endpoint administrator, this course gives you the knowledge and confidence to pass the exam and apply these skills immediately on the job.
What You’ll Learn
Through detailed lessons, live demonstrations, and downloadable resources, you’ll gain complete coverage of the four exam domains for MD-102:
Prepare Your Infrastructure for Devices
Configure Microsoft Entra ID device join and registration (cloud, hybrid, BYOD)
Set up automatic enrollment for Windows, iOS, Android, and macOS devices
Implement compliance policies, conditional access, and role-based access control
Integrate Windows Hello for Business and Local Administrator Password Solution (LAPS)
Manage and Maintain Devices
Deploy and configure devices with Windows Autopilot
Create and apply device configuration profiles across Windows, macOS, iOS, and Android
Manage multi-session devices and perform lifecycle management
Hands-on demonstrations of Intune device enrollment and policy application
Manage Applications
Deploy and maintain Microsoft 365 Apps and third-party applications
Configure application protection and app configuration policies
Control application access with conditional access and Intune app management
Demonstrations of app deployment and update management strategies
Protect Devices
Configure endpoint security settings: antivirus, firewall, disk encryption, and attack surface reduction
Implement and manage security baselines across all platforms
Manage OS and application updates through Microsoft Intune
Optimize delivery with Windows Update for Business and Delivery Optimization
Why Take This Course?
Exam-Focused & Practical – Every lesson is mapped to the MD-102 exam objectives, with live demos and real-world best practices.
Comprehensive Resources – Includes downloadable slides, learner notes, step-by-step guides, and links to official Microsoft documentation for deeper study.
Expert Instruction – Taught by an experienced technical trainer with 15+ years of IT training and course development experience.
Boost Your Career – The Microsoft 365 Endpoint Administrator Associate certification is highly in demand, validating your expertise in device management and endpoint security.
Who This Course Is For
IT professionals preparing for the Microsoft MD-102 exam
Endpoint administrators and desktop support engineers transitioning to cloud-based management with Intune
System administrators looking to deepen their Microsoft 365 expertise
Beginners seeking a structured path to becoming a Microsoft Certified Endpoint Administrator Associate