
This course is designed to fully prepare you for the MD-102 (Microsoft 365 Certified: Endpoint Administrator Associate) exam. It goes beyond just theory, providing the practical skills needed to manage, deploy, and secure modern endpoints in a corporate environment.
What You Will Learn:
Comprehensive Exam Coverage: A complete, detailed breakdown of all MD-102 exam objectives so you know exactly what to study.
Hands-On Experience: Practical labs using Microsoft Intune and Endpoint Manager to bridge the gap between textbook concepts and real-world execution.
Modern Device Management: Step-by-step guidance on Windows 11 provisioning, Azure AD Join, and enforcing Conditional Access.
Security & Compliance: Training on real-world device deployment, configuring compliance policies, managing app deployments, and utilizing remote management tools.
Key Takeaway
By the end of this course, you will not only understand the core objectives of the MD-102 exam, but you will also possess the hands-on expertise to confidently deploy, manage, and protect enterprise devices in a real-world setting.
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft’s cloud-based identity and access management (IAM) service. It serves as the central control plane for verifying user identities and controlling access to corporate applications and resources, making it a foundational pillar of modern, Zero-Trust security.
Key Highlights:
Core Purpose: Manages user identities, authentication, and secure access across cloud and hybrid environments, moving organizations away from traditional, on-premises perimeter security.
Essential Capabilities:
User Authentication & MFA: Enforces multi-factor authentication and self-service password management to protect credentials against unauthorized access.
Access Control: Uses Conditional Access policies to evaluate real-time signals (user, location, device risk) before granting resource access.
Alignment with MD-102: Entra ID is crucial for the MD-102 exam because cloud-based endpoint management relies directly on cloud identities. Key exam scenarios include joining devices (Entra Join / Hybrid Join), registering endpoints, and enforcing Conditional Access compliance policies.
Real-World Application: Powers seamless Single Sign-On (SSO) across enterprise apps, automates user onboarding/offboarding, and ensures only healthy, compliant devices can access company data.
This module covers the core concepts of identity management, access control, and hybrid synchronization within Microsoft Entra ID—essential skills for both real-world administration and the MD-102 exam.
Key Topics Breakdown
1. Role-Based Access Control (RBAC) & Delegation
Access Control: Explains RBAC principles and compares built-in Entra roles (e.g., Global Administrator) with custom roles to enforce the principle of least privilege.
Delegation & Groups: Demonstrates how to delegate administrative tasks safely and streamline permissions using group-based access assignments.
2. User & Group Management
User Types: Distinguishes between Member and Guest accounts, covering internal vs. external user workflows.
Identity Sources: Differentiates between Cloud-only and Synced identities.
Group Types & Membership: Details Security, M365, and Distribution groups, alongside Assigned vs. Dynamic membership rules (including device-based dynamic targeting).
Automation: Highlights PowerShell commands for managing user and group identities efficiently at scale.
3. Hybrid Identity & Synchronization
Entra ID Connect: Explores hybrid setups linking on-premises Active Directory to the cloud, discussing Single Sign-On (SSO), Password Hash Sync (PHS), and Federation options.
Limitations & Cloud Sync: Addresses on-prem group sync constraints and introduces Entra Cloud Sync as the lightweight, modern evolution for hybrid identity management.
Hands-on Lab: Includes a practical walkthrough of setting up and managing identity synchronization via Entra Connect.
This module provides a step-by-step practical demonstration of creating users and groups, configuring administrative roles, and managing Microsoft 365 licensing using both the Entra ID Admin Center and Microsoft Graph PowerShell.
Key Walkthrough Steps
1. User Creation & Attribute Configuration
GUI Creation: Manually creates individual users within the tenant and populates core user attributes (Name, Department, Location, and Job Title).
PowerShell Automation: Demonstrates installing the Microsoft.Graph module, authenticating with Connect-MgGraph, creating users via command line, and verifying accounts using Get-MgUser.
2. Role Assignment & Governance
Assigns specialized administrative privileges, including assigning the Help Desk Administrator role to a user.
Demonstrates Privileged Identity Management (PIM) concepts by configuring Eligible vs. Active role assignments (e.g., activating a Global Administrator role).
3. Group Management
GUI Setup: Creates a security group (Contoso Managers) and assigns user accounts.
PowerShell Setup: Demonstrates creating security groups (Contoso Sales) and managing group memberships via PowerShell commands.
4. License Allocation
Individual Licensing: Checks available tenant licenses and assigns Enterprise Mobility + Security (EMS) and M365 licenses to individual users via the M365 Admin Center.
Group-Based Licensing: Configures group-based license assignments (Contoso Managers) to streamline automated provisioning and verifies license inheritance across users.
This module covers identity security and access management within Microsoft Entra ID, focusing on passwordless deployment via Windows Hello for Business, automated risk detection through Microsoft Entra ID Protection, and self-service account management.
Key Topics Breakdown
1. Windows Hello for Business & Passwordless Authentication
Authentication Factors: Replaces traditional passwords with strong two-factor authentication tied directly to the physical endpoint (a asymmetric public/private key pair bound to the device's TPM chip + a local gesture like biometrics or PIN).
Supported Protocols: Full support for FIDO2 security keys, biometric sign-in (facial recognition/fingerprint), and PIN fallbacks.
Deployment Models: Evaluates Cloud-only, Hybrid (Cloud Kerberos Trust, Key Trust, Certificate Trust), and On-premises deployment topologies.
Management Options: Configured and managed across enterprise environments using Microsoft Intune (via CSPs), Active Directory Group Policy Objects (GPOs), or PKI certificates.
2. Microsoft Entra ID Protection & Risk Detection
Machine Learning Detection: Continuously evaluates behavioral signals and threat intelligence across trillions of daily events to calculate real-time Sign-in Risk and User Risk levels (Low, Medium, High).
Risk Indicators: Detects suspicious behaviors such as anonymous IP addresses, atypical locations, password spray attempts, and leaked credentials.
Automated Remediation: Feeds risk scores directly into Conditional Access policies to trigger automated responses (e.g., enforcing MFA for risky sign-ins or forcing a secure password reset for risky users).
3. Self-Service Password Reset (SSPR) & MFA Methods
Self-Service Capabilities: Enables users to securely unlock accounts and reset passwords without helpdesk intervention.
Password Writeback: Synchronizes password changes performed in the cloud back to on-premises Active Directory in real-time via the Entra Connect / Cloud Sync agent.
Multi-Factor Authentication (MFA): Explores licensing tiers and authentication methods (Microsoft Authenticator app, hardware tokens, FIDO2 keys, SMS/voice)
This module covers the core principles of cloud-based device authentication, specifically focusing on Microsoft Entra Join. It outlines how organizations transition from traditional Active Directory setups to modern, cloud-first endpoint management.
Key Topics Breakdown
1. What is Microsoft Entra Join?
Definition & Scenarios: Explores how devices join directly to Microsoft Entra ID without needing an on-premises Active Directory domain controller.
Supported Devices: Works across Windows Pro, Enterprise, and Education editions.
Benefits: Delivers Single Sign-On (SSO) to cloud and hybrid resources, self-service password resets, enterprise state roaming, and passwordless authentication options.
2. Entra ID vs. Traditional Active Directory
Management Shift: Replaces local Active Directory Group Policy Objects (GPOs) with cloud-based Mobile Device Management (MDM) solutions like Microsoft Intune.
Cloud vs. Hybrid: Compares cloud-only Entra Join with Hybrid Entra Join (for environments that still rely on legacy on-premises Active Directory infrastructure).
Use Cases: Ideal for cloud-first organizations, remote/mobile workforces, and branch offices without local domain controllers.
3. Execution & Device Management
Joining Methods: How users join devices during Out-of-Box Experience (OOBE) setup or manually via Windows System Settings.
Prerequisites & Roles: Setting up enrollment agents and defining appropriate device registration settings in the tenant.
Intune Auto-Enrollment: Configures seamless automatic enrollment into Intune upon joining Entra ID to instantly apply compliance policies and security controls.
This module covers the end-to-end device management lifecycle using Microsoft Intune. It details multi-platform enrollment methods across Windows, Android, and Apple ecosystems, as well as remote administration and device compliance strategies.
Key Topics Breakdown
1. Intune Setup & Device Eligibility
Platform Support: Manages Windows, macOS, iOS/iPadOS, and Android operating systems.
Prerequisites: Configuring CNAME records for auto-enrollment, establishing corporate enrollment policies, and setting up the MDM Authority.
2. Cross-Platform Enrollment Strategies
Windows:
BYOD: Manual Work/School account connection or MDM-only enrollment.
Corporate / New Devices: Direct Entra Join via Out-of-Box Experience (OOBE) or Windows Autopilot (User-Driven and Self-Deploying modes for kiosks/shared devices).
Hybrid / Enterprise: Co-management with MECM (ConfigMgr + Intune) and bulk enrollment via Windows Configuration Designer (WCD).
Android:
BYOD: Company Portal app and Android Work Profile (keeps personal/work data isolated).
Corporate: Android Enterprise Fully Managed or Dedicated (kiosk/POS) modes.
iOS / macOS:
Corporate: Automated Device Enrollment via Apple Business Manager / Apple School Manager.
Manual / Staging: Apple Configurator (Setup Assistant or Direct Enrollment) and Supervised Mode for deep restriction policies.
Bulk Enrollment Role: Highlights the Device Enrollment Manager (DEM) permission scope for staging large batches of corporate endpoints.
3. Data Protection & Remote Management
Data Safeguards: Utilizes Mobile Application Management (MAM) policies and data loss prevention safeguards to separate and encrypt corporate data without compromising personal privacy.
Remote Actions Scope:
Retire: Removes corporate data and managed apps while leaving personal data intact.
Wipe: Executes a full factory reset for lost/stolen corporate devices.
Delete: Unenrolls the device from Intune without erasing local device data.
Administrative Actions: Remote lock, PIN reset, device restart, policy sync, and initiating Defender quick/full scans.
This demonstration walks through the step-by-step process of registering a personal or workgroup Windows device with Microsoft Entra ID (BYOD scenario), verifying its state locally and in the cloud, and properly disconnecting it.
Key Demo Breakdown
1. Registration Process (BYOD Scenario)
Prerequisite: Tenant device settings must be configured to permit user-driven device registration.
Platform Scope: Designed for personal or unmanaged endpoints across Windows, Android, and iOS.
User Workflow: Navigates to Settings > Accounts > Access work or school, adds corporate credentials, and links the account without fully joining the device to the organization domain.
2. Local & Cloud Verification
Local Command Check: Uses the command-line tool dsregcmd /status in PowerShell to confirm device state. The output confirms the device is Workplace Joined (AzureAdJoined : NO, WorkplaceJoined : YES).
Attributes Inspected: Identifies key parameters including Workplace Join ID, TPM status, device certificate, and target Tenant ID.
Entra Portal Check: Verifies that the endpoint appears in the Microsoft Entra Admin Center with the join type explicitly listed as Microsoft Entra registered.
3. Unregistration & Clean Revocation
Disconnect Workflow: Removes the corporate connection directly via Settings > Accounts > Access work or school > Disconnect.
Impact & Verification: Instantly revokes corporate app and resource access without requiring a system reboot. Running dsregcmd /status confirms the Workplace Join state has returned to No.
This demonstration walks through performing a full Microsoft Entra Join on a Windows machine, triggering automatic Mobile Device Management (MDM) enrollment into Microsoft Intune, and validating the joint status locally and across cloud admin portals.
Key Demo Steps Breakdown
1. Device Joining & Intune Auto-Enrollment
Join Initiation: Connects the machine directly to Microsoft Entra ID using corporate credentials via Settings > Accounts > Access work or school > Join this device to Microsoft Entra ID.
MDM Auto-Enrollment: Triggers automatic enrollment into Microsoft Intune upon completing the authentication process.
Policy Sync & Certificates: Initiates a manual device sync to pull down baseline organization policies and validates device trust by inspecting local client certificates.
2. Local & Portal Verification
PowerShell Validation: Runs dsregcmd /status locally to verify the explicit join state. Look for AzureAdJoined : YES under the Device State output.
Work Account Sign-In: Authenticates onto the Windows lock screen using the newly joined corporate Entra ID user account.
Intune Admin Center Check: Confirms the endpoint appears in the Intune portal with an active management state, compliance status, and assigned profiles.
Entra Admin Center Check: Validates the device record in the Microsoft Entra Admin Center, confirming the Join Type is listed as Microsoft Entra joined (rather than Registered).
This demonstration covers the end-to-end setup for Hybrid Entra Join (formerly Hybrid Azure AD Join), bridging an on-premises Active Directory Domain Services (AD DS) environment with Microsoft Entra ID using Microsoft Entra Connect.
Key Demo Breakdown
1. On-Premises Active Directory & Sync Scope Setup
OU Staging: Prepares the targeted Organizational Unit (OU) in Active Directory and moves the destination machine object into it.
Sync Configuration: Launches Entra Connect to adjust sync filtering, ensuring the specific OU containing the target device object is included in the sync scope.
Force Sync: Triggers an immediate delta synchronization using PowerShell (Start-ADSyncSyncCycle -PolicyType Delta) to push the local computer object to the cloud.
2. Entra Connect Hybrid Join & SCP Configuration
Device Options: Reconfigures Entra Connect wizard settings to enable Configure Hybrid Azure AD join.
SCP Setup: Configures the Service Connection Point (SCP) in the on-premises Active Directory forest, providing client machines with the tenant ID and domain information required to discover their target Entra ID tenant.
3. Execution & Verification
Finalize Setup: Completes the Entra Connect wizard and restarts the client endpoint to apply Group Policy updates and trigger auto-enrollment.
Dual Validation:
Sync Service Manager: Confirms successful object export/import status in the Entra Connect Sync Service.
Entra Portal: Validates that the device record appears in the Entra Admin Center with the Join Type specified as Hybrid Microsoft Entra joined.
This walkthrough demonstrates how to configure the prerequisite Apple MDM Push Certificate in Microsoft Intune and execute user-driven enrollment on an iPad using the Intune Company Portal app.
Key Demo Steps Breakdown
1. Tenant Setup: Apple MDM Push Certificate
Prerequisites Check: Ensures licensing and tenant configuration permit iOS/iPadOS device enrollment.
Certificate Request: Generates an MDM Certificate Signing Request (CSR) in Intune and requests a signed certificate from the Apple Push Certificates Portal using an Apple ID.
Intune Binding: Uploads the .pem push certificate back into Intune, establishing trust between Intune and Apple Push Notification service (APNs).
2. On-Device Enrollment (iPadOS)
Company Portal App: Installs the Microsoft Intune Company Portal from the Apple App Store and authenticates with corporate work/school credentials.
Management Profile Download: Downloads the secure iOS/iPadOS management profile to the local device.
Profile Installation & Trust: Navigates to Settings > Profile Downloaded, installs the management profile, and trusts the management root certificate to grant Intune enrollment rights.
3. End-to-End Verification
Company Portal App: Confirms the device status changes to In Compliance and Managed.
Entra Admin Center Check: Verifies the device object appears in Microsoft Entra ID with its registered user.
Intune Admin Center Check: Confirms the iPad appears in Intune under Devices > iOS/iPadOS with active management, ownership details, and compliance state.
This module explores how to create, configure, and target Device Configuration Profiles in Microsoft Intune to enforce security settings, device features, and compliance across various operating systems.
Key Topics Breakdown
1. Device Profile Types & Platform Settings
Purpose: Uses configuration profiles to standardize security controls (e.g., Wi-Fi, VPN, email settings, camera restrictions, and device lock rules) across corporate and BYOD devices.
Platform Specifics: Covers how profile templates and setting catalogs adapt to specific operating systems, including Windows, Android, iOS/iPadOS, and macOS.
2. Assignment Scope & Applicability Rules
Targeting Groups: Assigns profiles to specific Entra ID user or device groups (including dynamic groups).
Applicability Rules: Evaluates granular parameters (such as OS edition or version) so settings only apply to eligible endpoints within a targeted group.
3. Custom Profile Creation Walkthrough
Building Profiles: Demonstrates the step-by-step workflow: entering basic details, selecting platform/profile type, configuring settings, applying scope tags, and validating assignments before deployment.
Custom Profiles: Explores advanced custom OMA-URI (Open Mobile Alliance Uniform Resource Identifier) settings for Windows and administrative templates for non-Windows platforms.
Deploy OMA-URIs to target a CSP through Intune, and a comparison to on-premises
https://learn.microsoft.com/en-us/troubleshoot/mem/intune/device-configuration/deploy-oma-uris-to-target-csp-via-intune
This module covers essential post-deployment management tasks in Microsoft Intune, focusing on monitoring profile deployment status, triggering device synchronizations, and executing custom administrative scripts across Windows and macOS endpoints.
Key Topics Breakdown
1. Monitoring Device Profiles & Assignments
Status Tracking: Evaluates deployment success, pending states, and errors across assigned users and devices using Intune monitoring dashboards.
Conflict Resolution: Identifies and resolves policy conflicts when two overlapping configuration profiles apply contradictory settings to the same endpoint.
2. Managing Device Sync & Policy Refresh
Deployment Cycles: Outlines how Intune schedules automatic policy sync triggers for active endpoints.
Manual Sync Methods: Demonstrates how to force an immediate policy refresh remotely via the Intune Admin Center or locally on the client machine (Settings > Accounts > Access work or school > Sync).
3. Managing Endpoints with Custom Scripts
Cross-Platform Scripting: Deploys PowerShell scripts for Windows devices and Shell (.sh) scripts for macOS endpoints to execute tasks beyond native Intune settings.
Execution Context & Security: Configures script assignments by specifying execution context (User vs. System context), signature checking, and 64-bit PowerShell host enforcement.
This demonstration provides an end-to-end walkthrough of building a custom Windows device profile using Intune templates, targeting it via dynamic device groups, applying settings on a client endpoint, and testing live policy updates.
Key Demo Breakdown
1. Baseline Assessment & Profile Creation
Pre-Check: Reviews existing baseline settings on the target Windows machine (Gaming settings, Start menu layout, Windows Security state).
Profile Setup: Opens the Intune Admin Center to create a new profile using Windows templates, configuring explicit device restrictions:
Restrictions: Disables Gaming features, restricts Control Panel applets, and locks down Privacy settings.
Customization: Enforces Start menu layouts and custom branding/personalization.
Antivirus: Adds specific path/process exclusions to Microsoft Defender Antivirus.
2. Dynamic Group Assignment & Sync Execution
Dynamic Group Setup: Builds a dynamic Entra ID device group (Contoso Developer Devices) using rules to automatically capture targeted Windows endpoints (deviceOSType -eq "Windows").
Assignment & Execution: Finalizes the profile configuration and assigns it directly to the dynamic group.
Client Synchronization: Triggers a manual sync on the client machine via Settings > Access work or school to pull and apply the newly assigned profile.
3. Verification & Live Modification Loop
Initial Validation: Confirms restricted settings on the client—Gaming options are hidden and Defender exclusions are actively applied.
Policy Modification: Updates the profile in Intune by removing the Privacy restriction.
Remote Sync & Re-Validation: Forces a remote device sync from the Intune portal and verifies on the client endpoint that the Privacy settings menu is immediately restored.
This demonstration walks through configuring a dedicated Windows device (Seattle Workstation 2) to run as a restricted, single-app kiosk displaying Microsoft Edge in full-screen mode with automatic logon.
Key Demo Breakdown
1. Device Staging & Group Assignment
Enrollment & Sync: Completes Microsoft Entra Join and Intune enrollment for the target endpoint, initiating an initial policy sync.
Group Management: Creates an Entra ID security group (Koso Kiosk Devices) and populates it with the specific machine object (Seattle Workstation 2).
2. Kiosk Profile Configuration
Template Selection: Creates a new Configuration Profile in Intune using the Kiosk template for Windows 10 and later.
Logon & App Settings: Configures Single-app kiosk mode with Auto logon (enabling the endpoint to launch directly into the application upon boot without prompting for user credentials).
Browser Customization: Specifies Microsoft Edge as the designated kiosk application, locking the starting URL to Bing and setting idle timeout refresh rules.
Assignment: Finalizes and assigns the profile to the Koso Kiosk Devices group.
3. Execution & Client-Side Verification
Sync & Reboot: Forces a manual device sync on Seattle Workstation 2 to pull down the kiosk policy, then reboots the machine.
Validation: The endpoint automatically boots into Windows, logs in with the built-in local kiosk account, and immediately launches Microsoft Edge locked in full-screen mode.
This demonstration walks through creating a static device security group for Apple endpoints and configuring a standardized Wi-Fi Configuration Profile in Microsoft Intune to automate corporate wireless connections.
Key Demo Breakdown
1. Group Creation & Device Targeting
Device Identification: Locates the enrolled targeted iPad endpoint within the Intune Admin Center.
Security Group Creation: Creates a static security group named iOS iPad OS Devices and manually assigns the target iPad to the group.
2. Wi-Fi Profile Creation & Configuration
Policy Setup: Navigates to Devices > Configuration in Intune and selects iOS/iPadOS as the target platform.
Template Selection: Chooses the Wi-Fi profile template to build custom connection rules.
Network Settings: Configures baseline connection properties:
Network Name & SSID: Specifies the broadcast network identifier.
Auto-Connect: Enables automatic network joining when the device is in range.
Security Type: Configures WPA/WPA2-Personal authentication along with the pre-shared key.
3. Assignment & Profile Finalization
Targeting: Assigns the newly created Wi-Fi configuration profile directly to the iOS iPad OS Devices security group.
Finalization: Reviews and completes profile creation to deploy wireless settings seamlessly to enrolled iPads.
This demonstration walks through exporting an on-premises Active Directory Group Policy Object (GPO) as an XML report and importing it into Microsoft Intune’s Group Policy Analytics tool to evaluate MDM compatibility and plan cloud policy migration.
Key Demo Breakdown
1. GPO Export (On-Premises AD)
GPMC Export: Opens the Group Policy Management Console (gpmc.msc) on the domain controller (contoso.com).
XML Generation: Selects the target GPO (Windows Client Policy), generates a detailed GPO report, and saves it locally as an .xml file.
2. Import & Policy Analysis in Intune
Analytics Import: Opens the Microsoft Intune Admin Center, navigates to Devices > Group Policy Analytics, and uploads the exported GPO XML file.
MDM Support Scoring: Evaluates the imported policy settings against modern cloud capabilities. In this demo, the GPO achieves an 89% MDM support score, showing which settings directly map to Intune policies.
Handling Unsupported Settings: Discusses alternative strategies for the remaining 11% unsupported GPO settings (e.g., using custom PowerShell/Shell scripts, custom OMA-URI Configuration Service Providers (CSPs), or Microsoft Endpoint Configuration Manager).
3. Migration Readiness Reporting
Readiness Report: Navigates to Reports > Group Policy Analytics > Migration readiness to filter by profile types and targeted CSPs.
Exporting Results: Generates and exports a comprehensive migration readiness report mapping GPO settings to their corresponding Intune Configuration Service Providers (CSPs) to streamline cloud transition planning.
This demonstration walks through using the Microsoft Intune Admin Center to audit user sign-in activity, inspect detailed device hardware inventory via Resource Explorer, and leverage telemetry data for troubleshooting and security investigations.
Key Demo Breakdown
1. User Sign-In & Audit Log Analysis
Navigation & Filters: Accesses the Users blade in the Intune Admin Center to review user audit logs and sign-in events, applying custom filters for specific users and date ranges.
Telemetry Insights: Evaluates granular sign-in details, including authentication timestamps, client IP addresses, geo-locations, operating system/browser types, and authentication methods.
Security & SIEM Integration: Verifies whether Conditional Access policies were triggered during authentication and highlights how these logs can be streamed to Security Information and Event Management (SIEM) tools like Microsoft Sentinel.
2. Device Inventory & Resource Explorer
Hardware & System Data: Navigates to a targeted endpoint (Seattle Workstation 1) and opens Resource Explorer to inspect detailed hardware specifications (OS version, BIOS details, CPU, and disk drives)—replacing legacy tools like SCCM/MECM.
Policy & State Monitoring: Reviews assigned configuration profiles, current logged-in user details, installed applications, system diagnostics, and local administrative privileges.
Practical Utility: Demonstrates how combining user log data with device-level inventory accelerates root-cause analysis during IT troubleshooting and security breach investigations.
This module explains how to secure corporate data at the application layer using Microsoft Intune MAM without requiring full device enrollment (MDM). It is ideal for Bring Your Own Device (BYOD) scenarios and third-party Enterprise Mobility Management (EMM) environments.
Key Topics Breakdown
1. Core MAM Principles & Benefits
MAM vs. MDM: MDM manages the whole device (hardware, settings, full remote wipe), while MAM manages only specific applications and encrypts corporate data within those apps.
Multi-Identity Support: Allows personal and corporate accounts to coexist within the same app (e.g., Outlook) while enforcing policies strictly on corporate data.
Data Loss Prevention (DLP): Prevents actions like copy-pasting corporate data into unmanaged apps, saving attachments to personal cloud storage, or taking screenshots.
MD-102 Note: Windows Information Protection (WIP) has been deprecated by Microsoft in favor of Microsoft Purview Data Loss Prevention (DLP) and Information Protection. App Protection Policies in Intune focus primarily on iOS/iPadOS and Android.
2. App Wrapping Tool vs. Intune App SDK
Intune App Wrapping Tool: Modifies compiled binaries (iOS .ipa / Android .apk) without touching source code. Used for quick deployment of legacy or internal line-of-business (LOB) apps.
Intune App SDK: Developers embed code directly into the app during source code development. Provides granular control, custom telemetry, and seamless integration with Intune policies.
This module explores the application lifecycle across hybrid and cloud enterprise environments, contrasting deployment mechanisms across Microsoft Intune, Microsoft Endpoint Configuration Manager (MECM), Group Policy (GPO), and the Microsoft Store app experience.
Key Topics Breakdown
1. Application Lifecycle & Deployment Platforms
Intune App Lifecycle: Covers the full lifecycle from acquisition, packaging, and assignment to updating, monitoring, and eventual retirement.
MECM (SCCM) Deployment Architecture:
Applications vs. Packages: Applications utilize state-based deployment with built-in detection rules, dependencies, and supersedence; Packages use traditional script-based execution.
Advanced Rules: Leverages Global Conditions to evaluate prerequisites, app groups for bundled installs, and revision tracking.
Targeting & Intent: Configures deployment purpose (Required vs. Available) across targeted collection scopes.
Group Policy (GPO) Software Deployment:
Assigned: Installs automatically at computer boot (machine target) or user sign-in (user target).
Published: Made available in Control Panel > Programs and Features for optional user installation (user target only).
2. Modern Microsoft Store & WinGet Integration
Store for Business Retirement: Details the deprecation of the legacy Microsoft Store for Business/Education in favor of the integrated Microsoft Store app (new) experience built on the Windows Package Manager (WinGet).
Supported Store Frameworks: Direct deployment of Universal Windows Platform (UWP), Win32 (packaged as .exe/.msi), and Progressive Web Apps (PWAs).
Automatic Updates: Store-based applications receive seamless background updates directly from publisher sources.
3. Assignments, Enrolled vs. Non-Enrolled, & SDK Packaging
Intune App Packaging: Uses the Microsoft Win32 Content Prep Tool (.intunewin) for custom Win32 packaging, alongside the Intune App Wrapping Tool and Intune App SDK for Mobile Application Management (MAM).
Enrolled vs. Non-Enrolled Scenarios: Differentiates between full MDM application deployment (for managed, enrolled devices) and MAM / App Protection Policies (for unmanaged BYOD endpoints).
Assignment Scope & Rules: Explores deployment intent (Required, Available for enrolled devices, Uninstall) and platform-specific targeting constraints.
This module covers the core strategies for managing applications in Microsoft Intune across both managed (MDM-enrolled) and unmanaged (BYOD) endpoints, deploying Microsoft 365 Apps, and configuring backward compatibility via Microsoft Edge IE Mode.
Key Topics Breakdown
1. Managing Apps on Unenrolled Devices (MAM / BYOD)
App Protection Policies (APP): Secures corporate data inside managed apps without taking control of personal devices.
App Assignment & Updates: Deploys designated apps via the Intune Company Portal app or public app stores; updates flow automatically through store channels or MAM policies.
Managed vs. Unmanaged State: Isolates enterprise data from personal applications to prevent data leakage.
2. Deploying Microsoft 365 Apps via Intune
Centralized Deployment: Streamlines the deployment of Microsoft 365 Apps (Word, Excel, PowerPoint, Outlook, Teams) to Windows and macOS endpoints using built-in Intune suite templates.
Configuration Controls: Standardizes baseline installation choices, including architecture selection (32-bit vs. 64-bit), update channels, and auto-installation behavior.
3. Configuring Microsoft Edge Internet Explorer (IE) Mode
Legacy Web Compatibility: Utilizes IE Mode in Microsoft Edge to render legacy web applications that require ActiveX, Java, or legacy Trident rendering engines directly within Microsoft Edge.
Enterprise Mode Site List: Configures an XML-based site list (hosted on Azure Blob Storage or managed via Enterprise Mode Cloud Site List in the M365 Admin Center) to automatically open designated URLs in IE mode.
Policy Enforcement: Deploys site lists and Edge policies across managed devices using Intune Settings Catalog or on-premises Group Policy Objects (GPOs).
This demonstration walks through adding, configuring, and assigning a modern Microsoft Store application (Microsoft Remote Desktop) using the integrated WinGet repository in Microsoft Intune, and deploying it to targeted user groups.
Key Demo Steps Breakdown
1. App Selection & Metadata Configuration
App Type Selection: Navigates to Apps > All Apps in the Intune Admin Center and selects the Microsoft Store app (new) deployment type.
Store Search: Uses the built-in catalog search powered by Windows Package Manager (WinGet) to search for and select Microsoft Remote Desktop.
Metadata & Branding: Automatically populates core app information (publisher, description, install context) and sets custom properties, such as assigning a category and toggling the app as a Featured App in the Company Portal.
2. Assignment Strategies & Targeting
Assignment Types Explained:
Required: Automatically installs the application in the background without user interaction.
Available for enrolled devices: Publishes the app to the Company Portal app for optional self-service download by users.
Uninstall: Automatically removes the application if present on targeted endpoints.
Targeting: Selects and assigns the deployment to a designated user group (Research group).
3. Client Availability & Synchronization
User vs. Device Scope: Clarifies deployment behaviors when assigning to user groups versus device groups.
Company Portal Visibility: Confirms that assigning the application as Available immediately exposes it in the Company Portal app for members of the targeted group.
Manual Sync: Demonstrates triggering a manual policy sync to speed up application availability on client endpoints.
This demonstration walks through building a targeted App Protection Policy (APP / MAM) in Microsoft Intune to enforce Data Loss Prevention (DLP) controls and access restrictions specifically on the Microsoft Outlook app on iOS/iPadOS endpoints.
Key Demo Steps Breakdown
1. Policy Initiation & App Targeting
Policy Setup: Opens the Microsoft Intune Admin Center, navigates to Apps > App protection policies, and creates a new protection policy for the iOS/iPadOS platform.
App Scope: Names the policy and explicitly selects Microsoft Outlook as the targeted managed application.
2. Data Protection & Access Controls (DLP Settings)
Backup Restrictions: Configures data transfer rules to Block iCloud backup, preventing corporate email and attachment data from being synced to unmanaged personal cloud storage.
Data Transfer In/Out: Restricts both Send org data to other apps and Receive data from other apps to Managed apps only (ensuring corporate content remains isolated inside approved managed applications).
Encryption & PIN Enforcement: Enables Data Encryption for corporate app data and requires users to enter an app-level PIN when launching Outlook.
Multi-Identity Control: Blocks personal accounts within Outlook to isolate corporate data from personal email configurations.
3. Assignment & Finalization
Group Targeting: Assigns the policy to the target developer group (Koso Developers).
Policy Creation: Reviews settings and finalizes policy creation to immediately start protecting corporate Outlook data on enrolled and unmanaged (BYOD) iOS/iPadOS devices.
This module covers the concepts, architecture, and deployment strategies for enabling secure corporate resource access using Virtual Private Networks (VPNs), with a primary focus on Always On VPN as the modern replacement for legacy DirectAccess.
Key Topics Breakdown
1. VPN Fundamentals & Windows Remote Access Protocols
VPN Architecture: Differentiates between Point-to-Site (P2S) connections (individual endpoints connecting to the corporate network) and Site-to-Site (S2S) tunnels (connecting entire branch offices).
Remote Access Role: Windows Server features including Routing and Remote Access Service (RAS/RRAS), Web Application Proxy, and Gateway options.
Tunneling Protocols: Evaluates core protocols—L2TP/IPsec, SSTP (SSL/TLS over port 443), and IKEv2 (reconnection-resilient mobility protocol).
Windows VPN Platforms: Supports native OS client integration, Universal Windows Platform (UWP) apps, and Win32 VPN plug-ins.
2. DirectAccess vs. Always On VPN
Evolution: Always On VPN supersedes legacy DirectAccess, removing strict dependencies on domain-joined endpoints, specific Windows editions, and complex infrastructure requirements.
Device & Identity Flexibility: Works across Domain-joined, Entra ID-joined, and Workgroup/BYOD endpoints.
Deployment Tools: Configured and deployed via Microsoft Intune, MECM, or PowerShell (not legacy Group Policy Objects).
3. Infrastructure Requirements & Deployment
Prerequisites: Requires a Public Key Infrastructure (PKI) for issuing client/server certificates, Network Policy Server (NPS / RADIUS) for authorization, and Windows Server 2022+ Gateway roles.
Connection Tunnels:
Device Tunnel: Establishes connection before user sign-in to allow domain controller connectivity, password resets, and management updates.
User Tunnel: Establishes connection after user sign-in to grant access to internal corporate shares, applications, and web services.
This module covers native portal export capabilities, compliance monitoring dashboards, and advanced data integrations using the Intune Data Warehouse, Power BI, and the Microsoft Graph API to build custom reporting workflows.
Key Topics Breakdown
1. Native Portal Reporting & CSV Export
Enrolled Device Inventory: Extracts device attributes, ownership state, OS builds, and management states directly from the Intune Admin Center.
Quick Exports: Export portal views directly as .csv files for ad-hoc analysis, sharing, or offline audit recordkeeping.
2. Compliance Monitoring & Historical Analytics
Compliance Reporting: Evaluates real-time compliance states across endpoints against configured compliance policies (e.g., BitLocker encryption, OS version baselines, defender state).
Intune Data Warehouse: Maintains up to 14 days of historical Intune data (refreshed daily) via an OData feed to track enrollment trends and compliance posture over time.
Power BI Integration: Connects the Intune Data Warehouse directly to Power BI Desktop or the Power BI Web App using the OData feed to build interactive dashboards and executive-level visual reports.
3. Automation with Microsoft Graph API
Graph API Architecture: Provides a RESTful, scalable endpoint ([https://graph.microsoft.com/v1.0/deviceManagement](https://graph.microsoft.com/v1.0/deviceManagement)) to programmatically query endpoint data, compliance flags, and application inventory.
Key Use Cases: Automates custom reporting pipelines, streams telemetry to external SIEM/analytics tools, and powers cross-platform administrative workflows.
This module details how to enforce a Zero Trust security posture by combining Microsoft Intune Device Compliance Policies with Microsoft Entra ID Conditional Access. It covers defining health baselines, configuring threat detection, and gating enterprise access based on verified device trust.
Key Topics Breakdown
1. Device Compliance Policy Architecture
Core Enforcement Rules: Defines health and security requirements endpoints must satisfy to be deemed "Compliant", including:
System Security: Password/PIN complexity, disk encryption (BitLocker/FileVault), active firewall, and minimum OS/build versions.
Integrity & Risk: Jailbreak/root detection, Secure Boot verification, and Mobile Threat Defense (MTD) level thresholds.
Prerequisites: Requires supported OS platforms, user licensing (Entra ID P1 + Intune Plan 1), and successful MDM device enrollment.
Non-Compliance Actions: Configures automated, scheduled sequences when a device drifts out of compliance (e.g., immediate notification emails, marking device non-compliant, or remotely locking/retiring the endpoint).
2. Mobile Threat Defense (MTD) Integration
Partner Connectors: Integrates MTD vendors (e.g., Microsoft Defender for Endpoint, Lookout, Zscaler) to evaluate real-time app, network, and OS threat levels on mobile devices.
Risk-Based Compliance: Maps MTD threat scores (Clear, Low, Medium, High) into compliance evaluations to protect services like Exchange Online and SharePoint from compromised endpoints.
3. Conditional Access (CA) Enforcement
Access Control Logic: Entra ID evaluates real-time signals (user identity, location, application risk, device compliance state) against policy conditions to determine grant, block, or step-up authentication (MFA) controls.
Gating Corporate Resources: Blocks unenrolled or non-compliant devices from reaching cloud apps (Microsoft 365, SaaS applications) until security issues are remediated on the endpoint.
This module covers data-at-rest protection, file-level encryption, and data loss prevention across Windows endpoints, focusing on BitLocker, Encrypting File System (EFS), Information Rights Management (IRM), and legacy Windows Information Protection (WIP) mechanisms.
Key Topics Breakdown
1. Data Protection Technologies Overview
Data Loss Prevention (DLP): Identifies, monitors, and protects sensitive information (e.g., credit card numbers, PII) from unauthorized sharing or accidental leakage across cloud services and endpoints.
Information Rights Management (IRM): Provides persistent document-level protection using Azure Rights Management (Azure RMS). Encryption and usage rights (e.g., read-only, block printing/forwarding) travel with the file, even when exported outside the corporate network.
2. Windows Information Protection (WIP) Capabilities & Policy Modes
Identity & Separation: Dynamically separates personal and enterprise data on Windows devices without requiring dual containers or changing user workflows.
Key Benefits: Enables selective selective wipes (removing corporate data while leaving personal files intact) and audit telemetry for tracking data movement.
Implementation Modes:
Block: Blocks unauthorized copy-pasting or sharing outside managed apps.
Allow Overrides: Warns users when moving data, requiring explicit user justification.
Silent: Allows data transfers uninterrupted while logging events for audit analysis.
Off: Disables WIP enforcement.
MD-102 Exam Note: Windows Information Protection (WIP) has been deprecated by Microsoft in favor of Microsoft Purview Data Loss Prevention (DLP) and Microsoft Purview Information Protection.
3. Storage & Encryption Technologies (EFS vs. BitLocker)
Encrypting File System (EFS): File- and folder-level encryption tied to specific user certificates. Ideal for securing specific sensitive directories on shared Windows endpoints.
BitLocker Drive Encryption: Full-volume disk encryption that protects the entire operating system, system files, and data partitions against physical device theft or cold-boot attacks (managed via TPM chips and BitLocker CSP policies in Intune).
This module covers the core security controls, hardware-backed isolation, and host intrusion prevention mechanisms built into Windows 11 and Microsoft 365 Security to protect devices against zero-day exploits, unauthorized software execution, and kernel-level tampering.
Key Topics Breakdown
1. Microsoft Defender for Endpoint & Management
Architecture: Combines endpoint behavioral sensors, cloud security analytics, and global threat intelligence.
Core Capabilities: Covers Attack Surface Reduction (ASR) rules, next-generation antivirus protection, Endpoint Detection and Response (EDR), and automated investigation/remediation.
Portal & Analytics: Managed centrally via the Microsoft Defender Portal, featuring Secure Score for security posture tracking, Advanced Hunting via Kusto Query Language (KQL), and REST APIs for SIEM integration.
2. Application Control & Hardware-Enforced Code Integrity
Windows Defender Application Control (WDAC): Restricts execution solely to trusted applications, signed executables, and verified catalog manifests.
Device Guard & HVCI: Employs Hypervisor-Protected Code Integrity (HVCI) to run kernel-mode code integrity checks within a secure Virtualization-Based Security (VBS) container, preventing kernel tampering.
3. Endpoint Isolation & Host Intrusion Prevention
Exploit Guard Features: Includes Exploit Protection, ASR rules, Network Protection, and Controlled Folder Access to defend against ransomware.
Application Guard (MDAG): Runs untrusted browser (Edge) and document sessions inside a Hyper-V micro-VM container.
MD-102 Exam Note: Microsoft Defender Application Guard (MDAG) for Edge and Office has been deprecated by Microsoft in favor of Microsoft Defender SmartScreen, Enhanced Security Mode, WDAC, and ASR rules.
4. Hardware-Backed Root of Trust (System Guard)
System Guard Architecture: Utilizes the hardware Trusted Platform Module (TPM) and Virtualization-Based Security (VBS) to maintain firmware and OS boot integrity.
Boot Integrity & Attestation: Protects early boot processes (Secure Boot, Measured Boot) and generates cryptographic health attestation measurements for Intune compliance evaluation.
This module covers the core OS-level defense components integrated into Windows 10/11, focusing on identity isolation with Credential Guard, next-generation threat protection via Microsoft Defender Antivirus, and network perimeter protection using Windows Defender Firewall.
Key Topics Breakdown
1. Windows Security Center & Credential Guard
Windows Security App: Centralized dashboard for managing device health, virus protection, network firewall status, and app/browser controls.
Windows Defender Credential Guard:
VBS-Based Isolation: Uses Virtualization-Based Security (VBS) and Virtual Secure Mode (VSM) to isolate NTLM hashes, Kerberos Ticket Granting Tickets (TGTs), and domain credentials inside a protected container.
Pass-the-Hash Mitigation: Prevents administrative malware on the host OS from dumping LSASS.exe memory.
Default Enablement: Enabled by default on hardware-compatible Windows 11 (22H2 and later) and Windows Server 2025 enterprise endpoints.
2. Microsoft Defender Antivirus Management
Scanning & Real-Time Engine: Combines signature detection, cloud-based heuristics, and behavioral monitoring to stop zero-day threats.
Exclusions & Governance: Configures path, file type, and process exclusions to prevent false positives on critical enterprise workloads.
Centralized Policy Management: Managed at scale using Microsoft Intune (via Endpoint Security Antivirus profiles) or MECM (Configuration Manager Antivirus policies).
3. Windows Defender Firewall with Advanced Security
Network Profiles: Enforces context-aware rules across three distinct network locations:
Domain: Active when connected to the corporate Active Directory domain.
Private: Intended for trusted home or small-office networks.
Public: Default untrusted profile for public Wi-Fi hotspots (strictest inbound rules).
Advanced Rules & IPsec: Uses the Advanced Security MMC snap-in (wf.msc) to create granular inbound/outbound rules, port/protocol filters, and IPsec connection security rules for encrypted peer-to-peer transport.
User Telemetry: Manages taskbar notifications and security alerts when applications request inbound network access.
This module introduces Microsoft Defender for Cloud Apps (Microsoft's Cloud Access Security Broker solution), explaining how it provides full visibility, data security, threat detection, and compliance controls across SaaS applications and shadow IT environments.
Key Topics Breakdown
1. Core CASB Pillars & Capabilities
Shadow IT Discovery & Visibility: Discovers unsanctioned cloud application usage across the enterprise network by ingesting log telemetry (e.g., from firewalls, proxy logs, or Microsoft Defender for Endpoint).
Data Security & DLP: Scans connected SaaS apps to identify sensitive corporate data, enforce classification tags (via Microsoft Purview Information Protection), and prevent data exfiltration.
Threat Protection & Behavioral Analytics: Monitors anomaly indicators, compromised user accounts, and OAuth app permissions to neutralize zero-day cloud threats.
Compliance Assessments: Evaluates discovered cloud applications against over 90 risk indicators to ensure regulatory compliance (e.g., HIPAA, GDPR, SOC 2).
2. Architecture & Deployment Planning
Licensing & Roles: Requires proper M365 licensing (e.g., Microsoft 365 E5 / Security) and role-based access control (RBAC) grants within the Microsoft Defender Portal.
Conditional Access App Control: Integrates directly with Microsoft Entra ID Conditional Access to proxy real-time web sessions.
Access Policies: Block or allow access based on device state (e.g., restricting access to unmanaged BYOD endpoints).
Session Policies: Enforce real-time in-session actions (e.g., blocking file downloads, copy-pasting, or uploading malware) during active user browser sessions.
3. Personalization & Policy Governance
App Sanctioning: Allows administrators to tag applications as Sanctioned (approved), Unsanctioned (blocked), or Monitored.
Automated Remediation: Configures governance actions to automatically revoke OAuth tokens, force user re-authentication, or isolate compromised files in quarantine.
This module focuses on securing enterprise endpoints by managing policy baselines, threat protection, and encryption controls directly within the Endpoint security blade of Microsoft Intune.
Key Topics Breakdown
1. Core Architecture of Intune Endpoint Security
Endpoint Security Blade: Serves as a dedicated management zone in Intune for security administrators to deploy targeted policies without needing full Intune MDM configuration access.
Security Baselines: Uses pre-configured, Microsoft-recommended security baselines (e.g., Windows 10/11 Security Baseline, Defender for Endpoint Baseline) to deploy enterprise security configurations instantly.
2. Security Workloads & Policy Configurations
Antivirus (Microsoft Defender): Builds Antivirus profiles to manage real-time protection engine settings, cloud-delivered protection levels, scheduled quick/full scans, and process or path exclusions.
Disk Encryption (BitLocker): Deploys BitLocker profiles across Windows endpoints to enforce full-volume encryption (XTS-AES 128/256), manage Trusted Platform Module (TPM) startup requirements, and securely back up recovery keys directly to Microsoft Entra ID.
Firewall Protection: Sets up Windows Defender Firewall policies to enforce domain, private, and public profile baselines, alongside granular inbound and outbound firewall rules.
3. Targeted Assignment & Verification
Assignment Scope: Deploys security profiles to targeted Microsoft Entra ID groups using Device Groups (for machine-wide enforcement like BitLocker and Firewall) or User Groups (for user-centric security configurations).
Compliance & Status Verification: Tracks real-time deployment status, monitors profile errors/conflicts, and audits endpoint security posture using Intune’s device and profile status reporting dashboards.
This demonstration walks through building, assigning, and testing a BitLocker Disk Encryption profile in Microsoft Intune on an enrolled Windows workstation (cattl-workstation1), verifying pre-boot PIN setup and drive encryption execution.
Key Demo Steps Breakdown
1. Policy Creation & BitLocker Configuration
Navigation: Navigates to Endpoint security > Disk encryption in the Intune Admin Center and creates a new policy for Windows 10/11 using the BitLocker profile template (named "Contoso BitLocker").
Core Settings: Enables full device encryption, BitLocker password rotation, and configures operating system drive settings.
TPM & Pre-Boot Controls: Enforces TPM startup requirements, allows BitLocker without a compatible TPM if needed, and sets a minimum pre-boot PIN length of 6 characters.
Recovery & Escrow: Enables custom pre-boot recovery messages and enforces automatic escrow of BitLocker recovery keys directly to Microsoft Entra ID / AD DS before encryption can commence. Skips the BitLocker setup wizard for end-users.
2. Group Targeting & Client Synchronization
Assignment: Targets the policy to the Koso Developer Devices group.
Client Sync: Logs into the client endpoint (cattl-workstation1) and initiates a manual policy sync from Settings > Accounts > Access work or school.
3. End-User Experience & Encryption Verification
User Notification: Triggers an automated system prompt indicating "Encryption needed".
PIN Configuration: The user accepts the encryption prompt, sets a 6-character pre-boot PIN, and starts the OS volume encryption process.
Boot Test Verification: Restarts the workstation to verify that the pre-boot PIN screen appears, accepts the user PIN, successfully decrypts the system volume, and boots into Windows.
This demonstration contrasts legacy Per-User Multi-Factor Authentication (MFA) with modern, targeted Conditional Access (CA) MFA policies using a test account (Alex) and Microsoft 365 cloud apps.
Key Demo Steps Breakdown
1. Part 1: Configuring & Testing Legacy Per-User MFA
Baseline Verification: Confirms that the target user account (Alex) currently has no active MFA requirement.
Per-User Configuration: Opens the Microsoft Entra Admin Center, navigates to the legacy Per-user MFA management portal, and configures global MFA service settings.
Enabling MFA: Changes the status for user Alex to Enabled.
End-User Testing & Registration: Logs in as Alex, which immediately triggers the initial MFA enrollment flow. Sets up the Microsoft Authenticator app, completes push notification verification, and validates a successful MFA sign-in.
Cleanup: Changes the per-user status back to Disabled and tests sign-in to confirm that MFA is no longer prompted.
2. Part 2: Configuring & Testing Conditional Access MFA
Policy Creation: Navigates to Entra ID > Protection > Conditional Access and creates a new targeted Conditional Access policy.
Targeting Scope:
Users: Target user (Alex).
Target Resources: Specific cloud application (Office 365).
Grant Control: Selects Require multifactor authentication.
Validation (Targeted App): Logs into Office 365 as Alex—Conditional Access evaluates the targeted app scope and triggers an MFA prompt.
Validation (Non-Targeted App): Logs into the Azure Portal (portal.azure.com) as Alex—because Azure is outside the policy scope, sign-in succeeds seamlessly without an MFA prompt.
Cleanup: Deletes the Conditional Access policy to clean up the tenant environment.
This lesson covers the end-to-end framework for preparing an enterprise environment for a large-scale Windows OS migration (such as upgrading to Windows 11), evaluating application compatibility, leveraging virtualization mitigations, and optimizing network delivery protocols.
Key Topics Breakdown
1. Deployment Guidelines & Pre-Migration Checklist
Inventory & Asset Mapping: Maps hardware inventory and enterprise network topology while retiring legacy or non-compliant hardware.
App & Data Planning: Classifies complex app installations, defines cloud/local virtualization strategies, and establishes minimal-downtime data migration and backup procedures.
Support & Deployment Plan: Formulates a phased deployment plan alongside end-user training and post-deployment helpdesk support.
2. Readiness Insights & Application Compatibility Mitigations
Readiness Evaluation: Uses Microsoft Intune and Endpoint Analytics to assess OS build states, hardware upgrade blockers (e.g., TPM 2.0, Secure Boot), and system performance telemetry.
App Compatibility Options:
OS Compatibility Modes: Executes legacy Win32 binaries using built-in Windows compatibility modes.
Application Compatibility Toolkit (ACT) / Shim Fixes: Applies compatibility shims or fixes for legacy Line-of-Business (LOB) apps.
Remote & Cloud Virtualization: Uses Client Hyper-V (local VM testing), Remote Desktop Services (RDS), Azure Virtual Desktop (AVD), or Windows 365 to deliver legacy applications in isolated virtual environments.
Modern Microsoft Note: Microsoft's App Assure program provides engineering support for LOB app compatibility issues during Windows 11 upgrades.
3. Network Optimization Protocols
Delivery Optimization (DO): Peer-to-peer (P2P) content distribution protocol that shares OS updates and app packages between endpoints on the same local network, saving Internet bandwidth.
BranchCache: WAN optimization feature that caches downloaded content from remote servers onto local subnet hosted/distributed caches.
BITS & LEDBAT:
BITS (Background Intelligent Transfer Service): Uses idle network bandwidth for asynchronous background downloads.
LEDBAT (Low Extra Delay Background Transport): Low-latency transport protocol that dynamically yields bandwidth to active user traffic to prevent WAN network congestion.
4. Identity & Deployment Rings (Pilot Strategy)
Hybrid Identity: Integrates Microsoft Entra ID for seamless single sign-on (SSO) and Conditional Access enforcement during OS transitions.
Phased Deployment Rings:
Phase 1 (Pilot): IT personnel and early adopter power users.
Phase 2 (Broad Pilot): Representative sample across business units to collect feedback and surface edge cases.
Phase 3 (Production): Full automated rollout across the organization.
This module covers traditional, on-premises Windows deployment workflows, comparing image strategies (Thin vs. Thick) and breaking down how Microsoft Deployment Toolkit (MDT) automates system imaging, task sequencing, and user state migrations.
Key Topics Breakdown
1. Image Deployment Strategies: Thin vs. Thick Images
Thin Images (Default/Recommended): Installs a clean, unmodified Windows base operating system image (install.wim) and applies core applications, language packs, and device drivers dynamically during task sequence execution.
Pros: Faster image maintenance and lower storage footprint; highly modular.
Cons: Longer overall deployment times on the endpoint during staging.
Thick Images (Custom/Golden): Captures a customized reference machine containing pre-installed line-of-business (LOB) software, configurations, and updates.
Pros: Faster end-to-end installation at the client endpoint.
Cons: Requires frequent recapture and maintenance whenever application versions or OS updates change.
2. MDT Core Architecture & Prerequisites
Prerequisites: Requires Active Directory Domain Services (AD DS), Windows Server 2016+, Windows Assessment and Deployment Kit (Windows ADK), Windows Deployment Services (WDS for PXE boot), and Windows Server Update Services (WSUS).
Core Components:
Deployment Workbench: Central Administrative console to manage driver repositories, operating system images, software packages, and task sequences.
Deployment Shares: Network shares hosting media, scripts, and source files.
User State Migration Tool (USMT): Integrates into task sequences to back up and restore user data and profile settings.
3. Deployment Models (LTI, ZTI, UDI)
Light Touch Installation (LTI): MDT default model requiring minimal user or IT administrative interaction at the client machine during setup.
Zero Touch Installation (ZTI): Fully automated deployment with zero end-user prompts; requires integration with MECM (System Center Configuration Manager).
User-Driven Installation (UDI): Displays customizable wizard screens during setup allowing technicians or users to select specific apps and language choices during deployment.
This demonstration walks through the end-to-end lifecycle of onboarding a Windows device into Windows Autopilot—from gathering its unique hardware hash via PowerShell to creating dynamic Entra ID targeting groups, deploying Autopilot profiles in Intune, and running through the Out-of-Box Experience (OOBE).
Key Demo Steps Breakdown
1. Group Preparation & Hardware Hash Collection
Dynamic Group Creation: Opens the Microsoft Entra Admin Center and creates a Dynamic Device Group targeting devices with a specific Autopilot Group Tag (ZTDID or custom tag).
Hardware Hash Extraction: Logs into the target Windows client, opens PowerShell, and executes the Autopilot collection script (Get-WindowsAutoPilotInfo.ps1 -OutputFile C:\HWID.csv) to generate the CSV containing the device's hardware hash.
Hash Inspection: Inspects the generated .csv file to verify device serial number, Windows PKID, and 4,000-character hardware hash payload.
2. Intune Import & Autopilot Profile Creation
Device Import: Navigates to Intune > Devices > Enrollment > Devices and imports the CSV file into the Windows Autopilot devices database.
Profile Configuration: Creates a Windows Autopilot Deployment Profile:
Mode: User-Driven or Self-Deploying experience.
OOBE Settings: Configures privacy settings, hides local admin account creation, sets language/keyboard options, and configures the Entra ID join type.
Profile Assignment: Assigns the deployment profile to the dynamic Entra ID device group created in Step 1.
3. Device Reset & OOBE Provisioning
Initiating Reset: Initiates a sync in Intune and triggers a remote Windows Autopilot Reset (or local system reset) on the target PC.
OOBE Flow: The device restarts into the customized Out-of-Box Experience, showing branded welcome screens and enforcing corporate sign-in prompts.
User Onboarding: The user signs in with their organizational Entra ID credentials, completes mandatory Multi-Factor Authentication (MFA), and sets up a Windows Hello for Business PIN.
4. Post-Deployment Verification
Sync & Policy Status: Accesses Settings > Accounts > Access work or school on the client to perform an initial policy sync.
Identity & Management Auditing: Confirms the endpoint's successful Entra ID join in the Entra Admin Center and verifies active Intune MDM enrollment status in the Intune portal.
This demonstration covers updating an existing Autopilot environment to use Self-Deploying Mode, setting automated device naming conventions, and executing a remote Autopilot Reset to re-provision an enterprise endpoint.
Key Demo Steps Breakdown
1. Profile Modification & Self-Deploying Setup
Removing Legacy Profile: Opens the Microsoft Intune Admin Center (Devices > Windows > Enrollment > Deployment Profiles) and unassigns/removes the previous deployment profile.
Creating Self-Deploying Profile: Configures a new profile using Self-Deploying Mode:
Self-Deploying Mode: Designed for shared devices, kiosks, or zero-touch deployments where no end-user interaction or credential entry is required during the initial OOBE phase (uses TPM 2.0 attestation for identity verification).
Device Naming Template: Sets an automated computer naming schema (e.g., IT-%SERIAL% or CORP-%RAND:4%) to standardize machine hostnames across the fleet upon enrollment.
Targeting: Assigns the newly created profile to the designated IT Devices Entra ID group.
2. Executing Remote Autopilot Reset
Initiating Reset: Navigates to the target device record within Intune and triggers an Autopilot Reset.
Autopilot Reset Mechanics: Clears user files, applications, and personal settings while retaining the OS, primary enrollment state, and Entra ID join status—preparing the device for immediate re-use without requiring a full OS reinstall over the network.
System Restart: Confirms and initiates the reset, causing the client machine to reboot and re-apply corporate baselines.
3. Post-Reset Provisioning & Verification
Account Setup: Post-reset, signs in with the enterprise work account to validate policy re-application.
MFA & Security Registration: Prompts the user to complete Multi-Factor Authentication (MFA) and register a Windows Hello for Business PIN.
Policy Sync: Navigates to Settings > Accounts > Access work or school on the client endpoint to execute a manual policy sync, ensuring all Intune profiles and applications finish deploying.
Master the art of securing enterprise devices with Microsoft Intune! Designed specifically for IT professionals and candidates preparing for the MD-102: Microsoft 365 Endpoint Administrator certification, this hands-on course gives you the practical skills needed to deploy, manage, and monitor robust endpoint security policies across your organization.
You will dive deep into the Intune Endpoint Security node to configure essential protection mechanisms, including Microsoft Defender Antivirus, BitLocker Disk Encryption, Attack Surface Reduction (ASR) rules, and Windows Firewall settings. Learn how to create targeted configuration profiles, leverage dynamic group assignments, and enforce strict compliance standards across Windows endpoints. Beyond basic setup, you’ll gain real-world experience in monitoring deployment reports, analyzing security baselines, and troubleshooting common policy conflicts.
Additionally, this course explores key strategies for maintaining zero-trust endpoint hygiene, managing Endpoint Detection and Response (EDR) capabilities, and automating remediations to keep your organization ahead of modern security threats. Through step-by-step practical demonstrations, you will gain actionable confidence to handle complex enterprise device management challenges effortlessly.
By the end of this course, you’ll not only be fully equipped to tackle the endpoint security domain of the MD-102 exam, but you'll also possess the job-ready expertise to build a hardened, resilient Microsoft 365 enterprise environment.