✅ GUARANTEED TO RUN
7:00 AM – 3:00 PM PST
Tentative
9:00 AM – 5:00 PM CST
Tentative
7:00 AM – 3:00 PM PST
Tentative
8:00 AM – 4:00 PM MST
Reserve Your Seat
- Virtual instructor Led Training
- Complete Hands-on Labs
- Softcopy of Courseware
- Learning Labs
- Virtual instructor Led Training
- Complete Hands-on Labs
- Softcopy of Courseware
- Learning Labs
- You can use your Purchase Card and checkout
- The GSA Contract Number: 47QTCA20D000D
- Call 800-453-5961 for details
- Customize your class
- Delivery Onsite or Online for your organization
- Choice of Dates when and where you want
- Guidance in choosing and customizing your class
Question About this Course?

MD-102: Microsoft 365 Endpoint Administrator
MD-102T00: Microsoft 365 Endpoint Administrator is an instructor-led course for administrators who deploy, configure, secure, manage, and monitor devices and client applications in Microsoft 365 environments.
Students learn how to manage Microsoft Entra ID identities, device registration, Intune enrollment, device configuration, app deployment, compliance policies, endpoint security, disk encryption, Windows Autopilot, Windows 365, Azure Virtual Desktop, and Microsoft Defender for Endpoint.
Certification: Microsoft 365 Certified: Endpoint Administrator Associate
Exam: MD-102: Endpoint Administrator
Why choose Dynamics Edge for MD-102 training?
Dynamics Edge delivers MD-102 training with practical endpoint administration examples, hands-on labs, certification review, and implementation-focused discussion. The course helps administrators understand how Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Defender for Endpoint, Windows 365, and endpoint security work together.
- Learn how to deploy, configure, protect, and manage endpoints with Microsoft Intune.
- Practice core endpoint administration tasks used in real Microsoft 365 environments.
- Prepare for the MD-102 certification exam with structured review and lab reinforcement.
- Understand endpoint security, compliance, application management, Autopilot, and device lifecycle management.
- Request private team delivery for endpoint modernization, Intune rollout, CMMC readiness, Windows 11 deployment, or administrator onboarding.
What will you learn in MD-102 training?
Students learn how to implement modern endpoint management across Windows, iOS, iPadOS, Android, macOS, Windows 365, and Azure Virtual Desktop scenarios.
- Manage identities, users, groups, licenses, device join, device registration, and Intune enrollment.
- Configure device profiles, compliance policies, Conditional Access, Windows Hello for Business, and endpoint security.
- Deploy and manage apps, Microsoft 365 Apps, Win32 apps, app protection policies, and app configuration policies.
- Deploy Windows with Autopilot, manage Windows updates, run remote actions, and monitor device health.
- Protect endpoints with Microsoft Defender for Endpoint, attack surface reduction, disk encryption, firewall, security baselines, and Intune security policies.
Course Outline Microsoft 365 Endpoint Administrator MD-102
Learning Path 1: Explore endpoint management
Module 1: Describe modern endpoint management
Students learn how endpoint management has evolved from traditional desktop management to cloud-based modern management with Microsoft Intune and Microsoft Entra ID.
Topics include:
- Describe modern endpoint management.
- Compare traditional and cloud-based endpoint management.
- Identify endpoint administrator responsibilities.
- Review supported platforms and device types.
- Understand endpoint management in Microsoft 365.
Module 2: Describe Microsoft Intune and Microsoft Entra ID
Students review how Microsoft Intune and Microsoft Entra ID provide the foundation for device enrollment, identity, access, compliance, and policy management.
Topics include:
- Describe Microsoft Intune capabilities.
- Describe Microsoft Entra ID device identity.
- Explain device join and registration options.
- Review Intune licensing and tenant requirements.
- Understand cloud-based policy management.
Learning Path 2: Manage identity and device enrollment
Module 3: Manage identities in Microsoft Entra ID
Students learn how endpoint administrators manage users, groups, roles, and licenses that support device management and application access.
Topics include:
- Create and modify users.
- Assign licenses to users.
- Create and manage groups.
- Assign administrative roles.
- Review identity requirements for endpoint management.
Module 4: Synchronize identities by using Microsoft Entra Connect
Students learn how synchronized identity supports hybrid environments. They review directory synchronization, hybrid identity planning, Microsoft Entra Connect, and validation of synchronized users and groups.
Topics include:
- Prepare identities for synchronization.
- Configure Microsoft Entra Connect.
- Synchronize users and groups.
- Validate synchronization results.
- Troubleshoot common synchronization issues.
Module 5: Configure and manage Microsoft Entra join
Students learn how devices join Microsoft Entra ID and how join type affects management, access, and deployment options.
Topics include:
- Configure Microsoft Entra join settings.
- Join Windows devices to Microsoft Entra ID.
- Configure hybrid Microsoft Entra join.
- Review device ownership and management status.
- Troubleshoot device join issues.
Module 6: Manage device registration and Intune enrollment
Students learn how to register and enroll devices into Intune. They review enrollment restrictions, automatic enrollment, platform enrollment options, and enrollment troubleshooting.
Topics include:
- Configure device registration settings.
- Configure Intune enrollment restrictions.
- Enable automatic enrollment.
- Enroll Windows and mobile devices.
- Validate enrollment status in Intune.
Learning Path 3: Manage and maintain devices
Module 7: Create and deploy configuration profiles
Students learn how configuration profiles manage endpoint settings across Windows and non-Windows platforms.
Topics include:
- Create device configuration profiles.
- Assign profiles to users and devices.
- Configure Windows settings with Intune.
- Configure iOS, iPadOS, Android, and macOS settings.
- Monitor profile deployment status.
Module 8: Configure kiosk mode and specialized devices
Students learn how Intune can configure devices for restricted-use and frontline scenarios.
Topics include:
- Configure Windows kiosk mode.
- Configure device restrictions.
- Assign profiles to device groups.
- Test kiosk behavior.
- Monitor policy deployment.
Module 9: Configure Wi-Fi and network profiles
Students learn how to deploy network settings to managed devices.
Topics include:
- Create Wi-Fi configuration profiles.
- Configure iOS and iPadOS Wi-Fi settings.
- Assign network profiles.
- Validate profile deployment.
- Troubleshoot connectivity policy issues.
Module 10: Analyze Group Policy migration to Intune
Students learn how Group Policy Analytics helps organizations evaluate existing GPOs for modern management migration.
Topics include:
- Import Group Policy settings.
- Analyze Intune support for GPO settings.
- Identify migration readiness.
- Plan migration from Group Policy to Intune.
- Review unsupported or partially supported settings.
Module 11: Monitor device and user activity
Students learn how to monitor endpoint activity, compliance, configuration, and device health in Intune.
Topics include:
- Monitor device status.
- Review user and device activity.
- Export device reports.
- Review Intune reporting options.
- Use reports to troubleshoot endpoint issues.
Learning Path 4: Manage applications
Module 12: Deploy apps by using Intune
Students learn how to deploy apps to managed devices by using Intune.
Topics include:
- Deploy cloud-based apps.
- Deploy Microsoft Store apps.
- Deploy Microsoft 365 Apps.
- Deploy Win32 apps.
- Monitor app installation status.
Module 13: Manage application protection and configuration policies
Students learn how app protection policies help protect organizational data on managed and unmanaged devices.
Topics include:
- Configure app protection policies.
- Configure app configuration policies.
- Protect data in mobile apps.
- Apply Conditional Access with app protection.
- Monitor app protection policy status.
Module 14: Manage Microsoft 365 Apps and browser-based apps
Students learn how administrators deploy and manage Microsoft 365 Apps and browser-based applications.
Topics include:
- Configure Microsoft 365 Apps deployment.
- Manage Office app settings.
- Review browser app management options.
- Monitor Microsoft 365 Apps deployment.
- Troubleshoot app installation and update issues.
Learning Path 5: Implement identity, compliance, and access protection
Module 15: Configure multi-factor authentication
Students learn how MFA improves access security for Microsoft 365 and endpoint management.
Topics include:
- Configure MFA requirements.
- Enable MFA for users.
- Test MFA sign-in behavior.
- Review authentication methods.
- Troubleshoot MFA registration issues.
Module 16: Configure self-service password reset
Students learn how SSPR reduces help desk load while improving identity recovery.
Topics include:
- Configure SSPR settings.
- Assign SSPR to user groups.
- Configure authentication methods.
- Test password reset.
- Monitor SSPR registration and usage.
Module 17: Configure and validate device compliance
Students learn how compliance policies evaluate device health and support Conditional Access decisions.
Topics include:
- Create device compliance policies.
- Configure platform-specific compliance settings.
- Assign compliance policies.
- Validate device compliance.
- Use compliance status with Conditional Access.
Learning Path 6: Protect devices
Module 18: Configure endpoint security policies
Students learn how Intune endpoint security policies protect devices from common threats.
Topics include:
- Configure antivirus policies.
- Configure firewall policies.
- Configure attack surface reduction policies.
- Configure security baselines.
- Monitor endpoint security status.
Module 19: Configure disk encryption
Students learn how to protect device data by using Intune-managed disk encryption.
Topics include:
- Configure BitLocker policies.
- Configure encryption settings.
- Rotate BitLocker recovery keys.
- Review encryption status.
- Troubleshoot encryption deployment issues.
Module 20: Integrate Microsoft Defender for Endpoint
Students learn how Defender for Endpoint works with Intune to protect and monitor managed devices.
Topics include:
- Connect Intune with Defender for Endpoint.
- Onboard devices to Defender for Endpoint.
- Review device risk signals.
- Use risk-based compliance.
- Monitor endpoint detection and response status.
Learning Path 7: Deploy and update Windows clients
Module 21: Deploy Windows 11
Students learn how to deploy Windows clients using modern and traditional deployment options.
Topics include:
- Plan Windows 11 deployment.
- Compare deployment methods.
- Use Microsoft Deployment Toolkit concepts.
- Prepare deployment images and task sequences.
- Validate Windows deployment outcomes.
Module 22: Deploy Windows with Autopilot
Students learn how Windows Autopilot automates device provisioning and reduces hands-on deployment work.
Topics include:
- Configure Windows Autopilot deployment profiles.
- Import device hardware hashes.
- Configure Enrollment Status Page.
- Deploy devices with Autopilot.
- Troubleshoot Autopilot deployment.
Module 23: Refresh devices with Autopilot Reset and self-deploying mode
Students learn how Autopilot Reset and self-deploying mode support device reuse and shared-device scenarios.
Topics include:
- Configure Autopilot Reset.
- Configure self-deploying mode.
- Assign Autopilot profiles.
- Reset and reprovision devices.
- Validate device readiness after reset.
Module 24: Manage Windows updates
Students learn how Intune manages updates for Windows clients and other supported platforms.
Topics include:
- Create Windows update rings.
- Configure feature update policies.
- Configure quality update policies.
- Monitor update status.
- Troubleshoot update deployment.
Learning Path 8: Manage cloud endpoints and advanced endpoint scenarios
Module 25: Implement Windows 365 Cloud PCs
Students learn how Windows 365 provides Cloud PCs for managed desktop access.
Topics include:
- Compare Windows 365 Business and Enterprise.
- Configure Cloud PC provisioning.
- Assign licenses and policies.
- Connect to Cloud PCs.
- Monitor Cloud PC status.
Module 26: Implement Azure Virtual Desktop
Students learn how Azure Virtual Desktop supports virtualized Windows desktop and app scenarios.
Topics include:
- Describe Azure Virtual Desktop architecture.
- Create host pools and session hosts.
- Configure users and application groups.
- Connect to virtual desktops.
- Manage AVD with PowerShell or Azure CLI.
Module 27: Implement Intune Suite add-on capabilities
Students review advanced Intune Suite features for enhanced endpoint management and support.
Topics include:
- Configure Remote Help.
- Review Endpoint Privilege Management.
- Review Microsoft Tunnel for mobile app management.
- Review Advanced Analytics.
- Identify use cases for Cloud PKI.
Hands-on labs
The MD-102 labs support hands-on practice for Microsoft 365 Endpoint Administrators. This single consolidated lab list merges the official GitHub-hosted MD-102 labs with the most important exercise topics found in the MD-102 PowerPoint speaker notes.
- Lab 1: Manage identities in Microsoft Entra ID.
- Lab 2: Synchronize identities by using Microsoft Entra Connect.
- Lab 3: Configure and manage Microsoft Entra join.
- Lab 4: Manage Microsoft Entra device registration.
- Lab 5: Manage device enrollment into Intune.
- Lab 6: Enroll devices into Intune.
- Lab 7: Create and deploy configuration profiles.
- Lab 8: Configure kiosk mode by using an Intune configuration profile.
- Lab 9: Configure iOS and iPadOS Wi-Fi settings by using a configuration profile.
- Lab 10: Use Group Policy Analytics to validate GPO support in Intune.
- Lab 11: Monitor device and user activity in Intune.
- Lab 12: Deploy cloud apps by using Intune.
- Lab 13: Configure app protection policies for mobile devices.
- Lab 14: Configure multi-factor authentication.
- Lab 15: Configure self-service password reset.
- Lab 16: Configure and validate device compliance.
- Lab 17: Configure endpoint security by using Intune.
- Lab 18: Configure disk encryption by using Intune.
- Lab 19: Deploy Windows 11 by using Microsoft Deployment Toolkit.
- Lab 20: Deploy and refresh Windows devices by using Windows Autopilot.
Certification alignment
This course supports preparation for Exam MD-102: Endpoint Administrator. The exam validates the ability to prepare device infrastructure, manage and maintain devices, manage applications, and protect devices in Microsoft 365 environments.
MD-102 skills measured
- Prepare infrastructure for devices.
- Manage and maintain devices.
- Manage applications.
- Protect devices.
Course review
Students should leave the course able to configure, enroll, manage, secure, and monitor endpoints by using Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint, Windows 365, and Azure Virtual Desktop. The course review should reinforce identity, device join, enrollment, configuration profiles, compliance, application deployment, endpoint security, disk encryption, Autopilot, Windows updates, Cloud PCs, and device monitoring.
Certification exam review
Exam review should focus on scenario-based endpoint administration decisions, policy dependencies, deployment options, and troubleshooting. Priority review areas should include Microsoft Entra join, device registration, Intune enrollment, compliance policies, Conditional Access, configuration profiles, app deployment, app protection, MFA, SSPR, endpoint security, BitLocker, Defender for Endpoint, Windows Autopilot, update rings, Windows 365, Azure Virtual Desktop, and Intune reporting.
Question About this Course?
Need help picking the right course?
Call Now