Learners working in a technology training room

Microsoft 365 Endpoint Administrator

# MD-102

Target Audience

This course is designed for endpoint administrators responsible for managing devices and client applications in a Microsoft 365 tenant using Microsoft Intune. Participants implement endpoint deployment and management solutions across Windows, macOS, iOS, iPadOS, Android, specialty devices, and cloud-hosted desktop environments. It is particularly suitable for professionals who collaborate with Microsoft 365 administrators, security administrators, architects, and workload administrators to implement modern workplace strategies. Participants should have experience with Microsoft Entra ID, Microsoft 365, Intune, Windows clients, and non-Windows device platforms.

Instructor-Led (Live Virtual/Classroom)

A live course led by a certified instructor, in virtual or classroom format — one full day of guided sessions with projects and case studies.

Duration5 day (live or virtual)
DeliveryLive virtual or classroom
IncludesOfficial exam + Digital badge
$1349.00 USD Starts October 30, 2026

Course Overview

MD-102: Manage and secure Microsoft 365 endpoints by using Intune develops the capabilities required to plan and execute an endpoint deployment, configuration, security, and management strategy using Microsoft Intune as the unified endpoint management platform. Participants prepare identity and device infrastructure with Microsoft Entra ID, enroll multiple device platforms, configure compliance and Conditional Access, deploy Windows through Windows Autopilot, manage Windows 365 Cloud PCs and Azure Virtual Desktop, and implement configuration profiles and Intune Suite capabilities. The course also covers endpoint security, Microsoft Defender for Endpoint, device updates, application deployment and protection, PowerShell and Microsoft Graph automation, Microsoft Security Copilot agents, Endpoint Analytics, proactive remediations, reporting, alerts, and operational monitoring.

Last Updated: 2026-09-01

Course Exam Overview

  • Program Name: Endpoint Administrator Exam
  • Included: Course, applicable labs, and virtual instructor-led facilitation included; certification exam attempt is managed separately when required.
  • Duration: 100 minutes
  • Prerequisites: Experience with Microsoft Entra ID, Microsoft 365, and Microsoft Intune; strong skills in deploying, configuring, and maintaining Windows and non-Windows devices; and foundational understanding of Microsoft Security Copilot, Intune agents, and Microsoft Defender XDR.
  • Exam Format: Proctored Microsoft role-based certification exam that may include interactive components.
  • Delivery: Pearson VUE
  • Outcome: Passing MD-102 fulfills the exam requirement for the Microsoft 365 Certified: Endpoint Administrator Associate certification

Skills You’ll Gain

Device enrollment planning
Intune policy management
Windows cloud deployment
Endpoint security configuration
Application lifecycle management
- Endpoint operations automation

Job Roles & Industry Outlook

Endpoint Administrator

Deploys, configures, protects, monitors, and maintains organizational endpoints using Microsoft Intune and related Microsoft technologies.

Modern Workplace Engineer

Designs and implements modern device, application, identity, security, and cloud-desktop management solutions.

Modern Workplace Engineer

Manages device enrollment, configuration profiles, compliance, applications, endpoint security, reporting, and automated operations in Intune.

Course Includes

• Five-day instructor-led training aligned with the official Microsoft MD-102T00-A course and current certification objectives.
• Live virtual instructor-led facilitation covering Microsoft Intune, Microsoft Entra ID, Windows, security, applications, and cloud-hosted desktops.
• Applicable hands-on labs for device enrollment, Windows deployment, configuration, compliance, endpoint security, and application management.
• Practical exercises using Windows Autopilot, Microsoft Intune Suite, Defender for Endpoint, PowerShell, Microsoft Graph, and Security Copilot.
• Course and applicable labs included; the MD-102 certification exam attempt is managed separately when required.

What You'll Learn

Close All

This module introduces modern endpoint management with Microsoft Intune and Microsoft Entra ID. Participants evaluate management models, configure the identity infrastructure, add devices to Microsoft Entra ID, create device groups, and prepare administrative roles and scope controls for enterprise endpoint management.

Lessons:
Explore modern endpoint management: understand Microsoft Intune, mobile device management, mobile application management, cloud-native management, co-management, and the role of Microsoft Entra ID in endpoint administration.
Configure Microsoft Entra ID for device management: manage users, device settings, registration permissions, administrative roles, and the identity components required to support Intune policies.
Add devices to Microsoft Entra ID: compare device registration, Microsoft Entra join, and hybrid join and select an appropriate device-identity model according to organizational requirements.
Create and manage device groups: implement assigned and dynamic groups, configure membership rules, and use device groups to target applications, profiles, compliance policies, and security controls.
Implement delegated administration: configure built-in and custom Intune roles, role assignments, scope groups, scope tags, and scoped administration for multi-administrator environments.

Key Topics:
• Microsoft Intune.
• Unified endpoint management.
• Cloud-native management.
• Co-management.
• Microsoft Entra ID.
• Device registration.
• Microsoft Entra join.
• Hybrid join.
• Assigned device groups.
• Dynamic membership rules.
• Intune roles.
• Scope groups and scope tags.
• Multi-admin approval.

Labs / Practical Exercises (if applicable):
• Compare endpoint-management models for an organizational scenario.
• Configure Microsoft Entra device settings and registration controls.
• Create dynamic device groups for policy and application targeting.
• Configure a delegated Intune administrative role with scope tags.

This module focuses on planning, configuring, and troubleshooting device enrollment across Windows, macOS, iOS, iPadOS, and Android. Participants implement enrollment settings, platform integrations, restrictions, profiles, and automated corporate enrollment methods.

Lessons:
Plan Microsoft Intune enrollment: evaluate platform requirements, configure enrollment settings and restrictions, identify ownership models, and establish appropriate enrollment methods for corporate and personal devices.
Enroll Windows devices: configure automatic enrollment, establish Microsoft Entra and Intune integration, and troubleshoot Windows enrollment failures.
Enroll Apple devices: configure personal enrollment for macOS, iOS, and iPadOS and integrate Intune with Apple Business Manager for automated corporate enrollment.
Enroll Android devices: configure fully managed, dedicated, corporate-owned work profile, and personal work profile enrollment and integrate Samsung Knox Mobile Enrollment or Google Zero Touch.
Monitor and troubleshoot enrollment: review enrollment status, investigate restrictions and authentication issues, and resolve platform-specific enrollment failures.

Key Topics:
• Enrollment settings.
• Enrollment restrictions.
• Corporate and personal devices.
• Windows automatic enrollment.
• Apple Business Manager.
• Automated Device Enrollment.
• Android Enterprise.
• Fully managed devices.
• Dedicated devices.
• Work profiles.
• Samsung Knox Mobile Enrollment.
• Google Zero Touch.
• Enrollment troubleshooting.

Labs / Practical Exercises (if applicable):
• Configure enrollment settings and platform restrictions.
• Enable automatic enrollment for Windows devices.
• Design enrollment profiles for Apple and Android corporate devices.
• Diagnose and resolve simulated enrollment failures.

This module develops the skills required to enforce identity, compliance, access, and local administrative controls across managed endpoints. Participants create compliance policies, integrate compliance with Conditional Access, implement Windows Hello for Business, and manage Windows Local Administrator Password Solution.

Lessons:
Implement device compliance: create and assign compliance policies for supported device platforms, configure compliance settings and actions for noncompliance, and monitor compliance status.
Integrate compliance with Conditional Access: create Microsoft Entra Conditional Access policies that require compliant devices and evaluate access decisions for managed and unmanaged endpoints.
Implement Windows Hello for Business: configure passwordless authentication settings, select an appropriate deployment model, assign policies, and validate user registration and sign-in behavior.
Implement Windows LAPS: configure password backup, rotation, access permissions, recovery, and monitoring by using Microsoft Intune and Microsoft Entra ID.
Manage local group membership: configure local users and groups policies and control administrative membership across Windows devices.

Key Topics:
• Device compliance policies.
• Compliance settings.
• Actions for noncompliance.
• Compliance monitoring.
• Conditional Access.
• Compliant-device requirements.
• Windows Hello for Business.
• Passwordless authentication.
• Windows LAPS.
• Password rotation and recovery.
• Local users and groups.
• Secure administrative access.

Labs / Practical Exercises (if applicable):
• Create and assign a device-compliance policy.
• Configure Conditional Access to require compliant devices.
• Implement a Windows Hello for Business policy.
• Configure Windows LAPS and local group membership controls.

This module focuses on deploying and upgrading Windows clients through cloud-based tools. Participants implement Windows Autopilot, manage Windows 11 upgrades and recovery, and provision cloud-hosted desktop environments through Windows 365 and Azure Virtual Desktop.

Lessons:
Plan Windows Autopilot deployment: compare deployment profiles and device-preparation policies and select user-driven, pre-provisioned, or self-deploying modes according to organizational requirements.
Implement Windows Autopilot: register devices, create deployment profiles, apply device-name templates, configure the Enrollment Status Page, assign policies, monitor deployment, and troubleshoot failures.
Plan Windows client upgrades: assess device readiness, configure Windows 11 upgrade policies, manage compatibility considerations, and monitor upgrade progress through Intune.
Implement Windows Backup and Restore: configure backup and recovery settings to support user-state protection and device replacement scenarios.
Provision cloud-hosted desktops: configure Windows 365 Cloud PCs, provisioning policies, network connections, device images, and appropriate management controls and examine Azure Virtual Desktop integration scenarios.

Key Topics:
• Windows Autopilot.
• Device-preparation policies.
• User-driven deployment.
• Pre-provisioning.
• Self-deploying mode.
• Device-name templates.
• Enrollment Status Page.
• Windows 11 upgrades.
• Windows Backup and Restore.
• Windows 365 Cloud PCs.
• Provisioning policies.
• Network connections.
• Image management.
• Azure Virtual Desktop.

Labs / Practical Exercises (if applicable):
• Create and assign a Windows Autopilot deployment profile.
• Configure an Enrollment Status Page and device-name template.
• Plan a Windows 11 upgrade and recovery strategy.
• Design a Windows 365 Cloud PC provisioning policy.

This module develops the capabilities required to configure devices across multiple platforms, target policies accurately, implement Intune Suite capabilities, and perform remote administrative actions for support, security, and lifecycle management.

Lessons:
Create device configuration profiles: configure profiles for Windows, Android, iOS, iPadOS, macOS, Teams Rooms, HoloLens 2, Zebra, and other supported specialty devices.
Configure advanced Windows settings: import administrative templates, use the Settings Catalog, import ADMX files, analyze Group Policy objects, and migrate appropriate settings to cloud management.
Target configuration policies: use assignments, assignment filters, applicability rules, and enrollment-time grouping to deliver settings to the appropriate users and devices.
Implement Intune Suite capabilities: configure Endpoint Privilege Management, Enterprise App Catalog, Remote Help, Microsoft Cloud PKI, Microsoft Tunnel for MAM, and Advanced Analytics.
Perform remote actions: synchronize, restart, retire, wipe, and locate devices; rotate recovery keys and local administrator passwords; run KQL device queries; and collect diagnostics and logs.

Key Topics:
• Configuration profiles.
• Settings Catalog.
• Administrative templates.
• ADMX ingestion.
• Group Policy analytics.
• Assignment filters.
• Enrollment-time grouping.
• Endpoint Privilege Management.
• Enterprise App Catalog.
• Remote Help.
• Microsoft Cloud PKI.
• Microsoft Tunnel for MAM.
• Intune Advanced Analytics.
• Remote device actions.
• Device queries and diagnostics.

Labs / Practical Exercises (if applicable):
• Create and assign configuration profiles for different device platforms.
• Analyze Group Policy settings and create a cloud-management profile.
• Configure an Intune Suite capability for an enterprise scenario.
• Perform remote actions and collect device diagnostics.

This module focuses on protecting organizational endpoints through Microsoft Intune and Microsoft Defender for Endpoint. Participants implement antivirus, encryption, firewall, attack-surface reduction, security baselines, application control, and cross-platform device-update strategies.

Lessons:
Configure endpoint security policies: create and assign antivirus, disk-encryption, firewall, attack-surface reduction, and security-baseline policies according to Zero Trust principles.
Manage device encryption: configure BitLocker, manage recovery keys, enable user self-service recovery, and monitor encryption compliance.
Integrate Intune with Defender for Endpoint: onboard devices, configure Endpoint Detection and Response policies, investigate threats, triage incidents, and review vulnerability-management recommendations.
Implement application control: configure App Control for Business policies to manage trusted and untrusted applications on Windows endpoints.
Manage device updates: configure Windows update rings, feature and quality updates, Windows Autopatch, Hotpatch, Delivery Optimization, and update policies for Apple and Android platforms.

Key Topics:
• Endpoint security policies.
• Microsoft Defender Antivirus.
• BitLocker encryption.
• Firewall policies.
• Attack-surface reduction.
• Zero Trust.
• Security baselines.
• Defender for Endpoint.
• Endpoint Detection and Response.
• Vulnerability Management.
• App Control for Business.
• Windows update rings.
• Feature and quality updates.
• Windows Autopatch and Hotpatch.
• Delivery Optimization.
• Apple and Android updates.

Labs / Practical Exercises (if applicable):
• Configure antivirus, firewall, encryption, and attack-surface reduction policies.
• Integrate Intune with Microsoft Defender for Endpoint.
• Review endpoint vulnerabilities and remediation recommendations.
• Create and monitor a Windows update-management strategy.

This module covers the complete application-management lifecycle in Microsoft Intune. Participants prepare, deploy, update, monitor, configure, and protect applications across managed and unmanaged devices and integrate application controls with Microsoft Entra Conditional Access.

Lessons:
Prepare applications for deployment: evaluate application requirements, package Win32 applications, configure detection and requirement rules, define dependencies and supersedence, and prepare line-of-business applications.
Deploy and update applications: distribute Win32, line-of-business, Microsoft Store, Microsoft 365, Apple Volume Purchase Program, and managed Google Play applications.
Manage Microsoft 365 Apps: deploy applications through Intune or Windows Autopilot, configure Office policies, use the Office Deployment Tool, and administer applications through the Microsoft 365 Apps admin center.
Implement application protection: create app protection policies for managed and unmanaged devices, configure data-transfer and access requirements, and implement Conditional Access for protected applications.
Configure and monitor applications: implement app configuration policies, configure Quiet Time where supported, monitor deployment status, and troubleshoot application installation failures.

Key Topics:
• Win32 applications.
• Line-of-business applications.
• Microsoft Store applications.
• Detection and requirement rules.
• Dependencies and supersedence.
• Microsoft 365 Apps.
• Office Deployment Tool.
• Apple Volume Purchase Program.
• Managed Google Play.
• App protection policies.
• Mobile application management.
• App configuration policies.
• Conditional Access.
• Application monitoring and troubleshooting.

Labs / Practical Exercises (if applicable):
• Package and deploy a Windows application through Microsoft Intune.
• Configure application requirements, detection rules, and assignments.
• Create an app protection and app configuration policy.
• Monitor an application deployment and troubleshoot installation failures.

This module focuses on improving endpoint-management operations through automation, AI-assisted analysis, reporting, monitoring, Endpoint Analytics, and proactive remediation. Participants use PowerShell, Microsoft Graph, Microsoft Security Copilot, and Intune reporting capabilities to manage endpoints at scale.

Lessons:
Automate Intune management: use PowerShell and Microsoft Graph to retrieve information, manage resources, perform bulk operations, and extend device-compliance processes.
Use Microsoft Security Copilot agents: investigate endpoint threats, analyze device performance, review AI-generated recommendations, and apply human validation to management decisions.
Implement Intune reporting: customize reports and filters, use workbooks and dashboards, export reporting data, and establish operational visibility across managed endpoints.
Monitor endpoint health and performance: use Endpoint Analytics to evaluate startup performance, restart frequency, application reliability, device health scores, anomalies, and user-experience indicators.
Implement proactive remediations: create detection and remediation scripts, schedule execution, monitor results, and resolve recurring endpoint issues automatically.
Monitor tenant operations: review service-health dashboards and message-center notifications and configure alerts for compliance drift, enrollment failures, and policy conflicts.

Key Topics:
• PowerShell automation.
• Microsoft Graph.
• Bulk management operations.
• Custom compliance.
• Microsoft Security Copilot.
• Intune agents.
• AI-assisted recommendations.
• Intune reports.
• Workbooks and dashboards.
• Endpoint Analytics.
• Device health scores.
• Application reliability.
• Proactive remediations.
• Service health.
• Operational alerts.
• Compliance and configuration drift.

Labs / Practical Exercises (if applicable):
• Automate an Intune administrative task using PowerShell or Microsoft Graph.
• Evaluate a Security Copilot recommendation for an endpoint scenario.
• Analyze device health and user-experience data through Endpoint Analytics.
• Create and monitor a proactive remediation for a recurring endpoint issue.

Recommended Courses

Levels
Beginner Intermediate Advance Applied Skills
AB-900: Introduction to Microsoft 365 and AI AdministrationMD-102: Microsoft 365 Endpoint AdministratorMD-4011: Enhance endpoint security with Microsoft Intune and Microsoft Security CopilotMS-700: Manage collaboration and communication with Microsoft TeamsMS-102: Microsoft 365 AdministratorMS-4017: Manage and extend Microsoft 365 CopilotMS-721: Plan, configure, and manage collaboration communications systems with Microsoft Teams
Career View

Frequently Asked Questions

If you see Register Now, the course is free and available for direct registration; simply complete the form to secure your seat.

If you see More Information, share your contact details and an ITG Learning Advisor will contact you to confirm pricing, available dates, delivery options, and next steps.

We’ll help you find the right fit. Select More Information, and one of our ITG Learning Advisors will present other available dates, related courses, delivery formats, and learning paths based on your goals.

BlockSkill is ITG’s learning and skilling platform. It brings your learning experience together in one place, giving you access to your enrolled courses, learning materials, available videos, activities, surveys, progress information, and certificates of completion.

Available resources may vary depending on the course and delivery format.

An exam voucher is a code or authorization that covers one attempt at an official certification exam. A practice assessment is included only when it is specifically listed as part of the selected package.

To earn the official certification, you must pass the corresponding vendor exam or assessment. Ask an ITG Learning Advisor whether the exam voucher is included with your course.

Yes. You may purchase an exam voucher without enrolling in the related course, subject to vendor availability, exam eligibility, and regional conditions.

Our team can help you identify the correct voucher for your certification goal and explain the available purchasing options.

ITG offers private and customized training for teams, businesses, government agencies, and other organizations. We can help you select the right courses and coordinate schedules, delivery formats, and learning paths aligned with your organization’s goals.

Select More Information to connect with an ITG Learning Advisor and explore the best training option for your team

Ready to start?
Get certified.

Join the next live cohort of AI+ Everyone™ and earn your industry-recognized credential.

Professional learning on a laptop
×

Stripe Checkout