Skip to main content

Microsoft 365 Endpoint Administrator (MD-102T00)

H37ZJS

Table of Contents

Table of Contents

    Course ID

    H37ZJS

    Duration

    5 days

    Format

    ILT/VILT

    Overview

    In this course, you learn how to plan and execute an endpoint deployment strategy using contemporary deployment techniques and implementing update strategies. The course introduces essential elements of modern management and Microsoft Intune integration. It covers app deployment, management of browser-based applications, and key security concepts such as authentication, identities, access, and compliance policies. Technologies like Microsoft Entra, Windows Autopilot, Microsoft Intune Suite and Microsoft Defender for Endpoint are explored to protect devices and data.

    Course ID

    H37ZJS

    Duration

    5 days

    Format

    ILT/VILT

    Audience

    This course is ideal for endpoint administrators, Microsoft 365 administrators, desktop support engineers, systems administrators, IT support specialists, and workplace technology professionals responsible for deploying, securing, managing, and monitoring devices and client applications in modern enterprise environments.

    Prerequisites

    Before attending this course, you should have:


    • Experience with Microsoft 365 workloads and services
    • Experience deploying, configuring, and maintaining Windows client devices
    • Basic understanding of Microsoft Entra ID and cloud identity concepts
    • Familiarity with endpoint management, device security, and compliance concepts
    • Basic knowledge of networking, authentication, and authorization technologies

    Objectives

    After completing this course, you should be able to:

    • Plan and implement modern endpoint deployment and management strategies using Microsoft 365 technologies.
    • Configure and manage Windows 11 and cross-platform devices through Microsoft Intune.
    • Enroll, provision, and deploy devices using Microsoft Intune, Windows Autopilot, and Microsoft Configuration Manager.
    • Manage identities, authentication, and access using Microsoft Entra ID.
    • Create and administer device configuration profiles, compliance policies, and security baselines.
    • Deploy, configure, and manage applications across enterprise devices.
    • Implement mobile application management (MAM) and mobile device management (MDM) solutions.
    • Protect organizational data through device security, compliance, and conditional access policies.
    • Configure and manage Microsoft Defender solutions to secure endpoints against threats.
    • Monitor device health, compliance, and inventory using reporting and analytics tools.
    • Plan and execute migration strategies from traditional on-premises management to modern cloud-based endpoint management.
    • Manage virtual desktop environments including Windows 365 and Azure Virtual Desktop.

    Certifications and related exams

    This course prepares you for the Microsoft 365 Certified: Endpoint Administrator Associate (MD102) certificate

    Divider

    Course outline

    Module 1: Explore the Enterprise Desktop

    Learn about modern endpoint management and enterprise desktop lifecycle concepts. You also examine the stages of the enterprise desktop lifecycle, including planning, deployment, maintenance, upgrades, and retirement.


    • Examine benefits of modern management
    • Examine the enterprise desktop lifecycle model
    • Examine planning and purchasing
    • Examine desktop deployment
    • Plan an application deployment
    • Plan for upgrades and retirement

    Module 2: Explore Windows Editions


    Learn about Windows operating system editions, capabilities, and installation methods. You also gain an understanding of edition selection and hardware requirements for Windows deployments.


    • Examine Windows client editions and capabilities
    • Select a client edition
    • Examine hardware requirements

    Module 3: Understand Microsoft Entra ID

    Learn about Microsoft Entra ID and its role in identity and access management. You also compare Microsoft Entra ID with Active Directory Domain Services and explore Microsoft Entra Domain Services for cloud-based device and application management.


    • Examine Microsoft Entra ID
    • Compare Microsoft Entra ID and Active Directory Domain Services
    • Examine Microsoft Entra ID as a directory service for cloud applications
    • Compare Microsoft Entra ID P1 and P2 plans
    • Examine Microsoft Entra Domain Services

    Module 4: Manage Microsoft Entra Identities


    How to manage identities in Microsoft Entra ID. You also explore role-based access control (RBAC), user and group management, Microsoft Graph PowerShell, and directory synchronization.


    • Examine RBAC and user roles in Microsoft Entra ID
    • Create and manage users in Microsoft Entra ID
    • Create and manage groups in Microsoft Entra ID
    • Manage Microsoft Entra objects with Microsoft Graph PowerShell
    • Synchronize objects from AD DS to Microsoft Entra ID

    Module 5: Manage Device Authentication


    Learn about device authentication and device management in Microsoft Entra ID. You also explore Microsoft Entra join and the requirements, benefits, and limitations associated with device enrollment and management.


    • Microsoft Entra join
    • Examine Microsoft Entra join prerequisites, limitations, and benefits
    • Join devices to Microsoft Entra ID
    • Manage devices joined to Microsoft Entra ID

    Module 6: Enroll Devices Using Microsoft Configuration Manager


    Learn about client deployment options and the management and monitoring capabilities available through Microsoft Configuration Manager.



    • Deploy the Microsoft Configuration Manager client
    • Monitor the Microsoft Configuration Manager client
    • Manage the Microsoft Configuration Manager client

    Module 7: Enroll Devices Using Microsoft Intune


    How to configure and use Microsoft Intune to manage Windows, Android, and iOS devices. You also explore device enrollment methods, enrollment policies, and remote device management capabilities.


    • Manage mobile devices with Intune
    • Enable mobile device management
    • Explain considerations for device enrollment
    • Manage corporate enrollment policy
    • Enroll Windows devices in Intune
    • Enroll Android devices in Intune
    • Enroll iOS devices in Intune
    • Explore Device Enrollment Manager
    • Monitor device enrollment
    • Manage devices remotely

    Module 8: Execute Device Profiles


    Learn about the different types of device profiles available in Microsoft Intune and how to create, customize, and manage them.


    • Explore Intune device profiles
    • Create device profiles
    • Create a custom device profile

    Module 9: Oversee Device Profiles


    How to monitor device profiles to ensure correct assignments and resolve conflicts when multiple profiles are applied to managed devices.


    • Monitor device profiles in Intune
    • Manage device sync in Intune
    • Manage devices in Intune by using scripts

    Module 10: Maintain User Profiles


    Learn about the benefits of different Windows user profiles, how to manage them, and how to synchronize profile data across multiple devices.


    • Examine user profiles
    • Explore user profile types
    • Examine options for minimizing user profile size
    • Deploy and configure folder redirection
    • Sync user state with Enterprise State Roaming
    • Configure Enterprise State Roaming in Azure

    Module 11: Execute Mobile Application Management


    Learn about Mobile Application Management (MAM), including implementation considerations and the management of mobile applications by using Microsoft Intune and Microsoft Configuration Manager.


    • Examine mobile application management
    • Examine considerations for mobile application management
    • Prepare line-of-business applications for app protection policies
    • Implement mobile application management policies in Intune
    • Manage mobile application management policies in Intune

    Module 12: Deploy and Update Applications

    How to deploy and manage applications by using Microsoft Intune, Microsoft Configuration Manager, Group Policy, and Microsoft Store applications. You also explore methods for updating and assigning applications across the organization.


    • Deploy applications with Intune
    • Add applications to Intune
    • Manage Win32 applications with Intune
    • Deploy applications with Microsoft Configuration Manager
    • Deploy applications with Group Policy
    • Assign and publish software
    • Explore Microsoft Store for Business
    • Implement Microsoft Store applications
    • Update Microsoft Store applications with Intune
    • Assign applications to company employees

    Module 13: Administer Endpoint Applications


    How to manage applications on Microsoft Intune-managed devices and explore application deployment options for Microsoft 365 applications. You also learn how to use Internet Explorer mode with Microsoft Edge.


    • Manage applications with Intune
    • Manage applications on non-enrolled devices
    • Deploy Microsoft 365 applications with Intune
    • Explore additional Microsoft 365 application deployment tools
    • Configure Microsoft Edge Internet Explorer mode
    • Review application inventory

    Module 14: Protect Identities in Microsoft Entra ID


    Learn about the authentication methods and identity protection capabilities available in Microsoft Entra ID. You also explore Windows Hello for Business, Microsoft Entra ID Protection, self-service password reset, and multifactor authentication.



    • Explore Windows Hello for Business
    • Deploy Windows Hello for Business
    • Manage Windows Hello for Business
    • Explore Microsoft Entra ID Protection
    • Manage self-service password reset in Microsoft Entra ID
    • Implement multifactor authentication

    Module 15: Enable Organizational Access

    How to configure client devices to access organizational resources securely by using virtual private network (VPN) technologies.



    • Enable access to organizational resources
    • Explore VPN types and configuration
    • Explore Always On VPN
    • Deploy Always On VPN

    Module 16: Implement Device Compliance


    How to use compliance policies and Conditional Access to help protect access to organizational resources and enforce security requirements on managed devices.



    • Protect access to resources by using Intune
    • Explore device compliance policies
    • Deploy a device compliance policy
    • Explore Conditional Access
    • Create Conditional Access policies

    Module 17: Generate Inventory and Compliance Reports


    How to use Microsoft Intune, Microsoft Endpoint Manager, Microsoft Graph API, and reporting tools to generate inventory, compliance, and custom reports.



    • Report enrolled device inventory in Intune
    • Monitor and report device compliance
    • Build custom Intune inventory reports
    • Access Intune by using Microsoft Graph API

    5 reasons to choose HPE as your training partner

    1. Learn HPE and in-demand IT industry technologies from expert instructors.
    2. Build career-advancing power skills.
    3. Enjoy personalized learning journeys aligned to your company’s needs.
    4. Choose how you learn: in-person, virtually, or online—anytime, anywhere.
    5. Sharpen your skills with access to real environments in virtual labs.

    Explore our simplified purchase options, including HPE Education Services – Learning Credits.

    Recommended for you