
Microsoft 365 Endpoint Administrator (Aligned Courseware) Courseware (MD-102)
In this course, students will learn to plan and execute an endpoint deployment strategy using contemporary deployment techniques and implementing update strategies. The course introduces essential elements of modern management, co-management approaches, and Microsoft Intune integration. It covers app deployment, management of browser-based applications, and key security concepts such as authentication, identities, access, and compliance policies. Technologies like Azure Active Directory, Azure Information Protection, and Microsoft Defender for Endpoint are explored to protect devices and data.
Based on customer feedback and demand from Training Service Providers (Learning Partners) and Microsoft Certified Trainers (MCTs) in regards to the content on Microsoft Learn not meeting the demands of students in the classroom, Specialist Courseware made the commitment to author courseware that aligned directly to the Microsoft Official Courses.
The content is aligned almost identically with official courses, with some exceptions. Where we find deficiencies in the official courses based on the exam requirements, we may add or enhance content. Where PPT slides lack detail, these have been amended to create a rich and more engaging experience for the students.
Benefits
The Microsoft 365 Endpoint Administrator is responsible for deploying, configuring, securing, managing, and monitoring devices and client applications in a corporate setting. Their duties include managing identity, access, policies, updates, and apps. They work alongside the M365 Enterprise Administrator to develop and execute a device strategy that aligns with the requirements of a modern organization. Microsoft 365 Endpoint Administrators should be well-versed in M365 workloads and possess extensive skills and experience in deploying, configuring, and maintaining Windows 11 and later, as well as non-Windows devices. Their role emphasizes cloud services over on-premises management technologies.
Outline
- What is Microsoft Intune?
- Intune integration
- Enroll in device management, application management, or both
- Protect data on any device
- What is Microsoft Entra ID?
- What are the Entra ID editions?
- Compare Microsoft Entra ID with AD DS
- Demonstration: Compare AD DS and Entra ID
- What is Azure AD Domain Services?
- Built-in roles
- Custom roles
- Scoping the roles
- Managing RBAC roles
- Demonstration: Reviewing RBAC roles and administrative units
- Managing Microsoft 365 with Windows PowerShell
- Managing user accounts
- Managing Groups
- Demonstration: Creating security principals
- Lab: Managing identities in Azure AD
- What is Directory Synchronization?
- What is Azure AD Connect?
- What is Azure AD Cloud Sync?
- Considerations for directory synchronization
- Planning writeback options
- Configuring Azure AD Connect Sync
- Demonstration: Configuring Azure AD Connect sync
- Lab: Synchronizing Identities by using Azure AD Connect
- Prerequisites for Azure AD Join or Register
- What is Azure AD Join?
- What is Hybrid Azure AD Join?
- What is Azure AD Register?
- Demonstration: Performing Azure AD Join and Azure AD Register
- Lab: Configuring and managing Azure AD Join
- Lab: Manage Azure AD device registration
- Mobility is the new normal
- What’s driving change?
- Empowering enterprise mobility
- Why Intune?
- Enterprise Mobility Suite
- Device management challenges
- Enterprise mobility management with Intune
- Comprehensive lifecycle management
- Supported device operating systems
- Prerequisites for enrollment
- Enrollment restrictions
- Device enrollment managers
- Demonstration: Preparing for device enrollment
- Lab: Manage Device Enrollment into Intune
- Enrolling Windows devices
- Enrolling Android and iOS devices
- Demonstration: Enrolling devices
- Lab: Enrolling devices into Microsoft Intune
- Remote actions
- Remotely lock devices
- Reset or remove a passcode
- Remove devices with wipe or retire
- Perform a Fresh Start
- Remotely restart devices
- Apple device actions – Enable lost mode
- Communication – Send custom notifications in Intune
- Communication – Organizational messages
- Sync a device
- Use bulk device actions
- Demonstration: Performing remote actions
- Windows Admin Center
- Demonstration: Using Windows Admin Center
- PowerShell remoting
- Implement and manage LAPS in Entra ID
- Demonstration: Configuring LAPS
- Implement Remote Help in Intune
- Overview of Group Policy fundamentals
- Group Policy Objects
- Scoping GPOs
- Group Policy inheritance
- Administrative templates
- Demonstration: Reviewing Group Policy
- Reviewing supported operating systems and types of profile
- Creating device configuration profiles
- Using scope tags
- Using policy sets
- Demonstration: Implementing device configuration profiles
- Lab: Creating and deploying configuration profiles
- Creating a kiosk configuration profile
- Demonstration: Implementing kiosk mode
- Lab: Using a Configuration Profile to configure Kiosk mode
- Lab: Using a Configuration Profile to configure iOS and iPadOS Wi-Fi settings
- Migrating from Group Policy
- Lab: Using Group Policy Analytics to validate GPO support in Intune
- Monitor device profiles
- Manage device sync
- Understand conflicts
- Demonstration: Monitoring configuration profiles
- Lab: Monitor device and user activity in Intune
- Overview of Folder Redirection
- Overview of UE-V
- Overview of enterprise state roaming
- Demonstration: Reviewing user state sync options
- Overview of MAM
- Review the app lifecycle
- Methods for app deployment
- Demonstration: Reviewing app management
- Overview of Microsoft 365 Apps for enterprise
- Microsoft 365 Apps for enterprise vs. Office Professional 2021
- Internet requirements
- Microsoft 365 Apps for enterprise licensing and activation
- Customizing Click-to-Run options
- Using the Microsoft Apps admin center
- Creating a deployment configuration file
- Overview of the Office Deployment Tool
- Demonstration: Managing Microsoft 365 apps
- Deploying apps with Intune
- Deploying Microsoft 365 apps for Enterprise with Intune
- Demonstration: Deploying apps
- Lab: Deploying cloud apps using Intune
- Mobile Application Management options
- Demonstration: Managing apps
- Lab: Configure App Protection Policies for Mobile Devices
- Overview of remote access options
- What is a VPN?
- Configuring a VPN
- What is Microsoft Tunnel Gateway?
- Demonstration: Reviewing Microsoft Tunnel Gateway setup
- Managing multi-factor authentication
- Implementing Windows Hello in Intune
- Demonstration: Managing MFA
- Self-service password reset
- Demonstration: Managing SSPR
- Managing device compliance
- Demonstration: Configuring compliance policies
- Managing conditional access policies
- Demonstration: Configuring conditional access policies
- Lab: Configuring Multi-factor Authentication
- Lab: Configuring Self-service password reset for user accounts in Azure AD
- Lab: Configuring and validating device compliance
- Windows 11 security features
- Windows Firewall with Advanced Security
- Microsoft Defender Antivirus
- Demonstration: Implementing Microsoft Defender in Windows
- Overview of security baselines
- Endpoint detection and response
- Demonstration: Securing endpoints in Intune
- Lab: Configuring Endpoint security using Intune
- Implementing Data Loss Prevention
- Configuring BitLocker
- Demonstration: Implementing device data protection
- Lab: Configuring Disk Encryption Using Intune
- Overview of images
- Overview of image-based installation tools
- Creating, updating, and maintaining images
- Windows ADK for Windows 10/11
- Windows Deployment Services
- Microsoft Deployment Toolkit
- Creating images in MDT
- Deploying images in MDT
- Demonstration: Deploying Windows with MDT
- Lab: Deploying Windows 11 using Microsoft Deployment Toolkit
- Windows Autopilot
- Provisioning packages with Windows Configuration Designer
- Implementing subscription activation
- Azure AD join with automatic MDM enrollment
- Autopilot for modern deployments
- Device lifecycle management with Windows Autopilot and Intune
- Requirements for Windows Autopilot
- Preparing for Autopilot
- Demonstration: Preparing for Autopilot
- Registering devices
- Demonstration: Uploading device IDs
- Assigning an Autopilot deployment profile
- Demonstration: Creating a deployment profile
- Creating an enrollment status page
- Windows Autopilot Deployment Scenarios
- Demonstration: Deploying Windows with Autopilot
- Lab: Deploying Windows with Autopilot
- Lab: Refreshing Windows with Autopilot Reset and Self-Deploying mode
- What are the available Servicing Channels?
- Applying Windows updates
- Configuring Windows Update settings
- Using Group Policy to configure Windows updates
- Windows Server Update Services
- Managing updates with Intune
- What is Windows Autopatch?
- Delivery Optimization for Windows Updates
- Demonstration: Managing updates in Intune
- Supported upgrade paths
- Compare in-place upgrades with migrations
- The process for performing an in-place upgrade to Windows 11
- The process for migrating to Windows 11
- Setup Endpoint Analytics
- Explore Endpoint Analytics
- Demonstration: Using Endpoint Analytics
Required Prerequisites
None
License
Length: 5
days | $62.00 per copy
Labs providers: Skillable, go deploy
*When labs are available, they must be purchased from the lab provider.