This is an example of a simple banner

Training: Manage and secure Microsoft 365 endpoints by using Intune (MD-102)

Ref. MD-102T00
Duration:
5
 jours
Exam:
Optionnel
Level:
Intermédiaire

Manage and secure Microsoft 365 endpoints with Intune Training (MD-102)

Managing workstations, mobile devices and endpoint security has become a major challenge with the widespread adoption of hybrid work. The Microsoft Endpoint Administrator training (MD-102) prepares you in five days to deploy, configure and secure Windows, iOS and Android devices with Microsoft Intune, Windows Autopilot and compliance policies. You will master modern endpoint management to ensure user productivity while maintaining your organization security.

Delivered by an MCT-certified instructor at ITTA in Geneva or Lausanne, this MD-102 training combines theoretical lectures and hands-on labs on the official Microsoft cloud environment. You will work on concrete deployment scenarios with Windows Autopilot, application management with Intune, compliance policy configuration and enterprise data protection. By the end of these five intensive days, you will be prepared for the MD-102 Microsoft 365 Endpoint Administrator certification exam.

Participant Profiles

  • Cloud Security Specialist
  • Cloud Administrator

Objectives

  • Deploy and manage Windows devices with Microsoft Intune and Windows Autopilot
  • Configure configuration profiles, compliance policies and conditional access
  • Manage enterprise applications: deployment, updates and data protection (MAM)
  • Implement endpoint security with Microsoft Defender for Endpoint and security baselines
  • Administer Windows updates and deployment rings with Windows Update for Business
  • Manage iOS, Android and macOS devices in a multi-platform environment

Prerequisites

  • To have functional experience with Microsoft 365 workloads and with Microsoft Azure Active Directory (Azure AD)
  • To have implemented security for Microsoft 365 environments, including hybrid environments
  • To have a working knowledge of Windows clients, Windows servers, Active Directory, and PowerShell

Course Content

Module 1: Understand endpoint management strategies and Microsoft Intune

  • What is Microsoft Intune and how does it work?
  • Compare Configuration Manager, Intune, and co-management
  • Understand the role of Microsoft Entra ID in Intune
  • Evaluate device management models
  • Explore MDM capabilities in Intune

Module 2: Configure Microsoft Entra ID for device and policy management

  • Understand the role of Microsoft Entra ID in endpoint management
  • Create and manage users and groups in Microsoft Entra ID
  • Assign Microsoft Entra ID roles for device management
  • Configure Microsoft Entra ID device registration settings
  • Use dynamic group membership and filters in Microsoft Entra ID

Module 3: Administer device identity and authentication using Microsoft Entra ID

  • Understand device identities in Microsoft Entra ID
  • Compare device registration, Microsoft Entra join, and hybrid join
  • Understand authentication methods—key trust, certificate trust, and TPM
  • Configure device trust and join settings
  • Validate and troubleshoot device identity and trust issues

Module 4: Plan and implement device enrollment using Microsoft Intune

  • Choose an enrollment strategy
  • Enroll Windows devices using Microsoft Intune
  • Enroll iOS and iPadOS devices
  • Enroll macOS devices
  • Enroll Android devices
  • Configure enrollment restrictions
  • Troubleshoot device enrollment

Module 5: Deploy Windows devices using Windows Autopilot

  • Understand Windows Autopilot scenarios and benefits
  • Register and import devices into Autopilot
  • Configure Autopilot profiles and deployment modes
  • Pre-provision devices using Autopilot
  • Assign profiles and monitor Autopilot deployments
  • Troubleshoot Autopilot deployment issues

Module 6: Configure device profiles and policy management using Microsoft Intune

  • Understand device configuration profiles and their role in policy enforcement
  • Create configuration profiles
  • Assign configuration profiles using groups and filters
  • Create compliance policies
  • Assign compliance policies using groups and filters
  • Analyze and migrate Group Policy using Group Policy analytics
  • Troubleshoot device configuration and policy application issues

Module 7: Monitor and maintain devices using Microsoft Intune

  • Understand the role of monitoring in endpoint management
  • Use Endpoint Analytics to monitor device health and performance
  • Use Remediations to fix common device issues
  • Monitor Windows Update rings and feature update deployments
  • View device and policy health in the Intune admin center
  • Generate and interpret device and compliance reports
  • Automate management tasks using PowerShell

Module 8: Manage Windows updates and lifecycle using Microsoft Intune

  • Understand the Windows servicing model and update types
  • Implement update rings and feature update policies in Intune
  • Configure and manage Hotpatch with Microsoft Intune
  • Manage Windows servicing channels for enterprise devices
  • Implement Windows Autopatch for automated update management
  • Troubleshoot update deployment and compliance issues
  • Retire and reset devices using Microsoft Intune

Module 9: Troubleshoot device and policy issues using Microsoft Intune

  • Understand the troubleshooting workflow in Microsoft Intune
  • Troubleshoot device enrollment and compliance failures
  • Troubleshoot configuration profile and policy conflicts
  • Use logs and diagnostics to investigate device issues
  • Use the Intune Troubleshooting blade for user-based diagnostics
  • Automate issue resolution using remediation scripts

Module 10: Deploy and manage applications using Microsoft Intune

  • Example scenario
  • Understand application deployment options in Microsoft Intune
  • Plan application deployment for your organization
  • Deploy Microsoft Store apps using Microsoft Intune
  • Deploy Microsoft 365 apps using Microsoft Intune
  • Deploy Win32 apps using Microsoft Intune
  • Deploy line-of-business (LOB) apps using Microsoft Intune
  • Configure app availability, targeting, and install behavior
  • Configure app update and assignment settings
  • Monitor app deployment and troubleshoot failures
  • Manage app deployment failures using logs and troubleshooting tools
  • Key takeaways

Module 11: Implement application protection and security using Microsoft Intune

  • Understand Mobile Application Management (MAM) and App Protection Policies
  • Plan application protection strategies for BYOD and corporate devices
  • Configure App Protection Policies for unenrolled BYOD devices
  • Configure App Protection Policies for enrolled corporate devices
  • Define data protection, encryption, and app restriction settings
  • Define access requirements and conditional launch behaviors
  • Configure Conditional Access policies for application access control
  • Assign and monitor App Protection Policies
  • Troubleshoot application protection policy issues

Module 12: Manage application lifecycle and user experience using Microsoft Intune

  • Understand application lifecycle management in Microsoft Intune
  • Update and retire applications in Microsoft Intune
  • Assign applications using groups, filters, and targeting
  • Manage user and device groups for application delivery
  • Configure default application settings and user experience
  • Enforce compliance requirements for applications
  • Monitor app lifecycle and usage analytics

Module 13: Monitor and optimize application performance using Microsoft Intune

  • Understand app health and performance in modern environments
  • Monitor app deployment and compliance using Intune
  • Track installation success and failure reports
  • Use Endpoint Analytics to measure app performance and startup times
  • Use Intune reporting tools to identify and resolve performance issues
  • Optimize user experience with actionable insights

Module 14: Manage Enterprise App Catalog applications

  • Discover and deploy apps from the catalog
  • Configure default install and detection settings
  • Monitor updates and supersedence
  • Use the Managed Apps report for insights

Module 15: Implement endpoint security with Microsoft Defender and Microsoft Intune

  • Understand how Microsoft Defender protects endpoints
  • Onboard devices to Microsoft Defender using Intune
  • Configure Microsoft Defender endpoint security settings and baselines
  • Configure Endpoint Detection and Response policies
  • Investigate and respond to endpoint threats using Microsoft Defender
  • Monitor and triage incidents in the Microsoft Defender portal

Module 16: Implement device encryption and security policies using Microsoft Intune

  • Understand the importance of device encryption for compliance and security
  • Configure BitLocker policies using Microsoft Intune
  • Manage BitLocker recovery keys and user self-service options
  • Monitor BitLocker compliance and encryption status in Microsoft Intune
  • Audit device encryption with Microsoft Defender

Module 17: Implement advanced threat protection using Microsoft Intune and Microsoft Defender

  • Understand advanced threat protection strategies for endpoint environments
  • Discover and monitor cloud apps with Microsoft Defender
  • Configure Attack Surface Reduction rules using Microsoft Intune
  • Apply Zero Trust principles for endpoint protection

Module 18: Enforce compliance and remediate security issues by using Microsoft Intune

  • Understand compliance policies and risk-based enforcement
  • Create compliance policies for supported platforms
  • Assign and scope compliance policies using groups and filters
  • Configure actions for noncompliant devices
  • Remediate device issues using compliance and configuration policies
  • Monitor and report on compliance results

Module 19: Secure mobile access using Microsoft Tunnel

  • Configure Tunnel gateway
  • Extend support to MAM devices
  • Monitor and troubleshoot Tunnel connections

Module 20: Implement Microsoft Cloud PKI

  • Set up cloud-based PKI
  • Automate certificate issuance and renewal
  • Monitor certificate health and compliance

Module 21: Automate endpoint management using PowerShell and Microsoft Graph

  • Understand automation options for managing Microsoft Intune
  • Register and secure Microsoft Graph API access for Intune
  • Authenticate and use the Microsoft Graph API for Intune
  • Use PowerShell to run scripts against Microsoft Intune
  • Automate device and policy tasks using Microsoft Graph
  • 08 – Summary

Module 22: Optimize device management using AI and Copilot tools

  • Understand the role of AI in modern endpoint management
  • Use Microsoft Security Copilot to investigate threats
  • Use AI-powered recommendations in Microsoft Intune
  • Use Microsoft Defender insights to support endpoint decisions

Module 23: Monitor and optimize endpoint performance using Microsoft Intune

  • Understand performance optimization in cloud-managed environments
  • Use Endpoint Analytics to optimize device performance
  • Configure remediation scripts using Microsoft Intune
  • Monitor endpoint reliability and user experience with Endpoint Analytics

Module 24: Implement reporting and data visibility using Microsoft Intune

  • Understand built-in reporting options in Microsoft Intune
  • Customize Intune reports and filters for actionable insights
  • Use Microsoft Intune workbooks and dashboards
  • Export, schedule, and share reporting data securely

Module 25: Apply RBAC and admin delegation in Microsoft Intune

  • Understand RBAC and scope tags in Microsoft Intune
  • Assign roles and permissions for multi-admin environments
  • Configure scoped administration for regional or business unit separation
  • Audit admin actions and monitor configuration changes

Module 26: Maintain tenant health and support readiness

  • Monitor tenant health and Intune service communications
  • Configure alerts and notifications in Microsoft Intune
  • Use support tools and troubleshoot service-related issues
  • Document tenant changes and establish operational baselines

Module 27: Explore Microsoft Intune Suite capabilities

  • Understand the purpose and value of the Microsoft Intune Suite
  • Identify key components of the Microsoft Intune Suite
  • Compare Microsoft Intune Suite features to core Intune capabilities
  • Plan licensing and deployment strategies for the Microsoft Intune Suite

Module 28: Implement Remote Help scenarios using Microsoft Intune

  • Understand Remote Help and its role in end-user support
  • Configure and deploy Remote Help with Microsoft Intune
  • Support and monitor Remote Help sessions
  • Evaluate privacy, permission, and compliance considerations

Module 29: Analyze advanced device signals with Microsoft Intune Suite

  • Explore advanced reporting with Intune Suite analytics
  • Identify and respond to anomaly detection insights
  • Integrate Intune with Microsoft Defender for proactive threat signals
  • Use advanced insights to support risk-based policy decisions

Module 30: Evaluate Endpoint Privilege Management with Microsoft Intune

  • Understand just-in-time elevation in Endpoint Privilege Management
  • Configure elevation policies and rules
  • Monitor elevated actions and review reports
  • Troubleshoot and refine an EPM deployment

Module 31: Explore Windows 365 for cloud PC deployment

  • Understand the role of Windows 365
  • Compare Windows 365 to traditional VDI
  • Identify Windows 365 licensing, service plans, and prerequisites
  • Identify Windows 365 use cases
  • Explore the Windows 365 endpoint experience

Module 32: Configure and manage Windows 365 with Microsoft Intune

  • Set up Windows 365 provisioning policies
  • Assign and manage Cloud PCs
  • Apply configuration profiles and policies to Cloud PCs
  • Monitor Cloud PC usage, performance, and health

Module 33: Explore Azure Virtual Desktop

  • Understand Azure Virtual Desktop architecture
  • Compare Azure Virtual Desktop with Windows 365
  • Examine host pools, session hosts, and scaling

Module 34: Integrate Azure Virtual Desktop with Microsoft Intune

  • Enroll Azure Virtual Desktop session hosts in Microsoft Intune
  • Apply compliance and configuration policies to session hosts
  • Monitor and troubleshoot Azure Virtual Desktop with Microsoft Intune
  • Address governance, licensing, and hybrid scenarios

Documentation

  • Access to Microsoft Learn (online learning content)

Lab / Exercises

  • Official Microsoft Labs

Exam

  • This course prepares you to the MD-102: Endpoint Administrator exam.

Complementary Courses

Eligible Funding

ITTA is a partner of a continuing education fund dedicated to temporary workers. This fund can subsidize your training, provided that you are subject to the “Service Provision” collective labor agreement (CCT) and meet certain conditions, including having worked at least 88 hours in the past 12 months.

Additional Information

Become a certified MD-102 endpoint administrator

The MD-102 certification validates your ability to deploy, configure and manage endpoints in a Microsoft 365 environment. As organizations in Switzerland transition to hybrid work models, demand for qualified endpoint administrators continues to grow. This certification proves you can manage devices, applications and security across Windows, iOS, Android and macOS using Microsoft Intune and related technologies.

At ITTA in Geneva and Lausanne, the MD-102 training is delivered over five days by an MCT-certified instructor with real-world enterprise experience. The training includes hands-on labs on the official Microsoft cloud environment.

Microsoft Intune: modern device management

Microsoft Intune is the cloud-based platform at the heart of modern endpoint management. The MD-102 training covers device enrollment (automatic, bulk, user-driven), configuration profiles for managing device settings, compliance policies for enforcing security requirements and application deployment and protection. You will learn to manage the complete device lifecycle from enrollment to retirement.

The training also covers co-management with Configuration Manager for organizations transitioning from on-premises management to cloud-based management with Intune.

Windows Autopilot and zero-touch deployment

Windows Autopilot transforms device provisioning. The training teaches you to configure Autopilot profiles for user-driven and self-deploying scenarios, register devices, customize the out-of-box experience (OOBE) and integrate Autopilot with Intune for automated policy and application deployment. You will master pre-provisioning (white glove) for IT teams that prepare devices before delivery.

These skills are essential for organizations that need to deploy devices at scale while minimizing IT intervention and maintaining a consistent user experience.

Endpoint security and Microsoft Defender

Endpoint security is a central component of the MD-102 training. You will learn to configure Microsoft Defender for Endpoint, deploy security baselines, manage attack surface reduction rules and implement endpoint detection and response (EDR). The training covers threat investigation, automated investigation and remediation, and integration with Microsoft 365 Defender.

Compliance policies and conditional access are also covered in depth: you will configure rules that restrict access to corporate resources based on device compliance status, user risk level and location.

Update management and Windows lifecycle

Managing Windows updates in an enterprise environment requires a structured strategy. The MD-102 training covers Windows Update for Business configuration, deployment rings, feature update management and driver updates with Intune. You will learn to balance security (rapid patching) and stability (gradual rollout) for your device fleet.

The training also addresses Windows 365 Cloud PC and Azure Virtual Desktop for virtual endpoint scenarios, giving you a complete view of the modern desktop management landscape.

FAQ

What are the prerequisites for the MD-102 training?

Experience in Windows administration, Microsoft 365 cloud concepts and IT security basics is recommended. The MS-900 or MD-900 certification can serve as a good prerequisite.

Is the MD-102, in the training?

The training prepares you for the official Microsoft certification exam, which can be taken after completing the course

Does the training cover SCCM (Configuration Manager)?

The MD-102 training covers co-management between Intune and Configuration Manager for migration scenarios. The main focus is on Microsoft Intune as the modern cloud management platform.

Is the training available as a virtual class?

Yes, in person in Geneva or Lausanne, or as a virtual class with the same MCT instructor and the same Microsoft cloud labs.

What is the difference between MD-102 and Intune alone?

MD-102 covers the full scope of endpoint management: Intune, Windows Autopilot, Defender for Endpoint, update management, application deployment and security. Intune is a central component of this training, but the program goes well beyond MDM management alone.

What certifications complement MD-102?

MS-102 (Microsoft 365 Administrator) covers overall Microsoft 365 administration. SC-200 (Security Operations) and SC-300 (Identity and Access) provide complementary skills in security and identity management.

Is MD-102 suitable for managing Apple and Android devices?

Yes. The training covers iOS, iPadOS, Android and macOS device management with Intune, in addition to Windows. You will learn to configure enrollment, configuration profiles and compliance policies for each platform.

Prix de l'inscription
CHF 3'650.-
Inclus dans ce cours
  • Training provided by a certified trainer
  • 180 days of access to Official Microsoft Labs
  • Official documentation in digital format
  • Official Microsoft achievement badge
Mois actuel

lun19Oct(Oct 19)09:00ven23(Oct 23)17:00VirtuelVirtual Etiquettes de sessionMD-102T00

lun19Oct(Oct 19)09:00ven23(Oct 23)17:00Genève, Route des Jeunes 35, 1227 Genève Etiquettes de sessionMD-102T00

lun23Nov(Nov 23)09:00ven27(Nov 27)17:00VirtuelVirtual Etiquettes de sessionMD-102T00

lun23Nov(Nov 23)09:00ven27(Nov 27)17:00Lausanne, Av. Mon-Repos 24, 1005 Lausanne Etiquettes de sessionMD-102T00

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday
8:30 AM to 6:00 PM
Tel. 058 307 73 00

Contact-us

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Make a request

Contact

ITTA
Route des jeunes 35
1227 Carouge, Suisse

Opening hours

Monday to Friday, from 8:30 am to 06:00 pm.

Contact us

Your request