About this Course

The MCA - Microsoft 365 Certified: Endpoint Administrator Associate course prepares IT professionals to manage, secure, and support modern devices using Microsoft Intune and Microsoft 365 technologies.

This five-day instructor-led MD-102 training, covers Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint, Conditional Access, Windows 365, Azure Virtual Desktop, PowerShell, and Microsoft Graph.

Participants gain practical skills in device enrollment, configuration, compliance, application deployment, endpoint security, monitoring, updates, and device lifecycle management—while preparing for the MD-102 certification exam.

Training Benefits

Your learning continues beyond the live class with:

  • 6 hours of consultation with a Microsoft Certified Trainer
  • Access to course recordings
  • Doubt-clearing sessions
  • Continued MD-102 exam preparation
  • MicroTrain Exam Pass Guarantee for eligible participants

MicroTrain Exam Pass Guarantee

Eligible participants who complete MicroTrain’s required exam-preparation activities before testing may qualify for additional exam support if they do not pass the MD-102 exam on their first attempt.

The MicroTrain Exam Pass Guarantee adds another layer of support to your Microsoft certification journey—helping you prepare thoroughly and approach the exam with greater confidence.

Eligibility requirements and program terms apply.

Outline

Course Outline

1. Prepare Infrastructure for Devices Using Microsoft Intune and Microsoft Entra ID

Build the foundation for modern endpoint management using Microsoft Intune and Microsoft Entra ID.

  • Understand endpoint management strategies and Microsoft Intune

  • Compare Configuration Manager, Intune, and co-management

  • Configure Microsoft Entra ID for device and policy management

  • Manage users, groups, roles, and device registration

  • Administer device identity and authentication

  • Compare Entra registration, Entra join, and hybrid join

  • Plan and implement device enrollment for Windows, iOS/iPadOS, macOS, and Android

  • Configure enrollment restrictions

  • Deploy Windows devices using Windows Autopilot

  • Configure Autopilot profiles, deployment modes, and pre-provisioning

  • Monitor and troubleshoot enrollment and Autopilot deployments

2. Manage and Maintain Devices Using Microsoft Intune

Configure, monitor, update, and troubleshoot managed devices throughout their lifecycle.

  • Create and assign device configuration profiles

  • Create and manage compliance policies

  • Use groups and filters for policy assignment

  • Analyze and migrate Group Policy using analytics

  • Monitor device health and performance with Endpoint Analytics

  • Use Remediations to address common device issues

  • Monitor Windows Update rings and feature updates

  • Generate and interpret device and compliance reports

  • Automate management tasks with PowerShell

  • Configure update rings and feature update policies

  • Manage Hotpatch and Windows Autopatch

  • Manage Windows servicing channels

  • Retire and reset devices

  • Troubleshoot enrollment, compliance, configuration, and policy conflicts

  • Use logs, diagnostics, and the Intune Troubleshooting blade

  • Automate issue resolution with remediation scripts

3. Manage Applications Using Microsoft Intune

Deploy, secure, monitor, and maintain applications across managed and unmanaged devices.

  • Plan application deployment strategies

  • Deploy Microsoft Store applications

  • Deploy Microsoft 365 Apps

  • Deploy Win32 and line-of-business applications

  • Configure application targeting, availability, and install behavior

  • Manage app updates and assignments

  • Monitor deployment status and troubleshoot failures

  • Implement Mobile Application Management (MAM)

  • Configure App Protection Policies for BYOD and corporate devices

  • Configure data protection, encryption, and app restrictions

  • Configure Conditional Access for application access

  • Manage application lifecycle and user experience

  • Monitor app health, performance, and usage

  • Use Endpoint Analytics and Intune reporting for application insights

  • Discover and deploy applications from the Enterprise App Catalog

  • Monitor application updates and supersedence

4. Protect Devices Using Microsoft Intune

Protect enterprise endpoints using Microsoft Intune, Microsoft Defender, compliance policies, and advanced security capabilities.

  • Implement Microsoft Defender for Endpoint with Intune

  • Onboard devices to Microsoft Defender for Endpoint

  • Configure security baselines

  • Configure Endpoint Detection and Response (EDR)

  • Investigate and respond to endpoint threats

  • Monitor and triage incidents using Microsoft Defender XDR

  • Configure BitLocker encryption policies

  • Manage BitLocker recovery keys

  • Monitor encryption and compliance status

  • Configure Attack Surface Reduction (ASR) rules

  • Apply Zero Trust principles to endpoint security

  • Use Microsoft Defender for Cloud Apps

  • Create and enforce device compliance policies

  • Remediate security and compliance issues

  • Configure Microsoft Tunnel for secure mobile access

  • Implement Microsoft Cloud PKI

  • Automate certificate issuance and renewal

5. Automate and Optimize Endpoint Management Using Microsoft Intune

Use automation, analytics, and AI-assisted tools to improve endpoint-management efficiency.

  • Automate Intune administration using PowerShell and Microsoft Graph

  • Register and secure Microsoft Graph API access

  • Authenticate and test Microsoft Graph API calls

  • Automate device and policy management tasks

  • Use Microsoft Security Copilot to investigate threats

  • Apply AI-powered recommendations in Microsoft Intune

  • Use Microsoft Defender insights to support endpoint decisions

  • Monitor endpoint performance with Endpoint Analytics

  • Configure remediation scripts

  • Monitor endpoint reliability and user experience

6. Support Operational Excellence and Readiness Using Microsoft Intune

Use reporting, administrative controls, and support tools to maintain a healthy Intune environment.

  • Use built-in Microsoft Intune reporting

  • Customize reports and filters

  • Use Intune workbooks and dashboards

  • Export, schedule, and securely share reporting data

  • Apply Role-Based Access Control (RBAC) and scope tags

  • Delegate administrative permissions

  • Configure scoped administration for business units or regions

  • Audit administrative actions and configuration changes

  • Monitor tenant health and Intune service communications

  • Configure alerts and notifications

  • Use Intune support and troubleshooting tools

  • Document tenant changes and establish operational baselines

7. Extend Endpoint Capabilities Using Microsoft Intune Suite

Explore advanced endpoint-management, security, support, and analytics capabilities available through Microsoft Intune Suite.

  • Understand Microsoft Intune Suite capabilities

  • Explore Remote Help

  • Explore Endpoint Privilege Management

  • Explore Advanced Analytics

  • Compare Intune Suite features with core Intune capabilities

  • Plan Intune Suite licensing and deployment

  • Configure and deploy Remote Help

  • Support and monitor Remote Help sessions

  • Analyze advanced device signals

  • Use anomaly detection insights

  • Integrate Intune data with Microsoft Defender for Endpoint

  • Use advanced insights for risk-based policy decisions

  • Configure Endpoint Privilege Management

  • Implement just-in-time elevation

  • Monitor elevated actions and user behavior

  • Troubleshoot Endpoint Privilege Management policies

8. Deliver Cloud-Hosted Desktops Using Azure Virtual Desktop and Windows 365

Extend endpoint management to Cloud PCs and virtual desktop environments.

  • Understand Windows 365 and its role in modern endpoint management

  • Compare Windows 365 with traditional PCs and VDI

  • Review Windows 365 licensing and prerequisites

  • Explore Windows 365 Boot, Switch, and remote-access experiences

  • Configure Windows 365 provisioning policies using Intune

  • Assign and manage Cloud PCs

  • Apply configuration profiles and policies to Cloud PCs

  • Monitor Cloud PC performance and device health

  • Understand Azure Virtual Desktop architecture

  • Compare Azure Virtual Desktop and Windows 365

  • Explore host pools, session hosts, and scaling options

  • Enroll Azure Virtual Desktop session hosts in Intune

  • Apply compliance and configuration policies to AVD session hosts

  • Monitor and troubleshoot Azure Virtual Desktop environments in Intune

  • Review governance and licensing considerations for hybrid deployments

Prerequisites

Required Experience

Microsoft states that participants must have prior experience with the following before taking this course:

  • Microsoft Entra ID
  • Microsoft 365 technologies
  • Microsoft Intune
  • Deploying, configuring, and maintaining Windows client devices
  • Deploying, configuring, and maintaining non-Windows devices
  • Participants should already have strong, hands-on endpoint administration experience and be comfortable supporting devices in a Microsoft 365 environment.

Recommended Knowledge

In addition to the required experience above, Microsoft states that participants should have an understanding of:

  • Microsoft Security Copilot
  • Intune agents
  • Microsoft Defender XDR

Who This Course Is Best For

This is an intermediate-level course designed for IT professionals who already have practical experience administering Microsoft 365 environments and managing      enterprise endpoints.

  • The course is especially appropriate for:
  • Endpoint Administrators
  • Microsoft Intune Administrators
  • Systems Administrators
  • Desktop Support Professionals
  • IT Support Engineers
  • Modern Workplace Administrators
  • Endpoint Security Specialists
  • Microsoft 365 Administrators

Because the course builds on existing Microsoft 365 and endpoint-management experience, it is not intended as an introductory course for someone with no prior exposure to Microsoft Entra ID, Microsoft Intune, or enterprise device administration.

Exam Details

Exam MD-102: End Point Administrator

Exam Pass Guarantee

At Microtrain we are committed to your success! Let us show you the return you get from great tech training. We will personally guarantee that if you take our class and follow our program you will be successfully certified!

Raves & Praise

Connect with MicroTrain

Begin building a successful long-term career pathway.

(630) 981-0200

Back to Top