Course ID: #MD-102

MD-102 Managing and Securing Microsoft 365 Endpoints by using Intune

Duration: 5 days Dates: 21 September 2026 9 November 2026

MD-102 is the course for modern workplace management with Microsoft Intune – and the successor to the two former courses MD-100 and MD-101. You set up device enrolment and compliance, roll out Windows clients via Autopilot, manage Windows, macOS, iOS and Android from a single console, secure endpoints with Defender, and control apps and updates. The course prepares you for the MD-102 exam (certification «Microsoft Certified: Endpoint Administrator Associate»).

Prepare the Infrastructure

  • Bring devices into Microsoft Entra ID: registration or Entra join, device groups with dynamic membership rules
  • Enrolment in Intune: settings, automatic enrolment for Windows, personal enrolment for macOS, iOS and iPadOS
  • Android enrolment profiles (fully managed, dedicated, work profile), Apple Business Manager, Samsung Knox and Google Zero Touch
  • Roles and scope tags for environments with multiple administrators, multi-stage approval
  • Compliance policies for all platforms, conditional access with compliance status, Windows Hello for Business, Windows LAPS, manage local groups

Manage Devices

  • Windows Autopilot: deployment profiles and device preparation policies, user-driven, pre-provisioned or self-deploying, naming templates, enrolment status page
  • Upgrade to Windows 11 via Intune, deploy Windows 365 Cloud PCs, Windows Backup and Restore
  • Configuration profiles for Windows (including ADMX import and Group Policy analytics), Android, iOS/iPadOS, macOS, and specialty devices such as Teams Rooms and HoloLens 2
  • Intune Suite: Endpoint Privilege Management, Enterprise App Catalog, Remote Help, Microsoft Cloud PKI, Microsoft Tunnel for MAM, Advanced Analytics
  • Remote actions: sync, restart, retire, reset, bulk actions, rotate BitLocker keys and local passwords, device diagnostics and queries with KQL

Protect Devices

  • Endpoint security: antivirus, disk encryption and firewall policies, attack surface reduction based on zero-trust principles, security baselines
  • Integration with Microsoft Defender for Endpoint: EDR policies, onboarding, investigate threats and triage incidents; App Control for Business
  • Control updates: update rings, feature and quality updates, Windows Autopatch and hotpatch, updates for iOS, macOS and Android, delivery optimisation, monitoring

Manage and Secure Applications

  • Deploy apps: Win32 apps, line-of-business apps, Microsoft Store apps, Microsoft 365 Apps – including as part of an Autopilot deployment
  • Apps from platform stores via the Apple Volume Purchase Program and Google Play, monitor deployment status and fix installation failures
  • App protection policies for managed and personal devices (BYOD), conditional access for app protection, app configuration policies

Automate and Monitor Operations

  • Automate Intune via PowerShell and Microsoft Graph, extend compliance through scripts
  • Security Copilot agents in Intune: investigate threats, analyse device performance, evaluate recommendations
  • Reports, workbooks and dashboards; Endpoint Analytics with proactive remediations, device health and startup performance
  • Monitor tenant status and service messages, alert rules for compliance deviations and enrolment failures
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar, Prüfungsvorbereitung

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/09/21, 2026/11/09, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, flexibel, auf Anfrage

Administrators who manage workplace devices and are moving from Group Policy and traditional software deployment to Intune.

Knowledge of Windows client administration is required, as well as basic knowledge of Microsoft 365 and Microsoft Entra ID.

After the course you will be able to:

  • enrol devices of all platforms in Intune and secure them with compliance policies
  • roll out Windows clients via Autopilot without an image and upgrade them to Windows 11
  • assign configuration profiles in a targeted way instead of spreading them broadly
  • harden endpoints with Defender for Endpoint, encryption and baselines
  • distribute apps and updates in a controlled way and monitor fleet health

Price range: CHF3'400 through CHF15'600 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation