Microsoft 365 Endpoint Administrator

3 days
md-102
3 days

Upcoming Sessions

Date:

Format:

Price:

Location:

Book now

Date:

Format:

Price:

Location:

Book now

Date:

Format:

Price:

Location:

Book now

Date:

Format:

Price:

Book now

Need a private training for your team?  Request a private training

Not ready to book yet?   Request an offer

Understand endpoint management strategies and Microsoft Intune

Introduces Microsoft Intune, management models (cloud-only, hybrid, co-managed), and how Microsoft Entra ID supports device management.

  • What is Microsoft Intune and how does it work?
  • Compare Configuration Manager, Intune, and co-management
  • Understand the role of Microsoft Entra ID in Intune
  • Evaluate device management models
  • Explore MDM capabilities in Intune

Configure Microsoft Entra ID for device and policy management

Configure user and device identity, admin roles, registration settings, and dynamic groups to support Intune policy targeting.

  • Understand the role of Microsoft Entra ID in endpoint management
  • Create and manage users and groups in Microsoft Entra ID
  • Assign Microsoft Entra ID roles for device management
  • Configure Microsoft Entra ID device registration settings
  • Use dynamic group membership and filters in Microsoft Entra ID

Administer device identity and authentication using Microsoft Entra ID

Explore device object lifecycle, join types, trust models, and troubleshooting join and authentication failures in Microsoft Entra ID.

  • Understand device identities in Microsoft Entra ID
  • Compare device registration, Microsoft Entra join, and hybrid join
  • Understand authentication methods—key trust, certificate trust, and TPM
  • Configure device trust and join settings
  • Validate and troubleshoot device identity and trust issues

Plan and implement device enrollment using Microsoft Intune

Covers enrollment strategy selection, step-by-step platform enrollment guidance for Windows, iOS/iPadOS, macOS, and Android, plus enrollment restrictions and troubleshooting.

  • Choose an enrollment strategy
  • Enroll Windows devices using Microsoft Intune
  • Enroll iOS and iPadOS devices
  • Enroll macOS devices
  • Enroll Android devices
  • Configure enrollment restrictions
  • Troubleshoot device enrollment

Deploy Windows devices using Windows Autopilot

Covers Windows Autopilot registration, deployment profiles, pre-provisioning, monitoring, and common troubleshooting scenarios.

  • Understand Windows Autopilot scenarios and benefits
  • Register and import devices into Autopilot
  • Configure Autopilot profiles and deployment modes
  • Pre-provision devices using Autopilot
  • Assign profiles and monitor Autopilot deployments
  • Troubleshoot Autopilot deployment issues

Configure device profiles and policy management using Microsoft Intune

Configure and assign device configuration and compliance policies, and analyze Group Policy migrations using Microsoft Intune.

  • Understand device configuration profiles and their role in policy enforcement
  • Create configuration profiles
  • Assign configuration profiles using groups and filters
  • Create compliance policies
  • Assign compliance policies using groups and filters
  • Analyze and migrate Group Policy using Group Policy analytics
  • Troubleshoot device configuration and policy application issues

Monitor and maintain devices using Microsoft Intune

Use Endpoint Analytics, proactive remediation, reporting, and automation to monitor and maintain device health and compliance.

  • Understand the role of monitoring in endpoint management
  • Use Endpoint Analytics to monitor device health and performance
  • Use Remediations to fix common device issues
  • Monitor Windows Update rings and feature update deployments
  • View device and policy health in the Intune admin center
  • Generate and interpret device and compliance reports
  • Automate management tasks using PowerShell

Manage Windows updates and lifecycle using Microsoft Intune

Configure update rings, feature updates, Hotpatch, and Autopatch to manage Windows servicing and lifecycle using Intune.

  • Understand the Windows servicing model and update types
  • Implement update rings and feature update policies in Intune
  • Configure and manage Hotpatch with Microsoft Intune
  • Manage Windows servicing channels for enterprise devices
  • Implement Windows Autopatch for automated update management
  • Troubleshoot update deployment and compliance issues
  • Retire and reset devices using Microsoft Intune

Troubleshoot device and policy issues using Microsoft Intune

Investigate and resolve device enrollment, configuration, and policy application issues using Intune diagnostics and remediation techniques.

  • Understand the troubleshooting workflow in Microsoft Intune
  • Troubleshoot device enrollment and compliance failures
  • Troubleshoot configuration profile and policy conflicts
  • Use logs and diagnostics to investigate device issues
  • Use the Intune Troubleshooting blade for user-based diagnostics
  • Automate issue resolution using remediation scripts

Deploy and manage applications using Microsoft Intune

Plan and deploy applications across Windows devices using Microsoft Intune, including Microsoft Store, Microsoft 365, Win32, and line-of-business apps.

  • Example scenario
  • Understand application deployment options in Microsoft Intune
  • Plan application deployment for your organization
  • Deploy Microsoft Store apps using Microsoft Intune
  • Deploy Microsoft 365 apps using Microsoft Intune
  • Deploy Win32 apps using Microsoft Intune
  • Deploy line-of-business (LOB) apps using Microsoft Intune
  • Configure app availability, targeting, and install behavior
  • Configure app update and assignment settings
  • Monitor app deployment and troubleshoot failures
  • Manage app deployment failures using logs and troubleshooting tools
  • Key takeaways

Implement application protection and security using Microsoft Intune

Plan, configure, assign, monitor, and troubleshoot Microsoft Intune Mobile Application Management (MAM) and App Protection Policies to secure corporate data on BYOD and corporate devices.

  • Understand Mobile Application Management (MAM) and App Protection Policies
  • Plan application protection strategies for BYOD and corporate devices
  • Configure App Protection Policies for unenrolled BYOD devices
  • Configure App Protection Policies for enrolled corporate devices
  • Define data protection, encryption, and app restriction settings
  • Define access requirements and conditional launch behaviors
  • Configure Conditional Access policies for application access control
  • Assign and monitor App Protection Policies
  • Troubleshoot application protection policy issues

Manage application lifecycle and user experience using Microsoft Intune

Learn how to manage applications across the full Microsoft Intune lifecycle, including deployment, configuration, protection, monitoring, update, and retirement.

  • Understand application lifecycle management in Microsoft Intune
  • Update and retire applications in Microsoft Intune
  • Assign applications using groups, filters, and targeting
  • Manage user and device groups for application delivery
  • Configure default application settings and user experience
  • Enforce compliance requirements for applications
  • Monitor app lifecycle and usage analytics

Monitor and optimize application performance using Microsoft Intune

Monitor application health, deployment status, and performance across managed devices using Microsoft Intune reports and Endpoint analytics.

  • Understand app health and performance in modern environments
  • Monitor app deployment and compliance using Intune
  • Track installation success and failure reports
  • Use Endpoint Analytics to measure app performance and startup times
  • Use Intune reporting tools to identify and resolve performance issues
  • Optimize user experience with actionable insights

Manage Enterprise App Catalog applications

Discover, deploy, configure, update, and monitor prepackaged Win32 applications from the Microsoft Intune Enterprise App Catalog.

  • Discover and deploy apps from the catalog
  • Configure default install and detection settings
  • Monitor updates and supersedence
  • Use the Managed Apps report for insights

Implement endpoint security with Microsoft Defender and Microsoft Intune

Onboard devices to Microsoft Defender with Microsoft Intune, configure security baselines and EDR policies, and investigate and triage incidents in the Microsoft Defender portal.

  • Understand how Microsoft Defender protects endpoints
  • Onboard devices to Microsoft Defender using Intune
  • Configure Microsoft Defender endpoint security settings and baselines
  • Configure Endpoint Detection and Response policies
  • Investigate and respond to endpoint threats using Microsoft Defender
  • Monitor and triage incidents in the Microsoft Defender portal

Implement device encryption and security policies using Microsoft Intune

Deploy and manage BitLocker device encryption on Windows endpoints using Microsoft Intune, including policy configuration, recovery key management, and compliance monitoring.

  • Understand the importance of device encryption for compliance and security
  • Configure BitLocker policies using Microsoft Intune
  • Manage BitLocker recovery keys and user self-service options
  • Monitor BitLocker compliance and encryption status in Microsoft Intune
  • Audit device encryption with Microsoft Defender

Implement advanced threat protection using Microsoft Intune and Microsoft Defender

Apply layered endpoint defenses by combining Microsoft Intune policy enforcement with Microsoft Defender for SaaS app discovery, Attack Surface Reduction rules, Zero Trust device access, and proactive remediation.

  • Understand advanced threat protection strategies for endpoint environments
  • Discover and monitor cloud apps with Microsoft Defender
  • Configure Attack Surface Reduction rules using Microsoft Intune
  • Apply Zero Trust principles for endpoint protection

Enforce compliance and remediate security issues by using Microsoft Intune

Design, assign, and monitor Microsoft Intune compliance policies, configure graduated noncompliance actions, and automate remediation for noncompliant devices.

  • Understand compliance policies and risk-based enforcement
  • Create compliance policies for supported platforms
  • Assign and scope compliance policies using groups and filters
  • Configure actions for noncompliant devices
  • Remediate device issues using compliance and configuration policies
  • Monitor and report on compliance results

Secure mobile access using Microsoft Tunnel

Learn how to deploy and manage Microsoft Tunnel Gateway to securely extend access to on-premises resources for enrolled and unenrolled mobile devices.

  • Configure Tunnel gateway
  • Extend support to MAM devices
  • Monitor and troubleshoot Tunnel connections

Implement Microsoft Cloud PKI

Stand up a cloud-hosted certificate authority hierarchy in Microsoft Intune, automate SCEP issuance and renewal, and monitor certificate health across managed devices.

  • Set up cloud-based PKI
  • Automate certificate issuance and renewal
  • Monitor certificate health and compliance

Automate endpoint management using PowerShell and Microsoft Graph

Automate Microsoft Intune operations at scale using PowerShell and the Microsoft Graph PowerShell SDK, including device management, policy assignment, and secure authentication.

  • Understand automation options for managing Microsoft Intune
  • Register and secure Microsoft Graph API access for Intune
  • Authenticate and use the Microsoft Graph API for Intune
  • Use PowerShell to run scripts against Microsoft Intune
  • Automate device and policy tasks using Microsoft Graph
  • 08 - Summary

Optimize device management using AI and Copilot tools

Use AI and Copilot tools across Microsoft Intune and Microsoft Defender to prioritize endpoint issues, investigate threats, and apply targeted remediation actions.

  • Understand the role of AI in modern endpoint management
  • Use Microsoft Security Copilot to investigate threats
  • Use AI-powered recommendations in Microsoft Intune
  • Use Microsoft Defender insights to support endpoint decisions

Monitor and optimize endpoint performance using Microsoft Intune

Monitor endpoint performance and implement proactive remediation using Microsoft Intune and Endpoint analytics.

  • Understand performance optimization in cloud-managed environments
  • Use Endpoint Analytics to optimize device performance
  • Configure remediation scripts using Microsoft Intune
  • Monitor endpoint reliability and user experience with Endpoint Analytics

Implement reporting and data visibility using Microsoft Intune

Access, customize, and share Microsoft Intune reports, workbooks, and dashboards to deliver actionable operational insights across your organization.

  • Understand built-in reporting options in Microsoft Intune
  • Customize Intune reports and filters for actionable insights
  • Use Microsoft Intune workbooks and dashboards
  • Export, schedule, and share reporting data securely

Apply RBAC and admin delegation in Microsoft Intune

Configure role-based access control, scope tags, role assignments, and auditing to delegate Microsoft Intune administration safely across your organization.

  • Understand RBAC and scope tags in Microsoft Intune
  • Assign roles and permissions for multi-admin environments
  • Configure scoped administration for regional or business unit separation
  • Audit admin actions and monitor configuration changes

Maintain tenant health and support readiness

Monitor Microsoft Intune tenant health, configure proactive alerts, use built-in support tools, and document changes to maintain operational readiness.

  • Monitor tenant health and Intune service communications
  • Configure alerts and notifications in Microsoft Intune
  • Use support tools and troubleshoot service-related issues
  • Document tenant changes and establish operational baselines

Explore Microsoft Intune Suite capabilities

Identify Microsoft Intune Suite add-on components, evaluate how they extend core Intune capabilities, and plan licensing and deployment strategies for advanced endpoint management scenarios.

  • Understand the purpose and value of the Microsoft Intune Suite
  • Identify key components of the Microsoft Intune Suite
  • Compare Microsoft Intune Suite features to core Intune capabilities
  • Plan licensing and deployment strategies for the Microsoft Intune Suite

Implement Remote Help scenarios using Microsoft Intune

Configure and deploy Microsoft Intune Remote Help, assign helper and sharer permissions, monitor support sessions, and evaluate privacy considerations for managed remote support.

  • Understand Remote Help and its role in end-user support
  • Configure and deploy Remote Help with Microsoft Intune
  • Support and monitor Remote Help sessions
  • Evaluate privacy, permission, and compliance considerations

Analyze advanced device signals with Microsoft Intune Suite

Use Microsoft Intune Suite Advanced Analytics, anomaly detection, and integration with Microsoft Defender to surface real-time device health and risk signals and drive risk-based policy decisions.

  • Explore advanced reporting with Intune Suite analytics
  • Identify and respond to anomaly detection insights
  • Integrate Intune with Microsoft Defender for proactive threat signals
  • Use advanced insights to support risk-based policy decisions

Evaluate Endpoint Privilege Management with Microsoft Intune

Evaluate Microsoft Intune Endpoint Privilege Management — design just-in-time elevation, configure elevation policies, monitor elevated actions, and troubleshoot and refine the deployment.

  • Understand just-in-time elevation in Endpoint Privilege Management
  • Configure elevation policies and rules
  • Monitor elevated actions and review reports
  • Troubleshoot and refine an EPM deployment

Explore Windows 365 for cloud PC deployment

Explore Windows 365 — its role for cloud PC deployment, how it compares to traditional VDI, licensing and prerequisites, common use cases, and endpoint experience options like Windows 365 Boot and Switch.

  • Understand the role of Windows 365
  • Compare Windows 365 to traditional VDI
  • Identify Windows 365 licensing, service plans, and prerequisites
  • Identify Windows 365 use cases
  • Explore the Windows 365 endpoint experience

Configure and manage Windows 365 with Microsoft Intune

Configure Windows 365 provisioning policies, assign and manage Cloud PCs, apply configuration profiles and security policies, and monitor Cloud PC usage, performance, and health with Microsoft Intune.

  • Set up Windows 365 provisioning policies
  • Assign and manage Cloud PCs
  • Apply configuration profiles and policies to Cloud PCs
  • Monitor Cloud PC usage, performance, and health

Explore Azure Virtual Desktop

Explore Azure Virtual Desktop architecture, compare it with Windows 365, and learn how host pools, session hosts, and scaling deliver virtualized Windows desktops and apps from Azure.

  • Understand Azure Virtual Desktop architecture
  • Compare Azure Virtual Desktop with Windows 365
  • Examine host pools, session hosts, and scaling

Integrate Azure Virtual Desktop with Microsoft Intune

Enroll Azure Virtual Desktop session hosts in Microsoft Intune, apply compliance and configuration policies, monitor and troubleshoot virtual desktops, and address governance, licensing, and hybrid scenarios.

  • Enroll Azure Virtual Desktop session hosts in Microsoft Intune
  • Apply compliance and configuration policies to session hosts
  • Monitor and troubleshoot Azure Virtual Desktop with Microsoft Intune
  • Address governance, licensing, and hybrid scenarios

In this course, students learn to plan and execute an endpoint deployment, configuration, and management strategy using Microsoft Intune as the unified endpoint management platform. The course covers preparing identity and device infrastructure with Microsoft Entra ID, enrolling and configuring devices, managing applications, and protecting endpoints and data. Students also explore automation with PowerShell and Microsoft Graph, AI-assisted management with Microsoft Security Copilot, the extended capabilities of the Microsoft Intune Suite, and the delivery of cloud-hosted desktops with Windows 365 and Azure Virtual Desktop. Technologies explored include Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Tunnel, Microsoft Cloud PKI, the Microsoft Intune Suite, Windows 365, and Azure Virtual Desktop.

As a candidate for this course and the associated exam, you have subject matter expertise managing devices and client applications in a Microsoft 365 tenant by using Microsoft Intune.  As an endpoint administrator, you collaborate with architects, Microsoft 365 administrators, security administrators, and other workload administrators to plan and implement a modern workplace strategy that meets the business needs of an organization. You are responsible for:

  • Implementing solutions for efficient deployment and management of endpoints on various operating systems, platforms, and device types.
  • Implementing and managing endpoints at scale by using Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Security Copilot, Microsoft Defender for Endpoint, Microsoft Entra ID, Azure Virtual Desktop, and Windows 365.
  • Implementing identity, security, access, policies, updates, and apps for endpoints.
Contact Us
  • Address:
    U2U
    Z.1 Researchpark 110
    1731 Zellik (Brussels)
    BELGIUM
  • Phone: +32 2 466 00 16
  • Email: info@u2u.be
  • Monday - Friday: 9:00 - 17:00
    Saturday - Sunday: Closed
Say Hi
© 2026 U2U All rights reserved.