課堂錄影隨時睇 10 大優點之免費試讀:無條件免費試讀,讓您毋須擔心錄影課程及導師質素,信心保證!

Microsoft 365 Certified Endpoint Administrator Associate (1科終端設備管理) 國際認可證書課程
課程簡稱:Microsoft Endpoint Administrator Training Course

在校免費重睇: 學員可於享用時期內於報讀地點不限次數地重看課堂錄影,從而可反覆重溫整個課程!
導師解答: 學員可於觀看某一課堂錄影後提出課堂直接相關的問題,課程導師會樂意為學員以單對單的形式解答!
課時: 30 小時
享用時期: 10 星期。進度由您控制,可快可慢。
課堂錄影導師: Larry (任教課程清單)
在校觀看: 詳情及示範片段

導師解答: 學員可於觀看某一課堂錄影後提出課堂直接相關的問題,課程導師會樂意為學員以單對單的形式解答!
課時: 30 小時
在家觀看時禁用程式: 一些危害課堂錄影版權的程式。
享用時期: 10 星期。進度由您控制,可快可慢。
課堂錄影導師: Larry (任教課程清單)
在家觀看: 服務條款及守則、報讀程序及示範片段

地區 地址 電話 教育局註冊編號
旺角 九龍旺角亞皆老街 109 號,皆旺商業大廈 18 樓 1802 - 1807 室 2332-6544 533459
觀塘 九龍觀塘成業街 7 號寧晉中心 12 樓 G2 室 3563-8425 588571
北角 香港北角馬寶道 41-47 號華寶商業大廈 3 樓 01-02 號舖 3580-1893 591262
沙田 新界沙田石門安群街 3 號京瑞廣場 1 期 10 樓 M 室 2151-9360 604488
屯門 新界屯門屯喜路 2 號屯門柏麗廣場 17 樓 1708 室 3523-1560 592552
注意! 客戶必須查問報讀學校的教育局註冊編號,以確認該校為註冊學校,以免蒙受不必要的損失!

本中心是 Microsoft 認可的合作夥伴 (Microsoft Certified Partner)。

如果您是負責部署及管理以 Microsoft 365 雲端及混合式環境為基礎的各式各樣終端設備,此 Endpoint Administrator Associate 認證便是專為您而設計。

身為此認證的應試者,您會具備終端設備管理的專業知識,能夠在 Microsoft 365 環境中部署、設定、保護、管理及監視終端設備和應用程式。您會:

  • 管理終端設備的身份識別、安全性、存取權、原則、更新和應用程式。
  • 實作解決方案,以便在各種作業系統、平台和終端設備上有效率地部署及管理。
  • 使用 Microsoft Intune、Windows 365、Windows Autopilot、適用於端點的 Microsoft Defender及 Microsoft Entra ID,大規模地部署及管理終端設備。

身為終端設備管理員,您會與架構師、Microsoft 365 管理員、安全性系統管理員及其他工作負載管理員合作,以規劃及實施符合商業需求的現代化工作場所 (Modern Workplace)。

修畢本課程,您便能具備 Microsoft Entra ID 和 Microsoft 365 技術 (包括 Intune) 的經驗,以及部署、設定和維護 Windows 用戶端和非 Windows 裝置的強大技能和經驗。

Microsoft 365 Certified Endpoint Administrator Associate

"Microsoft 365 Certified Endpoint Administrator Associate" 是一項中級認證,它是相應的 Fundamental 級別認證的下一步。


  1. 增強職業前景

獲得 Microsoft 365 端點管理員認證大大提高了你的就業能力和職業發展機會。這項認證證明了你的專業知識,使你成為晉升至更高職位的亮眼候選人。

  1. 深入的知識和專業技能

這項認證確保你對在 Microsoft 365 環境中部署、配置、保護、管理和監控終端設備和應用程式有全面的了解。這些知識涵蓋了各種操作系統、平台和設備類型,使你成為多才多藝且有價值的 I.T. 人才。

  1. 認可和可信度

全球有超過14億終端設備執行 Microsoft Windows (資料來源:Microsoft 年度財務報告),而獲得全球雲端服務領導者及最大份額商業終端設備供應商 - Microsoft的認證必能增強你的專業可信度,並表明你已達到高標準的卓越,並且致力於在快速發展的技術領域中保持現代化的技能。

  1. 實踐技能發展


  1. 熟識使用先進工具和技術

作為認證的 Microsoft 365 終端設備管理員,你將熟練使用如 Microsoft Intune、Windows Autopilot、Microsoft Defender for Endpoint 和 Microsoft Entra ID 等先進工具。這些工具對於大規模高效的終端設備管理至關重要,使你能夠簡化操作並增強企業的安全性。

  1. 個人滿足和信心


About the course

本課程將考試主題與現實生活中的例子、實際示範和商業案例互相結合,從而學懂在最新操作系統中實施、驗證和維護各種 Microsoft 365 和混合環境終端設備管理功能。

在整個培訓課程中,我們將口頭提供對不同 Microsoft 365 產品的評估、優缺點,以及可能的比較。由於 Microsoft 365 已經與多個第三方供應商建立合作關係及網絡安全生態系統,因此,課程中會用一小部份時間來簡要討論熱門合作夥伴的安全解決方案,並將其整合到 Microsoft 365 的商務雲端環境中。

我們的資深導師 Mr. Larry Chan 將就各種 Microsoft 365 相關產品提供建議、技巧和貼士。

課程名稱: Microsoft 365 Certified Endpoint Administrator Associate (1科終端設備管理) 國際認可證書課程
- 簡稱:Microsoft Endpoint Administrator Training Course
課程時數: 30 小時 (共 10 堂,共 1 科)

對現代化工作場所 (Modern Workplace) 相關雲端及終端設備技術有興趣人士 或 欲考取Microsoft 365 Certified Endpoint Administrator Associate 認證人士。


  • TCP/IP Networking
  • DNS administration
  • PowerShell usage

而已完成本中心的 Microsoft Certified 365 Fundamentals 認證課程 人士 或 Microsoft Certified Azure Virtual Desktop Specialty 認證課程 人士 均可直接參與本課程。

授課語言: 以廣東話為主,輔以英語
課程筆記: 本中心導師親自編寫英文為主筆記,而部份英文字附有中文對照。

1. 模擬考試題目: 本中心為學員提供模擬考試題目,每條考試題目均附有標準答案。
2. 時數適中:

本中心的 Microsoft 365 Certified Endpoint Administrator Associate (1 科終端設備管理) 國際認可證書課程時數適中,有 30 小時。

令學員能真正了解及掌握課程內容,而又能於短時間內考獲以下 1 張國際認可證書:

  • Microsoft 365 Certified Endpoint Administrator Associate
3. 導師親自編寫筆記: 由本中心已擁有五項 MCITP , 十多項 MCTS,MCSA 及 MCSE 資格,並有教授 Microsoft 相關課程 24年以上經驗的資深導師 Larry Chan 親自編寫筆記,絕對適合考試及實際管理之用,令你無須「死鋤」如字典般厚及不適合香港讀書格調的書本。
4. 一人一機上課: 本課程以一人一機模式上課。
5. 免費重讀: 傳統課堂學員可於課程結束後三個月內免費重看課堂錄影。

Microsoft 已公佈只要通過以下 1 個 Microsoft 365 相關科目的考試,便可獲發 Microsoft 365 Certified Endpoint Administrator Associate 國際認可證書:

考試編號 科目名稱
MD-102 Endpoint Administrator

本中心為Microsoft指定的考試試場。報考時請致電本中心,登記欲報考之科目考試編號、考試日期及時間 (最快可即日報考)。臨考試前要出示身份證及繳付每科 HK$1,025 之考試費。


考試合格後會收到來自Microsoft的作實電郵,並進入該電郵內的連結,登入 Microsoft Credentials Dashboard 下載您的證書。

考試不合格便可重新報考,不限次數。欲知道作答時間、題目總數、合格分數等詳細考試資料,可瀏覽本中心網頁 "各科考試分數資料"。

課程名稱:Microsoft 365 Certified Endpoint Administrator Associate (1科終端設備管理) 國際認可證書課程
- 簡稱:Microsoft Endpoint Administrator Training Course

MD-102 Microsoft 365 Administrator (30 hrs)

1. Exploring Enterprise Desktop
1.1 Introduction to Enterprise Desktop Environment
1.2 Examine benefits of modern management
1.3 Examine the enterprise desktop life-cycle model
1.4 Examine planning and purchasing
1.5 Examine desktop deployment
1.5.1 Building
1.5.2 Deployment
1.5.3 Enrollment
1.5.4 Data Migration
1.6 Plan an application deployment
1.6.1 Application inventory and compatibility
1.6.2 Application packaging
1.6.3 Application life-cycle support
1.6.4 Application Delivery
1.6.5 Microsoft Intune
1.6.6 Virtual Application Delivery
1.7 Plan for upgrades and retirement
1.7.1 Retirement
1.7.2 BYOD and Unenrollment

2. Exploring Windows Editions
2.1 Examine Windows client editions and capabilities
2.2 Windows edition details
2.2.1 Home
2.2.2 Pro
2.2.3 Pro for Workstations
2.2.4 Enterprise
2.2.5 Enterprise LTSC
2.2.6 Pro Education and Education
2.2.7 IoT Core/Enterprise
2.3 Select client edition
2.3.1 Form factors
2.3.2 32-bit and 64-bit editions
2.3.3 Scenarios
2.4 Examine hardware requirements
2.4.1 OS requirements
2.4.2 Feature-specific requirements
2.4.3 Device drivers
2.4.4 Check for Hyper-V compatibility

3. Understand Microsoft Entra ID
3.1 Introduction to Microsoft Entra ID
3.1.1 Microsoft Entra tenants
3.1.2 Microsoft Entra schema
3.2 Compare Microsoft Entra ID and Active Directory Domain Services
3.2.1 Characteristics of AD DS
3.2.2 Characteristics of Microsoft Entra ID
3.3 Examine Microsoft Entra ID as a directory service for cloud apps
3.4 Compare Microsoft Entra ID P1 and P2 plans
3.5 Introduction to Microsoft Entra Domain Services

4. Manage Microsoft Entra Identities
4.1 Examine RBAC and user roles in Microsoft Entra ID
4.1.1 Azure delegation model and role-based access control
4.1.2 User roles in Microsoft Entra ID
4.2 Create and manage users in Microsoft Entra ID
4.2.1 If you don’t wish to add users now
4.2.2 If you don’t want to license user now
4.3 Create and manage groups in Microsoft Entra ID
4.3.1 Manage a Microsoft 365 group
4.3.2 Strategies for Microsoft 365 Groups creation
4.3.3 Microsoft 365 Groups naming policy
4.3.4 Prefix-suffix naming policy
4.3.5 Custom blocked words
4.3.6 Configure Microsoft 365 groups naming policy using Microsoft Entra admin center
4.3.7 User experiences with naming policy
4.3.8 Configure Access with Entra ID Security Groups
4.3.9 Creating a Basic Group and add members
4.4 Manage Microsoft Entra objects with Microsoft Graph PowerShell
4.4.1 Connecting to Microsoft Entra with Microsoft Graph PowerShell SDK
4.4.2 Create users by using bulk import
4.5 Synchronize objects from AD DS to Microsoft Entra ID
4.6 Authentication options for the hybrid identity model
4.6.1 Password hash synchronization (PHS)
4.6.2 Pass-through authentication (PTA)
4.6.3 Federated authentication
4.7 Explore directory synchronization
4.8 Prepare for directory synchronization
4.8.1 Source of authority
4.8.2 Active Directory cleanup
4.8.3 UPN suffixes
4.8.4 Microsoft 365 IdFix tool
4.9 Comparing Directory Synchronization tools
4.9.1 Microsoft Entra Connect Sync
4.9.2 Microsoft Entra ID Tenant requirement
4.9.3 Microsoft Entra Connect Sync server
4.9.4 SQL Server used by Microsoft Entra Connect Sync
4.9.5 Accounts
4.9.6 Connectivity
4.9.7 Outbound proxy server requirements
4.9.8 Hardware requirements for Microsoft Entra Connect Sync
4.10 Configuring Microsoft Entra Connect Sync with Express Setup
4.11 Monitoring AD Connect Synchronization Health
4.11.1 Microsoft Entra Connect Sync Insight
4.11.2 Sync Latency
4.11.3 Sync Object Changes

5. Managing Device Authentication
5.1 Introduction to Microsoft Entra join
5.1.1 Usage Scenarios for Microsoft Entra join
5.1.2 Microsoft Entra hybrid join
5.2 Microsoft Entra join prerequisites limitations and benefits
5.3 Join devices to Microsoft Entra ID
5.4 Manage devices joined to Microsoft Entra ID

6. Enroll devices using Microsoft Configuration Manager
6.1 Deploy the Microsoft Configuration Manager client
6.1.1 Benefits of the Configuration Manager client
6.1.2 Client Deployment Options
6.2 Monitor the Microsoft Configuration Manager client
6.3 Manage the Microsoft Configuration Manager client
6.3.1 What is a Collection?

7. Enroll devices using Microsoft Intune
7.1 Manage mobile devices with Intune
7.1.1 Intune Company Portal
7.1.2 Device Management Lifecycle
7.2 Enable mobile device management
7.2.1 Activate MDM Services
7.2.2 Configure Intune for Apple Device Support
7.3 Considerations for device enrollment
7.3.1 To enable Windows Automatic Enrollment
7.3.2 Supported Devices
7.3.3 Define Allowed Devices
7.3.4 Ensure Users Enroll Their Devices
7.4 Manage corporate enrollment policy
7.4.1 To add and verify your custom domain
7.4.2 Configure automatic MDM enrollment
7.4.3 Simplify Manual Enrollment (Optional)
7.5 Enroll Windows devices in Intune
7.5.1 Enrolling Windows devices
7.6 Enroll Android devices in Intune
7.7 Android Enterprise
7.7.1 Android Enterprise work profile
7.7.2 Connect your Intune account to your managed Google Play account
7.8 Enroll iOS devices in Intune
7.8.1 Company-owned iOS devices
7.8.2 To setup the above Automated Device Enrollment for iOS in Intune (無須進行,理解便可)
7.8.3 Get an Apple automated device enrollment token
7.8.4 Create an Apple enrollment profile
7.8.5 Sync managed devices
7.8.6 Assign an enrollment profile to devices
7.8.7 Assign a default profile
7.8.8 Distribute devices
7.8.9 Re-enroll a device
7.8.10 Renew an Automated Device Enrollment token
7.8.11 Delete an Automated Device Enrollment token from Intune
7.9 Explore device enrollment manager
7.9.1 Example of a device enrollment manager scenario
7.9.2 What can a device enrollment manager do?
7.9.3 Limitations of devices that are enrolled with a DEM account
7.9.4 Add a device enrollment manager
7.9.5 Permissions for DEM
7.10 Monitor device enrollment
7.10.1 Monitoring enrolled devices
7.10.2 Monitoring Microsoft Entra joined devices
7.11 Manage devices remotely

8. Execute device profiles
8.1 Intune device profiles
8.1.1 Types of device profiles
8.2 Create device profiles
8.3 Create a custom device profile
8.3.1 Create a custom profile for Windows 10 and later devices
8.3.2 OMA-URIs
8.3.3 Create a custom profile for Android devices
8.3.4 Create a custom profile for Apple devices

9. Monitoring Device Profiles
9.1 Monitor device profiles in Intune
9.1.1 View existing profiles
9.1.2 View details on a profile
9.1.3 View conflicts
9.2 Manage device sync in Intune
9.2.1 Manage settings and features on your devices with Intune policies
9.3 Manage devices in Intune using scripts
9.3.1 Create a PowerShell script policy for Windows
9.3.2 Create a shell script policy for macOS

10. Managing User Profile
10.1 Windows user profile
10.2 User Profile Types
10.2.1 Local user profiles
10.2.2 Roaming user profiles
10.2.3 Mandatory user profiles
10.2.4 Temporary User Profiles
10.2.5 Profile extension for each Windows version
10.3 Options for minimizing user profile size
10.3.1 Use quotas
10.3.2 Redirect folders out of user profiles
10.3.3 Use Group Policy to limit user profile sizes
10.3.4 Deploy and configure folder redirection
10.4 Sync user state with Enterprise State Roaming
10.4.1 Sync user data
10.4.2 ESR and Microsoft Edge (Chromium based)
10.4.3 About Legacy User Experience Virtualization
10.5 Configure Enterprise State Roaming in Entra ID
10.5.1 What data roams?
10.5.2 Data storage
10.5.3 Data retention
10.5.4 Explicit deletion
10.5.5 Stale data deletion
10.5.6 Deleted data recovery

11. Mobile Application Management (MAM)
11.1 Two Scenarios of MAM
11.2 Considerations for Mobile Application Management
11.3 Prepare line-of-business apps for app protection policies
11.3.1 Intune App Wrapping Tool
11.3.2 Intune App SDK
11.3.3 Apps without app protection policies
11.3.4 Data protection with app protection policies
11.3.5 Data protection with app protection policies on devices managed by a Mobile Device Management solution
11.3.6 Data protection with app protection policies for devices without enrollment
11.4 Implement mobile application management policies in Intune
11.4.1 Understand app data protection
11.4.2 Data Transfer for iOS/iPadOS/Android app protection policy
11.4.3 Encryption
11.4.4 Functionality for iOS/iPadOS and Android app protection policy
11.4.5 App Protection Policy Access Requirements
11.4.6 App Protection Policy Conditional Launch
11.4.7 App Protection Policy Health Checks
11.5 Verify and Monitor App Protection
11.5.1 Intune diagnostics

12. Deploy and Update applications
12.1 Deploy applications with Intune
12.1.1 Microsoft Intune app lifecycle
12.2 Adding apps to Intune
12.3 Prepare and Manage Win32 apps with Intune
12.4 Deploy applications with Configuration Manager
12.4.1 Application deployment in Configuration Manager
12.4.2 Create an application in Configuration Manager
12.4.3 Choosing a solution for deploying an application
12.5 Deploying applications with Group Policy
12.5.1 Use Group Policy to manage the software lifecycle
12.5.2 How Windows Installer enhances software distribution
12.5.3 Manage software upgrades by using Group Policy
12.5.4 Publishing Software to Users
12.5.5 Assigning Software to Users
12.5.6 Assigning Software to Computers
12.6 Microsoft Store for Business
12.6.1 Add an app from the Microsoft Store
12.7 Update Microsoft Store Apps with Intune
12.7.1 App update
12.7.2 Microsoft Store Win32 apps
12.7.3 Intune management of Microsoft Store Win32 apps
12.8 Assign apps to company employees
12.9 Additional Microsoft 365 Apps Deployment Tools
12.9.1 Configuration Manager
12.9.2 Use the Office Deployment Tool
12.9.3 Use the Office Customization Tool
12.9.4 End-user installation
12.10 Configure Microsoft Edge Internet Explorer mode
12.10.1 Microsoft Edge with IE mode
12.10.2 Configure IE Mode Sites
12.11 App Inventory Review
12.11.1 Apps > Overview page
12.11.2 Apps > Monitor > App licenses page
12.11.3 Apps > Monitor > Discovered apps page
12.11.4 Apps > Monitor > App install status page

13. Device Compliance
13.1 Protect access to resources using Intune
13.2 Explore device compliance policy
13.2.1 Device Compliance policy basics:
13.2.2 Use Microsoft Entra device groups for policies
13.3 Deploy a device compliance policy
13.4 Entra Conditional Access with Intune
13.5 Entra Conditional Access and Exchange ActiveSync protocol

14. Windows Autopilot
14.1 Autopilot for modern deployment
14.1.1 New devices
14.1.2 Refresh existing devices
14.1.3 Autopilot compared to traditional methods
14.2 Requirements for Windows Autopilot
14.3 Prepare Device IDs for Autopilot
14.3.1 Manage Windows Autopilot in Intune
14.3.2 Prepare a Microsoft Autopilot deployment
14.3.3 Get the CSV file from your OEM partner
14.3.4 Generate your own CSV file
14.3.5 Upload the device-specific CSV file
14.3.6 Import a device hash directly into Intune
14.3.7 Enroll Windows devices in Intune by using the Windows Autopilot
14.3.8 Assigning a user to a specific Autopilot Device
14.4 Troubleshooting Windows Autopilot
14.4.1 Troubleshoot Autopilot OOBE issues
14.4.2 Windows Autopilot Diagnostics
14.4.3 Troubleshoot Entra ID join issues
14.4.4 Troubleshoot Intune enrollment issues
14.4.5 Troubleshoot Device Import

15. Windows Information Protection
15.1 Explore Windows Information Protection
15.1.1 Data loss prevention
15.1.2 Information Rights Management
15.2 Plan Windows Information Protection
15.3 Implement and use Windows Information Protection
15.3.1 Create a WIP policy in Intune
15.4 About BitLocker

16. Manage Microsoft Defender for Endpoint
16.1 Explore Microsoft Defender for Endpoint
16.2 Key Capabilities of Microsoft Defender for Endpoint
16.2.1 Attack surface reduction
16.2.2 Next generation protection
16.2.3 Endpoint detection and response
16.2.4 Auto investigation and remediation
16.2.5 Secure score
16.2.6 Advanced hunting
16.2.7 Management and APIs
16.3 Windows Defender Application Control and Device Guard
16.3.1 Windows Defender Application Control
16.3.2 Windows Defender Device Guard
16.4 Microsoft Defender Application Guard
16.4.1 Types of devices that should use Application Guard
16.5 Microsoft Defender Exploit Guard features


