MD-102 · Protect devices

Configure endpoint security

Objective 3.1 · Configure endpoint security.

3 learning blocksNext: about 12 minutes8 key conceptsPreview · not independently reviewed
ProgressNot started0/3 blocks learned and checked
Learn

Continue your lesson

Trace device identity, enrollment, assignment, policy evaluation, deployment, and reporting as separate stages.

0/3blocks complete
Block 1 of 3

Compare Security baseline · Endpoint detection and response policy

Current · 12 min
Learn with your providerOpen a provider lesson below, then return to try four related questions.
Optional concept notes

Security baseline

Applies a Microsoft-recommended group of endpoint security settings from one profile.

Endpoint detection and response policy

Onboards supported devices to collect endpoint telemetry for post-breach detection, investigation, and response.

Your sessionabout 12 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 2 of 3

Compare Microsoft Defender Antivirus policy · Microsoft Defender Firewall policy · Attack surface reduction rules

18 min
Optional concept notes

Microsoft Defender Antivirus policy

Configures real-time protection, malware scan behavior, exclusions, and cloud-delivered protection.

Microsoft Defender Firewall policy

Controls firewall profiles and connection behavior on managed Windows endpoints.

Attack surface reduction rules

Blocks or audits risky behaviors commonly used by malware and malicious scripts.

Your sessionabout 18 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

Block 3 of 3

Compare Disk encryption policy · Account protection policy · Windows LAPS policy

15 min
Optional concept notes

Disk encryption policy

Configures BitLocker requirements recovery information and encryption behavior.

Account protection policy

Manages local groups Windows Hello and credential protection settings.

Windows LAPS policy

Rotates and stores a unique managed local administrator password for each device.

Your sessionabout 15 minutes

Complete one provider lesson, then answer four related questions. That is enough for today; more practice is optional.

No setup required

Practice the reasoning here

Build a small fictional pilot. Map each user, device, group, policy, and report before deciding where a failed deployment should be repaired.

  1. State the expected result before changing or testing anything.
  2. Name the observation, command, log, or report that would confirm it.
  3. Explain why the closest alternative does not fit the same requirement.
Your next milestone

Check the whole objective

This unlocks objective 3.1 for recall. The latest checkpoint needs 70% or higher; a lower result puts the lesson back near the front of your timeline.

One lesson at a time.Your block checks prepare you for this milestone. A score of 70% or higher advances the course; finishing a practice session completes your daily goal.
Official blueprint references
Official Endpoint Administrator certification overviewMicrosoft ↗Official MD-102 study guideMicrosoft ↗