What MD-102 measures now
MD-102 is the required exam for Microsoft 365 Certified: Endpoint Administrator Associate. Microsoft describes an endpoint administrator who manages devices and client applications in a Microsoft 365 tenant with Microsoft Intune and agentic tools and workflows. The role implements endpoints at scale with Intune, Intune Suite, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Entra ID, PowerShell, Microsoft Graph, and Windows 365. It also manages identity, security, access, policies, updates, applications, automation, monitoring, and reporting.
The current study guide is explicit about multiplatform scope. Strong Windows knowledge remains essential, but Android, iOS, iPadOS, macOS, Teams Rooms, HoloLens 2, Zebra devices, and mobile application management appear in the objectives. Study the decision criteria—ownership, user affinity, platform, identity state, app boundary, risk, and operational support—rather than memorizing one Windows-only path.
Official weight 20-25%.
Official weight 25-30%.
Official weight 15-20%.
Official weight 15-20%.
Official weight 10-15%.
Those exact counts describe PrepKloud's independent 50-question MD-102 practice bank. They sit inside Microsoft's published ranges and do not predict the size or composition of a live exam.
Prepare infrastructure: separate every control plane
Device registration, join, enrollment, compliance, and cloud-resource access are separate decisions. A personal device can be Microsoft Entra registered. An organization-owned cloud-native Windows device can be Microsoft Entra joined. A device that preserves an on-premises Active Directory relationship can be hybrid joined. Intune enrollment adds management. Compliance evaluates state. Conditional Access consumes that signal and decides whether the identity and device can reach a selected application.
Automatic Windows enrollment depends on supported identity and licensing prerequisites plus the Intune MDM user scope. Device groups can be assigned or dynamic; dynamic rules evaluate supported Microsoft Entra properties. Group membership provides broad targeting, while Intune assignment filters can refine an assignment using supported device facts at evaluation time. Neither mechanism should be treated as instantaneous or infallible—monitor processing and validate a representative device.
Enrollment choices differ by platform and ownership. Apple Business Manager integrates with Intune for automated corporate Apple enrollment. Android Enterprise offers fully managed, dedicated, and corporate-owned work profile modes. Samsung Knox Mobile Enrollment and Android Zero Touch can help corporate provisioning. Enrollment restrictions provide a critical guardrail: block prohibited platforms or personally owned enrollment while preserving approved corporate paths.
Administration should be least privilege. Intune roles define allowed actions, scope groups define managed populations, and scope tags constrain visible resources. Multi Admin Approval adds a requester-and-approver workflow for supported changes. Windows Hello for Business provides key- or certificate-based authentication unlocked by a gesture. Windows LAPS manages unique rotating local administrator passwords. Local group membership policies provide controlled group changes without unmanaged scripts.
Deploy and maintain Windows and Cloud PCs
Windows Autopilot deployment profiles and device preparation policies are not interchangeable labels. Select the current supported approach from ownership, provisioning model, application and policy needs, hardware registration, and operational workflow. User-driven deployment expects a user to authenticate. Pre-provisioning lets a technician complete device-targeted work before delivery. Self-deploying mode fits supported userless or shared devices.
The Enrollment Status Page can block access until selected device or user configuration and required applications finish. It improves readiness only when blocking items are dependable. A brittle app detection rule can turn ESP into a provisioning deadlock. Keep the blocking list small, define timeout and support behavior, and test failure recovery.
Windows 365 provisioning policies combine supported image, network, and configuration decisions for Cloud PCs. Image management, network connections, licensing, provisioning status, and reprovisioning require separate evidence. Windows Backup and Restore can preserve supported settings and app information for the replacement experience, but it is not a substitute for organizational data protection or complete device backup.
Configuration profiles span Settings Catalog, templates, imported ADMX, and platform-specific payloads. Group Policy analytics helps assess GPO settings for modern management support. Establish one authoritative owner per setting; a security baseline does not automatically override a conflicting Settings Catalog profile. Conflicts require policy-source review and a deliberate effective value.
Use Intune Suite capabilities by requirement
Endpoint Privilege Management provides controlled elevation while the user remains a standard user. Define file identity, elevation type, audience, support ownership, and monitoring. Avoid broad publisher rules when a narrow file rule meets the need. Remote Help integrates supported assistance with organizational identity, role-based access, and session reporting. Test the helper's assigned role rather than granting broad tenant administration.
Microsoft Cloud PKI provides cloud-hosted certificate authority and issuance capabilities integrated with Intune. Design the hierarchy, certificate profiles, subject and SAN behavior, renewal, revocation, relying applications, and monitoring. Microsoft Tunnel for Mobile Application Management extends per-app connectivity to supported managed applications on unenrolled mobile devices. It is an app-level path, not full personal-device management.
The Enterprise App Catalog helps deploy supported prepackaged applications. Advanced Analytics adds anomaly detection, proactive insights, and risk-based recommendations where licensed. Product availability and licensing can change, so identify the problem each add-on solves and verify current prerequisites rather than assuming every Intune tenant contains every feature.
Remote actions and troubleshooting
Sync requests device check-in. Restart reboots. Retire removes managed organizational data where supported. Wipe resets the device according to chosen options. Always verify platform semantics, ownership, backup, activation locks, and authorization before a destructive action. Bulk actions increase blast radius and deserve additional approval.
BitLocker recovery-key rotation is appropriate after a recovery secret is disclosed. Windows LAPS password rotation serves the same broad principle for a local administrator secret. Device query uses KQL for supported on-demand Windows device facts. Collect diagnostics and Intune's Troubleshooting and support experience provide deeper evidence. Start from the affected user or device, assignment, status code, timestamp, and logs—do not delete every policy because one enrollment failed.
Protect endpoints with layered policy
Intune endpoint security includes antivirus, disk encryption, firewall, attack surface reduction, security baselines, EDR, account protection, and App Control. Each layer has different scope and evidence. Microsoft Defender Antivirus policy configures supported antimalware behavior. BitLocker policy manages encryption and recovery. Firewall policy manages network filtering. ASR rules reduce behaviors commonly abused by attacks. Use audit or warn modes where appropriate before broad blocking.
Connecting Intune to Microsoft Defender for Endpoint is separate from onboarding devices. The connector enables supported service integration; onboarding adds endpoint telemetry and response. Device risk can contribute to Intune compliance and Conditional Access. Investigate incidents in their proper context and do not assume an Intune policy report replaces Defender security evidence.
App Control for Business defines trusted code. Start with audit, collect representative application events, account for scripts, drivers, installers, updates, and managed installers, then enforce through rings. An incomplete allow policy can stop a business application or the management tools required to recover it.
Engineer updates rather than simply assigning them
Update rings govern supported Windows Update for Business behaviors such as deferrals, deadlines, restart experience, and quality update cadence. Feature update policies hold eligible devices to a selected Windows release. Quality update policies can expedite selected security updates. Windows Autopatch provides Microsoft-managed update orchestration for eligible environments. Hotpatch can reduce conventional restarts for eligible Windows editions and configurations.
Delivery Optimization controls peer-to-peer and download behavior. A branch-office design needs correct peer groups, network boundaries, cache expectations, and bandwidth measurement. The blueprint also covers iOS, iPadOS, and macOS update policies through supported Intune settings plus Android configuration or firmware-over-the-air approaches. Monitor update status and error detail rather than using assignment as proof of installation.
Deploy and secure applications
A Win32 app has a complete contract: source files, command lines, requirements, dependencies, return codes, detection, assignments, restart behavior, supersedence, uninstall, and troubleshooting. Detection rules answer whether Intune considers the application installed. Requirements answer whether the app applies. Dependencies define prerequisite apps. Supersedence defines replacement or update relationships. Confusing these concepts creates incorrect statuses and loops.
Use the correct source for Microsoft Store, Apple Volume Purchase Program, managed Google Play, line-of-business, and Microsoft 365 Apps deployments. Microsoft 365 Apps configuration includes architecture, applications, update channel, languages, and optional app settings. During Autopilot, avoid placing every productivity app on the critical ESP path.
App protection policies protect organizational data inside supported mobile apps, including unenrolled devices. They can control access requirements, data transfer, save-as, copy and paste, encryption, offline grace, and selective wipe. App configuration policies deliver supported application settings. Conditional Access can require a protected app for supported access. These controls complement one another but do not grant full management of a personal device.
Automation, monitoring, and reporting are now first-class
The July 24, 2026 blueprint introduces a distinct domain for optimization. Microsoft Graph enables repeatable Intune automation. Start with read-only inventory, grant the minimum application or delegated permission, protect the identity, handle pagination and throttling, avoid storing tokens, and log change intent and result. A script should not need Global Administrator to read managed-device inventory.
Custom compliance uses a PowerShell discovery script and JSON rules to evaluate organization-specific conditions. Make output deterministic, bounded, and free of secrets. Treat timeout, malformed output, and script failure explicitly. Intune Remediations uses detection and remediation scripts. Detection decides whether correction runs; remediation should be idempotent and reversible.
Endpoint Analytics provides startup performance, device health, application reliability, and related experience signals. Compare cohorts, time ranges, device models, OS versions, and application versions. A low score is a lead, not a root cause. Intune reports, filters, workbooks, dashboards, and exports need data freshness labels and privacy controls.
Tenant status, Microsoft 365 service health, and Message center communications help distinguish a service incident from a local policy regression. Establish operational baselines and alerts for enrollment failures, compliance drift, and configuration conflicts. Security Copilot agents in Intune can identify threat or performance findings and offer recommendations, but administrators retain responsibility. Validate evidence, assess scope, pilot, monitor, approve or reject, and preserve rollback.
A practical eight-week study plan
- Week 1: Draw device identity, join, enrollment, compliance, and Conditional Access as separate layers.
- Week 2: Build Windows Autopilot user-driven and pre-provisioning labs; study Windows 365 and restore paths.
- Week 3: Create multiplatform profiles, filters, RBAC, scope tags, and Intune Suite capability maps.
- Week 4: Deploy antivirus, BitLocker, firewall, ASR, baselines, Defender onboarding, and App Control in test modes.
- Week 5: Design Windows and non-Windows update servicing, monitor errors, and test Delivery Optimization.
- Week 6: Package Win32 apps and configure Store, Microsoft 365 Apps, mobile app protection, and app configuration.
- Week 7: Build Graph inventory, custom compliance, Remediations, Analytics baselines, and health triage.
- Week 8: Complete all three projects, retrieve 40 flashcards, run 50 questions under a 100-minute timer, and revisit the official guide.
Use the five-phase MD-102 roadmap, 40 flashcards, and three substantial projects. The timer builds pacing for the official duration, but the independent 50-question bank does not claim that a live exam contains 50 questions.
Official Microsoft references
- Endpoint Administrator Associate certification
- Study guide for MD-102
- What is Microsoft Intune?
- Device enrollment guide
- Windows Autopilot
- Windows 365 Enterprise
- Endpoint security
- Win32 app management
- App protection policies
- Microsoft Graph with Intune
- Endpoint Analytics
Continue learning
- MD-102 five-phase roadmap
- 50 original MD-102 questions
- 40 MD-102 flashcards
- Three MD-102 projects
- Microsoft identity roadmap
- PrepKloud editorial policy
Frequently asked questions
Is MD-102 active in 2026?
Yes. Microsoft Learn lists the active Endpoint Administrator Associate certification and skills measured from July 24, 2026. Check again before scheduling.
How long is MD-102?
Microsoft lists 100 minutes. Verify delivery, language, scheduling, and accommodations on Microsoft Learn.
What changed in July 2026?
The blueprint has five domains and adds a distinct automation, monitoring, and reporting domain while updating enrollment, Autopilot, Intune Suite, security, apps, and agent-assisted operations.
How is the practice bank allocated?
Infrastructure 12, devices 14, protection 9, applications 9, and operations 6. The independent bank count does not describe a live exam form.
Should I study only Windows?
No. Windows is central, but the current objectives also cover Android, iOS, iPadOS, macOS, specialty devices, managed apps, and platform-specific updates.
Do I need a production tenant?
No. Use an authorized disposable tenant, synthetic identities and data, test VMs or devices, small pilot groups, independent recovery access, and complete cleanup.
Are these materials exam dumps or a pass guarantee?
No. They are original educational content based on public Microsoft sources. They contain no live or recalled questions and cannot guarantee a pass or employment outcome.