MD-102 Exam Guide: Plan Your Endpoint Administrator Preparation
MD-102 validates the practical skills needed to manage Microsoft 365 devices and client applications with Microsoft Intune and related endpoint technologies. It serves administrators responsible for deployment, identity, security, policies, applications, updates, automation, monitoring, and reporting across Windows and non-Windows devices. This guide helps you decide whether your current experience is sufficient, which parts of the blueprint require focused study, how to sequence hands-on practice, and when to schedule the assessment based on evidence rather than familiarity with product names.
What does MD-102 validate?
MD-102 tests whether you can plan, deploy, protect, manage, and optimize endpoints in a Microsoft 365 environment. The role extends beyond creating Intune policies: it connects device identity, enrollment, configuration, applications, security controls, updates, monitoring, automation, and operational reporting.
Microsoft identifies the associated credential as Microsoft 365 Certified: Endpoint Administrator Associate. The certification describes an administrator who implements endpoint deployment and management solutions across platforms and device types, manages endpoints at scale, applies identity and security controls, and improves operations through automation, monitoring, and reporting.
The expected technology landscape includes Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Entra ID, PowerShell, Microsoft Graph, and Windows 365. The official course also explores Microsoft Security Copilot, Microsoft Tunnel, Microsoft Cloud PKI, Azure Virtual Desktop, and other endpoint capabilities.
This makes MD-102 a poor fit for preparation based only on memorizing portal locations. You need to understand why an administrator would choose a deployment approach, how assignments affect devices and users, how controls interact, and how to diagnose an outcome that does not match the design.
Who should take this exam?
MD-102 is intended for administrators who already manage Microsoft 365 devices and client applications with Microsoft Intune. Microsoft expects experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, together with strong skills deploying, configuring, and maintaining Windows client and non-Windows devices.
The role is collaborative. Endpoint administrators work with architects, Microsoft 365 administrators, security administrators, and other workload administrators to implement a modern workplace strategy that meets organizational needs. Your preparation should therefore include design decisions and operational handoffs, not just isolated device configuration tasks.
A useful readiness check is whether you can explain an endpoint lifecycle from identity and enrollment through configuration, application delivery, protection, update management, monitoring, and retirement. If your experience is limited to assigning a few compliance policies, begin with the infrastructure and identity foundations before attempting advanced troubleshooting or automation.
Microsoft’s course and certification pages identify the role as intermediate level and administrator-focused. Candidates should also understand Microsoft Security Copilot, Intune agents, and Microsoft Defender XDR. Treat those as areas to investigate in the current study guide rather than assuming that older endpoint-management experience covers them automatically.
Which skills are measured?
The official MD-102 certification page groups the assessment into five practical areas: prepare infrastructure for devices; manage and maintain devices; protect devices; manage and secure applications; and optimize endpoint operations by using automation, monitoring, and reporting.
Prepare infrastructure for devices is the foundation domain. Study the identity, enrollment, connectivity, platform, and management prerequisites that must exist before devices can be governed successfully. Think in terms of an organization preparing for scale, not a single test device.
Manage and maintain devices covers the ongoing lifecycle. Your study should connect provisioning and enrollment with configuration, policies, updates, device administration, and operational support. Include Windows and non-Windows scenarios where the official material addresses them.
Protect devices focuses on security controls and threat protection. Microsoft’s Defender for Endpoint module includes capabilities such as Defender Application Guard, Defender Exploit Guard, and Windows Defender System Guard. Learn how these controls contribute to endpoint protection and how an administrator would monitor or respond to their state.
Manage and secure applications requires more than knowing how to add an application. Prepare to reason about application deployment, configuration, access, protection, and troubleshooting. Consider how identity, device state, platform, assignment, and policy requirements influence whether a client application is usable.
Optimize endpoint operations by using automation, monitoring, and reporting is the operational maturity domain. Review PowerShell, Microsoft Graph, Intune reporting, and the role of automation and agentic tools. Be able to distinguish a repeatable administrative process from a one-time manual change.
How should you use the domains?
Use the five domains as a diagnostic map rather than a list to read once. For each domain, record the task you can perform, the task you can explain but have not performed, and the task whose purpose or dependencies you do not yet understand. Study the third category first, then validate the second with hands-on work.
What official learning path should anchor preparation?
The official course is MD-102T00-A, Manage and secure Microsoft 365 endpoints by using Intune. Microsoft lists it as an intermediate course with a course duration of 5 days and provides self-directed learning. Use its syllabus as the spine of your plan, then return to the exam study guide to check that your coverage matches the current assessed skills.
The course covers preparing identity and device infrastructure with Microsoft Entra ID, enrolling and configuring devices, managing applications, protecting endpoints and data, automating with PowerShell and Microsoft Graph, using Microsoft Security Copilot, extending Intune with the Microsoft Intune Suite, and delivering cloud-hosted desktops with Windows 365 and Azure Virtual Desktop.
The course is useful for structure, but completion is not proof of exam readiness. After each topic, translate the lesson into an administrative decision: which identity or enrollment prerequisite is needed, which assignment scope is appropriate, what outcome should be monitored, and what evidence would show that the configuration worked.
If you prefer instructor-led learning, use the official exam or credential page’s training links and verify the current offering with the training provider. The Microsoft Q&A material describes instructor-led options and training partners, but availability and delivery arrangements can change. Do not assume that a course shown in a discussion is currently scheduled in your region.
Which prerequisites deserve attention first?
Start with the dependencies that make later endpoint tasks understandable: Microsoft Entra ID, Microsoft 365 administration, Windows client management, networking, device identity, and application concepts. Configuration Manager experience is also relevant for administrators working with existing or co-managed environments, while PowerShell and Microsoft Graph support repeatable administration.
The Microsoft Configuration Manager module lists strong technical skills installing, maintaining, and troubleshooting Windows 10 or later, a strong understanding of networking, client security, and application concepts, and experience using Active Directory Domain Services as prerequisites. Use these as a gap checklist, especially if your background is cloud-only.
Do not postpone identity work. Enrollment, access, policy targeting, application availability, and device compliance depend on understanding users, groups, devices, and administrative scope. A learner who jumps directly into application deployment may misdiagnose an assignment or access problem as an installer failure.
Similarly, do not treat Configuration Manager as unrelated legacy material. The official module focuses on everyday administrator tasks, deployment components, client deployment, troubleshooting deployments, and in-place upgrades. Study its role in a broader endpoint strategy rather than trying to memorize every console option.
How should you build a hands-on practice environment?
Build a small, controlled tenant-and-device workflow if you have legitimate access to the required Microsoft services. The goal is not to reproduce a production estate; it is to observe enrollment, assignment, policy application, application delivery, protection status, and reporting as connected stages.
Create a written scenario before changing settings. For example, define a user group, a device population, a business application, a security requirement, an update expectation, and a reporting question. Then identify which service and assignment would implement each requirement. This prevents aimless portal navigation.
For every exercise, capture four items: the intended target, the configuration applied, the expected device or user result, and the evidence used to verify it. If the result differs, investigate scope, prerequisites, conflicts, platform support, connectivity, or client state before changing multiple settings at once.
Use separate test groups and reversible assignments. Avoid experimenting in a production tenant or applying broad policies without authorization. Where a feature or license is unavailable, study the official documentation and draw the configuration flow rather than inventing a result you cannot verify.
A practical lab sequence is enrollment first, then a simple configuration policy, then compliance and access behavior, then an application, then endpoint protection, then updates, reporting, and automation. Revisit the same device or test population so that you see how controls interact over time.
How should you study device deployment and maintenance?
Study deployment as a lifecycle: prepare identity and infrastructure, enroll or provision the device, apply configuration, deliver applications, protect the endpoint, maintain updates, monitor results, and troubleshoot exceptions. This sequence gives you a way to organize otherwise disconnected Intune, Autopilot, Windows, and device-management topics.
For Windows Autopilot, focus on the administrative purpose of the provisioning approach, the identities and profiles involved, device preparation, user experience, and the evidence that confirms successful deployment. Do not reduce the topic to a sequence of wizard screens; exam scenarios are more useful when you can identify the missing prerequisite or unsuitable deployment choice.
Include non-Windows devices in your review because the role covers various platforms and device types. Compare the management objective across platforms while checking which controls, enrollment methods, application models, or security capabilities are platform-specific. The correct answer may depend on that distinction.
For maintenance, create troubleshooting trees. Start with the symptom, determine whether the issue affects enrollment, policy, application, compliance, update, or security state, and then inspect the relevant assignment and device evidence. A disciplined diagnostic path is more valuable than collecting isolated fixes.
Use Configuration Manager material to understand client deployment, deployment components, troubleshooting, and upgrade planning. If your target environment uses co-management or hybrid administration, map which workload is handled by which management system and what transition state the device occupies.
How should you study protection and application security?
Separate endpoint protection into prevention, configuration, detection, and response. Microsoft’s Defender for Endpoint module covers additional protection and monitoring against threats, including Application Guard, Exploit Guard, and System Guard. Your notes should explain the security objective of each capability and how an administrator verifies its state.
Connect Defender for Endpoint to the wider endpoint design. Protection is not a standalone switch: identity, device configuration, application controls, update posture, and monitoring all influence risk. Practice explaining which signal or control would address a scenario and which administrative surface would provide evidence of the outcome.
Application study should cover the complete delivery path: package or app definition, target assignment, requirements, dependencies, detection, installation context, user experience, updates, and failure evidence. The exact path varies by application type, so organize notes by decision points rather than by a single package example.
Review how application access and device protection can interact. A device may have an application assigned but still fail a requirement, lack a dependency, be outside the assignment, or be prevented from access by a security or compliance condition. When practicing, deliberately create one failure at a time and identify the evidence that isolates it.
Keep application administration distinct from application security. Deployment makes software available; security controls determine whether the software, device, data, and user satisfy the organization’s conditions. MD-102 preparation should cover both sides and the relationship between them.
How should you prepare for automation, monitoring, and reporting?
Treat automation and reporting as operational tools, not optional advanced topics. The role includes optimizing endpoint operations through automation, monitoring, and reporting, and the official course includes PowerShell, Microsoft Graph, Microsoft Security Copilot, and Intune capabilities that support administration at scale.
Begin with a manual task you understand, such as identifying devices that need attention or checking policy results. Describe the required inputs, action, permissions, output, and error handling. Then investigate how PowerShell or Microsoft Graph could make the task repeatable. This approach teaches the administrative logic before the syntax.
For reporting, ask what decision the report supports. A count without scope, time context, or a defined status may not help an administrator act. Practice distinguishing device inventory, policy results, application status, compliance information, security signals, and update information, then identify the appropriate evidence for each.
Review Microsoft Security Copilot and Intune agents as current study topics, but verify the capabilities and terminology in the current official study guide. Features can change, and preview functionality should not be treated as universal production behavior. The study guide notes that most questions cover general availability features while preview features may appear when commonly used.
Do not automate before understanding permissions and impact. A script or Graph operation that targets the wrong group can create a larger problem than a manual change. Your preparation should include scope, authentication, least-privilege thinking, validation, logging, and rollback or correction steps.
What study roadmap should you follow?
A staged roadmap works better than reading every module in sequence without testing recall. Establish your baseline, build the infrastructure model, practice device and application administration, add protection and operations, and finish with scenario review. Adjust the pace to your experience and the date you intend to schedule.
Stage one is a gap assessment. Read the current MD-102 study guide, list each skill and supporting bullet, and mark your confidence based on demonstrated ability rather than recognition. Note where your experience is Windows-only, portal-only, or limited to one management model.
Stage two is foundation work. Review Microsoft Entra ID concepts, endpoint identity, enrollment, platform differences, networking dependencies, and the relationship between Intune and existing management tools. Complete the official Configuration Manager material if co-management, client deployment, or upgrade planning is unfamiliar.
Stage three is implementation practice. Work through enrollment, configuration profiles, compliance, applications, updates, Autopilot, and device troubleshooting. For every exercise, write the target, expected result, observed evidence, and correction. This record becomes a compact revision guide built from decisions rather than copied definitions.
Stage four is security and scale. Study Defender for Endpoint, endpoint protection controls, application security, Microsoft Intune Suite capabilities, Windows 365, Azure Virtual Desktop, Microsoft Tunnel, Microsoft Cloud PKI, automation, monitoring, reporting, and agentic tools where they appear in the current course or study guide.
Stage five is exam readiness. Take Microsoft’s free practice assessment to identify gaps and use the exam sandbox to become familiar with the interface and interactive components. Review every uncertain answer by returning to official learning material. Schedule only after you can explain why an answer is correct and why the alternatives do not fit the scenario.
If you use an instructor-led course, retain the same sequence. A class can compress exposure to the material, but it cannot replace deliberate practice, troubleshooting, or review of weak domains.
What should a weekly review session produce?
Each session should produce an artifact: a completed lab, a dependency diagram, a troubleshooting decision tree, a comparison of management choices, a short automation plan, or an error log with its resolution. If a study session produces only highlighted text, add a task that requires you to apply or explain the material without notes.
How can you tell whether you are ready?
Readiness means you can solve unfamiliar endpoint scenarios using the blueprint, not that you remember every label in the Intune portal. Use the practice assessment for a diagnostic signal, then confirm capability through hands-on tasks and explanation. Microsoft states that a score of 700 or greater is required to pass, but practice results should guide study rather than become a guarantee.
You are closer to readiness when you can trace a failure across identity, assignment, platform, licensing or service dependency, client state, and reporting evidence. You should also be able to select a management approach based on requirements such as scale, device ownership, platform, existing infrastructure, security posture, and operational control.
Keep a wrong-answer log. Record the domain, the mistaken assumption, the evidence you missed, and the rule or dependency that corrects it. Group repeated errors: for example, confusing user and device targeting, overlooking platform requirements, or treating compliance as equivalent to configuration.
Use the official exam sandbox before the assessment. It demonstrates the look and feel of the exam and lets you interact with different question types. This is a practical orientation step, separate from learning the technical content.
Do not use leaked questions, exam dumps, or memorization claims as a preparation strategy. They do not build the administrative judgment MD-102 measures and may expose you to inaccurate or unauthorized material.
What are the delivery and scheduling details?
Microsoft lists MD-102 as a proctored assessment with 100 minutes to complete it and says interactive components may be included. The certification page lists English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil) as available languages; confirm the current scheduling page before registering.
The exam page directs candidates to schedule through Pearson VUE. Use a personal Microsoft account for your certification profile where possible, because Microsoft warns that exam records associated with an organizational work or school account can be lost and unrecoverable if you leave that organization.
Microsoft’s study guide states that a score of 700 or greater is required to pass. If you fail the first attempt, the certification page states that you can retake it 24 hours after that attempt; later retakes have different waiting requirements, so check the current retake policy before planning a second appointment.
If the exam is not available in your preferred language, the study guide says you can request an additional 30 minutes. Accommodation requests are also available for candidates who use assistive devices, need extra time, or require another modification to the exam experience.
The price depends on the country or region in which the exam is proctored. Confirm the current amount, appointment availability, identification rules, delivery options, and cancellation terms with the exam provider rather than relying on an old guide or forum post.
Microsoft’s certification page states that the credential has a 12-month renewal frequency and that certification renewal can be completed through a free online assessment on Microsoft Learn. Treat renewal as a later maintenance task; first verify that MD-102 remains the correct current assessment for your goal.
Which mistakes should you avoid?
The most costly preparation mistakes are usually strategic: studying product names without workflows, ignoring identity and assignment dependencies, practicing only successful configurations, and relying on stale material. Replace passive review with scenario-based tasks that require you to choose, implement, verify, and troubleshoot an endpoint outcome.
Do not assume that a policy assigned to a user affects every device in the same way, or that a device assignment automatically reaches every user who signs in. Always state the target, scope, platform, and expected result when reviewing a configuration.
Do not treat every problem as an Intune problem. Enrollment can involve identity and device registration; application failures can involve requirements, dependencies, detection, context, or platform support; security results can depend on onboarding and configuration; reporting can lag or represent a different status than the one you expected.
Do not study only Windows desktop administration. MD-102 covers endpoint management across various platforms and device types, and the official role description includes Windows and non-Windows devices. Compare capabilities and constraints instead of assuming Windows behavior transfers unchanged.
Do not schedule immediately after finishing a course. Use the study guide, a practice assessment, the sandbox, and hands-on evidence to identify unresolved gaps. Schedule when your weak areas have a correction plan and your recent practice demonstrates consistent reasoning.
Do not rely on unsupported time-sensitive claims about languages, exam changes, pricing, or availability. The official study guide explains that exams are updated periodically and that English updates first. Check the current Microsoft pages close to registration and again before the appointment.
What should you do next?
Open the official MD-102 study guide and turn its five measured-skill areas into a checklist. Mark each item as demonstrated, understood but unpracticed, or unknown. Then choose the next learning activity from the weakest dependency, not from the topic you already find most comfortable.
If your infrastructure foundation is weak, begin with Microsoft Entra ID, enrollment, networking, and device-management prerequisites. If you can deploy devices but struggle with security, use the Defender for Endpoint module and build a protection-and-monitoring exercise. If you manage manually at scale, prioritize PowerShell, Microsoft Graph, reporting, and automation concepts.
Use the official MD-102T00 course for structured learning, the Configuration Manager and Defender for Endpoint modules for targeted gaps, and the practice assessment and sandbox for final preparation. Keep notes tied to decisions, prerequisites, expected evidence, and troubleshooting paths.
When your review shows a repeatable ability to reason through the measured skills, verify the current exam details and schedule through the official Pearson VUE route. Protect the certification record by using the Microsoft account guidance on the exam page, and check language or accommodation needs before booking.
Conclusion
MD-102 preparation is strongest when it mirrors the endpoint administrator’s real work: establish identity and infrastructure, deploy and configure devices, secure applications and endpoints, maintain the estate, and use evidence to improve operations. Let the current Microsoft study guide control scope, use hands-on scenarios to test judgment, and verify delivery details immediately before scheduling. The result should be a clear readiness decision based on demonstrated capability rather than familiarity with exam vocabulary.