MD-102 Exam Guide: A Practical Preparation and Scheduling Plan
MD-102 validates the skills of a Microsoft 365 Endpoint Administrator who deploys, manages, protects, and optimizes devices and client applications through Microsoft Intune and related Microsoft technologies. It is aimed at administrators working with Windows and non-Windows endpoints, identity, applications, security, updates, automation, monitoring, and reporting. This guide helps you decide whether your current experience is sufficient, which skills to study first, how to use Microsoft’s preparation resources, and when to schedule the exam.
What does MD-102 validate?
MD-102 validates practical endpoint administration rather than isolated product memorization. The official certification description centers on planning and executing endpoint deployment, managing devices at scale, implementing identity and security controls, and improving endpoint operations through automation, monitoring, and reporting.
The certification is Microsoft 365 Certified: Endpoint Administrator Associate. Microsoft classifies it as an intermediate-level administrator certification. The role involves collaborating with architects, Microsoft 365 administrators, security administrators, and other workload administrators to implement a modern workplace strategy that meets organizational needs.
The technologies named by Microsoft include Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Entra ID, PowerShell, Microsoft Graph, Windows 365, Azure Virtual Desktop, Microsoft Tunnel, and Microsoft Cloud PKI. You do not need to treat every product as an independent subject. Study how these services work together in an endpoint-management scenario.
The role behind the exam
An endpoint administrator is responsible for more than enrolling devices. The role includes deployment, configuration, application management, identity, access, policies, updates, endpoint protection, automation, monitoring, and reporting across different operating systems, platforms, and device types.
Microsoft expects candidates to have experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, together with strong skills in deploying, configuring, and maintaining Windows client and non-Windows devices. Microsoft also lists understanding of Microsoft Security Copilot, Intune agents, and Microsoft Defender XDR.
Who should take MD-102?
MD-102 is most suitable for administrators who already manage Microsoft 365 endpoints or have substantial hands-on experience with Intune, Entra ID, Windows deployment, device configuration, and endpoint security. If your experience is limited to using the Intune portal without understanding enrollment, policy scope, application dependencies, or troubleshooting, build that foundation before booking.
The official audience profile describes a candidate with subject-matter expertise managing devices and client applications in a Microsoft 365 tenant by using Microsoft Intune and agentic tools and workflows. The role also requires coordination with adjacent administrators, so preparation should include the boundaries between endpoint management, identity, security, and cloud-hosted desktop services.
A useful readiness test is whether you can explain a complete endpoint lifecycle: prepare identity and device prerequisites, enroll a device, apply configuration and compliance settings, deploy an application, protect the device, update it, investigate a problem, and report on the result. If you can only describe individual menu options, your preparation should be more scenario-based.
Prerequisite knowledge to check
Microsoft’s related learning material assumes strong technical skills installing, maintaining, and troubleshooting Windows 10 or later, a strong understanding of networking, client security, and application concepts, and experience with Active Directory Domain Services. These are preparation prerequisites, not a stated formal certification prerequisite.
Before starting the main study cycle, review DNS, networking, Active Directory Domain Services, Windows troubleshooting, application packaging concepts, PowerShell, and Microsoft Entra ID. Weakness in these areas can make Intune behavior appear confusing when the underlying issue is identity, connectivity, device state, or application detection.
Which skills are measured?
The official MD-102 certification page groups the assessed work into five domains: prepare infrastructure for devices; manage and maintain devices; protect devices; manage and secure applications; and optimize endpoint operations by using automation, monitoring, and reporting. Microsoft’s study guide should be your controlling reference because exam skills are updated periodically.
The study guide identifies the audience as administrators who manage devices and client applications in a Microsoft 365 tenant by using Intune and agentic tools and workflows. It also notes that the bullets under the measured skills illustrate assessment areas and that related topics may be covered. Treat the outline as a scope map, not as a list of guaranteed question wording.
Most questions cover generally available features, although Microsoft notes that preview features may appear when they are commonly used. This makes current Microsoft Learn documentation important, especially for capabilities that change quickly or have moved between product experiences.
Prepare infrastructure for devices
Study the decisions that must be made before a device receives a policy. This includes identity and tenant preparation, enrollment planning, device platforms, deployment approaches, Windows Autopilot, and the relationship between cloud management and existing infrastructure.
For this domain, build a deployment diagram. Show the user or device identity, enrollment path, management authority, required network access, assignment groups, configuration profiles, compliance policies, applications, and security integrations. Then explain what happens when the device is corporate-owned, personally owned, newly provisioned, or already managed by another tool.
Do not study Autopilot as a sequence of isolated screens. Focus on why an organization would choose a particular deployment profile, how device identity and user assignment affect the experience, and which prerequisites must be present before deployment can succeed.
Manage and maintain devices
This domain requires you to connect device enrollment and configuration with ongoing administration. Review configuration profiles, compliance policies, device actions, update management, inventory, monitoring, and troubleshooting across supported endpoint types.
A productive lab exercise is to create a small policy set and document its assignments, conflicts, exclusions, and expected device result. Then change one variable at a time and investigate why the endpoint does or does not receive the intended setting. This develops the diagnostic reasoning that scenario questions require.
Include co-management and Configuration Manager in your preparation where they appear in the official learning path. Microsoft’s Configuration Manager module covers capabilities, key components, client deployment, deployment troubleshooting, and in-place upgrades.
Protect devices
Protect-device preparation should connect endpoint configuration with threat prevention, detection, and response. Review Microsoft Defender for Endpoint, device security controls, security baselines, application control concepts, and the way endpoint signals support broader Microsoft security operations.
Microsoft’s Defender for Endpoint module covers its key capabilities, Windows Defender Application Control and Device Guard, Microsoft Defender Application Guard, Microsoft Defender Exploit Guard, and Windows Defender System Guard. Use those objectives to organize notes around the problem each control addresses, its dependencies, and how an administrator would monitor or troubleshoot it.
Avoid treating security as a catalogue of names. For each control, ask what threat or risk it addresses, which device or user scope it affects, how it is deployed, and what evidence would show that it is working.
Manage and secure applications
Application preparation should cover the complete process from selecting a deployment method to securing, assigning, updating, and troubleshooting the client application. Include Microsoft 365 Apps, line-of-business applications, application protection considerations, dependencies, supersedence, detection, and user or device targeting where applicable.
Create an application decision table for a few realistic cases: a required application for corporate devices, an optional application for a user group, an update replacing an older version, and an application that must be restricted to compliant devices. Record the assignment type, target, dependency, detection approach, and rollback or troubleshooting path.
The objective is not to memorize every application setting. It is to understand how application intent, device state, identity, licensing, detection, and policy assignment combine to produce the final result.
Optimize endpoint operations
The optimization domain moves beyond configuration into operational scale. Review automation with PowerShell and Microsoft Graph, reporting, monitoring, device and application status, and the use of Microsoft Security Copilot or Intune agents where they are relevant to the current study guide.
For practice, take a repetitive administrative task and describe two approaches: a portal-based workflow and an automated workflow. Identify the required permissions, input data, expected output, logging, and validation step. This prevents automation study from becoming a list of command names without operational judgment.
Monitoring should lead to an action. Practice interpreting a deployment failure, a compliance trend, an enrollment problem, or an update issue and deciding whether to investigate assignment, identity, connectivity, configuration conflict, application detection, or device health.
How should you sequence your study?
Start with the official MD-102 study guide, map each measured domain to your experience, and then study in an order that follows the endpoint lifecycle: infrastructure, device management, protection, applications, and operational optimization. Use labs and troubleshooting notes between reading sessions so that each product concept becomes an administrative decision.
Microsoft’s official course is “Manage and secure Microsoft 365 endpoints by using Intune.” The course covers endpoint deployment, configuration, and management with Intune; identity and device infrastructure with Microsoft Entra ID; device enrollment and configuration; applications; endpoint and data protection; PowerShell; Microsoft Graph; Microsoft Security Copilot; Microsoft Intune Suite; Windows 365; and Azure Virtual Desktop.
The course is listed as intermediate and has a course duration of 5 days. That duration describes the official course offering, not a guaranteed amount of time required for individual exam preparation. Use the course syllabus as a structured curriculum if you prefer guided coverage, but adjust your schedule according to your baseline and lab access.
A four-stage study cycle
Stage one is scope and diagnosis. Read the current study guide, list every skill under the five domains, and mark each item as experienced, understood but unpracticed, or unfamiliar. Schedule no exam until the unfamiliar items have been investigated and the practical items have been exercised.
Stage two is foundation. Study tenant, identity, enrollment, device platforms, Autopilot, configuration, compliance, and updates. Keep a decision log rather than copying definitions. Each entry should state the administrative goal, prerequisites, assignment target, expected outcome, and likely failure point.
Stage three is integration. Add Defender for Endpoint, applications, Configuration Manager, PowerShell, Graph, reporting, Windows 365, and Azure Virtual Desktop. Use scenario chains in which one decision affects another—for example, identity and enrollment affect policy assignment, which affects compliance, which affects application access.
Stage four is verification. Take Microsoft’s free practice assessment, review the exam sandbox, revisit missed objectives, and perform targeted labs. The practice assessment is intended to show the style, wording, and difficulty of likely exam questions; it is a readiness diagnostic, not a substitute for product experience.
When self-paced study is the better choice
Choose self-paced preparation when you can maintain a regular schedule, access a suitable tenant or lab environment, and already understand core Windows and Microsoft 365 administration. Self-paced study lets you spend more time on weak domains instead of following a fixed classroom pace.
Use Microsoft Learn modules and the official course syllabus as the structure, then add your own exercises. After each module, write a short operational runbook from memory. If the runbook omits prerequisites, assignment logic, validation, or troubleshooting, return to the source material before moving on.
When instructor-led training is worth considering
Instructor-led training is useful when you need a fixed timetable, guided demonstrations, or help connecting endpoint management to identity and security. Microsoft’s MD-102 course page supports instructor-led or self-directed study, while the official course is aligned with the Endpoint Administrator Associate certification.
Confirm the current delivery options, schedule, and provider details through Microsoft’s course or certification pages before committing. The Q&A material supplied for this guide is community content and should not be treated as a substitute for the live course catalogue.
What should you practise in a lab?
Practise workflows that expose dependencies rather than clicking through a feature once. A useful MD-102 lab should include identity, enrollment, configuration, compliance, applications, security, updates, monitoring, and at least one automation task. Record what you changed and how you verified the result.
Begin with a simple device-management baseline. Create groups, define an enrollment approach, apply a configuration profile, create a compliance requirement, deploy an application, and inspect device status. Then deliberately introduce a conflict or incorrect assignment and diagnose it. The learning value comes from explaining the outcome, not merely making the original deployment work.
Next, practise a Windows Autopilot scenario and compare it with management of an already provisioned device. Note which identity, ownership, enrollment, and assignment assumptions differ. Add a Defender for Endpoint exercise that asks you to identify the protection capability involved and the evidence you would inspect when a device is at risk.
Use the Configuration Manager learning module for the areas it explicitly covers: capabilities, components, client deployment, deployment troubleshooting, and in-place upgrades. If your work environment uses co-management, document which workload is managed by which service and what that means for policy ownership.
Finally, automate a small reporting or administrative task with PowerShell or Microsoft Graph. Validate permissions, scope, error handling, and output. Do not copy a script without understanding what it changes and how you would reverse or audit the change.
A practical lab record
For every exercise, capture five points: the business or administrative goal, the prerequisites, the configuration and assignment choices, the validation evidence, and the troubleshooting path. This format turns lab work into revision material and makes gaps visible before the exam.
Use screenshots sparingly. A written explanation of why a policy applies, does not apply, conflicts, or produces a particular device state is more useful than a collection of portal images that may become outdated.
How do you know you are ready?
Readiness means you can reason through unfamiliar endpoint scenarios, not that you recognize a particular set of remembered questions. Use the official practice assessment to identify weak areas, then confirm those areas through Microsoft Learn documentation and hands-on exercises.
You should be able to explain the difference between preparing infrastructure and managing a device after enrollment; distinguish configuration, compliance, application, and security purposes; trace an assignment from group membership to device result; and select a sensible troubleshooting order when the expected result is missing.
You should also be able to connect endpoint services to wider operations. Explain where Entra ID, Intune, Defender for Endpoint, Configuration Manager, PowerShell, Graph, Windows 365, and Azure Virtual Desktop fit in the lifecycle. The goal is not equal depth in every product, but reliable decisions about the role each service plays.
Microsoft states that a score of 700 or greater is required to pass. Do not interpret a practice result as a guaranteed exam score. Use it to decide whether to study a domain, repeat a lab, or proceed to scheduling.
Warning signs that you should delay scheduling
Delay the booking if you are relying mainly on memorized answer sets, cannot explain assignment scope, have not practised troubleshooting, or are unfamiliar with the current study-guide objectives. Leaked questions and exam dumps cannot establish the skills Microsoft describes and do not guarantee a passing result.
Also delay if your preparation is based on an older blueprint without checking the current study guide. Microsoft updates exams periodically, updates the English-language version first, and notes that localized versions may not always be updated on the same schedule.
What are the delivery details?
Microsoft lists MD-102 as a proctored exam with 100 minutes to complete the assessment. The exam may include interactive components. Review the current scheduling page and use the exam sandbox so that the interface and question interactions are familiar before the appointment.
The certification page lists English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil) as exam languages. Language availability can change, so confirm your preferred language when scheduling. Microsoft’s study guide says that if the exam is not available in your preferred language, you can request an additional 30 minutes to complete the exam.
The certification page directs candidates to schedule through Pearson VUE. Register with a personal Microsoft account when possible so that your exam records remain associated with you if you change employers or leave an organization. Confirm current appointment, delivery, identification, and accommodation requirements with the official scheduling provider.
Retakes, accommodations, and renewal
Microsoft states that a failed certification exam can be retaken 24 hours after the first attempt; the waiting period for subsequent retakes varies. Check the current retake policy before scheduling a second attempt.
If you use assistive devices, need extra time, or require another modification to the exam experience, request an accommodation through Microsoft’s certification process before the appointment. Do not assume that a preferred arrangement will be added automatically at the testing stage.
The Endpoint Administrator Associate certification has a 12-month renewal frequency. Microsoft says associate, expert, and specialty certifications can be renewed by passing a free online assessment on Microsoft Learn. Treat renewal as a separate maintenance activity and check the certification profile for current requirements.
What should you do before booking?
Use a short decision gate before paying for an appointment: verify that the current study guide matches your exam timing, check the available language and delivery choice, complete the practice assessment, review the sandbox, and identify any accommodation request. Then schedule only when your remaining gaps are specific and manageable.
Confirm the current exam page for price because Microsoft states that price is based on the country or region in which the exam is proctored. Do not rely on an old voucher, discount, or forum post. The supplied Microsoft Q&A response says there were no offers specifically for MD-102 and no Virtual Training Day events for this certification at the time of that response, while pointing readers to separate student, ESI, and voucher resources. Eligibility and availability can change.
Keep your Microsoft Learn profile current and connect it to your certification profile. Microsoft says this connection supports scheduling and renewal and allows candidates to share and print certificates. Use a personal account for the certification record rather than depending on an employer-controlled identity.
A final seven-step checklist
1. Open the current MD-102 study guide and confirm the measured skills for your exam version.
2. Rate your experience across infrastructure, device management, protection, applications, and operations.
3. Complete targeted Microsoft Learn modules and the official course material for weak areas.
4. Perform labs that include assignments, conflicts, enrollment, application deployment, security, and troubleshooting.
5. Use PowerShell or Microsoft Graph for at least one controlled administrative or reporting exercise.
6. Take the practice assessment and inspect the sandbox; revisit missed objectives rather than memorizing answers.
7. Confirm language, time, price, account, accommodation, and provider details on the official scheduling page before booking.
Conclusion
MD-102 preparation is strongest when it mirrors the endpoint administrator’s work: prepare identity and infrastructure, deploy and maintain devices, protect them, manage applications, and improve operations with automation and evidence. Use the current Microsoft study guide as the scope authority, the official course and modules as learning structure, and labs as the test of understanding. Schedule only after your practice results and troubleshooting work show that you can connect services and make defensible administrative decisions.