MD-102 Exam Guide: A Practical Plan for Microsoft 365 Endpoint Administrator Candidates
MD-102 validates the ability to plan, deploy, secure, manage, and optimize Microsoft 365 endpoints with tools such as Intune, Microsoft Entra ID, Windows Autopilot, and Microsoft Defender for Endpoint. It is intended for administrators who manage devices and client applications in a Microsoft 365 tenant. This guide helps you decide whether your experience is ready for focused exam preparation, which skills need hands-on work, and how to schedule study without relying on leaked questions or memorization.
What does MD-102 validate?
MD-102 tests practical endpoint administration rather than isolated product definitions. The official study guide frames the candidate as someone who manages devices and client applications in a Microsoft 365 tenant by using Microsoft Intune and related tools and workflows. Your preparation should therefore connect identity, enrollment, configuration, applications, security, updates, reporting, and automation into complete administrative decisions.
The associated credential is Microsoft 365 Certified: Endpoint Administrator Associate. Microsoft describes the role as planning and executing endpoint deployment, using modern management, co-management approaches, and Microsoft Intune integration. The work spans different operating systems, platforms, and device types, so a study plan limited to Windows desktop settings is too narrow.
An effective readiness question is not simply “Have I read about Intune?” Ask whether you can explain why an organization would choose a particular enrollment, policy, application, protection, or monitoring approach, and what dependency must be prepared first. That style of reasoning is more useful than collecting disconnected feature descriptions.
Who is the intended candidate?
MD-102 is aimed at an administrator who already has meaningful Microsoft 365 endpoint responsibility, not someone beginning with cloud administration. Microsoft expects experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, together with strong skills in deploying, configuring, and maintaining Windows client and non-Windows devices.
The role collaborates with architects, Microsoft 365 administrators, security administrators, and other workload owners. That means preparation should include boundary decisions: which service controls identity, which service manages the endpoint, how security signals affect device access, and how an application or update is delivered without undermining the organization’s operating model.
The official audience profile also includes Microsoft Security Copilot, Intune agents, and Microsoft Defender XDR as expected knowledge. Treat those topics as part of the role context, while prioritizing the core endpoint lifecycle. If you lack device administration experience, first build a working lab or supervised administrative practice before attempting to memorize exam terminology.
Which skills are measured?
The MD-102 certification page groups the assessed work into five areas: prepare infrastructure for devices; manage and maintain devices; protect devices; manage and secure applications; and optimize endpoint operations by using automation, monitoring, and reporting. Use these labels as the backbone of your study tracker and record evidence of practical understanding under each one.
Prepare infrastructure for devices covers the foundations that make endpoint management possible. Review Microsoft Entra ID, identity and access dependencies, enrollment preparation, device platforms, deployment planning, and the relationship between cloud management and existing infrastructure. The official course also includes Windows Autopilot, Microsoft Tunnel, Microsoft Cloud PKI, Windows 365, and Azure Virtual Desktop.
Manage and maintain devices requires more than knowing where a setting appears. Study enrollment and configuration, policy application, device lifecycle tasks, updates, troubleshooting, and operational maintenance. Include co-management concepts and Configuration Manager, particularly if your environment combines traditional management with Intune.
Protect devices includes endpoint security and Microsoft Defender for Endpoint. The Microsoft Learn module covers Defender for Endpoint capabilities, Application Guard, Exploit Guard, and System Guard. Connect these subjects to the administrative objective: reducing endpoint risk, monitoring devices, and responding to protection requirements.
Manage and secure applications includes application deployment, configuration, protection, and the relationship between applications, device compliance, identity, and data. The official course specifically includes application management and protection, Microsoft Intune Suite capabilities, and Microsoft 365 endpoint administration workflows.
Optimize endpoint operations focuses on automation, monitoring, and reporting. Prepare PowerShell and Microsoft Graph concepts at the level required to understand repeatable administration and data-driven operations. The course also introduces Microsoft Security Copilot and automation-related capabilities, so do not treat optimization as an optional final chapter.
Should I use percentage weights?
The supplied official MD-102 study materials identify the five exam domains but do not provide verified percentage weights in the research available for this guide. Do not rank the domains using bare percentages. Instead, use the official domain names as a coverage checklist and give extra study time to areas where your practical experience is weakest.
How should you assess readiness before studying?
Begin with an evidence-based skills inventory, then use Microsoft’s free practice assessment to locate gaps. The practice assessment is intended to show the style, wording, and difficulty of likely questions and to help identify where additional preparation is needed. It is a diagnostic tool, not proof that you can reproduce live exam content.
Create five columns using the official domains. In each column, mark a topic as demonstrated, understood, or unfamiliar. “Demonstrated” should mean you have completed or can clearly explain an administrative task. “Understood” means you can describe the design but have limited execution experience. “Unfamiliar” means you need documentation, guided practice, or structured instruction.
Pay particular attention to dependencies. For example, a device policy cannot be evaluated in isolation from enrollment, identity, assignments, platform support, compliance, and reporting. If your notes contain only feature names, convert them into a sequence: business requirement, prerequisite, configuration choice, assignment or deployment, validation, and remediation.
After the diagnostic, choose a target date only when you can reserve regular study sessions and still leave time to review weak domains. The date should create accountability, not force you to sit before you can explain the endpoint lifecycle.
What should I study first?
Study the endpoint lifecycle in dependency order: identity and infrastructure, enrollment and deployment, configuration and maintenance, protection, applications, then automation and reporting. This sequence prevents a common mistake—learning isolated Intune features before understanding how a device becomes known, trusted, configured, protected, and supportable.
Start with Microsoft Entra ID and the identity-device relationship. Review groups, administrative roles, access requirements, and the identity decisions that affect enrollment and access. Then examine device infrastructure and deployment planning, including Windows Autopilot and the role of existing Configuration Manager environments.
Move into Intune device management. Practice thinking through enrollment, configuration profiles, compliance, updates, device actions, and platform differences. For each exercise, write down the intended scope, assignment method, expected result, and troubleshooting evidence. This habit develops the reasoning needed for scenario-based questions without attempting to reproduce exam items.
Next, study protection as an operating process. Use the Microsoft Defender for Endpoint module to connect threat protection, endpoint signals, and device safeguards. Review how Application Guard, Exploit Guard, and System Guard fit into a broader endpoint security plan rather than treating them as independent vocabulary.
Finish the core pass with applications and operations. Trace an application from packaging or selection through assignment, installation, update, protection, monitoring, and removal. Then review PowerShell, Microsoft Graph, reporting, and automation as methods for reducing repetitive work and improving visibility.
Which official resources fit the roadmap?
Use the Microsoft Learn study guide as the controlling checklist, the MD-102T00 course as the structured learning path, and focused modules for Defender for Endpoint and Configuration Manager. Revisit the exam page before scheduling because Microsoft updates exam content and localized versions may not change at the same time as English.
The official course is “Manage and secure Microsoft 365 endpoints by using Intune.” Its coverage includes Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Tunnel, Microsoft Cloud PKI, Microsoft Intune Suite, Windows 365, and Azure Virtual Desktop. Use its syllabus to identify subjects that your current job does not expose you to.
The Defender for Endpoint module is useful when endpoint protection is a weak area. It covers the service, key capabilities, Application Guard, Exploit Guard, and System Guard, and it assumes Windows administration, networking, client security, application concepts, and Active Directory Domain Services knowledge.
The Configuration Manager module is appropriate for candidates supporting hybrid or co-managed environments. Its objectives include describing Configuration Manager capabilities and components, troubleshooting deployments, managing client deployment, and planning in-place upgrades. Do not skip it merely because your present environment is cloud-first; use the official skills list to decide how deeply it belongs in your plan.
A four-phase study roadmap
A four-phase plan works well when you need to turn broad product knowledge into exam readiness: establish foundations, build the endpoint lifecycle, strengthen security and applications, then validate and repair gaps. Adjust the pace to your experience, but keep the sequence so later subjects have the required context.
Phase one is an inventory and foundation pass. Read the MD-102 study guide, map your experience to the five domains, and review Microsoft Entra ID, device identity, tenant preparation, networking, DNS, Active Directory Domain Services, and PowerShell. Mark every claim that you can explain operationally rather than recognizing only by name.
Phase two is deployment and management. Work through enrollment, Windows Autopilot, device configuration, policy assignment, compliance, updates, platform differences, and co-management. Use a lab or documented practice environment where possible. For every task, capture the prerequisite, the administrator action, the expected device state, and the evidence you would inspect if the result failed.
Phase three is protection and applications. Study Microsoft Defender for Endpoint, endpoint security controls, application deployment and protection, Microsoft Tunnel, Microsoft Cloud PKI, and relevant Intune Suite capabilities. Link each subject to a scenario such as securing a newly enrolled device, restricting an application, or supporting access from a managed endpoint.
Phase four is optimization and verification. Review PowerShell, Microsoft Graph, monitoring, reporting, Windows 365, Azure Virtual Desktop, and Microsoft Security Copilot in the context supported by the official course. Take the practice assessment, classify each missed item by domain and dependency, then return to Microsoft Learn for targeted repair.
Do not use repeated practice attempts as a substitute for study. For each incorrect answer, write why the selected option was attractive, which requirement it failed to satisfy, and what evidence would distinguish the correct administrative approach. This produces a decision log rather than a memorization list.
How can I make hands-on practice count?
Hands-on work is most valuable when each exercise has a requirement, a controlled change, and a verification step. Build small endpoint-management scenarios instead of clicking randomly through portals. The goal is to understand relationships among identity, device state, policy, application, security, and reporting.
A useful exercise begins with a device population and a business requirement. Decide how the devices are identified, how users or devices are grouped, how enrollment occurs, what configuration is assigned, and how success is measured. Then deliberately test an exception: an unsupported platform, a missing assignment, a conflicting policy, or a device that fails to report.
For application practice, document the complete path from source or package to assignment and installation. Include detection or validation logic where relevant, user and device targeting, dependency considerations, update handling, and removal. If you cannot access a lab, use Microsoft Learn exercises and write the same design notes from the documented scenario.
For security practice, connect a protection requirement to the relevant endpoint control and monitoring signal. Ask what the administrator would configure, where the setting applies, how the device receives it, and how an operations team confirms that it is effective. Avoid assuming that a control is successful merely because it was created.
What mistakes weaken MD-102 preparation?
The most damaging preparation errors are studying only product names, ignoring prerequisites, treating every device as a Windows device, and using unauthorized question dumps. MD-102 asks you to reason about endpoint administration, so preparation should emphasize dependencies, scope, outcomes, and troubleshooting rather than recall without context.
A narrow Intune-only plan can miss identity, Autopilot, Defender for Endpoint, Configuration Manager, Microsoft Tunnel, Cloud PKI, cloud-hosted desktops, automation, and reporting. Use the official course and study guide to expose blind spots, then prioritize by your actual responsibilities and unfamiliarity.
Another mistake is reading every topic with equal intensity. A candidate who administers Windows devices daily may need less repetition on basic lifecycle tasks and more deliberate study of non-Windows management, Defender capabilities, Graph, or cloud-hosted desktop concepts. Conversely, a security-focused administrator may need more practice with enrollment, application deployment, and operational troubleshooting.
Do not infer that a practice assessment score represents the official passing result. Microsoft states that a score of 700 or greater is required to pass, but a practice assessment is intended to assess knowledge and identify gaps. Use its feedback to direct study; do not turn it into a promise of exam success.
Finally, do not rely on dumps, leaked questions, or memorized answer patterns. They can be inaccurate, violate exam rules, and leave you unable to manage the technology represented by the credential. Use official learning materials, the practice assessment, and legitimate hands-on work instead.
What are the delivery and scheduling details?
The official certification page states that MD-102 is proctored, may include interactive components, and provides 100 minutes to complete the assessment. It is offered in English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil). Confirm the current scheduling information with the exam provider before registering.
Microsoft provides an exam sandbox so you can become familiar with the interface and different question types before the appointment. Use it before exam day as a navigation exercise, not as a source of live questions. If you need assistive technology, extra time, or another modification, review the accommodation process in the official study guide before scheduling.
The certification page directs candidates to schedule through Pearson VUE and strongly recommends registering with a personal Microsoft account. This protects access to exam records if you later leave an organization. Check the current exam page for appointment availability, regional pricing, language options, and any provider-specific requirements.
If you fail a certification exam, Microsoft states that the first retake is available 24 hours after the first attempt; later retake intervals vary. A better scheduling decision is to reserve time for gap repair before the first attempt rather than treating a retake as part of the plan.
The study guide states that a score of 700 or greater is required to pass. The English version is updated first, and localized versions may be updated later. Check the study guide and exam details page for the version relevant to your language and appointment.
How should I decide whether to schedule?
Schedule when you can explain the five assessed domains, trace common endpoint workflows end to end, and identify the evidence used to validate or troubleshoot a change. A practice assessment should have exposed and reduced your major gaps, while your study notes should show decisions and dependencies rather than copied definitions.
Before registering, complete a final review using these questions: Can you prepare identity and device infrastructure? Can you distinguish deployment and maintenance tasks? Can you connect endpoint protection to Defender for Endpoint? Can you secure and deliver applications? Can you use automation, monitoring, and reporting to operate at scale?
Also confirm the practical conditions. Check the current language and appointment options, review the proctored-exam requirements, explore the sandbox, and request accommodations early if needed. Register with the account you intend to keep. Do not rely on an old page, an unofficial voucher claim, or a course description that does not match the current study guide.
If one domain remains unfamiliar, postpone and repair it. If the gap is limited to terminology, use targeted Microsoft Learn review and a short design exercise. The decision should be based on demonstrated capability and current official information, not on a fixed number of study days or confidence generated by answer memorization.
What should I do next?
Download or review the current MD-102 study guide, create the five-domain tracker, and take the official practice assessment. Use the result to choose your first weak area, then work through the relevant Microsoft Learn course or module with a written scenario and verification plan.
Next, build a short revision cycle: one pass for foundations, one for endpoint deployment and maintenance, one for protection and applications, and one for automation and operations. Recheck the official exam page immediately before scheduling, because Microsoft updates exam content and delivery information.
Keep this guide as a planning aid, not as a replacement for Microsoft Learn. The strongest preparation combines the current official objectives, practical endpoint administration, deliberate troubleshooting, and a careful review of the exam interface and appointment requirements.
Conclusion
MD-102 preparation is a decision about operational readiness, not access to a list of remembered answers. Use the official study guide to map the five domains, follow the endpoint lifecycle through identity, deployment, management, protection, applications, and optimization, and use Microsoft’s practice assessment to expose gaps. Then verify language, timing, proctoring, accommodations, and account details from the current official pages before scheduling.