Free Practice Questions for Microsoft Certified: Endpoint Administrator Associate (MD-102) Certification
Study with 349 exam-style practice questions designed to help you prepare for the Microsoft Certified: Endpoint Administrator Associate (MD-102). All questions are aligned with the latest exam guide and include detailed explanations to help you master the material.
Exam experiencesNew
Pass and fail outcomes from candidates who prepared here — advice, scores, and prep time.
Start Practicing
All Domains
Practice with randomly mixed questions from all topics
Domain Mode
Practice questions from a specific topic area
Quiz History
Exam Details
Key information about Microsoft Certified: Endpoint Administrator Associate (MD-102)
- Multiple choice
- Ordering
- True/False
- Fill in the blank
Associate
Microsoft Azure
MD-102
English, Other localized versions
Endpoint administrators with subject matter expertise managing devices and client applications in a Microsoft 365 tenant using Microsoft Intune and agentic tools and workflows.
July 24, 2026
Exam Topics & Skills Assessed
Skills measured (from the official study guide)
Domain 1: Prepare infrastructure for devices
Subdomain 1.1: Add devices to Microsoft Entra ID
Choose an appropriate device join type, including considerations such as device registration and Microsoft Entra join - Join devices to Microsoft Entra ID - Register devices to Microsoft Entra ID - Plan and implement groups for devices in Microsoft Entra ID, including dynamic group membership rules
Subdomain 1.2: Enroll devices to Microsoft Intune
Configure enrollment settings in Microsoft Intune - Configure automatic enrollment for Windows - Configure personal enrollment for macOS, iOS, iPadOS - Configure enrollment profiles for Android devices, including fully managed, dedicated, corporate owned, work profile, enrollment restrictions and troubleshooting enrollment failures - Configure corporate enrollment for macOS and iOS devices by integrating Intune with Apple Business Manager - Configure enrollment for Android devices by integrating Intune with Samsung Knox Mobile Enrollment or Google Zero Touch
Subdomain 1.3: Implement identity and compliance
Manage built-in and custom roles for Intune and Windows 365, including role assignments - Configure scope tags and scoped administration for multi-admin environments - Implement and manage multi-admin approval - Implement compliance policies for all supported device platforms by using Intune - Implement Microsoft Entra Conditional Access policies that require a compliance status - Configure Windows Hello for Business by using Intune - Implement and manage Windows Local Administrator Password Solution (Windows LAPS) by using Microsoft Intune and Microsoft Entra ID - Manage the membership of local groups on Windows devices by using Intune
Domain 2: Manage and maintain devices
Subdomain 2.1: Deploy and upgrade Windows clients by using cloud-based tools
Choose between Windows Autopilot deployment profiles and device preparation policies - Choose between Windows Autopilot deployment modes, including user-driven, pre-provisioning, and self-deploying - Apply a device name template by using Windows Autopilot - Implement Windows client deployment by using Windows Autopilot - Create an Enrollment Status Page (ESP) - Plan and implement device upgrades for Windows 11 by using Intune - Provision and configure Windows 365 Cloud PCs by using Intune, including provisioning policies, network connections, and image management - Implement Windows Backup and Restore by using Intune
Subdomain 2.2: Plan and implement device configuration profiles
Create device configuration profiles for Windows devices, including importing ADMX files and using Group Policy analytics - Create device configuration profiles for Android devices - Create device configuration profiles for iOS/iPadOS devices - Create device configuration profiles for macOS devices - Create device configuration profiles for specialty devices, including Teams Rooms, HoloLens 2, and Zebra - Target a profile by using assignment filters and enrollment time grouping
Subdomain 2.3: Implement Intune Suite add-on capabilities
Configure Endpoint Privilege Management including configuring elevation policies, monitoring elevated actions, and adjusting EPM settings - Manage applications by using the Enterprise App Catalog - Configure Microsoft Intune Remote Help - Plan and implement Microsoft Cloud PKI, including setting up cloud-based PKI, automating certificate issuance, and monitoring certificate health - Implement Microsoft Tunnel for Mobile Application Management, including configuring Tunnel Gateway, extending support to MAM devices, and monitoring tunnel connections - Implement Microsoft Intune Advanced Analytics, including anomaly detection, proactive insights, and risk-based policy recommendations
Subdomain 2.4: Perform remote actions on devices
Sync, restart, retire, or wipe devices - Perform bulk remote actions - Update Microsoft Defender Antivirus security intelligence - Rotate BitLocker recovery keys - Rotate locate administrator passwords - Run a device query by using KQL - Collect device diagnostics and logs by using Microsoft Intune, including using the Troubleshooting blade for user-based diagnostics
Domain 3: Protect devices
Subdomain 3.1: Configure endpoint security
Create antivirus policies by using Microsoft Intune - Create and manage disk encryption policies by using Microsoft Intune, including managing BitLocker recovery keys, configuring user self-service recovery, and monitoring encryption compliance status - Create firewall policies by using Microsoft Intune - Configure Attack surface reduction policies by using Microsoft Intune, including applying Zero Trust principles for endpoint protection - Plan and implement security baselines by using Microsoft Intune - Integrate Intune with Microsoft Defender for Endpoint, including configuring Endpoint Detection and Response (EDR) policies, investigating endpoint threats, and triaging incidents - Onboard devices into Microsoft Defender for Endpoint - Configure App Control for Business policies by using Microsoft Intune
Subdomain 3.2: Manage device updates
Plan for device updates by using Intune - Create and manage update rings, feature updates, and quality updates for Windows devices by using Intune - Implement Windows Autopatch and configure Hotpatch policies - Create and manage update policies for iOS/iPadOS and macOS devices by using the Settings Catalog in Microsoft Intune - Manage Android updates by using configuration profiles or firmware-over-the-air (FOTA) deployments - Configure Windows client Delivery Optimization by using Intune - Monitor device updates by using Intune
Domain 4: Manage and secure applications
Subdomain 4.1: Deploy and update apps
Prepare applications for deployment by using Intune - Deploy apps by using Intune, including Win32 apps, line-of-business (LOB) apps, and Microsoft Store apps - Configure Quiet Time policies for Android and iOS apps - Deploy Microsoft 365 Apps by using Intune - Configure policies for Office apps by using Microsoft Intune or the Microsoft 365 Apps admin center - Deploy Microsoft 365 Apps as part of a Windows Autopilot deployment, including using the Office Deployment Tool (ODT) or Microsoft Intune - Manage Microsoft 365 Apps by using the Microsoft 365 Apps admin center - Deploy apps from platform-specific app stores by using Intune, including Apple Volume Purchase Program and Google Play - Monitor app deployment status and troubleshoot installation failures by using Microsoft Intune
Subdomain 4.2: Plan and implement app protection and app configuration policies
Plan and implement app protection policies for managed and unmanaged (BYOD) devices by using Microsoft Intune - Implement Microsoft Entra Conditional Access policies for app protection policies - Plan and implement app configuration policies for managed apps and managed devices
Domain 5: Optimize endpoint operations by using automation, monitoring, and reporting
Subdomain 5.1: Automate management tasks
Automate Intune management tasks by using PowerShell and Microsoft Graph - Investigate threats identified by Security Copilot agents in Intune - Analyze device performance by using Security Copilot agents in Intune - Review and respond to Security Copilot agent recommendations to make management decisions - Extend device compliance by using PowerShell
Subdomain 5.2: Monitor and optimize health
Implement reporting and data visibility in Microsoft Intune, including customizing reports and filters, using workbooks and dashboards, and exporting reporting data - Monitor endpoint performance by using Endpoint Analytics, including proactive remediations, device health scores, and app startup performance - Configure and manage proactive remediation scripts, including detecting and fixing common device issues, and scheduling remediation runs - Analyze endpoint reliability and user experience scores, including startup performance, restart frequency, and application reliability metrics - Monitor tenant health and Intune service communications, including reviewing service health dashboards, message center notifications, and establishing operational baselines - Configure alerts and notifications for policy and compliance changes, including setting up alert rules for compliance drift, enrollment failures, and configuration conflicts
Techniques & products