Microsoft 365 Endpoint AdministratorStudy guide
The associate certification for an endpoint administrator who deploys, configures, protects, and manages endpoints and apps at scale with Microsoft Intune (MD-102).
About Microsoft 365 Endpoint Administrator (MD-102)
Microsoft 365 Endpoint Administrator (MD-102) is a Associate-level certification from Microsoft. This page organizes the exam scope into a 5-chapter, 13-section study guide and lets you check your understanding with exam-style practice questions. A good flow is to read the chapters below in order, then test yourself via "Practice questions."
Exam domains (approximate weighting)
- Prepare infrastructure for devices~22%
- Manage and maintain devices~27%
- Protect devices~18%
- Manage and secure applications~18%
- Optimize endpoint operations by using automation, monitoring, and reporting~15%
Weights are approximate guidance for the live exam. Each domain is covered in detail in the chapters and sections below.
Official exam information: https://learn.microsoft.com/en-us/credentials/certifications/resources/study-guides/md-102
1Prepare infrastructure for devices
- 1.1Add devices to Microsoft Entra ID
Understand Microsoft Entra join vs device registration, choosing the right join type, and dynamic group membership rules for devices.
- 1.2Enroll devices to Microsoft Intune
Understand Windows automatic enrollment, macOS/iOS personal enrollment, Android Enterprise enrollment types, automatic enrollment via Apple Business Manager/Samsung Knox/Google Zero Touch, and enrollment restrictions.
- 1.3Identity and compliance
Understand Intune roles/scope tags/multi-admin approval, compliance policies, requiring compliance via Conditional Access, Windows Hello for Business, and Windows LAPS.
2Manage and maintain devices
- 2.1Deploy Windows clients
Understand Windows Autopilot deployment profiles / device preparation policies, deployment modes (user-driven/pre-provisioning/self-deploying), the Enrollment Status Page (ESP), Windows 11 upgrades, and Windows 365 Cloud PC.
- 2.2Configuration profiles
Understand device configuration profiles, ADMX import and Group Policy analytics, each platform (Windows/Android/iOS/macOS) and specialty devices, and assignment filters and enrollment time grouping.
- 2.3Intune Suite and remote actions
Understand Intune Suite add-ons (Endpoint Privilege Management, Remote Help, Cloud PKI, Microsoft Tunnel, Advanced Analytics) and remote actions (sync/restart/retire/wipe, rotate BitLocker keys, device query KQL).
3Protect devices
- 3.1Endpoint security
Understand antivirus/disk encryption (BitLocker)/firewall/Attack surface reduction policies, security baselines, Microsoft Defender for Endpoint integration (EDR), and App Control for Business.
- 3.2Manage device updates
Understand update rings, feature updates vs quality updates, Windows Autopatch and Hotpatch, iOS/macOS updates via the Settings Catalog, Delivery Optimization, and update monitoring.
4Manage and secure applications
- 4.1Deploy and update apps
Understand Win32/LOB/Microsoft Store apps, Microsoft 365 Apps and the Office Deployment Tool, Apple VPP and Google Play, Quiet Time policies, and monitoring/troubleshooting installation failures.
- 4.2App protection and app configuration policies
Understand app protection policies (MAM) for in-app data protection on managed/unmanaged BYOD, requiring app protection via Conditional Access, and app configuration policies.
5Optimize endpoint operations
- 5.1Automate management tasks
Understand automating Intune management tasks with PowerShell and Microsoft Graph, extending compliance with PowerShell, and using Security Copilot agents in Intune for threat investigation, performance analysis, and acting on recommendations.
- 5.2Monitor and optimize health
Understand Endpoint Analytics (device health scores, startup performance, application reliability) and proactive remediations (detection/remediation scripts).
- 5.3Reporting and alerts
Understand Intune reporting (reports/workbooks/dashboards/export), tenant health and Intune service communications, and alerts and notifications (compliance drift/enrollment failures/configuration conflicts).

