Microsoft MD-102: A Practical Study Plan

MD-102 is an endpoint-management exam built around Microsoft Intune, Microsoft Entra ID, Windows Autopilot, application management, endpoint security, updates, automation, monitoring, and modern device operations. The current blueprint reflects an administrator who manages endpoints at scale rather than a technician who configures one Windows PC at a time.

As of October 5, 2026, the current MD-102 exam skills are the July 24, 2026 version. Microsoft has also announced another English-language blueprint update for October 27, 2026, so candidates testing after that date should recheck the study guide before final review.

A practical plan should begin with a small Microsoft 365 and Intune lab if possible. Create test users and groups, enroll devices or virtual machines, deploy policies and applications, and deliberately cause conflicts. Endpoint administration becomes much easier to remember when policy results are visible on a real device.

Start with tenant, identity, and enrollment prerequisites

Modern endpoint management depends on identity. Review Microsoft Entra join and registration states, licensing, device ownership, groups, enrollment restrictions, platform support, and the conditions that determine whether a device can be enrolled into Intune.

Do not memorize enrollment methods without context. Corporate Windows devices, BYOD mobile devices, shared devices, kiosks, and existing Configuration Manager estates can require different approaches. The administrator needs to choose a method that fits ownership, user experience, security, and deployment scale.

The Microsoft Entra ID is central because device management and access decisions depend on trustworthy identities, groups, and device records.

Windows Autopilot should be practiced as a deployment lifecycle

Autopilot is not simply an out-of-box wizard. Study device registration, deployment profiles, Enrollment Status Page behavior, user-driven and self-deploying scenarios, naming, group assignment, and the policies or applications that must arrive during provisioning.

Build one Autopilot deployment and record the dependencies. Which group receives the profile? Which apps are required? Which configuration policies block progress? What happens if the device loses connectivity? Which logs or Intune reports help explain a failed enrollment?

The Endpoint Administrator Associate certification validates the ability to plan and execute modern endpoint deployment, so candidates should understand not only how Autopilot starts but how the device reaches a managed, compliant, usable state.

Configuration profiles should be studied through policy outcomes

Intune can deliver settings through configuration profiles, security baselines, settings catalog policies, templates, and other management channels. Candidates need to recognize where settings overlap and what happens when policies conflict or fail to apply.

Create policies for browser settings, device restrictions, certificates, Wi-Fi, VPN, and Windows configuration. Then assign them to test groups and inspect device and user status. The useful skill is reading the result: succeeded, error, conflict, pending, or not applicable.

A mature administrator avoids making ten changes when one setting fails. Isolate the policy, confirm assignment, check applicability, inspect the client-side evidence, and understand which competing control may be overriding the intended value.

Compliance and Conditional Access should be tested together

Compliance policies define the state a device must meet, while Conditional Access can use that state as a signal when deciding whether access should be granted. The two capabilities are related but not identical.

Build a scenario where a device becomes noncompliant because encryption, password, operating-system version, or another requirement is missing. Confirm the compliance result, then observe what happens when an access policy requires a compliant device.

The adjacent MS-102 covers broader Microsoft 365 tenant administration. MD-102 stays focused on endpoint implementation, but endpoint administrators still need to understand how their device state feeds organization-wide access policy.

Application management needs deployment and protection practice

Study Windows apps, Microsoft 365 Apps, Store applications, line-of-business apps, Win32 deployment, app assignments, dependencies, supersedence, uninstall behavior, and update considerations. Then add mobile app protection and app configuration policies so the study plan includes both managed devices and managed application data.

For a Win32 app, practice packaging, detection rules, requirements, assignment, installation status, and troubleshooting. If an app fails, identify whether the problem is content, detection, dependency, user context, device context, network access, or installation logic.

The existing MD-102 endpoint administration is useful when it keeps application and policy work connected to the larger endpoint-operations role rather than treating Intune as a collection of independent menus.

Include a BYOD case where the organization needs to protect corporate data without taking full control of the personal device. Compare app protection with device enrollment, and verify how copy-and-paste restrictions, save-as behavior, managed application requirements, and selective wipe affect the user. This creates a clearer boundary between managing the endpoint itself and managing the organization’s data inside approved applications.

Endpoint security should be configured as layered control

MD-102 expects familiarity with endpoint security, Defender for Endpoint integration, firewall, antivirus, attack-surface reduction, disk encryption, account protection, security baselines, and the relationship between policy and device posture.

Create an endpoint-security lab where a device receives several controls, then verify them locally and in Intune. Trigger a policy conflict intentionally. Observe how security settings are reported and what evidence an administrator can use when a device does not match the expected state.

Security study should remain operational. The endpoint administrator is not replacing the SOC, but must know how management policies support protection and how alerts or device risk can influence access and remediation.

Update management is about rings, readiness, and recovery

Plan Windows update rings, feature update policies, quality updates, deadlines, deferrals, restart behavior, and reporting. Use small pilot groups before broad deployment. The exam can test both configuration and the operational logic behind staged rollouts.

A successful update strategy has a failure path. What happens if a driver breaks a critical application? How is a problematic update paused or rolled back? How does the administrator identify devices that are behind or stuck?

The AZ-104 exam is an infrastructure-administration credential rather than an endpoint credential, but candidates working across cloud and device teams benefit from understanding the boundary between Azure resource management and Intune-managed endpoints.

Practice device sync, restart, retire, wipe, Fresh Start or equivalent management actions where supported, remote diagnostics, and the reporting views that reveal device state. Understand the difference between removing corporate data and resetting the entire device.

When a policy or app fails, troubleshoot from both cloud and client perspectives. Check assignment, device identity, licensing, management extension status, event logs, policy reporting, and network reachability. Do not assume the Intune portal’s high-level status contains the whole answer.

Endpoint administrators operate distributed fleets, so evidence collection matters. A fix that works only when the user brings the laptop to the office is not enough for modern management.

Automation, monitoring, and reporting now deserve deliberate study

The July 2026 blueprint includes optimizing endpoint operations through automation, monitoring, and reporting. That means candidates should be comfortable with operational data, scripted or Graph-based tasks, health insights, and repeatable administrative workflows.

Do not treat automation as a final bonus topic. Use PowerShell or Microsoft Graph in a small way during study: retrieve a device list, inspect status, or repeat a safe administrative query. The goal is to understand why scale changes the administrator’s toolset.

Build one repeatable reporting task, such as identifying devices that have not checked in recently, devices with failed application deployment, or endpoints below a required operating-system version. Then decide what should be automated and what still needs human review. Endpoint administration at scale depends on turning telemetry into action without creating unsafe bulk changes.

The wider Microsoft certifications includes identity, security, Azure, and Microsoft 365 roles, but MD-102 is where endpoint automation becomes part of day-to-day operational competence.

Build mixed scenarios. A new device must be provisioned, receive applications, become compliant, access corporate resources, receive updates, and remain observable. A BYOD phone needs application protection without full device management. A pilot update causes issues. A remote user’s app deployment fails.

For each scenario, write the intended state and the evidence that proves it. That habit is more useful than memorizing every Intune blade because Microsoft can change interfaces while the management logic remains stable.

Include failure ownership in the exercise. If Autopilot fails, is the root cause identity, network, licensing, device registration, application deployment, or policy? If Conditional Access blocks the user, is the device actually noncompliant or is the compliance signal stale? Separating ownership prevents endpoint troubleshooting from becoming a sequence of random resets.

If you are taking the exam after October 27, 2026, compare your plan with the updated English blueprint before final review. The best preparation is current, but the durable skills remain deployment, policy, security, applications, updates, automation, and troubleshooting at scale.

MD-102 readiness means you can manage a fleet, not just a device

A single endpoint can be fixed manually. Thousands of endpoints require groups, policy, automation, reporting, staged deployment, and reliable recovery. That is the perspective the exam expects.

Your study plan is working when you can explain how a device enters management, receives configuration and apps, proves compliance, gains access, stays updated, reports health, and can be remediated remotely when something goes wrong.

That lifecycle is the real subject of MD-102. Intune is the central platform, but the skill is modern endpoint operations: controlled, secure, observable, and repeatable across an entire organization.

img