Microsoft MD-102: Skills Candidates Struggle With
MD-102 is difficult because endpoint management is no longer just Windows configuration. A modern endpoint administrator works across Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Microsoft Defender for Endpoint, Windows 365, application deployment, compliance, Conditional Access, update management, remote actions, reporting, automation, and user support. Candidates who study these services separately often struggle when a scenario connects several of them.
The current MD-102 exam is also in a transition window. Microsoft’s current study guide still lists the July 24, 2026 skills while also publishing an English-language update for October 27, 2026. Candidates testing before that date should prepare against the current blueprint; candidates testing on or after the update should recheck the live guide before final review.
The hardest questions usually describe a desired endpoint state and ask which control, assignment, identity signal, or deployment method gets the organization there with the least operational friction. The key is to think in lifecycle order: enrollment, configuration, compliance, applications, security, updates, monitoring, and recovery.
Intune enrollment depends on identity, licensing, platform support, enrollment restrictions, device ownership, management authority, and the enrollment method itself. A device that refuses to enroll may not have an Intune problem at all; it may have a licensing, join-state, scope, or platform restriction problem.
Practice distinguishing Microsoft Entra registered, joined, and hybrid joined devices. Then add ownership and platform. A corporate Windows device, personally owned iPhone, Android enterprise device, and shared kiosk do not follow the same management path.
The MD-102 endpoint administration perspective becomes more useful when candidates trace the prerequisites before reaching for a troubleshooting reset.
Windows Autopilot questions can include hardware registration, deployment profiles, group membership, Enrollment Status Page behavior, required applications, device naming, user-driven deployment, self-deploying scenarios, and pre-provisioning. The failure may appear at the screen, but the root cause can sit several layers earlier.
Create a diagram from device registration to final managed state. Which group receives the profile? Which apps are required during provisioning? Which policies can block the Enrollment Status Page? What happens when a required app fails detection?
The Endpoint Administrator Associate certification validates this whole deployment lifecycle, so Autopilot should be practiced as orchestration rather than as a wizard.
Settings can arrive from configuration profiles, Settings Catalog, security baselines, endpoint security policies, update policies, application configuration, and other management channels. The same setting may therefore appear in more than one policy.
When a device reports a conflict, inspect assignment, applicability, effective state, and the management channel that owns the setting. Do not simply delete one policy because it is newer or more visible in the portal.
For exam scenarios, ask whether the task is to configure a setting, secure an endpoint, enforce compliance, or control application behavior. Choosing the correct policy family is often the first half of the answer.
Intune compliance policies evaluate device state. Conditional Access can use the resulting compliance signal as one condition in an access decision. A device can therefore be enrolled yet noncompliant, compliant yet blocked by another access condition, or correctly configured but not reporting fresh state.
Build a lab where disk encryption or an operating-system requirement makes a device noncompliant. Then apply a Conditional Access rule that requires a compliant device and observe the sign-in evidence.
The adjacent SC-300 identity exam goes deeper into Conditional Access and identity governance, but MD-102 candidates need enough identity context to understand why endpoint posture affects application access.
Win32 application deployment can fail because of packaging, detection rules, requirements, dependencies, supersedence, install context, return codes, network access, or the installation command itself. The portal status is only the beginning of the investigation.
Practice packaging one application and write the detection logic before deployment. If detection is too broad, Intune can report success when the application is not actually in the required state. If it is too narrow, Intune can reinstall an application that is already present.
App protection policies introduce another axis: protecting organizational data inside applications without necessarily enrolling the entire personal device. Candidates should distinguish device management from managed application data.
Microsoft Defender for Endpoint, antivirus, firewall, attack-surface-reduction rules, disk encryption, account protection, security baselines, and endpoint privilege controls can all appear in the same scenario. The correct answer depends on the risk being reduced.
If the problem is malware execution, antivirus or attack-surface controls may matter. If the concern is stolen-device data, encryption matters. If the user has excessive local rights, account or privilege management is the target. A generic “security baseline” is not automatically the best response to every endpoint risk.
The broader AZ-104 administrator path operates at cloud-resource level rather than endpoint level, which helps clarify the role boundary: MD-102 owns managed endpoints and their security posture.
Windows updates involve pilot groups, quality updates, feature updates, deadlines, deferrals, restart behavior, reporting, and rollback. The hard part is balancing security and compatibility across a fleet.
Build three rings: validation, pilot, and broad deployment. Then simulate a bad driver or application regression. Decide which update should be paused, how affected devices are identified, and what evidence proves recovery.
Questions become easier when you think in deployment stages. A production-wide problem should not be solved by manually touching every device if the update policy can be adjusted centrally.
The July 2026 blueprint added explicit emphasis on automation, monitoring, and reporting. That reflects the real job: thousands of endpoints cannot be managed efficiently by clicking through individual records.
Use PowerShell or Microsoft Graph for one safe inventory task. Find devices that have not checked in, endpoints below a required OS version, or applications with failed deployment. Then decide which response can be automated and which requires review.
The wider Microsoft certifications split identity, Microsoft 365, security, cloud, and endpoint roles, but large-scale endpoint administration depends on understanding how those services exchange signals.
For final practice, take one new laptop from shipment to productive use. Register it, enroll it, apply profiles, deploy applications, verify compliance, enforce access, onboard security tooling, apply updates, monitor health, and perform a remote action. Then break one stage and determine which team or service owns the failure.
If you test after October 27, 2026, compare the updated Microsoft blueprint with your notes before the exam. The platform evolves, but the lifecycle remains a stable way to organize the work.
MD-102 becomes far less confusing when every setting belongs to a stage of endpoint operations. The exam is testing whether you can manage a fleet predictably, securely, and at scale—not whether you can memorize the most Intune menus.
Device ownership and management authority deserve deliberate practice because they influence which settings are appropriate. A corporate laptop can usually accept deeper management than a personally owned phone. Shared devices may require different enrollment and sign-in behavior again. When a scenario includes BYOD, kiosk, frontline, or shared-use language, pause before selecting the same policy you would use for a normal assigned Windows device.
Remote actions are another area where candidates can lose points by choosing the most destructive response. Sync, restart, retire, wipe, Fresh Start, remote lock, or other actions solve different problems and have different effects on user data. Read the scenario for ownership and recovery requirements before selecting a reset operation. A corporate device being reassigned is not the same as a personal device that should lose only organizational data.
Windows 365 and Cloud PC management can also appear in the broader endpoint role. The administrator may need to understand provisioning, policy assignment, user licensing, device access, and how cloud-hosted desktops integrate with Intune and Entra ID. The important skill is recognizing that a Cloud PC is still part of the managed endpoint estate even though the hardware is hosted in Microsoft’s cloud.
For final practice, build a matrix with rows for enrollment, configuration, compliance, apps, security, updates, automation, and remote recovery. Put one common failure and one evidence source in each row. If you cannot say where to look when a stage fails, that stage needs more hands-on work. MD-102 scenario questions become much easier when every symptom has a natural place in the endpoint lifecycle.
Licensing is worth adding to scenario practice because an apparently correct configuration can remain unavailable when the user or tenant lacks the required entitlement. Before troubleshooting a missing feature as a policy bug, confirm that the necessary Intune, Microsoft 365, Defender, or add-on licensing exists for the scenario. The exam does not require memorizing every commercial bundle, but it does expect administrators to recognize licensing as a prerequisite.
Keep the final review current to your test date. The October 27 blueprint update adds and adjusts endpoint topics, but the durable skill remains lifecycle reasoning: identify where the device is in management, what state it should have, which service owns that state, and which evidence proves the difference.