Microsoft MD-102: What Matters Most

MD-102 is an endpoint-administration exam, but its current scope is much broader than “manage Windows devices.” Microsoft now frames the role around managing and securing endpoints in a Microsoft 365 tenant with Intune, Entra ID, Defender for Endpoint, Windows Autopilot, Windows 365, PowerShell, Microsoft Graph, and automation. That reflects how endpoint work has changed: device deployment, identity, compliance, application security, monitoring, and operational efficiency are now part of one management loop.

The current MD-102 exam measures five areas: preparing infrastructure for devices at 20–25 percent; managing and maintaining devices at 25–30 percent; protecting devices at 15–20 percent; managing and securing applications at 15–20 percent; and optimizing endpoint operations through automation, monitoring, and reporting at 10–15 percent. Those weights make device lifecycle management the largest area, but every domain interacts with identity and policy.

Strong preparation should therefore follow a device from before enrollment through retirement. Decide how it will join or register with Entra, how it will enroll in Intune, which configuration and compliance policies apply, how applications arrive, how security controls are enforced, how updates are managed, how health is monitored, and what happens when the device or user leaves the organization.

Prepare infrastructure before thinking about individual device settings

Endpoint management begins with tenant readiness, licensing, administrative roles, identity, enrollment restrictions, platform support, connectors, groups, and scope. If those foundations are wrong, a perfectly designed device policy may never reach the intended users. MD-102 candidates need to understand the administrative plane that makes large-scale management possible.

The Microsoft certifications places MD-102 inside a larger Microsoft 365 and Azure ecosystem. That matters because endpoint administrators collaborate with identity administrators, security teams, Microsoft 365 administrators, and cloud administrators. You do not need to own every adjacent system, but you need to know which dependency to check before assuming Intune itself is the problem.

Use a small tenant diagram in your notes. Include Entra identities and groups, Intune enrollment, compliance, Conditional Access, application sources, Defender integration, update services, and reporting. Every time you learn a feature, place it on the diagram. This prevents the exam from becoming a collection of policies with no operating context.

Enrollment is a lifecycle design decision, not just a wizard

Organizations enroll corporate and personally owned devices under different assumptions. Windows Autopilot can support modern provisioning for corporate devices, while other enrollment methods address different platforms and ownership models. The important question is what identity and management state the organization expects at each stage and which controls should apply before the user receives full access.

Practice enrollment failures deliberately. Use the wrong user scope, an enrollment restriction, a missing assignment, an unexpected ownership state, or a stale device object. Then trace what the user sees and what the administrator can verify. The lesson is that enrollment combines identity, licensing, policy, platform support, and service communication; failure at any of those layers can produce similar symptoms.

A good administrator also plans offboarding before onboarding. Know how retire, wipe, delete, and selective corporate-data removal differ, and understand the consequences for managed applications, certificates, keys, and device records. Lifecycle knowledge is more durable than memorizing one enrollment screen.

Manage and maintain devices as a fleet, not one endpoint at a time

The largest current MD-102 domain covers ongoing device management. Configuration profiles, settings catalogs, policy assignments, remote actions, Windows configuration, cloud-based deployment and upgrade, inventory, and device maintenance all belong here. The exam expects administrators to think at fleet scale, where policy consistency and exceptions matter more than manual fixes on one PC.

The practical guidance in MD-102 endpoint administration is strongest when paired with assignment strategy. Use dynamic or assigned groups carefully, separate testing rings from broad production, document exclusions, and verify effective policy. When two profiles configure the same setting, the administrator must understand conflict behavior rather than assuming the most recently created policy wins.

Remote actions should also be connected to incident and support workflows. Sync, restart, rename, rotate keys, collect diagnostics, or wipe can be useful, but each action has risk. Practice choosing the least disruptive action that restores control while preserving evidence and user productivity.

Protection combines compliance, endpoint security, identity, and update hygiene

Protecting devices is not a single Defender toggle. Endpoint administrators manage security baselines, antivirus and attack-surface controls, encryption, firewall settings, update behavior, compliance rules, and integrations with security services. Compliance can feed Conditional Access, linking device health to identity-based access decisions. That makes the endpoint a participant in Zero Trust rather than a trusted asset merely because it sits on a corporate network.

The discussion of MD-102 and Zero Trust endpoints is useful when turned into scenarios. A device is encrypted but out of date; another is compliant but shows suspicious behavior; a third is personally owned and uses app protection without full device management. Decide which control applies at each layer and what the user experience should be.

Updates deserve operational attention because security and reliability can conflict if rollout is unmanaged. Use deployment rings, deadlines, restart behavior, feature-update strategy, and reporting to control risk. A successful update policy is not one that exists in the portal; it is one that moves the fleet forward without creating blind spots or excessive disruption.

Application management includes delivery, configuration, and data protection

Application work in MD-102 covers deploying and updating applications as well as app configuration and app protection. Administrators need to understand packaging and assignment, required versus available deployment, dependencies, detection, update behavior, and how mobile application management can protect corporate data even when full device enrollment is not appropriate.

Test an application lifecycle end to end. Publish an app, assign it to a pilot group, observe installation reporting, simulate a detection failure, update the package, and remove it. Then add an app configuration or protection requirement. This turns “application management” into an operational workflow and exposes the dependencies between identity, platform, management state, and user data.

Automation and reporting are now explicit endpoint skills

The current MD-102 outline includes a dedicated area for optimizing endpoint operations with automation, monitoring, and reporting. That is a significant signal. Modern endpoint teams cannot scale by clicking through individual devices; they need repeatable scripts, Microsoft Graph interactions, remediation, queries, health reports, alerts, and dashboards that identify exceptions.

Start with a simple automation that answers a real question: find devices that are stale, detect a missing configuration, remediate a registry or settings condition, or report an enrollment anomaly. Log the action and verify the outcome. The goal is not to become a full-time software developer; it is to make endpoint operations repeatable and observable.

Reporting should lead to action. A dashboard showing noncompliant devices is useful only if the team can explain why devices are noncompliant, who owns the next step, how long remediation should take, and which exceptions are legitimate. Practice moving from aggregate health to one device and back again.

MD-102 and MS-102 meet at the Microsoft 365 operating boundary

MS-102 is broader across Microsoft 365 administration, tenant management, identity and access, security, and compliance. MD-102 goes deeper on endpoints. A Microsoft 365 administrator may define or coordinate policies that affect devices, while the endpoint administrator is responsible for making device enrollment, configuration, security, applications, and operations work at scale.

The boundary is useful in troubleshooting. If a device is correctly managed but access is blocked by a tenant-wide identity policy, the endpoint administrator needs enough Microsoft 365 and Entra context to identify the owner. If an organization has a broad compliance goal, the endpoint specialist translates the relevant part into device controls and evidence.

Azure knowledge helps, but MD-102 is not an Azure administration exam

The AZ-104 role overlaps through Entra identity, Azure resources, governance, and operational concepts, but it targets Azure administration rather than endpoint management. Candidates coming from Azure should resist the temptation to overinvest in infrastructure services that MD-102 does not emphasize. Their advantage is understanding cloud identity, access, and operating discipline.

Endpoint candidates without Azure experience should still learn the identity relationships well enough to understand device registration, groups, Conditional Access dependencies, permissions, and service integration. The exam does not require a second certification, but it assumes endpoint management happens inside a broader cloud identity and security environment.

Build one endpoint lab around policy conflicts, failure, and recovery

Create a small managed-device population with a pilot ring and a production-like ring. Enroll devices, assign configuration and compliance settings, deploy an application, enable protection, configure updates, and create a health report. Then introduce a conflict, a failed app installation, a noncompliant state, and an enrollment problem. Diagnose each one from evidence before changing settings.

The existing MD-102 endpoint responsibilities can help organize topics, but your lab should organize the thinking. Track the full lifecycle: prepare, enroll, configure, secure, deploy, monitor, remediate, update, and retire. That is the role the exam is trying to model.

Microsoft updates role-based exams regularly, so confirm the live study guide before test day. The durable skill is the ability to manage an endpoint fleet as a controlled system: identities and devices enter through defined processes, policy is applied predictably, applications and updates are delivered safely, security state affects access, and operations can see and correct exceptions.

img