Active Microsoft associate certification
MD-102 Microsoft Endpoint Administrator Roadmap
Prepare infrastructure, enroll and maintain multiplatform devices, protect endpoints, deliver secure applications, and improve operations with automation, health evidence, reporting, and accountable agent-assisted decisions.
Exact 50-question study allocation
The public blueprint publishes ranges, not a prescribed practice-bank split. PrepKloud's independent 50-item bank uses an exact allocation inside those ranges: Prepare infrastructure 12; Manage and maintain devices 14; Protect devices 9; Manage and secure applications 9; Optimize endpoint operations 6.
Entra device identity, enrollment, RBAC, compliance, Conditional Access, Hello, LAPS.
Autopilot, Windows 365, profiles, Intune Suite, remote actions, diagnostics.
Antivirus, encryption, firewall, ASR, baselines, EDR, App Control, updates.
Win32, stores, Microsoft 365 Apps, app protection, configuration, access.
PowerShell, Graph, custom compliance, agents, Analytics, Remediations, health.
Phase 1 — Identity, enrollment, compliance, and delegated administration
Begin by separating device registration, Microsoft Entra join, hybrid join, and Intune enrollment. Choose from ownership, platform, user affinity, identity source, and management need—not from a preferred wizard.
- Design Microsoft Entra device groups, including supported dynamic membership rules.
- Configure MDM user scope, enrollment restrictions, and platform-specific corporate paths.
- Compare Apple automated device enrollment, Android fully managed, corporate-owned work profile, dedicated, Knox Mobile Enrollment, and Zero Touch.
- Delegate administration through built-in or custom roles, scope groups, scope tags, and Multi Admin Approval.
- Implement compliance separately from Conditional Access enforcement.
- Configure Windows Hello for Business, Windows LAPS, and local group membership with least privilege.
Phase 2 — Autopilot, Cloud PCs, configuration, and Intune Suite
Build a repeatable device lifecycle. Compare Autopilot deployment profiles with device preparation policies and select user-driven, pre-provisioning, or self-deploying mode from the scenario. Use ESP only for genuinely required setup.
- Deploy and upgrade Windows clients and plan supported Windows Backup and Restore behavior.
- Provision Windows 365 Cloud PCs with approved images, network connections, and policies.
- Create Windows, Android, iOS/iPadOS, macOS, Teams Rooms, HoloLens, and Zebra profiles as applicable.
- Use Group Policy analytics, imported ADMX, Settings Catalog, assignment filters, and enrollment-time grouping deliberately.
- Practice Endpoint Privilege Management, Enterprise App Catalog, Remote Help, Cloud PKI, Tunnel for MAM, and Advanced Analytics concepts.
- Perform sync, restart, retire, wipe, bulk actions, key rotation, device query, diagnostics, and user-centered troubleshooting safely.
Phase 3 — Endpoint security and update engineering
Layer endpoint controls rather than treating one baseline as complete protection. Connect Intune with Defender for Endpoint, onboard devices, and know how EDR evidence and device risk interact with compliance.
- Deploy antivirus, disk encryption, firewall, attack surface reduction, and security baseline policies through pilot rings.
- Recover and rotate BitLocker keys, monitor encryption state, and preserve least-privilege recovery access.
- Configure EDR policy, investigate threats, triage incidents, and distinguish connector configuration from onboarding.
- Design App Control for Business in audit before broad enforcement.
- Separate update rings, feature updates, quality updates, Autopatch, Hotpatch, and Delivery Optimization responsibilities.
- Include supported iOS/iPadOS, macOS, and Android update approaches and monitor deployment evidence.
Phase 4 — Application delivery and mobile data protection
For every app, reason through source, package, requirements, dependencies, detection, return codes, assignment intent, update path, supersedence, uninstall, and monitoring. A successful process exit is not enough if the app is unusable.
- Package and deploy Win32, line-of-business, Microsoft Store, Microsoft 365 Apps, Apple VPP, and managed Google Play apps.
- Use robust detection rules and inspect Intune Management Extension evidence when status is unexpected.
- Plan Microsoft 365 Apps architecture, channel, suite selection, and Autopilot timing.
- Configure supported Office policies from Intune or the Microsoft 365 Apps admin center.
- Protect organizational data on enrolled and unenrolled mobile devices with app protection policies.
- Deliver app settings through app configuration and reinforce supported access with Conditional Access.
Phase 5 — Automation, monitoring, reporting, and operational readiness
The July 2026 blueprint makes operations a distinct domain. Use PowerShell and Microsoft Graph with minimum permissions, deterministic scripts, protected identities, pagination, throttling handling, audit, and rollback.
- Build read-only inventory before write automation and extend compliance with a tested script plus JSON rules.
- Create idempotent Remediations detection and correction scripts with explicit outputs and schedules.
- Analyze startup performance, device health, app reliability, restart frequency, and user-experience cohorts in Endpoint Analytics.
- Customize reports, filters, workbooks, dashboards, and exports while minimizing personal data.
- Correlate Intune tenant status, Microsoft 365 service health, Message center notices, enrollment failures, compliance drift, and conflicts.
- Review Security Copilot agent threat, performance, and recommendation evidence; pilot changes and retain human approval.
Official Microsoft source set
All MD-102 learning surfaces
Frequently asked questions
Is MD-102 active in 2026?
Yes. Microsoft Learn lists the active Endpoint Administrator Associate certification and a study guide with skills measured from July 24, 2026. Recheck it before scheduling.
How long is MD-102?
Microsoft lists 100 minutes. Verify current scheduling, language, accommodation, and delivery details on the official exam page.
What are the current domains?
Prepare infrastructure 20-25%; manage and maintain devices 25-30%; protect devices 15-20%; manage and secure applications 15-20%; optimize endpoint operations 10-15%.
How are the 50 practice questions allocated?
12 infrastructure, 14 devices, 9 protection, 9 applications, and 6 operations. This is an independent study allocation, not a prediction of any live form.
Do I need a production tenant?
No. Use a disposable developer, trial, instructor, or otherwise authorized training tenant with synthetic data and test devices. Never test wipe or broad enforcement against production.
Are these questions from the live exam?
No. PrepKloud questions, cards, projects, and prose are original educational content grounded in public objectives and official documentation.
Does this roadmap guarantee a passing score?
No. It structures preparation but cannot guarantee a score, pass, role, promotion, or salary. Validate readiness through official sources, safe hands-on work, and honest weak-area review.
Build operational endpoint evidence
Read the guide · Start questions · Review cards · Build projects