MD-102 is the exam behind the Microsoft 365 Certified: Endpoint Administrator Associate certification, and it maps closely to what an Intune administrator does every day: enrolment, Autopilot, configuration, security, updates, apps and reporting. In this post I'll lay out a five-stage study plan built around the official Microsoft Learn learning paths, the labs worth doing in a test tenant, and what to expect on exam day.
Who this path is for#
This plan suits helpdesk and desktop engineers moving into device management, Configuration Manager admins adopting Intune, and Microsoft 365 admins who have inherited the Intune workload. You'll get the most from it if you already know basic Windows administration, Microsoft Entra ID (users, groups, licensing) and some PowerShell; Microsoft's audience profile also expects awareness of Microsoft Security Copilot, Intune agents and Microsoft Defender XDR.
Prerequisites in practice: a test tenant you can break (Intune plus Microsoft Entra ID P1, which Microsoft 365 E3/E5 and Business Premium include), a Windows 11 virtual machine or spare laptop you can reset repeatedly, and ideally a phone for mobile scenarios. Budget six to eight weeks at a few hours a week.
The exam at a glance#
Exam MD-102 is titled Managing and Securing Microsoft 365 Endpoints by using Intune and earns the Microsoft 365 Certified: Endpoint Administrator Associate certification. Microsoft's study guide notes the English version is being updated on October 27, 2026; the top-level domains and their weightings are unchanged by that update, but several sub-skills were revised, so read the current guide before you book.
The skills measured, as published in Microsoft's study guide (skills measured as of October 27, 2026):
| Domain | Weight |
|---|---|
| Prepare infrastructure for devices | 20–25% |
| Manage and maintain devices | 25–30% |
| Protect devices | 15–20% |
| Manage and secure applications | 15–20% |
| Optimize endpoint operations by using automation, monitoring, and reporting | 10–15% |
Other details from Microsoft Learn: a score of 700 or more passes, you get 100 minutes, the exam may contain interactive components, and a first retake is allowed 24 hours after a failed attempt. The listed price is 165 USD but varies by country. Microsoft updates the study guide regularly, so re-check it close to your exam date.
Stage-by-stage plan#
The current Microsoft Learn course for this exam is Manage and secure Microsoft 365 endpoints by using Intune. It's split into seven learning paths; the stages below group them by exam domain.
Stage 1 (week 1–2): identity, enrolment and compliance#
Study the learning path Prepare infrastructure for devices using Microsoft Intune and Microsoft Entra ID. Be able to explain Microsoft Entra join versus registration versus hybrid join, dynamic group rules, Windows automatic enrolment and the MDM user scope, Apple Business Manager and Android Enterprise enrolment profiles, Intune RBAC with scope tags and multi-admin approval, and how compliance policies feed Conditional Access. Windows Hello for Business, Windows LAPS and local group membership also sit here.
Stage 2 (week 3): deploy and configure devices#
Study Manage and maintain devices using Microsoft Intune. The exam expects you to choose between Windows Autopilot deployment profiles and the newer device preparation policies, know the deployment modes (user-driven, pre-provisioning, self-deploying), build an Enrollment Status Page, plan Windows 11 upgrades and understand Windows 365 provisioning. On configuration, know the settings catalog, ADMX import, Group Policy analytics, assignment filters and enrolment time grouping, plus remote actions such as wipe, retire, BitLocker key rotation and device query with KQL. Add Extend endpoint capabilities using Microsoft Intune Suite here: Endpoint Privilege Management, the Enterprise App Catalog, Remote Help, Cloud PKI, Microsoft Tunnel for MAM and Advanced Analytics are all named in the study guide.
Stage 3 (week 4): protect devices and manage updates#
Study Protect devices using Microsoft Intune. Cover the endpoint security policy types (antivirus, disk encryption, firewall, attack surface reduction, App Control for Business, EDR), security baselines, and onboarding to Defender for Endpoint. The updates half includes update rings, feature and quality update policies, Windows Autopatch and hotpatch, iOS/iPadOS and macOS update policies in the settings catalog, Android firmware updates and Delivery Optimization.
Stage 4 (week 5): applications#
Study Manage applications using Microsoft Intune: Win32, line-of-business and Microsoft Store apps, Microsoft 365 Apps (including the Office Deployment Tool during Autopilot), apps from Apple Business Manager and Managed Google Play, app protection and app configuration policies, and Conditional Access that requires an app protection policy.
Stage 5 (week 6–7): automate, monitor and rehearse#
Study Automate and optimize endpoint management using Microsoft Intune and Support operational excellence and readiness using Microsoft Intune. Topics include Microsoft Graph PowerShell automation, custom compliance scripts, Security Copilot agents in Intune, Endpoint analytics and Remediations, report customisation and export, service health and alert rules. Finish with the free practice assessment on Microsoft Learn and revisit every weak domain.
Hands-on practice#
Reading alone doesn't pass this exam. Work through these labs in your test tenant and note what each blade looks like:
- Autopilot end to end: capture a hardware hash with the
Get-WindowsAutopilotInfoscript, import the CSV, create a dynamic group on theZTDidattribute, build a user-driven Microsoft Entra join profile and an Enrollment Status Page, then reset the VM and watch it provision. - Compliance plus Conditional Access: require BitLocker and a minimum OS version, then pair the policy with a report-only Conditional Access policy and check the result with What If before enforcing.
- Win32 app: package an installer with the Microsoft Win32 Content Prep Tool, set install and uninstall commands, a requirement rule and a detection rule, assign it as Required to a pilot group and read the install status report.
- Update rings: create pilot and broad rings with different deferral and deadline values, then check the per-setting status report.
- Remediations: write a detection and a remediation script, deploy them on a schedule and review the output columns.
- App protection: target a policy for Outlook on iOS or Android to a test user and confirm the PIN prompt on a personal device.
- Baseline plus endpoint security: deploy the Security Baseline for Windows 10 and later, add an antivirus policy, deliberately create a conflicting setting and find it in the reports.
Tip: Keep a one-page "where is it?" sheet of portal paths as you go. Many exam questions are really asking which blade owns a task, and the admin center moves things around.
Exam-day tips#
- Register with a personal Microsoft account; Microsoft warns that exam records tied to a work account are lost if you leave the organisation.
- Try the exam sandbox on Microsoft Learn beforehand so the question types hold no surprises.
- Read for the qualifier: "least administrative effort", "minimum licensing", "without re-enrolling". The right answer satisfies the qualifier, not just the requirement.
- In a case study, read the questions first and then hunt for the relevant requirement.
- Mark uncertain questions for review and keep moving; 100 minutes goes quickly. If the exam isn't offered in your preferred language, you can request an extra 30 minutes.
After the exam#
Microsoft associate, expert and specialty certifications expire annually. You renew for free by passing an online assessment on Microsoft Learn before the expiry date, so connect your certification profile to your Learn profile early.
Sensible next steps for an Intune administrator: SC-300 (Microsoft Certified: Identity and Access Administrator Associate) deepens the Microsoft Entra ID side of device management, and SC-200 (Microsoft Certified: Security Operations Analyst Associate) covers the Defender XDR and Defender for Endpoint skills that endpoint admins increasingly share with security teams. One caution: Microsoft has announced that Exam MS-102 and the Microsoft 365 Certified: Administrator Expert certification retire on November 30, 2026, so don't build your roadmap around that one.