MD-102 now tests more than endpoint configuration. The July 24, 2026 blueprint adds a fifth domain for automation, monitoring, reporting, Endpoint Analytics, proactive remediations, and Security Copilot capabilities in Intune. Older material can still teach the fundamentals, but it may leave out the operational work that now appears in the exam objectives.
The short version
- The current MD-102 skills are measured as of July 24, 2026, with five domains instead of the earlier four-domain structure.
- The new fifth domain covers automation, monitoring, reporting, Endpoint Analytics, proactive remediations, tenant health, alerts, and Security Copilot capabilities in Intune.
- Manage and maintain devices remains the largest domain at 25–30%. Autopilot, device preparation, enrollment, configuration profiles, device actions, and diagnostics remain central.
- Microsoft does not publish a fixed question count. Recent candidate accounts describe roughly 45 to 53 questions, sometimes alongside case studies or interactive lab-style tasks.
- Preparation time ranges from about four weeks for experienced Intune administrators to three or four months for beginners. Hands-on tenant work matters at every level.
The practical change is straightforward. You are no longer preparing only to configure devices and applications. You are preparing to operate an endpoint environment, investigate its state, automate routine work, and explain what the data says.
Quick facts
| Item | Current MD-102 detail |
|---|---|
| Exam code | MD-102 |
| Current update | Skills measured as of July 24, 2026 |
| Domains | Five domains |
| Duration | 100 minutes |
| Price | $165 USD, varying by country or region |
| Passing score | 700 out of 1000 |
| Delivery | Pearson VUE test center or online proctored |
| Renewal | Valid for 12 months; renew annually at no cost with a Microsoft Learn assessment |
What changed on July 24, 2026
The main change is structural. Microsoft’s current MD-102 objectives contain five domains, and the fifth is Optimize endpoint operations by using automation, monitoring, and reporting. It accounts for 10–15% of the blueprint.
That domain adds a different kind of work to the exam. Earlier objectives centered mainly on preparing, managing, protecting, and securing endpoint devices and applications. The current objectives also ask administrators to work with PowerShell and Microsoft Graph, interpret Endpoint Analytics, create or use proactive remediations, build reports and dashboards, investigate endpoint issues, and respond to tenant health information.
The revision makes newer endpoint capabilities explicit inside the existing management and security areas. These include device preparation policies alongside classic Windows Autopilot deployment profiles, Intune Suite capabilities, KQL device queries, diagnostic collection, Windows Autopatch with Hotpatch, and Security Copilot agents and recommendations in Intune.
Microsoft’s own change log provides a direct prior-versus-current comparison. It does not publish the former numeric ranges in that table, so the honest comparison is directional: infrastructure increased, device management decreased, two domains kept their share, and the new operations domain now takes 10–15%.
| Prior skill area | Current skill area | Microsoft’s change rating |
|---|---|---|
| Audience profile | Updated audience profile | Minor |
| Prepare infrastructure for devices | Prepare infrastructure for devices | Exam share increased |
| Add devices to Microsoft Entra | Add devices to Microsoft Entra ID | Minor |
| Enroll devices to Microsoft Intune | Enroll devices to Microsoft Intune | Major |
| Implement identity and compliance | Implement identity and compliance | Minor |
| Manage and maintain devices | Manage and maintain devices | Exam share decreased |
| Deploy and upgrade Windows clients by using cloud-based tools | Same objective | Major |
| Plan and implement device configuration profiles | Same objective | Minor |
| Implement Intune Suite add-on capabilities | Same objective | Minor |
| Perform remote actions on devices | Same objective | Major |
| Manage applications | Manage and secure applications | No change at domain level |
| Deploy and update apps | Same objective | Minor |
| Plan and implement app protection and app configuration policies | Same objective | Minor |
| Protect devices | Protect devices | No change at domain level |
| Configure endpoint security | Same objective | Major |
| Manage device updates by using Intune | Manage device updates | Minor |
| Not present | Optimize endpoint operations by using automation, monitoring, and reporting | New |
| Not present | Automate management tasks | New |
| Not present | Monitor and optimize health | New |
The current official ranges are:
| Current domain | Official weight range | Direction from the prior version |
|---|---|---|
| Prepare infrastructure for devices | 20–25% | Increased |
| Manage and maintain devices | 25–30% | Decreased |
| Protect devices | 15–20% | No domain-level change |
| Manage and secure applications | 15–20% | No domain-level change |
| Optimize endpoint operations by using automation, monitoring, and reporting | 10–15% | New |
No specific removal is identified in Microsoft’s change log. The useful interpretation is narrower: MD-102 now has an explicit operations layer, while identity, enrollment, device management, security, and application administration remain part of the exam.
The mental model behind the new blueprint
Endpoint administration has become less about setting a policy once and more about operating a device fleet over time, including through Endpoint Analytics. An administrator prepares devices, identifies failures, investigates user-impacting problems, automates repetitive work, and reports on whether the environment is healthy.
The fifth domain reflects that operational cycle. Its topics connect administration to evidence: device health, application startup performance, tenant alerts, dashboards, proactive remediations, and data gathered through Graph, PowerShell, KQL, and Endpoint Analytics. You are not only configuring the endpoint. You are deciding what the data says and what action should follow.
The update also reflects how Microsoft’s endpoint tools have developed. Device preparation now sits alongside classic Autopilot workflows. Intune Suite capabilities are included in endpoint operations. Security Copilot appears as an investigation and recommendation tool. Windows update management includes Autopatch and Hotpatch.
The exam still validates knowledge rather than production experience. Hands-on work carries more weight in an interview, but MD-102 now tests whether you understand the decisions involved in running an endpoint environment.
Domain breakdown
Domain 1, Prepare infrastructure for devices (20–25%)
This domain covers device identity, enrollment, grouping, access, compliance, and endpoint security foundations. The official scope includes Entra registered, joined, and hybrid joined devices; Intune enrollment for Windows, Apple, and Android; dynamic groups; RBAC; scope tags; multi-admin approval; compliance; Conditional Access; Windows Hello for Business; Windows LAPS; and local group membership.
The distinction between identity and enrollment is the trap. A device can be registered, joined, or hybrid joined, and those states answer different questions. Enrollment determines how management is applied. Compliance evaluates the device against requirements. Conditional Access then uses that result when access is requested.
Recent test-taker accounts repeatedly describe Entra identity, enrollment methods, compliance, and Conditional Access as scenario-heavy areas. The question is rarely “What is Entra join?” It is closer to “Given this device state, user, enrollment method, and compliance result, what happens next?”
Cross-platform details also matter. Windows automatic enrollment, Apple Business Manager, Android Enterprise with Knox Mobile Enrollment, and Google Zero Touch all appear in the current scope. Do not study this domain as a vocabulary list.
Domain 2, Manage and maintain devices (25–30%)
This is the largest domain. It covers Windows Autopilot deployment profiles and device preparation policies, user-driven, pre-provisioning, and self-deploying modes, and Enrollment Status Page configuration. It also covers Windows 11 upgrades, Windows 365 provisioning, configuration profiles, ADMX and Group Policy analytics, Intune Suite capabilities, remote actions, KQL device queries, and diagnostics.
Practitioners commonly describe this as one of the most visible parts of the live exam. Autopilot, detailed Intune settings, enrollment, device actions, and interactive lab-style work appear repeatedly in experience accounts. Older material often treats classic Autopilot as the entire deployment story. The current objectives do not.
Know the difference between retire, delete, wipe, and Autopilot Reset. These actions have different consequences, and a scenario can turn on a single word about whether the device should be preserved, removed, or prepared for another user.
Device preparation policies deserve focused study. Compare them with classic deployment profiles, then connect each approach to the appropriate deployment mode and Enrollment Status Page behavior. Configuration profiles and diagnostics belong here too. A candidate who can describe a setting but cannot troubleshoot its outcome is exposed in this domain.
Domain 3, Protect devices (15–20%)
Protection covers antivirus, BitLocker, firewall policies, Attack Surface Reduction, Zero Trust, security baselines, Defender for Endpoint onboarding and EDR, incident triage, App Control for Business, update rings, feature and quality updates, Windows Autopatch, Hotpatch, and Delivery Optimization.
The failure reports are consistent on this point: knowing the product description is not enough. Questions can depend on policy interaction, onboarding state, recovery information, or the difference between a security baseline and a more targeted endpoint security policy.
BitLocker recovery and compliance monitoring deserve practical attention. So do Defender for Endpoint onboarding and the relationship between security configuration and Conditional Access. A secure setting that has not reached the device is not the same as a secure setting that is actively enforced.
Update management is broader than a single Windows update ring. The current scope includes Windows, Apple, and Android update management, along with Autopatch and Hotpatch. Learn what each control is intended to manage and what evidence would show that it worked.
Domain 4, Manage and secure applications (15–20%)
This domain covers Win32, line-of-business, and Microsoft Store apps; Microsoft 365 Apps and the Office Deployment Tool; Apple volume-purchased apps; Google Play; deployment troubleshooting; app protection policies; mobile application management; app configuration policies; and Conditional Access for app protection.
The central distinction is among device configuration, app configuration, and app protection. Device configuration manages the endpoint. App configuration supplies settings to an application. App protection controls how organizational data is handled inside supported applications, including on unmanaged devices.
Recent accounts describe low-level, cross-platform application questions, including iOS package details, MAM, and app protection. The operating system matters. Distribution methods, package formats, assignment behavior, and troubleshooting steps are not interchangeable across Windows, Apple, and Android.
Microsoft 365 Apps add another layer because deployment can involve Intune or the Microsoft 365 Apps admin center, with the Office Deployment Tool relevant during Autopilot. Study the workflow rather than memorizing isolated portal locations.
Domain 5, Optimize endpoint operations by using automation, monitoring, and reporting (10–15%)
This is the new domain. It covers PowerShell and Microsoft Graph automation, Security Copilot agents and recommendations in Intune, PowerShell-based compliance extensions, custom reports, filters, workbooks, dashboards, Endpoint Analytics, proactive remediation scripts, device health, application startup performance, tenant health, service communications, and operational alerts.
The available evidence is too recent for a deep independent consensus about how heavily each topic appears. The official objective set is enough to establish the priority. Treat automation, monitoring, reporting, KQL and device queries, proactive remediation, and Security Copilot as required study areas.
A useful way to learn this domain is to start with an operational question. Which devices have a problem? What evidence supports that conclusion? Can a query, report, script, or remediation reduce the work? How would you confirm that the fix improved device health or user experience?
This domain is smaller than device management, but it carries a higher stale-material risk. Older courses and practice tests may still reflect the earlier four-domain blueprint.
What older study material gets wrong
The first stale pattern is the four-domain outline. If a course, summary, or practice set ends after application management, it is organized around the earlier shape of the exam. That does not make every page useless. It makes the coverage incomplete.
The second stale pattern is treating Autopilot as one feature with one workflow. The current objectives require a distinction between classic Windows Autopilot deployment profiles and device preparation policies. They also include user-driven, pre-provisioning, and self-deploying modes, as well as Enrollment Status Page configuration.
The third is a thin treatment of operations. Candidates need exposure to PowerShell and Graph automation, custom reports, filters, workbooks, dashboards, Endpoint Analytics, proactive remediation scripts, tenant health, alerts, and device or performance data. A source that only teaches how to create a configuration profile will not prepare you for this part of the blueprint.
The fourth is cross-platform compression. The current objectives cover Windows, Apple, and Android enrollment and management. Application questions can involve managed and unmanaged devices, app protection, app configuration, and platform-specific distribution systems.
The fifth is relying on familiar practice banks without checking their date. Reported experiences mention newer Intune capabilities, device preparation, niche defaults, low-level settings, distracting case-study information, and interactive lab or virtual-lab tasks.
The current Microsoft study guide and documentation are the supplemental reference for terminology and detailed coverage. The July 24, 2026 objective set is the coverage to prepare against.
How to prepare for the current version
Start with the official foundation
Use Microsoft’s current MD-102 learning paths and study guide to map the five domains. The official material is strongest as a coverage checklist and terminology reference. Its weakness is that completing a learning path does not prove you can reason through policy conflicts, device states, or live troubleshooting.
The Microsoft Learning MD-102T00 lab files can turn the outline into practical exercises. The current blueprint changes quickly enough that the objective set, official documentation, and hands-on portal work should anchor your preparation.
Use practice questions diagnostically
Start with the MD-102 practice questions on CertCompanion. CertCompanion has realistic practice questions with detailed explanations for this exam, and you can begin with 30 free questions at certcompanion.com.
Use missed questions to identify a domain or distinction that needs work. Aim for 80% to 90% on varied practice sets before scheduling, but do not treat a score as proof of readiness if you have not practiced policy evaluation, case studies, and hands-on workflows.
You can also browse the Microsoft certification resources for official provider context. Microsoft’s free practice assessment is useful for diagnosis, although candidates commonly describe it as less representative than the live exam. Follow missed answers into Microsoft documentation and a tenant exercise.
Build a small operations lab
Mira, with several years of Intune and Entra experience, can compare a classic Autopilot deployment profile with a device preparation policy, configure an Enrollment Status Page scenario, run a KQL device query, collect diagnostics, review Endpoint Analytics data, and test a proactive remediation.
Jon, with Windows administration experience but little workplace Intune exposure, needs a longer sequence. He should begin with identity and enrollment, then move through compliance and Conditional Access, configuration, applications, security policies, update management, automation, and reporting.
A useful practice session has a concrete outcome. Take a device that is registered but not joined, determine how it should enroll, apply a compliance policy, observe the result, and trace how Conditional Access changes access. Separately, deploy an application, compare app configuration with app protection, and investigate a failed deployment.
Spend focused time on four operational areas:
- PowerShell and Microsoft Graph concepts
- Endpoint Analytics, reports, dashboards, and device health
- Proactive remediations and compliance extensions
- Security Copilot investigation and recommendations
The exact tenant capabilities available to you may vary. The objective language still tells you what to understand.
Study timeline by background
Recent candidate accounts range from about four weeks to three or four months. The difference is mostly prior Intune and Entra experience, hands-on access, and the amount of time available while working full time.
| Background | Estimated time | What drives the difference |
|---|---|---|
| Several years of Intune or Entra experience | About 4 weeks to 1 month | Existing familiarity with enrollment, policy evaluation, applications, and troubleshooting leaves the new operations domain as the main gap. |
| Adjacent Microsoft or Windows administration experience | Roughly 1 to 2 months | The platform is familiar, but Intune policy interactions, cross-platform management, and operational reporting need deliberate practice. |
| New to workplace Intune | Around 3 to 4 months | Identity, enrollment, compliance, applications, security, and automation must all be learned, preferably with hands-on tenant access. |
Mira and Jon should not use the same calendar. The number of endpoint states each person has already seen matters more than a generic hour target.
Logistics that did not fundamentally change
The exam costs $165 USD, varying by country or region, and the passing score is 700 out of 1000. Testing is available through a Pearson VUE test center or online proctoring.
The exam takes 100 minutes. Microsoft does not publish a fixed question count, while recent accounts describe roughly 45 to 53 questions, sometimes with case studies or lab-style components. Plan around the clock, not a promised number of questions.
The format includes scenario-based questions, multiple choice, multiple response, case studies, and potentially interactive lab-style components. Microsoft’s retake policy applies, but the exact interval should be confirmed on the current exam details page before booking.
Language can affect the experience. Reported experiences mention wording and translation issues, and eligible candidates should request the 30-minute ESL accommodation before scheduling. Online candidates should report virtual machine or authentication problems immediately.
The fundamentals stayed. Identity, enrollment, compliance, Conditional Access, configuration profiles, application deployment, security policy, update management, and device actions remain part of MD-102.
Where candidates lose points
The most common failure pattern is studying the old exam successfully. A candidate can score well on an older assessment and still miss device preparation, Intune Suite capabilities, KQL queries, diagnostics, Endpoint Analytics, proactive remediations, reporting, or Security Copilot.
Another problem is reading without operating. Compliance outcomes and policy conflicts are difficult to internalize from prose alone. Build or access a tenant and perform the workflow.
Case studies create a separate pressure point. The background can contain substantial distracting information, so read the questions before scanning the scenario for relevant facts. Mark uncertain items and keep moving.
Four habits cause avoidable trouble:
- Memorizing old question banks
- Treating Microsoft practice assessments as complete coverage
- Confusing retire, delete, wipe, and Autopilot Reset
- Treating app configuration, app protection, and device configuration as the same policy family
The exam can also include niche defaults and low-level settings. You do not need to memorize every portal label, but you do need to understand what a policy is meant to control and how its result appears on a device.
Exam-day tactics
Schedule only after your preparation includes the current five-domain objectives. Confirm the delivery option, check the current retake details, and request any eligible ESL accommodation before booking.
Use the first questions to establish pace. If a question is consuming too much time, flag it and move on. A case study or lab component can change the rhythm of the exam, so do not spend the opening section as if every item were a short definition question.
Read the question before the case-study background. Look for qualifiers about device state, user identity, platform, enrollment method, compliance, and the desired outcome.
The Microsoft Learn reference experience may be available during the exam, but it cannot rescue poor pacing. Use it for a precise lookup, not as a replacement for knowing the workflow.
After the exam, score reporting follows the delivery process. Certification renewal is separate from the exam result: MD-102 is valid for 12 months and can be renewed annually at no cost through a Microsoft Learn assessment.
After you pass
MD-102 maps to Endpoint Administrator, Intune Administrator, Modern Workplace Engineer, Microsoft 365 Administrator, Endpoint Management Engineer, and Systems Administrator roles. The credential is most useful when paired with evidence of hands-on work.
For an experienced administrator, the updated exam can validate a move toward broader endpoint operations. Interview examples should include automation, troubleshooting, reporting, and the reasoning behind a policy decision.
For someone earlier in their career, the certification can provide structure for a move into Microsoft endpoint work. It will not substitute for experience. A small portfolio of documented tenant exercises can make the credential more credible because it shows what you actually did.
Possible next certifications include:
- MS-102 Microsoft 365 Administrator Expert, for broader Microsoft 365 administration
- SC-300 Identity and Access Administrator, for deeper Entra identity and access work
- AZ-104 Azure Administrator Associate, for Azure infrastructure breadth
- AZ-140 Configuring and Operating Microsoft Azure Virtual Desktop, for AVD specialization
FAQ
What changed on the MD-102 exam in 2026?
The current objectives, measured as of July 24, 2026, contain five domains instead of the earlier four-domain preparation model. The new fifth domain covers automation, monitoring, reporting, Endpoint Analytics, proactive remediations, tenant health, alerts, and Security Copilot capabilities in Intune. Existing identity, enrollment, device management, security, and application topics remain relevant.
Is the MD-102 exam code changing?
No code change is established in the available evidence. This is a same-code objective update for MD-102. Microsoft’s current guide defines the July 24, 2026 skills, while older preparation material may still reflect the earlier objective structure.
Do I need to replace all my old MD-102 study material?
No. Older material can still help with Entra identity, enrollment, compliance, Conditional Access, Autopilot fundamentals, applications, security policies, and device actions. Supplement anything that omits the fifth domain, device preparation policies, newer Intune capabilities, KQL queries, diagnostics, proactive remediations, Endpoint Analytics, reporting, or Security Copilot.
How long should I study for the updated MD-102?
Recent candidate accounts range from about four weeks to three or four months. Candidates with several years of Intune or Entra experience report about four weeks to one month. Intermediate candidates report roughly one to two months while working full time. Beginners report around three to four months, especially without hands-on tenant access.
Does the MD-102 exam include a lab?
Microsoft does not publish a fixed question count or guarantee a lab in the available exam facts. Candidate accounts vary, with some describing interactive lab or virtual-lab tasks and others describing case studies without the same component. Prepare for hands-on scenarios anyway. Portal familiarity and policy reasoning help in either format.
Is MD-102 difficult for someone new to Intune?
It can be. The difficulty comes from connecting identity, enrollment, policy evaluation, applications, security, and operational data rather than memorizing isolated settings. A beginner should build or access a tenant and perform the workflows. Reading alone leaves too many policy interactions invisible.
Does the MD-102 certification expire?
The certification is valid for 12 months. Microsoft allows annual renewal at no cost through a Microsoft Learn assessment. Confirm the current renewal details in Microsoft’s certification account experience because renewal processes can change.
What score do I need to pass MD-102?
The passing score is 700 out of 1000. Microsoft does not publish a reliable pass rate, and available candidate accounts do not establish one. Practice scores should be used to find weak areas, especially the new operations topics and hands-on policy scenarios.
The practical conclusion
The July 24, 2026 MD-102 update is not a clean break from endpoint administration. It widens the job the exam represents. Device identity, enrollment, compliance, applications, security, and Autopilot still form the core, while automation, monitoring, reporting, proactive remediation, device analytics, and newer Intune capabilities now make that core look more like an operating discipline.
Experienced administrators should update a familiar foundation. Beginners should build the foundation and then add the operational layer. Both groups should use practice questions to find gaps, then verify current coverage against Microsoft’s official objectives.
The new blueprint rewards candidates who can do something with endpoint data and policy state, not just describe the menu where a setting lives.
Checked against official Microsoft MD-102 exam documentation and current candidate reports. Last verified 2026-09-22.