Microsoft • MD-102
Validates expertise in managing devices and client applications in a Microsoft 365 tenant using Microsoft Intune, implementing endpoint deployment and management solutions across various platforms.
Questions
723
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
The Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) validates expertise in deploying, configuring, and managing devices and client applications within a Microsoft 365 tenant. Certified professionals demonstrate proficiency with Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Entra ID, Azure Virtual Desktop, Windows 365, and Microsoft Copilot for Security. The exam was last updated on January 23, 2026, consolidating endpoint management into four core domains covering infrastructure preparation, device management, application management, and device protection.
The certification reflects the modern enterprise reality of managing distributed, heterogeneous fleets of endpoints—Windows, iOS, Android, and macOS—across hybrid and remote work environments. It validates the ability to implement Zero Trust-aligned security postures through compliance policies, Conditional Access, security baselines, and Microsoft Defender for Endpoint integration, all managed at scale through cloud-native tooling. Candidates are expected to understand both cloud-native and co-managed endpoint strategies and to collaborate cross-functionally with Microsoft 365 administrators, security teams, and enterprise architects.
This certification is designed for IT professionals working as Endpoint Administrators, Modern Desktop Administrators, Intune Administrators, or Device Management Specialists in organizations running Microsoft 365. Ideal candidates have hands-on experience deploying and managing Windows client devices at scale, administering Microsoft Intune policies, and implementing endpoint security controls. Professionals targeting roles such as Systems Administrator, Cloud Infrastructure Engineer, or IT Security Administrator who work primarily with Microsoft 365 environments will also benefit.
Candidates typically have 1–3 years of experience managing enterprise endpoints and are familiar with Windows client operating systems, device enrollment workflows, application lifecycle management, and identity platforms such as Microsoft Entra ID. Those working in hybrid environments or organizations undergoing digital transformation to cloud-first endpoint management are the primary target for this associate-level credential.
Microsoft does not enforce formal prerequisites for MD-102, but recommends that candidates have working experience with Microsoft Entra ID and Microsoft 365 technologies—particularly Microsoft Intune—before attempting the exam. A solid foundation in deploying, configuring, and maintaining Windows client environments is strongly advised, along with familiarity with non-Windows platforms (iOS, Android, macOS) managed through Intune. Understanding of networking fundamentals, Active Directory, and Group Policy is helpful given the exam's co-management and hybrid identity scenarios.
Practical, hands-on experience is the most critical prerequisite. Candidates with at least six months of direct experience administering endpoints through Microsoft Intune, configuring Conditional Access policies in Microsoft Entra ID, and deploying devices via Windows Autopilot are well positioned for success. Microsoft recommends completing the official instructor-led course MD-102T00-A: Microsoft 365 Endpoint Administrator or equivalent self-paced learning paths on Microsoft Learn prior to sitting the exam.
MD-102 is a proctored exam with a 100-minute time limit, delivered through Pearson VUE either at an authorized testing center or via online proctoring. The exam may include interactive lab-style components in addition to standard question formats such as multiple choice, multiple select, drag-and-drop, and scenario-based case studies. The exact number of questions is not published by Microsoft and varies per exam session. A scaled score of 700 or greater on a scale of 100–1000 is required to pass.
The exam is available in English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil). Candidates who take the exam in a non-English language may request an additional 30 minutes if their language version lags behind the English update cycle. The certification earned upon passing expires after 12 months and must be renewed annually at no cost through a free online renewal assessment on Microsoft Learn. The exam costs $165 USD, though pricing varies by country and region.
The MD-102 certification positions holders for roles including Endpoint Administrator, Modern Desktop Administrator, Intune Administrator, Systems Administrator, and Cloud Infrastructure Engineer in Microsoft 365 environments. With over 45,000 active job openings in the US market as of early 2026 and 78% of enterprises running Microsoft 365, demand for credentialed endpoint management professionals is strong and growing. According to salary aggregators, certified Endpoint Administrators in the US earn between $85,000 and $145,000 annually depending on experience, geography, and scope of responsibility, with mid-level professionals averaging approximately $95,000–$110,000.
Compared to the MS-102 Microsoft 365 Administrator credential, MD-102 is more narrowly focused on device and endpoint management, making it the preferred credential for professionals specializing in Intune, Autopilot, and endpoint security rather than broader Microsoft 365 administration. The certification's annual renewal requirement ensures that certified professionals stay current with the rapidly evolving Microsoft endpoint management stack. Organizations implementing Zero Trust security architectures and hybrid work strategies place high value on MD-102-certified staff who can manage and secure distributed device fleets across Windows, iOS, Android, and macOS platforms.
1. Litware has imported device IDs into Microsoft Endpoint Manager for Autopilot. To associate these devices with deployment profiles, what type of group must they create in Azure AD?
2. Fabrikam needs to implement load balancing for their Azure Virtual Desktop host pools to optimize performance. They prefer to fully utilize one virtual machine before moving to the next. Which load balancing mode should they select?
3. Tailwind Traders, a logistics company, has remote employees needing IT support without physical access to devices. Which function enables IT professionals to provide secure, real-time assistance on enrolled devices?
4. Woodgrove Bank is setting up the Microsoft Deployment Toolkit for client deployments. What prerequisites must they ensure are in place?
5. Tailspin Toys has a mix of Windows, iOS, and Android devices and wants to deploy software updates consistently across all platforms. Using Microsoft Intune, what should they configure to control update deployments?
All exams included • Cancel anytime