Microsoft • MD-102
Validates expertise in managing devices and client applications in a Microsoft 365 tenant using Microsoft Intune, implementing endpoint deployment and management solutions across various platforms.
Questions
723
Duration
100 minutes
Passing Score
700/1000
Difficulty
AssociateLast Updated
Jan 2026
The Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) validates expertise in deploying, configuring, and managing devices and client applications within a Microsoft 365 tenant. Certified professionals demonstrate proficiency with Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Defender for Endpoint, Microsoft Entra ID, Azure Virtual Desktop, Windows 365, and Microsoft Copilot for Security. The exam was last updated on January 23, 2026, consolidating endpoint management into four core domains covering infrastructure preparation, device management, application management, and device protection.
The certification reflects the modern enterprise reality of managing distributed, heterogeneous fleets of endpoints—Windows, iOS, Android, and macOS—across hybrid and remote work environments. It validates the ability to implement Zero Trust-aligned security postures through compliance policies, Conditional Access, security baselines, and Microsoft Defender for Endpoint integration, all managed at scale through cloud-native tooling. Candidates are expected to understand both cloud-native and co-managed endpoint strategies and to collaborate cross-functionally with Microsoft 365 administrators, security teams, and enterprise architects.
This certification is designed for IT professionals working as Endpoint Administrators, Modern Desktop Administrators, Intune Administrators, or Device Management Specialists in organizations running Microsoft 365. Ideal candidates have hands-on experience deploying and managing Windows client devices at scale, administering Microsoft Intune policies, and implementing endpoint security controls. Professionals targeting roles such as Systems Administrator, Cloud Infrastructure Engineer, or IT Security Administrator who work primarily with Microsoft 365 environments will also benefit.
Candidates typically have 1–3 years of experience managing enterprise endpoints and are familiar with Windows client operating systems, device enrollment workflows, application lifecycle management, and identity platforms such as Microsoft Entra ID. Those working in hybrid environments or organizations undergoing digital transformation to cloud-first endpoint management are the primary target for this associate-level credential.
Microsoft does not enforce formal prerequisites for MD-102, but recommends that candidates have working experience with Microsoft Entra ID and Microsoft 365 technologies—particularly Microsoft Intune—before attempting the exam. A solid foundation in deploying, configuring, and maintaining Windows client environments is strongly advised, along with familiarity with non-Windows platforms (iOS, Android, macOS) managed through Intune. Understanding of networking fundamentals, Active Directory, and Group Policy is helpful given the exam's co-management and hybrid identity scenarios.
Practical, hands-on experience is the most critical prerequisite. Candidates with at least six months of direct experience administering endpoints through Microsoft Intune, configuring Conditional Access policies in Microsoft Entra ID, and deploying devices via Windows Autopilot are well positioned for success. Microsoft recommends completing the official instructor-led course MD-102T00-A: Microsoft 365 Endpoint Administrator or equivalent self-paced learning paths on Microsoft Learn prior to sitting the exam.
MD-102 is a proctored exam with a 100-minute time limit, delivered through Pearson VUE either at an authorized testing center or via online proctoring. The exam may include interactive lab-style components in addition to standard question formats such as multiple choice, multiple select, drag-and-drop, and scenario-based case studies. The exact number of questions is not published by Microsoft and varies per exam session. A scaled score of 700 or greater on a scale of 100–1000 is required to pass.
The exam is available in English, Chinese (Simplified), German, Spanish, French, Japanese, and Portuguese (Brazil). Candidates who take the exam in a non-English language may request an additional 30 minutes if their language version lags behind the English update cycle. The certification earned upon passing expires after 12 months and must be renewed annually at no cost through a free online renewal assessment on Microsoft Learn. The exam costs $165 USD, though pricing varies by country and region.
The MD-102 certification positions holders for roles including Endpoint Administrator, Modern Desktop Administrator, Intune Administrator, Systems Administrator, and Cloud Infrastructure Engineer in Microsoft 365 environments. With over 45,000 active job openings in the US market as of early 2026 and 78% of enterprises running Microsoft 365, demand for credentialed endpoint management professionals is strong and growing. According to salary aggregators, certified Endpoint Administrators in the US earn between $85,000 and $145,000 annually depending on experience, geography, and scope of responsibility, with mid-level professionals averaging approximately $95,000–$110,000.
Compared to the MS-102 Microsoft 365 Administrator credential, MD-102 is more narrowly focused on device and endpoint management, making it the preferred credential for professionals specializing in Intune, Autopilot, and endpoint security rather than broader Microsoft 365 administration. The certification's annual renewal requirement ensures that certified professionals stay current with the rapidly evolving Microsoft endpoint management stack. Organizations implementing Zero Trust security architectures and hybrid work strategies place high value on MD-102-certified staff who can manage and secure distributed device fleets across Windows, iOS, Android, and macOS platforms.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 723 questions.
1. Adatum Corp. needs to create a package for configuring new Windows 11 devices, including setting network connections and adding apps, using a graphical tool. Which wizard in Windows Configuration Designer should they primarily use?
Explanation
The Desktop wizard in Windows Configuration Designer is used for configuring settings like network connections and apps on desktop devices. The Kiosk wizard sets up kiosks. The Mobile wizard is for mobile devices. The Device setup wizard assigns names and upgrades editions but not primarily for networks and apps.
2. VanArsdel University uses conditional access to require MFA for apps accessed from untrusted locations. In which scenario is this particularly useful?
Explanation
Requiring MFA for non-trusted networks is a key scenario for conditional access at VanArsdel, adding security for remote access. Allowing access from corporate devices only might not require MFA. Blocking all mobile access is overly restrictive. Disabling location checks would remove this protection.
3. Litware has 100 unmanaged iPad devices and a Microsoft 365 E5 subscription. You need to push a specific iOS update while blocking users from installing newer versions manually. Which two actions should you take? (Select two!)
Multiple correct answersExplanation
Creating a device configuration profile allows you to enforce the iOS version and prevent manual updates. Enrolling via Apple Business Manager enables supervised management for update control. Enrolling via Company Portal is for user-managed devices and lacks supervision features. A compliance policy enforces rules but does not directly manage updates. An app provisioning profile handles app certificates, not OS updates. Configuring update rings is not applicable for unmanaged iPads.
4. Litware Inc. wants a secure score to compare their security posture against similar companies and get step-by-step remediation guidance. Which Microsoft Defender for Endpoint capability offers this?
Explanation
Secure Score provides a comparative security posture score with step-by-step remediation for issues. Advanced Hunting allows custom queries for threats. Management and APIs enable integration but not scoring. Endpoint Detection and Response focuses on threat detection and response.
5. Adventure Works is using co-management and decides to migrate the Endpoint Protection workload to Intune. What must they ensure before switching this workload?
Explanation
Policies must be configured in Intune before switching. Windows 7 is outdated. Disabling Configuration Manager prevents co-management. Imaging is not required.
One-time access to this exam