MD-102 becomes easier when the five domains are mapped as one device lifecycle. Identity and enrollment establish management. Deployment and configuration create the desired endpoint state. Security and updates keep the device compliant. Applications deliver business capability. Automation, monitoring, analytics, and remediation keep the fleet healthy after deployment.
The current MD-102 weights are 20–25% infrastructure, 25–30% device management, 15–20% protection, 15–20% applications, and 10–15% operational optimization.
Entra identity sits beneath endpoint management
Device join, registration, dynamic groups, roles, scope tags, Windows Hello for Business, and Conditional Access create identity and administrative context before Intune can apply policy effectively.
The map should distinguish device identity from user identity and show how both influence assignment and access.
Enrollment establishes Intune authority
Automatic Windows enrollment, Apple Business Manager, Knox Mobile Enrollment, Google Zero Touch, Android modes, and personal enrollment determine how a device becomes managed.
An enrollment failure should be solved before configuration, compliance, or app problems are investigated.
Compliance connects device state with access decisions
Compliance policies evaluate whether the device meets required conditions. Entra Conditional Access can then require compliant status before a user accesses corporate resources.
This creates a control loop: Intune observes device state, compliance evaluates it, and Entra enforces access.
Autopilot connects identity, enrollment and deployment
User-driven, pre-provisioning, self-deploying, device-preparation policies, Enrollment Status Page, naming, and application/configuration assignment all combine during Windows deployment.
The Autopilot workflow is a strong example of several MD-102 domains interacting at once.
Configuration profiles define desired endpoint state
Settings Catalog, ADMX, Group Policy analytics, Android/iOS/macOS profiles, specialty-device profiles, assignment filters, and enrollment-time grouping all help the administrator target settings correctly.
Configuration is only useful when assignment scope and conflict behavior are understood.
Intune Suite extends the management plane
Endpoint Privilege Management, Remote Help, Cloud PKI, Microsoft Tunnel for MAM, Enterprise App Catalog, and Advanced Analytics add specialized controls around privilege, support, certificates, mobile access, apps, and insight.
These features should be mapped to the operational problem they solve instead of memorized as a list.
Security policy protects the device before and during incidents
Antivirus, firewall, attack-surface reduction, BitLocker, security baselines, App Control, Defender integration and EDR all reduce endpoint risk.
Defender for Endpoint then provides threat evidence and response context after suspicious activity is detected.
Update management is another desired-state system
Update rings, feature/quality updates, Autopatch, Hotpatch, Apple updates, Android FOTA and Delivery Optimization control software currency and rollout risk.
Update status should be monitored like compliance because incomplete deployment can become a fleet-wide security or reliability gap.
Apps sit between device state and user productivity
Win32, LOB, Store, Microsoft 365 Apps, platform app stores, app protection and app configuration deliver business functionality. BYOD scenarios may protect app data without managing the entire device.
Application deployment, protection and Conditional Access should be drawn as separate but connected controls.
Monitoring and automation close the lifecycle
Endpoint Analytics, proactive remediations, Graph/PowerShell automation, KQL device query, Copilot agents, reports, dashboards, health baselines and alerts reveal whether the endpoint estate remains healthy.
The map should also include administrative approval between management intent and execution. Multi-admin approval creates a governance checkpoint for sensitive Intune changes, while roles and scope tags decide who can propose or approve the action. This keeps privilege and workflow visible alongside technical settings.
Windows LAPS should be placed between device identity and least privilege. The endpoint still needs a local administrator account for some recovery scenarios, but the password should be unique, rotated, protected and recoverable by authorized administrators rather than shared permanently.
Windows 365 belongs beside Autopilot and ordinary Windows devices because the same user can consume a Cloud PC and a physical device under one management strategy. Policies, apps, security and monitoring can overlap even though the provisioning mechanics differ.
Cloud PKI should sit between identity and access. Certificates can authenticate devices or apps to Wi-Fi, VPN and other services. If certificate issuance or renewal fails, the endpoint may appear compliant yet still lose connectivity to protected resources.
Remote Help belongs on the support path rather than the configuration path. It gives authorized support staff a controlled remote-assistance capability with tenant identity and auditing. The tool solves a human support problem after policy deployment, not a device-enrollment problem.
Endpoint Privilege Management should be drawn between user productivity and security. It gives approved elevation for specific tasks without permanent local-admin rights. That control reduces standing privilege while preserving the user’s ability to perform justified administrative actions.
Application protection should be drawn around corporate data, not just the device. MAM policies can control copy/paste, save-as, authentication and other data behaviors inside supported apps. This makes the security boundary portable across managed and unmanaged devices.
Delivery Optimization belongs on the update path because update content consumes bandwidth as well as device time. Peer distribution and related settings can reduce repeated internet downloads in large fleets, which links update design with network efficiency.
Graph and PowerShell automation should be placed above the management APIs. Intune’s portal is one administrative surface; automation can query or change the same management objects at scale. Scripts need authentication, least privilege, error handling and testing like other production automation.
Copilot agents should sit on the analyst-assistance layer. They can surface performance or security insight, but reports, device state, Endpoint Analytics and Defender evidence remain authoritative. Administrators should treat AI output as another input to a decision.
Alerts for compliance drift, enrollment failure and configuration conflict create a proactive operations loop. Instead of waiting for users to open tickets, the endpoint team can detect changes in fleet health and respond before business impact spreads.
For final review, trace one BYOD user separately from one corporate Windows user. The BYOD path emphasizes app protection and selective access; the corporate path emphasizes full enrollment, configuration, security, updates and remote actions. Comparing those lifecycles makes ownership-based decisions easier.
Windows Backup and Restore should be placed beside deployment and recovery. A modern endpoint lifecycle includes replacing or resetting devices while preserving user settings or data where supported. Deployment success should therefore include restoration experience, not only initial enrollment.
Enterprise App Catalog should be drawn between app packaging and deployment. It can simplify management of common applications, but assignment, update behavior and monitoring still belong to Intune. Catalog availability does not eliminate application-lifecycle ownership.
App-install status should feed into support and Autopilot paths. A required application can block provisioning or reduce user productivity after enrollment. The map should therefore connect app deployment reporting with diagnostics and remediation.
Security baselines should sit above individual endpoint-security settings as a packaged starting point. Exceptions and conflicts should be visible, because organizations often need to deviate from baseline defaults for justified applications or roles.
Health dashboards and service communications belong outside the device itself. Not every fleet symptom originates on endpoints; a Microsoft service issue can affect many devices simultaneously. The map should preserve this external dependency.
Use the objective map to classify a ticket before opening Intune: identity/enrollment, configuration, security/update, app/data, or operations/analytics. This simple categorization reduces portal wandering and aligns directly to the exam’s weighted domains.
The map should include Windows 365 network and image dependencies around Cloud PC provisioning. A Cloud PC can fail before user sign-in if provisioning policy, image, license, network connection or assignment is wrong. This is a different path from troubleshooting a physical Windows device.
BitLocker key escrow and LAPS password recovery should be drawn as operational recovery controls. They preserve secure management while still giving authorized administrators a way to restore access when encryption or local-admin credentials are needed during support.
Device diagnostics and the Troubleshooting blade belong on the evidence layer. They help administrators decide whether the failure is user-specific, device-specific, assignment-related or service-wide before making configuration changes.
For scenario practice, start at ownership and lifecycle state. Is the endpoint corporate or personal? enrolled or app-managed? newly provisioning or steady-state? compliant or blocked? Those facts often eliminate several distractors immediately.
The complete map should make one principle obvious: Intune does not simply “push settings.” It evaluates identity, ownership, assignments, platform capability, app/device state and cloud-service health to produce an effective result.
Update rings and app deployments should also be connected to user experience. A technically successful rollout can still create poor business outcomes if restart timing, app failure, or device performance is ignored. Monitoring closes that gap.
Security Copilot and Intune agents belong on the decision-support layer rather than the enforcement layer. They can highlight risk or performance patterns, while administrators still validate evidence and choose the actual policy change.
The strongest objective map is therefore a flow of authority: identity establishes who/what the endpoint is; enrollment establishes management; targeting establishes scope; policy defines desired state; reporting proves effective state; automation remediates drift.
Remote actions also belong on the lifecycle path because support and offboarding can change endpoint state after deployment. Sync and diagnostics preserve the device, while retire or wipe can remove management or data. The map should show that remote actions have different consequences and should be chosen according to ownership, user status, and recovery needs.
Keep the lifecycle boundary visible: identity and enrollment start management, while retire or wipe ends it. The same policy choices mean different things depending on where the device sits in that lifecycle.
For final review, draw one new employee device from Entra identity through enrollment, Autopilot, configuration, security, apps, compliance, updates, analytics and remediation. That lifecycle connects the entire Endpoint Administrator role.