MD-102 is Microsoft’s current exam for the Microsoft 365 Certified: Endpoint Administrator Associate credential. As of October 4, 2026, the live English skills measured are the July 24, 2026 version. Microsoft has already published an upcoming October 27 update, so candidates should keep the date boundary clear: the July objectives remain the current basis today.
The current MD-102 blueprint has five weighted areas: Prepare infrastructure for devices at 20–25%, Manage and maintain devices at 25–30%, Protect devices at 15–20%, Manage and secure applications at 15–20%, and Optimize endpoint operations by using automation, monitoring, and reporting at 10–15%. Microsoft requires a score of 700 or greater to pass.
The role is centered on Intune-driven endpoint management
Microsoft describes the candidate as an endpoint administrator who manages devices and client applications at scale through Microsoft Intune and related Microsoft 365 services. The current audience profile also includes Microsoft Intune Suite, Windows Autopilot, Defender for Endpoint, Entra ID, PowerShell, Microsoft Graph, Windows 365, Security Copilot, and Intune agents.
This is no longer a Windows-only desktop deployment exam. The role spans Windows, macOS, iOS/iPadOS, Android, specialty devices, cloud PCs, managed applications, and automation.
Prepare infrastructure for devices is 20–25%
The first domain covers Entra ID device join/registration, dynamic device groups, Intune enrollment, automatic Windows enrollment, Apple Business Manager, Samsung Knox Mobile Enrollment, Google Zero Touch, Android enrollment modes, role assignments, scope tags, multi-admin approval, compliance policies, Conditional Access, Windows Hello for Business, Windows LAPS, and local-group management.
Conditional Access belongs here because compliance status can become a condition for accessing organizational resources.
Enrollment is now a large cross-platform skill
Windows, macOS, iOS/iPadOS, and Android devices use different enrollment models. Corporate ownership, personal/BYOD status, enrollment restrictions, automated enrollment, and platform-specific business enrollment all affect which workflow is appropriate.
Strong candidates should be able to explain why a device fails enrollment before changing compliance or application policy.
Manage and maintain devices is the largest domain
At 25–30%, this area covers Windows Autopilot, device-preparation policies, user-driven/pre-provisioned/self-deploying modes, Enrollment Status Page, Windows 11 upgrades, Windows 365 Cloud PCs, Windows Backup and Restore, configuration profiles, ADMX, Group Policy analytics, assignment filters, specialty devices, Intune Suite features, and remote actions.
A Windows Autopilot foundation is useful because deployment strategy is a major part of the administrator role.
Intune Suite adds advanced operational capabilities
The live scope includes Endpoint Privilege Management, Enterprise App Catalog, Remote Help, Microsoft Cloud PKI, Microsoft Tunnel for Mobile Application Management, and Intune Advanced Analytics.
These are not isolated premium features. They support least privilege, app management, support, certificates, mobile access, and proactive operational insight.
Remote actions now include richer diagnostics
Candidates should know sync, restart, retire, wipe, bulk actions, Defender intelligence updates, BitLocker key rotation, local-admin password rotation, KQL device queries, and collection of diagnostics/logs through Intune.
The endpoint administrator needs to understand which action is reversible, which removes organizational data, and which affects the entire device lifecycle.
Protect devices is 15–20%
The security domain covers antivirus policy, BitLocker/disk encryption, firewall, attack-surface reduction, security baselines, Defender for Endpoint integration, EDR policies, endpoint threat investigation, device onboarding, App Control for Business, and update management.
Defender for Endpoint provides the endpoint-security context behind several of these objectives.
Update management is broader than Windows Update rings
The current guide includes Windows update rings, feature and quality updates, Windows Autopatch, Hotpatch, iOS/iPadOS/macOS update policy, Android/FOTA deployments, Delivery Optimization, and update monitoring.
The exam expects platform-aware update operations rather than one Windows-only patching workflow.
Applications account for another 15–20%
App deployment includes Win32, LOB, Microsoft Store, Microsoft 365 Apps, Apple VPP, Google Play, Quiet Time, Office Deployment Tool scenarios, deployment monitoring, app protection, app configuration, and Conditional Access for app protection.
The difference between managed devices and managed apps is central, especially in BYOD scenarios where corporate data must be protected without full device ownership.
Automation, monitoring and reporting are now first-class objectives
The 10–15% final domain includes PowerShell/Graph automation, Security Copilot agent investigations, device-performance analysis, compliance extensions, Intune reporting, Endpoint Analytics, proactive remediation scripts, reliability/user-experience scores, service-health baselines, and alerts for drift or enrollment/configuration failures.
The July 24 update increased the weight of infrastructure preparation and introduced a new operations-optimization domain, which is a strong signal about the current role. Microsoft now expects endpoint administrators to design enrollment and access correctly up front and then manage health continuously after deployment. Candidates using older MD-102 notes should add the new automation, Copilot-agent, analytics, and operational-reporting objectives before final review.
Multi-admin approval is another current governance feature worth understanding. High-impact changes can require a second administrator to approve them before execution, reducing the risk of one person making a sensitive tenant-wide change alone. This fits the broader endpoint-management trend toward stronger administrative control rather than simply expanding technical capability.
Windows LAPS belongs in infrastructure and identity because local administrator credentials are a device-management risk. Intune and Entra can rotate and manage the local administrator password so the organization does not rely on a shared static credential across many endpoints. Candidates should understand both deployment and recovery/rotation implications.
Windows 365 appears inside device management because Cloud PCs are endpoints from the administrator’s perspective even though the compute runs in Microsoft’s cloud. Provisioning policy, network connection, image management, user assignment, configuration, applications, updates, and security still need operational ownership.
Cloud PKI connects identity, device configuration, and secure access. Certificates can be issued and managed through cloud-based infrastructure without depending on a traditional on-premises PKI for every scenario. The endpoint administrator should know why certificates are used and how issuance/health affects Wi-Fi, VPN, or other certificate-based access.
Microsoft Tunnel for MAM extends secure network access to app-managed scenarios. This is useful when corporate apps on personal devices need protected connectivity without requiring the organization to manage the entire device. The feature reinforces the distinction between app-level and device-level control.
Security baselines should be understood as managed collections of recommended settings, not immutable rules. Organizations can start from the baseline and adjust according to business or compatibility needs. Monitoring and exception management remain necessary after assignment.
App Control for Business adds another layer beyond antivirus. It can restrict which applications or code are allowed to execute according to policy. This makes application trust part of endpoint security rather than relying only on malware signatures.
Quiet Time policies illustrate how endpoint management also affects user experience. Organizations can reduce work notifications during protected periods on supported mobile platforms. The objective may look minor, but it demonstrates that app management includes productivity and policy, not only installation.
Security Copilot agents in Intune are now explicitly part of endpoint operations. Candidates should understand that agent-generated findings and recommendations support investigation and decision-making but still need administrator review. AI assistance does not remove responsibility for validating device state or the impact of a recommended action.
Endpoint Analytics should be viewed as fleet-level observability. Startup performance, app reliability, restart frequency, device health, anomalies, and proactive insights can reveal patterns that individual help-desk tickets miss. The administrator can then target remediation to affected groups rather than changing every endpoint.
Service health and Message Center awareness complete the role because some endpoint problems originate in Microsoft’s service rather than tenant configuration. Operational baselines help distinguish a local policy failure from a wider service event. That distinction can prevent unnecessary configuration changes during an outage.
Assignment filters and enrollment-time grouping also matter because large environments rarely target policy through static groups alone. Filters can refine scope using device properties, while enrollment-time grouping can improve policy/application timing during provisioning. The administrator should know when these mechanisms reduce complexity versus when they make troubleshooting harder.
Specialty-device management is a reminder that Intune extends beyond ordinary laptops and phones. Teams Rooms, HoloLens 2 and Zebra devices can have different configuration and update needs. Candidates should approach them through platform capability rather than assuming standard Windows-desktop behavior.
BitLocker recovery-key management now includes self-service and compliance visibility. Encryption policy is only complete when recovery material is escrowed appropriately and authorized support staff or users can recover without exposing keys broadly.
Windows Autopatch and Hotpatch represent Microsoft’s move toward service-managed update operations. The endpoint administrator still needs to understand eligibility, policy, monitoring, business impact and exceptions even when Microsoft automates more of the rollout mechanics.
For final scope control, separate the current July 24 blueprint from the published October 27 update. The upcoming version is useful for future bookings, but it should not silently replace the live objectives before the change date.
Endpoint operations also increasingly uses KQL outside the traditional Sentinel context. The live objective includes device query using KQL through Intune, which reinforces the administrator’s need to reason from data at scale rather than inspect devices one by one.
Proactive remediations should be read as a detect-and-fix loop. A detection script evaluates whether a device has the issue; a remediation script corrects it; reporting shows success or recurrence. The pattern is useful well beyond one specific script.
Overall, the current blueprint is best understood as modern workplace operations: identity and enrollment establish control, configuration and apps create productive endpoints, security/update policy maintains trust, and analytics/automation keeps the estate healthy over time.
That current lifecycle framing should guide final study priorities.
Within the broader Microsoft certification path, MD-102 now reflects a modern endpoint-operations role: deploy, secure, automate, monitor, and improve at scale.