Windows administration now spans two very different operating models: modern endpoint management through Microsoft Intune and hybrid Windows Server administration across on-premises and Azure-connected environments. MD-102 represents the endpoint-management route, while the older AZ-801 route has already retired and Microsoft’s current Windows Server Administrator Associate path now centers on AZ-802.
The important skill lesson is that Windows administration is no longer defined only by local configuration. Identity, device enrollment, compliance, application delivery, update control, endpoint security, cloud management, hybrid connectivity, monitoring, and automation all matter. The balance changes depending on whether the device is a user endpoint, a server workload, or a hybrid system connected to Azure.
Within the wider set of Microsoft certifications, candidates should treat endpoint administration and Windows Server administration as adjacent specializations rather than one universal Windows exam path.
MD-102 is centered on managing endpoints at organizational scale
MD-102 focuses on deploying, managing, securing, and maintaining endpoints through Microsoft Intune and related Microsoft 365 services. The administrator has to think about device identity, enrollment, configuration, compliance, application delivery, updates, endpoint security, monitoring, and remote actions as one operating system for the endpoint estate.
The scale problem is what separates enterprise endpoint administration from supporting individual PCs. A policy that works for ten devices may create disruption when deployed to ten thousand. Administrators need staged rollout, assignment logic, exception handling, health reporting, ownership, and a way to reverse changes that produce unexpected effects.
The guide to Windows Autopilot shows one practical part of that model: deployment can be policy-driven from first boot instead of depending on technicians manually imaging and configuring every device.
Identity and device trust are inseparable in modern management
A modern endpoint does not make access decisions in isolation. Microsoft Entra ID, device registration or join state, user identity, compliance signals, authentication methods, and Conditional Access can all influence whether a person may reach organizational resources.
That means endpoint administrators need to understand the difference between managing a device and establishing trust in a device. A machine can be enrolled yet noncompliant. A user can authenticate successfully while the device fails security requirements. An application can be permitted only when both user and device conditions are satisfied.
This relationship also explains why endpoint teams collaborate so closely with identity administrators. A device policy can affect authentication, and an identity policy can change the user experience on the endpoint. The implementation has to be tested as one access flow.
Application management extends beyond software installation
Enterprise application delivery includes assignment, update behavior, dependencies, configuration, protection policies, data boundaries, and removal. Administrators need to know whether the app is managed, how organizational data is handled, and whether the application can be secured even on devices the company does not fully own.
Mobile application management and app-protection policies are especially important in bring-your-own-device scenarios. The objective is often to protect corporate data inside an application without claiming full administrative control over the user’s personal device.
That is a different problem from traditional desktop software deployment. Modern endpoint administration is increasingly about controlling identities, applications, data, and policy relationships rather than only the operating system image.
Endpoint security is an operational discipline, not a one-time hardening task
Security settings need continuous maintenance because devices change, users travel, threats evolve, and new software introduces new risk. Firewall settings, attack-surface reduction, encryption, antivirus, endpoint detection and response, local privileges, device control, and compliance state all contribute to the security posture.
Microsoft Defender for Endpoint adds the detection-and-response layer. The administrator needs enough understanding to onboard devices, maintain healthy sensors, respond to findings, and coordinate with security teams when alerts reveal activity that policy alone cannot prevent.
The best endpoint-security programs also avoid treating users as an exception to the design. Policies that break legitimate work at scale will be bypassed or disabled. Security has to be strong enough to reduce risk and predictable enough to remain operationally sustainable.
Updates and change control are part of endpoint reliability
Operating-system and application updates are security controls, but they are also availability risks. Administrators have to balance deployment speed with compatibility, rollout rings, restart behavior, user disruption, and recovery options. A perfect patching policy on paper can still be a poor production policy if it ignores how users and applications behave.
Modern management makes phased deployment easier because administrators can segment devices, monitor health, and pause or adjust rollout when problems appear. That is especially important in large estates where one defective driver or application dependency can affect thousands of users.
Update management therefore belongs with observability. Administrators need evidence about install success, device health, application compatibility, and failure patterns, not just confirmation that a policy was assigned.
AZ-801 is now historical context, not a current registration path
AZ-801 covered advanced Windows Server hybrid services, including security, high availability, disaster recovery, migration, monitoring, and troubleshooting. It was paired with AZ-800 in the former Windows Server Hybrid Administrator Associate path. Both exams retired on September 30, 2026.
The retirement does not make the underlying skills obsolete. Hybrid identity, Windows Server security, failover, disaster recovery, migration, and Azure-connected management remain real operational concerns. The change means candidates should no longer present AZ-801 as an active exam target.
Microsoft’s current Windows Server Administrator Associate route now uses AZ-802. Existing AZ-801 hybrid-services material can still explain historical scope, but current preparation should follow the new exam and certification guidance.
AZ-802 reflects a broader hybrid Windows Server operating model
The current Windows Server route consolidates administration across on-premises, Azure, and hybrid environments. That is closer to how many organizations actually operate: Active Directory, file services, DNS, virtual machines, security controls, backup, monitoring, Azure Arc, and cloud-connected services coexist rather than moving to the cloud in one clean step.
Administrators therefore need to understand where control lives. Some tasks remain local to Windows Server, some are managed through Azure, and some depend on integration between both. Identity, networking, permissions, patching, monitoring, and recovery plans must work across those boundaries.
This makes hybrid administration a different specialization from endpoint administration even though both involve Windows. Server administrators optimize service continuity and infrastructure; endpoint administrators optimize user-device delivery, policy, applications, and secure access at scale.
Automation and monitoring are now core Windows administration skills
Manual configuration does not scale across thousands of endpoints or dozens of servers. PowerShell, Microsoft Graph, Intune automation, Azure automation, configuration tooling, and repeatable scripts reduce variance and provide evidence about what changed.
Monitoring provides the feedback. Device health, policy compliance, update status, application deployment, endpoint alerts, server performance, event logs, backup state, and availability need to be visible enough for administrators to spot trends before users become the monitoring system.
Automation without monitoring is risky because a fast automated mistake can spread farther than a manual one. Monitoring without automation creates a backlog of known problems that people fix one at a time. Mature operations combine both.
Coexistence and migration are part of modern endpoint engineering
Few organizations move from traditional Windows management to cloud-native endpoint management in one clean step. Group Policy, Configuration Manager, local scripts, legacy VPN assumptions, certificate dependencies, and application packaging practices can coexist with Intune for years. The engineering problem is deciding which control should be authoritative for each setting while the environment changes. Duplicating the same policy across tools can create conflicts that are difficult to diagnose, while removing an old control too quickly can expose devices that still depend on it.
A controlled migration starts with inventory and evidence. Administrators need to know which policies are still used, which applications depend on machine context, which devices cannot meet modern enrollment requirements, and which network paths are required before sign-in. Pilot groups should represent real hardware, user types, locations, and application dependencies rather than only friendly test users. Successful migration is measured by stable authentication, application delivery, compliance, update behavior, support volume, and recoverability—not simply by the percentage of devices enrolled in a new management service.
This is where endpoint administration becomes change engineering. The technical controls matter, but sequencing matters just as much. Identity registration, enrollment, application assignment, security baselines, update rings, and user communication have dependencies. A sound plan keeps rollback options, captures device and service telemetry, and makes ownership explicit when a policy changes hands. Those habits remain valuable even after the organization reaches a mostly cloud-managed state, because major Windows releases, security baselines, and application changes continue to introduce controlled transitions.
Choose endpoint or server administration from the asset you are accountable for
If your responsibility is user devices, Intune, applications, compliance, Windows Autopilot, endpoint security, and device experience, MD-102 is the direct route. If your responsibility is Windows Server across on-premises and Azure-connected environments, the current AZ-802 path is the better fit. AZ-801 should now be treated as retired historical context.
Some roles span both. A smaller infrastructure team may own laptops, virtual desktops, identity, and Windows servers together. In that case, the useful sequence is not dictated by exam numbering. Start with the environment where mistakes have the largest operational impact, then expand into the adjacent administration domain.
The durable Windows administration skill is the ability to manage change safely across identity, devices, applications, infrastructure, security, and monitoring. Products and exam codes will evolve, but that systems view remains the foundation of reliable Windows operations.
The same role-first logic helps teams divide responsibility cleanly. Endpoint engineers should be able to explain the device state, the identity that authorizes it, the management channel that configures it, and the evidence that proves a control is working. Server administrators should be able to do the equivalent for host roles, hybrid services, resilience, and recovery. Where the roles overlap, shared operating standards matter more than shared exam codes.