Microsoft MD-102: Co-management and Hybrid Environments — Study Guide

Part of the Microsoft Endpoint Administrator Associate MD-102 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Co-management and hybrid environments let you combine Configuration Manager (ConfigMgr) with Microsoft Intune to modernize Windows management at your own pace. Co-management enables workload-by-workload transition, while hybrid Azure AD join creates a unified device identity in both on-premises Active Directory and Azure AD. Azure AD Connect synchronizes identities and devices, and Cloud Attach features such as the Cloud Management Gateway (CMG) and tenant attach extend ConfigMgr to the cloud and Intune admin center for internet management and a unified console. Planning must address prerequisites, identity, synchronization, policy precedence between Group Policy and Intune MDM, and staged workload switching to avoid conflicts.

Co-management architecture and enrollment

Co-management integrates the ConfigMgr client with Intune MDM on Windows 10/11. It requires ConfigMgr current branch (1710+; use a supported recent release), an Intune subscription with MDM authority set to Microsoft Intune, an Azure AD tenant linked to your ConfigMgr site, and Windows 10 version 1709 or later or Windows 11. Devices should be hybrid Azure AD–joined or Azure AD–joined so the ConfigMgr client can acquire Azure AD tokens.

Enrollment flow for existing ConfigMgr clients uses the co-management wizard in the ConfigMgr console to connect the site to your Azure AD tenant and configure automatic MDM enrollment for a target collection. The client receives policy with the tenant information, uses its Azure AD device identity to request an MDM enrollment token, and enrolls into Intune without user interaction. This auto-enrollment supports devices with or without user affinity; it does not require the end user to trigger enrollment. Ensure:

After enrollment, the device has two management channels: the ConfigMgr client and the Intune MDM channel. You control which feature areas (workloads) are managed by which service. Use pilot collections to validate before switching all devices. Keep a clear configuration ownership model to avoid duplicate enforcement.

CMG and tenant attach are complementary but independent. CMG provides internet-based client connectivity for ConfigMgr, while tenant attach uploads ConfigMgr device metadata to the cloud and exposes real-time actions in the Intune admin center. Both are part of a cloud-attach posture that reduces dependency on on-premises network reachability.

Workloads, switching strategy, and policy domains

Workloads represent management domains that can be controlled by ConfigMgr or Intune. You can set each workload to:

Key workloads and guidance:

Switch in stages. Start with Compliance, then Device Configuration or Endpoint Protection, then Apps and Updates. Use pilot collections and report on drift and conflicts before moving “All”.

Hybrid Azure AD Join and Azure AD Connect

Hybrid Azure AD join creates a single device identity represented in both on-premises AD and Azure AD. It is required for seamless SSO, Conditional Access device-based policies for domain-joined computers, and for co-management enrollment using device credentials. Prerequisites include:

Azure AD Connect is the synchronization engine between on-premises AD and Azure AD. Core configuration considerations:

Correctly configured hybrid join ensures devices can acquire Azure AD device tokens, enabling co-management auto-enrollment and cloud-based policy enforcement.

Policy precedence: Group Policy vs Intune MDM

When Group Policy Objects (GPOs) and Intune MDM policies target the same setting, default precedence varies by setting and implementation. In general, traditional GPOs win for overlapping registry-based settings because they are applied by the Group Policy engine at refresh intervals. To support modern management, Windows 10 version 1709 and later introduced the ControlPolicyConflict policy to prefer MDM for supported Policy CSP areas.

Key practices to manage precedence and avoid conflicts:

For co-managed devices, also ensure ConfigMgr configuration baselines or Endpoint Protection settings are not duplicating the same controls as Intune policies. A single authoritative source per control avoids unpredictable outcomes.

Cloud attach: CMG and tenant attach

Cloud Management Gateway (CMG) allows ConfigMgr to manage internet-based clients without requiring VPN. CMG runs in Azure as a PaaS service (preferred on Virtual Machine Scale Sets) and proxies client communication to your on-premises site via the CMG connection point. Capabilities include client policy, hardware/software inventory, app deployments, scripts, CMPivot, and Software Updates when clients are configured for internet-based management. Core requirements and design points:

Tenant attach surfaces ConfigMgr device inventory and actions in the Microsoft Intune admin center without requiring co-management. When you enable “Upload to Microsoft Endpoint Manager admin center,” devices appear under Devices in the Intune portal with ConfigMgr as the management authority. You can perform actions such as:

Tenant attach integrates Azure AD/Intune RBAC with ConfigMgr RBAC. For internet clients, real-time actions require CMG; for intranet clients, actions flow through on-premises management points. Tenant attach complements co-management by giving a unified cloud console and enabling helpdesk tasks without granting access to the ConfigMgr console.

Practical Problem Scenario

Contoso, Ltd. has 5,000 Windows 10/11 devices managed by Configuration Manager across multiple sites. Remote work increased, and many devices rarely connect to VPN. Contoso wants to enforce Conditional Access based on device compliance, move security controls to the cloud, and manage internet-based devices without relying on VPN, while avoiding a big-bang migration.

  1. Establish identity and device foundation
  1. Configure co-management with staged enrollment
  1. Switch the Compliance policies workload to Intune (Pilot → All)
  1. Deploy Endpoint security via Intune; retire overlapping ConfigMgr EP
  1. Migrate device configuration to Intune with conflict control
  1. Implement Cloud Management Gateway
  1. Enable tenant attach for unified operations
  1. Expand workloads and decommission legacy controls

Identity · All domains · Windows Lifecycle and Update Management

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product