Microsoft Endpoint Administrator Associate MD-102 — Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the Microsoft exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each MD-102 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Device Enrollment and Azure AD Join — - Azure AD Join (AADJ): The device is cloud-joined to Entra ID and typically auto-enrolled into Intune. Use AADJ for cloud-first organizations,
- Device Configuration Profiles and Policies — Device restrictions are curated templates that centralize common controls such as password and sign-in requirements, browser and Store controls,
- Application Management and Deployment — App assignment intents define delivery behavior: - Required: Intune installs the app automatically on targeted devices/users. For Win32, you can set
- Endpoint Security and Microsoft Defender — Attack Surface Reduction rules prevent common attacker actions even if malware is unknown: - Modes: Each rule supports Block, Audit, or Not
- Identity, Access and Conditional Access — Key conditions you must master: - User and group: Scope who the policy targets. Use include/exclude logic to pilot and to carve out break-glass
- Co-management and Hybrid Environments — Enrollment flow for existing ConfigMgr clients uses the co-management wizard in the ConfigMgr console to connect the site to your Azure AD tenant and
- Windows Lifecycle and Update Management — Feature update policies target and hold devices on a specific Windows version, independently of ring deferrals. In Intune, use Feature updates for
- Remote Management and Monitoring — - Retire (selective wipe): Removes corporate footprint while preserving personal data. It unenrolls the device from Intune, removes the MDM
- Data Protection and Information Governance — Automatic and recommended labeling extend the same label taxonomy to devices. Modern Office apps with built-in sensitivity labeling on Windows,
- Intune Administration and Governance — RBAC assignments pair a role with: - Administrative group (the users/admins receiving the role) - Scope (groups of devices/users the role can manage)
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →