Back to blog
Study Tips13 min read

How to Pass the Microsoft MD-102 Exam in 2026: An 8-Week Endpoint Administrator Study Plan

MD-102 was restructured on 24 July 2026 and now has five domains, including a brand new one on automation, monitoring and Security Copilot agents. Here is the full outline, the pass mark, and an 8-week study plan built for the current version.

Owen Gallagher

Owen Gallagher · Study Skills & Careers Editor

1 August 2026

If you booked MD-102 before the summer and have been revising from a study guide you downloaded a few months ago, stop and check the date on it. Microsoft rewrote the MD-102 skills outline on 24 July 2026, and the change is not cosmetic. The exam went from four skill areas to five, and the new area covers automation, monitoring and Security Copilot agents in Intune, which simply were not testable before.

This guide gives you the current MD-102 exam structure straight from Microsoft's published study guide, explains exactly what moved, and lays out an eight week plan that gets a working IT administrator from a standing start to a pass. Every domain weight and objective below comes from the outline that took effect on 24 July 2026.

What MD-102 Is in 2026

MD-102 is the single exam behind the Microsoft 365 Certified: Endpoint Administrator Associate certification. It replaced the old MD-100 and MD-101 pair, both of which Microsoft retired on 30 September 2023.

The full exam title is now "Managing and Securing Microsoft 365 Endpoints by using Intune", and that title tells you where the emphasis sits. This is not a Windows client trivia exam. It is an Intune exam that happens to involve Windows, macOS, iOS, iPadOS and Android.

The audience profile Microsoft publishes is worth reading carefully, because it changed too. It now says candidates should have "an understanding of Microsoft Security Copilot, Intune agents, and Microsoft Defender XDR". Agentic tooling is officially part of the endpoint administrator role as Microsoft defines it.

Exam Tip: MD-102 requires a score of 700 or greater on a scale of 100 to 1000 to pass. That is a scaled score, not a percentage, so do not assume you need 70 percent of questions correct.

MD-102 Exam Format at a Glance

ItemDetail
CertificationMicrosoft 365 Certified: Endpoint Administrator Associate
Exam codeMD-102
LevelIntermediate
Passing score700 out of 1000 (scaled)
Outline last updated24 July 2026
Number of domains5
Renewal frequency12 months, via a free online assessment on Microsoft Learn
DeliveryPearson VUE, test centre or online proctored
Standard price165 USD, varies by country

Microsoft does not publish an official question count for MD-102. Candidates consistently report somewhere between 40 and 60 items, including a case study, and the appointment is booked with enough time that pacing is rarely the thing that fails people. Content gaps are.

If you are sitting online rather than at a test centre, read our guide to OnVUE online proctored exam rules before booking. Check-in problems cause more cancelled Microsoft exams than most people expect.

The Five MD-102 Domains and How to Weight Your Study Time

Here is the current outline with the weights Microsoft assigns to each area.

DomainWeightWhat it really covers
Prepare infrastructure for devices20 to 25%Entra ID join and registration, Intune enrolment for every platform, roles, scope tags, compliance policies, Conditional Access, Windows Hello for Business, Windows LAPS
Manage and maintain devices25 to 30%Autopilot and device preparation policies, Windows 365 Cloud PCs, configuration profiles, Intune Suite add-ons, remote actions, device query with KQL
Protect devices15 to 20%Antivirus, disk encryption, firewall and ASR policies, security baselines, Defender for Endpoint integration, App Control for Business, update rings, Autopatch and Hotpatch
Manage and secure applications15 to 20%Win32 and LOB app deployment, Microsoft 365 Apps, app protection policies for BYOD, app configuration policies
Optimize endpoint operations by using automation, monitoring, and reporting10 to 15%PowerShell and Microsoft Graph automation, Security Copilot agents in Intune, Endpoint Analytics, proactive remediations, reporting and alerting

The largest single block is "Manage and maintain devices" at 25 to 30 percent. If your revision time is limited, Autopilot and configuration profiles are where the marks are.

What Changed on 24 July 2026

Microsoft's own change log flags these as the meaningful shifts:

  • A whole new domain. "Optimize endpoint operations by using automation, monitoring, and reporting" is new, worth 10 to 15 percent, and did not exist in the previous version at all.
  • "Prepare infrastructure for devices" grew as a percentage of the exam, while "Manage and maintain devices" shrank.
  • Three objectives were rated a major change: enrolling devices to Intune, deploying and upgrading Windows clients with cloud based tools, and performing remote actions on devices.
  • "Configure endpoint security" was a major change within the Protect devices domain.
  • "Manage applications" was renamed "Manage and secure applications", with the weight unchanged.

The practical consequence is that a lot of the free MD-102 material currently ranking on Google describes a four domain exam. If a study guide does not mention Security Copilot agents, proactive remediations or device preparation policies, it predates the current version.

The New Automation and Monitoring Domain Explained

This is the part almost nobody has revised properly yet, which makes it the easiest place to pick up marks relative to effort. It splits into two objective groups.

Automate management tasks covers automating Intune tasks with PowerShell and Microsoft Graph, extending device compliance with PowerShell, and three separate objectives about Security Copilot agents in Intune: investigating threats they identify, analysing device performance with them, and reviewing and responding to their recommendations.

Monitor and optimize health covers Intune reporting and data visibility (custom reports, filters, workbooks, dashboards and data export), Endpoint Analytics (proactive remediations, device health scores, app startup performance), configuring and scheduling proactive remediation scripts, endpoint reliability and user experience scores, tenant health and service communications, and alert rules for compliance drift, enrolment failures and configuration conflicts.

Read that list as a checklist. Every bullet is a plausible question stem.

Exam Tip: Microsoft states that most questions cover features at general availability, but the exam may include Preview features if they are commonly used. Intune's agentic features are moving quickly, so do not skip something purely because it is badged Preview in your tenant.

The 8-Week MD-102 Study Plan

This plan assumes eight to ten hours a week. If you already administer Intune daily, compress it to six weeks by merging weeks 1 and 2 and weeks 6 and 7. If you have never touched Intune, add a fortnight rather than rushing.

The order deliberately follows the device lifecycle rather than Microsoft's domain order, because concepts stick better when they follow the sequence you would actually perform them in.

Week 1: Identity Foundations and Your Lab

Get your environment sorted first. Sign up for a Microsoft 365 developer or trial tenant so you have somewhere to click. Reading about enrolment restrictions teaches you far less than hitting one.

  • Entra ID join versus Entra hybrid join versus device registration, and when each is correct
  • Joining and registering devices, and what appears in Entra afterwards
  • Dynamic group membership rules for devices, including the syntax
  • Intune built in and custom roles, role assignments, scope tags and scoped administration
  • Multi-admin approval

Practise writing dynamic membership rules by hand. They appear in drag-and-drop and build-list questions and they are easy marks if you know the operators.

Week 2: Enrolment Across Every Platform

Enrolment was flagged as a major change, so treat it as a priority rather than a formality.

  • Intune enrolment settings and enrolment restrictions
  • Automatic enrolment for Windows
  • Personal enrolment for macOS, iOS and iPadOS
  • Android enrolment profiles: fully managed, dedicated, corporate owned with work profile, and personally owned with work profile
  • Apple Business Manager integration for corporate macOS and iOS
  • Samsung Knox Mobile Enrolment and Google Zero Touch
  • Troubleshooting enrolment failures

Build a table of the Android enrolment types with their use cases. Confusing dedicated with fully managed is one of the most common avoidable errors on this exam.

Week 3: Compliance, Conditional Access and Endpoint Identity

  • Compliance policies for every supported platform
  • Conditional Access policies that require a compliant device
  • Windows Hello for Business configured through Intune, including cloud Kerberos trust as the modern default
  • Windows LAPS via Intune and Entra ID
  • Managing local group membership on Windows devices

Understand the relationship between compliance state and Conditional Access properly. Questions frequently describe a user who cannot access a resource and ask you to identify which policy is responsible.

If identity is unfamiliar territory, our SC-300 study plan covers the Entra side in more depth than MD-102 requires, and the overlap is genuinely useful.

Week 4: Autopilot, Windows 365 and Deployment

This is the heaviest single week and it sits inside the heaviest domain.

  • Choosing between Autopilot deployment profiles and device preparation policies
  • Autopilot deployment modes: user-driven, pre-provisioning and self-deploying
  • Device name templates
  • Enrolment Status Page configuration
  • Windows 11 upgrades through Intune
  • Windows 365 Cloud PC provisioning policies, network connections and image management
  • Windows Backup and Restore via Intune

Device preparation policies versus classic Autopilot profiles is new decision-making territory. Learn what each one supports and when Microsoft steers you towards the newer option.

Week 5: Configuration Profiles and Intune Suite

  • Configuration profiles for Windows, including importing ADMX files and Group Policy analytics
  • Configuration profiles for Android, iOS, iPadOS and macOS
  • Specialty device profiles for Teams Rooms, HoloLens 2 and Zebra
  • Assignment filters and enrolment time grouping
  • Endpoint Privilege Management: elevation policies, monitoring elevated actions, adjusting settings
  • Enterprise App Catalog, Remote Help, Microsoft Cloud PKI, Microsoft Tunnel for MAM, Intune Advanced Analytics
  • Remote actions: sync, restart, retire, wipe, bulk actions, BitLocker key rotation, device query with KQL

Remote actions was also flagged as a major change. Know the difference between retire and wipe cold, because Microsoft loves that distinction.

Week 6: Protecting Devices

  • Antivirus policies in Intune
  • Disk encryption policies, BitLocker recovery key management, user self-service recovery, encryption compliance monitoring
  • Firewall policies and attack surface reduction rules, framed through Zero Trust
  • Security baselines
  • Defender for Endpoint integration: onboarding, EDR policies, investigating threats, triaging incidents
  • App Control for Business
  • Update rings, feature updates, quality updates
  • Windows Autopatch and Hotpatch policies
  • iOS, iPadOS and macOS update policies through the settings catalog
  • Android updates via configuration profiles or FOTA
  • Delivery Optimization

Hotpatch is a favourite of current question writers because it is recent and the eligibility rules are specific. Learn which editions and update rings support it.

If Microsoft security tooling interests you beyond endpoints, SC-500 is the logical next exam after this one.

Week 7: Applications and the New Automation Domain

Split this week in two.

Applications (three to four days): preparing apps for deployment, Win32 apps, LOB apps, Microsoft Store apps, Microsoft 365 Apps through Intune and the Office Deployment Tool, Office app policies, Apple Volume Purchase Program, Google Play, Quiet Time policies, monitoring deployment status and troubleshooting installation failures, app protection policies for managed and unmanaged BYOD devices, and app configuration policies.

Automation and monitoring (three to four days): PowerShell and Microsoft Graph automation, Security Copilot agents in Intune, Endpoint Analytics, proactive remediation scripts, reliability and user experience scores, tenant health monitoring, and alert rules.

App protection policies without enrolment (MAM-WE) is the standard answer to any scenario involving corporate data on a personal device where the organisation does not want to manage the whole device. Recognise that pattern and you will get several marks.

Week 8: Practice Exams and Weak Spot Repair

Do not learn anything new this week. Sit full length practice exams under timed conditions, then work backwards from every wrong answer to the objective it came from.

Two rules make this week effective:

  1. Score under 80 percent, revise rather than re-sit. Repeatedly taking practice exams without closing the gaps just teaches you the questions.
  2. Write one sentence explaining why each wrong answer was wrong. If you cannot write the sentence, you have not actually fixed the gap.

Take the free Microsoft practice assessment on the exam page as well as your paid practice, because it is written by the same organisation that writes the exam and its phrasing conventions match.

Common Reasons People Fail MD-102

  • Revising the old four domain outline. The single biggest risk right now. Anything published before late July 2026 is missing an entire domain.
  • No hands-on tenant. MD-102 asks where settings live and which blade performs an action. Reading cannot substitute for clicking.
  • Treating it as a Windows exam. macOS, iOS, iPadOS and Android appear throughout the outline. Ignoring non-Windows platforms costs marks across several domains.
  • Skipping the case study. Case studies carry disproportionate weight. Read the requirements section before the exhibit, not after.
  • Confusing similar features. Retire versus wipe, dedicated versus fully managed Android, deployment profiles versus device preparation policies, feature updates versus quality updates. Build a comparison sheet for each pair.

Frequently Asked Questions

What is MD-102 for?

MD-102 is the exam that earns the Microsoft 365 Certified: Endpoint Administrator Associate certification. It validates that you can deploy, configure, secure and monitor Windows, macOS, iOS, iPadOS and Android endpoints in a Microsoft 365 tenant using Microsoft Intune, Windows Autopilot, Microsoft Entra ID and Microsoft Defender for Endpoint. It is aimed at administrators who run the modern managed desktop for an organisation.

Is the MD-102 exam hard?

It is intermediate level and genuinely demanding for anyone without hands-on Intune experience, mainly because it tests where things live in the admin centre rather than definitions. Administrators who use Intune daily typically find it fair. The 24 July 2026 update raised the difficulty a little by adding automation, Endpoint Analytics and Security Copilot agent content that most candidates have never configured.

What is the difference between MD-102 and MS-102?

They are different exams for different roles. MD-102 is device focused and earns the Endpoint Administrator Associate certification, covering Intune, Autopilot and endpoint security. MS-102 is tenant focused and earns the Microsoft 365 Administrator Expert certification, covering tenant configuration, identity, and Microsoft 365 workload and threat management. If your job is managing laptops and phones, MD-102 is the right one.

Is MD-102 still valid?

Yes. MD-102 is current and was actively updated on 24 July 2026, so it is not being retired. It replaced MD-100 and MD-101, which Microsoft retired on 30 September 2023. The certification itself renews every 12 months through a free online assessment on Microsoft Learn rather than by re-sitting the full exam. You can check what else is changing in our roundup of every Microsoft certification retiring in 2026.

How long should I study for MD-102?

Eight weeks at eight to ten hours a week is a realistic target for an IT professional with some Microsoft 365 exposure. Daily Intune administrators can compress that to around six weeks. Anyone new to endpoint management should plan on ten to twelve weeks and spend the extra time building and breaking things in a lab tenant.

Ready to Start Practising?

Reading the objectives gets you familiar with MD-102. Answering exam style questions is what tells you whether you actually know it, and it is the fastest way to find the gaps while there is still time to close them.

CertCrush gives you realistic practice questions with full explanations for every option, so you learn why the wrong answers are wrong rather than just memorising the right ones. Track your scores by domain and you will see exactly which of the five MD-102 areas needs another pass.

Create your free CertCrush account and start practising today, or browse the full course catalogue to see everything covered.

MD-102Microsoft IntuneEndpoint AdministratorMicrosoft 365Study PlanExam PrepWindows Autopilot
Owen Gallagher

Written by

Owen Gallagher · Study Skills & Careers Editor

Owen spent years as an IT trainer watching smart people fail exams they should have passed — usually because of how they studied, not what they knew. He writes about study technique, exam psychology, career strategy and the service-management certifications (ITIL, PRINCE2, APM). His articles are the ones to read before you open a single practice question.

All articles by Owen

Want a MD-102 practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.