Browse Certification Practice Tests by Exam Family

Microsoft MD-102 Cheat Sheet: Endpoint Administrator

Review the Microsoft Endpoint Administrator (MD-102) scope, Microsoft Intune, enrollment, compliance, Autopilot, app deployment, endpoint security, updates, and troubleshooting traps before practicing.

MD-102 is an endpoint-management exam. Use this cheat sheet to separate enrollment, configuration, compliance, application delivery, security baselines, updates, and troubleshooting before practicing.

Use this with practice. Review the endpoint-management checkpoints, then return to the MD-102 exam page for sample questions and update tracking.

Open MD-102 practice page Compare Microsoft 365 routes

Exam snapshot

FieldDetail
IssuerMicrosoft
Certification laneMicrosoft Endpoint Administrator
Exam codeMD-102
Main scopeEndpoint deployment, Intune management, compliance, application deployment, security, updates, and troubleshooting
IT Mastery statusSample questions available

Endpoint map

AreaWhat to knowCommon trap
Enrollment and identityMicrosoft Entra join, hybrid join, Intune enrollment, device ownership, and enrollment restrictionsTroubleshooting policy before confirming enrollment state
Windows AutopilotDeployment profiles, device registration, user-driven setup, reset, and provisioningTreating Autopilot as traditional imaging
Configuration profilesSettings catalog, templates, baselines, filters, assignment, and conflictsAssigning a policy to the wrong user or device group
Compliance and accessCompliance policies, device health, Conditional Access, remediation, and reportingAssuming a compliant policy applies before the device checks in
Application managementRequired, available, uninstall, detection rules, supersedence, and app protectionIgnoring detection logic when an app appears not installed
Endpoint security and updatesDefender, firewall, attack-surface reduction, security baselines, update rings, and monitoringPatching everything at once with no staged rollout

Must-know distinctions

DistinctionHow to decide
Enrollment profile vs configuration profileEnrollment controls onboarding; configuration controls settings after management begins.
Compliance policy vs configuration profileCompliance reports whether a device meets rules; configuration enforces settings.
Required app vs available appRequired apps install automatically; available apps are user-selectable.
User assignment vs device assignmentUser targeting follows the person; device targeting follows the managed endpoint.
Autopilot vs imagingAutopilot provisions cloud-managed devices without a traditional image refresh in many scenarios.
Device management vs app protectionDevice management controls the whole device; app protection can protect data in managed apps.

High-yield checklist

  • Confirm enrollment, ownership, platform, and management state before policy troubleshooting.
  • Check assignment targeting, filters, groups, and sync status when a policy does not apply.
  • Use compliance with Conditional Access when access should depend on device health.
  • Use app protection policies when personal devices need app-level data controls.
  • Use security baselines and endpoint security profiles for Defender, firewall, and attack-surface settings.
  • Use update rings or staged groups for safe update deployment.
  • Use Autopilot for modern provisioning and reset scenarios.
  • Check conflicts and precedence when two policies set the same control.
  • Review reports and diagnostics before assuming Intune failed silently.

Common traps

  • Confusing compliance reporting with configuration enforcement.
  • Assigning a policy to users when the scenario requires device targeting.
  • Forgetting enrollment restrictions or platform support.
  • Troubleshooting app deployment without detection-rule evidence.
  • Using full device management when app protection is the less intrusive answer.
  • Skipping pilot rings for update rollout.

Practice strategy

For MD-102 misses, state the device lifecycle stage: enroll, configure, secure, deploy app, update, monitor, or retire. Then check whether the scenario is asking for a policy, profile, assignment, report, or troubleshooting step.

Revised on Monday, May 25, 2026