MD-102 is the endpoint administration exam for teams that manage Windows devices through Intune and Microsoft 365. The useful path is not memorizing console names. It is learning how enrollment, compliance, configuration, apps, and security baselines interact in a real device lifecycle.
Primary source checked on 2026-05-10: Study guide for Exam MD-102. Use the Microsoft page as the final source of truth before booking an exam or committing a remediation plan.
Who this is for
- Endpoint administrators moving from classic imaging or Group Policy to Intune.
- Helpdesk leads who need to understand compliance failures, app deployment, and device lifecycle issues.
- Microsoft 365 teams preparing for a modern workplace rollout or tenant cleanup.
What to work on first
- Create a lab tenant or test group with Windows enrollment, compliance policies, configuration profiles, and app deployment.
- Practice failure paths: noncompliant device, missing app, stale enrollment, broken update ring, and user-driven Autopilot issues.
- Connect endpoint security baselines to Defender and Conditional Access so device posture actually changes access decisions.
Team training angle
MD-102 training should produce an endpoint runbook: enrollment flow, naming rules, compliance policy, update rings, app assignment model, support escalation, and security baseline exceptions.
One-week action plan
- Day 1: Intune architecture, groups, roles, and enrollment methods.
- Day 2: compliance, configuration profiles, update rings, and device filters.
- Day 3: application deployment, Win32 packaging, and troubleshooting.
- Day 4: endpoint security baselines, Defender integration, and access decisions.
- Day 5: Autopilot and incident drills.
Where Cloud Evolvers fits
Cloud Evolvers can run MD-102 as Intune exam prep or as a modern endpoint workshop for teams that need reliable deployment and support operations.