md-102Associate
Endpoint Administrator
Microsoft 365 Certified: Endpoint Administrator Associate
MD-102 is Intune end to end: enrolment and Autopilot, compliance and Conditional Access, configuration and baselines, app deployment, updates, and endpoint security. The Intune path below is in the order the exam thinks about a device's life.
For: Intune and modern-workplace admins managing Windows, macOS, iOS, and Android. Replaced the MD-100 + MD-101 pair.
28 guides in 4sections. The sections are this site's grouping, written to follow the shape of the published skills outline; weightings and the current outline live on the exam page above and change between exam versions.
01Deploy and enrol devices
- 1Microsoft Intune and device managementMicrosoft Intune explained: what it manages, how policies work, how enrollment and compliance fit together, and where it sits in Microsoft 365.
- 2Intune Windows AutopilotWindows Autopilot provisions new PCs straight to the end user with zero IT touch. Here's how it works.
- 3How to register devices for Windows AutopilotHow-toHow to register devices for Windows Autopilot: OEM registration, the hardware-hash CSV route, group tags, dynamic groups, and the deployment profile assignment.
- 4Rebuilding Autopilot after an enrollment tenant changeHow to move Autopilot-registered devices to a different tenant: deregister from the old, re-register in the new, the OEM route, and what happens per device.
- 5Configuration Manager co-management with IntuneHow co-management bridges on-prem Configuration Manager and cloud Intune during the migration to cloud-native endpoint management.
- 6Intune and Android EnterpriseManaging Android devices with Intune through Android Enterprise — work profiles, fully managed, dedicated devices.
- 7Intune macOS managementHow Intune manages Mac devices — enrolment via Apple Business Manager, configuration, app deployment, and compliance.
02Identity, compliance, and configuration
- 8Intune compliance policies and Conditional AccessCombining Intune compliance with Conditional Access gives you device-aware access control — the heart of zero trust.
- 9How to require compliant devices with Conditional AccessHow-toHow to require a compliant or hybrid-joined device with Conditional Access: the Intune compliance policy first, the grant control, exclusions, report-only.
- 10How to bulk-assign Intune configuration profilesHow-toHow to bulk-assign Intune configuration profiles: assignment groups, filters, All devices vs All users, exclusions, and a Graph script for many profiles.
- 11Microsoft 365 security baselinesThe minimum security configuration every Microsoft 365 tenant should have — and how to get there.
- 12Intune scripts and proactive remediationsHow Intune runs PowerShell scripts and proactive remediations on managed Windows devices.
- 13Intune Endpoint Privilege ManagementEPM lets standard users run specific tasks with elevated privileges without making them local admins.
03Applications and updates
- 14Intune Win32 app deploymentHow to package and deploy Win32 applications via Intune — the IntuneWin format, detection rules, and dependencies.
- 15How to deploy a Win32 app with IntuneHow-toHow to deploy a Win32 app with Intune: wrap the installer into an .intunewin, set install and uninstall commands, detection rules, requirements, and assign it.
- 16Intune app deployment for Microsoft 365 AppsHow to deploy and manage Microsoft 365 Apps (Word, Excel, etc.) through Intune — channels, updates, and policies.
- 17The Office Deployment Tool deep diveHow to use the Office Deployment Tool (ODT) for granular Microsoft 365 Apps deployment.
- 18Intune app protection policiesHow MAM-WE protects corporate data inside specific apps on personal devices — without managing the device itself.
- 19Windows AutopatchMicrosoft's managed Windows update service — what it does, where it differs from Windows Update for Business, and when to use it.
- 20Windows 11 25H2 and annual servicing explainedHow Windows 11 feature updates work now: shared servicing branches, enablement packages, the 36-month enterprise clock, and running the annual update.
- 21Microsoft 365 deployment rings and release channelsHow Microsoft ships changes to Microsoft 365, and how to set up deployment rings to control what your users see.
04Protect and monitor
- 22Microsoft Defender for Endpoint explainedDefender for Endpoint is Microsoft's EDR/XDR platform for laptops, servers, and mobile. Here's what it does.
- 23Microsoft Defender Antivirus configurationHow to configure Microsoft Defender Antivirus for Windows endpoints — the settings that matter and how to manage them.
- 24How to remote wipe a lost device with IntuneHow-toHow to remote wipe a lost device with Intune: Wipe vs Retire vs selective wipe, triggering the action, what happens while offline, and BitLocker recovery keys.
- 25Intune Endpoint AnalyticsEndpoint Analytics measures device performance and user experience across the Windows fleet.
- 26Windows 365 explainedWhat Windows 365 is: how Cloud PCs work, the licensing tiers, how it connects to Intune and Entra ID, and when it beats AVD or a physical laptop.
- 27Intune baseline for Cloud PCsA minimum viable Intune configuration for Windows 365 Cloud PCs: enrolment, compliance, configuration profiles, Autopatch, and the differences from laptops.
- 28Universal Print overviewMicrosoft's cloud printing service for Microsoft 365 — what it does, how to deploy it, and the limits.
Independent site, not affiliated with Microsoft. Found a gap in this path? Send it through the contact form.