MD-102 — Endpoint Administrator
Microsoft

Endpoint Administrator (MD-102) Practice Questions

★★★★★ 5.0 103 verified reviews
92 questions
2026-06-18 updated
✓ Online quiz simulator

Domain coverage

  • Prepare infrastructure for devices (20–25%)
  • Manage and maintain devices (25–30%)
  • Protect devices (15–20%)
  • Manage and secure applications (15–20%)
  • Optimize endpoint operations by using automation, monitoring, and reporting (10–15%)

Sample Questions (10 of 92 shown)

Q1 Prepare infrastructure for devices (25-30%)
You have a Microsoft 365 subscription that contains 100 devices enrolled in Microsoft Intune. You need to review the startup processes and how often each device restarts. What should you use?
  1. Endpoint analytics
  2. Intune Data Warehouse
  3. Azure Monitor
  4. Device Management
✓ Correct Answer: A
Endpoint analytics in Microsoft Endpoint Manager provides insights into device startup performance, including startup processes and restart frequency. It measures boot time and identifies processes that slow down startup. Intune Data Warehouse provides reporting data, but Endpoint Analytics specifically provides the startup performance metrics requested.
Q2 Prepare infrastructure for devices (25-30%)
You have a Microsoft 365 E5 subscription that contains 100 Windows 10 devices enrolled in Microsoft Intune. You plan to use Endpoint analytics. You need to create baseline metrics. What should you do first?
  1. Create an Azure Monitor workbook
  2. Onboard 10 devices to Endpoint analytics
  3. Create a Log Analytics workspace
  4. Modify the Baseline regression threshold
✓ Correct Answer: B
To use Endpoint analytics, you must first onboard devices. Microsoft recommends onboarding at least 10 devices to establish baseline metrics. Endpoint analytics collects performance data from onboarded Windows devices and provides startup performance insights and recommendations. After onboarding, baseline metrics are automatically calculated.
Q3 Prepare infrastructure for devices (25-30%)
You need to download a report listing all devices that are NOT enrolled in Microsoft Intune but are assigned an app protection policy. Where should you look in the Microsoft Endpoint Manager admin center?
  1. Apps, and then App protection policies
  2. Apps, and then Monitor
  3. Devices, and then Monitor
  4. Reports, and then Device compliance
✓ Correct Answer: A
In the Microsoft Endpoint Manager admin center, you navigate to Apps > App protection policies to find reports about devices that have app protection policies applied but are not enrolled in Intune. This report shows devices that are managed at the app level (through MAM) without device enrollment.
Q4 Prepare infrastructure for devices (25-30%)
You need to add devices to Microsoft Entra ID. You have users who bring their personal Windows devices. Which join type should you recommend for these personal devices?
  1. Microsoft Entra registered
  2. Microsoft Entra joined
  3. Microsoft Entra hybrid joined
  4. Workplace joined
✓ Correct Answer: A
Microsoft Entra registered devices (formerly Workplace joined) are designed for BYOD scenarios. These devices have a Microsoft Entra account registered but are not joined to the directory. Users sign in with their organizational account to access resources while the device remains personally owned. Microsoft Entra joined is for organization-owned devices, and hybrid join is for domain-joined devices.
Q5 Prepare infrastructure for devices (25-30%)
You need to configure automatic enrollment for Windows devices in Microsoft Intune. What must be configured first?
  1. Microsoft Entra ID for automatic MDM enrollment
  2. Intune tenant with enrollment restrictions
  3. Windows Autopilot deployment profile
  4. Group Policy for MDM enrollment
✓ Correct Answer: A
For automatic Intune enrollment of Windows devices, you must first configure Microsoft Entra ID to enable automatic MDM enrollment. This is done in the Microsoft Entra admin center under Mobility (MDM and MAM) > Microsoft Intune. After configuring the MDM discovery URL and terms, Windows devices joined to Microsoft Entra ID will be automatically enrolled.
Q6 Prepare infrastructure for devices (25-30%)
You need to configure enrollment for corporate-owned Android devices that will be used by employees in a kiosk scenario. Which Android enrollment type should you use?
  1. Android Enterprise dedicated devices
  2. Android Enterprise fully managed
  3. Android Enterprise work profile
  4. Android device administrator
✓ Correct Answer: A
Android Enterprise dedicated devices enrollment is designed for kiosk, digital signage, and single-purpose devices. These devices are fully managed by the organization and are locked to a single app or set of apps. Fully managed devices are for corporate-owned with multi-user scenarios, work profile is for BYOD, and device administrator is a legacy method.
Q7 Prepare infrastructure for devices (25-30%)
You need to implement compliance policies for iOS/iPadOS devices in Intune. The policy must require a minimum operating system version. Which category in the compliance policy should you configure?
  1. Device Health
  2. Device Properties
  3. System Security
  4. Microsoft Defender for Endpoint
✓ Correct Answer: B
In an Intune compliance policy for iOS/iPadOS, the Device Properties category contains settings for minimum and maximum operating system versions. Device Health covers jailbreak detection, System Security covers password policies, and Defender for Endpoint covers endpoint detection and response requirements.
Q8 Prepare infrastructure for devices (25-30%)
You have a Microsoft 365 E5 subscription. You need to implement Conditional Access policies that require devices to be marked as compliant before accessing corporate resources. Where should you configure the compliance requirement?
  1. In the Conditional Access policy, under Grant, select Require device to be marked as compliant
  2. In the Intune compliance policy, under Actions for noncompliance
  3. In the Microsoft Entra admin center, under Device settings
  4. In the Microsoft 365 Defender portal, under Policies
✓ Correct Answer: A
To require compliant devices for accessing corporate resources, you configure the Conditional Access policy in the Microsoft Entra admin center. Under Grant controls, you select "Require device to be marked as compliant." This works together with Intune compliance policies - Intune evaluates compliance, and Conditional Access enforces access controls based on that status.
Q9 Prepare infrastructure for devices (25-30%)
You need to configure Windows Hello for Business for all Windows 10 devices enrolled in Intune. Where should you configure this?
  1. Intune device enrollment > Windows enrollment > Windows Hello for Business
  2. Microsoft Entra admin center > Devices > Device settings
  3. Group Policy > Windows Hello for Business
  4. Windows Settings > Accounts > Sign-in options
✓ Correct Answer: A
Windows Hello for Business configuration for Intune-enrolled devices is managed in the Microsoft Endpoint Manager admin center under Devices > Enrollment > Windows enrollment > Windows Hello for Business. This setting applies to all Windows devices enrolled in Intune and controls whether Windows Hello is enabled.
Q10 Prepare infrastructure for devices (25-30%)
You need to manage the membership of local groups on Windows devices by using Intune. Which profile type should you use?
  1. Administrative Templates
  2. Device restrictions
  3. Account protection
  4. Endpoint protection
✓ Correct Answer: C
Account protection profiles in Intune (under Endpoint security) include settings for managing local group membership on Windows devices. You can add or remove members from local groups such as Administrators, Remote Desktop Users, or create custom group management policies. This is part of the Account protection category within Endpoint security policies.

You've viewed 3 of 92 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 103 verified reviews

5.0 ★★★★★ Based on 103 reviews
★★★★★★
Solid Microsoft prep material. The MD-102 questions are well-written and the answer rationales are thorough.
— Madison T.
★★★★★★
My boss asked me to get the MD-102 cert for work. This was the best study tool I found. Passed in three weeks.
— Austin P.
★★★★★★
I bought access for the MD-102 exam as a gift for my brother. He passed on his first try and said the questions were spot-on.
— Cameron J.
★★★★★★
I have tried many Microsoft practice tests and this MD-102 bank is by far the most accurate and well-organized.
— Kevin N.
★★★★★★
I was preparing for the MD-102 exam while juggling a newborn at home. The flexibility of this platform was a lifesaver.
— Cooper D.
★★★★★★
The MD-102 exam was brutal, but these practice questions prepared me for the worst. Came out with a solid pass.
— Carter H.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

The biggest pitfall for candidates is resolving Intune device configuration profile conflicts when multiple profiles target the same endpoint population—understanding profile precedence rules is critical. Another common challenge is Windows Autopilot network prerequisites, specifically identifying when user-driven hybrid Entra ID joins require direct line-of-sight to a domain controller versus pure cloud-native joins. Our practice questions include scenario-based items on both topics with detailed explanations of the reasoning.

Microsoft offers the free MD-102 Practice Assessment on Microsoft Learn, which mirrors the formatting and technical difficulty of the real proctored exam. Additionally, the Exam Sandbox allows you to practice the split-screen Microsoft Learn interface, drag-and-drop mechanics, and case study section locks before exam day. Combining these with our practice question bank gives you both official and supplementary preparation.

If you do not pass on your first attempt, you must wait at least 24 hours before rescheduling a second try. For attempts 3 through 5, a 14-day waiting period is enforced between each registration. Microsoft caps candidates at five total exam attempts per rolling 12-month period. Our practice tests help you identify knowledge gaps before using an attempt.

The exam presents scenarios where multiple device configuration profiles apply to the same device or user group, and you must determine the effective setting based on Intune's profile precedence logic. Our practice questions include these conflict-resolution scenarios with step-by-step explanations, helping you understand not just the answer but the underlying policy evaluation order.

The online mock exam replicates the MD-102 exam format with case studies (complex enterprise scenarios with unreviewable section locks), drag-and-drop orchestration sequences, hot area configuration layouts, and multiple-choice questions. The practice engine also simulates partial credit scoring on multi-part items, so you can see how each correct component contributes to your overall score—just like the real exam's scaled scoring system.

Yes, the full question bank is available as a downloadable PDF that packages all practice questions, answer explanations, and domain references in a portable format. The PDF is ideal for offline review during commutes, flights, or in environments without stable internet access. It covers all five exam domains, with Intune configuration profiles, Windows Autopilot deployment, and Microsoft Defender for Endpoint scenarios receiving the same proportional coverage as the real exam.

The credential is valid for exactly one year from the date achieved. Microsoft allows you to extend its validity annually for free by passing an online, unproctored renewal assessment on Microsoft Learn within the 6-month window prior to expiration. No additional exam fee is required for renewal, making it straightforward to maintain your certification status.

Free Study Resources

Community-verified analysis of 91 topics from real test-taker discussions — 16 deep analyses and 0 FAQs.