Associate-level certification covering device enrollment and identity, Windows deployment with Autopilot, endpoint security and updates, app management, and automated endpoint operations with Microsoft Intune.
Free sample questions
No account needed. Every question explains why every answer is right or wrong, just like the full bank.
lock_openFree samplePrepare Infrastructure for Deviceshard
An Intune role assignment is created from the Help Desk Operator built-in role. The assignment lists the group HelpdeskAdmins as its members, a group named PerthDevices as its scope (groups), and the Default scope tag. What does the scope (groups) part of that assignment determine?
- AWhich users and devices the assigned administrators are permitted to apply those permissions to.check_circle Correct
- BWhich administrator accounts receive the permissions that the Help Desk Operator role carries.
- CWhich Intune objects, such as configuration profiles and apps, the assigned administrators can see.
- DWhich remote device actions, such as restart and sync, the assigned administrators are able to run.
An Intune role assignment separates who holds the role, which users and devices it reaches, and which objects the admin can see. An Intune role assignment is made of three independent parts: members, who hold the role; permissions, drawn from the role definition, which decide the actions; and scope (groups), which decides the users and devices those actions may target. Scope tags are a fourth, separate control that governs which Intune objects the administrator can view.
Why A is correct: Correct. The scope (groups) of a role assignment is the population of users and devices the assignment reaches, so the helpdesk can act only on members of PerthDevices.
Why B is wrong: Tempting because members and scope both name Microsoft Entra ID groups, so the two fields look interchangeable. The administrators who receive the permissions are the members of the assignment, which here is HelpdeskAdmins, not the scope.
Why C is wrong: Tempting because visibility really is restricted in Intune role-based access control, but that job belongs to scope tags. An administrator sees an object when a scope tag on the object matches a scope tag on the assignment.
Why D is wrong: Tempting because the helpdesk experience is built from remote actions, but the set of allowed actions comes from the permissions in the role definition. The scope decides the targets of those actions, not the actions themselves.
lock_openFree sampleProtect Deviceshard
A Windows 11 device is enrolled in Microsoft Intune and is already onboarded to Microsoft Defender for Endpoint. A third-party antivirus product is then installed on it and registers itself with Windows as the active antivirus solution. Which statement correctly describes the resulting state of Microsoft Defender Antivirus on that device?
- AIt moves into passive mode, so real-time protection is handed to the third-party product while the built-in engine keeps receiving security intelligence updates, can still run on-demand scans, and reports what it sees to Defender for Endpoint.check_circle Correct
- BIt is switched off entirely by the third-party installation and stops scanning, so nothing Microsoft Defender Antivirus does can be observed until the third-party product is uninstalled from the device.
- CIt remains the active antivirus solution alongside the third-party product, so two real-time engines inspect the same file operations and the device is protected by both engines at once.
- DIt is uninstalled from the device by Windows as soon as another antivirus product registers, and it can be brought back solely by rebuilding the device or by repairing the operating system image.
Recognise that a third-party antivirus places Microsoft Defender Antivirus into passive mode on a Windows client onboarded to Microsoft Defender for Endpoint, not into a disabled state. The mode Microsoft Defender Antivirus falls into when another product registers as the active antivirus depends on whether the device is onboarded to Microsoft Defender for Endpoint. Onboarding keeps the built-in engine loaded in passive mode, so it continues to update, remains available for on-demand scanning and keeps feeding signal to the service, while the third-party product owns real-time protection. Without onboarding the built-in engine would instead be disabled, which is why the onboarding state, and not the presence of the third-party product alone, decides the answer.
Why A is correct: Correct. On a Windows client that is onboarded to Microsoft Defender for Endpoint, installing a third-party antivirus places Microsoft Defender Antivirus in passive mode rather than disabling it, which preserves updates, on-demand scanning and reporting while the third-party product owns real-time protection.
Why B is wrong: This is tempting because it describes what happens on a Windows client that has not been onboarded to Microsoft Defender for Endpoint, where the built-in engine does step aside completely. It is wrong here because onboarding changes that outcome, leaving the engine running in a reduced role rather than switched off.
Why C is wrong: This is tempting because layered protection sounds safer and administrators often assume both engines simply coexist. It is wrong because Windows recognises a single registered real-time antivirus solution, and running two real-time engines against the same file operations is not the supported design.
Why D is wrong: This is tempting because third-party security products often insist that competing agents be removed before installation. It is wrong because Microsoft Defender Antivirus is a built-in platform component that is not uninstalled when another product registers; its mode changes instead.
lock_openFree sampleManage and Maintain Deviceshard
An organisation is comparing classic Windows Autopilot deployment profiles with Windows Autopilot device preparation policies before it rebuilds its provisioning process. Which statement correctly describes how each approach identifies the device that is about to be provisioned?
- ABoth approaches require the device hardware identity to be imported into the tenant list of Autopilot devices first, and both then deliver their settings to that device during the out-of-box experience.
- BA device preparation policy is assigned to a device group whose membership comes from imported hardware identities, while a classic deployment profile is assigned to the user who signs in during the out-of-box experience.
- CA device preparation policy identifies the device by its domain join configuration, so the device has to be joined to Active Directory before the policy applies and no registration in the tenant is required.
- DA classic deployment profile is delivered to a device that was registered as an Autopilot device in the tenant beforehand, while a device preparation policy is assigned to a user group and depends on Intune adding the provisioned device to a device group that it owns.check_circle Correct
A classic Autopilot profile finds a pre-registered device identity, while a device preparation policy is user assigned and populates its device group during provisioning. The two approaches differ at the point where device and policy meet. A deployment profile is matched to a hardware identity that already exists in the tenant, so registration is a prerequisite and an unregistered machine simply runs a normal out-of-box experience. A device preparation policy is assigned to a user group, so the policy is resolved from the account signing in, and Intune adds the machine to the device security group it owns during provisioning, which removes the registration prerequisite entirely.
Why A is wrong: It is tempting because hardware identity import is the step most administrators associate with Autopilot, and it is genuinely mandatory for a classic deployment profile. It is wrong because a device preparation policy provisions a device that was never imported, which is the main reason the newer approach exists.
Why B is wrong: It is tempting because a device preparation policy does involve a device group, so that group looks like the targeting object. It is wrong because the assignment is made to a user group and the device group is populated by Intune during provisioning, and a classic deployment profile targets registered devices rather than users.
Why C is wrong: It is tempting because hybrid scenarios do rely on a domain join configuration to complete provisioning. It is wrong because device preparation provisions a Microsoft Entra joined device and does not identify it through an on-premises domain join at all.
Why D is correct: Correct. The classic flow matches a device to a profile using the device identity already held in the tenant, so an unregistered device receives nothing. Device preparation inverts that: the signed-in user carries the policy, and Intune places the device into the security group it owns as part of provisioning.
More free MD-102 practice questions, every answer explainedFrequently asked questions
- How many questions are on the MD-102 exam?
- The Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) exam has Typically 40 to 60 questions questions and runs for 100 minutes. The format is multiple choice and multiple response, at a pearson vue testing center or online proctored.
- What score do I need to pass MD-102?
- The pass mark is 700 / 1000. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
- How much does the MD-102 exam cost?
- The exam costs 165 USD to sit. Practising on Examworthy is free to start, and every answer is explained, right and wrong.
- Is there a MD-102 practice exam?
- Yes. Examworthy's exam mode runs a timed MD-102 practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand. Timed mocks are free with an account.
- How does Examworthy help me prepare for MD-102?
- Every practice question explains why the right answer is right and why each wrong one is wrong, mapped to the official blueprint domains. You learn the reasoning, not just the letter.
- Is Examworthy affiliated with Microsoft?
- No. Examworthy is not affiliated with or endorsed by Microsoft. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.
Examworthy is not affiliated with or endorsed by Microsoft. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. MD-102 and related marks belong to their respective owners.