Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) cheat sheet
Microsoft
Free to share. Examworthy is not affiliated with or endorsed by Microsoft; MD-102 and related marks belong to their respective owners.
At a glance
Format: Multiple choice and multiple response, at a Pearson VUE testing center or online proctored
Domain weight map
Heaviest first - spend your time hereHow this exam thinks
MD-102 rewards knowing which Intune mechanism satisfies a stated requirement, not knowing what every Intune feature does.
Spot the trap
Tempting wrong answers, and why they failCommon misconception
Importing the hardware identity is not mandatory for both approaches. A device preparation policy provisions a device that was never imported, which is the main reason the newer approach exists.
Manage and Maintain Devices
Common misconception
A scope tag never grants a permission. Tagging the regional policies does make them visible to a Read Only Operator, but the role stays read only and the team still cannot create or edit anything.
Prepare Infrastructure for Devices
Common misconception
Two real-time engines do not simply coexist for layered safety. Windows recognises a single registered real-time antivirus solution, and running two real-time engines against the same file operations is not the supported design.
Protect Devices
Common misconception
Device licensing does not remove the Apple Business Manager token. The token is what proves the tenant owns the purchases, and without a valid synchronised token neither licensing model can assign a volume purchased title.
Manage and Secure Applications
Common misconception
Tenant wide admin consent only pre-approves a delegated permission so the individual consent prompt is skipped. A delegated call still needs a signed-in user in the token request.
Optimize Endpoint Operations by Using Automation, Monitoring, and Reporting
Common misconception
A feature update policy does not take over quality updates. It governs the feature version alone, and the update ring remains the object that controls quality update behaviour.
Manage and Maintain Devices
Common misconception
Devices can be given scope tags too, but a device tag exists so that scoped administrators see the right devices. Intune does not intersect an object's tags with a device's tags when it evaluates an assignment.
Prepare Infrastructure for Devices
Common misconception
Onboarding does not hand antivirus settings to the Defender portal. Endpoint detection and response and antivirus are separate components that run together, and an antivirus policy assigned from Intune keeps applying after onboarding.
Protect Devices
Key terms
Exam-day rules
- Read the final sentence of the stem first. The constraint lives there, and it is what separates the one correct mechanism from three plausible ones.
- Check the platform and the ownership model in every scenario before comparing options. Answers that assume Windows behaviour on Android or iOS, or corporate behaviour on a personally owned device, are a standard distractor family.
- When a question says to choose two, treat it as two independent decisions and verify each against the requirement separately. Picking one strong option and one that merely sounds related is the most common way a multi-select item is lost.
- Prefer the least-privilege answer whenever the scenario mentions delegation or an administrator who should see or do less. A built-in role that grants more than the task needs is usually the distractor next to a custom role or a scope tag.
- Ask which layer the requirement names: setting state, reporting state, gating access or governing data inside an application. Most pairs of plausible options sit on adjacent layers and separate instantly once you name the layer.
Revision schedule
- Day 1Read the current study guide and map your gaps
- Week 1Get a tenant you can break
- Weeks 2 to 3Work the two heaviest domains first
- Weeks 4 to 5Take protection and applications together
- Week 6Close the automation and reporting gap