All Practice Exams

200+ Free MD-102 Practice Questions

Pass your Microsoft 365 Endpoint Administrator (MD-102) exam on the first try — instant access, no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
~70% Pass Rate
200+ Questions
100% Free
1 / 200
Question 1
Score: 0/0

A company is issuing Windows 11 laptops to fully remote employees. The organization uses Microsoft 365 and Intune, but it has no on-premises Active Directory dependencies. Which device join option should the administrator choose?

A
B
C
D
to track
2026 Statistics

Key Facts: MD-102 Exam

700/1000

Passing Score

Microsoft

40-60 Q

Typical Questions

Microsoft

100 min

Exam Duration

Microsoft

US$165

U.S. Exam Fee

Microsoft

30-35%

Largest Domain

Microsoft blueprint

2026-01-23

Latest Blueprint Refresh

Microsoft study guide

MD-102 is a role-based Microsoft associate exam with a 700/1000 passing score, a 100-minute exam duration, and typical 40-60 question delivery. The largest domain is Manage and maintain devices at 30-35%, followed by Prepare infrastructure for devices at 25-30%. Microsoft refreshed the skills measured on January 23, 2026, with a minor update in the identity and compliance objective area.

Sample MD-102 Practice Questions

Try these sample questions to test your MD-102 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 200+ question experience with AI tutoring.

1A company is issuing Windows 11 laptops to fully remote employees. The organization uses Microsoft 365 and Intune, but it has no on-premises Active Directory dependencies. Which device join option should the administrator choose?
A.Microsoft Entra joined
B.Hybrid Microsoft Entra joined
C.Workgroup joined
D.Local accounts only
Explanation: Microsoft Entra joined is the standard choice for cloud-only organizations that manage Windows with Intune. It provides a cloud identity for the device, supports modern authentication, and avoids any dependency on on-premises domain services.
2An organization has existing Windows devices that must stay joined to on-premises Active Directory for legacy applications and Group Policy, but the devices also need cloud identity benefits and access to Microsoft 365. Which join state best meets this requirement?
A.Microsoft Entra registered
B.Hybrid Microsoft Entra joined
C.Workgroup joined
D.Microsoft Entra joined only
Explanation: Hybrid Microsoft Entra joined devices remain connected to on-premises Active Directory while also being represented in Microsoft Entra ID. That model is designed for environments that still need legacy domain features but also want modern cloud-based access and management.
3Licensed users are joining new Windows devices to Microsoft Entra ID, but the devices are not enrolling into Intune automatically. Which prerequisite is most likely missing?
A.An MDM user scope assignment for automatic enrollment
B.A device compliance policy
C.An attack surface reduction policy
D.A Microsoft Store app assignment
Explanation: Automatic enrollment for Microsoft Entra joined Windows devices depends on Intune being configured as the MDM authority for the appropriate users. If the MDM user scope is not set for those licensed users, the join can succeed while Intune enrollment never starts.
4You want to block users from enrolling personally owned Windows devices in Intune while still allowing corporate-owned Windows devices to be enrolled through Windows Autopilot. Which Intune control should you configure?
A.Device limit restrictions
B.Platform enrollment restrictions
C.App protection policies
D.Update rings
Explanation: Platform enrollment restrictions let you allow or block enrollment by platform and ownership type. That makes them the correct control for stopping personal Windows enrollment while continuing to allow corporate-owned scenarios such as Autopilot.
5A user cannot enroll a replacement laptop because Intune reports that the user has already reached the maximum number of enrolled devices. Which setting should the administrator review?
A.Enrollment Status Page settings
B.Device limit restriction
C.Security baseline assignment
D.App configuration policy
Explanation: Device limit restrictions control how many devices a user can enroll in Intune. If a user has reached the limit, increasing or otherwise adjusting that restriction is the direct fix.
6A hardware vendor will ship new Windows laptops directly to employees. Each employee should sign in during out-of-box setup and become the primary user of the device. Which Windows Autopilot deployment mode should you use?
A.Self-deploying mode
B.User-driven mode
C.Pre-provisioned deployment only
D.Device Enrollment Manager mode
Explanation: User-driven mode is intended for individually assigned devices where the end user signs in and completes the enrollment experience. It is the standard Autopilot choice for new corporate laptops shipped directly to users.
7The IT team wants to reduce the time employees spend waiting at first sign-in by having a technician or partner apply apps and policies before the device reaches the user. Which Windows Autopilot feature should be used?
A.Pre-provisioned deployment
B.Self-deploying mode
C.Platform enrollment restrictions
D.Provisioning package removal
Explanation: Pre-provisioned deployment lets IT or an OEM partner stage much of the device setup before handing the device to the user. That shortens the user-facing setup experience because required apps and policies can be processed in advance.
8A company is deploying Windows devices to lobbies as kiosks. The devices should set themselves up without a user sign-in and should not have user affinity. Which Windows Autopilot mode best fits this scenario?
A.User-driven mode
B.Self-deploying mode
C.Pre-provisioned deployment
D.Hybrid join conversion
Explanation: Self-deploying mode is built for shared, kiosk, or task-based devices that do not need a primary user. It allows the device to provision itself with minimal human involvement and no standard end-user enrollment flow.
9You need to register existing corporate Windows devices in Windows Autopilot so they can receive Autopilot deployment profiles. Which identifier is typically required for manual import?
A.The device serial number alone
B.The hardware hash
C.The public IP address
D.The list of installed applications
Explanation: For standard manual Autopilot import, the key identifier is the device hardware hash. It uniquely identifies the device to the Autopilot service so that deployment profiles can be assigned before or during setup.
10A field technician must configure a Windows device at a remote site with unreliable internet access, and the device can complete full cloud enrollment later. What is the best initial deployment method?
A.Windows Autopilot self-deploying mode
B.A Windows provisioning package created with Windows Configuration Designer
C.A Defender for Endpoint onboarding package
D.A Microsoft 365 Apps configuration XML file
Explanation: A provisioning package is useful when you need to apply settings or enrollment-related configuration offline or with limited connectivity. It is designed for staged setup scenarios where the full cloud experience can happen later.

About the MD-102 Exam

The Microsoft 365 Endpoint Administrator (MD-102) exam validates the skills needed to deploy, configure, secure, manage, and monitor endpoints in a Microsoft 365 environment. Candidates are expected to use Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Windows 365, and Microsoft Defender for Endpoint to administer Windows and cross-platform devices at scale.

Questions

60 scored questions

Time Limit

100 minutes

Passing Score

700/1000

Exam Fee

US$165 (Microsoft / Pearson VUE)

MD-102 Exam Content Outline

25-30%

Prepare infrastructure for devices

Device join and registration with Microsoft Entra ID, Intune enrollment settings, automatic and bulk enrollment, Android enrollment profiles, and identity/compliance controls such as Conditional Access, Windows Hello for Business, Windows LAPS, and local group management.

30-35%

Manage and maintain devices

Windows Autopilot and provisioning packages, Enrollment Status Page, Windows 11 upgrades, Windows 365 Cloud PCs, configuration profiles across supported platforms, Intune Suite capabilities, remote actions, and device reporting.

15-20%

Manage applications

Preparing and deploying apps with Intune, Microsoft 365 Apps deployment and policy management, app store integrations, app protection policies, app configuration policies, and Conditional Access for protected apps.

15-20%

Protect devices

Endpoint security policies, antivirus, BitLocker and FileVault-related encryption controls, firewall and attack surface reduction policies, security baselines, Defender for Endpoint integration, onboarding, update rings, feature updates, and delivery optimization.

How to Pass the MD-102 Exam

What You Need to Know

  • Passing score: 700/1000
  • Exam length: 60 questions
  • Time limit: 100 minutes
  • Exam fee: US$165

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

MD-102 Study Tips from Top Performers

1Spend the largest block of time on device lifecycle operations because Manage and maintain devices is the biggest domain at 30-35%.
2Memorize the differences between Microsoft Entra join, hybrid join, and Entra registration because join/enrollment scenarios are foundational.
3Practice Autopilot modes, Enrollment Status Page behavior, provisioning packages, and Windows 365 licensing and deployment prerequisites.
4Know where Intune uses compliance policies versus configuration profiles versus endpoint security policies, because those boundaries drive many scenario questions.
5Be comfortable with Microsoft 365 Apps deployment methods, app protection policies, and the difference between managed apps and managed devices.
6Review Defender for Endpoint onboarding, security baselines, update rings, feature updates, and delivery optimization together because Microsoft tests them as operational endpoint-protection workflows.

Frequently Asked Questions

What is the MD-102 passing score?

The MD-102 exam uses Microsoft's standard scaled passing score of 700 out of 1000. Microsoft role-based exams typically deliver 40-60 questions, and the current MD-102 certification page lists 100 minutes to complete the assessment.

How many questions are on the MD-102 exam?

Microsoft says certification exams typically contain between 40 and 60 questions, and MD-102 follows that role-based exam model. The exact number can vary because Microsoft adjusts item pools as technology and job-role requirements change.

What topics matter most on MD-102?

The most heavily weighted domain is Manage and maintain devices (30-35%), followed by Prepare infrastructure for devices (25-30%). That means Intune enrollment, compliance, Autopilot, configuration profiles, remote actions, Windows 365, and update management deserve the biggest share of your study time.

What changed on the MD-102 exam in 2026?

Microsoft updated the MD-102 skills measured effective January 23, 2026. The official change log marks Prepare infrastructure for devices as unchanged and lists a minor change in the identity and compliance area, so current prep should reflect the refreshed blueprint rather than older 2024 outlines.

Are there prerequisites for MD-102?

There is no formal exam prerequisite published for MD-102, but Microsoft expects candidates to already be comfortable managing devices and client apps in a Microsoft 365 tenant. Practical experience with Microsoft Intune, Microsoft Entra ID, Windows Autopilot, Windows client administration, and endpoint security makes a significant difference.

Does the MD-102 certification expire?

Yes. Microsoft's role-based certifications expire unless they are renewed. Microsoft currently allows renewal at no cost by passing an online assessment on Microsoft Learn before the certification expires.