All Practice Exams

100+ Free MD-102 Practice Questions

Pass your Microsoft 365 Certified: Endpoint Administrator Associate (MD-102) exam on the first try — instant access, no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
N/A Pass Rate
100+ Questions
100% Free
1 / 100
Question 1
Score: 0/0

You build a Windows Autopilot deployment profile and set Deployment mode to User-driven, Join type to Microsoft Entra joined, and Apply device name template to CON-%RAND:5%. What does the resulting computer name look like?

A
B
C
D
to track
2026 Statistics

Key Facts: MD-102 Exam

100 min

Assessment Time

Microsoft Learn 2026

700

Passing Score (of 1000)

Microsoft Learn 2026

$165

Exam Fee (USD)

Pearson VUE 2026

4

Functional Groups

MD-102 Skills Measured (April 28, 2026)

30-35%

Largest Domain (Manage and maintain devices)

MD-102 Skills Measured

12 months

Renewal Frequency

Microsoft Learn 2026

MD-102 is a 100-minute proctored exam delivered by Pearson VUE for $165 USD in the United States. Candidates answer roughly 40-60 multiple-choice and interactive items across four domains: Prepare infrastructure for devices (25-30%), Manage and maintain devices (30-35%), Manage applications (15-20%), and Protect devices (15-20%). A scaled score of 700 of 1000 is required to pass, and the certification renews annually via a free Microsoft Learn assessment.

Sample MD-102 Practice Questions

Try these sample questions to test your MD-102 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1A company wants to allow personal Windows 11 devices to access Microsoft 365 resources while keeping corporate data separate. Which Microsoft Entra device join type best fits this scenario?
A.Microsoft Entra joined
B.Microsoft Entra hybrid joined
C.Microsoft Entra registered
D.Domain joined only
Explanation: Microsoft Entra registered (formerly Azure AD registered) is designed for personal or BYOD scenarios. The user adds a work account to a personally owned device, gaining access to organizational resources without the device becoming corporate-owned. Conditional Access and Intune compliance/MAM can still be enforced.
2You need every new Windows 11 device that joins Microsoft Entra ID to automatically enroll in Microsoft Intune. Where do you configure this behavior?
A.Intune > Devices > Enrollment > Windows > Automatic Enrollment
B.Microsoft Entra admin center > Devices > Device settings
C.Intune > Endpoint security > Enrollment restrictions
D.Group Policy: Computer Configuration > Administrative Templates > Windows Components > MDM
Explanation: In the Microsoft Intune admin center, under Devices > Enrollment > Windows > Automatic Enrollment, you set the MDM user scope (None/Some/All) and MAM user scope. When MDM scope is set to All, Microsoft Entra joined Windows devices for licensed users automatically enroll in Intune at sign-in.
3Which Windows Autopilot deployment mode allows a shared device with no primary user, where each sign-in is treated like a new session?
A.User-driven mode
B.Self-deploying mode
C.Pre-provisioning (white glove)
D.Autopilot for existing devices
Explanation: Self-deploying mode is intended for kiosks, digital signage, or shared devices. The device joins Microsoft Entra ID with no user authentication during OOBE and enrolls in Intune without a primary user assignment. It requires a TPM 2.0 chip with attestation support.
4You import a hardware hash CSV into Intune > Devices > Enrollment > Windows > Devices but the device does not appear after 15 minutes. Which action should you take first?
A.Delete and re-import the CSV with a different group tag
B.Click Sync on the Windows Autopilot devices page
C.Reset the device with the Fresh Start remote action
D.Re-register the device in Microsoft Entra ID manually
Explanation: After importing a hardware hash, Intune queues the device for registration with the Autopilot Deployment Service. Clicking Sync on the Windows Autopilot devices blade forces Intune to refresh from the service so newly registered devices appear. Imports can take up to 15 minutes, but Sync confirms whether registration completed.
5What is the minimum Windows 11 edition that supports Microsoft Entra join and Intune MDM enrollment for an organization?
A.Windows 11 Home
B.Windows 11 Pro
C.Windows 11 Education
D.Windows 11 SE
Explanation: Microsoft Entra join and Intune MDM enrollment require at least Windows 11 Pro. Windows 11 Home only supports Microsoft Entra registered (BYOD) accounts and cannot be Entra joined, hybrid joined, or auto-enrolled into Intune.
6Which PowerShell cmdlet captures the hardware hash from a Windows device for Autopilot registration?
A.Get-AutopilotInfo
B.Get-WindowsAutopilotInfo
C.Export-AutopilotHash
D.Save-WindowsAutopilotInfo
Explanation: Get-WindowsAutopilotInfo (from the WindowsAutopilotIntune module on PowerShell Gallery) collects the hardware hash and serial number from a device and outputs a CSV that you can import into Intune. The script is commonly run with the -OutputFile parameter from an elevated PowerShell session.
7You want users to see deployment progress and block them from using the device until required apps and policies finish during Autopilot. Which Intune feature do you configure?
A.Enrollment Status Page (ESP)
B.Compliance policy with grace period
C.Conditional Access policy
D.Endpoint Privilege Management profile
Explanation: The Enrollment Status Page (ESP) shows installation progress during Autopilot OOBE and Account Setup phases. You can require selected apps to install before access is granted, set a timeout, and choose actions on failure such as allowing the user to continue or resetting the device.
8A compliance policy marks a Windows 11 device noncompliant when BitLocker is not enabled. Where in Intune do you set how soon after noncompliance the device is marked noncompliant rather than In grace period?
A.Compliance policy > Properties > Actions for noncompliance
B.Compliance policy > Compliance settings > Encryption
C.Tenant administration > Roles > Scope tags
D.Devices > Configuration profiles > Endpoint protection
Explanation: Inside a compliance policy, the Actions for noncompliance section lets you stage actions over time. The Mark device noncompliant action has a configurable schedule in days (0 means immediately). Setting it to a value greater than 0 creates a grace period before the device transitions from In grace period to Not compliant.
9Which Conditional Access grant control ensures only Intune-compliant devices can access Microsoft 365 resources?
A.Require multifactor authentication
B.Require device to be marked as compliant
C.Require approved client app
D.Require Hybrid Microsoft Entra joined device
Explanation: The Require device to be marked as compliant grant control verifies the compliance state surfaced from Intune to Microsoft Entra ID. Microsoft Entra ID reads the isCompliant attribute on the device object and blocks access for devices that are not compliant.
10You configure Windows Hello for Business for a cloud-only tenant with Microsoft Entra joined devices. Which trust model does Microsoft recommend for new deployments?
A.Key trust
B.Certificate trust
C.Cloud Kerberos trust
D.Hash-based trust
Explanation: For Microsoft Entra joined and hybrid joined devices that need to access on-premises resources or for cloud-only deployments, Microsoft recommends cloud Kerberos trust. It uses Microsoft Entra Kerberos to obtain a Kerberos TGT without needing a Windows Server PKI infrastructure.

About the MD-102 Exam

MD-102 is the single exam required for the Microsoft 365 Certified: Endpoint Administrator Associate certification. It validates skills in deploying, configuring, securing, and managing Windows endpoints and other client devices using Microsoft Intune, Microsoft Entra ID, Windows Autopilot, and Microsoft Defender for Endpoint.

Questions

50 scored questions

Time Limit

100 minutes

Passing Score

700 of 1000

Exam Fee

$165 USD (Microsoft (delivered via Pearson VUE))

MD-102 Exam Content Outline

25-30%

Prepare infrastructure for devices

Add devices to Microsoft Entra ID, enroll devices to Microsoft Intune (Windows automatic enrollment, Apple ADE, Android Enterprise), and implement identity and compliance including roles, Conditional Access for compliance, Windows Hello for Business, Windows LAPS, and local group membership.

30-35%

Manage and maintain devices

Deploy and upgrade Windows clients using Windows Autopilot, provisioning packages, and Windows 365; create configuration profiles for Windows, Android, iOS/iPadOS, macOS, and Windows 11 multi-session; implement Intune Suite add-ons (EPM, Enterprise App Catalog, Advanced Analytics, Remote Help, Cloud PKI, Tunnel for MAM); and perform remote actions including device queries with KQL.

15-20%

Manage applications

Prepare and deploy apps with Intune (Win32, MSIX, store, platform stores, Microsoft 365 Apps via ODT/OCT); configure Office app policies; and plan and implement app protection and app configuration policies for managed apps and managed devices, including Conditional Access for app protection.

15-20%

Protect devices

Configure endpoint security with antivirus, disk encryption (BitLocker), firewall, attack surface reduction, security baselines, and Microsoft Defender for Endpoint integration. Manage device updates with Intune update rings, feature update profiles, expedited updates, iOS/iPadOS and macOS update policies, Android FOTA, and Delivery Optimization.

How to Pass the MD-102 Exam

What You Need to Know

  • Passing score: 700 of 1000
  • Exam length: 50 questions
  • Time limit: 100 minutes
  • Exam fee: $165 USD

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

MD-102 Study Tips from Top Performers

1Build a free Microsoft 365 E5 trial tenant and Intune sandbox to practice Autopilot, configuration profiles, and compliance hands-on
2Memorize the four domain weights and which functional groups live in each, so you can budget exam time and focus revision
3Drill the difference between Microsoft Entra joined, hybrid joined, and registered, including which scenarios each one supports
4Practice every Autopilot deployment mode (user-driven, self-deploying, pre-provisioning, existing devices) with the Enrollment Status Page configured
5Learn the Intune RBAC built-in roles, scope tags, and filters so you can answer least-privilege and assignment-targeting scenarios

Frequently Asked Questions

What is the MD-102 exam format?

MD-102 is a proctored exam delivered online or at a Pearson VUE test center. Candidates have 100 minutes to answer roughly 40-60 items, including multiple choice, drag-and-drop, hot area, and interactive case-study questions. A scaled score of 700 of 1000 is required to pass.

What domains are on the MD-102 exam?

Microsoft's April 28, 2026 skills measured outline lists four functional groups: Prepare infrastructure for devices (25-30%), Manage and maintain devices (30-35%), Manage applications (15-20%), and Protect devices (15-20%).

How much does the MD-102 exam cost?

The MD-102 exam is $165 USD in the United States. Pricing varies by country and region. Optional Exam Replay vouchers bundle a second attempt at a discount.

What are the prerequisites for MD-102?

There is no required prerequisite exam. Microsoft expects candidates to have hands-on experience with Microsoft Entra ID, Microsoft Intune, Windows client deployment, and managing non-Windows devices. The recommended training path is Microsoft Learn or the MD-102T00 instructor-led course.

How should I study for MD-102?

Spend roughly one third of your time on Manage and maintain devices (the largest domain), one quarter on Prepare infrastructure for devices, and the remainder split between Manage applications and Protect devices. Practice in a real Microsoft 365 tenant with Intune trial licenses, build Autopilot, compliance, and Defender labs, and complete the Microsoft Learn practice assessment plus this question bank.

How do I keep my MD-102 certification active?

Microsoft associate certifications expire 12 months after issuance. You renew at no cost by passing the online MD-102 renewal assessment on Microsoft Learn within the 6-month renewal window.