Audience Profile and Endpoint Admin Mental Model

Key Takeaways

  • The MD-102 candidate manages devices and client applications in a Microsoft 365 tenant by using Microsoft Intune.
  • The role spans efficient endpoint deployment, management at scale, identity, security, access, policies, updates, and apps across Windows and non-Windows platforms.
  • Microsoft expects experience with Microsoft Entra ID, Microsoft 365 technologies, Intune, Windows client, and non-Windows devices.
  • Strong MD-102 answers usually start by identifying ownership, join state, enrollment path, target group, compliance requirement, and risk level.
  • Endpoint administrators collaborate with architects, Microsoft 365 administrators, security administrators, and other workload administrators.
Last updated: June 2026

Who Microsoft Is Testing

The official audience profile describes a candidate with subject matter expertise managing devices and client applications in a Microsoft 365 tenant by using Microsoft Intune. That language is deliberate. MD-102 is not just a Windows support exam and not just a theory exam about cloud management. It is a role-based exam for administrators who turn business requirements into endpoint policies, deployments, controls, and operations across multiple platforms.

Microsoft calls out tools and services that commonly appear together in real environments: Microsoft Intune, Microsoft Intune Suite, Windows Autopilot, Microsoft Security Copilot, Microsoft Defender for Endpoint, Microsoft Entra ID, Azure Virtual Desktop, and Windows 365. You do not need to be a deep specialist in every adjacent product, but you must understand why each one appears in endpoint scenarios and where the endpoint administrator's responsibility begins and ends.

Exam role phraseWhat it means in practiceScenario clue
Efficient deploymentChoose the provisioning or enrollment path that fits ownership and locationNew remote laptops, kiosk devices, shared devices, bring-your-own devices
Management at scaleUse groups, filters, profiles, assignments, and reporting instead of manual device workThousands of devices, phased rollout, different platforms
Identity and accessTie device state to Microsoft Entra ID and Conditional AccessRequire compliant device, join type, Windows Hello for Business
Policies and updatesConfigure settings, security baselines, update rings, and platform-specific update policiesStandardize Windows, macOS, iOS, Android, or multi-session devices
AppsDeploy, configure, update, and protect client applicationsMicrosoft 365 Apps, app stores, app protection, app configuration
Security operationsIntegrate endpoint security with Defender and respond to riskAntivirus, encryption, firewall, attack surface reduction, onboarding

The Endpoint Admin Mental Model

When you read an MD-102 question, first decide what kind of endpoint problem is being described. Most scenarios can be broken into six decisions:

  1. Identity state: Is the device Microsoft Entra joined, Microsoft Entra registered, Microsoft Entra hybrid joined, or not yet enrolled?
  2. Ownership and platform: Is it corporate-owned, personally owned, shared, kiosk, Windows, macOS, iOS/iPadOS, Android, Windows 365, or Azure Virtual Desktop?
  3. Enrollment and provisioning path: Does the scenario call for Windows Autopilot, automatic enrollment, bulk enrollment, Android Enterprise, Apple Automated Device Enrollment, or provisioning packages?
  4. Targeting model: Should the policy use users, devices, groups, filters, dynamic membership, or a staged assignment?
  5. Control objective: Is the requirement about compliance, configuration, app deployment, app protection, endpoint security, updates, or a remote action?
  6. Evidence and remediation: What report, device action, KQL device query, or policy status would prove the configuration is working?

This model prevents the most common exam mistakes. A question about unmanaged personal phones and corporate data is often an app protection problem (managed-app data boundary), not a full device-compliance problem. A question about a brand-new remote Windows laptop is often a Windows Autopilot and enrollment decision, not an image-deployment decision. A question about requiring healthy devices for access is usually both an Intune compliance policy (the signal) and a Microsoft Entra Conditional Access design (the gate). Training yourself to ask which layer the scenario lives in is worth more than memorizing every setting name.

Worked Example

A scenario reads: "Field technicians use shared Android tablets that run only a dispatch app; no personal use is allowed and no single user signs in." Walk the model: ownership is corporate, platform is Android, there is no primary user, and use is locked to one app. That maps to an Android Enterprise dedicated device enrollment with a kiosk configuration profile and a managed app set, not a personally owned work profile and not iOS Automated Device Enrollment. The mental model led straight to the answer before you considered any individual setting.

Collaboration and Role Boundaries

The audience profile says the endpoint administrator collaborates with architects, Microsoft 365 administrators, security administrators, and other workload administrators. On the exam, that translates into boundary awareness. You may choose or implement endpoint controls, but the scenario may also depend on tenant identity design, security operations, application ownership, network access, or licensing. A good answer fits the endpoint role without pretending Intune alone solves every Microsoft 365 governance problem.

When a question offers a tempting "do everything from Intune" option that ignores a needed Conditional Access policy, license, or Defender integration, it is usually a distractor. The strongest candidates pick the action that is correct for the endpoint role and recognize when a partner team or another service must also be involved.

The Experience Microsoft Assumes

The audience profile closes by stating that you must have experience with Microsoft Entra ID and Microsoft 365 technologies, including Intune, plus strong skills deploying, configuring, and maintaining Windows client and non-Windows devices. Read that as a warning: MD-102 is not a beginner cloud exam. Questions assume you already know what a security group is, how Conditional Access grant controls work, and what an enrollment profile does. If those concepts are new, build the foundation first; otherwise the scenario wording will hide too many cues.

Non-Windows coverage is real and frequently underestimated. Expect Apple Automated Device Enrollment, Android Enterprise enrollment modes, macOS configuration through the Settings catalog, and platform-specific compliance and update policies. Candidates who study only Windows leave 15 to 25 percent of the blueprint to chance.

Turn Requirements Into Actions

A reliable habit is to restate every scenario as a one-line requirement before reading the options: "protect corporate data on unmanaged phones," "ship Windows laptops to remote staff with a guided setup," or "block access from non-compliant devices." Once the requirement is explicit, the mental model points to the layer, the layer points to the tool, and the tool points to the correct option. This discipline is what separates a confident pass from a coin-flip on the harder, multi-constraint questions.

Test Your Knowledge
Matching

Match each MD-102 scenario clue to the best endpoint administrator concern.

Match each item on the left with the correct item on the right

1
New remote Windows devices shipped directly to employees
2
Access to Exchange Online requires healthy corporate devices
3
Users need corporate data protected in mobile apps on personal phones
4
Security team wants endpoint risk signals and onboarding
Test Your Knowledge

A scenario says users bring personal iOS and Android devices, but the company does not want to fully enroll those devices. The requirement is to prevent corporate data from being copied to unmanaged apps. Which mental-model decision should come first?

A
B
C
D