6.4 Final Seven-Day Review Plan and Mixed Scenario Priorities

Key Takeaways

  • Use the final week to review the current April 28, 2026 Microsoft skills outline, then drill weak objectives with mixed scenarios instead of rereading notes passively.
  • Protect devices is 15-20% of MD-102, but it blends with compliance, Conditional Access, app protection, Autopilot, remote actions, monitoring, and platform configuration.
  • Know current readiness facts: the certification page lists 100 minutes for MD-102, Microsoft scoring guidance says 700 or greater is required to pass, and the certification renews annually.
  • Mixed scenario questions usually reward the complete workflow: configure the device, evaluate the state, enforce access, monitor results, and remediate exceptions.
  • Spend the last day on official logistics, exam sandbox familiarity, missed-question review, and a compact decision matrix rather than new deep study.
Last updated: June 2026

Start from the current blueprint

Use the official Microsoft Learn study guide as your final source of truth. As of the current MD-102 study guide, the skills measured are effective April 28, 2026, and the four domains are Prepare infrastructure for devices, Manage and maintain devices, Manage applications, and Protect devices. Protect devices is listed at 15-20%. Confirm the page's own Last Updated date before exam day, because Microsoft can refresh objectives, and a fresh check is the cheapest way to avoid studying retired content.

Current readiness facts

FactCurrent study action
Skills measured effective April 28, 2026Review the current outline, not old MD-100/MD-101 or pre-refresh notes
Protect devices weight: 15-20%Give it focused review time, but practice it in mixed scenarios with compliance, Conditional Access, and monitoring
Exam duration: 100 minutesPractice pacing and do not over-invest in one long scenario
Passing score: 700 or greater on Microsoft's scaled modelAim for consistent margin on practice sets, not one barely passing run
Practice assessment and exam sandbox are available from Microsoft LearnUse them to check wording style and interface familiarity before exam day
Renewal frequency: 12 months for the certificationUnderstand that Microsoft expects current skills, not static memorization

Official anchors:

Seven-day plan

DayFocusDeliverable
Day 7Blueprint mapMark every official objective green, yellow, or red; Protect devices objectives should include security policies, Defender onboarding, and updates
Day 6Endpoint security policiesBuild a one-page matrix for antivirus, disk encryption, firewall, ASR, EDR, account protection, and baselines
Day 5Defender for Endpoint integrationPractice the full connector -> onboarding -> risk compliance -> Conditional Access chain
Day 4UpdatesDrill update rings vs feature updates vs expedited quality updates vs Delivery Optimization, then add Apple and Android controls
Day 3Mixed workflowsCombine compliance, Conditional Access, app protection, Defender risk, BitLocker, remote actions, and monitoring in one scenario set
Day 2Timed practiceRun a timed mixed set, tag every miss by objective, and redo only missed concepts after a break
Day 1Final readinessReview official logistics, exam sandbox, the policy decision matrix, and your top 20 missed-question lessons

Mixed scenario priorities

MD-102 rarely tests a single isolated button. A realistic item may say that finance users have managed Windows laptops, Microsoft 365 access must be blocked when devices are high risk, BitLocker must stay enabled, monthly updates must be staged to pilot and production, and the security team needs visibility into failures. That one scenario touches Defender for Endpoint, compliance, Conditional Access, disk encryption, update rings, reports, and remediation. The candidate who can decompose the requirement into discrete controls will beat the candidate who memorized portal paths.

Use this five-part checklist when answer choices look similar:

  1. Configure the device with the right policy family.
  2. Evaluate state with compliance, Defender risk, or reporting.
  3. Enforce access with Conditional Access when resource access is part of the requirement.
  4. Monitor assignment, per-setting status, update state, risk, and failures.
  5. Remediate with targeted actions such as BitLocker key rotation, security tasks, device isolation, expedited updates, or policy correction.

Last-week decision matrix

If the stem says...Think first
"Require compliant device for Microsoft 365"Intune compliance policy plus Conditional Access
"High Defender risk should block access"Defender connector, onboarding, risk-based compliance, Conditional Access
"Deploy Microsoft-recommended settings quickly"Security baseline, then tune exceptions and conflicts
"Configure BitLocker"Endpoint security disk encryption
"Configure firewall profiles or firewall rules"Endpoint security firewall
"Block malicious macro and exploit behaviors"Attack surface reduction rules
"Control regular Windows update timing and restarts"Update rings
"Hold devices at a Windows release"Feature update policy
"Patch a critical vulnerability immediately"Expedited quality update policy
"Reduce WAN impact of updates"Delivery Optimization
"Show update failures or readiness"Update reports and device-level monitoring
"Protect Outlook data on personal phones without enrollment"App protection policy and MAM without enrollment

What not to do in the final week

Do not memorize portal paths without understanding the policy intent. Do not assume every security requirement is a baseline. Do not treat a successful assignment as proof that a device is actually secure or updated; verify with reports. Do not ignore non-Windows devices; Apple and Android update management and protection appear in the current Protect devices objective list. Above all, practice mixed, timed scenarios so that on exam day you recognize the underlying decision quickly within the 100-minute limit.

Pacing and question-type strategy

With roughly 100 minutes, budget your time deliberately. Microsoft does not promise a fixed question count, but role-based exams typically include 40 to 60 items with a mix of single-answer multiple choice, multiple-response (select all that apply), drag-and-drop ordering, hot-area, build-list, and occasionally a case study with several linked questions. If a case study appears, read its requirements once, answer the questions, and move on; do not let one case consume a disproportionate share of your time.

Multiple-response items have no partial credit, so confirm every selected option independently rather than stopping at the first correct choice.

Use the review-flag feature. On a long scenario where two answers look close, eliminate options that violate a hard constraint (wrong platform, wrong ownership, wrong management state, or a control that reads state instead of configuring it), pick the best remaining answer, flag it, and return if time allows. Do not leave items blank; there is no penalty for a wrong answer, so an educated guess is always better than an omission.

Common close-call traps to rehearse

Finally, rehearse the trap pairs that separate close answers. Compliance policy versus configuration profile: compliance reports state while configuration sets state. App protection versus device compliance: app protection guards corporate data inside an app, while compliance evaluates the whole device. Update rings versus feature update policy: rings control timing and restarts, feature policies control the target version. Retire versus Wipe: Retire removes only company data, Wipe is a full reset.

Enrollment restriction versus compliance: restrictions block enrollment before it happens, compliance evaluates devices after. Walking into the exam with these contrasts automatic is worth more than memorizing one more portal blade.

Test Your Knowledge
Ordering

Order the best workflow for using Defender for Endpoint risk to block access to Microsoft 365 resources.

Arrange the items in the correct order

1
Create an Intune compliance policy that evaluates Defender device risk.
2
Onboard devices to Defender for Endpoint.
3
Create a Conditional Access policy that requires compliant devices.
4
Enable the Intune and Defender for Endpoint service connection.
Test Your Knowledge
Multi-Select

Which activities are high-value during the final seven days before MD-102? Select all that apply.

Select all that apply

Compare your notes to the current Microsoft skills outline effective April 28, 2026.
Practice mixed scenarios that combine protection, compliance, Conditional Access, updates, and monitoring.
Use the Microsoft exam sandbox or practice assessment to reduce interface and wording surprises.
Ignore Protect devices because it is not the largest domain.
Test Your Knowledge

A scenario asks you to stage monthly Windows updates to pilot and production groups, control restart deadlines, and then review deployment failures. Which answer pattern is strongest?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams