Microsoft MD-102 Practice Exam Questions & Answers

5 Free Questions · Last reviewed: September 18, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

Microsoft MD-102 Exam Details

Key details for this exam, checked against the published exam outline

417 Practice Questions (Our Bank)
100 minutes Exam Duration
700 out of 1000 Passing Score
USD 165 Exam Fee
Exam Code
MD-102
Full Name
Microsoft 365 Certified: Endpoint Administrator Associate
Issuing Body
Microsoft
Question Format (Our Bank)
Multiple Choice, Hotspot, Drag & Drop, Order List, Case Studies
Delivery
Online proctored via Pearson VUE OnVUE or at a Pearson VUE test centre
Eligibility
Experience with Microsoft Entra ID and Microsoft 365 technologies including Intune, plus hands-on experience deploying, configuring, and maintaining Windows client and non-Windows devices
Practice Questions

Free MD-102 Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our MD-102 exam preparation team, who also write the explanation shown with each one. How we research and review these pages

You have a Microsoft 365 E5 subscription.

You need to create a dynamic device group that will contain any device that has the word Marketing in its name. Which device membership rule should you use?

Correct Answer: D
Explanation

To create a dynamic device group with devices containing 'Marketing' in their name, you should use the device membership rule: (device.displayName -contains 'Marketing'). This rule uses the -contains operator to match any device where the displayName attribute contains the word 'Marketing'. Alternative syntax that works includes (device.displayName -match '.*Marketing.*') using regex pattern matching. The rule must target the displayName attribute and use case-insensitive matching.

You use Microsoft Defender for Endpoint to protect computers that run Windows 10.

You need to assess the differences between the configuration of Microsoft Defender for Endpoint and the Microsoft-recommended configuration baseline.

Which tool should you use?

Correct Answer: B
Explanation

To assess the differences between your current Microsoft Defender for Endpoint configuration and the Microsoft-recommended configuration baseline, you should use the Defender for Endpoint Configuration Manager (also known as the Configuration Assessment tool or Defender for Endpoint baseline comparison tool).

This tool allows you to compare your existing Defender for Endpoint settings against Microsoft's recommended security baselines. It provides a detailed analysis of configuration gaps and helps identify areas where your configuration deviates from best practices and security recommendations for protecting Windows 10 computers.

Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.

When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.

You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.

Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for Business enrollment options.

Does this meet the goal?

Correct Answer: B

You have following types of devices enrolled in Microsoft Intune:

* Windows 10

* Android

* iOS

For which types of devices can you create VPN profiles in Microsoft Intune admin center?

Correct Answer: E
Explanation

In Microsoft Intune admin center, VPN profiles can be created for: Windows 10, Android, and iOS devices. Intune supports creating and deploying VPN profiles to all three device types listed. Each platform supports different VPN connection types (IKEv2, L2TP, PPTP, etc.), but all three device types can have VPN profiles assigned to them. The answer depends on whether the question is asking which device types CAN have VPN profiles (answer: all three - Windows 10, Android, iOS), or if it's asking about specific VPN protocols supported by each type. Assuming the question asks which types support VPN profiles in general, the answer is all three: Windows 10, Android, and iOS.

You have a Hyper-V host that contains the virtual machines shown in the following table.

On which virtual machines can you install Windows 11?

Correct Answer: E
Explanation

This question references a table of virtual machines that is not provided in the question text. To properly answer which virtual machines can run Windows 11, you would need to review the specifications shown in that table, including processor architecture (Generation 2 VMs are required), RAM, storage, and other hardware requirements. Windows 11 requires specific hardware features such as TPM 2.0, UEFI firmware, Secure Boot capability, and a compatible processor (typically 8th generation Intel or 2nd generation AMD Ryzen or newer). The answer would depend on the specific configuration of each virtual machine listed in the table.

Get Full Access

417 questions covering all exam domains, starting from $20

Study Guide

What the Microsoft MD-102 Exam Covers

Exam domains verified against: Official Microsoft MD-102 exam guide, last checked September 2026.

Domain 1: Prepare infrastructure for devices 25% - 30%

This domain covers adding devices to Microsoft Entra ID and enrolling them to Microsoft Intune. You need to understand device registration, enrollment methods, and initial configuration for hybrid and cloud-native management scenarios. Hands-on experience with Windows Autopilot and enrollment policies is essential.

Sample questions from this domain above: Q2Q3

Domain 2: Manage and maintain devices 30% - 35%

This is the largest domain and focuses on deploying and upgrading Windows clients via cloud-based tools, designing device configuration profiles, and implementing Intune Suite capabilities. You will also need to perform remote actions on managed devices such as troubleshooting and retirement. Proficiency with Intune configuration at depth is critical here.

Sample questions from this domain above: Q1Q5

Domain 3: Manage applications 15% - 20%

This domain requires you to deploy and update applications across managed endpoints and implement app protection and app configuration policies. You need to understand application packaging, distribution methods through Intune, and how to enforce security and compliance policies for apps.

Domain 4: Protect devices 15% - 20%

This domain covers configuring endpoint security including antivirus, encryption, and firewall settings via Intune policies. You also need to manage device updates and understand compliance monitoring. Knowledge of Microsoft Defender for Endpoint integration and security baselines is important.

Sample question from this domain above: Q4

FAQ

MD-102 Exam FAQ

Common questions about the exam itself

What background do I need before attempting MD-102?
You need hands-on experience with Microsoft Entra ID, Microsoft 365, and Microsoft Intune. Practical experience deploying and configuring Windows 10 or 11 clients is essential. Many candidates without real lab experience in Intune struggle significantly, so setting up a free Microsoft 365 developer tenant and spending 20 to 30 hours on configuration exercises before the exam is strongly recommended.
Why is domain 2, Manage and maintain devices, considered the hardest part?
This domain covers about 30 to 35 percent of the exam and tests Intune configuration in significant depth. The exam assumes you can configure complex policies, troubleshoot device issues, and understand the interactions between different Intune features. Without hands-on experience, the level of detail required makes this section challenging.
How long does MD-102 certification stay valid?
Your MD-102 certification expires one year from the date you pass. You renew it free of charge by passing an online assessment on Microsoft Learn focused on current topics in the exam domains. You do not need to retake the full paid exam to renew.
How long should I spend preparing for MD-102?
Most candidates with hands-on Intune or modern device management experience need 6 to 10 weeks of structured study. If you have no lab experience, add extra time for setting up a dev tenant and running practical exercises. People trying to pass it without any practical Intune work consistently report higher failure rates.
What happens on exam day for MD-102?
You have 100 minutes to complete the exam, which contains multiple question types including multiple choice, drag and drop, scenario-based questions, and interactive simulations. The exam is proctored either online through Pearson VUE or at a physical test centre, with a proctor monitoring you throughout.
What if I fail MD-102? Can I retake it quickly?
Yes, you can retake the exam as soon as 24 hours after your first attempt. There is no waiting period mandated by Microsoft, though you do pay the full exam fee each time you sit it. Many people pass on a second or third attempt after focused study on their weak areas.
Does MD-102 require any prerequisite certifications?
No specific prior certifications are required. However, Microsoft strongly recommends hands-on experience with Microsoft Entra ID and Intune before attempting the exam. Some people complete the Azure Administrator (AZ-104) or Administrator (MS-102) certifications first to build foundational cloud knowledge.
How does MD-102 relate to MS-102?
MD-102 focuses on endpoint and device management using Intune, Windows Autopilot, and modern deployment tools. MS-102 focuses on broader Microsoft 365 tenant administration covering Exchange Online, Teams, SharePoint, and compliance. Many enterprise IT administrators hold both certifications since they cover complementary skill sets.
What job role does MD-102 prepare me for?
MD-102 certifies you as an Endpoint Administrator, also called a desktop administrator or modern workplace engineer. These professionals manage, deploy, and secure Windows and other devices at scale in corporate environments using cloud-based management tools. The role sits at the associate level and is a foundation for moving into endpoint management specialist or enterprise administrator positions.
How does MD-102 differ from the older MD-100 and MD-101 exams?
MD-102 replaced the older MD-100 and MD-101 exams. It is entirely focused on modern cloud-based management via Microsoft Intune and Entra ID rather than on-premises System Center Configuration Manager (SCCM). If you have SCCM experience from legacy exams, you will need to retrain on Intune-based approaches for MD-102.