🔥 40% Off Crucial Exams Memberships — This Week Only

6 hours, 45 minutes remaining!
00:20:00

Microsoft 365 Endpoint Administrator Associate Practice Test (MD-102)

Use the form below to configure your Microsoft 365 Endpoint Administrator Associate Practice Test (MD-102). The practice test can be configured to only include certain exam objectives and domains. You can choose between 5-100 questions and set a time limit.

Logo for Microsoft 365 Endpoint Administrator Associate MD-102
Questions
Number of questions in the practice test
Free users are limited to 20 questions, upgrade to unlimited
Seconds Per Question
Determines how long you have to finish the practice test
Exam Objectives
Which exam objectives should be included in the practice test

Microsoft 365 Endpoint Administrator Associate MD-102 Information

The Endpoint Administrator Associate Exam (MD-102)

The Microsoft 365 Endpoint Administrator Associate certification, obtained by passing the MD-102 exam, validates the skills required for deploying, configuring, protecting, managing, and monitoring devices and client applications in a Microsoft 365 environment. This certification has replaced the previous MD-100 and MD-101 exams, unifying the content into a single, comprehensive test that reflects the shift towards cloud-centric and hybrid endpoint management. The exam is intended for IT professionals, including system administrators and endpoint managers, who are responsible for managing identity, security, access, policies, updates, and apps for endpoints. Candidates should have subject matter expertise in Microsoft Intune, Windows 365, Windows Autopilot, Microsoft Defender for Endpoint, and Microsoft Entra ID.

The skills measured in the MD-102 exam are grouped into several key areas. A significant portion of the exam focuses on managing, maintaining, and protecting devices, which can account for 40-45% of the questions. Another major domain is the deployment of Windows clients, making up about 25-30% of the content. The remaining sections cover managing identity and compliance (15-20%) and managing applications (15-20%). This structure emphasizes the modern administrator's role in not just deploying operating systems but also ensuring that devices remain secure and compliant throughout their lifecycle using tools like Microsoft Intune.

The Value of Practice Exams for Success

To successfully pass the MD-102 exam, hands-on experience should be supplemented with thorough preparation, and practice exams are an invaluable tool in this process. Taking practice tests helps candidates assess their knowledge, identify areas of weakness, and become familiar with the format and types of questions they will encounter in the actual exam, which can include multiple-choice and scenario-based questions. These practice runs provide a realistic testing experience, allowing you to gauge your readiness and build confidence.

Many resources offer practice exams that cover all the domains of the official MD-102 syllabus and provide detailed explanations for both correct and incorrect answers. This feedback is crucial for understanding the underlying concepts and learning from mistakes. By simulating the exam environment, candidates can practice time management and reduce anxiety, which are key factors for success on exam day. Utilizing these tools allows you to focus your study efforts more effectively on the topics that require further attention, ultimately increasing your chances of earning the Microsoft 365 Certified: Endpoint Administrator Associate certification.

Microsoft 365 Endpoint Administrator Associate MD-102 Logo
  • Free Microsoft 365 Endpoint Administrator Associate MD-102 Practice Test

  • 20 Questions
  • Unlimited time
  • Prepare infrastructure for devices
    Manage and maintain devices
    Manage applications
    Protect devices
Question 1 of 20

Your company supports bring-your-own iOS and Android devices. You create an Intune app protection policy that encrypts corporate data in Outlook. You must ensure users can sign in to Exchange Online only when the Outlook instance on the device has the app protection policy applied. In the Conditional Access policy for Exchange Online, which grant control should you enable to meet the requirement?

  • Require app protection policy

  • Require approved client app

  • Require device to be marked as compliant

  • Require multi-factor authentication

Question 2 of 20

A Windows 11 laptop enrolled in Microsoft Intune is targeted by two update policies:

  • A Windows Update ring that defers feature updates for 90 days.
  • A Feature update policy that pins the device to Windows 11 version 22H2. The device is currently running Windows 11 version 21H2. What happens when both policies are applied to the laptop?
  • The laptop remains on Windows 11 version 21H2 until the 90-day deferral period ends, then upgrades.

  • Intune detects a conflict between the two policies and reports a policy error. No upgrade occurs.

  • The laptop upgrades to Windows 11 version 22H2 immediately, ignoring the 90-day deferral.

  • The laptop installs only quality updates and blocks all feature updates, including 22H2.

Question 3 of 20

You have imported a third-party ADMX/ADML pair into Microsoft Intune. The affected devices belong to an Azure AD group that contains both Windows 10 and Windows 11 computers. Only Windows 11 devices must receive the new settings, including future builds. What should you do next in Intune?

  • Create a Settings catalog profile, configure the imported settings, assign it to the Azure AD group, and include a filter where operatingSystemVersion ≥ 10.0.22000.

  • Use a Custom (OMA-URI) profile to upload the ADMX as an ADMXInstall policy and exclude Windows 10 devices in the assignment.

  • Move the Windows 11 devices into a separate dynamic Azure AD group and assign the imported settings to that group only.

  • Create a profile that uses the Imported Administrative Templates template and assign it without any additional filters.

Question 4 of 20

Your company is deploying new Windows 11 devices by using Windows Autopilot. You need every computer name to start with EMP- and end with a unique, randomly generated string that contains exactly five alphanumeric characters. The complete name must always stay within the 15-character NetBIOS limit. Which device name template should you configure in the Autopilot deployment profile?

  • EMP-%RAND:5%

  • EMP-%RAND%

  • EMP-%RAND:12%

  • EMP-%SERIAL%

Question 5 of 20

You manage Intune for an organization whose Windows 10 and 11 devices are Azure AD-joined and already enrolled. After purchasing Microsoft Defender for Endpoint (MDE), you finished service setup in the Microsoft 365 Defender portal. You must onboard all existing Windows devices to MDE with minimal administrative effort and without user interaction or local scripts. In Intune, what should you do next?

  • Enable Device Health Attestation policies and assign them to every Windows device.

  • Deploy a PowerShell script that runs the MDE onboarding command on each computer.

  • Package the Windows onboarding script as a Win32 application and deploy the app to all managed devices.

  • Enable the Microsoft Defender for Endpoint connector, then create and assign an Endpoint detection and response device configuration profile.

Question 6 of 20

Your company recently added the Microsoft Intune Suite add-on license and wants to streamline deployment of common third-party Windows desktop applications. You are asked to publish 7-Zip to managed devices without having to prepare a .intunewin package or manually configure detection rules. In the Intune admin center, you open Apps but are unsure which workflow provides the least administrative effort.

Which action should you perform first?

  • Select Apps > All apps > Add and choose App type: Microsoft Store app (new).

  • Select Apps > All apps > Add and choose App type: Windows app (Win32).

  • Select Apps > Catalog and choose Add app from catalog.

  • Select Apps > All apps > Add and choose App type: Line-of-business app.

Question 7 of 20

Your company has an Intune-managed tenant that includes Windows 11 Enterprise devices. You purchased Microsoft Defender for Endpoint P2 licenses and, in the Microsoft 365 Defender portal, turned on the Microsoft Intune connection. You need the devices to start reporting to Defender for Endpoint without running onboarding scripts. Which additional step must you perform?

  • Install the Microsoft Monitoring Agent on each device by using an Intune Win32 app.

  • Turn on automatic collection of diagnostic data in Windows telemetry settings.

  • Enable the Microsoft Defender for Endpoint connector in Intune under Tenant administration > Connectors and tokens.

  • Deploy the Microsoft Defender Antivirus security baseline to all Windows 11 devices.

Question 8 of 20

You are creating a Windows 10/11 update ring in Microsoft Intune for the Broad deployment group. The ring must meet these requirements:

  • Postpone installation of feature updates for 120 days after Microsoft releases them.
  • Download quality updates as soon as they are published, but force devices to finish installing those updates no later than three days after they become available.
  • Ensure that devices automatically restart outside active hours when the installation deadline is reached.

Which policy configuration meets all the requirements?

  • Feature update deferral period: 120 days; Quality update deferral period: 3 days; Deadline for quality updates: 0 days; Auto reboot before deadline: Disabled

  • Feature update deferral period: 0 days; Quality update deferral period: 120 days; Deadline for quality updates: 3 days; Auto reboot before deadline: Enabled

  • Feature update deferral period: 90 days; Quality update deferral period: 0 days; Deadline for quality updates: 7 days; Auto reboot before deadline: Disabled

  • Feature update deferral period: 120 days; Quality update deferral period: 0 days; Deadline for quality updates: 3 days; Auto reboot before deadline: Enabled

Question 9 of 20

You manage Windows 10 and Windows 11 devices that are enrolled in Microsoft Intune and onboarded to Microsoft Defender for Endpoint. A third-party antivirus product will be deployed to all devices, but you must still collect endpoint detection and response (EDR) telemetry through Microsoft Defender for Endpoint. You need to create an Endpoint security > Antivirus policy that meets the requirement and prevents two antivirus engines from running simultaneously. Which setting should you configure in the Intune policy?

  • Enable Windows Defender periodic scanning so it runs only when the third-party product is idle.

  • Enable Passive mode in the Microsoft Defender Antivirus policy.

  • Configure the "Turn off Microsoft Defender Antivirus" setting in the current security baseline.

  • Disable Real-time protection in the Microsoft Defender Antivirus policy.

Question 10 of 20

You are creating an Enrollment Status Page (ESP) profile for Windows Autopilot user-driven deployments. Support requires that users must be unable to reach the Windows desktop until every app and configuration profile that has been assigned to the user or the device as Required has completed installation. Which ESP setting should you configure to Yes to meet this requirement?

  • Show app and profile installation progress

  • Block device use until all apps and profiles are installed

  • Assign the ESP profile to the All Devices group

  • Allow users to reset the device if installation error occurs

Question 11 of 20

You manage Windows 11 devices that are enrolled in Microsoft Intune. Administrators sometimes disable Microsoft Defender Antivirus real-time protection while troubleshooting and then forget to turn it back on. You must create an Endpoint security Antivirus policy that blocks any local user, including administrators, from switching real-time protection off, while still keeping the feature enabled. Which policy setting should you configure, and how?

  • Disable user access to the Microsoft Defender Antivirus interface.

  • Enable the setting "Turn off real-time protection".

  • Enable the "Intrusion prevention system" option in the firewall policy.

  • Configure the setting "Allow users to pause real-time protection" and set it to Disabled.

Question 12 of 20

You are preparing 300 rugged laptops for warehouse workers. A technician in the staging facility must turn on each device once, allow all apps and policies to install, then reseal the device. When workers unbox the laptops, they should only sign in and immediately start using Windows. Which Windows Autopilot deployment mode meets the requirement?

  • Self-deploying mode

  • User-driven mode with Azure AD join

  • Pre-provisioned deployment

  • User-driven mode with Hybrid Azure AD join

Question 13 of 20

You administer a Microsoft Intune tenant that manages all Windows 10 21H2 devices. You need to onboard the devices into Microsoft Defender for Endpoint automatically and ensure any newly enrolled Windows devices are also onboarded. You have already turned on the Microsoft Defender for Endpoint connector in Intune. Which Intune policy should you deploy?

  • Deploy the Windows Defender for Endpoint onboarding package as a PowerShell script.

  • Create a settings catalog profile that enables the MDE-Management CSP.

  • Create and assign an Endpoint security - Endpoint detection and response profile.

  • Install the Microsoft Monitoring Agent (MMA) by deploying its MSI as a Win32 app.

Question 14 of 20

You are configuring Intune to deploy Microsoft 365 Apps during Windows Autopilot provisioning. After building the installation package with the Office Deployment Tool, you add the package as a Win32 app in Intune. You need the installation to run and be tracked during the device setup phase of the Enrollment Status Page so that the user reaches the desktop only after Microsoft 365 Apps is in place. Which configuration meets this requirement?

  • Configure Install behavior as User and assign the app as Required to the device group that contains the Autopilot devices.

  • Configure Install behavior as User and assign the app as Available to a user group.

  • Configure Install behavior as System and assign the app as Required to a device group that contains the Autopilot devices.

  • Configure Install behavior as System and assign the app as Available to a user group.

Question 15 of 20

Your company purchased 200 Android tablets that will be permanently mounted in meeting rooms to display a room-scheduling application. Users must be prevented from accessing system settings or adding personal Google accounts. You will enroll the tablets in Microsoft Intune by providing an enrollment token (for example, by scanning a QR code) during initial device setup after a factory reset. Which Android Enterprise enrollment profile should you configure to meet the requirements?

  • Android Enterprise dedicated device enrollment profile

  • Android Enterprise corporate-owned work profile enrollment profile

  • Android Enterprise fully managed device enrollment profile

  • Android Enterprise personally-owned work profile enrollment profile

Question 16 of 20

Your organization will deploy 300 new corporate-owned Android devices to be used as shared kiosks. You want the devices to enroll automatically in Microsoft Intune during the initial setup wizard without requiring technicians to interact with each handset. Which Intune enrollment approach should you implement to meet these requirements?

  • Android Enterprise fully managed enrollment by scanning a QR code generated in Intune during out-of-box setup

  • Apple Automated Device Enrollment (ADE) through Apple Business Manager

  • Android Enterprise dedicated device enrollment using a provisioning JSON assigned through the Google Zero-touch portal

  • Bulk enrollment with the Android device administrator profile and the Company Portal app

Question 17 of 20

You manage a Microsoft 365 tenant that uses Microsoft Intune to evaluate device compliance. You must create a Conditional Access policy that prevents users from accessing SharePoint Online when their device compliance state equals Not compliant but permits access without additional requirements when the state is Compliant. While configuring the policy's Grant controls, which single option should you enable to meet the requirement?

  • Require password change

  • Require device to be marked as compliant

  • Require multi-factor authentication

  • Require hybrid Azure AD joined device

Question 18 of 20

You deploy a Windows 10 feature updates policy to 500 laptops by using Microsoft Intune. Several devices fail to install the targeted feature update. You need to obtain a report that lists every affected device together with the specific Windows Update error code returned during installation so that you can begin troubleshooting. Which Intune report should you generate?

  • Windows 10 and later feature updates

  • Windows 10 and later quality update failures

  • Windows 10 and later feature update failures

  • Windows 10/11 update ring deployment status for the policy

Question 19 of 20

You are deploying Microsoft Tunnel for Mobile Application Management (MAM) to provide per-app VPN access for unmanaged Android and iOS devices. You have already created a Tunnel site in Intune and prepared an Ubuntu Server that will host the containerized Tunnel gateway. Before you can run the installation script on the Linux server and register it with Intune, which piece of information must you obtain from the Intune admin center and supply to the script so the server can join the correct site?

  • The IP address pool reserved for VPN clients

  • The site token that Intune generated for the Tunnel site

  • The public DNS name that devices will use to reach the Tunnel gateway

  • The custom DNS suffix to assign to internal resources

Question 20 of 20

You are creating a Windows 10 and later update ring in Microsoft Intune. The ring must install quality updates within two days of their release, but users should have an extra five days after that deadline before Windows automatically restarts to complete the installation. Which update ring setting should you configure to meet this requirement?

  • Display notifications to show a restart is required

  • Auto-install and restart at maintenance time

  • Quality update deferral period (days)

  • Grace period (days) for auto-restart