dc dotCreds
Microsoft 365 Endpoint Administrator

MD-102 Practice Test

Start today’s free 10-question MD-102 set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 12, 2026, 3:38 PM CDT

Go Pro - One Time Unlock

Unlock the full MD-102 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 MD-102 questions

Use this MD-102 practice test to review Microsoft 365 Endpoint Administrator. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Implement Windows deployment and provisioning Manage and maintain devices

New laptops will ship directly from the vendor to remote employees. Each employee should sign in with their organizational account and complete an assigned, user-associated Windows Autopilot deployment without technician staging. Which mode should the administrator select?

Concept tested:
Question 2 of 10
Objective Manage devices by using Intune Suite capabilities Manage and maintain devices

During a Remote Help session, an analyst sees a noncompliance warning and discovers that encryption policy failed. The analyst expects ending the support session to mark the device compliant. What should happen?

Concept tested:
Question 3 of 10
Objective Automate endpoint management by using PowerShell and Microsoft Graph Optimize endpoint operations by using automation, monitoring, and reporting

A PowerShell inventory script calls Microsoft Graph with an application secret copied into the source file. The repository is shared with several administrators. What should replace this design?

Concept tested:
Question 4 of 10
Objective Implement identity and compliance controls Prepare infrastructure for devices

A user believes a Windows Hello for Business PIN can be reused from another computer like a domain password. Which explanation correctly addresses the concern?

Concept tested:
Question 5 of 10
Objective Manage operating system updates Protect devices

An application team needs devices held on a specified Windows release, a network team wants peer content delivery, and operations must investigate safeguard holds separately from installation errors. Which design assigns each requirement correctly?

Concept tested:
Question 6 of 10
Objective Deploy and update applications Manage and secure applications

A required Win32 app is never attempted on a group of laptops. Reporting shows the app is Not applicable because its requirement rule excludes the installed Windows version. The team proposes changing detection. What should it do?

Concept tested:
Question 7 of 10
Objective Monitor and improve endpoint operations Optimize endpoint operations by using automation, monitoring, and reporting

Endpoint analytics reports poor application reliability, but only three newly enrolled devices have supplied data. A manager concludes that the score proves a faulty application across the entire company. What should the administrator do?

Concept tested:
Question 8 of 10
Objective Add devices to Microsoft Entra ID Prepare infrastructure for devices

New organization-owned devices should automatically enter a deployment group when their supported device attributes meet the company rule. Membership must update without weekly manual changes. What should the administrator use?

Concept tested:
Question 9 of 10
Objective Implement endpoint security policies and Defender integration Protect devices

A security team must deploy new antivirus and firewall settings this week. The current Microsoft security baseline also changes unrelated authentication settings and has not been tested with a legacy application. What should the administrator do?

Concept tested:
Question 10 of 10
Objective Implement app protection and app configuration policies Manage and secure applications

A managed-app configuration policy sends a supported server URL to an unenrolled mobile app. IT also needs to block copying corporate content to personal apps, but the current policy does not do so. What is missing?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
MD-102 Pro $4.99 one-time

Best if you only need this one certification.

50 Exam Practice Test $1.99 one-time

A 50-question MD-102 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full MD-102 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily MD-102 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily MD-102 set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 New laptops will ship directly from the vendor to remote employees. Each employee should sign in with their organizational account and complete an assigned, user-associated Windows Autopilot deployment without technician staging. Which mode should the administrator select?

Answer choices

  1. A. Self-deploying mode, for the required business outcome.
  2. B. User-driven deployment, under the documented operational and governance requirements.
  3. C. Pre-provisioned deployment, as the proposed design for the complete governed operational workflow.
  4. D. Microsoft Entra registration without Autopilot, for the specified implementation requirement.

Correct answer

User-driven deployment, under the documented operational and governance requirements.

User-driven Autopilot is intended for user-associated devices and lets the assigned employee complete provisioning. Pre-provisioning adds a technician stage, while self-deploying mode targets shared or kiosk scenarios without user credentials.

Wrong-answer review

  • A. Self-deploying mode, for the required business outcome.: Self-deploying mode is designed for supported shared or kiosk devices rather than an assigned employee’s laptop.
  • C. Pre-provisioned deployment, as the proposed design for the complete governed operational workflow.: Pre-provisioned deployment includes a technician or partner phase that the direct-to-employee requirement explicitly excludes.
  • D. Microsoft Entra registration without Autopilot, for the specified implementation requirement.: Registration alone cannot provide the requested corporate Windows Autopilot deployment profile and provisioning experience.

Extra learning features

Why candidates miss this

The distractor ‘Pre-provisioned deployment’ is tempting because it seems to align with the direct-to-employee shipment. The decisive clue that eliminates it is the explicit requirement for user-associated provisioning and the absence of a technician staging phase. Likely wrong answer: Pre-provisioned deployment Review focus: Windows Autopilot overview

Objective/domain: Manage and maintain devices

Source: Windows Autopilot overview

Question 2 During a Remote Help session, an analyst sees a noncompliance warning and discovers that encryption policy failed. The analyst expects ending the support session to mark the device compliant. What should happen?

Answer choices

  1. A. Grant the analyst tenant-wide administration so Remote Help can override compliance, for the described technical objective and its associated operational control requirements, as selected.
  2. B. Use the session to assist and gather evidence, then correct the encryption condition through the appropriate management control and allow compliance reevaluation, within the described context.
  3. C. Suppress the warning because support sessions make compliance unnecessary, for the described technical objective and its associated operational control requirements, in context.
  4. D. Convert every attended session to unattended access so policy failures repair automatically, for the described technical objective and its associated operational control requirements.

Correct answer

Use the session to assist and gather evidence, then correct the encryption condition through the appropriate management control and allow compliance reevaluation, within the described context.

Objective/domain: Manage and maintain devices

Source: Remote Help for Microsoft Intune

Question 3 A PowerShell inventory script calls Microsoft Graph with an application secret copied into the source file. The repository is shared with several administrators. What should replace this design?

Answer choices

  1. A. A longer secret committed to the same repository, for the described technical objective and its associated operational control requirements, in context.
  2. B. A supported protected authentication method for a least-privileged Graph identity, with consent and credential lifecycle governed outside the script, for the stated implementation and support requirements.
  3. C. A local device administrator account because local privilege authorizes Graph, for the described technical objective and its associated operational control requirements, for evaluation.
  4. D. Anonymous Graph access because the script reads inventory, for the described technical objective and its associated operational control requirements, within the described operational context.

Correct answer

A supported protected authentication method for a least-privileged Graph identity, with consent and credential lifecycle governed outside the script, for the stated implementation and support requirements.

Objective/domain: Optimize endpoint operations by using automation, monitoring, and reporting

Source: Microsoft Graph and Intune

Question 4 A user believes a Windows Hello for Business PIN can be reused from another computer like a domain password. Which explanation correctly addresses the concern?

Answer choices

  1. A. The PIN is synchronized as a reusable password to every joined device, as the recommended implementation across the complete governed service lifecycle.
  2. B. The PIN is only a shorter representation of the user's domain password, as the primary implementation for the described business requirement.
  3. C. The PIN is a local gesture that unlocks a device-bound key or certificate, so it is not a reusable domain password, within the described operational context.
  4. D. The PIN provides single-factor authentication because possession of the device is irrelevant, as the selected approach for the stated technical and business outcome, within the described context.

Correct answer

The PIN is a local gesture that unlocks a device-bound key or certificate, so it is not a reusable domain password, within the described operational context.

Objective/domain: Prepare infrastructure for devices

Source: Windows Hello for Business

Question 5 An application team needs devices held on a specified Windows release, a network team wants peer content delivery, and operations must investigate safeguard holds separately from installation errors. Which design assigns each requirement correctly?

Answer choices

  1. A. Use a permanent ring pause for release targeting, approval, and reporting, as the primary implementation for the described business requirement.
  2. B. Use a feature update policy for release targeting, Delivery Optimization for content delivery, and update reports for deployment-state analysis, in practice.
  3. C. Use Delivery Optimization to approve the release and remove safeguard holds, for the described technical objective and its associated operational control requirements.
  4. D. Use feature targeting as a replacement for quality updates and status reporting, for the described technical objective and its associated operational control requirements.

Correct answer

Use a feature update policy for release targeting, Delivery Optimization for content delivery, and update reports for deployment-state analysis, in practice.

Objective/domain: Protect devices

Source: Windows update settings for Intune

Question 6 A required Win32 app is never attempted on a group of laptops. Reporting shows the app is Not applicable because its requirement rule excludes the installed Windows version. The team proposes changing detection. What should it do?

Answer choices

  1. A. Add the app as its own dependency, for the described technical objective and its associated operational control requirements, for the specified implementation requirement.
  2. B. Configure supersedence to uninstall an unrelated application, for the described technical objective and its associated operational control requirements, as configured.
  3. C. Correct the requirement rule if the Windows version should be eligible, then reevaluate applicability before troubleshooting installation or detection, within the stated policy framework.
  4. D. Change detection because detection decides whether an ineligible device may attempt installation, for the described technical objective and its associated operational control requirements, as proposed.

Correct answer

Correct the requirement rule if the Windows version should be eligible, then reevaluate applicability before troubleshooting installation or detection, within the stated policy framework.

Objective/domain: Manage and secure applications

Source: Win32 app management in Microsoft Intune

Question 7 Endpoint analytics reports poor application reliability, but only three newly enrolled devices have supplied data. A manager concludes that the score proves a faulty application across the entire company. What should the administrator do?

Answer choices

  1. A. Uninstall the application from every managed device immediately, under the stated technical, operational, and governance constraints.
  2. B. Treat the selected analytics baseline as an automatic root-cause diagnosis, under the stated technical, operational, and governance constraints.
  3. C. Replace the application-reliability report with startup-performance data, for the described technical objective and its associated operational control requirements, when applied.
  4. D. Obtain sufficient reporting data and inspect affected-device evidence before generalizing the insight or selecting remediation

Correct answer

Obtain sufficient reporting data and inspect affected-device evidence before generalizing the insight or selecting remediation

Objective/domain: Optimize endpoint operations by using automation, monitoring, and reporting

Source: Endpoint analytics overview

Question 8 New organization-owned devices should automatically enter a deployment group when their supported device attributes meet the company rule. Membership must update without weekly manual changes. What should the administrator use?

Answer choices

  1. A. A dynamic device group based on the supported device attributes, while verifying enrollment and compliance separately, as the proposed prepare infrastructure for devices approach.
  2. B. A static group maintained from a spreadsheet, as the recommended implementation across the complete governed service lifecycle.
  3. C. A compliance policy that doubles as dynamic group membership logic, under the described prepare infrastructure for devices criteria.
  4. D. Microsoft Entra registration because every registered device is automatically organization-owned, as the primary implementation for the described business requirement.

Correct answer

A dynamic device group based on the supported device attributes, while verifying enrollment and compliance separately, as the proposed prepare infrastructure for devices approach.

Objective/domain: Prepare infrastructure for devices

Source: Microsoft Entra device identities overview

Question 9 A security team must deploy new antivirus and firewall settings this week. The current Microsoft security baseline also changes unrelated authentication settings and has not been tested with a legacy application. What should the administrator do?

Answer choices

  1. A. Deploy the complete untested baseline because it contains the requested settings, as the selected approach for the stated technical and business outcome.
  2. B. Create a compliance policy and expect it to configure antivirus and firewall settings, as the selected response to the described condition.
  3. C. Deploy focused Intune endpoint security policies for antivirus and firewall, and evaluate the broader baseline separately in a pilot, within the described context.
  4. D. Delay all endpoint protection changes until every baseline setting is accepted, for the described technical objective and its associated operational control requirements, for this task.

Correct answer

Deploy focused Intune endpoint security policies for antivirus and firewall, and evaluate the broader baseline separately in a pilot, within the described context.

Objective/domain: Protect devices

Source: Manage endpoint security in Microsoft Intune

Question 10 A managed-app configuration policy sends a supported server URL to an unenrolled mobile app. IT also needs to block copying corporate content to personal apps, but the current policy does not do so. What is missing?

Answer choices

  1. A. A managed-device configuration profile for an unsupported key, for the stated requirement.
  2. B. An app protection policy that enforces the organizational-data transfer restriction, within this design.
  3. C. A second copy of the same app configuration key, under the organization’s defined implementation and exception-management process.
  4. D. Full device enrollment solely because managed-app configuration cannot work without it, for this requirement.

Correct answer

An app protection policy that enforces the organizational-data transfer restriction, within this design.

Objective/domain: Manage and secure applications

Source: App configuration policies overview

Where to go after the daily web set

How are MD-102 questions generated?

dotCreds builds MD-102 practice questions from public exam objectives and Microsoft Learn and exam-objective references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start MD-102 practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.