Microsoft MD-102: Device Trust Under Inspection

A laptop shows as compliant in one report but still accesses business applications after the employee’s account was disabled. The device is enrolled, protected by an antivirus product and patched, yet the organization has failed to align identity, conditional access and endpoint state. Secure device management is an ongoing operating system, not a one-time enrollment task.

Microsoft MD-102, Managing and Securing Microsoft 365 Endpoints by using Intune , supports the Endpoint Administrator Associate role. Its July 24, 2026 objectives are current on October 8; Microsoft has announced a further update for October 27.

Enrollment defines the management relationship

Windows enrollment and other device onboarding methods differ by ownership, provisioning route and organizational needs. A corporate laptop with standardized provisioning has different privacy and management considerations from a personally owned mobile device. Define the inventory, user identity and enrollment restrictions before rolling devices out. A device that merely appears in a directory is not necessarily managed to the level a security policy expects.

Set up fictional groups for corporate devices and personally owned devices, then specify what configurations each should receive. Follow a device through enrollment and record what happens if the assigned user changes. Avoid using one policy for every device simply because it seems administratively convenient. A good onboarding design reduces manual handling while maintaining the ability to revoke access and reassign assets safely.

Configuration and compliance answer different questions

A configuration profile requests or enforces a particular setting, while a compliance policy evaluates whether the device meets defined requirements. The distinction matters because deployment failure, reporting delay or conflicting settings can create uncertainty. An endpoint may have received a policy without being compliant, and compliance status may depend on a recent check-in. Administrators need evidence from the device and service, not just a summary icon.

Simulate a device with an outdated operating system or disabled security feature. Trace what Intune reports, how remediation is communicated and how the device’s access is treated through appropriate identity controls. Then introduce a policy conflict and distinguish it from a device that is offline. The objective is to understand the path from intended setting to observed state, including reasons why those may differ.

Applications have separate lifecycle requirements

Deploying apps includes packaging, targeting, installation status, updates and removal. Business-critical software may need phased rollout, compatibility testing and rollback, especially when it depends on drivers or older components. An app that installs successfully is not necessarily usable by the employee. User and device targeting, assignment intent and dependency configuration determine much of the practical outcome.

Choose an app used by finance and roll it out first to a pilot group. Define success signals beyond a green installation status, such as startup, authentication and required plugin compatibility. Then simulate a bad update and an employee leaving the company. Explain how the organization limits disruption while preserving the ability to remove or block software according to device ownership and company policy.

Protection is layered across device and identity

Device encryption, endpoint protection, attack-surface reduction and least-privilege access cover different threats. No single control makes all other layers redundant. Conditional access may consider compliance, but a compliant device does not guarantee the user or session is trustworthy. Recovery keys, security alerts and incident response responsibilities should have controlled ownership and auditable access.

Model a lost laptop containing sensitive business files. Identify which evidence shows the device is encrypted, how account sessions are revoked and what remote actions may be appropriate. Consider the consequence of issuing a wipe to the wrong device or to a personally owned endpoint. Administrative tools can have irreversible effects, so permissions and verification steps belong in the response plan.

Operations require measurement and recovery

Endpoint health changes continuously as patches arrive, users travel and hardware ages. Monitor rollout failures, compliance trends, device check-in and support incidents rather than relying solely on device counts. Automated remediations can correct repeatable problems but need appropriate targeting, diagnostics and rollback. A bad configuration deployed broadly can be a larger operational risk than the original issue it was meant to solve.

For MD-102 practice, take a device from provisioning through application delivery, compliance failure, security response and reassignment. Capture logs and policy evaluations at each stage. Compare the current July objectives with the announced October 27 revision without treating future changes as already active. The skill is making endpoint trust measurable and recoverable over the entire device lifecycle.

  • img