Clik here to view.

MD-101 just got a minor update, but more importantly it’s been announced that this exam is retiring at the end of July. I’m currently working on the blog post for the exam that will replace it, MD-102: Endpoint Administrator, and that should be published within the next week. That means that this is most likely the last update I will be publishing for this exam guide, but much of what’s in here carries across to MD-102, and you’ll get my take on the new exam shortly.
Deploy Windows client (25-30%)
Plan a Windows client deployment
- assess infrastructure readiness by using Endpoint Analytics
- select a deployment tool based on requirements
- choose between migrate and rebuild
- choose an imaging and/or provisioning strategy
- plan and implement changes to Windows edition by using subscription activation or MAK license management
Plan and implement Windows client provisioning by using Windows Autopilot
- choose an Autopilot deployment method based on requirements, including user-driven mode, self-deploying mode, autopilot reset, and pre-provisioning
- configure device registration for Autopilot
- create, validate, and assign deployment profiles
- set up the Enrollment Status Page
- provision Windows devices by using Autopilot
- troubleshoot an Autopilot deployment
Plan and implement Windows client deployment by using Microsoft Deployment Toolkit (MDT)
- plan and implement an MDT deployment infrastructure
- choose configuration options based on requirements, such as boot images, OS images, upgrade packages, task sequences, and drivers
- create, manage, and deploy images
- plan and implement PXE boot by using Windows Deployment Services (WDS) •
- create and use task sequences
- manage application and driver deployment
- customize an MDT deployment by using customsettings.ini and bootstrap.ini
- monitor and troubleshoot deployment
- plan and configure user state migration
Manage identity and access (10-15%)
Manage identity
- register devices in and join devices to Microsoft Azure Active Directory (Azure AD), part of Microsoft Entra
- enable users and groups from Azure Active Directory to access Windows client
- register devices in and join devices to Azure Active Directory
- manage AD DS and Azure AD groups
- manage AD DS and Azure AD users
- configure Enterprise State Roaming in Azure AD
Plan and implement conditional access policies
- plan conditional access
- set up conditional access policies
- determine which users are affected by a conditional access policy
- troubleshoot conditional access
Manage compliance policies and configuration profiles (10-15%)
Implement device compliance policies
- plan device compliance policies
- implement device compliance policies
- manage notifications for device compliance policies
- monitor device compliance
- troubleshoot device compliance policies
Plan and implement device configuration profiles
- plan device configuration profiles
- implement device configuration profiles
- monitor and troubleshoot device configuration profiles
- configure and implement assigned access on public devices, including kiosks and dedicated devices
Manage, maintain, and protect devices (25-30%)
Manage device lifecycle
- configure enrollment settings in Intune
- configure automatic and bulk enrollment in Intune
- configure policy sets
- restart, retire, or wipe devices
Monitor devices
- monitor devices by using Azure Monitor
- monitor device hardware and software inventory by using Endpoint Manager Admin Center
- monitor devices by using Endpoint Analytics
Manage device updates
- plan for device updates
- create and manage quality update policies by using Intune
- create and manage feature update policies by using Intune
- create and manage iOS/iPadOS update policies by using Intune
- manage Android updates by using device configuration profiles
- monitor updates
- troubleshoot updates in Intune
- configure Windows client delivery optimization by using Intune
- create and manage update rings by using Intune
Plan and implement endpoint protection
- plan endpoint security
- implement and manage security baselines in Intune
- create and manage configuration policies for Endpoint Security including antivirus, encryption, firewall, endpoint detection and response, and attack surface reduction
- onboard devices into Microsoft Defender for Endpoint
- monitor Microsoft Defender for Endpoint
- investigate and respond to threats
Manage apps (10-15%)
Deploy and update applications
- deploy apps by using Intune
- configure Microsoft 365 Apps deployment by using Office Deployment Toolkit or Office Customization Tool
- manage Microsoft 365 Apps by using Microsoft 365 Apps Admin Center
- deploy Microsoft 365 Apps by using Intune
- manage Office app settings by using group policy or Intune
- deploy apps by using Microsoft Store for Business, Apple store, and Google store
Implement app protection and app configuration policies
- plan app protection policies
- plan app configuration policies for iOS and Android
- implement app protection policies
- implement app configuration policies for iOS and Android
- manage app protection policies
- manage app configuration policies