
An independent study guide for Microsoft 365 Certified: Endpoint Administrator Associate · by Tony Rough
Know which Intune enrolment, policy or setting fits each device, and why.
Due on Amazon in December 2026, in Kindle and paperback editions.
This independent study guide for the Microsoft 365 Certified: Endpoint Administrator Associate exam distils what MD-102 really expects you to understand into the comparisons, configuration choices and traps that endpoint decisions turn on, with short PowerShell, Microsoft Graph and KQL examples throughout.
Fifteen chapters, each readable on its own and together covering all five MD-102 skill areas:
Microsoft Intune changes quickly. This edition reflects Microsoft's documentation as of October 2026 and the skills measured from 27 October 2026, including Windows Autopilot device preparation, Windows 365 Flex, Windows settings backup and restore, the Intune Suite add-ons, Security Copilot in Intune and the retirement of tools such as the Microsoft Deployment Toolkit and Windows Information Protection.
This book contains no exam questions. It explains the knowledge the exam expects, so you can answer questions you have never seen and apply the same judgement to real devices.
Written by Tony Rough, a cloud architect with more than twenty years in IT infrastructure who holds the Azure Solutions Architect Expert, Azure Administrator and Azure Security Engineer certifications.
Part of the Ultra Transcenders series from Distilled Press. An independent publication, not affiliated with, sponsored by or endorsed by Microsoft Corporation.
Every skill area in Microsoft's MD-102 outline (as of October 27, 2026), and the chapters that cover it.
| Skill area | Weight | Chapters |
|---|---|---|
| Prepare infrastructure for devices | 20–25% | 1, 2, 3, 4, 5 |
| Manage and maintain devices | 25–30% | 6, 7, 8, 9, 10 |
| Protect devices | 15–20% | 11, 12 |
| Manage and secure applications | 15–20% | 13, 14 |
| Optimize endpoint operations by using automation, monitoring, and reporting | 10–15% | 15 |
Plus an appendix glossary of 400+ terms, each linked to Microsoft Learn, with the same terms explained free online for print readers.



Some sections of the book, free to read online:
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.
How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.