Reinforce MD-102 concepts with active-recall study cards covering all 4 blueprint domains. Each card shows the question on the front and the correct answer with a full explanation on the back.
Flashcards work through active recall — the process of retrieving information from memory rather than passively re-reading it. Research consistently shows that active recall produces stronger, longer-lasting memory than re-reading study guides. For MD-102 preparation, this means flashcards are one of the highest-return study tools available.
Attempt recall first
Read the MD-102 question on each card, pause, and attempt to formulate the answer in your own words before revealing. This retrieval attempt — even if wrong — dramatically strengthens memory compared to immediately reading the answer.
Review wrong cards again
When you get a card wrong, note it and add it back to your review pile. Spaced repetition — seeing difficult cards more frequently — is the mechanism that makes flashcard study far more efficient than linear reading.
Study by domain
Group your MD-102 flashcard sessions by domain for the first 3–4 weeks. Master one domain before moving to the next. In the final week, shuffle all cards together to test cross-domain recall — which is what the real MD-102 exam requires.
Short sessions beat marathon reviews
20–30 flashcard cards per session, done daily, produces better retention than a single 200-card marathon session. Five short daily sessions per week over 4 weeks gives you over 400 total card reviews — enough to reliably pass MD-102.
Sample cards from the MD-102 flashcard bank. Read the question, think of the answer, then read the explanation below.
Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?
The device's hardware hash, uploaded to Intune, and an Autopilot deployment profile assigned.
Windows Autopilot requires the device's hardware hash to be uploaded to Intune so that the device can be identified as an Autopilot device. An Autopilot deployment profile is then assigned to the device, which specifies the settings for joining Microsoft Entra ID, enrolling in Intune, and installing required applications during the first boot (Out-of-Box Experience). This combination ensures the entire provisioning flow occurs automatically without manual intervention.
Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?
Add a compliance policy setting: 'Require the device to be at or under the machine risk score' with a low score.
Microsoft Defender for Endpoint integrates with Intune compliance policies via the 'Require the device to be at or under the machine risk score' setting. When a device stops reporting to Defender, its risk score escalates above the 'Low' threshold, causing Intune to mark it as non-compliant. This directly meets the requirement to flag non-reporting devices without additional scripting or conditional access complexity.
You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?
Deploy a Windows 11 feature update using the 'Windows 10/11 feature update' servicing plan in Configuration Manager, enabling Delivery Optimization for peer-to-peer download.
It leverages Configuration Manager's 'Windows 10/11 feature update' servicing plan, which is specifically designed for in-place upgrades while preserving user data and settings. Enabling Delivery Optimization for peer-to-peer download reduces bandwidth consumption in remote offices by allowing devices to share upgrade content locally, addressing the limited bandwidth constraint.
Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?
Create an update ring for Windows 10 and later, and set the 'Automatic update behavior' to 'Auto install and reboot' and assign it to all devices.
Update rings are the primary policy in Microsoft Intune for controlling how and when Windows 10 and later devices receive updates from Windows Update. Setting 'Automatic update behavior' to 'Auto install and reboot' ensures that critical and security updates are automatically downloaded and installed without user intervention, meeting the requirement for all Windows 11 devices.
A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?
On the device, go to Settings > Accounts > Access work or school, select the account, and click Sync.
When a Windows 11 device shows 'Not evaluated' in Intune, it usually means the MDM enrollment is intact but the device hasn't checked in with the Intune service recently. Manually triggering a sync from Settings > Accounts > Access work or school forces the MDM client to pull the latest compliance policies immediately, which is the least disruptive first step.
Your organization uses Microsoft Entra ID joined devices with Windows 10. You need to ensure that only compliant devices can access corporate email in Microsoft Outlook for Windows. Which integration should you enable?
Create a Conditional Access policy in Microsoft Entra ID requiring compliant devices for Exchange Online.
Creating a Conditional Access policy in Microsoft Entra ID that requires compliant devices for Exchange Online is the correct integration because it directly enforces device compliance as a condition for accessing corporate email. This policy evaluates the device's compliance status reported by Intune before granting access to Exchange Online, ensuring only compliant devices can use Outlook for Windows.
Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Microsoft Entra ID registered' instead of 'Microsoft Entra ID joined'. What should you modify to ensure the device is joined?
Modify the Autopilot deployment profile to set 'Join to Microsoft Entra ID as' to 'Microsoft Entra ID joined'.
The Autopilot deployment profile includes a setting called 'Join to Microsoft Entra ID as' that determines whether the device performs an Microsoft Entra ID join or an Microsoft Entra ID registration. By default, this setting may be configured as 'Microsoft Entra ID registered', which results in a device that is only registered (workplace-joined) rather than fully joined. Changing this setting to 'Microsoft Entra ID joined' ensures the device completes a full Microsoft Entra ID join during the user-driven deployment, making it a managed device in Microsoft Entra ID.
You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?
Create an Intune device configuration profile using the Settings Catalog and assign it to the Microsoft Entra ID group containing Cloud PC users.
Intune device configuration profiles using the Settings Catalog allow granular control over Microsoft Defender for Endpoint settings (e.g., real-time protection) and custom firewall rules. These profiles can be assigned to an Microsoft Entra ID group containing Cloud PC users, ensuring the settings are applied automatically after provisioning via the Windows 365 service, which integrates with Intune for post-provisioning management.
A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?
A compliance policy was updated requiring a newer OS version or additional security settings.
Intune compliance policies are evaluated in real time when a user attempts to access corporate resources. If an administrator updates a policy to require a newer iOS version or additional security settings (e.g., passcode complexity, encryption), the device may become non-compliant even if it was previously compliant. The Outlook app checks device compliance via the Intune SDK and will block access if the device no longer meets the policy requirements, displaying the 'device not compliant' error.
You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?
The root CA certificate required to validate the RADIUS server certificate is not installed on the device.
The device can connect to other Wi-Fi networks but not the corporate one, indicating the issue is specific to the corporate network's authentication requirements. Since the profile uses SCEP certificate authentication, the device must trust the root CA that issued the RADIUS server certificate to validate the server during the EAP-TLS handshake. If the root CA certificate is missing, the client will reject the RADIUS server certificate, causing the connection to fail. This is the most likely cause because the profile assignment and driver are not specific to this single network failure.
Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?
Check if the user has logged in and acknowledged the FileVault prompt.
FileVault encryption on macOS requires user interaction to complete. When Intune deploys a FileVault profile with recovery key escrow, the user must log in and explicitly acknowledge the FileVault prompt to enable encryption. If the user has not done so, the device remains unencrypted regardless of the profile assignment.
Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?
The compliance policy includes a rule for 'Maximum days since last check-in' and these devices exceeded that limit.
The compliance policy includes a rule for 'Maximum days since last check-in', which checks the `lastSyncDateTime` property. Devices that have not synced within the configured threshold (e.g., 30 days) are marked as noncompliant. This is a common Intune compliance setting for Windows devices to ensure they regularly communicate with the service.
Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?
The Microsoft Defender for Endpoint sensor is not installed or configured correctly.
The Microsoft Defender for Endpoint sensor is the core component that collects and reports security telemetry from Windows 10 devices to the Defender for Endpoint cloud service. If the sensor is not installed, is missing, or is misconfigured (e.g., due to a corrupted installation or incorrect onboarding script), the device will appear as inactive in the Microsoft 365 Defender portal, even if the device is otherwise healthy and connected.
Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?
Set a deadline for quality updates to 7 days
To ensure critical security updates are installed within 7 days of release, set a deadline for quality updates to 7 days. A deadline specifies the maximum number of days after the update is offered that the device has to install it. This enforces installation within the desired timeframe. A deferral period delays when the update is offered, which would not guarantee installation within 7 days.
An organization uses Microsoft Intune for Windows 10 device management. They need to deploy a custom Windows app (.exe) to kiosk devices. The app requires admin privileges to install, and the devices are shared. Which deployment method should be used?
Use a Win32 app with install context set to 'system'.
Win32 apps in Microsoft Intune can be configured with the install context set to 'system', which grants the necessary admin privileges for installation and ensures the app is installed for all users on shared kiosk devices. This method uses the Intune Management Extension to run the installer with SYSTEM account privileges, bypassing user-level restrictions and supporting per-machine installations.
You manage a fleet of Android Enterprise devices. You need to ensure that only approved apps from the managed Play Store can be installed. What configuration should you enable?
Configure a device restriction policy to allow only managed Google Play apps.
A device restriction policy in Microsoft Intune allows you to restrict app installation to only the managed Google Play store. By configuring the 'Allow only managed Google Play apps' setting, you ensure that users cannot install apps from unapproved sources, effectively controlling the app ecosystem on Android Enterprise devices.
A company uses Microsoft Intune to manage Windows 10 devices. Users report that a LOB app deployed as a required install fails to install on some devices. The app is configured with a dependency on another app. What should the administrator verify first?
Check if the dependency app is assigned and installed successfully
When a required LOB app fails to install, the most common cause is that its dependency app is not present or not successfully installed on the target device. Intune enforces dependency apps to be installed before the parent app, and if the dependency is missing or failed, the parent app installation will not proceed. The administrator should first verify that the dependency app is assigned to the same device groups and has a successful installation status.
The MD-102 flashcard bank covers all 4 official blueprint domains published by Microsoft. Cards are distributed proportionally, so domains with higher exam weight have more cards.
Domain Coverage
Prepare infrastructure for devices
Protect devices
Manage and maintain devices
Manage applications
Both flashcards and practice questions are evidence-based study tools. The difference is in what they train:
Flashcards — concept retention
Best for memorising definitions, acronyms, protocol behaviours, command syntax, and conceptual distinctions. Use flashcards to build the foundational vocabulary that MD-102 questions assume you know.
Best in: weeks 1–3
Practice tests — application
Best for applying concepts to realistic scenarios, eliminating distractors, and building exam stamina.MD-102 questions test scenario reasoning — not just recall — so practice tests are essential.
Best in: weeks 3–6
The most effective MD-102 study plan combines both: use flashcards for the first 2–3 weeks to build conceptual foundations, then shift to practice tests and mock exams in the final 2–3 weeks to apply and benchmark that knowledge. Most candidates who pass on their first attempt use both tools.
Yes. Courseiva provides free MD-102 flashcards across all official exam domains. Every card includes the correct answer and a full explanation of why it is right and why the distractors are wrong. The platform also includes topic-based practice, mock exams, and readiness tracking — no account required.
Courseiva has 556+ original MD-102 flashcards across all 4 exam blueprint domains. New cards are added regularly as the question bank grows. All cards are checked against the official Microsoft exam objectives, with editorial oversight from an experienced network and security engineer.
Courseiva flashcards are purpose-built for IT certification exams. Unlike generic flashcard platforms where content quality varies, every Courseiva card is mapped to the official MD-102 exam blueprint, written by engineers who hold the certification, and includes a full explanation of the correct answer and why the distractors are wrong. This explanation quality is what separates genuine learning from rote memorisation.
Courseiva is a web platform — an internet connection is required. For offline study, we recommend creating free Courseiva account, using the platform in your browser, and using your device's offline capabilities if your browser supports offline web apps.
Save your results, see which domains need more work, and get spaced repetition recommendations — all free.
Sign Up FreeFree forever · Every certification included