Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.
Start practicing
Manage and maintain devices — choose a session length
Free · No account required
Domain overview
This domain covers day-to-day operations after enrollment: monitoring device and app status, applying compliance and configuration policies, running remote actions, and managing updates with Windows Update for Business and Autopilot. Questions are scenario-based, asking you to pick the correct Intune policy type, Defender XDR setting, or remote action for a stated outcome.
Exam objectives
Selecting Intune compliance, configuration, and device-retirement policy types for stated outcomes
Configuring Defender for Endpoint automatic investigation and response in the Microsoft Defender XDR portal
Applying iOS/iPadOS and Windows restriction settings such as passcode length, biometrics, and wipe thresholds
Reading policy JSON and interpreting settings like osMinimumVersion and remote actions such as wipe, retire, and fresh start
Confusing compliance policies, which report and gate access, with configuration profiles, which actually enforce settings on the device.
Choosing a manual remote action like Retire or Wipe when the requirement is an automated, scheduled policy.
Assuming Defender for Endpoint automatic investigation is on by default instead of configured in the XDR portal settings.
Click any question to see the full explanation and answer options, or start a focused practice session above.
You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?
2A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?
3You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?
4Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?
5Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?
6Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?
7Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?
8You are troubleshooting an Intune-managed Windows 10 device that is not receiving a required application. Which THREE steps should you take to diagnose the issue? (Choose three.)
9Your organization uses Microsoft Intune to manage devices. You need to configure a policy that automatically retires a device if it does not check in for 30 days. Which policy type should you configure?
10You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?
11You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?
12Your organization has Windows 10 devices managed by Intune. You need to enforce BitLocker encryption on all devices. The devices must use a TPM protector and a recovery password. What should you configure?
13You are planning a Windows 11 deployment for 500 new devices using Windows Autopilot. The devices will be shipped directly to users from the manufacturer. You need to ensure that the devices are automatically enrolled in Intune and joined to Microsoft Entra ID. What should you do?
14Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?
15Refer to the exhibit. You manage a Windows 11 device that is marked as compliant and has OS version 10.0.22621.0. You need to upgrade the device to Windows 11 version 23H2. Which Intune feature should you use?
16You need to ensure that corporate devices automatically install critical Windows updates within 24 hours of release. Which update ring setting should you configure in Intune?
17A user's Android device is not receiving email from the corporate Microsoft 365 tenant. The device is enrolled in Intune and shows as compliant. The email profile is assigned to the user. What should you check first?
18A company uses Microsoft Intune to manage iOS devices. They want to ensure that only devices with a passcode of at least 6 characters and without jailbreak can access corporate email. Which policy type should they configure?
19You are troubleshooting a Windows 11 device that fails to install an Intune-managed update. The device has been offline for two weeks. After reconnecting, the update does not install. In the Intune console, the update shows 'Failed to install' with error code 0x800f0831. What is the most likely cause?
20Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?
21A user's iOS device is enrolled in Microsoft Intune. The user reports that they cannot install the Company Portal app from the App Store. What is the most likely reason?
22Refer to the exhibit. You have applied this compliance policy to a Windows 10 device running build 10.0.19044. The device meets all requirements except that the firewall is disabled. What will be the compliance status of the device?
23You manage Windows 10 devices enrolled in Microsoft Intune. Users report that the Company Portal app is not installing required apps. You verify that the devices are compliant and checked in recently. What is the most likely cause?
24You need to ensure that Windows 10 devices are automatically upgraded to Windows 11 if they meet hardware requirements. Which policy should you configure in Microsoft Intune?
25You need to remotely wipe a lost corporate-owned iOS device enrolled in Microsoft Intune. The device is currently offline. What will happen when the device comes online?
26Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?
27Refer to the exhibit. You create a compliance policy for Windows 10 devices. A device is reported as non-compliant. Upon investigation, you find that the device has a password of 6 characters. Which setting is causing the non-compliance?
28You need to deploy a Windows 10 feature update to a pilot group. Which TWO steps are required in Microsoft Intune?
29Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?
30Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?
31You need to retire a device in Microsoft Intune. What is the effect of retiring a device?
32An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?
33A company uses Microsoft Intune to manage macOS devices. They need to deploy a custom plist configuration file to set security settings. Which policy type should they use?
34An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?
35A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?
36An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?
37Refer to the exhibit. A Microsoft Graph PowerShell cmdlet retrieves devices. What is the purpose of this query?
38A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?
39You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?
40A user has a Windows 10 device that is enrolled in Microsoft Intune. The user reports that they cannot install a required app from the Company Portal. You check the Intune console and see that the app assignment is 'Required' but the installation status shows 'Failed'. The device is compliant. What should you check first?
41Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?
42You need to remotely wipe a lost corporate-owned iOS device that is enrolled in Microsoft Intune. Which action should you perform in the Intune console?
43You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?
44Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?
45Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?
46You manage devices with Microsoft Intune. You need to ensure that only devices with a specific BIOS serial number can enroll. What should you configure?
47Your organization uses Windows Autopilot for device provisioning. Users report that after initial setup, devices are not automatically enrolled in Microsoft Intune. What should you verify?
48You manage devices with Microsoft Intune. Users report that after a recent policy change, some devices are not receiving updated policies. You verify that the devices are online and have connectivity. What should you do to force a policy refresh?
49Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?
50Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)
51Which THREE conditions can be used to create a dynamic device group in Microsoft Entra ID for Intune management? (Choose three.)
52Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)
53Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?
54Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?
55Refer to the exhibit. The JSON snippet shows a Windows Update for Business policy assigned to a device group. Users report that quality updates are installed 7 days after release. Which setting controls this behavior?
56You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?
57Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a .pkg app to these devices. What is the recommended method?
58You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?
59Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?
60Which TWO are valid methods to enroll Windows devices in Microsoft Intune?
61Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?
62Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?
63Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?
64You are designing a Windows 11 update strategy for a fleet of 500 devices managed by Intune. The organization requires that critical security updates be applied within 7 days, but feature updates can be delayed up to 60 days. Which Update Rings configuration should you use?
65You have assigned the compliance policy shown in the exhibit to all Windows devices. A Windows 11 device running build 10.0.22621.1500 reports as noncompliant. Which setting is causing the noncompliance?
66Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom configuration profile that sets a specific firewall rule. However, the profile fails to apply on a subset of devices. The Intune console shows 'Conflict' status. What is the most likely cause?
67You manage Windows 10 devices with Intune. You need to collect diagnostic logs from a remote device that is experiencing application crashes. Which Intune feature should you use?
68Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows 11 devices remotely? (Choose two.)
69You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?
70You need to deploy a custom Windows 11 feature update to a pilot group of 50 devices before rolling out to the entire organization. The devices are managed by Intune and are in a 'Pilot' Azure AD group. What is the best approach?
71Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?
72Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?
73Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?
74Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?
75Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?
76A company is planning to use Windows Autopilot to deploy new devices. They want to ensure that devices are automatically enrolled in Microsoft Intune when a user signs in with their Microsoft Entra ID credentials. Which configuration is required?
77Your organization wants to use Windows Autopilot for user-driven deployment. Users should be able to self-deploy their devices by signing in with their corporate credentials. Which Autopilot deployment mode should you use?
78Which THREE conditions must be met for a Windows 10 device to be co-managed with Microsoft Intune and Microsoft Configuration Manager? (Choose three.)
79Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?
80A company uses Microsoft Intune to manage Windows 11 devices. Users report that the Company Portal app is not showing required applications. You verify that the devices show as 'Compliant' in Microsoft Intune. Which configuration should you check first?
81You are troubleshooting an iPhone that cannot enroll in Microsoft Intune. The user receives an error stating 'This device is already enrolled in another MDM.' What is the most likely cause?
82You are deploying Windows 11 devices using Windows Autopilot. Some devices are not registering in Microsoft Intune. You have verified that the hardware hashes are uploaded correctly. What is the most likely cause?
83A user's device is marked as 'Noncompliant' in Microsoft Intune due to missing required updates. The device is configured with a compliance policy that requires a minimum OS version. The user claims the device is up-to-date. What should you verify first?
84Which TWO Windows Update for Business policies can you configure using Microsoft Intune?
85Which THREE are valid Windows Autopilot deployment scenarios?
86You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?
87You deployed this endpoint protection policy to a Windows 10 device. A user reports that a known malicious file was downloaded but not blocked. What is the most likely reason?
88You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?
89Refer to the exhibit. You run this PowerShell command using the Microsoft Graph PowerShell SDK. What is the primary purpose of this command?
90You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?
91Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?
92You need to wipe a lost corporate-owned Windows 10 device that is enrolled in Intune. Which action should you take?
93Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the result?
94You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?
95You are implementing Windows Autopilot for your organization. You need to ensure that during the first boot, the device automatically enrolls in Microsoft Intune and joins Microsoft Entra ID. What is the minimum requirement for the device?
96Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)
97Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)
98Your organization uses Microsoft Intune to manage 1,000 Windows 10 devices and 500 iOS devices. You need to enforce device compliance policies. For Windows devices, you require BitLocker encryption and Windows Defender Antivirus enabled. For iOS devices, you require a passcode of at least 6 characters and device encryption. Devices that become noncompliant should be marked as such and users should receive a notification email. After 7 days of noncompliance, the device should be blocked from accessing corporate email. You also need to create a report that shows the compliance status of all devices. Which combination of actions should you take?
99You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?
100Refer to the exhibit. You have configured the compliance policy shown above. A user reports that their Windows 11 device is compliant with all settings except the threat level. The device has no threat protection agent installed. What will happen when the user tries to access corporate resources?
101Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?
102You are the Intune administrator for Contoso Ltd., a company with 5,000 Windows 11 devices and 1,000 iOS devices managed by Microsoft Intune. The company uses Microsoft Defender for Endpoint for threat detection. You need to implement a solution that ensures devices are compliant before they can access corporate resources. You have the following requirements: 1. Windows devices must have Defender for Endpoint running and report a threat level of 'low' or better. 2. iOS devices must have a PIN of at least 6 characters and be jailbreak-detected as 'not jailbroken'. 3. If a device becomes noncompliant, it should be blocked immediately with no grace period. 4. Noncompliant devices should receive a notification to the user. You create compliance policies for Windows and iOS. You also create a conditional access policy in Microsoft Entra ID to require compliant devices. After deploying, you find that some Windows devices that are missing Defender for Endpoint are still able to access email. What should you do to resolve this issue?
103You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?
104You are implementing Windows Autopilot for a new fleet of devices. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and is enrolled in Intune. Which configuration is required?
105A company uses Microsoft Intune to manage Windows devices. They want to deploy a custom line-of-business (LOB) app as a Win32 app. The app requires .NET Framework 4.8 and must be installed silently. Which file type should you use for the app deployment in Intune?
106Which THREE components are required to deploy a Win32 app via Microsoft Intune?
107Refer to the exhibit. The exhibit shows a JSON representation of a managed device from Microsoft Graph API. The device shows as noncompliant. Which of the following is the most likely reason for the noncompliant status?
108You are the endpoint administrator for Contoso, a company with 10,000 Windows 11 devices managed by Microsoft Intune. The devices are a mix of corporate-owned and bring-your-own-device (BYOD). You need to implement a solution that allows users to access corporate resources only if their devices meet specific security requirements: disk encryption (BitLocker), antivirus (Microsoft Defender), and a minimum OS build. Additionally, you must ensure that users cannot access corporate email from devices that are jailbroken or rooted. The solution should automatically block non-compliant devices from accessing resources and provide a notification to the user explaining the issue. You have already configured compliance policies in Intune. What should you do next to enforce the block?
109Your organization is implementing a zero-trust security model using Microsoft Intune. Devices must be compliant before accessing corporate resources. You need to deploy compliance policies for Windows 10 devices that require BitLocker encryption and a minimum OS version. Which two policy settings should you configure? (Choose two.)
110A company uses Microsoft Intune to manage iOS devices. They need to enforce a policy that requires a passcode of at least 6 characters, allows Touch ID, and automatically wipes the device after 10 failed attempts. Which three settings should be configured in a device restrictions profile for iOS? (Choose three.)
111Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?
112You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Microsoft Intune to manage its Windows 10 devices. The company recently experienced a ransomware attack that encrypted local files on several devices. To mitigate future attacks, management wants to ensure that all devices have real-time protection enabled in Microsoft Defender Antivirus and that Controlled Folder Access is turned on. You need to configure these settings via Intune. You decide to create a device configuration profile for Windows 10. What is the most efficient way to deploy these settings to all existing and future devices?
113Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Azure AD. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Azure AD joined. What is the most likely reason for the failure, and how should you resolve it?
114You are an Intune administrator for a large enterprise that uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) for threat protection. You need to ensure that all Windows 10 devices are properly onboarded to Defender for Endpoint and that security settings are enforced via Intune. You have created a device configuration profile that includes the 'Microsoft Defender for Endpoint' settings, but some devices are not appearing in the Defender for Endpoint portal. You verify that the devices are Intune managed and enrolled. What should you do to ensure proper onboarding?
115Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?
116Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company-specific application (a .pkg file) to all macOS devices. The application requires a specific configuration file that must be placed in the /Library/Application Support/ directory. You also need to ensure that the application is installed silently without user interaction. How should you configure the deployment in Intune?
117You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?
118Your organization uses Microsoft Intune to manage devices. You need to collect diagnostic logs from a remote Windows device without user interaction. Which THREE methods can you use?
119You are troubleshooting a Windows device that is not receiving policies from Intune. Which TWO actions should you take?
120You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?
121You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?
122You manage Windows 11 devices with Microsoft Intune. A critical line-of-business app must be installed on all devices in the Finance department, but the app's installer requires administrator privileges and the users do not have local admin rights. You need to deploy the app silently without user interaction and ensure it installs even if no user is signed in. What should you do?
123Your company uses Microsoft Intune to manage Windows 11 devices. A security policy requires that devices automatically receive quality updates as soon as they are available, with a deadline of 2 days after release and automatic restart outside active hours. You create a Windows update ring in Intune. Which setting should you configure to meet the deadline requirement?
124You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)
125You manage 500 Windows 11 devices enrolled in Microsoft Intune. A security policy requires that a specific registry value be set on all devices, and you must be able to report which devices have the value applied and remediate any that do not. You need to implement this with the least administrative effort. What should you create?
126You are an administrator for a Microsoft Intune environment. You need to remotely wipe a lost Windows 11 device to prevent access to corporate data. The device is enrolled in Intune and is currently online. Which action should you perform from the Intune admin center?
127You manage a fleet of Windows 11 devices with Microsoft Intune. Users report that the Windows Update ring assigned to them installs quality updates but never installs the required feature update to Windows 11 version 23H2. You confirm the devices are active, check-in is successful, and the ring is assigned to the correct Microsoft Entra group. You need to ensure the feature update installs automatically without user interaction. What should you configure?
128You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy to require that devices have a specific minimum OS version and that BitLocker is enabled. Which two settings should you configure in the compliance policy? (Choose two.)
129You are the endpoint administrator for a company using Microsoft Intune. The IT director asks you to generate a report that shows which Windows devices have not installed the latest security update in the past 14 days. What should you use?
130You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. Users report that their devices are not receiving newly assigned compliance policies. You need to force the devices to check in with Intune immediately. What should you do from the Intune admin center?
131You manage a fleet of Windows 11 devices with Microsoft Intune. The security team requires that any device that has not checked in with Intune for more than 30 days is automatically retired so its resources are released and its compliance state is removed. You need to configure this behavior with the least administrative effort. What should you do?
132You administer Microsoft Intune for a company with Windows 11 devices joined to Microsoft Entra ID. A security requirement states that if a device is found noncompliant, it must lose access to Microsoft 365 services within 15 minutes, and the device must be marked noncompliant automatically when a required antivirus signature is out of date. You need to implement this with the least administrative effort. What should you do?
133You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?
134You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that Windows Update for Business policies are applied to these devices to control when feature updates are installed. What should you configure?
135You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?
136You manage a group of iOS devices enrolled in Microsoft Intune. Users report that they are unable to receive email on their devices after you deployed a new configuration profile. You need to identify the cause quickly. What should you use?
137You administer Microsoft Intune for a company with 500 Windows 11 devices. The security team requires that when a device is reported lost or stolen, you can remotely erase corporate data without affecting the user's personal files on devices enrolled as personally owned. Which action should you perform in the Intune admin center?
138You manage devices with Microsoft Intune. You need to ensure that only devices that meet specific compliance requirements can access Microsoft 365 services. You create a compliance policy and assign it to a group of users. What should you do next to enforce the policy?
139You manage 500 Windows 11 devices with Microsoft Intune. Several devices are shared by multiple employees across shifts at a manufacturing plant. You need to configure a policy that automatically removes local user profiles that have not been used for 60 days to conserve disk space, while preserving profiles of users who sign in regularly. What should you configure?
140You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, all corporate data is removed but the user's personal files remain intact. The devices are enrolled as personal devices with work profiles. What should you do?
141You manage Windows 11 devices with Microsoft Intune. Several devices are failing to check in and receive policy. You review the device list and see the devices are enrolled but show a compliance state of 'Not evaluated'. You need to force the devices to immediately check in with the Intune service from the local device. What should you do?
142You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, users receive a notification email with instructions to remediate the issue. The email must be sent only to the primary user of the device. What should you configure?
143Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?
144You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a user reports a lost device, you can remotely lock it and display a custom message on the lock screen. The solution must not erase any data. What should you do?
145You are the endpoint administrator for a company that uses Microsoft Intune. You need to ensure that when a Windows 11 device is retired or wiped, the device record is automatically removed from Intune after 30 days. Which action should you take?
146You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a Windows Update ring to defer quality updates by 7 days and feature updates by 60 days. Which two settings should you configure in the update ring? (Choose two.)
147You manage Windows 11 devices with Microsoft Intune. Users report that when they attempt to enroll a personal device, enrollment fails with error 80180014. You need to ensure that only corporate-owned devices can enroll. What should you configure?
148You manage iOS/iPadOS devices with Microsoft Intune. You need to ensure that when a device is lost or stolen, its corporate data can be remotely wiped while leaving personal data intact. The devices are enrolled as user enrollment (personal devices). What should you do?
149You are an endpoint administrator for a company that uses Microsoft Intune. You need to create a report that shows which devices have not checked in to Intune for more than 30 days. What should you use?
150Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?
151You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that devices automatically receive quality updates and feature updates according to a schedule you define, with the ability to pause updates. What should you configure?
152You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)
153You are deploying a Windows 11 device using Windows Autopilot. The device is enrolled in Microsoft Intune and assigned a device group. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and enrolls in Intune without user interaction. Which Autopilot deployment mode should you configure?
154You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, the user receives a notification email, and the device is automatically retired after 30 days. The solution must minimize administrative effort. What should you configure?
155You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Azure AD joined and enrolled in Intune. What should you configure?
156You are deploying a Windows 11 device using Windows Autopilot. The device fails to enroll in Intune and you see the error 'The device is not registered in Autopilot'. You have verified that the device hardware hash is uploaded. What is the most likely cause?
157You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?
158You use Microsoft Intune to manage Windows 11 devices. A device named LAPTOP-01 is not receiving a newly assigned device configuration profile. You verify the profile is assigned to a group that contains LAPTOP-01. You need to force the device to check in with Intune and apply the policy immediately. Which action should you perform from the Intune admin center?
159You manage a set of Windows 11 devices enrolled in Microsoft Intune. Users report that they can no longer sign in with their Microsoft Entra ID credentials after you deployed a new compliance policy. The devices show as compliant in Intune, but the sign-in fails with an error about device not meeting requirements. You need to ensure that users can sign in. What should you do?
160You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, the primary user's corporate data is removed but the device remains enrolled and managed. Which action should you take in the Intune admin center?
161You manage devices with Microsoft Intune. You need to ensure that when a device is marked as non-compliant, users receive a notification and the device is blocked from accessing corporate email. Which two actions should you perform? (Choose two.)
162You manage Windows 10 devices with Microsoft Intune. You need to ensure that devices receive a specific Windows quality update as soon as possible, bypassing any deferral settings. What should you configure?
163You manage a hybrid environment with Microsoft Intune and Microsoft Configuration Manager. You need to ensure that devices co-managed for Windows Update policies use Intune as the authoritative source for update deployments, while Configuration Manager continues to manage software updates. Which workload slider should you move to Intune?
164You are a Microsoft 365 Endpoint Administrator. You need to remotely wipe a lost Windows 11 device that is enrolled in Microsoft Intune. The device is currently offline. What happens when you initiate a wipe action from the Intune admin center?
165You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?
166You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a compliance policy that marks devices as noncompliant if they do not have a specific minimum OS version and if they have not checked in with Intune within the last 7 days. Which TWO settings should you configure in the compliance policy? (Choose two.)
167You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)
168You are responsible for managing Windows 10 devices with Microsoft Intune. You need to deploy a new line-of-business (LOB) app to a group of devices. The app requires a script to run after installation to configure settings. What should you use to deploy the app and ensure the script runs?
169You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. You need to ensure that devices receive quality updates with a maximum deferral of 7 days. What should you configure?
170You manage Windows 11 devices with Microsoft Intune. After a Windows quality update is deployed to a pilot ring, several devices report installation failures in the Update reports. You need to identify the exact error code returned by the update installation on a specific device without accessing the device directly. What should you do?
171You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?
172You use Microsoft Intune to manage Windows 11 devices. You configure a Windows Update ring policy to defer quality updates by 7 days and feature updates by 60 days. A critical security update is released that must be installed immediately on all devices, bypassing the deferral. What should you configure?
173A help desk technician reports that a Windows 11 device enrolled in Microsoft Intune has not received a newly assigned configuration profile. The device shows as compliant in the admin center. You need to force the device to check in with Intune immediately. What should you do?
174You manage Windows 11 devices with Microsoft Intune. A line-of-business application must be deployed to a specific group of devices. The application installer requires administrative privileges and must run in the system context. You need to ensure the app installs silently without user interaction. What should you create?
175You manage macOS devices enrolled in Microsoft Intune using the Intune Company Portal app. Users report that the Company Portal app does not detect newly assigned required apps and shows an outdated compliance status. You need to ensure the Company Portal refreshes device state on demand. What should you do?
176You manage devices in Microsoft Intune. You need to generate a report that shows which devices have not checked in with Intune for more than 30 days. What should you use?
177You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to configure a remediation to automatically restart the Windows Update service (wuauserv) if it stops. You create a proactive remediation script package. Which two components must you provide in the script package? (Choose two.)
178Your company uses Microsoft Intune to manage Windows 11 devices. An administrator needs to remotely restart a specific device that is currently online to apply pending updates. Which action should the administrator use in the Intune admin center?
179You manage devices in Microsoft Intune. You need to ensure that a specific set of Windows 10 devices automatically receive new configuration profiles as soon as they are assigned. The devices are already enrolled and are members of an Microsoft Entra ID group. What should you do?
180You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?
181You are configuring Windows Update for Business policies in Microsoft Intune for a group of Windows 11 devices. You need to ensure that devices do not install feature updates for 60 days after a new version is released, while still receiving quality updates immediately. Which setting should you configure?
182You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?
183You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to collect a list of installed applications from these devices and view the data in the Intune admin center. What should you configure?
Deep-dive questions
The most-searched questions in this domain — detailed explanations, worked examples, full answer breakdowns.
Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.
The Courseiva MD-102 question bank contains 183 questions in the Manage and maintain devices domain, covering the 41% of the exam attributed to this domain in the official Microsoft blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Manage and maintain devices domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included