MD-102 Prepare infrastructure for devices Practice Question
A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?
⚠ Common exam trap
MD-102 often tests the prerequisites for Autopilot, and candidates may confuse device registration with Microsoft Entra ID join or other requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The devices must be registered in Microsoft Intune via the hardware vendor or manually.
For Windows Autopilot to automatically enroll devices, the devices must be registered in Microsoft Intune. This can be done by the hardware vendor (OEM registration) or manually by the organization. Without registration, Autopilot cannot identify the device and apply the deployment profile.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The devices must be registered in Microsoft Intune via the hardware vendor or manually.
Why this is correct
Autopilot requires each device's hardware hash registered as an Autopilot device in Microsoft Intune before it can enrol. OEM registration lets the vendor upload hashes automatically, satisfying the stem's prerequisite so the 500 devices enrol without manual hash collection.
- ✗
The organization must have a hybrid Microsoft Entra ID join configuration in place.
Why it's wrong here
OEM-registered Autopilot devices enrol as Microsoft Entra joined; hybrid Microsoft Entra ID join requires line-of-sight to on-premises domain controllers and is not a prerequisite. It is tempting because hybrid join suits organisations with existing domain infrastructure, and it would be correct if the stem required on-premises domain authentication.
- ✗
BitLocker must be enabled on the devices before they are shipped.
Why it's wrong here
BitLocker is configured through Intune policy during or after Autopilot enrolment, not as a shipping prerequisite; OEM registration requires the device hardware hash to be uploaded. It is tempting because encryption is a deployment consideration, and this would be correct if the question asked how to enforce disk encryption on enrolled devices.
- ✗
A local administrator account must be created on each device prior to deployment.
Why it's wrong here
Autopilot provisions the OS and creates accounts during enrolment, so a pre-created local administrator is unnecessary; OEM registration instead supplies the hardware hash. It is tempting because local admin accounts matter for some imaging methods, and this would be correct if the question described manual, image-based deployment rather than Autopilot.
Go deeper
Related to this question
Learn chapter
Deploying Applications with Intune
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Windows Autopilot
Windows Autopilot is a cloud-based deployment technology that automates the setup and configuration of new Windows devices, reducing the need for IT staff to manually image or touch each machine.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are configuring Windows Autopilot for new devices. The devices need to be automatically enrolled in Intune and assigned to a specific group based on their serial number. What is the required step before the devices can be recognized by Autopilot?
easy- A.Configure Intune enrollment for all users using device enrollment managers.
- ✓ B.Register the devices using their hardware hash in the Microsoft Intune admin center.
- C.Join the devices to Microsoft Entra ID manually before shipping.
- D.Upload a CSV file with device serial numbers to Microsoft Entra ID.
Why B: Before Windows Autopilot can recognize and automatically enroll devices, they must be registered as Autopilot devices. This is done by uploading their hardware hash (a unique identifier derived from the device's TPM and other hardware) into the Microsoft Intune admin center. Once registered, the device is associated with an Autopilot profile and can be automatically enrolled in Intune and assigned to a group based on its serial number during the out-of-box experience.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.