MD-102 Manage and maintain devices Practice Question
A company uses Microsoft Intune to manage Windows 10 devices with a hybrid Azure AD join configuration. Users report that they are unable to access corporate resources on their devices. You verify that the devices are enrolled and that compliance policies are applied. What should you check next?
⚠ Common exam trap
The trap here is that candidates often jump to conditional access or certificate issues because they sound security-related, but the core requirement for hybrid Azure AD joined devices is on-premises domain controller connectivity for authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the devices can communicate with an on-premises domain controller.
In a hybrid Azure AD join configuration, devices must be able to communicate with an on-premises domain controller to authenticate and obtain Kerberos tickets for accessing corporate resources. Even if Intune enrollment and compliance policies are applied, a loss of connectivity to the domain controller (e.g., due to network changes or DNS issues) will prevent resource access. This is the most likely cause given that enrollment and compliance are verified as working.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the certificate profile assigned to the devices.
Why it's wrong here
Certificate issues are not the primary cause of failure to access resources.
- ✓
Verify that the devices can communicate with an on-premises domain controller.
Why this is correct
Hybrid Azure AD join devices need to connect to a domain controller to complete registration.
- ✗
Ensure the devices have a VPN connection to the corporate network.
Why it's wrong here
VPN is not required for hybrid Azure AD join.
- ✗
Review the conditional access policies for the users.
Why it's wrong here
Conditional access policies would only block after successful authentication.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Microsoft Intune
Microsoft Intune is a cloud-based service that helps organizations manage employee devices, apps, and security policies without needing to own or control the physical hardware.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.