Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 1–75

556 questions total · 8pages · All types, answers revealed

Page 1 of 8

Page 2
1
MCQeasy

You are setting up Microsoft Intune for a new company. The company has a mix of Windows 10, Windows 11, iOS, and Android devices. You need to ensure that devices can enroll in Intune automatically without user interaction for Windows devices that are Microsoft Entra joined. What should you configure?

A.Automatic enrollment in Intune.
B.Device enrollment manager.
C.Windows Autopilot deployment profile.
D.Enrollment restrictions.
AnswerA

Automatic enrollment in Intune is the feature that enables Windows devices that are Microsoft Entra joined or hybrid Azure AD joined to automatically enroll in Intune without user interaction. When enabled, devices receive Intune policies and management automatically upon joining Microsoft Entra ID. This is the correct configuration to ensure seamless enrollment for Windows devices without user action. It is configured in the Intune portal under Enrollment > Windows > Automatic Enrollment.

Why this answer

Automatic enrollment in Intune is the feature that allows Windows devices that are Microsoft Entra joined or hybrid Azure AD joined to enroll in Intune automatically without user interaction. This is configured in the Intune portal and ensures that devices are managed as soon as they join Microsoft Entra ID. This meets the requirement for automatic enrollment without user interaction for Windows devices.

Exam trap

The trap here is confusing automatic enrollment with Autopilot, which is for provisioning new devices but still requires user interaction during OOBE.

2
MCQmedium

You are an Endpoint Administrator for a company that uses Microsoft Intune. The security team requires that Windows 11 devices assigned to the Finance department must use a specific set of DNS servers and must not allow users to modify the DNS settings. You create a device configuration profile using the Settings catalog. Which setting category should you use to enforce the DNS server assignment?

A.VPN
B.Wi-Fi
C.DNS
D.Network proxy
AnswerC

The DNS category in the Settings catalog contains settings such as DNS server addresses for specific interfaces and DNS suffix search lists. Configuring this category lets you assign the required DNS servers to the Windows 11 devices and, when the profile is assigned, the settings are enforced so users cannot change the DNS configuration on those Finance devices.

Why this answer

The Settings catalog exposes granular Windows configuration service provider settings, and the DNS category specifically includes settings to define DNS server addresses and prevent modification. Applying a device configuration profile with those settings to the Finance device group enforces the required DNS servers and blocks user changes, directly satisfying the security team's requirement.

Exam trap

The trap here is assuming that DNS server assignment belongs under Network proxy or Wi-Fi settings, when the Settings catalog provides a dedicated DNS category for that purpose.

3
MCQeasy

You need to deploy a Microsoft 365 Apps for enterprise configuration to devices managed by Intune. Which policy type should you use?

A.Device configuration profile (settings catalog)
B.Managed apps policy
C.Windows update ring policy
D.Microsoft 365 Apps (Windows) configuration policy
AnswerD

Microsoft 365 Apps (Windows) configuration policies in Intune deploy and configure Office on Windows devices, letting you set update channels, remove previous installations, and choose specific apps. This directly satisfies the stem's requirement to deploy a Microsoft 365 Apps for enterprise configuration to Intune-managed devices, unlike settings catalog or compliance policies.

Why this answer

The Microsoft 365 Apps (Windows) configuration policy is the correct choice because it is specifically designed to manage the deployment, update settings, and configuration of Microsoft 365 Apps for enterprise on Intune-managed Windows devices. This policy type provides granular control over installation parameters, update channels, and app settings, directly aligning with the requirement to deploy a Microsoft 365 Apps configuration.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Apps configuration policy with a device configuration profile or a managed apps policy, mistakenly thinking that general device policies can handle Office-specific deployment tasks, when in fact only the dedicated Microsoft 365 Apps policy provides the necessary ODT integration and update channel management.

How to eliminate wrong answers

Option A is wrong because a Device configuration profile (settings catalog) is used to configure device-level settings (e.g., security policies, registry keys) and cannot directly manage the installation or update configuration of Microsoft 365 Apps. Option B is wrong because a Managed apps policy applies to mobile application management (MAM) for protecting app data on devices not necessarily managed by Intune, and it does not handle deployment or configuration of Microsoft 365 Apps. Option C is wrong because a Windows update ring policy controls Windows OS update settings (e.g., deferral periods, feature updates) and has no capability to deploy or configure Microsoft 365 Apps for enterprise.

4
MCQmedium

Your organization uses Microsoft Entra ID joined devices and Microsoft Intune for mobile device management. A user reports that their device is not receiving compliance policies. The device shows as 'Compliant' in Intune but the Conditional Access policy still blocks access. What should you verify first?

A.Check if the compliance policy is assigned to the device's group.
B.Review the Conditional Access policy to ensure it requires compliant device.
C.Confirm the device is enrolled in Intune.
D.Verify the user is in the correct Azure AD group for Conditional Access.
AnswerB

Correct. The device shows as compliant but Conditional Access still blocks, suggesting the policy may not require compliant device. Reviewing the policy's conditions is the logical first step.

Why this answer

The device shows as 'Compliant' in Intune, indicating enrollment and policy assignment are not the issue. The Conditional Access policy may be misconfigured to require a different condition (e.g., hybrid Azure AD join) or may not be set to require compliant device. Reviewing the policy ensures it enforces the correct requirement.

Option A is incorrect because the device is already compliant, implying the policy is assigned. Option C is incorrect since the device is already enrolled (shown by compliance status). Option D is incorrect because group membership is irrelevant if the policy itself doesn't require a compliant device.

Exam trap

A common trap is assuming compliance status is sufficient for access, but Conditional Access policies have additional conditions (e.g., require compliant device, require hybrid join) that must be explicitly configured.

5
Multi-Selectmedium

Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?

Select 2 answers
A.Enforce security baselines on devices
B.Convert existing devices to Autopilot by uploading hardware hash
C.Deploy third-party applications automatically
D.Customize the out-of-box experience (OOBE) for users
E.Configure BIOS settings remotely
AnswersB, D

Uploading a hardware hash registers an existing device with the Autopilot deployment service, enabling it to be reset and reprovisioned through the Autopilot out-of-box experience. This satisfies the stem's requirement for a supported Autopilot action in Microsoft Intune, converting already-deployed hardware into Autopilot-managed devices without manual imaging.

Why this answer

Option B is correct because Windows Autopilot supports registering existing devices by collecting their hardware hash (via the Get-WindowsAutoPilotInfo script or similar) and uploading it as a CSV to Intune, which creates an Autopilot device record so the device can be reset and reprovisioned through the Autopilot flow. Option D is correct because Autopilot's core purpose is to define and customize the out-of-box experience (OOBE) using deployment profiles, including settings like the privacy prompts, user account type, language/region, and whether the user is a standard user or local admin. Option A is not an Autopilot action; security baselines are enforced through Intune configuration profiles/policies, not through Autopilot itself.

Option C is not specific to Autopilot; third-party applications are deployed via Intune app deployment (Win32 apps, MSI, Microsoft Store apps, etc.), which can be assigned to Autopilot-enrolled devices but is not an Autopilot capability. Option E is not an Autopilot function; BIOS/UEFI settings are typically configured through vendor tools (e.g., Dell Command | Configure, HP Client Management Script Library) or Intune's OEM-specific configuration, not Autopilot.

Exam trap

The trap here is that candidates confuse Windows Autopilot's OOBE customization capabilities with broader device management features like security baselines or third-party app deployment, which are handled by Intune policies after enrollment, not during the Autopilot provisioning phase.

6
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks a device as noncompliant if it has not checked in with Intune for more than 30 days. Which compliance setting should you configure?

A.In the compliance policy, configure 'System Security' and set 'Require a password to unlock mobile devices' to 'Require'.
B.In the compliance policy, configure 'Device Health' and set 'Require BitLocker' to 'Require'.
C.In the compliance policy, set 'Compliance status validity period (days)' to 30.
D.In the compliance policy, set 'Mark devices with no compliance policy assigned as' to 'Not compliant'.
AnswerC

The compliance status validity period defines how long a device's last reported compliance state remains valid. When the device fails to check in within this period, Intune marks it noncompliant. Setting it to 30 days directly fulfills the requirement to flag devices that have not checked in for more than 30 days.

Why this answer

The compliance status validity period is the exact setting that determines how long a device's reported compliance state is trusted. When a device does not check in within that period, Intune automatically marks it noncompliant. Setting the validity period to 30 days ensures that any device silent for more than 30 days is flagged, matching the requirement precisely.

Exam trap

The trap here is confusing the setting that marks unassigned devices as noncompliant with the setting that expires stale compliance data.

7
MCQmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?

A.Create a device enrollment restriction that blocks personally owned Windows devices and allow corporate-owned devices.
B.Configure an Autopilot deployment profile that targets only corporate devices.
C.Configure a conditional access policy that requires compliant devices for all cloud apps.
D.Create a device compliance policy that requires BitLocker and mark personal devices as noncompliant.
AnswerA

Device enrollment restrictions in Intune let you control which platforms and personal ownership types can enroll. By blocking personally owned Windows devices while allowing corporate-owned ones, you prevent personal devices from enrolling as managed endpoints. Users can still access email through a browser because browser access is governed by conditional access, not enrollment restrictions, so the requirement is met.

Why this answer

Enrollment restrictions in Intune are the mechanism for controlling whether personally owned devices can enroll for a given platform. By blocking personal Windows ownership while allowing corporate ownership, only corporate devices enroll. Because browser-based email access is controlled separately through conditional access, personal devices can still reach email in a browser without being enrolled.

Exam trap

The trap here is confusing enrollment restrictions, which gate enrollment, with compliance or conditional access policies, which evaluate or gate access after enrollment.

8
MCQeasy

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a VPP (Volume Purchase Program) app that is already purchased and assigned to your tenant. What is the minimum configuration required to make the app available to users?

A.Configure a device enrollment restriction to allow the app.
B.Sync the VPP token, then add the app from the store and assign it.
C.Distribute the app via the Company Portal without any additional configuration.
D.Upload the app IPA file to Intune, then create an app configuration policy.
AnswerB

The VPP token must be synced so Microsoft Entra ID and Intune can retrieve the purchased licences, then the app is added from the store and assigned to users. This satisfies the minimum configuration needed to make the already-purchased app available.

Why this answer

For VPP apps in Intune, the minimum requirement is to sync the VPP token so Intune can communicate with Apple's Volume Purchase Program, then add the app from the store and assign it to users or groups. Once the token is synced and the app is assigned, Intune handles license distribution automatically. No IPA upload or configuration policy is required for basic availability.

Exam trap

MD-102 often tests the distinction between VPP apps and LOB apps — candidates incorrectly select IPA upload because they conflate the two deployment methods.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll, not which apps are available — they have no bearing on VPP app deployment. Option C is wrong because the Company Portal alone does not make VPP apps available; the token must be synced and the app assigned first. Option D is wrong because uploading an IPA file is for line-of-business (LOB) apps, not VPP apps, and an app configuration policy is optional for delivering app settings, not a prerequisite for availability.

9
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device that is enrolled in Microsoft Intune. Which action should you perform in the Intune console?

A.Retire.
B.Wipe.
C.Delete.
D.Reset.
AnswerB

Wipe performs a full factory reset, removing all data, settings, and the management enrolment itself, which satisfies the requirement to remotely erase a lost corporate-owned iOS device. Retire would only remove corporate data and leave personal content intact, so it cannot guarantee the device is cleared.

Why this answer

The Wipe action in Microsoft Intune restores a device to its factory default settings, removing all corporate and personal data. This is the appropriate action for a lost corporate-owned iOS device to ensure sensitive data is completely erased and the device cannot be accessed. Retire only removes managed apps and policies but leaves personal data intact, which is insufficient for a lost device scenario.

Exam trap

The trap here is that candidates confuse 'Retire' with 'Wipe', mistakenly thinking Retire is sufficient for a lost device, but Retire only removes management and corporate data without performing a full device reset, leaving personal data and the device usable.

How to eliminate wrong answers

Option A (Retire) is wrong because it only removes managed apps, corporate data, and Intune management, but does not perform a full factory reset, leaving personal data and the device operational. Option C (Delete) is wrong because deleting the device from the Intune console simply removes its enrollment record without initiating any wipe or data removal on the device itself. Option D (Reset) is wrong because Intune does not have a 'Reset' action; the correct term for a full factory reset is 'Wipe', and 'Reset' is not a valid action in the Intune console.

10
MCQeasy

You are configuring an app protection policy in Microsoft Intune for iOS/iPadOS devices. Which setting can you enforce to prevent users from copying data from a managed app and pasting it into an unmanaged app?

A.Restrict cut, copy, and paste between other apps
B.Require a PIN for access
C.Prevent iTunes and iCloud backups
D.Block managed apps from running on jailbroken devices
AnswerA

Restricting cut, copy and paste between other apps blocks clipboard transfer from managed to unmanaged apps on iOS/iPadOS, directly preventing the data-leak scenario. It is an app protection policy setting applied at the app layer.

Why this answer

The 'Restrict cut, copy, and paste between other apps' setting in an Intune app protection policy (APP) for iOS/iPadOS directly controls data transfer between managed and unmanaged apps. When set to 'Blocked' or 'Policy Managed with Paste In', it prevents users from copying data from a managed app and pasting it into an unmanaged app, enforcing data leakage prevention at the OS clipboard level via the Intune MAM SDK.

Exam trap

The trap here is that candidates often confuse device-level restrictions (like jailbreak detection or backup blocking) with app-level data transfer controls, assuming any security setting prevents copy/paste, when only the specific 'Restrict cut, copy, and paste' setting governs clipboard behavior between managed and unmanaged apps.

How to eliminate wrong answers

Option B is wrong because 'Require a PIN for access' controls authentication to the managed app, not data transfer operations like copy/paste; it prevents unauthorized access but does not restrict clipboard sharing. Option C is wrong because 'Prevent iTunes and iCloud backups' protects data at rest by blocking backup to personal cloud or local storage, but it does not address real-time clipboard data movement between apps. Option D is wrong because 'Block managed apps from running on jailbroken devices' is a device-level compliance check that prevents app launch on compromised devices, but it does not restrict copy/paste behavior on compliant devices.

11
MCQhard

You are an endpoint administrator for a company that uses Microsoft Intune. You need to configure a Windows 11 device to support multiple users who will sign in with their Microsoft Entra ID credentials. The device will be shared among shift workers. You want to ensure that each user receives their own configuration profiles and applications. What should you configure?

A.Windows Autopilot pre-provisioning mode.
B.Shared multi-user device configuration profile.
C.Device enrollment manager (DEM) account.
D.Windows Autopilot self-deploying mode.
AnswerB

A shared multi-user device configuration profile in Intune is specifically designed for Windows devices shared by multiple users. It configures settings like guest account, power management, and sign-in options to optimize for shared use. When combined with Microsoft Entra ID, each user can sign in and receive their own policies and applications based on user targeting.

Why this answer

For shared Windows devices used by multiple shift workers, you should configure a shared multi-user device configuration profile. This profile optimizes the device for shared use and allows each user to sign in with their own credentials, receiving personalized settings and applications. It is the correct choice for this scenario.

Exam trap

The trap here is confusing Autopilot modes with shared device configurations; Autopilot modes are for deployment, not for ongoing multi-user management.

12
MCQmedium

Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?

A.Configure enrollment restrictions to require corporate ownership
B.Set device type restrictions to block unregistered devices
C.Configure automatic enrollment via Group Policy
D.Configure Microsoft Entra join or Microsoft Entra registration as a prerequisite for Intune enrollment
AnswerD

Requiring Microsoft Entra join or Microsoft Entra registration before Intune enrolment enforces the identity prerequisite, so unregistered devices are blocked. This satisfies the security team's constraint that every device exist in Microsoft Entra ID prior to Intune management.

Why this answer

Microsoft Entra ID (formerly Azure AD) registration or join is a prerequisite for Intune enrollment. Intune requires a device to have an identity in Entra ID to apply policies and manage compliance. Without this prerequisite, the device cannot authenticate or receive management commands from Intune.

Exam trap

The trap here is that candidates often confuse 'enrollment restrictions' (which control device platform or ownership) with the prerequisite of having an Entra ID identity, leading them to select Option A or B instead of understanding that Entra ID registration is a separate, mandatory step before Intune enrollment can proceed.

How to eliminate wrong answers

Option A is wrong because enrollment restrictions for corporate ownership control how devices are marked (e.g., personal vs. corporate), not whether they are registered in Entra ID. Option B is wrong because device type restrictions block specific platforms or OS versions, not unregistered devices; there is no built-in restriction to block devices that lack an Entra ID registration. Option C is wrong because automatic enrollment via Group Policy enables Intune enrollment for domain-joined devices but does not enforce that the device must be registered in Entra ID before enrollment; it uses a different enrollment method (GPO-triggered MDM enrollment) that may not require prior Entra ID registration.

13
MCQmedium

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that Windows Update for Business policies are applied to these devices to control when feature updates are installed. What should you configure?

A.A device configuration profile with the Windows Update settings.
B.A quality update policy.
C.A Windows 10 and later update ring.
D.A feature update policy.
AnswerC

Update rings in Intune are used to configure Windows Update for Business settings, including feature update deferrals, quality update deferrals, and active hours. By assigning an update ring to the device group, you control when feature updates are installed. This directly meets the requirement to apply Windows Update for Business policies for feature updates. Update rings are the primary method for managing Windows updates in Intune.

Why this answer

Windows Update rings in Intune are the primary way to configure Windows Update for Business settings, including feature update deferrals, quality update deferrals, and active hours. Assigning an update ring to the device group ensures that these policies are applied. Feature update policies are used to target specific versions, but they do not provide the full set of Windows Update for Business controls.

Quality update policies are for expedited updates, and configuration profiles are not the recommended method for update management.

Exam trap

The trap here is confusing update rings with feature update policies; update rings control the overall update cadence, while feature update policies target specific versions.

14
MCQhard

Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?

A.To output the device names of all Windows devices.
B.To list the IDs of Windows devices.
C.To list devices that are registered in Autopilot.
D.To update the enrollment type of all Windows devices.
AnswerB

Correct. The script lists the unique IDs (`DeviceId`) of all Windows devices in Microsoft Entra ID. While the option says 'joined', the script does not filter by join type; it returns all Windows devices in the directory.

Why this answer

The script uses Get-MgDevice with a filter for operatingSystem eq 'Windows' to retrieve all Windows device objects from Microsoft Entra ID, regardless of their join type (joined, registered, or hybrid). By selecting the DeviceId property, it outputs the unique identifiers of these devices. The DeviceId is the Entra ID object identifier, not the device name or Autopilot registration status.

Exam trap

The trap here is confusing DeviceId (the Entra ID object ID) with the device name or Autopilot registration, leading candidates to select options about listing names or Autopilot devices instead of device IDs.

How to eliminate wrong answers

Option A is wrong because the script selects `DeviceId`, not `DisplayName` or `DeviceName`; it outputs IDs, not device names. Option C is wrong because `Get-MgDevice` retrieves all Entra ID registered/joined devices, not specifically Autopilot-registered devices; Autopilot devices are listed via `Get-MgDeviceManagementWindowsAutopilotDeviceIdentity`. Option D is wrong because the script only reads device data with a `Select` operation; it does not call any `Update-MgDevice` cmdlet or modify enrollment type.

15
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?

A.Set feature update deferral to 180 days and quality update deferral to 0 days.
B.Set feature update deferral to 30 days and quality update deferral to 120 days.
C.Set feature update deferral to 120 days and quality update deferral to 30 days.
D.Set both feature and quality update deferrals to 60 days.
AnswerC

Feature and quality update deferrals are separate settings within a Windows 10 update ring, each measured in days from release. Configuring 120 days for feature updates and 30 days for quality updates directly satisfies both constraints in the stem, since Intune applies these independently per ring without affecting the other update type.

Why this answer

The Windows 10 update ring settings in Microsoft Intune allow you to specify deferral periods for feature updates and quality updates independently. To meet the requirement of deferring feature updates by 120 days and quality updates by 30 days, you must set the feature update deferral to 120 days and the quality update deferral to 30 days. These values directly control how long the device waits before installing the respective update types after Microsoft releases them.

Exam trap

The trap here is that candidates often confuse the deferral periods for feature and quality updates, mistakenly swapping the values or assuming a single deferral applies to both, when the question explicitly requires independent settings for each update type.

How to eliminate wrong answers

Option A is wrong because setting feature update deferral to 180 days exceeds the required 120-day deferral, and setting quality update deferral to 0 days provides no deferral, failing the 30-day requirement. Option B is wrong because it reverses the deferral periods: feature updates would be deferred only 30 days (not 120) and quality updates would be deferred 120 days (not 30), which does not match the specified requirements. Option D is wrong because setting both deferrals to 60 days would defer feature updates by only 60 days instead of the required 120 days, and quality updates by 60 days instead of 30 days, failing both conditions.

16
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Users run a line-of-business desktop app that writes configuration data to HKEY_CURRENT_USER. After you deploy the app as a Win32 app with an install context of System, users report that their settings are not saved between sessions. You need to ensure that each user's settings persist in their own profile while the app still installs without user interaction. What should you do?

A.Wrap the app in a Win32 app package that includes a PowerShell script to copy HKCU settings to HKLM at logoff.
B.Add a requirement rule that targets only Windows 11 devices and redeploy the app.
C.Configure the app's detection rule to check for the registry key under HKEY_CURRENT_USER.
D.Change the app's install context to User and redeploy the app.
AnswerD

Setting the install context to User makes the app run under each signed-in user's context, so HKEY_CURRENT_USER writes go to that user's own hive and persist between sessions. The app is already packaged as a Win32 app, so only the context needs to change. Installing in System context runs the app under the local system account, whose HKCU hive is not the user's profile.

Why this answer

Win32 apps deployed by Intune can run in either User or System context. System context installs with elevated rights and writes to the system account's profile, so per-user HKCU data is not preserved for the signed-in user. Switching the install context to User makes the app run per user, allowing HKCU writes to land in each user's profile and persist.

Exam trap

The trap here is assuming that changing detection rules or requirement rules changes the runtime context of a Win32 app, when only the install context setting controls whether the app runs as the user or as the system account.

17
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. The company has a line-of-business iOS app that is not available in the App Store. You need to deploy this app to a group of iOS users. The app must be installed automatically without user interaction. What should you do first?

A.Upload the app package (.ipa file) to Intune as a line-of-business app.
B.Add the app to Microsoft Store for Business and sync it with Intune.
C.Configure a device configuration profile to install the app.
D.Create an app protection policy for the app.
AnswerA

Uploading the .ipa file as a line-of-business app is the required first step to make the app available in Intune. Once uploaded, you can assign it to groups and configure installation intent as required for automatic installation. This directly addresses the need to deploy a custom iOS app.

Why this answer

To deploy a custom iOS app, you must first upload the app package (.ipa file) to Intune as a line-of-business app. This makes the app available for assignment. After uploading, you can assign it to groups and set the installation intent to required for automatic installation.

The other options do not provide a deployment method for custom apps.

Exam trap

The trap here is confusing app deployment with app protection or configuration, which do not install apps.

18
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?

A.Create a device configuration profile that requires iOS 16.0.
B.Modify the enrollment profile to require iOS 16.0.
C.Create a compliance policy that requires iOS 16.0 or later.
D.Create an enrollment platform restriction for iOS/iPadOS and set the minimum OS version to 16.0.
AnswerD

Enrollment platform restrictions let you block or allow iOS/iPadOS enrolment and specify a minimum OS version, so devices below iOS 16 are refused at enrolment. This satisfies the requirement before device management begins, unlike a compliance policy which only flags non-compliance afterwards.

Why this answer

Enrollment platform restrictions in Intune let you define the minimum and maximum OS versions allowed to enroll for each platform, including iOS/iPadOS. Setting the minimum OS version to 16.0 blocks enrollment of devices running older versions at the enrollment gate. This is the correct control because the requirement is about enrollment eligibility, not ongoing compliance.

Exam trap

MD-102 often tests the difference between enrollment restrictions (block enrollment) and compliance policies (block access after enrollment) — candidates frequently choose compliance when the scenario says 'can enroll.'

How to eliminate wrong answers

Option A is wrong because a device configuration profile applies settings to already-enrolled devices and cannot block enrollment based on OS version. Option B is wrong because enrollment profiles (like the Apple enrollment profile) configure enrollment behavior (supervision, setup assistant panes) but do not enforce minimum OS versions. Option C is wrong because a compliance policy evaluates enrolled devices and marks them noncompliant — it does not prevent enrollment in the first place.

19
MCQeasy

A company uses Microsoft Intune to manage iOS devices. They want to enforce a policy that requires a passcode of at least 6 characters and auto-lock after 5 minutes. Which configuration profile type should they use?

A.Device restrictions profile.
B.Wi-Fi profile.
C.VPN profile.
D.Email profile.
AnswerA

Device restrictions profiles expose iOS passcode settings directly, including minimum passcode length and maximum minutes of inactivity before auto-lock. Assigning this profile to the device group enforces both the six-character and five-minute requirements, which the other profile types cannot satisfy.

Why this answer

A Device restrictions profile is the correct configuration profile type because it contains the security settings for iOS devices, including passcode requirements (minimum length, complexity) and device lock timeouts (auto-lock after minutes). This profile type enforces device-level security policies directly managed by Intune, making it the appropriate choice for requiring a 6-character passcode and 5-minute auto-lock.

Exam trap

The trap here is that candidates often confuse Device restrictions profiles with Compliance policies, but Compliance policies evaluate settings after they are applied, whereas Device restrictions profiles actually enforce the settings on the device.

How to eliminate wrong answers

Option B is wrong because a Wi-Fi profile is used to configure wireless network settings (SSID, authentication, certificates) and does not include passcode or auto-lock policies. Option C is wrong because a VPN profile configures virtual private network connections (server address, tunneling protocol, authentication) and has no settings for device passcode or lock timeout. Option D is wrong because an Email profile configures email account settings (server, username, SSL) and does not enforce device-level security policies like passcode length or auto-lock.

20
Multi-Selectmedium

You are configuring an app protection policy for iOS devices to protect corporate data in Microsoft Outlook. Which TWO settings prevent users from copying corporate data to personal apps?

Select 2 answers
A.Allow app to transfer data to other apps
B.Save copies of work data
C.Block screen capture and screen recording
D.Restrict cut, copy, and paste between apps
E.Encrypt app data
AnswersA, D

Setting app transfer to none blocks Outlook from sending corporate data to unmanaged personal apps, satisfying the requirement to prevent copying outside the protected boundary. Combined with cut, copy and paste restrictions, it enforces data containment at the app layer rather than relying on device management.

Why this answer

Option A, 'Allow app to transfer data to other apps,' is correct because setting it to 'None' or 'Policy managed apps' restricts Outlook from sharing or transferring corporate data to unmanaged personal apps, directly preventing data leakage to personal apps. Option D, 'Restrict cut, copy, and paste between apps,' is correct because configuring it to 'Policy managed apps' or 'Policy managed apps with paste in' prevents users from copying corporate content from Outlook and pasting it into personal apps. Option B, 'Save copies of work data,' controls whether users can save copies of corporate data to personal storage locations but does not specifically govern app-to-app copying.

Option C, 'Block screen capture and screen recording,' prevents screenshots of corporate data but does not stop copying data into personal apps. Option E, 'Encrypt app data,' protects data at rest on the device but does not prevent users from copying corporate data to personal apps.

Exam trap

The trap here is that candidates often confuse 'Block screen capture and screen recording' with data loss prevention, but it only prevents visual capture, not clipboard or app-to-app data transfer, which are the actual vectors for copying corporate data to personal apps.

21
MCQhard

You are a Microsoft 365 Endpoint Administrator for a global organization with 5,000 Windows 11 devices managed by Intune. The company has a strict security policy requiring that all devices have BitLocker enabled with TPM validation, PIN, and startup key. Currently, only 80% of devices are compliant with BitLocker. After investigating, you discover that many non-compliant devices are older models that lack TPM 2.0, but they do have TPM 1.2. Additionally, some devices are virtual machines (VMs) that do not have a TPM at all. The security team insists that all devices must be encrypted, but they are willing to accept alternative configurations for devices without TPM 2.0. You need to propose a solution that maximizes security while ensuring compliance. What should you do?

A.Create a single compliance policy that requires BitLocker with TPM validation, PIN, and startup key, and exclude devices without TPM 2.0 from the policy.
B.Modify the existing compliance policy to remove the PIN requirement so that all devices can comply.
C.Create multiple compliance policies: one for devices with TPM 2.0 requiring full BitLocker, one for devices with TPM 1.2 requiring BitLocker with TPM validation, and one for VMs requiring BitLocker with startup password.
D.Downgrade all non-compliant devices to Windows 10 and enable BitLocker with TPM 1.2.
AnswerC

This addresses different hardware capabilities while maintaining encryption.

Why this answer

It uses multiple compliance policies to enforce the strongest possible BitLocker configuration based on each device's TPM capabilities. Devices with TPM 2.0 can meet the full requirement (TPM validation, PIN, startup key), devices with TPM 1.2 can use TPM-only validation (since TPM 1.2 does not support PIN+startup key in the same way), and VMs without a TPM can use a startup password. This approach maximizes security while ensuring all devices remain compliant with the security policy's intent.

Exam trap

The trap here is that candidates assume a single compliance policy with exclusions is sufficient, but they overlook the need to enforce encryption on all devices by tailoring the BitLocker requirements to each device's TPM capabilities.

How to eliminate wrong answers

Option A is wrong because excluding devices without TPM 2.0 from the policy would leave them unmonitored and non-compliant, violating the requirement that all devices must be encrypted. Option B is wrong because removing the PIN requirement weakens security for devices that do support TPM 2.0, and it does not address the specific limitations of TPM 1.2 or VMs. Option D is wrong because downgrading to Windows 10 does not solve the TPM 1.2 or missing TPM issue; BitLocker on Windows 10 still requires a TPM (1.2 or 2.0) for TPM-only protection, and VMs still lack a TPM, so this would not achieve compliance.

22
MCQeasy

Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?

A.The device's hardware hash, uploaded to Intune, and an Autopilot deployment profile assigned.
B.The Configuration Manager client and a site code for automatic site assignment.
C.A provisioning package containing the MDM enrollment settings.
D.A Group Policy Object that configures automatic MDM enrollment.
AnswerA

Uploading the hardware hash registers the device with the Autopilot service, and the assigned deployment profile drives the out-of-box experience to join Microsoft Entra ID, auto-enrol in Intune, and trigger required app installation on first boot.

Why this answer

Windows Autopilot requires the device's hardware hash to be uploaded to Intune so that the device can be identified as an Autopilot device. An Autopilot deployment profile is then assigned to the device, which specifies the settings for joining Microsoft Entra ID, enrolling in Intune, and installing required applications during the first boot (Out-of-Box Experience). This combination ensures the entire provisioning flow occurs automatically without manual intervention.

Exam trap

The trap here is that candidates often confuse provisioning packages (PPKG) with Autopilot, but Autopilot is specifically designed to eliminate the need for any local media or manual steps, relying solely on cloud-based device identity and profile assignment.

How to eliminate wrong answers

Option B is wrong because the Configuration Manager client and site code are used for co-management or traditional client management, not for Windows Autopilot's zero-touch provisioning which relies on cloud-based enrollment via Intune. Option C is wrong because a provisioning package (PPKG) is used for manual or bulk provisioning via Windows Configuration Designer, not for the automatic, cloud-driven Autopilot process that requires no local media or USB drive. Option D is wrong because Group Policy Objects (GPOs) are applied after the device is already joined to the domain and enrolled, and they cannot trigger the initial Autopilot enrollment flow which happens before the device has network access to a domain controller.

23
Multi-Selecthard

You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?

Select 2 answers
A.Ensure the device is in the correct Microsoft Entra ID group targeted by the policy.
B.Reissue the user's Microsoft 365 license from the admin center.
C.Reset the device's enrollment state via the Company Portal.
D.Verify that the device has an active internet connection and can reach Intune services.
E.Run Invoke-Command to remotely execute gpupdate /force.
AnswersA, D

Policy assignment flows through Microsoft Entra ID group membership, so a device outside the targeted group never receives the configuration. Confirming correct group membership restores delivery of the security policy and clears the noncompliant state.

Why this answer

Option A is correct because Intune policies are assigned to Microsoft Entra ID groups, so if the device (or its user) is not a member of the group targeted by the security policy, the policy will never be delivered and the device will remain non-compliant. Option D is correct because Intune is a cloud-based MDM service; the device must have an active internet connection and be able to reach Intune endpoints (e.g., *.manage.microsoft.com over TCP 443) for policy sync, check-in, and compliance evaluation to occur. Option B is not relevant because Microsoft 365 licensing affects access to services like Exchange and Office, not Intune policy delivery or compliance state.

Option C is not appropriate because resetting enrollment state via the Company Portal is a drastic remediation that removes management and would not fix a group-targeting or connectivity issue. Option E is incorrect because gpupdate /force applies on-premises Active Directory Group Policy, not Intune MDM policies, and Invoke-Command targets PowerShell remoting rather than Intune policy sync.

Exam trap

The trap here is that candidates often confuse Intune MDM policy delivery with traditional on-premises Group Policy, leading them to select the gpupdate command (Option E) instead of recognizing that Intune relies on OMA-DM sync and network connectivity.

24
MCQeasy

A company wants to prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. What should they configure?

A.Intune app protection policy
B.Device compliance policy
C.Microsoft Defender for Cloud Apps session policy
D.Conditional Access policy
AnswerA

An Intune app protection policy applies MAM restrictions to managed Microsoft 365 apps, blocking cut, copy and paste of corporate content into personal apps on iOS without requiring device enrolment. This satisfies the requirement to prevent copying corporate data to personal apps.

Why this answer

Intune app protection policies (APP) are designed to manage and protect corporate data within applications, regardless of the device management state. By configuring data protection settings such as 'Allow app to transfer data to other apps' set to 'Policy managed apps only' and 'Save copies of org data' set to 'Block', you can prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. This policy applies at the app layer, using the Intune App SDK or MAM (Mobile Application Management) channel, and does not require device enrollment.

Exam trap

The trap here is that candidates often confuse app protection policies (MAM) with device compliance or Conditional Access, mistakenly thinking that device-level controls can restrict app-to-app data transfer, when in fact only app-layer policies can enforce granular data protection like copy/paste restrictions.

How to eliminate wrong answers

Option B is wrong because device compliance policies evaluate device health and configuration (e.g., jailbreak detection, minimum OS version) but do not control data transfer between apps; they enforce compliance at the device level, not the app data layer. Option C is wrong because Microsoft Defender for Cloud Apps session policies control access and data exfiltration in real-time via reverse proxy for web apps (e.g., blocking downloads in a browser), but they do not apply to native mobile apps or control copy/paste between apps on iOS. Option D is wrong because Conditional Access policies enforce access controls (e.g., require compliant device, MFA) at sign-in, but they do not govern data movement or copy/paste behavior after authentication; they are an access gate, not a data protection mechanism.

25
MCQeasy

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. Users report that their devices are not receiving newly assigned compliance policies. You need to force the devices to check in with Intune immediately. What should you do from the Intune admin center?

A.Remove and re-enroll each device in Intune.
B.Run the 'gpupdate /force' command on each device.
C.Select each device and choose 'Sync' to initiate a device check-in.
D.Restart the Intune Management Extension service on each device.
AnswerC

The Sync action in the Intune admin center triggers an immediate check-in with the Intune service. This causes the device to download and apply any pending policies, including compliance policies. It is the correct and least disruptive method to force policy retrieval without waiting for the regular check-in interval.

Why this answer

The Sync action in the Intune admin center sends a remote check-in request to the device, prompting it to contact the Intune service and apply any pending policies. This is the standard, efficient way to force policy retrieval without user intervention or disruptive re-enrollment.

Exam trap

The trap here is confusing Group Policy refresh commands like gpupdate with Intune MDM policy sync, which requires the Intune Sync action.

26
MCQmedium

You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?

A.Device restrictions configuration policy
B.Device compliance policy
C.App configuration policy
D.Enrollment restriction
AnswerA

Android Enterprise device restrictions policies expose a dedicated control that blocks installation from unknown sources, directly enforcing the requirement. App configuration policies only supply app settings, and compliance policies report state rather than prevent installation, so restrictions is the correct type.

Why this answer

Device restrictions configuration policies in Microsoft Intune are designed to control built-in device settings and hardware features, including security-related options like blocking installation from unknown sources. For Android Enterprise, this policy type directly maps to the 'Unknown sources' setting under Device Restrictions, allowing you to prevent sideloading of apps. Compliance policies only evaluate conditions and mark devices as compliant or non-compliant; they do not enforce configuration changes.

App configuration policies deliver app-specific settings (e.g., server URLs) to managed apps, and enrollment restrictions control which devices can enroll, not what users can do after enrollment.

Exam trap

MD-102 often tests the confusion between configuration policies (which enforce settings) and compliance policies (which evaluate and report), so candidates may incorrectly choose a compliance policy thinking it will block the action.

How to eliminate wrong answers

Option B is wrong because a device compliance policy only assesses device state against rules (e.g., OS version, encryption) and reports compliance; it cannot block app installation from unknown sources. Option C is wrong because an app configuration policy provides custom settings to individual apps (like Outlook or Chrome) after they are installed, and does not control device-level installation permissions. Option D is wrong because enrollment restrictions define which devices or platforms are allowed to enroll in Intune, not what settings apply after enrollment.

27
Drag & Dropmedium

Order the steps to deploy a Windows 10 virtual desktop in Azure using Windows 365.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Deploying Windows 10 virtual desktops via Windows 365 requires a specific sequence: first, ensure you have the appropriate licenses (Windows 365 Enterprise or Business). Then access the Microsoft Endpoint Manager admin center, create a provisioning policy, and configure its settings (e.g., network, management). After the policy is configured, you can provision Cloud PCs in bulk.

Finally, assign the Cloud PCs to users. Common mistakes include swapping the order of licensing and portal access, configuring after provisioning, or assigning before provisioning.

28
Multi-Selecthard

You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?

Select 3 answers
A.Apple Push Notification service certificate (for iOS)
B.Intune licenses assigned to users
C.Microsoft Entra ID (for identity and device registration)
D.Microsoft Intune subscription (for MDM authority)
E.Configuration Manager (for co-management)
AnswersB, C, D

Users must have Intune licenses to enroll devices.

Why this answer

Intune licenses must be assigned to users to grant them access to the service. Without a license, the user cannot authenticate with Intune, and automatic enrollment will fail during the device registration step. This is a prerequisite enforced by Microsoft Entra ID and Intune together.

Exam trap

The trap here is that candidates often confuse prerequisites for device management (like APNs certificate) with prerequisites for automatic enrollment, leading them to select Apple Push Notification service certificate as a required component when it is only needed after enrollment for iOS device management.

29
Multi-Selecthard

You are preparing infrastructure for Windows Autopilot at Contoso. You need to configure the environment so that devices can be deployed with Windows Autopilot in Microsoft Entra hybrid join mode. Which two components must be in place before devices can complete the hybrid join during OOBE? (Choose two.)

Select 2 answers
A.A device compliance policy requiring BitLocker and Secure Boot.
B.A Configuration Manager site system role for the enrollment proxy point.
C.A Windows Autopilot deployment profile configured with the Microsoft Entra hybrid joined join type.
D.The Intune Connector for Active Directory installed on a server with access to the on-premises domain.
E.A conditional access policy requiring multifactor authentication for all users.
AnswersC, D

A deployment profile set to Microsoft Entra hybrid joined tells the device to perform an on-premises domain join and then register with Entra ID. Without this profile, devices default to Entra joined or do not receive the correct OOBE behavior. It is a required configuration alongside the connector for hybrid join to succeed.

Why this answer

Autopilot hybrid join requires the Intune Connector for Active Directory to perform the offline domain join and a deployment profile configured for Microsoft Entra hybrid joined to direct the device through the correct OOBE path. Compliance policies, Configuration Manager enrollment proxy points, and Conditional Access policies do not perform the domain join or Entra registration steps, so they are not prerequisites for completing hybrid join.

Exam trap

The trap here is selecting Configuration Manager components or security policies as prerequisites, when the two essential elements are the AD connector and the hybrid-joined deployment profile.

30
MCQhard

An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?

A.Device configuration profile to enable BitLocker
B.Device compliance policy with a noncompliance action to mark device as non-compliant
C.PowerShell script deployment with assignment to all devices
D.Proactive remediations with a detection script for BitLocker status and a remediation script to enable BitLocker
AnswerD

Proactive remediations run a detection script on a schedule and execute a remediation script only when detection reports non-compliance, satisfying the automatic BitLocker enablement requirement. This differs from configuration profiles, which enforce settings but cannot run conditional script logic.

Why this answer

Proactive remediations in Microsoft Intune are specifically designed to detect and automatically fix common configuration drift on managed devices. By using a detection script to check BitLocker status and a remediation script to enable BitLocker, this feature meets the requirement for automatic remediation without user interaction or manual re-mediation.

Exam trap

The trap here is that candidates often confuse Proactive remediations with simple script deployment, not realizing that Proactive remediations provide a detection-then-remediation loop that automatically re-applies the fix when drift is detected, whereas a one-time script deployment does not.

How to eliminate wrong answers

Option A is wrong because a device configuration profile can enable BitLocker on new or compliant devices, but it does not automatically remediate devices that later become non-compliant (e.g., after a user disables BitLocker). Option B is wrong because a device compliance policy with a noncompliance action only marks the device as non-compliant and can trigger conditional access blocks, but it does not run a PowerShell script to re-enable BitLocker. Option C is wrong because PowerShell script deployment runs the script once at assignment or during a scheduled sync, but it lacks the detection-and-remediation loop that Proactive remediations provide; it cannot automatically re-run when BitLocker is disabled again.

31
MCQmedium

Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?

A.The devices failed to enroll properly.
B.The compliance policy includes a rule for 'Maximum days since last check-in' and these devices exceeded that limit.
C.The devices are running a non-Windows operating system.
D.The devices have names that do not match the naming convention.
AnswerB

A compliance policy rule of 'Maximum days since last check-in' directly marks devices noncompliant once their lastSyncDateTime exceeds the configured threshold. Since the exhibit shows lastSyncDateTime older than 30 days, those devices breached that rule, which explains the noncompliant complianceState without any other cause.

Why this answer

The compliance policy includes a rule for 'Maximum days since last check-in', which checks the `lastSyncDateTime` property. Devices that have not synced within the configured threshold (e.g., 30 days) are marked as noncompliant. This is a common Intune compliance setting for Windows devices to ensure they regularly communicate with the service.

Exam trap

The MD-102 exam often tests the distinction between enrollment failures and compliance violations; the trap here is that candidates may incorrectly attribute noncompliance to enrollment issues rather than recognizing that a valid `lastSyncDateTime` indicates successful enrollment, and the noncompliant state is due to a missed check-in threshold.

How to eliminate wrong answers

Option A is wrong because failed enrollment would prevent the device from appearing in the output at all, or it would show an enrollment failure state, not a compliance state of 'noncompliant' with a valid lastSyncDateTime. Option C is wrong because the PowerShell command specifically retrieves Windows devices (as stated in the question), and non-Windows OS devices would not be returned by this query. Option D is wrong because device naming conventions are not a compliance policy setting in Intune; naming is used for identification and management, not compliance evaluation.

32
Multi-Selecteasy

You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?

Select 2 answers
A.Android Zero Touch.
B.Microsoft Entra ID join with automatic MDM enrollment.
C.Apple Business Manager.
D.Windows Autopilot.
E.Samsung Knox Mobile Enrollment.
AnswersB, D

Microsoft Entra ID join with automatic MDM enrolment configures the device to join the tenant and register with Intune during OOBE or via Group Policy. This satisfies the stem's requirement for a valid Windows enrolment method using cloud identity.

Why this answer

The correct answers are B (Microsoft Entra ID join with automatic MDM enrollment) and D (Windows Autopilot). Both are valid methods to enroll Windows devices into Microsoft Intune. Option A (Android Zero Touch) is for Android devices, not Windows.

Option C (Apple Business Manager) is for Apple devices. Option E (Samsung Knox Mobile Enrollment) is for Samsung Android devices.

33
Multi-Selecthard

Which THREE of the following are requirements for deploying a Win32 app via Microsoft Intune?

Select 3 answers
A.The device must have the Intune Management Extension installed separately.
B.The app installation files must be hosted on an external web server.
C.The app must be assigned to a group of users or devices.
D.Detection rules must be configured to verify installation.
E.The app must be packaged in the .intunewin format.
AnswersC, D, E

A Win32 app must be assigned to a user or device group before Intune delivers it; without an assignment, no device receives the app. This is a mandatory requirement alongside the management extension and packaging.

Why this answer

Option C is correct because a Win32 app in Intune must be assigned to an Azure AD user or device group (required, available, or uninstall intent) before it can be delivered to any endpoint. Option D is correct because Intune requires detection rules (file, folder, registry, MSI product code, or custom script) to determine whether the app is already installed and to report installation status. Option E is correct because Win32 apps must be wrapped with the Microsoft Win32 Content Prep Tool into the .intunewin package format before upload to Intune.

Option A is not required because the Intune Management Extension is installed automatically on Windows devices when a Win32 app or PowerShell script is assigned, not installed separately by the admin. Option B is not required because the app content is uploaded to and hosted by Intune (or delivered via the CDN), not on an external web server.

Exam trap

The trap here is that candidates often confuse the automatic installation of the Intune Management Extension with a manual prerequisite, or assume that Win32 app files must be hosted externally rather than leveraging Intune's built-in cloud storage.

34
MCQhard

You are preparing infrastructure for device management at Adventure Works. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Intune. You need to configure a Windows Autopilot deployment profile that will be used for Microsoft Entra hybrid join. During testing, devices fail at the domain join step. You verify that the Intune Connector for Active Directory is installed and online. What should you check next?

A.The device has a TPM 2.0 chip and is UEFI-enabled.
B.The organizational unit (OU) specified in the deployment profile exists and the connector service account has permission to create computer objects in it.
C.The Microsoft Entra ID join type is set to Microsoft Entra joined instead of Microsoft Entra hybrid joined.
D.The Windows Autopilot deployment profile is assigned to a device group and not a user group.
AnswerB

For hybrid join, the Intune Connector for Active Directory uses a service account to create the computer object in the OU specified in the Autopilot deployment profile. If the OU path is invalid or the account lacks Create Computer Objects permission, the domain join fails even when the connector is online. Verifying the OU and permissions is the logical next step.

Why this answer

When the Intune Connector for Active Directory is online but hybrid join still fails, the next checks are the organizational unit specified in the deployment profile and the permissions of the connector's service account. The connector creates the computer object in that OU, so an invalid OU path or insufficient rights prevents the domain join. TPM, UEFI, group assignment, and join type are not the cause when devices already reach the domain join step.

Exam trap

The trap here is stopping at the connector's online status and overlooking that the connector still needs a valid OU path and an account with rights to create computer objects.

35
MCQeasy

You need to wipe a lost corporate-owned iOS device that is enrolled in Intune. Which action should you perform?

A.Delete the device from Intune.
B.Retire the device.
C.Wipe the device.
D.Disable the device.
AnswerC

Wipe performs a full factory reset, removing all data and settings, which suits a lost corporate-owned device where data must not remain accessible. Retire would only remove corporate data, leaving personal content intact, so wipe is the appropriate action.

Why this answer

The correct action is to wipe the device because a corporate-owned iOS device that is lost requires a full factory reset to remove all data and prevent unauthorized access. In Microsoft Intune, the 'Wipe' action performs a factory reset, returning the device to its out-of-box state and removing all corporate and personal data, which is appropriate for a lost corporate-owned device.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', assuming both achieve the same result, but 'Retire' is designed for BYOD scenarios where personal data must be preserved, while 'Wipe' is required for corporate-owned devices that need complete data sanitization.

How to eliminate wrong answers

Option A is wrong because deleting the device from Intune only removes it from the management console without initiating any remote wipe or data removal, leaving the device fully functional with all data intact. Option B is wrong because retiring the device removes only managed apps and corporate data but preserves personal data, which is insufficient for a lost corporate-owned device that must be completely sanitized. Option D is wrong because disabling the device is not a supported Intune action for iOS devices; Intune offers 'Retire' and 'Wipe' actions, and 'Disable' is a generic term that does not correspond to any specific remote management command.

36
Multi-Selecteasy

Which TWO of the following are valid app types in Microsoft Intune for iOS/iPadOS devices?

Select 2 answers
A.Windows 10 Universal app
B.iOS line-of-business app
C.Android Enterprise system app
D.Managed Google Play iframe
E.iOS store app
AnswersB, E

iOS line-of-business apps are a valid Intune app type, packaging signed .ipa files for deployment to enrolled iOS/iPadOS devices. This satisfies the stem's requirement for a supported app type, distinct from store apps, web links and built-in apps, and is uploaded directly through Microsoft Intune rather than the App Store.

Why this answer

In Microsoft Intune, the iOS/iPadOS app types include 'iOS line-of-business app' (B), which lets you upload and deploy an in-house .ipa package signed with your enterprise provisioning profile, and 'iOS store app' (E), which deploys apps by searching and selecting them from the Apple App Store. Both are legitimate iOS/iPadOS app categories available when adding an app in the Intune console. By contrast, 'Windows 10 Universal app' (A) targets Windows 10/11 devices, 'Android Enterprise system app' (C) targets Android Enterprise devices, and 'Managed Google Play iframe' (D) is an Android app type used to browse and approve Managed Google Play apps, so none of these apply to iOS/iPadOS.

Exam trap

The trap in this question is that candidates might select 'Managed Google Play iframe' thinking it is a generic web app type, but it is strictly an Android Enterprise feature and not valid for iOS/iPadOS devices in Microsoft Intune.

37
MCQmedium

You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?

A.Use the Microsoft Store for Business to automatically register devices
B.Contact the OEM to register the devices using the device serial numbers
C.Use the Windows Configuration Designer to create a provisioning package that includes Autopilot settings
D.Upload the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center
AnswerD

Uploading the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center registers each device, creating an Autopilot device record that can then be targeted by a deployment profile. This satisfies the requirement to associate devices with profiles.

Why this answer

Uploading the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center is the standard method to register devices for Windows Autopilot. Option A is incorrect because the Microsoft Store for Business is deprecated and no longer supports Autopilot registration. Option B is incorrect because while OEMs can register devices, you already have the hardware hashes, making direct upload more efficient.

Option C is incorrect because Windows Configuration Designer is used to create provisioning packages for manual setup, not for Autopilot device registration.

38
Multi-Selecthard

Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?

Select 3 answers
A.Run a detection script to identify issues.
B.Send email alerts when issues are detected.
C.Schedule scripts to run at regular intervals.
D.Run a remediation script to fix issues.
E.Mark devices as non-compliant if remediation fails.
AnswersA, C, D

Detection scripts execute first to assess device state, returning exit code 0 for compliant or non-zero for non-compliant, which triggers the paired remediation script. This satisfies the stem's requirement for actions available in proactive remediations, where detection is the mandatory first stage before any corrective action runs on the Windows device.

Why this answer

Proactive remediations in Microsoft Intune are built on a two-part script package, so option A is correct: each remediation includes a detection script that runs first to identify whether a problem exists on the Windows device. Option D is also correct because, when the detection script reports a non-compliant state, the paired remediation script executes to fix the identified issue. Option C is correct as well, since proactive remediations are assigned to device groups and run on a configurable schedule (for example, daily or hourly) rather than only once.

Option B is not part of proactive remediations, as Intune does not send email alerts as a built-in remediation action; reporting is surfaced through Intune reports and Endpoint Analytics. Option E is incorrect because proactive remediations do not change device compliance state — compliance is governed separately by compliance policies, and remediation scripts only detect and fix issues.

Exam trap

The trap here is that candidates often confuse proactive remediations with compliance policies or alerting features, assuming that failed remediation can automatically trigger non-compliance or email notifications, but Intune separates these functions into distinct policies and requires additional configuration for alerts.

39
MCQeasy

Your organization uses Windows Autopilot for device provisioning. Users report that after initial setup, devices are not automatically enrolled in Microsoft Intune. What should you verify?

A.That a device configuration profile is assigned to the devices.
B.That the devices are registered in Windows Autopilot with a valid hardware hash.
C.That a Conditional Access policy is in place requiring Intune enrollment.
D.That a device compliance policy is assigned to the Autopilot devices.
AnswerB

Autopilot requires each device's unique hardware hash registered as an Autopilot device before deployment, which links the device to your tenant and drives Intune enrolment. Without a valid hash, the profile cannot target the device, so automatic enrolment silently fails.

Why this answer

Windows Autopilot requires devices to be registered in the Autopilot service with a valid hardware hash (or other unique identifier like PKID or serial number) so that the service can match the device during OOBE and trigger the enrollment process into Intune. Without a valid hardware hash, the device will not be recognized by Autopilot and will proceed through standard OOBE without automatic Intune enrollment.

Exam trap

The trap here is that candidates often confuse post-enrollment policies (configuration profiles, compliance, Conditional Access) with the prerequisite registration step, assuming any assigned policy will force enrollment, when in fact the device must first be recognized by Autopilot via a valid hardware hash.

How to eliminate wrong answers

Option A is wrong because a device configuration profile is used to apply settings after enrollment, not to trigger enrollment itself; Autopilot enrollment happens before configuration profiles are applied. Option C is wrong because Conditional Access policies control access to resources after enrollment, they do not initiate or enforce the enrollment process during Autopilot. Option D is wrong because device compliance policies are evaluated after a device is enrolled in Intune, they have no role in the initial enrollment step.

40
MCQeasy

You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

A.Upload the app package as an iOS LOB app in Intune
B.Add the app as a Volume Purchase Program (VPP) app
C.Use an Enterprise Code Signing certificate to deploy via MDM
D.Publish the app to the Apple App Store and deploy as public app
AnswerA

iOS LOB apps are uploaded as .ipa packages signed with an enterprise distribution certificate, letting Intune push them directly to supervised or enrolled devices without the App Store. This satisfies the stem's enterprise-signed, 100-device constraint.

Why this answer

Intune supports deploying internally developed LOB apps to iOS devices by uploading the signed .ipa package directly. Since the app is already signed with an enterprise certificate, it can be distributed via Intune's iOS LOB app workflow without requiring the Apple App Store or VPP.

Exam trap

The trap here is confusing the signing certificate (used to sign the app) with the deployment method, leading candidates to select Option C, which describes a prerequisite rather than a distribution mechanism.

How to eliminate wrong answers

Option B is wrong because Volume Purchase Program (VPP) apps are purchased from the Apple App Store and assigned to devices via managed distribution, not used for custom LOB apps. Option C is wrong because Enterprise Code Signing certificates are used to sign the app, not as a deployment method; MDM deploys the app via Intune's LOB app upload, not by using the certificate directly. Option D is wrong because publishing to the Apple App Store is unnecessary and contradicts the requirement to deploy a signed LOB app; public apps are for store-distributed apps, not enterprise-signed ones.

41
MCQhard

Your company uses Microsoft Intune to manage Windows 11 devices. A security policy requires that devices automatically receive quality updates as soon as they are available, with a deadline of 2 days after release and automatic restart outside active hours. You create a Windows update ring in Intune. Which setting should you configure to meet the deadline requirement?

A.Set 'Restart checks' to 'Allow' and configure 'Auto restart' to 'Always'.
B.Set 'Automatic update behavior' to 'Auto install and restart at maintenance time'.
C.Set 'Update deadline' to 2 days and configure 'Grace period' as needed.
D.Set 'Active hours start' and 'Active hours end' to define the restart window.
AnswerC

The update deadline setting in a Windows update ring specifies the number of days after an update is available before it is forcibly installed and the device restarts. Setting it to 2 days meets the requirement. The grace period can allow users to postpone within that deadline.

Why this answer

A Windows update ring in Intune includes an 'Update deadline' setting that forces installation and restart after a specified number of days. Setting it to 2 days ensures quality updates are installed and the device restarts within two days of release, meeting the security policy. Other settings like active hours or auto restart do not enforce the deadline.

Exam trap

The trap here is confusing the deadline setting with automatic update behavior or active hours, which control timing but do not enforce a mandatory installation deadline.

42
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. The security team requires that BitLocker recovery keys be automatically escrowed to Microsoft Entra ID before a device is marked compliant. You need to configure a compliance policy setting that enforces this. Which setting should you configure?

A.Require Trusted Platform Module (TPM)
B.Require storage encryption
C.Require BitLocker recovery key backup
D.Require BitLocker
AnswerC

This setting explicitly verifies that the BitLocker recovery key has been backed up to Microsoft Entra ID. When enabled in a compliance policy, the device is marked non-compliant if the key is not escrowed. This directly enforces the security team's requirement that keys be escrowed before compliance is granted, ensuring recovery keys are available for administrative recovery.

Why this answer

The requirement is that BitLocker recovery keys are escrowed to Microsoft Entra ID before a device is compliant. The compliance policy setting 'Require BitLocker recovery key backup' specifically validates that the recovery key has been backed up to Microsoft Entra ID. Other BitLocker-related settings check for encryption or TPM presence but do not enforce escrow, so they would not satisfy the security team's condition.

Exam trap

The trap here is confusing general BitLocker enforcement with the specific recovery key escrow requirement, assuming that enabling 'Require BitLocker' automatically ensures key backup.

43
MCQmedium

You manage Windows 11 devices enrolled in Microsoft Intune. Security requires that devices with unsupported antivirus signatures be blocked from accessing Microsoft 365 resources. You create a compliance policy that sets the Microsoft Defender Antivirus requirement to 'Require' and the 'Antivirus signature age' to 3 days. A device reports an antivirus signature age of 5 days. What is the resulting device state?

A.The device is marked compliant but a remediation script is triggered.
B.The device is marked compliant because the signature age is not evaluated.
C.The device is marked noncompliant.
D.The device is marked noncompliant only if the user has not signed in for 30 days.
AnswerC

The compliance policy requires the antivirus signature age to be no more than 3 days. The device reports 5 days, which exceeds the threshold, so Intune evaluates the device as noncompliant. Conditional Access can then block access to Microsoft 365 resources. This is the expected behavior for a device that fails a compliance setting.

Why this answer

Compliance policies in Intune evaluate device settings such as antivirus signature age. When the signature age exceeds the configured value, the device is marked noncompliant. This status can be used by Conditional Access to block access to corporate resources.

The correct outcome is that the device is noncompliant because it fails the defined requirement.

Exam trap

The trap here is assuming that Intune only checks whether antivirus is enabled, not the signature age, leading to the incorrect belief that the device remains compliant.

44
MCQhard

You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?

A.Create a provisioning package with Windows 11 upgrade settings and apply it via USB drives.
B.Deploy a Windows 11 feature update using the 'Windows 10/11 feature update' servicing plan in Configuration Manager, enabling Delivery Optimization for peer-to-peer download.
C.Use Windows Autopilot to reset the device and reinstall Windows 11, restoring user data from OneDrive.
D.Create a task sequence to upgrade Windows, and configure it to download content from the internet to reduce distribution point load.
AnswerB

Deploying a Windows 11 feature update via a Configuration Manager servicing plan performs a true in-place upgrade, preserving user data and settings. Enabling Delivery Optimization satisfies the limited-bandwidth constraint by letting remote-office peers share update content, drastically reducing WAN consumption compared with each device downloading independently.

Why this answer

It leverages Configuration Manager's 'Windows 10/11 feature update' servicing plan, which is specifically designed for in-place upgrades while preserving user data and settings. Enabling Delivery Optimization for peer-to-peer download reduces bandwidth consumption in remote offices by allowing devices to share upgrade content locally, addressing the limited bandwidth constraint.

Exam trap

The trap here is that candidates may confuse provisioning packages (Option A) as a valid upgrade method, but they are designed for offline provisioning and cannot perform an in-place upgrade with user data preservation, while the feature update servicing plan is the correct, supported method for this scenario.

How to eliminate wrong answers

Option A is wrong because provisioning packages are intended for initial device configuration and offline deployment, not for in-place upgrades; they cannot orchestrate a Windows 11 upgrade while preserving existing user data and settings. Option C is wrong because Windows Autopilot reset wipes the device and reinstalls Windows, which does not preserve user data and settings; restoring from OneDrive is a separate process and not part of an in-place upgrade. Option D is wrong because configuring a task sequence to download content from the internet does not inherently reduce distribution point load; it shifts the download source to the internet, which may still consume significant bandwidth unless combined with peer caching or Delivery Optimization, and the task sequence method is more complex than the dedicated feature update servicing plan.

45
MCQeasy

You need to ensure that only compliant devices can access Microsoft 365 resources. You create a Conditional Access policy in Microsoft Entra ID. Which condition should you use?

A.Locations condition set to trusted IPs.
B.Grant access with multi-factor authentication.
C.Require device to be marked as compliant.
D.Device platform condition set to all.
AnswerC

The grant control 'Require device to be marked as compliant' makes Microsoft Entra ID check Intune compliance state before issuing a token, blocking non-compliant devices from Microsoft 365. This directly enforces the stated constraint that only compliant devices gain access.

Why this answer

The question specifically asks to ensure that only compliant devices can access Microsoft 365 resources. In a Conditional Access policy, the 'Require device to be marked as compliant' grant control enforces that the device must be enrolled in Microsoft Intune and meet all compliance policies (e.g., encryption, OS version, threat level) before access is granted. This directly ties device health to resource access, which is the core requirement.

Exam trap

The trap here is that candidates often confuse 'device compliance' with 'device platform' or 'MFA', thinking that restricting by platform or adding MFA is sufficient to ensure device health, but neither checks the actual security posture of the device.

How to eliminate wrong answers

Option A is wrong because the 'Locations condition set to trusted IPs' controls access based on network location (e.g., corporate office), not device compliance; a non-compliant device from a trusted IP would still be allowed. Option B is wrong because 'Grant access with multi-factor authentication' verifies user identity via a second factor, but does not evaluate the device's compliance status; a compromised but MFA-authenticated device could still access resources. Option D is wrong because 'Device platform condition set to all' simply includes all operating systems (Windows, iOS, Android, etc.) in the policy scope, but does not enforce any compliance check; it is a condition, not a grant control.

46
Multi-Selecthard

You are the endpoint administrator for a company that uses Microsoft Intune. The company has an on-premises network with Active Directory Domain Services (AD DS) and a Microsoft Entra tenant. You need to prepare the infrastructure for Windows Autopilot deployment of Microsoft Entra hybrid joined devices. You must ensure that the required components are in place to support the hybrid join process. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the Microsoft Entra Connect sync to include the device objects in the organizational unit (OU) where the devices will be created.
B.Install the Intune Connector for Active Directory on a server with line-of-sight to a domain controller.
C.Create a device configuration profile that enables the Windows Push Notification Service (WNS).
D.Deploy a Windows Autopilot deployment profile with the deployment mode set to Microsoft Entra joined.
E.Assign the Intune Connector for Active Directory the necessary permissions in Microsoft Entra ID to create device objects.
AnswersA, B

For Microsoft Entra hybrid joined devices, Microsoft Entra Connect must be configured to sync the device objects from the OU where the Autopilot-created computer accounts reside. This ensures that the device objects are synchronized to Microsoft Entra ID and can be used for conditional access and management. Without this sync, the hybrid join will not complete successfully.

Why this answer

For Microsoft Entra hybrid joined Autopilot, you must install the Intune Connector for Active Directory on a server with line-of-sight to a domain controller, and configure Microsoft Entra Connect to sync the OU containing the device objects. These two components enable the creation of the computer account in AD DS during OOBE and ensure the device object is synchronized to Microsoft Entra ID, completing the hybrid join.

Exam trap

The trap here is assuming that the Intune Connector for Active Directory requires Microsoft Entra ID permissions, when it actually operates against on-premises AD DS.

47
MCQeasy

You are the endpoint administrator for Contoso, which uses Microsoft Intune. You need to enroll 200 new Windows 11 devices into Intune with the least administrative effort. The devices are currently running Windows 11 Pro and are connected to the internet. You want to avoid imaging or manually installing agents. What should you do?

A.Configure Windows Autopilot deployment profiles and register the device hardware IDs.
B.Deploy the Intune agent MSI to each device using a logon script.
C.Manually enroll each device by having users sign in with their Microsoft Entra ID credentials in Settings.
D.Use Group Policy to enable automatic MDM enrollment for all domain-joined devices.
AnswerA

Windows Autopilot leverages the existing Windows installation and hardware ID to enroll devices into Intune without reimaging. By registering hardware hashes, you can assign deployment profiles that automatically join devices to Microsoft Entra ID and enroll them in Intune. This meets the requirement of least administrative effort and avoids imaging.

Why this answer

Windows Autopilot is designed to simplify and automate the enrollment of new Windows devices without reimaging. By registering hardware IDs, you can assign deployment profiles that automatically configure and enroll devices into Intune. This approach minimizes administrative effort and ensures devices are ready for use with minimal user interaction.

Exam trap

The trap here is assuming that a separate Intune agent must be installed on Windows devices, when in fact enrollment is natively integrated into the OS.

48
MCQmedium

You are configuring a Microsoft Intune compliance policy for Windows 11 devices. You need to ensure that devices with BitLocker not enabled are marked noncompliant. Which setting should you configure in the compliance policy?

A.Require BitLocker
B.Require code integrity
C.Require Trusted Platform Module (TPM)
D.Require Secure Boot
AnswerA

The 'Require BitLocker' setting in a Windows compliance policy directly checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This setting is specifically designed to enforce encryption at the device level, aligning with security requirements for data protection.

Why this answer

To enforce BitLocker encryption, the compliance policy must include the 'Require BitLocker' setting. This setting directly evaluates whether BitLocker is enabled on the device. Other security settings like Secure Boot or TPM presence do not confirm BitLocker status.

Therefore, configuring 'Require BitLocker' ensures devices without encryption are marked noncompliant.

Exam trap

The trap here is confusing BitLocker enforcement with other security settings like Secure Boot or TPM, which are related but do not directly check for BitLocker encryption.

49
MCQhard

Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?

A.The device was enrolled 5 days ago.
B.The device is non-compliant.
C.The device is unenrolled.
D.The device has not communicated with Intune for 5 days.
AnswerD

lastSyncDateTime records the most recent check-in between the device and the Intune service. A value five days old means no communication has occurred since then, so the device is likely offline, powered down, or otherwise unable to reach the service.

Why this answer

The `lastSyncDateTime` property in Microsoft Graph for Intune-managed devices indicates the most recent time the device successfully checked in with the Intune service. A value of 5 days ago means the device has not communicated with Intune for 5 days, which could be due to network issues, device inactivity, or configuration problems. This does not inherently mean the device is non-compliant or unenrolled—it simply reflects the last successful sync.

Exam trap

The trap here is that candidates often confuse `lastSyncDateTime` with enrollment date or compliance status, leading them to incorrectly assume the device is non-compliant or unenrolled, when in fact it simply indicates the last successful communication with Intune.

How to eliminate wrong answers

Option A is wrong because `lastSyncDateTime` records the last successful sync with Intune, not the enrollment date; enrollment date is tracked by the `enrolledDateTime` property. Option B is wrong because a device can be non-compliant for many reasons (e.g., missing required updates, jailbreak detection) and a stale sync date alone does not determine compliance—compliance is evaluated based on policy conditions, not sync recency. Option C is wrong because an unenrolled device would not appear in the managed devices list at all; the `lastSyncDateTime` field would be absent or the device would be removed from the inventory.

50
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?

Select 2 answers
A.Create local user accounts on the device
B.Remotely wipe a device
C.Configure DHCP settings
D.Apply BitLocker encryption policies
E.Add the device to an Active Directory group
AnswersB, D

Intune's remote device actions include wipe, which performs a factory reset removing corporate and personal data. This is distinct from retire, which removes only company data and management, and from selective wipe on supported platforms.

Why this answer

Option B is correct because Microsoft Intune supports remote device actions such as a full wipe (and also selective wipe/retire) for Windows 10 devices enrolled in MDM, allowing an administrator to reset the device to factory settings and remove corporate data. Option D is correct because Intune provides built-in BitLocker disk encryption policies (via the Endpoint Security Disk Encryption profile or configuration profiles) that let you enforce and manage BitLocker on Windows 10 devices, including storing recovery keys in Azure AD/Intune. Option A is not correct because Intune does not create local user accounts on Windows 10 devices; local account management is done via Group Policy, PowerShell, or other on-premises tools, not Intune MDM policy.

Option C is not correct because DHCP settings are configured on the DHCP server or network infrastructure, not through Intune device management policies. Option E is not correct because adding a device to an Active Directory group is an on-premises AD/Group Policy or Azure AD dynamic group operation, not an Intune device management action.

Exam trap

The trap here is that candidates often confuse Intune's device management capabilities with on-premises Group Policy or Active Directory tasks, leading them to incorrectly select options like creating local users or managing DHCP, which are outside Intune's scope.

51
MCQmedium

You manage Windows devices with Microsoft Intune. A line-of-business MSI installer must be deployed to 400 devices. The installer requires a custom transform (.mst) file and must run with administrative privileges. You need to deploy the app using the least administrative effort while ensuring the transform is applied. What should you do?

A.Convert the MSI to an .intunewin file and deploy it as a Win32 app without the .mst, then use a separate script to modify the registry.
B.Package the MSI and .mst into a Win32 app (.intunewin) and deploy it as required.
C.Deploy the MSI as a line-of-business app and use a PowerShell script to apply the .mst after installation.
D.Upload the MSI as a line-of-business app and specify the .mst file in the app configuration.
AnswerB

Packaging the MSI and its transform into a Win32 app allows you to include the .mst and specify the installation command with the TRANSFORMS property. Win32 apps support custom scripts and full control over installation, ensuring the transform is applied. This approach requires more effort than a line-of-business app but meets the requirement.

Why this answer

Win32 apps in Intune support the inclusion of additional files and custom installation commands, which is necessary to apply an MSI transform. By packaging the MSI and .mst together and specifying the correct command line, the transform is applied during installation. This ensures the customizations are correctly deployed to all targeted devices.

Exam trap

The trap here is assuming that line-of-business MSI apps in Intune support transform files, when they do not.

52
MCQeasy

You need to ensure that Windows 10 devices are automatically upgraded to Windows 11 if they meet hardware requirements. Which policy should you configure in Microsoft Intune?

A.Assign a driver update policy.
B.Assign a quality update policy.
C.Assign an update ring for Windows 10.
D.Assign a Windows 10/11 feature update policy.
AnswerD

A Windows 10/11 feature update policy in Microsoft Intune deploys a specific Windows 11 release to targeted devices, honouring the hardware readiness checks performed by Windows Update for Business. This directly satisfies the requirement that eligible Windows 10 devices upgrade automatically, while incompatible hardware is excluded from the rollout.

Why this answer

A Windows 10/11 feature update policy in Microsoft Intune is specifically designed to manage the upgrade of Windows 10 devices to Windows 11. This policy uses Windows Update for Business to deliver the feature update (e.g., Windows 11 23H2) and automatically applies it to devices that meet the hardware requirements, ensuring a controlled upgrade process.

Exam trap

The trap here is that candidates confuse 'update rings' (which control update behavior like deferrals and deadlines) with 'feature update policies' (which actually push the OS version upgrade), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because a driver update policy only manages driver updates, not OS version upgrades; it cannot trigger a Windows 11 feature update. Option B is wrong because a quality update policy handles cumulative security and non-security patches (e.g., monthly updates), not feature updates that change the OS version. Option C is wrong because an update ring for Windows 10 configures deferral and update behavior for Windows 10 updates but does not initiate a feature upgrade to Windows 11; it only controls how existing Windows 10 updates are applied.

53
Multi-Selecthard

Which FOUR of the following are valid detection rules for a Win32 app in Intune?

Select 4 answers
A.PowerShell script (custom detection)
B.MSI product code
C.Registry (key or value exists)
D.File system (file or folder exists)
E.Network share access
AnswersA, B, C, D

A PowerShell script used as a custom detection rule lets Intune evaluate arbitrary logic on the endpoint, satisfying the requirement for a valid Win32 app detection method. It returns an exit code and output that Intune interprets to confirm installation.

Why this answer

Option A (PowerShell script / custom detection) is valid because Intune Win32 apps support a custom detection script whose exit code and stdout determine whether the app is considered installed. Option B (MSI product code) is valid because Intune can detect an installed app by matching its MSI product code in the Windows Installer database. Option C (Registry key or value exists) is valid because Intune's registry detection rule checks for a specified key/value (and can compare a value's string, integer, or version) to confirm installation.

Option D (File system / file or folder exists) is valid because Intune's file/folder detection rule verifies existence (and optionally date, size, or version) of a specified path. Option E (Network share access) is not a supported Win32 app detection rule type in Intune, so it does not belong.

Exam trap

Candidates may mistakenly think network share access is a valid detection rule, but it is not.

54
MCQeasy

An IT administrator needs to ensure that iOS devices enrolled in Intune require a PIN of at least 6 digits. Where should the administrator configure this setting?

A.App protection policy
B.Device compliance policy for iOS
C.Conditional Access policy
D.Enrollment restrictions
AnswerB

A device compliance policy for iOS defines the minimum PIN length requirement, enforcing a six-digit passcode as a condition of compliance. Device restrictions profiles control features, not passcode length, so compliance is the correct location.

Why this answer

Device compliance policies in Intune define the rules and settings that devices must meet to be considered compliant, including password requirements such as minimum PIN length. For iOS devices, the compliance policy includes settings for passcode complexity and length. App protection policies apply to apps, not device-wide settings; Conditional Access policies enforce access based on compliance but do not define the PIN requirement; Enrollment restrictions control which devices can enroll, not security settings.

Exam trap

MD-102 often tests the difference between device compliance policies (device-wide settings) and app protection policies (app-level settings), so candidates may incorrectly choose app protection policy for device PIN requirements.

How to eliminate wrong answers

Option A is wrong because app protection policies apply to specific apps (e.g., Outlook) and can enforce PIN for app access, but they do not enforce a device-wide PIN requirement for iOS devices. Option C is wrong because Conditional Access policies use compliance status to grant or deny access, but they do not configure the PIN requirement itself. Option D is wrong because enrollment restrictions determine which devices are allowed to enroll (e.g., by platform or OS version), not security settings like PIN length.

55
MCQeasy

You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?

A.Proactive remediations
B.PowerShell scripts (Devices > Scripts)
C.Compliance policy
D.Device configuration profile
AnswerB

PowerShell scripts in Intune run in the SYSTEM context on enrolled Windows 10 devices by default, satisfying the stem's requirement. Upload the script under Devices > Scripts, where it executes once or on a schedule without user credentials, unlike proactive remediations or platform scripts requiring different scopes.

Why this answer

PowerShell scripts (Devices > Scripts) in Intune allow you to upload and assign custom PowerShell scripts that run under the SYSTEM account on Windows 10 devices. This feature is specifically designed for executing scripts during device enrollment or on a schedule, ensuring the script has elevated privileges without user interaction.

Exam trap

A common misconception is that Proactive remediations can replace custom PowerShell scripts. However, Proactive remediations require both a detection script and a remediation script, and are designed for automatic remediation of specific issues, not for general script deployment. Custom PowerShell scripts (Devices > Scripts) are the correct choice for deploying a standalone script under the SYSTEM account.

How to eliminate wrong answers

Option A is wrong because Proactive remediations are used for detecting and fixing common support issues with built-in detection and remediation scripts, not for deploying custom PowerShell scripts under the SYSTEM account. Option C is wrong because Compliance policies evaluate device settings against defined rules and do not execute scripts. Option D is wrong because Device configuration profiles manage settings via CSPs (Configuration Service Providers) and cannot run arbitrary PowerShell scripts.

56
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device enrolled in Microsoft Intune. The device is currently offline. What will happen when the device comes online?

A.The device must be unenrolled first and then wiped.
B.The device will be wiped immediately after a grace period of 24 hours.
C.The device will receive the wipe command the next time it checks in with Intune.
D.The wipe command will be queued only if the device is supervised.
AnswerC

Intune queues the wipe command until the device next establishes a connection, since it cannot push to an offline endpoint. On reconnection, the check-in retrieves the pending action and executes the wipe, satisfying the offline constraint in the stem.

Why this answer

When a remote wipe command is issued for an offline iOS device enrolled in Microsoft Intune, the command is stored in the Microsoft Intune service. The device will receive and execute the wipe command the next time it checks in with the Intune service, regardless of whether it is supervised or not. This check-in occurs periodically (typically every 8 hours) or when the device is powered on and connected to the internet.

Exam trap

The trap here is that candidates often confuse the offline wipe behavior with a mandatory grace period or think that supervision is required for remote wipe, when in fact Intune queues the command and executes it on the next check-in for any enrolled iOS device.

How to eliminate wrong answers

Option A is wrong because there is no requirement to unenroll the device before a remote wipe; the wipe command itself triggers the removal of management and corporate data. Option B is wrong because there is no built-in 24-hour grace period for offline wipe commands in Intune; the wipe executes immediately upon the next check-in, not after a fixed delay. Option D is wrong because the wipe command is not queued only for supervised devices; both supervised and unsupervised iOS devices can receive and execute a remote wipe command when they come online.

57
MCQhard

Your organization uses Microsoft Defender for Cloud Apps. You need to configure a policy that automatically blocks downloads of sensitive data from SharePoint Online to unmanaged devices. Which policy type should you use?

A.Activity policy
B.App discovery policy
C.Access policy
D.Session policy
AnswerD

A session policy in Defender for Cloud Apps applies Conditional Access App Control, proxying the SharePoint Online session so downloads to unmanaged devices can be blocked in real time. Access policies only evaluate sign-in conditions, so they cannot intercept an in-session download action.

Why this answer

Session policies in Microsoft Defender for Cloud Apps allow real-time monitoring and control of user activities based on app and device context. By configuring a session policy with the condition 'Device tag equals Unmanaged' and the control 'Block download', you can automatically block downloads of sensitive data from SharePoint Online to unmanaged devices, leveraging reverse proxy architecture to inspect and intercept traffic.

Exam trap

The trap here is confusing Access policies (which control sign-in and token issuance) with Session policies (which control in-session actions like downloads), leading candidates to incorrectly choose Access policy when the question explicitly requires blocking a specific file operation on unmanaged devices.

How to eliminate wrong answers

Option A is wrong because Activity policies are used for post-event detection and alerting on specific user activities (e.g., multiple failed logins), not for real-time blocking of downloads based on device compliance. Option B is wrong because App discovery policies analyze cloud app usage and shadow IT, not control data exfiltration from managed apps like SharePoint Online. Option C is wrong because Access policies control authentication and access (e.g., requiring MFA or blocking sign-in) but do not provide granular, session-level controls like blocking file downloads within an already authenticated session.

58
MCQhard

You have a Microsoft 365 subscription that includes Microsoft Intune. You have 100 Windows 11 devices enrolled in Intune. You need to ensure that BitLocker recovery keys are automatically escrowed to Microsoft Entra ID when BitLocker is enabled. What should you configure?

A.An Endpoint protection profile with 'BitLocker' settings configured to save recovery information to Microsoft Entra ID
B.A device configuration profile with the 'Encrypt devices' setting set to 'Require'
C.A compliance policy that requires BitLocker and marks devices without escrowed keys as non-compliant
D.A PowerShell script deployed via Intune that runs 'manage-bde -protectors -adbackup'
AnswerA

In Intune, the Endpoint protection profile includes BitLocker settings where you can specify 'Save BitLocker recovery information to Microsoft Entra ID' and choose to store recovery keys. This directly ensures automatic escrow of recovery keys to Microsoft Entra ID, meeting the requirement without additional scripts.

Why this answer

The Endpoint protection profile in Intune provides native BitLocker settings, including the option to save recovery information to Microsoft Entra ID. Enabling this setting ensures that when BitLocker is activated, the recovery key is automatically escrowed to Entra ID, allowing administrators to retrieve it if needed. This is the most direct and supported method.

Exam trap

The trap here is assuming that a compliance policy or a simple encryption requirement will automatically escrow keys, when escrow requires explicit configuration in the BitLocker settings.

59
Multi-Selectmedium

A company uses Microsoft Intune to manage Windows 10 devices. Users report that some required line-of-business (LOB) apps are not being installed on their devices. The apps are assigned as 'Required' to a device group that includes the affected devices. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Select 2 answers
A.Review the Intune Management Extension logs on a device for installation errors.
B.Uninstall the app from the affected devices and reassign it as Required.
C.Check the device’s last check-in time and perform a manual sync from the Intune console.
D.Reassign the app to the device group with a different assignment type.
E.Run gpresult /r on a device to confirm the app assignment policy is applied.
AnswersA, C

Logs provide detailed error messages.

Why this answer

The Intune Management Extension (IME) is the component responsible for deploying Win32 and line-of-business (LOB) apps on Windows 10 devices. Reviewing its logs (located in %ProgramData%\Microsoft\IntuneManagementExtension\Logs) provides detailed error messages, such as download failures, dependency issues, or script execution errors, which directly indicate why a required app failed to install.

Exam trap

The trap here is that candidates confuse Intune MDM app deployment with traditional Group Policy Software Installation (GPSI) and incorrectly choose gpresult /r, not realizing Intune uses the IME and MDM channel, not Active Directory Group Policy.

60
MCQhard

Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?

A.Create a device configuration profile that sets the Defender signature update interval to every hour and assign it to all devices.
B.Configure a Windows Defender Application Control policy that blocks access to Microsoft 365 when the signature is older than the required version.
C.Add a compliance policy rule that requires the device to be at or below a specific OS build version and rely on that as a proxy for signature currency.
D.Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.
AnswerD

Custom compliance settings in Intune allow a PowerShell discovery script to gather any device property, including Defender signature version, and a JSON file to define the expected values. This is the supported way to evaluate a condition that is not exposed as a built-in compliance rule, and the result feeds directly into the device compliance state used by conditional access.

Why this answer

Intune compliance policies include built-in rules for Defender Antivirus status, but they do not natively expose a rule for a specific signature version. Custom compliance settings close that gap: a PowerShell discovery script reads the current signature version from the device, and a JSON file defines the acceptable values. The resulting compliance state is then honored by conditional access, ensuring only devices with current signatures reach Microsoft 365.

Exam trap

The trap here is assuming that a Defender-related configuration profile or a built-in compliance rule can enforce a specific signature version, when only custom compliance settings can evaluate arbitrary properties.

61
Multi-Selectmedium

An Intune administrator needs to ensure that Windows 10 devices are compliant with security requirements. Which TWO options are valid compliance settings for Windows 10?

Select 2 answers
A.Device category must be 'Corporate'
B.Device enrollment type must be 'Corporate'
C.Require BitLocker
D.Minimum OS version
E.Require app protection policy
AnswersC, D

Requiring BitLocker is a valid Windows 10 compliance setting in Intune, enforcing full-disk encryption via the device encryption policy. It directly satisfies the stem's security requirement by verifying drive encryption status, and is configurable under Device Compliance > Windows 10/11 compliance policy alongside firewall and antivirus settings.

Why this answer

Option C (Require BitLocker) is correct because BitLocker drive encryption is a native Windows 10 compliance setting in Intune under Device Health, allowing the admin to require that encryption is enabled on the device. Option D (Minimum OS version) is correct because Intune's Device Properties compliance settings for Windows 10 let you specify a minimum OS version (for example, 10.0.19041.0) that devices must meet to be marked compliant. Option A is not a compliance setting; device category is an attribute used for grouping and reporting, not a compliance rule.

Option B is not valid because enrollment type is not a configurable compliance condition in Intune. Option E is not a Windows 10 device compliance setting; app protection policies are separate MAM policies applied to apps, not device compliance rules.

Exam trap

The trap here is that candidates confuse device-level compliance settings (like OS version and BitLocker) with enrollment properties (device category, enrollment type) or app-level policies (app protection policy), which are managed in different policy types within Intune.

62
MCQhard

Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?

A.The compliance policy requires password, but the device configuration policy does not configure any password settings, leading to non-compliance.
B.The compliance policy requires encryption, but the device configuration policy does not enforce BitLocker startup PIN, causing compliance failure.
C.The device configuration policy sets scanParameter to 'fullscan', which may interfere with compliance checks.
D.The compliance policy requires Defender, but the device configuration policy sets cloudBlockLevel to 'high', which may conflict with some devices.
AnswerA

Intune evaluates compliance independently of configuration. Because the compliance policy mandates a password while the configuration policy sets none, devices without a password are flagged non-compliant even though BitLocker and Defender Antivirus satisfy their own requirements. The password requirement is the conflicting setting.

Why this answer

The compliance policy requires a password, but the device configuration policy does not configure any password settings. In Intune, compliance policies evaluate device settings independently of configuration policies; if a compliance policy mandates a password and the device lacks one (because the configuration policy doesn't enforce it), the device will be marked non-compliant. BitLocker and Defender being enabled do not satisfy a password requirement, so the conflict is the missing password configuration.

Exam trap

The trap here is that candidates assume enabling BitLocker and Defender automatically satisfies all compliance requirements, but Intune compliance policies evaluate each setting independently, so a missing password configuration will cause non-compliance even if other security features are present.

How to eliminate wrong answers

Option B is wrong because the compliance policy requires encryption, not a BitLocker startup PIN; the device configuration policy not enforcing a startup PIN does not cause compliance failure if BitLocker is enabled and encryption is satisfied. Option C is wrong because the scanParameter setting in a device configuration policy does not interfere with compliance checks; compliance policies evaluate security state, not scan parameters. Option D is wrong because cloudBlockLevel set to 'high' in a device configuration policy does not conflict with a compliance policy requiring Defender; both can coexist without causing non-compliance.

63
MCQhard

You manage iOS devices with Microsoft Intune. You need to deploy an app that is not available in the Apple App Store. The app is developed internally and signed with an enterprise certificate. Which app type should you use?

A.iOS/iPadOS app store app
B.Web link
C.Built-in app
D.iOS/iPadOS Line-of-business app
AnswerD

Line-of-business app type uploads the signed .ipa directly, bypassing the App Store, and supports enterprise-signed internal apps. It satisfies the constraint that the app is unavailable in the Apple App Store and signed with an enterprise certificate.

Why this answer

An iOS/iPadOS Line-of-business (LOB) app is the correct app type in Intune for deploying internally developed apps that are signed with an enterprise certificate and not distributed through the Apple App Store. Intune uploads the .ipa file and pushes it to enrolled devices via MDM, bypassing the public store. This is the standard mechanism for enterprise-signed in-house apps.

Exam trap

MD-102 often tests the distinction between App Store apps, VPP apps, and Line-of-business apps — candidates confuse 'enterprise-signed internal app' with App Store distribution and pick the wrong app type.

How to eliminate wrong answers

Option A is wrong because iOS/iPadOS app store apps are sourced from the public Apple App Store and cannot host an internally developed enterprise-signed .ipa. Option B is wrong because a Web link simply creates a shortcut to a URL and does not install or manage an actual application binary. Option C is wrong because built-in apps refer to Microsoft-published apps (such as Edge or Office) that Intune can deploy directly, not custom internal apps.

64
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune to manage 500 Windows 11 devices. The security team requires that devices cannot be enrolled if they do not have a TPM 2.0 chip and Secure Boot enabled. You need to configure a device enrollment restriction to block enrollment of devices that do not meet these hardware requirements. What should you do?

A.Configure a Windows Autopilot deployment profile with hardware requirements and assign it to all devices.
B.Create a configuration profile with a custom OMA-URI that checks for TPM and Secure Boot, and assign it to all devices.
C.In the Microsoft Intune admin center, create a device enrollment restriction for Windows and set the minimum TPM version and require Secure Boot.
D.Create a device compliance policy that requires TPM 2.0 and Secure Boot, and assign it to all users.
AnswerC

Device enrollment restrictions in Intune allow you to specify hardware requirements such as minimum TPM version and Secure Boot enforcement for Windows devices. When configured, devices that do not meet these criteria are prevented from enrolling, directly fulfilling the requirement to block non-compliant hardware at enrollment time.

Why this answer

Device enrollment restrictions are the correct tool to control which devices can enroll based on hardware attributes like TPM version and Secure Boot. Compliance policies and configuration profiles only act after enrollment, and Autopilot profiles shape the provisioning experience but do not enforce hardware prerequisites. Thus, only enrollment restrictions can block non-compliant hardware at the point of enrollment.

Exam trap

The trap here is confusing post-enrollment compliance evaluation with pre-enrollment blocking, leading to selection of a compliance policy instead of an enrollment restriction.

65
MCQeasy

You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?

A.A PowerShell script deployed to the user group.
B.An app configuration policy assigned to the user group.
C.A compliance policy assigned to the user group.
D.A device configuration profile assigned to the device group.
AnswerD

Device configuration profiles are applied to devices and can be targeted to device groups. They are processed during enrollment and can apply settings before user sign-in, especially if they are assigned to the device. This ensures that the settings are in place regardless of which user signs in, meeting the requirement.

Why this answer

Device configuration profiles are the correct choice because they are designed to apply settings to devices and can be targeted to device groups. When assigned to a device group, they are processed during enrollment and apply to the device itself, ensuring settings are in place before any user signs in. This meets the requirement of applying settings that affect all users of the device.

Exam trap

The trap here is confusing device configuration profiles with compliance policies or user-targeted scripts, which do not apply settings at the device level before sign-in.

66
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. A line-of-business (LOB) app named App1 is deployed as required to a group of users. Users report that App1 installs successfully on some devices but fails on others with error code 0x87D1041C. You need to resolve the installation failures. What should you do?

A.Add a dependency to the app to ensure required frameworks are installed first.
B.Modify the detection rule to match the actual installation state on the failing devices.
C.Re-deploy the app with the 'Require a restart' option set to 'No'.
D.Change the app assignment from 'Required' to 'Available' for the affected users.
AnswerB

Error 0x87D1041C specifically means the app was installed but the detection rule did not detect it as installed. By adjusting the detection rule to accurately reflect the app's presence, you ensure Intune recognizes successful installations and stops retrying, resolving the failure.

Why this answer

Error 0x87D1041C occurs when the app installation succeeds but the detection rule fails to confirm it. This often happens if the detection rule checks for a file or registry key that is not present on all devices due to variations in installation paths or versions. Correcting the detection rule to match the actual state on the failing devices resolves the error and allows Intune to mark the app as installed.

Exam trap

The trap here is misinterpreting the error code as an installation failure rather than a detection failure, leading to unnecessary changes to deployment settings.

67
Multi-Selecthard

Which THREE of the following are valid methods to deploy Microsoft 365 Apps for enterprise using Microsoft Intune?

Select 3 answers
A.Use the built-in Microsoft 365 Apps app type in Intune.
B.Use the Office Deployment Tool (ODT) within a script deployed via Intune.
C.Assign the apps via Azure AD application registration.
D.Package the Office installer as a Win32 app.
E.Deploy the MSI version of Office via Intune.
AnswersA, B, D

The built-in Microsoft 365 Apps app type in Intune satisfies the requirement by packaging the Office suite directly, letting you configure update channels, remove prior installations and select specific products. It deploys natively through the Intune management extension without requiring separate packaging or third-party tooling, making it a valid deployment method.

Why this answer

Option A is correct because Intune provides a native Microsoft 365 Apps (Windows 10 and later) app type that lets you configure the Office apps, update channel, and architecture directly from the console without packaging. Option B is correct because you can use the Office Deployment Tool (ODT) with a configuration.xml and run setup.exe via a script (e.g., PowerShell or platform script) deployed through Intune to install Microsoft 365 Apps. Option D is correct because you can wrap the Office installer (using the ODT or a prepared source) into an .intunewin file and deploy it as a Win32 app, which supports custom detection and requirement rules.

Option C is not valid because Azure AD application registration is for identity/consent of apps, not for deploying Office binaries to devices. Option E is not valid because Microsoft 365 Apps for enterprise is delivered via Click-to-Run, not as an MSI, so there is no supported MSI deployment method for this product through Intune.

Exam trap

The trap here is that candidates confuse Azure AD application registration (an identity/authentication feature) with a deployment mechanism, or mistakenly think MSI-based Office deployment is still supported for Microsoft 365 Apps in Intune.

68
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A line-of-business MSI app must install only after a Visual C++ redistributable package is present, and the MSI must run with SYSTEM privileges at every device startup regardless of user sign-in. You need to configure the app deployment in Intune. What should you do?

A.Deploy the MSI as a line-of-business app and configure an Intune PowerShell script to install the redistributable first.
B.Deploy the MSI as a line-of-business app and set the app to install in user context.
C.Create a Windows app (Win32) package, add the redistributable as a supersedence, and set the install behavior to User.
D.Create a Windows app (Win32) package, add the redistributable as a dependency, and set the install behavior to System.
AnswerD

Packaging the MSI as a Windows app (Win32) lets Intune enforce a dependency on the redistributable before installing the MSI, and the install behavior set to System runs the installer with SYSTEM privileges. The dependency ensures ordering, and SYSTEM context satisfies the requirement that installation occur at device level independent of user sign-in, which matches the scenario's startup requirement.

Why this answer

A Windows app (Win32) package created with the Microsoft Win32 Content Prep Tool supports both dependency relationships and install behavior selection. Adding the redistributable as a dependency forces Intune to install it before the MSI, and choosing System install behavior runs the MSI with SYSTEM privileges. This combination uniquely satisfies the prerequisite and privilege requirements in the scenario.

Exam trap

The trap here is confusing supersedence with dependency, or assuming a line-of-business MSI can enforce prerequisite ordering.

69
Matchingmedium

Match each Intune configuration profile type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Control settings like password, camera, and Bluetooth

Define rules for device health and security

Deploy custom OMA-URI or Apple Configurator settings

Configure Windows Defender Firewall and BitLocker

Group Policy-like settings for Windows devices

Why these pairings

Device restrictions manage device features, Endpoint protection handles security settings, Administrative templates use ADMX, and Custom uses OMA-URI. Common confusions involve swapping the first two.

70
MCQmedium

Your organization uses Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices for accessing an internal web app. Which profile type should you use?

A.PKCS certificate profile
B.SCEP certificate profile
C.Trusted certificate profile
D.Custom configuration profile (preferences)
AnswerC

A Trusted certificate profile deploys the root or intermediate CA certificate to iOS/iPadOS devices so they trust the internal web app's server certificate. It satisfies the requirement to install a custom SSL certificate for internal access, unlike SCEP or PKCS profiles, which issue client certificates.

Why this answer

A Trusted certificate profile is used to deploy a root or intermediate CA certificate that the device must trust for certificate-based authentication, such as accessing an internal web app over HTTPS. This profile type simply installs the certificate into the device's trusted root store without generating a private key, which is exactly what is needed when you only need to establish trust for the server certificate presented by the web app.

Exam trap

The trap here is that candidates often confuse deploying a trusted root certificate (needed for server trust) with issuing a client certificate (needed for device authentication), leading them to incorrectly choose PKCS or SCEP profiles when the question only requires establishing trust for the server's SSL certificate.

How to eliminate wrong answers

Option A is wrong because a PKCS certificate profile is used to issue a client certificate with a private key to the device for client authentication, not to deploy a trusted root certificate. Option B is wrong because a SCEP certificate profile is used to request and renew client certificates dynamically via the Simple Certificate Enrollment Protocol, again for client authentication, not for deploying a trusted root. Option D is wrong because a Custom configuration profile (preferences) is used to deploy app-specific settings or plist files, not to install certificates into the device's trust store.

71
Multi-Selectmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to configure a remediation to automatically restart the Windows Update service (wuauserv) if it stops. You create a proactive remediation script package. Which two components must you provide in the script package? (Choose two.)

Select 2 answers
A.A detection script that checks whether the Windows Update service is running
B.A PowerShell script that runs only once at device enrollment
C.A requirement rule that checks the service status before installation
D.A compliance policy that marks the device noncompliant if the service is stopped
E.A remediation script that starts the Windows Update service if it is stopped
AnswersA, E

A detection script is required in a proactive remediation to determine if the device is compliant or non-compliant. In this scenario, it must check the status of the Windows Update service and exit with a non-zero code or 'non-compliant' output if the service is stopped, triggering the remediation script.

Why this answer

A proactive remediation script package in Intune consists of two scripts: a detection script and a remediation script. The detection script identifies whether the Windows Update service is running; if it is not, it signals non-compliance. The remediation script then starts the service.

Together, they automate the detection and correction of the issue, ensuring the service is restarted without manual intervention.

Exam trap

The trap here is confusing proactive remediation components with app deployment requirement rules or compliance policies, which serve different purposes.

72
MCQmedium

A company plans to deploy Windows 11 to 500 devices using Microsoft Deployment Toolkit (MDT). The deployment must be fully automated with minimal user interaction. Which configuration should be used in the CustomSettings.ini file?

A.SkipApps=YES
B.UserDataLocation=AUTO
C.SkipWizard=YES
D.DoNotCreateExtraPartition=YES
AnswerC

SkipWizard=YES suppresses the entire MDT deployment wizard, so the task sequence runs unattended from start to finish. This directly satisfies the stem's requirement for fully automated deployment with minimal user interaction across the 500 devices.

Why this answer

`SkipWizard=YES` in the CustomSettings.ini file tells MDT to bypass all deployment wizard pages, enabling a fully unattended, zero-touch deployment. This is the specific setting required to achieve minimal user interaction during the MDT deployment process.

Exam trap

The trap here is that candidates often confuse `SkipWizard=YES` with individual `Skip*` settings, thinking they need to list each one, or they mistakenly believe `UserDataLocation=AUTO` or `DoNotCreateExtraPartition=YES` control automation level when they only affect specific deployment phases.

How to eliminate wrong answers

Option A is wrong because `SkipApps=YES` only skips the application selection page in the wizard, but the deployment still requires user interaction for other wizard pages (e.g., computer name, credentials). Option B is wrong because `UserDataLocation=AUTO` controls where user state data is stored during migration, not the level of automation or wizard skipping. Option D is wrong because `DoNotCreateExtraPartition=YES` prevents MDT from creating additional partitions (like a recovery partition) during disk configuration, but does not affect the wizard interaction or automation level.

73
MCQmedium

You are the administrator for a company that uses Microsoft Intune. The company has a policy that all Windows 10 devices must have a minimum OS version of 10.0.19045. You need to ensure that devices that do not meet this requirement are blocked from accessing corporate email. What should you configure?

A.A device configuration profile that sets the minimum OS version and a conditional access policy that requires compliant devices.
B.A device compliance policy that sets the minimum OS version to 10.0.19045, and a conditional access policy that requires compliant devices.
C.A device enrollment restriction that blocks devices with an OS version lower than 10.0.19045.
D.A conditional access policy that requires multi-factor authentication for all users.
AnswerB

A device compliance policy can enforce the minimum OS version, marking devices below 10.0.19045 as noncompliant. A conditional access policy that requires compliant devices will then block access to corporate email for noncompliant devices. This combination directly achieves the goal of blocking email access for outdated devices.

Why this answer

To block email access for devices not meeting a minimum OS version, you need a compliance policy that defines that requirement and a conditional access policy that enforces compliance. Configuration profiles and enrollment restrictions do not evaluate compliance for access control, and MFA policies do not consider OS version. Thus, the combination of a compliance policy and a conditional access policy is required.

Exam trap

The trap here is selecting a device configuration profile to enforce OS version, but configuration profiles do not affect compliance state or conditional access decisions.

74
MCQmedium

You manage a set of Windows 11 devices enrolled in Microsoft Intune. Users report that they can no longer sign in with their Microsoft Entra ID credentials after you deployed a new compliance policy. The devices show as compliant in Intune, but the sign-in fails with an error about device not meeting requirements. You need to ensure that users can sign in. What should you do?

A.Review the conditional access policy that requires compliant devices and ensure the device is included.
B.Restart the Intune Management Extension service on the affected devices.
C.Assign the compliance policy to the device group instead of the user group.
D.Modify the compliance policy to mark the devices as compliant manually.
AnswerA

The sign-in error indicates that conditional access is blocking access because the device is not considered compliant. Even if Intune shows the device as compliant, the conditional access policy might not be targeting the correct device or user group, or the device might not be registered in Microsoft Entra ID. Verifying the policy's included devices and users ensures the device meets the access requirements.

Why this answer

The sign-in error indicates a conditional access block despite Intune reporting compliance. Conditional access evaluates device compliance at authentication time, and if the device is not included in the policy or not properly registered, access is denied. Reviewing the conditional access policy to ensure the device is targeted and meets requirements resolves the issue.

Other actions do not address the authentication flow.

Exam trap

The trap here is assuming that a compliant status in Intune automatically grants access, without verifying that the conditional access policy includes the device and that the device is registered in Microsoft Entra ID.

75
MCQhard

You manage Windows 11 devices with Microsoft Intune. A Win32 app deployed as Required is failing on a subset of devices, and the Intune Management Extension log shows the installer exiting with code 1618. You have already confirmed the app package and detection rule are correct. What is the most likely cause and the appropriate fix?

A.The app requires a reboot that was not granted; map return code 1618 to a soft reboot so the device restarts.
B.The install command is running in the user context and lacks elevation; switch Install behavior to System.
C.The detection rule is matching too early; add a longer detection script timeout so the installer finishes first.
D.Another installation is already in progress; adjust the app's dependencies or deployment timing so installs do not overlap.
AnswerD

Exit code 1618 is the Windows Installer error indicating another installation is already in progress. When multiple Required apps install simultaneously, the Windows Installer mutex blocks the second installer. Staggering deployments, sequencing dependencies, or reducing concurrent Required apps on those devices resolves the conflict so each installer can acquire the mutex and complete.

Why this answer

Exit code 1618 from Windows Installer means another installation is already running on the device. When several Required Win32 apps deploy at once, their installers contend for the single Windows Installer mutex, and the losing installer returns 1618. Sequencing dependencies or staggering deployment timing lets each installer run without contention, so the affected devices complete installation.

Exam trap

The trap here is assuming 1618 indicates a reboot requirement, when reboot codes are 3010 and 1641 and 1618 actually signals an installer mutex conflict.

Page 1 of 8

Page 2

All pages