Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 76–150

556 questions total · 8pages · All types, answers revealed

Page 1

Page 2 of 8

Page 3
76
MCQmedium

Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?

A.The devices are running a non-Windows OS.
B.The devices have not synced recently.
C.The devices do not meet the assigned compliance policies.
D.The admin lacks permissions to view compliance details.
AnswerC

A recent lastSyncDateTime confirms the device checked in and evaluated policy, so the noncompliant state reflects an actual policy failure rather than stale reporting. Microsoft Entra ID marks a device noncompliant when its settings breach the assigned compliance policy conditions, such as missing updates, disabled encryption, or absent antivirus.

Why this answer

A device's complianceState is determined by evaluating its configuration against assigned compliance policies. Even if lastSyncDateTime is recent, the device will be marked 'noncompliant' if it fails any of the policy checks (e.g., missing required updates, encryption not enabled, or a required antivirus solution not running). The sync timestamp only indicates when the device last communicated with Intune, not whether it meets policy requirements.

Exam trap

The trap here is that candidates assume a recent sync timestamp implies the device is healthy or compliant, when in fact sync and compliance are separate attributes—a device can be fully synced yet persistently noncompliant due to policy violations.

How to eliminate wrong answers

Option A is wrong because the cmdlet specifically queries 'managed Windows devices', so the output only includes Windows devices; a non-Windows OS would not appear in these results. Option B is wrong because the exhibit explicitly shows that lastSyncDateTime is recent, meaning the devices have synced recently; noncompliance is not caused by a lack of sync. Option D is wrong because if the admin lacked permissions to view compliance details, the cmdlet would either fail or return an access-denied error, not show a complianceState of 'noncompliant' for specific devices.

77
MCQhard

You manage devices with Microsoft Intune. You need to ensure that only devices with a specific BIOS serial number can enroll. What should you configure?

A.Enrollment restrictions that block devices by hardware identifier.
B.A device category with a dynamic group based on BIOS serial.
C.A device compliance policy that checks BIOS serial number.
D.A Conditional Access policy that requires a compliant device.
AnswerA

Enrollment restrictions can block devices based on hardware IDs like BIOS serial numbers.

Why this answer

Intune's enrollment restrictions allow you to block or allow devices based on hardware identifiers such as the BIOS serial number. By adding the specific BIOS serial numbers to the blocked hardware identifiers list, you can effectively prevent any device that does not match the allowed serials from enrolling. This is the only built-in mechanism in Intune that directly controls enrollment eligibility based on hardware characteristics.

Exam trap

The trap here is that candidates often confuse post-enrollment controls (compliance policies, Conditional Access) with pre-enrollment controls (enrollment restrictions), leading them to select options that only take effect after the device has already enrolled.

How to eliminate wrong answers

Option B is wrong because device categories and dynamic groups are used for organizational and targeting purposes after enrollment, not to block or allow enrollment itself. Option C is wrong because a device compliance policy checks conditions after enrollment and can mark a device as noncompliant, but it does not prevent the device from enrolling in the first place. Option D is wrong because a Conditional Access policy that requires a compliant device only applies after the device is enrolled and registered in Azure AD; it cannot block the initial enrollment process.

78
MCQhard

A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?

A.FileVault is not actually enabled on those devices.
B.The recovery key is not escrowed to Intune.
C.The devices are not supervised.
D.The compliance policy is not assigned to those devices.
AnswerB

FileVault being enabled is insufficient for compliance because Intune requires the personal recovery key to be escrowed before it reports the device as compliant. Without escrow, Intune cannot verify key custody, so the device shows non-compliant despite active encryption.

Why this answer

The most likely cause is that the recovery key is not escrowed to Intune. Even though FileVault is enabled on the device, Intune's compliance policy checks for the presence of the FileVault recovery key in its escrow database. If the key is missing, the device is marked non-compliant because Intune cannot verify full management and recovery capability, which is a key security requirement.

Exam trap

The trap here is that candidates assume enabling FileVault alone satisfies compliance, but Intune requires the recovery key to be escrowed to confirm full manageability and recovery capability.

How to eliminate wrong answers

Option A is wrong because the scenario explicitly states that FileVault is enabled on the non-compliant devices, so the issue is not that encryption is absent. Option C is wrong because macOS devices do not require supervision for FileVault compliance; supervision is an iOS/iPadOS concept and does not apply to macOS in this context. Option D is wrong because if the compliance policy were not assigned, the devices would not appear in compliance reports at all, or would show as 'not evaluated' rather than 'non-compliant'.

79
MCQeasy

You manage devices in Microsoft Intune. You need to ensure that a specific set of Windows 10 devices automatically receive new configuration profiles as soon as they are assigned. The devices are already enrolled and are members of an Microsoft Entra ID group. What should you do?

A.Create a device category and assign the profile to that category.
B.Assign the configuration profile to the user who owns the devices.
C.Assign the configuration profile to the Microsoft Entra ID group.
D.Use a dynamic device group based on device name and assign the profile to it.
AnswerC

Assigning the configuration profile to the Microsoft Entra ID group ensures that all devices in that group receive the profile. Intune automatically applies assigned profiles to targeted devices upon check-in. This is the standard method to deploy configurations to a set of devices.

Why this answer

Assigning the configuration profile to the existing Microsoft Entra ID group that contains the devices is the most direct and effective method. Intune will deploy the profile to all devices in the group automatically. Other options either target users, use categories that are not for assignment, or introduce unnecessary complexity.

Exam trap

The trap here is overcomplicating the assignment by using dynamic groups or categories when a static group already exists.

80
Multi-Selecthard

You use Microsoft Intune to manage Windows devices. You need to deploy a Win32 app that must run only on devices running Windows 11 and must be installed silently in the system context. The installer returns exit code 3010 on success but requires a restart. Which two actions must you perform to ensure the app installs correctly and Intune interprets the success code properly? (Choose two.)

Select 2 answers
A.Set the install command to run in user context instead of system context.
B.Assign the app as available instead of required so users can choose when to install it.
C.Create a PowerShell script that maps exit code 3010 to exit code 0 before returning.
D.Configure a requirement rule that the operating system is Windows 11.
E.Add 3010 to the list of return codes that indicate a soft reboot is required.
AnswersD, E

Requirement rules determine whether a Win32 app is applicable to a device. Configuring an operating system requirement for Windows 11 ensures the app is only offered to and installed on Windows 11 devices. Without this, Intune would attempt installation on Windows 10 devices as well, which violates the stated targeting requirement.

Why this answer

Two configuration steps are needed. First, a requirement rule restricting the app to Windows 11 ensures targeting is correct. Second, adding exit code 3010 to the soft reboot return codes tells Intune the installation succeeded but a restart is required, so the app is marked installed and the reboot is handled.

Together these satisfy the operating system targeting and exit code interpretation requirements.

Exam trap

The trap here is wrapping the installer to convert 3010 to 0 or changing the install context, when Intune already supports classifying 3010 as a soft reboot and the operating system targeting belongs in a requirement rule.

81
MCQhard

You are implementing Windows Autopilot for a new fleet of devices. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and is enrolled in Intune. Which configuration is required?

A.Upload corporate identifiers for each device.
B.Configure the Enrollment Status Page in Intune.
C.Create an Autopilot deployment profile assigned to the devices.
D.Create a dynamic device group in Microsoft Entra ID.
AnswerC

An Autopilot deployment profile defines the OOBE behaviour, including the join type. Setting it to Microsoft Entra joined with automatic Intune enrolment satisfies the requirement that the device joins the tenant and enrols during OOBE without manual intervention.

Why this answer

An Autopilot deployment profile specifies the out-of-box experience (OOBE) settings, including the option to automatically join the device to Microsoft Entra ID and enroll it in Intune. Without a deployment profile assigned to the device, Autopilot will not enforce these behaviors during OOBE.

Exam trap

The trap here is that candidates often confuse the prerequisite step of registering the device (uploading corporate identifiers) with the configuration step that actually defines the OOBE behavior (the deployment profile), leading them to select Option A instead of C.

How to eliminate wrong answers

Option A is wrong because uploading corporate identifiers (e.g., hardware hashes) registers the device with Autopilot but does not configure the OOBE behavior; it only enables the device to be recognized by the Autopilot service. Option B is wrong because the Enrollment Status Page (ESP) controls the post-enrollment device setup experience (e.g., app and policy installation progress), not the initial join or enrollment actions during OOBE. Option D is wrong because a dynamic device group in Microsoft Entra ID is used for targeting policies or applications after enrollment, not for triggering or configuring the Autopilot OOBE flow.

82
MCQhard

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

A.It sets the Windows Update for Business ring to that version.
B.It requires the device to be on a specific feature update.
C.It defines the minimum OS build version that the device must have to be compliant.
D.It forces the device to update to that version.
AnswerC

The osMinimumVersion setting in a compliance policy specifies the lowest acceptable OS build; devices below it are marked non-compliant. This satisfies the requirement to enforce a minimum Windows build, letting Intune flag outdated devices and trigger remediation or conditional access blocks.

Why this answer

The 'osMinimumVersion' setting in a Windows 10 compliance policy specifies the minimum OS build version (e.g., 10.0.19041) that a device must have to be considered compliant. If the device's OS build version is lower than this value, Intune marks it as non-compliant, which can trigger conditional access blocks or remediation actions. This setting does not initiate an update; it only evaluates the current version against the defined threshold.

Exam trap

Microsoft often tests the distinction between compliance evaluation (osMinimumVersion) and update enforcement (feature update policies or update rings), leading candidates to incorrectly assume that a compliance setting can force an update.

How to eliminate wrong answers

Option A is wrong because 'osMinimumVersion' does not configure any Windows Update for Business ring; update rings are set via a separate 'UpdateRing' policy or configuration profile. Option B is wrong because the setting checks the exact build number, not a feature update version like '21H2'; feature update versions are managed via feature update deployment policies, not compliance policies. Option D is wrong because this setting is purely evaluative and does not force or trigger an update; it only reports compliance status based on the current OS version.

83
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote workers who do not have access to the corporate network. You need to ensure that the devices are automatically enrolled in Intune and that users can sign in with their Microsoft Entra ID credentials. Which Autopilot deployment mode should you use?

A.Self-deploying mode with Microsoft Entra join.
B.User-driven mode with Microsoft Entra hybrid join.
C.Pre-provisioning with Microsoft Entra hybrid join.
D.User-driven mode with Microsoft Entra join.
AnswerD

User-driven mode with Microsoft Entra join allows users to sign in with their Microsoft Entra ID credentials during OOBE. The device joins Microsoft Entra ID and automatically enrolls in Intune. This mode is ideal for remote workers because it does not require on-premises network connectivity. It meets the requirements of automatic enrollment and Microsoft Entra ID sign-in.

Why this answer

User-driven mode with Microsoft Entra join is the correct choice for remote workers because it allows users to sign in with their Microsoft Entra ID credentials during OOBE, automatically joins the device to Microsoft Entra ID, and enrolls it in Intune without requiring on-premises network connectivity. Other modes either do not support user sign-in or require domain connectivity.

Exam trap

The trap here is assuming that hybrid join is needed for Microsoft Entra ID sign-in, but hybrid join requires on-premises connectivity that remote workers lack.

84
MCQhard

Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Azure AD registered' instead of 'Azure AD joined'. What should you modify to ensure the device is joined?

A.Modify the Autopilot deployment profile to set 'Join to Azure AD as' to 'Azure AD joined'.
B.Add the device to a hybrid Azure AD join profile.
C.Modify the Autopilot deployment profile to set 'Join to Azure AD as' to 'Azure AD registered'.
D.Modify the enrollment restrictions to block personally owned devices.
AnswerA

The Autopilot deployment profile's 'Join to Azure AD as' setting controls whether the device performs a Microsoft Entra join or a work account registration; setting it to 'Azure AD joined' produces the required join type.

Why this answer

The Autopilot deployment profile includes a setting called 'Join to Azure AD as' that determines whether the device performs an Azure AD join or an Azure AD registration. By default, this setting may be configured as 'Azure AD registered', which results in a device that is only registered (workplace-joined) rather than fully joined. Changing this setting to 'Azure AD joined' ensures the device completes a full Azure AD join during the user-driven deployment, making it a managed device in Microsoft Entra ID.

Exam trap

The trap here is that candidates often confuse 'Azure AD registered' with 'Azure AD joined' because both involve Azure AD, but they fail to recognize that the Autopilot profile's join type setting directly controls this distinction, and that enrollment restrictions or hybrid join profiles are unrelated to changing the join type for a cloud-native Autopilot deployment.

How to eliminate wrong answers

Option B is wrong because a hybrid Azure AD join profile is used for devices that need to be joined to both on-premises Active Directory and Azure AD, typically requiring connectivity to a domain controller and synchronization via Azure AD Connect; this does not apply to a pure cloud-native Autopilot scenario where the device should be directly Azure AD joined. Option C is wrong because setting 'Join to Azure AD as' to 'Azure AD registered' would explicitly configure the device to be registered (workplace-joined) rather than joined, which is the opposite of what is needed to fix the issue. Option D is wrong because enrollment restrictions control which devices are allowed to enroll based on platform or ownership type (e.g., blocking personally owned devices), but they do not change the join type from registered to joined; the device would still be registered if the profile specifies registration.

85
MCQeasy

You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?

A.Compliance policies
B.Enrollment restrictions
C.Windows Autopilot devices blade
D.Device cleanup rules in Intune admin center
AnswerD

Device cleanup rules in the Intune admin centre let administrators specify an inactivity threshold, such as 90 days since last check-in, after which Intune automatically retires the device. This directly satisfies the requirement to retire stale devices without manual intervention.

Why this answer

Device cleanup rules in the Intune admin center allow administrators to automatically retire or delete devices that have not checked in for a specified number of days. This is the correct location because the rule is specifically designed for lifecycle management of stale devices, not for compliance or enrollment policies. Setting the threshold to 90 days ensures that devices exceeding that inactivity period are removed from management.

Exam trap

The trap here is that candidates often confuse compliance policies (which can mark devices as non-compliant for inactivity) with the actual retirement action, but compliance policies do not automatically retire devices—they only trigger conditional access or user notifications, whereas device cleanup rules perform the actual removal.

How to eliminate wrong answers

Option A is wrong because compliance policies evaluate device configuration and health against rules (e.g., requiring encryption or a minimum OS version) and can mark devices as non-compliant, but they do not automatically retire devices based solely on check-in inactivity. Option B is wrong because enrollment restrictions control which devices can enroll (e.g., by platform, OS version, or device manufacturer) and do not manage post-enrollment lifecycle actions like retirement. Option C is wrong because the Windows Autopilot devices blade is used to manage Autopilot deployment profiles and device registration for zero-touch provisioning, not to configure automatic retirement rules for stale devices.

86
Multi-Selecteasy

You need to deploy a Windows 10 feature update to a pilot group. Which TWO steps are required in Microsoft Intune?

Select 2 answers
A.Create a feature update policy for Windows 10.
B.Create a driver update policy for Windows 10.
C.Assign the feature update policy to a device group containing pilot devices.
D.Create an update ring for Windows 10.
E.Create a compliance policy for Windows 10.
AnswersA, C

A feature update policy defines which Windows 10 version to deploy and its rollout settings, such as when the update becomes mandatory. This satisfies the stem's deployment requirement by creating the object that later gets assigned to the pilot device group.

Why this answer

Option A is correct because in Microsoft Intune, deploying a Windows 10 feature update requires creating a Windows 10 feature update policy (under Software updates > Windows 10 feature updates), which specifies the target Windows version (e.g., Windows 10 21H2) and rollout settings. Option C is correct because a policy has no effect until it is assigned to a group; you must assign the feature update policy to an Azure AD device group containing the pilot devices so those devices receive the update. Option B is incorrect because driver update policies manage hardware driver updates via Windows Update for Business, not OS feature updates.

Option D is incorrect because update rings control quality (monthly cumulative) updates and deferral/servicing settings, not feature update deployment. Option E is incorrect because compliance policies only evaluate device conditions (e.g., BitLocker, OS version) and do not deliver feature updates.

Exam trap

The trap here is confusing update rings (which control deferral periods and deadlines) with feature update policies (which explicitly set the target version), leading candidates to select 'Create an update ring' instead of the correct feature update policy.

87
MCQhard

You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?

A.Devices must have line-of-sight to an on-premises domain controller.
B.Devices must have VPN connectivity to Azure.
C.An Intune connector for Active Directory must be installed.
D.Azure AD Connect must be configured with password hash sync.
AnswerA

Hybrid Azure AD join requires the device to authenticate against on-premises Active Directory during Autopilot's offline domain join phase, so the device needs network line-of-sight to a domain controller. Without that connectivity, the off-premises domain join cannot complete, and Microsoft Entra ID hybrid registration subsequently fails.

Why this answer

For hybrid Azure AD join via Windows Autopilot, the device must complete domain join during the out-of-box experience. This requires line-of-sight to an on-premises domain controller so that the domain join operation can succeed, as the device cannot join the domain without contacting a DC directly over the network.

Exam trap

The trap here is that candidates often confuse the Intune connector for Active Directory (which is needed for device writeback in hybrid scenarios) with the actual domain join requirement, but the connector does not replace the need for direct line-of-sight to a domain controller.

How to eliminate wrong answers

Option B is wrong because VPN connectivity to Azure is not required; the device needs connectivity to on-premises domain controllers, not Azure. Option C is wrong because the Intune connector for Active Directory is used for device writeback and synchronization, not for the domain join step itself. Option D is wrong because password hash sync is a feature of Azure AD Connect for authentication, not a prerequisite for hybrid Azure AD join; the device must be able to authenticate to the on-premises domain controller directly.

88
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?

A.Create an app protection policy targeting Microsoft 365 apps.
B.Create a device configuration policy to enable TPM and Secure Boot.
C.Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.
D.Create a Conditional Access policy requiring TPM and Secure Boot.
AnswerC

The compliance policy evaluates TPM 2.0 and Secure Boot state via device health attestation, marking non-compliant devices; Conditional Access then blocks their access to Microsoft 365 resources. This combination enforces the hardware constraint at authentication time rather than merely reporting it.

Why this answer

Device compliance policies in Microsoft Intune can evaluate hardware attributes like TPM version and Secure Boot status. When combined with a Conditional Access policy that blocks non-compliant devices, this enforces the security requirements before granting access to Microsoft 365 resources. This two-step approach ensures only devices meeting the hardware security baseline can authenticate.

Exam trap

The trap here is that candidates often think a Conditional Access policy alone can directly check hardware features, but it actually requires a compliance policy to report those attributes first.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection within apps (e.g., copy/paste restrictions) and do not evaluate device-level hardware features like TPM or Secure Boot. Option B is wrong because device configuration policies are used to configure settings (e.g., enable BitLocker) but cannot enforce access control; they lack the ability to block devices from accessing cloud resources. Option D is wrong because a Conditional Access policy alone cannot evaluate TPM or Secure Boot; it relies on device compliance status, which must be reported by Intune via a compliance policy.

89
MCQmedium

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?

A.Device configuration profile
B.Device compliance policy
C.Enrollment restriction
D.App protection policy
AnswerB

A device compliance policy defines passcode requirements, including minimum length, and feeds that state to Microsoft Entra ID. Conditional Access then blocks corporate email on non-compliant iOS devices, directly enforcing the longer-than-six-character passcode constraint before granting access.

Why this answer

Device compliance policies in Microsoft Intune evaluate device settings against defined rules, such as requiring a passcode longer than six characters. When a device is marked noncompliant, Conditional Access can block access to corporate email. This is the correct mechanism because compliance policies are specifically designed to enforce security requirements like passcode length before granting resource access.

Exam trap

The trap here is confusing device configuration profiles (which can set a passcode policy) with compliance policies (which enforce and block access), leading candidates to choose Option A because they think 'configure a policy' means setting the passcode requirement, not enforcing it.

How to eliminate wrong answers

Option A is wrong because device configuration profiles are used to configure device settings (e.g., Wi-Fi, VPN, or passcode policy) but do not enforce compliance or block access to resources; they simply push settings. Option C is wrong because enrollment restrictions control which devices can enroll in Intune (e.g., by platform or OS version), not post-enrollment security requirements like passcode length. Option D is wrong because app protection policies (MAM) manage data within apps (e.g., copy/paste, encryption) and do not enforce device-level passcode requirements; they apply even on unmanaged devices.

90
MCQhard

An organization uses Microsoft Intune for Windows 10 device management. They need to deploy a custom Windows app (.exe) to kiosk devices. The app requires admin privileges to install, and the devices are shared. Which deployment method should be used?

A.Use a Win32 app with install context set to 'system'.
B.Assign the app as 'available' for user-install.
C.Deploy as a line-of-business app with device context.
D.Package as a Microsoft Store for Business app.
AnswerA

Win32 apps with install context set to system run the installer as SYSTEM, granting the admin privileges needed for installation on shared kiosk devices. This satisfies the requirement for privileged installation on shared Windows 10 devices.

Why this answer

Win32 apps in Microsoft Intune can be configured with the install context set to 'system', which grants the necessary admin privileges for installation and ensures the app is installed for all users on shared kiosk devices. This method uses the Intune Management Extension to run the installer with SYSTEM account privileges, bypassing user-level restrictions and supporting per-machine installations.

Exam trap

The trap here is that candidates often confuse 'device context' with 'system context', not realizing that LOB apps cannot handle .exe files and that 'available' assignments run in user context, which fails for admin-required installs on shared devices.

How to eliminate wrong answers

Option B is wrong because assigning the app as 'available' for user-install runs the installer in the user context, which lacks admin privileges and installs per-user, not per-device, making it unsuitable for shared kiosk devices. Option C is wrong because line-of-business (LOB) apps in Intune only support .msi, .appx, or .msix formats, not .exe files, and the 'device context' option for LOB apps is limited to .msi installers with system context, not custom .exe apps. Option D is wrong because packaging as a Microsoft Store for Business app requires the app to be available in the Store or repackaged as a Store-managed app, which does not support custom .exe files and cannot enforce admin privileges during installation.

91
MCQmedium

A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?

A.Use the Microsoft Store for Business to deploy only approved apps.
B.Deploy AppLocker rules via Intune to allow only approved publishers.
C.Enable Windows Defender SmartScreen to block unknown apps.
D.Configure User Account Control (UAC) to always notify.
AnswerB

AppLocker rules deployed through Intune let you allow only approved publishers, giving publisher, product name, file name and version-level control over executables, which is more granular than the broader allow or block lists offered by other application control methods.

Why this answer

AppLocker provides the most granular control because it allows administrators to create rules based on publisher, product name, file name, file version, or file hash, and apply them to specific users or groups. Deployed via Intune, these rules can enforce which applications are allowed to run, effectively blocking unapproved installations. This level of detail (e.g., allowing only signed apps from a specific publisher) is not achievable with the other options.

Exam trap

MD-102 often tests the difference between application control (AppLocker/WDAC) and application management (Intune app deployment); candidates may confuse 'prevent installation' with 'control availability' and pick Store for Business or SmartScreen, which do not provide granular allow-listing.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business only controls which apps are available for self-service installation from the Store; it does not prevent users from installing applications from other sources (e.g., downloading executables from the internet). Option C is wrong because SmartScreen blocks only known malicious or untrusted apps based on reputation, not a custom allow list of approved applications; it cannot enforce a granular policy. Option D is wrong because UAC prompts for elevation but does not block installation of unapproved applications; users with admin rights can still install anything.

92
MCQhard

Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?

A.Install the Intune connector for ConfigMgr and configure the workloads.
B.Create a Group Policy that enables automatic MDM enrollment to Intune.
C.In ConfigMgr, enable co-management, select the devices for pilot, and set the 'Device configuration' workload slider to 'Pilot Intune' or 'Intune'.
D.Configure hybrid Azure AD join for all devices via Group Policy and wait for auto-enrollment.
AnswerC

Co-management requires enabling the feature in ConfigMgr, targeting a pilot collection, then moving each workload slider independently. Setting Device configuration to Pilot Intune or Intune shifts that workload to Intune while Compliance policies and Windows Update policies remain in ConfigMgr.

Why this answer

To enable co-management and move the Device configuration workload to Intune, you need to configure co-management in ConfigMgr. This involves enabling co-management, selecting a pilot collection (or all devices), and setting the workload slider for Device configuration to either 'Pilot Intune' or 'Intune' (full migration). This triggers automatic enrollment in Intune via the co-management policy.

Option A is incorrect because the Intune connector is not needed for co-management; enrollment happens via ConfigMgr policy. Option B is incorrect because Group Policy for automatic MDM enrollment is not required when using co-management; the enrollment is triggered by ConfigMgr. Option D is incorrect because hybrid Azure AD join alone does not automatically enroll devices into co-management; the ConfigMgr co-management configuration is necessary.

93
MCQmedium

You are designing the Windows Autopilot deployment profile for a new subsidiary that has no on-premises infrastructure. All devices will be Microsoft Entra joined. The security team requires that during the out-of-box experience (OOBE), users authenticate with their Microsoft Entra credentials and that local administrator rights are not granted to the primary user. You also want to minimize the time spent at OOBE. Which deployment mode should you select in the Autopilot profile?

A.Microsoft Entra hybrid join with user-driven mode
B.User-driven mode with Microsoft Entra join
C.Pre-provisioning with white glove
D.Self-deploying mode
AnswerB

User-driven mode with Microsoft Entra join prompts the user to sign in with their Microsoft Entra credentials during OOBE, which meets the requirement for authentication. It does not automatically grant local administrator rights unless you explicitly configure the user as a local admin in the profile, so the security requirement is satisfied. This mode also streamlines OOBE by applying device settings and apps automatically after sign-in.

Why this answer

User-driven mode with Microsoft Entra join allows the user to sign in with their Microsoft Entra credentials during OOBE, satisfying the authentication requirement. It does not grant local administrator rights by default, aligning with the security policy. The absence of on-premises infrastructure rules out hybrid join, and self-deploying mode skips user authentication, while pre-provisioning is unnecessary for the stated goals.

Exam trap

The trap here is assuming that self-deploying mode authenticates users; it actually uses the device identity and is intended for shared or kiosk devices.

94
MCQmedium

You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?

A.Confirm that the user is assigned a Microsoft Entra ID P1 license.
B.Verify that the BitLocker recovery key is backed up to Microsoft Entra ID.
C.Ensure the Windows Defender Firewall allows inbound RPC traffic.
D.Check that the MDM enrollment URL (https://enrollment.manage.microsoft.com) is reachable and not blocked by a proxy.
AnswerD

Reaching the MDM enrolment URL is the prerequisite for MDM enrolment, but the stem already confirms internet connectivity, so a proxy blocking that specific endpoint remains the plausible cause. Domain-joined devices use the enrolment URL directly; verifying it is reachable isolates proxy or firewall filtering from the update's other effects.

Why this answer

The most common cause of MDM enrollment failure after a Windows update is a change in proxy or firewall settings that blocks the MDM enrollment URL. Since the devices can reach the internet generally but fail specifically during enrollment, verifying that `https://enrollment.manage.microsoft.com` is reachable and not blocked by a proxy is the logical first troubleshooting step. This URL is required for the device to communicate with the Intune MDM service during the enrollment process.

Exam trap

The trap here is that candidates often assume a general internet connection means all services are reachable, but MDM enrollment requires specific URLs that may be blocked by a proxy or firewall even when general browsing works.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P1 licenses are required for features like Conditional Access, but not for basic MDM enrollment; a user needs an Intune license (e.g., Microsoft 365 E3/E5 or standalone Intune) to enroll. Option B is wrong because BitLocker recovery key backup to Microsoft Entra ID is a post-enrollment compliance or recovery feature, not a prerequisite for MDM enrollment. Option C is wrong because inbound RPC traffic is not required for MDM enrollment; the device initiates outbound HTTPS (TCP 443) connections to Intune, and inbound RPC is irrelevant to this process.

95
MCQhard

You are troubleshooting a Windows 10 device that is showing as non-compliant in Intune. The exhibit shows the PowerShell output from the Microsoft Graph API. Based on the output, what is the most likely reason for the non-compliance?

A.The device does not have a compliant operating system version
B.BitLocker drive encryption is not enabled on the device
C.The device is not running a supported version of Windows 10
D.The device has a third-party antivirus installed
AnswerB

The Graph API output lists the compliance setting storageRequireEncryption as failing, which maps directly to BitLocker. Since the device reports non-compliant and this is the only failing rule shown, BitLocker encryption is not enabled, so Intune flags the device.

Why this answer

The output shows the non-compliance reason is 'RequireEncryption', indicating BitLocker is not enabled. Option A is incorrect because the reason is about encryption, not operating system version. Option C is incorrect because the reason is about encryption, not the Windows version.

Option D is incorrect because the reason is about encryption, not antivirus.

96
MCQhard

Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?

A.The devices have an OS version lower than 10.0.19041.
B.The install command line is missing the /silent switch.
C.The detection rule path is incorrect.
D.The install experience is set to system, but should be user.
AnswerA

Windows 10 builds below 10.0.19041 fall outside the minimum operating system requirement configured in the Win32 app's applicability rules, so Intune marks the app as not applicable and skips installation. Raising the requirement or upgrading those devices restores deployment, satisfying the OS version constraint in the stem.

Why this answer

The exhibit shows the 'Minimum OS version' requirement set to 10.0.19041 (Windows 10 version 20H1/2004). Devices with an OS build lower than this threshold will fail to install the Win32 app, as Intune enforces this requirement before executing the installation command. This is a common configuration issue when deploying apps to a mixed-OS environment.

Exam trap

The trap here is that candidates often focus on the install command or detection rules as the cause of installation failure, overlooking the explicit OS version requirement that prevents installation from even starting on incompatible devices.

How to eliminate wrong answers

Option B is wrong because the install command line is not missing the /silent switch; the exhibit shows the command includes '--silent' (or a similar silent flag), so the absence of /silent is not the issue. Option C is wrong because the detection rule path being incorrect would cause the app to appear as 'Not Installed' on devices where it actually installed, not prevent installation from starting. Option D is wrong because the install experience set to 'system' is correct for system-wide installations; setting it to 'user' would install per-user and could cause issues, but the exhibit shows 'system' is selected, so this is not the problem.

97
MCQeasy

You need to deploy a Microsoft Store app (e.g., Microsoft Whiteboard) to Windows 10 devices managed by Intune. Which app type should you use?

A.Microsoft Store app (Windows)
B.Windows app (Win32)
C.Web link
D.Microsoft Store for Business (offline licensed)
AnswerA

The Microsoft Store app (Windows) type deploys Store apps such as Microsoft Whiteboard to Windows 10 devices by linking the Store listing, enabling Intune to install and update them. This satisfies the stem's requirement for deploying a Microsoft Store app.

Why this answer

To deploy a Microsoft Store app like Microsoft Whiteboard to Windows 10 devices managed by Intune, you must use the 'Microsoft Store app (Windows)' app type. This type directly integrates with the Microsoft Store catalog, allowing you to select and deploy store apps without needing offline licensing or manual packaging. It supports both online and offline licensing models, but for a standard store app deployment, this is the correct and simplest choice.

Exam trap

The trap here is that candidates often confuse 'Microsoft Store app (Windows)' with 'Microsoft Store for Business (offline licensed)', thinking offline licensing is always required for managed deployments, but the standard store app type works for online scenarios and is the default choice for deploying store apps like Whiteboard.

How to eliminate wrong answers

Option B is wrong because 'Windows app (Win32)' is used for deploying traditional desktop applications (e.g., .exe, .msi) that require custom installation scripts or detection rules, not for Microsoft Store apps. Option C is wrong because 'Web link' simply creates a shortcut to a URL in the Company Portal and does not install any application. Option D is wrong because 'Microsoft Store for Business (offline licensed)' is a specific licensing model for offline deployment of store apps, but the question does not specify an offline requirement; the standard 'Microsoft Store app (Windows)' type can handle both online and offline scenarios, and is the general-purpose type for store apps.

98
MCQmedium

You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?

A.Device compliance policy for Windows 10 and later
B.Endpoint security policy for Windows 10 and later
C.Device configuration profile for Windows 10 and later
D.App protection policy for Windows 10 and later
AnswerA

A device compliance policy for Windows 10 and later allows you to specify a minimum OS version for Windows devices. You can set the required minimum OS version to 10.0.22621.1992, and Intune will evaluate the device's OS build and mark it noncompliant if it does not meet the requirement. This directly enforces the security team's requirement.

Why this answer

A device compliance policy for Windows 10 and later is the correct choice because it includes a setting to require a minimum OS version. By setting the minimum OS version to 10.0.22621.1992, Intune will evaluate the OS build and mark devices that do not meet the requirement as noncompliant, which can then trigger conditional access or other actions.

Exam trap

The trap here is confusing device configuration profiles, which configure settings, with compliance policies, which evaluate and report on device state.

99
Multi-Selectmedium

Which THREE are valid Windows Autopilot deployment scenarios?

Select 3 answers
A.Self-deploying
B.App-driven
C.User-driven
D.Policy-driven
E.White glove
AnswersA, C, E

Self-deploying mode provisions devices with no user interaction, using a device-based Microsoft Entra ID join and TPM attestation. This satisfies the scenario's requirement for kiosk and shared-device rollouts where no credentials can be entered, making it one of the three valid Windows Autopilot deployment scenarios.

Why this answer

Self-deploying (A) is a valid Windows Autopilot scenario in which the device is provisioned with no user interaction, using a device-targeted profile and TPM attestation, ideal for kiosks and shared devices. User-driven (C) is valid because it lets the end user sign in with their Azure AD credentials during OOBE, after which the Autopilot profile applies device and user settings. White glove (E) is valid as the pre-provisioning scenario where a partner or IT technician runs the provisioning process so the device reaches the user ready for a fast, final sign-in.

App-driven (B) and Policy-driven (D) are not Autopilot deployment scenarios; Autopilot modes are defined by user interaction and pre-provisioning, not by app or policy triggers.

Exam trap

The trap here is that candidates confuse deployment phases or management concepts (like app or policy deployment) with the three official Autopilot deployment scenarios, which are strictly self-deploying, user-driven, and white glove (pre-provisioning).

100
Multi-Selecteasy

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)

Select 2 answers
A.Reset a user's password.
B.View hardware inventory of a device.
C.Remotely sync a device with Intune.
D.Manage on-premises Active Directory objects.
E.Assign Microsoft 365 licenses to a user.
AnswersB, C

Inventory is visible in the device properties.

Why this answer

The Microsoft Intune admin center provides a hardware inventory view for managed Windows devices, displaying details such as processor, RAM, disk space, and firmware version. This data is collected via the Intune Management Extension and device inventory reports, enabling administrators to assess device compliance and readiness without requiring on-premises tools.

Exam trap

The trap here is that candidates confuse user management tasks (password reset, license assignment) with device management actions, or assume Intune can manage on-premises AD objects, when Intune's scope is strictly cloud-based device and app management via MDM and MAM.

101
MCQhard

You are configuring Windows Update for Business policies in Microsoft Intune for a group of Windows 11 devices. You need to ensure that devices do not install feature updates for 60 days after a new version is released, while still receiving quality updates immediately. Which setting should you configure?

A.Set the 'Automatic update behavior' to 'Auto install at maintenance time'.
B.Set the 'Quality update deferral period (days)' to 60.
C.Configure a Windows Update ring with a 'Servicing channel' set to 'Semi-Annual Channel'.
D.Set the 'Feature update deferral period (days)' to 60.
AnswerD

The feature update deferral period setting in Windows Update for Business allows you to postpone feature updates for a specified number of days after their release. Setting it to 60 ensures devices wait 60 days before installing a new feature update, while quality updates are not deferred and install immediately. This directly meets the requirement.

Why this answer

Feature update deferral in Windows Update for Business is specifically designed to delay feature updates while allowing quality updates to proceed. Setting the deferral period to 60 days ensures that devices will not receive a new feature update until 60 days after its release, meeting the requirement without affecting quality updates.

Exam trap

The trap here is confusing deferral settings for quality updates with those for feature updates, which can lead to delaying security patches unintentionally.

102
Multi-Selectmedium

You are an endpoint administrator for a company that uses Microsoft Intune. The company plans to deploy Windows 11 devices using Windows Autopilot in self-deploying mode. You need to ensure that the devices can be provisioned without any user interaction. Which two configurations are required for self-deploying mode? (Choose two.)

Select 2 answers
A.The device must be joined to an on-premises Active Directory domain.
B.The device must be registered with Windows Autopilot.
C.The device must have a wired network connection.
D.The device must have TPM 2.0 enabled.
E.A device enrollment manager (DEM) account must be assigned.
AnswersB, D

Before a device can use self-deploying mode, it must be registered with Windows Autopilot. This involves uploading the device's hardware hash to Intune. The Autopilot service uses this hash to identify the device and assign the appropriate deployment profile. Without registration, the device will not receive the self-deploying profile during OOBE.

Why this answer

Self-deploying mode requires TPM 2.0 and that the device is registered with Windows Autopilot. TPM 2.0 provides the hardware-based identity needed for device authentication without user credentials. Autopilot registration ensures the device receives the self-deploying profile.

On-premises domain join, DEM accounts, and wired connections are not required for this mode.

Exam trap

The trap here is assuming that self-deploying mode requires a DEM account or wired connection, when it actually relies on TPM 2.0 and Autopilot registration.

103
Multi-Selectmedium

Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?

Select 2 answers
A.Maximum OS version
B.Require antivirus (Windows Defender)
C.Minimum OS version
D.Device type
E.Storage encryption
AnswersB, C

Requiring antivirus in the Windows compliance policy directly satisfies the stem's second condition: devices must have antivirus enabled. Intune evaluates Windows Defender's real-time protection status through this setting, marking non-compliant devices that lack active antivirus. Combined with the minimum OS version setting, both stated requirements are enforced.

Why this answer

Option C (Minimum OS version) is correct because a Windows compliance policy enforces a required OS build/version by setting the minimum OS version, which blocks devices running older builds than the specified value. Option B (Require antivirus (Windows Defender)) is correct because the compliance policy includes a setting that requires Windows Defender Antivirus to be enabled (and optionally up to date) on the device. Option A (Maximum OS version) is not appropriate here because the requirement is to ensure devices are at least a specific OS version, not to cap them at a maximum version.

Option D (Device type) is not a compliance setting for enforcing OS version or antivirus state; it is used for targeting/platform scoping. Option E (Storage encryption) enforces BitLocker/device encryption and does not address the OS version or antivirus requirements.

Exam trap

MD-102 often tests the distinction between compliance settings that validate device state (minimum OS, antivirus, encryption) versus configuration settings that change device state, causing candidates to pick Maximum OS version or Device type by mistake.

104
MCQhard

Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?

A.The device will be allowed to proceed because enrollment status is notStarted.
B.The device will retry enrollment automatically.
C.The device will be blocked from completing OOBE.
D.The device will be blocked until retry due to pendingRetry setting.
AnswerC

When a required app fails during Autopilot OOBE, the enrolment profile's blocking behaviour halts the process, so the device cannot complete setup. This matches the stem's failed-app scenario: the device is blocked from finishing OOBE rather than continuing with reduced functionality.

Why this answer

The Autopilot deployment profile shown has the Enrollment Status Page (ESP) configured with 'Block device use until all required apps and profiles are installed' enabled. When a required app fails to install during OOBE, the ESP enforces a hard block, preventing the user from proceeding past the ESP until the failure is resolved. This is why the device is blocked from completing OOBE, making option C correct.

Exam trap

The trap here is that candidates confuse the ESP's 'block device use' setting with a simple retry mechanism, assuming the device will automatically retry or proceed, when in fact a hard block is enforced until the failure is resolved.

How to eliminate wrong answers

Option A is wrong because the enrollment status is not 'notStarted'; the ESP tracks installation progress, and a failure triggers a blocking state, not a pass-through. Option B is wrong because the ESP does not automatically retry enrollment; it blocks the device and requires manual intervention (e.g., reset or troubleshooting) unless a retry timeout is configured, which is not shown in the exhibit. Option D is wrong because 'pendingRetry' is not a valid ESP state; the ESP uses states like 'installing', 'failed', or 'timeout', and the device is blocked immediately upon failure, not placed into a pending retry state.

105
Multi-Selectmedium

You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)

Select 2 answers
A.Android store app type.
B.Windows Installer (Win32) app type using the Office Deployment Tool.
C.Web link app type pointing to the Office website.
D.iOS store app type.
E.Microsoft 365 Apps for Windows app type in Intune.
AnswersB, E

Packaging Microsoft 365 Apps as a Win32 app lets Intune run the Office Deployment Tool's setup.exe with a custom configuration XML, controlling which products, languages and update channels install. This satisfies the stem's Intune deployment requirement, since the Office Deployment Tool cannot be delivered through the Microsoft 365 Apps (Windows 10 and later) app type.

Why this answer

Option B is correct because you can package Microsoft 365 Apps as a Windows Installer (Win32) app in Intune by using the Office Deployment Tool (ODT) to generate the setup.exe and Configuration.xml, then wrap it with the Intune Win32 Content Prep Tool for deployment. Option E is correct because Intune provides a dedicated built-in app type called 'Microsoft 365 Apps for Windows' (the Microsoft 365 Apps app type) that lets you select Office apps, update channel, and architecture directly without packaging. Option A is incorrect because the Android store app type deploys Android apps, not Windows Office apps.

Option C is incorrect because a web link app type only creates a shortcut to a URL and does not install Microsoft 365 Apps. Option D is incorrect because the iOS store app type targets iOS devices, not Windows.

Exam trap

The trap here is that candidates often confuse the 'Web link' app type with a valid deployment method, thinking it will trigger an installation, when in fact it only provides a browser shortcut to the Office website without any local installation.

106
MCQeasy

You manage devices with Microsoft Intune. You need to deploy a Windows 10 feature update to a pilot group of devices. Which profile type should you use?

A.Windows 10 configuration profile
B.Windows 10 compliance policy
C.Windows 10 update ring profile
D.Windows 10 feature update profile
AnswerD

A Windows 10 feature update profile in Intune deploys a specific Windows feature update version to targeted devices, letting you scope it to the pilot group. Other profile types handle configuration, compliance, or quality updates, not feature-version upgrades.

Why this answer

A Windows 10 feature update profile is the correct choice because it is specifically designed to deploy feature updates (e.g., Windows 10 version 22H2) to targeted groups in Intune. Unlike update rings, which control the timing and deferral of updates, a feature update profile pins devices to a specific Windows version and orchestrates the upgrade process for pilot or broad deployments.

Exam trap

The trap here is that candidates often confuse update ring profiles (which manage update timing) with feature update profiles (which deploy a specific version), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because a Windows 10 configuration profile is used to configure device settings (e.g., security policies, browser settings) and cannot deploy feature updates. Option B is wrong because a Windows 10 compliance policy evaluates device compliance against rules (e.g., required OS version) but does not initiate or manage the deployment of feature updates. Option C is wrong because a Windows 10 update ring profile controls the deferral, pause, and rollout of quality updates and feature updates via Windows Update for Business, but it does not pin devices to a specific feature update version; it only manages update behavior and timing.

107
MCQhard

You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?

A.Create a dynamic device group in Microsoft Entra ID that includes all Windows 11 devices.
B.Assign Microsoft Intune licenses to all users who will receive the new devices.
C.Register the devices in Windows Autopilot by providing the hardware hash to the Microsoft Intune admin center.
D.Create a compliance policy that requires BitLocker encryption and a minimum OS version.
AnswerC

Windows Autopilot requires each device's hardware hash registered in Intune before deployment, binding the device to the tenant. Uploading hashes establishes this identity, enabling zero-touch provisioning where the vendor ships devices directly to users without IT imaging.

Why this answer

Windows Autopilot is the cloud-based zero-touch deployment solution that uses hardware hashes to register devices in Intune, enabling them to automatically enroll and receive configurations without IT intervention. This directly meets the requirement for pre-provisioned Windows 11 devices with no manual touch.

Exam trap

The trap here is confusing post-enrollment configuration steps (like creating groups or compliance policies) with the prerequisite enrollment mechanism, leading candidates to select a step that is necessary but not sufficient for zero-touch deployment.

How to eliminate wrong answers

Option A is wrong because creating a dynamic device group in Entra ID is a post-enrollment step for applying policies or targeting apps, not a mechanism for zero-touch enrollment itself. Option B is wrong because assigning Intune licenses is a prerequisite for enrollment but does not automate the enrollment process; it must be combined with Autopilot registration to achieve zero-touch. Option D is wrong because creating a compliance policy enforces security settings after enrollment, but it does not initiate or automate the enrollment process.

108
MCQhard

You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?

A.Endpoint Protection
B.Windows Update Policies
C.Client Apps
D.Device Configuration
AnswerB

Moving the Windows Update Policies workload slider to Intune transfers update policy authority from Configuration Manager to Intune for co-managed devices. This directly satisfies the stem's requirement that Intune manage Windows Update policies across all co-managed Windows 10 devices.

Why this answer

In a co-management scenario, the workload slider determines which management authority handles specific workloads. Setting the 'Windows Update Policies' slider to 'Intune' directs Windows Update for Business policies to be applied via Intune, overriding Configuration Manager policies for co-managed Windows 10 devices. This ensures that update rings and deferral settings configured in Intune are enforced.

Exam trap

The trap here is that candidates often confuse the 'Windows Update Policies' slider with the 'Endpoint Protection' slider, mistakenly thinking update management is part of security policies, but the slider specifically governs Windows Update for Business policies, not Defender or antivirus updates.

How to eliminate wrong answers

Option A is wrong because the Endpoint Protection workload slider controls antimalware and firewall policies (e.g., Defender for Endpoint), not Windows Update policies. Option C is wrong because the Client Apps workload slider governs the deployment of applications (e.g., MSI, Win32 apps) from Intune or Configuration Manager, not update management. Option D is wrong because the Device Configuration workload slider manages settings like compliance policies and resource access (e.g., VPN, Wi-Fi), not Windows Update policies.

109
Multi-Selectmedium

Which TWO actions are required to deploy a Win32 app using Microsoft Intune? (Choose two.)

Select 2 answers
A.Upload the .intunewin package file.
B.Configure detection rules.
C.Connect to Managed Google Play.
D.Assign a Microsoft Store license.
E.Sign the app with a macOS developer certificate.
AnswersA, B

Win32 apps in Intune require the source files wrapped by the IntuneWinAppUtil tool, producing a .intunewin package. Uploading that package is the mandatory first step before configuring the install and uninstall commands, detection rules and requirements.

Why this answer

Option A is correct because deploying a Win32 app in Intune requires first wrapping the source files with the Microsoft Win32 Content Prep Tool to produce a .intunewin package, which is then uploaded to the Intune admin center as the app's installation source. Option B is correct because Intune must determine whether the app is already installed on a device, so the Win32 app configuration requires detection rules (such as an MSI product code, file/folder path, or registry key) to report installation status and drive the install/uninstall behavior. Option C is incorrect because connecting to Managed Google Play applies to Android Enterprise app deployment, not Win32 apps.

Option D is incorrect because assigning a Microsoft Store license relates to Store apps (UWP/MSIX) rather than Win32 packages. Option E is incorrect because a macOS developer certificate is used for signing Apple apps, which is irrelevant to Windows Win32 deployment.

Exam trap

The trap here is that candidates may confuse the requirements for Win32 apps with those for other platforms (Android, Microsoft Store, macOS), leading them to select options that are valid for those platforms but irrelevant for Win32 deployment.

110
MCQhard

You are designing a Windows Autopilot deployment for a global organization. Devices are purchased from multiple OEMs and shipped directly to users. Some users report that their devices do not register in Autopilot automatically. You confirm the devices have Windows 11 Pro preinstalled and meet hardware requirements. What is the most likely reason for the registration failure, and what should you do to resolve it?

A.The devices are not registered in Autopilot by the OEM; collect the hardware hash using a script
B.The devices have a TPM chip that is not compliant with Autopilot requirements
C.The Autopilot deployment profile is assigned to a dynamic device group that excludes these devices
D.The devices are not connected to the internet during OOBE
AnswerA

Autopilot automatic registration depends on the OEM or reseller uploading the hardware hash to the tenant during manufacture. Windows 11 Pro preinstalled alone does not register a device, so the hash must be collected manually with a script and imported.

Why this answer

The most likely reason is that the OEM did not register the devices in Windows Autopilot by uploading their hardware hashes to the Microsoft Partner Center. Without this registration, the devices will not be recognized during OOBE and will not automatically receive the Autopilot deployment profile. To resolve this, you must collect the hardware hash from each device using a PowerShell script (e.g., Get-WindowsAutopilotInfo.ps1) and manually upload it to Intune or the Partner Center.

Exam trap

The trap here is that candidates often assume the issue is with TPM or connectivity during OOBE, but the core problem is that the device was never registered in Autopilot by the OEM, which is a prerequisite for automatic profile assignment.

How to eliminate wrong answers

Option B is wrong because TPM compliance is not a prerequisite for Autopilot registration; Autopilot requires TPM 2.0 only for self-deploying mode, but the question does not specify that mode, and devices with non-compliant TPM would still register and show in Intune. Option C is wrong because dynamic device group membership is evaluated after a device is registered in Autopilot; if the device is not registered, the group assignment is irrelevant. Option D is wrong because internet connectivity during OOBE is required for Autopilot to download the profile, but the issue here is that the device never appears in Autopilot at all, which indicates a registration failure, not a connectivity problem.

111
MCQmedium

You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?

A.Verify that the user is assigned an Intune license.
B.Run the 'dsregcmd /status' command to check the device registration status.
C.Check that the device has a TPM chip enabled and Secure Boot turned on.
D.Ensure the compliance policy is assigned to a group that includes the user or device.
AnswerD

A compliance policy showing 'Not evaluated' typically means no policy applies to that device or user. Verifying the policy's group assignment, ensuring the user or device is included, is the first check before investigating sync or client issues.

Why this answer

A compliance policy must be assigned to a group containing the user or device for it to be evaluated. Even if the device is enrolled and syncing, without assignment the policy will not apply, resulting in a 'Not evaluated' status in Intune.

Exam trap

The trap here is that candidates confuse 'Not evaluated' with a device health or configuration issue, when it actually points to a missing policy assignment or group membership problem.

How to eliminate wrong answers

Option A is wrong because an Intune license is required for enrollment and sync, which the user already has (device is enrolled and syncing), so licensing is not the cause of 'Not evaluated' status. Option B is wrong because 'dsregcmd /status' checks Azure AD registration and hybrid join status, not compliance policy assignment or evaluation; the device is already enrolled and syncing, indicating registration is fine. Option C is wrong because TPM and Secure Boot are prerequisites for BitLocker or device health attestation, not for compliance policy evaluation; their absence would cause specific compliance failures, not a 'Not evaluated' status.

112
MCQhard

You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?

A.The device does not have internet connectivity to download the app.
B.The device's certificate for Intune is expired.
C.The Intune management extension is not installed on the device.
D.The device requires a restart to complete previous updates.
AnswerC

Line-of-business apps deploy through the Intune management extension, which is installed by a PowerShell script agent on the device. Without that extension, the LOB app remains Pending indefinitely, even though the device is online and checking in.

Why this answer

The Intune management extension is responsible for deploying line-of-business (LOB) apps and PowerShell scripts on Windows devices. If this extension is not installed, the device will show a 'Pending' status for required app deployments because the Intune service cannot initiate the download or installation. Since the device has been online, connectivity is not the issue, and the extension must be present to process the deployment.

Exam trap

The trap here is that candidates often assume a 'Pending' status is always due to network issues or pending reboots, but Microsoft specifically tests the requirement of the Intune management extension for LOB app deployments on Windows devices.

How to eliminate wrong answers

Option A is wrong because the device has been online for the past 24 hours, indicating internet connectivity is available, and a 'Pending' status typically does not result from transient connectivity issues. Option B is wrong because an expired Intune certificate would cause the device to appear as 'Not compliant' or 'Unhealthy' in the Intune console, not a 'Pending' status for a specific app deployment. Option D is wrong because a pending restart would affect the installation of updates, not the initial download or deployment status of an LOB app, and the device would still show the app as 'Pending' only if the management extension were missing.

113
Multi-Selectmedium

Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?

Select 3 answers
A.Change the primary user
B.Change the enrolled user
C.Restart the device
D.Sync the device
E.Change the device name
AnswersA, C, D

Changing the primary user reassigns device ownership in Microsoft Intune, which is a supported remote action from the admin centre. It satisfies the stem's requirement for actions performed on a managed device without requiring physical access or re-enrolment.

Why this answer

The Microsoft Intune admin center supports several remote actions on managed devices. Changing the primary user (A), Restart (C), and Sync (D) are all valid remote actions. Options B (Change the enrolled user) and E (Change the device name) are not available remotely.

Exam trap

Candidates often assume that changing the primary user is not possible, but Intune does support this remote action. The trap is to incorrectly limit remote actions to only Restart and Sync, omitting Change primary user.

114
MCQeasy

Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?

A.Enable Device Encryption in Windows settings.
B.Configure a FileVault policy for Windows devices.
C.Create a BitLocker policy in Intune Endpoint Protection.
D.Deploy an Encrypting File System (EFS) policy.
AnswerC

BitLocker policy in Intune Endpoint Protection directly enforces full-disk encryption on Windows 10 laptops, satisfying the corporate encryption requirement. It configures TPM-backed drive encryption and recovery key escrow to Microsoft Entra ID, unlike device compliance policies, which only report encryption state rather than enforce it.

Why this answer

Microsoft Intune's Endpoint Protection policy includes a dedicated BitLocker settings section that allows administrators to enforce encryption on Windows 10 devices. This policy centrally manages BitLocker drive encryption, recovery key escrow to Azure AD, and encryption method (e.g., XTS-AES 128-bit), meeting the requirement for corporate laptop encryption.

Exam trap

The trap here is confusing file-level encryption (EFS) with full-disk encryption (BitLocker), or assuming that Device Encryption in Windows settings is the same as BitLocker, when in fact Device Encryption is a limited feature only available on specific hardware and lacks the management capabilities of Intune's BitLocker policy.

How to eliminate wrong answers

Option A is wrong because 'Enable Device Encryption' in Windows settings is a client-side toggle that only enables hardware-based encryption on devices that support InstantGo (Modern Standby), and it cannot be centrally managed or enforced via Intune policy. Option B is wrong because FileVault is Apple's full-disk encryption technology for macOS, not applicable to Windows 10 devices. Option D is wrong because Encrypting File System (EFS) provides file-level encryption, not full-disk encryption, and is managed via NTFS permissions or Group Policy, not Intune's endpoint protection policies for BitLocker.

115
MCQeasy

You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?

A.Device compliance policy
B.App protection policy
C.Conditional Access policy
D.Device configuration profile
AnswerC

Conditional Access evaluates device compliance state signalled by Intune before granting access to cloud apps, so it enforces the compliant-device requirement for Exchange Online. Compliance policies alone only mark devices; Conditional Access is the gate that blocks noncompliant ones.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) evaluate signals such as device compliance status from Intune before granting access to cloud apps like Exchange Online. By integrating with Intune compliance policies, a Conditional Access policy can block or allow access based on whether the device meets compliance requirements. This is the correct mechanism to enforce access control for compliant devices.

Exam trap

The trap here is that candidates often confuse Device compliance policies (which only assess and report compliance) with Conditional Access policies (which actually enforce access decisions), leading them to select the compliance policy as the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because a Device compliance policy only marks a device as compliant or non-compliant; it does not enforce access control to Exchange Online on its own. Option B is wrong because App protection policies manage data protection within applications (e.g., preventing copy/paste) and do not evaluate device compliance or control access to Exchange Online at the device level. Option D is wrong because Device configuration profiles apply settings like Wi-Fi or VPN configurations and do not enforce conditional access based on compliance status.

116
MCQhard

You are a Microsoft 365 Endpoint Administrator for a mid-sized company with 5,000 Windows 10 devices. The company is planning to migrate to Windows 11. You are tasked with deploying Windows 11 using a phased approach with Windows Autopilot. You have configured an Autopilot deployment profile for self-deploying mode targeting all Windows 10 devices in a dynamic device group. However, during the first wave of deployment, you notice that devices that have been upgraded to Windows 11 via an in-place upgrade are not automatically transitioning to the Autopilot experience. Instead, they boot directly to the existing Windows 10 desktop without any Autopilot enrollment. You verify that the devices are registered in Autopilot and that the deployment profile is assigned correctly. What is the most likely cause of this issue?

A.The Autopilot profile has a pre-provisioning policy that blocks self-deploying mode
B.The devices have not been reset to OOBE state after the in-place upgrade
C.The Autopilot profile is configured for user-driven mode instead of self-deploying mode
D.The devices are not connected to the internet during the first boot after upgrade
AnswerB

Autopilot self-deploying mode triggers only during the out-of-box experience. An in-place upgrade preserves the existing Windows installation and user state, so the device boots straight to the desktop and never presents OOBE, meaning Autopilot cannot intercept it until the device is reset.

Why this answer

Windows Autopilot requires the device to be in an Out-of-Box Experience (OOBE) state to trigger the enrollment process. An in-place upgrade to Windows 11 preserves the existing user state and settings, so the device boots directly to the desktop without entering OOBE. Even though the device is registered in Autopilot and the profile is assigned, the Autopilot experience only initiates when the device is reset to OOBE (e.g., via a Windows reset or a fresh start).

Therefore, the most likely cause is that the devices have not been reset to OOBE state after the in-place upgrade.

Exam trap

The trap here is that candidates assume Autopilot enrollment will automatically trigger after any upgrade or reboot on a registered device, but they overlook the critical requirement that the device must be in OOBE state to initiate the Autopilot process.

How to eliminate wrong answers

Option A is wrong because a pre-provisioning policy does not block self-deploying mode; pre-provisioning is an optional phase that can be used with self-deploying mode, and it does not prevent the Autopilot enrollment from starting. Option C is wrong because the question states the profile is configured for self-deploying mode, and if it were misconfigured for user-driven mode, the device would still attempt to enroll (but prompt for user credentials) rather than boot directly to the desktop. Option D is wrong because internet connectivity is required for Autopilot enrollment, but the issue here is that the device never enters the OOBE phase where it would check for connectivity; the device boots to the existing desktop, so connectivity is not the blocking factor.

117
Multi-Selectmedium

Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?

Select 3 answers
A.Add devices to Apple Business Manager (ABM).
B.Configure automated device enrollment (formerly DEP) in ABM and link to Intune.
C.Create an iOS enrollment profile in Intune with 'Supervised' enabled.
D.Assign a user to each device during enrollment.
E.Create a device compliance policy that requires supervision.
AnswersA, B, C

Adding devices to Apple Business Manager establishes the automated device enrolment (ADE) record Apple requires before Intune can push a supervision profile. Supervision is the constraint here: only DEP-enrolled iOS devices accept non-removable restriction payloads, so ABM enrolment is a mandatory prerequisite step.

Why this answer

Supervision on iOS requires the device to be owned and enrolled through Apple's corporate enrollment channel, so option A is correct: the devices must be added to Apple Business Manager (ABM) so Apple recognizes them as organization-owned and eligible for supervised enrollment. Option B is correct because automated device enrollment (formerly DEP) must be configured in ABM and linked to Intune via an MDM server token, which is the mechanism that pushes the devices into Intune as supervised during Setup Assistant. Option C is correct because the Intune iOS enrollment profile used for these devices must have the 'Supervised' setting enabled; this profile is what actually applies supervision and allows restrictions that users cannot remove.

Option D is not required because user assignment (or user affinity) is optional for automated device enrollment and does not create supervision. Option E is incorrect because a compliance policy only evaluates and reports device state; it cannot enable or grant supervision.

Exam trap

MD-102 often tests that supervision requires ABM + ADE + a supervised enrollment profile — candidates incorrectly think a compliance policy or user assignment can enable supervision.

118
Multi-Selecthard

An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?

Select 2 answers
A.BitLocker
B.Encrypting File System (EFS)
C.Device encryption
D.FileVault
E.APFS encryption
AnswersA, C

BitLocker is the native Windows volume-level encryption technology, configurable through Intune's disk encryption policy for Windows devices. It satisfies the stem's requirement for a valid encryption option to enforce disk encryption across managed Windows endpoints.

Why this answer

BitLocker (A) is correct because it is Microsoft's full-volume disk encryption feature for Windows and is the primary encryption method configured through Intune disk encryption policies. Device encryption (C) is also correct because it is a Windows feature (available on supported devices, often with Modern Standby and a Microsoft account) that Intune can enforce via the same disk encryption policy profile. EFS (B) is not a valid answer here because it encrypts individual files and folders on NTFS volumes rather than enforcing full disk encryption.

FileVault (D) is incorrect because it is Apple's macOS disk encryption technology, not a Windows encryption option. APFS encryption (E) is incorrect because APFS is an Apple file system and its encryption applies to macOS/iOS devices, not Windows devices managed by Intune.

Exam trap

The trap here is that candidates often confuse file-level encryption (EFS) with full-disk encryption, or mistakenly apply macOS-specific technologies (FileVault, APFS encryption) to Windows devices, forgetting that Intune policies are platform-specific.

119
MCQeasy

Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?

A.The level of update notifications
B.How long to defer feature updates
C.Whether updates are installed automatically and if the user can control reboot timing
D.The branch readiness level
AnswerC

This setting governs the Windows Update for Business behaviour: it determines whether updates install automatically and whether the signed-in user may choose when to restart, satisfying the ring's need to balance patching with user control over reboot timing.

Why this answer

The 'automaticUpdateBehavior' setting in a Windows 10 update ring configuration JSON controls whether updates are downloaded and installed automatically, and whether the user can control reboot timing. When set to 'autoInstallAndRebootWithNoUserControl', updates install automatically and reboots occur without user interaction; when set to 'autoInstallAndRebootWithUserControl', the user can schedule or postpone reboots. This directly matches option C, as it governs both automatic installation and reboot control.

Exam trap

The trap here is that candidates confuse 'automaticUpdateBehavior' with deferral periods or notification levels, because all three settings appear in the same update ring configuration JSON, but each controls a distinct aspect of Windows Update behavior.

How to eliminate wrong answers

Option A is wrong because 'automaticUpdateBehavior' does not control the level of update notifications; notification behavior is managed by the 'updateNotificationLevel' setting in the update ring policy. Option B is wrong because deferring feature updates is controlled by the 'deferFeatureUpdatesPeriodInDays' setting, not by 'automaticUpdateBehavior'. Option D is wrong because branch readiness level is set via the 'branchReadinessLevel' property (e.g., 'CurrentBranch' or 'SemiAnnualChannel'), which is independent of the automatic update behavior.

120
Multi-Selecthard

Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)

Select 3 answers
A.Configure Autopilot for the device.
B.Create a device compliance policy to enforce kiosk mode.
C.Create a device configuration profile with the kiosk settings.
D.Assign the kiosk profile to a Microsoft Entra ID group containing the target devices.
E.Ensure the device is enrolled in Microsoft Intune.
AnswersC, D, E

Kiosk settings are configured via a configuration profile.

Why this answer

A device configuration profile in Microsoft Intune is the mechanism used to define the specific kiosk settings, such as the user account, app type (e.g., single-app or multi-app kiosk), and browser configuration. This profile applies the kiosk mode configuration to the device via the Windows 10/11 kiosk policy CSP (Policy Configuration Service Provider).

Exam trap

The trap here is that candidates confuse device compliance policies with device configuration profiles, mistakenly thinking compliance policies can enforce kiosk mode, when in fact compliance policies only evaluate and report on device health and security settings.

121
MCQhard

You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?

A.The device is running Windows 10 Home edition.
B.MDM enrollment is blocked by a local Group Policy or registry setting.
C.The device is not connected to the internet.
D.The device has an expired certificate required for enrollment.
AnswerB

Error 0x8018000b indicates the device is already enrolled or MDM enrolment is disabled locally. A Group Policy or registry setting blocking MDM enrolment prevents the Intune service from completing enrolment despite valid licensing and supported Windows edition.

Why this answer

Error 0x8018000b indicates that the device is not allowed to enroll, typically because MDM enrollment is blocked by a local Group Policy or registry setting. Even with a valid license and Windows 10 Pro, if the 'MDM Enrollment' policy is disabled or the 'Enrollment automatic' registry key is misconfigured, the enrollment attempt will fail with this specific error.

Exam trap

The trap here is that candidates often assume error 0x8018000b is a licensing or connectivity issue, but it specifically indicates that enrollment is administratively blocked, not that the device is unsupported or offline.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the device runs Windows 10 Pro, not Home edition, and error 0x8018000b is not related to edition restrictions (which would produce a different error). Option C is wrong because lack of internet connectivity would generate a different error (e.g., 0x8018000a or timeout), not 0x8018000b. Option D is wrong because an expired certificate would produce a certificate-related error (e.g., 0x80180014 or 0x8018000c), not the specific 'enrollment blocked' code 0x8018000b.

122
MCQmedium

You manage a fleet of Windows 11 devices with Microsoft Intune. Users report that the Windows Update ring assigned to them installs quality updates but never installs the required feature update to Windows 11 version 23H2. You confirm the devices are active, check-in is successful, and the ring is assigned to the correct Microsoft Entra group. You need to ensure the feature update installs automatically without user interaction. What should you configure?

A.Configure a Windows Update for Business delivery optimization policy to enable peer-to-peer content sharing.
B.Add the devices to a Microsoft Entra dynamic device group that filters on operatingSystemVersion and assign the update ring to that group.
C.Increase the feature update deferral period in the existing Windows Update ring to zero days.
D.Create a Feature updates for Windows 10 and later policy targeting Windows 11 version 23H2 and assign it to the device group.
AnswerD

A Feature updates for Windows 10 and later policy explicitly targets a specific Windows version and is the supported Intune workload for deploying feature updates. Windows Update rings only control deferrals and deadlines for updates already offered; they do not select a target feature update version. Assigning the feature update policy to the device group ensures devices receive and install the specified Windows 11 version automatically.

Why this answer

Feature updates require a dedicated Feature updates for Windows 10 and later policy in Intune that specifies the target Windows version and is assigned to the intended devices. Windows Update rings manage quality update behavior and deferrals but do not select which feature update version a device receives. Creating and assigning the feature update policy ensures devices automatically upgrade to Windows 11 version 23H2 without user action.

Exam trap

The trap here is assuming that a Windows Update ring alone will deliver a specific Windows feature update version, when in fact feature updates require a separate Feature updates policy.

123
MCQhard

You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?

A.Configure a 'Quality update deadline' of 2 days and a 'Feature update deadline' of 60 days.
B.Use a 'Quality update deferral period' of 48 hours and a 'Feature update deferral period' of 60 days in a Windows 10 update ring.
C.Set the 'Update notification level' to '2 - Disable all notifications' and configure active hours.
D.Configure a 'Quality update deferral period' of 2 days and a 'Feature update deferral period' of 60 days.
AnswerA

Quality update deadlines enforce automatic installation once the deferral window lapses, guaranteeing critical security patches land within 48 hours regardless of user action. Feature update deadlines separately cap the 60-day delay, letting you defer upgrades while ensuring they eventually install. Both deadlines satisfy the stem's distinct timing constraints for security versus feature updates.

Why this answer

Windows Update for Business uses 'deadline' policies to enforce when updates must be installed, not deferral periods. A 'Quality update deadline' of 2 days ensures critical security updates are installed within 48 hours, while a 'Feature update deadline' of 60 days allows feature updates to be delayed up to 60 days. Deferral periods only postpone when an update is offered, not when it must be installed, making deadlines the appropriate mechanism for enforcing installation timelines.

Exam trap

The trap here is that candidates confuse deferral periods with deadlines, assuming a deferral of 2 days achieves the same result as a 2-day deadline, but deferrals only delay the offer while deadlines enforce installation timing.

How to eliminate wrong answers

Option B is wrong because deferral periods delay the offer of updates but do not enforce an installation deadline; a 48-hour deferral would only delay when the quality update is first offered, not ensure it is installed within 48 hours. Option C is wrong because notification settings and active hours control user experience and restart timing, not the deployment timeline for security or feature updates. Option D is wrong because a deferral period of 2 days for quality updates only delays the offer by 2 days, failing to guarantee installation within 48 hours; deadlines are required to enforce the installation window.

124
MCQhard

You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks devices as noncompliant if they do not have a specific antivirus signature version installed. The signature version is updated daily. Which compliance setting should you configure?

A.Require the device to have an active firewall.
B.Require the device to be at or under the machine risk score.
C.Require the device to have a minimum OS version.
D.Require the device to have up-to-date security intelligence.
AnswerD

The 'Require the device to have up-to-date security intelligence' setting in a Windows compliance policy checks whether the Microsoft Defender antivirus security intelligence (signature) version is current. You can configure the maximum number of days allowed since the last update. This directly enforces that devices have recent signatures, aligning with the daily update requirement.

Why this answer

The compliance setting 'Require the device to have up-to-date security intelligence' allows you to specify how many days old the antivirus signatures can be. By setting this to one day, you ensure that devices with signatures older than one day are marked noncompliant. This is the only setting among the options that directly evaluates the security intelligence version, making it the correct choice.

Exam trap

The trap here is confusing machine risk score with signature version; machine risk score uses threat intelligence from Defender for Endpoint, not the age of antivirus definitions.

125
Multi-Selecthard

Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?

Select 3 answers
A.The use of co-management to gradually move workloads.
B.The ability to manage on-premises servers with Intune.
C.The compatibility of existing application packages with Intune formats (Win32, LOB).
D.The need for an on-premises Intune server.
E.Network bandwidth requirements for device communication with Intune.
AnswersA, C, E

Co-management lets you move workloads such as compliance policies and Windows Update rings incrementally, keeping Configuration Manager authoritative until each is proven. This staged authority transfer satisfies the migration factor of controlling risk while devices transition to Microsoft Intune.

Why this answer

Option A is correct because co-management lets you attach Configuration Manager-managed devices to Intune and progressively shift workloads such as compliance policies, resource access, and Windows Update policies from Configuration Manager to Intune, enabling a controlled, phased migration rather than a disruptive cutover. Option C is correct because existing Configuration Manager applications and packages must be repackaged or converted into Intune-supported formats such as Win32 apps (.intunewin), line-of-business (LOB) apps, or Microsoft Store apps, and this compatibility assessment is essential for planning remediation and testing effort. Option E is correct because Intune is a cloud service, so devices must reach Microsoft endpoints over the internet, making bandwidth, proxy, firewall, and content-download requirements (for example, Windows Update for Business and Win32 app content) a key planning factor.

Option B is not correct because Intune does not manage on-premises Windows Server workloads the way Configuration Manager does; servers generally remain with Configuration Manager or another on-premises tool. Option D is not correct because Intune is a fully cloud-hosted Microsoft service and requires no on-premises Intune server; only the Configuration Manager site infrastructure remains on-premises during co-management.

Exam trap

The trap here is that candidates often assume Intune can manage on-premises servers like Configuration Manager does, or that an on-premises Intune server exists, when in reality Intune is purely cloud-based and cannot replace Configuration Manager for server management.

126
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Several devices are failing to check in and receive policy. You review the device list and see the devices are enrolled but show a compliance state of 'Not evaluated'. You need to force the devices to immediately check in with the Intune service from the local device. What should you do?

A.Restart the Microsoft Intune Management Extension service.
B.Run the command: deviceenroller.exe /c /z /o
C.Run the command: dsregcmd /status
D.In Settings, navigate to Accounts > Access work or school, select the work account, and click Info > Sync.
AnswerD

This action triggers an immediate MDM check-in with Intune. The device contacts the service, retrieves any pending policies, and re-evaluates compliance. It is the supported manual method to force a sync from the device side, directly addressing the 'Not evaluated' state and ensuring the device receives current configurations and compliance rules without waiting for the scheduled interval.

Why this answer

Forcing a manual sync from the device is the quickest way to make an enrolled Windows device check in with Intune. Using the Settings app under Access work or school triggers the MDM enrollment client to contact the service immediately, refreshing policies and compliance status. This resolves the 'Not evaluated' state because the device re-evaluates its configuration against assigned compliance policies and reports back.

Exam trap

The trap here is confusing the Intune Management Extension service with the MDM check-in process; the extension only handles Win32 apps and scripts, not core policy or compliance sync.

127
MCQmedium

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

A.Devices are onboarded to Defender for Endpoint
B.Group Policy objects are linked to the domain
C.Security baselines are configured and assigned in Intune endpoint security
D.Devices are registered in Microsoft 365 Defender portal
AnswerC

Security baselines in Intune endpoint security define and assign the configuration settings whose compliance state devices report. Verifying they are configured and assigned ensures Windows devices actually evaluate and surface baseline compliance data to Intune.

Why this answer

Intune security baselines are the mechanism that defines and enforces security configuration policies on Windows devices. To report compliance with those baselines, the baselines must first be configured and assigned to the devices via Intune endpoint security. Without this assignment, devices have no baseline to compare against, and compliance reporting will not occur.

Exam trap

The trap here is that candidates often confuse onboarding to Defender for Endpoint (which enables security telemetry and threat detection) with the separate requirement of configuring and assigning Intune security baselines to enforce and report compliance.

How to eliminate wrong answers

Option A is wrong because onboarding devices to Defender for Endpoint ensures they can send telemetry and be managed for threat detection, but it does not by itself configure or report on security baseline compliance; that requires Intune security baseline policies. Option B is wrong because Group Policy objects are a traditional on-premises management tool that does not report compliance to Intune; Intune uses its own policy engine and MDM channel, not GPOs. Option D is wrong because registering devices in the Microsoft 365 Defender portal is part of the Defender for Endpoint onboarding process and does not create or assign security baseline policies; compliance reporting to Intune requires the Intune security baseline assignment.

128
MCQhard

You are the endpoint administrator for Contoso Ltd., a multinational company with 10,000 Windows 10 and 11 devices managed by Microsoft Intune. The company recently acquired a subsidiary that uses on-premises Active Directory and Configuration Manager. The subsidiary's devices are not joined to Microsoft Entra ID. Your goal is to migrate these devices to cloud management with Intune within six months. The subsidiary has 2,000 devices, all running Windows 10. The devices are currently domain-joined and managed by ConfigMgr. You need to choose the most efficient migration strategy that minimizes user disruption and leverages existing investments. The subsidiary has a high-speed WAN link to the corporate network. You have the following options: A) Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune. B) Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join. C) Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps. D) Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning. Which option should you choose?

A.Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune.
B.Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join.
C.Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps.
D.Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning.
AnswerB

Co-management lets existing domain-joined devices enrol in Intune while ConfigMgr retains authority, then workloads (compliance policies, Windows Update, endpoint protection) shift gradually to Intune. This satisfies the minimal-disruption constraint and leverages the existing ConfigMgr investment, before the final Entra ID join switch.

Why this answer

Co-management allows you to gradually transition Configuration Manager workloads to Intune without disrupting existing management, leveraging the existing ConfigMgr infrastructure and high-speed WAN link. This minimizes user disruption by keeping devices domain-joined initially, then switching to Entra ID join after workloads are migrated, which is the most efficient path for 2,000 existing domain-joined devices.

Exam trap

The trap here is that candidates often choose Autopilot or PPKG options because they seem 'modern,' but for existing domain-joined devices with ConfigMgr, co-management is the least disruptive and most efficient migration path, not a full wipe or provisioning package.

How to eliminate wrong answers

Option A is wrong because using a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune while keeping the ConfigMgr client creates a dual-management scenario without the benefit of co-management's workload transition capabilities, leading to conflicts and no gradual migration path. Option C is wrong because Windows Autopilot for existing devices requires uploading hardware hashes and resetting devices, which causes significant user disruption (data loss, re-provisioning) and does not leverage the existing ConfigMgr investment or the high-speed WAN link. Option D is wrong because using ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot is overly disruptive (full wipe, data loss) and inefficient compared to co-management, which allows a phased, non-destructive migration.

129
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?

A.Configure a device compliance policy to require corporate ownership.
B.Set enrollment restrictions to block personally owned devices.
C.Deploy an app protection policy to block personal devices.
D.Add corporate device identifiers (e.g., serial numbers) in Intune.
AnswerD

Corporate device identifiers, such as serial numbers or IMEIs, are uploaded to Intune and matched during enrolment, marking devices as corporate. This satisfies the requirement to distinguish corporate-owned Windows 10 devices so conditional access compliance policies can be scoped to them.

Why this answer

Corporate device identifiers, such as serial numbers or IMEI numbers, are the specific mechanism in Microsoft Intune used to mark a device as corporate-owned. While a conditional access policy requiring compliant devices ensures only compliant devices can access Microsoft 365, it does not distinguish between corporate and personal devices. By uploading corporate identifiers, Intune automatically sets the ownership type to 'Corporate' upon enrollment, which can then be used in conditional access policies to restrict access to only those devices.

Exam trap

The trap here is that candidates often confuse device compliance policies with ownership identification, not realizing that compliance policies evaluate security posture, not ownership, and that corporate identifiers are the dedicated Intune feature for marking devices as corporate-owned.

How to eliminate wrong answers

Option A is wrong because device compliance policies evaluate security settings (e.g., encryption, OS version) but do not include a setting to require corporate ownership; ownership type is a separate attribute managed via enrollment or device identifiers. Option B is wrong because enrollment restrictions block personally owned devices from enrolling at all, which is a pre-enrollment control, but the question asks what else must be done after configuring a conditional access policy to require compliant devices—enrollment restrictions would prevent personal devices from being enrolled, not identify corporate-owned devices among those already enrolled. Option C is wrong because app protection policies (MAM) manage data access within apps and can block personal devices from accessing corporate data, but they do not identify corporate-owned devices; they apply to both enrolled and unenrolled devices based on app-level controls, not device ownership.

130
MCQeasy

A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?

A.Disconnect the device from Microsoft Entra ID and rejoin.
B.On the device, go to Settings > Accounts > Access work or school, select the account, and click Sync.
C.Delete and recreate the compliance policy in Microsoft Intune.
D.Re-enroll the device in Microsoft Intune.
AnswerB

A 'Not evaluated' status typically means the device has not checked in with the Intune service. Manually triggering a sync from Settings > Accounts > Access work or school forces the MDM enrolment to contact Intune, prompting policy evaluation before investigating deeper causes.

Why this answer

When a Windows 11 device shows 'Not evaluated' in Intune, it usually means the MDM enrollment is intact but the device hasn't checked in with the Intune service recently. Manually triggering a sync from Settings > Accounts > Access work or school forces the MDM client to pull the latest compliance policies immediately, which is the least disruptive first step.

Exam trap

MD-102 often tests the instinct to jump to re-enrollment or policy recreation when the real fix is a simple device sync — candidates overlook the manual sync option under Access work or school.

How to eliminate wrong answers

Option A is wrong because disconnecting from Entra ID and rejoining is a drastic action that would break the existing enrollment and require re-registration, not a first troubleshooting step. Option C is wrong because recreating the compliance policy does nothing if the device simply hasn't synced — the policy itself is likely fine. Option D is wrong because re-enrolling the device is a last-resort action that wipes the MDM state and is unnecessary when a simple sync may resolve the issue.

131
MCQmedium

You manage 500 Windows 11 devices with Microsoft Intune. A security policy requires that all devices run Microsoft Defender Antivirus with real-time protection enabled. You configure a Windows 10 and later antivirus policy in Intune and assign it to all devices. Several devices report that real-time protection is disabled. You need to ensure that real-time protection cannot be disabled by local administrators. What should you do?

A.Enable tamper protection in the Microsoft Defender for Endpoint security baseline or via a configuration profile.
B.Deploy a PowerShell script that runs at startup to enable real-time protection.
C.Create a compliance policy that requires real-time protection to be enabled.
D.Configure the 'Allow real-time protection' setting to 'Enabled' in the antivirus policy.
AnswerA

Tamper protection prevents users, including local administrators, from disabling real-time protection and other Defender Antivirus features. In Intune, you can enable tamper protection through the Defender for Endpoint security baseline or a custom configuration profile. Once enabled, the setting cannot be turned off locally, ensuring real-time protection remains active.

Why this answer

Tamper protection is the only feature that prevents local administrators from disabling real-time protection and other Defender Antivirus settings. While other methods can enable the setting, they cannot lock it. Enabling tamper protection via the Defender for Endpoint baseline or a configuration profile ensures the setting remains enforced and cannot be overridden on the device.

Exam trap

The trap here is assuming that setting 'Allow real-time protection' to Enabled will prevent users from turning it off, when it only makes the feature available.

132
MCQeasy

A company uses Microsoft Intune to manage Windows devices. They need to deploy a required app to all devices in the marketing department. The app is a Microsoft Store app (new). What should you do first?

A.Deploy the app using a PowerShell script that installs it from the Microsoft Store.
B.Create a configuration profile that installs the app from the Microsoft Store.
C.Add the app from the Microsoft Store app (new) in Intune and assign it to the marketing department group as required.
D.Package the app as a Win32 app using the Microsoft Win32 Content Prep Tool and deploy it as required.
AnswerC

The Microsoft Store app (new) app type in Intune allows you to search and add apps directly from the Microsoft Store. You can then assign the app to a group with the required intent. This is the correct first step to deploy a Store app to a specific department.

Why this answer

To deploy a Microsoft Store app (new) to a group, you add the app in Intune by selecting the Microsoft Store app (new) type, search for the app, and then assign it to the target group with the required intent. This is the standard and supported method.

Exam trap

The trap here is overcomplicating the deployment by using Win32 packaging or scripts instead of the native Microsoft Store app (new) type.

133
MCQeasy

You need to ensure that devices enrolled in Microsoft Intune automatically receive Windows quality updates as soon as they are released. Which update ring setting should you configure?

A.Set 'Driver update deferral period (days)' to 0
B.Set 'Quality update deferral period (days)' to 0
C.Set 'Feature update deferral period (days)' to 0
D.Set 'Microsoft product updates' to 'Allow'
AnswerB

A quality update deferral of 0 days means devices receive quality updates immediately upon release, with no postponement. This directly satisfies the requirement for automatic, as-soon-as-released delivery through the Windows update ring in Microsoft Intune.

Why this answer

In Intune Windows update rings, the 'Quality update deferral period (days)' setting controls how long quality updates (security and reliability fixes) are deferred after release. Setting it to 0 means devices receive quality updates as soon as they are released, satisfying the requirement.

Exam trap

The trap is confusing quality updates with feature updates or driver updates — candidates often pick feature update deferral when the question asks about monthly security patches.

How to eliminate wrong answers

Option A is wrong because driver update deferral only affects driver updates, not Windows quality updates. Option C is wrong because feature update deferral controls Windows version upgrades (e.g., 21H2 to 22H2), not monthly quality updates. Option D is wrong because 'Microsoft product updates' allows updates for other Microsoft products (like Office), not Windows quality updates.

134
MCQeasy

You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

A.Managed Browser app.
B.iOS/iPadOS LOB app.
C.iOS/iPadOS store app.
D.Volume Purchase Program (VPP) app.
AnswerB

iOS/iPadOS LOB app deployment handles enterprise-signed packages (.ipa) directly, satisfying the requirement to distribute a signed line-of-business app to company-owned devices. Intune pushes it via the Company Portal without App Store involvement, and the enterprise certificate is trusted through a configuration profile. Store apps and web clips cannot deploy custom enterprise-signed binaries.

Why this answer

An iOS/iPadOS LOB app deployment in Intune is specifically designed for line-of-business apps that are signed with an enterprise certificate and distributed internally. This method allows you to upload the .ipa file directly to Intune and deploy it to company-owned devices without requiring the Apple App Store or a Volume Purchase Program.

Exam trap

The trap here is that candidates often confuse LOB app deployment with VPP apps, mistakenly thinking that any app not from the public store must use VPP, but VPP is only for App Store apps, while LOB apps are for enterprise-signed .ipa files uploaded directly to Intune.

How to eliminate wrong answers

Option A is wrong because the Managed Browser app is a specific Intune policy for deploying Microsoft Edge or a managed browser configuration, not a method for deploying custom LOB apps. Option C is wrong because an iOS/iPadOS store app deployment requires the app to be publicly available in the Apple App Store, which does not apply to a custom LOB app signed with an enterprise certificate. Option D is wrong because a Volume Purchase Program (VPP) app is used for purchasing and deploying App Store apps in bulk with managed licenses, not for sideloading enterprise-signed LOB apps.

135
MCQhard

You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?

A.Noncompliant because passwordRequired is true and no password set.
B.Noncompliant because storage encryption is not enabled.
C.Noncompliant because OS version is not within range.
D.Compliant
AnswerA

The compliance policy sets passwordRequired to true, so a device lacking any password fails that rule and is marked noncompliant. Intune evaluates each configured setting; a single unmet requirement is sufficient to make the overall status noncompliant, regardless of other settings passing.

Why this answer

The device is noncompliant due to the passwordRequired policy setting being set to true while no password is configured on the device. In Microsoft Intune, compliance policies evaluate each setting independently; if a required setting like passwordRequired is not met, the device is marked noncompliant regardless of other compliant settings. The OS version 10.0.19043.1234 is within a supported range, and storage encryption is not evaluated unless explicitly required by a policy, so only the missing password triggers noncompliance.

Exam trap

The trap here is that candidates assume a device is compliant if most settings are met, but Microsoft Intune evaluates each compliance policy setting independently, and a single failure—such as missing a password—results in overall noncompliance.

How to eliminate wrong answers

Option B is wrong because storage encryption is not a default compliance requirement for Windows 10 devices; it must be explicitly configured in a compliance policy, and the question states only password requirements are noncompliant. Option C is wrong because OS version 10.0.19043.1234 corresponds to Windows 10 21H1, which is within the supported range for Intune compliance policies, and no OS version range issue is indicated. Option D is wrong because the device fails the passwordRequired setting, which is a mandatory compliance check, so it cannot be marked compliant.

136
Multi-Selectmedium

You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)

Select 2 answers
A.Run a PowerShell script that imports the Intune module and calls Get-IntuneManagedDevice to list devices by enrollment date.
B.Create a dynamic device group that includes devices based on the deviceManagement.approvisioningState property.
C.In the Intune console, review the Devices > All devices list and sort or filter by the Last check-in column.
D.Use the Intune Data Warehouse or a Graph API query on managedDevices with the lastSyncDateTime property to identify stale devices.
E.Configure a compliance policy with the 'Unable to check in' rule set to 30 days and a noncompliance action of 'Mark device noncompliant'.
AnswersC, D

The All devices list exposes a Last check-in column that can be sorted or filtered, making it the fastest way to identify devices that have not contacted Intune recently. It directly answers the requirement to find stale devices. From this view, an administrator can select a device and initiate a remote action such as wipe or retire, so it also supports the follow-up step.

Why this answer

Identifying devices that have stopped checking in requires data on the last contact time. The Intune console's All devices view exposes a Last check-in column that can be sorted or filtered, and Microsoft Graph's managedDevices entity exposes lastSyncDateTime, which can be queried directly or through the Intune Data Warehouse. Provisioning state, enrollment date filtering, and compliance marking do not surface last check-in information, so they cannot reliably identify the stale devices.

Exam trap

The trap here is confusing enrollment or provisioning properties with last check-in data; only the Last check-in column and lastSyncDateTime reflect recent device contact.

137
MCQeasy

A company is implementing Windows Hello for Business and wants to use certificate-based authentication. They have an on-premises Active Directory and are using Azure AD Connect for hybrid identity. Which prerequisites must be met to support certificate-based Windows Hello for Business?

A.All users must have the Microsoft Authenticator app installed.
B.Conditional Access policies must be configured to require Windows Hello for Business.
C.An enterprise certification authority (CA) must be deployed and all devices must be Azure AD joined or hybrid Azure AD joined.
D.All users must be configured for passwordless sign-in.
AnswerC

Certificate-based Windows Hello for Business requires an enterprise CA to issue the authentication certificates, and devices must be Microsoft Entra joined or hybrid joined so they can enrol and obtain those certificates. Both conditions are prerequisites for the certificate trust deployment model.

Why this answer

Certificate-based Windows Hello for Business requires an enterprise PKI to issue and validate certificates for authentication. Devices must be Azure AD joined or hybrid Azure AD joined to enroll these certificates and support the certificate trust model. On-premises Active Directory and Azure AD Connect provide the hybrid identity foundation, but the CA and appropriate device join state are the critical prerequisites.

Exam trap

The trap here is that candidates often confuse the prerequisites for certificate-based Windows Hello for Business with those for passwordless sign-in or MFA, mistakenly thinking that the Authenticator app or Conditional Access policies are required, when in fact the core requirement is an enterprise CA and the correct device join state.

How to eliminate wrong answers

Option A is wrong because the Microsoft Authenticator app is used for phone-based MFA or passwordless phone sign-in, not for certificate-based Windows Hello for Business, which relies on a PKI and device certificates. Option B is wrong because Conditional Access policies are used to enforce sign-in risk or compliance requirements, not to establish the infrastructure prerequisites for certificate-based Windows Hello for Business; the CA and device join state must exist first. Option D is wrong because passwordless sign-in is a broader concept that can be achieved via FIDO2 security keys or phone sign-in, but certificate-based Windows Hello for Business specifically requires a CA and does not mandate that all users be configured for passwordless sign-in.

138
MCQeasy

You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?

A.Join each device to Entra ID manually and then enroll in Intune.
B.Create a provisioning package using Windows Configuration Designer and deploy via USB.
C.Register the devices in Windows Autopilot and deploy an Autopilot profile.
D.Use a Configuration Manager task sequence to deploy the OS.
AnswerC

Windows Autopilot registers devices with Microsoft Entra ID during out-of-box experience, so no manual join is needed. This satisfies the constraint that the 100 computers are not yet joined, letting Intune deliver the Windows 10 Enterprise image and profile automatically.

Why this answer

Windows Autopilot is the recommended method for deploying Windows 10 Enterprise to new devices that are not yet joined to Microsoft Entra ID because it automates the entire provisioning process—from joining Entra ID to enrolling in Intune—without requiring any manual intervention or imaging. By registering the devices in Autopilot and deploying an Autopilot profile, the out-of-box experience (OOBE) is customized to join Entra ID and enroll in Intune automatically, ensuring a zero-touch deployment that aligns with modern management best practices.

Exam trap

The trap here is that candidates often confuse provisioning packages (Option B) as the recommended method for cloud-only deployments, but Autopilot is specifically designed for zero-touch, cloud-native provisioning and is the correct answer for new devices not yet joined to Entra ID.

How to eliminate wrong answers

Option A is wrong because manually joining each device to Entra ID and then enrolling in Intune is not recommended for 100 new computers; it is labor-intensive, error-prone, and defeats the purpose of automated, scalable deployment. Option B is wrong because provisioning packages created with Windows Configuration Designer are typically used for bulk provisioning in on-premises or hybrid scenarios, but they do not leverage cloud-native Autopilot capabilities and require physical USB deployment, which is less efficient for remote or large-scale rollouts. Option D is wrong because using a Configuration Manager task sequence to deploy the OS is a traditional imaging approach that relies on on-premises infrastructure and does not integrate natively with cloud-based Entra ID join and Intune enrollment, making it unsuitable for a modern, cloud-first deployment strategy.

139
Multi-Selectmedium

Which TWO of the following are benefits of using Windows Autopilot for device provisioning?

Select 2 answers
A.Eliminates the requirement for a Microsoft Entra ID subscription.
B.Allows end users to set up their own devices with minimal IT involvement.
C.Enables device provisioning over a VPN connection.
D.Reduces the need for custom imaging and manual setup.
E.Supports deployment without any internet connectivity.
AnswersB, D

Autopilot's cloud-based provisioning lets the end user sign in with their work credentials and complete the out-of-box experience themselves, so IT never touches the device. This satisfies the stem's benefit of minimal IT involvement during provisioning.

Why this answer

Option B is correct because Windows Autopilot lets end users complete the out-of-box experience (OOBE) themselves, joining the device to Microsoft Entra ID and applying Intune policies with minimal IT interaction. Option D is correct because Autopilot uses the OEM-installed Windows image and cloud-based configuration, eliminating the need to build, maintain, and apply custom images or perform manual setup steps. Option A is incorrect because Autopilot depends on Microsoft Entra ID for device identity and user authentication, so an Entra ID subscription is still required.

Option C is incorrect because Autopilot provisioning requires direct internet access and does not support deployment over a VPN connection during OOBE. Option E is incorrect because Autopilot is a cloud-based service that requires internet connectivity throughout provisioning.

Exam trap

The trap here is that candidates often assume Autopilot can work over a VPN or without internet because it is a cloud-based service, but it requires direct internet access during OOBE before any VPN client is installed.

140
MCQmedium

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?

A.Devices must be registered in Autopilot using hardware hash
B.Devices must be domain-joined to on-premises AD
C.An Azure AD Premium P2 license must be assigned
D.Configuration Manager must be deployed for OS imaging
AnswerA

Autopilot requires each device's hardware hash uploaded to the Autopilot device store, creating the Autopilot device identity that binds hardware to a Microsoft Entra ID tenant. Without this registration, the device cannot receive an Autopilot profile during OOBE.

Why this answer

Windows Autopilot requires that each device be registered in the Autopilot service using its unique hardware hash (also known as a hardware ID). This hash is collected from the device's firmware and uploaded to the Autopilot deployment service, which then associates the device with the target tenant. Without this registration, Autopilot cannot identify the device during the out-of-box experience (OOBE) and cannot automatically enroll it into Microsoft Entra ID.

Exam trap

The trap here is that candidates often assume Autopilot requires an on-premises domain join (option B) because they confuse Autopilot with traditional imaging or hybrid Azure AD join scenarios, but Autopilot's core value is cloud-native, domain-join-free provisioning.

How to eliminate wrong answers

Option B is wrong because Autopilot devices do not need to be domain-joined to on-premises Active Directory; Autopilot is designed to directly join devices to Microsoft Entra ID (formerly Azure AD) during OOBE, bypassing any on-premises dependency. Option C is wrong because while Azure AD Premium P2 licenses provide additional features like Identity Protection and Privileged Identity Management, Autopilot itself only requires Azure AD Premium P1 (or Microsoft 365 E3/E5) for the Autopilot deployment profile and automatic enrollment; P2 is not a prerequisite. Option D is wrong because Configuration Manager is not required for Autopilot; Autopilot uses cloud-based provisioning via Microsoft Intune and does not rely on any on-premises imaging or OS deployment tool like Configuration Manager.

141
MCQeasy

An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?

A.Device enrollment restriction to require TPM 2.0
B.Device configuration profile to enable TPM 2.0
C.Device compliance policy with a condition for TPM 2.0, combined with a conditional access policy
D.App protection policy to require TPM 2.0
AnswerC

A device compliance policy evaluates the TPM 2.0 requirement as a device health attestation, marking non-compliant devices accordingly. Pairing it with a Microsoft Entra ID conditional access policy then enforces the grant control, blocking corporate email access from any device failing that check. This satisfies the stem's requirement that only TPM 2.0 devices reach email.

Why this answer

A device compliance policy can evaluate whether a device has TPM 2.0 (via the TPM specification version check), and when combined with a Conditional Access policy, it can block access to corporate email for non-compliant devices. This is the standard Microsoft approach for enforcing hardware-based security requirements for cloud app access.

Exam trap

The trap here is that candidates often confuse device compliance policies with enrollment restrictions, thinking that blocking enrollment is sufficient, but Conditional Access is required to enforce access control after enrollment.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll in Intune, but they do not enforce ongoing access control for corporate email after enrollment; they only block enrollment itself. Option B is wrong because a device configuration profile cannot enable TPM 2.0—TPM is a hardware component that is either present or not, and configuration profiles manage settings, not hardware capabilities. Option D is wrong because app protection policies (MAM) manage data protection within apps without requiring device-level compliance checks like TPM presence; they are designed for unmanaged or BYOD scenarios where device compliance is not evaluated.

142
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?

A.The device must have a Microsoft Entra ID Premium P2 license assigned.
B.The device must have its hardware hash uploaded to Microsoft Intune.
C.The device must be Azure AD registered before shipping.
D.The device must be joined to on-premises Active Directory first.
AnswerB

Windows Autopilot identifies a device by its unique hardware hash, which must be uploaded to Microsoft Intune to create an Autopilot device record. Without that hash registered, the device cannot be recognised and will not auto-enrol with organisational settings.

Why this answer

For a device to be recognized by Windows Autopilot, its hardware hash must be uploaded to Microsoft Intune. This hash uniquely identifies the device and allows Autopilot to associate it with your organization's Intune tenant. Without the hardware hash, the device cannot be targeted for Autopilot deployment.

Exam trap

MD-102 often tests the misconception that Azure AD join or Intune license is the minimum requirement. The key is the hardware hash upload; without it, Autopilot cannot identify the device.

How to eliminate wrong answers

Option A is wrong because an Entra ID Premium P2 license is not required for Autopilot; Intune licenses are sufficient. Option C is wrong because Azure AD registration is not a prerequisite for Autopilot; devices are typically Azure AD joined during Autopilot. Option D is wrong because on-premises Active Directory join is not required; Autopilot supports Azure AD join and hybrid Azure AD join, but the minimum requirement is the hardware hash upload.

143
MCQhard

You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Azure AD joined and enrolled in Intune. What should you configure?

A.Configure a conditional access policy that requires compliant devices.
B.Deploy a PowerShell script that triggers a factory reset when a specific file is created.
C.Enable Windows Defender Application Guard.
D.Ensure the device has an active internet connection and use the 'Wipe' action in Intune.
AnswerD

The Wipe action in Intune can be initiated remotely and will execute when the device next connects to the internet. For Azure AD joined devices, the wipe command is delivered via the Intune service. As long as the device has internet access, it will receive and execute the wipe, even if not on the corporate network.

Why this answer

Intune's Wipe action is designed for remote device wipe. When initiated, the command is queued and delivered to the device over the internet through the Intune service. The device must have an active internet connection to receive the command, but it does not need to be on the corporate network.

This makes it effective for compromised devices that are off-site.

Exam trap

The trap here is thinking that remote wipe requires the device to be on the corporate network or that other security features like WDAG or conditional access can perform a wipe, when in fact only the Wipe action does, and it works over the internet.

144
Drag & Dropmedium

Arrange the steps to troubleshoot a BitLocker recovery key prompt on a Windows 10 device.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for troubleshooting a BitLocker recovery key prompt is to first identify the cause (e.g., TPM change, PIN reset), then retrieve the recovery key from its stored location (e.g., Azure AD, Microsoft account), enter it to unlock the drive, and finally address the root cause to prevent recurrence. This sequence ensures a logical progression from diagnosis to resolution without unnecessary steps.

145
Multi-Selecteasy

Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)

Select 2 answers
A.Works offline without internet connectivity.
B.Enables deployment of custom operating system images.
C.Allows IT to provision devices remotely without physical access.
D.Reduces the need for manual imaging and configuration.
E.Eliminates the need for any user interaction during setup.
AnswersC, D

Windows Autopilot uses the cloud-based Autopilot deployment service to join devices to Microsoft Entra ID and apply configuration during out-of-box experience, so IT never touches the hardware. This directly satisfies the stem's remote provisioning requirement, eliminating imaging, shipping devices to technicians, or on-site setup.

Why this answer

Option C is correct because Windows Autopilot lets IT provision and configure devices remotely through the cloud (Microsoft Intune/Endpoint Manager), so administrators never need to touch the hardware or maintain a staging network. Option D is correct because Autopilot uses the OEM-installed Windows image and applies configuration via Intune profiles and the Enrollment Status Page, eliminating the traditional wipe-and-load imaging and manual configuration steps. Options A, B, and E are not benefits of Autopilot: it requires internet connectivity to reach Intune and Azure AD, it deliberately uses the existing OEM image rather than deploying custom images (that is what MDT/ConfigMgr imaging does), and although the Out-of-Box Experience is largely automated, the user still must sign in and may complete some steps, so it does not eliminate all user interaction.

Exam trap

The trap here is that candidates often assume Autopilot eliminates all user interaction (Option E) because of the term 'zero-touch,' but in user-driven mode the user must still sign in, while self-deploying mode (for kiosks or shared devices) can be truly zero-touch—the question does not specify the mode, so Option E is too absolute and incorrect.

146
MCQeasy

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and uses Microsoft Entra ID with Microsoft Intune. You must configure a Windows Autopilot deployment for existing Windows 11 devices that are already joined to the on-premises domain. The devices must remain domain-joined and also be registered in Microsoft Entra ID. You need to create the Autopilot deployment profile. Which deployment mode should you select?

A.Microsoft Entra registered
B.Microsoft Entra hybrid joined
C.Existing device, no Autopilot
D.Microsoft Entra joined
AnswerB

Microsoft Entra hybrid joined mode is designed for devices that must remain joined to on-premises AD DS while also being registered in Microsoft Entra ID. It requires the Intune Connector for Active Directory and a line-of-sight to a domain controller during OOBE. This matches the requirement to keep existing domain membership while enabling Intune management through Autopilot.

Why this answer

The requirement to keep devices joined to on-premises AD DS while also registering them in Microsoft Entra ID and managing them with Intune maps directly to the Microsoft Entra hybrid joined Autopilot mode. This mode uses the Intune Connector for Active Directory to create the computer object in AD DS during OOBE, ensuring the device is both domain-joined and Microsoft Entra registered.

Exam trap

The trap here is confusing Microsoft Entra hybrid joined with Microsoft Entra joined, assuming that any Autopilot deployment automatically includes on-premises domain membership.

147
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. The company has a policy that all Windows devices must have a minimum OS version of 10.0.19045. You need to create a compliance policy that enforces this requirement. Which type of compliance setting should you configure?

A.Custom Compliance
B.Device Health
C.System Security
D.Device Properties
AnswerD

Device Properties in a compliance policy includes settings such as Minimum OS version, Maximum OS version, and Mobile Device Management (MDM) compliance. By specifying the minimum OS version as 10.0.19045, you enforce that devices must run that version or later to be compliant. This directly satisfies the company's policy.

Why this answer

The minimum OS version is a built-in setting under Device Properties in Intune compliance policies. Configuring it there ensures devices are evaluated against the specified version. Other setting categories like Device Health, System Security, and Custom Compliance serve different purposes and do not provide a direct way to set a minimum OS version.

Exam trap

The trap here is confusing Device Health with Device Properties; Device Health monitors security features, not OS version.

148
MCQeasy

You are reviewing a custom device configuration profile in Intune. The exhibit shows an OMA-URI setting. What is the purpose of this setting?

A.Enables the camera on the lock screen
B.Disables the camera on the device entirely
C.Disables the microphone on the lock screen
D.Disables the camera on the lock screen
AnswerD

This OMA-URI policy configures the AllowCamera policy under the Personalisation CSP, setting it to block camera access specifically from the lock screen. It satisfies the requirement to restrict lock-screen camera use without disabling the camera entirely elsewhere on the device.

Why this answer

The OMA-URI setting ./Vendor/MSFT/Policy/Config/DeviceLock/PreventLockScreenCamera is used to disable the camera on the Windows lock screen. This policy prevents users from accessing the camera while the device is locked, enhancing security by mitigating privacy risks such as unauthorized camera use. It does not affect camera functionality once the user logs in.

Exam trap

The trap here is that candidates often confuse 'disable camera on lock screen' with 'disable camera entirely' (Option B), but the OMA-URI explicitly targets the lock screen only, not the full device camera functionality.

How to eliminate wrong answers

Option A is wrong because the setting specifically disables the camera on the lock screen, not enables it; enabling would require a different policy value or OMA-URI path. Option B is wrong because this policy only restricts camera access on the lock screen, not the entire device; to disable the camera entirely, you would use a different policy such as AllowCamera under Device/Experience. Option C is wrong because this OMA-URI targets the camera, not the microphone; disabling the microphone on the lock screen would involve a separate policy like PreventLockScreenMicrophone.

149
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that only devices running Windows 11 version 23H2 or later can enroll into Intune. You also want to block enrollment for older Windows versions. What should you configure?

A.A device compliance policy with a minimum OS version rule.
B.A configuration profile with a Windows edition upgrade policy.
C.A conditional access policy requiring compliant devices.
D.An enrollment restriction for Windows devices.
AnswerD

Enrollment restrictions in Intune allow you to control which devices can enroll. You can configure a platform restriction for Windows that specifies a minimum OS version. Devices that do not meet the minimum version will be blocked from enrolling. This is the correct way to prevent older Windows versions from enrolling.

Why this answer

To block enrollment based on OS version, you configure enrollment restrictions. Specifically, you create a Windows enrollment restriction and set a minimum OS version. Devices running versions below the minimum will be prevented from enrolling.

This is a direct control over enrollment eligibility, unlike compliance policies or conditional access which operate after enrollment.

Exam trap

The trap here is assuming that compliance policies or conditional access can block enrollment, but they only affect access after enrollment.

150
Multi-Selecthard

You manage devices with Microsoft Intune. You need to ensure that when a device is marked as non-compliant, users receive a notification and the device is blocked from accessing corporate email. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create a Conditional Access policy that requires compliant devices for Exchange Online.
B.Set up an enrollment restriction to block non-compliant devices.
C.Configure an app protection policy for Outlook mobile.
D.Deploy a device configuration profile that disables email access.
E.Configure a compliance policy with actions for non-compliance to send email notifications to users.
AnswersA, E

Conditional Access policies can enforce compliance by requiring devices to be marked compliant before accessing Exchange Online. When a device is non-compliant, access is blocked. This meets the requirement to block access to corporate email. Conditional Access works with Intune compliance status to allow or deny access based on device state.

Why this answer

To notify users and block email access for non-compliant devices, you need a compliance policy with actions for non-compliance to send notifications, and a Conditional Access policy that requires compliant devices for Exchange Online. The compliance policy detects non-compliance and triggers notifications, while Conditional Access enforces the block. Together, they meet both requirements.

Exam trap

The trap here is assuming that app protection policies or device configuration profiles can block email access based on compliance; only Conditional Access can enforce such dynamic access control.

Page 1

Page 2 of 8

Page 3

All pages