Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 151–225

556 questions total · 8pages · All types, answers revealed

Page 2

Page 3 of 8

Page 4
151
MCQmedium

A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?

A.Create an endpoint security disk encryption policy in Intune and assign it to the devices
B.Use Apple Configurator to create the profile and import it into Intune
C.Ask users to manually enable FileVault
D.Use JAMF Pro to manage FileVault
AnswerA

The endpoint security disk encryption policy is the built-in Intune workload for FileVault, applying the required encryption settings to macOS devices without a custom profile. This satisfies the scenario's need to enforce FileVault through a supported policy type.

Why this answer

Intune provides a built-in endpoint security disk encryption policy for macOS that enforces FileVault encryption. This is the recommended approach because it integrates natively with Intune, allows assignment to device groups, and reports compliance status without requiring third-party tools or manual user action.

Exam trap

MD-102 often tests the preference for native Intune policies over third-party tools or manual methods — candidates may overcomplicate by choosing Apple Configurator or JAMF Pro when Intune has a built-in solution.

How to eliminate wrong answers

Option B is wrong because while Apple Configurator can create custom profiles, importing them into Intune is not the recommended approach for FileVault when a native Intune policy exists; it adds unnecessary complexity. Option C is wrong because asking users to manually enable FileVault is not a managed, enforceable solution and defeats the purpose of MDM. Option D is wrong because JAMF Pro is a third-party tool; while it can manage FileVault, the question specifies Intune as the management tool, so using JAMF Pro is out of scope.

152
MCQeasy

You assign a required app to a device group. After the next sync, some devices report a 'Failed' status. What should you check first?

A.The device's last sync time
B.If a newer version is already installed
C.Whether the user is licensed
D.The device management log
AnswerD

The device management log, found in Intune under Devices > Monitor or on the device via Event Viewer, records app installation errors and failure codes. Checking it first satisfies the stem's need to diagnose why required app deployment reported 'Failed' status after sync.

Why this answer

The device management log (also known as the Intune management extension log or the MDM agent log on the device) provides detailed, real-time error codes and failure reasons for app installation attempts. When a required app shows 'Failed' status after sync, this log is the first place to check because it captures the exact cause—such as a download failure, dependency issue, or script execution error—that the Intune console cannot surface in summary views.

Exam trap

The trap here is that candidates assume 'Failed' status always points to a licensing or sync timing issue, when in fact the device management log is the definitive source for granular failure details that the Intune console summary cannot provide.

How to eliminate wrong answers

Option A is wrong because the last sync time only tells you when the device last communicated with Intune, not why a specific app installation failed; a recent sync does not guarantee successful app processing. Option B is wrong because checking for a newer version already installed is a troubleshooting step for 'Not Applicable' or 'Already Installed' statuses, not for 'Failed' status—the failure indicates the installation process itself encountered an error. Option C is wrong because licensing is validated at enrollment and sync time; if the user were unlicensed, the app would typically show as 'Not Applicable' or the device would not receive the policy at all, not a 'Failed' installation status.

153
MCQhard

You are an Intune administrator for a large enterprise that uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) for threat protection. You need to ensure that all Windows 10 devices are properly onboarded to Defender for Endpoint and that security settings are enforced via Intune. You have created a device configuration profile that includes the 'Microsoft Defender for Endpoint' settings, but some devices are not appearing in the Defender for Endpoint portal. You verify that the devices are Intune managed and enrolled. What should you do to ensure proper onboarding?

A.Ensure that the devices are co-managed with Configuration Manager.
B.Deploy the Microsoft Defender for Endpoint onboarding package (WindowsDefenderATPOnboardingPackage.zip) via Intune using a PowerShell script or a device configuration profile.
C.Create a compliance policy that requires Defender for Endpoint to be active.
D.Register the devices in Microsoft Entra ID (Azure AD) as hybrid joined.
AnswerB

The onboarding package must be deployed via Intune to onboard devices to Defender for Endpoint.

Why this answer

Onboarding to Defender for Endpoint requires a specific deployment package (a .zip file containing the onboarding script) that must be deployed via Intune using a PowerShell script or a device configuration profile with the 'Microsoft Defender for Endpoint' template. However, the most common missing step is deploying the onboarding package. Option A is incorrect because co-management with Configuration Manager is not required for Defender for Endpoint onboarding; devices can be managed solely by Intune.

Option C is incorrect because while a compliance policy can verify that Defender for Endpoint is active, it does not deploy the onboarding package required for initial onboarding. Option D is incorrect because Microsoft Entra ID registration is not the issue.

154
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. Users report that some required applications are not being installed on their devices. You confirm the applications are assigned as 'Required' to a device group, and the devices are online. What is the most likely cause?

A.BitLocker encryption is pending
B.The user is not logged in to the device
C.The enrollment status page is blocking installation
D.The Intune Management Extension is missing
AnswerD

Win32 and PowerShell script applications assigned as Required are delivered by the Intune Management Extension agent on Windows 10 devices. Without that agent installed and running, the device never receives the installation instruction, explaining why required apps fail to install despite online devices and correct assignments.

Why this answer

The Intune Management Extension is required to process Win32 app installations. If the extension is missing or not running, required apps will not install even though the device is online and assignment is configured. Option A is wrong because BitLocker encryption status does not affect app installation.

Option B is wrong because device-targeted assignments do not require the user to be logged in. Option C is wrong because the enrollment status page does not block required app installations after enrollment is complete.

155
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. The finance team needs a specific third-party accounting application deployed to their Windows 11 laptops. The vendor provides an .msi installer and a setup.exe bootstrapper. You want the deployment to be tracked by Intune and to automatically retry if the install fails. What should you do?

A.Add the application as a Microsoft Store app (new) and assign it to the finance team.
B.Add the application as a line-of-business app and upload the .msi file directly.
C.Add the application as a Win32 app, upload the installer, and configure the install and uninstall commands.
D.Create a PowerShell script and deploy it as a platform script to the finance team devices.
AnswerC

Win32 app is the Intune app type designed for custom .msi, .exe, and .intunewin packages. It supports required assignments, success and failure return codes, detection rules, and automatic retries when installation fails, all of which match the stated requirements. Uploading the vendor installer and defining the commands gives Intune the information it needs to deploy and track the app accurately.

Why this answer

Win32 app is the correct type for deploying a vendor-supplied .msi or setup.exe with tracking and retry behavior. It provides install and uninstall commands, return code handling, detection rules, and reporting that the other app types cannot match. The result is a managed deployment with automatic retry on failure, exactly as required.

Exam trap

The trap here is choosing the line-of-business app type simply because it accepts an .msi, overlooking that Win32 app is required for robust tracking and retry behavior.

156
MCQhard

You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?

A.Endpoint Protection
B.Windows Update policies
C.Resource access
D.Client apps
AnswerD

Correct. Client apps workload includes the policy to automatically enroll devices to Intune when the Configuration Manager client is installed.

Why this answer

The 'Client apps' workload in Configuration Manager co-management is responsible for synchronizing client applications and enabling automatic enrollment of devices to Intune after the Configuration Manager client is installed. Option A (Endpoint Protection) is incorrect because it manages endpoint protection policies, not enrollment. Option B (Windows Update policies) is incorrect because it governs Windows Update for Business policies, not Intune enrollment.

Option C (Resource access) is incorrect because it configures resource access policies like certificates and VPN, not automatic enrollment.

157
MCQhard

You are planning to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote users who do not have a VPN connection during initial setup. The devices must be Microsoft Entra joined and enrolled in Intune. You need to ensure that the deployment works without requiring a domain controller. Which Autopilot mode should you configure?

A.Microsoft Entra joined
B.Self-deploying mode
C.Pre-provisioning (white glove)
D.Microsoft Entra hybrid joined
AnswerA

Microsoft Entra joined mode does not require on-premises domain connectivity. Devices join Microsoft Entra ID directly and enroll in Intune, making it ideal for remote users without VPN. This mode supports cloud-based management and access to cloud resources without a domain controller.

Why this answer

Microsoft Entra joined mode is the correct choice because it does not require connectivity to an on-premises domain controller. Devices join Microsoft Entra ID and enroll in Intune directly, enabling remote users to complete setup without VPN. This mode is designed for cloud-first management and supports access to cloud resources.

Exam trap

The trap here is selecting pre-provisioning as a solution, but it is a deployment method, not a join mode, and does not eliminate the need for domain controller connectivity in hybrid scenarios.

158
MCQeasy

You need to enroll a Windows 11 device into Microsoft Intune using a work or school account. The device is already joined to Microsoft Entra ID. What is the simplest enrollment method?

A.Windows Autopilot
B.Group Policy to configure enrollment
C.Manual enrollment using the Company Portal
D.Automatic enrollment via Microsoft Entra join
AnswerD

Microsoft Entra join with automatic MDM enrolment configured in Intune silently enrols the device using the signed-in work or school account, requiring no user action. This is the simplest method for the already-joined Windows 11 device in the stem.

Why this answer

When a Windows 11 device is already Microsoft Entra joined, the simplest enrollment path is automatic MDM enrollment via the Entra join process. During the Entra join, if the user's license includes Intune and the MDM user scope is configured in the Entra ID Mobility settings, the device is automatically enrolled into Intune without any additional user action. This is the least-effort method because it requires no additional configuration on the device itself.

Exam trap

MD-102 often tests the distinction between Autopilot (provisioning new devices) and automatic enrollment (enrolling existing Entra-joined devices), causing candidates to pick Autopilot for any enrollment scenario.

How to eliminate wrong answers

Option A is wrong because Windows Autopilot is used for provisioning new or reset devices out-of-box, not for enrolling an already Entra-joined device. Option B is wrong because Group Policy-based enrollment is a legacy method for hybrid Azure AD joined devices and requires on-premises AD infrastructure, not the simplest path for a cloud-joined device. Option C is wrong because manual enrollment via Company Portal requires the user to install the app and sign in, which is more steps than automatic enrollment.

159
MCQhard

You review the compliance policy JSON for Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.0) with a numeric-only password of 10 characters, BitLocker enabled, firewall enabled, and Microsoft Defender running reports as non-compliant. What is the most likely reason?

A.The password type is not alphanumeric.
B.The OS version is outside the allowed range.
C.Storage encryption is not enabled.
D.Microsoft Defender is not enabled.
AnswerA

A numeric-only password fails the alphanumeric password requirement, so the device reports non-compliant despite meeting the other conditions. Compliance policies in Microsoft Entra ID evaluate password complexity independently of length, meaning a 10-character PIN-style password satisfies length but not the required character-type constraint.

Why this answer

The compliance policy JSON for Windows 10 devices specifies a password type requirement of 'alphanumeric'. The device in question uses a numeric-only password (10 characters), which does not meet the alphanumeric requirement, causing it to be reported as non-compliant. All other conditions—BitLocker enabled, firewall enabled, and Microsoft Defender running—are satisfied, so the password type is the sole issue.

Exam trap

The trap here is that candidates often assume a long numeric password (10 characters) meets complexity requirements, but the policy explicitly requires alphanumeric characters, and the exam tests attention to the specific JSON setting rather than general password strength.

How to eliminate wrong answers

Option B is wrong because the OS version (Windows 10 version 22H2, build 22621.0) is within the allowed range; the compliance policy typically specifies a minimum OS version, and 22H2 is a supported build. Option C is wrong because storage encryption is enabled via BitLocker, which satisfies the encryption requirement. Option D is wrong because Microsoft Defender is explicitly stated as running, so it is enabled and compliant.

160
MCQmedium

You manage a fleet of Windows 11 devices with Microsoft Intune. The security team requires that any device that has not checked in with Intune for more than 30 days is automatically retired so its resources are released and its compliance state is removed. You need to configure this behavior with the least administrative effort. What should you do?

A.Configure an Autopilot deployment profile with a 30-day enrollment timeout and enable automatic device deletion.
B.Create a dynamic device group based on the last check-in date and apply a retire action using a scheduled PowerShell script.
C.Create a device cleanup rule in the Intune tenant settings and set the inactivity threshold to 30 days.
D.Assign a compliance policy that marks devices as noncompliant after 30 days of inactivity, and configure conditional access to block them.
AnswerC

Intune includes a built-in device cleanup rule under Tenant administration > Device cleanup rules. Setting the inactivity threshold to 30 days causes Intune to automatically retire devices that have not checked in for that period, which releases licenses and marks the device noncompliant, matching the requirement with minimal effort.

Why this answer

Intune's built-in device cleanup rule is designed exactly for this scenario: it automatically retires devices that have not checked in for a configured number of days. Setting the threshold to 30 days satisfies the security team's requirement without custom scripting, dynamic groups, or conditional access workarounds. It is the native, lowest-effort lifecycle management feature.

Exam trap

The trap here is assuming that compliance policies or conditional access can retire devices, when only the dedicated device cleanup rule performs the retire action automatically.

161
MCQeasy

You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?

A.Enrollment restrictions
B.Device categories
C.Device compliance policies
D.Conditional access policies
AnswerA

Enrollment restrictions control which users may enrol devices and which platforms or device types they can register, directly satisfying the requirement that only authorised users enrol in Microsoft Intune. Configuring a device-type or platform restriction, plus assigning it to a group, blocks unauthorised accounts at enrolment rather than relying on post-enrolment compliance.

Why this answer

Enrollment restrictions in Microsoft Intune let administrators control which users and devices are permitted to enroll, including platform, OS version, device type, and user/group targeting. By scoping enrollment to authorized groups or blocking personal devices, only approved users can complete MDM enrollment. This is the native control designed specifically to gate Intune enrollment.

Exam trap

MD-102 often tests the distinction between controls that gate enrollment (enrollment restrictions) versus controls that evaluate enrolled devices (compliance policies) or gate resource access (conditional access), so candidates pick a policy that sounds security-related but does not actually block enrollment.

How to eliminate wrong answers

Option B is wrong because device categories are metadata tags assigned to enrolled devices for reporting and policy targeting, not an enrollment gate. Option C is wrong because compliance policies evaluate already-enrolled devices against security baselines and mark them compliant/non-compliant; they do not prevent enrollment. Option D is wrong because conditional access policies control access to cloud resources based on device state, not whether a device can enroll in Intune.

162
MCQhard

You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?

A.The Conditional Access policy is set to 'Block' instead of 'Grant'.
B.The Conditional Access policy applies only to users in a specific group.
C.The compliance policy is not assigned to the users' devices.
D.The Conditional Access policy does not include the email application as a target.
AnswerD

Conditional Access grants apply only to the cloud apps explicitly targeted, so omitting Exchange Online leaves email unprotected regardless of compliance state. The policy's grant control therefore never evaluates sessions to that resource, satisfying the stem's requirement that non-compliant devices be blocked from corporate email.

Why this answer

A Conditional Access policy must include at least one cloud app as a target. If the corporate email application (e.g., Exchange Online) is not included in the policy, the policy will not apply to access attempts for that app, allowing non-compliant devices to connect. Option A is incorrect because a 'Block' policy would block access, not allow it.

Option B is incorrect because the policy's user scope does not affect whether the app is targeted. Option C is incorrect because while compliance policy assignment is important, the most direct reason is the missing app target.

163
MCQmedium

You are deploying a Windows 11 device using Windows Autopilot. The device fails to enroll in Intune and you see the error 'The device is not registered in Autopilot'. You have verified that the device hardware hash is uploaded. What is the most likely cause?

A.The device is not running a supported version of Windows 11.
B.The device is not connected to the internet during OOBE.
C.The device hardware hash is associated with a different tenant.
D.The Autopilot deployment profile is not assigned to the device.
AnswerC

If the hardware hash was uploaded to a different Microsoft Entra tenant, the device will not be recognized in your tenant's Autopilot service, resulting in the 'not registered' error. This can happen if the device was previously registered elsewhere or if the hash was uploaded incorrectly. Ensuring the hash is in the correct tenant resolves the issue.

Why this answer

The error 'The device is not registered in Autopilot' indicates that the device's hardware hash is not present in the Autopilot service for your tenant. A common cause is that the hash was uploaded to a different Microsoft Entra tenant, perhaps by the OEM or a previous owner. Verifying and re-uploading the hash to the correct tenant resolves the issue.

Other causes like internet connectivity or profile assignment do not produce this specific error.

Exam trap

The trap here is assuming that profile assignment or internet connectivity causes the 'not registered' error, when it specifically means the hardware hash is missing from the tenant.

164
MCQmedium

Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?

A.Get-MgDeviceManagementManagedDeviceCompliancePolicyState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
B.Get-MgDeviceManagementDeviceCompliancePolicySettingStateSummary -DeviceCompliancePolicyId <id>
C.Get-MgDeviceManagementManagedDeviceConfigurationState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
D.Get-MgDeviceManagementDeviceConfigurationState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
AnswerA

Get-MgDeviceManagementManagedDeviceCompliancePolicyState returns the per-policy compliance state for a specific managed device, including the setting-level failure reasons behind Laptop-02's non-compliant status. Passing the device's ManagedDeviceId satisfies the requirement to retrieve granular non-compliance detail, which the summary output alone does not expose.

Why this answer

Get-MgDeviceManagementManagedDeviceCompliancePolicyState returns the per-policy compliance state for a specific managed device, including the non-compliance reason strings for each assigned compliance policy. This is the correct cmdlet to drill into why a device is non-compliant after identifying it via a device listing. It maps directly to the Intune 'Device compliance' per-policy view in the portal.

Exam trap

MD-102 often tests the confusion between 'CompliancePolicyState' (compliance rules like BitLocker, firewall) and 'ConfigurationState' (settings profiles like Wi-Fi, VPN) — candidates pick the configuration cmdlet because both sound like 'device state'.

How to eliminate wrong answers

Option B is wrong because Get-MgDeviceManagementDeviceCompliancePolicySettingStateSummary returns aggregate setting-level state counts across all devices for a policy — it is a summary, not per-device detail. Option C is wrong because Get-MgDeviceManagementManagedDeviceConfigurationState returns configuration profile (device configuration) states, not compliance policy states — configuration profiles and compliance policies are separate workloads in Intune. Option D is wrong because Get-MgDeviceManagementDeviceConfigurationState is not the correct cmdlet for per-device configuration state; the managed-device-scoped variant is required, and even then it addresses configuration, not compliance.

165
MCQmedium

You have a hybrid Microsoft Entra ID joined Windows 10 device that is co-managed with Configuration Manager and Intune. You want Intune to manage Windows Update for Business settings. Which slider setting should you configure in Configuration Manager?

A.Move the slider for 'Windows Update policies' to 'Intune'
B.Move the slider for 'Endpoint protection' to 'Intune'
C.Move the slider for 'Resource access' to 'Intune'
D.Move the slider for 'Device configuration' to 'Intune'
AnswerA

Shifting the Windows Update policies workload slider to Intune transfers authority for Windows Update for Business settings to Microsoft Entra ID-based MDM, satisfying the requirement that Intune manage them. Configuration Manager retains the remaining co-management workloads, so update policy delivery no longer depends on the Configuration Manager client.

Why this answer

In a co-management scenario, workload sliders in Configuration Manager determine which authority manages specific workloads. To have Intune manage Windows Update for Business settings, you must move the slider for 'Windows Update policies' to Intune. This shifts the policy authority from Configuration Manager to Intune, allowing Intune's Update Rings and feature update policies to control Windows Update behavior on the device.

Exam trap

The trap here is that candidates often confuse 'Windows Update policies' with 'Device configuration' or 'Endpoint protection', assuming that update settings fall under a broader configuration or security category, but Microsoft specifically separates update management into its own workload slider.

How to eliminate wrong answers

Option B is wrong because 'Endpoint protection' controls antivirus, firewall, and Defender policies, not Windows Update settings. Option C is wrong because 'Resource access' manages VPN, Wi-Fi, email, and certificate profiles, which are unrelated to update policies. Option D is wrong because 'Device configuration' handles device restriction and configuration profiles, not Windows Update for Business policies.

166
MCQhard

You are the endpoint administrator for Contoso, a company with 10,000 Windows 11 devices managed by Microsoft Intune. The devices are a mix of corporate-owned and bring-your-own-device (BYOD). You need to implement a solution that allows users to access corporate resources only if their devices meet specific security requirements: disk encryption (BitLocker), antivirus (Microsoft Defender), and a minimum OS build. Additionally, you must ensure that users cannot access corporate email from devices that are jailbroken or rooted. The solution should automatically block non-compliant devices from accessing resources and provide a notification to the user explaining the issue. You have already configured compliance policies in Intune. What should you do next to enforce the block?

A.Configure a device enrollment restriction to block non-compliant devices from Azure AD join.
B.Create a device configuration policy that blocks access to corporate resources.
C.Create an app protection policy in Intune to block access to apps.
D.Create a Conditional Access policy in Microsoft Entra ID that requires compliant device for access.
AnswerD

A Conditional Access policy in Microsoft Entra ID evaluates device compliance state at authentication and blocks access when the device fails Intune compliance policies, covering BitLocker, Defender, OS build, and jailbroken or rooted detection. This enforces the block automatically and surfaces the non-compliance reason to users.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) enforce compliance by requiring devices to be marked compliant before granting access to corporate resources. Since compliance policies are already configured in Intune, creating a Conditional Access policy that requires a compliant device will block non-compliant devices and provide user notifications.

Exam trap

The trap is confusing device configuration policies with Conditional Access; candidates must remember that Conditional Access is the enforcement mechanism for compliance, not configuration policies.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll, not access to resources for already enrolled devices. Option B is wrong because device configuration policies configure settings on devices but do not block access. Option C is wrong because app protection policies protect app data but do not enforce device compliance for access to all corporate resources.

167
MCQmedium

You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?

A.Deploy a device configuration profile with the 'Allow copy and paste' setting set to 'Blocked'.
B.Create an app protection policy with the 'Restrict cut, copy, and paste between other apps' setting set to 'Blocked'.
C.Set the 'Require managed pasteboard' option in the app configuration policy for Outlook.
D.Configure a conditional access policy that requires compliant devices.
AnswerB

App protection policies (also known as MAM policies) can restrict data transfer between managed and unmanaged apps. Setting 'Restrict cut, copy, and paste between other apps' to 'Blocked' prevents copying from a managed app to any unmanaged app, including personal apps like Gmail. This is enforced without user interaction and meets the requirement.

Why this answer

App protection policies in Intune provide granular control over data sharing between apps. The setting to restrict cut, copy, and paste between other apps, when set to Blocked, prevents data from being copied from a managed app to any unmanaged app. This is enforced at the app level and does not require user action.

Exam trap

The trap here is assuming that device configuration profiles can control inter-app data sharing, but that capability is exclusive to app protection policies.

168
MCQmedium

A user's Android device is not receiving email from the corporate Microsoft 365 tenant. The device is enrolled in Intune and shows as compliant. The email profile is assigned to the user. What should you check first?

A.Verify that the device meets the compliance policy for Android.
B.Confirm that the user has an Exchange Online license.
C.Check the device's last check-in time with Intune.
D.Ensure the device is enrolled in Intune.
AnswerC

A stale Intune check-in means the device never collected the assigned email profile, so no mailbox connection is configured despite the compliance state. Verifying the last check-in time confirms whether policy and profile delivery actually reached the Android device, which is the prerequisite for email synchronisation in this scenario.

Why this answer

The device is already compliant and enrolled, and the email profile is assigned, so the most likely issue is that the device has not recently checked in with Intune to receive the latest policy or profile. Checking the last check-in time is the first troubleshooting step because Intune relies on periodic device check-ins to push configuration profiles, including email profiles. If the device hasn't checked in recently, it won't have the email profile applied, even if it's compliant and enrolled.

Exam trap

The trap here is that candidates assume compliance or enrollment guarantees policy delivery, but Intune requires a successful device check-in to actually apply profiles, making the last check-in time the critical first check.

How to eliminate wrong answers

Option A is wrong because the device already shows as compliant, so verifying compliance again would be redundant and not address why the email profile hasn't been applied. Option B is wrong because the user's ability to receive email from the corporate tenant is not dependent on an Exchange Online license; the email profile configuration and Intune policy delivery are the immediate technical blockers. Option D is wrong because the device is already enrolled in Intune (as stated in the scenario), so re-checking enrollment is unnecessary and does not explain why the email profile hasn't been delivered.

169
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that has a complex installation requiring multiple command-line parameters. The app must be available to users in the Company Portal. What is the best way to handle the installation parameters?

A.Deploy a PowerShell script via Intune that runs the installer with parameters.
B.Configure detection rules to run a script that passes parameters.
C.Use the Intune Win32 app packaging to specify the installation command with parameters.
D.Use an administrative template to set parameters before installing.
AnswerC

Win32 app packaging in Intune lets you define the install command line, including multiple parameters, within the app configuration. This satisfies the stem's constraint of a complex installation requiring parameters while remaining available to users in the Company Portal.

Why this answer

Intune's Win32 app packaging allows you to specify the full installation command, including complex parameters, directly in the 'Install command' field. This method ensures the installer runs with the exact parameters needed, and the app is then published to the Company Portal for user self-service. PowerShell scripts or detection rules do not handle the installation parameters themselves, and administrative templates are for configuring settings, not installation commands.

Exam trap

The trap here is that candidates may think a PowerShell script is needed for complex parameters, but Intune's Win32 app packaging directly supports any command-line string, making the script unnecessary and less efficient.

How to eliminate wrong answers

Option A is wrong because deploying a PowerShell script via Intune that runs the installer with parameters is an indirect workaround; Intune's Win32 app packaging natively supports specifying the installation command with parameters, making a separate script unnecessary and less reliable for detection and reporting. Option B is wrong because detection rules are used to verify if an app is already installed, not to pass installation parameters; they run after the installation command, not during it. Option D is wrong because administrative templates (ADMX-backed policies) are used to configure registry-based settings or policies, not to specify installation command-line parameters for a Win32 app.

170
MCQhard

You manage a set of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that requires a specific registry key to exist before installation. The app installer does not check for this key. You must ensure the app installs only on devices that have the registry key. What should you do?

A.Use a PowerShell script in the app package to create the registry key before installation.
B.Deploy the app as available and instruct users to verify the registry key before installing.
C.Add a requirement rule to the Win32 app that checks for the registry key.
D.Create a detection rule that checks for the registry key.
AnswerC

Requirement rules in Intune allow you to specify conditions that must be met for the app to install. You can create a rule that checks for the existence of a registry key, file, or value. This ensures the app is only offered to devices that meet the condition, without modifying the installer.

Why this answer

Requirement rules in Intune are evaluated before app installation. By adding a rule that checks for the presence of a specific registry key, you ensure the app is only installed on devices that already have that key. This enforces the prerequisite automatically and reliably.

Exam trap

The trap here is confusing detection rules with requirement rules; detection rules only check if an app is installed, while requirement rules control whether installation should proceed.

171
Drag & Dropmedium

Order the steps to configure a Windows 10 device for Microsoft 365 Apps deployment via Intune.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Begin in Intune admin center, add a new app, choose Microsoft 365 Apps, configure suite, and assign.

172
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps to all devices. The IT team wants to minimize administrative effort and ensure the apps are always up to date. What should they use?

A.PowerShell script that downloads and installs Office
B.Win32 app using the Office Deployment Tool
C.Microsoft 365 Apps (Windows 10 and later) app type in Intune
D.Microsoft Store app (new) for each Office app
AnswerC

Intune provides a built-in app type specifically for Microsoft 365 Apps. This app type allows you to select the Office apps to install, choose update channels, and configure other settings. It automatically handles updates and requires minimal administrative effort. It is the recommended method for deploying and managing Microsoft 365 Apps on Windows devices, ensuring they stay current with the selected update channel.

Why this answer

The Microsoft 365 Apps app type in Intune is purpose-built for deploying and managing Office. It allows you to select apps, configure update channels, and automatically keep the apps up to date. This reduces administrative effort and ensures devices receive updates according to the chosen channel, making it the ideal solution for deploying Microsoft 365 Apps at scale.

Exam trap

The trap here is thinking that a Win32 app with the Office Deployment Tool is required, when Intune offers a dedicated app type that simplifies deployment and updates.

173
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, all corporate data is removed but the user's personal files remain intact. The devices are enrolled as personal devices with work profiles. What should you do?

A.Use the 'Wipe' action in Intune.
B.Use the 'Retire' action in Intune.
C.Remove the device from the Azure AD group.
D.Perform a factory reset on the device.
AnswerB

The Retire action removes corporate data, management profiles, and policies from the device while leaving personal files and settings intact. For personal devices with work profiles, retiring the device removes the work profile and associated corporate data, which meets the requirement without affecting personal content.

Why this answer

For personal devices enrolled with work profiles, the Retire action is designed to remove only corporate data and management profiles, leaving personal files untouched. This is the correct way to deprovision a personal device without affecting the user's personal data. A factory reset or Wipe would delete everything, which is not desired.

Exam trap

The trap here is confusing the Wipe and Retire actions, or thinking that removing group membership removes data, when in fact Retire is specifically for removing corporate data while preserving personal files.

174
MCQhard

You are configuring a Windows Autopilot deployment for devices that must be hybrid Microsoft Entra joined. The environment includes an on-premises Active Directory domain and Microsoft Entra Connect. You need to ensure the devices can complete the hybrid join during OOBE. Which configuration is required?

A.Configure the Autopilot deployment profile to use Microsoft Entra hybrid join and ensure the device can reach a domain controller and the Intune service during OOBE.
B.Deploy a VPN configuration profile that connects the device to the corporate network before the Autopilot profile is applied.
C.Configure the Autopilot deployment profile to use Microsoft Entra join and rely on Microsoft Entra Connect to convert the device to hybrid join after enrollment.
D.Enable Windows Hello for Business in the Autopilot deployment profile to trigger the hybrid join during OOBE.
AnswerA

For hybrid join Autopilot, the deployment profile must specify Microsoft Entra hybrid join, and the device needs line-of-sight to a domain controller to perform the domain join, plus internet access to reach Intune and Microsoft Entra ID. Both conditions are essential for the OOBE flow to complete successfully.

Why this answer

Hybrid Microsoft Entra join in Autopilot requires the deployment profile to specify that join type and requires network conditions that allow the device to contact a domain controller for the domain join and reach the cloud services for the Microsoft Entra join and Intune enrollment. Missing either condition prevents successful completion.

Exam trap

The trap here is assuming that Microsoft Entra Connect or Windows Hello for Business can produce a hybrid join, when the join type must be selected in the Autopilot profile and domain controller connectivity is mandatory.

175
MCQmedium

You are the Intune administrator for a company that uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that when devices enroll, they automatically receive a set of configuration settings, including a custom Start menu layout and specific Wi-Fi profiles. What should you create and assign?

A.An app configuration policy
B.A compliance policy
C.A PowerShell script deployed via Intune
D.A device configuration profile
AnswerD

Device configuration profiles in Intune allow you to configure settings on devices, such as Start menu layout and Wi-Fi profiles. You can create a profile with the desired settings and assign it to groups of users or devices. Upon enrollment, devices receive and apply these configurations automatically.

Why this answer

Device configuration profiles are the correct choice for deploying settings like Start menu layout and Wi-Fi profiles to devices. They are declarative and ensure that settings are applied consistently. When assigned to groups, devices receive these configurations upon enrollment and check-in, meeting the requirement to automatically provision devices with specific settings.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance evaluates, while configuration enforces settings.

176
MCQeasy

You are deploying Microsoft Defender for Endpoint to 200 Windows 10 devices managed by Microsoft Intune. You want to onboard the devices to Defender for Endpoint using the least administrative effort. What should you do?

A.Create a configuration profile with the Defender for Endpoint onboarding blob and assign it to the devices.
B.Deploy a PowerShell script that runs the onboarding script on each device.
C.Use the Microsoft Defender for Endpoint connector in Intune to onboard the devices.
D.Manually install the Defender for Endpoint agent on each device.
AnswerC

The Microsoft Defender for Endpoint connector in Intune allows you to onboard devices with minimal effort. You simply enable the connector, and Intune automatically deploys the onboarding configuration to all targeted devices. This method is the most efficient and reduces manual steps, making it ideal for large-scale deployments.

Why this answer

The Microsoft Defender for Endpoint connector in Intune is designed to simplify onboarding. When enabled, it automatically deploys the onboarding package to all Intune-managed Windows devices. This eliminates the need for manual configuration or scripting, providing the least administrative effort and ensuring consistent deployment across the organization.

Exam trap

The trap here is overlooking the built-in connector and instead opting for manual or script-based methods, which require more effort and do not leverage Intune's automation.

177
Multi-Selecthard

You are preparing infrastructure for Windows Autopilot deployment in a hybrid Microsoft Entra join scenario. You need to ensure that devices can join the on-premises domain and enroll in Intune. Which two components must you configure? (Choose two.)

Select 2 answers
A.Device enrollment manager (DEM) account
B.Intune connector for Active Directory
C.Automatic MDM enrollment in Microsoft Entra ID
D.Windows Autopilot deployment profile with 'Convert all targeted devices to Autopilot'
E.Microsoft Entra Connect with device writeback
AnswersB, C

The Intune connector for Active Directory is required for hybrid Microsoft Entra join. It enables devices to perform an offline domain join during Autopilot, creating computer objects in Active Directory. Without this connector, devices cannot join the domain automatically, and the hybrid join process fails. It must be installed on a server with domain access.

Why this answer

For Windows Autopilot hybrid Microsoft Entra join, the Intune connector for Active Directory is essential to perform the offline domain join, and automatic MDM enrollment in Microsoft Entra ID ensures the device enrolls in Intune. These two components together enable the hybrid join and management workflow.

Exam trap

The trap here is including optional components like device writeback or DEM accounts, which are not required for the core hybrid join and enrollment process.

178
MCQmedium

Your organization, Fabrikam, uses Microsoft Intune to manage iOS/iPadOS and Android devices. You need to implement a solution that ensures company email can only be accessed from the Outlook mobile app, and that data from the Outlook app cannot be copied to personal apps. You also need to ensure that when a user leaves the company, the corporate data in Outlook is removed without affecting personal data. You plan to use app protection policies (MAM). The devices are not enrolled in Intune (unmanaged). You configure the app protection policies for Outlook on iOS and Android. However, users report that they can still copy email content to personal apps. What should you check?

A.Ensure that the devices are enrolled in Intune.
B.Check that the device compliance policy is assigned.
C.Verify that the 'Cut, copy, and paste' setting in the app protection policy is set to 'No' or 'Policy managed apps'.
D.Confirm that the Outlook app is a managed app in Intune.
AnswerC

Data transfer between apps is governed by the 'Cut, copy, and paste' restriction, which must be set to 'No' or 'Policy managed apps' to block copying into personal apps. Verifying this setting addresses the reported leak.

Why this answer

The 'Cut, copy, and paste' setting in the app protection policy controls data transfer between apps. To prevent copying email content to personal apps, this setting must be set to 'No' or 'Policy managed apps'. Option A is incorrect because device enrollment is not required for MAM policies on unmanaged devices.

Option B is incorrect because device compliance policies are not applicable without enrollment. Option D is incorrect because Outlook is already a managed app; the issue is the policy setting.

179
MCQhard

You manage macOS devices enrolled in Microsoft Intune using the Intune Company Portal app. Users report that the Company Portal app does not detect newly assigned required apps and shows an outdated compliance status. You need to ensure the Company Portal refreshes device state on demand. What should you do?

A.From the Intune admin center, select the device and choose Sync to push a check-in to the macOS device
B.Delete the device record in Intune and have the user re-enroll the macOS device to refresh state
C.Instruct users to open Company Portal, select Devices, choose the device, and select Check status to force a sync
D.Instruct users to sign out of and back into the Company Portal app to refresh the device state
AnswerC

The Check status action in the macOS Company Portal app triggers a device check-in with Intune, refreshing compliance state and app assignments. This is the supported self-service method for macOS users to force a sync without waiting for the scheduled interval. It directly addresses the scenario where the Company Portal shows stale information and required apps are not yet detected.

Why this answer

The macOS Company Portal app includes a Check status option that forces the device to check in with Intune, refreshing compliance and app assignment data. This is the correct self-service method for users to resolve stale Company Portal information without administrator intervention. Other actions such as re-authentication, admin-initiated sync, or re-enrollment either do not trigger a check-in or are unnecessarily disruptive.

Exam trap

The trap here is assuming that signing out and back into Company Portal refreshes device state, when only the Check status action triggers an actual device check-in.

180
MCQmedium

Refer to the exhibit. You run a PowerShell command to check the assignment status of device configuration profiles. The 'BitLocker Policy' shows 'Pending'. What does 'Pending' indicate?

A.The policy is waiting for user approval
B.The policy assignment failed due to a conflict
C.The policy has been successfully applied
D.The policy has been assigned to the device but not yet applied
AnswerD

A pending status means the configuration profile is targeted at the device through its Microsoft Entra ID group assignment, but the device has not yet downloaded and processed it. This satisfies the scenario's requirement to interpret assignment status, distinguishing delivery from actual application of the BitLocker settings.

Why this answer

In Microsoft Intune, when a device configuration profile shows a status of 'Pending', it means the policy has been successfully assigned to the device in the cloud but has not yet been applied or reported back as compliant. This is a normal transitional state that occurs while the device checks in with the Intune service, downloads the policy, and applies it during the next sync cycle. The 'Pending' status does not indicate failure, conflict, or user approval requirements.

Exam trap

The trap here is that candidates often confuse 'Pending' with a failure or conflict, when in fact it is a normal intermediate state that resolves automatically after the device syncs with Intune.

How to eliminate wrong answers

Option A is wrong because 'Pending' does not require user approval; user approval is only relevant for specific scenarios like enrollment or app installation prompts, not for device configuration profiles. Option B is wrong because a policy conflict would typically result in a 'Conflict' or 'Error' status, not 'Pending'. Option C is wrong because 'Pending' explicitly means the policy has not yet been applied; a successfully applied policy would show a status of 'Succeeded' or 'Compliant'.

181
MCQhard

A company uses Microsoft Defender for Endpoint to manage endpoint security. They observe that some devices are not reporting vulnerability data to Microsoft Defender XDR. Which component is most likely misconfigured?

A.Microsoft Sentinel workspace
B.Microsoft Defender for Endpoint sensor on the devices
C.Intune MDM authority
D.Microsoft Purview compliance portal
AnswerB

Vulnerability data reaches Microsoft Defender XDR only through the Defender for Endpoint sensor, which collects and uploads device telemetry. A misconfigured or unhealthy sensor means devices stop reporting, so threat and vulnerability information never surfaces in the portal.

Why this answer

(Microsoft Defender for Endpoint sensor) is correct. The sensor is the agent installed on devices that collects and reports vulnerability information to Microsoft Defender XDR. If the sensor is misconfigured, missing, or not running, devices will not report vulnerability data.

Option A (Microsoft Sentinel workspace) is a SIEM that ingests security data but is not the source of vulnerability data. Option C (Intune MDM authority) manages device compliance and configuration but does not directly collect vulnerability data. Option D (Microsoft Purview compliance portal) handles data governance and compliance, not vulnerability reporting.

182
MCQmedium

You have a Windows 10 device that is managed by Intune and enrolled in Microsoft Defender for Endpoint. The device is reporting a high number of false positive detections from Microsoft Defender Antivirus. You need to configure an exclusion for a specific folder path to reduce false positives. Where should you configure the exclusion?

A.In a device compliance policy
B.In Group Policy
C.In the endpoint protection profile for Microsoft Defender Antivirus in Intune
D.In Microsoft Defender Security Center
AnswerC

Antivirus exclusions for folder paths are delivered through the Microsoft Defender Antivirus endpoint protection profile in Intune, which configures the Defender AV policy on managed devices. This applies the exclusion centrally without touching local device settings.

Why this answer

In an Intune-managed environment, antivirus exclusions for Microsoft Defender Antivirus are configured within the endpoint protection profile, specifically under the Microsoft Defender Antivirus settings. This profile is assigned to devices via Intune policies, allowing centralized management of exclusions without requiring on-premises Group Policy or direct interaction with the Microsoft Defender Security Center portal.

Exam trap

The trap here is that candidates often confuse the Microsoft Defender Security Center (a cloud-based security analytics portal) with the Intune endpoint protection profile, mistakenly thinking exclusions are configured in the security center rather than in the device management policy.

How to eliminate wrong answers

Option A is wrong because device compliance policies are used to enforce security requirements (e.g., encryption, OS version) and do not contain settings for antivirus exclusions. Option B is wrong because Group Policy is a traditional on-premises management tool; while it can configure Defender exclusions, it is not applicable when the device is solely managed by Intune and not domain-joined or using Group Policy. Option D is wrong because Microsoft Defender Security Center (now part of Microsoft 365 Defender) is a security operations portal for threat investigation and response, not a configuration interface for local antivirus exclusions on individual devices.

183
Multi-Selecteasy

You are configuring Microsoft Intune for Windows 10 devices. Which two settings can you enforce using a device restrictions profile? (Select TWO.)

Select 2 answers
A.Disable the camera
B.Set default web browser
C.Set battery saver threshold
D.Configure Windows Update for Business settings
E.Require a password for device unlock
AnswersA, E

Device restrictions include hardware disabling.

Why this answer

A is correct because the device restrictions profile in Microsoft Intune includes a 'Camera' setting under the 'General' category, which allows you to disable the camera on Windows 10 devices by setting it to 'Block'. This enforces a policy that prevents camera access across all apps and the OS, leveraging the CSP (Policy CSP) `Camera/AllowCamera`.

Exam trap

The trap here is that candidates often confuse device restrictions profiles with other policy types, such as Administrative Templates or Windows Update for Business profiles, leading them to select settings like default browser or Windows Update configuration that belong to different policy categories.

184
Multi-Selecteasy

Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?

Select 2 answers
A.Request the hardware hash from the device manufacturer (OEM)
B.Extract the hardware hash from the device BIOS
C.Run a PowerShell script on a device that is already running Windows 10 or later
D.Use Microsoft Intune to generate the hardware hash from the device serial number
E.Use Windows Configuration Designer to create a provisioning package that captures the hardware hash
AnswersA, C

OEMs can provide the hardware hash.

Why this answer

OEMs can provide the hardware hash for devices they manufacture, which can be uploaded to Microsoft Intune or the Autopilot deployment service. This method is commonly used for new devices ordered directly from the manufacturer, as the hash is generated during the manufacturing process and included in the device's packaging or accessible via the OEM's portal.

Exam trap

The trap here is that candidates often assume the hardware hash can be extracted from BIOS or generated by Intune from a serial number, but the hash requires a running Windows OS to compute and must be collected via PowerShell or provided by the OEM.

185
MCQhard

You use Microsoft Intune to manage Windows devices. You deploy a Win32 app as required to a device group. The app's detection rule uses a file version check on `C:\Program Files\Contoso\app.exe`. Users report the app appears installed, but Intune repeatedly reinstalls it on every check-in. The app's installer does not actually place app.exe in that path; instead, it places it in `C:\Program Files (x86)\Contoso\`. What should you do?

A.Set the app's install behavior to user context so the file is placed in the correct path.
B.Increase the detection rule's version comparison to 'greater than or equal to' the installed version.
C.Change the detection rule to check the correct path `C:\Program Files (x86)\Contoso\app.exe`.
D.Add a requirement rule that the device runs a 64-bit version of Windows.
AnswerC

Intune re-evaluates the detection rule on each check-in. If the rule points to a path where the file does not exist, detection always returns false, so Intune treats the app as missing and reinstalls it repeatedly. Updating the detection rule to the actual install path makes detection succeed and stops the reinstall loop, directly resolving the reported behavior.

Why this answer

Intune evaluates the detection rule at each check-in to decide whether the app is present. A rule that points to a file path where the executable was never installed always evaluates as not detected, so Intune believes the app is missing and reinstalls it. Correcting the detection rule to reference the actual installation path, Program Files (x86), allows detection to succeed and ends the repeated reinstallations.

Exam trap

The trap here is treating repeated reinstallations as an assignment or requirement problem, when the actual cause is a detection rule pointing at a path the installer never writes to.

186
MCQeasy

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. You need to ensure that devices receive quality updates with a maximum deferral of 7 days. What should you configure?

A.Device compliance policy with a setting for update deferral.
B.Windows Update rings in Intune.
C.Endpoint security policy for Windows Update.
D.Windows Update for Business configuration in Group Policy.
AnswerB

Windows Update rings in Intune allow you to configure deferral periods for quality updates, feature updates, and driver updates. By setting the quality update deferral period to 7 days, you ensure that devices receive quality updates after a 7-day delay. This is the correct method to control update deferrals for Windows devices managed by Intune.

Why this answer

Windows Update rings in Intune are specifically designed to manage update deferrals for quality and feature updates. By configuring a quality update deferral of 7 days, you ensure devices receive updates after that period. Other options either do not support deferral settings or are not the correct tool for Intune-managed devices.

Exam trap

The trap here is confusing compliance policies or endpoint security policies with update rings, which are the only Intune feature that directly controls update deferrals.

187
Multi-Selecthard

Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?

Select 3 answers
A.A device compliance policy assigned to the device
B.MDM enrollment enabled in Microsoft Entra ID
C.Azure AD Premium P1 license
D.A valid Microsoft Intune license assigned to the user
E.Internet connectivity to Microsoft Intune service
AnswersB, D, E

MDM enrolment must be enabled in Microsoft Entra ID so the tenant's users are permitted to enrol Windows devices into Intune; without this, automatic MDM enrolment fails during OOBE or manual enrolment, regardless of licensing or connectivity.

Why this answer

Option B is correct because MDM enrollment must be enabled in Microsoft Entra ID (the Mobility (MDM and MAM) settings) so that Windows devices can be automatically or manually enrolled into Intune; without this, the tenant cannot accept MDM enrollments. Option D is correct because each enrolling user must hold a valid Microsoft Intune license (for example, an Intune, EMS E3/E5, or Microsoft 365 license that includes Intune) to be entitled to enroll and manage the device. Option E is correct because the Windows device must have internet connectivity to reach the Microsoft Intune service endpoints (and dependent services such as the enrollment and MDM endpoints) to complete enrollment and receive policy.

Option A is not required for enrollment itself, since a device compliance policy is applied after the device is enrolled and is used for conditional access evaluation, not as an enrollment prerequisite. Option C is not required, because Azure AD Premium P1 is not a prerequisite for Intune enrollment; Intune licensing covers the MDM functionality, and automatic MDM enrollment in Entra ID does not require P1.

Exam trap

The trap here is that candidates often confuse post-enrollment requirements (like compliance policies or Azure AD Premium P1) with prerequisites for enrollment, leading them to select options that are only needed after the device is already enrolled.

188
MCQeasy

Your company uses Microsoft Intune to manage Windows 11 devices. An administrator needs to remotely restart a specific device that is currently online to apply pending updates. Which action should the administrator use in the Intune admin center?

A.Wipe
B.Fresh Start
C.Retire
D.Restart
AnswerD

The Restart device action in Intune sends a remote reboot command to the managed device. It is the correct, least-destructive action to apply pending updates that require a restart, and it works on Windows devices that are online and checking in with the service.

Why this answer

The Restart action is designed specifically to remotely reboot a managed device so that pending updates requiring a restart can complete. Retire, Wipe, and Fresh Start are all destructive or unenrollment actions that remove data or management and are not appropriate when the goal is simply to reboot an online device.

Exam trap

The trap here is confusing destructive device actions such as Wipe or Fresh Start with the simple remote reboot action.

189
MCQmedium

You are the Endpoint Administrator for a company that uses Microsoft Intune to manage Windows 11 devices. The security team requires that Microsoft Edge be configured with a specific set of security settings, including blocking outdated plugins and enforcing SmartScreen. You need to deploy these settings to all Windows 11 devices with minimal administrative effort. What should you do?

A.Create a device configuration profile with the 'Administrative Templates' profile type and configure the Microsoft Edge settings.
B.Deploy a PowerShell script that modifies the registry to set the required Edge policies.
C.Create a custom configuration profile using the Open Mobile Alliance Uniform Resource Identifier (OMA-URI) settings.
D.Use the Microsoft 365 Apps for enterprise deployment to include Edge settings in the Office Configuration Service.
AnswerA

Administrative Templates in Intune are based on ADMX files and allow you to configure hundreds of Microsoft Edge policies directly from the Intune console. This is the recommended method for managing Edge settings at scale without scripting, and it applies to all targeted devices automatically.

Why this answer

Administrative Templates in Intune provide a streamlined way to configure Microsoft Edge policies using the same ADMX-backed settings that Group Policy uses. They are built into Intune, require no custom scripting, and can be assigned to device groups. This meets the requirement to deploy security settings with minimal administrative effort.

Exam trap

The trap here is assuming that any script or custom profile can achieve the same result, but Administrative Templates are purpose-built for this and reduce ongoing management overhead.

190
MCQeasy

You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?

A.Windows 10/11 (Microsoft 365 Apps)
B.Microsoft 365 (Web link)
C.Microsoft Store app (new)
D.Windows app (Win32)
AnswerA

The Windows 10/11 (Microsoft 365 Apps) app type uses the Microsoft 365 Apps deployment pipeline, packaging the suite as a required or available install. Marking it available publishes it in the Company Portal for user-initiated installation.

Why this answer

The 'Windows 10/11 (Microsoft 365 Apps)' app type in Intune is specifically designed to deploy Microsoft 365 Apps (formerly Office 365 ProPlus) with built-in support for the Office Deployment Tool (ODT) and XML configuration. This app type automatically handles the installation, updates, and licensing via the Microsoft 365 Apps for enterprise channel, and it appears in the Company Portal for user-initiated installation. Other app types lack the native integration for Microsoft 365 Apps deployment or do not support user-visible installation in the Company Portal.

Exam trap

The trap here is that candidates often choose 'Windows app (Win32)' because they think any desktop app must be deployed as a Win32 app, overlooking the dedicated Microsoft 365 Apps app type that provides built-in ODT integration and automatic update management.

How to eliminate wrong answers

Option B (Microsoft 365 (Web link)) is wrong because it only creates a shortcut to a web URL in the Company Portal, not an actual app installation, so it cannot deploy Microsoft 365 Apps locally. Option C (Microsoft Store app (new)) is wrong because it is used for deploying apps from the Microsoft Store, not for deploying Microsoft 365 Apps via the Office Deployment Tool. Option D (Windows app (Win32)) is wrong because while it can deploy any Win32 app, it requires manual packaging of the Office installation files and does not provide the built-in ODT integration, update management, or automatic licensing that the dedicated Microsoft 365 Apps app type offers.

191
Drag & Dropmedium

Arrange the steps to perform a Windows 10 feature update using Windows Update for Business in Intune.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for performing a Windows 10 feature update using Windows Update for Business in Intune starts with creating a deployment ring, then configuring the feature update version and rollout settings, followed by assigning the ring to the target devices or groups, and finally monitoring the update deployment to track success and issues. This order ensures that the ring is properly configured before being applied, and that monitoring captures the actual deployment activity.

192
MCQhard

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?

A.Use a Mobile App Configuration policy to enforce app settings.
B.Deploy an Intune App Protection Policy (APP) for Microsoft 365 apps.
C.Create a Device Compliance policy for iOS devices.
D.Configure a Conditional Access policy to require compliant devices.
AnswerB

App Protection Policies apply data-loss controls at the app layer, restricting copy, paste, save-as and sharing between managed Microsoft 365 apps and unmanaged locations, which protects corporate data on iOS devices without requiring full device enrolment.

Why this answer

Intune App Protection Policies (APP) are designed specifically to protect corporate data at the app layer on iOS and Android, without requiring device enrollment. They enforce controls like PIN access, blocking copy/paste to personal apps, and selective wipe of corporate data within Microsoft 365 apps. This directly addresses the requirement to protect corporate data when users access Microsoft 365 apps.

Exam trap

MD-102 often tests the confusion between App Protection Policies (data protection at app layer) and Device Compliance Policies (device state evaluation), tricking candidates into choosing compliance when the requirement is data protection.

How to eliminate wrong answers

Option A is wrong because a Mobile App Configuration policy customizes app settings (e.g., server URLs, feature toggles) but does not enforce data protection controls like encryption or copy/paste restrictions. Option C is wrong because a Device Compliance policy evaluates device state (OS version, jailbreak status, encryption) and marks the device compliant or not, but does not itself protect app data. Option D is wrong because Conditional Access controls access to resources based on conditions like compliance or location, but does not protect data within apps once access is granted.

193
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Intune to protect devices from malware?

Select 2 answers
A.Create network segmentation rules
B.Enable email attachment scanning
C.Deploy third-party antivirus software
D.Enforce Windows Defender Antivirus real-time protection
E.Configure Windows Defender Firewall rules
AnswersD, E

Enforcing Windows Defender Antivirus real-time protection through Intune endpoint security policies continuously scans files and processes, blocking malware before execution. This directly satisfies the stem's malware-protection requirement by configuring the antivirus engine on managed Windows devices via the Microsoft Intune security baseline or antivirus policy profile.

Why this answer

Option D is correct because Intune can enforce Windows Defender Antivirus settings through endpoint security antivirus policies, including turning on real-time protection, which actively detects and blocks malware on managed Windows devices. Option E is correct because Intune endpoint security firewall policies let you configure Windows Defender Firewall rules (such as blocking inbound/outbound traffic on specific ports or profiles), which helps prevent malware from communicating or spreading across the network. Option A is not provided by Intune itself; network segmentation is typically handled by network security appliances, VLANs, or Azure NSGs rather than Intune device configuration.

Option B is not an Intune malware-protection action; email attachment scanning is performed by Exchange Online Protection or Microsoft Defender for Office 365, not by Intune. Option C is not a native Intune malware-protection action in the sense described; while Intune can deploy apps, it does not itself provide antivirus protection, and the built-in Defender controls in D and E are the direct Intune mechanisms for malware protection.

Exam trap

Candidates often think only antivirus settings (like real-time protection) protect against malware, overlooking that firewall rules also play a crucial role by blocking malicious network traffic. The correct answers are D and E; a common mistake is selecting C (deploying third-party antivirus) or omitting E.

194
MCQmedium

You manage Windows 10 devices with Intune. You need to collect diagnostic logs from a remote device that is experiencing application crashes. Which Intune feature should you use?

A.Collect diagnostics
B.Company Portal app
C.Autopilot Reset
D.Windows Update for Business
AnswerA

Collect diagnostics remotely gathers Windows diagnostic logs, including event traces and app crash data, from the device without user interaction. This satisfies the requirement to collect logs from a remote device experiencing application crashes, unlike Remote Help or device restart actions.

Why this answer

The 'Collect diagnostics' feature in Intune allows you to remotely gather diagnostic logs from Windows 10 devices without user interaction. This is the correct tool for troubleshooting application crashes because it collects system logs, event logs, and crash dumps directly from the device via the Intune management channel, enabling analysis of the failure.

Exam trap

The trap here is that candidates may confuse 'Collect diagnostics' with the Company Portal's ability to view device status or sync policies, but the Company Portal cannot initiate log collection; only the Intune admin console's 'Collect diagnostics' action can remotely gather crash logs.

How to eliminate wrong answers

Option B is wrong because the Company Portal app is a self-service portal for users to install applications, access corporate resources, and enroll devices, not a tool for collecting diagnostic logs. Option C is wrong because Autopilot Reset is used to reset a device to a business-ready state, removing user data and apps, which would destroy the crash logs needed for diagnosis. Option D is wrong because Windows Update for Business manages update policies and deployment rings, not diagnostic log collection; it focuses on keeping devices patched, not troubleshooting application crashes.

195
MCQhard

An organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. The security team wants to automatically apply an Intune app protection policy (APP) when a user accesses a risky app from an unmanaged device. What should the administrator use?

A.Conditional Access App Control with session control
B.Device configuration policy
C.App protection policy assignment to users
D.Device compliance policy
AnswerA

Conditional Access App Control with session control proxies app sessions in real time, letting Defender for Cloud Apps enforce Intune app protection policies when a risky app is accessed from an unmanaged device. This satisfies the stem's requirement for automatic, session-level policy application based on device management state and app risk.

Why this answer

Conditional Access App Control with session control is the correct solution because it allows the administrator to monitor and control app sessions in real time, applying Intune app protection policies (APP) when a user accesses a risky app from an unmanaged device. This integration uses reverse proxy architecture to intercept traffic and enforce data protection policies, such as blocking downloads or requiring managed apps, directly within the cloud app session.

Exam trap

The trap here is that candidates often confuse 'app protection policy assignment to users' (Option C) as the direct method, but the question requires dynamic, risk-based triggering via Conditional Access and Defender for Cloud Apps, not static user assignment.

How to eliminate wrong answers

Option B (Device configuration policy) is wrong because it manages device settings (e.g., Wi-Fi, VPN) and does not enforce app-level protection based on risk or device management status. Option C (App protection policy assignment to users) is wrong because it assigns APP directly to users without session-level conditional access; it cannot dynamically trigger based on real-time risk detection from Defender for Cloud Apps. Option D (Device compliance policy) is wrong because it evaluates device compliance (e.g., jailbreak detection, OS version) and blocks access at the device level, but it does not apply app protection policies within a cloud app session from an unmanaged device.

196
MCQeasy

A company uses Microsoft 365 E3 licenses. They need to enforce that all users must use the Microsoft Authenticator app for MFA instead of SMS or phone call. What should the administrator configure?

A.MFA service settings in the legacy portal
B.Authentication methods policy
C.Security defaults
D.Conditional Access policy
AnswerB

The authentication methods policy in Microsoft Entra ID lets you enable Microsoft Authenticator while disabling SMS and voice call for all users, directly satisfying the requirement to enforce app-based MFA. Unlike legacy per-user MFA settings, it provides granular control over which methods are available tenant-wide.

Why this answer

The Authentication methods policy (B) is the correct configuration because it allows administrators to control exactly which authentication methods users can register and use for MFA. By targeting the policy to all users and disabling SMS and voice call while enabling Microsoft Authenticator (push notifications or OTP), the requirement is met. This policy supersedes legacy MFA settings and provides granular control over modern authentication methods.

Exam trap

The trap here is that candidates often confuse the Authentication methods policy with Conditional Access policies, assuming that a Conditional Access policy can restrict MFA methods, but in reality, Conditional Access only controls when MFA is required, not which methods are allowed.

How to eliminate wrong answers

Option A is wrong because the MFA service settings in the legacy portal only control per-user MFA enforcement and basic method availability (call, SMS, app), but they do not allow disabling specific methods like SMS or phone call for all users—they only enable or disable the app as a whole. Option C is wrong because Security defaults enforce a baseline set of security policies (including requiring MFA for all users) but do not allow granular control to restrict MFA methods to only the Authenticator app; they permit any available method. Option D is wrong because a Conditional Access policy can require MFA but cannot restrict which specific MFA methods (e.g., Authenticator app vs.

SMS) are allowed; method restriction is handled exclusively by the Authentication methods policy.

197
Matchingmedium

Match each Microsoft 365 compliance feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Prevent sensitive data from being shared inappropriately

Classify and protect documents and emails with labels

Manage retention and disposal of records

Search and export content for legal investigations

Log and investigate user and admin activities

Why these pairings

Compliance features are part of the Microsoft 365 security and compliance center, relevant for endpoint administrators.

198
MCQhard

Your organization deploys Microsoft Defender for Endpoint (now Microsoft Defender XDR) on Windows 10 devices using Intune. After deployment, some devices show 'Defender service is not running' in the security console. The devices are online and compliant. What is the most likely cause?

A.Tamper protection is enabled and blocking the service.
B.The devices are not compliant with the Defender policy.
C.Windows Firewall is blocking Defender updates.
D.A third-party antivirus is installed and active.
AnswerD

When a third-party antivirus is installed and active, it registers with the Windows Security Center and disables Microsoft Defender Antivirus, so the Defender service stops running. Intune's onboarding then reports the service as not running despite the device being online and compliant.

Why this answer

When a third-party antivirus is installed and active on a Windows 10 device, Windows Defender (now Microsoft Defender Antivirus) automatically disables itself to avoid conflicts. This is by design: the Windows Security Center detects the active third-party AV and sets Defender's service state to stopped or disabled. In the Microsoft Defender for Endpoint console, this appears as 'Defender service is not running' even though the device is online and compliant with Intune policies.

Exam trap

The trap here is that candidates often assume tamper protection (Option A) is the culprit because it is a common security feature, but they overlook the automatic disabling behavior triggered by a third-party antivirus registration in the Windows Security Center.

How to eliminate wrong answers

Option A is wrong because tamper protection prevents unauthorized changes to Defender settings but does not stop the Defender service itself; it blocks modifications to real-time protection, cloud-delivered protection, and security intelligence updates, not the service state. Option B is wrong because the devices are explicitly stated as compliant with the Defender policy, so non-compliance is not the cause. Option C is wrong because Windows Firewall does not block Defender updates; Defender updates use Windows Update or dedicated update channels (e.g., HTTP/HTTPS to Microsoft servers) which are not filtered by the built-in firewall unless custom rules are misconfigured, and even then, a blocked update would not stop the service from running.

199
MCQmedium

Refer to the exhibit. A Windows 10 device is showing as non-compliant. The compliance policy 'Require BitLocker' is assigned to all devices. The device does not have BitLocker enabled. However, the user is able to access corporate email on the device. What is the most likely reason for this?

A.The compliance policy has a grace period of 7 days for BitLocker.
B.The compliance policy is not assigned to the device.
C.The device is configured as a kiosk device, which exempts it from compliance.
D.There is no Conditional Access policy that requires compliant device for access to corporate email.
AnswerD

Compliance policy alone only reports device state; enforcement of access requires a Conditional Access policy requiring compliant devices. Without that policy bound to the email cloud app, the non-compliant device still obtains a token, so BitLocker's absence does not block email.

Why this answer

D is correct because compliance policies alone do not enforce access restrictions; they only report device compliance status. To block access to corporate email, a Conditional Access policy must be configured to require a compliant device. Without such a policy, the device can still access email even if it is non-compliant.

Exam trap

The trap here is that candidates assume a compliance policy automatically blocks access to resources when a device is non-compliant, but in reality, a separate Conditional Access policy is required to enforce that block.

How to eliminate wrong answers

Option A is wrong because a grace period delays enforcement but does not allow access if the device is non-compliant and a Conditional Access policy is in place; the question states the device is non-compliant and still accessing email, so the absence of Conditional Access is the key. Option B is wrong because the exhibit states the compliance policy is assigned to all devices, so the device is indeed assigned the policy. Option C is wrong because kiosk devices are not exempt from compliance policies; they can be targeted by compliance policies and Conditional Access, and there is no built-in exemption for kiosk mode in this context.

200
MCQmedium

Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?

A.The compliance policy has been removed from these devices.
B.The devices are still within the grace period and can access resources.
C.The devices were recently remediated and are now compliant.
D.The devices have exceeded the grace period and should be blocked from accessing resources.
AnswerD

A past complianceGracePeriodExpirationDateTime means the grace period has already elapsed, so Microsoft Entra ID conditional access policies enforcing compliance will block those devices from accessing resources. This satisfies the stem's constraint: the timestamp predates the current date, confirming the grace window closed without remediation.

Why this answer

The complianceGracePeriodExpirationDateTime represents the deadline by which a device must become compliant after initially being marked noncompliant. When this timestamp is in the past, it means the grace period has expired, and the device should be blocked from accessing corporate resources as per the conditional access policy. This is a standard behavior in Microsoft Intune for managing noncompliant devices.

Exam trap

The trap here is that candidates confuse the complianceGracePeriodExpirationDateTime with the last check-in time or assume a past timestamp means the device is still compliant, when in fact it signals the end of the grace period and triggers blocking actions.

How to eliminate wrong answers

Option A is wrong because removing the compliance policy from a device does not affect the grace period timestamp; the timestamp is set when the device is marked noncompliant and persists regardless of policy removal. Option B is wrong because a past grace period expiration indicates the grace period has ended, not that the device is still within it; devices within the grace period would have a future timestamp. Option C is wrong because remediated devices would have a new compliance status and a reset complianceGracePeriodExpirationDateTime, not a past one; a past timestamp indicates the grace period was not resolved in time.

201
MCQmedium

You deployed this endpoint protection policy to a Windows 10 device. A user reports that a known malicious file was downloaded but not blocked. What is the most likely reason?

A.Real-time scanning is set to monitorAllFiles, but the file was an archive.
B.The scan type is set to quick, which does not scan downloaded files.
C.The cloud block level is set to high, which may block unknown files, but known files might be missed.
D.The policy has not been applied to the device yet.
AnswerD

Endpoint protection settings reach a device only after it checks in and applies the configuration. If the policy has not yet been delivered, the malicious file download proceeds unchecked, since no scanning or blocking rules are active locally.

Why this answer

If the endpoint protection policy has not been applied to the device, the Microsoft Defender for Endpoint settings (including real-time scanning and cloud-delivered protection) are not active. The policy must be successfully delivered via Microsoft Intune or Configuration Manager before any protection rules take effect. Without policy application, the device runs with default or no protection, allowing known malicious files to be downloaded without being blocked.

Exam trap

The trap here is that candidates assume a protection policy is automatically active once created, but Microsoft Intune policies require device check-in and successful application before they take effect, and the cloud block level setting is often misunderstood as affecting known malware detection.

How to eliminate wrong answers

Option A is wrong because real-time scanning set to monitorAllFiles includes archives; Microsoft Defender scans archive files (e.g., .zip, .rar) by default when monitorAllFiles is enabled, so an archive would still be scanned. Option B is wrong because the scan type (quick, full, or custom) applies to scheduled or on-demand scans, not to real-time protection; real-time scanning always inspects files as they are downloaded or accessed, regardless of the scan type setting. Option C is wrong because the cloud block level setting (high, moderate, etc.) affects how aggressively unknown files are sent to the cloud for analysis, but known malicious files are blocked locally by signature-based detection and do not rely on cloud block level; a known file would be blocked even with a high cloud block level.

202
MCQeasy

You need to retire a device in Microsoft Intune. What is the effect of retiring a device?

A.The device is unenrolled, and corporate data and apps are removed. Personal data is preserved.
B.The device is factory reset to its original settings.
C.The device remains enrolled but can no longer access corporate resources.
D.The device is deleted from Azure AD and Intune.
AnswerA

Retire sends an unenrolment command that removes the management profile and corporate data such as managed apps, email profiles and policies, while leaving personal files and settings intact. This matches the stem's requirement to remove only organisational content.

Why this answer

Retiring a device in Microsoft Intune performs a selective wipe that removes only corporate-managed data and apps while preserving the user's personal data. The device is also unenrolled from Intune management, meaning it no longer receives policy or compliance enforcement. This is distinct from a full wipe, which resets the entire device to factory settings.

Exam trap

The trap here is that candidates often confuse 'retire' with 'wipe' (factory reset), assuming both remove all data, but Intune's selective wipe is designed specifically to preserve personal data while removing corporate resources.

How to eliminate wrong answers

Option B is wrong because it describes a factory reset (full wipe), which removes all data including personal content, whereas retirement only removes corporate data. Option C is wrong because a retired device is unenrolled and loses all access to corporate resources, not remaining enrolled with restricted access. Option D is wrong because while the device record is removed from Intune, it is not automatically deleted from Azure AD; the device object in Azure AD remains until explicitly removed or until the user's sync cycle cleans it up.

203
MCQeasy

A user's device is marked as 'Noncompliant' in Microsoft Intune due to missing required updates. The device is configured with a compliance policy that requires a minimum OS version. The user claims the device is up-to-date. What should you verify first?

A.The current OS version on the device.
B.The user's license status.
C.The compliance policy is assigned to the device.
D.The device is connected to the internet.
AnswerA

The compliance policy enforces a minimum OS version, so the reported build must be compared against that threshold. Verifying the actual OS version first confirms whether the device genuinely meets the minimum or the policy is misjudged.

Why this answer

The first step in troubleshooting a noncompliant device due to a missing minimum OS version is to verify the actual OS version currently installed on the device. The user's claim that the device is up-to-date may be based on a misunderstanding of what version is required, or the device may have pending updates that have not been applied. Intune compliance policies evaluate the OS version reported by the device during check-in, so confirming the exact build number against the policy requirement is the logical starting point.

Exam trap

The trap here is that candidates may jump to verifying policy assignment or connectivity, overlooking that the most direct and immediate verification is the actual OS version on the device, which is the specific attribute being evaluated by the compliance policy.

How to eliminate wrong answers

Option B is wrong because license status affects enrollment and access to Intune features, but it does not directly cause a device to be marked noncompliant due to a missing OS version; a licensed user can still have a noncompliant device. Option C is wrong because if the compliance policy were not assigned to the device, the device would not be evaluated against that policy and would not be marked noncompliant for that reason; the fact that it is marked noncompliant indicates the policy is assigned. Option D is wrong because while internet connectivity is required for the device to check in with Intune and report compliance, the device is already reporting its noncompliant status, meaning it has communicated with the service; connectivity is not the root cause of the OS version mismatch.

204
MCQmedium

Your organization manages Windows devices with Intune and uses Azure Information Protection (AIP) to classify documents. You are deploying the AIP client as a Win32 app. After deployment, some users report that the AIP add-in is not visible in Office applications. What should you check first?

A.Confirm that Office is updated to the latest version.
B.Ensure that the required .NET Framework and Visual Studio Tools for Office runtime are installed.
C.Verify that the user has local administrator rights.
D.Check if the device has internet access to activate the client.
AnswerB

The AIP add-in for Office depends on the .NET Framework and Visual Studio Tools for Office runtime; if these prerequisites are absent, the add-in loads silently without appearing. Checking them first addresses the missing add-in symptom.

Why this answer

The AIP client (Azure Information Protection unified labeling client) requires the .NET Framework and Visual Studio Tools for Office (VSTO) runtime to integrate with Office applications. If these prerequisites are missing, the AIP add-in will not load in Office, even if the client is installed. Therefore, checking for these dependencies is the first troubleshooting step.

Exam trap

MD-102 often tests the prerequisites for AIP client deployment; candidates may overlook the VSTO and .NET requirements and instead focus on Office updates or permissions, which are less likely to cause the add-in to be completely missing.

How to eliminate wrong answers

Option A is wrong because while Office updates can affect add-in compatibility, the most common cause of a missing AIP add-in is missing prerequisites, not Office version. Option C is wrong because local administrator rights are not required for the AIP add-in to function; the client can be installed per-user or per-machine. Option D is wrong because internet access is needed for activation and policy retrieval, but if the add-in is not visible at all, it's likely a prerequisite issue rather than connectivity.

205
MCQhard

A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?

A.The OMA-URI setting is invalid.
B.The device is not enrolled.
C.The device's group membership is still being processed, so policies are not yet applied.
D.The device is not compliant.
AnswerC

Group membership processing delays policy targeting: Intune evaluates assignments dynamically, so a newly added device may report enrolled and compliant before its configuration profile reaches it. MaxInactivityTimeDeviceLock applies only once the device falls into the assigned group, satisfying the stem's unapplied-setting constraint.

Why this answer

When a device shows 'Enrolled' and 'Compliant' in Intune, the issue is not enrollment or compliance but policy delivery. The 'MaxInactivityTimeDeviceLock' OMA-URI setting (./Device/Vendor/MSFT/Policy/Config/DeviceLock/MaxInactivityTimeDeviceLock) is a CSP-based policy that applies via group membership targeting. If the device was recently added to the group or the group membership is still being evaluated, Intune's policy processing cycle (which runs every 15–30 minutes by default) may not have delivered the policy yet.

The JSON exhibit likely shows the device is in a pending state for policy application despite being enrolled and compliant.

Exam trap

The trap here is that candidates see 'Enrolled' and 'Compliant' and assume the device is fully healthy, but they overlook that policy application is asynchronous and depends on group membership processing, which can lag behind enrollment and compliance evaluation.

How to eliminate wrong answers

Option A is wrong because if the OMA-URI setting were invalid, the policy would show an error or 'Not applicable' status in Intune, not a missing application while the device remains compliant. Option B is wrong because the device explicitly shows enrollment state 'Enrolled', so the device is enrolled and this contradicts the premise. Option D is wrong because the device shows compliance state 'Compliant', so non-compliance is not the reason the policy is not applied.

206
MCQmedium

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, the primary user's corporate data is removed but the device remains enrolled and managed. Which action should you take in the Intune admin center?

A.Wipe the device.
B.Use Selective wipe.
C.Retire the device.
D.Reset the device.
AnswerB

Selective wipe (also known as selective wipe for MDM) removes corporate data and settings from the device while leaving personal data intact. Crucially, it keeps the device enrolled in Intune, allowing continued management. This matches the requirement to remove corporate data but keep the device managed.

Why this answer

Selective wipe is the action that removes corporate data from a device while preserving personal data and keeping the device enrolled in Intune. Wipe and reset remove all data and unenroll the device, while retire removes corporate data but also unenrolls the device. Only selective wipe satisfies both conditions of removing corporate data and maintaining enrollment.

Exam trap

The trap here is confusing retire with selective wipe; retire removes corporate data but also unenrolls the device, whereas selective wipe keeps the device managed.

207
Drag & Dropmedium

Arrange the steps to configure Conditional Access for Microsoft 365 in Azure AD.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Sign in, go to Conditional Access, create policy, set conditions, set controls, enable.

208
Multi-Selecthard

You are deploying a Win32 app to Windows devices using Microsoft Intune. The app requires a specific registry key to be present for detection. You also need to ensure the app installs only on devices running Windows 11 version 22H2 or later. Which two actions must you perform when creating the app? (Choose two.)

Select 2 answers
A.Set the install command to include a check for the registry key.
B.Configure the app to run in system context.
C.Configure a detection rule that checks for the registry key.
D.Add a dependency on a previous version of the app.
E.Add a requirement rule for the operating system version.
AnswersC, E

Detection rules determine whether the app is already installed. Using a registry detection rule ensures Intune accurately reports installation status and triggers reinstallation if the key is missing. This is required to verify successful installation and to maintain compliance with the app's presence on the device.

Why this answer

To ensure the app installs only on Windows 11 22H2 or later, a requirement rule for the OS version is necessary. To verify the app is installed by checking for a specific registry key, a detection rule must be configured. These two actions directly address the deployment conditions described in the scenario.

Exam trap

The trap here is confusing detection rules with requirement rules, or assuming that the install command can handle detection.

209
MCQmedium

You manage devices with Microsoft Intune. Users report that after a recent policy change, some devices are not receiving updated policies. You verify that the devices are online and have connectivity. What should you do to force a policy refresh?

A.Ask users to restart their devices.
B.Ask users to run Windows Update.
C.Adjust the MDM sync interval in Intune.
D.In the Intune portal, select the devices and click 'Sync'.
AnswerD

Selecting 'Sync' in the Intune portal triggers a remote device action that queues a check-in, prompting the device to contact the Intune service and pull updated policies immediately. This satisfies the stem's requirement to force a refresh on online devices without waiting for the scheduled check-in interval.

Why this answer

The Intune 'Sync' action sends a direct MDM policy refresh command to the device via the Microsoft Intune service. This triggers the device's enrollment client to immediately check in with the MDM server, download the latest policies, and apply them without waiting for the next scheduled sync interval. Since the devices are online and have connectivity, this remote sync forces an immediate policy refresh.

Exam trap

The trap here is that candidates often confuse a device restart or Windows Update with triggering an MDM policy refresh, but Intune's MDM sync is a distinct, remote action that must be initiated from the Intune portal or via a manual sync on the device itself.

How to eliminate wrong answers

Option A is wrong because restarting the device does not force an MDM policy sync; it only reboots the OS, and the device will still wait for its next scheduled sync interval (typically every 8 hours) unless a sync is triggered via Intune. Option B is wrong because running Windows Update checks for OS and driver updates, not MDM policy changes; policy updates are handled by the MDM client, not Windows Update. Option C is wrong because adjusting the MDM sync interval in Intune only changes the default check-in frequency for future syncs; it does not force an immediate refresh for devices that have already missed a policy update.

210
MCQmedium

You have the following JSON compliance policy for Windows 10 devices in Intune. A device with OS version 10.0.19042.0, build 19042, with BitLocker enabled, Secure Boot enabled, but Code Integrity disabled reports as non-compliant. Which setting is causing the non-compliance?

A.requireCodeIntegrity
B.minimumOsVersion
C.requireSecureBoot
D.requireDeviceEncryption
AnswerA

The device meets the OS version and BitLocker requirements, but Code Integrity is disabled. The requireCodeIntegrity setting enforces that code integrity must be enabled, so its disabled state directly triggers non-compliance. This setting is the specific constraint the device fails to satisfy.

Why this answer

The device reports as non-compliant because the compliance policy requires `requireCodeIntegrity` to be enabled, but the device has Code Integrity disabled. Even though BitLocker and Secure Boot are enabled, and the OS version meets the minimum requirement, the absence of Code Integrity enforcement triggers non-compliance. In Intune, Windows 10 compliance policies evaluate each setting independently, and a failure on any required setting results in overall non-compliance.

Exam trap

The trap here is that candidates often assume Secure Boot or BitLocker alone satisfy all security requirements, but Intune's `requireCodeIntegrity` is a separate, independent check that specifically enforces runtime code validation, and failing to enable it causes non-compliance even when other security features are active.

How to eliminate wrong answers

Option B is wrong because `minimumOsVersion` is satisfied by OS version 10.0.19042.0 (build 19042), which is above the typical minimum (e.g., 10.0.17763 for 1809), so it is not causing non-compliance. Option C is wrong because `requireSecureBoot` is enabled on the device, as stated in the scenario, so Secure Boot is compliant. Option D is wrong because `requireDeviceEncryption` is satisfied by BitLocker being enabled, which provides full device encryption, so this setting is compliant.

211
Multi-Selectmedium

You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?

Select 2 answers
A.Microsoft Defender for Endpoint license assigned to the user or device
B.macOS device enrollment in Microsoft Intune
C.Microsoft Intune management extension installed on the device
D.Onboarding to Microsoft Defender for Cloud
E.A VPN connection to the corporate network
AnswersA, B

Onboarding macOS devices to Microsoft Defender for Endpoint through Intune requires an assigned Defender for Endpoint licence, whether user-based or device-based, to provision the service and permit portal onboarding. Without this entitlement, Intune cannot deploy the Defender agent or activate protection.

Why this answer

The correct prerequisites are: A and B. For A: Microsoft Defender for Endpoint requires a valid license assigned to the user or device. For B: The macOS device must be enrolled in Microsoft Intune to receive the configuration profile and policies for Defender.

Option C is incorrect because the Microsoft Intune management extension is for Windows only, not macOS. Option D is incorrect because onboarding to Microsoft Defender for Cloud is not a prerequisite; Defender for Endpoint can be deployed independently. Option E is incorrect because a VPN connection is not required for Defender for Endpoint to function on macOS.

212
MCQmedium

You are responsible for managing Windows 10 devices with Microsoft Intune. You need to deploy a new line-of-business (LOB) app to a group of devices. The app requires a script to run after installation to configure settings. What should you use to deploy the app and ensure the script runs?

A.Add the app as a Win32 app and include the script in the install command.
B.Add the app as a Win32 app and include the script as a detection rule.
C.Add the app as a Microsoft Store app and use a PowerShell script to configure settings.
D.Add the app as a Win32 app and include the script as a requirement rule.
AnswerA

For Win32 apps in Intune, you can specify an install command that runs the installer. You can chain a configuration script by using a command line that executes the installer and then the script, for example: `setup.exe /silent && powershell.exe -File config.ps1`. This ensures the script runs after installation completes, fulfilling the requirement.

Why this answer

Win32 apps in Intune support custom install commands, allowing you to run additional scripts after the main installer. By appending the script execution to the install command, you ensure it runs immediately after installation. This is a common method for configuring LOB apps that require post-installation steps.

Other options like requirement or detection rules are not designed for executing configuration scripts.

Exam trap

The trap here is confusing detection rules with post-installation scripts; detection rules only check for app presence, not run configuration logic.

213
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. Contoso has an on-premises Active Directory Domain Services (AD DS) forest and uses Microsoft Entra ID with Microsoft Intune. You plan to deploy 200 new Windows 11 devices by using Windows Autopilot in Microsoft Entra hybrid join mode. You need to ensure that each device is automatically joined to AD DS and registered in Microsoft Entra ID during the out-of-box experience. What should you configure first?

A.Install and configure the Intune Connector for Active Directory.
B.Assign a Windows Autopilot deployment profile to all targeted devices.
C.Create a device enrollment restriction that blocks personal Windows devices.
D.Enable automatic enrollment for Windows devices in Intune.
AnswerA

The Intune Connector for Active Directory allows Autopilot devices to perform the offline domain join during the out-of-box experience and create the computer object in a chosen organizational unit. Without this connector, Windows cannot complete the AD DS join and therefore cannot achieve Entra hybrid join. It must be installed on a server that can reach both AD DS and the internet.

Why this answer

For Windows Autopilot in Microsoft Entra hybrid join mode, the device must join on-premises AD DS and then register with Microsoft Entra ID. The Intune Connector for Active Directory is the component that performs the offline domain join during OOBE and creates the computer object. Deployment profiles, enrollment restrictions, and automatic enrollment are supporting configurations, but none of them enables the actual domain join step.

Exam trap

The trap here is assuming that an Autopilot deployment profile configured for hybrid join is sufficient, when the domain join itself depends on the Intune Connector for Active Directory.

214
Multi-Selectmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?

Select 2 answers
A.Create a SCEP certificate profile in Intune.
B.Create a device compliance policy that includes the certificate.
C.Create a Wi-Fi profile and embed the certificate in the profile.
D.Create a VPN profile that includes the certificate.
E.Create a PKCS certificate profile in Intune.
AnswersA, E

SCEP profiles request and install certificates from a CA.

Why this answer

A SCEP certificate profile in Intune allows iOS/iPadOS devices to request a certificate from a Simple Certificate Enrollment Protocol (SCEP) server, which can then be used for Wi-Fi authentication. This method supports automated enrollment and renewal of certificates without manual intervention, making it suitable for large-scale deployments.

Exam trap

The trap here is that candidates often confuse a Wi-Fi profile's ability to reference a certificate with the ability to embed the certificate directly, leading them to select option C, but Intune requires the certificate to be deployed separately via a certificate profile.

215
MCQeasy

You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?

A.Microsoft 365 Apps for Windows
B.Web link
C.Windows app (MSI)
D.Line-of-business app
AnswerA

The Microsoft 365 Apps for Windows app type is purpose-built for deploying Office to Windows devices through Intune, delivering the Click-to-Run package with update channel and configuration control. It satisfies the 200-device Windows deployment requirement without packaging the installer manually.

Why this answer

The Microsoft 365 Apps for Windows app type in Intune is specifically designed to deploy the Microsoft 365 Apps suite (e.g., Word, Excel, Outlook) to Windows devices. It provides built-in configuration options for update channels, removal of previous Office versions, and license assignment, making it the correct choice for deploying Microsoft 365 Apps to 200 devices. Other app types lack the integrated logic to handle the suite's installation, activation, and update management.

Exam trap

The trap here is that candidates often confuse the 'Microsoft 365 Apps for Windows' app type with the 'Windows app (MSI)' or 'Line-of-business app' types, mistakenly thinking they can upload an Office installer manually, but Intune requires the dedicated app type to properly handle the Click-to-Run installation and licensing integration.

How to eliminate wrong answers

Option B is wrong because a web link app type only creates a shortcut to a URL on the device's Start menu or desktop, not an actual software installation. Option C is wrong because Windows app (MSI) is used for deploying traditional MSI-based applications, but Microsoft 365 Apps is not distributed as a single MSI file; it uses the Office Deployment Tool (ODT) and Click-to-Run technology. Option D is wrong because the line-of-business (LOB) app type is intended for sideloading app packages (e.g., .intunewin, .msi, .appx) that are not available in the public store, but it does not provide the specialized configuration options for Microsoft 365 Apps, such as channel selection or exclusion of specific apps.

216
MCQmedium

Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?

A.The device is not enrolled in Intune correctly.
B.The password policy is conflicting with Secure Boot.
C.The virtual machine does not have Secure Boot enabled in its firmware settings.
D.The device does not have BitLocker enabled, which is required for Secure Boot.
AnswerC

Secure Boot is a firmware-level UEFI feature, so a virtual machine reports non-compliant when its firmware settings have Secure Boot disabled. Enabling it in the VM's firmware configuration satisfies the compliance policy's Secure Boot requirement.

Why this answer

Secure Boot is a hardware-based feature that ensures the system boots using only software trusted by the PC manufacturer. In virtual machines, Secure Boot is often not enabled by default or may not be supported by the hypervisor. For Intune compliance, if the VM does not have Secure Boot enabled, it will report as non-compliant.

Option C is correct because the VM's firmware settings likely have Secure Boot disabled. Option A is incorrect because the device may still be enrolled correctly. Option B is incorrect because password policy is unrelated to Secure Boot.

Option D is incorrect because BitLocker is a separate encryption feature not required for Secure Boot.

217
MCQhard

Refer to the exhibit. You are deploying a custom OMA-URI policy to Windows 10 devices. What is the effect of this policy?

A.Windows Update is configured to defer updates.
B.Device telemetry is set to enhanced.
C.Windows Defender is disabled.
D.Cortana is enabled.
AnswerB

The OMA-URI targets the System/AllowTelemetry policy CSP node, setting the value that maps to Enhanced (level 2). This restricts diagnostic data collection to enhanced level rather than Full or Basic, applying directly to Windows 10 devices.

Why this answer

The OMA-URI policy configured in the exhibit sets the 'System/AllowTelemetry' value to '2', which corresponds to the 'Enhanced' telemetry level in Windows 10. This policy enables Microsoft to collect additional diagnostic data, including how Windows and apps are used, to improve the user experience and device performance. It does not affect Windows Update deferral, Defender state, or Cortana.

Exam trap

The trap here is that candidates may confuse the telemetry policy with other common MDM policies, such as Windows Update deferral or Defender settings, because the exam often tests the specific numeric values and their corresponding telemetry levels rather than the broader functionality.

How to eliminate wrong answers

Option A is wrong because deferring Windows updates is configured via the 'Update/DeferUpdatePeriod' or 'Update/DeferFeatureUpdatesPeriod' OMA-URI, not through telemetry settings. Option C is wrong because disabling Windows Defender is controlled by policies such as 'Defender/DisableRealtimeMonitoring' or 'Defender/AllowUserUIAccess', not by the telemetry level. Option D is wrong because enabling Cortana is managed by policies like 'Experience/AllowCortana' or 'System/AllowCortana', not by the telemetry URI.

218
MCQeasy

You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?

A.Update rings
B.Configuration profiles
C.Device enrollment profiles
D.Compliance policies
AnswerB

Configuration profiles deliver a standard baseline of device settings, including disk encryption and firewall rules, to targeted groups. This satisfies the stem's requirement for uniform security settings across all corporate devices, unlike compliance policies, which only assess and report state.

Why this answer

Configuration profiles in Microsoft Intune are the correct feature to deploy standard security settings such as disk encryption (e.g., BitLocker) and firewall configuration across corporate devices. These profiles define device-level policies that enforce specific configurations, including endpoint protection settings, and can be assigned to groups of devices to ensure consistent security baselines.

Exam trap

The trap here is that candidates often confuse compliance policies with configuration profiles, mistakenly thinking that compliance policies can apply settings, when in fact compliance policies only evaluate and report on settings that must already be configured by a profile or other means.

How to eliminate wrong answers

Option A (Update rings) is wrong because update rings manage the rollout and deferral of Windows updates, not the configuration of security settings like encryption or firewall rules. Option C (Device enrollment profiles) is wrong because enrollment profiles control the enrollment process and initial device setup (e.g., user affinity, enrollment restrictions), not ongoing security configurations. Option D (Compliance policies) is wrong because compliance policies define conditions that devices must meet to be considered compliant (e.g., requiring encryption), but they do not actually apply the settings; they only mark devices as non-compliant if the settings are missing, whereas configuration profiles actively enforce the settings.

219
MCQmedium

A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?

A.Verify that BitLocker is enabled on the device.
B.Check the Enrollment Status Page (ESP) profile configuration in Intune.
C.Ensure that the device has a local administrator password set.
D.Review the Windows Autopilot deployment profile assigned to the device.
AnswerB

ESP profiles can cause enrollment failures if they are not configured correctly or if they are blocked.

Why this answer

Enrollment Status Page (ESP) profiles can block enrollment if misconfigured, and checking the Intune console is the first step to see errors. Option A is wrong because BitLocker is not related to enrollment. Option C is wrong because the local admin password is not required for enrollment.

Option D is wrong because the Autopilot profile is only relevant for Autopilot deployments, not general enrollment.

220
MCQhard

Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?

A.The ESP policy is configured to track progress for Autopilot only, but the device is not using Autopilot.
B.One of the required apps failed to install.
C.The user attempted to retry the setup and it was blocked.
D.The device reset on failure is enabled, causing a reset loop.
AnswerB

The Enrollment Status Page blocks the desktop until every targeted required app installs successfully. If any required app fails, ESP retries and stalls on 'Installing apps' indefinitely, preventing provisioning completion. Blocking apps, not available apps, cause this hang.

Why this answer

The Enrollment Status Page (ESP) policy tracks the installation of required apps during Autopilot provisioning. If a required app fails to install, the ESP will hang on 'Installing apps' indefinitely because it waits for all required apps to succeed before proceeding. This is the most common cause of a stuck ESP at the app phase.

Exam trap

The trap here is that candidates often assume the ESP hangs due to a network issue or user error, but Microsoft explicitly designs the ESP to block on required app failures, making this the primary troubleshooting focus for 'Installing apps' hangs.

How to eliminate wrong answers

Option A is wrong because the ESP policy is explicitly assigned to an Autopilot deployment, and the device is using Autopilot (the user is in provisioning). Option C is wrong because the ESP does not block retry attempts; the user can retry, but if the app continues to fail, the hang persists. Option D is wrong because 'device reset on failure' is a separate setting that triggers a full reset only after a timeout or explicit failure, not a reset loop; the device would not hang indefinitely.

221
MCQeasy

You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?

A.Intune device cleanup rules
B.Conditional access policy
C.Device compliance policy
D.Device configuration profile
AnswerA

Intune device cleanup rules automatically retire or delete devices that have not checked in for a specified number of days. Configuring the inactivity threshold to 30 days in this policy satisfies the stem's automatic retirement requirement.

Why this answer

Intune device cleanup rules allow you to automatically retire devices that have not checked in for a specified number of days. This setting is configured under Tenant Administration > Device Cleanup Rules.

Exam trap

MD-102 often tests the confusion between device compliance (which evaluates health) and device cleanup (which retires inactive devices), leading candidates to choose compliance policies.

How to eliminate wrong answers

Option B is wrong because conditional access policies control access to resources based on conditions, not device retirement. Option C is wrong because compliance policies evaluate device health and can mark devices non-compliant, but do not retire them. Option D is wrong because configuration profiles apply settings to devices, not lifecycle actions.

222
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. You need to ensure that all Windows 10 devices are automatically enrolled in Intune when they are joined to Microsoft Entra ID. What should you configure?

A.Create a device configuration profile with the "Enroll in Intune" setting enabled.
B.In the Microsoft Intune admin center, enable automatic enrollment for Windows devices.
C.Configure a conditional access policy to require compliant devices.
D.Assign an Intune license to each user and instruct them to manually enroll their devices.
AnswerB

Automatic enrollment in Intune is configured in the Microsoft Intune admin center under Devices > Enroll devices > Automatic Enrollment. Enabling the MDM user scope for Windows allows devices to automatically enroll when they join Microsoft Entra ID. This is the correct setting to ensure automatic enrollment without user intervention. It requires appropriate licensing and permissions, but it directly addresses the requirement.

Why this answer

Automatic enrollment in Intune for Windows devices is enabled through the Microsoft Intune admin center by configuring the MDM user scope. This setting ensures that when a device joins Microsoft Entra ID, it automatically enrolls in Intune without user action. Other options either describe non-existent settings or do not provide automatic enrollment.

Exam trap

The trap here is confusing automatic enrollment with conditional access or device configuration profiles, which serve different purposes and do not initiate enrollment.

223
MCQeasy

Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?

A.Azure AD Premium P1 license is required.
B.Microsoft Intune must be enabled for auto-enrollment.
C.Microsoft Defender for Endpoint must be deployed.
D.Microsoft Entra Connect must be installed and configured.
AnswerD

Microsoft Entra hybrid join requires the device's computer account to exist in both on-premises Active Directory and Microsoft Entra ID. Microsoft Entra Connect synchronises those objects, so it must be installed and configured before hybrid join can succeed.

Why this answer

Microsoft Entra hybrid joined devices require synchronization of on-premises Active Directory identities to Microsoft Entra ID. Microsoft Entra Connect (or Microsoft Entra Connect Sync) is the tool that performs this identity synchronization, making it a mandatory prerequisite. Without it, the on-premises AD objects cannot be linked to Entra ID for hybrid join.

Exam trap

The trap here is that candidates often confuse licensing requirements (Premium P1) or optional management tools (Intune, Defender) with the core prerequisite of identity synchronization, which is the foundational step for hybrid join.

How to eliminate wrong answers

Option A is wrong because Azure AD Premium P1 is not a prerequisite for hybrid join; it is required for features like Conditional Access or self-service password reset, but hybrid join itself works with any Azure AD license, including Free. Option B is wrong because Microsoft Intune auto-enrollment is optional for managing hybrid joined devices but not a prerequisite for the join process itself. Option C is wrong because Microsoft Defender for Endpoint is a security solution that can be deployed on hybrid joined devices but is not required for the hybrid join configuration.

224
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices are compliant with a new security policy that requires Windows Defender Antivirus to be enabled and up-to-date. You create a device compliance policy with the setting 'Require' for Windows Defender Antivirus. After assigning the policy, you see that 90% of devices are compliant. The remaining 10% show 'Not evaluated'. You check the devices and find that they are online, enrolled, and have Windows Defender Antivirus enabled. What is the most likely reason for the 'Not evaluated' status?

A.The devices have not checked in with Intune since the policy was assigned
B.The devices are offline
C.The policy is not assigned to the devices
D.Windows Defender Antivirus is disabled
AnswerA

Compliance status is calculated when a device checks in and evaluates the assigned policy. Devices that have not synced since assignment remain 'Not evaluated' despite being online and enrolled, so a manual or scheduled Intune sync triggers evaluation and resolves the status.

Why this answer

A 'Not evaluated' compliance status in Intune means the device has not yet processed the assigned compliance policy — typically because it has not performed a device check-in (MDM sync) since the policy was assigned. Even though the device is online and enrolled, compliance evaluation only occurs during a scheduled or triggered check-in cycle, which can take up to 8 hours by default. Forcing a sync from the Company Portal or Intune console resolves this.

Exam trap

MD-102 often tests the distinction between 'Not evaluated' (policy not yet processed) and 'Not compliant' (policy processed and failed), tricking candidates into troubleshooting device configuration when the real issue is simply check-in timing.

How to eliminate wrong answers

Option B is wrong because the question explicitly states the devices are online, so offline status cannot explain the 'Not evaluated' state. Option C is wrong because if the policy were unassigned, the devices would show 'Not applicable' rather than 'Not evaluated', and the question implies the policy was assigned. Option D is wrong because the question confirms Windows Defender Antivirus is enabled on the devices, so the underlying setting is satisfied — the issue is evaluation timing, not configuration.

225
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?

A.Create a compliance policy and assign it to a group containing the department's users.
B.Create a compliance policy and assign it to a group containing the department's devices.
C.Create a compliance policy and assign it to all devices, then exclude the department's devices.
D.Create a device configuration profile and assign it to the department's devices.
AnswerB

Compliance policies in Intune are assigned to groups, and assigning to a group that contains the department's devices scopes the policy to only those devices. This satisfies the requirement to apply settings to a specific department without affecting others. Device-based group targeting is the standard approach for scoping compliance policies to a subset of managed devices.

Why this answer

Compliance policies are assigned to groups, and to affect only a specific department's devices, the policy should be assigned to a device group that contains those devices. Assigning to all devices with exclusions, using a configuration profile, or targeting users would either invert the scope, fail to produce a compliance signal, or inadvertently include devices outside the department. Device group targeting is the precise and standard method.

Exam trap

The trap here is choosing user group targeting for a compliance policy, which can unintentionally apply to every device a user signs in to rather than only the department's corporate devices.

Page 2

Page 3 of 8

Page 4

All pages