Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 151225

942 questions total · 13pages · All types, answers revealed

Page 2

Page 3 of 13

Page 4
151
MCQeasy

You have the above compliance policy for Windows 10. A device running Windows 10 version 22H2 (build 22621.1) will be marked as?

A.Noncompliant because the OS version exceeds the maximum
B.Noncompliant because the password minimum length is not met
C.Noncompliant because the OS version is below the minimum
D.Compliant
AnswerA

The build is higher than the max allowed.

Why this answer

The compliance policy sets a maximum OS version of 22H2 (build 22621.1). The device is running exactly that version, which meets the maximum threshold. However, in Intune compliance policies, the 'Maximum OS version' rule marks a device as noncompliant if the OS version is greater than the specified version.

Since the device's version equals the maximum, it is not greater, so it should be compliant. But the question states the device is running version 22H2 (build 22621.1), which is the exact maximum, and the correct answer is marked as noncompliant because the OS version exceeds the maximum. This is a trick: the build number 22621.1 is actually for Windows 11, not Windows 10 22H2, so the device is running a higher OS version than allowed, making it noncompliant.

Exam trap

The trap here is that candidates assume the version string '22H2' alone determines compliance, but Microsoft uses build numbers to differentiate between Windows 10 and Windows 11, so a build of 22621 indicates Windows 11, which exceeds the maximum OS version policy for Windows 10.

How to eliminate wrong answers

Option B is wrong because the compliance policy does not include a password minimum length requirement; the policy only specifies OS version rules, so password length is irrelevant. Option C is wrong because the device's OS version (22H2 build 22621.1) is not below the minimum; the minimum is set to 21H2 (build 19044.1), and the device's version is higher. Option D is wrong because the device is noncompliant due to the OS version exceeding the maximum, as the build number 22621.1 corresponds to Windows 11, which is a higher version than Windows 10 22H2.

152
MCQmedium

You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?

A.Confirm that the user is assigned a Microsoft Entra ID P1 license.
B.Verify that the BitLocker recovery key is backed up to Microsoft Entra ID.
C.Ensure the Windows Defender Firewall allows inbound RPC traffic.
D.Check that the MDM enrollment URL (https://enrollment.manage.microsoft.com) is reachable and not blocked by a proxy.
AnswerD

The enrollment URL must be reachable for successful MDM enrollment.

Why this answer

The most common cause of MDM enrollment failure after a Windows update is a change in proxy or firewall settings that blocks the MDM enrollment URL. Since the devices can reach the internet generally but fail specifically during enrollment, verifying that `https://enrollment.manage.microsoft.com` is reachable and not blocked by a proxy is the logical first troubleshooting step. This URL is required for the device to communicate with the Intune MDM service during the enrollment process.

Exam trap

The trap here is that candidates often assume a general internet connection means all services are reachable, but MDM enrollment requires specific URLs that may be blocked by a proxy or firewall even when general browsing works.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P1 licenses are required for features like Conditional Access, but not for basic MDM enrollment; a user needs an Intune license (e.g., Microsoft 365 E3/E5 or standalone Intune) to enroll. Option B is wrong because BitLocker recovery key backup to Microsoft Entra ID is a post-enrollment compliance or recovery feature, not a prerequisite for MDM enrollment. Option C is wrong because inbound RPC traffic is not required for MDM enrollment; the device initiates outbound HTTPS (TCP 443) connections to Intune, and inbound RPC is irrelevant to this process.

153
MCQmedium

You need to deploy a custom Win32 app to Windows 10 devices. The app installation is silent and requires a reboot. You set the installation behavior to 'system' and the device restart behavior to 'Allow'. After deployment, users report that the app is installed but not working properly. What is the most likely cause?

A.The app requires user interaction to complete setup
B.The detection rule is misconfigured
C.The device was not restarted after installation
D.The app was not wrapped correctly with the Intune Win32 Content Prep Tool
AnswerC

A pending restart can cause apps to malfunction.

Why this answer

When the device restart behavior is set to 'Allow', Intune will request a reboot but does not force it; the user can postpone or ignore the prompt. If the app requires a reboot to complete its installation or initialize properly, skipping the restart leaves the app in a partially installed state, causing it to appear installed but malfunction. This is the most likely reason the app is not working correctly after deployment.

Exam trap

The trap here is that candidates assume 'Allow' means the device will always restart automatically, but Intune's 'Allow' setting only requests a restart and does not enforce it, leaving the user in control and potentially causing incomplete installations.

How to eliminate wrong answers

Option A is wrong because the installation behavior is set to 'system' and the app installation is described as silent, meaning it does not require user interaction to complete setup. Option B is wrong because a misconfigured detection rule would cause Intune to report the app as not installed or repeatedly attempt reinstallation, not result in the app being installed but not working properly. Option D is wrong because if the app were not wrapped correctly with the Intune Win32 Content Prep Tool, the deployment would typically fail entirely or the app would not install at all, rather than installing and then malfunctioning.

154
MCQmedium

You manage Android Enterprise devices with work profiles. A user reports that corporate apps are not appearing in the work profile after enrollment. The device shows as enrolled in Microsoft Intune. What is the most likely cause?

A.The device is not connected to the internet.
B.The device is not compliant with corporate policies.
C.The work profile was not created or was removed on the device.
D.The corporate apps are not assigned to the user.
AnswerC

Without a work profile, corporate apps have no container to install into.

Why this answer

If the work profile is not set up correctly on the device, corporate apps won't appear. Option A is wrong because if apps were assigned, they should deploy; the issue is with the profile. Option B is wrong because assignment not applied would affect all devices, not just one.

Option D is wrong because compliance policies don't affect app visibility.

155
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a Microsoft Copilot app that requires users to sign in with their work account. The app must be automatically installed without user interaction. What should you do?

A.Configure a web clip that links to the app in the App Store.
B.Create an Intune App Protection Policy for the app.
C.Add the app as a line-of-business app and deploy via Company Portal.
D.Purchase the app through Apple Business Manager and assign it as a required app in Intune.
AnswerD

VPP allows silent install on supervised devices.

Why this answer

When you purchase an app through Apple Business Manager (formerly Volume Purchase Program), you can assign it as a required app in Intune. If the iOS/iPadOS device is supervised, the app is installed silently without user interaction. Option A is incorrect because a web clip only creates a shortcut on the home screen and does not install the app.

Option B is incorrect because an App Protection Policy controls how data is used within an app, but it does not handle installation. Option C is incorrect because while a line-of-business app can be deployed via Company Portal, the user must manually initiate the installation from the Company Portal app.

156
MCQmedium

A company plans to deploy Windows 11 to 500 devices using Microsoft Deployment Toolkit (MDT). The deployment must support UEFI-based devices with Secure Boot enabled. During a pilot deployment, several devices fail to boot after deployment. You suspect the issue is related to the boot image configuration. Which boot image setting should you verify?

A.Ensure the boot image is set to x64 BIOS
B.Ensure the boot image is set to x86 BIOS
C.Ensure the boot image includes the WinPE optional component for Secure Boot
D.Ensure the boot image is set to x64 UEFI
AnswerD

x64 UEFI is required for UEFI and Secure Boot.

Why this answer

UEFI-based devices with Secure Boot require a 64-bit boot image because UEFI firmware does not support legacy BIOS boot modes. Selecting an x64 UEFI boot image ensures the deployment environment is compatible with Secure Boot and GPT disk partitioning, which are mandatory for Windows 11 on UEFI systems. An incorrect boot image type (e.g., BIOS-based) will cause boot failures on UEFI-only hardware.

Exam trap

The trap here is that candidates confuse the need for a Secure Boot-specific WinPE component (Option C) with the actual requirement of selecting the correct boot image architecture and firmware type (x64 UEFI), leading them to overlook that Secure Boot support is inherent to the UEFI boot image, not an add-on component.

How to eliminate wrong answers

Option A is wrong because an x64 BIOS boot image is designed for legacy BIOS firmware, not UEFI, and will fail to boot on UEFI-only devices with Secure Boot enabled. Option B is wrong because an x86 BIOS boot image is both the wrong architecture (32-bit) and the wrong firmware type (BIOS), making it incompatible with 64-bit UEFI hardware and Secure Boot requirements. Option C is wrong because Secure Boot support in WinPE is built into the x64 UEFI boot image itself; there is no separate 'WinPE optional component for Secure Boot' — the component is automatically included when you generate an x64 UEFI boot image in MDT.

157
MCQhard

You are troubleshooting a Windows 10 device that is showing as non-compliant in Intune. The exhibit shows the PowerShell output from the Microsoft Graph API. Based on the output, what is the most likely reason for the non-compliance?

A.The device does not have a compliant operating system version
B.BitLocker drive encryption is not enabled on the device
C.The device is not running a supported version of Windows 10
D.The device has a third-party antivirus installed
AnswerB

The 'RequireEncryption' reason indicates BitLocker is missing.

Why this answer

The output shows the non-compliance reason is 'RequireEncryption', indicating BitLocker is not enabled. Option A is incorrect because the reason is about encryption, not operating system version. Option C is incorrect because the reason is about encryption, not the Windows version.

Option D is incorrect because the reason is about encryption, not antivirus.

158
Multi-Selecteasy

Which TWO of the following are valid methods to wipe a Windows 10 device using Microsoft Intune? (Select TWO.)

Select 2 answers
A.Factory reset from Windows Settings
B.Retire (selective wipe)
C.Remote lock
D.Delete device from Intune
E.Full wipe (remote wipe)
AnswersB, E

Retire removes corporate data from the device.

Why this answer

A Retire (selective wipe) in Microsoft Intune removes managed corporate data and policies from a Windows 10 device while preserving the user's personal data. This is achieved by unenrolling the device from Intune and removing company-managed apps, certificates, and profiles, leaving the device in a usable state for the user. Option E is also correct: a Full wipe (remote wipe) restores the device to its factory default settings, erasing all data including personal files and applications.

This is used when the device is lost or stolen, or when it needs to be completely reset.

Exam trap

The trap here is that candidates confuse 'Delete device from Intune' with a wipe action, not realizing that deletion only removes the device record from the console without sending any wipe command to the device.

159
MCQhard

Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?

A.The devices have an OS version lower than 10.0.19041.
B.The install command line is missing the /silent switch.
C.The detection rule path is incorrect.
D.The install experience is set to system, but should be user.
AnswerA

The requirement rule sets a minimum OS version of 10.0.19041.

Why this answer

The exhibit shows the 'Minimum OS version' requirement set to 10.0.19041 (Windows 10 version 20H1/2004). Devices with an OS build lower than this threshold will fail to install the Win32 app, as Intune enforces this requirement before executing the installation command. This is a common configuration issue when deploying apps to a mixed-OS environment.

Exam trap

The trap here is that candidates often focus on the install command or detection rules as the cause of installation failure, overlooking the explicit OS version requirement that prevents installation from even starting on incompatible devices.

How to eliminate wrong answers

Option B is wrong because the install command line is not missing the /silent switch; the exhibit shows the command includes '--silent' (or a similar silent flag), so the absence of /silent is not the issue. Option C is wrong because the detection rule path being incorrect would cause the app to appear as 'Not Installed' on devices where it actually installed, not prevent installation from starting. Option D is wrong because the install experience set to 'system' is correct for system-wide installations; setting it to 'user' would install per-user and could cause issues, but the exhibit shows 'system' is selected, so this is not the problem.

160
MCQeasy

You need to deploy a Microsoft Store app (e.g., Microsoft Whiteboard) to Windows 10 devices managed by Intune. Which app type should you use?

A.Microsoft Store app (Windows)
B.Windows app (Win32)
C.Web link
D.Microsoft Store for Business (offline licensed)
AnswerA

Directly supports store apps.

Why this answer

To deploy a Microsoft Store app like Microsoft Whiteboard to Windows 10 devices managed by Intune, you must use the 'Microsoft Store app (Windows)' app type. This type directly integrates with the Microsoft Store catalog, allowing you to select and deploy store apps without needing offline licensing or manual packaging. It supports both online and offline licensing models, but for a standard store app deployment, this is the correct and simplest choice.

Exam trap

The trap here is that candidates often confuse 'Microsoft Store app (Windows)' with 'Microsoft Store for Business (offline licensed)', thinking offline licensing is always required for managed deployments, but the standard store app type works for online scenarios and is the default choice for deploying store apps like Whiteboard.

How to eliminate wrong answers

Option B is wrong because 'Windows app (Win32)' is used for deploying traditional desktop applications (e.g., .exe, .msi) that require custom installation scripts or detection rules, not for Microsoft Store apps. Option C is wrong because 'Web link' simply creates a shortcut to a URL in the Company Portal and does not install any application. Option D is wrong because 'Microsoft Store for Business (offline licensed)' is a specific licensing model for offline deployment of store apps, but the question does not specify an offline requirement; the standard 'Microsoft Store app (Windows)' type can handle both online and offline scenarios, and is the general-purpose type for store apps.

161
MCQeasy

Refer to the exhibit. You configure an Enrollment Status Page (ESP) policy as shown. During Windows Autopilot deployment, a device fails to install one of the required apps. What happens to the device?

A.The device blocks use and the user cannot proceed
B.The device automatically resets and retries
C.The user can skip the installation and use the device
D.The user can retry the installation
AnswerA

The device blocks use because allowDeviceUseOnInstallFailure is false.

Why this answer

The Enrollment Status Page (ESP) policy is configured with the 'Show error when installation takes longer than specified number of minutes' option set to 'Block device use until all required apps and profiles are installed.' When a required app fails to install, the ESP enters an error state and, because the policy is set to block use, the device remains locked at the ESP screen, preventing the user from proceeding to the desktop. This behavior is enforced by the Autopilot client, which monitors the installation status of required apps and profiles and will not allow the user to bypass the ESP until all required items are successfully installed or the timeout is reached.

Exam trap

The trap here is that candidates often assume the user can simply skip or retry the failed installation and continue, but the 'Block device use' setting explicitly prevents any progression until all required apps are installed, making the device effectively unusable until the issue is resolved.

How to eliminate wrong answers

Option B is wrong because the ESP does not automatically reset and retry the device; it only retries the installation of failed apps within the same session, but if the app continues to fail, the device remains blocked. Option C is wrong because the 'Block device use until all required apps and profiles are installed' setting explicitly prevents the user from skipping the installation; the user cannot proceed until the required apps are installed or the timeout expires. Option D is wrong because while the user can manually retry the installation from the ESP error screen, the question states the device 'fails to install' and the policy blocks use, meaning the user cannot simply retry and proceed—they are stuck at the ESP until the app installs successfully or the timeout triggers a different action.

162
Multi-Selectmedium

Which THREE are valid Windows Autopilot deployment scenarios?

Select 3 answers
A.Self-deploying
B.App-driven
C.User-driven
D.Policy-driven
E.White glove
AnswersA, C, E

Self-deploying is for shared devices.

Why this answer

Windows Autopilot self-deploying is a valid deployment scenario where a device can be automatically configured without user interaction, using a hardware hash to enroll in Azure AD and Intune. This scenario is ideal for kiosks, digital signage, or shared devices that require zero-touch provisioning.

Exam trap

The trap here is that candidates confuse deployment phases or management concepts (like app or policy deployment) with the three official Autopilot deployment scenarios, which are strictly self-deploying, user-driven, and white glove (pre-provisioning).

163
Multi-Selecteasy

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)

Select 2 answers
A.Reset a user's password.
B.View hardware inventory of a device.
C.Remotely sync a device with Intune.
D.Manage on-premises Active Directory objects.
E.Assign Microsoft 365 licenses to a user.
AnswersB, C

Inventory is visible in the device properties.

Why this answer

The Microsoft Intune admin center provides a hardware inventory view for managed Windows devices, displaying details such as processor, RAM, disk space, and firmware version. This data is collected via the Intune Management Extension and device inventory reports, enabling administrators to assess device compliance and readiness without requiring on-premises tools.

Exam trap

The trap here is that candidates confuse user management tasks (password reset, license assignment) with device management actions, or assume Intune can manage on-premises AD objects, when Intune's scope is strictly cloud-based device and app management via MDM and MAM.

164
Multi-Selecthard

You are troubleshooting an Intune deployment of a line-of-business (LOB) app for iOS. The app fails to install on some devices with error '0x87D13B9F'. Which THREE actions should you take to diagnose the issue?

Select 3 answers
A.Check the Intune Service Health dashboard for service incidents
B.Check if the device is supervised and that the app requires supervised mode
C.Ensure that an app configuration policy is assigned to the device
D.Verify that the app's provisioning profile has not expired
E.Confirm that the device has sufficient storage space available
AnswersB, D, E

Some LOB apps require supervised devices.

Why this answer

Error 0x87D13B9F in Intune for iOS LOB apps typically indicates a deployment restriction related to device supervision. If the app requires supervised mode (e.g., for managed app configuration or advanced MDM controls) and the target device is not supervised, Intune will fail to install the app with this error. Verifying supervision status is a primary diagnostic step.

Exam trap

The trap here is that candidates often confuse a device-level installation error with a service health or policy assignment issue, overlooking the specific requirement for supervised mode that is common for iOS LOB apps in enterprise deployments.

165
MCQeasy

Your company uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft Store app (new) named 'Company Portal' to all devices. The app is already added to Intune. You assign the app to a static device group that includes all current devices with the intent 'Required'. However, you notice that devices that enroll after the assignment do not receive the app automatically. What should you do to ensure that the app installs on newly enrolled devices?

A.Create a new assignment with 'Available' intent for the 'All devices' group
B.Ensure the device group is a dynamic group that includes all devices (e.g., use the built-in 'All devices' group)
C.Re-add the app to Intune
D.Change the assignment intent to 'Available'
AnswerB

Dynamic groups automatically include new devices.

Why this answer

Static groups in Intune do not automatically include devices that are enrolled after the group is created. To ensure the app installs on newly enrolled devices, the device group must be dynamic. Dynamic groups automatically include devices based on rules, such as all devices.

The built-in 'All devices' group is dynamic, but if you are using a custom static group, you should change it to a dynamic group or assign the app to a dynamic group like 'All devices'.

166
Multi-Selectmedium

Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?

Select 2 answers
A.Maximum OS version
B.Require antivirus (Windows Defender)
C.Minimum OS version
D.Device type
E.Storage encryption
AnswersB, C

Requires Windows Defender to be active.

Why this answer

The correct settings are 'Require antivirus (Windows Defender)' and 'Minimum OS version'. These are standard compliance policy settings for Windows devices in Microsoft Intune. 'Maximum OS version' is not typically used for compliance; instead, a minimum version ensures devices are up-to-date. 'Device type' is not a compliance setting. 'Storage encryption' is a compliance setting (Require BitLocker), but it is not required by the scenario's specific criteria.

167
MCQhard

Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?

A.The device will be allowed to proceed because enrollment status is notStarted.
B.The device will retry enrollment automatically.
C.The device will be blocked from completing OOBE.
D.The device will be blocked until retry due to pendingRetry setting.
AnswerC

Failure action is set to block.

Why this answer

The Autopilot deployment profile shown has the Enrollment Status Page (ESP) configured with 'Block device use until all required apps and profiles are installed' enabled. When a required app fails to install during OOBE, the ESP enforces a hard block, preventing the user from proceeding past the ESP until the failure is resolved. This is why the device is blocked from completing OOBE, making option C correct.

Exam trap

The trap here is that candidates confuse the ESP's 'block device use' setting with a simple retry mechanism, assuming the device will automatically retry or proceed, when in fact a hard block is enforced until the failure is resolved.

How to eliminate wrong answers

Option A is wrong because the enrollment status is not 'notStarted'; the ESP tracks installation progress, and a failure triggers a blocking state, not a pass-through. Option B is wrong because the ESP does not automatically retry enrollment; it blocks the device and requires manual intervention (e.g., reset or troubleshooting) unless a retry timeout is configured, which is not shown in the exhibit. Option D is wrong because 'pendingRetry' is not a valid ESP state; the ESP uses states like 'installing', 'failed', or 'timeout', and the device is blocked immediately upon failure, not placed into a pending retry state.

168
MCQeasy

You need to manage updates for Windows 10 devices using Microsoft Intune. You want to ensure that critical security updates are installed within 7 days of release, while feature updates are deferred for 60 days. Which approach should you use?

A.Create a Windows update ring policy with quality update deferral set to 7 days and feature update deferral set to 60 days.
B.Create a Windows feature update profile to deploy the latest feature update after 60 days.
C.Create a device compliance policy requiring devices to install updates within 7 days.
D.Configure Windows Update for Business settings via a configuration profile.
AnswerA

Update rings allow granular deferral settings for quality and feature updates.

Why this answer

Windows update ring policies in Microsoft Intune allow granular control over both quality (security) and feature update deferral periods. Setting quality update deferral to 7 days ensures critical security patches are installed within a week, while feature update deferral of 60 days delays non-security feature updates. This directly meets the requirement without additional profiles or compliance policies.

Exam trap

The trap here is that candidates often confuse update ring policies (which manage deferral periods) with feature update profiles (which target specific versions) or compliance policies (which only report compliance status), leading them to select B or C instead of the correct ring-based approach.

How to eliminate wrong answers

Option B is wrong because a Windows feature update profile is used to deploy a specific feature update version (e.g., Windows 10 22H2) to devices, not to manage deferral periods for ongoing updates; it does not control quality update timing. Option C is wrong because device compliance policies can require a minimum OS version or patch level but cannot enforce specific deferral periods for quality or feature updates; they are for compliance evaluation, not update scheduling. Option D is wrong because configuring Windows Update for Business settings via a configuration profile is a legacy approach that lacks the unified deferral management available in update ring policies; update rings are the modern, recommended method in Intune for controlling update deferrals.

169
MCQhard

Your organization uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR) to manage device threat detection. You have integrated Defender for Endpoint with Intune for compliance. Some devices are showing as non-compliant due to 'active threats' that are actually low-risk. How can you adjust the compliance policy to allow low-risk threats?

A.Modify the Conditional Access policy to require device compliance.
B.Configure the 'Machine risk score' in Defender for Endpoint.
C.Whitelist the specific threats in Defender for Endpoint.
D.Set the 'Threat level' in the Intune compliance policy to 'Low'.
AnswerD

This allows devices with low-risk threats to be compliant.

Why this answer

The Intune compliance policy includes a 'Threat level' setting that determines the minimum threat severity required for a device to be considered compliant. By setting this value to 'Low', devices with only low-risk threats will be marked as compliant, allowing them to pass the policy check. This directly addresses the scenario where low-risk threats are incorrectly causing non-compliance.

Exam trap

The trap here is that candidates often confuse the compliance policy's threat level threshold with the Defender for Endpoint risk score or alert suppression, leading them to incorrectly choose whitelisting or risk score configuration instead of the straightforward compliance policy setting.

How to eliminate wrong answers

Option A is wrong because modifying the Conditional Access policy to require device compliance does not change the compliance evaluation itself; it only enforces the existing compliance status, so it would not resolve the issue of low-risk threats causing non-compliance. Option B is wrong because the 'Machine risk score' in Defender for Endpoint is an aggregated risk assessment that cannot be manually adjusted to ignore low-risk threats; it reflects the actual threat posture and is not a configurable threshold for compliance. Option C is wrong because whitelisting specific threats in Defender for Endpoint would suppress alerts for those threats entirely, which is an overbroad security risk and does not align with the compliance policy's threat level filtering; the correct approach is to adjust the compliance policy threshold, not to hide threats.

170
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to enroll a personally owned device with a work profile. Which enrollment method should the user use?

A.Android Enterprise fully managed enrollment.
B.Android Enterprise personally owned work profile enrollment.
C.Android Enterprise corporate-owned work profile enrollment.
D.Corporate-owned dedicated device enrollment.
AnswerB

This creates a work profile on a personal device.

Why this answer

Android Enterprise personally owned devices with a work profile use the 'Bring your own device' (BYOD) enrollment method. Option A is wrong because corporate-owned dedicated devices use a different method. Option C is wrong because fully managed devices are corporate-owned.

Option D is wrong because corporate-owned work profile is for corporate devices with work profile.

171
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 devices. You deploy a PowerShell script via Intune management extension to install a legacy application. The script runs successfully on most devices, but fails on devices that have the 'LocalSystem' account disabled. What should you do to resolve the issue?

A.Configure the script to run in the user context by modifying the script settings in Intune
B.Change the script to run as the logged-on user using a scheduled task
C.Deploy the script using Microsoft Configuration Manager instead
D.Re-enable the LocalSystem account on the affected devices
AnswerA

Intune allows scripts to run in user context, which may resolve the issue.

Why this answer

The Intune Management Extension runs PowerShell scripts under the LocalSystem account by default. When this account is disabled, the script cannot execute. Configuring the script to run in the user context (option A) bypasses this dependency by executing the script under the logged-on user's security context, which is still active even if LocalSystem is disabled.

Exam trap

The trap here is that candidates assume the LocalSystem account is always available and try to re-enable it (option D) or switch to a different deployment tool (option C), rather than recognizing that Intune's user context execution setting directly solves the problem without compromising security.

How to eliminate wrong answers

Option B is wrong because creating a scheduled task to run as the logged-on user is an unsupported workaround that adds complexity and does not leverage Intune's native script execution settings; Intune already supports running scripts in user context directly. Option C is wrong because deploying via Configuration Manager does not resolve the root cause—it still requires a system context or a different execution method, and it introduces additional infrastructure and licensing requirements. Option D is wrong because re-enabling the LocalSystem account is a security risk and an unnecessary change; the account is often disabled for security hardening, and the correct solution is to adapt the script execution context rather than altering system accounts.

172
Multi-Selecthard

A company uses Microsoft Intune to manage devices. They have a Windows 10 device that is non-compliant due to missing required updates. The administrator reviews the device and sees the update status shows 'Pending restart'. Which THREE actions should the administrator take to resolve the compliance issue?

Select 3 answers
A.Check the Update Rings policy for deferral settings.
B.Sync the device with Intune.
C.Restart the device.
D.Wait for the automatic restart from the compliance policy.
E.Re-enroll the device in Intune.
AnswersA, B, C

Deferrals may delay update installation.

Why this answer

Update Rings policy deferral settings can delay the installation of required updates, causing the device to show a 'Pending restart' status without actually applying the updates. By checking and adjusting these deferral settings, the administrator can ensure updates are installed promptly, resolving the non-compliance issue.

Exam trap

The trap here is that candidates may assume waiting for an automatic restart (Option D) is sufficient, but Intune compliance policies do not enforce restarts; the administrator must take proactive steps like syncing and restarting to resolve the pending restart state.

173
MCQhard

Your company has a Microsoft 365 E5 subscription. You are planning to deploy Windows 11 using Microsoft Intune. You need to ensure that devices automatically receive English (US) language pack and regional settings during the provisioning process. You plan to use a provisioning package (PPKG) created with Windows Configuration Designer. What should you include in the PPKG?

A.Add a PowerShell script that runs during Autopilot to set language and region.
B.Include the 'Language' and 'RegionalSettings' settings in the PPKG.
C.Assign an Intune Language Pack policy to the device group.
D.Create a Group Policy Object that sets language and region, and link it to the device OU.
AnswerB

Windows Configuration Designer allows embedding language and regional settings directly.

Why this answer

Windows Configuration Designer (WCD) directly supports configuring language and regional settings within a provisioning package (PPKG) through built-in settings. Including the 'Language' and 'RegionalSettings' settings in the PPKG ensures these configurations are applied during the out-of-box experience (OOBE) or provisioning process, without requiring additional scripts or policies. This is the most efficient and supported method for offline or Autopilot pre-provisioning scenarios.

Exam trap

The trap here is that candidates often assume a PowerShell script or Intune policy is required for language configuration, overlooking that Windows Configuration Designer provides native, first-class settings for language and region within a PPKG.

How to eliminate wrong answers

Option A is wrong because adding a PowerShell script that runs during Autopilot to set language and region is unnecessary and less reliable; the PPKG can natively set these settings without scripting, and Autopilot does not guarantee script execution before user logon for language pack installation. Option C is wrong because Intune Language Pack policies are designed for deploying language packs to already-provisioned devices, not for setting regional settings during the initial provisioning process via a PPKG. Option D is wrong because Group Policy Objects (GPOs) require domain-joined devices and Active Directory, which are not applicable during the provisioning phase of a PPKG-based deployment, and GPOs cannot be applied during OOBE.

174
Multi-Selectmedium

You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)

Select 2 answers
A.Android store app type.
B.Windows Installer (Win32) app type using the Office Deployment Tool.
C.Web link app type pointing to the Office website.
D.iOS store app type.
E.Microsoft 365 Apps for Windows app type in Intune.
AnswersB, E

Win32 apps can deploy Office via the Office Deployment Tool.

Why this answer

The Windows Installer (Win32) app type in Intune allows you to deploy Microsoft 365 Apps using the Office Deployment Tool (ODT), which provides granular control over installation settings, languages, and update channels. Option E is correct because Intune includes a dedicated 'Microsoft 365 Apps for Windows' app type that simplifies deployment by automatically configuring the ODT XML and handling the installation process without manual scripting.

Exam trap

The trap here is that candidates often confuse the 'Web link' app type with a valid deployment method, thinking it will trigger an installation, when in fact it only provides a browser shortcut to the Office website without any local installation.

175
MCQhard

You manage Windows 10 devices with Microsoft Intune. You need to deploy a PowerShell script that runs every time a device boots, before the user logs on. The script is signed. What is the correct deployment approach?

A.Use a proactive remediation script set to run at device startup.
B.Package the script as a Win32 app and deploy it with installation behavior set to 'System'.
C.Deploy the script as a PowerShell script in Intune, configured to run in system context at device startup.
D.Add the script as a device configuration profile (OMA-URI).
AnswerC

This allows the script to run before user logon in system context.

Why this answer

Intune's PowerShell script deployment supports running scripts in the system context at device startup, which executes before user logon. This meets the requirement for a signed script that runs every boot, leveraging the 'Run this script using the logged on credentials' option unchecked and 'Run script in 64-bit PowerShell Host' as needed.

Exam trap

The trap here is that candidates confuse 'run at device startup' with 'run during app installation' (Option B) or assume proactive remediations (Option A) can be triggered at boot, when in fact only the PowerShell script deployment in Intune supports the exact 'device startup' trigger in system context.

How to eliminate wrong answers

Option A is wrong because proactive remediations are designed for detecting and fixing common issues on existing devices, not for running arbitrary scripts at every boot before logon; they run on a schedule or on demand, not at startup. Option B is wrong because packaging a script as a Win32 app with installation behavior set to 'System' runs the script once during app installation, not every time the device boots. Option D is wrong because device configuration profiles (OMA-URI) are used for configuring device settings via CSPs, not for executing PowerShell scripts.

176
MCQeasy

You manage devices with Microsoft Intune. You need to deploy a Windows 10 feature update to a pilot group of devices. Which profile type should you use?

A.Windows 10 configuration profile
B.Windows 10 compliance policy
C.Windows 10 update ring profile
D.Windows 10 feature update profile
AnswerD

This profile type is designed for deploying feature updates like version upgrades.

Why this answer

A Windows 10 feature update profile is the correct choice because it is specifically designed to deploy feature updates (e.g., Windows 10 version 22H2) to targeted groups in Intune. Unlike update rings, which control the timing and deferral of updates, a feature update profile pins devices to a specific Windows version and orchestrates the upgrade process for pilot or broad deployments.

Exam trap

The trap here is that candidates often confuse update ring profiles (which manage update timing) with feature update profiles (which deploy a specific version), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because a Windows 10 configuration profile is used to configure device settings (e.g., security policies, browser settings) and cannot deploy feature updates. Option B is wrong because a Windows 10 compliance policy evaluates device compliance against rules (e.g., required OS version) but does not initiate or manage the deployment of feature updates. Option C is wrong because a Windows 10 update ring profile controls the deferral, pause, and rollout of quality updates and feature updates via Windows Update for Business, but it does not pin devices to a specific feature update version; it only manages update behavior and timing.

177
Multi-Selecthard

Which TWO conditions in a Conditional Access policy can be used to enforce device compliance for access to Microsoft 365 services?

Select 2 answers
A.Sign-in risk
B.Locations (trusted IPs)
C.Applications (e.g., Exchange Online)
D.Client apps (Browser, Mobile apps and desktop clients)
E.Device state (Compliant or Domain joined)
AnswersD, E

Client apps condition can require compliant device for specific app types.

Why this answer

The 'Client apps' condition in a Conditional Access policy allows you to target specific client application types (e.g., browser, mobile apps, and desktop clients) to enforce device compliance. Option E is correct because the 'Device state' condition directly checks whether a device is marked as compliant in Microsoft Intune or is domain-joined (hybrid Azure AD join), which is the primary mechanism for enforcing device compliance for access to Microsoft 365 services.

Exam trap

The trap here is that candidates often confuse the 'Device state' condition with 'Sign-in risk' or 'Locations,' mistakenly thinking that location or risk level can enforce device compliance, when in fact only the 'Device state' condition directly checks compliance or domain join status.

178
MCQhard

You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?

A.Create a dynamic device group in Microsoft Entra ID that includes all Windows 11 devices.
B.Assign Microsoft Intune licenses to all users who will receive the new devices.
C.Register the devices in Windows Autopilot by providing the hardware hash to the Microsoft Intune admin center.
D.Create a compliance policy that requires BitLocker encryption and a minimum OS version.
AnswerC

Registering the hardware hash is the first step to enable Autopilot, which provides zero-touch deployment.

Why this answer

Windows Autopilot is the cloud-based zero-touch deployment solution that uses hardware hashes to register devices in Intune, enabling them to automatically enroll and receive configurations without IT intervention. This directly meets the requirement for pre-provisioned Windows 11 devices with no manual touch.

Exam trap

The trap here is confusing post-enrollment configuration steps (like creating groups or compliance policies) with the prerequisite enrollment mechanism, leading candidates to select a step that is necessary but not sufficient for zero-touch deployment.

How to eliminate wrong answers

Option A is wrong because creating a dynamic device group in Entra ID is a post-enrollment step for applying policies or targeting apps, not a mechanism for zero-touch enrollment itself. Option B is wrong because assigning Intune licenses is a prerequisite for enrollment but does not automate the enrollment process; it must be combined with Autopilot registration to achieve zero-touch. Option D is wrong because creating a compliance policy enforces security settings after enrollment, but it does not initiate or automate the enrollment process.

179
MCQhard

You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?

A.Endpoint Protection
B.Windows Update Policies
C.Client Apps
D.Device Configuration
AnswerB

Correct. This workload controls update management.

Why this answer

In a co-management scenario, the workload slider determines which management authority handles specific workloads. Setting the 'Windows Update Policies' slider to 'Intune' directs Windows Update for Business policies to be applied via Intune, overriding Configuration Manager policies for co-managed Windows 10 devices. This ensures that update rings and deferral settings configured in Intune are enforced.

Exam trap

The trap here is that candidates often confuse the 'Windows Update Policies' slider with the 'Endpoint Protection' slider, mistakenly thinking update management is part of security policies, but the slider specifically governs Windows Update for Business policies, not Defender or antivirus updates.

How to eliminate wrong answers

Option A is wrong because the Endpoint Protection workload slider controls antimalware and firewall policies (e.g., Defender for Endpoint), not Windows Update policies. Option C is wrong because the Client Apps workload slider governs the deployment of applications (e.g., MSI, Win32 apps) from Intune or Configuration Manager, not update management. Option D is wrong because the Device Configuration workload slider manages settings like compliance policies and resource access (e.g., VPN, Wi-Fi), not Windows Update policies.

180
Multi-Selectmedium

Which TWO actions are required to deploy a Win32 app using Microsoft Intune? (Choose two.)

Select 2 answers
A.Upload the .intunewin package file.
B.Configure detection rules.
C.Connect to Managed Google Play.
D.Assign a Microsoft Store license.
E.Sign the app with a macOS developer certificate.
AnswersA, B

The .intunewin file is the packaged app for Win32 deployment.

Why this answer

Uploading the .intunewin package file is mandatory for deploying a Win32 app via Intune; this file encapsulates the app's installation files and metadata. Option B is correct because configuring detection rules is essential to verify the app's installation status and reapply policies as needed. Both actions are required for successful deployment.

Exam trap

The trap here is that candidates may confuse the requirements for Win32 apps with those for other platforms (Android, Microsoft Store, macOS), leading them to select options that are valid for those platforms but irrelevant for Win32 deployment.

181
MCQhard

You are designing a Windows Autopilot deployment for a global organization. Devices are purchased from multiple OEMs and shipped directly to users. Some users report that their devices do not register in Autopilot automatically. You confirm the devices have Windows 11 Pro preinstalled and meet hardware requirements. What is the most likely reason for the registration failure, and what should you do to resolve it?

A.The devices are not registered in Autopilot by the OEM; collect the hardware hash using a script
B.The devices have a TPM chip that is not compliant with Autopilot requirements
C.The Autopilot deployment profile is assigned to a dynamic device group that excludes these devices
D.The devices are not connected to the internet during OOBE
AnswerA

The OEM must register the device; if not, manual hash collection is required.

Why this answer

The most likely reason is that the OEM did not register the devices in Windows Autopilot by uploading their hardware hashes to the Microsoft Partner Center. Without this registration, the devices will not be recognized during OOBE and will not automatically receive the Autopilot deployment profile. To resolve this, you must collect the hardware hash from each device using a PowerShell script (e.g., Get-WindowsAutopilotInfo.ps1) and manually upload it to Intune or the Partner Center.

Exam trap

The trap here is that candidates often assume the issue is with TPM or connectivity during OOBE, but the core problem is that the device was never registered in Autopilot by the OEM, which is a prerequisite for automatic profile assignment.

How to eliminate wrong answers

Option B is wrong because TPM compliance is not a prerequisite for Autopilot registration; Autopilot requires TPM 2.0 only for self-deploying mode, but the question does not specify that mode, and devices with non-compliant TPM would still register and show in Intune. Option C is wrong because dynamic device group membership is evaluated after a device is registered in Autopilot; if the device is not registered, the group assignment is irrelevant. Option D is wrong because internet connectivity during OOBE is required for Autopilot to download the profile, but the issue here is that the device never appears in Autopilot at all, which indicates a registration failure, not a connectivity problem.

182
MCQmedium

You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?

A.Verify that the user is assigned an Intune license.
B.Run the 'dsregcmd /status' command to check the device registration status.
C.Check that the device has a TPM chip enabled and Secure Boot turned on.
D.Ensure the compliance policy is assigned to a group that includes the user or device.
AnswerD

The compliance policy must be assigned to a group containing the user or device.

Why this answer

A compliance policy must be assigned to a group containing the user or device for it to be evaluated. Even if the device is enrolled and syncing, without assignment the policy will not apply, resulting in a 'Not evaluated' status in Intune.

Exam trap

The trap here is that candidates confuse 'Not evaluated' with a device health or configuration issue, when it actually points to a missing policy assignment or group membership problem.

How to eliminate wrong answers

Option A is wrong because an Intune license is required for enrollment and sync, which the user already has (device is enrolled and syncing), so licensing is not the cause of 'Not evaluated' status. Option B is wrong because 'dsregcmd /status' checks Azure AD registration and hybrid join status, not compliance policy assignment or evaluation; the device is already enrolled and syncing, indicating registration is fine. Option C is wrong because TPM and Secure Boot are prerequisites for BitLocker or device health attestation, not for compliance policy evaluation; their absence would cause specific compliance failures, not a 'Not evaluated' status.

183
MCQhard

An organization uses Microsoft Intune to manage iOS/iPadOS devices. They have a custom line-of-business (LOB) iOS app that must be deployed to 50 devices. The app is signed with an enterprise certificate. The administrator uploads the .ipa file to Intune and assigns it as 'Required' to a device group containing the 50 devices. After 24 hours, only 30 devices have the app installed. The remaining 20 devices show 'pending install' status. What is the most likely cause?

A.The .ipa file exceeds the maximum file size allowed for LOB apps.
B.The users on the 20 devices have not opened the Company Portal app to trigger the installation.
C.The devices do not have a trusted certificate profile that trusts the enterprise signing certificate.
D.The MDM push certificate has expired, preventing app installation.
AnswerC

Enterprise-signed apps require the device to trust the root certificate.

Why this answer

The most likely cause is that the 20 devices lack a trusted certificate profile that trusts the enterprise signing certificate. For an enterprise-signed LOB app to install on iOS/iPadOS, the device must trust the root certificate used to sign the app. Without a trusted certificate profile deployed via Intune, the installation will remain in 'pending install' status because the device cannot validate the app's signature.

Exam trap

The trap here is that candidates often assume 'pending install' means a user action is required (like opening Company Portal) or a network issue, but Microsoft Intune's MDM channel can push apps silently; the real blocker is certificate trust for enterprise-signed apps.

How to eliminate wrong answers

Option A is wrong because Intune's maximum file size for LOB apps is 2 GB, and the .ipa file would typically be much smaller; exceeding this limit would cause an upload failure, not a 'pending install' status. Option B is wrong because when an app is assigned as 'Required' in Intune, the installation is pushed silently via the MDM channel and does not require the user to open the Company Portal app. Option D is wrong because an expired MDM push certificate would prevent all MDM communication, not just app installations on a subset of devices, and the other 30 devices successfully installed the app, proving the push certificate is valid.

184
Multi-Selectmedium

A company is planning to deploy a custom Win32 app to Windows 10 devices using Intune. The app requires a .NET Framework 4.8 prerequisite. Which TWO methods can the administrator use to ensure the prerequisite is installed?

Select 2 answers
A.Require users to manually install the prerequisite
B.Use Group Policy to deploy the prerequisite
C.Add the prerequisite as a dependency in the app deployment
D.Package the prerequisite into the same Win32 app
E.Create a custom detection script that installs the prerequisite if missing
AnswersC, E

Dependencies allow automatic installation of prerequisites.

Why this answer

Intune Win32 app deployment supports dependencies, allowing an administrator to specify .NET Framework 4.8 as a required dependency. When configured, Intune automatically installs the dependency before the main app, ensuring the prerequisite is present without manual intervention or additional scripting.

Exam trap

The trap here is that candidates often confuse 'packaging the prerequisite into the same app' (Option D) as a valid method, but Intune requires dependencies to be separate app entries with their own detection rules, not bundled installers.

185
MCQmedium

A company uses Microsoft 365 with hybrid identity. Users report that after changing their on-premises passwords, they cannot access SharePoint Online for up to 30 minutes, but Outlook on the web works immediately. You need to reduce the delay for SharePoint Online access. What should you do?

A.Run a Delta Sync in Azure AD Connect.
B.Configure password writeback in Azure AD Connect.
C.Enable Azure AD Seamless Single Sign-On.
D.In Azure AD, configure the user to require password change at next sign-in.
AnswerA

Delta Sync immediately synchronizes recent password changes, reducing the delay.

Why this answer

The delay occurs because password changes are synchronized only during the next Azure AD Connect sync cycle, which by default runs every 30 minutes. Running a Delta Sync immediately replicates the new password hash to Azure AD, eliminating the wait for SharePoint Online authentication.

Exam trap

The trap here is confusing password writeback (cloud-to-on-premises) with password hash synchronization (on-premises-to-cloud), leading candidates to select writeback when the actual issue is sync frequency.

How to eliminate wrong answers

Option B is wrong because password writeback is used for self-service password reset from the cloud to on-premises, not for synchronizing on-premises password changes to Azure AD. Option C is wrong because Azure AD Seamless SSO provides silent authentication on domain-joined devices but does not affect the synchronization of password hashes. Option D is wrong because requiring a password change at next sign-in is a policy that forces the user to update their password, but it does not accelerate the sync of an already-changed password.

186
Multi-Selecthard

You are configuring Windows Hello for Business in Microsoft Intune. Which THREE settings are required to enable Windows Hello for Business on Windows 10 devices?

Select 3 answers
A.Configure a certificate enrollment policy for smart cards.
B.Set minimum PIN length to at least 4 digits.
C.Enable biometric authentication.
D.Enable Windows Hello for Business in the identity protection policy.
E.Configure a PIN complexity policy.
AnswersB, D, E

A minimum PIN length is required.

Why this answer

Windows Hello for Business requires a minimum PIN length of at least 4 digits when configured via Intune's identity protection policy. This setting is mandatory to enforce a baseline level of security for the PIN-based authentication method, and Intune will not enable Windows Hello for Business without a defined minimum PIN length.

Exam trap

The trap here is that candidates often assume biometric authentication is required for Windows Hello for Business, but Microsoft explicitly allows PIN-only deployments, and the mandatory settings are enabling the feature and configuring PIN complexity (including minimum length).

187
MCQhard

A company manages 500 Windows 11 devices with Microsoft Intune. They use BitLocker encryption with automatic encryption enabled. Several devices report that encryption did not start. The administrator reviews the devices and finds that they are not compliant with the BitLocker policy. What is the most likely cause?

A.Devices do not have a secure boot enabled
B.Devices do not have a Trusted Platform Module (TPM) chip
C.Devices are not Azure AD joined
D.BitLocker startup key is not saved to Azure AD
AnswerB

BitLocker requires a TPM to automatically encrypt devices.

Why this answer

BitLocker automatic encryption requires a compatible TPM chip to securely store encryption keys and validate system integrity. Without a TPM, BitLocker cannot start the encryption process automatically, leading to non-compliance with the policy. The other options do not directly prevent encryption from starting.

Exam trap

The trap here is that candidates often confuse Secure Boot with TPM requirements, assuming Secure Boot is mandatory for BitLocker, when in fact the TPM is the critical hardware component for automatic encryption to initiate.

How to eliminate wrong answers

Option A is wrong because Secure Boot is recommended but not strictly required for BitLocker automatic encryption; BitLocker can still encrypt without it, though it may affect integrity validation. Option C is wrong because Azure AD join is not a prerequisite for BitLocker encryption; devices can be Azure AD registered or hybrid joined and still encrypt. Option D is wrong because saving the BitLocker startup key to Azure AD is a recovery key backup step, not a prerequisite for encryption to start; encryption can begin without this backup.

188
MCQhard

You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?

A.The device does not have internet connectivity to download the app.
B.The device's certificate for Intune is expired.
C.The Intune management extension is not installed on the device.
D.The device requires a restart to complete previous updates.
AnswerC

LOB apps require the extension, which may be missing.

Why this answer

The Intune management extension is responsible for deploying line-of-business (LOB) apps and PowerShell scripts on Windows devices. If this extension is not installed, the device will show a 'Pending' status for required app deployments because the Intune service cannot initiate the download or installation. Since the device has been online, connectivity is not the issue, and the extension must be present to process the deployment.

Exam trap

The trap here is that candidates often assume a 'Pending' status is always due to network issues or pending reboots, but Microsoft specifically tests the requirement of the Intune management extension for LOB app deployments on Windows devices.

How to eliminate wrong answers

Option A is wrong because the device has been online for the past 24 hours, indicating internet connectivity is available, and a 'Pending' status typically does not result from transient connectivity issues. Option B is wrong because an expired Intune certificate would cause the device to appear as 'Not compliant' or 'Unhealthy' in the Intune console, not a 'Pending' status for a specific app deployment. Option D is wrong because a pending restart would affect the installation of updates, not the initial download or deployment status of an LOB app, and the device would still show the app as 'Pending' only if the management extension were missing.

189
Matchingmedium

Match each Microsoft Entra ID (Azure AD) join type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Personal devices with work account access

Devices owned by organization, cloud-only

Devices joined to on-premises AD and Azure AD

Hybrid join with automatic device enrollment

Hybrid join using federation services

Why these pairings

Azure AD Join is cloud-only; Hybrid Azure AD Join requires on-premises AD with sync; Azure AD Registered is for personal or bring-your-own devices.

190
Multi-Selectmedium

Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?

Select 3 answers
A.Change the primary user
B.Change the enrolled user
C.Restart the device
D.Sync the device
E.Change the device name
AnswersA, C, D

Correct. You can change the primary user of a managed device from the Intune admin center. This updates the user-device association.

Why this answer

The Microsoft Intune admin center supports several remote actions on managed devices. Changing the primary user (A), Restart (C), and Sync (D) are all valid remote actions. Options B (Change the enrolled user) and E (Change the device name) are not available remotely.

Exam trap

Candidates often assume that changing the primary user is not possible, but Intune does support this remote action. The trap is to incorrectly limit remote actions to only Restart and Sync, omitting Change primary user.

191
MCQeasy

Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?

A.Enable Device Encryption in Windows settings.
B.Configure a FileVault policy for Windows devices.
C.Create a BitLocker policy in Intune Endpoint Protection.
D.Deploy an Encrypting File System (EFS) policy.
AnswerC

BitLocker provides full disk encryption and can be managed via Intune.

Why this answer

Microsoft Intune's Endpoint Protection policy includes a dedicated BitLocker settings section that allows administrators to enforce encryption on Windows 10 devices. This policy centrally manages BitLocker drive encryption, recovery key escrow to Azure AD, and encryption method (e.g., XTS-AES 128-bit), meeting the requirement for corporate laptop encryption.

Exam trap

The trap here is confusing file-level encryption (EFS) with full-disk encryption (BitLocker), or assuming that Device Encryption in Windows settings is the same as BitLocker, when in fact Device Encryption is a limited feature only available on specific hardware and lacks the management capabilities of Intune's BitLocker policy.

How to eliminate wrong answers

Option A is wrong because 'Enable Device Encryption' in Windows settings is a client-side toggle that only enables hardware-based encryption on devices that support InstantGo (Modern Standby), and it cannot be centrally managed or enforced via Intune policy. Option B is wrong because FileVault is Apple's full-disk encryption technology for macOS, not applicable to Windows 10 devices. Option D is wrong because Encrypting File System (EFS) provides file-level encryption, not full-disk encryption, and is managed via NTFS permissions or Group Policy, not Intune's endpoint protection policies for BitLocker.

192
Multi-Selectmedium

Your organization uses Microsoft Intune to manage mobile devices. You need to configure compliance policies that trigger conditional access. Which TWO conditions can be used in a device compliance policy?

Select 2 answers
A.Device is enrolled in a specific MDM authority.
B.App must have a minimum version.
C.Minimum OS version is 14.0.
D.Device is not jailbroken or rooted.
E.SD card encryption is enabled.
AnswersC, D

Correct. A minimum OS version is a standard condition in device compliance policies.

Why this answer

Correct answers are C and D. Device compliance policies in Microsoft Intune can check for conditions like minimum OS version (C) and whether the device is jailbroken or rooted (D). These conditions can trigger conditional access to enforce compliance.

Option A is incorrect because compliance policies do not check the MDM authority; they assume Intune. Option B is incorrect because app version requirements are managed via app protection policies, not compliance policies. Option E is incorrect because SD card encryption is not a standard compliance policy setting; device encryption is checked but not specifically SD cards.

Exam trap

Candidates often confuse compliance policy conditions with app protection policy conditions. Remember that compliance policies focus on device-level settings (OS version, jailbreak status, encryption), while app protection policies manage app-level restrictions like minimum app version or data protection.

193
MCQeasy

Your organization has devices enrolled in Microsoft Intune that are not domain-joined. You need to deploy a LOB app that requires a license key stored in a file. The app must be installed automatically when devices are enrolled. What should you do?

A.Package the app as a Win32 app and include a script to copy the license file.
B.Use a Microsoft Store for Business app and include the license as a dependency.
C.Join devices to Azure AD and use Group Policy to install.
D.Create an Intune App Protection Policy to deploy the license.
AnswerA

Win32 app allows custom installation scripts.

Why this answer

Microsoft Intune can deploy Win32 apps with installation scripts that can handle license file copying. Option B is incorrect because Microsoft Store for Business apps do not support custom license files as dependencies. Option C is incorrect because Group Policy requires domain-joined devices and Azure AD Join does not enable Group Policy for app installation in Intune.

Option D is incorrect because App Protection Policies are used to manage data protection settings, not to deploy app binaries or license files.

194
MCQhard

You are deploying Windows 10 to 100 new devices using Microsoft Deployment Toolkit (MDT). You want to integrate with Microsoft Intune for post-deployment management. Which MDT integration method should you use?

A.Use Microsoft Configuration Manager to deploy the devices and then co-manage with Intune.
B.Configure Windows Autopilot for the devices and skip MDT.
C.Create a provisioning package in MDT that includes the Intune enrollment configuration and apply it during the deployment task sequence.
D.Install the Intune connector for MDT and configure it during deployment.
AnswerC

The provisioning package can include MDM enrollment settings.

Why this answer

MDT can create a provisioning package (PPKG) that includes Intune enrollment configuration (e.g., enrollment token, tenant ID) and apply it during the task sequence. This allows the device to automatically enroll into Intune after the OS deployment completes, enabling post-deployment management without requiring Configuration Manager or Autopilot.

Exam trap

The trap here is that candidates may confuse MDT integration with Configuration Manager co-management or assume a dedicated Intune connector exists, when in fact MDT relies on provisioning packages for Intune enrollment.

How to eliminate wrong answers

Option A is wrong because it suggests using Configuration Manager to deploy the devices and then co-manage with Intune, which is a valid approach but not an MDT integration method; the question specifically asks for MDT integration, and this option bypasses MDT entirely. Option B is wrong because it recommends skipping MDT and using Windows Autopilot, which is a separate deployment method and does not integrate with MDT; the question requires using MDT for deployment. Option D is wrong because there is no 'Intune connector for MDT' — Intune enrollment is configured via provisioning packages or scripts, not a dedicated connector; this option describes a fictional component.

195
Multi-Selectmedium

You are configuring Microsoft Intune device compliance policies for Windows 10. Which FOUR settings can be evaluated by compliance policies? (Choose four.)

Select 4 answers
A.Windows Firewall status
B.Minimum OS version
C.BitLocker encryption status
D.Password policy (length, complexity)
E.Threat level from Microsoft Defender for Endpoint
AnswersB, C, D, E

Correct. Minimum OS version is a common compliance policy setting.

Why this answer

Compliance policies in Microsoft Intune can evaluate minimum OS version (B), password policy (D), threat level from Microsoft Defender for Endpoint (E), and BitLocker encryption status (C). Windows Firewall status (A) is not evaluated by compliance policies but by device configuration policies. Therefore, all options except A are valid compliance policy settings.

Exam trap

A common mistake is to think BitLocker encryption status is not evaluated by compliance policies, but it is available under Device Health settings in Intune compliance policies.

196
MCQeasy

You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?

A.Device compliance policy
B.App protection policy
C.Conditional Access policy
D.Device configuration profile
AnswerC

Conditional Access blocks non-compliant devices.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) evaluate signals such as device compliance status from Intune before granting access to cloud apps like Exchange Online. By integrating with Intune compliance policies, a Conditional Access policy can block or allow access based on whether the device meets compliance requirements. This is the correct mechanism to enforce access control for compliant devices.

Exam trap

The trap here is that candidates often confuse Device compliance policies (which only assess and report compliance) with Conditional Access policies (which actually enforce access decisions), leading them to select the compliance policy as the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because a Device compliance policy only marks a device as compliant or non-compliant; it does not enforce access control to Exchange Online on its own. Option B is wrong because App protection policies manage data protection within applications (e.g., preventing copy/paste) and do not evaluate device compliance or control access to Exchange Online at the device level. Option D is wrong because Device configuration profiles apply settings like Wi-Fi or VPN configurations and do not enforce conditional access based on compliance status.

197
MCQhard

You are a Microsoft 365 Endpoint Administrator for a mid-sized company with 5,000 Windows 10 devices. The company is planning to migrate to Windows 11. You are tasked with deploying Windows 11 using a phased approach with Windows Autopilot. You have configured an Autopilot deployment profile for self-deploying mode targeting all Windows 10 devices in a dynamic device group. However, during the first wave of deployment, you notice that devices that have been upgraded to Windows 11 via an in-place upgrade are not automatically transitioning to the Autopilot experience. Instead, they boot directly to the existing Windows 10 desktop without any Autopilot enrollment. You verify that the devices are registered in Autopilot and that the deployment profile is assigned correctly. What is the most likely cause of this issue?

A.The Autopilot profile has a pre-provisioning policy that blocks self-deploying mode
B.The devices have not been reset to OOBE state after the in-place upgrade
C.The Autopilot profile is configured for user-driven mode instead of self-deploying mode
D.The devices are not connected to the internet during the first boot after upgrade
AnswerB

Autopilot requires OOBE; upgrade doesn't trigger OOBE.

Why this answer

Windows Autopilot requires the device to be in an Out-of-Box Experience (OOBE) state to trigger the enrollment process. An in-place upgrade to Windows 11 preserves the existing user state and settings, so the device boots directly to the desktop without entering OOBE. Even though the device is registered in Autopilot and the profile is assigned, the Autopilot experience only initiates when the device is reset to OOBE (e.g., via a Windows reset or a fresh start).

Therefore, the most likely cause is that the devices have not been reset to OOBE state after the in-place upgrade.

Exam trap

The trap here is that candidates assume Autopilot enrollment will automatically trigger after any upgrade or reboot on a registered device, but they overlook the critical requirement that the device must be in OOBE state to initiate the Autopilot process.

How to eliminate wrong answers

Option A is wrong because a pre-provisioning policy does not block self-deploying mode; pre-provisioning is an optional phase that can be used with self-deploying mode, and it does not prevent the Autopilot enrollment from starting. Option C is wrong because the question states the profile is configured for self-deploying mode, and if it were misconfigured for user-driven mode, the device would still attempt to enroll (but prompt for user credentials) rather than boot directly to the desktop. Option D is wrong because internet connectivity is required for Autopilot enrollment, but the issue here is that the device never enters the OOBE phase where it would check for connectivity; the device boots to the existing desktop, so connectivity is not the blocking factor.

198
Multi-Selectmedium

Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?

Select 3 answers
A.Add devices to Apple Business Manager (ABM).
B.Configure automated device enrollment (formerly DEP) in ABM and link to Intune.
C.Create an iOS enrollment profile in Intune with 'Supervised' enabled.
D.Assign a user to each device during enrollment.
E.Create a device compliance policy that requires supervision.
AnswersA, B, C

ABM is required for supervision.

Why this answer

Options A, B, and C are correct. Supervising devices requires Apple Business Manager, automated enrollment, and a supervision profile. Option D is not required because supervised devices do not need user affinity for supervision.

Option E is for device compliance, not supervision.

199
Multi-Selecthard

An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?

Select 2 answers
A.BitLocker
B.Encrypting File System (EFS)
C.Device encryption
D.FileVault
E.APFS encryption
AnswersA, C

BitLocker is a full disk encryption feature for Windows.

Why this answer

BitLocker is a full-disk encryption feature built into Windows Pro and Enterprise editions, and it can be managed via Microsoft Intune using the 'Endpoint Protection' profile under the 'Windows Encryption' category. Device encryption is available on Windows devices that support InstantGo (modern standby) and is enabled by default on many devices. In contrast, FileVault is a macOS-specific encryption feature and is not applicable to Windows devices.

Encrypting File System (EFS) provides file-level encryption, not full-disk encryption. APFS encryption is also macOS-specific. Therefore, only BitLocker (A) and Device encryption (C) are valid encryption options for Windows devices managed by Intune.

Exam trap

The trap here is that candidates often confuse file-level encryption (EFS) with full-disk encryption, or mistakenly apply macOS-specific technologies (FileVault, APFS encryption) to Windows devices, forgetting that Intune policies are platform-specific.

200
MCQeasy

Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?

A.The level of update notifications
B.How long to defer feature updates
C.Whether updates are installed automatically and if the user can control reboot timing
D.The branch readiness level
AnswerC

This setting defines the installation and reboot behavior.

Why this answer

The 'automaticUpdateBehavior' setting in a Windows 10 update ring configuration JSON controls whether updates are downloaded and installed automatically, and whether the user can control reboot timing. When set to 'autoInstallAndRebootWithNoUserControl', updates install automatically and reboots occur without user interaction; when set to 'autoInstallAndRebootWithUserControl', the user can schedule or postpone reboots. This directly matches option C, as it governs both automatic installation and reboot control.

Exam trap

The trap here is that candidates confuse 'automaticUpdateBehavior' with deferral periods or notification levels, because all three settings appear in the same update ring configuration JSON, but each controls a distinct aspect of Windows Update behavior.

How to eliminate wrong answers

Option A is wrong because 'automaticUpdateBehavior' does not control the level of update notifications; notification behavior is managed by the 'updateNotificationLevel' setting in the update ring policy. Option B is wrong because deferring feature updates is controlled by the 'deferFeatureUpdatesPeriodInDays' setting, not by 'automaticUpdateBehavior'. Option D is wrong because branch readiness level is set via the 'branchReadinessLevel' property (e.g., 'CurrentBranch' or 'SemiAnnualChannel'), which is independent of the automatic update behavior.

201
Multi-Selecthard

Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)

Select 3 answers
A.Configure Autopilot for the device.
B.Create a device compliance policy to enforce kiosk mode.
C.Create a device configuration profile with the kiosk settings.
D.Assign the kiosk profile to a Microsoft Entra ID group containing the target devices.
E.Ensure the device is enrolled in Microsoft Intune.
AnswersC, D, E

Kiosk settings are configured via a configuration profile.

Why this answer

A device configuration profile in Microsoft Intune is the mechanism used to define the specific kiosk settings, such as the user account, app type (e.g., single-app or multi-app kiosk), and browser configuration. This profile applies the kiosk mode configuration to the device via the Windows 10/11 kiosk policy CSP (Policy Configuration Service Provider).

Exam trap

The trap here is that candidates confuse device compliance policies with device configuration profiles, mistakenly thinking compliance policies can enforce kiosk mode, when in fact compliance policies only evaluate and report on device health and security settings.

202
MCQmedium

Your company uses Intune to manage iOS devices. You need to deploy a new app that is available in the Apple App Store. You create an iOS store app in Intune and assign it as 'Required' to a group of users. After 24 hours, some users report that the app is not installed. You verify that the app is available in the App Store and that the devices are online. The devices are supervised and enrolled via Apple Business Manager. What should you do first to troubleshoot the issue?

A.Review the iOS device restrictions policy
B.Confirm that the devices are enrolled in Intune
C.Check the app configuration policy for the app
D.Verify that a VPP token is configured and assigned
AnswerD

Supervised devices require a VPP token for app distribution.

Why this answer

For supervised iOS devices enrolled via Apple Business Manager, a Volume Purchase Program (VPP) token must be configured in Intune and assigned to the device group to allow automatic installation of store apps assigned as 'Required'. Without a valid VPP token, the app installation will fail even if the app is available and devices are online. Option A is incorrect because while device restrictions policy could block certain apps, it is not the first step in troubleshooting a missing app installation.

Option B is incorrect because the devices are already enrolled (as stated in the scenario). Option C is incorrect because an app configuration policy is used to customize app settings, not to control installation.

203
MCQhard

A user has an iOS device enrolled in Intune. The device is lost, and you need to immediately prevent unauthorized access to corporate data. The device contains both corporate and personal data. Which action should you take?

A.Disable the user's account in Microsoft Entra ID
B.Initiate a selective wipe
C.Initiate a full wipe
D.Use Remote Lock to lock the device
AnswerD

Remote lock immediately locks the device, preventing access.

Why this answer

Remote Lock immediately locks the iOS device, preventing unauthorized access to both corporate and personal data without altering the device's content. This is the correct first step to secure data while preserving the ability to recover the device later, as it does not remove any data or accounts.

Exam trap

The trap here is that candidates often confuse 'immediate prevention of unauthorized access' with data removal, leading them to choose a wipe option, but Remote Lock is the correct first step because it secures the device without destroying personal data or requiring re-enrollment.

How to eliminate wrong answers

Option A is wrong because disabling the user's account in Microsoft Entra ID revokes access to cloud services but does not lock the device itself, leaving local data accessible. Option B is wrong because a selective wipe removes only corporate data and apps, which still leaves personal data exposed and does not immediately prevent access to the device. Option C is wrong because a full wipe erases all data, including personal content, which is overly destructive and irreversible; it should only be used as a last resort after confirming the device cannot be recovered.

204
MCQhard

You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?

A.The device is running Windows 10 Home edition.
B.MDM enrollment is blocked by a local Group Policy or registry setting.
C.The device is not connected to the internet.
D.The device has an expired certificate required for enrollment.
AnswerB

This error code indicates enrollment is disabled via policy.

Why this answer

Error 0x8018000b indicates that the device is not allowed to enroll, typically because MDM enrollment is blocked by a local Group Policy or registry setting. Even with a valid license and Windows 10 Pro, if the 'MDM Enrollment' policy is disabled or the 'Enrollment automatic' registry key is misconfigured, the enrollment attempt will fail with this specific error.

Exam trap

The trap here is that candidates often assume error 0x8018000b is a licensing or connectivity issue, but it specifically indicates that enrollment is administratively blocked, not that the device is unsupported or offline.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the device runs Windows 10 Pro, not Home edition, and error 0x8018000b is not related to edition restrictions (which would produce a different error). Option C is wrong because lack of internet connectivity would generate a different error (e.g., 0x8018000a or timeout), not 0x8018000b. Option D is wrong because an expired certificate would produce a certificate-related error (e.g., 0x80180014 or 0x8018000c), not the specific 'enrollment blocked' code 0x8018000b.

205
MCQhard

Your organization uses Microsoft Intune to manage devices. You need to deploy a PowerShell script that runs every time a user logs in to a Windows 10 device. The script must run with administrative privileges. Which deployment approach should you use?

A.Package the script as a Win32 app and assign it as required.
B.Deploy the script as a proactive remediation in Intune.
C.Use Intune PowerShell scripts targeting the user, with a scheduled task triggered by logon.
D.Use a custom compliance policy to run the script.
AnswerC

Intune PowerShell scripts can run in user context; a scheduled task triggered at logon can elevate privileges.

Why this answer

Intune PowerShell scripts can be deployed to users and configured to run as the logged-on user. To run with administrative privileges and on every logon, a scheduled task triggered by logon can be created that runs the script with elevated rights. Option A is incorrect because deploying a PowerShell script as a Win32 app typically runs once per assigned device, not on every user logon.

Option B is incorrect because proactive remediations run on a schedule (e.g., daily) and can detect/fix issues but are not triggered by user logon events. Option D is incorrect because custom compliance policies evaluate device settings for compliance and do not execute scripts on login.

206
MCQhard

You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?

A.Configure a 'Quality update deadline' of 2 days and a 'Feature update deadline' of 60 days.
B.Use a 'Quality update deferral period' of 48 hours and a 'Feature update deferral period' of 60 days in a Windows 10 update ring.
C.Set the 'Update notification level' to '2 - Disable all notifications' and configure active hours.
D.Configure a 'Quality update deferral period' of 2 days and a 'Feature update deferral period' of 60 days.
AnswerA

Deadline policies are the modern approach to enforce update installation within a specific timeframe.

Why this answer

Windows Update for Business uses 'deadline' policies to enforce when updates must be installed, not deferral periods. A 'Quality update deadline' of 2 days ensures critical security updates are installed within 48 hours, while a 'Feature update deadline' of 60 days allows feature updates to be delayed up to 60 days. Deferral periods only postpone when an update is offered, not when it must be installed, making deadlines the appropriate mechanism for enforcing installation timelines.

Exam trap

The trap here is that candidates confuse deferral periods with deadlines, assuming a deferral of 2 days achieves the same result as a 2-day deadline, but deferrals only delay the offer while deadlines enforce installation timing.

How to eliminate wrong answers

Option B is wrong because deferral periods delay the offer of updates but do not enforce an installation deadline; a 48-hour deferral would only delay when the quality update is first offered, not ensure it is installed within 48 hours. Option C is wrong because notification settings and active hours control user experience and restart timing, not the deployment timeline for security or feature updates. Option D is wrong because a deferral period of 2 days for quality updates only delays the offer by 2 days, failing to guarantee installation within 48 hours; deadlines are required to enforce the installation window.

207
Multi-Selecthard

Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?

Select 3 answers
A.The use of co-management to gradually move workloads.
B.The ability to manage on-premises servers with Intune.
C.The compatibility of existing application packages with Intune formats (Win32, LOB).
D.The need for an on-premises Intune server.
E.Network bandwidth requirements for device communication with Intune.
AnswersA, C, E

Co-management enables you to manage devices with both Configuration Manager and Intune, allowing a phased migration.

Why this answer

Co-management allows you to attach your existing Configuration Manager deployment to Microsoft Intune, enabling a gradual migration of workloads (e.g., compliance policies, device configuration, Windows Update policies) at your own pace. This hybrid approach lets you keep some management functions on-premises while testing and shifting others to the cloud, minimizing disruption and providing a rollback path.

Exam trap

The trap here is that candidates often assume Intune can manage on-premises servers like Configuration Manager does, or that an on-premises Intune server exists, when in reality Intune is purely cloud-based and cannot replace Configuration Manager for server management.

208
MCQmedium

A user reports that their Windows 11 device is not receiving Microsoft 365 Apps updates from Intune. You verify the device is enrolled and compliant. The device has a Microsoft 365 Apps update policy assigned. What is the most likely cause?

A.The Microsoft 365 Apps update channel is not configured in the policy
B.The device is in a low-power state and not checking in for updates
C.The device is not connected to the internet
D.The device has an older version of Office installed that does not support Intune management
AnswerB

If the device is in a low-power state, update policies may not apply until it is active.

Why this answer

The most likely cause is that the device is in a low-power state (e.g., sleep or hibernation) and not checking in for updates. Intune relies on the Microsoft 365 Apps update service, which uses a scheduled task that runs only when the device is awake and connected. If the device is in a low-power state, it cannot execute the update check, even though it is enrolled and compliant.

Exam trap

The trap here is that candidates often assume the update channel must be configured (Option A) or that internet connectivity is the issue (Option C), but Intune policies have default channels and the device is already compliant, so the real culprit is the device's power state preventing the update check from running.

How to eliminate wrong answers

Option A is wrong because if the update channel were not configured, the policy would either fail to apply or use a default channel, but the device would still attempt to check for updates; the issue is that the device is not checking in at all. Option C is wrong because the question states the device is enrolled and compliant, which requires internet connectivity for Intune communication; if it were not connected, the device would not be compliant or would show as disconnected. Option D is wrong because all versions of Office that support Intune management (Microsoft 365 Apps, Office 2019 or later) can receive updates via Intune policies; an older version like Office 2016 would not be managed by Intune at all, but the device is already enrolled and has a policy assigned.

209
MCQeasy

You need to enforce encryption on Windows 10 devices managed by Intune. Which policy type should you configure?

A.Endpoint Protection profile
B.Device compliance policy
C.Windows Update for Business policy
D.Device configuration profile (settings catalog)
AnswerA

Endpoint Protection profiles include settings for BitLocker encryption.

Why this answer

Endpoint Protection profiles in Intune include the 'Windows Encryption' settings category, which allows you to enforce BitLocker Drive Encryption on Windows 10 devices. This profile directly manages encryption policies such as requiring BitLocker on OS and fixed drives, configuring encryption methods (e.g., XTS-AES 128-bit), and setting recovery password options. It is the correct policy type for enforcing encryption because it specifically targets security settings like device encryption and BitLocker.

Exam trap

The trap here is that candidates confuse Device Compliance Policies (which can check encryption status) with the actual policy that enforces encryption, leading them to select Option B, but compliance policies are read-only evaluations and cannot configure BitLocker settings.

How to eliminate wrong answers

Option B is wrong because Device Compliance Policies evaluate whether devices meet security requirements (e.g., encryption status) but do not configure or enforce encryption settings; they only mark devices as compliant or non-compliant. Option C is wrong because Windows Update for Business policies manage update rings, deferrals, and feature updates, not encryption or BitLocker settings. Option D is wrong because while the Settings Catalog in Device Configuration Profiles can include many settings, it does not contain the specific 'Windows Encryption' or 'BitLocker' policy categories that are exclusive to Endpoint Protection profiles for encryption enforcement.

210
MCQeasy

You are the compliance administrator for a large organization using Microsoft 365 E5 licenses. The company has a hybrid identity configuration with Azure AD Connect syncing on-premises Active Directory to Azure AD. The security team requires that all mobile devices accessing corporate email and documents must be enrolled in Microsoft Intune and compliant with company device policies. Recently, several users reported that they cannot access Outlook on their iOS devices, receiving a message: 'Your organization requires this device to be managed by Intune. Please install the Company Portal app and enroll your device.' However, after installing Company Portal and completing enrollment, they still cannot access Outlook and see the same error. Upon investigation, you find that the devices are showing as 'Compliant' in the Microsoft Intune admin center. You also verify that the Conditional Access policy requiring device compliance is correctly configured and assigned to all users. What should you do to resolve the issue?

A.Disable the Conditional Access policy, wait 10 minutes, and then re-enable it.
B.Recreate the Conditional Access policy with the same settings and assign it to the affected users.
C.Check if the affected users have an Intune license assigned; if not, assign one.
D.Verify that the devices are properly registered in Azure AD and, if not, ask users to unenroll and re-enroll their devices.
AnswerD

This addresses the common issue of devices being compliant but not properly registered in Azure AD, which causes Conditional Access to fail.

Why this answer

The issue is that the devices are compliant in Intune but not properly registered in Azure AD, which is a prerequisite for Conditional Access policies to evaluate device compliance. Even after enrollment, if the device registration fails or is incomplete, the Conditional Access policy will still block access. Option D addresses this by verifying and fixing the Azure AD registration, typically requiring unenrollment and re-enrollment to trigger a fresh registration.

Exam trap

The trap here is that candidates assume 'Compliant in Intune' automatically means 'Registered in Azure AD,' but Conditional Access evaluates Azure AD registration status separately, and a compliant device can still fail the registration check.

How to eliminate wrong answers

Option A is wrong because disabling and re-enabling a Conditional Access policy does not fix underlying device registration issues; it only temporarily removes the policy enforcement, which is not a sustainable solution. Option B is wrong because recreating the policy with identical settings does not resolve the root cause of devices not being properly registered in Azure AD; it would still evaluate the same non-registered devices. Option C is wrong because the affected users already have Microsoft 365 E5 licenses, which include Intune, and the devices show as compliant, indicating licensing is not the issue; the problem is Azure AD registration, not licensing.

211
MCQmedium

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

A.Devices are onboarded to Defender for Endpoint
B.Group Policy objects are linked to the domain
C.Security baselines are configured and assigned in Intune endpoint security
D.Devices are registered in Microsoft 365 Defender portal
AnswerC

Directly manages baseline compliance.

Why this answer

Intune security baselines are the mechanism that defines and enforces security configuration policies on Windows devices. To report compliance with those baselines, the baselines must first be configured and assigned to the devices via Intune endpoint security. Without this assignment, devices have no baseline to compare against, and compliance reporting will not occur.

Exam trap

The trap here is that candidates often confuse onboarding to Defender for Endpoint (which enables security telemetry and threat detection) with the separate requirement of configuring and assigning Intune security baselines to enforce and report compliance.

How to eliminate wrong answers

Option A is wrong because onboarding devices to Defender for Endpoint ensures they can send telemetry and be managed for threat detection, but it does not by itself configure or report on security baseline compliance; that requires Intune security baseline policies. Option B is wrong because Group Policy objects are a traditional on-premises management tool that does not report compliance to Intune; Intune uses its own policy engine and MDM channel, not GPOs. Option D is wrong because registering devices in the Microsoft 365 Defender portal is part of the Defender for Endpoint onboarding process and does not create or assign security baseline policies; compliance reporting to Intune requires the Intune security baseline assignment.

212
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?

A.Configure a device compliance policy to require corporate ownership.
B.Set enrollment restrictions to block personally owned devices.
C.Deploy an app protection policy to block personal devices.
D.Add corporate device identifiers (e.g., serial numbers) in Intune.
AnswerD

Corporate identifiers allow Intune to automatically mark devices as corporate-owned upon enrollment.

Why this answer

Corporate device identifiers, such as serial numbers or IMEI numbers, are the specific mechanism in Microsoft Intune used to mark a device as corporate-owned. While a conditional access policy requiring compliant devices ensures only compliant devices can access Microsoft 365, it does not distinguish between corporate and personal devices. By uploading corporate identifiers, Intune automatically sets the ownership type to 'Corporate' upon enrollment, which can then be used in conditional access policies to restrict access to only those devices.

Exam trap

The trap here is that candidates often confuse device compliance policies with ownership identification, not realizing that compliance policies evaluate security posture, not ownership, and that corporate identifiers are the dedicated Intune feature for marking devices as corporate-owned.

How to eliminate wrong answers

Option A is wrong because device compliance policies evaluate security settings (e.g., encryption, OS version) but do not include a setting to require corporate ownership; ownership type is a separate attribute managed via enrollment or device identifiers. Option B is wrong because enrollment restrictions block personally owned devices from enrolling at all, which is a pre-enrollment control, but the question asks what else must be done after configuring a conditional access policy to require compliant devices—enrollment restrictions would prevent personal devices from being enrolled, not identify corporate-owned devices among those already enrolled. Option C is wrong because app protection policies (MAM) manage data access within apps and can block personal devices from accessing corporate data, but they do not identify corporate-owned devices; they apply to both enrolled and unenrolled devices based on app-level controls, not device ownership.

213
Multi-Selecteasy

Which TWO of the following are device configuration settings you can manage with Microsoft Intune? (Choose two.)

Select 2 answers
A.Application settings for Microsoft 365 Apps
B.Device restrictions (e.g., camera, Bluetooth)
C.Wi-Fi profiles
D.Lock screen settings
E.Email profiles for Exchange Online
AnswersB, D

Device restrictions are part of device configuration.

Why this answer

Device restrictions, such as disabling the camera or Bluetooth, are a core configuration setting in Microsoft Intune. These are managed through device configuration profiles that enforce policies on devices, regardless of the user logged in. Option B is correct because Intune's device restrictions profile allows administrators to control hardware and system features at the device level.

Exam trap

The trap here is that candidates often confuse device restrictions with other configuration profile types like Wi-Fi or email profiles, but the question specifically asks for 'device configuration settings' that manage device-level features, not connectivity or account settings.

214
MCQeasy

A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?

A.Disconnect the device from Microsoft Entra ID and rejoin.
B.On the device, go to Settings > Accounts > Access work or school, select the account, and click Sync.
C.Delete and recreate the compliance policy in Microsoft Intune.
D.Re-enroll the device in Microsoft Intune.
AnswerB

Forcing a sync triggers a policy evaluation.

Why this answer

Forcing a sync from the device can refresh the policy evaluation and resolve the 'Not evaluated' status. Option A is wrong because the device is already enrolled. Option C is wrong because the issue is with policy evaluation, not configuration.

Option D is wrong because the device is already joined.

215
MCQhard

A user reports that their Windows 10 device is not receiving policies from Microsoft Intune. The device shows as 'Not compliant' in the Intune console. You run the Get-MgDeviceManagementManagedDevice cmdlet and see that the device is enrolled and appears in the list. However, the LastSyncTime is 14 days ago. What is the most likely cause?

A.The MDM certificate has expired.
B.The device is not connected to the internet due to a proxy misconfiguration.
C.The device is not enrolled in Intune.
D.The Intune Management Extension service is not running on the device.
AnswerD

This service manages policy sync.

Why this answer

The Intune Management Extension (IME) service is responsible for synchronizing policies, including compliance and configuration policies, from Intune to Windows 10 devices. If the IME service is not running, the device will not receive new policies or sync status, leading to a stale LastSyncTime (14 days ago) and a 'Not compliant' state, even though the device is enrolled and appears in the Get-MgDeviceManagementManagedDevice output.

Exam trap

The trap here is that candidates often assume a stale LastSyncTime always indicates a network or connectivity issue (like a proxy), but the question specifically states the device is enrolled and appears in the list, pointing instead to a service-level failure like the Intune Management Extension not running.

How to eliminate wrong answers

Option A is wrong because an expired MDM certificate would typically cause enrollment failure or a complete loss of communication, not just a stale sync time; the device would likely show as 'Not enrolled' or 'Pending' rather than enrolled with a 14-day-old sync. Option B is wrong because a proxy misconfiguration would prevent any internet connectivity, causing the device to fail to reach Intune entirely, which would result in a much older LastSyncTime or a 'Not connected' status, not a specific 14-day gap. Option C is wrong because the Get-MgDeviceManagementManagedDevice cmdlet output explicitly shows the device is enrolled and in the list, contradicting the claim that it is not enrolled.

216
MCQmedium

You are reviewing a Windows 10 compliance policy in Microsoft Intune. A user with a device running Windows 10 version 20H2 (build 19042.985) reports that the device is marked as non-compliant. The device has a password of length 8, a PIN with 4 characters, Secure Boot enabled, BitLocker enabled, and Windows Defender Firewall active. What is the most likely reason for non-compliance?

A.Windows Defender Firewall is not active.
B.Secure Boot is not enabled on the device.
C.The OS build number 19042.985 is below the required minimum version 19041.0.
D.The device uses a PIN with only 4 characters, which does not meet the minimum password length of 6.
AnswerD

Password minimum length is 6, but PIN length is 4.

Why this answer

The device uses a PIN with only 4 characters, which does not meet the minimum password length of 6. In Intune compliance policies for Windows 10, the 'Minimum password length' setting applies to both passwords and PINs. A PIN of 4 characters violates this requirement, causing non-compliance even if other settings like BitLocker and Secure Boot are properly configured.

Exam trap

The trap here is that candidates assume a PIN is separate from a password and not subject to the same minimum length requirement, but Intune's compliance policy treats both under the same 'password length' rule.

How to eliminate wrong answers

Option A is wrong because the user reports Windows Defender Firewall is active, and the question states it is active, so this is not the cause of non-compliance. Option B is wrong because Secure Boot is explicitly enabled on the device, as stated in the scenario. Option C is wrong because the build number 19042.985 is above the required minimum version 19041.0, so the OS version meets the compliance requirement.

217
MCQhard

You are troubleshooting a Windows 11 device that fails to enroll in Intune via Group Policy. The device is domain-joined and you have configured the 'Enable automatic MDM enrollment using default Azure AD credentials' GPO. The user has a valid Microsoft 365 license. What is the most likely reason for the failure?

A.The device is not registered in Azure AD.
B.The GPO is not linked to the correct organizational unit.
C.The user does not have an Intune license assigned.
D.The device does not have a service connection point configured.
AnswerA

Correct. The device must be registered in Azure AD (Hybrid Azure AD Join) for the GPO to trigger automatic MDM enrollment. Domain-join alone is insufficient.

Why this answer

For the 'Enable automatic MDM enrollment using default Azure AD credentials' GPO to succeed, the device must be registered in Azure AD. Since the device is only domain-joined and no Azure AD registration has occurred, the enrollment fails. Option B is incorrect because the GPO is configured correctly; if it were not linked, it would not apply at all.

Option C is incorrect because the user has a valid Microsoft 365 license that includes Intune. Option D is incorrect because a service connection point is used for Configuration Manager co-management, not for this GPO.

218
MCQmedium

Refer to the exhibit. A Windows 10 device is enrolled in Intune and has the above compliance policy assigned. The device reports as non-compliant. The device has TPM version 2.0, Secure Boot enabled, and a password of 8 characters. Which of the following is the most likely reason for non-compliance?

A.The OS version is outside the allowed range.
B.The device does not have a TPM chip.
C.Secure Boot is not enabled.
D.The password length is less than 6 characters.
AnswerA

The policy restricts OS version; the device likely has a newer build.

Why this answer

The compliance policy likely specifies a minimum OS version requirement, such as Windows 10 22H2 or a specific build number. Since the device reports as non-compliant despite meeting TPM 2.0, Secure Boot, and password length requirements, the most probable cause is that the OS version is below the allowed minimum. Intune evaluates OS version against the 'Minimum OS version' setting in the compliance policy, and failure to meet this threshold results in non-compliance.

Exam trap

The trap here is that candidates assume TPM, Secure Boot, or password length are the most common compliance failures, but the OS version check is often overlooked as a strict requirement that can cause non-compliance even when all hardware security features are present.

How to eliminate wrong answers

Option B is wrong because the exhibit states the device has TPM version 2.0, so a missing TPM chip is not the issue. Option C is wrong because the exhibit explicitly states Secure Boot is enabled, so this requirement is satisfied. Option D is wrong because the password length of 8 characters exceeds the typical minimum of 6 characters required by Intune compliance policies, so password length is not the cause.

219
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with TPM 2.0 and UEFI Secure Boot enabled can enroll. Which configuration profile setting should you configure?

A.Create a Conditional Access policy requiring compliant devices
B.Configure a BitLocker policy in Endpoint Security
C.Set a compliance policy for device health
D.Enable Device Health Attestation (DHA) in enrollment restrictions
AnswerD

DHA verifies TPM and Secure Boot before enrollment.

Why this answer

Device Health Attestation (DHA) in enrollment restrictions allows you to block enrollment for devices that do not meet specific hardware security requirements, such as TPM 2.0 and UEFI Secure Boot enabled. When configured, Intune verifies these attestation claims during the enrollment process and rejects non-compliant devices before they can enroll. This is the only setting that enforces hardware prerequisites at the enrollment stage, not after the device is already managed.

Exam trap

The trap here is that candidates confuse post-enrollment compliance policies (which only mark devices non-compliant) with enrollment restrictions (which block enrollment entirely), leading them to choose Option C instead of D.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy requiring compliant devices operates after enrollment, checking compliance status during resource access, not blocking enrollment itself. Option B is wrong because a BitLocker policy in Endpoint Security configures encryption settings on already-enrolled devices and does not enforce TPM or Secure Boot requirements during enrollment. Option C is wrong because a compliance policy for device health evaluates devices after they are enrolled and can mark them non-compliant, but it does not prevent enrollment from occurring in the first place.

220
MCQeasy

You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

A.Managed Browser app.
B.iOS/iPadOS LOB app.
C.iOS/iPadOS store app.
D.Volume Purchase Program (VPP) app.
AnswerB

LOB app type supports custom enterprise-signed apps.

Why this answer

An iOS/iPadOS LOB app deployment in Intune is specifically designed for line-of-business apps that are signed with an enterprise certificate and distributed internally. This method allows you to upload the .ipa file directly to Intune and deploy it to company-owned devices without requiring the Apple App Store or a Volume Purchase Program.

Exam trap

The trap here is that candidates often confuse LOB app deployment with VPP apps, mistakenly thinking that any app not from the public store must use VPP, but VPP is only for App Store apps, while LOB apps are for enterprise-signed .ipa files uploaded directly to Intune.

How to eliminate wrong answers

Option A is wrong because the Managed Browser app is a specific Intune policy for deploying Microsoft Edge or a managed browser configuration, not a method for deploying custom LOB apps. Option C is wrong because an iOS/iPadOS store app deployment requires the app to be publicly available in the Apple App Store, which does not apply to a custom LOB app signed with an enterprise certificate. Option D is wrong because a Volume Purchase Program (VPP) app is used for purchasing and deploying App Store apps in bulk with managed licenses, not for sideloading enterprise-signed LOB apps.

221
MCQhard

Refer to the exhibit. You have created the compliance policy shown in JSON format. The policy is assigned to a group containing Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.1) is showing as noncompliant. What is the most likely reason?

A.The device does not have BitLocker encryption enabled.
B.The device does not have a password set.
C.The device OS version exceeds the maximum allowed version.
D.The password type is not set to alphanumeric.
AnswerC

The maximum version is 10.0.22621.0, and the device is 22621.1, which is higher.

Why this answer

The compliance policy sets a maximum OS version. The device's OS version (10.0.22621.1) is higher than the maximum allowed version specified in the policy, causing the device to be marked as noncompliant. Therefore, option C is correct.

Exam trap

The trap is that candidates may assume a lower build number means the device is under the maximum, but the policy's maximum is set to an even lower build number, so the device's version actually exceeds it.

How to eliminate wrong answers

Option A is wrong because the JSON policy does not include any BitLocker settings; it only defines OS version requirements and password policies, so BitLocker encryption is not evaluated. Option B is wrong because the policy does not require a password; it only specifies password type and length, but the 'password required' setting is not present in the JSON, so a missing password would not cause noncompliance. Option D is wrong because the policy does not specify a password type; the JSON only includes 'passwordMinimumLength' and 'passwordRequiredType' is not defined, so the password type is not evaluated.

222
MCQhard

You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?

A.Noncompliant because passwordRequired is true and no password set.
B.Noncompliant because storage encryption is not enabled.
C.Noncompliant because OS version is not within range.
D.Compliant
AnswerA

The policy requires a password, and the device has none.

Why this answer

The device is noncompliant due to the passwordRequired policy setting being set to true while no password is configured on the device. In Microsoft Intune, compliance policies evaluate each setting independently; if a required setting like passwordRequired is not met, the device is marked noncompliant regardless of other compliant settings. The OS version 10.0.19043.1234 is within a supported range, and storage encryption is not evaluated unless explicitly required by a policy, so only the missing password triggers noncompliance.

Exam trap

The trap here is that candidates assume a device is compliant if most settings are met, but Microsoft Intune evaluates each compliance policy setting independently, and a single failure—such as missing a password—results in overall noncompliance.

How to eliminate wrong answers

Option B is wrong because storage encryption is not a default compliance requirement for Windows 10 devices; it must be explicitly configured in a compliance policy, and the question states only password requirements are noncompliant. Option C is wrong because OS version 10.0.19043.1234 corresponds to Windows 10 21H1, which is within the supported range for Intune compliance policies, and no OS version range issue is indicated. Option D is wrong because the device fails the passwordRequired setting, which is a mandatory compliance check, so it cannot be marked compliant.

223
MCQeasy

A company is implementing Windows Hello for Business and wants to use certificate-based authentication. They have an on-premises Active Directory and are using Azure AD Connect for hybrid identity. Which prerequisites must be met to support certificate-based Windows Hello for Business?

A.All users must have the Microsoft Authenticator app installed.
B.Conditional Access policies must be configured to require Windows Hello for Business.
C.An enterprise certification authority (CA) must be deployed and all devices must be Azure AD joined or hybrid Azure AD joined.
D.All users must be configured for passwordless sign-in.
AnswerC

Certificate-based Windows Hello requires a CA and hybrid or Azure AD joined devices.

Why this answer

Certificate-based Windows Hello for Business requires an enterprise PKI to issue and validate certificates for authentication. Devices must be Azure AD joined or hybrid Azure AD joined to enroll these certificates and support the certificate trust model. On-premises Active Directory and Azure AD Connect provide the hybrid identity foundation, but the CA and appropriate device join state are the critical prerequisites.

Exam trap

The trap here is that candidates often confuse the prerequisites for certificate-based Windows Hello for Business with those for passwordless sign-in or MFA, mistakenly thinking that the Authenticator app or Conditional Access policies are required, when in fact the core requirement is an enterprise CA and the correct device join state.

How to eliminate wrong answers

Option A is wrong because the Microsoft Authenticator app is used for phone-based MFA or passwordless phone sign-in, not for certificate-based Windows Hello for Business, which relies on a PKI and device certificates. Option B is wrong because Conditional Access policies are used to enforce sign-in risk or compliance requirements, not to establish the infrastructure prerequisites for certificate-based Windows Hello for Business; the CA and device join state must exist first. Option D is wrong because passwordless sign-in is a broader concept that can be achieved via FIDO2 security keys or phone sign-in, but certificate-based Windows Hello for Business specifically requires a CA and does not mandate that all users be configured for passwordless sign-in.

224
MCQmedium

Your company has iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot remove the Microsoft Intune Company Portal app from their devices. What should you configure?

A.Configure an App Configuration policy for Company Portal.
B.Configure an App Protection policy for Company Portal.
C.Configure a Required app assignment with removal prevention.
D.Configure a Device Compliance policy to require Company Portal installation.
AnswerC

Required apps with removal prevention prevent users from removing the app.

Why this answer

Configuring a Required app assignment with removal prevention in Microsoft Intune ensures that the Company Portal app is installed as a required app and users cannot uninstall it. This setting is specifically designed to prevent removal of managed apps on iOS/iPadOS devices enrolled in Intune, leveraging the MDM channel to enforce the policy.

Exam trap

The trap here is that candidates confuse App Protection policies (which control data behavior) with app assignment settings (which control installation and removal), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because App Configuration policies are used to supply custom settings or managed app configuration to apps, not to prevent uninstallation. Option B is wrong because App Protection policies (MAM) manage data protection and access control for apps, but they do not control app removal at the device level. Option D is wrong because Device Compliance policies check device health and configuration but cannot enforce app installation or prevent removal; they only mark devices as non-compliant if the app is missing.

225
MCQeasy

You need to ensure that users can access corporate resources on their personal iOS devices only if they are jailbroken. Which Intune policy should you configure?

A.App Protection Policy
B.Device Configuration Policy
C.Device Compliance Policy
D.Conditional Access Policy
AnswerC

Correct. Compliance policies can detect jailbroken devices.

Why this answer

Device Compliance Policy in Microsoft Intune allows you to set rules that devices must meet to be considered compliant, including a jailbreak detection rule for iOS devices. When a device is detected as jailbroken, you can mark it as non-compliant and then use Conditional Access to block access to corporate resources. This directly addresses the requirement to control access based on jailbreak status.

Exam trap

The trap here is that candidates often confuse Device Compliance Policy with Conditional Access Policy, thinking that Conditional Access itself performs the jailbreak detection, when in fact it only enforces the compliance status reported by the Device Compliance Policy.

How to eliminate wrong answers

Option A is wrong because App Protection Policies (APP) manage how data is handled within managed apps (e.g., preventing copy/paste or requiring PIN) and do not include jailbreak detection or device-level compliance checks. Option B is wrong because Device Configuration Policies are used to configure device settings (e.g., Wi-Fi, VPN, email profiles) and do not evaluate or enforce compliance based on jailbreak status. Option D is wrong because Conditional Access Policy is an Azure AD feature that enforces access controls based on signals like device compliance, but it cannot directly detect jailbreak status; it relies on a Device Compliance Policy to provide that signal.

Page 2

Page 3 of 13

Page 4