Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 226–300

556 questions total · 8pages · All types, answers revealed

Page 3

Page 4 of 8

Page 5
226
MCQmedium

Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?

A.The devices are not enrolled in Microsoft Intune.
B.The Microsoft Defender for Endpoint sensor is not installed or configured correctly.
C.The devices are not compliant with conditional access policies.
D.The devices have lost connectivity to the internet.
AnswerB

A missing or misconfigured Microsoft Defender for Endpoint sensor directly prevents telemetry from reaching the service, which is why devices appear inactive. Onboarding requires the sensor to be installed and running, with correct configuration, so any gap in that chain halts health reporting regardless of network or licensing state.

Why this answer

The Microsoft Defender for Endpoint sensor is the core component that collects and reports security telemetry from Windows 10 devices to the Defender for Endpoint cloud service. If the sensor is not installed, is missing, or is misconfigured (e.g., due to a corrupted installation or incorrect onboarding script), the device will appear as inactive in the Microsoft 365 Defender portal, even if the device is otherwise healthy and connected.

Exam trap

The trap here is that candidates often confuse device enrollment (Intune) with sensor onboarding, assuming that a device must be managed by Intune to report to Defender for Endpoint, when in fact any Windows 10 device can be onboarded via a simple script or GPO.

How to eliminate wrong answers

Option A is wrong because enrollment in Microsoft Intune is not a prerequisite for Defender for Endpoint reporting; devices can be onboarded via Group Policy, local script, or other methods without Intune. Option C is wrong because conditional access compliance policies control access to cloud apps, not the reporting of security health to Defender for Endpoint; a non-compliant device can still report telemetry. Option D is wrong because while internet connectivity is required for the sensor to communicate with the cloud, the question states some devices are inactive, not all; if connectivity were the issue, all devices would likely be affected, and the sensor would still attempt to report (showing as 'misconfigured' rather than 'inactive').

227
MCQeasy

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that devices automatically receive quality updates and feature updates according to a schedule you define, with the ability to pause updates. What should you configure?

A.Compliance policies for Windows 10 devices.
B.Endpoint security policies for update management.
C.Device configuration profiles for Windows Update for Business.
D.Windows Update rings in Intune.
AnswerD

Windows Update rings in Intune allow you to configure update settings such as deferral periods, active hours, and pause options for quality and feature updates. They are designed to schedule and control updates on Windows devices. This is the correct choice to meet the requirement of scheduled updates with pause capability.

Why this answer

Windows Update rings in Intune are specifically designed to manage and schedule Windows updates, including quality and feature updates. They provide settings for deferral, deadlines, active hours, and the ability to pause updates. This directly addresses the requirement to schedule updates and allow pausing.

Other options do not offer the same level of update control.

Exam trap

The trap here is assuming that compliance policies or configuration profiles can schedule updates, when update rings are the dedicated feature for this purpose.

228
Multi-Selecthard

Your organization is implementing a zero-trust security model using Microsoft Intune. Devices must be compliant before accessing corporate resources. You need to deploy compliance policies for Windows 10 devices that require BitLocker encryption and a minimum OS version. Which two policy settings should you configure? (Choose two.)

Select 2 answers
A.Minimum OS version.
B.Require device health attestation.
C.Require firewall (Windows Defender Firewall).
D.Require encryption of data storage on device.
E.Maximum OS version.
AnswersA, D

Minimum OS version directly satisfies the stem's requirement for a baseline OS build on Windows 10 devices. Compliance policies evaluate this attribute through Intune's device compliance engine, marking devices non-compliant when their reported build falls below the configured threshold, which Conditional Access then enforces alongside BitLocker encryption.

Why this answer

The 'Minimum OS version' setting in a Windows 10 compliance policy ensures that devices must be running at least a specified build number (e.g., 10.0.19041 for Windows 10 20H1). This directly enforces the zero-trust requirement that only devices with a supported, up-to-date OS can access corporate resources, reducing exposure to known vulnerabilities. Option D is correct because the 'Require encryption of data storage on device' setting mandates BitLocker encryption on the system drive, which is a core data protection control in a zero-trust model.

Exam trap

The trap here is that candidates often confuse 'Require encryption of data storage on device' with 'Require device health attestation,' mistakenly thinking health attestation covers encryption, when in fact health attestation focuses on boot integrity and does not enforce BitLocker status.

229
MCQmedium

You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?

A.Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant'. Then, in the compliance policy, set the 'Action for noncompliance' to 'Mark device noncompliant' after 30 minutes.
B.Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute session lifetime.
C.Create a Conditional Access policy that requires compliant devices, and configure the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute grace period.
D.In the compliance policy, set 'Mark device noncompliant' to 30 minutes and assign the policy to all users.
AnswerA

This approach correctly uses Conditional Access to block noncompliant devices and leverages the compliance policy's noncompliance action schedule to delay marking the device noncompliant for 30 minutes. During that window, the device is still considered compliant, so access is allowed. After 30 minutes, the device is marked noncompliant and Conditional Access blocks access.

Why this answer

To allow a grace period before blocking access, you must delay the device being marked noncompliant. Conditional Access itself does not provide a grace period. By configuring the compliance policy to mark the device noncompliant after 30 minutes, the device remains compliant during that time, and Conditional Access continues to allow access.

After the delay, the device becomes noncompliant and access is blocked.

Exam trap

The trap here is assuming that Conditional Access has a built-in grace period setting when it only enforces compliance status as evaluated by Intune.

230
MCQeasy

You are deploying Microsoft Defender for Endpoint to Windows 10 devices managed by Microsoft Intune. After onboarding, you need to verify that the sensor is running. Which cmdlet should you use on the device?

A.Get-Service -Name WinDefend
B.Get-DefenderEndpoint
C.Get-MpComputerStatus
D.Get-Service -Name Sense
AnswerD

Get-Service -Name Sense queries the Sense service, which hosts the Microsoft Defender for Endpoint sensor on Windows 10. Checking its Status confirms the sensor is running, directly satisfying the stem's verification requirement after Intune onboarding. Other cmdlets inspect configuration or events rather than live service state.

Why this answer

The correct cmdlet is Get-Service -Name Sense because the Microsoft Defender for Endpoint sensor runs as a Windows service named 'Sense' (Microsoft Defender Advanced Threat Protection Service). Checking this service confirms the sensor is installed and running, which is the standard verification step after onboarding devices to Defender for Endpoint.

Exam trap

The trap here is that candidates confuse the Defender for Endpoint sensor service (Sense) with the Windows Defender Antivirus service (WinDefend) or mistakenly use a non-existent cmdlet like Get-DefenderEndpoint, leading them to choose an incorrect verification method.

How to eliminate wrong answers

Option A is wrong because Get-Service -Name WinDefend checks the Windows Defender Antivirus service (WinDefend), not the Defender for Endpoint sensor. Option B is wrong because Get-DefenderEndpoint is not a valid PowerShell cmdlet; the correct cmdlet for checking sensor status is Get-MpComputerStatus or Get-Service -Name Sense. Option C is wrong because Get-MpComputerStatus retrieves antimalware status and definitions, not the running state of the Defender for Endpoint sensor service.

231
MCQhard

You are designing an app protection policy (APP) for Microsoft 365 mobile apps accessing corporate data on iOS devices. The security team requires that when a user opens a work document in the Microsoft Word app, the user must authenticate with Face ID or a passcode. Which setting should you configure?

A.Require PIN or Face ID for access (iOS)
B.Block managed apps from running on jailbroken devices
C.Encrypt app data
D.Require app PIN when device PIN is not set
AnswerA

This setting enforces biometric or passcode authentication at app launch, directly satisfying the security team's requirement that opening a work document in Word triggers Face ID or passcode verification. It applies at the app layer via Intune app protection policy, independent of device-level enrolment, so corporate data stays protected on iOS.

Why this answer

The 'Require PIN or Face ID for access (iOS)' setting enforces biometric or passcode authentication specifically when a user launches a managed app or resumes it from the background. This directly meets the requirement that opening a work document in Word triggers Face ID or passcode verification, as the app protection policy (APP) intercepts the app launch and prompts for authentication before granting access to corporate data.

Exam trap

The trap here is that candidates confuse 'Require PIN or Face ID for access' with 'Require app PIN when device PIN is not set', mistakenly thinking the latter covers all scenarios, when in fact it only applies conditionally when the device lacks a PIN.

How to eliminate wrong answers

Option B is wrong because 'Block managed apps from running on jailbroken devices' prevents the app from running at all on compromised devices but does not enforce per-session authentication like Face ID or passcode. Option C is wrong because 'Encrypt app data' ensures data-at-rest encryption on the device but does not require user authentication at app launch. Option D is wrong because 'Require app PIN when device PIN is not set' only applies a PIN if the device lacks a PIN, whereas the requirement is to always require Face ID or passcode regardless of device PIN status.

232
Multi-Selectmedium

You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy to require that devices have a specific minimum OS version and that BitLocker is enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require antivirus
B.Minimum OS version
C.Require Secure Boot
D.Require code integrity
E.Require BitLocker
AnswersB, E

The Minimum OS version setting allows you to specify the oldest Windows build that is considered compliant. Devices running an older build are marked noncompliant. This enforces the requirement for a specific minimum OS version. You can enter a version like 10.0.22000.1000 for Windows 11. This setting is found under Device Properties in the compliance policy.

Why this answer

To enforce a minimum OS version and BitLocker, you configure the Minimum OS version setting and the Require BitLocker setting in the Windows compliance policy. These settings directly map to the requirements. Secure Boot, code integrity, and antivirus are separate security controls that do not address the specific needs of the scenario.

Exam trap

The trap here is adding extra security settings that seem related to device health but are not the specific requirements for minimum OS version and BitLocker.

233
Multi-Selectmedium

You are planning to deploy Windows 11 devices using Windows Autopilot in Microsoft Intune. The company requires that the devices are Microsoft Entra joined and that the enrollment process includes the installation of required applications and configuration of device settings. You need to identify which two components are required to achieve this. (Choose two.)

Select 2 answers
A.Enrollment Status Page (ESP).
B.Autopilot deployment profile.
C.Microsoft Intune Connector for Active Directory.
D.Windows Configuration Designer package.
E.Device-based conditional access policy.
AnswersA, B

The Enrollment Status Page (ESP) is used to track the installation of applications and configuration of device settings during Autopilot enrollment. It ensures that these tasks complete before the user accesses the desktop. The requirement states that enrollment must include installation of required applications and configuration of device settings; ESP is the component that monitors and enforces this. Without ESP, the user might reach the desktop before these critical tasks are complete, leading to a poor experience.

Why this answer

The Autopilot deployment profile defines the join type and OOBE settings, ensuring the device joins Microsoft Entra ID. The Enrollment Status Page (ESP) ensures that required applications and configurations are applied before the user reaches the desktop. Together, they meet the requirement of Microsoft Entra join with app installation and device configuration during enrollment.

The other options are either for hybrid join, alternative provisioning, or post-enrollment security.

Exam trap

The trap here is assuming that the Intune Connector for Active Directory is needed for all Autopilot deployments, but it is only for hybrid Azure AD join.

234
MCQeasy

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?

A.Fresh Start the device
B.Reset the device
C.Retire the device
D.Wipe the device
AnswerD

The wipe action in Microsoft Intune performs a factory reset on the device, removing all data including corporate and personal information, and it can be initiated remotely. For lost or stolen devices, this ensures that no data remains accessible. It also supports a option to retain enrollment state and user account for Autopilot, but in a lost scenario, a full wipe is appropriate to protect corporate data.

Why this answer

The wipe action remotely resets the device to factory settings, removing all data and preventing access. This is the correct choice for lost or stolen devices because it ensures corporate data is not accessible. Retire, reset, and Fresh Start do not provide the same immediate data protection and remote wipe capability for lost devices.

Exam trap

The trap here is confusing retire with wipe; retire only removes corporate data but leaves personal data and does not prevent device access.

235
MCQeasy

You are the Microsoft 365 Endpoint Administrator for Contoso. The company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when devices are enrolled, they automatically receive a set of configuration settings without manual intervention. The settings include a custom Start menu layout and a set of allowed background apps. What should you create in Intune to achieve this?

A.An app protection policy
B.A compliance policy
C.A device configuration profile
D.A Windows Autopilot deployment profile
AnswerC

A device configuration profile in Intune allows you to configure settings such as Start menu layout and restricted apps on Windows devices. After assignment to a group, the settings are applied automatically during enrollment or check-in, meeting the requirement for automatic application without manual intervention.

Why this answer

Device configuration profiles in Microsoft Intune are designed to deliver settings to devices. They can configure Start menu layout, restrict apps, and many other settings. Once assigned, the settings are applied automatically, satisfying the requirement to avoid manual intervention.

Compliance policies assess, Autopilot profiles customize OOBE, and app protection policies secure data within apps, none of which apply configuration settings.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance evaluates settings while configuration applies them.

236
MCQeasy

You administer Microsoft Intune for Northwind Traders. The security team wants to prevent users from enrolling personally owned Windows 10 devices while still allowing corporate-owned devices to enroll. You need to configure a device enrollment restriction that blocks personal Windows devices. Which platform setting should you modify?

A.Windows Mobile
B.Windows (MDM)
C.Windows (ConfigMgr)
D.Windows (MDM) under Corporate Device Identifiers
AnswerB

Device enrollment restrictions in Intune have a per-platform configuration, and Windows devices enroll as Windows (MDM). Setting the Windows (MDM) platform to Block for personally owned devices prevents users from enrolling personal Windows 10 devices while still allowing corporate devices to enroll. This is the correct platform to modify for the stated requirement.

Why this answer

Intune device enrollment restrictions are configured per platform. Windows 10 and Windows 11 devices that enroll in MDM use the Windows (MDM) platform. To block personal Windows devices while allowing corporate ones, an administrator sets the Windows (MDM) platform to Block for personally owned devices.

Other platform entries such as Windows (ConfigMgr) or Windows Mobile do not apply to standard Windows 10 MDM enrollment.

Exam trap

The trap here is confusing Windows (ConfigMgr) or Windows Mobile with the platform that governs standard Windows 10 MDM enrollment, which is Windows (MDM).

237
MCQhard

An organization uses Microsoft Intune to manage Windows 10 devices. They deploy a PowerShell script via Intune to install a custom application. The script runs successfully on some devices but fails on others with error code 0x80070002. What is the most likely cause?

A.The script execution exceeds the 60-minute timeout.
B.The user does not have local administrator privileges on the failing devices.
C.The script references a file path that does not exist on the failing devices.
D.The PowerShell execution policy is set to Restricted on the failing devices.
AnswerC

Error 0x80070002 is ERROR_FILE_NOT_FOUND, raised when the script's referenced path is absent. Devices lacking that file, folder or mapped location fail, while others succeed, so the missing path is the cause rather than permissions or execution policy.

Why this answer

Error code 0x80070002 translates to 'The system cannot find the file specified' — a classic Windows error indicating a missing file or path. When an Intune-deployed PowerShell script fails with this code on some devices, the most likely cause is that the script references a file path (e.g., an installer, config file, or dependency) that exists on some devices but not on the failing ones. This is a path/dependency issue, not a permissions or policy issue.

Exam trap

MD-102 often tests whether candidates can map Windows error codes to root causes — 0x80070002 is specifically 'file not found', so options about permissions or execution policy are distractors.

How to eliminate wrong answers

Option A is wrong because a timeout would produce a different error (typically 0x800705B4 or a timeout-specific code), not 0x80070002, and the script would fail on all devices if it consistently exceeded 60 minutes. Option B is wrong because lack of local admin privileges typically yields access-denied errors (0x80070005), not file-not-found. Option D is wrong because a Restricted execution policy would produce a policy-related error (e.g., 'cannot be loaded because running scripts is disabled'), not 0x80070002.

238
MCQhard

You are deploying Windows 11 devices using Windows Autopilot. Some devices are not registering in Microsoft Intune. You have verified that the hardware hashes are uploaded correctly. What is the most likely cause?

A.The devices are not connected to the internet.
B.The hardware hashes are invalid.
C.The devices are not running Windows 11 Pro or Enterprise.
D.The user does not have an Intune license.
AnswerA

Without network connectivity during the out-of-box experience, the Autopilot profile cannot contact the Microsoft Intune enrolment service, so the device never registers even though its hardware hash exists. Autopilot enrolment depends entirely on cloud communication; offline devices simply skip the enrolment phase and fall through to the local setup screens.

Why this answer

Windows Autopilot requires internet connectivity during the out-of-box experience (OOBE) to contact the Autopilot deployment service and Microsoft Intune. Without internet access, the device cannot download the Autopilot profile or register in Intune, even if hardware hashes are correctly uploaded. The hardware hash upload is a separate step that does not guarantee the device can later connect to the service.

Exam trap

The trap here is that candidates often assume hardware hash upload is the only prerequisite for Autopilot registration, overlooking the critical requirement for internet connectivity during the device's initial boot process.

How to eliminate wrong answers

Option B is wrong because the question explicitly states that the hardware hashes are uploaded correctly, so invalid hashes are not the issue. Option C is wrong because Windows Autopilot supports Windows 11 Pro, Enterprise, and Education editions; the device not registering is not caused by running an unsupported edition. Option D is wrong because the user license is not required for device registration via Autopilot; device enrollment occurs before user sign-in, and Intune licenses are only needed for user-based management after enrollment.

239
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom .pkg app to all macOS devices. What app type should you create in Intune?

A.macOS app (line-of-business)
B.Windows app (Win32)
C.Web link
D.iOS app (line-of-business)
AnswerA

The macOS app (line-of-business) type accepts .pkg and .dmg files, supporting custom packaging and uninstall scripts. Other macOS app types target App Store or built-in packages, so line-of-business is required for a custom .pkg deployment.

Why this answer

To deploy a custom .pkg app to macOS devices via Microsoft Intune, you must create a macOS line-of-business (LOB) app. LOB apps are designed for sideloading custom or in-house applications that are not available in the public app store, and Intune supports .pkg and .dmg formats for macOS LOB deployment. This app type allows you to upload the .pkg file directly and assign it to devices, handling installation through the Intune management agent.

Exam trap

The trap here is that candidates may confuse 'line-of-business' as a generic term and select the iOS LOB option, forgetting that each platform (macOS, iOS, Windows) has its own specific LOB app type in Intune.

How to eliminate wrong answers

Option B is wrong because 'Windows app (Win32)' is a deployment type for Windows applications using .exe or .msi installers, and it has no relevance to macOS device management. Option C is wrong because 'Web link' creates a shortcut to a URL on the device's home screen or portal, not an actual app installation, and cannot deploy a .pkg file. Option D is wrong because 'iOS app (line-of-business)' is used for deploying custom .ipa files to iOS devices, not macOS, and the platform-specific app types are not interchangeable.

240
MCQhard

You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?

A.Create a device enrollment restriction in Intune that allows only the security group and enable Windows Autopilot for those devices.
B.Configure automatic MDM enrollment in the Microsoft Entra ID mobility settings and assign the Intune Enrollment scope to the security group.
C.Configure a Conditional Access policy that requires compliant devices and assign it to the security group.
D.Enable automatic enrollment in Intune and set the MDM user scope in Microsoft Entra ID to the security group.
AnswerD

Automatic MDM enrollment is enabled from the Intune portal, and the Microsoft Entra ID mobility settings include an MDM user scope that can be set to a specific security group. Setting the scope to that group ensures only its members are automatically enrolled in Intune when they join devices to Microsoft Entra ID, meeting both requirements.

Why this answer

Automatic enrollment is turned on in the Intune admin center, while the user scope that determines who is eligible is configured in the Microsoft Entra ID mobility settings. Pointing the MDM user scope at the chosen security group restricts automatic Intune enrollment to those users, which is exactly what the scenario requires.

Exam trap

The trap here is confusing enrollment restrictions or Conditional Access with the MDM user scope, which is the actual control for who can automatically enroll.

241
MCQhard

Refer to the exhibit. You have configured the compliance policy shown above. A user reports that their Windows 11 device is compliant with all settings except the threat level. The device has no threat protection agent installed. What will happen when the user tries to access corporate resources?

A.Access is granted but the user receives a warning notification.
B.Access is blocked only after a 24-hour grace period.
C.Access is blocked immediately.
D.Access is granted because the device meets all other compliance requirements.
AnswerC

Without a threat protection agent, Microsoft Entra ID cannot evaluate the threat level, so the device fails the compliance policy and is marked non-compliant. Conditional Access then blocks access to corporate resources immediately, satisfying the stem's requirement that the device lacks any agent capable of reporting threat state.

Why this answer

The compliance policy requires a minimum threat level, which cannot be evaluated because the device has no threat protection agent installed. In Microsoft Intune, when a required compliance setting cannot be assessed (e.g., no agent), the device is treated as non-compliant, and access is blocked immediately. There is no grace period for missing required agents, and conditional access enforces the block at the time of the access request.

Exam trap

The trap here is that candidates assume a grace period applies to all non-compliance scenarios, but grace periods are only applicable to specific settings (like password expiration) and not to missing required agents or unassessable settings.

How to eliminate wrong answers

Option A is wrong because access is not granted with a warning; Intune conditional access blocks non-compliant devices immediately, and a warning notification is only sent if the device is compliant but has a warning-level issue. Option B is wrong because a 24-hour grace period applies only to specific non-compliance actions (e.g., password expiration) when configured in a compliance policy, not to missing required agents like a threat protection agent. Option D is wrong because meeting all other compliance requirements does not override the specific threat level requirement; the device is non-compliant overall, and access is blocked.

242
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, the user receives a notification email, and the device is automatically retired after 30 days. The solution must minimize administrative effort. What should you configure?

A.A compliance policy with actions for non-compliance: send email to user at 0 days, and retire device at 30 days.
B.A Windows Update ring with a deadline of 30 days and an automatic retirement action.
C.A device configuration profile with a custom OMA-URI to send email and retire the device after 30 days.
D.An Intune device cleanup rule that retires devices after 30 days of inactivity and sends an email.
AnswerA

Compliance policies allow you to configure actions for non-compliance, including sending an email and retiring the device. You can set the email action to trigger immediately when the device becomes noncompliant, and schedule the retire action for 30 days later. This meets the requirement with minimal effort, as it is a single policy configuration.

Why this answer

Compliance policies are the correct tool to automate actions based on noncompliance. You can configure an action to send an email to the user immediately when the device becomes noncompliant, and another action to retire the device after 30 days. This requires only one policy and minimal administrative effort.

Exam trap

The trap here is thinking that update rings or cleanup rules can enforce compliance actions, when only compliance policies have actions for non-compliance.

243
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. A user reports that their device is not receiving critical security updates despite being compliant with all update policies. You verify that the device is online and communicating with Intune. Which action should you take to resolve the issue?

A.Verify that the device meets the minimum hardware requirements for the update.
B.Force a sync from the device via Intune Company Portal or Settings > Accounts > Access work or school.
C.Reassign the device to a different Update Ring policy that has no feature update deferral.
D.Review the Windows Update Rings policy assigned to the device and adjust the deferral settings for quality updates.
AnswerD

Quality update deferral settings in the assigned Windows Update Ring can postpone security patches even when the device is compliant and online. Reducing the deferral period allows the critical updates to install, addressing the reported delay.

Why this answer

The user's device is compliant and online, but not receiving critical security updates. The most likely cause is that the Windows Update Rings policy assigned to the device has a deferral period configured for quality updates, which delays the installation of security patches. Adjusting the deferral settings for quality updates to 0 days ensures that critical security updates are installed immediately upon release, resolving the issue without changing the feature update deferral.

Exam trap

The trap here is that candidates confuse 'force sync' with 'force update installation,' not realizing that a sync only retrieves policy and update metadata, but the deferral period still prevents the update from being offered until it expires.

How to eliminate wrong answers

Option A is wrong because minimum hardware requirements are checked by Windows Update itself before offering an update, and a device that is compliant with update policies would already meet those requirements; this is not a policy-related issue. Option B is wrong because forcing a sync only triggers the device to check for new policies and pending updates from Intune, but if the deferral period is still in effect, the sync will not cause the critical updates to be installed—they will remain deferred. Option C is wrong because reassigning to a different Update Ring policy that has no feature update deferral does not address the quality update deferral; feature update deferral controls major version upgrades, not critical security patches, and changing it would not resolve the delay in receiving quality updates.

244
MCQhard

A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?

A.The Intune service is experiencing an outage
B.The device is powered off or not connected to the internet
C.The device has conflicting policies from another MDM
D.The device's enrollment certificate has expired
AnswerB

Intune policies only reach a device when it checks in over the internet. A three-day-old check-in with the device still showing as Enrolled points to the device being powered off or offline, so it cannot contact the Intune service to receive configuration.

Why this answer

If the device is powered off or not connected to the internet, it cannot check in with Intune to receive new policies. Option A is wrong because an Intune service outage would affect multiple devices, not just one. Option C is wrong because conflicting policies would not prevent check-in; the device would still check in and report conflicts.

Option D is wrong because an expired enrollment certificate would prevent enrollment or cause immediate issues, not just a delayed check-in after three days.

245
MCQhard

You use Microsoft Intune to manage Windows 11 devices. You configure a Windows Update ring policy to defer quality updates by 7 days and feature updates by 60 days. A critical security update is released that must be installed immediately on all devices, bypassing the deferral. What should you configure?

A.Deploy a PowerShell script that runs the Windows Update client to install all available updates.
B.Create a new Windows Update ring policy with a deadline of 0 days and assign it to all devices.
C.Use expedited updates in Microsoft Intune to deploy the specific security update to all devices.
D.Modify the existing Windows Update ring policy to set the quality update deferral to 0 days.
AnswerC

Expedited updates allow administrators to deploy a specific Windows quality update immediately, bypassing deferrals and other update ring settings. This feature is designed for critical security updates that must be installed without delay. It targets devices directly and ensures the update is installed as soon as possible, meeting the requirement.

Why this answer

Expedited updates in Microsoft Intune are specifically designed to deploy a particular Windows quality update immediately, overriding deferrals and other update ring settings. This is the correct approach for critical security updates that cannot wait. Other methods either do not bypass deferrals or affect all updates rather than the specific one.

Exam trap

The trap here is assuming that changing a deferral or setting a deadline will force immediate installation, when only expedited updates bypass deferrals.

246
MCQmedium

You manage Windows 10 devices enrolled in Microsoft Intune. Users report that the Company Portal app is not installing required apps. You verify that the devices are compliant and checked in recently. What is the most likely cause?

A.The users are not members of the Azure AD group assigned to the required app.
B.The devices are not connected to a Wi-Fi network configured in Intune.
C.The devices are not compliant with the compliance policy.
D.The enrollment restrictions are blocking the devices from receiving apps.
AnswerA

Group membership drives Intune app assignment: if users are absent from the Microsoft Entra ID group targeted by the required app, the app never reaches their devices, regardless of compliance or check-in status. Since the devices are compliant and recently checked in, assignment targeting is the remaining constraint the stem leaves unsatisfied.

Why this answer

In Microsoft Intune, app deployment is based on Azure AD group assignments. Even if a device is compliant and has recently checked in, the required app will not install unless the user or device is a member of the Azure AD group that the app is assigned to. Intune evaluates group membership at each check-in to determine which apps should be pushed, so missing group membership is the most likely cause when compliance and connectivity are verified.

Exam trap

The trap here is that candidates often assume compliance or device connectivity is the primary blocker for app installation, overlooking that Intune's app delivery is strictly gated by Azure AD group membership, not by device health or network type.

How to eliminate wrong answers

Option B is wrong because Intune does not require a specific Wi-Fi network configured in Intune for app installation; apps can be delivered over any network connection, including cellular, as long as the device has internet access. Option C is wrong because the question explicitly states that devices are compliant, so non-compliance cannot be the cause. Option D is wrong because enrollment restrictions control which devices can enroll in Intune, not the delivery of apps to already enrolled devices; once enrolled, restrictions do not block app assignments.

247
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to implement a policy that requires devices to meet specific hardware and software conditions before they can access corporate email. The policy must evaluate the device's encryption status, OS version, and whether it has a firewall enabled. What should you create?

A.A Conditional Access policy that requires a compliant device.
B.An app protection policy that requires a PIN and blocks jailbroken devices.
C.A device configuration profile that enforces encryption, OS version, and firewall settings.
D.A device compliance policy that includes the required conditions, and then a Conditional Access policy that requires a compliant device.
AnswerD

A device compliance policy in Intune evaluates settings like BitLocker status, OS version, and firewall. Once the device is marked compliant, a Conditional Access policy can require a compliant device to grant access to email. This combination ensures devices meet the specified conditions before access is allowed.

Why this answer

To evaluate specific device conditions and control access, you must use a device compliance policy to assess the settings and a Conditional Access policy to enforce the requirement. The compliance policy checks encryption, OS version, and firewall; Conditional Access then blocks non-compliant devices from accessing email. This is the standard Intune and Microsoft Entra ID integration.

Exam trap

The trap here is assuming that Conditional Access alone can evaluate device settings; it only enforces compliance based on policies.

248
MCQeasy

A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?

A.The user's Intune license has expired.
B.The Outlook app is not installed on the device.
C.A compliance policy was updated requiring a newer OS version or additional security settings.
D.The device is not enrolled in Intune.
AnswerC

Intune evaluates compliance on device check-in, so a policy change adding a minimum OS version or stronger security settings marks the previously compliant iOS device non-compliant, blocking Outlook mobile access via conditional access until the device meets the new requirements.

Why this answer

Intune compliance policies are evaluated in real time when a user attempts to access corporate resources. If an administrator updates a policy to require a newer iOS version or additional security settings (e.g., passcode complexity, encryption), the device may become non-compliant even if it was previously compliant. The Outlook app checks device compliance via the Intune SDK and will block access if the device no longer meets the policy requirements, displaying the 'device not compliant' error.

Exam trap

The trap here is that candidates assume the error means the device is not enrolled or that the app is missing, but the question explicitly states the device is enrolled and compliant, so the most likely cause is a policy change that retroactively affects compliance status.

How to eliminate wrong answers

Option A is wrong because an expired Intune license would prevent the user from enrolling the device or accessing Intune-managed resources entirely, but the device is already enrolled and compliant, and the error specifically states non-compliance, not a licensing issue. Option B is wrong because if the Outlook app were not installed, the user would not be able to launch it or see an error within the app; the error is displayed by the app itself, confirming it is installed. Option D is wrong because the question explicitly states the device is enrolled in Intune and compliant, so the device is enrolled; the error is due to a change in compliance status, not enrollment status.

249
MCQmedium

A company uses Microsoft Intune to manage Windows 11 devices. You deploy a required Win32 app that installs a line-of-business tool. Two weeks later, the vendor releases a new version that must replace the old one. You need to ensure devices upgrade to the new version without user interaction and that the old version is removed first. What should you configure?

A.Deploy a PowerShell platform script that calls the vendor's installer and then deletes the old app registration.
B.Create a new Win32 app for the updated version and configure a supersedence relationship from the new app to the old app.
C.Create a new Win32 app for the updated version and assign it as available to the same group.
D.Update the existing Win32 app by uploading the new installer to the same app record.
AnswerB

Supersedence lets you define that a newer app replaces an older one, and you can choose to uninstall the previous version as part of the upgrade. Assigning the new app as required ensures targeted devices receive it automatically. This delivers a controlled, silent upgrade path that removes the old version first, which is exactly what the scenario requires.

Why this answer

Supersedence is the supported Intune mechanism for replacing one Win32 app with another. By defining the relationship from the new app to the old one and choosing to uninstall the previous version, you get a silent, managed upgrade. Assigning the new app as required ensures every targeted device transitions automatically, satisfying both the replacement and no-user-interaction requirements.

Exam trap

The trap here is editing the existing app record with new content, which updates the package but does not force already-installed devices to upgrade.

250
MCQeasy

Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?

A.A Microsoft Intune license assigned to the user
B.A VPN connection to the corporate network
C.An on-premises Active Directory domain
D.A Configuration Manager infrastructure
AnswerA

Intune enrolment is user-driven, so each enrolling user requires an Intune licence (included in EMS, Microsoft 365 E3/E5, or standalone) before the service accepts the device. Without this per-user assignment, enrolment fails at authentication, regardless of device compliance or network configuration.

Why this answer

A Microsoft Intune license assigned to the user is a prerequisite because Intune uses Azure Active Directory (Azure AD) for identity and access management. Without an Intune license (e.g., Microsoft 365 E3, E5, or standalone Intune license) assigned to the user, the device cannot authenticate and enroll via the Intune enrollment service, as the license is required to authorize the enrollment request and apply device management policies.

Exam trap

The trap here is that candidates often confuse on-premises prerequisites (like AD or VPN) with cloud-only requirements, mistakenly thinking corporate network connectivity or legacy infrastructure is needed for Intune enrollment, when in fact only an Azure AD identity and an Intune license are required.

How to eliminate wrong answers

Option B is wrong because a VPN connection to the corporate network is not required for Intune enrollment; Intune uses internet-based enrollment over HTTPS (port 443) to the Microsoft Intune service, and devices can enroll from anywhere without a VPN. Option C is wrong because an on-premises Active Directory domain is not a prerequisite; Intune enrollment relies on Azure AD for identity, and while hybrid Azure AD join can be used, a standalone on-premises AD domain is not required for basic Intune enrollment. Option D is wrong because a Configuration Manager infrastructure is not a prerequisite; Intune is a cloud-only MDM solution, and while co-management with Configuration Manager is possible, it is optional and not required for enrollment.

251
MCQhard

You configure a Windows 10 device compliance policy in Intune that requires 'Firewall' to be enabled. The device has Windows Defender Firewall enabled, but the device reports as non-compliant. You verify that the firewall is active. What is the most likely cause?

A.The firewall is configured to allow all inbound connections
B.The device uses a third-party firewall that Intune does not recognize
C.The firewall is enabled only on the Domain profile but not on Public or Private profiles
D.The device has multiple network adapters and the firewall is disabled on one
AnswerC

Intune's Firewall compliance rule evaluates all three Windows Defender Firewall profiles. Enabling the firewall only on the Domain profile leaves Public and Private profiles off, so the device reports non-compliant despite the firewall appearing active.

Why this answer

Intune's Firewall compliance setting evaluates Windows Defender Firewall across all three network profiles: Domain, Private, and Public. If the firewall is enabled only on the Domain profile but disabled on Private or Public, the device is reported as non-compliant even though the firewall appears active in some contexts. This is the most common cause of a false non-compliant report when the firewall is 'on'.

Exam trap

MD-102 often tests the misconception that 'firewall enabled' means a single toggle — candidates forget that Intune evaluates Domain, Private, and Public profiles independently and requires all three to be enabled.

How to eliminate wrong answers

Option A is wrong because allowing all inbound connections does not affect the compliance check — Intune only verifies that the firewall is enabled, not its rule configuration. Option B is wrong because Intune's built-in firewall compliance rule specifically checks Windows Defender Firewall status; a third-party firewall would cause non-compliance only if Defender Firewall itself is disabled, but the scenario states Defender Firewall is enabled. Option D is wrong because the compliance rule checks the firewall's overall state per profile, not per network adapter; a disabled firewall on one adapter would still be reflected in the profile state, but the more precise and common cause is a profile mismatch.

252
MCQhard

Refer to the exhibit. The JSON shows a compliance policy for Windows 10 devices. Devices that do not meet the policy are marked as non-compliant. Which diagnostic step would you take to identify why a specific device is non-compliant despite having BitLocker enabled?

A.Verify the compliance policy is assigned to the device's group.
B.Check the device's compliance status in Intune for details.
C.Review the device's hardware security features: Secure Boot and Code Integrity.
D.Modify the policy to remove the requireSecureBoot and requireCodeIntegrity settings.
AnswerC

Secure Boot and Code Integrity are separate device health attestation signals from BitLocker encryption status, so a device can have BitLocker enabled yet still fail the compliance policy if either is disabled or misconfigured. Reviewing these hardware security features identifies the specific setting causing non-compliance, satisfying the stem's requirement to diagnose why the device fails despite BitLocker.

Why this answer

The compliance policy JSON requires Secure Boot and Code Integrity in addition to BitLocker. Even if BitLocker is enabled, a device will be marked non-compliant if Secure Boot or Code Integrity is disabled or unsupported. Therefore, the correct diagnostic step is to review the device's hardware security features — Secure Boot and Code Integrity — to confirm they meet the policy requirements.

Exam trap

MD-102 often tests the assumption that BitLocker alone satisfies compliance — candidates forget that policies can require multiple settings, and a device fails if any single setting (like Secure Boot or Code Integrity) is not met.

How to eliminate wrong answers

Option A is wrong because if the policy were not assigned to the device's group, the device would not be evaluated against the policy at all and would not appear as non-compliant due to this policy — assignment issues produce a different symptom. Option B is wrong because checking compliance status in Intune shows the result but not the root cause; the question asks for the diagnostic step to identify why, and the status alone does not reveal that Secure Boot or Code Integrity is the failing setting. Option D is wrong because modifying the policy to remove the requirements is a remediation that weakens security, not a diagnostic step, and it does not identify why the device is non-compliant.

253
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?

A.Require device to be marked as compliant.
B.Require multi-factor authentication.
C.Require app protection policy.
D.Require device to be enrolled in Intune.
AnswerA

Require device to be marked as compliant makes Microsoft Entra ID conditional access grant Exchange Online access only when Intune reports the device compliant. It directly satisfies the stem's constraint that only compliant devices reach corporate email.

Why this answer

To ensure only compliant devices access Exchange Online, the Conditional Access policy must include the grant control 'Require device to be marked as compliant.' This control checks the device's compliance state in Intune and blocks access if the device is non-compliant, directly enforcing the requirement. It is the precise setting for compliance-based access.

Exam trap

MD-102 often tests the confusion between 'Require device to be marked as compliant' and 'Require device to be enrolled' — enrollment alone does not guarantee compliance, and only the compliance grant control enforces policy adherence.

How to eliminate wrong answers

Option B is wrong because requiring MFA verifies user identity but does not check device compliance, so a non-compliant device could still access email after MFA. Option C is wrong because app protection policies (MAM) protect app data on unmanaged devices but do not enforce device compliance for Exchange Online access. Option D is wrong because requiring Intune enrollment ensures the device is managed but does not guarantee it meets compliance policies; a device can be enrolled yet non-compliant.

254
MCQmedium

Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?

A.Replace the device's motherboard.
B.Enable the TPM in the device's BIOS settings.
C.Assign a grace period for the device.
D.Remove the tpmRequired setting from the compliance policy.
AnswerB

Compliance evaluation queries the TPM through Windows, which reports nothing when the chip is disabled in firmware. Enabling TPM in BIOS exposes the 2.0 chip to the OS, letting the policy detect it and clear the 'TPM not found' reason.

Why this answer

The device has a TPM 2.0 chip that is disabled in BIOS. Enabling the TPM in BIOS allows the device to report its TPM presence to Microsoft Intune, satisfying the compliance policy's tpmRequired setting. No hardware replacement, grace period, or policy modification is needed when the TPM is physically present but disabled.

Exam trap

The trap here is that candidates may assume a 'TPM not found' error indicates missing hardware, leading them to choose motherboard replacement or policy removal, rather than recognizing that a disabled TPM in BIOS is a common configuration issue that can be resolved without hardware changes.

How to eliminate wrong answers

Option A is wrong because replacing the motherboard is unnecessary when the TPM chip is already present and functional; the issue is only that it is disabled in BIOS. Option C is wrong because assigning a grace period would only delay enforcement of the non-compliance, not resolve the underlying TPM detection failure. Option D is wrong because removing the tpmRequired setting from the compliance policy would lower the security baseline, whereas the correct action is to enable the existing TPM hardware.

255
MCQeasy

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?

A.A device compliance policy with a required passcode length of 6.
B.A device configuration profile with a passcode payload.
C.An app protection policy for Microsoft Outlook.
D.A conditional access policy requiring compliant devices.
AnswerA

A device compliance policy defines passcode requirements, including minimum length, for iOS devices. Setting the required passcode length to six characters enforces the stem's constraint before Microsoft Entra ID conditional access permits corporate email access.

Why this answer

A device compliance policy in Microsoft Intune evaluates whether devices meet specific security requirements, such as a minimum passcode length. By creating a compliance policy with a required passcode length of 6, Intune marks any iOS device with a shorter passcode as noncompliant. This noncompliant status can then be used by a conditional access policy to block access to corporate email, achieving the stated goal.

Exam trap

The trap here is that candidates often confuse a device configuration profile (which enforces settings) with a device compliance policy (which evaluates and reports compliance), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because a device configuration profile with a passcode payload enforces the passcode settings on the device (e.g., requiring the user to set a 6-character passcode), but it does not evaluate compliance or block access to corporate email on its own; it only configures the device. Option C is wrong because an app protection policy for Microsoft Outlook manages data protection within the app (e.g., preventing copy/paste or requiring a PIN for app access), but it does not enforce a device-level passcode length requirement. Option D is wrong because a conditional access policy requiring compliant devices is the mechanism that blocks access based on compliance status, but it does not define the passcode length requirement itself; you must first create the compliance policy (Option A) to set that requirement.

256
MCQhard

Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is co-managed with Configuration Manager. You need to configure a policy that requires BitLocker encryption. You create a BitLocker policy in Intune and assign it to the device. After 24 hours, BitLocker is not enabled on the device. You verify that the device is online and the policy is assigned. What is the most likely cause?

A.The device is not online.
B.The encryption workload is set to Configuration Manager.
C.The device is not enrolled in Intune.
D.The BitLocker policy is not assigned to the correct group.
AnswerB

BitLocker falls under the Endpoint Protection workload in co-management. If that workload's authority remains with Configuration Manager, Intune's BitLocker policy is ignored on the device, so encryption never applies. Shifting the Endpoint Protection workload slider to Intune (or Pilot) resolves this.

Why this answer

In a co-managed environment, workload control determines which management authority (Configuration Manager or Intune) handles specific policies. If the encryption workload is set to Configuration Manager, Intune's BitLocker policy will be ignored, even if assigned and the device is online. This is the most likely reason the policy did not take effect after 24 hours.

Exam trap

The trap here is that candidates assume Intune policy always applies to enrolled devices, overlooking the co-management workload slider that can block Intune from managing specific workloads like encryption.

How to eliminate wrong answers

Option A is wrong because the device is verified as online, so connectivity is not the issue. Option C is wrong because the device is co-managed, meaning it is enrolled in both Configuration Manager and Intune; the policy assignment confirms enrollment. Option D is wrong because the policy is assigned to the device and verified, so group assignment is not the problem; the issue is workload control overriding Intune's authority.

257
MCQeasy

A company is planning to use Windows Autopilot to deploy new devices. They want to ensure that devices are automatically enrolled in Microsoft Intune when a user signs in with their Microsoft Entra ID credentials. Which configuration is required?

A.Configure an Enrollment Status Page (ESP) profile in Intune.
B.Create a device compliance policy with the Action for noncompliance set to 'Enforce enrollment'.
C.Set device enrollment restrictions to allow all device platforms.
D.Configure MDM auto-enrollment in Microsoft Intune admin center.
AnswerD

MDM auto-enrollment must be configured in the Microsoft Intune admin center (or Microsoft Entra ID under Mobility > MDM) to automatically enroll devices when users sign in with their Microsoft Entra ID credentials. This is essential for Windows Autopilot deployment.

Why this answer

Configuring MDM auto-enrollment in Microsoft Entra ID (under Mobility > MDM) is the required step to automatically enroll devices in Intune when users sign in with their Microsoft Entra ID credentials during Windows Autopilot. Option A (Enrollment Status Page) only affects the end-user experience during enrollment, it does not trigger enrollment. Option B (compliance policy) enforces compliance after enrollment, not enrollment itself.

Option C (device enrollment restrictions) controls which platforms can enroll, not automatic enrollment.

258
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. You need to ensure that when a Windows 11 device is retired or wiped, the device record is automatically removed from Intune after 30 days. Which action should you take?

A.Configure a device cleanup rule in the Intune tenant settings.
B.Assign a compliance policy that marks devices as noncompliant after 30 days.
C.Create a dynamic device group based on the enrollment date.
D.Enable automatic enrollment for all users and set a retention policy in Microsoft Entra ID.
AnswerA

Intune includes a device cleanup rule under Tenant administration > Device cleanup rules. You can set devices to be automatically deleted after a specified number of days since last check-in. Setting it to 30 days ensures stale records are removed. This directly meets the requirement without manual intervention.

Why this answer

The device cleanup rule in Intune tenant settings automatically deletes devices that have not checked in for a specified number of days. Setting it to 30 days removes records for retired or wiped devices that no longer communicate. Dynamic groups, compliance policies, and Entra ID retention policies do not delete Intune device records, so they cannot fulfill this requirement.

Exam trap

The trap here is confusing compliance or group membership with actual device record deletion; only the device cleanup rule removes stale records from Intune.

259
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that corporate data is separated from personal data on the device. Which management approach should you use?

A.Android Enterprise kiosk mode
B.Android Enterprise fully managed
C.Android Enterprise work profile
D.Android device administrator
AnswerC

A work profile creates a separate, managed container on the device, keeping corporate apps and data isolated from the personal profile. This directly satisfies the requirement to separate corporate from personal data on Android Enterprise devices.

Why this answer

Android Enterprise work profile creates a separate container for corporate data, keeping it isolated from personal data on the same device. Android Enterprise fully managed devices are for corporate-owned devices and do not have a personal space. Android Enterprise kiosk mode locks the device to a single app or set of apps, not designed for data separation.

Android device administrator is a legacy management method that does not provide data separation.

260
MCQeasy

You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?

A.Windows app (Win32)
B.Microsoft 365 Apps
C.Web link
D.Microsoft Store app
AnswerB

The Microsoft 365 Apps app type is purpose-built for deploying Office suites, letting you select channels, versions and exclude individual products. Assigning it to users makes it available in Company Portal, meeting the install-from-portal requirement.

Why this answer

The Microsoft 365 Apps app type in Intune is specifically designed to deploy Office 365 ProPlus (now Microsoft 365 Apps) suites, including Word, Excel, PowerPoint, and others, as a managed suite. This app type automatically configures the installation to use the Office Deployment Tool (ODT) with built-in settings for update channels, architecture (32-bit/64-bit), and language packs, and it makes the suite available in Company Portal for user-initiated installation. Unlike Win32 or other types, it handles the complex licensing and activation requirements for Microsoft 365 Apps without additional scripting.

Exam trap

The trap here is that candidates often choose 'Windows app (Win32)' because they think any desktop app must be deployed as a Win32 app, but they overlook that Intune has a dedicated app type for Microsoft 365 Apps that simplifies licensing, update management, and Company Portal integration, making it the correct and intended choice.

How to eliminate wrong answers

Option A is wrong because Windows app (Win32) is used for deploying traditional desktop applications (e.g., .exe or .msi files) via Intune, but it does not natively support the integrated licensing, update channel management, or suite-level configuration that Microsoft 365 Apps require; using Win32 would require manually packaging the Office Deployment Tool and scripts, which is unnecessary and error-prone. Option C is wrong because a Web link app type only creates a shortcut to a URL in Company Portal and does not perform any software installation, so users cannot install Microsoft 365 Apps from it. Option D is wrong because Microsoft Store app type is intended for deploying apps from the Microsoft Store (UWP or Store-licensed Win32 apps), and Microsoft 365 Apps is not distributed through the Microsoft Store for enterprise deployment via Intune.

261
MCQmedium

You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?

A.Shared iPad enrollment using Apple Business Manager and Intune.
B.Automated Device Enrollment with user affinity.
C.User Enrollment
D.Device Enrollment (DEP) without user affinity.
AnswerA

Shared iPad mode stores each student's apps and data in separate managed user partitions, so signing in on any device restores their own environment. Enrolling through Apple Business Manager with Intune applies the configuration and supervision needed to satisfy the multi-user requirement.

Why this answer

Shared iPad enrollment using Apple Business Manager (ABM) and Intune is designed specifically for scenarios where multiple students share the same iPad and each needs their own apps, data, and sign-in. It uses Managed Apple IDs and provides a personalized experience with separate user partitions, while the device remains supervised and managed by the school.

Exam trap

MD-102 often tests the confusion between 'Shared iPad' (multi-user with individual partitions) and 'Device Enrollment without user affinity' (kiosk/shared but no individual user data) — candidates must recognize the requirement for each student to have their own apps and data.

How to eliminate wrong answers

Option B is wrong because Automated Device Enrollment with user affinity is for one-to-one device scenarios where a single user is assigned to the device — it does not support multiple users sharing the same iPad with separate data. Option C is wrong because User Enrollment (BYOD) is for personal devices where the user enrolls their own device and the organization manages only work data — it does not provide shared device capabilities. Option D is wrong because Device Enrollment without user affinity is for kiosk or shared device scenarios but does not provide individual user partitions or personalized app/data access for multiple students.

262
Multi-Selecteasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?

Select 1 answer
A.Disable screen capture.
B.Disable copy and paste.
C.Disable camera.
D.Disable Bluetooth.
E.Disable Wi-Fi.
AnswersA

Disable screen capture is the Android Enterprise device restrictions setting that blocks screenshots and screen recording on managed devices. Configuring it in a device restrictions profile enforces the restriction through Intune without requiring app-level configuration.

Why this answer

To restrict screenshots on Android Enterprise devices, only the 'Disable screen capture' setting directly prevents the device from taking screenshots by using the FLAG_SECURE window flag. Options B and C ('Disable copy and paste' and 'Disable camera') do not prevent screen capture; they restrict clipboard operations and camera usage respectively. Therefore, the only correct setting is A.

Exam trap

Candidates might mistakenly think that 'Disable copy and paste' or 'Disable camera' can prevent screenshots, but they do not. Only 'Disable screen capture' effectively blocks screenshots.

263
MCQeasy

An organization uses Configuration Manager to deploy software updates to Windows 10 devices. The administrator wants to ensure that devices receive updates from the local distribution point rather than the cloud. Which boundary group option should be configured?

A.Prefer distribution points over cloud sources
B.Enable peer caching
C.Use cloud distribution points only
D.Fallback to cloud sources
AnswerA

Configuring "Prefer distribution points over cloud sources" in the boundary group directs clients to fetch content from on-premises distribution points before falling back to Microsoft Entra ID–joined cloud sources, satisfying the requirement that updates come from the local distribution point rather than the cloud.

Why this answer

The 'Prefer distribution points over cloud sources' boundary group option ensures that clients will attempt to download software updates from a local distribution point before falling back to a cloud-based source. This setting directly controls client behavior to prioritize on-premises distribution points, which aligns with the administrator's goal of keeping traffic local and avoiding cloud egress.

Exam trap

The trap here is that candidates often confuse 'Prefer distribution points over cloud sources' with 'Fallback to cloud sources,' mistakenly thinking that allowing fallback is the same as prioritizing local sources, when in fact the fallback option only enables cloud use as a last resort without establishing a preference order.

How to eliminate wrong answers

Option B is wrong because 'Enable peer caching' configures clients to share content with each other within the same boundary group, but it does not influence the preference between local distribution points and cloud sources; it is a separate optimization for peer-to-peer content distribution. Option C is wrong because 'Use cloud distribution points only' would force clients to exclusively use cloud sources, which is the opposite of the desired behavior to avoid the cloud. Option D is wrong because 'Fallback to cloud sources' allows clients to use cloud distribution points as a backup when local distribution points are unavailable, but it does not prioritize local distribution points over cloud sources; it merely permits cloud fallback.

264
MCQhard

Refer to the exhibit. You query Microsoft Graph API and receive this JSON for a managed device. App2 installation failed. The app is a Win32 app deployed as required. The device is compliant and enrolled via MDM. What is the most likely reason for the failure?

A.The Intune Management Extension is not installed.
B.The app is not assigned to the user.
C.The app version is incompatible with the device OS.
D.The device is not compliant.
AnswerA

Win32 apps deployed as required are processed by the Intune Management Extension agent, not the MDM channel. Without it installed on the device, the app never reaches the agent and installation fails, despite compliance and successful MDM enrolment.

Why this answer

Win32 apps deployed as required require the Intune Management Extension (IME) to be present on the device for installation. Since the device is enrolled via MDM and compliant, but the app installation failed, the most likely cause is that the IME is missing or not functioning. The IME handles Win32 app deployment, detection, and remediation, and without it, required Win32 apps cannot install.

Exam trap

The trap here is that candidates often assume a compliant device automatically has all required components, but the Intune Management Extension is a separate prerequisite that must be installed and running for Win32 app deployment to succeed.

How to eliminate wrong answers

Option B is wrong because the app is deployed as required, which means it is assigned to the device or user regardless of user-specific assignment; a missing user assignment would not cause a failure for a required deployment. Option C is wrong because the exhibit does not indicate any version incompatibility, and the device is compliant, so OS version issues would typically be flagged by Intune compliance policies or app requirements. Option D is wrong because the device is explicitly stated as compliant, so non-compliance cannot be the reason for the failure.

265
MCQhard

Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device reports as compliant, but you suspect it may have a weak password policy because the password type is 'deviceDefault'. What is the effect of 'deviceDefault' on the password requirement?

A.It requires a password that meets the minimum length but no complexity
B.It uses the password type configured in the device's local policy
C.It does not require a password at all
D.It requires a password that contains at least one number and one letter
AnswerB

Selecting deviceDefault for password type defers enforcement to whatever password policy already exists locally on the device, rather than imposing an Intune-defined complexity or length requirement. Compliance therefore reflects the local configuration, which may be weaker than intended.

Why this answer

When the password type is set to 'deviceDefault' in a Microsoft Intune compliance policy for Windows 10, the policy does not enforce a specific password type (e.g., alphanumeric or numeric). Instead, it defers to the password type already configured in the device's local security policy (via Local Group Policy or the SAM registry). This means the device can still be compliant even if the local policy requires only a simple PIN or no complexity, as long as the local password type meets the minimum length and other requirements defined in the compliance policy.

Exam trap

The trap here is that candidates assume 'deviceDefault' means the Intune policy enforces a default Microsoft-defined password type (like alphanumeric), when in fact it simply passes control to the device's local policy, which may be weaker or stronger.

How to eliminate wrong answers

Option A is wrong because 'deviceDefault' does not inherently require a password that meets minimum length without complexity; it simply inherits whatever password type is set locally, which could include complexity requirements or none at all. Option C is wrong because 'deviceDefault' does not mean no password is required; the device still must have a password configured locally, and the compliance policy will enforce other settings like minimum length and expiration. Option D is wrong because requiring at least one number and one letter corresponds to the 'alphanumeric' password type, not 'deviceDefault'; 'deviceDefault' does not mandate any specific character composition.

266
MCQhard

Your organization uses Windows Defender Application Control (WDAC) to allow only approved apps. After deploying a WDAC policy via Intune, some users report that a critical line-of-business app is blocked. How should you troubleshoot?

A.Review CodeIntegrity/Operational logs in Event Viewer
B.Check AppLocker logs in Event Viewer
C.Review Intune device management events for policy errors
D.Check Microsoft 365 Defender portal for WDAC alerts
AnswerA

Reviewing CodeIntegrity/Operational logs reveals the exact WDAC block event, including the file hash, publisher and policy GUID that denied execution. This directly satisfies the troubleshooting constraint: identifying why the line-of-business app was blocked, so you can add a supplemental policy or managed installer rule in Intune.

Why this answer

WDAC blocks or allows applications based on code integrity rules, and when a policy is enforced, blocked execution events are logged in the CodeIntegrity/Operational event log under Event Viewer. Reviewing this log provides specific block events with file details and rule identifiers, enabling you to identify why the LOB app was blocked and adjust the policy accordingly.

Exam trap

The trap here is that candidates confuse WDAC with AppLocker and assume AppLocker logs are relevant, but WDAC uses its own dedicated CodeIntegrity logs for all block events.

How to eliminate wrong answers

Option B is wrong because AppLocker logs are used for AppLocker policies, not WDAC; WDAC uses its own CodeIntegrity logs. Option C is wrong because Intune device management events show policy deployment status (e.g., sync errors) but do not capture runtime block events from the WDAC driver on the client. Option D is wrong because the Microsoft 365 Defender portal aggregates WDAC alerts from devices that report to Defender for Endpoint, but it may not show granular block details for every locally blocked app, and the primary troubleshooting source is the local CodeIntegrity log.

267
MCQmedium

A company with 500 users uses Microsoft 365 E3 licenses. They want to ensure that all users have multi-factor authentication (MFA) enforced. Currently, 80% of users have MFA enabled through the legacy per-user MFA setting. The security team wants to use Conditional Access policies instead. You need to migrate from per-user MFA to Conditional Access with no disruption to users. What should you do?

A.Create a Conditional Access policy requiring MFA for all cloud apps, including break-glass accounts. Then disable per-user MFA.
B.Create a Conditional Access policy requiring MFA for all users only when accessing from outside the corporate network.
C.Create a Conditional Access policy requiring MFA for all users, excluding break-glass accounts. Disable per-user MFA for all users.
D.Disable per-user MFA for all users, then create a Conditional Access policy requiring MFA for all cloud apps.
AnswerC

Creating a Conditional Access policy requiring MFA for all users, with break-glass accounts excluded, satisfies the no-disruption constraint because Conditional Access evaluates at sign-in and supersedes per-user MFA. Disabling per-user MFA afterwards prevents double prompts, since Microsoft Entra ID would otherwise apply both controls to the same users.

Why this answer

The correct approach is to create a Conditional Access policy requiring MFA for all users, excluding break-glass accounts, and then disable per-user MFA for all users. This ensures no disruption because Conditional Access will enforce MFA for all users except the emergency access accounts, which must remain excluded to avoid lockout. Disabling per-user MFA after the policy is in place prevents double-prompting and aligns with Microsoft's recommended migration path.

Exam trap

MD-102 often tests the order of operations in MFA migration, tricking candidates into disabling per-user MFA before enforcing Conditional Access, which can cause disruption.

How to eliminate wrong answers

Option A is wrong because including break-glass accounts in the MFA policy can lead to lockout if MFA is unavailable, and Microsoft explicitly recommends excluding them. Option B is wrong because requiring MFA only from outside the corporate network does not meet the requirement to enforce MFA for all users; it leaves internal access unprotected. Option D is wrong because disabling per-user MFA before creating the Conditional Access policy would leave users without MFA enforcement during the gap, causing a security lapse and potential disruption.

268
MCQhard

You are troubleshooting an iPhone that cannot enroll in Microsoft Intune. The user receives an error stating 'This device is already enrolled in another MDM.' What is the most likely cause?

A.The device is already enrolled in Apple Business Manager or another MDM.
B.The device has a VPN configuration installed.
C.The device is not running the latest iOS version.
D.The user's license is expired.
AnswerA

The error indicates an existing MDM enrolment record tied to the device's Apple serial or enrolment ID. iPhones permit only one MDM profile at a time, so a prior enrolment — via Apple Business Manager, Apple Configurator, or another MDM — must be removed before Microsoft Intune can enrol it.

Why this answer

The error 'This device is already enrolled in another MDM' indicates that the iPhone has an existing MDM profile that conflicts with Intune enrollment. This typically occurs when the device is already enrolled in Apple Business Manager (ABM) or another MDM solution, as iOS enforces a single MDM enrollment per device. Intune cannot overwrite an existing MDM profile without first removing it.

Exam trap

The trap here is that candidates may confuse MDM enrollment conflicts with other common issues like outdated OS or licensing, but the specific error message directly points to an existing MDM profile, not generic configuration or access problems.

How to eliminate wrong answers

Option B is wrong because a VPN configuration does not prevent MDM enrollment; it is a separate network setting that can coexist with an MDM profile. Option C is wrong because while an outdated iOS version might cause compatibility issues, it does not produce the specific 'already enrolled' error; Intune supports a range of iOS versions with appropriate requirements. Option D is wrong because an expired user license would block Intune enrollment with a different error (e.g., 'License not found' or 'Access denied'), not the 'already enrolled' message.

269
Multi-Selectmedium

You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?

Select 1 answer
A.Microsoft Entra ID (Azure AD) Premium P1 or P2.
B.Microsoft Intune license assigned to the user.
C.A Microsoft account (MSA) for each user.
D.Microsoft 365 E3 subscription.
E.Azure Information Protection license.
AnswersB

Enrolment requires a Microsoft Intune licence assigned to the enrolling user, since Intune is licensed per user rather than per device. Without that licence, the user cannot authenticate and the Windows 10 device cannot be enrolled or receive policy.

Why this answer

Option B is the correct prerequisite: a Microsoft Intune license must be assigned to the user enrolling the device. Option A (Microsoft Entra ID Premium P1/P2) is not required; Microsoft Entra ID Free is sufficient for Intune enrollment. Option C (Microsoft account) is not needed for corporate devices.

Option D (Microsoft 365 E3) is a bundled subscription but not a standalone prerequisite. Option E (Azure Information Protection) is unrelated to device enrollment. Therefore, only one option is correct.

Exam trap

Candidates may mistakenly select multiple options, but the stem clearly asks for only one prerequisite, and only Option B is correct.

270
MCQhard

You are designing a Windows 11 update strategy for a fleet of 500 devices managed by Intune. The organization requires that critical security updates be applied within 7 days, but feature updates can be delayed up to 60 days. Which Update Rings configuration should you use?

A.Assign a Quality Update policy with deferral of 7 days
B.Create an Update Ring with quality update deferral of 7 days and feature update deferral of 60 days
C.Configure Windows Update for Business via Group Policy on-premises
D.Assign a Feature Update policy with deferral of 60 days
AnswerB

Deferral values hold quality and feature updates back by the specified number of days, so a 7-day quality deferral meets the security deadline while a 60-day feature deferral matches the permitted delay for feature updates.

Why this answer

Update Rings in Intune allow you to independently configure deferral periods for quality updates (security fixes) and feature updates. Setting quality update deferral to 7 days ensures critical security patches are applied within the required window, while feature update deferral of 60 days delays non-security feature updates as needed, all managed via cloud-based Windows Update for Business policies.

Exam trap

The trap here is that candidates often confuse Update Rings with separate Quality or Feature Update policies, not realizing that Update Rings are the single object that can simultaneously control both deferral periods, while the other options only address one type of update.

How to eliminate wrong answers

Option A is wrong because a Quality Update policy (via Windows 10/11 feature update policies) only controls deferral for quality updates, but does not address the feature update deferral requirement of 60 days; it is an incomplete solution. Option C is wrong because configuring Windows Update for Business via on-premises Group Policy contradicts the requirement that devices are managed by Intune; Intune uses cloud-based policies, not local Group Policy, and this approach would not leverage the centralized mobile device management (MDM) capabilities. Option D is wrong because a Feature Update policy only controls deferral for feature updates, ignoring the quality update deferral requirement of 7 days; it addresses only half of the requirement.

271
MCQhard

You are planning a Windows 11 deployment for 500 new devices using Windows Autopilot. The devices will be shipped directly to users from the manufacturer. You need to ensure that the devices are automatically enrolled in Intune and joined to Microsoft Entra ID. What should you do?

A.Register the device hashes in Intune and assign an Autopilot deployment profile
B.Pre-install the Intune Management Extension on each device
C.Configure a provisioning package and include it with the shipment
D.Create a hybrid Azure AD join configuration in Intune
AnswerA

Registering hardware hashes creates Autopilot device records, letting Intune identify each device at first boot. Assigning a deployment profile then drives the Microsoft Entra join and automatic Intune enrolment, satisfying the requirement that manufacturer-shipped devices enrol without IT touching them.

Why this answer

Windows Autopilot uses device hashes (hardware IDs) to identify devices in Intune. By registering these hashes and assigning an Autopilot deployment profile, the devices are automatically enrolled in Intune and joined to Microsoft Entra ID during the out-of-box experience (OOBE), without requiring manual intervention or additional infrastructure.

Exam trap

The trap here is that candidates often confuse hybrid Azure AD join with Microsoft Entra ID join, or think provisioning packages are needed for Autopilot, when in fact Autopilot is designed for zero-touch, cloud-only scenarios without any on-premises dependency.

How to eliminate wrong answers

Option B is wrong because the Intune Management Extension is automatically installed during Intune enrollment, not pre-installed on devices before Autopilot runs. Option C is wrong because provisioning packages (PPKG files) are used for manual or bulk provisioning, not for the zero-touch, cloud-driven Autopilot scenario where devices are shipped directly to users. Option D is wrong because hybrid Azure AD join requires a connection to on-premises Active Directory and is not the default for Autopilot; the scenario specifies Microsoft Entra ID join, not hybrid.

272
MCQeasy

A company uses Microsoft Intune to manage Windows devices. Administrators need to deploy Microsoft 365 Apps to all managed Windows devices and ensure the apps receive updates automatically from the Microsoft 365 Apps update channel. Which Intune app type should they use?

A.Microsoft 365 Apps (Windows 10 and later)
B.Windows app (Win32)
C.Microsoft Store app (new)
D.Web link
AnswerA

The Microsoft 365 Apps (Windows 10 and later) app type in Intune is purpose-built to deploy Office. It provides the Office Configuration Service and XML settings that let you select the update channel, choose which Office apps to install, and control update behavior. Assigning it to device groups delivers and maintains Microsoft 365 Apps with the desired update channel automatically.

Why this answer

Intune includes a dedicated Microsoft 365 Apps (Windows 10 and later) app type that integrates with the Office Configuration Service. It lets administrators choose the update channel, select which Office applications to install, and configure update behavior, then assign the app to device groups. This provides automatic installation and ongoing updates from the chosen channel, which is exactly what the scenario requires.

Exam trap

The trap here is assuming any app type that can install Office will also manage its update channel, when only the Microsoft 365 Apps app type provides native channel and update controls.

273
MCQeasy

An organization needs to deploy Windows 11 to remote users who do not have access to the corporate network. The devices are brand new and have internet connectivity. Which deployment method should the administrator recommend?

A.Use Configuration Manager with a task sequence over VPN.
B.Use PXE boot from a distribution point at the local office.
C.Use Windows Autopilot with user-driven mode.
D.Deploy using MDT with a bootable USB drive.
AnswerC

Windows Autopilot user-driven mode provisions brand-new devices over the internet, requiring no corporate network connectivity or on-premises infrastructure. The device registers with Microsoft Entra ID during out-of-box experience, applying organisational configuration directly to the remote user, satisfying the stem's constraint that users lack corporate network access.

Why this answer

Windows Autopilot with user-driven mode is the correct choice because it enables remote, zero-touch deployment of new Windows 11 devices using only internet connectivity. The devices are pre-registered in Autopilot, and during the out-of-box experience (OOBE), they automatically download the organization-specific configuration, join Azure AD, and enroll in MDM without requiring any VPN or on-premises infrastructure.

Exam trap

The trap here is that candidates often assume VPN or PXE are viable for remote deployments, but they overlook the fundamental requirement that brand-new devices have no pre-existing network configuration or corporate connectivity, making internet-based Autopilot the only practical option.

How to eliminate wrong answers

Option A is wrong because Configuration Manager task sequences over VPN require the device to first establish a VPN connection to the corporate network, which is not possible for brand-new devices that lack pre-configured VPN profiles and have no prior network access. Option B is wrong because PXE boot relies on a local network broadcast and a distribution point on the same subnet; remote users without corporate network access cannot reach a PXE server, and PXE does not work over the internet. Option D is wrong because deploying with MDT using a bootable USB drive requires physical delivery of the USB media to each remote user, which is not a scalable or practical solution for a large number of remote devices and does not leverage internet connectivity for deployment.

274
Multi-Selectmedium

You are preparing to deploy a Win32 app to Windows 11 devices with Microsoft Intune. The app must install silently and be reported as installed only when a specific file exists at a known path. Which TWO configuration elements are required for Intune to evaluate and report the app as installed? (Choose two.)

Select 2 answers
A.A PowerShell script that writes a marker file after installation
B.A return code mapping that treats 3010 as a soft reboot
C.An install command that runs the app's silent installer
D.A requirement rule that limits installation to Windows 11
E.A detection rule that identifies the app on the device
AnswersC, E

The install command tells the Intune Management Extension how to run the app's installer. For a silent install, the command must include the vendor's quiet switches, for example an MSI executed with /qn. Without a valid install command, the extension has nothing to execute, so the app cannot be delivered or detected as installed.

Why this answer

For Intune to install and then report a Win32 app as installed, the app needs both an install command that invokes the silent installer and a detection rule that identifies the app on the device. The detection rule is what the Intune Management Extension evaluates after installation, and the install command is what it executes to place the app on the device.

Exam trap

The trap here is treating optional extras like marker scripts or return code mapping as required, when detection and install command are the core elements.

275
MCQeasy

You need to ensure that corporate devices automatically install critical Windows updates within 24 hours of release. Which update ring setting should you configure in Intune?

A.Grace Period for Restarts (days)
B.Defer Quality Updates (days)
C.Update Deadline for Quality Updates (days)
D.Active Hours
AnswerC

The Update Deadline for Quality Updates setting forces installation within a specified number of days after release, regardless of user deferral. Setting it to 1 day satisfies the requirement to install updates within 24 hours.

Why this answer

The 'Update Deadline for Quality Updates (days)' setting in Intune's update ring policy enforces a deadline by which quality updates must be installed. Configuring this to 1 day ensures that devices install critical Windows updates within 24 hours of release, as the deadline triggers automatic installation and restart after the specified number of days.

Exam trap

The trap here is that candidates confuse 'Defer Quality Updates' (which delays updates) with 'Update Deadline for Quality Updates' (which enforces installation timing), leading them to incorrectly select Option B thinking it controls installation speed.

How to eliminate wrong answers

Option A is wrong because 'Grace Period for Restarts (days)' controls how long after the deadline a user can postpone a restart, not the time to install the update. Option B is wrong because 'Defer Quality Updates (days)' delays the availability of updates, which would prevent automatic installation within 24 hours of release. Option D is wrong because 'Active Hours' defines a time window during which restarts are avoided, but does not enforce a deadline for update installation.

276
MCQmedium

Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?

A.Add an indicator of compromise for the file.
B.Configure a device control policy.
C.Create a new automation rule in the Microsoft 365 Defender portal.
D.Create an attack surface reduction rule.
AnswerC

Creating an automation rule in the Microsoft 365 Defender portal directly satisfies the requirement to quarantine a file when a specific alert triggers. Automation rules evaluate alerts and execute response actions such as quarantine, unlike custom detections, which only generate alerts, or device groups, which merely scope remediation levels.

Why this answer

Automated investigation and remediation (AIR) rules in Microsoft 365 Defender allow you to define automated actions—such as quarantining a file—when a specific alert is triggered. This is the native mechanism for orchestrating response actions based on alert conditions, directly supporting the requirement to automatically quarantine a file upon alert generation.

Exam trap

The trap here is that candidates often confuse indicators of compromise (IoC) with automated response rules, mistakenly thinking that adding an IoC for a file will automatically trigger a quarantine action when the file is detected, whereas IoCs only define detection or blocking logic, not conditional alert-triggered remediation workflows.

How to eliminate wrong answers

Option A is wrong because adding an indicator of compromise (IoC) for the file creates a custom threat intelligence indicator that can block or alert on the file, but it does not create an automated investigation and remediation rule that triggers a quarantine action based on a specific alert. Option B is wrong because a device control policy governs removable storage and peripheral device access (e.g., USB drives), not file-level quarantine actions in response to alerts. Option D is wrong because an attack surface reduction (ASR) rule is a set of behavioral-based rules that prevent common attack techniques (e.g., blocking Office apps from creating child processes), but it does not provide the ability to define automated quarantine actions triggered by a specific alert.

277
MCQeasy

A company uses Microsoft Intune to manage devices. They want to ensure that when a device is reported as lost or stolen, the IT admin can remotely wipe the device. Which action should the admin take in the Intune console?

A.Select the device and choose 'Retire'.
B.Select the device and choose 'Wipe'.
C.Select the device and choose 'Reset'.
D.Select the device and choose 'Delete'.
AnswerB

The Wipe action in Intune performs a full factory reset, removing all data and settings from the device. For a lost or stolen device this satisfies the requirement to remotely erase corporate and personal content, preventing data exposure.

Why this answer

The 'Wipe' action in Microsoft Intune restores a device to its factory default settings, removing all corporate and personal data. This is the appropriate action for a lost or stolen device to prevent unauthorized access to company data. The 'Retire' action only removes managed app data and policies but leaves personal data intact, which is insufficient for a security breach scenario.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', assuming both remove data equally, but 'Retire' only removes managed corporate data while leaving personal data and device access intact, making it unsuitable for lost or stolen scenarios.

How to eliminate wrong answers

Option A is wrong because 'Retire' removes only managed corporate data and policies from the device, leaving personal data and the device itself functional, which does not fully protect data on a lost or stolen device. Option C is wrong because 'Reset' is not a standard Intune action; the correct term is 'Wipe' for factory reset, and 'Reset' may be confused with a local device reset that is not initiated via Intune. Option D is wrong because 'Delete' removes the device object from Intune management but does not perform a remote wipe, leaving the device and its data untouched.

278
Multi-Selectmedium

Which THREE of the following are required to deploy a Win32 app using Microsoft Intune?

Select 3 answers
A.Product code
B.Detection rule
C.Return codes for success
D.Dependencies
E.Installation command
AnswersB, C, E

Intune requires a detection rule so it can determine whether the Win32 app is already installed on a device. Without it, the service cannot evaluate installation state, making the rule mandatory alongside the app package and install command.

Why this answer

To deploy a Win32 app in Microsoft Intune, a detection rule (B) is mandatory because Intune must determine whether the app is already installed on the device, using methods such as MSI product code, file/folder existence, or a custom script. Return codes for success (C) are also required so Intune can interpret the exit code returned by the installer and correctly report the installation as succeeded, failed, or requiring a restart (e.g., 0 for success, 3010 for soft reboot). The installation command (E) is essential because Intune needs the exact command line (for example, msiexec /i "app.msi" /qn or setup.exe /silent) to actually install the Win32 app on the target device.

Product code (A) is not universally required, since it is only one possible detection method and can be replaced by file, folder, or script-based detection. Dependencies (D) are optional, as they are only needed when the app requires other apps to be installed first, and are not mandatory for every Win32 app deployment.

Exam trap

The trap here is that candidates often confuse optional features like dependencies or product codes with mandatory requirements, but Intune explicitly requires only the installation command, detection rule, and at least one return code for success.

279
MCQhard

You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully, but the detection rule incorrectly reports the app as not installed, causing Intune to attempt reinstallation repeatedly. Which detection rule method is most likely causing this issue?

A.MSI product code detection uses a product code that does not match the installed app
B.File existence detection checks for a file that is installed by the app
C.Registry detection checks for a registry key that is created by the app
D.Custom script detection returns exit code 0 even if app is not present
AnswerA

MSI product code detection compares the specified GUID against the installed product's actual code. If the code does not match the installed app, detection always returns false, so Intune treats the app as absent and reinstalls it repeatedly.

Why this answer

When an MSI product code detection rule uses a product code that does not match the GUID of the installed application, Intune will always evaluate the app as 'not installed' regardless of the actual installation state. This mismatch causes Intune to repeatedly attempt reinstallation on every check-in cycle, as the detection logic never finds a matching product code in the Windows Installer database.

Exam trap

The trap here is that candidates often assume any detection rule method will work as long as the app is installed, but they overlook that MSI product code detection requires an exact GUID match, and a mismatch will cause Intune to perpetually attempt reinstallation.

How to eliminate wrong answers

Option B is wrong because file existence detection checks for a file that is installed by the app; if the file is present, the rule correctly reports the app as installed, so it would not cause repeated reinstallation. Option C is wrong because registry detection checks for a registry key created by the app; if the key exists, the rule correctly identifies the app as installed, preventing reinstallation loops. Option D is wrong because a custom script that returns exit code 0 when the app is not present would incorrectly report the app as installed, which would stop reinstallation attempts, not cause them.

280
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app as Required to all users. Users report that the app is not installing, and the Intune console shows the app status as 'Not applicable' for all devices. What is the most likely cause?

A.The app's detection rule is incorrect.
B.The app's requirement rules are not met by the devices.
C.The Intune Management Extension is not installed on the devices.
D.The app is not assigned to any groups.
AnswerB

When an app's requirement rules are not met, Intune marks the app as 'Not applicable' for those devices. This status indicates that the app is not intended for the device based on the defined requirements, such as OS version, architecture, or disk space. Reviewing and adjusting the requirement rules to match the device configuration resolves the issue.

Why this answer

The status 'Not applicable' in Intune for a Win32 app indicates that the app's requirement rules are not met by the device. This could be due to OS version, architecture, or other conditions defined in the requirement rules. Adjusting the requirement rules to match the device configuration resolves the issue.

Exam trap

The trap here is confusing 'Not applicable' with other statuses like 'Failed' or 'Not targeted', leading to troubleshooting the wrong component.

281
MCQmedium

Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?

A.Create an app protection policy for Windows 365 app.
B.Configure the Cloud PC provisioning policy to allow only compliant devices.
C.Assign a device compliance policy to all users.
D.Create a Conditional Access policy requiring device to be marked as compliant.
AnswerD

A Conditional Access policy evaluates device compliance state at sign-in, so only devices marked compliant in Intune can establish the Cloud PC connection. This directly enforces the constraint that users connect solely from compliant devices.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant is the only configuration that enforces compliance at the authentication and access level. This policy evaluates the device's compliance status (reported by Microsoft Intune) before granting access to Windows 365 Cloud PCs, ensuring that only devices meeting your organization's compliance requirements can connect.

Exam trap

The trap here is that candidates often confuse provisioning policies (which configure Cloud PCs) with access control policies (Conditional Access), leading them to select Option B, but provisioning policies do not enforce compliance-based access restrictions.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection within apps and do not evaluate device compliance; they are designed for unmanaged devices and cannot block access based on device compliance status. Option B is wrong because a Cloud PC provisioning policy defines the configuration and assignment of Cloud PCs (e.g., image, network, user assignments) but does not enforce access controls or compliance checks at the time of connection. Option C is wrong because assigning a device compliance policy to all users defines the compliance requirements (e.g., encryption, OS version) but does not enforce access restrictions; it only marks the device as compliant or non-compliant—a separate Conditional Access policy is needed to block non-compliant devices.

282
MCQhard

You are deploying a Win32 app that requires .NET Framework 4.8. You create a dependency in Intune for the .NET Framework app. However, some devices fail to install the parent app even though .NET Framework is present. What is the most likely issue?

A.The dependency version is set to 'Greater than' instead of 'Greater than or equal to'.
B.The dependency detection rule does not match the actual .NET installation.
C.The parent app is set to install before the dependency.
D.The dependency is set to 'Do not install automatically'.
AnswerB

Intune evaluates dependency detection rules before installing the parent app; if the rule checks the wrong registry path, file version or product code, it reports .NET Framework as absent even when installed. The parent app is then skipped, satisfying the stem's constraint that .NET is present yet installation fails.

Why this answer

Intune uses detection rules to verify whether a dependency is installed. If the detection rule for the .NET Framework dependency does not match the actual installation state (e.g., it checks for a registry key or file version that differs from what .NET 4.8 actually creates), Intune will incorrectly report the dependency as missing, blocking the parent app installation even though .NET is present.

Exam trap

The trap here is that candidates assume a dependency is automatically detected by its version number, but Intune requires an explicit detection rule that must exactly match the actual installation artifacts, and a mismatch in the detection rule (not the version logic) is the root cause of the failure.

How to eliminate wrong answers

Option A is wrong because setting the dependency version to 'Greater than' (instead of 'Greater than or equal to') would only cause failure if the installed .NET version is exactly 4.8 and the rule requires a version higher than 4.8, but the scenario states .NET is present, so version mismatch is not the core issue. Option C is wrong because Intune dependencies are designed to install the dependency before the parent app automatically; setting the parent to install before the dependency would violate dependency logic and is not a configurable option in Intune. Option D is wrong because setting a dependency to 'Do not install automatically' means Intune will not push the dependency to devices, but if the dependency is already present, the parent app should still install; the failure here is due to detection mismatch, not the auto-install setting.

283
MCQhard

You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?

A.allowBluetooth set to false
B.allowStorageCard set to false
C.allowCopyPaste set to false
D.allowCamera set to false
AnswerA

Setting allowBluetooth to false disables the Bluetooth radio entirely, so paired mice and keyboards stop working. This policy setting directly satisfies the stem's constraint: users cannot use Bluetooth devices after the custom policy applies. Other settings, such as camera or Wi-Fi restrictions, would not produce this specific symptom.

Why this answer

The `allowBluetooth` setting set to `false` explicitly disables the Bluetooth radio on the device, preventing any Bluetooth peripherals (mouse, keyboard, etc.) from pairing or connecting. This is a common policy in Windows CSP (Policy CSP – Bluetooth/AllowBluetooth) that controls the Bluetooth stack at the OS level, and setting it to false blocks all Bluetooth functionality.

Exam trap

The trap here is that candidates may confuse `allowBluetooth` with other device restriction policies (like camera or storage) or assume Bluetooth issues are caused by a network or driver problem, rather than recognizing the specific CSP policy that directly disables the Bluetooth radio.

How to eliminate wrong answers

Option B is wrong because `allowStorageCard` controls the use of removable storage (e.g., SD cards), not Bluetooth connectivity. Option C is wrong because `allowCopyPaste` restricts clipboard sharing between the device and other systems (e.g., in Remote Desktop or Kiosk mode), not Bluetooth device pairing. Option D is wrong because `allowCamera` disables the built-in camera, which has no impact on Bluetooth radio or peripheral connections.

284
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company-specific application (a .pkg file) to all macOS devices. The application requires a specific configuration file that must be placed in the /Library/Application Support/ directory. You also need to ensure that the application is installed silently without user interaction. How should you configure the deployment in Intune?

A.Use a shell script in Intune to download and install the .pkg file from a secure URL.
B.Create a device configuration profile for macOS that includes the app installation settings.
C.Add the .pkg file as a macOS line-of-business app in Intune, specify installation arguments for silent install, and include a script to copy the configuration file post-install.
D.Use Apple Volume Purchase Program (VPP) to distribute the app as a managed app.
AnswerC

This is the standard method for deploying custom macOS apps with configuration.

Why this answer

Intune's macOS line-of-business (LOB) app deployment supports .pkg files and allows you to specify installation arguments (e.g., `-silent` or `--acceptLicense`) for silent installation. To place the configuration file in /Library/Application Support/, you must use a post-install script because Intune does not natively copy files to specific directories during LOB app deployment. This combination ensures the app is installed silently and configured correctly.

Exam trap

The trap here is that candidates often confuse device configuration profiles (which only manage settings) with app deployment, or they assume a simple script can replace the structured LOB app deployment with its silent install and post-install script capabilities.

How to eliminate wrong answers

Option A is wrong because a shell script in Intune can download and install a .pkg, but it does not provide the built-in silent install arguments or the post-install script capability that LOB app deployment offers; additionally, Intune's script deployment lacks the same reporting and dependency management as LOB apps. Option B is wrong because device configuration profiles in Intune are used for settings (e.g., restrictions, preferences) and cannot deploy applications or run scripts. Option D is wrong because VPP is for distributing apps from the Apple App Store, not for deploying custom .pkg files or managing configuration files.

285
MCQmedium

You manage Windows devices with Microsoft Intune. A required Win32 app (an .intunewin package) was assigned to a device group, but the app never installs and the device shows no error. The app's install command is `setup.exe /silent`, and the detection rule is a registry key that the installer writes only under HKLM\SOFTWARE. You confirm the app installs successfully when run manually as a standard user. What is the most likely cause?

A.The app must be assigned to a user group because Win32 apps cannot be assigned to device groups.
B.The install command runs in the user context, so the HKLM registry key cannot be written.
C.The .intunewin package must be signed with a code-signing certificate before it can install.
D.The detection rule must use a file path instead of a registry key for required apps.
AnswerB

By default, Win32 app install commands run in the system context (SYSTEM) on the device. If the package was configured to install in user context, the installer cannot write to HKLM, which requires administrative rights. Because the detection rule looks for that HKLM key, detection fails and Intune reports the app as not installed with no visible error, matching the scenario.

Why this answer

The key detail is that the detection rule checks an HKLM registry key, which can only be written with administrative privileges. If the Win32 app was configured to install in user context, the installer cannot create that key, so detection never succeeds and Intune reports the app as not installed without an obvious error. Switching the install behavior to system context allows the installer to write to HKLM and satisfy detection.

Exam trap

The trap here is assuming that a silent non-installation always means a packaging or assignment problem, when the actual cause is the install context being unable to write to a machine-wide registry location.

286
MCQhard

You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?

A.Create an Intune device configuration profile using the Settings Catalog and assign it to the Azure AD group containing Cloud PC users.
B.Include the settings in the Windows 365 provisioning policy.
C.Create a PowerShell script that runs during provisioning and apply it via Azure Automation.
D.Use a Group Policy Object (GPO) applied via on-premises AD.
AnswerA

The Settings Catalog exposes Defender for Endpoint real-time protection and firewall configuration settings as a reusable Intune profile, which applies automatically to Cloud PCs once assigned to the Microsoft Entra ID group. This satisfies the requirement for automatic configuration at provisioning.

Why this answer

Intune device configuration profiles using the Settings Catalog allow granular control over Microsoft Defender for Endpoint settings (e.g., real-time protection) and custom firewall rules. These profiles can be assigned to an Azure AD group containing Cloud PC users, ensuring the settings are applied automatically after provisioning via the Windows 365 service, which integrates with Intune for post-provisioning management.

Exam trap

The trap here is that candidates mistakenly think Windows 365 provisioning policies can include security configurations, but in reality, they only define infrastructure settings, while all post-provisioning management (including Defender and firewall rules) must be handled by Intune policies.

How to eliminate wrong answers

Option B is wrong because Windows 365 provisioning policies only define Cloud PC configuration (e.g., region, network, image) and do not support granular security settings like Defender or custom firewall rules; those must be applied via Intune after provisioning. Option C is wrong because PowerShell scripts run during provisioning via Azure Automation are not natively integrated with Windows 365 provisioning; the recommended approach is to use Intune configuration profiles, which are designed for post-provisioning device management. Option D is wrong because Group Policy Objects (GPOs) require on-premises Active Directory and domain-joined devices, but Cloud PCs are Azure AD-joined or Hybrid Azure AD-joined by default and do not support direct GPO application without additional infrastructure like Group Policy Administrative Templates in Intune.

287
Multi-Selecteasy

You are troubleshooting a Windows device that is not receiving policies from Intune. Which TWO actions should you take?

Select 2 answers
A.Configure a Conditional Access policy
B.Reset the user's password
C.Verify the device is enrolled in Intune
D.Check the device sync status in the Intune console
E.Review the app protection policy assignment
AnswersC, D

Device must be enrolled to receive policies.

Why this answer

A device must be enrolled in Intune to receive policies; if enrollment is missing, the device will not appear in the Intune console and cannot process MDM policies. Verifying enrollment status (e.g., via Settings > Accounts > Access work or school) confirms the device is managed and can receive policy payloads.

Exam trap

The trap here is that candidates confuse policy delivery issues with authentication or app-level controls, leading them to select Conditional Access or app protection policies instead of focusing on the fundamental enrollment and sync prerequisites.

288
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?

A.Configure a device configuration profile with 'Windows Update for Business' settings.
B.Deploy a feature update policy to install the latest quality updates.
C.Create an update ring for Windows 10 and later, and set the 'Automatic update behavior' to 'Auto install and reboot' and assign it to all devices.
D.Create a device compliance policy that requires devices to have the latest updates.
AnswerC

An update ring for Windows 10 and later satisfies the automatic installation requirement by setting 'Automatic update behavior' to 'Auto install and reboot', which forces critical and security updates to download and install without user intervention. Assigning it to all devices ensures every Windows 11 endpoint receives the policy, meeting the stem's automatic-update constraint.

Why this answer

Update rings are the primary policy in Microsoft Intune for controlling how and when Windows 10 and later devices receive updates from Windows Update. Setting 'Automatic update behavior' to 'Auto install and reboot' ensures that critical and security updates are automatically downloaded and installed without user intervention, meeting the requirement for all Windows 11 devices.

Exam trap

The trap here is that candidates confuse device configuration profiles (which are for settings like BitLocker or Wi-Fi) with update rings, or they mistakenly think compliance policies can enforce update installation, when in fact only update rings control the automatic update behavior.

How to eliminate wrong answers

Option A is wrong because a device configuration profile with 'Windows Update for Business' settings is a legacy approach that has been deprecated in favor of update rings; it does not provide the granular control over update installation behavior required for automatic installation of critical and security updates. Option B is wrong because a feature update policy is used to move devices to a specific Windows version (e.g., from Windows 10 to Windows 11) or to defer feature updates, not to control the installation of critical and security quality updates. Option D is wrong because a device compliance policy can only report on whether devices have the latest updates installed and can trigger conditional access actions, but it cannot enforce the automatic installation of updates; it is a reporting and remediation tool, not an update deployment mechanism.

289
MCQeasy

You are asked to recommend a solution for deploying a web application as an icon on users' Windows 10 devices managed by Intune. Which app type should you use?

A.Windows app (Win32)
B.Microsoft Store app
C.Built-in app
D.Web link
AnswerD

A web link (web app) in Intune creates a shortcut icon on managed Windows devices that opens the specified URL in the default browser. It requires no packaging or installation, satisfying the requirement to surface a web application as an icon.

Why this answer

A web link app in Intune creates a shortcut on the Windows 10 desktop or Start menu that opens a specified URL in the default browser. This is the correct choice because the requirement is to deploy an icon that launches a web application, not to install a binary or package. Web link apps are lightweight, require no installation, and are managed via Intune's 'Web link' app type under Windows apps.

Exam trap

The trap here is that candidates confuse 'deploying a web application' with installing a traditional app, leading them to choose Win32 or Store app types, when the requirement is simply to place an icon that opens a URL.

How to eliminate wrong answers

Option A is wrong because Win32 apps are used for deploying traditional desktop applications (e.g., .exe, .msi) that require installation and local execution, not for simply placing a web shortcut. Option B is wrong because Microsoft Store apps are packaged UWP or Win32 apps distributed via the Store, requiring installation and local execution, not a web link. Option C is wrong because built-in apps are pre-installed Windows components (e.g., Notepad, Calculator) that cannot be used to add custom web shortcuts.

290
Multi-Selectmedium

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows 11 devices remotely? (Choose two.)

Select 2 answers
A.Collect diagnostics
B.Deploy a line-of-business app
C.Restart the device
D.Create a VPN profile
E.Assign a compliance policy
AnswersA, C

Collect diagnostics is a remote action in the Intune admin center that pulls Windows 11 device logs and uploads them for review, satisfying the requirement to manage devices remotely without physical access or user intervention.

Why this answer

Option A (Collect diagnostics) is correct because the Intune admin center provides a remote action on Windows 11 devices that gathers diagnostic logs from the device and uploads them to Intune for troubleshooting. Option C (Restart the device) is correct because Intune offers a remote restart action that sends a command to the Windows 11 device to reboot it without requiring physical access. The other options are not remote device actions: deploying a line-of-business app, creating a VPN profile, and assigning a compliance policy are configuration or policy management tasks performed on the Intune service, not direct remote actions executed against a specific enrolled device.

Exam trap

The trap here is that candidates confuse policy-based actions (like deploying apps or assigning compliance policies) with immediate remote actions, which are specifically listed under the 'Device actions' menu in the Intune admin center.

291
MCQeasy

A user's iOS device is enrolled in Microsoft Intune. The user reports that they cannot install the Company Portal app from the App Store. What is the most likely reason?

A.The user does not have an Apple ID.
B.The App Store is disabled by a device restriction policy.
C.The device is not enrolled in Intune.
D.The device is not supervised.
AnswerB

A device restriction policy blocking the App Store prevents all App Store installs, including Company Portal, which iOS requires to be installed from the App Store. This directly explains the reported failure, since the restriction removes the only permitted installation channel for that app on the enrolled device.

Why this answer

A device restriction policy in Microsoft Intune can block access to the App Store on iOS devices. When the App Store is disabled via a configuration profile, users cannot install or update any apps from the App Store, including the Company Portal app. This is a common policy setting used by organizations to control app installation sources.

Exam trap

The trap here is that candidates often assume the Company Portal app must be pre-installed or that device supervision is required for app installation, but Intune can deploy the Company Portal to unsupervised devices, and the issue is specifically a policy blocking the App Store.

How to eliminate wrong answers

Option A is wrong because an Apple ID is required to download apps from the App Store, but the absence of an Apple ID would prevent any app installation, not specifically the Company Portal app, and Intune enrollment does not require an Apple ID. Option C is wrong because the user's device is already enrolled in Intune as stated in the question, so lack of enrollment cannot be the reason. Option D is wrong because device supervision is not a prerequisite for installing the Company Portal app; supervised mode is primarily used for advanced management capabilities like device configuration and restrictions, but the Company Portal can be installed on both supervised and unsupervised devices.

292
MCQeasy

A company uses Microsoft Intune to manage iOS devices. They want to ensure that only devices with a passcode of at least 6 characters and without jailbreak can access corporate email. Which policy type should they configure?

A.Conditional Access policy
B.App protection policy
C.Device compliance policy
D.Device configuration policy
AnswerC

A device compliance policy defines exactly these conditions — minimum passcode length and jailbreak detection — as rules a device must satisfy. Conditional Access then blocks corporate email for non-compliant devices, directly meeting the stem's requirement that only passcode-protected, non-jailbroken iOS devices reach email.

Why this answer

Device compliance policies in Microsoft Intune evaluate device-level security settings such as jailbreak status and passcode length. By configuring a compliance policy that requires a passcode of at least 6 characters and detects jailbroken devices, Intune can mark non-compliant devices and, when combined with Conditional Access, block access to corporate email. This is the correct policy type because it directly assesses the device's security posture rather than app-level or configuration settings.

Exam trap

The trap here is that candidates confuse 'Conditional Access' (the gatekeeper) with the policy that defines the conditions (Device Compliance), leading them to select Option A because they think the policy that 'ensures only devices with... can access' is the access control policy itself, rather than the compliance policy that provides the evaluation signal.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies are access-control rules that rely on signals from compliance policies or other sources; they do not themselves define or enforce device-level requirements like passcode length or jailbreak detection. Option B is wrong because App protection policies (MAM) manage data protection at the app level (e.g., PIN for opening an app, data encryption) and do not evaluate device-level attributes such as jailbreak status or system passcode length. Option D is wrong because Device configuration policies push settings (e.g., Wi-Fi, VPN, email profiles) to devices but do not enforce compliance checks or block access based on security state; they are not designed for conditional access enforcement.

293
MCQhard

Refer to the exhibit. The exhibit shows a JSON representation of a managed device from Microsoft Graph API. The device shows as noncompliant. Which of the following is the most likely reason for the noncompliant status?

A.The device has not synced recently; the compliance policy may require a more recent check-in.
B.The device is company-owned, which is noncompliant by default.
C.The device is a userless device and cannot be compliant.
D.The device's operating system version is not supported.
AnswerA

Compliance policies often require devices to sync within a certain period; the last sync is March 15, which may be older than the policy threshold.

Why this answer

The JSON shows the device's lastSyncDateTime is significantly older than the current time, and the complianceState is 'noncompliant'. Microsoft Intune compliance policies require devices to check in within a configurable grace period (default 30 days for noncompliant devices, but policies can enforce a shorter interval). If the device hasn't synced recently, it fails the 'Device check-in frequency' compliance rule, marking it noncompliant.

Option A correctly identifies this as the most likely cause.

Exam trap

The trap here is that candidates often assume noncompliance is due to an unsupported OS version or ownership type, but the JSON explicitly shows a supported OS and no ownership-based policy, while the stale lastSyncDateTime is the clear indicator of a check-in failure.

How to eliminate wrong answers

Option B is wrong because company-owned devices are not noncompliant by default; ownership type (corporate vs. personal) does not directly affect compliance state unless a specific compliance policy targets ownership. Option C is wrong because userless devices (e.g., kiosk or shared devices) can be compliant if they meet all policy requirements; Intune supports device compliance for userless scenarios via device enrollment. Option D is wrong because the JSON shows the operating system version as '10.0.22621' (Windows 11 22H2), which is a supported version; there is no indication of an unsupported OS.

294
MCQhard

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. After deploying, users report that the app is not available in the work profile. What is the most likely cause?

A.The app has not been approved in the managed Google Play store.
B.The app is only available for corporate-owned devices.
C.Android Enterprise enrollment is not enabled in Intune.
D.The device does not have a work profile configured.
AnswerA

Managed Google Play apps must be approved by an Intune administrator before they become assignable to Android Enterprise work profile devices. Until approval occurs, the app remains unavailable in the managed store, so it never installs into the work profile despite the deployment.

Why this answer

Managed Google Play apps must be approved before they can be deployed to work profile devices. Without approval, the app will not appear in the work profile's Play Store.

Exam trap

Candidates often assume that deployment failure is due to device ownership type (corporate vs personal), but the key prerequisite is app approval in Managed Google Play.

295
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a .pkg app to these devices. What is the recommended method?

A.Add as a Windows line-of-business app.
B.Add as a macOS web app.
C.Add as a Microsoft Store app.
D.Add as a macOS line-of-business app.
AnswerD

Adding the .pkg as a macOS line-of-business app uses Intune's native LOB app type, which supports the .pkg format directly and satisfies the requirement to deploy to managed macOS devices without repackaging or third-party tooling.

Why this answer

The recommended method to deploy a .pkg app to macOS devices managed by Microsoft Intune is to add it as a macOS line-of-business (LOB) app. This app type is specifically designed for deploying macOS installer packages (.pkg) and requires the file to be uploaded directly to Intune, which then pushes the installation to enrolled devices using the Intune management agent for macOS.

Exam trap

The trap here is that candidates may confuse 'line-of-business app' with Windows-only deployment, or mistakenly think a 'web app' can install a native .pkg, but the correct answer is the macOS-specific LOB app type.

How to eliminate wrong answers

Option A is wrong because 'Windows line-of-business app' is intended for Windows app deployment (e.g., .msi or .exe files) and cannot be used to deploy .pkg files to macOS devices. Option B is wrong because 'macOS web app' is used to create a shortcut to a web application (URL) on the device, not to install a native .pkg package. Option C is wrong because 'Microsoft Store app' is for deploying apps from the Microsoft Store, which does not support .pkg files and is not applicable to macOS devices.

296
MCQhard

You manage Android Enterprise fully managed devices with Microsoft Intune. A critical line-of-business app must be installed silently on all devices, and users must not be able to uninstall it. The app is available as an APK. What should you do?

A.Upload the APK as a line-of-business app and assign it as available.
B.Upload the APK as a line-of-business app, assign it as required, and configure the app to be non-removable.
C.Deploy the app from the Managed Google Play store and assign it as required.
D.Use a mobile app configuration policy to push the APK to devices.
AnswerB

For Android Enterprise fully managed devices, Intune supports uploading APKs as line-of-business apps. A required assignment installs the app silently. Intune also provides an option to prevent users from uninstalling the app by marking it as non-removable, which directly satisfies both the silent installation and uninstall prevention requirements in the scenario.

Why this answer

Android Enterprise fully managed devices support line-of-business APK deployment through Intune. A required assignment ensures silent installation, and the non-removable setting prevents users from uninstalling the app. This combination is the correct way to meet both the silent install and uninstall prevention needs for a proprietary APK.

Exam trap

The trap here is thinking an available assignment or an app configuration policy can install an APK, or overlooking the non-removable setting.

297
MCQhard

Your organization plans to deploy a Win32 app to Windows 10 devices using Intune. The app requires the .NET Framework 4.8, which is not present on all devices. How should you handle this dependency?

A.Include the .NET installer in the same package
B.Use a PowerShell script to install .NET before the app
C.Add a dependency in Intune for the .NET Framework
D.Configure a detection rule for .NET
AnswerC

Adding a dependency in Intune lets the Win32 app's installation wait until the required .NET Framework 4.8 package is detected or installed on each device, satisfying the stem's constraint that the framework is missing on some devices. Intune evaluates dependencies before the app installs, ensuring the prerequisite is present first.

Why this answer

Intune's dependency feature allows you to specify another app (like .NET Framework 4.8) that must be installed before the Win32 app. Intune automatically installs the dependency app from the same Intune management extension context, ensuring the required runtime is present without manual scripting or bundling. This is the native, supported method for handling prerequisites in Win32 app deployment.

Exam trap

The trap here is that candidates confuse detection rules (which only check for existing software) with dependency management (which actually installs prerequisites), leading them to incorrectly choose Option D or attempt manual scripting in Option B.

How to eliminate wrong answers

Option A is wrong because including the .NET installer in the same package violates the principle of separation of concerns and can cause detection logic conflicts; Intune treats the package as a single app, so you cannot independently detect or manage .NET separately. Option B is wrong because using a PowerShell script to install .NET before the app is an unsupported workaround that bypasses Intune's dependency management, leading to unreliable detection and potential installation failures if the script fails. Option D is wrong because a detection rule only verifies whether the app is already installed; it does not trigger installation of the missing dependency, so .NET would remain absent and the app would fail to install.

298
MCQhard

You manage Windows devices with Microsoft Intune. You deploy a Win32 app that requires a specific registry key to be present before installation. You need to ensure the app installs only on devices that have the registry key. What should you configure?

A.A requirement rule in the app's properties.
B.A dependency on another app that creates the registry key.
C.A PowerShell script that checks for the registry key and installs the app if present.
D.A detection rule in the app's properties.
AnswerA

Requirement rules allow you to specify conditions that must be met for the app to install, such as operating system version, disk space, or a registry key. By configuring a requirement rule that checks for the registry key, Intune will only attempt installation on devices where the key exists.

Why this answer

Requirement rules in Intune Win32 app properties allow you to specify conditions that must be met for the app to be installed. You can check for a registry key, file, or other conditions. If the requirement is not met, the app is not installed.

This is the correct method to ensure installation only on devices with the specific registry key.

Exam trap

The trap here is confusing requirement rules with detection rules; requirement rules gate installation, detection rules verify it.

299
MCQeasy

A help desk technician reports that a Windows 11 device enrolled in Microsoft Intune has not received a newly assigned configuration profile. The device shows as compliant in the admin center. You need to force the device to check in with Intune immediately. What should you do?

A.From the device overview, select Retire to remove corporate data and force a re-enrollment
B.From the device overview in the Intune admin center, select Sync to trigger a check-in
C.From the device overview, select Collect diagnostics to gather logs and force a policy refresh
D.From the device overview, select Fresh Start to reset the device and reapply all policies
AnswerB

The Sync action on the device overview sends a push notification through the Windows Push Notification Service to the device, prompting the Intune Management Extension and MDM channel to check in immediately and pull new policies. This is the standard administrative action to force a check-in without waiting for the scheduled interval, and it directly addresses the scenario of a newly assigned profile not yet applied.

Why this answer

The Sync action in the Intune admin center sends a remote check-in request to the device, causing it to contact the service and apply any pending policies or profiles. It is the correct, non-destructive way to force an immediate check-in when a device appears healthy but has not yet received a newly assigned configuration. Other device actions such as Retire or Fresh Start are destructive and unrelated to policy refresh.

Exam trap

The trap here is confusing diagnostic or destructive device actions with the Sync action that actually triggers a policy refresh.

300
Multi-Selecteasy

You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?

Select 2 answers
A.Devices must be joined to Azure AD.
B.A Microsoft Defender for Endpoint license must be assigned.
C.Devices must be enrolled in Microsoft Intune.
D.Devices must have a third-party antivirus uninstalled.
E.An Azure AD Premium license must be assigned.
AnswersB, C

Assigning a Microsoft Defender for Endpoint licence to users is mandatory, since the service activates per-user entitlement; without it, onboarding packages deploy but devices remain unlicensed and report no telemetry to the Microsoft 365 Defender portal. This satisfies the stem's prerequisite that licensing be in place before Intune deployment begins.

Why this answer

Option B is correct because Microsoft Defender for Endpoint requires a valid license (e.g., Microsoft 365 E5 or a standalone Defender for Endpoint license) assigned to users before onboarding devices. Option C is correct because the scenario specifies deployment via Intune, so devices must be enrolled in Microsoft Intune to receive the onboarding configuration and policy. Option A is incorrect because Azure AD join is not strictly required; devices can be domain-joined or workgroup-joined as long as they are Intune-enrolled and meet other requirements.

Option D is incorrect because third-party antivirus does not need to be uninstalled; Defender for Endpoint can run in passive mode alongside it. Option E is incorrect because Azure AD Premium is not a prerequisite for Defender for Endpoint deployment.

Exam trap

The trap here is that candidates often confuse the prerequisites for Defender for Endpoint with those for other Microsoft 365 security services, mistakenly thinking Azure AD join or Azure AD Premium licenses are required, when in fact only an Intune enrollment and a Defender for Endpoint license are needed.

Page 3

Page 4 of 8

Page 5

All pages