Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 301–375

556 questions total · 8pages · All types, answers revealed

Page 4

Page 5 of 8

Page 6
301
Multi-Selecthard

You are preparing infrastructure for device management in Microsoft Intune. Your organization plans to deploy Windows 11 devices using Windows Autopilot in Microsoft Entra join mode. You need to ensure that the devices can be identified and assigned to the correct deployment profile. Which two actions must you perform? (Choose two.)

Select 2 answers
A.Deploy the Intune Company Portal app to all devices.
B.Register the device hardware hash in Intune.
C.Create an Autopilot deployment profile and assign it to a device group.
D.Enable automatic enrollment in Intune for all users.
E.Configure a conditional access policy requiring compliant devices.
AnswersB, C

Registering the hardware hash in Intune is essential for Autopilot. The hardware hash uniquely identifies the device, and without it, the device cannot be recognized as an Autopilot device. You can collect the hash manually or through the OEM, and then import it into Intune. This allows you to assign an Autopilot deployment profile to the device.

Why this answer

To identify and assign Autopilot devices, you must register the hardware hash in Intune and create an Autopilot deployment profile assigned to a device group. The hardware hash allows Intune to recognize the device as an Autopilot device, and the profile determines the deployment settings. Without these two actions, the device will not receive the intended Autopilot configuration.

Exam trap

The trap here is assuming that automatic enrollment or conditional access is needed for Autopilot, when actually the core requirements are hardware hash registration and a deployment profile assignment.

302
MCQhard

You use Microsoft Intune to manage Windows 11 devices. A critical Win32 app must install before any user signs in, and the installer cannot run in the user's context because it writes to protected registry keys and requires elevation. The app has no dependencies and does not need to be visible in the Company Portal. How should you configure the app?

A.Set Install behavior to User, and assign the app as Available to a device group.
B.Set Install behavior to System, and assign the app as Required to a device group.
C.Set Install behavior to System, and assign the app as Available to a user group.
D.Set Install behavior to User, and assign the app as Required to a device group.
AnswerB

System install context runs the installer as LocalSystem via the Intune Management Extension, which can write to protected registry keys and perform privileged operations without user interaction. Assigning as Required to a device group ensures the app is delivered to devices regardless of sign-in, satisfying the pre-sign-in requirement without publishing it in the Company Portal.

Why this answer

Because the installer needs privileged writes and must run without user interaction, configure Install behavior as System and assign the app as Required to a device group. System context lets the Intune Management Extension run the installer as LocalSystem, which handles protected registry writes silently, and Required device targeting guarantees delivery regardless of who signs in.

Exam trap

The trap here is pairing the correct System install context with an Available assignment, which reintroduces the user interaction the scenario forbids.

303
MCQhard

Your organization uses Microsoft Defender for Cloud Apps (part of Microsoft Defender XDR). You need to detect when users access cloud apps from unauthorized locations. Which log source should you integrate to get location information?

A.Microsoft Entra ID sign-in logs
B.Microsoft Intune device enrollment logs
C.Microsoft Purview audit logs
D.Microsoft Sentinel
AnswerA

Microsoft Entra ID sign-in logs record each authentication with the originating IP address, which Defender for Cloud Apps resolves into country, city and coordinates for its impossible travel and anomalous location detections. This directly satisfies the requirement to identify access from unauthorised locations, since the sign-in event carries the geo-location data the policy evaluates.

Why this answer

Microsoft Entra ID sign-in logs contain location information (IP address, country, city) for user sign-ins to cloud apps. Integrating these logs with Defender for Cloud Apps enables detection of access from unauthorized locations. Other log sources do not provide the necessary location context for cloud app access.

Exam trap

MD-102 often tests the confusion between different log sources; candidates may choose Microsoft Sentinel or Purview audit logs, but the specific location data for cloud app access comes from Entra ID sign-in logs.

How to eliminate wrong answers

Option B is wrong because Intune device enrollment logs pertain to device management, not user access to cloud apps, and lack location data. Option C is wrong because Microsoft Purview audit logs focus on compliance and data governance activities, not real-time sign-in locations. Option D is wrong because Microsoft Sentinel is a SIEM that can ingest logs, but it is not a log source itself; the question asks for the log source to integrate.

304
MCQeasy

You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?

A.Deploy a configuration profile with the Windows 11 installation script.
B.Create a Windows update ring profile targeting Windows 11.
C.Create a Windows feature update profile targeting Windows 11.
D.Configure a device compliance policy requiring Windows 11.
AnswerC

A Windows feature update profile is the dedicated Intune workload for delivering an in-place Windows 10 to Windows 11 upgrade, letting you target the 500 devices and control the version and rollout schedule. Update rings handle quality patches, not OS version upgrades, so they cannot satisfy this requirement.

Why this answer

A Windows feature update profile in Intune is specifically designed to deliver feature updates like upgrading from Windows 10 to Windows 11. It uses the Windows Update for Business (WUfB) service to orchestrate the in-place upgrade, ensuring the device meets prerequisites and the upgrade completes successfully. This is the correct policy type for managing OS version upgrades at scale.

Exam trap

The trap here is confusing a Windows update ring profile (which controls update behavior but not the target version) with a Windows feature update profile (which explicitly specifies the target OS version for an upgrade), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because Intune does not support deploying a configuration profile with an installation script for OS upgrades; configuration profiles manage settings, not OS installation or upgrade scripts. Option B is wrong because a Windows update ring profile controls the update deferral, delivery optimization, and restart behavior for quality and feature updates, but it does not specify the target OS version for an upgrade; it only manages how updates are applied, not which feature update is installed. Option D is wrong because a device compliance policy enforces security and configuration requirements (e.g., requiring Windows 11) but does not initiate or deliver the upgrade; it only reports non-compliance if the device is not running the required OS.

305
MCQeasy

A company uses Microsoft Intune to manage devices. They need to ensure that a critical line-of-business app is updated automatically on all devices. Which assignment type should they use?

A.Required
B.End-user notification
C.Uninstall
D.Available for enrolled devices
AnswerA

Required assignments push the app to every targeted device without user interaction, and Intune automatically installs updates when a newer version is detected. This satisfies the stem's constraint that the line-of-business app updates automatically across all devices, unlike Available, which depends on user initiation.

Why this answer

The Required assignment type in Microsoft Intune automatically installs and updates apps on managed devices without user interaction, making it the correct choice for ensuring a critical line-of-business app is updated automatically. This assignment enforces the app deployment policy by pushing the update to devices during their next check-in with the Intune service, typically within 8 hours.

Exam trap

The trap here is that candidates confuse 'Available for enrolled devices' with automatic updates, but it only provides optional installation from the Company Portal, not forced updates, which is a common misconception in MD-102 exams.

How to eliminate wrong answers

Option B is wrong because End-user notification is not an assignment type; it is a setting within an app assignment that controls whether users receive notifications about app updates, but it does not enforce automatic updates. Option C is wrong because Uninstall is an assignment type used to remove an app from devices, not to update it. Option D is wrong because Available for enrolled devices allows users to install the app from the Company Portal on demand, but it does not automatically update the app; users must manually trigger the update.

306
MCQeasy

A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?

A.Assign the app and configure 'Require device compliance' with a filter for minimum OS version.
B.Assign the app with 'Uninstall' intent.
C.Assign the app as 'Available for enrolled devices' without filters.
D.Assign the app as 'Required' to all devices.
AnswerA

Device compliance filters can enforce OS version requirements.

Why this answer

Intune allows you to create a filter based on device properties such as OS version, and apply that filter to app assignments. This ensures the deployment is only available to devices meeting the minimum OS version. Option B is incorrect because 'Uninstall' intent would remove the app, not deploy it with OS filtering.

Option C is incorrect because 'Available for enrolled devices' without filters does not enforce any OS version requirement. Option D is incorrect because assigning as 'Required' to all devices does not filter by OS version.

307
MCQeasy

You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?

A.Use Group Policy Editor to configure BitLocker locally on each device.
B.Check if the devices have TPM version 2.0.
C.Re-create the BitLocker policy with a different name.
D.Remotely sync the devices from the Intune console to refresh policy.
AnswerD

Intune applies policy on device check-in, so devices that have not contacted the service since assignment still lack BitLocker settings. Triggering a remote sync forces each device to retrieve and apply the endpoint security policy immediately.

Why this answer

When a BitLocker endpoint security policy is assigned but devices have not applied it, forcing a remote sync from the Intune console triggers the device to check in and apply pending policies, including BitLocker encryption.

Exam trap

MD-102 often tests whether candidates jump to re-enrollment or policy recreation when the correct first step is simply forcing a device sync to trigger pending policy application.

How to eliminate wrong answers

Option A is wrong because local Group Policy bypasses Intune management and defeats centralized control. Option B is wrong because TPM 2.0 is a prerequisite already verified; checking it again does not force policy application. Option C is wrong because recreating the policy with a new name does not address the sync delay and may cause duplicate policy conflicts.

308
MCQeasy

Refer to the exhibit. The JSON snippet shows a Windows Update for Business policy assigned to a device group. Users report that quality updates are installed 7 days after release. Which setting controls this behavior?

A.featureUpdateDeferralPeriodInDays
B.businessReadyUpdatesOnly
C.qualityUpdateDeferralPeriodInDays
D.automaticUpdateMode
AnswerC

qualityUpdateDeferralPeriodInDays directly governs how long devices wait before installing quality updates, so a value of 7 produces exactly the reported seven-day delay. The other deferral settings apply to different update categories, such as feature or driver updates, and therefore cannot satisfy this scenario's stated behaviour.

Why this answer

The setting `qualityUpdateDeferralPeriodInDays` controls how long quality updates (security fixes) are deferred after release. A value of 7 means updates are installed 7 days post-release, matching the user report. This is a Windows Update for Business policy configured via CSP (Policy CSP - Update).

Exam trap

The trap here is that candidates confuse `featureUpdateDeferralPeriodInDays` with quality update deferral, assuming all deferral settings work the same way, but they are separate policies for different update types.

How to eliminate wrong answers

Option A is wrong because `featureUpdateDeferralPeriodInDays` controls deferral of feature updates (major OS version upgrades), not quality updates. Option B is wrong because `businessReadyUpdatesOnly` determines whether to receive only business-ready (servicing channel) updates or preview updates, not the deferral period. Option D is wrong because `automaticUpdateMode` controls the update installation behavior (e.g., auto-install at scheduled time, notify download), not the deferral delay.

309
Multi-Selectmedium

You use Microsoft Intune to manage Windows 11 devices. You must deliver Microsoft 365 Apps (Microsoft 365 Apps for enterprise) to a group of devices and ensure that the deployment uses the Semi-Annual Enterprise Channel and excludes Access. You also need the installation to occur without user interaction. Which two actions should you perform? (Choose two.)

Select 2 answers
A.In the Microsoft 365 Apps app type in Intune, select the Semi-Annual Enterprise Channel from the update channel drop-down and remove Access from the list of Office apps.
B.Deploy a Win32 app that bundles the Office Deployment Tool and runs setup.exe with a configuration file as a system-context install.
C.Assign the Microsoft 365 Apps app as Required to the device group so it installs without user interaction.
D.Upload a custom Configuration.xml to the app's properties page and set the Office app suite to use the Current Channel.
E.Assign the Microsoft 365 Apps app as Available to the device group and instruct users to install it from the Company Portal.
AnswersA, C

The Microsoft 365 Apps (Windows 10 and later) app type in Intune includes configuration pages for update channel and app selection, so choosing Semi-Annual Enterprise Channel and deselecting Access directly satisfies both configuration requirements without scripting or XML editing.

Why this answer

The built-in Microsoft 365 Apps app type in Intune exposes update channel and app selection on its configuration pages, and a Required assignment installs the suite silently on targeted devices. Together these two actions deliver the specified channel while omitting Access and avoiding user interaction.

Exam trap

The trap here is assuming a custom XML or Win32 wrapper is mandatory for channel and app selection, when the native Microsoft 365 Apps app type already exposes those options.

310
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app using detection rules. The app installs but the detection rule incorrectly reports failure, causing repeated installation attempts. What is the best way to resolve this?

A.Uninstall and redeploy the app
B.Update the detection rule to accurately reflect installed state
C.Reinstall the app manually
D.Modify the installation command to suppress output
AnswerB

Detection rules determine whether Intune considers an app installed; a rule that misreads the installed state triggers repeated remediation. Correcting the rule to match the actual installed condition stops the false failure reporting, satisfying the requirement to halt repeated installation attempts.

Why this answer

The detection rule is the mechanism Intune uses to determine whether a Win32 app is already installed. If the rule incorrectly reports failure despite successful installation, Intune will repeatedly attempt to reinstall the app. Updating the detection rule to accurately reflect the installed state (e.g., checking for the correct file, registry key, or version) stops the unnecessary reinstall loop without requiring manual intervention or reconfiguration of the deployment.

Exam trap

The trap here is that candidates often assume the issue is with the installation command or the app itself, rather than recognizing that Intune's detection logic is the sole trigger for reinstallation attempts.

How to eliminate wrong answers

Option A is wrong because uninstalling and redeploying the app does not fix the root cause—the flawed detection rule—so the same incorrect detection will trigger reinstallation again after redeployment. Option C is wrong because manually reinstalling the app does not correct the detection rule; Intune will still detect the app as not installed based on the faulty rule and continue its reinstall attempts. Option D is wrong because modifying the installation command to suppress output does not change how Intune evaluates the detection rule; suppression only hides logs and does not address the mismatch between actual installation state and detection logic.

311
MCQeasy

You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?

A.Require device to be marked as compliant
B.Require multi-factor authentication
C.Require hybrid Azure AD joined device
D.Require approved client app
AnswerA

Requiring the device to be marked as compliant enforces Intune compliance state at token issuance, so Exchange Online blocks mail access from non-compliant devices. This directly satisfies the stem's constraint that only compliant devices reach corporate email, since Microsoft Entra ID evaluates the device's compliance status during sign-in.

Why this answer

The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your organization's compliance policies (e.g., BitLocker enabled, antivirus active, OS version current) can access Exchange Online. This leverages Microsoft Intune device compliance policies and the Microsoft Entra ID device registration state to block non-compliant devices from accessing corporate email.

Exam trap

The trap here is that candidates often confuse device compliance with device join type (hybrid Azure AD join) or app-level controls, mistakenly thinking that requiring a specific join type or approved app alone ensures the device is healthy and secure.

How to eliminate wrong answers

Option B is wrong because requiring multi-factor authentication (MFA) addresses identity verification, not device compliance; a compromised but MFA-enabled device could still access email. Option C is wrong because requiring a hybrid Azure AD joined device enforces a specific join type (typically for on-premises AD integration), but a device can be hybrid joined yet still be non-compliant (e.g., missing security updates). Option D is wrong because requiring an approved client app (e.g., Outlook mobile) controls the application used, not the device's compliance state; a non-compliant device could still use an approved app.

312
MCQmedium

You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?

A.The device is marked as non-compliant.
B.The device does not have a valid device certificate.
C.The device has not checked in with the Intune service recently.
D.The device enrollment profile has expired.
AnswerC

Intune policy evaluation depends on the device checking in with the service. Without a recent check-in, the console reports 'Not evaluated' or 'Pending' because no MDM session has delivered or acknowledged policy. Connectivity alone is insufficient.

Why this answer

When a device shows as 'Not evaluated' or 'Pending' in the Intune console, it indicates that the Intune service has not received a recent check-in from the device. Even if the device is enrolled and connected to the internet, it must periodically communicate with the Intune service to retrieve policies; the default check-in interval is approximately 8 hours, and if the device misses this window, policies remain unevaluated.

Exam trap

The trap here is that candidates often assume policy delivery failures are due to compliance or certificate issues, but the MD-102 exam specifically tests the understanding that a device must actively check in with the Intune service to receive policies, and a 'Pending' status directly indicates a missed check-in.

How to eliminate wrong answers

Option A is wrong because a non-compliant device still receives policies from Intune; compliance status affects conditional access, not policy delivery. Option B is wrong because while a valid device certificate is required for enrollment, the issue described is about policy retrieval after enrollment, and a missing or expired certificate would typically cause enrollment failure or a different error state, not a 'Not evaluated' status. Option D is wrong because enrollment profiles are used during the enrollment process itself; once a device is enrolled, the profile is no longer relevant for ongoing policy delivery, and an expired profile would prevent enrollment, not cause a 'Pending' state for already-enrolled devices.

313
MCQmedium

You are an administrator for a company that uses Microsoft Intune. You have an iOS line-of-business (LOB) app that you need to deploy to all iOS devices. The app is signed with an enterprise certificate. You upload the app to Intune and assign it as required. Users report that the app fails to install. What is the most likely cause?

A.The app was not packaged using the Microsoft Win32 Content Prep Tool.
B.The app assignment is set to required, but it should be set to available for iOS LOB apps.
C.The iOS devices are not enrolled in Intune as corporate-owned devices.
D.The app is not properly signed with a valid provisioning profile.
AnswerD

iOS LOB apps must be signed with a valid provisioning profile that includes the devices' UDIDs or uses enterprise distribution. If the provisioning profile is invalid, expired, or does not include the necessary devices, installation fails. Since the app is signed with an enterprise certificate, the provisioning profile must be correctly configured for enterprise distribution. A common cause of failure is an expired or misconfigured provisioning profile.

Why this answer

iOS line-of-business apps must be signed with a valid provisioning profile that supports enterprise distribution. If the provisioning profile is expired, does not include the necessary devices, or is otherwise invalid, the app will fail to install. This is the most likely cause when an enterprise-signed app fails to deploy.

Proper signing and provisioning are critical for successful iOS LOB app deployment via Intune.

Exam trap

The trap here is assuming that the assignment type or enrollment method is the issue, when the most common cause of iOS LOB app installation failure is an invalid or expired provisioning profile.

314
MCQhard

You use Microsoft Intune to manage Windows 11 devices. A device named LAPTOP-01 is not receiving a newly assigned device configuration profile. You verify the profile is assigned to a group that contains LAPTOP-01. You need to force the device to check in with Intune and apply the policy immediately. Which action should you perform from the Intune admin center?

A.Select the device and choose 'Sync'.
B.Restart the device from the Intune admin center.
C.Select the device and choose 'Remote lock'.
D.Select the device and choose 'Collect diagnostics'.
AnswerA

The 'Sync' action in the Intune admin center triggers an immediate check-in with the Intune service on the device. This causes the device to download and apply pending policies, including the new configuration profile. It is the standard method to force policy application without waiting for the scheduled check-in interval.

Why this answer

The 'Sync' action in the Intune admin center is designed to initiate an immediate device check-in with the Intune service. This prompts the device to retrieve and apply any pending policies, including newly assigned configuration profiles. Other actions like collecting diagnostics, remote lock, or restart do not directly trigger a policy sync and are not the correct approach for this requirement.

Exam trap

The trap here is assuming that restarting the device or collecting diagnostics will force a policy sync, when only the Sync action performs an immediate check-in.

315
MCQeasy

Your organization wants to deploy Windows Update for Business policies using Microsoft Intune to Windows 10 devices. Which policy type should you use?

A.App protection policy
B.Device configuration profile for Windows Update for Business
C.Device compliance policy
D.Endpoint security policy for antivirus
AnswerB

A device configuration profile containing the Windows Update for Business settings delivers deferral, deadline and restart controls directly to Windows 10 devices. This is the correct policy type for applying WUfB settings through Intune, rather than update rings or scripts.

Why this answer

Windows Update for Business (WUfB) policies are configured using a device configuration profile in Microsoft Intune, specifically under the 'Windows Update for Business' template. This profile type allows you to manage update settings such as deferral periods, pause updates, and feature update targeting directly from Intune without requiring on-premises WSUS or additional infrastructure.

Exam trap

The trap here is that candidates often confuse Device compliance policies (which can report update status) with the actual policy type that configures update behavior, leading them to select Option C instead of the correct Device configuration profile for Windows Update for Business.

How to eliminate wrong answers

Option A is wrong because App protection policies (APP) are designed to protect corporate data in mobile apps (e.g., Outlook, OneDrive) on iOS/iPadOS and Android devices, not to manage Windows Update settings. Option C is wrong because Device compliance policies evaluate device health (e.g., BitLocker status, antivirus state, OS version) and trigger conditional access, but they do not configure update deployment behavior or deferral policies. Option D is wrong because Endpoint security policies for antivirus manage Microsoft Defender Antivirus configurations (e.g., real-time protection, cloud-delivered protection), not Windows Update for Business settings.

316
MCQhard

Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?

A.Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.
B.Configure the MDM discovery URL in Microsoft Entra ID.
C.Create an enrollment restriction that allows Windows devices.
D.Assign a device compliance policy to the user.
AnswerA

The MDM user scope determines which Microsoft Entra ID users' devices are permitted to enrol automatically; setting it to All or Some enables automatic enrolment at sign-in. This satisfies the requirement for Microsoft Entra ID-joined Windows 11 devices to enrol without manual action.

Why this answer

Microsoft Entra ID joined devices automatically enroll in Intune when the MDM user scope is set to 'All' or 'Some'. Option B is incorrect because the MDM discovery URL is configured automatically for Microsoft Entra ID joined devices and does not need manual configuration. Option C is incorrect because enrollment restrictions control which devices can enroll but do not trigger automatic enrollment.

Option D is incorrect because device compliance policies are applied after enrollment, not before.

317
Multi-Selectmedium

You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require Trusted Platform Module (TPM)
B.Require Secure Boot to be enabled on the device
C.Require a minimum OS version
D.Require code integrity
E.Require BitLocker
AnswersB, E

The 'Require Secure Boot to be enabled on the device' setting verifies that Secure Boot is active. If Secure Boot is disabled, the device is noncompliant. This meets the requirement to enforce Secure Boot on Windows 11 devices.

Why this answer

To enforce BitLocker and Secure Boot, the compliance policy must include the 'Require BitLocker' and 'Require Secure Boot to be enabled on the device' settings. These directly evaluate the encryption and firmware security states. Other settings like TPM or code integrity are related but do not confirm that BitLocker and Secure Boot are active.

Exam trap

The trap here is selecting TPM or code integrity, which are prerequisites or related features, but do not directly verify that BitLocker and Secure Boot are enabled.

318
MCQmedium

Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?

A.Fully managed
B.Work profile
C.Device administrator
D.Corporate-owned personally enabled (COPE)
AnswerB

Android Enterprise work profile creates a separate managed profile on the device, isolating corporate apps and data from personal apps. This satisfies the sandboxing requirement by enforcing containerisation between work and personal contexts on the same device.

Why this answer

The Work profile enrollment type is correct because it creates a separate, managed container on Android Enterprise devices that isolates work apps and data from personal apps and data. This sandboxing is enforced by the Android Enterprise framework, ensuring that work apps cannot access personal data and vice versa, which meets the requirement for separation without requiring full device management.

Exam trap

The trap here is that candidates often confuse COPE with Work profile, assuming COPE is required for sandboxing on corporate-owned devices, but the question focuses on the enrollment type that ensures sandboxing regardless of ownership, making Work profile the correct choice.

How to eliminate wrong answers

Option A is wrong because Fully managed enrollment gives the organization complete control over the entire device, which does not provide sandboxing between work and personal apps—it manages the whole device as a corporate asset. Option C is wrong because Device administrator is a legacy Android management mode that does not support work profile sandboxing; it applies policies to the entire device and lacks the containerization capabilities of Android Enterprise. Option D is wrong because Corporate-owned personally enabled (COPE) uses a work profile for separation but is designed for corporate-owned devices that also allow personal use, whereas the question does not specify device ownership and Work profile is the standard enrollment type for sandboxing on personally owned devices.

319
MCQmedium

Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?

A.Create a Conditional Access policy requiring device compliance and blocking access if not compliant.
B.Enable 'Require BitLocker' compliance setting.
C.Deploy a PowerShell script via Intune that checks the Defender service status and reports to Intune custom compliance.
D.Add a compliance policy setting: 'Require the device to be at or under the machine risk score' with a low score.
AnswerD

This setting uses Defender for Endpoint risk score to evaluate compliance. If the device is not reporting, the score is not available, causing non-compliance.

Why this answer

Microsoft Defender for Endpoint integrates with Intune compliance policies via the 'Require the device to be at or under the machine risk score' setting. When a device stops reporting to Defender, its risk score escalates above the 'Low' threshold, causing Intune to mark it as non-compliant. This directly meets the requirement to flag non-reporting devices without additional scripting or conditional access complexity.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces compliance) with the compliance policy setting that actually defines what 'non-compliant' means, leading them to pick Option A instead of the correct risk-score setting.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy enforces access control based on compliance status but does not itself define or detect non-reporting devices; it relies on an existing compliance policy to flag them. Option B is wrong because 'Require BitLocker' only checks encryption status, not whether the device is actively reporting to Defender for Endpoint. Option C is wrong because while a custom PowerShell script can check Defender service status, it requires custom compliance discovery and is not the native, supported method for integrating Defender risk data into Intune compliance.

320
MCQhard

You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?

A.Windows compliance policy
B.Windows 10 and later update ring
C.Windows feature update policy
D.Windows driver update policy
AnswerB

Update rings for Windows 10 and later hold the deferral settings for feature and quality updates, so a single ring can defer feature updates 60 days and quality updates 14 days. Other Intune update profiles do not expose both deferral values together.

Why this answer

The Windows 10 and later update ring policy in Intune is specifically designed to configure Windows Update for Business settings, including deferral periods for feature and quality updates. By setting the 'Feature update deferral period (days)' to 60 and 'Quality update deferral period (days)' to 14, you directly control how long updates are postponed after they are released by Microsoft. This policy applies to devices managed via Intune and leverages the Windows Update for Business service to enforce these deferrals.

Exam trap

The trap here is that candidates often confuse the 'Windows feature update policy' (which targets a specific feature update version) with the 'update ring' policy (which controls deferral periods), leading them to select option C instead of B.

How to eliminate wrong answers

Option A is wrong because Windows compliance policy is used to evaluate device compliance against security requirements (e.g., OS version, antivirus status) and does not include settings to defer update installations. Option C is wrong because Windows feature update policy is a separate policy type that targets specific feature update versions (e.g., Windows 11 22H2) and does not control deferral periods for quality updates or general feature update deferral durations. Option D is wrong because Windows driver update policy is dedicated to managing driver updates (e.g., approval, deferral) and does not handle feature or quality update deferral settings.

321
MCQhard

You are an endpoint administrator for a company that uses Microsoft Intune. You deploy a Win32 app to Windows 10 devices using the Intune Management Extension. The app installation fails on some devices with error code 0x87D1041C. You need to resolve the installation failure. What is the most likely cause?

A.The app content is not fully uploaded to Intune.
B.The detection rule is not correctly identifying the app after installation.
C.The app installer requires a reboot that was not allowed.
D.The Intune Management Extension is not installed on the device.
AnswerB

Error code 0x87D1041C is specifically related to detection rule failures in Intune Win32 app deployments. It means the app installed but the detection rule did not find it, so Intune reports failure. Common causes include incorrect file path, version, or registry key in the detection rule. Reviewing and correcting the detection rule resolves the issue.

Why this answer

Error 0x87D1041C is a detection rule failure. It indicates the app installed but the detection rule did not find it, so Intune marks it as failed. The most likely cause is an incorrect detection rule, such as wrong file path, version, or registry key.

Correcting the detection rule resolves the issue.

Exam trap

The trap here is assuming the error is due to installation issues rather than detection, leading to troubleshooting the wrong component.

322
MCQeasy

A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?

A.The devices must be registered in Microsoft Intune via the hardware vendor or manually.
B.The organization must have a hybrid Azure AD join configuration in place.
C.BitLocker must be enabled on the devices before they are shipped.
D.A local administrator account must be created on each device prior to deployment.
AnswerA

Autopilot requires each device's hardware hash registered as an Autopilot device in Microsoft Intune before it can enrol. OEM registration lets the vendor upload hashes automatically, satisfying the stem's prerequisite so the 500 devices enrol without manual hash collection.

Why this answer

For Windows Autopilot to automatically enroll devices, the devices must be registered in Microsoft Intune. This can be done by the hardware vendor (OEM registration) or manually by the organization. Without registration, Autopilot cannot identify the device and apply the deployment profile.

Exam trap

MD-102 often tests the prerequisites for Autopilot, and candidates may confuse device registration with Azure AD join or other requirements.

How to eliminate wrong answers

Option B is wrong because hybrid Azure AD join is not a prerequisite for Autopilot; Autopilot supports Azure AD join and hybrid Azure AD join, but the key prerequisite is device registration. Option C is wrong because BitLocker does not need to be enabled before shipping; it can be enabled during Autopilot. Option D is wrong because a local administrator account is not required prior to deployment; Autopilot can configure local admin accounts as part of the deployment.

323
MCQmedium

You need to deploy a custom Windows 11 feature update to a pilot group of 50 devices before rolling out to the entire organization. The devices are managed by Intune and are in a 'Pilot' Azure AD group. What is the best approach?

A.Configure a Windows Update for Business deferral policy for all devices
B.Create a custom configuration profile with update settings
C.Create a feature update profile for Windows 11 and assign to the pilot group
D.Use Group Policy to configure Windows Update settings for the pilot group
AnswerC

A feature update profile targets specific Windows 11 versions and deploys to assigned Microsoft Entra groups, letting you scope the rollout to the 50-device Pilot group before broadening assignment. This satisfies the staged pilot-then-org requirement without manual installation.

Why this answer

Intune's feature update profiles are specifically designed to deploy Windows 11 feature updates to targeted Azure AD groups, such as the 'Pilot' group. This approach allows you to control the exact feature update version (e.g., Windows 11 23H2) and assign it only to the pilot devices, enabling a controlled rollout before expanding to the entire organization.

Exam trap

The trap here is that candidates often confuse feature update profiles with quality update policies or configuration profiles, mistakenly thinking any update-related setting can be applied via a configuration profile or deferral policy.

How to eliminate wrong answers

Option A is wrong because a Windows Update for Business deferral policy only delays the installation of updates; it does not deploy a specific feature update version to a targeted group. Option B is wrong because custom configuration profiles are used for device settings (e.g., security policies, app configurations), not for deploying feature updates; feature updates require a dedicated feature update profile. Option D is wrong because Group Policy is not applicable in a cloud-only Intune-managed environment; devices must be Azure AD joined and managed via Intune, and Group Policy requires on-premises Active Directory and Domain Services.

324
MCQmedium

Your organization uses Microsoft Intune to deploy apps to Windows 11 devices. You need to ensure that a Win32 app installs only when the device has at least 4 GB of RAM. What should you configure?

A.A dependency rule that includes a RAM check
B.A return code for insufficient RAM
C.A requirement rule that specifies minimum RAM
D.A detection rule for RAM
AnswerC

A requirement rule in Intune evaluates device attributes before installation, letting you specify minimum RAM as a custom requirement. This directly satisfies the stem's 4 GB threshold, blocking deployment on under-spec devices. Detection rules only verify presence post-install, and applicability rules belong to Configuration Manager, not Win32 app deployment.

Why this answer

To enforce a hardware prerequisite like minimum RAM for a Win32 app in Microsoft Intune, you configure a requirement rule. Requirement rules define the device conditions (e.g., operating system architecture, disk space, or RAM) that must be met before the app can install. Option C is correct because it directly specifies a minimum RAM value as a requirement rule, ensuring the app installs only on devices with at least 4 GB of RAM.

Exam trap

The trap here is confusing requirement rules (which enforce hardware/software prerequisites) with detection rules (which verify existing installation) or dependency rules (which manage app installation order), leading candidates to incorrectly select a detection or dependency rule for a hardware prerequisite.

How to eliminate wrong answers

Option A is wrong because dependency rules control the order of app installation (e.g., requiring another app to be installed first), not hardware checks like RAM. Option B is wrong because return codes define how Intune interprets the exit code from the app installer (e.g., success, reboot, or failure), but they cannot enforce a prerequisite condition before installation begins. Option D is wrong because detection rules are used to determine whether an app is already installed (e.g., checking for a file or registry key), not to evaluate hardware requirements before installation.

325
MCQeasy

Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?

A.The device's product key
B.The device's hardware hash (4K HH)
C.The user's Microsoft account
D.The device's BIOS password
AnswerB

Autopilot identifies devices by their unique hardware hash, a 4K value capturing serial number, hardware IDs and other attributes. Uploading this hash creates the Autopilot device record that ties the physical device to your tenant during OOBE.

Why this answer

Windows Autopilot requires the device's hardware hash (4K HH) to uniquely identify the device during the registration process. This hash is generated from the device's hardware components and is uploaded to the Microsoft Intune or Partner portal to associate the device with an Autopilot profile. Without the hardware hash, Autopilot cannot recognize the device as registered and will not apply the deployment profile.

Exam trap

The trap here is that candidates often confuse the hardware hash with the product key, assuming that a license or activation key is needed for Autopilot registration, but Autopilot relies solely on hardware-based identification.

How to eliminate wrong answers

Option A is wrong because the product key is used for Windows activation, not for Autopilot registration; Autopilot uses the hardware hash to identify the device. Option C is wrong because the user's Microsoft account is not required for device registration; Autopilot registration is device-centric and occurs before user sign-in. Option D is wrong because the BIOS password is a security feature for local access control and has no role in Autopilot's device identification or enrollment process.

326
MCQhard

Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?

A.Deploy Windows Autopilot for all devices and require Entra ID join
B.Configure Conditional Access policies in Microsoft Entra ID that require compliant devices
C.Configure a VPN profile in Intune and enforce device compliance on the VPN server
D.Create a compliance policy in Intune and assign it to all users
AnswerB

Conditional Access evaluates device compliance state signalled by Intune, granting Microsoft 365 access only when the device meets security policies. This satisfies the requirement that unmanaged devices be blocked, since compliance policies alone cannot enforce access at the identity layer.

Why this answer

Conditional Access policies in Microsoft Entra ID can require that devices accessing Microsoft 365 services be marked as compliant by Intune. This ensures that only devices meeting your security policies (e.g., encryption, antivirus, OS patch level) are granted access, directly addressing the security team's concern about unmanaged devices on public Wi-Fi.

Exam trap

The trap here is that candidates often confuse creating a compliance policy (which only defines the rules) with enforcing it via Conditional Access (which actually blocks access), leading them to select Option D instead of B.

How to eliminate wrong answers

Option A is wrong because Windows Autopilot and Entra ID join streamline device provisioning and identity, but they do not enforce compliance checks at the point of access to Microsoft 365 services. Option C is wrong because configuring a VPN profile in Intune and enforcing compliance on the VPN server only controls access to the VPN tunnel, not to Microsoft 365 services directly; users could still access those services without going through the VPN. Option D is wrong because creating a compliance policy in Intune and assigning it to users only defines and reports compliance status; it does not enforce access blocking—Conditional Access is required to actually block non-compliant devices from accessing Microsoft 365.

327
Multi-Selecthard

Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)

Select 3 answers
A.Windows Information Protection (WIP).
B.Windows Defender Application Control (WDAC).
C.Intune application control policies.
D.AppLocker.
E.BitLocker drive encryption.
AnswersB, C, D

WDAC is a Windows 10 hypervisor-protected code integrity feature that enforces an explicit allowlist of trusted binaries at the kernel level. Intune deploys WDAC policies as a custom OMA-URI, satisfying the requirement that only approved applications execute on managed devices.

Why this answer

Windows Defender Application Control (WDAC) (B) is correct because it is Microsoft's application control technology that enforces code integrity policies on Windows 10, allowing only approved/trusted binaries to execute based on publisher, hash, or file path rules. Intune application control policies (C) are correct because Intune can deploy and manage application control configurations—including WDAC and AppLocker policies—to Windows 10 devices, letting administrators centrally enforce which apps are allowed. AppLocker (D) is correct because it is a built-in Windows 10 application control feature that restricts which applications and files users can run using allow/deny rules based on publisher, path, or hash.

Windows Information Protection (A) is not an application control mechanism; it is a data protection feature that helps prevent accidental data leakage by separating and encrypting corporate data, not by blocking unapproved applications. BitLocker (E) is a full-disk encryption feature that protects data at rest, and it has no role in controlling which applications are permitted to run.

Exam trap

The trap here is that candidates often confuse Windows Information Protection (WIP) with application control because both involve 'policies' in Intune, but WIP is strictly for data loss prevention, not for blocking or allowing application execution.

328
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?

A.Check if the user has logged in and acknowledged the FileVault prompt.
B.Ensure that a compliance policy is also assigned requiring encryption.
C.Ensure the devices are supervised.
D.Verify that the profile is assigned to the correct device group.
AnswerA

FileVault encryption only starts after the local user authenticates and approves the privacy prompt enabling the secure token; until that acknowledgement occurs, the profile applies but the disk stays unencrypted, so checking user sign-in and prompt acceptance explains the unencrypted devices.

Why this answer

FileVault encryption on macOS requires user interaction to complete. When Intune deploys a FileVault profile with recovery key escrow, the user must log in and explicitly acknowledge the FileVault prompt to enable encryption. If the user has not done so, the device remains unencrypted regardless of the profile assignment.

Exam trap

The trap here is that candidates often assume a configuration profile alone enforces encryption immediately, overlooking the mandatory user interaction step required by macOS for FileVault activation.

How to eliminate wrong answers

Option B is wrong because compliance policies do not trigger encryption; they only report non-compliance after encryption is expected. Option C is wrong because macOS devices do not require supervision for FileVault encryption or key escrow; supervision is an iOS/iPadOS concept. Option D is wrong because if the profile were assigned to the wrong group, the profile would not appear on the device at all, but the issue here is that the profile is deployed yet encryption is not active, indicating a user interaction gap.

329
MCQmedium

You manage iOS/iPadOS devices with Microsoft Intune. You need to ensure that when a device is lost or stolen, its corporate data can be remotely wiped while leaving personal data intact. The devices are enrolled as user enrollment (personal devices). What should you do?

A.Retire the device from Intune and then delete the device record.
B.Issue a full wipe from the Intune console for the device.
C.Issue a selective wipe from the Intune console for the device.
D.Configure a conditional access policy to block the device from accessing corporate resources.
AnswerC

For user-enrolled iOS/iPadOS devices, a selective wipe removes only corporate data, management profiles, and managed apps, leaving personal data and apps untouched. This is the correct action to protect corporate information on a lost personal device without affecting the user's personal content.

Why this answer

For user-enrolled iOS/iPadOS devices, selective wipe is the correct action to remove corporate data while preserving personal data. It targets only managed apps, profiles, and corporate data. Full wipe would erase personal content, retiring does not actively wipe, and conditional access only blocks access without removing data.

Exam trap

The trap here is assuming that any wipe action removes all data; on personal devices, only selective wipe preserves personal content.

330
MCQmedium

You manage Windows 10 devices with Microsoft Intune. A user reports that a device has a red shield icon in the Windows Security Center, indicating tamper protection is off. You need to re-enable tamper protection on the device using Intune. Which profile type should you configure?

A.Device configuration profile (settings catalog)
B.Endpoint protection profile (Microsoft Defender Antivirus)
C.Security baseline (Windows 10/11)
D.Compliance policy
AnswerB

Endpoint protection profiles for Microsoft Defender Antivirus expose the tamper protection toggle directly, letting Intune push the setting to the device without a script. This satisfies the requirement to re-enable tamper protection remotely, since Defender Antivirus configuration is the only Intune profile type that carries that specific setting.

Why this answer

Tamper protection is a Microsoft Defender Antivirus setting that prevents unauthorized changes to security features. In Intune, this setting is configured under the 'Endpoint protection profile' using the 'Microsoft Defender Antivirus' template, specifically via the 'Enable tamper protection to prevent Microsoft Defender being disabled' toggle. This profile type directly manages Defender settings, including tamper protection, and applies them to enrolled Windows 10 devices.

Exam trap

The trap here is that candidates confuse the 'Security baseline' (which applies many security settings but not tamper protection) with the 'Endpoint protection profile' (which specifically manages Defender features like tamper protection), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because a Device configuration profile (settings catalog) can configure many Windows settings but does not include the specific tamper protection setting for Microsoft Defender Antivirus; tamper protection is only exposed through the Endpoint protection profile. Option C is wrong because a Security baseline (Windows 10/11) applies a predefined set of security policies, but tamper protection is not a setting within the baseline; it must be configured separately via an Endpoint protection profile. Option D is wrong because a Compliance policy evaluates device compliance against rules (e.g., requiring tamper protection to be on) but cannot enforce or enable tamper protection; it only reports non-compliance and can trigger remediation actions via other profiles.

331
MCQmedium

Refer to the exhibit. You run this PowerShell command using the Microsoft Graph PowerShell SDK. What is the primary purpose of this command?

A.To list only non-compliant Windows devices.
B.To retrieve all managed devices regardless of operating system.
C.To enforce compliance on Windows devices.
D.To retrieve a list of all Windows managed devices with their compliance status.
AnswerD

The Graph SDK cmdlet queries managedDevices filtered by operating system, returning each Windows device alongside its complianceState property. This satisfies the stem's aim of listing all Windows managed devices together with their current compliance status.

Why this answer

The PowerShell command uses `Get-MgDeviceManagementManagedDevice` with a filter for `operatingSystem eq 'Windows'` and selects properties including `complianceState`. This retrieves all Windows managed devices and their compliance status, making option D correct. The command does not filter by compliance state, so it returns both compliant and non-compliant devices, and it does not enforce any compliance action.

Exam trap

The trap here is that candidates may assume the command only returns non-compliant devices because complianceState is selected, but the filter does not restrict by compliance value—it merely includes that property in the output.

How to eliminate wrong answers

Option A is wrong because the command does not filter by complianceState; it retrieves all Windows devices, not just non-compliant ones. Option B is wrong because the filter `operatingSystem eq 'Windows'` explicitly limits results to Windows devices, not all managed devices regardless of operating system. Option C is wrong because the command is a read-only GET operation that retrieves device data; it does not perform any enforcement or remediation actions on compliance.

332
MCQeasy

Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?

A.Custom
B.Endpoint protection
C.Device restrictions
D.Device features
AnswerB

Endpoint protection profiles in Microsoft Intune expose the FileVault disk encryption settings for macOS, letting you enforce encryption across managed devices. This profile type satisfies the stem's requirement to ensure all macOS devices have FileVault enabled.

Why this answer

'Endpoint protection' profiles include FileVault settings for macOS. Option A is incorrect because 'Custom' profiles are used for importing custom settings, not for encryption. Option C is incorrect because 'Device restrictions' contain general restrictions but not FileVault.

Option D is incorrect because 'Device features' include settings like wallpaper and lock screen, not encryption.

333
Multi-Selecthard

Which THREE factors can cause a required app deployment to fail on a Windows 10 device managed by Intune? (Choose three.)

Select 3 answers
A.The device has an app update policy that blocks updates.
B.The device is not connected to the internet.
C.The user is not assigned to the app.
D.The device does not meet the app's requirement rules.
E.The app's dependency is not installed.
AnswersB, D, E

A required app deployment relies on the Intune Management Extension polling Microsoft Entra ID and Intune endpoints to receive policy and content. Without internet connectivity, the device cannot check in, so the assignment never reaches it and installation never triggers. This directly satisfies the stem's requirement for a cause of deployment failure.

Why this answer

Option B is correct because a required Intune app deployment relies on the device checking in with the Intune service and downloading content from Intune/Windows Delivery Optimization, so without internet connectivity the device cannot receive the policy or the app payload and the install fails. Option D is correct because requirement rules (such as OS version, architecture, disk space, or registry checks) are evaluated before installation; if the device does not satisfy them, Intune marks the app as not applicable and the required install does not proceed. Option E is correct because dependencies (for example, a Win32 app that requires another app or a specific framework) must be installed first; if a dependency fails or is missing, the dependent app's installation fails.

Option A is not correct because an app update policy blocking updates affects updating already-installed apps, not the initial required deployment of an app. Option C is not correct because a required deployment targets device or user groups; if the user is not assigned, the app simply is not deployed to that user rather than causing a deployment that was assigned to fail.

Exam trap

The trap here is that candidates often confuse 'app update policy' (which controls updates) with 'app deployment policy' (which controls initial installation), leading them to incorrectly select Option A as a cause of deployment failure.

334
MCQeasy

Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?

A.Join the device to Azure AD hybrid by configuring a domain join profile.
B.Create an Autopilot deployment profile with 'Assign to' set to 'All devices' and ensure the device is registered in Autopilot.
C.Configure the Enrollment Status Page (ESP) to require device enrollment.
D.Manually add the device serial number to Intune via the admin center.
AnswerB

An Autopilot deployment profile with 'Assign to' set to 'All devices' applies the enrolment settings to every registered Autopilot device. Combined with prior Autopilot registration, this triggers automatic Microsoft Intune enrolment at first power-on, requiring no user action.

Why this answer

Windows Autopilot requires both a registered device (identified by hardware hash) and an assigned deployment profile to trigger automatic enrollment in Microsoft Intune during the first power-on. Setting 'Assign to' to 'All devices' ensures the profile applies to any registered Autopilot device, and the device registration step links the hardware identity to your tenant. Without this combination, the device will not automatically enroll.

Exam trap

The trap here is that candidates confuse the Enrollment Status Page (ESP) with the enrollment trigger itself, thinking ESP configuration alone enables automatic enrollment, when in fact ESP only manages the post-enrollment provisioning sequence.

How to eliminate wrong answers

Option A is wrong because joining a device to Azure AD hybrid via a domain join profile is a separate configuration for hybrid-joined devices and does not by itself trigger automatic Intune enrollment; Autopilot enrollment requires a deployment profile with enrollment settings. Option C is wrong because the Enrollment Status Page (ESP) controls the end-user experience during enrollment (e.g., blocking use until apps are installed) but does not initiate or enforce device enrollment; enrollment must already be configured via a deployment profile. Option D is wrong because manually adding a device serial number to Intune via the admin center registers the device for management but does not create an Autopilot deployment profile; without a profile assigned, the device will not automatically enroll during first power-on.

335
MCQeasy

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a Microsoft Store app (new) to a set of users, and the app must be installed automatically without requiring them to visit the Company Portal. Which assignment intent should you choose for the user group?

A.Available for enrolled devices
B.Required
C.Available for enrolled devices with a deadline
D.Uninstall
AnswerB

Required intent tells Intune to install the app automatically on targeted devices or for targeted users without any action in the Company Portal. For a Microsoft Store app (new) assigned to a user group, Required delivers the app silently to those users' enrolled devices, matching the automatic-install requirement.

Why this answer

Required is the assignment intent that makes Intune install an app automatically for the targeted users or devices. Because the app must install without the user opening the Company Portal, Available intent is unsuitable, and Uninstall would remove rather than add the app. Required on the user group produces the silent automatic installation described.

Exam trap

The trap here is confusing Available with Required, since both deliver the app but only Required installs it without user action.

336
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps for enterprise to 500 devices. The devices are in a hybrid Azure AD joined configuration. The administrator wants to use Intune to deploy the apps. Which deployment method should the administrator use?

A.Use the Office Deployment Tool (ODT) to create a configuration file and deploy via Intune as a Win32 app.
B.Use Group Policy to deploy the Office 2019 suite.
C.Add a 'Microsoft 365 Apps for Windows 10 and later' app in Intune and assign it to the devices.
D.Upload the Office installation files as a line-of-business (LOB) app.
AnswerC

The built-in Microsoft 365 Apps app type in Intune deploys the suite to Windows 10 and later devices, supporting hybrid Azure AD joined endpoints. Assigning it to the device group satisfies the 500-device deployment requirement without packaging.

Why this answer

Intune provides a built-in 'Microsoft 365 Apps for Windows 10 and later' app type that is specifically designed to deploy and manage Microsoft 365 Apps for enterprise. This method uses Intune's native integration with the Office Content Delivery Network (CDN) to download and install the latest version of Office, and it supports hybrid Azure AD joined devices without requiring additional tools or configuration files.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing the Office Deployment Tool (Option A) because they think it provides more control, but they miss that Intune's native 'Microsoft 365 Apps' app type is the simplest and most appropriate method for standard deployments, especially when no custom XML configuration is required.

How to eliminate wrong answers

Option A is wrong because while the Office Deployment Tool (ODT) can be used to create a configuration file, deploying it as a Win32 app is unnecessarily complex and bypasses Intune's native Office app management capabilities, which provide automatic updates and simplified assignment. Option B is wrong because Group Policy is not an Intune deployment method; it relies on on-premises Active Directory and does not integrate with Intune for cloud-managed device deployment. Option D is wrong because uploading Office installation files as a line-of-business (LOB) app is intended for single-file or simple app packages, not for the multi-component, dynamically updated Microsoft 365 Apps suite, and it would require manual updates and lack the built-in configuration options.

337
MCQeasy

A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?

A.Use the Microsoft Intune admin center to view the Windows Update for Business report
B.Use Microsoft 365 Lighthouse
C.Use the Device compliance report in Intune
D.Use Microsoft Defender for Endpoint's advanced hunting
AnswerA

The Windows Update for Business report in the Microsoft Intune admin center aggregates update installation state per device, including specific KBs. It satisfies the requirement to identify which managed devices have a particular Windows update installed, without needing custom scripting or third-party tooling.

Why this answer

The Windows Update for Business report in the Microsoft Intune admin center provides a dedicated view of update compliance, including which devices have installed specific Windows updates. This report aggregates data from the Windows Update service and displays it per device, making it the correct method for identifying devices with a particular update installed.

Exam trap

The trap here is that candidates often confuse the Device compliance report (which checks OS version or build) with the Windows Update for Business report (which tracks specific KB installations), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Lighthouse is designed for multi-tenant management of Microsoft 365 services across customers, not for granular per-device Windows update reporting within a single tenant. Option C is wrong because the Device compliance report in Intune focuses on compliance policies (e.g., encryption, OS version) and does not track individual Windows update KB installations. Option D is wrong because Microsoft Defender for Endpoint's advanced hunting uses Kusto Query Language (KQL) to query security-related events and device information, but it is not the primary or recommended method for reporting on Windows update installation status; it requires custom queries and lacks the pre-built update-specific aggregation of the Windows Update for Business report.

338
MCQmedium

You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?

A.The kiosk profile is not correctly assigned.
B.The device is not assigned to a user.
C.The AUMID for Microsoft Edge is not specified.
D.The device is not running Windows 10/11 Enterprise.
AnswerC

The kiosk profile requires the Application User Model ID to identify which app launches in single-app mode. Without a valid Edge AUMID, the assigned access configuration cannot resolve a target application, so the device boots to a blank shell instead of Edge. Specifying the correct AUMID satisfies the single-app kiosk constraint.

Why this answer

The most likely issue is that the AUMID for Microsoft Edge is not specified in the kiosk profile. For a single-app kiosk on Windows 11, Intune requires the Application User Model ID (AUMID) to launch the app correctly. Without it, the kiosk shell cannot identify which executable to run, resulting in a blank screen instead of the Edge browser.

Exam trap

The trap here is that candidates assume a blank screen means a policy assignment failure or licensing issue, when in fact it is a configuration detail—the missing AUMID—that prevents the kiosk app from launching.

How to eliminate wrong answers

Option A is wrong because the kiosk profile assignment is verified by the device receiving the policy; a blank screen indicates the profile applied but the app failed to launch, not that assignment is missing. Option B is wrong because a kiosk device can be assigned to a device group without a user; user assignment is not required for single-app kiosk mode. Option D is wrong because Windows 11 Pro supports kiosk mode via Intune; only Windows 10/11 Enterprise or Education is required for multi-app kiosk or Assigned Access, but single-app kiosk works on Pro.

339
MCQeasy

You manage a fleet of Android Enterprise devices. You need to ensure that only approved apps from the managed Play Store can be installed. What configuration should you enable?

A.Set the device to 'Fully managed' and disable unknown sources.
B.Deploy an app configuration policy that blocks sideloading.
C.Configure a device restriction policy to allow only managed Google Play apps.
D.Use a compliance policy to block non-compliant apps.
AnswerC

Device restriction policies in Microsoft Intune expose a managed Google Play setting that blocks installation from unknown sources, so only apps approved in the managed Play Store can be installed. This directly satisfies the requirement to restrict Android Enterprise devices to approved applications.

Why this answer

A device restriction policy in Microsoft Intune allows you to restrict app installation to only the managed Google Play store. By configuring the 'Allow only managed Google Play apps' setting, you ensure that users cannot install apps from unapproved sources, effectively controlling the app ecosystem on Android Enterprise devices.

Exam trap

The trap here is that candidates often confuse reactive compliance policies (which detect non-compliant apps after installation) with proactive device restriction policies (which prevent installation entirely), leading them to choose Option D instead of the correct proactive setting.

How to eliminate wrong answers

Option A is wrong because setting the device to 'Fully managed' and disabling unknown sources does not restrict installations to only managed Google Play apps; it only prevents sideloading from unknown sources, but users could still install apps from the public Play Store. Option B is wrong because an app configuration policy is used to configure app-specific settings (e.g., account credentials or permissions), not to block sideloading or restrict app sources; blocking sideloading is a device restriction. Option D is wrong because a compliance policy can mark devices as non-compliant if non-approved apps are detected, but it does not prevent installation of those apps in the first place; it only reacts after the fact.

340
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a security baseline that enforces BitLocker encryption and Windows Defender Antivirus settings. What is the recommended approach?

A.Create a custom configuration profile using Configuration Manager.
B.Deploy a PowerShell script via Intune to configure the settings.
C.Use the built-in Windows 10 security baseline in Intune.
D.Apply Group Policy Objects from on-premises Active Directory.
AnswerC

The built-in Windows 10 security baseline in Intune delivers preconfigured Microsoft-recommended settings for exactly these areas, including BitLocker drive encryption and Windows Defender Antivirus. It satisfies the requirement to enforce both without manually authoring each setting, and supports version upgrades as new baseline releases appear.

Why this answer

The recommended approach is to use the built-in Windows 10 security baseline in Intune (Option C). Intune provides pre-configured security baselines that include settings for BitLocker encryption and Windows Defender Antivirus, which can be customized as needed. Option A is incorrect because custom configuration profiles do not provide the pre-built baseline and are more manual.

Option B is incorrect because PowerShell scripts are not a baseline and are less manageable at scale. Option D is incorrect because Group Policy from on-premises AD is not integrated with Intune and requires hybrid infrastructure.

341
MCQeasy

A company uses Windows Autopilot for user-driven deployments. They want to ensure that during the out-of-box experience (OOBE), users are required to sign in with their Azure AD credentials and the device is automatically enrolled in Intune. Which Autopilot deployment profile setting should be configured?

A.Set 'Deployment mode' to 'Self-Deploying' and 'Join to Azure AD as' to 'Azure AD joined'.
B.Set 'Deployment mode' to 'User-Driven' and 'Join to Azure AD as' to 'Hybrid Azure AD joined'.
C.Set 'Deployment mode' to 'White Glove' and 'Join to Azure AD as' to 'Azure AD joined'.
D.Set 'Deployment mode' to 'User-Driven' and 'Join to Azure AD as' to 'Azure AD joined'.
AnswerD

User-Driven mode presents the OOBE sign-in page, and Azure AD joined makes the device join Microsoft Entra ID and auto-enrol in Intune. Together they satisfy the requirement for credential-based sign-in and automatic enrolment during out-of-box experience.

Why this answer

The scenario requires a user-driven deployment where the user signs in with Azure AD credentials during OOBE, and the device is automatically enrolled in Intune. Setting 'Deployment mode' to 'User-Driven' ensures the user authenticates during OOBE, and 'Join to Azure AD as' to 'Azure AD joined' makes the device Azure AD-joined, which triggers automatic Intune enrollment via the MDM enrollment authority configured in Azure AD.

Exam trap

The trap here is that candidates often confuse 'Self-Deploying' with 'User-Driven' because both can result in Azure AD join and Intune enrollment, but 'Self-Deploying' does not require user sign-in during OOBE, which is explicitly required in the question.

How to eliminate wrong answers

Option A is wrong because 'Self-Deploying' mode does not require user sign-in during OOBE; it uses a device token for automatic enrollment, which contradicts the requirement for user Azure AD credentials. Option B is wrong because 'Hybrid Azure AD joined' requires the device to be joined to an on-premises Active Directory and then registered with Azure AD, which is not the scenario described and does not rely solely on Azure AD credentials during OOBE. Option C is wrong because 'White Glove' (now called 'Pre-Provisioning') is a technician-driven process that pre-provisions the device before the user receives it, and the user still signs in later, but the question specifies that users sign in during OOBE, not that a technician pre-provisions.

342
MCQeasy

An organization wants to enforce encryption on all Windows 10/11 devices using Intune. Which policy type should they use?

A.Device compliance policy
B.App protection policy
C.Device configuration profile (settings catalog)
D.Endpoint security disk encryption policy
AnswerD

Endpoint security disk encryption policies in Intune configure BitLocker settings and silently enable encryption across Windows 10 and 11 devices, including escrowing recovery keys to Microsoft Entra ID. This is the purpose-built policy type for enforcing encryption at scale.

Why this answer

The Endpoint security disk encryption policy in Intune is specifically designed to enforce encryption (e.g., BitLocker) on Windows 10/11 devices. It provides a dedicated, streamlined interface for configuring encryption settings and monitoring compliance, unlike general device configuration profiles which require manual setup via the settings catalog. This policy type is the correct choice because it directly targets disk encryption as a security baseline, aligning with the organization's goal to enforce encryption across all managed devices.

Exam trap

The trap here is that candidates often confuse Device compliance policy (which only checks encryption status) with a policy that actually enforces encryption, or they assume the settings catalog is the only way to configure BitLocker, missing the purpose-built Endpoint security disk encryption policy.

How to eliminate wrong answers

Option A is wrong because Device compliance policy evaluates whether devices meet compliance rules (e.g., encryption status) but does not enforce or configure encryption settings; it only reports non-compliance. Option B is wrong because App protection policy applies to mobile apps and data at the app level (e.g., MAM), not to the operating system or disk encryption on Windows devices. Option C is wrong because Device configuration profile (settings catalog) can configure BitLocker settings, but it is a general-purpose tool that requires manual selection of individual settings, whereas Endpoint security disk encryption policy provides a purpose-built, policy-driven approach with built-in monitoring and reporting for encryption enforcement.

343
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune. You need to deploy Microsoft 365 Apps to Windows devices. The company requires that the apps update automatically from the Office CDN and that users cannot modify the update channel. Which method should you use?

A.Deploy Microsoft 365 Apps using the Microsoft Store app (new) and configure automatic updates.
B.Deploy Microsoft 365 Apps as a Win32 app with a custom configuration XML.
C.Deploy Microsoft 365 Apps as a line-of-business app using an MSI package.
D.Deploy Microsoft 365 Apps using the Microsoft 365 Apps app type in Intune and configure update settings in the app suite configuration.
AnswerD

The Microsoft 365 Apps app type in Intune allows you to configure update settings, including the update channel and automatic updates from the Office CDN. You can also lock the channel to prevent user changes. This method provides the required control and meets the scenario's requirements.

Why this answer

The Microsoft 365 Apps app type in Intune is designed specifically for deploying and managing Microsoft 365 Apps. It includes options to set the update channel and enforce automatic updates from the Office CDN, and it allows you to prevent users from changing these settings. This is the most efficient and supported method.

Exam trap

The trap here is assuming that any deployment method that installs Microsoft 365 Apps will also provide the necessary update control, when only the built-in app type does.

344
Multi-Selecthard

Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)

Select 2 answers
A.Enrollment Status Page (ESP) configuration.
B.Device registration in the Autopilot service using hardware hash.
C.On-premises Active Directory domain join.
D.Windows Autopilot deployment profile in Intune.
E.Microsoft Configuration Manager co-management.
AnswersB, D

Registering the device's hardware hash in the Windows Autopilot service creates the Autopilot device identity, which is mandatory for user-driven Microsoft Entra ID join. Without this record, the device cannot be matched to a deployment profile during OOBE, so the profile's join settings never apply.

Why this answer

Option B is correct because a device must first be registered in the Windows Autopilot service by uploading its hardware hash (collected via Get-WindowsAutopilotInfo or the OEM) so that the Autopilot service can recognize the device and associate it with the tenant during OOBE. Option D is correct because a Windows Autopilot deployment profile in Intune defines the critical settings for the user-driven Entra ID join scenario, including the deployment mode (User-Driven), the join type (Microsoft Entra joined), and the out-of-box experience options that drive the enrollment. Option A is not required: the Enrollment Status Page is an optional configuration that only controls what the user sees during device setup and does not enable the Autopilot deployment itself.

Option C is incorrect because user-driven Autopilot with Microsoft Entra ID join does not require on-premises Active Directory domain join; that would be a hybrid Entra join scenario. Option E is incorrect because Microsoft Configuration Manager co-management is not a prerequisite for Autopilot; Intune alone is sufficient to deliver the deployment profile and manage the device.

Exam trap

The trap here is that candidates often confuse the optional Enrollment Status Page with a mandatory component, or they mistakenly believe on-premises Active Directory join is required for user-driven Autopilot, when in fact Microsoft Entra ID join is a separate, cloud-native identity option.

345
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a user reports a lost device, you can remotely lock it and display a custom message on the lock screen. The solution must not erase any data. What should you do?

A.Use the Fresh Start action.
B.Perform a full wipe.
C.Use the Remote lock action and configure a custom lock screen message.
D.Perform a selective wipe.
AnswerC

The Remote lock action in Intune allows you to lock a device remotely. For Windows devices, you can also configure a custom lock screen message via a device configuration profile. This combination locks the device and displays a message without erasing data, meeting all requirements.

Why this answer

To remotely lock a lost Windows device and display a custom message without erasing data, use the Remote lock action in Intune. Additionally, configure a custom lock screen message through a device configuration profile. This secures the device and provides contact information, all without data loss.

Exam trap

The trap here is assuming that selective wipe or Fresh Start can lock a device or display a message, when they are data removal or refresh tools.

346
MCQhard

Contoso Ltd. is a financial services company with 2,000 users. They use Microsoft Intune to manage Windows 10 devices. The company has a strict security policy that requires all devices to have a specific set of security applications installed: an antivirus (AV) app, a disk encryption app, and a VPN client. These apps are all line-of-business (LOB) Win32 apps packaged as .intunewin files. The administrator created a Win32 app for each and assigned them as 'Required' to all devices. After the deployment, the administrator notices that the apps are not installing on approximately 10% of devices. The devices are online and have connectivity. The Intune Management Extension is running. When the administrator checks the Intune Management Extension logs on a failing device, they see the following error: 'Failed to download content. Error: 0x80070002 - The system cannot find the file specified.' What is the most likely cause?

A.The content for the Win32 app was not uploaded correctly or is missing from Intune.
B.The Intune Management Extension does not have permission to install apps on those devices.
C.The user is not logged in, so the app cannot be installed.
D.The app detection rules do not match the installed version.
AnswerA

Error 0x80070002 means the Intune Management Extension cannot locate the app content in the local cache after download, which occurs when the .intunewin content was never successfully uploaded to Intune, leaving devices nothing to retrieve.

Why this answer

The error 0x80070002 ('The system cannot find the file specified') in the Intune Management Extension logs indicates that the client is attempting to download the Win32 app content from Intune, but the content blob is missing or inaccessible. This typically occurs when the .intunewin file was not uploaded correctly, the upload was interrupted, or the content was deleted from Intune after assignment. Since the extension is running and connectivity is confirmed, the issue is server-side content availability, not client-side permissions or detection logic.

Exam trap

The trap here is that candidates often confuse a download failure with a detection rule mismatch or permission issue, but the specific error code 0x80070002 points directly to missing content on the server side, not client-side configuration problems.

How to eliminate wrong answers

Option B is wrong because the Intune Management Extension runs as SYSTEM and does not require additional permissions to install apps; a permission issue would manifest as an access denied error, not a 'file not found' error. Option C is wrong because Win32 apps assigned as 'Required' install in the system context regardless of user login state; user presence is irrelevant for system-context installations. Option D is wrong because detection rules only affect whether the app is considered installed after the download and installation attempt; they do not cause a download failure with error 0x80070002, which occurs before any detection logic runs.

347
MCQeasy

You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?

A.Compliance policies in Intune
B.MDM user scope in Microsoft Entra ID
C.Co-management slider in Configuration Manager
D.Enrollment device platform restrictions in Intune
AnswerB

MDM user scope in Microsoft Entra ID determines which users' devices are automatically enrolled into Intune when they join Microsoft Entra ID. Configuring it to All or a selected group satisfies the stem's requirement for automatic enrolment triggered by the join itself.

Why this answer

The MDM user scope setting in Microsoft Entra ID (formerly Azure AD) controls which users can automatically enroll their Windows 10 devices into Intune when they join Entra ID. When set to 'All' or 'Some', the device triggers automatic MDM enrollment during the Entra ID join process using the MDM enrollment protocol (MS-MDE), eliminating the need for manual enrollment steps.

Exam trap

The trap here is that candidates often confuse the MDM user scope (which controls the automatic enrollment trigger) with enrollment restrictions or compliance policies, which only apply after the enrollment process has already started.

How to eliminate wrong answers

Option A is wrong because compliance policies in Intune evaluate device compliance after enrollment, not trigger or configure automatic enrollment. Option C is wrong because the co-management slider in Configuration Manager controls workload distribution between ConfigMgr and Intune for already-managed devices, not the initial automatic enrollment of Windows 10 into Intune during Entra ID join. Option D is wrong because enrollment device platform restrictions in Intune block or allow enrollment based on platform or version after the enrollment attempt is initiated, but do not enable or configure the automatic enrollment trigger itself.

348
MCQhard

Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?

A.Configure a Microsoft Sentinel playbook.
B.Configure a Microsoft Foundry AI model.
C.Configure a Microsoft Purview data loss prevention policy.
D.Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
AnswerD

The Defender for Endpoint–Intune connector shares device risk and vulnerability findings with Intune, which then applies remediation actions such as pushing scripts or configuration to affected devices. This satisfies the stem's automatic-trigger requirement without manual analyst intervention.

Why this answer

The native integration between Microsoft Defender for Endpoint and Microsoft Intune enables automatic remediation of vulnerabilities discovered by Defender's threat and vulnerability management (TVM) component. When Defender XDR surfaces a critical vulnerability, Intune can push remediation actions (patches, configuration changes, app updates) to the affected managed devices without manual intervention. This is the built-in 'security task' workflow that flows from Defender into Intune's endpoint security node.

Exam trap

MD-102 often tests whether candidates confuse Sentinel (SIEM/SOAR for log analytics) with the native Defender-to-Intune remediation pipeline, causing them to pick the 'automation' answer (Sentinel playbook) instead of the built-in integration.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel playbooks are SOAR automation triggered by Sentinel incidents/analytics rules, not by Defender for Endpoint vulnerability findings feeding Intune remediation. Option B is wrong because Microsoft Foundry (Azure AI Foundry) is an AI model development platform with no endpoint remediation capability. Option C is wrong because Microsoft Purview DLP policies govern data handling and exfiltration, not vulnerability remediation on endpoints.

349
MCQhard

You are deploying a Win32 app that requires administrator privileges to install. The app runs on Windows 11 devices. How should you configure the app in Intune to ensure it installs with elevated privileges?

A.Set the app install behavior to 'System'.
B.Set the app to run in user context.
C.Use a PowerShell script to run the installer.
D.Configure a detection rule to check for admin rights.
AnswerA

Setting install behaviour to System runs the Win32 app installer in the SYSTEM context, granting local administrator rights. This satisfies the elevation requirement, whereas User context installs with the signed-in user's standard privileges and would fail.

Why this answer

Setting the install behavior to 'System' in Intune for a Win32 app ensures the installer runs with the SYSTEM account, which inherently has administrator privileges. This is required for apps that demand elevated rights during installation, as the SYSTEM account bypasses user account control (UAC) and can write to protected system locations like Program Files or the registry.

Exam trap

The trap here is that candidates often confuse 'install behavior' with 'detection rules' or 'script execution,' mistakenly thinking a PowerShell script or a detection rule can enforce elevation, when in fact only the 'System' context setting in Intune ensures the installer runs with the necessary administrator privileges.

How to eliminate wrong answers

Option B is wrong because setting the app to run in user context executes the installer with the logged-on user's permissions, which typically lack the administrator privileges needed for this app, causing installation failure. Option C is wrong because using a PowerShell script to run the installer does not inherently elevate privileges; the script runs under the same context as the Intune deployment agent unless explicitly configured with a separate elevation mechanism, which is not specified. Option D is wrong because configuring a detection rule to check for admin rights does not grant or enforce elevation during installation; detection rules only verify whether the app is already installed, not how it installs.

350
MCQhard

You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?

A.Hybrid Azure AD join
B.Entra ID registered with on-premises domain join
C.Windows Autopilot self-deploying mode
D.Entra ID joined with VPN to on-premises
AnswerA

Hybrid Microsoft Entra join registers on-premises Active Directory domain-joined devices with Microsoft Entra ID, enabling Intune enrolment and policy delivery while preserving the Kerberos and LDAP trust needed for on-premises resource access. This satisfies the stem's dual requirement: Intune management plus continued access to on-premises resources.

Why this answer

Hybrid Azure AD join is the correct approach because it allows devices that are joined to on-premises Active Directory to also register with Microsoft Entra ID, enabling Intune management while maintaining access to on-premises resources via Kerberos/NTLM authentication. This configuration synchronizes the device object from AD to Entra ID using Azure AD Connect, creating a device identity that can be managed by Intune and can authenticate against both cloud and on-premises services without requiring a VPN.

Exam trap

The trap here is that candidates often confuse 'Entra ID registered' with 'Hybrid Azure AD join' because both involve Entra ID, but only Hybrid Azure AD join provides the on-premises domain join required for seamless resource access without a VPN.

How to eliminate wrong answers

Option B is wrong because Entra ID registered devices are only workplace-joined (personal or BYOD) and do not have a computer object in on-premises AD, so they cannot authenticate to on-premises resources using domain credentials or access domain-joined file shares without additional configuration. Option C is wrong because Windows Autopilot self-deploying mode is designed for kiosk or shared devices that are Entra ID joined only, not hybrid joined, and thus cannot natively access on-premises resources without a VPN or other connectivity solution. Option D is wrong because Entra ID joined devices with a VPN can access on-premises resources, but they are not domain-joined and therefore cannot use Kerberos authentication to on-premises AD; they rely on VPN connectivity and typically require additional solutions like Microsoft Entra application proxy or Always On VPN for seamless resource access, making it less integrated than Hybrid Azure AD join.

351
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?

A.Ensure the device is running Windows 10 Enterprise.
B.Run the Policy Manager tool on the device.
C.Verify the device is a member of the assigned device group.
D.Check the device's notification area for a policy update prompt.
AnswerC

Device configuration profiles apply only to targeted device groups. If the device is absent from the assigned group, the kiosk profile never reaches it, so membership is the first thing to verify before investigating policy conflicts or sync errors.

Why this answer

The most common reason a kiosk mode profile fails to apply is that the device is not a member of the assigned device group. Intune evaluates policy targeting based on group membership; if the device is missing from the group, the profile will never be delivered. Verifying group membership is the first logical troubleshooting step before investigating device-level issues.

Exam trap

The trap here is that candidates often assume the issue is a licensing or edition requirement (Windows 10 Enterprise) when the real problem is almost always a misconfigured or missing group assignment in Intune.

How to eliminate wrong answers

Option A is wrong because Windows 10 Pro also supports kiosk mode via assigned access, so Enterprise is not a strict prerequisite. Option B is wrong because the Policy Manager tool (rsop.msc) is used for Group Policy, not Intune MDM policies; Intune policies are managed via the MDM sync and the device's Settings app. Option D is wrong because Intune does not display a policy update prompt in the notification area; policy sync is silent or triggered manually via Settings > Accounts > Access work or school > Info > Sync.

352
MCQmedium

You manage devices with Microsoft Intune. You need to ensure that only devices that meet specific compliance requirements can access Microsoft 365 services. You create a compliance policy and assign it to a group of users. What should you do next to enforce the policy?

A.Enable device compliance in the Microsoft Intune admin center
B.Configure a device configuration profile with a compliance setting
C.Create a conditional access policy that requires compliant devices
D.Assign the compliance policy to the devices
AnswerC

Conditional Access policies in Microsoft Entra ID can require that devices be marked as compliant by Intune before granting access to cloud apps. This enforces the compliance policy. Without a Conditional Access policy, the compliance policy only reports status but does not block access. Therefore, this is the necessary next step to enforce compliance.

Why this answer

To enforce compliance for access to Microsoft 365 services, you must create a Conditional Access policy that requires devices to be compliant. The compliance policy alone only evaluates and reports compliance status; it does not block access. Assigning to devices or enabling a setting does not enforce access control.

Conditional Access is the correct enforcement tool.

Exam trap

The trap here is thinking that assigning a compliance policy is enough to block access; enforcement requires a Conditional Access policy.

353
Matchingmedium

Match each Microsoft 365 Apps update channel to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Monthly updates with new features first

Monthly security and quality updates

Updates twice a year (January and July)

Early access to upcoming features

Insider builds for testing

Why these pairings

Update channels control how Microsoft 365 Apps are updated, relevant for MD-102.

354
MCQeasy

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft Outlook is protected even if the device is not enrolled in MDM. Which policy should you deploy?

A.Device compliance policy
B.Device configuration profile
C.Conditional Access policy
D.App protection policy (MAM)
AnswerD

App protection policies apply at the app layer via Microsoft Intune, enforcing encryption, PIN and selective wipe on Outlook data without requiring device enrolment. This satisfies the constraint that corporate data must be protected on unenrolled iOS devices.

Why this answer

App protection policies (MAM) protect corporate data in apps like Outlook without requiring device enrollment in MDM. Option A (Device compliance policy) requires MDM enrollment. Option B (Device configuration profile) is for device settings, not data protection.

Option C (Conditional Access policy) controls access but does not directly protect data within apps.

355
MCQmedium

Your organization has Windows 10 devices managed by Intune. You need to enforce BitLocker encryption on all devices. The devices must use a TPM protector and a recovery password. What should you configure?

A.Compliance policy for Windows 10
B.Endpoint security > Disk encryption policy
C.Windows Update for Business policy
D.Device configuration profile for Windows 10
AnswerB

Disk encryption policies under Endpoint security configure BitLocker settings, including requiring a TPM protector and recovery password, then enforce encryption across targeted Windows devices. This is the dedicated Intune workload for BitLocker, unlike general device configuration profiles.

Why this answer

To enforce BitLocker encryption with a TPM protector and recovery password on Windows 10 devices managed by Intune, you must configure an Endpoint security > Disk encryption policy. This policy type specifically targets BitLocker settings, including TPM and recovery password requirements, and is designed to enforce encryption at the device level through the Intune MDM channel.

Exam trap

The trap here is that candidates often confuse Device configuration profiles (Option D) with Endpoint security policies, but Microsoft explicitly separates disk encryption into the Endpoint security node for focused management, and the exam tests this distinction.

How to eliminate wrong answers

Option A is wrong because Compliance policy for Windows 10 evaluates device compliance after encryption is applied but does not configure BitLocker settings like TPM or recovery password; it only reports on encryption status. Option C is wrong because Windows Update for Business policy controls update rings and feature updates, not disk encryption or BitLocker configuration. Option D is wrong because Device configuration profile for Windows 10 can include some BitLocker settings, but the recommended and correct method for enforcing BitLocker with specific protectors in Intune is the Endpoint security > Disk encryption policy, which provides a dedicated, streamlined interface for encryption policies.

356
MCQhard

You are deploying a line-of-business (LOB) app to iOS devices managed by Intune. The app requires a specific configuration to access internal resources. Which approach should you use to deliver the configuration?

A.Assign a custom device configuration profile
B.Create an App Configuration Policy targeting managed devices
C.Deploy an App Protection Policy
D.Use Apple Volume Purchase Program (VPP) tokens
AnswerB

An App Configuration Policy for managed devices pushes key-value settings to the app via the Intune MDM channel, so the LOB app receives its internal-resource configuration without repackaging. This satisfies the stem's requirement to deliver configuration to managed iOS devices.

Why this answer

An App Configuration Policy targeting managed devices is the correct approach because it allows you to supply XML or JSON settings directly to the LOB app on iOS devices enrolled in Intune. This policy is applied when the app runs, enabling it to access internal resources without requiring a separate device profile or user interaction.

Exam trap

The trap here is that candidates often confuse App Configuration Policies (which deliver app-specific settings) with App Protection Policies (which enforce data protection), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because a custom device configuration profile manages device-level settings (e.g., Wi-Fi, VPN, restrictions) and cannot deliver app-specific configuration settings to a line-of-business app. Option C is wrong because an App Protection Policy manages data protection and access controls (e.g., PIN, encryption, save-as restrictions) for apps that integrate with Intune SDK, but it does not deliver app-specific configuration settings. Option D is wrong because Apple Volume Purchase Program (VPP) tokens are used to manage app licensing and distribution, not to deliver app configuration settings.

357
MCQhard

A user has a Windows 10 device that is enrolled in Microsoft Intune. The user reports that they cannot install a required app from the Company Portal. You check the Intune console and see that the app assignment is 'Required' but the installation status shows 'Failed'. The device is compliant. What should you check first?

A.Review the Intune management extension logs on the device.
B.Verify the device compliance policy.
C.Check the Company Portal app version.
D.Reassign the app to the user.
AnswerA

Reviewing the Intune management extension logs reveals why the Win32 app agent failed to install, since that extension handles Win32 app delivery and its local log records specific error codes. This directly satisfies the stem's 'Failed' installation status on an enrolled, compliant device, where compliance is not the blocker.

Why this answer

The Intune management extension (IME) handles app installation, PowerShell scripts, and custom compliance actions on Windows devices. When a required app fails to install despite the device being compliant, the IME logs (located in `ProgramData\Microsoft\IntuneManagementExtension\Logs`) provide granular error details such as exit codes, download failures, or dependency issues. Reviewing these logs is the fastest way to diagnose the root cause without making assumptions about compliance or app version.

Exam trap

The trap here is that candidates assume a compliant device means all Intune operations will succeed, overlooking that the Intune management extension is a separate component with its own failure modes unrelated to device compliance.

How to eliminate wrong answers

Option B is wrong because the device is already confirmed compliant, so compliance policy is not the cause of the installation failure. Option C is wrong because the Company Portal app version affects the user interface and enrollment flow, not the backend installation of a required app pushed by Intune. Option D is wrong because reassigning the app does not address the underlying failure reason and may simply reproduce the same error without diagnostic insight.

358
MCQhard

A company uses Configuration Manager to deploy Windows 11. During the deployment, several devices fail with error code 0x80070002. The administrator suspects the issue is related to missing boot images or content distribution. What should the administrator do first to resolve the issue?

A.Increase the client cache size on the affected devices.
B.Check the driver packages in the task sequence.
C.Verify that the boot image and OS image are distributed to all distribution points.
D.Recreate the task sequence with new OS image.
AnswerC

Error 0x80070002 signals missing content, so the boot image or OS image package is absent from a distribution point the client queried. Verifying distribution to all distribution points directly addresses the content-distribution constraint in the stem before deeper troubleshooting.

Why this answer

Error code 0x80070002 translates to 'The system cannot find the file specified.' In a Configuration Manager task sequence deployment, this typically indicates that the boot image or OS image content is not available on the distribution point that the client is accessing. Verifying distribution ensures the required content is present and accessible, which is the most direct and common fix for this error.

Exam trap

The trap here is that candidates often focus on client-side issues like cache or drivers, but the error code 0x80070002 specifically points to missing or inaccessible content on the server side, making distribution verification the correct first step.

How to eliminate wrong answers

Option A is wrong because increasing client cache size does not resolve missing content on distribution points; cache size affects local storage of downloaded content, not content availability. Option B is wrong because driver packages are not the primary cause of a 'file not found' error during boot image or OS image retrieval; missing drivers would cause hardware-specific failures, not a generic 0x80070002. Option D is wrong because recreating the task sequence is unnecessary and time-consuming; the issue is content distribution, not the task sequence definition itself.

359
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Azure AD. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Azure AD joined. What is the most likely reason for the failure, and how should you resolve it?

A.Devices are not hybrid Azure AD joined; convert them to hybrid join for BitLocker policy to apply.
B.The policy does not specify a recovery key escrow location; configure it to escrow to Azure AD.
C.The policy is missing the 'Enable full disk encryption' setting or the encryption method is not specified; check the 'Windows Encryption' settings in the profile.
D.Devices are not co-managed with Configuration Manager; enable co-management to apply BitLocker policy.
AnswerC

The Endpoint Protection template requires the Windows Encryption settings to explicitly enable BitLocker and specify an encryption method; without them, no encryption is enforced. Enabling full disk encryption with the TPM protector and recovery key escrow resolves the failure.

Why this answer

The 'Endpoint Protection' template for Windows 10 and later requires explicit configuration of the 'Enable full disk encryption' setting and the encryption method (e.g., XTS-AES 128-bit) under the 'Windows Encryption' section. Without these settings, the policy does not trigger BitLocker to start encryption on the device, even if other settings like TPM protector and recovery key escrow are configured. The devices are Azure AD joined and meet hardware requirements, so the missing encryption enablement is the most likely cause.

Exam trap

The trap here is that candidates assume configuring TPM protector and recovery key escrow is sufficient to enable BitLocker, but the 'Enable full disk encryption' setting is a separate mandatory toggle that must be explicitly enabled in the policy.

How to eliminate wrong answers

Option A is wrong because BitLocker policies in Intune apply to both Azure AD joined and hybrid Azure AD joined devices; hybrid join is not a prerequisite for BitLocker policy application. Option B is wrong because the question states that the policy already includes a recovery key escrow to Azure AD, so the failure is not due to a missing escrow location. Option D is wrong because co-management with Configuration Manager is not required for Intune to manage BitLocker on Windows 11 devices; Intune can apply BitLocker policies directly via the MDM channel.

360
MCQmedium

Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?

A.The ComplianceState reflects the last sync; the device may have changed compliance since.
B.The device is compliant but not syncing because it is turned off.
C.The device is no longer enrolled but shows compliant due to a reporting delay.
D.The compliance policy was removed after the last sync.
AnswerA

ComplianceState is a cached value populated at the last device check-in. With no sync for seven days, Intune has not re-evaluated the device, so the stored 'compliant' result may no longer reflect its actual state.

Why this answer

The ComplianceState property in Microsoft Intune reflects the compliance status at the time of the last device check-in. If a device has not synced for 7 days, the stored ComplianceState is stale and may no longer represent the actual compliance posture. The device could have become non-compliant since its last sync due to policy changes, missing updates, or configuration drift, but Intune will not update the state until the next successful sync.

Exam trap

Microsoft Intune often tests the misconception that ComplianceState is a live, real-time indicator, when in fact it is a snapshot from the last successful sync, and candidates may incorrectly assume a compliant state means the device is currently secure.

How to eliminate wrong answers

Option B is wrong because a device that is turned off cannot sync, but the ComplianceState would still show the last known state; the issue is not that the device is compliant but not syncing, but that the state is outdated. Option C is wrong because if the device were no longer enrolled, it would not appear in the managed devices list or would show an 'unenrolled' status, not a compliant state with a 7-day sync gap. Option D is wrong because removing a compliance policy after the last sync would not retroactively change the ComplianceState; the device would remain compliant until the next sync, at which point it would be evaluated against the new policy set.

361
MCQeasy

You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?

A.The user's password has expired.
B.The root CA certificate required to validate the RADIUS server certificate is not installed on the device.
C.The Wi-Fi profile is not assigned to the user's device.
D.The device's Wi-Fi adapter driver is outdated.
AnswerB

SCEP certificate authentication requires the device to trust the RADIUS server's certificate chain. Without the root CA certificate installed via an Intune trusted certificate profile, the device rejects the server during the TLS handshake, so the Wi-Fi connection fails while other networks work.

Why this answer

The device can connect to other Wi-Fi networks but not the corporate one, indicating the issue is specific to the corporate network's authentication requirements. Since the profile uses SCEP certificate authentication, the device must trust the root CA that issued the RADIUS server certificate to validate the server during the EAP-TLS handshake. If the root CA certificate is missing, the client will reject the RADIUS server certificate, causing the connection to fail.

This is the most likely cause because the profile assignment and driver are not specific to this single network failure.

Exam trap

The trap here is that candidates confuse a missing root CA certificate with a missing client certificate, but the symptom of being able to connect to other networks isolates the problem to server-side certificate validation, not client-side enrollment.

How to eliminate wrong answers

Option A is wrong because password expiration is irrelevant to SCEP certificate authentication, which uses machine or user certificates, not passwords. Option C is wrong because the device is enrolled in Intune and has a Wi-Fi profile assigned, so the profile is present; if it were not assigned, the profile would not appear at all, but the user can see and attempt to connect. Option D is wrong because an outdated Wi-Fi adapter driver would affect all Wi-Fi connections, not just the corporate network, and the user can connect to other networks successfully.

362
MCQeasy

You use Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a minimum OS version of 10.0.19044. You configure the setting 'Minimum OS version' to '10.0.19044'. Which additional setting must you configure to ensure that devices running a higher version, such as 10.0.19045, are also considered compliant?

A.Set 'Maximum OS version' to the highest supported build.
B.Configure a device configuration profile to set the OS version.
C.Set 'Valid operating system builds' to include all builds greater than 10.0.19044.
D.No additional setting is required; the minimum OS version setting allows higher versions by default.
AnswerD

The 'Minimum OS version' setting in Intune compliance policies checks that the device's OS version is greater than or equal to the specified value. Devices running a higher version, such as 10.0.19045, automatically satisfy the requirement. Therefore, no additional configuration is needed to include higher versions; they are inherently compliant.

Why this answer

The 'Minimum OS version' setting in a Windows compliance policy specifies the lowest acceptable OS build. Any device with an OS version equal to or higher than the specified value is considered compliant. Therefore, devices running 10.0.19045 or later automatically meet the requirement.

No additional setting is needed to include higher versions, as the comparison is inclusive and allows any newer build.

Exam trap

The trap here is thinking you need to specify a range or maximum to include newer versions, when in fact the minimum setting already permits all higher versions.

363
MCQeasy

A user reports that their iOS device is not receiving email on their work account. The device is enrolled in Intune. You verify that the Exchange ActiveSync profile is assigned correctly. What should you check next?

A.Ensure the MDM authority is set to Intune.
B.Check if an app protection policy is assigned to the user.
C.Verify that the device is enrolled in device enrollment manager mode.
D.Check the device's compliance status in Intune.
AnswerD

Conditional access in Microsoft Entra ID blocks Exchange ActiveSync when a device falls out of compliance, so a non-compliant status directly halts mail synchronisation despite correct profile assignment. Verifying compliance confirms whether access policy, not configuration, is preventing the iOS device from receiving email.

Why this answer

When an iOS device enrolled in Intune is not receiving email despite a correctly assigned Exchange ActiveSync profile, the next logical check is the device's compliance status. Conditional Access policies often require compliant devices to access Exchange Online, so a non-compliant device will be blocked from syncing email even if the profile is assigned.

Exam trap

The trap is focusing on the EAS profile itself — candidates assume the profile is the issue, but Conditional Access and compliance status are common blockers for email sync on enrolled devices.

How to eliminate wrong answers

Option A is wrong because the MDM authority is a tenant-wide setting; if it were not set to Intune, no devices would enroll, but the device is already enrolled. Option B is wrong because app protection policies (MAM) apply to apps and do not block native iOS Mail from syncing Exchange ActiveSync. Option C is wrong because device enrollment manager mode is for enrolling multiple devices with a single account and is not relevant to a single user's email issue.

364
Multi-Selecthard

You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to migrate Group Policy objects (GPOs) to Intune policies for Windows 10 devices. Which THREE tools or methods should you use?

Select 3 answers
A.MDM Migration Analysis Tool (MMAT)
B.Custom OMA-URI settings in a configuration profile
C.Desktop Analytics
D.Group Policy Analytics in Microsoft Intune
E.PowerShell scripts to apply registry settings
AnswersA, B, D

MMAT assesses GPO compatibility with MDM.

Why this answer

The MDM Migration Analysis Tool (MMAT) is correct because it analyzes existing on-premises Group Policy Objects (GPOs) and generates a report mapping each GPO setting to its equivalent MDM policy in Intune, including a readiness score. This tool directly supports the migration workflow by identifying which GPOs can be converted and which require manual intervention, making it essential for planning a GPO-to-Intune migration.

Exam trap

The trap here is that candidates often confuse Desktop Analytics (a Windows upgrade readiness tool) with Group Policy Analytics (a GPO-to-Intune migration tool), leading them to incorrectly select Desktop Analytics as a valid migration method.

365
MCQmedium

You administer Microsoft Intune for a company with 2,000 Windows 11 devices. The security team requires that all devices automatically receive an Intune enrollment record when they are first powered on by end users, without requiring users to manually enroll. You have already configured a Windows Autopilot deployment profile and assigned it to a device group. Which additional configuration is required to meet the requirement?

A.Enable the Enrollment Status Page (ESP) in the Autopilot profile.
B.Assign the Autopilot deployment profile to a user group instead of a device group.
C.Create a device configuration profile that enables the Intune Management Extension.
D.Configure automatic enrollment in Microsoft Entra ID for Windows devices.
AnswerD

Automatic enrollment in Microsoft Entra ID ensures that when an Autopilot device joins or registers in Microsoft Entra ID, it is automatically enrolled in Intune without user action. This setting is found in the Microsoft Intune admin center under Devices > Enroll devices > Automatic enrollment, or in Microsoft Entra ID. Without it, even with an Autopilot profile, devices may not create an Intune enrollment record automatically.

Why this answer

Automatic enrollment in Microsoft Entra ID is the tenant-level setting that allows Windows devices to enroll in Intune automatically when they join or register in Microsoft Entra ID. For Autopilot, this must be enabled so that devices create an Intune record without user intervention. The other options do not enable automatic enrollment; they are either unrelated features or incorrect assignment methods.

Exam trap

The trap here is assuming that an Autopilot deployment profile alone triggers Intune enrollment, when actually automatic enrollment in Microsoft Entra ID must be configured separately.

366
Multi-Selecteasy

Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)

Select 2 answers
A.Change the primary user of the device
B.Reinstall Windows 11 from scratch
C.Retain the Autopilot registration
D.Remove personal files and apps
E.Remove the device from Microsoft Intune
AnswersC, D

Autopilot reset re-applies the existing Autopilot profile, so the device stays enrolled and registered without re-importing its hardware hash. This satisfies the scenario's requirement to keep the device deployment-ready while wiping it, avoiding manual re-registration in Microsoft Entra ID.

Why this answer

Options C and D are correct. Windows Autopilot reset retains the device's Autopilot registration (option C) and removes personal files and apps (option D). Option A is incorrect because Autopilot reset does not change the primary user; that requires a different process.

Option B is incorrect because Autopilot reset does not reinstall Windows from scratch; it refreshes the existing OS. Option E is incorrect because Autopilot reset does not remove the device from Microsoft Intune; that would require a manual action.

367
MCQmedium

Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?

A.It requires a reboot for the setting to take effect.
B.It enables real-time protection for scheduled scans.
C.It disables scheduled scans when the device is in use.
D.It reduces the CPU priority of scheduled scans to minimize performance impact.
AnswerD

The baseline setting lowers the CPU priority of scheduled scans, so antivirus scanning consumes fewer processor resources and interferes less with user workloads. This directly matches the stated effect of reducing scan priority to minimise performance impact.

Why this answer

This setting in the Microsoft Intune security baseline for Windows 10 configures the 'Low CPU priority for scheduled scans' policy for Microsoft Defender Antivirus. When enabled, it reduces the CPU priority of scheduled scans to minimize performance impact on the user's active workload, ensuring that background scanning does not interfere with foreground tasks.

Exam trap

The trap here is that candidates confuse 'reducing CPU priority' with 'disabling the scan' or 'requiring a reboot', leading them to select options that describe more drastic or unrelated behaviors rather than the subtle performance tuning this setting actually performs.

How to eliminate wrong answers

Option A is wrong because this setting does not require a reboot; Intune security baseline policies are applied via the Microsoft Defender Antivirus engine and take effect immediately or on the next scheduled scan without a system restart. Option B is wrong because real-time protection is a separate policy (e.g., 'Turn on real-time protection') and is not controlled by this CPU priority setting. Option C is wrong because this setting does not disable scheduled scans when the device is in use; it only lowers the CPU priority of the scan, allowing it to run concurrently without degrading user experience.

368
MCQeasy

A company uses Microsoft Intune to manage Android Enterprise personally owned work profile devices. Employees report that the corporate email app allows copying text into personal apps on the same device. You need to prevent copy and paste of corporate data into personal apps while leaving personal apps otherwise unaffected. What should you configure?

A.A conditional access policy requiring compliant devices for the corporate email app.
B.A device compliance policy for Android Enterprise that marks devices as noncompliant when data sharing is detected.
C.A device restrictions configuration profile that blocks the clipboard service on the Android device.
D.An app protection policy targeting the managed apps, with the 'Restrict cut, copy, and paste between other apps' setting configured for policy-managed apps.
AnswerD

App protection policies on Android Enterprise work profile devices govern data movement between managed and unmanaged apps, and the cut-copy-paste restriction blocks corporate data from leaving managed apps while leaving personal apps usable. This directly addresses the reported behavior without affecting the rest of the device.

Why this answer

App protection policies create a data boundary around managed apps, and the cut-copy-paste restriction setting specifically prevents corporate data from being pasted into unmanaged personal apps on Android Enterprise work profile devices while preserving personal app functionality.

Exam trap

The trap here is confusing device compliance or conditional access, which gate access to resources, with app protection policies that actually control data movement between apps.

369
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Entra ID with Microsoft Intune. You need to prepare infrastructure to deploy Windows 11 devices that are Microsoft Entra hybrid joined. You must ensure that devices can enroll in Intune without requiring user interaction during the out-of-box experience (OOBE). What should you configure first?

A.Create a device enrollment manager (DEM) account in Intune and assign it to the deployment team.
B.Configure automatic enrollment in Intune for Windows devices in the Microsoft Entra admin center.
C.Configure Windows Autopilot deployment profile with the 'Convert all targeted devices to Autopilot' option.
D.Deploy the Intune Company Portal app to devices via Group Policy.
AnswerB

Automatic enrollment in Microsoft Entra ID ensures that when a device joins or registers, it is automatically enrolled in Intune. For Microsoft Entra hybrid joined devices, this setting must be enabled so that the device receives Intune policies without user action. This is a prerequisite for zero-touch provisioning scenarios and aligns with the requirement to avoid manual enrollment during OOBE.

Why this answer

Automatic enrollment in Intune must be enabled in Microsoft Entra ID to allow Microsoft Entra hybrid joined devices to enroll automatically. This setting ensures that devices receive Intune policies without user interaction, which is essential for zero-touch provisioning during OOBE. Other options either require manual steps or do not directly enable automatic enrollment.

Exam trap

The trap here is assuming that Windows Autopilot alone handles Intune enrollment, when automatic enrollment must be configured separately.

370
Multi-Selectmedium

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to configure a compliance policy that enforces encryption and firewall settings. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require the device to be marked as compliant by a third-party MDM
B.Require Windows Defender Antivirus
C.Require Secure Boot to be enabled on the device
D.Require a firewall
E.Require BitLocker
AnswersD, E

Require a firewall is a compliance setting under System Security that verifies Microsoft Defender Firewall is enabled on the device. If the firewall is off, the device is marked noncompliant. This directly fulfills the requirement to enforce firewall settings in the compliance policy.

Why this answer

To enforce encryption and firewall settings in a Windows compliance policy, you configure 'Require BitLocker' under Device Health and 'Require a firewall' under System Security. These settings directly validate that encryption is active and the firewall is enabled, marking devices noncompliant if either condition fails.

Exam trap

The trap here is selecting other security-related settings like Secure Boot or antivirus, which are valuable but do not fulfill the specific encryption and firewall requirements.

371
MCQeasy

A company uses Configuration Manager to deploy Windows 11. During the deployment, the task sequence fails at the 'Apply Operating System' step. The error log shows 'Failed to find a valid operating system image package'. You verify that the operating system image package exists and is distributed to the distribution point. What is the most likely cause?

A.The client computer does not have enough disk space
B.The task sequence is not associated with the correct boot image
C.The operating system image package is not enabled for use with task sequences
D.The distribution point is not configured to support PXE boot
AnswerC

A package distributed to the distribution point still fails the Apply Operating System step if its task sequence usage flag is disabled. Enabling the package for task sequences lets Configuration Manager resolve it as a valid operating system image source.

Why this answer

When an operating system image package exists and is distributed to distribution points but the task sequence fails with 'Failed to find a valid operating system image package', the most common cause is that the image package is not enabled for use with task sequences. In Configuration Manager, each OS image package has a property 'Enable this operating system image for use in task sequences' that must be checked; if unchecked, the task sequence engine cannot reference the package during the Apply Operating System step, even though the package is present and distributed.

Exam trap

The trap here is that candidates often assume the error is due to distribution point issues (like PXE or content distribution) because the error message mentions 'failed to find', but the real cause is a simple property setting on the OS image package that is frequently overlooked during troubleshooting.

How to eliminate wrong answers

Option A is wrong because insufficient disk space would typically cause a different error, such as 'Failed to write to disk' or 'Not enough free space', not a failure to find a valid OS image package. Option B is wrong because the boot image association is critical for booting the client into WinPE, but the error occurs at the 'Apply Operating System' step, which runs after WinPE is loaded; an incorrect boot image would cause a failure earlier, during the boot process or initial task sequence start. Option D is wrong because PXE boot configuration is only relevant if the client is booting from the network; the error occurs during the task sequence execution after the client has already booted into WinPE, and the distribution point's PXE support does not affect the ability to locate an OS image package during the Apply Operating System step.

372
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that Windows 11 devices can receive configuration profiles and compliance policies. You have already assigned the necessary licenses to users. What should you do first to prepare the devices for management?

A.Enroll the devices into Microsoft Intune.
B.Create a device compliance policy.
C.Configure a conditional access policy.
D.Deploy a configuration profile.
AnswerA

Enrolling devices into Microsoft Intune is the foundational step to enable management. Without enrollment, devices cannot receive configuration profiles, compliance policies, or any other management tasks. Enrollment establishes a trust relationship between the device and Intune, allowing policies to be applied and device state to be reported.

Why this answer

Before any policies or profiles can be applied, devices must be enrolled into Microsoft Intune. Enrollment is the process that registers the device with the service, enabling management capabilities. Once enrolled, you can assign compliance policies, configuration profiles, and other management tasks.

The other actions listed are all dependent on enrollment.

Exam trap

The trap here is thinking that creating policies or profiles comes before enrollment, but enrollment is the prerequisite for any management to occur.

373
Drag & Dropmedium

Arrange the steps to deploy Windows 10 using Microsoft Deployment Toolkit (MDT) in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

MDT deployment requires importing OS and drivers first, then creating a task sequence, updating the share, booting the client, and finally running the wizard.

374
MCQeasy

You are an administrator for a Microsoft Intune environment. You need to remotely wipe a lost Windows 11 device to prevent access to corporate data. The device is enrolled in Intune and is currently online. Which action should you perform from the Intune admin center?

A.Wipe the device
B.Reset the device
C.Retire the device
D.Delete the device
AnswerA

The Wipe action performs a factory reset on the device, removing all data and settings. This is the correct action for a lost or stolen device because it ensures no corporate or personal data remains accessible. The device must be online to receive the command.

Why this answer

For a lost or stolen device, the Wipe action in Intune initiates a factory reset, erasing all data. This protects corporate information. Retire only removes corporate data, and Delete only removes the Intune record.

Reset is not a valid action. The device must be online to receive the wipe command.

Exam trap

The trap here is confusing Retire with Wipe; Retire leaves personal data intact and is not sufficient for a lost device.

375
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune to manage Windows 11 devices. You have a device compliance policy that requires BitLocker Drive Encryption to be enabled on the OS drive. A user reports that their device is marked as non-compliant, even though they have BitLocker enabled and the drive is encrypted. You check the device and see that the BitLocker protection status is 'Protection Off' in the BitLocker control panel. The user has not set up a PIN. You need to ensure the device is compliant. What should you do?

A.Instruct the user to open BitLocker Drive Encryption and click 'Resume protection'.
B.In Intune, create a new configuration profile to enforce BitLocker with a startup PIN.
C.In the compliance policy, change the BitLocker requirement to 'Not required'.
D.In the compliance policy, set the BitLocker requirement to 'Require' and enable 'Require device encryption'.
AnswerA

BitLocker protection can be suspended, which leaves the drive encrypted but not actively protected. The compliance policy checks the protection status, not just encryption. Resuming protection re-enables BitLocker and will make the device compliant. This is the correct action because it addresses the actual state of BitLocker without weakening security.

Why this answer

The device is non-compliant because BitLocker protection is suspended, even though the drive is encrypted. The compliance policy checks the protection status, so the user must resume protection to become compliant. Resuming protection re-enables BitLocker and ensures the drive is actively protected, satisfying the policy requirement without compromising security.

Exam trap

The trap here is assuming that encryption alone satisfies BitLocker compliance, when the policy actually checks the active protection status, which can be suspended independently.

Page 4

Page 5 of 8

Page 6

All pages