Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 376–450

556 questions total · 8pages · All types, answers revealed

Page 5

Page 6 of 8

Page 7
376
MCQeasy

Your organization wants to use Windows Autopilot for user-driven deployment. Users should be able to self-deploy their devices by signing in with their corporate credentials. Which Autopilot deployment mode should you use?

A.Pre-provisioned deployment
B.Hybrid Azure AD join
C.User-driven (Azure AD join)
D.Self-deploying (Azure AD join)
AnswerC

User-driven mode with Microsoft Entra join prompts users to sign in with corporate credentials during OOBE, enrolling the device automatically. This directly satisfies the requirement that users self-deploy their own devices using their organisational accounts.

Why this answer

User-driven (Azure AD join) deployment mode is correct because it allows users to self-deploy their devices by signing in with their corporate credentials during the out-of-box experience (OOBE). This mode joins the device to Azure AD and enrolls it in Microsoft Intune, enabling the user to complete the setup without IT intervention.

Exam trap

The trap here is that candidates often confuse 'self-deploying' with 'user-driven' because both involve Azure AD join, but self-deploying requires no user interaction during OOBE, making it unsuitable for scenarios where users must sign in with corporate credentials.

How to eliminate wrong answers

Option A is wrong because pre-provisioned deployment requires an IT technician to perform a pre-provisioning phase before the user receives the device, which does not align with the requirement for users to self-deploy by signing in with corporate credentials. Option B is wrong because Hybrid Azure AD join is not an Autopilot deployment mode; it is a device identity state that can be achieved through Autopilot but requires additional infrastructure like Active Directory and Azure AD Connect, and it does not describe a specific deployment mode. Option D is wrong because self-deploying (Azure AD join) mode is designed for kiosks or shared devices where no user credentials are required during OOBE; it uses a device certificate for authentication, not user sign-in.

377
MCQmedium

Your organization uses Windows Autopilot and Microsoft Intune. You need to ensure that during the Autopilot deployment, the device automatically installs a set of required applications (Microsoft 365 Apps, company portal, and a line-of-business app) before the user can access the desktop. Which configuration should you use?

A.Configure the Enrollment Status Page (ESP) to block device use until required apps are installed
B.Set a device compliance policy to require all apps to be installed
C.Use a PowerShell script that runs during Autopilot to install apps
D.Configure an Autopilot deployment profile with the 'Skip EULA' option
AnswerA

The Enrollment Status Page hooks into Autopilot's device ESP phase, tracking Win32 and Microsoft Store app installation via Intune management extension before allowing desktop access. This directly satisfies the stem's constraint that required apps — Microsoft 365 Apps, Company Portal, and the LOB app — must install before the user reaches the desktop.

Why this answer

The Enrollment Status Page (ESP) in Windows Autopilot can be configured to block device use until specified required apps are installed. This ensures that Microsoft 365 Apps, Company Portal, and line-of-business apps are fully deployed before the user reaches the desktop, meeting the requirement of a controlled, app-ready deployment.

Exam trap

The trap here is that candidates often confuse the ESP's ability to block desktop access with compliance policies or scripts, not realizing that only the ESP provides the specific 'block until installed' functionality during Autopilot.

How to eliminate wrong answers

Option B is wrong because a device compliance policy checks the state of devices after enrollment (e.g., requiring apps to be installed for compliance), but it does not block the user from accessing the desktop during Autopilot deployment; it only flags non-compliance later. Option C is wrong because a PowerShell script running during Autopilot can install apps, but it cannot reliably block the user from accessing the desktop until all apps are installed; the ESP provides that blocking mechanism. Option D is wrong because the 'Skip EULA' option in an Autopilot deployment profile only skips the End-User License Agreement pages during OOBE, which has no effect on app installation or blocking desktop access.

378
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that requires devices to run Windows version 22H2 or later. When you create the policy, which option must you select for the OS version requirement?

A.Require OS version
B.Maximum OS version
C.Minimum OS version
D.Exact OS version
AnswerC

Minimum OS version sets a floor that devices must meet or exceed, so specifying Windows 11 22H2 enforces that devices run 22H2 or later. This directly satisfies the stem's requirement for a compliance policy mandating version 22H2 or above.

Why this answer

The requirement for devices to run Windows version 22H2 or later is a minimum version constraint. In Microsoft Intune compliance policies, the 'Minimum OS version' setting enforces that the device's OS version must be equal to or greater than the specified version, which directly matches the '22H2 or later' condition.

Exam trap

The trap here is that candidates confuse 'Minimum OS version' with 'Exact OS version' or 'Require OS version', mistakenly thinking Intune can enforce a single specific build rather than a minimum threshold.

How to eliminate wrong answers

Option A is wrong because 'Require OS version' is not a valid setting in Intune compliance policies; the actual settings are 'Minimum OS version' and 'Maximum OS version'. Option B is wrong because 'Maximum OS version' would restrict devices to a version no higher than the specified one, which is the opposite of the 'or later' requirement. Option D is wrong because 'Exact OS version' is not a supported option in Intune; compliance policies do not allow pinning to a single specific build, only range-based constraints.

379
MCQmedium

Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?

A.Create a new custom detection rule based on an Advanced hunting query.
B.Configure a Device control policy to block PowerShell.
C.Add an Indicator of compromise for the script hash.
D.Create a new attack simulation training campaign.
AnswerA

Custom detection rules run Advanced hunting KQL queries on a schedule and raise alerts when results match, so a query targeting PowerShell script execution events detects the script across all onboarded devices. This is the only mechanism in the Defender portal for query-based custom detections.

Why this answer

A is correct because custom detection rules in Microsoft 365 Defender are built from Advanced hunting queries (Kusto Query Language) that can detect specific script execution patterns, such as a PowerShell script with a known command line or hash. This allows you to trigger an alert when the exact script runs, meeting the requirement for a custom detection rule.

Exam trap

The trap here is that candidates often confuse Indicators of compromise (IoC) with custom detection rules, thinking a hash-based IoC can create a detection rule, but IoCs are for blocking or alerting on known files, not for writing custom KQL-based detection logic.

How to eliminate wrong answers

Option B is wrong because configuring a Device control policy to block PowerShell would prevent all PowerShell execution, not create a detection rule for a specific script; it is a restrictive control, not a detection mechanism. Option C is wrong because adding an Indicator of compromise (IoC) for the script hash would block or alert on the file based on its hash, but it does not create a custom detection rule with an Advanced hunting query; IoCs are for known threats, not custom detection logic. Option D is wrong because creating an attack simulation training campaign is for phishing simulations and user awareness, not for detecting PowerShell script execution on devices.

380
MCQeasy

Refer to the exhibit. You manage a Windows 11 device that is marked as compliant and has OS version 10.0.22621.0. You need to upgrade the device to Windows 11 version 23H2. Which Intune feature should you use?

A.Windows quality update profile
B.Windows feature update profile
C.Driver update policy
D.Compliance policy
AnswerB

Windows feature update profiles deploy a specified Windows 11 version, such as 23H2, to targeted devices. This satisfies the requirement to upgrade the compliant Windows 11 device to a newer feature version rather than applying quality updates or driver updates.

Why this answer

A Windows feature update profile is the correct Intune feature to upgrade a Windows 11 device from one version to another (e.g., from 10.0.22621.0 to 23H2). Feature update profiles deploy new OS builds that enable feature-level changes, whereas quality updates deliver only security and cumulative fixes. This profile targets the specific version upgrade required for the device.

Exam trap

The trap here is confusing 'quality updates' (which are cumulative security fixes) with 'feature updates' (which are full OS version upgrades), leading candidates to incorrectly select the quality update profile for a version upgrade.

How to eliminate wrong answers

Option A is wrong because a Windows quality update profile delivers only monthly security and cumulative updates, not full OS version upgrades like 23H2. Option C is wrong because a driver update policy manages only device driver updates, not Windows OS version changes. Option D is wrong because a compliance policy evaluates device settings against rules but does not deploy OS upgrades; it can mark a device non-compliant but cannot perform the upgrade itself.

381
MCQhard

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?

A.Create a device compliance policy that uses Defender for Endpoint risk level, then use Conditional Access.
B.Configure a device compliance policy with 'Require Defender for Endpoint' setting.
C.Configure a device configuration policy to block access based on risk.
D.Configure an app protection policy to block access based on device risk.
AnswerA

Defender for Endpoint risk level feeds into Intune compliance policy, which marks the device non-compliant at high risk. Conditional Access then evaluates that compliance state and blocks access to corporate resources, satisfying the requirement for automatic blocking based on Defender's risk determination.

Why this answer

It combines a device compliance policy that evaluates the Defender for Endpoint risk level with a Conditional Access policy that blocks access when the device is noncompliant. This is the only supported method to automatically block corporate resource access based on real-time risk assessment from Defender for Endpoint.

Exam trap

The trap here is that candidates often think a device configuration policy or app protection policy can enforce risk-based blocking, but only the combination of a compliance policy with Defender risk evaluation and Conditional Access achieves this in Intune.

How to eliminate wrong answers

Option B is wrong because 'Require Defender for Endpoint' is a compliance setting that only checks if Defender is enabled and active, not the actual risk level. Option C is wrong because device configuration policies manage settings and features, not access control based on risk. Option D is wrong because app protection policies apply to apps on unmanaged devices and do not evaluate device-level risk from Defender for Endpoint.

382
MCQeasy

A company uses Microsoft Intune to manage its Windows devices. The IT team wants to ensure that new Windows devices can enroll without requiring users to manually enter the enrollment server address. The devices are already joined to Microsoft Entra ID. Which infrastructure component enables this automatic discovery?

A.A DNS SRV record for _enterpriseregistration in the on-premises DNS zone.
B.The MDM discovery endpoint published in Microsoft Entra ID through the mobility settings.
C.The Company Portal app installed on the device before enrollment.
D.The Intune enrollment policy in the Microsoft Intune admin center.
AnswerB

When automatic MDM enrollment is configured in Microsoft Entra ID, the service publishes the MDM discovery endpoint to enrolled clients. A Microsoft Entra joined device queries this endpoint during the join process and learns the Intune enrollment URL, enabling enrollment without the user typing a server address. This is the mechanism that enables automatic discovery.

Why this answer

Microsoft Entra ID publishes the MDM discovery endpoint when automatic enrollment is configured. A Microsoft Entra joined Windows device queries that endpoint during the join process and receives the Intune enrollment URL, so users do not need to enter a server address manually. This is the standard cloud-based discovery path.

Exam trap

The trap here is attributing automatic discovery to a DNS SRV record or the Company Portal, when the cloud discovery endpoint in Microsoft Entra ID is what cloud-joined devices actually use.

383
Multi-Selecteasy

Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)

Select 2 answers
A.Use the iOS Microsoft 365 Apps deployment method.
B.Package the Office Deployment Tool as a Win32 app.
C.Upload an MSI file for Microsoft 365 Apps.
D.Use the built-in Microsoft 365 Apps deployment for Windows 10 and later.
E.Add a web link to the Office 365 portal.
AnswersB, D

Wrapping the Office Deployment Tool inside a Win32 app package lets Intune deliver the setup executable and configuration XML, satisfying the requirement to deploy Microsoft 365 Apps through the Win32 app channel with full control over installation arguments.

Why this answer

Option B is correct because packaging the Office Deployment Tool (ODT) as a Win32 app in Intune lets you supply a custom configuration.xml, so setup.exe can download and install Microsoft 365 Apps with your chosen channel, architecture, and apps. Option D is correct because Intune provides a built-in Microsoft 365 Apps (Office) app type for Windows 10 and later, where you select the update channel, version, architecture, and which Office apps to install directly from the console. Option A is wrong because the iOS Microsoft 365 Apps deployment method targets mobile devices, not Windows devices.

Option C is wrong because Microsoft 365 Apps is not distributed as a single MSI for Intune deployment; it uses Click-to-Run via the ODT or the built-in app type. Option E is wrong because a web link to the Office 365 portal only opens a webpage and does not install the apps on the device.

Exam trap

The trap here is that candidates often confuse the built-in Microsoft 365 Apps deployment profile with a simple 'add an app' wizard, leading them to mistakenly think an MSI upload (Option C) is valid for Office, when in fact Intune only supports Click-to-Run installations for Microsoft 365 Apps via ODT-based methods.

384
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft 365 Apps for enterprise suite to all devices. Which app type should you use in Intune?

A.Web link
B.Windows app (Win32)
C.Microsoft 365 Apps for Windows 10 and later
D.Line-of-business app
AnswerC

The Microsoft 365 Apps for Windows 10 and later app type is purpose-built for deploying the suite through Intune, handling installation and update channels natively. It satisfies the requirement to roll out Microsoft 365 Apps for enterprise to all managed Windows 10 devices without packaging.

Why this answer

The 'Microsoft 365 Apps for Windows 10 and later' app type in Intune is specifically designed to deploy and manage Microsoft 365 Apps for enterprise (formerly Office 365 ProPlus) on Windows devices. It provides a streamlined, built-in experience with automatic updates and configuration options tailored for Microsoft 365 Apps, such as selecting update channels and removing previous installations. This is the recommended method for deploying the suite to Intune-managed Windows 10 devices.

Exam trap

MD-102 often tests the distinction between different Intune app types, and candidates may confuse the Microsoft 365 Apps app type with Windows app (Win32) because both can deploy desktop applications. The trap is that Win32 apps require manual packaging and do not offer the same integrated management for Microsoft 365 Apps.

How to eliminate wrong answers

Option A is wrong because a web link simply creates a shortcut to a web page and cannot install or manage a full desktop application suite. Option B is wrong because Windows app (Win32) is used for custom or third-party Win32 applications that require packaging with the IntuneWinAppUtil tool; while it could technically deploy Microsoft 365 Apps, it is not the purpose-built, supported method and lacks the integrated management features. Option D is wrong because line-of-business apps are for custom or purchased apps that are not available in the Microsoft Store, and they do not provide the specific deployment and update capabilities for Microsoft 365 Apps.

385
Multi-Selecthard

Which THREE components are required to deploy a Win32 app via Microsoft Intune?

Select 3 answers
A.Detection rule
B.A .intunewin file
C.PowerShell script for post-installation
D.Dependency on another app
E.Install command
AnswersA, B, E

Detection rules determine whether the app is already installed.

Why this answer

A detection rule is required because Intune needs a method to verify whether the Win32 app is already installed on the device. Without a detection rule, Intune cannot determine if the installation succeeded or if the app needs to be reinstalled. The detection rule can be based on a file, registry key, or custom script, and it is mandatory for any Win32 app deployment.

Exam trap

The trap here is that candidates often confuse optional features like dependencies or post-installation scripts with required components, leading them to select those options instead of the three mandatory ones: detection rule, .intunewin file, and install command.

386
MCQhard

You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?

A.Device configuration profile with user scope.
B.Device configuration profile with device scope.
C.Compliance policy.
D.Group Policy Object (GPO) via Intune.
AnswerB

A device configuration profile with device scope applies settings directly to the device, independent of user sign-in. These settings are enforced by the device and cannot be overridden by users. This meets the requirement of applying settings even when no user is signed in and preventing user override. Device-scoped profiles are ideal for security settings that must apply globally, such as BitLocker, firewall, or Defender settings. They are assigned to device groups in Intune.

Why this answer

Device configuration profiles with device scope apply settings directly to the device, independent of user sign-in, and enforce them so users cannot override. This meets the requirement of applying security settings even when no user is signed in. User-scoped profiles require sign-in, compliance policies only assess, and GPOs are not natively applied via Intune.

Device-scoped profiles are the correct choice for device-wide security configurations.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance policies only evaluate, they do not apply settings.

387
MCQmedium

You manage Windows 10 devices with Intune. You need to ensure that only approved apps can run on corporate devices. You configure AppLocker via a custom OMA-URI. However, users can still run unapproved apps. What is the most likely reason?

A.The device must be running Windows 10 Pro edition.
B.AppLocker rules can only be configured via Group Policy, not OMA-URI.
C.The AppLocker policy is set to 'Audit only' mode.
D.The policy is assigned to a device group instead of a user group.
AnswerC

Audit-only mode logs AppLocker events without blocking execution, so unapproved apps still launch despite the deployed policy. Switching the enforcement setting to Enforce makes the rules actively prevent unapproved applications from running on the managed devices.

Why this answer

When AppLocker is configured via custom OMA-URI in Intune, the policy is device-based and can be assigned to device groups. However, if the policy is set to 'Audit only' mode, it only logs events without actually blocking applications. This allows users to still run unapproved apps.

Option D is incorrect because assigning the policy to a device group does enforce AppLocker rules; the issue here is mode enforcement, not assignment type.

Exam trap

The trap is that candidates may overlook the enforcement mode of AppLocker policies, assuming they block by default, when 'Audit only' mode is a common configuration that logs but does not prevent execution.

How to eliminate wrong answers

Option A is wrong because AppLocker is supported on Windows 10 Enterprise and Education editions, not Pro; Pro edition lacks the AppLocker service and rule enforcement. Option B is wrong because AppLocker rules can be configured via OMA-URI using the ./Vendor/MSFT/AppLocker CSP, which is a supported method in Intune for Windows 10/11 devices. Option C is wrong because if the policy were in 'Audit only' mode, unapproved apps would still be allowed to run but events would be logged; the question states users can run unapproved apps, which could also happen in audit mode, but the most likely reason given the scenario is the assignment target mismatch.

388
MCQmedium

Refer to the exhibit. You configure this Enrollment Status Page (ESP) policy for Windows Autopilot deployments. During a deployment, a device fails to install a required app. What happens?

A.The device will be blocked from use until the app is installed or the device is reset.
B.The user can retry the installation manually.
C.The timeout will extend by 60 minutes.
D.The device will automatically retry the installation.
AnswerA

With the Enrollment Status Page blocking device use until all targeted apps install, a failed required app leaves the device locked on the ESP. The user cannot reach the desktop; only successful installation or a device reset clears the block.

Why this answer

The Enrollment Status Page (ESP) policy in Windows Autopilot can be configured to block device use until all required apps are installed. When a required app fails to install, the ESP enters a blocking state, preventing the user from accessing the desktop until the installation succeeds or the device is reset. This behavior is controlled by the 'Block device use until required apps are installed' setting in the ESP profile.

Exam trap

The trap here is that candidates often assume the ESP will automatically retry or extend the timeout, but the correct behavior is that the device is blocked indefinitely until the required app installs or the device is reset.

How to eliminate wrong answers

Option B is wrong because the ESP blocking state does not allow the user to manually retry the installation; the device remains blocked until the app installs or is reset. Option C is wrong because the ESP timeout extension (e.g., 60 minutes) applies only to the overall ESP timeout, not to a failed app installation; the blocking state persists indefinitely until resolved. Option D is wrong because the device does not automatically retry the installation; the ESP waits for the app to be installed via Intune management, but no automatic retry mechanism is triggered by the ESP itself.

389
MCQhard

A company uses Microsoft Intune to manage iOS/iPadOS devices enrolled through Apple Business Manager. They must distribute a proprietary in-house app that is not in the App Store to 500 supervised devices, and the app must be silently installed without user prompts. Which deployment method should they use?

A.Deploy the app as a Microsoft Store app for iOS and assign it as available.
B.Deploy the app as a line-of-business app using the iOS store app type and require installation.
C.Deploy the app as an iOS line-of-business app and assign it as required to the device group.
D.Deploy the app as a web link (web clip) and assign it as required.
AnswerC

The iOS line-of-business app type accepts an internal IPA uploaded directly to Intune. When assigned as required to supervised devices, Intune pushes a silent install through the MDM channel without user interaction. This matches the need to distribute a proprietary app to many supervised devices with no prompts, which store app types or user-driven installs cannot guarantee.

Why this answer

iOS line-of-business apps are internal IPA packages uploaded to Intune and delivered via MDM. For supervised devices with a required assignment, installation is silent and automatic, which is essential when distributing proprietary software to many devices without user involvement. Store app types and web clips either target public apps or create shortcuts, so they cannot fulfill this requirement.

Exam trap

The trap here is assuming any iOS app type supports silent install, or that 'available' assignment can install without user action.

390
MCQmedium

Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?

A.Create a feature update policy for Windows 10
B.Configure a deferral period of 7 days for quality updates
C.Set a deadline for quality updates to 7 days
D.Pause quality updates for 7 days
AnswerC

Deadlines in Windows Update for Business force installation of quality updates after a set number of days, automatically restarting to complete them. Setting seven days guarantees critical security updates install within the required window rather than relying on user-initiated installation.

Why this answer

To ensure critical security updates are installed within 7 days of release, set a deadline for quality updates to 7 days. A deadline specifies the maximum number of days after the update is offered that the device has to install it. This enforces installation within the desired timeframe.

A deferral period delays when the update is offered, which would not guarantee installation within 7 days.

Exam trap

The trap is confusing a deferral period with a deadline. Deferral delays when an update is offered, while a deadline enforces installation by a certain date. Setting a deferral of 7 days actually means updates are not offered until 7 days after release, making it impossible to install them within that window.

How to eliminate wrong answers

Option A is wrong because feature update policies are used to manage major version upgrades (e.g., Windows 10 22H2), not quality or security updates. Option B is wrong because a deferral period delays the installation of updates; setting a 7-day deferral would postpone the update by 7 days, not ensure it is installed within 7 days of release. Option D is wrong because pausing quality updates stops them from being installed entirely for a specified period, which is the opposite of ensuring timely installation.

391
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that devices receive a specific Windows quality update as soon as possible, bypassing any deferral settings. What should you configure?

A.Modify the update ring to set quality update deferral to 0 days.
B.Expedite the update using the Expedite update feature in Intune.
C.Use a PowerShell script to manually install the update on each device.
D.Create a new update ring with no deferrals and assign it to the devices.
AnswerB

The Expedite update feature in Intune allows you to deploy a specific quality update to devices immediately, bypassing deferral settings and deadlines. This ensures the update is installed as soon as possible. It is designed for urgent updates, such as security patches. You select the update and target devices, and Intune pushes it without waiting for the normal update cycle.

Why this answer

The Expedite update feature in Intune is specifically designed to deploy a specific quality update to devices immediately, bypassing deferrals and deadlines. It ensures the update is installed as soon as possible. Other options either do not target a specific update or do not guarantee immediate installation.

Therefore, expediting the update is the correct action.

Exam trap

The trap here is thinking that setting deferrals to zero will force a specific update immediately; deferrals only control timing relative to release, not immediate installation of a chosen update.

392
Multi-Selectmedium

Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)

Select 2 answers
A.Send a sync command to the device to re-evaluate compliance.
B.Deploy a proactive remediation script to detect and install antivirus.
C.Send a notification to the user to install antivirus via Windows Security.
D.Run a PowerShell script from Intune to install the missing antivirus.
E.Create a Conditional Access policy to block the device until fixed.
AnswersB, D

Proactive remediation scripts run detection and remediation logic directly on the device, satisfying the missing-antivirus compliance state without user interaction. Unlike configuration profiles, which enforce settings, this mechanism actively detects the absent antivirus and installs it, restoring compliance as reported to Microsoft Entra ID.

Why this answer

Option B is correct because proactive remediations in Intune pair a detection script with a remediation script that runs on the device, so you can detect missing antivirus and automatically install it to bring the device back into compliance. Option D is correct because running a PowerShell script from Intune (via a platform script or device script) lets you execute installation commands for the missing antivirus directly on the Windows device. Option A is not a remediation action; a sync only forces the device to check in and re-evaluate policy/compliance, which does not install antivirus.

Option C merely notifies the user and relies on manual action, so it does not remediate the device automatically. Option E is a Conditional Access policy that blocks access rather than fixing the noncompliance, so it is not a remediation action.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which block access but do not fix the issue) with actual remediation actions, or they assume a sync command will resolve noncompliance when it only re-evaluates the existing state.

393
MCQmedium

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

A.Manually tag each device in the Microsoft 365 Defender portal.
B.Configure device group rules in Microsoft Defender for Endpoint using OS version condition.
C.Use Microsoft Entra ID dynamic groups based on device OS.
D.Create a Microsoft Intune compliance policy that tags devices by OS version.
AnswerB

Device group rules in Microsoft Defender for Endpoint evaluate onboarding devices against conditions such as OS version, automatically placing them into the target group. This satisfies the requirement for automatic assignment based on operating system version, avoiding manual tagging or dynamic group queries in Microsoft Entra ID, which cannot drive Defender device group membership.

Why this answer

Device group rules in Microsoft Defender for Endpoint allow you to automatically assign devices to groups based on conditions such as operating system version. This is the correct approach because it uses the built-in grouping engine that evaluates device attributes during onboarding, ensuring consistent and automated assignment without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID dynamic groups (which are for identity and access management) with Defender for Endpoint device group rules (which are for security operations and automation), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because manually tagging each device in the Microsoft 365 Defender portal is not automated and does not scale for large environments; it also does not use OS version as a condition. Option C is wrong because Microsoft Entra ID dynamic groups are based on Azure AD device attributes and are used for identity-based access control, not for Defender for Endpoint device group assignment, which requires Defender-specific grouping rules. Option D is wrong because Microsoft Intune compliance policies are used to enforce device health and compliance settings, not to tag devices for Defender for Endpoint grouping; they do not create device groups in Defender.

394
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?

A.Create a device compliance policy and assign it to users.
B.Create a device configuration profile that restricts access.
C.Create a Conditional Access policy that requires compliant devices.
D.Configure enrollment restrictions to block non-compliant devices.
AnswerC

Conditional Access evaluates sign-in signals at authentication time, so a policy granting access only when the device is marked compliant in Intune blocks non-compliant devices from corporate resources. Compliance policies alone only report state; the Conditional Access policy enforces the block.

Why this answer

Conditional Access policies in Azure AD are the correct mechanism to enforce access controls based on device compliance status. By creating a policy that requires devices to be marked as compliant, you ensure that only compliant devices can access corporate resources, while non-compliant devices are blocked at the authentication level. This integrates with Intune compliance policies to evaluate device health before granting access.

Exam trap

The trap here is that candidates often confuse the role of a compliance policy (which only evaluates and reports) with the enforcement mechanism (Conditional Access), leading them to select Option A as the answer.

How to eliminate wrong answers

Option A is wrong because a device compliance policy alone only reports compliance status and can trigger actions like sending notifications or marking devices as non-compliant, but it does not block access to corporate resources; it requires a Conditional Access policy to enforce the block. Option B is wrong because a device configuration profile is used to configure device settings (e.g., password policies, restrictions) and does not enforce access control or block non-compliant devices from resources. Option D is wrong because enrollment restrictions control which devices can enroll in Intune, not whether already enrolled devices that become non-compliant are blocked from accessing corporate resources.

395
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?

A.Wipe
B.Reset
C.Delete
D.Retire
AnswerA

Wipe performs a full factory reset, removing all data, settings and the enrolment, which is required for a lost corporate-owned device. It satisfies the stem's constraint of remotely erasing the iOS device completely rather than only removing corporate data.

Why this answer

The 'Wipe' action in Microsoft Intune performs a factory reset on a corporate-owned iOS device, removing all data and settings to protect sensitive information. This is the appropriate action for a lost device because it restores the device to its out-of-box state, ensuring no corporate data remains accessible.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', mistakenly thinking Retire is sufficient for lost devices, but Retire only removes corporate data and leaves personal data intact, which is a critical distinction for corporate-owned devices.

How to eliminate wrong answers

Option B (Reset) is wrong because 'Reset' is not a specific Intune action for iOS devices; the correct term is 'Wipe', which performs a full factory reset. Option C (Delete) is wrong because 'Delete' removes the device from Intune management without wiping data, leaving the device and its contents intact. Option D (Retire) is wrong because 'Retire' removes only corporate data and management profiles, but leaves personal data on the device, which is insufficient for a lost corporate-owned device where all data must be erased.

396
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?

A.Recreate the Wi-Fi profile in Intune with new settings
B.Run the 'netsh wlan show profiles' command on affected devices
C.Check the Intune console for Wi-Fi profile assignment and conflict status
D.Review Microsoft Entra ID sign-in logs for authentication failures
AnswerC

Verifying profile assignment and conflict status in the Intune console first confirms whether the Wi-Fi profile actually reached affected devices, since a misassigned or conflicting profile would prevent the network settings from applying. This isolates configuration causes before investigating device-side or network-side faults.

Why this answer

Checking the Intune console for Wi-Fi profile assignment and conflict status is the fastest way to identify deployment issues, such as the profile not being assigned to the affected devices or conflicts with other profiles. Option A is wrong because recreating the profile may not address the root cause and could be time-consuming without first verifying the current assignment. Option B is wrong because running 'netsh wlan show profiles' only lists profiles stored locally and does not show Intune deployment status.

Option D is wrong because reviewing Microsoft Entra ID sign-in logs does not show Wi-Fi profile status or assignment conflicts.

397
Multi-Selectmedium

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a compliance policy that marks devices as noncompliant if they do not have a specific minimum OS version and if they have not checked in with Intune within the last 7 days. Which TWO settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Last check-in time
B.Encryption of data storage on device
C.Device health attestation
D.Minimum OS version
E.Antivirus and antispyware status
AnswersA, D

The Last check-in time setting marks devices as noncompliant if they have not communicated with Intune within a specified number of days. Configuring this to 7 days ensures devices that have not checked in recently are flagged. This directly meets the requirement for check-in recency.

Why this answer

The compliance policy settings for Minimum OS version and Last check-in time directly enforce the two requirements. Minimum OS version ensures devices meet the specified build, while Last check-in time flags devices that have not communicated with Intune within 7 days. Together, they define the compliance state as required.

Exam trap

The trap here is selecting security-related settings like encryption or antivirus, which are important but not the ones needed for OS version and check-in recency.

398
MCQhard

An organization is deploying Windows 10 using Configuration Manager task sequences. During a pilot deployment, the task sequence fails with error code 0x80070002. What is the most likely cause?

A.The device does not meet minimum hardware requirements
B.The task sequence includes a duplicate step
C.The boot image is missing or corrupted
D.The distribution point is unreachable
AnswerC

Error 0x80070002 is 'file not found', which during a task sequence typically indicates the referenced boot image cannot be located or is corrupted in the distribution point. Recreating or redistributing the boot image restores the missing content.

Why this answer

Error code 0x80070002 translates to 'The system cannot find the file specified.' In the context of a Configuration Manager task sequence, this typically indicates that the boot image (WIM file) referenced by the task sequence is missing from the distribution point or is corrupted. The boot image is required to start Windows PE and initiate the OS deployment; if it cannot be located or loaded, the task sequence fails immediately.

Exam trap

The trap here is that candidates often associate error 0x80070002 with a network connectivity issue (Option D) or a hardware problem (Option A), but the error code specifically indicates a missing file, not a network or hardware failure.

How to eliminate wrong answers

Option A is wrong because minimum hardware requirements would produce a different error (e.g., 0x80070570 or a pre-flight check failure), not a file-not-found error. Option B is wrong because a duplicate step in the task sequence would cause a validation error during editing or a runtime conflict, but not a 0x80070002 error, which is specifically a file access issue. Option D is wrong because an unreachable distribution point would result in a network-related error (e.g., 0x80072EFE or 0x80004005), not a file-not-found error; the boot image must be present on the distribution point for the task sequence to even begin.

399
Multi-Selectmedium

Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?

Select 3 answers
A.Check that Secure Boot is enabled.
B.Check that the processor is at least 1GHz with 1 core.
C.Check that the device has TPM 2.0 enabled.
D.Check that the device has at least 4GB of RAM.
E.Check that the device has at least 32GB of storage.
AnswersA, C, D

Secure Boot is a mandatory Windows 11 hardware requirement, so verifying it is enabled confirms the device satisfies that constraint before upgrade. Intune compliance policies can report this state, letting you gate the deployment on firmware configuration rather than discovering failures mid-upgrade.

Why this answer

Option A is correct because Windows 11 requires UEFI Secure Boot capability and the feature must be enabled on the device. Option C is correct because Windows 11 mandates TPM version 2.0, and it must be enabled and functioning in the firmware. Option D is correct because the minimum RAM requirement for Windows 11 is 4 GB.

Option B is incorrect because while the processor must be 1 GHz or faster with 2 or more cores on a compatible 64-bit processor, the stated 1 core is insufficient. Option E is incorrect because the minimum storage requirement for Windows 11 is 64 GB, not 32 GB.

Exam trap

MD-102 often tests the exact minimum hardware requirements for Windows 11, and candidates frequently confuse the core count (2 vs 1) or storage (64GB vs 32GB) because they remember Windows 10 requirements or general minimums.

400
MCQmedium

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

A.The policy has not been assigned to the device or its user group.
B.The BitLocker setting is not supported on Windows 11.
C.The policy was not saved correctly due to a syntax error.
D.The device does not have a TPM chip, which is required for BitLocker, but the compliance policy does not check TPM.
AnswerA

An unassigned compliance policy applies to no one, so Microsoft Intune never evaluates the device against its BitLocker requirement. The device therefore reports compliant by default, since no policy targets it — matching the stem's symptom of a non-encrypted device showing compliant.

Why this answer

The most likely reason is that the compliance policy was created but never assigned to the device or its user group. In Microsoft Intune, a compliance policy must be assigned to a security group that contains the device or its user; otherwise, the policy is not evaluated against the device, and the device will default to a compliant status. The PowerShell cmdlet shown only creates the policy object; it does not assign it.

Exam trap

The trap here is that candidates assume creating a policy with PowerShell automatically applies it to all devices, but Intune requires explicit assignment to a group before the policy is evaluated.

How to eliminate wrong answers

Option B is wrong because BitLocker is fully supported on Windows 11 Pro, Enterprise, and Education editions; the compliance policy setting for BitLocker is valid on these editions. Option C is wrong because if there were a syntax error, the New-IntuneCompliancePolicy cmdlet would have returned an error and the policy would not have been created; the fact that the policy exists indicates it was saved correctly. Option D is wrong because while a TPM chip is required for BitLocker to function, the compliance policy setting 'Require BitLocker' checks whether BitLocker is enabled on the device, not whether a TPM is present; if BitLocker is not enabled, the device should be marked noncompliant regardless of TPM status.

401
MCQhard

Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?

A.An Intune role-based access control (RBAC) role for Sales users.
B.A device configuration profile assigned to Sales users.
C.A Conditional Access policy that requires device compliance.
D.Enrollment restrictions that allow only users in the Sales group.
AnswerD

Enrollment restrictions in Intune can target specific Microsoft Entra ID groups, so scoping the restriction to the Sales group blocks all other users from enrolling. This directly satisfies the constraint that only Sales department users may enrol devices, without affecting existing enrolled devices.

Why this answer

Enrollment restrictions in Intune let you control which users or groups are allowed to enroll devices, so restricting enrollment to the Sales group directly satisfies the requirement. This is the purpose-built control for limiting enrollment by user or group, platform, or device type.

Exam trap

MD-102 often tests the distinction between enrollment restrictions (who/what can enroll) and Conditional Access or compliance policies (what enrolled devices can access), so candidates mistakenly pick a CA policy for an enrollment-scoping requirement.

How to eliminate wrong answers

Option A is wrong because Intune RBAC roles control what administrators can do in the console, not which end users can enroll devices. Option B is wrong because a device configuration profile applies settings to already-enrolled devices and does not gate enrollment. Option C is wrong because a Conditional Access policy requiring compliance controls access to resources after enrollment, not who is permitted to enroll in the first place.

402
MCQmedium

You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices are Microsoft Entra joined. You need to ensure that during OOBE, devices are automatically assigned to the correct group for policy targeting. What should you configure?

A.Use a Group Policy object to add devices to an on-premises security group that is synced to Microsoft Entra ID.
B.Assign the Autopilot deployment profile to a static group that contains all users.
C.Create a dynamic device group in Microsoft Entra ID with a rule based on the device's enrollment profile name.
D.Configure a device category in Intune and assign it during OOBE.
AnswerC

Dynamic device groups in Microsoft Entra ID can use the device's enrollment profile name (or other attributes like device model, manufacturer) to automatically include devices. This ensures that Autopilot devices are grouped correctly for policy assignment without manual intervention. The enrollment profile name is set during Autopilot and can be used as a rule criterion.

Why this answer

Dynamic device groups in Microsoft Entra ID allow automatic membership based on device attributes such as enrollment profile name. This is ideal for Autopilot deployments because devices are automatically added to the correct group, enabling targeted policy and app assignments without manual effort.

Exam trap

The trap here is assuming that static groups or device categories can automate group membership, when dynamic groups based on device attributes are required.

403
MCQhard

You administer Microsoft Intune for a company with Windows 11 devices joined to Microsoft Entra ID. A security requirement states that if a device is found noncompliant, it must lose access to Microsoft 365 services within 15 minutes, and the device must be marked noncompliant automatically when a required antivirus signature is out of date. You need to implement this with the least administrative effort. What should you do?

A.Create a device configuration profile that disables access to Microsoft 365 when antivirus signatures are stale, and assign it to all users.
B.Create a compliance policy with an antivirus requirement and a device health attestation setting, then assign it to all users without a Conditional Access policy.
C.Create a compliance policy with an antivirus requirement, set the compliance status validity period to 15 minutes, and create a Conditional Access policy that requires compliant devices for Microsoft 365.
D.Create a Conditional Access policy that requires multifactor authentication for all users and set a sign-in frequency of 15 minutes.
AnswerC

A compliance policy enforces the antivirus signature requirement and marks devices noncompliant when it fails. Setting the compliance status validity period to 15 minutes ensures Microsoft Entra ID reevaluates compliance quickly, and a Conditional Access policy requiring compliant devices blocks access to Microsoft 365 when the device is noncompliant. This combination meets the timing and automatic marking requirements with minimal overhead.

Why this answer

Compliance policies in Intune define the conditions a device must meet, and Conditional Access policies enforce those conditions for access to cloud apps. Setting the compliance status validity period to 15 minutes ensures Microsoft Entra ID quickly reflects a noncompliant state after antivirus signatures become stale. Together, these configurations automatically mark the device noncompliant and block Microsoft 365 access within the required time frame.

Exam trap

The trap here is treating a device configuration profile or a compliance policy alone as sufficient to revoke access, when Conditional Access is required to enforce compliance for cloud services.

404
Multi-Selecteasy

Which TWO are valid methods to enroll Windows devices in Microsoft Intune?

Select 2 answers
A.Apple Business Manager
B.Manual enrollment using work or school account
C.Windows Autopilot
D.Android Enterprise
E.Azure AD Join
AnswersB, C

Manual work-or-school-account enrolment joins the device to Microsoft Entra ID and registers it with Intune in one user-driven step, satisfying the stem's requirement for a valid Windows enrolment method without requiring Autopilot or bulk provisioning infrastructure.

Why this answer

Option B (Manual enrollment using work or school account) is correct because on a Windows 10/11 device a user can go to Settings > Accounts > Access work or school > Connect and sign in with their Azure AD work or school account, which triggers automatic MDM enrollment into Intune via the built-in Windows MDM client. Option C (Windows Autopilot) is correct because Autopilot uses a device hash registered in Intune so that during OOBE the device is automatically Azure AD joined (or Hybrid Azure AD joined) and enrolled in Intune without manual user configuration. Option A (Apple Business Manager) is wrong for this scenario because ABM is Apple's automated device enrollment service for iOS/iPadOS and macOS devices, not Windows.

Option D (Android Enterprise) is wrong because it is Google's management framework for Android devices and has no role in enrolling Windows. Option E (Azure AD Join) is not a standalone enrollment method; Azure AD Join is the identity state that must be combined with an MDM enrollment mechanism (such as manual work/school account connection or Autopilot) to actually register the device in Intune.

Exam trap

The trap here is that candidates confuse Azure AD Join (an identity state) with an enrollment method, but Azure AD Join alone does not enroll the device into Intune unless MDM auto-enrollment is configured via GPO or the user explicitly signs in with a work or school account.

405
MCQeasy

You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?

A.Deploy a line-of-business app from the installation file.
B.Deploy a Win32 app with the Office Deployment Tool.
C.Deploy Microsoft 365 Apps for enterprise as a built-in app type in Intune.
D.Deploy a custom script that installs Office from a network share.
AnswerC

The built-in Microsoft 365 Apps app type in Intune uses the Office Deployment Tool and updates automatically from the Microsoft 365 Apps update channel, keeping the latest version installed across both Windows 10 and Windows 11 devices.

Why this answer

The Microsoft 365 Apps for enterprise built-in app type in Intune is specifically designed to deploy and manage Office with automatic updates from the Office Content Delivery Network (CDN). This method ensures that devices always receive the latest version of Microsoft 365 Apps without requiring manual intervention or custom configuration, as Intune handles the deployment policy and update channel settings natively.

Exam trap

The trap here is that candidates often choose Option B (Win32 app with ODT) because they know ODT is the standard tool for Office deployment, but they overlook that the built-in app type in Intune provides a simpler, more reliable method that automatically handles update channel configuration and ensures the latest version is always installed without custom scripting.

How to eliminate wrong answers

Option A is wrong because deploying a line-of-business (LOB) app from an installation file requires manual packaging and does not support automatic updates to the latest version; it also lacks the built-in update channel management that Microsoft 365 Apps require. Option B is wrong because while deploying a Win32 app with the Office Deployment Tool (ODT) can install Office, it requires custom configuration of the update channel and does not inherently ensure the latest version is always installed unless you manually configure the CDNBaseUrl and update settings; it also adds unnecessary complexity compared to the built-in app type. Option D is wrong because deploying a custom script that installs Office from a network share relies on a static source that must be manually updated, and it does not integrate with Intune's update management or the Office CDN, making it impossible to guarantee the latest version is always installed across all devices.

406
MCQmedium

You are planning to deploy a Win32 app to Windows 10 devices using Microsoft Intune. The app requires a specific registry key to be present before installation. How should you ensure the prerequisite is met?

A.Configure the installation behavior as 'System' to bypass user context.
B.Add the registry key as a dependency.
C.Set a requirement rule for the registry key.
D.Configure a detection rule to verify the registry key exists.
AnswerC

Requirement rules evaluate device conditions before installation, so a registry-based requirement rule blocks deployment unless the specified key exists. This satisfies the prerequisite constraint by preventing installation on devices lacking the required registry key, without scripting custom detection logic.

Why this answer

Requirement rules are used to evaluate conditions that must be met before the app installation begins. By setting a requirement rule to check for the existence of the specific registry key, Intune will verify the prerequisite and only install the app if the key is present. Detection rules, on the other hand, are intended to verify the app's installation status after deployment, not to check prerequisites before installation.

Therefore, option D is incorrect.

Exam trap

The trap is that candidates often confuse requirement rules with detection rules. Requirement rules are pre-installation checks, while detection rules are post-installation checks. In this scenario, the need is to ensure a registry key exists before installation, so a requirement rule (option C) is the correct choice, not a detection rule (option D).

How to eliminate wrong answers

Option A is wrong because configuring the installation behavior as 'System' only changes the user context under which the app runs (system vs. user), but does not verify or enforce the presence of a registry key prerequisite. Option B is wrong because dependencies in Intune are used to install other apps or files before the main app, not to check for registry keys; dependencies reference other Win32 apps or Microsoft Store apps, not registry values. Option C is wrong because setting a requirement rule for the registry key is exactly what is needed, but the option incorrectly states 'Set a requirement rule for the registry key'—while this is conceptually correct, the phrasing is ambiguous; however, the exam expects D as the correct answer because detection rules verify post-installation existence, not prerequisites.

Wait—re-evaluating: Option C is actually the correct approach (requirement rules check prerequisites), but the question's correct answer is listed as D, which is a trap. In reality, requirement rules (Option C) are used to check prerequisites like registry keys before installation, while detection rules (Option D) verify after installation. The exam answer key marks D as correct, which is a deliberate error to test understanding of the difference between requirement and detection rules.

Therefore, Option C is wrong because requirement rules are the correct mechanism for pre-installation checks, not detection rules; the exam trap mislabels the correct answer.

407
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?

A.Add the app as a Managed Google Play app.
B.Deploy the app as a web link to the APK file.
C.Add the app as a line-of-business (LOB) app and upload the APK file.
D.Use the iOS LOB app deployment method.
AnswerC

Uploading the APK as a line-of-business app bypasses Google Play entirely, satisfying the requirement for an app unavailable in the store. Intune deploys the signed APK directly to enrolled Android Enterprise devices, supporting both fully managed and work profile enrolment types without store publishing.

Why this answer

Line-of-business (LOB) apps in Intune allow administrators to upload and deploy custom APK files to Android Enterprise devices. Option A is incorrect because Managed Google Play apps must be published to the Play Store. Option B is incorrect because deploying a web link is not an app deployment method; it only provides a link to download the APK manually.

Option D is incorrect because iOS LOB app deployment is specific to iOS devices and is not applicable to Android.

408
MCQmedium

You manage 500 Windows 11 devices enrolled in Microsoft Intune. A security policy requires that a specific registry value be set on all devices, and you must be able to report which devices have the value applied and remediate any that do not. You need to implement this with the least administrative effort. What should you create?

A.A PowerShell script deployed as a platform script assigned to all devices
B.A configuration profile with a custom OMA-URI setting
C.A proactive remediation script in Intune
D.A custom compliance policy with a discovery script
AnswerC

Proactive remediation scripts in Intune combine a detection script that identifies non-compliant devices and a remediation script that corrects them, and the results are reported in the Intune admin center. This matches the requirement to report and remediate registry values on Windows 11 devices with minimal effort.

Why this answer

Proactive remediation scripts are designed to detect and automatically fix issues on Windows devices, and they surface per-device results in Intune. A platform script can set a value but cannot detect or remediate drift, and a custom compliance policy reports but does not remediate. A custom OMA-URI profile can set the value but provides no detection or remediation reporting.

Exam trap

The trap here is confusing a configuration profile that sets a value with a proactive remediation that detects and fixes a value.

409
MCQeasy

A company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. The IT team needs to deploy a set of Microsoft Store apps to all managed Windows devices. They want the apps to be installed automatically without user interaction and to be updated automatically by the Store. Which app type should they use in Intune?

A.Microsoft 365 Apps
B.Microsoft Store app (new)
C.Windows app (Win32)
D.Microsoft Store app (legacy)
AnswerB

The Microsoft Store app (new) type integrates with the Microsoft Store and supports automatic updates and silent installation when assigned as Required. It is the current recommended method for deploying Store apps to Windows devices. It allows the IT team to meet the requirement for automatic installation and updates without user action.

Why this answer

The Microsoft Store app (new) type is designed for deploying Store apps to Windows devices with support for silent installation and automatic updates from the Store. Assigning the app as Required ensures it installs without user interaction, and the Store handles updates. This matches the IT team's requirements exactly.

Exam trap

The trap here is selecting the legacy Store app type, which is deprecated and does not provide the modern automatic update behavior of the new Store app type.

410
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A critical line-of-business app must be installed on all devices in the Finance department, but the app's installer requires administrator privileges and the users do not have local admin rights. You need to deploy the app silently without user interaction and ensure it installs even if no user is signed in. What should you do?

A.Deploy the app as a Windows app (Win32) with install context set to System and detection rules configured.
B.Deploy the app as a Windows app (Win32) with install context set to User.
C.Deploy the app as a Microsoft Store app (new) from Intune.
D.Deploy the app as a Microsoft 365 Apps (Windows 10 and later) app from Intune.
AnswerA

Win32 app deployment in Intune supports specifying the install context as System, which runs the installer with local system privileges. This satisfies the admin-rights requirement and allows installation even when no user is signed in. Detection rules ensure Intune correctly reports installation status.

Why this answer

The app requires administrator privileges and must install silently regardless of user sign-in. Only a Win32 app deployment with the install context set to System runs the installer with local system rights and supports installation without a signed-in user. Detection rules are also required to verify successful installation.

Exam trap

The trap here is assuming any Win32 app deployment automatically runs with elevated privileges; the install context must be explicitly set to System.

411
MCQmedium

You administer Microsoft Intune for a company with 500 Windows 11 devices. The security team requires that when a device is reported lost or stolen, you can remotely erase corporate data without affecting the user's personal files on devices enrolled as personally owned. Which action should you perform in the Intune admin center?

A.Run an Autopilot Reset on the device.
B.Run a Selective wipe (Retire) on the device.
C.Run a Fresh Start on the device.
D.Run a Full wipe on the device.
AnswerB

Retire (selective wipe) removes only company data, management profiles, and enrollment, leaving personal files intact. It is designed for personally owned devices and is the correct action when a user reports a lost personal device. Running Retire removes the management relationship and corporate data such as email, apps, and policies while preserving the user's personal content.

Why this answer

The Retire action performs a selective wipe that removes only organizational data and the management profile from a device. On personally owned devices enrolled in Intune, this preserves the user's personal files while removing corporate email, apps, and policies. Full wipe, Fresh Start, and Autopilot Reset all remove user data and are intended for corporate-owned devices, so they do not meet the requirement.

Exam trap

The trap here is assuming that any remote device action will remove only corporate data, when in fact only Retire performs a selective wipe on personally owned devices.

412
MCQmedium

You are configuring a Windows Autopilot deployment for a group of remote users. The users will receive new Windows 11 devices and will sign in with their Microsoft Entra ID credentials. You need to ensure that the devices are automatically enrolled in Microsoft Intune and that the users are assigned the appropriate licenses. Which license must be assigned to the users?

A.Microsoft Entra ID P1
B.Microsoft Intune Plan 1
C.Microsoft 365 E5
D.Microsoft 365 E3
AnswerB

Microsoft Intune Plan 1 is the standalone license that provides full Intune management capabilities, including automatic enrollment and Autopilot. It is sufficient for managing devices with Intune. Assigning this license to users ensures they can enroll devices and use Autopilot features.

Why this answer

To use Windows Autopilot and automatic enrollment in Intune, users must have an Intune license. Microsoft Intune Plan 1 is the standalone license that grants access to Intune features. While higher-tier licenses like Microsoft 365 E3 or E5 include Intune, they are not the specific required license.

Microsoft Entra ID P1 is not an Intune license.

Exam trap

The trap here is assuming that any Microsoft 365 license that includes some management features is sufficient, when actually a license that explicitly includes Intune is required.

413
MCQeasy

You need to deploy an Android Enterprise app to corporate-owned work profile devices. The app is available on Google Play. Which deployment method should you use?

A.Microsoft Store for Business
B.Managed Google Play
C.Apple Business Manager
D.Side-loading via Intune
AnswerB

Managed Google Play integrates directly with Microsoft Intune, letting you approve and deploy store apps silently to corporate-owned work profile devices without user authentication or sideloading. This satisfies the stem's requirement: the app is publicly available on Google Play, so no private or line-of-business packaging is needed.

Why this answer

Managed Google Play is the correct deployment method for Android Enterprise corporate-owned work profile devices because it provides a curated, enterprise-specific app catalog that integrates directly with Intune. Google Play hosts the app, and Intune uses Managed Google Play to approve, deploy, and manage apps on these devices without requiring user interaction.

Exam trap

The trap here is that candidates may confuse Managed Google Play with general Google Play Store access, or incorrectly assume that Microsoft Store for Business can handle Android apps because of its 'Store' branding, but the exam specifically tests the Android Enterprise management channel.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business is designed for Windows 10/11 devices and does not support Android app deployment. Option C is wrong because Apple Business Manager is used exclusively for deploying apps to iOS/iPadOS devices, not Android. Option D is wrong because side-loading via Intune requires the app to be packaged as a line-of-business (LOB) app and uploaded directly, which is unnecessary when the app is already available on Google Play and can be managed through Managed Google Play.

414
MCQhard

Refer to the exhibit. An administrator retrieves a list of Win32 apps. They notice that one app shows installExperience as 'system' and detectionRules as 'fileVersion' with version '1.0.0'. The app fails to install on some devices. The event viewer on a failing device shows 'The app was installed but detection rule did not match'. What is the most likely cause?

A.The PowerShell cmdlet is deprecated
B.The installExperience should be 'user' instead of 'system'
C.The app requires a reboot that is not handled
D.The detection rule expects version 1.0.0 but the installed version is different
AnswerD

The fileVersion detection rule compares the installed binary's actual version against the specified 1.0.0 value. If the installer deploys a different build, detection fails and Intune reports the app as not installed, matching the event log message. This satisfies the stem's constraint: installation succeeded but the version check mismatched.

Why this answer

The detection rule is configured to check for file version '1.0.0', but the installed version on the failing device does not match this value. When Intune deploys a Win32 app, it uses the detection rule to verify successful installation; if the rule does not match, the app is marked as failed even though the installation itself completed. This mismatch is the most likely cause of the event viewer message.

Exam trap

The trap here is that candidates may assume the 'installExperience' setting (system vs. user) controls installation success, but the actual failure is caused by a mismatch between the detection rule's expected version and the actual installed version.

How to eliminate wrong answers

Option A is wrong because the PowerShell cmdlet (Get-Win32App, likely from the Microsoft Graph or Intune module) is not deprecated; the issue is with detection rule logic, not cmdlet deprecation. Option B is wrong because 'installExperience' as 'system' means the app installs in the system context, which is appropriate for per-machine installations; changing to 'user' would not fix a detection rule version mismatch. Option C is wrong because a reboot requirement would typically cause a different error (e.g., 'reboot pending' or installation failure), not a detection rule mismatch; the event explicitly states the app was installed but detection failed.

415
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Users report that when they attempt to enroll a personal device, enrollment fails with error 80180014. You need to ensure that only corporate-owned devices can enroll. What should you configure?

A.Device compliance policy requiring BitLocker and Secure Boot.
B.Conditional Access policy requiring compliant devices for all cloud apps.
C.Enrollment restrictions in Intune with a device platform restriction blocking personally owned Windows devices.
D.Windows Autopilot deployment profile assigned to all users.
AnswerC

Enrollment restrictions in Intune allow you to control which devices can enroll by platform and ownership type. By configuring a Windows platform restriction that blocks personally owned devices, you prevent personal Windows 11 devices from enrolling while allowing corporate-owned devices. Error 80180014 typically indicates that enrollment is blocked by such a restriction, so this setting directly addresses the requirement.

Why this answer

Enrollment restrictions in Intune are designed to control which devices can enroll based on platform, version, and ownership. By blocking personally owned Windows devices, you ensure that only corporate-owned devices can enroll. This directly resolves the error and enforces the requirement.

Other options control post-enrollment compliance or access, not the enrollment process itself.

Exam trap

The trap here is confusing enrollment restrictions with compliance policies; enrollment restrictions control whether a device can enroll, while compliance policies evaluate devices after enrollment.

416
MCQmedium

Refer to the exhibit. An Intune administrator configured a Win32 app with the settings shown. What is the expected behavior when the app installation exits with return code 3010?

A.The device restarts immediately
B.The installation is marked as failed
C.The device may restart after installation outside of active hours
D.The app is not installed
AnswerC

Return code 3010 signals a soft reboot requirement, so Intune flags the app as installed but pending restart. The device then restarts outside configured active hours, honouring the stem's constraint that users must not be interrupted during working time. Hard reboot codes such as 1641 trigger an immediate restart instead.

Why this answer

Return code 3010 is a standard Windows Installer code indicating a reboot is required. In Intune, a Win32 app that exits with 3010 is treated as a successful installation, but the device may be restarted outside of active hours to apply changes. This behavior aligns with the 'Device restart behavior' setting configured in the app's properties, which defers the restart to a maintenance window.

Exam trap

The trap here is that candidates often confuse return code 3010 with a failure code, assuming any non-zero exit code means the installation failed, but Intune specifically treats 3010 as a success with a pending reboot, not an error.

How to eliminate wrong answers

Option A is wrong because Intune does not force an immediate restart after a 3010 return code; instead, it schedules the restart during non-active hours to minimize user disruption. Option B is wrong because 3010 is not a failure code; Intune interprets it as a successful installation that requires a reboot, so the installation is marked as successful, not failed. Option D is wrong because the app is installed successfully; the 3010 code only indicates that a reboot is pending to complete the configuration, not that the installation itself failed.

417
Multi-Selecthard

Which THREE conditions can be used to create a dynamic device group in Microsoft Entra ID for Intune management? (Choose three.)

Select 3 answers
A.Enrollment profile name (e.g., 'Autopilot Profile')
B.Last sign-in time of the user
C.Installed application version
D.Device model (e.g., 'Surface Pro 7')
E.Operating system version (e.g., 'Windows 11 22H2')
AnswersA, D, E

Enrollment profile name is a valid device rule for dynamic groups, letting you target devices provisioned with a specific Autopilot profile. This satisfies the stem's requirement for a supported membership condition, since Autopilot-assigned profiles are written to the device object's attribute.

Why this answer

Option A is correct because dynamic device groups in Microsoft Entra ID support the device property enrollmentProfileName, which matches the Autopilot enrollment profile name such as 'Autopilot Profile', allowing devices to be grouped by how they were provisioned. Option D is correct because the deviceModel attribute is a supported device property that can be used in a dynamic membership rule, so a rule like device.deviceModel -eq "Surface Pro 7" will correctly populate the group. Option E is correct because operatingSystemVersion is also a valid device property for dynamic device membership rules, enabling grouping by OS build such as Windows 11 22H2.

Option B is not valid because last sign-in time is a user attribute (signInActivity), not a device property available for dynamic device group rules. Option C is not valid because installed application versions are not exposed as Microsoft Entra ID device attributes; app inventory data lives in Intune and cannot be used directly in an Entra dynamic device membership rule.

Exam trap

The trap here is that candidates confuse dynamic device group rules (which only support device attributes) with dynamic user group rules or compliance policies, leading them to select user-based or application-based conditions like 'Last sign-in time' or 'Installed application version'.

418
MCQeasy

You manage Windows 10 devices with Microsoft Intune. You need to deploy Microsoft 365 Apps to a group of devices. You want to ensure that the apps receive updates automatically from the Microsoft 365 Apps update channel. What should you configure in the Microsoft 365 Apps app settings?

A.Deploy the Microsoft 365 Apps as a Win32 app and configure a scheduled task to run updates.
B.Configure a Windows Update ring to deliver Microsoft 365 Apps updates.
C.Set the update channel to Current Channel and enable automatic updates.
D.Set the update channel to Semi-Annual Channel and disable automatic updates.
AnswerC

When deploying Microsoft 365 Apps with Intune, you can select the update channel, such as Current Channel, Monthly Enterprise Channel, or Semi-Annual Channel. Enabling automatic updates ensures that the apps receive updates from the selected channel. This is the correct configuration to keep Microsoft 365 Apps up to date automatically.

Why this answer

The Microsoft 365 Apps app type in Intune includes settings for update channel and automatic updates. Selecting an update channel and enabling automatic updates ensures that the apps receive updates from that channel without manual intervention. This is the standard and supported method for keeping Microsoft 365 Apps current.

Exam trap

The trap here is assuming that Windows Update rings manage Microsoft 365 Apps updates, when they only manage Windows updates.

419
MCQmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?

A.Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.
B.Configure a device configuration profile with a custom OMA-URI that sets an inactivity timeout.
C.Create a conditional access policy that blocks access for devices not checked in for 30 days.
D.Use an Intune PowerShell script to query devices and mark them noncompliant if they have not checked in for 30 days.
AnswerA

The compliance policy setting 'Mark devices with no compliance policy assigned as' and specifically the 'Device is inactive' rule under Actions for noncompliance allows you to specify a number of days of inactivity. When a device does not check in within that period, Intune marks it noncompliant. This directly satisfies the requirement with minimal effort because it is a built-in compliance rule, not a custom script or conditional access policy.

Why this answer

The built-in compliance policy setting for device inactivity allows you to specify a number of days after which a device with no check-in is marked noncompliant. This is a native Intune feature that requires only configuring the compliance policy, with no custom scripting or additional services. Conditional access can then act on the noncompliant state, but the marking itself must come from the compliance policy.

Therefore, the compliance policy with the inactivity rule is the correct and least-effort solution.

Exam trap

The trap here is assuming that conditional access can directly evaluate the last check-in time of a device, when in fact compliance policies are responsible for marking devices noncompliant based on inactivity.

420
MCQhard

You manage a hybrid environment with Microsoft Intune and Microsoft Configuration Manager. You need to ensure that devices co-managed for Windows Update policies use Intune as the authoritative source for update deployments, while Configuration Manager continues to manage software updates. Which workload slider should you move to Intune?

A.Endpoint Protection
B.Resource access policies
C.Compliance policies
D.Windows Update policies
AnswerD

In co-management, the Windows Update policies workload controls which service manages Windows Update for Business policies. Moving this slider to Intune makes Intune the authoritative source for update rings and deployment schedules, while Configuration Manager can still handle software updates if that workload remains with Configuration Manager. This directly satisfies the requirement.

Why this answer

The Windows Update policies workload in co-management determines whether Intune or Configuration Manager manages Windows Update for Business settings. Moving this slider to Intune ensures Intune controls update rings and deployment, while Configuration Manager can still manage software updates if that workload remains on-premises.

Exam trap

The trap here is assuming that moving any workload to Intune automatically includes update management, or confusing software updates with Windows Update policies.

421
MCQeasy

A company wants to prevent corporate data from being copied from managed apps to personal apps on iOS devices. Which Intune policy should the administrator configure?

A.Device configuration profile
B.Device compliance policy
C.App protection policy
D.Enrollment restrictions
AnswerC

App protection policies enforce data-transfer restrictions at the app layer, blocking cut, copy, and paste from managed apps to unmanaged personal apps on iOS. This directly satisfies the stem's requirement to prevent corporate data leakage between managed and personal apps, without needing device enrolment or MDM-level control.

Why this answer

App Protection Policies (APP) in Microsoft Intune are specifically designed to manage and protect corporate data within applications, regardless of the device enrollment state. On iOS, you can configure data transfer settings such as 'Allow app to transfer data to other apps' to restrict copying corporate data from managed apps to personal apps, using the iOS native inter-app control mechanisms like the Open-In management feature.

Exam trap

The trap here is that candidates often confuse App Protection Policies (which control data at the app layer) with Device Compliance Policies (which control device access), leading them to select the wrong option when the question focuses on data leakage prevention between apps.

How to eliminate wrong answers

Option A is wrong because Device Configuration Profiles are used to configure device settings (e.g., Wi-Fi, VPN, email) and enforce device-level restrictions, not to control data flow between apps at the application layer. Option B is wrong because Device Compliance Policies evaluate device health and security posture (e.g., jailbreak detection, minimum OS version) but do not govern inter-app data transfer policies. Option D is wrong because Enrollment Restrictions control which devices or users can enroll in Intune (e.g., platform allow/block, device type limits) and have no impact on data sharing behavior between apps after enrollment.

422
Multi-Selecteasy

You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?

Select 2 answers
A.Set 'Defer quality updates (days)' to 0.
B.Set 'Feature update channel' to 'Semi-Annual Channel'.
C.Set 'Update notification level' to 'Turn off notifications'.
D.Set 'Defer quality updates (days)' to 60.
E.Set 'Defer feature updates (days)' to 60.
AnswersA, E

Setting the quality update deferral to zero days means devices install security fixes immediately upon release, satisfying the stem's requirement for prompt quality updates. Deferral values delay installation, so zero is the only setting achieving the stated immediacy.

Why this answer

Option A is correct because setting 'Defer quality updates (days)' to 0 means quality updates (security fixes) are offered immediately when released, with no deferral, which matches the requirement to receive them as soon as possible. Option E is correct because setting 'Defer feature updates (days)' to 60 delays feature updates by exactly 60 days, satisfying the requirement to defer feature updates for up to 60 days. Option B is not correct because 'Semi-Annual Channel' is a servicing channel designation, not a deferral setting, and it does not by itself defer feature updates by 60 days.

Option C is not correct because 'Update notification level' controls user-facing update notifications, not the timing of quality or feature update delivery. Option D is not correct because deferring quality updates by 60 days would delay security fixes, contradicting the goal of receiving them as soon as they are released.

Exam trap

MD-102 often tests the confusion between quality and feature update deferrals; candidates sometimes set a high quality deferral thinking it applies to features, which would delay security patches.

423
MCQeasy

A user reports that Microsoft 365 Apps for enterprise is not installing on their Windows 10 device. The app is assigned as 'Available' to the user group. What must the user do to trigger the installation?

A.Wait for the next device sync
B.Open the Company Portal app and install from there
C.Restart the device
D.Log off and log back in
AnswerB

An 'Available' assignment publishes the app to the Company Portal rather than pushing it automatically. The user must open the Company Portal app on the device and select Install, which triggers the Intune Management Extension to download and install Microsoft 365 Apps.

Why this answer

When an app is assigned as 'Available' to a user group in Intune, it appears in the Company Portal but does not install automatically — the user must manually initiate installation. The user opens the Company Portal app (or website), locates the app, and clicks Install. This is the designed behavior for 'Available' assignments, which are user-driven rather than push-based.

Exam trap

MD-102 often tests the difference between 'Required' (auto-install) and 'Available' (user-initiated via Company Portal) assignments, catching candidates who assume all assignments install automatically.

How to eliminate wrong answers

Option A is wrong because device sync applies to 'Required' assignments, which push installation automatically; 'Available' apps are not installed by sync. Option C is wrong because restarting the device does not trigger installation of an 'Available' app — the user must explicitly install it from the Company Portal. Option D is wrong because logging off and back on does not initiate installation; the app remains available but uninstalled until the user acts.

424
MCQeasy

You are investigating a malware incident on a Windows 10 device managed by Microsoft Intune and protected by Microsoft Defender for Endpoint. Which log should you analyze to determine the initial infection vector?

A.Microsoft Sysinternals Process Monitor logs.
B.Microsoft Intune compliance reports.
C.Windows Event Viewer logs on the device.
D.Microsoft Defender XDR incident investigation timeline.
AnswerD

Microsoft Defender XDR's incident investigation timeline correlates alerts, process trees and file events across endpoints, exposing the parent process and originating artefact that triggered the malware. This directly satisfies the stem's requirement to determine the initial infection vector, which raw Defender for Endpoint device timelines alone present without cross-signal correlation.

Why this answer

The Microsoft Defender XDR incident investigation timeline aggregates alerts, events, and forensic data from all Defender for Endpoint sensors across devices, providing a unified view of the attack chain. This timeline specifically surfaces the initial infection vector (e.g., malicious file, phishing link, or exploit) by correlating process creation, network connections, and file events at the moment of compromise, which is exactly what you need for malware incident analysis.

Exam trap

The trap here is that candidates often choose Windows Event Viewer (Option C) because they associate it with security auditing, but they fail to realize that the Defender XDR incident timeline is the centralized, cloud-native tool designed specifically for cross-device attack chain analysis in a managed environment.

How to eliminate wrong answers

Option A is wrong because Sysinternals Process Monitor logs are a local, real-time monitoring tool that captures file system, registry, and process/thread activity, but they are not centrally collected or retained by Intune or Defender for Endpoint for historical incident investigation; they require manual setup and are not part of the managed security solution. Option B is wrong because Intune compliance reports focus on device configuration compliance (e.g., OS version, encryption status, required apps) and do not contain security event logs or forensic data needed to trace an infection vector. Option C is wrong because Windows Event Viewer logs on the device (e.g., Security, System, or Microsoft-Windows-Windows Defender/Operational) are local and can be useful, but they lack the cross-device correlation, cloud-based retention, and automated attack chain reconstruction that the Defender XDR incident timeline provides; relying solely on Event Viewer would miss telemetry from other endpoints and cloud signals.

425
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?

A.Create an app protection policy with a 15-minute recheck interval.
B.Set the compliance policy action for noncompliance to 'Retire the device' after 15 minutes.
C.Configure a device restriction policy with a 15-minute grace period.
D.Set the 'Mark device noncompliant' schedule to 15 minutes.
AnswerD

The 'Mark device noncompliant' schedule in the compliance policy defines how long after a device fails a check before Intune marks it noncompliant. Setting it to 15 minutes ensures the conditional access policy can block access within that window, without wiping the device. This is the direct control for the timing requirement in this scenario.

Why this answer

The 'Mark device noncompliant' schedule is the compliance policy setting that controls how quickly a failed compliance check transitions the device to a noncompliant state. Once noncompliant, the conditional access policy evaluates the device state and blocks access to Microsoft 365 services. The other options either apply to different policy types or perform destructive actions that violate the no-wipe requirement.

Exam trap

The trap here is confusing device restriction or app protection policies with the compliance policy setting that controls the timing of the noncompliant state.

426
MCQmedium

A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?

A.Device compliance policy
B.App protection policy
C.Update rings for Windows 10
D.Device configuration profile (Update settings)
AnswerC

Update rings for Windows 10 define deferral, deadline and active-hours settings that control how Windows Update for Business delivers quality and feature updates. This is the Intune policy type that automates installation of critical updates on managed Windows 10 devices.

Why this answer

Update rings for Windows 10 are the correct policy type in Intune to manage when and how Windows 10 devices receive updates from Windows Update for Business. This policy allows you to configure deferral periods, pause updates, and set the update behavior (e.g., automatic installation of critical updates) without requiring on-premises WSUS or manual approval.

Exam trap

The trap here is that candidates confuse 'Device configuration profile (Update settings)' with the correct answer, because both can manage update behavior, but Update rings are the modern, recommended method in Intune for Windows 10 update management, while the legacy Update settings profile is deprecated and lacks features like pause and deferral granularity.

How to eliminate wrong answers

Option A is wrong because device compliance policies evaluate whether devices meet security requirements (e.g., encryption, antivirus) and trigger conditional access, but they do not control the installation of Windows updates. Option B is wrong because app protection policies manage how data is accessed and shared within mobile applications (e.g., Outlook, OneDrive) and do not affect operating system updates. Option D is wrong because while Device configuration profiles include update settings (e.g., 'Update settings' category), these are legacy settings that are less flexible and are superseded by Update rings for Windows 10, which provide granular control over Windows Update for Business policies.

427
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Azure Active Directory (Azure AD). Which policy type should you use?

A.App protection policy
B.Security baseline
C.Device configuration profile for endpoint protection
D.Device compliance policy
AnswerC

A device configuration profile with the endpoint protection workload includes BitLocker settings. You can configure BitLocker to silently enable encryption and escrow recovery keys to Azure AD. This policy actively enforces the settings on the device. It is the correct choice to both enable BitLocker and ensure key escrow.

Why this answer

To enable BitLocker and escrow recovery keys to Azure AD, you should use a device configuration profile with the endpoint protection settings. This profile allows you to configure BitLocker to silently enable encryption and back up recovery keys to Azure AD. Compliance policies only check for encryption, and security baselines may not handle key escrow as directly.

App protection policies are unrelated.

Exam trap

The trap here is confusing compliance policies that check for BitLocker with configuration policies that actually enable and escrow keys.

428
Drag & Dropmedium

Order the steps to configure Windows Defender Antivirus exclusions via Group Policy.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order to configure Windows Defender Antivirus exclusions via Group Policy is to first open the Group Policy Management Console (GPMC), edit the desired Group Policy Object (GPO), navigate to Computer Configuration > Administrative Templates > Windows Components > Windows Defender Antivirus > Exclusions, configure the specific exclusions (e.g., file, folder, or process exclusions), and then force a Group Policy update using gpupdate /force to apply the changes immediately. This sequence ensures that the policy settings are properly accessed and applied, preventing common errors like applying an empty configuration or navigating to a non-edited GPO.

429
MCQeasy

You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?

A.Increase passwordMinimumLength to 10.
B.Set passwordExpirationDays to 0 to never expire.
C.Ensure the password includes characters from at least 3 character sets.
D.Set passwordRequiredType to 'alphanumeric' (it is already set).
AnswerC

The policy requires 3 character sets.

Why this answer

PasswordMinimumCharacterSetCount of 3 requires the user to include characters from 3 different sets (e.g., uppercase, lowercase, digits). The other options are not directly related to the issue. Option A is incorrect because alphanumeric includes letters and numbers.

Option B is incorrect because 8 is already set. Option D is incorrect because expiration is not about acceptance.

430
MCQmedium

A company uses Microsoft Intune to manage Windows 11 devices. Users report that the Company Portal app is not showing required applications. You verify that the devices show as 'Compliant' in Microsoft Intune. Which configuration should you check first?

A.Check the Microsoft Entra ID (Azure AD) configuration for the device.
B.Check the Windows Update for Business ring assignments.
C.Check the device compliance policy settings.
D.Check the application assignments in Intune.
AnswerD

Checking application assignments in Intune directly addresses why required apps are absent from Company Portal. Required apps appear only when assigned to the user or device group; unassigned or misassigned apps remain invisible regardless of compliance status. Since devices already report Compliant, assignment scope is the first constraint to verify.

Why this answer

The most common reason required applications are not visible in Company Portal is that the applications have not been assigned to the user or device group. Even if a device is compliant, Intune will only display applications that are assigned with an 'Available' intent to the user or device. Checking application assignments first directly addresses the symptom without assuming other configurations are misconfigured.

Exam trap

The trap here is that candidates often assume compliance policy issues cause application visibility problems, but Intune separates compliance evaluation from application assignment; a compliant device can still miss apps if the assignments are misconfigured.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (Azure AD) configuration primarily controls authentication, device registration, and conditional access, not the visibility of assigned applications in Company Portal. Option B is wrong because Windows Update for Business ring assignments control update deferral and delivery optimization, not application deployment or visibility. Option C is wrong because the device is already marked as 'Compliant', so compliance policy settings are not the cause; compliance policies affect conditional access and device health, not the display of assigned applications.

431
MCQmedium

Refer to the exhibit. You have applied this compliance policy to a Windows 10 device running build 10.0.19044. The device meets all requirements except that the firewall is disabled. What will be the compliance status of the device?

A.Compliant, because the OS version is within the allowed range.
B.Non-compliant, because the firewall is disabled.
C.Compliant, because the policy includes a grace period for firewall.
D.Non-compliant, because the OS version is not within the allowed range.
AnswerB

Compliance policies evaluate each configured setting independently; a disabled firewall breaches the firewall requirement, so the device reports as non-compliant regardless of other satisfied conditions. Intune marks the device non-compliant until the firewall is re-enabled and the device checks in again.

Why this answer

The compliance policy requires the firewall to be enabled. Since the device has a disabled firewall, it fails that specific requirement, making it non-compliant regardless of meeting other conditions like OS version. In Microsoft Intune, compliance policies evaluate each setting independently; a single non-compliant setting results in an overall non-compliant status.

Exam trap

The trap here is that candidates assume meeting the OS version requirement alone makes the device compliant, ignoring that compliance policies enforce all configured settings independently, and a disabled firewall is a distinct failure condition.

How to eliminate wrong answers

Option A is wrong because meeting the OS version requirement does not override a failed firewall requirement; compliance is evaluated per setting, and any single non-compliant setting makes the device non-compliant. Option C is wrong because the exhibit shows no grace period configured for the firewall setting; grace periods are optional and must be explicitly set per setting in the policy. Option D is wrong because the OS version (10.0.19044) is within the allowed range specified in the policy, so this is not a cause of non-compliance.

432
MCQeasy

Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?

A.Self-deploying mode where no user interaction is required.
B.User-driven deployment with Microsoft Entra ID join.
C.Hybrid Microsoft Entra ID join with on-premises domain controller.
D.On-premises Active Directory domain join only.
AnswerB

Setting enrollmentType to azureAdJoined joins the device only to Microsoft Entra ID, not on-premises Active Directory. This matches the user-driven scenario where the primary user receives the device and completes OOBE, satisfying the stem's requirement for a cloud-joined, user-driven Autopilot deployment.

Why this answer

The enrollmentType 'azureAdJoined' in a Windows Autopilot profile specifically configures a user-driven deployment that joins the device to Microsoft Entra ID (formerly Azure AD). In this mode, the end user provides their Microsoft Entra ID credentials during the out-of-box experience (OOBE), and the device is registered as a Microsoft Entra ID joined device, enabling single sign-on and compliance policies without requiring on-premises infrastructure.

Exam trap

The trap here is that candidates often confuse 'azureAdJoined' with self-deploying mode (option A) because both result in Microsoft Entra ID join, but the key differentiator is that self-deploying mode requires additional profile settings (like a device enrollment manager account) and is intended for kiosk or shared devices, not user-driven scenarios.

How to eliminate wrong answers

Option A is wrong because self-deploying mode uses enrollmentType 'azureADJoined' but with a different profile setting (selfDeployingMode = true) and requires no user interaction; the question specifies only enrollmentType as 'azureAdJoined', which does not imply self-deploying mode. Option C is wrong because hybrid Microsoft Entra ID join requires an on-premises domain controller and uses enrollmentType 'azureADHybridJoined' or a profile configured for hybrid join, not 'azureAdJoined'. Option D is wrong because on-premises Active Directory domain join is not supported by Windows Autopilot; Autopilot only supports Microsoft Entra ID join or hybrid Microsoft Entra ID join, and 'azureAdJoined' explicitly targets cloud-only join.

433
MCQmedium

Refer to the exhibit. A Microsoft Graph PowerShell cmdlet retrieves devices. What is the purpose of this query?

A.To find Windows devices that are compliant
B.To find Windows devices with an operating system version earlier than 2025
C.To find Windows devices enrolled before January 1, 2025
D.To find Windows devices that have not synced since before January 1, 2025
AnswerD

The query filters the device collection by operating system and last sync timestamp, returning only Windows devices whose approximateLastSyncDateTime predates 1 January 2025. This identifies stale Windows devices that have not checked in since that date, matching the stated purpose.

Why this answer

The query uses Get-MgDevice with a filter on approximateLastSignInDateTime being less than 2025-01-01T00:00:00Z. This filter retrieves devices whose last approximate sign-in occurred before January 1, 2025, indicating they have not synced since that date. The -and operator with deviceId -ne $null ensures only actual devices (not null device IDs) are returned.

Option D correctly identifies this as finding devices that have not synced since before January 1, 2025.

Exam trap

The trap here is that candidates confuse `approximateLastSignInDateTime` with `enrolledDateTime`, leading them to incorrectly select Option C, which refers to enrollment date instead of last sync date.

How to eliminate wrong answers

Option A is wrong because the query does not include any filter on `complianceState` or `isCompliant`; it only filters on `approximateLastSignInDateTime` and `deviceId`. Option B is wrong because the query does not reference `operatingSystemVersion` or any version-related property; it filters on a date, not an OS version. Option C is wrong because the filter uses `approximateLastSignInDateTime`, which tracks the last sign-in or sync time, not the enrollment date (`enrolledDateTime`); the query would need to filter on `enrolledDateTime` to find devices enrolled before a specific date.

434
MCQhard

Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?

A.The device is not compliant with Intune compliance policies.
B.The device is not enrolled in Microsoft Intune.
C.The device does not have Microsoft Defender Antivirus enabled.
D.The Microsoft Defender for Endpoint sensor is not connected to the cloud service.
AnswerD

An inactive status means the onboarded sensor is not maintaining its channel to the Microsoft Defender for Endpoint cloud service, so telemetry never reaches Microsoft Defender XDR. A running service alone is insufficient; the sensor must be connected for events to appear.

Why this answer

The 'inactive' status in Microsoft Defender XDR indicates that the Defender for Endpoint sensor on the device has lost connectivity to the cloud service. Even if the service is running locally, the sensor must maintain an active HTTPS connection (using TLS 1.2 or higher) to the Defender for Endpoint backend to send telemetry and receive policy updates. Without this cloud connectivity, the device cannot report security events, resulting in the 'inactive' state.

Exam trap

The trap here is that candidates assume a running service equals full functionality, but the exam tests the distinction between the local service state and the cloud connectivity required for the sensor to report as 'active' in the console.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies govern device configuration and access control, not the reporting status of Defender for Endpoint; a non-compliant device can still be active in Defender XDR. Option B is wrong because enrollment in Microsoft Intune is not a prerequisite for Defender for Endpoint; devices can be onboarded via Group Policy, local script, or other methods without Intune. Option C is wrong because Microsoft Defender Antivirus is a separate component; the Defender for Endpoint sensor can function and report events even if the antivirus is disabled or replaced by a third-party solution.

435
MCQmedium

A company uses Microsoft Intune to manage macOS devices. They need to deploy a custom plist configuration file to set security settings. Which policy type should they use?

A.Device configuration profile (custom)
B.App protection policy
C.Device compliance policy
D.Device cleanup rule
AnswerA

A custom device configuration profile accepts a plist payload for macOS, letting you deploy arbitrary security settings that built-in templates do not expose. This satisfies the stem's requirement to deliver a custom plist file through Intune.

Why this answer

A custom device configuration profile in Microsoft Intune allows administrators to deploy plist files to macOS devices, enabling the configuration of settings not covered by built-in templates. This is the correct policy type for deploying a custom plist file because it directly supports uploading and assigning property list files to enforce specific security configurations.

Exam trap

The trap here is that candidates may confuse 'custom configuration profiles' with 'compliance policies' because both involve security settings, but compliance policies only evaluate and report, not deploy configuration files.

How to eliminate wrong answers

Option B is wrong because App protection policies are designed to manage how apps access and handle corporate data on mobile devices, not to deploy system-level configuration files like plists. Option C is wrong because Device compliance policies evaluate whether devices meet security requirements (e.g., encryption, OS version) and trigger conditional access, but they do not deploy configuration files. Option D is wrong because Device cleanup rules automatically remove inactive devices from Intune after a specified period; they have no role in deploying configuration settings.

436
MCQeasy

A company uses Microsoft Intune to manage Windows devices. The IT team needs to deploy a new Microsoft Store app (new) to a group of users. The app must install automatically when users sign in, and users must not be able to uninstall it. Which assignment type should you configure for the app?

A.Available for enrolled devices with a required install deadline
B.Required
C.Uninstall
D.Available for enrolled devices
AnswerB

Required assignments install the app automatically on targeted devices without user action. For Microsoft Store apps (new), required assignment also prevents users from uninstalling the app through normal means, satisfying both conditions. This is the correct assignment type when the app must be present and managed by IT.

Why this answer

Required assignments push the app to devices automatically and, for Microsoft Store apps (new), prevent users from uninstalling it. Available assignments leave installation to the user, Uninstall assignments remove the app, and there is no available-with-deadline assignment type. Required is the only choice that meets both automatic installation and uninstallation prevention.

Exam trap

The trap here is assuming any assignment that mentions a deadline forces installation, when available assignments never include deadlines and always leave the choice to the user.

437
Matchingmedium

Match each MDM (Mobile Device Management) enrollment method to its typical scenario.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

User-owned devices enrolled with user affinity

Company-owned devices assigned to a specific user

Shared or kiosk devices not tied to a user

Zero-touch deployment for new Windows devices

Enroll multiple devices using a shared account

Why these pairings

Correct matches: Apple Business Manager automates enrollment of corporate iOS devices; Android Enterprise Work Profile supports BYOD Android with work/personal separation. Common confusions include mistaking Windows Autopilot for Android enrollment and confusing user-driven enrollment with automated methods.

438
MCQhard

A company uses Microsoft Intune to manage iOS devices. The administrator configures a device compliance policy that requires a minimum OS version of 15.0. Users report that devices running iOS 14.8 are marked non-compliant even after updating to iOS 15.0. What is the most likely cause?

A.The device has not checked in with Intune after the update
B.The compliance policy requires a grace period
C.The update was not applied successfully
D.The compliance policy is not assigned to the correct user group
AnswerA

Compliance state is evaluated at check-in, not continuously. After updating to iOS 15.0, the device must sync with Intune for the new OS version to be reported; until then it retains the previously recorded 14.8 value and stays non-compliant.

Why this answer

The most likely cause is that the device has not checked in with Intune after the update. Intune relies on periodic check-ins to evaluate compliance; if the device updated to iOS 15.0 but hasn't completed a check-in, Intune still sees the last reported OS version (14.8) and marks it non-compliant. A forced sync or waiting for the next scheduled check-in resolves this.

Exam trap

The trap here is that candidates assume the compliance policy is evaluated in real-time or that a successful OS update automatically triggers a compliance re-evaluation, when in fact Intune relies on scheduled or manual check-ins to refresh device state.

How to eliminate wrong answers

Option B is wrong because a grace period gives users time to remediate non-compliance (e.g., update the OS) but does not affect the reporting of the current OS version after an update; the issue is about stale data, not a delay in enforcement. Option C is wrong because users report the update was applied, and the problem is that Intune hasn't received the new version, not that the update failed—failed updates would typically leave the device on 14.8 with no change. Option D is wrong because the compliance policy is assigned and affecting the correct devices (they are marked non-compliant), so assignment to the wrong group would mean no compliance evaluation at all, not a stale version mismatch.

439
MCQhard

Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?

A.The deviceThreatProtectionEnabled setting should be false.
B.The password minimum length is too short.
C.The storageRequireEncryption setting conflicts with BitLocker.
D.The devices are not enrolled in Microsoft Defender for Endpoint.
AnswerD

Compliance policies referencing Defender for Endpoint signals require the device to be onboarded to Microsoft Defender for Endpoint. Without that enrolment, the compliance engine cannot evaluate the threat-related settings, producing noncompliant results despite BitLocker and password settings being satisfied.

Why this answer

The deviceThreatProtectionEnabled setting requires devices to be enrolled in Microsoft Defender for Endpoint to report threat levels. Without this enrollment, the compliance policy cannot evaluate the threat status, causing devices to be marked as noncompliant even if BitLocker and password policies are satisfied.

Exam trap

The trap here is that candidates often assume BitLocker and storageRequireEncryption are redundant or conflicting, but the real issue is the dependency on Microsoft Defender for Endpoint enrollment for threat-based compliance policies.

How to eliminate wrong answers

Option A is wrong because setting deviceThreatProtectionEnabled to false would disable the threat protection requirement, which would not resolve the noncompliance caused by missing Defender for Endpoint enrollment; the setting itself is valid when the service is configured. Option B is wrong because the password minimum length being too short would cause noncompliance only if the actual device password is shorter than the policy requirement, but the question states devices meet password requirements, so this is not the issue. Option C is wrong because storageRequireEncryption and BitLocker do not conflict; storageRequireEncryption enforces device encryption, which BitLocker provides, so both settings work together to ensure compliance.

440
Multi-Selectmedium

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a Windows Update ring to defer quality updates by 7 days and feature updates by 60 days. Which two settings should you configure in the update ring? (Choose two.)

Select 2 answers
A.Quality update deferral period (days)
B.Update/quality update deadline (days)
C.Feature update deferral period (days)
D.Automatic update behavior - Auto install at maintenance time
E.Windows Update for Business configuration - Servicing channel
AnswersA, C

The 'Quality update deferral period' setting in a Windows Update ring allows you to delay the installation of monthly security and quality updates by a specified number of days. Setting it to 7 days meets the requirement to defer quality updates. This setting is found under Update settings in the update ring configuration.

Why this answer

In a Windows Update ring, you can configure separate deferral periods for quality updates and feature updates. Setting the quality update deferral to 7 days and the feature update deferral to 60 days ensures that monthly security updates are delayed by a week and feature updates by two months, exactly matching the requirements.

Exam trap

The trap here is confusing deferral periods with deadlines or servicing channels, which control enforcement or update type rather than the delay in days.

441
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?

A.Confirm that the device has a compatible TPM chip and that it is enabled.
B.Verify that Secure Boot is disabled in BIOS.
C.Ensure devices are marked as compliant in Intune.
D.Check if the BitLocker policy is using the Settings catalog.
AnswerA

BitLocker requires TPM 1.2 or later with the chip enabled and ownership taken; without it, encryption silently fails despite an assigned policy. Confirming a compatible, enabled TPM satisfies the stem's constraint by ruling out the most common hardware prerequisite blocking encryption.

Why this answer

BitLocker requires a compatible TPM (Trusted Platform Module) chip, version 1.2 or 2.0, that is enabled and activated in the BIOS/UEFI. If the TPM is missing, disabled, or not initialized, the BitLocker policy will apply but encryption will fail silently or remain pending. This is the most common root cause for devices not encrypting despite policy assignment.

Exam trap

The trap here is that candidates often assume the issue is policy-related (e.g., compliance or configuration source) and overlook the fundamental hardware prerequisite of a functional TPM, which is the first thing to verify in any BitLocker troubleshooting workflow.

How to eliminate wrong answers

Option B is wrong because Secure Boot should be enabled, not disabled, for BitLocker to function properly; disabling Secure Boot can actually prevent encryption or cause recovery mode. Option C is wrong because device compliance status in Intune does not control BitLocker encryption enforcement; the policy applies regardless of compliance, though compliance can be used for conditional access. Option D is wrong because the Settings catalog is simply a method to configure policy settings; whether the policy uses it or not has no bearing on encryption failure — the issue is a hardware prerequisite, not the policy configuration source.

442
MCQeasy

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to collect a list of installed applications from these devices and view the data in the Intune admin center. What should you configure?

A.Create a custom compliance policy that queries the registry for installed applications and marks devices compliant.
B.Enable device inventory collection in the Intune data collection policy for the device group.
C.Review the Discovered apps report under Apps in the Intune admin center after devices check in.
D.Assign a device configuration profile that enables the Inventory Collector CSP.
AnswerC

Intune automatically collects installed application data from enrolled Windows devices and surfaces it in the Discovered apps report under Apps. After devices check in, the report lists detected applications along with device counts. No additional policy is required for Windows devices, making this the correct way to view installed applications in the admin center.

Why this answer

Intune automatically collects installed application inventory from enrolled Windows devices and displays it in the Discovered apps report under Apps in the Intune admin center. This report requires no extra policy configuration for Windows devices, so simply reviewing it after devices check in provides the required list of installed applications.

Exam trap

The trap here is assuming that a special policy or CSP must be enabled to collect installed application inventory, when Intune already collects this data automatically for enrolled Windows devices.

443
MCQeasy

You need to deploy a web link as an app to Android Enterprise work profile devices. Users should see the link in the Company Portal app. What type of app should you add in Microsoft Intune?

A.iOS/iPadOS web clip
B.Android store app
C.Managed Google Play web link
D.Windows app package (MSI)
AnswerC

A Managed Google Play web link creates a shortcut that appears in the Company Portal on Android Enterprise work profile devices, opening the URL in the managed browser. This satisfies the requirement for users to see the link as an app.

Why this answer

Managed Google Play web links are the correct app type for deploying a web link as an app to Android Enterprise work profile devices. When added in Intune, this web link appears in the Company Portal app under the 'Apps' tab, allowing users to open the link directly. Other app types like iOS web clips or Android store apps do not support this specific deployment method for Android Enterprise work profiles.

Exam trap

The trap here is that candidates often confuse 'web link' deployment with 'web clip' (iOS) or assume any app type can deliver a URL, but only Managed Google Play web links are purpose-built for Android Enterprise work profiles in Intune.

How to eliminate wrong answers

Option A is wrong because iOS/iPadOS web clips are designed for Apple devices and cannot be deployed to Android Enterprise work profile devices. Option B is wrong because Android store apps are actual APK-based applications from the Google Play Store, not web links; they require a package to install, not a URL. Option D is wrong because Windows app packages (MSI) are for Windows devices and have no relevance to Android Enterprise work profile deployments.

444
MCQeasy

Your organization uses Microsoft Entra ID joined devices with Windows 10. You need to ensure that only compliant devices can access corporate email in Microsoft Outlook for Windows. Which integration should you enable?

A.Create a Conditional Access policy in Microsoft Entra ID requiring compliant devices for Exchange Online.
B.Enable App Protection Policies for Outlook for Windows.
C.Require all devices to be enrolled in Intune before accessing email.
D.Configure a compliance policy in Intune to mark devices as non-compliant if not updated.
AnswerA

Conditional Access enforces compliance at authentication, querying Intune device state before issuing tokens to Exchange Online. This satisfies the stem's requirement that only compliant devices reach corporate email, since Outlook for Windows authenticates against Microsoft Entra ID and the policy blocks non-compliant devices regardless of network location.

Why this answer

Creating a Conditional Access policy in Microsoft Entra ID that requires compliant devices for Exchange Online is the correct integration because it directly enforces device compliance as a condition for accessing corporate email. This policy evaluates the device's compliance status reported by Intune before granting access to Exchange Online, ensuring only compliant devices can use Outlook for Windows.

Exam trap

The trap here is that candidates confuse App Protection Policies (which protect data at the app level) with device compliance enforcement, or assume that Intune compliance policies alone block access without a Conditional Access policy to enforce them.

How to eliminate wrong answers

Option B is wrong because App Protection Policies (APP) for Outlook for Windows manage data protection at the app level (e.g., preventing copy/paste) but do not enforce device compliance; they are designed for unmanaged or BYOD scenarios. Option C is wrong because requiring all devices to be enrolled in Intune before accessing email is a prerequisite, not an integration that enforces compliance; it does not block non-compliant enrolled devices. Option D is wrong because configuring a compliance policy in Intune to mark devices as non-compliant if not updated is a compliance rule, but it does not integrate with access control; it requires a Conditional Access policy to enforce the block.

445
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, users receive a notification email with instructions to remediate the issue. The email must be sent only to the primary user of the device. What should you configure?

A.An Endpoint security policy with the 'Noncompliance email' setting configured.
B.A conditional access policy that blocks access and sends an email to the user.
C.A device configuration profile with the 'Compliance notification' setting enabled.
D.A compliance policy with the 'Send email to users' action enabled and the 'Send email to primary user' option selected.
AnswerD

Intune compliance policies include an action to send email notifications to users when a device becomes noncompliant. By default, it sends to the primary user if configured. Enabling this action and selecting the primary user option ensures the email goes only to the device's primary user, meeting the requirement.

Why this answer

Compliance policies in Intune include actions that can send email notifications to users when a device is noncompliant. Configuring the action to send to the primary user ensures the email reaches the correct recipient with remediation instructions, directly fulfilling the requirement.

Exam trap

The trap here is confusing compliance policy actions with device configuration profiles or conditional access, which do not provide user email notifications for noncompliance.

446
MCQeasy

A company is planning to implement Microsoft Intune for mobile device management. They want to ensure that only compliant devices can access Exchange Online. Which technology should they use?

A.Mobile Application Management (MAM) policies
B.Intune compliance policies without Conditional Access
C.Azure AD join with automatic enrollment
D.Conditional Access policies with device compliance
AnswerD

Conditional Access policies with device compliance evaluate real-time signals from Microsoft Intune, so Exchange Online access is granted only when a device meets your compliance rules. This directly satisfies the stem's requirement that only compliant devices reach Exchange Online, enforcing access at authentication rather than relying on static, per-device configuration.

Why this answer

Conditional Access policies with device compliance (Option D) is the correct technology because it integrates Intune compliance policies with Azure AD Conditional Access to enforce access controls on Exchange Online. When a device is marked non-compliant by Intune, Conditional Access blocks or restricts access to Exchange Online, ensuring only compliant devices can connect. This is the standard Microsoft approach for combining device management with identity-driven access control.

Exam trap

The trap here is that candidates often confuse Intune compliance policies alone with Conditional Access, thinking that marking a device non-compliant automatically blocks access, when in fact a Conditional Access policy is required to enforce the block.

How to eliminate wrong answers

Option A is wrong because Mobile Application Management (MAM) policies control app-level data protection and do not evaluate device compliance; they apply to apps regardless of device enrollment status. Option B is wrong because Intune compliance policies alone cannot block access to Exchange Online; they require a Conditional Access policy to enforce the compliance state. Option C is wrong because Azure AD join with automatic enrollment handles device registration and enrollment into Intune but does not enforce access restrictions based on compliance; it is a prerequisite, not the enforcement mechanism.

447
MCQmedium

You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?

A.Enable automatic MDM enrollment in Microsoft Entra ID and configure dynamic device groups in Microsoft Intune.
B.Create a conditional access policy requiring compliant devices and assign it to all users.
C.Deploy a Windows Autopilot deployment profile to all devices and use it to assign policies.
D.Configure a device compliance policy with a grace period and assign it to All Users.
AnswerA

Automatic MDM enrollment in Microsoft Entra ID ensures that any device joined to Entra ID is automatically enrolled in Intune without user action. Dynamic device groups based on attributes like deviceOSType or enrollmentProfileName allow policies to target devices automatically. This meets the requirement for zero-touch provisioning and grouping.

Why this answer

Automatic MDM enrollment in Microsoft Entra ID ensures devices are enrolled in Intune upon join. Dynamic device groups in Intune automatically include devices based on attributes, enabling policy assignment without manual intervention. Together, they provide the required zero-touch provisioning and grouping.

Exam trap

The trap here is confusing compliance policies or conditional access with enrollment mechanisms, assuming they automatically enroll devices.

448
MCQhard

You manage Windows 11 devices with Microsoft Intune. You need to configure a policy that will automatically lock the screen after 5 minutes of inactivity and require a password to unlock. Which policy type should you use?

A.Endpoint protection profile with 'Local device security options'
B.Group Policy analytics profile
C.Device restrictions configuration profile
D.Compliance policy with 'Require a password to unlock mobile devices'
AnswerA

The Endpoint protection profile includes 'Local device security options' where you can configure interactive logon: Machine inactivity limit to 300 seconds (5 minutes) and require password on wakeup. This directly meets the requirement with precise control over screen lock timeout and password enforcement.

Why this answer

The Endpoint protection profile in Intune includes 'Local device security options' which allow you to configure the machine inactivity limit (screen lock timeout) and require a password on wakeup. Setting the inactivity limit to 300 seconds enforces a 5-minute lock, and the password requirement ensures unlock security. This is the most direct and supported method.

Exam trap

The trap here is assuming that a compliance policy can enforce settings; compliance policies only assess, while configuration profiles like Endpoint protection enforce.

449
MCQeasy

You need to make a web app available to users in your organization through Microsoft Intune Company Portal. Which app type should you create in Intune?

A.iOS store app
B.Web app
C.Windows app (Win32)
D.Android store app
AnswerB

A web app type creates a shortcut in the Company Portal that launches the URL in the device browser, requiring no packaging or installation. This satisfies the requirement to publish a web app to users through the portal.

Why this answer

To make a web app available through Microsoft Intune Company Portal, you must create a 'Web app' type. This app type allows you to add a link to a web application that users can access via the Company Portal, without needing to install a native client. Intune's Web app type supports both HTTP and HTTPS URLs and can be configured with a display name, URL, and icon for the Company Portal listing.

Exam trap

The trap here is that candidates may confuse 'Web app' with other app types like 'Windows app (Win32)' or 'iOS store app', thinking they need to wrap a web app in a native installer, when Intune's Web app type is specifically designed for this purpose.

How to eliminate wrong answers

Option A is wrong because an iOS store app is designed for iOS devices and requires a native app package from the Apple App Store, not a web app. Option C is wrong because a Windows app (Win32) is used for deploying traditional desktop applications via .msi or .exe files, not for making a web app available. Option D is wrong because an Android store app is for native Android applications distributed through the Google Play Store, not for web-based apps.

450
MCQhard

You are deploying Windows 11 devices using Windows Autopilot. The devices must be joined to an on-premises Active Directory domain and also registered with Microsoft Entra ID. You need to configure the deployment profile. Which Autopilot mode should you use?

A.Microsoft Entra joined
B.Pre-provisioning (white glove)
C.Microsoft Entra hybrid joined
D.Self-deploying mode
AnswerC

Microsoft Entra hybrid joined mode joins devices to both on-premises Active Directory and Microsoft Entra ID. This is the correct choice when devices must be domain-joined and also registered with Microsoft Entra ID. It requires configuration of the Intune Connector for Active Directory and a domain join configuration profile.

Why this answer

Microsoft Entra hybrid joined mode is specifically designed for scenarios where devices need to be joined to on-premises Active Directory and registered with Microsoft Entra ID. This mode supports domain join during Autopilot and requires the Intune Connector for Active Directory to create computer objects in AD. It enables both cloud and on-premises management.

Exam trap

The trap here is selecting pre-provisioning as a join mode, when it is actually a deployment technique that can be used with different join types.

Page 5

Page 6 of 8

Page 7

All pages