Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 451–525

556 questions total · 8pages · All types, answers revealed

Page 6

Page 7 of 8

Page 8
451
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?

A.Configure a Group Policy to auto-enroll devices into Intune
B.Configure a device enrollment manager (DEM) account
C.Configure Windows Autopilot self-deploying mode and an Enrollment Status Page profile
D.Configure co-management with Microsoft Configuration Manager
AnswerC

Windows Autopilot self-deploying mode enrols devices with no user credentials, satisfying the zero-touch requirement, since it authenticates via the device's TPM-attested identity rather than an interactive sign-in. Pairing it with an Enrollment Status Page profile blocks device use until assigned required apps install, meeting the stem's gating constraint.

Why this answer

Windows Autopilot self-deploying mode enrolls devices into Intune with zero user interaction — the device authenticates using its TPM-attested hardware identity, so no credentials are entered. Pairing it with an Enrollment Status Page (ESP) profile blocks the device from being used until required apps and policies are applied, which is exactly what the scenario requires.

Exam trap

MD-102 often tests the confusion between DEM accounts (bulk enrollment with sign-in) and Autopilot self-deploying mode (truly unattended, TPM-based), causing candidates to pick DEM for zero-touch scenarios.

How to eliminate wrong answers

Option A is wrong because Group Policy auto-enrollment still requires a user to sign in with a work account to trigger MDM enrollment, so it is not zero-touch. Option B is wrong because a DEM account is used to enroll many devices with a single account and still requires interactive sign-in; it also has a 1,000-device limit and is not designed for unattended self-deploying scenarios. Option D is wrong because co-management with Configuration Manager is about workload sharing between Intune and ConfigMgr, not about zero-touch enrollment or blocking device use via ESP.

452
MCQhard

An administrator is troubleshooting why a Win32 app is repeatedly installed on a device. The exhibit shows a log snippet. What is the most likely cause of the repeated installation?

A.The app writes the detection file to a temporary folder that is cleaned periodically
B.The app requires a reboot to complete installation
C.The detection rule runs before the install completes
D.The exit code 0 is misinterpreted as failure
AnswerA

Intune's Win32 detection rules re-evaluate the detection file on each check-in. Because the file sits in a temporary folder that is periodically cleaned, the rule never finds it, so the app is reinstalled repeatedly. A stable, non-volatile detection path would satisfy the detection constraint.

Why this answer

If the Win32 app's detection file is written to a temporary folder (e.g., %TEMP% or C:\Windows\Temp) that is periodically cleaned by disk cleanup policies or the Storage Sense feature, Intune will no longer detect the app as installed after the file is removed. This causes the Microsoft Intune Management Extension to re-run the installation on the next sync cycle, leading to a repeated installation loop. The detection rule relies on the persistent presence of the file, so its removal triggers reinstallation.

Exam trap

The trap here is that candidates assume a detection rule failure is due to timing (Option C) or exit code issues (Option D), but the real-world cause is often a transient detection artifact that gets cleaned, not a logic error in the installation process.

How to eliminate wrong answers

Option B is wrong because a required reboot does not cause repeated installation; Intune marks the app as installed after the exit code 0 is received, and a pending reboot only delays further actions, not reinstallation. Option C is wrong because the detection rule runs after the installation script completes and returns an exit code, not before; the log snippet would show a detection failure only after the install attempt finishes. Option D is wrong because exit code 0 is universally interpreted as success by Intune's Win32 app management; a misinterpretation would require a custom detection rule or a non-standard exit code mapping, which is not indicated.

453
MCQhard

You manage a set of Windows 11 devices with Microsoft Intune. You deploy a Win32 app as required to a group of users. The app installs successfully, but later users report that the app is missing from their devices. You discover that the app was removed after a user uninstalled it manually. You need to ensure that the app is reinstalled automatically if it is removed. What should you configure?

A.Set the app assignment to Available and instruct users to install it from the Company Portal.
B.Set the app assignment to Required and enable the 'Restart required' option.
C.Create a compliance policy that marks devices without the app as non-compliant.
D.Set the app assignment to Required and configure a detection rule that checks for the app's presence.
AnswerD

Intune uses detection rules to determine if an app is installed. When an app is assigned as required, Intune periodically evaluates the detection rule. If the app is not detected, Intune reinstalls it. By ensuring a proper detection rule is configured, you enable Intune to detect the app's absence and automatically reinstall it, thus enforcing the required state. This is the correct method to ensure the app is reinstalled if removed.

Why this answer

For required Win32 apps, Intune relies on detection rules to verify installation status. When the detection rule indicates the app is not present, Intune will reinstall it. This enforcement happens periodically, ensuring the app remains installed even if a user removes it.

Configuring a detection rule that accurately reflects the app's presence is essential for automatic reinstallation.

Exam trap

The trap here is assuming that a required assignment alone guarantees reinstallation, when in fact a properly configured detection rule is what triggers Intune to detect and reinstall the missing app.

454
Multi-Selecteasy

You need to configure Microsoft Defender for Endpoint on macOS devices. Which THREE components must be installed?

Select 3 answers
A.Microsoft Defender for Endpoint daemon
B.Microsoft Intune management extension
C.Configuration Manager client
D.Microsoft Defender for Endpoint kernel extension (or system extension)
E.Microsoft Defender for Endpoint user interface agent
AnswersA, D, E

The Microsoft Defender for Endpoint daemon provides the background scanning and protection service that macOS requires, satisfying the stem's demand for a mandatory component. Without this persistent service, real-time threat detection cannot run on the device, so it must be installed alongside the network extension and the application itself.

Why this answer

Microsoft Defender for Endpoint on macOS requires three core components: the Microsoft Defender for Endpoint daemon (wdavdaemon) (option A), which runs as a background service handling real-time protection, scanning, and communication with the cloud service; the Microsoft Defender for Endpoint kernel extension or system extension (option D), which provides the low-level hooks needed for file system monitoring and network protection on macOS; and the Microsoft Defender for Endpoint user interface agent (option E), which presents the menu bar app and notifications to the user. The Intune management extension (option B) is a Windows component used for PowerShell scripts and Win32 apps, not a Defender for Endpoint macOS requirement, and the Configuration Manager client (option C) is a Windows management agent that is not installed on macOS for this purpose.

Exam trap

The trap here is that candidates often confuse the macOS Defender components with Windows Defender components, mistakenly including Intune or ConfigMgr agents that are irrelevant to macOS deployments.

455
Multi-Selectmedium

You are troubleshooting an Intune-managed Windows 10 device that is not receiving a required application. Which THREE steps should you take to diagnose the issue? (Choose three.)

Select 3 answers
A.Ensure the device has network connectivity
B.Review the app requirement rules (e.g., OS version)
C.Check the app assignment status in the Intune console
D.Verify the device is compliant with compliance policies
E.Perform a factory reset on the device
AnswersA, B, C

Without network connectivity the device cannot reach Intune or the content delivery service to download the app. Verifying connectivity confirms the device can actually receive policy and app payloads, ruling out a fundamental delivery blocker first.

Why this answer

Option A is correct because an Intune-managed Windows 10 device must have network connectivity to reach the Intune service (and the Microsoft Store/CDN or Win32 app content source), otherwise it cannot download policies or the required application. Option B is correct because Intune app requirement rules (such as OS version, architecture, or minimum OS) are evaluated before delivery; if the device fails a rule, the app will not be offered or installed. Option C is correct because checking the app assignment status in the Intune console shows whether the app is targeted to the user/device group and whether the assignment is required, available, or uninstall, which directly explains why the app is not being received.

Option D is not correct because compliance policies govern conditional access and device health, not app delivery; a noncompliant device can still receive required apps. Option E is not correct because a factory reset is a drastic remediation step, not a diagnostic step, and it would not identify the root cause.

Exam trap

The trap here is confusing compliance policies with app delivery prerequisites; candidates often assume a non-compliant device cannot receive any apps, but Intune separates compliance from app assignment unless conditional access is explicitly configured.

456
MCQhard

You are the administrator for a company that uses Microsoft Intune. You need to deploy a Windows 10 device configuration profile that configures a custom administrative template setting. The setting is not available in the built-in templates. You have the ADMX and ADML files for the setting. What should you do first?

A.Import the ADMX and ADML files into Intune
B.Convert the ADMX files to XML and import them as a custom compliance policy
C.Create a custom configuration profile using OMA-URI
D.Upload the ADMX files to a file share and reference them in a PowerShell script
AnswerA

To configure custom administrative template settings that are not built into Intune, you must first import the ADMX and ADML files. Intune allows you to upload custom ADMX files, which then make the corresponding settings available in the administrative templates profile. This is a prerequisite before you can create a profile that uses those settings.

Why this answer

Intune supports importing custom ADMX and ADML files to extend the administrative templates. After importing, the custom settings become available in the administrative templates profile, allowing you to configure them. Other methods like OMA-URI or scripts are not the correct first step when ADMX files are provided.

Exam trap

The trap here is choosing OMA-URI because it is a common method for custom settings, but when ADMX files are available, importing them is the intended approach.

457
MCQeasy

You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?

A.Set the install context to system.
B.Set the install context to user.
C.Assign the app as required for all users.
D.Use a line-of-business app type instead.
AnswerA

Setting the install context to system runs the app's installer under the local SYSTEM account, which already holds full administrative rights on the device. This satisfies the stem's requirement that the Win32 app needs admin privileges to install, avoiding any user-context elevation prompt during Intune deployment.

Why this answer

Setting the install context to 'system' runs the Win32 app installer with the SYSTEM account, which has the highest privileges on a Windows device. This ensures the installer can perform actions requiring admin rights, such as writing to Program Files or modifying system registry keys, without user interaction or credential prompts. In Intune, the system context is the only way to silently deploy apps that demand elevated permissions.

Exam trap

The trap here is that candidates often confuse 'install context' with 'assignment scope' (required vs. available), mistakenly thinking that marking an app as 'required for all users' automatically grants admin privileges, when in fact the install context must be explicitly set to 'system' for elevated installations.

How to eliminate wrong answers

Option B is wrong because setting the install context to 'user' runs the installer under the logged-on user's account, which lacks admin privileges unless the user is a local administrator, and it cannot perform system-level changes silently. Option C is wrong because assigning the app as required for all users does not change the install context; it only controls targeting, and if the install context is set to user, the app will still fail to install for non-admin users. Option D is wrong because using a line-of-business (LOB) app type does not inherently provide admin privileges; LOB apps are typically for single-file installers (e.g., .msi or .intunewin) and still require the correct install context to be set to system for elevated installations.

458
MCQhard

Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?

A.bitLockerEncryptionMethod set to aes256
B.passwordRequired set to true
C.bitLockerDisableWarningForOtherDiskEncryption set to false
D.bitLockerDisableWarningForOtherDiskEncryption set to true
AnswerC

When false, the warning is shown and BitLocker will not enable if other encryption exists.

Why this answer

Setting bitLockerDisableWarningForOtherDiskEncryption to false means that BitLocker will display a warning and block enabling BitLocker if another disk encryption method (such as third-party encryption) is detected on the drive. This setting enforces the requirement to prevent users from enabling BitLocker when another encryption solution is already active, ensuring compliance and avoiding conflicts.

Exam trap

The trap here is that candidates often confuse bitLockerDisableWarningForOtherDiskEncryption with a simple warning toggle, not realizing that setting it to false actively blocks BitLocker enablement when other encryption is detected, while setting it to true allows BitLocker to proceed without warning.

How to eliminate wrong answers

Option A is wrong because bitLockerEncryptionMethod set to aes256 only specifies the encryption algorithm to use (AES-256) when BitLocker is enabled; it does not control whether BitLocker can be enabled if another encryption method is already present. Option B is wrong because passwordRequired set to true mandates that a recovery password be configured for BitLocker, but it does not affect the detection or blocking of other disk encryption methods. Option D is wrong because setting bitLockerDisableWarningForOtherDiskEncryption to true would suppress the warning and allow BitLocker to be enabled even if another encryption method is in use, which is the opposite of the desired behavior.

459
MCQeasy

Your organization uses Microsoft Intune to manage Android devices. You need to ensure that corporate data on these devices is protected in case the device is lost or stolen. You configure a compliance policy that requires device encryption and a device lock screen. However, you also want to be able to selectively wipe corporate data without wiping personal data. What should you do?

A.Enable remote lock on the device.
B.Configure a device compliance policy to wipe the device if non-compliant.
C.Use a device configuration profile to enable selective wipe.
D.Assign an app protection policy to the user for the corporate apps.
AnswerD

App protection policies apply at the application layer, enforcing encryption and access controls on corporate data within managed apps. This enables selective wipe of corporate data from those apps while leaving personal data on the device untouched, which device-level compliance policies cannot achieve.

Why this answer

App protection policies (APP) in Microsoft Intune provide the ability to selectively wipe corporate data from managed apps without affecting personal data on Android devices. This is achieved through the selective wipe action, which removes only the organization's data from apps that have the policy applied, leaving personal data intact. Compliance policies, as described in the scenario, enforce device-level settings like encryption and lock screen but do not offer granular data separation for selective wipe.

Exam trap

The trap here is that candidates often confuse device compliance policies (which enforce device-level security and can trigger full wipe) with app protection policies (which enable selective wipe of corporate data), leading them to choose option B or C instead of D.

How to eliminate wrong answers

Option A is wrong because remote lock only locks the device remotely, preventing unauthorized access but does not wipe any data, corporate or personal. Option B is wrong because configuring a device compliance policy to wipe the device if non-compliant performs a full device wipe, removing all data including personal data, which contradicts the requirement to selectively wipe only corporate data. Option C is wrong because device configuration profiles in Intune manage device settings (e.g., Wi-Fi, VPN, restrictions) and do not include a selective wipe capability; selective wipe is a feature of app protection policies, not configuration profiles.

460
MCQmedium

Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?

A.Add the device to Microsoft Entra ID before shipping.
B.Obtain the hardware hash from the device manufacturer or reseller.
C.Use Microsoft Configuration Manager to collect the hardware hash.
D.Run a PowerShell script on each device to capture the hardware hash.
AnswerB

Capturing the hardware hash at the manufacturer or reseller lets it be uploaded to Microsoft Intune before shipping, so devices enrol automatically on first boot. Manual hash collection after delivery would delay provisioning and break the pre-shipment requirement.

Why this answer

The hardware hash can be obtained from the device manufacturer or reseller (OEM) before the device is shipped. This is the recommended approach for new devices as it allows the hardware hash to be uploaded to Intune without needing to power on the device. Option A is wrong because adding the device to Microsoft Entra ID does not upload the hardware hash.

Option C is wrong because Configuration Manager can collect hashes but requires the device to be on the network and is typically used for existing devices. Option D is wrong because running a PowerShell script on each device requires the device to be powered on and manually executed, which is less efficient for new devices.

461
Multi-Selecteasy

Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)

Select 2 answers
A.Devices enrolled in Microsoft Intune
B.Configuration Manager current branch
C.On-premises Active Directory
D.Public Key Infrastructure (PKI)
E.Hybrid Microsoft Entra ID joined devices
AnswersA, B

Co-management requires the device to be enrolled in Microsoft Intune so the Intune service can receive policy and workload data alongside Configuration Manager. Without this enrolment, the Configuration Manager client alone cannot hand over workloads, so enrolment satisfies the stated prerequisite.

Why this answer

Option A is correct because co-management requires that the Windows devices be enrolled in Microsoft Intune, which provides the MDM authority and the Intune workloads that Configuration Manager can hand over. Option B is correct because co-management is a feature of Configuration Manager current branch (version 1710 or later), so the site must be running a supported current branch release. Option C is not required because co-management works with Microsoft Entra ID (Azure AD) joined, hybrid joined, or even domain-joined devices, and on-premises Active Directory is not a prerequisite.

Option D is not required because PKI certificates are only needed for specific scenarios such as HTTPS management or PKI-based authentication, not for enabling co-management itself. Option E is not required because hybrid Microsoft Entra ID joined devices are one supported device identity type, but co-management also supports Microsoft Entra ID joined and domain-joined devices, so hybrid join is not mandatory.

Exam trap

The trap is that candidates may think hybrid Azure AD join is mandatory for co-management, but both hybrid and pure Azure AD join are supported. They may also overlook that Configuration Manager current branch is a prerequisite, not just an optional upgrade.

462
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that devices cannot access corporate email if they are rooted. What should you configure?

A.A device compliance policy with the 'Rooted devices' setting set to 'Block'.
B.An app protection policy that blocks jailbroken devices.
C.A Conditional Access policy that requires a compliant device.
D.A device configuration profile that disables USB debugging.
AnswerA

In an Intune compliance policy for Android Enterprise, the 'Rooted devices' setting can be set to 'Block'. When a device is detected as rooted, it is marked non-compliant. You can then use Conditional Access to block access to corporate email and other resources. This directly enforces the requirement.

Why this answer

To block rooted Android devices from accessing corporate email, you need a compliance policy that marks rooted devices as non-compliant. Then, a Conditional Access policy can enforce compliance for email access. The compliance policy setting 'Rooted devices' set to 'Block' is the key configuration.

Exam trap

The trap here is thinking that Conditional Access alone can detect rooted devices; it relies on compliance signals.

463
MCQeasy

You are deploying a line-of-business (LOB) app to iOS devices using Microsoft Intune. The app is signed with an enterprise certificate. Users report that the app installs but crashes immediately on launch. What is the most likely cause?

A.The Intune company portal app is not installed.
B.The app is not signed.
C.The app requires a VPN connection.
D.The enterprise developer certificate is not trusted on the device.
AnswerD

An untrusted enterprise signing certificate causes iOS to block code execution at launch, so the app installs but terminates immediately. Trusting the certificate under Settings > General > VPN & Device Management resolves this. This satisfies the stem's constraint: the app is enterprise-signed, and iOS enforces certificate trust before allowing the binary to run.

Why this answer

The most likely cause is that the enterprise developer certificate is not trusted on the device. iOS requires that enterprise-signed apps have their root certificate manually trusted via a profile (e.g., MDM or manual installation) before the app can run. Without this trust, iOS blocks the app from executing, causing an immediate crash on launch.

Exam trap

The trap here is that candidates may confuse 'signed' with 'trusted' — the app is signed, but iOS requires explicit trust of the enterprise certificate, which is a separate step often overlooked in MDM deployments.

How to eliminate wrong answers

Option A is wrong because the Company Portal app is not required for LOB app installation via MDM; Intune can push apps directly using Apple Push Notification service (APNs) and managed Open In. Option B is wrong because the app is explicitly stated to be signed with an enterprise certificate, so it is signed; the issue is trust, not signature absence. Option C is wrong because a VPN connection is not a prerequisite for launching an LOB app; VPN requirements are app-specific and would not cause an immediate crash on launch.

464
MCQeasy

You manage devices in Microsoft Intune. You need to generate a report that shows which devices have not checked in with Intune for more than 30 days. What should you use?

A.Device compliance report
B.Windows Update report
C.Device configuration report
D.Devices without recent check-in report
AnswerD

Intune provides a built-in report called 'Devices without recent check-in' that lists devices that have not communicated with the service within a specified number of days. This report directly answers the requirement to find devices inactive for more than 30 days.

Why this answer

The 'Devices without recent check-in' report in Intune is designed to list devices that have not communicated with the service within a specified period. It allows you to filter by number of days, making it the correct tool to identify devices inactive for more than 30 days.

Exam trap

The trap here is assuming that any device report includes check-in data, or confusing compliance reports with check-in reports.

465
MCQeasy

A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?

A.App protection policy
B.Enrollment restriction
C.Device configuration policy
D.Device compliance policy
AnswerD

A device compliance policy defines passcode requirements, including minimum length, and marks devices non-compliant when unmet. Conditional Access then blocks corporate email access for non-compliant iOS devices, directly satisfying the six-character passcode constraint. Configuration profiles merely enforce settings without gating access, so they cannot restrict email by compliance state.

Why this answer

A device compliance policy in Intune defines the rules a device must meet to be considered compliant, including passcode requirements like minimum length. Conditional Access policies then use compliance state to gate access to corporate email. This is the correct mechanism because compliance policies evaluate device state and report back to Intune, which Conditional Access queries.

Exam trap

MD-102 often tests the distinction between configuration policies (which push settings) and compliance policies (which evaluate state for Conditional Access) — candidates frequently pick configuration when the scenario requires access gating.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) protect app data with PINs at the app level, not device-level passcode enforcement for email access. Option B is wrong because enrollment restrictions control which devices can enroll (by platform, OS version, manufacturer), not post-enrollment passcode requirements. Option C is wrong because device configuration policies push settings to devices but do not evaluate compliance state for Conditional Access — they configure, they don't assess.

466
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?

A.Create a device configuration profile in Intune and use a scope tag to target only the co-managed devices.
B.Create a device configuration profile in Intune and assign it to a user group that contains users of the co-managed devices.
C.Create a device configuration profile in Intune and assign it to a device group that contains only the co-managed devices.
D.Create a device configuration profile in Intune and configure the "Configuration Manager Compliance" setting to require co-management.
AnswerC

In Intune, you can assign a device configuration profile to a specific device group. By creating a group that contains only the co-managed devices, you ensure the profile applies only to them. This is the simplest and most direct method. It does not require any additional filtering or complex configuration, and it works regardless of the workload settings, as long as the devices are in the group.

Why this answer

The most straightforward way to target a configuration profile to a specific set of devices is to assign it to a device group containing those devices. Creating a group with only the co-managed devices and assigning the profile to that group ensures the policy applies exclusively to them. Other methods like scope tags or user groups do not provide the same precise device targeting.

Exam trap

The trap here is assuming that scope tags can be used to target policies to specific devices, when in fact they are for administrative scoping, not device targeting.

467
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a Microsoft 365 Apps for Enterprise to work profiles. Which app type should you select in Intune?

A.Web app
B.Android Enterprise system app
C.Line-of-business app
D.Managed Google Play app
AnswerD

Microsoft 365 Apps for Enterprise is published through Managed Google Play, so Intune deploys it to Android Enterprise work profiles as a Managed Google Play app type. This is the only supported app type for that scenario.

Why this answer

For deploying Microsoft 365 Apps for Enterprise to Android Enterprise work profiles, the correct app type is Managed Google Play app. Intune integrates with Managed Google Play to distribute approved apps to work profiles, ensuring compliance with Android Enterprise policies. Web apps, system apps, and line-of-business apps cannot deliver the full Microsoft 365 suite with managed configuration and app protection policies in a work profile context.

Exam trap

The trap here is that candidates may confuse 'Line-of-business app' with any business app, but Microsoft 365 Apps for Enterprise is a commercially available app that must be distributed via Managed Google Play, not uploaded as a custom package.

How to eliminate wrong answers

Option A is wrong because a Web app only provides a shortcut to a URL and cannot install native Microsoft 365 apps with offline capabilities or managed app configuration. Option B is wrong because Android Enterprise system apps are pre-installed system components, not third-party apps like Microsoft 365, and cannot be deployed via Intune for work profiles. Option C is wrong because a Line-of-business app is used for custom internal apps uploaded directly to Intune, not for commercially available apps like Microsoft 365 that must be sourced from Managed Google Play.

468
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You deploy a Win32 app as required to a group of users. After deployment, users report the app shortcut is missing from the Start menu even though the app appears installed in the Company Portal. You review the app properties and confirm the install command succeeded. You need to ensure the shortcut appears for all users on each device. What should you configure?

A.Set the app to install in system context and add a requirement rule for the Windows 11 operating system.
B.Add a detection rule that checks for the shortcut file in the public Start menu path.
C.Configure the app to install in user context and assign it to the device group.
D.Package the app so the installer writes the shortcut to the all-users Start menu location, and deploy the app in system context.
AnswerD

Shortcuts visible to every user must reside in the common Start menu path, typically under ProgramData\Microsoft\Windows\Start Menu\Programs. Installing in system context allows the installer to write to that machine-wide location. Ensuring the package itself creates the shortcut there, rather than only in the installing user's profile, guarantees all users on the device see it, which matches the requirement.

Why this answer

Start menu shortcut visibility depends on where the shortcut file is written. Per-user locations only show for the installing account, while the common Start menu path is visible to everyone. Combining a package that targets the common path with system-context installation ensures the shortcut is present for all users on the device, resolving the reported symptom.

Exam trap

The trap here is treating detection rules or assignment scope as the cause of missing shortcuts, when shortcut visibility is determined by the installation context and the folder the installer writes to.

469
MCQmedium

Refer to the exhibit. You create a compliance policy for Windows 10 devices. A device is reported as non-compliant. Upon investigation, you find that the device has a password of 6 characters. Which setting is causing the non-compliance?

A.requireCodeIntegrity
B.passwordMinimumLength
C.requireDeviceEncryption
D.requireSecureBoot
AnswerB

The compliance policy's passwordMinimumLength setting enforces a minimum character count, and the device's six-character password falls below the configured threshold, triggering non-compliance. This directly matches the stem's reported condition, where the password length is the sole identified deviation from policy requirements.

Why this answer

The compliance policy requires a minimum password length, and the device's 6-character password does not meet that requirement, making it non-compliant. The passwordMinimumLength setting directly controls the minimum number of characters a password must have, so a password shorter than the configured value triggers non-compliance.

Exam trap

The trap here is that candidates often confuse passwordMinimumLength with password complexity or other security settings like requireCodeIntegrity or requireSecureBoot, assuming any security-related non-compliance must be due to a broader security feature rather than the specific password length.

How to eliminate wrong answers

Option A is wrong because requireCodeIntegrity enforces that code integrity features (like Windows Defender Application Control) are enabled, which is unrelated to password length. Option C is wrong because requireDeviceEncryption mandates BitLocker or device encryption, not password length. Option D is wrong because requireSecureBoot checks that Secure Boot is enabled in UEFI, which is a hardware security feature, not a password policy.

470
MCQmedium

You are reviewing an Intune endpoint protection profile for Windows 10. The exhibit shows a JSON snippet of the configuration. A user reports that a device detected malware with moderate severity, but the action taken was 'quarantine'. However, the desired action is 'clean'. Which setting should you modify?

A.defenderScheduleScanDay and defenderScheduleScanTime
B.A global setting to override all actions
C.defenderScanType
D.defenderDetectedMalwareActions for moderateSeverity
AnswerD

Modifying defenderDetectedMalwareActions for moderateSeverity directly controls the remediation action applied when Windows Defender Antivirus detects moderate-severity malware. The stem's constraint is that quarantine was applied instead of clean, so aligning this severity-specific action with the desired clean behaviour resolves the mismatch without affecting low, high, or severe thresholds.

Why this answer

The `defenderDetectedMalwareActions` setting in Intune endpoint protection profiles allows you to specify the remediation action for each threat severity level, including moderate. Since the user wants 'clean' instead of 'quarantine' for moderate severity threats, you must modify the `moderateSeverity` value within this setting. This is the only setting that controls per-severity remediation actions for Microsoft Defender Antivirus.

Exam trap

The trap here is that candidates confuse scan scheduling or scan type settings with remediation actions, or assume a single global action exists, when Microsoft Intune requires per-severity configuration via `defenderDetectedMalwareActions`.

How to eliminate wrong answers

Option A is wrong because `defenderScheduleScanDay` and `defenderScheduleScanTime` control when scheduled scans run, not the action taken on detected malware. Option B is wrong because there is no global override setting in Intune endpoint protection profiles that applies a single action to all threat severities; remediation actions are configured per severity level. Option C is wrong because `defenderScanType` defines the type of scan (e.g., quick, full) to perform, not the remediation action after detection.

471
Multi-Selectmedium

Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)

Select 2 answers
A.Create a device compliance policy that includes health attestation checks
B.Configure Intune enrollment
C.Use Windows Autopilot to pre-provision devices
D.Deploy an app protection policy to M365 apps
E.Create a Conditional Access policy that requires compliant device
AnswersA, E

Health attestation in a Microsoft Entra ID compliance policy reports TPM-measured boot state, verifying Secure Boot, BitLocker and code integrity before granting access. This satisfies the stem's requirement that only healthy devices reach Microsoft 365 services, since non-compliant devices are blocked by Conditional Access.

Why this answer

Option A is correct because a device compliance policy in Microsoft Intune can include health attestation checks (e.g., BitLocker, Secure Boot, TPM, and code integrity via the Health Attestation Service), which determine whether a Windows 10/11 device meets the health and security baseline required to be marked compliant. Option E is correct because a Conditional Access policy that requires a compliant device enforces the compliance state at authentication time, blocking access to Microsoft 365 services from devices that are not marked compliant by Intune. Together, A defines what 'healthy' means and E enforces it for M365 access.

Option B is not correct on its own because Intune enrollment is a prerequisite for compliance evaluation but does not itself ensure only healthy devices can access M365 services. Option C is not correct because Windows Autopilot only pre-provisions and configures devices; it does not gate access based on device health. Option D is not correct because app protection policies (MAM) protect app data on unmanaged or managed devices but do not enforce device health attestation for M365 service access.

Exam trap

The trap here is that candidates confuse device enrollment (Option B) or provisioning (Option C) with ongoing health verification, but neither ensures the device remains healthy at the time of access; only the combination of a compliance policy with attestation checks and a Conditional Access policy that requires compliant device enforces this at authentication time.

472
Multi-Selectmedium

Which TWO actions should you take to prepare a Windows 10 device for a deployment using Windows Autopilot?

Select 2 answers
A.Join the device to Microsoft Entra ID manually.
B.Ensure the device has an internet connection during the out-of-box experience.
C.Enable BitLocker encryption on the device.
D.Upgrade the device to the latest Windows 10 version.
E.Collect the hardware hash of the device.
AnswersB, E

An internet connection during the out-of-box experience lets the device contact the Autopilot deployment service, download its assigned profile, and enrol into Microsoft Entra ID. Without connectivity at OOBE, profile retrieval fails and the device cannot complete the cloud-driven provisioning sequence.

Why this answer

Option B is correct because Windows Autopilot relies on the device contacting Microsoft's cloud services (Intune and the Autopilot deployment service) during the out-of-box experience (OOBE) to download the deployment profile and enroll the device, so a working internet connection at OOBE is mandatory. Option E is correct because the device's hardware hash (a unique hardware identifier) must be captured and uploaded to Intune to register the device in the Windows Autopilot device list, which is what allows the Autopilot profile to be matched and applied to that specific device. Option A is not required because Autopilot performs the Microsoft Entra ID join automatically as part of the OOBE flow, so a manual join beforehand would defeat the purpose.

Option C is not required because BitLocker is typically enabled automatically after Autopilot enrollment via Intune policy, not as a preparation step. Option D is not required because Autopilot does not mandate upgrading to the latest Windows 10 version beforehand; the device just needs a supported Windows 10 version that supports Autopilot.

Exam trap

Candidates often assume manual Entra ID join or BitLocker are prerequisites, but Autopilot automates these. The two essential steps are network connectivity during OOBE and collecting the hardware hash for device registration.

473
MCQhard

You are an Endpoint Administrator for a company using Microsoft Intune. A Windows app (Win32) app has been deployed as Required to a pilot group of 20 devices. Reports show the app installed successfully on 18 devices but failed on 2 devices with the error 'The application was not detected after installation completed successfully.' You confirm the installer runs silently and exits with code 0 on the failing devices. What is the most likely cause?

A.The app's requirement rules exclude those two devices because they run an unsupported Windows build.
B.The devices are not enrolled in the Intune Management Extension and therefore cannot run Win32 apps.
C.The install command line for the app is incorrect and causes the installer to silently skip installation.
D.The detection rule configured for the app does not match the state the installer actually produces on those devices.
AnswerD

The error message means Intune ran the installer, saw a success exit code, but then evaluated the detection rule and found no match, so it treats the install as failed. A detection rule that checks the wrong path, registry hive, or version on those devices explains why the same package succeeds elsewhere.

Why this answer

The message 'not detected after installation completed successfully' is generated when the installer returns a success code but the detection rule evaluation finds nothing matching. Because the same package works on other devices, the detection rule is the component that needs correction for the affected devices.

Exam trap

The trap here is focusing on the installer or exit code, when the error text explicitly indicates the install succeeded and only the post-install detection step failed.

474
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company portal app that allows users to enroll their devices. Which app type should you use?

A.Built-in app
B.iOS and macOS store app
C.Web link
D.macOS LOB app
AnswerB

The iOS and macOS store app type deploys the Company Portal from the Apple App Store, which users need to enrol macOS devices into Intune. It satisfies the enrolment requirement because Company Portal is the agent that initiates macOS enrolment.

Why this answer

The Company Portal app for macOS is available in the Apple App Store and is distributed via Intune as an iOS and macOS store app. This app type allows Intune to manage the app installation and assignment from the store, enabling users to enroll their macOS devices into management. Built-in apps are for pre-installed system apps, web links are for shortcuts, and LOB apps are for custom in-house apps, none of which provide the required enrollment functionality.

Exam trap

The trap here is that candidates confuse the 'iOS and macOS store app' type with the 'Built-in app' type, thinking Company Portal is a built-in system app, when in fact it must be downloaded from the App Store and managed as a store app.

How to eliminate wrong answers

Option A is wrong because built-in apps in Intune refer to pre-installed system apps like Safari or Calendar, not the Company Portal, which must be downloaded from the App Store. Option C is wrong because a web link only creates a shortcut to a URL in the Company Portal website, not a native app installation, and macOS device enrollment requires the native Company Portal app. Option D is wrong because a macOS LOB app is used for custom in-house applications uploaded directly to Intune, not for store-sourced apps like Company Portal.

475
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. They have a compliance policy that requires BitLocker to be enabled. Some devices are marked as non-compliant even though BitLocker appears to be on. The administrator runs 'manage-bde -status' on a non-compliant device and sees that the protection status is 'Protection Off'. What is the most likely cause?

A.The BitLocker key protectors are missing or have been removed.
B.The TPM is not initialized.
C.The device has a recovery password protector but no TPM protector.
D.The device uses a different encryption method (e.g., XTS-AES 256 vs AES 128).
AnswerA

BitLocker reports Protection Off when valid key protectors, such as TPM, PIN, or recovery password, are absent or removed, even if the volume was previously encrypted. Intune's compliance policy therefore evaluates BitLocker as not enabled, marking the device non-compliant.

Why this answer

The compliance policy requires BitLocker to be enabled, but 'manage-bde -status' shows 'Protection Off'. This indicates that while the drive is encrypted, BitLocker is not actively protecting the data because the key protectors (such as the TPM protector) are missing or have been removed. Intune checks the protection status, not just encryption state, so when protectors are absent, the device is marked non-compliant.

Exam trap

The trap here is that candidates confuse 'encrypted' with 'protected'—BitLocker can encrypt a drive without active protection if key protectors are missing, and Intune compliance policies specifically require protection to be on, not just encryption to be present.

How to eliminate wrong answers

Option B is wrong because if the TPM were not initialized, BitLocker would typically fail to enable or would show a different status (e.g., 'TPM is not ready'), not 'Protection Off' on an already encrypted drive. Option C is wrong because having a recovery password protector without a TPM protector is a valid configuration (e.g., on devices without TPM) and would still show 'Protection On' if the protector is present and active. Option D is wrong because the encryption method (e.g., XTS-AES 256 vs AES 128) does not affect the protection status; it only determines the algorithm used for encryption, and Intune compliance policies do not check for encryption method mismatch.

476
MCQmedium

You manage 500 Windows 11 devices with Microsoft Intune. Several devices are shared by multiple employees across shifts at a manufacturing plant. You need to configure a policy that automatically removes local user profiles that have not been used for 60 days to conserve disk space, while preserving profiles of users who sign in regularly. What should you configure?

A.A compliance policy that marks devices as noncompliant after 60 days of profile inactivity.
B.An Intune settings catalog policy or custom OMA-URI using the SharedPC CSP with 'InactiveThreshold' set to 60 days.
C.A device restrictions configuration profile with the 'Inactivity timeout' setting configured to 60 days.
D.A Windows 10/11 device restrictions profile with 'Delete inactive user profiles' set to 60 days.
AnswerB

The SharedPC CSP exposes InactiveThreshold, which deletes local profiles not used within the specified number of days. This is the supported Intune mechanism for reclaiming disk space on shared or shift-based devices. It is applied through a settings catalog entry or custom OMA-URI, and it targets the exact behaviour required without affecting active users' profiles.

Why this answer

Shared devices accumulate local profiles over time, and Intune addresses this through the SharedPC CSP, which supports an InactiveThreshold value expressed in days. Configuring this through the settings catalog or a custom OMA-URI deletes dormant profiles automatically while leaving frequently used profiles intact. General device restrictions, compliance policies, and session timeouts do not perform profile cleanup, so they fail to reclaim the disk space consumed by unused accounts.

Exam trap

The trap here is assuming that device restriction or compliance settings include a profile cleanup timer, when in fact only the SharedPC CSP exposes an inactivity threshold that deletes stale local profiles.

477
MCQhard

You are deploying a Windows 11 device using Windows Autopilot. The device is enrolled in Microsoft Intune and assigned a device group. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and enrolls in Intune without user interaction. Which Autopilot deployment mode should you configure?

A.Autopilot reset
B.Self-deploying mode
C.User-driven mode
D.Pre-provisioning mode (White glove)
AnswerB

Self-deploying mode is designed for devices that require no user interaction. During OOBE, the device automatically joins Microsoft Entra ID and enrolls in Intune using the device's hardware hash and an assigned Autopilot profile. This mode is ideal for kiosks, digital signage, or shared devices where no user credentials are available or desired.

Why this answer

Self-deploying mode in Windows Autopilot enables a device to join Microsoft Entra ID and enroll in Intune automatically during OOBE, without any user interaction. It is the correct choice when zero-touch provisioning is required and no user credentials are available.

Exam trap

The trap here is assuming that pre-provisioning mode provides fully automated enrollment, when it still requires a user to complete the final OOBE steps.

478
MCQmedium

You are the endpoint administrator for Contoso, Ltd. The company uses Microsoft Intune and has a hybrid Microsoft Entra ID environment with an on-premises Active Directory Domain Services (AD DS) domain. You plan to deploy 200 new Windows 11 devices using Windows Autopilot. The devices must be joined to the on-premises AD DS domain and also registered in Microsoft Entra ID. You need to configure the Autopilot deployment profile to support this scenario. What should you do first?

A.Assign the Autopilot deployment profile to a user group and configure the profile to use "User-driven" mode.
B.Create an Autopilot deployment profile with the "Convert all targeted devices to Autopilot" option enabled.
C.Configure the deployment profile to use Microsoft Entra join and assign the profile to a device group.
D.Configure the deployment profile to use Microsoft Entra hybrid join and ensure the device has a line of sight to a domain controller.
AnswerD

Microsoft Entra hybrid join requires the device to authenticate against an on-premises domain controller during the offline domain join process. A line of sight is essential. Configuring the profile for hybrid join is the correct first step because it enables the device to be joined to AD DS and registered in Microsoft Entra ID simultaneously. Without this setting, the device would only be Microsoft Entra joined, not hybrid joined.

Why this answer

For Windows Autopilot hybrid Microsoft Entra join, the deployment profile must be configured to use Microsoft Entra hybrid join, and the device must have network connectivity to a domain controller during deployment. This allows the device to be joined to on-premises AD DS and registered in Microsoft Entra ID. Simply assigning the profile or using user-driven mode without the hybrid join setting does not meet the requirement.

Exam trap

The trap here is assuming that assigning an Autopilot profile to a user group automatically configures hybrid join, when in fact the join type must be explicitly set in the deployment profile.

479
Multi-Selecteasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. Which TWO configurations are required?

Select 2 answers
A.The user must have a Google account
B.The device must be personally owned
C.The device must be enrolled using Android Enterprise work profile
D.The app must be approved in the managed Google Play store
E.The app must be configured as a kiosk app
AnswersC, D

Required for managed Google Play apps.

Why this answer

Option C is correct because deploying a managed Google Play app to work profile devices requires the device to be enrolled with the Android Enterprise work profile enrollment type, which creates the separate work profile container where managed apps are installed. Option D is correct because managed Google Play apps must first be approved (and optionally configured) in the managed Google Play store within Intune before they can be assigned and deployed to devices. Option A is not required because the work profile enrollment handles the Google account binding through the managed Google Play connection, and end users do not need a separate personal Google account for app deployment.

Option B is not required because work profile enrollment supports both personally owned and corporate-owned devices. Option E is not required because kiosk mode is a separate dedicated-device configuration and is not needed to deploy a standard managed Google Play app.

Exam trap

The trap here is that candidates often confuse the requirement for a Google account (personal) with the managed Google Play account, or assume that work profile requires personal ownership, when in fact the enrollment type (work profile) is the sole prerequisite for deploying managed Google Play apps to work profile devices.

480
MCQeasy

You manage a group of iOS devices enrolled in Microsoft Intune. Users report that they are unable to receive email on their devices after you deployed a new configuration profile. You need to identify the cause quickly. What should you use?

A.Intune configuration profile assignment status
B.Intune device compliance report
C.Azure AD sign-in logs
D.Intune audit logs
AnswerA

The assignment status for a configuration profile shows which devices received the profile and any errors during deployment. This is the quickest way to see if the email profile was successfully applied or if there were conflicts or failures that could explain the email issue.

Why this answer

The configuration profile assignment status in Intune provides per-device deployment details, including success or failure and error messages. This helps quickly identify if the email profile was not applied correctly or if there was a conflict, directly addressing the user's inability to receive email.

Exam trap

The trap here is confusing compliance reports with configuration profile status, assuming compliance reports show deployment errors.

481
MCQmedium

You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?

A.Add a shell script under Devices > Scripts
B.Use Company Portal to distribute the script
C.Add a PowerShell script under Devices > Scripts
D.Create a custom configuration profile with Bash script
AnswerA

Intune's Devices > Scripts node deploys shell scripts natively to macOS, executing them via the Intune management agent. This satisfies the requirement to run a script across all managed macOS devices without repackaging as an app.

Why this answer

In Microsoft Intune, shell scripts for macOS are managed under Devices > Scripts, where you can add a script with a specific shell (e.g., bash, sh, zsh) and configure its execution frequency, run context, and notifications. This is the correct method because Intune natively supports deploying and running shell scripts on macOS devices via the Intune management agent, without requiring additional infrastructure.

Exam trap

The trap here is that candidates confuse the ability to run PowerShell scripts on Windows with macOS, or mistakenly think a configuration profile can execute arbitrary code, when in fact Intune strictly separates script deployment (Devices > Scripts) from configuration profiles (Devices > Configuration profiles).

How to eliminate wrong answers

Option B is wrong because Company Portal is a client application for end-user self-service tasks like installing available apps or enrolling devices, not a mechanism for deploying and executing scripts on macOS devices. Option C is wrong because PowerShell scripts are not natively supported on macOS in Intune; Intune's script deployment for macOS only supports shell scripts (e.g., bash, sh, zsh), not PowerShell. Option D is wrong because custom configuration profiles are used to apply settings (e.g., preferences, restrictions) via property lists, not to execute scripts; scripts require the dedicated 'Scripts' blade under Devices.

482
MCQhard

You run the PowerShell command to check the assignment of a Microsoft Store app in Intune. The output shows 'intent: required' and 'target: allDevicesAssignmentTarget'. Which statement is true about this app?

A.The app is assigned to a specific device group named 'All Devices'.
B.The app will install automatically on all enrolled devices.
C.The app is only assigned to devices that have the Intune Management Extension.
D.The app is available for users to install from Company Portal.
AnswerB

A required intent with an allDevicesAssignmentTarget forces automatic installation on every enrolled device, with no user interaction or opt-out. This satisfies the stem's constraint: the assignment targets all devices rather than users or groups, so Intune pushes the Microsoft Store app silently to each enrolled device.

Why this answer

The output shows 'intent: required' and 'target: allDevicesAssignmentTarget'. In Intune, 'intent: required' means the app is mandatory and will install automatically without user intervention. 'target: allDevicesAssignmentTarget' indicates the assignment applies to all enrolled devices, not a specific group. Therefore, the app will install automatically on every enrolled device, making option B correct.

Exam trap

The trap here is that candidates confuse 'allDevicesAssignmentTarget' with a manually created 'All Devices' group, or misinterpret 'intent: required' as making the app available in Company Portal, when in fact it enforces automatic installation.

How to eliminate wrong answers

Option A is wrong because 'allDevicesAssignmentTarget' is a built-in system group representing all enrolled devices, not a user-created device group named 'All Devices'. Option C is wrong because the Intune Management Extension is only required for Win32 apps or PowerShell scripts, not for Microsoft Store apps, which use the Windows Store client or the Intune management agent. Option D is wrong because 'intent: required' forces installation, whereas 'intent: available' would make the app visible in Company Portal for user-initiated installation.

483
MCQeasy

Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?

A.App Protection Policies (MAM).
B.Device Compliance Policies.
C.Conditional Access Policies.
D.Device Configuration Profiles.
AnswerA

App Protection Policies apply MAM controls at the app layer, blocking copy-paste and data transfer from managed apps to personal apps, and support selective wipe that removes only corporate data, leaving personal content intact on the enrolled device.

Why this answer

App Protection Policies (MAM) provide data protection settings such as preventing copy/paste between managed and unmanaged apps, and allow selective wipe of corporate data. Option B is incorrect because device compliance policies focus on device-level settings, not app-level data protection. Option C is incorrect because conditional access policies control access based on compliance, but do not directly prevent copy/paste or provide selective wipe at the app level.

Option D is incorrect because device configuration profiles configure device settings, not app data protection.

484
MCQhard

You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully on some devices but fails on others with no error in the Intune console. The app logs show 'Access Denied' during installation. What should you check first?

A.The device is not Microsoft Entra ID joined
B.The device has insufficient disk space
C.The app is not signed
D.The installation context (user vs system) in the app deployment
AnswerD

'Access Denied' typically means the installer ran under the wrong account context. A Win32 app set to user context executes with standard user rights, so system-level writes fail. Verifying whether the app is configured for system context resolves the failure.

Why this answer

The 'Access Denied' error in the app logs indicates a permissions issue during installation. In Intune, Win32 apps can be deployed in either 'user' or 'system' installation context. If the app requires administrative privileges (e.g., writing to Program Files or the registry under HKLM) but is configured to run in the user context, it will fail with an access denied error on devices where the user lacks sufficient rights.

Therefore, verifying the installation context is the first troubleshooting step.

Exam trap

The trap here is that candidates often assume 'Access Denied' is always a signing or permission issue at the device level, but the MD-102 exam specifically tests the distinction between user and system installation contexts in Intune Win32 app deployments.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) join status does not directly cause 'Access Denied' errors during app installation; it affects authentication and policy application, not local file system permissions. Option B is wrong because insufficient disk space typically produces a 'disk full' or 'out of space' error, not an 'Access Denied' error. Option C is wrong because an unsigned app would generate a different error, such as 'The publisher could not be verified' or a SmartScreen warning, not an 'Access Denied' error.

485
Multi-Selectmedium

Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?

Select 2 answers
A.Windows Autopilot
B.Provisioning packages (PPKG)
C.PXE boot from a distribution point
D.Network boot via WDS
E.Bootable USB media with Windows Setup
AnswersA, B

Windows Autopilot deploys Windows 10/11 by binding a device's hardware hash to a profile, so it enrols into Intune and receives configuration during the out-of-box experience, requiring no imaging infrastructure. This satisfies the question's requirement for a valid Intune-based deployment method.

Why this answer

Windows Autopilot (A) is a valid Intune-based deployment method that uses the device's hardware hash registered in Intune to apply an Autopilot profile, enroll the device in Azure AD/Entra ID, and drive the Out-of-Box Experience (OOBE) so the device is configured and joined automatically without reimaging. Provisioning packages (B) are also valid: a .ppkg created with Windows Configuration Designer can be applied during OOBE or after installation to enroll the device into Intune (via the enrollment package or bulk enrollment token) and apply settings, making it a supported Intune deployment path. PXE boot from a distribution point (C) and network boot via WDS (D) are Configuration Manager/legacy imaging technologies, not Intune deployment methods, and bootable USB media with Windows Setup (E) is a manual OS installation method that does not itself deploy or enroll devices through Intune.

Exam trap

The trap here is that candidates confuse on-premises deployment tools (WDS, PXE, USB media) with cloud-native Intune methods, forgetting that Intune is a cloud-only MDM service that does not support direct imaging or network boot protocols.

486
MCQhard

You manage a set of Windows 11 devices with Microsoft Intune. You need to configure attack surface reduction (ASR) rules to block Office applications from creating child processes. You want to ensure the rules are enforced and cannot be bypassed by users. Which Intune profile type should you use?

A.Devices > Compliance policies
B.Endpoint security > Attack surface reduction policy
C.Devices > Configuration profiles > Templates > Endpoint protection
D.Devices > Configuration profiles > Templates > Custom
AnswerB

The Attack surface reduction policy under Endpoint security in Intune is specifically designed to configure and enforce ASR rules. It provides a streamlined interface to set rules to Block, Audit, or Warn. When set to Block, the rules are enforced by Defender Antivirus and cannot be disabled by users, meeting the requirement.

Why this answer

The Attack surface reduction policy in Intune is the correct choice for configuring ASR rules. It provides a dedicated, user-friendly interface to set rules to Block, Audit, or Warn. When set to Block, the rules are enforced by Defender Antivirus and cannot be overridden by users, ensuring the desired protection.

Exam trap

The trap here is assuming that any configuration profile that mentions ASR or endpoint protection will suffice, but the dedicated Attack surface reduction policy is the only one that provides full enforcement and management.

487
MCQmedium

An Android device running OS version 9.0 with app version 1.5.0 is targeted by the app protection policy in the exhibit. What is the expected behavior when the user tries to access work data?

A.Access is blocked because the OS version is below the warning level
B.Access is allowed with a warning to update the app and OS
C.Access is allowed without any warning because minimum requirements are met
D.Access is blocked because the app version is below the warning level
AnswerC

Correct. The device satisfies minimum requirements and is not at the warning level, so access is granted without warning.

Why this answer

The device meets the minimum OS and app version requirements, and the versions are not at the warning threshold configured in the policy. Therefore, access is allowed without any warning.

Exam trap

Candidates may confuse the warning level with the block level or assume that meeting minimums always results in no warning, but here the warning level is higher than the device's versions.

How to eliminate wrong answers

Option A is wrong because the OS version 9.0 is not below the warning level (8.0) — it is above it, so access is not blocked for OS version. Option C is wrong because while access is allowed, the statement 'without any warning because minimum requirements are met' is partially correct, but the question expects the behavior when the user tries to access work data — the policy allows access with a warning only if the app or OS is below the warning level but above the minimum; here both are above warning levels, so no warning is shown, making C technically correct but the exam answer is B because the exhibit likely shows the app version is below the warning level (1.5.0 vs 1.4.0 warning) — wait, re-evaluating: if app version 1.5.0 is above warning 1.4.0, no warning. The trap is that the exhibit might show the warning level for OS as 8.0 and app as 1.4.0, but the device OS 9.0 is above warning, app 1.5.0 is above warning, so no warning.

Option D is wrong because the app version 1.5.0 is not below the warning level (1.4.0) — it is above, so access is not blocked for app version.

488
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. You need to create a report that shows which devices have not checked in to Intune for more than 30 days. What should you use?

A.Intune device inventory report
B.Microsoft Entra sign-in logs
C.Intune device compliance report
D.Intune devices with stale check-in report
AnswerD

Intune includes a built-in report called 'Devices with stale check-in' that lists devices that have not checked in for a specified number of days. This report can be filtered to show devices not checked in for more than 30 days, directly answering the requirement.

Why this answer

Intune provides a specific report called 'Devices with stale check-in' that identifies devices that have not communicated with the service for a defined period. This report can be filtered to show devices with check-in times older than 30 days, making it the correct tool for the task.

Exam trap

The trap here is assuming that compliance or inventory reports include check-in time filters, when in fact only the stale check-in report is designed for this purpose.

489
MCQmedium

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the result?

A.A list of all devices regardless of operating system.
B.A list of all Windows devices with their last activity.
C.A count of unique Windows devices per device name in the last 7 days.
D.A count of security alerts per device.
AnswerC

Correct. The query summarizes unique devices by name.

Why this answer

The KQL query uses `DeviceInfo` (a Microsoft Sentinel table for device inventory), filters with `where` to include only rows where `OperatingSystem` contains 'Windows', then uses `summarize` with `dcount(DeviceName)` to count distinct device names, and `bin(TimeGenerated, 7d)` to group by 7-day intervals. This produces a count of unique Windows devices per device name over the last 7 days, making option C correct.

Exam trap

The trap here is that candidates may misinterpret `dcount(DeviceName)` as a count of rows or a list of devices, rather than recognizing it as a distinct count aggregation, and may overlook that `DeviceInfo` is an inventory table, not an alert table.

How to eliminate wrong answers

Option A is wrong because the query explicitly filters for Windows devices (`where OperatingSystem contains 'Windows'`), so it does not return all devices regardless of OS. Option B is wrong because the query does not retrieve any 'last activity' data; it uses `dcount(DeviceName)` to count unique devices, not to list devices with their last activity timestamp. Option D is wrong because the query operates on `DeviceInfo`, which is a device inventory table, not a security alerts table; there is no alert data or alert count logic in the query.

490
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. Users report that a LOB app deployed as a required install fails to install on some devices. The app is configured with a dependency on another app. What should the administrator verify first?

A.Ensure the devices have internet connectivity
B.Verify that the app is signed with a trusted certificate
C.Recreate the deployment policy
D.Check if the dependency app is assigned and installed successfully
AnswerD

A required app with a dependency will not install until the dependency app is successfully assigned to the same device and installed. Verifying the dependency's assignment and installation state first isolates whether the failure originates from the prerequisite rather than the LOB app itself.

Why this answer

When a required LOB app fails to install, the most common cause is that its dependency app is not present or not successfully installed on the target device. Intune enforces dependency apps to be installed before the parent app, and if the dependency is missing or failed, the parent app installation will not proceed. The administrator should first verify that the dependency app is assigned to the same device groups and has a successful installation status.

Exam trap

The trap here is that candidates may assume the issue is with the app itself (signing or connectivity) rather than recognizing that Intune's dependency enforcement means the parent app will not install until the dependency is successfully deployed.

How to eliminate wrong answers

Option A is wrong because while internet connectivity is needed for Intune communication, a dependency issue is a more specific and likely cause for a required app failing to install, and connectivity would typically affect all apps, not just one. Option B is wrong because LOB apps deployed via Intune are already signed with a trusted certificate during enrollment or sideloading; signing issues would cause installation failures on all devices, not just some, and the question indicates the app is already configured. Option C is wrong because recreating the deployment policy is a generic troubleshooting step that does not address the specific dependency configuration; it would not resolve a missing or failed dependency app.

491
Drag & Dropmedium

Arrange the steps to troubleshoot a Windows 10 device failing to enroll in Microsoft Intune.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with basic connectivity and licensing, then check logs for errors, verify prerequisites, and retry.

492
MCQhard

Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?

A.A device compliance policy in Intune with an action for noncompliance that marks the device as noncompliant immediately.
B.A configuration profile in Intune that sets the device to block access to Microsoft 365 services when noncompliant.
C.A conditional access policy in Microsoft Entra ID that requires compliant devices and set the grant control to 'Require device to be marked as compliant'.
D.A Microsoft Defender for Endpoint device group in Intune with an automated task to restrict access.
AnswerC

Conditional access policies in Microsoft Entra ID evaluate device compliance state and can block access to cloud apps when a device is noncompliant. By requiring compliant devices, noncompliant devices are denied access to Microsoft 365 services. The timing depends on token lifetime and compliance re-evaluation, but this is the correct mechanism to enforce compliance-based access.

Why this answer

Conditional access in Microsoft Entra ID enforces access controls based on conditions such as device compliance. By creating a policy that requires compliant devices for Microsoft 365 apps, noncompliant devices are blocked from accessing those services. This integrates with Intune compliance policies, which evaluate and report device state.

The other options do not provide real-time access blocking based on compliance.

Exam trap

The trap here is confusing Intune compliance policy actions with conditional access enforcement, when only conditional access can block access to cloud apps based on compliance state.

493
MCQeasy

You are setting up Microsoft Intune for a new subsidiary. The subsidiary has an existing on-premises Active Directory Domain Services (AD DS) and uses Microsoft Entra Connect to synchronize users to Microsoft Entra ID. You need to enable automatic enrollment of Windows 10 devices into Intune for users who are synchronized from AD DS. What should you configure first?

A.In Microsoft Intune, create a Windows Autopilot deployment profile and assign it to all devices.
B.In Microsoft Intune, create a device enrollment restriction that allows Windows devices and assign it to all users.
C.In Microsoft Entra Connect, enable device writeback and synchronize device objects to Microsoft Entra ID.
D.In Microsoft Entra ID, configure the Mobility (MDM and MAM) settings to enable automatic MDM enrollment for Windows devices.
AnswerD

Automatic MDM enrollment for Windows devices is configured in Microsoft Entra ID under Mobility (MDM and MAM). By setting the MDM user scope to All or a specific group, synchronized users can automatically enroll their Windows 10 devices into Intune when they join or register the device in Microsoft Entra ID, which is the required first step.

Why this answer

Automatic Intune enrollment for Windows devices is enabled through the Mobility (MDM and MAM) configuration in Microsoft Entra ID. This setting, when scoped to users or groups, allows synchronized users to automatically enroll their Windows devices. Enrollment restrictions and Autopilot profiles serve different purposes and do not initiate automatic enrollment, while device writeback is unrelated to MDM enrollment.

Exam trap

The trap here is assuming that Intune enrollment restrictions or Autopilot profiles enable automatic enrollment, when the actual trigger is the Mobility (MDM and MAM) setting in Microsoft Entra ID.

494
MCQeasy

Refer to the exhibit. You deploy this custom OMA-URI policy to Windows 10 devices. What is the expected outcome?

A.Telemetry is set to 1 - Basic
B.The policy applies to users, not devices
C.The policy fails because value 0 is not allowed
D.Telemetry is set to 0 - Security (Enterprise only)
AnswerD

The OMA-URI value 0 maps to the Security telemetry level, the minimum setting that sends only security-related data. This level is restricted to Enterprise editions, so Windows Pro devices would not apply it, matching the stated Enterprise-only constraint.

Why this answer

The OMA-URI policy sets the 'AllowTelemetry' value to 0, which in Windows 10 corresponds to the 'Security (Enterprise only)' telemetry level. This level sends only essential security data, such as the Malicious Software Removal Tool (MSRT) and Windows Defender information, and is only available in Enterprise editions. Therefore, the expected outcome is that telemetry is set to 0 - Security (Enterprise only).

Exam trap

A common misconception is that setting telemetry to 0 causes policy failure on non-Enterprise editions. However, the policy applies successfully; the setting is simply ignored on editions that do not support it.

How to eliminate wrong answers

Option A is wrong because the policy explicitly sets the value to 0, not 1; value 1 corresponds to 'Basic' telemetry, which includes limited diagnostic data. Option B is wrong because OMA-URI policies for Windows 10 device configuration are applied at the device level via MDM, not per user; the policy targets the device CSP (Policy/Config/System/AllowTelemetry). Option C is wrong because value 0 is a valid and allowed integer for the AllowTelemetry policy in Windows 10 Enterprise editions; it is not a failure condition, though it may be ignored on non-Enterprise editions.

495
MCQmedium

You manage Windows 11 devices with Microsoft Intune. After a Windows quality update is deployed to a pilot ring, several devices report installation failures in the Update reports. You need to identify the exact error code returned by the update installation on a specific device without accessing the device directly. What should you do?

A.From the Intune admin center, select the device and review the device compliance policy status.
B.In the Microsoft Intune admin center, open the device's Windows Update for Business reports and view the 'Update installation failures' report.
C.In Microsoft Intune, review the device's discovered apps report to identify the update failure.
D.Use Microsoft Endpoint Configuration Manager to create a device collection and run a hardware inventory cycle.
AnswerB

Windows Update for Business reports in Intune provide detailed error codes and failure reasons for quality and feature updates, including per-device data. This directly meets the requirement to see the error code without accessing the device, as the report aggregates telemetry from the device and surfaces the exact failure code.

Why this answer

Windows Update for Business reports in Microsoft Intune include detailed update installation data, including failure codes and reasons. These reports are accessible from the Intune admin center and provide per-device information without requiring direct device access. The other options either report unrelated data or require additional infrastructure that does not surface update error codes.

Exam trap

The trap here is confusing update failure reporting with compliance or inventory reporting, which do not expose Windows Update error codes.

496
MCQhard

You are troubleshooting a Windows 11 device that fails to install an Intune-managed update. The device has been offline for two weeks. After reconnecting, the update does not install. In the Intune console, the update shows 'Failed to install' with error code 0x800f0831. What is the most likely cause?

A.The device does not have internet connectivity.
B.The device's Windows component store is corrupted due to missing prerequisites.
C.The device does not have enough disk space.
D.The update is superseded and no longer applicable.
AnswerB

Error 0x800f0831 indicates a missing servicing-stack or prerequisite update, not a network fault. Two weeks offline left the component store without the required cumulative prerequisites, so servicing cannot stage the Intune update. Reconnecting alone does not repair it; DISM /RestoreHealth or installing the prerequisite servicing stack update is needed.

Why this answer

Error code 0x800f0831 indicates that the Windows component store (CBS) is corrupted because a required servicing stack or prerequisite update is missing. When a device has been offline for two weeks, it may lack the necessary baseline updates that the current update depends on, causing the installation to fail even after reconnecting to the network.

Exam trap

The trap here is that candidates often assume 'offline for two weeks' implies a connectivity issue (option A), but the specific error code 0x800f0831 points to a corrupted component store from missing prerequisites, not a network problem.

How to eliminate wrong answers

Option A is wrong because the device has reconnected to the network and the Intune console shows the update attempt with a specific error code, which implies internet connectivity is present; a lack of connectivity would typically result in a 'pending download' or 'not applicable' status, not a specific CBS error. Option C is wrong because insufficient disk space usually produces error codes like 0x80070070 or 0x80070008, not 0x800f0831, which is specific to component store corruption. Option D is wrong because a superseded update would show as 'not applicable' or 'superseded' in the Intune console, not 'Failed to install' with a CBS-related error code; superseded updates are simply no longer offered to the device.

497
Multi-Selecthard

Your organization uses Microsoft Intune to manage devices. You need to collect diagnostic logs from a remote Windows device without user interaction. Which THREE methods can you use?

Select 3 answers
A.MDM diagnostic log collection policy
B.Device configuration profile
C.Device diagnostics (Intune device action)
D.Microsoft Support and Recovery Assistant
E.Remote Windows PowerShell session
AnswersA, C, E

Policy can trigger log upload to Intune.

Why this answer

The MDM diagnostic log collection policy is a built-in Intune feature that allows administrators to configure and trigger the collection of device diagnostic logs from Windows devices remotely without any user interaction. This policy leverages the Windows MDM protocol to gather logs such as event viewer logs, registry keys, and network traces, and uploads them to an Azure storage container for analysis.

Exam trap

The trap here is that candidates often confuse Device configuration profiles (which manage settings) with diagnostic collection actions, or assume that SaRA can be triggered remotely via Intune, when in fact it requires local user initiation.

498
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app named App1 that requires a specific command-line switch during installation. The app's installer is an .exe file that does not support silent installation by default. You must ensure the app installs without user interaction. What should you do?

A.Add the app as a Microsoft Store app (new) and upload the .exe file.
B.Create a PowerShell script that runs the installer with the required switch and deploy it as a platform script.
C.Package the app as a Win32 app and specify the silent install command in the install command field.
D.Deploy the app as a line-of-business app and upload the .exe file directly.
AnswerC

Win32 apps in Intune allow you to specify the exact install command, including silent switches such as /quiet or /silent. By packaging the .exe with the Microsoft Win32 Content Prep Tool and providing the correct silent command, Intune can install the app without user interaction. This is the standard method for deploying custom .exe installers.

Why this answer

Win32 apps in Intune are designed for custom .exe installers and allow you to specify the exact install command, including silent switches. After packaging with the Microsoft Win32 Content Prep Tool, you provide the silent install command in the app configuration. This ensures the app installs without user interaction and is tracked by Intune with detection and reporting.

Exam trap

The trap here is assuming that any .exe can be uploaded directly as a line-of-business app or a Store app, when only Win32 apps support custom .exe installers with command-line switches.

499
MCQeasy

You are a Microsoft 365 Endpoint Administrator. You need to remotely wipe a lost Windows 11 device that is enrolled in Microsoft Intune. The device is currently offline. What happens when you initiate a wipe action from the Intune admin center?

A.The wipe command is sent via push notification and will execute even if the device is offline.
B.The wipe fails immediately because the device is offline, and you must retry once it is online.
C.The device is marked as wiped in Intune immediately, but the actual wipe occurs only if the device comes online within 24 hours.
D.The wipe command is queued and will execute the next time the device checks in with Intune.
AnswerD

When you initiate a wipe action for an offline device, Intune queues the command. The device will receive and execute the wipe the next time it connects to the Intune service. This is standard behavior for remote actions on enrolled devices. The wipe will remove corporate data and, depending on the wipe type, may reset the device to factory settings. The command remains pending until the device checks in.

Why this answer

Intune queues remote actions for devices that are offline. When the device next connects to the Intune service, it receives the pending wipe command and executes it. This ensures that lost or stolen devices can be wiped even if they are currently disconnected.

The other options incorrectly suggest immediate failure, expiration, or push notification delivery to offline devices. The correct behavior is to queue the command until the device checks in.

Exam trap

The trap here is assuming that remote actions require the device to be online at the moment of initiation, or that they expire after a certain time.

500
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a firewall enabled. Which setting should you configure?

A.Firewall
B.Antivirus
C.Require a password to unlock mobile devices
D.Require BitLocker
AnswerA

The Firewall setting in a Windows compliance policy checks whether the Windows Firewall is enabled on the device. Configuring this setting to 'Require' ensures devices with the firewall disabled are marked non-compliant, directly fulfilling the requirement.

Why this answer

The Firewall setting in a Windows compliance policy specifically evaluates whether Windows Firewall is enabled. Setting it to 'Require' ensures devices without an active firewall are non-compliant, directly satisfying the scenario's requirement.

Exam trap

The trap here is confusing firewall with other security settings like antivirus or BitLocker, which are related but do not enforce firewall enablement.

501
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, it loses access to corporate email and Teams within 15 minutes. You have already configured a compliance policy and assigned it to all users. What should you do next to meet the requirement?

A.Configure a Conditional Access policy that requires compliant devices and set the grant control to require device compliance.
B.Configure a device compliance policy to automatically retire noncompliant devices after 15 minutes.
C.Configure an app protection policy that requires a PIN and blocks access to email and Teams on noncompliant devices.
D.Configure a Conditional Access policy that requires compliant devices and set the grant control to require multi-factor authentication.
AnswerA

A Conditional Access policy that requires compliant devices and uses the grant control 'Require device to be marked as compliant' will block access from devices that are not compliant. When a device becomes noncompliant, Intune marks it as such, and Conditional Access evaluates the device state. Access is typically blocked within minutes, meeting the 15-minute requirement. This is the correct approach to enforce compliance for access to corporate resources.

Why this answer

To block access to corporate resources like email and Teams when a device is noncompliant, you must use Conditional Access. A Conditional Access policy that requires the device to be marked as compliant will deny access if the device is not compliant. Intune updates the compliance status, and Conditional Access enforces it.

This typically takes effect within minutes, satisfying the 15-minute window. Other options do not provide the required enforcement.

Exam trap

The trap here is thinking that app protection policies or MFA can enforce device compliance; they cannot block access based on device compliance status.

502
MCQeasy

Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?

A.Group Policy
B.Windows Autopilot
C.System Center Updates Publisher (SCUP)
D.Configuration Manager Cloud Management Gateway (CMG)
AnswerA

Group Policy delivers the automatic MDM enrolment task that hybrid Azure AD joined Windows devices require, triggering Intune enrolment via the device's domain membership. Configuring it here satisfies the hybrid join scenario, unlike manual or provisioning-package methods.

Why this answer

For hybrid Azure AD joined devices, automatic enrollment into Intune is configured via Group Policy. Specifically, you deploy the 'Enable automatic MDM enrollment using default Azure AD credentials' policy setting, which triggers the MDM enrollment process using the user's Azure AD credentials during sign-in. This is the only supported method for bulk, automatic enrollment of hybrid Azure AD joined Windows devices without requiring additional infrastructure.

Exam trap

The trap here is that candidates often confuse Windows Autopilot with automatic enrollment, but Autopilot is a provisioning tool for new devices, not a configuration mechanism for existing hybrid domain-joined devices.

How to eliminate wrong answers

Option B (Windows Autopilot) is wrong because Autopilot is designed for new, out-of-box device provisioning and does not handle automatic enrollment of existing domain-joined devices; it requires a fresh OS deployment or reset. Option C (System Center Updates Publisher, SCUP) is wrong because SCUP is a tool for managing third-party software updates via Configuration Manager, not for configuring MDM enrollment. Option D (Configuration Manager Cloud Management Gateway, CMG) is wrong because CMG provides internet-based management for Configuration Manager clients, but it does not configure automatic Intune enrollment; enrollment is handled separately via Group Policy or co-management settings.

503
MCQmedium

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?

A.Create an app protection policy that restricts data transfer between work and personal apps.
B.Create a device configuration policy that disables clipboard sharing.
C.Create a device compliance policy that requires a work profile.
D.Create a conditional access policy that blocks personal apps.
AnswerA

An app protection policy enforces data-transfer restrictions at the app layer, blocking copy, paste and share actions between managed work apps and unmanaged personal apps within the Android Enterprise work profile. This directly satisfies the stem's requirement to prevent corporate data leaking from work apps to personal apps.

Why this answer

App protection policies (also called MAM policies) in Intune are designed to protect corporate data at the app layer, independent of device enrollment. For Android Enterprise work profiles, an app protection policy can enforce data transfer restrictions such as blocking copy/paste between work and personal apps, restricting save-as, and controlling sharing. This directly addresses the requirement without affecting the personal side of the device.

Exam trap

MD-102 often tests the difference between app protection policies (MAM, app-level data control) and device configuration/compliance policies (MDM, device-level settings), catching candidates who pick device-level controls for app-level data protection requirements.

How to eliminate wrong answers

Option B is wrong because device configuration policies control device settings (e.g., Wi-Fi, VPN, certificates) and do not provide the granular app-level data transfer restrictions needed to block copy/paste between work and personal apps. Option C is wrong because a device compliance policy only evaluates whether a device meets conditions (e.g., OS version, encryption) and marks it compliant or not; it does not enforce app-level data sharing restrictions. Option D is wrong because a conditional access policy controls access to cloud resources based on conditions (user, device, location), not clipboard or data transfer behavior between apps on the device.

504
MCQeasy

An administrator needs to ensure that only devices with a specific manufacturer are allowed to enroll in Intune. Which setting should the administrator configure?

A.Enrollment restrictions
B.Conditional Access policy
C.Device category
D.Device compliance policy
AnswerA

Enrollment restrictions can block devices by platform, manufacturer, etc.

Why this answer

Nrollment restrictions. Enrollment restrictions allow administrators to block devices based on manufacturer, OS version, or device platform. Conditional Access policies work after enrollment.

Device categories are for organizational grouping, not blocking enrollment. Device compliance policies evaluate device health after enrollment.

505
MCQhard

A user reports that a Microsoft 365 Apps for enterprise installation failed on their Windows 11 device managed by Intune. The Intune management extension logs show error code 0x80070005. The device is Azure AD joined and compliant. What is the most likely cause?

A.The user does not have local administrator privileges on the device
B.The device has insufficient disk space
C.The device does not have internet connectivity to the Microsoft CDN
D.The device is not compliant with the conditional access policy
AnswerA

Error 0x80070005 is Access Denied, which for Microsoft 365 Apps deployment via the Intune management extension typically reflects insufficient rights to write to protected locations. Because the app requires elevation and the user lacks local administrator privileges, the installation cannot complete.

Why this answer

Error code 0x80070005 translates to 'Access Denied' (E_ACCESSDENIED). Microsoft 365 Apps for enterprise installation requires local administrator privileges to write to protected system paths (e.g., Program Files, registry). Since the device is Azure AD joined and compliant, the most likely cause is that the user lacks local admin rights, which is a common Intune deployment prerequisite.

Exam trap

The trap here is that candidates confuse a compliance-related conditional access block (which would occur at sign-in) with a local installation permission error, overlooking that 0x80070005 specifically indicates an access-denied condition at the OS level, not a network or policy issue.

How to eliminate wrong answers

Option B is wrong because insufficient disk space typically produces error 0x80070070 (ERROR_DISK_FULL), not 0x80070005. Option C is wrong because lack of internet connectivity to the Microsoft CDN would result in download-related errors (e.g., 0x80072EFD or timeout), not an access-denied code. Option D is wrong because the device is explicitly stated as compliant, and conditional access policies affect access to cloud resources, not local installation permissions; non-compliance would block the app at the authentication layer, not produce a local access-denied error.

506
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. The security team requires that all Windows 11 devices automatically receive an Intune device configuration profile that enforces a minimum PIN length of 8 for Windows Hello for Business. You need to ensure the profile is applied without user interaction. What should you do?

A.Create a compliance policy that requires a minimum PIN length of 8, and assign it to all Windows 11 devices.
B.Create a Group Policy Object (GPO) in on-premises Active Directory and link it to the domain, then sync devices with Intune.
C.Deploy a PowerShell script through Intune that modifies the registry to set the minimum PIN length.
D.Create a device configuration profile with the Windows Hello for Business template, configure the minimum PIN length setting, and assign the profile to all Windows 11 devices.
AnswerD

This is correct because a device configuration profile using the Windows Hello for Business template in Intune allows you to centrally configure PIN requirements. Assigning the profile to all Windows 11 devices ensures that the settings are applied automatically to each device, meeting the requirement for no user interaction and enforcing the minimum PIN length.

Why this answer

A device configuration profile with the Windows Hello for Business template is the correct Intune-native method to enforce PIN requirements. Assigning it to all Windows 11 devices ensures automatic application without user action. Compliance policies only assess, GPOs are for domain-joined devices, and scripts are not the preferred method for this policy.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance policies do not enforce settings, they only evaluate them.

507
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. You need to deploy Microsoft 365 Apps to all Windows devices. The deployment must use the Microsoft 365 Apps wizard in Intune. What should you do?

A.Upload the Office Deployment Tool (ODT) and create a Win32 app.
B.Deploy the Microsoft Store version of Office as a required app.
C.Create a new app of type 'Microsoft 365 Apps' and configure the required settings.
D.Create a PowerShell script that downloads and installs Office, and assign it to devices.
AnswerC

Intune provides a built-in app type for Microsoft 365 Apps. Selecting this type launches a wizard where you can configure update channel, version, and other settings. This is the correct method to deploy Microsoft 365 Apps using the dedicated wizard.

Why this answer

In Intune, you can deploy Microsoft 365 Apps by creating an app of type 'Microsoft 365 Apps'. This opens a wizard where you configure settings such as update channel, architecture, and which Office apps to install. This is the dedicated method for deploying Microsoft 365 Apps and is simpler than using the Office Deployment Tool.

Exam trap

The trap here is assuming you must use the Office Deployment Tool, but the wizard is the direct method.

508
Multi-Selectmedium

Which THREE of the following are features of Microsoft Defender for Endpoint that help protect devices?

Select 3 answers
A.Attack surface reduction rules
B.Endpoint detection and response
C.Next-generation protection
D.Data loss prevention
E.Conditional access policies
AnswersA, B, C

Attack surface reduction rules block risky behaviours such as Office macros spawning child processes, script downloads and credential theft, satisfying the requirement for device protection features. They are enforced through Microsoft Defender for Endpoint policy and configuration profiles, hardening endpoints against common malware vectors without relying on signature detection alone.

Why this answer

Attack surface reduction rules (A) are a Defender for Endpoint feature that blocks risky behaviors such as Office macros spawning child processes or scripts launching executable content, thereby hardening the device against common attack vectors. Endpoint detection and response (B) provides behavioral monitoring, alert generation, investigation timelines, and automated remediation actions so security teams can detect and contain threats on endpoints. Next-generation protection (C) delivers cloud-delivered antivirus and antimalware capabilities, including real-time protection, behavior monitoring, and heuristics, to block malware at the device level.

Data loss prevention (D) is not a Defender for Endpoint device-protection feature; it is a separate Microsoft Purview/Compliance capability focused on preventing sensitive data exfiltration. Conditional access policies (E) are an identity and access control feature of Microsoft Entra ID, not a Defender for Endpoint device-protection capability.

Exam trap

The trap here is that candidates often confuse Data loss prevention (a compliance feature) with device protection features in Defender for Endpoint, or mistakenly think Conditional Access policies are part of Defender for Endpoint when they are actually an identity and access management feature in Microsoft Entra ID.

509
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a Microsoft Entra ID tenant with Intune configured. You need to ensure that when new Windows 10 devices are set up by users, they are automatically enrolled in Intune and receive company policies. The devices are purchased from a reseller and are not domain-joined. You want to minimize user interaction during setup. What should you configure?

A.Conditional Access policy
B.Windows Autopilot deployment profile
C.Device enrollment restrictions
D.Microsoft Intune enrollment policy for Windows
AnswerB

Windows Autopilot deployment profiles are used to configure the out-of-box experience (OOBE) for new devices. When a device is registered with Autopilot, the profile can automatically enroll the device in Intune, apply policies, and skip certain OOBE screens. This meets the requirement of minimal user interaction and automatic enrollment for non-domain-joined devices.

Why this answer

Windows Autopilot deployment profiles allow you to configure the OOBE so that devices automatically enroll in Intune and receive policies with minimal user interaction. The device must first be registered with Autopilot, which can be done by the reseller or by capturing a hardware hash. Once registered, the profile ensures that when the user turns on the device, it connects to Intune and applies the desired configuration.

Exam trap

The trap here is confusing enrollment restrictions with enrollment automation; restrictions only control who can enroll, not how devices are provisioned.

510
MCQmedium

You are deploying a new line-of-business app to 500 Windows 11 devices using Microsoft Intune. The app requires a specific PowerShell script to run after installation to configure registry settings. You need to ensure the script runs only after the app is successfully installed and that it does not require user interaction. What should you do?

A.Package the app and script together as a Win32 app with a custom installation command that runs the script after the installer.
B.Use a platform script that runs during device enrollment.
C.Add the PowerShell script as a dependency to the app.
D.Deploy the script using a separate PowerShell script policy and set it to run after the app is installed.
AnswerA

Packaging the app and script as a Win32 app allows you to define a custom installation command that can execute the installer followed by the PowerShell script. Intune runs the command as SYSTEM, and you can ensure the script runs only after successful installation by chaining commands with conditional execution. This meets the requirement without user interaction.

Why this answer

To run a PowerShell script after app installation without user interaction, you should package both as a Win32 app. The Win32 app deployment in Intune allows you to specify a custom installation command that can run the installer and then execute the script. This ensures the script runs in the system context after the app is installed.

Other methods like dependencies or separate script policies do not provide the required sequencing.

Exam trap

The trap here is assuming that Intune PowerShell script policies can be triggered by app installation events or that dependencies can be scripts, leading to unreliable sequencing.

511
MCQeasy

You need to wipe a lost corporate-owned Windows 10 device that is enrolled in Intune. Which action should you take?

A.Delete the device from Intune.
B.Select the device and choose Wipe.
C.Select the device and choose Retire.
D.Reset the device using the Company Portal.
AnswerB

Correct. Wipe resets the device to factory settings.

Why this answer

The Wipe action in Intune restores a Windows 10 device to its factory default settings, removing all data and corporate access. This is the appropriate action for a lost corporate-owned device because it ensures sensitive data is erased while retaining the device's enrollment record for potential recovery or re-provisioning.

Exam trap

The trap here is confusing the Retire action (which only removes management and corporate data) with the Wipe action (which performs a full factory reset), leading candidates to choose Retire when a complete data erasure is required.

How to eliminate wrong answers

Option A is wrong because deleting the device from Intune only removes the device object from the console; it does not send a wipe command to the device, so data remains intact. Option C is wrong because Retire removes managed apps and policies but preserves personal data and does not perform a full factory reset, leaving corporate data potentially accessible. Option D is wrong because the Company Portal reset is a user-initiated action that requires the device to be physically accessible and logged in, which is not possible for a lost device.

512
MCQeasy

You are configuring a Windows 10 kiosk device using Intune. The device should run a single-store app in full-screen mode. Which Intune policy type should you use?

A.A device configuration profile using the 'Kiosk' settings for single-app mode
B.A device restrictions profile blocking access to other apps
C.A compliance policy requiring the app to be installed
D.A configuration profile for Microsoft Edge in kiosk mode
AnswerA

A device configuration profile with the Kiosk settings configured for single-app mode assigns the store app as the sole full-screen experience on the Windows 10 device, satisfying the single-app kiosk constraint directly through Intune's built-in kiosk configuration.

Why this answer

A is correct because Intune's device configuration profile includes a 'Kiosk' settings category specifically designed for Windows 10/11 devices. When you select 'Single-app mode' under kiosk settings, you can specify a single Store app (e.g., a UWP or Win32 app) that will run in full-screen, locked-down mode, preventing users from accessing any other system functions or apps.

Exam trap

The trap here is that candidates confuse 'device restrictions' (which can block apps) with the dedicated 'Kiosk' settings profile, which is the only Intune policy type that enforces the full-screen, single-app, locked-down experience required for a kiosk device.

How to eliminate wrong answers

Option B is wrong because a device restrictions profile can block access to other apps, but it does not enforce the full-screen, single-app kiosk experience; it lacks the dedicated kiosk lock-down features (e.g., auto-launch, no exit gesture). Option C is wrong because a compliance policy only checks whether an app is installed and reports non-compliance; it cannot configure the device to run that app in kiosk mode. Option D is wrong because a configuration profile for Microsoft Edge in kiosk mode is a specific subset of kiosk settings that only applies to Edge, not to any single-store app; it cannot be used to run a non-Edge app in full-screen kiosk mode.

513
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Security requires that when a device is marked as noncompliant, access to Microsoft 365 services is blocked within 5 minutes, even if the user is already signed in. You configure a Conditional Access policy that requires a compliant device. What else must you configure to achieve this near-real-time enforcement?

A.Configure the Conditional Access policy to use 'Require device to be marked as compliant' and enable continuous access evaluation (CAE).
B.Decrease the compliance policy's 'Compliance status validity period' to 5 minutes.
C.Set the device compliance policy's action for noncompliance to 'Retire the device' immediately.
D.Set the compliance policy's 'Mark devices with no compliance policy assigned as' setting to 'Not compliant'.
AnswerA

Continuous access evaluation (CAE) enables near-real-time enforcement of Conditional Access policies by allowing Microsoft Entra ID to revoke access tokens when a device's compliance state changes, rather than waiting for token expiry. Combined with a compliant device requirement, CAE ensures that a noncompliant device is blocked within minutes, meeting the 5-minute requirement without user reauthentication.

Why this answer

Continuous access evaluation (CAE) is the feature that enables near-real-time enforcement of Conditional Access policies. When a device becomes noncompliant, Intune updates the device compliance state, and CAE allows Microsoft Entra ID to revoke access tokens immediately. Without CAE, access remains until token expiry, which can be up to an hour.

Therefore, enabling CAE alongside the compliant device requirement achieves the 5-minute block.

Exam trap

The trap here is assuming that shortening the compliance validity period or marking unassigned devices as noncompliant will speed up enforcement, when actually only continuous access evaluation provides near-real-time token revocation.

514
Matchingmedium

Match each Microsoft 365 Defender feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Endpoint detection and response (EDR) and antivirus

Protection for email and collaboration tools

Detect and investigate advanced attacks on-premises

Cloud access security broker (CASB) for SaaS apps

Identify and remediate vulnerabilities

Why these pairings

The correct matches are: Microsoft Defender for Endpoint (endpoint protection), Microsoft Defender for Office 365 (email/collaboration protection), Microsoft Defender for Identity (on-premises threat detection via AD), and Microsoft Defender for Cloud Apps (SaaS security via CASB). The distractors swap the definitions of Endpoint and Office 365.

515
MCQmedium

A company uses Microsoft Intune to manage Windows 10 devices. The security team reports that several devices are missing critical security updates. You need to ensure that devices install updates within 7 days of release. What should you configure?

A.Create a compliance policy for Windows 10 update compliance.
B.Create an update ring for Windows 10 with a deadline of 7 days.
C.Create a device configuration profile for Windows 10 updates.
D.Configure a Windows Update for Business policy in Group Policy.
AnswerB

An update ring's deadline setting forces installation within a defined window after release; setting it to 7 days directly satisfies the stem's requirement that devices install critical updates within 7 days, without relying on user-initiated checks.

Why this answer

Update rings in Microsoft Intune allow you to configure Windows Update for Business settings, including a deadline for feature and quality updates. Setting a deadline of 7 days ensures that devices must install released updates within that timeframe, directly addressing the requirement for timely installation of critical security updates.

Exam trap

The trap here is that candidates often confuse compliance policies (which only report on update status) with update rings (which enforce installation deadlines), leading them to choose Option A instead of B.

How to eliminate wrong answers

Option A is wrong because compliance policies evaluate device configuration and health (e.g., required updates installed) but do not enforce an installation deadline; they only report non-compliance. Option C is wrong because device configuration profiles manage settings like security policies or certificates, not update deadlines or rings. Option D is wrong because Group Policy is a traditional on-premises management tool that does not integrate with Intune for cloud-managed devices; the question specifies Microsoft Intune management, so a cloud-native solution (update ring) is required.

516
MCQmedium

A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?

A.Ensure that the device has a policy to allow installation of unapproved apps.
B.Check if the device's enrollment token is still valid.
C.Check if the app is available in the unmanaged Play Store.
D.Verify that the app has been approved in the managed Google Play store.
AnswerD

Approval in managed Google Play is mandatory before an Android Enterprise fully managed device can install any app, even when it appears in the Company Portal. Unapproved apps remain unavailable to Intune, so the install silently fails. Checking approval status directly addresses the managed Play Store constraint in the stem.

Why this answer

For Android Enterprise fully managed devices, apps must be approved in the managed Google Play store before they can be installed via Intune. If an app appears in the Company Portal but fails to install, the most likely cause is that it hasn't been approved in the managed Play Store. This is a common configuration step.

Exam trap

MD-102 often tests the managed Google Play approval process, confusing candidates with other Android Enterprise concepts like enrollment tokens or unmanaged store.

How to eliminate wrong answers

Option A is wrong because fully managed devices do not allow installation of unapproved apps by default, and a policy to allow that would be counterproductive. Option B is wrong because an invalid enrollment token would prevent enrollment, not app installation. Option C is wrong because the unmanaged Play Store is not used for fully managed devices; only the managed Play Store is relevant.

517
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to prevent users from installing apps from unknown sources on their personally-owned work profile devices. Which configuration profile type should you use?

A.Custom
B.Endpoint protection
C.Device restrictions
D.Identity protection
AnswerC

For Android Enterprise personally-owned work profile devices, device restrictions profiles include settings to block installation of apps from unknown sources. This directly prevents sideloading and meets the requirement. Device restrictions are used to control features like camera, Bluetooth, and app installation sources on managed devices.

Why this answer

To prevent installation of apps from unknown sources on Android Enterprise personally-owned work profile devices, you should use a device restrictions profile. This profile type includes a setting under 'Work Profile Settings' or 'Device Settings' to block unknown sources. It is the built-in, recommended method.

Other profile types either do not apply to Android or do not have the specific setting.

Exam trap

The trap here is selecting a custom profile thinking it's needed for granular control, but Intune provides a built-in device restrictions setting for this exact purpose.

518
MCQeasy

Your company has 500 Windows 10 devices that are Hybrid Azure AD joined and managed by Microsoft Intune. You need to deploy a new line-of-business (LOB) app to all devices. The app is packaged as a .msi file. You create a new app in Intune and assign it to a device group containing all devices. After 24 hours, some devices report the app as 'Installed' but others show 'Failed'. You verify that the devices are online and have network connectivity. What should you do next to resolve the installation failures?

A.Use a PowerShell script to install the app on failed devices.
B.Check the Intune management extension logs on a failed device.
C.Create a new device group and assign the app again.
D.Re-assign the app to the device group.
AnswerB

MSI apps deploy through the Intune management extension on Windows, so its logs record the actual installation failure reason. Devices showing 'Failed' have the agent present, making these logs the correct diagnostic source for the error code.

Why this answer

The Intune management extension logs on a failed device contain detailed information about why the app installation failed, including error codes, detection rule failures, and installation command output. Since some devices succeeded and others failed with the same app and assignment, the issue is device-specific — checking the logs on a failed device is the correct next step to identify the root cause (e.g., missing dependency, detection rule mismatch, or installer error). This is the standard troubleshooting approach for Win32/MSI app deployment failures in Intune.

Exam trap

MD-102 often tests the difference between assignment issues and device-specific issues — candidates may jump to re-assigning or re-creating groups, but when some devices succeed and others fail with the same assignment, the problem is device-specific and requires log analysis, not assignment changes.

How to eliminate wrong answers

Option A is wrong because using a PowerShell script to install the app bypasses Intune's management and does not address the root cause — it also doesn't scale to hundreds of devices and may violate the requirement to deploy via Intune. Option C is wrong because creating a new device group and re-assigning the app does not change the underlying cause of the failure — the same devices would likely fail again, and it adds unnecessary administrative overhead. Option D is wrong because re-assigning the app to the same group will not fix the failure — the assignment is already correct since some devices installed successfully, so the issue is device-specific, not assignment-related.

519
Multi-Selecthard

Which TWO Windows Update for Business policies can you configure using Microsoft Intune?

Select 2 answers
A.Feature update version targeting
B.Quality update deferral period
C.Driver update deferral period
D.Windows Defender definition update schedule
E.Microsoft 365 Apps update channel
AnswersA, B

Correct. Feature update version targeting is a Windows Update for Business policy in Intune that allows you to specify a feature update version for devices to stay on.

Why this answer

Microsoft Intune allows you to configure a 'Feature update version targeting' policy, which specifies a target feature update version (e.g., Windows 11 23H2) for devices. Option B is correct because you can configure a 'Quality update deferral period' within an update ring policy to delay quality updates. Option C is incorrect because, although a driver update deferral period can be configured in an update ring policy, it is not a separate Windows Update for Business policy type; the question expects the two distinct policy types: Feature update version targeting and Quality update deferral period.

Option D is incorrect because Windows Defender definition update schedule is not a Windows Update for Business policy; it is managed via Microsoft Defender for Endpoint or other settings. Option E is incorrect because Microsoft 365 Apps update channel is not a Windows Update for Business policy; it is configured separately for Office applications.

Exam trap

The trap is that candidates often think only quality and feature update deferrals are configurable in Intune, overlooking that driver update deferral periods are also part of Windows Update for Business policies. This leads them to select only A and B, missing C.

520
MCQeasy

You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Microsoft Intune to manage its Windows 10 devices. The company recently experienced a ransomware attack that encrypted local files on several devices. To mitigate future attacks, management wants to ensure that all devices have real-time protection enabled in Microsoft Defender Antivirus and that Controlled Folder Access is turned on. You need to configure these settings via Intune. You decide to create a device configuration profile for Windows 10. What is the most efficient way to deploy these settings to all existing and future devices?

A.Create a device configuration profile and assign it to a device group that includes all devices.
B.Use PowerShell scripts deployed via Intune to enable the settings on each device.
C.Create a device configuration profile and assign it to a user group that includes all users.
D.Create a compliance policy that requires these settings and assign it to all devices.
AnswerA

Assigning the device configuration profile to a device group containing all devices delivers the Defender Antivirus real-time protection and Controlled Folder Access settings to every existing and future member. This satisfies the stem's efficiency constraint, since new devices joining the group inherit the settings automatically.

Why this answer

A device configuration profile in Intune can include Microsoft Defender Antivirus settings (such as real-time protection and Controlled Folder Access) and is assigned to a device group. This ensures that both existing and future devices that join the group automatically receive the settings, providing a scalable and efficient deployment method without requiring user interaction or additional scripts.

Exam trap

The trap here is that candidates often confuse compliance policies with configuration profiles, thinking that compliance policies can enforce settings, when in reality they only evaluate and report on settings, requiring a separate configuration profile to actually apply the desired state.

How to eliminate wrong answers

Option B is wrong because PowerShell scripts deployed via Intune are executed on a per-device or per-user basis and require manual assignment or targeting; they do not provide the same declarative, policy-driven enforcement as a device configuration profile, and they cannot be as easily applied to future devices without ongoing script management. Option C is wrong because assigning the profile to a user group applies settings based on user identity, not device identity; if a user logs into a different device, the settings may not apply, and devices without a signed-in user (e.g., kiosks) would be missed. Option D is wrong because a compliance policy is designed to report or mark devices as non-compliant, not to enforce settings; it cannot enable real-time protection or Controlled Folder Access—it only checks if those settings are present and can trigger remediation actions only if configured with a corresponding device configuration profile.

521
Multi-Selectmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate applications. Which TWO configurations should you implement?

Select 2 answers
A.Deploy an App Protection Policy
B.Create a device compliance policy
C.Configure a device configuration profile
D.Enable multifactor authentication (MFA) for all users
E.Create a Conditional Access policy requiring compliant devices
AnswersB, E

A compliance policy defines the rules a device must meet, such as encryption, PIN and OS version, and reports each device's state to Intune. Conditional Access then uses that state, so the policy is the prerequisite that produces the compliance signal.

Why this answer

Option B (Create a device compliance policy) is correct because a compliance policy in Intune defines the rules a device must meet—such as BitLocker, minimum OS version, or jailbreak/root detection—and evaluates devices to produce a compliance state that Conditional Access can consume. Option E (Create a Conditional Access policy requiring compliant devices) is correct because Conditional Access is the enforcement engine in Microsoft Entra ID that grants or blocks access to corporate applications based on signals like device compliance, so requiring compliant devices ensures only compliant devices reach those apps. Together, the compliance policy establishes the device state and the Conditional Access policy enforces it at access time.

Option A (App Protection Policy) only protects app data on mobile apps via MAM and does not gate access to corporate applications based on device compliance. Option C (device configuration profile) merely configures settings on devices and does not itself evaluate or enforce compliance for access. Option D (MFA) strengthens user authentication but does not verify device compliance, so it does not satisfy the requirement on its own.

Exam trap

The trap here is that candidates often confuse App Protection Policies (which protect data on unmanaged devices) with device compliance policies (which require managed devices to meet security baselines), leading them to select Option A instead of the correct combination of B and E.

522
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?

A.Use a compliance policy with custom settings to enforce BitLocker.
B.Create a new security baseline from scratch and include the BitLocker settings.
C.Copy the built-in Windows security baseline and customize the BitLocker settings in the copy.
D.Edit the built-in Windows security baseline and add the BitLocker settings.
AnswerC

Copying the built-in Windows security baseline preserves Microsoft's curated hardening settings, then lets you adjust only the BitLocker values required. The copy is assigned to your Windows 11 device groups through Microsoft Entra ID, satisfying the need for a custom baseline without rebuilding every setting manually.

Why this answer

Intune's security baselines are designed to be copied and customized rather than edited directly. By copying the built-in Windows security baseline, you preserve the Microsoft-recommended settings as a template while allowing modifications—such as specific BitLocker configurations—in the copy. This approach ensures that the original baseline remains intact for reference or reuse, and the customized copy can be assigned to device groups via Intune's policy assignment workflow.

Exam trap

The trap here is that candidates assume baselines can be edited directly like other Intune policies, but Microsoft intentionally locks built-in baselines to enforce consistency, requiring a copy for customization.

How to eliminate wrong answers

Option A is wrong because compliance policies evaluate device compliance after configuration and cannot enforce settings like BitLocker; they only report non-compliance and trigger remediation actions, not deploy configurations. Option B is wrong because Intune does not allow creating a security baseline from scratch; you must start from a built-in baseline template and customize a copy. Option D is wrong because editing the built-in Windows security baseline directly is not supported; Intune baselines are read-only templates, and modifications require creating a copy.

523
MCQmedium

Your organization uses Microsoft Intune to manage iOS and Android devices. You have a compliance policy that requires a minimum OS version: iOS 16.0 and Android 12.0. You also have a Conditional Access policy that requires compliant devices. Several users report that they cannot access corporate email on their personal Android devices. The devices are Android 11.0. You need to allow these users to access email while ensuring that corporate data is protected. What should you do?

A.Remove the Conditional Access policy for these users.
B.Update the compliance policy to accept Android 11.0.
C.Create a Conditional Access policy that grants access but requires app protection policies and session controls.
D.Ask users to upgrade their devices to Android 12.0.
AnswerC

App protection policies with session controls let Android 11.0 devices reach email without meeting the OS-version compliance bar, because Conditional Access evaluates Intune app protection as a separate grant control rather than device compliance. Corporate data stays contained through encryption, selective wipe and copy/paste restrictions, satisfying the requirement to protect data on non-compliant personal devices.

Why this answer

It allows access from non-compliant devices while enforcing data protection through app protection policies (MAM) and session controls, such as limiting access to the web or approved apps. This balances security and usability. Option A is incorrect because removing the Conditional Access policy entirely would allow all devices, including those that are non-compliant, without any data protection.

Option B is incorrect because lowering the minimum OS version in the compliance policy weakens the security baseline and may not align with organizational requirements. Option D is incorrect because upgrading devices may not be immediately possible for all users, and the organization needs a solution that works with existing devices.

524
MCQhard

Refer to the exhibit. You deploy this endpoint protection configuration to a Windows 10 device. A user reports that they cannot connect to the device via RDP. What is the most likely cause?

A.The firewall rule 'Allow RDP' is configured to block traffic.
B.The firewall rule is for outbound traffic, not inbound.
C.The malware actions are blocking RDP traffic.
D.The firewall rule 'Allow RDP' is configured to allow traffic.
AnswerA

The endpoint protection configuration includes a firewall rule named 'Allow RDP' whose action is set to Block rather than Allow. This blocks inbound TCP 3389 traffic, preventing RDP connections even though the rule's name suggests otherwise.

Why this answer

The exhibit shows that the 'Allow RDP' firewall rule has its 'Action' set to 'Block', which overrides any other configuration. Windows Defender Firewall processes rules in order of priority, and a block action explicitly denies inbound RDP traffic (TCP port 3389), preventing any RDP connection to the device. This is the most direct cause of the user's inability to connect via RDP.

Exam trap

The trap here is that candidates assume a rule named 'Allow RDP' must permit traffic, overlooking the 'Action: Block' setting, which is the critical detail that reverses the rule's effect.

How to eliminate wrong answers

Option B is wrong because the firewall rule 'Allow RDP' is configured for inbound traffic (as indicated by the 'Direction: In' setting), not outbound; RDP connections to the device require inbound rules. Option C is wrong because malware actions (e.g., from Windows Defender Antivirus or Attack Surface Reduction) do not block RDP traffic unless specifically configured to do so, and the exhibit shows no such configuration; they focus on malicious behavior, not network connectivity. Option D is wrong because the rule is explicitly set to 'Block', not 'Allow', so stating it allows traffic contradicts the exhibited configuration.

525
MCQeasy

You are the endpoint administrator for a company using Microsoft Intune. The IT director asks you to generate a report that shows which Windows devices have not installed the latest security update in the past 14 days. What should you use?

A.Microsoft Intune Reports > Windows updates > Feature updates report.
B.Microsoft Intune Devices > Monitor > Noncompliant devices report.
C.Microsoft Intune Endpoint security > Windows updates report.
D.Microsoft Intune Reports > Windows updates > Windows quality updates report.
AnswerD

The Windows quality updates report shows the status of monthly security and quality updates across managed devices. It includes data on which devices have installed or are pending specific quality updates, and you can filter by update name and time. This report directly provides the information needed to identify devices missing recent security updates.

Why this answer

The Windows quality updates report in Intune provides detailed per-device status for monthly security and quality updates. It allows administrators to see which devices have not installed specific updates within a given timeframe, making it the correct tool for identifying devices missing recent security patches.

Exam trap

The trap here is assuming that the feature updates report covers all Windows updates, when in fact it only tracks annual feature updates, not monthly security patches.

Page 6

Page 7 of 8

Page 8

All pages