Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?
Windows Autopilot self-deploying mode enrols devices with no user credentials, satisfying the zero-touch requirement, since it authenticates via the device's TPM-attested identity rather than an interactive sign-in. Pairing it with an Enrollment Status Page profile blocks device use until assigned required apps install, meeting the stem's gating constraint.
Why this answer
Windows Autopilot self-deploying mode enrolls devices into Intune with zero user interaction — the device authenticates using its TPM-attested hardware identity, so no credentials are entered. Pairing it with an Enrollment Status Page (ESP) profile blocks the device from being used until required apps and policies are applied, which is exactly what the scenario requires.
Exam trap
MD-102 often tests the confusion between DEM accounts (bulk enrollment with sign-in) and Autopilot self-deploying mode (truly unattended, TPM-based), causing candidates to pick DEM for zero-touch scenarios.
How to eliminate wrong answers
Option A is wrong because Group Policy auto-enrollment still requires a user to sign in with a work account to trigger MDM enrollment, so it is not zero-touch. Option B is wrong because a DEM account is used to enroll many devices with a single account and still requires interactive sign-in; it also has a 1,000-device limit and is not designed for unattended self-deploying scenarios. Option D is wrong because co-management with Configuration Manager is about workload sharing between Intune and ConfigMgr, not about zero-touch enrollment or blocking device use via ESP.