Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 526–556

556 questions total · 8pages · All types, answers revealed

Page 7

Page 8 of 8

526
Multi-Selectmedium

You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?

Select 2 answers
A.Device configuration profile
B.Compliance policy for Microsoft Intune
C.Device compliance policy
D.Conditional Access policy in Microsoft Entra ID
E.App protection policy
AnswersB, D

Correct - defines compliance rules that devices must meet to be considered compliant.

Why this answer

To ensure only compliant devices can access corporate email, you need a compliance policy (Option B) that defines device health rules and a Conditional Access policy (Option D) that enforces access based on compliance status. Option C is essentially the same concept as Option B and should not be selected as an additional component. Option A (device configuration profile) sets device settings but does not define compliance.

Option E (app protection policy) protects app data but does not evaluate device compliance.

Exam trap

The trap is that candidates may mistakenly include additional components such as configuration profiles or app protection policies, not realizing that only two components are necessary: Compliance Policy and Conditional Access.

527
MCQhard

You manage Windows 11 devices with Microsoft Intune. A line-of-business application must be deployed to a specific group of devices. The application installer requires administrative privileges and must run in the system context. You need to ensure the app installs silently without user interaction. What should you create?

A.A Win32 app with the install command configured to run with system privileges and a detection rule based on a file version.
B.An Office app deployment using the Microsoft 365 Apps configuration.
C.A Microsoft Store app (new) assigned as required to the device group.
D.A PowerShell platform script that runs once per device and invokes the installer.
AnswerA

Win32 apps in Intune run as the SYSTEM account by default on Windows devices, which satisfies the requirement for administrative privileges and system context. Configuring a detection rule based on file version lets Intune verify installation success and avoid reinstalling. The installer runs silently when the install command includes appropriate silent switches, meeting the no-user-interaction requirement.

Why this answer

Win32 apps in Intune are the appropriate deployment type for custom line-of-business installers that require administrative rights and system context. The Intune Management Extension runs the install command as SYSTEM, and detection rules determine whether the app is present. This provides silent installation, verification, and uninstall support that a platform script would not deliver.

Exam trap

The trap here is assuming that any deployment method capable of running elevated commands, such as a platform script, is a suitable substitute for a Win32 app.

528
MCQmedium

You manage Windows devices with Microsoft Intune. A line-of-business Win32 app is deployed as Required to a device group. Users report the app never installs, and in the Intune console the app shows installation status 'Not applicable' for those devices. You confirm the app is assigned to the correct group and the devices are online and healthy. What is the most likely cause?

A.The app's requirement rules evaluate to false on those devices.
B.The app's detection rules evaluate to false on those devices.
C.The app content was not uploaded to Intune before assignment.
D.The Intune Management Extension is not installed on those devices.
AnswerA

Intune evaluates requirement rules (OS version, architecture, disk space, registry, etc.) before attempting installation. If none of the rules match, the app is marked 'Not applicable' and no install is attempted, which exactly matches the observed status. Reviewing and correcting the requirement rules on the app's properties will resolve it.

Why this answer

The 'Not applicable' installation status is unique to requirement rule evaluation. Intune checks requirement rules before downloading or installing a Win32 app; if no rule matches, the app is skipped and marked Not applicable. Since assignments and device health are confirmed, the requirement rules themselves must be excluding these devices, so they need to be reviewed and corrected.

Exam trap

The trap here is confusing requirement rules with detection rules, assuming a detection failure produces 'Not applicable' when it actually causes repeated install attempts or a failure status.

529
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom configuration profile that sets a specific firewall rule. However, the profile fails to apply on a subset of devices. The Intune console shows 'Conflict' status. What is the most likely cause?

A.The user does not have a macOS license
B.The macOS version is not supported by the profile
C.Another profile with overlapping settings is assigned
D.The device is not connected to the internet
AnswerC

Overlapping settings from a second assigned profile cause Intune to report 'Conflict', because macOS configuration profiles cannot merge contradictory payload values — one payload wins and the other is rejected. Removing the duplicate firewall setting from one profile, or consolidating both into a single profile, resolves the conflict status.

Why this answer

The 'Conflict' status in Microsoft Intune indicates that two or more configuration profiles are attempting to apply different values to the same setting on the device. Since the question specifies a custom firewall rule, the most likely cause is that another profile (e.g., a built-in or custom profile) is also configuring firewall settings, creating a conflict. Intune cannot resolve overlapping settings, so it marks the profile as 'Conflict' and does not apply it.

Exam trap

The trap here is that candidates confuse 'Conflict' with 'Error' or 'Not applicable' — Microsoft Intune exams often test the specific Intune status codes, where 'Conflict' uniquely points to overlapping settings, not version or connectivity issues.

How to eliminate wrong answers

Option A is wrong because a missing macOS license would prevent enrollment or management entirely, not cause a specific 'Conflict' status on a profile. Option B is wrong because an unsupported macOS version would result in an 'Error' or 'Not applicable' status, not a 'Conflict' — Intune validates version compatibility before attempting to apply the profile. Option D is wrong because a device not connected to the internet would show a 'Pending' or 'Not evaluated' status, as Intune cannot communicate with the device to report a conflict.

530
Multi-Selecthard

You are deploying a Windows line-of-business app to Intune-managed devices using the Win32 app type. The app installer is a .msi file that must run silently. You need to ensure the app installs correctly and Intune can accurately report its status. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Add a requirement rule that the device must be domain-joined.
B.Specify the install command as msiexec /i "app.msi" /qn.
C.Set the install behavior to 'User' so the app installs in the user's context.
D.Configure a detection rule that checks for the app's product code in the registry.
E.Upload the .msi file as a Windows app (Win32) package without an install command.
AnswersB, D

The Win32 app type requires an explicit install command that runs silently. Using msiexec with /qn suppresses the UI and returns proper exit codes, which Intune relies on to determine success or failure. Without a silent command, the installer may prompt and hang, causing the app to report as failed or pending indefinitely.

Why this answer

For a Win32 app packaged from an MSI, Intune requires a silent install command such as msiexec /i "app.msi" /qn, and a detection rule to verify installation. These two elements ensure the installer runs without user interaction and that Intune can accurately report success. Without them, the deployment will fail or produce unreliable status.

Exam trap

The trap here is assuming Intune automatically derives an install command or detection logic from an MSI, when both must be supplied manually for Win32 apps.

531
MCQhard

You are the Intune administrator for Contoso Ltd., a company with 5,000 Windows 11 devices and 1,000 iOS devices managed by Microsoft Intune. The company uses Microsoft Defender for Endpoint for threat detection. You need to implement a solution that ensures devices are compliant before they can access corporate resources. You have the following requirements: 1. Windows devices must have Defender for Endpoint running and report a threat level of 'low' or better. 2. iOS devices must have a PIN of at least 6 characters and be jailbreak-detected as 'not jailbroken'. 3. If a device becomes noncompliant, it should be blocked immediately with no grace period. 4. Noncompliant devices should receive a notification to the user. You create compliance policies for Windows and iOS. You also create a conditional access policy in Microsoft Entra ID to require compliant devices. After deploying, you find that some Windows devices that are missing Defender for Endpoint are still able to access email. What should you do to resolve this issue?

A.Configure a notification to users when their device is noncompliant.
B.Modify the conditional access policy to require a compliant device and a specific client app.
C.Enable the 'Require Defender for Endpoint' setting in the Windows compliance policy.
D.Set the required threat level to 'medium' in the Windows compliance policy.
AnswerC

The Windows compliance policy must itself evaluate Defender for Endpoint status; without that setting, devices missing Defender still report compliant, so conditional access grants email access. Enabling 'Require Defender for Endpoint' makes the missing-agent state noncompliant, satisfying the requirement that Defender running be enforced.

Why this answer

The Windows compliance policy must explicitly have the 'Require Defender for Endpoint' setting enabled to enforce that the Defender for Endpoint sensor is present and active on the device. Without this setting, the compliance policy only checks the threat level reported by Defender for Endpoint but does not require the sensor to be installed or running. Enabling this setting ensures that devices missing the Defender for Endpoint sensor are marked as noncompliant, which then triggers the conditional access policy to block access to corporate resources like email.

Exam trap

The trap here is that candidates often assume that setting the required threat level to 'low' automatically enforces the presence of Defender for Endpoint, but in reality, the threat level check only evaluates the last reported threat score, not the sensor's installation or running state.

How to eliminate wrong answers

Option A is wrong because configuring a notification to users when their device is noncompliant does not enforce compliance or block access; it only informs the user after the device is already noncompliant. Option B is wrong because modifying the conditional access policy to require a specific client app does not address the missing Defender for Endpoint sensor; the conditional access policy already requires a compliant device, and the issue is that the compliance policy is not correctly evaluating the Defender for Endpoint requirement. Option D is wrong because setting the required threat level to 'medium' would allow devices with a threat level of 'medium' to be compliant, which is less restrictive than 'low' and does not solve the problem of devices missing Defender for Endpoint entirely.

532
MCQmedium

An organization is moving from on-premises SCCM to Microsoft Intune for Windows app management. They need to ensure that users can self-install company portal apps without administrator intervention. Which configuration is required?

A.Configure the app as 'Required' for all users
B.Add the app to the Windows Autopilot deployment profile
C.Grant users local administrator rights on their devices
D.Assign the app to users as 'Available' in the Company Portal
AnswerD

Assigning the app as 'Available' to users publishes it in the Company Portal, letting users install it themselves without admin rights or IT intervention. Required assignments push silently, while Available is the self-service model the scenario demands.

Why this answer

The 'Available' assignment type in Microsoft Intune allows users to install apps on demand from the Company Portal without requiring administrator intervention. This configuration meets the requirement for self-service installation while respecting user intent, as opposed to forced installations.

Exam trap

The trap here is that candidates may confuse 'Available' assignments with 'Required' assignments, thinking that self-service implies mandatory installation, or incorrectly assume that local admin rights are needed for app installation in Intune.

How to eliminate wrong answers

Option A is wrong because configuring the app as 'Required' forces installation on all targeted devices, which does not allow users to choose when or if to install the app, contradicting the self-install requirement. Option B is wrong because Windows Autopilot deployment profiles are used for device provisioning and initial setup, not for ongoing self-service app installation via Company Portal. Option C is wrong because granting users local administrator rights is a security risk and unnecessary; Intune's 'Available' assignment enables self-installation without elevated privileges, as the Company Portal uses the Intune Management Extension to install apps in the system context.

533
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?

A.Automated investigation and response
B.Threat analytics
C.Device inventory
D.Alert queue
AnswerA

Automated investigation and response in the Microsoft Defender XDR portal governs whether alerts trigger automatic investigation and remediation actions on devices. Enabling it there satisfies the requirement to configure automatic investigation and response for onboarded endpoints.

Why this answer

The correct setting is 'Automated investigation and response' because it directly controls the configuration of automatic investigation and response (AIR) capabilities in Microsoft Defender for Endpoint. This setting allows administrators to enable or disable automated investigations, set the automation level (e.g., full, semi, or no automation), and define remediation actions for devices. Without adjusting this setting, the automatic investigation and response workflow cannot be tailored to the organization's security requirements.

Exam trap

The trap here is that candidates often confuse the 'Automated investigation and response' configuration with the 'Alert queue' or 'Threat analytics' because they all appear under the same XDR portal section, but only the AIR setting directly manages the automation behavior for device-level response actions.

How to eliminate wrong answers

Option B is wrong because Threat Analytics is a feature that provides threat intelligence, vulnerability reports, and mitigation recommendations, but it does not configure the automatic investigation and response behavior for devices. Option C is wrong because Device Inventory is a list of all managed devices with their security status and configuration details, not a setting to enable or adjust automated response actions. Option D is wrong because Alert Queue is a view of security alerts generated by Defender for Endpoint, and while it allows manual triage of alerts, it does not control the automation level or response configuration for investigations.

534
MCQeasy

A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?

A.Configure Windows Hello for Business in Intune
B.Deploy an attack surface reduction rule in Microsoft Defender XDR
C.Use Windows Autopilot to enforce TPM and Secure Boot during provisioning
D.Create a Conditional Access policy that requires device compliance and a device compliance policy that checks TPM 2.0 and Secure Boot
AnswerD

Conditional Access enforces the access decision in Microsoft Entra ID, while the compliance policy evaluates TPM 2.0 and Secure Boot via device health attestation. Combining both satisfies the requirement that only compliant devices reach corporate resources.

Why this answer

Conditional Access policies in Microsoft Entra ID can require devices to be marked as compliant before granting access to corporate resources. A device compliance policy in Intune can be configured to check for TPM 2.0 and Secure Boot status on Windows 11 devices. Only when both conditions are met will the device be considered compliant, and the Conditional Access policy will enforce that compliance requirement, effectively blocking non-compliant devices from accessing corporate resources.

Exam trap

The trap here is that candidates often confuse provisioning-time enforcement (Autopilot) with runtime compliance enforcement (Conditional Access + compliance policy), mistakenly thinking Autopilot can block access after the device is in use.

How to eliminate wrong answers

Option A is wrong because Windows Hello for Business is an authentication method that uses biometrics or PINs, not a mechanism to enforce TPM 2.0 or Secure Boot as a compliance check for resource access. Option B is wrong because attack surface reduction rules in Microsoft Defender XDR are designed to block malicious behaviors (e.g., script execution, Office macro abuse), not to enforce hardware security features like TPM or Secure Boot for device compliance. Option C is wrong because Windows Autopilot is a provisioning tool that can apply settings during initial setup, but it does not enforce ongoing compliance checks or block access to corporate resources after provisioning; it cannot replace a Conditional Access policy that dynamically evaluates device compliance.

535
MCQeasy

You are an administrator for a company that uses Microsoft Intune to manage Windows 10 devices. You need to deploy a new version of an internal line-of-business (LOB) app to all users. The app is packaged as an .msi file. What is the simplest way to deploy this app using Intune?

A.Upload the .msi file as a line-of-business app in Intune.
B.Create a PowerShell script that installs the .msi, and deploy the script as a platform script.
C.Convert the .msi to a .intunewin file using the Microsoft Win32 Content Prep Tool, then upload as a Win32 app.
D.Package the .msi into an .appx file and deploy as a Microsoft Store app.
AnswerA

Intune supports direct upload of .msi files as line-of-business apps. This method is straightforward: you select the .msi file, configure the app information, and assign it to users or devices. Intune handles the installation silently, making it the simplest approach for MSI deployment.

Why this answer

Intune's line-of-business app type supports direct upload of .msi files, automatically handling installation and detection. This is the simplest and most efficient method for deploying an MSI package, as it requires minimal configuration and leverages Intune's built-in app management capabilities.

Exam trap

The trap here is overcomplicating the deployment by assuming you need to repackage the MSI, when Intune natively supports MSI uploads.

536
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that all devices have a passcode of at least 6 characters and that devices are updated to the latest iOS version. You create a compliance policy. After assigning the policy, some devices are marked as non-compliant even though they have a passcode. What is the most likely cause?

A.The devices have multiple compliance policies applied.
B.iOS devices do not support compliance policies.
C.The devices have not checked in with Intune since the policy was assigned.
D.The policy was assigned to a user group instead of a device group.
AnswerC

Compliance state only refreshes when a device checks in with the Intune service. Until the device syncs and evaluates the newly assigned policy, it retains its previous status, so passcode-compliant devices can still appear non-compliant.

Why this answer

Intune compliance policies are evaluated only when devices check in with the service. If a device has not performed a check-in since the policy was assigned, it will not have received or evaluated the new policy, and its compliance status will remain based on the previous state. The check-in interval for iOS/iPadOS devices is typically every 8 hours, but can be forced manually by the user.

Until the device checks in, it cannot be marked compliant even if it meets the passcode and OS version requirements.

Exam trap

The trap here is that candidates assume compliance policies are evaluated immediately upon assignment, but Intune requires a device check-in to apply and evaluate the policy, and devices that haven't checked in will show as non-compliant even if they meet the requirements.

How to eliminate wrong answers

Option A is wrong because having multiple compliance policies does not inherently cause a device to be marked non-compliant; Intune evaluates all assigned policies and the device is compliant only if it meets all of them. Option B is wrong because iOS/iPadOS devices fully support compliance policies in Intune, including passcode and OS version requirements. Option D is wrong because assigning a compliance policy to a user group is the standard and supported method; Intune applies the policy to all devices owned by users in that group, and this does not cause false non-compliance.

537
MCQmedium

Your organization uses Microsoft Intune to manage 1,000 Windows 10 devices and 500 iOS devices. You need to enforce device compliance policies. For Windows devices, you require BitLocker encryption and Windows Defender Antivirus enabled. For iOS devices, you require a passcode of at least 6 characters and device encryption. Devices that become noncompliant should be marked as such and users should receive a notification email. After 7 days of noncompliance, the device should be blocked from accessing corporate email. You also need to create a report that shows the compliance status of all devices. Which combination of actions should you take?

A.Create Windows and iOS compliance policies with the required settings. Configure actions for noncompliance: send email immediately and block access after 7 days. Use the built-in compliance report.
B.Create app protection policies to require encryption and passcode. Use conditional access to block noncompliant devices.
C.Create device configuration profiles for BitLocker and encryption. Use conditional access to block noncompliant devices. Manually generate reports using PowerShell.
D.Use Autopilot to enforce encryption and passcode. Use Intune reporting for compliance status.
AnswerA

Separate Windows and iOS compliance policies apply platform-specific settings, while noncompliance actions send email immediately and block corporate email access after seven days. The built-in Intune compliance report satisfies the reporting requirement without custom tooling.

Why this answer

Intune compliance policies directly enforce device-level settings like BitLocker and passcode length, and they include built-in actions for noncompliance (e.g., send email, block access after a specified number of days). The built-in compliance report in the Intune portal provides an immediate view of all devices' compliance status without requiring manual scripting or additional tools.

Exam trap

Microsoft often tests the distinction between compliance policies (device-level enforcement with built-in actions) and app protection policies (data-level controls), leading candidates to confuse which policies can enforce BitLocker or trigger time-based blocking.

How to eliminate wrong answers

Option B is wrong because app protection policies (MAM) manage data-level security within apps, not device-level settings like BitLocker or device encryption; they cannot enforce BitLocker or Windows Defender Antivirus. Option C is wrong because device configuration profiles apply settings but do not include built-in actions for noncompliance (like sending email or blocking access after a delay); conditional access alone cannot trigger time-based actions, and manually generating reports with PowerShell is unnecessary when Intune provides a built-in compliance report. Option D is wrong because Autopilot is a deployment tool, not a compliance enforcement mechanism; it cannot enforce passcode length or device encryption on iOS, and Intune reporting is not limited to Autopilot.

538
Multi-Selectmedium

A company uses Microsoft Intune to manage iOS devices. They need to enforce a policy that requires a passcode of at least 6 characters, allows Touch ID, and automatically wipes the device after 10 failed attempts. Which three settings should be configured in a device restrictions profile for iOS? (Choose three.)

Select 3 answers
A.Number of failed attempts before wipe.
B.Maximum passcode age (days).
C.Minimum passcode length.
D.Allow simple passcode.
E.Allow Touch ID.
AnswersA, C, E

This triggers a wipe after 10 failed attempts.

Why this answer

The 'Number of failed attempts before wipe' setting directly enforces the requirement to automatically wipe the device after 10 failed passcode attempts. This setting is part of the device restrictions profile for iOS and triggers a device wipe when the specified threshold of consecutive incorrect passcode entries is reached.

Exam trap

The trap here is that candidates often confuse 'Maximum passcode age' with the wipe-on-failed-attempts setting, or mistakenly think 'Allow simple passcode' is required to enable Touch ID, when in fact Touch ID is a separate toggle that does not depend on simple passcode being allowed.

539
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?

A.Apple Configurator enrollment
B.Device Enrollment Manager (DEM) account
C.Apple Automated Device Enrollment (ADE)
D.User-initiated enrollment via Company Portal
AnswerC

Apple Automated Device Enrollment (ADE) ties corporate-owned iOS devices to Intune through Apple Business Manager, so devices enrol automatically during Setup Assistant without user-driven Company Portal enrolment. This satisfies the stem's requirement that all corporate-owned iOS devices enrol automatically when users sign in with their work account.

Why this answer

Apple Automated Device Enrollment (ADE) is the correct method because it enables zero-touch, automated enrollment for corporate-owned iOS devices. When ADE is configured with Intune, devices are automatically enrolled during the initial setup assistant when the user signs in with their work account, without requiring manual intervention or the Company Portal app.

Exam trap

The trap here is that candidates often confuse Apple Configurator enrollment (a manual, wired method) with ADE (an automated, over-the-air method), or they think user-initiated enrollment via Company Portal can be automated, but it requires manual steps by the user.

How to eliminate wrong answers

Option A is wrong because Apple Configurator enrollment is a manual, wired method intended for small-scale or shared device scenarios, not for automatic enrollment at scale when users sign in. Option B is wrong because the Device Enrollment Manager (DEM) account is used to enroll multiple devices using a single shared account, not to trigger automatic enrollment per user sign-in. Option D is wrong because user-initiated enrollment via Company Portal requires the user to manually download the app and enroll, which does not meet the requirement for automatic enrollment when signing in with a work account.

540
MCQeasy

You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?

A.Change the update ring policy deadline to 7 days to ensure devices have enough time.
B.Create a new feature update policy for KB5001234 and assign it to all devices.
C.Modify the 'Critical Ring' update ring policy to set the quality update deferral period to 0 days and the deadline for updates to 1 day.
D.Use the Windows Server Update Services (WSUS) console to approve the update for immediate installation.
AnswerC

Setting the quality update deferral to 0 days removes the seven-day hold, and a one-day deadline forces installation within the required 24-hour window. Both settings must change together; deferral alone would not guarantee the deadline is enforced on every device.

Why this answer

The update ring policy controls deferral and deadline. To install immediately, set deferral to 0 and deadline to 1 day. Creating a feature update policy is for feature updates, not quality updates.

Manually approving in WSUS is not relevant as Intune manages updates. Changing the deadline to 7 days would not meet the 24-hour requirement.

541
MCQmedium

A company uses Microsoft Intune to manage Windows devices. They want to deploy a custom line-of-business (LOB) app as a Win32 app. The app requires .NET Framework 4.8 and must be installed silently. Which file type should you use for the app deployment in Intune?

A..msi
B..appx
C..intunewin
D..exe
AnswerC

The .intunewin format is the packaged container produced by the Microsoft Win32 Content Prep Tool, which Intune requires to upload Win32 apps. It carries the silent install and uninstall commands plus detection rules, and prerequisite checks such as .NET Framework 4.8 are configured alongside it.

Why this answer

The .intunewin file is required for Win32 app deployment in Intune because it packages the installation files and detection rules into a single format that Intune can process. For a custom LOB app that needs silent installation and has dependencies like .NET Framework 4.8, the .intunewin wrapper allows you to specify the installation command (e.g., msiexec /i app.msi /qn) and detection logic, which is not possible with raw .msi or .exe files in the Win32 app context.

Exam trap

The trap here is that candidates mistakenly think a raw .exe or .msi can be deployed as a Win32 app in Intune, but Intune requires the .intunewin wrapper to handle detection, dependencies, and installation behavior for non-Store apps.

How to eliminate wrong answers

Option A is wrong because .msi files can be deployed directly as line-of-business apps in Intune, but they do not support the Win32 app deployment method's advanced features like custom detection rules, dependencies, or requirement rules; for a Win32 app, you must wrap the .msi in an .intunewin file. Option B is wrong because .appx files are used for Universal Windows Platform (UWP) apps, not Win32 apps, and they require a different deployment pipeline (e.g., Store or LOB app type). Option D is wrong because .exe files cannot be deployed directly as Win32 apps in Intune without being wrapped in an .intunewin file; the .intunewin packaging tool is required to encapsulate the .exe and its installation parameters.

542
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to configure a policy that automatically retires a device if it does not check in for 30 days. Which policy type should you configure?

A.Device configuration policy
B.Compliance policy
C.Windows Update for Business policy
D.Device health attestation policy
AnswerB

Compliance policies can include a grace period and action for non-compliance, including retiring devices after a specified period of inactivity.

Why this answer

A compliance policy in Microsoft Intune can include a 'Maximum days since device last checked in' setting. When a device fails to check in for the specified period (e.g., 30 days), Intune marks it as noncompliant, and a conditional access policy or automated action (such as retiring the device) can be triggered. This directly meets the requirement to automatically retire a device after 30 days of inactivity.

Exam trap

The trap here is that candidates often confuse a device configuration policy (which controls settings) with a compliance policy (which enforces conditions and triggers actions like retirement), leading them to select Option A instead of B.

How to eliminate wrong answers

Option A is wrong because a device configuration policy manages settings like passwords, encryption, and restrictions, but it does not include a check-in timeout or retirement trigger. Option C is wrong because a Windows Update for Business policy controls update deferrals and delivery optimization, not device check-in monitoring or retirement. Option D is wrong because a device health attestation policy verifies boot integrity and security features (e.g., Secure Boot, BitLocker) via the TPM, but it does not enforce a check-in interval or automatic retirement.

543
Multi-Selecthard

You manage a hybrid Azure AD joined Windows 11 device with Microsoft Intune. You need to configure a device compliance policy that requires BitLocker drive encryption and Secure Boot to be enabled. Which two settings must you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require BitLocker
B.Require antivirus
C.Require code integrity
D.Require Trusted Platform Module (TPM)
E.Require Secure Boot to be enabled on the device
AnswersA, E

The 'Require BitLocker' setting in a Windows compliance policy checks whether BitLocker Drive Encryption is enabled on the device. If BitLocker is not enabled, the device is marked noncompliant. This setting directly enforces the requirement for drive encryption and is essential for meeting the scenario's security requirement.

Why this answer

To enforce BitLocker and Secure Boot, you must enable the corresponding settings in a Windows compliance policy. 'Require BitLocker' checks encryption status, and 'Require Secure Boot to be enabled on the device' verifies Secure Boot. The other settings address different security aspects and do not satisfy the requirements.

Exam trap

The trap here is confusing related security features like TPM or code integrity with the specific settings that directly enforce BitLocker and Secure Boot in a compliance policy.

544
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?

A.Device compliance policies.
B.No additional configuration is needed.
C.Device configuration policies.
D.App protection policies.
AnswerA

Conditional Access grants or blocks access based on compliance state, but that state is produced by Intune device compliance policies. Without a compliance policy defining the rules, devices have no evaluated status for the Conditional Access policy to act on.

Why this answer

A is correct because Conditional Access policies in Microsoft Entra ID evaluate device compliance status, but they rely on Intune to report that status. Without a device compliance policy assigned to the device, Intune cannot mark the device as compliant, so the Conditional Access policy will block access or treat the device as non-compliant. You must create and assign a compliance policy in Intune that defines the required security baselines (e.g., encryption, OS version, jailbreak detection) for the device to be considered compliant.

Exam trap

The trap here is that candidates assume Conditional Access policies are self-sufficient for compliance enforcement, overlooking that Intune compliance policies are the required mechanism to generate the compliance state that Conditional Access evaluates.

How to eliminate wrong answers

Option B is wrong because Conditional Access alone cannot enforce compliance; it only checks the compliance status reported by Intune, so additional configuration in Intune is mandatory. Option C is wrong because device configuration policies manage settings like Wi-Fi or VPN profiles, not compliance evaluation; they do not mark a device as compliant or non-compliant for Conditional Access. Option D is wrong because app protection policies (MAM) manage data protection at the app level without requiring device enrollment, but they do not make a device compliant for device-based Conditional Access policies targeting Exchange Online.

545
Multi-Selecthard

An organization is planning to implement a zero-trust security model. They need to evaluate the following capabilities in Microsoft 365. Which THREE are essential for a zero-trust architecture? (Choose three.)

Select 3 answers
A.Azure AD Application Proxy
B.Multi-factor authentication (MFA)
C.Azure AD Connect sync
D.Device compliance policies
E.Conditional Access policies
AnswersB, D, E

MFA directly enforces zero trust's verify-explicitly principle by requiring a second authentication factor, so a compromised password alone cannot grant access. It satisfies the stem's demand for identity verification at every sign-in, blocking credential-based lateral movement and satisfying conditional access policies that Microsoft Entra ID evaluates per session.

Why this answer

Multi-factor authentication (MFA) (B) is essential because zero trust requires strong, verified identity for every access request, and MFA ensures a user's identity is validated with more than a single factor before granting access to Microsoft 365 resources. Device compliance policies (D) are essential because zero trust assumes no implicit trust based on network location, so access must be gated on the health and compliance state of the endpoint (for example, via Intune compliance policies evaluated by Conditional Access). Conditional Access policies (E) are essential because they are the policy engine that ties signals such as user identity, MFA status, device compliance, location, and risk together to enforce least-privilege, adaptive access decisions in Microsoft 365.

Azure AD Application Proxy (A) is not one of the three required capabilities here; it is a remote-access/publishing solution for on-premises web apps and, while useful, is not a core zero-trust pillar in this scenario. Azure AD Connect sync (C) is also not required; it is a directory synchronization tool for hybrid identity and does not itself enforce zero-trust verification or access control.

Exam trap

The trap here is that candidates often confuse infrastructure components (like Azure AD Connect sync or Application Proxy) with security controls, mistakenly thinking they are required for zero trust when they are merely supporting services for hybrid identity or remote access.

546
MCQeasy

Your organization needs to deploy a web app link to users' devices via Microsoft Intune. Which app type should you select?

A.Windows app (Win32)
B.iOS store app
C.Web link
D.Managed Google Play app
AnswerC

A web link in Microsoft Intune deploys a shortcut to a browser-based app, satisfying the requirement to publish a web app link to users' devices. It creates a URL shortcut on managed devices without packaging or installing application binaries, unlike line-of-business or store apps, which require actual installable content.

Why this answer

C is correct because a Web link app type in Microsoft Intune allows you to deploy a shortcut to a web app on users' devices without installing any software. This is ideal for linking to a web app that runs in a browser, as it simply places an icon on the device's app list or home screen that opens the specified URL.

Exam trap

The trap here is that candidates may confuse a Web link app with a full application deployment, thinking they need to select a platform-specific app type (like Win32 or iOS store app) even when the requirement is simply to provide a URL shortcut.

How to eliminate wrong answers

Option A is wrong because a Windows app (Win32) is used for deploying traditional desktop applications via .intunewin files, not for linking to a web app. Option B is wrong because an iOS store app is for deploying native iOS applications from the Apple App Store, not for creating a shortcut to a web URL. Option D is wrong because a Managed Google Play app is for deploying Android apps from the Google Play Store, not for web links.

547
MCQeasy

Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?

A.Disables the Windows Firewall for all network profiles
B.Enables the Windows Firewall for the public network profile
C.Enables Microsoft Defender Antivirus real-time protection
D.Disables the Windows Firewall for the domain network profile
AnswerB

This management intent configures the Windows Defender Firewall's public network profile state, enabling filtering for connections classified as public. It does not govern domain or private profiles, nor does it define inbound or outbound rules.

Why this answer

The setting shown in the exhibit configures the Windows Firewall to enable the firewall for the public network profile. In Intune, the 'Windows Firewall' configuration policy allows administrators to define per-profile firewall states. Enabling the firewall for the public profile is a common security baseline requirement to protect devices on untrusted networks.

Exam trap

The trap here is that candidates confuse the 'Windows Firewall' setting with Microsoft Defender Antivirus real-time protection, or assume the setting disables all profiles when it actually enables a specific profile; the exhibit's focus on a single profile (public) is the key detail to avoid misinterpreting the scope.

How to eliminate wrong answers

Option A is wrong because the setting specifically enables the firewall for the public profile, not disables it for all profiles; disabling all profiles would be a separate configuration. Option C is wrong because this setting controls Windows Firewall, not Microsoft Defender Antivirus real-time protection, which is managed under a different policy category (Endpoint Protection). Option D is wrong because the setting targets the public profile, not the domain profile; disabling the domain profile firewall would be a distinct policy choice and is not what is shown.

548
Multi-Selecthard

Which THREE conditions must be met for a Windows 10 device to be co-managed with Microsoft Intune and Microsoft Configuration Manager? (Choose three.)

Select 3 answers
A.The device must be enrolled in Microsoft Intune.
B.The device must have the Configuration Manager client installed.
C.The device must be Azure AD joined or hybrid Azure AD joined.
D.The device must be hybrid Azure AD joined.
E.The device must have the Intune Management Extension installed.
AnswersA, B, C

Co-management requires the device to be enrolled in Microsoft Intune, establishing the MDM authority alongside Configuration Manager's client agent. Without Intune enrolment, workloads cannot be shifted between the two services, so this condition directly satisfies the stem's requirement for simultaneous management by both tools.

Why this answer

Option A is correct because co-management requires the device to be enrolled in Microsoft Intune, which provides the MDM channel and enables the Intune workload authority alongside Configuration Manager. Option B is correct because the Configuration Manager client must be installed on the device so that the Configuration Manager channel and its workloads can function. Option C is correct because the device must be Azure AD joined or hybrid Azure AD joined to establish the identity and authentication needed for Intune enrollment and co-management.

Option D is not required because hybrid Azure AD join is only one of the acceptable identity states; Azure AD join alone also satisfies the requirement. Option E is not required because the Intune Management Extension is only needed for specific workloads such as PowerShell scripts and Win32 apps, not as a baseline condition for co-management.

Exam trap

The trap here is that candidates often think hybrid Azure AD join is mandatory (Option D), but Microsoft actually allows either Azure AD join or hybrid Azure AD join, and they confuse the Intune Management Extension (Option E) as a prerequisite when it is automatically installed post-enrollment for specific app deployment scenarios.

549
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with a Trusted Platform Module (TPM) version 2.0 and Secure Boot enabled can access corporate email. What should you configure?

A.Create a compliance policy with device health rules.
B.Configure Windows Hello for Business with TPM requirement.
C.Create a conditional access policy that requires compliant device.
D.Create a device configuration policy to enable Secure Boot.
AnswerA

A compliance policy with device health rules evaluates TPM version and Secure Boot status through the device health attestation service. Conditional Access can then require compliant devices before granting Exchange Online access, satisfying the requirement to restrict corporate email.

Why this answer

Intune compliance policies include device health rules that can require specific hardware attributes such as TPM version and Secure Boot status. By creating a compliance policy with these device health requirements and then pairing it with a conditional access policy requiring a compliant device, you enforce that only devices meeting the TPM 2.0 and Secure Boot criteria can access corporate email. The compliance policy is the correct configuration object for defining these hardware requirements.

Exam trap

MD-102 often tests the confusion between configuration policies (which set device settings) and compliance policies (which evaluate and enforce device state) — candidates pick the configuration option because it mentions Secure Boot, missing that enforcement requires a compliance policy plus conditional access.

How to eliminate wrong answers

Option B is wrong because Windows Hello for Business with a TPM requirement governs authentication credential storage, not device access to corporate email — it does not enforce Secure Boot or gate email access based on device health. Option C is wrong because a conditional access policy requiring a compliant device is necessary but insufficient on its own — without a compliance policy defining TPM 2.0 and Secure Boot as requirements, there is nothing for the device to be compliant with. Option D is wrong because a device configuration policy enabling Secure Boot configures the setting but does not enforce it as an access condition for email — configuration and compliance are separate concerns in Intune.

550
MCQhard

You manage Windows 10 devices with Microsoft Intune. You deploy a Win32 app that must run a custom installation script. The script requires a specific environment variable to be set during installation. The app installer does not set this variable. You need to ensure the variable is set only for the installation process and not permanently on the device. What should you do?

A.Create a PowerShell script that sets the environment variable at the machine level, then run the installer.
B.Use a requirement rule to set the environment variable before installation.
C.Configure the app to run in user context and set the variable in the user's profile.
D.Include the environment variable in the install command using the 'cmd /c set VAR=value && installer.exe' syntax.
AnswerD

You can set an environment variable for the duration of the command by using the 'set' command in a command prompt. This sets the variable only for that process and its child processes, so it does not persist on the device after installation. This meets the requirement.

Why this answer

Using the 'set' command within the install command line sets the environment variable only for that command's process. The variable is not written to the registry or user profile, so it does not persist after the installation completes. This satisfies the requirement of a temporary variable.

Exam trap

The trap here is assuming that any method of setting an environment variable will work, but permanent or user-specific settings violate the requirement for a temporary, process-scoped variable.

551
MCQmedium

You are implementing Windows Autopilot for your organization. You need to ensure that during the first boot, the device automatically enrolls in Microsoft Intune and joins Microsoft Entra ID. What is the minimum requirement for the device?

A.The device must have a local administrator account.
B.The device must be joined to an on-premises Active Directory domain.
C.The device must have a TPM 2.0 chip.
D.The device must be registered in Autopilot with a valid profile.
AnswerD

Autopilot requires the device hardware hash registered as an Autopilot device and assigned a deployment profile; without this, the Out-of-Box Experience cannot pull the Microsoft Entra ID join and Intune enrolment configuration, so registration plus a valid profile is the minimum.

Why this answer

Windows Autopilot requires the device to be registered in the Autopilot service with a valid profile assigned. This profile contains the settings that dictate the out-of-box experience (OOBE), including automatic enrollment into Microsoft Intune and joining Microsoft Entra ID (formerly Azure AD). Without a registered Autopilot profile, the device will not trigger the automated enrollment and join process during first boot.

Exam trap

The trap here is that candidates often confuse hardware prerequisites (like TPM 2.0) with the mandatory requirement of a registered Autopilot profile, leading them to select Option C instead of D.

How to eliminate wrong answers

Option A is wrong because a local administrator account is not a prerequisite for Autopilot; the device can be a standard user device and still enroll via Autopilot. Option B is wrong because Autopilot devices are designed to join Microsoft Entra ID directly, not an on-premises Active Directory domain; hybrid join is an optional configuration, not a minimum requirement. Option C is wrong because while TPM 2.0 is recommended for self-deploying mode and Windows Hello for Business, it is not a minimum requirement for user-driven Autopilot enrollment and Entra ID join; devices without TPM 2.0 can still use user-driven mode with password-based authentication.

552
MCQhard

You have assigned the compliance policy shown in the exhibit to all Windows devices. A Windows 11 device running build 10.0.22621.1500 reports as noncompliant. Which setting is causing the noncompliance?

A.OS version is above the maximum allowed
B.Password minimum length is not met
C.Device threat protection level is below medium
D.TPM is not present
AnswerA

The minimum OS version requirement exceeds build 10.0.22621.1500, so the device falls below the compliance threshold. Microsoft Entra ID marks it noncompliant because the assigned policy's minimum version constraint is unmet, not because of any maximum-version ceiling.

Why this answer

The compliance policy in the exhibit specifies a maximum OS version of 10.0.22621.1000, but the Windows 11 device is running build 10.0.22621.1500, which is above that maximum. Intune compares the device's OS version against the configured maximum OS version setting; if the device's version exceeds the maximum, it is marked as noncompliant. This setting is used to prevent devices with newer, potentially untested builds from accessing corporate resources.

Exam trap

The trap here is that candidates often assume noncompliance is due to missing security features like TPM or password policies, but the exhibit clearly shows a maximum OS version setting that the device's build exceeds, making it the direct cause.

How to eliminate wrong answers

Option B is wrong because the compliance policy does not include a password minimum length requirement, so the device cannot be noncompliant due to that setting. Option C is wrong because the policy does not configure a device threat protection level; the device threat protection setting is not present in the exhibit, so it cannot cause noncompliance. Option D is wrong because the policy does not require TPM presence; the TPM setting is not configured in the exhibit, so a missing TPM would not trigger noncompliance.

553
MCQeasy

Your organization uses Microsoft Intune to manage Android devices. You need to deploy an app that is available in the Managed Google Play store as a required app. What must you do first?

A.Connect Intune to the Managed Google Play store.
B.Enroll the device in Intune.
C.Install the Managed Google Play app on the device.
D.Upload the app package to Intune.
AnswerA

Approving and deploying Managed Google Play apps requires an established binding between Intune and the Managed Google Play store, so connecting them is the prerequisite. Without this link, Intune cannot browse, approve, or assign required apps to Android devices.

Why this answer

To deploy a required app from the Managed Google Play store, you must first establish the connection between Intune and the Managed Google Play store. This connection is a prerequisite because Intune uses it to synchronize apps, manage licenses, and push required apps to Android devices. Without this connection, Intune cannot access or deploy any apps from the Managed Google Play store.

Exam trap

The trap here is that candidates often think device enrollment (Option B) is the first step, but the connection to Managed Google Play must be established first because Intune cannot deploy any apps from the store without it.

How to eliminate wrong answers

Option B is wrong because enrolling the device in Intune is necessary for app deployment, but it is not the first step; the Intune-to-Managed Google Play connection must be established before any app deployment can occur. Option C is wrong because the Managed Google Play app is automatically installed on Android devices during the enrollment process when the connection is configured, so manually installing it is not a prerequisite. Option D is wrong because you do not upload app packages to Intune for Managed Google Play apps; instead, you approve and sync apps from the Managed Google Play store after the connection is established.

554
MCQhard

An administrator deploys a Win32 app via Intune with detection rule 'File exists: C:\Program Files\MyApp\app.exe'. The app is reported as installed, but users cannot launch it. The file exists but is corrupted. How should the administrator modify the detection rule to ensure the app is correctly detected and re-installed if corrupted?

A.Remove the detection rule so Intune always re-installs the app
B.Add a registry detection rule for the app's uninstall key
C.Use a custom detection script that validates the file hash or signature
D.Change detection rule to 'File version comparison' and set minimum version
AnswerC

A file-exists rule only confirms presence, so a corrupted app.exe still reports as installed and Intune never remediates it. A custom detection script validating the file hash or signature detects corruption, causing Intune to treat the app as non-compliant and reinstall it.

Why this answer

A custom detection script can verify the file's integrity by checking its hash or digital signature, ensuring that even if the file exists, it is not corrupted. Intune's built-in detection rules only check for file existence or version, not file integrity. By using a script that validates the hash, the administrator can force a reinstall when the file is corrupted, as the detection will fail.

Exam trap

The trap here is that candidates assume 'File exists' or 'File version comparison' are sufficient for detection, overlooking that these rules do not validate file integrity, which is a common misconception in Intune app deployment scenarios.

How to eliminate wrong answers

Option A is wrong because removing the detection rule would cause Intune to always reinstall the app on every sync, leading to unnecessary bandwidth and user disruption, and it does not solve the corruption detection issue. Option B is wrong because adding a registry detection rule for the uninstall key only confirms the app was installed via the registry, not that the executable is uncorrupted; the uninstall key remains even if the file is corrupted. Option D is wrong because 'File version comparison' only checks the version number of the file, not its integrity; a corrupted file can still have the correct version metadata, so this would not trigger a reinstall.

555
Multi-Selecteasy

Which TWO app types are available for deploying apps to iOS/iPadOS devices in Microsoft Intune? (Choose two.)

Select 2 answers
A.Web link
B.iOS/iPadOS app store app
C.Windows app (Win32)
D.Android Line-of-business app
E.iOS/iPadOS Line-of-business app
AnswersB, E

The iOS/iPadOS app store app type deploys apps sourced directly from the Apple App Store, linking to the store listing rather than hosting a package. This is one of the two supported iOS/iPadOS deployment types in Microsoft Intune, alongside line-of-business or store apps.

Why this answer

Option B (iOS/iPadOS app store app) is correct because Intune supports deploying apps directly from the Apple App Store to managed iOS/iPadOS devices, either as required or available installs, using the built-in app type for store-published apps. Option E (iOS/iPadOS Line-of-business app) is correct because Intune allows uploading and assigning custom in-house .ipa packages for iOS/iPadOS, which is the standard method for distributing proprietary enterprise apps. Option A (Web link) is not an iOS/iPadOS-specific app type in this context; it is a generic web link app type used across platforms to pin a URL, not a native iOS app deployment type.

Option C (Windows app (Win32)) is incorrect because Win32 apps target Windows devices, not iOS/iPadOS. Option D (Android Line-of-business app) is incorrect because Android LOB apps are for Android devices and use .apk or .aab packages, not iOS/iPadOS.

Exam trap

The trap here is that candidates often confuse web links (shortcuts) with actual app deployments, or mistakenly think platform-specific app types like Win32 or Android LOB can be cross-deployed, but Intune strictly enforces app type per OS platform.

556
Multi-Selecthard

You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)

Select 2 answers
A.Deploy a PowerShell script to modify the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU to point to Intune.
B.Enable the 'Microsoft Update' option in the Windows Update settings on each device.
C.Remove the WSUS Group Policy settings from the device.
D.Configure a conditional access policy to block WSUS traffic.
E.Enroll the device in Microsoft Intune and assign a Windows Update ring.
AnswersC, E

For Intune to manage Windows updates, the device must not be configured to use WSUS via Group Policy. Removing the WSUS settings ensures that the Windows Update client does not point to an on-premises server, allowing Intune update rings to take effect. This is a necessary step.

Why this answer

To transition from WSUS to Intune update management, you must remove the WSUS Group Policy settings that direct the device to the on-premises server, and then enroll the device in Intune and assign a Windows Update ring. These two actions ensure that Intune policies take precedence and manage update delivery.

Exam trap

The trap here is thinking that Intune can override existing WSUS Group Policy settings automatically, when in fact WSUS GPOs must be removed first for Intune update rings to apply.

Page 7

Page 8 of 8

All pages