Courseiva

Microsoft 365 Endpoint Administrator MD-102 (MD-102) — Questions 601675

942 questions total · 13pages · All types, answers revealed

Page 8

Page 9 of 13

Page 10
601
Multi-Selecteasy

Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)

Select 2 answers
A.Use the iOS Microsoft 365 Apps deployment method.
B.Package the Office Deployment Tool as a Win32 app.
C.Upload an MSI file for Microsoft 365 Apps.
D.Use the built-in Microsoft 365 Apps deployment for Windows 10 and later.
E.Add a web link to the Office 365 portal.
AnswersB, D

The Office Deployment Tool can be wrapped as a Win32 app.

Why this answer

The Office Deployment Tool (ODT) can be packaged as a Win32 app in Intune, allowing administrators to customize the installation of Microsoft 365 Apps (e.g., select specific products, languages, and update channels) and deploy it to Windows devices via the Microsoft Intune Management Extension. Option D is correct because Intune provides a built-in 'Microsoft 365 Apps for Windows 10 and later' deployment profile that simplifies the process by automatically configuring the installation using the ODT under the hood, requiring only a few settings in the Intune console.

Exam trap

The trap here is that candidates often confuse the built-in Microsoft 365 Apps deployment profile with a simple 'add an app' wizard, leading them to mistakenly think an MSI upload (Option C) is valid for Office, when in fact Intune only supports Click-to-Run installations for Microsoft 365 Apps via ODT-based methods.

602
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft 365 Apps for enterprise suite to all devices. Which app type should you use in Intune?

A.Web link
B.Windows app (Win32)
C.Microsoft 365 Apps for Windows 10 and later
D.Line-of-business app
AnswerC

This app type is specifically designed for deploying Office 365 ProPlus.

Why this answer

To deploy Microsoft 365 Apps for enterprise, use the 'Microsoft 365 Apps for Windows 10 and later' app type in Intune. This pre-configured app type handles the installation and updates of the Office suite. Option C is correct.

Option A (Web link) is wrong because it only creates a shortcut, not installs the app. Option B (Windows app (Win32)) is wrong because it is used for standalone .exe or .msi installers, not for the Office suite which has its own dedicated type. Option D (Line-of-business app) is wrong because it is intended for custom or in-house developed apps, not for Microsoft 365 Apps.

Exam trap

Candidates often confuse the 'Windows app (Win32)' type with the 'Microsoft 365 Apps' type. Remember that for Microsoft 365 Apps, you must use the dedicated app type in Intune.

603
MCQhard

Refer to the exhibit. You have configured the above enrollment restriction in Microsoft Intune. A user attempts to enroll a personal Windows 11 device. What will be the outcome?

A.The device will be blocked from enrolling.
B.The device will be prompted to confirm enrollment.
C.The device will enroll but will be marked as non-compliant.
D.The device will enroll successfully because it meets the OS requirements.
AnswerA

The restriction blocks personal Windows devices from enrolling.

Why this answer

The enrollment restriction is configured to block personally owned Windows devices. Since the user is trying to enroll a personal Windows 11 device, enrollment will be blocked regardless of OS version. Option B is incorrect because no prompt is shown; it's a block, not a prompt.

Option C is incorrect because enrollment is blocked, so the device never becomes non-compliant. Option D is incorrect because the restriction specifically blocks personal devices, so OS version does not matter; enrollment fails.

604
Multi-Selecthard

An organization uses Configuration Manager to manage Windows 10 devices. The administrator is configuring a phased deployment for a software update. Which THREE conditions can be used to define the phases?

Select 3 answers
A.Collection membership
B.Time-based delay between phases
C.Percentage of clients
D.Device compliance status
E.Manual approval for next phase
AnswersA, C, E

Phases can target specific collections.

Why this answer

Collection membership (A) is correct because Configuration Manager phased deployments allow you to specify a target collection for each phase, such as a collection containing pilot devices for the first phase and a broader collection for subsequent phases. This enables granular control over which devices receive the update at each stage, based on existing collection membership rules.

Exam trap

The trap here is that candidates confuse phased deployment conditions with general deployment options, mistakenly thinking time-based delays or compliance status are valid phase criteria, when only collection membership, percentage of clients, and manual approval are supported.

605
Multi-Selectmedium

Which TWO methods can you use to enroll macOS devices in Microsoft Intune?

Select 2 answers
A.Google Zero Touch Enrollment
B.Windows Autopilot
C.User-initiated enrollment via Company Portal
D.Apple Configurator
E.Automated Device Enrollment (ADE)
AnswersC, E

Users can enroll manually.

Why this answer

The Company Portal app on macOS allows users to initiate enrollment themselves, which registers the device with Microsoft Intune and applies compliance policies. This method is suitable for bring-your-own-device (BYOD) scenarios where the user controls enrollment. Option E is correct because Automated Device Enrollment (ADE), formerly DEP, uses Apple Business Manager to silently enroll corporate-owned macOS devices during initial setup, enforcing Intune management without user intervention.

Exam trap

The trap here is that candidates often confuse Apple Configurator (which is only for iOS/iPadOS manual enrollment) with Automated Device Enrollment (ADE), or they mistakenly think Windows Autopilot or Google Zero Touch Enrollment can be repurposed for macOS, when in fact each platform has its own distinct enrollment mechanisms.

606
Multi-Selectmedium

Your company uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft Store app (new) to a group of users. Which TWO requirements must be met?

Select 2 answers
A.The device must be joined to an on-premises Active Directory domain
B.The device must have the Microsoft Intune Management Extension installed
C.The device must have sideloading enabled
D.The device must be Azure AD joined or hybrid Azure AD joined
E.The user must have a valid Microsoft account or Azure AD account
AnswersD, E

Required for Intune management.

Why this answer

Microsoft Store apps (new) require the device to be Azure AD joined or hybrid Azure AD joined to support license enforcement and user-based app assignment via Intune. This ensures the device can authenticate with the Microsoft Store for Business and Education to download and install the app under the user's identity.

Exam trap

The trap here is that candidates often confuse the requirements for Microsoft Store apps (new) with those for Win32 apps, mistakenly thinking the Intune Management Extension or sideloading is needed, when in fact Azure AD join and a valid Azure AD account are the key prerequisites.

607
Multi-Selecthard

Which THREE components are required to deploy a Win32 app via Microsoft Intune?

Select 3 answers
A.Detection rule
B.A .intunewin file
C.PowerShell script for post-installation
D.Dependency on another app
E.Install command
AnswersA, B, E

Detection rules determine whether the app is already installed.

Why this answer

A detection rule is required because Intune needs a method to verify whether the Win32 app is already installed on the device. Without a detection rule, Intune cannot determine if the installation succeeded or if the app needs to be reinstalled. The detection rule can be based on a file, registry key, or custom script, and it is mandatory for any Win32 app deployment.

Exam trap

The trap here is that candidates often confuse optional features like dependencies or post-installation scripts with required components, leading them to select those options instead of the three mandatory ones: detection rule, .intunewin file, and install command.

608
MCQhard

You are troubleshooting a Windows 10 device that is not receiving Intune policies. The device is enrolled and shows as 'Active' in the Intune admin center. You run the Get-MgDeviceManagementManagedDevice cmdlet and the device's managementAgent is 'mdm'. Which of the following is the most likely cause of the issue?

A.The device is co-managed and the workload is set to Configuration Manager.
B.The device's enrollment certificate has expired.
C.The device's last sync time is more than 24 hours ago.
D.The device is retired from Intune.
AnswerC

A device that has not synced recently will not receive new policies.

Why this answer

The device's last sync time being more than 24 hours ago indicates that the device has not checked in with Intune within the required interval. Intune policies are delivered during a sync cycle, and if the device hasn't synced recently, it will not receive new or updated policies. The managementAgent being 'mdm' confirms the device is MDM-managed, so the sync interval is critical for policy delivery.

Exam trap

The trap here is that candidates often assume an 'Active' status means the device is fully communicating, but Intune's 'Active' status only indicates successful enrollment, not recent policy sync; the last sync time is the key metric for policy delivery.

How to eliminate wrong answers

Option A is wrong because co-management with the workload set to Configuration Manager would mean that Configuration Manager handles the specific workload (e.g., compliance policies), but the device would still receive other Intune policies unless the workload is explicitly set to Configuration Manager for the policy type in question. Option B is wrong because an expired enrollment certificate would prevent the device from authenticating with Intune entirely, causing it to show as 'Pending' or 'Unhealthy', not 'Active'. Option D is wrong because a retired device would be removed from Intune management and would not show as 'Active' in the admin center.

609
MCQeasy

You deploy a Microsoft 365 Apps for enterprise suite via Intune to Windows devices. Users report that updates are not being applied automatically. You need to ensure that updates are installed from the Office Content Delivery Network (CDN) without user intervention. What should you configure?

A.Configure Delivery Optimization to download from peers.
B.Configure the Office update channel via an Intune administrative template (ADMX).
C.Enable Windows Update for Business to manage Office updates.
D.Use the Office Deployment Tool to set update settings.
AnswerB

ADMX templates allow setting update path to CDN.

Why this answer

Configuring the Office update channel via an Intune administrative template (ADMX) directly sets the registry policy that controls which update channel (e.g., Monthly Enterprise) Office 365 Apps use, and by default, those updates are delivered from the Office Content Delivery Network (CDN) without user intervention. This policy ensures updates are applied automatically in the background, meeting the requirement for no user interaction.

Exam trap

The trap here is that candidates often confuse Windows Update for Business with Office update management, not realizing that Office 365 Apps have their own independent update mechanism (Click-to-Run) that must be configured separately via Office-specific policies, not through Windows Update policies.

How to eliminate wrong answers

Option A is wrong because Delivery Optimization controls peer-to-peer distribution of Windows and Office updates, but it does not configure the update source or channel; it only optimizes bandwidth after the update source is already set. Option C is wrong because Windows Update for Business manages Windows updates, not Office 365 Apps updates; Office updates are handled independently via the Office Click-to-Run servicing stack and require separate configuration. Option D is wrong because the Office Deployment Tool (ODT) is used for initial deployment and configuration of Office, but it is not the recommended method for ongoing update management in an Intune-managed environment; Intune administrative templates provide a more integrated and policy-driven approach.

610
MCQmedium

Refer to the exhibit. The ARM template snippet attempts to deploy a Windows 10 Security Baseline policy in Intune. The deployment fails. What is the most likely reason?

A.Intune configuration policies cannot be deployed via ARM templates.
B.The apiVersion is not supported.
C.The templateId is incorrect.
D.The setting value is invalid.
AnswerA

Intune uses Microsoft Graph, not ARM.

Why this answer

Intune does not support deploying Windows 10 Security Baseline policies via ARM templates because ARM templates are designed for Azure resource management (e.g., Azure VMs, storage accounts) and cannot directly manage Intune workloads. Intune policies, including Security Baselines, must be configured through Microsoft Graph API, PowerShell, or the Intune portal, not through Azure Resource Manager.

Exam trap

The trap here is that candidates assume ARM templates can deploy any Azure-adjacent service, but Intune is a Microsoft 365 workload that uses a separate management plane (Microsoft Graph) and is not integrated with Azure Resource Manager for policy deployment.

How to eliminate wrong answers

Option B is wrong because the apiVersion (e.g., '2018-08-01-beta') is a valid and supported version for Intune resources in ARM templates, though the resource type itself is not deployable via ARM. Option C is wrong because the templateId (e.g., 'Microsoft.Windows10.SecurityBaseline') is a correct identifier for the Windows 10 Security Baseline policy within Intune's context, but the issue is not the ID—it's the deployment method. Option D is wrong because the setting value (e.g., 'Enabled') is a valid configuration for the baseline setting; the failure occurs before any value validation, as ARM cannot process Intune policy resources at all.

611
MCQeasy

A user reports that their Android Enterprise work profile device is not receiving email from the corporate Exchange Online account. The device is enrolled in Intune and shows as compliant. The Outlook app is installed but cannot connect. What should you check first?

A.Email profile configuration in Intune
B.App protection policy settings
C.Device compliance policy settings
D.Intune license assignment
AnswerA

Misconfigured server address or authentication method prevents connection.

Why this answer

The most common reason for an Outlook connection failure on a compliant Android Enterprise work profile device is an incorrect email profile configuration in Intune. Since the device is compliant and licensed, and app protection policies affect data leakage rather than connectivity, the first step should be to verify the email profile settings (server, authentication method, and user identity) in the Intune console. Option A is correct.

612
Multi-Selectmedium

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy a line-of-business (LOB) app that is not available in the Microsoft Store. The app is packaged as an .msi file. Which TWO steps are required to deploy this app via Intune?

Select 2 answers
A.Upload the .msi file directly as a Microsoft Store for Business app.
B.Install the app on a file server and configure a shortcut.
C.Assign the app to a group of users or devices.
D.Convert the .msi file to the .intunewin format using the Microsoft Win32 Content Prep Tool.
E.Create a PowerShell script to install the app silently.
AnswersC, D

App must be assigned to a target group.

Why this answer

After preparing the Win32 app, you must assign it to a group of users or devices in Intune to trigger deployment. Without assignment, the app is uploaded but not installed on any target. This step is mandatory for any Intune-managed app deployment.

Exam trap

The trap here is that candidates often think uploading the .msi directly is sufficient, but Intune requires the .intunewin wrapper for Win32 apps, and they may also mistakenly believe a PowerShell script is mandatory for silent installation when the .msi’s built-in silent switches can be specified in the app deployment configuration.

613
MCQhard

You have an Intune-managed device that is not receiving compliance policies. You check the Intune console and see the device status is 'Pending'. The device is connected to the internet and can sync. What is the most likely cause?

A.The device's time zone is incorrect
B.The device's certificate has expired
C.The device has not checked in with Intune for more than 7 days
D.The device is not connected to the internet
AnswerC

If a device does not check in, its status becomes pending.

Why this answer

A 'Pending' status in Intune often indicates that the device has not checked in for more than 7 days, even if it can sync. Option A is incorrect because an incorrect time zone would not cause a pending status; it might cause other issues but not pending. Option B is incorrect because an expired certificate would typically show an error or conflict status, not pending.

Option D is incorrect because the device is connected to the internet and can sync, so network connectivity is not the issue.

614
MCQmedium

You manage Windows 10 devices with Intune. You need to ensure that only approved apps can run on corporate devices. You configure AppLocker via a custom OMA-URI. However, users can still run unapproved apps. What is the most likely reason?

A.The device must be running Windows 10 Pro edition.
B.AppLocker rules can only be configured via Group Policy, not OMA-URI.
C.The AppLocker policy is set to 'Audit only' mode.
D.The policy is assigned to a device group instead of a user group.
AnswerC

Correct. 'Audit only' mode logs application execution events but does not block unapproved apps, allowing them to run.

Why this answer

When AppLocker is configured via custom OMA-URI in Intune, the policy is device-based and can be assigned to device groups. However, if the policy is set to 'Audit only' mode, it only logs events without actually blocking applications. This allows users to still run unapproved apps.

Option D is incorrect because assigning the policy to a device group does enforce AppLocker rules; the issue here is mode enforcement, not assignment type.

Exam trap

The trap is that candidates may overlook the enforcement mode of AppLocker policies, assuming they block by default, when 'Audit only' mode is a common configuration that logs but does not prevent execution.

How to eliminate wrong answers

Option A is wrong because AppLocker is supported on Windows 10 Enterprise and Education editions, not Pro; Pro edition lacks the AppLocker service and rule enforcement. Option B is wrong because AppLocker rules can be configured via OMA-URI using the ./Vendor/MSFT/AppLocker CSP, which is a supported method in Intune for Windows 10/11 devices. Option C is wrong because if the policy were in 'Audit only' mode, unapproved apps would still be allowed to run but events would be logged; the question states users can run unapproved apps, which could also happen in audit mode, but the most likely reason given the scenario is the assignment target mismatch.

615
Multi-Selecthard

Which TWO of the following are valid reasons to use Windows Autopilot Reset? (Select TWO.)

Select 2 answers
A.To reassign a device to a new user without re-imaging.
B.To enroll a new device that was not purchased through an OEM.
C.To change a device from Azure AD joined to Hybrid Azure AD joined.
D.To deploy a custom Windows image to a device.
E.To quickly resolve device performance issues by resetting to a clean state.
AnswersA, E

Autopilot Reset allows repurposing a device quickly.

Why this answer

Options A and E are correct. Windows Autopilot Reset returns an already-enrolled device to a clean, ready-to-use state without re-imaging, preserving hardware identity and enrollment. Option A is correct because it allows reassigning a device to a new user quickly.

Option E is correct because it resolves performance issues by resetting to a clean state. Options B, C, and D are incorrect: Autopilot Reset does not enroll new devices (B), does not change Azure AD join type (C), and does not deploy custom images (D).

Exam trap

The trap here is that candidates often confuse Autopilot Reset with a full re-imaging or enrollment tool, leading them to select options B or D, when in fact Autopilot Reset is strictly a reset-to-clean-state mechanism for already-enrolled devices, not a deployment or enrollment method.

616
MCQhard

During a Windows 10 in-place upgrade using Configuration Manager, the task sequence fails with error code 0x800706BE. The smsts.log shows 'Failed to run the action: Upgrade Operating System'. What is the most likely cause?

A.Incompatible third-party drivers
B.Corrupted setup files in the OS upgrade package
C.Insufficient disk space on the system drive
D.Antivirus software blocking the upgrade process
AnswerD

Antivirus can block RPC calls, causing 0x800706BE.

Why this answer

Error code 0x800706BE is a generic 'The remote procedure call failed' error, which in the context of a Configuration Manager task sequence during an in-place upgrade is most commonly caused by antivirus software interfering with the setup process. Antivirus real-time scanning can lock files or block critical RPC calls that the Windows Setup engine requires, leading to the 'Failed to run the action: Upgrade Operating System' failure in smsts.log.

Exam trap

The trap here is that candidates often associate error 0x800706BE with generic setup corruption or disk space issues, but Microsoft specifically documents this RPC error as being caused by third-party security software blocking the upgrade process.

How to eliminate wrong answers

Option A is wrong because incompatible third-party drivers typically cause hardware-specific errors like 0x80070570 or 0x80070002, not the RPC-related 0x800706BE. Option B is wrong because corrupted setup files usually result in file hash mismatch errors (e.g., 0x80070017) or extraction failures, not an RPC failure. Option C is wrong because insufficient disk space triggers a specific error code 0x80070070 or a 'Not enough space' message in setupact.log, not 0x800706BE.

617
MCQmedium

Refer to the exhibit. You configure this Enrollment Status Page (ESP) policy for Windows Autopilot deployments. During a deployment, a device fails to install a required app. What happens?

A.The device will be blocked from use until the app is installed or the device is reset.
B.The user can retry the installation manually.
C.The timeout will extend by 60 minutes.
D.The device will automatically retry the installation.
AnswerA

The policy blocks use on failure.

Why this answer

The Enrollment Status Page (ESP) policy in Windows Autopilot can be configured to block device use until all required apps are installed. When a required app fails to install, the ESP enters a blocking state, preventing the user from accessing the desktop until the installation succeeds or the device is reset. This behavior is controlled by the 'Block device use until required apps are installed' setting in the ESP profile.

Exam trap

The trap here is that candidates often assume the ESP will automatically retry or extend the timeout, but the correct behavior is that the device is blocked indefinitely until the required app installs or the device is reset.

How to eliminate wrong answers

Option B is wrong because the ESP blocking state does not allow the user to manually retry the installation; the device remains blocked until the app installs or is reset. Option C is wrong because the ESP timeout extension (e.g., 60 minutes) applies only to the overall ESP timeout, not to a failed app installation; the blocking state persists indefinitely until resolved. Option D is wrong because the device does not automatically retry the installation; the ESP waits for the app to be installed via Intune management, but no automatic retry mechanism is triggered by the ESP itself.

618
MCQmedium

You need to deploy Microsoft 365 Apps to 500 Windows 10 devices managed by Intune. The deployment must be automatic and should not require user interaction. What is the best method?

A.Create a Configuration Manager application and deploy to the devices.
B.Use the Office Deployment Tool (ODT) to create a package and deploy via Intune as a line-of-business (LOB) app.
C.Create a Win32 app in Intune with the installation command for Microsoft 365 Apps.
D.Assign the Microsoft 365 Apps from the Microsoft Store for Business.
AnswerC

Win32 apps allow silent deployment and can be assigned to devices.

Why this answer

Creating a Win32 app in Intune allows you to use the Office Deployment Tool (ODT) with a custom configuration.xml to install Microsoft 365 Apps silently. This method supports automatic, unattended deployment to 500 Windows 10 devices managed by Intune, as Win32 apps can be assigned with required intent and run in system context without user interaction.

Exam trap

The trap here is that candidates confuse the Office Deployment Tool (ODT) with the line-of-business (LOB) app method, not realizing that LOB apps cannot handle the multi-file ODT package and require a single installer file, making Win32 app the only viable Intune-native option for silent, automated Office deployment.

How to eliminate wrong answers

Option A is wrong because Configuration Manager is a separate on-premises management tool, not the best method for devices already managed solely by Intune; it introduces unnecessary complexity and requires additional infrastructure. Option B is wrong because deploying via Intune as a line-of-business (LOB) app is not suitable for Microsoft 365 Apps; LOB apps are intended for single-file installers (e.g., .msi or .exe) and do not support the multi-file ODT package or the required detection and installation logic for Office. Option D is wrong because the Microsoft Store for Business is deprecated and does not support deploying Microsoft 365 Apps to Windows 10 devices managed by Intune; it was designed for Universal Windows Platform (UWP) apps, not Win32 Office installations.

619
MCQmedium

Your company uses Microsoft Intune to manage Windows 10 devices. You have a compliance policy that requires devices to have a minimum of 4GB RAM and 64GB disk space. Several devices are marked non-compliant due to disk space. You check the devices and find they have 60GB free. The compliance policy checks total disk capacity, not free space. You need to allow these devices to be compliant. What should you do?

A.Upgrade the disk on these devices to 128GB.
B.Change the compliance policy to check free disk space instead of total capacity.
C.Modify the compliance policy to require a minimum of 60GB disk capacity.
D.Create a script to free up disk space on the devices.
AnswerC

This accommodates the existing hardware.

Why this answer

The compliance policy in Microsoft Intune checks total disk capacity, not free space. By lowering the minimum required total disk capacity to 60GB, devices with 60GB total disk space will meet the policy requirement and become compliant, without needing hardware changes or scripts.

Exam trap

The trap here is that candidates confuse 'free disk space' with 'total disk capacity,' assuming the policy can be changed to check free space, but Intune's built-in compliance policies only evaluate total capacity.

How to eliminate wrong answers

Option A is wrong because upgrading disks to 128GB is unnecessary and costly; the issue is the policy threshold, not hardware inadequacy. Option B is wrong because Intune compliance policies for Windows 10 devices do not support checking free disk space; they only evaluate total disk capacity. Option D is wrong because freeing up disk space does not change the total disk capacity, which is what the policy evaluates.

620
MCQmedium

You are reviewing the Intune Win32 app configuration for FinanceApp. The app fails to install on a Windows 10 device running version 1809. The installation log shows no errors. What is the most likely reason?

A.The detection rule finds the finance.exe file already exists.
B.The device does not meet the minimum Windows release requirement.
C.The install experience is set to system but the device is user enrolled.
D.The install command line is missing a silent switch.
AnswerA

The detection rule uses 'exists' and if the file is present, Intune considers the app installed.

Why this answer

The app fails to install because the detection rule is configured to check for the existence of finance.exe. Since the file already exists on the device from a previous installation, Intune's detection logic determines the app is already installed and does not run the installation again. No errors appear because the installation process is never initiated.

Option B is incorrect because the device runs Windows 10 version 1809, which meets the minimum release requirement (10.0.16299). Option C is incorrect because the install experience can be set to system regardless of enrollment type. Option D is incorrect because the install command line includes the silent switch as required.

621
Multi-Selectmedium

Which TWO actions can you perform using the Microsoft Intune admin center to manage a Windows device that is enrolled in Intune?

Select 2 answers
A.Format the hard disk
B.Restart the device
C.Sync the device
D.Install a printer driver
E.Change BIOS settings
AnswersB, C

Restart is a supported remote action.

Why this answer

The Microsoft Intune admin center provides a 'Restart' remote action that triggers a reboot on a managed Windows device. This action is useful for applying pending updates or troubleshooting without requiring end-user interaction, and it leverages the Intune management extension to execute the restart command.

Exam trap

The trap here is that candidates may confuse Intune's remote actions with full remote control capabilities (like SCCM's remote tools) and assume actions like formatting or driver installation are possible, when in fact Intune only supports a limited set of non-destructive management actions such as restart, sync, wipe, and retire.

622
MCQhard

Your company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a configuration that requires users to use Windows Hello for Business (WHfB) and prohibits the use of FIDO2 security keys. Which CSP and value should you configure?

A.Set 'UseFIDO2' to 0 in the PassportForWork CSP.
B.Set 'EnableWindowsHelloForBusiness' to true in the PassportForWork CSP.
C.Set 'RequireSecurityDevice' to true in the PassportForWork CSP.
D.Set 'UseFIDO2' to 1 in the PassportForWork CSP.
AnswerA

This disables FIDO2 security keys while WHfB is enabled via other policies.

Why this answer

The 'UseFIDO2' setting in the PassportForWork CSP controls whether FIDO2 security keys can be used as a credential. Setting it to 0 explicitly disables FIDO2 keys, which meets the requirement to prohibit their use. The question also requires users to use Windows Hello for Business (WHfB), but that is a separate prerequisite—the 'UseFIDO2' value directly addresses the prohibition of FIDO2 keys.

Exam trap

The trap here is that candidates confuse the 'UseFIDO2' setting with enabling WHfB or TPM requirements, assuming that prohibiting FIDO2 keys is achieved by enabling WHfB or requiring a security device, when in fact it is a separate policy that must be explicitly set to 0.

How to eliminate wrong answers

Option B is wrong because 'EnableWindowsHelloForBusiness' to true enables WHfB but does not prohibit FIDO2 security keys; it only ensures WHfB is available. Option C is wrong because 'RequireSecurityDevice' to true mandates a Trusted Platform Module (TPM) for WHfB key generation, which is unrelated to blocking FIDO2 keys. Option D is wrong because 'UseFIDO2' to 1 would enable FIDO2 security keys, which is the opposite of the requirement to prohibit them.

623
Multi-Selectmedium

Which TWO actions should you take to ensure that Windows Update for Business settings are applied to all Windows 10 devices in your organization? (Choose two)

Select 2 answers
A.Configure a WSUS server to synchronize updates.
B.Create an update ring policy in Microsoft Intune.
C.Assign the update ring policy to a Microsoft Entra ID group that contains all devices.
D.Enable peer-to-peer content sharing for Windows updates.
E.Create a device compliance policy to enforce update installation.
AnswersB, C

Update ring policies configure Windows Update for Business settings.

Why this answer

B is correct because Windows Update for Business (WUfB) policies are configured through update ring policies in Microsoft Intune, which control how and when Windows 10 devices receive updates from Microsoft's update servers. This allows organizations to manage update deployment without needing on-premises infrastructure like WSUS.

Exam trap

The trap here is that candidates often confuse WSUS with Windows Update for Business, thinking both are required, or they mistakenly believe a compliance policy can enforce update ring settings, when in fact update rings are a separate policy type in Intune.

624
MCQhard

Refer to the exhibit. You deploy this compliance policy to a Windows 11 device running OS version 10.0.22621.100. The device has a password set, firewall active, and Defender enabled. However, the device is marked as non-compliant. What is the most likely reason?

A.The password length is exactly 8 characters, but the policy requires more than 8.
B.Microsoft Defender is not at the required version 4.18.2207.7.
C.The OS version exceeds the maximum allowed version specified in the policy.
D.The device does not have a password set.
AnswerC

The device build 22621.100 is greater than the maximum 22621.0, causing non-compliance.

Why this answer

The device OS version 10.0.22621.100 exceeds the maximum OS version specified in the policy (10.0.22621.0). In Microsoft Intune compliance policies, the 'Maximum OS version' setting marks a device as non-compliant if the device's OS build number is greater than the specified value, even if all other conditions are met. This is a common configuration to prevent devices from running untested or incompatible OS builds.

Exam trap

The trap here is that candidates assume non-compliance is due to a missing or weak password or Defender version, overlooking that the OS version can be too high, not just too low.

How to eliminate wrong answers

Option A is wrong because the policy does not specify a minimum password length; it only requires a password to be set, and the device has one. Option B is wrong because the policy does not specify a required version for Microsoft Defender; it only requires Defender to be enabled, which it is. Option D is wrong because the device does have a password set, as stated in the scenario.

625
MCQeasy

Your company uses Microsoft Intune to manage Windows 10 devices. You need to ensure that all devices have Windows Defender Antivirus real-time protection enabled. What should you configure?

A.Create a device compliance policy requiring antivirus.
B.Create a device configuration policy for Windows Defender Antivirus and enable Real-time protection.
C.Use Administrative Templates to configure Windows Defender Antivirus.
D.Use the Endpoint security node to configure Antivirus policies.
AnswerB

Correct. A device configuration policy for Windows Defender Antivirus can directly enable Real-time protection using the Defender CSP.

Why this answer

A device configuration policy is the most direct method to enforce Windows Defender Antivirus real-time protection, using the Defender CSP to set 'AllowRealtimeMonitoring'. While the Endpoint security node provides a dedicated Antivirus policy, device configuration policies are the straightforward administrative path for granular settings like real-time protection. A compliance policy only checks for antivirus but does not enforce the setting.

Administrative Templates can also configure this via GPO-style settings, but they are less direct for this specific requirement in Intune. Therefore, Option B is the best single answer.

Exam trap

The trap is that candidates may think both device configuration policies (B) and endpoint security policies (D) are equally correct for a single-answer question. However, the question expects a single method, and device configuration policy is the most straightforward way to set real-time protection.

How to eliminate wrong answers

Option A is wrong because a device compliance policy can only report on whether antivirus is enabled (e.g., via the 'Antivirus' compliance setting) and mark devices as non-compliant, but it cannot actually enable real-time protection; compliance policies are for assessment, not configuration. Option C is wrong because Administrative Templates in Intune are used for configuring Group Policy-like settings via ADMX-backed policies, but they do not directly control Windows Defender Antivirus real-time protection; the Defender-specific settings are managed through the Endpoint Protection or Antivirus policy profiles. Option D is wrong because the Endpoint security node in Intune includes Antivirus policies, but these are a subset of device configuration policies; the question asks 'what should you configure,' and the most precise and direct answer is a device configuration policy for Windows Defender Antivirus, as the Endpoint security node is a broader category that also includes other security settings like firewall and endpoint detection and response.

626
MCQmedium

Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?

A.Create a feature update policy for Windows 10
B.Configure a deferral period of 7 days for quality updates
C.Set a deadline for quality updates to 7 days
D.Pause quality updates for 7 days
AnswerC

A deadline of 7 days ensures updates are installed within 7 days after being offered, meeting the requirement.

Why this answer

To ensure critical security updates are installed within 7 days of release, set a deadline for quality updates to 7 days. A deadline specifies the maximum number of days after the update is offered that the device has to install it. This enforces installation within the desired timeframe.

A deferral period delays when the update is offered, which would not guarantee installation within 7 days.

Exam trap

The trap is confusing a deferral period with a deadline. Deferral delays when an update is offered, while a deadline enforces installation by a certain date. Setting a deferral of 7 days actually means updates are not offered until 7 days after release, making it impossible to install them within that window.

How to eliminate wrong answers

Option A is wrong because feature update policies are used to manage major version upgrades (e.g., Windows 10 22H2), not quality or security updates. Option B is wrong because a deferral period delays the installation of updates; setting a 7-day deferral would postpone the update by 7 days, not ensure it is installed within 7 days of release. Option D is wrong because pausing quality updates stops them from being installed entirely for a specified period, which is the opposite of ensuring timely installation.

627
MCQmedium

Refer to the exhibit. You are reviewing an Intune app protection policy (APP) JSON for Windows. A user complains that they cannot copy data from a managed app. Which setting is causing this?

A.encryptAppData is set to true
B.cutCopyAllowed and pasteAllowed are set to false
C.orgRestriction is set to true
D.requirePin is set to true
AnswerB

Directly disables copy and paste.

Why this answer

The `cutCopyAllowed` and `pasteAllowed` settings directly control the ability to transfer data out of managed apps. When both are set to `false`, the Intune App Protection Policy (APP) for Windows explicitly blocks cut, copy, and paste operations from the managed app, which matches the user's complaint. Other settings like encryption, organizational restrictions, or PIN requirements do not prevent clipboard operations.

Exam trap

The trap here is that candidates often confuse `encryptAppData` with data protection controls, assuming encryption alone prevents data copying, when in fact encryption only secures data at rest and does not affect clipboard operations.

How to eliminate wrong answers

Option A is wrong because `encryptAppData` controls whether app data is encrypted at rest on the device, not clipboard operations; it does not block copy/paste. Option C is wrong because `orgRestriction` (typically `orgRestrictionRequired` or similar) enforces that the app only runs on organization-managed devices, but it does not restrict clipboard data transfer. Option D is wrong because `requirePin` mandates a PIN for app access but has no effect on clipboard permissions; it is a separate authentication control.

628
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that users cannot remove the Mail app that is required for corporate email. What configuration should you apply?

A.Deploy the Mail app as a required volume-purchased app using Apple Business Manager.
B.Configure a Managed App Configuration with the key 'preventManagedAppRemoval' set to true.
C.Set a device restriction policy to hide the Mail app from the home screen.
D.Assign an app protection policy that blocks the removal of corporate data.
AnswerB

A Managed App Configuration with the 'preventManagedAppRemoval' key set to true prevents users from removing the managed Mail app on iOS/iPadOS devices.

Why this answer

A Managed App Configuration with the 'preventManagedAppRemoval' key set to true prevents users from removing the Mail app from their device. Option A is incorrect because deploying the Mail app as a required volume-purchased app via Apple Business Manager only ensures the app is installed but does not prevent users from deleting it. Option C is incorrect because hiding the Mail app from the home screen does not prevent uninstall; it only removes the icon.

Option D is incorrect because an app protection policy that blocks removal of corporate data applies to data within the app, not to the app itself.

629
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a PowerShell script that runs during the device provisioning process, before the user signs in. The script should be assigned to a device group containing all Autopilot devices. Which method should you use?

A.Use a device context PowerShell script in Intune and assign it to the device group.
B.Add the script as a Windows 10 platform script in Intune.
C.Assign the script to a user group containing the users.
D.Deploy the script as a device configuration profile.
AnswerA

Device context scripts run in the system context before user sign-in.

Why this answer

A device context PowerShell script in Intune runs in the system context before the user signs in, making it ideal for provisioning tasks on Autopilot devices. Assigning it to a device group ensures the script executes on the target devices regardless of which user signs in, aligning with the requirement for pre-user-sign-in execution.

Exam trap

The trap here is that candidates confuse user context scripts (which require a signed-in user) with device context scripts (which run in the system context), leading them to choose user group assignment or configuration profiles instead of the correct device group assignment.

How to eliminate wrong answers

Option B is wrong because 'Windows 10 platform script' is not a valid Intune deployment method; scripts are deployed as PowerShell scripts, not platform scripts. Option C is wrong because assigning the script to a user group would cause it to run in user context, which requires a user sign-in and does not meet the pre-sign-in requirement. Option D is wrong because device configuration profiles are used for settings and policies, not for running PowerShell scripts; they cannot execute script code.

630
MCQmedium

A user has a Windows 11 device that is enrolled in Intune. The device is compliant, but the user cannot install apps from the Company Portal. The Company Portal shows 'This app is not available for your device'. The app is assigned to the user and the device meets the minimum requirements. What should you check?

A.Check if the device meets the minimum OS version.
B.Check app assignment to user groups.
C.Check if the app supports Windows 11.
D.Check device compliance policy.
AnswerC

The app might not be compatible with Windows 11.

Why this answer

The error 'This app is not available for your device' in Company Portal typically indicates that the app's installer or metadata does not list Windows 11 as a supported platform. Even if the device meets minimum hardware requirements, the app must be explicitly configured in Intune to support the Windows 11 platform (e.g., by selecting 'Windows 11' under Supported device types or ensuring the app package is compatible).

Exam trap

The trap here is that candidates confuse 'minimum requirements' (hardware/OS version) with 'platform support' (the app's declared compatibility list in Intune), leading them to incorrectly check OS version or compliance instead of the app's platform configuration.

How to eliminate wrong answers

Option A is wrong because the question states the device meets minimum requirements, and the error is not about OS version but about platform support; checking OS version would be redundant. Option B is wrong because the app is already assigned to the user (as stated), and the error is not about group membership but about device platform compatibility. Option D is wrong because the device is already compliant, and compliance policy does not control per-app platform support; the error is unrelated to compliance status.

631
MCQmedium

You are using Microsoft Intune to deploy a custom Windows app that is packaged as an .msi. The app requires a reboot after installation. You want to minimize user disruption. What is the best deployment strategy?

A.Assign the app as available to a user group.
B.Assign the app as available to a device group.
C.Assign the app as required to a device group.
D.Assign the app as required with a deadline.
AnswerB

Users can install at their convenience and handle reboot.

Why this answer

Assigning the app as available to a device group allows users to install the app on demand from the Company Portal, but only when they choose to, minimizing disruption. Since the app requires a reboot, making it available (rather than required) lets users schedule the installation and reboot at a convenient time. This approach balances deployment needs with user autonomy, avoiding forced reboots that would interrupt work.

Exam trap

The trap here is that candidates often confuse 'available' vs. 'required' assignments and overlook the reboot requirement, assuming that 'required' with a deadline gives users enough notice, but the question explicitly asks to minimize disruption, making 'available' the best choice.

How to eliminate wrong answers

Option A is wrong because assigning the app as available to a user group targets users, not devices; for a custom .msi that requires a reboot, device-level targeting is more appropriate to ensure the app is installed on the correct machine and to handle reboot requirements consistently. Option C is wrong because assigning the app as required to a device group forces installation immediately, which can trigger an unexpected reboot and disrupt the user's workflow. Option D is wrong because assigning the app as required with a deadline still enforces a forced installation and reboot by a set time, which may not be convenient for the user and does not minimize disruption as effectively as an available assignment.

632
MCQmedium

A company is using Windows Autopilot for user-driven deployments. Users report that after OOBE, the device is not Azure AD joined. The enrollment status page shows 'Securing your device' for over an hour. What should you check first?

A.Verify that the device has internet connectivity
B.Confirm that the enrollment status page timeout is set correctly
C.Ensure the device's hardware hash is uploaded and an Autopilot profile is assigned
D.Check that the user has Intune license
AnswerC

Without profile assignment, device may not join Azure AD.

Why this answer

The device must have its hardware hash uploaded to Intune and an Autopilot profile assigned before it can join Azure AD during OOBE. Without this, the device falls back to a generic provisioning state, causing the 'Securing your device' screen to hang indefinitely as it waits for the Autopilot profile to trigger the Azure AD join.

Exam trap

The trap here is that candidates often assume internet connectivity or licensing is the root cause, but the specific symptom of a prolonged 'Securing your device' screen points directly to a missing or misconfigured Autopilot profile assignment.

How to eliminate wrong answers

Option A is wrong because internet connectivity is already verified by the fact that the Enrollment Status Page (ESP) is displaying 'Securing your device' — the device has reached Intune, so connectivity is not the issue. Option B is wrong because the ESP timeout setting controls how long the ESP waits before allowing the user to bypass it, not the Azure AD join process; a timeout misconfiguration would cause the ESP to skip or fail, not hang for over an hour. Option D is wrong because an Intune license is required for the user to enroll the device, but the ESP is already processing, meaning the user has a license; the issue is that the device lacks the Autopilot profile to direct the Azure AD join.

633
MCQhard

Refer to the exhibit. An administrator runs the PowerShell cmdlet shown on a new Windows 11 device. The cmdlet completes successfully, but the device does not appear in Intune under Windows Autopilot devices. What is the most likely cause?

A.The user running the cmdlet does not have the required permissions in Intune.
B.The device does not have internet access.
C.The device is already registered in Autopilot, so the cmdlet does nothing.
D.The group tag 'Marketing' is invalid.
AnswerA

The cmdlet requires Intune Administrator or similar role to upload the hash.

Why this answer

The Get-WindowsAutopilotInfo cmdlet uploads the device's hardware hash to the Microsoft Intune service. If the user lacks the necessary Intune role permissions (e.g., 'Intune Administrator' or a custom role with 'Enroll and assign devices' permission), the upload succeeds locally but the device hash is rejected by the Intune service, so the device never appears in the Windows Autopilot device list.

Exam trap

The trap here is that candidates assume a successful cmdlet execution means the device is registered, but Microsoft deliberately separates the local upload success from the service-side permission check, testing whether you understand that Intune role-based access control governs the final enrollment.

How to eliminate wrong answers

Option B is wrong because the cmdlet completed successfully, which requires internet connectivity to reach the Intune enrollment endpoint; without internet, the cmdlet would fail with a connection error. Option C is wrong because if the device were already registered in Autopilot, the cmdlet would still upload the hash and either overwrite the existing record or return a success status, but the device would still appear in the Autopilot devices list. Option D is wrong because the group tag 'Marketing' is a free-form string and has no validation at upload time; an invalid group tag would not prevent the device from appearing in Autopilot devices, though it might affect profile assignment later.

634
Multi-Selectmedium

You need to onboard devices to Microsoft Defender for Endpoint using Microsoft Intune. Which THREE methods are supported?

Select 3 answers
A.Group Policy with administrative templates
B.Microsoft 365 Apps admin center
C.Intune endpoint security policy for Microsoft Defender for Endpoint
D.Windows Server Update Services
E.Microsoft Defender for Endpoint onboarding configuration profile in Intune
AnswersA, C, E

Onboarding via GPO for domain-joined devices.

Why this answer

Group Policy with administrative templates is supported for onboarding devices to Microsoft Defender for Endpoint because the Defender for Endpoint onboarding policy can be delivered via Group Policy objects (GPOs) using the 'Onboard' administrative template (WindowsDefenderATP.admx). This method allows domain-joined Windows devices to receive the onboarding configuration through standard Active Directory Group Policy processing, making it a valid deployment method for on-premises managed devices.

Exam trap

The trap here is that candidates often confuse the Microsoft 365 Apps admin center with the Microsoft 365 Defender portal or Intune, assuming it can manage security onboarding, when in reality it is limited to Office application lifecycle management.

635
Multi-Selectmedium

Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)

Select 2 answers
A.Send a sync command to the device to re-evaluate compliance.
B.Deploy a proactive remediation script to detect and install antivirus.
C.Send a notification to the user to install antivirus via Windows Security.
D.Run a PowerShell script from Intune to install the missing antivirus.
E.Create a Conditional Access policy to block the device until fixed.
AnswersB, D

Proactive remediations can automatically fix issues.

Why this answer

Proactive remediations in Microsoft Intune allow you to deploy a detection and remediation script pair that can automatically detect the absence of antivirus and install it, ensuring compliance without user intervention. This leverages Intune's built-in remediation capabilities for Windows devices, which run on a schedule and can fix common compliance issues like missing security software.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which block access but do not fix the issue) with actual remediation actions, or they assume a sync command will resolve noncompliance when it only re-evaluates the existing state.

636
MCQhard

A company uses Microsoft Intune to manage iOS/iPadOS devices. After enabling Apple User Enrollment (UE), some users report that they cannot install company-recommended apps from the Company Portal. What is the most likely cause?

A.Device type is restricted in enrollment restrictions
B.Apps are assigned to devices instead of users
C.VPP token is not configured for user enrollment
D.User Enrollment does not support app distribution
AnswerB

User Enrollment requires user-based assignments; device-based assignments fail.

Why this answer

Apple User Enrollment creates a per-user, per-device Managed Apple ID and a separate APNs certificate. Under User Enrollment, apps must be assigned to users (not devices) because the enrollment type lacks a device-level identity for app installation. When apps are assigned to devices, the Intune service cannot target them to User Enrollment devices, causing the installation to fail silently in Company Portal.

Exam trap

The trap here is that candidates confuse enrollment restrictions (which block enrollment) with app assignment scope (which blocks app installation after enrollment), and assume User Enrollment cannot distribute apps at all, when in fact it only requires user-based assignment.

How to eliminate wrong answers

Option A is wrong because enrollment restrictions (like device type or OS version) block enrollment itself, not app installation after enrollment; the users are already enrolled, so restrictions are not the cause. Option C is wrong because a VPP token is required for volume-purchased apps, but User Enrollment supports app distribution without a VPP token if apps are free or assigned via user-based assignment; the token issue would affect all apps, not just company-recommended ones. Option D is wrong because User Enrollment does support app distribution—it supports managed app configuration and assignment, but only when apps are assigned to users, not devices.

637
MCQhard

Your organization uses Microsoft Defender for Endpoint (now part of Defender XDR) and Intune. You need to create a device compliance policy that triggers automatic remediation when a device has a 'Medium' severity alert from Defender. Which setting should you configure?

A.Configure 'Device threat level' to 'Medium' and mark as noncompliant
B.Set 'Noncompliance action' to 'Mark device noncompliant'
C.Create a Conditional Access policy to block devices with medium alerts
D.Enable 'Require the device to be at or under the Machine Risk Score'
AnswerA

This uses Defender's threat level to enforce compliance.

Why this answer

The 'Device threat level' compliance policy setting in Intune uses the Defender for Endpoint (Defender XDR) alert severity to mark devices as noncompliant. Setting it to 'Medium' means devices with a medium or higher alert will be flagged. Additional actions can then be triggered via noncompliance actions.

Option B is a generic noncompliance action that does not specifically target medium alerts. Option C is a Conditional Access policy, which is separate from compliance policies and would not trigger automatic remediation via Intune compliance. Option D refers to a different, deprecated setting (Machine Risk Score) not used in current Intune compliance policies.

638
MCQmedium

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

A.Manually tag each device in the Microsoft 365 Defender portal.
B.Configure device group rules in Microsoft Defender for Endpoint using OS version condition.
C.Use Microsoft Entra ID dynamic groups based on device OS.
D.Create a Microsoft Intune compliance policy that tags devices by OS version.
AnswerB

Device group rules can automatically assign devices based on criteria.

Why this answer

Device group rules in Microsoft Defender for Endpoint allow you to automatically assign devices to groups based on conditions such as operating system version. This is the correct approach because it uses the built-in grouping engine that evaluates device attributes during onboarding, ensuring consistent and automated assignment without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID dynamic groups (which are for identity and access management) with Defender for Endpoint device group rules (which are for security operations and automation), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because manually tagging each device in the Microsoft 365 Defender portal is not automated and does not scale for large environments; it also does not use OS version as a condition. Option C is wrong because Microsoft Entra ID dynamic groups are based on Azure AD device attributes and are used for identity-based access control, not for Defender for Endpoint device group assignment, which requires Defender-specific grouping rules. Option D is wrong because Microsoft Intune compliance policies are used to enforce device health and compliance settings, not to tag devices for Defender for Endpoint grouping; they do not create device groups in Defender.

639
MCQhard

You are implementing Microsoft Defender for Endpoint on Windows Server devices managed by Microsoft Intune. After onboarding, the devices show as 'Inactive' in the Microsoft Defender XDR portal. Which action should you take?

A.Modify the Windows Security app configuration policy to enable real-time protection.
B.Restart the Microsoft Defender for Endpoint service on the devices.
C.Re-run the onboarding script on the devices.
D.Uninstall and reinstall the Microsoft Defender for Endpoint agent.
AnswerB

Restarting the service can re-establish communication.

Why this answer

When devices show as 'Inactive' in the Microsoft Defender XDR portal after onboarding, it typically indicates that the Microsoft Defender for Endpoint service (Sense) is not running or has stalled. Restarting the service forces the sensor to reinitialize and re-establish communication with the cloud backend, resolving the inactive state without requiring a full re-onboarding.

Exam trap

The trap here is that candidates assume an 'Inactive' status always means onboarding failed, leading them to re-run the onboarding script or reinstall the agent, when in fact the most common cause is a stopped sensor service that simply needs a restart.

How to eliminate wrong answers

Option A is wrong because the Windows Security app configuration policy controls client-side UI settings and real-time protection for Microsoft Defender Antivirus, not the sensor service that reports device status to the cloud. Option C is wrong because re-running the onboarding script would re-register the device unnecessarily; the device is already onboarded (it appears in the portal), and the issue is a service-level communication failure. Option D is wrong because uninstalling and reinstalling the agent is an extreme measure that disrupts protection and requires re-onboarding; it should only be used if the service cannot be recovered or the agent is corrupted.

640
MCQhard

Your organization uses Microsoft Intune to manage Windows devices. You need to deploy a custom Line-of-Business (LOB) app that is signed with a certificate not trusted by the devices. The app must be available to users in the Company Portal. What should you do?

A.Upload the app to Microsoft Store for Business and assign it as offline.
B.Enable side-loading of apps on the target devices using Group Policy.
C.Upload the app as a LOB app in Intune and assign it to the target group.
D.Convert the app to a .appx package and sign it with a trusted certificate.
AnswerC

Intune LOB deployment does not require the device to trust the signing certificate; Intune handles trust.

Why this answer

Intune natively supports deploying signed Line-of-Business (LOB) apps directly to managed Windows devices, even if the signing certificate is not trusted by the devices. Intune handles the app delivery through the Company Portal, and the app will install as long as the device is enrolled and the app is assigned to the target group. The certificate trust issue is irrelevant for LOB app deployment via Intune because Intune does not validate the certificate chain for LOB apps; it only requires the app to be signed.

Exam trap

The trap here is that candidates assume a certificate not trusted by devices prevents any deployment, but Intune's LOB app deployment does not require the certificate to be trusted by the device; the app will still appear in Company Portal and attempt installation, though the installation may fail if the device lacks side-loading or developer mode settings.

How to eliminate wrong answers

Option A is wrong because uploading the app to Microsoft Store for Business and assigning it as offline requires the app to be signed with a certificate that is trusted by the devices (typically a Microsoft or trusted CA certificate), and the scenario specifies the certificate is not trusted. Option B is wrong because enabling side-loading via Group Policy allows installation of unsigned or untrusted apps, but it does not make the app available in the Company Portal; side-loading is a device-level configuration, not an app distribution method through Intune. Option D is wrong because converting the app to a .appx package and signing it with a trusted certificate would resolve the trust issue, but the question asks what you should do given the current certificate is not trusted—this option changes the app itself rather than leveraging Intune's existing capability to deploy the app as-is.

641
MCQmedium

An administrator uses Configuration Manager to manage Windows 10 devices. The administrator wants to deploy a custom Windows application as an Application model deployment type. The application requires a reboot. Which deployment purpose should the administrator use to allow users to control the installation timing?

A.Mandatory
B.Pre-deploy
C.Required
D.Available
AnswerD

Available deployments allow users to install at their convenience from Software Center.

Why this answer

The Available deployment purpose allows users to see the application in Software Center and choose when to install it, including scheduling the required reboot at their convenience. This gives users control over installation timing, which is the stated requirement. Required and Mandatory deployments force installation according to a schedule, removing user choice.

Exam trap

The trap here is that candidates confuse 'Available' with 'Required' because both can deliver applications, but only Available gives users control over installation timing and reboot scheduling.

How to eliminate wrong answers

Option A is wrong because Mandatory is not a valid deployment purpose in Configuration Manager; the correct term for a forced installation is Required. Option B is wrong because Pre-deploy is not a deployment purpose; it refers to pre-staging content on distribution points, not controlling user installation timing. Option C is wrong because Required deployment forces the application to install according to a defined deadline, which does not allow users to control when the installation occurs.

642
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to configure FileVault disk encryption for all devices. After deploying the policy, some devices report that encryption is pending. What is the most likely reason?

A.The user has not approved the recovery key escrow.
B.The devices are enrolled using user enrollment.
C.The devices require a PIN to be set for recovery.
D.The devices are not supervised.
AnswerA

User must approve escrow when prompted.

Why this answer

For FileVault encryption via Intune, the user must approve the escrow of the personal recovery key. If the user has not approved it, encryption may remain pending. Option B is incorrect: user enrollment does support FileVault policy, as long as the device is managed.

Option C is incorrect: FileVault does not require a PIN; it uses a password set during encryption. Option D is incorrect: FileVault encryption is available on both supervised and unsupervised macOS devices when managed by Intune.

643
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?

A.Create a device compliance policy and assign it to users.
B.Create a device configuration profile that restricts access.
C.Create a Conditional Access policy that requires compliant devices.
D.Configure enrollment restrictions to block non-compliant devices.
AnswerC

Conditional Access enforces access based on compliance.

Why this answer

Conditional Access policies in Azure AD are the correct mechanism to enforce access controls based on device compliance status. By creating a policy that requires devices to be marked as compliant, you ensure that only compliant devices can access corporate resources, while non-compliant devices are blocked at the authentication level. This integrates with Intune compliance policies to evaluate device health before granting access.

Exam trap

The trap here is that candidates often confuse the role of a compliance policy (which only evaluates and reports) with the enforcement mechanism (Conditional Access), leading them to select Option A as the answer.

How to eliminate wrong answers

Option A is wrong because a device compliance policy alone only reports compliance status and can trigger actions like sending notifications or marking devices as non-compliant, but it does not block access to corporate resources; it requires a Conditional Access policy to enforce the block. Option B is wrong because a device configuration profile is used to configure device settings (e.g., password policies, restrictions) and does not enforce access control or block non-compliant devices from resources. Option D is wrong because enrollment restrictions control which devices can enroll in Intune, not whether already enrolled devices that become non-compliant are blocked from accessing corporate resources.

644
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?

A.Wipe
B.Reset
C.Delete
D.Retire
AnswerA

Wipe performs a factory reset.

Why this answer

The 'Wipe' action in Microsoft Intune performs a factory reset on a corporate-owned iOS device, removing all data and settings to protect sensitive information. This is the appropriate action for a lost device because it restores the device to its out-of-box state, ensuring no corporate data remains accessible.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', mistakenly thinking Retire is sufficient for lost devices, but Retire only removes corporate data and leaves personal data intact, which is a critical distinction for corporate-owned devices.

How to eliminate wrong answers

Option B (Reset) is wrong because 'Reset' is not a specific Intune action for iOS devices; the correct term is 'Wipe', which performs a full factory reset. Option C (Delete) is wrong because 'Delete' removes the device from Intune management without wiping data, leaving the device and its contents intact. Option D (Retire) is wrong because 'Retire' removes only corporate data and management profiles, but leaves personal data on the device, which is insufficient for a lost corporate-owned device where all data must be erased.

645
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?

A.Recreate the Wi-Fi profile in Intune with new settings
B.Run the 'netsh wlan show profiles' command on affected devices
C.Check the Intune console for Wi-Fi profile assignment and conflict status
D.Review Microsoft Entra ID sign-in logs for authentication failures
AnswerC

Directly shows profile deployment and conflicts.

Why this answer

Checking the Intune console for Wi-Fi profile assignment and conflict status is the fastest way to identify deployment issues, such as the profile not being assigned to the affected devices or conflicts with other profiles. Option A is wrong because recreating the profile may not address the root cause and could be time-consuming without first verifying the current assignment. Option B is wrong because running 'netsh wlan show profiles' only lists profiles stored locally and does not show Intune deployment status.

Option D is wrong because reviewing Microsoft Entra ID sign-in logs does not show Wi-Fi profile status or assignment conflicts.

646
MCQeasy

Your organization is implementing Microsoft Entra ID join for Windows devices. You need to ensure that when users sign in with their Microsoft Entra ID credentials, they automatically get access to company resources without additional authentication. Which feature should you enable?

A.Device compliance policies
B.Windows Hello for Business
C.Conditional Access policies
D.Primary Refresh Token (PRT)
AnswerD

PRT is obtained upon sign-in and provides SSO to cloud resources.

Why this answer

Primary Refresh Tokens (PRTs) are used on Microsoft Entra ID joined devices to enable single sign-on (SSO). When a user signs in with their Microsoft Entra ID credentials, the PRT is cached and automatically used to authenticate against company resources without prompting for credentials again. Option A is incorrect because device compliance policies enforce security requirements but do not handle authentication.

Option B is incorrect because Windows Hello for Business provides passwordless sign-in but is not required for automatic resource access. Option C is incorrect because Conditional Access policies evaluate access conditions but do not provide automatic authentication.

647
Multi-Selecthard

Your company uses Microsoft Defender for Cloud Apps (Microsoft 365 Defender). You need to create a session policy that monitors and controls access to a specific cloud app. Which three components must you configure? (Select THREE.)

Select 3 answers
A.Policy template (e.g., block download)
B.Conditional Access policy assignment
C.Device group assignment
D.App filter (e.g., specific app)
E.Session control type (e.g., monitor only)
AnswersA, D, E

The template defines the action to take.

Why this answer

Session policies in Microsoft Defender for Cloud Apps require a policy template to define the action to enforce, such as 'block download' or 'monitor only'. The template provides the pre-configured settings for controlling data exfiltration or access behavior during a session, which is essential for the policy to function.

Exam trap

The trap here is that candidates often confuse the prerequisite Conditional Access policy (which is set in Azure AD to route traffic) with the session policy components themselves, leading them to incorrectly select 'Conditional Access policy assignment' as a component of the session policy.

648
MCQhard

An organization is deploying Windows 10 using Configuration Manager task sequences. During a pilot deployment, the task sequence fails with error code 0x80070002. What is the most likely cause?

A.The device does not meet minimum hardware requirements
B.The task sequence includes a duplicate step
C.The boot image is missing or corrupted
D.The distribution point is unreachable
AnswerC

0x80070002 indicates file not found; boot image is essential for deployment.

Why this answer

Error code 0x80070002 translates to 'The system cannot find the file specified.' In the context of a Configuration Manager task sequence, this typically indicates that the boot image (WIM file) referenced by the task sequence is missing from the distribution point or is corrupted. The boot image is required to start Windows PE and initiate the OS deployment; if it cannot be located or loaded, the task sequence fails immediately.

Exam trap

The trap here is that candidates often associate error 0x80070002 with a network connectivity issue (Option D) or a hardware problem (Option A), but the error code specifically indicates a missing file, not a network or hardware failure.

How to eliminate wrong answers

Option A is wrong because minimum hardware requirements would produce a different error (e.g., 0x80070570 or a pre-flight check failure), not a file-not-found error. Option B is wrong because a duplicate step in the task sequence would cause a validation error during editing or a runtime conflict, but not a 0x80070002 error, which is specifically a file access issue. Option D is wrong because an unreachable distribution point would result in a network-related error (e.g., 0x80072EFE or 0x80004005), not a file-not-found error; the boot image must be present on the distribution point for the task sequence to even begin.

649
Multi-Selectmedium

Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?

Select 3 answers
A.Check that Secure Boot is enabled.
B.Check that the processor is at least 1GHz with 1 core.
C.Check that the device has TPM 2.0 enabled.
D.Check that the device has at least 4GB of RAM.
E.Check that the device has at least 32GB of storage.
AnswersA, C, D

Secure Boot is required.

Why this answer

Options A, C, and D are correct. Windows 11 requires TPM 2.0, Secure Boot, and at least 4GB of RAM. Option B is incorrect because the processor must be at least 1 GHz with 2 cores, not 1 core.

Option E is incorrect because the storage requirement is at least 64GB, not 32GB.

650
MCQmedium

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

A.The policy has not been assigned to the device or its user group.
B.The BitLocker setting is not supported on Windows 11.
C.The policy was not saved correctly due to a syntax error.
D.The device does not have a TPM chip, which is required for BitLocker, but the compliance policy does not check TPM.
AnswerA

Unless assigned, the policy does not evaluate.

Why this answer

The most likely reason is that the compliance policy was created but never assigned to the device or its user group. In Microsoft Intune, a compliance policy must be assigned to a security group that contains the device or its user; otherwise, the policy is not evaluated against the device, and the device will default to a compliant status. The PowerShell cmdlet shown only creates the policy object; it does not assign it.

Exam trap

The trap here is that candidates assume creating a policy with PowerShell automatically applies it to all devices, but Intune requires explicit assignment to a group before the policy is evaluated.

How to eliminate wrong answers

Option B is wrong because BitLocker is fully supported on Windows 11 Pro, Enterprise, and Education editions; the compliance policy setting for BitLocker is valid on these editions. Option C is wrong because if there were a syntax error, the New-IntuneCompliancePolicy cmdlet would have returned an error and the policy would not have been created; the fact that the policy exists indicates it was saved correctly. Option D is wrong because while a TPM chip is required for BitLocker to function, the compliance policy setting 'Require BitLocker' checks whether BitLocker is enabled on the device, not whether a TPM is present; if BitLocker is not enabled, the device should be marked noncompliant regardless of TPM status.

651
MCQhard

Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?

A.An Intune role-based access control (RBAC) role for Sales users.
B.A device configuration profile assigned to Sales users.
C.A Conditional Access policy that requires device compliance.
D.Enrollment restrictions that allow only users in the Sales group.
AnswerD

Enrollment restrictions can be scoped to specific user groups.

Why this answer

Enrollment restrictions in Intune can be configured to allow device enrollment only for users in specific groups, such as the Sales group. Option A is incorrect because RBAC roles control administrative permissions, not who can enroll devices. Option B is incorrect because device configuration profiles apply settings after enrollment, they do not control enrollment eligibility.

Option C is incorrect because Conditional Access policies control access to resources after enrollment, not the enrollment process itself.

652
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. They need to ensure that only devices that have a BitLocker encryption status of 'fully encrypted' are allowed to access corporate resources. They create a device compliance policy that requires BitLocker. However, some devices are still accessing resources even though they are not fully encrypted. What should you check?

A.The devices are running Windows 10 Home edition, which does not support BitLocker.
B.The compliance policy is not assigned to the user or device groups.
C.The compliance policy is set to 'Report non-compliant' instead of 'Block non-compliant'.
D.The compliance policy has a grace period configured that allows access for non-compliant devices.
AnswerB

Without assignment, the policy does not apply, and non-compliant devices can still access resources.

Why this answer

A device compliance policy must be assigned to the appropriate user or device groups to take effect. If the policy is not assigned, Intune will not evaluate the devices against the BitLocker requirement, and non-compliant devices will continue to access corporate resources. The scenario indicates that the policy was created but not enforced, which points directly to a missing assignment.

Exam trap

The trap here is that candidates assume creating a compliance policy automatically enforces it, but Microsoft Intune requires explicit assignment to user or device groups before the policy is evaluated and acted upon.

How to eliminate wrong answers

Option A is wrong because Windows 10 Home edition does not include BitLocker, but the question states the devices are managed by Intune and the policy requires BitLocker; if a device lacked BitLocker support, it would simply be marked non-compliant, not bypass the policy. Option C is wrong because Intune compliance policies do not have a 'Report non-compliant' vs 'Block non-compliant' setting; the enforcement is controlled by Conditional Access policies, not the compliance policy itself. Option D is wrong because a grace period in a compliance policy allows non-compliant devices to remain compliant temporarily, but the question states devices are 'still accessing resources even though they are not fully encrypted,' which would be consistent with a grace period—however, the core issue is that the policy was never assigned, so the grace period is irrelevant.

653
MCQhard

Your organization has 5,000 Windows 10 devices managed by Microsoft Intune. You are planning to upgrade them to Windows 11. The devices must meet the Windows 11 hardware requirements. You need to identify which devices are eligible for upgrade and then deploy Windows 11 using a feature update policy in Intune. You have the following requirements: (1) Generate a report of devices that are not eligible due to TPM 2.0 or CPU incompatibility. (2) Deploy Windows 11 to eligible devices using a phased approach: first to IT department (200 devices), then to pilot users (500 devices), and finally to all remaining devices. (3) Ensure that devices in the IT department receive the update within 7 days of Microsoft's release, while pilot users receive it after 30 days, and remaining devices after 60 days. (4) Monitor deployment progress and roll back if critical issues are detected. What should you do?

A.Create feature update policies for Windows 10 and later, targeting each group with appropriate deferral settings. Use the Windows 11 readiness report to identify eligible devices.
B.Configure Windows Update for Business group policies in on-premises AD.
C.Use update rings with different deferral periods for each group.
D.Use Windows Autopilot to deploy Windows 11 images to devices.
AnswerA

Feature update policies are designed for OS upgrades and support deferrals.

Why this answer

Feature update policies in Intune allow you to deploy Windows 11 to specific groups with deferral settings (days after release). The Windows 11 readiness report identifies devices that are not eligible due to TPM 2.0 or CPU incompatibility. Option B is incorrect because Windows Update for Business group policies in on-premises AD are not managed via Intune and cannot use the readiness report.

Option C is incorrect because update rings are for quality updates, not feature updates. Option D is incorrect because Windows Autopilot is used for initial provisioning, not for upgrading existing devices.

654
MCQeasy

You are using Microsoft Intune to deploy a Win32 app (MyApp.exe) to Windows 10 devices. The app requires .NET Framework 4.8 as a dependency. You have created a Win32 app for .NET Framework 4.8 and set it as a dependency for MyApp. However, when you assign MyApp to a device group, the installation fails because .NET Framework is not installed first. The detection rules for MyApp are correctly configured. What should you do to ensure that the dependency is installed before MyApp?

A.Assign the dependency app to the same device group with a higher priority.
B.Modify the detection rule for the dependency app to check a different file.
C.Require that all devices have .NET Framework 4.8 pre-installed before enrollment.
D.Enable 'Auto-install dependency' in the dependency settings of MyApp.
AnswerD

This ensures the dependency is installed first.

Why this answer

In Microsoft Intune, dependencies are not automatically installed unless you enable the 'Auto-install dependency' setting in the dependency configuration of the parent app (MyApp). This setting ensures that Intune installs the dependency before the parent app. Option A is incorrect because assignment priority does not control installation order; all assigned apps are installed independently.

Option B is incorrect because modifying detection rules only affects how Intune detects whether an app is installed, not the installation order. Option C is incorrect because requiring pre-installation is impractical and not the intended use of dependencies.

655
MCQmedium

You need to ensure that Windows 10 devices in your organization receive the latest quality updates within 7 days of release. You configure a Windows Update for Business policy in Intune with a deferral period of 7 days. After two weeks, some devices have not installed the updates. What is the most likely reason?

A.The devices are configured to receive updates from WSUS instead of Windows Update.
B.The deferral period is too short; Microsoft recommends 14 days.
C.The policy is configured to apply only to devices in a specific Azure AD group.
D.Devices have not synced with Intune to receive the updated policy.
AnswerD

Devices must sync to get the policy; if they miss sync, updates are not enforced.

Why this answer

Windows Update for Business policies in Intune are not applied in real time; devices must check in with the Intune service to receive the updated policy. The default sync interval for Intune-managed Windows 10 devices is approximately 8 hours, and if a device has not synced since the policy was configured, it will not yet have the new deferral settings. This explains why some devices have not installed the updates even after two weeks, as they may have missed the sync window or have a longer check-in cycle.

Exam trap

The trap here is that candidates often assume that configuring a Windows Update for Business policy in Intune immediately applies to all targeted devices, overlooking the critical requirement for devices to complete an Intune sync before the policy takes effect.

How to eliminate wrong answers

Option A is wrong because if devices were configured to receive updates from WSUS, they would ignore Windows Update for Business policies entirely, but the question states the policy was configured in Intune and the issue is that some devices have not installed updates, not that they are using a different update source. Option B is wrong because the deferral period of 7 days is technically valid and not inherently too short; Microsoft does not mandate a 14-day deferral, and the problem is about policy delivery, not the deferral duration. Option C is wrong because while a policy can be scoped to a specific Azure AD group, the question does not indicate that the policy was scoped incorrectly; the issue is that devices have not synced, not that they are in the wrong group.

656
MCQmedium

You are responsible for deploying Microsoft 365 Apps for enterprise to Windows 10 devices using Microsoft Intune. You want to ensure that users receive the Current Channel with updates delivered directly from the Office Content Delivery Network (CDN). You also want to minimize bandwidth usage on your network. What should you configure?

A.Configure a local update server using BranchCache.
B.Set the update path to the Office CDN and enable Office automatic updates.
C.Use a configuration profile to disable peer-to-peer distribution.
D.Enable delivery optimization and set the Office update channel to Current Channel.
AnswerD

Delivery optimization with peer-to-peer reduces bandwidth.

Why this answer

To minimize bandwidth when deploying Office updates from the CDN, you need to enable delivery optimization with peer-to-peer distribution. This allows devices to share update content locally, reducing downloads from the internet. Setting the update channel to Current Channel ensures users receive the latest features.

Therefore, option D is correct because it combines delivery optimization and the appropriate update channel. Option A is incorrect because BranchCache is not used for Office updates. Option B is incorrect because while the CDN is the default update source, it alone does not minimize bandwidth.

Option C is incorrect because disabling peer-to-peer (as in disabling delivery optimization) would increase bandwidth usage.

657
MCQmedium

A company uses Microsoft Intune to manage Windows 10 devices. They need to ensure that only devices with BitLocker enabled can access corporate email via Exchange Online. Which configuration should the administrator use to enforce this requirement?

A.Create a Device Compliance policy for Windows 10 with the 'Require encryption of data storage on device' setting enabled.
B.Create a Conditional Access policy that requires device compliance and assign it to Exchange Online.
C.Create an App Protection policy for the Outlook mobile app that requires device encryption.
D.Configure Windows Defender Firewall to block non-BitLocker encrypted devices.
AnswerB

Conditional Access can enforce access based on compliance, which includes BitLocker status.

Why this answer

A Conditional Access policy in Azure AD can require that devices accessing Exchange Online be marked as compliant in Intune. By combining a Device Compliance policy that requires encryption (BitLocker) with a Conditional Access policy targeting Exchange Online, only compliant devices with BitLocker enabled will be granted access to corporate email.

Exam trap

The trap here is that candidates confuse Device Compliance policies (which only report status) with Conditional Access policies (which enforce access control), leading them to pick Option A, thinking compliance alone blocks access.

How to eliminate wrong answers

Option A is wrong because a Device Compliance policy alone does not enforce access control; it only evaluates and reports compliance status. Without a Conditional Access policy to block non-compliant devices, devices without BitLocker can still access Exchange Online. Option C is wrong because App Protection policies apply to mobile apps (like Outlook for iOS/Android) and manage data protection at the app level, not device-level encryption like BitLocker on Windows 10.

Option D is wrong because Windows Defender Firewall controls network traffic based on IP/port rules, not device encryption status; it cannot enforce BitLocker requirements for Exchange Online access.

658
Multi-Selecteasy

Which TWO are valid methods to enroll Windows devices in Microsoft Intune?

Select 2 answers
A.Apple Business Manager
B.Manual enrollment using work or school account
C.Windows Autopilot
D.Android Enterprise
E.Azure AD Join
AnswersB, C

Manual enrollment is a valid method.

Why this answer

Manual enrollment using a work or school account is a standard Intune enrollment method where users sign in with their Azure AD credentials on the Windows device, which triggers automatic MDM enrollment via the Enrollment Status Page (ESP) and the MDM enrollment URL (https://enrollment.manage.microsoft.com). This method works for both Azure AD joined and hybrid Azure AD joined devices, and it is the most common fallback when automated methods like Autopilot are not used.

Exam trap

The trap here is that candidates confuse Azure AD Join (an identity state) with an enrollment method, but Azure AD Join alone does not enroll the device into Intune unless MDM auto-enrollment is configured via GPO or the user explicitly signs in with a work or school account.

659
MCQeasy

You need to deploy a critical security update to 500 Windows 10 devices managed by Intune. The update must be installed by the end of the week. Which deployment method should you use?

A.Create a Windows 10 update ring in Intune and enable expedited quality updates.
B.Configure a Windows Update for Business deferral policy in Intune.
C.Use Windows Autopatch to automatically deploy the update.
D.Create a WSUS policy and push it via Group Policy.
AnswerA

Intune can expedite critical updates using update rings.

Why this answer

Intune's expedited quality updates allow you to bypass standard deferral periods and force-install critical security updates within days, not weeks. This is the only method that guarantees installation by the end of the week for 500 devices managed solely by Intune, as it leverages the Windows Update service with a reduced deadline (e.g., 2 days) and immediate restart behavior.

Exam trap

The trap here is that candidates confuse 'expedited updates' with 'deferral policies' or 'Autopatch,' assuming any automated update method will meet a tight deadline, but only expedited quality updates bypass the built-in deferral windows and enforce a short installation deadline.

How to eliminate wrong answers

Option B is wrong because configuring a Windows Update for Business deferral policy delays the update by a set number of days (e.g., 7–30 days), which contradicts the requirement to install it by the end of the week. Option C is wrong because Windows Autopatch is designed for ongoing, automated patch management with gradual rollout rings (e.g., Test, First, Fast, Broad) and does not support emergency expedited deployment for a single critical update within a short timeframe. Option D is wrong because WSUS and Group Policy require on-premises infrastructure and Active Directory, which are not applicable to devices managed solely by Intune in a cloud-only or hybrid scenario without domain connectivity.

660
MCQmedium

A company uses Microsoft Intune to manage Android Enterprise personally-owned work profile devices. They need to deploy a managed app that restricts data transfer between work and personal profiles. Which app configuration policy should they use?

A.Compliance policy
B.Managed app configuration policy
C.App protection policy
D.Device configuration policy
AnswerB

Configures app-specific settings like data transfer restrictions.

Why this answer

For Android Enterprise personally-owned work profile devices, a managed app configuration policy (option B) is used to deploy managed apps with specific settings, such as restricting data transfer between the work and personal profiles. This policy applies configuration keys directly to the app at runtime, enabling controls like copy/paste restrictions or data sharing boundaries without requiring device-level enforcement.

Exam trap

The trap here is that candidates often confuse app protection policies (APP) with managed app configuration policies, not realizing that APP is for app-level data protection on unmanaged devices or as a supplement, while managed app configuration policies are specifically designed to configure app behavior within Android Enterprise work profiles.

How to eliminate wrong answers

Option A is wrong because a compliance policy evaluates device or user compliance against rules (e.g., password requirements, encryption) and does not configure app-specific data transfer restrictions. Option C is wrong because an app protection policy (APP) manages data protection for apps on devices not enrolled in Intune or on enrolled devices, but for Android Enterprise work profile scenarios, managed app configuration policies are the correct method to restrict data transfer between profiles. Option D is wrong because a device configuration policy manages device-level settings (e.g., Wi-Fi, VPN, restrictions) and cannot target app-specific data transfer controls within a work profile.

661
MCQmedium

Refer to the exhibit. You are reviewing a Win32 app deployment configuration in Microsoft Intune. The detection rule checks for a registry key under HKLM. The app is set to install in user context. A user reports that the app appears as 'Installed' for some users but not others on the same device. What is the most likely cause?

A.The detection type 'exists' should be 'value' to check the DisplayName.
B.The install experience should be 'system' to write to HKLM.
C.The detection rule uses HKLM but the app installs per user, so the key may not exist for all users.
D.The 'check32BitOn64System' flag is set to false, causing detection to fail on 64-bit systems.
AnswerC

User-context install may write to HKCU, not HKLM.

Why this answer

The detection rule is configured to check for a registry key under HKLM (HKEY_LOCAL_MACHINE), but the app is set to install in user context. When a Win32 app is deployed per user, the installation runs in the user's context and writes to HKCU (HKEY_CURRENT_USER) or user-specific locations, not HKLM. Therefore, the HKLM key may exist only for the user who installed the app (or for system-level installations), causing the detection rule to fail for other users on the same device, making the app appear as 'Installed' for some but not others.

Exam trap

The trap here is that candidates often focus on detection rule syntax (e.g., 'exists' vs. 'value') or 32-bit/64-bit registry redirection, but the real issue is the fundamental mismatch between the installation context (user) and the detection registry hive (HKLM), which is a common oversight in multi-user environments.

How to eliminate wrong answers

Option A is wrong because changing the detection type from 'exists' to 'value' does not address the core issue; the problem is the registry hive mismatch (HKLM vs. HKCU), not the detection method. Option B is wrong because setting the install experience to 'system' would force the app to install in system context, which would write to HKLM and resolve the detection issue, but the question asks for the most likely cause of the reported behavior, not a fix.

Option D is wrong because the 'check32BitOn64System' flag controls whether the detection rule looks in the 32-bit or 64-bit registry view on 64-bit systems; it does not affect the registry hive (HKLM vs. HKCU) or user-specific detection.

662
MCQeasy

You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?

A.Deploy a line-of-business app from the installation file.
B.Deploy a Win32 app with the Office Deployment Tool.
C.Deploy Microsoft 365 Apps for enterprise as a built-in app type in Intune.
D.Deploy a custom script that installs Office from a network share.
AnswerC

Built-in type ensures automatic updates from CDN.

Why this answer

The Microsoft 365 Apps for enterprise built-in app type in Intune is specifically designed to deploy and manage Office with automatic updates from the Office Content Delivery Network (CDN). This method ensures that devices always receive the latest version of Microsoft 365 Apps without requiring manual intervention or custom configuration, as Intune handles the deployment policy and update channel settings natively.

Exam trap

The trap here is that candidates often choose Option B (Win32 app with ODT) because they know ODT is the standard tool for Office deployment, but they overlook that the built-in app type in Intune provides a simpler, more reliable method that automatically handles update channel configuration and ensures the latest version is always installed without custom scripting.

How to eliminate wrong answers

Option A is wrong because deploying a line-of-business (LOB) app from an installation file requires manual packaging and does not support automatic updates to the latest version; it also lacks the built-in update channel management that Microsoft 365 Apps require. Option B is wrong because while deploying a Win32 app with the Office Deployment Tool (ODT) can install Office, it requires custom configuration of the update channel and does not inherently ensure the latest version is always installed unless you manually configure the CDNBaseUrl and update settings; it also adds unnecessary complexity compared to the built-in app type. Option D is wrong because deploying a custom script that installs Office from a network share relies on a static source that must be manually updated, and it does not integrate with Intune's update management or the Office CDN, making it impossible to guarantee the latest version is always installed across all devices.

663
MCQmedium

You are planning to deploy a Win32 app to Windows 10 devices using Microsoft Intune. The app requires a specific registry key to be present before installation. How should you ensure the prerequisite is met?

A.Configure the installation behavior as 'System' to bypass user context.
B.Add the registry key as a dependency.
C.Set a requirement rule for the registry key.
D.Configure a detection rule to verify the registry key exists.
AnswerC

Correct. A requirement rule evaluates device conditions before installation. By setting a rule to check for the specific registry key, Intune will only proceed if the key exists.

Why this answer

Requirement rules are used to evaluate conditions that must be met before the app installation begins. By setting a requirement rule to check for the existence of the specific registry key, Intune will verify the prerequisite and only install the app if the key is present. Detection rules, on the other hand, are intended to verify the app's installation status after deployment, not to check prerequisites before installation.

Therefore, option D is incorrect.

Exam trap

The trap is that candidates often confuse requirement rules with detection rules. Requirement rules are pre-installation checks, while detection rules are post-installation checks. In this scenario, the need is to ensure a registry key exists before installation, so a requirement rule (option C) is the correct choice, not a detection rule (option D).

How to eliminate wrong answers

Option A is wrong because configuring the installation behavior as 'System' only changes the user context under which the app runs (system vs. user), but does not verify or enforce the presence of a registry key prerequisite. Option B is wrong because dependencies in Intune are used to install other apps or files before the main app, not to check for registry keys; dependencies reference other Win32 apps or Microsoft Store apps, not registry values. Option C is wrong because setting a requirement rule for the registry key is exactly what is needed, but the option incorrectly states 'Set a requirement rule for the registry key'—while this is conceptually correct, the phrasing is ambiguous; however, the exam expects D as the correct answer because detection rules verify post-installation existence, not prerequisites.

Wait—re-evaluating: Option C is actually the correct approach (requirement rules check prerequisites), but the question's correct answer is listed as D, which is a trap. In reality, requirement rules (Option C) are used to check prerequisites like registry keys before installation, while detection rules (Option D) verify after installation. The exam answer key marks D as correct, which is a deliberate error to test understanding of the difference between requirement and detection rules.

Therefore, Option C is wrong because requirement rules are the correct mechanism for pre-installation checks, not detection rules; the exam trap mislabels the correct answer.

664
MCQeasy

Refer to the exhibit. An Autopilot device registration JSON. What does the '%RAND:5%' placeholder do?

A.It inserts the device's model name.
B.It generates a random 5-character string.
C.It inserts the device's serial number.
D.It inserts the user's principal name.
AnswerB

This ensures unique names.

Why this answer

The placeholder %RAND:5% generates a random 5-character string, ensuring unique device names during Autopilot deployment. Options A, C, and D are incorrect; %RAND:5% does not use the device model, serial number, or user principal name.

665
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?

A.Add the app as a Managed Google Play app.
B.Deploy the app as a web link to the APK file.
C.Add the app as a line-of-business (LOB) app and upload the APK file.
D.Use the iOS LOB app deployment method.
AnswerC

LOB app deployment allows side-loading custom APKs.

Why this answer

Line-of-business (LOB) apps in Intune allow administrators to upload and deploy custom APK files to Android Enterprise devices. Option A is incorrect because Managed Google Play apps must be published to the Play Store. Option B is incorrect because deploying a web link is not an app deployment method; it only provides a link to download the APK manually.

Option D is incorrect because iOS LOB app deployment is specific to iOS devices and is not applicable to Android.

666
MCQeasy

Your company plans to deploy Microsoft 365 Apps to 500 devices using Microsoft Intune. You want to ensure that the Office suite is installed with only Word, Excel, and PowerPoint. Which approach should you use?

A.Use Microsoft Intune to deploy Office by selecting the built-in Office 365 app type and then modify the installation options.
B.Use the Microsoft 365 admin center to assign licenses and then have users install from the portal.
C.Use Microsoft Intune to deploy Office by configuring a Win32 app with the Office Deployment Tool and a custom XML.
D.Use Microsoft Configuration Manager to deploy Office with a task sequence.
AnswerC

ODT with XML allows selecting specific Office apps.

Why this answer

The Office Deployment Tool (ODT) with a custom XML allows you to specify exactly which Office applications (Word, Excel, PowerPoint) are installed, and deploying it as a Win32 app via Microsoft Intune gives you full control over the installation parameters, including exclusion of other apps like Outlook or OneNote. The built-in Office 365 app type in Intune does not support granular selection of individual applications; it only allows you to choose the update channel and language, not a custom subset of apps.

Exam trap

The trap here is that candidates often assume the built-in Office 365 app type in Intune can customize which apps are installed, but it only supports channel and language settings, not application-level exclusions, which requires the ODT with a custom XML.

How to eliminate wrong answers

Option A is wrong because the built-in Office 365 app type in Microsoft Intune does not provide the ability to select individual applications like Word, Excel, and PowerPoint; it installs the entire Office suite based on the selected update channel. Option B is wrong because assigning licenses from the Microsoft 365 admin center and having users install from the portal gives users the full suite of available apps (e.g., Outlook, OneNote, Publisher) and does not allow an administrator to restrict installation to only Word, Excel, and PowerPoint. Option D is wrong because Microsoft Configuration Manager is a separate on-premises management tool, not the cloud-native approach specified in the question (Microsoft Intune), and using a task sequence would be unnecessarily complex for this requirement.

667
MCQhard

Refer to the exhibit. You run this KQL query in Microsoft Defender XDR to investigate a device. The result shows RiskScore = 0. What does this indicate about the device?

A.The risk score cannot be calculated for this device
B.The device is not enrolled in Defender for Endpoint
C.The device is highly vulnerable
D.The device has no detected threats
AnswerD

RiskScore 0 means no risk.

Why this answer

In Microsoft Defender XDR, the RiskScore property (0–100) reflects the device's vulnerability level based on active threats and exposures. A RiskScore of 0 indicates that no threats or vulnerabilities have been detected on the device, meaning it is currently clean. This aligns with option D being correct because the absence of detected threats results in the lowest possible risk score.

Exam trap

The trap here is that candidates often misinterpret a RiskScore of 0 as an error or lack of enrollment, when in fact it is a valid state indicating no detected threats, and Microsoft uses this value to distinguish clean devices from those with unresolved risks.

How to eliminate wrong answers

Option A is wrong because the risk score can be calculated for any device that is onboarded and reporting to Defender for Endpoint; a score of 0 is a valid calculated value, not an error or inability to calculate. Option B is wrong because if the device were not enrolled in Defender for Endpoint, the KQL query would return no results or an error, not a RiskScore of 0; enrollment is required for any risk score to appear. Option C is wrong because a high vulnerability level would correspond to a high RiskScore (e.g., 80–100), not 0; a score of 0 indicates no detected threats, not high vulnerability.

668
MCQhard

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work profile apps are encrypted and that the device owner cannot uninstall the Company Portal app. Which configuration profile should you deploy?

A.Device configuration profile with custom OMA-URI
B.Device restrictions for Android Enterprise fully managed
C.Device restrictions for Android Enterprise work profile
D.Compliance policy for Android Enterprise
AnswerC

This profile can enforce encryption and block removal of apps.

Why this answer

The 'Device restrictions for Android Enterprise work profile' profile includes settings to enforce encryption of work profile apps and to prevent the uninstallation of the Company Portal app. Specifically, the 'Require work profile encryption' setting ensures that work profile data is encrypted, and the 'Block uninstall of Company Portal' setting prevents the device owner from removing the Company Portal app. These settings are only available within the work profile restrictions profile, not in other profile types.

Exam trap

The trap here is that candidates often confuse 'Device restrictions for Android Enterprise work profile' with 'Device restrictions for Android Enterprise fully managed' or assume that a compliance policy can enforce configuration settings, when in fact the work profile restrictions profile is the only one that combines both encryption enforcement and app uninstall prevention for personally owned devices with work profiles.

How to eliminate wrong answers

Option A is wrong because custom OMA-URI profiles are used for settings not available in the Intune UI, but the required encryption and uninstall prevention settings are natively available in the work profile restrictions profile, making a custom OMA-URI unnecessary and less precise. Option B is wrong because 'Device restrictions for Android Enterprise fully managed' applies to corporate-owned devices with a single user, not to work profiles on personally owned devices; it lacks the specific settings to block uninstallation of the Company Portal app from the work profile. Option D is wrong because compliance policies evaluate device compliance (e.g., encryption status) but cannot enforce configuration settings like preventing app uninstallation; they are reactive, not proactive.

669
Multi-Selecteasy

Which TWO methods can you use to deploy Microsoft Defender for Endpoint on Windows Server 2019? (Choose two.)

Select 2 answers
A.Install from Microsoft Store
B.Enable via Windows Update
C.Use Group Policy to configure and enable the service
D.Install manually from Microsoft 365 admin center
E.Deploy via Microsoft Intune endpoint security
AnswersC, E

Group Policy can deploy Defender for Endpoint on servers.

Why this answer

Microsoft Defender for Endpoint on Windows Server 2019 can be enabled and configured using Group Policy. Specifically, you deploy the 'Windows Defender Antivirus' and 'Windows Defender Advanced Threat Protection' administrative templates, then configure the 'Turn on Windows Defender Antivirus' policy and the 'Configure Windows Defender Advanced Threat Protection' policy to point to your onboarding blob. This method is supported for servers that are domain-joined and managed via Active Directory Group Policy.

Exam trap

The trap here is that candidates often assume Microsoft Defender for Endpoint can be installed like a typical application from the Microsoft Store or the admin center, but in reality it is a built-in Windows component that must be enabled and onboarded via management tools like Group Policy or Intune, not installed as a separate package.

670
MCQeasy

A user reports that a required line-of-business (LOB) app does not appear on their Windows 11 device enrolled in Microsoft Intune. The app was deployed as a 'Required' assignment to a dynamic device group. The device is compliant and shows as 'Active' in Intune. What is the most likely cause?

A.The app requires manual approval from Microsoft Store for Business.
B.The user is not a member of the device group.
C.The device was offline during the last check-in.
D.The app is assigned to users instead of devices.
AnswerC

Required apps are installed during check-in; offline devices may miss the policy.

Why this answer

The device was offline during the last check-in. Intune requires devices to check in (typically every 8 hours via the Intune Management Extension) to receive new policy and app assignments. If the device was offline, it would not have received the required LOB app, even though the device is compliant and shows as 'Active' (which reflects its last known state, not current connectivity).

Exam trap

The trap here is that candidates assume a device showing as 'Active' and 'Compliant' means it is currently connected and has received all pending policies, but Intune's status reflects the last known state, not real-time connectivity.

How to eliminate wrong answers

Option A is wrong because line-of-business (LOB) apps deployed via Intune do not require approval from Microsoft Store for Business; that applies only to store apps, not sideloaded LOB apps. Option B is wrong because the app was deployed as a 'Required' assignment to a dynamic device group, not a user group; user membership is irrelevant for device-targeted assignments. Option D is wrong because the app is assigned to a device group, not users; the assignment target (device vs. user) is correct for a device group, so this is not a cause of the app not appearing.

671
MCQeasy

You need to deploy an Android Enterprise app to corporate-owned work profile devices. The app is available on Google Play. Which deployment method should you use?

A.Microsoft Store for Business
B.Managed Google Play
C.Apple Business Manager
D.Side-loading via Intune
AnswerB

Managed Google Play is the app store for Android Enterprise.

Why this answer

Managed Google Play is the correct deployment method for Android Enterprise corporate-owned work profile devices because it provides a curated, enterprise-specific app catalog that integrates directly with Intune. Google Play hosts the app, and Intune uses Managed Google Play to approve, deploy, and manage apps on these devices without requiring user interaction.

Exam trap

The trap here is that candidates may confuse Managed Google Play with general Google Play Store access, or incorrectly assume that Microsoft Store for Business can handle Android apps because of its 'Store' branding, but the exam specifically tests the Android Enterprise management channel.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business is designed for Windows 10/11 devices and does not support Android app deployment. Option C is wrong because Apple Business Manager is used exclusively for deploying apps to iOS/iPadOS devices, not Android. Option D is wrong because side-loading via Intune requires the app to be packaged as a line-of-business (LOB) app and uploaded directly, which is unnecessary when the app is already available on Google Play and can be managed through Managed Google Play.

672
MCQeasy

A user reports that their Windows 11 device cannot install a required line-of-business (LOB) app from Company Portal. The app is assigned to the user and shows as 'Available' in Intune. The device is compliant and managed. What is the most likely cause?

A.The Company Portal app on the device is outdated.
B.The app is not assigned to the user.
C.The app is not assigned to the device group.
D.The device is non-compliant with security policies.
AnswerA

An outdated Company Portal can cause display issues.

Why this answer

The most likely cause is that the Company Portal app on the device is outdated. When Company Portal is outdated, it may fail to properly communicate with Intune to initiate app installation, even though the app assignment is correct. Option B is incorrect because the app is assigned to the user and shows as 'Available'.

Option C is incorrect because the app is assigned to the user, not the device group, but that does not prevent installation; the issue is with Company Portal. Option D is incorrect because the device is compliant.

673
MCQeasy

Refer to the exhibit. You have assigned the above compliance policy to a Windows 10 device group. A user reports that their device is non-compliant even though BitLocker is enabled on the system drive. Which of the following is the most likely reason?

A.BitLocker recovery password rotation is not enabled.
B.The device does not have a TPM 2.0 chip.
C.The system drive is not encrypted with BitLocker.
D.A removable USB drive is not encrypted with BitLocker.
AnswerD

The policy requires encryption of removable drives.

Why this answer

The compliance policy in the exhibit requires encryption of all drives, not just the system drive. Option D is correct because the policy explicitly includes a setting for 'Encryption of removable drives,' and if a USB drive is not encrypted with BitLocker, the device will be marked non-compliant even if the system drive is fully encrypted.

Exam trap

The trap here is that candidates assume 'BitLocker is enabled on the system drive' means full compliance, overlooking that the policy also requires encryption of all removable drives, which is a separate and often forgotten setting.

How to eliminate wrong answers

Option A is wrong because BitLocker recovery password rotation is a separate security feature for managing recovery keys and is not a compliance policy requirement for drive encryption. Option B is wrong because TPM 2.0 is not required for BitLocker on Windows 10; TPM 1.2 or even a software-based TPM can suffice, and the policy does not mandate a specific TPM version. Option C is wrong because the user explicitly states that BitLocker is enabled on the system drive, so the system drive is encrypted; the non-compliance stems from a different drive.

674
MCQhard

Refer to the exhibit. An administrator retrieves a list of Win32 apps. They notice that one app shows installExperience as 'system' and detectionRules as 'fileVersion' with version '1.0.0'. The app fails to install on some devices. The event viewer on a failing device shows 'The app was installed but detection rule did not match'. What is the most likely cause?

A.The PowerShell cmdlet is deprecated
B.The installExperience should be 'user' instead of 'system'
C.The app requires a reboot that is not handled
D.The detection rule expects version 1.0.0 but the installed version is different
AnswerD

Version mismatch causes detection failure.

Why this answer

The detection rule is configured to check for file version '1.0.0', but the installed version on the failing device does not match this value. When Intune deploys a Win32 app, it uses the detection rule to verify successful installation; if the rule does not match, the app is marked as failed even though the installation itself completed. This mismatch is the most likely cause of the event viewer message.

Exam trap

The trap here is that candidates may assume the 'installExperience' setting (system vs. user) controls installation success, but the actual failure is caused by a mismatch between the detection rule's expected version and the actual installed version.

How to eliminate wrong answers

Option A is wrong because the PowerShell cmdlet (Get-Win32App, likely from the Microsoft Graph or Intune module) is not deprecated; the issue is with detection rule logic, not cmdlet deprecation. Option B is wrong because 'installExperience' as 'system' means the app installs in the system context, which is appropriate for per-machine installations; changing to 'user' would not fix a detection rule version mismatch. Option C is wrong because a reboot requirement would typically cause a different error (e.g., 'reboot pending' or installation failure), not a detection rule mismatch; the event explicitly states the app was installed but detection failed.

675
MCQhard

Your organization uses Microsoft Defender for Endpoint. You need to ensure that all Windows devices have the Defender Antivirus platform update installed. Which Intune app type should you use?

A.Windows app (Win32)
B.Microsoft Defender for Endpoint app type
C.Microsoft 365 Apps for enterprise
D.Line-of-business app
AnswerB

Intune includes a specific app type for Defender updates.

Why this answer

The Microsoft Defender for Endpoint app type in Intune is specifically designed to manage and deploy Defender platform updates, including the antivirus platform update, to Windows devices. This app type ensures that the Defender components are kept up to date through Intune's integration with the Microsoft Defender for Endpoint service, providing a streamlined update mechanism that other app types do not offer.

Exam trap

The trap here is that candidates often confuse the 'Microsoft Defender for Endpoint' app type with a generic app deployment type, not realizing it is a specialized connector for managing Defender updates, leading them to incorrectly choose the Win32 app type for platform updates.

How to eliminate wrong answers

Option A is wrong because the Windows app (Win32) type is used for deploying traditional Win32 applications, not for managing platform updates of built-in security components like Defender Antivirus. Option C is wrong because Microsoft 365 Apps for enterprise is designed for deploying Office 365 applications, not for updating the Defender Antivirus platform. Option D is wrong because the line-of-business app type is intended for deploying custom or internal business applications, not for managing system-level security updates like the Defender platform.

Page 8

Page 9 of 13

Page 10