Courseiva

MD-102 · domain

Manage and maintain devices

This domain covers day-to-day operations after enrollment: monitoring device and app status, applying compliance and configuration policies, running remote actions, and managing updates with Windows Update for Business and Autopilot. Questions are scenario-based, asking you to pick the correct Intune policy type, Defender XDR setting, or remote action for a stated outcome.

183 questions50 easy74 medium59 hard

Focused practice

Practice Manage and maintain devices questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage and maintain devices

Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.

Selecting Intune compliance, configuration, and device-retirement policy types for stated outcomes

Configuring Defender for Endpoint automatic investigation and response in the Microsoft Defender XDR portal

Applying iOS/iPadOS and Windows restriction settings such as passcode length, biometrics, and wipe thresholds

Reading policy JSON and interpreting settings like osMinimumVersion and remote actions such as wipe, retire, and fresh start

Watch out for

Common Manage and maintain devices exam traps

  • ▸Confusing compliance policies, which report and gate access, with configuration profiles, which actually enforce settings on the device.
  • ▸Choosing a manual remote action like Retire or Wipe when the requirement is an automated, scheduled policy.
  • ▸Assuming Defender for Endpoint automatic investigation is on by default instead of configured in the XDR portal settings.

Question index

All Manage and maintain devices questions (183)

Click any question to see the full explanation, or start a practice session above.

1

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?

Medium
2

You need to remotely wipe a lost corporate-owned iOS device that is enrolled in Microsoft Intune. Which action should you perform in the Intune console?

Easy
3

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that Windows Update for Business policies are applied to these devices to control when feature updates are installed. What should you configure?

Medium
4

You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?

Hard
5

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. Users report that their devices are not receiving newly assigned compliance policies. You need to force the devices to check in with Intune immediately. What should you do from the Intune admin center?

Easy
6

An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?

Hard
7

Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?

Medium
8

Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?

Hard
9

Your organization uses Windows Autopilot for device provisioning. Users report that after initial setup, devices are not automatically enrolled in Microsoft Intune. What should you verify?

Easy
10

Your company uses Microsoft Intune to manage Windows 11 devices. A security policy requires that devices automatically receive quality updates as soon as they are available, with a deadline of 2 days after release and automatic restart outside active hours. You create a Windows update ring in Intune. Which setting should you configure to meet the deadline requirement?

Hard
11

Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?

Hard
12

Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?

Medium
13

You need to ensure that Windows 10 devices are automatically upgraded to Windows 11 if they meet hardware requirements. Which policy should you configure in Microsoft Intune?

Easy
14

You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?

Easy
15

You need to remotely wipe a lost corporate-owned iOS device enrolled in Microsoft Intune. The device is currently offline. What will happen when the device comes online?

Easy
16

Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?

Hard
17

Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?

Hard
18

You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?

Easy
19

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to configure a remediation to automatically restart the Windows Update service (wuauserv) if it stops. You create a proactive remediation script package. Which two components must you provide in the script package? (Choose two.)

Medium
20

You manage a set of Windows 11 devices enrolled in Microsoft Intune. Users report that they can no longer sign in with their Microsoft Entra ID credentials after you deployed a new compliance policy. The devices show as compliant in Intune, but the sign-in fails with an error about device not meeting requirements. You need to ensure that users can sign in. What should you do?

Medium
21

Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?

Medium
22

You manage devices with Microsoft Intune. You need to ensure that only devices with a specific BIOS serial number can enroll. What should you configure?

Hard
23

A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?

Hard
24

You manage devices in Microsoft Intune. You need to ensure that a specific set of Windows 10 devices automatically receive new configuration profiles as soon as they are assigned. The devices are already enrolled and are members of an Microsoft Entra ID group. What should you do?

Easy
25

You are implementing Windows Autopilot for a new fleet of devices. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and is enrolled in Intune. Which configuration is required?

Hard
26

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

Hard
27

You need to deploy a Windows 10 feature update to a pilot group. Which TWO steps are required in Microsoft Intune?

Easy
28

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?

Medium
29

You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?

Medium
30

Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?

Hard
31

Which THREE are valid Windows Autopilot deployment scenarios?

Medium
32

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)

Easy
33

You are configuring Windows Update for Business policies in Microsoft Intune for a group of Windows 11 devices. You need to ensure that devices do not install feature updates for 60 days after a new version is released, while still receiving quality updates immediately. Which setting should you configure?

Hard
34

You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?

Hard
35

You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?

Medium
36

You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?

Hard
37

Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?

Medium
38

You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?

Easy
39

An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?

Hard
40

Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?

Easy
41

Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)

Hard
42

You manage a fleet of Windows 11 devices with Microsoft Intune. Users report that the Windows Update ring assigned to them installs quality updates but never installs the required feature update to Windows 11 version 23H2. You confirm the devices are active, check-in is successful, and the ring is assigned to the correct Microsoft Entra group. You need to ensure the feature update installs automatically without user interaction. What should you configure?

Medium
43

You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?

Hard
44

You manage Windows 11 devices with Microsoft Intune. Several devices are failing to check in and receive policy. You review the device list and see the devices are enrolled but show a compliance state of 'Not evaluated'. You need to force the devices to immediately check in with the Intune service from the local device. What should you do?

Medium
45

Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?

Medium
46

You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

Easy
47

You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?

Hard
48

You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)

Medium
49

An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?

Easy
50

You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Azure AD joined and enrolled in Intune. What should you configure?

Hard
51

You manage devices with Microsoft Intune. You need to ensure that when a device is marked as non-compliant, users receive a notification and the device is blocked from accessing corporate email. Which two actions should you perform? (Choose two.)

Hard
52

You are an Intune administrator for a large enterprise that uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) for threat protection. You need to ensure that all Windows 10 devices are properly onboarded to Defender for Endpoint and that security settings are enforced via Intune. You have created a device configuration profile that includes the 'Microsoft Defender for Endpoint' settings, but some devices are not appearing in the Defender for Endpoint portal. You verify that the devices are Intune managed and enrolled. What should you do to ensure proper onboarding?

Hard
53

You manage a fleet of Windows 11 devices with Microsoft Intune. The security team requires that any device that has not checked in with Intune for more than 30 days is automatically retired so its resources are released and its compliance state is removed. You need to configure this behavior with the least administrative effort. What should you do?

Medium
54

You are deploying a Windows 11 device using Windows Autopilot. The device fails to enroll in Intune and you see the error 'The device is not registered in Autopilot'. You have verified that the device hardware hash is uploaded. What is the most likely cause?

Medium
55

You are the endpoint administrator for Contoso, a company with 10,000 Windows 11 devices managed by Microsoft Intune. The devices are a mix of corporate-owned and bring-your-own-device (BYOD). You need to implement a solution that allows users to access corporate resources only if their devices meet specific security requirements: disk encryption (BitLocker), antivirus (Microsoft Defender), and a minimum OS build. Additionally, you must ensure that users cannot access corporate email from devices that are jailbroken or rooted. The solution should automatically block non-compliant devices from accessing resources and provide a notification to the user explaining the issue. You have already configured compliance policies in Intune. What should you do next to enforce the block?

Hard
56

You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?

Medium
57

A user's Android device is not receiving email from the corporate Microsoft 365 tenant. The device is enrolled in Intune and shows as compliant. The email profile is assigned to the user. What should you check first?

Medium
58

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, all corporate data is removed but the user's personal files remain intact. The devices are enrolled as personal devices with work profiles. What should you do?

Medium
59

You manage macOS devices enrolled in Microsoft Intune using the Intune Company Portal app. Users report that the Company Portal app does not detect newly assigned required apps and shows an outdated compliance status. You need to ensure the Company Portal refreshes device state on demand. What should you do?

Hard
60

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. You need to ensure that devices receive quality updates with a maximum deferral of 7 days. What should you configure?

Easy
61

Your company uses Microsoft Intune to manage Windows 11 devices. An administrator needs to remotely restart a specific device that is currently online to apply pending updates. Which action should the administrator use in the Intune admin center?

Easy
62

You manage Windows 10 devices with Intune. You need to collect diagnostic logs from a remote device that is experiencing application crashes. Which Intune feature should you use?

Medium
63

Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?

Medium
64

You deployed this endpoint protection policy to a Windows 10 device. A user reports that a known malicious file was downloaded but not blocked. What is the most likely reason?

Medium
65

You need to retire a device in Microsoft Intune. What is the effect of retiring a device?

Easy
66

A user's device is marked as 'Noncompliant' in Microsoft Intune due to missing required updates. The device is configured with a compliance policy that requires a minimum OS version. The user claims the device is up-to-date. What should you verify first?

Easy
67

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, the primary user's corporate data is removed but the device remains enrolled and managed. Which action should you take in the Intune admin center?

Medium
68

You manage devices with Microsoft Intune. Users report that after a recent policy change, some devices are not receiving updated policies. You verify that the devices are online and have connectivity. What should you do to force a policy refresh?

Medium
69

You are responsible for managing Windows 10 devices with Microsoft Intune. You need to deploy a new line-of-business (LOB) app to a group of devices. The app requires a script to run after installation to configure settings. What should you use to deploy the app and ensure the script runs?

Medium
70

Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?

Medium
71

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that devices automatically receive quality updates and feature updates according to a schedule you define, with the ability to pause updates. What should you configure?

Easy
72

Your organization is implementing a zero-trust security model using Microsoft Intune. Devices must be compliant before accessing corporate resources. You need to deploy compliance policies for Windows 10 devices that require BitLocker encryption and a minimum OS version. Which two policy settings should you configure? (Choose two.)

Hard
73

You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?

Medium
74

You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy to require that devices have a specific minimum OS version and that BitLocker is enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Medium
75

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?

Easy
76

You are deploying Windows 11 devices using Windows Autopilot. Some devices are not registering in Microsoft Intune. You have verified that the hardware hashes are uploaded correctly. What is the most likely cause?

Hard
77

Refer to the exhibit. You have configured the compliance policy shown above. A user reports that their Windows 11 device is compliant with all settings except the threat level. The device has no threat protection agent installed. What will happen when the user tries to access corporate resources?

Hard
78

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, the user receives a notification email, and the device is automatically retired after 30 days. The solution must minimize administrative effort. What should you configure?

Medium
79

You use Microsoft Intune to manage Windows 11 devices. You configure a Windows Update ring policy to defer quality updates by 7 days and feature updates by 60 days. A critical security update is released that must be installed immediately on all devices, bypassing the deferral. What should you configure?

Hard
80

You manage Windows 10 devices enrolled in Microsoft Intune. Users report that the Company Portal app is not installing required apps. You verify that the devices are compliant and checked in recently. What is the most likely cause?

Medium
81

A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?

Easy
82

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?

Medium
83

Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?

Medium
84

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?

Easy
85

A company is planning to use Windows Autopilot to deploy new devices. They want to ensure that devices are automatically enrolled in Microsoft Intune when a user signs in with their Microsoft Entra ID credentials. Which configuration is required?

Easy
86

You are the endpoint administrator for a company that uses Microsoft Intune. You need to ensure that when a Windows 11 device is retired or wiped, the device record is automatically removed from Intune after 30 days. Which action should you take?

Easy
87

You are troubleshooting an iPhone that cannot enroll in Microsoft Intune. The user receives an error stating 'This device is already enrolled in another MDM.' What is the most likely cause?

Hard
88

You are designing a Windows 11 update strategy for a fleet of 500 devices managed by Intune. The organization requires that critical security updates be applied within 7 days, but feature updates can be delayed up to 60 days. Which Update Rings configuration should you use?

Hard
89

You are planning a Windows 11 deployment for 500 new devices using Windows Autopilot. The devices will be shipped directly to users from the manufacturer. You need to ensure that the devices are automatically enrolled in Intune and joined to Microsoft Entra ID. What should you do?

Hard
90

You need to ensure that corporate devices automatically install critical Windows updates within 24 hours of release. Which update ring setting should you configure in Intune?

Easy
91

You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?

Hard
92

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company-specific application (a .pkg file) to all macOS devices. The application requires a specific configuration file that must be placed in the /Library/Application Support/ directory. You also need to ensure that the application is installed silently without user interaction. How should you configure the deployment in Intune?

Medium
93

You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?

Hard
94

You are troubleshooting a Windows device that is not receiving policies from Intune. Which TWO actions should you take?

Easy
95

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows 11 devices remotely? (Choose two.)

Medium
96

A user's iOS device is enrolled in Microsoft Intune. The user reports that they cannot install the Company Portal app from the App Store. What is the most likely reason?

Easy
97

A company uses Microsoft Intune to manage iOS devices. They want to ensure that only devices with a passcode of at least 6 characters and without jailbreak can access corporate email. Which policy type should they configure?

Easy
98

Refer to the exhibit. The exhibit shows a JSON representation of a managed device from Microsoft Graph API. The device shows as noncompliant. Which of the following is the most likely reason for the noncompliant status?

Hard
99

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a .pkg app to these devices. What is the recommended method?

Hard
100

A help desk technician reports that a Windows 11 device enrolled in Microsoft Intune has not received a newly assigned configuration profile. The device shows as compliant in the admin center. You need to force the device to check in with Intune immediately. What should you do?

Easy
101

You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?

Easy
102

Refer to the exhibit. The JSON snippet shows a Windows Update for Business policy assigned to a device group. Users report that quality updates are installed 7 days after release. Which setting controls this behavior?

Easy
103

You use Microsoft Intune to manage Windows 11 devices. A device named LAPTOP-01 is not receiving a newly assigned device configuration profile. You verify the profile is assigned to a group that contains LAPTOP-01. You need to force the device to check in with Intune and apply the policy immediately. Which action should you perform from the Intune admin center?

Hard
104

You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Medium
105

You need to deploy a custom Windows 11 feature update to a pilot group of 50 devices before rolling out to the entire organization. The devices are managed by Intune and are in a 'Pilot' Azure AD group. What is the best approach?

Medium
106

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?

Hard
107

You manage iOS/iPadOS devices with Microsoft Intune. You need to ensure that when a device is lost or stolen, its corporate data can be remotely wiped while leaving personal data intact. The devices are enrolled as user enrollment (personal devices). What should you do?

Medium
108

Refer to the exhibit. You run this PowerShell command using the Microsoft Graph PowerShell SDK. What is the primary purpose of this command?

Medium
109

A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?

Easy
110

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a user reports a lost device, you can remotely lock it and display a custom message on the lock screen. The solution must not erase any data. What should you do?

Medium
111

You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?

Hard
112

You manage devices with Microsoft Intune. You need to ensure that only devices that meet specific compliance requirements can access Microsoft 365 services. You create a compliance policy and assign it to a group of users. What should you do next to enforce the policy?

Medium
113

Your organization has Windows 10 devices managed by Intune. You need to enforce BitLocker encryption on all devices. The devices must use a TPM protector and a recovery password. What should you configure?

Medium
114

A user has a Windows 10 device that is enrolled in Microsoft Intune. The user reports that they cannot install a required app from the Company Portal. You check the Intune console and see that the app assignment is 'Required' but the installation status shows 'Failed'. The device is compliant. What should you check first?

Hard
115

Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Azure AD. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Azure AD joined. What is the most likely reason for the failure, and how should you resolve it?

Medium
116

Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?

Medium
117

You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?

Easy
118

You are an administrator for a Microsoft Intune environment. You need to remotely wipe a lost Windows 11 device to prevent access to corporate data. The device is enrolled in Intune and is currently online. Which action should you perform from the Intune admin center?

Easy
119

Your organization wants to use Windows Autopilot for user-driven deployment. Users should be able to self-deploy their devices by signing in with their corporate credentials. Which Autopilot deployment mode should you use?

Easy
120

Refer to the exhibit. You manage a Windows 11 device that is marked as compliant and has OS version 10.0.22621.0. You need to upgrade the device to Windows 11 version 23H2. Which Intune feature should you use?

Easy
121

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?

Hard
122

Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)

Easy
123

Which THREE components are required to deploy a Win32 app via Microsoft Intune?

Hard
124

Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?

Medium
125

You manage Windows 10 devices with Microsoft Intune. You need to ensure that devices receive a specific Windows quality update as soon as possible, bypassing any deferral settings. What should you configure?

Medium
126

Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)

Medium
127

You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?

Easy
128

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a compliance policy that marks devices as noncompliant if they do not have a specific minimum OS version and if they have not checked in with Intune within the last 7 days. Which TWO settings should you configure in the compliance policy? (Choose two.)

Medium
129

Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?

Hard
130

You administer Microsoft Intune for a company with Windows 11 devices joined to Microsoft Entra ID. A security requirement states that if a device is found noncompliant, it must lose access to Microsoft 365 services within 15 minutes, and the device must be marked noncompliant automatically when a required antivirus signature is out of date. You need to implement this with the least administrative effort. What should you do?

Hard
131

Which TWO are valid methods to enroll Windows devices in Microsoft Intune?

Easy
132

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?

Medium
133

You manage 500 Windows 11 devices enrolled in Microsoft Intune. A security policy requires that a specific registry value be set on all devices, and you must be able to report which devices have the value applied and remediate any that do not. You need to implement this with the least administrative effort. What should you create?

Medium
134

You manage Windows 11 devices with Microsoft Intune. A critical line-of-business app must be installed on all devices in the Finance department, but the app's installer requires administrator privileges and the users do not have local admin rights. You need to deploy the app silently without user interaction and ensure it installs even if no user is signed in. What should you do?

Medium
135

You administer Microsoft Intune for a company with 500 Windows 11 devices. The security team requires that when a device is reported lost or stolen, you can remotely erase corporate data without affecting the user's personal files on devices enrolled as personally owned. Which action should you perform in the Intune admin center?

Medium
136

You manage Windows 11 devices with Microsoft Intune. Users report that when they attempt to enroll a personal device, enrollment fails with error 80180014. You need to ensure that only corporate-owned devices can enroll. What should you configure?

Medium
137

Which THREE conditions can be used to create a dynamic device group in Microsoft Entra ID for Intune management? (Choose three.)

Hard
138

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?

Medium
139

You manage a hybrid environment with Microsoft Intune and Microsoft Configuration Manager. You need to ensure that devices co-managed for Windows Update policies use Intune as the authoritative source for update deployments, while Configuration Manager continues to manage software updates. Which workload slider should you move to Intune?

Hard
140

You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?

Medium
141

A company uses Microsoft Intune to manage Windows 11 devices. Users report that the Company Portal app is not showing required applications. You verify that the devices show as 'Compliant' in Microsoft Intune. Which configuration should you check first?

Medium
142

Refer to the exhibit. You have applied this compliance policy to a Windows 10 device running build 10.0.19044. The device meets all requirements except that the firewall is disabled. What will be the compliance status of the device?

Medium
143

Refer to the exhibit. A Microsoft Graph PowerShell cmdlet retrieves devices. What is the purpose of this query?

Medium
144

A company uses Microsoft Intune to manage macOS devices. They need to deploy a custom plist configuration file to set security settings. Which policy type should they use?

Medium
145

Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?

Hard
146

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a Windows Update ring to defer quality updates by 7 days and feature updates by 60 days. Which two settings should you configure in the update ring? (Choose two.)

Medium
147

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?

Medium
148

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to collect a list of installed applications from these devices and view the data in the Intune admin center. What should you configure?

Easy
149

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, users receive a notification email with instructions to remediate the issue. The email must be sent only to the primary user of the device. What should you configure?

Medium
150

You are troubleshooting an Intune-managed Windows 10 device that is not receiving a required application. Which THREE steps should you take to diagnose the issue? (Choose three.)

Medium
151

Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?

Hard
152

You manage devices in Microsoft Intune. You need to generate a report that shows which devices have not checked in with Intune for more than 30 days. What should you use?

Easy
153

Refer to the exhibit. You create a compliance policy for Windows 10 devices. A device is reported as non-compliant. Upon investigation, you find that the device has a password of 6 characters. Which setting is causing the non-compliance?

Medium
154

You manage 500 Windows 11 devices with Microsoft Intune. Several devices are shared by multiple employees across shifts at a manufacturing plant. You need to configure a policy that automatically removes local user profiles that have not been used for 60 days to conserve disk space, while preserving profiles of users who sign in regularly. What should you configure?

Medium
155

You are deploying a Windows 11 device using Windows Autopilot. The device is enrolled in Microsoft Intune and assigned a device group. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and enrolls in Intune without user interaction. Which Autopilot deployment mode should you configure?

Hard
156

You manage a group of iOS devices enrolled in Microsoft Intune. Users report that they are unable to receive email on their devices after you deployed a new configuration profile. You need to identify the cause quickly. What should you use?

Easy
157

Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?

Easy
158

You are an endpoint administrator for a company that uses Microsoft Intune. You need to create a report that shows which devices have not checked in to Intune for more than 30 days. What should you use?

Easy
159

Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the result?

Medium
160

Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?

Hard
161

You manage Windows 11 devices with Microsoft Intune. After a Windows quality update is deployed to a pilot ring, several devices report installation failures in the Update reports. You need to identify the exact error code returned by the update installation on a specific device without accessing the device directly. What should you do?

Medium
162

You are troubleshooting a Windows 11 device that fails to install an Intune-managed update. The device has been offline for two weeks. After reconnecting, the update does not install. In the Intune console, the update shows 'Failed to install' with error code 0x800f0831. What is the most likely cause?

Hard
163

Your organization uses Microsoft Intune to manage devices. You need to collect diagnostic logs from a remote Windows device without user interaction. Which THREE methods can you use?

Hard
164

You are a Microsoft 365 Endpoint Administrator. You need to remotely wipe a lost Windows 11 device that is enrolled in Microsoft Intune. The device is currently offline. What happens when you initiate a wipe action from the Intune admin center?

Easy
165

You need to wipe a lost corporate-owned Windows 10 device that is enrolled in Intune. Which action should you take?

Easy
166

Which TWO Windows Update for Business policies can you configure using Microsoft Intune?

Hard
167

You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Microsoft Intune to manage its Windows 10 devices. The company recently experienced a ransomware attack that encrypted local files on several devices. To mitigate future attacks, management wants to ensure that all devices have real-time protection enabled in Microsoft Defender Antivirus and that Controlled Folder Access is turned on. You need to configure these settings via Intune. You decide to create a device configuration profile for Windows 10. What is the most efficient way to deploy these settings to all existing and future devices?

Easy
168

You are the endpoint administrator for a company using Microsoft Intune. The IT director asks you to generate a report that shows which Windows devices have not installed the latest security update in the past 14 days. What should you use?

Easy
169

You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?

Medium
170

You manage Windows 11 devices with Microsoft Intune. A line-of-business application must be deployed to a specific group of devices. The application installer requires administrative privileges and must run in the system context. You need to ensure the app installs silently without user interaction. What should you create?

Hard
171

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom configuration profile that sets a specific firewall rule. However, the profile fails to apply on a subset of devices. The Intune console shows 'Conflict' status. What is the most likely cause?

Hard
172

You are the Intune administrator for Contoso Ltd., a company with 5,000 Windows 11 devices and 1,000 iOS devices managed by Microsoft Intune. The company uses Microsoft Defender for Endpoint for threat detection. You need to implement a solution that ensures devices are compliant before they can access corporate resources. You have the following requirements: 1. Windows devices must have Defender for Endpoint running and report a threat level of 'low' or better. 2. iOS devices must have a PIN of at least 6 characters and be jailbreak-detected as 'not jailbroken'. 3. If a device becomes noncompliant, it should be blocked immediately with no grace period. 4. Noncompliant devices should receive a notification to the user. You create compliance policies for Windows and iOS. You also create a conditional access policy in Microsoft Entra ID to require compliant devices. After deploying, you find that some Windows devices that are missing Defender for Endpoint are still able to access email. What should you do to resolve this issue?

Hard
173

Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?

Hard
174

Your organization uses Microsoft Intune to manage 1,000 Windows 10 devices and 500 iOS devices. You need to enforce device compliance policies. For Windows devices, you require BitLocker encryption and Windows Defender Antivirus enabled. For iOS devices, you require a passcode of at least 6 characters and device encryption. Devices that become noncompliant should be marked as such and users should receive a notification email. After 7 days of noncompliance, the device should be blocked from accessing corporate email. You also need to create a report that shows the compliance status of all devices. Which combination of actions should you take?

Medium
175

A company uses Microsoft Intune to manage iOS devices. They need to enforce a policy that requires a passcode of at least 6 characters, allows Touch ID, and automatically wipes the device after 10 failed attempts. Which three settings should be configured in a device restrictions profile for iOS? (Choose three.)

Medium
176

You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?

Easy
177

A company uses Microsoft Intune to manage Windows devices. They want to deploy a custom line-of-business (LOB) app as a Win32 app. The app requires .NET Framework 4.8 and must be installed silently. Which file type should you use for the app deployment in Intune?

Medium
178

Your organization uses Microsoft Intune to manage devices. You need to configure a policy that automatically retires a device if it does not check in for 30 days. Which policy type should you configure?

Easy
179

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?

Medium
180

Which THREE conditions must be met for a Windows 10 device to be co-managed with Microsoft Intune and Microsoft Configuration Manager? (Choose three.)

Hard
181

You are implementing Windows Autopilot for your organization. You need to ensure that during the first boot, the device automatically enrolls in Microsoft Intune and joins Microsoft Entra ID. What is the minimum requirement for the device?

Medium
182

You have assigned the compliance policy shown in the exhibit to all Windows devices. A Windows 11 device running build 10.0.22621.1500 reports as noncompliant. Which setting is causing the noncompliance?

Hard
183

You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)

Hard

Frequently asked questions

What does the Manage and maintain devices domain cover on the MD-102 exam?
Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.
How many questions are in this domain?
This page lists all 183 Manage and maintain devices questions in the MD-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage and maintain devices questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
md-102 MD-102 manage maintain devices Practice Questions