Courseiva

CCNA Manage and maintain devices Questions

75 of 183 questions · Page 1/3 · Manage and maintain devices · Answers revealed

1
MCQmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?

A.Create a device enrollment restriction that blocks personally owned Windows devices and allow corporate-owned devices.
B.Configure an Autopilot deployment profile that targets only corporate devices.
C.Configure a conditional access policy that requires compliant devices for all cloud apps.
D.Create a device compliance policy that requires BitLocker and mark personal devices as noncompliant.
AnswerA

Device enrollment restrictions in Intune let you control which platforms and personal ownership types can enroll. By blocking personally owned Windows devices while allowing corporate-owned ones, you prevent personal devices from enrolling as managed endpoints. Users can still access email through a browser because browser access is governed by conditional access, not enrollment restrictions, so the requirement is met.

Why this answer

Enrollment restrictions in Intune are the mechanism for controlling whether personally owned devices can enroll for a given platform. By blocking personal Windows ownership while allowing corporate ownership, only corporate devices enroll. Because browser-based email access is controlled separately through conditional access, personal devices can still reach email in a browser without being enrolled.

Exam trap

The trap here is confusing enrollment restrictions, which gate enrollment, with compliance or conditional access policies, which evaluate or gate access after enrollment.

2
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device that is enrolled in Microsoft Intune. Which action should you perform in the Intune console?

A.Retire.
B.Wipe.
C.Delete.
D.Reset.
AnswerB

Wipe performs a full factory reset, removing all data, settings, and the management enrolment itself, which satisfies the requirement to remotely erase a lost corporate-owned iOS device. Retire would only remove corporate data and leave personal content intact, so it cannot guarantee the device is cleared.

Why this answer

The Wipe action in Microsoft Intune restores a device to its factory default settings, removing all corporate and personal data. This is the appropriate action for a lost corporate-owned iOS device to ensure sensitive data is completely erased and the device cannot be accessed. Retire only removes managed apps and policies but leaves personal data intact, which is insufficient for a lost device scenario.

Exam trap

The trap here is that candidates confuse 'Retire' with 'Wipe', mistakenly thinking Retire is sufficient for a lost device, but Retire only removes management and corporate data without performing a full device reset, leaving personal data and the device usable.

How to eliminate wrong answers

Option A (Retire) is wrong because it only removes managed apps, corporate data, and Intune management, but does not perform a full factory reset, leaving personal data and the device operational. Option C (Delete) is wrong because deleting the device from the Intune console simply removes its enrollment record without initiating any wipe or data removal on the device itself. Option D (Reset) is wrong because Intune does not have a 'Reset' action; the correct term for a full factory reset is 'Wipe', and 'Reset' is not a valid action in the Intune console.

3
MCQmedium

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that Windows Update for Business policies are applied to these devices to control when feature updates are installed. What should you configure?

A.A device configuration profile with the Windows Update settings.
B.A quality update policy.
C.A Windows 10 and later update ring.
D.A feature update policy.
AnswerC

Update rings in Intune are used to configure Windows Update for Business settings, including feature update deferrals, quality update deferrals, and active hours. By assigning an update ring to the device group, you control when feature updates are installed. This directly meets the requirement to apply Windows Update for Business policies for feature updates. Update rings are the primary method for managing Windows updates in Intune.

Why this answer

Windows Update rings in Intune are the primary way to configure Windows Update for Business settings, including feature update deferrals, quality update deferrals, and active hours. Assigning an update ring to the device group ensures that these policies are applied. Feature update policies are used to target specific versions, but they do not provide the full set of Windows Update for Business controls.

Quality update policies are for expedited updates, and configuration profiles are not the recommended method for update management.

Exam trap

The trap here is confusing update rings with feature update policies; update rings control the overall update cadence, while feature update policies target specific versions.

4
Multi-Selecthard

You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?

Select 2 answers
A.Ensure the device is in the correct Microsoft Entra ID group targeted by the policy.
B.Reissue the user's Microsoft 365 license from the admin center.
C.Reset the device's enrollment state via the Company Portal.
D.Verify that the device has an active internet connection and can reach Intune services.
E.Run Invoke-Command to remotely execute gpupdate /force.
AnswersA, D

Policy assignment flows through Microsoft Entra ID group membership, so a device outside the targeted group never receives the configuration. Confirming correct group membership restores delivery of the security policy and clears the noncompliant state.

Why this answer

Option A is correct because Intune policies are assigned to Microsoft Entra ID groups, so if the device (or its user) is not a member of the group targeted by the security policy, the policy will never be delivered and the device will remain non-compliant. Option D is correct because Intune is a cloud-based MDM service; the device must have an active internet connection and be able to reach Intune endpoints (e.g., *.manage.microsoft.com over TCP 443) for policy sync, check-in, and compliance evaluation to occur. Option B is not relevant because Microsoft 365 licensing affects access to services like Exchange and Office, not Intune policy delivery or compliance state.

Option C is not appropriate because resetting enrollment state via the Company Portal is a drastic remediation that removes management and would not fix a group-targeting or connectivity issue. Option E is incorrect because gpupdate /force applies on-premises Active Directory Group Policy, not Intune MDM policies, and Invoke-Command targets PowerShell remoting rather than Intune policy sync.

Exam trap

The trap here is that candidates often confuse Intune MDM policy delivery with traditional on-premises Group Policy, leading them to select the gpupdate command (Option E) instead of recognizing that Intune relies on OMA-DM sync and network connectivity.

5
MCQeasy

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. Users report that their devices are not receiving newly assigned compliance policies. You need to force the devices to check in with Intune immediately. What should you do from the Intune admin center?

A.Remove and re-enroll each device in Intune.
B.Run the 'gpupdate /force' command on each device.
C.Select each device and choose 'Sync' to initiate a device check-in.
D.Restart the Intune Management Extension service on each device.
AnswerC

The Sync action in the Intune admin center triggers an immediate check-in with the Intune service. This causes the device to download and apply any pending policies, including compliance policies. It is the correct and least disruptive method to force policy retrieval without waiting for the regular check-in interval.

Why this answer

The Sync action in the Intune admin center sends a remote check-in request to the device, prompting it to contact the Intune service and apply any pending policies. This is the standard, efficient way to force policy retrieval without user intervention or disruptive re-enrollment.

Exam trap

The trap here is confusing Group Policy refresh commands like gpupdate with Intune MDM policy sync, which requires the Intune Sync action.

6
MCQhard

An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?

A.Device configuration profile to enable BitLocker
B.Device compliance policy with a noncompliance action to mark device as non-compliant
C.PowerShell script deployment with assignment to all devices
D.Proactive remediations with a detection script for BitLocker status and a remediation script to enable BitLocker
AnswerD

Proactive remediations run a detection script on a schedule and execute a remediation script only when detection reports non-compliance, satisfying the automatic BitLocker enablement requirement. This differs from configuration profiles, which enforce settings but cannot run conditional script logic.

Why this answer

Proactive remediations in Microsoft Intune are specifically designed to detect and automatically fix common configuration drift on managed devices. By using a detection script to check BitLocker status and a remediation script to enable BitLocker, this feature meets the requirement for automatic remediation without user interaction or manual re-mediation.

Exam trap

The trap here is that candidates often confuse Proactive remediations with simple script deployment, not realizing that Proactive remediations provide a detection-then-remediation loop that automatically re-applies the fix when drift is detected, whereas a one-time script deployment does not.

How to eliminate wrong answers

Option A is wrong because a device configuration profile can enable BitLocker on new or compliant devices, but it does not automatically remediate devices that later become non-compliant (e.g., after a user disables BitLocker). Option B is wrong because a device compliance policy with a noncompliance action only marks the device as non-compliant and can trigger conditional access blocks, but it does not run a PowerShell script to re-enable BitLocker. Option C is wrong because PowerShell script deployment runs the script once at assignment or during a scheduled sync, but it lacks the detection-and-remediation loop that Proactive remediations provide; it cannot automatically re-run when BitLocker is disabled again.

7
MCQmedium

Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?

A.The devices failed to enroll properly.
B.The compliance policy includes a rule for 'Maximum days since last check-in' and these devices exceeded that limit.
C.The devices are running a non-Windows operating system.
D.The devices have names that do not match the naming convention.
AnswerB

A compliance policy rule of 'Maximum days since last check-in' directly marks devices noncompliant once their lastSyncDateTime exceeds the configured threshold. Since the exhibit shows lastSyncDateTime older than 30 days, those devices breached that rule, which explains the noncompliant complianceState without any other cause.

Why this answer

The compliance policy includes a rule for 'Maximum days since last check-in', which checks the `lastSyncDateTime` property. Devices that have not synced within the configured threshold (e.g., 30 days) are marked as noncompliant. This is a common Intune compliance setting for Windows devices to ensure they regularly communicate with the service.

Exam trap

The MD-102 exam often tests the distinction between enrollment failures and compliance violations; the trap here is that candidates may incorrectly attribute noncompliance to enrollment issues rather than recognizing that a valid `lastSyncDateTime` indicates successful enrollment, and the noncompliant state is due to a missed check-in threshold.

How to eliminate wrong answers

Option A is wrong because failed enrollment would prevent the device from appearing in the output at all, or it would show an enrollment failure state, not a compliance state of 'noncompliant' with a valid lastSyncDateTime. Option C is wrong because the PowerShell command specifically retrieves Windows devices (as stated in the question), and non-Windows OS devices would not be returned by this query. Option D is wrong because device naming conventions are not a compliance policy setting in Intune; naming is used for identification and management, not compliance evaluation.

8
Multi-Selecthard

Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?

Select 3 answers
A.Run a detection script to identify issues.
B.Send email alerts when issues are detected.
C.Schedule scripts to run at regular intervals.
D.Run a remediation script to fix issues.
E.Mark devices as non-compliant if remediation fails.
AnswersA, C, D

Detection scripts execute first to assess device state, returning exit code 0 for compliant or non-zero for non-compliant, which triggers the paired remediation script. This satisfies the stem's requirement for actions available in proactive remediations, where detection is the mandatory first stage before any corrective action runs on the Windows device.

Why this answer

Proactive remediations in Microsoft Intune are built on a two-part script package, so option A is correct: each remediation includes a detection script that runs first to identify whether a problem exists on the Windows device. Option D is also correct because, when the detection script reports a non-compliant state, the paired remediation script executes to fix the identified issue. Option C is correct as well, since proactive remediations are assigned to device groups and run on a configurable schedule (for example, daily or hourly) rather than only once.

Option B is not part of proactive remediations, as Intune does not send email alerts as a built-in remediation action; reporting is surfaced through Intune reports and Endpoint Analytics. Option E is incorrect because proactive remediations do not change device compliance state — compliance is governed separately by compliance policies, and remediation scripts only detect and fix issues.

Exam trap

The trap here is that candidates often confuse proactive remediations with compliance policies or alerting features, assuming that failed remediation can automatically trigger non-compliance or email notifications, but Intune separates these functions into distinct policies and requires additional configuration for alerts.

9
MCQeasy

Your organization uses Windows Autopilot for device provisioning. Users report that after initial setup, devices are not automatically enrolled in Microsoft Intune. What should you verify?

A.That a device configuration profile is assigned to the devices.
B.That the devices are registered in Windows Autopilot with a valid hardware hash.
C.That a Conditional Access policy is in place requiring Intune enrollment.
D.That a device compliance policy is assigned to the Autopilot devices.
AnswerB

Autopilot requires each device's unique hardware hash registered as an Autopilot device before deployment, which links the device to your tenant and drives Intune enrolment. Without a valid hash, the profile cannot target the device, so automatic enrolment silently fails.

Why this answer

Windows Autopilot requires devices to be registered in the Autopilot service with a valid hardware hash (or other unique identifier like PKID or serial number) so that the service can match the device during OOBE and trigger the enrollment process into Intune. Without a valid hardware hash, the device will not be recognized by Autopilot and will proceed through standard OOBE without automatic Intune enrollment.

Exam trap

The trap here is that candidates often confuse post-enrollment policies (configuration profiles, compliance, Conditional Access) with the prerequisite registration step, assuming any assigned policy will force enrollment, when in fact the device must first be recognized by Autopilot via a valid hardware hash.

How to eliminate wrong answers

Option A is wrong because a device configuration profile is used to apply settings after enrollment, not to trigger enrollment itself; Autopilot enrollment happens before configuration profiles are applied. Option C is wrong because Conditional Access policies control access to resources after enrollment, they do not initiate or enforce the enrollment process during Autopilot. Option D is wrong because device compliance policies are evaluated after a device is enrolled in Intune, they have no role in the initial enrollment step.

10
MCQhard

Your company uses Microsoft Intune to manage Windows 11 devices. A security policy requires that devices automatically receive quality updates as soon as they are available, with a deadline of 2 days after release and automatic restart outside active hours. You create a Windows update ring in Intune. Which setting should you configure to meet the deadline requirement?

A.Set 'Restart checks' to 'Allow' and configure 'Auto restart' to 'Always'.
B.Set 'Automatic update behavior' to 'Auto install and restart at maintenance time'.
C.Set 'Update deadline' to 2 days and configure 'Grace period' as needed.
D.Set 'Active hours start' and 'Active hours end' to define the restart window.
AnswerC

The update deadline setting in a Windows update ring specifies the number of days after an update is available before it is forcibly installed and the device restarts. Setting it to 2 days meets the requirement. The grace period can allow users to postpone within that deadline.

Why this answer

A Windows update ring in Intune includes an 'Update deadline' setting that forces installation and restart after a specified number of days. Setting it to 2 days ensures quality updates are installed and the device restarts within two days of release, meeting the security policy. Other settings like active hours or auto restart do not enforce the deadline.

Exam trap

The trap here is confusing the deadline setting with automatic update behavior or active hours, which control timing but do not enforce a mandatory installation deadline.

11
MCQhard

Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?

A.The device was enrolled 5 days ago.
B.The device is non-compliant.
C.The device is unenrolled.
D.The device has not communicated with Intune for 5 days.
AnswerD

lastSyncDateTime records the most recent check-in between the device and the Intune service. A value five days old means no communication has occurred since then, so the device is likely offline, powered down, or otherwise unable to reach the service.

Why this answer

The `lastSyncDateTime` property in Microsoft Graph for Intune-managed devices indicates the most recent time the device successfully checked in with the Intune service. A value of 5 days ago means the device has not communicated with Intune for 5 days, which could be due to network issues, device inactivity, or configuration problems. This does not inherently mean the device is non-compliant or unenrolled—it simply reflects the last successful sync.

Exam trap

The trap here is that candidates often confuse `lastSyncDateTime` with enrollment date or compliance status, leading them to incorrectly assume the device is non-compliant or unenrolled, when in fact it simply indicates the last successful communication with Intune.

How to eliminate wrong answers

Option A is wrong because `lastSyncDateTime` records the last successful sync with Intune, not the enrollment date; enrollment date is tracked by the `enrolledDateTime` property. Option B is wrong because a device can be non-compliant for many reasons (e.g., missing required updates, jailbreak detection) and a stale sync date alone does not determine compliance—compliance is evaluated based on policy conditions, not sync recency. Option C is wrong because an unenrolled device would not appear in the managed devices list at all; the `lastSyncDateTime` field would be absent or the device would be removed from the inventory.

12
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?

Select 2 answers
A.Create local user accounts on the device
B.Remotely wipe a device
C.Configure DHCP settings
D.Apply BitLocker encryption policies
E.Add the device to an Active Directory group
AnswersB, D

Intune's remote device actions include wipe, which performs a factory reset removing corporate and personal data. This is distinct from retire, which removes only company data and management, and from selective wipe on supported platforms.

Why this answer

Option B is correct because Microsoft Intune supports remote device actions such as a full wipe (and also selective wipe/retire) for Windows 10 devices enrolled in MDM, allowing an administrator to reset the device to factory settings and remove corporate data. Option D is correct because Intune provides built-in BitLocker disk encryption policies (via the Endpoint Security Disk Encryption profile or configuration profiles) that let you enforce and manage BitLocker on Windows 10 devices, including storing recovery keys in Azure AD/Intune. Option A is not correct because Intune does not create local user accounts on Windows 10 devices; local account management is done via Group Policy, PowerShell, or other on-premises tools, not Intune MDM policy.

Option C is not correct because DHCP settings are configured on the DHCP server or network infrastructure, not through Intune device management policies. Option E is not correct because adding a device to an Active Directory group is an on-premises AD/Group Policy or Azure AD dynamic group operation, not an Intune device management action.

Exam trap

The trap here is that candidates often confuse Intune's device management capabilities with on-premises Group Policy or Active Directory tasks, leading them to incorrectly select options like creating local users or managing DHCP, which are outside Intune's scope.

13
MCQeasy

You need to ensure that Windows 10 devices are automatically upgraded to Windows 11 if they meet hardware requirements. Which policy should you configure in Microsoft Intune?

A.Assign a driver update policy.
B.Assign a quality update policy.
C.Assign an update ring for Windows 10.
D.Assign a Windows 10/11 feature update policy.
AnswerD

A Windows 10/11 feature update policy in Microsoft Intune deploys a specific Windows 11 release to targeted devices, honouring the hardware readiness checks performed by Windows Update for Business. This directly satisfies the requirement that eligible Windows 10 devices upgrade automatically, while incompatible hardware is excluded from the rollout.

Why this answer

A Windows 10/11 feature update policy in Microsoft Intune is specifically designed to manage the upgrade of Windows 10 devices to Windows 11. This policy uses Windows Update for Business to deliver the feature update (e.g., Windows 11 23H2) and automatically applies it to devices that meet the hardware requirements, ensuring a controlled upgrade process.

Exam trap

The trap here is that candidates confuse 'update rings' (which control update behavior like deferrals and deadlines) with 'feature update policies' (which actually push the OS version upgrade), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because a driver update policy only manages driver updates, not OS version upgrades; it cannot trigger a Windows 11 feature update. Option B is wrong because a quality update policy handles cumulative security and non-security patches (e.g., monthly updates), not feature updates that change the OS version. Option C is wrong because an update ring for Windows 10 configures deferral and update behavior for Windows 10 updates but does not initiate a feature upgrade to Windows 11; it only controls how existing Windows 10 updates are applied.

14
MCQeasy

You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?

A.Proactive remediations
B.PowerShell scripts (Devices > Scripts)
C.Compliance policy
D.Device configuration profile
AnswerB

PowerShell scripts in Intune run in the SYSTEM context on enrolled Windows 10 devices by default, satisfying the stem's requirement. Upload the script under Devices > Scripts, where it executes once or on a schedule without user credentials, unlike proactive remediations or platform scripts requiring different scopes.

Why this answer

PowerShell scripts (Devices > Scripts) in Intune allow you to upload and assign custom PowerShell scripts that run under the SYSTEM account on Windows 10 devices. This feature is specifically designed for executing scripts during device enrollment or on a schedule, ensuring the script has elevated privileges without user interaction.

Exam trap

A common misconception is that Proactive remediations can replace custom PowerShell scripts. However, Proactive remediations require both a detection script and a remediation script, and are designed for automatic remediation of specific issues, not for general script deployment. Custom PowerShell scripts (Devices > Scripts) are the correct choice for deploying a standalone script under the SYSTEM account.

How to eliminate wrong answers

Option A is wrong because Proactive remediations are used for detecting and fixing common support issues with built-in detection and remediation scripts, not for deploying custom PowerShell scripts under the SYSTEM account. Option C is wrong because Compliance policies evaluate device settings against defined rules and do not execute scripts. Option D is wrong because Device configuration profiles manage settings via CSPs (Configuration Service Providers) and cannot run arbitrary PowerShell scripts.

15
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device enrolled in Microsoft Intune. The device is currently offline. What will happen when the device comes online?

A.The device must be unenrolled first and then wiped.
B.The device will be wiped immediately after a grace period of 24 hours.
C.The device will receive the wipe command the next time it checks in with Intune.
D.The wipe command will be queued only if the device is supervised.
AnswerC

Intune queues the wipe command until the device next establishes a connection, since it cannot push to an offline endpoint. On reconnection, the check-in retrieves the pending action and executes the wipe, satisfying the offline constraint in the stem.

Why this answer

When a remote wipe command is issued for an offline iOS device enrolled in Microsoft Intune, the command is stored in the Microsoft Intune service. The device will receive and execute the wipe command the next time it checks in with the Intune service, regardless of whether it is supervised or not. This check-in occurs periodically (typically every 8 hours) or when the device is powered on and connected to the internet.

Exam trap

The trap here is that candidates often confuse the offline wipe behavior with a mandatory grace period or think that supervision is required for remote wipe, when in fact Intune queues the command and executes it on the next check-in for any enrolled iOS device.

How to eliminate wrong answers

Option A is wrong because there is no requirement to unenroll the device before a remote wipe; the wipe command itself triggers the removal of management and corporate data. Option B is wrong because there is no built-in 24-hour grace period for offline wipe commands in Intune; the wipe executes immediately upon the next check-in, not after a fixed delay. Option D is wrong because the wipe command is not queued only for supervised devices; both supervised and unsupervised iOS devices can receive and execute a remote wipe command when they come online.

16
MCQhard

Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?

A.Create a device configuration profile that sets the Defender signature update interval to every hour and assign it to all devices.
B.Configure a Windows Defender Application Control policy that blocks access to Microsoft 365 when the signature is older than the required version.
C.Add a compliance policy rule that requires the device to be at or below a specific OS build version and rely on that as a proxy for signature currency.
D.Add a custom compliance setting to the compliance policy that uses a PowerShell discovery script returning the signature version and a JSON file that validates it.
AnswerD

Custom compliance settings in Intune allow a PowerShell discovery script to gather any device property, including Defender signature version, and a JSON file to define the expected values. This is the supported way to evaluate a condition that is not exposed as a built-in compliance rule, and the result feeds directly into the device compliance state used by conditional access.

Why this answer

Intune compliance policies include built-in rules for Defender Antivirus status, but they do not natively expose a rule for a specific signature version. Custom compliance settings close that gap: a PowerShell discovery script reads the current signature version from the device, and a JSON file defines the acceptable values. The resulting compliance state is then honored by conditional access, ensuring only devices with current signatures reach Microsoft 365.

Exam trap

The trap here is assuming that a Defender-related configuration profile or a built-in compliance rule can enforce a specific signature version, when only custom compliance settings can evaluate arbitrary properties.

17
MCQhard

Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?

A.The compliance policy requires password, but the device configuration policy does not configure any password settings, leading to non-compliance.
B.The compliance policy requires encryption, but the device configuration policy does not enforce BitLocker startup PIN, causing compliance failure.
C.The device configuration policy sets scanParameter to 'fullscan', which may interfere with compliance checks.
D.The compliance policy requires Defender, but the device configuration policy sets cloudBlockLevel to 'high', which may conflict with some devices.
AnswerA

Intune evaluates compliance independently of configuration. Because the compliance policy mandates a password while the configuration policy sets none, devices without a password are flagged non-compliant even though BitLocker and Defender Antivirus satisfy their own requirements. The password requirement is the conflicting setting.

Why this answer

The compliance policy requires a password, but the device configuration policy does not configure any password settings. In Intune, compliance policies evaluate device settings independently of configuration policies; if a compliance policy mandates a password and the device lacks one (because the configuration policy doesn't enforce it), the device will be marked non-compliant. BitLocker and Defender being enabled do not satisfy a password requirement, so the conflict is the missing password configuration.

Exam trap

The trap here is that candidates assume enabling BitLocker and Defender automatically satisfies all compliance requirements, but Intune compliance policies evaluate each setting independently, so a missing password configuration will cause non-compliance even if other security features are present.

How to eliminate wrong answers

Option B is wrong because the compliance policy requires encryption, not a BitLocker startup PIN; the device configuration policy not enforcing a startup PIN does not cause compliance failure if BitLocker is enabled and encryption is satisfied. Option C is wrong because the scanParameter setting in a device configuration policy does not interfere with compliance checks; compliance policies evaluate security state, not scan parameters. Option D is wrong because cloudBlockLevel set to 'high' in a device configuration policy does not conflict with a compliance policy requiring Defender; both can coexist without causing non-compliance.

18
MCQeasy

You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?

A.A PowerShell script deployed to the user group.
B.An app configuration policy assigned to the user group.
C.A compliance policy assigned to the user group.
D.A device configuration profile assigned to the device group.
AnswerD

Device configuration profiles are applied to devices and can be targeted to device groups. They are processed during enrollment and can apply settings before user sign-in, especially if they are assigned to the device. This ensures that the settings are in place regardless of which user signs in, meeting the requirement.

Why this answer

Device configuration profiles are the correct choice because they are designed to apply settings to devices and can be targeted to device groups. When assigned to a device group, they are processed during enrollment and apply to the device itself, ensuring settings are in place before any user signs in. This meets the requirement of applying settings that affect all users of the device.

Exam trap

The trap here is confusing device configuration profiles with compliance policies or user-targeted scripts, which do not apply settings at the device level before sign-in.

19
Multi-Selectmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to configure a remediation to automatically restart the Windows Update service (wuauserv) if it stops. You create a proactive remediation script package. Which two components must you provide in the script package? (Choose two.)

Select 2 answers
A.A detection script that checks whether the Windows Update service is running
B.A PowerShell script that runs only once at device enrollment
C.A requirement rule that checks the service status before installation
D.A compliance policy that marks the device noncompliant if the service is stopped
E.A remediation script that starts the Windows Update service if it is stopped
AnswersA, E

A detection script is required in a proactive remediation to determine if the device is compliant or non-compliant. In this scenario, it must check the status of the Windows Update service and exit with a non-zero code or 'non-compliant' output if the service is stopped, triggering the remediation script.

Why this answer

A proactive remediation script package in Intune consists of two scripts: a detection script and a remediation script. The detection script identifies whether the Windows Update service is running; if it is not, it signals non-compliance. The remediation script then starts the service.

Together, they automate the detection and correction of the issue, ensuring the service is restarted without manual intervention.

Exam trap

The trap here is confusing proactive remediation components with app deployment requirement rules or compliance policies, which serve different purposes.

20
MCQmedium

You manage a set of Windows 11 devices enrolled in Microsoft Intune. Users report that they can no longer sign in with their Microsoft Entra ID credentials after you deployed a new compliance policy. The devices show as compliant in Intune, but the sign-in fails with an error about device not meeting requirements. You need to ensure that users can sign in. What should you do?

A.Review the conditional access policy that requires compliant devices and ensure the device is included.
B.Restart the Intune Management Extension service on the affected devices.
C.Assign the compliance policy to the device group instead of the user group.
D.Modify the compliance policy to mark the devices as compliant manually.
AnswerA

The sign-in error indicates that conditional access is blocking access because the device is not considered compliant. Even if Intune shows the device as compliant, the conditional access policy might not be targeting the correct device or user group, or the device might not be registered in Microsoft Entra ID. Verifying the policy's included devices and users ensures the device meets the access requirements.

Why this answer

The sign-in error indicates a conditional access block despite Intune reporting compliance. Conditional access evaluates device compliance at authentication time, and if the device is not included in the policy or not properly registered, access is denied. Reviewing the conditional access policy to ensure the device is targeted and meets requirements resolves the issue.

Other actions do not address the authentication flow.

Exam trap

The trap here is assuming that a compliant status in Intune automatically grants access, without verifying that the conditional access policy includes the device and that the device is registered in Microsoft Entra ID.

21
MCQmedium

Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?

A.The devices are running a non-Windows OS.
B.The devices have not synced recently.
C.The devices do not meet the assigned compliance policies.
D.The admin lacks permissions to view compliance details.
AnswerC

A recent lastSyncDateTime confirms the device checked in and evaluated policy, so the noncompliant state reflects an actual policy failure rather than stale reporting. Microsoft Entra ID marks a device noncompliant when its settings breach the assigned compliance policy conditions, such as missing updates, disabled encryption, or absent antivirus.

Why this answer

A device's complianceState is determined by evaluating its configuration against assigned compliance policies. Even if lastSyncDateTime is recent, the device will be marked 'noncompliant' if it fails any of the policy checks (e.g., missing required updates, encryption not enabled, or a required antivirus solution not running). The sync timestamp only indicates when the device last communicated with Intune, not whether it meets policy requirements.

Exam trap

The trap here is that candidates assume a recent sync timestamp implies the device is healthy or compliant, when in fact sync and compliance are separate attributes—a device can be fully synced yet persistently noncompliant due to policy violations.

How to eliminate wrong answers

Option A is wrong because the cmdlet specifically queries 'managed Windows devices', so the output only includes Windows devices; a non-Windows OS would not appear in these results. Option B is wrong because the exhibit explicitly shows that lastSyncDateTime is recent, meaning the devices have synced recently; noncompliance is not caused by a lack of sync. Option D is wrong because if the admin lacked permissions to view compliance details, the cmdlet would either fail or return an access-denied error, not show a complianceState of 'noncompliant' for specific devices.

22
MCQhard

You manage devices with Microsoft Intune. You need to ensure that only devices with a specific BIOS serial number can enroll. What should you configure?

A.Enrollment restrictions that block devices by hardware identifier.
B.A device category with a dynamic group based on BIOS serial.
C.A device compliance policy that checks BIOS serial number.
D.A Conditional Access policy that requires a compliant device.
AnswerA

Enrollment restrictions can block devices based on hardware IDs like BIOS serial numbers.

Why this answer

Intune's enrollment restrictions allow you to block or allow devices based on hardware identifiers such as the BIOS serial number. By adding the specific BIOS serial numbers to the blocked hardware identifiers list, you can effectively prevent any device that does not match the allowed serials from enrolling. This is the only built-in mechanism in Intune that directly controls enrollment eligibility based on hardware characteristics.

Exam trap

The trap here is that candidates often confuse post-enrollment controls (compliance policies, Conditional Access) with pre-enrollment controls (enrollment restrictions), leading them to select options that only take effect after the device has already enrolled.

How to eliminate wrong answers

Option B is wrong because device categories and dynamic groups are used for organizational and targeting purposes after enrollment, not to block or allow enrollment itself. Option C is wrong because a device compliance policy checks conditions after enrollment and can mark a device as noncompliant, but it does not prevent the device from enrolling in the first place. Option D is wrong because a Conditional Access policy that requires a compliant device only applies after the device is enrolled and registered in Azure AD; it cannot block the initial enrollment process.

23
MCQhard

A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?

A.FileVault is not actually enabled on those devices.
B.The recovery key is not escrowed to Intune.
C.The devices are not supervised.
D.The compliance policy is not assigned to those devices.
AnswerB

FileVault being enabled is insufficient for compliance because Intune requires the personal recovery key to be escrowed before it reports the device as compliant. Without escrow, Intune cannot verify key custody, so the device shows non-compliant despite active encryption.

Why this answer

The most likely cause is that the recovery key is not escrowed to Intune. Even though FileVault is enabled on the device, Intune's compliance policy checks for the presence of the FileVault recovery key in its escrow database. If the key is missing, the device is marked non-compliant because Intune cannot verify full management and recovery capability, which is a key security requirement.

Exam trap

The trap here is that candidates assume enabling FileVault alone satisfies compliance, but Intune requires the recovery key to be escrowed to confirm full manageability and recovery capability.

How to eliminate wrong answers

Option A is wrong because the scenario explicitly states that FileVault is enabled on the non-compliant devices, so the issue is not that encryption is absent. Option C is wrong because macOS devices do not require supervision for FileVault compliance; supervision is an iOS/iPadOS concept and does not apply to macOS in this context. Option D is wrong because if the compliance policy were not assigned, the devices would not appear in compliance reports at all, or would show as 'not evaluated' rather than 'non-compliant'.

24
MCQeasy

You manage devices in Microsoft Intune. You need to ensure that a specific set of Windows 10 devices automatically receive new configuration profiles as soon as they are assigned. The devices are already enrolled and are members of an Microsoft Entra ID group. What should you do?

A.Create a device category and assign the profile to that category.
B.Assign the configuration profile to the user who owns the devices.
C.Assign the configuration profile to the Microsoft Entra ID group.
D.Use a dynamic device group based on device name and assign the profile to it.
AnswerC

Assigning the configuration profile to the Microsoft Entra ID group ensures that all devices in that group receive the profile. Intune automatically applies assigned profiles to targeted devices upon check-in. This is the standard method to deploy configurations to a set of devices.

Why this answer

Assigning the configuration profile to the existing Microsoft Entra ID group that contains the devices is the most direct and effective method. Intune will deploy the profile to all devices in the group automatically. Other options either target users, use categories that are not for assignment, or introduce unnecessary complexity.

Exam trap

The trap here is overcomplicating the assignment by using dynamic groups or categories when a static group already exists.

25
MCQhard

You are implementing Windows Autopilot for a new fleet of devices. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and is enrolled in Intune. Which configuration is required?

A.Upload corporate identifiers for each device.
B.Configure the Enrollment Status Page in Intune.
C.Create an Autopilot deployment profile assigned to the devices.
D.Create a dynamic device group in Microsoft Entra ID.
AnswerC

An Autopilot deployment profile defines the OOBE behaviour, including the join type. Setting it to Microsoft Entra joined with automatic Intune enrolment satisfies the requirement that the device joins the tenant and enrols during OOBE without manual intervention.

Why this answer

An Autopilot deployment profile specifies the out-of-box experience (OOBE) settings, including the option to automatically join the device to Microsoft Entra ID and enroll it in Intune. Without a deployment profile assigned to the device, Autopilot will not enforce these behaviors during OOBE.

Exam trap

The trap here is that candidates often confuse the prerequisite step of registering the device (uploading corporate identifiers) with the configuration step that actually defines the OOBE behavior (the deployment profile), leading them to select Option A instead of C.

How to eliminate wrong answers

Option A is wrong because uploading corporate identifiers (e.g., hardware hashes) registers the device with Autopilot but does not configure the OOBE behavior; it only enables the device to be recognized by the Autopilot service. Option B is wrong because the Enrollment Status Page (ESP) controls the post-enrollment device setup experience (e.g., app and policy installation progress), not the initial join or enrollment actions during OOBE. Option D is wrong because a dynamic device group in Microsoft Entra ID is used for targeting policies or applications after enrollment, not for triggering or configuring the Autopilot OOBE flow.

26
MCQhard

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

A.It sets the Windows Update for Business ring to that version.
B.It requires the device to be on a specific feature update.
C.It defines the minimum OS build version that the device must have to be compliant.
D.It forces the device to update to that version.
AnswerC

The osMinimumVersion setting in a compliance policy specifies the lowest acceptable OS build; devices below it are marked non-compliant. This satisfies the requirement to enforce a minimum Windows build, letting Intune flag outdated devices and trigger remediation or conditional access blocks.

Why this answer

The 'osMinimumVersion' setting in a Windows 10 compliance policy specifies the minimum OS build version (e.g., 10.0.19041) that a device must have to be considered compliant. If the device's OS build version is lower than this value, Intune marks it as non-compliant, which can trigger conditional access blocks or remediation actions. This setting does not initiate an update; it only evaluates the current version against the defined threshold.

Exam trap

Microsoft often tests the distinction between compliance evaluation (osMinimumVersion) and update enforcement (feature update policies or update rings), leading candidates to incorrectly assume that a compliance setting can force an update.

How to eliminate wrong answers

Option A is wrong because 'osMinimumVersion' does not configure any Windows Update for Business ring; update rings are set via a separate 'UpdateRing' policy or configuration profile. Option B is wrong because the setting checks the exact build number, not a feature update version like '21H2'; feature update versions are managed via feature update deployment policies, not compliance policies. Option D is wrong because this setting is purely evaluative and does not force or trigger an update; it only reports compliance status based on the current OS version.

27
Multi-Selecteasy

You need to deploy a Windows 10 feature update to a pilot group. Which TWO steps are required in Microsoft Intune?

Select 2 answers
A.Create a feature update policy for Windows 10.
B.Create a driver update policy for Windows 10.
C.Assign the feature update policy to a device group containing pilot devices.
D.Create an update ring for Windows 10.
E.Create a compliance policy for Windows 10.
AnswersA, C

A feature update policy defines which Windows 10 version to deploy and its rollout settings, such as when the update becomes mandatory. This satisfies the stem's deployment requirement by creating the object that later gets assigned to the pilot device group.

Why this answer

Option A is correct because in Microsoft Intune, deploying a Windows 10 feature update requires creating a Windows 10 feature update policy (under Software updates > Windows 10 feature updates), which specifies the target Windows version (e.g., Windows 10 21H2) and rollout settings. Option C is correct because a policy has no effect until it is assigned to a group; you must assign the feature update policy to an Azure AD device group containing the pilot devices so those devices receive the update. Option B is incorrect because driver update policies manage hardware driver updates via Windows Update for Business, not OS feature updates.

Option D is incorrect because update rings control quality (monthly cumulative) updates and deferral/servicing settings, not feature update deployment. Option E is incorrect because compliance policies only evaluate device conditions (e.g., BitLocker, OS version) and do not deliver feature updates.

Exam trap

The trap here is confusing update rings (which control deferral periods and deadlines) with feature update policies (which explicitly set the target version), leading candidates to select 'Create an update ring' instead of the correct feature update policy.

28
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?

A.Create an app protection policy targeting Microsoft 365 apps.
B.Create a device configuration policy to enable TPM and Secure Boot.
C.Create a device compliance policy requiring TPM and Secure Boot, and a Conditional Access policy to block non-compliant devices.
D.Create a Conditional Access policy requiring TPM and Secure Boot.
AnswerC

The compliance policy evaluates TPM 2.0 and Secure Boot state via device health attestation, marking non-compliant devices; Conditional Access then blocks their access to Microsoft 365 resources. This combination enforces the hardware constraint at authentication time rather than merely reporting it.

Why this answer

Device compliance policies in Microsoft Intune can evaluate hardware attributes like TPM version and Secure Boot status. When combined with a Conditional Access policy that blocks non-compliant devices, this enforces the security requirements before granting access to Microsoft 365 resources. This two-step approach ensures only devices meeting the hardware security baseline can authenticate.

Exam trap

The trap here is that candidates often think a Conditional Access policy alone can directly check hardware features, but it actually requires a compliance policy to report those attributes first.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection within apps (e.g., copy/paste restrictions) and do not evaluate device-level hardware features like TPM or Secure Boot. Option B is wrong because device configuration policies are used to configure settings (e.g., enable BitLocker) but cannot enforce access control; they lack the ability to block devices from accessing cloud resources. Option D is wrong because a Conditional Access policy alone cannot evaluate TPM or Secure Boot; it relies on device compliance status, which must be reported by Intune via a compliance policy.

29
MCQmedium

You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?

A.Confirm that the user is assigned a Microsoft Entra ID P1 license.
B.Verify that the BitLocker recovery key is backed up to Microsoft Entra ID.
C.Ensure the Windows Defender Firewall allows inbound RPC traffic.
D.Check that the MDM enrollment URL (https://enrollment.manage.microsoft.com) is reachable and not blocked by a proxy.
AnswerD

Reaching the MDM enrolment URL is the prerequisite for MDM enrolment, but the stem already confirms internet connectivity, so a proxy blocking that specific endpoint remains the plausible cause. Domain-joined devices use the enrolment URL directly; verifying it is reachable isolates proxy or firewall filtering from the update's other effects.

Why this answer

The most common cause of MDM enrollment failure after a Windows update is a change in proxy or firewall settings that blocks the MDM enrollment URL. Since the devices can reach the internet generally but fail specifically during enrollment, verifying that `https://enrollment.manage.microsoft.com` is reachable and not blocked by a proxy is the logical first troubleshooting step. This URL is required for the device to communicate with the Intune MDM service during the enrollment process.

Exam trap

The trap here is that candidates often assume a general internet connection means all services are reachable, but MDM enrollment requires specific URLs that may be blocked by a proxy or firewall even when general browsing works.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID P1 licenses are required for features like Conditional Access, but not for basic MDM enrollment; a user needs an Intune license (e.g., Microsoft 365 E3/E5 or standalone Intune) to enroll. Option B is wrong because BitLocker recovery key backup to Microsoft Entra ID is a post-enrollment compliance or recovery feature, not a prerequisite for MDM enrollment. Option C is wrong because inbound RPC traffic is not required for MDM enrollment; the device initiates outbound HTTPS (TCP 443) connections to Intune, and inbound RPC is irrelevant to this process.

30
MCQhard

Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?

A.The devices have an OS version lower than 10.0.19041.
B.The install command line is missing the /silent switch.
C.The detection rule path is incorrect.
D.The install experience is set to system, but should be user.
AnswerA

Windows 10 builds below 10.0.19041 fall outside the minimum operating system requirement configured in the Win32 app's applicability rules, so Intune marks the app as not applicable and skips installation. Raising the requirement or upgrading those devices restores deployment, satisfying the OS version constraint in the stem.

Why this answer

The exhibit shows the 'Minimum OS version' requirement set to 10.0.19041 (Windows 10 version 20H1/2004). Devices with an OS build lower than this threshold will fail to install the Win32 app, as Intune enforces this requirement before executing the installation command. This is a common configuration issue when deploying apps to a mixed-OS environment.

Exam trap

The trap here is that candidates often focus on the install command or detection rules as the cause of installation failure, overlooking the explicit OS version requirement that prevents installation from even starting on incompatible devices.

How to eliminate wrong answers

Option B is wrong because the install command line is not missing the /silent switch; the exhibit shows the command includes '--silent' (or a similar silent flag), so the absence of /silent is not the issue. Option C is wrong because the detection rule path being incorrect would cause the app to appear as 'Not Installed' on devices where it actually installed, not prevent installation from starting. Option D is wrong because the install experience set to 'system' is correct for system-wide installations; setting it to 'user' would install per-user and could cause issues, but the exhibit shows 'system' is selected, so this is not the problem.

31
Multi-Selectmedium

Which THREE are valid Windows Autopilot deployment scenarios?

Select 3 answers
A.Self-deploying
B.App-driven
C.User-driven
D.Policy-driven
E.White glove
AnswersA, C, E

Self-deploying mode provisions devices with no user interaction, using a device-based Microsoft Entra ID join and TPM attestation. This satisfies the scenario's requirement for kiosk and shared-device rollouts where no credentials can be entered, making it one of the three valid Windows Autopilot deployment scenarios.

Why this answer

Self-deploying (A) is a valid Windows Autopilot scenario in which the device is provisioned with no user interaction, using a device-targeted profile and TPM attestation, ideal for kiosks and shared devices. User-driven (C) is valid because it lets the end user sign in with their Azure AD credentials during OOBE, after which the Autopilot profile applies device and user settings. White glove (E) is valid as the pre-provisioning scenario where a partner or IT technician runs the provisioning process so the device reaches the user ready for a fast, final sign-in.

App-driven (B) and Policy-driven (D) are not Autopilot deployment scenarios; Autopilot modes are defined by user interaction and pre-provisioning, not by app or policy triggers.

Exam trap

The trap here is that candidates confuse deployment phases or management concepts (like app or policy deployment) with the three official Autopilot deployment scenarios, which are strictly self-deploying, user-driven, and white glove (pre-provisioning).

32
Multi-Selecteasy

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)

Select 2 answers
A.Reset a user's password.
B.View hardware inventory of a device.
C.Remotely sync a device with Intune.
D.Manage on-premises Active Directory objects.
E.Assign Microsoft 365 licenses to a user.
AnswersB, C

Inventory is visible in the device properties.

Why this answer

The Microsoft Intune admin center provides a hardware inventory view for managed Windows devices, displaying details such as processor, RAM, disk space, and firmware version. This data is collected via the Intune Management Extension and device inventory reports, enabling administrators to assess device compliance and readiness without requiring on-premises tools.

Exam trap

The trap here is that candidates confuse user management tasks (password reset, license assignment) with device management actions, or assume Intune can manage on-premises AD objects, when Intune's scope is strictly cloud-based device and app management via MDM and MAM.

33
MCQhard

You are configuring Windows Update for Business policies in Microsoft Intune for a group of Windows 11 devices. You need to ensure that devices do not install feature updates for 60 days after a new version is released, while still receiving quality updates immediately. Which setting should you configure?

A.Set the 'Automatic update behavior' to 'Auto install at maintenance time'.
B.Set the 'Quality update deferral period (days)' to 60.
C.Configure a Windows Update ring with a 'Servicing channel' set to 'Semi-Annual Channel'.
D.Set the 'Feature update deferral period (days)' to 60.
AnswerD

The feature update deferral period setting in Windows Update for Business allows you to postpone feature updates for a specified number of days after their release. Setting it to 60 ensures devices wait 60 days before installing a new feature update, while quality updates are not deferred and install immediately. This directly meets the requirement.

Why this answer

Feature update deferral in Windows Update for Business is specifically designed to delay feature updates while allowing quality updates to proceed. Setting the deferral period to 60 days ensures that devices will not receive a new feature update until 60 days after its release, meeting the requirement without affecting quality updates.

Exam trap

The trap here is confusing deferral settings for quality updates with those for feature updates, which can lead to delaying security patches unintentionally.

34
MCQhard

You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?

A.Endpoint Protection
B.Windows Update Policies
C.Client Apps
D.Device Configuration
AnswerB

Moving the Windows Update Policies workload slider to Intune transfers update policy authority from Configuration Manager to Intune for co-managed devices. This directly satisfies the stem's requirement that Intune manage Windows Update policies across all co-managed Windows 10 devices.

Why this answer

In a co-management scenario, the workload slider determines which management authority handles specific workloads. Setting the 'Windows Update Policies' slider to 'Intune' directs Windows Update for Business policies to be applied via Intune, overriding Configuration Manager policies for co-managed Windows 10 devices. This ensures that update rings and deferral settings configured in Intune are enforced.

Exam trap

The trap here is that candidates often confuse the 'Windows Update Policies' slider with the 'Endpoint Protection' slider, mistakenly thinking update management is part of security policies, but the slider specifically governs Windows Update for Business policies, not Defender or antivirus updates.

How to eliminate wrong answers

Option A is wrong because the Endpoint Protection workload slider controls antimalware and firewall policies (e.g., Defender for Endpoint), not Windows Update policies. Option C is wrong because the Client Apps workload slider governs the deployment of applications (e.g., MSI, Win32 apps) from Intune or Configuration Manager, not update management. Option D is wrong because the Device Configuration workload slider manages settings like compliance policies and resource access (e.g., VPN, Wi-Fi), not Windows Update policies.

35
MCQmedium

You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?

A.Verify that the user is assigned an Intune license.
B.Run the 'dsregcmd /status' command to check the device registration status.
C.Check that the device has a TPM chip enabled and Secure Boot turned on.
D.Ensure the compliance policy is assigned to a group that includes the user or device.
AnswerD

A compliance policy showing 'Not evaluated' typically means no policy applies to that device or user. Verifying the policy's group assignment, ensuring the user or device is included, is the first check before investigating sync or client issues.

Why this answer

A compliance policy must be assigned to a group containing the user or device for it to be evaluated. Even if the device is enrolled and syncing, without assignment the policy will not apply, resulting in a 'Not evaluated' status in Intune.

Exam trap

The trap here is that candidates confuse 'Not evaluated' with a device health or configuration issue, when it actually points to a missing policy assignment or group membership problem.

How to eliminate wrong answers

Option A is wrong because an Intune license is required for enrollment and sync, which the user already has (device is enrolled and syncing), so licensing is not the cause of 'Not evaluated' status. Option B is wrong because 'dsregcmd /status' checks Azure AD registration and hybrid join status, not compliance policy assignment or evaluation; the device is already enrolled and syncing, indicating registration is fine. Option C is wrong because TPM and Secure Boot are prerequisites for BitLocker or device health attestation, not for compliance policy evaluation; their absence would cause specific compliance failures, not a 'Not evaluated' status.

36
MCQhard

You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?

A.The device does not have internet connectivity to download the app.
B.The device's certificate for Intune is expired.
C.The Intune management extension is not installed on the device.
D.The device requires a restart to complete previous updates.
AnswerC

Line-of-business apps deploy through the Intune management extension, which is installed by a PowerShell script agent on the device. Without that extension, the LOB app remains Pending indefinitely, even though the device is online and checking in.

Why this answer

The Intune management extension is responsible for deploying line-of-business (LOB) apps and PowerShell scripts on Windows devices. If this extension is not installed, the device will show a 'Pending' status for required app deployments because the Intune service cannot initiate the download or installation. Since the device has been online, connectivity is not the issue, and the extension must be present to process the deployment.

Exam trap

The trap here is that candidates often assume a 'Pending' status is always due to network issues or pending reboots, but Microsoft specifically tests the requirement of the Intune management extension for LOB app deployments on Windows devices.

How to eliminate wrong answers

Option A is wrong because the device has been online for the past 24 hours, indicating internet connectivity is available, and a 'Pending' status typically does not result from transient connectivity issues. Option B is wrong because an expired Intune certificate would cause the device to appear as 'Not compliant' or 'Unhealthy' in the Intune console, not a 'Pending' status for a specific app deployment. Option D is wrong because a pending restart would affect the installation of updates, not the initial download or deployment status of an LOB app, and the device would still show the app as 'Pending' only if the management extension were missing.

37
Multi-Selectmedium

Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?

Select 3 answers
A.Change the primary user
B.Change the enrolled user
C.Restart the device
D.Sync the device
E.Change the device name
AnswersA, C, D

Changing the primary user reassigns device ownership in Microsoft Intune, which is a supported remote action from the admin centre. It satisfies the stem's requirement for actions performed on a managed device without requiring physical access or re-enrolment.

Why this answer

The Microsoft Intune admin center supports several remote actions on managed devices. Changing the primary user (A), Restart (C), and Sync (D) are all valid remote actions. Options B (Change the enrolled user) and E (Change the device name) are not available remotely.

Exam trap

Candidates often assume that changing the primary user is not possible, but Intune does support this remote action. The trap is to incorrectly limit remote actions to only Restart and Sync, omitting Change primary user.

38
MCQeasy

You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?

A.Device compliance policy
B.App protection policy
C.Conditional Access policy
D.Device configuration profile
AnswerC

Conditional Access evaluates device compliance state signalled by Intune before granting access to cloud apps, so it enforces the compliant-device requirement for Exchange Online. Compliance policies alone only mark devices; Conditional Access is the gate that blocks noncompliant ones.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) evaluate signals such as device compliance status from Intune before granting access to cloud apps like Exchange Online. By integrating with Intune compliance policies, a Conditional Access policy can block or allow access based on whether the device meets compliance requirements. This is the correct mechanism to enforce access control for compliant devices.

Exam trap

The trap here is that candidates often confuse Device compliance policies (which only assess and report compliance) with Conditional Access policies (which actually enforce access decisions), leading them to select the compliance policy as the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because a Device compliance policy only marks a device as compliant or non-compliant; it does not enforce access control to Exchange Online on its own. Option B is wrong because App protection policies manage data protection within applications (e.g., preventing copy/paste) and do not evaluate device compliance or control access to Exchange Online at the device level. Option D is wrong because Device configuration profiles apply settings like Wi-Fi or VPN configurations and do not enforce conditional access based on compliance status.

39
Multi-Selecthard

An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?

Select 2 answers
A.BitLocker
B.Encrypting File System (EFS)
C.Device encryption
D.FileVault
E.APFS encryption
AnswersA, C

BitLocker is the native Windows volume-level encryption technology, configurable through Intune's disk encryption policy for Windows devices. It satisfies the stem's requirement for a valid encryption option to enforce disk encryption across managed Windows endpoints.

Why this answer

BitLocker (A) is correct because it is Microsoft's full-volume disk encryption feature for Windows and is the primary encryption method configured through Intune disk encryption policies. Device encryption (C) is also correct because it is a Windows feature (available on supported devices, often with Modern Standby and a Microsoft account) that Intune can enforce via the same disk encryption policy profile. EFS (B) is not a valid answer here because it encrypts individual files and folders on NTFS volumes rather than enforcing full disk encryption.

FileVault (D) is incorrect because it is Apple's macOS disk encryption technology, not a Windows encryption option. APFS encryption (E) is incorrect because APFS is an Apple file system and its encryption applies to macOS/iOS devices, not Windows devices managed by Intune.

Exam trap

The trap here is that candidates often confuse file-level encryption (EFS) with full-disk encryption, or mistakenly apply macOS-specific technologies (FileVault, APFS encryption) to Windows devices, forgetting that Intune policies are platform-specific.

40
MCQeasy

Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?

A.The level of update notifications
B.How long to defer feature updates
C.Whether updates are installed automatically and if the user can control reboot timing
D.The branch readiness level
AnswerC

This setting governs the Windows Update for Business behaviour: it determines whether updates install automatically and whether the signed-in user may choose when to restart, satisfying the ring's need to balance patching with user control over reboot timing.

Why this answer

The 'automaticUpdateBehavior' setting in a Windows 10 update ring configuration JSON controls whether updates are downloaded and installed automatically, and whether the user can control reboot timing. When set to 'autoInstallAndRebootWithNoUserControl', updates install automatically and reboots occur without user interaction; when set to 'autoInstallAndRebootWithUserControl', the user can schedule or postpone reboots. This directly matches option C, as it governs both automatic installation and reboot control.

Exam trap

The trap here is that candidates confuse 'automaticUpdateBehavior' with deferral periods or notification levels, because all three settings appear in the same update ring configuration JSON, but each controls a distinct aspect of Windows Update behavior.

How to eliminate wrong answers

Option A is wrong because 'automaticUpdateBehavior' does not control the level of update notifications; notification behavior is managed by the 'updateNotificationLevel' setting in the update ring policy. Option B is wrong because deferring feature updates is controlled by the 'deferFeatureUpdatesPeriodInDays' setting, not by 'automaticUpdateBehavior'. Option D is wrong because branch readiness level is set via the 'branchReadinessLevel' property (e.g., 'CurrentBranch' or 'SemiAnnualChannel'), which is independent of the automatic update behavior.

41
Multi-Selecthard

Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)

Select 3 answers
A.Configure Autopilot for the device.
B.Create a device compliance policy to enforce kiosk mode.
C.Create a device configuration profile with the kiosk settings.
D.Assign the kiosk profile to a Microsoft Entra ID group containing the target devices.
E.Ensure the device is enrolled in Microsoft Intune.
AnswersC, D, E

Kiosk settings are configured via a configuration profile.

Why this answer

A device configuration profile in Microsoft Intune is the mechanism used to define the specific kiosk settings, such as the user account, app type (e.g., single-app or multi-app kiosk), and browser configuration. This profile applies the kiosk mode configuration to the device via the Windows 10/11 kiosk policy CSP (Policy Configuration Service Provider).

Exam trap

The trap here is that candidates confuse device compliance policies with device configuration profiles, mistakenly thinking compliance policies can enforce kiosk mode, when in fact compliance policies only evaluate and report on device health and security settings.

42
MCQmedium

You manage a fleet of Windows 11 devices with Microsoft Intune. Users report that the Windows Update ring assigned to them installs quality updates but never installs the required feature update to Windows 11 version 23H2. You confirm the devices are active, check-in is successful, and the ring is assigned to the correct Microsoft Entra group. You need to ensure the feature update installs automatically without user interaction. What should you configure?

A.Configure a Windows Update for Business delivery optimization policy to enable peer-to-peer content sharing.
B.Add the devices to a Microsoft Entra dynamic device group that filters on operatingSystemVersion and assign the update ring to that group.
C.Increase the feature update deferral period in the existing Windows Update ring to zero days.
D.Create a Feature updates for Windows 10 and later policy targeting Windows 11 version 23H2 and assign it to the device group.
AnswerD

A Feature updates for Windows 10 and later policy explicitly targets a specific Windows version and is the supported Intune workload for deploying feature updates. Windows Update rings only control deferrals and deadlines for updates already offered; they do not select a target feature update version. Assigning the feature update policy to the device group ensures devices receive and install the specified Windows 11 version automatically.

Why this answer

Feature updates require a dedicated Feature updates for Windows 10 and later policy in Intune that specifies the target Windows version and is assigned to the intended devices. Windows Update rings manage quality update behavior and deferrals but do not select which feature update version a device receives. Creating and assigning the feature update policy ensures devices automatically upgrade to Windows 11 version 23H2 without user action.

Exam trap

The trap here is assuming that a Windows Update ring alone will deliver a specific Windows feature update version, when in fact feature updates require a separate Feature updates policy.

43
MCQhard

You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?

A.Configure a 'Quality update deadline' of 2 days and a 'Feature update deadline' of 60 days.
B.Use a 'Quality update deferral period' of 48 hours and a 'Feature update deferral period' of 60 days in a Windows 10 update ring.
C.Set the 'Update notification level' to '2 - Disable all notifications' and configure active hours.
D.Configure a 'Quality update deferral period' of 2 days and a 'Feature update deferral period' of 60 days.
AnswerA

Quality update deadlines enforce automatic installation once the deferral window lapses, guaranteeing critical security patches land within 48 hours regardless of user action. Feature update deadlines separately cap the 60-day delay, letting you defer upgrades while ensuring they eventually install. Both deadlines satisfy the stem's distinct timing constraints for security versus feature updates.

Why this answer

Windows Update for Business uses 'deadline' policies to enforce when updates must be installed, not deferral periods. A 'Quality update deadline' of 2 days ensures critical security updates are installed within 48 hours, while a 'Feature update deadline' of 60 days allows feature updates to be delayed up to 60 days. Deferral periods only postpone when an update is offered, not when it must be installed, making deadlines the appropriate mechanism for enforcing installation timelines.

Exam trap

The trap here is that candidates confuse deferral periods with deadlines, assuming a deferral of 2 days achieves the same result as a 2-day deadline, but deferrals only delay the offer while deadlines enforce installation timing.

How to eliminate wrong answers

Option B is wrong because deferral periods delay the offer of updates but do not enforce an installation deadline; a 48-hour deferral would only delay when the quality update is first offered, not ensure it is installed within 48 hours. Option C is wrong because notification settings and active hours control user experience and restart timing, not the deployment timeline for security or feature updates. Option D is wrong because a deferral period of 2 days for quality updates only delays the offer by 2 days, failing to guarantee installation within 48 hours; deadlines are required to enforce the installation window.

44
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Several devices are failing to check in and receive policy. You review the device list and see the devices are enrolled but show a compliance state of 'Not evaluated'. You need to force the devices to immediately check in with the Intune service from the local device. What should you do?

A.Restart the Microsoft Intune Management Extension service.
B.Run the command: deviceenroller.exe /c /z /o
C.Run the command: dsregcmd /status
D.In Settings, navigate to Accounts > Access work or school, select the work account, and click Info > Sync.
AnswerD

This action triggers an immediate MDM check-in with Intune. The device contacts the service, retrieves any pending policies, and re-evaluates compliance. It is the supported manual method to force a sync from the device side, directly addressing the 'Not evaluated' state and ensuring the device receives current configurations and compliance rules without waiting for the scheduled interval.

Why this answer

Forcing a manual sync from the device is the quickest way to make an enrolled Windows device check in with Intune. Using the Settings app under Access work or school triggers the MDM enrollment client to contact the service immediately, refreshing policies and compliance status. This resolves the 'Not evaluated' state because the device re-evaluates its configuration against assigned compliance policies and reports back.

Exam trap

The trap here is confusing the Intune Management Extension service with the MDM check-in process; the extension only handles Win32 apps and scripts, not core policy or compliance sync.

45
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?

A.Configure a device compliance policy to require corporate ownership.
B.Set enrollment restrictions to block personally owned devices.
C.Deploy an app protection policy to block personal devices.
D.Add corporate device identifiers (e.g., serial numbers) in Intune.
AnswerD

Corporate device identifiers, such as serial numbers or IMEIs, are uploaded to Intune and matched during enrolment, marking devices as corporate. This satisfies the requirement to distinguish corporate-owned Windows 10 devices so conditional access compliance policies can be scoped to them.

Why this answer

Corporate device identifiers, such as serial numbers or IMEI numbers, are the specific mechanism in Microsoft Intune used to mark a device as corporate-owned. While a conditional access policy requiring compliant devices ensures only compliant devices can access Microsoft 365, it does not distinguish between corporate and personal devices. By uploading corporate identifiers, Intune automatically sets the ownership type to 'Corporate' upon enrollment, which can then be used in conditional access policies to restrict access to only those devices.

Exam trap

The trap here is that candidates often confuse device compliance policies with ownership identification, not realizing that compliance policies evaluate security posture, not ownership, and that corporate identifiers are the dedicated Intune feature for marking devices as corporate-owned.

How to eliminate wrong answers

Option A is wrong because device compliance policies evaluate security settings (e.g., encryption, OS version) but do not include a setting to require corporate ownership; ownership type is a separate attribute managed via enrollment or device identifiers. Option B is wrong because enrollment restrictions block personally owned devices from enrolling at all, which is a pre-enrollment control, but the question asks what else must be done after configuring a conditional access policy to require compliant devices—enrollment restrictions would prevent personal devices from being enrolled, not identify corporate-owned devices among those already enrolled. Option C is wrong because app protection policies (MAM) manage data access within apps and can block personal devices from accessing corporate data, but they do not identify corporate-owned devices; they apply to both enrolled and unenrolled devices based on app-level controls, not device ownership.

46
MCQeasy

You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

A.Managed Browser app.
B.iOS/iPadOS LOB app.
C.iOS/iPadOS store app.
D.Volume Purchase Program (VPP) app.
AnswerB

iOS/iPadOS LOB app deployment handles enterprise-signed packages (.ipa) directly, satisfying the requirement to distribute a signed line-of-business app to company-owned devices. Intune pushes it via the Company Portal without App Store involvement, and the enterprise certificate is trusted through a configuration profile. Store apps and web clips cannot deploy custom enterprise-signed binaries.

Why this answer

An iOS/iPadOS LOB app deployment in Intune is specifically designed for line-of-business apps that are signed with an enterprise certificate and distributed internally. This method allows you to upload the .ipa file directly to Intune and deploy it to company-owned devices without requiring the Apple App Store or a Volume Purchase Program.

Exam trap

The trap here is that candidates often confuse LOB app deployment with VPP apps, mistakenly thinking that any app not from the public store must use VPP, but VPP is only for App Store apps, while LOB apps are for enterprise-signed .ipa files uploaded directly to Intune.

How to eliminate wrong answers

Option A is wrong because the Managed Browser app is a specific Intune policy for deploying Microsoft Edge or a managed browser configuration, not a method for deploying custom LOB apps. Option C is wrong because an iOS/iPadOS store app deployment requires the app to be publicly available in the Apple App Store, which does not apply to a custom LOB app signed with an enterprise certificate. Option D is wrong because a Volume Purchase Program (VPP) app is used for purchasing and deploying App Store apps in bulk with managed licenses, not for sideloading enterprise-signed LOB apps.

47
MCQhard

You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?

A.Noncompliant because passwordRequired is true and no password set.
B.Noncompliant because storage encryption is not enabled.
C.Noncompliant because OS version is not within range.
D.Compliant
AnswerA

The compliance policy sets passwordRequired to true, so a device lacking any password fails that rule and is marked noncompliant. Intune evaluates each configured setting; a single unmet requirement is sufficient to make the overall status noncompliant, regardless of other settings passing.

Why this answer

The device is noncompliant due to the passwordRequired policy setting being set to true while no password is configured on the device. In Microsoft Intune, compliance policies evaluate each setting independently; if a required setting like passwordRequired is not met, the device is marked noncompliant regardless of other compliant settings. The OS version 10.0.19043.1234 is within a supported range, and storage encryption is not evaluated unless explicitly required by a policy, so only the missing password triggers noncompliance.

Exam trap

The trap here is that candidates assume a device is compliant if most settings are met, but Microsoft Intune evaluates each compliance policy setting independently, and a single failure—such as missing a password—results in overall noncompliance.

How to eliminate wrong answers

Option B is wrong because storage encryption is not a default compliance requirement for Windows 10 devices; it must be explicitly configured in a compliance policy, and the question states only password requirements are noncompliant. Option C is wrong because OS version 10.0.19043.1234 corresponds to Windows 10 21H1, which is within the supported range for Intune compliance policies, and no OS version range issue is indicated. Option D is wrong because the device fails the passwordRequired setting, which is a mandatory compliance check, so it cannot be marked compliant.

48
Multi-Selectmedium

You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)

Select 2 answers
A.Run a PowerShell script that imports the Intune module and calls Get-IntuneManagedDevice to list devices by enrollment date.
B.Create a dynamic device group that includes devices based on the deviceManagement.approvisioningState property.
C.In the Intune console, review the Devices > All devices list and sort or filter by the Last check-in column.
D.Use the Intune Data Warehouse or a Graph API query on managedDevices with the lastSyncDateTime property to identify stale devices.
E.Configure a compliance policy with the 'Unable to check in' rule set to 30 days and a noncompliance action of 'Mark device noncompliant'.
AnswersC, D

The All devices list exposes a Last check-in column that can be sorted or filtered, making it the fastest way to identify devices that have not contacted Intune recently. It directly answers the requirement to find stale devices. From this view, an administrator can select a device and initiate a remote action such as wipe or retire, so it also supports the follow-up step.

Why this answer

Identifying devices that have stopped checking in requires data on the last contact time. The Intune console's All devices view exposes a Last check-in column that can be sorted or filtered, and Microsoft Graph's managedDevices entity exposes lastSyncDateTime, which can be queried directly or through the Intune Data Warehouse. Provisioning state, enrollment date filtering, and compliance marking do not surface last check-in information, so they cannot reliably identify the stale devices.

Exam trap

The trap here is confusing enrollment or provisioning properties with last check-in data; only the Last check-in column and lastSyncDateTime reflect recent device contact.

49
MCQeasy

An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?

A.Device enrollment restriction to require TPM 2.0
B.Device configuration profile to enable TPM 2.0
C.Device compliance policy with a condition for TPM 2.0, combined with a conditional access policy
D.App protection policy to require TPM 2.0
AnswerC

A device compliance policy evaluates the TPM 2.0 requirement as a device health attestation, marking non-compliant devices accordingly. Pairing it with a Microsoft Entra ID conditional access policy then enforces the grant control, blocking corporate email access from any device failing that check. This satisfies the stem's requirement that only TPM 2.0 devices reach email.

Why this answer

A device compliance policy can evaluate whether a device has TPM 2.0 (via the TPM specification version check), and when combined with a Conditional Access policy, it can block access to corporate email for non-compliant devices. This is the standard Microsoft approach for enforcing hardware-based security requirements for cloud app access.

Exam trap

The trap here is that candidates often confuse device compliance policies with enrollment restrictions, thinking that blocking enrollment is sufficient, but Conditional Access is required to enforce access control after enrollment.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll in Intune, but they do not enforce ongoing access control for corporate email after enrollment; they only block enrollment itself. Option B is wrong because a device configuration profile cannot enable TPM 2.0—TPM is a hardware component that is either present or not, and configuration profiles manage settings, not hardware capabilities. Option D is wrong because app protection policies (MAM) manage data protection within apps without requiring device-level compliance checks like TPM presence; they are designed for unmanaged or BYOD scenarios where device compliance is not evaluated.

50
MCQhard

You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Azure AD joined and enrolled in Intune. What should you configure?

A.Configure a conditional access policy that requires compliant devices.
B.Deploy a PowerShell script that triggers a factory reset when a specific file is created.
C.Enable Windows Defender Application Guard.
D.Ensure the device has an active internet connection and use the 'Wipe' action in Intune.
AnswerD

The Wipe action in Intune can be initiated remotely and will execute when the device next connects to the internet. For Azure AD joined devices, the wipe command is delivered via the Intune service. As long as the device has internet access, it will receive and execute the wipe, even if not on the corporate network.

Why this answer

Intune's Wipe action is designed for remote device wipe. When initiated, the command is queued and delivered to the device over the internet through the Intune service. The device must have an active internet connection to receive the command, but it does not need to be on the corporate network.

This makes it effective for compromised devices that are off-site.

Exam trap

The trap here is thinking that remote wipe requires the device to be on the corporate network or that other security features like WDAG or conditional access can perform a wipe, when in fact only the Wipe action does, and it works over the internet.

51
Multi-Selecthard

You manage devices with Microsoft Intune. You need to ensure that when a device is marked as non-compliant, users receive a notification and the device is blocked from accessing corporate email. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Create a Conditional Access policy that requires compliant devices for Exchange Online.
B.Set up an enrollment restriction to block non-compliant devices.
C.Configure an app protection policy for Outlook mobile.
D.Deploy a device configuration profile that disables email access.
E.Configure a compliance policy with actions for non-compliance to send email notifications to users.
AnswersA, E

Conditional Access policies can enforce compliance by requiring devices to be marked compliant before accessing Exchange Online. When a device is non-compliant, access is blocked. This meets the requirement to block access to corporate email. Conditional Access works with Intune compliance status to allow or deny access based on device state.

Why this answer

To notify users and block email access for non-compliant devices, you need a compliance policy with actions for non-compliance to send notifications, and a Conditional Access policy that requires compliant devices for Exchange Online. The compliance policy detects non-compliance and triggers notifications, while Conditional Access enforces the block. Together, they meet both requirements.

Exam trap

The trap here is assuming that app protection policies or device configuration profiles can block email access based on compliance; only Conditional Access can enforce such dynamic access control.

52
MCQhard

You are an Intune administrator for a large enterprise that uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) for threat protection. You need to ensure that all Windows 10 devices are properly onboarded to Defender for Endpoint and that security settings are enforced via Intune. You have created a device configuration profile that includes the 'Microsoft Defender for Endpoint' settings, but some devices are not appearing in the Defender for Endpoint portal. You verify that the devices are Intune managed and enrolled. What should you do to ensure proper onboarding?

A.Ensure that the devices are co-managed with Configuration Manager.
B.Deploy the Microsoft Defender for Endpoint onboarding package (WindowsDefenderATPOnboardingPackage.zip) via Intune using a PowerShell script or a device configuration profile.
C.Create a compliance policy that requires Defender for Endpoint to be active.
D.Register the devices in Microsoft Entra ID (Azure AD) as hybrid joined.
AnswerB

The onboarding package must be deployed via Intune to onboard devices to Defender for Endpoint.

Why this answer

Onboarding to Defender for Endpoint requires a specific deployment package (a .zip file containing the onboarding script) that must be deployed via Intune using a PowerShell script or a device configuration profile with the 'Microsoft Defender for Endpoint' template. However, the most common missing step is deploying the onboarding package. Option A is incorrect because co-management with Configuration Manager is not required for Defender for Endpoint onboarding; devices can be managed solely by Intune.

Option C is incorrect because while a compliance policy can verify that Defender for Endpoint is active, it does not deploy the onboarding package required for initial onboarding. Option D is incorrect because Microsoft Entra ID registration is not the issue.

53
MCQmedium

You manage a fleet of Windows 11 devices with Microsoft Intune. The security team requires that any device that has not checked in with Intune for more than 30 days is automatically retired so its resources are released and its compliance state is removed. You need to configure this behavior with the least administrative effort. What should you do?

A.Configure an Autopilot deployment profile with a 30-day enrollment timeout and enable automatic device deletion.
B.Create a dynamic device group based on the last check-in date and apply a retire action using a scheduled PowerShell script.
C.Create a device cleanup rule in the Intune tenant settings and set the inactivity threshold to 30 days.
D.Assign a compliance policy that marks devices as noncompliant after 30 days of inactivity, and configure conditional access to block them.
AnswerC

Intune includes a built-in device cleanup rule under Tenant administration > Device cleanup rules. Setting the inactivity threshold to 30 days causes Intune to automatically retire devices that have not checked in for that period, which releases licenses and marks the device noncompliant, matching the requirement with minimal effort.

Why this answer

Intune's built-in device cleanup rule is designed exactly for this scenario: it automatically retires devices that have not checked in for a configured number of days. Setting the threshold to 30 days satisfies the security team's requirement without custom scripting, dynamic groups, or conditional access workarounds. It is the native, lowest-effort lifecycle management feature.

Exam trap

The trap here is assuming that compliance policies or conditional access can retire devices, when only the dedicated device cleanup rule performs the retire action automatically.

54
MCQmedium

You are deploying a Windows 11 device using Windows Autopilot. The device fails to enroll in Intune and you see the error 'The device is not registered in Autopilot'. You have verified that the device hardware hash is uploaded. What is the most likely cause?

A.The device is not running a supported version of Windows 11.
B.The device is not connected to the internet during OOBE.
C.The device hardware hash is associated with a different tenant.
D.The Autopilot deployment profile is not assigned to the device.
AnswerC

If the hardware hash was uploaded to a different Microsoft Entra tenant, the device will not be recognized in your tenant's Autopilot service, resulting in the 'not registered' error. This can happen if the device was previously registered elsewhere or if the hash was uploaded incorrectly. Ensuring the hash is in the correct tenant resolves the issue.

Why this answer

The error 'The device is not registered in Autopilot' indicates that the device's hardware hash is not present in the Autopilot service for your tenant. A common cause is that the hash was uploaded to a different Microsoft Entra tenant, perhaps by the OEM or a previous owner. Verifying and re-uploading the hash to the correct tenant resolves the issue.

Other causes like internet connectivity or profile assignment do not produce this specific error.

Exam trap

The trap here is assuming that profile assignment or internet connectivity causes the 'not registered' error, when it specifically means the hardware hash is missing from the tenant.

55
MCQhard

You are the endpoint administrator for Contoso, a company with 10,000 Windows 11 devices managed by Microsoft Intune. The devices are a mix of corporate-owned and bring-your-own-device (BYOD). You need to implement a solution that allows users to access corporate resources only if their devices meet specific security requirements: disk encryption (BitLocker), antivirus (Microsoft Defender), and a minimum OS build. Additionally, you must ensure that users cannot access corporate email from devices that are jailbroken or rooted. The solution should automatically block non-compliant devices from accessing resources and provide a notification to the user explaining the issue. You have already configured compliance policies in Intune. What should you do next to enforce the block?

A.Configure a device enrollment restriction to block non-compliant devices from Azure AD join.
B.Create a device configuration policy that blocks access to corporate resources.
C.Create an app protection policy in Intune to block access to apps.
D.Create a Conditional Access policy in Microsoft Entra ID that requires compliant device for access.
AnswerD

A Conditional Access policy in Microsoft Entra ID evaluates device compliance state at authentication and blocks access when the device fails Intune compliance policies, covering BitLocker, Defender, OS build, and jailbroken or rooted detection. This enforces the block automatically and surfaces the non-compliance reason to users.

Why this answer

Conditional Access policies in Microsoft Entra ID (formerly Azure AD) enforce compliance by requiring devices to be marked compliant before granting access to corporate resources. Since compliance policies are already configured in Intune, creating a Conditional Access policy that requires a compliant device will block non-compliant devices and provide user notifications.

Exam trap

The trap is confusing device configuration policies with Conditional Access; candidates must remember that Conditional Access is the enforcement mechanism for compliance, not configuration policies.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll, not access to resources for already enrolled devices. Option B is wrong because device configuration policies configure settings on devices but do not block access. Option C is wrong because app protection policies protect app data but do not enforce device compliance for access to all corporate resources.

56
MCQmedium

You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?

A.Deploy a device configuration profile with the 'Allow copy and paste' setting set to 'Blocked'.
B.Create an app protection policy with the 'Restrict cut, copy, and paste between other apps' setting set to 'Blocked'.
C.Set the 'Require managed pasteboard' option in the app configuration policy for Outlook.
D.Configure a conditional access policy that requires compliant devices.
AnswerB

App protection policies (also known as MAM policies) can restrict data transfer between managed and unmanaged apps. Setting 'Restrict cut, copy, and paste between other apps' to 'Blocked' prevents copying from a managed app to any unmanaged app, including personal apps like Gmail. This is enforced without user interaction and meets the requirement.

Why this answer

App protection policies in Intune provide granular control over data sharing between apps. The setting to restrict cut, copy, and paste between other apps, when set to Blocked, prevents data from being copied from a managed app to any unmanaged app. This is enforced at the app level and does not require user action.

Exam trap

The trap here is assuming that device configuration profiles can control inter-app data sharing, but that capability is exclusive to app protection policies.

57
MCQmedium

A user's Android device is not receiving email from the corporate Microsoft 365 tenant. The device is enrolled in Intune and shows as compliant. The email profile is assigned to the user. What should you check first?

A.Verify that the device meets the compliance policy for Android.
B.Confirm that the user has an Exchange Online license.
C.Check the device's last check-in time with Intune.
D.Ensure the device is enrolled in Intune.
AnswerC

A stale Intune check-in means the device never collected the assigned email profile, so no mailbox connection is configured despite the compliance state. Verifying the last check-in time confirms whether policy and profile delivery actually reached the Android device, which is the prerequisite for email synchronisation in this scenario.

Why this answer

The device is already compliant and enrolled, and the email profile is assigned, so the most likely issue is that the device has not recently checked in with Intune to receive the latest policy or profile. Checking the last check-in time is the first troubleshooting step because Intune relies on periodic device check-ins to push configuration profiles, including email profiles. If the device hasn't checked in recently, it won't have the email profile applied, even if it's compliant and enrolled.

Exam trap

The trap here is that candidates assume compliance or enrollment guarantees policy delivery, but Intune requires a successful device check-in to actually apply profiles, making the last check-in time the critical first check.

How to eliminate wrong answers

Option A is wrong because the device already shows as compliant, so verifying compliance again would be redundant and not address why the email profile hasn't been applied. Option B is wrong because the user's ability to receive email from the corporate tenant is not dependent on an Exchange Online license; the email profile configuration and Intune policy delivery are the immediate technical blockers. Option D is wrong because the device is already enrolled in Intune (as stated in the scenario), so re-checking enrollment is unnecessary and does not explain why the email profile hasn't been delivered.

58
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, all corporate data is removed but the user's personal files remain intact. The devices are enrolled as personal devices with work profiles. What should you do?

A.Use the 'Wipe' action in Intune.
B.Use the 'Retire' action in Intune.
C.Remove the device from the Azure AD group.
D.Perform a factory reset on the device.
AnswerB

The Retire action removes corporate data, management profiles, and policies from the device while leaving personal files and settings intact. For personal devices with work profiles, retiring the device removes the work profile and associated corporate data, which meets the requirement without affecting personal content.

Why this answer

For personal devices enrolled with work profiles, the Retire action is designed to remove only corporate data and management profiles, leaving personal files untouched. This is the correct way to deprovision a personal device without affecting the user's personal data. A factory reset or Wipe would delete everything, which is not desired.

Exam trap

The trap here is confusing the Wipe and Retire actions, or thinking that removing group membership removes data, when in fact Retire is specifically for removing corporate data while preserving personal files.

59
MCQhard

You manage macOS devices enrolled in Microsoft Intune using the Intune Company Portal app. Users report that the Company Portal app does not detect newly assigned required apps and shows an outdated compliance status. You need to ensure the Company Portal refreshes device state on demand. What should you do?

A.From the Intune admin center, select the device and choose Sync to push a check-in to the macOS device
B.Delete the device record in Intune and have the user re-enroll the macOS device to refresh state
C.Instruct users to open Company Portal, select Devices, choose the device, and select Check status to force a sync
D.Instruct users to sign out of and back into the Company Portal app to refresh the device state
AnswerC

The Check status action in the macOS Company Portal app triggers a device check-in with Intune, refreshing compliance state and app assignments. This is the supported self-service method for macOS users to force a sync without waiting for the scheduled interval. It directly addresses the scenario where the Company Portal shows stale information and required apps are not yet detected.

Why this answer

The macOS Company Portal app includes a Check status option that forces the device to check in with Intune, refreshing compliance and app assignment data. This is the correct self-service method for users to resolve stale Company Portal information without administrator intervention. Other actions such as re-authentication, admin-initiated sync, or re-enrollment either do not trigger a check-in or are unnecessarily disruptive.

Exam trap

The trap here is assuming that signing out and back into Company Portal refreshes device state, when only the Check status action triggers an actual device check-in.

60
MCQeasy

You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. You need to ensure that devices receive quality updates with a maximum deferral of 7 days. What should you configure?

A.Device compliance policy with a setting for update deferral.
B.Windows Update rings in Intune.
C.Endpoint security policy for Windows Update.
D.Windows Update for Business configuration in Group Policy.
AnswerB

Windows Update rings in Intune allow you to configure deferral periods for quality updates, feature updates, and driver updates. By setting the quality update deferral period to 7 days, you ensure that devices receive quality updates after a 7-day delay. This is the correct method to control update deferrals for Windows devices managed by Intune.

Why this answer

Windows Update rings in Intune are specifically designed to manage update deferrals for quality and feature updates. By configuring a quality update deferral of 7 days, you ensure devices receive updates after that period. Other options either do not support deferral settings or are not the correct tool for Intune-managed devices.

Exam trap

The trap here is confusing compliance policies or endpoint security policies with update rings, which are the only Intune feature that directly controls update deferrals.

61
MCQeasy

Your company uses Microsoft Intune to manage Windows 11 devices. An administrator needs to remotely restart a specific device that is currently online to apply pending updates. Which action should the administrator use in the Intune admin center?

A.Wipe
B.Fresh Start
C.Retire
D.Restart
AnswerD

The Restart device action in Intune sends a remote reboot command to the managed device. It is the correct, least-destructive action to apply pending updates that require a restart, and it works on Windows devices that are online and checking in with the service.

Why this answer

The Restart action is designed specifically to remotely reboot a managed device so that pending updates requiring a restart can complete. Retire, Wipe, and Fresh Start are all destructive or unenrollment actions that remove data or management and are not appropriate when the goal is simply to reboot an online device.

Exam trap

The trap here is confusing destructive device actions such as Wipe or Fresh Start with the simple remote reboot action.

62
MCQmedium

You manage Windows 10 devices with Intune. You need to collect diagnostic logs from a remote device that is experiencing application crashes. Which Intune feature should you use?

A.Collect diagnostics
B.Company Portal app
C.Autopilot Reset
D.Windows Update for Business
AnswerA

Collect diagnostics remotely gathers Windows diagnostic logs, including event traces and app crash data, from the device without user interaction. This satisfies the requirement to collect logs from a remote device experiencing application crashes, unlike Remote Help or device restart actions.

Why this answer

The 'Collect diagnostics' feature in Intune allows you to remotely gather diagnostic logs from Windows 10 devices without user interaction. This is the correct tool for troubleshooting application crashes because it collects system logs, event logs, and crash dumps directly from the device via the Intune management channel, enabling analysis of the failure.

Exam trap

The trap here is that candidates may confuse 'Collect diagnostics' with the Company Portal's ability to view device status or sync policies, but the Company Portal cannot initiate log collection; only the Intune admin console's 'Collect diagnostics' action can remotely gather crash logs.

How to eliminate wrong answers

Option B is wrong because the Company Portal app is a self-service portal for users to install applications, access corporate resources, and enroll devices, not a tool for collecting diagnostic logs. Option C is wrong because Autopilot Reset is used to reset a device to a business-ready state, removing user data and apps, which would destroy the crash logs needed for diagnosis. Option D is wrong because Windows Update for Business manages update policies and deployment rings, not diagnostic log collection; it focuses on keeping devices patched, not troubleshooting application crashes.

63
MCQmedium

Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?

A.The compliance policy has been removed from these devices.
B.The devices are still within the grace period and can access resources.
C.The devices were recently remediated and are now compliant.
D.The devices have exceeded the grace period and should be blocked from accessing resources.
AnswerD

A past complianceGracePeriodExpirationDateTime means the grace period has already elapsed, so Microsoft Entra ID conditional access policies enforcing compliance will block those devices from accessing resources. This satisfies the stem's constraint: the timestamp predates the current date, confirming the grace window closed without remediation.

Why this answer

The complianceGracePeriodExpirationDateTime represents the deadline by which a device must become compliant after initially being marked noncompliant. When this timestamp is in the past, it means the grace period has expired, and the device should be blocked from accessing corporate resources as per the conditional access policy. This is a standard behavior in Microsoft Intune for managing noncompliant devices.

Exam trap

The trap here is that candidates confuse the complianceGracePeriodExpirationDateTime with the last check-in time or assume a past timestamp means the device is still compliant, when in fact it signals the end of the grace period and triggers blocking actions.

How to eliminate wrong answers

Option A is wrong because removing the compliance policy from a device does not affect the grace period timestamp; the timestamp is set when the device is marked noncompliant and persists regardless of policy removal. Option B is wrong because a past grace period expiration indicates the grace period has ended, not that the device is still within it; devices within the grace period would have a future timestamp. Option C is wrong because remediated devices would have a new compliance status and a reset complianceGracePeriodExpirationDateTime, not a past one; a past timestamp indicates the grace period was not resolved in time.

64
MCQmedium

You deployed this endpoint protection policy to a Windows 10 device. A user reports that a known malicious file was downloaded but not blocked. What is the most likely reason?

A.Real-time scanning is set to monitorAllFiles, but the file was an archive.
B.The scan type is set to quick, which does not scan downloaded files.
C.The cloud block level is set to high, which may block unknown files, but known files might be missed.
D.The policy has not been applied to the device yet.
AnswerD

Endpoint protection settings reach a device only after it checks in and applies the configuration. If the policy has not yet been delivered, the malicious file download proceeds unchecked, since no scanning or blocking rules are active locally.

Why this answer

If the endpoint protection policy has not been applied to the device, the Microsoft Defender for Endpoint settings (including real-time scanning and cloud-delivered protection) are not active. The policy must be successfully delivered via Microsoft Intune or Configuration Manager before any protection rules take effect. Without policy application, the device runs with default or no protection, allowing known malicious files to be downloaded without being blocked.

Exam trap

The trap here is that candidates assume a protection policy is automatically active once created, but Microsoft Intune policies require device check-in and successful application before they take effect, and the cloud block level setting is often misunderstood as affecting known malware detection.

How to eliminate wrong answers

Option A is wrong because real-time scanning set to monitorAllFiles includes archives; Microsoft Defender scans archive files (e.g., .zip, .rar) by default when monitorAllFiles is enabled, so an archive would still be scanned. Option B is wrong because the scan type (quick, full, or custom) applies to scheduled or on-demand scans, not to real-time protection; real-time scanning always inspects files as they are downloaded or accessed, regardless of the scan type setting. Option C is wrong because the cloud block level setting (high, moderate, etc.) affects how aggressively unknown files are sent to the cloud for analysis, but known malicious files are blocked locally by signature-based detection and do not rely on cloud block level; a known file would be blocked even with a high cloud block level.

65
MCQeasy

You need to retire a device in Microsoft Intune. What is the effect of retiring a device?

A.The device is unenrolled, and corporate data and apps are removed. Personal data is preserved.
B.The device is factory reset to its original settings.
C.The device remains enrolled but can no longer access corporate resources.
D.The device is deleted from Azure AD and Intune.
AnswerA

Retire sends an unenrolment command that removes the management profile and corporate data such as managed apps, email profiles and policies, while leaving personal files and settings intact. This matches the stem's requirement to remove only organisational content.

Why this answer

Retiring a device in Microsoft Intune performs a selective wipe that removes only corporate-managed data and apps while preserving the user's personal data. The device is also unenrolled from Intune management, meaning it no longer receives policy or compliance enforcement. This is distinct from a full wipe, which resets the entire device to factory settings.

Exam trap

The trap here is that candidates often confuse 'retire' with 'wipe' (factory reset), assuming both remove all data, but Intune's selective wipe is designed specifically to preserve personal data while removing corporate resources.

How to eliminate wrong answers

Option B is wrong because it describes a factory reset (full wipe), which removes all data including personal content, whereas retirement only removes corporate data. Option C is wrong because a retired device is unenrolled and loses all access to corporate resources, not remaining enrolled with restricted access. Option D is wrong because while the device record is removed from Intune, it is not automatically deleted from Azure AD; the device object in Azure AD remains until explicitly removed or until the user's sync cycle cleans it up.

66
MCQeasy

A user's device is marked as 'Noncompliant' in Microsoft Intune due to missing required updates. The device is configured with a compliance policy that requires a minimum OS version. The user claims the device is up-to-date. What should you verify first?

A.The current OS version on the device.
B.The user's license status.
C.The compliance policy is assigned to the device.
D.The device is connected to the internet.
AnswerA

The compliance policy enforces a minimum OS version, so the reported build must be compared against that threshold. Verifying the actual OS version first confirms whether the device genuinely meets the minimum or the policy is misjudged.

Why this answer

The first step in troubleshooting a noncompliant device due to a missing minimum OS version is to verify the actual OS version currently installed on the device. The user's claim that the device is up-to-date may be based on a misunderstanding of what version is required, or the device may have pending updates that have not been applied. Intune compliance policies evaluate the OS version reported by the device during check-in, so confirming the exact build number against the policy requirement is the logical starting point.

Exam trap

The trap here is that candidates may jump to verifying policy assignment or connectivity, overlooking that the most direct and immediate verification is the actual OS version on the device, which is the specific attribute being evaluated by the compliance policy.

How to eliminate wrong answers

Option B is wrong because license status affects enrollment and access to Intune features, but it does not directly cause a device to be marked noncompliant due to a missing OS version; a licensed user can still have a noncompliant device. Option C is wrong because if the compliance policy were not assigned to the device, the device would not be evaluated against that policy and would not be marked noncompliant for that reason; the fact that it is marked noncompliant indicates the policy is assigned. Option D is wrong because while internet connectivity is required for the device to check in with Intune and report compliance, the device is already reporting its noncompliant status, meaning it has communicated with the service; connectivity is not the root cause of the OS version mismatch.

67
MCQmedium

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, the primary user's corporate data is removed but the device remains enrolled and managed. Which action should you take in the Intune admin center?

A.Wipe the device.
B.Use Selective wipe.
C.Retire the device.
D.Reset the device.
AnswerB

Selective wipe (also known as selective wipe for MDM) removes corporate data and settings from the device while leaving personal data intact. Crucially, it keeps the device enrolled in Intune, allowing continued management. This matches the requirement to remove corporate data but keep the device managed.

Why this answer

Selective wipe is the action that removes corporate data from a device while preserving personal data and keeping the device enrolled in Intune. Wipe and reset remove all data and unenroll the device, while retire removes corporate data but also unenrolls the device. Only selective wipe satisfies both conditions of removing corporate data and maintaining enrollment.

Exam trap

The trap here is confusing retire with selective wipe; retire removes corporate data but also unenrolls the device, whereas selective wipe keeps the device managed.

68
MCQmedium

You manage devices with Microsoft Intune. Users report that after a recent policy change, some devices are not receiving updated policies. You verify that the devices are online and have connectivity. What should you do to force a policy refresh?

A.Ask users to restart their devices.
B.Ask users to run Windows Update.
C.Adjust the MDM sync interval in Intune.
D.In the Intune portal, select the devices and click 'Sync'.
AnswerD

Selecting 'Sync' in the Intune portal triggers a remote device action that queues a check-in, prompting the device to contact the Intune service and pull updated policies immediately. This satisfies the stem's requirement to force a refresh on online devices without waiting for the scheduled check-in interval.

Why this answer

The Intune 'Sync' action sends a direct MDM policy refresh command to the device via the Microsoft Intune service. This triggers the device's enrollment client to immediately check in with the MDM server, download the latest policies, and apply them without waiting for the next scheduled sync interval. Since the devices are online and have connectivity, this remote sync forces an immediate policy refresh.

Exam trap

The trap here is that candidates often confuse a device restart or Windows Update with triggering an MDM policy refresh, but Intune's MDM sync is a distinct, remote action that must be initiated from the Intune portal or via a manual sync on the device itself.

How to eliminate wrong answers

Option A is wrong because restarting the device does not force an MDM policy sync; it only reboots the OS, and the device will still wait for its next scheduled sync interval (typically every 8 hours) unless a sync is triggered via Intune. Option B is wrong because running Windows Update checks for OS and driver updates, not MDM policy changes; policy updates are handled by the MDM client, not Windows Update. Option C is wrong because adjusting the MDM sync interval in Intune only changes the default check-in frequency for future syncs; it does not force an immediate refresh for devices that have already missed a policy update.

69
MCQmedium

You are responsible for managing Windows 10 devices with Microsoft Intune. You need to deploy a new line-of-business (LOB) app to a group of devices. The app requires a script to run after installation to configure settings. What should you use to deploy the app and ensure the script runs?

A.Add the app as a Win32 app and include the script in the install command.
B.Add the app as a Win32 app and include the script as a detection rule.
C.Add the app as a Microsoft Store app and use a PowerShell script to configure settings.
D.Add the app as a Win32 app and include the script as a requirement rule.
AnswerA

For Win32 apps in Intune, you can specify an install command that runs the installer. You can chain a configuration script by using a command line that executes the installer and then the script, for example: `setup.exe /silent && powershell.exe -File config.ps1`. This ensures the script runs after installation completes, fulfilling the requirement.

Why this answer

Win32 apps in Intune support custom install commands, allowing you to run additional scripts after the main installer. By appending the script execution to the install command, you ensure it runs immediately after installation. This is a common method for configuring LOB apps that require post-installation steps.

Other options like requirement or detection rules are not designed for executing configuration scripts.

Exam trap

The trap here is confusing detection rules with post-installation scripts; detection rules only check for app presence, not run configuration logic.

70
MCQmedium

Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?

A.The devices are not enrolled in Microsoft Intune.
B.The Microsoft Defender for Endpoint sensor is not installed or configured correctly.
C.The devices are not compliant with conditional access policies.
D.The devices have lost connectivity to the internet.
AnswerB

A missing or misconfigured Microsoft Defender for Endpoint sensor directly prevents telemetry from reaching the service, which is why devices appear inactive. Onboarding requires the sensor to be installed and running, with correct configuration, so any gap in that chain halts health reporting regardless of network or licensing state.

Why this answer

The Microsoft Defender for Endpoint sensor is the core component that collects and reports security telemetry from Windows 10 devices to the Defender for Endpoint cloud service. If the sensor is not installed, is missing, or is misconfigured (e.g., due to a corrupted installation or incorrect onboarding script), the device will appear as inactive in the Microsoft 365 Defender portal, even if the device is otherwise healthy and connected.

Exam trap

The trap here is that candidates often confuse device enrollment (Intune) with sensor onboarding, assuming that a device must be managed by Intune to report to Defender for Endpoint, when in fact any Windows 10 device can be onboarded via a simple script or GPO.

How to eliminate wrong answers

Option A is wrong because enrollment in Microsoft Intune is not a prerequisite for Defender for Endpoint reporting; devices can be onboarded via Group Policy, local script, or other methods without Intune. Option C is wrong because conditional access compliance policies control access to cloud apps, not the reporting of security health to Defender for Endpoint; a non-compliant device can still report telemetry. Option D is wrong because while internet connectivity is required for the sensor to communicate with the cloud, the question states some devices are inactive, not all; if connectivity were the issue, all devices would likely be affected, and the sensor would still attempt to report (showing as 'misconfigured' rather than 'inactive').

71
MCQeasy

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that devices automatically receive quality updates and feature updates according to a schedule you define, with the ability to pause updates. What should you configure?

A.Compliance policies for Windows 10 devices.
B.Endpoint security policies for update management.
C.Device configuration profiles for Windows Update for Business.
D.Windows Update rings in Intune.
AnswerD

Windows Update rings in Intune allow you to configure update settings such as deferral periods, active hours, and pause options for quality and feature updates. They are designed to schedule and control updates on Windows devices. This is the correct choice to meet the requirement of scheduled updates with pause capability.

Why this answer

Windows Update rings in Intune are specifically designed to manage and schedule Windows updates, including quality and feature updates. They provide settings for deferral, deadlines, active hours, and the ability to pause updates. This directly addresses the requirement to schedule updates and allow pausing.

Other options do not offer the same level of update control.

Exam trap

The trap here is assuming that compliance policies or configuration profiles can schedule updates, when update rings are the dedicated feature for this purpose.

72
Multi-Selecthard

Your organization is implementing a zero-trust security model using Microsoft Intune. Devices must be compliant before accessing corporate resources. You need to deploy compliance policies for Windows 10 devices that require BitLocker encryption and a minimum OS version. Which two policy settings should you configure? (Choose two.)

Select 2 answers
A.Minimum OS version.
B.Require device health attestation.
C.Require firewall (Windows Defender Firewall).
D.Require encryption of data storage on device.
E.Maximum OS version.
AnswersA, D

Minimum OS version directly satisfies the stem's requirement for a baseline OS build on Windows 10 devices. Compliance policies evaluate this attribute through Intune's device compliance engine, marking devices non-compliant when their reported build falls below the configured threshold, which Conditional Access then enforces alongside BitLocker encryption.

Why this answer

The 'Minimum OS version' setting in a Windows 10 compliance policy ensures that devices must be running at least a specified build number (e.g., 10.0.19041 for Windows 10 20H1). This directly enforces the zero-trust requirement that only devices with a supported, up-to-date OS can access corporate resources, reducing exposure to known vulnerabilities. Option D is correct because the 'Require encryption of data storage on device' setting mandates BitLocker encryption on the system drive, which is a core data protection control in a zero-trust model.

Exam trap

The trap here is that candidates often confuse 'Require encryption of data storage on device' with 'Require device health attestation,' mistakenly thinking health attestation covers encryption, when in fact health attestation focuses on boot integrity and does not enforce BitLocker status.

73
MCQmedium

You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?

A.Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant'. Then, in the compliance policy, set the 'Action for noncompliance' to 'Mark device noncompliant' after 30 minutes.
B.Create a Conditional Access policy that requires compliant devices, and set the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute session lifetime.
C.Create a Conditional Access policy that requires compliant devices, and configure the 'Grant' control to 'Require device to be marked as compliant' with a 30-minute grace period.
D.In the compliance policy, set 'Mark device noncompliant' to 30 minutes and assign the policy to all users.
AnswerA

This approach correctly uses Conditional Access to block noncompliant devices and leverages the compliance policy's noncompliance action schedule to delay marking the device noncompliant for 30 minutes. During that window, the device is still considered compliant, so access is allowed. After 30 minutes, the device is marked noncompliant and Conditional Access blocks access.

Why this answer

To allow a grace period before blocking access, you must delay the device being marked noncompliant. Conditional Access itself does not provide a grace period. By configuring the compliance policy to mark the device noncompliant after 30 minutes, the device remains compliant during that time, and Conditional Access continues to allow access.

After the delay, the device becomes noncompliant and access is blocked.

Exam trap

The trap here is assuming that Conditional Access has a built-in grace period setting when it only enforces compliance status as evaluated by Intune.

74
Multi-Selectmedium

You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy to require that devices have a specific minimum OS version and that BitLocker is enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require antivirus
B.Minimum OS version
C.Require Secure Boot
D.Require code integrity
E.Require BitLocker
AnswersB, E

The Minimum OS version setting allows you to specify the oldest Windows build that is considered compliant. Devices running an older build are marked noncompliant. This enforces the requirement for a specific minimum OS version. You can enter a version like 10.0.22000.1000 for Windows 11. This setting is found under Device Properties in the compliance policy.

Why this answer

To enforce a minimum OS version and BitLocker, you configure the Minimum OS version setting and the Require BitLocker setting in the Windows compliance policy. These settings directly map to the requirements. Secure Boot, code integrity, and antivirus are separate security controls that do not address the specific needs of the scenario.

Exam trap

The trap here is adding extra security settings that seem related to device health but are not the specific requirements for minimum OS version and BitLocker.

75
MCQeasy

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?

A.Fresh Start the device
B.Reset the device
C.Retire the device
D.Wipe the device
AnswerD

The wipe action in Microsoft Intune performs a factory reset on the device, removing all data including corporate and personal information, and it can be initiated remotely. For lost or stolen devices, this ensures that no data remains accessible. It also supports a option to retain enrollment state and user account for Autopilot, but in a lost scenario, a full wipe is appropriate to protect corporate data.

Why this answer

The wipe action remotely resets the device to factory settings, removing all data and preventing access. This is the correct choice for lost or stolen devices because it ensures corporate data is not accessible. Retire, reset, and Fresh Start do not provide the same immediate data protection and remote wipe capability for lost devices.

Exam trap

The trap here is confusing retire with wipe; retire only removes corporate data but leaves personal data and does not prevent device access.

Page 1 of 3 · 183 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage and maintain devices questions.