Courseiva

CCNA Manage and maintain devices Questions

75 of 183 questions · Page 2/3 · Manage and maintain devices · Answers revealed

76
MCQhard

You are deploying Windows 11 devices using Windows Autopilot. Some devices are not registering in Microsoft Intune. You have verified that the hardware hashes are uploaded correctly. What is the most likely cause?

A.The devices are not connected to the internet.
B.The hardware hashes are invalid.
C.The devices are not running Windows 11 Pro or Enterprise.
D.The user does not have an Intune license.
AnswerA

Without network connectivity during the out-of-box experience, the Autopilot profile cannot contact the Microsoft Intune enrolment service, so the device never registers even though its hardware hash exists. Autopilot enrolment depends entirely on cloud communication; offline devices simply skip the enrolment phase and fall through to the local setup screens.

Why this answer

Windows Autopilot requires internet connectivity during the out-of-box experience (OOBE) to contact the Autopilot deployment service and Microsoft Intune. Without internet access, the device cannot download the Autopilot profile or register in Intune, even if hardware hashes are correctly uploaded. The hardware hash upload is a separate step that does not guarantee the device can later connect to the service.

Exam trap

The trap here is that candidates often assume hardware hash upload is the only prerequisite for Autopilot registration, overlooking the critical requirement for internet connectivity during the device's initial boot process.

How to eliminate wrong answers

Option B is wrong because the question explicitly states that the hardware hashes are uploaded correctly, so invalid hashes are not the issue. Option C is wrong because Windows Autopilot supports Windows 11 Pro, Enterprise, and Education editions; the device not registering is not caused by running an unsupported edition. Option D is wrong because the user license is not required for device registration via Autopilot; device enrollment occurs before user sign-in, and Intune licenses are only needed for user-based management after enrollment.

77
MCQhard

Refer to the exhibit. You have configured the compliance policy shown above. A user reports that their Windows 11 device is compliant with all settings except the threat level. The device has no threat protection agent installed. What will happen when the user tries to access corporate resources?

A.Access is granted but the user receives a warning notification.
B.Access is blocked only after a 24-hour grace period.
C.Access is blocked immediately.
D.Access is granted because the device meets all other compliance requirements.
AnswerC

Without a threat protection agent, Microsoft Entra ID cannot evaluate the threat level, so the device fails the compliance policy and is marked non-compliant. Conditional Access then blocks access to corporate resources immediately, satisfying the stem's requirement that the device lacks any agent capable of reporting threat state.

Why this answer

The compliance policy requires a minimum threat level, which cannot be evaluated because the device has no threat protection agent installed. In Microsoft Intune, when a required compliance setting cannot be assessed (e.g., no agent), the device is treated as non-compliant, and access is blocked immediately. There is no grace period for missing required agents, and conditional access enforces the block at the time of the access request.

Exam trap

The trap here is that candidates assume a grace period applies to all non-compliance scenarios, but grace periods are only applicable to specific settings (like password expiration) and not to missing required agents or unassessable settings.

How to eliminate wrong answers

Option A is wrong because access is not granted with a warning; Intune conditional access blocks non-compliant devices immediately, and a warning notification is only sent if the device is compliant but has a warning-level issue. Option B is wrong because a 24-hour grace period applies only to specific non-compliance actions (e.g., password expiration) when configured in a compliance policy, not to missing required agents like a threat protection agent. Option D is wrong because meeting all other compliance requirements does not override the specific threat level requirement; the device is non-compliant overall, and access is blocked.

78
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, the user receives a notification email, and the device is automatically retired after 30 days. The solution must minimize administrative effort. What should you configure?

A.A compliance policy with actions for non-compliance: send email to user at 0 days, and retire device at 30 days.
B.A Windows Update ring with a deadline of 30 days and an automatic retirement action.
C.A device configuration profile with a custom OMA-URI to send email and retire the device after 30 days.
D.An Intune device cleanup rule that retires devices after 30 days of inactivity and sends an email.
AnswerA

Compliance policies allow you to configure actions for non-compliance, including sending an email and retiring the device. You can set the email action to trigger immediately when the device becomes noncompliant, and schedule the retire action for 30 days later. This meets the requirement with minimal effort, as it is a single policy configuration.

Why this answer

Compliance policies are the correct tool to automate actions based on noncompliance. You can configure an action to send an email to the user immediately when the device becomes noncompliant, and another action to retire the device after 30 days. This requires only one policy and minimal administrative effort.

Exam trap

The trap here is thinking that update rings or cleanup rules can enforce compliance actions, when only compliance policies have actions for non-compliance.

79
MCQhard

You use Microsoft Intune to manage Windows 11 devices. You configure a Windows Update ring policy to defer quality updates by 7 days and feature updates by 60 days. A critical security update is released that must be installed immediately on all devices, bypassing the deferral. What should you configure?

A.Deploy a PowerShell script that runs the Windows Update client to install all available updates.
B.Create a new Windows Update ring policy with a deadline of 0 days and assign it to all devices.
C.Use expedited updates in Microsoft Intune to deploy the specific security update to all devices.
D.Modify the existing Windows Update ring policy to set the quality update deferral to 0 days.
AnswerC

Expedited updates allow administrators to deploy a specific Windows quality update immediately, bypassing deferrals and other update ring settings. This feature is designed for critical security updates that must be installed without delay. It targets devices directly and ensures the update is installed as soon as possible, meeting the requirement.

Why this answer

Expedited updates in Microsoft Intune are specifically designed to deploy a particular Windows quality update immediately, overriding deferrals and other update ring settings. This is the correct approach for critical security updates that cannot wait. Other methods either do not bypass deferrals or affect all updates rather than the specific one.

Exam trap

The trap here is assuming that changing a deferral or setting a deadline will force immediate installation, when only expedited updates bypass deferrals.

80
MCQmedium

You manage Windows 10 devices enrolled in Microsoft Intune. Users report that the Company Portal app is not installing required apps. You verify that the devices are compliant and checked in recently. What is the most likely cause?

A.The users are not members of the Azure AD group assigned to the required app.
B.The devices are not connected to a Wi-Fi network configured in Intune.
C.The devices are not compliant with the compliance policy.
D.The enrollment restrictions are blocking the devices from receiving apps.
AnswerA

Group membership drives Intune app assignment: if users are absent from the Microsoft Entra ID group targeted by the required app, the app never reaches their devices, regardless of compliance or check-in status. Since the devices are compliant and recently checked in, assignment targeting is the remaining constraint the stem leaves unsatisfied.

Why this answer

In Microsoft Intune, app deployment is based on Azure AD group assignments. Even if a device is compliant and has recently checked in, the required app will not install unless the user or device is a member of the Azure AD group that the app is assigned to. Intune evaluates group membership at each check-in to determine which apps should be pushed, so missing group membership is the most likely cause when compliance and connectivity are verified.

Exam trap

The trap here is that candidates often assume compliance or device connectivity is the primary blocker for app installation, overlooking that Intune's app delivery is strictly gated by Azure AD group membership, not by device health or network type.

How to eliminate wrong answers

Option B is wrong because Intune does not require a specific Wi-Fi network configured in Intune for app installation; apps can be delivered over any network connection, including cellular, as long as the device has internet access. Option C is wrong because the question explicitly states that devices are compliant, so non-compliance cannot be the cause. Option D is wrong because enrollment restrictions control which devices can enroll in Intune, not the delivery of apps to already enrolled devices; once enrolled, restrictions do not block app assignments.

81
MCQeasy

A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?

A.The user's Intune license has expired.
B.The Outlook app is not installed on the device.
C.A compliance policy was updated requiring a newer OS version or additional security settings.
D.The device is not enrolled in Intune.
AnswerC

Intune evaluates compliance on device check-in, so a policy change adding a minimum OS version or stronger security settings marks the previously compliant iOS device non-compliant, blocking Outlook mobile access via conditional access until the device meets the new requirements.

Why this answer

Intune compliance policies are evaluated in real time when a user attempts to access corporate resources. If an administrator updates a policy to require a newer iOS version or additional security settings (e.g., passcode complexity, encryption), the device may become non-compliant even if it was previously compliant. The Outlook app checks device compliance via the Intune SDK and will block access if the device no longer meets the policy requirements, displaying the 'device not compliant' error.

Exam trap

The trap here is that candidates assume the error means the device is not enrolled or that the app is missing, but the question explicitly states the device is enrolled and compliant, so the most likely cause is a policy change that retroactively affects compliance status.

How to eliminate wrong answers

Option A is wrong because an expired Intune license would prevent the user from enrolling the device or accessing Intune-managed resources entirely, but the device is already enrolled and compliant, and the error specifically states non-compliance, not a licensing issue. Option B is wrong because if the Outlook app were not installed, the user would not be able to launch it or see an error within the app; the error is displayed by the app itself, confirming it is installed. Option D is wrong because the question explicitly states the device is enrolled in Intune and compliant, so the device is enrolled; the error is due to a change in compliance status, not enrollment status.

82
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?

A.Require device to be marked as compliant.
B.Require multi-factor authentication.
C.Require app protection policy.
D.Require device to be enrolled in Intune.
AnswerA

Require device to be marked as compliant makes Microsoft Entra ID conditional access grant Exchange Online access only when Intune reports the device compliant. It directly satisfies the stem's constraint that only compliant devices reach corporate email.

Why this answer

To ensure only compliant devices access Exchange Online, the Conditional Access policy must include the grant control 'Require device to be marked as compliant.' This control checks the device's compliance state in Intune and blocks access if the device is non-compliant, directly enforcing the requirement. It is the precise setting for compliance-based access.

Exam trap

MD-102 often tests the confusion between 'Require device to be marked as compliant' and 'Require device to be enrolled' — enrollment alone does not guarantee compliance, and only the compliance grant control enforces policy adherence.

How to eliminate wrong answers

Option B is wrong because requiring MFA verifies user identity but does not check device compliance, so a non-compliant device could still access email after MFA. Option C is wrong because app protection policies (MAM) protect app data on unmanaged devices but do not enforce device compliance for Exchange Online access. Option D is wrong because requiring Intune enrollment ensures the device is managed but does not guarantee it meets compliance policies; a device can be enrolled yet non-compliant.

83
MCQmedium

Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?

A.Replace the device's motherboard.
B.Enable the TPM in the device's BIOS settings.
C.Assign a grace period for the device.
D.Remove the tpmRequired setting from the compliance policy.
AnswerB

Compliance evaluation queries the TPM through Windows, which reports nothing when the chip is disabled in firmware. Enabling TPM in BIOS exposes the 2.0 chip to the OS, letting the policy detect it and clear the 'TPM not found' reason.

Why this answer

The device has a TPM 2.0 chip that is disabled in BIOS. Enabling the TPM in BIOS allows the device to report its TPM presence to Microsoft Intune, satisfying the compliance policy's tpmRequired setting. No hardware replacement, grace period, or policy modification is needed when the TPM is physically present but disabled.

Exam trap

The trap here is that candidates may assume a 'TPM not found' error indicates missing hardware, leading them to choose motherboard replacement or policy removal, rather than recognizing that a disabled TPM in BIOS is a common configuration issue that can be resolved without hardware changes.

How to eliminate wrong answers

Option A is wrong because replacing the motherboard is unnecessary when the TPM chip is already present and functional; the issue is only that it is disabled in BIOS. Option C is wrong because assigning a grace period would only delay enforcement of the non-compliance, not resolve the underlying TPM detection failure. Option D is wrong because removing the tpmRequired setting from the compliance policy would lower the security baseline, whereas the correct action is to enable the existing TPM hardware.

84
MCQeasy

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?

A.A device compliance policy with a required passcode length of 6.
B.A device configuration profile with a passcode payload.
C.An app protection policy for Microsoft Outlook.
D.A conditional access policy requiring compliant devices.
AnswerA

A device compliance policy defines passcode requirements, including minimum length, for iOS devices. Setting the required passcode length to six characters enforces the stem's constraint before Microsoft Entra ID conditional access permits corporate email access.

Why this answer

A device compliance policy in Microsoft Intune evaluates whether devices meet specific security requirements, such as a minimum passcode length. By creating a compliance policy with a required passcode length of 6, Intune marks any iOS device with a shorter passcode as noncompliant. This noncompliant status can then be used by a conditional access policy to block access to corporate email, achieving the stated goal.

Exam trap

The trap here is that candidates often confuse a device configuration profile (which enforces settings) with a device compliance policy (which evaluates and reports compliance), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because a device configuration profile with a passcode payload enforces the passcode settings on the device (e.g., requiring the user to set a 6-character passcode), but it does not evaluate compliance or block access to corporate email on its own; it only configures the device. Option C is wrong because an app protection policy for Microsoft Outlook manages data protection within the app (e.g., preventing copy/paste or requiring a PIN for app access), but it does not enforce a device-level passcode length requirement. Option D is wrong because a conditional access policy requiring compliant devices is the mechanism that blocks access based on compliance status, but it does not define the passcode length requirement itself; you must first create the compliance policy (Option A) to set that requirement.

85
MCQeasy

A company is planning to use Windows Autopilot to deploy new devices. They want to ensure that devices are automatically enrolled in Microsoft Intune when a user signs in with their Microsoft Entra ID credentials. Which configuration is required?

A.Configure an Enrollment Status Page (ESP) profile in Intune.
B.Create a device compliance policy with the Action for noncompliance set to 'Enforce enrollment'.
C.Set device enrollment restrictions to allow all device platforms.
D.Configure MDM auto-enrollment in Microsoft Intune admin center.
AnswerD

MDM auto-enrollment must be configured in the Microsoft Intune admin center (or Microsoft Entra ID under Mobility > MDM) to automatically enroll devices when users sign in with their Microsoft Entra ID credentials. This is essential for Windows Autopilot deployment.

Why this answer

Configuring MDM auto-enrollment in Microsoft Entra ID (under Mobility > MDM) is the required step to automatically enroll devices in Intune when users sign in with their Microsoft Entra ID credentials during Windows Autopilot. Option A (Enrollment Status Page) only affects the end-user experience during enrollment, it does not trigger enrollment. Option B (compliance policy) enforces compliance after enrollment, not enrollment itself.

Option C (device enrollment restrictions) controls which platforms can enroll, not automatic enrollment.

86
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. You need to ensure that when a Windows 11 device is retired or wiped, the device record is automatically removed from Intune after 30 days. Which action should you take?

A.Configure a device cleanup rule in the Intune tenant settings.
B.Assign a compliance policy that marks devices as noncompliant after 30 days.
C.Create a dynamic device group based on the enrollment date.
D.Enable automatic enrollment for all users and set a retention policy in Microsoft Entra ID.
AnswerA

Intune includes a device cleanup rule under Tenant administration > Device cleanup rules. You can set devices to be automatically deleted after a specified number of days since last check-in. Setting it to 30 days ensures stale records are removed. This directly meets the requirement without manual intervention.

Why this answer

The device cleanup rule in Intune tenant settings automatically deletes devices that have not checked in for a specified number of days. Setting it to 30 days removes records for retired or wiped devices that no longer communicate. Dynamic groups, compliance policies, and Entra ID retention policies do not delete Intune device records, so they cannot fulfill this requirement.

Exam trap

The trap here is confusing compliance or group membership with actual device record deletion; only the device cleanup rule removes stale records from Intune.

87
MCQhard

You are troubleshooting an iPhone that cannot enroll in Microsoft Intune. The user receives an error stating 'This device is already enrolled in another MDM.' What is the most likely cause?

A.The device is already enrolled in Apple Business Manager or another MDM.
B.The device has a VPN configuration installed.
C.The device is not running the latest iOS version.
D.The user's license is expired.
AnswerA

The error indicates an existing MDM enrolment record tied to the device's Apple serial or enrolment ID. iPhones permit only one MDM profile at a time, so a prior enrolment — via Apple Business Manager, Apple Configurator, or another MDM — must be removed before Microsoft Intune can enrol it.

Why this answer

The error 'This device is already enrolled in another MDM' indicates that the iPhone has an existing MDM profile that conflicts with Intune enrollment. This typically occurs when the device is already enrolled in Apple Business Manager (ABM) or another MDM solution, as iOS enforces a single MDM enrollment per device. Intune cannot overwrite an existing MDM profile without first removing it.

Exam trap

The trap here is that candidates may confuse MDM enrollment conflicts with other common issues like outdated OS or licensing, but the specific error message directly points to an existing MDM profile, not generic configuration or access problems.

How to eliminate wrong answers

Option B is wrong because a VPN configuration does not prevent MDM enrollment; it is a separate network setting that can coexist with an MDM profile. Option C is wrong because while an outdated iOS version might cause compatibility issues, it does not produce the specific 'already enrolled' error; Intune supports a range of iOS versions with appropriate requirements. Option D is wrong because an expired user license would block Intune enrollment with a different error (e.g., 'License not found' or 'Access denied'), not the 'already enrolled' message.

88
MCQhard

You are designing a Windows 11 update strategy for a fleet of 500 devices managed by Intune. The organization requires that critical security updates be applied within 7 days, but feature updates can be delayed up to 60 days. Which Update Rings configuration should you use?

A.Assign a Quality Update policy with deferral of 7 days
B.Create an Update Ring with quality update deferral of 7 days and feature update deferral of 60 days
C.Configure Windows Update for Business via Group Policy on-premises
D.Assign a Feature Update policy with deferral of 60 days
AnswerB

Deferral values hold quality and feature updates back by the specified number of days, so a 7-day quality deferral meets the security deadline while a 60-day feature deferral matches the permitted delay for feature updates.

Why this answer

Update Rings in Intune allow you to independently configure deferral periods for quality updates (security fixes) and feature updates. Setting quality update deferral to 7 days ensures critical security patches are applied within the required window, while feature update deferral of 60 days delays non-security feature updates as needed, all managed via cloud-based Windows Update for Business policies.

Exam trap

The trap here is that candidates often confuse Update Rings with separate Quality or Feature Update policies, not realizing that Update Rings are the single object that can simultaneously control both deferral periods, while the other options only address one type of update.

How to eliminate wrong answers

Option A is wrong because a Quality Update policy (via Windows 10/11 feature update policies) only controls deferral for quality updates, but does not address the feature update deferral requirement of 60 days; it is an incomplete solution. Option C is wrong because configuring Windows Update for Business via on-premises Group Policy contradicts the requirement that devices are managed by Intune; Intune uses cloud-based policies, not local Group Policy, and this approach would not leverage the centralized mobile device management (MDM) capabilities. Option D is wrong because a Feature Update policy only controls deferral for feature updates, ignoring the quality update deferral requirement of 7 days; it addresses only half of the requirement.

89
MCQhard

You are planning a Windows 11 deployment for 500 new devices using Windows Autopilot. The devices will be shipped directly to users from the manufacturer. You need to ensure that the devices are automatically enrolled in Intune and joined to Microsoft Entra ID. What should you do?

A.Register the device hashes in Intune and assign an Autopilot deployment profile
B.Pre-install the Intune Management Extension on each device
C.Configure a provisioning package and include it with the shipment
D.Create a hybrid Azure AD join configuration in Intune
AnswerA

Registering hardware hashes creates Autopilot device records, letting Intune identify each device at first boot. Assigning a deployment profile then drives the Microsoft Entra join and automatic Intune enrolment, satisfying the requirement that manufacturer-shipped devices enrol without IT touching them.

Why this answer

Windows Autopilot uses device hashes (hardware IDs) to identify devices in Intune. By registering these hashes and assigning an Autopilot deployment profile, the devices are automatically enrolled in Intune and joined to Microsoft Entra ID during the out-of-box experience (OOBE), without requiring manual intervention or additional infrastructure.

Exam trap

The trap here is that candidates often confuse hybrid Azure AD join with Microsoft Entra ID join, or think provisioning packages are needed for Autopilot, when in fact Autopilot is designed for zero-touch, cloud-only scenarios without any on-premises dependency.

How to eliminate wrong answers

Option B is wrong because the Intune Management Extension is automatically installed during Intune enrollment, not pre-installed on devices before Autopilot runs. Option C is wrong because provisioning packages (PPKG files) are used for manual or bulk provisioning, not for the zero-touch, cloud-driven Autopilot scenario where devices are shipped directly to users. Option D is wrong because hybrid Azure AD join requires a connection to on-premises Active Directory and is not the default for Autopilot; the scenario specifies Microsoft Entra ID join, not hybrid.

90
MCQeasy

You need to ensure that corporate devices automatically install critical Windows updates within 24 hours of release. Which update ring setting should you configure in Intune?

A.Grace Period for Restarts (days)
B.Defer Quality Updates (days)
C.Update Deadline for Quality Updates (days)
D.Active Hours
AnswerC

The Update Deadline for Quality Updates setting forces installation within a specified number of days after release, regardless of user deferral. Setting it to 1 day satisfies the requirement to install updates within 24 hours.

Why this answer

The 'Update Deadline for Quality Updates (days)' setting in Intune's update ring policy enforces a deadline by which quality updates must be installed. Configuring this to 1 day ensures that devices install critical Windows updates within 24 hours of release, as the deadline triggers automatic installation and restart after the specified number of days.

Exam trap

The trap here is that candidates confuse 'Defer Quality Updates' (which delays updates) with 'Update Deadline for Quality Updates' (which enforces installation timing), leading them to incorrectly select Option B thinking it controls installation speed.

How to eliminate wrong answers

Option A is wrong because 'Grace Period for Restarts (days)' controls how long after the deadline a user can postpone a restart, not the time to install the update. Option B is wrong because 'Defer Quality Updates (days)' delays the availability of updates, which would prevent automatic installation within 24 hours of release. Option D is wrong because 'Active Hours' defines a time window during which restarts are avoided, but does not enforce a deadline for update installation.

91
MCQhard

You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?

A.allowBluetooth set to false
B.allowStorageCard set to false
C.allowCopyPaste set to false
D.allowCamera set to false
AnswerA

Setting allowBluetooth to false disables the Bluetooth radio entirely, so paired mice and keyboards stop working. This policy setting directly satisfies the stem's constraint: users cannot use Bluetooth devices after the custom policy applies. Other settings, such as camera or Wi-Fi restrictions, would not produce this specific symptom.

Why this answer

The `allowBluetooth` setting set to `false` explicitly disables the Bluetooth radio on the device, preventing any Bluetooth peripherals (mouse, keyboard, etc.) from pairing or connecting. This is a common policy in Windows CSP (Policy CSP – Bluetooth/AllowBluetooth) that controls the Bluetooth stack at the OS level, and setting it to false blocks all Bluetooth functionality.

Exam trap

The trap here is that candidates may confuse `allowBluetooth` with other device restriction policies (like camera or storage) or assume Bluetooth issues are caused by a network or driver problem, rather than recognizing the specific CSP policy that directly disables the Bluetooth radio.

How to eliminate wrong answers

Option B is wrong because `allowStorageCard` controls the use of removable storage (e.g., SD cards), not Bluetooth connectivity. Option C is wrong because `allowCopyPaste` restricts clipboard sharing between the device and other systems (e.g., in Remote Desktop or Kiosk mode), not Bluetooth device pairing. Option D is wrong because `allowCamera` disables the built-in camera, which has no impact on Bluetooth radio or peripheral connections.

92
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company-specific application (a .pkg file) to all macOS devices. The application requires a specific configuration file that must be placed in the /Library/Application Support/ directory. You also need to ensure that the application is installed silently without user interaction. How should you configure the deployment in Intune?

A.Use a shell script in Intune to download and install the .pkg file from a secure URL.
B.Create a device configuration profile for macOS that includes the app installation settings.
C.Add the .pkg file as a macOS line-of-business app in Intune, specify installation arguments for silent install, and include a script to copy the configuration file post-install.
D.Use Apple Volume Purchase Program (VPP) to distribute the app as a managed app.
AnswerC

This is the standard method for deploying custom macOS apps with configuration.

Why this answer

Intune's macOS line-of-business (LOB) app deployment supports .pkg files and allows you to specify installation arguments (e.g., `-silent` or `--acceptLicense`) for silent installation. To place the configuration file in /Library/Application Support/, you must use a post-install script because Intune does not natively copy files to specific directories during LOB app deployment. This combination ensures the app is installed silently and configured correctly.

Exam trap

The trap here is that candidates often confuse device configuration profiles (which only manage settings) with app deployment, or they assume a simple script can replace the structured LOB app deployment with its silent install and post-install script capabilities.

How to eliminate wrong answers

Option A is wrong because a shell script in Intune can download and install a .pkg, but it does not provide the built-in silent install arguments or the post-install script capability that LOB app deployment offers; additionally, Intune's script deployment lacks the same reporting and dependency management as LOB apps. Option B is wrong because device configuration profiles in Intune are used for settings (e.g., restrictions, preferences) and cannot deploy applications or run scripts. Option D is wrong because VPP is for distributing apps from the Apple App Store, not for deploying custom .pkg files or managing configuration files.

93
MCQhard

You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?

A.Create an Intune device configuration profile using the Settings Catalog and assign it to the Azure AD group containing Cloud PC users.
B.Include the settings in the Windows 365 provisioning policy.
C.Create a PowerShell script that runs during provisioning and apply it via Azure Automation.
D.Use a Group Policy Object (GPO) applied via on-premises AD.
AnswerA

The Settings Catalog exposes Defender for Endpoint real-time protection and firewall configuration settings as a reusable Intune profile, which applies automatically to Cloud PCs once assigned to the Microsoft Entra ID group. This satisfies the requirement for automatic configuration at provisioning.

Why this answer

Intune device configuration profiles using the Settings Catalog allow granular control over Microsoft Defender for Endpoint settings (e.g., real-time protection) and custom firewall rules. These profiles can be assigned to an Azure AD group containing Cloud PC users, ensuring the settings are applied automatically after provisioning via the Windows 365 service, which integrates with Intune for post-provisioning management.

Exam trap

The trap here is that candidates mistakenly think Windows 365 provisioning policies can include security configurations, but in reality, they only define infrastructure settings, while all post-provisioning management (including Defender and firewall rules) must be handled by Intune policies.

How to eliminate wrong answers

Option B is wrong because Windows 365 provisioning policies only define Cloud PC configuration (e.g., region, network, image) and do not support granular security settings like Defender or custom firewall rules; those must be applied via Intune after provisioning. Option C is wrong because PowerShell scripts run during provisioning via Azure Automation are not natively integrated with Windows 365 provisioning; the recommended approach is to use Intune configuration profiles, which are designed for post-provisioning device management. Option D is wrong because Group Policy Objects (GPOs) require on-premises Active Directory and domain-joined devices, but Cloud PCs are Azure AD-joined or Hybrid Azure AD-joined by default and do not support direct GPO application without additional infrastructure like Group Policy Administrative Templates in Intune.

94
Multi-Selecteasy

You are troubleshooting a Windows device that is not receiving policies from Intune. Which TWO actions should you take?

Select 2 answers
A.Configure a Conditional Access policy
B.Reset the user's password
C.Verify the device is enrolled in Intune
D.Check the device sync status in the Intune console
E.Review the app protection policy assignment
AnswersC, D

Device must be enrolled to receive policies.

Why this answer

A device must be enrolled in Intune to receive policies; if enrollment is missing, the device will not appear in the Intune console and cannot process MDM policies. Verifying enrollment status (e.g., via Settings > Accounts > Access work or school) confirms the device is managed and can receive policy payloads.

Exam trap

The trap here is that candidates confuse policy delivery issues with authentication or app-level controls, leading them to select Conditional Access or app protection policies instead of focusing on the fundamental enrollment and sync prerequisites.

95
Multi-Selectmedium

Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows 11 devices remotely? (Choose two.)

Select 2 answers
A.Collect diagnostics
B.Deploy a line-of-business app
C.Restart the device
D.Create a VPN profile
E.Assign a compliance policy
AnswersA, C

Collect diagnostics is a remote action in the Intune admin center that pulls Windows 11 device logs and uploads them for review, satisfying the requirement to manage devices remotely without physical access or user intervention.

Why this answer

Option A (Collect diagnostics) is correct because the Intune admin center provides a remote action on Windows 11 devices that gathers diagnostic logs from the device and uploads them to Intune for troubleshooting. Option C (Restart the device) is correct because Intune offers a remote restart action that sends a command to the Windows 11 device to reboot it without requiring physical access. The other options are not remote device actions: deploying a line-of-business app, creating a VPN profile, and assigning a compliance policy are configuration or policy management tasks performed on the Intune service, not direct remote actions executed against a specific enrolled device.

Exam trap

The trap here is that candidates confuse policy-based actions (like deploying apps or assigning compliance policies) with immediate remote actions, which are specifically listed under the 'Device actions' menu in the Intune admin center.

96
MCQeasy

A user's iOS device is enrolled in Microsoft Intune. The user reports that they cannot install the Company Portal app from the App Store. What is the most likely reason?

A.The user does not have an Apple ID.
B.The App Store is disabled by a device restriction policy.
C.The device is not enrolled in Intune.
D.The device is not supervised.
AnswerB

A device restriction policy blocking the App Store prevents all App Store installs, including Company Portal, which iOS requires to be installed from the App Store. This directly explains the reported failure, since the restriction removes the only permitted installation channel for that app on the enrolled device.

Why this answer

A device restriction policy in Microsoft Intune can block access to the App Store on iOS devices. When the App Store is disabled via a configuration profile, users cannot install or update any apps from the App Store, including the Company Portal app. This is a common policy setting used by organizations to control app installation sources.

Exam trap

The trap here is that candidates often assume the Company Portal app must be pre-installed or that device supervision is required for app installation, but Intune can deploy the Company Portal to unsupervised devices, and the issue is specifically a policy blocking the App Store.

How to eliminate wrong answers

Option A is wrong because an Apple ID is required to download apps from the App Store, but the absence of an Apple ID would prevent any app installation, not specifically the Company Portal app, and Intune enrollment does not require an Apple ID. Option C is wrong because the user's device is already enrolled in Intune as stated in the question, so lack of enrollment cannot be the reason. Option D is wrong because device supervision is not a prerequisite for installing the Company Portal app; supervised mode is primarily used for advanced management capabilities like device configuration and restrictions, but the Company Portal can be installed on both supervised and unsupervised devices.

97
MCQeasy

A company uses Microsoft Intune to manage iOS devices. They want to ensure that only devices with a passcode of at least 6 characters and without jailbreak can access corporate email. Which policy type should they configure?

A.Conditional Access policy
B.App protection policy
C.Device compliance policy
D.Device configuration policy
AnswerC

A device compliance policy defines exactly these conditions — minimum passcode length and jailbreak detection — as rules a device must satisfy. Conditional Access then blocks corporate email for non-compliant devices, directly meeting the stem's requirement that only passcode-protected, non-jailbroken iOS devices reach email.

Why this answer

Device compliance policies in Microsoft Intune evaluate device-level security settings such as jailbreak status and passcode length. By configuring a compliance policy that requires a passcode of at least 6 characters and detects jailbroken devices, Intune can mark non-compliant devices and, when combined with Conditional Access, block access to corporate email. This is the correct policy type because it directly assesses the device's security posture rather than app-level or configuration settings.

Exam trap

The trap here is that candidates confuse 'Conditional Access' (the gatekeeper) with the policy that defines the conditions (Device Compliance), leading them to select Option A because they think the policy that 'ensures only devices with... can access' is the access control policy itself, rather than the compliance policy that provides the evaluation signal.

How to eliminate wrong answers

Option A is wrong because Conditional Access policies are access-control rules that rely on signals from compliance policies or other sources; they do not themselves define or enforce device-level requirements like passcode length or jailbreak detection. Option B is wrong because App protection policies (MAM) manage data protection at the app level (e.g., PIN for opening an app, data encryption) and do not evaluate device-level attributes such as jailbreak status or system passcode length. Option D is wrong because Device configuration policies push settings (e.g., Wi-Fi, VPN, email profiles) to devices but do not enforce compliance checks or block access based on security state; they are not designed for conditional access enforcement.

98
MCQhard

Refer to the exhibit. The exhibit shows a JSON representation of a managed device from Microsoft Graph API. The device shows as noncompliant. Which of the following is the most likely reason for the noncompliant status?

A.The device has not synced recently; the compliance policy may require a more recent check-in.
B.The device is company-owned, which is noncompliant by default.
C.The device is a userless device and cannot be compliant.
D.The device's operating system version is not supported.
AnswerA

Compliance policies often require devices to sync within a certain period; the last sync is March 15, which may be older than the policy threshold.

Why this answer

The JSON shows the device's lastSyncDateTime is significantly older than the current time, and the complianceState is 'noncompliant'. Microsoft Intune compliance policies require devices to check in within a configurable grace period (default 30 days for noncompliant devices, but policies can enforce a shorter interval). If the device hasn't synced recently, it fails the 'Device check-in frequency' compliance rule, marking it noncompliant.

Option A correctly identifies this as the most likely cause.

Exam trap

The trap here is that candidates often assume noncompliance is due to an unsupported OS version or ownership type, but the JSON explicitly shows a supported OS and no ownership-based policy, while the stale lastSyncDateTime is the clear indicator of a check-in failure.

How to eliminate wrong answers

Option B is wrong because company-owned devices are not noncompliant by default; ownership type (corporate vs. personal) does not directly affect compliance state unless a specific compliance policy targets ownership. Option C is wrong because userless devices (e.g., kiosk or shared devices) can be compliant if they meet all policy requirements; Intune supports device compliance for userless scenarios via device enrollment. Option D is wrong because the JSON shows the operating system version as '10.0.22621' (Windows 11 22H2), which is a supported version; there is no indication of an unsupported OS.

99
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a .pkg app to these devices. What is the recommended method?

A.Add as a Windows line-of-business app.
B.Add as a macOS web app.
C.Add as a Microsoft Store app.
D.Add as a macOS line-of-business app.
AnswerD

Adding the .pkg as a macOS line-of-business app uses Intune's native LOB app type, which supports the .pkg format directly and satisfies the requirement to deploy to managed macOS devices without repackaging or third-party tooling.

Why this answer

The recommended method to deploy a .pkg app to macOS devices managed by Microsoft Intune is to add it as a macOS line-of-business (LOB) app. This app type is specifically designed for deploying macOS installer packages (.pkg) and requires the file to be uploaded directly to Intune, which then pushes the installation to enrolled devices using the Intune management agent for macOS.

Exam trap

The trap here is that candidates may confuse 'line-of-business app' with Windows-only deployment, or mistakenly think a 'web app' can install a native .pkg, but the correct answer is the macOS-specific LOB app type.

How to eliminate wrong answers

Option A is wrong because 'Windows line-of-business app' is intended for Windows app deployment (e.g., .msi or .exe files) and cannot be used to deploy .pkg files to macOS devices. Option B is wrong because 'macOS web app' is used to create a shortcut to a web application (URL) on the device, not to install a native .pkg package. Option C is wrong because 'Microsoft Store app' is for deploying apps from the Microsoft Store, which does not support .pkg files and is not applicable to macOS devices.

100
MCQeasy

A help desk technician reports that a Windows 11 device enrolled in Microsoft Intune has not received a newly assigned configuration profile. The device shows as compliant in the admin center. You need to force the device to check in with Intune immediately. What should you do?

A.From the device overview, select Retire to remove corporate data and force a re-enrollment
B.From the device overview in the Intune admin center, select Sync to trigger a check-in
C.From the device overview, select Collect diagnostics to gather logs and force a policy refresh
D.From the device overview, select Fresh Start to reset the device and reapply all policies
AnswerB

The Sync action on the device overview sends a push notification through the Windows Push Notification Service to the device, prompting the Intune Management Extension and MDM channel to check in immediately and pull new policies. This is the standard administrative action to force a check-in without waiting for the scheduled interval, and it directly addresses the scenario of a newly assigned profile not yet applied.

Why this answer

The Sync action in the Intune admin center sends a remote check-in request to the device, causing it to contact the service and apply any pending policies or profiles. It is the correct, non-destructive way to force an immediate check-in when a device appears healthy but has not yet received a newly assigned configuration. Other device actions such as Retire or Fresh Start are destructive and unrelated to policy refresh.

Exam trap

The trap here is confusing diagnostic or destructive device actions with the Sync action that actually triggers a policy refresh.

101
MCQeasy

You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?

A.Use Group Policy Editor to configure BitLocker locally on each device.
B.Check if the devices have TPM version 2.0.
C.Re-create the BitLocker policy with a different name.
D.Remotely sync the devices from the Intune console to refresh policy.
AnswerD

Intune applies policy on device check-in, so devices that have not contacted the service since assignment still lack BitLocker settings. Triggering a remote sync forces each device to retrieve and apply the endpoint security policy immediately.

Why this answer

When a BitLocker endpoint security policy is assigned but devices have not applied it, forcing a remote sync from the Intune console triggers the device to check in and apply pending policies, including BitLocker encryption.

Exam trap

MD-102 often tests whether candidates jump to re-enrollment or policy recreation when the correct first step is simply forcing a device sync to trigger pending policy application.

How to eliminate wrong answers

Option A is wrong because local Group Policy bypasses Intune management and defeats centralized control. Option B is wrong because TPM 2.0 is a prerequisite already verified; checking it again does not force policy application. Option C is wrong because recreating the policy with a new name does not address the sync delay and may cause duplicate policy conflicts.

102
MCQeasy

Refer to the exhibit. The JSON snippet shows a Windows Update for Business policy assigned to a device group. Users report that quality updates are installed 7 days after release. Which setting controls this behavior?

A.featureUpdateDeferralPeriodInDays
B.businessReadyUpdatesOnly
C.qualityUpdateDeferralPeriodInDays
D.automaticUpdateMode
AnswerC

qualityUpdateDeferralPeriodInDays directly governs how long devices wait before installing quality updates, so a value of 7 produces exactly the reported seven-day delay. The other deferral settings apply to different update categories, such as feature or driver updates, and therefore cannot satisfy this scenario's stated behaviour.

Why this answer

The setting `qualityUpdateDeferralPeriodInDays` controls how long quality updates (security fixes) are deferred after release. A value of 7 means updates are installed 7 days post-release, matching the user report. This is a Windows Update for Business policy configured via CSP (Policy CSP - Update).

Exam trap

The trap here is that candidates confuse `featureUpdateDeferralPeriodInDays` with quality update deferral, assuming all deferral settings work the same way, but they are separate policies for different update types.

How to eliminate wrong answers

Option A is wrong because `featureUpdateDeferralPeriodInDays` controls deferral of feature updates (major OS version upgrades), not quality updates. Option B is wrong because `businessReadyUpdatesOnly` determines whether to receive only business-ready (servicing channel) updates or preview updates, not the deferral period. Option D is wrong because `automaticUpdateMode` controls the update installation behavior (e.g., auto-install at scheduled time, notify download), not the deferral delay.

103
MCQhard

You use Microsoft Intune to manage Windows 11 devices. A device named LAPTOP-01 is not receiving a newly assigned device configuration profile. You verify the profile is assigned to a group that contains LAPTOP-01. You need to force the device to check in with Intune and apply the policy immediately. Which action should you perform from the Intune admin center?

A.Select the device and choose 'Sync'.
B.Restart the device from the Intune admin center.
C.Select the device and choose 'Remote lock'.
D.Select the device and choose 'Collect diagnostics'.
AnswerA

The 'Sync' action in the Intune admin center triggers an immediate check-in with the Intune service on the device. This causes the device to download and apply pending policies, including the new configuration profile. It is the standard method to force policy application without waiting for the scheduled check-in interval.

Why this answer

The 'Sync' action in the Intune admin center is designed to initiate an immediate device check-in with the Intune service. This prompts the device to retrieve and apply any pending policies, including newly assigned configuration profiles. Other actions like collecting diagnostics, remote lock, or restart do not directly trigger a policy sync and are not the correct approach for this requirement.

Exam trap

The trap here is assuming that restarting the device or collecting diagnostics will force a policy sync, when only the Sync action performs an immediate check-in.

104
Multi-Selectmedium

You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Require Trusted Platform Module (TPM)
B.Require Secure Boot to be enabled on the device
C.Require a minimum OS version
D.Require code integrity
E.Require BitLocker
AnswersB, E

The 'Require Secure Boot to be enabled on the device' setting verifies that Secure Boot is active. If Secure Boot is disabled, the device is noncompliant. This meets the requirement to enforce Secure Boot on Windows 11 devices.

Why this answer

To enforce BitLocker and Secure Boot, the compliance policy must include the 'Require BitLocker' and 'Require Secure Boot to be enabled on the device' settings. These directly evaluate the encryption and firmware security states. Other settings like TPM or code integrity are related but do not confirm that BitLocker and Secure Boot are active.

Exam trap

The trap here is selecting TPM or code integrity, which are prerequisites or related features, but do not directly verify that BitLocker and Secure Boot are enabled.

105
MCQmedium

You need to deploy a custom Windows 11 feature update to a pilot group of 50 devices before rolling out to the entire organization. The devices are managed by Intune and are in a 'Pilot' Azure AD group. What is the best approach?

A.Configure a Windows Update for Business deferral policy for all devices
B.Create a custom configuration profile with update settings
C.Create a feature update profile for Windows 11 and assign to the pilot group
D.Use Group Policy to configure Windows Update settings for the pilot group
AnswerC

A feature update profile targets specific Windows 11 versions and deploys to assigned Microsoft Entra groups, letting you scope the rollout to the 50-device Pilot group before broadening assignment. This satisfies the staged pilot-then-org requirement without manual installation.

Why this answer

Intune's feature update profiles are specifically designed to deploy Windows 11 feature updates to targeted Azure AD groups, such as the 'Pilot' group. This approach allows you to control the exact feature update version (e.g., Windows 11 23H2) and assign it only to the pilot devices, enabling a controlled rollout before expanding to the entire organization.

Exam trap

The trap here is that candidates often confuse feature update profiles with quality update policies or configuration profiles, mistakenly thinking any update-related setting can be applied via a configuration profile or deferral policy.

How to eliminate wrong answers

Option A is wrong because a Windows Update for Business deferral policy only delays the installation of updates; it does not deploy a specific feature update version to a targeted group. Option B is wrong because custom configuration profiles are used for device settings (e.g., security policies, app configurations), not for deploying feature updates; feature updates require a dedicated feature update profile. Option D is wrong because Group Policy is not applicable in a cloud-only Intune-managed environment; devices must be Azure AD joined and managed via Intune, and Group Policy requires on-premises Active Directory and Domain Services.

106
MCQhard

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?

A.Check if the user has logged in and acknowledged the FileVault prompt.
B.Ensure that a compliance policy is also assigned requiring encryption.
C.Ensure the devices are supervised.
D.Verify that the profile is assigned to the correct device group.
AnswerA

FileVault encryption only starts after the local user authenticates and approves the privacy prompt enabling the secure token; until that acknowledgement occurs, the profile applies but the disk stays unencrypted, so checking user sign-in and prompt acceptance explains the unencrypted devices.

Why this answer

FileVault encryption on macOS requires user interaction to complete. When Intune deploys a FileVault profile with recovery key escrow, the user must log in and explicitly acknowledge the FileVault prompt to enable encryption. If the user has not done so, the device remains unencrypted regardless of the profile assignment.

Exam trap

The trap here is that candidates often assume a configuration profile alone enforces encryption immediately, overlooking the mandatory user interaction step required by macOS for FileVault activation.

How to eliminate wrong answers

Option B is wrong because compliance policies do not trigger encryption; they only report non-compliance after encryption is expected. Option C is wrong because macOS devices do not require supervision for FileVault encryption or key escrow; supervision is an iOS/iPadOS concept. Option D is wrong because if the profile were assigned to the wrong group, the profile would not appear on the device at all, but the issue here is that the profile is deployed yet encryption is not active, indicating a user interaction gap.

107
MCQmedium

You manage iOS/iPadOS devices with Microsoft Intune. You need to ensure that when a device is lost or stolen, its corporate data can be remotely wiped while leaving personal data intact. The devices are enrolled as user enrollment (personal devices). What should you do?

A.Retire the device from Intune and then delete the device record.
B.Issue a full wipe from the Intune console for the device.
C.Issue a selective wipe from the Intune console for the device.
D.Configure a conditional access policy to block the device from accessing corporate resources.
AnswerC

For user-enrolled iOS/iPadOS devices, a selective wipe removes only corporate data, management profiles, and managed apps, leaving personal data and apps untouched. This is the correct action to protect corporate information on a lost personal device without affecting the user's personal content.

Why this answer

For user-enrolled iOS/iPadOS devices, selective wipe is the correct action to remove corporate data while preserving personal data. It targets only managed apps, profiles, and corporate data. Full wipe would erase personal content, retiring does not actively wipe, and conditional access only blocks access without removing data.

Exam trap

The trap here is assuming that any wipe action removes all data; on personal devices, only selective wipe preserves personal content.

108
MCQmedium

Refer to the exhibit. You run this PowerShell command using the Microsoft Graph PowerShell SDK. What is the primary purpose of this command?

A.To list only non-compliant Windows devices.
B.To retrieve all managed devices regardless of operating system.
C.To enforce compliance on Windows devices.
D.To retrieve a list of all Windows managed devices with their compliance status.
AnswerD

The Graph SDK cmdlet queries managedDevices filtered by operating system, returning each Windows device alongside its complianceState property. This satisfies the stem's aim of listing all Windows managed devices together with their current compliance status.

Why this answer

The PowerShell command uses `Get-MgDeviceManagementManagedDevice` with a filter for `operatingSystem eq 'Windows'` and selects properties including `complianceState`. This retrieves all Windows managed devices and their compliance status, making option D correct. The command does not filter by compliance state, so it returns both compliant and non-compliant devices, and it does not enforce any compliance action.

Exam trap

The trap here is that candidates may assume the command only returns non-compliant devices because complianceState is selected, but the filter does not restrict by compliance value—it merely includes that property in the output.

How to eliminate wrong answers

Option A is wrong because the command does not filter by complianceState; it retrieves all Windows devices, not just non-compliant ones. Option B is wrong because the filter `operatingSystem eq 'Windows'` explicitly limits results to Windows devices, not all managed devices regardless of operating system. Option C is wrong because the command is a read-only GET operation that retrieves device data; it does not perform any enforcement or remediation actions on compliance.

109
MCQeasy

A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?

A.Use the Microsoft Intune admin center to view the Windows Update for Business report
B.Use Microsoft 365 Lighthouse
C.Use the Device compliance report in Intune
D.Use Microsoft Defender for Endpoint's advanced hunting
AnswerA

The Windows Update for Business report in the Microsoft Intune admin center aggregates update installation state per device, including specific KBs. It satisfies the requirement to identify which managed devices have a particular Windows update installed, without needing custom scripting or third-party tooling.

Why this answer

The Windows Update for Business report in the Microsoft Intune admin center provides a dedicated view of update compliance, including which devices have installed specific Windows updates. This report aggregates data from the Windows Update service and displays it per device, making it the correct method for identifying devices with a particular update installed.

Exam trap

The trap here is that candidates often confuse the Device compliance report (which checks OS version or build) with the Windows Update for Business report (which tracks specific KB installations), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option B is wrong because Microsoft 365 Lighthouse is designed for multi-tenant management of Microsoft 365 services across customers, not for granular per-device Windows update reporting within a single tenant. Option C is wrong because the Device compliance report in Intune focuses on compliance policies (e.g., encryption, OS version) and does not track individual Windows update KB installations. Option D is wrong because Microsoft Defender for Endpoint's advanced hunting uses Kusto Query Language (KQL) to query security-related events and device information, but it is not the primary or recommended method for reporting on Windows update installation status; it requires custom queries and lacks the pre-built update-specific aggregation of the Windows Update for Business report.

110
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a user reports a lost device, you can remotely lock it and display a custom message on the lock screen. The solution must not erase any data. What should you do?

A.Use the Fresh Start action.
B.Perform a full wipe.
C.Use the Remote lock action and configure a custom lock screen message.
D.Perform a selective wipe.
AnswerC

The Remote lock action in Intune allows you to lock a device remotely. For Windows devices, you can also configure a custom lock screen message via a device configuration profile. This combination locks the device and displays a message without erasing data, meeting all requirements.

Why this answer

To remotely lock a lost Windows device and display a custom message without erasing data, use the Remote lock action in Intune. Additionally, configure a custom lock screen message through a device configuration profile. This secures the device and provides contact information, all without data loss.

Exam trap

The trap here is assuming that selective wipe or Fresh Start can lock a device or display a message, when they are data removal or refresh tools.

111
MCQhard

You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?

A.Hybrid Azure AD join
B.Entra ID registered with on-premises domain join
C.Windows Autopilot self-deploying mode
D.Entra ID joined with VPN to on-premises
AnswerA

Hybrid Microsoft Entra join registers on-premises Active Directory domain-joined devices with Microsoft Entra ID, enabling Intune enrolment and policy delivery while preserving the Kerberos and LDAP trust needed for on-premises resource access. This satisfies the stem's dual requirement: Intune management plus continued access to on-premises resources.

Why this answer

Hybrid Azure AD join is the correct approach because it allows devices that are joined to on-premises Active Directory to also register with Microsoft Entra ID, enabling Intune management while maintaining access to on-premises resources via Kerberos/NTLM authentication. This configuration synchronizes the device object from AD to Entra ID using Azure AD Connect, creating a device identity that can be managed by Intune and can authenticate against both cloud and on-premises services without requiring a VPN.

Exam trap

The trap here is that candidates often confuse 'Entra ID registered' with 'Hybrid Azure AD join' because both involve Entra ID, but only Hybrid Azure AD join provides the on-premises domain join required for seamless resource access without a VPN.

How to eliminate wrong answers

Option B is wrong because Entra ID registered devices are only workplace-joined (personal or BYOD) and do not have a computer object in on-premises AD, so they cannot authenticate to on-premises resources using domain credentials or access domain-joined file shares without additional configuration. Option C is wrong because Windows Autopilot self-deploying mode is designed for kiosk or shared devices that are Entra ID joined only, not hybrid joined, and thus cannot natively access on-premises resources without a VPN or other connectivity solution. Option D is wrong because Entra ID joined devices with a VPN can access on-premises resources, but they are not domain-joined and therefore cannot use Kerberos authentication to on-premises AD; they rely on VPN connectivity and typically require additional solutions like Microsoft Entra application proxy or Always On VPN for seamless resource access, making it less integrated than Hybrid Azure AD join.

112
MCQmedium

You manage devices with Microsoft Intune. You need to ensure that only devices that meet specific compliance requirements can access Microsoft 365 services. You create a compliance policy and assign it to a group of users. What should you do next to enforce the policy?

A.Enable device compliance in the Microsoft Intune admin center
B.Configure a device configuration profile with a compliance setting
C.Create a conditional access policy that requires compliant devices
D.Assign the compliance policy to the devices
AnswerC

Conditional Access policies in Microsoft Entra ID can require that devices be marked as compliant by Intune before granting access to cloud apps. This enforces the compliance policy. Without a Conditional Access policy, the compliance policy only reports status but does not block access. Therefore, this is the necessary next step to enforce compliance.

Why this answer

To enforce compliance for access to Microsoft 365 services, you must create a Conditional Access policy that requires devices to be compliant. The compliance policy alone only evaluates and reports compliance status; it does not block access. Assigning to devices or enabling a setting does not enforce access control.

Conditional Access is the correct enforcement tool.

Exam trap

The trap here is thinking that assigning a compliance policy is enough to block access; enforcement requires a Conditional Access policy.

113
MCQmedium

Your organization has Windows 10 devices managed by Intune. You need to enforce BitLocker encryption on all devices. The devices must use a TPM protector and a recovery password. What should you configure?

A.Compliance policy for Windows 10
B.Endpoint security > Disk encryption policy
C.Windows Update for Business policy
D.Device configuration profile for Windows 10
AnswerB

Disk encryption policies under Endpoint security configure BitLocker settings, including requiring a TPM protector and recovery password, then enforce encryption across targeted Windows devices. This is the dedicated Intune workload for BitLocker, unlike general device configuration profiles.

Why this answer

To enforce BitLocker encryption with a TPM protector and recovery password on Windows 10 devices managed by Intune, you must configure an Endpoint security > Disk encryption policy. This policy type specifically targets BitLocker settings, including TPM and recovery password requirements, and is designed to enforce encryption at the device level through the Intune MDM channel.

Exam trap

The trap here is that candidates often confuse Device configuration profiles (Option D) with Endpoint security policies, but Microsoft explicitly separates disk encryption into the Endpoint security node for focused management, and the exam tests this distinction.

How to eliminate wrong answers

Option A is wrong because Compliance policy for Windows 10 evaluates device compliance after encryption is applied but does not configure BitLocker settings like TPM or recovery password; it only reports on encryption status. Option C is wrong because Windows Update for Business policy controls update rings and feature updates, not disk encryption or BitLocker configuration. Option D is wrong because Device configuration profile for Windows 10 can include some BitLocker settings, but the recommended and correct method for enforcing BitLocker with specific protectors in Intune is the Endpoint security > Disk encryption policy, which provides a dedicated, streamlined interface for encryption policies.

114
MCQhard

A user has a Windows 10 device that is enrolled in Microsoft Intune. The user reports that they cannot install a required app from the Company Portal. You check the Intune console and see that the app assignment is 'Required' but the installation status shows 'Failed'. The device is compliant. What should you check first?

A.Review the Intune management extension logs on the device.
B.Verify the device compliance policy.
C.Check the Company Portal app version.
D.Reassign the app to the user.
AnswerA

Reviewing the Intune management extension logs reveals why the Win32 app agent failed to install, since that extension handles Win32 app delivery and its local log records specific error codes. This directly satisfies the stem's 'Failed' installation status on an enrolled, compliant device, where compliance is not the blocker.

Why this answer

The Intune management extension (IME) handles app installation, PowerShell scripts, and custom compliance actions on Windows devices. When a required app fails to install despite the device being compliant, the IME logs (located in `ProgramData\Microsoft\IntuneManagementExtension\Logs`) provide granular error details such as exit codes, download failures, or dependency issues. Reviewing these logs is the fastest way to diagnose the root cause without making assumptions about compliance or app version.

Exam trap

The trap here is that candidates assume a compliant device means all Intune operations will succeed, overlooking that the Intune management extension is a separate component with its own failure modes unrelated to device compliance.

How to eliminate wrong answers

Option B is wrong because the device is already confirmed compliant, so compliance policy is not the cause of the installation failure. Option C is wrong because the Company Portal app version affects the user interface and enrollment flow, not the backend installation of a required app pushed by Intune. Option D is wrong because reassigning the app does not address the underlying failure reason and may simply reproduce the same error without diagnostic insight.

115
MCQmedium

Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Azure AD. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Azure AD joined. What is the most likely reason for the failure, and how should you resolve it?

A.Devices are not hybrid Azure AD joined; convert them to hybrid join for BitLocker policy to apply.
B.The policy does not specify a recovery key escrow location; configure it to escrow to Azure AD.
C.The policy is missing the 'Enable full disk encryption' setting or the encryption method is not specified; check the 'Windows Encryption' settings in the profile.
D.Devices are not co-managed with Configuration Manager; enable co-management to apply BitLocker policy.
AnswerC

The Endpoint Protection template requires the Windows Encryption settings to explicitly enable BitLocker and specify an encryption method; without them, no encryption is enforced. Enabling full disk encryption with the TPM protector and recovery key escrow resolves the failure.

Why this answer

The 'Endpoint Protection' template for Windows 10 and later requires explicit configuration of the 'Enable full disk encryption' setting and the encryption method (e.g., XTS-AES 128-bit) under the 'Windows Encryption' section. Without these settings, the policy does not trigger BitLocker to start encryption on the device, even if other settings like TPM protector and recovery key escrow are configured. The devices are Azure AD joined and meet hardware requirements, so the missing encryption enablement is the most likely cause.

Exam trap

The trap here is that candidates assume configuring TPM protector and recovery key escrow is sufficient to enable BitLocker, but the 'Enable full disk encryption' setting is a separate mandatory toggle that must be explicitly enabled in the policy.

How to eliminate wrong answers

Option A is wrong because BitLocker policies in Intune apply to both Azure AD joined and hybrid Azure AD joined devices; hybrid join is not a prerequisite for BitLocker policy application. Option B is wrong because the question states that the policy already includes a recovery key escrow to Azure AD, so the failure is not due to a missing escrow location. Option D is wrong because co-management with Configuration Manager is not required for Intune to manage BitLocker on Windows 11 devices; Intune can apply BitLocker policies directly via the MDM channel.

116
MCQmedium

Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?

A.The ComplianceState reflects the last sync; the device may have changed compliance since.
B.The device is compliant but not syncing because it is turned off.
C.The device is no longer enrolled but shows compliant due to a reporting delay.
D.The compliance policy was removed after the last sync.
AnswerA

ComplianceState is a cached value populated at the last device check-in. With no sync for seven days, Intune has not re-evaluated the device, so the stored 'compliant' result may no longer reflect its actual state.

Why this answer

The ComplianceState property in Microsoft Intune reflects the compliance status at the time of the last device check-in. If a device has not synced for 7 days, the stored ComplianceState is stale and may no longer represent the actual compliance posture. The device could have become non-compliant since its last sync due to policy changes, missing updates, or configuration drift, but Intune will not update the state until the next successful sync.

Exam trap

Microsoft Intune often tests the misconception that ComplianceState is a live, real-time indicator, when in fact it is a snapshot from the last successful sync, and candidates may incorrectly assume a compliant state means the device is currently secure.

How to eliminate wrong answers

Option B is wrong because a device that is turned off cannot sync, but the ComplianceState would still show the last known state; the issue is not that the device is compliant but not syncing, but that the state is outdated. Option C is wrong because if the device were no longer enrolled, it would not appear in the managed devices list or would show an 'unenrolled' status, not a compliant state with a 7-day sync gap. Option D is wrong because removing a compliance policy after the last sync would not retroactively change the ComplianceState; the device would remain compliant until the next sync, at which point it would be evaluated against the new policy set.

117
MCQeasy

You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?

A.The user's password has expired.
B.The root CA certificate required to validate the RADIUS server certificate is not installed on the device.
C.The Wi-Fi profile is not assigned to the user's device.
D.The device's Wi-Fi adapter driver is outdated.
AnswerB

SCEP certificate authentication requires the device to trust the RADIUS server's certificate chain. Without the root CA certificate installed via an Intune trusted certificate profile, the device rejects the server during the TLS handshake, so the Wi-Fi connection fails while other networks work.

Why this answer

The device can connect to other Wi-Fi networks but not the corporate one, indicating the issue is specific to the corporate network's authentication requirements. Since the profile uses SCEP certificate authentication, the device must trust the root CA that issued the RADIUS server certificate to validate the server during the EAP-TLS handshake. If the root CA certificate is missing, the client will reject the RADIUS server certificate, causing the connection to fail.

This is the most likely cause because the profile assignment and driver are not specific to this single network failure.

Exam trap

The trap here is that candidates confuse a missing root CA certificate with a missing client certificate, but the symptom of being able to connect to other networks isolates the problem to server-side certificate validation, not client-side enrollment.

How to eliminate wrong answers

Option A is wrong because password expiration is irrelevant to SCEP certificate authentication, which uses machine or user certificates, not passwords. Option C is wrong because the device is enrolled in Intune and has a Wi-Fi profile assigned, so the profile is present; if it were not assigned, the profile would not appear at all, but the user can see and attempt to connect. Option D is wrong because an outdated Wi-Fi adapter driver would affect all Wi-Fi connections, not just the corporate network, and the user can connect to other networks successfully.

118
MCQeasy

You are an administrator for a Microsoft Intune environment. You need to remotely wipe a lost Windows 11 device to prevent access to corporate data. The device is enrolled in Intune and is currently online. Which action should you perform from the Intune admin center?

A.Wipe the device
B.Reset the device
C.Retire the device
D.Delete the device
AnswerA

The Wipe action performs a factory reset on the device, removing all data and settings. This is the correct action for a lost or stolen device because it ensures no corporate or personal data remains accessible. The device must be online to receive the command.

Why this answer

For a lost or stolen device, the Wipe action in Intune initiates a factory reset, erasing all data. This protects corporate information. Retire only removes corporate data, and Delete only removes the Intune record.

Reset is not a valid action. The device must be online to receive the wipe command.

Exam trap

The trap here is confusing Retire with Wipe; Retire leaves personal data intact and is not sufficient for a lost device.

119
MCQeasy

Your organization wants to use Windows Autopilot for user-driven deployment. Users should be able to self-deploy their devices by signing in with their corporate credentials. Which Autopilot deployment mode should you use?

A.Pre-provisioned deployment
B.Hybrid Azure AD join
C.User-driven (Azure AD join)
D.Self-deploying (Azure AD join)
AnswerC

User-driven mode with Microsoft Entra join prompts users to sign in with corporate credentials during OOBE, enrolling the device automatically. This directly satisfies the requirement that users self-deploy their own devices using their organisational accounts.

Why this answer

User-driven (Azure AD join) deployment mode is correct because it allows users to self-deploy their devices by signing in with their corporate credentials during the out-of-box experience (OOBE). This mode joins the device to Azure AD and enrolls it in Microsoft Intune, enabling the user to complete the setup without IT intervention.

Exam trap

The trap here is that candidates often confuse 'self-deploying' with 'user-driven' because both involve Azure AD join, but self-deploying requires no user interaction during OOBE, making it unsuitable for scenarios where users must sign in with corporate credentials.

How to eliminate wrong answers

Option A is wrong because pre-provisioned deployment requires an IT technician to perform a pre-provisioning phase before the user receives the device, which does not align with the requirement for users to self-deploy by signing in with corporate credentials. Option B is wrong because Hybrid Azure AD join is not an Autopilot deployment mode; it is a device identity state that can be achieved through Autopilot but requires additional infrastructure like Active Directory and Azure AD Connect, and it does not describe a specific deployment mode. Option D is wrong because self-deploying (Azure AD join) mode is designed for kiosks or shared devices where no user credentials are required during OOBE; it uses a device certificate for authentication, not user sign-in.

120
MCQeasy

Refer to the exhibit. You manage a Windows 11 device that is marked as compliant and has OS version 10.0.22621.0. You need to upgrade the device to Windows 11 version 23H2. Which Intune feature should you use?

A.Windows quality update profile
B.Windows feature update profile
C.Driver update policy
D.Compliance policy
AnswerB

Windows feature update profiles deploy a specified Windows 11 version, such as 23H2, to targeted devices. This satisfies the requirement to upgrade the compliant Windows 11 device to a newer feature version rather than applying quality updates or driver updates.

Why this answer

A Windows feature update profile is the correct Intune feature to upgrade a Windows 11 device from one version to another (e.g., from 10.0.22621.0 to 23H2). Feature update profiles deploy new OS builds that enable feature-level changes, whereas quality updates deliver only security and cumulative fixes. This profile targets the specific version upgrade required for the device.

Exam trap

The trap here is confusing 'quality updates' (which are cumulative security fixes) with 'feature updates' (which are full OS version upgrades), leading candidates to incorrectly select the quality update profile for a version upgrade.

How to eliminate wrong answers

Option A is wrong because a Windows quality update profile delivers only monthly security and cumulative updates, not full OS version upgrades like 23H2. Option C is wrong because a driver update policy manages only device driver updates, not Windows OS version changes. Option D is wrong because a compliance policy evaluates device settings against rules but does not deploy OS upgrades; it can mark a device non-compliant but cannot perform the upgrade itself.

121
MCQhard

Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?

A.Create a device compliance policy that uses Defender for Endpoint risk level, then use Conditional Access.
B.Configure a device compliance policy with 'Require Defender for Endpoint' setting.
C.Configure a device configuration policy to block access based on risk.
D.Configure an app protection policy to block access based on device risk.
AnswerA

Defender for Endpoint risk level feeds into Intune compliance policy, which marks the device non-compliant at high risk. Conditional Access then evaluates that compliance state and blocks access to corporate resources, satisfying the requirement for automatic blocking based on Defender's risk determination.

Why this answer

It combines a device compliance policy that evaluates the Defender for Endpoint risk level with a Conditional Access policy that blocks access when the device is noncompliant. This is the only supported method to automatically block corporate resource access based on real-time risk assessment from Defender for Endpoint.

Exam trap

The trap here is that candidates often think a device configuration policy or app protection policy can enforce risk-based blocking, but only the combination of a compliance policy with Defender risk evaluation and Conditional Access achieves this in Intune.

How to eliminate wrong answers

Option B is wrong because 'Require Defender for Endpoint' is a compliance setting that only checks if Defender is enabled and active, not the actual risk level. Option C is wrong because device configuration policies manage settings and features, not access control based on risk. Option D is wrong because app protection policies apply to apps on unmanaged devices and do not evaluate device-level risk from Defender for Endpoint.

122
Multi-Selecteasy

Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)

Select 2 answers
A.Use the iOS Microsoft 365 Apps deployment method.
B.Package the Office Deployment Tool as a Win32 app.
C.Upload an MSI file for Microsoft 365 Apps.
D.Use the built-in Microsoft 365 Apps deployment for Windows 10 and later.
E.Add a web link to the Office 365 portal.
AnswersB, D

Wrapping the Office Deployment Tool inside a Win32 app package lets Intune deliver the setup executable and configuration XML, satisfying the requirement to deploy Microsoft 365 Apps through the Win32 app channel with full control over installation arguments.

Why this answer

Option B is correct because packaging the Office Deployment Tool (ODT) as a Win32 app in Intune lets you supply a custom configuration.xml, so setup.exe can download and install Microsoft 365 Apps with your chosen channel, architecture, and apps. Option D is correct because Intune provides a built-in Microsoft 365 Apps (Office) app type for Windows 10 and later, where you select the update channel, version, architecture, and which Office apps to install directly from the console. Option A is wrong because the iOS Microsoft 365 Apps deployment method targets mobile devices, not Windows devices.

Option C is wrong because Microsoft 365 Apps is not distributed as a single MSI for Intune deployment; it uses Click-to-Run via the ODT or the built-in app type. Option E is wrong because a web link to the Office 365 portal only opens a webpage and does not install the apps on the device.

Exam trap

The trap here is that candidates often confuse the built-in Microsoft 365 Apps deployment profile with a simple 'add an app' wizard, leading them to mistakenly think an MSI upload (Option C) is valid for Office, when in fact Intune only supports Click-to-Run installations for Microsoft 365 Apps via ODT-based methods.

123
Multi-Selecthard

Which THREE components are required to deploy a Win32 app via Microsoft Intune?

Select 3 answers
A.Detection rule
B.A .intunewin file
C.PowerShell script for post-installation
D.Dependency on another app
E.Install command
AnswersA, B, E

Detection rules determine whether the app is already installed.

Why this answer

A detection rule is required because Intune needs a method to verify whether the Win32 app is already installed on the device. Without a detection rule, Intune cannot determine if the installation succeeded or if the app needs to be reinstalled. The detection rule can be based on a file, registry key, or custom script, and it is mandatory for any Win32 app deployment.

Exam trap

The trap here is that candidates often confuse optional features like dependencies or post-installation scripts with required components, leading them to select those options instead of the three mandatory ones: detection rule, .intunewin file, and install command.

124
MCQmedium

Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?

A.Create a feature update policy for Windows 10
B.Configure a deferral period of 7 days for quality updates
C.Set a deadline for quality updates to 7 days
D.Pause quality updates for 7 days
AnswerC

Deadlines in Windows Update for Business force installation of quality updates after a set number of days, automatically restarting to complete them. Setting seven days guarantees critical security updates install within the required window rather than relying on user-initiated installation.

Why this answer

To ensure critical security updates are installed within 7 days of release, set a deadline for quality updates to 7 days. A deadline specifies the maximum number of days after the update is offered that the device has to install it. This enforces installation within the desired timeframe.

A deferral period delays when the update is offered, which would not guarantee installation within 7 days.

Exam trap

The trap is confusing a deferral period with a deadline. Deferral delays when an update is offered, while a deadline enforces installation by a certain date. Setting a deferral of 7 days actually means updates are not offered until 7 days after release, making it impossible to install them within that window.

How to eliminate wrong answers

Option A is wrong because feature update policies are used to manage major version upgrades (e.g., Windows 10 22H2), not quality or security updates. Option B is wrong because a deferral period delays the installation of updates; setting a 7-day deferral would postpone the update by 7 days, not ensure it is installed within 7 days of release. Option D is wrong because pausing quality updates stops them from being installed entirely for a specified period, which is the opposite of ensuring timely installation.

125
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that devices receive a specific Windows quality update as soon as possible, bypassing any deferral settings. What should you configure?

A.Modify the update ring to set quality update deferral to 0 days.
B.Expedite the update using the Expedite update feature in Intune.
C.Use a PowerShell script to manually install the update on each device.
D.Create a new update ring with no deferrals and assign it to the devices.
AnswerB

The Expedite update feature in Intune allows you to deploy a specific quality update to devices immediately, bypassing deferral settings and deadlines. This ensures the update is installed as soon as possible. It is designed for urgent updates, such as security patches. You select the update and target devices, and Intune pushes it without waiting for the normal update cycle.

Why this answer

The Expedite update feature in Intune is specifically designed to deploy a specific quality update to devices immediately, bypassing deferrals and deadlines. It ensures the update is installed as soon as possible. Other options either do not target a specific update or do not guarantee immediate installation.

Therefore, expediting the update is the correct action.

Exam trap

The trap here is thinking that setting deferrals to zero will force a specific update immediately; deferrals only control timing relative to release, not immediate installation of a chosen update.

126
Multi-Selectmedium

Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)

Select 2 answers
A.Send a sync command to the device to re-evaluate compliance.
B.Deploy a proactive remediation script to detect and install antivirus.
C.Send a notification to the user to install antivirus via Windows Security.
D.Run a PowerShell script from Intune to install the missing antivirus.
E.Create a Conditional Access policy to block the device until fixed.
AnswersB, D

Proactive remediation scripts run detection and remediation logic directly on the device, satisfying the missing-antivirus compliance state without user interaction. Unlike configuration profiles, which enforce settings, this mechanism actively detects the absent antivirus and installs it, restoring compliance as reported to Microsoft Entra ID.

Why this answer

Option B is correct because proactive remediations in Intune pair a detection script with a remediation script that runs on the device, so you can detect missing antivirus and automatically install it to bring the device back into compliance. Option D is correct because running a PowerShell script from Intune (via a platform script or device script) lets you execute installation commands for the missing antivirus directly on the Windows device. Option A is not a remediation action; a sync only forces the device to check in and re-evaluate policy/compliance, which does not install antivirus.

Option C merely notifies the user and relies on manual action, so it does not remediate the device automatically. Option E is a Conditional Access policy that blocks access rather than fixing the noncompliance, so it is not a remediation action.

Exam trap

The trap here is that candidates often confuse Conditional Access policies (which block access but do not fix the issue) with actual remediation actions, or they assume a sync command will resolve noncompliance when it only re-evaluates the existing state.

127
MCQeasy

You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?

A.Wipe
B.Reset
C.Delete
D.Retire
AnswerA

Wipe performs a full factory reset, removing all data, settings and the enrolment, which is required for a lost corporate-owned device. It satisfies the stem's constraint of remotely erasing the iOS device completely rather than only removing corporate data.

Why this answer

The 'Wipe' action in Microsoft Intune performs a factory reset on a corporate-owned iOS device, removing all data and settings to protect sensitive information. This is the appropriate action for a lost device because it restores the device to its out-of-box state, ensuring no corporate data remains accessible.

Exam trap

The trap here is that candidates often confuse 'Retire' with 'Wipe', mistakenly thinking Retire is sufficient for lost devices, but Retire only removes corporate data and leaves personal data intact, which is a critical distinction for corporate-owned devices.

How to eliminate wrong answers

Option B (Reset) is wrong because 'Reset' is not a specific Intune action for iOS devices; the correct term is 'Wipe', which performs a full factory reset. Option C (Delete) is wrong because 'Delete' removes the device from Intune management without wiping data, leaving the device and its contents intact. Option D (Retire) is wrong because 'Retire' removes only corporate data and management profiles, but leaves personal data on the device, which is insufficient for a lost corporate-owned device where all data must be erased.

128
Multi-Selectmedium

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a compliance policy that marks devices as noncompliant if they do not have a specific minimum OS version and if they have not checked in with Intune within the last 7 days. Which TWO settings should you configure in the compliance policy? (Choose two.)

Select 2 answers
A.Last check-in time
B.Encryption of data storage on device
C.Device health attestation
D.Minimum OS version
E.Antivirus and antispyware status
AnswersA, D

The Last check-in time setting marks devices as noncompliant if they have not communicated with Intune within a specified number of days. Configuring this to 7 days ensures devices that have not checked in recently are flagged. This directly meets the requirement for check-in recency.

Why this answer

The compliance policy settings for Minimum OS version and Last check-in time directly enforce the two requirements. Minimum OS version ensures devices meet the specified build, while Last check-in time flags devices that have not communicated with Intune within 7 days. Together, they define the compliance state as required.

Exam trap

The trap here is selecting security-related settings like encryption or antivirus, which are important but not the ones needed for OS version and check-in recency.

129
MCQhard

Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?

A.An Intune role-based access control (RBAC) role for Sales users.
B.A device configuration profile assigned to Sales users.
C.A Conditional Access policy that requires device compliance.
D.Enrollment restrictions that allow only users in the Sales group.
AnswerD

Enrollment restrictions in Intune can target specific Microsoft Entra ID groups, so scoping the restriction to the Sales group blocks all other users from enrolling. This directly satisfies the constraint that only Sales department users may enrol devices, without affecting existing enrolled devices.

Why this answer

Enrollment restrictions in Intune let you control which users or groups are allowed to enroll devices, so restricting enrollment to the Sales group directly satisfies the requirement. This is the purpose-built control for limiting enrollment by user or group, platform, or device type.

Exam trap

MD-102 often tests the distinction between enrollment restrictions (who/what can enroll) and Conditional Access or compliance policies (what enrolled devices can access), so candidates mistakenly pick a CA policy for an enrollment-scoping requirement.

How to eliminate wrong answers

Option A is wrong because Intune RBAC roles control what administrators can do in the console, not which end users can enroll devices. Option B is wrong because a device configuration profile applies settings to already-enrolled devices and does not gate enrollment. Option C is wrong because a Conditional Access policy requiring compliance controls access to resources after enrollment, not who is permitted to enroll in the first place.

130
MCQhard

You administer Microsoft Intune for a company with Windows 11 devices joined to Microsoft Entra ID. A security requirement states that if a device is found noncompliant, it must lose access to Microsoft 365 services within 15 minutes, and the device must be marked noncompliant automatically when a required antivirus signature is out of date. You need to implement this with the least administrative effort. What should you do?

A.Create a device configuration profile that disables access to Microsoft 365 when antivirus signatures are stale, and assign it to all users.
B.Create a compliance policy with an antivirus requirement and a device health attestation setting, then assign it to all users without a Conditional Access policy.
C.Create a compliance policy with an antivirus requirement, set the compliance status validity period to 15 minutes, and create a Conditional Access policy that requires compliant devices for Microsoft 365.
D.Create a Conditional Access policy that requires multifactor authentication for all users and set a sign-in frequency of 15 minutes.
AnswerC

A compliance policy enforces the antivirus signature requirement and marks devices noncompliant when it fails. Setting the compliance status validity period to 15 minutes ensures Microsoft Entra ID reevaluates compliance quickly, and a Conditional Access policy requiring compliant devices blocks access to Microsoft 365 when the device is noncompliant. This combination meets the timing and automatic marking requirements with minimal overhead.

Why this answer

Compliance policies in Intune define the conditions a device must meet, and Conditional Access policies enforce those conditions for access to cloud apps. Setting the compliance status validity period to 15 minutes ensures Microsoft Entra ID quickly reflects a noncompliant state after antivirus signatures become stale. Together, these configurations automatically mark the device noncompliant and block Microsoft 365 access within the required time frame.

Exam trap

The trap here is treating a device configuration profile or a compliance policy alone as sufficient to revoke access, when Conditional Access is required to enforce compliance for cloud services.

131
Multi-Selecteasy

Which TWO are valid methods to enroll Windows devices in Microsoft Intune?

Select 2 answers
A.Apple Business Manager
B.Manual enrollment using work or school account
C.Windows Autopilot
D.Android Enterprise
E.Azure AD Join
AnswersB, C

Manual work-or-school-account enrolment joins the device to Microsoft Entra ID and registers it with Intune in one user-driven step, satisfying the stem's requirement for a valid Windows enrolment method without requiring Autopilot or bulk provisioning infrastructure.

Why this answer

Option B (Manual enrollment using work or school account) is correct because on a Windows 10/11 device a user can go to Settings > Accounts > Access work or school > Connect and sign in with their Azure AD work or school account, which triggers automatic MDM enrollment into Intune via the built-in Windows MDM client. Option C (Windows Autopilot) is correct because Autopilot uses a device hash registered in Intune so that during OOBE the device is automatically Azure AD joined (or Hybrid Azure AD joined) and enrolled in Intune without manual user configuration. Option A (Apple Business Manager) is wrong for this scenario because ABM is Apple's automated device enrollment service for iOS/iPadOS and macOS devices, not Windows.

Option D (Android Enterprise) is wrong because it is Google's management framework for Android devices and has no role in enrolling Windows. Option E (Azure AD Join) is not a standalone enrollment method; Azure AD Join is the identity state that must be combined with an MDM enrollment mechanism (such as manual work/school account connection or Autopilot) to actually register the device in Intune.

Exam trap

The trap here is that candidates confuse Azure AD Join (an identity state) with an enrollment method, but Azure AD Join alone does not enroll the device into Intune unless MDM auto-enrollment is configured via GPO or the user explicitly signs in with a work or school account.

132
MCQmedium

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?

A.Add the app as a Managed Google Play app.
B.Deploy the app as a web link to the APK file.
C.Add the app as a line-of-business (LOB) app and upload the APK file.
D.Use the iOS LOB app deployment method.
AnswerC

Uploading the APK as a line-of-business app bypasses Google Play entirely, satisfying the requirement for an app unavailable in the store. Intune deploys the signed APK directly to enrolled Android Enterprise devices, supporting both fully managed and work profile enrolment types without store publishing.

Why this answer

Line-of-business (LOB) apps in Intune allow administrators to upload and deploy custom APK files to Android Enterprise devices. Option A is incorrect because Managed Google Play apps must be published to the Play Store. Option B is incorrect because deploying a web link is not an app deployment method; it only provides a link to download the APK manually.

Option D is incorrect because iOS LOB app deployment is specific to iOS devices and is not applicable to Android.

133
MCQmedium

You manage 500 Windows 11 devices enrolled in Microsoft Intune. A security policy requires that a specific registry value be set on all devices, and you must be able to report which devices have the value applied and remediate any that do not. You need to implement this with the least administrative effort. What should you create?

A.A PowerShell script deployed as a platform script assigned to all devices
B.A configuration profile with a custom OMA-URI setting
C.A proactive remediation script in Intune
D.A custom compliance policy with a discovery script
AnswerC

Proactive remediation scripts in Intune combine a detection script that identifies non-compliant devices and a remediation script that corrects them, and the results are reported in the Intune admin center. This matches the requirement to report and remediate registry values on Windows 11 devices with minimal effort.

Why this answer

Proactive remediation scripts are designed to detect and automatically fix issues on Windows devices, and they surface per-device results in Intune. A platform script can set a value but cannot detect or remediate drift, and a custom compliance policy reports but does not remediate. A custom OMA-URI profile can set the value but provides no detection or remediation reporting.

Exam trap

The trap here is confusing a configuration profile that sets a value with a proactive remediation that detects and fixes a value.

134
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A critical line-of-business app must be installed on all devices in the Finance department, but the app's installer requires administrator privileges and the users do not have local admin rights. You need to deploy the app silently without user interaction and ensure it installs even if no user is signed in. What should you do?

A.Deploy the app as a Windows app (Win32) with install context set to System and detection rules configured.
B.Deploy the app as a Windows app (Win32) with install context set to User.
C.Deploy the app as a Microsoft Store app (new) from Intune.
D.Deploy the app as a Microsoft 365 Apps (Windows 10 and later) app from Intune.
AnswerA

Win32 app deployment in Intune supports specifying the install context as System, which runs the installer with local system privileges. This satisfies the admin-rights requirement and allows installation even when no user is signed in. Detection rules ensure Intune correctly reports installation status.

Why this answer

The app requires administrator privileges and must install silently regardless of user sign-in. Only a Win32 app deployment with the install context set to System runs the installer with local system rights and supports installation without a signed-in user. Detection rules are also required to verify successful installation.

Exam trap

The trap here is assuming any Win32 app deployment automatically runs with elevated privileges; the install context must be explicitly set to System.

135
MCQmedium

You administer Microsoft Intune for a company with 500 Windows 11 devices. The security team requires that when a device is reported lost or stolen, you can remotely erase corporate data without affecting the user's personal files on devices enrolled as personally owned. Which action should you perform in the Intune admin center?

A.Run an Autopilot Reset on the device.
B.Run a Selective wipe (Retire) on the device.
C.Run a Fresh Start on the device.
D.Run a Full wipe on the device.
AnswerB

Retire (selective wipe) removes only company data, management profiles, and enrollment, leaving personal files intact. It is designed for personally owned devices and is the correct action when a user reports a lost personal device. Running Retire removes the management relationship and corporate data such as email, apps, and policies while preserving the user's personal content.

Why this answer

The Retire action performs a selective wipe that removes only organizational data and the management profile from a device. On personally owned devices enrolled in Intune, this preserves the user's personal files while removing corporate email, apps, and policies. Full wipe, Fresh Start, and Autopilot Reset all remove user data and are intended for corporate-owned devices, so they do not meet the requirement.

Exam trap

The trap here is assuming that any remote device action will remove only corporate data, when in fact only Retire performs a selective wipe on personally owned devices.

136
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Users report that when they attempt to enroll a personal device, enrollment fails with error 80180014. You need to ensure that only corporate-owned devices can enroll. What should you configure?

A.Device compliance policy requiring BitLocker and Secure Boot.
B.Conditional Access policy requiring compliant devices for all cloud apps.
C.Enrollment restrictions in Intune with a device platform restriction blocking personally owned Windows devices.
D.Windows Autopilot deployment profile assigned to all users.
AnswerC

Enrollment restrictions in Intune allow you to control which devices can enroll by platform and ownership type. By configuring a Windows platform restriction that blocks personally owned devices, you prevent personal Windows 11 devices from enrolling while allowing corporate-owned devices. Error 80180014 typically indicates that enrollment is blocked by such a restriction, so this setting directly addresses the requirement.

Why this answer

Enrollment restrictions in Intune are designed to control which devices can enroll based on platform, version, and ownership. By blocking personally owned Windows devices, you ensure that only corporate-owned devices can enroll. This directly resolves the error and enforces the requirement.

Other options control post-enrollment compliance or access, not the enrollment process itself.

Exam trap

The trap here is confusing enrollment restrictions with compliance policies; enrollment restrictions control whether a device can enroll, while compliance policies evaluate devices after enrollment.

137
Multi-Selecthard

Which THREE conditions can be used to create a dynamic device group in Microsoft Entra ID for Intune management? (Choose three.)

Select 3 answers
A.Enrollment profile name (e.g., 'Autopilot Profile')
B.Last sign-in time of the user
C.Installed application version
D.Device model (e.g., 'Surface Pro 7')
E.Operating system version (e.g., 'Windows 11 22H2')
AnswersA, D, E

Enrollment profile name is a valid device rule for dynamic groups, letting you target devices provisioned with a specific Autopilot profile. This satisfies the stem's requirement for a supported membership condition, since Autopilot-assigned profiles are written to the device object's attribute.

Why this answer

Option A is correct because dynamic device groups in Microsoft Entra ID support the device property enrollmentProfileName, which matches the Autopilot enrollment profile name such as 'Autopilot Profile', allowing devices to be grouped by how they were provisioned. Option D is correct because the deviceModel attribute is a supported device property that can be used in a dynamic membership rule, so a rule like device.deviceModel -eq "Surface Pro 7" will correctly populate the group. Option E is correct because operatingSystemVersion is also a valid device property for dynamic device membership rules, enabling grouping by OS build such as Windows 11 22H2.

Option B is not valid because last sign-in time is a user attribute (signInActivity), not a device property available for dynamic device group rules. Option C is not valid because installed application versions are not exposed as Microsoft Entra ID device attributes; app inventory data lives in Intune and cannot be used directly in an Entra dynamic device membership rule.

Exam trap

The trap here is that candidates confuse dynamic device group rules (which only support device attributes) with dynamic user group rules or compliance policies, leading them to select user-based or application-based conditions like 'Last sign-in time' or 'Installed application version'.

138
MCQmedium

You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?

A.Create a device compliance policy with the 'Device is inactive for a period of time' setting configured to 30 days.
B.Configure a device configuration profile with a custom OMA-URI that sets an inactivity timeout.
C.Create a conditional access policy that blocks access for devices not checked in for 30 days.
D.Use an Intune PowerShell script to query devices and mark them noncompliant if they have not checked in for 30 days.
AnswerA

The compliance policy setting 'Mark devices with no compliance policy assigned as' and specifically the 'Device is inactive' rule under Actions for noncompliance allows you to specify a number of days of inactivity. When a device does not check in within that period, Intune marks it noncompliant. This directly satisfies the requirement with minimal effort because it is a built-in compliance rule, not a custom script or conditional access policy.

Why this answer

The built-in compliance policy setting for device inactivity allows you to specify a number of days after which a device with no check-in is marked noncompliant. This is a native Intune feature that requires only configuring the compliance policy, with no custom scripting or additional services. Conditional access can then act on the noncompliant state, but the marking itself must come from the compliance policy.

Therefore, the compliance policy with the inactivity rule is the correct and least-effort solution.

Exam trap

The trap here is assuming that conditional access can directly evaluate the last check-in time of a device, when in fact compliance policies are responsible for marking devices noncompliant based on inactivity.

139
MCQhard

You manage a hybrid environment with Microsoft Intune and Microsoft Configuration Manager. You need to ensure that devices co-managed for Windows Update policies use Intune as the authoritative source for update deployments, while Configuration Manager continues to manage software updates. Which workload slider should you move to Intune?

A.Endpoint Protection
B.Resource access policies
C.Compliance policies
D.Windows Update policies
AnswerD

In co-management, the Windows Update policies workload controls which service manages Windows Update for Business policies. Moving this slider to Intune makes Intune the authoritative source for update rings and deployment schedules, while Configuration Manager can still handle software updates if that workload remains with Configuration Manager. This directly satisfies the requirement.

Why this answer

The Windows Update policies workload in co-management determines whether Intune or Configuration Manager manages Windows Update for Business settings. Moving this slider to Intune ensures Intune controls update rings and deployment, while Configuration Manager can still manage software updates if that workload remains on-premises.

Exam trap

The trap here is assuming that moving any workload to Intune automatically includes update management, or confusing software updates with Windows Update policies.

140
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?

A.Create an app protection policy with a 15-minute recheck interval.
B.Set the compliance policy action for noncompliance to 'Retire the device' after 15 minutes.
C.Configure a device restriction policy with a 15-minute grace period.
D.Set the 'Mark device noncompliant' schedule to 15 minutes.
AnswerD

The 'Mark device noncompliant' schedule in the compliance policy defines how long after a device fails a check before Intune marks it noncompliant. Setting it to 15 minutes ensures the conditional access policy can block access within that window, without wiping the device. This is the direct control for the timing requirement in this scenario.

Why this answer

The 'Mark device noncompliant' schedule is the compliance policy setting that controls how quickly a failed compliance check transitions the device to a noncompliant state. Once noncompliant, the conditional access policy evaluates the device state and blocks access to Microsoft 365 services. The other options either apply to different policy types or perform destructive actions that violate the no-wipe requirement.

Exam trap

The trap here is confusing device restriction or app protection policies with the compliance policy setting that controls the timing of the noncompliant state.

141
MCQmedium

A company uses Microsoft Intune to manage Windows 11 devices. Users report that the Company Portal app is not showing required applications. You verify that the devices show as 'Compliant' in Microsoft Intune. Which configuration should you check first?

A.Check the Microsoft Entra ID (Azure AD) configuration for the device.
B.Check the Windows Update for Business ring assignments.
C.Check the device compliance policy settings.
D.Check the application assignments in Intune.
AnswerD

Checking application assignments in Intune directly addresses why required apps are absent from Company Portal. Required apps appear only when assigned to the user or device group; unassigned or misassigned apps remain invisible regardless of compliance status. Since devices already report Compliant, assignment scope is the first constraint to verify.

Why this answer

The most common reason required applications are not visible in Company Portal is that the applications have not been assigned to the user or device group. Even if a device is compliant, Intune will only display applications that are assigned with an 'Available' intent to the user or device. Checking application assignments first directly addresses the symptom without assuming other configurations are misconfigured.

Exam trap

The trap here is that candidates often assume compliance policy issues cause application visibility problems, but Intune separates compliance evaluation from application assignment; a compliant device can still miss apps if the assignments are misconfigured.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (Azure AD) configuration primarily controls authentication, device registration, and conditional access, not the visibility of assigned applications in Company Portal. Option B is wrong because Windows Update for Business ring assignments control update deferral and delivery optimization, not application deployment or visibility. Option C is wrong because the device is already marked as 'Compliant', so compliance policy settings are not the cause; compliance policies affect conditional access and device health, not the display of assigned applications.

142
MCQmedium

Refer to the exhibit. You have applied this compliance policy to a Windows 10 device running build 10.0.19044. The device meets all requirements except that the firewall is disabled. What will be the compliance status of the device?

A.Compliant, because the OS version is within the allowed range.
B.Non-compliant, because the firewall is disabled.
C.Compliant, because the policy includes a grace period for firewall.
D.Non-compliant, because the OS version is not within the allowed range.
AnswerB

Compliance policies evaluate each configured setting independently; a disabled firewall breaches the firewall requirement, so the device reports as non-compliant regardless of other satisfied conditions. Intune marks the device non-compliant until the firewall is re-enabled and the device checks in again.

Why this answer

The compliance policy requires the firewall to be enabled. Since the device has a disabled firewall, it fails that specific requirement, making it non-compliant regardless of meeting other conditions like OS version. In Microsoft Intune, compliance policies evaluate each setting independently; a single non-compliant setting results in an overall non-compliant status.

Exam trap

The trap here is that candidates assume meeting the OS version requirement alone makes the device compliant, ignoring that compliance policies enforce all configured settings independently, and a disabled firewall is a distinct failure condition.

How to eliminate wrong answers

Option A is wrong because meeting the OS version requirement does not override a failed firewall requirement; compliance is evaluated per setting, and any single non-compliant setting makes the device non-compliant. Option C is wrong because the exhibit shows no grace period configured for the firewall setting; grace periods are optional and must be explicitly set per setting in the policy. Option D is wrong because the OS version (10.0.19044) is within the allowed range specified in the policy, so this is not a cause of non-compliance.

143
MCQmedium

Refer to the exhibit. A Microsoft Graph PowerShell cmdlet retrieves devices. What is the purpose of this query?

A.To find Windows devices that are compliant
B.To find Windows devices with an operating system version earlier than 2025
C.To find Windows devices enrolled before January 1, 2025
D.To find Windows devices that have not synced since before January 1, 2025
AnswerD

The query filters the device collection by operating system and last sync timestamp, returning only Windows devices whose approximateLastSyncDateTime predates 1 January 2025. This identifies stale Windows devices that have not checked in since that date, matching the stated purpose.

Why this answer

The query uses Get-MgDevice with a filter on approximateLastSignInDateTime being less than 2025-01-01T00:00:00Z. This filter retrieves devices whose last approximate sign-in occurred before January 1, 2025, indicating they have not synced since that date. The -and operator with deviceId -ne $null ensures only actual devices (not null device IDs) are returned.

Option D correctly identifies this as finding devices that have not synced since before January 1, 2025.

Exam trap

The trap here is that candidates confuse `approximateLastSignInDateTime` with `enrolledDateTime`, leading them to incorrectly select Option C, which refers to enrollment date instead of last sync date.

How to eliminate wrong answers

Option A is wrong because the query does not include any filter on `complianceState` or `isCompliant`; it only filters on `approximateLastSignInDateTime` and `deviceId`. Option B is wrong because the query does not reference `operatingSystemVersion` or any version-related property; it filters on a date, not an OS version. Option C is wrong because the filter uses `approximateLastSignInDateTime`, which tracks the last sign-in or sync time, not the enrollment date (`enrolledDateTime`); the query would need to filter on `enrolledDateTime` to find devices enrolled before a specific date.

144
MCQmedium

A company uses Microsoft Intune to manage macOS devices. They need to deploy a custom plist configuration file to set security settings. Which policy type should they use?

A.Device configuration profile (custom)
B.App protection policy
C.Device compliance policy
D.Device cleanup rule
AnswerA

A custom device configuration profile accepts a plist payload for macOS, letting you deploy arbitrary security settings that built-in templates do not expose. This satisfies the stem's requirement to deliver a custom plist file through Intune.

Why this answer

A custom device configuration profile in Microsoft Intune allows administrators to deploy plist files to macOS devices, enabling the configuration of settings not covered by built-in templates. This is the correct policy type for deploying a custom plist file because it directly supports uploading and assigning property list files to enforce specific security configurations.

Exam trap

The trap here is that candidates may confuse 'custom configuration profiles' with 'compliance policies' because both involve security settings, but compliance policies only evaluate and report, not deploy configuration files.

How to eliminate wrong answers

Option B is wrong because App protection policies are designed to manage how apps access and handle corporate data on mobile devices, not to deploy system-level configuration files like plists. Option C is wrong because Device compliance policies evaluate whether devices meet security requirements (e.g., encryption, OS version) and trigger conditional access, but they do not deploy configuration files. Option D is wrong because Device cleanup rules automatically remove inactive devices from Intune after a specified period; they have no role in deploying configuration settings.

145
MCQhard

Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?

A.The deviceThreatProtectionEnabled setting should be false.
B.The password minimum length is too short.
C.The storageRequireEncryption setting conflicts with BitLocker.
D.The devices are not enrolled in Microsoft Defender for Endpoint.
AnswerD

Compliance policies referencing Defender for Endpoint signals require the device to be onboarded to Microsoft Defender for Endpoint. Without that enrolment, the compliance engine cannot evaluate the threat-related settings, producing noncompliant results despite BitLocker and password settings being satisfied.

Why this answer

The deviceThreatProtectionEnabled setting requires devices to be enrolled in Microsoft Defender for Endpoint to report threat levels. Without this enrollment, the compliance policy cannot evaluate the threat status, causing devices to be marked as noncompliant even if BitLocker and password policies are satisfied.

Exam trap

The trap here is that candidates often assume BitLocker and storageRequireEncryption are redundant or conflicting, but the real issue is the dependency on Microsoft Defender for Endpoint enrollment for threat-based compliance policies.

How to eliminate wrong answers

Option A is wrong because setting deviceThreatProtectionEnabled to false would disable the threat protection requirement, which would not resolve the noncompliance caused by missing Defender for Endpoint enrollment; the setting itself is valid when the service is configured. Option B is wrong because the password minimum length being too short would cause noncompliance only if the actual device password is shorter than the policy requirement, but the question states devices meet password requirements, so this is not the issue. Option C is wrong because storageRequireEncryption and BitLocker do not conflict; storageRequireEncryption enforces device encryption, which BitLocker provides, so both settings work together to ensure compliance.

146
Multi-Selectmedium

You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a Windows Update ring to defer quality updates by 7 days and feature updates by 60 days. Which two settings should you configure in the update ring? (Choose two.)

Select 2 answers
A.Quality update deferral period (days)
B.Update/quality update deadline (days)
C.Feature update deferral period (days)
D.Automatic update behavior - Auto install at maintenance time
E.Windows Update for Business configuration - Servicing channel
AnswersA, C

The 'Quality update deferral period' setting in a Windows Update ring allows you to delay the installation of monthly security and quality updates by a specified number of days. Setting it to 7 days meets the requirement to defer quality updates. This setting is found under Update settings in the update ring configuration.

Why this answer

In a Windows Update ring, you can configure separate deferral periods for quality updates and feature updates. Setting the quality update deferral to 7 days and the feature update deferral to 60 days ensures that monthly security updates are delayed by a week and feature updates by two months, exactly matching the requirements.

Exam trap

The trap here is confusing deferral periods with deadlines or servicing channels, which control enforcement or update type rather than the delay in days.

147
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?

A.Confirm that the device has a compatible TPM chip and that it is enabled.
B.Verify that Secure Boot is disabled in BIOS.
C.Ensure devices are marked as compliant in Intune.
D.Check if the BitLocker policy is using the Settings catalog.
AnswerA

BitLocker requires TPM 1.2 or later with the chip enabled and ownership taken; without it, encryption silently fails despite an assigned policy. Confirming a compatible, enabled TPM satisfies the stem's constraint by ruling out the most common hardware prerequisite blocking encryption.

Why this answer

BitLocker requires a compatible TPM (Trusted Platform Module) chip, version 1.2 or 2.0, that is enabled and activated in the BIOS/UEFI. If the TPM is missing, disabled, or not initialized, the BitLocker policy will apply but encryption will fail silently or remain pending. This is the most common root cause for devices not encrypting despite policy assignment.

Exam trap

The trap here is that candidates often assume the issue is policy-related (e.g., compliance or configuration source) and overlook the fundamental hardware prerequisite of a functional TPM, which is the first thing to verify in any BitLocker troubleshooting workflow.

How to eliminate wrong answers

Option B is wrong because Secure Boot should be enabled, not disabled, for BitLocker to function properly; disabling Secure Boot can actually prevent encryption or cause recovery mode. Option C is wrong because device compliance status in Intune does not control BitLocker encryption enforcement; the policy applies regardless of compliance, though compliance can be used for conditional access. Option D is wrong because the Settings catalog is simply a method to configure policy settings; whether the policy uses it or not has no bearing on encryption failure — the issue is a hardware prerequisite, not the policy configuration source.

148
MCQeasy

You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to collect a list of installed applications from these devices and view the data in the Intune admin center. What should you configure?

A.Create a custom compliance policy that queries the registry for installed applications and marks devices compliant.
B.Enable device inventory collection in the Intune data collection policy for the device group.
C.Review the Discovered apps report under Apps in the Intune admin center after devices check in.
D.Assign a device configuration profile that enables the Inventory Collector CSP.
AnswerC

Intune automatically collects installed application data from enrolled Windows devices and surfaces it in the Discovered apps report under Apps. After devices check in, the report lists detected applications along with device counts. No additional policy is required for Windows devices, making this the correct way to view installed applications in the admin center.

Why this answer

Intune automatically collects installed application inventory from enrolled Windows devices and displays it in the Discovered apps report under Apps in the Intune admin center. This report requires no extra policy configuration for Windows devices, so simply reviewing it after devices check in provides the required list of installed applications.

Exam trap

The trap here is assuming that a special policy or CSP must be enabled to collect installed application inventory, when Intune already collects this data automatically for enrolled Windows devices.

149
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, users receive a notification email with instructions to remediate the issue. The email must be sent only to the primary user of the device. What should you configure?

A.An Endpoint security policy with the 'Noncompliance email' setting configured.
B.A conditional access policy that blocks access and sends an email to the user.
C.A device configuration profile with the 'Compliance notification' setting enabled.
D.A compliance policy with the 'Send email to users' action enabled and the 'Send email to primary user' option selected.
AnswerD

Intune compliance policies include an action to send email notifications to users when a device becomes noncompliant. By default, it sends to the primary user if configured. Enabling this action and selecting the primary user option ensures the email goes only to the device's primary user, meeting the requirement.

Why this answer

Compliance policies in Intune include actions that can send email notifications to users when a device is noncompliant. Configuring the action to send to the primary user ensures the email reaches the correct recipient with remediation instructions, directly fulfilling the requirement.

Exam trap

The trap here is confusing compliance policy actions with device configuration profiles or conditional access, which do not provide user email notifications for noncompliance.

150
Multi-Selectmedium

You are troubleshooting an Intune-managed Windows 10 device that is not receiving a required application. Which THREE steps should you take to diagnose the issue? (Choose three.)

Select 3 answers
A.Ensure the device has network connectivity
B.Review the app requirement rules (e.g., OS version)
C.Check the app assignment status in the Intune console
D.Verify the device is compliant with compliance policies
E.Perform a factory reset on the device
AnswersA, B, C

Without network connectivity the device cannot reach Intune or the content delivery service to download the app. Verifying connectivity confirms the device can actually receive policy and app payloads, ruling out a fundamental delivery blocker first.

Why this answer

Option A is correct because an Intune-managed Windows 10 device must have network connectivity to reach the Intune service (and the Microsoft Store/CDN or Win32 app content source), otherwise it cannot download policies or the required application. Option B is correct because Intune app requirement rules (such as OS version, architecture, or minimum OS) are evaluated before delivery; if the device fails a rule, the app will not be offered or installed. Option C is correct because checking the app assignment status in the Intune console shows whether the app is targeted to the user/device group and whether the assignment is required, available, or uninstall, which directly explains why the app is not being received.

Option D is not correct because compliance policies govern conditional access and device health, not app delivery; a noncompliant device can still receive required apps. Option E is not correct because a factory reset is a drastic remediation step, not a diagnostic step, and it would not identify the root cause.

Exam trap

The trap here is confusing compliance policies with app delivery prerequisites; candidates often assume a non-compliant device cannot receive any apps, but Intune separates compliance from app assignment unless conditional access is explicitly configured.

← PreviousPage 2 of 3 · 183 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage and maintain devices questions.