Courseiva

CCNA Manage applications Questions

75 of 104 questions · Page 1/2 · Manage applications · Answers revealed

1
MCQeasy

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a VPP (Volume Purchase Program) app that is already purchased and assigned to your tenant. What is the minimum configuration required to make the app available to users?

A.Configure a device enrollment restriction to allow the app.
B.Sync the VPP token, then add the app from the store and assign it.
C.Distribute the app via the Company Portal without any additional configuration.
D.Upload the app IPA file to Intune, then create an app configuration policy.
AnswerB

The VPP token must be synced so Microsoft Entra ID and Intune can retrieve the purchased licences, then the app is added from the store and assigned to users. This satisfies the minimum configuration needed to make the already-purchased app available.

Why this answer

For VPP apps in Intune, the minimum requirement is to sync the VPP token so Intune can communicate with Apple's Volume Purchase Program, then add the app from the store and assign it to users or groups. Once the token is synced and the app is assigned, Intune handles license distribution automatically. No IPA upload or configuration policy is required for basic availability.

Exam trap

MD-102 often tests the distinction between VPP apps and LOB apps — candidates incorrectly select IPA upload because they conflate the two deployment methods.

How to eliminate wrong answers

Option A is wrong because device enrollment restrictions control which devices can enroll, not which apps are available — they have no bearing on VPP app deployment. Option C is wrong because the Company Portal alone does not make VPP apps available; the token must be synced and the app assigned first. Option D is wrong because uploading an IPA file is for line-of-business (LOB) apps, not VPP apps, and an app configuration policy is optional for delivering app settings, not a prerequisite for availability.

2
MCQeasy

You are configuring an app protection policy in Microsoft Intune for iOS/iPadOS devices. Which setting can you enforce to prevent users from copying data from a managed app and pasting it into an unmanaged app?

A.Restrict cut, copy, and paste between other apps
B.Require a PIN for access
C.Prevent iTunes and iCloud backups
D.Block managed apps from running on jailbroken devices
AnswerA

Restricting cut, copy and paste between other apps blocks clipboard transfer from managed to unmanaged apps on iOS/iPadOS, directly preventing the data-leak scenario. It is an app protection policy setting applied at the app layer.

Why this answer

The 'Restrict cut, copy, and paste between other apps' setting in an Intune app protection policy (APP) for iOS/iPadOS directly controls data transfer between managed and unmanaged apps. When set to 'Blocked' or 'Policy Managed with Paste In', it prevents users from copying data from a managed app and pasting it into an unmanaged app, enforcing data leakage prevention at the OS clipboard level via the Intune MAM SDK.

Exam trap

The trap here is that candidates often confuse device-level restrictions (like jailbreak detection or backup blocking) with app-level data transfer controls, assuming any security setting prevents copy/paste, when only the specific 'Restrict cut, copy, and paste' setting governs clipboard behavior between managed and unmanaged apps.

How to eliminate wrong answers

Option B is wrong because 'Require a PIN for access' controls authentication to the managed app, not data transfer operations like copy/paste; it prevents unauthorized access but does not restrict clipboard sharing. Option C is wrong because 'Prevent iTunes and iCloud backups' protects data at rest by blocking backup to personal cloud or local storage, but it does not address real-time clipboard data movement between apps. Option D is wrong because 'Block managed apps from running on jailbroken devices' is a device-level compliance check that prevents app launch on compromised devices, but it does not restrict copy/paste behavior on compliant devices.

3
MCQmedium

You manage Windows 11 devices with Microsoft Intune. Users run a line-of-business desktop app that writes configuration data to HKEY_CURRENT_USER. After you deploy the app as a Win32 app with an install context of System, users report that their settings are not saved between sessions. You need to ensure that each user's settings persist in their own profile while the app still installs without user interaction. What should you do?

A.Wrap the app in a Win32 app package that includes a PowerShell script to copy HKCU settings to HKLM at logoff.
B.Add a requirement rule that targets only Windows 11 devices and redeploy the app.
C.Configure the app's detection rule to check for the registry key under HKEY_CURRENT_USER.
D.Change the app's install context to User and redeploy the app.
AnswerD

Setting the install context to User makes the app run under each signed-in user's context, so HKEY_CURRENT_USER writes go to that user's own hive and persist between sessions. The app is already packaged as a Win32 app, so only the context needs to change. Installing in System context runs the app under the local system account, whose HKCU hive is not the user's profile.

Why this answer

Win32 apps deployed by Intune can run in either User or System context. System context installs with elevated rights and writes to the system account's profile, so per-user HKCU data is not preserved for the signed-in user. Switching the install context to User makes the app run per user, allowing HKCU writes to land in each user's profile and persist.

Exam trap

The trap here is assuming that changing detection rules or requirement rules changes the runtime context of a Win32 app, when only the install context setting controls whether the app runs as the user or as the system account.

4
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. The company has a line-of-business iOS app that is not available in the App Store. You need to deploy this app to a group of iOS users. The app must be installed automatically without user interaction. What should you do first?

A.Upload the app package (.ipa file) to Intune as a line-of-business app.
B.Add the app to Microsoft Store for Business and sync it with Intune.
C.Configure a device configuration profile to install the app.
D.Create an app protection policy for the app.
AnswerA

Uploading the .ipa file as a line-of-business app is the required first step to make the app available in Intune. Once uploaded, you can assign it to groups and configure installation intent as required for automatic installation. This directly addresses the need to deploy a custom iOS app.

Why this answer

To deploy a custom iOS app, you must first upload the app package (.ipa file) to Intune as a line-of-business app. This makes the app available for assignment. After uploading, you can assign it to groups and set the installation intent to required for automatic installation.

The other options do not provide a deployment method for custom apps.

Exam trap

The trap here is confusing app deployment with app protection or configuration, which do not install apps.

5
Multi-Selectmedium

You are configuring an app protection policy for iOS devices to protect corporate data in Microsoft Outlook. Which TWO settings prevent users from copying corporate data to personal apps?

Select 2 answers
A.Allow app to transfer data to other apps
B.Save copies of work data
C.Block screen capture and screen recording
D.Restrict cut, copy, and paste between apps
E.Encrypt app data
AnswersA, D

Setting app transfer to none blocks Outlook from sending corporate data to unmanaged personal apps, satisfying the requirement to prevent copying outside the protected boundary. Combined with cut, copy and paste restrictions, it enforces data containment at the app layer rather than relying on device management.

Why this answer

Option A, 'Allow app to transfer data to other apps,' is correct because setting it to 'None' or 'Policy managed apps' restricts Outlook from sharing or transferring corporate data to unmanaged personal apps, directly preventing data leakage to personal apps. Option D, 'Restrict cut, copy, and paste between apps,' is correct because configuring it to 'Policy managed apps' or 'Policy managed apps with paste in' prevents users from copying corporate content from Outlook and pasting it into personal apps. Option B, 'Save copies of work data,' controls whether users can save copies of corporate data to personal storage locations but does not specifically govern app-to-app copying.

Option C, 'Block screen capture and screen recording,' prevents screenshots of corporate data but does not stop copying data into personal apps. Option E, 'Encrypt app data,' protects data at rest on the device but does not prevent users from copying corporate data to personal apps.

Exam trap

The trap here is that candidates often confuse 'Block screen capture and screen recording' with data loss prevention, but it only prevents visual capture, not clipboard or app-to-app data transfer, which are the actual vectors for copying corporate data to personal apps.

6
Drag & Dropmedium

Order the steps to deploy a Windows 10 virtual desktop in Azure using Windows 365.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Deploying Windows 10 virtual desktops via Windows 365 requires a specific sequence: first, ensure you have the appropriate licenses (Windows 365 Enterprise or Business). Then access the Microsoft Endpoint Manager admin center, create a provisioning policy, and configure its settings (e.g., network, management). After the policy is configured, you can provision Cloud PCs in bulk.

Finally, assign the Cloud PCs to users. Common mistakes include swapping the order of licensing and portal access, configuring after provisioning, or assigning before provisioning.

7
Multi-Selecthard

Which THREE of the following are requirements for deploying a Win32 app via Microsoft Intune?

Select 3 answers
A.The device must have the Intune Management Extension installed separately.
B.The app installation files must be hosted on an external web server.
C.The app must be assigned to a group of users or devices.
D.Detection rules must be configured to verify installation.
E.The app must be packaged in the .intunewin format.
AnswersC, D, E

A Win32 app must be assigned to a user or device group before Intune delivers it; without an assignment, no device receives the app. This is a mandatory requirement alongside the management extension and packaging.

Why this answer

Option C is correct because a Win32 app in Intune must be assigned to an Azure AD user or device group (required, available, or uninstall intent) before it can be delivered to any endpoint. Option D is correct because Intune requires detection rules (file, folder, registry, MSI product code, or custom script) to determine whether the app is already installed and to report installation status. Option E is correct because Win32 apps must be wrapped with the Microsoft Win32 Content Prep Tool into the .intunewin package format before upload to Intune.

Option A is not required because the Intune Management Extension is installed automatically on Windows devices when a Win32 app or PowerShell script is assigned, not installed separately by the admin. Option B is not required because the app content is uploaded to and hosted by Intune (or delivered via the CDN), not on an external web server.

Exam trap

The trap here is that candidates often confuse the automatic installation of the Intune Management Extension with a manual prerequisite, or assume that Win32 app files must be hosted externally rather than leveraging Intune's built-in cloud storage.

8
Multi-Selecteasy

Which TWO of the following are valid app types in Microsoft Intune for iOS/iPadOS devices?

Select 2 answers
A.Windows 10 Universal app
B.iOS line-of-business app
C.Android Enterprise system app
D.Managed Google Play iframe
E.iOS store app
AnswersB, E

iOS line-of-business apps are a valid Intune app type, packaging signed .ipa files for deployment to enrolled iOS/iPadOS devices. This satisfies the stem's requirement for a supported app type, distinct from store apps, web links and built-in apps, and is uploaded directly through Microsoft Intune rather than the App Store.

Why this answer

In Microsoft Intune, the iOS/iPadOS app types include 'iOS line-of-business app' (B), which lets you upload and deploy an in-house .ipa package signed with your enterprise provisioning profile, and 'iOS store app' (E), which deploys apps by searching and selecting them from the Apple App Store. Both are legitimate iOS/iPadOS app categories available when adding an app in the Intune console. By contrast, 'Windows 10 Universal app' (A) targets Windows 10/11 devices, 'Android Enterprise system app' (C) targets Android Enterprise devices, and 'Managed Google Play iframe' (D) is an Android app type used to browse and approve Managed Google Play apps, so none of these apply to iOS/iPadOS.

Exam trap

The trap in this question is that candidates might select 'Managed Google Play iframe' thinking it is a generic web app type, but it is strictly an Android Enterprise feature and not valid for iOS/iPadOS devices in Microsoft Intune.

9
MCQmedium

You manage Windows devices with Microsoft Intune. A line-of-business MSI installer must be deployed to 400 devices. The installer requires a custom transform (.mst) file and must run with administrative privileges. You need to deploy the app using the least administrative effort while ensuring the transform is applied. What should you do?

A.Convert the MSI to an .intunewin file and deploy it as a Win32 app without the .mst, then use a separate script to modify the registry.
B.Package the MSI and .mst into a Win32 app (.intunewin) and deploy it as required.
C.Deploy the MSI as a line-of-business app and use a PowerShell script to apply the .mst after installation.
D.Upload the MSI as a line-of-business app and specify the .mst file in the app configuration.
AnswerB

Packaging the MSI and its transform into a Win32 app allows you to include the .mst and specify the installation command with the TRANSFORMS property. Win32 apps support custom scripts and full control over installation, ensuring the transform is applied. This approach requires more effort than a line-of-business app but meets the requirement.

Why this answer

Win32 apps in Intune support the inclusion of additional files and custom installation commands, which is necessary to apply an MSI transform. By packaging the MSI and .mst together and specifying the correct command line, the transform is applied during installation. This ensures the customizations are correctly deployed to all targeted devices.

Exam trap

The trap here is assuming that line-of-business MSI apps in Intune support transform files, when they do not.

10
Multi-Selecthard

Which FOUR of the following are valid detection rules for a Win32 app in Intune?

Select 4 answers
A.PowerShell script (custom detection)
B.MSI product code
C.Registry (key or value exists)
D.File system (file or folder exists)
E.Network share access
AnswersA, B, C, D

A PowerShell script used as a custom detection rule lets Intune evaluate arbitrary logic on the endpoint, satisfying the requirement for a valid Win32 app detection method. It returns an exit code and output that Intune interprets to confirm installation.

Why this answer

Option A (PowerShell script / custom detection) is valid because Intune Win32 apps support a custom detection script whose exit code and stdout determine whether the app is considered installed. Option B (MSI product code) is valid because Intune can detect an installed app by matching its MSI product code in the Windows Installer database. Option C (Registry key or value exists) is valid because Intune's registry detection rule checks for a specified key/value (and can compare a value's string, integer, or version) to confirm installation.

Option D (File system / file or folder exists) is valid because Intune's file/folder detection rule verifies existence (and optionally date, size, or version) of a specified path. Option E (Network share access) is not a supported Win32 app detection rule type in Intune, so it does not belong.

Exam trap

Candidates may mistakenly think network share access is a valid detection rule, but it is not.

11
Multi-Selectmedium

A company uses Microsoft Intune to manage Windows 10 devices. Users report that some required line-of-business (LOB) apps are not being installed on their devices. The apps are assigned as 'Required' to a device group that includes the affected devices. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)

Select 2 answers
A.Review the Intune Management Extension logs on a device for installation errors.
B.Uninstall the app from the affected devices and reassign it as Required.
C.Check the device’s last check-in time and perform a manual sync from the Intune console.
D.Reassign the app to the device group with a different assignment type.
E.Run gpresult /r on a device to confirm the app assignment policy is applied.
AnswersA, C

Logs provide detailed error messages.

Why this answer

The Intune Management Extension (IME) is the component responsible for deploying Win32 and line-of-business (LOB) apps on Windows 10 devices. Reviewing its logs (located in %ProgramData%\Microsoft\IntuneManagementExtension\Logs) provides detailed error messages, such as download failures, dependency issues, or script execution errors, which directly indicate why a required app failed to install.

Exam trap

The trap here is that candidates confuse Intune MDM app deployment with traditional Group Policy Software Installation (GPSI) and incorrectly choose gpresult /r, not realizing Intune uses the IME and MDM channel, not Active Directory Group Policy.

12
MCQhard

You manage iOS devices with Microsoft Intune. You need to deploy an app that is not available in the Apple App Store. The app is developed internally and signed with an enterprise certificate. Which app type should you use?

A.iOS/iPadOS app store app
B.Web link
C.Built-in app
D.iOS/iPadOS Line-of-business app
AnswerD

Line-of-business app type uploads the signed .ipa directly, bypassing the App Store, and supports enterprise-signed internal apps. It satisfies the constraint that the app is unavailable in the Apple App Store and signed with an enterprise certificate.

Why this answer

An iOS/iPadOS Line-of-business (LOB) app is the correct app type in Intune for deploying internally developed apps that are signed with an enterprise certificate and not distributed through the Apple App Store. Intune uploads the .ipa file and pushes it to enrolled devices via MDM, bypassing the public store. This is the standard mechanism for enterprise-signed in-house apps.

Exam trap

MD-102 often tests the distinction between App Store apps, VPP apps, and Line-of-business apps — candidates confuse 'enterprise-signed internal app' with App Store distribution and pick the wrong app type.

How to eliminate wrong answers

Option A is wrong because iOS/iPadOS app store apps are sourced from the public Apple App Store and cannot host an internally developed enterprise-signed .ipa. Option B is wrong because a Web link simply creates a shortcut to a URL and does not install or manage an actual application binary. Option C is wrong because built-in apps refer to Microsoft-published apps (such as Edge or Office) that Intune can deploy directly, not custom internal apps.

13
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. A line-of-business (LOB) app named App1 is deployed as required to a group of users. Users report that App1 installs successfully on some devices but fails on others with error code 0x87D1041C. You need to resolve the installation failures. What should you do?

A.Add a dependency to the app to ensure required frameworks are installed first.
B.Modify the detection rule to match the actual installation state on the failing devices.
C.Re-deploy the app with the 'Require a restart' option set to 'No'.
D.Change the app assignment from 'Required' to 'Available' for the affected users.
AnswerB

Error 0x87D1041C specifically means the app was installed but the detection rule did not detect it as installed. By adjusting the detection rule to accurately reflect the app's presence, you ensure Intune recognizes successful installations and stops retrying, resolving the failure.

Why this answer

Error 0x87D1041C occurs when the app installation succeeds but the detection rule fails to confirm it. This often happens if the detection rule checks for a file or registry key that is not present on all devices due to variations in installation paths or versions. Correcting the detection rule to match the actual state on the failing devices resolves the error and allows Intune to mark the app as installed.

Exam trap

The trap here is misinterpreting the error code as an installation failure rather than a detection failure, leading to unnecessary changes to deployment settings.

14
Multi-Selecthard

Which THREE of the following are valid methods to deploy Microsoft 365 Apps for enterprise using Microsoft Intune?

Select 3 answers
A.Use the built-in Microsoft 365 Apps app type in Intune.
B.Use the Office Deployment Tool (ODT) within a script deployed via Intune.
C.Assign the apps via Azure AD application registration.
D.Package the Office installer as a Win32 app.
E.Deploy the MSI version of Office via Intune.
AnswersA, B, D

The built-in Microsoft 365 Apps app type in Intune satisfies the requirement by packaging the Office suite directly, letting you configure update channels, remove prior installations and select specific products. It deploys natively through the Intune management extension without requiring separate packaging or third-party tooling, making it a valid deployment method.

Why this answer

Option A is correct because Intune provides a native Microsoft 365 Apps (Windows 10 and later) app type that lets you configure the Office apps, update channel, and architecture directly from the console without packaging. Option B is correct because you can use the Office Deployment Tool (ODT) with a configuration.xml and run setup.exe via a script (e.g., PowerShell or platform script) deployed through Intune to install Microsoft 365 Apps. Option D is correct because you can wrap the Office installer (using the ODT or a prepared source) into an .intunewin file and deploy it as a Win32 app, which supports custom detection and requirement rules.

Option C is not valid because Azure AD application registration is for identity/consent of apps, not for deploying Office binaries to devices. Option E is not valid because Microsoft 365 Apps for enterprise is delivered via Click-to-Run, not as an MSI, so there is no supported MSI deployment method for this product through Intune.

Exam trap

The trap here is that candidates confuse Azure AD application registration (an identity/authentication feature) with a deployment mechanism, or mistakenly think MSI-based Office deployment is still supported for Microsoft 365 Apps in Intune.

15
MCQmedium

You manage Windows 11 devices with Microsoft Intune. A line-of-business MSI app must install only after a Visual C++ redistributable package is present, and the MSI must run with SYSTEM privileges at every device startup regardless of user sign-in. You need to configure the app deployment in Intune. What should you do?

A.Deploy the MSI as a line-of-business app and configure an Intune PowerShell script to install the redistributable first.
B.Deploy the MSI as a line-of-business app and set the app to install in user context.
C.Create a Windows app (Win32) package, add the redistributable as a supersedence, and set the install behavior to User.
D.Create a Windows app (Win32) package, add the redistributable as a dependency, and set the install behavior to System.
AnswerD

Packaging the MSI as a Windows app (Win32) lets Intune enforce a dependency on the redistributable before installing the MSI, and the install behavior set to System runs the installer with SYSTEM privileges. The dependency ensures ordering, and SYSTEM context satisfies the requirement that installation occur at device level independent of user sign-in, which matches the scenario's startup requirement.

Why this answer

A Windows app (Win32) package created with the Microsoft Win32 Content Prep Tool supports both dependency relationships and install behavior selection. Adding the redistributable as a dependency forces Intune to install it before the MSI, and choosing System install behavior runs the MSI with SYSTEM privileges. This combination uniquely satisfies the prerequisite and privilege requirements in the scenario.

Exam trap

The trap here is confusing supersedence with dependency, or assuming a line-of-business MSI can enforce prerequisite ordering.

16
Matchingmedium

Match each Intune configuration profile type to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Control settings like password, camera, and Bluetooth

Define rules for device health and security

Deploy custom OMA-URI or Apple Configurator settings

Configure Windows Defender Firewall and BitLocker

Group Policy-like settings for Windows devices

Why these pairings

Device restrictions manage device features, Endpoint protection handles security settings, Administrative templates use ADMX, and Custom uses OMA-URI. Common confusions involve swapping the first two.

17
MCQmedium

Your organization uses Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices for accessing an internal web app. Which profile type should you use?

A.PKCS certificate profile
B.SCEP certificate profile
C.Trusted certificate profile
D.Custom configuration profile (preferences)
AnswerC

A Trusted certificate profile deploys the root or intermediate CA certificate to iOS/iPadOS devices so they trust the internal web app's server certificate. It satisfies the requirement to install a custom SSL certificate for internal access, unlike SCEP or PKCS profiles, which issue client certificates.

Why this answer

A Trusted certificate profile is used to deploy a root or intermediate CA certificate that the device must trust for certificate-based authentication, such as accessing an internal web app over HTTPS. This profile type simply installs the certificate into the device's trusted root store without generating a private key, which is exactly what is needed when you only need to establish trust for the server certificate presented by the web app.

Exam trap

The trap here is that candidates often confuse deploying a trusted root certificate (needed for server trust) with issuing a client certificate (needed for device authentication), leading them to incorrectly choose PKCS or SCEP profiles when the question only requires establishing trust for the server's SSL certificate.

How to eliminate wrong answers

Option A is wrong because a PKCS certificate profile is used to issue a client certificate with a private key to the device for client authentication, not to deploy a trusted root certificate. Option B is wrong because a SCEP certificate profile is used to request and renew client certificates dynamically via the Simple Certificate Enrollment Protocol, again for client authentication, not for deploying a trusted root. Option D is wrong because a Custom configuration profile (preferences) is used to deploy app-specific settings or plist files, not to install certificates into the device's trust store.

18
MCQhard

You manage Windows 11 devices with Microsoft Intune. A Win32 app deployed as Required is failing on a subset of devices, and the Intune Management Extension log shows the installer exiting with code 1618. You have already confirmed the app package and detection rule are correct. What is the most likely cause and the appropriate fix?

A.The app requires a reboot that was not granted; map return code 1618 to a soft reboot so the device restarts.
B.The install command is running in the user context and lacks elevation; switch Install behavior to System.
C.The detection rule is matching too early; add a longer detection script timeout so the installer finishes first.
D.Another installation is already in progress; adjust the app's dependencies or deployment timing so installs do not overlap.
AnswerD

Exit code 1618 is the Windows Installer error indicating another installation is already in progress. When multiple Required apps install simultaneously, the Windows Installer mutex blocks the second installer. Staggering deployments, sequencing dependencies, or reducing concurrent Required apps on those devices resolves the conflict so each installer can acquire the mutex and complete.

Why this answer

Exit code 1618 from Windows Installer means another installation is already running on the device. When several Required Win32 apps deploy at once, their installers contend for the single Windows Installer mutex, and the losing installer returns 1618. Sequencing dependencies or staggering deployment timing lets each installer run without contention, so the affected devices complete installation.

Exam trap

The trap here is assuming 1618 indicates a reboot requirement, when reboot codes are 3010 and 1641 and 1618 actually signals an installer mutex conflict.

19
Multi-Selecthard

You use Microsoft Intune to manage Windows devices. You need to deploy a Win32 app that must run only on devices running Windows 11 and must be installed silently in the system context. The installer returns exit code 3010 on success but requires a restart. Which two actions must you perform to ensure the app installs correctly and Intune interprets the success code properly? (Choose two.)

Select 2 answers
A.Set the install command to run in user context instead of system context.
B.Assign the app as available instead of required so users can choose when to install it.
C.Create a PowerShell script that maps exit code 3010 to exit code 0 before returning.
D.Configure a requirement rule that the operating system is Windows 11.
E.Add 3010 to the list of return codes that indicate a soft reboot is required.
AnswersD, E

Requirement rules determine whether a Win32 app is applicable to a device. Configuring an operating system requirement for Windows 11 ensures the app is only offered to and installed on Windows 11 devices. Without this, Intune would attempt installation on Windows 10 devices as well, which violates the stated targeting requirement.

Why this answer

Two configuration steps are needed. First, a requirement rule restricting the app to Windows 11 ensures targeting is correct. Second, adding exit code 3010 to the soft reboot return codes tells Intune the installation succeeded but a restart is required, so the app is marked installed and the reboot is handled.

Together these satisfy the operating system targeting and exit code interpretation requirements.

Exam trap

The trap here is wrapping the installer to convert 3010 to 0 or changing the install context, when Intune already supports classifying 3010 as a soft reboot and the operating system targeting belongs in a requirement rule.

20
MCQhard

An organization uses Microsoft Intune for Windows 10 device management. They need to deploy a custom Windows app (.exe) to kiosk devices. The app requires admin privileges to install, and the devices are shared. Which deployment method should be used?

A.Use a Win32 app with install context set to 'system'.
B.Assign the app as 'available' for user-install.
C.Deploy as a line-of-business app with device context.
D.Package as a Microsoft Store for Business app.
AnswerA

Win32 apps with install context set to system run the installer as SYSTEM, granting the admin privileges needed for installation on shared kiosk devices. This satisfies the requirement for privileged installation on shared Windows 10 devices.

Why this answer

Win32 apps in Microsoft Intune can be configured with the install context set to 'system', which grants the necessary admin privileges for installation and ensures the app is installed for all users on shared kiosk devices. This method uses the Intune Management Extension to run the installer with SYSTEM account privileges, bypassing user-level restrictions and supporting per-machine installations.

Exam trap

The trap here is that candidates often confuse 'device context' with 'system context', not realizing that LOB apps cannot handle .exe files and that 'available' assignments run in user context, which fails for admin-required installs on shared devices.

How to eliminate wrong answers

Option B is wrong because assigning the app as 'available' for user-install runs the installer in the user context, which lacks admin privileges and installs per-user, not per-device, making it unsuitable for shared kiosk devices. Option C is wrong because line-of-business (LOB) apps in Intune only support .msi, .appx, or .msix formats, not .exe files, and the 'device context' option for LOB apps is limited to .msi installers with system context, not custom .exe apps. Option D is wrong because packaging as a Microsoft Store for Business app requires the app to be available in the Store or repackaged as a Store-managed app, which does not support custom .exe files and cannot enforce admin privileges during installation.

21
MCQeasy

You need to deploy a Microsoft Store app (e.g., Microsoft Whiteboard) to Windows 10 devices managed by Intune. Which app type should you use?

A.Microsoft Store app (Windows)
B.Windows app (Win32)
C.Web link
D.Microsoft Store for Business (offline licensed)
AnswerA

The Microsoft Store app (Windows) type deploys Store apps such as Microsoft Whiteboard to Windows 10 devices by linking the Store listing, enabling Intune to install and update them. This satisfies the stem's requirement for deploying a Microsoft Store app.

Why this answer

To deploy a Microsoft Store app like Microsoft Whiteboard to Windows 10 devices managed by Intune, you must use the 'Microsoft Store app (Windows)' app type. This type directly integrates with the Microsoft Store catalog, allowing you to select and deploy store apps without needing offline licensing or manual packaging. It supports both online and offline licensing models, but for a standard store app deployment, this is the correct and simplest choice.

Exam trap

The trap here is that candidates often confuse 'Microsoft Store app (Windows)' with 'Microsoft Store for Business (offline licensed)', thinking offline licensing is always required for managed deployments, but the standard store app type works for online scenarios and is the default choice for deploying store apps like Whiteboard.

How to eliminate wrong answers

Option B is wrong because 'Windows app (Win32)' is used for deploying traditional desktop applications (e.g., .exe, .msi) that require custom installation scripts or detection rules, not for Microsoft Store apps. Option C is wrong because 'Web link' simply creates a shortcut to a URL in the Company Portal and does not install any application. Option D is wrong because 'Microsoft Store for Business (offline licensed)' is a specific licensing model for offline deployment of store apps, but the question does not specify an offline requirement; the standard 'Microsoft Store app (Windows)' type can handle both online and offline scenarios, and is the general-purpose type for store apps.

22
Multi-Selectmedium

Which TWO actions are required to deploy a Win32 app using Microsoft Intune? (Choose two.)

Select 2 answers
A.Upload the .intunewin package file.
B.Configure detection rules.
C.Connect to Managed Google Play.
D.Assign a Microsoft Store license.
E.Sign the app with a macOS developer certificate.
AnswersA, B

Win32 apps in Intune require the source files wrapped by the IntuneWinAppUtil tool, producing a .intunewin package. Uploading that package is the mandatory first step before configuring the install and uninstall commands, detection rules and requirements.

Why this answer

Option A is correct because deploying a Win32 app in Intune requires first wrapping the source files with the Microsoft Win32 Content Prep Tool to produce a .intunewin package, which is then uploaded to the Intune admin center as the app's installation source. Option B is correct because Intune must determine whether the app is already installed on a device, so the Win32 app configuration requires detection rules (such as an MSI product code, file/folder path, or registry key) to report installation status and drive the install/uninstall behavior. Option C is incorrect because connecting to Managed Google Play applies to Android Enterprise app deployment, not Win32 apps.

Option D is incorrect because assigning a Microsoft Store license relates to Store apps (UWP/MSIX) rather than Win32 packages. Option E is incorrect because a macOS developer certificate is used for signing Apple apps, which is irrelevant to Windows Win32 deployment.

Exam trap

The trap here is that candidates may confuse the requirements for Win32 apps with those for other platforms (Android, Microsoft Store, macOS), leading them to select options that are valid for those platforms but irrelevant for Win32 deployment.

23
MCQeasy

A company uses Microsoft Intune to manage Windows devices. They need to deploy a required app to all devices in the marketing department. The app is a Microsoft Store app (new). What should you do first?

A.Deploy the app using a PowerShell script that installs it from the Microsoft Store.
B.Create a configuration profile that installs the app from the Microsoft Store.
C.Add the app from the Microsoft Store app (new) in Intune and assign it to the marketing department group as required.
D.Package the app as a Win32 app using the Microsoft Win32 Content Prep Tool and deploy it as required.
AnswerC

The Microsoft Store app (new) app type in Intune allows you to search and add apps directly from the Microsoft Store. You can then assign the app to a group with the required intent. This is the correct first step to deploy a Store app to a specific department.

Why this answer

To deploy a Microsoft Store app (new) to a group, you add the app in Intune by selecting the Microsoft Store app (new) type, search for the app, and then assign it to the target group with the required intent. This is the standard and supported method.

Exam trap

The trap here is overcomplicating the deployment by using Win32 packaging or scripts instead of the native Microsoft Store app (new) type.

24
MCQeasy

You assign a required app to a device group. After the next sync, some devices report a 'Failed' status. What should you check first?

A.The device's last sync time
B.If a newer version is already installed
C.Whether the user is licensed
D.The device management log
AnswerD

The device management log, found in Intune under Devices > Monitor or on the device via Event Viewer, records app installation errors and failure codes. Checking it first satisfies the stem's need to diagnose why required app deployment reported 'Failed' status after sync.

Why this answer

The device management log (also known as the Intune management extension log or the MDM agent log on the device) provides detailed, real-time error codes and failure reasons for app installation attempts. When a required app shows 'Failed' status after sync, this log is the first place to check because it captures the exact cause—such as a download failure, dependency issue, or script execution error—that the Intune console cannot surface in summary views.

Exam trap

The trap here is that candidates assume 'Failed' status always points to a licensing or sync timing issue, when in fact the device management log is the definitive source for granular failure details that the Intune console summary cannot provide.

How to eliminate wrong answers

Option A is wrong because the last sync time only tells you when the device last communicated with Intune, not why a specific app installation failed; a recent sync does not guarantee successful app processing. Option B is wrong because checking for a newer version already installed is a troubleshooting step for 'Not Applicable' or 'Already Installed' statuses, not for 'Failed' status—the failure indicates the installation process itself encountered an error. Option C is wrong because licensing is validated at enrollment and sync time; if the user were unlicensed, the app would typically show as 'Not Applicable' or the device would not receive the policy at all, not a 'Failed' installation status.

25
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. Users report that some required applications are not being installed on their devices. You confirm the applications are assigned as 'Required' to a device group, and the devices are online. What is the most likely cause?

A.BitLocker encryption is pending
B.The user is not logged in to the device
C.The enrollment status page is blocking installation
D.The Intune Management Extension is missing
AnswerD

Win32 and PowerShell script applications assigned as Required are delivered by the Intune Management Extension agent on Windows 10 devices. Without that agent installed and running, the device never receives the installation instruction, explaining why required apps fail to install despite online devices and correct assignments.

Why this answer

The Intune Management Extension is required to process Win32 app installations. If the extension is missing or not running, required apps will not install even though the device is online and assignment is configured. Option A is wrong because BitLocker encryption status does not affect app installation.

Option B is wrong because device-targeted assignments do not require the user to be logged in. Option C is wrong because the enrollment status page does not block required app installations after enrollment is complete.

26
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. The finance team needs a specific third-party accounting application deployed to their Windows 11 laptops. The vendor provides an .msi installer and a setup.exe bootstrapper. You want the deployment to be tracked by Intune and to automatically retry if the install fails. What should you do?

A.Add the application as a Microsoft Store app (new) and assign it to the finance team.
B.Add the application as a line-of-business app and upload the .msi file directly.
C.Add the application as a Win32 app, upload the installer, and configure the install and uninstall commands.
D.Create a PowerShell script and deploy it as a platform script to the finance team devices.
AnswerC

Win32 app is the Intune app type designed for custom .msi, .exe, and .intunewin packages. It supports required assignments, success and failure return codes, detection rules, and automatic retries when installation fails, all of which match the stated requirements. Uploading the vendor installer and defining the commands gives Intune the information it needs to deploy and track the app accurately.

Why this answer

Win32 app is the correct type for deploying a vendor-supplied .msi or setup.exe with tracking and retry behavior. It provides install and uninstall commands, return code handling, detection rules, and reporting that the other app types cannot match. The result is a managed deployment with automatic retry on failure, exactly as required.

Exam trap

The trap here is choosing the line-of-business app type simply because it accepts an .msi, overlooking that Win32 app is required for robust tracking and retry behavior.

27
MCQhard

You manage a fleet of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that has a complex installation requiring multiple command-line parameters. The app must be available to users in the Company Portal. What is the best way to handle the installation parameters?

A.Deploy a PowerShell script via Intune that runs the installer with parameters.
B.Configure detection rules to run a script that passes parameters.
C.Use the Intune Win32 app packaging to specify the installation command with parameters.
D.Use an administrative template to set parameters before installing.
AnswerC

Win32 app packaging in Intune lets you define the install command line, including multiple parameters, within the app configuration. This satisfies the stem's constraint of a complex installation requiring parameters while remaining available to users in the Company Portal.

Why this answer

Intune's Win32 app packaging allows you to specify the full installation command, including complex parameters, directly in the 'Install command' field. This method ensures the installer runs with the exact parameters needed, and the app is then published to the Company Portal for user self-service. PowerShell scripts or detection rules do not handle the installation parameters themselves, and administrative templates are for configuring settings, not installation commands.

Exam trap

The trap here is that candidates may think a PowerShell script is needed for complex parameters, but Intune's Win32 app packaging directly supports any command-line string, making the script unnecessary and less efficient.

How to eliminate wrong answers

Option A is wrong because deploying a PowerShell script via Intune that runs the installer with parameters is an indirect workaround; Intune's Win32 app packaging natively supports specifying the installation command with parameters, making a separate script unnecessary and less reliable for detection and reporting. Option B is wrong because detection rules are used to verify if an app is already installed, not to pass installation parameters; they run after the installation command, not during it. Option D is wrong because administrative templates (ADMX-backed policies) are used to configure registry-based settings or policies, not to specify installation command-line parameters for a Win32 app.

28
MCQhard

You manage a set of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that requires a specific registry key to exist before installation. The app installer does not check for this key. You must ensure the app installs only on devices that have the registry key. What should you do?

A.Use a PowerShell script in the app package to create the registry key before installation.
B.Deploy the app as available and instruct users to verify the registry key before installing.
C.Add a requirement rule to the Win32 app that checks for the registry key.
D.Create a detection rule that checks for the registry key.
AnswerC

Requirement rules in Intune allow you to specify conditions that must be met for the app to install. You can create a rule that checks for the existence of a registry key, file, or value. This ensures the app is only offered to devices that meet the condition, without modifying the installer.

Why this answer

Requirement rules in Intune are evaluated before app installation. By adding a rule that checks for the presence of a specific registry key, you ensure the app is only installed on devices that already have that key. This enforces the prerequisite automatically and reliably.

Exam trap

The trap here is confusing detection rules with requirement rules; detection rules only check if an app is installed, while requirement rules control whether installation should proceed.

29
Drag & Dropmedium

Order the steps to configure a Windows 10 device for Microsoft 365 Apps deployment via Intune.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Begin in Intune admin center, add a new app, choose Microsoft 365 Apps, configure suite, and assign.

30
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps to all devices. The IT team wants to minimize administrative effort and ensure the apps are always up to date. What should they use?

A.PowerShell script that downloads and installs Office
B.Win32 app using the Office Deployment Tool
C.Microsoft 365 Apps (Windows 10 and later) app type in Intune
D.Microsoft Store app (new) for each Office app
AnswerC

Intune provides a built-in app type specifically for Microsoft 365 Apps. This app type allows you to select the Office apps to install, choose update channels, and configure other settings. It automatically handles updates and requires minimal administrative effort. It is the recommended method for deploying and managing Microsoft 365 Apps on Windows devices, ensuring they stay current with the selected update channel.

Why this answer

The Microsoft 365 Apps app type in Intune is purpose-built for deploying and managing Office. It allows you to select apps, configure update channels, and automatically keep the apps up to date. This reduces administrative effort and ensures devices receive updates according to the chosen channel, making it the ideal solution for deploying Microsoft 365 Apps at scale.

Exam trap

The trap here is thinking that a Win32 app with the Office Deployment Tool is required, when Intune offers a dedicated app type that simplifies deployment and updates.

31
MCQhard

You use Microsoft Intune to manage Windows devices. You deploy a Win32 app as required to a device group. The app's detection rule uses a file version check on `C:\Program Files\Contoso\app.exe`. Users report the app appears installed, but Intune repeatedly reinstalls it on every check-in. The app's installer does not actually place app.exe in that path; instead, it places it in `C:\Program Files (x86)\Contoso\`. What should you do?

A.Set the app's install behavior to user context so the file is placed in the correct path.
B.Increase the detection rule's version comparison to 'greater than or equal to' the installed version.
C.Change the detection rule to check the correct path `C:\Program Files (x86)\Contoso\app.exe`.
D.Add a requirement rule that the device runs a 64-bit version of Windows.
AnswerC

Intune re-evaluates the detection rule on each check-in. If the rule points to a path where the file does not exist, detection always returns false, so Intune treats the app as missing and reinstalls it repeatedly. Updating the detection rule to the actual install path makes detection succeed and stops the reinstall loop, directly resolving the reported behavior.

Why this answer

Intune evaluates the detection rule at each check-in to decide whether the app is present. A rule that points to a file path where the executable was never installed always evaluates as not detected, so Intune believes the app is missing and reinstalls it. Correcting the detection rule to reference the actual installation path, Program Files (x86), allows detection to succeed and ends the repeated reinstallations.

Exam trap

The trap here is treating repeated reinstallations as an assignment or requirement problem, when the actual cause is a detection rule pointing at a path the installer never writes to.

32
MCQmedium

You are the Endpoint Administrator for a company that uses Microsoft Intune to manage Windows 11 devices. The security team requires that Microsoft Edge be configured with a specific set of security settings, including blocking outdated plugins and enforcing SmartScreen. You need to deploy these settings to all Windows 11 devices with minimal administrative effort. What should you do?

A.Create a device configuration profile with the 'Administrative Templates' profile type and configure the Microsoft Edge settings.
B.Deploy a PowerShell script that modifies the registry to set the required Edge policies.
C.Create a custom configuration profile using the Open Mobile Alliance Uniform Resource Identifier (OMA-URI) settings.
D.Use the Microsoft 365 Apps for enterprise deployment to include Edge settings in the Office Configuration Service.
AnswerA

Administrative Templates in Intune are based on ADMX files and allow you to configure hundreds of Microsoft Edge policies directly from the Intune console. This is the recommended method for managing Edge settings at scale without scripting, and it applies to all targeted devices automatically.

Why this answer

Administrative Templates in Intune provide a streamlined way to configure Microsoft Edge policies using the same ADMX-backed settings that Group Policy uses. They are built into Intune, require no custom scripting, and can be assigned to device groups. This meets the requirement to deploy security settings with minimal administrative effort.

Exam trap

The trap here is assuming that any script or custom profile can achieve the same result, but Administrative Templates are purpose-built for this and reduce ongoing management overhead.

33
MCQhard

Your organization deploys Microsoft Defender for Endpoint (now Microsoft Defender XDR) on Windows 10 devices using Intune. After deployment, some devices show 'Defender service is not running' in the security console. The devices are online and compliant. What is the most likely cause?

A.Tamper protection is enabled and blocking the service.
B.The devices are not compliant with the Defender policy.
C.Windows Firewall is blocking Defender updates.
D.A third-party antivirus is installed and active.
AnswerD

When a third-party antivirus is installed and active, it registers with the Windows Security Center and disables Microsoft Defender Antivirus, so the Defender service stops running. Intune's onboarding then reports the service as not running despite the device being online and compliant.

Why this answer

When a third-party antivirus is installed and active on a Windows 10 device, Windows Defender (now Microsoft Defender Antivirus) automatically disables itself to avoid conflicts. This is by design: the Windows Security Center detects the active third-party AV and sets Defender's service state to stopped or disabled. In the Microsoft Defender for Endpoint console, this appears as 'Defender service is not running' even though the device is online and compliant with Intune policies.

Exam trap

The trap here is that candidates often assume tamper protection (Option A) is the culprit because it is a common security feature, but they overlook the automatic disabling behavior triggered by a third-party antivirus registration in the Windows Security Center.

How to eliminate wrong answers

Option A is wrong because tamper protection prevents unauthorized changes to Defender settings but does not stop the Defender service itself; it blocks modifications to real-time protection, cloud-delivered protection, and security intelligence updates, not the service state. Option B is wrong because the devices are explicitly stated as compliant with the Defender policy, so non-compliance is not the cause. Option C is wrong because Windows Firewall does not block Defender updates; Defender updates use Windows Update or dedicated update channels (e.g., HTTP/HTTPS to Microsoft servers) which are not filtered by the built-in firewall unless custom rules are misconfigured, and even then, a blocked update would not stop the service from running.

34
MCQmedium

Your organization manages Windows devices with Intune and uses Azure Information Protection (AIP) to classify documents. You are deploying the AIP client as a Win32 app. After deployment, some users report that the AIP add-in is not visible in Office applications. What should you check first?

A.Confirm that Office is updated to the latest version.
B.Ensure that the required .NET Framework and Visual Studio Tools for Office runtime are installed.
C.Verify that the user has local administrator rights.
D.Check if the device has internet access to activate the client.
AnswerB

The AIP add-in for Office depends on the .NET Framework and Visual Studio Tools for Office runtime; if these prerequisites are absent, the add-in loads silently without appearing. Checking them first addresses the missing add-in symptom.

Why this answer

The AIP client (Azure Information Protection unified labeling client) requires the .NET Framework and Visual Studio Tools for Office (VSTO) runtime to integrate with Office applications. If these prerequisites are missing, the AIP add-in will not load in Office, even if the client is installed. Therefore, checking for these dependencies is the first troubleshooting step.

Exam trap

MD-102 often tests the prerequisites for AIP client deployment; candidates may overlook the VSTO and .NET requirements and instead focus on Office updates or permissions, which are less likely to cause the add-in to be completely missing.

How to eliminate wrong answers

Option A is wrong because while Office updates can affect add-in compatibility, the most common cause of a missing AIP add-in is missing prerequisites, not Office version. Option C is wrong because local administrator rights are not required for the AIP add-in to function; the client can be installed per-user or per-machine. Option D is wrong because internet access is needed for activation and policy retrieval, but if the add-in is not visible at all, it's likely a prerequisite issue rather than connectivity.

35
Multi-Selecthard

You are deploying a Win32 app to Windows devices using Microsoft Intune. The app requires a specific registry key to be present for detection. You also need to ensure the app installs only on devices running Windows 11 version 22H2 or later. Which two actions must you perform when creating the app? (Choose two.)

Select 2 answers
A.Set the install command to include a check for the registry key.
B.Configure the app to run in system context.
C.Configure a detection rule that checks for the registry key.
D.Add a dependency on a previous version of the app.
E.Add a requirement rule for the operating system version.
AnswersC, E

Detection rules determine whether the app is already installed. Using a registry detection rule ensures Intune accurately reports installation status and triggers reinstallation if the key is missing. This is required to verify successful installation and to maintain compliance with the app's presence on the device.

Why this answer

To ensure the app installs only on Windows 11 22H2 or later, a requirement rule for the OS version is necessary. To verify the app is installed by checking for a specific registry key, a detection rule must be configured. These two actions directly address the deployment conditions described in the scenario.

Exam trap

The trap here is confusing detection rules with requirement rules, or assuming that the install command can handle detection.

36
MCQhard

You are designing an app protection policy (APP) for Microsoft 365 mobile apps accessing corporate data on iOS devices. The security team requires that when a user opens a work document in the Microsoft Word app, the user must authenticate with Face ID or a passcode. Which setting should you configure?

A.Require PIN or Face ID for access (iOS)
B.Block managed apps from running on jailbroken devices
C.Encrypt app data
D.Require app PIN when device PIN is not set
AnswerA

This setting enforces biometric or passcode authentication at app launch, directly satisfying the security team's requirement that opening a work document in Word triggers Face ID or passcode verification. It applies at the app layer via Intune app protection policy, independent of device-level enrolment, so corporate data stays protected on iOS.

Why this answer

The 'Require PIN or Face ID for access (iOS)' setting enforces biometric or passcode authentication specifically when a user launches a managed app or resumes it from the background. This directly meets the requirement that opening a work document in Word triggers Face ID or passcode verification, as the app protection policy (APP) intercepts the app launch and prompts for authentication before granting access to corporate data.

Exam trap

The trap here is that candidates confuse 'Require PIN or Face ID for access' with 'Require app PIN when device PIN is not set', mistakenly thinking the latter covers all scenarios, when in fact it only applies conditionally when the device lacks a PIN.

How to eliminate wrong answers

Option B is wrong because 'Block managed apps from running on jailbroken devices' prevents the app from running at all on compromised devices but does not enforce per-session authentication like Face ID or passcode. Option C is wrong because 'Encrypt app data' ensures data-at-rest encryption on the device but does not require user authentication at app launch. Option D is wrong because 'Require app PIN when device PIN is not set' only applies a PIN if the device lacks a PIN, whereas the requirement is to always require Face ID or passcode regardless of device PIN status.

37
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom .pkg app to all macOS devices. What app type should you create in Intune?

A.macOS app (line-of-business)
B.Windows app (Win32)
C.Web link
D.iOS app (line-of-business)
AnswerA

The macOS app (line-of-business) type accepts .pkg and .dmg files, supporting custom packaging and uninstall scripts. Other macOS app types target App Store or built-in packages, so line-of-business is required for a custom .pkg deployment.

Why this answer

To deploy a custom .pkg app to macOS devices via Microsoft Intune, you must create a macOS line-of-business (LOB) app. LOB apps are designed for sideloading custom or in-house applications that are not available in the public app store, and Intune supports .pkg and .dmg formats for macOS LOB deployment. This app type allows you to upload the .pkg file directly and assign it to devices, handling installation through the Intune management agent.

Exam trap

The trap here is that candidates may confuse 'line-of-business' as a generic term and select the iOS LOB option, forgetting that each platform (macOS, iOS, Windows) has its own specific LOB app type in Intune.

How to eliminate wrong answers

Option B is wrong because 'Windows app (Win32)' is a deployment type for Windows applications using .exe or .msi installers, and it has no relevance to macOS device management. Option C is wrong because 'Web link' creates a shortcut to a URL on the device's home screen or portal, not an actual app installation, and cannot deploy a .pkg file. Option D is wrong because 'iOS app (line-of-business)' is used for deploying custom .ipa files to iOS devices, not macOS, and the platform-specific app types are not interchangeable.

38
MCQmedium

A company uses Microsoft Intune to manage Windows 11 devices. You deploy a required Win32 app that installs a line-of-business tool. Two weeks later, the vendor releases a new version that must replace the old one. You need to ensure devices upgrade to the new version without user interaction and that the old version is removed first. What should you configure?

A.Deploy a PowerShell platform script that calls the vendor's installer and then deletes the old app registration.
B.Create a new Win32 app for the updated version and configure a supersedence relationship from the new app to the old app.
C.Create a new Win32 app for the updated version and assign it as available to the same group.
D.Update the existing Win32 app by uploading the new installer to the same app record.
AnswerB

Supersedence lets you define that a newer app replaces an older one, and you can choose to uninstall the previous version as part of the upgrade. Assigning the new app as required ensures targeted devices receive it automatically. This delivers a controlled, silent upgrade path that removes the old version first, which is exactly what the scenario requires.

Why this answer

Supersedence is the supported Intune mechanism for replacing one Win32 app with another. By defining the relationship from the new app to the old one and choosing to uninstall the previous version, you get a silent, managed upgrade. Assigning the new app as required ensures every targeted device transitions automatically, satisfying both the replacement and no-user-interaction requirements.

Exam trap

The trap here is editing the existing app record with new content, which updates the package but does not force already-installed devices to upgrade.

39
MCQhard

Refer to the exhibit. You query Microsoft Graph API and receive this JSON for a managed device. App2 installation failed. The app is a Win32 app deployed as required. The device is compliant and enrolled via MDM. What is the most likely reason for the failure?

A.The Intune Management Extension is not installed.
B.The app is not assigned to the user.
C.The app version is incompatible with the device OS.
D.The device is not compliant.
AnswerA

Win32 apps deployed as required are processed by the Intune Management Extension agent, not the MDM channel. Without it installed on the device, the app never reaches the agent and installation fails, despite compliance and successful MDM enrolment.

Why this answer

Win32 apps deployed as required require the Intune Management Extension (IME) to be present on the device for installation. Since the device is enrolled via MDM and compliant, but the app installation failed, the most likely cause is that the IME is missing or not functioning. The IME handles Win32 app deployment, detection, and remediation, and without it, required Win32 apps cannot install.

Exam trap

The trap here is that candidates often assume a compliant device automatically has all required components, but the Intune Management Extension is a separate prerequisite that must be installed and running for Win32 app deployment to succeed.

How to eliminate wrong answers

Option B is wrong because the app is deployed as required, which means it is assigned to the device or user regardless of user-specific assignment; a missing user assignment would not cause a failure for a required deployment. Option C is wrong because the exhibit does not indicate any version incompatibility, and the device is compliant, so OS version issues would typically be flagged by Intune compliance policies or app requirements. Option D is wrong because the device is explicitly stated as compliant, so non-compliance cannot be the reason for the failure.

40
MCQeasy

A company uses Microsoft Intune to manage Windows devices. Administrators need to deploy Microsoft 365 Apps to all managed Windows devices and ensure the apps receive updates automatically from the Microsoft 365 Apps update channel. Which Intune app type should they use?

A.Microsoft 365 Apps (Windows 10 and later)
B.Windows app (Win32)
C.Microsoft Store app (new)
D.Web link
AnswerA

The Microsoft 365 Apps (Windows 10 and later) app type in Intune is purpose-built to deploy Office. It provides the Office Configuration Service and XML settings that let you select the update channel, choose which Office apps to install, and control update behavior. Assigning it to device groups delivers and maintains Microsoft 365 Apps with the desired update channel automatically.

Why this answer

Intune includes a dedicated Microsoft 365 Apps (Windows 10 and later) app type that integrates with the Office Configuration Service. It lets administrators choose the update channel, select which Office applications to install, and configure update behavior, then assign the app to device groups. This provides automatic installation and ongoing updates from the chosen channel, which is exactly what the scenario requires.

Exam trap

The trap here is assuming any app type that can install Office will also manage its update channel, when only the Microsoft 365 Apps app type provides native channel and update controls.

41
Multi-Selectmedium

You are preparing to deploy a Win32 app to Windows 11 devices with Microsoft Intune. The app must install silently and be reported as installed only when a specific file exists at a known path. Which TWO configuration elements are required for Intune to evaluate and report the app as installed? (Choose two.)

Select 2 answers
A.A PowerShell script that writes a marker file after installation
B.A return code mapping that treats 3010 as a soft reboot
C.An install command that runs the app's silent installer
D.A requirement rule that limits installation to Windows 11
E.A detection rule that identifies the app on the device
AnswersC, E

The install command tells the Intune Management Extension how to run the app's installer. For a silent install, the command must include the vendor's quiet switches, for example an MSI executed with /qn. Without a valid install command, the extension has nothing to execute, so the app cannot be delivered or detected as installed.

Why this answer

For Intune to install and then report a Win32 app as installed, the app needs both an install command that invokes the silent installer and a detection rule that identifies the app on the device. The detection rule is what the Intune Management Extension evaluates after installation, and the install command is what it executes to place the app on the device.

Exam trap

The trap here is treating optional extras like marker scripts or return code mapping as required, when detection and install command are the core elements.

42
Multi-Selectmedium

Which THREE of the following are required to deploy a Win32 app using Microsoft Intune?

Select 3 answers
A.Product code
B.Detection rule
C.Return codes for success
D.Dependencies
E.Installation command
AnswersB, C, E

Intune requires a detection rule so it can determine whether the Win32 app is already installed on a device. Without it, the service cannot evaluate installation state, making the rule mandatory alongside the app package and install command.

Why this answer

To deploy a Win32 app in Microsoft Intune, a detection rule (B) is mandatory because Intune must determine whether the app is already installed on the device, using methods such as MSI product code, file/folder existence, or a custom script. Return codes for success (C) are also required so Intune can interpret the exit code returned by the installer and correctly report the installation as succeeded, failed, or requiring a restart (e.g., 0 for success, 3010 for soft reboot). The installation command (E) is essential because Intune needs the exact command line (for example, msiexec /i "app.msi" /qn or setup.exe /silent) to actually install the Win32 app on the target device.

Product code (A) is not universally required, since it is only one possible detection method and can be replaced by file, folder, or script-based detection. Dependencies (D) are optional, as they are only needed when the app requires other apps to be installed first, and are not mandatory for every Win32 app deployment.

Exam trap

The trap here is that candidates often confuse optional features like dependencies or product codes with mandatory requirements, but Intune explicitly requires only the installation command, detection rule, and at least one return code for success.

43
MCQhard

You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully, but the detection rule incorrectly reports the app as not installed, causing Intune to attempt reinstallation repeatedly. Which detection rule method is most likely causing this issue?

A.MSI product code detection uses a product code that does not match the installed app
B.File existence detection checks for a file that is installed by the app
C.Registry detection checks for a registry key that is created by the app
D.Custom script detection returns exit code 0 even if app is not present
AnswerA

MSI product code detection compares the specified GUID against the installed product's actual code. If the code does not match the installed app, detection always returns false, so Intune treats the app as absent and reinstalls it repeatedly.

Why this answer

When an MSI product code detection rule uses a product code that does not match the GUID of the installed application, Intune will always evaluate the app as 'not installed' regardless of the actual installation state. This mismatch causes Intune to repeatedly attempt reinstallation on every check-in cycle, as the detection logic never finds a matching product code in the Windows Installer database.

Exam trap

The trap here is that candidates often assume any detection rule method will work as long as the app is installed, but they overlook that MSI product code detection requires an exact GUID match, and a mismatch will cause Intune to perpetually attempt reinstallation.

How to eliminate wrong answers

Option B is wrong because file existence detection checks for a file that is installed by the app; if the file is present, the rule correctly reports the app as installed, so it would not cause repeated reinstallation. Option C is wrong because registry detection checks for a registry key created by the app; if the key exists, the rule correctly identifies the app as installed, preventing reinstallation loops. Option D is wrong because a custom script that returns exit code 0 when the app is not present would incorrectly report the app as installed, which would stop reinstallation attempts, not cause them.

44
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app as Required to all users. Users report that the app is not installing, and the Intune console shows the app status as 'Not applicable' for all devices. What is the most likely cause?

A.The app's detection rule is incorrect.
B.The app's requirement rules are not met by the devices.
C.The Intune Management Extension is not installed on the devices.
D.The app is not assigned to any groups.
AnswerB

When an app's requirement rules are not met, Intune marks the app as 'Not applicable' for those devices. This status indicates that the app is not intended for the device based on the defined requirements, such as OS version, architecture, or disk space. Reviewing and adjusting the requirement rules to match the device configuration resolves the issue.

Why this answer

The status 'Not applicable' in Intune for a Win32 app indicates that the app's requirement rules are not met by the device. This could be due to OS version, architecture, or other conditions defined in the requirement rules. Adjusting the requirement rules to match the device configuration resolves the issue.

Exam trap

The trap here is confusing 'Not applicable' with other statuses like 'Failed' or 'Not targeted', leading to troubleshooting the wrong component.

45
MCQhard

You are deploying a Win32 app that requires .NET Framework 4.8. You create a dependency in Intune for the .NET Framework app. However, some devices fail to install the parent app even though .NET Framework is present. What is the most likely issue?

A.The dependency version is set to 'Greater than' instead of 'Greater than or equal to'.
B.The dependency detection rule does not match the actual .NET installation.
C.The parent app is set to install before the dependency.
D.The dependency is set to 'Do not install automatically'.
AnswerB

Intune evaluates dependency detection rules before installing the parent app; if the rule checks the wrong registry path, file version or product code, it reports .NET Framework as absent even when installed. The parent app is then skipped, satisfying the stem's constraint that .NET is present yet installation fails.

Why this answer

Intune uses detection rules to verify whether a dependency is installed. If the detection rule for the .NET Framework dependency does not match the actual installation state (e.g., it checks for a registry key or file version that differs from what .NET 4.8 actually creates), Intune will incorrectly report the dependency as missing, blocking the parent app installation even though .NET is present.

Exam trap

The trap here is that candidates assume a dependency is automatically detected by its version number, but Intune requires an explicit detection rule that must exactly match the actual installation artifacts, and a mismatch in the detection rule (not the version logic) is the root cause of the failure.

How to eliminate wrong answers

Option A is wrong because setting the dependency version to 'Greater than' (instead of 'Greater than or equal to') would only cause failure if the installed .NET version is exactly 4.8 and the rule requires a version higher than 4.8, but the scenario states .NET is present, so version mismatch is not the core issue. Option C is wrong because Intune dependencies are designed to install the dependency before the parent app automatically; setting the parent to install before the dependency would violate dependency logic and is not a configurable option in Intune. Option D is wrong because setting a dependency to 'Do not install automatically' means Intune will not push the dependency to devices, but if the dependency is already present, the parent app should still install; the failure here is due to detection mismatch, not the auto-install setting.

46
MCQmedium

You manage Windows devices with Microsoft Intune. A required Win32 app (an .intunewin package) was assigned to a device group, but the app never installs and the device shows no error. The app's install command is `setup.exe /silent`, and the detection rule is a registry key that the installer writes only under HKLM\SOFTWARE. You confirm the app installs successfully when run manually as a standard user. What is the most likely cause?

A.The app must be assigned to a user group because Win32 apps cannot be assigned to device groups.
B.The install command runs in the user context, so the HKLM registry key cannot be written.
C.The .intunewin package must be signed with a code-signing certificate before it can install.
D.The detection rule must use a file path instead of a registry key for required apps.
AnswerB

By default, Win32 app install commands run in the system context (SYSTEM) on the device. If the package was configured to install in user context, the installer cannot write to HKLM, which requires administrative rights. Because the detection rule looks for that HKLM key, detection fails and Intune reports the app as not installed with no visible error, matching the scenario.

Why this answer

The key detail is that the detection rule checks an HKLM registry key, which can only be written with administrative privileges. If the Win32 app was configured to install in user context, the installer cannot create that key, so detection never succeeds and Intune reports the app as not installed without an obvious error. Switching the install behavior to system context allows the installer to write to HKLM and satisfy detection.

Exam trap

The trap here is assuming that a silent non-installation always means a packaging or assignment problem, when the actual cause is the install context being unable to write to a machine-wide registry location.

47
MCQeasy

You are asked to recommend a solution for deploying a web application as an icon on users' Windows 10 devices managed by Intune. Which app type should you use?

A.Windows app (Win32)
B.Microsoft Store app
C.Built-in app
D.Web link
AnswerD

A web link (web app) in Intune creates a shortcut icon on managed Windows devices that opens the specified URL in the default browser. It requires no packaging or installation, satisfying the requirement to surface a web application as an icon.

Why this answer

A web link app in Intune creates a shortcut on the Windows 10 desktop or Start menu that opens a specified URL in the default browser. This is the correct choice because the requirement is to deploy an icon that launches a web application, not to install a binary or package. Web link apps are lightweight, require no installation, and are managed via Intune's 'Web link' app type under Windows apps.

Exam trap

The trap here is that candidates confuse 'deploying a web application' with installing a traditional app, leading them to choose Win32 or Store app types, when the requirement is simply to place an icon that opens a URL.

How to eliminate wrong answers

Option A is wrong because Win32 apps are used for deploying traditional desktop applications (e.g., .exe, .msi) that require installation and local execution, not for simply placing a web shortcut. Option B is wrong because Microsoft Store apps are packaged UWP or Win32 apps distributed via the Store, requiring installation and local execution, not a web link. Option C is wrong because built-in apps are pre-installed Windows components (e.g., Notepad, Calculator) that cannot be used to add custom web shortcuts.

48
MCQhard

You manage Android Enterprise fully managed devices with Microsoft Intune. A critical line-of-business app must be installed silently on all devices, and users must not be able to uninstall it. The app is available as an APK. What should you do?

A.Upload the APK as a line-of-business app and assign it as available.
B.Upload the APK as a line-of-business app, assign it as required, and configure the app to be non-removable.
C.Deploy the app from the Managed Google Play store and assign it as required.
D.Use a mobile app configuration policy to push the APK to devices.
AnswerB

For Android Enterprise fully managed devices, Intune supports uploading APKs as line-of-business apps. A required assignment installs the app silently. Intune also provides an option to prevent users from uninstalling the app by marking it as non-removable, which directly satisfies both the silent installation and uninstall prevention requirements in the scenario.

Why this answer

Android Enterprise fully managed devices support line-of-business APK deployment through Intune. A required assignment ensures silent installation, and the non-removable setting prevents users from uninstalling the app. This combination is the correct way to meet both the silent install and uninstall prevention needs for a proprietary APK.

Exam trap

The trap here is thinking an available assignment or an app configuration policy can install an APK, or overlooking the non-removable setting.

49
MCQhard

Your organization plans to deploy a Win32 app to Windows 10 devices using Intune. The app requires the .NET Framework 4.8, which is not present on all devices. How should you handle this dependency?

A.Include the .NET installer in the same package
B.Use a PowerShell script to install .NET before the app
C.Add a dependency in Intune for the .NET Framework
D.Configure a detection rule for .NET
AnswerC

Adding a dependency in Intune lets the Win32 app's installation wait until the required .NET Framework 4.8 package is detected or installed on each device, satisfying the stem's constraint that the framework is missing on some devices. Intune evaluates dependencies before the app installs, ensuring the prerequisite is present first.

Why this answer

Intune's dependency feature allows you to specify another app (like .NET Framework 4.8) that must be installed before the Win32 app. Intune automatically installs the dependency app from the same Intune management extension context, ensuring the required runtime is present without manual scripting or bundling. This is the native, supported method for handling prerequisites in Win32 app deployment.

Exam trap

The trap here is that candidates confuse detection rules (which only check for existing software) with dependency management (which actually installs prerequisites), leading them to incorrectly choose Option D or attempt manual scripting in Option B.

How to eliminate wrong answers

Option A is wrong because including the .NET installer in the same package violates the principle of separation of concerns and can cause detection logic conflicts; Intune treats the package as a single app, so you cannot independently detect or manage .NET separately. Option B is wrong because using a PowerShell script to install .NET before the app is an unsupported workaround that bypasses Intune's dependency management, leading to unreliable detection and potential installation failures if the script fails. Option D is wrong because a detection rule only verifies whether the app is already installed; it does not trigger installation of the missing dependency, so .NET would remain absent and the app would fail to install.

50
MCQhard

You manage Windows devices with Microsoft Intune. You deploy a Win32 app that requires a specific registry key to be present before installation. You need to ensure the app installs only on devices that have the registry key. What should you configure?

A.A requirement rule in the app's properties.
B.A dependency on another app that creates the registry key.
C.A PowerShell script that checks for the registry key and installs the app if present.
D.A detection rule in the app's properties.
AnswerA

Requirement rules allow you to specify conditions that must be met for the app to install, such as operating system version, disk space, or a registry key. By configuring a requirement rule that checks for the registry key, Intune will only attempt installation on devices where the key exists.

Why this answer

Requirement rules in Intune Win32 app properties allow you to specify conditions that must be met for the app to be installed. You can check for a registry key, file, or other conditions. If the requirement is not met, the app is not installed.

This is the correct method to ensure installation only on devices with the specific registry key.

Exam trap

The trap here is confusing requirement rules with detection rules; requirement rules gate installation, detection rules verify it.

51
MCQhard

You use Microsoft Intune to manage Windows 11 devices. A critical Win32 app must install before any user signs in, and the installer cannot run in the user's context because it writes to protected registry keys and requires elevation. The app has no dependencies and does not need to be visible in the Company Portal. How should you configure the app?

A.Set Install behavior to User, and assign the app as Available to a device group.
B.Set Install behavior to System, and assign the app as Required to a device group.
C.Set Install behavior to System, and assign the app as Available to a user group.
D.Set Install behavior to User, and assign the app as Required to a device group.
AnswerB

System install context runs the installer as LocalSystem via the Intune Management Extension, which can write to protected registry keys and perform privileged operations without user interaction. Assigning as Required to a device group ensures the app is delivered to devices regardless of sign-in, satisfying the pre-sign-in requirement without publishing it in the Company Portal.

Why this answer

Because the installer needs privileged writes and must run without user interaction, configure Install behavior as System and assign the app as Required to a device group. System context lets the Intune Management Extension run the installer as LocalSystem, which handles protected registry writes silently, and Required device targeting guarantees delivery regardless of who signs in.

Exam trap

The trap here is pairing the correct System install context with an Available assignment, which reintroduces the user interaction the scenario forbids.

52
MCQeasy

A company uses Microsoft Intune to manage devices. They need to ensure that a critical line-of-business app is updated automatically on all devices. Which assignment type should they use?

A.Required
B.End-user notification
C.Uninstall
D.Available for enrolled devices
AnswerA

Required assignments push the app to every targeted device without user interaction, and Intune automatically installs updates when a newer version is detected. This satisfies the stem's constraint that the line-of-business app updates automatically across all devices, unlike Available, which depends on user initiation.

Why this answer

The Required assignment type in Microsoft Intune automatically installs and updates apps on managed devices without user interaction, making it the correct choice for ensuring a critical line-of-business app is updated automatically. This assignment enforces the app deployment policy by pushing the update to devices during their next check-in with the Intune service, typically within 8 hours.

Exam trap

The trap here is that candidates confuse 'Available for enrolled devices' with automatic updates, but it only provides optional installation from the Company Portal, not forced updates, which is a common misconception in MD-102 exams.

How to eliminate wrong answers

Option B is wrong because End-user notification is not an assignment type; it is a setting within an app assignment that controls whether users receive notifications about app updates, but it does not enforce automatic updates. Option C is wrong because Uninstall is an assignment type used to remove an app from devices, not to update it. Option D is wrong because Available for enrolled devices allows users to install the app from the Company Portal on demand, but it does not automatically update the app; users must manually trigger the update.

53
Multi-Selectmedium

You use Microsoft Intune to manage Windows 11 devices. You must deliver Microsoft 365 Apps (Microsoft 365 Apps for enterprise) to a group of devices and ensure that the deployment uses the Semi-Annual Enterprise Channel and excludes Access. You also need the installation to occur without user interaction. Which two actions should you perform? (Choose two.)

Select 2 answers
A.In the Microsoft 365 Apps app type in Intune, select the Semi-Annual Enterprise Channel from the update channel drop-down and remove Access from the list of Office apps.
B.Deploy a Win32 app that bundles the Office Deployment Tool and runs setup.exe with a configuration file as a system-context install.
C.Assign the Microsoft 365 Apps app as Required to the device group so it installs without user interaction.
D.Upload a custom Configuration.xml to the app's properties page and set the Office app suite to use the Current Channel.
E.Assign the Microsoft 365 Apps app as Available to the device group and instruct users to install it from the Company Portal.
AnswersA, C

The Microsoft 365 Apps (Windows 10 and later) app type in Intune includes configuration pages for update channel and app selection, so choosing Semi-Annual Enterprise Channel and deselecting Access directly satisfies both configuration requirements without scripting or XML editing.

Why this answer

The built-in Microsoft 365 Apps app type in Intune exposes update channel and app selection on its configuration pages, and a Required assignment installs the suite silently on targeted devices. Together these two actions deliver the specified channel while omitting Access and avoiding user interaction.

Exam trap

The trap here is assuming a custom XML or Win32 wrapper is mandatory for channel and app selection, when the native Microsoft 365 Apps app type already exposes those options.

54
MCQhard

Your organization uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app using detection rules. The app installs but the detection rule incorrectly reports failure, causing repeated installation attempts. What is the best way to resolve this?

A.Uninstall and redeploy the app
B.Update the detection rule to accurately reflect installed state
C.Reinstall the app manually
D.Modify the installation command to suppress output
AnswerB

Detection rules determine whether Intune considers an app installed; a rule that misreads the installed state triggers repeated remediation. Correcting the rule to match the actual installed condition stops the false failure reporting, satisfying the requirement to halt repeated installation attempts.

Why this answer

The detection rule is the mechanism Intune uses to determine whether a Win32 app is already installed. If the rule incorrectly reports failure despite successful installation, Intune will repeatedly attempt to reinstall the app. Updating the detection rule to accurately reflect the installed state (e.g., checking for the correct file, registry key, or version) stops the unnecessary reinstall loop without requiring manual intervention or reconfiguration of the deployment.

Exam trap

The trap here is that candidates often assume the issue is with the installation command or the app itself, rather than recognizing that Intune's detection logic is the sole trigger for reinstallation attempts.

How to eliminate wrong answers

Option A is wrong because uninstalling and redeploying the app does not fix the root cause—the flawed detection rule—so the same incorrect detection will trigger reinstallation again after redeployment. Option C is wrong because manually reinstalling the app does not correct the detection rule; Intune will still detect the app as not installed based on the faulty rule and continue its reinstall attempts. Option D is wrong because modifying the installation command to suppress output does not change how Intune evaluates the detection rule; suppression only hides logs and does not address the mismatch between actual installation state and detection logic.

55
MCQmedium

You are an administrator for a company that uses Microsoft Intune. You have an iOS line-of-business (LOB) app that you need to deploy to all iOS devices. The app is signed with an enterprise certificate. You upload the app to Intune and assign it as required. Users report that the app fails to install. What is the most likely cause?

A.The app was not packaged using the Microsoft Win32 Content Prep Tool.
B.The app assignment is set to required, but it should be set to available for iOS LOB apps.
C.The iOS devices are not enrolled in Intune as corporate-owned devices.
D.The app is not properly signed with a valid provisioning profile.
AnswerD

iOS LOB apps must be signed with a valid provisioning profile that includes the devices' UDIDs or uses enterprise distribution. If the provisioning profile is invalid, expired, or does not include the necessary devices, installation fails. Since the app is signed with an enterprise certificate, the provisioning profile must be correctly configured for enterprise distribution. A common cause of failure is an expired or misconfigured provisioning profile.

Why this answer

iOS line-of-business apps must be signed with a valid provisioning profile that supports enterprise distribution. If the provisioning profile is expired, does not include the necessary devices, or is otherwise invalid, the app will fail to install. This is the most likely cause when an enterprise-signed app fails to deploy.

Proper signing and provisioning are critical for successful iOS LOB app deployment via Intune.

Exam trap

The trap here is assuming that the assignment type or enrollment method is the issue, when the most common cause of iOS LOB app installation failure is an invalid or expired provisioning profile.

56
MCQhard

You are an endpoint administrator for a company that uses Microsoft Intune. You deploy a Win32 app to Windows 10 devices using the Intune Management Extension. The app installation fails on some devices with error code 0x87D1041C. You need to resolve the installation failure. What is the most likely cause?

A.The app content is not fully uploaded to Intune.
B.The detection rule is not correctly identifying the app after installation.
C.The app installer requires a reboot that was not allowed.
D.The Intune Management Extension is not installed on the device.
AnswerB

Error code 0x87D1041C is specifically related to detection rule failures in Intune Win32 app deployments. It means the app installed but the detection rule did not find it, so Intune reports failure. Common causes include incorrect file path, version, or registry key in the detection rule. Reviewing and correcting the detection rule resolves the issue.

Why this answer

Error 0x87D1041C is a detection rule failure. It indicates the app installed but the detection rule did not find it, so Intune marks it as failed. The most likely cause is an incorrect detection rule, such as wrong file path, version, or registry key.

Correcting the detection rule resolves the issue.

Exam trap

The trap here is assuming the error is due to installation issues rather than detection, leading to troubleshooting the wrong component.

57
MCQmedium

Your organization uses Microsoft Intune to deploy apps to Windows 11 devices. You need to ensure that a Win32 app installs only when the device has at least 4 GB of RAM. What should you configure?

A.A dependency rule that includes a RAM check
B.A return code for insufficient RAM
C.A requirement rule that specifies minimum RAM
D.A detection rule for RAM
AnswerC

A requirement rule in Intune evaluates device attributes before installation, letting you specify minimum RAM as a custom requirement. This directly satisfies the stem's 4 GB threshold, blocking deployment on under-spec devices. Detection rules only verify presence post-install, and applicability rules belong to Configuration Manager, not Win32 app deployment.

Why this answer

To enforce a hardware prerequisite like minimum RAM for a Win32 app in Microsoft Intune, you configure a requirement rule. Requirement rules define the device conditions (e.g., operating system architecture, disk space, or RAM) that must be met before the app can install. Option C is correct because it directly specifies a minimum RAM value as a requirement rule, ensuring the app installs only on devices with at least 4 GB of RAM.

Exam trap

The trap here is confusing requirement rules (which enforce hardware/software prerequisites) with detection rules (which verify existing installation) or dependency rules (which manage app installation order), leading candidates to incorrectly select a detection or dependency rule for a hardware prerequisite.

How to eliminate wrong answers

Option A is wrong because dependency rules control the order of app installation (e.g., requiring another app to be installed first), not hardware checks like RAM. Option B is wrong because return codes define how Intune interprets the exit code from the app installer (e.g., success, reboot, or failure), but they cannot enforce a prerequisite condition before installation begins. Option D is wrong because detection rules are used to determine whether an app is already installed (e.g., checking for a file or registry key), not to evaluate hardware requirements before installation.

58
Multi-Selecthard

Which THREE factors can cause a required app deployment to fail on a Windows 10 device managed by Intune? (Choose three.)

Select 3 answers
A.The device has an app update policy that blocks updates.
B.The device is not connected to the internet.
C.The user is not assigned to the app.
D.The device does not meet the app's requirement rules.
E.The app's dependency is not installed.
AnswersB, D, E

A required app deployment relies on the Intune Management Extension polling Microsoft Entra ID and Intune endpoints to receive policy and content. Without internet connectivity, the device cannot check in, so the assignment never reaches it and installation never triggers. This directly satisfies the stem's requirement for a cause of deployment failure.

Why this answer

Option B is correct because a required Intune app deployment relies on the device checking in with the Intune service and downloading content from Intune/Windows Delivery Optimization, so without internet connectivity the device cannot receive the policy or the app payload and the install fails. Option D is correct because requirement rules (such as OS version, architecture, disk space, or registry checks) are evaluated before installation; if the device does not satisfy them, Intune marks the app as not applicable and the required install does not proceed. Option E is correct because dependencies (for example, a Win32 app that requires another app or a specific framework) must be installed first; if a dependency fails or is missing, the dependent app's installation fails.

Option A is not correct because an app update policy blocking updates affects updating already-installed apps, not the initial required deployment of an app. Option C is not correct because a required deployment targets device or user groups; if the user is not assigned, the app simply is not deployed to that user rather than causing a deployment that was assigned to fail.

Exam trap

The trap here is that candidates often confuse 'app update policy' (which controls updates) with 'app deployment policy' (which controls initial installation), leading them to incorrectly select Option A as a cause of deployment failure.

59
MCQeasy

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a Microsoft Store app (new) to a set of users, and the app must be installed automatically without requiring them to visit the Company Portal. Which assignment intent should you choose for the user group?

A.Available for enrolled devices
B.Required
C.Available for enrolled devices with a deadline
D.Uninstall
AnswerB

Required intent tells Intune to install the app automatically on targeted devices or for targeted users without any action in the Company Portal. For a Microsoft Store app (new) assigned to a user group, Required delivers the app silently to those users' enrolled devices, matching the automatic-install requirement.

Why this answer

Required is the assignment intent that makes Intune install an app automatically for the targeted users or devices. Because the app must install without the user opening the Company Portal, Available intent is unsuitable, and Uninstall would remove rather than add the app. Required on the user group produces the silent automatic installation described.

Exam trap

The trap here is confusing Available with Required, since both deliver the app but only Required installs it without user action.

60
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps for enterprise to 500 devices. The devices are in a hybrid Azure AD joined configuration. The administrator wants to use Intune to deploy the apps. Which deployment method should the administrator use?

A.Use the Office Deployment Tool (ODT) to create a configuration file and deploy via Intune as a Win32 app.
B.Use Group Policy to deploy the Office 2019 suite.
C.Add a 'Microsoft 365 Apps for Windows 10 and later' app in Intune and assign it to the devices.
D.Upload the Office installation files as a line-of-business (LOB) app.
AnswerC

The built-in Microsoft 365 Apps app type in Intune deploys the suite to Windows 10 and later devices, supporting hybrid Azure AD joined endpoints. Assigning it to the device group satisfies the 500-device deployment requirement without packaging.

Why this answer

Intune provides a built-in 'Microsoft 365 Apps for Windows 10 and later' app type that is specifically designed to deploy and manage Microsoft 365 Apps for enterprise. This method uses Intune's native integration with the Office Content Delivery Network (CDN) to download and install the latest version of Office, and it supports hybrid Azure AD joined devices without requiring additional tools or configuration files.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing the Office Deployment Tool (Option A) because they think it provides more control, but they miss that Intune's native 'Microsoft 365 Apps' app type is the simplest and most appropriate method for standard deployments, especially when no custom XML configuration is required.

How to eliminate wrong answers

Option A is wrong because while the Office Deployment Tool (ODT) can be used to create a configuration file, deploying it as a Win32 app is unnecessarily complex and bypasses Intune's native Office app management capabilities, which provide automatic updates and simplified assignment. Option B is wrong because Group Policy is not an Intune deployment method; it relies on on-premises Active Directory and does not integrate with Intune for cloud-managed device deployment. Option D is wrong because uploading Office installation files as a line-of-business (LOB) app is intended for single-file or simple app packages, not for the multi-component, dynamically updated Microsoft 365 Apps suite, and it would require manual updates and lack the built-in configuration options.

61
MCQeasy

You manage a fleet of Android Enterprise devices. You need to ensure that only approved apps from the managed Play Store can be installed. What configuration should you enable?

A.Set the device to 'Fully managed' and disable unknown sources.
B.Deploy an app configuration policy that blocks sideloading.
C.Configure a device restriction policy to allow only managed Google Play apps.
D.Use a compliance policy to block non-compliant apps.
AnswerC

Device restriction policies in Microsoft Intune expose a managed Google Play setting that blocks installation from unknown sources, so only apps approved in the managed Play Store can be installed. This directly satisfies the requirement to restrict Android Enterprise devices to approved applications.

Why this answer

A device restriction policy in Microsoft Intune allows you to restrict app installation to only the managed Google Play store. By configuring the 'Allow only managed Google Play apps' setting, you ensure that users cannot install apps from unapproved sources, effectively controlling the app ecosystem on Android Enterprise devices.

Exam trap

The trap here is that candidates often confuse reactive compliance policies (which detect non-compliant apps after installation) with proactive device restriction policies (which prevent installation entirely), leading them to choose Option D instead of the correct proactive setting.

How to eliminate wrong answers

Option A is wrong because setting the device to 'Fully managed' and disabling unknown sources does not restrict installations to only managed Google Play apps; it only prevents sideloading from unknown sources, but users could still install apps from the public Play Store. Option B is wrong because an app configuration policy is used to configure app-specific settings (e.g., account credentials or permissions), not to block sideloading or restrict app sources; blocking sideloading is a device restriction. Option D is wrong because a compliance policy can mark devices as non-compliant if non-approved apps are detected, but it does not prevent installation of those apps in the first place; it only reacts after the fact.

62
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune. You need to deploy Microsoft 365 Apps to Windows devices. The company requires that the apps update automatically from the Office CDN and that users cannot modify the update channel. Which method should you use?

A.Deploy Microsoft 365 Apps using the Microsoft Store app (new) and configure automatic updates.
B.Deploy Microsoft 365 Apps as a Win32 app with a custom configuration XML.
C.Deploy Microsoft 365 Apps as a line-of-business app using an MSI package.
D.Deploy Microsoft 365 Apps using the Microsoft 365 Apps app type in Intune and configure update settings in the app suite configuration.
AnswerD

The Microsoft 365 Apps app type in Intune allows you to configure update settings, including the update channel and automatic updates from the Office CDN. You can also lock the channel to prevent user changes. This method provides the required control and meets the scenario's requirements.

Why this answer

The Microsoft 365 Apps app type in Intune is designed specifically for deploying and managing Microsoft 365 Apps. It includes options to set the update channel and enforce automatic updates from the Office CDN, and it allows you to prevent users from changing these settings. This is the most efficient and supported method.

Exam trap

The trap here is assuming that any deployment method that installs Microsoft 365 Apps will also provide the necessary update control, when only the built-in app type does.

63
MCQhard

Contoso Ltd. is a financial services company with 2,000 users. They use Microsoft Intune to manage Windows 10 devices. The company has a strict security policy that requires all devices to have a specific set of security applications installed: an antivirus (AV) app, a disk encryption app, and a VPN client. These apps are all line-of-business (LOB) Win32 apps packaged as .intunewin files. The administrator created a Win32 app for each and assigned them as 'Required' to all devices. After the deployment, the administrator notices that the apps are not installing on approximately 10% of devices. The devices are online and have connectivity. The Intune Management Extension is running. When the administrator checks the Intune Management Extension logs on a failing device, they see the following error: 'Failed to download content. Error: 0x80070002 - The system cannot find the file specified.' What is the most likely cause?

A.The content for the Win32 app was not uploaded correctly or is missing from Intune.
B.The Intune Management Extension does not have permission to install apps on those devices.
C.The user is not logged in, so the app cannot be installed.
D.The app detection rules do not match the installed version.
AnswerA

Error 0x80070002 means the Intune Management Extension cannot locate the app content in the local cache after download, which occurs when the .intunewin content was never successfully uploaded to Intune, leaving devices nothing to retrieve.

Why this answer

The error 0x80070002 ('The system cannot find the file specified') in the Intune Management Extension logs indicates that the client is attempting to download the Win32 app content from Intune, but the content blob is missing or inaccessible. This typically occurs when the .intunewin file was not uploaded correctly, the upload was interrupted, or the content was deleted from Intune after assignment. Since the extension is running and connectivity is confirmed, the issue is server-side content availability, not client-side permissions or detection logic.

Exam trap

The trap here is that candidates often confuse a download failure with a detection rule mismatch or permission issue, but the specific error code 0x80070002 points directly to missing content on the server side, not client-side configuration problems.

How to eliminate wrong answers

Option B is wrong because the Intune Management Extension runs as SYSTEM and does not require additional permissions to install apps; a permission issue would manifest as an access denied error, not a 'file not found' error. Option C is wrong because Win32 apps assigned as 'Required' install in the system context regardless of user login state; user presence is irrelevant for system-context installations. Option D is wrong because detection rules only affect whether the app is considered installed after the download and installation attempt; they do not cause a download failure with error 0x80070002, which occurs before any detection logic runs.

64
MCQhard

You are deploying a Win32 app that requires administrator privileges to install. The app runs on Windows 11 devices. How should you configure the app in Intune to ensure it installs with elevated privileges?

A.Set the app install behavior to 'System'.
B.Set the app to run in user context.
C.Use a PowerShell script to run the installer.
D.Configure a detection rule to check for admin rights.
AnswerA

Setting install behaviour to System runs the Win32 app installer in the SYSTEM context, granting local administrator rights. This satisfies the elevation requirement, whereas User context installs with the signed-in user's standard privileges and would fail.

Why this answer

Setting the install behavior to 'System' in Intune for a Win32 app ensures the installer runs with the SYSTEM account, which inherently has administrator privileges. This is required for apps that demand elevated rights during installation, as the SYSTEM account bypasses user account control (UAC) and can write to protected system locations like Program Files or the registry.

Exam trap

The trap here is that candidates often confuse 'install behavior' with 'detection rules' or 'script execution,' mistakenly thinking a PowerShell script or a detection rule can enforce elevation, when in fact only the 'System' context setting in Intune ensures the installer runs with the necessary administrator privileges.

How to eliminate wrong answers

Option B is wrong because setting the app to run in user context executes the installer with the logged-on user's permissions, which typically lack the administrator privileges needed for this app, causing installation failure. Option C is wrong because using a PowerShell script to run the installer does not inherently elevate privileges; the script runs under the same context as the Intune deployment agent unless explicitly configured with a separate elevation mechanism, which is not specified. Option D is wrong because configuring a detection rule to check for admin rights does not grant or enforce elevation during installation; detection rules only verify whether the app is already installed, not how it installs.

65
MCQhard

You are deploying a line-of-business (LOB) app to iOS devices managed by Intune. The app requires a specific configuration to access internal resources. Which approach should you use to deliver the configuration?

A.Assign a custom device configuration profile
B.Create an App Configuration Policy targeting managed devices
C.Deploy an App Protection Policy
D.Use Apple Volume Purchase Program (VPP) tokens
AnswerB

An App Configuration Policy for managed devices pushes key-value settings to the app via the Intune MDM channel, so the LOB app receives its internal-resource configuration without repackaging. This satisfies the stem's requirement to deliver configuration to managed iOS devices.

Why this answer

An App Configuration Policy targeting managed devices is the correct approach because it allows you to supply XML or JSON settings directly to the LOB app on iOS devices enrolled in Intune. This policy is applied when the app runs, enabling it to access internal resources without requiring a separate device profile or user interaction.

Exam trap

The trap here is that candidates often confuse App Configuration Policies (which deliver app-specific settings) with App Protection Policies (which enforce data protection), leading them to select Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because a custom device configuration profile manages device-level settings (e.g., Wi-Fi, VPN, restrictions) and cannot deliver app-specific configuration settings to a line-of-business app. Option C is wrong because an App Protection Policy manages data protection and access controls (e.g., PIN, encryption, save-as restrictions) for apps that integrate with Intune SDK, but it does not deliver app-specific configuration settings. Option D is wrong because Apple Volume Purchase Program (VPP) tokens are used to manage app licensing and distribution, not to deliver app configuration settings.

66
MCQeasy

A company uses Microsoft Intune to manage Android Enterprise personally owned work profile devices. Employees report that the corporate email app allows copying text into personal apps on the same device. You need to prevent copy and paste of corporate data into personal apps while leaving personal apps otherwise unaffected. What should you configure?

A.A conditional access policy requiring compliant devices for the corporate email app.
B.A device compliance policy for Android Enterprise that marks devices as noncompliant when data sharing is detected.
C.A device restrictions configuration profile that blocks the clipboard service on the Android device.
D.An app protection policy targeting the managed apps, with the 'Restrict cut, copy, and paste between other apps' setting configured for policy-managed apps.
AnswerD

App protection policies on Android Enterprise work profile devices govern data movement between managed and unmanaged apps, and the cut-copy-paste restriction blocks corporate data from leaving managed apps while leaving personal apps usable. This directly addresses the reported behavior without affecting the rest of the device.

Why this answer

App protection policies create a data boundary around managed apps, and the cut-copy-paste restriction setting specifically prevents corporate data from being pasted into unmanaged personal apps on Android Enterprise work profile devices while preserving personal app functionality.

Exam trap

The trap here is confusing device compliance or conditional access, which gate access to resources, with app protection policies that actually control data movement between apps.

67
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft 365 Apps for enterprise suite to all devices. Which app type should you use in Intune?

A.Web link
B.Windows app (Win32)
C.Microsoft 365 Apps for Windows 10 and later
D.Line-of-business app
AnswerC

The Microsoft 365 Apps for Windows 10 and later app type is purpose-built for deploying the suite through Intune, handling installation and update channels natively. It satisfies the requirement to roll out Microsoft 365 Apps for enterprise to all managed Windows 10 devices without packaging.

Why this answer

The 'Microsoft 365 Apps for Windows 10 and later' app type in Intune is specifically designed to deploy and manage Microsoft 365 Apps for enterprise (formerly Office 365 ProPlus) on Windows devices. It provides a streamlined, built-in experience with automatic updates and configuration options tailored for Microsoft 365 Apps, such as selecting update channels and removing previous installations. This is the recommended method for deploying the suite to Intune-managed Windows 10 devices.

Exam trap

MD-102 often tests the distinction between different Intune app types, and candidates may confuse the Microsoft 365 Apps app type with Windows app (Win32) because both can deploy desktop applications. The trap is that Win32 apps require manual packaging and do not offer the same integrated management for Microsoft 365 Apps.

How to eliminate wrong answers

Option A is wrong because a web link simply creates a shortcut to a web page and cannot install or manage a full desktop application suite. Option B is wrong because Windows app (Win32) is used for custom or third-party Win32 applications that require packaging with the IntuneWinAppUtil tool; while it could technically deploy Microsoft 365 Apps, it is not the purpose-built, supported method and lacks the integrated management features. Option D is wrong because line-of-business apps are for custom or purchased apps that are not available in the Microsoft Store, and they do not provide the specific deployment and update capabilities for Microsoft 365 Apps.

68
MCQhard

A company uses Microsoft Intune to manage iOS/iPadOS devices enrolled through Apple Business Manager. They must distribute a proprietary in-house app that is not in the App Store to 500 supervised devices, and the app must be silently installed without user prompts. Which deployment method should they use?

A.Deploy the app as a Microsoft Store app for iOS and assign it as available.
B.Deploy the app as a line-of-business app using the iOS store app type and require installation.
C.Deploy the app as an iOS line-of-business app and assign it as required to the device group.
D.Deploy the app as a web link (web clip) and assign it as required.
AnswerC

The iOS line-of-business app type accepts an internal IPA uploaded directly to Intune. When assigned as required to supervised devices, Intune pushes a silent install through the MDM channel without user interaction. This matches the need to distribute a proprietary app to many supervised devices with no prompts, which store app types or user-driven installs cannot guarantee.

Why this answer

iOS line-of-business apps are internal IPA packages uploaded to Intune and delivered via MDM. For supervised devices with a required assignment, installation is silent and automatic, which is essential when distributing proprietary software to many devices without user involvement. Store app types and web clips either target public apps or create shortcuts, so they cannot fulfill this requirement.

Exam trap

The trap here is assuming any iOS app type supports silent install, or that 'available' assignment can install without user action.

69
MCQmedium

You are planning to deploy a Win32 app to Windows 10 devices using Microsoft Intune. The app requires a specific registry key to be present before installation. How should you ensure the prerequisite is met?

A.Configure the installation behavior as 'System' to bypass user context.
B.Add the registry key as a dependency.
C.Set a requirement rule for the registry key.
D.Configure a detection rule to verify the registry key exists.
AnswerC

Requirement rules evaluate device conditions before installation, so a registry-based requirement rule blocks deployment unless the specified key exists. This satisfies the prerequisite constraint by preventing installation on devices lacking the required registry key, without scripting custom detection logic.

Why this answer

Requirement rules are used to evaluate conditions that must be met before the app installation begins. By setting a requirement rule to check for the existence of the specific registry key, Intune will verify the prerequisite and only install the app if the key is present. Detection rules, on the other hand, are intended to verify the app's installation status after deployment, not to check prerequisites before installation.

Therefore, option D is incorrect.

Exam trap

The trap is that candidates often confuse requirement rules with detection rules. Requirement rules are pre-installation checks, while detection rules are post-installation checks. In this scenario, the need is to ensure a registry key exists before installation, so a requirement rule (option C) is the correct choice, not a detection rule (option D).

How to eliminate wrong answers

Option A is wrong because configuring the installation behavior as 'System' only changes the user context under which the app runs (system vs. user), but does not verify or enforce the presence of a registry key prerequisite. Option B is wrong because dependencies in Intune are used to install other apps or files before the main app, not to check for registry keys; dependencies reference other Win32 apps or Microsoft Store apps, not registry values. Option C is wrong because setting a requirement rule for the registry key is exactly what is needed, but the option incorrectly states 'Set a requirement rule for the registry key'—while this is conceptually correct, the phrasing is ambiguous; however, the exam expects D as the correct answer because detection rules verify post-installation existence, not prerequisites.

Wait—re-evaluating: Option C is actually the correct approach (requirement rules check prerequisites), but the question's correct answer is listed as D, which is a trap. In reality, requirement rules (Option C) are used to check prerequisites like registry keys before installation, while detection rules (Option D) verify after installation. The exam answer key marks D as correct, which is a deliberate error to test understanding of the difference between requirement and detection rules.

Therefore, Option C is wrong because requirement rules are the correct mechanism for pre-installation checks, not detection rules; the exam trap mislabels the correct answer.

70
MCQeasy

A company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. The IT team needs to deploy a set of Microsoft Store apps to all managed Windows devices. They want the apps to be installed automatically without user interaction and to be updated automatically by the Store. Which app type should they use in Intune?

A.Microsoft 365 Apps
B.Microsoft Store app (new)
C.Windows app (Win32)
D.Microsoft Store app (legacy)
AnswerB

The Microsoft Store app (new) type integrates with the Microsoft Store and supports automatic updates and silent installation when assigned as Required. It is the current recommended method for deploying Store apps to Windows devices. It allows the IT team to meet the requirement for automatic installation and updates without user action.

Why this answer

The Microsoft Store app (new) type is designed for deploying Store apps to Windows devices with support for silent installation and automatic updates from the Store. Assigning the app as Required ensures it installs without user interaction, and the Store handles updates. This matches the IT team's requirements exactly.

Exam trap

The trap here is selecting the legacy Store app type, which is deprecated and does not provide the modern automatic update behavior of the new Store app type.

71
MCQeasy

You need to deploy an Android Enterprise app to corporate-owned work profile devices. The app is available on Google Play. Which deployment method should you use?

A.Microsoft Store for Business
B.Managed Google Play
C.Apple Business Manager
D.Side-loading via Intune
AnswerB

Managed Google Play integrates directly with Microsoft Intune, letting you approve and deploy store apps silently to corporate-owned work profile devices without user authentication or sideloading. This satisfies the stem's requirement: the app is publicly available on Google Play, so no private or line-of-business packaging is needed.

Why this answer

Managed Google Play is the correct deployment method for Android Enterprise corporate-owned work profile devices because it provides a curated, enterprise-specific app catalog that integrates directly with Intune. Google Play hosts the app, and Intune uses Managed Google Play to approve, deploy, and manage apps on these devices without requiring user interaction.

Exam trap

The trap here is that candidates may confuse Managed Google Play with general Google Play Store access, or incorrectly assume that Microsoft Store for Business can handle Android apps because of its 'Store' branding, but the exam specifically tests the Android Enterprise management channel.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business is designed for Windows 10/11 devices and does not support Android app deployment. Option C is wrong because Apple Business Manager is used exclusively for deploying apps to iOS/iPadOS devices, not Android. Option D is wrong because side-loading via Intune requires the app to be packaged as a line-of-business (LOB) app and uploaded directly, which is unnecessary when the app is already available on Google Play and can be managed through Managed Google Play.

72
MCQhard

Refer to the exhibit. An administrator retrieves a list of Win32 apps. They notice that one app shows installExperience as 'system' and detectionRules as 'fileVersion' with version '1.0.0'. The app fails to install on some devices. The event viewer on a failing device shows 'The app was installed but detection rule did not match'. What is the most likely cause?

A.The PowerShell cmdlet is deprecated
B.The installExperience should be 'user' instead of 'system'
C.The app requires a reboot that is not handled
D.The detection rule expects version 1.0.0 but the installed version is different
AnswerD

The fileVersion detection rule compares the installed binary's actual version against the specified 1.0.0 value. If the installer deploys a different build, detection fails and Intune reports the app as not installed, matching the event log message. This satisfies the stem's constraint: installation succeeded but the version check mismatched.

Why this answer

The detection rule is configured to check for file version '1.0.0', but the installed version on the failing device does not match this value. When Intune deploys a Win32 app, it uses the detection rule to verify successful installation; if the rule does not match, the app is marked as failed even though the installation itself completed. This mismatch is the most likely cause of the event viewer message.

Exam trap

The trap here is that candidates may assume the 'installExperience' setting (system vs. user) controls installation success, but the actual failure is caused by a mismatch between the detection rule's expected version and the actual installed version.

How to eliminate wrong answers

Option A is wrong because the PowerShell cmdlet (Get-Win32App, likely from the Microsoft Graph or Intune module) is not deprecated; the issue is with detection rule logic, not cmdlet deprecation. Option B is wrong because 'installExperience' as 'system' means the app installs in the system context, which is appropriate for per-machine installations; changing to 'user' would not fix a detection rule version mismatch. Option C is wrong because a reboot requirement would typically cause a different error (e.g., 'reboot pending' or installation failure), not a detection rule mismatch; the event explicitly states the app was installed but detection failed.

73
MCQmedium

Refer to the exhibit. An Intune administrator configured a Win32 app with the settings shown. What is the expected behavior when the app installation exits with return code 3010?

A.The device restarts immediately
B.The installation is marked as failed
C.The device may restart after installation outside of active hours
D.The app is not installed
AnswerC

Return code 3010 signals a soft reboot requirement, so Intune flags the app as installed but pending restart. The device then restarts outside configured active hours, honouring the stem's constraint that users must not be interrupted during working time. Hard reboot codes such as 1641 trigger an immediate restart instead.

Why this answer

Return code 3010 is a standard Windows Installer code indicating a reboot is required. In Intune, a Win32 app that exits with 3010 is treated as a successful installation, but the device may be restarted outside of active hours to apply changes. This behavior aligns with the 'Device restart behavior' setting configured in the app's properties, which defers the restart to a maintenance window.

Exam trap

The trap here is that candidates often confuse return code 3010 with a failure code, assuming any non-zero exit code means the installation failed, but Intune specifically treats 3010 as a success with a pending reboot, not an error.

How to eliminate wrong answers

Option A is wrong because Intune does not force an immediate restart after a 3010 return code; instead, it schedules the restart during non-active hours to minimize user disruption. Option B is wrong because 3010 is not a failure code; Intune interprets it as a successful installation that requires a reboot, so the installation is marked as successful, not failed. Option D is wrong because the app is installed successfully; the 3010 code only indicates that a reboot is pending to complete the configuration, not that the installation itself failed.

74
MCQeasy

You manage Windows 10 devices with Microsoft Intune. You need to deploy Microsoft 365 Apps to a group of devices. You want to ensure that the apps receive updates automatically from the Microsoft 365 Apps update channel. What should you configure in the Microsoft 365 Apps app settings?

A.Deploy the Microsoft 365 Apps as a Win32 app and configure a scheduled task to run updates.
B.Configure a Windows Update ring to deliver Microsoft 365 Apps updates.
C.Set the update channel to Current Channel and enable automatic updates.
D.Set the update channel to Semi-Annual Channel and disable automatic updates.
AnswerC

When deploying Microsoft 365 Apps with Intune, you can select the update channel, such as Current Channel, Monthly Enterprise Channel, or Semi-Annual Channel. Enabling automatic updates ensures that the apps receive updates from the selected channel. This is the correct configuration to keep Microsoft 365 Apps up to date automatically.

Why this answer

The Microsoft 365 Apps app type in Intune includes settings for update channel and automatic updates. Selecting an update channel and enabling automatic updates ensures that the apps receive updates from that channel without manual intervention. This is the standard and supported method for keeping Microsoft 365 Apps current.

Exam trap

The trap here is assuming that Windows Update rings manage Microsoft 365 Apps updates, when they only manage Windows updates.

75
MCQeasy

A user reports that Microsoft 365 Apps for enterprise is not installing on their Windows 10 device. The app is assigned as 'Available' to the user group. What must the user do to trigger the installation?

A.Wait for the next device sync
B.Open the Company Portal app and install from there
C.Restart the device
D.Log off and log back in
AnswerB

An 'Available' assignment publishes the app to the Company Portal rather than pushing it automatically. The user must open the Company Portal app on the device and select Install, which triggers the Intune Management Extension to download and install Microsoft 365 Apps.

Why this answer

When an app is assigned as 'Available' to a user group in Intune, it appears in the Company Portal but does not install automatically — the user must manually initiate installation. The user opens the Company Portal app (or website), locates the app, and clicks Install. This is the designed behavior for 'Available' assignments, which are user-driven rather than push-based.

Exam trap

MD-102 often tests the difference between 'Required' (auto-install) and 'Available' (user-initiated via Company Portal) assignments, catching candidates who assume all assignments install automatically.

How to eliminate wrong answers

Option A is wrong because device sync applies to 'Required' assignments, which push installation automatically; 'Available' apps are not installed by sync. Option C is wrong because restarting the device does not trigger installation of an 'Available' app — the user must explicitly install it from the Company Portal. Option D is wrong because logging off and back on does not initiate installation; the app remains available but uninstalled until the user acts.

Page 1 of 2 · 104 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage applications questions.