Courseiva

CCNA Manage applications Questions

29 of 104 questions · Page 2/2 · Manage applications · Answers revealed

76
MCQeasy

A company uses Microsoft Intune to manage Windows devices. The IT team needs to deploy a new Microsoft Store app (new) to a group of users. The app must install automatically when users sign in, and users must not be able to uninstall it. Which assignment type should you configure for the app?

A.Available for enrolled devices with a required install deadline
B.Required
C.Uninstall
D.Available for enrolled devices
AnswerB

Required assignments install the app automatically on targeted devices without user action. For Microsoft Store apps (new), required assignment also prevents users from uninstalling the app through normal means, satisfying both conditions. This is the correct assignment type when the app must be present and managed by IT.

Why this answer

Required assignments push the app to devices automatically and, for Microsoft Store apps (new), prevent users from uninstalling it. Available assignments leave installation to the user, Uninstall assignments remove the app, and there is no available-with-deadline assignment type. Required is the only choice that meets both automatic installation and uninstallation prevention.

Exam trap

The trap here is assuming any assignment that mentions a deadline forces installation, when available assignments never include deadlines and always leave the choice to the user.

77
MCQeasy

You need to deploy a web link as an app to Android Enterprise work profile devices. Users should see the link in the Company Portal app. What type of app should you add in Microsoft Intune?

A.iOS/iPadOS web clip
B.Android store app
C.Managed Google Play web link
D.Windows app package (MSI)
AnswerC

A Managed Google Play web link creates a shortcut that appears in the Company Portal on Android Enterprise work profile devices, opening the URL in the managed browser. This satisfies the requirement for users to see the link as an app.

Why this answer

Managed Google Play web links are the correct app type for deploying a web link as an app to Android Enterprise work profile devices. When added in Intune, this web link appears in the Company Portal app under the 'Apps' tab, allowing users to open the link directly. Other app types like iOS web clips or Android store apps do not support this specific deployment method for Android Enterprise work profiles.

Exam trap

The trap here is that candidates often confuse 'web link' deployment with 'web clip' (iOS) or assume any app type can deliver a URL, but only Managed Google Play web links are purpose-built for Android Enterprise work profiles in Intune.

How to eliminate wrong answers

Option A is wrong because iOS/iPadOS web clips are designed for Apple devices and cannot be deployed to Android Enterprise work profile devices. Option B is wrong because Android store apps are actual APK-based applications from the Google Play Store, not web links; they require a package to install, not a URL. Option D is wrong because Windows app packages (MSI) are for Windows devices and have no relevance to Android Enterprise work profile deployments.

78
MCQeasy

You need to make a web app available to users in your organization through Microsoft Intune Company Portal. Which app type should you create in Intune?

A.iOS store app
B.Web app
C.Windows app (Win32)
D.Android store app
AnswerB

A web app type creates a shortcut in the Company Portal that launches the URL in the device browser, requiring no packaging or installation. This satisfies the requirement to publish a web app to users through the portal.

Why this answer

To make a web app available through Microsoft Intune Company Portal, you must create a 'Web app' type. This app type allows you to add a link to a web application that users can access via the Company Portal, without needing to install a native client. Intune's Web app type supports both HTTP and HTTPS URLs and can be configured with a display name, URL, and icon for the Company Portal listing.

Exam trap

The trap here is that candidates may confuse 'Web app' with other app types like 'Windows app (Win32)' or 'iOS store app', thinking they need to wrap a web app in a native installer, when Intune's Web app type is specifically designed for this purpose.

How to eliminate wrong answers

Option A is wrong because an iOS store app is designed for iOS devices and requires a native app package from the Apple App Store, not a web app. Option C is wrong because a Windows app (Win32) is used for deploying traditional desktop applications via .msi or .exe files, not for making a web app available. Option D is wrong because an Android store app is for native Android applications distributed through the Google Play Store, not for web-based apps.

79
MCQhard

An administrator is troubleshooting why a Win32 app is repeatedly installed on a device. The exhibit shows a log snippet. What is the most likely cause of the repeated installation?

A.The app writes the detection file to a temporary folder that is cleaned periodically
B.The app requires a reboot to complete installation
C.The detection rule runs before the install completes
D.The exit code 0 is misinterpreted as failure
AnswerA

Intune's Win32 detection rules re-evaluate the detection file on each check-in. Because the file sits in a temporary folder that is periodically cleaned, the rule never finds it, so the app is reinstalled repeatedly. A stable, non-volatile detection path would satisfy the detection constraint.

Why this answer

If the Win32 app's detection file is written to a temporary folder (e.g., %TEMP% or C:\Windows\Temp) that is periodically cleaned by disk cleanup policies or the Storage Sense feature, Intune will no longer detect the app as installed after the file is removed. This causes the Microsoft Intune Management Extension to re-run the installation on the next sync cycle, leading to a repeated installation loop. The detection rule relies on the persistent presence of the file, so its removal triggers reinstallation.

Exam trap

The trap here is that candidates assume a detection rule failure is due to timing (Option C) or exit code issues (Option D), but the real-world cause is often a transient detection artifact that gets cleaned, not a logic error in the installation process.

How to eliminate wrong answers

Option B is wrong because a required reboot does not cause repeated installation; Intune marks the app as installed after the exit code 0 is received, and a pending reboot only delays further actions, not reinstallation. Option C is wrong because the detection rule runs after the installation script completes and returns an exit code, not before; the log snippet would show a detection failure only after the install attempt finishes. Option D is wrong because exit code 0 is universally interpreted as success by Intune's Win32 app management; a misinterpretation would require a custom detection rule or a non-standard exit code mapping, which is not indicated.

80
MCQhard

You manage a set of Windows 11 devices with Microsoft Intune. You deploy a Win32 app as required to a group of users. The app installs successfully, but later users report that the app is missing from their devices. You discover that the app was removed after a user uninstalled it manually. You need to ensure that the app is reinstalled automatically if it is removed. What should you configure?

A.Set the app assignment to Available and instruct users to install it from the Company Portal.
B.Set the app assignment to Required and enable the 'Restart required' option.
C.Create a compliance policy that marks devices without the app as non-compliant.
D.Set the app assignment to Required and configure a detection rule that checks for the app's presence.
AnswerD

Intune uses detection rules to determine if an app is installed. When an app is assigned as required, Intune periodically evaluates the detection rule. If the app is not detected, Intune reinstalls it. By ensuring a proper detection rule is configured, you enable Intune to detect the app's absence and automatically reinstall it, thus enforcing the required state. This is the correct method to ensure the app is reinstalled if removed.

Why this answer

For required Win32 apps, Intune relies on detection rules to verify installation status. When the detection rule indicates the app is not present, Intune will reinstall it. This enforcement happens periodically, ensuring the app remains installed even if a user removes it.

Configuring a detection rule that accurately reflects the app's presence is essential for automatic reinstallation.

Exam trap

The trap here is assuming that a required assignment alone guarantees reinstallation, when in fact a properly configured detection rule is what triggers Intune to detect and reinstall the missing app.

81
MCQeasy

You are deploying a line-of-business (LOB) app to iOS devices using Microsoft Intune. The app is signed with an enterprise certificate. Users report that the app installs but crashes immediately on launch. What is the most likely cause?

A.The Intune company portal app is not installed.
B.The app is not signed.
C.The app requires a VPN connection.
D.The enterprise developer certificate is not trusted on the device.
AnswerD

An untrusted enterprise signing certificate causes iOS to block code execution at launch, so the app installs but terminates immediately. Trusting the certificate under Settings > General > VPN & Device Management resolves this. This satisfies the stem's constraint: the app is enterprise-signed, and iOS enforces certificate trust before allowing the binary to run.

Why this answer

The most likely cause is that the enterprise developer certificate is not trusted on the device. iOS requires that enterprise-signed apps have their root certificate manually trusted via a profile (e.g., MDM or manual installation) before the app can run. Without this trust, iOS blocks the app from executing, causing an immediate crash on launch.

Exam trap

The trap here is that candidates may confuse 'signed' with 'trusted' — the app is signed, but iOS requires explicit trust of the enterprise certificate, which is a separate step often overlooked in MDM deployments.

How to eliminate wrong answers

Option A is wrong because the Company Portal app is not required for LOB app installation via MDM; Intune can push apps directly using Apple Push Notification service (APNs) and managed Open In. Option B is wrong because the app is explicitly stated to be signed with an enterprise certificate, so it is signed; the issue is trust, not signature absence. Option C is wrong because a VPN connection is not a prerequisite for launching an LOB app; VPN requirements are app-specific and would not cause an immediate crash on launch.

82
MCQeasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a Microsoft 365 Apps for Enterprise to work profiles. Which app type should you select in Intune?

A.Web app
B.Android Enterprise system app
C.Line-of-business app
D.Managed Google Play app
AnswerD

Microsoft 365 Apps for Enterprise is published through Managed Google Play, so Intune deploys it to Android Enterprise work profiles as a Managed Google Play app type. This is the only supported app type for that scenario.

Why this answer

For deploying Microsoft 365 Apps for Enterprise to Android Enterprise work profiles, the correct app type is Managed Google Play app. Intune integrates with Managed Google Play to distribute approved apps to work profiles, ensuring compliance with Android Enterprise policies. Web apps, system apps, and line-of-business apps cannot deliver the full Microsoft 365 suite with managed configuration and app protection policies in a work profile context.

Exam trap

The trap here is that candidates may confuse 'Line-of-business app' with any business app, but Microsoft 365 Apps for Enterprise is a commercially available app that must be distributed via Managed Google Play, not uploaded as a custom package.

How to eliminate wrong answers

Option A is wrong because a Web app only provides a shortcut to a URL and cannot install native Microsoft 365 apps with offline capabilities or managed app configuration. Option B is wrong because Android Enterprise system apps are pre-installed system components, not third-party apps like Microsoft 365, and cannot be deployed via Intune for work profiles. Option C is wrong because a Line-of-business app is used for custom internal apps uploaded directly to Intune, not for commercially available apps like Microsoft 365 that must be sourced from Managed Google Play.

83
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You deploy a Win32 app as required to a group of users. After deployment, users report the app shortcut is missing from the Start menu even though the app appears installed in the Company Portal. You review the app properties and confirm the install command succeeded. You need to ensure the shortcut appears for all users on each device. What should you configure?

A.Set the app to install in system context and add a requirement rule for the Windows 11 operating system.
B.Add a detection rule that checks for the shortcut file in the public Start menu path.
C.Configure the app to install in user context and assign it to the device group.
D.Package the app so the installer writes the shortcut to the all-users Start menu location, and deploy the app in system context.
AnswerD

Shortcuts visible to every user must reside in the common Start menu path, typically under ProgramData\Microsoft\Windows\Start Menu\Programs. Installing in system context allows the installer to write to that machine-wide location. Ensuring the package itself creates the shortcut there, rather than only in the installing user's profile, guarantees all users on the device see it, which matches the requirement.

Why this answer

Start menu shortcut visibility depends on where the shortcut file is written. Per-user locations only show for the installing account, while the common Start menu path is visible to everyone. Combining a package that targets the common path with system-context installation ensures the shortcut is present for all users on the device, resolving the reported symptom.

Exam trap

The trap here is treating detection rules or assignment scope as the cause of missing shortcuts, when shortcut visibility is determined by the installation context and the folder the installer writes to.

84
MCQhard

You are an Endpoint Administrator for a company using Microsoft Intune. A Windows app (Win32) app has been deployed as Required to a pilot group of 20 devices. Reports show the app installed successfully on 18 devices but failed on 2 devices with the error 'The application was not detected after installation completed successfully.' You confirm the installer runs silently and exits with code 0 on the failing devices. What is the most likely cause?

A.The app's requirement rules exclude those two devices because they run an unsupported Windows build.
B.The devices are not enrolled in the Intune Management Extension and therefore cannot run Win32 apps.
C.The install command line for the app is incorrect and causes the installer to silently skip installation.
D.The detection rule configured for the app does not match the state the installer actually produces on those devices.
AnswerD

The error message means Intune ran the installer, saw a success exit code, but then evaluated the detection rule and found no match, so it treats the install as failed. A detection rule that checks the wrong path, registry hive, or version on those devices explains why the same package succeeds elsewhere.

Why this answer

The message 'not detected after installation completed successfully' is generated when the installer returns a success code but the detection rule evaluation finds nothing matching. Because the same package works on other devices, the detection rule is the component that needs correction for the affected devices.

Exam trap

The trap here is focusing on the installer or exit code, when the error text explicitly indicates the install succeeded and only the post-install detection step failed.

85
MCQmedium

Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company portal app that allows users to enroll their devices. Which app type should you use?

A.Built-in app
B.iOS and macOS store app
C.Web link
D.macOS LOB app
AnswerB

The iOS and macOS store app type deploys the Company Portal from the Apple App Store, which users need to enrol macOS devices into Intune. It satisfies the enrolment requirement because Company Portal is the agent that initiates macOS enrolment.

Why this answer

The Company Portal app for macOS is available in the Apple App Store and is distributed via Intune as an iOS and macOS store app. This app type allows Intune to manage the app installation and assignment from the store, enabling users to enroll their macOS devices into management. Built-in apps are for pre-installed system apps, web links are for shortcuts, and LOB apps are for custom in-house apps, none of which provide the required enrollment functionality.

Exam trap

The trap here is that candidates confuse the 'iOS and macOS store app' type with the 'Built-in app' type, thinking Company Portal is a built-in system app, when in fact it must be downloaded from the App Store and managed as a store app.

How to eliminate wrong answers

Option A is wrong because built-in apps in Intune refer to pre-installed system apps like Safari or Calendar, not the Company Portal, which must be downloaded from the App Store. Option C is wrong because a web link only creates a shortcut to a URL in the Company Portal website, not a native app installation, and macOS device enrollment requires the native Company Portal app. Option D is wrong because a macOS LOB app is used for custom in-house applications uploaded directly to Intune, not for store-sourced apps like Company Portal.

86
Multi-Selecteasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. Which TWO configurations are required?

Select 2 answers
A.The user must have a Google account
B.The device must be personally owned
C.The device must be enrolled using Android Enterprise work profile
D.The app must be approved in the managed Google Play store
E.The app must be configured as a kiosk app
AnswersC, D

Required for managed Google Play apps.

Why this answer

Option C is correct because deploying a managed Google Play app to work profile devices requires the device to be enrolled with the Android Enterprise work profile enrollment type, which creates the separate work profile container where managed apps are installed. Option D is correct because managed Google Play apps must first be approved (and optionally configured) in the managed Google Play store within Intune before they can be assigned and deployed to devices. Option A is not required because the work profile enrollment handles the Google account binding through the managed Google Play connection, and end users do not need a separate personal Google account for app deployment.

Option B is not required because work profile enrollment supports both personally owned and corporate-owned devices. Option E is not required because kiosk mode is a separate dedicated-device configuration and is not needed to deploy a standard managed Google Play app.

Exam trap

The trap here is that candidates often confuse the requirement for a Google account (personal) with the managed Google Play account, or assume that work profile requires personal ownership, when in fact the enrollment type (work profile) is the sole prerequisite for deploying managed Google Play apps to work profile devices.

87
MCQhard

You run the PowerShell command to check the assignment of a Microsoft Store app in Intune. The output shows 'intent: required' and 'target: allDevicesAssignmentTarget'. Which statement is true about this app?

A.The app is assigned to a specific device group named 'All Devices'.
B.The app will install automatically on all enrolled devices.
C.The app is only assigned to devices that have the Intune Management Extension.
D.The app is available for users to install from Company Portal.
AnswerB

A required intent with an allDevicesAssignmentTarget forces automatic installation on every enrolled device, with no user interaction or opt-out. This satisfies the stem's constraint: the assignment targets all devices rather than users or groups, so Intune pushes the Microsoft Store app silently to each enrolled device.

Why this answer

The output shows 'intent: required' and 'target: allDevicesAssignmentTarget'. In Intune, 'intent: required' means the app is mandatory and will install automatically without user intervention. 'target: allDevicesAssignmentTarget' indicates the assignment applies to all enrolled devices, not a specific group. Therefore, the app will install automatically on every enrolled device, making option B correct.

Exam trap

The trap here is that candidates confuse 'allDevicesAssignmentTarget' with a manually created 'All Devices' group, or misinterpret 'intent: required' as making the app available in Company Portal, when in fact it enforces automatic installation.

How to eliminate wrong answers

Option A is wrong because 'allDevicesAssignmentTarget' is a built-in system group representing all enrolled devices, not a user-created device group named 'All Devices'. Option C is wrong because the Intune Management Extension is only required for Win32 apps or PowerShell scripts, not for Microsoft Store apps, which use the Windows Store client or the Intune management agent. Option D is wrong because 'intent: required' forces installation, whereas 'intent: available' would make the app visible in Company Portal for user-initiated installation.

88
MCQhard

You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully on some devices but fails on others with no error in the Intune console. The app logs show 'Access Denied' during installation. What should you check first?

A.The device is not Microsoft Entra ID joined
B.The device has insufficient disk space
C.The app is not signed
D.The installation context (user vs system) in the app deployment
AnswerD

'Access Denied' typically means the installer ran under the wrong account context. A Win32 app set to user context executes with standard user rights, so system-level writes fail. Verifying whether the app is configured for system context resolves the failure.

Why this answer

The 'Access Denied' error in the app logs indicates a permissions issue during installation. In Intune, Win32 apps can be deployed in either 'user' or 'system' installation context. If the app requires administrative privileges (e.g., writing to Program Files or the registry under HKLM) but is configured to run in the user context, it will fail with an access denied error on devices where the user lacks sufficient rights.

Therefore, verifying the installation context is the first troubleshooting step.

Exam trap

The trap here is that candidates often assume 'Access Denied' is always a signing or permission issue at the device level, but the MD-102 exam specifically tests the distinction between user and system installation contexts in Intune Win32 app deployments.

How to eliminate wrong answers

Option A is wrong because Microsoft Entra ID (formerly Azure AD) join status does not directly cause 'Access Denied' errors during app installation; it affects authentication and policy application, not local file system permissions. Option B is wrong because insufficient disk space typically produces a 'disk full' or 'out of space' error, not an 'Access Denied' error. Option C is wrong because an unsigned app would generate a different error, such as 'The publisher could not be verified' or a SmartScreen warning, not an 'Access Denied' error.

89
MCQmedium

An Android device running OS version 9.0 with app version 1.5.0 is targeted by the app protection policy in the exhibit. What is the expected behavior when the user tries to access work data?

A.Access is blocked because the OS version is below the warning level
B.Access is allowed with a warning to update the app and OS
C.Access is allowed without any warning because minimum requirements are met
D.Access is blocked because the app version is below the warning level
AnswerC

Correct. The device satisfies minimum requirements and is not at the warning level, so access is granted without warning.

Why this answer

The device meets the minimum OS and app version requirements, and the versions are not at the warning threshold configured in the policy. Therefore, access is allowed without any warning.

Exam trap

Candidates may confuse the warning level with the block level or assume that meeting minimums always results in no warning, but here the warning level is higher than the device's versions.

How to eliminate wrong answers

Option A is wrong because the OS version 9.0 is not below the warning level (8.0) — it is above it, so access is not blocked for OS version. Option C is wrong because while access is allowed, the statement 'without any warning because minimum requirements are met' is partially correct, but the question expects the behavior when the user tries to access work data — the policy allows access with a warning only if the app or OS is below the warning level but above the minimum; here both are above warning levels, so no warning is shown, making C technically correct but the exam answer is B because the exhibit likely shows the app version is below the warning level (1.5.0 vs 1.4.0 warning) — wait, re-evaluating: if app version 1.5.0 is above warning 1.4.0, no warning. The trap is that the exhibit might show the warning level for OS as 8.0 and app as 1.4.0, but the device OS 9.0 is above warning, app 1.5.0 is above warning, so no warning.

Option D is wrong because the app version 1.5.0 is not below the warning level (1.4.0) — it is above, so access is not blocked for app version.

90
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. Users report that a LOB app deployed as a required install fails to install on some devices. The app is configured with a dependency on another app. What should the administrator verify first?

A.Ensure the devices have internet connectivity
B.Verify that the app is signed with a trusted certificate
C.Recreate the deployment policy
D.Check if the dependency app is assigned and installed successfully
AnswerD

A required app with a dependency will not install until the dependency app is successfully assigned to the same device and installed. Verifying the dependency's assignment and installation state first isolates whether the failure originates from the prerequisite rather than the LOB app itself.

Why this answer

When a required LOB app fails to install, the most common cause is that its dependency app is not present or not successfully installed on the target device. Intune enforces dependency apps to be installed before the parent app, and if the dependency is missing or failed, the parent app installation will not proceed. The administrator should first verify that the dependency app is assigned to the same device groups and has a successful installation status.

Exam trap

The trap here is that candidates may assume the issue is with the app itself (signing or connectivity) rather than recognizing that Intune's dependency enforcement means the parent app will not install until the dependency is successfully deployed.

How to eliminate wrong answers

Option A is wrong because while internet connectivity is needed for Intune communication, a dependency issue is a more specific and likely cause for a required app failing to install, and connectivity would typically affect all apps, not just one. Option B is wrong because LOB apps deployed via Intune are already signed with a trusted certificate during enrollment or sideloading; signing issues would cause installation failures on all devices, not just some, and the question indicates the app is already configured. Option C is wrong because recreating the deployment policy is a generic troubleshooting step that does not address the specific dependency configuration; it would not resolve a missing or failed dependency app.

91
MCQmedium

You manage Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app named App1 that requires a specific command-line switch during installation. The app's installer is an .exe file that does not support silent installation by default. You must ensure the app installs without user interaction. What should you do?

A.Add the app as a Microsoft Store app (new) and upload the .exe file.
B.Create a PowerShell script that runs the installer with the required switch and deploy it as a platform script.
C.Package the app as a Win32 app and specify the silent install command in the install command field.
D.Deploy the app as a line-of-business app and upload the .exe file directly.
AnswerC

Win32 apps in Intune allow you to specify the exact install command, including silent switches such as /quiet or /silent. By packaging the .exe with the Microsoft Win32 Content Prep Tool and providing the correct silent command, Intune can install the app without user interaction. This is the standard method for deploying custom .exe installers.

Why this answer

Win32 apps in Intune are designed for custom .exe installers and allow you to specify the exact install command, including silent switches. After packaging with the Microsoft Win32 Content Prep Tool, you provide the silent install command in the app configuration. This ensures the app installs without user interaction and is tracked by Intune with detection and reporting.

Exam trap

The trap here is assuming that any .exe can be uploaded directly as a line-of-business app or a Store app, when only Win32 apps support custom .exe installers with command-line switches.

92
MCQhard

A user reports that a Microsoft 365 Apps for enterprise installation failed on their Windows 11 device managed by Intune. The Intune management extension logs show error code 0x80070005. The device is Azure AD joined and compliant. What is the most likely cause?

A.The user does not have local administrator privileges on the device
B.The device has insufficient disk space
C.The device does not have internet connectivity to the Microsoft CDN
D.The device is not compliant with the conditional access policy
AnswerA

Error 0x80070005 is Access Denied, which for Microsoft 365 Apps deployment via the Intune management extension typically reflects insufficient rights to write to protected locations. Because the app requires elevation and the user lacks local administrator privileges, the installation cannot complete.

Why this answer

Error code 0x80070005 translates to 'Access Denied' (E_ACCESSDENIED). Microsoft 365 Apps for enterprise installation requires local administrator privileges to write to protected system paths (e.g., Program Files, registry). Since the device is Azure AD joined and compliant, the most likely cause is that the user lacks local admin rights, which is a common Intune deployment prerequisite.

Exam trap

The trap here is that candidates confuse a compliance-related conditional access block (which would occur at sign-in) with a local installation permission error, overlooking that 0x80070005 specifically indicates an access-denied condition at the OS level, not a network or policy issue.

How to eliminate wrong answers

Option B is wrong because insufficient disk space typically produces error 0x80070070 (ERROR_DISK_FULL), not 0x80070005. Option C is wrong because lack of internet connectivity to the Microsoft CDN would result in download-related errors (e.g., 0x80072EFD or timeout), not an access-denied code. Option D is wrong because the device is explicitly stated as compliant, and conditional access policies affect access to cloud resources, not local installation permissions; non-compliance would block the app at the authentication layer, not produce a local access-denied error.

93
MCQeasy

A company uses Microsoft Intune to manage Windows 10 devices. You need to deploy Microsoft 365 Apps to all Windows devices. The deployment must use the Microsoft 365 Apps wizard in Intune. What should you do?

A.Upload the Office Deployment Tool (ODT) and create a Win32 app.
B.Deploy the Microsoft Store version of Office as a required app.
C.Create a new app of type 'Microsoft 365 Apps' and configure the required settings.
D.Create a PowerShell script that downloads and installs Office, and assign it to devices.
AnswerC

Intune provides a built-in app type for Microsoft 365 Apps. Selecting this type launches a wizard where you can configure update channel, version, and other settings. This is the correct method to deploy Microsoft 365 Apps using the dedicated wizard.

Why this answer

In Intune, you can deploy Microsoft 365 Apps by creating an app of type 'Microsoft 365 Apps'. This opens a wizard where you configure settings such as update channel, architecture, and which Office apps to install. This is the dedicated method for deploying Microsoft 365 Apps and is simpler than using the Office Deployment Tool.

Exam trap

The trap here is assuming you must use the Office Deployment Tool, but the wizard is the direct method.

94
MCQeasy

You are configuring a Windows 10 kiosk device using Intune. The device should run a single-store app in full-screen mode. Which Intune policy type should you use?

A.A device configuration profile using the 'Kiosk' settings for single-app mode
B.A device restrictions profile blocking access to other apps
C.A compliance policy requiring the app to be installed
D.A configuration profile for Microsoft Edge in kiosk mode
AnswerA

A device configuration profile with the Kiosk settings configured for single-app mode assigns the store app as the sole full-screen experience on the Windows 10 device, satisfying the single-app kiosk constraint directly through Intune's built-in kiosk configuration.

Why this answer

A is correct because Intune's device configuration profile includes a 'Kiosk' settings category specifically designed for Windows 10/11 devices. When you select 'Single-app mode' under kiosk settings, you can specify a single Store app (e.g., a UWP or Win32 app) that will run in full-screen, locked-down mode, preventing users from accessing any other system functions or apps.

Exam trap

The trap here is that candidates confuse 'device restrictions' (which can block apps) with the dedicated 'Kiosk' settings profile, which is the only Intune policy type that enforces the full-screen, single-app, locked-down experience required for a kiosk device.

How to eliminate wrong answers

Option B is wrong because a device restrictions profile can block access to other apps, but it does not enforce the full-screen, single-app kiosk experience; it lacks the dedicated kiosk lock-down features (e.g., auto-launch, no exit gesture). Option C is wrong because a compliance policy only checks whether an app is installed and reports non-compliance; it cannot configure the device to run that app in kiosk mode. Option D is wrong because a configuration profile for Microsoft Edge in kiosk mode is a specific subset of kiosk settings that only applies to Edge, not to any single-store app; it cannot be used to run a non-Edge app in full-screen kiosk mode.

95
Multi-Selectmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate applications. Which TWO configurations should you implement?

Select 2 answers
A.Deploy an App Protection Policy
B.Create a device compliance policy
C.Configure a device configuration profile
D.Enable multifactor authentication (MFA) for all users
E.Create a Conditional Access policy requiring compliant devices
AnswersB, E

A compliance policy defines the rules a device must meet, such as encryption, PIN and OS version, and reports each device's state to Intune. Conditional Access then uses that state, so the policy is the prerequisite that produces the compliance signal.

Why this answer

Option B (Create a device compliance policy) is correct because a compliance policy in Intune defines the rules a device must meet—such as BitLocker, minimum OS version, or jailbreak/root detection—and evaluates devices to produce a compliance state that Conditional Access can consume. Option E (Create a Conditional Access policy requiring compliant devices) is correct because Conditional Access is the enforcement engine in Microsoft Entra ID that grants or blocks access to corporate applications based on signals like device compliance, so requiring compliant devices ensures only compliant devices reach those apps. Together, the compliance policy establishes the device state and the Conditional Access policy enforces it at access time.

Option A (App Protection Policy) only protects app data on mobile apps via MAM and does not gate access to corporate applications based on device compliance. Option C (device configuration profile) merely configures settings on devices and does not itself evaluate or enforce compliance for access. Option D (MFA) strengthens user authentication but does not verify device compliance, so it does not satisfy the requirement on its own.

Exam trap

The trap here is that candidates often confuse App Protection Policies (which protect data on unmanaged devices) with device compliance policies (which require managed devices to meet security baselines), leading them to select Option A instead of the correct combination of B and E.

96
MCQmedium

You manage Windows devices with Microsoft Intune. A line-of-business Win32 app is deployed as Required to a device group. Users report the app never installs, and in the Intune console the app shows installation status 'Not applicable' for those devices. You confirm the app is assigned to the correct group and the devices are online and healthy. What is the most likely cause?

A.The app's requirement rules evaluate to false on those devices.
B.The app's detection rules evaluate to false on those devices.
C.The app content was not uploaded to Intune before assignment.
D.The Intune Management Extension is not installed on those devices.
AnswerA

Intune evaluates requirement rules (OS version, architecture, disk space, registry, etc.) before attempting installation. If none of the rules match, the app is marked 'Not applicable' and no install is attempted, which exactly matches the observed status. Reviewing and correcting the requirement rules on the app's properties will resolve it.

Why this answer

The 'Not applicable' installation status is unique to requirement rule evaluation. Intune checks requirement rules before downloading or installing a Win32 app; if no rule matches, the app is skipped and marked Not applicable. Since assignments and device health are confirmed, the requirement rules themselves must be excluding these devices, so they need to be reviewed and corrected.

Exam trap

The trap here is confusing requirement rules with detection rules, assuming a detection failure produces 'Not applicable' when it actually causes repeated install attempts or a failure status.

97
Multi-Selecthard

You are deploying a Windows line-of-business app to Intune-managed devices using the Win32 app type. The app installer is a .msi file that must run silently. You need to ensure the app installs correctly and Intune can accurately report its status. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Add a requirement rule that the device must be domain-joined.
B.Specify the install command as msiexec /i "app.msi" /qn.
C.Set the install behavior to 'User' so the app installs in the user's context.
D.Configure a detection rule that checks for the app's product code in the registry.
E.Upload the .msi file as a Windows app (Win32) package without an install command.
AnswersB, D

The Win32 app type requires an explicit install command that runs silently. Using msiexec with /qn suppresses the UI and returns proper exit codes, which Intune relies on to determine success or failure. Without a silent command, the installer may prompt and hang, causing the app to report as failed or pending indefinitely.

Why this answer

For a Win32 app packaged from an MSI, Intune requires a silent install command such as msiexec /i "app.msi" /qn, and a detection rule to verify installation. These two elements ensure the installer runs without user interaction and that Intune can accurately report success. Without them, the deployment will fail or produce unreliable status.

Exam trap

The trap here is assuming Intune automatically derives an install command or detection logic from an MSI, when both must be supplied manually for Win32 apps.

98
MCQmedium

An organization is moving from on-premises SCCM to Microsoft Intune for Windows app management. They need to ensure that users can self-install company portal apps without administrator intervention. Which configuration is required?

A.Configure the app as 'Required' for all users
B.Add the app to the Windows Autopilot deployment profile
C.Grant users local administrator rights on their devices
D.Assign the app to users as 'Available' in the Company Portal
AnswerD

Assigning the app as 'Available' to users publishes it in the Company Portal, letting users install it themselves without admin rights or IT intervention. Required assignments push silently, while Available is the self-service model the scenario demands.

Why this answer

The 'Available' assignment type in Microsoft Intune allows users to install apps on demand from the Company Portal without requiring administrator intervention. This configuration meets the requirement for self-service installation while respecting user intent, as opposed to forced installations.

Exam trap

The trap here is that candidates may confuse 'Available' assignments with 'Required' assignments, thinking that self-service implies mandatory installation, or incorrectly assume that local admin rights are needed for app installation in Intune.

How to eliminate wrong answers

Option A is wrong because configuring the app as 'Required' forces installation on all targeted devices, which does not allow users to choose when or if to install the app, contradicting the self-install requirement. Option B is wrong because Windows Autopilot deployment profiles are used for device provisioning and initial setup, not for ongoing self-service app installation via Company Portal. Option C is wrong because granting users local administrator rights is a security risk and unnecessary; Intune's 'Available' assignment enables self-installation without elevated privileges, as the Company Portal uses the Intune Management Extension to install apps in the system context.

99
MCQeasy

You are an administrator for a company that uses Microsoft Intune to manage Windows 10 devices. You need to deploy a new version of an internal line-of-business (LOB) app to all users. The app is packaged as an .msi file. What is the simplest way to deploy this app using Intune?

A.Upload the .msi file as a line-of-business app in Intune.
B.Create a PowerShell script that installs the .msi, and deploy the script as a platform script.
C.Convert the .msi to a .intunewin file using the Microsoft Win32 Content Prep Tool, then upload as a Win32 app.
D.Package the .msi into an .appx file and deploy as a Microsoft Store app.
AnswerA

Intune supports direct upload of .msi files as line-of-business apps. This method is straightforward: you select the .msi file, configure the app information, and assign it to users or devices. Intune handles the installation silently, making it the simplest approach for MSI deployment.

Why this answer

Intune's line-of-business app type supports direct upload of .msi files, automatically handling installation and detection. This is the simplest and most efficient method for deploying an MSI package, as it requires minimal configuration and leverages Intune's built-in app management capabilities.

Exam trap

The trap here is overcomplicating the deployment by assuming you need to repackage the MSI, when Intune natively supports MSI uploads.

100
MCQeasy

Your organization needs to deploy a web app link to users' devices via Microsoft Intune. Which app type should you select?

A.Windows app (Win32)
B.iOS store app
C.Web link
D.Managed Google Play app
AnswerC

A web link in Microsoft Intune deploys a shortcut to a browser-based app, satisfying the requirement to publish a web app link to users' devices. It creates a URL shortcut on managed devices without packaging or installing application binaries, unlike line-of-business or store apps, which require actual installable content.

Why this answer

C is correct because a Web link app type in Microsoft Intune allows you to deploy a shortcut to a web app on users' devices without installing any software. This is ideal for linking to a web app that runs in a browser, as it simply places an icon on the device's app list or home screen that opens the specified URL.

Exam trap

The trap here is that candidates may confuse a Web link app with a full application deployment, thinking they need to select a platform-specific app type (like Win32 or iOS store app) even when the requirement is simply to provide a URL shortcut.

How to eliminate wrong answers

Option A is wrong because a Windows app (Win32) is used for deploying traditional desktop applications via .intunewin files, not for linking to a web app. Option B is wrong because an iOS store app is for deploying native iOS applications from the Apple App Store, not for creating a shortcut to a web URL. Option D is wrong because a Managed Google Play app is for deploying Android apps from the Google Play Store, not for web links.

101
MCQhard

You manage Windows 10 devices with Microsoft Intune. You deploy a Win32 app that must run a custom installation script. The script requires a specific environment variable to be set during installation. The app installer does not set this variable. You need to ensure the variable is set only for the installation process and not permanently on the device. What should you do?

A.Create a PowerShell script that sets the environment variable at the machine level, then run the installer.
B.Use a requirement rule to set the environment variable before installation.
C.Configure the app to run in user context and set the variable in the user's profile.
D.Include the environment variable in the install command using the 'cmd /c set VAR=value && installer.exe' syntax.
AnswerD

You can set an environment variable for the duration of the command by using the 'set' command in a command prompt. This sets the variable only for that process and its child processes, so it does not persist on the device after installation. This meets the requirement.

Why this answer

Using the 'set' command within the install command line sets the environment variable only for that command's process. The variable is not written to the registry or user profile, so it does not persist after the installation completes. This satisfies the requirement of a temporary variable.

Exam trap

The trap here is assuming that any method of setting an environment variable will work, but permanent or user-specific settings violate the requirement for a temporary, process-scoped variable.

102
MCQeasy

Your organization uses Microsoft Intune to manage Android devices. You need to deploy an app that is available in the Managed Google Play store as a required app. What must you do first?

A.Connect Intune to the Managed Google Play store.
B.Enroll the device in Intune.
C.Install the Managed Google Play app on the device.
D.Upload the app package to Intune.
AnswerA

Approving and deploying Managed Google Play apps requires an established binding between Intune and the Managed Google Play store, so connecting them is the prerequisite. Without this link, Intune cannot browse, approve, or assign required apps to Android devices.

Why this answer

To deploy a required app from the Managed Google Play store, you must first establish the connection between Intune and the Managed Google Play store. This connection is a prerequisite because Intune uses it to synchronize apps, manage licenses, and push required apps to Android devices. Without this connection, Intune cannot access or deploy any apps from the Managed Google Play store.

Exam trap

The trap here is that candidates often think device enrollment (Option B) is the first step, but the connection to Managed Google Play must be established first because Intune cannot deploy any apps from the store without it.

How to eliminate wrong answers

Option B is wrong because enrolling the device in Intune is necessary for app deployment, but it is not the first step; the Intune-to-Managed Google Play connection must be established before any app deployment can occur. Option C is wrong because the Managed Google Play app is automatically installed on Android devices during the enrollment process when the connection is configured, so manually installing it is not a prerequisite. Option D is wrong because you do not upload app packages to Intune for Managed Google Play apps; instead, you approve and sync apps from the Managed Google Play store after the connection is established.

103
MCQhard

An administrator deploys a Win32 app via Intune with detection rule 'File exists: C:\Program Files\MyApp\app.exe'. The app is reported as installed, but users cannot launch it. The file exists but is corrupted. How should the administrator modify the detection rule to ensure the app is correctly detected and re-installed if corrupted?

A.Remove the detection rule so Intune always re-installs the app
B.Add a registry detection rule for the app's uninstall key
C.Use a custom detection script that validates the file hash or signature
D.Change detection rule to 'File version comparison' and set minimum version
AnswerC

A file-exists rule only confirms presence, so a corrupted app.exe still reports as installed and Intune never remediates it. A custom detection script validating the file hash or signature detects corruption, causing Intune to treat the app as non-compliant and reinstall it.

Why this answer

A custom detection script can verify the file's integrity by checking its hash or digital signature, ensuring that even if the file exists, it is not corrupted. Intune's built-in detection rules only check for file existence or version, not file integrity. By using a script that validates the hash, the administrator can force a reinstall when the file is corrupted, as the detection will fail.

Exam trap

The trap here is that candidates assume 'File exists' or 'File version comparison' are sufficient for detection, overlooking that these rules do not validate file integrity, which is a common misconception in Intune app deployment scenarios.

How to eliminate wrong answers

Option A is wrong because removing the detection rule would cause Intune to always reinstall the app on every sync, leading to unnecessary bandwidth and user disruption, and it does not solve the corruption detection issue. Option B is wrong because adding a registry detection rule for the uninstall key only confirms the app was installed via the registry, not that the executable is uncorrupted; the uninstall key remains even if the file is corrupted. Option D is wrong because 'File version comparison' only checks the version number of the file, not its integrity; a corrupted file can still have the correct version metadata, so this would not trigger a reinstall.

104
Multi-Selecteasy

Which TWO app types are available for deploying apps to iOS/iPadOS devices in Microsoft Intune? (Choose two.)

Select 2 answers
A.Web link
B.iOS/iPadOS app store app
C.Windows app (Win32)
D.Android Line-of-business app
E.iOS/iPadOS Line-of-business app
AnswersB, E

The iOS/iPadOS app store app type deploys apps sourced directly from the Apple App Store, linking to the store listing rather than hosting a package. This is one of the two supported iOS/iPadOS deployment types in Microsoft Intune, alongside line-of-business or store apps.

Why this answer

Option B (iOS/iPadOS app store app) is correct because Intune supports deploying apps directly from the Apple App Store to managed iOS/iPadOS devices, either as required or available installs, using the built-in app type for store-published apps. Option E (iOS/iPadOS Line-of-business app) is correct because Intune allows uploading and assigning custom in-house .ipa packages for iOS/iPadOS, which is the standard method for distributing proprietary enterprise apps. Option A (Web link) is not an iOS/iPadOS-specific app type in this context; it is a generic web link app type used across platforms to pin a URL, not a native iOS app deployment type.

Option C (Windows app (Win32)) is incorrect because Win32 apps target Windows devices, not iOS/iPadOS. Option D (Android Line-of-business app) is incorrect because Android LOB apps are for Android devices and use .apk or .aab packages, not iOS/iPadOS.

Exam trap

The trap here is that candidates often confuse web links (shortcuts) with actual app deployments, or mistakenly think platform-specific app types like Win32 or Android LOB can be cross-deployed, but Intune strictly enforces app type per OS platform.

← PreviousPage 2 of 2 · 104 questions total

Ready to test yourself?

Try a timed practice session using only Manage applications questions.