MD-102 · domain
Prepare infrastructure for devices
This domain covers the groundwork for managing endpoints in Microsoft 365: getting devices enrolled and compliant so they can be targeted by policy. Expect questions on Intune enrollment prerequisites, Windows Autopilot hardware hash collection, Conditional Access for device compliance, and deploying Win32 apps that need elevated install rights.
Focused practice
Practice Prepare infrastructure for devices questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Prepare infrastructure for devices
Be able to prepare devices for management: confirm licensing and MDM authority, enroll devices, capture Autopilot hardware hashes, and build Conditional Access policies that gate access on compliance. The key is knowing which prerequisite or setting actually enables each step.
Intune enrollment prerequisites including licensing, MDM authority, and automatic enrollment scope
Windows Autopilot hardware hash capture via PowerShell script or OEM/partner registration
Conditional Access policies requiring compliant or Microsoft Entra hybrid joined devices
Win32 app deployment using Intune Management Extension with system-context install commands
Watch out for
Common Prepare infrastructure for devices exam traps
- ▸Assuming the hardware hash is auto-collected; it must be captured and uploaded before Autopilot deployment works.
- ▸Setting Conditional Access to require MFA instead of requiring a compliant or hybrid joined device.
- ▸Forgetting the Intune Management Extension is required for Win32 (.intunewin) apps and PowerShell scripts.
Question index
All Prepare infrastructure for devices questions (145)
Click any question to see the full explanation, or start a practice session above.
You are setting up Microsoft Intune for a new company. The company has a mix of Windows 10, Windows 11, iOS, and Android devices. You need to ensure that devices can enroll in Intune automatically without user interaction for Windows devices that are Microsoft Entra joined. What should you configure?
Easy2You are an Endpoint Administrator for a company that uses Microsoft Intune. The security team requires that Windows 11 devices assigned to the Finance department must use a specific set of DNS servers and must not allow users to modify the DNS settings. You create a device configuration profile using the Settings catalog. Which setting category should you use to enforce the DNS server assignment?
Medium3Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?
Medium4You are an endpoint administrator for a company that uses Microsoft Intune. You need to configure a Windows 11 device to support multiple users who will sign in with their Microsoft Entra ID credentials. The device will be shared among shift workers. You want to ensure that each user receives their own configuration profiles and applications. What should you configure?
Hard5Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?
Medium6Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?
Hard7Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?
Easy8Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?
Medium9Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?
Easy10You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?
Medium11You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?
Hard12You are preparing infrastructure for Windows Autopilot at Contoso. You need to configure the environment so that devices can be deployed with Windows Autopilot in Microsoft Entra hybrid join mode. Which two components must be in place before devices can complete the hybrid join during OOBE? (Choose two.)
Hard13You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?
Easy14You are preparing infrastructure for device management at Adventure Works. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Intune. You need to configure a Windows Autopilot deployment profile that will be used for Microsoft Entra hybrid join. During testing, devices fail at the domain join step. You verify that the Intune Connector for Active Directory is installed and online. What should you check next?
Hard15You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?
Medium16You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?
Easy17You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?
Hard18You are the endpoint administrator for a company that uses Microsoft Intune. The company has an on-premises network with Active Directory Domain Services (AD DS) and a Microsoft Entra tenant. You need to prepare the infrastructure for Windows Autopilot deployment of Microsoft Entra hybrid joined devices. You must ensure that the required components are in place to support the hybrid join process. Which two actions should you perform? (Choose two.)
Hard19You are the endpoint administrator for Contoso, which uses Microsoft Intune. You need to enroll 200 new Windows 11 devices into Intune with the least administrative effort. The devices are currently running Windows 11 Pro and are connected to the internet. You want to avoid imaging or manually installing agents. What should you do?
Easy20You are the endpoint administrator for a company that uses Microsoft Intune to manage 500 Windows 11 devices. The security team requires that devices cannot be enrolled if they do not have a TPM 2.0 chip and Secure Boot enabled. You need to configure a device enrollment restriction to block enrollment of devices that do not meet these hardware requirements. What should you do?
Medium21You are the administrator for a company that uses Microsoft Intune. The company has a policy that all Windows 10 devices must have a minimum OS version of 10.0.19045. You need to ensure that devices that do not meet this requirement are blocked from accessing corporate email. What should you configure?
Medium22You are the endpoint administrator for a company that uses Microsoft Intune. You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote workers who do not have access to the corporate network. You need to ensure that the devices are automatically enrolled in Intune and that users can sign in with their Microsoft Entra ID credentials. Which Autopilot deployment mode should you use?
Medium23You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?
Easy24You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?
Hard25Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?
Medium26A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?
Medium27Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?
Hard28You are designing the Windows Autopilot deployment profile for a new subsidiary that has no on-premises infrastructure. All devices will be Microsoft Entra joined. The security team requires that during the out-of-box experience (OOBE), users authenticate with their Microsoft Entra credentials and that local administrator rights are not granted to the primary user. You also want to minimize the time spent at OOBE. Which deployment mode should you select in the Autopilot profile?
Medium29You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?
Medium30You are an endpoint administrator for a company that uses Microsoft Intune. The company plans to deploy Windows 11 devices using Windows Autopilot in self-deploying mode. You need to ensure that the devices can be provisioned without any user interaction. Which two configurations are required for self-deploying mode? (Choose two.)
Medium31Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?
Medium32Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?
Hard33You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)
Medium34You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?
Hard35Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?
Easy36Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?
Medium37You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?
Hard38Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?
Hard39Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?
Medium40You are the endpoint administrator for Contoso Ltd., a multinational company with 10,000 Windows 10 and 11 devices managed by Microsoft Intune. The company recently acquired a subsidiary that uses on-premises Active Directory and Configuration Manager. The subsidiary's devices are not joined to Microsoft Entra ID. Your goal is to migrate these devices to cloud management with Intune within six months. The subsidiary has 2,000 devices, all running Windows 10. The devices are currently domain-joined and managed by ConfigMgr. You need to choose the most efficient migration strategy that minimizes user disruption and leverages existing investments. The subsidiary has a high-speed WAN link to the corporate network. You have the following options: A) Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune. B) Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join. C) Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps. D) Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning. Which option should you choose?
Hard41You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?
Easy42Which TWO of the following are benefits of using Windows Autopilot for device provisioning?
Medium43Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?
Medium44Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?
Medium45Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)
Easy46You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and uses Microsoft Entra ID with Microsoft Intune. You must configure a Windows Autopilot deployment for existing Windows 11 devices that are already joined to the on-premises domain. The devices must remain domain-joined and also be registered in Microsoft Entra ID. You need to create the Autopilot deployment profile. Which deployment mode should you select?
Easy47You are the endpoint administrator for a company that uses Microsoft Intune. The company has a policy that all Windows devices must have a minimum OS version of 10.0.19045. You need to create a compliance policy that enforces this requirement. Which type of compliance setting should you configure?
Easy48Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that only devices running Windows 11 version 23H2 or later can enroll into Intune. You also want to block enrollment for older Windows versions. What should you configure?
Medium49You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?
Hard50You are planning to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote users who do not have a VPN connection during initial setup. The devices must be Microsoft Entra joined and enrolled in Intune. You need to ensure that the deployment works without requiring a domain controller. Which Autopilot mode should you configure?
Hard51You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?
Hard52Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?
Medium53You are configuring a Windows Autopilot deployment for devices that must be hybrid Microsoft Entra joined. The environment includes an on-premises Active Directory domain and Microsoft Entra Connect. You need to ensure the devices can complete the hybrid join during OOBE. Which configuration is required?
Hard54You are the Intune administrator for a company that uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that when devices enroll, they automatically receive a set of configuration settings, including a custom Start menu layout and specific Wi-Fi profiles. What should you create and assign?
Medium55You are preparing infrastructure for Windows Autopilot deployment in a hybrid Microsoft Entra join scenario. You need to ensure that devices can join the on-premises domain and enroll in Intune. Which two components must you configure? (Choose two.)
Hard56Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?
Easy57Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?
Hard58You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?
Easy59Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?
Hard60A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?
Hard61You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?
Medium62You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. Contoso has an on-premises Active Directory Domain Services (AD DS) forest and uses Microsoft Entra ID with Microsoft Intune. You plan to deploy 200 new Windows 11 devices by using Windows Autopilot in Microsoft Entra hybrid join mode. You need to ensure that each device is automatically joined to AD DS and registered in Microsoft Entra ID during the out-of-box experience. What should you configure first?
Medium63Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?
Medium64You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?
Easy65Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?
Medium66You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?
Easy67A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?
Medium68Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?
Hard69You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?
Easy70You are an endpoint administrator for a company that uses Microsoft Intune. You need to ensure that all Windows 10 devices are automatically enrolled in Intune when they are joined to Microsoft Entra ID. What should you configure?
Easy71Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?
Easy72You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?
Medium73You are planning to deploy Windows 11 devices using Windows Autopilot in Microsoft Intune. The company requires that the devices are Microsoft Entra joined and that the enrollment process includes the installation of required applications and configuration of device settings. You need to identify which two components are required to achieve this. (Choose two.)
Medium74You are the Microsoft 365 Endpoint Administrator for Contoso. The company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when devices are enrolled, they automatically receive a set of configuration settings without manual intervention. The settings include a custom Start menu layout and a set of allowed background apps. What should you create in Intune to achieve this?
Easy75You administer Microsoft Intune for Northwind Traders. The security team wants to prevent users from enrolling personally owned Windows 10 devices while still allowing corporate-owned devices to enroll. You need to configure a device enrollment restriction that blocks personal Windows devices. Which platform setting should you modify?
Easy76You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?
Hard77A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?
Hard78Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?
Easy79You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?
Easy80You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?
Medium81Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?
Easy82You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?
Medium83Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?
Medium84Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?
Easy85You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?
Easy86You are preparing infrastructure for device management in Microsoft Intune. Your organization plans to deploy Windows 11 devices using Windows Autopilot in Microsoft Entra join mode. You need to ensure that the devices can be identified and assigned to the correct deployment profile. Which two actions must you perform? (Choose two.)
Hard87You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?
Easy88A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?
Easy89You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?
Easy90You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?
Medium91Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?
Hard92Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?
Medium93You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?
Hard94A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?
Easy95Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?
Easy96Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?
Hard97Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)
Hard98Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?
Easy99Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?
Easy100You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?
Medium101Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)
Hard102You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?
Easy103Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?
Hard104Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?
Medium105You administer Microsoft Intune for a company with 2,000 Windows 11 devices. The security team requires that all devices automatically receive an Intune enrollment record when they are first powered on by end users, without requiring users to manually enroll. You have already configured a Windows Autopilot deployment profile and assigned it to a device group. Which additional configuration is required to meet the requirement?
Medium106Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)
Easy107Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?
Medium108You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Entra ID with Microsoft Intune. You need to prepare infrastructure to deploy Windows 11 devices that are Microsoft Entra hybrid joined. You must ensure that devices can enroll in Intune without requiring user interaction during the out-of-box experience (OOBE). What should you configure first?
Medium109Your company uses Microsoft Intune to manage devices. You need to ensure that Windows 11 devices can receive configuration profiles and compliance policies. You have already assigned the necessary licenses to users. What should you do first to prepare the devices for management?
Easy110A company uses Microsoft Intune to manage its Windows devices. The IT team wants to ensure that new Windows devices can enroll without requiring users to manually enter the enrollment server address. The devices are already joined to Microsoft Entra ID. Which infrastructure component enables this automatic discovery?
Easy111You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?
Hard112Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?
Medium113Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?
Medium114A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?
Hard115Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?
Medium116Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?
Medium117You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices are Microsoft Entra joined. You need to ensure that during OOBE, devices are automatically assigned to the correct group for policy targeting. What should you configure?
Medium118You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?
Easy119You are configuring a Windows Autopilot deployment for a group of remote users. The users will receive new Windows 11 devices and will sign in with their Microsoft Entra ID credentials. You need to ensure that the devices are automatically enrolled in Microsoft Intune and that the users are assigned the appropriate licenses. Which license must be assigned to the users?
Medium120You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?
Easy121You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?
Easy122Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?
Easy123Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?
Hard124You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?
Medium125You are deploying Windows 11 devices using Windows Autopilot. The devices must be joined to an on-premises Active Directory domain and also registered with Microsoft Entra ID. You need to configure the deployment profile. Which Autopilot mode should you use?
Hard126Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?
Medium127You are the administrator for a company that uses Microsoft Intune. You need to deploy a Windows 10 device configuration profile that configures a custom administrative template setting. The setting is not available in the built-in templates. You have the ADMX and ADML files for the setting. What should you do first?
Hard128You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?
Easy129Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?
Medium130Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)
Easy131A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?
Easy132You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?
Medium133Which TWO actions should you take to prepare a Windows 10 device for a deployment using Windows Autopilot?
Medium134You are the endpoint administrator for Contoso, Ltd. The company uses Microsoft Intune and has a hybrid Microsoft Entra ID environment with an on-premises Active Directory Domain Services (AD DS) domain. You plan to deploy 200 new Windows 11 devices using Windows Autopilot. The devices must be joined to the on-premises AD DS domain and also registered in Microsoft Entra ID. You need to configure the Autopilot deployment profile to support this scenario. What should you do first?
Medium135You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?
Medium136Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?
Medium137You are setting up Microsoft Intune for a new subsidiary. The subsidiary has an existing on-premises Active Directory Domain Services (AD DS) and uses Microsoft Entra Connect to synchronize users to Microsoft Entra ID. You need to enable automatic enrollment of Windows 10 devices into Intune for users who are synchronized from AD DS. What should you configure first?
Easy138Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?
Easy139Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?
Medium140You are the endpoint administrator for a company that uses Microsoft Intune. The security team requires that all Windows 11 devices automatically receive an Intune device configuration profile that enforces a minimum PIN length of 8 for Windows Hello for Business. You need to ensure the profile is applied without user interaction. What should you do?
Medium141You are an endpoint administrator for a company that uses Microsoft Intune. The company has a Microsoft Entra ID tenant with Intune configured. You need to ensure that when new Windows 10 devices are set up by users, they are automatically enrolled in Intune and receive company policies. The devices are purchased from a reseller and are not domain-joined. You want to minimize user interaction during setup. What should you configure?
Easy142A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?
Medium143Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?
Hard144Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?
Easy145Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?
EasyOther domains
All MD-102 exam domains
Frequently asked questions
- What does the Prepare infrastructure for devices domain cover on the MD-102 exam?
- Be able to prepare devices for management: confirm licensing and MDM authority, enroll devices, capture Autopilot hardware hashes, and build Conditional Access policies that gate access on compliance. The key is knowing which prerequisite or setting actually enables each step.
- How many questions are in this domain?
- This page lists all 145 Prepare infrastructure for devices questions in the MD-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Prepare infrastructure for devices questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.