Courseiva

MD-102 · domain

Prepare infrastructure for devices

This domain covers the groundwork for managing endpoints in Microsoft 365: getting devices enrolled and compliant so they can be targeted by policy. Expect questions on Intune enrollment prerequisites, Windows Autopilot hardware hash collection, Conditional Access for device compliance, and deploying Win32 apps that need elevated install rights.

145 questions49 easy58 medium38 hard

Focused practice

Practice Prepare infrastructure for devices questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Prepare infrastructure for devices

Be able to prepare devices for management: confirm licensing and MDM authority, enroll devices, capture Autopilot hardware hashes, and build Conditional Access policies that gate access on compliance. The key is knowing which prerequisite or setting actually enables each step.

Intune enrollment prerequisites including licensing, MDM authority, and automatic enrollment scope

Windows Autopilot hardware hash capture via PowerShell script or OEM/partner registration

Conditional Access policies requiring compliant or Microsoft Entra hybrid joined devices

Win32 app deployment using Intune Management Extension with system-context install commands

Watch out for

Common Prepare infrastructure for devices exam traps

  • ▸Assuming the hardware hash is auto-collected; it must be captured and uploaded before Autopilot deployment works.
  • ▸Setting Conditional Access to require MFA instead of requiring a compliant or hybrid joined device.
  • ▸Forgetting the Intune Management Extension is required for Win32 (.intunewin) apps and PowerShell scripts.

Question index

All Prepare infrastructure for devices questions (145)

Click any question to see the full explanation, or start a practice session above.

1

You are setting up Microsoft Intune for a new company. The company has a mix of Windows 10, Windows 11, iOS, and Android devices. You need to ensure that devices can enroll in Intune automatically without user interaction for Windows devices that are Microsoft Entra joined. What should you configure?

Easy
2

You are an Endpoint Administrator for a company that uses Microsoft Intune. The security team requires that Windows 11 devices assigned to the Finance department must use a specific set of DNS servers and must not allow users to modify the DNS settings. You create a device configuration profile using the Settings catalog. Which setting category should you use to enforce the DNS server assignment?

Medium
3

Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?

Medium
4

You are an endpoint administrator for a company that uses Microsoft Intune. You need to configure a Windows 11 device to support multiple users who will sign in with their Microsoft Entra ID credentials. The device will be shared among shift workers. You want to ensure that each user receives their own configuration profiles and applications. What should you configure?

Hard
5

Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?

Medium
6

Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?

Hard
7

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?

Easy
8

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?

Medium
9

Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?

Easy
10

You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?

Medium
11

You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?

Hard
12

You are preparing infrastructure for Windows Autopilot at Contoso. You need to configure the environment so that devices can be deployed with Windows Autopilot in Microsoft Entra hybrid join mode. Which two components must be in place before devices can complete the hybrid join during OOBE? (Choose two.)

Hard
13

You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?

Easy
14

You are preparing infrastructure for device management at Adventure Works. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Intune. You need to configure a Windows Autopilot deployment profile that will be used for Microsoft Entra hybrid join. During testing, devices fail at the domain join step. You verify that the Intune Connector for Active Directory is installed and online. What should you check next?

Hard
15

You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?

Medium
16

You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

Easy
17

You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?

Hard
18

You are the endpoint administrator for a company that uses Microsoft Intune. The company has an on-premises network with Active Directory Domain Services (AD DS) and a Microsoft Entra tenant. You need to prepare the infrastructure for Windows Autopilot deployment of Microsoft Entra hybrid joined devices. You must ensure that the required components are in place to support the hybrid join process. Which two actions should you perform? (Choose two.)

Hard
19

You are the endpoint administrator for Contoso, which uses Microsoft Intune. You need to enroll 200 new Windows 11 devices into Intune with the least administrative effort. The devices are currently running Windows 11 Pro and are connected to the internet. You want to avoid imaging or manually installing agents. What should you do?

Easy
20

You are the endpoint administrator for a company that uses Microsoft Intune to manage 500 Windows 11 devices. The security team requires that devices cannot be enrolled if they do not have a TPM 2.0 chip and Secure Boot enabled. You need to configure a device enrollment restriction to block enrollment of devices that do not meet these hardware requirements. What should you do?

Medium
21

You are the administrator for a company that uses Microsoft Intune. The company has a policy that all Windows 10 devices must have a minimum OS version of 10.0.19045. You need to ensure that devices that do not meet this requirement are blocked from accessing corporate email. What should you configure?

Medium
22

You are the endpoint administrator for a company that uses Microsoft Intune. You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote workers who do not have access to the corporate network. You need to ensure that the devices are automatically enrolled in Intune and that users can sign in with their Microsoft Entra ID credentials. Which Autopilot deployment mode should you use?

Medium
23

You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?

Easy
24

You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?

Hard
25

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?

Medium
26

A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?

Medium
27

Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?

Hard
28

You are designing the Windows Autopilot deployment profile for a new subsidiary that has no on-premises infrastructure. All devices will be Microsoft Entra joined. The security team requires that during the out-of-box experience (OOBE), users authenticate with their Microsoft Entra credentials and that local administrator rights are not granted to the primary user. You also want to minimize the time spent at OOBE. Which deployment mode should you select in the Autopilot profile?

Medium
29

You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?

Medium
30

You are an endpoint administrator for a company that uses Microsoft Intune. The company plans to deploy Windows 11 devices using Windows Autopilot in self-deploying mode. You need to ensure that the devices can be provisioned without any user interaction. Which two configurations are required for self-deploying mode? (Choose two.)

Medium
31

Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?

Medium
32

Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?

Hard
33

You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)

Medium
34

You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?

Hard
35

Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?

Easy
36

Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?

Medium
37

You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?

Hard
38

Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?

Hard
39

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

Medium
40

You are the endpoint administrator for Contoso Ltd., a multinational company with 10,000 Windows 10 and 11 devices managed by Microsoft Intune. The company recently acquired a subsidiary that uses on-premises Active Directory and Configuration Manager. The subsidiary's devices are not joined to Microsoft Entra ID. Your goal is to migrate these devices to cloud management with Intune within six months. The subsidiary has 2,000 devices, all running Windows 10. The devices are currently domain-joined and managed by ConfigMgr. You need to choose the most efficient migration strategy that minimizes user disruption and leverages existing investments. The subsidiary has a high-speed WAN link to the corporate network. You have the following options: A) Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune. B) Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join. C) Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps. D) Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning. Which option should you choose?

Hard
41

You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?

Easy
42

Which TWO of the following are benefits of using Windows Autopilot for device provisioning?

Medium
43

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?

Medium
44

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?

Medium
45

Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)

Easy
46

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and uses Microsoft Entra ID with Microsoft Intune. You must configure a Windows Autopilot deployment for existing Windows 11 devices that are already joined to the on-premises domain. The devices must remain domain-joined and also be registered in Microsoft Entra ID. You need to create the Autopilot deployment profile. Which deployment mode should you select?

Easy
47

You are the endpoint administrator for a company that uses Microsoft Intune. The company has a policy that all Windows devices must have a minimum OS version of 10.0.19045. You need to create a compliance policy that enforces this requirement. Which type of compliance setting should you configure?

Easy
48

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that only devices running Windows 11 version 23H2 or later can enroll into Intune. You also want to block enrollment for older Windows versions. What should you configure?

Medium
49

You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?

Hard
50

You are planning to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote users who do not have a VPN connection during initial setup. The devices must be Microsoft Entra joined and enrolled in Intune. You need to ensure that the deployment works without requiring a domain controller. Which Autopilot mode should you configure?

Hard
51

You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?

Hard
52

Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?

Medium
53

You are configuring a Windows Autopilot deployment for devices that must be hybrid Microsoft Entra joined. The environment includes an on-premises Active Directory domain and Microsoft Entra Connect. You need to ensure the devices can complete the hybrid join during OOBE. Which configuration is required?

Hard
54

You are the Intune administrator for a company that uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that when devices enroll, they automatically receive a set of configuration settings, including a custom Start menu layout and specific Wi-Fi profiles. What should you create and assign?

Medium
55

You are preparing infrastructure for Windows Autopilot deployment in a hybrid Microsoft Entra join scenario. You need to ensure that devices can join the on-premises domain and enroll in Intune. Which two components must you configure? (Choose two.)

Hard
56

Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?

Easy
57

Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?

Hard
58

You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?

Easy
59

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?

Hard
60

A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?

Hard
61

You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?

Medium
62

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. Contoso has an on-premises Active Directory Domain Services (AD DS) forest and uses Microsoft Entra ID with Microsoft Intune. You plan to deploy 200 new Windows 11 devices by using Windows Autopilot in Microsoft Entra hybrid join mode. You need to ensure that each device is automatically joined to AD DS and registered in Microsoft Entra ID during the out-of-box experience. What should you configure first?

Medium
63

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?

Medium
64

You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?

Easy
65

Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?

Medium
66

You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?

Easy
67

A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?

Medium
68

Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?

Hard
69

You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?

Easy
70

You are an endpoint administrator for a company that uses Microsoft Intune. You need to ensure that all Windows 10 devices are automatically enrolled in Intune when they are joined to Microsoft Entra ID. What should you configure?

Easy
71

Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?

Easy
72

You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?

Medium
73

You are planning to deploy Windows 11 devices using Windows Autopilot in Microsoft Intune. The company requires that the devices are Microsoft Entra joined and that the enrollment process includes the installation of required applications and configuration of device settings. You need to identify which two components are required to achieve this. (Choose two.)

Medium
74

You are the Microsoft 365 Endpoint Administrator for Contoso. The company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when devices are enrolled, they automatically receive a set of configuration settings without manual intervention. The settings include a custom Start menu layout and a set of allowed background apps. What should you create in Intune to achieve this?

Easy
75

You administer Microsoft Intune for Northwind Traders. The security team wants to prevent users from enrolling personally owned Windows 10 devices while still allowing corporate-owned devices to enroll. You need to configure a device enrollment restriction that blocks personal Windows devices. Which platform setting should you modify?

Easy
76

You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?

Hard
77

A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?

Hard
78

Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?

Easy
79

You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?

Easy
80

You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?

Medium
81

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?

Easy
82

You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?

Medium
83

Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?

Medium
84

Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?

Easy
85

You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?

Easy
86

You are preparing infrastructure for device management in Microsoft Intune. Your organization plans to deploy Windows 11 devices using Windows Autopilot in Microsoft Entra join mode. You need to ensure that the devices can be identified and assigned to the correct deployment profile. Which two actions must you perform? (Choose two.)

Hard
87

You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?

Easy
88

A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?

Easy
89

You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?

Easy
90

You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?

Medium
91

Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?

Hard
92

Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?

Medium
93

You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?

Hard
94

A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?

Easy
95

Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?

Easy
96

Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?

Hard
97

Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)

Hard
98

Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?

Easy
99

Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?

Easy
100

You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?

Medium
101

Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)

Hard
102

You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?

Easy
103

Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?

Hard
104

Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?

Medium
105

You administer Microsoft Intune for a company with 2,000 Windows 11 devices. The security team requires that all devices automatically receive an Intune enrollment record when they are first powered on by end users, without requiring users to manually enroll. You have already configured a Windows Autopilot deployment profile and assigned it to a device group. Which additional configuration is required to meet the requirement?

Medium
106

Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)

Easy
107

Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?

Medium
108

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Entra ID with Microsoft Intune. You need to prepare infrastructure to deploy Windows 11 devices that are Microsoft Entra hybrid joined. You must ensure that devices can enroll in Intune without requiring user interaction during the out-of-box experience (OOBE). What should you configure first?

Medium
109

Your company uses Microsoft Intune to manage devices. You need to ensure that Windows 11 devices can receive configuration profiles and compliance policies. You have already assigned the necessary licenses to users. What should you do first to prepare the devices for management?

Easy
110

A company uses Microsoft Intune to manage its Windows devices. The IT team wants to ensure that new Windows devices can enroll without requiring users to manually enter the enrollment server address. The devices are already joined to Microsoft Entra ID. Which infrastructure component enables this automatic discovery?

Easy
111

You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?

Hard
112

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

Medium
113

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?

Medium
114

A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?

Hard
115

Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?

Medium
116

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

Medium
117

You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices are Microsoft Entra joined. You need to ensure that during OOBE, devices are automatically assigned to the correct group for policy targeting. What should you configure?

Medium
118

You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?

Easy
119

You are configuring a Windows Autopilot deployment for a group of remote users. The users will receive new Windows 11 devices and will sign in with their Microsoft Entra ID credentials. You need to ensure that the devices are automatically enrolled in Microsoft Intune and that the users are assigned the appropriate licenses. Which license must be assigned to the users?

Medium
120

You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?

Easy
121

You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?

Easy
122

Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?

Easy
123

Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?

Hard
124

You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?

Medium
125

You are deploying Windows 11 devices using Windows Autopilot. The devices must be joined to an on-premises Active Directory domain and also registered with Microsoft Entra ID. You need to configure the deployment profile. Which Autopilot mode should you use?

Hard
126

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?

Medium
127

You are the administrator for a company that uses Microsoft Intune. You need to deploy a Windows 10 device configuration profile that configures a custom administrative template setting. The setting is not available in the built-in templates. You have the ADMX and ADML files for the setting. What should you do first?

Hard
128

You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?

Easy
129

Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?

Medium
130

Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)

Easy
131

A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?

Easy
132

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?

Medium
133

Which TWO actions should you take to prepare a Windows 10 device for a deployment using Windows Autopilot?

Medium
134

You are the endpoint administrator for Contoso, Ltd. The company uses Microsoft Intune and has a hybrid Microsoft Entra ID environment with an on-premises Active Directory Domain Services (AD DS) domain. You plan to deploy 200 new Windows 11 devices using Windows Autopilot. The devices must be joined to the on-premises AD DS domain and also registered in Microsoft Entra ID. You need to configure the Autopilot deployment profile to support this scenario. What should you do first?

Medium
135

You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?

Medium
136

Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?

Medium
137

You are setting up Microsoft Intune for a new subsidiary. The subsidiary has an existing on-premises Active Directory Domain Services (AD DS) and uses Microsoft Entra Connect to synchronize users to Microsoft Entra ID. You need to enable automatic enrollment of Windows 10 devices into Intune for users who are synchronized from AD DS. What should you configure first?

Easy
138

Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?

Easy
139

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?

Medium
140

You are the endpoint administrator for a company that uses Microsoft Intune. The security team requires that all Windows 11 devices automatically receive an Intune device configuration profile that enforces a minimum PIN length of 8 for Windows Hello for Business. You need to ensure the profile is applied without user interaction. What should you do?

Medium
141

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a Microsoft Entra ID tenant with Intune configured. You need to ensure that when new Windows 10 devices are set up by users, they are automatically enrolled in Intune and receive company policies. The devices are purchased from a reseller and are not domain-joined. You want to minimize user interaction during setup. What should you configure?

Easy
142

A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?

Medium
143

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?

Hard
144

Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?

Easy
145

Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?

Easy

Frequently asked questions

What does the Prepare infrastructure for devices domain cover on the MD-102 exam?
Be able to prepare devices for management: confirm licensing and MDM authority, enroll devices, capture Autopilot hardware hashes, and build Conditional Access policies that gate access on compliance. The key is knowing which prerequisite or setting actually enables each step.
How many questions are in this domain?
This page lists all 145 Prepare infrastructure for devices questions in the MD-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Prepare infrastructure for devices questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
md-102 MD-102 prepare device infrastructure Practice Questions