Courseiva

MD-102 · domain

Prepare infrastructure for devices

Practise Microsoft 365 Endpoint Administrator MD-102 Prepare infrastructure for devices practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

237 questions67 easy84 medium86 hard

Focused practice

Practice Prepare infrastructure for devices questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Prepare infrastructure for devices

Prepare infrastructure for devices questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Prepare infrastructure for devices exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Prepare infrastructure for devices questions (237)

Click any question to see the full explanation, or start a practice session above.

1

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom VPN configuration that uses per-app VPN and certificate-based authentication. The certificate is already deployed via a PKCS certificate profile. However, the VPN connection fails. What is the most likely reason?

Hard
2

Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?

Medium
3

Refer to the exhibit. You are configuring Windows enrollment restrictions in Intune. After applying this JSON, a user tries to enroll a Windows 10 device but receives an error that enrollment is blocked. What is the most likely cause?

Hard
4

Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?

Medium
5

Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?

Hard
6

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?

Easy
7

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?

Medium
8

Which THREE actions can be taken from the Intune admin center when a device is retired?

Hard
9

Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?

Easy
10

A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the compliance status. Other devices in the same group are compliant. What is the most likely cause?

Hard
11

You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?

Medium
12

You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?

Hard
13

You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?

Easy
14

Refer to the exhibit. You run the Get-AutopilotInfo script on a new Surface Pro 7. The output shows DeviceState as 'Unknown' and AssignmentStatus as 'NotAssigned'. The device is connected to the internet. What should you do to prepare this device for Autopilot deployment?

Hard
15

You are configuring Microsoft Defender for Endpoint in Microsoft Intune for Windows 10 devices. You need to ensure that when a threat is detected, the device automatically receives a remediation action. Which configuration should you use?

Medium
16

You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?

Medium
17

You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

Easy
18

You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?

Hard
19

You are troubleshooting a Windows 10 device that is not receiving required security updates from Microsoft Intune. The device is enrolled and shows as compliant. The update ring policy is assigned to the device. You check the Windows Update for Business logs and see that the deferral period is set correctly. What is the most likely cause?

Medium
20

Your organization uses Microsoft Intune to manage iOS devices. You need to deploy an app that requires a VPN configuration when the app is launched. Which TWO options can you use to achieve this? (Choose two.)

Hard
21

Which TWO prerequisites are required for Windows Autopilot self-deploying mode? (Choose two.)

Medium
22

Your organization has Windows 11 devices used by remote employees. You need to ensure that only devices compliant with your security policies can access corporate email via Microsoft Outlook for Windows. What should you configure?

Medium
23

Which TWO are required to enable Windows Hello for Business in a hybrid deployment? (Select TWO.)

Hard
24

Your company uses Microsoft Intune to manage Windows 10 devices. You need to deploy a PowerShell script that runs in the system context during automatic enrollment. The script must run before the user logs on. Which approach should you use?

Hard
25

Which TWO Intune policies can be used to enforce encryption on macOS devices?

Medium
26

You are the endpoint administrator for Contoso, Ltd., a company with 10,000 employees. The environment includes Windows 10/11 devices, iOS/iPadOS, and Android Enterprise devices. The company recently acquired a subsidiary that uses non-compliant Android devices. The security team mandates that all devices must have encryption enabled and a PIN of at least 6 digits. Additionally, the company wants to use Microsoft Defender for Endpoint on all Windows devices. Currently, only 60% of devices are enrolled in Intune. The CIO wants to increase enrollment to 95% within 6 months. You need to design a device preparation strategy. Which approach should you recommend?

Hard
27

A user reports that their Windows device is not appearing in the Intune console after enrollment. The device is joined to Microsoft Entra ID and the user has an Intune license. What should you check first?

Easy
28

Your organization recently deployed Windows 11 devices managed by Microsoft Intune. You need to ensure that only approved third-party drivers are installed on these devices. What is the best approach?

Medium
29

Refer to the exhibit. An Intune compliance policy JSON for Windows 10 devices. A device with OS version 10.0.19041.1 and no encryption reports as noncompliant. What is the most likely reason?

Hard
30

Refer to the exhibit. You are reviewing a JSON representation of a Microsoft Intune compliance policy for Windows 10. The policy is assigned to a group of devices running Windows 10 version 22H2 (build 22621). The devices are non-compliant due to the OS version. What is the most likely reason?

Medium
31

Which THREE permissions are required for a service account to register devices in Windows Autopilot? (Select THREE.)

Hard
32

Your organization uses Microsoft Intune to manage Windows 10 devices. You deploy a Windows 10 feature update policy to keep devices on a specific version. After deployment, some devices report that the update is not being offered. The devices are not in a maintenance window. What is the most likely cause?

Hard
33

You manage devices with Microsoft Intune. Users report that after a recent policy update, they cannot access company SharePoint sites on their Android devices. The devices show as compliant in Intune. What is the most likely cause?

Hard
34

You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?

Easy
35

You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?

Hard
36

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?

Medium
37

A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?

Medium
38

Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?

Hard
39

Your organization is deploying Windows 10 devices using Windows Autopilot. The devices are purchased from a vendor and will be shipped directly to users. You need to ensure that the devices are automatically enrolled in Intune and configured with your organization's standard settings as soon as the user turns on the device and connects to the internet. The devices should be Azure AD joined. What is the minimal configuration required?

Easy
40

Refer to the exhibit. You configure an Enrollment Status Page (ESP) policy as shown. During Windows Autopilot deployment, a device fails to install one of the required apps. What happens to the device?

Easy
41

Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?

Medium
42

Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?

Hard
43

You need to manage updates for Windows 10 devices using Microsoft Intune. You want to ensure that critical security updates are installed within 7 days of release, while feature updates are deferred for 60 days. Which approach should you use?

Easy
44

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to enroll a personally owned device with a work profile. Which enrollment method should the user use?

Medium
45

Your organization uses Microsoft Intune to manage Windows 10 devices. You deploy a PowerShell script via Intune management extension to install a legacy application. The script runs successfully on most devices, but fails on devices that have the 'LocalSystem' account disabled. What should you do to resolve the issue?

Hard
46

Your company has a Microsoft 365 E5 subscription. You are planning to deploy Windows 11 using Microsoft Intune. You need to ensure that devices automatically receive English (US) language pack and regional settings during the provisioning process. You plan to use a provisioning package (PPKG) created with Windows Configuration Designer. What should you include in the PPKG?

Hard
47

You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)

Medium
48

You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?

Hard
49

You are configuring Windows Hello for Business in Microsoft Intune. Which THREE settings are required to enable Windows Hello for Business on Windows 10 devices?

Hard
50

Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?

Easy
51

You are deploying Windows 10 to 100 new devices using Microsoft Deployment Toolkit (MDT). You want to integrate with Microsoft Intune for post-deployment management. Which MDT integration method should you use?

Hard
52

You are configuring Microsoft Intune device compliance policies for Windows 10. Which FOUR settings can be evaluated by compliance policies? (Choose four.)

Medium
53

Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?

Medium
54

You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?

Hard
55

Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?

Hard
56

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

Medium
57

You are troubleshooting a Windows 11 device that fails to enroll in Intune via Group Policy. The device is domain-joined and you have configured the 'Enable automatic MDM enrollment using default Azure AD credentials' GPO. The user has a valid Microsoft 365 license. What is the most likely reason for the failure?

Hard
58

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with TPM 2.0 and UEFI Secure Boot enabled can enroll. Which configuration profile setting should you configure?

Medium
59

You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?

Easy
60

Which TWO of the following are benefits of using Windows Autopilot for device provisioning?

Medium
61

You are the Intune administrator for Fabrikam, Inc., which has 5,000 Windows 10 devices. The company wants to move from on-premises Group Policy management to Intune. You have already deployed the Intune Management Extension to all devices. However, some devices are not receiving policies. You discover that these devices are not enrolled in Intune. You need to enroll all devices as quickly as possible with minimal user interaction. The devices are already joined to on-premises Active Directory. You have Microsoft Entra ID Connect configured. What should you do?

Medium
62

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?

Medium
63

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?

Medium
64

You are designing a Windows Autopilot deployment for a new fleet of devices. The devices will be shipped directly to users from the vendor. You need to ensure that the devices automatically enroll in Microsoft Intune and receive a standard set of applications during the out-of-box experience (OOBE). Which Autopilot deployment profile should you assign?

Medium
65

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a set of Line-of-Business (LOB) apps using the Microsoft Intune Management Extension. Which THREE conditions must be met?

Hard
66

Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)

Easy
67

You run the above PowerShell script to change the Windows Autopilot group tag for devices currently tagged as 'Sales' to 'Marketing'. You have assigned different deployment profiles to the 'Sales' and 'Marketing' group tags. After running the script, you check the Autopilot devices in Intune and see that the group tag for the devices has changed. However, the devices still apply the 'Sales' deployment profile during OOBE. What is the most likely reason?

Hard
68

Your organization is deploying Windows Autopilot self-deploying mode for kiosk devices. The devices will be used in a public area and must not require user interaction during the initial setup. What is the prerequisite for this deployment?

Hard
69

You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?

Hard
70

You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?

Hard
71

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that when a device is lost or stolen, the IT admin can remotely lock the device and display a custom message on the lock screen. What should you configure?

Hard
72

Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?

Medium
73

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices automatically receive the latest feature updates from the Windows 11 servicing channel. You configure a Windows 10 feature update policy targeting the devices. However, after 24 hours, devices still show Windows 10 version 22H2. What is the most likely cause?

Medium
74

Which THREE components are required for a successful Windows Autopilot self-deploying mode deployment?

Hard
75

Refer to the exhibit. You have configured a Windows Update for Business policy in Intune. Based on the JSON, what is the effect on devices?

Medium
76

You are designing a device management strategy for a remote workforce using Windows 10 laptops that are Azure AD joined. You need to ensure that devices can be remotely wiped if lost or stolen, and that BitLocker recovery keys are escrowed to Azure AD. Which THREE configurations should you implement?

Hard
77

You are configuring Microsoft Intune for a new organization. You need to ensure that users can only enroll corporate-owned devices and are blocked from enrolling personal devices. Which TWO settings should you configure?

Easy
78

Which TWO actions are required to prepare Windows devices for subscription activation? (Select TWO.)

Medium
79

You are deploying Microsoft 365 Apps for enterprise using Microsoft Intune. Which TWO methods can you use to assign the application to users?

Easy
80

Which TWO are valid methods to enroll iOS/iPadOS devices into Microsoft Intune?

Easy
81

Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?

Easy
82

Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?

Hard
83

You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?

Easy
84

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?

Hard
85

Your organization uses Microsoft Intune to manage Windows 10 devices. You create a compliance policy requiring devices to have BitLocker enabled. Some devices report as non-compliant even though BitLocker appears to be on. You discover these devices are using software-based encryption instead of hardware-based encryption. What should you do to resolve the compliance failure?

Hard
86

You manage devices with Microsoft Intune. Some Windows devices are not receiving required security updates despite being assigned to an update ring for Windows 10. You verify that the devices are active and connected to the internet. What is the most likely cause?

Hard
87

Which THREE of the following are prerequisites for using Microsoft Intune to manage Linux devices?

Hard
88

Your organization is planning to enroll Windows devices into Microsoft Intune using Group Policy. Which TWO prerequisites must be in place? (Choose two.)

Medium
89

A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?

Hard
90

Which TWO prerequisites are required for Windows Autopilot self-deploying mode?

Medium
91

You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?

Medium
92

You have deployed the above Endpoint Protection configuration profile to Windows 10 devices. Some users report that their devices are not encrypted. You verify that the devices have TPM 2.0 and meet hardware requirements. What is the most likely cause?

Easy
93

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?

Medium
94

You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?

Easy
95

Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?

Medium
96

You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?

Easy
97

A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?

Medium
98

Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?

Hard
99

You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?

Easy
100

Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?

Easy
101

Your organization uses Microsoft Intune for device management. You need to ensure that only corporate-owned devices can enroll in Intune. Which configuration should you use?

Easy
102

Refer to the exhibit. You execute this PowerShell script to wipe noncompliant Windows devices. After running, you find that some compliant devices were also wiped. What is the most likely reason?

Hard
103

Refer to the exhibit. You are evaluating a compliance policy for Windows 10. The policy is assigned to a group containing devices running Windows 10 version 1803 (build 17134.1). Which of the following devices will be marked as non-compliant?

Medium
104

You have a Windows device with serial number ABC123 that is registered for Autopilot. The above PowerShell output shows the diagnostics. The device is not receiving the Autopilot profile. What is the most likely cause?

Hard
105

Your organization uses Microsoft Intune to manage devices. You have a compliance policy that requires devices to have a password of at least 6 characters. Some users report that their devices are marked as non-compliant even though they have a password set. What is the most likely cause?

Hard
106

You are planning a Windows Autopilot deployment for your organization. You need to ensure that during the out-of-box experience (OOBE), the user is prompted to set up Windows Hello for Business. What should you configure in the Autopilot profile?

Easy
107

A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?

Hard
108

Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?

Easy
109

You run the PowerShell command shown in the exhibit for a managed device. The device shows as noncompliant. Which action should you take first to resolve the noncompliance?

Easy
110

You are reviewing an ARM template for Intune device configuration. The exhibit shows a snippet. What will be the effect on Windows 10 devices?

Medium
111

You need to configure Microsoft Intune remote help for Windows devices. Which THREE conditions must be met?

Hard
112

You need to ensure that Windows 11 devices automatically install critical updates as soon as they are released by Microsoft. Which update ring setting should you configure?

Easy
113

You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?

Easy
114

You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?

Medium
115

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?

Easy
116

Refer to the exhibit. You have configured the above Windows Autopilot profile. A device with this profile is being set up. However, the device does not appear to be provisioning correctly. What is the most likely issue?

Medium
117

You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?

Medium
118

Which TWO actions should you take to prepare infrastructure for devices running macOS in your organization? (Select two.)

Medium
119

Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?

Medium
120

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a custom Windows 10 feature update using the Windows 10 Update Rings feature. However, the deployment fails and devices show error 0x800f0905. What is the most likely cause?

Hard
121

You need to ensure that only corporate-owned devices can access Microsoft 365 apps. You plan to use Conditional Access in Microsoft Entra ID. What should you configure as the grant control?

Easy
122

Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?

Easy
123

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that corporate data in managed apps is encrypted at rest. Which setting should you configure?

Medium
124

Your organization plans to deploy Windows 11 to 500 devices using Microsoft Intune. You need to ensure that each device receives the correct language pack and regional settings based on the user's location. Which configuration method should you use?

Medium
125

Your organization plans to use Windows Autopilot for device provisioning. You need to ensure devices are automatically registered in Microsoft Entra ID when they are powered on for the first time. Which prerequisite must be met?

Easy
126

Your organization is rolling out Windows 11 devices using Autopilot. You need to ensure that all new devices are automatically enrolled in Microsoft Intune and configured with a custom device name prefix 'CORP-'. Which configuration should you implement?

Medium
127

Your organization is planning to deploy Windows 11 to 5000 devices using Microsoft Intune. The devices are currently a mix of Windows 10 and Windows 11 eligible hardware. You need to ensure that only devices meeting the Windows 11 hardware requirements can be upgraded. What is the most efficient way to achieve this using Intune?

Medium
128

You are deploying Windows 11 devices using Autopilot. The devices are purchased from a hardware vendor and need to be registered in your tenant. You want to ensure that the vendor can register the devices on your behalf without granting them full user privileges. What should you configure?

Medium
129

Your organization uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) and Microsoft Intune. You need to ensure that devices that are deemed 'at risk' by Microsoft Defender for Endpoint are automatically blocked from accessing corporate resources. What should you configure?

Hard
130

You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?

Easy
131

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a policy that prevents users from installing apps from outside the Microsoft Store. Which TWO settings can you use?

Hard
132

You are the Intune administrator for a small business with 50 Windows 10 devices that are currently managed by a legacy on-premises MDM. The company wants to move to Microsoft Intune for cloud management. All devices are already joined to Microsoft Entra ID. You need to migrate the devices to Intune management without resetting them. You have the following options: A) Use Windows Autopilot to reset the devices and re-enroll. B) Use Group Policy to configure MDM enrollment. C) Use the 'Switch to Intune' option in the device's 'Access work or school' settings. D) Use a provisioning package (PPKG) to enroll devices. Which option should you choose?

Easy
133

You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?

Easy
134

A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?

Easy
135

You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?

Easy
136

You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?

Medium
137

Your organization is implementing Windows Autopilot. Which TWO prerequisites must be met before you can use Autopilot?

Easy
138

Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?

Hard
139

Your organization uses Microsoft Intune for device management. You have a compliance policy that requires Windows devices to have BitLocker enabled. A user reports that their device is marked as non-compliant even though BitLocker is turned on. What is the most likely cause?

Hard
140

Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?

Medium
141

You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?

Hard
142

A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?

Easy
143

Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?

Easy
144

Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?

Hard
145

Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)

Hard
146

Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?

Easy
147

Refer to the exhibit. An Intune administrator created this device restrictions policy for Windows 10 devices. Which statement about the policy is true?

Medium
148

Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?

Easy
149

Your organization is deploying Windows 10 devices using Windows Autopilot. You need to ensure that during the out-of-box experience (OOBE), users are required to set up Windows Hello for Business. Which TWO configurations should you apply?

Medium
150

You are configuring Microsoft Intune for a school that provides iPads to students. You want students to be able to use their personal Apple IDs to install apps, but you need to ensure that the devices are enrolled in Intune and managed. Which Apple enrollment method should you use?

Medium
151

You are planning to enroll macOS devices in Intune. Users must authenticate with their Microsoft Entra ID credentials and then be prompted to install the Company Portal app. Which enrollment method should you use?

Medium
152

You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?

Medium
153

Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)

Hard
154

You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?

Easy
155

Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?

Hard
156

You manage devices with Microsoft Intune. Users report that enrollment fails on Android Enterprise personally-owned work profiles. After reviewing enrollment restrictions, you verify that Android Enterprise is allowed. What should you check next?

Medium
157

Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?

Medium
158

You are configuring conditional access policies in Microsoft Entra ID to require compliant devices for access to Microsoft 365 services. Some users report that they cannot access Outlook Web App (OWA) even though their device is marked as compliant in Intune. What should you verify?

Medium
159

Your company deploys Microsoft Defender for Endpoint to Windows devices managed by Microsoft Intune. You need to ensure that all devices send diagnostic data at the 'Optional diagnostic data' level. Which configuration profile type should you use?

Easy
160

Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)

Easy
161

You are deploying Windows 10 to 500 new devices using a task sequence in Microsoft Configuration Manager. The devices need to be joined to Microsoft Entra ID and enrolled in Intune automatically during OSD. Which method should you use?

Hard
162

Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned devices can access company resources, while allowing users to enroll personal devices for limited access. You plan to use enrollment restrictions and compliance policies. What should you configure?

Medium
163

Which TWO of the following are required to configure Windows Autopilot for existing devices?

Medium
164

Refer to the exhibit. You have configured the above enrollment restriction in Microsoft Intune. A user attempts to enroll a personal Windows 11 device. What will be the outcome?

Hard
165

You need to deploy Microsoft 365 Apps to 500 Windows 10 devices managed by Intune. The deployment must be automatic and should not require user interaction. What is the best method?

Medium
166

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that users cannot remove the Mail app that is required for corporate email. What configuration should you apply?

Medium
167

Refer to the exhibit. An administrator runs the PowerShell cmdlet shown on a new Windows 11 device. The cmdlet completes successfully, but the device does not appear in Intune under Windows Autopilot devices. What is the most likely cause?

Hard
168

A company uses Microsoft Intune to manage iOS/iPadOS devices. After enabling Apple User Enrollment (UE), some users report that they cannot install company-recommended apps from the Company Portal. What is the most likely cause?

Hard
169

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

Medium
170

Your organization uses Microsoft Intune to manage macOS devices. You need to configure FileVault disk encryption for all devices. After deploying the policy, some devices report that encryption is pending. What is the most likely reason?

Hard
171

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?

Medium
172

A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?

Hard
173

Your organization is implementing Microsoft Entra ID join for Windows devices. You need to ensure that when users sign in with their Microsoft Entra ID credentials, they automatically get access to company resources without additional authentication. Which feature should you enable?

Easy
174

Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?

Medium
175

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

Medium
176

You are responsible for deploying Microsoft 365 Apps for enterprise to Windows 10 devices using Microsoft Intune. You want to ensure that users receive the Current Channel with updates delivered directly from the Office Content Delivery Network (CDN). You also want to minimize bandwidth usage on your network. What should you configure?

Medium
177

You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?

Easy
178

Refer to the exhibit. An Autopilot device registration JSON. What does the '%RAND:5%' placeholder do?

Easy
179

Your company plans to deploy Microsoft 365 Apps to 500 devices using Microsoft Intune. You want to ensure that the Office suite is installed with only Word, Excel, and PowerPoint. Which approach should you use?

Easy
180

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work profile apps are encrypted and that the device owner cannot uninstall the Company Portal app. Which configuration profile should you deploy?

Hard
181

Your company is deploying iOS devices using Apple Business Manager and Intune. You need to ensure that devices are automatically configured with Wi-Fi settings, email profiles, and a list of required apps during the initial setup. Which THREE configurations should you create in Intune?

Medium
182

You manage devices with Microsoft Intune. A user reports that their Windows 11 device is not receiving updates from Windows Update for Business. The device shows as compliant in Intune. You verify that update rings are assigned to the device. What should you check next?

Hard
183

A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy a custom security baseline that includes blocking PowerShell scripts from running unless they are signed by a trusted publisher. Which configuration should be applied?

Hard
184

You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?

Easy
185

You are troubleshooting an issue where Windows 10 devices are not receiving policies from Microsoft Intune. The devices are enrolled and show as 'active' in the console. Which THREE steps should you take to diagnose the problem?

Hard
186

Refer to the exhibit. The JSON shows a managed device's properties retrieved from Microsoft Graph. The device's complianceState is 'noncompliant'. Which step should you take next to investigate why the device is noncompliant?

Medium
187

You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?

Easy
188

During Windows Autopilot deployment, devices fail to enroll in Intune with error code 0x80180014. You confirm the device is registered in Autopilot and has internet connectivity. What is the most likely cause?

Hard
189

You are configuring Windows Information Protection (WIP) in Microsoft Intune. You want to protect corporate data from being accidentally shared to personal locations while still allowing the user to work productively. Which THREE settings should you configure?

Hard
190

Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?

Easy
191

You have deployed the compliance policy shown in the exhibit. A Windows 10 device reports as non-compliant. The device has Windows 10 version 21H2 (build 19044.1288), password is set with 8 characters and includes numbers only, firewall is active, Defender is enabled, and BitLocker is on. Which setting is causing non-compliance?

Hard
192

Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?

Hard
193

A user reports that their Windows 10 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' but the last check-in was 5 days ago. What is the most likely cause?

Medium
194

You have a hybrid Azure AD joined Windows 10 device that is managed by Microsoft Intune. The device is not receiving policies. You verify that the device is enrolled and shows in Intune. You also verify that the user has an appropriate license. What should you check next?

Easy
195

You are troubleshooting an Intune enrollment issue on a Windows 10 device. The device is Microsoft Entra joined, but the enrollment status shows 'Pending'. What is the most likely cause?

Hard
196

Your organization plans to use Microsoft Intune to manage macOS devices. Which TWO prerequisites are required for macOS enrollment?

Medium
197

You need to deploy a line-of-business (LOB) app to 100 Windows 10 devices managed by Intune. The app is packaged as an .msi file. Which app type should you choose in Intune?

Easy
198

You are troubleshooting a Windows 10 device that fails to enroll in Intune manually via 'Access work or school'. The user receives the error 'We couldn't auto-discover a management endpoint matching the username entered'. What is the most likely cause?

Hard
199

Which TWO are valid methods to enroll Windows devices into Microsoft Intune?

Easy
200

Your company has 200 iOS devices that are enrolled in Microsoft Intune via Apple Business Manager. The devices are used by field sales representatives who need access to the corporate CRM app and email. You need to ensure that if a device is lost or stolen, the corporate data can be removed without affecting personal data. The devices are configured with user affinity. What should you do?

Medium
201

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?

Medium
202

You manage a fleet of 2,000 iOS devices for a healthcare organization. The devices are used by clinicians and must be enrolled in Intune. Due to security requirements, you must ensure that devices are supervised and that the Company Portal app is installed automatically. You have Apple Business Manager (ABM) set up with Intune. You need to configure the enrollment process so that when a new device is unboxed and turned on, it automatically enrolls and receives the required configuration. Which enrollment method should you use?

Medium
203

You need to configure Windows 10 devices to automatically encrypt their drives using BitLocker when they enroll in Microsoft Intune. You have created a BitLocker policy in Endpoint Security. However, after enrollment, some devices are not encrypted. You verify that the devices have a TPM 2.0 and meet hardware requirements. What is the most likely reason for the failure?

Hard
204

You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?

Easy
205

Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?

Medium
206

Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)

Easy
207

You are planning a Windows 11 deployment using Microsoft Intune. The organization has a requirement that all devices must have BitLocker enabled with a TPM protector. You configure a BitLocker policy in Intune. However, some devices report that BitLocker is not enabled. What is the most likely reason?

Hard
208

A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?

Easy
209

You are troubleshooting an issue where a user reports that their Windows device is not receiving compliance policies from Intune. The device shows as 'Not compliant' in the Intune console. What is the most likely cause?

Easy
210

Your organization uses Microsoft Intune and you need to configure Windows Autopilot for hybrid Microsoft Entra ID join. Which THREE components are required?

Hard
211

Refer to the exhibit. A detection script for a Win32 app in Intune uses a WMI query. The script is expected to detect if BitLocker is not enabled. What will the script return if BitLocker is enabled on the device?

Easy
212

Refer to the exhibit. You create a new update ring policy for Windows 10 devices. You assign the policy to a test group. After a week, you notice that no devices have installed any quality updates. Devices are online and enrolled. What is the most likely reason?

Medium
213

You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?

Medium
214

A multinational organization uses Microsoft Entra ID joined devices with Intune. The security team wants to block enrollment of devices from non-corporate networks unless they have a compliant certificate. Which enrollment restriction should you configure?

Hard
215

A user reports that their Windows 11 device is not receiving a required security baseline policy from Microsoft Intune. The device appears as compliant in the Microsoft Intune admin center. Other devices in the same group receive the policy. You verify that the policy is assigned to the correct group and that the user is a member. What is the most likely cause?

Hard
216

Which THREE of the following are valid methods to enroll Android devices into Microsoft Intune?

Hard
217

Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?

Medium
218

You need to ensure that all corporate-owned Windows devices automatically receive security updates as soon as they are released by Microsoft. Which update ring policy setting should you configure in Microsoft Intune?

Easy
219

Which THREE components are required for a successful co-management setup between Configuration Manager and Microsoft Intune? (Choose three.)

Hard
220

You are planning device management for a corporate environment with Windows 10, iOS, and Android devices. You need to implement a solution that allows users to access corporate email and documents securely on their personal devices without IT managing the entire device. Which THREE components should you include?

Hard
221

Your organization plans to deploy Windows Autopilot for existing devices that are currently running Windows 10. You need to convert these devices from a traditional imaging deployment to an Autopilot deployment. You want to minimize user disruption. What should you do?

Hard
222

You are configuring Windows Autopilot for new devices. The devices need to be automatically enrolled in Intune and assigned to a specific group based on their serial number. What is the required step before the devices can be recognized by Autopilot?

Easy
223

You are troubleshooting an Autopilot deployment where devices are not receiving the expected configuration policies after enrollment. The devices show as enrolled in Intune but are stuck in a 'pending' state for policy application. What is the most likely cause?

Easy
224

You need to configure device compliance for devices that are not running Windows. The devices include iOS, iPadOS, Android, and macOS. Which compliance settings are common across all platforms?

Medium
225

Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?

Easy
226

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?

Medium
227

You need to deploy a custom Windows 10 image to 100 new devices using Microsoft Intune. The devices are not yet enrolled. Which method should you use to deploy the image and enroll the devices?

Easy
228

Your organization uses Windows Autopilot for user-driven deployments. You need to ensure that during the out-of-box experience (OOBE), users are prompted to set up Windows Hello for Business. Which setting should you configure in the Autopilot profile?

Medium
229

A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?

Medium
230

You have the above profile assigned to a macOS device. After the profile is applied, the device shows FileVault as 'Encrypted'. However, the recovery key is not escrowed to Intune. What is the most likely reason?

Medium
231

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?

Hard
232

Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. Some devices running Windows 10 22H2 (build 19045.3803) are marked as noncompliant. What is the most likely reason?

Hard
233

You manage devices with Microsoft Intune. You need to deploy a line-of-business (LOB) app to iOS devices. The app is signed with an enterprise certificate. Some devices report installation failure with error code 0x87D13B9F. What is the most likely cause?

Hard
234

Refer to the exhibit. You have configured a Windows update ring using the JSON above. Today is March 10, 2025. Devices assigned to this ring are not receiving any quality updates. What is the most likely reason?

Hard
235

You are setting up Microsoft Intune for the first time. You need to ensure that users can enroll their iOS devices using the Company Portal app. You have configured the enrollment restrictions to allow iOS enrollment. However, users report that they see an error 'This device is not allowed to enroll' when trying to enroll. What is the most likely cause?

Medium
236

Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?

Easy
237

Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?

Easy

Frequently asked questions

What does the Prepare infrastructure for devices domain cover on the MD-102 exam?
Prepare infrastructure for devices questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 237 Prepare infrastructure for devices questions in the MD-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Prepare infrastructure for devices questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
md-102 MD-102 prepare device infrastructure Practice Questions