Courseiva

CCNA Prepare infrastructure for devices Questions

75 of 145 questions · Page 1/2 · Prepare infrastructure for devices · Answers revealed

1
MCQeasy

You are setting up Microsoft Intune for a new company. The company has a mix of Windows 10, Windows 11, iOS, and Android devices. You need to ensure that devices can enroll in Intune automatically without user interaction for Windows devices that are Microsoft Entra joined. What should you configure?

A.Automatic enrollment in Intune.
B.Device enrollment manager.
C.Windows Autopilot deployment profile.
D.Enrollment restrictions.
AnswerA

Automatic enrollment in Intune is the feature that enables Windows devices that are Microsoft Entra joined or hybrid Azure AD joined to automatically enroll in Intune without user interaction. When enabled, devices receive Intune policies and management automatically upon joining Microsoft Entra ID. This is the correct configuration to ensure seamless enrollment for Windows devices without user action. It is configured in the Intune portal under Enrollment > Windows > Automatic Enrollment.

Why this answer

Automatic enrollment in Intune is the feature that allows Windows devices that are Microsoft Entra joined or hybrid Azure AD joined to enroll in Intune automatically without user interaction. This is configured in the Intune portal and ensures that devices are managed as soon as they join Microsoft Entra ID. This meets the requirement for automatic enrollment without user interaction for Windows devices.

Exam trap

The trap here is confusing automatic enrollment with Autopilot, which is for provisioning new devices but still requires user interaction during OOBE.

2
MCQmedium

You are an Endpoint Administrator for a company that uses Microsoft Intune. The security team requires that Windows 11 devices assigned to the Finance department must use a specific set of DNS servers and must not allow users to modify the DNS settings. You create a device configuration profile using the Settings catalog. Which setting category should you use to enforce the DNS server assignment?

A.VPN
B.Wi-Fi
C.DNS
D.Network proxy
AnswerC

The DNS category in the Settings catalog contains settings such as DNS server addresses for specific interfaces and DNS suffix search lists. Configuring this category lets you assign the required DNS servers to the Windows 11 devices and, when the profile is assigned, the settings are enforced so users cannot change the DNS configuration on those Finance devices.

Why this answer

The Settings catalog exposes granular Windows configuration service provider settings, and the DNS category specifically includes settings to define DNS server addresses and prevent modification. Applying a device configuration profile with those settings to the Finance device group enforces the required DNS servers and blocks user changes, directly satisfying the security team's requirement.

Exam trap

The trap here is assuming that DNS server assignment belongs under Network proxy or Wi-Fi settings, when the Settings catalog provides a dedicated DNS category for that purpose.

3
Multi-Selectmedium

Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?

Select 2 answers
A.Enforce security baselines on devices
B.Convert existing devices to Autopilot by uploading hardware hash
C.Deploy third-party applications automatically
D.Customize the out-of-box experience (OOBE) for users
E.Configure BIOS settings remotely
AnswersB, D

Uploading a hardware hash registers an existing device with the Autopilot deployment service, enabling it to be reset and reprovisioned through the Autopilot out-of-box experience. This satisfies the stem's requirement for a supported Autopilot action in Microsoft Intune, converting already-deployed hardware into Autopilot-managed devices without manual imaging.

Why this answer

Option B is correct because Windows Autopilot supports registering existing devices by collecting their hardware hash (via the Get-WindowsAutoPilotInfo script or similar) and uploading it as a CSV to Intune, which creates an Autopilot device record so the device can be reset and reprovisioned through the Autopilot flow. Option D is correct because Autopilot's core purpose is to define and customize the out-of-box experience (OOBE) using deployment profiles, including settings like the privacy prompts, user account type, language/region, and whether the user is a standard user or local admin. Option A is not an Autopilot action; security baselines are enforced through Intune configuration profiles/policies, not through Autopilot itself.

Option C is not specific to Autopilot; third-party applications are deployed via Intune app deployment (Win32 apps, MSI, Microsoft Store apps, etc.), which can be assigned to Autopilot-enrolled devices but is not an Autopilot capability. Option E is not an Autopilot function; BIOS/UEFI settings are typically configured through vendor tools (e.g., Dell Command | Configure, HP Client Management Script Library) or Intune's OEM-specific configuration, not Autopilot.

Exam trap

The trap here is that candidates confuse Windows Autopilot's OOBE customization capabilities with broader device management features like security baselines or third-party app deployment, which are handled by Intune policies after enrollment, not during the Autopilot provisioning phase.

4
MCQhard

You are an endpoint administrator for a company that uses Microsoft Intune. You need to configure a Windows 11 device to support multiple users who will sign in with their Microsoft Entra ID credentials. The device will be shared among shift workers. You want to ensure that each user receives their own configuration profiles and applications. What should you configure?

A.Windows Autopilot pre-provisioning mode.
B.Shared multi-user device configuration profile.
C.Device enrollment manager (DEM) account.
D.Windows Autopilot self-deploying mode.
AnswerB

A shared multi-user device configuration profile in Intune is specifically designed for Windows devices shared by multiple users. It configures settings like guest account, power management, and sign-in options to optimize for shared use. When combined with Microsoft Entra ID, each user can sign in and receive their own policies and applications based on user targeting.

Why this answer

For shared Windows devices used by multiple shift workers, you should configure a shared multi-user device configuration profile. This profile optimizes the device for shared use and allows each user to sign in with their own credentials, receiving personalized settings and applications. It is the correct choice for this scenario.

Exam trap

The trap here is confusing Autopilot modes with shared device configurations; Autopilot modes are for deployment, not for ongoing multi-user management.

5
MCQmedium

Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?

A.Configure enrollment restrictions to require corporate ownership
B.Set device type restrictions to block unregistered devices
C.Configure automatic enrollment via Group Policy
D.Configure Microsoft Entra join or Microsoft Entra registration as a prerequisite for Intune enrollment
AnswerD

Requiring Microsoft Entra join or Microsoft Entra registration before Intune enrolment enforces the identity prerequisite, so unregistered devices are blocked. This satisfies the security team's constraint that every device exist in Microsoft Entra ID prior to Intune management.

Why this answer

Microsoft Entra ID (formerly Azure AD) registration or join is a prerequisite for Intune enrollment. Intune requires a device to have an identity in Entra ID to apply policies and manage compliance. Without this prerequisite, the device cannot authenticate or receive management commands from Intune.

Exam trap

The trap here is that candidates often confuse 'enrollment restrictions' (which control device platform or ownership) with the prerequisite of having an Entra ID identity, leading them to select Option A or B instead of understanding that Entra ID registration is a separate, mandatory step before Intune enrollment can proceed.

How to eliminate wrong answers

Option A is wrong because enrollment restrictions for corporate ownership control how devices are marked (e.g., personal vs. corporate), not whether they are registered in Entra ID. Option B is wrong because device type restrictions block specific platforms or OS versions, not unregistered devices; there is no built-in restriction to block devices that lack an Entra ID registration. Option C is wrong because automatic enrollment via Group Policy enables Intune enrollment for domain-joined devices but does not enforce that the device must be registered in Entra ID before enrollment; it uses a different enrollment method (GPO-triggered MDM enrollment) that may not require prior Entra ID registration.

6
MCQhard

Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?

A.To output the device names of all Windows devices.
B.To list the IDs of Windows devices.
C.To list devices that are registered in Autopilot.
D.To update the enrollment type of all Windows devices.
AnswerB

Correct. The script lists the unique IDs (`DeviceId`) of all Windows devices in Microsoft Entra ID. While the option says 'joined', the script does not filter by join type; it returns all Windows devices in the directory.

Why this answer

The script uses Get-MgDevice with a filter for operatingSystem eq 'Windows' to retrieve all Windows device objects from Microsoft Entra ID, regardless of their join type (joined, registered, or hybrid). By selecting the DeviceId property, it outputs the unique identifiers of these devices. The DeviceId is the Entra ID object identifier, not the device name or Autopilot registration status.

Exam trap

The trap here is confusing DeviceId (the Entra ID object ID) with the device name or Autopilot registration, leading candidates to select options about listing names or Autopilot devices instead of device IDs.

How to eliminate wrong answers

Option A is wrong because the script selects `DeviceId`, not `DisplayName` or `DeviceName`; it outputs IDs, not device names. Option C is wrong because `Get-MgDevice` retrieves all Entra ID registered/joined devices, not specifically Autopilot-registered devices; Autopilot devices are listed via `Get-MgDeviceManagementWindowsAutopilotDeviceIdentity`. Option D is wrong because the script only reads device data with a `Select` operation; it does not call any `Update-MgDevice` cmdlet or modify enrollment type.

7
MCQeasy

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?

A.Set feature update deferral to 180 days and quality update deferral to 0 days.
B.Set feature update deferral to 30 days and quality update deferral to 120 days.
C.Set feature update deferral to 120 days and quality update deferral to 30 days.
D.Set both feature and quality update deferrals to 60 days.
AnswerC

Feature and quality update deferrals are separate settings within a Windows 10 update ring, each measured in days from release. Configuring 120 days for feature updates and 30 days for quality updates directly satisfies both constraints in the stem, since Intune applies these independently per ring without affecting the other update type.

Why this answer

The Windows 10 update ring settings in Microsoft Intune allow you to specify deferral periods for feature updates and quality updates independently. To meet the requirement of deferring feature updates by 120 days and quality updates by 30 days, you must set the feature update deferral to 120 days and the quality update deferral to 30 days. These values directly control how long the device waits before installing the respective update types after Microsoft releases them.

Exam trap

The trap here is that candidates often confuse the deferral periods for feature and quality updates, mistakenly swapping the values or assuming a single deferral applies to both, when the question explicitly requires independent settings for each update type.

How to eliminate wrong answers

Option A is wrong because setting feature update deferral to 180 days exceeds the required 120-day deferral, and setting quality update deferral to 0 days provides no deferral, failing the 30-day requirement. Option B is wrong because it reverses the deferral periods: feature updates would be deferred only 30 days (not 120) and quality updates would be deferred 120 days (not 30), which does not match the specified requirements. Option D is wrong because setting both deferrals to 60 days would defer feature updates by only 60 days instead of the required 120 days, and quality updates by 60 days instead of 30 days, failing both conditions.

8
MCQmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?

A.Create a device configuration profile that requires iOS 16.0.
B.Modify the enrollment profile to require iOS 16.0.
C.Create a compliance policy that requires iOS 16.0 or later.
D.Create an enrollment platform restriction for iOS/iPadOS and set the minimum OS version to 16.0.
AnswerD

Enrollment platform restrictions let you block or allow iOS/iPadOS enrolment and specify a minimum OS version, so devices below iOS 16 are refused at enrolment. This satisfies the requirement before device management begins, unlike a compliance policy which only flags non-compliance afterwards.

Why this answer

Enrollment platform restrictions in Intune let you define the minimum and maximum OS versions allowed to enroll for each platform, including iOS/iPadOS. Setting the minimum OS version to 16.0 blocks enrollment of devices running older versions at the enrollment gate. This is the correct control because the requirement is about enrollment eligibility, not ongoing compliance.

Exam trap

MD-102 often tests the difference between enrollment restrictions (block enrollment) and compliance policies (block access after enrollment) — candidates frequently choose compliance when the scenario says 'can enroll.'

How to eliminate wrong answers

Option A is wrong because a device configuration profile applies settings to already-enrolled devices and cannot block enrollment based on OS version. Option B is wrong because enrollment profiles (like the Apple enrollment profile) configure enrollment behavior (supervision, setup assistant panes) but do not enforce minimum OS versions. Option C is wrong because a compliance policy evaluates enrolled devices and marks them noncompliant — it does not prevent enrollment in the first place.

9
MCQeasy

Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?

A.The device's hardware hash, uploaded to Intune, and an Autopilot deployment profile assigned.
B.The Configuration Manager client and a site code for automatic site assignment.
C.A provisioning package containing the MDM enrollment settings.
D.A Group Policy Object that configures automatic MDM enrollment.
AnswerA

Uploading the hardware hash registers the device with the Autopilot service, and the assigned deployment profile drives the out-of-box experience to join Microsoft Entra ID, auto-enrol in Intune, and trigger required app installation on first boot.

Why this answer

Windows Autopilot requires the device's hardware hash to be uploaded to Intune so that the device can be identified as an Autopilot device. An Autopilot deployment profile is then assigned to the device, which specifies the settings for joining Microsoft Entra ID, enrolling in Intune, and installing required applications during the first boot (Out-of-Box Experience). This combination ensures the entire provisioning flow occurs automatically without manual intervention.

Exam trap

The trap here is that candidates often confuse provisioning packages (PPKG) with Autopilot, but Autopilot is specifically designed to eliminate the need for any local media or manual steps, relying solely on cloud-based device identity and profile assignment.

How to eliminate wrong answers

Option B is wrong because the Configuration Manager client and site code are used for co-management or traditional client management, not for Windows Autopilot's zero-touch provisioning which relies on cloud-based enrollment via Intune. Option C is wrong because a provisioning package (PPKG) is used for manual or bulk provisioning via Windows Configuration Designer, not for the automatic, cloud-driven Autopilot process that requires no local media or USB drive. Option D is wrong because Group Policy Objects (GPOs) are applied after the device is already joined to the domain and enrolled, and they cannot trigger the initial Autopilot enrollment flow which happens before the device has network access to a domain controller.

10
MCQmedium

You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?

A.Device restrictions configuration policy
B.Device compliance policy
C.App configuration policy
D.Enrollment restriction
AnswerA

Android Enterprise device restrictions policies expose a dedicated control that blocks installation from unknown sources, directly enforcing the requirement. App configuration policies only supply app settings, and compliance policies report state rather than prevent installation, so restrictions is the correct type.

Why this answer

Device restrictions configuration policies in Microsoft Intune are designed to control built-in device settings and hardware features, including security-related options like blocking installation from unknown sources. For Android Enterprise, this policy type directly maps to the 'Unknown sources' setting under Device Restrictions, allowing you to prevent sideloading of apps. Compliance policies only evaluate conditions and mark devices as compliant or non-compliant; they do not enforce configuration changes.

App configuration policies deliver app-specific settings (e.g., server URLs) to managed apps, and enrollment restrictions control which devices can enroll, not what users can do after enrollment.

Exam trap

MD-102 often tests the confusion between configuration policies (which enforce settings) and compliance policies (which evaluate and report), so candidates may incorrectly choose a compliance policy thinking it will block the action.

How to eliminate wrong answers

Option B is wrong because a device compliance policy only assesses device state against rules (e.g., OS version, encryption) and reports compliance; it cannot block app installation from unknown sources. Option C is wrong because an app configuration policy provides custom settings to individual apps (like Outlook or Chrome) after they are installed, and does not control device-level installation permissions. Option D is wrong because enrollment restrictions define which devices or platforms are allowed to enroll in Intune, not what settings apply after enrollment.

11
Multi-Selecthard

You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?

Select 3 answers
A.Apple Push Notification service certificate (for iOS)
B.Intune licenses assigned to users
C.Microsoft Entra ID (for identity and device registration)
D.Microsoft Intune subscription (for MDM authority)
E.Configuration Manager (for co-management)
AnswersB, C, D

Users must have Intune licenses to enroll devices.

Why this answer

Intune licenses must be assigned to users to grant them access to the service. Without a license, the user cannot authenticate with Intune, and automatic enrollment will fail during the device registration step. This is a prerequisite enforced by Microsoft Entra ID and Intune together.

Exam trap

The trap here is that candidates often confuse prerequisites for device management (like APNs certificate) with prerequisites for automatic enrollment, leading them to select Apple Push Notification service certificate as a required component when it is only needed after enrollment for iOS device management.

12
Multi-Selecthard

You are preparing infrastructure for Windows Autopilot at Contoso. You need to configure the environment so that devices can be deployed with Windows Autopilot in Microsoft Entra hybrid join mode. Which two components must be in place before devices can complete the hybrid join during OOBE? (Choose two.)

Select 2 answers
A.A device compliance policy requiring BitLocker and Secure Boot.
B.A Configuration Manager site system role for the enrollment proxy point.
C.A Windows Autopilot deployment profile configured with the Microsoft Entra hybrid joined join type.
D.The Intune Connector for Active Directory installed on a server with access to the on-premises domain.
E.A conditional access policy requiring multifactor authentication for all users.
AnswersC, D

A deployment profile set to Microsoft Entra hybrid joined tells the device to perform an on-premises domain join and then register with Entra ID. Without this profile, devices default to Entra joined or do not receive the correct OOBE behavior. It is a required configuration alongside the connector for hybrid join to succeed.

Why this answer

Autopilot hybrid join requires the Intune Connector for Active Directory to perform the offline domain join and a deployment profile configured for Microsoft Entra hybrid joined to direct the device through the correct OOBE path. Compliance policies, Configuration Manager enrollment proxy points, and Conditional Access policies do not perform the domain join or Entra registration steps, so they are not prerequisites for completing hybrid join.

Exam trap

The trap here is selecting Configuration Manager components or security policies as prerequisites, when the two essential elements are the AD connector and the hybrid-joined deployment profile.

13
Multi-Selecteasy

You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?

Select 2 answers
A.Android Zero Touch.
B.Microsoft Entra ID join with automatic MDM enrollment.
C.Apple Business Manager.
D.Windows Autopilot.
E.Samsung Knox Mobile Enrollment.
AnswersB, D

Microsoft Entra ID join with automatic MDM enrolment configures the device to join the tenant and register with Intune during OOBE or via Group Policy. This satisfies the stem's requirement for a valid Windows enrolment method using cloud identity.

Why this answer

The correct answers are B (Microsoft Entra ID join with automatic MDM enrollment) and D (Windows Autopilot). Both are valid methods to enroll Windows devices into Microsoft Intune. Option A (Android Zero Touch) is for Android devices, not Windows.

Option C (Apple Business Manager) is for Apple devices. Option E (Samsung Knox Mobile Enrollment) is for Samsung Android devices.

14
MCQhard

You are preparing infrastructure for device management at Adventure Works. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Intune. You need to configure a Windows Autopilot deployment profile that will be used for Microsoft Entra hybrid join. During testing, devices fail at the domain join step. You verify that the Intune Connector for Active Directory is installed and online. What should you check next?

A.The device has a TPM 2.0 chip and is UEFI-enabled.
B.The organizational unit (OU) specified in the deployment profile exists and the connector service account has permission to create computer objects in it.
C.The Microsoft Entra ID join type is set to Microsoft Entra joined instead of Microsoft Entra hybrid joined.
D.The Windows Autopilot deployment profile is assigned to a device group and not a user group.
AnswerB

For hybrid join, the Intune Connector for Active Directory uses a service account to create the computer object in the OU specified in the Autopilot deployment profile. If the OU path is invalid or the account lacks Create Computer Objects permission, the domain join fails even when the connector is online. Verifying the OU and permissions is the logical next step.

Why this answer

When the Intune Connector for Active Directory is online but hybrid join still fails, the next checks are the organizational unit specified in the deployment profile and the permissions of the connector's service account. The connector creates the computer object in that OU, so an invalid OU path or insufficient rights prevents the domain join. TPM, UEFI, group assignment, and join type are not the cause when devices already reach the domain join step.

Exam trap

The trap here is stopping at the connector's online status and overlooking that the connector still needs a valid OU path and an account with rights to create computer objects.

15
MCQmedium

You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?

A.Use the Microsoft Store for Business to automatically register devices
B.Contact the OEM to register the devices using the device serial numbers
C.Use the Windows Configuration Designer to create a provisioning package that includes Autopilot settings
D.Upload the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center
AnswerD

Uploading the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center registers each device, creating an Autopilot device record that can then be targeted by a deployment profile. This satisfies the requirement to associate devices with profiles.

Why this answer

Uploading the hardware hashes to the Autopilot devices page in the Microsoft Intune admin center is the standard method to register devices for Windows Autopilot. Option A is incorrect because the Microsoft Store for Business is deprecated and no longer supports Autopilot registration. Option B is incorrect because while OEMs can register devices, you already have the hardware hashes, making direct upload more efficient.

Option C is incorrect because Windows Configuration Designer is used to create provisioning packages for manual setup, not for Autopilot device registration.

16
MCQeasy

You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?

A.Upload the app package as an iOS LOB app in Intune
B.Add the app as a Volume Purchase Program (VPP) app
C.Use an Enterprise Code Signing certificate to deploy via MDM
D.Publish the app to the Apple App Store and deploy as public app
AnswerA

iOS LOB apps are uploaded as .ipa packages signed with an enterprise distribution certificate, letting Intune push them directly to supervised or enrolled devices without the App Store. This satisfies the stem's enterprise-signed, 100-device constraint.

Why this answer

Intune supports deploying internally developed LOB apps to iOS devices by uploading the signed .ipa package directly. Since the app is already signed with an enterprise certificate, it can be distributed via Intune's iOS LOB app workflow without requiring the Apple App Store or VPP.

Exam trap

The trap here is confusing the signing certificate (used to sign the app) with the deployment method, leading candidates to select Option C, which describes a prerequisite rather than a distribution mechanism.

How to eliminate wrong answers

Option B is wrong because Volume Purchase Program (VPP) apps are purchased from the Apple App Store and assigned to devices via managed distribution, not used for custom LOB apps. Option C is wrong because Enterprise Code Signing certificates are used to sign the app, not as a deployment method; MDM deploys the app via Intune's LOB app upload, not by using the certificate directly. Option D is wrong because publishing to the Apple App Store is unnecessary and contradicts the requirement to deploy a signed LOB app; public apps are for store-distributed apps, not enterprise-signed ones.

17
MCQhard

You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?

A.Create a provisioning package with Windows 11 upgrade settings and apply it via USB drives.
B.Deploy a Windows 11 feature update using the 'Windows 10/11 feature update' servicing plan in Configuration Manager, enabling Delivery Optimization for peer-to-peer download.
C.Use Windows Autopilot to reset the device and reinstall Windows 11, restoring user data from OneDrive.
D.Create a task sequence to upgrade Windows, and configure it to download content from the internet to reduce distribution point load.
AnswerB

Deploying a Windows 11 feature update via a Configuration Manager servicing plan performs a true in-place upgrade, preserving user data and settings. Enabling Delivery Optimization satisfies the limited-bandwidth constraint by letting remote-office peers share update content, drastically reducing WAN consumption compared with each device downloading independently.

Why this answer

It leverages Configuration Manager's 'Windows 10/11 feature update' servicing plan, which is specifically designed for in-place upgrades while preserving user data and settings. Enabling Delivery Optimization for peer-to-peer download reduces bandwidth consumption in remote offices by allowing devices to share upgrade content locally, addressing the limited bandwidth constraint.

Exam trap

The trap here is that candidates may confuse provisioning packages (Option A) as a valid upgrade method, but they are designed for offline provisioning and cannot perform an in-place upgrade with user data preservation, while the feature update servicing plan is the correct, supported method for this scenario.

How to eliminate wrong answers

Option A is wrong because provisioning packages are intended for initial device configuration and offline deployment, not for in-place upgrades; they cannot orchestrate a Windows 11 upgrade while preserving existing user data and settings. Option C is wrong because Windows Autopilot reset wipes the device and reinstalls Windows, which does not preserve user data and settings; restoring from OneDrive is a separate process and not part of an in-place upgrade. Option D is wrong because configuring a task sequence to download content from the internet does not inherently reduce distribution point load; it shifts the download source to the internet, which may still consume significant bandwidth unless combined with peer caching or Delivery Optimization, and the task sequence method is more complex than the dedicated feature update servicing plan.

18
Multi-Selecthard

You are the endpoint administrator for a company that uses Microsoft Intune. The company has an on-premises network with Active Directory Domain Services (AD DS) and a Microsoft Entra tenant. You need to prepare the infrastructure for Windows Autopilot deployment of Microsoft Entra hybrid joined devices. You must ensure that the required components are in place to support the hybrid join process. Which two actions should you perform? (Choose two.)

Select 2 answers
A.Configure the Microsoft Entra Connect sync to include the device objects in the organizational unit (OU) where the devices will be created.
B.Install the Intune Connector for Active Directory on a server with line-of-sight to a domain controller.
C.Create a device configuration profile that enables the Windows Push Notification Service (WNS).
D.Deploy a Windows Autopilot deployment profile with the deployment mode set to Microsoft Entra joined.
E.Assign the Intune Connector for Active Directory the necessary permissions in Microsoft Entra ID to create device objects.
AnswersA, B

For Microsoft Entra hybrid joined devices, Microsoft Entra Connect must be configured to sync the device objects from the OU where the Autopilot-created computer accounts reside. This ensures that the device objects are synchronized to Microsoft Entra ID and can be used for conditional access and management. Without this sync, the hybrid join will not complete successfully.

Why this answer

For Microsoft Entra hybrid joined Autopilot, you must install the Intune Connector for Active Directory on a server with line-of-sight to a domain controller, and configure Microsoft Entra Connect to sync the OU containing the device objects. These two components enable the creation of the computer account in AD DS during OOBE and ensure the device object is synchronized to Microsoft Entra ID, completing the hybrid join.

Exam trap

The trap here is assuming that the Intune Connector for Active Directory requires Microsoft Entra ID permissions, when it actually operates against on-premises AD DS.

19
MCQeasy

You are the endpoint administrator for Contoso, which uses Microsoft Intune. You need to enroll 200 new Windows 11 devices into Intune with the least administrative effort. The devices are currently running Windows 11 Pro and are connected to the internet. You want to avoid imaging or manually installing agents. What should you do?

A.Configure Windows Autopilot deployment profiles and register the device hardware IDs.
B.Deploy the Intune agent MSI to each device using a logon script.
C.Manually enroll each device by having users sign in with their Microsoft Entra ID credentials in Settings.
D.Use Group Policy to enable automatic MDM enrollment for all domain-joined devices.
AnswerA

Windows Autopilot leverages the existing Windows installation and hardware ID to enroll devices into Intune without reimaging. By registering hardware hashes, you can assign deployment profiles that automatically join devices to Microsoft Entra ID and enroll them in Intune. This meets the requirement of least administrative effort and avoids imaging.

Why this answer

Windows Autopilot is designed to simplify and automate the enrollment of new Windows devices without reimaging. By registering hardware IDs, you can assign deployment profiles that automatically configure and enroll devices into Intune. This approach minimizes administrative effort and ensures devices are ready for use with minimal user interaction.

Exam trap

The trap here is assuming that a separate Intune agent must be installed on Windows devices, when in fact enrollment is natively integrated into the OS.

20
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune to manage 500 Windows 11 devices. The security team requires that devices cannot be enrolled if they do not have a TPM 2.0 chip and Secure Boot enabled. You need to configure a device enrollment restriction to block enrollment of devices that do not meet these hardware requirements. What should you do?

A.Configure a Windows Autopilot deployment profile with hardware requirements and assign it to all devices.
B.Create a configuration profile with a custom OMA-URI that checks for TPM and Secure Boot, and assign it to all devices.
C.In the Microsoft Intune admin center, create a device enrollment restriction for Windows and set the minimum TPM version and require Secure Boot.
D.Create a device compliance policy that requires TPM 2.0 and Secure Boot, and assign it to all users.
AnswerC

Device enrollment restrictions in Intune allow you to specify hardware requirements such as minimum TPM version and Secure Boot enforcement for Windows devices. When configured, devices that do not meet these criteria are prevented from enrolling, directly fulfilling the requirement to block non-compliant hardware at enrollment time.

Why this answer

Device enrollment restrictions are the correct tool to control which devices can enroll based on hardware attributes like TPM version and Secure Boot. Compliance policies and configuration profiles only act after enrollment, and Autopilot profiles shape the provisioning experience but do not enforce hardware prerequisites. Thus, only enrollment restrictions can block non-compliant hardware at the point of enrollment.

Exam trap

The trap here is confusing post-enrollment compliance evaluation with pre-enrollment blocking, leading to selection of a compliance policy instead of an enrollment restriction.

21
MCQmedium

You are the administrator for a company that uses Microsoft Intune. The company has a policy that all Windows 10 devices must have a minimum OS version of 10.0.19045. You need to ensure that devices that do not meet this requirement are blocked from accessing corporate email. What should you configure?

A.A device configuration profile that sets the minimum OS version and a conditional access policy that requires compliant devices.
B.A device compliance policy that sets the minimum OS version to 10.0.19045, and a conditional access policy that requires compliant devices.
C.A device enrollment restriction that blocks devices with an OS version lower than 10.0.19045.
D.A conditional access policy that requires multi-factor authentication for all users.
AnswerB

A device compliance policy can enforce the minimum OS version, marking devices below 10.0.19045 as noncompliant. A conditional access policy that requires compliant devices will then block access to corporate email for noncompliant devices. This combination directly achieves the goal of blocking email access for outdated devices.

Why this answer

To block email access for devices not meeting a minimum OS version, you need a compliance policy that defines that requirement and a conditional access policy that enforces compliance. Configuration profiles and enrollment restrictions do not evaluate compliance for access control, and MFA policies do not consider OS version. Thus, the combination of a compliance policy and a conditional access policy is required.

Exam trap

The trap here is selecting a device configuration profile to enforce OS version, but configuration profiles do not affect compliance state or conditional access decisions.

22
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote workers who do not have access to the corporate network. You need to ensure that the devices are automatically enrolled in Intune and that users can sign in with their Microsoft Entra ID credentials. Which Autopilot deployment mode should you use?

A.Self-deploying mode with Microsoft Entra join.
B.User-driven mode with Microsoft Entra hybrid join.
C.Pre-provisioning with Microsoft Entra hybrid join.
D.User-driven mode with Microsoft Entra join.
AnswerD

User-driven mode with Microsoft Entra join allows users to sign in with their Microsoft Entra ID credentials during OOBE. The device joins Microsoft Entra ID and automatically enrolls in Intune. This mode is ideal for remote workers because it does not require on-premises network connectivity. It meets the requirements of automatic enrollment and Microsoft Entra ID sign-in.

Why this answer

User-driven mode with Microsoft Entra join is the correct choice for remote workers because it allows users to sign in with their Microsoft Entra ID credentials during OOBE, automatically joins the device to Microsoft Entra ID, and enrolls it in Intune without requiring on-premises network connectivity. Other modes either do not support user sign-in or require domain connectivity.

Exam trap

The trap here is assuming that hybrid join is needed for Microsoft Entra ID sign-in, but hybrid join requires on-premises connectivity that remote workers lack.

23
MCQeasy

You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?

A.Compliance policies
B.Enrollment restrictions
C.Windows Autopilot devices blade
D.Device cleanup rules in Intune admin center
AnswerD

Device cleanup rules in the Intune admin centre let administrators specify an inactivity threshold, such as 90 days since last check-in, after which Intune automatically retires the device. This directly satisfies the requirement to retire stale devices without manual intervention.

Why this answer

Device cleanup rules in the Intune admin center allow administrators to automatically retire or delete devices that have not checked in for a specified number of days. This is the correct location because the rule is specifically designed for lifecycle management of stale devices, not for compliance or enrollment policies. Setting the threshold to 90 days ensures that devices exceeding that inactivity period are removed from management.

Exam trap

The trap here is that candidates often confuse compliance policies (which can mark devices as non-compliant for inactivity) with the actual retirement action, but compliance policies do not automatically retire devices—they only trigger conditional access or user notifications, whereas device cleanup rules perform the actual removal.

How to eliminate wrong answers

Option A is wrong because compliance policies evaluate device configuration and health against rules (e.g., requiring encryption or a minimum OS version) and can mark devices as non-compliant, but they do not automatically retire devices based solely on check-in inactivity. Option B is wrong because enrollment restrictions control which devices can enroll (e.g., by platform, OS version, or device manufacturer) and do not manage post-enrollment lifecycle actions like retirement. Option C is wrong because the Windows Autopilot devices blade is used to manage Autopilot deployment profiles and device registration for zero-touch provisioning, not to configure automatic retirement rules for stale devices.

24
MCQhard

You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?

A.Devices must have line-of-sight to an on-premises domain controller.
B.Devices must have VPN connectivity to Azure.
C.An Intune connector for Active Directory must be installed.
D.Azure AD Connect must be configured with password hash sync.
AnswerA

Hybrid Azure AD join requires the device to authenticate against on-premises Active Directory during Autopilot's offline domain join phase, so the device needs network line-of-sight to a domain controller. Without that connectivity, the off-premises domain join cannot complete, and Microsoft Entra ID hybrid registration subsequently fails.

Why this answer

For hybrid Azure AD join via Windows Autopilot, the device must complete domain join during the out-of-box experience. This requires line-of-sight to an on-premises domain controller so that the domain join operation can succeed, as the device cannot join the domain without contacting a DC directly over the network.

Exam trap

The trap here is that candidates often confuse the Intune connector for Active Directory (which is needed for device writeback in hybrid scenarios) with the actual domain join requirement, but the connector does not replace the need for direct line-of-sight to a domain controller.

How to eliminate wrong answers

Option B is wrong because VPN connectivity to Azure is not required; the device needs connectivity to on-premises domain controllers, not Azure. Option C is wrong because the Intune connector for Active Directory is used for device writeback and synchronization, not for the domain join step itself. Option D is wrong because password hash sync is a feature of Azure AD Connect for authentication, not a prerequisite for hybrid Azure AD join; the device must be able to authenticate to the on-premises domain controller directly.

25
MCQmedium

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?

A.Device configuration profile
B.Device compliance policy
C.Enrollment restriction
D.App protection policy
AnswerB

A device compliance policy defines passcode requirements, including minimum length, and feeds that state to Microsoft Entra ID. Conditional Access then blocks corporate email on non-compliant iOS devices, directly enforcing the longer-than-six-character passcode constraint before granting access.

Why this answer

Device compliance policies in Microsoft Intune evaluate device settings against defined rules, such as requiring a passcode longer than six characters. When a device is marked noncompliant, Conditional Access can block access to corporate email. This is the correct mechanism because compliance policies are specifically designed to enforce security requirements like passcode length before granting resource access.

Exam trap

The trap here is confusing device configuration profiles (which can set a passcode policy) with compliance policies (which enforce and block access), leading candidates to choose Option A because they think 'configure a policy' means setting the passcode requirement, not enforcing it.

How to eliminate wrong answers

Option A is wrong because device configuration profiles are used to configure device settings (e.g., Wi-Fi, VPN, or passcode policy) but do not enforce compliance or block access to resources; they simply push settings. Option C is wrong because enrollment restrictions control which devices can enroll in Intune (e.g., by platform or OS version), not post-enrollment security requirements like passcode length. Option D is wrong because app protection policies (MAM) manage data within apps (e.g., copy/paste, encryption) and do not enforce device-level passcode requirements; they apply even on unmanaged devices.

26
MCQmedium

A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?

A.Use the Microsoft Store for Business to deploy only approved apps.
B.Deploy AppLocker rules via Intune to allow only approved publishers.
C.Enable Windows Defender SmartScreen to block unknown apps.
D.Configure User Account Control (UAC) to always notify.
AnswerB

AppLocker rules deployed through Intune let you allow only approved publishers, giving publisher, product name, file name and version-level control over executables, which is more granular than the broader allow or block lists offered by other application control methods.

Why this answer

AppLocker provides the most granular control because it allows administrators to create rules based on publisher, product name, file name, file version, or file hash, and apply them to specific users or groups. Deployed via Intune, these rules can enforce which applications are allowed to run, effectively blocking unapproved installations. This level of detail (e.g., allowing only signed apps from a specific publisher) is not achievable with the other options.

Exam trap

MD-102 often tests the difference between application control (AppLocker/WDAC) and application management (Intune app deployment); candidates may confuse 'prevent installation' with 'control availability' and pick Store for Business or SmartScreen, which do not provide granular allow-listing.

How to eliminate wrong answers

Option A is wrong because Microsoft Store for Business only controls which apps are available for self-service installation from the Store; it does not prevent users from installing applications from other sources (e.g., downloading executables from the internet). Option C is wrong because SmartScreen blocks only known malicious or untrusted apps based on reputation, not a custom allow list of approved applications; it cannot enforce a granular policy. Option D is wrong because UAC prompts for elevation but does not block installation of unapproved applications; users with admin rights can still install anything.

27
MCQhard

Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?

A.Install the Intune connector for ConfigMgr and configure the workloads.
B.Create a Group Policy that enables automatic MDM enrollment to Intune.
C.In ConfigMgr, enable co-management, select the devices for pilot, and set the 'Device configuration' workload slider to 'Pilot Intune' or 'Intune'.
D.Configure hybrid Azure AD join for all devices via Group Policy and wait for auto-enrollment.
AnswerC

Co-management requires enabling the feature in ConfigMgr, targeting a pilot collection, then moving each workload slider independently. Setting Device configuration to Pilot Intune or Intune shifts that workload to Intune while Compliance policies and Windows Update policies remain in ConfigMgr.

Why this answer

To enable co-management and move the Device configuration workload to Intune, you need to configure co-management in ConfigMgr. This involves enabling co-management, selecting a pilot collection (or all devices), and setting the workload slider for Device configuration to either 'Pilot Intune' or 'Intune' (full migration). This triggers automatic enrollment in Intune via the co-management policy.

Option A is incorrect because the Intune connector is not needed for co-management; enrollment happens via ConfigMgr policy. Option B is incorrect because Group Policy for automatic MDM enrollment is not required when using co-management; the enrollment is triggered by ConfigMgr. Option D is incorrect because hybrid Azure AD join alone does not automatically enroll devices into co-management; the ConfigMgr co-management configuration is necessary.

28
MCQmedium

You are designing the Windows Autopilot deployment profile for a new subsidiary that has no on-premises infrastructure. All devices will be Microsoft Entra joined. The security team requires that during the out-of-box experience (OOBE), users authenticate with their Microsoft Entra credentials and that local administrator rights are not granted to the primary user. You also want to minimize the time spent at OOBE. Which deployment mode should you select in the Autopilot profile?

A.Microsoft Entra hybrid join with user-driven mode
B.User-driven mode with Microsoft Entra join
C.Pre-provisioning with white glove
D.Self-deploying mode
AnswerB

User-driven mode with Microsoft Entra join prompts the user to sign in with their Microsoft Entra credentials during OOBE, which meets the requirement for authentication. It does not automatically grant local administrator rights unless you explicitly configure the user as a local admin in the profile, so the security requirement is satisfied. This mode also streamlines OOBE by applying device settings and apps automatically after sign-in.

Why this answer

User-driven mode with Microsoft Entra join allows the user to sign in with their Microsoft Entra credentials during OOBE, satisfying the authentication requirement. It does not grant local administrator rights by default, aligning with the security policy. The absence of on-premises infrastructure rules out hybrid join, and self-deploying mode skips user authentication, while pre-provisioning is unnecessary for the stated goals.

Exam trap

The trap here is assuming that self-deploying mode authenticates users; it actually uses the device identity and is intended for shared or kiosk devices.

29
MCQmedium

You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?

A.Device compliance policy for Windows 10 and later
B.Endpoint security policy for Windows 10 and later
C.Device configuration profile for Windows 10 and later
D.App protection policy for Windows 10 and later
AnswerA

A device compliance policy for Windows 10 and later allows you to specify a minimum OS version for Windows devices. You can set the required minimum OS version to 10.0.22621.1992, and Intune will evaluate the device's OS build and mark it noncompliant if it does not meet the requirement. This directly enforces the security team's requirement.

Why this answer

A device compliance policy for Windows 10 and later is the correct choice because it includes a setting to require a minimum OS version. By setting the minimum OS version to 10.0.22621.1992, Intune will evaluate the OS build and mark devices that do not meet the requirement as noncompliant, which can then trigger conditional access or other actions.

Exam trap

The trap here is confusing device configuration profiles, which configure settings, with compliance policies, which evaluate and report on device state.

30
Multi-Selectmedium

You are an endpoint administrator for a company that uses Microsoft Intune. The company plans to deploy Windows 11 devices using Windows Autopilot in self-deploying mode. You need to ensure that the devices can be provisioned without any user interaction. Which two configurations are required for self-deploying mode? (Choose two.)

Select 2 answers
A.The device must be joined to an on-premises Active Directory domain.
B.The device must be registered with Windows Autopilot.
C.The device must have a wired network connection.
D.The device must have TPM 2.0 enabled.
E.A device enrollment manager (DEM) account must be assigned.
AnswersB, D

Before a device can use self-deploying mode, it must be registered with Windows Autopilot. This involves uploading the device's hardware hash to Intune. The Autopilot service uses this hash to identify the device and assign the appropriate deployment profile. Without registration, the device will not receive the self-deploying profile during OOBE.

Why this answer

Self-deploying mode requires TPM 2.0 and that the device is registered with Windows Autopilot. TPM 2.0 provides the hardware-based identity needed for device authentication without user credentials. Autopilot registration ensures the device receives the self-deploying profile.

On-premises domain join, DEM accounts, and wired connections are not required for this mode.

Exam trap

The trap here is assuming that self-deploying mode requires a DEM account or wired connection, when it actually relies on TPM 2.0 and Autopilot registration.

31
Multi-Selectmedium

Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?

Select 2 answers
A.Maximum OS version
B.Require antivirus (Windows Defender)
C.Minimum OS version
D.Device type
E.Storage encryption
AnswersB, C

Requiring antivirus in the Windows compliance policy directly satisfies the stem's second condition: devices must have antivirus enabled. Intune evaluates Windows Defender's real-time protection status through this setting, marking non-compliant devices that lack active antivirus. Combined with the minimum OS version setting, both stated requirements are enforced.

Why this answer

Option C (Minimum OS version) is correct because a Windows compliance policy enforces a required OS build/version by setting the minimum OS version, which blocks devices running older builds than the specified value. Option B (Require antivirus (Windows Defender)) is correct because the compliance policy includes a setting that requires Windows Defender Antivirus to be enabled (and optionally up to date) on the device. Option A (Maximum OS version) is not appropriate here because the requirement is to ensure devices are at least a specific OS version, not to cap them at a maximum version.

Option D (Device type) is not a compliance setting for enforcing OS version or antivirus state; it is used for targeting/platform scoping. Option E (Storage encryption) enforces BitLocker/device encryption and does not address the OS version or antivirus requirements.

Exam trap

MD-102 often tests the distinction between compliance settings that validate device state (minimum OS, antivirus, encryption) versus configuration settings that change device state, causing candidates to pick Maximum OS version or Device type by mistake.

32
MCQhard

Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?

A.The device will be allowed to proceed because enrollment status is notStarted.
B.The device will retry enrollment automatically.
C.The device will be blocked from completing OOBE.
D.The device will be blocked until retry due to pendingRetry setting.
AnswerC

When a required app fails during Autopilot OOBE, the enrolment profile's blocking behaviour halts the process, so the device cannot complete setup. This matches the stem's failed-app scenario: the device is blocked from finishing OOBE rather than continuing with reduced functionality.

Why this answer

The Autopilot deployment profile shown has the Enrollment Status Page (ESP) configured with 'Block device use until all required apps and profiles are installed' enabled. When a required app fails to install during OOBE, the ESP enforces a hard block, preventing the user from proceeding past the ESP until the failure is resolved. This is why the device is blocked from completing OOBE, making option C correct.

Exam trap

The trap here is that candidates confuse the ESP's 'block device use' setting with a simple retry mechanism, assuming the device will automatically retry or proceed, when in fact a hard block is enforced until the failure is resolved.

How to eliminate wrong answers

Option A is wrong because the enrollment status is not 'notStarted'; the ESP tracks installation progress, and a failure triggers a blocking state, not a pass-through. Option B is wrong because the ESP does not automatically retry enrollment; it blocks the device and requires manual intervention (e.g., reset or troubleshooting) unless a retry timeout is configured, which is not shown in the exhibit. Option D is wrong because 'pendingRetry' is not a valid ESP state; the ESP uses states like 'installing', 'failed', or 'timeout', and the device is blocked immediately upon failure, not placed into a pending retry state.

33
Multi-Selectmedium

You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)

Select 2 answers
A.Android store app type.
B.Windows Installer (Win32) app type using the Office Deployment Tool.
C.Web link app type pointing to the Office website.
D.iOS store app type.
E.Microsoft 365 Apps for Windows app type in Intune.
AnswersB, E

Packaging Microsoft 365 Apps as a Win32 app lets Intune run the Office Deployment Tool's setup.exe with a custom configuration XML, controlling which products, languages and update channels install. This satisfies the stem's Intune deployment requirement, since the Office Deployment Tool cannot be delivered through the Microsoft 365 Apps (Windows 10 and later) app type.

Why this answer

Option B is correct because you can package Microsoft 365 Apps as a Windows Installer (Win32) app in Intune by using the Office Deployment Tool (ODT) to generate the setup.exe and Configuration.xml, then wrap it with the Intune Win32 Content Prep Tool for deployment. Option E is correct because Intune provides a dedicated built-in app type called 'Microsoft 365 Apps for Windows' (the Microsoft 365 Apps app type) that lets you select Office apps, update channel, and architecture directly without packaging. Option A is incorrect because the Android store app type deploys Android apps, not Windows Office apps.

Option C is incorrect because a web link app type only creates a shortcut to a URL and does not install Microsoft 365 Apps. Option D is incorrect because the iOS store app type targets iOS devices, not Windows.

Exam trap

The trap here is that candidates often confuse the 'Web link' app type with a valid deployment method, thinking it will trigger an installation, when in fact it only provides a browser shortcut to the Office website without any local installation.

34
MCQhard

You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?

A.Create a dynamic device group in Microsoft Entra ID that includes all Windows 11 devices.
B.Assign Microsoft Intune licenses to all users who will receive the new devices.
C.Register the devices in Windows Autopilot by providing the hardware hash to the Microsoft Intune admin center.
D.Create a compliance policy that requires BitLocker encryption and a minimum OS version.
AnswerC

Windows Autopilot requires each device's hardware hash registered in Intune before deployment, binding the device to the tenant. Uploading hashes establishes this identity, enabling zero-touch provisioning where the vendor ships devices directly to users without IT imaging.

Why this answer

Windows Autopilot is the cloud-based zero-touch deployment solution that uses hardware hashes to register devices in Intune, enabling them to automatically enroll and receive configurations without IT intervention. This directly meets the requirement for pre-provisioned Windows 11 devices with no manual touch.

Exam trap

The trap here is confusing post-enrollment configuration steps (like creating groups or compliance policies) with the prerequisite enrollment mechanism, leading candidates to select a step that is necessary but not sufficient for zero-touch deployment.

How to eliminate wrong answers

Option A is wrong because creating a dynamic device group in Entra ID is a post-enrollment step for applying policies or targeting apps, not a mechanism for zero-touch enrollment itself. Option B is wrong because assigning Intune licenses is a prerequisite for enrollment but does not automate the enrollment process; it must be combined with Autopilot registration to achieve zero-touch. Option D is wrong because creating a compliance policy enforces security settings after enrollment, but it does not initiate or automate the enrollment process.

35
MCQeasy

Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?

A.Enable Device Encryption in Windows settings.
B.Configure a FileVault policy for Windows devices.
C.Create a BitLocker policy in Intune Endpoint Protection.
D.Deploy an Encrypting File System (EFS) policy.
AnswerC

BitLocker policy in Intune Endpoint Protection directly enforces full-disk encryption on Windows 10 laptops, satisfying the corporate encryption requirement. It configures TPM-backed drive encryption and recovery key escrow to Microsoft Entra ID, unlike device compliance policies, which only report encryption state rather than enforce it.

Why this answer

Microsoft Intune's Endpoint Protection policy includes a dedicated BitLocker settings section that allows administrators to enforce encryption on Windows 10 devices. This policy centrally manages BitLocker drive encryption, recovery key escrow to Azure AD, and encryption method (e.g., XTS-AES 128-bit), meeting the requirement for corporate laptop encryption.

Exam trap

The trap here is confusing file-level encryption (EFS) with full-disk encryption (BitLocker), or assuming that Device Encryption in Windows settings is the same as BitLocker, when in fact Device Encryption is a limited feature only available on specific hardware and lacks the management capabilities of Intune's BitLocker policy.

How to eliminate wrong answers

Option A is wrong because 'Enable Device Encryption' in Windows settings is a client-side toggle that only enables hardware-based encryption on devices that support InstantGo (Modern Standby), and it cannot be centrally managed or enforced via Intune policy. Option B is wrong because FileVault is Apple's full-disk encryption technology for macOS, not applicable to Windows 10 devices. Option D is wrong because Encrypting File System (EFS) provides file-level encryption, not full-disk encryption, and is managed via NTFS permissions or Group Policy, not Intune's endpoint protection policies for BitLocker.

36
Multi-Selectmedium

Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?

Select 3 answers
A.Add devices to Apple Business Manager (ABM).
B.Configure automated device enrollment (formerly DEP) in ABM and link to Intune.
C.Create an iOS enrollment profile in Intune with 'Supervised' enabled.
D.Assign a user to each device during enrollment.
E.Create a device compliance policy that requires supervision.
AnswersA, B, C

Adding devices to Apple Business Manager establishes the automated device enrolment (ADE) record Apple requires before Intune can push a supervision profile. Supervision is the constraint here: only DEP-enrolled iOS devices accept non-removable restriction payloads, so ABM enrolment is a mandatory prerequisite step.

Why this answer

Supervision on iOS requires the device to be owned and enrolled through Apple's corporate enrollment channel, so option A is correct: the devices must be added to Apple Business Manager (ABM) so Apple recognizes them as organization-owned and eligible for supervised enrollment. Option B is correct because automated device enrollment (formerly DEP) must be configured in ABM and linked to Intune via an MDM server token, which is the mechanism that pushes the devices into Intune as supervised during Setup Assistant. Option C is correct because the Intune iOS enrollment profile used for these devices must have the 'Supervised' setting enabled; this profile is what actually applies supervision and allows restrictions that users cannot remove.

Option D is not required because user assignment (or user affinity) is optional for automated device enrollment and does not create supervision. Option E is incorrect because a compliance policy only evaluates and reports device state; it cannot enable or grant supervision.

Exam trap

MD-102 often tests that supervision requires ABM + ADE + a supervised enrollment profile — candidates incorrectly think a compliance policy or user assignment can enable supervision.

37
MCQhard

You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?

A.The device is running Windows 10 Home edition.
B.MDM enrollment is blocked by a local Group Policy or registry setting.
C.The device is not connected to the internet.
D.The device has an expired certificate required for enrollment.
AnswerB

Error 0x8018000b indicates the device is already enrolled or MDM enrolment is disabled locally. A Group Policy or registry setting blocking MDM enrolment prevents the Intune service from completing enrolment despite valid licensing and supported Windows edition.

Why this answer

Error 0x8018000b indicates that the device is not allowed to enroll, typically because MDM enrollment is blocked by a local Group Policy or registry setting. Even with a valid license and Windows 10 Pro, if the 'MDM Enrollment' policy is disabled or the 'Enrollment automatic' registry key is misconfigured, the enrollment attempt will fail with this specific error.

Exam trap

The trap here is that candidates often assume error 0x8018000b is a licensing or connectivity issue, but it specifically indicates that enrollment is administratively blocked, not that the device is unsupported or offline.

How to eliminate wrong answers

Option A is wrong because the question explicitly states the device runs Windows 10 Pro, not Home edition, and error 0x8018000b is not related to edition restrictions (which would produce a different error). Option C is wrong because lack of internet connectivity would generate a different error (e.g., 0x8018000a or timeout), not 0x8018000b. Option D is wrong because an expired certificate would produce a certificate-related error (e.g., 0x80180014 or 0x8018000c), not the specific 'enrollment blocked' code 0x8018000b.

38
Multi-Selecthard

Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?

Select 3 answers
A.The use of co-management to gradually move workloads.
B.The ability to manage on-premises servers with Intune.
C.The compatibility of existing application packages with Intune formats (Win32, LOB).
D.The need for an on-premises Intune server.
E.Network bandwidth requirements for device communication with Intune.
AnswersA, C, E

Co-management lets you move workloads such as compliance policies and Windows Update rings incrementally, keeping Configuration Manager authoritative until each is proven. This staged authority transfer satisfies the migration factor of controlling risk while devices transition to Microsoft Intune.

Why this answer

Option A is correct because co-management lets you attach Configuration Manager-managed devices to Intune and progressively shift workloads such as compliance policies, resource access, and Windows Update policies from Configuration Manager to Intune, enabling a controlled, phased migration rather than a disruptive cutover. Option C is correct because existing Configuration Manager applications and packages must be repackaged or converted into Intune-supported formats such as Win32 apps (.intunewin), line-of-business (LOB) apps, or Microsoft Store apps, and this compatibility assessment is essential for planning remediation and testing effort. Option E is correct because Intune is a cloud service, so devices must reach Microsoft endpoints over the internet, making bandwidth, proxy, firewall, and content-download requirements (for example, Windows Update for Business and Win32 app content) a key planning factor.

Option B is not correct because Intune does not manage on-premises Windows Server workloads the way Configuration Manager does; servers generally remain with Configuration Manager or another on-premises tool. Option D is not correct because Intune is a fully cloud-hosted Microsoft service and requires no on-premises Intune server; only the Configuration Manager site infrastructure remains on-premises during co-management.

Exam trap

The trap here is that candidates often assume Intune can manage on-premises servers like Configuration Manager does, or that an on-premises Intune server exists, when in reality Intune is purely cloud-based and cannot replace Configuration Manager for server management.

39
MCQmedium

Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?

A.Devices are onboarded to Defender for Endpoint
B.Group Policy objects are linked to the domain
C.Security baselines are configured and assigned in Intune endpoint security
D.Devices are registered in Microsoft 365 Defender portal
AnswerC

Security baselines in Intune endpoint security define and assign the configuration settings whose compliance state devices report. Verifying they are configured and assigned ensures Windows devices actually evaluate and surface baseline compliance data to Intune.

Why this answer

Intune security baselines are the mechanism that defines and enforces security configuration policies on Windows devices. To report compliance with those baselines, the baselines must first be configured and assigned to the devices via Intune endpoint security. Without this assignment, devices have no baseline to compare against, and compliance reporting will not occur.

Exam trap

The trap here is that candidates often confuse onboarding to Defender for Endpoint (which enables security telemetry and threat detection) with the separate requirement of configuring and assigning Intune security baselines to enforce and report compliance.

How to eliminate wrong answers

Option A is wrong because onboarding devices to Defender for Endpoint ensures they can send telemetry and be managed for threat detection, but it does not by itself configure or report on security baseline compliance; that requires Intune security baseline policies. Option B is wrong because Group Policy objects are a traditional on-premises management tool that does not report compliance to Intune; Intune uses its own policy engine and MDM channel, not GPOs. Option D is wrong because registering devices in the Microsoft 365 Defender portal is part of the Defender for Endpoint onboarding process and does not create or assign security baseline policies; compliance reporting to Intune requires the Intune security baseline assignment.

40
MCQhard

You are the endpoint administrator for Contoso Ltd., a multinational company with 10,000 Windows 10 and 11 devices managed by Microsoft Intune. The company recently acquired a subsidiary that uses on-premises Active Directory and Configuration Manager. The subsidiary's devices are not joined to Microsoft Entra ID. Your goal is to migrate these devices to cloud management with Intune within six months. The subsidiary has 2,000 devices, all running Windows 10. The devices are currently domain-joined and managed by ConfigMgr. You need to choose the most efficient migration strategy that minimizes user disruption and leverages existing investments. The subsidiary has a high-speed WAN link to the corporate network. You have the following options: A) Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune. B) Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join. C) Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps. D) Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning. Which option should you choose?

A.Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune.
B.Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join.
C.Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps.
D.Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning.
AnswerB

Co-management lets existing domain-joined devices enrol in Intune while ConfigMgr retains authority, then workloads (compliance policies, Windows Update, endpoint protection) shift gradually to Intune. This satisfies the minimal-disruption constraint and leverages the existing ConfigMgr investment, before the final Entra ID join switch.

Why this answer

Co-management allows you to gradually transition Configuration Manager workloads to Intune without disrupting existing management, leveraging the existing ConfigMgr infrastructure and high-speed WAN link. This minimizes user disruption by keeping devices domain-joined initially, then switching to Entra ID join after workloads are migrated, which is the most efficient path for 2,000 existing domain-joined devices.

Exam trap

The trap here is that candidates often choose Autopilot or PPKG options because they seem 'modern,' but for existing domain-joined devices with ConfigMgr, co-management is the least disruptive and most efficient migration path, not a full wipe or provisioning package.

How to eliminate wrong answers

Option A is wrong because using a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune while keeping the ConfigMgr client creates a dual-management scenario without the benefit of co-management's workload transition capabilities, leading to conflicts and no gradual migration path. Option C is wrong because Windows Autopilot for existing devices requires uploading hardware hashes and resetting devices, which causes significant user disruption (data loss, re-provisioning) and does not leverage the existing ConfigMgr investment or the high-speed WAN link. Option D is wrong because using ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot is overly disruptive (full wipe, data loss) and inefficient compared to co-management, which allows a phased, non-destructive migration.

41
MCQeasy

You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?

A.Join each device to Entra ID manually and then enroll in Intune.
B.Create a provisioning package using Windows Configuration Designer and deploy via USB.
C.Register the devices in Windows Autopilot and deploy an Autopilot profile.
D.Use a Configuration Manager task sequence to deploy the OS.
AnswerC

Windows Autopilot registers devices with Microsoft Entra ID during out-of-box experience, so no manual join is needed. This satisfies the constraint that the 100 computers are not yet joined, letting Intune deliver the Windows 10 Enterprise image and profile automatically.

Why this answer

Windows Autopilot is the recommended method for deploying Windows 10 Enterprise to new devices that are not yet joined to Microsoft Entra ID because it automates the entire provisioning process—from joining Entra ID to enrolling in Intune—without requiring any manual intervention or imaging. By registering the devices in Autopilot and deploying an Autopilot profile, the out-of-box experience (OOBE) is customized to join Entra ID and enroll in Intune automatically, ensuring a zero-touch deployment that aligns with modern management best practices.

Exam trap

The trap here is that candidates often confuse provisioning packages (Option B) as the recommended method for cloud-only deployments, but Autopilot is specifically designed for zero-touch, cloud-native provisioning and is the correct answer for new devices not yet joined to Entra ID.

How to eliminate wrong answers

Option A is wrong because manually joining each device to Entra ID and then enrolling in Intune is not recommended for 100 new computers; it is labor-intensive, error-prone, and defeats the purpose of automated, scalable deployment. Option B is wrong because provisioning packages created with Windows Configuration Designer are typically used for bulk provisioning in on-premises or hybrid scenarios, but they do not leverage cloud-native Autopilot capabilities and require physical USB deployment, which is less efficient for remote or large-scale rollouts. Option D is wrong because using a Configuration Manager task sequence to deploy the OS is a traditional imaging approach that relies on on-premises infrastructure and does not integrate natively with cloud-based Entra ID join and Intune enrollment, making it unsuitable for a modern, cloud-first deployment strategy.

42
Multi-Selectmedium

Which TWO of the following are benefits of using Windows Autopilot for device provisioning?

Select 2 answers
A.Eliminates the requirement for a Microsoft Entra ID subscription.
B.Allows end users to set up their own devices with minimal IT involvement.
C.Enables device provisioning over a VPN connection.
D.Reduces the need for custom imaging and manual setup.
E.Supports deployment without any internet connectivity.
AnswersB, D

Autopilot's cloud-based provisioning lets the end user sign in with their work credentials and complete the out-of-box experience themselves, so IT never touches the device. This satisfies the stem's benefit of minimal IT involvement during provisioning.

Why this answer

Option B is correct because Windows Autopilot lets end users complete the out-of-box experience (OOBE) themselves, joining the device to Microsoft Entra ID and applying Intune policies with minimal IT interaction. Option D is correct because Autopilot uses the OEM-installed Windows image and cloud-based configuration, eliminating the need to build, maintain, and apply custom images or perform manual setup steps. Option A is incorrect because Autopilot depends on Microsoft Entra ID for device identity and user authentication, so an Entra ID subscription is still required.

Option C is incorrect because Autopilot provisioning requires direct internet access and does not support deployment over a VPN connection during OOBE. Option E is incorrect because Autopilot is a cloud-based service that requires internet connectivity throughout provisioning.

Exam trap

The trap here is that candidates often assume Autopilot can work over a VPN or without internet because it is a cloud-based service, but it requires direct internet access during OOBE before any VPN client is installed.

43
MCQmedium

Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?

A.Devices must be registered in Autopilot using hardware hash
B.Devices must be domain-joined to on-premises AD
C.An Azure AD Premium P2 license must be assigned
D.Configuration Manager must be deployed for OS imaging
AnswerA

Autopilot requires each device's hardware hash uploaded to the Autopilot device store, creating the Autopilot device identity that binds hardware to a Microsoft Entra ID tenant. Without this registration, the device cannot receive an Autopilot profile during OOBE.

Why this answer

Windows Autopilot requires that each device be registered in the Autopilot service using its unique hardware hash (also known as a hardware ID). This hash is collected from the device's firmware and uploaded to the Autopilot deployment service, which then associates the device with the target tenant. Without this registration, Autopilot cannot identify the device during the out-of-box experience (OOBE) and cannot automatically enroll it into Microsoft Entra ID.

Exam trap

The trap here is that candidates often assume Autopilot requires an on-premises domain join (option B) because they confuse Autopilot with traditional imaging or hybrid Azure AD join scenarios, but Autopilot's core value is cloud-native, domain-join-free provisioning.

How to eliminate wrong answers

Option B is wrong because Autopilot devices do not need to be domain-joined to on-premises Active Directory; Autopilot is designed to directly join devices to Microsoft Entra ID (formerly Azure AD) during OOBE, bypassing any on-premises dependency. Option C is wrong because while Azure AD Premium P2 licenses provide additional features like Identity Protection and Privileged Identity Management, Autopilot itself only requires Azure AD Premium P1 (or Microsoft 365 E3/E5) for the Autopilot deployment profile and automatic enrollment; P2 is not a prerequisite. Option D is wrong because Configuration Manager is not required for Autopilot; Autopilot uses cloud-based provisioning via Microsoft Intune and does not rely on any on-premises imaging or OS deployment tool like Configuration Manager.

44
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?

A.The device must have a Microsoft Entra ID Premium P2 license assigned.
B.The device must have its hardware hash uploaded to Microsoft Intune.
C.The device must be Azure AD registered before shipping.
D.The device must be joined to on-premises Active Directory first.
AnswerB

Windows Autopilot identifies a device by its unique hardware hash, which must be uploaded to Microsoft Intune to create an Autopilot device record. Without that hash registered, the device cannot be recognised and will not auto-enrol with organisational settings.

Why this answer

For a device to be recognized by Windows Autopilot, its hardware hash must be uploaded to Microsoft Intune. This hash uniquely identifies the device and allows Autopilot to associate it with your organization's Intune tenant. Without the hardware hash, the device cannot be targeted for Autopilot deployment.

Exam trap

MD-102 often tests the misconception that Azure AD join or Intune license is the minimum requirement. The key is the hardware hash upload; without it, Autopilot cannot identify the device.

How to eliminate wrong answers

Option A is wrong because an Entra ID Premium P2 license is not required for Autopilot; Intune licenses are sufficient. Option C is wrong because Azure AD registration is not a prerequisite for Autopilot; devices are typically Azure AD joined during Autopilot. Option D is wrong because on-premises Active Directory join is not required; Autopilot supports Azure AD join and hybrid Azure AD join, but the minimum requirement is the hardware hash upload.

45
Multi-Selecteasy

Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)

Select 2 answers
A.Works offline without internet connectivity.
B.Enables deployment of custom operating system images.
C.Allows IT to provision devices remotely without physical access.
D.Reduces the need for manual imaging and configuration.
E.Eliminates the need for any user interaction during setup.
AnswersC, D

Windows Autopilot uses the cloud-based Autopilot deployment service to join devices to Microsoft Entra ID and apply configuration during out-of-box experience, so IT never touches the hardware. This directly satisfies the stem's remote provisioning requirement, eliminating imaging, shipping devices to technicians, or on-site setup.

Why this answer

Option C is correct because Windows Autopilot lets IT provision and configure devices remotely through the cloud (Microsoft Intune/Endpoint Manager), so administrators never need to touch the hardware or maintain a staging network. Option D is correct because Autopilot uses the OEM-installed Windows image and applies configuration via Intune profiles and the Enrollment Status Page, eliminating the traditional wipe-and-load imaging and manual configuration steps. Options A, B, and E are not benefits of Autopilot: it requires internet connectivity to reach Intune and Azure AD, it deliberately uses the existing OEM image rather than deploying custom images (that is what MDT/ConfigMgr imaging does), and although the Out-of-Box Experience is largely automated, the user still must sign in and may complete some steps, so it does not eliminate all user interaction.

Exam trap

The trap here is that candidates often assume Autopilot eliminates all user interaction (Option E) because of the term 'zero-touch,' but in user-driven mode the user must still sign in, while self-deploying mode (for kiosks or shared devices) can be truly zero-touch—the question does not specify the mode, so Option E is too absolute and incorrect.

46
MCQeasy

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and uses Microsoft Entra ID with Microsoft Intune. You must configure a Windows Autopilot deployment for existing Windows 11 devices that are already joined to the on-premises domain. The devices must remain domain-joined and also be registered in Microsoft Entra ID. You need to create the Autopilot deployment profile. Which deployment mode should you select?

A.Microsoft Entra registered
B.Microsoft Entra hybrid joined
C.Existing device, no Autopilot
D.Microsoft Entra joined
AnswerB

Microsoft Entra hybrid joined mode is designed for devices that must remain joined to on-premises AD DS while also being registered in Microsoft Entra ID. It requires the Intune Connector for Active Directory and a line-of-sight to a domain controller during OOBE. This matches the requirement to keep existing domain membership while enabling Intune management through Autopilot.

Why this answer

The requirement to keep devices joined to on-premises AD DS while also registering them in Microsoft Entra ID and managing them with Intune maps directly to the Microsoft Entra hybrid joined Autopilot mode. This mode uses the Intune Connector for Active Directory to create the computer object in AD DS during OOBE, ensuring the device is both domain-joined and Microsoft Entra registered.

Exam trap

The trap here is confusing Microsoft Entra hybrid joined with Microsoft Entra joined, assuming that any Autopilot deployment automatically includes on-premises domain membership.

47
MCQeasy

You are the endpoint administrator for a company that uses Microsoft Intune. The company has a policy that all Windows devices must have a minimum OS version of 10.0.19045. You need to create a compliance policy that enforces this requirement. Which type of compliance setting should you configure?

A.Custom Compliance
B.Device Health
C.System Security
D.Device Properties
AnswerD

Device Properties in a compliance policy includes settings such as Minimum OS version, Maximum OS version, and Mobile Device Management (MDM) compliance. By specifying the minimum OS version as 10.0.19045, you enforce that devices must run that version or later to be compliant. This directly satisfies the company's policy.

Why this answer

The minimum OS version is a built-in setting under Device Properties in Intune compliance policies. Configuring it there ensures devices are evaluated against the specified version. Other setting categories like Device Health, System Security, and Custom Compliance serve different purposes and do not provide a direct way to set a minimum OS version.

Exam trap

The trap here is confusing Device Health with Device Properties; Device Health monitors security features, not OS version.

48
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that only devices running Windows 11 version 23H2 or later can enroll into Intune. You also want to block enrollment for older Windows versions. What should you configure?

A.A device compliance policy with a minimum OS version rule.
B.A configuration profile with a Windows edition upgrade policy.
C.A conditional access policy requiring compliant devices.
D.An enrollment restriction for Windows devices.
AnswerD

Enrollment restrictions in Intune allow you to control which devices can enroll. You can configure a platform restriction for Windows that specifies a minimum OS version. Devices that do not meet the minimum version will be blocked from enrolling. This is the correct way to prevent older Windows versions from enrolling.

Why this answer

To block enrollment based on OS version, you configure enrollment restrictions. Specifically, you create a Windows enrollment restriction and set a minimum OS version. Devices running versions below the minimum will be prevented from enrolling.

This is a direct control over enrollment eligibility, unlike compliance policies or conditional access which operate after enrollment.

Exam trap

The trap here is assuming that compliance policies or conditional access can block enrollment, but they only affect access after enrollment.

49
MCQhard

You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?

A.Endpoint Protection
B.Windows Update policies
C.Resource access
D.Client apps
AnswerD

Correct. Client apps workload includes the policy to automatically enroll devices to Intune when the Configuration Manager client is installed.

Why this answer

The 'Client apps' workload in Configuration Manager co-management is responsible for synchronizing client applications and enabling automatic enrollment of devices to Intune after the Configuration Manager client is installed. Option A (Endpoint Protection) is incorrect because it manages endpoint protection policies, not enrollment. Option B (Windows Update policies) is incorrect because it governs Windows Update for Business policies, not Intune enrollment.

Option C (Resource access) is incorrect because it configures resource access policies like certificates and VPN, not automatic enrollment.

50
MCQhard

You are planning to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote users who do not have a VPN connection during initial setup. The devices must be Microsoft Entra joined and enrolled in Intune. You need to ensure that the deployment works without requiring a domain controller. Which Autopilot mode should you configure?

A.Microsoft Entra joined
B.Self-deploying mode
C.Pre-provisioning (white glove)
D.Microsoft Entra hybrid joined
AnswerA

Microsoft Entra joined mode does not require on-premises domain connectivity. Devices join Microsoft Entra ID directly and enroll in Intune, making it ideal for remote users without VPN. This mode supports cloud-based management and access to cloud resources without a domain controller.

Why this answer

Microsoft Entra joined mode is the correct choice because it does not require connectivity to an on-premises domain controller. Devices join Microsoft Entra ID and enroll in Intune directly, enabling remote users to complete setup without VPN. This mode is designed for cloud-first management and supports access to cloud resources.

Exam trap

The trap here is selecting pre-provisioning as a solution, but it is a deployment method, not a join mode, and does not eliminate the need for domain controller connectivity in hybrid scenarios.

51
MCQhard

You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?

A.The Conditional Access policy is set to 'Block' instead of 'Grant'.
B.The Conditional Access policy applies only to users in a specific group.
C.The compliance policy is not assigned to the users' devices.
D.The Conditional Access policy does not include the email application as a target.
AnswerD

Conditional Access grants apply only to the cloud apps explicitly targeted, so omitting Exchange Online leaves email unprotected regardless of compliance state. The policy's grant control therefore never evaluates sessions to that resource, satisfying the stem's requirement that non-compliant devices be blocked from corporate email.

Why this answer

A Conditional Access policy must include at least one cloud app as a target. If the corporate email application (e.g., Exchange Online) is not included in the policy, the policy will not apply to access attempts for that app, allowing non-compliant devices to connect. Option A is incorrect because a 'Block' policy would block access, not allow it.

Option B is incorrect because the policy's user scope does not affect whether the app is targeted. Option C is incorrect because while compliance policy assignment is important, the most direct reason is the missing app target.

52
MCQmedium

Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?

A.Get-MgDeviceManagementManagedDeviceCompliancePolicyState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
B.Get-MgDeviceManagementDeviceCompliancePolicySettingStateSummary -DeviceCompliancePolicyId <id>
C.Get-MgDeviceManagementManagedDeviceConfigurationState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
D.Get-MgDeviceManagementDeviceConfigurationState -ManagedDeviceId 87654321-4321-4321-4321-123456789abc
AnswerA

Get-MgDeviceManagementManagedDeviceCompliancePolicyState returns the per-policy compliance state for a specific managed device, including the setting-level failure reasons behind Laptop-02's non-compliant status. Passing the device's ManagedDeviceId satisfies the requirement to retrieve granular non-compliance detail, which the summary output alone does not expose.

Why this answer

Get-MgDeviceManagementManagedDeviceCompliancePolicyState returns the per-policy compliance state for a specific managed device, including the non-compliance reason strings for each assigned compliance policy. This is the correct cmdlet to drill into why a device is non-compliant after identifying it via a device listing. It maps directly to the Intune 'Device compliance' per-policy view in the portal.

Exam trap

MD-102 often tests the confusion between 'CompliancePolicyState' (compliance rules like BitLocker, firewall) and 'ConfigurationState' (settings profiles like Wi-Fi, VPN) — candidates pick the configuration cmdlet because both sound like 'device state'.

How to eliminate wrong answers

Option B is wrong because Get-MgDeviceManagementDeviceCompliancePolicySettingStateSummary returns aggregate setting-level state counts across all devices for a policy — it is a summary, not per-device detail. Option C is wrong because Get-MgDeviceManagementManagedDeviceConfigurationState returns configuration profile (device configuration) states, not compliance policy states — configuration profiles and compliance policies are separate workloads in Intune. Option D is wrong because Get-MgDeviceManagementDeviceConfigurationState is not the correct cmdlet for per-device configuration state; the managed-device-scoped variant is required, and even then it addresses configuration, not compliance.

53
MCQhard

You are configuring a Windows Autopilot deployment for devices that must be hybrid Microsoft Entra joined. The environment includes an on-premises Active Directory domain and Microsoft Entra Connect. You need to ensure the devices can complete the hybrid join during OOBE. Which configuration is required?

A.Configure the Autopilot deployment profile to use Microsoft Entra hybrid join and ensure the device can reach a domain controller and the Intune service during OOBE.
B.Deploy a VPN configuration profile that connects the device to the corporate network before the Autopilot profile is applied.
C.Configure the Autopilot deployment profile to use Microsoft Entra join and rely on Microsoft Entra Connect to convert the device to hybrid join after enrollment.
D.Enable Windows Hello for Business in the Autopilot deployment profile to trigger the hybrid join during OOBE.
AnswerA

For hybrid join Autopilot, the deployment profile must specify Microsoft Entra hybrid join, and the device needs line-of-sight to a domain controller to perform the domain join, plus internet access to reach Intune and Microsoft Entra ID. Both conditions are essential for the OOBE flow to complete successfully.

Why this answer

Hybrid Microsoft Entra join in Autopilot requires the deployment profile to specify that join type and requires network conditions that allow the device to contact a domain controller for the domain join and reach the cloud services for the Microsoft Entra join and Intune enrollment. Missing either condition prevents successful completion.

Exam trap

The trap here is assuming that Microsoft Entra Connect or Windows Hello for Business can produce a hybrid join, when the join type must be selected in the Autopilot profile and domain controller connectivity is mandatory.

54
MCQmedium

You are the Intune administrator for a company that uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that when devices enroll, they automatically receive a set of configuration settings, including a custom Start menu layout and specific Wi-Fi profiles. What should you create and assign?

A.An app configuration policy
B.A compliance policy
C.A PowerShell script deployed via Intune
D.A device configuration profile
AnswerD

Device configuration profiles in Intune allow you to configure settings on devices, such as Start menu layout and Wi-Fi profiles. You can create a profile with the desired settings and assign it to groups of users or devices. Upon enrollment, devices receive and apply these configurations automatically.

Why this answer

Device configuration profiles are the correct choice for deploying settings like Start menu layout and Wi-Fi profiles to devices. They are declarative and ensure that settings are applied consistently. When assigned to groups, devices receive these configurations upon enrollment and check-in, meeting the requirement to automatically provision devices with specific settings.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance evaluates, while configuration enforces settings.

55
Multi-Selecthard

You are preparing infrastructure for Windows Autopilot deployment in a hybrid Microsoft Entra join scenario. You need to ensure that devices can join the on-premises domain and enroll in Intune. Which two components must you configure? (Choose two.)

Select 2 answers
A.Device enrollment manager (DEM) account
B.Intune connector for Active Directory
C.Automatic MDM enrollment in Microsoft Entra ID
D.Windows Autopilot deployment profile with 'Convert all targeted devices to Autopilot'
E.Microsoft Entra Connect with device writeback
AnswersB, C

The Intune connector for Active Directory is required for hybrid Microsoft Entra join. It enables devices to perform an offline domain join during Autopilot, creating computer objects in Active Directory. Without this connector, devices cannot join the domain automatically, and the hybrid join process fails. It must be installed on a server with domain access.

Why this answer

For Windows Autopilot hybrid Microsoft Entra join, the Intune connector for Active Directory is essential to perform the offline domain join, and automatic MDM enrollment in Microsoft Entra ID ensures the device enrolls in Intune. These two components together enable the hybrid join and management workflow.

Exam trap

The trap here is including optional components like device writeback or DEM accounts, which are not required for the core hybrid join and enrollment process.

56
Multi-Selecteasy

Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?

Select 2 answers
A.Request the hardware hash from the device manufacturer (OEM)
B.Extract the hardware hash from the device BIOS
C.Run a PowerShell script on a device that is already running Windows 10 or later
D.Use Microsoft Intune to generate the hardware hash from the device serial number
E.Use Windows Configuration Designer to create a provisioning package that captures the hardware hash
AnswersA, C

OEMs can provide the hardware hash.

Why this answer

OEMs can provide the hardware hash for devices they manufacture, which can be uploaded to Microsoft Intune or the Autopilot deployment service. This method is commonly used for new devices ordered directly from the manufacturer, as the hash is generated during the manufacturing process and included in the device's packaging or accessible via the OEM's portal.

Exam trap

The trap here is that candidates often assume the hardware hash can be extracted from BIOS or generated by Intune from a serial number, but the hash requires a running Windows OS to compute and must be collected via PowerShell or provided by the OEM.

57
Multi-Selecthard

Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?

Select 3 answers
A.A device compliance policy assigned to the device
B.MDM enrollment enabled in Microsoft Entra ID
C.Azure AD Premium P1 license
D.A valid Microsoft Intune license assigned to the user
E.Internet connectivity to Microsoft Intune service
AnswersB, D, E

MDM enrolment must be enabled in Microsoft Entra ID so the tenant's users are permitted to enrol Windows devices into Intune; without this, automatic MDM enrolment fails during OOBE or manual enrolment, regardless of licensing or connectivity.

Why this answer

Option B is correct because MDM enrollment must be enabled in Microsoft Entra ID (the Mobility (MDM and MAM) settings) so that Windows devices can be automatically or manually enrolled into Intune; without this, the tenant cannot accept MDM enrollments. Option D is correct because each enrolling user must hold a valid Microsoft Intune license (for example, an Intune, EMS E3/E5, or Microsoft 365 license that includes Intune) to be entitled to enroll and manage the device. Option E is correct because the Windows device must have internet connectivity to reach the Microsoft Intune service endpoints (and dependent services such as the enrollment and MDM endpoints) to complete enrollment and receive policy.

Option A is not required for enrollment itself, since a device compliance policy is applied after the device is enrolled and is used for conditional access evaluation, not as an enrollment prerequisite. Option C is not required, because Azure AD Premium P1 is not a prerequisite for Intune enrollment; Intune licensing covers the MDM functionality, and automatic MDM enrollment in Entra ID does not require P1.

Exam trap

The trap here is that candidates often confuse post-enrollment requirements (like compliance policies or Azure AD Premium P1) with prerequisites for enrollment, leading them to select options that are only needed after the device is already enrolled.

58
MCQeasy

You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?

A.Windows 10/11 (Microsoft 365 Apps)
B.Microsoft 365 (Web link)
C.Microsoft Store app (new)
D.Windows app (Win32)
AnswerA

The Windows 10/11 (Microsoft 365 Apps) app type uses the Microsoft 365 Apps deployment pipeline, packaging the suite as a required or available install. Marking it available publishes it in the Company Portal for user-initiated installation.

Why this answer

The 'Windows 10/11 (Microsoft 365 Apps)' app type in Intune is specifically designed to deploy Microsoft 365 Apps (formerly Office 365 ProPlus) with built-in support for the Office Deployment Tool (ODT) and XML configuration. This app type automatically handles the installation, updates, and licensing via the Microsoft 365 Apps for enterprise channel, and it appears in the Company Portal for user-initiated installation. Other app types lack the native integration for Microsoft 365 Apps deployment or do not support user-visible installation in the Company Portal.

Exam trap

The trap here is that candidates often choose 'Windows app (Win32)' because they think any desktop app must be deployed as a Win32 app, overlooking the dedicated Microsoft 365 Apps app type that provides built-in ODT integration and automatic update management.

How to eliminate wrong answers

Option B (Microsoft 365 (Web link)) is wrong because it only creates a shortcut to a web URL in the Company Portal, not an actual app installation, so it cannot deploy Microsoft 365 Apps locally. Option C (Microsoft Store app (new)) is wrong because it is used for deploying apps from the Microsoft Store, not for deploying Microsoft 365 Apps via the Office Deployment Tool. Option D (Windows app (Win32)) is wrong because while it can deploy any Win32 app, it requires manual packaging of the Office installation files and does not provide the built-in ODT integration, update management, or automatic licensing that the dedicated Microsoft 365 Apps app type offers.

59
MCQhard

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?

A.Use a Mobile App Configuration policy to enforce app settings.
B.Deploy an Intune App Protection Policy (APP) for Microsoft 365 apps.
C.Create a Device Compliance policy for iOS devices.
D.Configure a Conditional Access policy to require compliant devices.
AnswerB

App Protection Policies apply data-loss controls at the app layer, restricting copy, paste, save-as and sharing between managed Microsoft 365 apps and unmanaged locations, which protects corporate data on iOS devices without requiring full device enrolment.

Why this answer

Intune App Protection Policies (APP) are designed specifically to protect corporate data at the app layer on iOS and Android, without requiring device enrollment. They enforce controls like PIN access, blocking copy/paste to personal apps, and selective wipe of corporate data within Microsoft 365 apps. This directly addresses the requirement to protect corporate data when users access Microsoft 365 apps.

Exam trap

MD-102 often tests the confusion between App Protection Policies (data protection at app layer) and Device Compliance Policies (device state evaluation), tricking candidates into choosing compliance when the requirement is data protection.

How to eliminate wrong answers

Option A is wrong because a Mobile App Configuration policy customizes app settings (e.g., server URLs, feature toggles) but does not enforce data protection controls like encryption or copy/paste restrictions. Option C is wrong because a Device Compliance policy evaluates device state (OS version, jailbreak status, encryption) and marks the device compliant or not, but does not itself protect app data. Option D is wrong because Conditional Access controls access to resources based on conditions like compliance or location, but does not protect data within apps once access is granted.

60
MCQhard

A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?

A.The OMA-URI setting is invalid.
B.The device is not enrolled.
C.The device's group membership is still being processed, so policies are not yet applied.
D.The device is not compliant.
AnswerC

Group membership processing delays policy targeting: Intune evaluates assignments dynamically, so a newly added device may report enrolled and compliant before its configuration profile reaches it. MaxInactivityTimeDeviceLock applies only once the device falls into the assigned group, satisfying the stem's unapplied-setting constraint.

Why this answer

When a device shows 'Enrolled' and 'Compliant' in Intune, the issue is not enrollment or compliance but policy delivery. The 'MaxInactivityTimeDeviceLock' OMA-URI setting (./Device/Vendor/MSFT/Policy/Config/DeviceLock/MaxInactivityTimeDeviceLock) is a CSP-based policy that applies via group membership targeting. If the device was recently added to the group or the group membership is still being evaluated, Intune's policy processing cycle (which runs every 15–30 minutes by default) may not have delivered the policy yet.

The JSON exhibit likely shows the device is in a pending state for policy application despite being enrolled and compliant.

Exam trap

The trap here is that candidates see 'Enrolled' and 'Compliant' and assume the device is fully healthy, but they overlook that policy application is asynchronous and depends on group membership processing, which can lag behind enrollment and compliance evaluation.

How to eliminate wrong answers

Option A is wrong because if the OMA-URI setting were invalid, the policy would show an error or 'Not applicable' status in Intune, not a missing application while the device remains compliant. Option B is wrong because the device explicitly shows enrollment state 'Enrolled', so the device is enrolled and this contradicts the premise. Option D is wrong because the device shows compliance state 'Compliant', so non-compliance is not the reason the policy is not applied.

61
Multi-Selectmedium

You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?

Select 2 answers
A.Microsoft Defender for Endpoint license assigned to the user or device
B.macOS device enrollment in Microsoft Intune
C.Microsoft Intune management extension installed on the device
D.Onboarding to Microsoft Defender for Cloud
E.A VPN connection to the corporate network
AnswersA, B

Onboarding macOS devices to Microsoft Defender for Endpoint through Intune requires an assigned Defender for Endpoint licence, whether user-based or device-based, to provision the service and permit portal onboarding. Without this entitlement, Intune cannot deploy the Defender agent or activate protection.

Why this answer

The correct prerequisites are: A and B. For A: Microsoft Defender for Endpoint requires a valid license assigned to the user or device. For B: The macOS device must be enrolled in Microsoft Intune to receive the configuration profile and policies for Defender.

Option C is incorrect because the Microsoft Intune management extension is for Windows only, not macOS. Option D is incorrect because onboarding to Microsoft Defender for Cloud is not a prerequisite; Defender for Endpoint can be deployed independently. Option E is incorrect because a VPN connection is not required for Defender for Endpoint to function on macOS.

62
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. Contoso has an on-premises Active Directory Domain Services (AD DS) forest and uses Microsoft Entra ID with Microsoft Intune. You plan to deploy 200 new Windows 11 devices by using Windows Autopilot in Microsoft Entra hybrid join mode. You need to ensure that each device is automatically joined to AD DS and registered in Microsoft Entra ID during the out-of-box experience. What should you configure first?

A.Install and configure the Intune Connector for Active Directory.
B.Assign a Windows Autopilot deployment profile to all targeted devices.
C.Create a device enrollment restriction that blocks personal Windows devices.
D.Enable automatic enrollment for Windows devices in Intune.
AnswerA

The Intune Connector for Active Directory allows Autopilot devices to perform the offline domain join during the out-of-box experience and create the computer object in a chosen organizational unit. Without this connector, Windows cannot complete the AD DS join and therefore cannot achieve Entra hybrid join. It must be installed on a server that can reach both AD DS and the internet.

Why this answer

For Windows Autopilot in Microsoft Entra hybrid join mode, the device must join on-premises AD DS and then register with Microsoft Entra ID. The Intune Connector for Active Directory is the component that performs the offline domain join during OOBE and creates the computer object. Deployment profiles, enrollment restrictions, and automatic enrollment are supporting configurations, but none of them enables the actual domain join step.

Exam trap

The trap here is assuming that an Autopilot deployment profile configured for hybrid join is sufficient, when the domain join itself depends on the Intune Connector for Active Directory.

63
Multi-Selectmedium

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?

Select 2 answers
A.Create a SCEP certificate profile in Intune.
B.Create a device compliance policy that includes the certificate.
C.Create a Wi-Fi profile and embed the certificate in the profile.
D.Create a VPN profile that includes the certificate.
E.Create a PKCS certificate profile in Intune.
AnswersA, E

SCEP profiles request and install certificates from a CA.

Why this answer

A SCEP certificate profile in Intune allows iOS/iPadOS devices to request a certificate from a Simple Certificate Enrollment Protocol (SCEP) server, which can then be used for Wi-Fi authentication. This method supports automated enrollment and renewal of certificates without manual intervention, making it suitable for large-scale deployments.

Exam trap

The trap here is that candidates often confuse a Wi-Fi profile's ability to reference a certificate with the ability to embed the certificate directly, leading them to select option C, but Intune requires the certificate to be deployed separately via a certificate profile.

64
MCQeasy

You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?

A.Microsoft 365 Apps for Windows
B.Web link
C.Windows app (MSI)
D.Line-of-business app
AnswerA

The Microsoft 365 Apps for Windows app type is purpose-built for deploying Office to Windows devices through Intune, delivering the Click-to-Run package with update channel and configuration control. It satisfies the 200-device Windows deployment requirement without packaging the installer manually.

Why this answer

The Microsoft 365 Apps for Windows app type in Intune is specifically designed to deploy the Microsoft 365 Apps suite (e.g., Word, Excel, Outlook) to Windows devices. It provides built-in configuration options for update channels, removal of previous Office versions, and license assignment, making it the correct choice for deploying Microsoft 365 Apps to 200 devices. Other app types lack the integrated logic to handle the suite's installation, activation, and update management.

Exam trap

The trap here is that candidates often confuse the 'Microsoft 365 Apps for Windows' app type with the 'Windows app (MSI)' or 'Line-of-business app' types, mistakenly thinking they can upload an Office installer manually, but Intune requires the dedicated app type to properly handle the Click-to-Run installation and licensing integration.

How to eliminate wrong answers

Option B is wrong because a web link app type only creates a shortcut to a URL on the device's Start menu or desktop, not an actual software installation. Option C is wrong because Windows app (MSI) is used for deploying traditional MSI-based applications, but Microsoft 365 Apps is not distributed as a single MSI file; it uses the Office Deployment Tool (ODT) and Click-to-Run technology. Option D is wrong because the line-of-business (LOB) app type is intended for sideloading app packages (e.g., .intunewin, .msi, .appx) that are not available in the public store, but it does not provide the specialized configuration options for Microsoft 365 Apps, such as channel selection or exclusion of specific apps.

65
MCQmedium

Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?

A.The device is not enrolled in Intune correctly.
B.The password policy is conflicting with Secure Boot.
C.The virtual machine does not have Secure Boot enabled in its firmware settings.
D.The device does not have BitLocker enabled, which is required for Secure Boot.
AnswerC

Secure Boot is a firmware-level UEFI feature, so a virtual machine reports non-compliant when its firmware settings have Secure Boot disabled. Enabling it in the VM's firmware configuration satisfies the compliance policy's Secure Boot requirement.

Why this answer

Secure Boot is a hardware-based feature that ensures the system boots using only software trusted by the PC manufacturer. In virtual machines, Secure Boot is often not enabled by default or may not be supported by the hypervisor. For Intune compliance, if the VM does not have Secure Boot enabled, it will report as non-compliant.

Option C is correct because the VM's firmware settings likely have Secure Boot disabled. Option A is incorrect because the device may still be enrolled correctly. Option B is incorrect because password policy is unrelated to Secure Boot.

Option D is incorrect because BitLocker is a separate encryption feature not required for Secure Boot.

66
MCQeasy

You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?

A.Update rings
B.Configuration profiles
C.Device enrollment profiles
D.Compliance policies
AnswerB

Configuration profiles deliver a standard baseline of device settings, including disk encryption and firewall rules, to targeted groups. This satisfies the stem's requirement for uniform security settings across all corporate devices, unlike compliance policies, which only assess and report state.

Why this answer

Configuration profiles in Microsoft Intune are the correct feature to deploy standard security settings such as disk encryption (e.g., BitLocker) and firewall configuration across corporate devices. These profiles define device-level policies that enforce specific configurations, including endpoint protection settings, and can be assigned to groups of devices to ensure consistent security baselines.

Exam trap

The trap here is that candidates often confuse compliance policies with configuration profiles, mistakenly thinking that compliance policies can apply settings, when in fact compliance policies only evaluate and report on settings that must already be configured by a profile or other means.

How to eliminate wrong answers

Option A (Update rings) is wrong because update rings manage the rollout and deferral of Windows updates, not the configuration of security settings like encryption or firewall rules. Option C (Device enrollment profiles) is wrong because enrollment profiles control the enrollment process and initial device setup (e.g., user affinity, enrollment restrictions), not ongoing security configurations. Option D (Compliance policies) is wrong because compliance policies define conditions that devices must meet to be considered compliant (e.g., requiring encryption), but they do not actually apply the settings; they only mark devices as non-compliant if the settings are missing, whereas configuration profiles actively enforce the settings.

67
MCQmedium

A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?

A.Verify that BitLocker is enabled on the device.
B.Check the Enrollment Status Page (ESP) profile configuration in Intune.
C.Ensure that the device has a local administrator password set.
D.Review the Windows Autopilot deployment profile assigned to the device.
AnswerB

ESP profiles can cause enrollment failures if they are not configured correctly or if they are blocked.

Why this answer

Enrollment Status Page (ESP) profiles can block enrollment if misconfigured, and checking the Intune console is the first step to see errors. Option A is wrong because BitLocker is not related to enrollment. Option C is wrong because the local admin password is not required for enrollment.

Option D is wrong because the Autopilot profile is only relevant for Autopilot deployments, not general enrollment.

68
MCQhard

Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?

A.The ESP policy is configured to track progress for Autopilot only, but the device is not using Autopilot.
B.One of the required apps failed to install.
C.The user attempted to retry the setup and it was blocked.
D.The device reset on failure is enabled, causing a reset loop.
AnswerB

The Enrollment Status Page blocks the desktop until every targeted required app installs successfully. If any required app fails, ESP retries and stalls on 'Installing apps' indefinitely, preventing provisioning completion. Blocking apps, not available apps, cause this hang.

Why this answer

The Enrollment Status Page (ESP) policy tracks the installation of required apps during Autopilot provisioning. If a required app fails to install, the ESP will hang on 'Installing apps' indefinitely because it waits for all required apps to succeed before proceeding. This is the most common cause of a stuck ESP at the app phase.

Exam trap

The trap here is that candidates often assume the ESP hangs due to a network issue or user error, but Microsoft explicitly designs the ESP to block on required app failures, making this the primary troubleshooting focus for 'Installing apps' hangs.

How to eliminate wrong answers

Option A is wrong because the ESP policy is explicitly assigned to an Autopilot deployment, and the device is using Autopilot (the user is in provisioning). Option C is wrong because the ESP does not block retry attempts; the user can retry, but if the app continues to fail, the hang persists. Option D is wrong because 'device reset on failure' is a separate setting that triggers a full reset only after a timeout or explicit failure, not a reset loop; the device would not hang indefinitely.

69
MCQeasy

You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?

A.Intune device cleanup rules
B.Conditional access policy
C.Device compliance policy
D.Device configuration profile
AnswerA

Intune device cleanup rules automatically retire or delete devices that have not checked in for a specified number of days. Configuring the inactivity threshold to 30 days in this policy satisfies the stem's automatic retirement requirement.

Why this answer

Intune device cleanup rules allow you to automatically retire devices that have not checked in for a specified number of days. This setting is configured under Tenant Administration > Device Cleanup Rules.

Exam trap

MD-102 often tests the confusion between device compliance (which evaluates health) and device cleanup (which retires inactive devices), leading candidates to choose compliance policies.

How to eliminate wrong answers

Option B is wrong because conditional access policies control access to resources based on conditions, not device retirement. Option C is wrong because compliance policies evaluate device health and can mark devices non-compliant, but do not retire them. Option D is wrong because configuration profiles apply settings to devices, not lifecycle actions.

70
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. You need to ensure that all Windows 10 devices are automatically enrolled in Intune when they are joined to Microsoft Entra ID. What should you configure?

A.Create a device configuration profile with the "Enroll in Intune" setting enabled.
B.In the Microsoft Intune admin center, enable automatic enrollment for Windows devices.
C.Configure a conditional access policy to require compliant devices.
D.Assign an Intune license to each user and instruct them to manually enroll their devices.
AnswerB

Automatic enrollment in Intune is configured in the Microsoft Intune admin center under Devices > Enroll devices > Automatic Enrollment. Enabling the MDM user scope for Windows allows devices to automatically enroll when they join Microsoft Entra ID. This is the correct setting to ensure automatic enrollment without user intervention. It requires appropriate licensing and permissions, but it directly addresses the requirement.

Why this answer

Automatic enrollment in Intune for Windows devices is enabled through the Microsoft Intune admin center by configuring the MDM user scope. This setting ensures that when a device joins Microsoft Entra ID, it automatically enrolls in Intune without user action. Other options either describe non-existent settings or do not provide automatic enrollment.

Exam trap

The trap here is confusing automatic enrollment with conditional access or device configuration profiles, which serve different purposes and do not initiate enrollment.

71
MCQeasy

Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?

A.Azure AD Premium P1 license is required.
B.Microsoft Intune must be enabled for auto-enrollment.
C.Microsoft Defender for Endpoint must be deployed.
D.Microsoft Entra Connect must be installed and configured.
AnswerD

Microsoft Entra hybrid join requires the device's computer account to exist in both on-premises Active Directory and Microsoft Entra ID. Microsoft Entra Connect synchronises those objects, so it must be installed and configured before hybrid join can succeed.

Why this answer

Microsoft Entra hybrid joined devices require synchronization of on-premises Active Directory identities to Microsoft Entra ID. Microsoft Entra Connect (or Microsoft Entra Connect Sync) is the tool that performs this identity synchronization, making it a mandatory prerequisite. Without it, the on-premises AD objects cannot be linked to Entra ID for hybrid join.

Exam trap

The trap here is that candidates often confuse licensing requirements (Premium P1) or optional management tools (Intune, Defender) with the core prerequisite of identity synchronization, which is the foundational step for hybrid join.

How to eliminate wrong answers

Option A is wrong because Azure AD Premium P1 is not a prerequisite for hybrid join; it is required for features like Conditional Access or self-service password reset, but hybrid join itself works with any Azure AD license, including Free. Option B is wrong because Microsoft Intune auto-enrollment is optional for managing hybrid joined devices but not a prerequisite for the join process itself. Option C is wrong because Microsoft Defender for Endpoint is a security solution that can be deployed on hybrid joined devices but is not required for the hybrid join configuration.

72
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?

A.Create a compliance policy and assign it to a group containing the department's users.
B.Create a compliance policy and assign it to a group containing the department's devices.
C.Create a compliance policy and assign it to all devices, then exclude the department's devices.
D.Create a device configuration profile and assign it to the department's devices.
AnswerB

Compliance policies in Intune are assigned to groups, and assigning to a group that contains the department's devices scopes the policy to only those devices. This satisfies the requirement to apply settings to a specific department without affecting others. Device-based group targeting is the standard approach for scoping compliance policies to a subset of managed devices.

Why this answer

Compliance policies are assigned to groups, and to affect only a specific department's devices, the policy should be assigned to a device group that contains those devices. Assigning to all devices with exclusions, using a configuration profile, or targeting users would either invert the scope, fail to produce a compliance signal, or inadvertently include devices outside the department. Device group targeting is the precise and standard method.

Exam trap

The trap here is choosing user group targeting for a compliance policy, which can unintentionally apply to every device a user signs in to rather than only the department's corporate devices.

73
Multi-Selectmedium

You are planning to deploy Windows 11 devices using Windows Autopilot in Microsoft Intune. The company requires that the devices are Microsoft Entra joined and that the enrollment process includes the installation of required applications and configuration of device settings. You need to identify which two components are required to achieve this. (Choose two.)

Select 2 answers
A.Enrollment Status Page (ESP).
B.Autopilot deployment profile.
C.Microsoft Intune Connector for Active Directory.
D.Windows Configuration Designer package.
E.Device-based conditional access policy.
AnswersA, B

The Enrollment Status Page (ESP) is used to track the installation of applications and configuration of device settings during Autopilot enrollment. It ensures that these tasks complete before the user accesses the desktop. The requirement states that enrollment must include installation of required applications and configuration of device settings; ESP is the component that monitors and enforces this. Without ESP, the user might reach the desktop before these critical tasks are complete, leading to a poor experience.

Why this answer

The Autopilot deployment profile defines the join type and OOBE settings, ensuring the device joins Microsoft Entra ID. The Enrollment Status Page (ESP) ensures that required applications and configurations are applied before the user reaches the desktop. Together, they meet the requirement of Microsoft Entra join with app installation and device configuration during enrollment.

The other options are either for hybrid join, alternative provisioning, or post-enrollment security.

Exam trap

The trap here is assuming that the Intune Connector for Active Directory is needed for all Autopilot deployments, but it is only for hybrid Azure AD join.

74
MCQeasy

You are the Microsoft 365 Endpoint Administrator for Contoso. The company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when devices are enrolled, they automatically receive a set of configuration settings without manual intervention. The settings include a custom Start menu layout and a set of allowed background apps. What should you create in Intune to achieve this?

A.An app protection policy
B.A compliance policy
C.A device configuration profile
D.A Windows Autopilot deployment profile
AnswerC

A device configuration profile in Intune allows you to configure settings such as Start menu layout and restricted apps on Windows devices. After assignment to a group, the settings are applied automatically during enrollment or check-in, meeting the requirement for automatic application without manual intervention.

Why this answer

Device configuration profiles in Microsoft Intune are designed to deliver settings to devices. They can configure Start menu layout, restrict apps, and many other settings. Once assigned, the settings are applied automatically, satisfying the requirement to avoid manual intervention.

Compliance policies assess, Autopilot profiles customize OOBE, and app protection policies secure data within apps, none of which apply configuration settings.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance evaluates settings while configuration applies them.

75
MCQeasy

You administer Microsoft Intune for Northwind Traders. The security team wants to prevent users from enrolling personally owned Windows 10 devices while still allowing corporate-owned devices to enroll. You need to configure a device enrollment restriction that blocks personal Windows devices. Which platform setting should you modify?

A.Windows Mobile
B.Windows (MDM)
C.Windows (ConfigMgr)
D.Windows (MDM) under Corporate Device Identifiers
AnswerB

Device enrollment restrictions in Intune have a per-platform configuration, and Windows devices enroll as Windows (MDM). Setting the Windows (MDM) platform to Block for personally owned devices prevents users from enrolling personal Windows 10 devices while still allowing corporate devices to enroll. This is the correct platform to modify for the stated requirement.

Why this answer

Intune device enrollment restrictions are configured per platform. Windows 10 and Windows 11 devices that enroll in MDM use the Windows (MDM) platform. To block personal Windows devices while allowing corporate ones, an administrator sets the Windows (MDM) platform to Block for personally owned devices.

Other platform entries such as Windows (ConfigMgr) or Windows Mobile do not apply to standard Windows 10 MDM enrollment.

Exam trap

The trap here is confusing Windows (ConfigMgr) or Windows Mobile with the platform that governs standard Windows 10 MDM enrollment, which is Windows (MDM).

Page 1 of 2 · 145 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Prepare infrastructure for devices questions.