Courseiva

CCNA Prepare infrastructure for devices Questions

70 of 145 questions · Page 2/2 · Prepare infrastructure for devices · Answers revealed

76
MCQhard

You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?

A.Create a device enrollment restriction in Intune that allows only the security group and enable Windows Autopilot for those devices.
B.Configure automatic MDM enrollment in the Microsoft Entra ID mobility settings and assign the Intune Enrollment scope to the security group.
C.Configure a Conditional Access policy that requires compliant devices and assign it to the security group.
D.Enable automatic enrollment in Intune and set the MDM user scope in Microsoft Entra ID to the security group.
AnswerD

Automatic MDM enrollment is enabled from the Intune portal, and the Microsoft Entra ID mobility settings include an MDM user scope that can be set to a specific security group. Setting the scope to that group ensures only its members are automatically enrolled in Intune when they join devices to Microsoft Entra ID, meeting both requirements.

Why this answer

Automatic enrollment is turned on in the Intune admin center, while the user scope that determines who is eligible is configured in the Microsoft Entra ID mobility settings. Pointing the MDM user scope at the chosen security group restricts automatic Intune enrollment to those users, which is exactly what the scenario requires.

Exam trap

The trap here is confusing enrollment restrictions or Conditional Access with the MDM user scope, which is the actual control for who can automatically enroll.

77
MCQhard

A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?

A.The Intune service is experiencing an outage
B.The device is powered off or not connected to the internet
C.The device has conflicting policies from another MDM
D.The device's enrollment certificate has expired
AnswerB

Intune policies only reach a device when it checks in over the internet. A three-day-old check-in with the device still showing as Enrolled points to the device being powered off or offline, so it cannot contact the Intune service to receive configuration.

Why this answer

If the device is powered off or not connected to the internet, it cannot check in with Intune to receive new policies. Option A is wrong because an Intune service outage would affect multiple devices, not just one. Option C is wrong because conflicting policies would not prevent check-in; the device would still check in and report conflicts.

Option D is wrong because an expired enrollment certificate would prevent enrollment or cause immediate issues, not just a delayed check-in after three days.

78
MCQeasy

Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?

A.A Microsoft Intune license assigned to the user
B.A VPN connection to the corporate network
C.An on-premises Active Directory domain
D.A Configuration Manager infrastructure
AnswerA

Intune enrolment is user-driven, so each enrolling user requires an Intune licence (included in EMS, Microsoft 365 E3/E5, or standalone) before the service accepts the device. Without this per-user assignment, enrolment fails at authentication, regardless of device compliance or network configuration.

Why this answer

A Microsoft Intune license assigned to the user is a prerequisite because Intune uses Azure Active Directory (Azure AD) for identity and access management. Without an Intune license (e.g., Microsoft 365 E3, E5, or standalone Intune license) assigned to the user, the device cannot authenticate and enroll via the Intune enrollment service, as the license is required to authorize the enrollment request and apply device management policies.

Exam trap

The trap here is that candidates often confuse on-premises prerequisites (like AD or VPN) with cloud-only requirements, mistakenly thinking corporate network connectivity or legacy infrastructure is needed for Intune enrollment, when in fact only an Azure AD identity and an Intune license are required.

How to eliminate wrong answers

Option B is wrong because a VPN connection to the corporate network is not required for Intune enrollment; Intune uses internet-based enrollment over HTTPS (port 443) to the Microsoft Intune service, and devices can enroll from anywhere without a VPN. Option C is wrong because an on-premises Active Directory domain is not a prerequisite; Intune enrollment relies on Azure AD for identity, and while hybrid Azure AD join can be used, a standalone on-premises AD domain is not required for basic Intune enrollment. Option D is wrong because a Configuration Manager infrastructure is not a prerequisite; Intune is a cloud-only MDM solution, and while co-management with Configuration Manager is possible, it is optional and not required for enrollment.

79
MCQeasy

You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?

A.Windows app (Win32)
B.Microsoft 365 Apps
C.Web link
D.Microsoft Store app
AnswerB

The Microsoft 365 Apps app type is purpose-built for deploying Office suites, letting you select channels, versions and exclude individual products. Assigning it to users makes it available in Company Portal, meeting the install-from-portal requirement.

Why this answer

The Microsoft 365 Apps app type in Intune is specifically designed to deploy Office 365 ProPlus (now Microsoft 365 Apps) suites, including Word, Excel, PowerPoint, and others, as a managed suite. This app type automatically configures the installation to use the Office Deployment Tool (ODT) with built-in settings for update channels, architecture (32-bit/64-bit), and language packs, and it makes the suite available in Company Portal for user-initiated installation. Unlike Win32 or other types, it handles the complex licensing and activation requirements for Microsoft 365 Apps without additional scripting.

Exam trap

The trap here is that candidates often choose 'Windows app (Win32)' because they think any desktop app must be deployed as a Win32 app, but they overlook that Intune has a dedicated app type for Microsoft 365 Apps that simplifies licensing, update management, and Company Portal integration, making it the correct and intended choice.

How to eliminate wrong answers

Option A is wrong because Windows app (Win32) is used for deploying traditional desktop applications (e.g., .exe or .msi files) via Intune, but it does not natively support the integrated licensing, update channel management, or suite-level configuration that Microsoft 365 Apps require; using Win32 would require manually packaging the Office Deployment Tool and scripts, which is unnecessary and error-prone. Option C is wrong because a Web link app type only creates a shortcut to a URL in Company Portal and does not perform any software installation, so users cannot install Microsoft 365 Apps from it. Option D is wrong because Microsoft Store app type is intended for deploying apps from the Microsoft Store (UWP or Store-licensed Win32 apps), and Microsoft 365 Apps is not distributed through the Microsoft Store for enterprise deployment via Intune.

80
MCQmedium

You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?

A.Shared iPad enrollment using Apple Business Manager and Intune.
B.Automated Device Enrollment with user affinity.
C.User Enrollment
D.Device Enrollment (DEP) without user affinity.
AnswerA

Shared iPad mode stores each student's apps and data in separate managed user partitions, so signing in on any device restores their own environment. Enrolling through Apple Business Manager with Intune applies the configuration and supervision needed to satisfy the multi-user requirement.

Why this answer

Shared iPad enrollment using Apple Business Manager (ABM) and Intune is designed specifically for scenarios where multiple students share the same iPad and each needs their own apps, data, and sign-in. It uses Managed Apple IDs and provides a personalized experience with separate user partitions, while the device remains supervised and managed by the school.

Exam trap

MD-102 often tests the confusion between 'Shared iPad' (multi-user with individual partitions) and 'Device Enrollment without user affinity' (kiosk/shared but no individual user data) — candidates must recognize the requirement for each student to have their own apps and data.

How to eliminate wrong answers

Option B is wrong because Automated Device Enrollment with user affinity is for one-to-one device scenarios where a single user is assigned to the device — it does not support multiple users sharing the same iPad with separate data. Option C is wrong because User Enrollment (BYOD) is for personal devices where the user enrolls their own device and the organization manages only work data — it does not provide shared device capabilities. Option D is wrong because Device Enrollment without user affinity is for kiosk or shared device scenarios but does not provide individual user partitions or personalized app/data access for multiple students.

81
Multi-Selecteasy

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?

Select 1 answer
A.Disable screen capture.
B.Disable copy and paste.
C.Disable camera.
D.Disable Bluetooth.
E.Disable Wi-Fi.
AnswersA

Disable screen capture is the Android Enterprise device restrictions setting that blocks screenshots and screen recording on managed devices. Configuring it in a device restrictions profile enforces the restriction through Intune without requiring app-level configuration.

Why this answer

To restrict screenshots on Android Enterprise devices, only the 'Disable screen capture' setting directly prevents the device from taking screenshots by using the FLAG_SECURE window flag. Options B and C ('Disable copy and paste' and 'Disable camera') do not prevent screen capture; they restrict clipboard operations and camera usage respectively. Therefore, the only correct setting is A.

Exam trap

Candidates might mistakenly think that 'Disable copy and paste' or 'Disable camera' can prevent screenshots, but they do not. Only 'Disable screen capture' effectively blocks screenshots.

82
Multi-Selectmedium

You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?

Select 1 answer
A.Microsoft Entra ID (Azure AD) Premium P1 or P2.
B.Microsoft Intune license assigned to the user.
C.A Microsoft account (MSA) for each user.
D.Microsoft 365 E3 subscription.
E.Azure Information Protection license.
AnswersB

Enrolment requires a Microsoft Intune licence assigned to the enrolling user, since Intune is licensed per user rather than per device. Without that licence, the user cannot authenticate and the Windows 10 device cannot be enrolled or receive policy.

Why this answer

Option B is the correct prerequisite: a Microsoft Intune license must be assigned to the user enrolling the device. Option A (Microsoft Entra ID Premium P1/P2) is not required; Microsoft Entra ID Free is sufficient for Intune enrollment. Option C (Microsoft account) is not needed for corporate devices.

Option D (Microsoft 365 E3) is a bundled subscription but not a standalone prerequisite. Option E (Azure Information Protection) is unrelated to device enrollment. Therefore, only one option is correct.

Exam trap

Candidates may mistakenly select multiple options, but the stem clearly asks for only one prerequisite, and only Option B is correct.

83
MCQmedium

Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?

A.Create an app protection policy for Windows 365 app.
B.Configure the Cloud PC provisioning policy to allow only compliant devices.
C.Assign a device compliance policy to all users.
D.Create a Conditional Access policy requiring device to be marked as compliant.
AnswerD

A Conditional Access policy evaluates device compliance state at sign-in, so only devices marked compliant in Intune can establish the Cloud PC connection. This directly enforces the constraint that users connect solely from compliant devices.

Why this answer

A Conditional Access policy that requires the device to be marked as compliant is the only configuration that enforces compliance at the authentication and access level. This policy evaluates the device's compliance status (reported by Microsoft Intune) before granting access to Windows 365 Cloud PCs, ensuring that only devices meeting your organization's compliance requirements can connect.

Exam trap

The trap here is that candidates often confuse provisioning policies (which configure Cloud PCs) with access control policies (Conditional Access), leading them to select Option B, but provisioning policies do not enforce compliance-based access restrictions.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) manage data protection within apps and do not evaluate device compliance; they are designed for unmanaged devices and cannot block access based on device compliance status. Option B is wrong because a Cloud PC provisioning policy defines the configuration and assignment of Cloud PCs (e.g., image, network, user assignments) but does not enforce access controls or compliance checks at the time of connection. Option C is wrong because assigning a device compliance policy to all users defines the compliance requirements (e.g., encryption, OS version) but does not enforce access restrictions; it only marks the device as compliant or non-compliant—a separate Conditional Access policy is needed to block non-compliant devices.

84
MCQeasy

Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?

A.Configure a device configuration profile with 'Windows Update for Business' settings.
B.Deploy a feature update policy to install the latest quality updates.
C.Create an update ring for Windows 10 and later, and set the 'Automatic update behavior' to 'Auto install and reboot' and assign it to all devices.
D.Create a device compliance policy that requires devices to have the latest updates.
AnswerC

An update ring for Windows 10 and later satisfies the automatic installation requirement by setting 'Automatic update behavior' to 'Auto install and reboot', which forces critical and security updates to download and install without user intervention. Assigning it to all devices ensures every Windows 11 endpoint receives the policy, meeting the stem's automatic-update constraint.

Why this answer

Update rings are the primary policy in Microsoft Intune for controlling how and when Windows 10 and later devices receive updates from Windows Update. Setting 'Automatic update behavior' to 'Auto install and reboot' ensures that critical and security updates are automatically downloaded and installed without user intervention, meeting the requirement for all Windows 11 devices.

Exam trap

The trap here is that candidates confuse device configuration profiles (which are for settings like BitLocker or Wi-Fi) with update rings, or they mistakenly think compliance policies can enforce update installation, when in fact only update rings control the automatic update behavior.

How to eliminate wrong answers

Option A is wrong because a device configuration profile with 'Windows Update for Business' settings is a legacy approach that has been deprecated in favor of update rings; it does not provide the granular control over update installation behavior required for automatic installation of critical and security updates. Option B is wrong because a feature update policy is used to move devices to a specific Windows version (e.g., from Windows 10 to Windows 11) or to defer feature updates, not to control the installation of critical and security quality updates. Option D is wrong because a device compliance policy can only report on whether devices have the latest updates installed and can trigger conditional access actions, but it cannot enforce the automatic installation of updates; it is a reporting and remediation tool, not an update deployment mechanism.

85
Multi-Selecteasy

You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?

Select 2 answers
A.Devices must be joined to Azure AD.
B.A Microsoft Defender for Endpoint license must be assigned.
C.Devices must be enrolled in Microsoft Intune.
D.Devices must have a third-party antivirus uninstalled.
E.An Azure AD Premium license must be assigned.
AnswersB, C

Assigning a Microsoft Defender for Endpoint licence to users is mandatory, since the service activates per-user entitlement; without it, onboarding packages deploy but devices remain unlicensed and report no telemetry to the Microsoft 365 Defender portal. This satisfies the stem's prerequisite that licensing be in place before Intune deployment begins.

Why this answer

Option B is correct because Microsoft Defender for Endpoint requires a valid license (e.g., Microsoft 365 E5 or a standalone Defender for Endpoint license) assigned to users before onboarding devices. Option C is correct because the scenario specifies deployment via Intune, so devices must be enrolled in Microsoft Intune to receive the onboarding configuration and policy. Option A is incorrect because Azure AD join is not strictly required; devices can be domain-joined or workgroup-joined as long as they are Intune-enrolled and meet other requirements.

Option D is incorrect because third-party antivirus does not need to be uninstalled; Defender for Endpoint can run in passive mode alongside it. Option E is incorrect because Azure AD Premium is not a prerequisite for Defender for Endpoint deployment.

Exam trap

The trap here is that candidates often confuse the prerequisites for Defender for Endpoint with those for other Microsoft 365 security services, mistakenly thinking Azure AD join or Azure AD Premium licenses are required, when in fact only an Intune enrollment and a Defender for Endpoint license are needed.

86
Multi-Selecthard

You are preparing infrastructure for device management in Microsoft Intune. Your organization plans to deploy Windows 11 devices using Windows Autopilot in Microsoft Entra join mode. You need to ensure that the devices can be identified and assigned to the correct deployment profile. Which two actions must you perform? (Choose two.)

Select 2 answers
A.Deploy the Intune Company Portal app to all devices.
B.Register the device hardware hash in Intune.
C.Create an Autopilot deployment profile and assign it to a device group.
D.Enable automatic enrollment in Intune for all users.
E.Configure a conditional access policy requiring compliant devices.
AnswersB, C

Registering the hardware hash in Intune is essential for Autopilot. The hardware hash uniquely identifies the device, and without it, the device cannot be recognized as an Autopilot device. You can collect the hash manually or through the OEM, and then import it into Intune. This allows you to assign an Autopilot deployment profile to the device.

Why this answer

To identify and assign Autopilot devices, you must register the hardware hash in Intune and create an Autopilot deployment profile assigned to a device group. The hardware hash allows Intune to recognize the device as an Autopilot device, and the profile determines the deployment settings. Without these two actions, the device will not receive the intended Autopilot configuration.

Exam trap

The trap here is assuming that automatic enrollment or conditional access is needed for Autopilot, when actually the core requirements are hardware hash registration and a deployment profile assignment.

87
MCQeasy

You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?

A.Deploy a configuration profile with the Windows 11 installation script.
B.Create a Windows update ring profile targeting Windows 11.
C.Create a Windows feature update profile targeting Windows 11.
D.Configure a device compliance policy requiring Windows 11.
AnswerC

A Windows feature update profile is the dedicated Intune workload for delivering an in-place Windows 10 to Windows 11 upgrade, letting you target the 500 devices and control the version and rollout schedule. Update rings handle quality patches, not OS version upgrades, so they cannot satisfy this requirement.

Why this answer

A Windows feature update profile in Intune is specifically designed to deliver feature updates like upgrading from Windows 10 to Windows 11. It uses the Windows Update for Business (WUfB) service to orchestrate the in-place upgrade, ensuring the device meets prerequisites and the upgrade completes successfully. This is the correct policy type for managing OS version upgrades at scale.

Exam trap

The trap here is confusing a Windows update ring profile (which controls update behavior but not the target version) with a Windows feature update profile (which explicitly specifies the target OS version for an upgrade), leading candidates to incorrectly choose Option B.

How to eliminate wrong answers

Option A is wrong because Intune does not support deploying a configuration profile with an installation script for OS upgrades; configuration profiles manage settings, not OS installation or upgrade scripts. Option B is wrong because a Windows update ring profile controls the update deferral, delivery optimization, and restart behavior for quality and feature updates, but it does not specify the target OS version for an upgrade; it only manages how updates are applied, not which feature update is installed. Option D is wrong because a device compliance policy enforces security and configuration requirements (e.g., requiring Windows 11) but does not initiate or deliver the upgrade; it only reports non-compliance if the device is not running the required OS.

88
MCQeasy

A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?

A.Assign the app and configure 'Require device compliance' with a filter for minimum OS version.
B.Assign the app with 'Uninstall' intent.
C.Assign the app as 'Available for enrolled devices' without filters.
D.Assign the app as 'Required' to all devices.
AnswerA

Device compliance filters can enforce OS version requirements.

Why this answer

Intune allows you to create a filter based on device properties such as OS version, and apply that filter to app assignments. This ensures the deployment is only available to devices meeting the minimum OS version. Option B is incorrect because 'Uninstall' intent would remove the app, not deploy it with OS filtering.

Option C is incorrect because 'Available for enrolled devices' without filters does not enforce any OS version requirement. Option D is incorrect because assigning as 'Required' to all devices does not filter by OS version.

89
MCQeasy

You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?

A.Require device to be marked as compliant
B.Require multi-factor authentication
C.Require hybrid Azure AD joined device
D.Require approved client app
AnswerA

Requiring the device to be marked as compliant enforces Intune compliance state at token issuance, so Exchange Online blocks mail access from non-compliant devices. This directly satisfies the stem's constraint that only compliant devices reach corporate email, since Microsoft Entra ID evaluates the device's compliance status during sign-in.

Why this answer

The 'Require device to be marked as compliant' setting in a Conditional Access policy enforces that only devices meeting your organization's compliance policies (e.g., BitLocker enabled, antivirus active, OS version current) can access Exchange Online. This leverages Microsoft Intune device compliance policies and the Microsoft Entra ID device registration state to block non-compliant devices from accessing corporate email.

Exam trap

The trap here is that candidates often confuse device compliance with device join type (hybrid Azure AD join) or app-level controls, mistakenly thinking that requiring a specific join type or approved app alone ensures the device is healthy and secure.

How to eliminate wrong answers

Option B is wrong because requiring multi-factor authentication (MFA) addresses identity verification, not device compliance; a compromised but MFA-enabled device could still access email. Option C is wrong because requiring a hybrid Azure AD joined device enforces a specific join type (typically for on-premises AD integration), but a device can be hybrid joined yet still be non-compliant (e.g., missing security updates). Option D is wrong because requiring an approved client app (e.g., Outlook mobile) controls the application used, not the device's compliance state; a non-compliant device could still use an approved app.

90
MCQmedium

You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?

A.The device is marked as non-compliant.
B.The device does not have a valid device certificate.
C.The device has not checked in with the Intune service recently.
D.The device enrollment profile has expired.
AnswerC

Intune policy evaluation depends on the device checking in with the service. Without a recent check-in, the console reports 'Not evaluated' or 'Pending' because no MDM session has delivered or acknowledged policy. Connectivity alone is insufficient.

Why this answer

When a device shows as 'Not evaluated' or 'Pending' in the Intune console, it indicates that the Intune service has not received a recent check-in from the device. Even if the device is enrolled and connected to the internet, it must periodically communicate with the Intune service to retrieve policies; the default check-in interval is approximately 8 hours, and if the device misses this window, policies remain unevaluated.

Exam trap

The trap here is that candidates often assume policy delivery failures are due to compliance or certificate issues, but the MD-102 exam specifically tests the understanding that a device must actively check in with the Intune service to receive policies, and a 'Pending' status directly indicates a missed check-in.

How to eliminate wrong answers

Option A is wrong because a non-compliant device still receives policies from Intune; compliance status affects conditional access, not policy delivery. Option B is wrong because while a valid device certificate is required for enrollment, the issue described is about policy retrieval after enrollment, and a missing or expired certificate would typically cause enrollment failure or a different error state, not a 'Not evaluated' status. Option D is wrong because enrollment profiles are used during the enrollment process itself; once a device is enrolled, the profile is no longer relevant for ongoing policy delivery, and an expired profile would prevent enrollment, not cause a 'Pending' state for already-enrolled devices.

91
MCQhard

Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?

A.Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.
B.Configure the MDM discovery URL in Microsoft Entra ID.
C.Create an enrollment restriction that allows Windows devices.
D.Assign a device compliance policy to the user.
AnswerA

The MDM user scope determines which Microsoft Entra ID users' devices are permitted to enrol automatically; setting it to All or Some enables automatic enrolment at sign-in. This satisfies the requirement for Microsoft Entra ID-joined Windows 11 devices to enrol without manual action.

Why this answer

Microsoft Entra ID joined devices automatically enroll in Intune when the MDM user scope is set to 'All' or 'Some'. Option B is incorrect because the MDM discovery URL is configured automatically for Microsoft Entra ID joined devices and does not need manual configuration. Option C is incorrect because enrollment restrictions control which devices can enroll but do not trigger automatic enrollment.

Option D is incorrect because device compliance policies are applied after enrollment, not before.

92
MCQmedium

Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?

A.Create a Conditional Access policy requiring device compliance and blocking access if not compliant.
B.Enable 'Require BitLocker' compliance setting.
C.Deploy a PowerShell script via Intune that checks the Defender service status and reports to Intune custom compliance.
D.Add a compliance policy setting: 'Require the device to be at or under the machine risk score' with a low score.
AnswerD

This setting uses Defender for Endpoint risk score to evaluate compliance. If the device is not reporting, the score is not available, causing non-compliance.

Why this answer

Microsoft Defender for Endpoint integrates with Intune compliance policies via the 'Require the device to be at or under the machine risk score' setting. When a device stops reporting to Defender, its risk score escalates above the 'Low' threshold, causing Intune to mark it as non-compliant. This directly meets the requirement to flag non-reporting devices without additional scripting or conditional access complexity.

Exam trap

The trap here is that candidates often confuse Conditional Access (which enforces compliance) with the compliance policy setting that actually defines what 'non-compliant' means, leading them to pick Option A instead of the correct risk-score setting.

How to eliminate wrong answers

Option A is wrong because a Conditional Access policy enforces access control based on compliance status but does not itself define or detect non-reporting devices; it relies on an existing compliance policy to flag them. Option B is wrong because 'Require BitLocker' only checks encryption status, not whether the device is actively reporting to Defender for Endpoint. Option C is wrong because while a custom PowerShell script can check Defender service status, it requires custom compliance discovery and is not the native, supported method for integrating Defender risk data into Intune compliance.

93
MCQhard

You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?

A.Windows compliance policy
B.Windows 10 and later update ring
C.Windows feature update policy
D.Windows driver update policy
AnswerB

Update rings for Windows 10 and later hold the deferral settings for feature and quality updates, so a single ring can defer feature updates 60 days and quality updates 14 days. Other Intune update profiles do not expose both deferral values together.

Why this answer

The Windows 10 and later update ring policy in Intune is specifically designed to configure Windows Update for Business settings, including deferral periods for feature and quality updates. By setting the 'Feature update deferral period (days)' to 60 and 'Quality update deferral period (days)' to 14, you directly control how long updates are postponed after they are released by Microsoft. This policy applies to devices managed via Intune and leverages the Windows Update for Business service to enforce these deferrals.

Exam trap

The trap here is that candidates often confuse the 'Windows feature update policy' (which targets a specific feature update version) with the 'update ring' policy (which controls deferral periods), leading them to select option C instead of B.

How to eliminate wrong answers

Option A is wrong because Windows compliance policy is used to evaluate device compliance against security requirements (e.g., OS version, antivirus status) and does not include settings to defer update installations. Option C is wrong because Windows feature update policy is a separate policy type that targets specific feature update versions (e.g., Windows 11 22H2) and does not control deferral periods for quality updates or general feature update deferral durations. Option D is wrong because Windows driver update policy is dedicated to managing driver updates (e.g., approval, deferral) and does not handle feature or quality update deferral settings.

94
MCQeasy

A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?

A.The devices must be registered in Microsoft Intune via the hardware vendor or manually.
B.The organization must have a hybrid Azure AD join configuration in place.
C.BitLocker must be enabled on the devices before they are shipped.
D.A local administrator account must be created on each device prior to deployment.
AnswerA

Autopilot requires each device's hardware hash registered as an Autopilot device in Microsoft Intune before it can enrol. OEM registration lets the vendor upload hashes automatically, satisfying the stem's prerequisite so the 500 devices enrol without manual hash collection.

Why this answer

For Windows Autopilot to automatically enroll devices, the devices must be registered in Microsoft Intune. This can be done by the hardware vendor (OEM registration) or manually by the organization. Without registration, Autopilot cannot identify the device and apply the deployment profile.

Exam trap

MD-102 often tests the prerequisites for Autopilot, and candidates may confuse device registration with Azure AD join or other requirements.

How to eliminate wrong answers

Option B is wrong because hybrid Azure AD join is not a prerequisite for Autopilot; Autopilot supports Azure AD join and hybrid Azure AD join, but the key prerequisite is device registration. Option C is wrong because BitLocker does not need to be enabled before shipping; it can be enabled during Autopilot. Option D is wrong because a local administrator account is not required prior to deployment; Autopilot can configure local admin accounts as part of the deployment.

95
MCQeasy

Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?

A.The device's product key
B.The device's hardware hash (4K HH)
C.The user's Microsoft account
D.The device's BIOS password
AnswerB

Autopilot identifies devices by their unique hardware hash, a 4K value capturing serial number, hardware IDs and other attributes. Uploading this hash creates the Autopilot device record that ties the physical device to your tenant during OOBE.

Why this answer

Windows Autopilot requires the device's hardware hash (4K HH) to uniquely identify the device during the registration process. This hash is generated from the device's hardware components and is uploaded to the Microsoft Intune or Partner portal to associate the device with an Autopilot profile. Without the hardware hash, Autopilot cannot recognize the device as registered and will not apply the deployment profile.

Exam trap

The trap here is that candidates often confuse the hardware hash with the product key, assuming that a license or activation key is needed for Autopilot registration, but Autopilot relies solely on hardware-based identification.

How to eliminate wrong answers

Option A is wrong because the product key is used for Windows activation, not for Autopilot registration; Autopilot uses the hardware hash to identify the device. Option C is wrong because the user's Microsoft account is not required for device registration; Autopilot registration is device-centric and occurs before user sign-in. Option D is wrong because the BIOS password is a security feature for local access control and has no role in Autopilot's device identification or enrollment process.

96
MCQhard

Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?

A.Deploy Windows Autopilot for all devices and require Entra ID join
B.Configure Conditional Access policies in Microsoft Entra ID that require compliant devices
C.Configure a VPN profile in Intune and enforce device compliance on the VPN server
D.Create a compliance policy in Intune and assign it to all users
AnswerB

Conditional Access evaluates device compliance state signalled by Intune, granting Microsoft 365 access only when the device meets security policies. This satisfies the requirement that unmanaged devices be blocked, since compliance policies alone cannot enforce access at the identity layer.

Why this answer

Conditional Access policies in Microsoft Entra ID can require that devices accessing Microsoft 365 services be marked as compliant by Intune. This ensures that only devices meeting your security policies (e.g., encryption, antivirus, OS patch level) are granted access, directly addressing the security team's concern about unmanaged devices on public Wi-Fi.

Exam trap

The trap here is that candidates often confuse creating a compliance policy (which only defines the rules) with enforcing it via Conditional Access (which actually blocks access), leading them to select Option D instead of B.

How to eliminate wrong answers

Option A is wrong because Windows Autopilot and Entra ID join streamline device provisioning and identity, but they do not enforce compliance checks at the point of access to Microsoft 365 services. Option C is wrong because configuring a VPN profile in Intune and enforcing compliance on the VPN server only controls access to the VPN tunnel, not to Microsoft 365 services directly; users could still access those services without going through the VPN. Option D is wrong because creating a compliance policy in Intune and assigning it to users only defines and reports compliance status; it does not enforce access blocking—Conditional Access is required to actually block non-compliant devices from accessing Microsoft 365.

97
Multi-Selecthard

Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)

Select 3 answers
A.Windows Information Protection (WIP).
B.Windows Defender Application Control (WDAC).
C.Intune application control policies.
D.AppLocker.
E.BitLocker drive encryption.
AnswersB, C, D

WDAC is a Windows 10 hypervisor-protected code integrity feature that enforces an explicit allowlist of trusted binaries at the kernel level. Intune deploys WDAC policies as a custom OMA-URI, satisfying the requirement that only approved applications execute on managed devices.

Why this answer

Windows Defender Application Control (WDAC) (B) is correct because it is Microsoft's application control technology that enforces code integrity policies on Windows 10, allowing only approved/trusted binaries to execute based on publisher, hash, or file path rules. Intune application control policies (C) are correct because Intune can deploy and manage application control configurations—including WDAC and AppLocker policies—to Windows 10 devices, letting administrators centrally enforce which apps are allowed. AppLocker (D) is correct because it is a built-in Windows 10 application control feature that restricts which applications and files users can run using allow/deny rules based on publisher, path, or hash.

Windows Information Protection (A) is not an application control mechanism; it is a data protection feature that helps prevent accidental data leakage by separating and encrypting corporate data, not by blocking unapproved applications. BitLocker (E) is a full-disk encryption feature that protects data at rest, and it has no role in controlling which applications are permitted to run.

Exam trap

The trap here is that candidates often confuse Windows Information Protection (WIP) with application control because both involve 'policies' in Intune, but WIP is strictly for data loss prevention, not for blocking or allowing application execution.

98
MCQeasy

Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?

A.Custom
B.Endpoint protection
C.Device restrictions
D.Device features
AnswerB

Endpoint protection profiles in Microsoft Intune expose the FileVault disk encryption settings for macOS, letting you enforce encryption across managed devices. This profile type satisfies the stem's requirement to ensure all macOS devices have FileVault enabled.

Why this answer

'Endpoint protection' profiles include FileVault settings for macOS. Option A is incorrect because 'Custom' profiles are used for importing custom settings, not for encryption. Option C is incorrect because 'Device restrictions' contain general restrictions but not FileVault.

Option D is incorrect because 'Device features' include settings like wallpaper and lock screen, not encryption.

99
MCQeasy

Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?

A.Join the device to Azure AD hybrid by configuring a domain join profile.
B.Create an Autopilot deployment profile with 'Assign to' set to 'All devices' and ensure the device is registered in Autopilot.
C.Configure the Enrollment Status Page (ESP) to require device enrollment.
D.Manually add the device serial number to Intune via the admin center.
AnswerB

An Autopilot deployment profile with 'Assign to' set to 'All devices' applies the enrolment settings to every registered Autopilot device. Combined with prior Autopilot registration, this triggers automatic Microsoft Intune enrolment at first power-on, requiring no user action.

Why this answer

Windows Autopilot requires both a registered device (identified by hardware hash) and an assigned deployment profile to trigger automatic enrollment in Microsoft Intune during the first power-on. Setting 'Assign to' to 'All devices' ensures the profile applies to any registered Autopilot device, and the device registration step links the hardware identity to your tenant. Without this combination, the device will not automatically enroll.

Exam trap

The trap here is that candidates confuse the Enrollment Status Page (ESP) with the enrollment trigger itself, thinking ESP configuration alone enables automatic enrollment, when in fact ESP only manages the post-enrollment provisioning sequence.

How to eliminate wrong answers

Option A is wrong because joining a device to Azure AD hybrid via a domain join profile is a separate configuration for hybrid-joined devices and does not by itself trigger automatic Intune enrollment; Autopilot enrollment requires a deployment profile with enrollment settings. Option C is wrong because the Enrollment Status Page (ESP) controls the end-user experience during enrollment (e.g., blocking use until apps are installed) but does not initiate or enforce device enrollment; enrollment must already be configured via a deployment profile. Option D is wrong because manually adding a device serial number to Intune via the admin center registers the device for management but does not create an Autopilot deployment profile; without a profile assigned, the device will not automatically enroll during first power-on.

100
MCQmedium

You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?

A.The kiosk profile is not correctly assigned.
B.The device is not assigned to a user.
C.The AUMID for Microsoft Edge is not specified.
D.The device is not running Windows 10/11 Enterprise.
AnswerC

The kiosk profile requires the Application User Model ID to identify which app launches in single-app mode. Without a valid Edge AUMID, the assigned access configuration cannot resolve a target application, so the device boots to a blank shell instead of Edge. Specifying the correct AUMID satisfies the single-app kiosk constraint.

Why this answer

The most likely issue is that the AUMID for Microsoft Edge is not specified in the kiosk profile. For a single-app kiosk on Windows 11, Intune requires the Application User Model ID (AUMID) to launch the app correctly. Without it, the kiosk shell cannot identify which executable to run, resulting in a blank screen instead of the Edge browser.

Exam trap

The trap here is that candidates assume a blank screen means a policy assignment failure or licensing issue, when in fact it is a configuration detail—the missing AUMID—that prevents the kiosk app from launching.

How to eliminate wrong answers

Option A is wrong because the kiosk profile assignment is verified by the device receiving the policy; a blank screen indicates the profile applied but the app failed to launch, not that assignment is missing. Option B is wrong because a kiosk device can be assigned to a device group without a user; user assignment is not required for single-app kiosk mode. Option D is wrong because Windows 11 Pro supports kiosk mode via Intune; only Windows 10/11 Enterprise or Education is required for multi-app kiosk or Assigned Access, but single-app kiosk works on Pro.

101
Multi-Selecthard

Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)

Select 2 answers
A.Enrollment Status Page (ESP) configuration.
B.Device registration in the Autopilot service using hardware hash.
C.On-premises Active Directory domain join.
D.Windows Autopilot deployment profile in Intune.
E.Microsoft Configuration Manager co-management.
AnswersB, D

Registering the device's hardware hash in the Windows Autopilot service creates the Autopilot device identity, which is mandatory for user-driven Microsoft Entra ID join. Without this record, the device cannot be matched to a deployment profile during OOBE, so the profile's join settings never apply.

Why this answer

Option B is correct because a device must first be registered in the Windows Autopilot service by uploading its hardware hash (collected via Get-WindowsAutopilotInfo or the OEM) so that the Autopilot service can recognize the device and associate it with the tenant during OOBE. Option D is correct because a Windows Autopilot deployment profile in Intune defines the critical settings for the user-driven Entra ID join scenario, including the deployment mode (User-Driven), the join type (Microsoft Entra joined), and the out-of-box experience options that drive the enrollment. Option A is not required: the Enrollment Status Page is an optional configuration that only controls what the user sees during device setup and does not enable the Autopilot deployment itself.

Option C is incorrect because user-driven Autopilot with Microsoft Entra ID join does not require on-premises Active Directory domain join; that would be a hybrid Entra join scenario. Option E is incorrect because Microsoft Configuration Manager co-management is not a prerequisite for Autopilot; Intune alone is sufficient to deliver the deployment profile and manage the device.

Exam trap

The trap here is that candidates often confuse the optional Enrollment Status Page with a mandatory component, or they mistakenly believe on-premises Active Directory join is required for user-driven Autopilot, when in fact Microsoft Entra ID join is a separate, cloud-native identity option.

102
MCQeasy

You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?

A.Compliance policies in Intune
B.MDM user scope in Microsoft Entra ID
C.Co-management slider in Configuration Manager
D.Enrollment device platform restrictions in Intune
AnswerB

MDM user scope in Microsoft Entra ID determines which users' devices are automatically enrolled into Intune when they join Microsoft Entra ID. Configuring it to All or a selected group satisfies the stem's requirement for automatic enrolment triggered by the join itself.

Why this answer

The MDM user scope setting in Microsoft Entra ID (formerly Azure AD) controls which users can automatically enroll their Windows 10 devices into Intune when they join Entra ID. When set to 'All' or 'Some', the device triggers automatic MDM enrollment during the Entra ID join process using the MDM enrollment protocol (MS-MDE), eliminating the need for manual enrollment steps.

Exam trap

The trap here is that candidates often confuse the MDM user scope (which controls the automatic enrollment trigger) with enrollment restrictions or compliance policies, which only apply after the enrollment process has already started.

How to eliminate wrong answers

Option A is wrong because compliance policies in Intune evaluate device compliance after enrollment, not trigger or configure automatic enrollment. Option C is wrong because the co-management slider in Configuration Manager controls workload distribution between ConfigMgr and Intune for already-managed devices, not the initial automatic enrollment of Windows 10 into Intune during Entra ID join. Option D is wrong because enrollment device platform restrictions in Intune block or allow enrollment based on platform or version after the enrollment attempt is initiated, but do not enable or configure the automatic enrollment trigger itself.

103
MCQhard

Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?

A.Configure a Microsoft Sentinel playbook.
B.Configure a Microsoft Foundry AI model.
C.Configure a Microsoft Purview data loss prevention policy.
D.Configure the integration between Microsoft Defender for Endpoint and Microsoft Intune.
AnswerD

The Defender for Endpoint–Intune connector shares device risk and vulnerability findings with Intune, which then applies remediation actions such as pushing scripts or configuration to affected devices. This satisfies the stem's automatic-trigger requirement without manual analyst intervention.

Why this answer

The native integration between Microsoft Defender for Endpoint and Microsoft Intune enables automatic remediation of vulnerabilities discovered by Defender's threat and vulnerability management (TVM) component. When Defender XDR surfaces a critical vulnerability, Intune can push remediation actions (patches, configuration changes, app updates) to the affected managed devices without manual intervention. This is the built-in 'security task' workflow that flows from Defender into Intune's endpoint security node.

Exam trap

MD-102 often tests whether candidates confuse Sentinel (SIEM/SOAR for log analytics) with the native Defender-to-Intune remediation pipeline, causing them to pick the 'automation' answer (Sentinel playbook) instead of the built-in integration.

How to eliminate wrong answers

Option A is wrong because Microsoft Sentinel playbooks are SOAR automation triggered by Sentinel incidents/analytics rules, not by Defender for Endpoint vulnerability findings feeding Intune remediation. Option B is wrong because Microsoft Foundry (Azure AI Foundry) is an AI model development platform with no endpoint remediation capability. Option C is wrong because Microsoft Purview DLP policies govern data handling and exfiltration, not vulnerability remediation on endpoints.

104
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?

A.Ensure the device is running Windows 10 Enterprise.
B.Run the Policy Manager tool on the device.
C.Verify the device is a member of the assigned device group.
D.Check the device's notification area for a policy update prompt.
AnswerC

Device configuration profiles apply only to targeted device groups. If the device is absent from the assigned group, the kiosk profile never reaches it, so membership is the first thing to verify before investigating policy conflicts or sync errors.

Why this answer

The most common reason a kiosk mode profile fails to apply is that the device is not a member of the assigned device group. Intune evaluates policy targeting based on group membership; if the device is missing from the group, the profile will never be delivered. Verifying group membership is the first logical troubleshooting step before investigating device-level issues.

Exam trap

The trap here is that candidates often assume the issue is a licensing or edition requirement (Windows 10 Enterprise) when the real problem is almost always a misconfigured or missing group assignment in Intune.

How to eliminate wrong answers

Option A is wrong because Windows 10 Pro also supports kiosk mode via assigned access, so Enterprise is not a strict prerequisite. Option B is wrong because the Policy Manager tool (rsop.msc) is used for Group Policy, not Intune MDM policies; Intune policies are managed via the MDM sync and the device's Settings app. Option D is wrong because Intune does not display a policy update prompt in the notification area; policy sync is silent or triggered manually via Settings > Accounts > Access work or school > Info > Sync.

105
MCQmedium

You administer Microsoft Intune for a company with 2,000 Windows 11 devices. The security team requires that all devices automatically receive an Intune enrollment record when they are first powered on by end users, without requiring users to manually enroll. You have already configured a Windows Autopilot deployment profile and assigned it to a device group. Which additional configuration is required to meet the requirement?

A.Enable the Enrollment Status Page (ESP) in the Autopilot profile.
B.Assign the Autopilot deployment profile to a user group instead of a device group.
C.Create a device configuration profile that enables the Intune Management Extension.
D.Configure automatic enrollment in Microsoft Entra ID for Windows devices.
AnswerD

Automatic enrollment in Microsoft Entra ID ensures that when an Autopilot device joins or registers in Microsoft Entra ID, it is automatically enrolled in Intune without user action. This setting is found in the Microsoft Intune admin center under Devices > Enroll devices > Automatic enrollment, or in Microsoft Entra ID. Without it, even with an Autopilot profile, devices may not create an Intune enrollment record automatically.

Why this answer

Automatic enrollment in Microsoft Entra ID is the tenant-level setting that allows Windows devices to enroll in Intune automatically when they join or register in Microsoft Entra ID. For Autopilot, this must be enabled so that devices create an Intune record without user intervention. The other options do not enable automatic enrollment; they are either unrelated features or incorrect assignment methods.

Exam trap

The trap here is assuming that an Autopilot deployment profile alone triggers Intune enrollment, when actually automatic enrollment in Microsoft Entra ID must be configured separately.

106
Multi-Selecteasy

Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)

Select 2 answers
A.Change the primary user of the device
B.Reinstall Windows 11 from scratch
C.Retain the Autopilot registration
D.Remove personal files and apps
E.Remove the device from Microsoft Intune
AnswersC, D

Autopilot reset re-applies the existing Autopilot profile, so the device stays enrolled and registered without re-importing its hardware hash. This satisfies the scenario's requirement to keep the device deployment-ready while wiping it, avoiding manual re-registration in Microsoft Entra ID.

Why this answer

Options C and D are correct. Windows Autopilot reset retains the device's Autopilot registration (option C) and removes personal files and apps (option D). Option A is incorrect because Autopilot reset does not change the primary user; that requires a different process.

Option B is incorrect because Autopilot reset does not reinstall Windows from scratch; it refreshes the existing OS. Option E is incorrect because Autopilot reset does not remove the device from Microsoft Intune; that would require a manual action.

107
MCQmedium

Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?

A.It requires a reboot for the setting to take effect.
B.It enables real-time protection for scheduled scans.
C.It disables scheduled scans when the device is in use.
D.It reduces the CPU priority of scheduled scans to minimize performance impact.
AnswerD

The baseline setting lowers the CPU priority of scheduled scans, so antivirus scanning consumes fewer processor resources and interferes less with user workloads. This directly matches the stated effect of reducing scan priority to minimise performance impact.

Why this answer

This setting in the Microsoft Intune security baseline for Windows 10 configures the 'Low CPU priority for scheduled scans' policy for Microsoft Defender Antivirus. When enabled, it reduces the CPU priority of scheduled scans to minimize performance impact on the user's active workload, ensuring that background scanning does not interfere with foreground tasks.

Exam trap

The trap here is that candidates confuse 'reducing CPU priority' with 'disabling the scan' or 'requiring a reboot', leading them to select options that describe more drastic or unrelated behaviors rather than the subtle performance tuning this setting actually performs.

How to eliminate wrong answers

Option A is wrong because this setting does not require a reboot; Intune security baseline policies are applied via the Microsoft Defender Antivirus engine and take effect immediately or on the next scheduled scan without a system restart. Option B is wrong because real-time protection is a separate policy (e.g., 'Turn on real-time protection') and is not controlled by this CPU priority setting. Option C is wrong because this setting does not disable scheduled scans when the device is in use; it only lowers the CPU priority of the scan, allowing it to run concurrently without degrading user experience.

108
MCQmedium

You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Entra ID with Microsoft Intune. You need to prepare infrastructure to deploy Windows 11 devices that are Microsoft Entra hybrid joined. You must ensure that devices can enroll in Intune without requiring user interaction during the out-of-box experience (OOBE). What should you configure first?

A.Create a device enrollment manager (DEM) account in Intune and assign it to the deployment team.
B.Configure automatic enrollment in Intune for Windows devices in the Microsoft Entra admin center.
C.Configure Windows Autopilot deployment profile with the 'Convert all targeted devices to Autopilot' option.
D.Deploy the Intune Company Portal app to devices via Group Policy.
AnswerB

Automatic enrollment in Microsoft Entra ID ensures that when a device joins or registers, it is automatically enrolled in Intune. For Microsoft Entra hybrid joined devices, this setting must be enabled so that the device receives Intune policies without user action. This is a prerequisite for zero-touch provisioning scenarios and aligns with the requirement to avoid manual enrollment during OOBE.

Why this answer

Automatic enrollment in Intune must be enabled in Microsoft Entra ID to allow Microsoft Entra hybrid joined devices to enroll automatically. This setting ensures that devices receive Intune policies without user interaction, which is essential for zero-touch provisioning during OOBE. Other options either require manual steps or do not directly enable automatic enrollment.

Exam trap

The trap here is assuming that Windows Autopilot alone handles Intune enrollment, when automatic enrollment must be configured separately.

109
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that Windows 11 devices can receive configuration profiles and compliance policies. You have already assigned the necessary licenses to users. What should you do first to prepare the devices for management?

A.Enroll the devices into Microsoft Intune.
B.Create a device compliance policy.
C.Configure a conditional access policy.
D.Deploy a configuration profile.
AnswerA

Enrolling devices into Microsoft Intune is the foundational step to enable management. Without enrollment, devices cannot receive configuration profiles, compliance policies, or any other management tasks. Enrollment establishes a trust relationship between the device and Intune, allowing policies to be applied and device state to be reported.

Why this answer

Before any policies or profiles can be applied, devices must be enrolled into Microsoft Intune. Enrollment is the process that registers the device with the service, enabling management capabilities. Once enrolled, you can assign compliance policies, configuration profiles, and other management tasks.

The other actions listed are all dependent on enrollment.

Exam trap

The trap here is thinking that creating policies or profiles comes before enrollment, but enrollment is the prerequisite for any management to occur.

110
MCQeasy

A company uses Microsoft Intune to manage its Windows devices. The IT team wants to ensure that new Windows devices can enroll without requiring users to manually enter the enrollment server address. The devices are already joined to Microsoft Entra ID. Which infrastructure component enables this automatic discovery?

A.A DNS SRV record for _enterpriseregistration in the on-premises DNS zone.
B.The MDM discovery endpoint published in Microsoft Entra ID through the mobility settings.
C.The Company Portal app installed on the device before enrollment.
D.The Intune enrollment policy in the Microsoft Intune admin center.
AnswerB

When automatic MDM enrollment is configured in Microsoft Entra ID, the service publishes the MDM discovery endpoint to enrolled clients. A Microsoft Entra joined device queries this endpoint during the join process and learns the Intune enrollment URL, enabling enrollment without the user typing a server address. This is the mechanism that enables automatic discovery.

Why this answer

Microsoft Entra ID publishes the MDM discovery endpoint when automatic enrollment is configured. A Microsoft Entra joined Windows device queries that endpoint during the join process and receives the Intune enrollment URL, so users do not need to enter a server address manually. This is the standard cloud-based discovery path.

Exam trap

The trap here is attributing automatic discovery to a DNS SRV record or the Company Portal, when the cloud discovery endpoint in Microsoft Entra ID is what cloud-joined devices actually use.

111
MCQhard

You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?

A.Device configuration profile with user scope.
B.Device configuration profile with device scope.
C.Compliance policy.
D.Group Policy Object (GPO) via Intune.
AnswerB

A device configuration profile with device scope applies settings directly to the device, independent of user sign-in. These settings are enforced by the device and cannot be overridden by users. This meets the requirement of applying settings even when no user is signed in and preventing user override. Device-scoped profiles are ideal for security settings that must apply globally, such as BitLocker, firewall, or Defender settings. They are assigned to device groups in Intune.

Why this answer

Device configuration profiles with device scope apply settings directly to the device, independent of user sign-in, and enforce them so users cannot override. This meets the requirement of applying security settings even when no user is signed in. User-scoped profiles require sign-in, compliance policies only assess, and GPOs are not natively applied via Intune.

Device-scoped profiles are the correct choice for device-wide security configurations.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance policies only evaluate, they do not apply settings.

112
MCQmedium

Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?

A.Manually tag each device in the Microsoft 365 Defender portal.
B.Configure device group rules in Microsoft Defender for Endpoint using OS version condition.
C.Use Microsoft Entra ID dynamic groups based on device OS.
D.Create a Microsoft Intune compliance policy that tags devices by OS version.
AnswerB

Device group rules in Microsoft Defender for Endpoint evaluate onboarding devices against conditions such as OS version, automatically placing them into the target group. This satisfies the requirement for automatic assignment based on operating system version, avoiding manual tagging or dynamic group queries in Microsoft Entra ID, which cannot drive Defender device group membership.

Why this answer

Device group rules in Microsoft Defender for Endpoint allow you to automatically assign devices to groups based on conditions such as operating system version. This is the correct approach because it uses the built-in grouping engine that evaluates device attributes during onboarding, ensuring consistent and automated assignment without manual intervention.

Exam trap

The trap here is that candidates often confuse Microsoft Entra ID dynamic groups (which are for identity and access management) with Defender for Endpoint device group rules (which are for security operations and automation), leading them to choose Option C incorrectly.

How to eliminate wrong answers

Option A is wrong because manually tagging each device in the Microsoft 365 Defender portal is not automated and does not scale for large environments; it also does not use OS version as a condition. Option C is wrong because Microsoft Entra ID dynamic groups are based on Azure AD device attributes and are used for identity-based access control, not for Defender for Endpoint device group assignment, which requires Defender-specific grouping rules. Option D is wrong because Microsoft Intune compliance policies are used to enforce device health and compliance settings, not to tag devices for Defender for Endpoint grouping; they do not create device groups in Defender.

113
MCQmedium

Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?

A.Create a device compliance policy and assign it to users.
B.Create a device configuration profile that restricts access.
C.Create a Conditional Access policy that requires compliant devices.
D.Configure enrollment restrictions to block non-compliant devices.
AnswerC

Conditional Access evaluates sign-in signals at authentication time, so a policy granting access only when the device is marked compliant in Intune blocks non-compliant devices from corporate resources. Compliance policies alone only report state; the Conditional Access policy enforces the block.

Why this answer

Conditional Access policies in Azure AD are the correct mechanism to enforce access controls based on device compliance status. By creating a policy that requires devices to be marked as compliant, you ensure that only compliant devices can access corporate resources, while non-compliant devices are blocked at the authentication level. This integrates with Intune compliance policies to evaluate device health before granting access.

Exam trap

The trap here is that candidates often confuse the role of a compliance policy (which only evaluates and reports) with the enforcement mechanism (Conditional Access), leading them to select Option A as the answer.

How to eliminate wrong answers

Option A is wrong because a device compliance policy alone only reports compliance status and can trigger actions like sending notifications or marking devices as non-compliant, but it does not block access to corporate resources; it requires a Conditional Access policy to enforce the block. Option B is wrong because a device configuration profile is used to configure device settings (e.g., password policies, restrictions) and does not enforce access control or block non-compliant devices from resources. Option D is wrong because enrollment restrictions control which devices can enroll in Intune, not whether already enrolled devices that become non-compliant are blocked from accessing corporate resources.

114
MCQhard

A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?

A.Recreate the Wi-Fi profile in Intune with new settings
B.Run the 'netsh wlan show profiles' command on affected devices
C.Check the Intune console for Wi-Fi profile assignment and conflict status
D.Review Microsoft Entra ID sign-in logs for authentication failures
AnswerC

Verifying profile assignment and conflict status in the Intune console first confirms whether the Wi-Fi profile actually reached affected devices, since a misassigned or conflicting profile would prevent the network settings from applying. This isolates configuration causes before investigating device-side or network-side faults.

Why this answer

Checking the Intune console for Wi-Fi profile assignment and conflict status is the fastest way to identify deployment issues, such as the profile not being assigned to the affected devices or conflicts with other profiles. Option A is wrong because recreating the profile may not address the root cause and could be time-consuming without first verifying the current assignment. Option B is wrong because running 'netsh wlan show profiles' only lists profiles stored locally and does not show Intune deployment status.

Option D is wrong because reviewing Microsoft Entra ID sign-in logs does not show Wi-Fi profile status or assignment conflicts.

115
Multi-Selectmedium

Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?

Select 3 answers
A.Check that Secure Boot is enabled.
B.Check that the processor is at least 1GHz with 1 core.
C.Check that the device has TPM 2.0 enabled.
D.Check that the device has at least 4GB of RAM.
E.Check that the device has at least 32GB of storage.
AnswersA, C, D

Secure Boot is a mandatory Windows 11 hardware requirement, so verifying it is enabled confirms the device satisfies that constraint before upgrade. Intune compliance policies can report this state, letting you gate the deployment on firmware configuration rather than discovering failures mid-upgrade.

Why this answer

Option A is correct because Windows 11 requires UEFI Secure Boot capability and the feature must be enabled on the device. Option C is correct because Windows 11 mandates TPM version 2.0, and it must be enabled and functioning in the firmware. Option D is correct because the minimum RAM requirement for Windows 11 is 4 GB.

Option B is incorrect because while the processor must be 1 GHz or faster with 2 or more cores on a compatible 64-bit processor, the stated 1 core is insufficient. Option E is incorrect because the minimum storage requirement for Windows 11 is 64 GB, not 32 GB.

Exam trap

MD-102 often tests the exact minimum hardware requirements for Windows 11, and candidates frequently confuse the core count (2 vs 1) or storage (64GB vs 32GB) because they remember Windows 10 requirements or general minimums.

116
MCQmedium

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

A.The policy has not been assigned to the device or its user group.
B.The BitLocker setting is not supported on Windows 11.
C.The policy was not saved correctly due to a syntax error.
D.The device does not have a TPM chip, which is required for BitLocker, but the compliance policy does not check TPM.
AnswerA

An unassigned compliance policy applies to no one, so Microsoft Intune never evaluates the device against its BitLocker requirement. The device therefore reports compliant by default, since no policy targets it — matching the stem's symptom of a non-encrypted device showing compliant.

Why this answer

The most likely reason is that the compliance policy was created but never assigned to the device or its user group. In Microsoft Intune, a compliance policy must be assigned to a security group that contains the device or its user; otherwise, the policy is not evaluated against the device, and the device will default to a compliant status. The PowerShell cmdlet shown only creates the policy object; it does not assign it.

Exam trap

The trap here is that candidates assume creating a policy with PowerShell automatically applies it to all devices, but Intune requires explicit assignment to a group before the policy is evaluated.

How to eliminate wrong answers

Option B is wrong because BitLocker is fully supported on Windows 11 Pro, Enterprise, and Education editions; the compliance policy setting for BitLocker is valid on these editions. Option C is wrong because if there were a syntax error, the New-IntuneCompliancePolicy cmdlet would have returned an error and the policy would not have been created; the fact that the policy exists indicates it was saved correctly. Option D is wrong because while a TPM chip is required for BitLocker to function, the compliance policy setting 'Require BitLocker' checks whether BitLocker is enabled on the device, not whether a TPM is present; if BitLocker is not enabled, the device should be marked noncompliant regardless of TPM status.

117
MCQmedium

You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices are Microsoft Entra joined. You need to ensure that during OOBE, devices are automatically assigned to the correct group for policy targeting. What should you configure?

A.Use a Group Policy object to add devices to an on-premises security group that is synced to Microsoft Entra ID.
B.Assign the Autopilot deployment profile to a static group that contains all users.
C.Create a dynamic device group in Microsoft Entra ID with a rule based on the device's enrollment profile name.
D.Configure a device category in Intune and assign it during OOBE.
AnswerC

Dynamic device groups in Microsoft Entra ID can use the device's enrollment profile name (or other attributes like device model, manufacturer) to automatically include devices. This ensures that Autopilot devices are grouped correctly for policy assignment without manual intervention. The enrollment profile name is set during Autopilot and can be used as a rule criterion.

Why this answer

Dynamic device groups in Microsoft Entra ID allow automatic membership based on device attributes such as enrollment profile name. This is ideal for Autopilot deployments because devices are automatically added to the correct group, enabling targeted policy and app assignments without manual effort.

Exam trap

The trap here is assuming that static groups or device categories can automate group membership, when dynamic groups based on device attributes are required.

118
MCQeasy

You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?

A.Deploy a line-of-business app from the installation file.
B.Deploy a Win32 app with the Office Deployment Tool.
C.Deploy Microsoft 365 Apps for enterprise as a built-in app type in Intune.
D.Deploy a custom script that installs Office from a network share.
AnswerC

The built-in Microsoft 365 Apps app type in Intune uses the Office Deployment Tool and updates automatically from the Microsoft 365 Apps update channel, keeping the latest version installed across both Windows 10 and Windows 11 devices.

Why this answer

The Microsoft 365 Apps for enterprise built-in app type in Intune is specifically designed to deploy and manage Office with automatic updates from the Office Content Delivery Network (CDN). This method ensures that devices always receive the latest version of Microsoft 365 Apps without requiring manual intervention or custom configuration, as Intune handles the deployment policy and update channel settings natively.

Exam trap

The trap here is that candidates often choose Option B (Win32 app with ODT) because they know ODT is the standard tool for Office deployment, but they overlook that the built-in app type in Intune provides a simpler, more reliable method that automatically handles update channel configuration and ensures the latest version is always installed without custom scripting.

How to eliminate wrong answers

Option A is wrong because deploying a line-of-business (LOB) app from an installation file requires manual packaging and does not support automatic updates to the latest version; it also lacks the built-in update channel management that Microsoft 365 Apps require. Option B is wrong because while deploying a Win32 app with the Office Deployment Tool (ODT) can install Office, it requires custom configuration of the update channel and does not inherently ensure the latest version is always installed unless you manually configure the CDNBaseUrl and update settings; it also adds unnecessary complexity compared to the built-in app type. Option D is wrong because deploying a custom script that installs Office from a network share relies on a static source that must be manually updated, and it does not integrate with Intune's update management or the Office CDN, making it impossible to guarantee the latest version is always installed across all devices.

119
MCQmedium

You are configuring a Windows Autopilot deployment for a group of remote users. The users will receive new Windows 11 devices and will sign in with their Microsoft Entra ID credentials. You need to ensure that the devices are automatically enrolled in Microsoft Intune and that the users are assigned the appropriate licenses. Which license must be assigned to the users?

A.Microsoft Entra ID P1
B.Microsoft Intune Plan 1
C.Microsoft 365 E5
D.Microsoft 365 E3
AnswerB

Microsoft Intune Plan 1 is the standalone license that provides full Intune management capabilities, including automatic enrollment and Autopilot. It is sufficient for managing devices with Intune. Assigning this license to users ensures they can enroll devices and use Autopilot features.

Why this answer

To use Windows Autopilot and automatic enrollment in Intune, users must have an Intune license. Microsoft Intune Plan 1 is the standalone license that grants access to Intune features. While higher-tier licenses like Microsoft 365 E3 or E5 include Intune, they are not the specific required license.

Microsoft Entra ID P1 is not an Intune license.

Exam trap

The trap here is assuming that any Microsoft 365 license that includes some management features is sufficient, when actually a license that explicitly includes Intune is required.

120
Multi-Selecteasy

You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?

Select 2 answers
A.Set 'Defer quality updates (days)' to 0.
B.Set 'Feature update channel' to 'Semi-Annual Channel'.
C.Set 'Update notification level' to 'Turn off notifications'.
D.Set 'Defer quality updates (days)' to 60.
E.Set 'Defer feature updates (days)' to 60.
AnswersA, E

Setting the quality update deferral to zero days means devices install security fixes immediately upon release, satisfying the stem's requirement for prompt quality updates. Deferral values delay installation, so zero is the only setting achieving the stated immediacy.

Why this answer

Option A is correct because setting 'Defer quality updates (days)' to 0 means quality updates (security fixes) are offered immediately when released, with no deferral, which matches the requirement to receive them as soon as possible. Option E is correct because setting 'Defer feature updates (days)' to 60 delays feature updates by exactly 60 days, satisfying the requirement to defer feature updates for up to 60 days. Option B is not correct because 'Semi-Annual Channel' is a servicing channel designation, not a deferral setting, and it does not by itself defer feature updates by 60 days.

Option C is not correct because 'Update notification level' controls user-facing update notifications, not the timing of quality or feature update delivery. Option D is not correct because deferring quality updates by 60 days would delay security fixes, contradicting the goal of receiving them as soon as they are released.

Exam trap

MD-102 often tests the confusion between quality and feature update deferrals; candidates sometimes set a high quality deferral thinking it applies to features, which would delay security patches.

121
MCQeasy

You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?

A.Increase passwordMinimumLength to 10.
B.Set passwordExpirationDays to 0 to never expire.
C.Ensure the password includes characters from at least 3 character sets.
D.Set passwordRequiredType to 'alphanumeric' (it is already set).
AnswerC

The policy requires 3 character sets.

Why this answer

PasswordMinimumCharacterSetCount of 3 requires the user to include characters from 3 different sets (e.g., uppercase, lowercase, digits). The other options are not directly related to the issue. Option A is incorrect because alphanumeric includes letters and numbers.

Option B is incorrect because 8 is already set. Option D is incorrect because expiration is not about acceptance.

122
MCQeasy

Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?

A.Self-deploying mode where no user interaction is required.
B.User-driven deployment with Microsoft Entra ID join.
C.Hybrid Microsoft Entra ID join with on-premises domain controller.
D.On-premises Active Directory domain join only.
AnswerB

Setting enrollmentType to azureAdJoined joins the device only to Microsoft Entra ID, not on-premises Active Directory. This matches the user-driven scenario where the primary user receives the device and completes OOBE, satisfying the stem's requirement for a cloud-joined, user-driven Autopilot deployment.

Why this answer

The enrollmentType 'azureAdJoined' in a Windows Autopilot profile specifically configures a user-driven deployment that joins the device to Microsoft Entra ID (formerly Azure AD). In this mode, the end user provides their Microsoft Entra ID credentials during the out-of-box experience (OOBE), and the device is registered as a Microsoft Entra ID joined device, enabling single sign-on and compliance policies without requiring on-premises infrastructure.

Exam trap

The trap here is that candidates often confuse 'azureAdJoined' with self-deploying mode (option A) because both result in Microsoft Entra ID join, but the key differentiator is that self-deploying mode requires additional profile settings (like a device enrollment manager account) and is intended for kiosk or shared devices, not user-driven scenarios.

How to eliminate wrong answers

Option A is wrong because self-deploying mode uses enrollmentType 'azureADJoined' but with a different profile setting (selfDeployingMode = true) and requires no user interaction; the question specifies only enrollmentType as 'azureAdJoined', which does not imply self-deploying mode. Option C is wrong because hybrid Microsoft Entra ID join requires an on-premises domain controller and uses enrollmentType 'azureADHybridJoined' or a profile configured for hybrid join, not 'azureAdJoined'. Option D is wrong because on-premises Active Directory domain join is not supported by Windows Autopilot; Autopilot only supports Microsoft Entra ID join or hybrid Microsoft Entra ID join, and 'azureAdJoined' explicitly targets cloud-only join.

123
MCQhard

Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?

A.The device is not compliant with Intune compliance policies.
B.The device is not enrolled in Microsoft Intune.
C.The device does not have Microsoft Defender Antivirus enabled.
D.The Microsoft Defender for Endpoint sensor is not connected to the cloud service.
AnswerD

An inactive status means the onboarded sensor is not maintaining its channel to the Microsoft Defender for Endpoint cloud service, so telemetry never reaches Microsoft Defender XDR. A running service alone is insufficient; the sensor must be connected for events to appear.

Why this answer

The 'inactive' status in Microsoft Defender XDR indicates that the Defender for Endpoint sensor on the device has lost connectivity to the cloud service. Even if the service is running locally, the sensor must maintain an active HTTPS connection (using TLS 1.2 or higher) to the Defender for Endpoint backend to send telemetry and receive policy updates. Without this cloud connectivity, the device cannot report security events, resulting in the 'inactive' state.

Exam trap

The trap here is that candidates assume a running service equals full functionality, but the exam tests the distinction between the local service state and the cloud connectivity required for the sensor to report as 'active' in the console.

How to eliminate wrong answers

Option A is wrong because Intune compliance policies govern device configuration and access control, not the reporting status of Defender for Endpoint; a non-compliant device can still be active in Defender XDR. Option B is wrong because enrollment in Microsoft Intune is not a prerequisite for Defender for Endpoint; devices can be onboarded via Group Policy, local script, or other methods without Intune. Option C is wrong because Microsoft Defender Antivirus is a separate component; the Defender for Endpoint sensor can function and report events even if the antivirus is disabled or replaced by a third-party solution.

124
MCQmedium

You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?

A.Enable automatic MDM enrollment in Microsoft Entra ID and configure dynamic device groups in Microsoft Intune.
B.Create a conditional access policy requiring compliant devices and assign it to all users.
C.Deploy a Windows Autopilot deployment profile to all devices and use it to assign policies.
D.Configure a device compliance policy with a grace period and assign it to All Users.
AnswerA

Automatic MDM enrollment in Microsoft Entra ID ensures that any device joined to Entra ID is automatically enrolled in Intune without user action. Dynamic device groups based on attributes like deviceOSType or enrollmentProfileName allow policies to target devices automatically. This meets the requirement for zero-touch provisioning and grouping.

Why this answer

Automatic MDM enrollment in Microsoft Entra ID ensures devices are enrolled in Intune upon join. Dynamic device groups in Intune automatically include devices based on attributes, enabling policy assignment without manual intervention. Together, they provide the required zero-touch provisioning and grouping.

Exam trap

The trap here is confusing compliance policies or conditional access with enrollment mechanisms, assuming they automatically enroll devices.

125
MCQhard

You are deploying Windows 11 devices using Windows Autopilot. The devices must be joined to an on-premises Active Directory domain and also registered with Microsoft Entra ID. You need to configure the deployment profile. Which Autopilot mode should you use?

A.Microsoft Entra joined
B.Pre-provisioning (white glove)
C.Microsoft Entra hybrid joined
D.Self-deploying mode
AnswerC

Microsoft Entra hybrid joined mode joins devices to both on-premises Active Directory and Microsoft Entra ID. This is the correct choice when devices must be domain-joined and also registered with Microsoft Entra ID. It requires configuration of the Intune Connector for Active Directory and a domain join configuration profile.

Why this answer

Microsoft Entra hybrid joined mode is specifically designed for scenarios where devices need to be joined to on-premises Active Directory and registered with Microsoft Entra ID. This mode supports domain join during Autopilot and requires the Intune Connector for Active Directory to create computer objects in AD. It enables both cloud and on-premises management.

Exam trap

The trap here is selecting pre-provisioning as a join mode, when it is actually a deployment technique that can be used with different join types.

126
MCQmedium

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?

A.Configure a Group Policy to auto-enroll devices into Intune
B.Configure a device enrollment manager (DEM) account
C.Configure Windows Autopilot self-deploying mode and an Enrollment Status Page profile
D.Configure co-management with Microsoft Configuration Manager
AnswerC

Windows Autopilot self-deploying mode enrols devices with no user credentials, satisfying the zero-touch requirement, since it authenticates via the device's TPM-attested identity rather than an interactive sign-in. Pairing it with an Enrollment Status Page profile blocks device use until assigned required apps install, meeting the stem's gating constraint.

Why this answer

Windows Autopilot self-deploying mode enrolls devices into Intune with zero user interaction — the device authenticates using its TPM-attested hardware identity, so no credentials are entered. Pairing it with an Enrollment Status Page (ESP) profile blocks the device from being used until required apps and policies are applied, which is exactly what the scenario requires.

Exam trap

MD-102 often tests the confusion between DEM accounts (bulk enrollment with sign-in) and Autopilot self-deploying mode (truly unattended, TPM-based), causing candidates to pick DEM for zero-touch scenarios.

How to eliminate wrong answers

Option A is wrong because Group Policy auto-enrollment still requires a user to sign in with a work account to trigger MDM enrollment, so it is not zero-touch. Option B is wrong because a DEM account is used to enroll many devices with a single account and still requires interactive sign-in; it also has a 1,000-device limit and is not designed for unattended self-deploying scenarios. Option D is wrong because co-management with Configuration Manager is about workload sharing between Intune and ConfigMgr, not about zero-touch enrollment or blocking device use via ESP.

127
MCQhard

You are the administrator for a company that uses Microsoft Intune. You need to deploy a Windows 10 device configuration profile that configures a custom administrative template setting. The setting is not available in the built-in templates. You have the ADMX and ADML files for the setting. What should you do first?

A.Import the ADMX and ADML files into Intune
B.Convert the ADMX files to XML and import them as a custom compliance policy
C.Create a custom configuration profile using OMA-URI
D.Upload the ADMX files to a file share and reference them in a PowerShell script
AnswerA

To configure custom administrative template settings that are not built into Intune, you must first import the ADMX and ADML files. Intune allows you to upload custom ADMX files, which then make the corresponding settings available in the administrative templates profile. This is a prerequisite before you can create a profile that uses those settings.

Why this answer

Intune supports importing custom ADMX and ADML files to extend the administrative templates. After importing, the custom settings become available in the administrative templates profile, allowing you to configure them. Other methods like OMA-URI or scripts are not the correct first step when ADMX files are provided.

Exam trap

The trap here is choosing OMA-URI because it is a common method for custom settings, but when ADMX files are available, importing them is the intended approach.

128
MCQeasy

You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?

A.Set the install context to system.
B.Set the install context to user.
C.Assign the app as required for all users.
D.Use a line-of-business app type instead.
AnswerA

Setting the install context to system runs the app's installer under the local SYSTEM account, which already holds full administrative rights on the device. This satisfies the stem's requirement that the Win32 app needs admin privileges to install, avoiding any user-context elevation prompt during Intune deployment.

Why this answer

Setting the install context to 'system' runs the Win32 app installer with the SYSTEM account, which has the highest privileges on a Windows device. This ensures the installer can perform actions requiring admin rights, such as writing to Program Files or modifying system registry keys, without user interaction or credential prompts. In Intune, the system context is the only way to silently deploy apps that demand elevated permissions.

Exam trap

The trap here is that candidates often confuse 'install context' with 'assignment scope' (required vs. available), mistakenly thinking that marking an app as 'required for all users' automatically grants admin privileges, when in fact the install context must be explicitly set to 'system' for elevated installations.

How to eliminate wrong answers

Option B is wrong because setting the install context to 'user' runs the installer under the logged-on user's account, which lacks admin privileges unless the user is a local administrator, and it cannot perform system-level changes silently. Option C is wrong because assigning the app as required for all users does not change the install context; it only controls targeting, and if the install context is set to user, the app will still fail to install for non-admin users. Option D is wrong because using a line-of-business (LOB) app type does not inherently provide admin privileges; LOB apps are typically for single-file installers (e.g., .msi or .intunewin) and still require the correct install context to be set to system for elevated installations.

129
MCQmedium

Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?

A.Add the device to Microsoft Entra ID before shipping.
B.Obtain the hardware hash from the device manufacturer or reseller.
C.Use Microsoft Configuration Manager to collect the hardware hash.
D.Run a PowerShell script on each device to capture the hardware hash.
AnswerB

Capturing the hardware hash at the manufacturer or reseller lets it be uploaded to Microsoft Intune before shipping, so devices enrol automatically on first boot. Manual hash collection after delivery would delay provisioning and break the pre-shipment requirement.

Why this answer

The hardware hash can be obtained from the device manufacturer or reseller (OEM) before the device is shipped. This is the recommended approach for new devices as it allows the hardware hash to be uploaded to Intune without needing to power on the device. Option A is wrong because adding the device to Microsoft Entra ID does not upload the hardware hash.

Option C is wrong because Configuration Manager can collect hashes but requires the device to be on the network and is typically used for existing devices. Option D is wrong because running a PowerShell script on each device requires the device to be powered on and manually executed, which is less efficient for new devices.

130
Multi-Selecteasy

Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)

Select 2 answers
A.Devices enrolled in Microsoft Intune
B.Configuration Manager current branch
C.On-premises Active Directory
D.Public Key Infrastructure (PKI)
E.Hybrid Microsoft Entra ID joined devices
AnswersA, B

Co-management requires the device to be enrolled in Microsoft Intune so the Intune service can receive policy and workload data alongside Configuration Manager. Without this enrolment, the Configuration Manager client alone cannot hand over workloads, so enrolment satisfies the stated prerequisite.

Why this answer

Option A is correct because co-management requires that the Windows devices be enrolled in Microsoft Intune, which provides the MDM authority and the Intune workloads that Configuration Manager can hand over. Option B is correct because co-management is a feature of Configuration Manager current branch (version 1710 or later), so the site must be running a supported current branch release. Option C is not required because co-management works with Microsoft Entra ID (Azure AD) joined, hybrid joined, or even domain-joined devices, and on-premises Active Directory is not a prerequisite.

Option D is not required because PKI certificates are only needed for specific scenarios such as HTTPS management or PKI-based authentication, not for enabling co-management itself. Option E is not required because hybrid Microsoft Entra ID joined devices are one supported device identity type, but co-management also supports Microsoft Entra ID joined and domain-joined devices, so hybrid join is not mandatory.

Exam trap

The trap is that candidates may think hybrid Azure AD join is mandatory for co-management, but both hybrid and pure Azure AD join are supported. They may also overlook that Configuration Manager current branch is a prerequisite, not just an optional upgrade.

131
MCQeasy

A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?

A.App protection policy
B.Enrollment restriction
C.Device configuration policy
D.Device compliance policy
AnswerD

A device compliance policy defines passcode requirements, including minimum length, and marks devices non-compliant when unmet. Conditional Access then blocks corporate email access for non-compliant iOS devices, directly satisfying the six-character passcode constraint. Configuration profiles merely enforce settings without gating access, so they cannot restrict email by compliance state.

Why this answer

A device compliance policy in Intune defines the rules a device must meet to be considered compliant, including passcode requirements like minimum length. Conditional Access policies then use compliance state to gate access to corporate email. This is the correct mechanism because compliance policies evaluate device state and report back to Intune, which Conditional Access queries.

Exam trap

MD-102 often tests the distinction between configuration policies (which push settings) and compliance policies (which evaluate state for Conditional Access) — candidates frequently pick configuration when the scenario requires access gating.

How to eliminate wrong answers

Option A is wrong because app protection policies (MAM) protect app data with PINs at the app level, not device-level passcode enforcement for email access. Option B is wrong because enrollment restrictions control which devices can enroll (by platform, OS version, manufacturer), not post-enrollment passcode requirements. Option C is wrong because device configuration policies push settings to devices but do not evaluate compliance state for Conditional Access — they configure, they don't assess.

132
MCQmedium

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?

A.Create a device configuration profile in Intune and use a scope tag to target only the co-managed devices.
B.Create a device configuration profile in Intune and assign it to a user group that contains users of the co-managed devices.
C.Create a device configuration profile in Intune and assign it to a device group that contains only the co-managed devices.
D.Create a device configuration profile in Intune and configure the "Configuration Manager Compliance" setting to require co-management.
AnswerC

In Intune, you can assign a device configuration profile to a specific device group. By creating a group that contains only the co-managed devices, you ensure the profile applies only to them. This is the simplest and most direct method. It does not require any additional filtering or complex configuration, and it works regardless of the workload settings, as long as the devices are in the group.

Why this answer

The most straightforward way to target a configuration profile to a specific set of devices is to assign it to a device group containing those devices. Creating a group with only the co-managed devices and assigning the profile to that group ensures the policy applies exclusively to them. Other methods like scope tags or user groups do not provide the same precise device targeting.

Exam trap

The trap here is assuming that scope tags can be used to target policies to specific devices, when in fact they are for administrative scoping, not device targeting.

133
Multi-Selectmedium

Which TWO actions should you take to prepare a Windows 10 device for a deployment using Windows Autopilot?

Select 2 answers
A.Join the device to Microsoft Entra ID manually.
B.Ensure the device has an internet connection during the out-of-box experience.
C.Enable BitLocker encryption on the device.
D.Upgrade the device to the latest Windows 10 version.
E.Collect the hardware hash of the device.
AnswersB, E

An internet connection during the out-of-box experience lets the device contact the Autopilot deployment service, download its assigned profile, and enrol into Microsoft Entra ID. Without connectivity at OOBE, profile retrieval fails and the device cannot complete the cloud-driven provisioning sequence.

Why this answer

Option B is correct because Windows Autopilot relies on the device contacting Microsoft's cloud services (Intune and the Autopilot deployment service) during the out-of-box experience (OOBE) to download the deployment profile and enroll the device, so a working internet connection at OOBE is mandatory. Option E is correct because the device's hardware hash (a unique hardware identifier) must be captured and uploaded to Intune to register the device in the Windows Autopilot device list, which is what allows the Autopilot profile to be matched and applied to that specific device. Option A is not required because Autopilot performs the Microsoft Entra ID join automatically as part of the OOBE flow, so a manual join beforehand would defeat the purpose.

Option C is not required because BitLocker is typically enabled automatically after Autopilot enrollment via Intune policy, not as a preparation step. Option D is not required because Autopilot does not mandate upgrading to the latest Windows 10 version beforehand; the device just needs a supported Windows 10 version that supports Autopilot.

Exam trap

Candidates often assume manual Entra ID join or BitLocker are prerequisites, but Autopilot automates these. The two essential steps are network connectivity during OOBE and collecting the hardware hash for device registration.

134
MCQmedium

You are the endpoint administrator for Contoso, Ltd. The company uses Microsoft Intune and has a hybrid Microsoft Entra ID environment with an on-premises Active Directory Domain Services (AD DS) domain. You plan to deploy 200 new Windows 11 devices using Windows Autopilot. The devices must be joined to the on-premises AD DS domain and also registered in Microsoft Entra ID. You need to configure the Autopilot deployment profile to support this scenario. What should you do first?

A.Assign the Autopilot deployment profile to a user group and configure the profile to use "User-driven" mode.
B.Create an Autopilot deployment profile with the "Convert all targeted devices to Autopilot" option enabled.
C.Configure the deployment profile to use Microsoft Entra join and assign the profile to a device group.
D.Configure the deployment profile to use Microsoft Entra hybrid join and ensure the device has a line of sight to a domain controller.
AnswerD

Microsoft Entra hybrid join requires the device to authenticate against an on-premises domain controller during the offline domain join process. A line of sight is essential. Configuring the profile for hybrid join is the correct first step because it enables the device to be joined to AD DS and registered in Microsoft Entra ID simultaneously. Without this setting, the device would only be Microsoft Entra joined, not hybrid joined.

Why this answer

For Windows Autopilot hybrid Microsoft Entra join, the deployment profile must be configured to use Microsoft Entra hybrid join, and the device must have network connectivity to a domain controller during deployment. This allows the device to be joined to on-premises AD DS and registered in Microsoft Entra ID. Simply assigning the profile or using user-driven mode without the hybrid join setting does not meet the requirement.

Exam trap

The trap here is assuming that assigning an Autopilot profile to a user group automatically configures hybrid join, when in fact the join type must be explicitly set in the deployment profile.

135
MCQmedium

You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?

A.Add a shell script under Devices > Scripts
B.Use Company Portal to distribute the script
C.Add a PowerShell script under Devices > Scripts
D.Create a custom configuration profile with Bash script
AnswerA

Intune's Devices > Scripts node deploys shell scripts natively to macOS, executing them via the Intune management agent. This satisfies the requirement to run a script across all managed macOS devices without repackaging as an app.

Why this answer

In Microsoft Intune, shell scripts for macOS are managed under Devices > Scripts, where you can add a script with a specific shell (e.g., bash, sh, zsh) and configure its execution frequency, run context, and notifications. This is the correct method because Intune natively supports deploying and running shell scripts on macOS devices via the Intune management agent, without requiring additional infrastructure.

Exam trap

The trap here is that candidates confuse the ability to run PowerShell scripts on Windows with macOS, or mistakenly think a configuration profile can execute arbitrary code, when in fact Intune strictly separates script deployment (Devices > Scripts) from configuration profiles (Devices > Configuration profiles).

How to eliminate wrong answers

Option B is wrong because Company Portal is a client application for end-user self-service tasks like installing available apps or enrolling devices, not a mechanism for deploying and executing scripts on macOS devices. Option C is wrong because PowerShell scripts are not natively supported on macOS in Intune; Intune's script deployment for macOS only supports shell scripts (e.g., bash, sh, zsh), not PowerShell. Option D is wrong because custom configuration profiles are used to apply settings (e.g., preferences, restrictions) via property lists, not to execute scripts; scripts require the dedicated 'Scripts' blade under Devices.

136
Multi-Selectmedium

Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?

Select 2 answers
A.Windows Autopilot
B.Provisioning packages (PPKG)
C.PXE boot from a distribution point
D.Network boot via WDS
E.Bootable USB media with Windows Setup
AnswersA, B

Windows Autopilot deploys Windows 10/11 by binding a device's hardware hash to a profile, so it enrols into Intune and receives configuration during the out-of-box experience, requiring no imaging infrastructure. This satisfies the question's requirement for a valid Intune-based deployment method.

Why this answer

Windows Autopilot (A) is a valid Intune-based deployment method that uses the device's hardware hash registered in Intune to apply an Autopilot profile, enroll the device in Azure AD/Entra ID, and drive the Out-of-Box Experience (OOBE) so the device is configured and joined automatically without reimaging. Provisioning packages (B) are also valid: a .ppkg created with Windows Configuration Designer can be applied during OOBE or after installation to enroll the device into Intune (via the enrollment package or bulk enrollment token) and apply settings, making it a supported Intune deployment path. PXE boot from a distribution point (C) and network boot via WDS (D) are Configuration Manager/legacy imaging technologies, not Intune deployment methods, and bootable USB media with Windows Setup (E) is a manual OS installation method that does not itself deploy or enroll devices through Intune.

Exam trap

The trap here is that candidates confuse on-premises deployment tools (WDS, PXE, USB media) with cloud-native Intune methods, forgetting that Intune is a cloud-only MDM service that does not support direct imaging or network boot protocols.

137
MCQeasy

You are setting up Microsoft Intune for a new subsidiary. The subsidiary has an existing on-premises Active Directory Domain Services (AD DS) and uses Microsoft Entra Connect to synchronize users to Microsoft Entra ID. You need to enable automatic enrollment of Windows 10 devices into Intune for users who are synchronized from AD DS. What should you configure first?

A.In Microsoft Intune, create a Windows Autopilot deployment profile and assign it to all devices.
B.In Microsoft Intune, create a device enrollment restriction that allows Windows devices and assign it to all users.
C.In Microsoft Entra Connect, enable device writeback and synchronize device objects to Microsoft Entra ID.
D.In Microsoft Entra ID, configure the Mobility (MDM and MAM) settings to enable automatic MDM enrollment for Windows devices.
AnswerD

Automatic MDM enrollment for Windows devices is configured in Microsoft Entra ID under Mobility (MDM and MAM). By setting the MDM user scope to All or a specific group, synchronized users can automatically enroll their Windows 10 devices into Intune when they join or register the device in Microsoft Entra ID, which is the required first step.

Why this answer

Automatic Intune enrollment for Windows devices is enabled through the Mobility (MDM and MAM) configuration in Microsoft Entra ID. This setting, when scoped to users or groups, allows synchronized users to automatically enroll their Windows devices. Enrollment restrictions and Autopilot profiles serve different purposes and do not initiate automatic enrollment, while device writeback is unrelated to MDM enrollment.

Exam trap

The trap here is assuming that Intune enrollment restrictions or Autopilot profiles enable automatic enrollment, when the actual trigger is the Mobility (MDM and MAM) setting in Microsoft Entra ID.

138
MCQeasy

Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?

A.Group Policy
B.Windows Autopilot
C.System Center Updates Publisher (SCUP)
D.Configuration Manager Cloud Management Gateway (CMG)
AnswerA

Group Policy delivers the automatic MDM enrolment task that hybrid Azure AD joined Windows devices require, triggering Intune enrolment via the device's domain membership. Configuring it here satisfies the hybrid join scenario, unlike manual or provisioning-package methods.

Why this answer

For hybrid Azure AD joined devices, automatic enrollment into Intune is configured via Group Policy. Specifically, you deploy the 'Enable automatic MDM enrollment using default Azure AD credentials' policy setting, which triggers the MDM enrollment process using the user's Azure AD credentials during sign-in. This is the only supported method for bulk, automatic enrollment of hybrid Azure AD joined Windows devices without requiring additional infrastructure.

Exam trap

The trap here is that candidates often confuse Windows Autopilot with automatic enrollment, but Autopilot is a provisioning tool for new devices, not a configuration mechanism for existing hybrid domain-joined devices.

How to eliminate wrong answers

Option B (Windows Autopilot) is wrong because Autopilot is designed for new, out-of-box device provisioning and does not handle automatic enrollment of existing domain-joined devices; it requires a fresh OS deployment or reset. Option C (System Center Updates Publisher, SCUP) is wrong because SCUP is a tool for managing third-party software updates via Configuration Manager, not for configuring MDM enrollment. Option D (Configuration Manager Cloud Management Gateway, CMG) is wrong because CMG provides internet-based management for Configuration Manager clients, but it does not configure automatic Intune enrollment; enrollment is handled separately via Group Policy or co-management settings.

139
MCQmedium

Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?

A.Create an app protection policy that restricts data transfer between work and personal apps.
B.Create a device configuration policy that disables clipboard sharing.
C.Create a device compliance policy that requires a work profile.
D.Create a conditional access policy that blocks personal apps.
AnswerA

An app protection policy enforces data-transfer restrictions at the app layer, blocking copy, paste and share actions between managed work apps and unmanaged personal apps within the Android Enterprise work profile. This directly satisfies the stem's requirement to prevent corporate data leaking from work apps to personal apps.

Why this answer

App protection policies (also called MAM policies) in Intune are designed to protect corporate data at the app layer, independent of device enrollment. For Android Enterprise work profiles, an app protection policy can enforce data transfer restrictions such as blocking copy/paste between work and personal apps, restricting save-as, and controlling sharing. This directly addresses the requirement without affecting the personal side of the device.

Exam trap

MD-102 often tests the difference between app protection policies (MAM, app-level data control) and device configuration/compliance policies (MDM, device-level settings), catching candidates who pick device-level controls for app-level data protection requirements.

How to eliminate wrong answers

Option B is wrong because device configuration policies control device settings (e.g., Wi-Fi, VPN, certificates) and do not provide the granular app-level data transfer restrictions needed to block copy/paste between work and personal apps. Option C is wrong because a device compliance policy only evaluates whether a device meets conditions (e.g., OS version, encryption) and marks it compliant or not; it does not enforce app-level data sharing restrictions. Option D is wrong because a conditional access policy controls access to cloud resources based on conditions (user, device, location), not clipboard or data transfer behavior between apps on the device.

140
MCQmedium

You are the endpoint administrator for a company that uses Microsoft Intune. The security team requires that all Windows 11 devices automatically receive an Intune device configuration profile that enforces a minimum PIN length of 8 for Windows Hello for Business. You need to ensure the profile is applied without user interaction. What should you do?

A.Create a compliance policy that requires a minimum PIN length of 8, and assign it to all Windows 11 devices.
B.Create a Group Policy Object (GPO) in on-premises Active Directory and link it to the domain, then sync devices with Intune.
C.Deploy a PowerShell script through Intune that modifies the registry to set the minimum PIN length.
D.Create a device configuration profile with the Windows Hello for Business template, configure the minimum PIN length setting, and assign the profile to all Windows 11 devices.
AnswerD

This is correct because a device configuration profile using the Windows Hello for Business template in Intune allows you to centrally configure PIN requirements. Assigning the profile to all Windows 11 devices ensures that the settings are applied automatically to each device, meeting the requirement for no user interaction and enforcing the minimum PIN length.

Why this answer

A device configuration profile with the Windows Hello for Business template is the correct Intune-native method to enforce PIN requirements. Assigning it to all Windows 11 devices ensures automatic application without user action. Compliance policies only assess, GPOs are for domain-joined devices, and scripts are not the preferred method for this policy.

Exam trap

The trap here is confusing compliance policies with configuration profiles; compliance policies do not enforce settings, they only evaluate them.

141
MCQeasy

You are an endpoint administrator for a company that uses Microsoft Intune. The company has a Microsoft Entra ID tenant with Intune configured. You need to ensure that when new Windows 10 devices are set up by users, they are automatically enrolled in Intune and receive company policies. The devices are purchased from a reseller and are not domain-joined. You want to minimize user interaction during setup. What should you configure?

A.Conditional Access policy
B.Windows Autopilot deployment profile
C.Device enrollment restrictions
D.Microsoft Intune enrollment policy for Windows
AnswerB

Windows Autopilot deployment profiles are used to configure the out-of-box experience (OOBE) for new devices. When a device is registered with Autopilot, the profile can automatically enroll the device in Intune, apply policies, and skip certain OOBE screens. This meets the requirement of minimal user interaction and automatic enrollment for non-domain-joined devices.

Why this answer

Windows Autopilot deployment profiles allow you to configure the OOBE so that devices automatically enroll in Intune and receive policies with minimal user interaction. The device must first be registered with Autopilot, which can be done by the reseller or by capturing a hardware hash. Once registered, the profile ensures that when the user turns on the device, it connects to Intune and applies the desired configuration.

Exam trap

The trap here is confusing enrollment restrictions with enrollment automation; restrictions only control who can enroll, not how devices are provisioned.

142
MCQmedium

A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?

A.Ensure that the device has a policy to allow installation of unapproved apps.
B.Check if the device's enrollment token is still valid.
C.Check if the app is available in the unmanaged Play Store.
D.Verify that the app has been approved in the managed Google Play store.
AnswerD

Approval in managed Google Play is mandatory before an Android Enterprise fully managed device can install any app, even when it appears in the Company Portal. Unapproved apps remain unavailable to Intune, so the install silently fails. Checking approval status directly addresses the managed Play Store constraint in the stem.

Why this answer

For Android Enterprise fully managed devices, apps must be approved in the managed Google Play store before they can be installed via Intune. If an app appears in the Company Portal but fails to install, the most likely cause is that it hasn't been approved in the managed Play Store. This is a common configuration step.

Exam trap

MD-102 often tests the managed Google Play approval process, confusing candidates with other Android Enterprise concepts like enrollment tokens or unmanaged store.

How to eliminate wrong answers

Option A is wrong because fully managed devices do not allow installation of unapproved apps by default, and a policy to allow that would be counterproductive. Option B is wrong because an invalid enrollment token would prevent enrollment, not app installation. Option C is wrong because the unmanaged Play Store is not used for fully managed devices; only the managed Play Store is relevant.

143
MCQhard

Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?

A.Use a compliance policy with custom settings to enforce BitLocker.
B.Create a new security baseline from scratch and include the BitLocker settings.
C.Copy the built-in Windows security baseline and customize the BitLocker settings in the copy.
D.Edit the built-in Windows security baseline and add the BitLocker settings.
AnswerC

Copying the built-in Windows security baseline preserves Microsoft's curated hardening settings, then lets you adjust only the BitLocker values required. The copy is assigned to your Windows 11 device groups through Microsoft Entra ID, satisfying the need for a custom baseline without rebuilding every setting manually.

Why this answer

Intune's security baselines are designed to be copied and customized rather than edited directly. By copying the built-in Windows security baseline, you preserve the Microsoft-recommended settings as a template while allowing modifications—such as specific BitLocker configurations—in the copy. This approach ensures that the original baseline remains intact for reference or reuse, and the customized copy can be assigned to device groups via Intune's policy assignment workflow.

Exam trap

The trap here is that candidates assume baselines can be edited directly like other Intune policies, but Microsoft intentionally locks built-in baselines to enforce consistency, requiring a copy for customization.

How to eliminate wrong answers

Option A is wrong because compliance policies evaluate device compliance after configuration and cannot enforce settings like BitLocker; they only report non-compliance and trigger remediation actions, not deploy configurations. Option B is wrong because Intune does not allow creating a security baseline from scratch; you must start from a built-in baseline template and customize a copy. Option D is wrong because editing the built-in Windows security baseline directly is not supported; Intune baselines are read-only templates, and modifications require creating a copy.

144
MCQeasy

Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?

A.Apple Configurator enrollment
B.Device Enrollment Manager (DEM) account
C.Apple Automated Device Enrollment (ADE)
D.User-initiated enrollment via Company Portal
AnswerC

Apple Automated Device Enrollment (ADE) ties corporate-owned iOS devices to Intune through Apple Business Manager, so devices enrol automatically during Setup Assistant without user-driven Company Portal enrolment. This satisfies the stem's requirement that all corporate-owned iOS devices enrol automatically when users sign in with their work account.

Why this answer

Apple Automated Device Enrollment (ADE) is the correct method because it enables zero-touch, automated enrollment for corporate-owned iOS devices. When ADE is configured with Intune, devices are automatically enrolled during the initial setup assistant when the user signs in with their work account, without requiring manual intervention or the Company Portal app.

Exam trap

The trap here is that candidates often confuse Apple Configurator enrollment (a manual, wired method) with ADE (an automated, over-the-air method), or they think user-initiated enrollment via Company Portal can be automated, but it requires manual steps by the user.

How to eliminate wrong answers

Option A is wrong because Apple Configurator enrollment is a manual, wired method intended for small-scale or shared device scenarios, not for automatic enrollment at scale when users sign in. Option B is wrong because the Device Enrollment Manager (DEM) account is used to enroll multiple devices using a single shared account, not to trigger automatic enrollment per user sign-in. Option D is wrong because user-initiated enrollment via Company Portal requires the user to manually download the app and enroll, which does not meet the requirement for automatic enrollment when signing in with a work account.

145
MCQeasy

Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?

A.Disables the Windows Firewall for all network profiles
B.Enables the Windows Firewall for the public network profile
C.Enables Microsoft Defender Antivirus real-time protection
D.Disables the Windows Firewall for the domain network profile
AnswerB

This management intent configures the Windows Defender Firewall's public network profile state, enabling filtering for connections classified as public. It does not govern domain or private profiles, nor does it define inbound or outbound rules.

Why this answer

The setting shown in the exhibit configures the Windows Firewall to enable the firewall for the public network profile. In Intune, the 'Windows Firewall' configuration policy allows administrators to define per-profile firewall states. Enabling the firewall for the public profile is a common security baseline requirement to protect devices on untrusted networks.

Exam trap

The trap here is that candidates confuse the 'Windows Firewall' setting with Microsoft Defender Antivirus real-time protection, or assume the setting disables all profiles when it actually enables a specific profile; the exhibit's focus on a single profile (public) is the key detail to avoid misinterpreting the scope.

How to eliminate wrong answers

Option A is wrong because the setting specifically enables the firewall for the public profile, not disables it for all profiles; disabling all profiles would be a separate configuration. Option C is wrong because this setting controls Windows Firewall, not Microsoft Defender Antivirus real-time protection, which is managed under a different policy category (Endpoint Protection). Option D is wrong because the setting targets the public profile, not the domain profile; disabling the domain profile firewall would be a distinct policy choice and is not what is shown.

← PreviousPage 2 of 2 · 145 questions total

Ready to test yourself?

Try a timed practice session using only Prepare infrastructure for devices questions.