MD-102 · domain
troubleshooting
Practise Microsoft 365 Endpoint Administrator MD-102 troubleshooting practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice troubleshooting questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about troubleshooting
troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common troubleshooting exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All troubleshooting questions (556)
Click any question to see the full explanation, or start a practice session above.
You are setting up Microsoft Intune for a new company. The company has a mix of Windows 10, Windows 11, iOS, and Android devices. You need to ensure that devices can enroll in Intune automatically without user interaction for Windows devices that are Microsoft Entra joined. What should you configure?
Easy2You are an Endpoint Administrator for a company that uses Microsoft Intune. The security team requires that Windows 11 devices assigned to the Finance department must use a specific set of DNS servers and must not allow users to modify the DNS settings. You create a device configuration profile using the Settings catalog. Which setting category should you use to enforce the DNS server assignment?
Medium3You need to deploy a Microsoft 365 Apps for enterprise configuration to devices managed by Intune. Which policy type should you use?
Easy4Your organization uses Microsoft Entra ID joined devices and Microsoft Intune for mobile device management. A user reports that their device is not receiving compliance policies. The device shows as 'Compliant' in Intune but the Conditional Access policy still blocks access. What should you verify first?
Medium5Which TWO actions can you perform using Windows Autopilot in Microsoft Intune?
Medium6Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks a device as noncompliant if it has not checked in with Intune for more than 30 days. Which compliance setting should you configure?
Medium7You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. Users report that when they attempt to enroll a personally owned Windows device, enrollment is blocked. You need to allow only corporate-owned devices to enroll while still permitting personally owned devices to access email through a browser. What should you configure?
Medium8Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a VPP (Volume Purchase Program) app that is already purchased and assigned to your tenant. What is the minimum configuration required to make the app available to users?
Easy9You need to remotely wipe a lost corporate-owned iOS device that is enrolled in Microsoft Intune. Which action should you perform in the Intune console?
Easy10You are configuring an app protection policy in Microsoft Intune for iOS/iPadOS devices. Which setting can you enforce to prevent users from copying data from a managed app and pasting it into an unmanaged app?
Easy11You are an endpoint administrator for a company that uses Microsoft Intune. You need to configure a Windows 11 device to support multiple users who will sign in with their Microsoft Entra ID credentials. The device will be shared among shift workers. You want to ensure that each user receives their own configuration profiles and applications. What should you configure?
Hard12Your organization is evaluating Microsoft Intune for device management. The security team requires that all devices be registered in Microsoft Entra ID before they can enroll in Intune. Which configuration should you implement?
Medium13You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that Windows Update for Business policies are applied to these devices to control when feature updates are installed. What should you configure?
Medium14Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?
Hard15Your organization uses Microsoft Intune to manage Windows 10 devices. You need to configure a Windows 10 update ring that ensures feature updates are deferred by 120 days and quality updates are deferred by 30 days. Which settings should you configure in the update ring?
Easy16You manage Windows 11 devices with Microsoft Intune. Users run a line-of-business desktop app that writes configuration data to HKEY_CURRENT_USER. After you deploy the app as a Win32 app with an install context of System, users report that their settings are not saved between sessions. You need to ensure that each user's settings persist in their own profile while the app still installs without user interaction. What should you do?
Medium17You are the endpoint administrator for a company that uses Microsoft Intune. The company has a line-of-business iOS app that is not available in the App Store. You need to deploy this app to a group of iOS users. The app must be installed automatically without user interaction. What should you do first?
Medium18Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that only devices running iOS 16 or later can enroll. Which configuration should you use?
Medium19A company uses Microsoft Intune to manage iOS devices. They want to enforce a policy that requires a passcode of at least 6 characters and auto-lock after 5 minutes. Which configuration profile type should they use?
Easy20You are configuring an app protection policy for iOS devices to protect corporate data in Microsoft Outlook. Which TWO settings prevent users from copying corporate data to personal apps?
Medium21You are a Microsoft 365 Endpoint Administrator for a global organization with 5,000 Windows 11 devices managed by Intune. The company has a strict security policy requiring that all devices have BitLocker enabled with TPM validation, PIN, and startup key. Currently, only 80% of devices are compliant with BitLocker. After investigating, you discover that many non-compliant devices are older models that lack TPM 2.0, but they do have TPM 1.2. Additionally, some devices are virtual machines (VMs) that do not have a TPM at all. The security team insists that all devices must be encrypted, but they are willing to accept alternative configurations for devices without TPM 2.0. You need to propose a solution that maximizes security while ensuring compliance. What should you do?
Hard22Your company is deploying Windows 11 devices using Windows Autopilot. You need to ensure that during the first boot, the device automatically joins Microsoft Entra ID, enrolls in Intune, and installs required applications. What should you provide to the device?
Easy23You are troubleshooting a Windows 10 device that is not receiving a required security policy from Intune. The device shows as 'Not compliant' in the Intune console. Which TWO actions should you take to resolve the issue?
Hard24A company wants to prevent users from copying corporate data from managed Microsoft 365 apps to personal apps on iOS devices. What should they configure?
Easy25You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. Users report that their devices are not receiving newly assigned compliance policies. You need to force the devices to check in with Intune immediately. What should you do from the Intune admin center?
Easy26You manage a fleet of Android Enterprise devices. You need to configure a policy that prevents users from installing apps from unknown sources. Which policy type should you use?
Medium27Order the steps to deploy a Windows 10 virtual desktop in Azure using Windows 365.
Medium28You are planning a Microsoft Intune deployment for a large organization with Windows, iOS, and Android devices. You need to ensure that devices can enroll automatically when users sign in with their work accounts. Which THREE components are required?
Hard29You are preparing infrastructure for Windows Autopilot at Contoso. You need to configure the environment so that devices can be deployed with Windows Autopilot in Microsoft Entra hybrid join mode. Which two components must be in place before devices can complete the hybrid join during OOBE? (Choose two.)
Hard30An organization uses Microsoft Intune for device management. They have a requirement that all Windows devices must have BitLocker enabled. They want to automatically remediate any device that has BitLocker disabled by running a PowerShell script. Which Intune feature should be used?
Hard31Refer to the exhibit. You run this PowerShell command to retrieve Windows devices. The output shows several devices with lastSyncDateTime older than 30 days and complianceState as 'noncompliant'. What is the most likely cause for these devices to be noncompliant?
Medium32You are preparing infrastructure for device management. Which TWO are valid methods to enroll Windows devices into Microsoft Intune?
Easy33Which THREE of the following are requirements for deploying a Win32 app via Microsoft Intune?
Hard34You are preparing infrastructure for device management at Adventure Works. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Intune. You need to configure a Windows Autopilot deployment profile that will be used for Microsoft Entra hybrid join. During testing, devices fail at the domain join step. You verify that the Intune Connector for Active Directory is installed and online. What should you check next?
Hard35You need to wipe a lost corporate-owned iOS device that is enrolled in Intune. Which action should you perform?
Easy36Which TWO of the following are valid app types in Microsoft Intune for iOS/iPadOS devices?
Easy37You are preparing to deploy Windows Autopilot for your organization. You have obtained the hardware hashes for 100 new devices. You need to register these devices in Microsoft Intune so that they can be associated with an Autopilot deployment profile. What should you do?
Medium38Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?
Hard39Your organization uses Windows Autopilot for device provisioning. Users report that after initial setup, devices are not automatically enrolled in Microsoft Intune. What should you verify?
Easy40You need to deploy a line-of-business (LOB) app to 100 iOS devices managed by Intune. The app is signed with an enterprise certificate. Which deployment method should you use?
Easy41Your company uses Microsoft Intune to manage Windows 11 devices. A security policy requires that devices automatically receive quality updates as soon as they are available, with a deadline of 2 days after release and automatic restart outside active hours. You create a Windows update ring in Intune. Which setting should you configure to meet the deadline requirement?
Hard42Your organization uses Microsoft Intune to manage Windows 11 devices. The security team requires that BitLocker recovery keys be automatically escrowed to Microsoft Entra ID before a device is marked compliant. You need to configure a compliance policy setting that enforces this. Which setting should you configure?
Medium43You manage Windows 11 devices enrolled in Microsoft Intune. Security requires that devices with unsupported antivirus signatures be blocked from accessing Microsoft 365 resources. You create a compliance policy that sets the Microsoft Defender Antivirus requirement to 'Require' and the 'Antivirus signature age' to 3 days. A device reports an antivirus signature age of 5 days. What is the resulting device state?
Medium44You are planning a Windows 11 deployment for 200 devices using Microsoft Configuration Manager (current branch). The devices are currently running Windows 10. You need to perform an in-place upgrade while preserving user data and settings. The devices are located in remote offices with limited bandwidth. Which deployment method should you use?
Hard45You need to ensure that only compliant devices can access Microsoft 365 resources. You create a Conditional Access policy in Microsoft Entra ID. Which condition should you use?
Easy46You are the endpoint administrator for a company that uses Microsoft Intune. The company has an on-premises network with Active Directory Domain Services (AD DS) and a Microsoft Entra tenant. You need to prepare the infrastructure for Windows Autopilot deployment of Microsoft Entra hybrid joined devices. You must ensure that the required components are in place to support the hybrid join process. Which two actions should you perform? (Choose two.)
Hard47You are the endpoint administrator for Contoso, which uses Microsoft Intune. You need to enroll 200 new Windows 11 devices into Intune with the least administrative effort. The devices are currently running Windows 11 Pro and are connected to the internet. You want to avoid imaging or manually installing agents. What should you do?
Easy48You are configuring a Microsoft Intune compliance policy for Windows 11 devices. You need to ensure that devices with BitLocker not enabled are marked noncompliant. Which setting should you configure in the compliance policy?
Medium49Refer to the exhibit. You run this Microsoft Graph PowerShell command to retrieve managed devices. The output shows a device with a lastSyncDateTime of 5 days ago. What does this indicate?
Hard50Which TWO actions can you perform using Microsoft Intune to manage Windows 10 devices?
Medium51You manage Windows devices with Microsoft Intune. A line-of-business MSI installer must be deployed to 400 devices. The installer requires a custom transform (.mst) file and must run with administrative privileges. You need to deploy the app using the least administrative effort while ensuring the transform is applied. What should you do?
Medium52You need to ensure that Windows 10 devices are automatically upgraded to Windows 11 if they meet hardware requirements. Which policy should you configure in Microsoft Intune?
Easy53Which FOUR of the following are valid detection rules for a Win32 app in Intune?
Hard54An IT administrator needs to ensure that iOS devices enrolled in Intune require a PIN of at least 6 digits. Where should the administrator configure this setting?
Easy55You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?
Easy56You need to remotely wipe a lost corporate-owned iOS device enrolled in Microsoft Intune. The device is currently offline. What will happen when the device comes online?
Easy57Your organization uses Microsoft Defender for Cloud Apps. You need to configure a policy that automatically blocks downloads of sensitive data from SharePoint Online to unmanaged devices. Which policy type should you use?
Hard58You have a Microsoft 365 subscription that includes Microsoft Intune. You have 100 Windows 11 devices enrolled in Intune. You need to ensure that BitLocker recovery keys are automatically escrowed to Microsoft Entra ID when BitLocker is enabled. What should you configure?
Hard59A company uses Microsoft Intune to manage Windows 10 devices. Users report that some required line-of-business (LOB) apps are not being installed on their devices. The apps are assigned as 'Required' to a device group that includes the affected devices. Which two actions should the administrator take to troubleshoot the issue? (Choose two.)
Medium60Your company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. A security team requires that all devices run a specific antivirus signature version before users can access Microsoft 365 resources. You have already created a compliance policy that requires Microsoft Defender Antivirus to be enabled. You now need to add a rule that evaluates the antivirus signature version. What should you do?
Hard61An Intune administrator needs to ensure that Windows 10 devices are compliant with security requirements. Which TWO options are valid compliance settings for Windows 10?
Medium62Refer to the exhibit. You have an Intune configuration that includes a compliance policy and a device configuration policy for Windows 10 devices. You deploy both policies to a group of devices. After deployment, some devices are marked as non-compliant even though they have BitLocker enabled and Windows Defender Antivirus running. Which setting is most likely causing the conflict?
Hard63You manage iOS devices with Microsoft Intune. You need to deploy an app that is not available in the Apple App Store. The app is developed internally and signed with an enterprise certificate. Which app type should you use?
Hard64You are the endpoint administrator for a company that uses Microsoft Intune to manage 500 Windows 11 devices. The security team requires that devices cannot be enrolled if they do not have a TPM 2.0 chip and Secure Boot enabled. You need to configure a device enrollment restriction to block enrollment of devices that do not meet these hardware requirements. What should you do?
Medium65You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?
Easy66You manage a fleet of Windows 10 devices with Microsoft Intune. A line-of-business (LOB) app named App1 is deployed as required to a group of users. Users report that App1 installs successfully on some devices but fails on others with error code 0x87D1041C. You need to resolve the installation failures. What should you do?
Hard67Which THREE of the following are valid methods to deploy Microsoft 365 Apps for enterprise using Microsoft Intune?
Hard68You manage Windows 11 devices with Microsoft Intune. A line-of-business MSI app must install only after a Visual C++ redistributable package is present, and the MSI must run with SYSTEM privileges at every device startup regardless of user sign-in. You need to configure the app deployment in Intune. What should you do?
Medium69Match each Intune configuration profile type to its purpose.
Medium70Your organization uses Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices for accessing an internal web app. Which profile type should you use?
Medium71You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to configure a remediation to automatically restart the Windows Update service (wuauserv) if it stops. You create a proactive remediation script package. Which two components must you provide in the script package? (Choose two.)
Medium72A company plans to deploy Windows 11 to 500 devices using Microsoft Deployment Toolkit (MDT). The deployment must be fully automated with minimal user interaction. Which configuration should be used in the CustomSettings.ini file?
Medium73You are the administrator for a company that uses Microsoft Intune. The company has a policy that all Windows 10 devices must have a minimum OS version of 10.0.19045. You need to ensure that devices that do not meet this requirement are blocked from accessing corporate email. What should you configure?
Medium74You manage a set of Windows 11 devices enrolled in Microsoft Intune. Users report that they can no longer sign in with their Microsoft Entra ID credentials after you deployed a new compliance policy. The devices show as compliant in Intune, but the sign-in fails with an error about device not meeting requirements. You need to ensure that users can sign in. What should you do?
Medium75You manage Windows 11 devices with Microsoft Intune. A Win32 app deployed as Required is failing on a subset of devices, and the Intune Management Extension log shows the installer exiting with code 1618. You have already confirmed the app package and detection rule are correct. What is the most likely cause and the appropriate fix?
Hard76Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?
Medium77You manage devices with Microsoft Intune. You need to ensure that only devices with a specific BIOS serial number can enroll. What should you configure?
Hard78A company uses Microsoft Intune to manage macOS devices. A security audit requires that all macOS devices must have FileVault encryption enabled. Compliance policy reports show that 90% of devices are compliant, but 10% are non-compliant. You review the non-compliant devices and find that FileVault is enabled on them. What is the most likely cause of the non-compliance?
Hard79You manage devices in Microsoft Intune. You need to ensure that a specific set of Windows 10 devices automatically receive new configuration profiles as soon as they are assigned. The devices are already enrolled and are members of an Microsoft Entra ID group. What should you do?
Easy80You use Microsoft Intune to manage Windows devices. You need to deploy a Win32 app that must run only on devices running Windows 11 and must be installed silently in the system context. The installer returns exit code 3010 on success but requires a restart. Which two actions must you perform to ensure the app installs correctly and Intune interprets the success code properly? (Choose two.)
Hard81You are implementing Windows Autopilot for a new fleet of devices. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and is enrolled in Intune. Which configuration is required?
Hard82Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?
Hard83You are the endpoint administrator for a company that uses Microsoft Intune. You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote workers who do not have access to the corporate network. You need to ensure that the devices are automatically enrolled in Intune and that users can sign in with their Microsoft Entra ID credentials. Which Autopilot deployment mode should you use?
Medium84Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Azure AD registered' instead of 'Azure AD joined'. What should you modify to ensure the device is joined?
Hard85You need to configure Intune to automatically retire devices that have not checked in for 90 days. Where should you set this?
Easy86You need to deploy a Windows 10 feature update to a pilot group. Which TWO steps are required in Microsoft Intune?
Easy87You are evaluating Windows Autopilot for a hybrid Azure AD join scenario. Devices are domain-joined on-premises and will be hybrid Azure AD joined. Which prerequisite is required for Autopilot to perform hybrid Azure AD join?
Hard88Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that only devices with TPM 2.0 and Secure Boot enabled can access Microsoft 365 resources. What is the best approach?
Medium89Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode longer than six characters can access corporate email. Which type of policy should you configure?
Medium90An organization uses Microsoft Intune for Windows 10 device management. They need to deploy a custom Windows app (.exe) to kiosk devices. The app requires admin privileges to install, and the devices are shared. Which deployment method should be used?
Hard91A company uses Microsoft Intune to manage Windows 10 devices. They want to prevent users from installing unapproved applications. Which approach provides the most granular control?
Medium92Your organization has 500 Windows 10 devices that are currently managed by Microsoft Configuration Manager (ConfigMgr). You plan to enable co-management with Microsoft Intune to leverage cloud-based policies and conditional access. The devices are on-premises Active Directory joined and are already enrolled in ConfigMgr. You need to configure the co-management workload slider in ConfigMgr to move the 'Device configuration' workload to Intune while keeping 'Compliance policies' and 'Windows Update policies' in ConfigMgr initially. The devices should automatically enroll in Intune upon receiving the co-management policy. You have already configured Azure AD Connect for hybrid Azure AD join. What should you do next?
Hard93You are designing the Windows Autopilot deployment profile for a new subsidiary that has no on-premises infrastructure. All devices will be Microsoft Entra joined. The security team requires that during the out-of-box experience (OOBE), users authenticate with their Microsoft Entra credentials and that local administrator rights are not granted to the primary user. You also want to minimize the time spent at OOBE. Which deployment mode should you select in the Autopilot profile?
Medium94You manage Windows 10 devices with Microsoft Intune. Users report that after a recent Windows update, some devices fail to enroll in mobile device management (MDM). You verify that the devices are domain-joined and can reach the internet. Which configuration should you check first?
Medium95You are troubleshooting a Windows 10 device that is showing as non-compliant in Intune. The exhibit shows the PowerShell output from the Microsoft Graph API. Based on the output, what is the most likely reason for the non-compliance?
Hard96Refer to the exhibit. You are reviewing a Win32 app configuration in Microsoft Intune. The app is not installing on some Windows 10 devices. Which is the most likely reason?
Hard97You need to deploy a Microsoft Store app (e.g., Microsoft Whiteboard) to Windows 10 devices managed by Intune. Which app type should you use?
Easy98You are a Microsoft 365 Endpoint Administrator at Contoso. You have 200 Windows 11 devices enrolled in Microsoft Intune. The security team requires that all devices have a minimum OS build of 22621.1992 and that this requirement be enforced through a compliance policy. You need to configure the compliance policy in the Microsoft Intune admin center. Which policy type should you create?
Medium99Which THREE are valid Windows Autopilot deployment scenarios?
Medium100Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows devices? (Choose two)
Easy101You are configuring Windows Update for Business policies in Microsoft Intune for a group of Windows 11 devices. You need to ensure that devices do not install feature updates for 60 days after a new version is released, while still receiving quality updates immediately. Which setting should you configure?
Hard102You are an endpoint administrator for a company that uses Microsoft Intune. The company plans to deploy Windows 11 devices using Windows Autopilot in self-deploying mode. You need to ensure that the devices can be provisioned without any user interaction. Which two configurations are required for self-deploying mode? (Choose two.)
Medium103Your organization uses Microsoft Intune to manage devices. You need to configure a compliance policy for Windows devices that requires the device to be at a specific OS version and have antivirus enabled. Which TWO settings should you configure in the compliance policy?
Medium104Refer to the exhibit. An Intune administrator configures an Autopilot deployment profile with the shown settings. During OOBE, a device fails to install a required app and enrollment fails. What will happen to the device?
Hard105You are planning to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. Which TWO methods can you use to deploy Microsoft 365 Apps? (Choose two.)
Medium106You manage devices with Microsoft Intune. You need to deploy a Windows 10 feature update to a pilot group of devices. Which profile type should you use?
Easy107You are the endpoint administrator for Contoso, a company with 5,000 employees. The organization uses Microsoft Intune for device management and Microsoft Entra ID for identity. The current environment includes: - 3,000 Windows 11 Enterprise devices (corporate-owned, managed via Intune) - 1,500 iOS devices (corporate-owned, managed via Intune) - 500 Android devices (BYOD, managed via Intune with work profile) - 200 macOS devices (corporate-owned, managed via Intune) You need to implement a solution to automatically enroll new Windows 11 devices purchased from a vendor. The devices should be pre-provisioned with the organization's configuration and applications without requiring IT staff to touch them. Additionally, you need to ensure that only compliant devices can access corporate email and documents. The solution must minimize manual effort and leverage cloud-based services. You have the following requirements: 1. Zero-touch enrollment for new Windows 11 devices. 2. Devices must be automatically configured with security policies and required applications. 3. Conditional access to Microsoft 365 resources based on device compliance. 4. Support for both corporate and BYOD devices. Which of the following actions should you take FIRST to meet the zero-touch enrollment requirement?
Hard108You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?
Hard109Which TWO actions are required to deploy a Win32 app using Microsoft Intune? (Choose two.)
Medium110You are designing a Windows Autopilot deployment for a global organization. Devices are purchased from multiple OEMs and shipped directly to users. Some users report that their devices do not register in Autopilot automatically. You confirm the devices have Windows 11 Pro preinstalled and meet hardware requirements. What is the most likely reason for the registration failure, and what should you do to resolve it?
Hard111You manage Windows 10 devices with Microsoft Intune. A user reports that their device is not receiving required compliance policies, and the device status in Intune shows 'Not evaluated' for compliance. You confirm the device is enrolled and able to sync. What should you check first?
Medium112You are troubleshooting a Windows 11 device that is enrolled in Microsoft Intune. The device shows 'Pending' status for a required app deployment. The app is a line-of-business (LOB) app. The device has been online for the past 24 hours. What is the most likely cause?
Hard113Which THREE actions can you perform on a managed device from the Microsoft Intune admin center?
Medium114Your organization requires that all corporate laptops be encrypted. You manage Windows 10 devices with Microsoft Intune. Which policy should you configure?
Easy115You need to ensure that only compliant devices can access Exchange Online. Which Intune policy should you use?
Easy116You are a Microsoft 365 Endpoint Administrator for a mid-sized company with 5,000 Windows 10 devices. The company is planning to migrate to Windows 11. You are tasked with deploying Windows 11 using a phased approach with Windows Autopilot. You have configured an Autopilot deployment profile for self-deploying mode targeting all Windows 10 devices in a dynamic device group. However, during the first wave of deployment, you notice that devices that have been upgraded to Windows 11 via an in-place upgrade are not automatically transitioning to the Autopilot experience. Instead, they boot directly to the existing Windows 10 desktop without any Autopilot enrollment. You verify that the devices are registered in Autopilot and that the deployment profile is assigned correctly. What is the most likely cause of this issue?
Hard117Your organization uses Microsoft Intune to manage corporate-owned iOS devices. You need to ensure that devices are supervised and can be configured with restrictions that cannot be removed by the user. Which THREE steps must you take?
Medium118An organization uses Microsoft Intune to manage Windows devices. They need to configure a policy to enforce disk encryption on devices. Which TWO of the following are valid encryption options?
Hard119Refer to the exhibit. You are reviewing a Windows 10 update ring configuration JSON. What does the 'automaticUpdateBehavior' setting control?
Easy120Which THREE steps are required to configure a Windows 10 device for kiosk mode using Microsoft Intune? (Choose three)
Hard121You are troubleshooting a Windows 10 device that fails to enroll in Microsoft Intune. The device shows error code 0x8018000b. You verify that the user has a valid Intune license and that the device is running Windows 10 Pro. What is the most likely cause of the enrollment failure?
Hard122You manage a fleet of Windows 11 devices with Microsoft Intune. Users report that the Windows Update ring assigned to them installs quality updates but never installs the required feature update to Windows 11 version 23H2. You confirm the devices are active, check-in is successful, and the ring is assigned to the correct Microsoft Entra group. You need to ensure the feature update installs automatically without user interaction. What should you configure?
Medium123You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?
Hard124You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that automatically marks devices as noncompliant if they do not have a specific antivirus signature version installed. The signature version is updated daily. Which compliance setting should you configure?
Hard125Which THREE factors should you consider when planning a Microsoft Intune migration from Configuration Manager?
Hard126You manage Windows 11 devices with Microsoft Intune. Several devices are failing to check in and receive policy. You review the device list and see the devices are enrolled but show a compliance state of 'Not evaluated'. You need to force the devices to immediately check in with the Intune service from the local device. What should you do?
Medium127Your organization uses Microsoft Defender for Endpoint (Defender XDR) to manage endpoint security. You need to ensure that all Windows devices report their security baselines compliance to Intune. Which configuration should you verify?
Medium128You are the endpoint administrator for Contoso Ltd., a multinational company with 10,000 Windows 10 and 11 devices managed by Microsoft Intune. The company recently acquired a subsidiary that uses on-premises Active Directory and Configuration Manager. The subsidiary's devices are not joined to Microsoft Entra ID. Your goal is to migrate these devices to cloud management with Intune within six months. The subsidiary has 2,000 devices, all running Windows 10. The devices are currently domain-joined and managed by ConfigMgr. You need to choose the most efficient migration strategy that minimizes user disruption and leverages existing investments. The subsidiary has a high-speed WAN link to the corporate network. You have the following options: A) Use ConfigMgr to deploy a task sequence that performs a wipe-and-load with Windows Autopilot, then enroll in Intune. B) Use ConfigMgr co-management with Intune, then gradually transition workloads to Intune, and finally switch devices to Entra ID join. C) Use a provisioning package (PPKG) to join devices to Entra ID and enroll in Intune, while keeping ConfigMgr client for legacy apps. D) Use Windows Autopilot for existing devices by uploading hardware hashes, resetting devices, and re-provisioning. Which option should you choose?
Hard129Your organization uses Microsoft Intune to manage devices. You need to ensure that only corporate-owned Windows 10 devices are allowed to access Microsoft 365 services. You have configured a conditional access policy to require compliant devices. What else must you do to identify corporate-owned devices?
Medium130A user reports that their Windows 11 device is not receiving compliance policies from Microsoft Intune. The device shows as 'Not evaluated' in the Microsoft Intune admin center. Which step should you take first to resolve the issue?
Easy131You manage 500 Windows 11 devices with Microsoft Intune. A security policy requires that all devices run Microsoft Defender Antivirus with real-time protection enabled. You configure a Windows 10 and later antivirus policy in Intune and assign it to all devices. Several devices report that real-time protection is disabled. You need to ensure that real-time protection cannot be disabled by local administrators. What should you do?
Medium132A company uses Microsoft Intune to manage Windows devices. They need to deploy a required app to all devices in the marketing department. The app is a Microsoft Store app (new). What should you do first?
Easy133You need to ensure that devices enrolled in Microsoft Intune automatically receive Windows quality updates as soon as they are released. Which update ring setting should you configure?
Easy134You need to deploy a line-of-business (LOB) iOS app to company-owned devices using Microsoft Intune. The app is signed with an enterprise certificate. Which deployment method should you use?
Easy135You have a Windows 10 device running OS version 10.0.19043.1234. The device is compliant with all settings except password requirements. The device does not have a password set. What is the compliance status?
Hard136You manage 1,200 Windows 11 devices with Microsoft Intune. The security team reports that several devices have stopped checking in and may be compromised. You need to identify devices that have not contacted the service recently and then take action. Which TWO actions should you perform? (Choose two.)
Medium137A company is implementing Windows Hello for Business and wants to use certificate-based authentication. They have an on-premises Active Directory and are using Azure AD Connect for hybrid identity. Which prerequisites must be met to support certificate-based Windows Hello for Business?
Easy138You need to deploy Windows 10 Enterprise to 100 new computers using Microsoft Intune. The computers are not yet joined to Microsoft Entra ID. What is the recommended method?
Easy139Which TWO of the following are benefits of using Windows Autopilot for device provisioning?
Medium140Your organization is migrating from on-premises Active Directory to Microsoft Entra ID. You plan to use Windows Autopilot for new devices. Which prerequisite must be met for Autopilot to work with Entra ID?
Medium141An organization uses Microsoft Intune to manage Windows devices. They want to ensure that only devices with a TPM 2.0 chip can access corporate email. Which policy should be configured?
Easy142Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to configure a Windows Autopilot deployment for new devices that are shipped directly to users. The devices must be automatically enrolled in Intune and configured with your organization's standard settings. What is the minimum requirement for the device to be recognized by Windows Autopilot?
Medium143You manage a fleet of Windows 11 devices with Microsoft Intune. You need to ensure that when a device is compromised, it can be remotely wiped even if the user is not connected to the corporate network. The devices are Azure AD joined and enrolled in Intune. What should you configure?
Hard144Arrange the steps to troubleshoot a BitLocker recovery key prompt on a Windows 10 device.
Medium145Which TWO are benefits of using Windows Autopilot for device provisioning? (Select two.)
Easy146You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) domain named contoso.com and uses Microsoft Entra ID with Microsoft Intune. You must configure a Windows Autopilot deployment for existing Windows 11 devices that are already joined to the on-premises domain. The devices must remain domain-joined and also be registered in Microsoft Entra ID. You need to create the Autopilot deployment profile. Which deployment mode should you select?
Easy147You are the endpoint administrator for a company that uses Microsoft Intune. The company has a policy that all Windows devices must have a minimum OS version of 10.0.19045. You need to create a compliance policy that enforces this requirement. Which type of compliance setting should you configure?
Easy148You are reviewing a custom device configuration profile in Intune. The exhibit shows an OMA-URI setting. What is the purpose of this setting?
Easy149Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that only devices running Windows 11 version 23H2 or later can enroll into Intune. You also want to block enrollment for older Windows versions. What should you configure?
Medium150You manage devices with Microsoft Intune. You need to ensure that when a device is marked as non-compliant, users receive a notification and the device is blocked from accessing corporate email. Which two actions should you perform? (Choose two.)
Hard151A company uses Intune to manage macOS devices. They need to deploy a custom configuration profile that enforces FileVault encryption. What is the recommended approach?
Medium152You assign a required app to a device group. After the next sync, some devices report a 'Failed' status. What should you check first?
Easy153You are an Intune administrator for a large enterprise that uses Microsoft Defender for Endpoint (now Microsoft Defender XDR) for threat protection. You need to ensure that all Windows 10 devices are properly onboarded to Defender for Endpoint and that security settings are enforced via Intune. You have created a device configuration profile that includes the 'Microsoft Defender for Endpoint' settings, but some devices are not appearing in the Defender for Endpoint portal. You verify that the devices are Intune managed and enrolled. What should you do to ensure proper onboarding?
Hard154Your organization uses Microsoft Intune to manage Windows 10 devices. Users report that some required applications are not being installed on their devices. You confirm the applications are assigned as 'Required' to a device group, and the devices are online. What is the most likely cause?
Medium155You are the endpoint administrator for a company that uses Microsoft Intune. The finance team needs a specific third-party accounting application deployed to their Windows 11 laptops. The vendor provides an .msi installer and a setup.exe bootstrapper. You want the deployment to be tracked by Intune and to automatically retry if the install fails. What should you do?
Easy156You are planning a Windows 11 deployment for 1000 devices using Configuration Manager co-management with Intune. You need to ensure that devices automatically enroll to Intune after the Configuration Manager client is installed. Which workload must you configure in Configuration Manager?
Hard157You are planning to deploy Windows 11 devices using Windows Autopilot. The devices will be used by remote users who do not have a VPN connection during initial setup. The devices must be Microsoft Entra joined and enrolled in Intune. You need to ensure that the deployment works without requiring a domain controller. Which Autopilot mode should you configure?
Hard158You need to enroll a Windows 11 device into Microsoft Intune using a work or school account. The device is already joined to Microsoft Entra ID. What is the simplest enrollment method?
Easy159You review the compliance policy JSON for Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.0) with a numeric-only password of 10 characters, BitLocker enabled, firewall enabled, and Microsoft Defender running reports as non-compliant. What is the most likely reason?
Hard160You manage a fleet of Windows 11 devices with Microsoft Intune. The security team requires that any device that has not checked in with Intune for more than 30 days is automatically retired so its resources are released and its compliance state is removed. You need to configure this behavior with the least administrative effort. What should you do?
Medium161You need to ensure that only authorized users can enroll devices in Microsoft Intune. Which setting should you configure?
Easy162You are configuring Conditional Access for device compliance. You have an Intune compliance policy that requires a minimum OS version. You create a Conditional Access policy that grants access only when devices are marked as compliant. However, some users can still access corporate email from non-compliant devices. What is the most likely reason?
Hard163You are deploying a Windows 11 device using Windows Autopilot. The device fails to enroll in Intune and you see the error 'The device is not registered in Autopilot'. You have verified that the device hardware hash is uploaded. What is the most likely cause?
Medium164Refer to the exhibit. You run the PowerShell cmdlet shown and get the output. You need to investigate why Laptop-02 is non-compliant. Which additional cmdlet should you run to get the non-compliance reasons?
Medium165You have a hybrid Microsoft Entra ID joined Windows 10 device that is co-managed with Configuration Manager and Intune. You want Intune to manage Windows Update for Business settings. Which slider setting should you configure in Configuration Manager?
Medium166You are the endpoint administrator for Contoso, a company with 10,000 Windows 11 devices managed by Microsoft Intune. The devices are a mix of corporate-owned and bring-your-own-device (BYOD). You need to implement a solution that allows users to access corporate resources only if their devices meet specific security requirements: disk encryption (BitLocker), antivirus (Microsoft Defender), and a minimum OS build. Additionally, you must ensure that users cannot access corporate email from devices that are jailbroken or rooted. The solution should automatically block non-compliant devices from accessing resources and provide a notification to the user explaining the issue. You have already configured compliance policies in Intune. What should you do next to enforce the block?
Hard167You manage a set of iOS/iPadOS devices enrolled in Microsoft Intune. You need to ensure that users cannot copy data from a managed corporate app (e.g., Outlook) to a personal app (e.g., Gmail). The solution must not require user interaction. What should you configure?
Medium168A user's Android device is not receiving email from the corporate Microsoft 365 tenant. The device is enrolled in Intune and shows as compliant. The email profile is assigned to the user. What should you check first?
Medium169You manage a fleet of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that has a complex installation requiring multiple command-line parameters. The app must be available to users in the Company Portal. What is the best way to handle the installation parameters?
Hard170You manage a set of Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app that requires a specific registry key to exist before installation. The app installer does not check for this key. You must ensure the app installs only on devices that have the registry key. What should you do?
Hard171Order the steps to configure a Windows 10 device for Microsoft 365 Apps deployment via Intune.
Medium172A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps to all devices. The IT team wants to minimize administrative effort and ensure the apps are always up to date. What should they use?
Easy173You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, all corporate data is removed but the user's personal files remain intact. The devices are enrolled as personal devices with work profiles. What should you do?
Medium174You are configuring a Windows Autopilot deployment for devices that must be hybrid Microsoft Entra joined. The environment includes an on-premises Active Directory domain and Microsoft Entra Connect. You need to ensure the devices can complete the hybrid join during OOBE. Which configuration is required?
Hard175You are the Intune administrator for a company that uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that when devices enroll, they automatically receive a set of configuration settings, including a custom Start menu layout and specific Wi-Fi profiles. What should you create and assign?
Medium176You are deploying Microsoft Defender for Endpoint to 200 Windows 10 devices managed by Microsoft Intune. You want to onboard the devices to Defender for Endpoint using the least administrative effort. What should you do?
Easy177You are preparing infrastructure for Windows Autopilot deployment in a hybrid Microsoft Entra join scenario. You need to ensure that devices can join the on-premises domain and enroll in Intune. Which two components must you configure? (Choose two.)
Hard178Your organization, Fabrikam, uses Microsoft Intune to manage iOS/iPadOS and Android devices. You need to implement a solution that ensures company email can only be accessed from the Outlook mobile app, and that data from the Outlook app cannot be copied to personal apps. You also need to ensure that when a user leaves the company, the corporate data in Outlook is removed without affecting personal data. You plan to use app protection policies (MAM). The devices are not enrolled in Intune (unmanaged). You configure the app protection policies for Outlook on iOS and Android. However, users report that they can still copy email content to personal apps. What should you check?
Medium179You manage macOS devices enrolled in Microsoft Intune using the Intune Company Portal app. Users report that the Company Portal app does not detect newly assigned required apps and shows an outdated compliance status. You need to ensure the Company Portal refreshes device state on demand. What should you do?
Hard180Refer to the exhibit. You run a PowerShell command to check the assignment status of device configuration profiles. The 'BitLocker Policy' shows 'Pending'. What does 'Pending' indicate?
Medium181A company uses Microsoft Defender for Endpoint to manage endpoint security. They observe that some devices are not reporting vulnerability data to Microsoft Defender XDR. Which component is most likely misconfigured?
Hard182You have a Windows 10 device that is managed by Intune and enrolled in Microsoft Defender for Endpoint. The device is reporting a high number of false positive detections from Microsoft Defender Antivirus. You need to configure an exclusion for a specific folder path to reduce false positives. Where should you configure the exclusion?
Medium183You are configuring Microsoft Intune for Windows 10 devices. Which two settings can you enforce using a device restrictions profile? (Select TWO.)
Easy184Your organization plans to use Windows Autopilot to provision new devices. Which TWO methods can you use to obtain the hardware hash for a new device?
Easy185You use Microsoft Intune to manage Windows devices. You deploy a Win32 app as required to a device group. The app's detection rule uses a file version check on `C:\Program Files\Contoso\app.exe`. Users report the app appears installed, but Intune repeatedly reinstalls it on every check-in. The app's installer does not actually place app.exe in that path; instead, it places it in `C:\Program Files (x86)\Contoso\`. What should you do?
Hard186You manage a fleet of Windows 10 devices enrolled in Microsoft Intune. You need to ensure that devices receive quality updates with a maximum deferral of 7 days. What should you configure?
Easy187Which THREE are required for a successful Microsoft Intune enrollment of a Windows device?
Hard188Your company uses Microsoft Intune to manage Windows 11 devices. An administrator needs to remotely restart a specific device that is currently online to apply pending updates. Which action should the administrator use in the Intune admin center?
Easy189You are the Endpoint Administrator for a company that uses Microsoft Intune to manage Windows 11 devices. The security team requires that Microsoft Edge be configured with a specific set of security settings, including blocking outdated plugins and enforcing SmartScreen. You need to deploy these settings to all Windows 11 devices with minimal administrative effort. What should you do?
Medium190You need to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune. The deployment must be available to users in the company portal. Which app type should you select?
Easy191Arrange the steps to perform a Windows 10 feature update using Windows Update for Business in Intune.
Medium192Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data is protected when users access Microsoft 365 apps. Which policy should you configure?
Hard193Which TWO actions can you perform using Microsoft Intune to protect devices from malware?
Medium194You manage Windows 10 devices with Intune. You need to collect diagnostic logs from a remote device that is experiencing application crashes. Which Intune feature should you use?
Medium195An organization uses Microsoft Defender for Cloud Apps to monitor cloud app usage. The security team wants to automatically apply an Intune app protection policy (APP) when a user accesses a risky app from an unmanaged device. What should the administrator use?
Hard196A company uses Microsoft 365 E3 licenses. They need to enforce that all users must use the Microsoft Authenticator app for MFA instead of SMS or phone call. What should the administrator configure?
Easy197Match each Microsoft 365 compliance feature to its description.
Medium198Your organization deploys Microsoft Defender for Endpoint (now Microsoft Defender XDR) on Windows 10 devices using Intune. After deployment, some devices show 'Defender service is not running' in the security console. The devices are online and compliant. What is the most likely cause?
Hard199Refer to the exhibit. A Windows 10 device is showing as non-compliant. The compliance policy 'Require BitLocker' is assigned to all devices. The device does not have BitLocker enabled. However, the user is able to access corporate email on the device. What is the most likely reason for this?
Medium200Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?
Medium201You deployed this endpoint protection policy to a Windows 10 device. A user reports that a known malicious file was downloaded but not blocked. What is the most likely reason?
Medium202You need to retire a device in Microsoft Intune. What is the effect of retiring a device?
Easy203A user's device is marked as 'Noncompliant' in Microsoft Intune due to missing required updates. The device is configured with a compliance policy that requires a minimum OS version. The user claims the device is up-to-date. What should you verify first?
Easy204Your organization manages Windows devices with Intune and uses Azure Information Protection (AIP) to classify documents. You are deploying the AIP client as a Win32 app. After deployment, some users report that the AIP add-in is not visible in Office applications. What should you check first?
Medium205A Windows device shows enrollment state 'Enrolled' and compliance state 'compliant', but the policy setting 'MaxInactivityTimeDeviceLock' is not applied. The exhibit shows the device JSON from Intune. What is the most likely reason?
Hard206You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is retired, the primary user's corporate data is removed but the device remains enrolled and managed. Which action should you take in the Intune admin center?
Medium207Arrange the steps to configure Conditional Access for Microsoft 365 in Azure AD.
Medium208You are deploying a Win32 app to Windows devices using Microsoft Intune. The app requires a specific registry key to be present for detection. You also need to ensure the app installs only on devices running Windows 11 version 22H2 or later. Which two actions must you perform when creating the app? (Choose two.)
Hard209You manage devices with Microsoft Intune. Users report that after a recent policy change, some devices are not receiving updated policies. You verify that the devices are online and have connectivity. What should you do to force a policy refresh?
Medium210You have the following JSON compliance policy for Windows 10 devices in Intune. A device with OS version 10.0.19042.0, build 19042, with BitLocker enabled, Secure Boot enabled, but Code Integrity disabled reports as non-compliant. Which setting is causing the non-compliance?
Medium211You are planning the deployment of Microsoft Defender for Endpoint to macOS devices managed by Microsoft Intune. Which TWO prerequisites are required?
Medium212You are responsible for managing Windows 10 devices with Microsoft Intune. You need to deploy a new line-of-business (LOB) app to a group of devices. The app requires a script to run after installation to configure settings. What should you use to deploy the app and ensure the script runs?
Medium213You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. Contoso has an on-premises Active Directory Domain Services (AD DS) forest and uses Microsoft Entra ID with Microsoft Intune. You plan to deploy 200 new Windows 11 devices by using Windows Autopilot in Microsoft Entra hybrid join mode. You need to ensure that each device is automatically joined to AD DS and registered in Microsoft Entra ID during the out-of-box experience. What should you configure first?
Medium214Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to deploy a custom SSL certificate to all devices to authenticate to a corporate Wi-Fi network. Which TWO methods can you use to deploy the certificate?
Medium215You need to deploy Microsoft 365 Apps to 200 Windows devices using Intune. Which app type should you select in Intune?
Easy216Refer to the exhibit. You are reviewing an Intune compliance policy JSON for Windows 10. A device reports as non-compliant, and the compliance status details indicate that the setting 'Secure Boot' is not compliant. The device is a virtual machine. What is the most likely reason?
Medium217Refer to the exhibit. You are deploying a custom OMA-URI policy to Windows 10 devices. What is the effect of this policy?
Hard218You need to ensure that all corporate devices have a standard set of security settings, including disk encryption and firewall configuration. Which Microsoft Intune feature should you use?
Easy219A user reports that their Windows 11 device fails to enroll in Microsoft Intune. The device is Microsoft Entra joined and the user has a valid Intune license. What should you check first?
Medium220Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?
Hard221You need to configure Microsoft Intune to automatically retire a device if it has not checked in for 30 days. Where would you configure this setting?
Easy222You are an endpoint administrator for a company that uses Microsoft Intune. You need to ensure that all Windows 10 devices are automatically enrolled in Intune when they are joined to Microsoft Entra ID. What should you configure?
Easy223Your organization is planning to deploy Microsoft Entra hybrid joined devices. What is a prerequisite for this configuration?
Easy224Your organization uses Microsoft Intune to manage Windows 10 devices. You need to ensure that devices are compliant with a new security policy that requires Windows Defender Antivirus to be enabled and up-to-date. You create a device compliance policy with the setting 'Require' for Windows Defender Antivirus. After assigning the policy, you see that 90% of devices are compliant. The remaining 10% show 'Not evaluated'. You check the devices and find that they are online, enrolled, and have Windows Defender Antivirus enabled. What is the most likely reason for the 'Not evaluated' status?
Medium225You are the Microsoft 365 Endpoint Administrator for Litware, Inc. Litware uses Microsoft Intune and has 500 Windows 11 devices that are already enrolled. The security team wants to require that all Windows devices use a specific set of compliance settings, and they want the settings to apply to devices in a specific department without affecting other departments. You need to deploy a compliance policy that targets only the department's devices. What should you do?
Medium226Your organization uses Microsoft Defender for Endpoint (Microsoft Defender XDR). You need to ensure that all Windows 10 devices report their security health to Microsoft Defender for Endpoint. Some devices are showing as inactive. What is the most likely cause?
Medium227You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that devices automatically receive quality updates and feature updates according to a schedule you define, with the ability to pause updates. What should you configure?
Easy228Your organization is implementing a zero-trust security model using Microsoft Intune. Devices must be compliant before accessing corporate resources. You need to deploy compliance policies for Windows 10 devices that require BitLocker encryption and a minimum OS version. Which two policy settings should you configure? (Choose two.)
Hard229You manage Windows 11 devices in Microsoft Intune. A compliance policy named 'Win11-Compliance' is assigned to all users. You need to prevent users whose devices are not compliant with 'Win11-Compliance' from accessing Microsoft 365 apps, but you want to allow a 30-minute grace period before access is blocked. What should you configure?
Medium230You are deploying Microsoft Defender for Endpoint to Windows 10 devices managed by Microsoft Intune. After onboarding, you need to verify that the sensor is running. Which cmdlet should you use on the device?
Easy231You are designing an app protection policy (APP) for Microsoft 365 mobile apps accessing corporate data on iOS devices. The security team requires that when a user opens a work document in the Microsoft Word app, the user must authenticate with Face ID or a passcode. Which setting should you configure?
Hard232You use Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy to require that devices have a specific minimum OS version and that BitLocker is enabled. Which two settings should you configure in the compliance policy? (Choose two.)
Medium233You are planning to deploy Windows 11 devices using Windows Autopilot in Microsoft Intune. The company requires that the devices are Microsoft Entra joined and that the enrollment process includes the installation of required applications and configuration of device settings. You need to identify which two components are required to achieve this. (Choose two.)
Medium234You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. You need to ensure that when a device is reported as lost or stolen, you can remotely wipe the device and prevent access to corporate data. Which action should you perform?
Easy235You are the Microsoft 365 Endpoint Administrator for Contoso. The company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when devices are enrolled, they automatically receive a set of configuration settings without manual intervention. The settings include a custom Start menu layout and a set of allowed background apps. What should you create in Intune to achieve this?
Easy236You administer Microsoft Intune for Northwind Traders. The security team wants to prevent users from enrolling personally owned Windows 10 devices while still allowing corporate-owned devices to enroll. You need to configure a device enrollment restriction that blocks personal Windows devices. Which platform setting should you modify?
Easy237An organization uses Microsoft Intune to manage Windows 10 devices. They deploy a PowerShell script via Intune to install a custom application. The script runs successfully on some devices but fails on others with error code 0x80070002. What is the most likely cause?
Hard238You are deploying Windows 11 devices using Windows Autopilot. Some devices are not registering in Microsoft Intune. You have verified that the hardware hashes are uploaded correctly. What is the most likely cause?
Hard239Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom .pkg app to all macOS devices. What app type should you create in Intune?
Medium240You are preparing infrastructure for Microsoft Intune enrollment of Windows 11 devices. The company uses Microsoft Entra ID and requires that devices automatically enroll in Intune when users join them to Microsoft Entra ID. You also need to ensure that only users in a specific security group are allowed to enroll devices. What should you configure?
Hard241Refer to the exhibit. You have configured the compliance policy shown above. A user reports that their Windows 11 device is compliant with all settings except the threat level. The device has no threat protection agent installed. What will happen when the user tries to access corporate resources?
Hard242You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, the user receives a notification email, and the device is automatically retired after 30 days. The solution must minimize administrative effort. What should you configure?
Medium243A company uses Microsoft Intune to manage Windows 10 devices. A user reports that their device is not receiving critical security updates despite being compliant with all update policies. You verify that the device is online and communicating with Intune. Which action should you take to resolve the issue?
Hard244A user reports that their Windows 11 device is not receiving configuration policies from Intune. The device shows as 'Enrolled' in the Intune console but last check-in was three days ago. What is the most likely cause?
Hard245You use Microsoft Intune to manage Windows 11 devices. You configure a Windows Update ring policy to defer quality updates by 7 days and feature updates by 60 days. A critical security update is released that must be installed immediately on all devices, bypassing the deferral. What should you configure?
Hard246You manage Windows 10 devices enrolled in Microsoft Intune. Users report that the Company Portal app is not installing required apps. You verify that the devices are compliant and checked in recently. What is the most likely cause?
Medium247Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to implement a policy that requires devices to meet specific hardware and software conditions before they can access corporate email. The policy must evaluate the device's encryption status, OS version, and whether it has a firewall enabled. What should you create?
Hard248A user's iOS device is enrolled in Microsoft Intune and is compliant. However, the user cannot access corporate email in the Outlook mobile app. The app displays an error that the device is not compliant. What is the most likely cause?
Easy249A company uses Microsoft Intune to manage Windows 11 devices. You deploy a required Win32 app that installs a line-of-business tool. Two weeks later, the vendor releases a new version that must replace the old one. You need to ensure devices upgrade to the new version without user interaction and that the old version is removed first. What should you configure?
Medium250Your organization is deploying Microsoft Intune for the first time. You need to ensure that devices can enroll in Intune. Which of the following is a prerequisite for Intune enrollment?
Easy251You configure a Windows 10 device compliance policy in Intune that requires 'Firewall' to be enabled. The device has Windows Defender Firewall enabled, but the device reports as non-compliant. You verify that the firewall is active. What is the most likely cause?
Hard252Refer to the exhibit. The JSON shows a compliance policy for Windows 10 devices. Devices that do not meet the policy are marked as non-compliant. Which diagnostic step would you take to identify why a specific device is non-compliant despite having BitLocker enabled?
Hard253Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate Exchange Online email. Which conditional access policy setting should you use?
Medium254Refer to the exhibit. You have a compliance policy for Windows 10 devices. A device reports as non-compliant with the reason 'TPM not found'. The device does have a TPM 2.0 chip but it is disabled in BIOS. What should you do to resolve the compliance issue?
Medium255Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that only devices with a passcode of at least 6 characters can access corporate email. What should you create?
Easy256Your organization uses Microsoft Intune to manage devices. You have a Windows 10 device that is co-managed with Configuration Manager. You need to configure a policy that requires BitLocker encryption. You create a BitLocker policy in Intune and assign it to the device. After 24 hours, BitLocker is not enabled on the device. You verify that the device is online and the policy is assigned. What is the most likely cause?
Hard257A company is planning to use Windows Autopilot to deploy new devices. They want to ensure that devices are automatically enrolled in Microsoft Intune when a user signs in with their Microsoft Entra ID credentials. Which configuration is required?
Easy258You are the endpoint administrator for a company that uses Microsoft Intune. You need to ensure that when a Windows 11 device is retired or wiped, the device record is automatically removed from Intune after 30 days. Which action should you take?
Easy259Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that corporate data is separated from personal data on the device. Which management approach should you use?
Easy260You need to deploy Microsoft 365 Apps to Windows devices using Intune. Users should be able to install from Company Portal. What app type should you choose in Intune?
Easy261You are planning the device enrollment strategy for a school that provides shared iPads to students. The iPads are used by multiple students throughout the day, and each student must have access to their own apps and data. Which enrollment method should you recommend?
Medium262Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to configure a policy that restricts the device from taking screenshots. Which setting can you use?
Easy263An organization uses Configuration Manager to deploy software updates to Windows 10 devices. The administrator wants to ensure that devices receive updates from the local distribution point rather than the cloud. Which boundary group option should be configured?
Easy264Refer to the exhibit. You query Microsoft Graph API and receive this JSON for a managed device. App2 installation failed. The app is a Win32 app deployed as required. The device is compliant and enrolled via MDM. What is the most likely reason for the failure?
Hard265Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device reports as compliant, but you suspect it may have a weak password policy because the password type is 'deviceDefault'. What is the effect of 'deviceDefault' on the password requirement?
Hard266Your organization uses Windows Defender Application Control (WDAC) to allow only approved apps. After deploying a WDAC policy via Intune, some users report that a critical line-of-business app is blocked. How should you troubleshoot?
Hard267A company with 500 users uses Microsoft 365 E3 licenses. They want to ensure that all users have multi-factor authentication (MFA) enforced. Currently, 80% of users have MFA enabled through the legacy per-user MFA setting. The security team wants to use Conditional Access policies instead. You need to migrate from per-user MFA to Conditional Access with no disruption to users. What should you do?
Medium268You are troubleshooting an iPhone that cannot enroll in Microsoft Intune. The user receives an error stating 'This device is already enrolled in another MDM.' What is the most likely cause?
Hard269You are planning to deploy Microsoft Intune for device management. Which ONE of the following is a prerequisite for enrolling Windows 10 devices in Intune?
Medium270You are designing a Windows 11 update strategy for a fleet of 500 devices managed by Intune. The organization requires that critical security updates be applied within 7 days, but feature updates can be delayed up to 60 days. Which Update Rings configuration should you use?
Hard271You are planning a Windows 11 deployment for 500 new devices using Windows Autopilot. The devices will be shipped directly to users from the manufacturer. You need to ensure that the devices are automatically enrolled in Intune and joined to Microsoft Entra ID. What should you do?
Hard272A company uses Microsoft Intune to manage Windows devices. Administrators need to deploy Microsoft 365 Apps to all managed Windows devices and ensure the apps receive updates automatically from the Microsoft 365 Apps update channel. Which Intune app type should they use?
Easy273An organization needs to deploy Windows 11 to remote users who do not have access to the corporate network. The devices are brand new and have internet connectivity. Which deployment method should the administrator recommend?
Easy274You are preparing to deploy a Win32 app to Windows 11 devices with Microsoft Intune. The app must install silently and be reported as installed only when a specific file exists at a known path. Which TWO configuration elements are required for Intune to evaluate and report the app as installed? (Choose two.)
Medium275You need to ensure that corporate devices automatically install critical Windows updates within 24 hours of release. Which update ring setting should you configure in Intune?
Easy276Your company uses Microsoft Defender for Endpoint (Defender XDR). You need to configure an automated investigation and remediation (AIR) rule that automatically quarantines a file when a specific alert is triggered. Which action should you take?
Medium277A company uses Microsoft Intune to manage devices. They want to ensure that when a device is reported as lost or stolen, the IT admin can remotely wipe the device. Which action should the admin take in the Intune console?
Easy278Which THREE of the following are required to deploy a Win32 app using Microsoft Intune?
Medium279You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully, but the detection rule incorrectly reports the app as not installed, causing Intune to attempt reinstallation repeatedly. Which detection rule method is most likely causing this issue?
Hard280A company uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app as Required to all users. Users report that the app is not installing, and the Intune console shows the app status as 'Not applicable' for all devices. What is the most likely cause?
Hard281Your organization plans to deploy Windows 365 Cloud PCs. You need to ensure that users can connect only from compliant devices. Which configuration should you implement?
Medium282You are deploying a Win32 app that requires .NET Framework 4.8. You create a dependency in Intune for the .NET Framework app. However, some devices fail to install the parent app even though .NET Framework is present. What is the most likely issue?
Hard283You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?
Hard284Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company-specific application (a .pkg file) to all macOS devices. The application requires a specific configuration file that must be placed in the /Library/Application Support/ directory. You also need to ensure that the application is installed silently without user interaction. How should you configure the deployment in Intune?
Medium285You manage Windows devices with Microsoft Intune. A required Win32 app (an .intunewin package) was assigned to a device group, but the app never installs and the device shows no error. The app's install command is `setup.exe /silent`, and the detection rule is a registry key that the installer writes only under HKLM\SOFTWARE. You confirm the app installs successfully when run manually as a standard user. What is the most likely cause?
Medium286You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?
Hard287You are troubleshooting a Windows device that is not receiving policies from Intune. Which TWO actions should you take?
Easy288Your organization uses Microsoft Intune to manage devices. You need to ensure that all Windows 11 devices automatically install critical and security updates from Windows Update. Which policy should you configure?
Easy289You are asked to recommend a solution for deploying a web application as an icon on users' Windows 10 devices managed by Intune. Which app type should you use?
Easy290Which TWO actions can you perform using the Microsoft Intune admin center to manage Windows 11 devices remotely? (Choose two.)
Medium291A user's iOS device is enrolled in Microsoft Intune. The user reports that they cannot install the Company Portal app from the App Store. What is the most likely reason?
Easy292A company uses Microsoft Intune to manage iOS devices. They want to ensure that only devices with a passcode of at least 6 characters and without jailbreak can access corporate email. Which policy type should they configure?
Easy293Refer to the exhibit. The exhibit shows a JSON representation of a managed device from Microsoft Graph API. The device shows as noncompliant. Which of the following is the most likely reason for the noncompliant status?
Hard294Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. After deploying, users report that the app is not available in the work profile. What is the most likely cause?
Hard295Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a .pkg app to these devices. What is the recommended method?
Hard296You manage Android Enterprise fully managed devices with Microsoft Intune. A critical line-of-business app must be installed silently on all devices, and users must not be able to uninstall it. The app is available as an APK. What should you do?
Hard297Your organization plans to deploy a Win32 app to Windows 10 devices using Intune. The app requires the .NET Framework 4.8, which is not present on all devices. How should you handle this dependency?
Hard298You manage Windows devices with Microsoft Intune. You deploy a Win32 app that requires a specific registry key to be present before installation. You need to ensure the app installs only on devices that have the registry key. What should you configure?
Hard299A help desk technician reports that a Windows 11 device enrolled in Microsoft Intune has not received a newly assigned configuration profile. The device shows as compliant in the admin center. You need to force the device to check in with Intune immediately. What should you do?
Easy300You are planning to deploy Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. Which TWO prerequisites must be met before deploying?
Easy301You are preparing infrastructure for device management in Microsoft Intune. Your organization plans to deploy Windows 11 devices using Windows Autopilot in Microsoft Entra join mode. You need to ensure that the devices can be identified and assigned to the correct deployment profile. Which two actions must you perform? (Choose two.)
Hard302You use Microsoft Intune to manage Windows 11 devices. A critical Win32 app must install before any user signs in, and the installer cannot run in the user's context because it writes to protected registry keys and requires elevation. The app has no dependencies and does not need to be visible in the Company Portal. How should you configure the app?
Hard303Your organization uses Microsoft Defender for Cloud Apps (part of Microsoft Defender XDR). You need to detect when users access cloud apps from unauthorized locations. Which log source should you integrate to get location information?
Hard304You are preparing to deploy Windows 11 to 500 devices using Microsoft Intune. The devices are currently running Windows 10 22H2. You need to ensure that the in-place upgrade from Windows 10 to Windows 11 completes successfully. Which policy type should you configure in Intune to deliver the upgrade?
Easy305A company uses Microsoft Intune to manage devices. They need to ensure that a critical line-of-business app is updated automatically on all devices. Which assignment type should they use?
Easy306A company wants to deploy Microsoft 365 Apps to 200 devices using Intune. They need to ensure that the deployment is available only to devices that meet a specific minimum OS version. Which feature should they use?
Easy307You are a Microsoft Intune administrator for Tailwind Traders. The company has enrolled Windows 11 devices. You need to configure BitLocker encryption on all devices using Intune. You have created an endpoint security policy for BitLocker and assigned it to the correct group. After 24 hours, some devices still show as not encrypted. You verify that the devices are compliant with the policy's prerequisites. What should you do to force the policy to apply?
Easy308Refer to the exhibit. The JSON snippet shows a Windows Update for Business policy assigned to a device group. Users report that quality updates are installed 7 days after release. Which setting controls this behavior?
Easy309You use Microsoft Intune to manage Windows 11 devices. You must deliver Microsoft 365 Apps (Microsoft 365 Apps for enterprise) to a group of devices and ensure that the deployment uses the Semi-Annual Enterprise Channel and excludes Access. You also need the installation to occur without user interaction. Which two actions should you perform? (Choose two.)
Medium310Your organization uses Microsoft Intune to manage Windows 10 devices. They deploy a Win32 app using detection rules. The app installs but the detection rule incorrectly reports failure, causing repeated installation attempts. What is the best way to resolve this?
Hard311You need to ensure that only compliant devices can access corporate email in Exchange Online. Which Conditional Access policy setting should you configure?
Easy312You are troubleshooting a Windows device that is not receiving policies from Microsoft Intune. The device shows as 'Not evaluated' or 'Pending' in the Intune console. The device is enrolled and connected to the internet. What is the most likely cause?
Medium313You are an administrator for a company that uses Microsoft Intune. You have an iOS line-of-business (LOB) app that you need to deploy to all iOS devices. The app is signed with an enterprise certificate. You upload the app to Intune and assign it as required. Users report that the app fails to install. What is the most likely cause?
Medium314You use Microsoft Intune to manage Windows 11 devices. A device named LAPTOP-01 is not receiving a newly assigned device configuration profile. You verify the profile is assigned to a group that contains LAPTOP-01. You need to force the device to check in with Intune and apply the policy immediately. Which action should you perform from the Intune admin center?
Hard315Your organization wants to deploy Windows Update for Business policies using Microsoft Intune to Windows 10 devices. Which policy type should you use?
Easy316Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?
Hard317You manage devices enrolled in Microsoft Intune. You need to configure a device compliance policy for Windows 11 devices that requires BitLocker to be enabled and Secure Boot to be enabled. Which two settings should you configure in the compliance policy? (Choose two.)
Medium318Your company uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that work apps are sandboxed from personal apps. Which enrollment type should you use?
Medium319Your organization uses Microsoft Defender for Endpoint (part of Microsoft Defender XDR) on all Windows devices. You need to ensure that devices that are not actively reporting to Defender for Endpoint are flagged as non-compliant in Intune. What should you configure?
Medium320You need to configure Windows Update for Business policies using Intune. You want to defer feature updates by 60 days and quality updates by 14 days. Which policy setting should you use?
Hard321You are an endpoint administrator for a company that uses Microsoft Intune. You deploy a Win32 app to Windows 10 devices using the Intune Management Extension. The app installation fails on some devices with error code 0x87D1041C. You need to resolve the installation failure. What is the most likely cause?
Hard322A company plans to deploy Windows 11 to 500 new devices using Windows Autopilot. The devices are purchased from a hardware vendor that supports OEM registration. Which prerequisite must be met to ensure Autopilot can automatically enroll these devices?
Easy323You need to deploy a custom Windows 11 feature update to a pilot group of 50 devices before rolling out to the entire organization. The devices are managed by Intune and are in a 'Pilot' Azure AD group. What is the best approach?
Medium324Your organization uses Microsoft Intune to deploy apps to Windows 11 devices. You need to ensure that a Win32 app installs only when the device has at least 4 GB of RAM. What should you configure?
Medium325Your organization wants to use Windows Autopilot to deploy new Windows 11 devices. What is required to register a device with Windows Autopilot?
Easy326Your company uses Microsoft Intune to manage Windows devices. Users frequently work from public Wi-Fi and the security team is concerned about unmanaged devices accessing corporate resources. You need to ensure that only devices compliant with your security policies can access Microsoft 365 services. What should you implement?
Hard327Your organization uses Microsoft Intune to manage devices. You need to ensure that only approved applications can run on Windows 10 devices. Which THREE components can you use to implement application control? (Choose three.)
Hard328Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a configuration profile that enforces FileVault encryption. The profile must allow recovery key escrow to Intune. After deploying the profile, you notice that some devices are not encrypted. What should you check first?
Hard329You manage iOS/iPadOS devices with Microsoft Intune. You need to ensure that when a device is lost or stolen, its corporate data can be remotely wiped while leaving personal data intact. The devices are enrolled as user enrollment (personal devices). What should you do?
Medium330You manage Windows 10 devices with Microsoft Intune. A user reports that a device has a red shield icon in the Windows Security Center, indicating tamper protection is off. You need to re-enable tamper protection on the device using Intune. Which profile type should you configure?
Medium331Refer to the exhibit. You run this PowerShell command using the Microsoft Graph PowerShell SDK. What is the primary purpose of this command?
Medium332Your organization uses Microsoft Intune to manage macOS devices. You need to ensure that all devices have FileVault disk encryption enabled. Which configuration profile type should you use?
Easy333Which THREE factors can cause a required app deployment to fail on a Windows 10 device managed by Intune? (Choose three.)
Hard334Your organization is deploying Windows devices using Windows Autopilot. You need to ensure that devices are automatically enrolled in Microsoft Intune when they are first powered on. What should you configure?
Easy335Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a Microsoft Store app (new) to a set of users, and the app must be installed automatically without requiring them to visit the Company Portal. Which assignment intent should you choose for the user group?
Easy336A company uses Microsoft Intune to manage Windows 10 devices. They need to deploy Microsoft 365 Apps for enterprise to 500 devices. The devices are in a hybrid Azure AD joined configuration. The administrator wants to use Intune to deploy the apps. Which deployment method should the administrator use?
Easy337A company uses Microsoft Intune to manage devices. They need to report on which devices have a specific Windows update installed. Which reporting method should be used?
Easy338You deploy a Windows 11 kiosk device using Intune. The kiosk should run a single app (Microsoft Edge). After assignment, the device starts but shows a blank screen. What is the most likely issue?
Medium339You manage a fleet of Android Enterprise devices. You need to ensure that only approved apps from the managed Play Store can be installed. What configuration should you enable?
Easy340Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a security baseline that enforces BitLocker encryption and Windows Defender Antivirus settings. What is the recommended approach?
Easy341A company uses Windows Autopilot for user-driven deployments. They want to ensure that during the out-of-box experience (OOBE), users are required to sign in with their Azure AD credentials and the device is automatically enrolled in Intune. Which Autopilot deployment profile setting should be configured?
Easy342An organization wants to enforce encryption on all Windows 10/11 devices using Intune. Which policy type should they use?
Easy343You are an endpoint administrator for a company that uses Microsoft Intune. You need to deploy Microsoft 365 Apps to Windows devices. The company requires that the apps update automatically from the Office CDN and that users cannot modify the update channel. Which method should you use?
Medium344Which TWO components are required for a successful Windows Autopilot deployment with user-driven Microsoft Entra ID join? (Select two.)
Hard345You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a user reports a lost device, you can remotely lock it and display a custom message on the lock screen. The solution must not erase any data. What should you do?
Medium346Contoso Ltd. is a financial services company with 2,000 users. They use Microsoft Intune to manage Windows 10 devices. The company has a strict security policy that requires all devices to have a specific set of security applications installed: an antivirus (AV) app, a disk encryption app, and a VPN client. These apps are all line-of-business (LOB) Win32 apps packaged as .intunewin files. The administrator created a Win32 app for each and assigned them as 'Required' to all devices. After the deployment, the administrator notices that the apps are not installing on approximately 10% of devices. The devices are online and have connectivity. The Intune Management Extension is running. When the administrator checks the Intune Management Extension logs on a failing device, they see the following error: 'Failed to download content. Error: 0x80070002 - The system cannot find the file specified.' What is the most likely cause?
Hard347You need to ensure that Windows 10 devices automatically enroll in Intune when they join Microsoft Entra ID. Which setting should you configure?
Easy348Your organization uses Microsoft Defender for Endpoint (Defender XDR) and Intune. You need to ensure that when a device is found to have a critical vulnerability, a remediation action is automatically triggered. Which integration should you configure?
Hard349You are deploying a Win32 app that requires administrator privileges to install. The app runs on Windows 11 devices. How should you configure the app in Intune to ensure it installs with elevated privileges?
Hard350You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?
Hard351Your organization uses Microsoft Intune to manage Windows 10 devices. You create a device configuration profile for kiosk mode. The profile is assigned to a device group. After syncing, the device does not enter kiosk mode. What should you check first?
Medium352You manage devices with Microsoft Intune. You need to ensure that only devices that meet specific compliance requirements can access Microsoft 365 services. You create a compliance policy and assign it to a group of users. What should you do next to enforce the policy?
Medium353Match each Microsoft 365 Apps update channel to its description.
Medium354Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft Outlook is protected even if the device is not enrolled in MDM. Which policy should you deploy?
Easy355Your organization has Windows 10 devices managed by Intune. You need to enforce BitLocker encryption on all devices. The devices must use a TPM protector and a recovery password. What should you configure?
Medium356You are deploying a line-of-business (LOB) app to iOS devices managed by Intune. The app requires a specific configuration to access internal resources. Which approach should you use to deliver the configuration?
Hard357A user has a Windows 10 device that is enrolled in Microsoft Intune. The user reports that they cannot install a required app from the Company Portal. You check the Intune console and see that the app assignment is 'Required' but the installation status shows 'Failed'. The device is compliant. What should you check first?
Hard358A company uses Configuration Manager to deploy Windows 11. During the deployment, several devices fail with error code 0x80070002. The administrator suspects the issue is related to missing boot images or content distribution. What should the administrator do first to resolve the issue?
Hard359Your organization uses Microsoft Intune to manage Windows 11 devices. You have a requirement to ensure that all devices have BitLocker Drive Encryption enabled with a TPM protector and a recovery key escrowed to Azure AD. Additionally, you need to configure a policy that prevents users from changing the BitLocker settings. You create a device configuration profile using the 'Endpoint Protection' template for Windows 10 and later. After deploying the policy to a test group, you notice that BitLocker is not enabled on some devices. The devices meet the hardware requirements and are Azure AD joined. What is the most likely reason for the failure, and how should you resolve it?
Medium360Refer to the exhibit. You run a PowerShell command to retrieve a managed device's details. The ComplianceState is 'compliant' but the device has not synced in 7 days. What is the most likely reason?
Medium361You are troubleshooting a Windows 11 device that cannot connect to the corporate Wi-Fi network. The device is enrolled in Intune and has a Wi-Fi profile assigned. The profile uses SCEP certificate authentication. The user can connect to other Wi-Fi networks. What is the most likely cause?
Easy362You use Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a minimum OS version of 10.0.19044. You configure the setting 'Minimum OS version' to '10.0.19044'. Which additional setting must you configure to ensure that devices running a higher version, such as 10.0.19045, are also considered compliant?
Easy363A user reports that their iOS device is not receiving email on their work account. The device is enrolled in Intune. You verify that the Exchange ActiveSync profile is assigned correctly. What should you check next?
Easy364You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to migrate Group Policy objects (GPOs) to Intune policies for Windows 10 devices. Which THREE tools or methods should you use?
Hard365You administer Microsoft Intune for a company with 2,000 Windows 11 devices. The security team requires that all devices automatically receive an Intune enrollment record when they are first powered on by end users, without requiring users to manually enroll. You have already configured a Windows Autopilot deployment profile and assigned it to a device group. Which additional configuration is required to meet the requirement?
Medium366Which TWO actions can be performed using a Windows Autopilot reset? (Choose two.)
Easy367Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?
Medium368A company uses Microsoft Intune to manage Android Enterprise personally owned work profile devices. Employees report that the corporate email app allows copying text into personal apps on the same device. You need to prevent copy and paste of corporate data into personal apps while leaving personal apps otherwise unaffected. What should you configure?
Easy369You are the Microsoft 365 Endpoint Administrator for Contoso, Ltd. The company has an on-premises Active Directory Domain Services (AD DS) environment and uses Microsoft Entra ID with Microsoft Intune. You need to prepare infrastructure to deploy Windows 11 devices that are Microsoft Entra hybrid joined. You must ensure that devices can enroll in Intune without requiring user interaction during the out-of-box experience (OOBE). What should you configure first?
Medium370Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to configure a compliance policy that enforces encryption and firewall settings. Which two settings should you configure in the compliance policy? (Choose two.)
Medium371A company uses Configuration Manager to deploy Windows 11. During the deployment, the task sequence fails at the 'Apply Operating System' step. The error log shows 'Failed to find a valid operating system image package'. You verify that the operating system image package exists and is distributed to the distribution point. What is the most likely cause?
Easy372Your company uses Microsoft Intune to manage devices. You need to ensure that Windows 11 devices can receive configuration profiles and compliance policies. You have already assigned the necessary licenses to users. What should you do first to prepare the devices for management?
Easy373Arrange the steps to deploy Windows 10 using Microsoft Deployment Toolkit (MDT) in the correct order.
Medium374You are an administrator for a Microsoft Intune environment. You need to remotely wipe a lost Windows 11 device to prevent access to corporate data. The device is enrolled in Intune and is currently online. Which action should you perform from the Intune admin center?
Easy375You are an endpoint administrator for a company that uses Microsoft Intune to manage Windows 11 devices. You have a device compliance policy that requires BitLocker Drive Encryption to be enabled on the OS drive. A user reports that their device is marked as non-compliant, even though they have BitLocker enabled and the drive is encrypted. You check the device and see that the BitLocker protection status is 'Protection Off' in the BitLocker control panel. The user has not set up a PIN. You need to ensure the device is compliant. What should you do?
Medium376Your organization wants to use Windows Autopilot for user-driven deployment. Users should be able to self-deploy their devices by signing in with their corporate credentials. Which Autopilot deployment mode should you use?
Easy377Your organization uses Windows Autopilot and Microsoft Intune. You need to ensure that during the Autopilot deployment, the device automatically installs a set of required applications (Microsoft 365 Apps, company portal, and a line-of-business app) before the user can access the desktop. Which configuration should you use?
Medium378Your organization uses Microsoft Intune to manage Windows 11 devices. You need to configure a device compliance policy that requires devices to run Windows version 22H2 or later. When you create the policy, which option must you select for the OS version requirement?
Hard379Your company deploys Microsoft Defender for Endpoint (Defender XDR) to all Windows devices. You need to create a custom detection rule that triggers an alert when a specific PowerShell script is executed on any device. Which action should you take in the Microsoft 365 Defender portal?
Medium380Refer to the exhibit. You manage a Windows 11 device that is marked as compliant and has OS version 10.0.22621.0. You need to upgrade the device to Windows 11 version 23H2. Which Intune feature should you use?
Easy381Your organization uses Microsoft Intune and Microsoft Defender for Endpoint. You need to ensure that when a device is determined to be at high risk by Defender, it is automatically blocked from accessing corporate resources. What should you configure?
Hard382A company uses Microsoft Intune to manage its Windows devices. The IT team wants to ensure that new Windows devices can enroll without requiring users to manually enter the enrollment server address. The devices are already joined to Microsoft Entra ID. Which infrastructure component enables this automatic discovery?
Easy383Which TWO are valid methods to deploy Microsoft 365 Apps to Windows devices using Microsoft Intune? (Choose two.)
Easy384Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a Microsoft 365 Apps for enterprise suite to all devices. Which app type should you use in Intune?
Easy385Which THREE components are required to deploy a Win32 app via Microsoft Intune?
Hard386You are the administrator for a company that uses Microsoft Intune. The company has a policy that requires all Windows 10 devices to have a specific set of security settings applied via Intune configuration profiles. You need to ensure that these settings are applied to devices even if the user is not signed in, and that the settings cannot be overridden by the user. Which type of configuration profile should you use?
Hard387You manage Windows 10 devices with Intune. You need to ensure that only approved apps can run on corporate devices. You configure AppLocker via a custom OMA-URI. However, users can still run unapproved apps. What is the most likely reason?
Medium388Refer to the exhibit. You configure this Enrollment Status Page (ESP) policy for Windows Autopilot deployments. During a deployment, a device fails to install a required app. What happens?
Medium389A company uses Microsoft Intune to manage iOS/iPadOS devices enrolled through Apple Business Manager. They must distribute a proprietary in-house app that is not in the App Store to 500 supervised devices, and the app must be silently installed without user prompts. Which deployment method should they use?
Hard390Your organization is planning to deploy Windows 10 updates using Windows Update for Business. You need to ensure that critical security updates are installed within 7 days of release. Which configuration should you use?
Medium391You manage Windows 10 devices with Microsoft Intune. You need to ensure that devices receive a specific Windows quality update as soon as possible, bypassing any deferral settings. What should you configure?
Medium392Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)
Medium393Your organization uses Microsoft Defender for Endpoint. You need to ensure that devices onboarding to Microsoft Defender for Endpoint are automatically assigned to a specific device group based on their operating system version. What should you use?
Medium394Your organization uses Microsoft Intune to manage devices. You need to ensure that devices that are not compliant are blocked from accessing corporate resources. Which configuration should you use?
Medium395You need to remotely wipe a lost corporate-owned iOS device that is managed by Intune. Which action should you use?
Easy396A company uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are unable to connect to the corporate Wi-Fi network. The Wi-Fi profile is deployed via Intune. Which troubleshooting step should you take first?
Hard397You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a compliance policy that marks devices as noncompliant if they do not have a specific minimum OS version and if they have not checked in with Intune within the last 7 days. Which TWO settings should you configure in the compliance policy? (Choose two.)
Medium398An organization is deploying Windows 10 using Configuration Manager task sequences. During a pilot deployment, the task sequence fails with error code 0x80070002. What is the most likely cause?
Hard399Your organization is preparing to deploy Windows 11 using Microsoft Intune. You need to ensure that all devices meet the minimum hardware requirements for Windows 11 before upgrade. Which THREE checks should you perform?
Medium400Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?
Medium401Your organization uses Microsoft Intune to manage Windows devices. You need to ensure that only users in the Sales department can enroll their devices. What should you configure?
Hard402You are preparing to deploy Windows 11 devices using Windows Autopilot. The devices are Microsoft Entra joined. You need to ensure that during OOBE, devices are automatically assigned to the correct group for policy targeting. What should you configure?
Medium403You administer Microsoft Intune for a company with Windows 11 devices joined to Microsoft Entra ID. A security requirement states that if a device is found noncompliant, it must lose access to Microsoft 365 services within 15 minutes, and the device must be marked noncompliant automatically when a required antivirus signature is out of date. You need to implement this with the least administrative effort. What should you do?
Hard404Which TWO are valid methods to enroll Windows devices in Microsoft Intune?
Easy405You need to deploy Microsoft 365 Apps to 1000 devices using Microsoft Intune. The devices are a mix of Windows 10 and Windows 11. Which app deployment method should you use to ensure the latest version is always installed?
Easy406You are planning to deploy a Win32 app to Windows 10 devices using Microsoft Intune. The app requires a specific registry key to be present before installation. How should you ensure the prerequisite is met?
Medium407Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a custom app that is not available in the Google Play Store. Which app deployment method should you use?
Medium408You manage 500 Windows 11 devices enrolled in Microsoft Intune. A security policy requires that a specific registry value be set on all devices, and you must be able to report which devices have the value applied and remediate any that do not. You need to implement this with the least administrative effort. What should you create?
Medium409A company uses Microsoft Intune to manage Windows 10 and Windows 11 devices. The IT team needs to deploy a set of Microsoft Store apps to all managed Windows devices. They want the apps to be installed automatically without user interaction and to be updated automatically by the Store. Which app type should they use in Intune?
Easy410You manage Windows 11 devices with Microsoft Intune. A critical line-of-business app must be installed on all devices in the Finance department, but the app's installer requires administrator privileges and the users do not have local admin rights. You need to deploy the app silently without user interaction and ensure it installs even if no user is signed in. What should you do?
Medium411You administer Microsoft Intune for a company with 500 Windows 11 devices. The security team requires that when a device is reported lost or stolen, you can remotely erase corporate data without affecting the user's personal files on devices enrolled as personally owned. Which action should you perform in the Intune admin center?
Medium412You are configuring a Windows Autopilot deployment for a group of remote users. The users will receive new Windows 11 devices and will sign in with their Microsoft Entra ID credentials. You need to ensure that the devices are automatically enrolled in Microsoft Intune and that the users are assigned the appropriate licenses. Which license must be assigned to the users?
Medium413You need to deploy an Android Enterprise app to corporate-owned work profile devices. The app is available on Google Play. Which deployment method should you use?
Easy414Refer to the exhibit. An administrator retrieves a list of Win32 apps. They notice that one app shows installExperience as 'system' and detectionRules as 'fileVersion' with version '1.0.0'. The app fails to install on some devices. The event viewer on a failing device shows 'The app was installed but detection rule did not match'. What is the most likely cause?
Hard415You manage Windows 11 devices with Microsoft Intune. Users report that when they attempt to enroll a personal device, enrollment fails with error 80180014. You need to ensure that only corporate-owned devices can enroll. What should you configure?
Medium416Refer to the exhibit. An Intune administrator configured a Win32 app with the settings shown. What is the expected behavior when the app installation exits with return code 3010?
Medium417Which THREE conditions can be used to create a dynamic device group in Microsoft Entra ID for Intune management? (Choose three.)
Hard418You manage Windows 10 devices with Microsoft Intune. You need to deploy Microsoft 365 Apps to a group of devices. You want to ensure that the apps receive updates automatically from the Microsoft 365 Apps update channel. What should you configure in the Microsoft 365 Apps app settings?
Easy419You manage a fleet of Windows 11 devices enrolled in Microsoft Intune. A security policy requires that devices be automatically marked as noncompliant if they have not checked in with Intune for more than 30 days. You need to configure this behavior with the least administrative effort. What should you do?
Medium420You manage a hybrid environment with Microsoft Intune and Microsoft Configuration Manager. You need to ensure that devices co-managed for Windows Update policies use Intune as the authoritative source for update deployments, while Configuration Manager continues to manage software updates. Which workload slider should you move to Intune?
Hard421A company wants to prevent corporate data from being copied from managed apps to personal apps on iOS devices. Which Intune policy should the administrator configure?
Easy422You are configuring Windows Update for Business policies in Microsoft Intune. You want to ensure that devices receive quality updates (security fixes) as soon as they are released, but defer feature updates for up to 60 days. Which TWO settings should you configure?
Easy423A user reports that Microsoft 365 Apps for enterprise is not installing on their Windows 10 device. The app is assigned as 'Available' to the user group. What must the user do to trigger the installation?
Easy424You are investigating a malware incident on a Windows 10 device managed by Microsoft Intune and protected by Microsoft Defender for Endpoint. Which log should you analyze to determine the initial infection vector?
Easy425You manage Windows 11 devices with Microsoft Intune. A security requirement states that when a device is marked as noncompliant, it must lose access to Microsoft 365 services within 15 minutes, but the device must not be wiped. You create a compliance policy and a conditional access policy. Which setting should you configure in the compliance policy to meet the time requirement?
Medium426A hospital uses Intune to manage Windows 10 devices used by doctors. The devices should automatically install critical updates from Windows Update for Business. Which type of policy should the administrator create?
Medium427Your organization uses Microsoft Intune to manage Windows 10 and Windows 11 devices. You need to ensure that BitLocker Drive Encryption is enabled on all devices and that the recovery keys are escrowed to Azure Active Directory (Azure AD). Which policy type should you use?
Easy428Order the steps to configure Windows Defender Antivirus exclusions via Group Policy.
Medium429You have the above JSON policy assigned to a Windows 10 device. A user reports that they are unable to set a password that meets the policy. Which additional setting is required for the password to be accepted?
Easy430A company uses Microsoft Intune to manage Windows 11 devices. Users report that the Company Portal app is not showing required applications. You verify that the devices show as 'Compliant' in Microsoft Intune. Which configuration should you check first?
Medium431Refer to the exhibit. You have applied this compliance policy to a Windows 10 device running build 10.0.19044. The device meets all requirements except that the firewall is disabled. What will be the compliance status of the device?
Medium432Refer to the exhibit. You are configuring a Windows Autopilot profile. The profile specifies enrollmentType as 'azureAdJoined'. Which scenario does this profile support?
Easy433Refer to the exhibit. A Microsoft Graph PowerShell cmdlet retrieves devices. What is the purpose of this query?
Medium434Your organization uses Microsoft Defender for Endpoint to manage device security. You need to ensure that all Windows devices are reporting security events to Microsoft Defender XDR. You have verified that the Microsoft Defender for Endpoint service is running on the devices. However, some devices show as 'inactive' in the Microsoft Defender XDR console. What is the most likely cause?
Hard435A company uses Microsoft Intune to manage macOS devices. They need to deploy a custom plist configuration file to set security settings. Which policy type should they use?
Medium436A company uses Microsoft Intune to manage Windows devices. The IT team needs to deploy a new Microsoft Store app (new) to a group of users. The app must install automatically when users sign in, and users must not be able to uninstall it. Which assignment type should you configure for the app?
Easy437Match each MDM (Mobile Device Management) enrollment method to its typical scenario.
Medium438A company uses Microsoft Intune to manage iOS devices. The administrator configures a device compliance policy that requires a minimum OS version of 15.0. Users report that devices running iOS 14.8 are marked non-compliant even after updating to iOS 15.0. What is the most likely cause?
Hard439Refer to the exhibit. The JSON snippet shows a device compliance policy for Windows 10. You assign this policy to a device group. Some devices report as noncompliant even though they have BitLocker enabled and meet password requirements. What is the most likely cause?
Hard440You manage Windows 10 and Windows 11 devices with Microsoft Intune. You need to configure a Windows Update ring to defer quality updates by 7 days and feature updates by 60 days. Which two settings should you configure in the update ring? (Choose two.)
Medium441Your organization uses Microsoft Intune to manage Windows 10 devices. You need to enforce BitLocker encryption on all devices. Some devices are not encrypting even though the policy is assigned. What should you check first?
Medium442You manage a group of Windows 11 devices enrolled in Microsoft Intune. You need to collect a list of installed applications from these devices and view the data in the Intune admin center. What should you configure?
Easy443You need to deploy a web link as an app to Android Enterprise work profile devices. Users should see the link in the Company Portal app. What type of app should you add in Microsoft Intune?
Easy444Your organization uses Microsoft Entra ID joined devices with Windows 10. You need to ensure that only compliant devices can access corporate email in Microsoft Outlook for Windows. Which integration should you enable?
Easy445You manage Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, users receive a notification email with instructions to remediate the issue. The email must be sent only to the primary user of the device. What should you configure?
Medium446A company is planning to implement Microsoft Intune for mobile device management. They want to ensure that only compliant devices can access Exchange Online. Which technology should they use?
Easy447You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?
Medium448You manage Windows 11 devices with Microsoft Intune. You need to configure a policy that will automatically lock the screen after 5 minutes of inactivity and require a password to unlock. Which policy type should you use?
Hard449You need to make a web app available to users in your organization through Microsoft Intune Company Portal. Which app type should you create in Intune?
Easy450You are deploying Windows 11 devices using Windows Autopilot. The devices must be joined to an on-premises Active Directory domain and also registered with Microsoft Entra ID. You need to configure the deployment profile. Which Autopilot mode should you use?
Hard451Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?
Medium452An administrator is troubleshooting why a Win32 app is repeatedly installed on a device. The exhibit shows a log snippet. What is the most likely cause of the repeated installation?
Hard453You manage a set of Windows 11 devices with Microsoft Intune. You deploy a Win32 app as required to a group of users. The app installs successfully, but later users report that the app is missing from their devices. You discover that the app was removed after a user uninstalled it manually. You need to ensure that the app is reinstalled automatically if it is removed. What should you configure?
Hard454You need to configure Microsoft Defender for Endpoint on macOS devices. Which THREE components must be installed?
Easy455You are troubleshooting an Intune-managed Windows 10 device that is not receiving a required application. Which THREE steps should you take to diagnose the issue? (Choose three.)
Medium456You are the administrator for a company that uses Microsoft Intune. You need to deploy a Windows 10 device configuration profile that configures a custom administrative template setting. The setting is not available in the built-in templates. You have the ADMX and ADML files for the setting. What should you do first?
Hard457You need to deploy a Win32 app to Windows devices using Intune. The app requires admin privileges to install. How should you configure the deployment?
Easy458Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?
Hard459Your organization uses Microsoft Intune to manage Android devices. You need to ensure that corporate data on these devices is protected in case the device is lost or stolen. You configure a compliance policy that requires device encryption and a device lock screen. However, you also want to be able to selectively wipe corporate data without wiping personal data. What should you do?
Easy460Your organization plans to deploy Windows Autopilot for new devices. You need to ensure that the hardware hashes are uploaded to Microsoft Intune before the devices are shipped to users. What is the recommended approach?
Medium461Which TWO are prerequisites for co-management with Microsoft Intune and Configuration Manager? (Select TWO.)
Easy462Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that devices cannot access corporate email if they are rooted. What should you configure?
Medium463You are deploying a line-of-business (LOB) app to iOS devices using Microsoft Intune. The app is signed with an enterprise certificate. Users report that the app installs but crashes immediately on launch. What is the most likely cause?
Easy464You manage devices in Microsoft Intune. You need to generate a report that shows which devices have not checked in with Intune for more than 30 days. What should you use?
Easy465A company uses Microsoft Intune to manage iOS devices. They need to ensure that only devices with a passcode of at least 6 characters can access corporate email. Which type of policy should they create?
Easy466You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?
Medium467Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a Microsoft 365 Apps for Enterprise to work profiles. Which app type should you select in Intune?
Easy468Your organization uses Microsoft Intune to manage Windows 11 devices. You deploy a Win32 app as required to a group of users. After deployment, users report the app shortcut is missing from the Start menu even though the app appears installed in the Company Portal. You review the app properties and confirm the install command succeeded. You need to ensure the shortcut appears for all users on each device. What should you configure?
Hard469Refer to the exhibit. You create a compliance policy for Windows 10 devices. A device is reported as non-compliant. Upon investigation, you find that the device has a password of 6 characters. Which setting is causing the non-compliance?
Medium470You are reviewing an Intune endpoint protection profile for Windows 10. The exhibit shows a JSON snippet of the configuration. A user reports that a device detected malware with moderate severity, but the action taken was 'quarantine'. However, the desired action is 'clean'. Which setting should you modify?
Medium471Which TWO actions should you take to ensure that only healthy Windows 10/11 devices can access Microsoft 365 services? (Choose two.)
Medium472Which TWO actions should you take to prepare a Windows 10 device for a deployment using Windows Autopilot?
Medium473You are an Endpoint Administrator for a company using Microsoft Intune. A Windows app (Win32) app has been deployed as Required to a pilot group of 20 devices. Reports show the app installed successfully on 18 devices but failed on 2 devices with the error 'The application was not detected after installation completed successfully.' You confirm the installer runs silently and exits with code 0 on the failing devices. What is the most likely cause?
Hard474Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a company portal app that allows users to enroll their devices. Which app type should you use?
Medium475A company uses Microsoft Intune to manage Windows 10 devices. They have a compliance policy that requires BitLocker to be enabled. Some devices are marked as non-compliant even though BitLocker appears to be on. The administrator runs 'manage-bde -status' on a non-compliant device and sees that the protection status is 'Protection Off'. What is the most likely cause?
Hard476You manage 500 Windows 11 devices with Microsoft Intune. Several devices are shared by multiple employees across shifts at a manufacturing plant. You need to configure a policy that automatically removes local user profiles that have not been used for 60 days to conserve disk space, while preserving profiles of users who sign in regularly. What should you configure?
Medium477You are deploying a Windows 11 device using Windows Autopilot. The device is enrolled in Microsoft Intune and assigned a device group. You need to ensure that during the out-of-box experience (OOBE), the device automatically joins Microsoft Entra ID and enrolls in Intune without user interaction. Which Autopilot deployment mode should you configure?
Hard478You are the endpoint administrator for Contoso, Ltd. The company uses Microsoft Intune and has a hybrid Microsoft Entra ID environment with an on-premises Active Directory Domain Services (AD DS) domain. You plan to deploy 200 new Windows 11 devices using Windows Autopilot. The devices must be joined to the on-premises AD DS domain and also registered in Microsoft Entra ID. You need to configure the Autopilot deployment profile to support this scenario. What should you do first?
Medium479Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to deploy a managed Google Play app to work profile devices. Which TWO configurations are required?
Easy480You manage a group of iOS devices enrolled in Microsoft Intune. Users report that they are unable to receive email on their devices after you deployed a new configuration profile. You need to identify the cause quickly. What should you use?
Easy481You use Microsoft Intune to manage macOS devices. You need to deploy a shell script that runs on all macOS devices. What is the correct method?
Medium482You run the PowerShell command to check the assignment of a Microsoft Store app in Intune. The output shows 'intent: required' and 'target: allDevicesAssignmentTarget'. Which statement is true about this app?
Hard483Your organization uses Microsoft Intune to manage iOS and Android devices. You need to ensure that corporate data on these devices is protected. Specifically, you want to prevent users from copying corporate data from managed apps to personal apps. You also want to ensure that when a device is lost or stolen, the corporate data can be selectively wiped without affecting personal data. Which Intune feature should you use to achieve these requirements?
Easy484You deploy a Win32 app via Intune to Windows 10 devices. The app installs successfully on some devices but fails on others with no error in the Intune console. The app logs show 'Access Denied' during installation. What should you check first?
Hard485Which TWO are valid methods to deploy Windows 10/11 using Microsoft Intune?
Medium486You manage a set of Windows 11 devices with Microsoft Intune. You need to configure attack surface reduction (ASR) rules to block Office applications from creating child processes. You want to ensure the rules are enforced and cannot be bypassed by users. Which Intune profile type should you use?
Hard487An Android device running OS version 9.0 with app version 1.5.0 is targeted by the app protection policy in the exhibit. What is the expected behavior when the user tries to access work data?
Medium488You are an endpoint administrator for a company that uses Microsoft Intune. You need to create a report that shows which devices have not checked in to Intune for more than 30 days. What should you use?
Easy489Refer to the exhibit. You run this KQL query in Microsoft Sentinel. What is the result?
Medium490A company uses Microsoft Intune to manage Windows 10 devices. Users report that a LOB app deployed as a required install fails to install on some devices. The app is configured with a dependency on another app. What should the administrator verify first?
Easy491Arrange the steps to troubleshoot a Windows 10 device failing to enroll in Microsoft Intune.
Medium492Your company uses Microsoft Intune to manage Windows 11 devices. You need to ensure that when a device is marked as noncompliant, it loses access to Microsoft 365 services within 15 minutes, without affecting compliant devices. You have already created a compliance policy and assigned it to all users. What should you configure next?
Hard493You are setting up Microsoft Intune for a new subsidiary. The subsidiary has an existing on-premises Active Directory Domain Services (AD DS) and uses Microsoft Entra Connect to synchronize users to Microsoft Entra ID. You need to enable automatic enrollment of Windows 10 devices into Intune for users who are synchronized from AD DS. What should you configure first?
Easy494Refer to the exhibit. You deploy this custom OMA-URI policy to Windows 10 devices. What is the expected outcome?
Easy495You manage Windows 11 devices with Microsoft Intune. After a Windows quality update is deployed to a pilot ring, several devices report installation failures in the Update reports. You need to identify the exact error code returned by the update installation on a specific device without accessing the device directly. What should you do?
Medium496You are troubleshooting a Windows 11 device that fails to install an Intune-managed update. The device has been offline for two weeks. After reconnecting, the update does not install. In the Intune console, the update shows 'Failed to install' with error code 0x800f0831. What is the most likely cause?
Hard497Your organization uses Microsoft Intune to manage devices. You need to collect diagnostic logs from a remote Windows device without user interaction. Which THREE methods can you use?
Hard498You manage Windows 10 devices with Microsoft Intune. You need to deploy a Win32 app named App1 that requires a specific command-line switch during installation. The app's installer is an .exe file that does not support silent installation by default. You must ensure the app installs without user interaction. What should you do?
Medium499You are a Microsoft 365 Endpoint Administrator. You need to remotely wipe a lost Windows 11 device that is enrolled in Microsoft Intune. The device is currently offline. What happens when you initiate a wipe action from the Intune admin center?
Easy500Your organization uses Microsoft Intune to manage Windows 10 devices. You need to create a compliance policy that requires devices to have a firewall enabled. Which setting should you configure?
Easy501You manage a fleet of Windows 10 devices with Microsoft Intune. You need to ensure that when a device is marked as noncompliant, it loses access to corporate email and Teams within 15 minutes. You have already configured a compliance policy and assigned it to all users. What should you do next to meet the requirement?
Hard502Your organization wants to use Microsoft Intune to manage Windows devices that are joined to an on-premises Active Directory domain. The devices will be hybrid Azure AD joined. Which tool should you use to configure automatic enrollment into Intune?
Easy503Your company uses Microsoft Intune to manage mobile devices. You need to ensure that corporate data on Android Enterprise work profiles is protected so that users cannot copy and paste data from work apps to personal apps. Which configuration should you implement?
Medium504An administrator needs to ensure that only devices with a specific manufacturer are allowed to enroll in Intune. Which setting should the administrator configure?
Easy505A user reports that a Microsoft 365 Apps for enterprise installation failed on their Windows 11 device managed by Intune. The Intune management extension logs show error code 0x80070005. The device is Azure AD joined and compliant. What is the most likely cause?
Hard506You are the endpoint administrator for a company that uses Microsoft Intune. The security team requires that all Windows 11 devices automatically receive an Intune device configuration profile that enforces a minimum PIN length of 8 for Windows Hello for Business. You need to ensure the profile is applied without user interaction. What should you do?
Medium507A company uses Microsoft Intune to manage Windows 10 devices. You need to deploy Microsoft 365 Apps to all Windows devices. The deployment must use the Microsoft 365 Apps wizard in Intune. What should you do?
Easy508Which THREE of the following are features of Microsoft Defender for Endpoint that help protect devices?
Medium509You are an endpoint administrator for a company that uses Microsoft Intune. The company has a Microsoft Entra ID tenant with Intune configured. You need to ensure that when new Windows 10 devices are set up by users, they are automatically enrolled in Intune and receive company policies. The devices are purchased from a reseller and are not domain-joined. You want to minimize user interaction during setup. What should you configure?
Easy510You are deploying a new line-of-business app to 500 Windows 11 devices using Microsoft Intune. The app requires a specific PowerShell script to run after installation to configure registry settings. You need to ensure the script runs only after the app is successfully installed and that it does not require user interaction. What should you do?
Medium511You need to wipe a lost corporate-owned Windows 10 device that is enrolled in Intune. Which action should you take?
Easy512You are configuring a Windows 10 kiosk device using Intune. The device should run a single-store app in full-screen mode. Which Intune policy type should you use?
Easy513You manage Windows 11 devices with Microsoft Intune. Security requires that when a device is marked as noncompliant, access to Microsoft 365 services is blocked within 5 minutes, even if the user is already signed in. You configure a Conditional Access policy that requires a compliant device. What else must you configure to achieve this near-real-time enforcement?
Medium514Match each Microsoft 365 Defender feature to its description.
Medium515A company uses Microsoft Intune to manage Windows 10 devices. The security team reports that several devices are missing critical security updates. You need to ensure that devices install updates within 7 days of release. What should you configure?
Medium516A user has an Android Enterprise fully managed device. The device is enrolled in Microsoft Intune and all policies are applied. However, the user cannot install a required app from the managed Play Store. The app appears in the company portal but fails to install. What should you check first?
Medium517Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to prevent users from installing apps from unknown sources on their personally-owned work profile devices. Which configuration profile type should you use?
Easy518Your company has 500 Windows 10 devices that are Hybrid Azure AD joined and managed by Microsoft Intune. You need to deploy a new line-of-business (LOB) app to all devices. The app is packaged as a .msi file. You create a new app in Intune and assign it to a device group containing all devices. After 24 hours, some devices report the app as 'Installed' but others show 'Failed'. You verify that the devices are online and have network connectivity. What should you do next to resolve the installation failures?
Easy519Which TWO Windows Update for Business policies can you configure using Microsoft Intune?
Hard520You are a Microsoft 365 Endpoint Administrator for a medium-sized company that uses Microsoft Intune to manage its Windows 10 devices. The company recently experienced a ransomware attack that encrypted local files on several devices. To mitigate future attacks, management wants to ensure that all devices have real-time protection enabled in Microsoft Defender Antivirus and that Controlled Folder Access is turned on. You need to configure these settings via Intune. You decide to create a device configuration profile for Windows 10. What is the most efficient way to deploy these settings to all existing and future devices?
Easy521Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate applications. Which TWO configurations should you implement?
Medium522Your organization uses Microsoft Intune to manage Windows 11 devices. You need to deploy a custom Windows security baseline that includes specific BitLocker settings. What is the best approach to create and assign this configuration?
Hard523Your organization uses Microsoft Intune to manage iOS and Android devices. You have a compliance policy that requires a minimum OS version: iOS 16.0 and Android 12.0. You also have a Conditional Access policy that requires compliant devices. Several users report that they cannot access corporate email on their personal Android devices. The devices are Android 11.0. You need to allow these users to access email while ensuring that corporate data is protected. What should you do?
Medium524Refer to the exhibit. You deploy this endpoint protection configuration to a Windows 10 device. A user reports that they cannot connect to the device via RDP. What is the most likely cause?
Hard525You are the endpoint administrator for a company using Microsoft Intune. The IT director asks you to generate a report that shows which Windows devices have not installed the latest security update in the past 14 days. What should you use?
Easy526You are managing devices with Microsoft Intune. You need to ensure that only compliant devices can access corporate email. Which TWO components should you configure?
Medium527You manage Windows 11 devices with Microsoft Intune. A line-of-business application must be deployed to a specific group of devices. The application installer requires administrative privileges and must run in the system context. You need to ensure the app installs silently without user interaction. What should you create?
Hard528You manage Windows devices with Microsoft Intune. A line-of-business Win32 app is deployed as Required to a device group. Users report the app never installs, and in the Intune console the app shows installation status 'Not applicable' for those devices. You confirm the app is assigned to the correct group and the devices are online and healthy. What is the most likely cause?
Medium529Your organization uses Microsoft Intune to manage macOS devices. You need to deploy a custom configuration profile that sets a specific firewall rule. However, the profile fails to apply on a subset of devices. The Intune console shows 'Conflict' status. What is the most likely cause?
Hard530You are deploying a Windows line-of-business app to Intune-managed devices using the Win32 app type. The app installer is a .msi file that must run silently. You need to ensure the app installs correctly and Intune can accurately report its status. Which two actions should you perform? (Choose two.)
Hard531You are the Intune administrator for Contoso Ltd., a company with 5,000 Windows 11 devices and 1,000 iOS devices managed by Microsoft Intune. The company uses Microsoft Defender for Endpoint for threat detection. You need to implement a solution that ensures devices are compliant before they can access corporate resources. You have the following requirements: 1. Windows devices must have Defender for Endpoint running and report a threat level of 'low' or better. 2. iOS devices must have a PIN of at least 6 characters and be jailbreak-detected as 'not jailbroken'. 3. If a device becomes noncompliant, it should be blocked immediately with no grace period. 4. Noncompliant devices should receive a notification to the user. You create compliance policies for Windows and iOS. You also create a conditional access policy in Microsoft Entra ID to require compliant devices. After deploying, you find that some Windows devices that are missing Defender for Endpoint are still able to access email. What should you do to resolve this issue?
Hard532An organization is moving from on-premises SCCM to Microsoft Intune for Windows app management. They need to ensure that users can self-install company portal apps without administrator intervention. Which configuration is required?
Medium533Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?
Hard534A company uses Microsoft Intune to manage Windows 11 devices. They want to ensure that only devices with a TPM 2.0 and Secure Boot enabled can access corporate resources in Microsoft Entra ID. What should they configure?
Easy535You are an administrator for a company that uses Microsoft Intune to manage Windows 10 devices. You need to deploy a new version of an internal line-of-business (LOB) app to all users. The app is packaged as an .msi file. What is the simplest way to deploy this app using Intune?
Easy536Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to ensure that all devices have a passcode of at least 6 characters and that devices are updated to the latest iOS version. You create a compliance policy. After assigning the policy, some devices are marked as non-compliant even though they have a passcode. What is the most likely cause?
Medium537Your organization uses Microsoft Intune to manage 1,000 Windows 10 devices and 500 iOS devices. You need to enforce device compliance policies. For Windows devices, you require BitLocker encryption and Windows Defender Antivirus enabled. For iOS devices, you require a passcode of at least 6 characters and device encryption. Devices that become noncompliant should be marked as such and users should receive a notification email. After 7 days of noncompliance, the device should be blocked from accessing corporate email. You also need to create a report that shows the compliance status of all devices. Which combination of actions should you take?
Medium538A company uses Microsoft Intune to manage iOS devices. They need to enforce a policy that requires a passcode of at least 6 characters, allows Touch ID, and automatically wipes the device after 10 failed attempts. Which three settings should be configured in a device restrictions profile for iOS? (Choose three.)
Medium539Your company uses Microsoft Intune to manage devices. You need to ensure that all corporate-owned iOS devices automatically enroll in Intune when users sign in with their work account. Which enrollment method should you configure?
Easy540You are the endpoint administrator for Contoso Ltd. The company uses Microsoft Intune to manage Windows 11 devices. You need to deploy a critical security update to all devices within 24 hours. The update is a quality update (KB5001234). You have created an update ring policy named 'Critical Ring' assigned to all devices. The policy currently has a deferral period of 7 days. You need to ensure that the update is installed immediately. What should you do?
Easy541A company uses Microsoft Intune to manage Windows devices. They want to deploy a custom line-of-business (LOB) app as a Win32 app. The app requires .NET Framework 4.8 and must be installed silently. Which file type should you use for the app deployment in Intune?
Medium542Your organization uses Microsoft Intune to manage devices. You need to configure a policy that automatically retires a device if it does not check in for 30 days. Which policy type should you configure?
Easy543You manage a hybrid Azure AD joined Windows 11 device with Microsoft Intune. You need to configure a device compliance policy that requires BitLocker drive encryption and Secure Boot to be enabled. Which two settings must you configure in the compliance policy? (Choose two.)
Hard544Your organization uses Microsoft Intune to manage devices. You need to ensure that only compliant devices can access corporate email. You configure a Conditional Access policy in Microsoft Entra ID targeting Exchange Online. What else must you configure in Intune to enforce compliance?
Medium545An organization is planning to implement a zero-trust security model. They need to evaluate the following capabilities in Microsoft 365. Which THREE are essential for a zero-trust architecture? (Choose three.)
Hard546Your organization needs to deploy a web app link to users' devices via Microsoft Intune. Which app type should you select?
Easy547Refer to the exhibit. You are reviewing an Intune management intent configuration. What does this setting configure on Windows devices?
Easy548Which THREE conditions must be met for a Windows 10 device to be co-managed with Microsoft Intune and Microsoft Configuration Manager? (Choose three.)
Hard549Your organization uses Microsoft Intune to manage Windows 11 devices. You need to ensure that only devices with a Trusted Platform Module (TPM) version 2.0 and Secure Boot enabled can access corporate email. What should you configure?
Medium550You manage Windows 10 devices with Microsoft Intune. You deploy a Win32 app that must run a custom installation script. The script requires a specific environment variable to be set during installation. The app installer does not set this variable. You need to ensure the variable is set only for the installation process and not permanently on the device. What should you do?
Hard551You are implementing Windows Autopilot for your organization. You need to ensure that during the first boot, the device automatically enrolls in Microsoft Intune and joins Microsoft Entra ID. What is the minimum requirement for the device?
Medium552You have assigned the compliance policy shown in the exhibit to all Windows devices. A Windows 11 device running build 10.0.22621.1500 reports as noncompliant. Which setting is causing the noncompliance?
Hard553Your organization uses Microsoft Intune to manage Android devices. You need to deploy an app that is available in the Managed Google Play store as a required app. What must you do first?
Easy554An administrator deploys a Win32 app via Intune with detection rule 'File exists: C:\Program Files\MyApp\app.exe'. The app is reported as installed, but users cannot launch it. The file exists but is corrupted. How should the administrator modify the detection rule to ensure the app is correctly detected and re-installed if corrupted?
Hard555Which TWO app types are available for deploying apps to iOS/iPadOS devices in Microsoft Intune? (Choose two.)
Easy556You manage a hybrid Azure AD joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)
HardOther domains
All MD-102 exam domains
Frequently asked questions
- What does the troubleshooting domain cover on the MD-102 exam?
- troubleshooting questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 556 troubleshooting questions in the MD-102 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only troubleshooting questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.