Courseiva
← Back to Microsoft 365 Endpoint Administrator MD-102 questions

Scenario-based practice

Hard Difficulty Questions

Practise Microsoft 365 Endpoint Administrator MD-102 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

20
scenario questions
MD-102
exam code
Microsoft
vendor

Scenario guide

How to approach hard difficulty questions

These are the questions most candidates get wrong. They require connecting multiple concepts, reading tricky output, or knowing edge-case behaviour that isn't on most study cards. Practising them trains you to operate under uncertainty — a necessary skill on the real exam.

Quick answer

Hard Difficulty Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related MD-102 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

Your organization uses Microsoft Defender for Endpoint. You need to configure automatic investigation and response for devices. Which setting in the Microsoft Defender XDR portal should you adjust?

Question 2hardmulti select
Full question →

Which TWO of the following are valid reasons to use Windows Autopilot Reset? (Select TWO.)

Question 3hardmultiple choice
Full question →

Your organization uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data on these devices is automatically removed when a user is unenrolled from Intune. Which action should you configure?

Question 4hardmultiple choice
Full question →

You are troubleshooting a Windows 11 device that fails to receive a PowerShell script deployed via Intune. The script is assigned to a group containing the device. Other policies on the device apply successfully. What should you check first?

Question 5hardmultiple choice
Full question →

You are troubleshooting a Windows 10 device that is enrolled in Microsoft Intune. The device shows as 'Pending' in the Intune console. The user confirms that the device was enrolled using a provisioning package. Which log file should you review to diagnose the enrollment failure?

Question 6hardmultiple choice
Full question →

You are planning a Windows 11 deployment using Microsoft Intune. The organization has a requirement that all devices must have BitLocker enabled with a TPM protector. You configure a BitLocker policy in Intune. However, some devices report that BitLocker is not enabled. What is the most likely reason?

Question 7hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Require BitLocker and Secure Boot",
  "deviceThreatProtectionEnabled": true,
  "deviceThreatProtectionRequiredSecurityLevel": "medium",
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "osMinimumVersion": "10.0.19042.0"
}
Question 8hardmultiple choice
Full question →

You are troubleshooting a Windows 11 device that fails to install a required application from the Company Portal. The app is assigned as required to the device. The device shows as compliant and has a healthy connection. What is the most likely cause?

Question 9hardmultiple choice
Full question →

You are designing a Windows Update for Business deployment for a hybrid environment with 5,000 devices. You need to ensure that critical security updates are deployed within 48 hours while allowing feature updates to be delayed up to 60 days. Which policy configuration should you use?

Question 10hardmultiple choice
Full question →

A company uses Microsoft Intune for mobile device management. They have a group of Android Enterprise devices that need to be enrolled in a way that allows the device to have a work profile while keeping personal apps separate. Which enrollment method should be used?

Question 11hardmultiple choice
Full question →

You are troubleshooting an issue where Windows 10 devices are not receiving Windows updates from Intune. The update rings are configured, and the devices are enrolled. However, devices show 'Up to date' even though they are missing critical security updates. What should you verify?

Question 12hardmultiple choice
Full question →

Your organization uses Microsoft Defender for Endpoint (MDE) and Microsoft Intune. You need to create a device group that dynamically includes all devices with a threat level of 'High' from MDE. You then plan to apply a compliance policy to force those devices to be non-compliant. Which method should you use to create the dynamic group?

Question 13hardmultiple choice
Full question →

Your organization uses Microsoft Defender for Endpoint (now part of Microsoft Defender XDR) to manage device threat detection. You have integrated Defender for Endpoint with Intune for compliance. Some devices are showing as non-compliant due to 'active threats' that are actually low-risk. How can you adjust the compliance policy to allow low-risk threats?

Question 14hardmultiple choice
Full question →

Refer to the exhibit. You apply this configuration profile to Windows 10 devices. A user reports that their device's diagnostic data level is set to 'Full' in Settings > Diagnostics & feedback. What is the most likely reason?

Exhibit

Refer to the exhibit.

```json
{
  "microsoft365BusinessVoice": {
    "@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
    "telemetryLevel": "1 - Basic",
    "enableDeviceManufacturer": "Contoso",
    "enableDeviceModel": "Surface Pro 7",
    "enableDeviceName": "LAPTOP-01",
    "enableDeviceOSVersion": true,
    "enableDeviceOSBuild": true,
    "enableDeviceSerialNumber": true,
    "enableDeviceIMEI": null
  }
}
```
Question 15hardmultiple choice
Full question →

Your organization uses Windows Autopilot for device deployment. After a device completes the user-driven deployment, it appears in Microsoft Entra ID as 'Azure AD registered' instead of 'Azure AD joined'. What should you modify to ensure the device is joined?

Question 16hardmultiple choice
Full question →

Refer to the exhibit. A Windows 10 device with OS build 10.0.19041.1 is evaluated against this compliance policy. The device meets all settings except one: the OS version is 10.0.19041.1, which is below the minimum 10.0.19041.0? Actually it is above. But wait, the device has BitLocker enabled, Secure Boot enabled, and firewall enabled. Which setting will cause the device to be non-compliant?

Exhibit

Refer to the exhibit.

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "passwordRequired": true,
  "passwordMinimumLength": 6,
  "passwordRequiredType": "deviceDefault",
  "passwordMinutesOfInactivityBeforeLock": 5,
  "passwordExpirationDays": 90,
  "passwordPreviousPasswordBlockCount": 5,
  "requireHealthyDevice": false,
  "osMinimumVersion": "10.0.19041.0",
  "osMaximumVersion": "10.0.19043.0",
  "mobileOsMinimumVersion": null,
  "mobileOsMaximumVersion": null,
  "earlyLaunchAntiMalwareDriverEnabled": true,
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "codeIntegrityEnabled": true,
  "storageRequireEncryption": true,
  "activeFirewallRequired": true,
  "defenderEnabled": true,
  "defenderVersion": "1.1.1800.0",
  "signatureOutOfDate": false,
  "rtpEnabled": true
}
Question 17hardmultiple choice
Full question →

You manage a fleet of iOS devices enrolled in Microsoft Intune. You need to ensure that only approved corporate devices can access Exchange Online. You configure a Conditional Access policy that requires devices to be compliant with Intune compliance policies. However, some users report that they are still able to access email from personal iOS devices that are not enrolled. What should you check first?

Question 18hardmultiple choice
Full question →

Your organization uses Microsoft Intune to manage Windows 11 devices. You notice that some devices are not receiving security updates even though update rings are assigned. What is the most likely cause?

Question 19hardmultiple choice
Full question →

Your organization uses Microsoft Intune to manage iOS/iPadOS devices. You need to enforce that all devices use a 6-digit passcode and that the device automatically wipes after 10 failed attempts. Which profile type should you configure?

Question 20hardmultiple choice
Full question →

A company uses Microsoft Intune to manage Windows 10 devices. They have a compliance policy that requires BitLocker to be enabled. Some devices are marked as non-compliant even though BitLocker appears to be on. The administrator runs 'manage-bde -status' on a non-compliant device and sees that the protection status is 'Protection Off'. What is the most likely cause?

These MD-102 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style MD-102 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.