Courseiva
← Back to Microsoft 365 Endpoint Administrator MD-102 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise Microsoft 365 Endpoint Administrator MD-102 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
MD-102
exam code
Microsoft
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related MD-102 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Full question →

Refer to the exhibit. You deploy this custom OMA-URI policy to Windows 10 devices. What is the expected outcome?

Exhibit

Refer to the exhibit.

Exhibit (Intune JSON configuration policy snippet):
{
  "@odata.type": "#microsoft.graph.windows10CustomConfiguration",
  "omaSettings": [
    {
      "@odata.type": "#microsoft.graph.omaSettingString",
      "displayName": "Disable Telemetry",
      "description": null,
      "omaUri": "./Device/Vendor/MSFT/Policy/Config/System/AllowTelemetry",
      "value": "0"
    }
  ]
}
Question 2hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing a Windows 10 compliance policy JSON. What is the purpose of the 'osMinimumVersion' setting?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Require BitLocker and Secure Boot",
  "deviceThreatProtectionEnabled": true,
  "deviceThreatProtectionRequiredSecurityLevel": "medium",
  "bitLockerEnabled": true,
  "secureBootEnabled": true,
  "osMinimumVersion": "10.0.19042.0"
}
Question 3mediummultiple choice
Full question →

Refer to the exhibit. You run the PowerShell command above to get a list of noncompliant devices. The output shows that some devices have a complianceGracePeriodExpirationDateTime in the past. What does this indicate?

Exhibit

Get-DeviceManagement_ManagedDevices | Where-Object {$_.complianceState -eq 'noncompliant'} | Select-Object deviceName, lastSyncDateTime, complianceGracePeriodExpirationDateTime
Question 4mediummultiple choice
Full question →

Refer to the exhibit. You run the PowerShell command shown to create a compliance policy. However, when you check the compliance status of a Windows 11 device, it shows as compliant even though the device does not have BitLocker enabled. What is the most likely reason?

Exhibit

New-IntuneCompliancePolicy -DisplayName "Windows 11 Compliance" -Platform Windows10AndLater -PasswordRequired $true -PasswordMinimumLength 8 -PasswordRequiredType DeviceDefault -PasswordMinutesOfInactivityBeforeLock 15 -PasswordExpirationDays 90 -PasswordPreviousPasswordCountToBlock 5 -SecureBootEnabled $true -CodeIntegrityEnabled $true -EarlyLaunchAntimalwareDriverProtectionEnabled $true -BitLockerEnabled $true -BitLockerRecoveryPasswordRotation Disabled -TpmRequired $true
Question 5hardmultiple choice
Full question →

Refer to the exhibit. You deploy this compliance policy to Windows 10 devices. A device reports as compliant, but you suspect it may have a weak password policy because the password type is 'deviceDefault'. What is the effect of 'deviceDefault' on the password requirement?

Exhibit

Refer to the exhibit.

Exhibit (Intune JSON policy snippet):
{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Company compliance policy",
  "passwordRequired": true,
  "passwordMinimumLength": 8,
  "passwordRequiredType": "deviceDefault",
  "passwordMinutesOfInactivityBeforeLock": 15,
  "passwordExpirationDays": 90,
  "passwordPreviousPasswordBlockCount": 5,
  "requireHealthyUntrustedEndorsementCertificate": false,
  "requireHealthyTrustedEndorsementCertificate": false,
  "tpmRequired": false,
  "secureBootEnabled": true,
  "codeIntegrityEnabled": true,
  "earlyLaunchAntiMalwareDriverEnabled": true,
  "deviceThreatProtectionEnabled": false,
  "deviceThreatProtectionRequiredSecurityLevel": "unavailable",
  "configurationManagerComplianceRequired": false
}
Question 6mediummultiple choice
Full question →

Refer to the exhibit. A Microsoft Intune security baseline is configured for Windows 10 devices. What is the effect of this setting?

Exhibit

{
  "displayName": "Windows 10 Security Baseline",
  "settings": [
    {
      "settingInstance": {
        "@odata.type": "#microsoft.graph.deviceManagementConfigurationSettingInstance",
        "settingDefinitionId": "device_vendor_msft_policy_config_windowsdefender_scan_enablelowcpupriority",
        "settingInstanceTemplateReference": null,
        "choiceSettingInstance": {
          "choiceSettingValue": {
            "value": "device_vendor_msft_policy_config_windowsdefender_scan_enablelowcpupriority_1",
            "children": []
          }
        }
      }
    }
  ]
}
Question 7hardmultiple choice
Full question →

Refer to the exhibit. You are reviewing an Intune configuration profile JSON for Windows 10. The profile includes BitLocker settings. Which setting will prevent users from enabling BitLocker if another encryption method is already in use?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
  "id": "00000000-0000-0000-0000-000000000000",
  "displayName": "Windows 10 Security Baseline",
  "description": "Custom security settings",
  "passwordRequired": true,
  "passwordMinimumLength": 8,
  "passwordExpirationDays": 90,
  "passwordPreviousPasswordBlockCount": 5,
  "passwordRequiredType": "alphanumeric",
  "passwordSignInFailureCountBeforeReset": 10,
  "passwordBlockSimple": true,
  "bitLockerEncryptionMethod": "aes256",
  "bitLockerDisableWarningForOtherDiskEncryption": false
}
Question 8hardmultiple choice
Full question →

Refer to the exhibit. An administrator runs this Graph PowerShell script. What is the purpose?

Exhibit

Refer to the exhibit.

$devices = Get-MgDeviceManagementManagedDevice -Filter "operatingSystem eq 'Windows'"
foreach ($device in $devices) {
  if ($device.deviceEnrollmentType -eq 'windowsAzureADJoin') {
    Write-Output $device.id
  }
}
Question 9hardmultiple choice
Full question →

Refer to the exhibit. You are deploying a custom OMA-URI policy to Windows 10 devices. What is the effect of this policy?

Exhibit

Refer to the exhibit.

{
  "@odata.type": "#microsoft.graph.windows10ConfigurationPolicy",
  "displayName": "Custom Policy",
  "omaSettings": [
    {
      "@odata.type": "#microsoft.graph.omaSettingString",
      "displayName": "Enable telemetry",
      "description": null,
      "omaUri": "./Vendor/MSFT/Policy/Config/System/AllowTelemetry",
      "value": "2"
    },
    {
      "@odata.type": "#microsoft.graph.omaSettingString",
      "displayName": "Disable Cortana",
      "description": null,
      "omaUri": "./Vendor/MSFT/Policy/Config/Experience/AllowCortana",
      "value": "0"
    }
  ]
}
Question 10hardmultiple choice
Full question →

Refer to the exhibit. You have assigned the above Enrollment Status Page (ESP) policy to a Windows Autopilot deployment. A user reports that the provisioning process hangs on 'Installing apps' and never completes. What is the most likely cause?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10EnrollmentCompletionPageConfigurationPolicy",
  "id": "00000000-0000-0000-0000-000000000000",
  "displayName": "ESP for Autopilot",
  "description": "Required apps must install",
  "showInstallationProgress": true,
  "blockDeviceSetupRetryByUser": true,
  "allowDeviceResetOnInstallFailure": false,
  "trackInstallProgressForAutopilotOnly": true,
  "selectedMobileAppIds": [
    "App1",
    "App2"
  ]
}
Question 11mediummultiple choice
Full question →

Refer to the exhibit. You run the PowerShell cmdlet in Microsoft Graph to list managed Windows devices. The output shows that several devices have a complianceState of 'noncompliant' but lastSyncDateTime is recent. What is the most likely reason for noncompliance?

Exhibit

Get-MgDeviceManagementManagedDevice -Filter "operatingSystem eq 'Windows'" | Select-Object id, deviceName, complianceState, lastSyncDateTime
Question 12hardmultiple choice
Full question →

You apply the custom policy shown in the exhibit to a Windows 11 device. Users report that they cannot use Bluetooth devices (e.g., mouse, keyboard) after the policy applies. Which setting in the policy is causing this issue?

Exhibit

Refer to the exhibit.

{
  "@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
  "displayName": "Windows 11 Security Baseline",
  "description": "Custom security settings",
  "passwordRequire": true,
  "passwordMinimumLength": 10,
  "passwordExpirationDays": 90,
  "passwordPreviousPasswordBlockCount": 24,
  "passwordMinutesOfInactivityBeforeScreenTimeout": 15,
  "allowCopyPaste": false,
  "allowCamera": false,
  "allowBluetooth": false,
  "allowVPNOverCellular": false,
  "allowStorageCard": false,
  "allowWiFi": true
}
Question 13hardmultiple choice
Full question →

Refer to the exhibit. You deploy this endpoint protection configuration to a Windows 10 device. A user reports that they cannot connect to the device via RDP. What is the most likely cause?

Exhibit

Refer to the exhibit.

```json
{
  "@odata.type": "#microsoft.graph.windows10EndpointProtectionConfiguration",
  "firewallRules": [
    {
      "@odata.type": "#microsoft.graph.windowsFirewallRule",
      "displayName": "Allow RDP",
      "direction": "inbound",
      "protocol": "tcp",
      "localPortRanges": ["3389"],
      "action": "block"
    }
  ],
  "defenderDetectedMalwareActions": {
    "highSeverity": "block",
    "moderateSeverity": "clean",
    "lowSeverity": "allow"
  }
}
```
Question 14mediummultiple choice
Full question →

Refer to the exhibit. You run a PowerShell command to check the assignment status of device configuration profiles. The 'BitLocker Policy' shows 'Pending'. What does 'Pending' indicate?

Exhibit

Refer to the exhibit.

Exhibit (PowerShell output from Get-MgDeviceManagementDeviceConfiguration):
Id                                   DisplayName             AssignmentStatus
--                                   -----------             ----------------
d36f8c2a-1234-5678-9abc-def012345678 Windows Defender AV     Success
b7a1c3d4-5678-90ab-cdef-1234567890ab BitLocker Policy        Pending
f8e7d6c5-4321-0fed-cba9-876543210abc Firewall Rules          Error
Question 15mediummultiple choice
Full question →

An Android device running OS version 9.0 with app version 1.5.0 is targeted by the app protection policy in the exhibit. What is the expected behavior when the user tries to access work data?

Exhibit

Refer to the exhibit.

Intune app protection policy JSON:
```json
{
  "AppProtectionPolicy": {
    "@odata.type": "#microsoft.graph.androidManagedAppProtection",
    "displayName": "Android Policy",
    "description": "Policy for Android devices",
    "periodOfflineBeforeAccessCheck": "PT12H",
    "periodOnlineBeforeAccessCheck": "PT30M",
    "allowedDataStorageLocations": ["sharePoint", "oneDriveForBusiness"],
    "exemptedAppPackages": [],
    "minimumRequiredAppVersion": "1.0.0",
    "minimumRequiredOSVersion": "9.0",
    "minimumWarningAppVersion": "2.0.0",
    "minimumWarningOSVersion": "10.0",
    "appDataEncryptionType": "whenDeviceLocked",
    "managedBrowser": "microsoftEdge",
    "deployedAppCount": 2
  }
}
```

These MD-102 practice questions are part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style MD-102 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.