Courseiva

MD-102 · topic practice

Manage and maintain devices practice questions

This domain covers day-to-day operations after enrollment: monitoring device and app status, applying compliance and configuration policies, running remote actions, and managing updates with Windows Update for Business and Autopilot. Questions are scenario-based, asking you to pick the correct Intune policy type, Defender XDR setting, or remote action for a stated outcome.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Manage and maintain devices

What the exam tests

What to know about Manage and maintain devices

Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.

Selecting Intune compliance, configuration, and device-retirement policy types for stated outcomes

Configuring Defender for Endpoint automatic investigation and response in the Microsoft Defender XDR portal

Applying iOS/iPadOS and Windows restriction settings such as passcode length, biometrics, and wipe thresholds

Reading policy JSON and interpreting settings like osMinimumVersion and remote actions such as wipe, retire, and fresh start

Watch out for

Common Manage and maintain devices exam traps

  • ▸Confusing compliance policies, which report and gate access, with configuration profiles, which actually enforce settings on the device.
  • ▸Choosing a manual remote action like Retire or Wipe when the requirement is an automated, scheduled policy.
  • ▸Assuming Defender for Endpoint automatic investigation is on by default instead of configured in the XDR portal settings.

Practice set

Manage and maintain devices questions

20 questions · select your answer, then reveal the explanation

Your organization manages Windows 10 and 11 devices using Microsoft Intune. Users report that after a recent update, the Microsoft Store for Business app 'Company Portal' fails to launch. You verify that the app is assigned as required to all devices. What should you do first to resolve the issue?

Your organization uses Microsoft Intune to manage Windows devices. You need to deploy a custom Line-of-Business (LOB) app that is signed with a certificate not trusted by the devices. The app must be available to users in the Company Portal. What should you do?

You need to ensure that Windows 10 devices in your organization receive the latest quality updates within 7 days of release. You configure a Windows Update for Business policy in Intune with a deferral period of 7 days. After two weeks, some devices have not installed the updates. What is the most likely reason?

You need to implement a solution that automatically wipes a company-owned Windows 10 device when it has not connected to Intune for 30 days. Which Intune feature should you configure?

A user reports that after resetting their Windows 10 device, they cannot re-enroll it in Intune. The device appears as 'Pending' in the admin center. What is the most likely reason?

Which TWO actions can you take to improve the performance of Microsoft Intune management for Windows devices that are geographically distributed and have limited bandwidth?

Which THREE conditions must be met for a Windows 10 device to be able to use Windows Autopilot self-deploying mode?

Which TWO methods can you use to deploy Microsoft 365 Apps to Windows 10 devices managed by Intune?

Refer to the exhibit. You deploy this compliance policy to a Windows 11 device running OS version 10.0.22621.100. The device has a password set, firewall active, and Defender enabled. However, the device is marked as non-compliant. What is the most likely reason?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Device compliance policy for Windows 10 devices",
  "displayName": "Windows 10 Compliance Policy v2",
  "passwordRequired": true,
  "passwordMinimumLength": 8,
  "passwordRequiredType": "deviceDefault",
  "passwordMinutesOfInactivityBeforeLock": 15,
  "storageRequireEncryption": true,
  "activeFirewallRequired": true,
  "defenderEnabled": true,
  "defenderVersion": "4.18.2207.7",
  "osMinimumVersion": "10.0.19042.0",
  "osMaximumVersion": "10.0.22621.0"
}

Refer to the exhibit. You apply this device configuration profile to a group of Windows 10 devices. Users report that they receive update notifications outside of active hours. Which setting should you modify to suppress notifications during active hours?

Exhibit

{
  "@odata.type": "#microsoft.graph.windows10GeneralConfiguration",
  "displayName": "Windows 10 Security Baselines",
  "privacy": {
    "advertisingId": "disabled",
    "enableEnhancedSafeguards": true
  },
  "defender": {
    "detectionFrequency": 2,
    "realTimeProtection": true,
    "cloudBlockLevel": "high"
  },
  "windowsUpdate": {
    "activeHoursStart": "08:00",
    "activeHoursEnd": "17:00",
    "updateNotificationLevel": "defaultNotifications"
  }
}

Your organization uses Microsoft Intune to manage Windows 10 devices. Users report that after a recent update, some devices are no longer receiving compliance policies. You verify that the devices are enrolled and show as active in Intune. What should you check first?

A company uses Microsoft Intune to manage iOS devices. They need to ensure that corporate data on these devices is protected if a device is lost or stolen. The solution must allow users to continue using personal apps and data after a selective wipe. What should they configure?

You are managing Windows 10 devices with Intune. You need to deploy a PowerShell script that runs under the system context during device enrollment. Which approach should you use?

A company uses Microsoft Intune to manage Windows 10 devices with a hybrid Azure AD join configuration. Users report that they are unable to access corporate resources on their devices. You verify that the devices are enrolled and that compliance policies are applied. What should you check next?

You need to enforce encryption on Windows 10 devices managed by Intune. Which policy type should you configure?

Your organization uses Microsoft Intune to manage Android Enterprise devices. You need to ensure that only approved corporate apps can be installed on work profiles. What should you configure?

A user has an iOS device enrolled in Intune. The device is lost, and you need to immediately prevent unauthorized access to corporate data. The device contains both corporate and personal data. Which action should you take?

Your organization uses Microsoft Intune to manage Windows 10 devices. You need to deploy a PowerShell script that runs in the user context on a schedule. Which TWO methods can you use? (Choose two.)

Which THREE are valid device management actions in Microsoft Intune? (Choose three.)

Refer to the exhibit. You have created the compliance policy shown in JSON format. The policy is assigned to a group containing Windows 10 devices. A device running Windows 10 version 22H2 (build 22621.1) is showing as noncompliant. What is the most likely reason?

Exhibit

Refer to the exhibit.
{
  "@odata.type": "#microsoft.graph.windows10CompliancePolicy",
  "description": "Windows 10 compliance policy",
  "passwordRequired": true,
  "passwordMinimumLength": 6,
  "passwordRequiredType": "deviceDefault",
  "osMinimumVersion": "10.0.19041.0",
  "osMaximumVersion": "10.0.22621.0",
  "storageRequireEncryption": true
}

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Manage and maintain devices sessions

Start a Manage and maintain devices only practice session

Every question in these sessions is drawn from the Manage and maintain devices domain — nothing else.

Related practice questions

Related MD-102 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the MD-102 exam test about Manage and maintain devices?
Be able to map a required outcome to the correct Intune policy type or Defender XDR setting, and to run the right remote action. The most important thing is distinguishing compliance policies from configuration profiles and knowing which one enforces versus reports.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Manage and maintain devices questions in a focused session?
Yes — the session launcher on this page draws every question from the Manage and maintain devices domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other MD-102 topics?
Use the topic links above to move to related areas, or go back to the MD-102 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the MD-102 exam covers. They are not copied from any real exam or dump site.