Intune Proactive Remediations: Automating Issue Detection and Fix
Which THREE actions are available in Microsoft Intune's proactive remediations for Windows devices?
Quick Answer
The answer is running a remediation script to fix issues, which is one of the three core actions available in Intune proactive remediations for Windows devices. This is correct because proactive remediations operate as a two-script workflow: a detection script first scans the device for specific problems—like registry misconfigurations or missing files—and returns an exit code; if that code signals an issue, the remediation script automatically executes to resolve it without user intervention. On the Microsoft 365 Endpoint Administrator MD-102 exam, this concept tests your understanding of how Intune shifts from reactive to automated issue detection and fix, often appearing in scenario-based questions where you must choose the correct sequence. A common trap is confusing detection scripts with remediation scripts—remember, detection only identifies, remediation actually fixes. For a memory tip, think “Detect then Correct” to recall that the detection script must run first and return a non-zero exit code before the remediation script triggers.
⚠ Common exam trap
Many candidates confuse proactive remediations with compliance policies or alerting features, assuming that failed remediation can automatically trigger non-compliance or email notifications, but Intune separates these functions into distinct policies and requires additional configuration for alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run a detection script to identify issues.
Proactive remediations in Microsoft Intune are built on a two-part script package, so option A is correct: each remediation includes a detection script that runs first to identify whether a problem exists on the Windows device. Option D is also correct because, when the detection script reports a non-compliant state, the paired remediation script executes to fix the identified issue. Option C is correct as well, since proactive remediations are assigned to device groups and run on a configurable schedule (for example, daily or hourly) rather than only once. Option B is not part of proactive remediations, as Intune does not send email alerts as a built-in remediation action; reporting is surfaced through Intune reports and Endpoint Analytics. Option E is incorrect because proactive remediations do not change device compliance state — compliance is governed separately by compliance policies, and remediation scripts only detect and fix issues.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run a detection script to identify issues.
Why this is correct
Detection scripts execute first to assess device state, returning exit code 0 for compliant or non-zero for non-compliant, which triggers the paired remediation script. This satisfies the stem's requirement for actions available in proactive remediations, where detection is the mandatory first stage before any corrective action runs on the Windows device.
- ✗
Send email alerts when issues are detected.
Why it's wrong here
Proactive remediations execute detection and remediation scripts on a schedule and surface results in reports; they contain no notification engine for emailing alerts. It is tempting because alerting on detected issues is a common monitoring need, but that capability sits in Intune's endpoint analytics or alert rules, not in remediations.
- ✓
Schedule scripts to run at regular intervals.
Why this is correct
Proactive remediations comprise detection and remediation script pairs that Intune runs on a recurring schedule, satisfying the requirement for automated, repeatable execution. The schedule is configured when assigning the script to device groups, with a defined interval and optional grace period before remediation triggers.
- ✓
Run a remediation script to fix issues.
Why this is correct
Remediation scripts execute on the device after detection scripts report non-compliance, applying the fix automatically. This action satisfies the requirement to correct detected issues without manual intervention, forming the second half of the proactive remediation pair alongside detection scripts.
- ✗
Mark devices as non-compliant if remediation fails.
Why it's wrong here
Proactive remediations run detection and remediation scripts, then report results; they cannot change device compliance state, which Intune compliance policies govern. It is tempting because failed remediation signals a problem, but marking non-compliance belongs to conditional access and compliance policy evaluation, not the remediation engine.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Compliance state
Compliance state is the current status of a system, application, or device indicating whether it meets a defined set of security policies, regulatory requirements, or configuration standards.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MD-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions can you perform in Microsoft Intune to remediate a noncompliant Windows device that has been marked as noncompliant due to missing antivirus? (Choose two.)
medium- A.Send a sync command to the device to re-evaluate compliance.
- ✓ B.Deploy a proactive remediation script to detect and install antivirus.
- C.Send a notification to the user to install antivirus via Windows Security.
- ✓ D.Run a PowerShell script from Intune to install the missing antivirus.
- E.Create a Conditional Access policy to block the device until fixed.
Why B: Option B is correct because proactive remediations in Intune pair a detection script with a remediation script that runs on the device, so you can detect missing antivirus and automatically install it to bring the device back into compliance. Option D is correct because running a PowerShell script from Intune (via a platform script or device script) lets you execute installation commands for the missing antivirus directly on the Windows device. Option A is not a remediation action; a sync only forces the device to check in and re-evaluate policy/compliance, which does not install antivirus. Option C merely notifies the user and relies on manual action, so it does not remediate the device automatically. Option E is a Conditional Access policy that blocks access rather than fixing the noncompliance, so it is not a remediation action.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.