Courseiva
Manage applications →hardMultiple Select

Win32 App Detection Rule Types in Intune

Which FOUR of the following are valid detection rules for a Win32 app in Intune?

⚠ Common exam trap

Candidates may mistakenly think network share access is a valid detection rule, but it is not.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PowerShell script (custom detection)

Option A (PowerShell script / custom detection) is valid because Intune Win32 apps support a custom detection script whose exit code and stdout determine whether the app is considered installed. Option B (MSI product code) is valid because Intune can detect an installed app by matching its MSI product code in the Windows Installer database. Option C (Registry key or value exists) is valid because Intune's registry detection rule checks for a specified key/value (and can compare a value's string, integer, or version) to confirm installation. Option D (File system / file or folder exists) is valid because Intune's file/folder detection rule verifies existence (and optionally date, size, or version) of a specified path. Option E (Network share access) is not a supported Win32 app detection rule type in Intune, so it does not belong.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PowerShell script (custom detection)

    Why this is correct

    A PowerShell script used as a custom detection rule lets Intune evaluate arbitrary logic on the endpoint, satisfying the requirement for a valid Win32 app detection method. It returns an exit code and output that Intune interprets to confirm installation.

  • ✓

    MSI product code

    Why this is correct

    An MSI product code is a valid Win32 app detection rule in Intune, satisfying the requirement for four correct detection methods. Intune queries the product code registered in Windows Installer to confirm the app's presence, which reliably identifies MSI-installed applications without relying on file paths or registry keys.

  • ✓

    Registry (key or value exists)

    Why this is correct

    Registry detection checks whether a specified key or value exists on the device, satisfying the requirement for a valid Win32 app detection rule in Intune. It confirms installation state without relying on file paths, and supports both 32-bit and 64-bit registry hives, making it one of the four permitted rule types.

  • ✓

    File system (file or folder exists)

    Why this is correct

    A file or folder existence rule lets Intune confirm installation by checking a specific path the installer creates, such as the executable under Program Files. This detection method suits Win32 apps whose installer leaves a predictable artefact, satisfying the requirement for a valid detection rule type.

  • ✗

    Network share access

    Why it's wrong here

    Network share access is not a Win32 app detection rule type; Intune supports MSI product code, file or folder existence, registry key, and custom PowerShell script detection. It is tempting because many packaged apps read configuration from UNC paths, but detection must evaluate the endpoint itself, not a remote share's reachability.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.