Courseiva

MD-102 Prepare infrastructure for devices Practice Question

You are a Microsoft 365 administrator for a company with 200 Windows 11 devices joined to Microsoft Entra ID. The security team requires that all devices automatically receive a set of configuration profiles and compliance policies without user intervention. You need to ensure that when devices are joined, they are automatically enrolled in Microsoft Intune and grouped for policy assignment. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse compliance policies or conditional access with enrollment mechanisms, assuming they automatically enroll devices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable automatic MDM enrollment in Microsoft Entra ID and configure dynamic device groups in Microsoft Intune.

Automatic MDM enrollment in Microsoft Entra ID ensures devices are enrolled in Intune upon join. Dynamic device groups in Intune automatically include devices based on attributes, enabling policy assignment without manual intervention. Together, they provide the required zero-touch provisioning and grouping.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable automatic MDM enrollment in Microsoft Entra ID and configure dynamic device groups in Microsoft Intune.

    Why this is correct

    Automatic MDM enrollment in Microsoft Entra ID ensures that any device joined to Entra ID is automatically enrolled in Intune without user action. Dynamic device groups based on attributes like deviceOSType or enrollmentProfileName allow policies to target devices automatically. This meets the requirement for zero-touch provisioning and grouping.

  • ✗

    Create a conditional access policy requiring compliant devices and assign it to all users.

    Why it's wrong here

    Conditional access policies enforce access controls based on device compliance but do not enroll devices or create groups. They require devices to already be enrolled and compliant. This does not achieve automatic enrollment or grouping for policy assignment.

  • ✗

    Deploy a Windows Autopilot deployment profile to all devices and use it to assign policies.

    Why it's wrong here

    Windows Autopilot profiles are used during initial device provisioning to customize the out-of-box experience. They do not automatically enroll already-joined devices or create dynamic groups. While Autopilot can trigger enrollment, it is not the mechanism for ongoing automatic enrollment of existing devices.

  • ✗

    Configure a device compliance policy with a grace period and assign it to All Users.

    Why it's wrong here

    A compliance policy evaluates device state but does not enroll devices into Intune or create groups. It also targets users, not devices, and without enrollment, devices won't receive the policy. This does not meet the requirement for automatic enrollment and grouping.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.