Courseiva

MD-102 Manage and maintain devices Practice Question

You are an administrator for Microsoft Intune. You need to ensure that when a Windows 11 device is enrolled, it automatically receives a set of configuration settings that apply to all users of the device. The settings must be applied before the user signs in. What should you create?

⚠ Common exam trap

Many exam-takers confuse device configuration profiles with compliance policies or user-targeted scripts, which do not apply settings at the device level before sign-in.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A device configuration profile assigned to the device group.

Device configuration profiles are the correct choice because they are designed to apply settings to devices and can be targeted to device groups. When assigned to a device group, they are processed during enrollment and apply to the device itself, ensuring settings are in place before any user signs in. This meets the requirement of applying settings that affect all users of the device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A PowerShell script deployed to the user group.

    Why it's wrong here

    PowerShell scripts in Intune are deployed to devices and can run in the user or system context. If deployed to a user group, they run when the user signs in, not before. To run before sign-in, you would need to target the device group and run in system context. This option does not guarantee application before user sign-in.

  • ✗

    An app configuration policy assigned to the user group.

    Why it's wrong here

    App configuration policies provide settings for specific apps, such as Outlook or Edge, not for general device settings. They are delivered when the app is launched and are not applied at the device level before sign-in. They cannot enforce device-wide configuration settings.

  • ✗

    A compliance policy assigned to the user group.

    Why it's wrong here

    Compliance policies evaluate device state and are assigned to users or devices, but they do not apply configuration settings. They only determine compliance and can trigger actions. They do not push settings to the device before sign-in. Therefore, they cannot fulfill the requirement of applying configuration settings.

  • ✓

    A device configuration profile assigned to the device group.

    Why this is correct

    Device configuration profiles are applied to devices and can be targeted to device groups. They are processed during enrollment and can apply settings before user sign-in, especially if they are assigned to the device. This ensures that the settings are in place regardless of which user signs in, meeting the requirement.

Go deeper

Related to this question

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.