MD-102 Prepare infrastructure for devices Practice Question
You are an endpoint administrator for a company that uses Microsoft Intune. The company has a group of Windows 10 devices that are enrolled in Intune and are also co-managed with Configuration Manager. You need to configure a device configuration profile that applies a custom Start menu layout to these devices. You want to ensure that the profile is applied only to the co-managed devices and not to devices managed solely by Intune. What should you do?
⚠ Common exam trap
The trap here is assuming that scope tags can be used to target policies to specific devices, when in fact they are for administrative scoping, not device targeting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a device configuration profile in Intune and assign it to a device group that contains only the co-managed devices.
The most straightforward way to target a configuration profile to a specific set of devices is to assign it to a device group containing those devices. Creating a group with only the co-managed devices and assigning the profile to that group ensures the policy applies exclusively to them. Other methods like scope tags or user groups do not provide the same precise device targeting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a device configuration profile in Intune and use a scope tag to target only the co-managed devices.
Why it's wrong here
Scope tags are used for role-based access control and to filter what administrators can see and manage, not to target policies to specific devices. While scope tags can be assigned to policies, they do not determine which devices receive the policy. Device assignment is done through groups. Therefore, using scope tags would not restrict the profile to co-managed devices and could lead to unintended application.
- ✗
Create a device configuration profile in Intune and assign it to a user group that contains users of the co-managed devices.
Why it's wrong here
Assigning a device configuration profile to a user group is possible, but it would apply the profile to all devices used by those users, including non-co-managed devices. Since the requirement is to target only co-managed devices, this approach is too broad. User-based assignment does not distinguish between co-managed and Intune-only devices, so it does not meet the requirement.
- ✓
Create a device configuration profile in Intune and assign it to a device group that contains only the co-managed devices.
Why this is correct
In Intune, you can assign a device configuration profile to a specific device group. By creating a group that contains only the co-managed devices, you ensure the profile applies only to them. This is the simplest and most direct method. It does not require any additional filtering or complex configuration, and it works regardless of the workload settings, as long as the devices are in the group.
- ✗
Create a device configuration profile in Intune and configure the "Configuration Manager Compliance" setting to require co-management.
Why it's wrong here
The "Configuration Manager Compliance" setting in a compliance policy checks whether the device is compliant with Configuration Manager, but it does not control the assignment of configuration profiles. Configuration profiles are assigned via groups, not via compliance settings. Using this setting would not target the profile to co-managed devices and would not prevent it from applying to Intune-only devices. It is a misunderstanding of the feature.
Go deeper
Related to this question
Learn chapter
Managing Device Configuration Profiles
Key term
Configuration Manager
Configuration Manager is a systems management tool by Microsoft that helps IT administrators deploy software, enforce security policies, and manage devices across an organization.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.