Courseiva
Manage applications →hardMultiple Choice

MD-102 Manage applications Practice Question

You are deploying a Win32 app that requires administrator privileges to install. The app runs on Windows 11 devices. How should you configure the app in Intune to ensure it installs with elevated privileges?

⚠ Common exam trap

A common mix-up: candidates confuse 'install behavior' with 'detection rules' or 'script execution,' mistakenly thinking a PowerShell script or a detection rule can enforce elevation, when in fact only the 'System' context setting in Intune ensures the installer runs with the necessary administrator privileges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the app install behavior to 'System'.

Setting the install behavior to 'System' in Intune for a Win32 app ensures the installer runs with the SYSTEM account, which inherently has administrator privileges. This is required for apps that demand elevated rights during installation, as the SYSTEM account bypasses user account control (UAC) and can write to protected system locations like Program Files or the registry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the app install behavior to 'System'.

    Why this is correct

    Setting install behaviour to System runs the Win32 app installer in the SYSTEM context, granting local administrator rights. This satisfies the elevation requirement, whereas User context installs with the signed-in user's standard privileges and would fail.

  • ✗

    Set the app to run in user context.

    Why it's wrong here

    User context runs the installer with the signed-in user's token, which lacks administrator rights, so the installation fails or triggers a UAC prompt the user cannot satisfy. User context suits per-user apps that write to the user profile; system context is required when setup must write to protected locations such as Program Files or HKLM.

  • ✗

    Use a PowerShell script to run the installer.

    Why it's wrong here

    A PowerShell script runs in the Intune Management Extension's own context, which is not SYSTEM by default, so the installer still lacks the elevation the app demands. Scripts suit remediation, detection or configuration tasks; for privileged installation the app itself must be assigned to run in system context with the installer command configured accordingly.

  • ✗

    Configure a detection rule to check for admin rights.

    Why it's wrong here

    A detection rule only reports whether the app is present; it neither grants nor checks privileges, so it cannot elevate the installer. Detection rules exist to determine compliance state after installation, and would be the right configuration when you need to verify an app's presence, version or registry key rather than control how setup executes.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.