Courseiva
Protect devices →easyMultiple Choice

MD-102 Protect devices Practice Question

You are deploying Microsoft Defender for Endpoint to 200 Windows 10 devices managed by Microsoft Intune. You want to onboard the devices to Defender for Endpoint using the least administrative effort. What should you do?

⚠ Common exam trap

The trap here is overlooking the built-in connector and instead opting for manual or script-based methods, which require more effort and do not leverage Intune's automation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the Microsoft Defender for Endpoint connector in Intune to onboard the devices.

The Microsoft Defender for Endpoint connector in Intune is designed to simplify onboarding. When enabled, it automatically deploys the onboarding package to all Intune-managed Windows devices. This eliminates the need for manual configuration or scripting, providing the least administrative effort and ensuring consistent deployment across the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a configuration profile with the Defender for Endpoint onboarding blob and assign it to the devices.

    Why it's wrong here

    While a configuration profile can deploy the onboarding blob, it requires manual creation of the profile and uploading the blob. This is more administrative effort than using the built-in connector. The connector automates the process and is the recommended method for Intune-managed devices.

  • ✗

    Deploy a PowerShell script that runs the onboarding script on each device.

    Why it's wrong here

    A PowerShell script can onboard devices, but it requires you to obtain the script, deploy it, and ensure it runs successfully on each device. This approach involves more administrative overhead and potential for errors compared to using the built-in connector. It is not the least-effort method.

  • ✓

    Use the Microsoft Defender for Endpoint connector in Intune to onboard the devices.

    Why this is correct

    The Microsoft Defender for Endpoint connector in Intune allows you to onboard devices with minimal effort. You simply enable the connector, and Intune automatically deploys the onboarding configuration to all targeted devices. This method is the most efficient and reduces manual steps, making it ideal for large-scale deployments.

  • ✗

    Manually install the Defender for Endpoint agent on each device.

    Why it's wrong here

    Manual installation is time-consuming and not scalable for 200 devices. It also increases the risk of human error. Intune provides automated methods that are far more efficient. Manual installation is typically used only for troubleshooting or small deployments.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.