MD-102 Manage and maintain devices Practice Question
You are designing a device management strategy for a hybrid environment with on-premises Active Directory and Microsoft Entra ID. You need to ensure that devices are managed by Intune and can access on-premises resources. Which approach should you recommend?
⚠ Common exam trap
A common mix-up: candidates confuse 'Entra ID registered' with 'Hybrid Microsoft Entra ID join' because both involve Entra ID, but only Hybrid Microsoft Entra ID join provides the on-premises domain join required for seamless resource access without a VPN.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hybrid Microsoft Entra ID join
Hybrid Microsoft Entra ID join is the correct approach because it allows devices that are joined to on-premises Active Directory to also register with Microsoft Entra ID, enabling Intune management while maintaining access to on-premises resources via Kerberos/NTLM authentication. This configuration synchronizes the device object from AD to Entra ID using Microsoft Entra Connect, creating a device identity that can be managed by Intune and can authenticate against both cloud and on-premises services without requiring a VPN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hybrid Microsoft Entra ID join
Why this is correct
Hybrid Microsoft Entra join registers on-premises Active Directory domain-joined devices with Microsoft Entra ID, enabling Intune enrolment and policy delivery while preserving the Kerberos and LDAP trust needed for on-premises resource access. This satisfies the stem's dual requirement: Intune management plus continued access to on-premises resources.
- ✗
Entra ID registered with on-premises domain join
Why it's wrong here
Entra ID registered devices remain workgroup-style; they lack the on-premises domain join needed for Kerberos and Group Policy access to domain resources. Registration suits bring-your-own-device scenarios granting conditional access to cloud apps, not hybrid domain membership managed by Intune.
- ✗
Windows Autopilot self-deploying mode
Why it's wrong here
Self-deploying mode provisions Entra ID joined devices with no user affinity and no on-premises domain join, so domain resources stay unreachable. It suits kiosks and shared devices needing zero-touch provisioning, not hybrid environments requiring Active Directory membership.
- ✗
Entra ID joined with VPN to on-premises
Why it's wrong here
Entra ID joined devices have no on-premises domain membership; VPN supplies network reachability only, not Kerberos tickets or Group Policy. This suits cloud-native estates accessing legacy apps over VPN, not hybrid designs needing true domain join plus Intune co-management.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
VPN
A VPN (Virtual Private Network) creates a secure, encrypted tunnel between your device and a remote server, protecting your data and hiding your online activity.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.