Courseiva

MD-102 Manage and maintain devices Practice Question

You are designing a Windows 365 Cloud PC provisioning policy. The requirement is that when a user is assigned a Cloud PC, it must automatically have Microsoft Defender for Endpoint configured with real-time protection enabled and a custom firewall rule allowing only specific IPs. Which approach should you use?

⚠ Common exam trap

The trap here is that candidates mistakenly think Windows 365 provisioning policies can include security configurations, but in reality, they only define infrastructure settings, while all post-provisioning management (including Defender and firewall rules) must be handled by Intune policies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Intune device configuration profile using the Settings Catalog and assign it to the Microsoft Entra ID group containing Cloud PC users.

Intune device configuration profiles using the Settings Catalog allow granular control over Microsoft Defender for Endpoint settings (e.g., real-time protection) and custom firewall rules. These profiles can be assigned to an Microsoft Entra ID group containing Cloud PC users, ensuring the settings are applied automatically after provisioning via the Windows 365 service, which integrates with Intune for post-provisioning management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an Intune device configuration profile using the Settings Catalog and assign it to the Microsoft Entra ID group containing Cloud PC users.

    Why this is correct

    The Settings Catalog exposes Defender for Endpoint real-time protection and firewall configuration settings as a reusable Intune profile, which applies automatically to Cloud PCs once assigned to the Microsoft Entra ID group. This satisfies the requirement for automatic configuration at provisioning.

  • ✗

    Include the settings in the Windows 365 provisioning policy.

    Why it's wrong here

    Windows 365 provisioning policies only define network, image, and region settings; they cannot configure Defender for Endpoint or firewall rules. It is tempting because provisioning policies are the natural place for per-user Cloud PC configuration, but security baselines and firewall policy belong to Intune configuration profiles.

  • ✗

    Create a PowerShell script that runs during provisioning and apply it via Azure Automation.

    Why it's wrong here

    A PowerShell script run via Azure Automation executes outside the Cloud PC's provisioning sequence and cannot reliably apply Defender or firewall settings at first sign-in. It is tempting because scripting feels flexible, but Intune configuration profiles deliver these settings declaratively during provisioning.

  • ✗

    Use a Group Policy Object (GPO) applied via on-premises AD.

    Why it's wrong here

    On-premises GPO requires domain-joined devices and line-of-sight to a domain controller; Cloud PCs are Microsoft Entra joined, so they never process those objects. It is tempting because GPO is the traditional Windows management route, but it cannot deliver settings to Entra-joined Cloud PCs.

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.