Courseiva
Prepare infrastructure for deviceshardMultiple ChoiceObjective-mapped

MD-102 Prepare infrastructure for devices Practice Question

You are troubleshooting a Windows 11 device that fails to enroll in Intune via Group Policy. The device is domain-joined and you have configured the 'Enable automatic MDM enrollment using default Azure AD credentials' GPO. The user has a valid Microsoft 365 license. What is the most likely reason for the failure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The device is not registered in Azure AD.

For the 'Enable automatic MDM enrollment using default Azure AD credentials' GPO to succeed, the device must be registered in Azure AD. Since the device is only domain-joined and no Azure AD registration has occurred, the enrollment fails. Option B is incorrect because the GPO is configured correctly; if it were not linked, it would not apply at all. Option C is incorrect because the user has a valid Microsoft 365 license that includes Intune. Option D is incorrect because a service connection point is used for Configuration Manager co-management, not for this GPO.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The device is not registered in Azure AD.

    Why this is correct

    Correct. The device must be registered in Azure AD (Hybrid Azure AD Join) for the GPO to trigger automatic MDM enrollment. Domain-join alone is insufficient.

  • The GPO is not linked to the correct organizational unit.

    Why it's wrong here

    Incorrect. While the GPO must be linked to the correct OU, this is a common misconfiguration but not the most likely reason given that the device fails to enroll even with the policy applied.

  • The user does not have an Intune license assigned.

    Why it's wrong here

    Incorrect. The question states the user has a valid Microsoft 365 license, which includes Intune. Licensing is not the issue.

  • The device does not have a service connection point configured.

    Why it's wrong here

    Incorrect. A service connection point is used for Configuration Manager (SCCM) integration, not for Intune enrollment via the 'Enable automatic MDM enrollment' GPO.

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.