Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

You have a hybrid Microsoft Entra ID joined Windows 10 device that is co-managed with Configuration Manager and Intune. You want Intune to manage Windows Update for Business settings. Which slider setting should you configure in Configuration Manager?

⚠ Common exam trap

Many candidates confuse 'Windows Update policies' with 'Device configuration' or 'Endpoint protection', assuming that update settings fall under a broader configuration or security category, but Microsoft specifically separates update management into its own workload slider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Move the slider for 'Windows Update policies' to 'Intune'

In a co-management scenario, workload sliders in Configuration Manager determine which authority manages specific workloads. To have Intune manage Windows Update for Business settings, you must move the slider for 'Windows Update policies' to Intune. This shifts the policy authority from Configuration Manager to Intune, allowing Intune's Update Rings and feature update policies to control Windows Update behavior on the device.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Move the slider for 'Windows Update policies' to 'Intune'

    Why this is correct

    Shifting the Windows Update policies workload slider to Intune transfers authority for Windows Update for Business settings to Microsoft Entra ID-based MDM, satisfying the requirement that Intune manage them. Configuration Manager retains the remaining co-management workloads, so update policy delivery no longer depends on the Configuration Manager client.

  • ✗

    Move the slider for 'Endpoint protection' to 'Intune'

    Why it's wrong here

    Endpoint protection covers Defender antivirus, firewall and attack surface reduction policies, not update rings. Windows Update for Business needs the Windows Update slider moved to Intune. Endpoint protection is the correct slider when you want Intune to manage Defender and firewall configuration rather than Configuration Manager.

  • ✗

    Move the slider for 'Resource access' to 'Intune'

    Why it's wrong here

    Resource access controls VPN, Wi-Fi, certificate and email profile delivery, not update policy. Windows Update for Business requires the Windows Update slider, so moving Resource access leaves update settings with Configuration Manager. Resource access is the right slider when Intune should deliver certificates and network profiles to co-managed devices.

  • ✗

    Move the slider for 'Device configuration' to 'Intune'

    Why it's wrong here

    Windows Update for Business settings sit under the Windows Update workload slider, not Device configuration, which governs general device settings such as encryption and platform restrictions. Moving Device configuration to Intune is correct when you want Intune to own those broader device settings instead of Configuration Manager.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MD-102 question from scratch — 556 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.