Courseiva

MD-102 Manage and maintain devices Practice Question

You manage a hybrid Microsoft Entra ID joined environment with Microsoft Intune. You need to configure a Windows 10 device to receive Windows updates from Intune instead of from on-premises WSUS. The device is currently configured to use WSUS via Group Policy. Which TWO actions should you perform? (Choose two.)

⚠ Common exam trap

The trap here is thinking that Intune can override existing WSUS Group Policy settings automatically, when in fact WSUS GPOs must be removed first for Intune update rings to apply.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the WSUS Group Policy settings from the device.

To transition from WSUS to Intune update management, you must remove the WSUS Group Policy settings that direct the device to the on-premises server, and then enroll the device in Intune and assign a Windows Update ring. These two actions ensure that Intune policies take precedence and manage update delivery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a PowerShell script to modify the registry key HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU to point to Intune.

    Why it's wrong here

    There is no registry key that points Windows Update to Intune. Intune manages updates via MDM policies, not by redirecting the update server address. Modifying this key would not achieve the goal and could disrupt update functionality. The correct approach involves removing WSUS GPOs and using Intune update rings.

  • ✗

    Enable the 'Microsoft Update' option in the Windows Update settings on each device.

    Why it's wrong here

    The 'Microsoft Update' option allows the device to receive updates for other Microsoft products, but it does not redirect update management from WSUS to Intune. It is unrelated to the requirement. The necessary steps are removing WSUS policies and assigning an Intune update ring.

  • ✓

    Remove the WSUS Group Policy settings from the device.

    Why this is correct

    For Intune to manage Windows updates, the device must not be configured to use WSUS via Group Policy. Removing the WSUS settings ensures that the Windows Update client does not point to an on-premises server, allowing Intune update rings to take effect. This is a necessary step.

  • ✗

    Configure a conditional access policy to block WSUS traffic.

    Why it's wrong here

    Conditional access policies control access to cloud apps based on conditions, not network traffic to on-premises WSUS servers. They cannot block WSUS traffic. This action would not help transition update management to Intune and is irrelevant to the scenario.

  • ✓

    Enroll the device in Microsoft Intune and assign a Windows Update ring.

    Why this is correct

    Enrolling the device in Intune and assigning a Windows Update ring configures the Windows Update for Business settings to be managed by Intune. This allows the device to receive updates directly from Microsoft or via Intune policies, fulfilling the requirement to manage updates through Intune.

About these practice questions

One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.