MD-102 Manage and maintain devices Practice Question
You manage devices with Microsoft Intune and have enabled co-management with Configuration Manager. You need to ensure that Windows Update policies are managed by Intune for all co-managed Windows 10 devices. Which workload slider should you set in Configuration Manager?
⚠ Common exam trap
Many exam-takers confuse the 'Windows Update Policies' slider with the 'Endpoint Protection' slider, mistakenly thinking update management is part of security policies, but the slider specifically governs Windows Update for Business policies, not Defender or antivirus updates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows Update Policies
In a co-management scenario, the workload slider determines which management authority handles specific workloads. Setting the 'Windows Update Policies' slider to 'Intune' directs Windows Update for Business policies to be applied via Intune, overriding Configuration Manager policies for co-managed Windows 10 devices. This ensures that update rings and deferral settings configured in Intune are enforced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Endpoint Protection
Why it's wrong here
Endpoint Protection governs Defender antivirus and firewall policy, not update rings or Windows Update for Business settings. Moving this slider to Intune suits organisations standardising endpoint security agents centrally while leaving update policy in Configuration Manager.
- ✓
Windows Update Policies
Why this is correct
Moving the Windows Update Policies workload slider to Intune transfers update policy authority from Configuration Manager to Intune for co-managed devices. This directly satisfies the stem's requirement that Intune manage Windows Update policies across all co-managed Windows 10 devices.
- ✗
Client Apps
Why it's wrong here
Client Apps governs deployment of applications from Intune or Configuration Manager, not update policy. It is tempting because moving this workload lets Intune deliver Win32 apps to co-managed devices, which is the right choice when application deployment, rather than Windows Update policy, must shift to Intune.
- ✗
Device Configuration
Why it's wrong here
Device Configuration governs settings delivered through configuration profiles, not update deployment. Windows Update policies sit under the Windows Update workload slider, which must move to Intune for co-managed devices. Device Configuration would be the right slider when you want Intune to manage compliance-adjacent configuration baselines instead of Configuration Manager.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Windows Update for Business
Windows Update for Business is a set of policies and settings that IT administrators use to manage and control how Windows devices receive updates from Microsoft, allowing for staged rollouts and deferrals while ensuring security patches are applied.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
One of 556 original MD-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.