Courseiva
Manage and maintain deviceseasyMultiple ChoiceObjective-mapped

MD-102 Manage and maintain devices Practice Question

You need to configure Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. What is the recommended method to onboard devices?

⚠ Common exam trap

It's easy for candidates to assume Group Policy (Option D) is the standard for all Windows management, but for Intune-managed devices, the recommended and supported method is the device configuration profile, not Group Policy, which requires on-premises infrastructure and does not integrate with cloud-based enrollment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a device configuration profile in Intune to deploy the onboarding package.

Intune's device configuration profiles allow you to deploy the Defender for Endpoint onboarding package (a .zip containing the onboarding script and required files) directly to Windows 10 devices. This method is recommended as it integrates seamlessly with Intune's management framework, supports bulk deployment via policies, and ensures devices are properly configured without manual intervention or user interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Install the Defender for Endpoint client manually on each device.

    Why it's wrong here

    Manual installation of the Defender for Endpoint client on each device lacks the centralised, policy-driven deployment and configuration that Intune provides via its Security Configuration Management, which is required for consistent onboarding across a managed fleet. This approach is tempting because it works for unmanaged devices or proof-of-concept testing where no MDM solution like Intune is in place, and it would be correct in a small, non-domain-joined environment without Microsoft Entra ID integration.

  • Use a device configuration profile in Intune to deploy the onboarding package.

    Why this is correct

    Correct: Device configuration profiles in Intune can deploy the onboarding package to enrolled devices.

  • Use the Microsoft 365 Defender portal to generate a script that users run.

    Why it's wrong here

    The Microsoft 365 Defender portal generates an onboarding script, but for Intune-managed devices, using Intune profiles is the recommended method.

  • Use Group Policy to configure the onboarding registry keys.

    Why it's wrong here

    Group Policy is not the recommended method for Intune-managed devices; Intune profiles are preferred.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.