MD-102 Manage and maintain devices Practice Question
You need to configure Microsoft Defender for Endpoint on Windows 10 devices managed by Intune. What is the recommended method to onboard devices?
⚠ Common exam trap
It's easy for candidates to assume Group Policy (Option D) is the standard for all Windows management, but for Intune-managed devices, the recommended and supported method is the device configuration profile, not Group Policy, which requires on-premises infrastructure and does not integrate with cloud-based enrollment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a device configuration profile in Intune to deploy the onboarding package.
Intune's device configuration profiles allow you to deploy the Defender for Endpoint onboarding package (a .zip containing the onboarding script and required files) directly to Windows 10 devices. This method is recommended as it integrates seamlessly with Intune's management framework, supports bulk deployment via policies, and ensures devices are properly configured without manual intervention or user interaction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Install the Defender for Endpoint client manually on each device.
Why it's wrong here
Manual installation of the Defender for Endpoint client on each device lacks the centralised, policy-driven deployment and configuration that Intune provides via its Security Configuration Management, which is required for consistent onboarding across a managed fleet. This approach is tempting because it works for unmanaged devices or proof-of-concept testing where no MDM solution like Intune is in place, and it would be correct in a small, non-domain-joined environment without Microsoft Entra ID integration.
- ✓
Use a device configuration profile in Intune to deploy the onboarding package.
Why this is correct
Correct: Device configuration profiles in Intune can deploy the onboarding package to enrolled devices.
- ✗
Use the Microsoft 365 Defender portal to generate a script that users run.
Why it's wrong here
The Microsoft 365 Defender portal generates an onboarding script, but for Intune-managed devices, using Intune profiles is the recommended method.
- ✗
Use Group Policy to configure the onboarding registry keys.
Why it's wrong here
Group Policy is not the recommended method for Intune-managed devices; Intune profiles are preferred.
Go deeper
Related to this question
Learn chapter
Introduction to Endpoint Management in Microsoft 365
Key term
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a cloud-delivered enterprise-grade security platform that protects devices, servers, and networks from advanced cyber threats by combining antivirus, endpoint detection and response, and automated investigation and remediation.
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
About these practice questions
This MD-102 question is part of Courseiva's 942-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.