Courseiva

MD-102 Manage and maintain devices Practice Question

You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?

⚠ Common exam trap

A common misconception is that Proactive remediations can replace custom PowerShell scripts. However, Proactive remediations require both a detection script and a remediation script, and are designed for automatic remediation of specific issues, not for general script deployment. Custom PowerShell scripts (Devices > Scripts) are the correct choice for deploying a standalone script under the SYSTEM account.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PowerShell scripts (Devices > Scripts)

PowerShell scripts (Devices > Scripts) in Intune allow you to upload and assign custom PowerShell scripts that run under the SYSTEM account on Windows 10 devices. This feature is specifically designed for executing scripts during device enrollment or on a schedule, ensuring the script has elevated privileges without user interaction.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Proactive remediations

    Why it's wrong here

    Proactive remediations run detection and remediation scripts, but they execute in the user or SYSTEM context depending on configuration and are designed for health checks, not broad script deployment. They suit recurring detection-and-fix pairs, not a one-off custom script pushed to all devices.

  • ✓

    PowerShell scripts (Devices > Scripts)

    Why this is correct

    PowerShell scripts in Intune run in the SYSTEM context on enrolled Windows 10 devices by default, satisfying the stem's requirement. Upload the script under Devices > Scripts, where it executes once or on a schedule without user credentials, unlike proactive remediations or platform scripts requiring different scopes.

  • ✗

    Compliance policy

    Why it's wrong here

    Compliance policy evaluates device settings against rules and reports non-compliance; it cannot execute scripts. It is the right feature for conditional access gating based on encryption, OS version or firewall state, not for running a PowerShell payload as SYSTEM on enrolled devices.

  • ✗

    Device configuration profile

    Why it's wrong here

    Device configuration profiles deliver settings and some scripts, but Windows PowerShell script deployment with SYSTEM execution is handled by the Intune scripts feature, not configuration profiles. Configuration profiles are correct for enforcing settings such as BitLocker or firewall rules, not arbitrary script execution.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.