MD-102 Manage and maintain devices Practice Question
You need to deploy a custom PowerShell script to all Windows 10 devices enrolled in Intune. The script must run under the SYSTEM account. Which Intune feature should you use?
⚠ Common exam trap
A common misconception is that Proactive remediations can replace custom PowerShell scripts. However, Proactive remediations require both a detection script and a remediation script, and are designed for automatic remediation of specific issues, not for general script deployment. Custom PowerShell scripts (Devices > Scripts) are the correct choice for deploying a standalone script under the SYSTEM account.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PowerShell scripts (Devices > Scripts)
PowerShell scripts (Devices > Scripts) in Intune allow you to upload and assign custom PowerShell scripts that run under the SYSTEM account on Windows 10 devices. This feature is specifically designed for executing scripts during device enrollment or on a schedule, ensuring the script has elevated privileges without user interaction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proactive remediations
Why it's wrong here
Proactive remediations run detection and remediation scripts, but they execute in the user or SYSTEM context depending on configuration and are designed for health checks, not broad script deployment. They suit recurring detection-and-fix pairs, not a one-off custom script pushed to all devices.
- ✓
PowerShell scripts (Devices > Scripts)
Why this is correct
PowerShell scripts in Intune run in the SYSTEM context on enrolled Windows 10 devices by default, satisfying the stem's requirement. Upload the script under Devices > Scripts, where it executes once or on a schedule without user credentials, unlike proactive remediations or platform scripts requiring different scopes.
- ✗
Compliance policy
Why it's wrong here
Compliance policy evaluates device settings against rules and reports non-compliance; it cannot execute scripts. It is the right feature for conditional access gating based on encryption, OS version or firewall state, not for running a PowerShell payload as SYSTEM on enrolled devices.
- ✗
Device configuration profile
Why it's wrong here
Device configuration profiles deliver settings and some scripts, but Windows PowerShell script deployment with SYSTEM execution is handled by the Intune scripts feature, not configuration profiles. Configuration profiles are correct for enforcing settings such as BitLocker or firewall rules, not arbitrary script execution.
Go deeper
Related to this question
Learn chapter
Troubleshooting Device Enrollment and Management
Key term
Intune
Microsoft Intune is a cloud-based service that helps organizations manage their users' devices and applications, ensuring security and compliance without needing to own or control the physical hardware.
Key term
Device enrollment
Device enrollment is the process of registering a device with a management system so that it can receive policies, apps, and security settings under organizational control.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.