Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.

Microsoft Entra ID joined devices automatically enroll in Intune when the MDM user scope is set to 'All' or 'Some'. Option B is incorrect because the MDM discovery URL is configured automatically for Microsoft Entra ID joined devices and does not need manual configuration. Option C is incorrect because enrollment restrictions control which devices can enroll but do not trigger automatic enrollment. Option D is incorrect because device compliance policies are applied after enrollment, not before.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.

    Why this is correct

    The MDM user scope determines which Microsoft Entra ID users' devices are permitted to enrol automatically; setting it to All or Some enables automatic enrolment at sign-in. This satisfies the requirement for Microsoft Entra ID-joined Windows 11 devices to enrol without manual action.

  • ✗

    Configure the MDM discovery URL in Microsoft Entra ID.

    Why it's wrong here

    The MDM discovery URL tells a device where to enrol when it is not already Entra-joined; for an Entra-joined Windows 11 device, automatic enrolment is driven by the Intune automatic MDM enrolment setting scoped to users. It is tempting because discovery URLs are used for manual or Group Policy enrolment, which would apply to non-Entra-joined devices.

  • ✗

    Create an enrollment restriction that allows Windows devices.

    Why it's wrong here

    Enrollment restrictions filter which platforms, versions, or ownership types may enrol; they do not initiate enrolment for an Entra-joined device. It is tempting because restrictions control enrolment eligibility, and would be correct when blocking personal Android or iOS devices, not when enabling Windows automatic enrolment through user scope.

  • ✗

    Assign a device compliance policy to the user.

    Why it's wrong here

    A compliance policy evaluates devices already enrolled and reports their state against conditions; it cannot cause enrolment to occur. It is tempting because compliance policies are central to Conditional Access, and would be correct once devices are enrolled and you need to gate resource access on their health.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.