MD-102 Prepare infrastructure for devices Practice Question
Your organization has an existing Microsoft Intune environment. You need to configure a Windows 11 device to automatically enroll in Intune when a user signs in with their Microsoft Entra ID credentials. The device is joined to Microsoft Entra ID. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.
Microsoft Entra ID joined devices automatically enroll in Intune when the MDM user scope is set to 'All' or 'Some'. Option B is incorrect because the MDM discovery URL is configured automatically for Microsoft Entra ID joined devices and does not need manual configuration. Option C is incorrect because enrollment restrictions control which devices can enroll but do not trigger automatic enrollment. Option D is incorrect because device compliance policies are applied after enrollment, not before.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the MDM user scope in Microsoft Entra ID to 'All' or 'Some'.
Why this is correct
The MDM user scope determines which Microsoft Entra ID users' devices are permitted to enrol automatically; setting it to All or Some enables automatic enrolment at sign-in. This satisfies the requirement for Microsoft Entra ID-joined Windows 11 devices to enrol without manual action.
- ✗
Configure the MDM discovery URL in Microsoft Entra ID.
Why it's wrong here
The MDM discovery URL tells a device where to enrol when it is not already Entra-joined; for an Entra-joined Windows 11 device, automatic enrolment is driven by the Intune automatic MDM enrolment setting scoped to users. It is tempting because discovery URLs are used for manual or Group Policy enrolment, which would apply to non-Entra-joined devices.
- ✗
Create an enrollment restriction that allows Windows devices.
Why it's wrong here
Enrollment restrictions filter which platforms, versions, or ownership types may enrol; they do not initiate enrolment for an Entra-joined device. It is tempting because restrictions control enrolment eligibility, and would be correct when blocking personal Android or iOS devices, not when enabling Windows automatic enrolment through user scope.
- ✗
Assign a device compliance policy to the user.
Why it's wrong here
A compliance policy evaluates devices already enrolled and reports their state against conditions; it cannot cause enrolment to occur. It is tempting because compliance policies are central to Conditional Access, and would be correct once devices are enrolled and you need to gate resource access on their health.
Go deeper
Related to this question
Learn chapter
Managing Microsoft 365 Apps and Office Updates
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
About these practice questions
This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.