Courseiva

MD-102 Prepare infrastructure for devices Practice Question

Your organization uses Microsoft Intune to manage Windows 10/11 devices. You need to ensure that devices are enrolled automatically without user interaction and that the enrollment status page (ESP) is configured to block device use until required apps are installed. What should you configure?

⚠ Common exam trap

MD-102 often tests the confusion between DEM accounts (bulk enrollment with sign-in) and Autopilot self-deploying mode (truly unattended, TPM-based), causing candidates to pick DEM for zero-touch scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Windows Autopilot self-deploying mode and an Enrollment Status Page profile

Windows Autopilot self-deploying mode enrolls devices into Intune with zero user interaction — the device authenticates using its TPM-attested hardware identity, so no credentials are entered. Pairing it with an Enrollment Status Page (ESP) profile blocks the device from being used until required apps and policies are applied, which is exactly what the scenario requires.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Group Policy to auto-enroll devices into Intune

    Why it's wrong here

    Group Policy cannot deliver the Intune enrollment status page, which blocks device use until required apps install; it only handles on-premises domain auto-enrolment. Windows Autopilot deployment profiles configure both zero-touch enrolment and the ESP. Group Policy suits hybrid domain-joined device management.

  • ✗

    Configure a device enrollment manager (DEM) account

    Why it's wrong here

    A device enrollment manager (DEM) account is used for bulk enrollment, allowing one user to enroll many devices, but it requires manual intervention during enrollment and does not provide automatic zero-touch enrollment. DEM supports Windows devices as well as other platforms, so it is not limited to Android/iOS.

  • ✓

    Configure Windows Autopilot self-deploying mode and an Enrollment Status Page profile

    Why this is correct

    Windows Autopilot self-deploying mode enrols devices with no user credentials, satisfying the zero-touch requirement, since it authenticates via the device's TPM-attested identity rather than an interactive sign-in. Pairing it with an Enrollment Status Page profile blocks device use until assigned required apps install, meeting the stem's gating constraint.

  • ✗

    Configure co-management with Microsoft Configuration Manager

    Why it's wrong here

    Co-management splits workloads between Microsoft Configuration Manager and Intune but does not itself perform zero-touch enrolment or present the ESP. Windows Autopilot deployment profiles deliver both. Co-management suits gradually migrating existing Configuration Manager-managed devices to Intune.

Go deeper

Related to this question

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.