Courseiva
Protect devices →mediumMultiple Choice

MD-102 Protect devices Practice Question

Your organization uses Windows Autopilot and Microsoft Intune. You need to ensure that during the Autopilot deployment, the device automatically installs a set of required applications (Microsoft 365 Apps, company portal, and a line-of-business app) before the user can access the desktop. Which configuration should you use?

⚠ Common exam trap

Many candidates confuse the ESP's ability to block desktop access with compliance policies or scripts, not realizing that only the ESP provides the specific 'block until installed' functionality during Autopilot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the Enrollment Status Page (ESP) to block device use until required apps are installed

The Enrollment Status Page (ESP) in Windows Autopilot can be configured to block device use until specified required apps are installed. This ensures that Microsoft 365 Apps, Company Portal, and line-of-business apps are fully deployed before the user reaches the desktop, meeting the requirement of a controlled, app-ready deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure the Enrollment Status Page (ESP) to block device use until required apps are installed

    Why this is correct

    The Enrollment Status Page hooks into Autopilot's device ESP phase, tracking Win32 and Microsoft Store app installation via Intune management extension before allowing desktop access. This directly satisfies the stem's constraint that required apps — Microsoft 365 Apps, Company Portal, and the LOB app — must install before the user reaches the desktop.

  • ✗

    Set a device compliance policy to require all apps to be installed

    Why it's wrong here

    A compliance policy evaluates and reports device state after enrolment; it cannot install Microsoft 365 Apps, Company Portal or the LOB app, so nothing is deployed before desktop access. It is tempting because compliance gates access, and would be correct for blocking non-compliant devices from resources.

  • ✗

    Use a PowerShell script that runs during Autopilot to install apps

    Why it's wrong here

    A PowerShell script runs as a platform script after enrolment, not as a blocking required app, so it cannot guarantee installation before desktop access. It is tempting because scripts can install anything, and would suit one-off customisation where no Intune app packaging or ESP enforcement is needed.

  • ✗

    Configure an Autopilot deployment profile with the 'Skip EULA' option

    Why it's wrong here

    Skipping the EULA only suppresses a licence-agreement screen during OOBE; it installs no applications and does not gate desktop access on app installation. It is tempting as a way to streamline the out-of-box experience, and would be correct when the requirement is simply to reduce user prompts.

About these practice questions

This MD-102 question is part of Courseiva's 556-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MD-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MD-102 exam.