MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization is deploying Windows 11 using Microsoft Intune. You need to ensure that devices are automatically enrolled in Intune when users sign in with their Microsoft Entra ID credentials. Which THREE prerequisites must be met?
⚠ Common exam trap
Test-takers frequently confuse the licensing requirement (Entra ID P1/P2) with the need for a separate MDM license like Intune, or mistakenly think that Windows Home edition or Configuration Manager are required for automatic enrollment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID P1 or P2 license.
Microsoft Entra ID P1 or P2 licenses are required to enable automatic MDM enrollment via Intune. Without these licenses, the MDM authority cannot be set to Intune, and the automatic enrollment policy in Microsoft Entra ID will not function. This licensing requirement ensures that the tenant has the necessary features for conditional access and device management policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Devices must run Windows 10/11 Home edition.
Why it's wrong here
Windows 10/11 Home edition is a consumer-focused SKU that lacks support for Microsoft Entra ID join and provides no MDM enrollment capability for Intune. Home edition does not include the enterprise management components such as the ability to process provisioning packages or automatically register with Intune during device setup. For this reason, requiring Home edition would block Intune enrollment entirely, making this option incorrect.
- ✗
Microsoft Configuration Manager must be deployed.
Why it's wrong here
Microsoft Configuration Manager is a separate on-premises management solution that can be co-managed with Intune, but it is not a prerequisite for the automatic enrollment of Windows 11 devices into Intune. Automatic enrollment relies on Microsoft Entra ID device identity and MDM scope configuration, not on a Configuration Manager deployment. In a cloud-only environment, you can enroll Windows devices into Intune with no Configuration Manager infrastructure at all.
- ✓
Microsoft Entra ID P1 or P2 license.
Why this is correct
A Microsoft Entra ID P1 or P2 license is required in the tenant to enable the automatic MDM enrollment feature that connects Microsoft Entra ID to Intune. This license tier permits group-based assignment of Intune licenses and allows the MDM auto-enrollment policy to be configured for users. Without P1 or P2, the automatic enrollment setting is not available, even if the user has a standalone Intune license assigned.
- ✓
Devices must be Microsoft Entra joined or hybrid Microsoft Entra joined.
Why this is correct
For a Windows 11 device to be automatically enrolled into Intune, it must have an identity in Microsoft Entra ID, which is established by being Microsoft Entra joined (cloud-only) or hybrid Microsoft Entra joined (on-prem AD plus Entra). These join states register the device with Microsoft Entra ID and link it to the user, allowing Intune to take over management. A device that is only classic domain joined without Entra registration cannot trigger auto-enrollment.
- ✓
MDM user scope must be set to All or Some in Microsoft Entra ID.
Why this is correct
The MDM user scope setting in Microsoft Entra ID controls which users' devices are automatically enrolled into Intune when they sign in to Windows. If this scope is set to 'None', automatic enrollment is disabled regardless of the user's license or device join state. Choosing 'All' enrolls every user's devices, while selecting 'Some' targets a security group, providing granular control over the enrollment population for compliance and policy targeting.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Verified ID
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
MDM
MDM stands for Mobile Device Management, a technology that allows IT administrators to securely manage, monitor, and enforce policies on mobile devices like smartphones and tablets from a central console.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.