Microsoft

MD-102 Free Practice Questions

This is the free Microsoft MD-102 practice question bank — 190 of 373 total questions, each with a full explanation, free to read with no signup required. Updated 2026-08-05.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

You have a Microsoft 365 subscription that uses Microsoft Intune and contains a group named Group1. You have a line-of-business (LOB) app named App1 that supports in-app notifications. App1 is assigned to all the users in the subscription. You need to ensure that the users in Group1 receive a custom notification when they launch App1. What should you do?

A. Create an app configuration policy and assign the policy to Group1.
B. Edit the assignment for App1.
C. Create a device configuration profile and assign the profile to Group1.
D. Create an app protection policy and assign the policy to Group1.
Show Answer
Correct Answer: A
Explanation:
App configuration policies in Microsoft Intune are used to deliver configuration settings to managed apps, including vendor-specific settings that enable app features such as in-app notifications or custom behavior. Assigning an app configuration policy to Group1 ensures only those users receive the custom notification when they launch the LOB app. Editing the app assignment only changes deployment targeting, device configuration profiles manage device settings, and app protection policies control data protection rather than app-specific notification behavior.

Question 2

HOTSPOT - You have a Microsoft 365 subscription that uses Microsoft Intune and contains a Microsoft Tunnel for Mobile Application. You have the devices shown in the following table. You need to ensure that you can use Tunnel for MAM on each device. The solution must minimize the number of apps required on each device. Which apps should you install on each device? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 2 Illustration for MD-102 question 2
Show Answer
Correct Answer: Device1: Microsoft Defender and Intune Company Portal Device2: No additional apps
Explanation:
For Microsoft Tunnel for MAM, Android requires both Microsoft Defender and the Intune Company Portal to support the tunnel. On iOS, Tunnel for MAM is built into supported Microsoft apps, so no additional app is required.

Question 3

You have a Microsoft 365 subscription that uses Microsoft Intune and has the following advanced analytics reports enabled: • Endpoint analytics • Application reliability • Work from anywhere You purchase a new device named Device1 that is enrolled in Intune. You need to ensure that advanced analytics reports can be generated for Device1. Which telemetry should you enable for Device1?

A. hardware specifications
B. device cloud-only identity information
C. endpoint performance and user experience data
D. remote wipe status
Show Answer
Correct Answer: C
Explanation:
Advanced analytics features in Microsoft Intune, including Endpoint analytics, Application reliability, and Work from anywhere, rely on Windows diagnostic telemetry for endpoint performance and user experience. Enabling endpoint performance and user experience data (required diagnostic data) allows Device1 to contribute data for these reports. The other options do not provide the telemetry used by advanced analytics.

Question 4

You have an Android Enterprise fully managed device named Device1 that is enrolled in Microsoft Intune. Devicel is assigned a device profile. You plan to manage software updates for Device1 by using Android firmware over-the-air (FOTA). You discover that FOTA is unavailable for Device1. You need to manage software updates for Device1 by using Intune instead. What should you use?

A. an app configuration policy
B. an update ring
C. a device configuration profile
D. a device compliance policy
Show Answer
Correct Answer: C
Explanation:
For Android Enterprise fully managed devices, if Android FOTA is unavailable, software update behavior can be managed through an Intune device configuration profile (Device restrictions), which includes system update settings. Update rings are for Windows, app configuration policies do not manage OS updates, and compliance policies only evaluate/report compliance rather than configure update behavior.

Question 5

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft Entra tenant named contoso.com. You purchase an Android device named Device1. You need to register Device1 in contoso.com. Solution: You use Microsoft Entra Connect Sync. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Microsoft Entra Connect Sync synchronizes identities (users, groups, and supported devices) from on-premises Active Directory to Microsoft Entra ID. It is not used to register an Android device in Microsoft Entra. Android device registration is performed through Microsoft Intune/Company Portal or Microsoft Entra device registration workflows, not Entra Connect Sync.

Question 6

HOTSPOT - You have a Microsoft Entra tenant that contains the groups shown in the following table. Microsoft Intune is configured with the enrollment restrictions shown in the following table. You purchase the devices shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 6 Illustration for MD-102 question 6 Illustration for MD-102 question 6 Illustration for MD-102 question 6
Show Answer
Correct Answer: Yes No Yes
Explanation:
User2 is only affected by the Windows minimum-version restriction and Windows 11 meets it. User1 is subject to the Windows minimum-version restriction, so Windows 10 cannot enroll. Device3 is Windows 11, and since the devices were purchased by the organization, the personally owned device restriction does not block enrollment.

Question 7

You have a Microsoft 365 subscription that uses Microsoft Intune. You have a Google account. You plan to enroll Android devices in Intune. You need to configure Intune to apply a work profile to Android fully managed and corporate-owned devices. The solution must NOT affect personal Android devices enrolled in Intune. What should you do first?

A. Link your Google account to Intune.
B. Create a device platform restriction for Android device administrator.
C. Configure a device enrollment manager (DEM) account.
D. Configure an enrollment profile in Intune.
Show Answer
Correct Answer: A
Explanation:
Android Enterprise enrollment (including fully managed and corporate-owned work profile devices) requires first connecting the Intune tenant to a Managed Google Play account. Linking the Google account establishes this integration. Enrollment profiles are configured afterward, and DEM accounts or Android device administrator restrictions are not the prerequisite for Android Enterprise.

Question 8

You have a Microsoft 365 subscription that contains 1,000 Windows devices enrolled in Microsoft Intune. You have the apps shown in the following table. You need to deploy App1 to the devices. Which apps can you deploy by using Intune?

A. App1 only
B. App1 and App2 only
C. App1, App2, and App3 only
D. App1, App2, App3, and App4
Show Answer
Correct Answer: D
Explanation:
Current Microsoft Intune supports Win32 app packages up to 30 GB. Based on the updated limit, all four listed apps are within the supported deployment size, so each can be deployed.

Question 9

You have a Microsoft 365 subscription that contains a user named User1 and 500 Windows devices enrolled in Microsoft Intune. You configure an attack surface reduction (ASR) rule and enable the rule in Warn mode. User1 downloads a file named file1.exe. When User1 attempts to run file1.exe he receives a prompt that the content has been blocked. The user unblocks the content. How much time will pass until the user is prompted next to unblock the content?

A. 10 minutes
B. one hour
C. 24 hours
D. one week
Show Answer
Correct Answer: C
Explanation:
The correct answer is C. When an Attack Surface Reduction (ASR) rule is configured in Warn mode, users can choose to bypass the block. That bypass is remembered for 24 hours for the specific file, after which the user will be prompted again if the file triggers the same ASR rule.

Question 10

You have a Microsoft 365 subscription that uses Microsoft Intune. You need to ensure that users are prompted for multifactor authentication (MFA) when they enroll a personal device in Intune. The solution must minimize administrative effort. What should you create?

A. an attack surface reduction (ASR) policy
B. a device configuration profile
C. an authentication method policy
D. a Conditional Access policy
Show Answer
Correct Answer: D
Explanation:
A Conditional Access policy can require multifactor authentication during Intune enrollment for personal devices by targeting the Microsoft Intune Enrollment cloud app. This is the standard, centralized way to enforce MFA at enrollment with minimal administrative effort. ASR policies and device configuration profiles do not control enrollment authentication, and an authentication method policy configures available MFA methods rather than requiring MFA during enrollment.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.