Microsoft

MD-102 Free Practice Questions

This is the free Microsoft MD-102 practice question bank — 190 of 373 total questions, each with a full explanation, free to read with no signup required. Updated 2026-04-24.

Every answer is verified against official Microsoft documentation — see our methodology.

Question 1

You have a Microsoft 365 subscription that uses Microsoft Intune and contains a group named Group1. You have a line-of-business (LOB) app named App1 that supports in-app notifications. App1 is assigned to all the users in the subscription. You need to ensure that the users in Group1 receive a custom notification when they launch App1. What should you do?

A. Create an app configuration policy and assign the policy to Group1.
B. Edit the assignment for App1.
C. Create a device configuration profile and assign the profile to Group1.
D. Create an app protection policy and assign the policy to Group1.
Show Answer
Correct Answer: A
Explanation:
Custom or in-app notifications for a line-of-business app in Intune are delivered through app configuration policies. These policies allow you to define app-specific settings and behaviors, such as in-app messages, and target them to specific user groups like Group1. Editing the app assignment, using device configuration profiles, or app protection policies does not provide a mechanism to configure in-app notifications.

Question 2

HOTSPOT - You have a Microsoft 365 subscription that uses Microsoft Intune and contains a Microsoft Tunnel for Mobile Application. You have the devices shown in the following table. You need to ensure that you can use Tunnel for MAM on each device. The solution must minimize the number of apps required on each device. Which apps should you install on each device? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 2 Illustration for MD-102 question 2
Show Answer
Correct Answer: Device1: Microsoft Defender and Intune Company Portal Device2: Microsoft Defender only
Explanation:
For Tunnel for MAM on Android, the Microsoft Defender app provides the tunnel client, and Intune Company Portal is also required to support MAM-based policy and tunnel connectivity. On iOS, Tunnel for MAM functionality is delivered through the Microsoft Defender app alone, so no additional apps are required.

Question 3

You have a Microsoft 365 subscription that uses Microsoft Intune and has the following advanced analytics reports enabled: • Endpoint analytics • Application reliability • Work from anywhere You purchase a new device named Device1 that is enrolled in Intune. You need to ensure that advanced analytics reports can be generated for Device1. Which telemetry should you enable for Device1?

A. hardware specifications
B. device cloud-only identity information
C. endpoint performance and user experience data
D. remote wipe status
Show Answer
Correct Answer: C
Explanation:
Microsoft Intune advanced analytics (Endpoint analytics, Application reliability, and Work from anywhere) require collection of endpoint performance and user experience telemetry. Without this telemetry, Intune cannot generate the advanced analytics reports. The other options do not provide the performance and reliability data these reports depend on.

Question 4

You have an Android Enterprise fully managed device named Device1 that is enrolled in Microsoft Intune. Devicel is assigned a device profile. You plan to manage software updates for Device1 by using Android firmware over-the-air (FOTA). You discover that FOTA is unavailable for Device1. You need to manage software updates for Device1 by using Intune instead. What should you use?

A. an app configuration policy
B. an update ring
C. a device configuration profile
D. a device compliance policy
Show Answer
Correct Answer: C
Explanation:
When Android firmware over-the-air (FOTA) is unavailable on a fully managed Android Enterprise device, Intune can manage OS update behavior through Android device configuration profiles (specifically device restrictions). Update rings apply to Windows, compliance policies only evaluate settings, and app configuration policies do not control OS updates. Therefore, a device configuration profile is the correct choice.

Question 5

Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem. After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen. You have a Microsoft Entra tenant named contoso.com. You purchase an Android device named Device1. You need to register Device1 in contoso.com. Solution: You use Microsoft Entra Connect Sync. Does this meet the goal?

A. Yes
B. No
Show Answer
Correct Answer: B
Explanation:
Microsoft Entra Connect Sync is used to synchronize on‑premises Active Directory objects (users, groups, and Windows domain‑joined devices) to Microsoft Entra ID. It cannot be used to register an Android device directly in a cloud‑only Entra tenant. Android devices are registered or enrolled through Intune/Company Portal, not Entra Connect Sync.

Question 6

HOTSPOT - You have a Microsoft Entra tenant that contains the groups shown in the following table. Microsoft Intune is configured with the enrollment restrictions shown in the following table. You purchase the devices shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 6 Illustration for MD-102 question 6 Illustration for MD-102 question 6 Illustration for MD-102 question 6
Show Answer
Correct Answer: Yes No No
Explanation:
Restriction precedence applies when priorities are equal: the most restrictive settings win. User2 is in Group2 and Group1; Windows 11 meets the minimum OS, and MDM is allowed, so enrollment via Company Portal is permitted. User1’s Windows 10 device fails the minimum OS requirement for applicable restrictions, blocking automatic enrollment. User1’s Windows 11 device is blocked because personally owned devices are disallowed by the applicable restriction; Company Portal does not bypass restrictions.

Question 7

You have a Microsoft 365 subscription that uses Microsoft Intune. You have a Google account. You plan to enroll Android devices in Intune. You need to configure Intune to apply a work profile to Android fully managed and corporate-owned devices. The solution must NOT affect personal Android devices enrolled in Intune. What should you do first?

A. Link your Google account to Intune.
B. Create a device platform restriction for Android device administrator.
C. Configure a device enrollment manager (DEM) account.
D. Configure an enrollment profile in Intune.
Show Answer
Correct Answer: A
Explanation:
To manage Android Enterprise scenarios (work profiles, fully managed, and corporate-owned devices) in Intune, you must first establish the Android Enterprise connection by linking a Google account. Without linking a Google account, Intune cannot create or manage work profiles or fully managed Android Enterprise devices. This step does not affect personal devices by itself; it only enables Android Enterprise management capabilities.

Question 8

You have a Microsoft 365 subscription that contains 1,000 Windows devices enrolled in Microsoft Intune. You have the apps shown in the following table. You need to deploy App1 to the devices. Which apps can you deploy by using Intune?

A. App1 only
B. App1 and App2 only
C. App1, App2, and App3 only
D. App1, App2, App3, and App4
Show Answer
Correct Answer: D
Explanation:
Microsoft Intune Win32 app content size limit was increased to 30 GB (source files) as of early 2024. Given this limit, all listed apps—including the largest 30‑GB app—can be deployed using Intune. Therefore, App1, App2, App3, and App4 are all deployable.

Question 9

You have a Microsoft 365 subscription that contains a user named User1 and 500 Windows devices enrolled in Microsoft Intune. You configure an attack surface reduction (ASR) rule and enable the rule in Warn mode. User1 downloads a file named file1.exe. When User1 attempts to run file1.exe he receives a prompt that the content has been blocked. The user unblocks the content. How much time will pass until the user is prompted next to unblock the content?

A. 10 minutes
B. one hour
C. 24 hours
D. one week
Show Answer
Correct Answer: C
Explanation:
In Microsoft Defender Attack Surface Reduction rules configured in Warn mode, when a user chooses to bypass (unblock) the warning, the bypass is cached for 24 hours. During this period, the user will not be prompted again for the same action. After 24 hours, the warning prompt will reappear if the action is attempted again.

Question 10

You have a Microsoft 365 subscription that uses Microsoft Intune. You need to ensure that users are prompted for multifactor authentication (MFA) when they enroll a personal device in Intune. The solution must minimize administrative effort. What should you create?

A. an attack surface reduction (ASR) policy
B. a device configuration profile
C. an authentication method policy
D. a Conditional Access policy
Show Answer
Correct Answer: D
Explanation:
To require users to perform multifactor authentication during Intune enrollment of personal devices with minimal administrative effort, you must control access to the cloud service involved in enrollment. Conditional Access policies are designed to enforce MFA based on conditions such as user, device state, and cloud app (for example, Microsoft Intune enrollment or Microsoft Entra device registration). ASR policies and device configuration profiles apply after enrollment, and authentication method policies only define available methods, not when MFA is enforced. Therefore, a Conditional Access policy is the correct solution.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.