HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
The subscription contains the dynamic device groups shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Group1 requires deviceTrustType = AzureAD and deviceOSType = Windows. Only Microsoft Entra joined Windows devices match, not hybrid joined (ServerAD). Group2 requires deviceTrustType = Workplace, which corresponds to Microsoft Entra registered devices.
Question 97
You have a Microsoft 365 E5 subscription that contains devices enrolled in Microsoft Intune.
You plan to use Device query to provide on-demand information about the state of the devices. The solution must minimize costs.
What should you do first?
A. Use the Collect diagnostics remote action.
B. Purchase the Intune Advanced Analytics add-on.
C. Purchase the Intune Suite add-on.
D. Onboard the devices to Endpoint analytics.
Show Answer
Correct Answer: B
Explanation: Device query requires licensing that includes Microsoft Intune Advanced Analytics. Microsoft 365 E5 includes Endpoint analytics, but not the Intune Advanced Analytics add-on required to enable Device query. Intune Suite also includes the feature, but to minimize cost, purchase the standalone Intune Advanced Analytics add-on first. After licensing, devices can be onboarded to Endpoint analytics if not already enrolled.
Question 98
You have a Microsoft 365 subscription and use Microsoft Intune Suite.
The subscription contains devices enrolled in Intune as shown in the following table.
Which devices support Device query?
A. Device1 only
B. Device2 only
C. Device1 and Device2 only
D. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation: Device query in Microsoft Intune Suite supports only corporate-owned, Intune-managed Windows 10/11 devices that are enrolled in Endpoint Analytics and are Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra registered (workplace joined) devices are not supported, and iOS/Android devices do not support Device query. Therefore, only Device1 qualifies.
Question 99
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You need to deploy new Android devices as shown in the following table.
Which enrollment profile should you use for each device? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: Corporate-owned dedicated devices
Device2: Corporate-owned, fully managed user devices
Device3: Corporate-owned devices with work profile
Explanation: Dedicated devices are for shared/kiosk scenarios. Fully managed user devices are for a single user with work-only use. Corporate-owned devices with work profile (COPE) support both work and personal use and can be enrolled via QR code.
Question 100
DRAG DROP
-
You have a Microsoft 365 subscription.
You plan to enroll devices in Microsoft Intune.
You need to meet the following requirements:
• Only allow the enrollment of devices that have a specific international mobile equipment identifier (IMEI).
• Support the enrollment and management of up to 1,000 devices.
Which enrollment setting should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Only allow the enrollment of devices with a specific IMEI: Corporate device identifiers
Support the enrollment and management of up to 1,000 devices: Device enrollment managers
Explanation: Corporate device identifiers let you whitelist corporate-owned devices by IMEI. Device Enrollment Manager (DEM) accounts can enroll and manage up to 1,000 devices.
Question 101
HOTSPOT
-
You have a Microsoft 365 subscription that includes Microsoft Intune and Microsoft Defender for Endpoint.
Users have devices that run Windows 11.
You deploy a connection from Defender for Endpoint to Intune.
You need to ensure that when a device is enrolled in Intune, the device is onboarded automatically to Defender for Endpoint.
What should you configure, and which portal should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Configure: An endpoint detection and response (EDR) profile
In portal: Microsoft Intune admin center
Explanation: With the Defender for Endpoint–Intune connection configured, Windows 11 devices are onboarded automatically by deploying an Intune Endpoint detection and response (EDR) policy/profile. A separate onboarding package is for manual or non-Intune onboarding.
Question 102
HOTSPOT
-
You have a Microsoft Entra tenant that contains the users shown in the following table.
When you sign in to the tenant, the available verification methods are shown in the following exhibit.
Which users will be prompted for the verification code method, and which users will be prompted for the text method? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Verification code:
User2, User3, and User4 only
Text:
User1 only
Explanation: 'Use a verification code' is available for users with a Software OATH token. 'Text' requires a registered mobile phone for SMS. User1 has only a mobile phone; Users2–4 have Software OATH tokens, while only User4's passwordless capability does not remove the OATH method option.
Question 103
DRAG DROP
-
You have a Microsoft 365 subscription that contains the following devices enrolled in Microsoft Intune:
• A corporate-owned Windows device named Device1
• A personally-owned Android device named Device2
You need to use a remote action on each device. The solution must meet the following requirements:
• Repurpose Device1 by returning the device to the factory default settings.
• Remove only corporate data from Device2 and remove the device from Intune when the device checks in.
Which remote action should you use on each device? To answer, drag the appropriate remote actions to the correct devices. Each remote action may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
Show Answer
Correct Answer: Device1: Wipe
Device2: Retire
Explanation: Wipe restores a Windows device to factory default settings, making it suitable for repurposing. Retire removes only corporate data and unenrolls a personally owned Android device from Intune when it next checks in.
Question 104
You have a Microsoft 365 E5 subscription.
All Windows devices are enrolled in Microsoft Intune.
You need to deploy the Remote Help app to all the devices. The solution must minimize administrative effort.
Which type of app should you deploy?
A. Windows app (Win32)
B. line-of-business (LOB)
C. Microsoft 365
D. Microsoft Store
Show Answer
Correct Answer: D
Explanation: For minimizing administrative effort, deploy Remote Help as a Microsoft Store app through Intune (including via the Enterprise App Catalog integration where applicable). This provides simplified deployment and automatic updates, whereas packaging it as a Win32 app requires more administrative maintenance. Older guidance used Win32 before Remote Help became available through the Microsoft Store integration.
Question 105
You have a Microsoft 365 E5 subscription.
You need to manage operating system updates for corporate-owned Android Enterprise devices enrolled in Microsoft Intune.
What should you use?
A. a compliance policy
B. an Android FOTA deployment
C. an Endpoint security policy
D. a configuration profile
Show Answer
Correct Answer: D
Explanation: The best answer is D. With a Microsoft 365 E5 subscription, Intune can manage Android system update behavior through a device configuration profile (Device restrictions > System update). Android FOTA deployment is a separate feature that depends on OEM support and typically requires Intune Plan 2 or Intune Suite. Because the question specifies only Microsoft 365 E5 and asks generally how to manage OS updates for corporate-owned Android Enterprise devices, a configuration profile is the appropriate choice. Compliance policies and Endpoint security policies do not manage Android OS update settings.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.