You have a Microsoft Intune subscription.
You have devices enrolled in Intune as shown in the following table.
An app named App1 is installed on each device.
What is the minimum number of app configuration policies required to manage App1?
A. 1
B. 2
C. 3
D. 4
E. 5
Show Answer
Correct Answer: B
Explanation: App configuration policies in Microsoft Intune are platform-specific. A single policy cannot target both Android and iOS/iPadOS. Therefore, if App1 must be managed on both Android and iOS devices, the minimum required is one Android app configuration policy and one iOS/iPadOS app configuration policy, for a total of two policies.
Question 107
You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune.
You plan to manage Microsoft Defender for Endpoint on the computers.
You need to prevent users from disabling Microsoft Defender for Endpoint.
What should you do?
A. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
B. From the Microsoft Intune admin center, create an account protection policy.
C. From the Microsoft Defender portal, enable tamper protection.
D. From the Microsoft Intune admin center, create a device compliance policy.
Show Answer
Correct Answer: C
Explanation: Tamper protection prevents users and malware from changing critical Microsoft Defender security settings, including disabling Microsoft Defender for Endpoint. It is managed from the Microsoft Defender portal. ASR policies reduce attack surface but do not prevent disabling Defender, account protection policies manage identity/security settings, and compliance policies only evaluate device state.
Question 108
HOTSPOT
-
You have a Microsoft 365 E5 subscription. All devices are enrolled in Microsoft Intune.
You have a device group named Group1 that contains five Windows 11 devices.
You need to ensure that the devices in Group1 automatically receive new Windows 11 builds before the builds are released to the public.
What should you configure in Intune? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Profile type: Update rings for Windows 10 and later
Prerelease channel: Windows Insider - Release Preview
Explanation: Windows Insider prerelease channels are configured through Update rings. To receive new Windows builds before public release with the most stable prerelease option, use the Windows Insider - Release Preview channel.
Question 109
You have a Microsot Entra tenant named contoso.com.
You have a workgroup computer named Computer1 that runs Windows 11.
You need to add Computer1 to contoso.com.
What should you use?
A. the Settings app
B. Computer Management
C. netdom.exe
Show Answer
Correct Answer: A
Explanation: To add a Windows 11 workgroup computer to a Microsoft Entra (formerly Azure AD) tenant, you use the Settings app: Settings > Accounts > Access work or school > Connect, then choose to join the device to Microsoft Entra ID. Computer Management cannot join devices to Entra ID, and netdom.exe is used for Active Directory domain operations, not Microsoft Entra join.
Question 110
You have a Microsoft 365 subscription.
You have 10 computers that run Windows 10 and are enrolled in Microsoft Intune.
You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers.
What should you do?
A. From the Microsoft Intune admin center, add an app.
B. From the Microsoft Intune admin center, create a Windows 10 and later device profile.
C. From the Microsoft Entra admin center, add an enterprise application.
D. From the Microsoft Entra admin center, add an app registration.
Show Answer
Correct Answer: A
Explanation: Microsoft 365 Apps for enterprise is deployed to Intune-managed Windows devices by creating a Microsoft 365 Apps app deployment in the Microsoft Intune admin center under Apps > Windows > Add. Device profiles configure settings, not app deployment, and Microsoft Entra enterprise applications/app registrations are for identity and application integration rather than software installation.
Question 111
You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices that are joined to Microsoft Entra.
You purchase Microsoft 365 E5 licenses for all users.
You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort.
Which upgrade method should you use?
A. a Microsoft Deployment Toolkit (MDT) lite-touch deployment
B. Subscription Activation
C. an in-place upgrade by using Windows installation media
D. Windows Autopilot
Show Answer
Correct Answer: B
Explanation: Subscription Activation automatically steps eligible, Microsoft Entra-joined Windows Pro devices up to Windows Enterprise when users with qualifying Microsoft 365 E5 licenses sign in. This requires minimal administration and avoids reimaging or in-place OS deployment. MDT, installation media, and Windows Autopilot are deployment/provisioning methods rather than the simplest license-based edition upgrade.
Question 112
You have a Microsoft 365 E5 subscription.
You have a Windows device named Device1 that is enrolled in Microsoft Intune.
On January 1,2024, you assign an app named App1 to Device1 as a required app.
The install of App1 fails.
What is the next date that Intune will attempt to install App1?
A. January 2, 2024
B. January 5, 2024
C. January 8, 2024
D. January 31, 2024
Show Answer
Correct Answer: A
Explanation: For required apps on Windows devices, Intune retries failed installations automatically. After the initial retry logic, failed required app installations are retried every 24 hours. Therefore, if the assignment occurs and the installation fails on January 1, the next retry date is January 2, 2024.
Question 113
HOTSPOT
-
You have a Microsoft 365 subscription that includes Microsoft Intune.
From the Microsoft Intune admin center, you add the apps shown in the following table.
You need to configure the apps to meet the following requirements:
• App1 must automatically install for all users in the marketing department on any Windows 11 device enrolled in Intune. If a user receives a new device, App1 must install automatically.
• App2 must be available for download for any user in the HR department from a personal Android device that is not enrolled in Intune.
Which assignment should you configure for each app? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: App1: A Required assignment to a user group
App2: An Available assignment to a user group
Explanation: Required user assignments follow users across enrolled devices, meeting the automatic installation requirement for marketing users on any new Windows 11 device. Available user assignments let HR users access the Android app from the Company Portal without forcing installation.
Question 114
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Intune. The subscription contains a Microsoft Entra tenant that syncs with an on-premises Active Directory Domain Services (AD DS) domain. The tenant has Windows Local Administrator Password Solution (Windows LAPS) enabled.
You have the Windows devices shown in the following table.
You have an Endpoint security policy that is configured as shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Windows LAPS with password backup set to Microsoft Entra ID (Azure AD) only requires Microsoft Entra joined or hybrid joined devices. A purely AD DS-joined device cannot use Azure-only backup. Device2 is hybrid joined and Intune-enrolled, so its password is backed up and recoverable from Microsoft Entra ID. Device3 is not enrolled in Intune, so the Intune LAPS policy is not applied.
Question 115
HOTSPOT
-
You have an Azure subscription that is linked to a Microsoft Entra tenant. The tenant contains the devices shown in the following table.
You install the Azure Monitor Agent on all supported devices.
You create a monitored object (MO) and associate the MO to a data collection rule (DCR) named DCR1.
You configure DCR1 as shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Show Answer
Correct Answer: Device1: No
Device2: Yes
Device3: No
Explanation: AMA monitored objects with DCRs for client devices support Windows (Entra joined/hybrid joined) but not Entra registered Windows devices for this scenario, and Android doesn't support Windows performance counters. The DCR collects CPU and Memory counters, so only the Entra-joined Windows device collects the requested memory data.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.