Microsoft

MD-102 Free Practice Questions — Page 11

Question 104

You have a Microsoft 365 E5 subscription. You need to manage operating system updates for corporate-owned Android Enterprise devices enrolled in Microsoft Intune. What should you use?

A. a compliance policy
B. an Android FOTA deployment
C. an Endpoint security policy
D. a configuration profile
Show Answer
Correct Answer: D
Explanation:
For corporate-owned Android Enterprise devices in Microsoft Intune, operating system update management is done through device restrictions in a configuration profile. Configuration profiles let you control system update behavior such as postponement and maintenance windows and are supported across all OEMs. Android FOTA deployments require additional licensing and OEM support and are not universally available, so the generally correct and supported method is a configuration profile.

Question 105

You have a Microsoft Intune subscription. You have devices enrolled in Intune as shown in the following table. An app named App1 is installed on each device. What is the minimum number of app configuration policies required to manage App1?

A. 1
B. 2
C. 3
D. 4
E. 5
Show Answer
Correct Answer: B
Explanation:
Intune app configuration policies are platform-specific. Since App1 is installed on devices running two platforms (Android and iOS), a minimum of one app configuration policy is required per platform. Therefore, one policy for Android devices and one policy for iOS devices are sufficient, totaling two policies.

Question 106

You have a Microsoft 365 subscription that contains 500 computers that run Windows 11. The computers are Microsoft Entra joined and are enrolled in Microsoft Intune. You plan to manage Microsoft Defender for Endpoint on the computers. You need to prevent users from disabling Microsoft Defender for Endpoint. What should you do?

A. From the Microsoft Intune admin center, create an attack surface reduction (ASR) policy.
B. From the Microsoft Intune admin center, create an account protection policy.
C. From the Microsoft Defender portal, enable tamper protection.
D. From the Microsoft Intune admin center, create a device compliance policy.
Show Answer
Correct Answer: C
Explanation:
To prevent users from disabling Microsoft Defender for Endpoint, you must enable Tamper Protection. Tamper protection blocks users (even local admins) and malicious processes from turning off or modifying critical Defender for Endpoint security settings. This setting is configured and enforced from the Microsoft Defender portal, not through Intune ASR, account protection, or compliance policies.

Question 107

HOTSPOT - You have a Microsoft 365 E5 subscription. All devices are enrolled in Microsoft Intune. You have a device group named Group1 that contains five Windows 11 devices. You need to ensure that the devices in Group1 automatically receive new Windows 11 builds before the builds are released to the public. What should you configure in Intune? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 107
Show Answer
Correct Answer: Profile type: Update rings for Windows 10 and later Prerelease channel: Windows Insider – Release Preview
Explanation:
Update rings allow configuring Windows Insider settings via Intune. The Release Preview channel delivers upcoming Windows 11 builds before public release with higher stability than Beta or Dev channels, suitable for early validation.

Question 108

You have a Microsot Entra tenant named contoso.com. You have a workgroup computer named Computer1 that runs Windows 11. You need to add Computer1 to contoso.com. What should you use?

A. the Settings app
B. Computer Management
C. netdom.exe
Show Answer
Correct Answer: A
Explanation:
To add a Windows 11 workgroup computer to a Microsoft Entra (Azure AD) tenant, you perform an Entra join. In Windows 11, Entra join is done through the Settings app under Accounts > Access work or school. Computer Management and netdom.exe are used for on-premises Active Directory domain joins, not Microsoft Entra.

Question 109

You have a Microsoft 365 subscription. You have 10 computers that run Windows 10 and are enrolled in Microsoft Intune. You need to deploy the Microsoft 365 Apps for enterprise suite to all the computers. What should you do?

A. From the Microsoft Intune admin center, add an app.
B. From the Microsoft Intune admin center, create a Windows 10 and later device profile.
C. From the Microsoft Entra admin center, add an enterprise application.
D. From the Microsoft Entra admin center, add an app registration.
Show Answer
Correct Answer: A
Explanation:
Microsoft 365 Apps for enterprise are deployed to Intune-enrolled Windows 10 devices by adding an app in the Microsoft Intune admin center. Specifically, you add a Windows app of type "Microsoft 365 Apps for Windows 10 and later" and assign it to the target devices or users. Device profiles, Entra enterprise applications, and app registrations are not used for software deployment to Windows endpoints.

Question 110

You have a Microsoft 365 Business Standard subscription and 100 Windows 10 Pro devices that are joined to Microsoft Entra. You purchase Microsoft 365 E5 licenses for all users. You need to upgrade the Windows 10 Pro devices to Windows 10 Enterprise. The solution must minimize administrative effort. Which upgrade method should you use?

A. a Microsoft Deployment Toolkit (MDT) lite-touch deployment
B. Subscription Activation
C. an in-place upgrade by using Windows installation media
D. Windows Autopilot
Show Answer
Correct Answer: B
Explanation:
Subscription Activation automatically upgrades Windows 10 Pro to Windows 10 Enterprise when users sign in with eligible Microsoft 365 E5 licenses on Entra-joined devices. It requires no reimaging or deployment workflows, making it the lowest administrative effort compared to MDT, in-place upgrades, or Autopilot.

Question 111

You have a Microsoft 365 E5 subscription. You have a Windows device named Device1 that is enrolled in Microsoft Intune. On January 1,2024, you assign an app named App1 to Device1 as a required app. The install of App1 fails. What is the next date that Intune will attempt to install App1?

A. January 2, 2024
B. January 5, 2024
C. January 8, 2024
D. January 31, 2024
Show Answer
Correct Answer: A
Explanation:
For a required app in Intune, if installation fails, the client performs several immediate retries (multiple attempts spaced minutes apart). After these fail, Intune retries the installation once every 24 hours. Since the initial assignment and failure occurred on January 1, 2024, the next retry date is January 2, 2024.

Question 112

HOTSPOT - You have a Microsoft 365 subscription that includes Microsoft Intune. From the Microsoft Intune admin center, you add the apps shown in the following table. You need to configure the apps to meet the following requirements: • App1 must automatically install for all users in the marketing department on any Windows 11 device enrolled in Intune. If a user receives a new device, App1 must install automatically. • App2 must be available for download for any user in the HR department from a personal Android device that is not enrolled in Intune. Which assignment should you configure for each app? To answer, select the appropriate options in the answer area. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 112 Illustration for MD-102 question 112
Show Answer
Correct Answer: App1: A Required assignment to a user group App2: An Available assignment to a user group
Explanation:
App1 must automatically install for all users in the marketing department and follow users to any new Windows 11 device, which requires a required user-based assignment. App2 must be optionally downloadable by HR users on personal, unenrolled Android devices, which requires an available user-based assignment.

Question 113

HOTSPOT - You have a Microsoft 365 E5 subscription and use Microsoft Intune. The subscription contains a Microsoft Entra tenant that syncs with an on-premises Active Directory Domain Services (AD DS) domain. The tenant has Windows Local Administrator Password Solution (Windows LAPS) enabled. You have the Windows devices shown in the following table. You have an Endpoint security policy that is configured as shown in the following table. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.

Illustration for MD-102 question 113 Illustration for MD-102 question 113 Illustration for MD-102 question 113
Show Answer
Correct Answer: Device1: No Device2: Yes Device3: No
Explanation:
Windows LAPS with backup to Microsoft Entra ID requires devices to be Microsoft Entra joined or hybrid joined and managed by Intune. - Device1 is only AD DS–joined, so Azure AD (Entra ID) backup isn’t supported; the reset won’t apply. - Device2 is Entra hybrid joined and Intune-enrolled, so the password is backed up and recoverable from Entra ID. - Device3 is Entra joined but not Intune-enrolled, so the Intune policy doesn’t apply and no reset occurs.

$19

Get all 373 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.