You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
All the devices are enrolled in Microsoft Intune and have Microsoft 365 Apps for enterprise installed.
On which devices can you use the Cloud Policy service for Microsoft 365 to manage Microsoft 365 Apps for enterprise?
A. Device2 only
B. Device1 and Device2 only
C. Device1, Device2, and Device3 only
D. Device1, Device2, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: E
Explanation: The Cloud Policy service for Microsoft 365 applies user-based Microsoft 365 Apps for enterprise policies across supported platforms (Windows, macOS, iOS, and Android). It does not require devices to be domain joined or otherwise managed beyond users signing into Microsoft 365 Apps with supported clients. Since all four devices are enrolled in Intune and have Microsoft 365 Apps for enterprise installed, all are supported.
Question 117
HOTSPOT
-
You have a Microsoft 365 E5 subscription that includes Microsoft Intune.
You need to configure a compliance policy for the iOS/iPadOS platform. The solution must meet the following requirements:
• Require jailbroken devices to be marked as noncompliant.
• Mark devices without a password lock as noncompliant.
Which compliance policy settings should you configure for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Require jailbroken devices to be marked as noncompliant: Device Health
Require a password to unlock mobile devices: System Security
Explanation: In Intune iOS/iPadOS compliance policies, jailbreak detection is configured under Device Health, while requiring a device passcode is configured under System Security.
Question 118
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to route Microsoft Intune logs to an Azure resource that supports the use of visuals, monitoring, and alerting.
Which settings should you configure in Intune, and which resource should you use? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Settings: Diagnostic settings
Resource: A Log Analytics workspace
Explanation: Intune diagnostic settings can stream logs to Azure Monitor destinations. For visualization, monitoring, and alerting, the appropriate destination is an Azure Log Analytics workspace.
Question 119
You have a Microsoft 365 E5 subscription.
You need to configure the automated investigation and response (AIR) remediation level for a device named Device1 to require approval for all folders.
What should you create?
A. a security group
B. a device group
C. an administrative unit
D. an action group
Show Answer
Correct Answer: B
Explanation: Automated investigation and response (AIR) remediation levels in Microsoft Defender for Endpoint are configured at the device group level. To require approval for all folders for Device1, create a device group with the remediation level set to 'Require approval for all folders' and place Device1 in that device group.
Question 120
HOTSPOT
-
You have a Microsoft 365 E5 subscription and use Microsoft Intune.
You purchase 50 Windows devices.
You configure automatic enrollment to Intune for Microsoft Entra joined devices.
You need to use a provisioning package to join the devices to Microsoft Entra.
What should you use to create the provisioning package, and what is the maximum amount of time you can use the package for bulk enrollment? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Use: Windows Configuration Designer
Maximum amount of time: 180 days
Explanation: Provisioning packages for Microsoft Entra bulk enrollment are created with Windows Configuration Designer. The bulk enrollment token used in the provisioning package is valid for a maximum of 180 days.
Question 121
HOTSPOT
-
Your network contains an on-premises Active Directory Domain Services (AD DS) domain.
You have a Microsoft 365 E5 subscription that includes Microsoft Intune and syncs with the AD DS domain.
Windows Local Administrator Password Solution (Windows LAPS) is enabled in Microsoft Entra ID.
The subscription has the custom roles shown in the following table.
Microsoft Entra contains the users shown in the following table.
You have the devices shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Only Microsoft Entra hybrid-joined and Entra-joined devices can store Windows LAPS passwords in Microsoft Entra ID. A password can be read only with the deviceLocalCredentials/password/read permission. Role1 has password/read but Device1 is only AD DS joined. Role2 has only standard/read (metadata only), so it cannot read Device2's password. Role3 includes password/read, so User3 can read Device3's password.
Question 122
HOTSPOT
-
You have a Microsoft 365 tenant that uses Microsoft Intune to manage the devices shown in the following table.
You need to deploy a compliance solution that meets the following requirements:
• Marks the devices as Not Compliant if they do not meet compliance policies
• Remotely locks noncompliant devices
What is the minimum number of compliance policies required, and which devices support the remote lock action? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: 4
Device2, Device3, Device4, and Device5
Explanation: Compliance policies are platform-specific: Windows, Android device administrator, Android Enterprise, and iOS/iPadOS (shared), requiring four policies. The remote lock action is supported for Android Device Administrator, Android Enterprise, iOS, and iPadOS, but not Windows desktop.
Question 123
HOTSPOT
-
You have a Microsoft Entra tenant that contains the devices shown in the following table.
The tenant contains the groups shown in the following table.
You create a Windows Autopilot deployment profile as shown in the Deployment Profile exhibit. (Click the Deployment Profile tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: No
Device2: Yes
Device3: No
Explanation: 'Convert all targeted devices to Autopilot = Yes' registers targeted corporate, non-Autopilot devices. Personal (Entra registered) devices aren't automatically registered. Group1 is included, but Group2 is excluded, and exclusions override inclusions.
Question 124
You have a Microsoft 365 E5 subscription.
All devices are enrolled in Microsoft Intune.
You create a Conditional Access policy named Policy1 that requires multifactor authentication (MFA).
You need to ensure that Policy1 only applies to devices marked as noncompliant.
Which settings of Policy1 should you configure?
A. Device platforms under Conditions
B. Filter for devices under Conditions
C. Target resources
D. Grant
E. Session
Show Answer
Correct Answer: B
Explanation: Use the Conditional Access policy's Conditions > Filter for devices to scope the policy so it only applies to devices where the device compliance property indicates noncompliance (for example, filtering on isCompliant). The Grant control is where you require MFA, but it does not determine that the policy targets only noncompliant devices; 'Require device to be marked as compliant' would instead enforce compliance as an access requirement rather than scope the policy to noncompliant devices.
Question 125
You have a Microsoft 365 E5 subscription.
All devices are enrolled in Microsoft Intune.
You need to ensure that devices that have NOT checked in for 30 days are deleted from Intune.
What should you configure from the Microsoft Intune admin center?
A. a device limit restriction
B. automatic enrollment
C. a device clean-up rule
D. a configuration profile
Show Answer
Correct Answer: C
Explanation: Configure a device clean-up rule in the Microsoft Intune admin center. Device clean-up rules automatically remove stale devices that have not checked in for a specified number of days, such as 30. Device limit restrictions control how many devices a user can enroll, automatic enrollment configures enrollment behavior, and configuration profiles apply settings but do not delete inactive devices.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.