You have a Microsoft 365 E5 subscription.
All devices are enrolled in Microsoft Intune.
You need to ensure that devices that have NOT checked in for 30 days are deleted from Intune.
What should you configure from the Microsoft Intune admin center?
A. a device limit restriction
B. automatic enrollment
C. a device clean-up rule
D. a configuration profile
Show Answer
Correct Answer: C
Explanation: Intune provides Device cleanup rules that automatically delete devices which have not checked in for a specified number of days. Configuring a cleanup rule with a 30‑day threshold meets the requirement. Other options do not control automatic deletion based on inactivity.
Question 125
You have a Microsoft 365 E5 subscription.
You use Microsoft Intune to manage all Windows 11 devices.
You create an attack surface reduction (ASR) policy named Profile1 based on the Attack Surface Reduction Rules profile and assign Profile1 to all the devices.
A user reports that an Adobe Reader plug-in is now blocked.
You need to ensure that the plug-in is unblocked.
What should you do?
A. Create an Endpoint Privilege Management policy and assign the policy to all the devices.
B. Add a scope tag to Profile1.
C. Configure ASR Only Per Rule Exclusions in Profile1.
D. Create a device compliance policy and assign the policy to all the devices.
Show Answer
Correct Answer: C
Explanation: The Adobe Reader plug-in is being blocked by an Attack Surface Reduction (ASR) rule. To unblock a specific application or plug-in while keeping the ASR rules enabled, you must configure ASR per-rule exclusions in the existing ASR policy (Profile1). This allows the plug-in executable or path to be excluded from the specific ASR rule causing the block. The other options do not modify ASR behavior.
Question 126
You have a Microsoft 365 E5 subscription.
All Windows devices are enrolled in Microsoft Intune.
You need to create an app protection policy named Policy1 and apply Policy1 to the devices.
What can you protect by using Policy1?
A. Microsoft Outlook
B. Microsoft OneDrive
C. Microsoft Teams
D. Microsoft Edge
Show Answer
Correct Answer: D
Explanation: For Windows devices, Intune App Protection Policies (MAM) are very limited compared to iOS and Android. On the Windows platform, the only supported app that can be targeted by an app protection policy is Microsoft Edge. Outlook, OneDrive, and Teams on Windows rely on device-based management rather than app protection policies. Therefore, Policy1 can protect Microsoft Edge only.
Question 127
You have a Microsoft 365 subscription that includes Microsoft Intune.
You create a new Android app protection policy named Policy1 that prevents screen captures in all Microsoft apps.
You discover that an unmanaged email client installed on Android devices can still capture screens.
You need to ensure that users can only use Microsoft apps to access email.
What should you do?
A. Create a Conditional Access policy.
B. Create a compliance policy.
C. Modify the Data protection settings of Policy1.
D. Modify the assignments of Policy1.
Show Answer
Correct Answer: A
Explanation: App protection policies only control behavior inside managed apps and cannot stop an unmanaged email client from accessing Exchange or capturing the screen. To ensure users can only access email through Microsoft apps (such as Outlook) and block unmanaged clients, you must use a Conditional Access policy. Conditional Access can require approved or Intune-protected apps for Exchange Online access, effectively preventing unmanaged email clients from being used.
Question 128
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You use Microsoft Intune to manage Windows 365 Cloud PC devices.
You need to deploy a Windows 365 Security Baseline to the Cloud PC devices. The solution must meet the following requirements:
• Block data execution prevention.
• Enable virtualization-based security (VBS) and Secure Boot.
What should you configure for the Windows 365 Security Baseline profile? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: File Explorer
Device Guard
Explanation: In the Windows 365 Security Baseline, Data Execution Prevention is controlled by the **File Explorer** setting ("Turn off Data Execution Prevention for Explorer"), which remains disabled to block execution. Virtualization-based security and Secure Boot are enabled under **Device Guard**, where VBS options are configured.
Question 129
You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains corporate-owned, fully managed Android Enterprise devices.
You plan to deploy a configuration profile that will have a device restrictions profile type named Profile1. Profile1 will assign maintenance windows for system updates.
What should you configure from the Configuration settings for Profile1?
A. Device experience
B. General
C. Connectivity
D. Power Settings
Show Answer
Correct Answer: B
Explanation: For corporate-owned, fully managed Android Enterprise devices, the maintenance window for system updates is configured in an Intune Device restrictions profile under **General**. The path is Android Enterprise > Device restrictions > General > System update > Maintenance window.
Question 130
You have a Microsoft 365 E5 subscription that uses Microsoft Intune.
You configure Intune to send log data to Log Analytics.
You need to review events involving devices that fail to enroll in Intune.
What should you monitor?
A. operational logs
B. audit logs
C. the Intune Device log
D. device compliance organizational logs
Show Answer
Correct Answer: A
Explanation: Intune Operational logs (sent to Log Analytics) record the success and failure of device enrollment events, including reasons why devices fail to enroll. Audit logs track administrative changes, while device compliance or device-specific logs do not focus on enrollment failures.
Question 131
You have a Microsoft 365 subscription that includes Microsoft Intune. The subscription contains Windows 11 devices enrolled in Intune. The subscription contains three groups named Departement1, Department2, and Department3.
You need to deploy Microsoft 365 Apps to the Windows 11 devices. The solution must meet the following requirements:
• Users in Department1 and Department2 must receive the full Microsoft 365 Apps suite, including Microsoft Project and Visio.
• Users in Department3 must receive the full Microsoft 365 Apps suite, including Microsoft Project, but without Visio.
• All other users must receive the full Microsoft 365 Apps suite without Microsoft Project or Visio.
What is the minimum number of deployments you should create?
A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: C
Explanation: Different app inclusion requirements require separate Intune app deployments. One deployment targets Department1 and Department2 with Microsoft 365 Apps + Project + Visio. A second deployment targets Department3 with Microsoft 365 Apps + Project (without Visio). A third deployment targets all remaining users with Microsoft 365 Apps without Project or Visio. This is the minimum needed to meet all requirements.
Question 132
You have a Microsoft 365 E5 subscription that includes Microsoft Intune and contains a user named Admin1.
Admin1 must use the Microsoft Intune admin center to perform the following tasks:
• Create and assign apps and policies to users and devices by using Intune.
• Create, assign, and delete Windows 365 Cloud PC provisioning policies.
You need to assign the required roles to Admin1. The solution must meet the following requirements:
• Follow the principle of least privilege.
• Minimize administrative effort.
What should you do?
A. Assign Admin1 the Help Desk Operator role.
B. Assign Admin1 the Cloud PC Reader role.
C. Assign Admin1 the Cloud PC Administrator role.
D. Create a custom Microsoft Entra role and assign the role to Admin1.
E. Create a custom Intune role and assign the role to Admin1.
Show Answer
Correct Answer: E
Explanation: Admin1 needs permissions to manage Intune apps/policies and to create, assign, and delete Windows 365 Cloud PC provisioning policies. No single built-in role (including Cloud PC Administrator) fully covers general Intune app and policy creation/assignment while also adhering to least privilege. Creating a custom Intune role allows granting exactly the required Intune and Windows 365 permissions, meeting least privilege; other options either lack required permissions or grant unnecessary access.
Question 133
HOTSPOT
-
You have a Microsoft 365 E5 subscription that includes Microsoft Intune. The subscription contains a group named Group1. Group1 contains devices enrolled in Intune.
You deploy Remote Help in Intune.
You need to configure Remote Help to only allow support administrators to join Remote Help sessions from the devices in Group1.
Which type of Microsoft Entra object should you create, and which type of policy should you configure? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: A service principal
Conditional Access
Explanation: Remote Help access is controlled through its backend service represented by a service principal in Microsoft Entra. A Conditional Access policy targeting that service principal can restrict which administrators and which devices (such as those in Group1) are allowed to join Remote Help sessions.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.