Your company has a Microsoft 365 subscription.
All the users in the finance department own personal devices that run iOS or Android. All the devices are enrolled in Microsoft Intune.
The finance department adds new users each month.
The company develops a mobile application named App1 for the finance department users.
You need to ensure that only the finance department users can download App1.
What should you do first?
A. Register App1 in Azure AD.
B. Add App1 to the vendor stores for iOS and Android applications.
C. Add App1 to a Microsoft Deployment Toolkit (MDT) deployment share.
D. Add App1 to Intune.
Show Answer
Correct Answer: D
Explanation: The first step is to add the mobile app to Microsoft Intune. Once the app is added, it can be assigned to Azure AD user groups such as the Finance department so only those users can install it through the Company Portal. Registering the app in Azure AD is for identity integration, publishing to vendor stores is not required to restrict deployment through Intune, and MDT is for Windows deployment, not iOS/Android apps.
Question 169
HOTSPOT
-
Your network contains an Active Directory domain. Active Directory is synced with Azure AD.
There are 500 Active Directory domain-joined computers that run Windows 10 and are enrolled in Microsoft Intune.
You plan to implement Microsoft Defender Exploit Guard.
You need to create a custom Microsoft Defender Exploit Guard policy, and then distribute the policy to all the computers.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Microsoft Intune admin center
An Endpoint Protection configuration profile
Explanation: Custom Microsoft Defender Exploit Guard policies for Windows 10 devices managed by Intune are created in the Microsoft Intune admin center and deployed using an Endpoint Protection configuration profile.
Question 170
HOTSPOT
-
You have an Azure AD tenant that contains the following:
• Windows 11 devices that are joined to Azure AD
• A user that has a display name of User1 and a UPN of
You enable Remote Desktop on the Windows 11 devices.
You need to ensure that User1 can use Remote Desktop to connect to the devices.
How should you complete the command that must be run on each device? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
Explanation: Use the local group "Remote Desktop Users" and add the Microsoft Entra (Azure AD) user in the format AzureAD\<UPN>.
Question 173
You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.
You use Microsoft Intune to manage devices that run Windows 11.
You need to remove User1 from the local Administrators group on all enrolled devices.
What should you configure?
A. a device compliance policy
B. an account protection policy
C. an app configuration policy
Show Answer
Correct Answer: B
Explanation: Use an Intune Endpoint security account protection policy to manage local user group membership, including removing users from the local Administrators group on enrolled Windows devices. Device compliance policies evaluate compliance and app configuration policies configure app settings; neither manages local administrator group membership.
Question 174
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a computer named Computer1 that runs Windows 11. Computer1 is enrolled in Microsoft Intune.
You need to deploy an app named App1 to Computer1. The App1 installation will use multiple files.
What should you use to package App1, and which file format will be used? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: For Microsoft Intune Win32 app deployments that require multiple installation files, package the app with the Microsoft Win32 Content Prep Tool, which produces an .intunewin package for deployment.
Question 175
HOTSPOT
-
You have a Microsoft 365 subscription that contains the devices shown in the following table.
All the devices will be reimaged and licensed by using subscription activation.
The devices are assigned to the users shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
No
Yes
Explanation: Windows 11 requires TPM 2.0; Device1 has TPM 1.2 so it cannot be upgraded as-is. Device2 meets Windows 11 hardware minimums (4 GB RAM, 64 GB storage, TPM 2.0), so no additional hardware is required. Subscription activation requires a qualifying Microsoft 365 Windows license (such as Microsoft 365 E3/E5); Office 365 E5 + EMS E5 does not include the Windows entitlement, so User3 needs an additional license.
Question 176
You have a Microsoft Intune subscription associated to an Azure AD tenant named contoso.com.
Users use one of the following three suffixes when they sign in to the tenant: us.contoso.com, eu.contoso.com, or contoso.com.
You need to ensure that the users are NOT required to specify the mobile device management (MDM) enrollment URL as part of the enrollment process. The solution must minimize the number of changes.
Which DNS records do you need?
A. one TXT record only
B. three CNAME records
C. three TXT records
D. one CNAME record only
Show Answer
Correct Answer: B
Explanation: To enable automatic Microsoft Intune MDM discovery, you create a DNS CNAME record named EnterpriseEnrollment for each UPN suffix used by users. Since users sign in with three different UPN suffixes (contoso.com, us.contoso.com, and eu.contoso.com), you need three CNAME records, each pointing to EnterpriseEnrollment-s.manage.microsoft.com. This avoids requiring users to manually specify the MDM enrollment URL and is the minimum necessary configuration.
Question 177
DRAG DROP
-
You have a Microsoft 365 subscription that contains the devices shown in the following table.
You need to configure the Microsoft Edge settings for each device.
What should you use? To answer, drag the appropriate Intune features to the correct devices. Each feature may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Windows Edge settings are typically managed through an Intune device configuration profile (Settings catalog/Administrative Templates). On Android Enterprise and iOS/iPadOS, Microsoft Edge settings are configured using managed app configuration policies.
Question 178
HOTSPOT
-
Your network contains an on-premises Active Directory domain that contains the locations shown in the following table.
In Microsoft Intune, you enroll the Windows 10 devices shown in the following table.
You have a Delivery Optimization device configuration profile applied to all the devices. The profile is configured as shown in the following exhibit.
From which devices can Device1 and Device2 get updates? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: Can get updates from Device3 only.
Device2: Cannot get updates from any device.
Explanation: Restrict Peer Selection is set to Subnet mask, which limits peering to the local subnet. The /16 subnet 10.10.0.0/16 contains Device1 and Device3. Device2 is alone in 10.20.0.0/16, and Device4 is in a different subnet.
Question 179
DRAG DROP
-
You have an on-premises Active Directory domain that syncs to Azure AD tenant.
The tenant contains computers that run Windows 10. The computers are hybrid Azure AD joined and enrolled in Microsoft Intune.
The Microsoft Office settings on the computers are configured by using a Group Policy Object (GPO).
You need to migrate the GPO to Intune.
Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
Show Answer
Correct Answer: Import an ADMX file
Create a configuration profile
Assign the profile
Explanation: For Office GPO settings that rely on ADMX-backed policies, first import the ADMX template into Intune, then create a configuration profile using it, and finally assign the profile to the target devices or users.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.