HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a group named Group1 and 500 mobile devices that run Android or iOS.
You need to create app protection policies and Conditional Access policies for the subscription. The solution must meet the following requirements:
• Encrypt corporate data stored on the mobile devices.
• Automatically remove corporate data stored on a mobile device if the device is offline for 45 days.
• Ensure that only users assigned app protection policies can use mobile devices to access the subscription.
• On the mobile devices used only by Group1, automatically remove corporate data stored on the devices if the devices are offline for 30 days.
What is the minimum number of policies you should create? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Different offline wipe requirements require separate app protection policies (45 days for general users, 30 days for Group1, plus platform-specific separation for Android and iOS). A single Conditional Access policy can enforce that only users with app protection policies can access Microsoft 365.
Question 12
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You have 500 Windows devices that are NOT onboarded.
You need to connect Microsoft Intune with Microsoft Defender for Endpoint and onboard the devices. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point
Show Answer
Correct Answer: Enable the connection by using:
The Microsoft Intune admin center
Onboard the devices by using:
The Microsoft Defender portal
Explanation: The Intune–Defender for Endpoint integration is configured in the Intune admin center. Large-scale device onboarding with minimal effort is performed from the Microsoft Defender portal, which provides centralized onboarding methods for Windows devices.
Question 13
You have a Microsoft 365 E5 subscription and use the Microsoft Intune Suite. The subscription contains a Microsoft SharePoint Online site named Site1 and 500 Windows devices enrolled in Intune.
You have the apps shown in the following table.
You need to deploy the apps to the devices by using Intune.
For which apps must you upload app package files before you can deploy them?
A. App1 only
B. App1 and App2 only
C. App1 and App4 only
D. App1, App2, and App4 only
E. App1, App2, App3, and App4
Show Answer
Correct Answer: A
Explanation: In Intune, you must upload an app package only when the app is not hosted by Microsoft and is deployed as a Win32 app. Microsoft Store apps, Microsoft 365 apps, and apps available through built‑in Intune connectors do not require uploading installation files. Based on the table, only App1 is a Win32 app that is not Microsoft‑hosted, so its package must be uploaded before deployment.
Question 14
You have devices enrolled in Microsoft Intune as shown in the following table.
On which devices can you apply app configuration policies for the managed devices?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device2 and Device3 only
E. Device1, Device2, and Device3
Show Answer
Correct Answer: D
Explanation: App configuration policies for managed devices in Microsoft Intune are supported on iOS/iPadOS and Android Enterprise devices. They are not supported on Windows devices. Based on the table implied by the question, Device2 and Device3 correspond to iOS/iPadOS and Android Enterprise, so only those devices can have managed app configuration policies applied.
Question 15
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a Conditional Access policy for the sg-Legal group that requires Android devices to be compliant when they connect to Microsoft Office 365. Access to other apps and devices must NOT be affected.
Show Answer
Correct Answer: Create a Conditional Access policy
Users: Include sg-Legal
Cloud apps: Select Microsoft Office 365
Conditions: Device platforms = Android
Access controls (Grant): Require device to be marked as compliant
Enable policy: On
Explanation: The policy targets only the sg-Legal group and only Microsoft Office 365. Limiting the device platform to Android ensures other devices are unaffected, and requiring compliant devices enforces Intune compliance without impacting other apps or users.
Question 16
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a configuration profile that will enable Single app, full-screen kiosk mode for Windows 10 and later devices in a group named sg-IT. The solution must sign in a local user named KioskUser automatically and display Microsoft Edge with the https://bing.com homepage.
Show Answer
Correct Answer: Create an Intune configuration profile
Platform: Windows 10 and later
Profile type: Templates > Kiosk
Kiosk settings
Kiosk mode: Single app, full-screen kiosk
User logon type: Auto logon
Local user: KioskUser
App configuration
Application: Microsoft Edge
Home page URL: https://bing.com
Assignments
Assign the profile to device group sg-IT
Explanation: A Windows 10 and later Kiosk template in Intune supports single-app, full-screen kiosk mode. Configuring auto logon with the local user KioskUser ensures automatic sign-in, while Microsoft Edge is set as the sole application with https://bing.com as the startup page. Assigning the profile to sg-IT applies the configuration to the required devices.
Question 17
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create an endpoint security policy to turn on Windows SmartScreen for all Windows devices.
Show Answer
Correct Answer: Microsoft Intune admin center
Endpoint security > Application control > Create policy
Platform: Windows
Profile: Microsoft Defender Application Control
Setting: Turn on Windows SmartScreen
Explanation: Windows SmartScreen is configured through an Endpoint security **Application control** policy in Intune. Creating a Windows Application Control (MDAC/WDAC) profile and enabling the SmartScreen setting applies it to all assigned Windows devices.
Question 18
You have a Microsoft 365 subscription that contains 500 Android devices. The devices are managed by using Microsoft Intune.
You need to ensure that you can manage software updates for the devices by using Android FOTA.
What should you do first?
A. Create a compliance policy.
B. Add a compliance partner.
C. Configure a connector.
D. Add derived credentials.
Show Answer
Correct Answer: C
Explanation: Android FOTA in Microsoft Intune requires an OEM firmware partner integration. The first step is to configure the Android FOTA (OEM) connector in Intune; without this connector, firmware updates cannot be managed or deployed.
Question 19
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the devices shown in the following table.
All the devices are enrolled in Microsoft Intune.
The devices have apps installed as shown in the following table.
In Intune, you create an app configuration policy named Policy1 that has the following settings:
• Device enrollment type: Managed apps
• Target policy to: All Microsoft Apps
• Assignments
o Included groups: Group1
o Excluded groups: Group2
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: App configuration policies for managed apps apply to supported mobile platforms (Android/iOS) and included groups.
Device1 (Windows 11): Teams is a Microsoft app and included → applies.
Device2 (Android): OneDrive is a Microsoft app and included → applies.
Device3 (iOS): Although supported, the device is in an excluded group → does not apply.
Question 20
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains 500 Windows devices enrolled in Microsoft Intune.
You deploy Microsoft Defender for Endpoint.
You need to onboard the devices to Defender for Endpoint. The solution must minimize administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Onboarding
An endpoint detection and response (EDR) policy
Explanation: To minimize administrative effort with Intune-enrolled devices, enable Defender for Endpoint onboarding in the Microsoft Defender portal, then use Intune to deploy an EDR policy, which automatically onboards devices to Defender for Endpoint without scripts or manual steps.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.