You have a Microsoft 365 E5 subscription.
You purchase the devices shown in the following table.
Which devices can be enrolled in Microsoft Intune by using automatic enrollment?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation: Microsoft Intune automatic MDM enrollment (via the MDM user scope in Microsoft Entra ID) applies to Windows 10/11 devices when they are Azure AD joined or registered. Other platforms (iOS, Android, macOS) use different enrollment methods and are not covered by this specific automatic enrollment mechanism. Therefore, only the Windows device (Device1) qualifies.
Question 23
HOTSPOT
-
You have a Microsoft 365 subscription that contains the users shown in the following table.
You have the devices shown in the following table.
The Windows Enrollment settings have the following configurations:
• MDM user scope: Group1
• Windows Information Protection (WIP) user scope: Group2
You configure Microsoft Intune enrollment restrictions as shown in the exhibit. (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 can enroll Device1 in Intune: Yes
User2 can enroll Device2 in Intune: No
User3 can enroll Device3 in Intune: No
Explanation: Intune enrollment requires the user to be included in the MDM user scope. Only User1 is in Group1, which is configured as the MDM user scope, so only User1 can enroll a device. Platform enrollment restrictions allow all platforms, but they are evaluated only after the MDM user scope requirement is met.
Question 24
You have a Microsoft 365 subscription and use the Microsoft Intune Suite.
You have the devices shown in the following table.
All the devices are enrolled in Intune.
Which devices can you query by using Device query?
A. Device1 only
B. Device1 and Device2 only
C. Device1, Device2, and Device3 only
D. Device1, Device2, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: B
Explanation: Intune Device query supports only Windows 10/11 devices that are Intune-managed and either Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra registered (workplace joined) devices and non-Windows devices (such as macOS) aren’t supported. Based on the table, only Device1 and Device2 meet these requirements.
Question 25
You have a Microsoft 365 subscription and use Microsoft Intune.
You need to implement Microsoft Tunnel for Mobile Application Management (MAM) for personal Android devices.
You perform the following actions:
• Configure Microsoft Tunnel for managed devices.
• Validate that user devices meet the prerequisites for Tunnel for MAM.
• Create app configuration policies for Microsoft Defender and Microsoft Edge.
What should you configure next?
A. an app protection policy
B. a custom profile for Android Enterprise devices
C. a Conditional Access policy
D. a VPN profile for Android Enterprise devices
Show Answer
Correct Answer: A
Explanation: For Microsoft Tunnel for Mobile Application Management (MAM) on personal Android devices, after configuring the Tunnel infrastructure and creating app configuration policies for Microsoft Defender and Microsoft Edge, the next required step is to create an Intune app protection policy (MAM policy). The app protection policy enables data protection for the apps and triggers the Microsoft Tunnel for MAM connection when a protected app (such as Edge) accesses corporate resources. VPN profiles and Android Enterprise device profiles are for device management scenarios, not MAM-only deployments, and Conditional Access is not the immediate next configuration step.
Question 26
HOTSPOT
-
You have a Microsoft 365 subscription that includes Microsoft Intune.
Users have iOS devices that use Microsoft Outlook.
You need to configure Outlook. The solution must meet the following requirements:
• Restrict copy and paste actions from Outlook other apps.
• Enable S/MIME for Outlook.
Which type of policy should you configure for each requirement? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
Explanation: Copy and paste restrictions between Outlook and other apps are enforced using Intune App protection (MAM) policies. S/MIME settings for Outlook on iOS are configured through an Intune App configuration policy, which controls app-specific features.
Question 27
HOTSPOT
-
You have a hybrid environment that contains a Microsoft Entra tenant and an on-premises Active Directory Domain Services (AD DS) domain.
You purchase the devices shown in the following table.
Which Microsoft Entra join type can each device use? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1:
Microsoft Entra registered, Microsoft Entra joined, or Microsoft Entra hybrid joined
Device2:
Microsoft Entra registered only
Explanation: Windows 11 devices can be Microsoft Entra joined, hybrid joined with on-prem AD DS, or Entra registered. iOS devices do not support Entra join or hybrid join and can only be Entra registered.
Question 29
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains three Windows devices named Device1, Device2, and Device3. The devices are managed by using Microsoft Intune. Each device contains a file named Script1.ps1.
Users do NOT have local administrator permissions for the devices.
The subscription contains the groups shown in the following table.
You create two Endpoint Privilege Management (EPM) elevation settings policies that have the following settings:
• Name: Policy1
• Endpoint Privilege Management: Enabled
o Default elevation response: Deny all requests
o Allow Elevation Detection: No
o Send elevation data for reporting: No
• Assignments:
o Included groups: Group1
• Name: Policy2
• Endpoint Privilege Management: Require support approval
o Allow Elevation Detection: No
o Send elevation data for reporting: No
• Assignments:
o Included groups: Group3
You create an EPM elevation rules policy named RulesPolicy1 that has the following settings:
• Rule name: Rule1
o Elevation type: Automatic
o Child process behavior: Deny all
o File name: Script1.ps1
o File hash:
Show Answer
Correct Answer: Device1: No
Device2: No
Device3: Yes
Explanation: Device1: Assigned Policy1 (Deny all). Although an automatic elevation rule exists, elevation is blocked, so no approval occurs.
Device2: No EPM settings policy assigned, so EPM isn’t active and no approval process applies.
Device3: Assigned Policy2 (Require support approval). With no matching elevation rule, the default requires approval.
Question 30
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription. The subscription contains devices that are Microsoft Entra joined and enrolled in Microsoft Intune.
You create a user named User1.
You need to ensure that User1 can rotate BitLocker recovery keys by using Intune.
Solution: From the Microsoft Entra admin center, you assign the Cloud Device Administrator role to User1.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Assigning the Cloud Device Administrator role does not meet the goal. Cloud Device Administrator is a Microsoft Entra role that allows limited device management in Entra ID, but it does not grant the Intune permissions required to rotate BitLocker recovery keys. BitLocker key rotation via Intune requires an Intune role such as Intune Administrator, Endpoint Security Manager, Help Desk Operator, or a custom Intune role with BitLocker/endpoint security permissions.
Question 31
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a compliance policy to validate whether all the Windows 10 or later devices enrolled in Microsoft Intune have BitLocker Drive Encryption (BitLocker) enabled.
Show Answer
Correct Answer: Intune admin center → Devices → Compliance policies → Create policy
Platform: Windows 10 and later
Settings → Device health → Require BitLocker = Require
Assign to all Windows 10 or later device groups
Create the policy
Explanation: A compliance policy is used to validate device state, not configure encryption. Setting **Require BitLocker** under **Device health** checks whether BitLocker is enabled and marks devices compliant or noncompliant accordingly.
Question 32
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
You purchase the devices shown in the following table.
Administrators perform the following actions:
• Join Device1 to contoso.com by using the credentials of Admin1.
• Register Device2 in contoso.com by using the credentials of Admin2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Device1 is Microsoft Entra joined, which allows any user in the tenant to sign in by default (local admin rights are separate). Device2 is only Microsoft Entra registered, which does not support Windows sign-in using Entra credentials. User roles (Global Admin, Cloud Device Admin, or none) do not restrict basic sign-in to an Entra-joined device.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.