You have a Microsoft 365 E5 subscription.
You purchase the devices shown in the following table.
Which devices can be enrolled in Microsoft Intune by using automatic enrollment?
A. Device1 only
B. Device1 and Device2 only
C. Device1 and Device3 only
D. Device1, Device2, and Device3 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: A
Explanation: Automatic MDM enrollment via Microsoft Entra ID is the Windows automatic enrollment feature. With Microsoft 365 E5, supported Windows 10/11 devices can automatically enroll in Intune when joined or registered to Microsoft Entra ID and within the MDM user scope. Android, iOS, and macOS use different enrollment methods rather than this Windows automatic enrollment feature.
Question 24
HOTSPOT
-
You have a Microsoft 365 subscription that contains the users shown in the following table.
You have the devices shown in the following table.
The Windows Enrollment settings have the following configurations:
• MDM user scope: Group1
• Windows Information Protection (WIP) user scope: Group2
You configure Microsoft Intune enrollment restrictions as shown in the exhibit. (Click the Exhibit tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
Yes
Explanation: The enrollment restriction allows Windows, macOS, and Android platforms and personally owned devices. The MDM user scope governs Windows automatic MDM enrollment, while macOS and Android can be enrolled through supported manual Intune enrollment methods; the WIP scope is unrelated to enrollment.
Question 25
You have a Microsoft 365 subscription and use the Microsoft Intune Suite.
You have the devices shown in the following table.
All the devices are enrolled in Intune.
Which devices can you query by using Device query?
A. Device1 only
B. Device1 and Device2 only
C. Device1, Device2, and Device3 only
D. Device1, Device2, and Device4 only
E. Device1, Device2, Device3, and Device4
Show Answer
Correct Answer: B
Explanation: Device query in Microsoft Intune supports only Intune-managed, corporate-owned Windows devices that are Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft Entra registered (workplace joined) devices and non-Windows devices such as macOS aren't supported.
Question 26
You have a Microsoft 365 subscription and use Microsoft Intune.
You need to implement Microsoft Tunnel for Mobile Application Management (MAM) for personal Android devices.
You perform the following actions:
• Configure Microsoft Tunnel for managed devices.
• Validate that user devices meet the prerequisites for Tunnel for MAM.
• Create app configuration policies for Microsoft Defender and Microsoft Edge.
What should you configure next?
A. an app protection policy
B. a custom profile for Android Enterprise devices
C. a Conditional Access policy
D. a VPN profile for Android Enterprise devices
Show Answer
Correct Answer: A
Explanation: For Microsoft Tunnel for MAM on personal Android devices, after configuring Microsoft Tunnel, validating prerequisites, and creating the required app configuration policies for Microsoft Defender and Microsoft Edge, the next step is to create and assign an Intune app protection policy (MAM). The app protection policy enables protected apps to use Tunnel for MAM and applies the required mobile application management settings.
Question 27
HOTSPOT
-
You have a Microsoft 365 subscription that includes Microsoft Intune.
Users have iOS devices that use Microsoft Outlook.
You need to configure Outlook. The solution must meet the following requirements:
• Restrict copy and paste actions from Outlook other apps.
• Enable S/MIME for Outlook.
Which type of policy should you configure for each requirement? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
Explanation: Copy/paste restrictions are controlled by Intune App Protection (MAM) policies. Outlook S/MIME settings for iOS are deployed using an App Configuration policy.
Question 28
HOTSPOT
-
You have a hybrid environment that contains a Microsoft Entra tenant and an on-premises Active Directory Domain Services (AD DS) domain.
You purchase the devices shown in the following table.
Which Microsoft Entra join type can each device use? To answer, select the appropriate options in the answer area
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Device1: Microsoft Entra registered, Microsoft Entra joined, or Microsoft Entra hybrid joined
Device2: Microsoft Entra registered only
Explanation: Windows 11 supports Microsoft Entra registration, Microsoft Entra join, and Microsoft Entra hybrid join. iOS devices support Microsoft Entra registration (workplace join) but not Microsoft Entra join or hybrid join.
Question 30
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains three Windows devices named Device1, Device2, and Device3. The devices are managed by using Microsoft Intune. Each device contains a file named Script1.ps1.
Users do NOT have local administrator permissions for the devices.
The subscription contains the groups shown in the following table.
You create two Endpoint Privilege Management (EPM) elevation settings policies that have the following settings:
• Name: Policy1
• Endpoint Privilege Management: Enabled
o Default elevation response: Deny all requests
o Allow Elevation Detection: No
o Send elevation data for reporting: No
• Assignments:
o Included groups: Group1
• Name: Policy2
• Endpoint Privilege Management: Require support approval
o Allow Elevation Detection: No
o Send elevation data for reporting: No
• Assignments:
o Included groups: Group3
You create an EPM elevation rules policy named RulesPolicy1 that has the following settings:
• Rule name: Rule1
o Elevation type: Automatic
o Child process behavior: Deny all
o File name: Script1.ps1
o File hash:
Show Answer
Correct Answer: No
No
Yes
Explanation: Device1 receives an EPM settings policy with default 'Deny all requests'; approval is not used. Device2 has no EPM settings policy, so support approval is not required. Device3 receives an EPM settings policy with default 'Require support approval'; without a matching automatic elevation rule for that device, the default behavior is to require approval.
Question 31
Note: This section contains one or more sets of questions with the same scenario and problem. Each question presents a unique solution to the problem. You must determine whether the solution meets the stated goals. More than one solution in the set might solve the problem. It is also possible that none of the solutions in the set solve the problem.
After you answer a question in this section, you will NOT be able to return. As a result, these questions do not appear on the Review Screen.
You have a Microsoft 365 E5 subscription. The subscription contains devices that are Microsoft Entra joined and enrolled in Microsoft Intune.
You create a user named User1.
You need to ensure that User1 can rotate BitLocker recovery keys by using Intune.
Solution: From the Microsoft Entra admin center, you assign the Cloud Device Administrator role to User1.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: Assigning the Microsoft Entra Cloud Device Administrator role does not grant the Intune permissions required to rotate BitLocker recovery keys. Rotating BitLocker recovery keys through Intune requires appropriate Intune administrative permissions (or an Entra role that includes the necessary Intune capabilities), not the Cloud Device Administrator role.
Question 32
SIMULATION
-
Username and password
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below.
To enter your password, place your cursor in the Enter password box and select the password below.
Microsoft 365 Username:
Microsoft 365 Password: i7A4$3o^HGD3L~=c[9xuOhM%^4:s11Ai
If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://portal.office.com”, and press Enter.
The following information is for technical support purposes only:
Lab Instance: 48262079
-
You need to create a compliance policy to validate whether all the Windows 10 or later devices enrolled in Microsoft Intune have BitLocker Drive Encryption (BitLocker) enabled.
Show Answer
Correct Answer: Devices → Compliance policies → Create policy
Platform: Windows 10 and later
Device health → Require BitLocker = Require
Assign the policy
Create
Explanation: A Windows compliance policy validates device state. Setting 'Require BitLocker' to 'Require' under Device health checks that BitLocker is enabled and marks devices compliant or noncompliant accordingly.
Question 33
HOTSPOT
-
You have a Microsoft Entra tenant named contoso.com that contains the users shown in the following table.
You purchase the devices shown in the following table.
Administrators perform the following actions:
• Join Device1 to contoso.com by using the credentials of Admin1.
• Register Device2 in contoso.com by using the credentials of Admin2.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Microsoft Entra joined Windows devices allow any tenant user to sign in by default (unless restricted). Microsoft Entra registered devices are signed in with the existing local/Microsoft account, not with Microsoft Entra credentials.
$19
Get all 373 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.